15:03:26 #startmeeting keystone 15:03:26 Meeting started Tue Feb 14 15:03:26 2023 UTC and is due to finish in 60 minutes. The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:03:26 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:03:26 The meeting name has been set to 'keystone' 15:03:36 #topic roll call 15:03:52 ping admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla[m], lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, arequate 15:05:13 o/ 15:05:19 o/ 15:05:27 o/ 15:05:45 o/ 15:06:04 #topic review past meeting work items 15:06:29 #link https://meetings.opendev.org/meetings/keystone/2023/keystone.2023-01-31-15.01.html 15:06:45 the only thing is this: d34dh0r53 look into the keystone-groups members as well https://review.opendev.org/admin/groups/d7203dc55fa9bdf98c578b16ac398e0c754a1a67,members not sure if it's used any more 15:06:58 I started this but more work to be done so I'll carry it over 15:07:04 #action d34dh0r53 look into the keystone-groups members as well https://review.opendev.org/admin/groups/d7203dc55fa9bdf98c578b16ac398e0c754a1a67,members not sure if it's used any more 15:07:19 #topic liaison updates 15:07:23 nothing from VMT 15:09:06 release management is working on the release of Antelope, the deadline is Feb. 17 for the Antelope-3 milestone 15:09:30 as always please let me know if you'd like to volunteer for a liaison position 15:09:46 moving on 15:10:11 #topic specification OAuth 2.0 (hiromu) 15:10:22 #link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext 15:10:25 External OAuth 2.0 Specification 15:10:27 #link https://review.opendev.org/c/openstack/keystone-specs/+/861554 15:10:29 OAuth 2.0 Implementation 15:10:31 #link https://review.opendev.org/q/topic:bp%252Fsupport-oauth2-mtls 15:10:33 OAuth 2.0 Documentation 15:10:35 #link https://review.opendev.org/c/openstack/keystone/+/838108 15:10:37 #link https://review.opendev.org/c/openstack/keystoneauth/+/838104 15:10:43 It's not directly related to OAuth2.0, I submitted patch to keystonemiddleware https://review.opendev.org/c/openstack/keystonemiddleware/+/873382 15:11:02 The OAuth2.0 patch for keystone middleware depends on the above patch 15:11:25 Please kindly merge it, if you have time. 15:12:20 Also, the all comments for the OAuth2.0 patches are resolved. 15:13:02 I hope we can merge them within this feature freeze week. 15:14:00 ack, hopefully we can do it during the reviewathon, dmendiza will be back :) 15:14:19 anything else hiromu ? 15:14:43 good! nothing else 15:15:08 ok, thank you! 15:15:13 next up is: 15:15:35 #topic specification Secure RBAC (dmendiza[m]) 15:15:46 #link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_ 15:15:49 Service Role Implementation 15:15:51 #link https://review.opendev.org/c/openstack/keystone/+/863420 15:15:53 Manager Role Implementation 15:15:55 #link https://review.opendev.org/c/openstack/keystone/+/822601 15:16:06 anyone need any S-RBAC things? 15:17:46 ok, moving on 15:17:59 #topic open discussion 15:18:13 first item is from last week but it still hasn't merged 15:18:24 (drencrom) Need a workflow +1 for this cherry pick https://review.opendev.org/c/openstack/keystonemiddleware/+/871993 15:18:27 I need to port it all the way to ussuri 15:18:37 #link https://review.opendev.org/c/openstack/keystonemiddleware/+/871993 15:18:59 please review if you have a minute 15:19:15 next up we have: 15:19:24 PooledLdapHandler MaxConnectionReachedError bug 15:19:27 #link https://bugs.launchpad.net/keystone/+bug/1998789 15:19:29 Review request 15:19:31 #link https://review.opendev.org/c/openstack/keystone/+/866723 15:20:20 need one more core review on that one ^ 15:21:03 next up: 15:21:05 (arequate) keycloakauth plugin for OAuth 2.0 Device Authorization Grant 15:21:08 Review request 15:21:10 #link https://review.opendev.org/c/openstack/keystoneauth/+/869876 15:23:13 that will need some testing, and a better commit message 15:23:50 that's all on the agenda for open discussion, anyone have anything else before we move to bug review? 15:24:19 hi 15:24:33 hi kpdev 15:24:49 can we consider bug for discussion 15:24:56 https://bugs.launchpad.net/cinder/+bug/2006631 15:25:14 if anyone from keystone might have tried this configuration before and experienced similar issue 15:25:35 I have not yet 15:26:56 d34dh0r53: ok, 15:27:16 I started looking at it again yesterday and will try to reproduce this afternoon 15:27:42 thanks 15:27:51 no problem, what timezone are you in BTW? 15:27:54 lets discuss on bug then 15:27:56 CEST 15:28:18 kpdev: ack, thanks :) 15:29:03 #topic bug review 15:29:10 #link https://bugs.launchpad.net/keystone/?orderby=-id&start=0 15:29:46 the only new keystone bug is #link https://bugs.launchpad.net/keystone/+bug/2006631 15:30:04 that's the one we just discussed that I am going to look at this afternoon 15:30:18 next up we have: 15:30:20 #link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=0 15:30:32 no new bugs there 15:30:48 #link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=0 15:31:20 no new bugs in keystoneauth 15:31:32 #link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=0 15:31:47 nothing new in keystonemiddleware 15:32:06 #link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=0 15:32:09 pycadf is clean 15:32:14 and finally: 15:32:23 #link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=0 15:32:36 which is also clean 15:32:43 that does it for bug review 15:32:50 #topic conclusion 15:32:56 anyone have anything else? 15:33:54 Please try to make the reviewathon if you can on Friday. We're done with Antelope and it would be nice to see if we can get OAuth 2.0 patches merged. 15:34:50 I'll send out a link to the meeting here on Friday (09:00 CDT, 15:00 UTC) 15:35:47 or if you would like to be added to the calendar invite please let me know 15:35:53 Thanks folks! 15:35:56 #endmeeting