*** tosky has quit IRC | 00:09 | |
*** brokencycle has quit IRC | 00:53 | |
*** threestrands has joined #openstack-dev | 02:51 | |
*** morazi has quit IRC | 03:27 | |
*** psachin has joined #openstack-dev | 03:30 | |
*** factor has joined #openstack-dev | 03:34 | |
*** avolkov has joined #openstack-dev | 04:12 | |
*** ircuser-1 has quit IRC | 04:23 | |
*** evrardjp has quit IRC | 04:35 | |
*** evrardjp has joined #openstack-dev | 04:35 | |
*** udesale has joined #openstack-dev | 05:29 | |
*** dpawlik has joined #openstack-dev | 05:56 | |
*** pcaruana has joined #openstack-dev | 06:01 | |
*** yolanda has joined #openstack-dev | 06:16 | |
*** seco has joined #openstack-dev | 06:41 | |
*** dancn has joined #openstack-dev | 06:50 | |
*** lennyb has quit IRC | 06:54 | |
*** nightmare_unreal has joined #openstack-dev | 07:02 | |
*** ccamposr__ has joined #openstack-dev | 07:05 | |
*** ltyrex has joined #openstack-dev | 07:06 | |
*** slaweq has joined #openstack-dev | 07:06 | |
*** iurygregory has quit IRC | 07:09 | |
*** iurygregory has joined #openstack-dev | 07:10 | |
*** tesseract has joined #openstack-dev | 07:14 | |
*** rpittau|afk is now known as rpittau | 07:22 | |
*** tosky has joined #openstack-dev | 07:26 | |
*** jcapitao has joined #openstack-dev | 07:34 | |
*** sshnaidm|afk is now known as sshnaidm | 07:35 | |
*** jcapitao has quit IRC | 07:38 | |
*** jcapitao has joined #openstack-dev | 07:40 | |
*** ccamacho has joined #openstack-dev | 07:43 | |
*** ccamposr has joined #openstack-dev | 07:45 | |
*** ccamposr__ has quit IRC | 07:47 | |
*** jpich has joined #openstack-dev | 07:50 | |
*** jpich has quit IRC | 07:52 | |
*** jpich has joined #openstack-dev | 07:55 | |
*** rcernin has quit IRC | 08:13 | |
*** threestrands has quit IRC | 08:20 | |
*** tkajinam has quit IRC | 08:23 | |
*** logan_ has joined #openstack-dev | 08:31 | |
*** logan- has quit IRC | 08:32 | |
*** logan_ is now known as logan- | 08:35 | |
*** gfidente has joined #openstack-dev | 09:22 | |
*** ttsiouts has joined #openstack-dev | 09:24 | |
*** dtantsur|afk is now known as dtantsur | 09:49 | |
*** yolanda has quit IRC | 09:56 | |
*** yolanda has joined #openstack-dev | 10:10 | |
*** rpittau is now known as rpittau|bbl | 10:32 | |
*** ttsiouts has quit IRC | 10:49 | |
*** ttsiouts has joined #openstack-dev | 10:54 | |
*** jcapitao is now known as jcapitao_lunch | 11:03 | |
*** smcginnis has quit IRC | 11:40 | |
*** smcginnis has joined #openstack-dev | 11:41 | |
*** yolanda has quit IRC | 11:44 | |
*** yolanda has joined #openstack-dev | 11:44 | |
*** bbowen_ has quit IRC | 11:53 | |
*** bbowen_ has joined #openstack-dev | 11:53 | |
*** nweinber has joined #openstack-dev | 11:57 | |
*** __ministry has joined #openstack-dev | 12:04 | |
*** jcapitao_lunch is now known as jcapitao | 12:04 | |
*** __ministry has quit IRC | 12:05 | |
*** raildo has joined #openstack-dev | 12:09 | |
*** morazi has joined #openstack-dev | 12:20 | |
*** seco has quit IRC | 12:33 | |
*** ondrejburian has quit IRC | 12:45 | |
*** rpittau|bbl is now known as rpittau | 12:49 | |
*** lbragstad has joined #openstack-dev | 12:59 | |
*** kgiusti has joined #openstack-dev | 13:00 | |
*** mrtadis has quit IRC | 13:02 | |
*** mrtadis has joined #openstack-dev | 13:03 | |
*** seco has joined #openstack-dev | 13:04 | |
*** seco has quit IRC | 13:08 | |
*** _mmethot_ has quit IRC | 13:10 | |
*** mmethot has joined #openstack-dev | 13:11 | |
*** eharney has joined #openstack-dev | 13:14 | |
*** udesale_ has joined #openstack-dev | 13:20 | |
*** udesale has quit IRC | 13:23 | |
*** dsneddon has quit IRC | 13:23 | |
*** mmethot has quit IRC | 13:25 | |
*** mmethot has joined #openstack-dev | 13:26 | |
*** ttsiouts has quit IRC | 13:26 | |
*** rloo has joined #openstack-dev | 13:27 | |
*** seco has joined #openstack-dev | 13:32 | |
*** psachin has quit IRC | 13:35 | |
*** tkajinam has joined #openstack-dev | 13:42 | |
*** ondrejburian has joined #openstack-dev | 13:47 | |
*** mikecmpbll has joined #openstack-dev | 13:53 | |
*** ttsiouts has joined #openstack-dev | 13:58 | |
*** ttsiouts has quit IRC | 14:03 | |
*** ttsiouts has joined #openstack-dev | 14:05 | |
*** irclogbot_0 has joined #openstack-dev | 14:08 | |
*** irclogbot_0 has quit IRC | 14:12 | |
*** irclogbot_1 has joined #openstack-dev | 14:22 | |
*** irclogbot_1 has quit IRC | 14:25 | |
*** irclogbot_1 has joined #openstack-dev | 14:25 | |
*** ttsiouts has quit IRC | 14:27 | |
*** irclogbot_1 has quit IRC | 14:29 | |
*** irclogbot_2 has joined #openstack-dev | 14:29 | |
*** irclogbot_2 has quit IRC | 14:35 | |
*** irclogbot_1 has joined #openstack-dev | 14:35 | |
*** READ10 has joined #openstack-dev | 14:37 | |
*** irclogbot_1 has quit IRC | 14:39 | |
*** irclogbot_2 has joined #openstack-dev | 14:39 | |
*** mlavalle has joined #openstack-dev | 14:41 | |
*** irclogbot_2 has quit IRC | 14:45 | |
*** irclogbot_3 has joined #openstack-dev | 14:45 | |
*** iurygregory has quit IRC | 14:47 | |
*** iurygregory has joined #openstack-dev | 14:48 | |
*** stewie925 has joined #openstack-dev | 14:49 | |
*** beekneemech is now known as bnemec | 14:50 | |
*** irclogbot_3 has quit IRC | 14:51 | |
*** irclogbot_2 has joined #openstack-dev | 14:51 | |
*** tkajinam has quit IRC | 14:54 | |
*** irclogbot_2 has quit IRC | 14:55 | |
*** irclogbot_2 has joined #openstack-dev | 14:56 | |
*** irclogbot_2 has quit IRC | 14:59 | |
*** irclogbot_0 has joined #openstack-dev | 15:00 | |
*** dklyle has joined #openstack-dev | 15:00 | |
*** irclogbot_0 has quit IRC | 15:03 | |
*** irclogbot_3 has joined #openstack-dev | 15:04 | |
*** irclogbot_3 has quit IRC | 15:07 | |
*** irclogbot_0 has joined #openstack-dev | 15:08 | |
*** irclogbot_0 has quit IRC | 15:11 | |
*** irclogbot_2 has joined #openstack-dev | 15:12 | |
*** irclogbot_2 has quit IRC | 15:15 | |
*** irclogbot_0 has joined #openstack-dev | 15:16 | |
*** ltyrex has quit IRC | 15:17 | |
*** irclogbot_0 has quit IRC | 15:19 | |
*** irclogbot_1 has joined #openstack-dev | 15:20 | |
*** irclogbot_1 has quit IRC | 15:23 | |
*** irclogbot_2 has joined #openstack-dev | 15:24 | |
*** irclogbot_2 has quit IRC | 15:27 | |
*** irclogbot_1 has joined #openstack-dev | 15:28 | |
*** __ministry has joined #openstack-dev | 15:28 | |
*** irclogbot_1 has quit IRC | 15:31 | |
*** irclogbot_3 has joined #openstack-dev | 15:37 | |
*** _mlavalle_1 has joined #openstack-dev | 15:38 | |
*** mlavalle has quit IRC | 15:40 | |
*** seco has quit IRC | 15:51 | |
*** sshnaidm is now known as sshnaidm|afk | 15:53 | |
*** mikefix has joined #openstack-dev | 15:59 | |
*** dsneddon has joined #openstack-dev | 15:59 | |
*** tesseract has quit IRC | 16:02 | |
*** rpittau is now known as rpittau|afk | 16:07 | |
*** jpich has quit IRC | 16:11 | |
*** iurygregory has quit IRC | 16:17 | |
*** Dantalio- has joined #openstack-dev | 16:20 | |
*** Dantalion has quit IRC | 16:20 | |
*** dsneddon has quit IRC | 16:26 | |
*** udesale_ has quit IRC | 16:26 | |
*** mrtadis has quit IRC | 16:26 | |
*** kgiusti has quit IRC | 16:26 | |
*** raildo has quit IRC | 16:26 | |
*** vesper11 has quit IRC | 16:26 | |
*** mbandeir has quit IRC | 16:26 | |
*** negronjl has quit IRC | 16:26 | |
*** mikecmpbll has quit IRC | 16:26 | |
*** maharg101 has quit IRC | 16:26 | |
*** athmane has quit IRC | 16:26 | |
*** haleyb has quit IRC | 16:26 | |
*** fmount has quit IRC | 16:26 | |
*** iokiwi has quit IRC | 16:26 | |
*** cswang has quit IRC | 16:26 | |
*** admcleod has quit IRC | 16:26 | |
*** radez has quit IRC | 16:26 | |
*** rmk has quit IRC | 16:26 | |
*** rektide has quit IRC | 16:26 | |
*** rha has quit IRC | 16:26 | |
*** tonyb has quit IRC | 16:26 | |
*** kgz has quit IRC | 16:26 | |
*** tris has quit IRC | 16:26 | |
*** rektide has joined #openstack-dev | 16:27 | |
*** admcleod has joined #openstack-dev | 16:28 | |
*** irclogbot_3 has quit IRC | 16:28 | |
*** tris has joined #openstack-dev | 16:29 | |
*** vesper11 has joined #openstack-dev | 16:29 | |
*** irclogbot_1 has joined #openstack-dev | 16:29 | |
*** kgz has joined #openstack-dev | 16:29 | |
*** dsneddon has joined #openstack-dev | 16:31 | |
*** udesale_ has joined #openstack-dev | 16:31 | |
*** mrtadis has joined #openstack-dev | 16:31 | |
*** kgiusti has joined #openstack-dev | 16:31 | |
*** raildo has joined #openstack-dev | 16:31 | |
*** mbandeir has joined #openstack-dev | 16:31 | |
*** negronjl has joined #openstack-dev | 16:31 | |
*** mikecmpbll has joined #openstack-dev | 16:32 | |
*** maharg101 has joined #openstack-dev | 16:32 | |
*** athmane has joined #openstack-dev | 16:32 | |
*** haleyb has joined #openstack-dev | 16:32 | |
*** fmount has joined #openstack-dev | 16:32 | |
*** iokiwi has joined #openstack-dev | 16:32 | |
*** cswang has joined #openstack-dev | 16:32 | |
*** radez has joined #openstack-dev | 16:32 | |
*** rmk has joined #openstack-dev | 16:32 | |
*** rha has joined #openstack-dev | 16:32 | |
*** tonyb has joined #openstack-dev | 16:32 | |
*** evrardjp has quit IRC | 16:35 | |
*** jcapitao has quit IRC | 16:35 | |
*** ChanServ has quit IRC | 16:42 | |
*** ChanServ has joined #openstack-dev | 16:45 | |
*** tepper.freenode.net sets mode: +o ChanServ | 16:45 | |
*** evrardjp has joined #openstack-dev | 16:46 | |
*** udesale_ has quit IRC | 16:50 | |
*** _mlavalle_1 has quit IRC | 17:09 | |
*** mlavalle has joined #openstack-dev | 17:11 | |
*** dtantsur is now known as dtantsur|afk | 17:18 | |
*** yolanda has quit IRC | 17:18 | |
*** bbowen_ has quit IRC | 17:22 | |
*** bbowen has joined #openstack-dev | 17:25 | |
*** maharg101 has quit IRC | 17:26 | |
*** athmane has quit IRC | 17:26 | |
*** haleyb has quit IRC | 17:26 | |
*** fmount has quit IRC | 17:26 | |
*** iokiwi has quit IRC | 17:26 | |
*** cswang has quit IRC | 17:26 | |
*** radez has quit IRC | 17:26 | |
*** rmk has quit IRC | 17:26 | |
*** rha has quit IRC | 17:26 | |
*** tonyb has quit IRC | 17:26 | |
*** dsneddon has quit IRC | 17:26 | |
*** mrtadis has quit IRC | 17:26 | |
*** kgiusti has quit IRC | 17:26 | |
*** raildo has quit IRC | 17:26 | |
*** mbandeir has quit IRC | 17:26 | |
*** negronjl has quit IRC | 17:26 | |
*** jcapitao has joined #openstack-dev | 17:28 | |
*** maharg101 has joined #openstack-dev | 17:29 | |
*** athmane has joined #openstack-dev | 17:29 | |
*** haleyb has joined #openstack-dev | 17:29 | |
*** fmount has joined #openstack-dev | 17:29 | |
*** iokiwi has joined #openstack-dev | 17:29 | |
*** cswang has joined #openstack-dev | 17:29 | |
*** radez has joined #openstack-dev | 17:29 | |
*** rmk has joined #openstack-dev | 17:29 | |
*** rha has joined #openstack-dev | 17:29 | |
*** tonyb has joined #openstack-dev | 17:29 | |
*** dsneddon has joined #openstack-dev | 17:29 | |
*** mrtadis has joined #openstack-dev | 17:29 | |
*** kgiusti has joined #openstack-dev | 17:29 | |
*** raildo has joined #openstack-dev | 17:29 | |
*** mbandeir has joined #openstack-dev | 17:29 | |
*** negronjl has joined #openstack-dev | 17:29 | |
*** nightmare_unreal has quit IRC | 17:32 | |
*** ChanServ has quit IRC | 17:39 | |
*** ChanServ has joined #openstack-dev | 17:42 | |
*** tepper.freenode.net sets mode: +o ChanServ | 17:42 | |
*** jcapitao has quit IRC | 17:43 | |
*** mbandeir has quit IRC | 17:51 | |
*** READ10 is now known as READ10|away | 17:57 | |
*** factor has quit IRC | 17:58 | |
*** gfidente is now known as gfidente|afk | 18:02 | |
*** factor has joined #openstack-dev | 18:04 | |
*** mehakmittal has joined #openstack-dev | 18:04 | |
*** dmellado has quit IRC | 18:17 | |
*** mikefix has quit IRC | 18:19 | |
*** mehakmittal has quit IRC | 18:20 | |
*** dmellado has joined #openstack-dev | 18:24 | |
*** muskan has joined #openstack-dev | 18:25 | |
*** dmellado has quit IRC | 18:25 | |
*** dmellado has joined #openstack-dev | 18:33 | |
*** iurygregory has joined #openstack-dev | 18:34 | |
*** READ10|away is now known as READ10 | 18:45 | |
*** dpawlik has quit IRC | 18:47 | |
*** __ministry has quit IRC | 18:54 | |
*** ttsiouts has joined #openstack-dev | 18:59 | |
*** ttsiouts has quit IRC | 19:13 | |
*** ttsiouts has joined #openstack-dev | 19:13 | |
*** muskan has quit IRC | 19:14 | |
*** READ10 has quit IRC | 19:24 | |
*** mikecmpbll has quit IRC | 19:35 | |
*** mikecmpbll has joined #openstack-dev | 19:37 | |
*** mmethot has quit IRC | 19:40 | |
*** brokencycle has joined #openstack-dev | 19:40 | |
*** mmethot has joined #openstack-dev | 19:40 | |
*** Lucas_Gray has joined #openstack-dev | 19:41 | |
*** Lucas_Gray has quit IRC | 19:42 | |
*** ttsiouts has quit IRC | 19:44 | |
*** ttsiouts has joined #openstack-dev | 19:45 | |
*** roukoswarf has joined #openstack-dev | 19:49 | |
*** Lucas_Gray has joined #openstack-dev | 19:51 | |
roukoswarf | anyone know if i can somehow insert like... arbitrary code in oslo policy, or if ill need to edit in specific code changes? | 19:52 |
---|---|---|
roukoswarf | im trying to policy verify security groups against an external policy that checks more than just owner etc | 19:52 |
*** rloo has quit IRC | 19:55 | |
*** dklyle has quit IRC | 19:56 | |
bnemec | roukoswarf: We've had users who wrote policy checks against an external policy engine using HttpChecks. | 19:56 |
*** rloo has joined #openstack-dev | 19:56 | |
bnemec | It is also possible to write custom checks against things other than owner and what-not. | 19:56 |
roukoswarf | is that in oslo_policy, or in neutron? | 19:56 |
*** rloo has quit IRC | 19:57 | |
roukoswarf | cause, i know i can do whatever if i hard code it into neutron, but i was hoping for a pluggable method. | 19:57 |
*** rloo has joined #openstack-dev | 19:57 | |
roukoswarf | huh, didnt know about httpchecks in oslo. | 19:58 |
roukoswarf | this might be perfect, if it can send enough detail about the object. | 19:58 |
*** dklyle has joined #openstack-dev | 20:00 | |
*** rloo has quit IRC | 20:00 | |
*** rloo has joined #openstack-dev | 20:01 | |
bnemec | roukoswarf: If there isn't enough detail sent, you could open a bug to request it. We found a few places back when this first started to be used where services were not actually sending what they were supposed to send. | 20:07 |
bnemec | I think we fixed all of those, but since this doesn't really get tested upstream it's possible there were regressions. | 20:07 |
roukoswarf | well, im just working through what id need to do to get neutron to send the full rule being created when doing security group rule creates. | 20:08 |
roukoswarf | so i dont have to directly generate the payload? its just hardcoded into oslo? | 20:12 |
*** ttsiouts has quit IRC | 20:15 | |
bnemec | roukoswarf: I think the object being affected by the policy is usually passed to the policy. Unfortunately you may have to check code itself to see exactly what is passed. | 20:15 |
roukoswarf | wonder where that code would be in neutron. | 20:16 |
bnemec | roukoswarf: The target is what I was thinking of: https://opendev.org/openstack/neutron/src/branch/master/neutron/policy.py#L422 | 20:19 |
bnemec | For creation that might not be useful though if it's just passing a project_id. :-/ | 20:19 |
*** stewie925 has quit IRC | 20:20 | |
*** smarcet has joined #openstack-dev | 20:23 | |
*** smarcet has left #openstack-dev | 20:23 | |
roukoswarf | well i guess ill just change the policy and see what it does. | 20:23 |
roukoswarf | see what i get | 20:23 |
bnemec | Yeah, that might be easiest. | 20:24 |
bnemec | I glanced through the neutron code, but there are several different places policy checks are done, depending on what api call is being made. | 20:24 |
roukoswarf | yeah, i just want create_security_group_rule | 20:25 |
*** nweinber has quit IRC | 20:26 | |
*** ccamacho has quit IRC | 20:38 | |
roukoswarf | bnemec: its not in the docs, does oslo support and? or just or? | 20:55 |
roukoswarf | nvm, its just not explicitly mentioned very well, i did find an example. | 20:56 |
bnemec | Yeah, the docs are example-based so the specifics of what exists is kind of buried. | 20:58 |
*** igordc has joined #openstack-dev | 21:07 | |
roukoswarf | can the policy take port numbers? i got nothing hitting my webserver and the rule was accepted without asking... | 21:12 |
*** rcernin has joined #openstack-dev | 21:14 | |
*** rloo has quit IRC | 21:29 | |
*** gfidente|afk has quit IRC | 21:41 | |
*** ttsiouts has joined #openstack-dev | 21:42 | |
*** rloo has joined #openstack-dev | 21:44 | |
*** rloo has quit IRC | 21:45 | |
*** rloo has joined #openstack-dev | 21:45 | |
*** slaweq has quit IRC | 21:49 | |
*** ttsiouts has quit IRC | 21:51 | |
*** slaweq has joined #openstack-dev | 21:52 | |
bnemec | roukoswarf: I believe should be able to specify a port. The URL basically gets passed to requests, which does recognize ports in URLs. | 21:52 |
roukoswarf | yeah, for some reason nothing ever hits my api, after adding "create_security_group_rule": "http://10.0.74.95/policy/verifyrule" to my policy | 21:55 |
roukoswarf | is there some step im missing/misunderstanding? | 21:55 |
*** raildo has quit IRC | 21:56 | |
roukoswarf | it just... accepts the change, even without hitting the api. | 21:57 |
bnemec | Yeah, that's concerning. Even if it's failing to reach the server it should have failed closed. | 21:59 |
roukoswarf | so it looks like neutron is cheeky and for some reason totally bypasses policy if youre an admin. | 21:59 |
roukoswarf | which uh... sounds wrong to me. | 21:59 |
bnemec | Ohhh, I remember discussing this in regard to the role and scope policy changes. | 22:00 |
bnemec | Some projects still have hard-coded policy checks like that. | 22:00 |
roukoswarf | its not a dealbreaker for me... just not very nice to bypass policy processing like that. | 22:01 |
roukoswarf | i guess at least i can check what i get sent finally. | 22:01 |
bnemec | Yeah, you would need to talk to the neutron team about that. | 22:02 |
bnemec | I know it's a concern in general for the new policy work because we don't want admin to be a special one-off thing. That makes it impossible to delegate admin permissions to other users who may need a subset of admin functionality. | 22:02 |
*** slaweq has quit IRC | 22:03 | |
*** dancn has quit IRC | 22:06 | |
roukoswarf | bnemec: the good news is the rule create http verification does in fact send literally everything about the request to the httpcheck, so this will work excellently, thanks a bunch for the pointer. | 22:08 |
bnemec | roukoswarf: Glad I could help! | 22:09 |
*** dancn has joined #openstack-dev | 22:10 | |
*** dancn has quit IRC | 22:15 | |
*** Lucas_Gray has quit IRC | 22:21 | |
*** tkajinam has joined #openstack-dev | 22:49 | |
*** tkajinam has quit IRC | 22:49 | |
*** tkajinam has joined #openstack-dev | 22:50 | |
*** rloo has quit IRC | 22:51 | |
*** roukoswarf has quit IRC | 22:54 | |
*** lbragstad has quit IRC | 22:56 | |
*** tosky has quit IRC | 23:02 | |
*** igordc has quit IRC | 23:14 | |
*** avolkov has quit IRC | 23:22 | |
*** bbowen has quit IRC | 23:32 | |
*** bbowen has joined #openstack-dev | 23:32 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!