*** markvoelker has quit IRC | 00:02 | |
*** shoutm has quit IRC | 00:06 | |
*** shadower has quit IRC | 00:23 | |
*** shadower has joined #openstack-keystone | 00:23 | |
*** browne has quit IRC | 00:31 | |
*** piyanai has joined #openstack-keystone | 00:35 | |
*** narengan has quit IRC | 00:45 | |
*** narengan has joined #openstack-keystone | 00:46 | |
*** narengan has quit IRC | 00:50 | |
*** mestery has joined #openstack-keystone | 00:59 | |
*** boris-42 has quit IRC | 01:10 | |
*** ankita_wagh has joined #openstack-keystone | 01:11 | |
*** vmbrasseur_GONE has quit IRC | 01:13 | |
*** ngupta has joined #openstack-keystone | 01:15 | |
*** davechen has joined #openstack-keystone | 01:20 | |
*** vmbrasseur has joined #openstack-keystone | 01:21 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Use wsgi_scripts to create admin and public httpd files https://review.openstack.org/194442 | 01:23 |
---|---|---|
*** davechen1 has joined #openstack-keystone | 01:23 | |
*** davechen has quit IRC | 01:25 | |
*** piyanai has quit IRC | 01:36 | |
*** mestery has quit IRC | 01:36 | |
*** mestery has joined #openstack-keystone | 01:37 | |
*** mestery has quit IRC | 01:37 | |
*** boris-42 has joined #openstack-keystone | 01:38 | |
*** ngupta has quit IRC | 01:39 | |
*** ankita_wagh has quit IRC | 01:43 | |
*** ankita_wagh has joined #openstack-keystone | 01:44 | |
*** ankita_wagh has quit IRC | 01:48 | |
*** rodrigod` has quit IRC | 01:53 | |
*** rodrigod` has joined #openstack-keystone | 01:53 | |
*** rodrigod` is now known as rodrigods | 01:57 | |
*** markvoelker has joined #openstack-keystone | 01:58 | |
*** markvoelker has quit IRC | 02:03 | |
*** ankita_wagh has joined #openstack-keystone | 02:11 | |
*** ngupta has joined #openstack-keystone | 02:20 | |
*** markvoelker has joined #openstack-keystone | 02:31 | |
*** ngupta has quit IRC | 02:42 | |
*** hakimo_ has joined #openstack-keystone | 02:52 | |
*** hakimo has quit IRC | 02:54 | |
*** ankita_wagh has quit IRC | 03:06 | |
*** ankita_wagh has joined #openstack-keystone | 03:06 | |
*** ankita_wagh has quit IRC | 03:11 | |
*** ankita_w_ has joined #openstack-keystone | 03:11 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Log request ID https://review.openstack.org/213595 | 03:17 |
*** piyanai has joined #openstack-keystone | 03:29 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Log request ID https://review.openstack.org/213595 | 03:39 |
*** piyanai has quit IRC | 03:39 | |
*** flwang1 has joined #openstack-keystone | 03:49 | |
*** ayoung has quit IRC | 03:52 | |
*** flwang has quit IRC | 03:53 | |
*** Ephur has joined #openstack-keystone | 04:02 | |
*** hrou has quit IRC | 04:03 | |
*** openstack has joined #openstack-keystone | 04:17 | |
*** markvoelker has quit IRC | 04:31 | |
*** geoffarnoldX is now known as geoffarnold | 04:49 | |
*** geoffarnold is now known as geoffarnoldX | 04:50 | |
*** geoffarnoldX is now known as geoffarnold | 05:15 | |
*** topol has joined #openstack-keystone | 05:23 | |
*** ChanServ sets mode: +v topol | 05:23 | |
*** topol has quit IRC | 05:27 | |
*** geoffarnold is now known as geoffarnoldX | 05:27 | |
*** markvoelker has joined #openstack-keystone | 05:32 | |
*** geoffarnoldX has quit IRC | 05:32 | |
*** urulama has joined #openstack-keystone | 05:35 | |
*** markvoelker has quit IRC | 05:36 | |
*** topol has joined #openstack-keystone | 05:37 | |
*** ChanServ sets mode: +v topol | 05:37 | |
*** urulama has quit IRC | 06:01 | |
*** urulama has joined #openstack-keystone | 06:01 | |
*** afazekas has quit IRC | 06:10 | |
*** lsmola has joined #openstack-keystone | 06:12 | |
*** topol has quit IRC | 06:17 | |
*** topol has joined #openstack-keystone | 06:18 | |
*** ChanServ sets mode: +v topol | 06:18 | |
*** Navid_ has joined #openstack-keystone | 06:18 | |
*** gpanda has joined #openstack-keystone | 06:21 | |
*** claudiub has joined #openstack-keystone | 06:21 | |
*** ankita_w_ has quit IRC | 06:22 | |
*** ankita_wagh has joined #openstack-keystone | 06:22 | |
*** gpanda has quit IRC | 06:22 | |
*** gpanda has joined #openstack-keystone | 06:23 | |
*** topol has quit IRC | 06:24 | |
*** ankita_wagh has quit IRC | 06:27 | |
*** akscram has quit IRC | 06:32 | |
*** akscram has joined #openstack-keystone | 06:33 | |
*** sileht has quit IRC | 06:55 | |
*** sileht has joined #openstack-keystone | 06:56 | |
*** ankita_wagh has joined #openstack-keystone | 06:56 | |
*** afazekas_ has joined #openstack-keystone | 07:01 | |
*** shoutm has joined #openstack-keystone | 07:01 | |
-openstackstatus- NOTICE: Gerrit is currently under very high load and may be unresponsive. infra are looking into the issue. | 07:06 | |
*** Nirupama has joined #openstack-keystone | 07:07 | |
*** gpanda has quit IRC | 07:26 | |
*** gpanda has joined #openstack-keystone | 07:27 | |
*** gpanda has quit IRC | 07:33 | |
*** markvoelker has joined #openstack-keystone | 07:33 | |
*** gpanda has joined #openstack-keystone | 07:33 | |
*** markvoelker has quit IRC | 07:37 | |
*** fhubik has joined #openstack-keystone | 07:39 | |
*** vivekd has joined #openstack-keystone | 07:42 | |
*** gpanda has quit IRC | 07:46 | |
*** ankita_wagh has quit IRC | 07:46 | |
*** gpanda has joined #openstack-keystone | 07:47 | |
*** fhubik is now known as fhubik_brb | 07:49 | |
*** gpanda has quit IRC | 07:56 | |
*** gpanda has joined #openstack-keystone | 07:57 | |
*** fhubik_brb is now known as fhubik | 08:08 | |
*** henrynash has quit IRC | 08:08 | |
*** afazekas_ is now known as afazkas | 08:12 | |
*** fhubik is now known as fhubik_brb | 08:14 | |
*** fhubik_brb is now known as fhubik | 08:16 | |
*** gpanda has quit IRC | 08:16 | |
*** gpanda has joined #openstack-keystone | 08:17 | |
*** fhubik is now known as fhubik_brb | 08:18 | |
*** gpanda has quit IRC | 08:18 | |
*** gpanda has joined #openstack-keystone | 08:18 | |
*** jistr has joined #openstack-keystone | 08:21 | |
*** fhubik_brb is now known as fhubik | 08:21 | |
*** vivekd has quit IRC | 08:23 | |
*** fhubik is now known as fhubik_brb | 08:24 | |
*** pnavarro has joined #openstack-keystone | 08:31 | |
*** josecastroleon has joined #openstack-keystone | 08:35 | |
*** gpanda has quit IRC | 08:36 | |
*** fhubik_brb is now known as fhubik | 08:37 | |
*** gpanda has joined #openstack-keystone | 08:37 | |
*** fhubik is now known as fhubik_brb | 08:38 | |
*** davechen1 has left #openstack-keystone | 08:46 | |
*** gpanda has quit IRC | 08:46 | |
*** gpanda has joined #openstack-keystone | 08:47 | |
*** marekd_404 has quit IRC | 08:54 | |
*** fhubik_brb is now known as fhubik | 08:58 | |
*** urulama has quit IRC | 09:01 | |
*** urulama has joined #openstack-keystone | 09:01 | |
*** gpanda has quit IRC | 09:07 | |
*** gpanda has joined #openstack-keystone | 09:07 | |
*** gpanda has quit IRC | 09:14 | |
openstackgerrit | Paweł Pamuła proposed openstack/keystone: IdP deletion triggers token revocation https://review.openstack.org/210456 | 09:19 |
*** pnavarro has quit IRC | 09:22 | |
*** vivekd has joined #openstack-keystone | 09:23 | |
*** pnavarro has joined #openstack-keystone | 09:24 | |
*** markvoelker has joined #openstack-keystone | 09:33 | |
*** markvoelker has quit IRC | 09:38 | |
*** Guest47951 is now known as d0ugal | 09:49 | |
*** d0ugal has quit IRC | 09:49 | |
*** d0ugal has joined #openstack-keystone | 09:49 | |
*** dims has joined #openstack-keystone | 10:17 | |
*** fhubik has quit IRC | 10:18 | |
*** fhubik has joined #openstack-keystone | 10:18 | |
*** yottatsa has joined #openstack-keystone | 10:20 | |
-openstackstatus- NOTICE: review.openstack.org (aka gerrit) is going down for an emergency restart | 10:21 | |
*** ChanServ changes topic to "review.openstack.org (aka gerrit) is going down for an emergency restart" | 10:21 | |
*** dims has quit IRC | 10:30 | |
*** dims has joined #openstack-keystone | 10:31 | |
*** dims_ has joined #openstack-keystone | 10:36 | |
*** dims has quit IRC | 10:38 | |
*** marekd has joined #openstack-keystone | 10:39 | |
*** ChanServ sets mode: +v marekd | 10:39 | |
*** marekd is now known as marekd_404 | 10:40 | |
*** josecastroleon has quit IRC | 10:40 | |
*** piyanai has joined #openstack-keystone | 10:45 | |
*** Navid_ has quit IRC | 10:46 | |
*** dikonoo has joined #openstack-keystone | 10:47 | |
*** dikonoor has joined #openstack-keystone | 10:47 | |
*** ChanServ changes topic to "Review code, feature freeze is rapidly approaching." | 10:48 | |
-openstackstatus- NOTICE: Gerrit restart has resolved the issue and systems are back up and functioning | 10:48 | |
*** dims_ has quit IRC | 10:50 | |
*** dims has joined #openstack-keystone | 10:51 | |
*** fhubik is now known as fhubik_brb | 10:53 | |
*** piyanai has quit IRC | 10:56 | |
*** piyanai has joined #openstack-keystone | 10:56 | |
*** dims has quit IRC | 10:59 | |
*** dims has joined #openstack-keystone | 11:00 | |
*** dims has quit IRC | 11:06 | |
*** dims has joined #openstack-keystone | 11:08 | |
*** boris-42 has quit IRC | 11:10 | |
*** dims_ has joined #openstack-keystone | 11:12 | |
*** dims has quit IRC | 11:12 | |
*** dims_ has quit IRC | 11:17 | |
*** henrynash has joined #openstack-keystone | 11:19 | |
*** ChanServ sets mode: +v henrynash | 11:19 | |
*** mflobo has joined #openstack-keystone | 11:19 | |
*** piyanai has quit IRC | 11:20 | |
*** dims has joined #openstack-keystone | 11:22 | |
*** urulama has quit IRC | 11:24 | |
*** urulama has joined #openstack-keystone | 11:24 | |
*** dims has quit IRC | 11:27 | |
*** dims has joined #openstack-keystone | 11:29 | |
*** josecastroleon has joined #openstack-keystone | 11:31 | |
*** markvoelker has joined #openstack-keystone | 11:34 | |
*** dims_ has joined #openstack-keystone | 11:34 | |
*** dims has quit IRC | 11:35 | |
*** markvoelker has quit IRC | 11:39 | |
*** dims_ has quit IRC | 11:39 | |
*** mflobo has left #openstack-keystone | 11:40 | |
*** dims has joined #openstack-keystone | 11:40 | |
*** woodster_ has joined #openstack-keystone | 11:46 | |
*** fhubik_brb is now known as fhubik | 11:48 | |
*** dims has quit IRC | 11:49 | |
*** dikonoo has quit IRC | 11:49 | |
*** dims has joined #openstack-keystone | 11:53 | |
*** dims_ has joined #openstack-keystone | 11:56 | |
*** dims has quit IRC | 11:58 | |
*** chlong has quit IRC | 11:59 | |
openstackgerrit | Terry Howe proposed openstack/keystoneauth: Keep a consistent logger name for keystoneauth https://review.openstack.org/212602 | 12:00 |
*** dims_ has quit IRC | 12:04 | |
*** dims has joined #openstack-keystone | 12:04 | |
*** dims_ has joined #openstack-keystone | 12:08 | |
*** yottatsa has quit IRC | 12:09 | |
*** dims has quit IRC | 12:10 | |
*** dims has joined #openstack-keystone | 12:12 | |
*** dims_ has quit IRC | 12:14 | |
*** dims_ has joined #openstack-keystone | 12:18 | |
*** edmondsw has joined #openstack-keystone | 12:18 | |
*** dims has quit IRC | 12:18 | |
*** dims has joined #openstack-keystone | 12:19 | |
*** dims_ has quit IRC | 12:23 | |
*** dims_ has joined #openstack-keystone | 12:26 | |
*** henrynash has quit IRC | 12:26 | |
*** dims has quit IRC | 12:26 | |
*** topol has joined #openstack-keystone | 12:27 | |
*** ChanServ sets mode: +v topol | 12:27 | |
*** tellesnobrega_af has quit IRC | 12:28 | |
*** dims has joined #openstack-keystone | 12:30 | |
*** tellesnobrega has joined #openstack-keystone | 12:30 | |
*** pnavarro is now known as pnavarro|lunch | 12:30 | |
*** yottatsa has joined #openstack-keystone | 12:31 | |
openstackgerrit | Merged openstack/pycadf: Adding barbican specific base resources. https://review.openstack.org/210023 | 12:31 |
*** dims_ has quit IRC | 12:31 | |
*** topol has quit IRC | 12:31 | |
*** jianzj has joined #openstack-keystone | 12:31 | |
*** yottatsa has quit IRC | 12:32 | |
*** yottatsa_ has joined #openstack-keystone | 12:33 | |
jianzj | Hi, I am a new member, who want to learn more in this Keystone Community, and hope if I could contribute to Keystone Service. | 12:33 |
*** hrou has joined #openstack-keystone | 12:33 | |
jianzj | My name is Zhao Jian, English name is Eric. I am from China, I am glad to join this family, and if anything that I could do or I could help, please just let me know. Thanks very much! | 12:34 |
*** dims has quit IRC | 12:35 | |
*** dims has joined #openstack-keystone | 12:35 | |
*** dims_ has joined #openstack-keystone | 12:38 | |
*** dims has quit IRC | 12:40 | |
*** edmondsw_ has joined #openstack-keystone | 12:41 | |
*** ekarlso has quit IRC | 12:44 | |
*** ekarlso has joined #openstack-keystone | 12:44 | |
*** dims has joined #openstack-keystone | 12:45 | |
*** dims_ has quit IRC | 12:45 | |
*** tjcocozz has joined #openstack-keystone | 12:48 | |
*** edmondsw_ has quit IRC | 12:48 | |
*** Nirupama has quit IRC | 12:49 | |
*** topol has joined #openstack-keystone | 12:49 | |
*** ChanServ sets mode: +v topol | 12:49 | |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone: Add is_domain field in Project Table https://review.openstack.org/213273 | 12:50 |
*** piyanai has joined #openstack-keystone | 12:51 | |
*** dims has quit IRC | 12:55 | |
*** raildo-afk is now known as raildo | 12:57 | |
*** shikel has joined #openstack-keystone | 12:58 | |
*** dims has joined #openstack-keystone | 12:58 | |
*** geoffarnold has joined #openstack-keystone | 13:01 | |
*** lifeless has quit IRC | 13:05 | |
*** dims has quit IRC | 13:06 | |
*** dims has joined #openstack-keystone | 13:09 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Build oslo.context RequestContext https://review.openstack.org/213595 | 13:11 |
*** dims has quit IRC | 13:14 | |
*** dims has joined #openstack-keystone | 13:14 | |
*** dims has quit IRC | 13:21 | |
*** geoffarnold has quit IRC | 13:21 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Build oslo.context RequestContext https://review.openstack.org/213595 | 13:25 |
*** dims has joined #openstack-keystone | 13:27 | |
*** pnavarro|lunch is now known as pnavarro | 13:28 | |
*** lifeless has joined #openstack-keystone | 13:28 | |
*** jianzj has quit IRC | 13:31 | |
*** narengan has joined #openstack-keystone | 13:35 | |
*** fhubik is now known as fhubik_brb | 13:35 | |
*** markvoelker has joined #openstack-keystone | 13:35 | |
*** dims has quit IRC | 13:36 | |
*** jecarey has joined #openstack-keystone | 13:38 | |
*** zzzeek has joined #openstack-keystone | 13:38 | |
*** markvoelker has quit IRC | 13:39 | |
*** piyanai has quit IRC | 13:40 | |
*** dims has joined #openstack-keystone | 13:42 | |
*** fhubik_brb is now known as fhubik | 13:46 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Build oslo.context RequestContext https://review.openstack.org/213595 | 13:47 |
*** dims has quit IRC | 13:48 | |
*** piyanai has joined #openstack-keystone | 13:49 | |
*** mylu has joined #openstack-keystone | 13:50 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Build oslo.context RequestContext https://review.openstack.org/213595 | 13:51 |
*** dims has joined #openstack-keystone | 13:54 | |
*** petertr7_away is now known as petertr7 | 13:56 | |
*** fhubik is now known as fhubik_brb | 13:57 | |
*** narengan has quit IRC | 13:59 | |
*** dims has quit IRC | 13:59 | |
*** narengan has joined #openstack-keystone | 13:59 | |
*** boris-42 has joined #openstack-keystone | 14:00 | |
*** ngupta has joined #openstack-keystone | 14:01 | |
*** mylu has quit IRC | 14:02 | |
*** mylu has joined #openstack-keystone | 14:02 | |
*** topol has quit IRC | 14:03 | |
*** chlong has joined #openstack-keystone | 14:03 | |
*** topol has joined #openstack-keystone | 14:03 | |
*** ChanServ sets mode: +v topol | 14:03 | |
*** fhubik_brb is now known as fhubik | 14:04 | |
*** dims has joined #openstack-keystone | 14:04 | |
*** narengan has quit IRC | 14:04 | |
*** mylu has quit IRC | 14:04 | |
*** mylu has joined #openstack-keystone | 14:08 | |
*** doug-fish has joined #openstack-keystone | 14:09 | |
*** mylu has quit IRC | 14:10 | |
*** HT_sergio has joined #openstack-keystone | 14:10 | |
*** mylu has joined #openstack-keystone | 14:11 | |
*** dims has quit IRC | 14:11 | |
*** shoutm has quit IRC | 14:12 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:15 | |
*** dims has joined #openstack-keystone | 14:16 | |
*** ngupta has quit IRC | 14:18 | |
*** samueldmq has joined #openstack-keystone | 14:20 | |
*** piyanai_ has joined #openstack-keystone | 14:20 | |
samueldmq | morning | 14:20 |
*** dims has quit IRC | 14:22 | |
*** mylu has quit IRC | 14:22 | |
*** mylu has joined #openstack-keystone | 14:22 | |
*** piyanai has quit IRC | 14:22 | |
*** piyanai_ is now known as piyanai | 14:22 | |
*** samueldmq has quit IRC | 14:24 | |
*** fhubik is now known as fhubik_brb | 14:24 | |
*** doug-fish has quit IRC | 14:26 | |
*** phalmos has joined #openstack-keystone | 14:26 | |
*** samueldmq has joined #openstack-keystone | 14:26 | |
*** dsirrine has quit IRC | 14:26 | |
*** narengan has joined #openstack-keystone | 14:27 | |
dstanek | samueldmq: morning | 14:28 |
*** piyanai_ has joined #openstack-keystone | 14:28 | |
*** dsirrine has joined #openstack-keystone | 14:29 | |
*** ngupta has joined #openstack-keystone | 14:29 | |
*** doug-fish has joined #openstack-keystone | 14:30 | |
*** piyanai has quit IRC | 14:30 | |
*** piyanai_ is now known as piyanai | 14:30 | |
*** afazkas has quit IRC | 14:31 | |
*** mylu has quit IRC | 14:32 | |
*** topol has quit IRC | 14:33 | |
*** mylu has joined #openstack-keystone | 14:33 | |
vivekd | dstanek: good morning | 14:34 |
vivekd | dstanek: i submitted a simple one line fix @ https://review.openstack.org/#/c/213342/ and dolphm has given a code-review+2 for it. | 14:34 |
vivekd | dstanek: would you be able to spare sometime to review it? | 14:34 |
dstanek | vivekd: sure, what company do you work for? | 14:37 |
vivekd | dstanek: thank you! its reliance industries limited | 14:38 |
*** fhubik_brb is now known as fhubik | 14:38 | |
vivekd | dstanek: how about u? | 14:38 |
dstanek | vivekd: ok, cool. i couldn't tell by your email and if you were a Racker I couldn't +A the change | 14:38 |
vivekd | dstanek: racker means? and +A means approve? | 14:40 |
dstanek | vivekd: Racker == work at Rackspace | 14:41 |
dstanek | vivekd: yes, a +A is an approval | 14:41 |
*** narengan has quit IRC | 14:41 | |
*** narengan has joined #openstack-keystone | 14:42 | |
vivekd | oh ok :-) dstanek . that implies u work for rackspace | 14:42 |
*** fhubik is now known as fhubik_brb | 14:44 | |
*** ayoung has joined #openstack-keystone | 14:44 | |
*** ChanServ sets mode: +v ayoung | 14:44 | |
*** doug-fis_ has joined #openstack-keystone | 14:45 | |
*** narengan has quit IRC | 14:46 | |
*** doug-fish has quit IRC | 14:48 | |
*** dims has joined #openstack-keystone | 14:48 | |
*** phalmos has quit IRC | 14:49 | |
lbragstad | random question - this is liberty milestone 2, right? https://github.com/openstack/keystone/commits/8.0.0.0b2 | 14:49 |
*** markvoelker has joined #openstack-keystone | 14:51 | |
*** samueldmq has quit IRC | 14:51 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Build oslo.context RequestContext https://review.openstack.org/213595 | 14:53 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Add user_has_domain property to KeystoneToken https://review.openstack.org/213742 | 14:53 |
ayoung | rodrigods, so...let me bounce something off you about roles, policy and so forth.... | 14:55 |
dstanek | vivekd: correct | 14:55 |
*** markvoelker has quit IRC | 14:55 | |
rodrigods | ayoung, ok... :) | 14:55 |
*** gordc has joined #openstack-keystone | 14:56 | |
ayoung | rodrigods, OK, so I was trying to implement one of the later stages of dyanmic policy: let a user select which roles to have in a token | 14:56 |
ayoung | and...fernet tokens make that really hard. | 14:56 |
ayoung | today with fernet, the token does not have a role list. It reproduces it from the user-project assignments | 14:56 |
rodrigods | yes... that's a problem if you are not hitting keystone | 14:57 |
*** dikonoor has quit IRC | 14:57 | |
ayoung | rodrigods, fernet hits Keystone, but it is s till a problem. Actually, PKI would handle this fine, as would UUID | 14:57 |
ayoung | both keep a serialized blob that represents the token data | 14:58 |
ayoung | UUID in the database, PKI in the body of the token | 14:58 |
rodrigods | ayoung, ok... forget what I said | 14:58 |
ayoung | rodrigods, its good to make it explicit... | 14:58 |
rodrigods | (imagined you'd want to use the actual information in the token without hitting keystone) | 14:58 |
ayoung | rodrigods, I would state the goal this way: record as little explicit information as possible | 14:59 |
*** doug-fis_ has quit IRC | 14:59 | |
rodrigods | ayoung, ok... but why fernet is giving you problems? | 15:00 |
ayoung | rodrigods, for instance, in fernet, they hold the userid, but not the username. Projectid, but not roles..etc | 15:00 |
*** doug-fish has joined #openstack-keystone | 15:00 | |
ayoung | rodrigods, the fernet tokens are ephemeral...only store info neded to reproduce the whole token | 15:00 |
*** phalmos has joined #openstack-keystone | 15:00 | |
ayoung | so...arbitrary list of roles either needs to be stored in the token, or we need another database table | 15:00 |
ayoung | but wirth Fernet, we are trying to keep them small. | 15:01 |
rodrigods | ayoung, yes... but why you listing role assignments doesn't work for your case? | 15:01 |
ayoung | rodrigods, originally, I wanted to say that a token could have only one role in it....but that does not really work. | 15:01 |
ayoung | rodrigods, OK... | 15:01 |
ayoung | so, lets say we want to make a token with only the info to do nova boot | 15:02 |
ayoung | so, we have APIs like | 15:02 |
ayoung | compute:create storage:attach, network:port_attach and image:download | 15:02 |
ayoung | lets say we make all of those into explicit roles. | 15:02 |
ayoung | so we want a token with those 4 roles on it. And only those four | 15:03 |
*** doug-fish has quit IRC | 15:03 | |
ayoung | so the size of the fernet token would expand by 4 UUIDs | 15:03 |
ayoung | and...if we had an audit token, and it needed read_only access to say, 18 different APIs... | 15:04 |
ayoung | you see the pattern? | 15:04 |
rodrigods | ayoung, right... not I get it | 15:04 |
rodrigods | now* | 15:04 |
ayoung | either we use the roles as a nichname for the permissions, and then, we should only allow a single role. | 15:04 |
ayoung | Or we allow an arbitrary set of permissions. | 15:04 |
ayoung | I think I'm going to go with "if you request a specific role, you can only get one" | 15:05 |
ayoung | and make people come up with new roles for grouping | 15:05 |
* morgan_503 waves from airport otw to ops midcycle thing. | 15:05 | |
rodrigods | ayoung, I agree... looks like the right first step to make | 15:06 |
*** csoukup has joined #openstack-keystone | 15:06 | |
*** morgan_503 is now known as morgan_2549 | 15:06 | |
bknudson | morgan_2549: godspeed | 15:10 |
morgan_2549 | Hehe | 15:12 |
ayoung | rodrigods, so...this might actually cover Henrynash's "domain scoped roles" and so forth | 15:13 |
*** mylu has quit IRC | 15:13 | |
*** markvoelker has joined #openstack-keystone | 15:15 | |
*** narengan has joined #openstack-keystone | 15:17 | |
*** chlong has quit IRC | 15:18 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Build oslo.context RequestContext https://review.openstack.org/213595 | 15:19 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Fix docstring for common.authorization https://review.openstack.org/213752 | 15:19 |
*** mylu has joined #openstack-keystone | 15:20 | |
*** tsubic has quit IRC | 15:20 | |
openstackgerrit | Monty Taylor proposed openstack/keystoneauth: Finalize rename of token_endpoint to admin_token https://review.openstack.org/213385 | 15:23 |
openstackgerrit | Monty Taylor proposed openstack/keystoneauth: Port in the argument scrubbing from OCC https://review.openstack.org/213477 | 15:24 |
*** urulama has quit IRC | 15:26 | |
*** urulama has joined #openstack-keystone | 15:26 | |
*** e0ne has joined #openstack-keystone | 15:26 | |
*** topol has joined #openstack-keystone | 15:27 | |
*** ChanServ sets mode: +v topol | 15:27 | |
*** doug-fish has joined #openstack-keystone | 15:27 | |
*** vivekd has quit IRC | 15:28 | |
*** chlong has joined #openstack-keystone | 15:32 | |
*** chlong has quit IRC | 15:38 | |
*** chlong has joined #openstack-keystone | 15:40 | |
*** geoffarnold has joined #openstack-keystone | 15:42 | |
*** geoffarnold is now known as geoffarnoldX | 15:42 | |
*** _cjones_ has joined #openstack-keystone | 15:42 | |
*** nkinder has joined #openstack-keystone | 15:42 | |
*** fhubik_brb is now known as fhubik | 15:43 | |
*** _cjones_ has quit IRC | 15:43 | |
*** _cjones_ has joined #openstack-keystone | 15:44 | |
*** Ephur has joined #openstack-keystone | 15:46 | |
*** dguerri` is now known as dguerri | 15:46 | |
*** mylu has quit IRC | 15:47 | |
*** geoffarnoldX is now known as geoffarnold | 15:47 | |
*** mylu has joined #openstack-keystone | 15:48 | |
*** mylu has quit IRC | 15:52 | |
*** mestery has joined #openstack-keystone | 15:53 | |
*** gyee has joined #openstack-keystone | 15:56 | |
*** ChanServ sets mode: +v gyee | 15:56 | |
openstackgerrit | ayoung proposed openstack/keystoneauth: Port in the argument scrubbing from OCC https://review.openstack.org/213477 | 15:57 |
*** zzzeek has quit IRC | 15:57 | |
*** zzzeek has joined #openstack-keystone | 15:59 | |
*** tsymanczyk has quit IRC | 16:02 | |
*** samueldmq has joined #openstack-keystone | 16:08 | |
*** e0ne has quit IRC | 16:09 | |
openstackgerrit | Doug Fish proposed openstack/keystoneauth: Update k2k plugin with related code comments https://review.openstack.org/209671 | 16:13 |
*** david-ly_ is now known as david-lyle | 16:15 | |
*** lhcheng has joined #openstack-keystone | 16:16 | |
*** ChanServ sets mode: +v lhcheng | 16:16 | |
*** jistr has quit IRC | 16:19 | |
openstackgerrit | Doug Fish proposed openstack/python-keystoneclient: Add Keystone2Keystone auth plugin for K2K https://review.openstack.org/207585 | 16:23 |
*** stevemar has joined #openstack-keystone | 16:24 | |
*** ChanServ sets mode: +v stevemar | 16:24 | |
openstackgerrit | Doug Fish proposed openstack/python-keystoneclient: Add Keystone2Keystone auth plugin for K2K https://review.openstack.org/207585 | 16:28 |
*** fhubik is now known as fhubik_brb | 16:31 | |
*** fhubik_brb is now known as fhubik | 16:31 | |
ayoung | dstanek, morgan_2549 bknudson so. we need to book hotel rooms through the night of the 30th to do the full Developers summit, right? | 16:32 |
*** henrynash has joined #openstack-keystone | 16:32 | |
*** ChanServ sets mode: +v henrynash | 16:32 | |
bknudson | ayoung: design summit is tuesday - friday | 16:34 |
ayoung | bknudson, and Friday is 30th. But I guess if you can get a flight out the night of the 30th you are OK? | 16:34 |
dstanek | ayoung: i was not planning on staying the night of the 30th | 16:35 |
*** yottatsa_ has quit IRC | 16:35 | |
*** yottatsa has joined #openstack-keystone | 16:36 | |
*** tqtran-afk has joined #openstack-keystone | 16:38 | |
*** tqtran-afk is now known as tqtran | 16:38 | |
stevemar | dstanek: why not? when are you going to be back in tokyo? :) | 16:41 |
dstanek | stevemar: ideally, never :-) i'm not a fan of international travel | 16:42 |
*** tsymanczyk has joined #openstack-keystone | 16:43 | |
openstackgerrit | Timothy Symanczyk proposed openstack/keystone: Simplify rule in sample v3 policy file https://review.openstack.org/213338 | 16:44 |
*** Navid_ has joined #openstack-keystone | 16:45 | |
*** c_soukup has joined #openstack-keystone | 16:49 | |
*** csoukup_ has joined #openstack-keystone | 16:50 | |
openstackgerrit | Merged openstack/keystone: EndpointFilter driver doesnt inherit its interface https://review.openstack.org/213342 | 16:50 |
gyee | book a room or capsule? | 16:53 |
*** c_soukup has quit IRC | 16:53 | |
*** csoukup has quit IRC | 16:54 | |
stevemar | room :) | 16:54 |
stevemar | i doubt i'll fit in a capsule | 16:54 |
gyee | hah | 16:54 |
morgan_2549 | ayoung: uhmm. Not sure | 16:54 |
ayoung | stevemar, claustrophobia | 16:55 |
gyee | morgan_2549, you in Palo Alto today? its like 100 degrees here | 16:55 |
ayoung | where'd people get rooms? | 16:55 |
morgan_2549 | Just landed at sjc | 16:55 |
morgan_2549 | Headed to Sunnyvale once I get car and such. | 16:56 |
*** fhubik has quit IRC | 16:56 | |
*** jecarey has quit IRC | 16:57 | |
*** henrynash has quit IRC | 16:58 | |
*** pnavarro has quit IRC | 16:59 | |
gyee | morgan_2549, stay indoors today, its going to be triple digits | 16:59 |
*** _cjones_ has quit IRC | 17:00 | |
dolphm | morgan_2549: RFC 2549? | 17:00 |
morgan_2549 | gyee: it's been 100-108 the last 5 days in SoCal | 17:00 |
*** narengan has quit IRC | 17:00 | |
morgan_2549 | dolphm: yeah :P | 17:00 |
dolphm | morgan_2549: Workflow+1 | 17:00 |
*** afaranha has joined #openstack-keystone | 17:01 | |
*** afaranha has left #openstack-keystone | 17:01 | |
*** narengan has joined #openstack-keystone | 17:01 | |
*** alex_xu has quit IRC | 17:01 | |
*** tjcocozz has quit IRC | 17:03 | |
*** alex_xu has joined #openstack-keystone | 17:03 | |
morgan_2549 | ayoung: I've got a room at... Sheraton I think. About 1km from the venue | 17:05 |
*** narengan has quit IRC | 17:05 | |
dolphm | is there a trick to uploading rebases to gerrit that don't otherwise affect the rebased change? i don't know how to get around "No changes between prior commit ... and new commit... [remote rejected]" | 17:06 |
ayoung | morgan_2549, sheraton Miyako? | 17:06 |
dolphm | morgan_2549: i'm trying to take those two i18n patches out of the stable/kilo sequence, but can't upload the result ^ | 17:06 |
morgan_2549 | dolphm: uhmmm. It should just work | 17:06 |
*** urulama has quit IRC | 17:06 | |
morgan_2549 | No magic needed if you evict patches | 17:07 |
*** urulama has joined #openstack-keystone | 17:07 | |
dolphm | morgan_2549: http://cdn.pasteraw.com/jvehh4bt33m1pvvau4wnwhvjvvfmdeg | 17:07 |
dolphm | morgan_2549: gerrit does not like | 17:07 |
morgan_2549 | If you just upload the first patch after them based on stable HEAD you can click debase button for the rest? | 17:07 |
morgan_2549 | I can take a look / try when I get to the office. | 17:08 |
dolphm | morgan_2549: oh wait, *facepalm*, i kept those two patches somehow | 17:08 |
ayoung | dolphm, does this sound like an appropriate compromise to you: to keep Fernet tokens small, we will only allow a user to explicitly request a single role for a token if they don't want all roles to be enumerated? So we would have a fernet format that would have an additional field, role_id? | 17:08 |
morgan_2549 | dolphm: hehe | 17:09 |
*** dguerri is now known as dguerri` | 17:09 | |
ayoung | dolphm, I'm thinking explicitly of the case where a user has both admin and member, and needs to do work through a third party type system, so they want as little exposure as possible. | 17:09 |
dolphm | ayoung: what does the number of roles matter? they're in the token body which has no size limit? also, you should already be able to accomplish that by creating and consuming a trust with yourself | 17:11 |
ayoung | dolphm, nah, this would have to be in the signed portion; if "all roles" then you can implicitly get from the query, but if explicitly a subset, it needs to be recorded somehwo | 17:12 |
ayoung | dolphm, and I don't want to have to create a new table | 17:12 |
ayoung | yes, self trust would work | 17:12 |
ayoung | dolphm, I'm trying to not force the creation of trusts if not necessary | 17:12 |
*** roxanaghe has joined #openstack-keystone | 17:14 | |
*** piyanai has quit IRC | 17:14 | |
*** mestery has quit IRC | 17:15 | |
dolphm | ayoung: "have to be in the signed portion" what's the use case? | 17:15 |
ayoung | dolphm, so, think of how you work with a Linux box. even though you own the whole thin, you log in as a limited power user, and only explicitly sudo for admin tasks | 17:16 |
ayoung | same kind of approach: if you are both admin and member, you want to explicitly ask for admin to do that kind of work | 17:16 |
ayoung | dolphm, and, if there are more roles in the future, there might be more fine grained reasons to hand out tokens with fewer roles. | 17:17 |
ayoung | dolphm, the thing is, the roles could be completely server side constructs, like Henrynash was asking for. When you expand the token in validation, you could convert a domain-speicif-role (id) in to the explicit subordniate roles | 17:18 |
dolphm | ayoung: seems kind of pointless when you can just rescope a token for whatever you want, right? | 17:19 |
ayoung | dolphm, so, rescoping can be turned off | 17:19 |
ayoung | we got that merged in Kilo | 17:19 |
*** kfjohnson_ is now known as kfjohnson | 17:21 | |
*** jasonsb has quit IRC | 17:23 | |
*** jasonsb has joined #openstack-keystone | 17:24 | |
*** ankita_wagh has joined #openstack-keystone | 17:24 | |
*** mestery has joined #openstack-keystone | 17:26 | |
*** jasonsb has quit IRC | 17:28 | |
*** lsmola has quit IRC | 17:31 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Build oslo.context RequestContext https://review.openstack.org/213595 | 17:31 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Add user_domain_id, project_domain_id to auth context https://review.openstack.org/213792 | 17:31 |
*** Navid_ has quit IRC | 17:31 | |
*** _cjones_ has joined #openstack-keystone | 17:32 | |
*** therve has left #openstack-keystone | 17:33 | |
*** mestery has quit IRC | 17:34 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Unit tests for is_domain field in project's table https://review.openstack.org/212045 | 17:34 |
*** piyanai has joined #openstack-keystone | 17:34 | |
openstackgerrit | Sean Perry proposed openstack/keystone: Prevent an exception from occurring for invalidly encoded parameters https://review.openstack.org/213796 | 17:41 |
*** piyanai has quit IRC | 17:41 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Add user_domain_id, project_domain_id to auth context https://review.openstack.org/213792 | 17:42 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Build oslo.context RequestContext https://review.openstack.org/213595 | 17:42 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Add unit tests for token_to_auth_context https://review.openstack.org/213797 | 17:42 |
*** piyanai has joined #openstack-keystone | 17:42 | |
openstackgerrit | Sean Perry proposed openstack/keystone: Prevent exception from occurring for invalidly encoded parameters https://review.openstack.org/213796 | 17:44 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Remove unnecessary load_backends from TestKeystoneTokenModel https://review.openstack.org/213801 | 17:47 |
*** afazkas has joined #openstack-keystone | 17:50 | |
*** tjcocozz has joined #openstack-keystone | 17:50 | |
*** browne has joined #openstack-keystone | 17:52 | |
opilotte | https://review.openstack.org/#/c/210581/ | 17:52 |
*** piyanai has quit IRC | 17:53 | |
*** dims_ has joined #openstack-keystone | 17:53 | |
*** urulama has quit IRC | 17:56 | |
*** urulama has joined #openstack-keystone | 17:56 | |
*** dims has quit IRC | 17:57 | |
*** piyanai has joined #openstack-keystone | 17:58 | |
*** piyanai has quit IRC | 17:59 | |
openstackgerrit | Merged openstack/oslo.policy: Have the enforcer have its own file cache https://review.openstack.org/209656 | 17:59 |
*** afazkas has quit IRC | 18:01 | |
*** piyanai has joined #openstack-keystone | 18:01 | |
*** stevemar has quit IRC | 18:08 | |
*** stevemar has joined #openstack-keystone | 18:10 | |
*** ChanServ sets mode: +v stevemar | 18:10 | |
*** jasonsb has joined #openstack-keystone | 18:11 | |
*** Navid_ has joined #openstack-keystone | 18:13 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Manager support for projects acting as domains https://review.openstack.org/213448 | 18:14 |
*** btully has quit IRC | 18:18 | |
*** fangzhou has joined #openstack-keystone | 18:22 | |
*** yottatsa_ has joined #openstack-keystone | 18:23 | |
*** afazkas has joined #openstack-keystone | 18:24 | |
*** yottatsa has quit IRC | 18:24 | |
*** ngupta_ has joined #openstack-keystone | 18:24 | |
*** ankita_w_ has joined #openstack-keystone | 18:25 | |
*** piyanai has quit IRC | 18:27 | |
*** ankita_wagh has quit IRC | 18:27 | |
*** ngupta has quit IRC | 18:27 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Change project name constraints https://review.openstack.org/158372 | 18:28 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Add is_domain parameter to get_project_by_name https://review.openstack.org/210600 | 18:28 |
*** piyanai has joined #openstack-keystone | 18:29 | |
*** afazkas has quit IRC | 18:30 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Limit subtree and parents queries https://review.openstack.org/209132 | 18:30 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Replicate domain info in projects table https://review.openstack.org/211170 | 18:30 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Creating tests for projects acting as domains https://review.openstack.org/211219 | 18:30 |
openstackgerrit | Sean Perry proposed openstack/keystone: Prevent exception from occurring for invalidly encoded parameters https://review.openstack.org/213796 | 18:31 |
morgan_2549 | dolphm: this should be an easy couple +A https://review.openstack.org/#/c/196475/ [starting here[ | 18:36 |
morgan_2549 | needed fernet fixes | 18:36 |
*** ayoung has quit IRC | 18:38 | |
*** narengan has joined #openstack-keystone | 18:40 | |
*** e0ne has joined #openstack-keystone | 18:40 | |
*** yottatsa_ has quit IRC | 18:41 | |
*** d34dh0r53 is now known as VD | 18:42 | |
*** VD is now known as Guest69442 | 18:43 | |
*** Guest69442 is now known as d34dh0r53 | 18:47 | |
*** henrynash has joined #openstack-keystone | 18:49 | |
*** ChanServ sets mode: +v henrynash | 18:49 | |
*** mylu has joined #openstack-keystone | 18:50 | |
*** mylu has quit IRC | 18:51 | |
*** mylu has joined #openstack-keystone | 18:52 | |
*** piyanai has quit IRC | 18:52 | |
openstackgerrit | henry-nash proposed openstack/keystone: Rationalize unfiltered list role assignment test https://review.openstack.org/213820 | 18:56 |
*** mylu has quit IRC | 18:57 | |
*** samueldmq has quit IRC | 18:58 | |
*** e0ne has quit IRC | 19:03 | |
*** topol has quit IRC | 19:04 | |
*** topol has joined #openstack-keystone | 19:05 | |
*** ChanServ sets mode: +v topol | 19:05 | |
*** samueldmq has joined #openstack-keystone | 19:06 | |
*** geoffarnold has quit IRC | 19:07 | |
*** e0ne has joined #openstack-keystone | 19:09 | |
*** topol has quit IRC | 19:09 | |
morgan_2549 | lbragstad: ping | 19:11 |
morgan_2549 | lbragstad: any issues with https://review.openstack.org/#/c/209349/ still? | 19:11 |
*** geoffarnold has joined #openstack-keystone | 19:12 | |
lbragstad | morgan_2549: nope, my one comment was address. looks like mordred had a comment similar to mine around the commit message? | 19:12 |
morgan_2549 | nod. | 19:13 |
lbragstad | " I am curious as to why we want pluggable sessions." | 19:13 |
lbragstad | morgan_2549: I can remove my -1, but maybe a bit of detail in the commit message around the purpose would be helpful (though this is probably pretty nit picky)? | 19:13 |
openstackgerrit | henry-nash proposed openstack/keystone: Add support for data-driven backend assignment testing https://review.openstack.org/149178 | 19:15 |
*** petertr7 is now known as petertr7_away | 19:24 | |
*** Ephur has quit IRC | 19:28 | |
*** petertr7_away is now known as petertr7 | 19:29 | |
*** Ephur has joined #openstack-keystone | 19:40 | |
*** Navid_ has quit IRC | 19:41 | |
*** tjcocozz has quit IRC | 19:42 | |
*** tjcocozz has joined #openstack-keystone | 19:42 | |
*** e0ne has quit IRC | 19:45 | |
*** e0ne has joined #openstack-keystone | 19:48 | |
*** dims_ has quit IRC | 19:48 | |
*** dims has joined #openstack-keystone | 19:48 | |
*** annasort has joined #openstack-keystone | 19:53 | |
*** ayoung has joined #openstack-keystone | 19:53 | |
*** ChanServ sets mode: +v ayoung | 19:53 | |
*** piyanai has joined #openstack-keystone | 19:59 | |
openstackgerrit | Sean Perry proposed openstack/keystone: Prevent exception from occurring for invalidly encoded parameters https://review.openstack.org/213796 | 20:05 |
*** doug-fish has quit IRC | 20:09 | |
*** doug-fish has joined #openstack-keystone | 20:09 | |
*** yottatsa has joined #openstack-keystone | 20:13 | |
*** mylu has joined #openstack-keystone | 20:16 | |
* stevemar just found out that hitting "enter" when you have a file selected in OSX, renames it! | 20:22 | |
* stevemar mind proceeds to blow | 20:22 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Model: Create policy cache table https://review.openstack.org/211679 | 20:24 |
openstackgerrit | Merged openstack/keystoneauth: Add required property to Opt class https://review.openstack.org/213476 | 20:25 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Driver: Provide function to cache policies https://review.openstack.org/212959 | 20:25 |
dstanek | stevemar: yeah, that's given me several "oh, shit" moments in my time with OSX | 20:25 |
*** samueldmq has quit IRC | 20:28 | |
*** mylu has quit IRC | 20:33 | |
*** mylu has joined #openstack-keystone | 20:34 | |
*** mylu_ has joined #openstack-keystone | 20:35 | |
*** jasonsb has quit IRC | 20:35 | |
*** mylu has quit IRC | 20:35 | |
*** jasonsb_ has joined #openstack-keystone | 20:35 | |
*** doug-fish has quit IRC | 20:35 | |
*** doug-fish has joined #openstack-keystone | 20:35 | |
*** ankita_w_ has quit IRC | 20:37 | |
*** ankita_w_ has joined #openstack-keystone | 20:41 | |
*** ajayaa has joined #openstack-keystone | 20:42 | |
*** urulama has quit IRC | 20:42 | |
*** urulama has joined #openstack-keystone | 20:43 | |
*** claudiub has quit IRC | 20:48 | |
*** raildo is now known as raildo-afk | 20:50 | |
openstackgerrit | henry-nash proposed openstack/keystone: Rationalize unfiltered list role assignment test https://review.openstack.org/213820 | 20:51 |
*** mylu_ has quit IRC | 20:52 | |
openstackgerrit | henry-nash proposed openstack/keystone: Add support for data-driven backend assignment testing https://review.openstack.org/149178 | 20:52 |
*** pnavarro has joined #openstack-keystone | 20:53 | |
morgan_2549 | lbragstad: we should just get jaimie to post more to the commit | 20:56 |
morgan_2549 | lbragstad: but the long/short of it is not "pluggable" but "loadable" | 20:56 |
lbragstad | morgan_2549: yeah, that would be helpful | 20:56 |
morgan_2549 | so we can chain them together | 20:56 |
*** ajayaa has quit IRC | 20:56 | |
morgan_2549 | jamielennox: ^ re session loading commit | 20:56 |
morgan_2549 | just needs a better commit/answer to why thisis useful | 20:57 |
morgan_2549 | dolphm, dstanek, stevemar, lbragstad: could one of you run the meeting tomorrow | 20:58 |
morgan_2549 | i should be there but at the ops midcycle thing | 20:58 |
morgan_2549 | so i'd rather not try and chair the meeting | 20:58 |
*** tjcocozz has quit IRC | 20:59 | |
*** claudiub|2 has joined #openstack-keystone | 21:00 | |
*** yottatsa has quit IRC | 21:01 | |
dstanek | morgan_2549: sure | 21:02 |
lbragstad | I get nervous in front of crowds ;) | 21:02 |
*** dave-mccowan has joined #openstack-keystone | 21:06 | |
dave-mccowan | ayoung ping | 21:07 |
morgan_2549 | dstanek: since you're here | 21:08 |
morgan_2549 | https://review.openstack.org/#/c/196475/ | 21:08 |
morgan_2549 | and the one following it | 21:08 |
morgan_2549 | important for the sake of shoring up fernet | 21:09 |
stevemar | morgan_2549: sure, dstanek or i will pick it up | 21:11 |
ayoung | dave-mccowan, one sec | 21:12 |
*** ankita_w_ has quit IRC | 21:12 | |
*** ankita_wagh has joined #openstack-keystone | 21:12 | |
dstanek | morgan_2549: sure, i can hit up those reviews | 21:13 |
stevemar | morgan_2549: should that be backported | 21:14 |
*** mestery has joined #openstack-keystone | 21:15 | |
*** topol has joined #openstack-keystone | 21:16 | |
*** ChanServ sets mode: +v topol | 21:16 | |
*** doug-fish has quit IRC | 21:18 | |
*** mylu has joined #openstack-keystone | 21:20 | |
*** ngupta_ has quit IRC | 21:21 | |
stevemar | dstanek: i approved the first 2 patches in that chain | 21:22 |
dstanek | stevemar: perfect, now i don't even have to look! | 21:22 |
*** mylu has quit IRC | 21:23 | |
dstanek | stevemar: are you looking at the third too? | 21:23 |
stevemar | i looked briefly | 21:23 |
stevemar | same concerns as gyee | 21:23 |
*** pnavarro has quit IRC | 21:23 | |
*** pnavarro has joined #openstack-keystone | 21:36 | |
gyee | stevemar, dstanek, morgan_2549, you mean 196483? | 21:37 |
gyee | I though role_id is in the v2 token data | 21:37 |
gyee | no? | 21:37 |
morgan_2549 | right | 21:37 |
gyee | https://review.openstack.org/#/c/196483/4/keystone/token/providers/common.py | 21:38 |
morgan_2549 | fernet was, i believe erronously removing it | 21:38 |
gyee | ah, gotcha | 21:38 |
ayoung | dave-mccowan, ok...I'm back | 21:39 |
gyee | do we need a bug on this? | 21:39 |
openstackgerrit | henry-nash proposed openstack/keystone: Add support for effective & inherited mode in data driven tests https://review.openstack.org/151623 | 21:39 |
morgan_2549 | *shrug* | 21:39 |
dave-mccowan | ayoung hi adam. i'm working on adding a barbican feature and someone recommended i ask for your advice. we need to add a "super-admin" with certain cross-project permissions. we want to do it in a standard oslo policy way. | 21:39 |
morgan_2549 | it didn't "break" anything until I started changing how this all worked | 21:40 |
morgan_2549 | but fernet didn't pass check/gate as the default | 21:40 |
morgan_2549 | fwiw | 21:40 |
gyee | otherwise, looks good to me! | 21:40 |
ayoung | dave-mccowan, so...give me more context before I jump to too many conclusions. What does this user need to do? | 21:40 |
* morgan_2549 put out the "jump to conclusions" mat for ayoung | 21:40 | |
openstackgerrit | henry-nash proposed openstack/keystone: Add support for group membership to data driven assignment tests https://review.openstack.org/151962 | 21:41 |
* ayoung jumps over the lazy sleeping dog | 21:41 | |
dave-mccowan | ayound here's complete context: https://review.openstack.org/213570 | 21:41 |
dave-mccowan | ayoung i'm guessing using domain id to scope the admin role is the only/best way to go. but want to make sure. | 21:41 |
ayoung | dave-mccowan, looks like you are tracking. Setting quotas is separate use case from managing secrets... | 21:42 |
gyee | ayoung love "super-admin" topic :) | 21:42 |
ayoung | dave-mccowan, service-admin is probably not the right name, though. Barbican is the "secret" service, right? | 21:43 |
dave-mccowan | ayoung yes, Barbican is the key/secret manager. quota support is our first cloud-admin type of api command. | 21:44 |
ayoung | dave-mccowan, so call the role secret-agent | 21:44 |
* redrobot pokes head in | 21:45 | |
ayoung | Or 00 if you are feeling even more obscure | 21:45 |
redrobot | barbican is officially the "key-manager" service in governance | 21:45 |
openstackgerrit | Merged openstack/keystone-specs: Add region_id filter in List Endpoints API https://review.openstack.org/213356 | 21:46 |
dave-mccowan | ayoung :-) | 21:46 |
ayoung | redrobot, that is not nearly as much fun | 21:46 |
ayoung | dave-mccowan, actually, the key-manager role would be a decent name | 21:46 |
redrobot | ayoung agreed :) | 21:46 |
*** narengan has quit IRC | 21:47 | |
ayoung | I like using "manager" in place of admin for things that have limited power | 21:47 |
gyee | morgan_2549, check out the dependency on dolphm's patch https://review.openstack.org/#/c/213216/ | 21:47 |
*** narengan has joined #openstack-keystone | 21:47 | |
morgan_2549 | gyee: yeah | 21:47 |
morgan_2549 | gyee: stable backport | 21:47 |
gyee | wow | 21:47 |
dave-mccowan | ayoung i found this example in a keystone sample file: "cloud_admin": "rule:admin_required and domain_id:admin_domain_id" | 21:48 |
ayoung | dave-mccowan, you need to set the admin_domain_id for that to work. right henrynash ? | 21:48 |
morgan_2549 | gyee: already fixed in master | 21:48 |
*** csoukup_ has quit IRC | 21:49 | |
dave-mccowan | ayoung. i didn't think that just a new role would cover this. i thought i'd need to scope it either with a service project or service domain. | 21:49 |
ayoung | dave-mccowan, yep...you want what everyone wants. THis is why I've been pushing dynamic policy | 21:50 |
ayoung | https://bugs.launchpad.net/keystone/+bug/968696 | 21:50 |
openstack | Launchpad bug 968696 in Cinder ""admin"-ness not properly scoped" [Undecided,In progress] - Assigned to Brent Roskos (broskos) | 21:50 |
*** uvirtbot has quit IRC | 21:50 | |
henrynash | dave-mccowan: yes, that sample is meant to be edited with the id of a domain you have blessed as reprsenting cloud admins | 21:51 |
ayoung | dave-mccowan, https://twitter.com/admiyoung/status/627293342578155520 | 21:51 |
dave-mccowan | so, in real life, it would be a UUID? | 21:51 |
ayoung | henrynash, I have a cool idea for you | 21:51 |
ayoung | dave-mccowan, yes, and it would be deployment specific | 21:51 |
*** narengan has quit IRC | 21:52 | |
ayoung | henrynash, so...private roles...I think are a good thing. | 21:52 |
ayoung | domain scoped roles...which then expand out to specific permission? | 21:52 |
henrynash | ayoung: ok.... | 21:52 |
openstackgerrit | henry-nash proposed openstack/keystone: Broaden domain-group testing of list_role_assignments https://review.openstack.org/154302 | 21:53 |
ayoung | henrynash, what if...we made it such that certain roles get this "private" flag, and, it maps to one or more public roles | 21:53 |
dave-mccowan | i've seen your 968696 presentation at a summit. :-) i don't remember which one. | 21:54 |
ayoung | then...we allow a user to request a token with a specific role, and the token records the private role ID internally (thinking fernet) | 21:54 |
ayoung | http://openstacksummitmay2015vancouver.sched.org/event/14f4c5993e34b0f6a10c810510abbd73#.VdJYFZP-SV4 | 21:54 |
henrynash | ayoung: it records that it is private, not what it maps to, I assume you mean? | 21:55 |
ayoung | henrynash, the id is a shortcut | 21:55 |
ayoung | when you validate, you get the list of public roles | 21:55 |
ayoung | not the private one | 21:56 |
dave-mccowan | ayoung, so it wouldn't be worse than anything else, if i added a new role key-manager and ignore the missing scope. this is just for a default policy file. a customer can adjust the policy to his/her own liking. | 21:56 |
henrynash | ayoung: so validation causes a roudn trip to keystone, but at least our tokens stay small… | 21:56 |
ayoung | dave-mccowan, yes, you will be cargo culting the bad behvaior but we have no better solution for you now | 21:57 |
ayoung | henrynash, exactly | 21:57 |
ayoung | henrynash, it also allow a user a way to specify a subset of roles for a token. And, if roles really mean "policy targets..." | 21:57 |
henrynash | ayoung: so I think that is an interesting middle ground… | 21:58 |
ayoung | henrynash, I could do "subset of roles in a token" with uuid or PKI tokens without it, but not fernet. | 21:59 |
henrynash | ayoung: understand…. | 22:00 |
henrynash | ayoung: the other thing that might fall into this is the need for some kind of grouping that is “part of assignment” but different to users/grops (since the later are usually RO for keystone admins) | 22:00 |
*** petertr7 is now known as petertr7_away | 22:01 | |
*** mestery has quit IRC | 22:01 | |
ayoung | henrynash, yeah....although, it might be possible to specify that a certain domain can get userids from outside. idmapping table would make that work, too | 22:01 |
dave-mccowan | ayoung henrynash thanks for the discussion. just what i needed. if you have a minute, please chime in on the CR I linked above. | 22:01 |
henrynash | ayoung: true, you can use idmapping for that.... | 22:02 |
ayoung | henrynash, considering that groups need to be actually written in the keystone backend for federation, I guess that they would just be more mapping rules...but mappings are so painful to manage, we really need that tool that dave chadwick is pushing to make it palatable. | 22:03 |
*** mestery has joined #openstack-keystone | 22:04 | |
henrynash | ayoung: agreed….I do think we are getting to the point where we need to consider whether teh solution to some problems may not be a new API, but better tooling using the existing APIs | 22:04 |
*** hrou has quit IRC | 22:05 | |
ayoung | henrynash, what if we make every policy target into a role, and then policy enforcement is "you must have this role" | 22:05 |
ayoung | we could implement that in olso-policy as a global config option or something | 22:06 |
*** shoutm has joined #openstack-keystone | 22:06 | |
*** pnavarro has quit IRC | 22:07 | |
ayoung | but....we can't do that today. The number of roles returned for _member_ would be too big | 22:07 |
henrynash | ayoung: that was the “in the limit” scenario I was pushing a while back….bascially each service would register its targets with keystone (which become the capabilities or base roles)….then role-groups (at least that’s what I called them) would be used to collect usefull buckets of those togetehr | 22:07 |
openstackgerrit | Haneef Ali proposed openstack/keystone: Return correct URL in /v3 version response https://review.openstack.org/213379 | 22:07 |
ayoung | henrynash, I am so with you on that | 22:07 |
ayoung | we could do the role expansion as a cached query as opposed to dynamically generating the policy file | 22:08 |
openstackgerrit | Haneef Ali proposed openstack/keystone: Return correct URL in /v3 version response https://review.openstack.org/213379 | 22:08 |
*** mestery has quit IRC | 22:09 | |
henrynash | ayoung: yes, agreed | 22:09 |
*** ngupta has joined #openstack-keystone | 22:09 | |
openstackgerrit | henry-nash proposed openstack/keystone: Test list_role_assignment in standard inheritance tests https://review.openstack.org/153897 | 22:10 |
*** HT_sergio has quit IRC | 22:10 | |
*** ngupta has quit IRC | 22:11 | |
*** ngupta has joined #openstack-keystone | 22:12 | |
openstackgerrit | henry-nash proposed openstack/keystone: Support project hierarchies in data driver tests https://review.openstack.org/154485 | 22:13 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/213893 | 22:16 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystonemiddleware: Updated from global requirements https://review.openstack.org/213894 | 22:16 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements https://review.openstack.org/213898 | 22:19 |
gyee | morgan_2549, I thought we don't backport tests? https://review.openstack.org/#/c/212944/ | 22:20 |
gyee | unless this is needed somewhere in the chain | 22:20 |
gyee | I haven't look through the entire chain yet | 22:21 |
openstackgerrit | Sean Perry proposed openstack/keystone: Prevent exception from occurring for invalidly encoded parameters https://review.openstack.org/213796 | 22:22 |
openstackgerrit | Sean Perry proposed openstack/keystone: Prevent exception for invalidly encoded parameters https://review.openstack.org/213796 | 22:24 |
*** dims_ has joined #openstack-keystone | 22:25 | |
*** edmondsw has quit IRC | 22:26 | |
dolphm | gyee: we have backported new tests, certainly. we usually don't backport refactors though. in this case, there's several test refactors in that sequence that would make it really hard to land the later patches that utilize those revised test structures | 22:26 |
dolphm | gyee: and i wouldn't want to backport those changes without their tests | 22:27 |
*** dims has quit IRC | 22:28 | |
openstackgerrit | henry-nash proposed openstack/keystone: Remove manager-driver assignment metadata construct https://review.openstack.org/148995 | 22:29 |
*** gordc has quit IRC | 22:30 | |
*** shoutm has quit IRC | 22:32 | |
*** chlong has quit IRC | 22:34 | |
*** shoutm has joined #openstack-keystone | 22:36 | |
*** claudiub|2 has quit IRC | 22:39 | |
*** e0ne has quit IRC | 22:41 | |
gyee | dolphm, k, make sense, just want to make sure | 22:43 |
*** Navid_ has joined #openstack-keystone | 22:43 | |
*** dims_ has quit IRC | 22:47 | |
*** Ephur has quit IRC | 22:47 | |
*** dims has joined #openstack-keystone | 22:47 | |
*** markvoelker has quit IRC | 22:51 | |
*** dims has quit IRC | 22:51 | |
*** hrou has joined #openstack-keystone | 23:07 | |
*** mestery has joined #openstack-keystone | 23:13 | |
*** piyanai has quit IRC | 23:15 | |
*** ngupta has quit IRC | 23:18 | |
*** tiny-hands has joined #openstack-keystone | 23:18 | |
*** Navid_ has quit IRC | 23:20 | |
*** zzzeek has quit IRC | 23:28 | |
*** ngupta has joined #openstack-keystone | 23:30 | |
*** ankita_w_ has joined #openstack-keystone | 23:33 | |
*** markvoelker has joined #openstack-keystone | 23:35 | |
*** ankita_wagh has quit IRC | 23:36 | |
*** topol has quit IRC | 23:44 | |
*** phalmos has quit IRC | 23:47 | |
*** mestery has quit IRC | 23:55 | |
*** Ctina_ has joined #openstack-keystone | 23:56 | |
*** ctina has joined #openstack-keystone | 23:56 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!