17:01:48 #startmeeting policy_popup 17:01:48 Meeting started Tue May 9 17:01:48 2023 UTC and is due to finish in 60 minutes. The chair is gmann. Information about MeetBot at http://wiki.debian.org/MeetBot. 17:01:48 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 17:01:48 The meeting name has been set to 'policy_popup' 17:01:53 dmendiza[m]: hi 17:02:02 Hi gmann 17:02:11 this is today agenda, #link https://etherpad.opendev.org/p/rbac-goal-tracking#L148 17:02:16 dmendiza[m]: hi, how r u 17:02:37 Good, just trying to get back into the SRBAC happenings 17:02:45 great 17:03:03 let me go through the agenda and then we can discuss if anything specific you have 17:03:05 Updating the RBAC goal timeline for old rule removal considering the SLURP releases 17:03:22 I updated it and governance change is merged #link https://review.opendev.org/c/openstack/governance/+/880238 17:04:00 and you might see neutron also switched their new defaults by default 17:04:19 #link https://lists.openstack.org/pipermail/openstack-discuss/2023-May/033579.html 17:04:30 Nice 17:04:30 nova, glance already did it in last cycle 17:04:44 I can get Barbican and Keystone to switch over this cycle too 17:04:59 thanks 17:05:23 I think we need some work to do in keystone on supporting the project scope for every rule. 17:05:31 I will try to push the changes in this week 17:05:48 That's to s/system-scope/admin-role/g right? 17:05:48 that is needed as all services except ironic dropped the system scope 17:06:19 yeah, basically allow project scope token to keep accessing the APIs as per their original persona 17:06:32 > supporting the project scope for every rule 17:06:43 Will that be a change to Keystone's policies? 17:07:15 yes, it will add 'project' in allowed scope but will keep system scope support also 17:07:39 I mean just addition of project scope allow and no change in what is allowed currently 17:07:42 oh gotcha. So, not dropping system, but also allowing "admin" role to do those things. 17:07:49 yup 17:08:09 I will try to push the change and then it will be more clear, will add you in review 17:08:33 Thanks, yeah, I'll keep an eye out for that. 17:08:41 cool 17:08:41 I think we need to do something similar in Barbican 17:08:51 there's a few Barbican APIs that still require system scope 17:09:16 dmendiza[m]: but we do not want system scope support in anywhere except ironic and keystone 17:09:34 gotcha 17:09:35 OK 17:09:49 yeah, I'll propose a patch to Barbican to drop system scope 17:09:52 octavia also dropped system scope recently which is what our goal is 17:09:57 great 17:10:14 #action dmendiza[m] to propose change in barbican to drop system scope 17:10:20 dmendiza[m]: ^^ just to have it reminder 17:10:34 #action gmann to propose keystone change to support project scope 17:10:43 thanks 17:11:13 next is review requests 17:11:17 magnum 17:11:20 #link https://review.opendev.org/c/openstack/magnum/+/875625 17:11:43 it has one +2 and I also reviewed it +1 since last cycle but not merging 17:11:56 I think I need to send it on ML if any other core can merge 17:12:11 #action gmann to ask for magnum rbac change review on ML 17:12:41 next is keystone 17:12:47 Service role #link https://review.opendev.org/c/openstack/keystone/+/863420 17:13:24 dmendiza[m]: I think this is ready ? I also need to review the latest PS 17:13:44 I'll add it to the next Keystone Reviewathon. 17:13:52 cool, thanks 17:13:55 (which won't be until next week because Red Hat has a holiday on Friday) 17:14:18 ohk 17:14:18 but I'll try to review it before then 17:14:30 thanks, really appreciate, they have been open for long 17:14:54 manger role #link https://review.opendev.org/c/openstack/keystone/+/822601 17:15:04 this need some changes as per review comment 17:15:17 I will try to ping abhishek about it 17:15:33 Ah yes, I remember this one ... I'll need a refresher though. 17:16:41 that is all from agenda today 17:16:48 dmendiza[m]: anything else you have to discuss ? 17:17:09 Nope. I was mainly wondering what the status of "system" scope was 17:17:21 but we talked about that already 17:17:41 ok, yeah we decided to dropped system scope from every project except Ironic and Keystone 17:18:39 dmendiza[m]: this is documentation for that and above section on why we need to do it #link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#change-in-scope-implementation 17:19:10 I am keeping this goal document up to dated so any time you can refer it 17:19:26 That's good to know. Thanks for that. 👍️ 17:19:32 np! 17:19:40 ok, let's close the meeting, 17:19:46 thanks dmendiza[m] for joining 17:19:52 Sounds good, thanks gmann 17:19:55 #endmeeting