*** mhen_ is now known as mhen | 03:01 | |
opendevreview | OpenStack Proposal Bot proposed openstack/keystone master: Imported Translations from Zanata https://review.opendev.org/c/openstack/keystone/+/930663 | 04:29 |
---|---|---|
opendevreview | Stanislav Zaprudskiy proposed openstack/keystone-specs master: Include invalid password details in audit messages https://review.opendev.org/c/openstack/keystone-specs/+/915482 | 12:16 |
d34dh0r53 | #startmeeting keystone | 15:00 |
opendevmeet | Meeting started Wed Dec 11 15:00:51 2024 UTC and is due to finish in 60 minutes. The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:00 |
opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:00 |
opendevmeet | The meeting name has been set to 'keystone' | 15:00 |
d34dh0r53 | Reminder: This meeting takes place under the OpenInfra Foundation Code of Conduct | 15:00 |
d34dh0r53 | #link https://openinfra.dev/legal/code-of-conduct | 15:00 |
d34dh0r53 | #topic roll call | 15:01 |
d34dh0r53 | admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m], dmendiza, mharley, jph, gtema, cardoe | 15:01 |
d34dh0r53 | o/ | 15:01 |
xek | o/ | 15:01 |
gtema | o/ | 15:01 |
jph | o/ | 15:01 |
d34dh0r53 | Welcome, let's get started | 15:02 |
d34dh0r53 | #topic review past meeting work items | 15:02 |
d34dh0r53 | #link https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-12-04-15.04.html | 15:02 |
d34dh0r53 | reviewathon look at the Bad Password spec https://review.opendev.org/c/openstack/keystone-specs/+/915482 | 15:02 |
d34dh0r53 | that was the only action item, we reviewed it in the Reviewathon on Friday | 15:03 |
d34dh0r53 | next up | 15:03 |
d34dh0r53 | #topic liaison updates | 15:03 |
d34dh0r53 | nothing from Releases or VMT | 15:04 |
d34dh0r53 | #topic specification OAuth 2.0 (hiromu) | 15:04 |
d34dh0r53 | #link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext | 15:04 |
d34dh0r53 | #link https://review.opendev.org/q/topic:bp%252Fenhance-oauth2-interoperability | 15:04 |
d34dh0r53 | External OAuth 2.0 Specification | 15:04 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone-specs/+/861554 (merged) | 15:04 |
d34dh0r53 | OAuth 2.0 Implementation | 15:04 |
d34dh0r53 | #link https://review.opendev.org/q/topic:bp%252Fsupport-oauth2-mtls | 15:04 |
d34dh0r53 | OAuth 2.0 Documentation | 15:04 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone/+/838108 (merged) | 15:04 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystoneauth/+/838104 (merged) | 15:04 |
d34dh0r53 | no updates from me on this one, hopefully will be able to recheck and rebase on Friday to get the last couple of remaining patches out | 15:05 |
d34dh0r53 | #topic specification Secure RBAC (dmendiza[m]) | 15:05 |
d34dh0r53 | #link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_ | 15:05 |
d34dh0r53 | 2024.1 Release Timeline | 15:05 |
d34dh0r53 | Update oslo.policy in keystone to enforce_new_defaults=True | 15:05 |
d34dh0r53 | Update oslo.policy in keystone to enforce_scope=True | 15:05 |
d34dh0r53 | guess dmendiza isn't around today | 15:07 |
d34dh0r53 | #topic specification OpenAPI support (gtema) | 15:07 |
d34dh0r53 | #link https://review.opendev.org/q/topic:%22openapi%22+project:openstack/keystone | 15:07 |
gtema | I wasn't working on that this week so far, so no changes, but on friday we can review next changes done by students | 15:08 |
d34dh0r53 | ack, thanks gtema (Artem Goncharov) | 15:10 |
d34dh0r53 | #topic specification domain manager (mhen) | 15:10 |
d34dh0r53 | still unmerged are: | 15:10 |
d34dh0r53 | 'v | 15:10 |
d34dh0r53 | documentation: https://review.opendev.org/c/openstack/keystone/+/928135 | 15:10 |
d34dh0r53 | tempest tests: https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/924222 | 15:10 |
d34dh0r53 | Grzegorz Grasza, dmendiza please review the domain manager patches | 15:11 |
dmendiza[m] | 🙋♂️ | 15:11 |
d34dh0r53 | ohai dmendiza | 15:11 |
d34dh0r53 | any S-RBAC updates? | 15:12 |
dmendiza[m] | Negative, no updates this week. 😅 | 15:12 |
d34dh0r53 | ack, thanks | 15:13 |
d34dh0r53 | #topic specification Include bad password details in audit messages (stanislav-z) | 15:13 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone-specs/+/915482 | 15:13 |
d34dh0r53 | #link https://review.opendev.org/c/openstack/keystone/+/932423 | 15:13 |
d34dh0r53 | 11-Dec update: thanks for reviews, I've updated the spec according to comments, or otherwise raised my questions in Gerrit - would appreciate your feedback. | 15:13 |
d34dh0r53 | CI for keystone-spec is failing :/ | 15:13 |
stanislav-z | Hi! Thanks for the review. I updated and responded in Gerrit | 15:14 |
d34dh0r53 | Thanks Stanislav Zaprudskiy ! | 15:14 |
d34dh0r53 | I thought we unblocked the docs gate but I guess not :/ | 15:14 |
stanislav-z | And CI indeed is failing - also the build is failing locally. Would looking into it in a separate patch be a way to fix it? | 15:14 |
gtema | in keystone but not in keystone-specs | 15:15 |
d34dh0r53 | ahh, thanks gtema (Artem Goncharov) | 15:15 |
d34dh0r53 | #topic open discussion | 15:16 |
d34dh0r53 | nothing from me | 15:16 |
stanislav-z | I have a question | 15:17 |
stanislav-z | there are 2 APIs that allow creation of ec2 credentials: | 15:17 |
stanislav-z | 1) https://docs.openstack.org/api-ref/identity/v3/#credentials | 15:17 |
stanislav-z | and 2. https://github.com/openstack/keystone/commit/afd897f9122cdee925376a1c25994a515082963f#diff-c626451fb39f390fb94dcd5e75446540e9dad2df619eec121d57d5284def37e0R434 | 15:17 |
stanislav-z | they both have similar set of functionality - creation of ec2 credentials. I'm wondering, why both are kept? | 15:19 |
stanislav-z | btw, the second - /ec2tokens - is not mentioned in documentation | 15:19 |
gtema | ec2creds are normal creds of the EC2 type | 15:19 |
gtema | there is a separate API (I think for backwards compatibility reasons) | 15:19 |
d34dh0r53 | AFAIK that API has been retired | 15:20 |
stanislav-z | /credentials also allows creation of ec2 credentials - the difference is, that /ec2tokens auto-generates access key/secret, while /credentials requires caller to submit the desired access key/value | 15:21 |
stanislav-z | the follow-up question - why does the /credentials API not auto-generates the values for users? in other words, it allows users to create insecure credentials like admin/password. Just in case someone could know ... | 15:23 |
stanislav-z | * the follow-up question - why does the /credentials API not auto-generate the values for users? in other words, it allows users to create insecure credentials like admin/password. Just in case someone could know ... | 15:23 |
stanislav-z | * the follow-up question - why does the /credentials API not auto-generate the values for users? in other words, it allows users to create insecure credentials like admin/password. Just in case someone could know the historical background | 15:23 |
d34dh0r53 | I have no idea about the history of EC2 in Keystone, we should deprecate it IMHO as no one is able to maintain it and the EC2-API project has been retired. | 15:24 |
stanislav-z | I would image that Swift S3 emulation might use/rely on it. But got your answer, thanks for the clarification | 15:25 |
stanislav-z | s/image/imagine/ | 15:26 |
gtema | Dave Wilde (d34dh0r53): yes, swift and rados GW still rely heavily on the ec2 creds | 15:26 |
gtema | we cant drop it | 15:26 |
d34dh0r53 | ahh, yeah | 15:27 |
d34dh0r53 | that's a bummer | 15:29 |
d34dh0r53 | oh well | 15:29 |
d34dh0r53 | Sorry I can't be of more help with those questions Stanislav Zaprudskiy | 15:30 |
d34dh0r53 | anything else for open discussion? | 15:30 |
d34dh0r53 | cool, moving on | 15:31 |
d34dh0r53 | #topic bug review | 15:31 |
d34dh0r53 | #link https://bugs.launchpad.net/keystone/?orderby=-id&start=0 | 15:31 |
d34dh0r53 | one new bug for keystone | 15:31 |
d34dh0r53 | #link https://bugs.launchpad.net/keystone/+bug/2091317 | 15:31 |
cardoe | That's my bug. | 15:34 |
cardoe | So I got it to work now by setting default_authorization_ttl | 15:35 |
cardoe | So I was going to close it. | 15:35 |
d34dh0r53 | We need to dig into default_authorization_ttl I think | 15:36 |
d34dh0r53 | IIRC there are several bugs surrounding it, or the confusion as to what it actually does | 15:36 |
d34dh0r53 | ok | 15:39 |
d34dh0r53 | that does it for keystone | 15:39 |
d34dh0r53 | #link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=0 | 15:39 |
d34dh0r53 | no new bugs in python-keystoneclient | 15:40 |
d34dh0r53 | #link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=0 | 15:40 |
d34dh0r53 | keystoneauth is good | 15:40 |
d34dh0r53 | #link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=0 | 15:40 |
d34dh0r53 | no new bugs in keystonemiddleware | 15:41 |
d34dh0r53 | #link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=0 | 15:41 |
d34dh0r53 | pycadf is good | 15:41 |
d34dh0r53 | so it ldappool | 15:41 |
d34dh0r53 | #topic conclusion | 15:41 |
d34dh0r53 | nothing else from me, thanks folks! | 15:41 |
d34dh0r53 | #endmeeting | 15:42 |
opendevmeet | Meeting ended Wed Dec 11 15:42:02 2024 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:42 |
opendevmeet | Minutes: https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-12-11-15.00.html | 15:42 |
opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-12-11-15.00.txt | 15:42 |
opendevmeet | Log: https://meetings.opendev.org/meetings/keystone/2024/keystone.2024-12-11-15.00.log.html | 15:42 |
cardoe | d34dh0r53: I was going to ask about doc updates. So the mapping docs don't match up with what the JSON schema requires / enforces. So I wanted to update them. But not sure if that's an area that's gonna change so you're not wanting updates to those docs? | 16:06 |
cardoe | Like https://review.opendev.org/c/openstack/keystone/+/929315 I understand is going to change so that's why no docs merge. | 16:06 |
frickler | d34dh0r53: just a reminder that https://review.opendev.org/c/openstack/releases/+/936261 is still waiting for an update | 17:50 |
-opendevstatus- NOTICE: Gerrit will undergo a short restart to pick up some bugfixes for the 3.10 release that we upgraded to. | 19:25 | |
opendevreview | Oria Weng proposed openstack/keystone master: Add JSON schema and validation for `implied role` https://review.opendev.org/c/openstack/keystone/+/937572 | 22:48 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!