15:00:56 #startmeeting keystone 15:00:56 Meeting started Tue Nov 1 15:00:56 2022 UTC and is due to finish in 60 minutes. The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:00:56 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:00:56 The meeting name has been set to 'keystone' 15:01:05 #topic Roll Call 15:01:08 admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek 15:01:54 o/ 15:02:06 o/ 15:03:07 Hi folks! 15:03:23 #topic Review past meeting work items 15:03:44 We had a few, first up is 15:03:54 dmendiza[m] will look at https://bugs.launchpad.net/keystone/+bug/1990987 15:04:03 dmendiza[m]: any update? 15:04:08 👀 15:04:11 Still looking 15:04:49 ack 15:04:53 next up is 15:04:59 d34dh0r53 look into user-defined attribute access control 15:05:06 no updates 15:05:26 we have some reviewathon items that we were going to look at 15:05:43 reviewathon review https://review.opendev.org/c/openstack/keystoneauth/+/838104 15:05:45 reviewathon review https://review.opendev.org/c/openstack/keystone/+/838108 15:05:47 reviewathon review https://review.opendev.org/c/openstack/keystone/+/822601 15:05:49 reviewathon review https://review.opendev.org/c/openstack/keystone-specs/+/818616 15:06:15 We didn't get to the first one 15:06:27 nor the second 15:07:06 the third has -1's and commentary so that is in progress 15:07:25 the fourth is the default service role 15:07:54 next up is dmendiza[m] and d34dh0r53 make some time to start the gap analysis between CLI and OSC. 15:08:02 we didn't get to that 15:08:22 and finally we have d34dh0r53 try to reproduce https://bugs.launchpad.net/python-keystoneclient/+bug/1993614 15:08:28 which I wasn't able to get to 15:08:33 the gap analysis is about sdk and the client 15:08:44 we don't have any other cli besides osc already :) 15:09:36 knikolla[m]: right 15:11:12 #action dmendiza[m] and d34dh0r53 make some time to start the gap analysis between SDK and the Client 15:11:28 #action dmendiza[m] will look at https://bugs.launchpad.net/keystone/+bug/1990987 15:11:41 #action reviewathon review https://review.opendev.org/c/openstack/keystoneauth/+/838104 15:11:50 #action reviewathon review https://review.opendev.org/c/openstack/keystone/+/838108 15:12:14 #action d34dh0r53 look into user-defined attribute access control 15:12:35 ok, next up we have 15:12:37 #topic Liaison Updates 15:12:46 Nothing from VMT 15:12:58 dmendiza[m], knikolla[m] anything from Release Management? 15:13:47 I can't think of anything 15:13:58 ok, thanks 15:14:08 #help still looking for additional cross-project liaisons 15:14:38 any other liaison updates? 15:15:19 #topic specification OAuth 2.0 (hiromu) 15:15:48 thanks for the remind. 15:15:56 first, i've updated the spec 15:16:01 https://review.opendev.org/c/openstack/keystone-specs/+/861554/2..3 15:16:37 I think it's now ready for the first review. 15:17:00 and I have a question 15:17:25 ok 15:17:27 that i wrote on the etherpad. 15:18:23 the etherpad is here: https://etherpad.opendev.org/p/keystone-weekly-meeting 15:18:35 The question is, which is better? 15:18:45 yes 15:19:09 supporting authentication with external OAuth 2.0 authorization servers (ext authz servers) by keystoneauth 15:19:20 i.e., users can use openstack command as usual when using ext authn servers. 15:19:31 or do not support ext authn servers by keystoneauth 15:19:38 i.e., users set an access token as an environment variable, e.g., OS_TOKEN, to call API of OpenStack services. This is not unnatural, assuming the programmatic access which must be a major usecase of the client credentials grant. 15:19:54 thank you d34dh0r53 :) 15:20:01 :) 15:21:00 I think the second approach is simpler and consistent with the way many things already work 15:22:04 I agree with you 15:22:22 knikolla[m], dmendiza[m] any thoughts? 15:23:10 I also don't think we should worry about authenticating with external servers with keystoneauth 15:24:09 ok, so we're in agreement 15:24:25 ok, i'll go with the second one. 15:24:34 awesome! 15:24:34 👍️ 15:24:42 thanks a lot 15:24:51 thank you hiromu! 15:25:07 #topic Secure RBAC (dmendiza[m]) 15:25:58 Not a whole lot of progress this week. I did bring up the next two tasks with my team downstream: 15:26:50 #link https://review.opendev.org/c/openstack/keystone/+/822601 15:27:27 Getting the "manager" role patch updated/landed. 15:27:42 and 2) 15:28:19 The "service" role spec: 15:28:20 #link https://review.opendev.org/c/openstack/keystone-specs/+/818616 15:28:29 followed by implementation 15:29:29 I'll try to help out as much as possible for the next +/-2 weeks before I take leave for a few months. 15:31:27 ack, thanks dmendiza[m] 15:31:59 #action reviewathon https://review.opendev.org/c/openstack/keystone-specs/+/818616 15:32:12 we really need to get that spec reviewed and merged 15:32:45 Agreed. I'm going to read/comment in the next few days and maybe we can check progress on Friday 15:32:48 for the reviewathon 15:32:56 ack 15:33:11 * d34dh0r53 needs to remember to look at the meeting log for the reviewathon action items 15:33:43 #topic Open Discussion 15:34:02 we don't have anything on the agenda, does anyone have anything before we do bug review? 15:34:52 ok, moving on then 15:34:58 #topic bug review 15:35:09 First off we have keystone 15:35:16 #link https://bugs.launchpad.net/keystone/?orderby=-id&start=0 15:35:25 no new bugs here 15:35:34 next up, python-keystoneclient 15:35:43 #link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=0 15:36:01 no new bugs, I'll attempt to reproduce the create service bug this week 15:36:11 keystoneauth is next 15:36:18 #link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=0 15:36:29 no new bugs 15:36:46 #link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=0 15:37:08 nothing new in keystonemiddleware 15:37:17 pycadf 15:37:26 #link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=0 15:37:32 nothing new 15:37:39 finally we have ldappool 15:37:47 #link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=0 15:38:00 no new bugs there either 15:38:30 thanks for joining today everyone! Is there anything else before we close? 15:39:12 have a great rest of your week then :) 15:39:16 #endmeeting