*** jamielennox|away is now known as jamielennox | 00:02 | |
*** zz_dimtruck is now known as dimtruck | 00:11 | |
*** pdesai has quit IRC | 00:12 | |
*** rellerreller has joined #openstack-barbican | 00:16 | |
*** edtubill has joined #openstack-barbican | 00:21 | |
redrobot | arunkant workflowed. also, the agenda is open for anyone to add discussion items: https://wiki.openstack.org/wiki/Meetings/Barbican#Agenda | 00:24 |
---|---|---|
*** jamielennox is now known as jamielennox|away | 00:38 | |
*** jamielennox|away is now known as jamielennox | 00:39 | |
arunkant | redrobot: thanks. Will add discussion item for next week. | 00:42 |
*** edtubill has quit IRC | 00:54 | |
*** cheneydc has joined #openstack-barbican | 00:57 | |
*** ccneill has quit IRC | 00:58 | |
openstackgerrit | Merged openstack/barbican: Addressing error by clearing sqlalchemy session leak https://review.openstack.org/263358 | 00:59 |
*** spotz is now known as spotz_zzz | 01:00 | |
*** rellerreller has quit IRC | 01:11 | |
*** fnaval has quit IRC | 01:13 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Introduce Castellan Credential Factory https://review.openstack.org/273863 | 01:23 |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Allow Barbican Key Manager to accept different auth credentials https://review.openstack.org/273872 | 01:23 |
*** jamielennox is now known as jamielennox|away | 01:30 | |
*** dimtruck is now known as zz_dimtruck | 01:40 | |
*** zz_dimtruck is now known as dimtruck | 01:47 | |
*** su_zhang has quit IRC | 01:48 | |
*** kebray has joined #openstack-barbican | 01:59 | |
*** kebray has quit IRC | 02:03 | |
*** kebray has joined #openstack-barbican | 02:04 | |
*** fnaval has joined #openstack-barbican | 02:29 | |
*** jamielennox|away is now known as jamielennox | 02:31 | |
*** woodster_ has joined #openstack-barbican | 02:37 | |
*** dimtruck is now known as zz_dimtruck | 02:41 | |
*** zz_dimtruck is now known as dimtruck | 02:42 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Allow Barbican Key Manager to accept different auth credentials https://review.openstack.org/273872 | 03:06 |
*** fnaval_ has joined #openstack-barbican | 03:09 | |
*** fnaval has quit IRC | 03:12 | |
*** yuanying_ has quit IRC | 03:20 | |
*** yuanying has joined #openstack-barbican | 03:24 | |
*** gyee has quit IRC | 03:28 | |
*** gyee has joined #openstack-barbican | 03:38 | |
*** Nirupama has joined #openstack-barbican | 03:48 | |
openstackgerrit | Merged openstack/barbican: Python 3 deprecated the logger.warn method in favor of warning https://review.openstack.org/262659 | 03:48 |
*** pdesai has joined #openstack-barbican | 03:59 | |
*** diazjf has quit IRC | 04:01 | |
*** yuanying has quit IRC | 04:06 | |
*** gyee has quit IRC | 04:07 | |
*** yuanying has joined #openstack-barbican | 04:07 | |
*** jamielennox is now known as jamielennox|away | 04:09 | |
*** su_zhang has joined #openstack-barbican | 04:13 | |
*** su_zhang has quit IRC | 04:15 | |
*** su_zhang has joined #openstack-barbican | 04:16 | |
*** sidx64 has joined #openstack-barbican | 04:17 | |
*** su_zhang_ has joined #openstack-barbican | 04:26 | |
*** su_zhang has quit IRC | 04:27 | |
*** dimtruck is now known as zz_dimtruck | 04:29 | |
*** diazjf has joined #openstack-barbican | 04:32 | |
*** diazjf has quit IRC | 04:33 | |
*** diazjf has joined #openstack-barbican | 04:35 | |
*** fnaval_ has quit IRC | 04:50 | |
*** fnaval has joined #openstack-barbican | 04:54 | |
*** fnaval has quit IRC | 04:54 | |
*** fnaval has joined #openstack-barbican | 04:54 | |
*** Nirupama has quit IRC | 05:07 | |
*** Nirupama has joined #openstack-barbican | 05:22 | |
*** diazjf has quit IRC | 05:47 | |
*** pdesai has quit IRC | 06:00 | |
*** woodster_ has quit IRC | 06:16 | |
*** dave-mccowan has quit IRC | 06:48 | |
*** lbragstad has quit IRC | 07:16 | |
*** lbragstad has joined #openstack-barbican | 07:21 | |
*** spotz_zzz is now known as spotz | 07:34 | |
*** spotz is now known as spotz_zzz | 07:35 | |
*** spotz_zzz is now known as spotz | 07:35 | |
*** spotz is now known as spotz_zzz | 07:57 | |
*** su_zhang_ has quit IRC | 08:33 | |
*** jaosorior has joined #openstack-barbican | 08:39 | |
*** Nirupama has quit IRC | 08:58 | |
*** Nirupama has joined #openstack-barbican | 09:14 | |
*** chlong has quit IRC | 09:20 | |
*** jaosorior has quit IRC | 09:53 | |
*** jaosorior has joined #openstack-barbican | 09:54 | |
*** cheneydc has quit IRC | 10:02 | |
*** jaosorior has quit IRC | 10:09 | |
*** jaosorior has joined #openstack-barbican | 10:16 | |
*** sidx64 has quit IRC | 10:51 | |
*** spotz_zzz is now known as spotz | 10:52 | |
*** jaosorior has quit IRC | 10:58 | |
*** jaosorior has joined #openstack-barbican | 10:59 | |
*** spotz is now known as spotz_zzz | 11:15 | |
*** jaosorior has quit IRC | 11:21 | |
*** spotz_zzz is now known as spotz | 11:57 | |
*** spotz is now known as spotz_zzz | 12:08 | |
*** zz_dimtruck has quit IRC | 12:15 | |
-openstackstatus- NOTICE: Infra running with lower capacity now, due to a temporary problem affecting one of our nodepool providers. Please expect some delays in your jobs. Apologies for any inconvenience caused. | 12:39 | |
*** jaosorior has joined #openstack-barbican | 12:57 | |
*** openstackgerrit has quit IRC | 13:02 | |
*** openstackgerrit has joined #openstack-barbican | 13:03 | |
*** Nirupama has quit IRC | 14:05 | |
*** Kevin_Zheng has joined #openstack-barbican | 14:07 | |
*** dave-mccowan has joined #openstack-barbican | 14:20 | |
*** krotscheck1 has joined #openstack-barbican | 14:21 | |
krotscheck1 | I've got a review that's been around for 2 months without a lot of attention, can I get some cores to look at it? https://review.openstack.org/#/c/255364/ | 14:22 |
*** su_zhang has joined #openstack-barbican | 14:23 | |
jaosorior | krotscheck1: Just a quick question. CORS middleware will block all headers that are not in that list, right? Including X-Forwarded-Proto | 14:26 |
krotscheck1 | jaosorior: It won't block- it will simply not permit an x-domain browser request if that header is present. | 14:28 |
krotscheck1 | jaosorior: I mean: It won't filter out headers that aren't permitted. | 14:29 |
krotscheck1 | jaosorior: It will just not decorate the response with the things that tell the browser it's allowed to make the request. | 14:29 |
jaosorior | krotscheck1: Done | 14:32 |
krotscheck1 | jaosorior: WOO! Thanks :) | 14:32 |
*** edtubill has joined #openstack-barbican | 14:36 | |
*** jmckind has joined #openstack-barbican | 14:38 | |
jaosorior | redrobot: Are you around> | 14:51 |
jaosorior | ? | 14:51 |
*** sidx64 has joined #openstack-barbican | 14:54 | |
*** spotz_zzz is now known as spotz | 15:03 | |
openstackgerrit | Elvin Tubillara proposed openstack/barbican-specs: Create blueprint for restoring secrets https://review.openstack.org/267030 | 15:04 |
openstackgerrit | Elvin Tubillara proposed openstack/barbican-specs: Blueprint for making soft deletions optional https://review.openstack.org/267034 | 15:04 |
*** sidx64_Cern has joined #openstack-barbican | 15:07 | |
*** sid_cerner has joined #openstack-barbican | 15:09 | |
*** sidx64 has quit IRC | 15:11 | |
*** sidx64_Cern has quit IRC | 15:13 | |
*** mp1 has joined #openstack-barbican | 15:31 | |
*** sidx64_Cern has joined #openstack-barbican | 15:33 | |
*** sid_cerner has quit IRC | 15:37 | |
*** dimtruck has joined #openstack-barbican | 15:42 | |
*** jhfeng has joined #openstack-barbican | 16:00 | |
*** diazjf has joined #openstack-barbican | 16:03 | |
*** woodster_ has joined #openstack-barbican | 16:05 | |
jaosorior | redrobot: ping | 16:05 |
redrobot | jaosorior pong | 16:05 |
jaosorior | redrobot: Hey dude, so pretty much. So then Arun is gonna work on enabling multiple endpoints for barbican then? | 16:06 |
redrobot | jaosorior yeah, it appears that having multiple endpoints is a requirement for him, and running two sets of API nodes with different configurations is not acceptable to his ops team. | 16:07 |
jaosorior | redrobot: that makes sense. So what do we do with our patches then? They do pretty much the same thing | 16:07 |
redrobot | jaosorior I don't think we need to wait on that work to land either patch. I'd rather fix the inconsistency now, and let arunkant take his time to implement something that works for him. | 16:08 |
redrobot | jaosorior want to review mine? I can probably get woodster_ to take a look at it as well | 16:09 |
jaosorior | redrobot: Honestly I rather have the patch I did land, since it removes the unused parameter from the function. | 16:10 |
redrobot | jaosorior sounds good, want to remove the WIP? | 16:10 |
redrobot | jaosorior I'll +2 and get woodster_ to take a look at it as well. | 16:10 |
arunkant | redrobot, jaosorior : Actually for supporting multiple endpoint, there is nothing do we done, if just follow what's currently done in version side..is done on href side | 16:11 |
redrobot | arunkant I thought I explained yesterday why the way that versions is handled is a problem | 16:11 |
jaosorior | arunkant: What about the host_href that is currently being returned? | 16:11 |
arunkant | version side of code already works for multiple endpoint | 16:11 |
redrobot | arunkant i'm running barbican inside a container | 16:11 |
redrobot | arunkant and versions does not work for me | 16:12 |
redrobot | arunkant because of the way that docker handles the network | 16:12 |
redrobot | arunkant I would prefer for you to implement something like the Keystone solution that you linked yesterday | 16:13 |
jaosorior | arunkant: Seems to me that the real solution for handling multiple endpoints is to support something similar like public_endpoint and internal_endpoint options, but this also needs to be reflected in the secret's href that is returned from the barbican side | 16:13 |
redrobot | arunkant so that the endpoints are set in conf, instead of depending on the environment, because env assumptions are not going to be consistent for every possible deployment. | 16:13 |
arunkant | redrobot: But then there is no possible solution which works for dokcer container setup and other kind of setup. We will need to pass header from proxy to differentiate internal and public endpoint. | 16:13 |
jaosorior | arunkant: Yeah, we probably should be using X-Forwarded | 16:14 |
redrobot | jaosorior +1 | 16:14 |
jaosorior | which is what I do for other services. But it seems to me that the easiest thing is to get the endpoint type from the keystone context, and then use the configuration accordingly | 16:14 |
arunkant | jaosorior: Yes..that's the way it currently works with X-Forwarded-For and X-Forwarded-Proto header for version logic | 16:15 |
redrobot | arunkant whatever the solution is, it HAS to work for containers. | 16:15 |
* redrobot thinks containers are the future! ;) | 16:16 | |
arunkant | jaosorior: Call is coming from client, I don't think keystone provides anything related to endpoint_type in token validation response | 16:16 |
jaosorior | redrobot, arunkant: a middleground would be to add a config option that tells the server what to use. Either the solution that's there now, or the host_href | 16:16 |
redrobot | jaosorior i'd be ok with that... I still insist we need to fix the version inconsistency now. and then implement something that works for both arunkant and I | 16:17 |
arunkant | jaosorior: +1, yes..that's what keystone currently has | 16:17 |
arunkant | redrobot: Okay...yes..that will work for me..if that is an acceptable option. I can add the fix for that in coming weeks. | 16:18 |
jaosorior | redrobot: Lets get your commit merged, in that case, the request's url will still be present there, so then a config option can be added easily that will use the url if set | 16:19 |
arunkant | redrobot: Are you going to be okay for adding this as bug fix in that manner ? I have bug for that..https://bugs.launchpad.net/barbican/+bug/1541118 | 16:20 |
openstack | Launchpad bug 1541118 in Barbican "Barbican single host setting does not work with internal and public endpoints" [Undecided,New] | 16:20 |
*** silos has joined #openstack-barbican | 16:20 | |
*** diazjf has quit IRC | 16:21 | |
jaosorior | redrobot, arunkant: Oh, I see mine merged. Anyway, now it's a matter of fixing the bug report you added. | 16:21 |
*** diazjf has joined #openstack-barbican | 16:22 | |
jaosorior | arunkant: And you're right, keystone context doesn't have information about the endpoint type. The way they do it is that they have different configuration for the versions resource depending on which endpoint was accessed | 16:22 |
openstackgerrit | Christopher Solis proposed openstack/barbican-specs: Add a KMIP key manager interface in Castellan https://review.openstack.org/246546 | 16:22 |
arunkant | jaosorior: Okay..yes I looked into this other day. | 16:22 |
jaosorior | arunkant: Yeah... so the fact that barbican secrets are always returned with the public endpoint prepended is not a problem for you? | 16:25 |
jaosorior | brb | 16:26 |
*** pwp has joined #openstack-barbican | 16:27 | |
jaosorior | wooster_, redrobot: Anyway, thanks for the reviews | 16:31 |
edtubill | woodster_: can you review this when you have time? https://review.openstack.org/#/c/269903/ | 16:32 |
*** sid_cerner has joined #openstack-barbican | 16:40 | |
*** sidx64_Cern has quit IRC | 16:45 | |
*** tonyb has quit IRC | 16:45 | |
*** tonyb has joined #openstack-barbican | 16:46 | |
*** ccneill has joined #openstack-barbican | 16:49 | |
*** sidx64 has joined #openstack-barbican | 16:51 | |
*** su_zhang has quit IRC | 16:53 | |
*** sid_cerner has quit IRC | 16:54 | |
*** pwp has quit IRC | 16:56 | |
*** pwp has joined #openstack-barbican | 16:57 | |
openstackgerrit | Merged openstack/barbican: Use host href for version discovery https://review.openstack.org/273895 | 17:01 |
*** gyee has joined #openstack-barbican | 17:01 | |
*** mp1 has quit IRC | 17:01 | |
*** jmckind has quit IRC | 17:06 | |
*** mp1 has joined #openstack-barbican | 17:06 | |
openstackgerrit | Merged openstack/barbican: Add missing database constraints and defaults https://review.openstack.org/274276 | 17:10 |
*** jmckind has joined #openstack-barbican | 17:13 | |
*** jmckind has quit IRC | 17:33 | |
*** alee has joined #openstack-barbican | 17:33 | |
*** pwp has quit IRC | 17:34 | |
*** mp1 has quit IRC | 17:36 | |
*** mp1 has joined #openstack-barbican | 17:37 | |
*** sidx64 has quit IRC | 17:38 | |
*** sidx64_Cern has joined #openstack-barbican | 17:38 | |
*** pwp has joined #openstack-barbican | 17:38 | |
*** fnaval has quit IRC | 17:43 | |
*** pwp has quit IRC | 17:43 | |
*** jaosorior has quit IRC | 17:46 | |
*** pdesai has joined #openstack-barbican | 17:50 | |
*** jorge_munoz has quit IRC | 17:59 | |
*** su_zhang has joined #openstack-barbican | 17:59 | |
*** su_zhang has quit IRC | 18:01 | |
*** su_zhang has joined #openstack-barbican | 18:02 | |
*** fnaval has joined #openstack-barbican | 18:03 | |
*** diazjf has quit IRC | 18:04 | |
*** silos has quit IRC | 18:04 | |
*** fnaval_ has joined #openstack-barbican | 18:05 | |
*** alee has quit IRC | 18:06 | |
*** su_zhang has quit IRC | 18:07 | |
*** su_zhang_ has joined #openstack-barbican | 18:07 | |
jkf | Any cores around who can workflow this bug fix of mine? https://review.openstack.org/#/c/270572 | 18:07 |
*** mp1 has quit IRC | 18:08 | |
*** fnaval has quit IRC | 18:08 | |
*** sidx64_Cern has quit IRC | 18:09 | |
*** su_zhang_ has quit IRC | 18:39 | |
*** su_zhang has joined #openstack-barbican | 18:40 | |
*** mp1 has joined #openstack-barbican | 18:45 | |
*** diazjf has joined #openstack-barbican | 18:49 | |
openstackgerrit | Fernando Diaz proposed openstack/barbican: WIP: User Metadata API and tests https://review.openstack.org/275885 | 18:50 |
*** silos has joined #openstack-barbican | 18:52 | |
*** diazjf has quit IRC | 19:08 | |
*** kebray has quit IRC | 19:09 | |
*** jmckind has joined #openstack-barbican | 19:11 | |
*** fnaval_ is now known as fnaval | 19:12 | |
*** kebray has joined #openstack-barbican | 19:15 | |
*** jsavak has joined #openstack-barbican | 19:20 | |
*** su_zhang has quit IRC | 19:32 | |
*** su_zhang has joined #openstack-barbican | 19:33 | |
*** su_zhang has quit IRC | 19:33 | |
*** su_zhang has joined #openstack-barbican | 19:34 | |
*** pwp has joined #openstack-barbican | 19:34 | |
*** pwp has quit IRC | 19:36 | |
*** su_zhang has quit IRC | 19:40 | |
*** mp1 has quit IRC | 19:40 | |
*** pwp has joined #openstack-barbican | 19:40 | |
*** pwp has quit IRC | 19:40 | |
*** krotscheck1 is now known as krotscheck_dcm | 19:42 | |
*** silos has quit IRC | 19:42 | |
*** silos has joined #openstack-barbican | 19:43 | |
*** mp1 has joined #openstack-barbican | 19:43 | |
*** su_zhang has joined #openstack-barbican | 19:46 | |
*** kebray has quit IRC | 19:57 | |
*** jsavak has quit IRC | 19:58 | |
*** kebray has joined #openstack-barbican | 19:59 | |
*** diazjf has joined #openstack-barbican | 20:08 | |
*** diazjf has quit IRC | 20:09 | |
*** diazjf has joined #openstack-barbican | 20:18 | |
*** su_zhang has quit IRC | 20:40 | |
openstackgerrit | Elvin Tubillara proposed openstack/barbican: Simple soft deletion clean up for barbican-db-manage https://review.openstack.org/269903 | 20:47 |
*** su_zhang has joined #openstack-barbican | 20:48 | |
*** rtmorgan has quit IRC | 21:00 | |
*** diazjf has quit IRC | 21:02 | |
*** edtubill has quit IRC | 21:05 | |
*** su_zhang has quit IRC | 21:05 | |
*** edtubill has joined #openstack-barbican | 21:05 | |
*** jhfeng has quit IRC | 21:10 | |
*** silos has quit IRC | 21:10 | |
*** rtmorgan has joined #openstack-barbican | 21:16 | |
*** su_zhang has joined #openstack-barbican | 21:17 | |
*** rtmorgan has quit IRC | 21:20 | |
*** rtmorgan has joined #openstack-barbican | 21:21 | |
*** rtmorgan has quit IRC | 21:33 | |
*** rtmorgan has joined #openstack-barbican | 21:34 | |
*** edtubill has quit IRC | 21:39 | |
*** su_zhang has quit IRC | 21:41 | |
*** edtubill has joined #openstack-barbican | 21:50 | |
*** edtubill has quit IRC | 21:50 | |
*** lbragstad has left #openstack-barbican | 21:56 | |
*** silos has joined #openstack-barbican | 21:56 | |
*** edtubill has joined #openstack-barbican | 21:57 | |
silos | If anyone has some free time to review, i'm trying to get this spec into mitaka: https://review.openstack.org/#/c/246546/ | 21:58 |
edtubill | ping woodster_ | 22:04 |
*** su_zhang has joined #openstack-barbican | 22:04 | |
*** krotscheck_dcm has quit IRC | 22:17 | |
*** krotscheck1 has joined #openstack-barbican | 22:17 | |
*** su_zhang has quit IRC | 22:17 | |
*** jhfeng has joined #openstack-barbican | 22:19 | |
*** diazjf has joined #openstack-barbican | 22:21 | |
*** rtmorgan has quit IRC | 22:37 | |
*** rtmorgan has joined #openstack-barbican | 22:41 | |
*** silos has left #openstack-barbican | 22:45 | |
*** mp1 has quit IRC | 22:46 | |
*** rtmorgan has quit IRC | 22:48 | |
*** krotscheck1 has quit IRC | 22:49 | |
*** alee has joined #openstack-barbican | 22:51 | |
*** su_zhang has joined #openstack-barbican | 22:52 | |
*** diazjf has quit IRC | 22:54 | |
*** pdesai has quit IRC | 23:00 | |
*** jmckind has quit IRC | 23:04 | |
*** dave-mccowan has quit IRC | 23:08 | |
*** alee has quit IRC | 23:17 | |
*** jhfeng has quit IRC | 23:23 | |
*** spotz is now known as spotz_zzz | 23:29 | |
openstackgerrit | Elvin Tubillara proposed openstack/barbican: Simple soft deletion clean up for barbican-db-manage https://review.openstack.org/269903 | 23:30 |
*** edtubill has quit IRC | 23:33 | |
*** dave-mccowan has joined #openstack-barbican | 23:40 | |
*** dimtruck is now known as zz_dimtruck | 23:42 | |
*** jamielennox|away is now known as jamielennox | 23:47 | |
*** yuanying has quit IRC | 23:54 | |
*** yuanying has joined #openstack-barbican | 23:56 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!