*** roxanaghe has quit IRC | 00:00 | |
*** henrynash has quit IRC | 00:00 | |
navidp | jamielennox, yeah i ma just trying to first work the authentication then try to fix others | 00:00 |
---|---|---|
*** oomichi has quit IRC | 00:01 | |
*** RichardRaseley has quit IRC | 00:01 | |
navidp | jamielennox, thanks for your time. | 00:03 |
jamielennox | navidp: yep, i think you'll have to fix a couple of different projects, get it working and the see what they need | 00:03 |
jamielennox | navidp: any time | 00:03 |
navidp | jamielennox, :) | 00:04 |
*** daemontool_ has quit IRC | 00:04 | |
*** dims has quit IRC | 00:04 | |
*** rbak has quit IRC | 00:04 | |
*** pushkaru has quit IRC | 00:05 | |
*** gordc has quit IRC | 00:06 | |
*** daemontool_ has joined #openstack-keystone | 00:06 | |
*** phalmos has quit IRC | 00:09 | |
*** _cjones_ has quit IRC | 00:12 | |
*** _cjones_ has joined #openstack-keystone | 00:12 | |
*** daemontool_ has quit IRC | 00:13 | |
*** lhcheng has joined #openstack-keystone | 00:14 | |
*** ChanServ sets mode: +v lhcheng | 00:14 | |
*** mylu has quit IRC | 00:15 | |
*** slberger has left #openstack-keystone | 00:22 | |
*** ebalduf has joined #openstack-keystone | 00:26 | |
*** mylu has joined #openstack-keystone | 00:37 | |
jamielennox | notmorgan: bknudson: we reverted all the caching changes to auth_token? | 00:37 |
*** shoutm_ has joined #openstack-keystone | 00:38 | |
*** shoutm has quit IRC | 00:39 | |
*** markvoelker has quit IRC | 00:51 | |
*** markvoelker has joined #openstack-keystone | 00:56 | |
*** EinstCrazy has quit IRC | 01:01 | |
*** gildub has quit IRC | 01:04 | |
*** ebalduf has quit IRC | 01:04 | |
*** spzala has quit IRC | 01:10 | |
*** mgarza has quit IRC | 01:10 | |
*** spzala has joined #openstack-keystone | 01:10 | |
*** mylu has quit IRC | 01:14 | |
*** spzala has quit IRC | 01:15 | |
*** shoutm_ has quit IRC | 01:17 | |
*** spzala has joined #openstack-keystone | 01:19 | |
*** shoutm has joined #openstack-keystone | 01:19 | |
*** lhcheng_ has joined #openstack-keystone | 01:30 | |
*** lhcheng has quit IRC | 01:31 | |
*** phalmos has joined #openstack-keystone | 01:35 | |
*** david-lyle has quit IRC | 01:36 | |
*** gildub has joined #openstack-keystone | 01:37 | |
*** shoutm_ has joined #openstack-keystone | 01:41 | |
*** phalmos has quit IRC | 01:42 | |
*** EinstCrazy has joined #openstack-keystone | 01:43 | |
*** shoutm has quit IRC | 01:44 | |
*** ninag has joined #openstack-keystone | 01:49 | |
*** _cjones_ has quit IRC | 01:50 | |
*** _cjones_ has joined #openstack-keystone | 01:50 | |
*** _cjones_ has quit IRC | 01:50 | |
*** _cjones_ has joined #openstack-keystone | 01:51 | |
*** lhcheng_ has quit IRC | 01:52 | |
*** ninag has quit IRC | 01:53 | |
*** lhcheng has joined #openstack-keystone | 01:53 | |
*** ChanServ sets mode: +v lhcheng | 01:53 | |
*** _cjones_ has quit IRC | 01:55 | |
*** fawadkhaliq has joined #openstack-keystone | 01:58 | |
*** fawadkhaliq has quit IRC | 01:59 | |
*** mylu has joined #openstack-keystone | 02:00 | |
*** topol has quit IRC | 02:10 | |
*** topol_ has joined #openstack-keystone | 02:12 | |
notmorgan | jamielennox: yes | 02:19 |
notmorgan | :( | 02:19 |
notmorgan | Some folks made a lot of noise and I wasn't awake to.fight the revert | 02:19 |
jamielennox | notmorgan: out of interest who cares? | 02:21 |
jamielennox | i saw devstack, but you had a fix for that | 02:21 |
notmorgan | This was folks in nova and other upstream projects complaint we needed to depreciate | 02:21 |
jamielennox | bah | 02:21 |
notmorgan | For 2/cycles cause omg it broke so much | 02:21 |
jamielennox | 2 cycles! | 02:22 |
notmorgan | Was a overreaction | 02:22 |
notmorgan | But I honestly was asleep. | 02:22 |
notmorgan | :( | 02:22 |
notmorgan | If I had been awake I would have halted the revert | 02:22 |
jamielennox | it broke testing because devstack - that's it | 02:22 |
jamielennox | wtf does nova etc care | 02:23 |
jamielennox | caching of pki certs got reverted as well | 02:23 |
*** dims has joined #openstack-keystone | 02:24 | |
jamielennox | hmm, ok brant has already proposed the deprecation | 02:24 |
*** daemontool has joined #openstack-keystone | 02:31 | |
*** browne has quit IRC | 02:32 | |
*** diazjf has joined #openstack-keystone | 02:33 | |
*** su_zhang has quit IRC | 02:35 | |
*** richm has quit IRC | 02:37 | |
*** jasonsb has joined #openstack-keystone | 02:39 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs: Time-based One-time Password https://review.openstack.org/130376 | 02:47 |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs: Add spec for multifactor authentication https://review.openstack.org/272287 | 02:47 |
*** e0ne has joined #openstack-keystone | 02:48 | |
*** alexvictorchan has quit IRC | 02:57 | |
*** spzala has quit IRC | 03:00 | |
*** spzala has joined #openstack-keystone | 03:01 | |
*** spandhe has quit IRC | 03:04 | |
*** spzala has quit IRC | 03:05 | |
*** diazjf has quit IRC | 03:08 | |
*** mylu has quit IRC | 03:14 | |
*** mylu has joined #openstack-keystone | 03:14 | |
*** spzala has joined #openstack-keystone | 03:15 | |
*** gokrokve has joined #openstack-keystone | 03:18 | |
*** browne has joined #openstack-keystone | 03:21 | |
*** gokrokve has quit IRC | 03:22 | |
*** mylu has quit IRC | 03:24 | |
*** dims has quit IRC | 03:30 | |
*** shoutm_ has quit IRC | 03:33 | |
*** mylu has joined #openstack-keystone | 03:33 | |
*** shoutm has joined #openstack-keystone | 03:40 | |
*** doug-fish has joined #openstack-keystone | 03:49 | |
ayoung | jamielennox, notmorgan Roles API. Cleaned up the controller, made the policy enforec admin only for all calls, and made a hardcoded check that admin could not be an implied role (only prior) https://review.openstack.org/#/c/242614/ | 04:00 |
*** markvoelker has quit IRC | 04:04 | |
*** gokrokve has joined #openstack-keystone | 04:05 | |
*** gokrokve has quit IRC | 04:10 | |
openstackgerrit | henry-nash proposed openstack/keystone: Allow project domain_id to be nullable at the manager level https://review.openstack.org/264533 | 04:14 |
openstackgerrit | henry-nash proposed openstack/keystone: Allow project domain_id to be nullable at the manager level https://review.openstack.org/264533 | 04:14 |
openstackgerrit | henry-nash proposed openstack/keystone: Verify project unique constraints for projects acting as domains https://review.openstack.org/158372 | 04:14 |
openstackgerrit | henry-nash proposed openstack/keystone: Add tests in preparation of projects acting as a domain https://review.openstack.org/272369 | 04:14 |
openstackgerrit | henry-nash proposed openstack/keystone: Projects acting as domains https://review.openstack.org/231289 | 04:14 |
*** henrynash has joined #openstack-keystone | 04:15 | |
*** ChanServ sets mode: +v henrynash | 04:15 | |
*** henrynash has quit IRC | 04:19 | |
openstackgerrit | fengzhr proposed openstack/keystone: The name can be just white character except project and user https://review.openstack.org/272358 | 04:20 |
*** spzala has quit IRC | 04:23 | |
*** spzala has joined #openstack-keystone | 04:24 | |
openstackgerrit | henry-nash proposed openstack/keystone: Projects acting as domains https://review.openstack.org/231289 | 04:24 |
*** david-lyle has joined #openstack-keystone | 04:25 | |
*** EinstCrazy has quit IRC | 04:25 | |
*** david-lyle has quit IRC | 04:25 | |
*** spzala has quit IRC | 04:28 | |
*** gokrokve has joined #openstack-keystone | 04:30 | |
*** gokrokve has quit IRC | 04:36 | |
*** david-lyle has joined #openstack-keystone | 04:37 | |
*** fpatwa has joined #openstack-keystone | 04:44 | |
*** fawadkhaliq has joined #openstack-keystone | 04:46 | |
*** fpatwa has quit IRC | 04:49 | |
*** vivekd has joined #openstack-keystone | 04:56 | |
*** ebalduf has joined #openstack-keystone | 05:01 | |
*** roxanaghe has joined #openstack-keystone | 05:03 | |
*** markvoelker has joined #openstack-keystone | 05:05 | |
openstackgerrit | henry-nash proposed openstack/keystone: Allow project domain_id to be nullable at the manager level https://review.openstack.org/264533 | 05:09 |
*** su_zhang has joined #openstack-keystone | 05:09 | |
openstackgerrit | henry-nash proposed openstack/keystone: Verify project unique constraints for projects acting as domains https://review.openstack.org/158372 | 05:09 |
*** markvoelker has quit IRC | 05:10 | |
openstackgerrit | henry-nash proposed openstack/keystone: Add tests in preparation of projects acting as a domain https://review.openstack.org/272369 | 05:11 |
openstackgerrit | henry-nash proposed openstack/keystone: Projects acting as domains https://review.openstack.org/231289 | 05:11 |
*** vivekd has quit IRC | 05:12 | |
*** vivekd has joined #openstack-keystone | 05:12 | |
*** pushkaru has joined #openstack-keystone | 05:16 | |
*** spandhe has joined #openstack-keystone | 05:17 | |
*** EinstCrazy has joined #openstack-keystone | 05:21 | |
*** spzala has joined #openstack-keystone | 05:24 | |
*** gokrokve has joined #openstack-keystone | 05:30 | |
*** spzala has quit IRC | 05:30 | |
*** fawadkhaliq has quit IRC | 05:31 | |
*** topol_ has quit IRC | 05:32 | |
*** e0ne has quit IRC | 05:33 | |
*** topol_ has joined #openstack-keystone | 05:34 | |
*** vivekd has quit IRC | 05:35 | |
notmorgan | jamielennox: yeah | 05:41 |
openstackgerrit | ChangBo Guo(gcb) proposed openstack/keystone: Use the oslo.utils.reflection to extract the class name https://review.openstack.org/241494 | 05:43 |
*** fawadkhaliq has joined #openstack-keystone | 05:47 | |
*** fawadkhaliq has quit IRC | 05:47 | |
*** EinstCrazy has quit IRC | 05:47 | |
*** ebalduf has quit IRC | 05:47 | |
*** EinstCrazy has joined #openstack-keystone | 05:48 | |
*** gokrokve has quit IRC | 05:49 | |
*** fawadkhaliq has joined #openstack-keystone | 05:50 | |
*** mylu has quit IRC | 06:00 | |
openstackgerrit | henry-nash proposed openstack/keystone: Allow project domain_id to be nullable at the manager level https://review.openstack.org/264533 | 06:01 |
openstackgerrit | henry-nash proposed openstack/keystone: Verify project unique constraints for projects acting as domains https://review.openstack.org/158372 | 06:02 |
openstackgerrit | henry-nash proposed openstack/keystone: Add tests in preparation of projects acting as a domain https://review.openstack.org/272369 | 06:03 |
*** spandhe has quit IRC | 06:05 | |
openstackgerrit | henry-nash proposed openstack/keystone: Projects acting as domains https://review.openstack.org/231289 | 06:05 |
*** vgridnev has joined #openstack-keystone | 06:07 | |
stevemar | who's online?! | 06:09 |
jamielennox | nope | 06:11 |
*** vivekd has joined #openstack-keystone | 06:12 | |
stevemar | jamielennox: you're on opposite time | 06:16 |
jamielennox | stevemar: not in my opinion | 06:17 |
stevemar | jamielennox: you have an opposite opinion | 06:17 |
*** Nirupama has joined #openstack-keystone | 06:18 | |
*** jaosorior has joined #openstack-keystone | 06:27 | |
*** spzala has joined #openstack-keystone | 06:27 | |
*** shoutm_ has joined #openstack-keystone | 06:28 | |
*** shoutm has quit IRC | 06:30 | |
*** spzala has quit IRC | 06:32 | |
*** spandhe has joined #openstack-keystone | 06:43 | |
*** spandhe_ has joined #openstack-keystone | 06:46 | |
*** roxanaghe has quit IRC | 06:47 | |
*** spandhe has quit IRC | 06:48 | |
*** spandhe_ is now known as spandhe | 06:48 | |
*** spandhe has left #openstack-keystone | 06:49 | |
*** spandhe has joined #openstack-keystone | 06:51 | |
*** jasonsb has quit IRC | 06:57 | |
openstackgerrit | Merged openstack/keystoneauth: Updated from global requirements https://review.openstack.org/272791 | 06:58 |
*** vgridnev has quit IRC | 07:00 | |
*** pushkaru has quit IRC | 07:05 | |
*** markvoelker has joined #openstack-keystone | 07:06 | |
openstackgerrit | Merged openstack/keystonemiddleware: Updated from global requirements https://review.openstack.org/272792 | 07:07 |
*** markvoelker has quit IRC | 07:11 | |
*** EinstCrazy has quit IRC | 07:12 | |
*** browne has quit IRC | 07:13 | |
*** belmoreira has joined #openstack-keystone | 07:15 | |
*** spandhe has quit IRC | 07:21 | |
*** EinstCrazy has joined #openstack-keystone | 07:22 | |
*** gokrokve has joined #openstack-keystone | 07:24 | |
*** rcernin has joined #openstack-keystone | 07:27 | |
openstackgerrit | Merged openstack/oslo.policy: Updated from global requirements https://review.openstack.org/272817 | 07:28 |
*** roxanaghe has joined #openstack-keystone | 07:28 | |
*** gokrokve has quit IRC | 07:28 | |
*** chlong_zzz is now known as chlong | 07:31 | |
*** roxanaghe has quit IRC | 07:33 | |
*** pnavarro has joined #openstack-keystone | 07:35 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/269479 | 07:36 |
*** vgridnev has joined #openstack-keystone | 07:38 | |
*** ninag has joined #openstack-keystone | 07:43 | |
*** ninag has quit IRC | 07:48 | |
openstackgerrit | Merged openstack/pycadf: Updated from global requirements https://review.openstack.org/272824 | 08:03 |
*** EinstCrazy has quit IRC | 08:05 | |
*** EinstCrazy has joined #openstack-keystone | 08:09 | |
*** lhcheng has quit IRC | 08:18 | |
*** su_zhang has quit IRC | 08:27 | |
*** spzala has joined #openstack-keystone | 08:28 | |
*** roxanaghe has joined #openstack-keystone | 08:29 | |
*** roxanaghe has quit IRC | 08:33 | |
*** spzala has quit IRC | 08:35 | |
*** gildub has quit IRC | 08:35 | |
*** vgridnev has quit IRC | 08:36 | |
*** shoutm_ has quit IRC | 08:38 | |
*** vgridnev has joined #openstack-keystone | 08:44 | |
*** vgridnev has quit IRC | 08:46 | |
*** fhubik has joined #openstack-keystone | 08:51 | |
*** markvoelker has joined #openstack-keystone | 09:07 | |
*** markvoelker has quit IRC | 09:12 | |
*** LZ has joined #openstack-keystone | 09:16 | |
*** woodster_ has quit IRC | 09:16 | |
*** jaosorior has quit IRC | 09:19 | |
*** jaosorior has joined #openstack-keystone | 09:20 | |
*** jaosorior has quit IRC | 09:25 | |
*** jaosorior has joined #openstack-keystone | 09:25 | |
*** spzala has joined #openstack-keystone | 09:31 | |
*** permalac has joined #openstack-keystone | 09:34 | |
*** spzala has quit IRC | 09:36 | |
*** mhickey has joined #openstack-keystone | 09:37 | |
*** jistr has joined #openstack-keystone | 09:43 | |
*** vgridnev has joined #openstack-keystone | 09:46 | |
*** david8hu has quit IRC | 09:48 | |
*** david8hu has joined #openstack-keystone | 09:48 | |
*** EinstCrazy has quit IRC | 09:55 | |
*** alex_xu has quit IRC | 09:56 | |
*** vgridnev has quit IRC | 09:57 | |
*** aix has joined #openstack-keystone | 09:57 | |
*** alex_xu has joined #openstack-keystone | 09:58 | |
*** vgridnev has joined #openstack-keystone | 09:58 | |
*** vgridnev has quit IRC | 09:58 | |
*** vgridnev has joined #openstack-keystone | 10:00 | |
*** lhcheng has joined #openstack-keystone | 10:06 | |
*** ChanServ sets mode: +v lhcheng | 10:06 | |
*** markvoelker has joined #openstack-keystone | 10:08 | |
*** davechen has joined #openstack-keystone | 10:08 | |
*** lhcheng has quit IRC | 10:11 | |
*** markvoelker has quit IRC | 10:13 | |
*** lhcheng has joined #openstack-keystone | 10:14 | |
*** ChanServ sets mode: +v lhcheng | 10:14 | |
*** davechen1 has joined #openstack-keystone | 10:17 | |
*** davechen has quit IRC | 10:19 | |
*** roxanaghe has joined #openstack-keystone | 10:24 | |
*** davechen has joined #openstack-keystone | 10:26 | |
*** roxanaghe has quit IRC | 10:28 | |
*** davechen1 has quit IRC | 10:30 | |
*** spzala has joined #openstack-keystone | 10:32 | |
*** spzala has quit IRC | 10:37 | |
*** shoutm has joined #openstack-keystone | 10:37 | |
*** lhcheng has quit IRC | 10:38 | |
openstackgerrit | Dave Chen proposed openstack/keystone: Create V9 version of catalog driver interface https://review.openstack.org/269455 | 10:49 |
samueldmq | davechen: hey | 10:52 |
davechen | samueldmq: hey, hey | 10:53 |
davechen | samueldmq: are you in summit? | 10:53 |
davechen | sorry | 10:54 |
davechen | mid cycle | 10:54 |
openstackgerrit | Dave Chen proposed openstack/keystone: Create V9 version of catalog driver interface https://review.openstack.org/269455 | 10:54 |
samueldmq | davechen: yes I am, you too ? | 10:55 |
davechen | samueldmq: no, too far, no budget. :-( | 10:55 |
davechen | samueldmq: how is going? | 10:56 |
samueldmq | davechen: :-( | 10:56 |
davechen | samueldmq: Have you relocated to US? | 10:56 |
davechen | samueldmq: it's fine, Brazil is close to US. :) | 10:57 |
*** gokrokve has joined #openstack-keystone | 11:02 | |
*** davechen1 has joined #openstack-keystone | 11:04 | |
samueldmq | davechen: no I didn't do yet | 11:05 |
samueldmq | davechen: yes, not too far | 11:06 |
*** davechen has quit IRC | 11:06 | |
*** gokrokve has quit IRC | 11:06 | |
*** davechen1 is now known as davechen | 11:07 | |
davechen | samueldmq: see many friends there? Haven't visited Austin last time, but I guess it's fantastic place. | 11:10 |
davechen | samueldmq: maybe have a travel in San Antonio too. :) | 11:11 |
samueldmq | davechen: looks to be a great place, I arrived yesterday and haven't have a chance to visit some places yet | 11:13 |
davechen | samueldmq: have a good rest. | 11:15 |
samueldmq | davechen: I did, and actually woke up early :) | 11:17 |
samueldmq | davechen: 5 am here | 11:17 |
davechen | samueldmq: why wake up so early, if it was me i will sleep all the morning. | 11:18 |
davechen | samueldmq: i't might be very quiet there, how stevemar will treat you guys? :) | 11:20 |
samueldmq | davechen: very quiet at midcycle ? | 11:21 |
davechen | samueldmq: quiet in the morning. | 11:21 |
davechen | everyone is sleeping. | 11:21 |
*** fhubik has quit IRC | 11:22 | |
samueldmq | yes | 11:22 |
*** e0ne has joined #openstack-keystone | 11:22 | |
davechen | ask stevemar to take some beer in the midcycle. | 11:22 |
*** davechen1 has joined #openstack-keystone | 11:25 | |
*** davechen has quit IRC | 11:27 | |
*** davechen1 is now known as davechen | 11:30 | |
*** spzala has joined #openstack-keystone | 11:33 | |
*** spzala has quit IRC | 11:38 | |
openstackgerrit | Dave Chen proposed openstack/keystone: Create V9 version of catalog driver interface https://review.openstack.org/269455 | 11:40 |
openstackgerrit | Dave Chen proposed openstack/keystone: Service Providers and Projects associations https://review.openstack.org/264854 | 11:40 |
*** fawadkhaliq has quit IRC | 11:42 | |
*** fawadkhaliq has joined #openstack-keystone | 11:42 | |
*** aix has quit IRC | 11:43 | |
*** pcaruana has joined #openstack-keystone | 11:44 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Improve Development Environment Docs https://review.openstack.org/246400 | 11:50 |
*** clenimar has joined #openstack-keystone | 11:52 | |
*** reddy has joined #openstack-keystone | 11:57 | |
reddy | Hi. can someone help me in one doubt about keystone authentication method. Q: if i integrate LDAP to my openstack environment and if i want to use horizon login screen to authenticate both openstack and other servers outside openstack at same time ? | 12:00 |
reddy | just want to know is it possible that i can use same login details for authenticating openstack and another application at same time from horizon login screen | 12:02 |
*** jsheeren has joined #openstack-keystone | 12:04 | |
*** vgridnev has quit IRC | 12:07 | |
*** markvoelker has joined #openstack-keystone | 12:09 | |
*** pauloewerton has joined #openstack-keystone | 12:09 | |
*** vgridnev has joined #openstack-keystone | 12:10 | |
*** davechen has left #openstack-keystone | 12:13 | |
*** markvoelker has quit IRC | 12:14 | |
*** vgridnev has quit IRC | 12:15 | |
*** roxanaghe has joined #openstack-keystone | 12:18 | |
*** daemontool has quit IRC | 12:19 | |
*** vgridnev has joined #openstack-keystone | 12:21 | |
*** dims has joined #openstack-keystone | 12:23 | |
*** roxanaghe has quit IRC | 12:23 | |
*** aix has joined #openstack-keystone | 12:25 | |
*** gordc has joined #openstack-keystone | 12:29 | |
*** spzala has joined #openstack-keystone | 12:34 | |
*** fhubik has joined #openstack-keystone | 12:35 | |
*** fhubik is now known as fhubik_brb | 12:35 | |
*** pcaruana has quit IRC | 12:37 | |
*** ninag has joined #openstack-keystone | 12:39 | |
*** daemontool has joined #openstack-keystone | 12:39 | |
*** spzala has quit IRC | 12:40 | |
*** fhubik_brb is now known as fhubik | 12:40 | |
*** ninag has quit IRC | 12:40 | |
*** ninag has joined #openstack-keystone | 12:41 | |
*** e0ne has quit IRC | 12:42 | |
*** e0ne has joined #openstack-keystone | 12:52 | |
*** clenimar has quit IRC | 12:56 | |
*** david-lyle has quit IRC | 13:08 | |
*** markvoelker has joined #openstack-keystone | 13:09 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Split assignment backend tests https://review.openstack.org/268307 | 13:13 |
*** markvoelker has quit IRC | 13:14 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Split resource backend tests https://review.openstack.org/268702 | 13:15 |
*** chlong has quit IRC | 13:15 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Split token backend tests https://review.openstack.org/269111 | 13:18 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Split trust backend tests https://review.openstack.org/269115 | 13:20 |
*** e0ne has quit IRC | 13:21 | |
openstackgerrit | henry-nash proposed openstack/keystone: Projects acting as domains https://review.openstack.org/231289 | 13:24 |
*** chlong has joined #openstack-keystone | 13:28 | |
*** Ephur has joined #openstack-keystone | 13:31 | |
*** spzala has joined #openstack-keystone | 13:35 | |
*** raildo-afk is now known as raildo | 13:36 | |
*** vgridnev has quit IRC | 13:39 | |
*** vgridnev has joined #openstack-keystone | 13:40 | |
*** spzala has quit IRC | 13:41 | |
*** markvoelker has joined #openstack-keystone | 13:45 | |
*** richm has joined #openstack-keystone | 13:48 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Split catalog backend tests https://review.openstack.org/269125 | 13:53 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Split policy backend tests https://review.openstack.org/269133 | 13:54 |
*** fawadkhaliq has quit IRC | 13:55 | |
*** fawadk has joined #openstack-keystone | 13:55 | |
*** daemontool has quit IRC | 14:00 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Split identity backend tests https://review.openstack.org/269148 | 14:00 |
*** vivekd has quit IRC | 14:07 | |
*** Nirupama has quit IRC | 14:08 | |
*** phalmos has joined #openstack-keystone | 14:10 | |
*** jsavak has joined #openstack-keystone | 14:12 | |
*** fawadk has quit IRC | 14:12 | |
*** fawadkhaliq has joined #openstack-keystone | 14:15 | |
*** EinstCrazy has joined #openstack-keystone | 14:16 | |
*** fawadkhaliq has quit IRC | 14:16 | |
*** david-lyle has joined #openstack-keystone | 14:17 | |
*** jsheeren has quit IRC | 14:17 | |
*** dims has quit IRC | 14:21 | |
*** spzala has joined #openstack-keystone | 14:21 | |
*** jsheeren has joined #openstack-keystone | 14:21 | |
notmorgan | samueldmq: wow | 14:30 |
*** daemontool has joined #openstack-keystone | 14:31 | |
openstackgerrit | Marek Denis proposed openstack/keystone: Service Providers and Projects associations https://review.openstack.org/264854 | 14:35 |
*** jsavak has quit IRC | 14:35 | |
*** dims has joined #openstack-keystone | 14:36 | |
*** jsavak has joined #openstack-keystone | 14:36 | |
*** spzala has quit IRC | 14:38 | |
*** jsheeren has quit IRC | 14:39 | |
*** spzala has joined #openstack-keystone | 14:40 | |
*** dulek has left #openstack-keystone | 14:41 | |
*** henrynash has joined #openstack-keystone | 14:41 | |
*** ChanServ sets mode: +v henrynash | 14:41 | |
*** jsheeren has joined #openstack-keystone | 14:42 | |
*** david-lyle has quit IRC | 14:44 | |
*** david-lyle has joined #openstack-keystone | 14:48 | |
*** pushkaru has joined #openstack-keystone | 14:49 | |
*** reddy has quit IRC | 14:49 | |
*** henrynash has quit IRC | 14:49 | |
*** e0ne has joined #openstack-keystone | 14:53 | |
*** david-lyle has quit IRC | 14:53 | |
*** su_zhang has joined #openstack-keystone | 14:53 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:55 | |
*** ChanServ sets mode: +v topol_ | 14:56 | |
*** topol_ is now known as topol | 14:56 | |
*** edmondsw has joined #openstack-keystone | 14:57 | |
*** rbak has joined #openstack-keystone | 14:57 | |
*** gokrokve has joined #openstack-keystone | 14:58 | |
*** e0ne has quit IRC | 14:59 | |
*** e0ne has joined #openstack-keystone | 15:05 | |
*** shoutm has quit IRC | 15:07 | |
*** diazjf has joined #openstack-keystone | 15:11 | |
*** EinstCrazy has quit IRC | 15:13 | |
*** gokrokve has quit IRC | 15:16 | |
*** AJaeger has joined #openstack-keystone | 15:18 | |
AJaeger | Hi, is Morgan Fainberg here? | 15:18 |
AJaeger | sorry, not sure which nick he uses... | 15:18 |
*** slberger has joined #openstack-keystone | 15:19 | |
*** timcline has joined #openstack-keystone | 15:19 | |
*** chris_19 has joined #openstack-keystone | 15:19 | |
*** rderose has joined #openstack-keystone | 15:20 | |
*** KarthikB has joined #openstack-keystone | 15:20 | |
*** narengan12 has joined #openstack-keystone | 15:20 | |
*** paul-carlton2 has joined #openstack-keystone | 15:22 | |
lbragstad | dstanek I assume this is one of the bugs we were just talking about - https://review.openstack.org/#/c/175980/ | 15:23 |
AJaeger | keystone folks, Morgan just abandoned a change of me and I disagree with him naturally ;) Do you know whether he's around here? | 15:25 |
*** tonytan4ever has joined #openstack-keystone | 15:25 | |
bknudson | midcycle time. | 15:25 |
bknudson | AJaeger: he's at the midcycle here | 15:25 |
bknudson | we can throw stuff at him. | 15:26 |
AJaeger | bknudson: happy midcycling ;) | 15:26 |
AJaeger | bknudson: don't throw stuff at him ;) | 15:26 |
bknudson | I think you should restore it. | 15:26 |
AJaeger | bknudson: I did already, just wanted to discus it here with him, since that might be better than in the comment | 15:26 |
AJaeger | https://review.openstack.org/#/c/270370/ is the change... | 15:27 |
ayoung | lbragstad, anything on telepresence? | 15:28 |
ayoung | bknudson, dstanek stevemar ? | 15:28 |
lbragstad | ayoung I think we are going to try a Google hangout here in a minute | 15:29 |
ayoung | cool | 15:29 |
ayoung | standing by | 15:29 |
dstanek | AJaeger: why remove it? just curious | 15:30 |
*** chris_19 has quit IRC | 15:32 | |
AJaeger | dstanek: you already merged I1a4cc85ff6b61174ca06048d353c7a87c523e8f0 to remove python 2.6 support | 15:33 |
AJaeger | argparse moved from external to internal in 2.7 and later, so installing it is not needed at all. | 15:34 |
*** csoukup has joined #openstack-keystone | 15:34 | |
dstanek | does it work in 2.6 at all or is it just busted | 15:34 |
AJaeger | the new pip 8.0 broke also with argparse as requirement - but that was fixed with 8.0.2 | 15:34 |
AJaeger | dstanek: keystoneauth does not support 2.6 anymore since November with I1a4cc85ff6b61174ca06048d353c7a87c523e8f0 merged. | 15:35 |
AJaeger | dstanek: so, why keep an old artefact around? | 15:35 |
AJaeger | dstanek: see also https://review.openstack.org/270354 | 15:35 |
bknudson | if somebody wants to try to run on 2.6 they can install argparse... and, they probably have it already | 15:35 |
*** jgriffith is now known as Guest94234 | 15:36 | |
dstanek | AJaeger: i don't care either way. it seems the argument is that it may work and doesn't hurt anything | 15:36 |
AJaeger | dstanek: we're not gating for it, you removed already python 2.6 from setup.cfg as marker... | 15:37 |
dstanek | AJaeger: i realize that. just wanted to see why it was important to you | 15:38 |
ayoung | lbragstad, have things actually started there? | 15:38 |
*** vgridnev has quit IRC | 15:38 | |
ayoung | I forgot you are an hour later than I am here | 15:39 |
lbragstad | ayoung talking about caching | 15:39 |
*** chris_19 has joined #openstack-keystone | 15:39 | |
lbragstad | just started | 15:39 |
AJaeger | dstanek: it was important to me last week in an effort to fix pip 8.0 breakage | 15:39 |
lbragstad | stevemar are we doing teleconferencing? | 15:39 |
AJaeger | dstanek: with pip 8.0.2 it's not important, just a cleanup | 15:39 |
dolphm | stevemar: for our sanity, please use a unified diff | 15:39 |
dstanek | dolphm: ++ | 15:39 |
*** fawadkhaliq has joined #openstack-keystone | 15:40 | |
*** fawadkhaliq has quit IRC | 15:40 | |
*** fawadkhaliq has joined #openstack-keystone | 15:40 | |
* AJaeger is just irritated, especially seeing bugs marked as closed like https://bugs.launchpad.net/keystone/+bug/1519449 " | 15:41 | |
openstack | Launchpad bug 1519449 in python-keystoneclient-kerberos "Remove Python 2.6 Support" [Low,Fix released] - Assigned to David Stanek (dstanek) | 15:41 |
AJaeger | Remove Python 2.6 Support" | 15:41 |
*** gokrokve has joined #openstack-keystone | 15:42 | |
lbragstad | ayoung stevemar wants to wait until a break to try out a hangout with you on the big screen | 15:42 |
*** vgridnev has joined #openstack-keystone | 15:43 | |
ayoung | stevemar, lbragstad OK. I just did a test run, have it all set up | 15:43 |
ayoung | till then lbragstad gets to live chat | 15:43 |
lbragstad | ayoung reviewing the internal interface changes of https://review.openstack.org/#/c/215715/ | 15:49 |
lbragstad | ayoung which will get better when https://review.openstack.org/#/c/272007/ and we get that into dogpile | 15:49 |
*** tonytan_brb has joined #openstack-keystone | 15:50 | |
ayoung | lbragstad, is there any controversy there? | 15:51 |
lbragstad | ayoung not really - we are just discussing the maintenance of holding https://review.openstack.org/#/c/215715/23/keystone/common/cache/core.py internally | 15:52 |
lbragstad | until we get the fix in dogpile | 15:53 |
lbragstad | ayoung no real objections | 15:53 |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Add caching to role assignments https://review.openstack.org/215715 | 15:53 |
*** tonytan4ever has quit IRC | 15:53 | |
ayoung | lbragstad, nah push yours first | 15:53 |
ayoung | my argument is that token validation is unlikely to benefit from request level caching | 15:53 |
ayoung | maybe marginally, but we only fetch roles ones per validation | 15:53 |
ayoung | where notmorgan 's will really help is with identityt, cuz that is where we look up a lot of info time and again | 15:54 |
*** vgridnev has quit IRC | 15:59 | |
*** su_zhang has quit IRC | 16:03 | |
*** mgarza_ has joined #openstack-keystone | 16:03 | |
*** su_zhang has joined #openstack-keystone | 16:06 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Split token backend tests https://review.openstack.org/269111 | 16:08 |
*** rcernin has quit IRC | 16:09 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Split trust backend tests https://review.openstack.org/269115 | 16:10 |
*** alexvictorchan has joined #openstack-keystone | 16:11 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Split catalog backend tests https://review.openstack.org/269125 | 16:12 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Split policy backend tests https://review.openstack.org/269133 | 16:13 |
*** tonytan_brb has quit IRC | 16:13 | |
*** tonytan4ever has joined #openstack-keystone | 16:14 | |
*** david-lyle has joined #openstack-keystone | 16:14 | |
*** su_zhang has quit IRC | 16:17 | |
*** diazjf has quit IRC | 16:17 | |
*** fhubik is now known as fhubik_brb | 16:18 | |
raildo | lbragstad: change this for fernet, fix a test :) https://github.com/openstack/keystone/blob/master/keystone/tests/unit/test_token_provider.py#L746 | 16:18 |
lbragstad | raildo awesome - thanks | 16:19 |
lbragstad | raildo if you propose a patch I'll pull it into ayoung 's review | 16:19 |
*** jsavak has quit IRC | 16:19 | |
ayoung | thanks | 16:19 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Split identity backend tests https://review.openstack.org/269148 | 16:20 |
raildo | lbragstad: nice, I'll try fix some other tests and send a patch today :) | 16:20 |
lbragstad | raildo thank you sir! | 16:20 |
*** woodster_ has joined #openstack-keystone | 16:21 | |
*** dgonzalez has quit IRC | 16:23 | |
*** jsavak has joined #openstack-keystone | 16:23 | |
*** dgonzalez has joined #openstack-keystone | 16:24 | |
*** chris_19 has quit IRC | 16:24 | |
ayoung | lbragstad, at some point I'll free uop enough time to rip the not-needed revocation events out | 16:26 |
*** avarner has joined #openstack-keystone | 16:27 | |
*** jsheeren has quit IRC | 16:27 | |
*** diazjf has joined #openstack-keystone | 16:28 | |
*** chris_19 has joined #openstack-keystone | 16:28 | |
*** jsavak has quit IRC | 16:29 | |
*** jsavak has joined #openstack-keystone | 16:29 | |
*** simondodsley has joined #openstack-keystone | 16:32 | |
lbragstad | ayoung you and jorge_munoz share a common goal :) | 16:34 |
lbragstad | ayoung that was his mission that lead him to the trust rework | 16:35 |
ayoung | I need to get back to jorge_munoz . Is he there? | 16:35 |
jorge_munoz | o/ | 16:35 |
lbragstad | ayoung unfortunately no :( | 16:35 |
lbragstad | ayoung but he's right there ^ | 16:35 |
lbragstad | :) | 16:35 |
ayoung | jorge_munoz, so, on the trust thing, I think the biggest thing is the policy check | 16:35 |
ayoung | IIUC the bug is that we enforce on user_id | 16:35 |
ayoung | and that forces us to use impersonation | 16:35 |
ayoung | question is, what is the right policy rule to enforce | 16:36 |
ayoung | and maybe it is not not policy | 16:36 |
ayoung | maybe it is in the trust code itsef | 16:36 |
ayoung | itself | 16:36 |
ayoung | if there is no existing trust, then the trust needs to be created by the trustor. Period. | 16:36 |
ayoung | If extending a trust, the trust must be extended by the trustee. | 16:37 |
ayoung | Does that make sense? | 16:37 |
ayoung | I don;t think you should have a trust token to extend a trust | 16:37 |
ayoung | that makes you use up one of the count if it is a limited use trust | 16:38 |
ayoung | jorge_munoz, am I making sense? | 16:38 |
jorge_munoz | Yes, there are still some bug that I’m trying to expose by fixing the trust test cases. I just opened a bug to fix those: https://bugs.launchpad.net/keystone/+bug/1538626 | 16:38 |
openstack | Launchpad bug 1538626 in OpenStack Identity (keystone) "Fix trust test cases for redelegation and add test for impersonation" [Undecided,New] - Assigned to Jorge Munoz (jorge-munoz) | 16:38 |
*** belmoreira has quit IRC | 16:38 | |
*** david-lyle has quit IRC | 16:38 | |
jorge_munoz | So, we need to stop creating trust if impersonation is used. | 16:38 |
jorge_munoz | I don’t know the use case for creating a new trust using impersonation. | 16:39 |
ayoung | right. that means first changing the policuy rule, but we can't do that without enforcing something else | 16:39 |
lbragstad | yeah - that's where the "weird" condition is | 16:39 |
ayoung | creating a new trust using impersonation should only be done by the trustee | 16:39 |
dstanek | samueldmq: ! | 16:40 |
*** david-lyle has joined #openstack-keystone | 16:40 | |
*** jbell8 has joined #openstack-keystone | 16:42 | |
jorge_munoz | ayoung: Yea, a check to be done to prevent a user from creating a trust using a trusted token with impersonation, but that would still pass the policy enforment. | 16:42 |
*** spandhe has joined #openstack-keystone | 16:42 | |
jorge_munoz | by check I mean with code. | 16:43 |
ayoung | jorge_munoz, there are some use cases from Heat where they use the users token to create a trust, but I think those would still work. I don't think they use a trust token to create a trust | 16:43 |
jorge_munoz | ayoung: Yes, that should work. Only thing not working was redelegation, but that should be fixed now. I can strart working on fixing the policy issue and making sure impersonation is not used when attemping to redelegate a new trust. | 16:48 |
*** fhubik_brb is now known as fhubik | 16:48 | |
ayoung | jorge_munoz, is that in you latest patch? | 16:48 |
jorge_munoz | Yes, that fixed the redelegation work flow. There are still some bug that i want to address. Ex. Passing redelegation_trust_id is allowed even if its the frist trust in the chain. | 16:50 |
ayoung | jorge_munoz, sounds good. Are you familiar with amakarov's work on unified delegation? | 16:51 |
*** haneef_ has quit IRC | 16:51 | |
jorge_munoz | ayoung: No, but if I get pointed to the right direction I can take a look. | 16:52 |
lbragstad | ayoung https://etherpad.openstack.org/p/keystone-mitaka-midcycle | 16:55 |
*** gokrokve has quit IRC | 16:57 | |
*** _cjones_ has joined #openstack-keystone | 16:58 | |
*** _cjones_ has quit IRC | 16:58 | |
*** _cjones_ has joined #openstack-keystone | 16:58 | |
*** jistr has quit IRC | 16:59 | |
ayoung | stevemar, turn your computer around ,please. so mike can pike up the conversation | 17:00 |
*** chris_19 has quit IRC | 17:01 | |
*** fhubik is now known as fhubik_brb | 17:01 | |
*** fhubik_brb is now known as fhubik | 17:03 | |
*** gokrokve has joined #openstack-keystone | 17:03 | |
*** cdcasey has joined #openstack-keystone | 17:03 | |
*** clenimar has joined #openstack-keystone | 17:05 | |
*** paul-carlton2 has quit IRC | 17:07 | |
*** chris_19 has joined #openstack-keystone | 17:09 | |
*** mhickey has quit IRC | 17:12 | |
*** fhubik has quit IRC | 17:19 | |
*** jaosorior has quit IRC | 17:20 | |
*** jaosorior has joined #openstack-keystone | 17:20 | |
*** jaosorior has quit IRC | 17:21 | |
*** permalac has quit IRC | 17:22 | |
*** jasonsb has joined #openstack-keystone | 17:29 | |
*** cdcasey has quit IRC | 17:30 | |
*** chris_19 has quit IRC | 17:30 | |
*** chris_19 has joined #openstack-keystone | 17:30 | |
*** pgbridge_ has quit IRC | 17:33 | |
*** aix has quit IRC | 17:36 | |
*** pgbridge_ has joined #openstack-keystone | 17:36 | |
*** narengan12 has quit IRC | 17:42 | |
*** jed56 has quit IRC | 17:43 | |
*** pwp has joined #openstack-keystone | 17:47 | |
*** mylu has joined #openstack-keystone | 17:48 | |
*** fawadkhaliq has quit IRC | 17:51 | |
raildo | lbragstad: I have the feeling that most of this tests will only be fixed after the issue_v2_token() and v3 patches... =/ | 17:53 |
*** su_zhang has joined #openstack-keystone | 17:53 | |
*** pwp has quit IRC | 17:55 | |
*** dims has quit IRC | 17:58 | |
*** rcernin has joined #openstack-keystone | 18:00 | |
*** rderose has quit IRC | 18:01 | |
*** cdcasey has joined #openstack-keystone | 18:03 | |
*** narengan12 has joined #openstack-keystone | 18:07 | |
*** browne has joined #openstack-keystone | 18:12 | |
*** jsavak has quit IRC | 18:13 | |
*** mylu has quit IRC | 18:13 | |
*** jsavak has joined #openstack-keystone | 18:13 | |
*** EinstCrazy has joined #openstack-keystone | 18:14 | |
lbragstad | dolphm https://review.openstack.org/#/c/215715/19 | 18:16 |
lbragstad | raildo yeah, probably | 18:16 |
*** chris_19 has left #openstack-keystone | 18:16 | |
*** mylu has joined #openstack-keystone | 18:16 | |
*** doug-fish has quit IRC | 18:16 | |
*** EinstCrazy has quit IRC | 18:18 | |
*** jsavak has quit IRC | 18:19 | |
samueldmq | AJaeger: if you're still looking for morgan, he's notmorgan | 18:19 |
samueldmq | AJaeger: fyi irc conversations may be a bit slow today because of midcycle | 18:20 |
*** fhubik has joined #openstack-keystone | 18:21 | |
*** fhubik has quit IRC | 18:22 | |
*** doug-fish has joined #openstack-keystone | 18:22 | |
*** KarthikB has quit IRC | 18:25 | |
*** pwp has joined #openstack-keystone | 18:26 | |
*** doug-fish has quit IRC | 18:27 | |
bknudson | http://eavesdrop.openstack.org/ | 18:30 |
lbragstad | dstanek https://review.openstack.org/#/c/253671/7 | 18:31 |
lbragstad | dstanek https://review.openstack.org/#/c/253670/6 | 18:31 |
lbragstad | dstanek and https://review.openstack.org/#/c/253672/7 | 18:31 |
*** jsavak has joined #openstack-keystone | 18:33 | |
*** stack_ has joined #openstack-keystone | 18:33 | |
*** rderose has joined #openstack-keystone | 18:33 | |
*** jasonsb has quit IRC | 18:34 | |
lbragstad | bknudson ^ | 18:35 |
*** cdcasey has quit IRC | 18:35 | |
*** doug-fish has joined #openstack-keystone | 18:35 | |
*** cdcasey has joined #openstack-keystone | 18:36 | |
*** KarthikB has joined #openstack-keystone | 18:36 | |
*** narengan12 has quit IRC | 18:37 | |
*** doug-fish has quit IRC | 18:40 | |
samueldmq | tjcocozz: dstanek: https://review.openstack.org/#/c/268307 | 18:40 |
samueldmq | test_backend split ^ | 18:40 |
*** pwp has quit IRC | 18:41 | |
*** mylu has quit IRC | 18:43 | |
openstackgerrit | Raildo Mascena proposed openstack/keystone: Make fernet default token provider https://review.openstack.org/258650 | 18:43 |
*** mylu has joined #openstack-keystone | 18:43 | |
*** daemontool_ has joined #openstack-keystone | 18:45 | |
*** clenimar has quit IRC | 18:45 | |
ayoung | lbragstad, topol have we started yet? | 18:45 |
lbragstad | ayoung not yet | 18:46 |
*** stack_ is now known as narengan | 18:46 | |
lbragstad | ayoung people are still lunching | 18:46 |
samueldmq | tjcocozz: https://review.openstack.org/#/c/246400 | 18:46 |
lbragstad | ayoung starting in 10 minutes | 18:47 |
*** daemontool has quit IRC | 18:47 | |
ayoung | I'm dialed in | 18:47 |
*** cdcasey_ has joined #openstack-keystone | 18:48 | |
*** spzala has quit IRC | 18:49 | |
*** spzala has joined #openstack-keystone | 18:50 | |
*** cdcasey_ has quit IRC | 18:51 | |
topol | ayoung, time to call back in | 18:53 |
*** phalmos has quit IRC | 18:54 | |
openstackgerrit | Matthew Edmonds proposed openstack/keystone: Simplify admin_required policy https://review.openstack.org/273193 | 18:54 |
*** spzala has quit IRC | 18:54 | |
*** doug-fish has joined #openstack-keystone | 18:55 | |
openstackgerrit | henry-nash proposed openstack/keystone: Change get_project permission https://review.openstack.org/270057 | 18:58 |
*** doug-fish has quit IRC | 19:00 | |
*** doug-fish has joined #openstack-keystone | 19:01 | |
*** fpatwa has joined #openstack-keystone | 19:02 | |
*** doug-fis_ has joined #openstack-keystone | 19:02 | |
openstackgerrit | David Stanek proposed openstack/keystone: Correctly handle direct mapping with keywords https://review.openstack.org/175980 | 19:02 |
edmondsw | ayoung, please take another look at the review I proposed above. I don't see any case where admin_required and admin_or_cloud_admin are not equivalent | 19:03 |
*** doug-fi__ has joined #openstack-keystone | 19:03 | |
*** pwp has joined #openstack-keystone | 19:04 | |
*** cdcasey has quit IRC | 19:04 | |
*** cdcasey has joined #openstack-keystone | 19:04 | |
ayoung | edmondsw, look at the dom,ain match | 19:04 |
*** doug-fish has quit IRC | 19:06 | |
ayoung | edmondsw, Oh..I see what you are saying...there is a mistake in policy | 19:06 |
edmondsw | ayoung, look at how that is part of an AND... it won't matter unless the other side of the AND matches | 19:06 |
ayoung | edmondsw, “I know that you believe you understand what you think I said, but I'm not sure you realize that what you heard is not what I meant.” | 19:07 |
edmondsw | lol | 19:07 |
*** doug-fis_ has quit IRC | 19:07 | |
edmondsw | ok... | 19:07 |
edmondsw | right back at you? ;) | 19:07 |
ayoung | edmondsw, we wanted to split admin project (is_admin) from cloud-admin (admin for domain) | 19:07 |
*** alexpro2 has joined #openstack-keystone | 19:07 | |
*** pwp has quit IRC | 19:08 | |
ayoung | and..I thought that was what we were doing...and we are not | 19:08 |
ayoung | so...you exposed a bug | 19:08 |
*** csoukup has quit IRC | 19:08 | |
*** cdcasey has quit IRC | 19:08 | |
*** alexpro2 has quit IRC | 19:08 | |
*** cdcasey has joined #openstack-keystone | 19:08 | |
*** apetrov has joined #openstack-keystone | 19:09 | |
edmondsw | you thought admin_required was matching admin project? | 19:09 |
edmondsw | not clear what you thought it was doing / want it to do | 19:10 |
*** apetrov has quit IRC | 19:10 | |
*** _cjones_ has quit IRC | 19:11 | |
*** boris-42 has quit IRC | 19:13 | |
*** e0ne has quit IRC | 19:13 | |
*** phalmos has joined #openstack-keystone | 19:14 | |
openstackgerrit | Matthew Edmonds proposed openstack/keystone: Simplify admin_required policy https://review.openstack.org/273193 | 19:19 |
*** RichardRaseley has joined #openstack-keystone | 19:21 | |
*** _cjones_ has joined #openstack-keystone | 19:24 | |
*** _cjones_ has quit IRC | 19:24 | |
*** _cjones_ has joined #openstack-keystone | 19:24 | |
*** e0ne has joined #openstack-keystone | 19:25 | |
*** fpatwa has quit IRC | 19:26 | |
*** rderose has quit IRC | 19:27 | |
*** spandhe has quit IRC | 19:28 | |
*** spandhe has joined #openstack-keystone | 19:28 | |
*** csoukup has joined #openstack-keystone | 19:28 | |
*** ebalduf has joined #openstack-keystone | 19:30 | |
*** tonytan_brb has joined #openstack-keystone | 19:32 | |
*** pwp has joined #openstack-keystone | 19:33 | |
*** tonytan4ever has quit IRC | 19:35 | |
*** spzala has joined #openstack-keystone | 19:37 | |
*** pece has joined #openstack-keystone | 19:38 | |
*** jsavak has quit IRC | 19:38 | |
*** jsavak has joined #openstack-keystone | 19:39 | |
ayoung | edmondsw, admin_required should require is is_admin_project check | 19:40 |
*** pece has quit IRC | 19:40 | |
*** pwp has left #openstack-keystone | 19:41 | |
edmondsw | ayoung, that would make it nearly equivalent to cloud_admin | 19:41 |
ayoung | edmondsw, it should be like this | 19:41 |
openstackgerrit | David Stanek proposed openstack/keystone: Test hyphens instead of underscores in request attributes https://review.openstack.org/258601 | 19:42 |
ayoung | "admin_required": "role:admin and token.is_admin_project:True" | 19:42 |
ayoung | "cloud_admin": "role:admin and domain_id:admin_domain_id", | 19:42 |
ayoung | edmondsw, that make sense? | 19:43 |
edmondsw | no... | 19:43 |
edmondsw | why aren't we deprecating admin_domain_id? | 19:44 |
edmondsw | in favor of token.is_admin_project | 19:44 |
ayoung | oh, I did that wrong | 19:44 |
ayoung | "cloud_admin": "role:admin and domain_id:domain_id", | 19:44 |
ayoung | or better | 19:44 |
ayoung | "cloud_admin": "role:admin and token.domain_id:domain_id", | 19:44 |
ayoung | but that is domain admin... | 19:44 |
ayoung | meh | 19:44 |
ayoung | need henry, and he is in the midcycle convo right now | 19:45 |
ayoung | edmondsw, I'll downgrade to -1 | 19:45 |
edmondsw | henry's having trouble getting on IRC, but he's sitting next to me | 19:45 |
ayoung | there is certainly someothig that can be cleanedup | 19:45 |
edmondsw | let's talk after this midcycle convo finishes | 19:45 |
ayoung | ++ | 19:45 |
*** tonytan_brb has quit IRC | 19:46 | |
*** tonytan4ever has joined #openstack-keystone | 19:46 | |
*** dims has joined #openstack-keystone | 19:53 | |
openstackgerrit | David Stanek proposed openstack/python-keystoneclient: Missing defaults in the create() method in the v2 ServiceManager https://review.openstack.org/262450 | 20:01 |
dstanek | ayoung: lbragstad: dolphm: stevemar: samueldmq: bknudson: my last two pushes close out bugs ^ | 20:03 |
*** daemontool has joined #openstack-keystone | 20:06 | |
*** tonytan_brb has joined #openstack-keystone | 20:07 | |
*** tonytan4ever has quit IRC | 20:09 | |
*** daemontool_ has quit IRC | 20:09 | |
samueldmq | dstanek: just left a comment there | 20:10 |
openstackgerrit | Matthew Edmonds proposed openstack/keystone: invalidate cache immediately https://review.openstack.org/273218 | 20:14 |
edmondsw | dstanek notmorgan ^ | 20:14 |
*** ebalduf has quit IRC | 20:15 | |
notmorgan | edmondsw: cool we might need more of those btw | 20:16 |
notmorgan | you can't delete after invalidate | 20:16 |
edmondsw | yeah, figured I'd throw this up before we forgot | 20:16 |
notmorgan | you need to delete then invalidate | 20:16 |
notmorgan | :) | 20:16 |
*** tonytan_brb has quit IRC | 20:16 | |
notmorgan | but you want it to be .deletE() next line .invalidatE() | 20:16 |
edmondsw | oh, did I do that? | 20:16 |
notmorgan | yeah | 20:16 |
edmondsw | oops | 20:16 |
notmorgan | hehe | 20:17 |
*** tonytan4ever has joined #openstack-keystone | 20:17 | |
*** jsavak has quit IRC | 20:18 | |
edmondsw | hmmm... not seeing it | 20:18 |
notmorgan | commented | 20:19 |
notmorgan | you moved one that didn't need to be moved | 20:19 |
notmorgan | oh wait hmm. | 20:20 |
notmorgan | i mis read the patch | 20:20 |
notmorgan | sec | 20:20 |
notmorgan | eeek, that is a hard one. | 20:20 |
edmondsw | should the assignment be deleted before the project itself? | 20:21 |
edmondsw | and same for credentials | 20:22 |
*** timcline has quit IRC | 20:24 | |
openstackgerrit | David Stanek proposed openstack/python-keystoneclient: Missing defaults in the create() method in the v2 ServiceManager https://review.openstack.org/262450 | 20:25 |
*** jsavak has joined #openstack-keystone | 20:27 | |
*** doug-fi__ is now known as doug-fish | 20:27 | |
*** mylu has quit IRC | 20:28 | |
dstanek | notmorgan: counter on https://review.openstack.org/#/c/273218/1 | 20:30 |
notmorgan | yeah i need to think about thos that works | 20:30 |
notmorgan | this was a weired on | 20:30 |
notmorgan | wait we're invalidating project and project_name, how does that impact delete assignments? | 20:31 |
notmorgan | assignment delete should be fine. | 20:32 |
notmorgan | after the invalidate? or am i mis-reading your comment? | 20:32 |
notmorgan | dstanek: ^ | 20:32 |
*** timcline has joined #openstack-keystone | 20:32 | |
*** jsavak has quit IRC | 20:34 | |
edmondsw | are assignments cached, and we'd need to call invalidate on those as well? | 20:35 |
notmorgan | edmondsw: the delete assignments should do that | 20:37 |
edmondsw | ok good... so... why wouldn't we delete the assignments, then the project? | 20:37 |
notmorgan | because we don't want a race where someone adds a new assignment that isn't in the assignment list but the project is still valid | 20:38 |
notmorgan | so delete the project so no new assignments can be created for that project, then cleanup the assignments | 20:38 |
samueldmq | dstanek: ping | 20:38 |
notmorgan | samueldmq: i see you | 20:38 |
edmondsw | seems like we need some kind of synchronization | 20:38 |
samueldmq | dstanek: regarding your patch above, looking at https://wiki.openstack.org/wiki/OpenStackClient/Commands | 20:38 |
samueldmq | notmorgan: o/ | 20:39 |
notmorgan | edmondsw: you also can't login once the project is deleted | 20:39 |
notmorgan | edmondsw: this is less sync and more ordering. | 20:39 |
notmorgan | so, .delete .invalidate | 20:39 |
notmorgan | no more logins | 20:39 |
samueldmq | dstanek: type is also optional, shouldn't its default be none as well | 20:39 |
dstanek | notmorgan: i was thinking about just being careful - once you delete the project then go ahead and invalidate the project - if the next delete fails the cache will be correct | 20:39 |
notmorgan | cleanup the assignments (which are invalid anyway) | 20:39 |
notmorgan | dstanek: once this convo in the room is done, expalin it i'm still missing it | 20:40 |
edmondsw | I guess if we invalidate twice... dstanek, is that what you were suggesting? | 20:40 |
dstanek | samueldmq: no reason to test every combination of everything - just want to focus on the thing being tested and in this case that's description | 20:40 |
dstanek | notmorgan: k, i may be missing something too :-) between pushing code, reviewing other code and trying to listen | 20:41 |
notmorgan | yeah | 20:41 |
notmorgan | exactly | 20:41 |
samueldmq | dstanek: sure, not about the tests, but about the bug reported itself | 20:41 |
samueldmq | dstanek: if the bug wouldn't apply to the type filter as well | 20:41 |
*** diazjf has quit IRC | 20:41 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Reuse project scoped token check for trusts https://review.openstack.org/253672 | 20:42 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add checks for domain scoped data creep https://review.openstack.org/253671 | 20:42 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add checks for project scoped data creep to tests https://review.openstack.org/253670 | 20:42 |
lbragstad | bknudson stevemar dstanek address comments and rebased ^ | 20:42 |
*** jsavak has joined #openstack-keystone | 20:44 | |
openstackgerrit | Jorge Munoz proposed openstack/keystone: Fix trust redelegation tests https://review.openstack.org/273232 | 20:46 |
*** jsavak has quit IRC | 20:47 | |
*** jsavak has joined #openstack-keystone | 20:47 | |
*** narengan has quit IRC | 20:48 | |
*** narengan has joined #openstack-keystone | 20:52 | |
*** alexpro has quit IRC | 20:54 | |
*** apetrov has joined #openstack-keystone | 20:56 | |
*** gokrokve has quit IRC | 20:57 | |
*** gokrokve_ has joined #openstack-keystone | 20:57 | |
*** apetrov has quit IRC | 20:58 | |
*** gokrokve_ has quit IRC | 20:59 | |
*** gokrokve has joined #openstack-keystone | 20:59 | |
*** gokrokve has quit IRC | 21:00 | |
*** gokrokve has joined #openstack-keystone | 21:05 | |
edmondsw | ayoung, so I've chatted with henrynash, and he thinks this is correct as-is | 21:05 |
edmondsw | we think you're assuming all the checks throughout the policy that use admin_required are doing more than they are... they just check that you're some kind of admin, not what kind | 21:06 |
edmondsw | if we need to check more than that in some places, sure... I'd probably agree with that. I'm just starting to go through the file and see what makes sense and what may need to change | 21:06 |
edmondsw | this patch was just the first of what will probably be more to address that kind of thing | 21:07 |
edmondsw | talking about https://review.openstack.org/#/c/273193 | 21:07 |
ayoung | edmondsw, yeah | 21:07 |
*** raildo has left #openstack-keystone | 21:07 | |
edmondsw | so... you gonna +2 or what do you want here? | 21:08 |
ayoung | I'm tempted to call in again and talk with him directly, but I'm kind of on something urgent...killing eventelt in Tripleo | 21:08 |
edmondsw | sure | 21:08 |
ayoung | i'LL +2 | 21:08 |
edmondsw | tx | 21:08 |
*** amakarov has joined #openstack-keystone | 21:13 | |
*** timcline has quit IRC | 21:13 | |
*** jsavak has quit IRC | 21:14 | |
*** gokrokve has quit IRC | 21:14 | |
*** timcline has joined #openstack-keystone | 21:14 | |
*** jsavak has joined #openstack-keystone | 21:14 | |
*** diazjf has joined #openstack-keystone | 21:15 | |
*** rcernin has quit IRC | 21:16 | |
*** raildo has joined #openstack-keystone | 21:18 | |
*** narengan has quit IRC | 21:19 | |
*** RichardRaseley has quit IRC | 21:19 | |
*** raildo is now known as raildo-afk | 21:20 | |
dstanek | edmondsw: this is what i was thinking http://paste.openstack.org/show/485193/ | 21:23 |
edmondsw | makes sense | 21:24 |
edmondsw | want to throw that up as a separate patch, since this was already +workflow, or do you want me to add this here? | 21:25 |
amakarov | dstanek: please, give me a link to your change(s) related to dependency | 21:26 |
*** pauloewerton has quit IRC | 21:26 | |
*** paul-carlton2 has joined #openstack-keystone | 21:27 | |
paul-carlton2 | jamielennox, hi | 21:27 |
paul-carlton2 | jamielennox, https://openstack.nimeyo.com/69269/openstack-keystone-addressing-keysone-running-operations | 21:27 |
paul-carlton2 | any progress on this? | 21:27 |
samueldmq | tjcocozz: https://review.openstack.org/#/c/231289/ | 21:29 |
stevemar | dstanek: please approve: https://review.openstack.org/#/c/258601/ | 21:30 |
stevemar | dstanek: 1 character change is not co-authorship :) | 21:30 |
*** timcline_ has joined #openstack-keystone | 21:33 | |
*** timcline has quit IRC | 21:36 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Reuse project scoped token check for trusts https://review.openstack.org/253672 | 21:38 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add checks for domain scoped data creep https://review.openstack.org/253671 | 21:38 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add checks for project scoped data creep to tests https://review.openstack.org/253670 | 21:38 |
lbragstad | bknudson followed a different pattern suggested by dstanek ^ and removed the comments since they no longer apply | 21:38 |
*** andrewbogott has joined #openstack-keystone | 21:40 | |
openstackgerrit | Merged openstack/python-keystoneclient: Remove bandit tox environment https://review.openstack.org/269269 | 21:40 |
openstackgerrit | Merged openstack/python-keystoneclient: Remove Babel from requirements.txt https://review.openstack.org/272112 | 21:41 |
ayoung | edmondsw, make sure https://review.openstack.org/#/c/242614/ gets some love, would you | 21:42 |
edmondsw | several of us looking at that one now | 21:43 |
edmondsw | at least me and topol | 21:43 |
andrewbogott | How does /v2.0/tenants/{tenantId}/users relate to roles? Does that return all users that have the role ‘user’ on {tenantId}? Or some other role? | 21:44 |
ayoung | edmondsw, I'm here to answer questions, and can call back in if that helps | 21:44 |
topol | ayoung, I'm on it!!! | 21:45 |
*** dims has quit IRC | 21:46 | |
*** ajmiller has joined #openstack-keystone | 21:46 | |
*** e0ne has quit IRC | 21:49 | |
*** su_zhang has quit IRC | 21:49 | |
*** spzala has quit IRC | 21:50 | |
*** spzala has joined #openstack-keystone | 21:51 | |
*** diazjf has quit IRC | 21:51 | |
openstackgerrit | Brant Knudson proposed openstack/python-keystoneclient: Bandit profile updates https://review.openstack.org/267810 | 21:51 |
*** lifeless has quit IRC | 21:53 | |
*** lifeless has joined #openstack-keystone | 21:55 | |
*** spzala has quit IRC | 21:55 | |
*** spzala has joined #openstack-keystone | 21:57 | |
mgagne | ayoung so far, I got much better UX/performance by leaving the keystone service in a centralized zone (with 100ms) and memcached in keystonestonemiddleware VS having regional keystone service/nodes but with centralized database (with 100ms) | 21:58 |
ayoung | mgagne, very good to know | 21:58 |
ayoung | mgagne, does put you at risk if the central keystone is not avaialble, but you know that | 21:59 |
mgagne | ayoung we are talking about: 2s/0.03s VS 1m15s/0.03s when 1st is initial call to nova API and 2nd subsequent calls | 21:59 |
mgagne | ayoung it's already the case, nothing changes here. will work on distributed keystone later | 21:59 |
mgagne | ayoung we are working on fernet migration, we just don't want to introduce performance regression. | 22:00 |
ayoung | mgagne, sounds good. I think Fernet will close the gap on what you need. | 22:00 |
ayoung | ++ | 22:00 |
mgagne | I very much like the non-persisted token | 22:01 |
ayoung | mgagne, me too...I tried to make that happend a couple years ago | 22:02 |
mgagne | "I felt a great disturbance in Keystone, as if millions of PKI tokens suddenly cried out in terror, and were suddenly deleted. I feel something great has happened." | 22:02 |
*** spzala has quit IRC | 22:03 | |
*** daemontool has quit IRC | 22:19 | |
*** KarthikB has quit IRC | 22:21 | |
*** KarthikB has joined #openstack-keystone | 22:24 | |
*** paul-carlton2 has quit IRC | 22:25 | |
dolphm | how trusts redelegation works in keystone (with impersonation) https://twitter.com/dolphm/status/692473164937465856 | 22:25 |
*** diazjf has joined #openstack-keystone | 22:25 | |
dolphm | jorge_munoz: ^ cc- stevemar lbragstad ayoung | 22:25 |
stevemar | yo | 22:25 |
stevemar | mgagne: lol | 22:27 |
ayoung | dolphm, can you get a clearer picture? All I see is foot gun, but can't tell if the folks to the right are all getting capped | 22:27 |
jorge_munoz | lol | 22:27 |
stevemar | mgagne: move to fernet? | 22:27 |
mgagne | trying to =) | 22:27 |
dolphm | ayoung: lol it's a trust "chain" between them! | 22:27 |
ayoung | dolphm, so only the first guy gets shot, but anyone of them can pull the chain, which then pulls the trigger? | 22:28 |
*** daemontool has joined #openstack-keystone | 22:30 | |
*** pnavarro has quit IRC | 22:32 | |
*** daemontool_ has joined #openstack-keystone | 22:37 | |
*** daemontool has quit IRC | 22:39 | |
*** timcline_ has quit IRC | 22:39 | |
*** RA_ has joined #openstack-keystone | 22:42 | |
*** jsavak has quit IRC | 22:47 | |
*** jsavak has joined #openstack-keystone | 22:48 | |
*** dims has joined #openstack-keystone | 22:51 | |
*** dims has quit IRC | 22:54 | |
*** jsavak has quit IRC | 22:55 | |
*** jsavak has joined #openstack-keystone | 22:56 | |
*** daemontool has joined #openstack-keystone | 22:58 | |
*** c_soukup has joined #openstack-keystone | 23:00 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystone: Use requst local in-process cache per request https://review.openstack.org/272007 | 23:00 |
*** tonytan4ever has quit IRC | 23:01 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Reuse project scoped token check for trusts https://review.openstack.org/253672 | 23:01 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add checks for domain scoped data creep https://review.openstack.org/253671 | 23:01 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add checks for project scoped data creep to tests https://review.openstack.org/253670 | 23:01 |
*** daemontool_ has quit IRC | 23:01 | |
*** diazjf has quit IRC | 23:01 | |
*** e0ne has joined #openstack-keystone | 23:02 | |
*** su_zhang has joined #openstack-keystone | 23:02 | |
*** pushkaru has quit IRC | 23:02 | |
*** csoukup has quit IRC | 23:03 | |
*** doug-fish has quit IRC | 23:03 | |
*** harlowja has quit IRC | 23:03 | |
*** jbell8 has quit IRC | 23:03 | |
*** e0ne_ has joined #openstack-keystone | 23:04 | |
*** harlowja has joined #openstack-keystone | 23:04 | |
*** cdcasey has quit IRC | 23:04 | |
*** e0ne has quit IRC | 23:06 | |
openstackgerrit | Merged openstack/python-keystoneclient: Missing defaults in the create() method in the v2 ServiceManager https://review.openstack.org/262450 | 23:06 |
*** simondodsley has quit IRC | 23:08 | |
*** slberger has left #openstack-keystone | 23:10 | |
*** doug-fish has joined #openstack-keystone | 23:10 | |
*** pushkaru has joined #openstack-keystone | 23:15 | |
*** amakarov has quit IRC | 23:15 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 23:16 | |
*** edmondsw has quit IRC | 23:17 | |
*** doug-fish has quit IRC | 23:18 | |
*** chlong has quit IRC | 23:18 | |
*** jbell8 has joined #openstack-keystone | 23:19 | |
*** doug-fish has joined #openstack-keystone | 23:21 | |
*** vivekd has joined #openstack-keystone | 23:23 | |
*** e0ne_ has quit IRC | 23:24 | |
*** doug-fish has quit IRC | 23:24 | |
*** doug-fish has joined #openstack-keystone | 23:25 | |
*** doug-fish has quit IRC | 23:25 | |
*** doug-fish has joined #openstack-keystone | 23:25 | |
*** KarthikB has quit IRC | 23:26 | |
*** jbell8 has quit IRC | 23:26 | |
*** doug-fish has quit IRC | 23:27 | |
*** doug-fish has joined #openstack-keystone | 23:27 | |
*** jbell8 has joined #openstack-keystone | 23:29 | |
*** dims_ has joined #openstack-keystone | 23:30 | |
*** timcline has joined #openstack-keystone | 23:31 | |
*** chlong has joined #openstack-keystone | 23:31 | |
*** timcline has quit IRC | 23:31 | |
*** timcline has joined #openstack-keystone | 23:32 | |
*** doug-fish has quit IRC | 23:32 | |
*** jbell8 has quit IRC | 23:35 | |
*** jbell8 has joined #openstack-keystone | 23:38 | |
openstackgerrit | Jorge Munoz proposed openstack/keystone: Add tests for trust using impersonation https://review.openstack.org/273279 | 23:39 |
*** timcline has quit IRC | 23:39 | |
*** avarner has quit IRC | 23:42 | |
*** _cjones_ has quit IRC | 23:42 | |
*** _cjones_ has joined #openstack-keystone | 23:43 | |
*** jbell8 has quit IRC | 23:44 | |
*** c_soukup has quit IRC | 23:44 | |
*** _cjones__ has joined #openstack-keystone | 23:45 | |
*** rbak has quit IRC | 23:46 | |
*** _cjones__ has quit IRC | 23:46 | |
*** _cjones_ has quit IRC | 23:46 | |
*** _cjones__ has joined #openstack-keystone | 23:46 | |
*** jsavak has quit IRC | 23:48 | |
*** jbell8 has joined #openstack-keystone | 23:49 | |
*** pushkaru has quit IRC | 23:50 | |
*** su_zhang has quit IRC | 23:56 | |
*** shoutm has joined #openstack-keystone | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!