Wednesday, 2013-09-11

*** Tross has joined #openstack-dev00:01
*** alop has quit IRC00:03
*** ecarlin has joined #openstack-dev00:04
*** ecarlin has left #openstack-dev00:05
*** kbrierly has quit IRC00:06
*** jhesketh has joined #openstack-dev00:08
*** sushils has quit IRC00:09
*** freedomhui has joined #openstack-dev00:10
*** sthaha has joined #openstack-dev00:10
*** Ryan_Lane has quit IRC00:11
*** epim has quit IRC00:15
*** reed has quit IRC00:19
*** jasdeepH has quit IRC00:20
*** Tross has quit IRC00:22
*** colinmcnamara has joined #openstack-dev00:23
morganfainberganteaya, btw, product guy says blog is so far so good.00:27
morganfainberganteaya, thought you'd want to know :)00:27
anteayamorganfainberg: thank you00:28
anteaya:D00:28
anteayathanks to product guy00:28
roaetanteaya: may I see the blog? :D00:29
anteayasure00:29
morganfainbergroaet, it's awesome00:30
roaetmorganfainberg: you're awesome!00:30
anteayaroaet: this is the post I believe we are talking about: http://anteaya.info/blog/2013/09/01/installing-devstack-with-vagrant/00:30
morganfainbergayup00:30
morganfainbergthats the one anteaya00:30
*** spzala has joined #openstack-dev00:31
*** jhesketh__ has joined #openstack-dev00:31
*** mangelajo has joined #openstack-dev00:31
*** jhesketh has quit IRC00:32
*** xarses has quit IRC00:32
roaetanteaya: oh that's awesome. I'll forward it to my crew00:32
*** jhesketh has joined #openstack-dev00:32
*** Tross has joined #openstack-dev00:32
anteayaroaet: thank you, yes do pass it around00:32
roaetanteaya: a few folk in my crew use vagrant00:32
anteayait comes in handy00:33
anteayait has limitations but it is an easy jumping off point00:33
morganfainberganteaya, i might owe you a beer for saving me a lot of headache explaining vagrant to the product guy...00:34
anteayamorganfainberg: too bad I don't drink00:34
anteayamind if we negotiate for a tea00:34
morganfainberganteaya, s/beer/coffee? ok tea00:34
anteayawe will be in hong kong so I can find a fancy one00:35
morganfainbergthat works00:35
anteaya:D00:35
anteayathanks00:35
* morganfainberg is a tea snob when i can afford to be.00:35
anteayaright on00:35
anteayafound yellow and red tea in Montreal00:35
morganfainbergusually i'm too busy and fall back to coffee.00:35
anteayanever had them before00:35
anteayaI can't do coffee either00:35
anteayacaffinee and I don't do well00:35
morganfainbergI used to work w/ a british guy when i worked at blizzard.  he always had the best earl grey when he came back from visiting family00:35
anteayanice00:36
*** nosnos has joined #openstack-dev00:36
anteayaI could go for a nice earl grey00:36
anteayathere should be a few options in HK00:36
* morganfainberg loves a good bergamot tea.00:36
morganfainbergoh i am sure HK is going to have some very fine teas00:37
*** colinmcnamara has quit IRC00:37
*** Tross has quit IRC00:38
roaetI love me some earl grey. Man I should make some.00:38
roaetAll these great ideas in here.00:38
*** mangelajo has quit IRC00:41
*** markwash has joined #openstack-dev00:41
*** xmltok has quit IRC00:41
*** angdraug has quit IRC00:41
anteayamorganfainberg: I have bergamot in my garden00:41
morganfainberganteaya, i am jealous00:42
anteayaI always think I should pick the leaves in the fall and save them and I never do00:42
morganfainbergyou totally should!00:42
anteayado you have any place for a garden00:42
anteayabergamot grows anywhere00:42
anteayasun, shade acidic soil00:42
morganfainberganteaya, unfortunately, no.  well, i could try and do it potted on my balcony00:42
anteayaI saw a full garden of it under pine trees00:42
morganfainbergurban style00:43
morganfainberg:P00:43
morganfainbergwould actually probably be an awesome plant to have.00:43
morganfainberg"plant"00:43
anteayanothing grows in soil made acid by pine needles but bergamot does00:43
anteayait is, very tall too00:43
morganfainbergmaybe i'll plant some at my parent's house (in the mountains)00:43
anteayaroaet: always a good time for earl grey00:43
anteayamorganfainberg: bet it will grow00:43
roaetanteaya: ain't that the truth.00:43
morganfainberganteaya, likely.  wonder if it'd grow where the maple (sadly) died.00:44
morganfainbergbad soil there.00:44
anteayabet it would00:44
anteayatoo bad the maple died00:44
* anteaya goes outside to check the bergamot00:44
morganfainberganteaya, yeah the maple (was a volunteer) just couldn't handle the soil after a year or so.00:45
*** SumitNaiksatam has quit IRC00:45
morganfainbergit's also a cedar forest up there, so, who knows what got the maple… might have even been some kind of bark-beetle00:46
roaetI wonder if I can grow bergamot.00:46
anteayaroaet: what else grows around there?00:48
anteayamorganfainberg: cedar is acidic like pine00:48
morganfainberganteaya, aye00:48
anteayathat might have killed the maple, the pH of the soil00:48
*** pmathews has quit IRC00:49
morganfainberganteaya, and it doesn't help that it was the dumping ground for some "potting" soil w/ extra nitrate / nitrite nutrients00:49
roaetanteaya: I'm checking the hardiness level of my area.00:49
anteayaall the flower petals are gone but lots of leaves, citrusy and peppery00:49
anteayamorganfainberg: hmmmm00:49
anteayaroaet: k00:49
morganfainberganteaya, probably a combination of stuff.00:49
morganfainberganteaya, i've decided, going to see if i can find a dwarf bergamot tree :)  put it on my balcony00:50
roaetanteaya: about 3 hours away there is a part of the state that grows citrus all over, but I think I'm just out of that climate.00:50
roaetI guess I could keep it inside every now and then, but we get freezes randomly.00:50
anteayamorganfainberg: that would be pretty00:51
anteayaroaet: we get frost all winter00:51
*** MIDENN_ has joined #openstack-dev00:51
*** branen_ has joined #openstack-dev00:51
anteayabergamot grows back00:51
anteayaroaet: I'm in Canada00:51
*** s00pcan has quit IRC00:52
anteayaI'd say I'm zone 400:52
anteayaor 300:52
morganfainberganteaya, i think i'll just need to make sure to water it more in the summer (>101 for the last week or so)00:53
anteayaah yeah00:53
anteayaearly morning water or late at night00:53
anteayanot during the heat of the day00:53
*** Tross has joined #openstack-dev00:54
morganfainberganteaya, aye. and don't leave water on the leaves when the sun is hitting it (poor rose bushes at my neighbors house)00:54
morganfainbergburnt leaves because of that00:54
*** fabio_ has joined #openstack-dev00:54
anteaya:(00:54
anteayapoor roses00:54
morganfainbergyeah00:54
anteayaI can't grow roses00:54
*** mdenny has quit IRC00:54
morganfainbergtoo much frost?00:54
anteayano i suck at growing roses00:54
roaetanteaya: I'm in texas, and I think we can grow them.00:55
*** fabio has quit IRC00:55
*** branen has quit IRC00:55
morganfainberganteaya, hehe00:55
anteayaroaet: you are good00:55
anteayaI need a plant that thrives on neglect that is so pungent that the deer won't eat it00:55
roaetcatnip!00:56
morganfainbergroaet, bamboo! :P00:56
anteayalavender, day lilies, hyssop, horseradish, thyme, tarragon, mint, oregano00:56
roaetbamboo is an evil plant.00:56
anteayais it?00:56
morganfainberganteaya, can't get rid of it00:56
anteayareally?00:56
anteayathat would be awesome00:56
roaetI had a bit in my backyard and spent 4 days digging it up, 2 years later.. right back again00:56
roaetIt's a curse00:56
anteayaI would grow a stand of bamboo and then make a yurt00:56
roaetInvasive and cannot be destroyed without salting the earth00:57
morganfainberganteaya really, very hard to remove.  keeps growing back.  a lot of places prevent the planting of it.  it'll destroy cement etc00:57
morganfainbergand it grows insanely fast00:57
anteayaawesome00:57
*** matiu has quit IRC00:57
roaetmorganfainberg: I had this crazy idea to be bamboo-appleseed and just drop random shoots around my neighborhood (when I was a punk kid)00:57
anteayawhen it gets to be an inch in diameter and 6 feet long cut it off and ship it to me00:57
morganfainbergroaet, you're evil ;)00:57
anteayaabout 72 pieces should do00:57
*** vipul is now known as vipul-away00:57
morganfainberganteaya, my old place had either bamboo or sugarcane00:58
morganfainbergnever figured out which00:58
morganfainbergit was a pain to deal with00:58
anteayahow did it taste?00:58
morganfainbergnever tried.00:58
anteayashame00:58
*** pixelb has quit IRC00:58
roaetthey are both evil00:59
morganfainbergi wasn't bold enough with the health of the plant (owners neglected it a lot before i moved in)00:59
anteayaoh00:59
* roaet has some earl grey steeped, mmmm00:59
*** adjohn has quit IRC00:59
anteayanice00:59
* morganfainberg is jealous of roaet.00:59
*** vipul-away is now known as vipul00:59
morganfainberganteaya, lets see how well devstack stands up keystone with an LDAP backend.01:00
anteayayes let's01:00
morganfainbergalmost done stacking actually.01:00
roaetI was working on a devstack alternative, called zenstack, but I have given up on it since devstack is pretty good01:00
anteayaisn't there a movement away from LDAP?01:00
morganfainberganteaya, there is, but i'm actually working on a bug01:01
roaetIt had some features I preferred, I'd like to put them into devstack someday01:01
anteayaroaet: can you share your code?01:01
anteayamorganfainberg: ah01:01
roaetanteaya: https://github.com/roaet/zenstack01:01
morganfainberganteaya, and we're not moving away from LDAP, just possibly looking to deprecate LDAP assignment backend01:01
morganfainbergsince identity and assignment don't need ot be 1-in-the-same now01:01
roaetIt uses tmux and runs all services in venvs01:02
roaetAnd instead of making a bazillion screens it splits panes01:02
morganfainbergroaet, i've been tempted to try and use anvil to build my dev environment01:02
morganfainbergroaet, not a bad idea.01:02
morganfainbergthe vnenv part would be nice01:02
roaetI'd like to help with devstack, no idea how to start though01:02
morganfainbergactually… i want to roll out production openstack using venvs personally.01:02
roaeti believe we do that, but I probably can't confirm that.01:03
anteayamorganfainberg: ah okay01:03
anteayaroaet: are you in the #openstack-qa channel01:03
*** faramir has joined #openstack-dev01:03
anteayamany of the devstack devs are in there01:03
*** Tross has quit IRC01:03
roaetI am now :D01:03
roaetI gotta figure out how to manage these channels. I have over 50 open now01:04
morganfainbergroaet, what OS?01:04
morganfainberglinux? windows? mac?01:04
*** jhesketh has quit IRC01:04
clarkbweechat/irssi in screen/tmux and done :)01:05
morganfainberg*shameless plug* I use ZNC bouncer, textual, and store IRC logs on my google drive (so i can search later)01:05
*** jhesketh has joined #openstack-dev01:05
roaetmorganfainberg: prety much what clarkb said01:05
roaetheh01:05
morganfainbergthough, i only really reside in ~10 channels at a time now.01:06
roaeti have too many things01:06
*** Tross has joined #openstack-dev01:07
morganfainbergroaet, you know the real solution to that is, right? :P01:07
anteayaroaet: that's a theme song01:07
anteayawe need some music for that01:07
morganfainberganteaya ++01:08
roaetmorganfainberg: have less? :)01:08
*** stevemar has joined #openstack-dev01:08
*** xarses has joined #openstack-dev01:11
*** erkules_ has joined #openstack-dev01:12
*** ayoung has joined #openstack-dev01:13
*** erkules has quit IRC01:14
*** slagle has joined #openstack-dev01:16
morganfainberganteaya, oh boy i somehow got the memory thing for vmware vboxes wrong.01:21
morganfainbergnot so successful in starting up a devstack w/ 500MB of ram :P01:21
anteayathat would be a feat01:22
*** SumitNaiksatam has joined #openstack-dev01:22
anteayalet me know when you and product guy have that config working01:22
anteayait would be a blog post01:22
morganfainberganteaya, most people don't use the VMWare provider for vagrant01:22
morganfainbergdon't know if it's something I'd recommend adding as a blog.01:22
morganfainbergbesides, it costs like an extra $80 for the vagrant plugin, on top of the cost of vmware fusion/workstation01:23
clarkband after the virtualbox relicense there is a lot less funny with using it01:24
morganfainbergclarkb, virtualbox relicense?01:24
clarkbmorganfainberg: oracle GPLd most of it, but prior to oracle it had a funny license for non personal use01:25
morganfainbergclarkb oh yes01:25
*** freedomhui has quit IRC01:26
anteayamorganfainberg: I had mis-read what you had typed - you had typed 500MB and I had read 500GB01:30
anteayamy mistake01:30
*** terriyu has quit IRC01:31
*** freedomhui has joined #openstack-dev01:32
*** freedomhui has quit IRC01:32
*** freedomhui has joined #openstack-dev01:33
*** slagle has quit IRC01:33
*** danwent has quit IRC01:34
*** Tross has quit IRC01:35
*** kushal has joined #openstack-dev01:36
*** mangelajo has joined #openstack-dev01:37
*** chenxu has joined #openstack-dev01:44
*** slagle has joined #openstack-dev01:44
*** mangelajo has quit IRC01:47
*** melwitt has quit IRC01:49
*** freedomhui has quit IRC01:51
*** medberry is now known as med_01:52
*** slagle has quit IRC01:57
*** yaguang has joined #openstack-dev01:58
*** davi67232 has joined #openstack-dev01:58
*** d34dh0r53 has joined #openstack-dev01:59
*** edmund has joined #openstack-dev02:00
morganfainbergayoung / gyee, ping02:00
*** ljjjustin has joined #openstack-dev02:00
*** d34dh0r53 has quit IRC02:01
*** gyee has quit IRC02:03
*** novas0x2a|laptop has quit IRC02:04
*** freedomhui has joined #openstack-dev02:05
*** gyee has joined #openstack-dev02:06
*** alexxu has joined #openstack-dev02:09
*** SergeyLukjanov has joined #openstack-dev02:13
*** colinmcnamara has joined #openstack-dev02:15
ayoungmorganfainberg, the person you have reached, ayoung, is no longer in service.  PLease check your irc handle and try again.02:15
*** ayoung is now known as admiyo02:16
* admiyo hiding from morganfainberg 02:16
morganfainbergadmiyo, hehe02:18
*** eharney has joined #openstack-dev02:20
morganfainbergadmiyo, https://bugs.launchpad.net/keystone/+bug/1219739 this looks like it might be simply invalid?  I don't see a reference to "tenantId" or even "tenant_id" (or project variants) on the user objects when using the LDAP backend.02:20
uvirtbotLaunchpad bug 1219739 in keystone "LDAP use 'tenant_id' instead of 'tenantId' in user_ref" [Medium,New]02:20
morganfainbergadmiyo, am i just mis-understanding where that information is stored?02:20
morganfainbergfrom what i can see, we don't store "tenantId" in ldap on the user object.02:22
*** galstrom_zzz is now known as galstrom02:22
*** davi67232 has quit IRC02:22
morganfainbergor even extra data really… but i might be missing how that is encoded.02:23
* morganfainberg keeps looking. I feel like i'm just missing something02:25
*** xchu has joined #openstack-dev02:26
*** kbrierly has joined #openstack-dev02:26
morganfainbergor are they complaining that we reference tenant_id when updating/creating a user instead of tenantId ?02:27
*** martine has joined #openstack-dev02:27
*** martine is now known as Guest7323402:28
*** Ruetobas has joined #openstack-dev02:29
*** anteaya_ has joined #openstack-dev02:31
*** lnxnut has joined #openstack-dev02:31
*** anteaya has quit IRC02:32
*** xchu has quit IRC02:34
*** Ruetobas has quit IRC02:35
*** Ruetobas has joined #openstack-dev02:35
*** davi67232 has joined #openstack-dev02:35
*** anteaya_ has quit IRC02:37
*** marun has quit IRC02:39
*** davi67232 has quit IRC02:41
*** salv-orlando has quit IRC02:41
*** salv-orlando_ has joined #openstack-dev02:41
*** xchu has joined #openstack-dev02:42
*** mangelajo has joined #openstack-dev02:43
*** Ruetobas has quit IRC02:43
*** xchu has quit IRC02:47
*** davi67232 has joined #openstack-dev02:47
*** stevemar has quit IRC02:48
*** otherwiseguy has joined #openstack-dev02:49
*** gyee has quit IRC02:51
*** mangelajo has quit IRC02:52
*** salv-orlando_ has quit IRC02:52
*** salv-orlando has joined #openstack-dev02:53
*** colinmcnamara has quit IRC02:53
*** dims has quit IRC02:54
*** wenjianhn has joined #openstack-dev02:56
*** colinmcnamara has joined #openstack-dev02:56
*** radsy has joined #openstack-dev02:57
*** galstrom is now known as galstrom_zzz02:58
*** davi67232 has quit IRC02:58
*** jimfehlig has joined #openstack-dev03:02
*** salv-orlando has quit IRC03:05
*** xchu has joined #openstack-dev03:06
*** salv-orlando has joined #openstack-dev03:06
*** galstrom_zzz is now known as galstrom03:07
*** spzala has quit IRC03:10
*** SergeyLukjanov has quit IRC03:10
*** salv-orlando_ has joined #openstack-dev03:11
*** salv-orlando has quit IRC03:11
*** salv-orlando_ is now known as salv-orlando03:11
*** vipul has quit IRC03:11
*** bdpayne has quit IRC03:11
*** vipul has joined #openstack-dev03:12
*** chenxu has quit IRC03:15
*** lnxnut has quit IRC03:17
*** salv-orlando_ has joined #openstack-dev03:18
*** salv-orlando has quit IRC03:18
*** salv-orlando_ is now known as salv-orlando03:18
*** ljjjustin has quit IRC03:19
*** paragan has joined #openstack-dev03:19
*** paragan has joined #openstack-dev03:19
*** Guest73234 has quit IRC03:21
*** davi67232 has joined #openstack-dev03:25
*** bdpayne has joined #openstack-dev03:28
*** stevemar has joined #openstack-dev03:28
*** kushal has quit IRC03:30
*** ljjjustin has joined #openstack-dev03:32
*** otherwiseguy has quit IRC03:32
*** galstrom is now known as galstrom_zzz03:35
*** Tross has joined #openstack-dev03:36
*** schwicht has quit IRC03:36
*** salv-orlando has quit IRC03:38
*** salv-orlando has joined #openstack-dev03:39
*** herndon_ has joined #openstack-dev03:40
*** colinmcnamara has quit IRC03:41
*** shang has joined #openstack-dev03:43
*** colinmcnamara has joined #openstack-dev03:46
*** salv-orlando has quit IRC03:46
*** salv-orlando has joined #openstack-dev03:46
*** sarob has joined #openstack-dev03:47
*** Mandell has quit IRC03:47
*** HenryG has quit IRC03:49
*** colinmcnamara has quit IRC03:49
*** mangelajo has joined #openstack-dev03:50
*** sarob has quit IRC03:53
*** sarob has joined #openstack-dev03:54
*** xchu has quit IRC03:54
*** sridevi has joined #openstack-dev03:55
*** sarob has quit IRC03:58
*** mangelajo has quit IRC03:58
*** salv-orlando has quit IRC03:59
*** salv-orlando has joined #openstack-dev03:59
*** eharney has quit IRC04:00
*** salv-orlando has quit IRC04:02
*** salv-orlando_ has joined #openstack-dev04:02
*** herndon_ has quit IRC04:02
*** salv-orlando has joined #openstack-dev04:06
*** salv-orlando_ has quit IRC04:06
*** edmund has quit IRC04:10
*** jimfehlig has quit IRC04:11
*** xchu has joined #openstack-dev04:12
*** salv-orlando_ has joined #openstack-dev04:14
*** salv-orlando has quit IRC04:14
*** salv-orlando_ is now known as salv-orlando04:14
*** gordc has joined #openstack-dev04:19
*** kushal has joined #openstack-dev04:19
*** jasdeepH has joined #openstack-dev04:21
*** kaushikc has joined #openstack-dev04:21
*** noslzzp has joined #openstack-dev04:24
*** CaptTofu_ has joined #openstack-dev04:28
*** salv-orlando_ has joined #openstack-dev04:29
*** salv-orlando has quit IRC04:29
*** salv-orlando_ is now known as salv-orlando04:29
*** shang has quit IRC04:29
*** CaptTofu has quit IRC04:30
*** shang has joined #openstack-dev04:32
*** salv-orlando_ has joined #openstack-dev04:33
*** salv-orlando has quit IRC04:33
*** salv-orlando_ is now known as salv-orlando04:33
*** prekarat has joined #openstack-dev04:34
*** jasdeepH has quit IRC04:35
*** freedomhui has quit IRC04:38
*** garyk has quit IRC04:39
*** adjohn has joined #openstack-dev04:42
*** davi67232 has quit IRC04:43
*** gordc has quit IRC04:44
*** salv-orlando_ has joined #openstack-dev04:50
*** salv-orlando has quit IRC04:50
*** salv-orlando_ is now known as salv-orlando04:50
*** boris-42 has joined #openstack-dev04:51
*** noslzzp has quit IRC04:51
*** adjohn_ has joined #openstack-dev04:52
*** zaitcev has quit IRC04:53
*** mangelajo has joined #openstack-dev04:54
*** adjohn has quit IRC04:55
*** Ryan_Lane has joined #openstack-dev05:01
*** adjohn has joined #openstack-dev05:03
*** adjohn_ has quit IRC05:04
*** sridevi has quit IRC05:12
*** freedomhui has joined #openstack-dev05:13
*** kaushikc has quit IRC05:21
*** dmakogon_ has joined #openstack-dev05:22
*** radsy has quit IRC05:26
*** jasdeepH has joined #openstack-dev05:28
*** skraynev has quit IRC05:30
*** aeperezt has quit IRC05:30
*** mrunge has joined #openstack-dev05:31
*** skraynev has joined #openstack-dev05:34
*** neoXsys has quit IRC05:38
*** Max__ has joined #openstack-dev05:40
*** Mandell has joined #openstack-dev05:44
*** stevemar has quit IRC05:44
*** jasdeepH has quit IRC05:46
*** Mandell has quit IRC05:47
*** sridevi has joined #openstack-dev05:48
*** freedomhui has quit IRC05:48
*** neoXsys has joined #openstack-dev05:55
*** vartom9 has joined #openstack-dev05:56
*** sarob has joined #openstack-dev05:56
*** nshaikh has joined #openstack-dev05:58
*** rdopieralski has joined #openstack-dev05:59
*** prekarat has quit IRC06:02
*** egallen has joined #openstack-dev06:03
*** erkules_ is now known as erkules06:03
*** RajeshMohan has quit IRC06:05
*** RajeshMohan has joined #openstack-dev06:05
*** marios has joined #openstack-dev06:06
*** jhesketh has quit IRC06:06
*** jhesketh has joined #openstack-dev06:07
*** bdpayne has quit IRC06:07
*** egallen has quit IRC06:07
*** amotoki has quit IRC06:07
*** rdopieralski has quit IRC06:08
*** rdopieralski has joined #openstack-dev06:08
*** rdopieralski has quit IRC06:09
*** rdopieralski has joined #openstack-dev06:09
*** rdopieralski has joined #openstack-dev06:09
*** RajeshMohan has quit IRC06:10
*** gargya_ has joined #openstack-dev06:10
*** gargya_ is now known as gargya06:10
*** RajeshMohan has joined #openstack-dev06:10
*** sumanthns has joined #openstack-dev06:11
*** salv-orlando has quit IRC06:11
*** garyk has joined #openstack-dev06:11
*** salv-orlando has joined #openstack-dev06:11
*** bdpayne has joined #openstack-dev06:12
*** RajeshMohan has quit IRC06:14
*** RajeshMohan has joined #openstack-dev06:14
*** afazekas has joined #openstack-dev06:15
*** _anant has joined #openstack-dev06:17
*** salv-orlando has quit IRC06:17
*** salv-orlando has joined #openstack-dev06:18
*** gargya has quit IRC06:21
*** RajeshMohan has quit IRC06:21
*** RajeshMohan has joined #openstack-dev06:22
*** RajeshMohan has quit IRC06:22
*** prekarat has joined #openstack-dev06:22
*** RajeshMohan has joined #openstack-dev06:22
*** amotoki has joined #openstack-dev06:23
*** jasdeepH has joined #openstack-dev06:23
*** iartarisi has joined #openstack-dev06:24
*** o_petit has joined #openstack-dev06:24
*** sarob has quit IRC06:26
lifelessis the "Member" role that devstack makes needed in real clouds, or is _member_ sufficient ?06:26
*** sarob has joined #openstack-dev06:26
*** sridevi has quit IRC06:27
*** henrynash has joined #openstack-dev06:28
*** avishay has joined #openstack-dev06:29
*** Mandell has joined #openstack-dev06:31
*** Max__ has quit IRC06:31
*** sarob has quit IRC06:31
*** mars has quit IRC06:34
*** mars has joined #openstack-dev06:35
*** bdpayne has quit IRC06:36
*** henrynash has quit IRC06:40
*** doron_afk has joined #openstack-dev06:47
*** gargya has joined #openstack-dev06:52
*** mmagr has joined #openstack-dev06:53
*** athomas has quit IRC06:54
*** athomas has joined #openstack-dev06:56
*** reidrac has joined #openstack-dev06:59
*** rushiagr has joined #openstack-dev07:02
*** yolanda has joined #openstack-dev07:03
*** giulivo has quit IRC07:07
*** networkstatic has joined #openstack-dev07:09
*** Mandell has quit IRC07:09
*** tkammer has joined #openstack-dev07:11
*** marios_ has joined #openstack-dev07:15
*** arnaud has joined #openstack-dev07:18
*** salv-orlando has quit IRC07:18
*** bswrchrd has quit IRC07:20
*** marios has quit IRC07:21
*** marios_ has quit IRC07:21
*** marios has joined #openstack-dev07:22
*** marios has joined #openstack-dev07:25
*** vishy has quit IRC07:26
*** gimps has quit IRC07:26
*** vishy has joined #openstack-dev07:29
*** Traktopel has joined #openstack-dev07:29
*** flaper87|afk is now known as flaper8707:29
*** devvesa has joined #openstack-dev07:30
*** henrynash has joined #openstack-dev07:31
*** danpb has joined #openstack-dev07:31
*** dmakogon_ has quit IRC07:34
*** boris-42 has quit IRC07:35
*** romcheg has joined #openstack-dev07:35
*** gargya has quit IRC07:36
*** JordanP has joined #openstack-dev07:36
*** sarob has joined #openstack-dev07:37
*** marios has quit IRC07:38
*** marios has joined #openstack-dev07:38
*** xqueralt-afk is now known as xqueralt07:39
*** sarob has quit IRC07:41
*** mangelajo_ has joined #openstack-dev07:46
*** mangelajo has quit IRC07:46
*** yves has joined #openstack-dev07:46
*** jistr has joined #openstack-dev07:47
*** jhesketh has quit IRC07:48
*** kbrierly has quit IRC07:48
*** yassine has joined #openstack-dev07:49
*** fbo_away is now known as fbo07:50
*** AnilV4 has joined #openstack-dev07:50
*** corXi has joined #openstack-dev07:50
*** Max__ has joined #openstack-dev07:51
*** Max__ has quit IRC07:52
*** xga has joined #openstack-dev07:53
*** vartom10 has joined #openstack-dev07:55
*** vartom9 has quit IRC07:55
*** pichuang has left #openstack-dev07:56
*** Max__ has joined #openstack-dev07:57
*** mangelajo_ has quit IRC07:57
*** eglynn has joined #openstack-dev07:57
*** xga_ has quit IRC07:57
*** mangelajo has joined #openstack-dev07:57
*** jasdeepH has quit IRC07:58
*** mangelajo has quit IRC08:00
*** adjohn has quit IRC08:00
*** ifarkas has joined #openstack-dev08:02
*** mattmalesky has quit IRC08:02
*** markwash has quit IRC08:02
*** jprovazn has joined #openstack-dev08:03
*** Ryan_Lane has quit IRC08:05
*** boden has joined #openstack-dev08:06
*** fc__ has quit IRC08:06
*** xga_ has joined #openstack-dev08:07
*** xga has quit IRC08:10
*** safchain has joined #openstack-dev08:13
*** salv-orlando has joined #openstack-dev08:15
*** safchain has quit IRC08:17
*** safchain has joined #openstack-dev08:17
*** lucasagomes has joined #openstack-dev08:19
*** neeti has joined #openstack-dev08:19
*** bashok has joined #openstack-dev08:20
*** rushiagr has quit IRC08:20
*** salv-orlando has quit IRC08:24
*** sushils has joined #openstack-dev08:24
*** Alexei_987 has joined #openstack-dev08:24
*** pixelb has joined #openstack-dev08:28
*** sridevi has joined #openstack-dev08:28
*** gongysh has joined #openstack-dev08:28
*** jpich has joined #openstack-dev08:30
*** adjohn has joined #openstack-dev08:31
*** danpb has quit IRC08:35
*** lsmola has quit IRC08:35
*** Ryan_Lane has joined #openstack-dev08:35
*** Traktopel has quit IRC08:35
*** alexpilotti has joined #openstack-dev08:36
*** salv-orlando has joined #openstack-dev08:36
*** adjohn has quit IRC08:40
*** giulivo has joined #openstack-dev08:41
*** rushiagr has joined #openstack-dev08:41
*** Ryan_Lane has quit IRC08:42
*** fc__ has joined #openstack-dev08:43
*** alexpilotti has quit IRC08:43
*** danpb has joined #openstack-dev08:47
*** boris-42 has joined #openstack-dev08:49
*** lsmola has joined #openstack-dev08:50
*** xchu has quit IRC08:50
*** ifarkas has quit IRC08:51
*** johnthetubaguy has joined #openstack-dev08:51
*** nshaikh has left #openstack-dev08:52
*** martyntaylor has joined #openstack-dev08:53
*** rushiagr has quit IRC08:53
*** e1mer has joined #openstack-dev08:55
*** ifarkas has joined #openstack-dev08:55
*** kushal has quit IRC08:58
*** DeeJay1 has joined #openstack-dev08:58
*** lsmola has quit IRC08:59
*** paragan has quit IRC08:59
*** ndipanov has joined #openstack-dev08:59
*** neeti has quit IRC09:00
*** romcheg has left #openstack-dev09:07
*** adjohn has joined #openstack-dev09:07
*** xchu has joined #openstack-dev09:07
*** Ryan_Lane has joined #openstack-dev09:09
*** adjohn has quit IRC09:11
*** Ryan_Lane has quit IRC09:14
*** lsmola has joined #openstack-dev09:14
*** Max__ has quit IRC09:15
*** Max__ has joined #openstack-dev09:16
*** sridevi has quit IRC09:17
*** sridevi has joined #openstack-dev09:29
*** ljjjustin has quit IRC09:33
*** Alexei_987 has quit IRC09:39
*** paragan has joined #openstack-dev09:39
*** sushils has quit IRC09:42
*** wenjianhn has quit IRC09:43
gongysharosen Ping09:46
*** sushils has joined #openstack-dev09:46
*** xga_ has quit IRC09:46
*** ruhe has joined #openstack-dev09:46
*** xga has joined #openstack-dev09:47
*** paragan has quit IRC09:48
*** sushils has quit IRC09:48
*** kaushikc has joined #openstack-dev09:53
*** sushils has joined #openstack-dev09:53
*** paragan has joined #openstack-dev09:56
*** dguitarbite has joined #openstack-dev09:56
*** rushiagr has joined #openstack-dev09:59
*** sergmelikyan has joined #openstack-dev10:00
*** avishay has quit IRC10:00
*** ruhe has quit IRC10:03
*** romcheg1 has joined #openstack-dev10:04
*** sridevi has quit IRC10:05
*** networkstatic has quit IRC10:09
*** VeggieMeat has joined #openstack-dev10:10
*** apevec has joined #openstack-dev10:10
*** apevec has joined #openstack-dev10:10
*** apevec has left #openstack-dev10:11
*** HenryG has joined #openstack-dev10:11
*** rushiagr has quit IRC10:11
*** nshaikh has joined #openstack-dev10:12
*** kushal has joined #openstack-dev10:12
*** xchu has quit IRC10:13
*** swifterdarrell has quit IRC10:14
*** ruhe has joined #openstack-dev10:17
*** sridevi has joined #openstack-dev10:19
*** swifterdarrell has joined #openstack-dev10:20
*** MIDENN_ has quit IRC10:20
*** rushiagr has joined #openstack-dev10:20
*** prekarat has quit IRC10:20
*** prekarat has joined #openstack-dev10:22
*** doron_afk has quit IRC10:24
*** nshaikh has left #openstack-dev10:28
*** imsurit has joined #openstack-dev10:28
*** paragan has quit IRC10:29
*** kaushikc has quit IRC10:29
*** kaushikc has joined #openstack-dev10:29
*** sridevi has quit IRC10:31
*** tonyfy has joined #openstack-dev10:31
*** schwicht has joined #openstack-dev10:32
*** Max__ has quit IRC10:32
*** rushiagr has quit IRC10:32
*** pcm_ has joined #openstack-dev10:32
*** sridevi has joined #openstack-dev10:33
*** pcm_ has quit IRC10:33
*** pcm_ has joined #openstack-dev10:34
*** o_petit has quit IRC10:34
*** adjohn has joined #openstack-dev10:37
*** CaptTofu_ has quit IRC10:39
*** CaptTofu has joined #openstack-dev10:39
*** faramir has quit IRC10:41
*** adjohn has quit IRC10:42
*** jamielennox is now known as jamielennox|away10:45
*** rushiagr has joined #openstack-dev10:49
*** sridevi has quit IRC10:49
*** swann has left #openstack-dev10:49
*** sridevi has joined #openstack-dev10:50
*** yaguang has quit IRC10:52
*** sridevi_ has joined #openstack-dev10:53
*** lucasagomes has quit IRC10:54
*** lucasagomes has joined #openstack-dev10:55
*** sridevi has quit IRC10:55
*** sridevi_ is now known as sridevi10:55
*** asavu has joined #openstack-dev10:56
*** gongysh has quit IRC10:57
*** alexxu has quit IRC10:58
*** Max__ has joined #openstack-dev11:03
*** dims has joined #openstack-dev11:04
*** imsurit has quit IRC11:04
*** tonyfy has quit IRC11:06
*** morazi has quit IRC11:08
*** Max__ has quit IRC11:08
*** adjohn has joined #openstack-dev11:08
*** mkollaro has joined #openstack-dev11:09
*** nshaikh has joined #openstack-dev11:09
*** Ryan_Lane has joined #openstack-dev11:10
*** adjohn has quit IRC11:13
*** Ryan_Lane has quit IRC11:14
*** alexpilotti has joined #openstack-dev11:14
*** rushiagr has quit IRC11:16
*** sumansn_ has joined #openstack-dev11:20
*** SergeyLukjanov has joined #openstack-dev11:20
*** rushiagr has joined #openstack-dev11:20
*** zbitter is now known as zaneb11:20
*** sumanthns has quit IRC11:22
*** Max__ has joined #openstack-dev11:24
*** doron_afk has joined #openstack-dev11:25
*** imsurit has joined #openstack-dev11:28
*** o_petit has joined #openstack-dev11:29
*** o_petit has quit IRC11:32
*** romcheg has joined #openstack-dev11:32
*** o_petit has joined #openstack-dev11:33
*** neoXsys has quit IRC11:34
*** henrynash has quit IRC11:36
*** romcheg1 has quit IRC11:37
*** jcoufal has joined #openstack-dev11:38
*** adjohn has joined #openstack-dev11:39
*** doron_afk is now known as doron11:40
*** davi67232 has joined #openstack-dev11:41
*** kaushikc has quit IRC11:42
*** jistr is now known as jistr|eng11:42
*** paragan has joined #openstack-dev11:42
*** adjohn has quit IRC11:44
*** FunnyLookinHat has joined #openstack-dev11:46
*** dkranz has joined #openstack-dev11:46
*** terryh has joined #openstack-dev11:49
*** markmcclain has joined #openstack-dev11:50
*** davi67232 has quit IRC11:52
*** Alexei_987 has joined #openstack-dev11:52
*** lucasagomes is now known as lucas-hungry11:53
*** yongli is now known as yongli_away11:54
*** ondergetekende_ has joined #openstack-dev11:54
*** neoXsys has joined #openstack-dev11:57
*** drewlander has joined #openstack-dev11:59
*** kushal has quit IRC12:01
*** ruhe has quit IRC12:01
*** vkmc has joined #openstack-dev12:02
*** martine has joined #openstack-dev12:02
*** _anant has quit IRC12:02
*** martine is now known as Guest5430412:02
*** mkollaro1 has joined #openstack-dev12:03
*** mkollaro has quit IRC12:03
*** ruhe has joined #openstack-dev12:04
*** galstrom_zzz is now known as galstrom12:04
*** morazi has joined #openstack-dev12:05
*** tkammer has quit IRC12:05
*** ruhe has quit IRC12:06
*** afazekas has quit IRC12:06
*** hartsocks has joined #openstack-dev12:07
*** tkammer has joined #openstack-dev12:07
*** o_petit has quit IRC12:09
*** sridevi has quit IRC12:09
*** adjohn has joined #openstack-dev12:10
*** afazekas has joined #openstack-dev12:10
*** amotoki has quit IRC12:10
*** kaushikc has joined #openstack-dev12:11
*** Max__ has quit IRC12:14
*** adjohn has quit IRC12:15
*** Max__ has joined #openstack-dev12:15
*** kaushikc1 has joined #openstack-dev12:16
*** kaushikc has quit IRC12:16
*** shang has quit IRC12:17
*** ruhe has joined #openstack-dev12:17
*** rfolco has joined #openstack-dev12:17
*** kaushikc1 has quit IRC12:18
*** mrunge has quit IRC12:20
*** asavu has quit IRC12:22
*** imsurit has quit IRC12:24
*** noslzzp has joined #openstack-dev12:24
*** dvarga has joined #openstack-dev12:25
*** o_petit has joined #openstack-dev12:26
*** gordc has joined #openstack-dev12:27
*** slagle has joined #openstack-dev12:28
*** dprince has joined #openstack-dev12:31
*** e1mer has quit IRC12:31
*** afazekas has quit IRC12:32
*** markmcclain has quit IRC12:32
*** sandywalsh has quit IRC12:32
*** Max__ has quit IRC12:33
*** Guest54304 is now known as martine_12:35
*** galstrom is now known as galstrom_zzz12:36
*** rwsu has joined #openstack-dev12:36
*** boden has quit IRC12:37
*** jprovazn has quit IRC12:37
*** jprovazn has joined #openstack-dev12:38
*** topol has joined #openstack-dev12:39
*** boden has joined #openstack-dev12:40
*** jasondotstar has joined #openstack-dev12:41
*** o_petit has quit IRC12:43
*** radez_g0n3 is now known as radez12:43
*** sandywalsh has joined #openstack-dev12:44
*** davi67232 has joined #openstack-dev12:45
*** gargya has joined #openstack-dev12:46
*** eharney has joined #openstack-dev12:49
*** ifarkas has quit IRC12:50
*** doron is now known as doron_afk12:51
*** chenxu has joined #openstack-dev12:52
*** afazekas has joined #openstack-dev12:53
*** shang has joined #openstack-dev12:53
*** cthulhup has quit IRC12:53
*** afazekas has quit IRC12:54
*** afazekas has joined #openstack-dev12:54
*** vartom10 has quit IRC12:55
*** iartarisi has quit IRC12:58
*** maheshp has joined #openstack-dev12:59
*** maheshp1 has joined #openstack-dev13:00
*** ruhe has quit IRC13:01
*** davi67232 has quit IRC13:02
*** ifarkas has joined #openstack-dev13:02
*** ruhe has joined #openstack-dev13:03
*** asavu has joined #openstack-dev13:04
*** tkammer has quit IRC13:04
*** tkammer has joined #openstack-dev13:05
*** afazekas has quit IRC13:05
*** doron_afk has quit IRC13:06
*** mkollaro1 has quit IRC13:06
*** anteaya_ has joined #openstack-dev13:06
*** nshaikh has left #openstack-dev13:07
*** nshaikh has quit IRC13:07
*** eglynn has quit IRC13:08
*** alunduil has quit IRC13:08
*** jayg|g0n3 is now known as jayg13:10
*** imsurit has joined #openstack-dev13:10
*** lucas-hungry is now known as lucasagomes13:11
*** adjohn has joined #openstack-dev13:11
*** anteaya_ is now known as anteaya13:13
*** galstrom_zzz is now known as galstrom13:14
*** adjohn has quit IRC13:16
*** clayb has joined #openstack-dev13:17
*** galstrom is now known as galstrom_zzz13:18
*** lucasagomes is now known as lucas-afk13:19
*** otherwiseguy has joined #openstack-dev13:20
*** athomas has quit IRC13:20
*** morazi has quit IRC13:20
*** mkollaro has joined #openstack-dev13:21
*** athomas has joined #openstack-dev13:22
*** kbringard has joined #openstack-dev13:22
*** davi67232 has joined #openstack-dev13:23
*** bknudson has joined #openstack-dev13:24
*** spzala has joined #openstack-dev13:25
*** jecarey has joined #openstack-dev13:26
*** lbragstad has joined #openstack-dev13:28
*** afazekas has joined #openstack-dev13:28
*** sthaha has quit IRC13:29
*** yassine has quit IRC13:30
*** yassine has joined #openstack-dev13:30
*** ruhe has quit IRC13:30
*** Tross has left #openstack-dev13:31
*** bashok has quit IRC13:31
*** jistr|eng is now known as jistr13:31
*** morazi has joined #openstack-dev13:32
*** freedomhui has joined #openstack-dev13:32
*** ruhe has joined #openstack-dev13:33
*** jistr has quit IRC13:34
*** terriyu has joined #openstack-dev13:35
*** jistr has joined #openstack-dev13:36
*** yaguang has joined #openstack-dev13:36
*** topol has quit IRC13:38
*** o_petit has joined #openstack-dev13:38
*** nosnos has quit IRC13:38
*** dolphm has joined #openstack-dev13:39
*** davi67232 has quit IRC13:39
*** neelashah has joined #openstack-dev13:40
*** Max__ has joined #openstack-dev13:41
*** burt has joined #openstack-dev13:41
*** athomas has quit IRC13:41
*** adalbas has joined #openstack-dev13:41
*** adjohn has joined #openstack-dev13:41
*** eglynn has joined #openstack-dev13:42
*** Ruetobas has joined #openstack-dev13:45
*** tmclaugh[work] has joined #openstack-dev13:46
*** adjohn has quit IRC13:46
*** FunnyLookinHat has quit IRC13:47
*** gimps has joined #openstack-dev13:49
*** kushal has joined #openstack-dev13:49
*** Ruetobas has quit IRC13:50
*** dolphm has quit IRC13:53
*** dolphm has joined #openstack-dev13:54
*** terryh has quit IRC13:54
*** jimfehlig has joined #openstack-dev13:55
*** athomas has joined #openstack-dev13:55
*** dolphm has joined #openstack-dev13:55
*** terryh has joined #openstack-dev13:56
*** imsurit has quit IRC13:58
*** romcheg has left #openstack-dev13:58
*** Ruetobas has joined #openstack-dev13:58
*** davi67232 has joined #openstack-dev14:00
*** dkranz has quit IRC14:01
*** kevinconway has quit IRC14:05
*** jistr has quit IRC14:05
*** morazi has quit IRC14:05
*** rushiagr has quit IRC14:06
*** kevinconway has joined #openstack-dev14:06
*** xga_ has joined #openstack-dev14:06
*** morazi has joined #openstack-dev14:06
*** MaxV_ has joined #openstack-dev14:07
*** waa_ has joined #openstack-dev14:07
*** markmcclain has joined #openstack-dev14:08
*** xga has quit IRC14:09
*** MaxV_ has quit IRC14:09
*** davi67232 has quit IRC14:09
*** mrodden has joined #openstack-dev14:10
*** alunduil has joined #openstack-dev14:10
*** MaxV_ has joined #openstack-dev14:10
*** Max__ has quit IRC14:10
*** carl_baldwin has joined #openstack-dev14:10
*** adjohn has joined #openstack-dev14:12
*** topol has joined #openstack-dev14:13
*** adjohn has quit IRC14:16
*** ruhe has quit IRC14:17
*** alexpilotti_ has joined #openstack-dev14:17
*** SergeyLukjanov has quit IRC14:17
*** samuelbercovici has quit IRC14:18
*** jistr has joined #openstack-dev14:18
*** alexpilotti has quit IRC14:18
*** alexpilotti_ is now known as alexpilotti14:18
*** edmund has joined #openstack-dev14:18
*** Ruetobas has quit IRC14:21
*** ruhe has joined #openstack-dev14:22
*** Ruetobas has joined #openstack-dev14:23
*** FunnyLookinHat has joined #openstack-dev14:23
*** stevemar has joined #openstack-dev14:24
*** hartsocks has quit IRC14:24
*** sumansn_ has quit IRC14:24
*** hartsocks has joined #openstack-dev14:25
*** ruhe has quit IRC14:26
*** afazekas_ has joined #openstack-dev14:26
*** afazekas_ has quit IRC14:26
*** matiu has joined #openstack-dev14:27
*** matiu has quit IRC14:27
*** matiu has joined #openstack-dev14:27
*** SergeyLukjanov has joined #openstack-dev14:28
*** Max__ has joined #openstack-dev14:29
*** chenxu has quit IRC14:29
*** kenperkins has quit IRC14:29
*** jruzicka has joined #openstack-dev14:30
*** mmagr has quit IRC14:30
*** o_petit_ has joined #openstack-dev14:30
*** hartsocks has quit IRC14:30
*** souvik has joined #openstack-dev14:30
*** MaxV_ has quit IRC14:31
*** ruhe has joined #openstack-dev14:32
*** o_petit has quit IRC14:33
*** ruhe has quit IRC14:34
*** Thor has quit IRC14:34
*** Thor has joined #openstack-dev14:35
insanidadedevstack question: what user should one use to fire up ./stack.sh in a non-vagrant environment? I have a vm I created on my own, installed CentOs 6 (which perfectly works for me in the vagrant setup with devstack) but I see some permission problems on the logs.14:37
*** lbragstad has quit IRC14:37
*** jgriffith has quit IRC14:37
*** freedomhui has quit IRC14:37
*** lbragstad has joined #openstack-dev14:38
*** DeeJay1 has quit IRC14:38
*** Thor has quit IRC14:38
*** lbragstad has quit IRC14:38
*** Thor has joined #openstack-dev14:39
*** lbragstad has joined #openstack-dev14:39
*** rdopieralski has quit IRC14:39
*** danwent has joined #openstack-dev14:42
*** sandywalsh has quit IRC14:42
*** adjohn has joined #openstack-dev14:43
*** asavu has quit IRC14:43
garykarosen: ping - please look at https://review.openstack.org/#/c/33504/14:44
*** jgriffith has joined #openstack-dev14:44
*** Alexei_987 has quit IRC14:45
*** jprovazn has quit IRC14:46
*** yaguang has quit IRC14:46
*** the_real_kp has joined #openstack-dev14:47
*** adjohn has quit IRC14:48
*** ondergetekende_ has quit IRC14:48
*** galstrom_zzz is now known as galstrom14:50
*** mlavalle has joined #openstack-dev14:52
jgriffithmkerrin: ping14:53
mkerrinjgriffith: pong14:53
jgriffithmkerrin: hey... looking at https://review.openstack.org/#/c/45631/14:53
*** xga has joined #openstack-dev14:54
jgriffithmkerrin: looks good, however wanted to make sure you tested this out using the new flag14:54
jgriffithmkerrin: I did something like this a long long time ago and it broke nova/ec214:54
*** Mandell has joined #openstack-dev14:55
*** aeperezt has joined #openstack-dev14:55
*** radez is now known as radez_g0n314:55
*** radez_g0n3 is now known as radez14:55
*** freedomhui has joined #openstack-dev14:56
*** xga_ has quit IRC14:56
mkerrinjgriffith: I have tried it out in devstack, but haven't put it into our test system yet. Nothing in devstack is amiss from what I can see14:57
jgriffithmkerrin: well, in devstack though did you use your new flag or let it default back to the old one?14:58
jgriffithmkerrin: know what I mean?14:58
jgriffithmkerrin: you have a safety in there to revert and devstack by default won't use the new flag so....14:58
*** flaper87 is now known as flaper87|afk14:58
*** noslzzp has quit IRC14:59
*** yamahata has joined #openstack-dev14:59
*** sandywalsh has joined #openstack-dev14:59
*** prekarat has quit IRC14:59
*** SergeyLukjanov has quit IRC15:01
*** dubsquared has joined #openstack-dev15:01
*** reidrac has quit IRC15:02
*** avishay has joined #openstack-dev15:02
*** SergeyLukjanov has joined #openstack-dev15:03
*** davidhadas has quit IRC15:03
*** lbragstad has left #openstack-dev15:04
*** ruhe has joined #openstack-dev15:04
*** sandywalsh has quit IRC15:05
*** sahid has joined #openstack-dev15:05
*** danwent has quit IRC15:06
*** cdub has joined #openstack-dev15:06
*** maheshp1 has quit IRC15:06
*** noslzzp has joined #openstack-dev15:07
*** markwash has joined #openstack-dev15:07
*** flaper87|afk is now known as flaper8715:08
*** mdenny has joined #openstack-dev15:08
*** mattmalesky has joined #openstack-dev15:09
*** lbragstad has joined #openstack-dev15:11
*** mrodden has quit IRC15:12
*** souvik1 has joined #openstack-dev15:13
*** souvik1 has quit IRC15:13
*** jecarey has quit IRC15:13
*** adjohn has joined #openstack-dev15:14
*** souvik has quit IRC15:14
mkerrinjgriffith: sorry there, I have set the option but I now see that the environment isn't multi az, I will test that now15:14
*** lbragstad has left #openstack-dev15:14
jgriffithmkerrin: thanks!  Just want to make sure we don't run into a surprise in a couple months :)15:15
*** Max__ has quit IRC15:15
*** jecarey has joined #openstack-dev15:15
*** Max__ has joined #openstack-dev15:15
*** davi67232 has joined #openstack-dev15:18
*** pmathews has joined #openstack-dev15:18
*** adjohn has quit IRC15:18
*** Mandell has quit IRC15:20
*** sandywalsh has joined #openstack-dev15:21
*** markmcclain has quit IRC15:21
*** paragan has quit IRC15:23
*** jvrbanac has joined #openstack-dev15:23
*** mrodden has joined #openstack-dev15:23
*** rnirmal has joined #openstack-dev15:25
*** imsurit has joined #openstack-dev15:26
*** danwent has joined #openstack-dev15:29
*** davi67232 has quit IRC15:32
*** jecarey has quit IRC15:32
*** yaguang has joined #openstack-dev15:33
roaetIs there a separate project for documentation? I'm reading the neutron docs and would like to propose a change, or at least see if a 'bug' has been filed for said change. Would I use the neutron launchpad or is there something else? This is primarily in regards to docs.openstack.org.15:35
jgriffithroaet: yes there is15:35
jgriffithroaet: depending on what you're looking at specifically: https://github.com/openstack/openstack-manuals15:36
roaetjgriffith: thank you. for some reason I didn't consider *-manuals.15:36
*** thouveng has quit IRC15:37
*** pmathews has quit IRC15:38
*** prad has joined #openstack-dev15:38
*** jprovazn has joined #openstack-dev15:40
*** xga_ has joined #openstack-dev15:41
*** sumanthns has joined #openstack-dev15:41
*** pmathews has joined #openstack-dev15:42
*** xga has quit IRC15:42
*** kbrierly has joined #openstack-dev15:43
*** adjohn has joined #openstack-dev15:44
*** yassine has quit IRC15:46
*** chenxu has joined #openstack-dev15:47
*** romcheg has joined #openstack-dev15:47
*** romcheg has left #openstack-dev15:48
*** zaitcev has joined #openstack-dev15:48
*** gmoro has joined #openstack-dev15:49
*** adjohn has quit IRC15:49
*** xarses has quit IRC15:49
*** gargya has quit IRC15:49
*** doron_afk has joined #openstack-dev15:50
*** erfanian has quit IRC15:50
*** xqueralt is now known as xqueralt-afk15:51
*** gargya has joined #openstack-dev15:51
*** kbrierly has quit IRC15:52
*** colinmcnamara has joined #openstack-dev15:52
*** eglynn is now known as eglynn-on-a-call15:53
*** sridevi has joined #openstack-dev15:54
*** networkstatic has joined #openstack-dev15:56
*** networkstatic has quit IRC15:56
*** colinmcnamara has quit IRC15:57
*** JordanP has quit IRC15:58
*** dnoll has joined #openstack-dev15:58
*** bdpayne has joined #openstack-dev15:59
*** devoid has joined #openstack-dev16:00
*** sridevi has quit IRC16:00
*** sridevi has joined #openstack-dev16:01
*** gargya has quit IRC16:02
*** ndipanov has quit IRC16:02
*** giroro_ has joined #openstack-dev16:03
*** feleouet has quit IRC16:03
*** Ruetobas has quit IRC16:03
*** kaushikc has joined #openstack-dev16:04
*** msmedved has quit IRC16:04
*** morazi has quit IRC16:04
*** jcoufal is now known as jcoufal_mtg16:04
dnoll#openstack-meeting16:05
*** xga_ has quit IRC16:05
*** dolphm has quit IRC16:05
*** hartsocks has joined #openstack-dev16:06
*** davi67232 has joined #openstack-dev16:07
*** reed has joined #openstack-dev16:07
*** giroro_ has quit IRC16:08
*** xga has joined #openstack-dev16:08
*** hartsocks has left #openstack-dev16:08
*** hemnafk is now known as hemna16:08
*** jecarey has joined #openstack-dev16:09
*** kbrierly has joined #openstack-dev16:09
*** erfanian has joined #openstack-dev16:09
*** corXi has quit IRC16:09
*** garyk has quit IRC16:10
chenxuis there any (good) documentation on how to use provider networks?16:11
*** mlavalle has quit IRC16:12
chenxuI am a bit confused: the physical network setup seems to be per-agent16:12
*** mattmalesky has quit IRC16:12
*** dolphm has joined #openstack-dev16:12
chenxuand when I do net-create, that's going against the neutron service, which may not know about the local physical networks16:12
chenxunot sure if that's why I got:16:12
chenxuneutron net-create --shared --router:external=True --tenant-id=demo --provider:network_type=flat --provider:physical_network=pnet1 outside16:12
chenxuInvalid input for operation: Unknown provider:physical_network pnet1.16:12
*** sahid has quit IRC16:12
*** gyee has joined #openstack-dev16:13
*** vartom10 has joined #openstack-dev16:13
*** angdraug has joined #openstack-dev16:14
*** Ruetobas has joined #openstack-dev16:14
*** davi67232 has quit IRC16:14
*** adjohn has joined #openstack-dev16:15
*** kaushikc has quit IRC16:15
*** kaushikc has joined #openstack-dev16:16
*** jasdeepH has joined #openstack-dev16:16
*** ndipanov has joined #openstack-dev16:17
*** morazi has joined #openstack-dev16:18
*** radez is now known as radez_g0n316:18
*** lbragstad has joined #openstack-dev16:18
*** devvesa has quit IRC16:19
*** xarses has joined #openstack-dev16:19
*** jpich has quit IRC16:19
*** alop has joined #openstack-dev16:19
*** yaguang has quit IRC16:19
*** yves has quit IRC16:20
*** adjohn has quit IRC16:20
*** reed has quit IRC16:20
*** sarob has joined #openstack-dev16:21
*** o_petit_ has quit IRC16:21
*** cdub has quit IRC16:21
*** radez_g0n3 is now known as radez16:22
*** o_petit has joined #openstack-dev16:22
*** egallen has joined #openstack-dev16:22
*** doron_afk has quit IRC16:24
*** alop has quit IRC16:24
*** sarob has quit IRC16:26
*** sarob has joined #openstack-dev16:27
*** afazekas has quit IRC16:27
*** boris-42 has quit IRC16:29
*** jistr has quit IRC16:31
*** ifarkas has quit IRC16:32
*** Max__ has quit IRC16:32
*** markwash has quit IRC16:32
*** comay has quit IRC16:34
*** comay has joined #openstack-dev16:34
*** sumanthns has quit IRC16:34
*** comay has quit IRC16:34
*** dguitarbite has quit IRC16:35
mkerrinjgriffith: I have tested that change in a multi-az devstack's setup and everything is working as I was expecting.16:35
*** chenxu has quit IRC16:35
*** devvesa has joined #openstack-dev16:36
*** leif has joined #openstack-dev16:36
*** leif is now known as Guest5809916:36
*** vartom10 has quit IRC16:37
*** feleouet has joined #openstack-dev16:37
*** dguitarbite has joined #openstack-dev16:37
*** SumitNaiksatam has quit IRC16:38
*** o_petit has quit IRC16:38
*** safchain has quit IRC16:38
*** xga_ has joined #openstack-dev16:40
*** reed has joined #openstack-dev16:41
*** xga has quit IRC16:42
*** isd has joined #openstack-dev16:42
*** vartom10 has joined #openstack-dev16:43
*** devvesa has quit IRC16:43
*** ndipanov has quit IRC16:45
*** marun has joined #openstack-dev16:46
*** dachary has quit IRC16:46
*** adjohn has joined #openstack-dev16:46
ekarlso-516:46
*** dkranz has joined #openstack-dev16:46
*** sushils has quit IRC16:47
*** sushils has joined #openstack-dev16:48
*** yjiang5 has joined #openstack-dev16:48
*** otherwiseguy has quit IRC16:48
*** dachary has joined #openstack-dev16:48
*** adjohn has quit IRC16:51
*** vuil has joined #openstack-dev16:51
*** epim has joined #openstack-dev16:51
*** ndipanov has joined #openstack-dev16:51
*** sushils has quit IRC16:52
*** garyk has joined #openstack-dev16:52
*** bknudson has left #openstack-dev16:52
*** henrynash has joined #openstack-dev16:52
*** fbo is now known as fbo_away16:53
*** cdub has joined #openstack-dev16:54
henrynashayoung: you around?16:54
*** kaushikc has quit IRC16:55
*** nati_ueno has joined #openstack-dev16:57
*** sushils has joined #openstack-dev16:57
*** imsurit has quit IRC16:58
*** kbrierly has quit IRC16:59
*** markmcclain has joined #openstack-dev16:59
henrynashayoung, bknudson, morganfainberg, gyee: looking to move https://review.openstack.org/#/c/45584/ along…16:59
*** kbrierly has joined #openstack-dev17:00
*** davi67232 has joined #openstack-dev17:01
*** athomas has quit IRC17:01
gyeehenrynash, looking ...17:02
henrynashgyee: thx17:03
*** krtaylor has quit IRC17:03
*** adalbas has quit IRC17:04
*** vartom10 has quit IRC17:04
*** RajeshMohan has quit IRC17:04
*** RajeshMohan has joined #openstack-dev17:04
*** mlavalle has joined #openstack-dev17:04
*** harlowja has joined #openstack-dev17:05
*** lucas-afk is now known as lucasagomes17:05
*** asavu has joined #openstack-dev17:07
*** bknudson has joined #openstack-dev17:07
*** SergeyLukjanov has quit IRC17:09
*** sridevi has quit IRC17:11
*** tkammer has quit IRC17:11
*** RajeshMohan has quit IRC17:11
*** dubsquared has quit IRC17:11
*** RajeshMohan has joined #openstack-dev17:11
*** ruhe has quit IRC17:14
*** johnthetubaguy has quit IRC17:14
*** xga_ has quit IRC17:15
*** arnaudvm has joined #openstack-dev17:15
*** xga_ has joined #openstack-dev17:16
*** adjohn has joined #openstack-dev17:16
*** Mandell has joined #openstack-dev17:17
*** adalbas has joined #openstack-dev17:18
*** SumitNaiksatam has joined #openstack-dev17:19
*** isd has quit IRC17:19
*** alop has joined #openstack-dev17:19
*** markwash has joined #openstack-dev17:20
*** gimps has quit IRC17:20
*** networkstatic has joined #openstack-dev17:20
*** noslzzp has quit IRC17:20
*** adjohn has quit IRC17:21
*** xga_ has quit IRC17:21
*** gimps has joined #openstack-dev17:22
*** alop_ has joined #openstack-dev17:22
*** msmedved has joined #openstack-dev17:23
*** RajeshMohan has quit IRC17:23
*** alop has quit IRC17:24
*** RajeshMohan has joined #openstack-dev17:24
*** alop_ is now known as alop17:24
*** davi67232 has quit IRC17:24
*** vartom10 has joined #openstack-dev17:24
arosenthank garyk looks good to me.17:25
*** Ryan_Lane has joined #openstack-dev17:25
*** ruhe has joined #openstack-dev17:25
*** comay has joined #openstack-dev17:26
*** davi67232 has joined #openstack-dev17:26
*** adalbas has quit IRC17:27
*** Ryan_Lane1 has joined #openstack-dev17:27
*** Ryan_Lane has quit IRC17:27
*** sushils has quit IRC17:28
*** safchain has joined #openstack-dev17:28
*** avishay has quit IRC17:28
*** safchain has quit IRC17:29
*** MaxV_ has joined #openstack-dev17:29
*** dubsquared has joined #openstack-dev17:29
*** alop has quit IRC17:29
*** wfoster is now known as wfoster_away17:30
morganfainbergmornin.17:31
morganfainbergdolphm, ping17:31
dolphmmorganfainberg: o/17:31
*** chenxu has joined #openstack-dev17:31
morganfainbergdolphm, https://bugs.launchpad.net/keystone/+bug/1219739 looks to be at least partially invalid17:31
uvirtbotLaunchpad bug 1219739 in keystone "LDAP use 'tenant_id' instead of 'tenantId' in user_ref" [Medium,New]17:31
morganfainbergdolphm, ldap we don't store "extra" data (e.g. tenantId) on users17:32
morganfainbergand by default tenant_id (or should be tenantId) is explicitly in the ignored attributes17:32
morganfainbergdolphm, just making sure i'm not crazy before commenting on it.17:32
*** ndipanov has quit IRC17:33
dolphmmorganfainberg: those both sound like reasonable assertions, but i really don't know off hand without looking/testing17:34
morganfainbergdolphm, yeah, i'll hit up bknudson or ayoung later today and confirm.17:34
morganfainbergdolphm, but i should have it wrapped up today (one way or another)17:35
dolphmmorganfainberg: awesome17:35
bknudsonmorganfainberg: there are a lot of weird config options for LDAP... you can ignore attributes and assign keystone attrs to random LDAP attrs.17:36
*** Ryan_Lane1 has quit IRC17:36
*** Ryan_Lane has joined #openstack-dev17:36
*** jasdeepH has quit IRC17:36
morganfainbergbknudson, yeah i know.  i don't think we explicitly have a store for tenant_id/tenantId/project_id/projectId though17:36
*** larsks has joined #openstack-dev17:37
morganfainbergit's just a "go add a user to a role in this project" if it exists17:37
*** davi67232 has quit IRC17:37
morganfainbergand if you don't "ignore" tenant_id, and pass it in (or anything like that) you get a nice key error traceback since ldap doesn't know what to do (at least in my testing)17:37
morganfainberggyee, ping17:37
gyeeyes sir17:38
*** alop has joined #openstack-dev17:39
*** adalbas has joined #openstack-dev17:39
morganfainberggyee, regarding your comment on the domain cleanup.  Do you have another suggestion on doing the domain_Scope (driver) lookup but not exposing ourselves to referencing an incorrect domain?17:39
morganfainberge.g., domain != user.domain, but the backend ends up being correct (the default driver)17:39
morganfainbergmaybe an explicit check to see if domain_ref id == user.domain_id instead of the second lookup?17:40
*** kiall has quit IRC17:41
*** davi67232 has joined #openstack-dev17:41
*** chenxu has quit IRC17:41
gyeemorganfainberg, I don't understand why you need that change in the first place, seems like backing out the changes should be fine17:41
morganfainberggyee, i'd like to correct the double lookup on domain, but not disallow password auth with the per-domain-backends17:41
morganfainberggyee, today, we don't have domain_scope to look up by user_id17:41
gyeeuser_id is globally unique17:41
*** mlavalle has quit IRC17:42
morganfainberggyee, unfortunately, no it isn't with per-domain backends17:42
morganfainbergwell.  not guaranteed to be17:42
*** mlavalle has joined #openstack-dev17:42
gyeemorganfainberg, then we have a much bigger problem17:42
morganfainbergand you still don't know what domain the ID driver is coming from when using the per-domain backends.17:42
gyeein that case, we'll need API spec changes17:42
morganfainberggyee, this has been discussed a lot.  it's an issue with the implementation.  the goal is to get this to "expirimental" and finish the cleanup in icehouse17:43
morganfainberggyee, and include the domain with the user ID (int he case of LDAP the full DN as the user_id)17:44
morganfainberggyee, but I didn't want to risk the massive change to format / etc and possible api shifts in havana17:44
*** krtaylor has joined #openstack-dev17:44
*** HenryG has quit IRC17:45
morganfainberggyee, and even if user_id was globally unique, right now we don't know the domain backend to use for the lookup (if the per-domain-identity backend is used)17:45
*** RajeshMohan has quit IRC17:45
*** RajeshMohan has joined #openstack-dev17:46
gyeemorganfainberg, user_id needs to be globally unique per API spec, if you want to be creative by encoding it into the user_id that's fine17:46
gyeeuser_id=domain_id:user_id17:46
*** ndipanov has joined #openstack-dev17:46
morganfainberggyee, right. but i didn't want to try and handle that kind of change this late in the cycle.  there are other implications.17:46
morganfainberggyee, and this split-per-domain backend is experimental at best in havana17:47
*** davi67232 has quit IRC17:47
*** dhellmann is now known as dhellmann_17:47
*** adjohn has joined #openstack-dev17:47
*** blamar has joined #openstack-dev17:47
morganfainbergi can instead do a user.domain_id == domain_ref['id'] or raise unauthorized there and get the same effect.17:47
gyeemorganfainberg, I think we should punt it, this topic need more indepth review17:47
*** noslzzp has joined #openstack-dev17:48
*** o_petit has joined #openstack-dev17:48
*** adjohn has quit IRC17:48
gyeethis is high risk for havana anyway17:48
*** adjohn has joined #openstack-dev17:48
morganfainberggyee, i'm not opposed to that.  dolphm, bknudson, henrynash, care to weigh in.17:48
morganfainbergi know we've discussed this a bunch.17:48
*** isd has joined #openstack-dev17:49
bknudsonmorganfainberg: I don't see us making major pervasive changes like user-id handling for havana at this point.17:50
morganfainberggyee, i think the other option is to mark this feature as "don't use at all" vs. "expirimental"17:50
bknudsonI prefer don't use at all rather than experimental if we know there are things that don't work.17:50
morganfainbergbknudson, right. the question falls into the cleanup to hit "expirimental" on the per-domain-split.17:50
bknudsonbecause I don't want to be getting bug reports17:50
*** AlanClark has joined #openstack-dev17:51
morganfainbergbknudson, i'm perfectly fine with that.  I'd like to pull all the referencing docs for it then, and examples out of the keystone.conf.sample17:51
gyeemorganfainberg, if Keystone is a car, I wonder if an experimental feature will get us lots of lawsuits :)17:51
*** kiall has joined #openstack-dev17:51
bknudsonmorganfainberg: yes, that sounds like the way to go to make it not usable17:52
morganfainberggyee, i'm not in disagreement (though your use of a car metaphor makes be cringe :P) i was going based upon the previous conversation17:52
bknudsonwe can try again in icehouse, now that we know what (some of) the problems are17:52
gyeebknudson, yeah, I agreed17:52
*** sumanthns has joined #openstack-dev17:52
morganfainbergi just want to make sure we have buy-in for pulling the docs and such.17:52
*** yjiang5 is now known as yjiang_away17:52
*** yjiang_away has quit IRC17:52
*** jasdeepH has joined #openstack-dev17:52
bknudsonmorganfainberg: thanks for looking into this and figuring out how much work it is to get it working17:53
morganfainbergbknudson, i don't think we need to wedge in extra disable code though, just pulling docs should be sufficient17:53
*** salv-orlando has quit IRC17:54
*** admiyo has quit IRC17:54
henrynashbknudson, morganfainberg: I felt that our "experimental" description was sufficient for us to go forward….but am happy with the collective view...17:54
*** ayoung_ has joined #openstack-dev17:54
*** HenryG has joined #openstack-dev17:54
morganfainberghenrynash, i don't see it impacting LDAP identity and SQL assignment configuration17:55
morganfainberghenrynash, just simply the split-per-domain-identity backend17:55
*** ndipanov is now known as ndipanov_gone17:55
henrynashdisabling is, of course, easy. we just never let the config setting get set17:55
morganfainberghenrynash, aye.17:55
gyeemorganfainberg, I have a feeling this feature will be replace in favor on federation17:55
gyeereplaced17:55
morganfainberggyee, i think that this feature will be incorporated by the federation stuff (e.g. same net effect)17:56
ayoung_sorry guysm forgot I had changed my nick...17:56
*** sumanthns has quit IRC17:57
gyeeayoung_, how do I know you are the real ayoung :)17:57
bknudsonayoung_: can you pgp sign something for us?17:58
*** mlavalle has quit IRC17:58
henrynashmorganfainberg, gyee: I'd personally still like us to keep it in as experimental….with morganfainberg's changes17:58
*** david-lyle has quit IRC17:58
*** yjiang5 has joined #openstack-dev17:58
morganfainberggyee, but yes, i agree, esp. if we end up making SQL/LDAP/etc talk the same mechanism as other federation like sources of identity17:58
bknudsonI don't have a problem with experimental, but I don't really see the point of it? It doesn't work and we're not going to fix it.17:58
morganfainbergbknudson, i haven't trusted ayoung_ 's pgp key, even if he signs it, how do i know it's him :P17:59
*** ayoung_ is now known as ayoung17:59
*** RajeshMohan has quit IRC17:59
ayoungjust /ghost ed some poor soul17:59
*** RajeshMohan has joined #openstack-dev17:59
morganfainbergayoung, poor poor soul.17:59
* ayoung reads up17:59
bknudsonit was probably the real ayoung.18:00
*** yjiang5 has left #openstack-dev18:00
ayoungwell, his password was 'password'18:00
henrynashbknudson: I think with morganfainberg's changes it will work, with restrictions, no?18:00
*** boris-42 has joined #openstack-dev18:00
bknudsonif we know the restrictions and can document then I'm fine with that.18:00
xarsesat least it wasn't 123418:01
*** davi67232 has joined #openstack-dev18:01
*** spzala has quit IRC18:01
morganfainbergxarses, 12345, 12345? amazing, thats the code to my luggage18:01
ayoungPatch set 3...wake me when morganfainberg gets to double digits,18:01
henrynashbknudson: I think we can….18:01
ayoungI hate Yoghurt18:01
gyeehenrynash, I have a problem with the user_id no longer globally unique part18:01
ayounguser_id stays globally unique18:01
*** alexpilotti has quit IRC18:02
ayoungI kaibosh making them non-globally unique18:02
gyeethat would be contradicting the API spec18:02
morganfainberggyee, it's an edgecase that -could- happen18:02
morganfainbergnot expected to18:02
morganfainbergnor supported18:02
ayoungnope18:02
ayoungwe should not allow it18:02
morganfainbergayoung, that requires the changes to user_id i was hesitant to make this late in havana18:02
gyeeayoung, yeah I agreed18:02
bknudsonI'm worried not handling non-unique IDs probably would raise a security exposure.18:03
henrynashgyee: I would agree, but we're saying it must still be globally unique18:03
ayoungmorganfainberg,then don't make them....we live with an imperfect implementation for a release18:03
bknudsonif one company could assign an ID that another company has and mask their user18:03
morganfainbergbknudson, the explicit domain lookups should prevent that.18:03
*** melwitt has joined #openstack-dev18:03
morganfainbergbut, i can't guarantee that without a lot more testing18:03
ayoung  bknudson that is why we need to order the domains.  I had a blueprint that discussed this....one sec18:04
*** Mandell has quit IRC18:04
morganfainbergayoung, that is my plan, i wasn't going to make those changes this cycle.  in fact, i would -2 any attempts to make a change to the user_id handling this late.18:04
morganfainbergayoung, it would be a big risk/potential for lots of bugs.18:05
*** RajeshMohan has quit IRC18:05
*** RajeshMohan has joined #openstack-dev18:05
bknudson+239, -131 lines changes and only +21, -12 / +7, -4 are tests?18:05
*** ruhe has quit IRC18:05
ayounghttps://etherpad.openstack.org/chain-of-domains18:05
*** lnxnut has joined #openstack-dev18:06
*** asavu has quit IRC18:06
morganfainbergbknudson, i can add in more tests if you would like, but i am looking for feedback on approach as well before diving in to the tests.  i am leaning more and more towards your and gyee 's view that expirimental is even possibly too much risk18:07
ayoungmorganfainberg, so multiple domains in SQL are going to use the UUID approach.  Any LDAP based domains should be registered using DNs, and then the IDs will be checked against that apttern.  SAML, and ABFAB probably have similar concepts.  Bascially, we need to embed the domain in the user_id18:07
morganfainbergayoung, even with UUID you still need to know the domain to lookup from.18:07
morganfainbergayoung, but the id should def. be unique.18:08
morganfainbergthat way18:08
*** jasdeepH has quit IRC18:08
*** xqueralt-afk is now known as xqueralt18:08
morganfainberge.g. it is possible to have 2 domains in separate sql stores… or would that not be supported?18:08
bknudsonI believe we expected to support multiple SQL stores just like multiple LDAPs18:09
henrynashbknudson: true18:09
*** yolanda has quit IRC18:10
*** davi67232 has quit IRC18:10
*** tmclaugh[work] has quit IRC18:10
morganfainbergayoung, if we do the harder split, where ID becomes silo'd off (convo from yesterday) and it talks a standard-ish federation protocol, we could eliminate this problem at the same time.18:10
*** xqueralt is now known as xqueralt-afk18:11
*** RajeshMohan has quit IRC18:11
gyeebknudson, henrynash, I wonder what's likelihood of multiple SQL deployment, or even multiple LDAP18:12
*** tmclaugh[work] has joined #openstack-dev18:12
morganfainberggyee, i think HP has a need for multiple LDAP backends (the origin on this bug report)18:12
gyeemorganfainberg, not my part of HP :)18:12
morganfainberggyee, hehe18:13
henrynashmorganfainberg: I would think anyone using OS to run a public cloud that supportd enterprises would need this18:13
gyeehenrynash, that would be federation where IdP maintain the own LDAP18:13
morganfainberghenrynash, even in a private cloud, i know I want to use a separate store for the project my company uses to support the cloud18:14
*** Mandell has joined #openstack-dev18:14
morganfainbergs/project/domain18:14
*** boris-42 has quit IRC18:15
bknudsonclassic example is OpenStack users (nova, etc) in one store and company users in LDAP18:15
morganfainbergbknudson ++18:15
bknudsonOpenStack users in SQL18:15
morganfainberg"system"/manager accounts don't need to be in the corporate LDAP/IdP that way.18:16
*** freedomhui has quit IRC18:16
*** o_petit has quit IRC18:16
*** boris-42 has joined #openstack-dev18:17
*** jvrbanac has quit IRC18:17
*** vipul is now known as vipul-away18:17
*** dnoll has quit IRC18:19
*** jvrbanac has joined #openstack-dev18:19
*** gimps_ has joined #openstack-dev18:21
*** dprince has quit IRC18:22
*** maheshp has joined #openstack-dev18:22
*** drewlander has quit IRC18:23
gyeebknudson, morganfainberg, yeah, that's a legit use case18:23
*** Mandell has quit IRC18:24
bknudsongyee: or did you want a car analogy about employee / customer parking spots?18:24
gyeeits still one parking lot :)18:25
bknudsonthis gives us separate lots18:25
*** Mandell has joined #openstack-dev18:25
morganfainbergso, real-world use case (literally got this email 10 minutes ago).  company wants the users for my company (we manage the cloud) in separate parking lot^H^Hnamspace from their users18:26
*** vipul-away is now known as vipul18:26
*** prometheanfire has joined #openstack-dev18:26
morganfainbergjust asked us to do a split like this, and similarly, for the system users.18:26
*** dachary has quit IRC18:26
gyeebut user_id still need to be unique within the context of Keystone18:27
*** dachary has joined #openstack-dev18:27
morganfainberggyee, agreed.  in ldap, ideally it should be the full DN (we can derive the domain from that), and SQL / Federation we would need to know how to derive the right domain.18:28
*** safchain has joined #openstack-dev18:28
bknudsonthen you need a mapping from DN -> domain, etc18:28
*** safchain has quit IRC18:28
morganfainbergbknudson, correct.18:28
prometheanfiredoes https://bugs.launchpad.net/keystone/+bug/1179955 CVE-2013-4222 effect grizzly/folsom?18:29
uvirtbotprometheanfire: ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided. (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4222)18:29
uvirtbotLaunchpad bug 1179955 in ossn "Disabling a tenant would not disable a user token" [High,Fix released]18:29
morganfainbergbknudson, but that is far easier than "Example_User_Name"18:29
morganfainbergwhich could be cn=18:29
morganfainberg"example_user_name",dc=example or dc=example2 etc18:29
bknudsonmakes sense for DN, but what about UUID / SQL?18:29
morganfainbergbknudson, UUID:domain ?18:30
bknudsonlike a domain UUID ?18:30
morganfainbergyeah.18:30
morganfainbergor user_id@domain18:30
*** SergeyLukjanov has joined #openstack-dev18:30
*** safchain has joined #openstack-dev18:31
bknudsonmakes sense, just not sure how it fits into keystone code.18:32
morganfainbergor, we could make ID speak some kind of federation protocol, and use that to do the domain peice, similar to what ayoung stated above (and in the etherpad)18:32
*** lefoo77 has joined #openstack-dev18:32
*** lefoo77 has quit IRC18:33
morganfainbergeven run ID as a separate process if needed (keystone-id) (**Note I don't advocate this, but, it is an option)18:34
bknudsonhorizon is going to need to talk directly to all these IDs or point to their GUI.18:35
morganfainbergbknudson, fair point.18:36
*** drewlander has joined #openstack-dev18:37
ayoungno multiple SQL stores18:38
ayoungor , if we do that, we embed the domain in the user id18:38
*** safchain has quit IRC18:39
*** luis has joined #openstack-dev18:39
ayoungtwas IBM that wanted multiple LDAPs, which is why henrynash did it18:39
prometheanfirechmouel: ping18:39
*** marios has quit IRC18:40
*** bashok has joined #openstack-dev18:40
ayoungmorganfainberg, bknudson sounds like we are all on the same measure, and playing the same tune.18:40
*** marios has joined #openstack-dev18:40
*** amohn9 has joined #openstack-dev18:40
bknudsonayoung: I think we're still not sure what to do with existing support in Havana.18:41
*** davi67232 has joined #openstack-dev18:41
bknudsonayoung: full fix, quick fix, experimental, remove ?18:41
ayoungbknudson, has anyone even tested if DNs work as is?18:41
bknudsonayoung: I haven't heard of anyone testing DNs... not sure how it work work18:42
bknudsoncan I just put DN in for the ID attribute?18:42
ayoungbknudson, I was halfway through it last week18:42
ayoungbknudson, yep18:42
bknudsonshould be easy to set up with the devstack support18:42
ayoungbknudson, yeah, except for creating users...needs to be read only18:42
bknudsonayoung: ok, not going to work with devstack then.18:43
gyeeany plan to do lazy provisioning of LDAP users in Keystone18:43
ayounggyee, why18:44
ayounggyee, what does that mean?  Making a duplicate record from LDAP in the SQL backend?18:44
gyeeI thought someone was asking for it so they can assign roles18:44
gyeeand suspend/disable users18:45
*** dmakogon_ has joined #openstack-dev18:45
morganfainbergayoung, we would need a migration script. user_id is varchar(64), 255 is needed for full dn possibvilities18:45
morganfainbergiirc18:45
gyeeayoung, correct, basically creating a shadow account in SQL18:45
ayoungmorganfainberg, acha18:45
*** spzala has joined #openstack-dev18:46
ayoungmorganfainberg, that should be an acceptable migration, though...18:46
morganfainbergayoung, yes18:46
*** yolanda has joined #openstack-dev18:46
morganfainbergayoung, the migration of exisiting data is a bit more work, but not a lot.18:46
ayounggyee, I think not.  User stay in ldap,  assignments are the only "shadow"18:46
morganfainberge.g. from user_id to full dn18:46
ayoungmorganfainberg, existing data should left alone18:46
gyeek, that make sense18:46
ayoungmorganfainberg, mixed ldap/sql is not going to be migrated18:47
*** bswrchrd has joined #openstack-dev18:47
ayoungand wasn't supported before Havana2/318:47
morganfainbergayoung, ah yes18:47
*** novas0x2a|laptop has joined #openstack-dev18:47
ayoungmorganfainberg, you only need to migrate the assignments backend18:47
*** danpb has quit IRC18:47
ayoungleave identity as is, or do it in a follow on migration if we really want to be on par18:48
*** wal99d has joined #openstack-dev18:48
morganfainbergi'd say consistent makes sense, but doesn't really matter18:48
ayoungfollow on migration in Icehouse, though...we don't need for Havana18:48
morganfainbergmy guess is it'll change in icehouse either way18:48
*** networkstatic has quit IRC18:49
gyeeayoung, so what does it mean? experimental and unsupported?18:49
ayounggyee, I say we fix the assignements backend.18:50
ayoungfor Havana18:50
*** thedodd has joined #openstack-dev18:50
ayoungtis a minor fix...18:50
*** networkstatic has joined #openstack-dev18:50
morganfainbergayoung, and we need to fix group to be dn as well18:50
morganfainbergbut same fix18:50
morganfainbergjust noticed that18:50
*** davi67232 has quit IRC18:51
ayoungmorganfainberg, figured you would get that...all IDs from identity....18:52
morganfainbergayoung, yeah.18:52
*** david-lyle has joined #openstack-dev18:53
morganfainbergok, so the scope has been increased for the fixup to include migration and making user_id full DNs for ldap backend?18:53
morganfainbergin assignment that is18:53
morganfainberguser_id/group_id sorry.18:53
morganfainbergerm.  crud.  LDAP identity, sql assignment18:53
morganfainbergthere.18:53
*** epim has quit IRC18:54
*** bknudson has left #openstack-dev18:55
*** jecarey has quit IRC18:56
*** lucasagomes has quit IRC18:57
insanidadewhat are the env variables I must set for running admin commands againts keystone ?18:57
insanidadeOS_* ??18:57
ayoungmorganfainberg, separate bug, separate review18:58
dolphminsanidade: http://pasteraw.com/1zesvx5rhxxtg3vaow05l3tlkonnwcf18:58
ayounginsanidade, OS_USERNAME OS_PASSWORD OS_AUTH_URL...or maybe Im  lying18:58
insanidadedolphm, ayoung: you both are correct. I lost a text file where I recorded those tips. Thanks a lot.18:59
morganfainbergayoung, right, but still in the scope of the fixup for havana.  or are we ditching the expirimental support for multiple backends?  I'm a little confused now.18:59
ayoungmorganfainberg, still in scope, separate commit18:59
*** dhellmann_ is now known as dhellmann19:00
*** vipul is now known as vipul-away19:00
*** sheepdog801 has joined #openstack-dev19:01
*** jecarey has joined #openstack-dev19:01
*** boris-42 has quit IRC19:01
*** networkstatic has quit IRC19:01
*** sheepdog801 has left #openstack-dev19:01
henrynashhi19:02
henrynashsorry, wrong window19:03
*** asavu has joined #openstack-dev19:04
insanidadeanother question: according to the logs (screen sessions), all services are up and running. why do I get a 404 error after a 'neutron net-gateway-list'  ?19:05
*** cdub has quit IRC19:06
*** jasdeepH has joined #openstack-dev19:07
*** jasdeepH has quit IRC19:07
*** alop_ has joined #openstack-dev19:08
*** danwent has quit IRC19:09
*** alop has quit IRC19:09
*** alop_ is now known as alop19:09
ayoungmorganfainberg, do we currently have a way to test if a domain is backend by LDAP or SQL?19:10
ayounghenrynash, you are always welcome to say Hi here19:10
*** david-lyle has quit IRC19:10
*** danwent has joined #openstack-dev19:10
*** cdub has joined #openstack-dev19:13
*** mkollaro has quit IRC19:14
*** marios has quit IRC19:14
*** marios has joined #openstack-dev19:14
*** mlavalle has joined #openstack-dev19:15
*** stevemar2 has joined #openstack-dev19:16
*** stevemar has quit IRC19:16
*** atiwari has joined #openstack-dev19:16
*** SergeyLukjanov has quit IRC19:16
*** xga_ has joined #openstack-dev19:16
*** boris-42 has joined #openstack-dev19:17
*** markwash has quit IRC19:18
*** sushils has joined #openstack-dev19:18
*** lnxnut has quit IRC19:19
*** maheshp has quit IRC19:20
*** maheshp has joined #openstack-dev19:20
notmynamein keystone, what is dogpile.cache?19:21
*** xga_ has quit IRC19:21
dolphmnotmyname: it provides a caching decorator that can utilize memcached, etc19:21
*** SergeyLukjanov has joined #openstack-dev19:22
notmynamedolphm: any known reason it wouldn't be available on a CI devstack instance?19:23
*** davi67232 has joined #openstack-dev19:24
dolphmnotmyname: no? it's been in global-requirements for a while https://github.com/openstack/requirements/blob/master/global-requirements.txt#L919:24
notmynamedolphm: perhaps a transient thing then http://logs.openstack.org/05/46105/2/check/gate-swift-devstack-vm-functional/f3b37d6/console.html19:24
dolphmnotmyname: hmm19:25
*** benonsoftware has quit IRC19:25
*** yolanda has quit IRC19:26
dolphmnotmyname: not a known bug as far as i'm aware19:27
*** chenxu has joined #openstack-dev19:27
notmynamedolphm: k, thanks19:27
*** otherwiseguy has joined #openstack-dev19:29
*** epim has joined #openstack-dev19:30
dolphmnotmyname: appears to be a transient unrelated to dogpile19:31
dolphmnotmyname: look at the traceback at 2013-09-11 18:38:04.10919:31
dolphmnotmyname: it fails to install keystone, attempts to run it anyway (?!), and dogpile just happens to be the first missing dependency it runs into19:31
*** bswartz has quit IRC19:32
dolphmnotmyname: sounds like a bug against devstack? or maybe pbr?19:33
notmynamedolphm: perhaps. maybe just a network hiccup? /me doesn't really know19:33
*** amohn9 has quit IRC19:33
dolphmnotmyname: appears to be a network hiccup to me, but devstack is not handling that failure correctly (it's ignoring it, instead of retrying or aborting)19:34
*** bswartz has joined #openstack-dev19:34
*** egallen has quit IRC19:34
*** amohn9 has joined #openstack-dev19:36
*** davi67232 has quit IRC19:37
*** ruhe has joined #openstack-dev19:37
*** fbo_away is now known as fbo19:38
*** amohn9 has joined #openstack-dev19:39
ayoungisd, for planned Identity work, you might want to look at the blueprints: https://blueprints.launchpad.net/keystone19:39
*** amohn9 has quit IRC19:39
ayoungisd, the summit topics are just getting posted now:19:40
ayounghttp://summit.openstack.org/19:40
*** ruhe has quit IRC19:41
*** amohn9 has joined #openstack-dev19:42
*** cdub has quit IRC19:42
*** amohn9 has quit IRC19:42
*** devoid has left #openstack-dev19:42
*** bashok has left #openstack-dev19:45
*** waa_ has quit IRC19:46
*** boris-42 has quit IRC19:47
*** drewlander has quit IRC19:47
*** mattmalesky has joined #openstack-dev19:48
*** david-lyle has joined #openstack-dev19:49
*** sarob has quit IRC19:52
*** benonsoftware has joined #openstack-dev19:52
morganfainbergayoung, don't think we have a canonical way to know if a domain is SQL or LDAP or… anything else short of looking at the driver19:55
*** vipul-away is now known as vipul19:56
*** mangelajo has joined #openstack-dev19:58
ayoungmorganfainberg, pattern of the user_id gets regiestered.  UUID means sql.  But that is not what I was asking....19:58
ayoungI want to know when I get a domain id whether the associated domain is ldap or sql19:59
*** mangelajo has quit IRC19:59
ayoungso we can skip all of the delete domain stuff on the LDAP case19:59
morganfainbergayoung, that was what i assumed you meant.19:59
insanidadehmm. ok. got it.19:59
morganfainbergwouldn't we want to still cleanup the assigment portion?19:59
*** markwash has joined #openstack-dev20:00
morganfainbergayoung, or you mean just skip anything on ID?20:00
morganfainberge,g, delete user/group20:00
*** topol has quit IRC20:00
ayoungdolphm, so...what if we let Keystone parse the policy config files it is handed.  Keystone would then be able to deduce what a give token would be allowed to do.  THen, instead of delegating a whole a role, a user could delegate the ability to execute individual api functions.  Then, a token could say:  only let the bearer execute function X on Nova....20:02
*** mike has joined #openstack-dev20:02
*** mike is now known as Guest5251620:02
ayoungstevemar2, ^^  how would you like that for oauth?20:02
stevemar2ayoung: just reading now... give me a sec20:03
*** Guest52516 has quit IRC20:03
*** msmedved has quit IRC20:04
morganfainbergayoung, so keystone would be responsible for part of the enforcement chain?  e.g. move all policy stuff into keystone?20:05
*** msmedved has joined #openstack-dev20:05
ayoungmorganfainberg, it is already supposed to be distributed from there20:05
morganfainbergah.20:05
morganfainbergoh right20:05
ayoungpolicy is uploaded, keystone just treats it as a blob20:05
morganfainberghence policy controllers.20:05
*** sarob has joined #openstack-dev20:06
ayoungso..Keystone really doesn't even need to parse it, just evaluate against it20:06
*** dolphm has quit IRC20:06
ayoungbut pasing it would be  nice for Horizon.  They want to know "user has roles X Y and Z,  what should I show them?"20:06
stevemar2ayoung: ahh, i get ya20:07
stevemar2ayoung: but there are a lot of policies once could delegate20:08
*** rwsu has quit IRC20:08
stevemar2not sure if policy is the right word there20:08
ayoungis stevemar2 policy is the word we already use20:08
ayoungit is the rules file distribution backend in keystone20:08
stevemar2yeah20:09
*** jecarey has quit IRC20:09
ayounghttps://github.com/openstack/keystone/tree/master/keystone/policy20:09
stevemar2i'm just wondering if it's too fine grained?20:09
stevemar2what if i want the bearer to be able to do all network related tasks20:09
ayoungstevemar2, not for the actual deleagtion.  And it will allow roles to be what they are supposed to be:  course grained collections of permissions20:09
ayoungstevemar2, we can still deleaget roles.  Just add in the individual APIs as an additional way to delegate20:10
ayoungeither give them all, or just the ones they need20:10
* stevemar2 nods20:10
stevemar2could be done20:10
*** boden_ has joined #openstack-dev20:11
sdaguezul: for what's left on the nova-client python3 compat changes, could we get a blueprint up for them? just easier to see all the patches that are related to it, and would probably ease the concerns of folks that want bugs for them.20:11
ayoungstevemar2, grew out of a discussion with my boss over this BZ entry I have assigned  https://bugzilla.redhat.com/show_bug.cgi?id=90593120:11
uvirtbotayoung: Error: Could not parse XML returned by bugzilla.redhat.com: HTTP Error 404: Not Found20:11
stevemar2ayoung: "Keystone would then be able to deduce what a give token would be allowed to do" could you expand on that20:11
ayoungstevemar2, sure20:11
*** msmedved has quit IRC20:11
ayoungstevemar2, I get a token as me.  I want to create a targetted delegation for you20:11
ayoungso I ask keystone:  hey, If I send this token to Nova, what functions can I call?20:12
*** boden has quit IRC20:12
ayoungKeystone can return a list based on the roles in my token20:12
ayoungstevemar2, Horzon could do the same thing, and build a set of Roles->API mappings for the UI.  Wish Gabriel Hurley were here, he'd be Kvelling20:13
ayoungand Horzion folks around?20:13
stevemar2ayoung: it would take some of the user error parts out of the current impl20:14
ayoungstevemar2, yep20:14
stevemar2potential user errors*20:14
ayoungthe data is there, it is just not parsed or used...lets use it20:14
stevemar2ayoung: cool cool20:15
*** wal99d has quit IRC20:15
ayoungstevemar2, maybe the oauth session should be trusts, oauth and delegation20:15
stevemar2ayoung: i made a session topic about future oauth work... (nvm, you've noticed it)20:15
ayoungthat way we can lay out a path ahead that deals with this, and clears up the distinctions between them20:15
*** msmedved has joined #openstack-dev20:15
ayoungI think trusts and oauth should be considered two different APIs for getting at a core delegation functionality20:16
stevemar2ayoung: yeah, i wanted to have it so people can get informed about the oauth work, and so that we can get new ideas for it.20:16
stevemar2yes agreed20:16
stevemar2i'll add what you said to the session20:16
ayoungstevemar2, cool.  It was one of those Aha moments....20:16
jog0Any ceilometer people around?20:17
ayoungstevemar2, I'd advise looking at the policy file that ships with Nova, too.  COmpare it with the Keystone one, and you get a sense of the patterns20:17
*** boden_ has quit IRC20:17
stevemar2also, nice use of the word kvelling, i learned a new word today20:17
ayoungstevemar2, Nu?20:17
jog0havea big that *may* be related to celio https://bugs.launchpad.net/nova/+bug/122198720:17
uvirtbotLaunchpad bug 1221987 in nova "compute node heartbeat out of sync causing scheduler to fail in devstack:  VMs fail to spawn" [Critical,Confirmed]20:17
*** davi67232 has joined #openstack-dev20:18
stevemar2ayoung: yep20:18
*** maheshp has quit IRC20:18
ayoungnunosantos, who's an upstream Horizon dev that would be interested in how to tailor the UI based on what roles the  user has?20:18
jog0jd__: ^20:18
dhellmannjog0: ugh, trying to keep that plugin working in nova is a real pita20:20
nunosantosayoung: hmm, maybe jpichon or mrunge20:20
ayoungnunosantos, thanks...that should get their attention.20:20
ayoungexcept they are not here now...oh well20:20
ayoungah well.20:20
*** anteaya has quit IRC20:21
jog0dhellmann: well if the bug above *is* related to celio then we are in trouble.  But I am not sure it is20:21
zulsdague:  *sigh* sure20:21
stevemar2ayoung: just a quick update as i'm leaving soon: http://summit.openstack.org/20:22
jog0was hoping to figure to get a celio dev to see if it smells related or not20:22
dhellmannjog0: if it's related to ceilometer, then just disable the plugin -- we know we have to rewrite it again because more internal nova apis changed on us20:22
*** giulivo has quit IRC20:22
jog0dhellmann: we should then just disable celimeter nova plugin in devstack/devstack-gate then right?20:23
jog0clarkb ^20:23
dhellmannjog0: well, unless some nova devs want to help us fix it20:23
dhellmannevery time we get it working you guys change APIs on us again :-)20:23
jog0dhellmann: sounds like we need a summit session on how to play nice with eachother20:23
dhellmannwhat we're trying to do is collect final usage info for an instance right before it is deleted20:23
dhellmannjog0: I'll bring the beer.20:23
*** davi67232 has quit IRC20:24
dhellmannI wonder if we're getting eventlet confused by making an extra rpc call in there20:24
jog0I see apparmor freak out too20:24
jog0dont know if thats related though20:25
jog0that appears unrelated20:25
*** noorul` has joined #openstack-dev20:26
dhellmannI don't run with apparmor, so I have no idea20:26
*** stevemar2 has quit IRC20:26
dhellmannat least I don't think I use that20:26
*** sarob has quit IRC20:28
*** noorul`` has joined #openstack-dev20:28
jog0dhellmann: http://summit.openstack.org/cfp/details/7320:28
*** asavu has quit IRC20:28
*** boden has joined #openstack-dev20:28
*** noorul has quit IRC20:28
*** mars has quit IRC20:29
dhellmannjog0: cool, just in time for me to share it with jd__ at our meeting in a few minutes20:29
jog0dhellmann: awesome, anyway need to step out for a bit20:29
dhellmannok20:30
jog0would you be fine with disabling nova celio plugin in devstack gate for now?20:30
morganfainbergayoung, are you (in anyway) opposed to encoding the domain in the user_id within assignment?  e.g. dn@domain, UUID@domain, etc.  it would make it so we could support multiple SQL domains as well.20:30
morganfainbergit means we'd need varchar(319) vs 255 though in assignment20:31
dhellmannjog0: I'll bring it up in the meeting. If we can prove that it's the plugin causing the problem, and not eventlet or something else in the notification pipeline, then I'm personally OK with it. But it's not my call alone.20:31
*** jcoufal_mtg is now known as jcoufal20:31
*** shinylasers has joined #openstack-dev20:31
*** adalbas has quit IRC20:31
*** noorul` has quit IRC20:32
morganfainbergayoung, oh wait nevermind.  looking at the data structure, that would make it more costly to look everything up20:32
*** boden has quit IRC20:33
jog0dhellmann: thanks, also celio is stacktracing like crazy even if its not related here20:34
jog0thanks20:34
dhellmannjog0: I'd love to have bugs for some of those so we can clean them up.20:34
dhellmannjog0: https://wiki.openstack.org/wiki/Meetings/MeteringAgenda#Agenda20:34
*** SergeyLukjanov has quit IRC20:35
*** bknudson has joined #openstack-dev20:36
*** larsks has quit IRC20:36
*** rwsu has joined #openstack-dev20:37
*** sarob has joined #openstack-dev20:40
*** noslzzp has quit IRC20:40
*** mattmalesky has quit IRC20:44
*** jecarey has joined #openstack-dev20:44
*** jpeeler1 has joined #openstack-dev20:45
*** jpeeler has quit IRC20:46
*** networkstatic has joined #openstack-dev20:46
*** jpeeler1 is now known as jpeeler20:46
*** jprovazn has quit IRC20:47
*** gimps_ has quit IRC20:49
*** mars has joined #openstack-dev20:51
*** dubsquared has quit IRC20:55
*** dubsquared has joined #openstack-dev20:55
*** eglynn-on-a-call is now known as eglynn20:57
*** dubsquared has quit IRC20:59
*** egallen has joined #openstack-dev21:00
*** tmclaugh[work] has quit IRC21:00
*** boden has joined #openstack-dev21:00
*** safchain has joined #openstack-dev21:01
*** martyntaylor has quit IRC21:02
*** kushal has quit IRC21:02
*** vuil has quit IRC21:03
*** rfolco has quit IRC21:04
*** pcm_ has quit IRC21:04
*** dolphm has joined #openstack-dev21:04
sdaguedtroyer: https://review.openstack.org/#/c/46114/ easy review :)21:04
*** esheffield has quit IRC21:05
*** boden has quit IRC21:05
*** swills has quit IRC21:05
*** rnirmal has quit IRC21:06
*** changbl has joined #openstack-dev21:06
*** davi67232 has joined #openstack-dev21:06
*** herndon has joined #openstack-dev21:08
*** vartom10 has quit IRC21:09
*** martine_ has quit IRC21:09
*** swills has joined #openstack-dev21:09
*** swills has quit IRC21:09
*** swills has joined #openstack-dev21:09
*** krtaylor has quit IRC21:09
dtroyersdague: +A21:10
*** sarob has quit IRC21:11
*** AlanClark has quit IRC21:14
*** jayg is now known as jayg|g0n321:15
*** mlavalle has quit IRC21:16
*** dvarga has quit IRC21:18
*** alunduil has quit IRC21:18
*** davi67232 has quit IRC21:18
*** donaldh has joined #openstack-dev21:22
*** changbl has quit IRC21:22
*** esheffield has joined #openstack-dev21:23
*** hashfail has joined #openstack-dev21:24
*** gimps has quit IRC21:26
*** dkranz has quit IRC21:26
*** blamar has quit IRC21:27
*** Ryan_Lane has quit IRC21:28
*** Ryan_Lane has joined #openstack-dev21:28
*** jasondotstar has quit IRC21:29
*** salv-orlando has joined #openstack-dev21:29
*** Ryan_Lane has quit IRC21:30
*** Ryan_Lane1 has joined #openstack-dev21:30
*** chenxu has quit IRC21:31
*** sushils has quit IRC21:34
*** henrynash has quit IRC21:36
*** sushils has joined #openstack-dev21:36
*** sarob has joined #openstack-dev21:36
*** anteaya has joined #openstack-dev21:39
*** spzala has quit IRC21:40
bknudsonanybody use keystone with ipv6? trying to figure out how to get it to listen on both v4 and v6 local21:43
bknudson(this is using keystone-all)21:43
dolphmbknudson: how do you have it configured?21:43
bknudsondolphm: just using the default now21:44
bknudsondefault bind_host21:44
*** doron_afk has joined #openstack-dev21:44
*** alop has quit IRC21:44
*** mlavalle has joined #openstack-dev21:44
*** sarob has quit IRC21:48
*** sarob has joined #openstack-dev21:48
*** alop has joined #openstack-dev21:50
dolphmbknudson: set bind_host to ::21:50
dolphmbknudson: 0.0.0.0 only appears to listen on all ipv4; :: appears to listen on all ipv4 + all ipv621:51
*** enikanorov_ has joined #openstack-dev21:51
bknudsondolphm: that's it.21:53
*** alagalah has joined #openstack-dev21:53
*** enikanorov has quit IRC21:54
*** shang has quit IRC21:55
*** angdraug has quit IRC21:55
*** angdraug has joined #openstack-dev21:57
*** alop has quit IRC21:57
*** davi67232 has joined #openstack-dev21:57
*** luxfx has joined #openstack-dev21:59
*** luxfx has quit IRC22:01
*** rwsu has quit IRC22:01
*** jecarey has quit IRC22:03
bknudsonI set KEYSTONE_AUTH_HOST=[::1] in localrc to see what happens.22:03
*** slagle has quit IRC22:04
*** isd has quit IRC22:06
*** danwent has quit IRC22:06
*** erkules has quit IRC22:07
*** alagalah has left #openstack-dev22:07
*** burt has quit IRC22:08
*** erkules has joined #openstack-dev22:08
*** kbringard has quit IRC22:09
*** fbo is now known as fbo_away22:10
*** alop has joined #openstack-dev22:11
*** gsilvis has quit IRC22:11
morganfainbergbknudson, let me know when you have a few, want to just run by this lingering RC1 bug I have make sure I'm not missing anything (LDAP stuffs)22:12
morganfainbergsame as this morning, but make sure someone else says "yep sounds right"22:12
morganfainbergwith the "fix" approach22:12
bknudsonmorganfainberg: shoot!22:12
*** gsilvis has joined #openstack-dev22:13
morganfainbergbknudson, ok https://bugs.launchpad.net/keystone/+bug/1219739 I think the fix is to fix "tenant_id" references to "tenandId" to match sql.  The other part of the bug, that keystone user-get <id> doesn't show the "default tenant" is invalid22:14
uvirtbotLaunchpad bug 1219739 in keystone "LDAP use 'tenant_id' instead of 'tenantId' in user_ref" [Medium,New]22:14
morganfainbergsince.. we don't store "extra data" in LDAP identity22:14
*** cdub has joined #openstack-dev22:14
morganfainbergand we don't have config options to store "tenantId" on the user object (e.g. ldap attribute)22:14
*** Ryan_Lane1 is now known as Ryan_Lane22:14
*** Ryan_Lane has joined #openstack-dev22:14
morganfainbergand the default behavior (config) is to "ignore" tenant_id attribute22:15
*** dolphm has quit IRC22:15
bknudsonthis is the user's default tenant ID?22:16
morganfainbergyep.22:16
bknudsonwhere's references to tenant_id ?22:16
morganfainbergin the ldap driver, it pulls "tenant_id" key off the user_ref when doing create/update22:16
morganfainbergsql would look at tenandId22:16
*** shardy is now known as shardy_afk22:17
*** lbragstad has quit IRC22:17
morganfainbergand the behavior is to add a role for the user associated with the project if tenant_id exists in the user_ref22:17
bknudsonso in create_user we've got tenant_id = user.get('tenant_id')22:17
morganfainbergyep.22:17
*** lifeless has quit IRC22:17
*** danwent has joined #openstack-dev22:17
bknudsonbut the client sends tenantId?22:18
*** mrodden has quit IRC22:18
*** dolphm has joined #openstack-dev22:18
morganfainbergchecking.22:18
*** krtaylor has joined #openstack-dev22:18
morganfainbergbut at least the other driver (SQL) expects tenantId22:18
bknudsonapi spec has "default_project_id": "263fd9", ... maybe it gets converted22:18
dolphmmorganfainberg: a bit of this review is your code- https://review.openstack.org/#/c/46098/22:18
*** otherwiseguy has quit IRC22:19
morganfainbergdolphm, will review as soon as i'm done with this convo w/ bknudson22:19
morganfainbergdolphm, looks straightforward though22:19
morganfainbergbknudson, hrm. i think we might have bigger issues then.22:19
morganfainberglooking at the client code right now22:19
morganfainbergoh.22:20
morganfainbergclient sends default_project_id22:20
*** networkstatic has quit IRC22:20
morganfainberglooks like the driver(s) might be wrong.22:20
morganfainbergmaybe controller is doing something22:20
bknudsongrepping for default_project_id in keystone only turns up tests and auth/controllers.22:21
morganfainbergv2.0 user controller uses tenantId22:22
bknudsonok, let's focus on v222:22
*** davi67232 has quit IRC22:22
morganfainbergbknudson, ok lets start there22:23
morganfainbergbknudson, ok tenantId is left as an "extra" attribute on the user in the controller, and it does a self.identity_api.add_user_to_project(default_tenant_id, user_id)22:24
dolphmv2 xml: <user tenantId="value" />, v2 json: "user": {"tenant_id": "value"}, v3 json: "user": {"default_tenant_id": "value"}22:24
bknudsonmorganfainberg: looking at https://github.com/openstack/keystone/blob/master/keystone/identity/controllers.py#L20622:25
bknudsonuser_ref is going to have tenantId and not tenant22:25
bknudsontenant_id22:25
morganfainbergbknudson, yep22:25
bknudsoncalls identity_api with that user_ref22:25
dolphmmorganfainberg: v3 should *not* call add_user_to_project() on user create / update, but v3 *should* check default_project_id on auth22:25
*** alop has quit IRC22:25
morganfainbergdolphm, correct, we're looking at v2.0 to start22:25
morganfainbergbknudson, it seems like we have a mis-implementation of the spec.22:26
bknudsonmorganfainberg: https://github.com/openstack/keystone/blob/master/keystone/identity/backends/ldap.py#L9622:26
bknudsonwouldn't expect the user to have tenant_id.22:26
morganfainbergwhere tenantId has been used before (essex and folsom) in the SQL driver.22:26
bknudsonhttps://github.com/openstack/keystone/blob/master/keystone/identity/controllers.py#L21522:27
dolphmldap driver shouldn't be calling the assignment_api...22:27
bknudsondoes self.identity_api.add_user_to_project(default_tenant_id, user_id)22:27
bknudsonhttps://github.com/openstack/keystone/blob/master/keystone/identity/backends/ldap.py#L9822:27
dolphmthis looks like manager code that code pasted into the ldap driver22:27
bknudsondoes self.assignment_api.add_user_to_project(tenant_id, user_id)22:27
bknudsonluckily tenant_id will always be None in ldap.py.22:28
*** tstevenson has quit IRC22:28
morganfainbergbknudson, ok so this is a bit of spaghetti to unravel.22:28
morganfainbergbknudson, right.22:28
morganfainbergok, so controller is the only place that should be handling the tenant_id portion?22:29
*** galstrom is now known as galstrom_zzz22:29
morganfainbergnot the drivers.22:29
*** prad has quit IRC22:29
bknudsonwe have to store the default project, right?22:30
dolphmmorganfainberg: it makes sense for the drivers to store it, but they shouldn't be performing business logic based on the value22:30
morganfainbergdolphm, right22:30
morganfainbergwe leave it as a property22:30
morganfainbergnot do the assignment work22:30
morganfainbergbknudson, well we don't have a mapping to store it in ldap at the moment, so ldap identity drops it on the floor22:30
morganfainbergit's by default in the ignore_attributes22:30
morganfainbergsql should store it.22:31
bknudsonwhat if it's not in ignore_attributes ?22:31
bknudsonalso, is it tenantId, tenant_id, or default_project_id ?22:31
morganfainbergbknudson, without a mapping, it raises an exception (400) on a key error?22:31
morganfainbergv2, should be tenant_id22:31
bknudsonwhat if it's mapped to something like businessCategory?22:31
morganfainbergas per the spec.22:31
morganfainbergbknudson, we use that for domain, but we could add the mapping22:32
*** neelashah has quit IRC22:32
morganfainbergto something else22:32
bknudsonit's user specific so doesn't have to be something in both group and user, so have more options for attributes.22:32
morganfainbergdolphm, you know this is two "looks simpler than it is" bugs i've stumbled into :P22:32
*** thedodd has quit IRC22:33
dolphmmorganfainberg: haha touche22:33
morganfainbergbknudson, right. let me look at the inetOrgPerson class and see what we have.22:33
morganfainbergbknudson, we could use "departmentNumber"22:34
morganfainbergor, if we want to go crazy with the car metaphors, "carLicense"22:34
morganfainberg:P22:34
jog0dhellmann: ping22:34
*** FunnyLookinHat has quit IRC22:35
morganfainbergthough.  i wonder if departmentNumber has to be int.22:35
*** alop has joined #openstack-dev22:36
dolphmmorganfainberg: it's a string22:36
*** carl_baldwin has quit IRC22:36
morganfainbergdolphm, yep, just found the reference.22:36
*** sushils has quit IRC22:36
morganfainbergso, department number could be the attribute map for tenant_id / default_project_id22:36
morganfainbergbknudson, unless there is a good reason not to use that.22:37
*** SumitNaiksatam has quit IRC22:37
bknudsonmorganfainberg: anything works in your tests.22:37
bknudsonand in the tests that you add to keystone22:38
morganfainbergbknudson, right, this would also be the default behavior if someone stood up keystone w/ a R/W ldap backend22:38
*** changbl has joined #openstack-dev22:38
bknudsonmorganfainberg: I thought the default is that tenant id is ignored?22:38
morganfainbergbknudson, right now, because we don't have an attribute mapping22:39
morganfainbergwe could remove that ignore if we added this mapping22:39
*** epim has quit IRC22:40
*** e1mer has joined #openstack-dev22:41
*** e1mer has joined #openstack-dev22:41
dolphmbknudson: morganfainberg: i suspect the reason it's ignored by default is due to the same uncertainty you're facing... i'd say pick an attribute to hijack and document that default behavior in keystone.conf.sample AND docs22:41
dolphmbknudson: morganfainberg: i.e. ensure whatever is chosen is not a surprise22:41
bknudsonthe problem is there is no good mapping.22:42
morganfainbergdolphm, sounds good.22:42
*** flaper87 is now known as flaper87|afk22:42
jog0jd__: ping22:42
morganfainbergbknudson, businessCategory is already being hijacked for domain.22:42
bknudsonmorganfainberg: is that only in devstack or in keystone?22:42
morganfainbergbknudson, default in keystone22:42
*** sushils has joined #openstack-dev22:43
morganfainberghttps://github.com/openstack/keystone/blob/master/keystone/common/config.py#L18322:43
bknudsonsince we've been able to live with it not mapped until now, I suggest continue to leave it not mapped.22:43
bknudsonwe might have had to have businessCategory mapped just to function.22:44
morganfainbergbknudson, that means default tenant/project will not be handled by LDAP identity backend?22:44
dolphmbknudson: worth noting: last time this came up for discussion, the user's tenant id represented authz, but now it's just a user preference / attribute22:44
*** sandywalsh has quit IRC22:44
bknudsonit won't be handled by default22:44
*** jvrbanac has quit IRC22:44
morganfainbergbknudson, i'm ok with that.22:44
bknudsonbut it will be handled if the customer can come up with some way to map it.22:44
*** danwent_ has joined #openstack-dev22:44
morganfainbergbknudson and not ignore it22:45
bknudson(which it appears is not working now)22:45
*** radsy has joined #openstack-dev22:45
morganfainbergso, v2.0 of the keystone client passes in tenantId22:45
morganfainbergand the api spec says it should be tenant_id22:45
bknudsondolphm: btw - I did some experimentation on this one: https://review.openstack.org/#/c/43041/ , and now think it's useful.22:45
dolphmmorganfainberg: eek, let me check the spec22:46
morganfainbergdolphm, at least waht you posted earlier that is22:46
dolphmmorganfainberg: well.. nvm... the spec only covers xml22:46
*** danwent has quit IRC22:46
*** danwent_ is now known as danwent22:46
morganfainbergdolphm, wouldn't that translate the same to json though?22:46
dolphmmorganfainberg: there's no api spec for v2 json -- implementation is the truth there22:46
morganfainberg<tenant_id>blah<./..> == tenant_id: blah22:46
morganfainbergdolphm, i meant how it gets passed to the controller.22:47
*** alunduil has joined #openstack-dev22:47
dolphmmorganfainberg: IIRC, the camelcase in the xml spec is/was translated to use underscores22:48
morganfainbergdolphm, ah22:48
dolphmmorganfainberg: whatever the client sends and the v2 controller expects is the truth though22:48
morganfainbergok so it's tenantId22:48
bknudsondolphm: where's the spec? on your whiteboard?22:48
dolphmbknudson: in openstack/identity-api22:48
dolphmbknudson: https://github.com/openstack/identity-api/tree/master/openstack-identity-api/v2.0/src/docbkx22:49
morganfainbergdolphm, i haven't looked at the xml translation stuff.. should see what it actually does22:49
bknudsonit's a lot different22:49
bknudsonmorganfainberg: you will be amazed and surprised22:49
morganfainbergbknudson, should i be scared?22:50
dolphmbknudson: what the xml looks like?22:50
dolphmbknudson: or what the spec looks like?22:50
dolphmbknudson: ... which is more xml22:50
bknudsonthe XML <-> JSON conversion22:50
dolphmah22:50
bknudsonI meant the v2 spec in docbook is a lot different than the .md for v3.22:51
*** jimfehlig has quit IRC22:51
*** networkstatic has joined #openstack-dev22:51
dolphmbknudson: someone at HP is working on writing wadl+xsd for v322:52
bknudsondolphm: is our v3 spec supposed to look like the v2 spec (with wadls, etc?)22:52
bknudsonhow did you answer my question before I sent it?22:52
dolphmbknudson: magicals22:52
bknudsonhopefully they document JSON this time.22:52
dolphmbknudson: in fact, a bit of it is already in review22:53
*** alop has quit IRC22:53
dolphmbknudson: of course not!22:53
bknudsonhere's the json : https://github.com/openstack/identity-api/blob/master/openstack-identity-api/v2.0/src/docbkx/samples/user.json22:53
*** colinmcnamara has joined #openstack-dev22:53
morganfainbergdolphm, it looks like the from_xml doesn't handle tenant_id -> tenantId22:53
dolphmbknudson: it's been on my wishlist for a long time to doc the json in jsonschema22:53
*** dmakogon_ has quit IRC22:53
morganfainbergseems like it should be the special case e.g. "policies" -> "policy" type deal22:54
morganfainbergthouhg… i might be just missing something22:54
bknudsonmorganfainberg: what does the client send? when you do keystone user-create22:55
dolphmmorganfainberg: hmm... the translator probably doesn't handle it because create user is non-core, and the translator was only written against the core api22:55
morganfainbergtenantId json.22:55
morganfainbergbknudson, that was to you22:55
bknudsonmorganfainberg: and that's what the controller is expecting.22:55
morganfainbergdolphm, ah. that means this whole semantic is probably not working via xml :P22:55
morganfainbergbknudson, yep.22:55
bknudsonmorganfainberg: I would trust the controller a lot more than I would trust the ldap backend for some reason22:56
*** MaxV_ has quit IRC22:56
morganfainbergbknudson, i don't think we should change that.22:56
dolphmmorganfainberg: it's not tested == it's broken, in my book22:56
morganfainbergi was wondering if we needed to change the from_xml.22:56
morganfainbergor just… call it a day and come back to this kind of issue in v3 :P22:56
morganfainbergi doubt people are heavily using the XML in this fashion…since it doesn't work :P22:56
*** sandywalsh has joined #openstack-dev22:56
bknudsonmorganfainberg: still wondering what happens with v3, does it change default_project_id to tenantId ?22:56
morganfainbergbknudson, looking at that now.  i don't think so.22:57
bknudsondoes the sql backend handle both?22:57
morganfainbergthere is a FIXME i think by dolph i saw.  trying to find it22:57
*** e1mer has quit IRC22:57
dolphmmorganfainberg: =(22:57
*** nrs_ has quit IRC22:57
*** e1mer has joined #openstack-dev22:57
*** e1mer has joined #openstack-dev22:57
morganfainbergbknudson, SQL doesn't care.  they are both jsut arbitrary attributes that are stored in the "extra" (i.e. json blob) field22:57
morganfainbergyou mean does it do anything with them?  thats what i'm looking for22:58
dolphmbknudson: i'd actually expect the opposite now... the deprecated controllers should rewrite things in terms of the v3 api's semantics, for persistance22:58
*** nrs_ has joined #openstack-dev22:58
dolphmmorganfainberg: sql doesn't care, but a user created on one api will behave unexpectedly on the other api22:59
bknudsontry create a user with v2 and then get user with v322:59
bknudsonshould get back default_project_id for v3?22:59
morganfainbergwell, with ldap and v3 if you pass default_project_id in, you'll get an exception22:59
dolphmbknudson: *should*22:59
*** shang has joined #openstack-dev22:59
morganfainbergit looks like23:00
*** mlavalle has quit IRC23:00
morganfainbergoh .23:00
morganfainberguhm.23:00
morganfainbergright 1 domain per ldap server right?23:01
bknudsonI got "tenantId": "57a08bb4053c43a999bca6a93830cc9d" and no default_project_id23:01
*** alop has joined #openstack-dev23:02
morganfainbergbknudson, did it have tenantId on it?23:02
*** dhellmann is now known as dhellmann_23:02
morganfainbergassuming creation in v2?23:02
*** dhellmann_ is now known as dhellmann23:02
bknudson$ keystone user-create --name blk1 --tenant demo --pass blkpwd23:02
bknudsonoops, gave away my password23:02
*** Samos123 has quit IRC23:02
morganfainberglol23:02
morganfainbergshowed up as ****** herre23:02
morganfainberg:P23:02
dolphmmorganfainberg: ++23:03
dolphmbknudson: no need to file a CVE23:03
bknudsonbut with curl -H "X-Auth-Token: blkpwd" "http://\[::1\]:5000/v3/users/97fedfd671aa4798bdde8462f4505f7b"23:03
bknudsonget back "tenantId": "57a08bb4053c43a999bca6a93830cc9d"23:03
bknudsonand no default_project_id23:03
*** Samos123 has joined #openstack-dev23:03
morganfainbergyeah, it doesn't translate.23:03
bknudsonthat's going to make it difficult for a gui23:04
morganfainbergdo we _really_ need to support the default_project_id semantic?23:04
morganfainberg(i know i know...spec)23:04
dolphmmorganfainberg: that question gets asked like once a month lol23:04
morganfainbergdolphm, i'd love to see it go away23:04
dolphmmorganfainberg: v3 is a step in that direction... and as *away* as we could make it23:04
bknudsonwe've got other options too, like email23:05
dolphmmorganfainberg: it's at least not magical authz anymore23:05
bknudsondoes openstack really need that?23:05
dolphmbknudson: nope23:05
morganfainbergdolphm, ok so we need to make the respective get_user do the translation to the "correct" attribute23:05
*** colinmcnamara has quit IRC23:05
morganfainbergand store it the same way on the backend.23:05
dolphmmorganfainberg: and probably migrate one value to the other23:06
morganfainbergi was going to make it go to the v3 one23:06
dolphmmorganfainberg: and turn it into an first class column in sql23:06
bknudsonwe need to continue to support existing messed up systems.23:06
morganfainbergdolphm, yeah23:06
morganfainbergand we need to get the tenant_id, tenantId, default_project_id sillyness out of the driver and in the manager/controller23:07
morganfainbergok.  i think i have the fix in mind.23:07
morganfainbergbknudson, dolphm, thanks for working this one through.  more rabbit hole bugs ;)23:07
*** prad has joined #openstack-dev23:08
*** edmund has quit IRC23:08
dolphmmorganfainberg: thank you!23:08
bknudsonmorganfainberg: not sure what this might affect out in the field, but backport to grizzly?23:09
morganfainbergreminds me, i have a bug fix i need to get into oslo's logging… something something RFC5424 support is bad in python.23:09
morganfainbergbknudson, yeah, this should be backported.23:09
bknudsonmorganfainberg: I don't think we can add a migration in a backport.23:10
morganfainbergbknudson, no, but i can do the translation stuff23:10
morganfainbergthat can just be magic code mucking with the data in-flight23:10
bknudsonmorganfainberg: sounds good23:10
dolphmmorganfainberg: is this all as a result of that ldap bug?23:10
*** zbitter has joined #openstack-dev23:11
morganfainbergdolphm, i'm going to mark that bug as invalid and open a new one that actually adresses the issue23:11
*** dhellmann is now known as dhellmann_23:11
dolphmmorganfainberg: okay, i'd like *this* issue to be High and RC123:11
morganfainbergthat bug is claiming that ldap isn't returning a tenant_id / default_project_id23:11
dolphmmorganfainberg: which is really "ldap is probably misconfigured"?23:11
morganfainbergthat is invalid, since it's intentional we drop that on the floor in current impl23:11
morganfainbergdolphm, i'd say more so the implementation decided to ignore that field.23:12
morganfainbergit is by default in the ignore_attributes23:12
morganfainbergand yes, i'll mark it as high against RC1 and see what i can pull together in the next day or so.23:12
dolphmmorganfainberg: you can't configure which attribute it gets written to?23:12
*** lifeless has joined #openstack-dev23:12
morganfainbergdolphm, nope no option to do that23:12
dolphmoh23:12
*** sushils has quit IRC23:12
morganfainbergwould require a code change to do it.23:12
morganfainbergyeah, dropping it on the floor seems very intentional here23:13
bknudsonwe can have a mapping?23:13
morganfainbergyep, i'll add the mapping to departmentNumber23:13
morganfainbergas the default.23:13
bknudsonI don't think we have to change the default config.23:13
bknudsonas long as there's a config that works, customers can use it.23:13
morganfainbergbknudson, we can keep it ignored.23:13
morganfainbergbut it looks like you need some kind of sane default mapping.23:14
bknudsondepartmentNumber is sane?23:14
*** zaneb has quit IRC23:14
morganfainbergbknudson, inetorgperson has limited options23:14
morganfainbergi actually vote carlicense23:15
morganfainbergkeep with the car metaphors23:15
bknudsonthat's why there's no good default mapping23:15
*** donaldh has quit IRC23:15
morganfainbergand businessCategory is good for domain?23:15
morganfainbergbesides really just being "needed"23:15
morganfainbergactually.23:15
morganfainbergwait a sec.23:15
*** jamielennox|away is now known as jamielennox23:15
morganfainbergwe should be stripping the domain out .23:15
morganfainberghttps://github.com/openstack/keystone/blob/master/keystone/identity/core.py#L27923:16
dolphmmorganfainberg: what's the analogy for car license?23:16
morganfainbergldap driver is not domain aware23:16
dolphmdomain shouldn't be stored in ldap, anymore23:16
morganfainbergso we should be dropping domain info on the floor23:16
bknudsonyea, that's weird.23:16
morganfainbergi'll yank that mapping then23:16
dolphmmorganfainberg: https://bugs.launchpad.net/keystone/+bug/120944023:16
uvirtbotLaunchpad bug 1209440 in keystone "LDAP identity still allows setting domain via attribute" [Medium,Incomplete]23:16
dolphmmorganfainberg: i think resolving this bug ^ just involves cleaning up any remaining domain stuff for ldap23:17
morganfainbergyep.23:17
dolphmand i don't think ayoung is working it23:17
morganfainbergdolphm, i'll solve that one as a side-effect of the rest of the fixes here.23:17
*** alop has quit IRC23:20
*** jcoufal has quit IRC23:21
*** salv-orlando has quit IRC23:21
*** gordc has quit IRC23:22
*** herndon has quit IRC23:27
*** dolphm has quit IRC23:28
*** prad has quit IRC23:29
jamielennoxgyee: ayoung: you here?23:31
jamielennoxregarding: https://review.openstack.org/#/c/34161 - auth_token with requests library23:32
*** dolphm has joined #openstack-dev23:34
*** anteaya_ has joined #openstack-dev23:35
*** dolphm has quit IRC23:35
*** huats has quit IRC23:37
*** huats has joined #openstack-dev23:37
*** kbrierly has quit IRC23:37
*** mattmalesky has joined #openstack-dev23:38
*** anteaya has quit IRC23:38
gyeejamielennox, yes23:38
jamielennoxgyee: so i'm not sure you and ayoung are arguing different points, though he ended up with a +123:39
gyeejamielennox, I think we are arguing over two different topics23:39
jamielennoxi essentially that you should be able to provide a specific CA for https connections23:39
jamielennoxessentially agree23:39
gyeethat's correct23:39
jamielennoxputting things into system cas seems dodgy23:40
gyeewe need add a configurable param for auth_token filter, ca_file23:40
gyeein the same manner as certfile and keyfile23:40
*** markwash has quit IRC23:40
jamielennoxah, my mistake23:41
jamielennoxi was under the impression that we already have a config argument for a ca file23:41
jamielennoxbut it's generated from the siging_dir variable23:41
*** sarob has quit IRC23:41
gyeejamielennox, signing_dir is for facilitating token validation23:42
jamielennoxthat's the signing token ca23:42
gyeeright, which is different than SSL cert CA23:42
jamielennoxyes and they shouldn't be the same23:42
jamielennoxshouldn't necessarily be the same23:43
gyeeagree with your second sentence :)23:43
jamielennoxgyee: ok, that's easier than i thought - i was thinking i was going to have to have 2 ca's specified in config23:44
jamielennoxi'll fix that up today23:44
*** hartsocks has joined #openstack-dev23:44
gyeejamielennox, awesome23:44
*** sarob has joined #openstack-dev23:45
ayoungjamielennox, I'm here...reading up23:45
jamielennoxayoung: that's ok, i was thinking i was going to have to kludge some config variablse but it's fine23:45
*** sarob has quit IRC23:46
ayoungmorganfainberg, if you want to take bug 1209440 go for it.  I hadn't started looking at it23:47
uvirtbotLaunchpad bug 1209440 in keystone "LDAP identity still allows setting domain via attribute" [Medium,Incomplete] https://launchpad.net/bugs/120944023:47
morganfainbergayoung, yeah i'll grab that as part of this ldap cleanup23:47
ayoungmorganfainberg, thanks23:47
bknudsonjamielennox: your https://review.openstack.org/#/c/34161 and https://review.openstack.org/#/c/43041 hit some of the same lines.23:47
morganfainbergran into some inconsistencies that need to be addressed around tenant_id etc23:47
ayoungmorganfainberg, anything need review?23:47
jamielennoxbknudson: so it looks like 43041 will pass, so i'll rebase on that23:48
morganfainbergayoung, not yet. unless you have criticism for the domain_cleanup one https://review.openstack.org/#/c/45649/ before the next patchset (which will depend on the changes inc. migration user_id etc fixes talked about this morning)23:48
gyeejamielennox, one more thing, https://review.openstack.org/#/c/45997/23:48
jamielennoxayoung: if you're looking for things look at keystoneclient23:48
morganfainbergayoung, there is the httpretty one that needs review on client ;)23:49
gyeeI thought auth plugin is passed in during client instantiation23:49
ayoungjamielennox, I have been looking at yours, but wanted to make sure I wasn't blocking anything that morganfainberg was doing that was fixing my bugs for me23:49
morganfainbergjamielennox, see that, plugged it for you!23:49
*** cdub has quit IRC23:49
*** hartsocks has left #openstack-dev23:49
jamielennoxgyee: no, the auth plugin will be attached to the session object23:49
*** jcoufal has joined #openstack-dev23:49
morganfainbergayoung, i'll have some stuff up likely tonight/tomorrow. bunch of work to start working on.23:50
jamielennoxgyee: the idea is that session will be passed around and shared between multiple clients, thus sharing a token23:50
gyeejamielennox, have you look at the novaclient impl23:50
gyeeI mean the auth plugin23:50
jamielennoxgyee: it was a couple of weeks ago, but i think that still works23:50
bknudsonjamielennox: my own analysis of https://review.openstack.org/#/c/43041 is that it's ok but not very useful, but it may be more interesting with https://review.openstack.org/#/c/3416123:50
jamielennoxbknudson: i passed on 43041, i've not done enough with ipv6 to even understand what it's trying to do23:51
bknudsonjamielennox: when you build a url with IPv6 literal address, need to put it in []23:52
bknudsonhttp://[::1]:5000/v3/auth/tokens23:52
gyeebknudson, why can't auth_uri be configured to a IPv6 uri?23:52
bknudsonan IPv6 address works in auth_host now23:53
gyeeauth_uri = http://[]...23:53
*** alop has joined #openstack-dev23:53
gyeeuri_parse can't handle that?23:53
jamielennoxbknudson: my preferred approach when this requests thing goes in is to get rid of the url building23:53
bknudsongyee: auth_uri can optionally be set, or it gets built from other parts (auth_host for example)23:53
*** otherwiseguy has joined #openstack-dev23:54
jamielennoxthe seperate handling of auth_protocol, auth_uri, auth_port etc make sense (somewhat) when using httplib, with requests we specify a URI to talk to23:54
bknudsonjamielennox: your patch https://review.openstack.org/#/c/34161/13/keystoneclient/middleware/auth_token.py doesn't use provided auth_uri23:54
jamielennoxi'd much prefer to deprecate all those config options in favour of passing a fully qualified url23:54
bknudsonjamielennox: wouldn't that be auth_uri?23:54
gyeeI thought we are deprecating host and port in favor of auth_uri, no?23:54
jamielennoxbknudson: i did originally, but there are some tempest tests that fail that way23:55
*** anteaya__ has joined #openstack-dev23:55
bknudsonmight need to fix tempest23:55
jamielennoxauth_uri is used specifically in one place, where you specify a 401 with a auth_url23:55
*** alop has quit IRC23:55
jamielennoxthere is no requirement that auth_uri therefore be the same as what is provided initially - it's bad and it's wrong but i talked with ayoung about it and it just has the potential to break too many people23:56
jamielennoxprovided initially = auth_protocol + auth_host + auth_port23:56
bknudsonwhy can't you use auth_uri if it's given rather than auth_protocol + auth_host + auth_port ?23:57
gyeeexactly, look for auth_uri first23:58
*** anteaya_ has quit IRC23:58
gyeeif its there, ignore the others23:58
jamielennoxthat would be great and that's how i started, what happens in the case both are configured?23:59
bknudsongyee was saying to ignore auth_protocol + auth_host + auth_port23:59

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!