15:00:11 #startmeeting keystone 15:00:11 Meeting started Tue Dec 6 15:00:11 2022 UTC and is due to finish in 60 minutes. The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:00:11 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:00:11 The meeting name has been set to 'keystone' 15:00:22 #topic roll call 15:00:29 admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann 15:02:36 let's get started 15:02:37 Rafael Weingartner proposed openstack/keystone-specs master: Add schema version and add support to "domain" attribute in mapping rules https://review.opendev.org/c/openstack/keystone-specs/+/748042 15:02:52 #topic review past meeting work items 15:03:14 #link https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-11-29-15.01.html 15:05:23 sorry, copy pasta issues :/ 15:05:33 first up we have reivewathon review https://review.opendev.org/c/openstack/keystoneauth/+/838104 15:06:04 we actually have several OAuth 2.0 things to review, we focused on getting the Spec for M+TLS merged which we're close to doing 15:06:25 once that merges we can focus on the actual code for OAuth 2.0 with M+TLS 15:06:41 #action reviewathon https://review.opendev.org/c/openstack/keystoneauth/+/838104 15:07:10 #action reviewathon https://review.opendev.org/c/openstack/keystone/+/838108 15:07:42 #action reviewathon https://review.opendev.org/c/openstack/keystone/+/860928 15:08:00 #action reviewathon https://review.opendev.org/c/openstack/keystoneauth/+/860923 15:08:28 next up is d34dh0r53 look into user-defined attribute access control 15:08:32 didn't get to it, so pushing 15:08:35 #action d34dh0r53 look into user-defined attribute access control 15:08:54 next up d34dh0r53 request pycadf release once https://review.opendev.org/c/openstack/pycadf/+/863702 merges 15:09:25 we need another core reviewer on this one, going to assign it to knikolla[m] so we can get it merged 15:09:44 #action knikolla[m] please review https://review.opendev.org/c/openstack/pycadf/+/863702 15:10:01 that does it for last meeting action items 15:10:28 #topic liaison updates 15:10:54 nothing from VMT, and neither Doug nor knikolla[m] are here so we can move on 15:11:18 #help Let me know if you're interested in volunteering for a liaison role 15:11:48 #topic specification OAuth 2.0 (hiromu) 15:11:59 #link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext 15:12:05 #link https://review.opendev.org/c/openstack/keystone-specs/+/843765 15:12:56 I think we're ready to merge this spec, there were just a couple of nits that came out during the reviewathon which Hiromu has cleared up 15:13:22 #topic specification Secure RBAC (dmendiza[m]) 15:13:32 #link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_ 15:13:42 Service Role Spec 15:13:44 #link https://review.opendev.org/c/openstack/keystone-specs/+/818616 15:14:03 the service role spec has merged! Thanks for all the reviews and work on this 15:14:15 Manager Role Implementation 15:14:23 #link https://review.opendev.org/c/openstack/keystone/+/822601 15:14:33 There are some valid -1's on this so more work is needed 15:15:02 I don't think any of the stakeholders are here today so we'll move on, but please update/review if you get a chance 15:15:14 #topic open discussion 15:15:36 drencrom: zuul failing because test-requirements not compatible with python 3.10 (see https://review.opendev.org/c/openstack/keystonemiddleware/+/860481) 15:15:47 I'll look at that this week and try to get it cleared 15:16:11 #action d34dh0r53 unblock https://review.opendev.org/c/openstack/keystonemiddleware/+/860481 15:16:31 anything else for open discussion? 15:21:20 moving on then 15:21:25 #topic bug review 15:21:33 #link https://bugs.launchpad.net/keystone/?orderby=-id&start=0 15:22:30 looks like we have a couple of new bugs with fixes proposed 15:22:40 #link https://bugs.launchpad.net/keystone/+bug/1998268 15:22:48 Fernet uid/gid logic issue 15:23:13 #action d34dh0r53 review https://review.opendev.org/c/openstack/keystone/+/866096 15:23:39 #link https://bugs.launchpad.net/keystone/+bug/1998789 15:23:44 PooledLDAPHandler.result3 does not release pool connection back when an exception is raised Edit 15:24:07 #action d34dh0r53 review https://review.opendev.org/c/openstack/keystone/+/866723 15:24:23 thanks for the bug reports and fixes, I'll review this week 15:24:31 next up 15:24:53 #link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=0 15:25:10 nothing new for python-keystoneclient 15:25:22 #link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=0 15:25:47 keystoneauth has a new bug 15:25:57 #link https://bugs.launchpad.net/keystoneauth/+bug/1998366 15:26:04 Federated auth plugins do not work with unversioned auth_url 15:26:16 and there is a review, I'll take a look this week 15:26:28 #action d34dh0r53 review https://review.opendev.org/c/openstack/keystoneauth/+/866189 15:26:48 that does it for keystoneauth 15:26:52 next up is 15:26:55 #link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=0 15:27:12 nothing new for keystonemiddleware 15:27:24 #link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=0 15:27:34 pycadf is clean 15:27:39 and finally we have 15:27:52 #link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=0 15:28:02 which has no new issues 15:28:24 #topic conclusion 15:28:36 anyone have anything they need before we close? 15:29:15 What about this spec https://review.opendev.org/c/openstack/keystone-specs/+/748042? 15:30:46 thanks for bringing that up rafaelweingartn 15:30:57 I will review that this week and bring it up in the reviewathon 15:31:13 #action d34dh0r53 review https://review.opendev.org/c/openstack/keystone-specs/+/748042 15:31:45 AFAIK we've fully moved to alembic but I need to double check that there aren't any lingering dependencies 15:33:00 Anything else? 15:33:35 thanks everyone! 15:33:41 #endmeeting