yasufum | hi tacker team. | 08:02 |
---|---|---|
manpreetk_ | hi | 08:02 |
ueha | hi | 08:02 |
yu-kinjo | hi | 08:02 |
sairam | hi | 08:02 |
yuta-kazato | hi | 08:02 |
yasufum | #link https://etherpad.opendev.org/p/tacker-meeting | 08:02 |
yasufum | #startmeeting tacker | 08:03 |
opendevmeet | Meeting started Tue May 9 08:03:01 2023 UTC and is due to finish in 60 minutes. The chair is yasufum. Information about MeetBot at http://wiki.debian.org/MeetBot. | 08:03 |
opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 08:03 |
opendevmeet | The meeting name has been set to 'tacker' | 08:03 |
yasufum | #link https://etherpad.opendev.org/p/tacker-meeting | 08:03 |
yasufum | It seems we don't need to have so much time today | 08:04 |
yasufum | looking on the etherpad. | 08:04 |
yasufum | #topic Share the result of proposing OIS forum sessions | 08:05 |
yasufum | It's my item. | 08:05 |
yasufum | Just for sharing our proposals. | 08:05 |
yasufum | Unfortunately, both of them are not on the schedule already fixed. | 08:06 |
yasufum | Anyway, thanks for your items for topics were going to be discussed on https://etherpad.opendev.org/p/tacker-forum-feedback-for-etsi-nfv-usecases. | 08:08 |
yasufum | That's all for the first item. | 08:09 |
yasufum | Any comment, or do you have any other items should be discussed? | 08:10 |
ueha | Thanks for your sharing, I have no comment and other items today. | 08:11 |
yasufum | Nothing? | 08:11 |
yasufum | ueha: ok | 08:12 |
yasufum | good | 08:12 |
yasufum | So, let's close this meeting. | 08:12 |
yasufum | Thank you for joining, bye. | 08:12 |
ueha | thanks, bye | 08:13 |
manpreetk_ | bye! | 08:13 |
takahashi-tsc | bye | 08:13 |
yu-kinjo | bye | 08:13 |
yasufum | #endmeeting | 08:13 |
opendevmeet | Meeting ended Tue May 9 08:13:17 2023 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 08:13 |
opendevmeet | Minutes: https://meetings.opendev.org/meetings/tacker/2023/tacker.2023-05-09-08.03.html | 08:13 |
opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/tacker/2023/tacker.2023-05-09-08.03.txt | 08:13 |
opendevmeet | Log: https://meetings.opendev.org/meetings/tacker/2023/tacker.2023-05-09-08.03.log.html | 08:13 |
w-juso | bye | 08:13 |
yuta-kazato | bye | 08:14 |
dmendiza[m] | 🙋♂️ | 17:01 |
gmann | #startmeeting policy_popup | 17:01 |
opendevmeet | Meeting started Tue May 9 17:01:48 2023 UTC and is due to finish in 60 minutes. The chair is gmann. Information about MeetBot at http://wiki.debian.org/MeetBot. | 17:01 |
opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 17:01 |
opendevmeet | The meeting name has been set to 'policy_popup' | 17:01 |
gmann | dmendiza[m]: hi | 17:01 |
dmendiza[m] | Hi gmann | 17:02 |
gmann | this is today agenda, #link https://etherpad.opendev.org/p/rbac-goal-tracking#L148 | 17:02 |
gmann | dmendiza[m]: hi, how r u | 17:02 |
dmendiza[m] | Good, just trying to get back into the SRBAC happenings | 17:02 |
gmann | great | 17:02 |
gmann | let me go through the agenda and then we can discuss if anything specific you have | 17:03 |
gmann | Updating the RBAC goal timeline for old rule removal considering the SLURP releases | 17:03 |
gmann | I updated it and governance change is merged #link https://review.opendev.org/c/openstack/governance/+/880238 | 17:03 |
gmann | and you might see neutron also switched their new defaults by default | 17:04 |
gmann | #link https://lists.openstack.org/pipermail/openstack-discuss/2023-May/033579.html | 17:04 |
dmendiza[m] | Nice | 17:04 |
gmann | nova, glance already did it in last cycle | 17:04 |
dmendiza[m] | I can get Barbican and Keystone to switch over this cycle too | 17:04 |
gmann | thanks | 17:04 |
gmann | I think we need some work to do in keystone on supporting the project scope for every rule. | 17:05 |
gmann | I will try to push the changes in this week | 17:05 |
dmendiza[m] | That's to s/system-scope/admin-role/g right? | 17:05 |
gmann | that is needed as all services except ironic dropped the system scope | 17:05 |
gmann | yeah, basically allow project scope token to keep accessing the APIs as per their original persona | 17:06 |
dmendiza[m] | > supporting the project scope for every rule | 17:06 |
dmendiza[m] | Will that be a change to Keystone's policies? | 17:06 |
gmann | yes, it will add 'project' in allowed scope but will keep system scope support also | 17:07 |
gmann | I mean just addition of project scope allow and no change in what is allowed currently | 17:07 |
dmendiza[m] | oh gotcha. So, not dropping system, but also allowing "admin" role to do those things. | 17:07 |
gmann | yup | 17:07 |
gmann | I will try to push the change and then it will be more clear, will add you in review | 17:08 |
dmendiza[m] | Thanks, yeah, I'll keep an eye out for that. | 17:08 |
gmann | cool | 17:08 |
dmendiza[m] | I think we need to do something similar in Barbican | 17:08 |
dmendiza[m] | there's a few Barbican APIs that still require system scope | 17:08 |
gmann | dmendiza[m]: but we do not want system scope support in anywhere except ironic and keystone | 17:09 |
dmendiza[m] | gotcha | 17:09 |
dmendiza[m] | OK | 17:09 |
dmendiza[m] | yeah, I'll propose a patch to Barbican to drop system scope | 17:09 |
gmann | octavia also dropped system scope recently which is what our goal is | 17:09 |
gmann | great | 17:09 |
gmann | #action dmendiza[m] to propose change in barbican to drop system scope | 17:10 |
gmann | dmendiza[m]: ^^ just to have it reminder | 17:10 |
gmann | #action gmann to propose keystone change to support project scope | 17:10 |
dmendiza[m] | thanks | 17:10 |
gmann | next is review requests | 17:11 |
gmann | magnum | 17:11 |
gmann | #link https://review.opendev.org/c/openstack/magnum/+/875625 | 17:11 |
gmann | it has one +2 and I also reviewed it +1 since last cycle but not merging | 17:11 |
gmann | I think I need to send it on ML if any other core can merge | 17:11 |
gmann | #action gmann to ask for magnum rbac change review on ML | 17:12 |
gmann | next is keystone | 17:12 |
gmann | Service role #link https://review.opendev.org/c/openstack/keystone/+/863420 | 17:12 |
gmann | dmendiza[m]: I think this is ready ? I also need to review the latest PS | 17:13 |
dmendiza[m] | I'll add it to the next Keystone Reviewathon. | 17:13 |
gmann | cool, thanks | 17:13 |
dmendiza[m] | (which won't be until next week because Red Hat has a holiday on Friday) | 17:13 |
gmann | ohk | 17:14 |
dmendiza[m] | but I'll try to review it before then | 17:14 |
gmann | thanks, really appreciate, they have been open for long | 17:14 |
gmann | manger role #link https://review.opendev.org/c/openstack/keystone/+/822601 | 17:14 |
gmann | this need some changes as per review comment | 17:15 |
gmann | I will try to ping abhishek about it | 17:15 |
dmendiza[m] | Ah yes, I remember this one ... I'll need a refresher though. | 17:15 |
gmann | that is all from agenda today | 17:16 |
gmann | dmendiza[m]: anything else you have to discuss ? | 17:16 |
dmendiza[m] | Nope. I was mainly wondering what the status of "system" scope was | 17:17 |
dmendiza[m] | but we talked about that already | 17:17 |
gmann | ok, yeah we decided to dropped system scope from every project except Ironic and Keystone | 17:17 |
gmann | dmendiza[m]: this is documentation for that and above section on why we need to do it #link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#change-in-scope-implementation | 17:18 |
gmann | I am keeping this goal document up to dated so any time you can refer it | 17:19 |
dmendiza[m] | That's good to know. Thanks for that. 👍️ | 17:19 |
gmann | np! | 17:19 |
gmann | ok, let's close the meeting, | 17:19 |
gmann | thanks dmendiza[m] for joining | 17:19 |
dmendiza[m] | Sounds good, thanks gmann | 17:19 |
gmann | #endmeeting | 17:19 |
opendevmeet | Meeting ended Tue May 9 17:19:55 2023 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 17:19 |
opendevmeet | Minutes: https://meetings.opendev.org/meetings/policy_popup/2023/policy_popup.2023-05-09-17.01.html | 17:19 |
opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/policy_popup/2023/policy_popup.2023-05-09-17.01.txt | 17:19 |
opendevmeet | Log: https://meetings.opendev.org/meetings/policy_popup/2023/policy_popup.2023-05-09-17.01.log.html | 17:19 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!