Wednesday, 2024-09-04

*** mhen_ is now known as mhen01:39
*** __ministry is now known as Guest241902:21
opendevreviewOpenStack Proposal Bot proposed openstack/keystone master: Imported Translations from Zanata  https://review.opendev.org/c/openstack/keystone/+/92446003:28
*** __ministry is now known as Guest243907:13
*** whoami-rajat_ is now known as whoami-rajat14:00
d34dh0r53#startmeeting keystone15:02
opendevmeetMeeting started Wed Sep  4 15:02:12 2024 UTC and is due to finish in 60 minutes.  The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot.15:02
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:02
opendevmeetThe meeting name has been set to 'keystone'15:02
xeko/15:02
d34dh0r53#topic roll call15:02
d34dh0r53admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m], mharley, jph, gtema15:02
mheno/15:02
d34dh0r53o/15:03
mharley[m]o/15:03
d34dh0r53#topic review past meeting work items15:04
d34dh0r53#link https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-08-28-15.04.html15:05
d34dh0r53just one, for dmendiza 15:05
d34dh0r53dmendiza clean up the SRBAC Specification section of the weekly meeting etherpad15:05
dmendiza[m]I did not do that 😅15:06
gtemaSorry, I am on a business trip, so not really here15:06
d34dh0r53no worries dmendiza or gtema (Artem Goncharov) 15:08
d34dh0r53I'll re-add the action item15:08
d34dh0r53#action dmendiza clean up the SRBAC Specification section of the weekly meeting etherpad15:09
d34dh0r53#topic liaison updates15:09
d34dh0r53nothing from VMT15:09
d34dh0r53we're in feature freeze for dalmatian so bug fixes only15:09
d34dh0r53that's it for liaison updates15:09
d34dh0r53#topic specification OAuth 2.0 (hiromu)15:11
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext15:11
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Fenhance-oauth2-interoperability15:11
d34dh0r53External OAuth 2.0 Specification15:11
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-specs/+/861554 (merged)15:11
d34dh0r53OAuth 2.0 Implementation15:11
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Fsupport-oauth2-mtls15:11
d34dh0r53OAuth 2.0 Documentation15:11
d34dh0r53#link https://review.opendev.org/c/openstack/keystone/+/838108 (merged)15:12
d34dh0r53#link https://review.opendev.org/c/openstack/keystoneauth/+/838104 (merged)15:12
d34dh0r53next up15:12
d34dh0r53no updates15:12
d34dh0r53#topic specification Secure RBAC (dmendiza[m])15:12
d34dh0r53#link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_15:12
d34dh0r532024.1 Release Timeline15:12
d34dh0r53Update oslo.policy in keystone to enforce_new_defaults=True15:12
d34dh0r53Update oslo.policy in keystone to enforce_scope=True15:12
d34dh0r53#link https://review.opendev.org/c/openstack/keystone/+/902730 (Merged)15:12
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/903713 (Merged)15:12
d34dh0r53#link https://review.opendev.org/c/openstack/tempest/+/912489 (Merged)15:13
d34dh0r53next up15:15
d34dh0r53#topic specification OpenAPI support (gtema)15:16
d34dh0r53#link https://review.opendev.org/q/topic:%22openapi%22+project:openstack/keystone15:16
d34dh0r53gtema: changes awaiting review15:16
d34dh0r53I'll try to review these, had a couple of fires to put out last week15:16
gtema👍15:17
d34dh0r53next up15:18
d34dh0r53#topic specification domain manager (mhen)15:18
d34dh0r53#link https://review.opendev.org/q/topic:%22domain-manager%2215:18
d34dh0r53keystone patchset adjusted according to Douglas' review, keystone-tempest-plugin aligned accordingly15:18
mhenthat is an old note15:18
mhenI replaced it but was too late ig15:19
d34dh0r53oops15:19
d34dh0r53tempest and keystone-tempest-plugin patchsets not merged yet15:19
mhenI've been wondering: how do the tempest tests relate to the release?15:19
d34dh0r53were you able to get anyone from the QE team to review?15:20
mhendo we have a deadline here as well?15:20
dmendiza[m]No, tests for a feature that has already merged don't need to be held up by the FFE15:21
dmendiza[m]*Feature Freeze (no E)15:21
mhenokay good15:21
mhenI haven't been able to reach out yet because I was busy with other stuff and haven't really figured out yet how or where to reach to exactly15:22
d34dh0r53I would do a ping in #openstack-qa asking for help with reviews on your tempest patch, once that is merged we can get the keystone-tempest-plugin one merged15:24
mhend34dh0r53: alright, will do that, thanks for the hint about the IRC channel15:24
d34dh0r53👍️ and you're welcome15:26
d34dh0r53#topic open discussion15:26
d34dh0r53I don't have anything15:26
mhensmall thing maybe15:28
d34dh0r53#topic bug review15:28
d34dh0r53#undo15:28
opendevmeetRemoving item from minutes: #topic bug review15:28
d34dh0r53go ahead mhen 15:28
mhenwould it be beneficial to have a guide on how to use the domain manager persona? e.g. how to create domain managers as an admin and as a domain manager how to manage resources in a domain?15:30
mhenif so, where would be the best place for this?15:30
d34dh0r53I think it would be very helpful, as for the best place I'm not sure, dmendiza might know for sure15:31
d34dh0r53maybe in the user guide15:32
d34dh0r53#link https://docs.openstack.org/keystone/2024.1/user/15:32
d34dh0r53or here #link https://docs.openstack.org/operations-guide/ops-projects-users.html15:33
d34dh0r53That's probably a better place for it, it's more operational than user facing15:33
d34dh0r53or here #link https://docs.openstack.org/keystone/2024.1/admin/service-api-protection.html#domain-personas15:34
mhenI think the last one would not be intuitive if I were to put myself into a users/operators shoes and looking for documentation15:35
dmendiza[m]managers are users though, 15:35
dmendiza[m]so the user guide makes the most sense to me15:36
mhenThe last one is more like an overview of the very basics of main roles; plus it is already updated by the domain manager patchset15:36
dmendiza[m]option 2 would also make sense15:37
d34dh0r53Yeah, I'm really not sure, so I'm fine with any of the three15:39
mhenstrictly speaking, I think appointing domain managers as an admin would be part of 2 and usage of the domain manager persona by appointed users would be part of 115:39
d34dh0r53Yeah, and the documentation of what they are in 3?15:40
mhenwe already have 3 at home :)15:40
mhenit was part of the keystone patchset that we merged15:40
mhenif I'm not mistaken15:40
mhenhttps://review.opendev.org/c/openstack/keystone/+/924132/11/doc/source/admin/service-api-protection.rst15:41
d34dh0r53I'm looking at the old release :/15:42
d34dh0r53Sorry for the confusion, yeah it's there15:43
mhenno worries :)15:44
d34dh0r53cool15:46
d34dh0r53ok, moving on15:46
d34dh0r53#topic bug review15:46
d34dh0r53#link https://bugs.launchpad.net/keystone/?orderby=-id&start=015:46
d34dh0r53no new bugs for keystone15:46
d34dh0r53#link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=015:46
d34dh0r53python-keystoneclient is good15:46
d34dh0r53#link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=015:46
d34dh0r53keystoneauth has a new bug that is in progress15:47
d34dh0r53#link https://bugs.launchpad.net/keystoneauth/+bug/207843715:47
d34dh0r53There's a patch up here #link https://review.opendev.org/c/openstack/keystoneauth/+/92758115:48
d34dh0r53#link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=015:48
d34dh0r53no new bugs for keystonemiddleware15:48
d34dh0r53#link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=015:48
d34dh0r53pycadf is good15:48
d34dh0r53#link https://bugs.launchpad.net/ldappool/+bugs?ordterby=-id&start=015:48
d34dh0r53ldappool is also good15:49
d34dh0r53#topic conclusion15:49
d34dh0r53Nothing else from me, thanks all!15:49
d34dh0r53#endmeeting15:50
opendevmeetMeeting ended Wed Sep  4 15:50:10 2024 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:50
opendevmeetMinutes:        https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-09-04-15.02.html15:50
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-09-04-15.02.txt15:50
opendevmeetLog:            https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-09-04-15.02.log.html15:50

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!