WG voting seat withdrawal
by Truong Anh Tuan
Hi folks,
I am writing this email to express that I would like to withdraw
my voting seat in Server WG.
Because I have been quite busy recently by day job and also I
would like to give more opportunities to more active people (I
see there are a couple of people just nominated to WG voting
seats) who can push Fedora Server go faster in the future.
I will be still around to contribute to Fedora Server as a
non-voting member.
Thank you all, especially ones who come up with me from the
beginning days of the Server WG.
Good luck and hope to see you again and again :)
Rgds,
Tuan
8 years, 6 months
Joining the Server Working Group
by Jon Stanley
Earlier today, Stephen Gallagher asked me if I'd be interested in
joining the Server WG. I'd love to if y'all will have me (you'd have
to put up with a Cardinals fan, though!)!!! I was very humbled to have
been asked.
The requisite disclaimer is that I am employed by Bank of America, and
all opinions are my own, and not those of my employer :) (you'll never
have to hear that again, promise!).
What makes me a particularly good member of the Server WG (IMHO) is
that I am primarily a consumer of downstream derivatives of Fedora
Server in my professional life. In my personal life, I'm a consumer of
both Fedora and (different) downstream derivatives, and contributor to
Fedora since 2007. I've worn many hats in that time - bug triage,
infrastructure, packaging, etc.
Why do I think that this makes me an ideal candidate for the WG?
Simple - real world experience provisioning, operating, and managing
systems at scale and what that entails. This includes everything from
installing the OS (via Kickstart or other means - rpm-ostree for
example is extremely exciting), as well as thinking about the big
picture and how it all works together - interoperability with legacy
environments as well as innovation into new spaces, for example the
brave new world of microservices, containers, and container
orchestration.
My major goal would be making Fedora the platform of choice for
hosting containers and containerized applications, due to the out of
the box orchestration components that we can deliver and make
seamlessly work without massive amounts of custom configuration
(unless you want to). I see this as something that a RoleKit role
could probably do.
Speaking of which, one of the things that was being worked on in
Rochester was making it easier to add roles to RoleKit. I think that
once the foundational work is completed, we need to start adding roles
with anger, and make them useful to users (and easy to customize if
they aren't).
Another (secondary) goal for the WG would be making Fedora deployable
out of the box into existing network topologies, including those that
might require interacting with proprietary pieces (using obviously all
FOSS software on Fedora!) of infrastructure that already exist in most
enterprise environments, and making that interaction easy and as
painless as possible (AD, I'm looking at you!). Some of this has
already been done, while there might be more integration to go in
other cases.
Thanks for reading this (now I realize entirely too long)
introduction. Look forward to working with everyone!
8 years, 6 months
Joining the server working group
by Major Hayden
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Hello there,
Stephen Gallagher reached out to me earlier today to see if I'd be interested in joining the server working group. I'm really interested in joining (if you'll have me).
I'm not the greatest at writing about myself, but here's what I'm currently doing in the land of Fedora:
* Member of the Fedora Security Team
* Maintainer of several packages
* Author of some Fedora Magazine posts
* Proponent of SELinux, defender of Dan Walsh
* In the process of writing documentation for systemd-networkd for Fedora Cloud images
And I do a few things with Fedora, server-wise:
* Small home lab with 3-4 machines running KVM
* Two servers in a colo running some OpenStack lab stuff
* Running icanhazip.com (and related services) on Fedora
* Running major.io (my blog) on Fedora
* Built a virtualization platform at $dayjob with Fedora
All in all, I have about 10-15 servers running Fedora at one time or another. I'd like to help improve Fedora in any way I can, especially on servers. Some of my ideas are around secure-by-default images and further improvements to make Fedora a preferred platform for the most common web server software packages.
Thanks for your time and consideration. Feel free to email me with any questions! :)
- --
Major Hayden
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
iQIcBAEBCAAGBQJWHUbcAAoJEHNwUeDBAR+xcogP+gJtYqh67iNEPdAO3D+UKtbP
gn6KKy535t13T0a2so7UbABpxHLQyE7NquS/MxhH45ER4dkD+mLSnbTS0uDphdbv
1i/5Iuvz9qFge/No+MEKBpkbnwRrFcCxRRfGs77mYypJuLWuimMYFlMuP+0YF7dE
Sy44CrLl9yiEbxB9vyifx2fzPzlMPpWHtEdoQXX/IGh2RYHo1d9SV+5lI+5RgHjm
kIcaQceSyBVnrqYWp2kLi833Vhbv2gplpDo5hGDghHIu1SjVNFasArxNEjTqK5kx
mf9/hoxkI36HyIlIWaGnL7OF29C2syGYwCRYxWE0IsPKAUzc+o4pYsNksVFzk9Sf
C/9dgsnsGEVXqOHJlf1Ry9TaNGBAyIp5V+RyW2TWsvgmocNPSvJtzM2/G24xmG+9
TCdvqgZ97v1EU3MarA/+MTpi2JZpEjVpQ7QccRXKQG8eIg1YjjENHzJlItscuaTu
NS2Ri9A1tUTqLeuBlZnqNbEb7id4PhQa+qs4SnRj8Vc4cWGethyqN/6XwosgMjIH
LBA6vznJ/K2MRCjBv1l6GrFhnGQLC+P91pWmZMlx7Zc9lj/ULsZsdS9Qcybj3iVY
k0Cq4PqjVdxqIJmaNjRoLmXurL1XJ8y87nuxktpeLlfHCc+1wyT/uB76BEMe9i3c
u5YLEcED5ejT7H6QNyNv
=4XC2
-----END PGP SIGNATURE-----
8 years, 6 months
Server SIG Weekly Meeting Minutes (2015-10-13)
by Stephen Gallagher
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
=========================================================
#fedora-meeting-1: Server SIG Weekly Meeting (2015-10-13)
=========================================================
Meeting started by sgallagh at 15:00:04 UTC. The full logs are available
at
http://meetbot.fedoraproject.org/fedora-meeting-1/2015-10-13/serversig.2
015-10-13-15.00.log.html
.
Meeting summary
- ---------------
* roll call (sgallagh, 15:00:04)
* Agenda (sgallagh, 15:02:33)
* Agenda Item: Empty WG Seat (sgallagh, 15:03:21)
* Agenda Item: Fedora 23 Final Tasks (sgallagh, 15:03:21)
* Agenda Item: Fedora 24 Planning (sgallagh, 15:03:21)
* Empty WG Seat (sgallagh, 15:05:43)
* ACTION: sgallagh to reach out to Major Hayden and Jon Stanley about
vacant Server WG seat. (sgallagh, 15:26:32)
* Fedora 23 Final Tasks (sgallagh, 15:27:06)
* Fedora 23 is in Final Freeze (sgallagh, 15:34:02)
* There was a compose issue related to a bodhi bug causing 389ds to
break dependencies. It will be fixed in TC8. (sgallagh, 15:34:34)
* ACTION: sgallagh to test upgrades of FreeIPA from F22 to F23.
(sgallagh, 15:35:29)
* Fedora 24 Planning (sgallagh, 15:39:19)
* adamw is working on automating the release validation tests for F24
(sgallagh, 15:40:24)
* rolekit will be focusing on support for creating out-of-tree roles
(sgallagh, 15:40:57)
* Reminder: i386 install images are going away in Fedora Server 24.
(sgallagh, 15:42:47)
* General theme for Fedora 24: Closer integration with other editions
(sgallagh, 15:52:08)
* Some ideas for integration: Cockpit getting server lists from
FreeIPA, better support for pgAdmin in Workstation, Better
autodetection of FreeIPA domains in Initial Setup. (sgallagh,
16:04:11)
* Server-Cloud interaction needs some more thought (sgallagh,
16:04:41)
* Open Floor (sgallagh, 16:09:45)
Meeting ended at 16:11:35 UTC.
Action Items
- ------------
* sgallagh to reach out to Major Hayden and Jon Stanley about vacant
Server WG seat.
* sgallagh to test upgrades of FreeIPA from F22 to F23.
Action Items, by person
- -----------------------
* sgallagh
* sgallagh to reach out to Major Hayden and Jon Stanley about vacant
Server WG seat.
* sgallagh to test upgrades of FreeIPA from F22 to F23.
* **UNASSIGNED**
* (none)
People Present (lines said)
- ---------------------------
* sgallagh (112)
* mizmo (29)
* adamw (28)
* nirik (16)
* roshi (12)
* stefw (11)
* simo (11)
* zodbot (10)
* bconoboy (2)
* dgilmore (1)
* danofsatx (0)
* tuanta (0)
Generated by `MeetBot`_ 0.1.4
.. _`MeetBot`: http://wiki.debian.org/MeetBot
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
iEYEARECAAYFAlYdLX4ACgkQeiVVYja6o6ODnwCgp37WOsE2nQBtqbeN2IuteYZf
gpIAoJ7gIzWQ9LLNItbFeRdvyY1969GF
=13if
-----END PGP SIGNATURE-----
8 years, 6 months
Rolekit Weekly Meeting Minutes (2015-10-13)
by Stephen Gallagher
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
====================================
#fedora-server: rolekit (2015-10-13)
====================================
Meeting started by sgallagh at 12:59:59 UTC. The full logs are available
at
http://meetbot.fedoraproject.org/fedora-server/2015-10-13/rolekitweekly.
2015-10-13-12.59.log.html
.
Meeting summary
- ---------------
* init process (sgallagh, 13:00:00)
* Agenda (sgallagh, 13:01:00)
* Agenda Item: Fedora 23 Final Steps (sgallagh, 13:01:24)
* Agenda Item: Fedora 24 Planning (sgallagh, 13:01:33)
* Fedora 23 Final Steps (sgallagh, 13:02:52)
* Fedora 23 entered Final Freeze as of midnight UTC today (sgallagh,
13:03:06)
* ACTION: twoerner and nilsph to test the rolekit-0.4.0.1 package and
provide karma in Bodhi (sgallagh, 13:07:54)
* LINK: http://dl.fedoraproject.org/pub/alt/stage/ (sgallagh,
13:12:09)
* Fedora 24 Planning (sgallagh, 13:19:38)
* ACTION: sgallagh to work on the job-control/progress monitoring
feature (sgallagh, 13:37:28)
* ACTION: twoerner to work on the firewall configuration options
(sgallagh, 13:37:41)
* ACTION: nilsph to work on supporting out-of-tree role creation
(sgallagh, 13:37:52)
* Open Floor (sgallagh, 13:42:24)
* Continuous Integration (sgallagh, 13:44:31)
* ACTION: nilsph to pick the brains of the Cockpit and QA crowd about
CI (sgallagh, 13:50:53)
Meeting ended at 13:56:03 UTC.
Action Items
- ------------
* twoerner and nilsph to test the rolekit-0.4.0.1 package and provide
karma in Bodhi
* sgallagh to work on the job-control/progress monitoring feature
* twoerner to work on the firewall configuration options
* nilsph to work on supporting out-of-tree role creation
* nilsph to pick the brains of the Cockpit and QA crowd about CI
Action Items, by person
- -----------------------
* nilsph
* twoerner and nilsph to test the rolekit-0.4.0.1 package and provide
karma in Bodhi
* nilsph to work on supporting out-of-tree role creation
* nilsph to pick the brains of the Cockpit and QA crowd about CI
* sgallagh
* sgallagh to work on the job-control/progress monitoring feature
* twoerner
* twoerner and nilsph to test the rolekit-0.4.0.1 package and provide
karma in Bodhi
* twoerner to work on the firewall configuration options
* **UNASSIGNED**
* (none)
People Present (lines said)
- ---------------------------
* sgallagh (100)
* nilsph (34)
* twoerner (24)
* zodbot (6)
Generated by `MeetBot`_ 0.1.4
.. _`MeetBot`: http://wiki.debian.org/MeetBot
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
iEYEARECAAYFAlYdDZMACgkQeiVVYja6o6NI4wCfZzd6jDKo37TqGSWHjkdQP2KT
H0cAnAmv4acRDK7S6KsvQqVpwmFKSaAh
=De88
-----END PGP SIGNATURE-----
8 years, 6 months
Proposed new blocking criterion for Fedora Server: GSSAPI SSO via SSH
by Stephen Gallagher
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Currently, we have a number of blocking criterion in Fedora Server
around domain membership that the machine must be able to join a
domain and that a user must be able to log into the machine using
standard login mechanisms (console, GDM, etc.).
What we are lacking is a criterion specifying single-sign-on
functionality, which is a key part of the domain experience. I'd like
to propose that the following functionality be added as a Beta
criterion from here forth:
== Server Product Requirements ==
=== Remote Authentication ===
* A user who signs in locally or via SSH to a Fedora Server joined to
a FreeIPA or Active Directory domain using a supported domain-joining
mechanism[1] must be capable of connecting via SSH to any other Fedora
Server of the same version to which they have appropriate access
privileges without being required to re-enter their password.[2]
(Note: this assumes an "online" login; if the user logs in while
disconnected from the authentication server, they may not be able to
use SSO features without manual intervention.)
* Single-sign-on capabilities must be available without any additional
configuration by the user except the initial join to the domain.
[1] This means realmd in the current implementation, which is the
mechanism used under the hood by Cockpit. I'd recommend leaving out
more manual methods like ipa-client-install, adcli and 'net ads'.
[2] Under the hood, this means that the authentication negotiation
should happen via GSSAPI.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
iEYEARECAAYFAlYSygMACgkQeiVVYja6o6NUMwCgkNjoXxlGB6cyCZC3bkVJ1pNX
+K4AoJn6Yg24djVWofsN5qr9AhGoBdDn
=vY35
-----END PGP SIGNATURE-----
8 years, 6 months
Rolekit Weekly Meeting Minutes (2015-10-06)
by Stephen Gallagher
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
====================================
#fedora-server: rolekit (2015-10-06)
====================================
Meeting started by sgallagh at 13:01:15 UTC. The full logs are available
at
http://meetbot.fedoraproject.org/fedora-server/2015-10-06/rolekitweekly.
2015-10-06-13.01.log.html
.
Meeting summary
- ---------------
* init process (sgallagh, 13:01:16)
* Agenda (sgallagh, 13:04:08)
* Agenda Item: Ticket Triage (sgallagh, 13:04:16)
* https://github.com/libre-server/rolekit/issues/51 - Implement a CI
test framework (sgallagh, 13:07:15)
* AGREED: Continuous Integration/Deployment efforts will be a primary
focus for the Fedora 24 schedule and we will try to collaborate on
this with Fedora QA (+3, 0, -0) (sgallagh, 13:17:46)
* Open Floor (sgallagh, 13:17:57)
* LINK:
https://www.reviewboard.org/docs/rbtools/dev/rbt/commands/post/#controll
ing-guessing-behavior
(sgallagh, 13:43:22)
* LINK: https://github.com/reviewboard/rbtools (sgallagh, 13:55:48)
Meeting ended at 14:01:22 UTC.
Action Items
- ------------
Action Items, by person
- -----------------------
* **UNASSIGNED**
* (none)
People Present (lines said)
- ---------------------------
* sgallagh (94)
* nilsph (52)
* twoerner (27)
* zodbot (7)
Generated by `MeetBot`_ 0.1.4
.. _`MeetBot`: http://wiki.debian.org/MeetBot
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
iEYEARECAAYFAlYT1GcACgkQeiVVYja6o6OfBACgsXUSex7j8rSj65cMfUzXr14S
9u0AoIdJRN3WU9OdeLOf3Ss8rO+aGqmc
=gOoz
-----END PGP SIGNATURE-----
8 years, 6 months
Call for Agenda for Server SIG Weekly Meeting (2015-10-06)
by Stephen Gallagher
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
I don't have any specific agenda items for this week. I'd like to see
a response on the list to the proposed blocking criteria, but that
doesn't require a meeting. We'll cancel unless anyone comes up with an
urgent topic.
Also, please find the time to test Fedora Server 23 TC1. We're about a
week away from Final Freeze and it would be best if we knew about any
show-stoppers early.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
iEYEARECAAYFAlYTy3EACgkQeiVVYja6o6NDbgCfWp6VzJh5tDUGL4bU+R8+Ffty
DgEAmgNli2nB5dGOJfA1+QTsFsUdWkw6
=wPZf
-----END PGP SIGNATURE-----
8 years, 6 months