Tuesday, 2021-08-10

*** rpittau|afk is now known as rpittau06:15
*** mtreinish_ is now known as mtreinish06:40
*** jpena|off is now known as jpena07:37
*** jpena is now known as jpena|lunch11:25
*** dviroel|out is now known as dviroel11:26
*** xek_ is now known as xek11:52
*** jpena|lunch is now known as jpena12:27
*** geguileo is now known as Guest381212:30
*** geguileor is now known as geguileo12:48
*** lbragstad__ is now known as lbragstad13:35
*** slaweq_ is now known as slaweq14:01
*** whoami-rajat__ is now known as whoami-rajat14:06
lbragstadgmann do you know if the default permissions for devstack accounts changed recently?14:25
lbragstadi'm noticing something strange with the keystone protection job 14:26
gmannlbragstad: few of the operation are made as admin i think. and one change in Tempest is about no network creation for system scope token14:27
lbragstadok - interesting 14:28
lbragstadhttps://bugs.launchpad.net/keystone/+bug/193935014:28
gmannlbragstad: ah I think I am also seeing failure about project creation - https://review.opendev.org/c/openstack/keystone/+/79942314:28
lbragstadwith that - i noticed that one of the failures was because devstack couldn't create admin resources (like role assignments) 14:29
gmannlbragstad: yeah same issue, there was change in network creation for ovn14:29
lbragstadhttps://github.com/openstack/devstack/blob/a5ed116814fa3a435f15231aa7b18d389f917844/lib/glance#L312 fails when KEYSTONE_ENFORCE_SCOPE == True because that request isn't made with a system-scoped token 14:29
gmannlet me find patch14:30
gmannlbragstad: this caused the net id fetch (network creation on ovn) and then it is reverted https://review.opendev.org/c/openstack/neutron/+/80147814:34
gmannlbragstad: and I think it is same time I think keystone protection job started failing for project_id demo 14:36
lbragstadok so the original patch broke tempest becuase the project wasn't created? 14:36
lbragstadand it just cascades from there? 14:36
gmannlbragstad: network creation in tempest for system scope is stopped in https://review.opendev.org/c/openstack/tempest/+/79813014:38
gmannI am not sure it caused any issue?14:39
gmannlbragstad: for neutron change, default network was not created for ovn14:39
lbragstadhmm - ok 14:40
lbragstadin my local environment if i enable KEYSTONE_ENFORCE_SCOPE and the keystone devstack plugin, i see a lot of 403s as devstack goes through and sets things up 14:40
lbragstadand i'm not sure why it's a problem now since it was passing earlier 14:41
lbragstadand so i thought it was the glance change to enable quotas, but it appears to be wider than that14:41
gmannlbragstad: ah, is this making any difference, it is effort to move the setting from keystone devstack plugin to devstack https://review.opendev.org/c/openstack/devstack/+/778975/114:44
gmannbasically these setting https://review.opendev.org/c/openstack/keystone/+/77897914:45
lbragstadmmm 14:46
lbragstadhttps://github.com/openstack/keystone/blob/master/devstack/plugin.sh#L51-L5514:46
lbragstadwhen we did that in keystone's devstack plugin we did it in test-config14:46
lbragstadso, after everything was setup, i believe14:46
lbragstadthis is happening during keystone configuration 14:47
lbragstadhttps://review.opendev.org/c/openstack/devstack/+/778975/1/lib/keystone14:47
lbragstadwhich is before anything in devstack is created14:47
gmannhummmm14:47
lbragstadwhich might explain why *everything* is failing with a 40314:47
gmannwe need to move devstack creation to system first in this case14:47
lbragstadyeah - devstack needs to know what profile to use in either case14:48
lbragstadhttps://github.com/openstack/keystone/blob/master/devstack/plugin.sh#L52-L5314:48
lbragstadi think that's the primary reason why we did that in test-config14:48
gmannlbragstad: yeah, you are right. let me revert that for now and then we can do it once we move whole devstack to system scope setting. 14:48
lbragstadi'll test your revert locally when you get the proposed14:48
*** ralonsoh_ is now known as ralonsoh15:22
*** owalsh_ is now known as owalsh15:31
*** jpena is now known as jpena|off15:37
*** rpittau is now known as rpittau|afk16:31
*** dviroel is now known as dviroel|brb18:41
*** dviroel|brb is now known as dviroel19:00
*** lbragstad_ is now known as lbragstad19:45
*** dviroel is now known as dviroel|out20:52

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!