*** rhagarty has joined #openstack-barbican | 00:03 | |
*** rhagarty_ has joined #openstack-barbican | 00:06 | |
*** rhagarty has quit IRC | 00:08 | |
*** zz_dimtruck is now known as dimtruck | 00:31 | |
*** ccneill has quit IRC | 00:36 | |
*** dimtruck is now known as zz_dimtruck | 00:46 | |
*** zz_dimtruck is now known as dimtruck | 00:55 | |
*** rellerreller has joined #openstack-barbican | 01:02 | |
*** tkelsey has joined #openstack-barbican | 01:08 | |
*** tkelsey has quit IRC | 01:12 | |
*** chenli has joined #openstack-barbican | 01:15 | |
*** rhagarty_ has quit IRC | 01:20 | |
*** rhagarty has joined #openstack-barbican | 01:20 | |
*** diazjf has joined #openstack-barbican | 01:24 | |
*** diazjf has quit IRC | 01:32 | |
*** rellerreller has quit IRC | 01:49 | |
*** rhagarty has quit IRC | 01:58 | |
*** su_zhang has quit IRC | 02:04 | |
openstackgerrit | Douglas Mendizábal proposed openstack/barbican: Update and reorganize the doc landing page. https://review.openstack.org/281607 | 02:05 |
---|---|---|
*** yuanying_ has quit IRC | 03:21 | |
*** woodster_ has quit IRC | 03:36 | |
*** yuanying has joined #openstack-barbican | 03:39 | |
*** yuanying has quit IRC | 03:55 | |
*** chenli has quit IRC | 04:02 | |
*** yuanying has joined #openstack-barbican | 04:05 | |
*** yuanying_ has joined #openstack-barbican | 04:07 | |
*** yuanying has quit IRC | 04:09 | |
*** dimtruck is now known as zz_dimtruck | 04:14 | |
*** chenli has joined #openstack-barbican | 04:44 | |
*** diazjf has joined #openstack-barbican | 05:00 | |
*** diazjf has quit IRC | 05:01 | |
*** tkelsey has joined #openstack-barbican | 05:09 | |
*** tkelsey has quit IRC | 05:13 | |
*** diazjf has joined #openstack-barbican | 05:19 | |
*** gyee has quit IRC | 05:35 | |
*** dave-mccowan has quit IRC | 05:38 | |
*** Nirupama has joined #openstack-barbican | 05:42 | |
openstackgerrit | Fernando Diaz proposed openstack/barbican: WIP: User Metadata API and tests https://review.openstack.org/275885 | 05:59 |
*** fnaval has quit IRC | 06:10 | |
*** jaosorior has quit IRC | 06:23 | |
*** jaosorior has joined #openstack-barbican | 06:24 | |
*** sidx64 has joined #openstack-barbican | 06:29 | |
*** diazjf has quit IRC | 06:55 | |
*** fnaval has joined #openstack-barbican | 07:00 | |
*** su_zhang has joined #openstack-barbican | 07:02 | |
*** scheuran has joined #openstack-barbican | 07:17 | |
*** pcaruana has joined #openstack-barbican | 08:05 | |
*** su_zhang has quit IRC | 08:08 | |
*** tkelsey has joined #openstack-barbican | 08:20 | |
*** sidx64 has quit IRC | 08:29 | |
*** RuiChen has joined #openstack-barbican | 09:18 | |
*** RuiChen has left #openstack-barbican | 09:22 | |
*** chenli has quit IRC | 09:37 | |
*** openstackgerrit has quit IRC | 10:02 | |
*** openstackgerrit has joined #openstack-barbican | 10:03 | |
*** Nirupama has quit IRC | 10:37 | |
*** Nirupama has joined #openstack-barbican | 10:40 | |
*** kebray has quit IRC | 11:18 | |
*** kebray has joined #openstack-barbican | 11:24 | |
openstackgerrit | Adam Harwell proposed openstack/barbican: Remove consumer check for project_id to match containers https://review.openstack.org/251168 | 11:29 |
*** dave-mccowan has joined #openstack-barbican | 12:26 | |
*** alee_dinner has quit IRC | 13:23 | |
*** jhfeng has joined #openstack-barbican | 13:51 | |
*** Nirupama has quit IRC | 13:55 | |
*** jhfeng has quit IRC | 13:55 | |
*** dave-mccowan has quit IRC | 14:09 | |
*** dave-mccowan has joined #openstack-barbican | 14:10 | |
*** rellerreller has joined #openstack-barbican | 14:20 | |
*** su_zhang has joined #openstack-barbican | 14:21 | |
*** jaosorior has quit IRC | 14:24 | |
*** jaosorior has joined #openstack-barbican | 14:25 | |
*** alee_dinner has joined #openstack-barbican | 14:36 | |
*** dave-mccowan has quit IRC | 14:48 | |
*** jhfeng has joined #openstack-barbican | 14:57 | |
*** jaosorior has quit IRC | 14:58 | |
*** jaosorior has joined #openstack-barbican | 14:59 | |
*** dave-mccowan has joined #openstack-barbican | 15:02 | |
*** rhagarty has joined #openstack-barbican | 15:03 | |
*** spotz_zzz is now known as spotz | 15:23 | |
*** mp1 has joined #openstack-barbican | 15:24 | |
*** zz_dimtruck is now known as dimtruck | 15:28 | |
*** silos has joined #openstack-barbican | 15:39 | |
*** woodster_ has joined #openstack-barbican | 15:39 | |
*** spotz is now known as spotz_zzz | 15:46 | |
*** spotz_zzz is now known as spotz | 15:49 | |
*** kebray has quit IRC | 15:51 | |
*** kebray has joined #openstack-barbican | 15:53 | |
*** mp1 has quit IRC | 15:56 | |
*** mp1 has joined #openstack-barbican | 15:59 | |
*** krotscheck_dcm is now known as krotscheck | 16:00 | |
*** alee_dinner is now known as alee | 16:01 | |
alee | redrobot, jaosorior - any idea what is going on here? http://paste.openstack.org/show/487424/ | 16:01 |
*** mp1 has quit IRC | 16:01 | |
jaosorior | alee: not too familiar with gunicorn, sorry :/ | 16:02 |
alee | jaosorior, just trying to figure out why the server is not starting -- must be something new that has been added | 16:03 |
alee | redrobot, familiar? | 16:03 |
*** zigo has quit IRC | 16:03 | |
*** jaosorior has left #openstack-barbican | 16:03 | |
*** jaosorior has joined #openstack-barbican | 16:04 | |
*** zigo has joined #openstack-barbican | 16:05 | |
alee | jaosorior, I think its a config error - not a gunicorn error .. | 16:06 |
jaosorior | alee: H ow does your paste.ini look like? | 16:09 |
jaosorior | Seems that the problem might be there | 16:09 |
alee | jaosorior, looking -- pasting .. | 16:12 |
*** mp1 has joined #openstack-barbican | 16:14 | |
alee | jaosorior, the paste.ini looks exactly the same as the regular paste.ini except for this addtional bits .. | 16:14 |
alee | [server:main] | 16:14 |
alee | > use = egg:gunicorn#main | 16:14 |
alee | > [server:main] | 16:15 |
alee | > use = egg:gunicorn#main | 16:15 |
*** pcaruana has quit IRC | 16:15 | |
*** fnaval has quit IRC | 16:18 | |
jaosorior | alee: I'll be back in a couple of hours | 16:18 |
alee | jaosorior, ok --- looks like an oslo problem -- maybe different oslo version .. | 16:19 |
alee | oslo-middleware | 16:20 |
*** ccneill has joined #openstack-barbican | 16:22 | |
alee | jaosorior, yup - that was it .. | 16:27 |
openstackgerrit | Douglas Mendizábal proposed openstack/barbican: Update and reorganize the doc landing page. https://review.openstack.org/281607 | 16:27 |
*** insequent has quit IRC | 16:30 | |
*** fnaval has joined #openstack-barbican | 16:34 | |
*** fredyx10 has joined #openstack-barbican | 16:49 | |
*** scheuran has quit IRC | 16:53 | |
*** mp1 has quit IRC | 16:56 | |
*** diazjf has joined #openstack-barbican | 16:57 | |
*** jhfeng has quit IRC | 16:58 | |
alee | redrobot, ya'll changed the barbican client .. | 16:58 |
redrobot | alee eh? | 16:58 |
alee | there is no longer an order create .. | 16:59 |
alee | now is secret order create ? | 16:59 |
redrobot | alee are you using barbican or openstack cli? | 16:59 |
alee | barbican | 17:00 |
redrobot | alee weird ... I don't recall it being changed. | 17:00 |
*** jhfeng has joined #openstack-barbican | 17:00 | |
redrobot | alee I think it should be "barbican order create" as well | 17:01 |
*** gyee has joined #openstack-barbican | 17:01 | |
alee | redrobot, let me pull up source .. but this used to work for me .. | 17:02 |
*** su_zhang has quit IRC | 17:02 | |
alee | barbican --os-username barbican --os-password a_big_secret --os-tenant-name services --os-auth-url http://127.0.0.1:5000/v2.0 --endpoint http://localhost:9311 order create --name foo --type key --os-identity-api-version 2 | 17:02 |
alee | and it does not now .. | 17:02 |
*** mp1 has joined #openstack-barbican | 17:06 | |
alee | redrobot, what is working for you? | 17:06 |
*** rhagarty_ has joined #openstack-barbican | 17:08 | |
diazjf | alee, redrobot, I believe it was changed to 'barbican secret order create' checkout setup.cfg here https://github.com/openstack/python-barbicanclient/commit/85f5ec262c1b996a8a096719f432f9cedcf560ba | 17:09 |
*** jhfeng has quit IRC | 17:10 | |
*** rhagarty has quit IRC | 17:10 | |
*** insequent has joined #openstack-barbican | 17:11 | |
alee | diazjf, well thats interesting .. good thing we're not worried about backward compatibility | 17:12 |
alee | diazjf, you also made a change for the type of the order | 17:13 |
alee | diazjf, changed it to a positional parameter? | 17:13 |
diazjf | alee, I'd ask jaosorior ^ | 17:14 |
alee | diazjf, well that particular change was your commit :) | 17:14 |
alee | this now works .. | 17:15 |
diazjf | ohh lol alee, yeah I remember now | 17:15 |
alee | barbican --os-username barbican --os-password a_big_secret --os-tenant-name services --os-auth-url http://127.0.0.1:5000/v2.0 --endpoint http://localhost:9311 secret order create key --name foo --os-identity-api-version 2 | 17:15 |
redrobot | alee sorry, i'm mid-meeting right now... will take a look in the afternoon. | 17:15 |
alee | redrobot, no worries | 17:15 |
alee | diazjf, redrobot - I'm just not sure the cli is very intuitive now -- barbican secret order create key .... | 17:16 |
alee | barbican secret order create certificate .. | 17:17 |
alee | ugh | 17:17 |
silos | alee: redrobot and I were going to create an etherpad to discuss changes to the client to make it more user-friendly. | 17:17 |
silos | alee: I can probably have it up in a bit and post the link | 17:18 |
alee | silos, that would be a good idea. although all these changes make me want to use the openstack client | 17:18 |
redrobot | alee agreed... one thing I was talking to silos about is that I think our approach to the CLI is not the correct one. It seems we are trying to map 1:1 the REST concepts and make them available in the CLI | 17:18 |
redrobot | alee but I think a better approach would be to think of use cases that a user of barbican would want to do with the CLI and only expose that | 17:19 |
redrobot | alee a good example is 2-step secrets | 17:19 |
alee | redrobot, whats the long term strategy on the cli ? are we moving to the openstack clientZ? | 17:20 |
redrobot | alee 2-step workflow was put in place because of JSON limitations when working with the HTTP API directly. but it doesn't make sense to issue 2 cli commands to achieve a secret store, because we can address that limitation in code and never have to expose it to the user. | 17:20 |
alee | because if we are -- then I'm not sure how much effort we should put into prettyfying the cli. | 17:20 |
redrobot | alee We have an initial plugin for the unified CLI that jaosorior worked on | 17:20 |
redrobot | alee but it mostly looks like the current cli | 17:21 |
redrobot | alee with warts and all | 17:21 |
redrobot | alee I would like to completely revamp it with silos | 17:21 |
alee | redrobot, right - but maybe we should fix it there | 17:21 |
alee | at this point, I'm not sure who is using the cli -- certainly I' | 17:21 |
redrobot | alee yeah, that would work for me | 17:21 |
alee | I'm the first one to notice that key gen cli has changed | 17:22 |
alee | and thats because I use it in my puppet-openstack ci test | 17:22 |
alee | and they're all broken now | 17:22 |
alee | redrobot, we need to put a stick in the sand and start thinking about api compatibility | 17:23 |
silos | I think this also raises the necessity for better testing. I feel like backwards compatibility should be a common use case when testing changes to the client. | 17:25 |
alee | silos, yes | 17:25 |
*** krotscheck is now known as krotscheck_dr | 17:27 | |
openstackgerrit | Merged openstack/barbican: Typo change Barbican to barbican Closes-Bug: 1542508 https://review.openstack.org/276939 | 17:43 |
openstack | bug 1542508 in Barbican "Welcome page typo" [Undecided,In progress] https://launchpad.net/bugs/1542508 - Assigned to Luz Cazares (luz-cazares) | 17:43 |
*** insequent has quit IRC | 17:51 | |
*** su_zhang has joined #openstack-barbican | 17:53 | |
*** jhfeng has joined #openstack-barbican | 17:55 | |
*** fredyx101 has joined #openstack-barbican | 17:56 | |
*** fredyx101 has quit IRC | 17:56 | |
*** fredyx101 has joined #openstack-barbican | 17:57 | |
*** alee is now known as alee_lunch | 17:58 | |
*** fredyx10 has quit IRC | 17:59 | |
*** mp1 has quit IRC | 18:01 | |
*** jhfeng has quit IRC | 18:01 | |
*** fredyx101 has quit IRC | 18:02 | |
*** fredyx10 has joined #openstack-barbican | 18:10 | |
*** mp1 has joined #openstack-barbican | 18:15 | |
*** jhfeng has joined #openstack-barbican | 18:19 | |
*** fredyx10 has quit IRC | 18:21 | |
*** fredyx10 has joined #openstack-barbican | 18:22 | |
*** ccneill has quit IRC | 18:25 | |
*** insequent has joined #openstack-barbican | 18:34 | |
*** silos is now known as silos_away | 18:41 | |
*** gyee has quit IRC | 18:44 | |
*** ccneill has joined #openstack-barbican | 18:49 | |
*** silos_away has quit IRC | 18:55 | |
*** ccneill has quit IRC | 18:55 | |
openstackgerrit | Douglas Mendizábal proposed openstack/barbican: Update and reorganize the doc landing page. https://review.openstack.org/281607 | 18:57 |
*** mp1 has quit IRC | 18:59 | |
*** jaosorior has quit IRC | 19:04 | |
hockeynut | greetings barbicaneers - not sure why I feel like being a masochist but I am digging into content types today and I want to pose a question for y'all. | 19:06 |
hockeynut | specifically talking about GET secret with /payload | 19:06 |
hockeynut | and Accept header | 19:06 |
hockeynut | old (and likely incorrect) behavior - when you create a secret as binary, then GET /payload with accept:text/plain it will convert for you | 19:07 |
hockeynut | we have tests (RSA in particular) that validate that behavior | 19:07 |
hockeynut | I am working on a CR to fix a few http 500 errors in get secret payload with Accept header and one side effect is that we will no longer do that automagic conversion | 19:08 |
woodster_ | hockeynut: I thought we had decided not to do conversions a long time ago... :\ | 19:09 |
hockeynut | before I put the CR up and then run like holy hell I want to run it past y'all. In particular I'd like to hear from Ozz (who isn't on at the moment) dave-mccowan rellerreller and some of the other oldtimers who have felt the content type pain before :-) | 19:10 |
hockeynut | woodster_ thats what I thought, but the RSA tests seem to say otherwise. Unless they were written to the behavior which now appears to be incorrect. | 19:10 |
hockeynut | I will gladly dig thru those tests and update and we could discuss on gerrit, but this is a heads up to be sure that no one is depending on that behavior in the real world | 19:11 |
rellerreller | hockeynut what are you seeing? | 19:12 |
rellerreller | Can you provide more details? I'm imagining that you are inputting a secret as base64(pem(pkcs#8)). | 19:14 |
rellerreller | hockeynut what is the return you are seeing? | 19:14 |
hockeynut | an example: RSATestCase.test_rsa_store_and_get_container_with_passphrase now fails with a 406 because the content type passed in doesn't match the content type used when the secret was created | 19:15 |
hockeynut | (that content type match enforcement is new with my fix) | 19:17 |
*** mp1 has joined #openstack-barbican | 19:17 | |
rellerreller | hockeynut I did not think that there was any conversion on the return. I thought everything was expected in base64 format and returned in that format. | 19:18 |
rellerreller | hockeynut It's been so long, and I've tried to erase this from memory. I can't remember anymore. | 19:18 |
hockeynut | rellerreller if you create a secret with base64 then retrieve with text you can see what I mean. I took the text string"mypayload"...base64'd it...and used that to create a binary secret. Then I did a GET /payload with Accept:text/plain and I got back "mypayload" | 19:19 |
hockeynut | and you, sir, are very smart to forgot anything remotely related to content type | 19:19 |
hockeynut | and we shall see how client tests handle it | 19:20 |
* hockeynut is regretting going into programming, especially when crime pays so much better | 19:20 | |
*** alee_lunch is now known as alee | 19:28 | |
*** mp1 has quit IRC | 19:29 | |
*** su_zhang has quit IRC | 19:31 | |
*** mp1 has joined #openstack-barbican | 19:32 | |
diazjf | redrobot ping | 19:48 |
*** silos has joined #openstack-barbican | 19:52 | |
*** ccneill has joined #openstack-barbican | 19:53 | |
*** ccneill has left #openstack-barbican | 19:56 | |
*** gyee has joined #openstack-barbican | 19:58 | |
*** mp1 has quit IRC | 20:01 | |
*** mp1 has joined #openstack-barbican | 20:02 | |
*** insequent has quit IRC | 20:03 | |
*** fnaval_ has joined #openstack-barbican | 20:07 | |
*** silos has quit IRC | 20:11 | |
*** fnaval has quit IRC | 20:12 | |
*** stevemar has quit IRC | 20:12 | |
*** stevemar has joined #openstack-barbican | 20:13 | |
*** jhfeng has quit IRC | 20:23 | |
*** mp1 has quit IRC | 20:29 | |
*** jhfeng has joined #openstack-barbican | 20:29 | |
*** silos has joined #openstack-barbican | 20:29 | |
*** mp1 has joined #openstack-barbican | 20:29 | |
silos | redrobot, alee: I made an etherpad with my initial thoughts for revamping the client: https://etherpad.openstack.org/p/barbican-client-v2 | 20:32 |
silos | I will mention it again in Monday's meeting. | 20:32 |
silos | For everyone. | 20:32 |
*** insequent has joined #openstack-barbican | 20:33 | |
*** rellerreller has quit IRC | 21:00 | |
redrobot | diazjf pong | 21:00 |
*** silos has left #openstack-barbican | 21:00 | |
*** silos has joined #openstack-barbican | 21:00 | |
diazjf | redrobot, just wanted to see if you have a scheduled time for the guild meetup next week, and I just checked http://lists.openstack.org/pipermail/openstack-dev/2016-February/086581.html got all 5 votes :)!!!!!! | 21:02 |
redrobot | diazjf I don't have a time yet.. still working with my boss to get something scheduled. | 21:03 |
redrobot | diazjf do you have a preference for Austin vs SA, or all-day/afternoon+evening/evening only? | 21:03 |
diazjf | redrobot, no preference, whatever works for you. | 21:04 |
*** tkelsey has quit IRC | 21:06 | |
openstackgerrit | Fernando Diaz proposed openstack/barbican: WIP: User Metadata API and tests https://review.openstack.org/275885 | 21:07 |
openstackgerrit | Jeff Feng proposed openstack/barbican: Introducing barbican-manage utility command https://review.openstack.org/282059 | 21:10 |
alee | silos, thanks - will take a look shortly | 21:19 |
*** silos has quit IRC | 21:19 | |
mp1 | silos great suggestions for client changes; I made some comments on the etherpad | 21:19 |
*** silos has joined #openstack-barbican | 21:21 | |
*** su_zhang has joined #openstack-barbican | 21:57 | |
*** chlong has quit IRC | 21:57 | |
*** chlong_ has joined #openstack-barbican | 21:58 | |
*** dave-mccowan has quit IRC | 22:26 | |
*** diazjf has quit IRC | 22:31 | |
*** silos has left #openstack-barbican | 22:38 | |
*** mp1 has quit IRC | 22:47 | |
*** mp1 has joined #openstack-barbican | 22:48 | |
*** mp1 has quit IRC | 23:02 | |
*** alee has quit IRC | 23:03 | |
*** tkelsey has joined #openstack-barbican | 23:04 | |
*** tkelsey has quit IRC | 23:08 | |
*** jamielennox is now known as jamielennox|away | 23:20 | |
*** fredyx10 has quit IRC | 23:27 | |
*** nkinder has quit IRC | 23:28 | |
*** cheneydc has joined #openstack-barbican | 23:33 | |
*** dimtruck is now known as zz_dimtruck | 23:37 | |
*** cheneydc has quit IRC | 23:38 | |
*** dave-mccowan has joined #openstack-barbican | 23:41 | |
*** openstackgerrit has quit IRC | 23:47 | |
*** openstackgerrit_ is now known as openstackgerrit | 23:47 | |
*** openstackgerrit_ has joined #openstack-barbican | 23:47 | |
*** openstackgerrit_ is now known as openstackgerrit | 23:48 | |
*** openstackgerrit_ has joined #openstack-barbican | 23:49 | |
*** chlong_ has quit IRC | 23:52 | |
*** openstackgerrit_ has quit IRC | 23:55 | |
*** openstackgerrit_ has joined #openstack-barbican | 23:56 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!