Tuesday, 2022-11-22

*** rlandy|rover|biab is now known as rlandy|rover00:33
*** rlandy|rover is now known as rlandy|out01:08
*** tkajinam is now known as Guest216202:04
*** tkajinam is now known as Guest217403:28
*** yadnesh|away is now known as yadnesh04:03
*** ysandeep|out is now known as ysandeep04:49
*** ysandeep is now known as ysandeep|ruck04:49
*** tkajinam is now known as Guest217905:36
*** yadnesh is now known as yadnesh|afk08:20
*** jpena|off is now known as jpena08:22
*** yadnesh|afk is now known as yadnesh08:51
*** jpena is now known as jpena|off08:56
*** jpena|off is now known as jpena08:57
*** dviroel|afk is now known as dviroel11:20
*** rlandy|out is now known as rlandy|rover11:23
*** dviroel_ is now known as dviroel11:38
*** dviroel_ is now known as dviroel12:16
*** dasm|off is now known as dasm13:55
ade_lee__fungi, hey -- so where are we with https://review.opendev.org/c/openstack/project-config/+/861457 ?14:24
ade_lee__frickler, fungi - what do we need to do to move this forward?  14:26
fungiade_lee__: i think frickler wanted to get the tc to decide whether it was acceptable for openstack projects to test upstream with privileged access to resources not all developers would be able to install on their own systems (without buying licenses)14:34
*** frenzy_friday is now known as frenzy_friday|doc14:43
*** blarnath is now known as d34dh0r5314:53
ade_lee__fungi, even if the relevant resource is available for them to use and download locally - and just not get support?14:54
fungiade_lee__: i guess that's one thing we could do... not obfuscate the token as a zuul secret in a config project and instead add it in plaintext directly to a playbook in an untrusted project like openstack-zuul-jobs as a normal ansible variable15:33
funginot sure if that alleviates all of frickler's concerns15:33
ade_lee__fungi, do we have precedent or any other case where we plan to do something similar?15:40
fungiade_lee__: precedent is subjective. for example, openstack already mirrors git refs to github (obviously not open source) using a credential encoded as a zuul secret. openstack tests upstream on some kinds of specialized hardware which not every developer has access to. openstack has test jobs which are simply not feasible to try to run locally on developers' systems... none of those is15:48
fungiexactly the same but they do have similar aspects15:48
fricklerif "the relevant resource is available for them to use and download locally", why do we need that token at all?15:56
fricklerthe feedback from the tc so far was vague and there seemed to be diverging opinions there, too16:00
*** yadnesh is now known as yadnesh|away16:12
fungii think by "relevant resource" he meant the token itself could be downloaded and used (if we switched to a plaintext representation)16:16
fungifrickler: if you are looking for non-vague consensus from the tc, you're really going to have to either put a motion on next week's meeting agenda and hope for sufficient quorum to be able to hold a vote, or propose a resolution to openstack/governance and have the tc members vote through code review16:17
*** dviroel is now known as dviroel|lunch16:19
*** dasm is now known as dasm|off16:23
*** dviroel|lunch is now known as dviroel17:00
*** jpena is now known as jpena|off17:33
*** frenzy_friday|doc is now known as frenzy_friday17:36
fricklerI don't think I'm motivated to drive that. I think the path forward best would be to look for votes/reviews from other config-cores17:48
fungiclarkb: ianw: mnaser: ^ as the other config-core reviewers in this channel, feedback on https://review.opendev.org/861457 "Add an Ubuntu FIPS testing token" is requested17:57
clarkbI think adding the secret is probably fine as it will help us learn more. I do think that if openstack wanted to require the testing with fips on ubuntu or similar then openstack should consider these concerns.18:01
clarkbBasically I don't think the line is at investigating making it working. Its more at applying it everywhere or requiring it18:01
*** dmellado_ is now known as dmellado18:01
*** dmellado_ is now known as dmellado18:04
*** dasm|off is now known as dasm20:31
*** dviroel is now known as dviroel|afk20:37
*** dasm is now known as dasm|off22:25
*** rlandy|rover is now known as rlandy|out23:09

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!