openstackgerrit | Merged openstack/keystoneauth: Add session and auth loading to loading.__init__ https://review.openstack.org/219463 | 00:11 |
---|---|---|
*** wwwjfy_ has joined #openstack-keystone | 00:11 | |
*** wwwjfy has quit IRC | 00:11 | |
*** hockeynut has quit IRC | 00:13 | |
*** charz has quit IRC | 00:14 | |
*** jasonsb_ has quit IRC | 00:14 | |
*** tobasco_ has quit IRC | 00:15 | |
*** notmyname has quit IRC | 00:15 | |
*** tobasco has joined #openstack-keystone | 00:16 | |
*** charz has joined #openstack-keystone | 00:16 | |
*** hockeynut has joined #openstack-keystone | 00:17 | |
*** notmyname has joined #openstack-keystone | 00:17 | |
*** btully has joined #openstack-keystone | 00:19 | |
*** goodygum has quit IRC | 00:19 | |
openstackgerrit | Merged openstack/keystoneauth: Use auth_type instead of auth_plugin by default https://review.openstack.org/219520 | 00:20 |
openstackgerrit | Matt Riedemann proposed openstack/python-keystoneclient: Update path to subunit2html in post_test_hook https://review.openstack.org/219931 | 00:20 |
*** goodygum has joined #openstack-keystone | 00:21 | |
*** shadower has quit IRC | 00:23 | |
*** hockeynut has quit IRC | 00:23 | |
*** shadower has joined #openstack-keystone | 00:23 | |
*** hockeynut has joined #openstack-keystone | 00:23 | |
*** btully has quit IRC | 00:23 | |
*** wwwjfy_ has quit IRC | 00:29 | |
*** wwwjfy has joined #openstack-keystone | 00:30 | |
*** bknudson has quit IRC | 00:44 | |
openstackgerrit | Merged openstack/keystoneauth: Raise exception for v2 with domain scope https://review.openstack.org/216883 | 00:45 |
*** btully has joined #openstack-keystone | 00:46 | |
*** browne has quit IRC | 00:46 | |
*** btully has quit IRC | 00:51 | |
*** wwwjfy has quit IRC | 00:53 | |
*** wwwjfy has joined #openstack-keystone | 00:53 | |
*** shoutm_ has joined #openstack-keystone | 00:56 | |
*** shoutm has quit IRC | 00:56 | |
*** browne has joined #openstack-keystone | 00:58 | |
*** zzzeek has joined #openstack-keystone | 01:03 | |
morgan | gyee: whoa, 62 patchsets?! | 01:04 |
*** wwwjfy has quit IRC | 01:07 | |
*** dsirrine has quit IRC | 01:12 | |
*** jdandrea has quit IRC | 01:13 | |
openstackgerrit | Terry Howe proposed openstack/keystoneauth: Move around the tests so they can be found easier https://review.openstack.org/219947 | 01:22 |
*** roxanaghe has quit IRC | 01:22 | |
*** nigelb has left #openstack-keystone | 01:23 | |
openstackgerrit | Terry Howe proposed openstack/keystoneauth: Move around the tests so they can be found easier https://review.openstack.org/219947 | 01:24 |
mordred | jamielennox: so - I'm fine with using the private ... _except_ the functionality is already exposed in prod in ansible modules | 01:33 |
mordred | which I understand is not necessarily ksa's problem | 01:33 |
mordred | jamielennox: but it means that to provide that, I'll need to be relying on a private thing across library boundaries | 01:34 |
mordred | and that means I'm opening myself to being screwed, because changing a private impl thing is totally fair game | 01:35 |
mordred | also - printing out the catalog is a thing I do A LOT in interacting with clouds, fwiw | 01:35 |
mordred | it's basically my first step in figuring out what's going on | 01:35 |
*** sdake has quit IRC | 01:36 | |
*** jasonsb has joined #openstack-keystone | 01:46 | |
*** boris-42 has quit IRC | 01:50 | |
jamielennox | mordred: ok, i'm fine to expose it | 01:51 |
jamielennox | mordred: the same thing applies with the AccessInfo object, and there was a problem there whether it should have a private object which is a dict or if the whole thing should just be the dict | 01:52 |
jamielennox | to which i boldly said - meh | 01:53 |
mordred | it's the right bold statement | 01:53 |
*** geoffarnold is now known as geoffarnoldX | 01:55 | |
ayoung | morgan, https://review.openstack.org/#/c/156870/61..62/doc/source/configure_tokenless_x509.rst,cm sufficient? If so, I'll pull the trigger | 01:56 |
*** fangzhou has quit IRC | 01:57 | |
jamielennox | mordred: either way would prefer it as a property though, but if you're busy i can fix that quick | 01:57 |
jamielennox | i don't know if morgan is still hoping to release today | 01:57 |
mordred | jamielennox: I can do it - but also _totaly_ don't mind you do it if that works for your brain | 01:57 |
morgan | jamielennox: was planning on waiting if needed we are at the last "make sure we arent broken phase" an extra day doesnt hurt things. | 02:01 |
jamielennox | morgan: there's things still merging | 02:01 |
morgan | Yes. We woild have to wait for that too | 02:02 |
jamielennox | i don't have anything else - but i didn't think i did yesterday either | 02:02 |
morgan | ayoung: yeah its good enough | 02:03 |
ayoung | gyee, Fire in the hole! | 02:04 |
*** zzzeek has quit IRC | 02:09 | |
gyee | ayoung, thanks! | 02:12 |
*** mylu has joined #openstack-keystone | 02:13 | |
*** mylu has quit IRC | 02:17 | |
*** spandhe has quit IRC | 02:17 | |
*** samleon has quit IRC | 02:17 | |
*** mylu has joined #openstack-keystone | 02:17 | |
*** woodster_ has quit IRC | 02:19 | |
*** csoukup has joined #openstack-keystone | 02:24 | |
*** mylu has quit IRC | 02:25 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Add accessor method for raw catalog content https://review.openstack.org/219862 | 02:27 |
*** sdake has joined #openstack-keystone | 02:28 | |
*** Kennan has quit IRC | 02:29 | |
*** Kennan has joined #openstack-keystone | 02:30 | |
*** sdake_ has joined #openstack-keystone | 02:31 | |
*** mylu has joined #openstack-keystone | 02:31 | |
*** mylu has quit IRC | 02:34 | |
*** sdake has quit IRC | 02:34 | |
*** lhcheng_ has quit IRC | 02:41 | |
*** kiran-r has joined #openstack-keystone | 02:43 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: List credentials by type https://review.openstack.org/208620 | 02:52 |
*** hakimo_ has quit IRC | 02:54 | |
*** hakimo has joined #openstack-keystone | 02:57 | |
*** kiran-r has quit IRC | 02:58 | |
*** wwwjfy has joined #openstack-keystone | 03:04 | |
*** richm has quit IRC | 03:04 | |
*** mylu has joined #openstack-keystone | 03:05 | |
*** lhcheng has joined #openstack-keystone | 03:06 | |
*** ChanServ sets mode: +v lhcheng | 03:06 | |
*** mylu has quit IRC | 03:09 | |
*** djc_ has joined #openstack-keystone | 03:10 | |
*** mylu has joined #openstack-keystone | 03:10 | |
djc_ | I'm setting up keystone domains. I have one domain called 'LDAP' which has users in AD. I have another domain called 'default' which has service accounts like glance, nova, etc in mysql. I can't login to the dashboard with an admin account that is in mysql. Any ideas what I'm doing wrong? | 03:13 |
*** csoukup has quit IRC | 03:16 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Tests for projects acting as domains https://review.openstack.org/211219 | 03:18 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Manager support for projects acting as domains https://review.openstack.org/213448 | 03:18 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Replicate domain info in projects table https://review.openstack.org/211170 | 03:18 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Change project name constraints https://review.openstack.org/158372 | 03:18 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Add is_domain parameter to get_project_by_name https://review.openstack.org/210600 | 03:18 |
*** shoutm_ has quit IRC | 03:20 | |
*** mylu has quit IRC | 03:26 | |
*** eglute has quit IRC | 03:27 | |
*** dolphm has quit IRC | 03:29 | |
*** erhudy1 has quit IRC | 03:29 | |
*** sigmavirus24 has quit IRC | 03:30 | |
*** dguerri` has quit IRC | 03:30 | |
*** d34dh0r53 has quit IRC | 03:30 | |
*** dikonoor has joined #openstack-keystone | 03:31 | |
*** d34dh0r53 has joined #openstack-keystone | 03:31 | |
*** dolphm has joined #openstack-keystone | 03:32 | |
*** eglute has joined #openstack-keystone | 03:32 | |
*** dguerri` has joined #openstack-keystone | 03:32 | |
*** dguerri` is now known as dguerri | 03:32 | |
*** dguerri has joined #openstack-keystone | 03:32 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Honor domain operations in project table https://review.openstack.org/143763 | 03:33 |
openstackgerrit | Henrique Truta proposed openstack/keystone: List projects filtering by is_domain flag https://review.openstack.org/158398 | 03:34 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Restricting domain_id update https://review.openstack.org/207218 | 03:34 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Limit subtree and parents queries https://review.openstack.org/209132 | 03:34 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Restrict inherited role assignments to subdomains https://review.openstack.org/164180 | 03:34 |
*** sigmavirus24_awa has joined #openstack-keystone | 03:35 | |
*** dikonoor has quit IRC | 03:35 | |
*** dims has joined #openstack-keystone | 03:35 | |
openstackgerrit | Merged openstack/keystone: Add support for effective & inherited mode in data driven tests https://review.openstack.org/151623 | 03:36 |
*** geoffarnoldX is now known as geoffarnold | 03:39 | |
*** gyee has quit IRC | 03:40 | |
*** shoutm has joined #openstack-keystone | 03:41 | |
*** sdake_ is now known as sdake | 03:42 | |
*** jecarey has quit IRC | 03:46 | |
*** boris-42 has joined #openstack-keystone | 03:59 | |
*** dims has quit IRC | 04:00 | |
*** links has joined #openstack-keystone | 04:02 | |
*** Nirupama has joined #openstack-keystone | 04:13 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/219493 | 04:14 |
*** btully has joined #openstack-keystone | 04:15 | |
*** stevemar has joined #openstack-keystone | 04:23 | |
*** ChanServ sets mode: +v stevemar | 04:23 | |
*** djc_ has quit IRC | 04:26 | |
*** shoutm has quit IRC | 04:38 | |
*** lhcheng_ has joined #openstack-keystone | 04:39 | |
*** lhcheng has quit IRC | 04:39 | |
*** geoffarnold is now known as geoffarnoldX | 04:40 | |
*** stevemar has quit IRC | 04:43 | |
*** ayoung has quit IRC | 04:44 | |
*** shoutm has joined #openstack-keystone | 04:47 | |
*** fangzhou has joined #openstack-keystone | 04:52 | |
*** fangzhou has quit IRC | 04:57 | |
*** dims has joined #openstack-keystone | 04:59 | |
*** afazekas has joined #openstack-keystone | 05:04 | |
morgan | jamielennox: you ok with https://review.openstack.org/#/c/219862/ ? | 05:04 |
jamielennox | morgan: yep | 05:04 |
jamielennox | i uploaded the second review | 05:05 |
morgan | ok cool | 05:05 |
openstackgerrit | Merged openstack/keystone: Initial support for versioned driver classes https://review.openstack.org/218481 | 05:05 |
*** vivekd has joined #openstack-keystone | 05:05 | |
morgan | and https://review.openstack.org/#/c/219947/ | 05:05 |
morgan | ? | 05:05 |
morgan | since i'm doing ksa 1.x prepare stuff | 05:06 |
*** dims has quit IRC | 05:06 | |
morgan | i have no issues with it | 05:06 |
morgan | but.. worth 2x checking your view | 05:06 |
*** sdake_ has joined #openstack-keystone | 05:13 | |
*** kiran-r has joined #openstack-keystone | 05:14 | |
*** sdake has quit IRC | 05:17 | |
*** hrou has quit IRC | 05:18 | |
*** Kennan2 has joined #openstack-keystone | 05:24 | |
*** Kennan has quit IRC | 05:25 | |
*** mylu has joined #openstack-keystone | 05:26 | |
*** stevemar has joined #openstack-keystone | 05:28 | |
*** ChanServ sets mode: +v stevemar | 05:28 | |
*** mylu has quit IRC | 05:31 | |
*** shoutm has quit IRC | 05:36 | |
*** shoutm has joined #openstack-keystone | 05:37 | |
jamielennox | whoa, hand't seen that | 05:39 |
jamielennox | morgan: sure, i don't mind | 05:40 |
jamielennox | same number of tests are running, i don't care where they live | 05:40 |
*** kiran-r has quit IRC | 05:44 | |
stevemar | marekd: i promise to look at the idp revocation token stuff in ~ 8hrs | 05:44 |
*** stevemar has quit IRC | 05:44 | |
*** sdake has joined #openstack-keystone | 05:48 | |
*** sdake_ has quit IRC | 05:52 | |
*** sdake_ has joined #openstack-keystone | 05:54 | |
*** sdake has quit IRC | 05:57 | |
*** shoutm has quit IRC | 05:58 | |
*** shoutm has joined #openstack-keystone | 05:58 | |
*** vivekd has quit IRC | 06:12 | |
*** stevemar has joined #openstack-keystone | 06:14 | |
*** ChanServ sets mode: +v stevemar | 06:14 | |
openstackgerrit | Merged openstack/keystoneauth: Change auth plugin help text to auth type https://review.openstack.org/219838 | 06:16 |
*** stevemar has quit IRC | 06:19 | |
*** shoutm_ has joined #openstack-keystone | 06:25 | |
*** chmouel has quit IRC | 06:26 | |
*** shoutm has quit IRC | 06:26 | |
*** chmouel has joined #openstack-keystone | 06:27 | |
*** mylu has joined #openstack-keystone | 06:28 | |
*** ParsectiX has joined #openstack-keystone | 06:29 | |
*** mylu has quit IRC | 06:32 | |
openstackgerrit | Craige McWhirter proposed openstack/python-keystoneclient: Add drivers to the documentation https://review.openstack.org/218099 | 06:39 |
openstackgerrit | Craige McWhirter proposed openstack/python-keystoneclient: Add drivers to the documentation https://review.openstack.org/218099 | 06:42 |
*** kiran-r has joined #openstack-keystone | 06:44 | |
*** henrynash has joined #openstack-keystone | 06:45 | |
*** ChanServ sets mode: +v henrynash | 06:45 | |
*** vivekd has joined #openstack-keystone | 06:50 | |
*** btully has quit IRC | 06:51 | |
*** ParsectiX has quit IRC | 06:55 | |
*** kiran-r has quit IRC | 06:59 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystone: Added CORS support to Keystone https://review.openstack.org/216387 | 07:05 |
*** browne has quit IRC | 07:07 | |
*** martinus__ has joined #openstack-keystone | 07:09 | |
*** browne has joined #openstack-keystone | 07:09 | |
*** browne has quit IRC | 07:09 | |
*** lhcheng_ has quit IRC | 07:10 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystoneauth: Change the README to remove the warning for 1.0.0 release https://review.openstack.org/220019 | 07:12 |
morgan | jamielennox: ^^ | 07:12 |
morgan | jamielennox: that could use a quick +2 | 07:12 |
jamielennox | morgan: done | 07:12 |
morgan | thnx | 07:13 |
* jamielennox finds copy and paste haproxy config error after 3.5 hours | 07:13 | |
morgan | we can bug someone else to +2/+A that one and we should be ready to cut 1.0 | 07:13 |
morgan | unless you ran into something else last minute? | 07:13 |
* jamielennox not sure if he's a genius or an idiot | 07:13 | |
jamielennox | ah, i just +Aed | 07:13 |
morgan | oh all good | 07:13 |
morgan | :) | 07:13 |
morgan | wfm | 07:14 |
jamielennox | we probably need to get back to 2 +2 | 07:14 |
morgan | post 1.0 we will be back to 2x+2 before +A | 07:14 |
jamielennox | :) | 07:14 |
morgan | we also need to get a project to be consuming it in the neutron gate test | 07:15 |
morgan | so we can be sure we have it exercised outside of our unit tests | 07:15 |
morgan | i figure the test renames can happen post 1.0 | 07:15 |
jamielennox | so did the g-r patch go in? | 07:15 |
morgan | no | 07:16 |
morgan | it was held for 1.0 | 07:16 |
morgan | https://review.openstack.org/#/c/219521/ can wait eh? | 07:16 |
jamielennox | i'm wondering how we can test it in gate and not crash everything | 07:16 |
jamielennox | morgan: oh yea | 07:16 |
morgan | we will release 1.0 | 07:17 |
morgan | get g-r landed | 07:17 |
morgan | and start converting things over to use it | 07:17 |
morgan | if there was a "oh #$%^" moment where something is horribly broken we can fix that | 07:17 |
morgan | but i think we've done a good job here tbh | 07:17 |
*** jorge_munoz has quit IRC | 07:20 | |
*** ParsectiX has joined #openstack-keystone | 07:20 | |
*** jorge_munoz_ has joined #openstack-keystone | 07:21 | |
*** ftco has quit IRC | 07:21 | |
jamielennox | morgan: i'm happy | 07:21 |
jamielennox | it took longer than expected | 07:21 |
jamielennox | but whatever | 07:21 |
jamielennox | i don't expect to put it as a dep in anything in kilo but we can then try and get ksc 2 ready to go | 07:22 |
jamielennox | i wonder if i can like "borrow" a docs writer to sit down with me for a day | 07:22 |
morgan | s/kilo/liberty | 07:22 |
jamielennox | i'll just have gotten used to that and have to switch to the next one | 07:23 |
*** ParsectiX has quit IRC | 07:24 | |
morgan | SDK folks will be happy with KSA being released | 07:24 |
*** ParsectiX has joined #openstack-keystone | 07:24 | |
morgan | jamielennox: also that CORS patch ^^ should be super easy to review | 07:24 |
morgan | it should be safe to +2/+A if you're inclined since I did just a change of the commit message to not reference ironic | 07:25 |
*** ccard has quit IRC | 07:26 | |
jamielennox | hmm, CORS, i went to that talk, what do i remember... | 07:29 |
jamielennox | morgan: why wouldn't CORS be configured via paste? | 07:29 |
morgan | 2 reasons | 07:30 |
morgan | 1: don't configure things via paste | 07:30 |
morgan | 2: we're ripping apart tons of that stuff atm | 07:30 |
morgan | and it was easier to place it in our WSGI code | 07:30 |
jamielennox | mmm - this seems like an _actually optional_ middleware. ie perfect for paste | 07:30 |
morgan | except it wont be optional once horizon makes a shift to angular | 07:30 |
morgan | it'll be "optional" like keystonemiddleware is "optional" only if you want everything to not work | 07:31 |
jamielennox | hmm | 07:31 |
jamielennox | alright | 07:31 |
morgan | but i disagree with configuring anything via paste at this point | 07:31 |
jamielennox | not bothering with keystone-all | 07:31 |
jamielennox | oh - speaking of which did sileht speak to you about wanting a middleware release? | 07:32 |
morgan | i grudgingly give it a pass for swift etc | 07:32 |
morgan | jamielennox: no, but i just did a flush of the easy approvals in KSM | 07:32 |
morgan | so i figure we'll do a release tomorrow | 07:32 |
morgan | just like we'll do a keystoneclient release | 07:32 |
sileht | jamielennox, thx for the reminder | 07:33 |
jamielennox | oh, hi | 07:33 |
*** afazekas__ has joined #openstack-keystone | 07:33 | |
sileht | a keystonemiddleware release would be great for aodh project | 07:33 |
jamielennox | bah, all those middleware patches of mine are still unreviewed | 07:33 |
morgan | jamielennox: sorry =/ | 07:34 |
morgan | i'll be sweeping through your cache ones once FF is done | 07:35 |
*** ftco has joined #openstack-keystone | 07:35 | |
jamielennox | meh, mostly cleanups, the other chain is the one that would let me put auth_token in front of keystone but i wouldn't do that for this cycle anyway | 07:35 |
jamielennox | alright - i'm out for a few hours | 07:36 |
morgan | jamielennox: thnx | 07:38 |
morgan | cheers | 07:38 |
*** browne has joined #openstack-keystone | 07:53 | |
openstackgerrit | Merged openstack/keystoneauth: Add accessor method for raw catalog content https://review.openstack.org/219862 | 08:00 |
*** vikram has joined #openstack-keystone | 08:02 | |
vikram | Hi there | 08:02 |
vikram | I am facing errors while starting devstack | 08:02 |
*** links has quit IRC | 08:02 | |
vikram | openstack role add: error: argument --user: expected one argument | 08:03 |
vikram | 2015-09-03 08:01:29.756 | + user_role_id= | 08:03 |
vikram | 2015-09-03 08:01:29.756 | + echo | 08:03 |
vikram | 2015-09-03 08:01:29.756 | | 08:03 |
vikram | 2015-09-03 08:01:29.756 | + get_or_create_project service default | 08:03 |
vikram | 2015-09-03 08:01:29.756 | + local project_id | 08:03 |
vikram | 2015-09-03 08:01:29.757 | ++ openstack --os-url=http://192.168.1.101:5000/v3 --os-identity-api-version=3 project create service --domain=default --or-show -f value -c id | 08:03 |
vikram | 2015-09-03 08:01:30.326 | ERROR: openstack Internal Server Error (HTTP 500) | 08:03 |
vikram | Can someone please help me ? | 08:03 |
*** vivekd has quit IRC | 08:07 | |
openstackgerrit | Merged openstack/keystonemiddleware: Allow specifying a region name to auth_token https://review.openstack.org/216579 | 08:08 |
*** pnavarro has joined #openstack-keystone | 08:09 | |
openstackgerrit | Merged openstack/keystone: Stable Keystone Driver Interfaces https://review.openstack.org/209524 | 08:12 |
*** ParsectiX has quit IRC | 08:22 | |
*** yottatsa has joined #openstack-keystone | 08:25 | |
*** vikram has quit IRC | 08:25 | |
*** stevemar has joined #openstack-keystone | 08:26 | |
*** ChanServ sets mode: +v stevemar | 08:26 | |
*** mylu has joined #openstack-keystone | 08:29 | |
*** stevemar has quit IRC | 08:31 | |
*** vivekd has joined #openstack-keystone | 08:33 | |
*** mylu has quit IRC | 08:33 | |
openstackgerrit | henry-nash proposed openstack/keystone: Remove manager-driver assignment metadata construct https://review.openstack.org/148995 | 08:34 |
*** browne has quit IRC | 08:35 | |
*** jistr has joined #openstack-keystone | 08:37 | |
*** katkapilatova has joined #openstack-keystone | 08:43 | |
*** btully has joined #openstack-keystone | 08:43 | |
*** btully has quit IRC | 08:47 | |
*** vivekd has quit IRC | 08:47 | |
*** ftco1 has joined #openstack-keystone | 08:49 | |
*** ftco has quit IRC | 08:51 | |
*** vivekd has joined #openstack-keystone | 08:55 | |
*** lhcheng has joined #openstack-keystone | 08:59 | |
*** ChanServ sets mode: +v lhcheng | 08:59 | |
*** yottatsa has quit IRC | 09:01 | |
*** lhcheng has quit IRC | 09:04 | |
openstackgerrit | Merged openstack/keystoneauth: Change the README to remove the warning for 1.0.0 release https://review.openstack.org/220019 | 09:06 |
*** ParsectiX has joined #openstack-keystone | 09:07 | |
openstackgerrit | henry-nash proposed openstack/keystone: Enable listing of role assignments in a project hierarchy https://review.openstack.org/208152 | 09:17 |
*** yottatsa has joined #openstack-keystone | 09:18 | |
*** yottatsa has quit IRC | 09:20 | |
*** yottatsa has joined #openstack-keystone | 09:25 | |
*** belmoreira has joined #openstack-keystone | 09:26 | |
openstackgerrit | Merged openstack/keystone: Add support for group membership to data driven assignment tests https://review.openstack.org/151962 | 09:28 |
openstackgerrit | Merged openstack/keystone: Broaden domain-group testing of list_role_assignments https://review.openstack.org/154302 | 09:28 |
*** e0ne has joined #openstack-keystone | 09:32 | |
*** marzif has joined #openstack-keystone | 09:42 | |
*** e0ne has quit IRC | 10:04 | |
*** e0ne has joined #openstack-keystone | 10:08 | |
*** marzif has quit IRC | 10:08 | |
*** vivekd has quit IRC | 10:19 | |
*** yottatsa has quit IRC | 10:24 | |
*** links has joined #openstack-keystone | 10:31 | |
*** Kennan2 is now known as Kennan_on_vacati | 10:44 | |
*** Kennan_on_vacati is now known as Kennan_Vacation | 10:45 | |
*** vivekd has joined #openstack-keystone | 10:45 | |
*** aix has quit IRC | 10:46 | |
*** marzif has joined #openstack-keystone | 10:47 | |
*** lhcheng has joined #openstack-keystone | 10:48 | |
*** ChanServ sets mode: +v lhcheng | 10:48 | |
openstackgerrit | Merged openstack/keystone: Add federated auth for idp specific websso https://review.openstack.org/214766 | 10:48 |
*** henrynash has quit IRC | 10:52 | |
*** lhcheng has quit IRC | 10:52 | |
*** henrynash has joined #openstack-keystone | 10:53 | |
*** ChanServ sets mode: +v henrynash | 10:53 | |
*** stevemar has joined #openstack-keystone | 10:56 | |
*** ChanServ sets mode: +v stevemar | 10:56 | |
*** henrynash has quit IRC | 10:57 | |
*** claudiub has joined #openstack-keystone | 10:59 | |
*** stevemar has quit IRC | 11:01 | |
*** lhcheng has joined #openstack-keystone | 11:12 | |
*** ChanServ sets mode: +v lhcheng | 11:12 | |
*** vivekd has quit IRC | 11:14 | |
*** aix has joined #openstack-keystone | 11:15 | |
*** lhcheng has quit IRC | 11:16 | |
*** shoutm has joined #openstack-keystone | 11:17 | |
*** vivekd has joined #openstack-keystone | 11:18 | |
*** shoutm_ has quit IRC | 11:18 | |
*** pnavarro is now known as pnavarro|lunch | 11:34 | |
*** martinus__ has quit IRC | 11:37 | |
*** amakarov_away is now known as amakarov | 11:45 | |
*** mylu has joined #openstack-keystone | 12:00 | |
*** wwwjfy_ has joined #openstack-keystone | 12:04 | |
*** mylu has quit IRC | 12:04 | |
*** wwwjfy has quit IRC | 12:07 | |
*** wwwjfy_ has quit IRC | 12:12 | |
*** wwwjfy_ has joined #openstack-keystone | 12:13 | |
*** marzif has quit IRC | 12:14 | |
*** marzif has joined #openstack-keystone | 12:15 | |
*** gordc has joined #openstack-keystone | 12:17 | |
*** raildo-afk is now known as raildo | 12:18 | |
*** petertr7_away is now known as petertr7 | 12:22 | |
*** Nirupama has quit IRC | 12:24 | |
*** pnavarro|lunch is now known as pnavarro | 12:24 | |
openstackgerrit | Ralf Haferkamp proposed openstack/keystone: Add new eventlet config option 'url_length_limit' https://review.openstack.org/220116 | 12:34 |
*** yottatsa has joined #openstack-keystone | 12:35 | |
*** richm has joined #openstack-keystone | 12:40 | |
*** dims has joined #openstack-keystone | 12:41 | |
*** shoutm_ has joined #openstack-keystone | 12:47 | |
*** shoutm has quit IRC | 12:48 | |
openstackgerrit | Merged openstack/keystone: Tokenless authz with X.509 SSL client certificate https://review.openstack.org/156870 | 12:53 |
*** chutwig has joined #openstack-keystone | 12:55 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/220124 | 12:55 |
*** hrou has joined #openstack-keystone | 13:01 | |
*** geoffarnoldX is now known as geoffarnold | 13:08 | |
*** petertr7 is now known as petertr7_away | 13:09 | |
*** dsirrine has joined #openstack-keystone | 13:09 | |
openstackgerrit | Terry Howe proposed openstack/keystoneauth: Convert project to os-testr https://review.openstack.org/220131 | 13:09 |
*** edmondsw has joined #openstack-keystone | 13:13 | |
*** petertr7_away is now known as petertr7 | 13:15 | |
*** jsavak has joined #openstack-keystone | 13:16 | |
*** lhcheng has joined #openstack-keystone | 13:19 | |
*** ChanServ sets mode: +v lhcheng | 13:19 | |
lbragstad | dolphm: quick question on the fernet length. Currently, fernet tokens end with percent encoded '=' signs (http://cdn.pasteraw.com/6tl69nuqrj56l3bl9nnlbotsqbqw4j7). What if we were to truncate the '=' and '%3D' and re-inflate them on validate? | 13:21 |
lbragstad | it would result in project and domain scoped token length being a little smaller | 13:22 |
*** stevemar has joined #openstack-keystone | 13:23 | |
*** ChanServ sets mode: +v stevemar | 13:23 | |
*** btully has joined #openstack-keystone | 13:27 | |
*** stevemar has quit IRC | 13:28 | |
openstackgerrit | Lin Hua Cheng proposed openstack/keystone: Deprecate LDAP Resource Backend https://review.openstack.org/203748 | 13:31 |
*** afaranha has joined #openstack-keystone | 13:34 | |
*** jecarey has joined #openstack-keystone | 13:34 | |
*** afaranha has left #openstack-keystone | 13:35 | |
*** afaranha has joined #openstack-keystone | 13:36 | |
*** afaranha has left #openstack-keystone | 13:36 | |
*** links has quit IRC | 13:40 | |
openstackgerrit | NAVEEN KUNAREDDY proposed openstack/keystone: Fixed typos in 'developing_drivers' doc https://review.openstack.org/220144 | 13:45 |
*** yottatsa has quit IRC | 13:50 | |
*** zzzeek has joined #openstack-keystone | 13:51 | |
*** vivekd has quit IRC | 13:57 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 13:59 | |
*** petertr7 is now known as petertr7_away | 14:00 | |
*** lhcheng has quit IRC | 14:04 | |
*** KarthikB has joined #openstack-keystone | 14:04 | |
*** geoffarnold is now known as geoffarnoldX | 14:08 | |
*** rbak has joined #openstack-keystone | 14:09 | |
*** jsavak has quit IRC | 14:12 | |
*** geoffarnoldX is now known as geoffarnold | 14:13 | |
*** ParsectiX has quit IRC | 14:14 | |
gordc | there's no 'super-admin' role is there? something like an admin for domain rather than admin for project? | 14:14 |
*** stevemar has joined #openstack-keystone | 14:15 | |
*** ChanServ sets mode: +v stevemar | 14:15 | |
*** shoutm_ has quit IRC | 14:18 | |
*** dave-mccowan has quit IRC | 14:18 | |
*** roxanaghe has joined #openstack-keystone | 14:19 | |
*** stevemar has quit IRC | 14:19 | |
*** jsavak has joined #openstack-keystone | 14:19 | |
*** topol has joined #openstack-keystone | 14:22 | |
*** ChanServ sets mode: +v topol | 14:22 | |
openstackgerrit | Merged openstack/python-keystoneclient: Update path to subunit2html in post_test_hook https://review.openstack.org/219931 | 14:23 |
*** ayoung has joined #openstack-keystone | 14:24 | |
*** ChanServ sets mode: +v ayoung | 14:24 | |
openstackgerrit | Marek Denis proposed openstack/keystone: Add methods for checking scoped tokens https://review.openstack.org/208885 | 14:24 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Add user domain info to federated fernet tokens https://review.openstack.org/213742 | 14:25 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Add user_domain_id, project_domain_id to auth context https://review.openstack.org/213792 | 14:25 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Correct docstring for common.authorization https://review.openstack.org/213752 | 14:25 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Add unit tests for token_to_auth_context https://review.openstack.org/213797 | 14:25 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Build oslo.context RequestContext https://review.openstack.org/218511 | 14:25 |
openstackgerrit | Brant Knudson proposed openstack/keystone: More info in RequestContext https://review.openstack.org/213595 | 14:25 |
*** mhickey_ has joined #openstack-keystone | 14:27 | |
*** tonytan4ever has joined #openstack-keystone | 14:28 | |
*** browne has joined #openstack-keystone | 14:31 | |
*** dave-mccowan has joined #openstack-keystone | 14:31 | |
*** yottatsa has joined #openstack-keystone | 14:32 | |
*** devlaps has quit IRC | 14:33 | |
*** mpmsimo has joined #openstack-keystone | 14:33 | |
*** chutwig has quit IRC | 14:36 | |
*** KarthikB has quit IRC | 14:37 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Move TestClient to test_versions https://review.openstack.org/218584 | 14:39 |
*** mpmsimo has quit IRC | 14:39 | |
*** bknudson has joined #openstack-keystone | 14:41 | |
*** ChanServ sets mode: +v bknudson | 14:41 | |
*** HT_sergio has joined #openstack-keystone | 14:42 | |
*** Ephur has quit IRC | 14:45 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Protect initialization with critical sections https://review.openstack.org/210001 | 14:46 |
*** stevemar has joined #openstack-keystone | 14:46 | |
*** ChanServ sets mode: +v stevemar | 14:46 | |
*** stevemar has quit IRC | 14:51 | |
*** roxanaghe has quit IRC | 14:54 | |
*** KarthikB has joined #openstack-keystone | 14:55 | |
*** stevemar has joined #openstack-keystone | 14:56 | |
*** ChanServ sets mode: +v stevemar | 14:56 | |
*** petertr7_away is now known as petertr7 | 14:56 | |
*** jsavak has quit IRC | 14:58 | |
*** erhudy has joined #openstack-keystone | 14:59 | |
*** jsavak has joined #openstack-keystone | 14:59 | |
*** stevemar has quit IRC | 15:00 | |
*** jorge_munoz_ has quit IRC | 15:00 | |
dolphm | dstanek: you're not in one of the breakout rooms, are you? | 15:01 |
*** Ephur has joined #openstack-keystone | 15:02 | |
*** jistr is now known as jistr|call | 15:02 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Add is_domain in token response https://review.openstack.org/197331 | 15:05 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Bye Bye Domain Table https://review.openstack.org/161854 | 15:05 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Change policy to comply with is_domain in token https://review.openstack.org/206063 | 15:05 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Remove domain table references https://review.openstack.org/165936 | 15:05 |
*** Ephur has quit IRC | 15:06 | |
morgan | mordred, jamielennox: https://review.openstack.org/220186 | 15:06 |
*** csoukup has joined #openstack-keystone | 15:07 | |
*** markvoelker has joined #openstack-keystone | 15:08 | |
mordred | morgan: yay! | 15:09 |
*** yottatsa has quit IRC | 15:10 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 15:12 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 15:13 | |
*** phalmos has joined #openstack-keystone | 15:13 | |
*** stevemar has joined #openstack-keystone | 15:13 | |
*** ChanServ sets mode: +v stevemar | 15:13 | |
*** geoffarnold is now known as geoffarnoldX | 15:14 | |
*** chutwig has joined #openstack-keystone | 15:14 | |
*** yottatsa has joined #openstack-keystone | 15:15 | |
*** yottatsa has quit IRC | 15:15 | |
*** Ephur has joined #openstack-keystone | 15:16 | |
*** stevemar_ has joined #openstack-keystone | 15:17 | |
*** ChanServ sets mode: +v stevemar_ | 15:17 | |
*** stevemar has quit IRC | 15:18 | |
*** jorge_munoz has joined #openstack-keystone | 15:18 | |
openstackgerrit | Merged openstack/keystoneauth-saml2: Fix Accept header in SAML2 requests https://review.openstack.org/216929 | 15:18 |
*** yottatsa has joined #openstack-keystone | 15:20 | |
openstackgerrit | David Stanek proposed openstack/keystone: Removes py3 test import hacks https://review.openstack.org/220199 | 15:24 |
*** dims has quit IRC | 15:26 | |
*** geoffarnoldX is now known as geoffarnold | 15:26 | |
*** yottatsa has quit IRC | 15:28 | |
*** pnavarro is now known as pnavarro|off | 15:29 | |
*** KarthikB has quit IRC | 15:30 | |
stevemar_ | dstanek: ldappool is now py3 friendly? | 15:30 |
openstackgerrit | David Stanek proposed openstack/keystone: Adds warning when no domain configs were uploaded https://review.openstack.org/214287 | 15:31 |
*** yottatsa has joined #openstack-keystone | 15:33 | |
dstanek | stevemar_: it at least isn't completely unfriendly | 15:33 |
stevemar_ | dstanek: ah i see what you mean, none of the things we "depend" on, so the 'extras' might still be py27 only | 15:33 |
dstanek | stevemar_: i haven't tried running any of the tests yet, but the existing tests no longer fail on import | 15:33 |
*** pnavarro|off has quit IRC | 15:34 | |
dstanek | stevemar_: we initially had some import issues because of transitive imports an those hacks basically stopped the madness | 15:34 |
stevemar_ | seems like a half measure | 15:34 |
stevemar_ | but meh | 15:34 |
stevemar_ | well, i mean, it seems like we'll just run into this problem again | 15:34 |
stevemar_ | but we'll cross that bridge when it comes | 15:35 |
dstanek | stevemar_: only as we add more tests that get covered in py34 - i really want to get them all covered sooner rather than later | 15:35 |
stevemar_ | makes sense | 15:36 |
*** dims has joined #openstack-keystone | 15:36 | |
morgan | lbragstad: https://review.openstack.org/#/c/218353/ needs rebase it's the only thing that hasn't been implemented for the BP | 15:36 |
morgan | lbragstad: i'm ok with that becoming a folloup bug as it's docs | 15:36 |
morgan | lbragstad: please open the bug and rebase/retarget the change to rc | 15:36 |
morgan | actually.. | 15:37 |
*** yottatsa has quit IRC | 15:38 | |
*** yottatsa has joined #openstack-keystone | 15:39 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystone: Add documentation for configuring IdP WebSSO https://review.openstack.org/218353 | 15:39 |
*** yottatsa has quit IRC | 15:39 | |
stevemar_ | morgan: yay doc patch | 15:40 |
stevemar_ | guys guys guys, i actually have time to review and do stuff today!! | 15:41 |
morgan | stevemar_: i just fixed the commit | 15:41 |
stevemar_ | look, i'm on IRC! | 15:41 |
morgan | stevemar_: so it's a RC-targeted patch | 15:41 |
lbragstad | morgan: awesome, thanks.. I was just in the middle of rebasing | 15:41 |
lbragstad | morgan: but you beat me to it | 15:41 |
lbragstad | stevemar_: o/ | 15:41 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Add documentation for configuring IdP WebSSO https://review.openstack.org/218353 | 15:41 |
stevemar_ | morgan: you based it on an ancient patch | 15:41 |
morgan | stevemar_: it needs a rebase | 15:41 |
stevemar_ | oh there we go | 15:41 |
stevemar_ | the button works | 15:41 |
morgan | stevemar_: seriously i just updated the commit msg for the doc bug | 15:42 |
*** markvoelker_ has joined #openstack-keystone | 15:42 | |
morgan | stevemar_: https://review.openstack.org/#/c/153897/28 start reviewing here | 15:42 |
*** woodster_ has joined #openstack-keystone | 15:44 | |
stevemar_ | morgan: its all good | 15:44 |
stevemar_ | +2ed that one! | 15:44 |
*** jistr|call is now known as jistr | 15:44 | |
stevemar_ | eww inheritance testing | 15:45 |
stevemar_ | +73, -0, i can dig it | 15:45 |
*** markvoelker has quit IRC | 15:45 | |
*** phalmos has quit IRC | 15:47 | |
lbragstad | morgan: https://bugs.launchpad.net/keystone/+bug/1491916 does that work? | 15:49 |
openstack | Launchpad bug 1491916 in Keystone "Improve IdP Specific WebSSO docs" [Undecided,New] | 15:49 |
*** KarthikB has joined #openstack-keystone | 15:49 | |
*** btully has quit IRC | 15:50 | |
lbragstad | dolphm: http://cdn.pasteraw.com/es3j52dpfgem4nom62e7vktk7g5u2j1 | 15:50 |
tdurakov | jamielennox, ping | 15:51 |
morgan | lbragstad: i already did it... there is now a duplicate bug :P | 15:51 |
morgan | lbragstad: feel free to mark mine as a dupe | 15:51 |
morgan | lbragstad: bug 1491910 | 15:52 |
openstack | bug 1491910 in Keystone "document configuring websso idp" [Medium,In progress] https://launchpad.net/bugs/1491910 - Assigned to Steve Martinelli (stevemar) | 15:52 |
morgan | lbragstad: one of the two should be duplicate | 15:52 |
morgan | for what it's worth our cut off for L3 tag looks to be https://review.openstack.org/216387 if it can land in the next couple hours | 15:53 |
morgan | (in gate ~6-7 from the top) | 15:54 |
morgan | anything beyond that is unlikely to merge in L3 | 15:54 |
morgan | today is FF / Liberty3 | 15:54 |
*** browne has quit IRC | 15:54 | |
lbragstad | morgan: done, i marked yours as a dupe | 15:54 |
morgan | lbragstad: be sure to update commit message and tag that bug to rc1 | 15:55 |
*** bknudson has quit IRC | 15:55 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add documentation for configuring IdP WebSSO https://review.openstack.org/218353 | 15:55 |
lbragstad | morgan: done | 15:56 |
*** phalmos has joined #openstack-keystone | 15:56 | |
morgan | lbragstad: cool | 15:57 |
*** afazekas__ has quit IRC | 15:59 | |
*** diazjf has joined #openstack-keystone | 16:01 | |
*** phalmos has quit IRC | 16:01 | |
*** phalmos has joined #openstack-keystone | 16:01 | |
*** stevemar_ has quit IRC | 16:01 | |
*** yottatsa has joined #openstack-keystone | 16:02 | |
lbragstad | dolphm: new bug open - https://bugs.launchpad.net/keystone/+bug/1491926 | 16:02 |
openstack | Launchpad bug 1491926 in Keystone "Remove padding from Fernet tokens" [Undecided,New] | 16:02 |
*** marzif has quit IRC | 16:04 | |
*** yottatsa has quit IRC | 16:05 | |
*** browne has joined #openstack-keystone | 16:06 | |
*** jistr has quit IRC | 16:06 | |
*** wwwjfy_ has quit IRC | 16:08 | |
openstackgerrit | Ralf Haferkamp proposed openstack/keystone: Add new eventlet config option 'url_length_limit' https://review.openstack.org/220116 | 16:09 |
*** aix has quit IRC | 16:12 | |
*** yottatsa has joined #openstack-keystone | 16:13 | |
*** roxanaghe has joined #openstack-keystone | 16:17 | |
openstackgerrit | Olivier Pilotte proposed openstack/keystone: Accepts Group IDs from the IdP without domain https://review.openstack.org/210581 | 16:21 |
*** chutwig has quit IRC | 16:25 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Protect initialization with critical sections https://review.openstack.org/210001 | 16:27 |
*** katkapilatova has left #openstack-keystone | 16:27 | |
*** stevemar has joined #openstack-keystone | 16:28 | |
*** ChanServ sets mode: +v stevemar | 16:28 | |
*** petertr7 is now known as petertr7_away | 16:29 | |
*** chutwig has joined #openstack-keystone | 16:29 | |
stevemar | morgan: dstanek i just presented ldap stuff to a bunch of folks that are customer facing | 16:29 |
stevemar | they lol'ed hard when i brought up horizon/paging/ldap issue | 16:30 |
*** tsymanczyk has quit IRC | 16:30 | |
stevemar | "if i can't manage the users, why do i need to see them" | 16:30 |
openstackgerrit | Merged openstack/keystone: Stop reading local config for domain-specific SQL config driver https://review.openstack.org/217348 | 16:31 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/220124 | 16:32 |
morgan | ~35 mins (hopefully) from L3 | 16:33 |
morgan | and then a lot of things are getting smacked with Feature Freeze -2s :( | 16:34 |
*** e0ne has quit IRC | 16:34 | |
*** bknudson has joined #openstack-keystone | 16:37 | |
*** ChanServ sets mode: +v bknudson | 16:37 | |
*** jsavak has quit IRC | 16:37 | |
*** jsavak has joined #openstack-keystone | 16:38 | |
*** phalmos has quit IRC | 16:38 | |
stevemar | morgan: :( | 16:38 |
dolphm | morgan: Won't Fix? PKI + eventlet woes https://bugs.launchpad.net/keystone/+bug/1491817 | 16:38 |
raildo | :( | 16:38 |
openstack | Launchpad bug 1491817 in Keystone "Revoking large token fails with "Request-URI Too Long (HTTP 414)"" [Undecided,In progress] - Assigned to Ralf Haferkamp (rhafer) | 16:38 |
morgan | wont fix | 16:38 |
dolphm | cc dstanek ^ | 16:39 |
stevemar | dolphm: they are both going away | 16:39 |
morgan | we're ... 1 month from rm -rf eventlet | 16:39 |
amakarov | Hi, all! I've run into missing (intentionally?) feature: neither keystone nor openstack CLI does support groups | 16:39 |
morgan | ok ok.. 40 days | 16:39 |
morgan | but... close enough | 16:39 |
stevemar | amakarov: groups should work :O | 16:39 |
stevemar | http://docs.openstack.org/developer/python-openstackclient/command-objects/group.html | 16:40 |
stevemar | set OS_IDENTITY_API_VERSION to 3 | 16:40 |
stevemar | morgan: got some great feedback about room for ldap improvements | 16:40 |
amakarov | stevemar, openstack --help seems to know nothing about it :) | 16:40 |
stevemar | look for new blueprints in the future | 16:40 |
*** yottatsa has quit IRC | 16:40 | |
*** afazekas__ has joined #openstack-keystone | 16:40 | |
* amakarov doublechecking cli version... | 16:41 | |
stevemar | amakarov: `export OS_IDENTITY_API_VERSION=3` is your friend | 16:41 |
stevemar | we should default it to 3 :\ | 16:41 |
amakarov | stevemar, MAGIC! | 16:41 |
stevemar | some people say i'm a magician | 16:41 |
bknudson | use clouds.yaml | 16:42 |
stevemar | bknudson: truth | 16:43 |
amakarov | stevemar, thanks, now I know kung-fu too :) | 16:44 |
*** btully has joined #openstack-keystone | 16:45 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Change tests to use common name for keystone.tests.unit https://review.openstack.org/218665 | 16:47 |
*** tsymanczyk has joined #openstack-keystone | 16:47 | |
*** tsymanczyk is now known as Guest29412 | 16:48 | |
*** btully has quit IRC | 16:49 | |
stevemar | bknudson: gonna propose to remove the ones in test_v3? | 16:50 |
bknudson | stevemar: I'm thinking about it. | 16:50 |
bknudson | just to keep anybody from writing new code that uses the functions | 16:51 |
stevemar | bknudson, yap | 16:51 |
bknudson | or, someone else could propose the change... | 16:51 |
bknudson | otherwise it may be part of the unit test hackathon | 16:52 |
*** Guest29412 is now known as tsymanczyk | 16:52 | |
*** mpmsimo has joined #openstack-keystone | 16:57 | |
*** mpmsimo has left #openstack-keystone | 16:59 | |
*** Reulan1 has joined #openstack-keystone | 17:00 | |
*** Reulan1 has quit IRC | 17:00 | |
*** Reulan1 has joined #openstack-keystone | 17:01 | |
*** Reulan1 has quit IRC | 17:01 | |
*** lhcheng has joined #openstack-keystone | 17:04 | |
*** ChanServ sets mode: +v lhcheng | 17:04 | |
morgan | sileht: | 17:05 |
morgan | sileht: https://review.openstack.org/220240 | 17:05 |
*** stevemar has quit IRC | 17:06 | |
*** ChanServ sets mode: +o morgan | 17:06 | |
*** mhickey_ has quit IRC | 17:06 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Remove padding from Fernet tokens https://review.openstack.org/220242 | 17:07 |
*** morgan changes topic to "Liberty-3 Today, this means Feature Freeze is in effect! | KeystoneAuth 1.0 Released (pending g-r inclusion) | Submit FFE requests to the ML as needed" | 17:07 | |
*** belmoreira has quit IRC | 17:07 | |
morgan | also keystonemiddleware release plan for today: https://review.openstack.org/#/c/220240/ | 17:08 |
*** afazekas__ has quit IRC | 17:08 | |
*** ChanServ sets mode: -o morgan | 17:08 | |
*** amakarov is now known as amakarov_away | 17:11 | |
*** afazekas__ has joined #openstack-keystone | 17:12 | |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Fixes confusing deprecation message https://review.openstack.org/219906 | 17:13 |
*** markvoelker_ has quit IRC | 17:16 | |
*** erhudy has quit IRC | 17:19 | |
*** tsymanczyk has quit IRC | 17:20 | |
*** afazekas__ has quit IRC | 17:21 | |
*** tsymanczyk has joined #openstack-keystone | 17:25 | |
*** tsymanczyk is now known as Guest28543 | 17:25 | |
*** phalmos has joined #openstack-keystone | 17:35 | |
*** petertr7_away is now known as petertr7 | 17:38 | |
*** e0ne has joined #openstack-keystone | 17:46 | |
*** tonytan4ever has quit IRC | 17:47 | |
*** kfox1111 has joined #openstack-keystone | 17:47 | |
kfox1111 | so, we just upgraded to kilo... we were able to do an openstack group list before but can't now. we get a permission denied. | 17:48 |
kfox1111 | we're using the ldap backend for groups/users, but not tenants and roles. | 17:48 |
kfox1111 | and the permission denieds seem to follow that pattern. did something change there? | 17:48 |
*** Guest28543 is now known as tsymanczyk | 17:49 | |
kfox1111 | s/permission denied/401 request requires auth/ | 17:50 |
*** bradjones has joined #openstack-keystone | 17:53 | |
*** bradjones has quit IRC | 17:53 | |
*** bradjones has joined #openstack-keystone | 17:53 | |
ayoung | kfox1111, anything else changed? | 17:54 |
openstackgerrit | werner mendizabal proposed openstack/keystone: Fix for token revocation not always respected when using fernet tokens https://review.openstack.org/220259 | 17:54 |
*** tsymanczyk has quit IRC | 17:55 | |
*** btully has joined #openstack-keystone | 17:58 | |
*** diazjf has quit IRC | 18:00 | |
*** tonytan4ever has joined #openstack-keystone | 18:00 | |
*** tsymancz1k has joined #openstack-keystone | 18:04 | |
*** phalmos has quit IRC | 18:05 | |
*** diazjf has joined #openstack-keystone | 18:10 | |
*** jasonsb has quit IRC | 18:14 | |
*** jasonsb has joined #openstack-keystone | 18:14 | |
kfox1111 | ayoung. don't think so? just yum upgraded things and followed the upgrade instructions. | 18:18 |
kfox1111 | no config entries changed. | 18:18 |
ayoung | kfox1111, http://adam.younglogic.com/2015/03/troubleshoot-new-keystone/ | 18:18 |
*** jasonsb has quit IRC | 18:19 | |
kfox1111 | ayoung: looking. | 18:19 |
kfox1111 | another interesting data point... | 18:19 |
kfox1111 | keystone user-list does work with v2. | 18:20 |
*** pgbridge has quit IRC | 18:20 | |
ayoung | kfox1111, were you doing LDAP before, too? | 18:21 |
lbragstad | bknudson: around? looking at your patch to switch the token provider default in devstack to fernet | 18:21 |
kfox1111 | yup. | 18:21 |
bknudson | lbragstad: what's up? | 18:21 |
kfox1111 | default domain's ldap, the rest sql. | 18:21 |
kfox1111 | juno didn't support enough of v3 to work with anything but default for nova/neutron. | 18:21 |
bknudson | I'm at the security group meetup | 18:22 |
kfox1111 | we have heat using v3 and groups work, so were using those. | 18:22 |
lbragstad | bknudson: we have three tests (afaik) that are failing - one of which is addressed by - https://review.openstack.org/#/c/220242/ | 18:22 |
lbragstad | bknudson: oh, nevermind, I don't mean to bother you if you're busy | 18:22 |
ayoung | kfox1111, you doing multi domain or just a singe? | 18:22 |
bknudson | lbragstad: I'm not that busy. I don't know what there is to discuss. We've got to get it working. | 18:22 |
kfox1111 | single, except for heat has its own doamin. | 18:22 |
kfox1111 | domain | 18:22 |
ayoung | kfox1111, um...that is multidomain | 18:23 |
kfox1111 | which is sql. | 18:23 |
kfox1111 | k. | 18:23 |
ayoung | so sqlbackend with a domain specific Backend for LDAP? | 18:23 |
lbragstad | bknudson: yeah, i'm just curious if you have an opinion on one of the other tests thats failing | 18:23 |
kfox1111 | yeah. ldap config's in /etc/keystone/domains/keystone.Default.conf | 18:23 |
openstackgerrit | werner mendizabal proposed openstack/keystone: Fix for token revocation not always respected when using fernet tokens https://review.openstack.org/220259 | 18:24 |
ayoung | kfox1111, make sure the user attempting to do a user-list or gorup list has a role asignment scoped to the Default domain | 18:24 |
ayoung | a project scoped token won't work...well, it depends on policy | 18:24 |
lbragstad | bknudson: this test fails because everything happens within the same second, so the unscoped token and the rescoped tokens have the same issued-at time - https://github.com/openstack/tempest/blob/master/tempest/api/identity/admin/v3/test_tokens.py#L120 | 18:24 |
ayoung | what is the policy rule for list_groups and list_users for the policy file you are using? | 18:24 |
kfox1111 | we're using the default policy. | 18:24 |
*** gyee has joined #openstack-keystone | 18:24 | |
*** ChanServ sets mode: +v gyee | 18:24 | |
kfox1111 | k. looking. | 18:24 |
bknudson | lbragstad: we'll have to figure out if tokens are granular to the second or microsecond or what. | 18:25 |
lbragstad | bknudson: and it only fails for fernet because the subsecond precision is truncated. | 18:25 |
bknudson | lbragstad: because if tokens must be subsecond then fernet is wrong. | 18:25 |
bknudson | and if tokens aren't subsecond then uuid is wrong. | 18:25 |
lbragstad | bknudson: that's out of our control because we rely on the timestamp that fernet is using | 18:25 |
kfox1111 | "identity:list_groups": "rule:admin_required" | 18:25 |
kfox1111 | ayoung: so, I'm using the cli. do I drop out the projectname/domain from the environment then? | 18:26 |
lbragstad | bknudson: we have subsecond precision, but it's always .000000Z | 18:27 |
lbragstad | for fernet tokens | 18:27 |
bknudson | lbragstad: if that's the case then tempest needs to be fixed to allow it. | 18:28 |
lbragstad | bknudson: ok | 18:28 |
*** pgbridge has joined #openstack-keystone | 18:28 | |
*** marzif has joined #openstack-keystone | 18:28 | |
kfox1111 | the cli doesn't seem to want to let me authenticate without a project. | 18:28 |
ayoung | kfox1111, add OS_DOMAIN_ID | 18:29 |
ayoung | for domain scoped operations, you want drop OS_PROJECT* | 18:29 |
kfox1111 | k. I'll try that. | 18:30 |
kfox1111 | the user is an admin on the admin tenant. | 18:30 |
*** harlowja has quit IRC | 18:31 | |
*** harlowja has joined #openstack-keystone | 18:32 | |
*** jsavak has quit IRC | 18:34 | |
*** phalmos has joined #openstack-keystone | 18:34 | |
kfox1111 | ok. when I drop the project and add the domain, all requests are now failing. | 18:34 |
kfox1111 | DEBUG: requests.packages.urllib3.connectionpool "POST /v3/auth/tokens HTTP/1.1" 401 114 | 18:35 |
kfox1111 | seems to be failing earlier. | 18:35 |
*** stevemar has joined #openstack-keystone | 18:36 | |
*** ChanServ sets mode: +v stevemar | 18:36 | |
stevemar | classic dhellmann - spamming my inbox! | 18:38 |
*** marzif has quit IRC | 18:38 | |
lbragstad | bknudson: https://review.openstack.org/#/c/220272/ | 18:43 |
stevemar | lbragstad: nice | 18:44 |
lbragstad | stevemar: do you love my super complex and efficient fix? ;) | 18:45 |
stevemar | dtroyer morgan - how do you guys feel about setting identity api version in OSC to v3? | 18:45 |
stevemar | setting *default* identitiy... | 18:45 |
stevemar | with devstack running in v3 only mode, i think its okay | 18:46 |
odyssey4me | stevemar shall I hold your beer? ;) | 18:46 |
stevemar | odyssey4me: hehe, hold my beer while i push a patch to see if devstack falls on its face | 18:47 |
stevemar | odyssey4me: then give it back | 18:47 |
odyssey4me | stevemar I have scotch, so you can have your beer back. :) | 18:48 |
odyssey4me | stevemar we're still waiting for https://review.openstack.org/186684 to land though :/ | 18:48 |
kfox1111 | yeah, the removing project and setting domain_id just causes everythign to fail. | 18:49 |
kfox1111 | do I have to be an admin on the domain? | 18:50 |
stevemar | odyssey4me: yep, thats my motivation for changing it in OSC | 18:51 |
dtroyer | stevemar: I may be ready for that. | 18:51 |
dtroyer | I'm so far behind the curve ATM though I'm not going to commit just yet without playing with it | 18:51 |
morgan | stevemar, dolphm, dstanek, lbragstad, marekd, lhcheng, ayoung, bknudson, jamielennox, gyee, topol, Henrynash, FYI L3 has been tagged for keystone. Feature freeze is in effect. (don't punt things that are currently gating out, they are fine) - just be wary of approving things (i'll be doing the -2 sweep later today) | 18:53 |
bknudson | morgan: ok. bug fixes are ok? | 18:54 |
morgan | bknudson: yep | 18:54 |
morgan | bug fixes are fine | 18:54 |
morgan | though the gate is hellacious | 18:54 |
morgan | you may want to give it some time to calm down ;) | 18:54 |
bknudson | changes to translatable strings? | 18:54 |
bknudson | that part was always confusing | 18:54 |
morgan | string freeze... hm i need to check when that is | 18:54 |
topol | morgan, ok thanks! | 18:55 |
dstanek | topol: howdy; long time no see | 18:55 |
stevemar | morgan: damn, i missed the window for my oslo.cache change :( | 18:55 |
morgan | bknudson: lets just go with next week on strings or until we hear otherwise | 18:56 |
stevemar | and moving a few of the extensions around (thought we might be able to still do this?) | 18:56 |
morgan | stevemar: this is what happens when everything is crammed into the last minute | 18:56 |
morgan | stevemar: shuffling code internally around should be fine. | 18:56 |
morgan | stevemar: same thing with adding new tests | 18:56 |
stevemar | morgan: yeah, but not using oslo.cache right? | 18:56 |
stevemar | i think nova -2'ed that too | 18:56 |
morgan | stevemar: correct moving to oslo.cache is now mitaka unless you want a FFE | 18:56 |
morgan | which case... send an email | 18:57 |
stevemar | naw | 18:57 |
morgan | ^^ topic | 18:57 |
*** jasonsb has joined #openstack-keystone | 18:57 | |
odyssey4me | morgan good news - openstack-ansible be doing a test review for sha updates tomorrow. we seem to test a bit more integration than the devstack tests and will feed back any issues :) | 18:57 |
morgan | cool | 18:58 |
stevemar | morgan: probably not https://review.openstack.org/#/c/210456/9 ? | 18:58 |
*** alextricity has joined #openstack-keystone | 18:59 | |
stevemar | meh, it can go into M | 18:59 |
morgan | stevemar: looks like a bug to me... | 18:59 |
*** diazjf has quit IRC | 18:59 | |
stevemar | i suppose | 18:59 |
morgan | like i said, i'll sweep through and -2 all the things later today | 18:59 |
* morgan needs food and stuff | 18:59 | |
alextricity | Does anybody know why switching from fernet tokens to UUID tokens might break the keystone v2 api | 18:59 |
morgan | alextricity: you'd need everything to re-auth | 18:59 |
stevemar | lbragstad: ^ | 19:00 |
dolphm | alextricity: define "break the api? | 19:00 |
morgan | alextricity: but fundamentally it shouldn't "break the api" | 19:00 |
alextricity | morgan: How would I do that? 'Keystone user-list' gives me a 401 unautherized | 19:00 |
alextricity | but 'openstack user list' runs just fine | 19:00 |
*** stevemar has quit IRC | 19:00 | |
*** topol has quit IRC | 19:00 | |
morgan | if keystoneclient is using keyring? are you specifying a token explicitly? | 19:01 |
*** stevemar has joined #openstack-keystone | 19:01 | |
*** ChanServ sets mode: +v stevemar | 19:01 | |
morgan | you have to be sure you are re-authing. OSC is probably doing a reauth for you | 19:01 |
alextricity | morgan: I'm not sure if the client is using a keyring to be honest. Can I check in the configs? I'm also not specifying a token explicityly | 19:02 |
alextricity | I'm using OS_USERNAME/OS_PASSWORD | 19:02 |
lhcheng | morgan: does the Feature Freeze apply to KSC and middleware too? | 19:03 |
alextricity | typical OS variables that I use for the clients | 19:03 |
*** stevemar has quit IRC | 19:03 | |
*** stevemar has joined #openstack-keystone | 19:03 | |
*** ChanServ sets mode: +v stevemar | 19:03 | |
morgan | lhcheng: we will be careful about merging there but it's less tightly controlled. but i don't want to have to bump g-r versions for either unless we have a very good reason after this week | 19:03 |
kfox1111 | keystone still broken. :/ | 19:04 |
morgan | lhcheng: also depends on when the stable branches are cut for liberty | 19:04 |
* morgan has to go for food. | 19:04 | |
kfox1111 | its so odd that it is only affecting user/group listing. | 19:04 |
lhcheng | morgan: got it | 19:04 |
kfox1111 | hmm... the rules on the working api calls are identicle to the non working ones. so I'm thinking somethings different somehow in the ldap plugin? | 19:05 |
bknudson | keystonemiddleware might be broken by a release of something -- https://review.openstack.org/#/c/208213/ | 19:07 |
*** jsavak has joined #openstack-keystone | 19:09 | |
*** diazjf has joined #openstack-keystone | 19:10 | |
kfox1111 | oh, weird... | 19:11 |
kfox1111 | ok. so it looks like group list isn't working without specifying --domain default now. | 19:11 |
openstackgerrit | Merged openstack/keystone: Added CORS support to Keystone https://review.openstack.org/216387 | 19:12 |
kfox1111 | yay for CORS! :) | 19:13 |
*** jsavak has quit IRC | 19:15 | |
*** _hrou_ has joined #openstack-keystone | 19:15 | |
*** jsavak has joined #openstack-keystone | 19:15 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/220124 | 19:18 |
*** hrou has quit IRC | 19:19 | |
*** _cjones_ has joined #openstack-keystone | 19:29 | |
*** dguerri is now known as dguerri` | 19:29 | |
*** _cjones_ has quit IRC | 19:31 | |
*** _cjones_ has joined #openstack-keystone | 19:32 | |
*** _cjones_ has quit IRC | 19:36 | |
mordred | woot CORS! | 19:38 |
*** _hrou_ has quit IRC | 19:38 | |
morgan | Yes! CORS!! | 19:42 |
*** henrynash has joined #openstack-keystone | 19:47 | |
*** ChanServ sets mode: +v henrynash | 19:47 | |
henrynash | gyee: (or anyone who knows about stable driver interfaces) - are the driver interfaces frozen on release cycles or are they already froxen? | 19:48 |
*** ayoung has quit IRC | 19:50 | |
*** jsavak has quit IRC | 19:51 | |
*** jsavak has joined #openstack-keystone | 19:51 | |
*** phalmos_ has joined #openstack-keystone | 19:53 | |
*** phalmos_ has quit IRC | 19:55 | |
gyee | henrynash, yes, they will be treated as API changes going forward | 19:55 |
henrynash | gyee: as of now…or releae of Liberty? | 19:56 |
*** phalmos has quit IRC | 19:56 | |
gyee | I would think as of now, but morgan may disagree | 19:56 |
gyee | vivekd's working on 3rd party driver based on the current interface | 19:57 |
*** mylu has joined #openstack-keystone | 19:57 | |
*** phalmos has joined #openstack-keystone | 19:57 | |
morgan | Feature Freeze was an hour or so ago | 19:57 |
morgan | Driver interfaces should probably be frozen at the same point? | 19:58 |
morgan | Open to discussion on it. | 19:58 |
henrynash | morgan: I think that probably makes sense | 19:58 |
gyee | morgan, like now? because the team in India is working on contributing their 3rd party driver | 19:58 |
morgan | If so then yes. As of today | 19:59 |
gyee | yeah I agree | 19:59 |
morgan | It is open to change just as ffes can happen | 19:59 |
*** mylu has quit IRC | 19:59 | |
morgan | But we should have w damn good reason to change it after feature freeze | 20:00 |
*** mylu has joined #openstack-keystone | 20:00 | |
henrynash | gyee, morgan: so jsut trying to work our the implcations of this…e.g. we may have to specify that in the Identity API sepc that certain APIs won’t work unless you have the latest drivers | 20:00 |
*** petertr7 is now known as petertr7_away | 20:01 | |
gyee | or bump the driver version | 20:01 |
morgan | This is where we try to manage with the naive implementations | 20:01 |
henrynash | gyee: but isn;t the point that we must support the N-1 driver version? | 20:01 |
gyee | anyway, gotta run, be back in an hour | 20:01 |
morgan | henrynash: that is the idea n-1 | 20:02 |
morgan | Most cases we can do a naive implementation on the n-1 driver base | 20:02 |
morgan | In fact i cant think of a case we can't | 20:02 |
henrynash | morgan: naive…as in return NotImplemented? | 20:03 |
*** pnavarro|off has joined #openstack-keystone | 20:03 | |
morgan | No as in do the work without backend specific interface code | 20:03 |
*** jsavak has quit IRC | 20:03 | |
*** jsavak has joined #openstack-keystone | 20:03 | |
*** btully has quit IRC | 20:03 | |
morgan | Example is find_by_name, naive is list, in-memory search for name, return | 20:03 |
*** mylu_ has joined #openstack-keystone | 20:04 | |
morgan | Vs filter in the backend | 20:04 |
*** chutwig is now known as erhud1 | 20:04 | |
*** erhud1 is now known as erhudy1 | 20:04 | |
*** mylu has quit IRC | 20:04 | |
morgan | In very few cases this wont work | 20:04 |
morgan | And those cases we can evaluate what options we have. | 20:04 |
*** petertr7_away is now known as petertr7 | 20:05 | |
henrynash | morgan: I see more case where this won’t work that when it will to be honest…e.g. we’ll ahve to have bug fixes that are by driver version not by release, APIs that only work in driver versions, not by release..... | 20:06 |
henrynash | morgan: personally, I think this is going to be a train wreck | 20:06 |
*** dave-mccowan has quit IRC | 20:06 | |
morgan | We shouldnt be changing our driver interfaces much. | 20:06 |
morgan | If we are... We really are doing something horribly wrong | 20:07 |
morgan | Or we need to stop supporting "loading arbitrary" drivers | 20:07 |
henrynash | morgan: so every thing I am working on needs driver chanegs | 20:07 |
morgan | It is frankly stupid we cant commit to a contract for our backends | 20:07 |
henrynash | moragn: e.g. https://review.openstack.org/#/c/191976/, https://review.openstack.org/#/c/148995/, https://review.openstack.org/#/c/208152/ | 20:08 |
henrynash | morgan: I’m not saying we can’t do commit to it…just that we will need to revamp how we diven “big fixed in relase” or API supported from release X | 20:09 |
henrynash | morgan: that’s the naive bit, we’ll have to speciffy driver versions | 20:10 |
morgan | So most of what you just linked can eaisly be done with versions. | 20:10 |
morgan | Metadata is trivial. We stop calling/returning it. | 20:10 |
morgan | The list hierarchy is expensive to do naively but can be done | 20:11 |
*** phalmos has quit IRC | 20:11 | |
morgan | And the sql restriction requires no driver changes, but requires loader changes and/or not calling certain methods | 20:11 |
*** e0ne has quit IRC | 20:12 | |
morgan | And anything experimental is more open to change. | 20:13 |
morgan | Because it has to be. | 20:13 |
henrynash | moragn: (to be exact sql restriction does add driver methods to v8 of DomainConfig so I don’t know how we get round that)….but my point is that even if we do naive implemtations, we’ll have to document performance impacts etc. | 20:13 |
morgan | Why are we adding driver methods for that? | 20:13 |
henrynash | morgan: we are useing an SQL table for a lock | 20:14 |
morgan | I think this is putting the config in the wrong place. But w/e. | 20:14 |
morgan | Sql as a lock /me shakes head | 20:15 |
*** topol has joined #openstack-keystone | 20:16 | |
*** ChanServ sets mode: +v topol | 20:16 | |
morgan | And you dont need to document soecific performance impact. In our driver development guide we have said there will be negative performance impact if you dont update your driver version | 20:16 |
*** btully has joined #openstack-keystone | 20:17 | |
*** dguerri` is now known as dguerri | 20:18 | |
henrynash | moragn: just think this is a sledge hammer to crack a nut…. | 20:18 |
morgan | Feel free to suggest undoing this change next cycle | 20:18 |
morgan | It's always open to discussion | 20:19 |
henrynash | morgan: alrady on my list :-) | 20:19 |
morgan | This cycle we are locking in an interface. | 20:19 |
*** dguerri is now known as dguerri` | 20:20 | |
morgan | My view is simply: every driver is in tree and we never support out of tree drivers or lodes externally | 20:20 |
morgan | Or we need a contract on this interface. | 20:20 |
morgan | We need to stop doing the "this isnt an api" if we support it being used as one | 20:21 |
*** btully has quit IRC | 20:21 | |
*** phalmos has joined #openstack-keystone | 20:22 | |
morgan | Either it is or it isnt. And if it is, we should stop changing it every cycle like crazy. So yes, a sledgehammer but it's not to crack a nut, its to drive a stake in to support the people using the interface in the way we agreed to and keep telling them to do (eg for mongo) | 20:22 |
morgan | Or is it a steak? ... | 20:23 |
henrynash | morgan: steaks are always more tasty in my view | 20:24 |
morgan | This is true | 20:24 |
henrynash | morgan: well, I ‘m up for trying anything….so we’ll give this a whirl | 20:25 |
*** e0ne has joined #openstack-keystone | 20:25 | |
*** sdake has joined #openstack-keystone | 20:25 | |
morgan | Sure. I think this will be a net win. | 20:25 |
morgan | Honestly, i kindof would like see us punt all drivers (including sql and ldap) out of tree. Wont happen | 20:26 |
morgan | But it would be interesting if we could. | 20:26 |
*** e0ne has quit IRC | 20:26 | |
openstackgerrit | Merged openstack/python-keystoneclient: Mask passwords when logging the HTTP response https://review.openstack.org/219004 | 20:29 |
*** sdake_ has quit IRC | 20:29 | |
henrynash | morgan: on FFE….we send teh reequest to the dev mailing list with the [keystone] tag? | 20:30 |
morgan | And [ffe] tag i think | 20:31 |
henrynash | morgan: ok, thx | 20:32 |
morgan | Ah just say FFE in the subject | 20:32 |
*** dave-mccowan has joined #openstack-keystone | 20:32 | |
morgan | Looking at others. | 20:32 |
morgan | henrynash: ^ | 20:32 |
HT_sergio | Hey all. Silly question: how does the middleware know about revoked UUID tokens? | 20:32 |
HT_sergio | I'm having problems with revoked tokens continuing to work against nova/cinder APIs seemingly forever (even after the default cache time of 300 seconds has passed) | 20:33 |
*** pnavarro|off has quit IRC | 20:36 | |
*** KarthikB has quit IRC | 20:38 | |
*** ayoung has joined #openstack-keystone | 20:41 | |
*** ChanServ sets mode: +v ayoung | 20:41 | |
*** thiagop has joined #openstack-keystone | 20:42 | |
*** pgbridge has quit IRC | 20:49 | |
*** pnavarro|off has joined #openstack-keystone | 20:49 | |
HT_sergio | disregard that last bit, the 5 minute cache time seems to be working as expected now :) I'm still confused about the token revocations list tho. Any tips or pointers to documentation would be appreciated. You guys rock :) | 20:51 |
*** jsavak has quit IRC | 20:55 | |
*** dramakri has joined #openstack-keystone | 21:03 | |
*** dramakri has left #openstack-keystone | 21:06 | |
*** gordc has quit IRC | 21:07 | |
*** tdurakov_ has joined #openstack-keystone | 21:07 | |
*** raildo is now known as raildo-afk | 21:08 | |
*** tsymancz1k has quit IRC | 21:09 | |
*** tdurakov_ has quit IRC | 21:11 | |
*** stevemar has quit IRC | 21:11 | |
*** diazjf has quit IRC | 21:13 | |
*** stevemar has joined #openstack-keystone | 21:15 | |
*** ChanServ sets mode: +v stevemar | 21:15 | |
*** tdurakov__ has joined #openstack-keystone | 21:15 | |
*** tdurakov__ has quit IRC | 21:15 | |
*** stevemar has quit IRC | 21:16 | |
*** ayoung has quit IRC | 21:17 | |
*** djc_ has joined #openstack-keystone | 21:19 | |
*** mylu_ has quit IRC | 21:20 | |
djc_ | In the horizon dashboard, I am unable to switch projects. I don't believe this is a horizon problem. Here is my keystone error_log. https://gist.github.com/anonymous/e1af043c6ea4c8b04cd1 | 21:21 |
*** mylu has joined #openstack-keystone | 21:23 | |
*** topol has quit IRC | 21:29 | |
*** mylu has quit IRC | 21:31 | |
*** petertr7 is now known as petertr7_away | 21:31 | |
*** mylu has joined #openstack-keystone | 21:32 | |
*** pnavarro|off has quit IRC | 21:33 | |
*** marzif has joined #openstack-keystone | 21:39 | |
*** mylu has quit IRC | 21:40 | |
*** djc_ has quit IRC | 21:41 | |
*** HT_sergio has quit IRC | 21:44 | |
*** phalmos has quit IRC | 21:46 | |
*** tsymancz1k has joined #openstack-keystone | 21:49 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Remove padding from Fernet tokens https://review.openstack.org/220242 | 21:50 |
*** diazjf has joined #openstack-keystone | 21:56 | |
*** jorge_munoz has quit IRC | 21:57 | |
*** diazjf has quit IRC | 22:02 | |
gyee | lbragstad, ^^^, hah nice, you mean I can inject bits to the end of the token anymore? :) | 22:02 |
gyee | s/can/can't/ | 22:02 |
lbragstad | gyee: :P | 22:03 |
*** btully has joined #openstack-keystone | 22:05 | |
*** btully has quit IRC | 22:09 | |
*** jorge_munoz has joined #openstack-keystone | 22:10 | |
*** jorge_munoz has quit IRC | 22:25 | |
*** thiagop has quit IRC | 22:28 | |
odyssey4me | \o/ https://review.openstack.org/186684 :) | 22:29 |
openstackgerrit | henry-nash proposed openstack/keystone: Rationalize list role assignment routing https://review.openstack.org/220335 | 22:32 |
*** henrynash has quit IRC | 22:33 | |
*** dsirrine has quit IRC | 22:36 | |
openstackgerrit | Merged openstack/python-keystoneclient: Deprecate create Discover without session https://review.openstack.org/205829 | 22:48 |
*** jorge_munoz has joined #openstack-keystone | 22:49 | |
*** tonytan4ever has quit IRC | 22:49 | |
*** rbak has quit IRC | 22:51 | |
*** ayoung has joined #openstack-keystone | 22:51 | |
*** ChanServ sets mode: +v ayoung | 22:51 | |
*** dsirrine has joined #openstack-keystone | 22:52 | |
*** edmondsw has quit IRC | 22:53 | |
*** jecarey has quit IRC | 22:59 | |
*** gyee has quit IRC | 23:04 | |
*** NM has joined #openstack-keystone | 23:06 | |
*** _hrou_ has joined #openstack-keystone | 23:06 | |
*** sdake has quit IRC | 23:06 | |
*** zzzeek has quit IRC | 23:10 | |
*** NM has quit IRC | 23:10 | |
*** markvoelker has joined #openstack-keystone | 23:13 | |
*** csoukup has quit IRC | 23:17 | |
*** markvoelker has quit IRC | 23:17 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Remove padding from Fernet tokens https://review.openstack.org/220242 | 23:18 |
*** jorge_munoz has quit IRC | 23:20 | |
*** marzif has quit IRC | 23:21 | |
*** markvoelker has joined #openstack-keystone | 23:25 | |
*** bradjones has quit IRC | 23:31 | |
*** dims has quit IRC | 23:44 | |
*** shoutm has joined #openstack-keystone | 23:50 | |
*** petertr7_away is now known as petertr7 | 23:51 | |
bknudson | lbragstad: are fixes posted for the failures in the devstack fernet change: https://review.openstack.org/#/c/195780/ ? | 23:53 |
*** dims has joined #openstack-keystone | 23:53 | |
bknudson | if so we can add depends-on | 23:53 |
*** dsirrine has quit IRC | 23:58 | |
*** aix has joined #openstack-keystone | 23:58 | |
lbragstad | bknudson: oh, good point | 23:58 |
lbragstad | bknudson: afaik, these are the reviews the need to land before 195780 has the ability to pass - https://review.openstack.org/#/c/220272/ and https://review.openstack.org/#/c/220242/ | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!