*** dims has quit IRC | 00:03 | |
jamielennox | morgan: i'm looking through keystoneauth for any last minute changes | 00:04 |
---|---|---|
jamielennox | i'm not sure we should include mordred's https://github.com/openstack/keystoneauth/blob/master/keystoneauth1/loading/base.py#L88 in a 1.0 vs having it in OCC for now | 00:05 |
jamielennox | eg https://github.com/openstack/keystoneauth/blob/master/keystoneauth1/loading/base.py#L109 'auth_type' is an OSC thing | 00:06 |
*** jasonsb has joined #openstack-keystone | 00:09 | |
*** ankita_wagh has joined #openstack-keystone | 00:11 | |
*** shadower has quit IRC | 00:23 | |
*** gyee has quit IRC | 00:23 | |
*** shadower has joined #openstack-keystone | 00:23 | |
*** wwwjfy has joined #openstack-keystone | 00:25 | |
*** vivekd has joined #openstack-keystone | 00:28 | |
*** hrou has joined #openstack-keystone | 00:31 | |
morgan | jamielennox: nod | 00:42 |
jamielennox | morgan: just looking at a patch that does the required value checking and i can discuss with mordred later how to do that | 00:42 |
morgan | ok | 00:43 |
jamielennox | but i don't think at the moment that OCC should be in the business of validating those requirements | 00:43 |
*** geoffarnold has quit IRC | 00:46 | |
*** geoffarnold has joined #openstack-keystone | 00:49 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Better isolate loading tests https://review.openstack.org/219081 | 00:59 |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Change option requirement testing https://review.openstack.org/219082 | 00:59 |
jamielennox | morgan, mordred: ^ | 00:59 |
* morgan looks | 00:59 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 01:00 | |
*** chlong has joined #openstack-keystone | 01:02 | |
*** vivekd_ has joined #openstack-keystone | 01:03 | |
*** vivekd has quit IRC | 01:04 | |
*** vivekd_ is now known as vivekd | 01:04 | |
*** dave-mccowan has quit IRC | 01:04 | |
*** samleon has quit IRC | 01:06 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: get_available_loaders should return loader object https://review.openstack.org/219086 | 01:12 |
*** btully has joined #openstack-keystone | 01:19 | |
*** dims has joined #openstack-keystone | 01:20 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Remove deprecated options from identity base plugin https://review.openstack.org/219087 | 01:22 |
*** mylu has joined #openstack-keystone | 01:24 | |
*** roxanaghe has quit IRC | 01:25 | |
*** wwwjfy has quit IRC | 01:31 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Provide has_scope_parameters function on plugins https://review.openstack.org/219089 | 01:31 |
*** topol has joined #openstack-keystone | 01:41 | |
*** ChanServ sets mode: +v topol | 01:41 | |
*** vivekd has quit IRC | 01:42 | |
*** vivekd has joined #openstack-keystone | 01:44 | |
*** geoffarnold is now known as geoffarnoldX | 01:46 | |
*** fangzhou_ has joined #openstack-keystone | 01:47 | |
*** fangzhou has quit IRC | 01:48 | |
*** fangzhou_ is now known as fangzhou | 01:48 | |
*** ankita_wagh has quit IRC | 01:50 | |
*** stevemar has joined #openstack-keystone | 01:50 | |
*** ChanServ sets mode: +v stevemar | 01:50 | |
*** stevemar has quit IRC | 01:55 | |
*** spandhe has quit IRC | 01:58 | |
*** mylu has quit IRC | 01:59 | |
openstackgerrit | Dave Chen proposed openstack/keystone: Refactor: Don't hard code the error code https://review.openstack.org/198623 | 02:00 |
*** davechen has joined #openstack-keystone | 02:01 | |
*** zzzeek has quit IRC | 02:04 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Raise error if loader is provided name without id https://review.openstack.org/219094 | 02:08 |
*** woodster_ has quit IRC | 02:19 | |
*** geoffarnoldX is now known as geoffarnold | 02:20 | |
*** bknudson has quit IRC | 02:24 | |
*** wwwjfy has joined #openstack-keystone | 02:34 | |
*** ankita_wagh has joined #openstack-keystone | 02:46 | |
*** hakimo has joined #openstack-keystone | 02:52 | |
*** hakimo_ has quit IRC | 02:54 | |
*** csoukup has joined #openstack-keystone | 03:04 | |
*** csoukup has quit IRC | 03:04 | |
*** csoukup has joined #openstack-keystone | 03:05 | |
*** lhcheng has quit IRC | 03:05 | |
*** annasort has quit IRC | 03:09 | |
*** diazjf has joined #openstack-keystone | 03:12 | |
*** chlong has quit IRC | 03:12 | |
*** Nirupama has joined #openstack-keystone | 03:14 | |
*** davechen1 has joined #openstack-keystone | 03:20 | |
*** davechen has quit IRC | 03:23 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Auth-url is required for identity plugins https://review.openstack.org/219111 | 03:24 |
openstackgerrit | Merged openstack/keystone: Unit tests for is_domain field in project's table https://review.openstack.org/212045 | 03:24 |
*** darrenc is now known as darrenc_afk | 03:28 | |
*** annasort has joined #openstack-keystone | 03:31 | |
*** lhcheng has joined #openstack-keystone | 03:31 | |
*** ChanServ sets mode: +v lhcheng | 03:31 | |
*** davechen has joined #openstack-keystone | 03:33 | |
*** fangzhou has quit IRC | 03:34 | |
*** davechen1 has quit IRC | 03:36 | |
*** chlong has joined #openstack-keystone | 03:38 | |
*** vivekd has quit IRC | 03:44 | |
*** links has joined #openstack-keystone | 03:46 | |
*** sigmavirus24 has quit IRC | 03:48 | |
*** sigmavirus24 has joined #openstack-keystone | 03:50 | |
*** lhcheng_ has joined #openstack-keystone | 03:51 | |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Disable memory caching of tokens https://review.openstack.org/212345 | 03:53 |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Seperate standalone cache tests https://review.openstack.org/212344 | 03:53 |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Handle memcache pool arguments collectively https://review.openstack.org/212341 | 03:53 |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Import _memcache_pool normally https://review.openstack.org/212343 | 03:53 |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Create Environment cache pool https://review.openstack.org/212342 | 03:53 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Manager support for projects acting as domains https://review.openstack.org/213448 | 03:53 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Add is_domain parameter to get_project_by_name https://review.openstack.org/210600 | 03:53 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Change project name constraints https://review.openstack.org/158372 | 03:53 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Replicate domain info in projects table https://review.openstack.org/211170 | 03:53 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Tests for projects acting as domains https://review.openstack.org/211219 | 03:53 |
*** lhcheng has quit IRC | 03:54 | |
*** stevemar has joined #openstack-keystone | 03:56 | |
*** ChanServ sets mode: +v stevemar | 03:56 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Auth-url is required for identity plugins https://review.openstack.org/219111 | 03:57 |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Raise error if loader is provided name without id https://review.openstack.org/219094 | 03:59 |
*** sigmavirus24 is now known as sigmavirus24_awa | 03:59 | |
*** markvoelker has joined #openstack-keystone | 04:00 | |
*** markvoelker_ has joined #openstack-keystone | 04:02 | |
*** chlong_ has joined #openstack-keystone | 04:04 | |
*** chlong has quit IRC | 04:04 | |
*** markvoelker has quit IRC | 04:04 | |
*** btully has quit IRC | 04:05 | |
*** geoffarnold is now known as geoffarnoldX | 04:07 | |
*** Ephur has quit IRC | 04:07 | |
*** geoffarnoldX is now known as geoffarnold | 04:23 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/214509 | 04:24 |
*** ayoung has quit IRC | 04:29 | |
*** dims has quit IRC | 04:30 | |
*** csoukup has quit IRC | 04:41 | |
*** shaleh_ has quit IRC | 04:44 | |
*** darrenc_afk is now known as darrenc | 04:54 | |
*** topol has quit IRC | 05:00 | |
*** vivekd has joined #openstack-keystone | 05:05 | |
*** geoffarnold has quit IRC | 05:11 | |
*** geoffarnold has joined #openstack-keystone | 05:11 | |
*** wwwjfy has quit IRC | 05:17 | |
*** spandhe_ has joined #openstack-keystone | 05:19 | |
*** stevemar has quit IRC | 05:20 | |
*** henrynash has joined #openstack-keystone | 05:22 | |
*** ChanServ sets mode: +v henrynash | 05:22 | |
openstackgerrit | Merged openstack/keystone: Group tox optional dependencies https://review.openstack.org/218693 | 05:29 |
*** stevemar has joined #openstack-keystone | 05:33 | |
*** ChanServ sets mode: +v stevemar | 05:33 | |
*** wwwjfy has joined #openstack-keystone | 05:36 | |
*** stevemar has quit IRC | 05:38 | |
*** geoffarnold is now known as geoffarnoldX | 05:51 | |
*** markvoelker_ has quit IRC | 05:53 | |
*** dims has joined #openstack-keystone | 05:59 | |
*** ankita_wagh has quit IRC | 06:02 | |
*** spandhe_ has quit IRC | 06:02 | |
*** dims has quit IRC | 06:04 | |
*** spandhe has joined #openstack-keystone | 06:05 | |
*** roxanaghe has joined #openstack-keystone | 06:06 | |
*** ankita_wagh has joined #openstack-keystone | 06:08 | |
*** roxanaghe has quit IRC | 06:10 | |
*** roxanaghe has joined #openstack-keystone | 06:11 | |
*** lhcheng has joined #openstack-keystone | 06:14 | |
*** ChanServ sets mode: +v lhcheng | 06:14 | |
*** btully has joined #openstack-keystone | 06:17 | |
*** shoutm has quit IRC | 06:17 | |
*** lhcheng_ has quit IRC | 06:17 | |
*** dikonoor has joined #openstack-keystone | 06:21 | |
*** ParsectiX has joined #openstack-keystone | 06:22 | |
*** dikonoo has joined #openstack-keystone | 06:22 | |
*** roxanaghe has quit IRC | 06:23 | |
*** lhcheng has quit IRC | 06:33 | |
*** lhcheng has joined #openstack-keystone | 06:34 | |
*** ChanServ sets mode: +v lhcheng | 06:34 | |
openstackgerrit | henry-nash proposed openstack/keystone: Add support for data-driven backend assignment testing https://review.openstack.org/149178 | 06:34 |
openstackgerrit | henry-nash proposed openstack/keystone: Add support for effective & inherited mode in data driven tests https://review.openstack.org/151623 | 06:35 |
*** topol has joined #openstack-keystone | 06:35 | |
*** ChanServ sets mode: +v topol | 06:35 | |
*** afazekas__ has joined #openstack-keystone | 06:36 | |
*** lhcheng has quit IRC | 06:38 | |
*** ankita_wagh has quit IRC | 06:39 | |
*** topol has quit IRC | 06:40 | |
*** kiran-r has joined #openstack-keystone | 06:43 | |
openstackgerrit | henry-nash proposed openstack/keystone: Add support for group membership to data driven assignment tests https://review.openstack.org/151962 | 06:43 |
openstackgerrit | henry-nash proposed openstack/keystone: Broaden domain-group testing of list_role_assignments https://review.openstack.org/154302 | 06:44 |
openstackgerrit | henry-nash proposed openstack/keystone: Test list_role_assignment in standard inheritance tests https://review.openstack.org/153897 | 06:44 |
*** fangzhou has joined #openstack-keystone | 06:45 | |
*** dikonoo has quit IRC | 06:48 | |
*** spandhe has quit IRC | 06:50 | |
*** josecastroleon has quit IRC | 06:50 | |
*** kiran-r has quit IRC | 06:53 | |
*** hrou has quit IRC | 06:54 | |
*** fhubik has joined #openstack-keystone | 07:08 | |
openstackgerrit | Dave Chen proposed openstack/keystonemiddleware: Fix the outdated options https://review.openstack.org/219162 | 07:09 |
openstackgerrit | Dave Chen proposed openstack/keystonemiddleware: Fix the outdated options https://review.openstack.org/219162 | 07:10 |
*** diazjf has quit IRC | 07:11 | |
*** sirushti has quit IRC | 07:15 | |
*** pnavarro has joined #openstack-keystone | 07:18 | |
*** kodoku has joined #openstack-keystone | 07:23 | |
*** shoutm has joined #openstack-keystone | 07:24 | |
*** chlong_ has quit IRC | 07:24 | |
*** henrynash has quit IRC | 07:25 | |
kodoku | Hi, someone can help me ? I don't understand why keystone DELETE my token and causes neutron error ====> http://paste.openstack.org/show/437002/ | 07:25 |
kodoku | maybe because neutron use keystone v3 ? | 07:27 |
*** kiran-r has joined #openstack-keystone | 07:38 | |
*** henrynash has joined #openstack-keystone | 07:43 | |
*** ChanServ sets mode: +v henrynash | 07:43 | |
*** vivekd has quit IRC | 07:46 | |
*** henrynash has quit IRC | 07:50 | |
*** katkapilatova has joined #openstack-keystone | 07:52 | |
*** kodoku has quit IRC | 07:58 | |
*** jistr has joined #openstack-keystone | 08:08 | |
*** fhubik has quit IRC | 08:13 | |
*** fhubik has joined #openstack-keystone | 08:13 | |
*** e0ne has joined #openstack-keystone | 08:13 | |
openstackgerrit | Christian Berendt proposed openstack/keystone: Log the user id when using an invalid username or password https://review.openstack.org/128860 | 08:14 |
*** lhcheng has joined #openstack-keystone | 08:22 | |
*** ChanServ sets mode: +v lhcheng | 08:22 | |
openstackgerrit | Dave Chen proposed openstack/keystonemiddleware: Fix the outdated options https://review.openstack.org/219162 | 08:25 |
openstackgerrit | Dave Chen proposed openstack/keystonemiddleware: Fix the outdated options https://review.openstack.org/219162 | 08:26 |
*** lhcheng has quit IRC | 08:27 | |
*** lars1 has quit IRC | 08:31 | |
*** sirushti has joined #openstack-keystone | 08:32 | |
*** e0ne has quit IRC | 08:36 | |
*** dims has joined #openstack-keystone | 08:42 | |
*** e0ne has joined #openstack-keystone | 08:48 | |
*** dims has quit IRC | 08:48 | |
*** aix has quit IRC | 08:50 | |
*** kiran-r has quit IRC | 08:57 | |
*** lars1 has joined #openstack-keystone | 08:59 | |
*** boris-42 has quit IRC | 09:00 | |
*** jaosorior has joined #openstack-keystone | 09:00 | |
*** marzif has joined #openstack-keystone | 09:01 | |
*** kiran-r has joined #openstack-keystone | 09:04 | |
*** marzif has quit IRC | 09:04 | |
*** marzif has joined #openstack-keystone | 09:05 | |
*** sirushti has quit IRC | 09:08 | |
*** sirushti has joined #openstack-keystone | 09:11 | |
*** aix has joined #openstack-keystone | 09:19 | |
*** fhubik has quit IRC | 09:19 | |
*** fhubik has joined #openstack-keystone | 09:28 | |
*** katkapilatova has left #openstack-keystone | 09:32 | |
*** dims has joined #openstack-keystone | 09:36 | |
*** dims has quit IRC | 09:41 | |
*** davechen has left #openstack-keystone | 09:54 | |
*** aix has quit IRC | 10:05 | |
*** aix has joined #openstack-keystone | 10:05 | |
*** dave-mccowan has joined #openstack-keystone | 10:06 | |
*** lhcheng has joined #openstack-keystone | 10:11 | |
*** ChanServ sets mode: +v lhcheng | 10:11 | |
*** lhcheng has quit IRC | 10:16 | |
*** marzif has quit IRC | 10:24 | |
*** btully has quit IRC | 10:29 | |
*** fhubik is now known as fhubik_brb | 10:30 | |
*** dims has joined #openstack-keystone | 10:30 | |
*** lhcheng has joined #openstack-keystone | 10:35 | |
*** ChanServ sets mode: +v lhcheng | 10:35 | |
*** dims has quit IRC | 10:36 | |
*** fhubik_brb has quit IRC | 10:40 | |
*** lhcheng has quit IRC | 10:40 | |
*** h00327910__ has quit IRC | 10:43 | |
*** topol has joined #openstack-keystone | 10:44 | |
*** ChanServ sets mode: +v topol | 10:44 | |
*** marzif has joined #openstack-keystone | 10:44 | |
*** pnavarro is now known as pnavarro|lunch | 10:50 | |
*** ParsectiX has quit IRC | 10:53 | |
*** wwwjfy has quit IRC | 11:00 | |
*** marzif has quit IRC | 11:02 | |
*** btully has joined #openstack-keystone | 11:07 | |
*** btully has quit IRC | 11:12 | |
*** claudiub has joined #openstack-keystone | 11:14 | |
*** ParsectiX has joined #openstack-keystone | 11:17 | |
*** shoutm has quit IRC | 11:19 | |
*** dims has joined #openstack-keystone | 11:25 | |
*** dims has quit IRC | 11:29 | |
*** fhubik has joined #openstack-keystone | 11:33 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Materialized path mixin for hierarchical models https://review.openstack.org/198418 | 11:34 |
*** exploreshaifali has joined #openstack-keystone | 11:35 | |
*** gordc has joined #openstack-keystone | 11:36 | |
*** ParsectiX has quit IRC | 11:41 | |
*** hrou has joined #openstack-keystone | 11:44 | |
*** e0ne has quit IRC | 11:46 | |
*** diegows has joined #openstack-keystone | 11:59 | |
*** eandersson has joined #openstack-keystone | 11:59 | |
*** Nirupama has quit IRC | 11:59 | |
*** wwwjfy has joined #openstack-keystone | 12:02 | |
*** ParsectiX has joined #openstack-keystone | 12:03 | |
*** petertr7_away is now known as petertr7 | 12:06 | |
*** chlong_ has joined #openstack-keystone | 12:09 | |
*** nicodemos has joined #openstack-keystone | 12:15 | |
*** e0ne has joined #openstack-keystone | 12:18 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Honor domain operations in project table https://review.openstack.org/143763 | 12:26 |
openstackgerrit | Henrique Truta proposed openstack/keystone: List projects filtering by is_domain flag https://review.openstack.org/158398 | 12:27 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Restricting domain_id update https://review.openstack.org/207218 | 12:27 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Limit subtree and parents queries https://review.openstack.org/209132 | 12:27 |
*** Ephur has joined #openstack-keystone | 12:28 | |
*** dims has joined #openstack-keystone | 12:33 | |
*** pnavarro|lunch is now known as pnavarro | 12:33 | |
*** Ephur has quit IRC | 12:34 | |
*** woodster_ has joined #openstack-keystone | 12:36 | |
*** fhubik has quit IRC | 12:39 | |
*** raildo is now known as raildo-afk | 12:40 | |
*** Ephur has joined #openstack-keystone | 12:41 | |
*** thiagop has joined #openstack-keystone | 12:50 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 12:51 | |
*** diegows has quit IRC | 12:52 | |
*** ninag has joined #openstack-keystone | 12:53 | |
*** zzzeek has joined #openstack-keystone | 12:57 | |
*** fhubik has joined #openstack-keystone | 12:58 | |
*** richm has joined #openstack-keystone | 13:05 | |
*** gordc has quit IRC | 13:09 | |
*** topol has quit IRC | 13:19 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 13:24 | |
*** geoffarnoldX is now known as geoffarnold | 13:29 | |
*** petertr7 is now known as petertr7_away | 13:31 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Fix grammar in doc string https://review.openstack.org/219277 | 13:33 |
*** petertr7_away is now known as petertr7 | 13:37 | |
*** fhubik is now known as fhubik_brb | 13:38 | |
mordred | jamielennox: looking | 13:38 |
*** rbak has joined #openstack-keystone | 13:39 | |
*** ayoung has joined #openstack-keystone | 13:39 | |
*** ChanServ sets mode: +v ayoung | 13:39 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 13:39 | |
*** kiran-r has quit IRC | 13:40 | |
*** kiran-r has joined #openstack-keystone | 13:41 | |
mordred | jamielennox, morgan: (or anyone else) - any chance people konw off the top of their head if all the clients support "interface" instead of "endpoint_type" yet? | 13:41 |
*** kiran-r has quit IRC | 13:41 | |
*** fhubik_brb is now known as fhubik | 13:42 | |
*** jsavak has joined #openstack-keystone | 13:45 | |
*** raildo has joined #openstack-keystone | 13:46 | |
*** edmondsw has joined #openstack-keystone | 13:47 | |
*** gordc has joined #openstack-keystone | 13:52 | |
*** petertr7 is now known as petertr7_away | 13:59 | |
*** mpmsimo has joined #openstack-keystone | 14:00 | |
*** Kennan has joined #openstack-keystone | 14:03 | |
*** Kennan2 has quit IRC | 14:03 | |
*** pnavarro is now known as pnavarro|afk | 14:05 | |
*** phalmos has joined #openstack-keystone | 14:07 | |
*** dave-mccowan has quit IRC | 14:13 | |
*** exploreshaifali has quit IRC | 14:13 | |
*** ParsectiX has quit IRC | 14:13 | |
*** geoffarnold has quit IRC | 14:14 | |
*** wwwjfy has quit IRC | 14:16 | |
*** links has quit IRC | 14:23 | |
*** alejandrito has joined #openstack-keystone | 14:26 | |
*** dave-mccowan has joined #openstack-keystone | 14:28 | |
*** petertr7_away is now known as petertr7 | 14:29 | |
*** wwwjfy has joined #openstack-keystone | 14:32 | |
*** hrou has quit IRC | 14:34 | |
*** diazjf has joined #openstack-keystone | 14:35 | |
*** afazekas__ has quit IRC | 14:41 | |
*** boris-42 has joined #openstack-keystone | 14:42 | |
*** ninag has quit IRC | 14:43 | |
*** ninag has joined #openstack-keystone | 14:43 | |
*** topol has joined #openstack-keystone | 14:45 | |
*** ChanServ sets mode: +v topol | 14:45 | |
*** ninag has quit IRC | 14:48 | |
*** shoutm has joined #openstack-keystone | 14:49 | |
*** phalmos has quit IRC | 14:49 | |
*** dave-mccowan has quit IRC | 14:51 | |
*** csoukup has joined #openstack-keystone | 14:52 | |
*** geoffarnold has joined #openstack-keystone | 14:53 | |
*** phalmos has joined #openstack-keystone | 14:55 | |
*** tonytan4ever has joined #openstack-keystone | 14:56 | |
*** afaranha has joined #openstack-keystone | 14:56 | |
*** afaranha has left #openstack-keystone | 14:56 | |
*** diazjf has quit IRC | 14:57 | |
*** links has joined #openstack-keystone | 14:57 | |
*** dave-mccowan has joined #openstack-keystone | 14:58 | |
*** jistr is now known as jistr|call | 14:58 | |
*** bknudson has joined #openstack-keystone | 14:59 | |
*** ChanServ sets mode: +v bknudson | 14:59 | |
*** daemontool_ has quit IRC | 15:01 | |
*** fhubik is now known as fhubik_brb | 15:01 | |
*** ninag has joined #openstack-keystone | 15:03 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Unified delegation model https://review.openstack.org/208488 | 15:08 |
*** shoutm has quit IRC | 15:10 | |
*** sdake has joined #openstack-keystone | 15:11 | |
sdake | hey quick question folks | 15:11 |
ayoung | fire way | 15:11 |
sdake | we have 3 keystone services running in active/active/active | 15:11 |
*** shardy has joined #openstack-keystone | 15:12 | |
sdake | we get a token from the first kyestone serice, and then try to use it on the 2nd keystone service | 15:12 |
sdake | we get a rbac error about the key not being found | 15:12 |
*** vivekd has joined #openstack-keystone | 15:12 | |
*** diazjf has joined #openstack-keystone | 15:12 | |
sdake | becaue the first node didn't save it to the database prior to us reading it on the 2nd node | 15:12 |
sdake | is there some flush option? | 15:12 |
sdake | the obvious "flush" keyword doesn't turn anything up | 15:12 |
sdake | database setion doesn't have anything on synchronous writes | 15:12 |
sdake | any pointers ayoung? | 15:14 |
ayoung | sdake, what kind of tokens? | 15:14 |
sdake | we tried turning caching off | 15:14 |
sdake | sec | 15:14 |
*** SamYaple has joined #openstack-keystone | 15:14 | |
SamYaple | \o | 15:14 |
sdake | samyaple ayoung asked whicih type of tokens we are using to which i dont knwo the answer | 15:15 |
SamYaple | uuid | 15:15 |
*** petertr7 is now known as petertr7_away | 15:15 | |
ayoung | sdake, I'm going to assume PKI, actually, since you said Key | 15:15 |
ayoung | there are no keys in uuid... | 15:15 |
SamYaple | ayoung: its uuid | 15:15 |
SamYaple | dont worry about key | 15:16 |
sdake | apparently we are using uuids :) | 15:16 |
*** ninag has quit IRC | 15:16 | |
ayoung | with UUID, you need a common database backend | 15:16 |
sdake | ayoung this is for kolla | 15:16 |
SamYaple | yea we are using mysql | 15:16 |
ayoung | the uuids are pointers to recorfs in the database. | 15:16 |
*** ninag has joined #openstack-keystone | 15:16 | |
*** links has quit IRC | 15:16 | |
ayoung | Gallera and replication is the usual solution there | 15:16 |
ayoung | PKI tokens don't have that issue, but have others | 15:17 |
sdake | we have galera in master/slave/slave mode | 15:17 |
ayoung | Fernet tokens are coming up as a replacement, but are still considered experimental | 15:17 |
*** dims has quit IRC | 15:17 | |
SamYaple | i like fernet tokens. they work well for me | 15:17 |
ayoung | although mfisch has them in production | 15:17 |
SamYaple | but this is uuid | 15:17 |
sdake | so the problem is ayougn we have uuid tokens and are using a commond b back | 15:17 |
sdake | backend | 15:17 |
sdake | but the toens are not being flushed on each token creation | 15:17 |
ayoung | sounds like the sync iof the token table is not set up properly, then | 15:18 |
mfisch | what do you mean flushed? | 15:18 |
ayoung | mfisch, I think he means synced | 15:18 |
mfisch | ok | 15:18 |
ayoung | mfisch, not the token flush, as that is cleanup | 15:18 |
mfisch | that makes way more sense | 15:18 |
sdake | mfisch i mean if i get a token from keystone 1, and use it in keystone 2, keystone 2 doesn't see it | 15:18 |
mfisch | thats a pure galera issue | 15:18 |
mfisch | you need to have all reads and writes going to 1 box or enable wsrep_causal_reads | 15:19 |
mfisch | which kills perf | 15:19 |
SamYaple | its syncing tokens, give me wone moment ill try to explain the problem as i see it | 15:19 |
SamYaple | we do have all to one box | 15:19 |
sdake | we have all reads and writes going to 1 box | 15:19 |
SamYaple | the cluster is active/active but haproxy only sends to one box | 15:19 |
mfisch | if you shutdown keystone2, do you have any issues? | 15:19 |
mfisch | service keystone stop | 15:19 |
sdake | we are running in containers ;) | 15:20 |
sdake | for kolla, deploying openstack in containers using ansible | 15:20 |
mfisch | docker whatever stop kill keystone | 15:20 |
mfisch | if you have 1 container does it work? | 15:20 |
sdake | yes that would work because the second keystone wouldn't be accessed | 15:20 |
sdake | we have forced access to one keystone service | 15:20 |
sdake | that does work | 15:20 |
SamYaple | im not convinced this is a keystone issue but something auth wierd is going on, building a pastebin | 15:21 |
*** ninag has quit IRC | 15:21 | |
mfisch | I'm sure this is a galera issue | 15:21 |
mfisch | your 2nd keystone node is talking to a different box | 15:21 |
sdake | 2nd keystone definately talkign to the same box | 15:21 |
mfisch | try to get a token on one and validate on another and sleep 3 seconds in between | 15:21 |
sdake | all traffic is forced to one active galera service continually | 15:23 |
*** jasonsb has quit IRC | 15:23 | |
mfisch | you've checked keystone.conf there? | 15:23 |
sdake | otherwise the databae locks up in neutron and nova | 15:23 |
sdake | we route to a vip | 15:23 |
sdake | the vip routes to haproy | 15:23 |
*** jasonsb has joined #openstack-keystone | 15:23 | |
sdake | haproxy connects to thespecific galera service because it is speified as master | 15:23 |
sdake | the other two are backups | 15:23 |
SamYaple | mfisch: ill satisfy your question by using a single mysql node | 15:23 |
sdake | therefore the other two never hit round robyn | 15:23 |
mfisch | yes please | 15:23 |
sdake | sounds good samyaple | 15:24 |
SamYaple | ill kill hte other two and bring the cluster to 1 | 15:24 |
mfisch | otherwise you've found a pretty amazing keystone bug that nobody else has found | 15:24 |
SamYaple | i dont think its that for the record | 15:24 |
SamYaple | but im a bit stumped as well | 15:24 |
SamYaple | this same stuff works for me just fine | 15:24 |
*** ninag has joined #openstack-keystone | 15:24 | |
sdake | oh ya, so this works on some peoples hardware and not on mine ;) | 15:24 |
*** fhubik_brb is now known as fhubik | 15:24 | |
sdake | mfisch as soon as keystone creates the token, its synced it with the database | 15:25 |
sdake | ? | 15:25 |
ayoung | sdake, you lie | 15:25 |
mfisch | uuid? yes | 15:25 |
*** ninag has quit IRC | 15:25 | |
ayoung | it is supposed to, but you have messed up a configuration somewhere which means it don't | 15:26 |
*** ninag has joined #openstack-keystone | 15:26 | |
sdake | i agree our config is dmanaged in some way - we are tyring to figure out which option we need to make er work ;) | 15:26 |
ayoung | sdake, make sure all three Keystone servers are pointing at the same database to start with | 15:27 |
openstackgerrit | Merged openstack/keystone: Updated from global requirements https://review.openstack.org/214509 | 15:27 |
sdake | they should be | 15:27 |
ayoung | eliminate the simple things | 15:27 |
sdake | but samyaple is verifyign that | 15:27 |
ayoung | yes...the *should* be | 15:27 |
mfisch | connection = mysql://keystone:pass@haproxy-vip:3307/keystone | 15:27 |
ayoung | but could HA proxy be playing games with you? | 15:27 |
mfisch | hatop will show you how many connections you have | 15:27 |
mfisch | you should have 0 to the other nodes in galera | 15:28 |
* ayoung needs to learn ha proxy | 15:28 | |
*** jasonsb has quit IRC | 15:28 | |
SamYaple | mfisch: it was 0 | 15:28 |
* ayoung decides actually that would be a bad idea | 15:28 | |
SamYaple | i checked via the socket | 15:28 |
sdake | samyaple any results in shutting down the other two galera services? | 15:28 |
SamYaple | yea im rekicking everything, with a single mariadb node | 15:29 |
mfisch | here is our haproxy gui: http://i.imgur.com/bvAWHHm.png | 15:29 |
SamYaple | just exec | 15:29 |
SamYaple | should take 5 min | 15:29 |
mfisch | only talking to node 1 | 15:29 |
SamYaple | mfisch: well this wont need to be part of the discussion in a few minutes | 15:29 |
SamYaple | but for the record, i did check those stats | 15:29 |
mfisch | we've used haproxy-galera-keystone UUID since icehouse | 15:30 |
mfisch | now on fernet though | 15:30 |
sdake | ansible takes 5 minutes to deploy openstack | 15:30 |
sdake | mfisch arey ou using the source routing option in haproxy? | 15:30 |
*** stevemar has joined #openstack-keystone | 15:30 | |
*** ChanServ sets mode: +v stevemar | 15:30 | |
mfisch | oh I should trade my help for fixing an ansible bug ;) | 15:30 |
sdake | if so, that locks traffic to one keystone service | 15:30 |
SamYaple | mfisch: you name it imve got you covered | 15:30 |
SamYaple | i also fix bugs for whiskey | 15:31 |
*** ninag has quit IRC | 15:31 | |
SamYaple | just fyi | 15:31 |
mfisch | I've already harassed Robyn ;) | 15:31 |
sdake | SamYaple is a ansible rocket surgeon | 15:31 |
*** diazjf has quit IRC | 15:31 | |
SamYaple | ill be honest I would prefer the whiskey | 15:32 |
sdake | lol | 15:32 |
sdake | mfish can you check your haproxy for the source routing option? | 15:32 |
mfisch | sure | 15:32 |
*** ninag has joined #openstack-keystone | 15:32 | |
ayoung | Whiskey prices in Tokyo going to exceed my expense account limits I'm sure | 15:32 |
mfisch | for keystone or galera? | 15:32 |
sdake | https://review.openstack.org/#/c/219261/ | 15:32 |
sdake | for keystone | 15:32 |
*** diazjf has joined #openstack-keystone | 15:33 | |
SamYaple | mfisch: is that fernet in production you are using? | 15:33 |
marekd | ayoung: so buy your own on a duty free :P | 15:33 |
sdake | my expense account at rht was my personal amex ;-) | 15:33 |
ayoung | marekd, planning on it | 15:33 |
SamYaple | i saw ayoung writeup on that. looked good to me. i use that in my lab | 15:33 |
mfisch | here's the config for galera | 15:33 |
mfisch | http://paste.openstack.org/show/438007/ | 15:33 |
mfisch | SamYaple: yes fernet in prod | 15:33 |
ayoung | sdake, I lopve REd Hat, but its pockets are shallow | 15:33 |
mfisch | galera cluster UUID == pain in my ass | 15:34 |
sdake | balance source | 15:34 |
mfisch | but look at the server list | 15:34 |
sdake | so this will lock all traffic to one keystone service | 15:34 |
mfisch | backup backup | 15:34 |
mfisch | thats for galera | 15:34 |
mfisch | keystone is round-robin | 15:34 |
SamYaple | there guys. everyone should be happy. mariadb 1 host no multihost same issue | 15:34 |
marekd | mfisch: is galera making a cluster without a single master? so you can write to every node and it will not be fully commited until all (or majority) of nodes commit ? | 15:34 |
sdake | do you have balance source? | 15:34 |
SamYaple | how shall we proceed | 15:34 |
mfisch | marekd: they're all masters technically but we only use one as a hangover from UUID days | 15:35 |
ayoung | "cluster" is only half the word.... | 15:35 |
mfisch | AFAIK galera will return success on a write as soon as its in the transaction log and guaranteed not to conflict with anything pending | 15:35 |
marekd | mfisch: i know i should probably ask such questions on #galera but since you seem to be an expert in the topic :-) | 15:35 |
sdake | charlie foxtrot is the appropriate terminology ayoung :) | 15:35 |
mfisch | lol | 15:35 |
mfisch | thats scary marekd | 15:35 |
marekd | mfisch: so how does it know nothing is in conflict, some requests,tasks may be on the wire while local node is retuning commit | 15:36 |
marekd | ^^ that's scary :P | 15:36 |
mfisch | Special Finnish magic that has been passed down from DBA to DBA since ancient times | 15:36 |
SamYaple | GTID | 15:37 |
mfisch | tbh I've never asked that question before | 15:37 |
mfisch | SamYaple: if you can repro with 1 host my assistance here is done ;) | 15:37 |
SamYaple | mfisch: i cannot | 15:37 |
SamYaple | same issue | 15:37 |
SamYaple | twas my point | 15:37 |
sdake | so we are down to one galera server, and problem persists | 15:37 |
mfisch | right, its broken with 1 host thats your point | 15:38 |
SamYaple | correct | 15:38 |
mfisch | so its not a galera clustering/haproxy issue | 15:38 |
SamYaple | ah i follow | 15:38 |
morgan | ayoung: ping | 15:38 |
mfisch | its out of my realm of where I can help ;) | 15:38 |
sdake | 1 galera 3 keystone | 15:38 |
morgan | ayoung: need to point you at something | 15:38 |
SamYaple | yea i didnt think it was but glad we could rule it out mfisch :) | 15:38 |
ayoung | morgan, that is only marginally better than a naked ping. | 15:38 |
morgan | ayoung: there is a reason | 15:38 |
ayoung | at least it wasn't a PM | 15:38 |
*** arunkant_ has joined #openstack-keystone | 15:40 | |
sdake | so 1 galera server, 3 keystone servers, is there a way to ensure via a config option that the key has been flushed to the db? | 15:40 |
sdake | the upstream docs say to use that source routing stuff | 15:41 |
sdake | but that forces all traffic to one keystone server | 15:41 |
sdake | rather then spreading the load | 15:41 |
mfisch | wsrep_causal_reads | 15:41 |
mfisch | that forces every transcation to sync before reads | 15:41 |
mfisch | but its slower | 15:42 |
*** HT_sergio has joined #openstack-keystone | 15:42 | |
SamYaple | awesome. so here is the deal curl command, some hosts it returns 200 others it 401's | 15:43 |
SamYaple | pastebin incoming | 15:43 |
sdake | samyaple what are your thoughts on this wsrep_casual_reads idea | 15:43 |
mfisch | tbh I dont know anyone doing it | 15:43 |
sdake | i think that is worse then source routing | 15:43 |
*** roxanaghe has joined #openstack-keystone | 15:44 | |
mfisch | does your galera cliuster include neutron/nova etc or is it just keystone? | 15:44 |
SamYaple | host 1 fails, the other two succed | 15:44 |
SamYaple | http://paste.fedoraproject.org/262042/12226814/ | 15:44 |
SamYaple | repeatable | 15:44 |
sdake | its got the whole deployment in it | 15:44 |
mfisch | ok | 15:44 |
mfisch | ours is separate | 15:44 |
sdake | samyaple is it minime-one that fails? | 15:45 |
mfisch | you can see similar "not found" issues with neutron too | 15:45 |
mfisch | if you dont do something like primary/backups | 15:45 |
SamYaple | sdake: yea but it varies, its not consistent | 15:45 |
SamYaple | im going to disable some servers in haproxy to see if it works with _any_ keystone server as long as its one o there are some busted ones | 15:46 |
*** diazjf has quit IRC | 15:46 | |
sdake | samyaple your pastebin is why i wanted to try out 2 node baremetal in my environment | 15:47 |
mfisch | simplify this | 15:47 |
mfisch | modify keystone.conf by hand to point direct to a node not haproxy and try to repro | 15:47 |
openstackgerrit | Monty Taylor proposed openstack/keystoneauth: Mark tenant-name and tenant-id deprecated https://review.openstack.org/213475 | 15:48 |
sdake | that will force reads to one keystone service, we have already verified that works | 15:48 |
mfisch | There are N keystones and M mysqls right? | 15:48 |
sdake | ther is 1 mysql 3 keystones | 15:48 |
openstackgerrit | Monty Taylor proposed openstack/keystoneauth: Mark tenant-name and tenant-id deprecated https://review.openstack.org/213475 | 15:49 |
mfisch | are you using caching of any sort? | 15:49 |
sdake | memcache? nope | 15:49 |
*** diazjf has joined #openstack-keystone | 15:49 | |
sdake | all the caching options ar set to false in keystone.conf | 15:49 |
openstackgerrit | Marek Denis proposed openstack/keystone: IdP deletion triggers token revocation https://review.openstack.org/210456 | 15:49 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Add user domain info to federated fernet tokens https://review.openstack.org/213742 | 15:49 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Add user_domain_id, project_domain_id to auth context https://review.openstack.org/213792 | 15:49 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Correct docstring for common.authorization https://review.openstack.org/213752 | 15:50 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Add unit tests for token_to_auth_context https://review.openstack.org/213797 | 15:50 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Build oslo.context RequestContext https://review.openstack.org/218511 | 15:50 |
openstackgerrit | Brant Knudson proposed openstack/keystone: More info in RequestContext https://review.openstack.org/213595 | 15:50 |
SamYaple | same random 401 beahviour with single keystone server, since mariadb backend | 15:50 |
mfisch | sdake: you have 3x Keystone --> 1 haproxy --> 1 mysql right now right? | 15:50 |
mfisch | ok | 15:50 |
SamYaple | mfisch: no right now its 1x1x1 | 15:50 |
SamYaple | same random 401 digging in logs now | 15:50 |
sdake | right but the haproxy goess back to the 3x keystones | 15:50 |
mfisch | if you can get that to break, then next do 1->1 and skip haproxy | 15:50 |
mfisch | ah so you have this | 15:50 |
mfisch | you -> 1 haproxy -> 3 keystone -> 1 haproxy -> 1 mysql | 15:50 |
*** bknudson has quit IRC | 15:50 | |
*** j_king has left #openstack-keystone | 15:50 | |
sdake | right but its actually just 1 haproxy process servering the whole thing | 15:51 |
mfisch | sure but its in the middle of everything | 15:51 |
mfisch | remove it from the chain | 15:51 |
mfisch | configgure keystoe to talk direct to maria | 15:51 |
mfisch | and you curl direct to keystone | 15:51 |
sdake | if we do that it works | 15:51 |
sdake | we have already verified that | 15:51 |
mfisch | ok | 15:52 |
SamYaple | yea definetely not keystone being the problem here | 15:52 |
SamYaple | the 401 comes but glance never talked to keystone | 15:52 |
SamYaple | (according ot the logs) | 15:52 |
mfisch | maybe we should move to #openstack-operators? | 15:52 |
*** roxanaghe has quit IRC | 15:53 | |
SamYaple | yea it shouldnt be here | 15:53 |
mfisch | before ayoung tells us we're doing it all wrong and we shouldnt be using dbs or something | 15:53 |
SamYaple | pad and pencil is my go to | 15:53 |
*** fhubik has quit IRC | 15:53 | |
mfisch | one time pads | 15:53 |
ayoung | mfisch, Keystone is wrong. THe rest is commentary. Go and study | 15:53 |
mfisch | see you guys in #openstack-operators | 15:53 |
mfisch | lo | 15:53 |
mfisch | lol | 15:53 |
ayoung | lo lo lo lo LOOOOOO! | 15:54 |
*** roxanaghe has joined #openstack-keystone | 15:58 | |
openstackgerrit | David Stanek proposed openstack/keystone: Adds caching to paste deploy's egg lookup https://review.openstack.org/219323 | 15:59 |
*** ninag has quit IRC | 15:59 | |
*** ninag has joined #openstack-keystone | 16:00 | |
*** ankita_wagh has joined #openstack-keystone | 16:02 | |
*** richm has quit IRC | 16:02 | |
*** roxanaghe has quit IRC | 16:03 | |
*** ninag has quit IRC | 16:05 | |
*** dims has joined #openstack-keystone | 16:05 | |
*** sdake_ has joined #openstack-keystone | 16:05 | |
*** e0ne has quit IRC | 16:05 | |
*** bknudson has joined #openstack-keystone | 16:06 | |
*** ChanServ sets mode: +v bknudson | 16:06 | |
*** browne has joined #openstack-keystone | 16:06 | |
*** sdake has quit IRC | 16:09 | |
*** spandhe has joined #openstack-keystone | 16:09 | |
*** raildo has quit IRC | 16:10 | |
*** phalmos has quit IRC | 16:11 | |
*** fhubik has joined #openstack-keystone | 16:11 | |
*** ninag has joined #openstack-keystone | 16:11 | |
*** fhubik has quit IRC | 16:11 | |
*** spandhe_ has joined #openstack-keystone | 16:12 | |
*** jasonsb has joined #openstack-keystone | 16:13 | |
*** spandhe has quit IRC | 16:13 | |
*** spandhe_ is now known as spandhe | 16:13 | |
*** phalmos has joined #openstack-keystone | 16:14 | |
*** richm has joined #openstack-keystone | 16:17 | |
*** sdake_ is now known as sdake | 16:21 | |
*** spandhe has quit IRC | 16:22 | |
dstanek | bknudson: i think the tests now take 2 days to run :-( | 16:23 |
*** ninag has quit IRC | 16:24 | |
*** ninag has joined #openstack-keystone | 16:24 | |
bknudson | dstanek: it runs in the gate in 15 mins or so, although it's not consistent | 16:26 |
*** ninag has quit IRC | 16:27 | |
*** ninag has joined #openstack-keystone | 16:27 | |
*** jistr|call has quit IRC | 16:28 | |
*** tonytan4ever has quit IRC | 16:28 | |
morgan | dstanek: I approve of putting the eggs in one basket | 16:29 |
dstanek | i'm going to try to be in the meeting today, but i'm in SAT and i'll be in a meeting there too - so i may be a little sluggish on the keyboard | 16:30 |
*** ninag has quit IRC | 16:32 | |
openstackgerrit | David Stanek proposed openstack/keystone: Adds caching to paste deploy's egg lookup https://review.openstack.org/219323 | 16:35 |
*** ankita_wagh has quit IRC | 16:35 | |
openstackgerrit | David Stanek proposed openstack/keystone: Initial support for versioned driver classes https://review.openstack.org/218481 | 16:36 |
*** thedodd has joined #openstack-keystone | 16:41 | |
*** jasonsb has quit IRC | 16:42 | |
*** jasonsb has joined #openstack-keystone | 16:43 | |
*** aix has quit IRC | 16:45 | |
*** exploreshaifali has joined #openstack-keystone | 16:46 | |
*** jasonsb has quit IRC | 16:47 | |
*** david-ly_ has joined #openstack-keystone | 16:49 | |
*** david-lyle has quit IRC | 16:49 | |
*** tonytan4ever has joined #openstack-keystone | 16:50 | |
*** geoffarnold has quit IRC | 16:50 | |
*** lhcheng has joined #openstack-keystone | 16:51 | |
*** ChanServ sets mode: +v lhcheng | 16:51 | |
*** fangzhou has quit IRC | 16:52 | |
*** geoffarnold has joined #openstack-keystone | 16:54 | |
*** eandersson has quit IRC | 16:55 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Unified delegation model https://review.openstack.org/208488 | 16:56 |
*** roxanaghe has joined #openstack-keystone | 17:03 | |
*** sdake_ has joined #openstack-keystone | 17:06 | |
*** sdake has quit IRC | 17:06 | |
*** sdake has joined #openstack-keystone | 17:07 | |
*** david-ly_ has quit IRC | 17:07 | |
*** wwwjfy has quit IRC | 17:07 | |
*** jasonsb has joined #openstack-keystone | 17:08 | |
*** vivekd_ has joined #openstack-keystone | 17:10 | |
*** sdake_ has quit IRC | 17:10 | |
*** vivekd has quit IRC | 17:11 | |
*** vivekd_ is now known as vivekd | 17:11 | |
*** jasonsb has quit IRC | 17:12 | |
*** petertr7_away is now known as petertr7 | 17:13 | |
*** roxanaghe_ has joined #openstack-keystone | 17:13 | |
*** samleon has joined #openstack-keystone | 17:15 | |
*** roxanaghe has quit IRC | 17:16 | |
openstackgerrit | David Stanek proposed openstack/keystone: Initial support for versioned driver classes https://review.openstack.org/218481 | 17:17 |
*** tonytan4ever has quit IRC | 17:18 | |
*** jasonsb has joined #openstack-keystone | 17:19 | |
*** jasonsb has quit IRC | 17:21 | |
*** aix has joined #openstack-keystone | 17:25 | |
*** spandhe has joined #openstack-keystone | 17:26 | |
*** tonytan4ever has joined #openstack-keystone | 17:27 | |
*** fangzhou has joined #openstack-keystone | 17:36 | |
*** stevemar has quit IRC | 17:42 | |
*** exploreshaifali has quit IRC | 17:46 | |
*** afazekas__ has joined #openstack-keystone | 17:46 | |
openstackgerrit | Lin Hua Cheng proposed openstack/keystone: Add federated auth for idp specific websso https://review.openstack.org/214766 | 17:50 |
*** afazekas__ has quit IRC | 17:51 | |
*** vivekd_ has joined #openstack-keystone | 17:52 | |
lhcheng | lbragstad: made a small fix on the routing ^ | 17:52 |
*** jasonsb has joined #openstack-keystone | 17:53 | |
*** vivekd has quit IRC | 17:53 | |
*** vivekd_ is now known as vivekd | 17:53 | |
lbragstad | lhcheng: awesome, thanks! | 17:53 |
*** david-lyle has joined #openstack-keystone | 17:54 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 17:54 | |
*** afazekas__ has joined #openstack-keystone | 17:54 | |
lbragstad | lhcheng: i'm going to push another patch, i think there might be an indentation nit? | 17:55 |
lhcheng | lbragstad: np. I am still trying to setup my env, for some reason I can't re-use the env I setup last release for testing websso, getting a lot of package conflict with oslo. | 17:55 |
morgan | dstanek: mind running the meeting today? (Cc lbragstad ?) | 17:55 |
lbragstad | morgan: i think dstanek is at a lunch meeting? | 17:56 |
lhcheng | lbragstad: sure go ahead, but this is the best I got where pep8p is still happy. | 17:56 |
lbragstad | morgan: I can give it a shot | 17:56 |
morgan | lbragstad: thnx | 17:56 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add federated auth for idp specific websso https://review.openstack.org/214766 | 17:57 |
lbragstad | lhcheng: ^ done | 17:57 |
lhcheng | lbragstad: cool, pep8 is still happy with that :) | 17:58 |
*** gyee has joined #openstack-keystone | 17:59 | |
*** ChanServ sets mode: +v gyee | 17:59 | |
*** amakarov_away is now known as amakarov | 18:01 | |
*** david-lyle has quit IRC | 18:01 | |
*** NM has joined #openstack-keystone | 18:03 | |
*** zeus- has joined #openstack-keystone | 18:04 | |
*** spandhe_ has joined #openstack-keystone | 18:04 | |
*** spandhe has quit IRC | 18:05 | |
*** spandhe_ is now known as spandhe | 18:05 | |
*** afazekas__ has quit IRC | 18:07 | |
*** alex_xu has quit IRC | 18:08 | |
*** ankita_wagh has joined #openstack-keystone | 18:09 | |
*** ankita_wagh has quit IRC | 18:10 | |
*** ankita_wagh has joined #openstack-keystone | 18:10 | |
HT_sergio | Hey all. I'm seeing a very strange behaviour from KS: I call keystoneclientv3.tokens.revoke_token() on the token I'm using the make the API request. Every other request fails :S | 18:11 |
*** alex_xu has joined #openstack-keystone | 18:11 | |
HT_sergio | Normally I dive into the code to figure stuff out, but I'm lost this time ! | 18:11 |
HT_sergio | I'm using UUID tokens with memcache backend (1 server). | 18:12 |
HT_sergio | where should I look to start narrowing down the cause ? | 18:13 |
*** NM has quit IRC | 18:15 | |
*** samueldmq has joined #openstack-keystone | 18:17 | |
*** david-lyle has joined #openstack-keystone | 18:19 | |
*** NM has joined #openstack-keystone | 18:24 | |
*** boltR has joined #openstack-keystone | 18:26 | |
boltR | is it possible to generate a permanent token? | 18:27 |
boltR | for service-to-service calls | 18:28 |
*** e0ne has joined #openstack-keystone | 18:29 | |
*** ankita_w_ has joined #openstack-keystone | 18:30 | |
*** fangzhou_ has joined #openstack-keystone | 18:31 | |
*** fangzhou has quit IRC | 18:33 | |
*** fangzhou_ is now known as fangzhou | 18:33 | |
*** ankita_wagh has quit IRC | 18:33 | |
*** exploreshaifali has joined #openstack-keystone | 18:34 | |
*** pgbridge has joined #openstack-keystone | 18:38 | |
*** e0ne has quit IRC | 18:39 | |
*** dims has quit IRC | 18:40 | |
*** dims has joined #openstack-keystone | 18:40 | |
*** dikonoor has quit IRC | 18:41 | |
*** dims has quit IRC | 18:45 | |
amakarov | boltR, use trusts | 18:52 |
*** raildo-afk is now known as raildo | 18:53 | |
amakarov | boltR, long-living tokens considered a bad idea as there are problems to revoke them correctly | 18:53 |
*** slberger has joined #openstack-keystone | 18:54 | |
*** e0ne has joined #openstack-keystone | 18:55 | |
*** zeus- is now known as zeus | 18:56 | |
*** zeus has quit IRC | 18:56 | |
*** zeus has joined #openstack-keystone | 18:56 | |
boltR | amakarov: cool i had no idea this existed! | 18:58 |
amakarov | boltR, welcome ) | 18:58 |
HT_sergio | amakarov: any idea where to start looking for my issue ? | 18:59 |
openstackgerrit | Vivek Dhayaal proposed openstack/keystone: Stable Keystone Driver Interfaces https://review.openstack.org/209524 | 18:59 |
*** tsymanczyk has quit IRC | 19:00 | |
amakarov | HT_sergio, yes, it was a trade-off: | 19:00 |
amakarov | revocation event is created with role+project rather than user+role+project | 19:01 |
dstanek | marekd: you still hanging around? | 19:01 |
amakarov | so any token issued for role+project is considered revoked on group revocation for example | 19:02 |
HT_sergio | amakarov: OK, that unfortunate for me. But then how come the token correctly gets rejected sometimes, but not always | 19:02 |
*** nicodemos has quit IRC | 19:03 | |
amakarov | HT_sergio, the recommended behaviour: if your token rots away - request a new one | 19:03 |
*** sigmavirus24_awa is now known as sigmavirus24 | 19:04 | |
HT_sergio | amakarov: that's not the issue I'm having. I'm trying to revoke a token, but it's not working consistently | 19:04 |
openstackgerrit | Vivek Dhayaal proposed openstack/keystone: Stable Keystone Driver Interfaces https://review.openstack.org/209524 | 19:04 |
amakarov | HT_sergio, revocation engine is not hardened to flawless state yet and it it already considered a mistake :) | 19:04 |
*** afazekas has quit IRC | 19:04 | |
HT_sergio | amakarov: lol ok. Thank you amakarov ! | 19:04 |
amakarov | HT_sergio, the latest silver bullet is 5-minutes tokens living long enough for a single operation | 19:06 |
amakarov | They just expire and don't need any revocation/deletion and other annoying stuff ) | 19:06 |
*** petertr7 is now known as petertr7_away | 19:06 | |
HT_sergio | do you know who works on token revocation, so I could learn more about it? | 19:07 |
*** fangzhou has quit IRC | 19:07 | |
*** stevemar has joined #openstack-keystone | 19:07 | |
*** ChanServ sets mode: +v stevemar | 19:07 | |
*** dims has joined #openstack-keystone | 19:09 | |
amakarov | HT_sergio, iirc revocation engine is ayoung's doing, I've fixed it a bit too so I think I can answer some of your questions | 19:11 |
*** ankita_wagh has joined #openstack-keystone | 19:12 | |
*** sdake_ has joined #openstack-keystone | 19:12 | |
*** sdake has quit IRC | 19:13 | |
*** dims has quit IRC | 19:13 | |
*** sdake has joined #openstack-keystone | 19:14 | |
*** jaosorior has quit IRC | 19:15 | |
*** ankita_w_ has quit IRC | 19:16 | |
*** fangzhou has joined #openstack-keystone | 19:17 | |
*** sdake_ has quit IRC | 19:18 | |
*** dims has joined #openstack-keystone | 19:18 | |
*** samueldmq has quit IRC | 19:20 | |
*** tsymanczyk has joined #openstack-keystone | 19:24 | |
*** tsymanczyk is now known as Guest69111 | 19:24 | |
*** dims has quit IRC | 19:25 | |
openstackgerrit | David Stanek proposed openstack/keystone: Adds caching to paste deploy's egg lookup https://review.openstack.org/219323 | 19:25 |
*** geoffarnold has quit IRC | 19:27 | |
*** roxanaghe_ has quit IRC | 19:27 | |
marekd | dstanek: yes | 19:28 |
*** pgbridge has quit IRC | 19:34 | |
*** claudiub has quit IRC | 19:34 | |
*** hakimo has quit IRC | 19:34 | |
*** lifeless has quit IRC | 19:34 | |
*** tobasco_ has quit IRC | 19:34 | |
*** rmstar has quit IRC | 19:34 | |
*** mtreinish has quit IRC | 19:34 | |
*** raginbajin has quit IRC | 19:34 | |
*** harlowja has quit IRC | 19:34 | |
*** goodygum has quit IRC | 19:34 | |
*** dobson has quit IRC | 19:34 | |
*** jamiec has quit IRC | 19:34 | |
openstackgerrit | David Stanek proposed openstack/keystone: Adds warning when no domain configs were uploaded https://review.openstack.org/214287 | 19:34 |
*** dobson has joined #openstack-keystone | 19:34 | |
*** jamiec has joined #openstack-keystone | 19:34 | |
*** pgbridge has joined #openstack-keystone | 19:35 | |
*** claudiub has joined #openstack-keystone | 19:35 | |
*** hakimo has joined #openstack-keystone | 19:35 | |
*** lifeless has joined #openstack-keystone | 19:35 | |
*** tobasco_ has joined #openstack-keystone | 19:35 | |
*** rmstar has joined #openstack-keystone | 19:35 | |
*** mtreinish has joined #openstack-keystone | 19:35 | |
*** raginbajin has joined #openstack-keystone | 19:35 | |
*** goodygum has joined #openstack-keystone | 19:35 | |
*** harlowja has joined #openstack-keystone | 19:35 | |
*** harlowja has quit IRC | 19:35 | |
*** harlowja has joined #openstack-keystone | 19:35 | |
*** dims has joined #openstack-keystone | 19:35 | |
openstackgerrit | David Stanek proposed openstack/keystone: Adds caching to paste deploy's egg lookup https://review.openstack.org/219323 | 19:36 |
dstanek | wow, i'm doing too many things at once and getting confused | 19:38 |
*** jdennis has joined #openstack-keystone | 19:39 | |
mordred | jamielennox, morgan: what's the new way of doing auth.get_plugin_class? | 19:40 |
openstackgerrit | David Stanek proposed openstack/keystone: Adds caching to paste deploy's egg lookup https://review.openstack.org/219323 | 19:41 |
*** ankita_w_ has joined #openstack-keystone | 19:41 | |
*** ankita_w_ has quit IRC | 19:42 | |
*** ankita_w_ has joined #openstack-keystone | 19:42 | |
*** ankita_wagh has quit IRC | 19:43 | |
*** sdake_ has joined #openstack-keystone | 19:45 | |
*** amakarov is now known as amakarov_away | 19:45 | |
*** ankita_wagh has joined #openstack-keystone | 19:47 | |
*** ankita_w_ has quit IRC | 19:47 | |
*** harlowja has quit IRC | 19:47 | |
*** pgbridge has quit IRC | 19:47 | |
*** claudiub has quit IRC | 19:47 | |
*** hakimo has quit IRC | 19:47 | |
*** lifeless has quit IRC | 19:47 | |
*** tobasco_ has quit IRC | 19:47 | |
*** rmstar has quit IRC | 19:47 | |
*** mtreinish has quit IRC | 19:47 | |
*** raginbajin has quit IRC | 19:47 | |
*** goodygum has quit IRC | 19:47 | |
mordred | morgan, jamielennox: or, more importantly, how do I create a session now without argparse or oslo.config structures - like, what's the Python API | 19:48 |
*** ankita_wagh has quit IRC | 19:48 | |
*** petertr7_away is now known as petertr7 | 19:48 | |
*** sdake has quit IRC | 19:49 | |
*** fangzhou has quit IRC | 19:49 | |
*** sdake has joined #openstack-keystone | 19:49 | |
*** ayoung has quit IRC | 19:50 | |
jamielennox | mordred: there's auth.get_plugin_loader | 19:50 |
*** ankita_wagh has joined #openstack-keystone | 19:50 | |
*** Guest69111 has quit IRC | 19:50 | |
mordred | ah! loading.get_plugin_loader | 19:51 |
jamielennox | also i think most clients now support interface= because i pass **kwargs from Client.__init__ to Adapter.__init__ | 19:51 |
*** fangzhou has joined #openstack-keystone | 19:52 | |
mordred | ok. cool | 19:52 |
*** harlowja has joined #openstack-keystone | 19:52 | |
*** pgbridge has joined #openstack-keystone | 19:52 | |
*** claudiub has joined #openstack-keystone | 19:52 | |
*** hakimo has joined #openstack-keystone | 19:52 | |
*** lifeless has joined #openstack-keystone | 19:52 | |
*** tobasco_ has joined #openstack-keystone | 19:52 | |
*** rmstar has joined #openstack-keystone | 19:52 | |
*** mtreinish has joined #openstack-keystone | 19:52 | |
*** raginbajin has joined #openstack-keystone | 19:52 | |
*** goodygum has joined #openstack-keystone | 19:52 | |
mordred | I'lll go through and check and see if I can just do that in shade directly | 19:52 |
*** geoffarnold has joined #openstack-keystone | 19:52 | |
*** sdake_ has quit IRC | 19:53 | |
jamielennox | mordred: so i removed the auth-validate function but i added a couple of reviews to keystoneauth yesterday that i think will let you do the same thing | 19:53 |
mordred | yeah - saw that - I tink that looks fine | 19:53 |
jamielennox | ok | 19:54 |
*** e0ne has quit IRC | 19:54 | |
*** e0ne has joined #openstack-keystone | 19:55 | |
*** ayoung has joined #openstack-keystone | 19:56 | |
*** ChanServ sets mode: +v ayoung | 19:56 | |
*** ayoung has quit IRC | 19:58 | |
openstackgerrit | Andrey Pavlov proposed openstack/keystone: Add S3 signature v4 checking https://review.openstack.org/215481 | 19:59 |
*** ayoung has joined #openstack-keystone | 20:00 | |
*** ChanServ sets mode: +v ayoung | 20:00 | |
*** boris-42 has quit IRC | 20:00 | |
dstanek | marekd: i was pinging you about that review you mentioned in the meeting | 20:03 |
dstanek | marekd: left some feedback | 20:03 |
dstanek | morgan: should our stable drivers actually be v9 since that would be our next keystone release? | 20:03 |
*** ayoung has quit IRC | 20:05 | |
marekd | dstanek: yeah, you are right. Thanks! | 20:05 |
dstanek | marekd: np | 20:05 |
*** tsymancz1k has joined #openstack-keystone | 20:06 | |
*** ayoung has joined #openstack-keystone | 20:07 | |
*** ChanServ sets mode: +v ayoung | 20:07 | |
*** djc__ has joined #openstack-keystone | 20:10 | |
djc__ | when my identity backend for keystone is using ldap, is it placed in the 'default' domain if no domain is specified? | 20:10 |
*** exploreshaifali has quit IRC | 20:12 | |
*** vivekd has quit IRC | 20:13 | |
stevemar | djc__: yep | 20:14 |
djc__ | stevemar thanks. I now want to place service accounts in mysql and other users in AD using domains. do I need to create a keystone.default.conf file in /etc/keystone/domains directory? | 20:15 |
djc__ | steenmar and also create a domain called 'users' with a file a called 'keystone.users.conf' and place ldap configuration in this file? | 20:16 |
*** petertr7 is now known as petertr7_away | 20:22 | |
*** mpmsimo has quit IRC | 20:23 | |
*** mpmsimo has joined #openstack-keystone | 20:24 | |
*** dave-mccowan has quit IRC | 20:25 | |
slberger | djc__ I don't think the keystone.default.conf will be necessary if the mysql connection information is overridden in the new keystone."users".conf | 20:26 |
djc__ | slberger In the keystone.users.conf I plan to have ldap information. See link: https://gist.github.com/anonymous/c2a4911f7ad207732b29 | 20:28 |
*** mpmsimo has quit IRC | 20:29 | |
djc__ | slberger: AD will have regular users. I would like service accounts to be in mysql and not in AD. | 20:29 |
slberger | djc__ that should work, we created a similar looking file for our ldap setup | 20:29 |
*** vivekd has joined #openstack-keystone | 20:30 | |
djc__ | slberger: It doesn't work. when i source admin creds (which is in AD) and try to run a command it fails: "openstack user list ERROR: openstack The request you have made requires authentication. (HTTP 401) " | 20:31 |
slberger | djc__ it should overwrite values when using the domain specific config. stevemar could you confirm | 20:31 |
slberger | try running the openstack command it the --domain <domain_name> option | 20:32 |
djc__ | slberger: same error message | 20:33 |
slberger | djc__ I see this in our environment when we moved to v3 and started using domains | 20:33 |
slberger | djc__ is this when trying to grab users from the users or default domain | 20:33 |
djc__ | slberger: the name of my domain is actually Service not users. I'll send my environment. one sec | 20:34 |
djc__ | slberger: https://gist.github.com/anonymous/ff6f698977facd6f4b29 | 20:35 |
stevemar | djc__: i wrote up something around this | 20:36 |
stevemar | https://developer.ibm.com/opentech/2015/08/14/configuring-keystone-with-ibms-bluepages-ldap/ | 20:36 |
stevemar | basically slberger is right, you *MUST* make your default domain SQL backed, and any other domains backed by ldp | 20:37 |
stevemar | ldap | 20:37 |
*** dave-mccowan has joined #openstack-keystone | 20:38 | |
djc__ | stevemar: awesome thanks! so I don't need a keystone.default.conf file in /etc/keystone/domains? | 20:38 |
openstackgerrit | Vivek Dhayaal proposed openstack/keystone: Stable Keystone Driver Interfaces https://review.openstack.org/209524 | 20:38 |
djc__ | stevemar: I'm not sure how much you read, but I wan't service accounts in mysql and regular user accounts in ldap. | 20:39 |
djc__ | stevemar: I'm curious if I need to have two files in /etc/keystone/domains directory. One file for ldap (default domain) and one file for mysql (Service domain). | 20:40 |
djc__ | stevemar: Ok..looks like the link you sent covers this exact scenario. | 20:41 |
djc__ | stevemar: thanks. | 20:41 |
openstackgerrit | Vivek Dhayaal proposed openstack/keystone: Stable Keystone Driver Interfaces https://review.openstack.org/209524 | 20:50 |
stevemar | djc__: yeah, no need to create a default conf | 20:51 |
stevemar | ayoung: hey, how can i get in contact with gsilvis oh there he is | 20:51 |
stevemar | gsilvis: around? | 20:51 |
ayoung | stevemar, he's almost always in #moc too, as is the rest of his team | 20:52 |
stevemar | ty! | 20:52 |
*** sdake has quit IRC | 20:53 | |
*** thedodd has quit IRC | 20:53 | |
*** thedodd has joined #openstack-keystone | 20:54 | |
morgan | jamielennox are we loading in any of the new patches for KSA1 before we want to cut 1.0? | 20:58 |
*** thedodd has quit IRC | 20:59 | |
jamielennox | morgan: yes, it would be good to get those in, one or two are compat changes | 21:00 |
morgan | ok. | 21:00 |
morgan | jamielennox: second question - do you think we can cut 1.0 before g-r freeze? | 21:01 |
morgan | jamielennox: or should we land 0.4.0 or a 0.5.0? | 21:01 |
jamielennox | morgan: those patches i proposed for ksa was me going through it and figuring out what was missing and anything i thought was a problem | 21:01 |
morgan | ok | 21:02 |
jamielennox | i don't think i have anything else i want for a 1.0 | 21:02 |
morgan | lets land those and call it good for 1.x | 21:02 |
*** raildo is now known as raildo-afk | 21:02 | |
jamielennox | there is the get_endpoint returns None but i don't think that's a problem to change later | 21:02 |
morgan | if things aren't horked with shade etc (cc mordred ) | 21:02 |
*** spandhe has quit IRC | 21:02 | |
*** spandhe has joined #openstack-keystone | 21:04 | |
*** spandhe has quit IRC | 21:04 | |
bknudson | OH: "if you have, say, python-${PROJECT}client updates or features that need to go in liberty, you probably want to get them released ASAP" | 21:04 |
bknudson | I don't think we've done a keystoneclient release in a while? | 21:05 |
jamielennox | morgan: oh, the other thing i was thinking was allow auth_plugin as auth_type for compatibility with OSC and try and put that debate away | 21:05 |
morgan | jamielennox: i'm fine with that | 21:05 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add federated auth for idp specific websso https://review.openstack.org/214766 | 21:06 |
jamielennox | this can be > 1.0 as well | 21:06 |
*** spandhe has joined #openstack-keystone | 21:07 | |
morgan | jamielennox: +A most of the chain you had going there | 21:08 |
openstackgerrit | Michael Krotscheck proposed openstack/keystone: Added CORS support to Keystone https://review.openstack.org/216387 | 21:09 |
morgan | jamielennox: any issue with https://review.openstack.org/#/c/209671/ ? | 21:10 |
*** topol has quit IRC | 21:10 | |
*** pnavarro|afk has quit IRC | 21:11 | |
jamielennox | morgan: nope | 21:11 |
morgan | jamielennox: if that is approved, that will leave 2 outstanding patches against ksa | 21:11 |
morgan | and i'm happy with everything that has been proposed *except* the missing tests from the one terry proposed | 21:12 |
morgan | but his change is good | 21:12 |
morgan | jamielennox: what about https://review.openstack.org/#/c/218727/ ? | 21:13 |
*** ankita_w_ has joined #openstack-keystone | 21:14 | |
jamielennox | morgan: minor fix | 21:14 |
jamielennox | umm, not sure why it's failing | 21:14 |
morgan | does it need to be pre-1.0? | 21:14 |
morgan | and https://review.openstack.org/#/c/216883/ | 21:15 |
jamielennox | i don't think so because the path is public, can only be accessed by the entrypoint | 21:15 |
*** e0ne has quit IRC | 21:15 | |
jamielennox | mm, not sure about that one | 21:16 |
*** e0ne has joined #openstack-keystone | 21:16 | |
*** geoffarnold has quit IRC | 21:17 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Move admin_token to base _plugins dir https://review.openstack.org/218727 | 21:17 |
*** ankita_wagh has quit IRC | 21:17 | |
*** mpmsimo has joined #openstack-keystone | 21:17 | |
jamielennox | morgan: is this you going for a release like today? | 21:18 |
jamielennox | /now | 21:18 |
morgan | that is my hope | 21:18 |
jamielennox | ok, let me just comment one bit out and i can fix post 1.0 | 21:18 |
morgan | I want to make the 1.0 cut today if possible so we can g-r it | 21:18 |
morgan | also we want to propose a fix to the readme | 21:19 |
morgan | to stop saying "OMG DONT USE THIS" | 21:19 |
morgan | mordred: ^ cc | 21:21 |
mordred | morgan, jamielennox: shade/occ use auth_type at the moment | 21:24 |
mordred | I'd be happy to put in a rename/backwards-compat-deprecation for auth_plugin | 21:25 |
jamielennox | mordred: yea, it was initially --os-auth-plugin but dean prefered --os-auth-type, i care not i just want to have it all handled by ksa | 21:26 |
morgan | jamielennox: lets just support both | 21:26 |
jamielennox | morgan: right - i don't want to break anyone already using AUTH_PLUGIN either | 21:26 |
*** geoffarnold has joined #openstack-keystone | 21:26 | |
mordred | k. well, I pass something to loading.get_plugin_loader - and in the other places I can support both | 21:26 |
mordred | in my stuffs | 21:26 |
jamielennox | and like auth_token middleware etc all uses auth_plugin = in CONF | 21:26 |
mordred | oh wait - which is the one you prefer? | 21:27 |
mordred | like, what is the word that ksa _wants_ to call it? | 21:27 |
morgan | auth_type iirc | 21:27 |
morgan | but some people use auth_plugin | 21:27 |
mordred | k. that's what I do now. I'm just going to keep it that way for simplicity, since I have no backwards compat people | 21:27 |
morgan | yeah | 21:27 |
morgan | we just should support both in KSA | 21:27 |
morgan | thats all | 21:27 |
mordred | ++ | 21:28 |
*** mpmsimo has quit IRC | 21:28 | |
*** mpmsimo has joined #openstack-keystone | 21:28 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Remove the conf loading methods from loading.__init__ https://review.openstack.org/219463 | 21:28 |
jamielennox | mordred: initially we had auth_plugin= i'm happy to say that auth_type= can be the default and just have plugin as a fallback | 21:29 |
jamielennox | auth-type does feel a bit nicer from a user perspective | 21:29 |
jamielennox | mordred, morgan: ^ review just gives us some room later, we could probably fix it now but we seem to be on a release roll | 21:30 |
morgan | jamielennox: ++ | 21:31 |
jamielennox | oo, actually they could be a problem | 21:31 |
jamielennox | damnit | 21:32 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Tests for projects acting as domains https://review.openstack.org/211219 | 21:33 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Manager support for projects acting as domains https://review.openstack.org/213448 | 21:33 |
openstackgerrit | Henrique Truta proposed openstack/keystone: List projects filtering by is_domain flag https://review.openstack.org/158398 | 21:33 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Honor domain operations in project table https://review.openstack.org/143763 | 21:33 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Replicate domain info in projects table https://review.openstack.org/211170 | 21:33 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Change project name constraints https://review.openstack.org/158372 | 21:33 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Add is_domain parameter to get_project_by_name https://review.openstack.org/210600 | 21:33 |
morgan | jamielennox: ? | 21:34 |
jamielennox | morgan: i might need another day | 21:35 |
morgan | ok we can hold until tomorrow. | 21:35 |
jamielennox | thanks | 21:36 |
jamielennox | good to find these problems, wish it had been when i was looking yesterday | 21:36 |
morgan | yeah | 21:39 |
*** tsymancz1k is now known as tsymanczyk | 21:42 | |
*** csoukup has quit IRC | 21:44 | |
*** phalmos has quit IRC | 21:52 | |
*** spandhe has quit IRC | 21:55 | |
*** diazjf has quit IRC | 21:55 | |
*** djc__ has quit IRC | 21:55 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Return oslo.config opts from config loading https://review.openstack.org/219467 | 21:55 |
*** spandhe has joined #openstack-keystone | 21:57 | |
*** stevemar has quit IRC | 21:59 | |
*** NM has quit IRC | 21:59 | |
*** shardy has quit IRC | 22:01 | |
*** csoukup has joined #openstack-keystone | 22:01 | |
*** stevemar has joined #openstack-keystone | 22:02 | |
*** ChanServ sets mode: +v stevemar | 22:02 | |
*** stevemar has quit IRC | 22:02 | |
openstackgerrit | gordon chung proposed openstack/keystonemiddleware: use the same context across a request https://review.openstack.org/216889 | 22:03 |
*** slberger has left #openstack-keystone | 22:06 | |
*** jsavak has quit IRC | 22:08 | |
*** e0ne has quit IRC | 22:10 | |
*** e0ne has joined #openstack-keystone | 22:14 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 22:18 | |
*** ChanServ sets mode: +o morgan | 22:21 | |
openstackgerrit | Merged openstack/keystoneauth: Better isolate loading tests https://review.openstack.org/219081 | 22:21 |
openstackgerrit | Merged openstack/keystoneauth: Change option requirement testing https://review.openstack.org/219082 | 22:21 |
*** morgan changes topic to "Please review code linked via BPs and Bugs on https://launchpad.net/keystone/+milestone/liberty-3 List" | 22:21 | |
*** ChanServ sets mode: -o morgan | 22:22 | |
morgan | dstanek, dolphm, lbragstad, marekd, lhcheng, ayoung, jamielennox, stevemar, gyee, henrynash: Please review code for bugs/BPs on the L3 list | 22:23 |
ayoung | No | 22:23 |
morgan | dstanek, dolphm, lbragstad, marekd, lhcheng, ayoung, jamielennox, stevemar, gyee, henrynash: Anything that isn't gating today is being punted. | 22:23 |
morgan | or will require a FFE to land | 22:23 |
ayoung | Or a FFT | 22:23 |
morgan | gating = approved. | 22:23 |
morgan | I'll circle back through everything a little later today as well. | 22:24 |
*** gordc has quit IRC | 22:27 | |
*** edmondsw has quit IRC | 22:28 | |
*** csoukup has quit IRC | 22:28 | |
openstackgerrit | Merged openstack/keystoneauth: get_available_loaders should return loader object https://review.openstack.org/219086 | 22:29 |
openstackgerrit | Merged openstack/keystoneauth: Raise error if loader is provided name without id https://review.openstack.org/219094 | 22:29 |
openstackgerrit | Merged openstack/keystoneauth: Mark tenant-name and tenant-id deprecated https://review.openstack.org/213475 | 22:29 |
*** thiagop has quit IRC | 22:30 | |
*** spandhe has quit IRC | 22:33 | |
*** e0ne has quit IRC | 22:34 | |
*** zzzeek has quit IRC | 22:36 | |
*** alejandrito_ has joined #openstack-keystone | 22:43 | |
*** alejandrito_ has quit IRC | 22:45 | |
*** alejandrito has quit IRC | 22:45 | |
*** rbak has quit IRC | 22:49 | |
*** mpmsimo has quit IRC | 22:53 | |
*** boris-42 has joined #openstack-keystone | 22:57 | |
*** Ephur has quit IRC | 23:00 | |
*** vivekd has quit IRC | 23:00 | |
*** vivekd has joined #openstack-keystone | 23:01 | |
*** dims has quit IRC | 23:03 | |
*** chlong_ is now known as chlong | 23:18 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Limit subtree and parents queries https://review.openstack.org/209132 | 23:18 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Restrict inherited role assignments to subdomains https://review.openstack.org/164180 | 23:18 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/219493 | 23:21 |
*** tonytan4ever has quit IRC | 23:22 | |
*** henrynash has joined #openstack-keystone | 23:22 | |
*** ChanServ sets mode: +v henrynash | 23:22 | |
gyee | morgan, yes, sorry too many meetings today | 23:24 |
*** dims__ has joined #openstack-keystone | 23:24 | |
gyee | will be reviewing | 23:24 |
gyee | morgan, if we are not going to do the split pipeline solution, can we get this one instead? https://review.openstack.org/#/c/208168/ | 23:26 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Restricting domain_id update https://review.openstack.org/207218 | 23:27 |
*** diazjf has joined #openstack-keystone | 23:35 | |
*** geoffarnold has quit IRC | 23:43 | |
*** ankita_w_ has quit IRC | 23:44 | |
*** shoutm has joined #openstack-keystone | 23:48 | |
*** arunkant_ has quit IRC | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!