Monday, 2019-05-13

*** altlogbot_3 has quit IRC00:50
*** altlogbot_0 has joined #openstack-dns00:53
*** altlogbot_0 has quit IRC00:54
*** altlogbot_1 has joined #openstack-dns00:55
*** awalende has joined #openstack-dns01:23
*** awalende has quit IRC01:28
*** ircuser-1 has quit IRC01:32
*** v12aml has quit IRC02:10
*** ivve has quit IRC05:07
*** pcaruana has joined #openstack-dns06:16
*** ivve has joined #openstack-dns06:17
*** awalende has joined #openstack-dns06:58
*** awalende has quit IRC07:01
*** ginopc has joined #openstack-dns07:06
*** awalende has joined #openstack-dns07:40
mugsiehjohnson1: not sure if you will see this, but you need to look at your pools.yaml and run the pool update command08:20
mugsiestep 9+10 here : https://docs.openstack.org/designate/latest/install/install-rdo.html08:21
*** pcaruana|afk| has joined #openstack-dns12:55
*** pcaruana has quit IRC12:57
*** ginopc has quit IRC13:31
*** ginopc has joined #openstack-dns13:32
*** ginopc has quit IRC13:37
*** awalende has quit IRC13:40
*** awalende has joined #openstack-dns13:41
*** awalende has quit IRC13:42
*** awalende has joined #openstack-dns13:43
*** awalende has quit IRC13:43
*** awalende has joined #openstack-dns13:44
*** awalende has quit IRC13:48
*** ginopc has joined #openstack-dns13:53
*** ginopc has quit IRC13:55
*** ginopc has joined #openstack-dns13:56
*** ginopc has quit IRC13:57
*** ginopc has joined #openstack-dns13:58
*** ginopc has quit IRC14:01
*** ginopc has joined #openstack-dns14:03
*** gmann has joined #openstack-dns14:06
*** gmann is now known as gmann_pto14:07
*** pcaruana|afk| has quit IRC14:55
*** beekneemech is now known as bnemec15:00
*** ircuser-1 has joined #openstack-dns15:15
*** ginopc has quit IRC15:42
*** pcaruana|afk| has joined #openstack-dns15:44
*** awalende has joined #openstack-dns16:14
*** awalende has quit IRC16:19
*** ivve has quit IRC16:48
*** ivve has joined #openstack-dns18:19
*** tuxjohnson has joined #openstack-dns19:08
tuxjohnsonWeird question maybe... I have just installed Rocky on CentOS with designate.  Everything is working fine with the BIND9 server we also installed.  The question is, has anyone restricted creating zones, recordsets, etc to everyone but cloud_admins using a policy.yaml in the /etc/designate directory.  We do not want end users to be able to alter the DNS.19:13
*** gmann_pto has quit IRC19:33
*** tuxjohnson has left #openstack-dns20:14
*** goldyfruit has joined #openstack-dns20:34
*** pcaruana|afk| has quit IRC20:46
eanderssontuxjohnson I think that is pretty common20:52
ivvehe left :(20:53
ivvei was just about to answer20:53
eanderssonHe might read the irc logs20:53
eandersson:p20:53
ivvewell in that case, change all admin_or_owner to only admin in policy.json :)20:59
ivveor just put role:cloud_admins if that's your role21:02
ivveanyways, im here for another question. i was wondering if its possible to allow other tenants to create subzones of an already existing zone in the same cloud21:03
*** goldyfruit has quit IRC21:07
*** openstackgerrit has quit IRC21:09
eanderssonI don't think that is possible at the moment21:10
eanderssonWould / could probably be part of this? https://etherpad.openstack.org/p/BER-Designate-Shared-Zones21:10
eanderssonmugsie, should probably know more21:10
ivveeandersson: its possible for the admin to create the subzone and transfer it to the tenant who "needs" it21:14
ivveor rather, the owner of the zone21:15
ivvefor the subzone.. :)21:15
ivveliek if i own example.com i can create another.example.com and transfer it to you21:15
eanderssonhttps://github.com/openstack/designate/blob/master/designate/central/service.py#L87721:15
ivveso that leaves me to wonder if it would be possible to allow anyone to create it..21:16
eanderssonRight now it looks like we enforce project21:16
ivveah21:16
eandersson> if subzone.tenant_id != zone.tenant_id:21:16
ivveyea it looks like its a dead end right there21:16
ivvebut you can do what i described21:17
eanderssonYea - that is a valid work around for now21:17
eanderssonSounds like a reaonsable usecase21:17
ivvewell what is describe there is very reasonable21:20
ivvecan't even create the subzone for the tenant as admin... i mean that should also be possible. like creating tenant+users+groups+zones and maybe some other smaller things with a heat template as admin would be nice21:24
eanderssonYep21:38

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!