Wednesday, 2024-08-07

*** ministry is now known as __ministry00:54
*** mhen_ is now known as mhen01:45
opendevreviewDouglas Mendizábal proposed openstack/keystone master: Add keystone-manage reset_last_active command  https://review.opendev.org/c/openstack/keystone/+/92489202:46
opendevreviewTakashi Kajinami proposed openstack/keystone master: Remove templated catalog driver  https://review.opendev.org/c/openstack/keystone/+/91792310:39
MikeCTZAI upgraded our openstack a few weeks back (from Yoga to Zed to Antelope) using Kolla-Ansible, since then I've not had keystone tokens working nicely (I see errors in the logs), anyone here familiar with that, I've tried all sorts like recreating the fernet-tokens but nothing has helped. I'm not sure if it's causing the error I'm seeing in horizon when viewing my hypervisors (suspect so)12:03
gtemaIn situations like that you should eliminate all side factors. I mean here if you want to check - check keystone and not use horizon12:05
MikeCTZAon my 1 node I have keystone working perfectly fine, on the others I am getting "exception.TokenNotFound(e) keystone.exception.TokenNotFound: Could not recognize Fernet token" type errors12:08
MikeCTZAagreed that horizon is just feeling at a knock on (I suspect)12:08
MikeCTZAI've checked and the tokens which I believe are whats in play here in /var/lib/docker/volumes/keystone_fernet_tokens/_data are the same on all 3 nodes12:09
MikeCTZAthis all started when we had out upgrade fail due to a network disconnect, but we think we recovered OK and reran the upgrade, a few other small mistakes were made thereafter but I think we're OK - VMs and the cloud is working as expected (mostly)12:11
MikeCTZAI shut down keystone on the 2 "bad" nodes, I still cant do the admin (project), admin, compute, hypervisors (I get this Error: Unable to retrieve providers information. 'MEMORY_MB') ... I'm wonder, possibly I should ask in main openstack channel as could be something not keystone, although I do have errors with that12:13
*** tkajinam is now known as Guest241512:52
*** tkajinam is now known as Guest241613:00
*** ministry is now known as __ministry13:55
*** whoami-rajat_ is now known as whoami-rajat13:56
mnaserMikeCTZA: try flushing memcache out14:46
tafkamaxI am looking at the docs for users: https://docs.openstack.org/keystone/2024.1/admin/cli-manage-projects-users-and-roles.html14:59
tafkamaxI found that some examples have 'user' and some have 'username'14:59
tafkamaxIn my DB there is no username entry. Is it still relevant or a deprecated thing?14:59
tafkamaxI am asking this because of skyline 'Real Name' value that would Firstname Lastname15:00
tafkamax* that would be Firstname Lastname15:00
d34dh0r53#startmeeting keystone15:03
opendevmeetMeeting started Wed Aug  7 15:03:17 2024 UTC and is due to finish in 60 minutes.  The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot.15:03
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:03
opendevmeetThe meeting name has been set to 'keystone'15:03
d34dh0r53#topic roll call15:03
d34dh0r53admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla[m], lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m], mharley, jph, gtema15:03
gtemao/15:03
d34dh0r53o/15:03
mharley[m]o/15:03
jpho/15:04
dmendiza[m]🙋‍♂️15:06
d34dh0r53sorry, was grabbing coffee15:08
d34dh0r53#topic review past meeting work items15:08
d34dh0r53#link https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-07-24-15.00.html15:08
d34dh0r53first up15:08
d34dh0r53reviewathon look at https://review.opendev.org/c/openstack/keystone/+/92413215:09
d34dh0r53We spoke about this one on Friday, dmendiza was going to do some testing to ensure that the roles were working correctly15:09
dmendiza[m]Yeah, I did a first-pass review and left some comments.  Looks like it'15:10
dmendiza[m]s been updated so I'll look again this week.15:10
d34dh0r53awesome, thanks dmendiza 15:11
d34dh0r53I'll re-add it to the actions items for the reviewathon15:11
d34dh0r53#action reviewathon look at https://review.opendev.org/c/openstack/keystone/+/92413215:11
d34dh0r53next up15:11
d34dh0r53reviewathon https://review.opendev.org/c/openstack/keystone/+/923067 and https://review.opendev.org/c/openstack/keystone/+/92332415:12
d34dh0r53We talked about these as well, I think they're ready for review now that the codebase has been reformatted15:13
gtemayupp, correct15:13
d34dh0r53sweet15:14
d34dh0r53thanks gtema (Artem Goncharov) 15:14
d34dh0r53I'll review those today15:14
d34dh0r53That does it for the past meeting work items15:15
d34dh0r53#topic liaison updates15:15
d34dh0r53nothing from VMT15:15
d34dh0r53we're coming up on dalmation-3 near the end of the month15:16
d34dh0r53other than that I've got nothing15:16
d34dh0r53moving on15:16
d34dh0r53#topic specification OAuth 2.0 (hiromu)15:16
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext... (full message at <https://matrix.org/_matrix/media/v3/download/matrix.org/ABBUvkDlfXLRJEgqLawTZbEN>)15:17
d34dh0r53no updates from me15:17
d34dh0r53next up15:17
d34dh0r53#topic specification Secure RBAC (dmendiza[m])15:18
d34dh0r53#link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_... (full message at <https://matrix.org/_matrix/media/v3/download/matrix.org/wUsSZyvccxRMDwapARTwQYLL>)15:18
dmendiza[m]No updates other than reviewing domain-manager15:20
d34dh0r53ack, thanks dmendiza 15:20
d34dh0r53#topic specification OpenAPI support (gtema)15:21
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-specs/+/910584 (merged)15:21
d34dh0r53#link https://review.opendev.org/q/topic:%22openapi%22+project:openstack/keystone15:21
d34dh0r53gtema: changes awaiting review15:21
gtemanothing else then reviewing ;-)15:21
d34dh0r53ack, thanks gtema (Artem Goncharov) 15:21
d34dh0r53next up15:22
d34dh0r53#topic specification domain manager (mhen)15:22
d34dh0r53#link https://review.opendev.org/q/topic:%22domain-manager%22... (full message at <https://matrix.org/_matrix/media/v3/download/matrix.org/ZYtGtQuOofpGnjLvLjCnzwOy>)15:22
gtemalong names should not be a problem with reformatted code (at least with the black in the game)15:23
gtemabut still we may want to shorten them15:23
gtemawrt release notes I will explain to mhen offline (I have a shorter link to him)15:24
d34dh0r53ack, thank you15:24
d34dh0r53moving on to open discussion15:25
mharley[m]But Python has no limit for variables names. Is it just because of legibility / aesthetics that Black is recommending reducing them?15:26
gtemamharley - not the black on it's own. There is "OpenStack" guide with the limit15:27
mharley[m]Hmm, gotcha.15:27
gtemawrt renovation: there is py312 fix change ready for review15:27
gtemaand the one I mentioned on the etherpad in pycadf15:27
gtemathose 2 are fixing pretty much all sort of unittesting locally failing with py31215:28
d34dh0r53codebase renovation (gtema)... (full message at <https://matrix.org/_matrix/media/v3/download/matrix.org/koTieTclPIBbnzusrWvbMQuu>)15:28
gtemaright, those 215:28
jphHave an issue with SAML integration with Keystone when using Chrome. I have managed to resolve it locally with `SetEnv MELLON_DISABLE_SAMESITE 1` in `/etc/apache2/mods-enabled/auth_mellon.conf` I will open a bug report but wondered if anyone else has encountered this in Zed onwards?15:30
d34dh0r53jph: we don't use SAML so I'm not much help.15:32
d34dh0r53jph: is this for the open discussion section of the meeting?15:32
jphYeah for open discussion.15:33
d34dh0r53unless anyone here uses SAML I would file a bug report15:34
jphSure I don't think SAML gets all that much use. Will open bug report only just found temporary solution. Thanks.15:35
d34dh0r53jph: thank you!15:36
d34dh0r53next up15:36
d34dh0r53deprecate EC2 and S3 code in keystone, keystoneauth, and keystone middleware (d34dh0r53)15:36
d34dh0r53the top level ec2-api project has been retired, there are some security issues in the code we have floating around our codebase.15:36
d34dh0r53ec2-api has been retired upstream, any objections to me deprecating the keystone code?15:36
gtemait depends15:37
gtemaI know for sure there are some places where people use ec2 credentials to access ceph (rados gw)15:37
d34dh0r53specifically S315:37
gtemaso people create ec2 creds and use them to access rgw in S3 style15:38
d34dh0r53Does that still work?15:38
gtemayes, sadly15:38
gtemabecause it is not OpenStack itself15:38
jphYeah it does just deployed it yesterday.15:38
gtemabut ceph has integration with keystone and that works15:39
gtemabasically ec2 creds are just a "proxy" to regular credentials15:39
jrosseryou still need an ec2 style credential to use the s3 api15:39
gtemajust with a specific type15:39
d34dh0r53Ok, I think that means we're going to need to update the code as our SAST tooling has found some issues in those functions. But if it's still in use...it's still in use :)15:42
d34dh0r53next up15:42
d34dh0r53SAML issue with Google Chrome due to SAMESITE cookies (jph)15:42
d34dh0r53Will open bug report with findings15:42
d34dh0r53jph: thanks for this15:42
gtemain the renovation there is still one more interesting change: adding mypy15:42
gtemain the long run I think it would be very useful15:43
d34dh0r53do you have a link to the review handy gtema (Artem Goncharov) ?15:43
gtemahttps://review.opendev.org/c/openstack/keystone/+/92408515:43
d34dh0r53#action reviewathon https://review.opendev.org/c/openstack/keystone/+/92408515:44
d34dh0r53thanks gtema (Artem Goncharov) 15:44
d34dh0r53moving on to bug review15:44
d34dh0r53#topic bug review15:44
d34dh0r53#link https://bugs.launchpad.net/keystone/?orderby=-id&start=015:44
d34dh0r53looks like three new bugs15:45
d34dh0r53#link https://bugs.launchpad.net/keystone/+bug/207534915:45
d34dh0r53Jadon is working on this and has a patch up, reviews appreciated15:45
gtemait is a sort of doc/deployment bug and not the code15:46
gtemaah no, sorry, wrong bug15:46
d34dh0r53#link https://bugs.launchpad.net/keystone/+bug/207572315:46
d34dh0r53yeah, this looks like a doc bug15:46
gtemarevoke no - it is the thing I mentioned15:46
d34dh0r53oops, yeah15:47
d34dh0r53finally15:48
d34dh0r53#link https://bugs.launchpad.net/keystone/+bug/207404515:48
d34dh0r53dineshk: it would be awesome if you can take this15:49
d34dh0r53That doc definitely needs some TLC15:50
gtemawrt this15:50
gtemaI have already a change updating setup guide15:50
d34dh0r53ack, maybe you can add that bug to the commit message15:51
gtemabug was created afterwards15:51
gtemaso not technically correct, but ok, will do so15:51
gtema#link https://review.opendev.org/c/openstack/keystone/+/92501015:51
d34dh0r53yeah, slightly out of order15:52
d34dh0r53thanks gtema (Artem Goncharov) 15:52
d34dh0r53next up15:52
d34dh0r53#link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=015:52
d34dh0r53nothing new for python-keystoneclient15:52
d34dh0r53#link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=015:52
opendevreviewArtem Goncharov proposed openstack/keystone master: Update development setup doc  https://review.opendev.org/c/openstack/keystone/+/92501015:52
d34dh0r53nor keystoneauth15:53
d34dh0r53#link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=015:53
d34dh0r53keystonemiddleware is good15:53
d34dh0r53#link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=015:53
d34dh0r53pycadf is good as well15:53
d34dh0r53#link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=015:53
d34dh0r53no new bugs for ldappool15:54
d34dh0r53#topic conclusion15:54
d34dh0r53I don't have anything, reviewaton on Friday15:54
d34dh0r53*reviewathon15:54
d34dh0r53Thanks all!15:54
d34dh0r53#endmeeting15:54
opendevmeetMeeting ended Wed Aug  7 15:54:53 2024 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:54
opendevmeetMinutes:        https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-08-07-15.03.html15:54
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-08-07-15.03.txt15:54
opendevmeetLog:            https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-08-07-15.03.log.html15:54
gtemathks everybody15:55
opendevreviewMerged openstack/keystone master: Add keystone-manage reset_last_active command  https://review.opendev.org/c/openstack/keystone/+/92489216:36
*** ministry is now known as __ministry20:06

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!