Attending 

  • Chris Hyzer, Penn, Chair
  • Vivek Sachdiva, independent  
  • Chad Redmon, UNC
  • Carey Matt Black, Purdue
  • JJ, Unicon
  • Chris Hubing, Internet2
  • Drew Aschenbrener, Internet2
  • Emily Eisbruch, Internet2

DISCUSSION

 Administrivia

Training



Grouper Release

Next tasks for provisioning

  • Object caching for subjects and target objects
  • Handle this in Start Withs
  • Touch up doc for start withs
  • Work on attribute framework

Rules Issue:

  • https://spaces.at.internet2.edu/display/Grouper/Grouper+rules
  • A rules issue was found;  Chris will work to fix it.  
  • Suggestion: have ACT AS for all the controls
  • actAs: subject that the rule will act as.  If blank, then it will be filled in with the user who created the rule (probably a bad idea since the person might leave at some point, unless it is a service principal).  There can be configurations in the grouper.properties (details) which allow users to act as other users or GrouperSysAdmin.
  • Can have a GSH script to make that happen
  • Will require another Grouper release

Current Work

Vivek

  • Working on Provisioning and Jiras
  • GRP-4217 add button to UI to remove sync data and/or cache dat
  • Carey raised question on Auditing issues
  • GRP-4299 : Provisioning Framework should produce "Audit data" about what it does to external systems.
  • https://todos.internet2.edu/browse/GRP-4298 (new jira for vivek)


Chris  

  • Provisioning framework changes
  • Azure sometimes need to look up a group
  • Full sync will get all groups and members…. 
  • Where objects are stored in java
  • Logic could be confusing
  • Removed a bunch of stuff so data stored in provisioning class
  • Using wrappers with pointers to targets
  • Improved data model

  • Worked on various Jiras
  • Test environment issues
  • Unicon can help with testing, assign jiras to JJ
  • Unicon doing testing in spok and jeb frameworks
  • More info showing in daemon logs, don’t need to go to container logs and splunk
  • JSON is easier for splunk

  • Multiple search attributes (matching fields)  in provisioning,
  • Chris created an Azure provisioning demo video  
  • https://youtu.be/abTkJVBMr1M

  • Meeting today to talk about how the container works, with chris Hyzer ,Chad, J Gasper, M. Gettes, Chris Hubing
  • Openshift issues



  • InCommon Looking at moving off CentOS, 
  • ShibD, Arm
  • Distroless
  • Idea: Docker file from Shib, copy container file, run shell script, do CHMOD
  • During build time
  • Won't work for openshift



Chad

  • Looking at JIRA around LDAP DN copying from CN field
  • Copy translation as well as grouper fields


Issue Roundup 


Jiras in past two weeks


GRP-4296

gsh template drop down should be able to accept non string columns




Grouper Emails in past two weeks


Grouper wiki updates in past two weeks

  • No labels