Please see the ESC meeting minutes at [1], including the ElasticSearch support in core dropped from v3.5.x onwards [2].
On 10 Nov 2021, at 13:16, Sven Selberg <sven.s...@axis.com> wrote:On Wednesday, November 10, 2021 at 12:50:41 PM UTC+1 lucamilanesio wrote:Please see the ESC meeting minutes at [1], including the ElasticSearch support in core dropped from v3.5.x onwards [2].There's an 'l' missing in this link. Should be:
--
--
To unsubscribe, email repo-discuss...@googlegroups.com
More info at http://groups.google.com/group/repo-discuss?hl=en
---
You received this message because you are subscribed to the Google Groups "Repo and Gerrit Discussion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to repo-discuss...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/repo-discuss/a711293e-5d19-4f30-bb98-c443e40ab063n%40googlegroups.com.
On 10 Nov 2021, at 13:16, Sven Selberg <sven.s...@axis.com> wrote:On Wednesday, November 10, 2021 at 12:50:41 PM UTC+1 lucamilanesio wrote:Please see the ESC meeting minutes at [1], including the ElasticSearch support in core dropped from v3.5.x onwards [2].There's an 'l' missing in this link. Should be:Thanks Sven, yes it was indeed missing :-)
On 10 Nov 2021, at 13:26, Sven Selberg <sven.s...@axis.com> wrote:On Wednesday, November 10, 2021 at 2:21:24 PM UTC+1 lucamilanesio wrote:On 10 Nov 2021, at 13:16, Sven Selberg <sven.s...@axis.com> wrote:On Wednesday, November 10, 2021 at 12:50:41 PM UTC+1 lucamilanesio wrote:Please see the ESC meeting minutes at [1], including the ElasticSearch support in core dropped from v3.5.x onwards [2].There's an 'l' missing in this link. Should be:Thanks Sven, yes it was indeed missing :-)It seems like there's a discrepancy between what's deployed and what's merged.
If you look at the date in the link of the MoM it says "2021-10-06" but the document served shows the MoM for "2021-11-03".
This doesn't match how that document looks in git [1], and in git the Nov 3 MoM[2] have the correct path but it's not served from the homepage.
Luca.--
--
To unsubscribe, email repo-discuss...@googlegroups.com
More info at http://groups.google.com/group/repo-discuss?hl=en
---
You received this message because you are subscribed to the Google Groups "Repo and Gerrit Discussion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to repo-discuss...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/repo-discuss/a711293e-5d19-4f30-bb98-c443e40ab063n%40googlegroups.com.
--
--
To unsubscribe, email repo-discuss...@googlegroups.com
More info at http://groups.google.com/group/repo-discuss?hl=en
---
You received this message because you are subscribed to the Google Groups "Repo and Gerrit Discussion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to repo-discuss...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/repo-discuss/a4e5c9db-42fd-4011-b68b-eb67c54d0273n%40googlegroups.com.
On 10 Nov 2021, at 13:26, Sven Selberg <sven.s...@axis.com> wrote:On Wednesday, November 10, 2021 at 2:21:24 PM UTC+1 lucamilanesio wrote:On 10 Nov 2021, at 13:16, Sven Selberg <sven.s...@axis.com> wrote:On Wednesday, November 10, 2021 at 12:50:41 PM UTC+1 lucamilanesio wrote:Please see the ESC meeting minutes at [1], including the ElasticSearch support in core dropped from v3.5.x onwards [2].There's an 'l' missing in this link. Should be:Thanks Sven, yes it was indeed missing :-)It seems like there's a discrepancy between what's deployed and what's merged.
If you look at the date in the link of the MoM it says "2021-10-06" but the document served shows the MoM for "2021-11-03".
This doesn't match how that document looks in git [1], and in git the Nov 3 MoM[2] have the correct path but it's not served from the homepage.Let me upload a fix.Luca.
On 10 Nov 2021, at 13:28, Luca Milanesio <luca.mi...@gmail.com> wrote:On 10 Nov 2021, at 13:26, Sven Selberg <sven.s...@axis.com> wrote:On Wednesday, November 10, 2021 at 2:21:24 PM UTC+1 lucamilanesio wrote:On 10 Nov 2021, at 13:16, Sven Selberg <sven.s...@axis.com> wrote:On Wednesday, November 10, 2021 at 12:50:41 PM UTC+1 lucamilanesio wrote:Please see the ESC meeting minutes at [1], including the ElasticSearch support in core dropped from v3.5.x onwards [2].There's an 'l' missing in this link. Should be:Thanks Sven, yes it was indeed missing :-)It seems like there's a discrepancy between what's deployed and what's merged.
If you look at the date in the link of the MoM it says "2021-10-06" but the document served shows the MoM for "2021-11-03".
This doesn't match how that document looks in git [1], and in git the Nov 3 MoM[2] have the correct path but it's not served from the homepage.Let me upload a fix.
JFYI, the first link doesn't work (missing the "l")Was there anything more said about the "Trojan Source" issue, there's been some worries going on around that internally for us.
On Wednesday, November 10, 2021 at 11:50:41 AM UTC lucamilanesio wrote:Please see the ESC meeting minutes at [1], including the ElasticSearch support in core dropped from v3.5.x onwards [2].
--
--
To unsubscribe, email repo-discuss...@googlegroups.com
More info at http://groups.google.com/group/repo-discuss?hl=en
---
You received this message because you are subscribed to the Google Groups "Repo and Gerrit Discussion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to repo-discuss...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/repo-discuss/6a625e52-e8ec-44d3-96f7-c5c1488d0b21n%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/repo-discuss/CAKSZd3TaRjkuBehq49NE%2BMoFzLXbAom7HwZUcTf_cQQK9bfDAw%40mail.gmail.com.
On 11 Nov 2021, at 01:35, Richard Christie <richard....@arm.com> wrote:The idea of scoped credentials, potentially separate from a user account and with a max TTL on them is something we would be quite interested in too. JFrog do something similar to this in Artifactory.Or just the possibility of having multiple user http tokens (again ideally with max TTL) so that it is possible to rotate them in accordance with security policy. Currently this is quite hard for system accounts that may be accessing through CI as you can never be sure there isn't a job running somewhere with the older credential still "active" at the point you cycle.Having (say) just two tokens would allow say, daily rotation with a 2 day time to live making sure that all uses of the "older" were almost certainly expired by that point.
It is something that can already be done by ssh since you can have multiple ssh public keys, but there is a general movement away from ssh towards https within engineering for flows these days.
On Wednesday, November 10, 2021 at 5:10:50 PM UTC clark....@gmail.com wrote:On Wed, Nov 10, 2021 at 8:43 AM Luca Milanesio <luca.mi...@gmail.com> wrote:
>
> The meeting minutes have been re-published at:
> https://www.gerritcodereview.com/2021-11-03-esc-minutes.html
>
Thank you for putting this together. Wanted to clarify on the scoped
credentials topic. This came out of a brainstorm around how to make
HTTP credentials easier to use. Currently the vast majority of our
users use SSH to push to Gerrit, and I think that works great for
those users. I think we're happy to continue to use SSH as the primary
method here (I know this is my personal preference).
Don't want to give the impression this is a hard requirement for us.
We'd like to continue to be able to use SSH for most of our users, and
maybe we can improve things for those where SSH does not work
(typically for firewall reasons). Happy to consider other ideas as
well.
Clark
--
--
To unsubscribe, email repo-discuss...@googlegroups.com
More info at http://groups.google.com/group/repo-discuss?hl=en
---
You received this message because you are subscribed to the Google Groups "Repo and Gerrit Discussion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to repo-discuss...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/repo-discuss/1c31b35a-b6f4-4015-b793-1e21b1ee2103n%40googlegroups.com.
On 11 Nov 2021, at 01:35, Richard Christie <richard....@arm.com> wrote:The idea of scoped credentials, potentially separate from a user account and with a max TTL on them is something we would be quite interested in too. JFrog do something similar to this in Artifactory.Or just the possibility of having multiple user http tokens (again ideally with max TTL) so that it is possible to rotate them in accordance with security policy. Currently this is quite hard for system accounts that may be accessing through CI as you can never be sure there isn't a job running somewhere with the older credential still "active" at the point you cycle.Having (say) just two tokens would allow say, daily rotation with a 2 day time to live making sure that all uses of the "older" were almost certainly expired by that point.I agree that it would be useful indeed. Having HTTP secure keys (with TTL and limited scope) is paramount for having a robust and secure Git/HTTPS communication between the CI system and Gerrit.I believe that could be achieved with a plugin: if you (or anyone else) have interest in writing one, I can setup a brainstorming session and we can kickstart the project.I would be happy to contribute / review / participate in the development.
It is something that can already be done by ssh since you can have multiple ssh public keys, but there is a general movement away from ssh towards https within engineering for flows these days.SSH keys are less secure though, because you cannot scope them to individual commands / features.Also, if anyone would eavesdrop the key, he could potentially set an HTTP password and then use that for invoking any REST-API and do anything he wants with it.I believe we need something better, more robust and secure.
--
--
To unsubscribe, email repo-discuss...@googlegroups.com
More info at http://groups.google.com/group/repo-discuss?hl=en
---
You received this message because you are subscribed to the Google Groups "Repo and Gerrit Discussion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to repo-discuss...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/repo-discuss/03fd2dcc-3e02-4582-9f02-f83f31668296n%40googlegroups.com.
It’s sad to hear about the elasticsearch (I will call ES for short in this context) will be deprecated soon. Alibaba use ES to auto-scale the Reversed indexes of 5 large Gerrit Clusters and they are working well.I totally understand and agree the decision of that, it will be plenty of time for us to care about the solution or replacement if we want to upgrade to v3.5x.