*** stevemar has joined #openstack-keystone | 00:00 | |
*** ChanServ sets mode: +v stevemar | 00:00 | |
*** dims has joined #openstack-keystone | 00:40 | |
*** marg7175 has quit IRC | 00:53 | |
*** avozza is now known as zz_avozza | 00:59 | |
*** zz_avozza is now known as avozza | 00:59 | |
*** chrisshattuck has joined #openstack-keystone | 01:14 | |
*** dims has quit IRC | 01:25 | |
*** chrisshattuck has quit IRC | 01:26 | |
*** dims has joined #openstack-keystone | 01:26 | |
*** dims_ has joined #openstack-keystone | 01:27 | |
*** dims has quit IRC | 01:31 | |
*** dims_ has quit IRC | 01:34 | |
*** erkules_ has joined #openstack-keystone | 02:25 | |
*** erkules has quit IRC | 02:27 | |
*** marg7175 has joined #openstack-keystone | 02:36 | |
*** topol has joined #openstack-keystone | 03:08 | |
*** ChanServ sets mode: +v topol | 03:08 | |
*** chrisshattuck has joined #openstack-keystone | 03:26 | |
*** samueldmq has quit IRC | 03:37 | |
openstackgerrit | ChangBo Guo(gcb) proposed openstack/keystone: Add library oslo.concurrency in config-generator config file https://review.openstack.org/137270 | 03:53 |
---|---|---|
*** mitz has quit IRC | 04:10 | |
*** mitz has joined #openstack-keystone | 04:11 | |
*** avozza is now known as zz_avozza | 04:23 | |
*** zz_avozza is now known as avozza | 04:25 | |
*** avozza is now known as zz_avozza | 04:34 | |
*** chrisshattuck has quit IRC | 04:56 | |
*** chrisshattuck has joined #openstack-keystone | 05:05 | |
*** marg7175 has quit IRC | 05:09 | |
*** richm has quit IRC | 05:38 | |
*** dims has joined #openstack-keystone | 05:52 | |
*** zz_avozza is now known as avozza | 06:01 | |
*** jaosorior has joined #openstack-keystone | 06:03 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Imported Translations from Transifex https://review.openstack.org/149158 | 06:04 |
*** MasterPiece has joined #openstack-keystone | 06:05 | |
*** chrisshattuck has quit IRC | 06:11 | |
*** stevemar has quit IRC | 06:12 | |
*** MasterPiece has quit IRC | 06:14 | |
*** topol has quit IRC | 06:16 | |
*** afazekas has quit IRC | 06:18 | |
*** dims has quit IRC | 06:19 | |
*** dims has joined #openstack-keystone | 06:19 | |
*** dims has quit IRC | 06:20 | |
*** avozza is now known as zz_avozza | 06:26 | |
*** rwsu has joined #openstack-keystone | 06:54 | |
*** rwsu is now known as rwsu-afk | 06:54 | |
*** afazekas has joined #openstack-keystone | 07:01 | |
*** MasterPiece has joined #openstack-keystone | 07:02 | |
*** marg7175 has joined #openstack-keystone | 07:10 | |
*** marg7175 has quit IRC | 07:14 | |
*** dims has joined #openstack-keystone | 07:20 | |
*** dims has quit IRC | 07:25 | |
*** mzbik has joined #openstack-keystone | 07:33 | |
*** marg7175 has joined #openstack-keystone | 08:17 | |
*** marg7175 has quit IRC | 08:19 | |
*** marg7175 has joined #openstack-keystone | 08:19 | |
*** erkules_ is now known as erkules | 08:22 | |
*** marg7175 has quit IRC | 08:24 | |
*** marg7175_ has joined #openstack-keystone | 08:24 | |
*** marg7175_ has quit IRC | 08:29 | |
*** pnavarro has joined #openstack-keystone | 08:29 | |
*** f13o has joined #openstack-keystone | 08:37 | |
*** marg7175 has joined #openstack-keystone | 08:39 | |
openstackgerrit | Marek Denis proposed openstack/keystone-specs: Allow for direct mapping in federated authN. https://review.openstack.org/149071 | 08:44 |
*** dims has joined #openstack-keystone | 08:48 | |
*** dims has quit IRC | 08:53 | |
*** bdossant has joined #openstack-keystone | 08:57 | |
openstackgerrit | Marek Denis proposed openstack/keystone-specs: Visual Page for WebSSO https://review.openstack.org/133529 | 09:15 |
*** oomichi_ has quit IRC | 09:17 | |
*** jistr has joined #openstack-keystone | 09:22 | |
*** Guest66252 is now known as d0ugal | 09:22 | |
*** d0ugal has quit IRC | 09:23 | |
*** d0ugal has joined #openstack-keystone | 09:23 | |
*** zz_avozza is now known as avozza | 09:28 | |
openstackgerrit | ChangBo Guo(gcb) proposed openstack/keystone: Add library oslo.concurrency in config-generator config file https://review.openstack.org/137270 | 09:35 |
openstackgerrit | Dave Chen proposed openstack/keystone: Remove unnecessary code block of exception handling https://review.openstack.org/149956 | 09:44 |
*** samueldmq has joined #openstack-keystone | 09:52 | |
*** nellysmitt has joined #openstack-keystone | 09:53 | |
*** marg7175 has quit IRC | 10:08 | |
*** marg7175 has joined #openstack-keystone | 10:09 | |
openstackgerrit | Marek Denis proposed openstack/python-keystoneclient: Create a framework for federation plugins https://review.openstack.org/130564 | 10:09 |
*** rushiagr_away is now known as rushiagr | 10:10 | |
*** bdossant has quit IRC | 10:19 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/149967 | 10:27 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystonemiddleware: Updated from global requirements https://review.openstack.org/149968 | 10:27 |
*** samueldmq has quit IRC | 10:29 | |
*** aix has joined #openstack-keystone | 10:30 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-keystoneclient-kerberos: Updated from global requirements https://review.openstack.org/149979 | 10:34 |
*** dims has joined #openstack-keystone | 10:34 | |
*** dims has quit IRC | 10:39 | |
*** andreaf_ has joined #openstack-keystone | 10:43 | |
*** avozza is now known as zz_avozza | 10:55 | |
*** zz_avozza is now known as avozza | 10:56 | |
*** htruta has joined #openstack-keystone | 11:01 | |
*** tellesnobrega has joined #openstack-keystone | 11:02 | |
*** bdossant has joined #openstack-keystone | 11:04 | |
*** bdossant has quit IRC | 11:07 | |
*** andreaf_ has quit IRC | 11:17 | |
openstackgerrit | Yuriy Taraday proposed openstack/keystone: Add a module to work with LDAP filters and DNs https://review.openstack.org/117484 | 11:18 |
*** nellysmitt has quit IRC | 11:19 | |
*** samueldmq has joined #openstack-keystone | 11:19 | |
*** gabriel-bezerra has joined #openstack-keystone | 11:24 | |
*** MasterPiece has quit IRC | 11:34 | |
*** andreaf_ has joined #openstack-keystone | 11:34 | |
openstackgerrit | Marek Denis proposed openstack/keystone-specs: Visual Page for WebSSO https://review.openstack.org/133529 | 11:35 |
*** dims has joined #openstack-keystone | 11:35 | |
*** nellysmitt has joined #openstack-keystone | 11:38 | |
*** dims has quit IRC | 11:40 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Improve List Role Assignments Filters Performance https://review.openstack.org/137202 | 11:42 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Improve List Role Assignment Tests https://review.openstack.org/137021 | 11:42 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Check for invalid filtering on v3/role_assignments https://review.openstack.org/144703 | 11:42 |
*** tellesnobrega_ has joined #openstack-keystone | 11:54 | |
*** raildo has joined #openstack-keystone | 12:07 | |
rodrigods | ayoung, ping... any agreements regarding the policy enforcement mechanism in the midcycle? (aka https://review.openstack.org/#/c/133480/) | 12:07 |
*** samueldmq is now known as samueldmq-away | 12:25 | |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone-specs: Dynamic Policy Overview https://review.openstack.org/147651 | 12:25 |
*** tellesnobrega_ has quit IRC | 12:43 | |
*** redrobot has quit IRC | 12:51 | |
*** redrobot has joined #openstack-keystone | 12:53 | |
*** redrobot is now known as Guest36473 | 12:53 | |
*** samueldmq has joined #openstack-keystone | 12:55 | |
openstackgerrit | Dave Chen proposed openstack/keystone: Remove duplicated check https://review.openstack.org/150022 | 12:57 |
*** richm has joined #openstack-keystone | 13:13 | |
*** amakarov_away is now known as amakarov | 13:15 | |
*** dims has joined #openstack-keystone | 13:23 | |
*** dims has quit IRC | 13:28 | |
openstackgerrit | Merged openstack/python-keystoneclient-kerberos: Updated from global requirements https://review.openstack.org/149979 | 13:29 |
*** tellesnobrega_ has joined #openstack-keystone | 13:34 | |
*** avozza is now known as zz_avozza | 13:35 | |
*** zz_avozza is now known as avozza | 13:35 | |
*** avozza is now known as zz_avozza | 13:47 | |
*** zz_avozza is now known as avozza | 13:47 | |
*** samueldmq has quit IRC | 13:48 | |
*** gordc has joined #openstack-keystone | 13:50 | |
*** samueldmq has joined #openstack-keystone | 13:57 | |
*** joesavak has joined #openstack-keystone | 14:00 | |
openstackgerrit | Marek Denis proposed openstack/keystone: Implement Service Providers API for OS-FEDERATION https://review.openstack.org/104623 | 14:04 |
openstackgerrit | Merged openstack/keystonemiddleware: Updated from global requirements https://review.openstack.org/149968 | 14:07 |
*** sriram has joined #openstack-keystone | 14:10 | |
*** tellesnobrega_ has quit IRC | 14:11 | |
*** tellesnobrega_ has joined #openstack-keystone | 14:14 | |
*** jraim has quit IRC | 14:15 | |
*** jraim has joined #openstack-keystone | 14:15 | |
*** mzbik_ has joined #openstack-keystone | 14:17 | |
*** tellesnobrega_ has quit IRC | 14:21 | |
*** mzbik has quit IRC | 14:21 | |
*** tellesnobrega_ has joined #openstack-keystone | 14:21 | |
*** mzbik_ has quit IRC | 14:22 | |
*** stevemar has joined #openstack-keystone | 14:24 | |
*** ChanServ sets mode: +v stevemar | 14:24 | |
openstackgerrit | Merged openstack/keystone: Updated from global requirements https://review.openstack.org/149967 | 14:25 |
openstackgerrit | Marek Denis proposed openstack/keystone: Implement Service Providers API for OS-FEDERATION https://review.openstack.org/104623 | 14:28 |
marekd | rodrigods: it's a big rebase so I might have missed something : https://review.openstack.org/#/c/104623/ | 14:29 |
*** vhoward has joined #openstack-keystone | 14:30 | |
rodrigods | marekd, nice, will take a look | 14:33 |
stevemar | marekd, i'll take a look too :) | 14:34 |
*** mattfarina has joined #openstack-keystone | 14:36 | |
*** svasheka has joined #openstack-keystone | 14:37 | |
marekd | stevemar: please do, thanks | 14:37 |
*** dims has joined #openstack-keystone | 14:39 | |
*** dims_ has joined #openstack-keystone | 14:40 | |
*** dims has quit IRC | 14:40 | |
marekd | stevemar: ayoung: for the websso spec (https://review.openstack.org/#/c/133529/) i need your opinions whether we add an API for list of trusted horizons or we store a list of such URLs in keystone.conf | 14:40 |
*** bknudson has joined #openstack-keystone | 14:40 | |
*** ChanServ sets mode: +v bknudson | 14:40 | |
marekd | i think it was not eventually decided. | 14:41 |
marekd | rodrigods: hah, i even rememvered i need to change attributes list | 14:50 |
marekd | remembered. | 14:50 |
marekd | and later got distracted. | 14:51 |
*** abhirc has quit IRC | 14:53 | |
stevemar | marekd, not sure we came to a decision | 14:59 |
*** radez_g0n3 is now known as radez | 15:00 | |
marekd | stevemar: no, we didn't | 15:02 |
marekd | :( | 15:02 |
marekd | i expect some big deployers cannot afford restarting keystone for such a reason. | 15:03 |
marekd | what's your experience? | 15:03 |
*** tellesnobrega_ has quit IRC | 15:03 | |
stevemar | marekd, neither are really good for UX | 15:03 |
*** vsilva has quit IRC | 15:06 | |
marekd | stevemar: ok, but it's a must. I think we cannot do it other way round. | 15:07 |
marekd | we cannot redirect to any url. | 15:08 |
marekd | :/ | 15:08 |
*** vsilva has joined #openstack-keystone | 15:09 | |
*** topol has joined #openstack-keystone | 15:09 | |
*** ChanServ sets mode: +v topol | 15:09 | |
*** tellesnobrega_ has joined #openstack-keystone | 15:09 | |
*** vsilva has quit IRC | 15:10 | |
*** Ctina has joined #openstack-keystone | 15:16 | |
*** tellesnobrega_ has quit IRC | 15:20 | |
*** samueldmq has quit IRC | 15:21 | |
marekd | topol: please, find responses to your comments at https://review.openstack.org/#/c/133529/ . | 15:24 |
openstackgerrit | Boris Bobrov proposed openstack/keystone: alembic initial support https://review.openstack.org/150057 | 15:26 |
topol | Hi marekd, I will take a look. THANKS | 15:31 |
*** EmilienM is now known as EmilienM|mtg | 15:33 | |
marekd | topol: thanks. | 15:33 |
*** henrynash has joined #openstack-keystone | 15:36 | |
*** ChanServ sets mode: +v henrynash | 15:36 | |
*** carlosmarin has joined #openstack-keystone | 15:39 | |
*** Ctina has quit IRC | 15:40 | |
*** Ctina has joined #openstack-keystone | 15:41 | |
*** avozza is now known as zz_avozza | 15:47 | |
*** abhirc has joined #openstack-keystone | 15:52 | |
openstackgerrit | Rodrigo Duarte proposed openstack/python-keystoneclient: Hierarchical multitenancy basic calls https://review.openstack.org/115770 | 15:59 |
openstackgerrit | Rodrigo Duarte proposed openstack/python-keystoneclient: Implements subtree_as_ids and parents_as_ids https://review.openstack.org/150078 | 15:59 |
*** aslaen has joined #openstack-keystone | 15:59 | |
openstackgerrit | Boris Bobrov proposed openstack/keystone: Fix dict comprehension in federation utils https://review.openstack.org/150079 | 15:59 |
*** dims_ has quit IRC | 15:59 | |
breton | marekd: hey | 16:00 |
*** aix has quit IRC | 16:02 | |
breton | marekd: I'd appreciate if you had a look at https://review.openstack.org/#/c/150079/ . We either need this fix, or some tests in https://review.openstack.org/#/c/139013/17 are lacking | 16:03 |
*** nkinder has joined #openstack-keystone | 16:03 | |
*** topol_ has joined #openstack-keystone | 16:04 | |
*** ChanServ sets mode: +v topol_ | 16:04 | |
raildo | henrynash, ping, do you think about the clash name problem? any other idea? | 16:04 |
*** vishy has quit IRC | 16:05 | |
henrynash | raildo: so, I guess the project naming is all we can really do…obviously there is onlu a name clash between a project and it’s owning Domain…not with someone else’s domain? | 16:06 |
henrynash | raildo: I assume? | 16:06 |
*** Guest36473 is now known as redrobot | 16:06 | |
*** topol has quit IRC | 16:06 | |
*** topol_ is now known as topol | 16:06 | |
rodrigods | henrynash, ping 2: rebased this https://review.openstack.org/#/c/148567/ depending on a patch of yours (https://review.openstack.org/#/c/148567/), but we have a change in Nova that required this to be merged ASAP, should I rebase against another change? | 16:06 |
rodrigods | requires* | 16:07 |
raildo | henrynash, yes, i think that the problem is just with between a project and your domain. | 16:07 |
*** chrisshattuck has joined #openstack-keystone | 16:07 | |
*** vishy has joined #openstack-keystone | 16:07 | |
raildo | s/just with between/ just between | 16:07 |
*** tellesnobrega_ has joined #openstack-keystone | 16:09 | |
henrynash | rodigods: so how urgent is? | 16:10 |
henrynash | rodigods; it? | 16:10 |
rodrigods | henrynash, this change here: https://review.openstack.org/#/c/149828/ needs it | 16:10 |
rodrigods | (the useful part of HMT outside keystone boundaries) | 16:11 |
henrynash | rodigods: so how about a compromise: if you rebase on: https://review.openstack.org/#/c/144824/ then this means all our core/backends are fine, then I’ll handle teh re-merge with the controller chanegs… | 16:13 |
henrynash | rodigods: and https://review.openstack.org/#/c/144824/ isn’t dependant on anything…so will try and get that in asap | 16:13 |
rodrigods | henrynash, ok, I appreciate that, will rebase against that patch | 16:14 |
henrynash | ayoung, stevemar, lbragstad: any chance of some eyes on https://review.openstack.org/#/c/144824/ - good to get that in somce that our core/backends are now upto date with teh assignment split. Since domain/projects were logically split in the previous patches…this one is just mechanical movement into theire new location | 16:15 |
ayoung | ++ | 16:16 |
*** markvoelker has joined #openstack-keystone | 16:17 | |
ayoung | henrynash, Looking at it now. I wonder if, for a huge refactoring like this, we should do something like: copy the file verbatim to locations X, then hack out everything that should not be in the new version. | 16:17 |
ayoung | Note that I AM NOT SUGGESTING THIS NOW! | 16:17 |
openstackgerrit | Marek Denis proposed openstack/keystone-specs: Visual Page for WebSSO https://review.openstack.org/133529 | 16:18 |
henrynash | ayoung: would that improve the diff output? or somehow let it more easily be reviewed? If so, I’d be all for it….cause it’s a real pain to check whether the patch as mucked up the mthods being moved... | 16:18 |
ayoung | henrynash, so one review which states: duplicates the file assignment.core as resource.core means that I can do diff assignment/core.py resourec.core.py | 16:19 |
ayoung | won't show up in the code review view, but we could do it locally. | 16:20 |
ayoung | then the second commit creates the real changes to the files.... | 16:20 |
marekd | breton: let me look. | 16:20 |
henrynash | ayoung: oh, I get it…then get rid of what you don’t want….hmm, yeah, next time around that seems like a better plan! | 16:20 |
ayoung | removing assingment stuff from core and the opposite. | 16:20 |
ayoung | yeah...next time. If there is a next time. | 16:20 |
ayoung | and there is always a next time | 16:21 |
henrynash | ayoung: just want to make sure nobody get’s confused a gets in an updates the ones that are about to be nixed in between, but we could prevent that | 16:21 |
ayoung | yeah... | 16:21 |
henrynash | ayoung: well, we could be on the lookout for that | 16:21 |
ayoung | ++ | 16:21 |
henrynash | ayoung: and yes, there’s always a next time! | 16:21 |
ayoung | anyway, this one is going to be impossible to confirm as is. I wonder if I should do something like this: | 16:22 |
ayoung | git checkout HEAD~1 assignment/core.py | 16:22 |
ayoung | diff assignment/core.py resource/core.py ? | 16:22 |
henrynash | I think that’s was dstanek said he usual does | 16:23 |
marekd | breton: why do you think tests are lacking? | 16:26 |
marekd | breton: the reason why i wrote this line for group in {g['name']: g for g in groups}.values(): was that i just wanted to get rid of groups mentioned multile times. | 16:28 |
*** ctracey has quit IRC | 16:29 | |
*** ctracey has joined #openstack-keystone | 16:29 | |
ayoung | henrynash, that seems to be a good solution for this one | 16:29 |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone: Implements parents_as_ids query param https://review.openstack.org/148567 | 16:31 |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone: Implements subtree_as_ids query param https://review.openstack.org/148618 | 16:31 |
breton | marekd: it's normal that group names might appear more than once? | 16:32 |
marekd | breton: this is input for mapping rules | 16:32 |
marekd | so I'd say: yes | 16:32 |
*** david-ly_ is now known as david-lyle | 16:33 | |
marekd | if you specify two different rules, and in both of them you map to group named 'X' and luckily you qualify for both of the rules (because you work in IT dep but also work as a manager) that you may be have group mapped twice. | 16:33 |
marekd | and there i am simply removing duplicates. | 16:33 |
breton | understood. So, https://bugs.launchpad.net/keystone/+bug/1413538 can be closed as invalid I guess | 16:33 |
marekd | for group in groupes will not work. | 16:34 |
marekd | breton: as long as you claim something is not properly tested. | 16:34 |
marekd | you can add a test | 16:34 |
marekd | however i am not sure this deserves a bug. | 16:34 |
marekd | (well, it does if you provide a test that fails Keystone :-) | 16:34 |
marekd | breton: makes sense? | 16:34 |
breton | > for group in groupes will not work | 16:37 |
breton | it works for me now though | 16:37 |
*** rwsu-afk is now known as rwsu | 16:38 | |
*** zz_avozza is now known as avozza | 16:42 | |
dstanek | henrynash: ? | 16:42 |
henrynash | dstanek: ? | 16:47 |
dstanek | henrynash: you mentioned me earlier, but I didn't see the context | 16:47 |
henrynash | dstanek: oh. no issue….ayoung and I were discussing techniques for checking pacthes that invlove mots of code moveing aournd…and someone( I think it was you) was describing how you used diff locally….so no action requried :-) | 16:48 |
*** abhirc has quit IRC | 16:48 | |
dstanek | henrynash: ah, ok. 'no action require' is like music to my ears | 16:49 |
henrynash | dstanek: :-) | 16:49 |
bknudson | stanek and nash : no action required | 16:49 |
henrynash | bknudson: stanekandnash: no action likely! | 16:49 |
*** gokrokve has joined #openstack-keystone | 16:51 | |
*** kfox1111 has joined #openstack-keystone | 17:03 | |
*** _cjones_ has joined #openstack-keystone | 17:05 | |
*** EmilienM|mtg is now known as EmilienM|afk | 17:05 | |
*** jdennis1 has quit IRC | 17:06 | |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone: Implements parents_as_ids query param https://review.openstack.org/148567 | 17:07 |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone: Implements subtree_as_ids query param https://review.openstack.org/148618 | 17:07 |
rodrigods | henrynash, rebased ^ :) | 17:07 |
henrynash | rodigods: ok, take a look... | 17:07 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Improve List Role Assignments Filters Performance https://review.openstack.org/137202 | 17:07 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Improve List Role Assignment Tests https://review.openstack.org/137021 | 17:07 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Check for invalid filtering on v3/role_assignments https://review.openstack.org/144703 | 17:07 |
samueldmq-away | henrynash, ping - ^ | 17:08 |
rodrigods | henrynash, thanks! | 17:08 |
*** dims has joined #openstack-keystone | 17:08 | |
samueldmq-away | henrynash, I've updating i) the checking for invalid filters ii) tests for invalid filters iii) list role assignments refactoring to allow filtering by domain or inherited in effective mode | 17:09 |
*** samueldmq-away is now known as samueldmq | 17:09 | |
* samueldmq was still away as samueldmq-away :) | 17:10 | |
*** jdennis has joined #openstack-keystone | 17:11 | |
*** lhcheng has joined #openstack-keystone | 17:13 | |
rodrigods | bknudson, ping... thanks for your reviews in https://review.openstack.org/#/c/115770/, added the tests you requested | 17:13 |
*** andreaf_ has quit IRC | 17:15 | |
*** andreaf_ has joined #openstack-keystone | 17:16 | |
ayoung | dstanek, henrynash was pushing the review for https://review.openstack.org/#/c/144824/16 to merge. I would appreicate getting it in; reviewing it for diffs is painful, but it is basically just code moves and adjustments for the new locations; lets get it in so we don't have to review it again, please. | 17:20 |
*** ayoung is now known as adminyoung | 17:20 | |
adminyoung | and now I have to get some admin tasks done. | 17:20 |
raildo | adminyoung, ping, maybe we can put some topic in the keystone meeting to discuss that problem about idp, domain, project domain-ness... | 17:28 |
adminyoung | raildo, yes, good idea | 17:29 |
adminyoung | raildo, I'm wondering how important it really is to treat domains and projects the same, or if we just help out Horizon to deal with them, and continue to treat them as different things in Keystone | 17:30 |
rodrigods | adminyoung, and fyi: managed to have a task here so I can take a look in the dynamic policies part so... whenever you have time, lets chat about it (already ping ed you 3 times :P ) | 17:30 |
adminyoung | I mean, what we should have done 2 years ago and what we can do today are two different things | 17:30 |
*** serverascode has quit IRC | 17:35 | |
*** serverascode has joined #openstack-keystone | 17:36 | |
samueldmq | stevemar, ping - just would like to talk about https://review.openstack.org/#/c/137270 | 17:38 |
samueldmq | stevemar, is that just to expose that we dont use oslo.concurrency config options ? why is that so important that we need to do that ... | 17:38 |
morganfainberg | this is a beast of a patch: https://review.openstack.org/#/c/144824/ | 17:39 |
*** thedodd has joined #openstack-keystone | 17:39 | |
morganfainberg | even just moving things around... it is a beast | 17:39 |
*** tqtran has joined #openstack-keystone | 17:40 | |
morganfainberg | bknudson, topol, i'm seeing some consistent errors on db2 CI | 17:40 |
bknudson | morganfainberg: do you have an example? | 17:40 |
morganfainberg | bknudson, http://dal05.objectstorage.softlayer.net/v1/AUTH_58396f85-2c60-47b9-aaf8-e03bc24a1a6f/cilog/24/144824/16/check/ibm-db2-ci-keystone/2c2edc9/logs/devstack-gate-setup-workspace-new.txt | 17:41 |
topol | uggh, hopefully bknudson can look :-) | 17:41 |
morganfainberg | i am looking through that now to pick out why | 17:41 |
morganfainberg | was trying to give more than just "this one" ;) | 17:41 |
morganfainberg | might be a sync of a repo needed: | 17:41 |
morganfainberg | 2015-01-22 16:31:55.004 | fatal: http://10.20.0.113/p/openstack-dev/grenade/info/refs not found: did you run git update-server-info on the server? | 17:41 |
morganfainberg | seeing some of that. | 17:41 |
morganfainberg | error is: ERROR: the main setup script run by this job failed - exit code: 1 from main log | 17:42 |
morganfainberg | might be pip/requires/grenade/etc - we've had soem issues lately on this front with the main gate. | 17:43 |
tqtran | marekd: concerning https://review.openstack.org/#/c/133529/14, could you clarify how the new spec would help prevent a man-in-the-middle attack? Doesn't Horizon end up with a token in the end anyway? | 17:44 |
Ctina | Hey guys, anyone have a minute to answer some dumb ldap questions? | 17:47 |
stevemar | marekd, ^ still around? | 17:48 |
stevemar | Ctina, ask away | 17:48 |
raildo | adminyoung, ++. could you add this topic there? or just formulate here the topic and I can add. | 17:48 |
morganfainberg | Ctina, anytime. | 17:48 |
Ctina | I'm seeing something similar to what's discussed here: https://bugs.launchpad.net/keystone/+bug/1231488 where i set my user_id_attribute=uidNumber but doing a keystone user-list or a keystone user-get shows the cn as the user-id | 17:49 |
Ctina | i found https://bugs.launchpad.net/keystone/+bug/1361306 which puts the fix in Juno. I'm currently running icehouse and thinking of switching to a ldap + mysql backend. Should I wait until we upgrade to Juno? | 17:49 |
stevemar | samueldmq, we didn't have to change it, but we should list all the modules are import there ... and leave a reason why we comment it out | 17:49 |
rodrigods | stevemar, samueldmq, a new generate of config.py wouldn't erase it? | 17:50 |
morganfainberg | Ctina, looking at the bugs now. | 17:51 |
Ctina | since my 'id' isn't an element in my dn | 17:51 |
Ctina | kk | 17:51 |
*** tellesnobrega_ has quit IRC | 17:51 | |
stevemar | rodrigods, nope | 17:52 |
stevemar | Ctina, what are the settings in your keystone.conf, can you add them to http://paste.openstack.org/ ? | 17:53 |
stevemar | just the ldap ones :) don't include hostname + uname/pass obv :P | 17:53 |
morganfainberg | Ctina, the fix you pointed out does in-fact look like what you need. the DIT isn't controlled so we need to honor the attr map for ID | 17:54 |
morganfainberg | Ctina, so when you user-get, you get a "no such user" or bad data? | 17:55 |
Ctina | morganfainberg, I was able to get the user by i had to do a user-get "<cn>" | 17:56 |
stevemar | i think marekd is away for a bit :( | 17:57 |
Ctina | stevemar: http://paste.openstack.org/show/162338/ | 17:58 |
Ctina | morganfainberg: the user i got back though has the email set and the cn for the id, name, and username attributes | 17:59 |
morganfainberg | Ctina, ok this does absolutely look like that bug then. | 17:59 |
Ctina | morganfainberg: boo okay thanks. Having a single uuid across zones would save us a lot of headache. Looks like i'll hold off implementing ldap + mysql backend until we go to Kilo (we're skipping Juno) | 18:02 |
morganfainberg | Ctina, well let me see if we can backport to I. this might be a pretty easy backport | 18:03 |
morganfainberg | this looks to be the bulk of the change: https://review.openstack.org/#/c/117658/10/keystone/common/ldap/core.py | 18:03 |
morganfainberg | it's not massive. and might be worth sneaking into icehouse. | 18:03 |
morganfainberg | s/sneaking/properly backporting | 18:03 |
*** EmilienM|afk is now known as EmilienM | 18:03 | |
*** gyee has joined #openstack-keystone | 18:04 | |
*** ChanServ sets mode: +v gyee | 18:04 | |
Ctina | morganfainberg: that'd be awesome | 18:04 |
morganfainberg | Ctina, infactt...... | 18:04 |
morganfainberg | gyee, how painful would backport of https://review.openstack.org/#/c/117658/10/keystone/common/ldap/core.py be to icehouse? | 18:05 |
morganfainberg | gyee, i know a lot of stuff has shifted in the LDAP driver since then. | 18:05 |
gyee | morganfainberg, looking | 18:06 |
*** _cjones_ has quit IRC | 18:06 | |
morganfainberg | gyee, might be worth fixing that bug in icehouse before it's EOL | 18:06 |
morganfainberg | 'd | 18:06 |
rodrigods | morganfainberg, marekd, stevemar regarding URL field deprecation for regions table, should we just drop it? | 18:07 |
raildo | morganfainberg, do you if exits some tutorial explain how to install two(or more) keystone in a single cloud? | 18:07 |
morganfainberg | rodrigods, it was only ever used for K2K right? (cc marekd stevemar )? | 18:07 |
adminyoung | Ctina, so there might be something you want to try: | 18:07 |
morganfainberg | rodrigods, if so - probably. | 18:07 |
stevemar | morganfainberg, right, and it was experimental | 18:07 |
stevemar | so drop it | 18:08 |
morganfainberg | then yes. drop it | 18:08 |
morganfainberg | like it's hot | 18:08 |
stevemar | no need to migrate it | 18:08 |
morganfainberg | i mean... sorry >.> | 18:08 |
stevemar | like it HOT! | 18:08 |
adminyoung | Ctina, is the problem only with users/groups for you? | 18:08 |
gyee | morganfainberg, should be able to backport, I don't think its that bad | 18:08 |
rodrigods | morganfainberg, stevemar, remove the migration that was adding it, and add a migration to drop it if present? (or just the last one?) | 18:08 |
morganfainberg | gyee, that was my thought. i'm going to run to get coffee/food - follow Ctina and adminyoung's convo - i'm good with proposing that to stable if it sovles that issue | 18:09 |
morganfainberg | rodrigods, no don't remove the migration adding it | 18:09 |
stevemar | rodrigods, i mean no need to add a migration 'region_url -> sp_url' | 18:09 |
*** adminyoung is now known as ayoung | 18:09 | |
*** harlowja has joined #openstack-keystone | 18:09 | |
rodrigods | stevemar, morganfainberg, ++ | 18:09 |
rodrigods | thanks | 18:09 |
Ctina | adminyoung: i think so? I was trying out the mysql + ldap backend stuff since i'm a noob at ldap and noticed that i couldn't get the userids to show up | 18:09 |
Ctina | ayoung* | 18:10 |
morganfainberg | stevemar, hm. actually do we want a migration? | 18:10 |
morganfainberg | stevemar, that *might* be easy... or are we saying you can't use the old k2k and need to re-setup things? | 18:10 |
ayoung | Ctina, there is some wierdness in the mapping, due to an assumption that the DN was composed of the CN...which is true in only some cases | 18:10 |
gyee | sorry I missed the whole conversation, so Ctina and adminyoung's having issue with attribute mapping? | 18:10 |
Ctina | ayoung: i thought with the dual backends it was only users and groups that you used the ldap for? | 18:10 |
morganfainberg | stevemar, experimental lets us do that, but think of the best experience | 18:11 |
ayoung | Ctina, that is true | 18:11 |
ayoung | Ctina, you want the stuff we have in Juno, for certain | 18:11 |
morganfainberg | gyee, Ctina is having issues with a get-user call without using the CN (vs. using the uid mapped, e.g. id_attr = uidNumber | 18:11 |
samueldmq | stevemar, great. fair enough (https://review.openstack.org/#/c/137270) | 18:11 |
Ctina | gyee: i don't have an id attribute in my dn so when i configure my system for an ldap + mysql backend, it uses the cn for the user id | 18:11 |
ayoung | on the User side, you want to do queries for the user as opposed to the approach of building the DN straight from CN+Subtree path/ | 18:11 |
ayoung | You might be doing this already; | 18:12 |
samueldmq | rodrigods, ^ no, rerunning tox -e sample_config doesnt override it | 18:12 |
samueldmq | rodrigods, just tested | 18:12 |
morganfainberg | Ctina, ++ better description than mine /me ducks out with the really-LDAP-smart folks on the case. | 18:12 |
gyee | ldap + mysql in IceHouse? you are doing custom driver right? | 18:12 |
rodrigods | samueldmq, great! :) | 18:12 |
ayoung | Ctina, http://git.openstack.org/cgit/openstack/keystone/tree/keystone/common/config.py#n535 | 18:12 |
morganfainberg | raildo, as in HA? | 18:12 |
morganfainberg | raildo, or Keystone-to-Keystone? | 18:12 |
ayoung | what do you have your query_scope set to? | 18:12 |
raildo | in HA | 18:12 |
morganfainberg | raildo, sounds like you're asking for HA. | 18:12 |
raildo | morganfainberg, yes :) | 18:13 |
morganfainberg | raildo, hm. i think some docs are out there, but we don't have any in-tree because it's outside the scope of keystone. | 18:13 |
ayoung | Ctina, this might not be your problem | 18:13 |
Ctina | ayoung: i left the default "query_scop=one" | 18:13 |
ayoung | Ctina, try it with sub | 18:13 |
morganfainberg | raildo, e.g. "you can HA this in many ways, but we don't prescribe a specific method" - you can use HAProxy, Keepalived | 18:13 |
morganfainberg | raildo, etc | 18:13 |
morganfainberg | raildo, vrrp | 18:14 |
Ctina | @gyee yes ldap + mysql in Icehouse using the ldap driver for identity and sql for assignment | 18:14 |
*** harlowja has quit IRC | 18:14 | |
raildo | morganfainberg, right, I'll search something about this, thank you. | 18:14 |
Ctina | ayoung: same result | 18:14 |
ayoung | OK...different problem then | 18:15 |
Ctina | ayoung: https://bugs.launchpad.net/keystone/+bug/1361306 | 18:15 |
morganfainberg | ayoung, it looks like this is that bug linked because the id_mapped attribute is being ignored | 18:15 |
morganfainberg | ayoung, in favor of the values in the CN | 18:15 |
*** harlowja has joined #openstack-keystone | 18:15 | |
gyee | yep | 18:15 |
morganfainberg | oh. uvirbot. how i miss you | 18:15 |
gyee | though by using sub filter, the code will attempt to parse the id from user DN | 18:16 |
Ctina | ayoung, morganfainberg, gyee: it's not a big deal to wait until we go to kilo for this, but if it's easy to sneak into Icehouse before EOL it'd be very helpful | 18:16 |
ayoung | morganfainberg, we can backport that if it is essential,but since there are so many shortcomings of the old code base, would recommend that we not do that back to anything older than maybe Icehouse | 18:16 |
ayoung | what is supported right now? | 18:16 |
morganfainberg | ayoung, icehouse is oldest | 18:17 |
morganfainberg | ayoung, and fix is in juno | 18:17 |
morganfainberg | ayoung, this is a case of "yeah probably makes sense to backport it" | 18:17 |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone-specs: Remove URL field from regions https://review.openstack.org/150109 | 18:17 |
Ctina | ayoung: would the other shortcomings you reference make you afraid to put it in production with icehouse ldap + mysql? | 18:17 |
rodrigods | morganfainberg, marekd, stevemar first step ^ | 18:17 |
ayoung | yeah... richm do you think this one is going to mess you up as well: https://bugs.launchpad.net/keystone/+bug/1361306 ? | 18:17 |
*** _cjones_ has joined #openstack-keystone | 18:18 | |
morganfainberg | it looks like a small enough change, with a big enough win to fix a real-hits-operators bug, its worth it | 18:18 |
ayoung | Ctina, I was talking older: read only LDAP not supported if you don't have identity and assignment in two different backends | 18:18 |
Ctina | ayoung: gotcha | 18:19 |
morganfainberg | dstanek, talked to dhellmann about strictabc, we're going to move it to it's own lib once we get things all happy w/ it | 18:19 |
morganfainberg | dstanek, it's likely to be useful for stevedore as well | 18:19 |
dstanek | morganfainberg: nice | 18:20 |
*** abhirc has joined #openstack-keystone | 18:20 | |
morganfainberg | lbragstad, digging up the MySQL tunables for you today | 18:21 |
lbragstad | morganfainberg: \o/ | 18:21 |
morganfainberg | dstanek, that review is ready for more eyes. but i think i want to make another tweak - abstract out the @six.add_metaclass needs | 18:21 |
morganfainberg | so there is a direct decorator to apply to a class @strict_abstract | 18:22 |
morganfainberg | which does all the @six.add_metaclass magic | 18:22 |
dstanek | morganfainberg: i added it to today's queue - i didn't realize that it wasnt' a wip anymore | 18:22 |
morganfainberg | the only question i have then is do I go one step further and make it possible to automatically mark all methods and properties abstract? /me isn't sure. | 18:22 |
morganfainberg | dstanek, it was made non-WIP as of thursday, or friday. | 18:23 |
morganfainberg | no big deal that it wasn't looked at until today | 18:23 |
richm | ayoung: yes, it could, but so far none of us working on puppet-keystone have run into it - I see that it is targeted for juno - has it been backported yet? | 18:24 |
ayoung | richm, I don't think it is a backport: I think it was written for Junoi | 18:25 |
richm | ok - so the fix is already in juno | 18:25 |
ayoung | I wish it had "merge" instead of "commit" dates in the message | 18:25 |
ayoung | richm but the bug update message was generated on 2014-09-13: | 18:26 |
ayoung | that was Juno | 18:26 |
ayoung | richm, so you are not concerned with Icehouse issues then on the Puppet side of thing, just Juno? | 18:26 |
richm | correct | 18:26 |
ayoung | Cool | 18:26 |
samueldmq | topol, ping - would like to ask a view from a core-reviewer on keystone-specs :) | 18:27 |
samueldmq | topol, could please take a look at https://review.openstack.org/#/c/139531/4/api/v3/identity-api-v3.rst ? | 18:28 |
samueldmq | topol, it's a patch that addresses API changes for 'Add support for domain specific roles ' (https://review.openstack.org/#/c/133855/), which has tour +1 (could be a +2 :p) | 18:29 |
*** amakarov is now known as amakarov_away | 18:35 | |
*** zzzeek has joined #openstack-keystone | 18:35 | |
* morganfainberg needs coffee badly [/gauntlet reference] | 18:36 | |
gyee | light roasted | 18:38 |
morganfainberg | gyee, https://bugs.launchpad.net/keystone/+bug/1361306 added icehouse and assigned to you | 18:39 |
*** atiwari has joined #openstack-keystone | 18:39 | |
gyee | k, coding day :) | 18:39 |
morganfainberg | lbragstad, can i ask you a huuuuuge favor today? | 18:40 |
morganfainberg | lbragstad, help me knock this list down to something less than... say 5: https://bugs.launchpad.net/keystone/+bugs?search=Search&field.status=New | 18:40 |
lbragstad | morganfainberg: sure | 18:40 |
morganfainberg | 19 new | 18:40 |
lbragstad | damn... | 18:40 |
morganfainberg | yeah | 18:40 |
*** zhiyan has quit IRC | 18:40 | |
lbragstad | what happened! | 18:40 |
morganfainberg | some of these are dupes i can already see | 18:40 |
morganfainberg | lbragstad, midcycle | 18:40 |
*** zhiyan has joined #openstack-keystone | 18:40 | |
morganfainberg | lbragstad, i've been keeping it hovering at about 8 | 18:41 |
morganfainberg | but.. | 18:41 |
morganfainberg | some of these are deep in our code and hard to chase | 18:41 |
morganfainberg | we also have a number with priority but in "new" status | 18:41 |
morganfainberg | (3) | 18:41 |
morganfainberg | ayoung, we got a bug against LDAP assignment: https://bugs.launchpad.net/keystone/+bug/1409635 | 18:42 |
morganfainberg | ayoung, damn. | 18:42 |
* morganfainberg really misses uvirbot | 18:42 | |
*** jistr has quit IRC | 18:42 | |
gyee | thought we have precisely one R/W LDAP deployment out there, according to the survey | 18:43 |
morganfainberg | gyee, this is R/O LDAP assignment it looks like | 18:43 |
gyee | oh | 18:43 |
Ctina | morganfainberg, gyee: thanks! | 18:44 |
gyee | Ctina, no problem, I love writing code | 18:45 |
*** thedodd has quit IRC | 18:53 | |
*** rushiagr is now known as rushiagr_away | 18:57 | |
*** harlowja has quit IRC | 18:57 | |
*** pnavarro has quit IRC | 18:58 | |
topol | Hi samuelq, https://review.openstack.org/#/c/139531/4/api/v3/identity-api-v3.rst looks like it has some type of merge conflict | 18:59 |
topol | samueldmq, it looks like https://review.openstack.org/#/c/139531/4/api/v3/identity-api-v3.rst ? has some type of merge conflict? | 19:01 |
*** kfox1111 has quit IRC | 19:09 | |
*** pnavarro has joined #openstack-keystone | 19:09 | |
*** atiwari has quit IRC | 19:11 | |
*** david-lyle is now known as david-lyle_afk | 19:15 | |
samueldmq | topol, yes .. looks like something were added at same lines I'm adding, but what we propose is there | 19:16 |
samueldmq | topol, I didnt submitted a new patch set because I'd like to keep the comments in there | 19:17 |
samueldmq | topol, I'll rebase it and then re-add comments ... | 19:17 |
topol | K | 19:17 |
*** nellysmitt has quit IRC | 19:26 | |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone: Drop URL field from region table https://review.openstack.org/150122 | 19:35 |
*** harlowja has joined #openstack-keystone | 19:41 | |
*** thedodd has joined #openstack-keystone | 19:42 | |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone: Drop URL field from region table https://review.openstack.org/150122 | 19:43 |
*** radez is now known as radez_g0n3 | 19:46 | |
*** thedodd has quit IRC | 19:51 | |
*** nellysmitt has joined #openstack-keystone | 19:51 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone-specs: Add domain roles APIs https://review.openstack.org/139531 | 19:52 |
*** thedodd has joined #openstack-keystone | 19:53 | |
samueldmq | topol, ^ new version ... you can refer to previous patch sets to get the discussion that is going on | 19:53 |
samueldmq | topol, in summary, whether we should add new apis for domain-role operations or not | 19:54 |
samueldmq | topol, thanks :) | 19:54 |
samueldmq | henrynash, you around ? | 19:54 |
*** pnavarro has quit IRC | 19:54 | |
*** hichtakk has joined #openstack-keystone | 19:55 | |
stevemar | samueldmq, henrynash is probably offline, he's london time :) | 19:58 |
*** r-daneel has joined #openstack-keystone | 19:59 | |
samueldmq | stevemar, oh sure, thanks :) | 20:01 |
henrynash | stevemar, samueldmq: but I happen to be just checking in, actually….so what’s up? | 20:05 |
samueldmq | henrynash, hey, just woud like to talk about assignments patch, I updated it according to our discussion of last week | 20:09 |
samueldmq | morganfainberg, could you please give me your view on the migration being done at https://review.openstack.org/#/c/142472/ ? | 20:09 |
henrynash | samueldmq: yes, started to look at it…will review ore later - and rebase my experiemtnal data driven tests on it to see if they now pass | 20:09 |
samueldmq | henrynash, great! I will still add more tests and see if I need to update docs | 20:10 |
morganfainberg | henrynash, sorry about the "this patch is too large" comment on your resource split - but even just moving 1400+ lines is very hard to follow. | 20:10 |
henrynash | samueldms: well all my tests are in test_backend…not at the REST level…so if we decide to merge mine in, then they would complement each other nicely | 20:11 |
morganfainberg | henrynash, doing my best to get through it. | 20:11 |
raildo | henrynash, ping, i put a topic about clashing names in the tomorrow meeting, ok? | 20:11 |
henrynash | morganfainberg: i know, i kno | 20:11 |
henrynash | know | 20:11 |
marekd | stevemar: topol morganfainberg rodrigods k2k talk? | 20:11 |
samueldmq | henrynash, great! I will review your work as well | 20:11 |
samueldmq | henrynash, I will base one patch of mine on your metadata removal patch | 20:12 |
samueldmq | henrynash, mines regarding the removal of duplicated inherited logic from several methods in assignments | 20:12 |
samueldmq | henrynash, they'll use list_role_assignments instead (just to recap) | 20:12 |
stevemar | marekd, i'm prepping an etherpad will send out soon | 20:13 |
samueldmq | morganfainberg, is this still valid ? bug #1240625 | 20:16 |
samueldmq | https://bugs.launchpad.net/keystone/+bug/1240625 | 20:16 |
samueldmq | is the channel bot on vacancies ? | 20:16 |
morganfainberg | the channel bot is gone | 20:16 |
morganfainberg | i'm looking at fixing that | 20:16 |
samueldmq | :-( | 20:16 |
morganfainberg | the bot owner also dropped from all channels | 20:16 |
samueldmq | sad, we need it back :) | 20:17 |
morganfainberg | working on that | 20:17 |
samueldmq | nice ! will ask someone else to look at that | 20:17 |
samueldmq | thanks | 20:17 |
morganfainberg | and i don't know if we care about that bug. i mean. it is a valid bug. | 20:17 |
morganfainberg | working on the bot that is | 20:17 |
morganfainberg | not the bug | 20:17 |
morganfainberg | :P | 20:17 |
samueldmq | ahha ++ | 20:17 |
morganfainberg | s/valid bug/gap in capability of a user | 20:18 |
samueldmq | so should that be invalid? | 20:18 |
samueldmq | maybe ? | 20:18 |
morganfainberg | like i said, not sure how much we care. | 20:18 |
samueldmq | I have a patch for that, and wouldnt like to spent efforts if we don't really care :) | 20:19 |
samueldmq | s/spent/spend more | 20:19 |
morganfainberg | samueldmq, hehe so *maybe* the answer is if we go down that path we need to make a " | 20:19 |
morganfainberg | user can update XXX things about themselves" api, not just password | 20:20 |
morganfainberg | but we can't just "fix" the policy in this case. | 20:20 |
morganfainberg | especially since changing the defaulty project in v2 has access implicatio9ns | 20:21 |
samueldmq | looks like we should not touch that ... | 20:21 |
morganfainberg | samueldmq, yeah it gets a bit scary | 20:21 |
samueldmq | not this way at least | 20:21 |
samueldmq | will abandon my patch and say I got scared | 20:22 |
morganfainberg | haha you can just abandon the patch w/o saying you're scared ;) | 20:22 |
samueldmq | will describe the possible implications you pointed out here :-) | 20:23 |
samueldmq | abandoning something w/o saying anything is like 'I got scared' for me | 20:23 |
morganfainberg | sure. | 20:23 |
*** radez_g0n3 is now known as radez | 20:29 | |
*** nellysmitt has quit IRC | 20:35 | |
*** tellesnobrega_ has joined #openstack-keystone | 20:35 | |
bknudson | btw - there was some question at the keystone meetup about the barbican meetup -- it's feb 16-18 : https://wiki.openstack.org/wiki/Sprints/BarbicanKiloSprint | 20:36 |
*** kfox1111 has joined #openstack-keystone | 20:41 | |
*** atiwari has joined #openstack-keystone | 20:41 | |
richm | ayoung: ping - If one does not specify /v2.0 or /v3 in front of a REST URI, what happens e.g. http://host:port/users? | 20:42 |
dstanek | richm: i'm guessing 404, but i haven't tried that | 20:42 |
ayoung | richm, human sacrifice, dogs and cats living together, mass hysteria | 20:42 |
dstanek | ayoung: and a marshmallow man! | 20:43 |
ayoung | or a 404 | 20:43 |
richm | so it is required to specify /v2.0 or /v3 | 20:43 |
ayoung | dstanek, we have a project in house called Staypuft. | 20:43 |
* richm runs . . . | 20:43 | |
ayoung | richm, you making a direct URL call? | 20:43 |
dstanek | nice | 20:43 |
ayoung | dstanek, I want to toast it | 20:43 |
*** tellesnobrega_ has quit IRC | 20:44 | |
richm | need a project S'Mores | 20:44 |
richm | ayoung: someone in #puppet-keystone is asking if we even need to have /v2.0 or /v3 in some urls, due to something called "service discovery" | 20:44 |
*** kfox1111 has quit IRC | 20:45 | |
*** abhirc has quit IRC | 20:48 | |
*** abhirc has joined #openstack-keystone | 20:49 | |
*** abhirc has quit IRC | 20:54 | |
*** _cjones_ has quit IRC | 20:59 | |
*** _cjones_ has joined #openstack-keystone | 20:59 | |
*** markvoelker has quit IRC | 21:00 | |
*** Ctina_ has joined #openstack-keystone | 21:01 | |
*** Ctina has quit IRC | 21:04 | |
*** Ctina_ has quit IRC | 21:06 | |
*** gabriel-bezerra has quit IRC | 21:07 | |
*** samueldmq has quit IRC | 21:07 | |
*** tellesnobrega has quit IRC | 21:07 | |
*** raildo has quit IRC | 21:07 | |
*** htruta has quit IRC | 21:07 | |
*** evilrob has joined #openstack-keystone | 21:07 | |
evilrob | I'm going through the steps at http://docs.openstack.org/juno/install-guide/install/apt/content/keystone-install.html and am to the creating the tenant point. I don't have any processes listening on the indicated port in the config example. Did I miss a step or is something not going right? | 21:08 |
*** raildo has joined #openstack-keystone | 21:12 | |
*** htruta has joined #openstack-keystone | 21:12 | |
*** gabriel-bezerra has joined #openstack-keystone | 21:13 | |
evilrob | yeah... just getting constant restarts "init: keystone main process (19642) terminated with status 1" | 21:14 |
*** tellesnobrega has joined #openstack-keystone | 21:15 | |
*** dims has quit IRC | 21:16 | |
*** dims has joined #openstack-keystone | 21:16 | |
*** dims has quit IRC | 21:21 | |
*** dims has joined #openstack-keystone | 21:27 | |
openstackgerrit | ayoung proposed openstack/keystone-specs: certmonger https://review.openstack.org/134099 | 21:29 |
topol | hi marekd, I just reviewed https://review.openstack.org/#/c/133529/. I think its close | 21:35 |
*** david-lyle_afk is now known as david-lyle | 21:40 | |
*** packet has joined #openstack-keystone | 21:50 | |
*** atiwari has quit IRC | 21:55 | |
*** atiwari has joined #openstack-keystone | 21:56 | |
*** _cjones_ has quit IRC | 21:58 | |
*** _cjones_ has joined #openstack-keystone | 22:00 | |
*** sriram has quit IRC | 22:14 | |
*** samueldmq has joined #openstack-keystone | 22:21 | |
*** radez is now known as radez_g0n3 | 22:22 | |
*** jasondotstar has joined #openstack-keystone | 22:28 | |
*** bknudson has quit IRC | 22:30 | |
*** kfox1111 has joined #openstack-keystone | 22:34 | |
*** mattfarina has quit IRC | 22:39 | |
*** jamielennox|away is now known as jamielennox | 22:41 | |
*** topol has quit IRC | 22:43 | |
morganfainberg | FYI, working with Infra to re-enable bug XXX -> bot showing the info about that bug: https://review.openstack.org/#/c/150166/ | 22:52 |
*** abhirc has joined #openstack-keystone | 22:56 | |
*** thedodd has quit IRC | 22:59 | |
*** mriedem has joined #openstack-keystone | 23:07 | |
mriedem | someone please photoshop bknudson's new evil face on this http://img2-2.timeinc.net/people/i/2007/news/071210/evel_knievel240.jpg | 23:07 |
jamielennox | mriedem: 'new' evil face? | 23:08 |
mriedem | http://static.giantbomb.com/uploads/original/4/40126/1507121-spock_20goatee.jpg | 23:08 |
mriedem | well, evil face 2.0 | 23:08 |
* jamielennox just got here - missed something | 23:09 | |
*** andreaf_ has quit IRC | 23:09 | |
mriedem | bknudson's newish goatee | 23:09 |
*** abhirc has quit IRC | 23:09 | |
jamielennox | mriedem: haven't seen him | 23:09 |
*** andreaf_ has joined #openstack-keystone | 23:10 | |
jamielennox | but i'll look out for it | 23:10 |
openstackgerrit | Jamie Lennox proposed openstack/python-keystoneclient: Add get_communication_params interface to plugins https://review.openstack.org/141267 | 23:12 |
openstackgerrit | Jamie Lennox proposed openstack/python-keystoneclient: Add get_headers interface to authentication plugins https://review.openstack.org/140894 | 23:12 |
*** jaosorior has quit IRC | 23:14 | |
*** _cjones_ has quit IRC | 23:18 | |
*** joesavak has quit IRC | 23:18 | |
*** stevemar has quit IRC | 23:19 | |
*** henrynash has quit IRC | 23:19 | |
morganfainberg | stevemar, marekd, is there anything left to do on this bp: https://review.openstack.org/#/c/130593/ | 23:29 |
morganfainberg | ? | 23:29 |
*** tellesnobrega_ has joined #openstack-keystone | 23:29 | |
*** gordc has quit IRC | 23:29 | |
*** david-lyle is now known as david-lyle_afk | 23:31 | |
jamielennox | morganfainberg: i am not a channel operator, can you set topic: | 23:35 |
jamielennox | Release Blockers: https://gist.github.com/dolph/651c6a1748f69637abd0 << please review | http://opensax.com/ | 23:35 |
*** carlosmarin has quit IRC | 23:36 | |
morganfainberg | LOL "you're not a channel operator" | 23:36 |
jamielennox | who the hell is a channel operator? | 23:36 |
morganfainberg | sec | 23:36 |
morganfainberg | jamielennox, try: /msg chanserv topic #openstack-keystone Release Blockers: https://gist.github.com/dolph/651c6a1748f69637abd0 << please review | http://opensax.com/ | 23:37 |
morganfainberg | jamielennox, want to see if you have permission to do that | 23:37 |
*** ChanServ changes topic to "Release Blockers: https://gist.github.com/dolph/651c6a1748f69637abd0 << please review | http://opensax.com/" | 23:37 | |
morganfainberg | jamielennox, there ya go all current core can do that | 23:37 |
jamielennox | huh - ok | 23:37 |
* morganfainberg actually setup permissions right initially | 23:37 | |
jamielennox | that's reasonable | 23:37 |
jamielennox | morganfainberg: my release on the 1st target is going to fail miserably at this rate | 23:38 |
morganfainberg | jamielennox, now that i'm back home i actually have time for reviews | 23:39 |
morganfainberg | whole last week kinda made things icky | 23:39 |
jamielennox | marekd: are you here? | 23:41 |
morganfainberg | jamielennox, https://blueprints.launchpad.net/openstack/?searchtext=add-saml2-cli-authentication is missing | 23:41 |
morganfainberg | something weird with that one | 23:42 |
jamielennox | morganfainberg: i wrote the original impl - marekd's been doing the work | 23:42 |
morganfainberg | but no bp. | 23:42 |
morganfainberg | in lp? | 23:42 |
morganfainberg | or.. uh.. | 23:42 |
jamielennox | didn't realize i still was author | 23:42 |
morganfainberg | that was a direct link from the blocking reviews gist | 23:42 |
*** ChanServ changes topic to "Release Blockers: https://gist.github.com/dolph/651c6a1748f69637abd0 << please review for client release on Feb 1st | http://opensax.com/" | 23:43 | |
*** abhirc has joined #openstack-keystone | 23:43 | |
openstackgerrit | ayoung proposed openstack/keystone: member for assignment policy https://review.openstack.org/142162 | 23:54 |
*** chlong has joined #openstack-keystone | 23:55 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!