*** EinstCra_ has quit IRC | 00:00 | |
*** shoutm has joined #openstack-keystone | 00:03 | |
*** tsymancz1k has quit IRC | 00:04 | |
*** tsymanczyk has joined #openstack-keystone | 00:04 | |
*** tsymanczyk has quit IRC | 00:04 | |
*** ninag has quit IRC | 00:04 | |
*** tsymancz1k has joined #openstack-keystone | 00:13 | |
notmorgan | bigjools: no version | 00:15 |
---|---|---|
bigjools | notmorgan: cool thanks very much. Did I miss documentation for this? | 00:15 |
*** timcline has quit IRC | 00:18 | |
openstackgerrit | ayoung proposed openstack/keystone: Implied Roles API https://review.openstack.org/242614 | 00:34 |
notmorgan | I don't think it is documented because some apis have versions. | 00:39 |
*** arunkant_ has quit IRC | 00:39 | |
notmorgan | In devstack | 00:39 |
notmorgan | We are trying to fix that | 00:39 |
*** shoutm_ has joined #openstack-keystone | 00:39 | |
*** shoutm has quit IRC | 00:41 | |
*** Ephur has quit IRC | 00:46 | |
bigjools | I know tempest breaks if you put them in | 00:47 |
*** ayoung has joined #openstack-keystone | 00:49 | |
*** ChanServ sets mode: +v ayoung | 00:49 | |
*** chlong has joined #openstack-keystone | 00:49 | |
*** RichardRaseley has quit IRC | 00:55 | |
*** _cjones_ has quit IRC | 00:56 | |
*** _cjones_ has joined #openstack-keystone | 00:56 | |
*** alexvictorchan has quit IRC | 01:00 | |
*** drjones has joined #openstack-keystone | 01:01 | |
*** spandhe has quit IRC | 01:01 | |
*** spandhe has joined #openstack-keystone | 01:01 | |
*** _cjones_ has quit IRC | 01:02 | |
*** drjones has quit IRC | 01:06 | |
*** _cjones_ has joined #openstack-keystone | 01:06 | |
*** jbell8 has joined #openstack-keystone | 01:16 | |
*** shoutm_ has quit IRC | 01:16 | |
*** shoutm has joined #openstack-keystone | 01:17 | |
*** jbell8 has quit IRC | 01:17 | |
*** jbell8 has joined #openstack-keystone | 01:18 | |
*** hockeynut has quit IRC | 01:31 | |
*** yarkot has quit IRC | 01:32 | |
*** hughsaunders has quit IRC | 01:32 | |
*** mgagne has quit IRC | 01:32 | |
*** _cjones_ has quit IRC | 01:32 | |
*** mgagne has joined #openstack-keystone | 01:32 | |
*** mgagne has quit IRC | 01:32 | |
*** mgagne has joined #openstack-keystone | 01:32 | |
*** hughsaunders has joined #openstack-keystone | 01:32 | |
*** hockeynut has joined #openstack-keystone | 01:34 | |
*** davechen has joined #openstack-keystone | 01:34 | |
*** jbell8 has quit IRC | 01:37 | |
*** fawadkhaliq has joined #openstack-keystone | 01:38 | |
*** fawadkhaliq has quit IRC | 01:38 | |
*** amakarov has joined #openstack-keystone | 01:45 | |
*** diazjf has joined #openstack-keystone | 01:49 | |
*** alexvictorchan has joined #openstack-keystone | 01:56 | |
*** jasonsb has joined #openstack-keystone | 01:58 | |
*** jbell8 has joined #openstack-keystone | 02:00 | |
ayoung | SOMEONE IS DOING SOMETHING EVIL IN OUR CHECK JOB! | 02:00 |
*** browne has quit IRC | 02:02 | |
*** bill_az has quit IRC | 02:06 | |
*** gildub has quit IRC | 02:07 | |
*** Ephur has joined #openstack-keystone | 02:15 | |
*** tsymancz1k has quit IRC | 02:16 | |
*** woodster_ has quit IRC | 02:16 | |
openstackgerrit | ayoung proposed openstack/keystone: Implied Roles API https://review.openstack.org/242614 | 02:23 |
ayoung | caching. Its what's for dinner. | 02:24 |
*** vivekd has joined #openstack-keystone | 02:32 | |
*** jbell8 has quit IRC | 02:32 | |
*** jbell8 has joined #openstack-keystone | 02:33 | |
*** Nirupama has joined #openstack-keystone | 02:36 | |
*** gildub has joined #openstack-keystone | 02:41 | |
*** RichardRaseley has joined #openstack-keystone | 02:44 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: Shadow users: unified identity - Separate user identities https://review.openstack.org/262045 | 02:47 |
*** yarkot has joined #openstack-keystone | 02:48 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: Shadow users: unified identity - Separate user identities https://review.openstack.org/262045 | 02:48 |
*** RichardRaseley has quit IRC | 02:49 | |
*** mgagne has quit IRC | 02:51 | |
*** mgagne has joined #openstack-keystone | 02:51 | |
*** jasonsb has quit IRC | 02:55 | |
*** browne has joined #openstack-keystone | 02:59 | |
*** e0ne has joined #openstack-keystone | 03:00 | |
*** dims has quit IRC | 03:11 | |
*** fpatwa has joined #openstack-keystone | 03:14 | |
*** vivekd has quit IRC | 03:17 | |
*** tsymanczyk has joined #openstack-keystone | 03:17 | |
*** tsymanczyk is now known as Guest9137 | 03:18 | |
*** e0ne has quit IRC | 03:19 | |
*** su_zhang has quit IRC | 03:23 | |
*** su_zhang has joined #openstack-keystone | 03:29 | |
*** Guest9137 has quit IRC | 03:31 | |
*** jbell8 has quit IRC | 03:32 | |
*** su_zhang has quit IRC | 03:32 | |
*** richm has quit IRC | 03:33 | |
*** fpatwa has quit IRC | 03:36 | |
*** fpatwa has joined #openstack-keystone | 03:37 | |
*** spandhe has quit IRC | 03:43 | |
*** tsymancz2k has joined #openstack-keystone | 03:45 | |
*** shoutm has quit IRC | 03:48 | |
*** jasonsb has joined #openstack-keystone | 03:49 | |
*** shoutm has joined #openstack-keystone | 03:55 | |
*** vivekd has joined #openstack-keystone | 04:01 | |
*** su_zhang has joined #openstack-keystone | 04:27 | |
bigjools | oh and Rally breaks if you *don't* have the versions in the URLs. Awesome. | 04:28 |
*** spandhe has joined #openstack-keystone | 04:30 | |
*** diazjf has quit IRC | 04:31 | |
openstackgerrit | henry-nash proposed openstack/keystone: Add tests for role management with v3policy file https://review.openstack.org/261846 | 04:38 |
*** markvoelker has quit IRC | 04:38 | |
openstackgerrit | henry-nash proposed openstack/keystone: Add CRUD support for domain specific roles https://review.openstack.org/261870 | 04:39 |
openstackgerrit | henry-nash proposed openstack/keystone: Modify rules in the v3 policy sample for domain specifc roles https://review.openstack.org/262078 | 04:39 |
openstackgerrit | henry-nash proposed openstack/keystone: Modify implied roles to honor domain specific roles https://review.openstack.org/263064 | 04:39 |
openstackgerrit | henry-nash proposed openstack/keystone: Modify rules for domain specific role assignments https://review.openstack.org/263549 | 04:39 |
*** henrynash has joined #openstack-keystone | 04:43 | |
*** ChanServ sets mode: +v henrynash | 04:43 | |
*** vivekd has quit IRC | 04:46 | |
*** bill_az has joined #openstack-keystone | 04:58 | |
*** vgridnev has joined #openstack-keystone | 05:04 | |
stevemar | davechen: yay https://review.openstack.org/#/c/237448/ is gating! | 05:05 |
stevemar | davechen: also, congratulations :) | 05:06 |
*** reddy has joined #openstack-keystone | 05:07 | |
openstackgerrit | Merged openstack/keystone: Use the oslo.utils.reflection to extract the class name https://review.openstack.org/241494 | 05:09 |
*** browne has quit IRC | 05:09 | |
davechen | stevemar: thanks boss! | 05:11 |
davechen | stevemar: it's a big surprise. | 05:11 |
*** chlong has quit IRC | 05:12 | |
henrynash | davechen: and well deserved! | 05:17 |
davechen | henrynash: thanks you sir. | 05:19 |
davechen | henrynash: are you at the midcycle meetups? | 05:19 |
*** fpatwa has quit IRC | 05:19 | |
henrynash | davechen: yep | 05:19 |
davechen | henrynash: cool, when will you back? | 05:20 |
*** jaosorior has joined #openstack-keystone | 05:20 | |
henrynash | davechen: in the UK? I get back on Mon/Tues | 05:20 |
davechen | henrynash: do you have a extra plan to look around? | 05:21 |
davechen | yeah | 05:21 |
davechen | henrynash: nice. | 05:21 |
davechen | henrynash: enjoy the weekend. | 05:21 |
henrynash | davechen: thx (I’m actually going back via California…so will spend the weekend there) | 05:21 |
davechen | henrynash: see you in the coming summit, miss you guys! although I was in Cananda last time but haven't got a chance to talk with you personally. | 05:22 |
henrynash | davechen: look forward to it | 05:22 |
*** amakarov has quit IRC | 05:23 | |
*** fpatwa has joined #openstack-keystone | 05:25 | |
*** chlong has joined #openstack-keystone | 05:33 | |
*** markvoelker has joined #openstack-keystone | 05:39 | |
openstackgerrit | Merged openstack/keystone: Add checks for domain scoped data creep https://review.openstack.org/253671 | 05:41 |
openstackgerrit | Merged openstack/keystone: remove KVS backend for keystone.contrib.revoke https://review.openstack.org/272134 | 05:42 |
openstackgerrit | Merged openstack/keystone: Replace tenant for project in resource files https://review.openstack.org/248295 | 05:43 |
*** markvoelker has quit IRC | 05:43 | |
*** vgridnev has quit IRC | 05:49 | |
*** fpatwa has quit IRC | 05:50 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/269479 | 05:59 |
*** henrynash has quit IRC | 06:01 | |
*** vivekd has joined #openstack-keystone | 06:02 | |
*** jbell8 has joined #openstack-keystone | 06:10 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/269479 | 06:13 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/269479 | 06:15 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/269479 | 06:17 |
*** vgridnev has joined #openstack-keystone | 06:22 | |
*** fpatwa has joined #openstack-keystone | 06:26 | |
*** chlong has quit IRC | 06:28 | |
*** rcernin has quit IRC | 06:29 | |
*** bill_az has quit IRC | 06:30 | |
*** chlong has joined #openstack-keystone | 06:39 | |
*** jaosorior has quit IRC | 06:40 | |
*** spandhe has quit IRC | 06:40 | |
*** jaosorior has joined #openstack-keystone | 06:47 | |
*** vgridnev has quit IRC | 06:51 | |
*** fpatwa has quit IRC | 06:56 | |
*** vgridnev has joined #openstack-keystone | 06:58 | |
*** xek_ has quit IRC | 07:00 | |
*** xek_ has joined #openstack-keystone | 07:01 | |
*** shoutm_ has joined #openstack-keystone | 07:01 | |
*** shoutm has quit IRC | 07:02 | |
*** vgridnev has quit IRC | 07:06 | |
*** shoutm_ has quit IRC | 07:07 | |
*** vgridnev has joined #openstack-keystone | 07:10 | |
*** shoutm has joined #openstack-keystone | 07:14 | |
openstackgerrit | Merged openstack/keystone: Add checks for project scoped data creep to tests https://review.openstack.org/253670 | 07:17 |
openstackgerrit | Merged openstack/keystone: Reuse project scoped token check for trusts https://review.openstack.org/253672 | 07:18 |
openstackgerrit | Merged openstack/keystone: Fix schema validation to use JSONSchema for empty entity https://review.openstack.org/237448 | 07:18 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/269479 | 07:20 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/269479 | 07:21 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/269479 | 07:22 |
*** jbell8 has quit IRC | 07:25 | |
*** rcernin has joined #openstack-keystone | 07:25 | |
*** jbell8 has joined #openstack-keystone | 07:26 | |
*** jbell8 has quit IRC | 07:27 | |
*** jbell8 has joined #openstack-keystone | 07:28 | |
*** chlong has quit IRC | 07:32 | |
*** belmoreira has joined #openstack-keystone | 07:33 | |
*** jbell8 has quit IRC | 07:36 | |
*** jbell8 has joined #openstack-keystone | 07:37 | |
*** su_zhang has quit IRC | 07:39 | |
*** markvoelker has joined #openstack-keystone | 07:40 | |
*** markvoelker has quit IRC | 07:44 | |
*** shoutm has quit IRC | 07:48 | |
*** shoutm has joined #openstack-keystone | 07:49 | |
*** shoutm has quit IRC | 07:51 | |
*** boris-42 has joined #openstack-keystone | 07:58 | |
*** jbell8 has quit IRC | 08:09 | |
*** jbell8 has joined #openstack-keystone | 08:10 | |
*** shoutm has joined #openstack-keystone | 08:13 | |
*** oomichi has quit IRC | 08:17 | |
*** jbell8 has quit IRC | 08:19 | |
*** jbell8 has joined #openstack-keystone | 08:20 | |
*** sinese has joined #openstack-keystone | 08:26 | |
*** shoutm has quit IRC | 08:35 | |
*** vgridnev has quit IRC | 08:36 | |
*** vgridnev has joined #openstack-keystone | 08:43 | |
*** fpatwa has joined #openstack-keystone | 08:56 | |
*** fhubik has joined #openstack-keystone | 09:00 | |
*** fpatwa has quit IRC | 09:00 | |
*** RA_ has quit IRC | 09:04 | |
*** vgridnev has quit IRC | 09:08 | |
*** jaosorior has quit IRC | 09:22 | |
*** jaosorior has joined #openstack-keystone | 09:22 | |
*** vgridnev has joined #openstack-keystone | 09:28 | |
*** jbell8 has quit IRC | 09:29 | |
*** jistr has joined #openstack-keystone | 09:30 | |
*** mhickey has joined #openstack-keystone | 09:37 | |
*** links has joined #openstack-keystone | 09:38 | |
*** links has quit IRC | 09:38 | |
*** vgridnev has quit IRC | 09:40 | |
*** markvoelker has joined #openstack-keystone | 09:41 | |
*** davechen has left #openstack-keystone | 09:43 | |
*** markvoelker has quit IRC | 09:45 | |
*** jaosorior has quit IRC | 10:08 | |
*** jaosorior has joined #openstack-keystone | 10:08 | |
*** fpatwa has joined #openstack-keystone | 10:23 | |
*** vgridnev has joined #openstack-keystone | 10:27 | |
*** reddy has quit IRC | 10:37 | |
*** RA_ has joined #openstack-keystone | 10:44 | |
openstackgerrit | Andreas Jaeger proposed openstack/oslo.policy: Update translation setup https://review.openstack.org/274000 | 10:48 |
*** reddy has joined #openstack-keystone | 10:48 | |
*** markvoelker has joined #openstack-keystone | 10:56 | |
*** markvoelker has quit IRC | 11:02 | |
*** aix has joined #openstack-keystone | 11:04 | |
*** dims has joined #openstack-keystone | 11:08 | |
*** reddy has quit IRC | 11:22 | |
*** dulek has joined #openstack-keystone | 11:23 | |
*** fpatwa has quit IRC | 11:30 | |
*** RA_ has quit IRC | 11:31 | |
*** reddy has joined #openstack-keystone | 11:36 | |
*** gildub has quit IRC | 11:42 | |
*** fpatwa has joined #openstack-keystone | 11:44 | |
*** vivekd has quit IRC | 11:49 | |
*** reddy has quit IRC | 11:51 | |
*** doug-fish has quit IRC | 11:51 | |
*** BlackDex has joined #openstack-keystone | 11:55 | |
BlackDex | Hello there, we have an issue where keystone returns unauthorized while the credentials are correct. When keystone is restarted it works for a few minutes, and after that it stops again. | 11:56 |
BlackDex | We can't seem to pinpoint the problem. | 11:56 |
BlackDex | Some suggestions? | 11:56 |
ktychkova | BlackDex: is it possible that you have some time sync issues? Is datetime correct? | 12:07 |
*** raildo-afk is now known as raildo | 12:08 | |
BlackDex | between the keystone and ldap server? | 12:08 |
*** thiagolib has quit IRC | 12:09 | |
ktychkova | BlackDex: between client machine and keystone, i think. I had something simullar - it was time sync issue between client and keystone | 12:09 |
BlackDex | and does milli-seconds generate a issue? | 12:10 |
zigo | In the Keystone Mitaka b2 package, I'm running "keystone-manage --noverbose db_sync", but its still seem to be quite verbose, what's going on? | 12:13 |
zigo | Is the option --noverbose broken, somehow? :) | 12:13 |
zigo | Not a big deal, but I'd like to have it fixed still ... :P | 12:14 |
ktychkova | BlackDex: no :) it can not be milli-seconds issue. Check that time at all your machines is almost same | 12:14 |
BlackDex | the seconds seem to be the same, on the keystone server and ldap server atleat. Ill go and check others | 12:15 |
BlackDex | ktychkova: some other suggestions maybe where to look? | 12:15 |
*** daemontool has joined #openstack-keystone | 12:15 | |
*** RA_ has joined #openstack-keystone | 12:15 | |
*** rcernin has quit IRC | 12:18 | |
ktychkova | BlackDex: give me more details. What type of authorization do you use? How to reproduce issue - what request do you send? | 12:18 |
*** rcernin has joined #openstack-keystone | 12:18 | |
BlackDex | well every client which want to use something like `nova list` etc.. or even using the horizon dashboard failes to login | 12:20 |
BlackDex | it uses LDAP | 12:20 |
*** eandersson has quit IRC | 12:23 | |
BlackDex | ktychkova: we have checked all compute nodes, and keystone server and ldap server, all have the same date/time | 12:23 |
*** fpatwa has quit IRC | 12:26 | |
ktychkova | BlackDex: I suggest you try to send dirrect request to keystone by curl. Here is manual: http://docs.openstack.org/developer/keystone/api_curl_examples.html Try: 1. restart keystone 2. send request to check it works (it should) 3. wait 4. send again | 12:30 |
ktychkova | BlackDex: so we can understand it is not a client issue | 12:31 |
ktychkova | BlackDex: you need to use first requeest from manual | 12:31 |
BlackDex | ktychkova: we still use the v2 api | 12:44 |
BlackDex | one moment | 12:44 |
*** vivekd has joined #openstack-keystone | 12:44 | |
*** markvoelker has joined #openstack-keystone | 12:57 | |
BlackDex | ktychkova: with some changes because we uses v2.0 but retreiving an auth-token works, and using that auth token to for instance get all tenants works also | 12:59 |
BlackDex | so using curl is just fine | 12:59 |
BlackDex | even using the commands a few times after eachother | 12:59 |
BlackDex | when i change the token one char, it is unauth, and change it back again, it works again | 13:00 |
*** mattt has left #openstack-keystone | 13:00 | |
BlackDex | we receive a large auth-token btw. | 13:01 |
*** markvoelker has quit IRC | 13:01 | |
ktychkova | BlackDex: I'm afraid then it is some deployment issue or client issue. And I'm not the right person to help you with it. At least we know that it is not keystone bug | 13:02 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Allow project domain_id to be nullable at the manager level https://review.openstack.org/264533 | 13:02 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Add tests in preparation of projects acting as a domain https://review.openstack.org/272369 | 13:02 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Projects acting as domains https://review.openstack.org/231289 | 13:02 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Verify project unique constraints for projects acting as domains https://review.openstack.org/158372 | 13:02 |
*** pauloewerton has joined #openstack-keystone | 13:04 | |
BlackDex | ktychkova: Thx for your help, we atleat have ruled-out something | 13:08 |
*** kragniz has quit IRC | 13:12 | |
*** gordc has joined #openstack-keystone | 13:16 | |
*** kragniz has joined #openstack-keystone | 13:18 | |
htruta | tjcocozz: hey. Are you still working on that patch? | 13:21 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Manager support for project cascade delete https://review.openstack.org/244149 | 13:23 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Add backend support for deleting a projects list https://review.openstack.org/245916 | 13:23 |
*** markvoelker has joined #openstack-keystone | 13:24 | |
*** daemontool has quit IRC | 13:29 | |
*** peter-hamilton has joined #openstack-keystone | 13:31 | |
*** doug-fish has joined #openstack-keystone | 13:31 | |
*** doug-fish has quit IRC | 13:32 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Manager support for project cascade update https://review.openstack.org/243584 | 13:32 |
*** doug-fish has joined #openstack-keystone | 13:32 | |
samueldmq | htruta: yes he is, he's just finishing a more robust test | 13:46 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Restricting domain_id update https://review.openstack.org/207218 | 13:46 |
htruta | samueldmq: ok. Just be aware that I've just rebased it due to merge conflicts | 13:46 |
samueldmq | htruta: I'd expect him to submit it this morning | 13:47 |
samueldmq | htruta: got it, tjcocozz ^ | 13:47 |
*** daemontool has joined #openstack-keystone | 13:47 | |
*** vgridnev has quit IRC | 13:47 | |
*** vgridnev has joined #openstack-keystone | 13:48 | |
*** ninag has joined #openstack-keystone | 13:51 | |
openstackgerrit | Merged openstack/oslo.policy: Update translation setup https://review.openstack.org/274000 | 13:53 |
*** daemontool has quit IRC | 13:56 | |
*** daemontool has joined #openstack-keystone | 13:57 | |
breton | oslo_config folks had a discussion about implementing storing config in a database | 13:57 |
breton | maybe someone could have a look at how they do want to do it and how we could use it for out domain-specific configs | 13:58 |
samueldmq | breton: or even share our experience with domain specific configs with them | 13:59 |
samueldmq | breton: thanks for the heads up, I will let folks know today at midcycle (cc stevemar) | 13:59 |
*** peter-hamilton has quit IRC | 14:00 | |
notmorgan | breton: i am frightened. | 14:00 |
*** peter-hamilton_ has joined #openstack-keystone | 14:00 | |
*** EinstCrazy has joined #openstack-keystone | 14:01 | |
*** Nirupama has quit IRC | 14:01 | |
*** RA_ has quit IRC | 14:03 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystone: Deprecate keystone.common.kvs https://review.openstack.org/271948 | 14:06 |
notmorgan | stevemar: ^ fixed | 14:06 |
*** peter-hamilton_ has quit IRC | 14:09 | |
breton | I see only spec https://review.openstack.org/#/c/243114/ and bknudson already -1-reviewed it | 14:10 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone: Revert "Unit test for checking cross-version migrations compatibility" https://review.openstack.org/274079 | 14:13 |
notmorgan | dolphm, lbragstad, dstanek, henrynash, ^ revert of the problem test for migrations | 14:14 |
breton | notmorgan: why revert it? | 14:14 |
notmorgan | breton: it is not an accurate nor valid test and it is blocking work. We also have spent a significant time evaluating how we are handling cross version schemas and there is a lot of work to do to prove out the "right" approach | 14:15 |
notmorgan | breton: look at the commit message for a bit more detail, but in short, unit test is the wrong approach and it misses thing. We also have gone circles on how we can even suppot x-version schemas and the original spec was both insufficient and would not really work. | 14:16 |
breton | got it | 14:17 |
notmorgan | breton: new plan is in order, and we'll be moving this type of test into it's own gate/check job that has more control and the ability to verify actual cross-version run and upgrade patterns :) | 14:17 |
notmorgan | but to unblock mitaka, we need to back it out. | 14:17 |
breton | you need to revert the spec too then | 14:18 |
*** richm has joined #openstack-keystone | 14:18 | |
notmorgan | breton: or update the spec to reflect new plan | 14:18 |
*** e0ne has joined #openstack-keystone | 14:19 | |
notmorgan | breton: that will be determined today | 14:19 |
*** vgridnev has quit IRC | 14:19 | |
*** vgridnev has joined #openstack-keystone | 14:21 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystone: Add in TRACE logging for the manager https://review.openstack.org/274085 | 14:27 |
notmorgan | dhellmann, dims: ^ first pass at some TRACE level logging, if you want to take a look :) | 14:27 |
*** fpatwa has joined #openstack-keystone | 14:27 | |
*** jsavak has joined #openstack-keystone | 14:29 | |
*** fpatwa has quit IRC | 14:31 | |
*** EinstCrazy has quit IRC | 14:51 | |
*** fhubik has quit IRC | 14:51 | |
*** mhickey has quit IRC | 14:59 | |
*** bill_az has joined #openstack-keystone | 15:01 | |
*** mhickey has joined #openstack-keystone | 15:03 | |
*** su_zhang has joined #openstack-keystone | 15:03 | |
*** pushkaru has joined #openstack-keystone | 15:05 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 15:05 | |
*** fesp has joined #openstack-keystone | 15:05 | |
*** KarthikB has joined #openstack-keystone | 15:07 | |
tjcocozz | htruta, samueldmq: I will push your test up within the hour. | 15:08 |
*** fesp has quit IRC | 15:09 | |
*** vivekd has quit IRC | 15:09 | |
*** krotscheck has quit IRC | 15:10 | |
*** slberger has joined #openstack-keystone | 15:11 | |
dims | notmorgan : nice! | 15:11 |
*** thebloggu has joined #openstack-keystone | 15:12 | |
*** vivekd has joined #openstack-keystone | 15:13 | |
*** amakarov has joined #openstack-keystone | 15:15 | |
thebloggu | keystone supports multiple endpoints for a service type and it's not considered bad practice right? I have swift running over http and https and would like to add both the endpoints to keystone | 15:16 |
openstackgerrit | Ron De Rose proposed openstack/keystone: Shadow users: unified identity - Separate user identities https://review.openstack.org/262045 | 15:19 |
*** clenimar has quit IRC | 15:19 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: Shadow users: unified identity - Separate user identities https://review.openstack.org/262045 | 15:20 |
*** clenimar has joined #openstack-keystone | 15:20 | |
*** edmondsw has joined #openstack-keystone | 15:20 | |
*** krotscheck has joined #openstack-keystone | 15:21 | |
*** timcline has joined #openstack-keystone | 15:25 | |
*** diazjf has joined #openstack-keystone | 15:27 | |
*** diazjf has left #openstack-keystone | 15:27 | |
*** diazjf has joined #openstack-keystone | 15:27 | |
*** vgridnev has quit IRC | 15:28 | |
*** vgridnev has joined #openstack-keystone | 15:32 | |
*** vgridnev has quit IRC | 15:33 | |
*** clenimar_ has quit IRC | 15:36 | |
*** clenimar has quit IRC | 15:36 | |
*** tonytan4ever has joined #openstack-keystone | 15:40 | |
*** amakarov has quit IRC | 15:41 | |
*** shaleh has joined #openstack-keystone | 15:41 | |
lbragstad | shaleh https://etherpad.openstack.org/p/keystone-office-hours | 15:42 |
*** jsavak has quit IRC | 15:44 | |
*** jsavak has joined #openstack-keystone | 15:50 | |
*** mhickey has quit IRC | 15:51 | |
*** mhickey has joined #openstack-keystone | 15:52 | |
*** jbell8 has joined #openstack-keystone | 15:55 | |
openstackgerrit | David Stanek proposed openstack/keystone: WiP: make cache invalidation safe https://review.openstack.org/274129 | 15:55 |
*** jbell8 has quit IRC | 15:57 | |
*** jbell8 has joined #openstack-keystone | 15:58 | |
*** roxanagherle has joined #openstack-keystone | 16:01 | |
*** spandhe has joined #openstack-keystone | 16:03 | |
*** belmoreira has quit IRC | 16:08 | |
*** mgarza has joined #openstack-keystone | 16:14 | |
notmorgan | 36 | 16:16 |
*** jbell8 has quit IRC | 16:17 | |
*** csoukup has joined #openstack-keystone | 16:17 | |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Introduce an identity_admin role to policy.json https://review.openstack.org/274143 | 16:17 |
*** jbell8 has joined #openstack-keystone | 16:18 | |
*** su_zhang has quit IRC | 16:19 | |
*** sinese has quit IRC | 16:19 | |
*** alejandrito has joined #openstack-keystone | 16:19 | |
*** jbell8 has quit IRC | 16:20 | |
*** alexvictorchan has quit IRC | 16:20 | |
ayoung | can we dial in? | 16:22 |
openstackgerrit | David Stanek proposed openstack/keystone: Correctly handle direct mapping with keywords https://review.openstack.org/175980 | 16:22 |
*** su_zhang has joined #openstack-keystone | 16:22 | |
ayoung | edmondsw, You OK with my rationale on https://review.openstack.org/#/c/242614/ | 16:25 |
*** rcernin has quit IRC | 16:27 | |
*** fpatwa has joined #openstack-keystone | 16:28 | |
*** spandhe has quit IRC | 16:30 | |
openstackgerrit | Tom Cocozzello proposed openstack/keystone: Manager support for project cascade delete https://review.openstack.org/244149 | 16:31 |
openstackgerrit | Tom Cocozzello proposed openstack/keystone: Add backend support for deleting a projects list https://review.openstack.org/245916 | 16:31 |
tjcocozz | htruta, samueldmq ^^ | 16:31 |
*** jaosorior has quit IRC | 16:31 | |
notmorgan | dstanek: https://review.openstack.org/#/c/272007/ and trace logger: https://review.openstack.org/#/c/274085/ | 16:32 |
*** fpatwa has quit IRC | 16:32 | |
*** jbell8 has joined #openstack-keystone | 16:33 | |
htruta | tjcocozz: nice. looking | 16:35 |
tjcocozz | htruta, glade to hear that. I wanted to add a little more complex tree test just to make sure everything was still working. | 16:36 |
*** c_soukup has joined #openstack-keystone | 16:38 | |
tjcocozz | ping stevemar | 16:38 |
stevemar | tjcocozz: oh hai | 16:38 |
tjcocozz | stevemar, if you have time could you help me set up a federated keystone? | 16:39 |
htruta | tjcocozz: liked it. Just found some minor nits. Do you want me to comment there? If not, I can fix them later | 16:39 |
tjcocozz | htruta, you don't need to comment, you can fix it later! :-) | 16:40 |
*** csoukup_ has joined #openstack-keystone | 16:41 | |
openstackgerrit | Roxana Gherle proposed openstack/keystone: Make WebSSO trusted_dashboard hostname case-insensitive https://review.openstack.org/273394 | 16:41 |
*** csoukup has quit IRC | 16:42 | |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Add "manager" roles to policy.json https://review.openstack.org/274153 | 16:42 |
*** amakarov has joined #openstack-keystone | 16:42 | |
stevemar | #success devstack now defaults to v3 for keystone | 16:43 |
openstackstatus | stevemar: Added success to Success page | 16:43 |
edmondsw | ayoung, I don't think so... WHY do you think the implied roles are safe to allow everyone to do if we don't think it's safe to allow everyone to get/list roles in general? | 16:43 |
ayoung | edmondsw, I do think it is safe to let everyone list roles | 16:44 |
edmondsw | why don't we need consistency, one way or the other? | 16:44 |
ayoung | but changing that is not in the scope of my review | 16:44 |
edmondsw | so then you should be arguing to change the others, not to make this inconsistent | 16:44 |
ayoung | I am arguing, but that is not in the scope of this review | 16:44 |
edmondsw | so make these new ones consistent with what we have for the general get/list roles, and then submit a later patch to change them both to less restricted | 16:44 |
htruta | tjcocozz: nice :) Thank you! | 16:44 |
edmondsw | don't have them inconsistent, and then make them consistent later... make them consistent now, and change them both later | 16:45 |
*** c_soukup has quit IRC | 16:45 | |
ayoung | Must I quote Thoreau at you? | 16:45 |
edmondsw | and at that point we can have the discussion of whether that second change is appropriate or not, since you don't want to have it here :) | 16:45 |
edmondsw | do you think it'll do any good? ;) | 16:45 |
edmondsw | inconsistency is clearly wrong... whereas whether get/list roles should be allowed for everyone is at least debatable... so make them consistent as first priority | 16:46 |
ayoung | edmondsw, aside from that, then, | 16:46 |
*** mhickey_ has joined #openstack-keystone | 16:47 | |
edmondsw | what was the "needed to take caching into account" comment? | 16:48 |
edmondsw | oh, that just probably wasn't replying to me... k | 16:48 |
ayoung | edmondsw, that is why the unit tests started failin in test_v3_auth | 16:48 |
edmondsw | yeah, gotcha | 16:48 |
ayoung | if you add a role inference rule, you need to invalidate the cache | 16:48 |
ayoung | otherwise, the user has the same roles in the token before and after | 16:49 |
ayoung | same for delete | 16:49 |
*** mhickey has quit IRC | 16:49 | |
edmondsw | right, sure | 16:49 |
ayoung | edmondsw, there was some git weirdness that origin/master did not have the changes that gerrit/master had, and a local rebase was not working. | 16:49 |
edmondsw | the "additional APIs required should be submitted as follow-on changes" comment... I'm not a core, so I can't -2 this. you need to convince the other cores there, not me. | 16:50 |
ayoung | took me a while to be able to reproduce the issue | 16:50 |
edmondsw | I would argue that it's always easier to make API changes before they're merged, but it's not my call | 16:50 |
edmondsw | we're not talking about additional APIs here... we're talking about replacing some of these with different APIs | 16:50 |
ayoung | edmondsw, the spec was approved as is. If you want a different API, post it as a spec change | 16:50 |
ayoung | we can certainly change to that, but at this point it really is bike shedding | 16:51 |
ayoung | we have the infomration we need to do implied roles | 16:51 |
ayoung | we can probably modify the core role APIs to show the data you want | 16:51 |
ayoung | although I don't know if we want it to have both implied and prior in the response | 16:52 |
*** diazjf has quit IRC | 16:53 | |
edmondsw | ayoung, wish you were here... you'd love the conversation we just had about why we don't actually need implied roles after all... | 16:55 |
lbragstad | notmorgan https://review.openstack.org/#/c/258650/ | 16:55 |
gordc | stevemar: do i have to change anything that says v2.0 to v3 now? | 16:55 |
gordc | stevemar: https://github.com/openstack-dev/devstack/commit/f4ce44bf3fbf06e53c2ae3ec6aa4996831cf4605 | 16:56 |
lbragstad | notmorgan consolidation stuff needs to happen too https://review.openstack.org/#/q/status:open+project:openstack/keystone+branch:master+topic:consolidate-fernet-provider | 16:56 |
ayoung | edmondsw, well I'm not there. What was the rationale | 16:56 |
edmondsw | not sure where to begin there... outcome of a long discussion | 16:57 |
*** alexvictorchan has joined #openstack-keystone | 16:57 | |
ayoung | edmondsw, I can call in | 16:57 |
ayoung | edmondsw, then it didn't happen and is meaning less. | 16:57 |
ayoung | And yes, I am starting to get a little annoyed | 16:57 |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Add an "auditor" role to policy.json https://review.openstack.org/274157 | 16:57 |
edmondsw | lol we cannot be blamed for your absence... to my knowledge ;) | 16:57 |
ayoung | dolphm, there was a spec by jamielennox|away for this | 16:57 |
dolphm | ayoung: *shrug* | 16:58 |
ayoung | dolphm, fot all the roles...let me find it | 16:58 |
edmondsw | ayoung, check with normorgan and henrynash... I'll let them explain | 16:58 |
ayoung | I think you are on the same page as him | 16:58 |
dolphm | ayoung: cross project spec? | 16:58 |
ayoung | dolphm, yea | 16:58 |
ayoung | dolphm, https://review.openstack.org/#/c/245629/ | 16:59 |
ayoung | dolphm, he called it observer, | 16:59 |
ayoung | but the identity_admin is in keeping with what he had | 16:59 |
notmorgan | ayoung: and we talked about some changes to oslo.policy to make it easier | 17:00 |
ayoung | notmorgan, I can call in | 17:00 |
notmorgan | ayoung: it's not really a group thing small breakout groups | 17:00 |
notmorgan | so a call in doesn't help | 17:00 |
notmorgan | [and the wifi sucks so hangouts may tip over :( ] | 17:01 |
openstackgerrit | Ron De Rose proposed openstack/keystone: Shadow users: unified identity - Separate user identities https://review.openstack.org/262045 | 17:01 |
notmorgan | s/may/will. | 17:01 |
ayoung | notmorgan, I need to be part of this discsussion | 17:01 |
*** diazjf has joined #openstack-keystone | 17:01 | |
notmorgan | ayoung: we will continue it on IRC after midcycle | 17:01 |
notmorgan | dolphm: is setting up the "code example" so we can discuss more | 17:01 |
openstackgerrit | Ron De Rose proposed openstack/keystone: Shadow users: unified identity - Separate user identities https://review.openstack.org/262045 | 17:01 |
notmorgan | this is not "merge as is proposed" | 17:01 |
gordc | anyone? do i need to update keystone target( https://github.com/openstack/aodh/blob/master/devstack/plugin.sh#L202) now that devstack defaults to v3? | 17:01 |
notmorgan | and most people are picking up to leave soon since flights | 17:02 |
ayoung | notmorgan, give me the summary please | 17:02 |
notmorgan | ayoung: will do once it's all posted. | 17:02 |
ayoung | I'm happy to call direct | 17:02 |
*** jbell8_ has joined #openstack-keystone | 17:02 | |
notmorgan | ayoung: easier to do so then so we have common things to look at. | 17:02 |
notmorgan | concrete examples = easier to discuss than nebulous hand-waving-over-the-phone | 17:02 |
*** shaleh has quit IRC | 17:02 | |
*** e0ne has quit IRC | 17:03 | |
*** shaleh has joined #openstack-keystone | 17:03 | |
*** jbell8 has quit IRC | 17:03 | |
lbragstad | notmorgan looks like devstack already does #1 on your list - https://github.com/openstack-dev/devstack/blob/f4ce44bf3fbf06e53c2ae3ec6aa4996831cf4605/lib/keystone#L461-L464 | 17:03 |
notmorgan | lbragstad: fantastic | 17:04 |
notmorgan | lbragstad: easy then | 17:04 |
*** daemontool has quit IRC | 17:04 | |
lbragstad | notmorgan so then we make this fernet? | 17:05 |
lbragstad | https://github.com/openstack-dev/devstack/blob/f4ce44bf3fbf06e53c2ae3ec6aa4996831cf4605/lib/keystone#L250 | 17:05 |
ayoung | notmorgan, of course we don't need implied roles. We can do it all in policy. Except then we can't query it. | 17:05 |
notmorgan | ayoung: and i think what we're saying is we don't need to query it | 17:06 |
ayoung | notmorgan, then you have not really solved the problem | 17:06 |
edmondsw | gordc, everything should be changing to v3, so I would say yes | 17:06 |
edmondsw | you'd need to change more than just the auth_url... you'd at least have to specify domain as well | 17:07 |
*** diazjf has quit IRC | 17:08 | |
gordc | edmondsw: sigh... i hope this was broadcasted and i just missed it. | 17:08 |
*** vivekd has quit IRC | 17:08 | |
gordc | edmondsw: do you happen to have example service_credentials list required? | 17:08 |
*** spandhe has joined #openstack-keystone | 17:09 | |
notmorgan | ayoung: we would create local groups [regardless of the idm groups], so you can use groups to do the assignment of a "set of roles" which we already support | 17:09 |
notmorgan | ayoung: so, always have "keystone managed groups" | 17:09 |
ayoung | notmorgan, I'm calling in | 17:09 |
*** su_zhang has quit IRC | 17:09 | |
notmorgan | i wanted to hold up until we had the concrete examples then we can figure this out and discuss it more | 17:09 |
ayoung | there are so many things you have not considered. | 17:10 |
notmorgan | ayoung: we have a lot of other convos happening | 17:10 |
notmorgan | ayoung: so example will be posted and we can then have the convo | 17:10 |
notmorgan | not "merge this example" | 17:10 |
notmorgan | just so we can explain with a concrete example and we can say "oh we are missing X then" | 17:10 |
ayoung | or you are completely missing the point and I have been heads down on this problem for 2 years. | 17:10 |
notmorgan | ayoung: so.. lets have the example first then make sure we covered the bases and aren't missing something. | 17:10 |
ayoung | and by you I mean all of you | 17:11 |
*** pushkaru has quit IRC | 17:11 | |
*** diazjf has joined #openstack-keystone | 17:11 | |
* notmorgan has to jump into a different convo now. | 17:11 | |
*** pushkaru has joined #openstack-keystone | 17:12 | |
edmondsw | gordc, I'm trying to remember what service_credentials is and why it's distinct from keystone_authtoken ? | 17:12 |
ayoung | edmondsw, stevemar, bknudson topol please dial in to the conf line | 17:12 |
lbragstad | raildo o/ | 17:12 |
raildo | lbragstad: \o | 17:12 |
lbragstad | raildo getting a few minutes here at the mid-cycle. when you left your comment on https://review.openstack.org/#/c/258650/15 did you test that patch on the consolidation patches? | 17:13 |
*** _cjones_ has joined #openstack-keystone | 17:13 | |
*** sinese has joined #openstack-keystone | 17:14 | |
edmondsw | gordc, look at stack.sh lines 1009-1017 | 17:15 |
raildo | lbragstad: no I didn't but I saw that a lot of tests was broking on the issue_v2_token | 17:15 |
lbragstad | ah gotcha - let me see if I can rebase those | 17:16 |
lbragstad | the validate_v3_token patch is ready for review | 17:16 |
*** thiagolib has joined #openstack-keystone | 17:16 | |
*** sinese has quit IRC | 17:16 | |
raildo | lbragstad: so I thought that this patch https://review.openstack.org/#/c/197647/23 will fix this erros | 17:16 |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Add granular roles (per policy capability) to policy.json https://review.openstack.org/274168 | 17:16 |
raildo | lbragstad: nice, i'll review it in a few minutes :) | 17:17 |
openstackgerrit | Roxana Gherle proposed openstack/keystone: Allow '_' character in mapping_id value https://review.openstack.org/264937 | 17:17 |
lbragstad | raildo thanks - I'll see if I can fix up the v2 ones | 17:17 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Remove foreign assignments when deleting a domain https://review.openstack.org/127433 | 17:17 |
samueldmq | dstanek: lbragstad: ^ this should fix one more bug | 17:17 |
gordc | edmondsw: ack. thanks | 17:17 |
raildo | lbragstad: great :) anything that you want related to this, I'm available | 17:18 |
edmondsw | gordc, and for endpoint type, note that v2 would be something like "publicURL" whereas v3 would be something like "public"... drops the "URL" from the end | 17:18 |
lbragstad | raildo awesome - let's start with https://review.openstack.org/#/c/196877/ and see if we can get that close to merging | 17:19 |
lbragstad | raildo then we can move to fixing up the issue_v2_token and validate_v2_token paths | 17:19 |
edmondsw | gordc, why is service_credentials distinct from keystone_authtoken? | 17:19 |
raildo | lbragstad: sounds good to me :) | 17:20 |
*** _cjones_ has quit IRC | 17:20 | |
lbragstad | which are https://review.openstack.org/#/c/197647/ and https://review.openstack.org/#/c/197706/ | 17:20 |
*** _cjones_ has joined #openstack-keystone | 17:20 | |
lbragstad | then we can rebase https://review.openstack.org/#/c/267781/ and https://review.openstack.org/#/c/258650/15 on top of all those | 17:20 |
lbragstad | raildo then we should have a better idea of the other failures (hopefully) | 17:20 |
raildo | lbragstad: there is a lot of odd tests :( | 17:22 |
bknudson | ayoung: I don't have the moderator passcode | 17:23 |
gordc | edmondsw: we use service_credentials to access other service apis (polling) | 17:23 |
bknudson | ayoung: we're just having small group discussion so I don't think you'd be able to hear anything | 17:23 |
lbragstad | dstanek https://review.openstack.org/#/c/196877/32 | 17:23 |
lbragstad | raildo some of that is going to be the lack of sub-second precision | 17:23 |
bknudson | ayoung: plus, we'll be breaking up for lunch | 17:23 |
lbragstad | raildo which notmorgan wants to mock the time on | 17:23 |
ayoung | bknudson, something was discussed about implied groups, something is going on with that and if that discussion is happening I should be a part of it. | 17:24 |
bknudson | ayoung: that discussion is complete | 17:24 |
ayoung | If someone proposed that it can all be done in policy, they don't understand the full problem | 17:24 |
ayoung | bknudson, you missed a word | 17:25 |
bknudson | I think it's about domain roles | 17:25 |
raildo | lbragstad: hum... got it | 17:25 |
ayoung | is henry still there? | 17:25 |
bknudson | ayoung: henry is here. | 17:25 |
ayoung | bknudson, tell him to call me | 17:27 |
*** sinese has joined #openstack-keystone | 17:27 | |
bknudson | ayoung: apparently he can't get on irc so I told him you're interested | 17:27 |
*** shaleh_ has joined #openstack-keystone | 17:28 | |
*** woodster_ has joined #openstack-keystone | 17:29 | |
*** sinese has quit IRC | 17:30 | |
*** shaleh has quit IRC | 17:31 | |
notmorgan | bknudson, stevemar: https://review.openstack.org/#/c/274074/2 | 17:33 |
*** jasonsb has quit IRC | 17:36 | |
*** jasonsb has joined #openstack-keystone | 17:37 | |
*** sinese has joined #openstack-keystone | 17:38 | |
*** sinese has quit IRC | 17:39 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Consolidate the fernet provider issue_v2_token() https://review.openstack.org/197647 | 17:44 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Consolidate the fernet provider validate_v3_token() https://review.openstack.org/196877 | 17:44 |
*** jasonsb has quit IRC | 17:46 | |
dolphm | notmorgan: freezegun usage in keystone https://review.openstack.org/#/c/227995/ | 17:47 |
openstackgerrit | David Stanek proposed openstack/keystone: Correctly handle direct mapping with keywords https://review.openstack.org/175980 | 17:49 |
*** jistr has quit IRC | 17:49 | |
*** timcline has quit IRC | 17:49 | |
*** browne has joined #openstack-keystone | 17:51 | |
*** sinese has joined #openstack-keystone | 17:56 | |
*** rodrigods has quit IRC | 17:57 | |
*** rodrigods has joined #openstack-keystone | 17:57 | |
*** sinese has quit IRC | 17:58 | |
*** su_zhang has joined #openstack-keystone | 17:59 | |
dolphm | updated the cross-project spec https://review.openstack.org/#/c/245629/ | 18:01 |
*** su_zhang has quit IRC | 18:01 | |
dolphm | for "common default policy" conventions / schema | 18:01 |
*** sigmavirus24 is now known as sigmavirus24_awa | 18:02 | |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Add an "observer" role to policy.json https://review.openstack.org/274157 | 18:03 |
dolphm | ayoung: replaced "auditor" with "observer," btw ^ | 18:03 |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Add granular roles (per policy capability) to policy.json https://review.openstack.org/274168 | 18:06 |
*** diazjf has quit IRC | 18:08 | |
*** edmondsw has quit IRC | 18:23 | |
*** roxanagherle has quit IRC | 18:24 | |
*** timcline has joined #openstack-keystone | 18:25 | |
*** fpatwa has joined #openstack-keystone | 18:29 | |
*** timcline has quit IRC | 18:30 | |
openstackgerrit | ayoung proposed openstack/keystone: Implied Roles API https://review.openstack.org/242614 | 18:32 |
*** fpatwa has quit IRC | 18:33 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 18:41 | |
*** iurygregory has quit IRC | 18:41 | |
*** amakarov has quit IRC | 18:45 | |
*** su_zhang has joined #openstack-keystone | 18:57 | |
*** pcaruana has joined #openstack-keystone | 18:57 | |
*** su_zhang has quit IRC | 18:58 | |
*** daemontool has joined #openstack-keystone | 18:58 | |
*** markd_ has joined #openstack-keystone | 18:59 | |
*** gordc has quit IRC | 19:00 | |
*** su_zhang has joined #openstack-keystone | 19:02 | |
thebloggu | i'm trying to get the service catalog using keystonclient with a token but the client seems not to have one. can someone help me? if I try to use a token and the cli to get the catalog I get the message "Configuration error: Client configured to run without a service catalog. Run the client using --os-auth-url or OS_AUTH_URL, instead of --os-endpoint or OS_SERVICE_ENDPOINT, for example." | 19:02 |
*** timcline has joined #openstack-keystone | 19:03 | |
*** jsavak has quit IRC | 19:04 | |
*** markd_ has quit IRC | 19:04 | |
openstackgerrit | Merged openstack/keystone: Update bandit.yaml https://review.openstack.org/267044 | 19:10 |
*** daemontool has quit IRC | 19:10 | |
openstackgerrit | Merged openstack/keystone: Enable bandit tests https://review.openstack.org/267051 | 19:11 |
*** mhickey_ has quit IRC | 19:11 | |
*** jsavak has joined #openstack-keystone | 19:13 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/269479 | 19:17 |
*** pushkaru has quit IRC | 19:17 | |
*** krotscheck has quit IRC | 19:17 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/269479 | 19:18 |
*** pcaruana has quit IRC | 19:24 | |
*** gordc has joined #openstack-keystone | 19:26 | |
*** jsavak has quit IRC | 19:29 | |
*** jsavak has joined #openstack-keystone | 19:30 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystone: Add in TRACE logging for the manager https://review.openstack.org/274085 | 19:32 |
*** pcaruana has joined #openstack-keystone | 19:37 | |
*** jistr has joined #openstack-keystone | 19:37 | |
*** fesp has joined #openstack-keystone | 19:38 | |
*** diazjf has joined #openstack-keystone | 19:38 | |
*** pushkaru has joined #openstack-keystone | 19:39 | |
jorge_munoz | ayoung: lbragstad I think I found another issue with trust, but I wanted to double check with you guys. User A creates a trust for redelegation to User B, then User B gets a trust scope token and is able to create a trust to User C with impersonation set to True. That should return something like bad request, right? | 19:42 |
ayoung | dolphm, I really like this https://review.openstack.org/#/c/245629/4..5/specs/common-default-policy.rst | 19:42 |
lbragstad | jorge_munoz meaning that you can't create an impersonated trust with a trust? | 19:43 |
ayoung | jorge_munoz, if the origianly trust allowed impersonation, it probably should not allow redelegation, but it might be required | 19:43 |
ayoung | if the origianly trust did not allow impersonation, the redelegated trust should not allow impersonation | 19:43 |
*** shaleh_ has quit IRC | 19:43 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystone: Use requst local in-process cache per request https://review.openstack.org/272007 | 19:44 |
lbragstad | i agree - i don't think we should allow *any* intermixing of redelegation and impersonation | 19:44 |
lbragstad | as someone creating a trust - i either need to use impersonation, redelegation, or neither | 19:45 |
ayoung | lbragstad, what we want, and what is required are two different things | 19:45 |
ayoung | if impersonation is needed, it will need to be redelegated | 19:45 |
jorge_munoz | Yes, the original trust did not allow impersonation, but i was able to create a redelegated trust with impersonation. | 19:45 |
jorge_munoz | impersonation set to trust. | 19:46 |
ayoung | for example, if the resournce is owned by a user, and you need to be that user to change it, such as some swift and barbican resources, then I delegate to, say Ansible-as-a-server which tehn delegates to heat which delelagest to glance, which needs to do the actual work | 19:46 |
jorge_munoz | true* | 19:46 |
ayoung | jorge_munoz, that is a bug | 19:46 |
jorge_munoz | ayoung: lbragstad thanks, I’ll create a bug for it then. | 19:47 |
*** su_zhang has quit IRC | 19:48 | |
dstanek | notmorgan: http://paste.openstack.org/show/485480/ | 19:52 |
*** fesp has quit IRC | 19:56 | |
*** jasonsb has joined #openstack-keystone | 19:59 | |
*** thebloggu has quit IRC | 20:03 | |
*** jsavak has quit IRC | 20:03 | |
*** pcaruana has quit IRC | 20:06 | |
*** jsavak has joined #openstack-keystone | 20:06 | |
*** pcaruana has joined #openstack-keystone | 20:09 | |
samueldmq | stevemar: http://fairy-slipper.russellsim.org/#/by-tag/identity/v3/ | 20:09 |
*** pcaruana has quit IRC | 20:19 | |
*** thiagolib has quit IRC | 20:19 | |
*** diazjf has quit IRC | 20:21 | |
*** timcline has quit IRC | 20:25 | |
*** slberger has quit IRC | 20:25 | |
*** timcline has joined #openstack-keystone | 20:26 | |
*** vgridnev has joined #openstack-keystone | 20:29 | |
*** fpatwa has joined #openstack-keystone | 20:30 | |
*** richm has quit IRC | 20:30 | |
*** fpatwa has quit IRC | 20:34 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/272790 | 20:45 |
*** richm has joined #openstack-keystone | 20:46 | |
*** slberger has joined #openstack-keystone | 20:47 | |
openstackgerrit | Paulo Ewerton Gomes Fragoso proposed openstack/keystone: WIP API support for project cascade update https://review.openstack.org/243585 | 20:51 |
openstackgerrit | Jorge Munoz proposed openstack/keystone: Fix trust redelegation tests https://review.openstack.org/273232 | 20:53 |
openstackgerrit | Jorge Munoz proposed openstack/keystone: Add tests for trust using impersonation https://review.openstack.org/273279 | 20:53 |
*** diazjf has joined #openstack-keystone | 20:57 | |
*** diazjf1 has joined #openstack-keystone | 20:58 | |
openstackgerrit | Jorge Munoz proposed openstack/keystone: Add tests for trust using impersonation https://review.openstack.org/273279 | 20:59 |
*** diazjf has quit IRC | 20:59 | |
*** jasonsb has quit IRC | 20:59 | |
*** tsymanczyk has joined #openstack-keystone | 21:04 | |
*** tsymancz2k has quit IRC | 21:04 | |
*** tsymanczyk is now known as Guest75940 | 21:04 | |
openstackgerrit | Jorge Munoz proposed openstack/keystone: Add tests for trust using impersonation https://review.openstack.org/273279 | 21:05 |
*** dims has quit IRC | 21:09 | |
*** su_zhang has joined #openstack-keystone | 21:09 | |
*** jistr has quit IRC | 21:10 | |
openstackgerrit | Jorge Munoz proposed openstack/keystone: Do not allow creating redelegated trust when using impersonated token. https://review.openstack.org/274250 | 21:30 |
*** bill_az has quit IRC | 21:35 | |
*** rcernin has joined #openstack-keystone | 21:36 | |
*** dims has joined #openstack-keystone | 21:39 | |
*** jgriffith is now known as jgriffith_away | 21:43 | |
*** vgridnev has quit IRC | 21:44 | |
*** ninag has quit IRC | 21:48 | |
*** raildo is now known as raildo-afk | 21:48 | |
*** jsavak has quit IRC | 21:49 | |
*** jsavak has joined #openstack-keystone | 21:49 | |
*** diazjf1 has quit IRC | 21:50 | |
*** zqfan has quit IRC | 21:51 | |
*** pauloewerton has quit IRC | 21:51 | |
*** timcline has quit IRC | 21:52 | |
*** vgridnev has joined #openstack-keystone | 21:52 | |
*** timcline has joined #openstack-keystone | 21:53 | |
*** alejandrito has quit IRC | 21:54 | |
*** vgridnev has quit IRC | 21:56 | |
*** su_zhang has quit IRC | 21:59 | |
*** alexvictorchan has quit IRC | 22:00 | |
*** Guest75940 has quit IRC | 22:03 | |
*** su_zhang has joined #openstack-keystone | 22:07 | |
*** doug-fis_ has joined #openstack-keystone | 22:10 | |
*** doug-fi__ has joined #openstack-keystone | 22:14 | |
*** gordc has quit IRC | 22:14 | |
*** doug-fish has quit IRC | 22:14 | |
*** timcline has quit IRC | 22:15 | |
*** doug-fis_ has quit IRC | 22:17 | |
*** doug-fi__ has quit IRC | 22:18 | |
*** jbell8_ has quit IRC | 22:19 | |
*** e0ne has joined #openstack-keystone | 22:24 | |
*** doug-fish has joined #openstack-keystone | 22:26 | |
*** tonytan4ever has quit IRC | 22:27 | |
*** RA_ has joined #openstack-keystone | 22:28 | |
*** fpatwa has joined #openstack-keystone | 22:30 | |
*** doug-fish has quit IRC | 22:31 | |
* notmorgan does the hotel bar devstack build dance. | 22:33 | |
*** fpatwa has quit IRC | 22:35 | |
*** RA_ has quit IRC | 22:36 | |
*** cdcasey has joined #openstack-keystone | 22:36 | |
*** spzala has joined #openstack-keystone | 22:36 | |
*** e0ne_ has joined #openstack-keystone | 22:37 | |
*** dims has quit IRC | 22:38 | |
*** cdcasey has left #openstack-keystone | 22:38 | |
*** cdcasey has joined #openstack-keystone | 22:38 | |
*** e0ne has quit IRC | 22:39 | |
*** aix has quit IRC | 22:39 | |
*** aix has joined #openstack-keystone | 22:40 | |
*** aix is now known as Guest965 | 22:40 | |
*** e0ne has joined #openstack-keystone | 22:45 | |
*** e0ne_ has quit IRC | 22:45 | |
*** e0ne_ has joined #openstack-keystone | 22:46 | |
*** lhcheng has joined #openstack-keystone | 22:47 | |
*** ChanServ sets mode: +v lhcheng | 22:47 | |
*** e0ne has quit IRC | 22:49 | |
*** roxanaghe has joined #openstack-keystone | 22:54 | |
*** su_zhang has quit IRC | 22:59 | |
*** KarthikB has quit IRC | 22:59 | |
*** su_zhang has joined #openstack-keystone | 23:00 | |
openstackgerrit | Jorge Munoz proposed openstack/keystone: Do not allow creating redelegated trust when using impersonated token. https://review.openstack.org/274250 | 23:00 |
*** sigmavirus24 is now known as sigmavirus24_awa | 23:00 | |
*** alejandrito has joined #openstack-keystone | 23:01 | |
*** alexvictorchan has joined #openstack-keystone | 23:02 | |
*** jsavak has quit IRC | 23:03 | |
cdcasey | I'm assuming keystone client is only deprecated for CLI, correct? E.G., when writing a python script, we should still be importing from keystoneclient.v3, not from some openstack lib? | 23:04 |
*** jorge_munoz has quit IRC | 23:04 | |
*** tsymancz1k has joined #openstack-keystone | 23:10 | |
*** roxanaghe has quit IRC | 23:15 | |
*** cdcasey has quit IRC | 23:23 | |
breton | yes, that's correct, the guy who quit | 23:29 |
*** mgarza has quit IRC | 23:30 | |
*** sshen has quit IRC | 23:34 | |
*** sshen has joined #openstack-keystone | 23:37 | |
*** csoukup_ has quit IRC | 23:41 | |
*** alejandrito has quit IRC | 23:41 | |
*** sshen has quit IRC | 23:43 | |
*** su_zhang has quit IRC | 23:44 | |
*** sshen has joined #openstack-keystone | 23:45 | |
*** e0ne_ has quit IRC | 23:49 | |
*** hughsaunders has quit IRC | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!