Wednesday, 2024-06-05

*** mhen_ is now known as mhen01:54
bbobrovo/?15:02
gtemalol15:03
xekWe have an internal meeting that's running late15:07
d34dh0r53sorry15:08
d34dh0r53#startmeeting keystone15:08
opendevmeetMeeting started Wed Jun  5 15:08:09 2024 UTC and is due to finish in 60 minutes.  The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot.15:08
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:08
opendevmeetThe meeting name has been set to 'keystone'15:08
d34dh0r53#topic roll call15:08
d34dh0r53admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla[m], lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m], mharley, jph, gtema15:08
xeko/15:08
d34dh0r53apologies for the late start, internal meeting ran over15:09
gtemao/15:09
d34dh0r53#topic review past meeting work items15:10
d34dh0r53#link https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-05-29-15.02.html15:10
d34dh0r53No action items from the last meeting, so we'll move on15:10
d34dh0r53#topic liaison updates15:11
d34dh0r53no updates from VMT or Releases15:11
d34dh0r53#topic specification OAuth 2.0 (hiromu)... (full message at <https://matrix.org/_matrix/media/v3/download/matrix.org/fvtpEMahbekNLRCfgoxzSTWG>)15:11
d34dh0r53I need to get to rebasing the remaining patches to see if we can finish this up15:12
d34dh0r53next up15:12
d34dh0r53#topic specification Secure RBAC (dmendiza[m])... (full message at <https://matrix.org/_matrix/media/v3/download/matrix.org/uWeAyJusTMVCvAcmLqLAwxNC>)15:13
d34dh0r53dmendiza: are you around? I didn't see you in the roll call15:13
dmendiza[m]🙋‍♂️15:14
d34dh0r53guess not, moving on15:15
d34dh0r53#topic specification Improve federated users management (gtema) 15:16
d34dh0r53#link https://review.opendev.org/c/openstack/keystone/+/92089215:16
d34dh0r53ready for review15:16
gtemawait15:16
gtemadoes somebody remember what is the state with SRBAC and Heat - there was something15:16
dmendiza[m]gtema (Artem Goncharov): Yeah, there is some workflow in Heat where they send Keystone a domain-scoped token15:17
dmendiza[m]policy for that specific API did not allow domain-scoped requests, so the request failed15:17
gtemasomebody is working on the fix?15:18
d34dh0r53I'll give this a review this week, thanks gtema (Artem Goncharov) 15:19
dmendiza[m]The policy was fixed in this patch: 15:19
d34dh0r53next up15:19
dmendiza[m]#link https://opendev.org/openstack/keystone/commit/dd785ee692118a56ea0e3aaaf7f5bd6c73ea9c9115:19
d34dh0r53#topic specification OpenAPI support (gtema)15:19
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-specs/+/91058415:19
d34dh0r53gtema: waiting for reviews15:19
dmendiza[m]gtema (Artem Goncharov) ☝️15:19
gtemafeels like a heavy un-sync between my element and Dave's 15:19
dmendiza[m]gtema (Artem Goncharov): 💯15:20
gtemathks dmendiza15:20
dmendiza[m]gtema (Artem Goncharov): pinging Dave Wilde (d34dh0r53) on a different channel15:20
d34dh0r53I just found out I'm not seeing any of your messages, going to restart my client, BRB15:21
bbobrov(just use irc, duh)15:21
gtemanope - that's the problem: IRC bridge15:21
d34dh0r53testing?15:21
bbobrovd34dh0r53: passed15:21
dmendiza[m]Dave Wilde (d34dh0r53): pong15:22
opendevreviewArtem Goncharov proposed openstack/keystone master: Improve configuration of out-of-tree identity drivers  https://review.opendev.org/c/openstack/keystone/+/92089215:22
d34dh0r53hah, wow, really sorry about that15:22
d34dh0r53I had an element update waiting for me and I'll bet it had expired my keys15:22
gtemaDave Wilde (d34dh0r53): just pushed pep God's fix for the improving out-of-tree driver config (misread email that test failed before)15:23
gtemathe change itself is not big, added lots of comments and therefore it looks bigger then it is15:23
d34dh0r53ok, cool15:23
gtemastruggled (as usual) convincing all the singletons my test is fine - it's a nightmare15:24
gtemaanyway - the change is ready for review and no race in tests should be added with the latest patchset15:24
gtematested explicitly with serial=115:24
gtemawrt openapi: waiting for the spec to land15:25
d34dh0r53ack15:26
d34dh0r53dmendiza: any srbac updates?15:26
dmendiza[m]Only the link I shared earlier that allows domain-scoped tokens to /v3/domains15:27
dmendiza[m]it was backported back to antelope15:27
d34dh0r53ack15:27
bbobrov(the one that i wanted reverted i guess)15:29
d34dh0r53No, I think it was a different one bbobrov 15:30
bbobrovhttps://review.opendev.org/q/I8ee50efc3b4850060cce840fc904bae17f1503a9 ?15:31
d34dh0r53Yeah15:32
bbobrovyes, it is the one15:32
bbobrovi don't know. I managed to work around this in our cloud, so i am not broken any more. But i still think that this change breaks API stability and should not have been merged like that.15:33
dmendiza[m]Yeah, IIRC, your disagreement was about the filtering, not necessarily the policy?15:34
bbobrovyes, it was about the filtering, but filtering got backported too15:34
bbobrovi am not broken with the change. I know a company that will get broken with this. Maybe they will come with a bugreport later.15:35
d34dh0r53Sorry, was looking for your comment, and I just found it, I thought it was a -115:40
bbobrovyeah, i should have put a -115:42
d34dh0r53I would argue that the previous behavior was a bug and this fixes it, but my gut feeling is that 'domain' means different things to different people.  Let's see if a bug is filed.15:42
d34dh0r53I think the only spec we haven't visited yet is15:43
d34dh0r53#topic specification OpenAPI support (gtema)15:43
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-specs/+/91058415:43
d34dh0r53gtema: waiting for reviews15:43
d34dh0r53Grzegorz Grasza: 15:44
d34dh0r53can you take a look at that one?15:44
d34dh0r53moving on15:46
d34dh0r53#topic open discussion15:46
d34dh0r53passlib update... (full message at <https://matrix.org/_matrix/media/v3/download/matrix.org/enFOUAKlodnKOxTDbwCwmyOA>)15:47
d34dh0r53no update, I need to propose a patch to pin upper-constraints15:47
d34dh0r53next up15:47
d34dh0r53domain manager (mhen)... (full message at <https://matrix.org/_matrix/media/v3/download/matrix.org/ttlvUIIdMfZZgFLPrzPZbnRG>)15:47
d34dh0r53dmendiza or Grzegorz Grasza can y'all please take a look at this one?15:48
gtemayes, pls pls pls15:49
bbobrovthere is also this - https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/90054515:49
bbobrovwhich was blocked for me (thanks!) and which should not be blocked any more15:49
d34dh0r53ack, I'll unblock that one15:52
d34dh0r53thanks bbobrov 15:52
d34dh0r53domain list scoping fix (mhen)... (full message at <https://matrix.org/_matrix/media/v3/download/matrix.org/kgigdMYKyYbaZFuKdYDXyewK>)15:52
d34dh0r53next up15:52
d34dh0r53We just talked about that15:53
d34dh0r53finally in open discussion we have15:53
d34dh0r53Enforcing scope in keystone breaks heat (and probably magnum) (tkajinam)... (full message at <https://matrix.org/_matrix/media/v3/download/matrix.org/GTlTzihMFAAlDTiTFGJHvjTl>)15:53
dmendiza[m]I think this is just about the test, not the patch15:53
dmendiza[m]oh whoops, a second too late haha15:54
d34dh0r53no worries dmendiza we can go back ^Z ^Z15:54
dmendiza[m]Yeah, I want to say the only question we had was whether to merge that patch to tempest-plugin with the test for that endpoint15:58
dmendiza[m]IIRC, the test that is there now only tests on the domain for the user making the request and that patch has a cross-domain test ...15:58
dmendiza[m]I don't have a preference either way15:58
d34dh0r53I think we should merge 900545 then16:00
d34dh0r53and I think the only two remaining on the last point are whether or not https://review.opendev.org/c/openstack/keystone/+/916707 needs backports and https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/919405 needs reviews from dmendiza and Grzegorz Grasza.16:01
d34dh0r53Let's quickly go through bug review16:01
d34dh0r53#topic bug review16:01
d34dh0r53#link https://bugs.launchpad.net/keystone/?orderby=-id&start=016:01
d34dh0r53no new bugs for keystone16:02
d34dh0r53#link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=016:02
d34dh0r53python-keystoneclient is good16:02
d34dh0r53#link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=016:03
d34dh0r53nothing new in keystoneauth16:03
d34dh0r53#link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=016:03
d34dh0r53keystonemiddleware is also good16:03
d34dh0r53#link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=016:03
d34dh0r53no new bugs in pycadf16:03
d34dh0r53#link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=016:04
d34dh0r53and ldappool is also clean16:04
d34dh0r53#topic conclusion16:04
d34dh0r53nothing from me, thanks all, apologies for the late start and missing messages :/16:04
d34dh0r53#endmeeting16:04
opendevmeetMeeting ended Wed Jun  5 16:04:52 2024 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)16:04
opendevmeetMinutes:        https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-06-05-15.08.html16:04
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-06-05-15.08.txt16:04
opendevmeetLog:            https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-06-05-15.08.log.html16:04
bbobrovi would like to point out an issue with element: the minutes are a little broken with it - https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-05-15-15.01.html16:12
bbobrovall the #link commands end up in the text messages on matrix.org16:12
dmendiza[m]bbobrov: not sure I understand the issue? 🤔 The plaintext log looks fine to me: https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-06-05-15.08.log.txt 16:21
dmendiza[m]the pretty log looks fine too: https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-06-05-15.08.log.html16:21
dmendiza[m]bbobrov: Is there something missing from the meeting summary that you were expecting? 🤔16:22
bbobrovdmendiza[m]: the summary does not look nice: https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-06-05-15.08.html and there are those matrix.org links in the logs that one has to click a lot16:49
d34dh0r53bbobrov: thanks for pointing that out, I see what you're saying18:25
d34dh0r53I believe it's the way I'm copy/pasting18:26
*** dasm is now known as Guest871620:46

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!