15:00:29 #startmeeting keystone 15:00:29 Meeting started Wed Aug 30 15:00:29 2023 UTC and is due to finish in 60 minutes. The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:00:29 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:00:29 The meeting name has been set to 'keystone' 15:00:46 #topic roll call 15:00:47 admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla[m], lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m] 15:00:49 o/ 15:01:09 o/ 15:01:36 o/ 15:02:26 #topic review past meeting work items 15:02:43 #link https://meetings.opendev.org/meetings/keystone/2023/keystone.2023-08-23-15.02.html 15:02:59 d34dh0r53 Look into adding/restoring a known issues section to our documentation 15:03:21 no update on any of the docs issues 15:03:26 #action d34dh0r53 Look into adding/restoring a known issues section to our documentation 15:03:44 #action d34dh0r53 add https://bugs.launchpad.net/keystone/+bug/1305950 to the known issues section of our documentation 15:03:54 #action d34dh0r53 look into doc bug of missing Identity section on https://docs.openstack.org/2023.1/projects.html 15:04:26 o/ 15:05:07 reviewathon get https://review.opendev.org/c/openstack/keystone/+/890661 merged 15:05:15 this was merged during the reviewathon, thanks! 15:05:23 reviewathon https://review.opendev.org/c/openstack/keystone/+/891024 15:05:35 We still need to get this one merged 15:05:47 #action reviewathon https://review.opendev.org/c/openstack/keystone/+/891024 15:06:12 and we're going to get to the OAuth 2.0 interoperability this week as hiromu will be able to join 15:06:21 #action reviewathon https://review.opendev.org/q/topic:bp%252Fenhance-oauth2-interoperability 15:06:35 b 15:06:42 that does it for the past meeting action items 15:06:44 next up we have 15:06:52 #topic liaison updates 15:06:56 nothing from VMT 15:07:30 Would be awesome to have this backport to also merge https://review.opendev.org/c/openstack/keystone/+/892864 not sure if it's for reviewathon or not 15:08:48 noonedeadpunk: I just did it, thanks for the reminder 15:09:23 cool, moving on 15:09:33 #topic specification OAuth 2.0 (hiromu) 15:09:42 #link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext 15:09:44 #link https://review.opendev.org/q/topic:bp%252Fenhance-oauth2-interoperability 15:09:46 External OAuth 2.0 Specification 15:09:48 #link https://review.opendev.org/c/openstack/keystone-specs/+/861554 15:09:50 OAuth 2.0 Implementation 15:09:52 #link https://review.opendev.org/q/topic:bp%252Fsupport-oauth2-mtls 15:09:54 OAuth 2.0 Documentation 15:09:56 #link https://review.opendev.org/c/openstack/keystone/+/838108 15:09:58 #link https://review.opendev.org/c/openstack/keystoneauth/+/838104 15:11:19 https://review.opendev.org/c/openstack/keystonemiddleware/+/868734 has been updated 15:12:14 I think the comments we recieved have been solved. I'd appricate if you could check them again. 15:12:26 excellent, thanks hiromu, I'll try to start looking at that today/tomorrow, hopefully others can as well as we'll hit that in the reviewathon on Friday 15:13:10 thanks. yes. let's look the details Friday 15:13:27 🙋 15:14:31 hi dmendiza[m] 15:14:39 speaking of, next up we have 15:14:47 #topic Secure RBAC (dmendiza[m]) 15:14:57 #link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_ 15:14:59 Hi! 15:14:59 Manager Role Implementation 15:15:01 #link https://review.opendev.org/c/openstack/keystone/+/822601 15:15:12 Yeah, so I'm hoping we can lad the manager role before M3 15:15:20 so please hold on on approving the tag until we land it 15:15:48 It's a small enough change, but it does not clean up the role implication data during an upgrade 15:16:09 basically we end up with this mapping with the current patch: 15:16:11 admin ----> manager... (full message at ) 15:16:21 oops, that looks terrible on paste 15:16:41 `admin ----> manager... (full message at ) 15:16:54 yeah, still terrible 15:17:03 last try to paste: 15:17:12 admin ----> manager 15:17:20 \ | 15:17:29 \ |' 15:17:35 ugh, that looks awful too 15:17:45 anyway, we end up with the "admin" role having two mappings 15:17:47 which is wrong 15:17:54 since the previous mapping does not get removed on upgrade 15:17:59 so I'm working on a fix to the patch to do that 15:18:07 the barbican-manage bootstrap command is pretty barebones 15:18:29 and takes a "insert to DB first, ask questions later" approach, which is not ideal 15:19:12 I've also got to check to see if we have any defaults that need to be changed.\ 15:19:50 I promised gmann I would do something else, and as soon as I remember what that is I'l ltry to do that before M3 too. 15:21:40 awesome, thank you for that work dmendiza[m] 15:21:51 the admin dual mapping does seem wrong to me as well 15:23:29 I'll hold off on the M3 approvals for now 15:23:42 next up 15:23:47 #topic open discussion 15:23:58 anyone have anything? there's nothing on the agenda 15:24:04 You get you PTL in? 15:24:11 It's ending super soon 15:24:57 Oh, I see it now 15:24:59 #link https://review.opendev.org/c/openstack/election/+/893179 15:25:05 d34dh0r53: PTLFL!!! 15:25:10 LOL 15:25:36 yes, if y'all will have me :) 15:25:54 I sent out the same thing on the mailing list 15:26:27 Sorry if I missed the time for bugs. Is there any chance someone could take a look at / confirm I'm not missing something for https://bugs.launchpad.net/keystone/+bug/2030061 ? 15:27:11 dmendiza[m], can you look at that one it dovetails into what you're working on 15:28:16 ack, I'll take a look 15:28:21 Thanks :) 15:28:38 np, thanks andrewbonney 15:29:46 moving on 15:29:59 #topic bug review 15:30:09 #link https://bugs.launchpad.net/keystone/?orderby=-id&start=0 15:30:15 we have one new bug in keystone 15:30:30 https://bugs.launchpad.net/keystone/+bug/2032839 15:30:43 looks like the enforcer may not be thread safe 15:32:36 that one will take some replication and digging, any volunteers? 15:35:01 ok 15:35:05 next up we have 15:35:20 #link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=0 15:35:30 no new bugs there 15:35:41 #link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=0 15:35:53 nothing new for keystoneauth 15:35:59 #link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=0 15:36:16 keystonemiddleware is good 15:36:23 #link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=0 15:36:35 pycadf is operating flawlessly 15:36:47 #link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=0 15:37:07 and ldappool is pooling 15:37:13 #topic conclusion 15:37:18 anything before we go? 15:37:37 reviewathon on Friday 15:37:41 thanks everyone! 15:37:45 #endmeeting