15:01:28 #startmeeting keystone 15:01:28 Meeting started Tue Oct 25 15:01:28 2022 UTC and is due to finish in 60 minutes. The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:01:28 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:01:28 The meeting name has been set to 'keystone' 15:01:42 #topic Roll Call 15:01:44 admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek 15:02:05 o/ 15:02:09 o/ 15:02:14 dmendiza[m], do you want to be on the roll call list? 15:02:54 o/ 15:03:26 o/ everyone :) 15:03:38 hopefully everyone has recovered from the PTG 15:04:06 let's get started 15:04:29 #topic Review past meeting work items 15:04:33 #link https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-10-11-15.02.html 15:04:40 🙋‍♂️ 15:05:04 We did some PTG planning, more on that later and we had one Action Item 15:05:14 https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-10-11-15.02.html 15:05:22 oops, wrong paste 15:05:31 dmendiza[m] will look at https://bugs.launchpad.net/keystone/+bug/1990987 15:05:52 did not get a chance to do that yet. was busy with PTG last week 15:06:06 dmendiza[m]: ack, can I re-assign that action item to you? 15:06:43 yep 15:06:50 awesome, thank you! 15:06:56 #action dmendiza[m] will look at https://bugs.launchpad.net/keystone/+bug/1990987 15:08:00 next up we have d34dh0r53 look into user-defined attribute access control 15:08:13 I did not get to this, will add again for this week 15:08:18 #action d34dh0r53 look into user-defined attribute access control 15:08:33 finally we have d34dh0r53 submit fix for Bug/1992183 15:09:00 that review is up here 15:09:03 #link https://review.opendev.org/c/openstack/keystone/+/861232 15:09:18 thanks for the reviews so far 15:09:48 that does it for the past meeting work items 15:10:17 #topic Liaison Updates 15:10:30 Anyone have anything? 15:11:21 #help still looking for additional cross-project liaisons 15:11:21 * dmendiza[m] checks release patches 15:12:01 Ok, yeah 15:12:06 https://review.opendev.org/c/openstack/releases/+/862323 15:12:18 Release team wants to move Wallaby into EM 15:12:42 for us it just means no new releases will be made, but we will still be able to merge backports when necessary 15:13:09 d34dh0r53: I should be able to help with release things. 15:13:19 at least for the next couple of weeks. 15:13:20 dmendiza[m]: excellent, thank you 15:13:39 I'm fine with moving Wallaby to EM, any objections? 15:14:06 fine by me as well 15:14:46 Ok, I'll +1 that patch unless I hear otherwise 15:15:54 any other Liaison updates? I don't have anything from VMT 15:17:13 next up on the agenda we have 15:17:31 #topic specification OAuth 2.0 (h_asahina) 15:17:47 #link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext 15:18:11 #link https://review.opendev.org/c/openstack/keystone-specs/+/843765 15:18:48 No update this week 15:19:01 but our team's arguing over what grant type should be used 15:19:08 hiromu: ack 15:19:30 so, may be I'll change flows in the spec. 15:19:31 I haven't had a chance yet to look at it in-depth. 15:19:59 it's ok :) 15:20:29 I'll remind you when we fix the contents of the spec. 15:20:42 thank you hiromu 15:20:53 btw, this is just a reminder, please kindly review these docs patches and hopefully backport them to Zed. 15:21:02 https://review.opendev.org/c/openstack/keystoneauth/+/838104 15:21:04 https://review.opendev.org/c/openstack/keystone/+/838108 15:21:42 #action reviewathon review https://review.opendev.org/c/openstack/keystone-specs/+/843765 15:22:03 #undo 15:22:03 Removing item from minutes: #action reviewathon review https://review.opendev.org/c/openstack/keystone-specs/+/843765 15:22:25 #action reviewathon review https://review.opendev.org/c/openstack/keystoneauth/+/838104 15:22:34 #action reviewathon review https://review.opendev.org/c/openstack/keystone/+/838108 15:22:49 great. thanks d34dh0r53 15:23:03 np hiromu 15:23:28 #topic specification Secure RBAC (dmendiza[m]) 15:23:41 #link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_ 15:25:33 Yeah, there were a few SRBAC sessions during PTG 15:25:46 I think the main goals for us this cycle are: 15:25:55 1. Merge the "manager" role implementation 15:26:05 2. Merge the "service" role spec 15:26:18 3. Implement the "service" role after spec has landed 15:26:45 I'm not sure if we're already defaulting to `enforce_scope=True` and `enforce_new_defaults=True` but I think we may be able to do that this cycle. 15:27:46 ok 15:28:27 I'd like to look at the manager role implementation during the reviewathon 15:28:52 #action reviewathon review https://review.opendev.org/c/openstack/keystone/+/822601 15:28:52 +1 15:29:42 it looks like gmann has updated the service role spec so we should look at that as well 15:30:02 #action reviewathon review https://review.opendev.org/c/openstack/keystone-specs/+/818616 15:31:04 So, speaking of the PTG 15:31:15 #topic Open Discussion 15:31:23 d34dh0r53: ptg review https://etherpad.opendev.org/p/antelope-ptg-keystone 15:31:59 #link https://etherpad.opendev.org/p/antelope-ptg-keystone 15:32:26 anything to add regarding the Secure RBAC community goal? 15:33:58 ok, hiromu do you have any asks/updates on the Supporting external authz server by Keystone Middleware BP/Spec? 15:34:58 ok 15:35:02 there's no update so far 15:35:07 ok, thanks hiromu 15:35:29 next up we have deprecate python-keystone client that dmendiza[m] and myself have action items on 15:36:09 I know there was talk at one of the TC sessions about openstacksdk and the individual clients but I'm not sure if any consensus was reached 15:36:47 knikolla[m]: were there any takeaways we should consider before doing this work? 15:37:01 It's a slow road and we're well ahead of the rest of OpenStack on it, haha. 15:37:23 haha, awesome 15:37:48 We have removed CLI access from the keystoneclient, and that's the first target of that work. Full parity between CLI clients and OSC. 15:38:00 I don't think we've targeted anything yet for moving entirely to SDK. 15:38:22 I think a good goal for this cycle is to determine our feature gaps 15:38:24 One thing that's not clear to me is whether keystone-manage or keysotne-bootstrap or w/e else needs to also be part of OSC? 15:38:40 I don't think so. 15:38:55 They usually interact with the DB directly, rather than through the API. 15:39:18 Gotcha ... yeah, as I typed that I realized those are CLIs that are part of the server, not the client 15:40:36 Ok dmendiza[m] and I will try to carve out a little time to start the gap analysis 15:41:04 #action dmendiza[m] and d34dh0r53 make some time to start the gap analysis between CLI and OSC. 15:41:50 next up, Ade Lee is working on a new OIDC gate. He's using the plugin that you wrote knikolla[m], thanks again for pointing us to that 15:42:13 I think it will be a big help 15:42:38 any other topics for Open Discussion? 15:44:01 #topic Bug Review 15:44:13 Keystone Bugs 15:44:24 #link https://bugs.launchpad.net/keystone/?orderby=-id&start=0 15:44:42 we have https://bugs.launchpad.net/keystone/+bug/1993742 15:45:48 this was fixed in wallaby by an SQL upgrade 15:45:58 ahh 15:46:12 xek: would you mind commenting on that bug with a link? 15:47:07 d34dh0r53: ok, I'll also look into it to make sure this is the same bug 15:47:12 xek: thank you 15:47:26 that's it for new keystone bugs, next up we have python-keystoneclient 15:47:37 #link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=0 15:47:55 looks like this is new https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=0 15:48:12 man, the copy paste game is bad today :/ 15:48:20 https://bugs.launchpad.net/python-keystoneclient/+bug/1993614 15:51:20 hmm, that doesn't seem right, anyone have a devstack up to verify that? 15:51:47 I'll try to take a look at this one 15:52:05 #action d34dh0r53 try to reproduce https://bugs.launchpad.net/python-keystoneclient/+bug/1993614 15:52:16 that's all for python-keystoneclient 15:52:22 next up we have keystoneauth 15:52:39 #link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=0 15:52:54 no new bugs there 15:53:02 keystonemiddleware is next 15:53:10 #link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=0 15:53:26 nothing new here 15:53:33 PyCADF 15:53:43 #link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=0 15:54:00 no new bugs 15:54:07 Finally we have ldappool 15:54:15 #link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=0 15:54:25 which has nothing new 15:54:35 Anything else before we end the meeting? 15:55:34 Thanks for joining everyone! Have a great week, and I'll see y'all online :) 15:55:38 #endmeeting