15:05:51 #startmeeting keystone 15:05:51 Meeting started Tue Mar 21 15:05:51 2023 UTC and is due to finish in 60 minutes. The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:05:51 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:05:51 The meeting name has been set to 'keystone' 15:05:57 #topic roll call 15:06:03 admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla[m], lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, arequate, dmendiza[m] 15:06:36 🙋 15:07:02 o/ 15:08:11 o/ 15:08:59 o/ 15:09:13 #topic review past meeting work items 15:09:28 #link https://meetings.opendev.org/meetings/keystone/2023/keystone.2023-03-14-15.02.html 15:09:49 #action d34dh0r53 look into the keystone-groups members as well https://review.opendev.org/admin/groups/d7203dc55fa9bdf98c578b16ac398e0c754a1a67,members not sure if it's used any more 15:10:00 d34dh0r53 investigate https://bugs.launchpad.net/keystone/+bug/2009752 15:10:45 I'm still looking at this, my reproducer environment is unreachable ATM 15:10:48 #action d34dh0r53 investigate https://bugs.launchpad.net/keystone/+bug/2009752 15:11:31 that does it for the past meeting work items 15:11:34 next up we have 15:11:40 #topic liaison updates 15:11:47 nothing from VMT 15:12:45 moving on 15:13:05 #topic specification OAuth 2.0 (hiromu) 15:13:17 #link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext 15:13:20 External OAuth 2.0 Specification 15:13:22 #link https://review.opendev.org/c/openstack/keystone-specs/+/861554 15:13:24 OAuth 2.0 Implementation 15:13:26 #link https://review.opendev.org/q/topic:bp%252Fsupport-oauth2-mtls 15:13:28 OAuth 2.0 Documentation 15:13:30 #link https://review.opendev.org/c/openstack/keystone/+/838108 15:13:32 #link https://review.opendev.org/c/openstack/keystoneauth/+/838104 15:14:03 I sent ML to decide time slot for discussing ext OAuth2.0 server support on vPTG, and I got a reply from Ironic 15:14:09 https://lists.openstack.org/pipermail/openstack-discuss/2023-March/032796.html 15:16:10 I need one slot for this topic, so I'm going to suggest the Keystone's first slot on next Monday. Is this okay for Keystone? 15:16:46 Yes, this is fine for me 15:16:53 Does it work for you knikolla[m] and dmendiza[m] ? 15:17:13 * dmendiza[m] checks PTG calendar 15:18:04 #link https://ptg.opendev.org/ptg.html 15:18:18 Works for me. There's nothing else on MOnday that I need to attend 15:18:24 ack 15:18:37 The date may vary depending on Ironic's reply, please check this thread. 15:19:04 hiromu: I'm watching that thread and will update accordingly 15:19:18 thanks a lot 15:19:46 no problem, anything else? 15:20:13 no, thanks :) 15:20:30 next up 15:20:39 #topic Secure RBAC (dmendiza[m]) 15:20:42 #link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_ 15:20:44 Service Role Implementation 15:20:46 #link https://review.opendev.org/c/openstack/keystone/+/863420 15:20:48 Manager Role Implementation 15:20:50 #link https://review.opendev.org/c/openstack/keystone/+/822601 15:20:51 any updates dmendiza[m] ? 15:21:09 No updates, sorry. I've been focused on downstream things 😅 15:21:15 no worries :) 15:21:21 next up 15:21:29 #topic specification SQLAlchemy 2.0 (stephenfin) 15:21:32 #link https://review.opendev.org/q/topic:sqlalchemy-20+is:open+project:openstack/keystone 15:21:34 Can I get reviews on this, while I have context/time to close it out? 15:21:36 What more do you need from me? 15:22:00 stephenfin: thanks for these, I'll start reviewing this week 15:22:12 no worries (y) 15:22:52 cool, moving to open discussion 15:23:02 #topic open discussion 15:23:14 (mustafakemalgilor) PooledLdapHandler message.clean() patch backports 15:23:33 * dmendiza[m] needs to catch up on reviews 15:23:55 what's the next branch on those backports? 15:24:05 review request 15:24:08 #link ussuri: https://review.opendev.org/c/openstack/keystone/+/874846 15:24:10 #link victoria: https://review.opendev.org/c/openstack/keystone/+/874847 15:24:12 #link wallaby: https://review.opendev.org/c/openstack/keystone/+/874844 15:24:14 #link xena: https://review.opendev.org/c/openstack/keystone/+/874843 15:24:16 #link yoga: https://review.opendev.org/c/openstack/keystone/+/874842 15:24:18 #link zed: https://review.opendev.org/c/openstack/keystone/+/874841 15:24:26 #undo 15:24:26 Removing item from minutes: #link https://review.opendev.org/c/openstack/keystone/+/874841 15:24:26 No train? 15:24:40 I don't see one 15:24:55 Yoga +2/+A 15:25:17 thanks dmendiza[m] 15:25:32 I'll keep an eye out for this to merge and kick the next branch 15:25:40 Going back to the Gerrit group AI 15:25:44 ack, TYS 15:25:45 so we don't have to keep kicking it 15:26:10 next up 15:26:13 (drencrom) We need to merge and backport this patch https://review.opendev.org/c/openstack/keystonemiddleware/+/877808 to fix pep8 tests 15:26:50 dmendiza[m]: mind looking at ^ while you have gerrit open ;) 15:27:03 * dmendiza[m] looks 15:27:39 d34dh0r53: +2/+A'd 15:28:02 thanks dmendiza[m] 15:28:10 any thing else for open discussion> 15:28:12 ? 15:28:30 cool, moving on to 15:28:33 Thanks, I'll do the cherry picks for backports later 15:28:35 Takashi Kajinami proposed openstack/keystone-tempest-plugin master: Replace deprecated tenant_id property https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/878111 15:28:40 thanks drencrom 15:28:52 #topic bug review 15:29:00 #link ussuri: https://review.opendev.org/c/openstack/keystone/+/874846 15:29:06 wait hold up 15:29:07 #undo 15:29:07 Removing item from minutes: #link https://review.opendev.org/c/openstack/keystone/+/874846 15:29:14 #undo 15:29:14 Removing item from minutes: #topic bug review 15:29:14 I wanted to talk about the gerrit groups 15:29:23 sorry, missed the last call there 15:29:29 ahh, no worries dmendiza[m] 15:29:36 * d34dh0r53 hands dmendiza[m] the mic 15:29:38 #link https://paste.opendev.org/show/bnWClSh0CkCnc87qc8aG/ 15:29:43 this is currently what's in project-config 15:30:48 I'm not sure exactly what group you were wanting to check 15:30:49 ? 15:31:22 We could probably do some group linking so that keystone-core is the main group and the others include keystone-core 15:31:31 so we don't have to go update every single group every time keystone-core changes 15:33:20 right, I think we should do that. Do you know if https://review.opendev.org/admin/groups/d7203dc55fa9bdf98c578b16ac398e0c754a1a67,members is used at all? 15:34:23 It's used here: 15:34:25 #link https://opendev.org/openstack/project-config/src/branch/master/gerrit/acls/openstack/keystone.config#L4-L5 15:34:53 pushMerge for "refs/for/refs/*", which my gerrit-fu is not strong enough to decypher 15:34:58 the ref spec looks weird 15:35:13 yeah 15:35:43 and where does keystonemiddleware inherit from? 15:37:54 #link https://opendev.org/openstack/project-config/src/branch/master/gerrit/projects.yaml#L3626-L3630 15:38:15 ack 15:38:23 looks like keystonemiddlware is configured to use keystoneauth 15:38:25 #link https://opendev.org/openstack/project-config/src/branch/master/gerrit/acls/openstack/keystoneauth.config 15:38:56 so it uses keystoneauth-core and keystone-stable-maint, 15:39:15 yep 15:39:46 dmendiza[m]: let's work to get this cleaned up, I think everything should inherit from keystone-core unless there are objections 15:40:06 Sounds good to me. knikolla ? 15:41:45 I've added it as a quick PTG agenda item 15:42:21 thanks dmendiza[m] 15:42:35 anything else for open discussion? 15:42:35 sure 15:42:45 nope, I'm good now, thanks 15:43:04 ++ 15:43:08 #topic bug review 15:43:13 #link https://bugs.launchpad.net/keystone/?orderby=-id&start=0 15:43:20 no new bugs for keystone 15:43:32 #link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=0 15:43:48 python-keystoneclient is clean 15:43:57 #link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=0 15:44:11 nothing new in keystoneauth 15:44:19 #link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=0 15:44:31 nor in keystonemiddleware 15:44:40 #link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=0 15:45:21 pycadf has nothing new 15:45:29 #link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=0 15:45:45 and no new bugs in ldappool 15:45:53 #topic conclusion 15:45:57 PTG is next week 15:46:09 #link https://etherpad.opendev.org/p/bobcat-ptg-keystone 15:46:39 dmendiza[m]: we have a topic on there from last cycle for deprecating python-keystoneclient. Are you still interested in helping/advising with that? 15:47:35 Yeah, sure 15:48:18 tys! 15:48:26 please add agenda items 15:49:12 no weekly meeting next week. We'll talk about the reviewathon in one of our sessions 15:49:18 thanks all! 15:49:32 #endmeeting