*** mhen_ is now known as mhen | 01:26 | |
opendevreview | Douglas Mendizábal proposed openstack/keystone master: Run Secure RBAC tests as project-admin https://review.opendev.org/c/openstack/keystone/+/913999 | 01:58 |
---|---|---|
opendevreview | Douglas Mendizábal proposed openstack/keystone master: Allow admin to access tokens and credentials https://review.opendev.org/c/openstack/keystone/+/914520 | 01:59 |
opendevreview | Douglas Mendizábal proposed openstack/keystone master: Enable protection jobs https://review.opendev.org/c/openstack/keystone/+/909238 | 02:04 |
opendevreview | Douglas Mendizábal proposed openstack/keystone-tempest-plugin master: Update tests for admin role in credentials https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/914934 | 02:17 |
opendevreview | Douglas Mendizábal proposed openstack/keystone-tempest-plugin master: DNM: test keystone change https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/914089 | 02:22 |
opendevreview | Douglas Mendizábal proposed openstack/keystone master: Enable protection jobs https://review.opendev.org/c/openstack/keystone/+/909238 | 04:18 |
opendevreview | Douglas Mendizábal proposed openstack/keystone-tempest-plugin master: Update tests for admin role in credentials https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/914934 | 04:23 |
crohmann | xek: Could you maybe give https://review.opendev.org/c/openstack/keystone/+/885463 another look. You gave it a +2 before and I really believe this kind of inconsistency should be fixed (and backported) before the Caracal release! | 06:20 |
crohmann | I also pushed a backport to 2024.1 now https://review.opendev.org/c/openstack/keystone/+/914939 | 06:29 |
opendevreview | Merged openstack/keystone-tempest-plugin master: Fix domain-scope tests for list_domains https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/914558 | 08:19 |
opendevreview | Merged openstack/keystone master: Run Secure RBAC tests as project-admin https://review.opendev.org/c/openstack/keystone/+/913999 | 09:17 |
*** whoami-rajat_ is now known as whoami-rajat | 14:47 | |
opendevreview | Merged openstack/keystone master: Allow admin to access tokens and credentials https://review.opendev.org/c/openstack/keystone/+/914520 | 14:59 |
*** blarnath is now known as d34dh0r53 | 15:00 | |
d34dh0r53 | @startmeeting keystone | 15:00 |
d34dh0r53 | #startmeeting keystone | 15:01 |
opendevmeet | Meeting started Wed Apr 3 15:01:00 2024 UTC and is due to finish in 60 minutes. The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:01 |
opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:01 |
opendevmeet | The meeting name has been set to 'keystone' | 15:01 |
d34dh0r53 | bruh | 15:01 |
d34dh0r53 | #topic roll call | 15:01 |
d34dh0r53 | admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla[m], lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m], mharley, jph, gtema | 15:01 |
d34dh0r53 | o/ | 15:01 |
gtema | o/ | 15:01 |
dmendiza[m] | 🙋♂️(ish) | 15:02 |
xek | o/ | 15:03 |
d34dh0r53 | hi all! | 15:03 |
d34dh0r53 | #topic review past meeting work items | 15:03 |
d34dh0r53 | #link https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-03-27-15.02.html | 15:04 |
d34dh0r53 | no updates from me and I had the only action items, push them to next week | 15:04 |
d34dh0r53 | I should have time to work on them this Friday | 15:04 |
d34dh0r53 | #action d34dh0r53 Look into adding/restoring a known issues section to our documentation | 15:05 |
d34dh0r53 | #action d34dh0r53 add https://bugs.launchpad.net/keystone/+bug/1305950 to the known issues section of our documentation | 15:05 |
d34dh0r53 | #topic liaison updates | 15:05 |
d34dh0r53 | nothing from me | 15:05 |
d34dh0r53 | #topic specification OAuth 2.0 (hiromu) | 15:11 |
d34dh0r53 | #link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext | 15:11 |
d34dh0r53 | #link https://review.opendev.org/q/topic:bp%252Fenhance-oauth2-interoperability | 15:11 |
d34dh0r53 | External OAuth 2.0 Specification | 15:11 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone-specs/+/861554 | 15:11 |
d34dh0r53 | OAuth 2.0 Implementation | 15:11 |
d34dh0r53 | #link https://review.opendev.org/q/topic:bp%252Fsupport-oauth2-mtls | 15:12 |
d34dh0r53 | OAuth 2.0 Documentation | 15:12 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone/+/838108 | 15:12 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystoneauth/+/838104 | 15:12 |
d34dh0r53 | doesn't look like hiromu is around, hopefully we'll see them at the PTG | 15:13 |
d34dh0r53 | #topic Secure RBAC (dmendiza[m]) | 15:13 |
d34dh0r53 | #link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_ | 15:14 |
d34dh0r53 | 2024.1 Release Timeline | 15:14 |
d34dh0r53 | Update oslo.policy in keystone to enforce_new_defaults=True | 15:14 |
d34dh0r53 | Update oslo.policy in keystone to enforce_scope=True | 15:14 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone/+/902730 (Merged) | 15:14 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/903713 (Merged) | 15:14 |
d34dh0r53 | #link ttps://review.opendev.org/c/openstack/tempest/+/912489 | 15:14 |
dmendiza[m] | Lots of patches up for y | 15:14 |
dmendiza[m] | Review | 15:15 |
dmendiza[m] | I don't have the links on hand though | 15:15 |
dmendiza[m] | 😅 | 15:15 |
d34dh0r53 | no worries, I think xek and I have reviewed most of them | 15:16 |
d34dh0r53 | cool, next up | 15:17 |
d34dh0r53 | #topic Improve federated users management (gtema) | 15:18 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone-specs/+/748748 - waiting for reviews | 15:18 |
gtema | as stated - still waiting for spec reviews | 15:18 |
gtema | but to remind - I really do not want to screw mapping API more then it is already now | 15:18 |
d34dh0r53 | yeah, I see there is a -1 on it right now which is keeping it off my radar but I can read through it again to refresh my memory and vote | 15:19 |
gtema | yes pls, since spec author tend to ignore my review | 15:19 |
d34dh0r53 | ack | 15:19 |
d34dh0r53 | #topic specification OpenAPI support (gtema) | 15:20 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone-specs/+/910584 | 15:20 |
gtema | my job situation changed and I have now no confidence on my ability to implement this spec in time (or at all) | 15:20 |
gtema | I think I need 2-3 weeks to sort things out | 15:21 |
d34dh0r53 | I was reading this over, and while I really like it I think this should be proposed to the TC as a community goal | 15:21 |
gtema | right, it is submitted to the TC PTG | 15:21 |
d34dh0r53 | oh cool | 15:22 |
d34dh0r53 | #topic open discussion | 15:23 |
d34dh0r53 | passlib update | 15:23 |
d34dh0r53 | The maintainer responded to the bug, and one of the top priorities is to fix the bcrypt version bug | 15:23 |
d34dh0r53 | #link https://foss.heptapod.net/python-libs/passlib/-/issues/190 | 15:23 |
d34dh0r53 | Targeted to 1.7.5 | 15:23 |
d34dh0r53 | I asked today what the status of 1.7.5 is, he said it would be a week ago and we haven't heard anything | 15:23 |
d34dh0r53 | hopefully soon | 15:23 |
d34dh0r53 | anything else for open discussion? | 15:24 |
gtema | not from my side | 15:24 |
d34dh0r53 | cool | 15:24 |
d34dh0r53 | #topic bug review | 15:25 |
d34dh0r53 | #link https://bugs.launchpad.net/keystone/?orderby=-id&start=0 | 15:25 |
d34dh0r53 | looks like a new bug with a fix already proposed | 15:26 |
d34dh0r53 | #link https://bugs.launchpad.net/keystone/+bug/2059780 | 15:26 |
d34dh0r53 | dmendiza[m]: mind looking at that review to see if it's included in some of your fixes? | 15:27 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone/+/914759 | 15:27 |
d34dh0r53 | #link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=0 | 15:27 |
d34dh0r53 | nothing new for python-keystoneclient | 15:27 |
d34dh0r53 | #link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=0 | 15:27 |
d34dh0r53 | keystoneauth is good | 15:28 |
d34dh0r53 | #link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=0 | 15:28 |
d34dh0r53 | keystonemiddleware is also good | 15:28 |
d34dh0r53 | #link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=0 | 15:28 |
d34dh0r53 | pycadf is clean | 15:28 |
d34dh0r53 | #link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=0 | 15:28 |
d34dh0r53 | as is ldappool | 15:28 |
d34dh0r53 | that does it for bug review | 15:29 |
d34dh0r53 | #topic conclusion | 15:29 |
d34dh0r53 | PTG is next week | 15:29 |
d34dh0r53 | Keystone rooms are scheduled, but let me know if you need different times | 15:29 |
d34dh0r53 | also, please add to the agenda | 15:29 |
d34dh0r53 | #link https://etherpad.opendev.org/p/dalmation-ptg-keystone | 15:29 |
d34dh0r53 | Thanks everyone! | 15:30 |
d34dh0r53 | #endmeeting | 15:30 |
opendevmeet | Meeting ended Wed Apr 3 15:30:03 2024 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:30 |
opendevmeet | Minutes: https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-04-03-15.01.html | 15:30 |
opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-04-03-15.01.txt | 15:30 |
opendevmeet | Log: https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-04-03-15.01.log.html | 15:30 |
*** ganso_ is now known as ganso | 16:55 | |
*** vishalmanchanda_ is now known as vishalmanchanda | 16:55 | |
*** gmann_ is now known as gmann | 16:55 | |
opendevreview | Douglas Mendizábal proposed openstack/keystone-tempest-plugin master: Update tests for admin role in credentials https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/914934 | 18:50 |
opendevreview | Douglas Mendizábal proposed openstack/keystone-tempest-plugin master: DNM: test keystone change https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/914089 | 18:50 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!