*** VW has joined #craton | 00:25 | |
*** VW has quit IRC | 00:30 | |
*** valw has quit IRC | 01:24 | |
*** valw has joined #craton | 01:25 | |
*** Syed has quit IRC | 01:26 | |
*** valw has quit IRC | 01:57 | |
*** VW has joined #craton | 02:43 | |
*** VW has quit IRC | 02:51 | |
*** VW has joined #craton | 02:52 | |
*** valw has joined #craton | 03:05 | |
*** valw has quit IRC | 04:28 | |
*** VW has quit IRC | 05:15 | |
*** Mudpuppy has quit IRC | 06:04 | |
*** Mudpuppy has joined #craton | 06:05 | |
*** Mudpuppy has quit IRC | 06:09 | |
*** sorrison_laptop has joined #craton | 08:36 | |
*** sorrison_laptop has left #craton | 08:36 | |
*** mdorman_ has joined #craton | 10:17 | |
*** mdorman has quit IRC | 10:19 | |
*** logan- has quit IRC | 10:19 | |
*** palendae has quit IRC | 10:19 | |
*** logan- has joined #craton | 10:20 | |
*** Guest46299 has joined #craton | 10:28 | |
*** Mudpuppy has joined #craton | 11:06 | |
*** Mudpuppy has quit IRC | 11:11 | |
*** valw has joined #craton | 13:00 | |
*** valw has quit IRC | 13:05 | |
*** valw has joined #craton | 13:25 | |
*** valw has quit IRC | 13:48 | |
*** Mudpuppy has joined #craton | 14:11 | |
*** Mudpuppy has quit IRC | 14:11 | |
sulo | sigmavirus: will you be loooking at harry's pr's today ? it would be nice to get those in for some other cleanup work | 14:21 |
---|---|---|
*** VW has joined #craton | 14:41 | |
*** valw has joined #craton | 14:47 | |
*** valw has quit IRC | 14:47 | |
*** valw has joined #craton | 14:47 | |
*** VW has quit IRC | 14:51 | |
*** VW has joined #craton | 14:51 | |
*** valw has quit IRC | 15:13 | |
*** valw has joined #craton | 15:17 | |
*** Mudpuppy has joined #craton | 15:25 | |
*** valw has quit IRC | 15:29 | |
*** valw has joined #craton | 15:39 | |
*** valw has quit IRC | 15:42 | |
*** valw has joined #craton | 15:42 | |
*** valw has quit IRC | 15:45 | |
*** Syed_ has joined #craton | 15:51 | |
*** valw has joined #craton | 15:53 | |
*** valw has quit IRC | 15:58 | |
*** valw has joined #craton | 16:20 | |
*** Guest46299 is now known as palendae | 16:24 | |
*** valw has quit IRC | 16:25 | |
*** valw has joined #craton | 16:27 | |
*** valw has quit IRC | 16:36 | |
*** valw has joined #craton | 16:36 | |
*** valw has quit IRC | 16:45 | |
*** valw has joined #craton | 16:46 | |
*** valw has quit IRC | 16:50 | |
*** valw has joined #craton | 17:04 | |
*** valw has quit IRC | 17:10 | |
*** valw has joined #craton | 17:10 | |
*** valw has quit IRC | 17:15 | |
jimbaker | sigmavirus, just a minor fix necessary for https://review.openstack.org/#/c/401438/ | 17:21 |
jimbaker | otherwise it looks good | 17:21 |
*** valw has joined #craton | 17:41 | |
*** valw has quit IRC | 17:42 | |
*** valw has joined #craton | 17:42 | |
*** VW has quit IRC | 18:02 | |
*** VW has joined #craton | 18:11 | |
*** valw has quit IRC | 18:33 | |
*** valw has joined #craton | 18:47 | |
*** valw has quit IRC | 18:52 | |
*** valw has joined #craton | 18:57 | |
*** valw has quit IRC | 19:36 | |
*** valw has joined #craton | 19:38 | |
*** VW_ has joined #craton | 20:00 | |
*** VW_ has quit IRC | 20:01 | |
*** VW_ has joined #craton | 20:02 | |
*** VW_ has quit IRC | 20:03 | |
*** VW has quit IRC | 20:04 | |
*** VW has joined #craton | 20:05 | |
*** valw has quit IRC | 20:26 | |
*** valw has joined #craton | 20:29 | |
jimbaker | Syed_, any questions on rbac? especially next steps? | 20:47 |
jimbaker | right now i'm focused on blueprints for virtualized variables and encrypting variables | 20:47 |
jimbaker | also will try to get some more reviewing done | 20:47 |
Syed_ | jimbaker: still searching on oslo.policy to enforce rules, going through their documentation | 20:48 |
jimbaker | Syed_, good stuff | 20:49 |
Syed_ | blueprint seems good to me, gives a clear picture ahead, i went through the article you posted | 20:49 |
jimbaker | i suggest writing a custom rule | 20:49 |
Syed_ | jimbaker: i have a question though, not related to rbac :) | 20:49 |
Syed_ | so for testing routes in endpoints as per schemas | 20:50 |
jimbaker | also worth trying out the naive approach where everything is in the policy.json - so duplicates what the blueprint suggests would be managed by the db | 20:50 |
Syed_ | i am thinking to do a check of routes with https://github.com/openstack/craton/blob/master/craton/api/v1/schemas.py#L1790 | 20:50 |
jimbaker | Syed_, i haven't looked at any of those details | 20:50 |
Syed_ | hmm ... | 20:50 |
jimbaker | sulo is certainly the most knowledgeable here - i did one little thing on flask at this point :) | 20:51 |
Syed_ | maybe i will ping sulo then | 20:51 |
Syed_ | jimbaker: i will read more depths and search over it today evening on oslo policies :) | 20:51 |
jimbaker | Syed_, almost certainly the best for that work. i'm going to try to avoid getting sucked into flask other than when i sees something obvious. git-harry seems to be pretty on top of it as well, but i believe he's out all this week | 20:52 |
jimbaker | Syed_, yeah, just want to involve you here, since this is an interest of yours | 20:53 |
Syed_ | jimbaker: appreciate it, yeah rbac is really cool stuff, i wanna know more on how we get that going in openstack | 20:53 |
jimbaker | i plan to do the same with jovon re api stuff | 20:53 |
jimbaker | Syed_, yeah, it's going to be super interesting work. lots of opportunities to further apply to other projects as well | 20:54 |
jimbaker | Syed_, is jovon around today? | 20:54 |
Syed_ | jimbaker: jovon i guess is off today, i haven't seen him from morning | 20:54 |
jimbaker | anyway, i want to get him going on some more of the stuff we discussed | 20:55 |
jimbaker | no worries, i will keep putting that together, and we can discuss when we have a chance | 20:55 |
jimbaker | hopefully tomorrow | 20:55 |
Syed_ | jimbaker: actually my security professor who taught me advance computer security is a very well known name in rbac, thats when i found out about access control and its importance | 20:56 |
jimbaker | basically trying out the changes in the python client. want to get this tested and documented | 20:56 |
jimbaker | Syed_, name? | 20:56 |
Syed_ | Ravi Sandhu | 20:56 |
Syed_ | jimbaker: http://www.profsandhu.com/ | 20:56 |
jimbaker | Syed_, nice. when i know a bit more about this topic, i'm sure to reach out to him - with you as well | 20:56 |
Syed_ | jimbaker: sounds good | 20:57 |
jimbaker | as a sort-of academic, i do enjoy these discussions | 20:57 |
jimbaker | right now, i'm trying to figure out rbac myself :) and next step, how this fits into some of the approaches | 20:58 |
jimbaker | to describe | 20:58 |
Syed_ | jimbaker: i really liked this article when i first studied that, http://csrc.nist.gov/rbac/sandhu96.pdf | 20:59 |
jimbaker | for example: i'm pretty sure we can easily prove the equivalence of the model i have in that blueprint with what the naive policy.json can do | 20:59 |
jimbaker | i handwave it in the blueprint | 20:59 |
jimbaker | it will be interesting to map some of the formal models to what oslo.policy itself doea | 21:00 |
jimbaker | does | 21:00 |
jimbaker | so that could be a great point of contact with ravi. i'm sure he would appreciate us reaching out to him | 21:00 |
Syed_ | Yes indeed, will be researching more into oslo.policy more today | 21:00 |
jimbaker | so basically the baker model :) looks more like the active directory model | 21:00 |
jimbaker | more or less like | 21:01 |
jimbaker | which we can then rewrite to oslo.policy | 21:01 |
jimbaker | which is probably equivalent to say an attribute extension of rbac in the formal models | 21:01 |
jimbaker | that's the path i would take | 21:01 |
Syed_ | makes sense. | 21:02 |
*** VW has quit IRC | 21:31 | |
*** VW has joined #craton | 21:32 | |
*** VW has quit IRC | 21:36 | |
*** VW has joined #craton | 21:41 | |
*** valw has quit IRC | 21:53 | |
*** valw has joined #craton | 21:55 | |
*** Mudpuppy_ has joined #craton | 22:06 | |
*** Mudpuppy has quit IRC | 22:10 | |
*** Mudpuppy_ has quit IRC | 22:11 | |
*** valw has quit IRC | 22:31 | |
*** VW has quit IRC | 22:44 | |
*** valw has joined #craton | 23:42 | |
*** valw has quit IRC | 23:49 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!