*** markvoelker has quit IRC | 00:00 | |
bknudson | how about put them in an extras package? | 00:00 |
---|---|---|
bknudson | keystoneauth1.extras.kerberos | 00:00 |
bknudson | it could match the value in [extras] | 00:00 |
jamielennox | yea, extras vs contrib i don't mind | 00:01 |
jamielennox | i'm just wondering if it's confusing if we put it in standard /auth/plugins/v3 when you have to do the extras install | 00:01 |
*** jasonsb has quit IRC | 00:03 | |
*** jasonsb has joined #openstack-keystone | 00:03 | |
*** jerrygb has quit IRC | 00:03 | |
*** hrou has joined #openstack-keystone | 00:06 | |
bknudson | we could do try-import so that it's in __all__ but then you try to use it and it fails at runtime | 00:07 |
jamielennox | that's similar to the lazy importer that marekd copied over with the saml2 plugin | 00:09 |
*** browne has quit IRC | 00:09 | |
*** pgbridge has quit IRC | 00:10 | |
*** EinstCrazy has quit IRC | 00:10 | |
*** EinstCrazy has joined #openstack-keystone | 00:12 | |
shaleh | isn't part of the complain slow load times for modules many don't use? | 00:20 |
bknudson | whatever we pick we can move it anyways | 00:20 |
shaleh | I know dtroyer was grumbling about slow module loads due to imports | 00:21 |
bknudson | if someone opens a bug due to slow import times we'll use the lazy importer | 00:21 |
bknudson | jamielennox: pick a module and we'll use it... contrib or optional or extras or whatever. | 00:22 |
jamielennox | the slow load times was because doing import keystoneclient would import everything ever used | 00:23 |
*** EinstCrazy has quit IRC | 00:23 | |
jamielennox | i think extras, then just namespace that on the [extras] bit | 00:24 |
bknudson | jamielennox: can you put up the review to create the extras directory with some docs and I'll rebase mine on that | 00:25 |
bknudson | ? | 00:25 |
jamielennox | bknudson: yep | 00:26 |
*** mylu has quit IRC | 00:26 | |
*** mylu has joined #openstack-keystone | 00:27 | |
openstackgerrit | Raildo Mascena de Sousa Filho proposed openstack/keystone: Translation-friendly formatting of msg string https://review.openstack.org/240316 | 00:27 |
*** jasonsb has quit IRC | 00:28 | |
*** jasonsb has joined #openstack-keystone | 00:29 | |
*** mylu has quit IRC | 00:31 | |
openstackgerrit | zouyee proposed openstack/keystone: get_user_roles in RoleAssignmentV2 to resolve ProjectNotFound https://review.openstack.org/237658 | 00:33 |
*** jasonsb has quit IRC | 00:33 | |
*** diazjf has joined #openstack-keystone | 00:40 | |
*** gildub has quit IRC | 00:42 | |
*** pumaranikar has joined #openstack-keystone | 00:43 | |
*** su_zhang has quit IRC | 00:47 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Declare an extras directory for plugins https://review.openstack.org/241055 | 00:50 |
*** mylu has joined #openstack-keystone | 00:51 | |
*** zzzeek has quit IRC | 00:52 | |
*** zzzeek has joined #openstack-keystone | 00:53 | |
*** mylu has quit IRC | 00:54 | |
*** phalmos has quit IRC | 00:55 | |
*** r-daneel has quit IRC | 00:55 | |
*** mylu has joined #openstack-keystone | 00:55 | |
*** mylu has quit IRC | 00:57 | |
*** zzzeek has quit IRC | 00:59 | |
*** zzzeek has joined #openstack-keystone | 00:59 | |
*** EinstCrazy has joined #openstack-keystone | 01:00 | |
*** markvoelker has joined #openstack-keystone | 01:00 | |
*** mylu has joined #openstack-keystone | 01:01 | |
*** mylu has quit IRC | 01:03 | |
*** gyee has quit IRC | 01:03 | |
*** mylu has joined #openstack-keystone | 01:03 | |
*** mylu has quit IRC | 01:04 | |
*** mylu has joined #openstack-keystone | 01:04 | |
*** markvoelker has quit IRC | 01:05 | |
*** mylu has quit IRC | 01:06 | |
*** mylu has joined #openstack-keystone | 01:06 | |
*** EinstCra_ has joined #openstack-keystone | 01:09 | |
*** mylu has quit IRC | 01:11 | |
*** browne has joined #openstack-keystone | 01:11 | |
*** EinstCr__ has joined #openstack-keystone | 01:12 | |
*** su_zhang has joined #openstack-keystone | 01:13 | |
*** EinstCrazy has quit IRC | 01:13 | |
*** su_zhang has quit IRC | 01:15 | |
*** EinstCra_ has quit IRC | 01:16 | |
*** su_zhang has joined #openstack-keystone | 01:16 | |
*** diazjf has quit IRC | 01:16 | |
*** mylu has joined #openstack-keystone | 01:17 | |
*** shaleh has quit IRC | 01:24 | |
*** jasonsb has joined #openstack-keystone | 01:25 | |
*** gildub has joined #openstack-keystone | 01:29 | |
*** diazjf has joined #openstack-keystone | 01:30 | |
*** csoukup has joined #openstack-keystone | 01:34 | |
*** su_zhang has quit IRC | 01:36 | |
*** davechen1 has joined #openstack-keystone | 01:37 | |
*** jerrygb has joined #openstack-keystone | 01:38 | |
*** EinstCr__ has quit IRC | 01:41 | |
*** davechen has joined #openstack-keystone | 01:47 | |
*** dims has quit IRC | 01:49 | |
*** davechen1 has quit IRC | 01:50 | |
*** srl4373 has quit IRC | 01:56 | |
*** josecastroleon has quit IRC | 01:57 | |
*** markvoelker has joined #openstack-keystone | 02:01 | |
*** diazjf1 has joined #openstack-keystone | 02:03 | |
*** diazjf has quit IRC | 02:04 | |
*** markvoelker has quit IRC | 02:06 | |
*** dims has joined #openstack-keystone | 02:08 | |
openstackgerrit | Merged openstack/python-keystoneclient: Replace repeated assertion with the loss https://review.openstack.org/240738 | 02:11 |
*** dikonoor has joined #openstack-keystone | 02:21 | |
*** gildub_ has joined #openstack-keystone | 02:23 | |
*** gildub_ has quit IRC | 02:32 | |
*** sseago has quit IRC | 02:38 | |
*** diazjf1 has quit IRC | 02:39 | |
*** sseago has joined #openstack-keystone | 02:40 | |
*** gildub has quit IRC | 02:45 | |
*** markvoelker has joined #openstack-keystone | 03:02 | |
*** ayoung has joined #openstack-keystone | 03:07 | |
*** ChanServ sets mode: +v ayoung | 03:07 | |
*** markvoelker has quit IRC | 03:07 | |
*** spandhe has quit IRC | 03:15 | |
*** woodster_ has quit IRC | 03:19 | |
*** dims has quit IRC | 03:28 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Declare an extras directory for plugins https://review.openstack.org/241055 | 03:31 |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: SAML2 authentication plugins in keystoneauth https://review.openstack.org/238549 | 03:31 |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Split ADFS and SAML2 plugins https://review.openstack.org/241081 | 03:31 |
*** The-Kid98 has joined #openstack-keystone | 03:32 | |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Use keystoneauth https://review.openstack.org/235090 | 03:40 |
*** The-Kid98 has quit IRC | 03:41 | |
*** gildub has joined #openstack-keystone | 03:51 | |
*** btully has quit IRC | 03:53 | |
*** links has joined #openstack-keystone | 03:53 | |
*** dikonoor has quit IRC | 03:54 | |
*** pumaranikar has quit IRC | 04:07 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/239019 | 04:30 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements https://review.openstack.org/239039 | 04:34 |
*** mylu has quit IRC | 04:40 | |
*** btully has joined #openstack-keystone | 04:41 | |
*** mylu has joined #openstack-keystone | 04:41 | |
*** mylu has quit IRC | 04:45 | |
*** btully has quit IRC | 04:45 | |
*** diazjf has joined #openstack-keystone | 04:50 | |
*** mylu has joined #openstack-keystone | 04:51 | |
*** mylu has quit IRC | 04:53 | |
*** mylu has joined #openstack-keystone | 04:53 | |
*** mylu has quit IRC | 04:57 | |
*** nate_gone is now known as njohnston | 04:58 | |
*** boris-42 has quit IRC | 04:58 | |
*** markvoelker has joined #openstack-keystone | 05:03 | |
*** markvoelker has quit IRC | 05:07 | |
*** flwang has quit IRC | 05:08 | |
*** akanksha_ has quit IRC | 05:08 | |
*** spandhe has joined #openstack-keystone | 05:08 | |
*** sseago has quit IRC | 05:10 | |
*** njohnston is now known as nate_gone | 05:10 | |
*** mylu has joined #openstack-keystone | 05:26 | |
*** ajaya has joined #openstack-keystone | 05:29 | |
*** btully has joined #openstack-keystone | 05:29 | |
*** diazjf has quit IRC | 05:35 | |
*** EinstCrazy has joined #openstack-keystone | 05:40 | |
*** sileht has joined #openstack-keystone | 05:40 | |
*** meker12 has quit IRC | 05:45 | |
*** spandhe has quit IRC | 05:46 | |
*** jaosorior has joined #openstack-keystone | 05:46 | |
*** jamielennox is now known as jamielennox|away | 05:47 | |
*** ajaya has quit IRC | 05:47 | |
*** mylu has quit IRC | 05:51 | |
*** EinstCra_ has joined #openstack-keystone | 05:51 | |
*** mylu has joined #openstack-keystone | 05:51 | |
*** EinstCrazy has quit IRC | 05:54 | |
*** sseago has joined #openstack-keystone | 05:55 | |
*** jamielennox|away is now known as jamielennox | 05:58 | |
*** ajaya has joined #openstack-keystone | 06:00 | |
*** abhishekk has joined #openstack-keystone | 06:01 | |
*** mylu_ has joined #openstack-keystone | 06:02 | |
*** hrou has quit IRC | 06:02 | |
*** mylu has quit IRC | 06:03 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Imported Translations from Zanata https://review.openstack.org/238789 | 06:11 |
*** mflobo has joined #openstack-keystone | 06:12 | |
*** mylu_ has quit IRC | 06:13 | |
*** jerrygb has quit IRC | 06:14 | |
*** jbell8 has quit IRC | 06:18 | |
*** spandhe has joined #openstack-keystone | 06:26 | |
*** jaosorior has quit IRC | 06:32 | |
*** jaosorior has joined #openstack-keystone | 06:34 | |
*** spandhe has quit IRC | 06:34 | |
*** spandhe has joined #openstack-keystone | 06:36 | |
*** openstackstatus has quit IRC | 06:49 | |
*** nate_gone is now known as njohnston | 06:49 | |
*** markvoelker has joined #openstack-keystone | 06:50 | |
*** openstackstatus has joined #openstack-keystone | 06:50 | |
*** ChanServ sets mode: +v openstackstatus | 06:50 | |
*** markvoelker has quit IRC | 06:55 | |
*** njohnston is now known as nate_gone | 06:58 | |
*** josecastroleon has joined #openstack-keystone | 07:00 | |
*** flwang has joined #openstack-keystone | 07:04 | |
*** mflobo has left #openstack-keystone | 07:05 | |
*** flwang has quit IRC | 07:08 | |
*** EinstCra_ has quit IRC | 07:13 | |
*** jerrygb has joined #openstack-keystone | 07:15 | |
*** boris-42 has joined #openstack-keystone | 07:18 | |
*** jerrygb has quit IRC | 07:19 | |
Anticimex | I don't see "keystone" among http://lists.openstack.org/cgi-bin/mailman/listinfo - is it hidden or actually non-existant? | 07:25 |
jaosorior | Anticimex: non-existant | 07:28 |
jaosorior | Anticimex: But this is the one you're interested in http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev | 07:28 |
*** jamielennox is now known as jamielennox|away | 07:29 | |
*** chlong has quit IRC | 07:31 | |
Anticimex | jaosorior: ack, thx, just subscribed | 07:33 |
*** tobberydberg has joined #openstack-keystone | 07:42 | |
*** lsmola has joined #openstack-keystone | 07:48 | |
*** spandhe has quit IRC | 07:49 | |
*** spandhe_ has joined #openstack-keystone | 07:49 | |
*** zigo has quit IRC | 07:53 | |
*** zigo has joined #openstack-keystone | 07:55 | |
*** josecastroleon has quit IRC | 07:58 | |
*** lsmola has quit IRC | 08:03 | |
*** Ephur has quit IRC | 08:04 | |
*** csoukup has quit IRC | 08:10 | |
*** aix has quit IRC | 08:10 | |
*** tobberyd_ has joined #openstack-keystone | 08:17 | |
*** btully has quit IRC | 08:18 | |
*** lsmola has joined #openstack-keystone | 08:19 | |
*** jbell8 has joined #openstack-keystone | 08:19 | |
*** tobberydberg has quit IRC | 08:20 | |
*** spandhe has joined #openstack-keystone | 08:24 | |
*** jbell8 has quit IRC | 08:24 | |
*** spandhe_ has quit IRC | 08:25 | |
*** xek has quit IRC | 08:28 | |
*** flwang has joined #openstack-keystone | 08:38 | |
*** ccard has joined #openstack-keystone | 08:39 | |
*** josecastroleon has joined #openstack-keystone | 08:39 | |
*** spandhe has quit IRC | 08:44 | |
*** mhu has quit IRC | 08:45 | |
*** spandhe has joined #openstack-keystone | 08:48 | |
*** aix has joined #openstack-keystone | 08:49 | |
*** btully has joined #openstack-keystone | 08:51 | |
*** markvoelker has joined #openstack-keystone | 08:52 | |
*** btully has quit IRC | 08:56 | |
*** spandhe has quit IRC | 08:56 | |
*** markvoelker has quit IRC | 08:56 | |
*** jistr has joined #openstack-keystone | 09:00 | |
*** fhubik has joined #openstack-keystone | 09:02 | |
openstackgerrit | Julien Danjou proposed openstack/keystone: wsgi: fix base_url finding https://review.openstack.org/226464 | 09:07 |
*** topol has joined #openstack-keystone | 09:08 | |
*** ChanServ sets mode: +v topol | 09:08 | |
*** topol has quit IRC | 09:13 | |
*** e0ne has joined #openstack-keystone | 09:15 | |
*** jerrygb has joined #openstack-keystone | 09:16 | |
*** jerrygb has quit IRC | 09:21 | |
*** aix has quit IRC | 09:45 | |
*** pnavarro has joined #openstack-keystone | 09:50 | |
*** markvoelker has joined #openstack-keystone | 09:53 | |
*** davechen has left #openstack-keystone | 09:54 | |
*** aix has joined #openstack-keystone | 09:57 | |
*** markvoelker has quit IRC | 09:58 | |
*** aix has quit IRC | 10:01 | |
*** jamielennox|away is now known as jamielennox | 10:06 | |
*** aix has joined #openstack-keystone | 10:06 | |
*** doug-fis_ has joined #openstack-keystone | 10:09 | |
*** ccard has quit IRC | 10:12 | |
*** doug-fish has quit IRC | 10:13 | |
*** nate_gone is now known as njohnston | 10:25 | |
*** njohnston is now known as nate_gone | 10:35 | |
*** josecastroleon has quit IRC | 10:37 | |
*** wanghua_ has quit IRC | 10:38 | |
*** wanghua_ has joined #openstack-keystone | 10:39 | |
*** alex_xu has quit IRC | 10:40 | |
*** alex_xu has joined #openstack-keystone | 10:44 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Split ADFS and SAML2 plugins https://review.openstack.org/241081 | 10:49 |
*** josecastroleon has joined #openstack-keystone | 10:53 | |
*** daemontool has quit IRC | 10:58 | |
*** daemontool has joined #openstack-keystone | 10:59 | |
*** fhubik is now known as fhubik_brb | 11:04 | |
*** csoukup has joined #openstack-keystone | 11:06 | |
*** markvoelker has joined #openstack-keystone | 11:09 | |
*** dims has joined #openstack-keystone | 11:09 | |
*** csoukup has quit IRC | 11:10 | |
*** nisha has joined #openstack-keystone | 11:10 | |
*** markvoelker has quit IRC | 11:13 | |
*** henrynash has quit IRC | 11:22 | |
*** alex_xu has quit IRC | 11:24 | |
*** alex_xu has joined #openstack-keystone | 11:25 | |
*** henrynash has joined #openstack-keystone | 11:27 | |
*** ChanServ sets mode: +v henrynash | 11:27 | |
*** jaosorior has quit IRC | 11:35 | |
*** jamielennox is now known as jamielennox|away | 11:35 | |
*** jaosorior has joined #openstack-keystone | 11:35 | |
*** josecastroleon has quit IRC | 11:36 | |
*** tellesnobrega_af is now known as tellesnobrega | 11:38 | |
*** henrynash has quit IRC | 11:42 | |
*** chlong has joined #openstack-keystone | 11:46 | |
*** fhubik_brb is now known as fhubik | 11:51 | |
*** nisha has quit IRC | 11:51 | |
*** henrynash has joined #openstack-keystone | 11:58 | |
*** ChanServ sets mode: +v henrynash | 11:58 | |
*** daemontool has quit IRC | 12:01 | |
*** fhubik is now known as fhubik_brb | 12:01 | |
*** jerrygb has joined #openstack-keystone | 12:03 | |
*** jerrygb has quit IRC | 12:03 | |
*** chlong has quit IRC | 12:03 | |
*** chlong has joined #openstack-keystone | 12:04 | |
*** jbell8 has joined #openstack-keystone | 12:07 | |
*** aix has quit IRC | 12:07 | |
*** browne has quit IRC | 12:09 | |
*** markvoelker has joined #openstack-keystone | 12:09 | |
*** josecastroleon has joined #openstack-keystone | 12:10 | |
*** jbell8 has quit IRC | 12:11 | |
*** aix has joined #openstack-keystone | 12:12 | |
*** nate_gone is now known as njohnston | 12:14 | |
*** markvoelker has quit IRC | 12:14 | |
*** fhubik_brb is now known as fhubik | 12:18 | |
*** njohnston is now known as nate_gone | 12:24 | |
*** jaosorior has quit IRC | 12:25 | |
*** jaosorior has joined #openstack-keystone | 12:26 | |
*** EmilienM has quit IRC | 12:33 | |
*** EmilienM has joined #openstack-keystone | 12:36 | |
*** tellesnobrega is now known as tellesnobrega_af | 12:42 | |
*** tellesnobrega_af is now known as tellesnobrega | 12:46 | |
*** abhishekk has quit IRC | 12:55 | |
*** links has quit IRC | 12:56 | |
*** boris-42 has quit IRC | 12:58 | |
*** sseago has quit IRC | 13:00 | |
*** jerrygb has joined #openstack-keystone | 13:01 | |
*** tellesnobrega is now known as tellesnobrega_af | 13:03 | |
*** tellesnobrega_af is now known as tellesnobrega | 13:07 | |
*** pnavarro has quit IRC | 13:09 | |
*** gordc has joined #openstack-keystone | 13:12 | |
*** sseago has joined #openstack-keystone | 13:13 | |
*** josecastroleon has quit IRC | 13:17 | |
*** sseago has quit IRC | 13:20 | |
*** sseago has joined #openstack-keystone | 13:20 | |
*** notmyname_ has joined #openstack-keystone | 13:21 | |
*** gerhardq1x has joined #openstack-keystone | 13:22 | |
*** notmyname has quit IRC | 13:22 | |
*** david8hu has quit IRC | 13:22 | |
*** gerhardqux has quit IRC | 13:22 | |
*** notmyname_ is now known as notmyname | 13:22 | |
*** lsmola has quit IRC | 13:22 | |
*** gildub has quit IRC | 13:22 | |
*** jasonsb has quit IRC | 13:22 | |
*** david8hu has joined #openstack-keystone | 13:22 | |
*** gildub has joined #openstack-keystone | 13:22 | |
*** lsmola has joined #openstack-keystone | 13:22 | |
*** jasonsb has joined #openstack-keystone | 13:23 | |
*** richm has joined #openstack-keystone | 13:29 | |
*** edmondsw has joined #openstack-keystone | 13:31 | |
*** nisha has joined #openstack-keystone | 13:35 | |
*** topol has joined #openstack-keystone | 13:43 | |
*** ChanServ sets mode: +v topol | 13:43 | |
*** topol has quit IRC | 13:44 | |
*** petertr7_away is now known as petertr7 | 13:46 | |
*** josecastroleon has joined #openstack-keystone | 13:50 | |
*** alejandrito has joined #openstack-keystone | 13:52 | |
*** raildo-afk is now known as raildo | 13:55 | |
ajaya | Hi guys. When I am trying to run unit tests through tox -e py27, it fails. | 13:56 |
ajaya | istributionNotFound: No distributions at all found for .[ldap,memcache,mongodb] | 13:56 |
ajaya | This is the log output. | 13:57 |
ajaya | Any idea why this is failing? | 13:58 |
*** RA_ has joined #openstack-keystone | 13:58 | |
ajaya | ayoung ^^ | 13:59 |
ajaya | marekd ^^ | 13:59 |
ayoung | ajaya, did you rebuild the venv? tox -r? | 14:00 |
ajaya | I just cloned Keystone repo from upstream and ran tox -epy27 | 14:00 |
ajaya | ayoung ^^ | 14:01 |
*** fhubik is now known as fhubik_brb | 14:01 | |
tjcocozz | ajaya, did you install the dependencies? http://docs.openstack.org/developer/keystone/devref/development.environment.html#installing-dependencies | 14:02 |
ajaya | ayoung, so I am building the venv for the first time itself. | 14:02 |
*** nate_gone is now known as njohnston | 14:03 | |
tjcocozz | ajaya, I had the same problem until I did this ^^ | 14:03 |
*** su_zhang has joined #openstack-keystone | 14:04 | |
ajaya | tjcocozz, You are right. Thanks. | 14:04 |
tjcocozz | ajaya, np | 14:04 |
ajaya | btw I wonder what is the meaning of this line ".[ldap,memcache,mongodb]" in tox.ini | 14:05 |
*** tellesnobrega is now known as tellesnobrega_af | 14:05 | |
ajaya | Would it install python driver for these services? | 14:05 |
tjcocozz | ajaya, I agree it is a very cryptic error. But if I remeber correctly there is another error above that one. | 14:05 |
*** jvarlamova_ has joined #openstack-keystone | 14:05 | |
*** henrynash has quit IRC | 14:09 | |
ajaya | tjcocozz, Even after installing dependencies "tox -epy27" fails with same error. | 14:09 |
ajaya | No distributions at all found for .[ldap,memcache,mongodb] | 14:10 |
ajaya | How do you run unit tests? | 14:10 |
*** markvoelker has joined #openstack-keystone | 14:10 | |
ajaya | One way is to install deps from requirements.txt file and test-requirements.txt file manually and use testr | 14:11 |
*** pnavarro has joined #openstack-keystone | 14:11 | |
*** njohnston is now known as nate_gone | 14:13 | |
*** jbell8 has joined #openstack-keystone | 14:14 | |
tjcocozz | ajaya, Do you have these packages? http://goo.gl/QSd2na | 14:15 |
*** markvoelker has quit IRC | 14:15 | |
ajaya | Yes I do have those packages. | 14:16 |
ajaya | tjcocozz I think it's due to having a older pip version. | 14:18 |
ajaya | I have 1.5.4 which comes with trusty. | 14:18 |
ajaya | Maybe I should upgrade pip. | 14:18 |
ajaya | That should solve the problem. | 14:18 |
tjcocozz | pip install pip | 14:18 |
tjcocozz | that is your problem | 14:18 |
*** jbell8 has quit IRC | 14:19 | |
ajaya | Let's see if pip install pip works. | 14:19 |
tjcocozz | pip install pip --upgrade | 14:20 |
ajaya | pip install --upgrade pip | 14:20 |
ajaya | does not work. | 14:20 |
ajaya | Need to do something else | 14:20 |
*** Ephur has joined #openstack-keystone | 14:24 | |
*** hrou has joined #openstack-keystone | 14:26 | |
*** su_zhang has quit IRC | 14:28 | |
*** tellesnobrega_af is now known as tellesnobrega | 14:31 | |
*** akanksha_ has joined #openstack-keystone | 14:37 | |
*** RA_ has quit IRC | 14:41 | |
dstanek | ajaya: did you get it working yet? | 14:43 |
dstanek | ajaya: make sure you have the latest pbr too | 14:44 |
*** e0ne has quit IRC | 14:48 | |
ajaya | dstanek, tjcocozz I did that. Still I am not able to run the tests. Here is the log. http://paste.openstack.org/show/477860/ | 14:48 |
ajaya | I mean I installed pbr too. | 14:48 |
ajaya | So to summarize I upgraded setuptools, pip, virtualenv and installed tox with apt-get, installed pbr with pip. | 14:49 |
dstanek | ajaya: did you install pbr using the system pip? | 14:52 |
ajaya | nope. Installed it using upgraded pip. | 14:52 |
openstackgerrit | Brant Knudson proposed openstack/keystoneauth: Migrate kerberos plugin https://review.openstack.org/240458 | 14:52 |
openstackgerrit | Brant Knudson proposed openstack/keystoneauth: Correct references in authentication-plugin.rst https://review.openstack.org/241229 | 14:53 |
ajaya | pbr==1.8.1 | 14:53 |
dstanek | ajaya: but the pip at the system level? as in "sudo pip install -U pbr"? | 14:53 |
openstackgerrit | Brant Knudson proposed openstack/keystoneauth: Correct references in authentication-plugin.rst https://review.openstack.org/241229 | 14:53 |
ajaya | Yes. I ran "sudo pip install pbr" | 14:54 |
ajaya | dstanek ^^ | 14:54 |
openstackgerrit | Brant Knudson proposed openstack/keystoneauth: Migrate kerberos plugin https://review.openstack.org/240458 | 14:55 |
ajaya | Let me run devstack once. | 14:55 |
dstanek | ajaya: can you recreate your env and paste the entire output (command + stdout + stderr) | 14:56 |
*** tonytan4ever has joined #openstack-keystone | 14:58 | |
*** jrist has quit IRC | 14:59 | |
*** phalmos has joined #openstack-keystone | 14:59 | |
*** phalmos has quit IRC | 14:59 | |
mordred | bknudson: I know you're just copying stuff in - but I REALLY want to actually code review part of that | 15:02 |
*** e0ne has joined #openstack-keystone | 15:03 | |
*** tellesnobrega is now known as tellesnobrega_af | 15:03 | |
mordred | bknudson: so I'm going to do that - and feel free to ignore me | 15:04 |
bknudson | mordred: there's not much to it... for some reason there are more test classes than the plugin. | 15:05 |
ajaya | dstanek, http://paste.openstack.org/show/477863/ | 15:05 |
ajaya | There was nothing in the err.log file. | 15:05 |
bknudson | maybe I should put all the test code into 1 module. | 15:06 |
mordred | bknudson: I have made my -1 | 15:09 |
mordred | also - hrm. we have a problem in that repo with cores and company affiliation | 15:09 |
*** jrist has joined #openstack-keystone | 15:09 | |
*** woodster_ has joined #openstack-keystone | 15:09 | |
mordred | if we're going to keep to that as a rule | 15:09 |
*** btully has joined #openstack-keystone | 15:09 | |
bknudson | mordred: keystone is going to get kicked out of openstack if we don't watch it. | 15:10 |
mordred | bknudson: heh. it's not going to get kicked out - it just may lose the diverse-affiiation tag | 15:11 |
mordred | bknudson: and no worries - IBM is only up to 39% of reviews and 35% of commits - that's still pretty diverse compared to the problem projects | 15:12 |
*** pumaranikar has joined #openstack-keystone | 15:12 | |
*** fhubik_brb is now known as fhubik | 15:12 | |
ajaya | dstanek, tjcocozz I upgraded tox now and it seems to be running for a while which means it's downloading the deps. | 15:14 |
ajaya | So seems like the problem is solved. | 15:15 |
tjcocozz | \o/ | 15:15 |
ajaya | moral of the story, Upgrade everything you can. :) | 15:16 |
*** doug-fis_ has quit IRC | 15:21 | |
ajaya | dstanek, Unit tests are running fine now. Thanks for the pbr hint. :) | 15:21 |
*** nisha_ has joined #openstack-keystone | 15:22 | |
*** fhubik is now known as fhubik_brb | 15:23 | |
*** nisha has quit IRC | 15:23 | |
*** dims has quit IRC | 15:24 | |
*** dims has joined #openstack-keystone | 15:24 | |
*** timcline has joined #openstack-keystone | 15:26 | |
*** markvoelker has joined #openstack-keystone | 15:26 | |
dstanek | ajaya: yw | 15:29 |
*** markvoelker has quit IRC | 15:31 | |
*** csoukup has joined #openstack-keystone | 15:31 | |
openstackgerrit | Brant Knudson proposed openstack/keystoneauth: Migrate kerberos plugin https://review.openstack.org/240458 | 15:36 |
*** jistr has quit IRC | 15:37 | |
*** e0ne has quit IRC | 15:37 | |
*** jvarlamova_ has quit IRC | 15:37 | |
*** jvarlamova_ has joined #openstack-keystone | 15:38 | |
openstackgerrit | gordon chung proposed openstack/pycadf: make generate_uuid return valid uuid https://review.openstack.org/240979 | 15:38 |
*** slberger has joined #openstack-keystone | 15:38 | |
*** HenryG has quit IRC | 15:40 | |
*** HenryG has joined #openstack-keystone | 15:41 | |
*** pgbridge has joined #openstack-keystone | 15:44 | |
*** browne has joined #openstack-keystone | 15:44 | |
*** nisha_ has quit IRC | 15:45 | |
*** nisha has joined #openstack-keystone | 15:46 | |
*** ajaya has quit IRC | 15:47 | |
samueldmq | ayoung: is there a concept of admin_domain (for domain operations) ? or is it just an admin project ? | 15:47 |
ayoung | samueldmq, I'm going to limit it to admin project. We are phasing out domain scoped tokens | 15:47 |
lbragstad | dolphm I was able to talk to mtreinish about this on friday - https://review.openstack.org/#/c/231191/ | 15:49 |
samueldmq | ayoung: hmm, didn't we decide to keep domain as it is for now? I mean, we change the way we represent them inside keystone, but the API remains the same | 15:50 |
lbragstad | dolphm i'm going to propose another ps to move the sleep from the client into the test cases | 15:50 |
ayoung | samueldmq, yeah, but we don't need domain scoped tokens for most operations. We can use project scoped tokens for all | 15:50 |
*** nate_gone is now known as njohnston | 15:52 | |
samueldmq | ayoung: it's like global admin was breaking both i) isolation between projects/domains (a project admin could touch another projets) and ii) not respecting the difference between domains and projects (touch domain with project scope) | 15:53 |
openstackgerrit | Merged openstack/keystoneauth: Updated from global requirements https://review.openstack.org/239068 | 15:54 |
samueldmq | ayoung: and now we are fixing only i) , since we still allow ii) to happen, by keeping domain operations possible with project scoped tokens | 15:54 |
ayoung | samueldmq, so scope from the project should be used for auth, but not for scoping the call. If the domain doesn't match and it is an admin call, it needs to go through anyway, so, don;'t need admin domain, just projecty | 15:54 |
ayoung | plus it makes things better for Horizon | 15:55 |
*** rderose has joined #openstack-keystone | 15:55 | |
*** amakarov has joined #openstack-keystone | 15:55 | |
samueldmq | ayoung: yeah I understand; wht I wonder is if we should allow 'god mode' from domain tokens as well, besides project tokens | 15:56 |
ayoung | samueldmq, nah | 15:57 |
samueldmq | ayoung: would be much similar with waht we hve today, but only constrained to admin project/domain | 15:57 |
ayoung | we should not use domain scoped tokens anymore...we can do all we need with project scoped | 15:57 |
*** su_zhang has joined #openstack-keystone | 15:57 | |
samueldmq | ayoung: kindof, we will still check the domain scoping; but it will be (project_id_matches and project:is_domain) rather than just (domain_id_matches) | 15:58 |
ayoung | samueldmq, exactly | 15:58 |
*** henrynash has joined #openstack-keystone | 15:59 | |
*** ChanServ sets mode: +v henrynash | 15:59 | |
*** phalmos has joined #openstack-keystone | 15:59 | |
*** petertr7 is now known as petertr7_away | 16:01 | |
samueldmq | ayoung: do we expect a domain exclusively for the admin project ? or the admin project can be wherever ? | 16:01 |
*** jistr has joined #openstack-keystone | 16:01 | |
ayoung | samueldmq, gah...can't multitask right now... | 16:01 |
*** njohnston is now known as nate_gone | 16:02 | |
samueldmq | ayoung: that's okay, can talk later | 16:02 |
*** petertr7_away is now known as petertr7 | 16:03 | |
*** topol has joined #openstack-keystone | 16:03 | |
*** ChanServ sets mode: +v topol | 16:03 | |
*** phalmos has quit IRC | 16:04 | |
*** fhubik_brb is now known as fhubik | 16:10 | |
*** tobberyd_ has quit IRC | 16:11 | |
*** su_zhang has quit IRC | 16:12 | |
*** petertr7 is now known as petertr7_away | 16:12 | |
*** dhellmann has quit IRC | 16:16 | |
*** dhellmann has joined #openstack-keystone | 16:18 | |
*** petertr7_away is now known as petertr7 | 16:19 | |
*** dims_ has joined #openstack-keystone | 16:24 | |
*** josecastroleon has quit IRC | 16:24 | |
*** dims has quit IRC | 16:24 | |
*** kodokuu has joined #openstack-keystone | 16:25 | |
*** tellesnobrega_af is now known as tellesnobrega | 16:27 | |
*** ccard has joined #openstack-keystone | 16:27 | |
*** ajaya has joined #openstack-keystone | 16:28 | |
openstackgerrit | Merged openstack/keystone-specs: Improve get project query strings https://review.openstack.org/235971 | 16:30 |
*** ninag has joined #openstack-keystone | 16:30 | |
*** diazjf has joined #openstack-keystone | 16:30 | |
*** jsavak has joined #openstack-keystone | 16:31 | |
*** chrisshattuck has joined #openstack-keystone | 16:33 | |
*** gyee has joined #openstack-keystone | 16:34 | |
*** ChanServ sets mode: +v gyee | 16:34 | |
krotscheck | bknudson: About https://review.openstack.org/#/c/237062 -> I'm hesitant to add a revert commit of a feature that shipped with liberty, without approval of the replacement. Would you prefer I split this into two patches? | 16:34 |
bknudson | krotscheck: you can mark it a work in progress to keep it from being merged without the follow-on. | 16:35 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Manager support for projects acting as domains https://review.openstack.org/213448 | 16:37 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Add is_domain parameter to get_project_by_name https://review.openstack.org/210600 | 16:37 |
*** fhubik is now known as fhubik_brb | 16:39 | |
*** jbell8 has joined #openstack-keystone | 16:41 | |
*** markvoelker has joined #openstack-keystone | 16:45 | |
*** lsmola has quit IRC | 16:46 | |
*** aix has quit IRC | 16:48 | |
*** akanksha_ has quit IRC | 16:48 | |
*** c_soukup has joined #openstack-keystone | 16:50 | |
*** c_soukup has quit IRC | 16:51 | |
*** csoukup has quit IRC | 16:54 | |
*** fhubik_brb is now known as fhubik | 16:54 | |
*** fhubik is now known as fhubik_brb | 16:55 | |
openstackgerrit | gordon chung proposed openstack/keystonemiddleware: use the same context across a request https://review.openstack.org/216889 | 16:55 |
*** ryanpetrello has joined #openstack-keystone | 16:57 | |
ryanpetrello | o/ hey keystone folks | 16:57 |
ryanpetrello | has anybody ever asked for the ability to specify tenant uuid at creation time via the REST API? | 16:57 |
ryanpetrello | i.e., `tenant create --uuid <something-specific>" | 16:57 |
ryanpetrello | where something specific passes some validation, of course | 16:57 |
*** su_zhang has joined #openstack-keystone | 16:59 | |
*** jbell8 has quit IRC | 16:59 | |
*** petertr7 is now known as petertr7_away | 17:00 | |
*** fhubik_brb is now known as fhubik | 17:01 | |
*** fhubik has quit IRC | 17:01 | |
ryanpetrello | I suppose instead of "tenant uuid", I should really say "project ID" | 17:05 |
ryanpetrello | it looks like keystone just randomly generates this now: https://github.com/openstack/keystone/blob/6f8c99b72e29608bb1ae7b19a97e90db105ae853/keystone/resource/controllers.py#L217 | 17:06 |
*** jvarlamova_ has quit IRC | 17:07 | |
*** gordc has quit IRC | 17:10 | |
*** su_zhang has quit IRC | 17:10 | |
*** gordc has joined #openstack-keystone | 17:14 | |
*** csoukup has joined #openstack-keystone | 17:14 | |
openstackgerrit | henry-nash proposed openstack/keystone: Provide storage for new inheritance assignment https://review.openstack.org/241301 | 17:17 |
*** nisha has quit IRC | 17:22 | |
openstackgerrit | henry-nash proposed openstack/keystone: Provide storage for new inheritance assignment https://review.openstack.org/241301 | 17:23 |
*** henrynash has quit IRC | 17:25 | |
*** jbell8 has joined #openstack-keystone | 17:26 | |
*** Ephur has quit IRC | 17:27 | |
*** rderose has quit IRC | 17:29 | |
*** phalmos has joined #openstack-keystone | 17:30 | |
*** jsavak has quit IRC | 17:35 | |
*** kodokuu has quit IRC | 17:35 | |
*** jsavak has joined #openstack-keystone | 17:37 | |
openstackgerrit | Merged openstack/keystone: Updated from global requirements https://review.openstack.org/239019 | 17:40 |
*** pnavarro has quit IRC | 17:41 | |
*** nate_gone is now known as njohnston | 17:41 | |
openstackgerrit | Merged openstack/keystone: I18n safe exceptions https://review.openstack.org/240273 | 17:43 |
*** spandhe has joined #openstack-keystone | 17:44 | |
openstackgerrit | Michael Krotscheck proposed openstack/keystone: Revert "Added CORS support to Keystone" https://review.openstack.org/241316 | 17:46 |
openstackgerrit | Michael Krotscheck proposed openstack/keystone: Added CORS support to Keystone https://review.openstack.org/241317 | 17:46 |
*** hrou has quit IRC | 17:46 | |
*** tonytan4ever has quit IRC | 17:48 | |
*** jasonsb has quit IRC | 17:49 | |
*** njohnston is now known as nate_gone | 17:50 | |
*** petertr7_away is now known as petertr7 | 17:52 | |
*** hrou has joined #openstack-keystone | 17:52 | |
ayoung | ryanpetrello, I had one along those lines, for resurrecting a deleted project, but why would you want it? | 17:53 |
ryanpetrello | I discussed with you at the summit some of the multi-side stuff we're doing | 17:54 |
ryanpetrello | we have an older Juno cluster that can't take advantage of some of the newer stuff | 17:54 |
ryanpetrello | and we'd love a setup where the project ID is the same *across* clusters for the same customer | 17:54 |
ryanpetrello | *right now* our clusters have distinct keystones that have no knowledge of eachother | 17:55 |
ryanpetrello | it would *be nice* for us to be able to choose project IDs ourselves without any sort of database level replication stuff | 17:56 |
ryanpetrello | went to a few talks at the summit from folks who'd encountered a similar problem and has expressed a desire for this sort of thing, too | 17:56 |
*** phalmos has quit IRC | 17:59 | |
dstanek | no meeting today? | 18:00 |
ryanpetrello | ayoung: looking at the keystone code, it seems like a pretty easy thing to accomplish | 18:00 |
ryanpetrello | so I figured I'd gauge interest | 18:00 |
lbragstad | dstanek not sure, I was just looking | 18:01 |
gyee | dstanek, not sure | 18:01 |
lbragstad | looks like we do | 18:01 |
lbragstad | we have items on the agenda | 18:01 |
dstanek | maybe Steve forgot about the time change? | 18:01 |
lbragstad | possibly | 18:02 |
*** su_zhang has joined #openstack-keystone | 18:02 | |
ayoung | ryanpetrello, question is just how to make sure it doesn't open up other holes. Make it a spec and we can discuss | 18:03 |
gyee | ayoung, rynpetrello, if we do open that up, for the folks who do replication, there would be a chance for conflict right, like two project created in two clusters with the exact same ID | 18:05 |
gyee | though the chances are low | 18:05 |
*** su_zhang has quit IRC | 18:07 | |
*** tonytan4ever has joined #openstack-keystone | 18:07 | |
*** ChanServ sets mode: +o dolphm | 18:07 | |
*** petertr7 is now known as petertr7_away | 18:07 | |
*** su_zhang has joined #openstack-keystone | 18:11 | |
amakarov | lbragstad, o/ | 18:20 |
amakarov | lbragstad, can you please give me a link to your rotation script? | 18:20 |
lbragstad | amakarov o/ rotation or distribution? | 18:20 |
lbragstad | amakarov this is the rotate + distribution script that osa uses - https://github.com/openstack/openstack-ansible/blob/master/playbooks/roles/os_keystone/templates/keystone-fernet-rotate.sh.j2 | 18:21 |
amakarov | lbragstad, rotation | 18:21 |
amakarov | lbragstad, thank you! | 18:22 |
lbragstad | amakarov no problem! | 18:22 |
openstackgerrit | gordon chung proposed openstack/keystonemiddleware: use the same context across a request https://review.openstack.org/216889 | 18:22 |
*** jsavak has quit IRC | 18:24 | |
*** jsavak has joined #openstack-keystone | 18:24 | |
*** jsavak has quit IRC | 18:28 | |
*** jsavak has joined #openstack-keystone | 18:30 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Move region configuration to a critical section https://review.openstack.org/222173 | 18:34 |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Move region configuration to a critical section https://review.openstack.org/222173 | 18:34 |
*** phalmos has joined #openstack-keystone | 18:36 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Removes project.domain_id FK https://review.openstack.org/233274 | 18:38 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Change project name constraints https://review.openstack.org/158372 | 18:38 |
*** jistr has quit IRC | 18:39 | |
*** mylu has joined #openstack-keystone | 18:41 | |
*** jasonsb has joined #openstack-keystone | 18:45 | |
*** mylu has quit IRC | 18:45 | |
*** rmstar has joined #openstack-keystone | 18:48 | |
dstanek | topol: i have motivation to not mention them....did you see my team? | 18:48 |
*** haneef has joined #openstack-keystone | 18:48 | |
*** rmstar has left #openstack-keystone | 18:49 | |
*** jasonsb has quit IRC | 18:49 | |
*** rmstar has joined #openstack-keystone | 18:49 | |
topol | dstanek :-).. I feel your pain | 18:50 |
topol | dstanek could be worse. we could be 49ers fans | 18:51 |
dstanek | topol: i'm not sure what was worse 25 hours of travel to get home from Tokyo or 3 hours at the Browns stadium | 18:51 |
topol | dstanek, Doh!!! | 18:51 |
topol | sorry friend | 18:52 |
topol | dstanek Austin will be much easier for the next summit | 18:52 |
gyee | dstanek, do you go to the game with a brown bag over your head? | 18:53 |
dstanek | gyee: not yet, but after the devastating loss they will suffer this Thursday, I may have to | 18:54 |
topol | dstanek, dolphm ever goto to defrag? http://defragcon.com/ | 18:54 |
dstanek | never heard of it | 18:55 |
topol | K, Im going for the first time next week. I figured Tokyo just wasnt enough travel for me | 18:55 |
*** shaleh has joined #openstack-keystone | 18:55 | |
dstanek | topol: i've never need a conference that is 75%+ keynotes | 18:57 |
dstanek | ego stroking at its finest! | 18:58 |
bknudson | dstanek: did johnny football play? | 19:00 |
bknudson | I thought he was in trouble for something again | 19:00 |
*** ninag has quit IRC | 19:00 | |
ayoung | ryanpetrello, I didn;t forget you...just lots of demands for my attention at the moment. | 19:01 |
dstanek | bknudson: for a second... our QB was visibly hurt most of the game and they still didn't feel he should go it... not a good sign | 19:01 |
topol | dstanel... interesting. Never been there before. But will let you know what I experience | 19:01 |
dstanek | bknudson: i think he'a dud and they don't want to show anyone so they can get decent trade value for him | 19:01 |
ayoung | I'm not certin if having the project ids in sync is the right approach or not. with K2K auth, you would start with the local project id, and end up with a token for the remote. Mapping from one to the other, but not keeping them in sync | 19:01 |
dstanek | topol: do you have a keynote there? | 19:01 |
*** jaosorior has quit IRC | 19:02 | |
*** ninag has joined #openstack-keystone | 19:02 | |
topol | dstanek, no I'm hosting a cloud huddle which is a bolt on meeting | 19:02 |
bknudson | we should have the keystone midcycle at a swank resort | 19:02 |
shaleh | did I miss the move of the keystone meeting? | 19:02 |
topol | shaleh, yes :-) | 19:02 |
topol | time change | 19:03 |
dstanek | shaleh: it didn't move. your local time moved | 19:03 |
ayoung | ryanpetrello, and having two Keystones manage tje same project might be weird. I could see and admin call to sync, though. | 19:03 |
dstanek | bknudson: days inn? | 19:03 |
shaleh | so it is noon for PDT? | 19:03 |
*** jsavak has quit IRC | 19:03 | |
ryanpetrello | ayoung: our intention at this point is actually exactly that | 19:03 |
ryanpetrello | two have two distinct geographically distant keystones that have no knowledge of eachother | 19:03 |
ryanpetrello | *to have two | 19:04 |
bknudson | dstanek: no, like defrag does : http://www.omnihotels.com/hotels/denver-interlocken/meetings/defrag-llc-2015 | 19:04 |
ryanpetrello | our public cloud customers may belong to one or more | 19:04 |
*** jasonsb has joined #openstack-keystone | 19:04 | |
ayoung | ryanpetrello, post a spec for it. I suspect K2K is a better fit | 19:04 |
ryanpetrello | but we'd like the project ID to be the same in each if they're a member of both | 19:04 |
bknudson | I thought san antonio waterfront was pretty swank. | 19:04 |
ryanpetrello | k2k? | 19:04 |
ryanpetrello | the federation stuff? | 19:04 |
dstanek | shaleh: 18:00 UTC | 19:04 |
shaleh | dstanek: thanks | 19:04 |
*** jsavak has joined #openstack-keystone | 19:05 | |
topol | bknudson, Im guessing Imnot using the pool in Nivember... in Colorado | 19:05 |
topol | bknudson, its not like I grew up in Minnesota | 19:05 |
*** ninag_ has joined #openstack-keystone | 19:05 | |
*** ninag_ has quit IRC | 19:05 | |
*** ninag_ has joined #openstack-keystone | 19:05 | |
dstanek | topol: you should really give it a try | 19:05 |
topol | bknudson Im sure November in Colorado feels like summer to you | 19:06 |
bknudson | it feels like summer to me today in mn since it's 70 | 19:06 |
*** ninag has quit IRC | 19:07 | |
*** ninag_ has quit IRC | 19:11 | |
*** hrou has quit IRC | 19:11 | |
*** e0ne has joined #openstack-keystone | 19:14 | |
*** marzif has joined #openstack-keystone | 19:17 | |
*** phalmos has quit IRC | 19:18 | |
*** tobberydberg has joined #openstack-keystone | 19:18 | |
*** diazjf has quit IRC | 19:19 | |
*** alejandrito has quit IRC | 19:21 | |
dolphm | tophave not heard of it either | 19:21 |
dolphm | topol: ^ | 19:21 |
*** hrou has joined #openstack-keystone | 19:21 | |
*** petertr7_away is now known as petertr7 | 19:24 | |
*** marzif is now known as daemontool | 19:25 | |
*** phalmos has joined #openstack-keystone | 19:26 | |
topol | dolphm, k brad | 19:27 |
topol | dolphm thanks | 19:27 |
*** flwang has quit IRC | 19:27 | |
*** jasonsb has quit IRC | 19:29 | |
*** nate_gone is now known as njohnston | 19:29 | |
openstackgerrit | Sean Perry proposed openstack/keystone: Use unit.new_endpoint_ref consistently https://review.openstack.org/237758 | 19:33 |
shaleh | dstanek: I cleaned that patch up like we discussed. Hopefully I reached the right balance. | 19:34 |
shaleh | dstanek: I will update the others soon | 19:35 |
openstackgerrit | Sean Perry proposed openstack/keystone: Use unit.new_service_ref() consistently https://review.openstack.org/238283 | 19:35 |
*** gordc has quit IRC | 19:35 | |
openstackgerrit | Sean Perry proposed openstack/keystone: Use unit.new_region_ref() consistently https://review.openstack.org/238302 | 19:35 |
andrewbogott | ayoung: when you have a few minutes can you help advise about my transition away from ldap assignments? I’ve thought about it enough that I think I have specific questions now. | 19:36 |
*** Ephur has joined #openstack-keystone | 19:36 | |
ayoung | andrewbogott, sure. Fire away | 19:37 |
andrewbogott | ok. Here’s my outline of before and after, for starters: https://wikitech.wikimedia.org/wiki/Labs_keystone_roles | 19:38 |
andrewbogott | Not that you should read all of that :) | 19:38 |
andrewbogott | So, my first question is easy: | 19:38 |
ayoung | shhh Im reading | 19:38 |
andrewbogott | Are role names at this point pretty much arbitrary, are are there good default roles that I should lean towards? | 19:38 |
*** su_zhang has quit IRC | 19:39 | |
ayoung | andrewbogott, we just have admin and Member and _member_ | 19:39 |
andrewbogott | yeah, it’s that Member and _member_ that creeps me out :) | 19:39 |
*** jerrygb has quit IRC | 19:39 | |
*** njohnston is now known as nate_gone | 19:39 | |
andrewbogott | I think that what OS traditionally calls a ‘member’ is what we call ‘projectadmin' | 19:40 |
openstackgerrit | Ryan Petrello proposed openstack/keystone-specs: Spec for optional Project ID via the Project creation API. https://review.openstack.org/241346 | 19:40 |
*** jerrygb has joined #openstack-keystone | 19:40 | |
*** henrynash has joined #openstack-keystone | 19:41 | |
*** ChanServ sets mode: +v henrynash | 19:41 | |
*** rderose has joined #openstack-keystone | 19:41 | |
*** chrisshattuck has quit IRC | 19:43 | |
*** e0ne has quit IRC | 19:45 | |
*** jerrygb has quit IRC | 19:45 | |
*** jasonsb has joined #openstack-keystone | 19:48 | |
andrewbogott | ayoung: so, next question… I recall from an earlier conversation that 'Can also add and remove members and assign roles within project’ is somehow hard to implement as part of a role policy. Is that still true? | 19:50 |
ayoung | yep | 19:50 |
ayoung | andrewbogott, we have a plan, but it has not been implemented yet | 19:50 |
ayoung | andrewbogott, something along the lines of | 19:51 |
ayoung | https://review.openstack.org/#/c/240719/ | 19:51 |
*** petertr7 is now known as petertr7_away | 19:51 | |
*** petertr7_away is now known as petertr7 | 19:52 | |
andrewbogott | I don’t understand… doesn’t this fall under create_role/update_role? | 19:52 |
andrewbogott | Or does the policy decide who can create/delete roles but not who can assign roles? | 19:53 |
*** browne has quit IRC | 19:54 | |
*** jasonsb has quit IRC | 19:55 | |
ayoung | andrewbogott, the problem is that if you can assign any role within a project, you can make anyone admin | 19:55 |
*** jasonsb has joined #openstack-keystone | 19:55 | |
andrewbogott | admin of the project, or admin of the entire cloud? | 19:55 |
andrewbogott | oh, right, those are the same aren’t they | 19:55 |
andrewbogott | that is so strange | 19:57 |
andrewbogott | I thought that somehow domains were supposed to fix this | 19:57 |
*** jerrygb has joined #openstack-keystone | 19:57 | |
*** rderose has quit IRC | 19:59 | |
*** gyee has quit IRC | 20:00 | |
*** gordc has joined #openstack-keystone | 20:02 | |
andrewbogott | ayoung: so it sounds like I should introduce a new role (e.g. ‘user’) for my weird case of users who can view things about a project but not change things. And adopt the existing ‘Member’ role for users who can create/destroy instances. | 20:03 |
andrewbogott | Where does _member_ come in? | 20:03 |
ayoung | observer | 20:03 |
ayoung | that is what most peopel are calling it | 20:04 |
andrewbogott | ah, ok. | 20:04 |
andrewbogott | so, policy files have a thing called an ‘owner’. But I can’t make any sense of this: | 20:04 |
andrewbogott | "owner" : "user_id:%(user_id)s" | 20:04 |
andrewbogott | That looks to me like I’m an owner if my user id is my user id. | 20:05 |
bknudson | that's defining a rule | 20:05 |
ayoung | I didnt write that | 20:05 |
*** ninag has joined #openstack-keystone | 20:06 | |
*** ninag_ has joined #openstack-keystone | 20:08 | |
*** ninag_ has quit IRC | 20:08 | |
*** hongbin has joined #openstack-keystone | 20:09 | |
bknudson | andrewbogott: here's some docs... didn't merge for some reason: https://review.openstack.org/#/c/123862/4/doc/source/configuration.rst | 20:09 |
*** ninag has quit IRC | 20:10 | |
bknudson | here's the good stuff: http://docs.openstack.org/developer/oslo.policy/api/oslo_policy.html#module-oslo_policy.policy | 20:10 |
andrewbogott | I think it must just be that I don’t know what it means for an api object to have an owner | 20:10 |
*** ninag has joined #openstack-keystone | 20:10 | |
andrewbogott | I understand the syntax but not the intent | 20:10 |
bknudson | maybe the rule needs a better name. | 20:11 |
andrewbogott | bknudson: for me at least :) | 20:12 |
andrewbogott | ayoung: ok, so, we’ve established that having a cloud-wide admin user is easy (too easy!). Is creating other cloud-wide roles possible now? I had the impression that that was somehow a part of domain support, but now I don’t quite follow how that would work. | 20:13 |
bknudson | there's only a few apis that use owner | 20:14 |
bknudson | list_user_projects change_password list_groups_for_user ec2_* | 20:14 |
bknudson | that's in the default policy.json | 20:15 |
ayoung | andrewbogott, are you in favor of or agains cloud wide admin here? | 20:15 |
*** ninag has quit IRC | 20:15 | |
andrewbogott | bknudson: cool, I will ignore for now then :) | 20:15 |
andrewbogott | ayoung: um… both? I mean, I want users to be able to administrate their own projects. And /I/ want to be able to administrate all projects. | 20:16 |
bknudson | if you give yourself a role on a domain and set the role assignment to be inherited to projects then you can give yourself admin on all projects in the domain | 20:16 |
lbragstad | from a keystone perspective, i think http://governance.openstack.org/reference/tags/assert_follows-standard-deprecation.html looks fine | 20:17 |
andrewbogott | ok, great. So that’s how I can make a universal observer. | 20:17 |
ayoung | andrewbogott, admin is not scoped to anything, but all the other APIs are. If you want a universal observer, write it into the policy file. | 20:19 |
andrewbogott | ayoung: how can the policy file enforce a universal role when roles are bound to projects? | 20:21 |
ayoung | andrewbogott, roles are bound to projects....BY POLICY! | 20:21 |
andrewbogott | ah! | 20:21 |
andrewbogott | ok then :) | 20:21 |
andrewbogott | ok, time to define some new roles. | 20:23 |
andrewbogott | and write some backwards-compatibility gui code. Going to be a long time until we can actually switch to using Horizon :( | 20:23 |
*** tonytan4ever has quit IRC | 20:26 | |
*** erhudy has joined #openstack-keystone | 20:32 | |
*** slberger has left #openstack-keystone | 20:46 | |
*** tobberydberg has quit IRC | 20:50 | |
dstanek | ... lots of fail ... https://review.openstack.org/#/c/237658/ | 20:50 |
*** jdennis has quit IRC | 20:50 | |
hongbin | Hi, I need a help for one thing. I tried to reduce the token expiration time. I edit the config file /etc/keystone/keystone.conf and restart the key* processes in screen. It seems keystone doesn't pick up the new expiration time. Any idea? | 20:51 |
bknudson | dstanek: "# COMPAT(essex-3)" | 20:51 |
dstanek | bknudson: awesome right? | 20:52 |
bknudson | dstanek: let me dig out my essex-3 devstack and see how it worked. | 20:52 |
dstanek | bknudson: are you serious? | 20:52 |
bknudson | I'm not serious | 20:53 |
lbragstad | hongbin if you're using devstack the default is apache | 20:53 |
lbragstad | hongbin sudo service apache2 restart | 20:53 |
dstanek | :-) i actually thought you may have one hanging around | 20:53 |
dstanek | bknudson: the current behavior is a 500 - so they want to change it to a 501 | 20:53 |
hongbin | lbragstad: thx. Will give it a try | 20:54 |
*** boris-42 has joined #openstack-keystone | 20:55 | |
*** chrisshattuck has joined #openstack-keystone | 20:56 | |
*** roxanaghe has quit IRC | 20:56 | |
*** ajaya has quit IRC | 20:58 | |
*** topol has quit IRC | 20:58 | |
*** su_zhang has joined #openstack-keystone | 21:02 | |
*** hongbin has left #openstack-keystone | 21:03 | |
*** tonytan4ever has joined #openstack-keystone | 21:03 | |
*** hockeynut_afk has joined #openstack-keystone | 21:04 | |
*** jsavak has quit IRC | 21:06 | |
*** su_zhang has quit IRC | 21:07 | |
*** jsavak has joined #openstack-keystone | 21:07 | |
*** roxanaghe has joined #openstack-keystone | 21:09 | |
*** alex_xu has quit IRC | 21:10 | |
*** alex_xu has joined #openstack-keystone | 21:12 | |
*** jimbaker has quit IRC | 21:14 | |
*** jimbaker has joined #openstack-keystone | 21:14 | |
*** jimbaker has quit IRC | 21:15 | |
*** jimbaker has joined #openstack-keystone | 21:15 | |
* notmorgan lurks a little | 21:16 | |
notmorgan | sooooooooooooooooo | 21:16 |
*** jerrygb has quit IRC | 21:16 | |
*** alex_xu has quit IRC | 21:16 | |
*** gordc has quit IRC | 21:16 | |
*** slberger has joined #openstack-keystone | 21:17 | |
*** su_zhang has joined #openstack-keystone | 21:18 | |
*** nate_gone is now known as njohnston | 21:18 | |
*** hockeynut_afk has left #openstack-keystone | 21:19 | |
*** gordc has joined #openstack-keystone | 21:19 | |
*** flwang has joined #openstack-keystone | 21:21 | |
*** alex_xu has joined #openstack-keystone | 21:22 | |
dstanek | if you're notmorgan then who are you? | 21:22 |
*** mylu has joined #openstack-keystone | 21:23 | |
*** diazjf has joined #openstack-keystone | 21:24 | |
*** jamielennox|away is now known as jamielennox | 21:25 | |
*** jsavak has quit IRC | 21:28 | |
*** njohnston is now known as nate_gone | 21:28 | |
notmorgan | dstanek: defintely notmorgan | 21:30 |
notmorgan | actually... going to make this my permanent nick... | 21:30 |
notmorgan | because i seem to have less overlap with notmyname than with mordred | 21:30 |
notmorgan | irc channel wise | 21:30 |
notmyname | heh | 21:31 |
notmorgan | notmyname: it's true... | 21:32 |
* notmorgan joins #openstack-swift now... | 21:32 | |
*** jsavak has joined #openstack-keystone | 21:33 | |
*** su_zhang has quit IRC | 21:35 | |
*** dims_ has quit IRC | 21:37 | |
*** su_zhang has joined #openstack-keystone | 21:38 | |
notmyname | notmorgan: you'll just kill any tab-complete effectiveness for people talking to either of us :-) | 21:39 |
openstackgerrit | Sean Perry proposed openstack/keystone: Use unit.new_service_ref() consistently https://review.openstack.org/238283 | 21:40 |
notmorgan | notmyname: *evilgrin* | 21:41 |
notmorgan | notmyname: i mean... what? >> | 21:41 |
*** gyee has joined #openstack-keystone | 21:42 | |
*** ChanServ sets mode: +v gyee | 21:42 | |
openstackgerrit | Sean Perry proposed openstack/keystone: Use unit.new_region_ref() consistently https://review.openstack.org/238302 | 21:43 |
*** bandwidth has joined #openstack-keystone | 21:44 | |
bandwidth | can someone help me with that? : Downloading/unpacking .[ldap,memcache,mongodb] Could not find any downloads that satisfy the requirement .[ldap,memcache,mongodb] | 21:44 |
*** nate_gone is now known as njohnston | 21:45 | |
*** dims has joined #openstack-keystone | 21:48 | |
*** petertr7 is now known as petertr7_away | 21:52 | |
*** jsavak has quit IRC | 21:53 | |
openstackgerrit | Tom Cocozzello proposed openstack/keystone: Validate Distinguished Names https://review.openstack.org/241005 | 21:53 |
openstackgerrit | Tom Cocozzello proposed openstack/keystone: Change tests that are setting incorrect Distinguished Names https://review.openstack.org/241378 | 21:53 |
*** dims has quit IRC | 21:54 | |
*** jamielennox is now known as jamielennox|away | 21:55 | |
*** jsavak has joined #openstack-keystone | 21:56 | |
*** jsavak has quit IRC | 22:00 | |
*** mylu has quit IRC | 22:00 | |
*** mylu has joined #openstack-keystone | 22:01 | |
*** jsavak has joined #openstack-keystone | 22:01 | |
*** mylu has quit IRC | 22:01 | |
*** mylu has joined #openstack-keystone | 22:02 | |
*** Guest12181 has quit IRC | 22:03 | |
*** jdennis has joined #openstack-keystone | 22:04 | |
*** d0ugal has joined #openstack-keystone | 22:04 | |
*** d0ugal is now known as Guest98556 | 22:04 | |
*** jsavak has quit IRC | 22:05 | |
*** jsavak has joined #openstack-keystone | 22:06 | |
*** daemontool has quit IRC | 22:08 | |
openstackgerrit | Kent Wang proposed openstack/keystone: Support HEAD requests for v2 API https://review.openstack.org/241383 | 22:09 |
openstackgerrit | Olivier Pilotte proposed openstack/keystone: Accepts Group IDs from the IdP without domain https://review.openstack.org/210581 | 22:10 |
*** tellesnobrega is now known as tellesnobrega_af | 22:11 | |
*** mylu has quit IRC | 22:13 | |
*** mylu has joined #openstack-keystone | 22:13 | |
*** gordc has quit IRC | 22:15 | |
*** browne has joined #openstack-keystone | 22:15 | |
*** daemontool has joined #openstack-keystone | 22:16 | |
*** timcline has quit IRC | 22:17 | |
*** jerrygb has joined #openstack-keystone | 22:17 | |
bknudson | notmorgan: think we should have the keystone midcycle in LA? | 22:18 |
*** RA_ has joined #openstack-keystone | 22:18 | |
notmorgan | bknudson: I'd say Bay Area would be better. not much OpenStack (except Cisco? would Cisco sponsor?) folks in LA | 22:19 |
notmorgan | bknudson: i wont be living in LA much longer. LA also has miserable traffic. | 22:19 |
notmorgan | and if you're going to SCaLE you'll be in Pasadena anyway | 22:20 |
bknudson | take public transportation | 22:20 |
notmorgan | bknudson: public what? | 22:20 |
notmorgan | that stuff doesn't really exist here. | 22:21 |
notmorgan | :P | 22:21 |
*** jerrygb has quit IRC | 22:22 | |
*** roxanaghe has quit IRC | 22:23 | |
openstackgerrit | Kent Wang proposed openstack/keystone: Add Trusts unique constraint to remove duplicates https://review.openstack.org/239114 | 22:23 |
*** mylu has quit IRC | 22:23 | |
openstackgerrit | Kent Wang proposed openstack/keystone: Add Trusts unique constraint to remove duplicates https://review.openstack.org/239114 | 22:23 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Deprecate the pki and pkiz token providers. https://review.openstack.org/241389 | 22:24 |
*** mylu has joined #openstack-keystone | 22:26 | |
*** diazjf has left #openstack-keystone | 22:28 | |
*** su_zhang has quit IRC | 22:29 | |
*** chlong has quit IRC | 22:31 | |
*** jerrygb has joined #openstack-keystone | 22:32 | |
*** tellesnobrega_af is now known as tellesnobrega | 22:32 | |
*** mylu has quit IRC | 22:33 | |
*** mylu has joined #openstack-keystone | 22:34 | |
*** jsavak has quit IRC | 22:38 | |
*** mylu has quit IRC | 22:38 | |
*** jsavak has joined #openstack-keystone | 22:39 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Removes project.domain_id FK https://review.openstack.org/233274 | 22:39 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Change project name constraints https://review.openstack.org/158372 | 22:39 |
*** _cjones_ has quit IRC | 22:41 | |
*** fangzhou has joined #openstack-keystone | 22:44 | |
*** csoukup has quit IRC | 22:50 | |
*** su_zhang has joined #openstack-keystone | 22:55 | |
*** tonytan4ever has quit IRC | 22:58 | |
*** jamielennox|away is now known as jamielennox | 23:00 | |
jamielennox | this company based approval thing is going to be a PITA | 23:00 |
*** jbell8 has quit IRC | 23:01 | |
jamielennox | ayoung, notmorgan: can you have a look at the reviews starting https://review.openstack.org/#/c/236765/ | 23:01 |
jamielennox | there's a couple with 2 +2s | 23:01 |
openstackgerrit | Brant Knudson proposed openstack/keystone: More useful message when using direct driver import https://review.openstack.org/241403 | 23:07 |
*** jsavak has quit IRC | 23:15 | |
*** jsavak has joined #openstack-keystone | 23:15 | |
*** lhcheng has joined #openstack-keystone | 23:16 | |
*** ChanServ sets mode: +v lhcheng | 23:16 | |
*** jbell8 has joined #openstack-keystone | 23:17 | |
gyee | bknudson, notmorgan, big blue have an office in San Jose, we can do midcycle there | 23:19 |
*** pumaranikar has quit IRC | 23:20 | |
gyee | in sunny, dry, norcal | 23:20 |
jamielennox | gyee: can you have a look at https://review.openstack.org/#/c/236765/ and the follow on? | 23:21 |
gyee | jamielennox, sure, just got back to my desk | 23:21 |
gyee | gimme a min | 23:21 |
*** sileht has quit IRC | 23:24 | |
samueldmq | jamielennox: hey, do you have a minute to talk about v3 only gate/current state ? | 23:24 |
jamielennox | samueldmq: always | 23:24 |
samueldmq | jamielennox: nice, basically I'd like to know how far we are at this point, and what's missing | 23:25 |
jamielennox | samueldmq: it's passing, but it's only in the experimental gate on devstack | 23:25 |
samueldmq | jamielennox: I remember you had a chain of patches last cycle .. | 23:25 |
samueldmq | jamielennox: it's all passing now ? | 23:25 |
openstackgerrit | Olivier Pilotte proposed openstack/keystone: Accepts Group IDs from the IdP without domain https://review.openstack.org/210581 | 23:25 |
jamielennox | yep | 23:25 |
jamielennox | so we need a way to start pushing it out to other projects | 23:26 |
samueldmq | jamielennox: omg, nicely done! that's a huge step, congrats :D | 23:26 |
jamielennox | and probably remove it from the experimental queue on devstack | 23:26 |
*** dims has joined #openstack-keystone | 23:27 | |
jamielennox | samueldmq: there is a check experimental at the bottom of https://review.openstack.org/#/c/213430/ | 23:27 |
jamielennox | gate-tempest-dsvm-neutron-identity-v3-only-full SUCCESS in 50m 05s | 23:27 |
samueldmq | jamielennox: great! did you have too much trouble to make it happen ? | 23:28 |
jamielennox | if you want i think we should promote that to a full devstack voting job | 23:28 |
jamielennox | samueldmq: it took a while :) | 23:28 |
samueldmq | jamielennox: the last patches I remember were to make roles and things with v3 apis, and we had some trouble with another specific client | 23:28 |
samueldmq | jamielennox: anyway, it's working now .. everything with sessions ? | 23:28 |
*** jasonsb has quit IRC | 23:29 | |
jamielennox | yep | 23:29 |
jamielennox | so it's probably still going to fail with some of the less common services | 23:29 |
jamielennox | like i don't know how to configure ceilometer/sahara/trove etc | 23:29 |
samueldmq | jamielennox: that's understandable, have it working with the "core" services is a great step already | 23:30 |
*** dims has quit IRC | 23:30 | |
samueldmq | jamielennox: do you want me to promote that to the voting pipeline ? | 23:31 |
jamielennox | samueldmq: yea, that would be great | 23:31 |
samueldmq | jamielennox: or you want to do tht yourself ? (I'm fine either way) | 23:31 |
jamielennox | they might make you promote it from experimental -> non voting -> voting | 23:31 |
samueldmq | ++ | 23:32 |
samueldmq | jamielennox: is that patch needed (https://review.openstack.org/#/c/213430/) to make the gate pass ? | 23:32 |
samueldmq | jamielennox: I mean, do we need to get that merged before promoting the gate ? | 23:33 |
jamielennox | samueldmq: no it should be fine as is, i just needed a review to run the check on | 23:33 |
samueldmq | jamielennox: gah, no we don't .. just looked at the commit message | 23:33 |
*** chrisshattuck has quit IRC | 23:33 | |
samueldmq | jamielennox: yep, gonna work on this right now | 23:34 |
jamielennox | samueldmq: thanks | 23:34 |
samueldmq | jamielennox: thanks to you, I just helped with the gate bits :) | 23:35 |
*** hrou has quit IRC | 23:35 | |
*** gildub has quit IRC | 23:35 | |
*** bandwidth has quit IRC | 23:36 | |
*** jerrygb has quit IRC | 23:43 | |
*** roxanaghe has joined #openstack-keystone | 23:43 | |
*** josecastroleon has joined #openstack-keystone | 23:44 | |
*** mylu has joined #openstack-keystone | 23:47 | |
samueldmq | jamielennox: actually we can now add the gate job to several projects, right ? | 23:54 |
samueldmq | jamielennox: does that make sense ? maybe only for the clients ? | 23:54 |
jamielennox | samueldmq: we should be able to add it to at least nova, cinder and those things covered by the devstack job | 23:54 |
samueldmq | jamielennox: cool, adding it to devstack is definitely the first step, I expect others to not be afraid after that :) | 23:55 |
jamielennox | samueldmq: yep, nova is generally the most difficult after that but worth tackling first as the other projects just blindly accept what nova is doing | 23:56 |
samueldmq | jamielennox: nice, so nova is going to be next | 23:56 |
*** mylu has quit IRC | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!