Monday, 2020-09-21

*** brinzhang has joined #openstack-oslo00:33
*** redrobot has quit IRC01:08
*** zaneb has quit IRC02:03
*** zaneb has joined #openstack-oslo02:04
*** hberaud has quit IRC02:34
*** dave-mccowan has quit IRC03:23
*** zzzeek has quit IRC04:15
*** zzzeek has joined #openstack-oslo04:17
*** rcernin has quit IRC04:31
*** rcernin has joined #openstack-oslo04:40
*** rcernin has quit IRC05:39
*** sboyron has joined #openstack-oslo05:45
*** sboyron has quit IRC05:46
*** sboyron has joined #openstack-oslo05:48
*** rcernin has joined #openstack-oslo06:01
*** rcernin has quit IRC06:20
*** ralonsoh has joined #openstack-oslo06:24
*** tosky has joined #openstack-oslo07:03
*** hberaud has joined #openstack-oslo07:32
*** rcernin has joined #openstack-oslo07:39
*** rcernin has quit IRC07:52
*** moguimar has joined #openstack-oslo09:30
*** raildo has joined #openstack-oslo10:36
*** vishakha has joined #openstack-oslo12:10
*** kgiusti has joined #openstack-oslo12:33
*** dave-mccowan has joined #openstack-oslo12:35
*** Luzi has joined #openstack-oslo12:55
*** lbragstad has joined #openstack-oslo13:16
*** Luzi has quit IRC13:54
*** hemna has quit IRC14:30
*** hemna has joined #openstack-oslo14:30
openstackgerritMerged openstack/oslo.utils master: Add function to encapsule md5 for FIPS systems  https://review.opendev.org/75003114:41
*** hberaud has quit IRC14:47
*** hberaud has joined #openstack-oslo14:48
bnemec#startmeeting oslo15:00
bnemecCourtesy ping for bnemec, smcginnis, moguimar, johnsom, stephenfin, bcafarel, kgiusti, jungleboyj15:00
bnemec#link https://wiki.openstack.org/wiki/Meetings/Oslo#Agenda_for_Next_Meeting15:00
openstackMeeting started Mon Sep 21 15:00:35 2020 UTC and is due to finish in 60 minutes.  The chair is bnemec. Information about MeetBot at http://wiki.debian.org/MeetBot.15:00
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:00
*** openstack changes topic to " (Meeting topic: oslo)"15:00
openstackThe meeting name has been set to 'oslo'15:00
hberaudo/15:00
moguimaro/15:00
smcginniso/15:00
kgiustio/15:00
johnsomo/15:01
bnemec#topic Red flags for/from liaisons15:03
*** openstack changes topic to "Red flags for/from liaisons (Meeting topic: oslo)"15:03
moguimarnone from Barbican15:03
smcginnisI don't see Jay yet - none from Cinder that I'm aware of.15:04
bnemecHopefully everything is quiet. I don't think we released anything last week.15:04
smcginnisHopefully it will be quiet for a few weeks yet.15:04
hberaud:)15:04
johnsomNothing from Octavia15:05
* bnemec crosses fingers15:05
bnemec#topic Releases15:06
*** openstack changes topic to "Releases (Meeting topic: oslo)"15:06
bnemecAs I mentioned, not much going on here either.15:06
bnemecIf all goes well we won't have to release victoria between now and when it ships.15:06
bnemec#topic Action items from last meeting15:07
*** openstack changes topic to "Action items from last meeting (Meeting topic: oslo)"15:07
bnemec"bnemec send ptg planning email"15:08
bnemecDone15:08
bnemec"backport https://review.opendev.org/#/c/719876/"15:08
bnemecAlso done15:08
bnemec"Switch oslo.utils to wallaby test template"15:08
bnemecI believe smcginnis took care of that. Thanks!15:08
bnemecThat's it for action items.15:09
bnemec#topic PTG/Forum Planning15:09
*** openstack changes topic to "PTG/Forum Planning (Meeting topic: oslo)"15:09
bnemec#link https://etherpad.opendev.org/p/oslo-wallaby-topics15:09
smcginnisbnemec: We should have that template updated now every time we branch.15:10
bnemecJust a reminder that the etherpad is out there. If there's anything we should discuss "face-to-face" then please add it to the list.15:10
bnemecsmcginnis: Yeah, IIRC you said it didn't happen this time because we didn't get the victoria one merged in time.15:10
smcginnisAh, right!15:11
bnemecWhich was because of a legitimate breakage, so hopefully not a regular occurrence. :-)15:11
smcginnis(fingers crossed)15:11
bnemecOn the etherpad there's already a retrospective topic, so please fill that in with any thoughts you have on how the cycle went.15:13
bnemecAt some point we should probably discuss whether we want to do a project update too.15:13
bnemecHowever, that kind of leads me into the next topic...15:14
bnemec#topic  PTL election season15:14
*** openstack changes topic to "PTL election season (Meeting topic: oslo)"15:14
bnemecOnce again, I don't intend to continue as PTL.15:14
bnemecEspecially as of late, my non-OpenStack responsibilities have been sucking up a lot of time. That situation will probably get worse as time goes on.15:15
bnemecI'm still not planning to disappear completely or anything, but it would be good to have someone leading Oslo that is a little more in touch with what's going on.15:15
bnemecSo, if you're interested in the position, start preparing your nomination email now. :-)15:16
bnemec#topic Weekly Wayward Review15:18
*** openstack changes topic to "Weekly Wayward Review (Meeting topic: oslo)"15:18
bnemec#link https://review.opendev.org/#/c/725938/15:18
bnemechberaud: This is one of yours. I left a few comments that would be nice to address before merging.15:19
hberaudbnemec: ack I'll take a look, thanks15:19
bnemecParticularly the copyright and option name one.15:20
hberaudack15:20
bnemechberaud: Thanks, I'll WIP it for now.15:20
hberaudok15:20
hberaud#link https://review.opendev.org/#/c/746723/15:20
hberaudif some of you could take a look to this one too ^^^15:21
moguimarI added myself to the reviewers15:21
bnemecCrud, I never came back to that, did I?15:21
hberaudbnemec: yes15:22
*** redrobot has joined #openstack-oslo15:23
openstackgerritHervĂ© Beraud proposed openstack/oslo.config master: Allow HostAddressOpt to accept undercore - RFC1033  https://review.opendev.org/74672315:24
bnemecOkay, I'll take a look at that when we're done here.15:24
hberaudthanks15:24
bnemec#topic Open discussion15:25
*** openstack changes topic to "Open discussion (Meeting topic: oslo)"15:25
bnemecThat's it for the agenda. Anything else to discuss this week?15:26
moguimarwe need tributes to review pre-commit patches15:26
moguimarhttps://review.opendev.org/#/q/topic:oslo-pre-commit+(status:open+OR+status:merged)15:26
moguimarmy inbox is full of those, and more than half of them are ready to go15:26
moguimarthanks for the hard work there hberaud o/15:27
hberaudthanks, my pleasure15:27
hberaudI need to re-take a look to some of these15:28
hberaudwhose in failure15:28
bnemec#action merge pre-commit patches15:28
moguimarall -2 are gone15:28
moguimarso it means that all have been updated to our last proposal of pre-commits15:29
hberauds/whose/those/15:29
moguimarso now we just need to please the gate god15:29
* hberaud start to slaughter a chicken15:29
bnemecThis is the second time in a week that someone has offered chickens to the ci gods. :-)15:30
moguimarxD15:30
hberaudpoor chickens15:30
bnemecFair warning: I don't think it worked last time. :-P15:30
hberaudyou broke my dreams15:31
moguimaryou should sacrifice an empty floppy disk15:31
hberaudmy laptop even doesn't have CDROM reader15:31
moguimarif it doesn't work, a floppy disk that hasn't been backed up yet15:32
bnemeclol15:32
hberaudlol15:32
bnemecFloppies were such a terrible storage medium.15:32
moguimarI used to cross my fingers everytime I was copying something out of them15:33
moguimarback to the PC15:33
hberaudhahaha15:33
moguimarI was like 12-ish15:34
hberaud:)15:34
moguimarlast milenium15:34
JayFI have a bit of a question, if open discussion is extra-open now :D. o/ for those who don't know me, I've worked on Ironic for a while and manage it at Verizon Media.15:34
bnemeco/ JayF15:35
hberaudJayF: o/15:35
moguimaro/15:35
JayFI was going to file an RFE about getting support for SAN-name checking in the ssl socket wrapper in oslo.service -- primary use case: requiring client certificates with specific SAN names for clients connecting to the Ironic Python Agent (which uses oslo.service wsgi server)15:35
JayFJust curious if that held  any general interest for you all, or if anyone is likely to vehemently oppose it. Barring any objections, I'd expect to put up an RFE soon and work on it sometime soon (think weeks, not days).15:36
moguimarwhat happens right now if you try a SAN-name?15:36
hberaudseems a good things15:36
JayFSAN name is just a field in a client cert15:37
JayFtoday; oslo.service supports ensuring that cert is signed by a specific CA15:37
JayFbut there's no way to say "signed by the CA, and SAN is 'my-trusted-server.example.com'"15:37
moguimarI see15:38
moguimarsounds ok15:38
moguimarcount me in for reviews15:38
*** vishakha has quit IRC15:39
hberaud+115:39
JayFThanks! Like I said, no promise on timeline -- but it's something I wanted to ensure there was general interest in upstream, and will do that code here. All part of a project to enhance TLS server support in IPA.15:39
bnemecI will admit I don't entirely understand what you gain from checking that, but I'm no security expert so I wouldn't block it if there's a need.15:39
JayFSo let me give you a concrete example: we have a corporate-wide certificate issuing system15:40
JayFcurrently, we have IPA checking that it has any-valid-cert from that system15:40
JayFinstead, we want to limit it to any-valid-cert /that an Ironic Conductor would hold/15:40
JayFit's essentially imparting some authorization logic on what's primarily used for only authentication today15:40
JayFIPA's API is generally minimally or unauthenticated, so adding this is a helpful security addition; especially for deployers who are not using dedicated provisioning/cleaning networks in Ironic to isolate nodes when the agent is running.15:41
bnemecAh, I think I see. It's the combination of the cert being valid and the name being correct, not one or the other.15:41
bnemecYou couldn't spoof an invalid SAN because you wouldn't have access to the cert issuing system.15:42
JayFExactly.15:42
hberaudI don't think it can hurt15:42
JayFI suspect the use case for it, with IPA at least, is minimal, but I could see other users of oslo.service seeing a benefit15:42
bnemecYeah, that sounds totally reasonable to add.15:42
JayFand frankly, it's just nicer to contribute stuff like that upstream so I don't have to hold a patched library forever :D15:43
hberaud:)15:43
bnemec+100015:43
bnemecWe don't want people to feel the need to have downstream forks of stuff.15:44
bnemecSounds like we're all in agreement on this.15:44
bnemecAnything else before we call it a meeting?15:44
hberaudnope15:45
JayFThanks! I'll be sure to link the relevant story (you all use storyboard, I presume?) and code as it gets written in here for review. And feel free to ping if you ever have an Ironic question :)15:46
bnemecJayF: We don't use storyboard. We're still on launchpad.15:46
JayFack, I can do that15:46
bnemecI'd probably advocate for just a wishlist bug, unless there ends up being significant design needed.15:47
JayFthat's what my plan was, this should be straightforward enough to not need a spec, at least by ironic standards15:48
bnemecAgreed.15:48
bnemecOkay, looks like we're done.15:50
bnemecThanks for joining, everyone!15:50
hberaudbnemec: Thans15:50
bnemec#endmeeting15:50
*** openstack changes topic to "OpenStack Common Libraries | https://wiki.openstack.org/wiki/Oslo"15:50
openstackMeeting ended Mon Sep 21 15:50:44 2020 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:50
openstackMinutes:        http://eavesdrop.openstack.org/meetings/oslo/2020/oslo.2020-09-21-15.00.html15:50
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/oslo/2020/oslo.2020-09-21-15.00.txt15:50
openstackLog:            http://eavesdrop.openstack.org/meetings/oslo/2020/oslo.2020-09-21-15.00.log.html15:50
hberauds/thans/thanks15:50
*** ralonsoh has quit IRC15:57
*** moguimar has quit IRC17:18
*** dtantsur is now known as dtantsur|afk17:31
*** hamalq has joined #openstack-oslo17:57
*** sboyron has quit IRC18:42
*** dave-mccowan has quit IRC21:58
*** dave-mccowan has joined #openstack-oslo22:01
*** Dmitrii-Sh has quit IRC22:05
*** Dmitrii-Sh has joined #openstack-oslo22:10
*** Dmitrii-Sh has quit IRC22:48
*** tosky has quit IRC22:49
*** Dmitrii-Sh has joined #openstack-oslo22:55
*** rcernin has joined #openstack-oslo23:02
*** zzzeek has quit IRC23:10
*** rcernin has quit IRC23:11
*** rcernin has joined #openstack-oslo23:11
*** zzzeek has joined #openstack-oslo23:13
*** zzzeek has quit IRC23:17
*** zzzeek has joined #openstack-oslo23:20

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!