*** spzala has joined #openstack-keystone | 00:00 | |
*** shaleh has quit IRC | 00:01 | |
*** doug-fis_ has joined #openstack-keystone | 00:02 | |
*** rderose has quit IRC | 00:02 | |
*** doug-fish has quit IRC | 00:03 | |
*** spzala has quit IRC | 00:05 | |
*** doug-fis_ has quit IRC | 00:07 | |
bknudson | oops, it was the apache config needs to match the keystone setting. | 00:07 |
---|---|---|
*** markvoelker has joined #openstack-keystone | 00:09 | |
*** furface has joined #openstack-keystone | 00:15 | |
*** doug-fish has joined #openstack-keystone | 00:16 | |
*** edtubill has joined #openstack-keystone | 00:22 | |
*** mylu has quit IRC | 00:28 | |
*** lhcheng has quit IRC | 00:37 | |
*** rbridgeman has quit IRC | 00:38 | |
openstackgerrit | ZhiQiang Fan proposed openstack/keystone: switch to tempest instead of deprecated tempest-lib https://review.openstack.org/311901 | 00:43 |
*** sigmavirus24 is now known as sigmavirus24_awa | 00:45 | |
*** fawadkhaliq has quit IRC | 00:50 | |
*** dan_nguyen has quit IRC | 00:51 | |
*** spzala has joined #openstack-keystone | 00:58 | |
knikolla | o/ | 01:01 |
knikolla | sorry for missing the discussion, still haven’t recovered from the cold | 01:01 |
*** david-lyle has joined #openstack-keystone | 01:09 | |
stevemar | bknudson: try "dos" | 01:13 |
*** EinstCrazy has joined #openstack-keystone | 01:22 | |
*** EinstCra_ has joined #openstack-keystone | 01:31 | |
*** adu has joined #openstack-keystone | 01:32 | |
*** EinstCrazy has quit IRC | 01:35 | |
knikolla | stevemar: “review at own risk” and firefox crashed :P | 01:35 |
*** dan_nguyen has joined #openstack-keystone | 01:40 | |
*** edmondsw has quit IRC | 01:42 | |
*** doug-fish has quit IRC | 01:57 | |
*** doug-fish has joined #openstack-keystone | 01:57 | |
*** adu has quit IRC | 01:57 | |
*** jrist has quit IRC | 01:59 | |
*** doug-fis_ has joined #openstack-keystone | 02:00 | |
*** doug-fish has quit IRC | 02:01 | |
*** doug-fis_ has quit IRC | 02:05 | |
*** doug-fish has joined #openstack-keystone | 02:07 | |
*** jrist has joined #openstack-keystone | 02:12 | |
morgan | knikolla: feel better | 02:13 |
*** spzala has quit IRC | 02:17 | |
*** topol has quit IRC | 02:18 | |
*** TxGVNN has joined #openstack-keystone | 02:20 | |
*** sdake has joined #openstack-keystone | 02:20 | |
stevemar | knikolla: clearly firefox is looking out for you :P | 02:21 |
stevemar | knikolla: get some rest and start fresh tomorrow :) | 02:21 |
*** c_soukup has joined #openstack-keystone | 02:21 | |
*** topol_ has joined #openstack-keystone | 02:23 | |
knikolla | morgan, stevemar: thank you | 02:23 |
knikolla | and thank you firefox also :P haha | 02:25 |
*** hoonetorg has quit IRC | 02:35 | |
*** ozialien10 has quit IRC | 02:39 | |
*** hoonetorg has joined #openstack-keystone | 02:49 | |
*** spzala has joined #openstack-keystone | 02:50 | |
*** ChanServ sets mode: +v topol_ | 02:55 | |
*** topol_ is now known as topol | 02:55 | |
*** richm has quit IRC | 03:01 | |
openstackgerrit | Steve Martinelli proposed openstack/python-keystoneclient: Updated from global requirements https://review.openstack.org/311548 | 03:13 |
*** fangxu has quit IRC | 03:17 | |
*** wanghua has joined #openstack-keystone | 03:21 | |
*** dave-mccowan has quit IRC | 04:06 | |
*** tqtran has quit IRC | 04:07 | |
*** spzala has quit IRC | 04:07 | |
*** spzala has joined #openstack-keystone | 04:08 | |
*** doug-fish has quit IRC | 04:09 | |
*** spzala has quit IRC | 04:12 | |
*** sudorandom has quit IRC | 04:14 | |
*** pleia2 has quit IRC | 04:16 | |
*** pleia2 has joined #openstack-keystone | 04:16 | |
*** links has joined #openstack-keystone | 04:17 | |
*** markvoelker has quit IRC | 04:19 | |
*** sudorandom has joined #openstack-keystone | 04:19 | |
*** c_soukup has quit IRC | 04:23 | |
*** spzala has joined #openstack-keystone | 04:24 | |
*** dan_nguyen has quit IRC | 04:26 | |
*** spzala has quit IRC | 04:29 | |
*** adu has joined #openstack-keystone | 04:45 | |
*** adu has quit IRC | 04:49 | |
*** josecastroleon has joined #openstack-keystone | 04:52 | |
*** spzala has joined #openstack-keystone | 05:00 | |
*** lhcheng has joined #openstack-keystone | 05:02 | |
*** ChanServ sets mode: +v lhcheng | 05:02 | |
*** spzala has quit IRC | 05:05 | |
*** lhcheng_ has joined #openstack-keystone | 05:08 | |
*** lhcheng has quit IRC | 05:11 | |
*** markvoelker has joined #openstack-keystone | 05:19 | |
TxGVNN | hi everyone, i want to config federation in keystone. | 05:23 |
TxGVNN | when i execute "keystone saml_idp_metadata" | 05:23 |
TxGVNN | it is a error: http://paste.openstack.org/show/495922/ | 05:24 |
*** markvoelker has quit IRC | 05:24 | |
TxGVNN | ValidationError: Ensure configuration option idp_entity_id is set | 05:24 |
TxGVNN | sorry, i have found my problem. thanks | 05:29 |
*** sdake has quit IRC | 05:37 | |
*** sdake has joined #openstack-keystone | 05:39 | |
openstackgerrit | Tin Lam proposed openstack/keystoneauth: Fix ClientException message property not set properly https://review.openstack.org/285757 | 05:42 |
*** yolanda has joined #openstack-keystone | 05:44 | |
*** yolanda has quit IRC | 05:48 | |
*** yolanda has joined #openstack-keystone | 05:48 | |
*** edtubill has quit IRC | 05:53 | |
*** edtubill has joined #openstack-keystone | 05:55 | |
*** spzala has joined #openstack-keystone | 06:02 | |
*** spzala has quit IRC | 06:07 | |
*** edtubill has quit IRC | 06:12 | |
*** rcernin has joined #openstack-keystone | 06:15 | |
*** EinstCra_ has quit IRC | 06:17 | |
*** EinstCrazy has joined #openstack-keystone | 06:17 | |
*** markvoelker has joined #openstack-keystone | 06:20 | |
*** markvoelker has quit IRC | 06:25 | |
*** yolanda has quit IRC | 06:27 | |
*** yolanda has joined #openstack-keystone | 06:27 | |
stevemar | jamielennox: poke | 06:28 |
jamielennox | stevemar: poke | 06:28 |
jamielennox | stevemar: poke poke stab stab | 06:29 |
stevemar | jamielennox: hope you're not sick :) | 06:29 |
jamielennox | stevemar: still scratchy but Jayne has gotten immediately sick | 06:29 |
stevemar | jamielennox: :( | 06:29 |
jamielennox | so i have been blamed as a carrier - and i completely through you under a bus | 06:29 |
stevemar | jamielennox: topol is also reporting in sick | 06:29 |
stevemar | i blame whoever gave it to me | 06:29 |
jamielennox | without solid names i have no one else to offer | 06:30 |
jamielennox | stevemar: you back to full health? | 06:31 |
stevemar | jamielennox: just about -- DM'ed ya | 06:31 |
stevemar | jamielennox: throat is still a bit scratchy | 06:32 |
*** yolanda has quit IRC | 06:34 | |
*** yolanda has joined #openstack-keystone | 06:40 | |
*** lhcheng_ has quit IRC | 06:42 | |
*** tesseract has joined #openstack-keystone | 06:44 | |
*** tesseract is now known as Guest40479 | 06:44 | |
-openstackstatus- NOTICE: Filesystem on logs.openstack.org is broken, we are on the process of repairing it. Please stop checking your jobs until further notice | 06:44 | |
*** ChanServ changes topic to "Filesystem on logs.openstack.org is broken, we are on the process of repairing it. Please stop checking your jobs until further notice" | 06:44 | |
*** daemontool_ has quit IRC | 06:45 | |
*** Guest40479 has quit IRC | 06:47 | |
*** tesseract- has joined #openstack-keystone | 06:49 | |
*** fangxu has joined #openstack-keystone | 06:49 | |
*** fangxu_ has joined #openstack-keystone | 06:57 | |
*** fangxu has quit IRC | 06:58 | |
*** fangxu_ is now known as fangxu | 06:58 | |
*** furface has quit IRC | 07:02 | |
*** spzala has joined #openstack-keystone | 07:03 | |
*** rcernin_ has joined #openstack-keystone | 07:04 | |
*** spzala has quit IRC | 07:09 | |
*** jed56 has joined #openstack-keystone | 07:11 | |
*** furface has joined #openstack-keystone | 07:21 | |
*** markvoelker has joined #openstack-keystone | 07:21 | |
*** EinstCrazy has quit IRC | 07:22 | |
*** EinstCrazy has joined #openstack-keystone | 07:23 | |
*** markvoelker has quit IRC | 07:26 | |
*** rcernin_ has quit IRC | 07:33 | |
*** pnavarro has joined #openstack-keystone | 07:36 | |
*** rcernin has quit IRC | 07:36 | |
*** chlong has quit IRC | 07:47 | |
*** henrynash has joined #openstack-keystone | 07:53 | |
*** ChanServ sets mode: +v henrynash | 07:53 | |
*** sdake has quit IRC | 07:56 | |
*** xek__ has joined #openstack-keystone | 07:57 | |
*** zhiyan_ has joined #openstack-keystone | 07:58 | |
*** DuncanT has quit IRC | 07:58 | |
*** boris-42 has quit IRC | 07:58 | |
*** zhiyan has quit IRC | 07:58 | |
*** jed56 has quit IRC | 07:58 | |
*** raddaoui has quit IRC | 07:58 | |
*** sudorandom has quit IRC | 07:58 | |
*** woodster_ has quit IRC | 07:58 | |
*** zzzeek has quit IRC | 07:58 | |
*** hughsaunders has quit IRC | 07:58 | |
*** DuncanT_ has joined #openstack-keystone | 07:58 | |
*** yolanda has quit IRC | 07:58 | |
*** xek_ has quit IRC | 07:58 | |
*** dstanek has quit IRC | 07:58 | |
*** dtroyer has quit IRC | 07:58 | |
*** agrebennikov_ has quit IRC | 07:58 | |
*** ayoung has quit IRC | 07:58 | |
*** d0ugal has quit IRC | 07:58 | |
*** gus has quit IRC | 07:58 | |
*** lbragstad has quit IRC | 07:58 | |
*** sudorandom has joined #openstack-keystone | 07:59 | |
*** d0ugal has joined #openstack-keystone | 07:59 | |
*** jistr has joined #openstack-keystone | 07:59 | |
*** dstanek has joined #openstack-keystone | 07:59 | |
*** ChanServ sets mode: +v dstanek | 07:59 | |
*** raddaoui has joined #openstack-keystone | 07:59 | |
*** lbragstad has joined #openstack-keystone | 07:59 | |
*** ayoung has joined #openstack-keystone | 07:59 | |
*** ChanServ sets mode: +v ayoung | 07:59 | |
*** agrebennikov_ has joined #openstack-keystone | 08:00 | |
*** zhiyan_ is now known as zhiyan | 08:00 | |
*** dtroyer has joined #openstack-keystone | 08:00 | |
*** hughsaunders has joined #openstack-keystone | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:00 | |
*** chlong has joined #openstack-keystone | 08:01 | |
*** DuncanT_ is now known as DuncanT | 08:02 | |
*** gus has joined #openstack-keystone | 08:02 | |
*** yolanda has joined #openstack-keystone | 08:03 | |
*** woodster_ has joined #openstack-keystone | 08:05 | |
*** spzala has joined #openstack-keystone | 08:05 | |
*** boris-42 has joined #openstack-keystone | 08:10 | |
*** spzala has quit IRC | 08:11 | |
*** jed56 has joined #openstack-keystone | 08:11 | |
*** mvk has joined #openstack-keystone | 08:18 | |
*** markvoelker has joined #openstack-keystone | 08:22 | |
*** ChanServ changes topic to "Newton Summit Soon! | Midcycle Planning Thread: http://lists.openstack.org/pipermail/openstack-dev/2016-April/092298.html" | 08:24 | |
-openstackstatus- NOTICE: Logs filesystem has been successfully restored, please recheck your jobs | 08:24 | |
*** mdavidson has joined #openstack-keystone | 08:25 | |
*** henrynash has quit IRC | 08:26 | |
*** markvoelker has quit IRC | 08:27 | |
*** josecastroleon has quit IRC | 08:28 | |
-openstackstatus- NOTICE: Filesystem on docs-draft.openstack.org is broken, we are on the process of repairing it. Please stop checking jobs using this filesystem until further notice | 08:35 | |
*** dmk0202 has joined #openstack-keystone | 08:35 | |
*** e0ne has joined #openstack-keystone | 08:52 | |
*** harbor has joined #openstack-keystone | 08:57 | |
*** josecastroleon has joined #openstack-keystone | 09:00 | |
*** sileht has quit IRC | 09:01 | |
*** sileht has joined #openstack-keystone | 09:02 | |
*** gangaec has joined #openstack-keystone | 09:03 | |
*** spzala has joined #openstack-keystone | 09:07 | |
harbor | Hi, I am trying to get my head round mapping for federation and user groups - Currently i have ephemeral users sharing the Federation domain, and things are working pretty slick - however do you need to manually create a domain?->project->group->mapping for each user to provide isolation? With older versions of keystone I think i could have done this pretty easily by using the ldap assignment backend - but I'm | 09:08 |
harbor | not sure what the best way to implement this would be? if anyone has any pointers I be most appreciative :) | 09:08 |
*** fangxu has quit IRC | 09:10 | |
*** fangxu has joined #openstack-keystone | 09:10 | |
*** spzala has quit IRC | 09:12 | |
*** e0ne has quit IRC | 09:21 | |
-openstackstatus- NOTICE: Docs-draft filesystem has been restored. Please check your affected jobs again | 09:22 | |
*** belmoreira has joined #openstack-keystone | 09:23 | |
*** markvoelker has joined #openstack-keystone | 09:23 | |
*** markvoelker has quit IRC | 09:28 | |
*** josecastroleon has quit IRC | 09:47 | |
*** links has quit IRC | 09:48 | |
*** henrynash has joined #openstack-keystone | 09:52 | |
*** ChanServ sets mode: +v henrynash | 09:52 | |
*** fangxu has quit IRC | 09:53 | |
*** fangxu has joined #openstack-keystone | 09:54 | |
*** mhickey has joined #openstack-keystone | 09:58 | |
*** e0ne has joined #openstack-keystone | 10:02 | |
*** links has joined #openstack-keystone | 10:04 | |
*** links has quit IRC | 10:07 | |
*** spzala has joined #openstack-keystone | 10:07 | |
*** spzala has quit IRC | 10:13 | |
*** henrynash has quit IRC | 10:14 | |
*** links has joined #openstack-keystone | 10:14 | |
*** dave-mccowan has joined #openstack-keystone | 10:23 | |
*** markvoelker has joined #openstack-keystone | 10:24 | |
*** markvoelker has quit IRC | 10:28 | |
*** EinstCrazy has quit IRC | 10:28 | |
*** TxGVNN has quit IRC | 11:02 | |
*** spzala has joined #openstack-keystone | 11:09 | |
*** eandersson has joined #openstack-keystone | 11:13 | |
*** spzala has quit IRC | 11:13 | |
*** adu has joined #openstack-keystone | 11:21 | |
*** yolanda has quit IRC | 11:22 | |
*** links has quit IRC | 11:24 | |
*** markvoelker has joined #openstack-keystone | 11:24 | |
*** josecastroleon has joined #openstack-keystone | 11:27 | |
*** yolanda has joined #openstack-keystone | 11:27 | |
*** markvoelker has quit IRC | 11:29 | |
*** gordc has joined #openstack-keystone | 11:29 | |
*** henrynash has joined #openstack-keystone | 11:40 | |
*** ChanServ sets mode: +v henrynash | 11:40 | |
*** adu has quit IRC | 11:44 | |
*** naresh_ has joined #openstack-keystone | 11:58 | |
*** naresh_ is now known as Guest5666 | 11:58 | |
*** links has joined #openstack-keystone | 12:03 | |
*** spzala has joined #openstack-keystone | 12:10 | |
*** spzala has quit IRC | 12:15 | |
*** markvoelker has joined #openstack-keystone | 12:22 | |
*** vgridnev has joined #openstack-keystone | 12:28 | |
*** julim has joined #openstack-keystone | 12:36 | |
*** BlackDex has quit IRC | 12:38 | |
*** richm has joined #openstack-keystone | 12:39 | |
*** mou has joined #openstack-keystone | 12:41 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Remove test_invalid_policy_raises_error https://review.openstack.org/311804 | 12:46 |
*** EinstCrazy has joined #openstack-keystone | 12:51 | |
*** raildo-afk is now known as raildo | 12:58 | |
*** csoukup has joined #openstack-keystone | 13:00 | |
*** wanghua has quit IRC | 13:04 | |
*** edmondsw has joined #openstack-keystone | 13:04 | |
*** stingaci has joined #openstack-keystone | 13:07 | |
samueldmq | howdy keystoners | 13:07 |
*** vgridnev has quit IRC | 13:07 | |
*** spzala has joined #openstack-keystone | 13:11 | |
*** mylu has joined #openstack-keystone | 13:11 | |
*** EinstCrazy has quit IRC | 13:12 | |
*** mylu has quit IRC | 13:12 | |
raildo | :) | 13:13 |
*** stingaci has quit IRC | 13:14 | |
*** josecastroleon has quit IRC | 13:15 | |
*** spzala has quit IRC | 13:16 | |
*** fangxu_ has joined #openstack-keystone | 13:20 | |
*** fangxu has quit IRC | 13:20 | |
*** fangxu_ is now known as fangxu | 13:20 | |
hoonetorg | lbragstad asked me to provide a link in the official docs where token.provider=uuid and keystone-manage pki_setup is mentioned | 13:22 |
hoonetorg | tataa: | 13:22 |
hoonetorg | http://docs.openstack.org/juno/install-guide/install/yum/content/keystone-install.html | 13:22 |
hoonetorg | as lbragstad said: pki_setup is not required when token.provider=uuid | 13:23 |
dstanek | hoonetorg: did you get your stuff working? | 13:24 |
morgan | lbragstad, stevemar: re ML topic on fernet, should i dump the uuid payload thing? | 13:24 |
hoonetorg | i'm still in progress | 13:26 |
hoonetorg | first i needed to create a salt-formula to automatically deploy a HA-apache resource for keystone wsgi | 13:27 |
hoonetorg | that is done and works | 13:27 |
*** fangxu has quit IRC | 13:27 | |
*** spzala has joined #openstack-keystone | 13:28 | |
*** julim has quit IRC | 13:29 | |
*** fangxu has joined #openstack-keystone | 13:29 | |
hoonetorg | dstanek; currently I'm reworking https://github.com/openstack/salt-formula-keystone, especially https://github.com/openstack/salt-formula-keystone/blob/master/keystone/files/mitaka/keystone.conf.Debian | 13:30 |
hoonetorg | in a few hours there should be a reworked version on https://github.com/hoonetorg/salt-formula-keystone | 13:31 |
*** julim has joined #openstack-keystone | 13:32 | |
hoonetorg | dstanek: I will start up with token provider=uuid and persistence=sql and when that works (after some time) work in a high available compatible fernet key creation and rotation mechanism | 13:33 |
hoonetorg | dstanek: can I ask u a question | 13:34 |
hoonetorg | when I use memcache as cache backend (i have multiple, but they are not high available) and one of the memcache nodes goes down | 13:36 |
hoonetorg | will it cause troubles in keystone | 13:36 |
hoonetorg | ? | 13:36 |
dstanek | hoonetorg: no, things should just slow down | 13:37 |
dstanek | as long as you are not using it as a token store | 13:37 |
hoonetorg | ... because it's only a cache | 13:37 |
hoonetorg | it will re-gather the objects from where they came | 13:38 |
dstanek | hoonetorg: exactly, but we unfortunately provided a memcached back token backend - just don't use that | 13:38 |
hoonetorg | k | 13:38 |
openstackgerrit | Victor Stinner proposed openstack/keystone: Port test_v2 unit test to Python 3 https://review.openstack.org/312060 | 13:39 |
openstackgerrit | Victor Stinner proposed openstack/keystone: Port test_v3_auth unit test to Python 3 https://review.openstack.org/312061 | 13:39 |
eandersson | What was the token change that happened in Kilo release 3 that made it backwards incompatible with old tokens? | 13:39 |
dstanek | i can't remember off the top of my head, but i think we deleted it in newer releases | 13:39 |
eandersson | *fernet tokens | 13:40 |
*** sheel has joined #openstack-keystone | 13:42 | |
morgan | eandersson: removed padding | 13:42 |
eandersson | ah | 13:42 |
eandersson | Do you think it would be difficult for me to write a backwards compatible fix for that? So that we can upgrade without having to re-create all the tokens? | 13:42 |
eandersson | https://github.com/openstack/keystone/commit/bd94a41eefa4a1208f06886c598b75cab8339250 | 13:43 |
eandersson | Was that the one? | 13:43 |
*** TxGVNN has joined #openstack-keystone | 13:45 | |
eandersson | http://paste.openstack.org/show/oCQ27VXtbH38AuvU9RQQ/ | 13:45 |
openstackgerrit | Victor Stinner proposed openstack/keystone: Port test_v3_auth unit test to Python 3 https://review.openstack.org/312061 | 13:50 |
*** ametts has joined #openstack-keystone | 13:52 | |
dstanek | eandersson: i'm not sure it that was it or not, but i'm pretty sure over time we make a few backward incompatible changes. i just don't know the timeline. | 13:55 |
dstanek | eandersson: we had redundant data that was removed and other data was added. i'm not sure how much time was spent on backward compat in the early releases as we harded the feature | 13:56 |
*** sigmavirus24_awa is now known as sigmavirus24 | 13:56 | |
eandersson | Yea, I talked to someone earlier about this, and I think it was just an oversight in terms of backwards compat. | 13:59 |
eandersson | I understand from one major version to another, but just wasn't excepting it from one Kilo release to another =] | 14:00 |
*** tonytan4ever has joined #openstack-keystone | 14:01 | |
*** josecastroleon has joined #openstack-keystone | 14:02 | |
*** edtubill has joined #openstack-keystone | 14:04 | |
*** phalmos has joined #openstack-keystone | 14:05 | |
lbragstad | eandersson there was a padding change on the tokens but that was between l and m I think? | 14:06 |
eandersson | Hmm, so this is something else, as this happens from k to l, even k to k.3 I think. | 14:08 |
eandersson | It's the traceback I posted above. | 14:08 |
*** links has quit IRC | 14:10 | |
*** rderose has joined #openstack-keystone | 14:11 | |
lbragstad | eandersson oh - yeah that would be https://github.com/openstack/keystone/commit/bd94a41eefa4a1208f06886c598b75cab8339250 | 14:15 |
lbragstad | eandersson looks like that went back all the way to kilo https://review.openstack.org/#/q/Ia4a4f760d67d8bbc22759c48fc800aef016b84ed | 14:15 |
eandersson | yep, that is the one I was looking at | 14:16 |
lbragstad | stevemar do you know how we change docs from Juno? | 14:20 |
lbragstad | stevemar or if we can? | 14:20 |
*** stingaci has joined #openstack-keystone | 14:22 | |
raildo | lbragstad: ping, this patch https://review.openstack.org/#/c/311811/ is related to this bug https://bugs.launchpad.net/keystone/+bug/1576315, right? | 14:25 |
openstack | Launchpad bug 1576315 in OpenStack Identity (keystone) "Critically fail on startup if fernet_setup has not been run" [High,Confirmed] | 14:25 |
patchbot | raildo: patch 311811 - keystone - Make keystone exit when fernet keys don't exist | 14:25 |
lbragstad | raildo yep - I actually just saw that bug today | 14:27 |
lbragstad | raildo I can link that bug in the commit message | 14:27 |
raildo | lbragstad: ++ | 14:27 |
*** mylu has joined #openstack-keystone | 14:27 | |
lbragstad | raildo I have another patch up for getting v2 + fernet working | 14:27 |
lbragstad | raildo in case you want to put some eyes on it (if you have time0 | 14:27 |
lbragstad | )* | 14:27 |
*** BjoernT has joined #openstack-keystone | 14:27 | |
raildo | lbragstad: so many new patches related to fernet :P | 14:28 |
raildo | lbragstad: sure, I'll | 14:28 |
lbragstad | raildo https://review.openstack.org/#/c/311886/ | 14:28 |
patchbot | lbragstad: patch 311886 - keystone - Fix fernet audit ids for v2.0 | 14:28 |
raildo | lbragstad: thanks | 14:28 |
lbragstad | raildo I need to fix up the tests on py34 | 14:28 |
raildo | lbragstad: If you want, I can take a look on it | 14:28 |
lbragstad | raildo were you aware of the audit_ids issue at all? | 14:29 |
raildo | lbragstad: hum... not sure | 14:29 |
lbragstad | no worries - just curious, I know you found a few things in the process of working on ayoung's patch | 14:29 |
ayoung | lbragstad, raildo I think I have just about gotten the simplified revocating check working | 14:30 |
ayoung | one test failing. | 14:30 |
raildo | ayoung: awesome | 14:30 |
ayoung | I'd like to see if that then makes the race condition go-away or at lease make it easier to debug | 14:31 |
ayoung | raildo, https://review.openstack.org/#/c/311652/ WIP still | 14:32 |
patchbot | ayoung: patch 311652 - keystone - WIP replace revoke tree with linear search | 14:32 |
ayoung | net reduction of 40 lines, too | 14:32 |
ayoung | Um...so more than one test failure, though....suspect that the failure I am seeing in test_revoke is the cause of most of those... | 14:33 |
ayoung | No serialization handler registered for type 'RevokeEvent' | 14:34 |
*** iurygregory has joined #openstack-keystone | 14:35 | |
*** phalmos has quit IRC | 14:36 | |
*** richm has quit IRC | 14:37 | |
*** rderose has quit IRC | 14:37 | |
hoonetorg | for caching dogpile.cache.memcached is recommended when using keystone with apache/wsgi (not! eventlet) | 14:37 |
hoonetorg | isn't it??? | 14:37 |
hoonetorg | (mitaka, 3 memcached servers ) | 14:38 |
*** slberger has joined #openstack-keystone | 14:39 | |
openstackgerrit | henry-nash proposed openstack/keystone: Create V9 driver for identity backend https://review.openstack.org/305315 | 14:40 |
*** phalmos has joined #openstack-keystone | 14:43 | |
*** richm has joined #openstack-keystone | 14:44 | |
*** e0ne has quit IRC | 14:47 | |
*** josecastroleon has quit IRC | 14:47 | |
*** fawadkhaliq has joined #openstack-keystone | 14:51 | |
*** Guest5666 has quit IRC | 14:51 | |
*** doug-fish has joined #openstack-keystone | 14:52 | |
lbragstad | dstanek https://review.openstack.org/#/c/311886/ | 14:52 |
patchbot | lbragstad: patch 311886 - keystone - Fix fernet audit ids for v2.0 | 14:52 |
lbragstad | dstanek and https://review.openstack.org/#/c/311811/ | 14:53 |
patchbot | lbragstad: patch 311811 - keystone - Make keystone exit when fernet keys don't exist | 14:53 |
dstanek | lbragstad: that's a strange py34 error. does it fail like that locally? | 14:56 |
*** doug-fis_ has joined #openstack-keystone | 14:58 | |
*** doug-fi__ has joined #openstack-keystone | 15:00 | |
lbragstad | dstanek i need to test it with py34 locally | 15:00 |
*** doug-fish has quit IRC | 15:01 | |
*** doug-fis_ has quit IRC | 15:02 | |
*** jaugustine has joined #openstack-keystone | 15:02 | |
openstackgerrit | Navid Pustchi proposed openstack/python-keystoneclient: Fixing D208 PEP257 violation. https://review.openstack.org/311787 | 15:03 |
*** pauloewerton has joined #openstack-keystone | 15:04 | |
*** doug-fi__ has quit IRC | 15:05 | |
*** doug-fish has joined #openstack-keystone | 15:07 | |
*** mylu has quit IRC | 15:08 | |
*** BlackDex has joined #openstack-keystone | 15:08 | |
*** BlackDex has quit IRC | 15:10 | |
morgan | zzzeek: i am going to merge PR 49 for dogpile.cache, it's the same as PR 47, but now with my added test. | 15:11 |
morgan | zzzeek: (uses the PR47 commit/author) | 15:11 |
*** tesseract- has quit IRC | 15:12 | |
*** dan_nguyen has joined #openstack-keystone | 15:15 | |
*** links has joined #openstack-keystone | 15:19 | |
*** sdake has joined #openstack-keystone | 15:23 | |
*** pushkaru has joined #openstack-keystone | 15:25 | |
*** sdake_ has joined #openstack-keystone | 15:26 | |
*** belmoreira has quit IRC | 15:26 | |
*** tonytan_brb has joined #openstack-keystone | 15:27 | |
stevemar | morgan: the ops in the room thought the fernet+uuid modified token was not cool | 15:28 |
stevemar | lbragstad: you mean dev docs from juno? | 15:28 |
*** sdake has quit IRC | 15:28 | |
*** vgridnev has joined #openstack-keystone | 15:29 | |
morgan | stevemar: ookay | 15:29 |
morgan | stevemar: will just kill it | 15:30 |
morgan | stevemar: dead | 15:30 |
*** tonytan4ever has quit IRC | 15:31 | |
stevemar | morgan: ty sir | 15:31 |
*** julim has quit IRC | 15:32 | |
*** julim has joined #openstack-keystone | 15:33 | |
*** timcline has joined #openstack-keystone | 15:35 | |
dstanek | lbragstad: sounds good | 15:35 |
*** mou has quit IRC | 15:35 | |
hoonetorg | dstanek: the [memcache] section in keystone conf is only required if memcached is used for persistence (which you didn't recommend) | 15:38 |
hoonetorg | where all memcached settings for [cache] dogpile.cache.memcached are done in section [cache] (memcache_servers at minimum) , right? | 15:40 |
openstackgerrit | Matthew Edmonds proposed openstack/keystone: Honor ldap_filter on filtered user list https://review.openstack.org/312126 | 15:40 |
*** pgbridge has joined #openstack-keystone | 15:40 | |
*** mylu has joined #openstack-keystone | 15:41 | |
kfox1111 | is there a reason validate token needs an admin account? | 15:43 |
kfox1111 | you already have the token to validate against. | 15:43 |
kfox1111 | I'm looking at how to hook in kubernetes so that the users can authenticate with a keystone token, but it requres kubernetes to have an admin cred, which seems like more power then it might need? | 15:44 |
*** mylu has quit IRC | 15:45 | |
*** tonytan_brb has quit IRC | 15:49 | |
*** haplo37 has joined #openstack-keystone | 15:49 | |
*** stingaci has quit IRC | 15:50 | |
morgan | kfox1111: with V2, yes | 15:51 |
morgan | kfox1111: because v2 is very limited | 15:51 |
*** doug-fish has quit IRC | 15:52 | |
*** doug-fish has joined #openstack-keystone | 15:52 | |
morgan | kfox1111: but with v3 you should be able to grant that to a non-admin role | 15:52 |
*** tonytan4ever has joined #openstack-keystone | 15:52 | |
morgan | kfox1111: also keep in mind that v2 the token validate puts the token_id on the URI vs in the header | 15:52 |
*** tonytan4ever has quit IRC | 15:53 | |
*** doug-fish has quit IRC | 15:53 | |
*** stingaci has joined #openstack-keystone | 15:56 | |
*** TxGVNN has quit IRC | 16:00 | |
kfox1111 | nice. | 16:02 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements https://review.openstack.org/311548 | 16:02 |
*** fangxu has quit IRC | 16:02 | |
*** dmk0202 has quit IRC | 16:03 | |
kfox1111 | so, if I recommend we stick to v3, then add a new role type for "validateOnly" or something, and change the policy on that one service, we should be good making service accounts that use only that role? | 16:03 |
*** stingaci has quit IRC | 16:03 | |
*** phalmos has quit IRC | 16:04 | |
morgan | kfox1111: yeah, | 16:04 |
morgan | kfox1111: you'll need to update hte keystone policy.json too | 16:05 |
*** BjoernT has quit IRC | 16:05 | |
*** doug-fish has joined #openstack-keystone | 16:05 | |
*** doug-fish has quit IRC | 16:05 | |
morgan | kfox1111: make sure the new role can do the validate | 16:05 |
*** gordc has quit IRC | 16:05 | |
*** doug-fish has joined #openstack-keystone | 16:06 | |
*** phalmos has joined #openstack-keystone | 16:06 | |
*** doug-fish has quit IRC | 16:08 | |
kfox1111 | I wonder how many other openstack service accounts could remove their admin bit if they had this role. | 16:08 |
*** doug-fish has joined #openstack-keystone | 16:08 | |
kfox1111 | should I submit a patch to keystone to add the validate role to the policy file by default? I'd think many clouds would benifit. | 16:09 |
lbragstad | stevemar yeah - for juno | 16:10 |
*** mylu has joined #openstack-keystone | 16:11 | |
stevemar | lbragstad: i don't think you can: https://github.com/openstack/keystone/tree/juno-eol | 16:11 |
stevemar | you'd have to edit the docs there | 16:11 |
lbragstad | stevemar gotcha - | 16:11 |
lbragstad | just curious | 16:11 |
*** e0ne has joined #openstack-keystone | 16:11 | |
lbragstad | because we apparently say to use uuid and run pki_setup http://docs.openstack.org/juno/install-guide/install/yum/content/keystone-install.html | 16:11 |
lbragstad | which doesn't make sense to me? | 16:11 |
*** mylu has quit IRC | 16:13 | |
*** roxanaghe has joined #openstack-keystone | 16:15 | |
*** mylu has joined #openstack-keystone | 16:16 | |
stevemar | lbragstad: ah, thats the install guide | 16:16 |
lbragstad | stevemar hoonetorg was referencing it and it was causing some confusion | 16:17 |
*** mylu has quit IRC | 16:18 | |
*** roxanaghe has quit IRC | 16:19 | |
stevemar | lbragstad: i think you may have to edit it here: https://github.com/openstack/openstack-manuals/blob/juno-eol/doc/install-guide/section_keystone-install.xml | 16:19 |
stevemar | but it's also EOL | 16:19 |
lbragstad | stevemar gotcha | 16:21 |
lbragstad | dstanek for running py34 tests locally - have you ever gotten this? http://cdn.pasteraw.com/d4r3ojmxd2uoj0n37i9qigv49npqmt9 | 16:21 |
*** fawadkhaliq has quit IRC | 16:22 | |
dstanek | lbragstad: you don't have the python dev libs installed so it can't compile the C extensions | 16:22 |
lbragstad | dstanek ah - i'm missing python3-dev | 16:22 |
*** stingaci has joined #openstack-keystone | 16:25 | |
edmondsw | bknudson, if you could take a look at https://review.openstack.org/#/c/307335 I would appreciate it | 16:26 |
edmondsw | dims as well | 16:27 |
*** gyee has joined #openstack-keystone | 16:27 | |
*** ChanServ sets mode: +v gyee | 16:27 | |
lbragstad | dstanek look like i can recreate that py34 failure locally | 16:30 |
dims | edmondsw : lgtm | 16:30 |
edmondsw | tx | 16:30 |
*** doug-fish has quit IRC | 16:36 | |
edtubill | stevemar: I was going to start working on PCI-DSS mentioned in https://etherpad.openstack.org/p/newton-keystone-work-session -Who is ron again? | 16:37 |
*** doug-fish has joined #openstack-keystone | 16:37 | |
*** doug-fish has quit IRC | 16:37 | |
lbragstad | dstanek looks like that test is failing because the project.id is bytes instead of a string | 16:39 |
*** roxanaghe has joined #openstack-keystone | 16:43 | |
*** gordc has joined #openstack-keystone | 16:46 | |
dstanek | lbragstad: not fun | 16:49 |
*** navidp has joined #openstack-keystone | 16:50 | |
*** rbridgeman has joined #openstack-keystone | 16:52 | |
*** doug-fish has joined #openstack-keystone | 16:57 | |
*** rderose has joined #openstack-keystone | 16:58 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Fix fernet audit ids for v2.0 https://review.openstack.org/311886 | 16:59 |
lbragstad | dstanek fixed - https://review.openstack.org/#/c/311886/ | 17:00 |
patchbot | lbragstad: patch 311886 - keystone - Fix fernet audit ids for v2.0 | 17:00 |
lbragstad | dstanek that works for me locally and I added a comment. but i'll defer to you if you have a better way to do that | 17:00 |
*** doug-fish has quit IRC | 17:00 | |
*** fangxu has joined #openstack-keystone | 17:00 | |
*** tonytan4ever has joined #openstack-keystone | 17:01 | |
*** jistr has quit IRC | 17:04 | |
*** doug-fish has joined #openstack-keystone | 17:06 | |
*** ericksonsantos has joined #openstack-keystone | 17:06 | |
openstackgerrit | Gyorgy Szombathelyi proposed openstack/keystone: Allow 'domain' property for local.group https://review.openstack.org/310147 | 17:08 |
*** mvk has quit IRC | 17:08 | |
*** doug-fish has quit IRC | 17:12 | |
zzzeek | morgan: thanks | 17:16 |
zzzeek | morgan: not too much time to look closely this week / next as we are moving but will try to catch up | 17:16 |
*** doug-fish has joined #openstack-keystone | 17:16 | |
*** pushkaru has quit IRC | 17:17 | |
*** phalmos has quit IRC | 17:21 | |
*** tellesnobrega_af is now known as tellesnobrega | 17:21 | |
*** roxanaghe has quit IRC | 17:23 | |
*** roxanaghe has joined #openstack-keystone | 17:24 | |
stevemar | edtubill: ron is rderose :) | 17:25 |
stevemar | edtubill: glad you can start working on it, let me or rderose know if you need help :) | 17:26 |
edtubill | stevemar: thanks, I'm gonna look at dstanek's old patches and take a look around the mysql drivers in keystone. | 17:26 |
rderose | edtubill: is this for the PCI stuff? | 17:27 |
edtubill | rderose: yup | 17:27 |
rderose | edtubill: cool | 17:27 |
stevemar | edtubill: rderose feel free to start an etherpad that outlines some of the work | 17:29 |
rderose | stevemar edtubill: will do. I'm out today, dealing with the after-summit-sickness. | 17:31 |
rderose | I blame stevemar | 17:31 |
*** e0ne has quit IRC | 17:31 | |
rderose | edtubill: go ahead and start; I'll catch up in the next day or 2 | 17:31 |
edtubill | rderose: lol, sure | 17:32 |
*** sheel has quit IRC | 17:34 | |
*** serverascode has quit IRC | 17:34 | |
*** woodster_ has quit IRC | 17:35 | |
*** zhiyan has quit IRC | 17:35 | |
*** zhiyan has joined #openstack-keystone | 17:37 | |
*** sheel has joined #openstack-keystone | 17:37 | |
*** woodster_ has joined #openstack-keystone | 17:37 | |
*** serverascode has joined #openstack-keystone | 17:38 | |
bknudson | edmondsw: the commit message says it adds babel but it doesn't. | 17:39 |
*** tonytan4ever has quit IRC | 17:39 | |
*** rbridgeman has quit IRC | 17:41 | |
ayoung | morgan, need help serializing the revocation events | 17:42 |
*** sileht has quit IRC | 17:42 | |
ayoung | the RevokeTree (which I will rename later) gets serialized, and needs to serialize all of the events it has inside. And these each need to be serialized to bytes. | 17:42 |
ayoung | I can user dictionaries as the basis, as the Events are created by dicts with a kwargs param and cna createa dict with obj.to_dict() call | 17:44 |
*** pnavarro has quit IRC | 17:44 | |
ayoung | I can't just put them in a python list, as that is not "bytes" | 17:44 |
*** gagehugo has joined #openstack-keystone | 17:45 | |
*** lhcheng has joined #openstack-keystone | 17:46 | |
*** ChanServ sets mode: +v lhcheng | 17:46 | |
*** sileht has joined #openstack-keystone | 17:48 | |
stevemar | rderose: i took out you, topol, jamielennox's wife, and i think knikolla | 17:49 |
stevemar | bknudson: it didn't need babel | 17:51 |
raildo | will we have meeting today? | 17:51 |
lbragstad | anyone hitting this locally when running unittests (against py27 and py34)? http://cdn.pasteraw.com/j69h9lhyqsbikglma7fgx7hkaiqja1j | 17:51 |
stevemar | bknudson: the same change is also on liberty and mitaka | 17:51 |
edmondsw | bknudson, yeah, stevemar removed that and I guess forgot to update the commit | 17:52 |
stevemar | edmondsw: yep | 17:52 |
morgan | ayoung: this is why i did a bit of magic in the msgpack thing | 17:53 |
morgan | ayoung: in all seriousness don't overload list | 17:53 |
lbragstad | looks like it was added here - https://review.openstack.org/#/c/300131/ | 17:53 |
patchbot | lbragstad: patch 300131 - keystone - Add logging to cli if keystone.conf is not found (MERGED) | 17:53 |
morgan | ayoung: make it something else | 17:53 |
ayoung | morgan, I was not going to overload list | 17:53 |
ayoung | it needs to be bytes, so msgpack makes some sense | 17:53 |
morgan | ayoung: wait are you serializing w/ msgpack still or with json? | 17:53 |
morgan | ayoung: and why does it need to be bytes? | 17:54 |
ayoung | morgan, that was the error message I got | 17:54 |
morgan | oh | 17:54 |
ayoung | I tried returning a list of the msgpacked values (yeah dumb but whatev) | 17:54 |
stevemar | theres nothing on the agenda for the meeting | 17:55 |
morgan | stevemar: so lets skip! :) | 17:55 |
ayoung | is there a better way to serialize? The Events should be converted to-from dicts pretty easy | 17:55 |
stevemar | anyone have anything they want to discuss? | 17:55 |
stevemar | morgan: :) | 17:55 |
stevemar | i think the midcycle is the only thing i wanted to talk about | 17:55 |
morgan | i told the folks i needed an answer by tomorrow. | 17:55 |
morgan | on space | 17:55 |
morgan | ... i haven't heard anything | 17:55 |
stevemar | i need to get deadlines in order | 17:55 |
stevemar | so i can't announce that yet | 17:56 |
lbragstad | stevemar I want to get https://review.openstack.org/#/c/311886/3 in to fix the ksc functional tests | 17:56 |
patchbot | lbragstad: patch 311886 - keystone - Fix fernet audit ids for v2.0 | 17:56 |
stevemar | lbragstad: yeah, that will go in even if we don't have a meeting | 17:56 |
topol | Im requesting that hazmat suits be provided to all attendees... #typhoidsteve | 17:56 |
stevemar | we can skip this meeting | 17:56 |
stevemar | no agenda topics, just immediate stuff that needs eyes (lances patch) and meds (topol) | 17:57 |
morgan | ayoung: so, if you aren't building a strang tree object you can probably move to json | 17:57 |
morgan | ayoung: and it'll serialize better | 17:58 |
morgan | / easier | 17:58 |
ayoung | ok serialize to-from JSON. And then JSON to bytes? | 17:58 |
stevemar | meeting is canceled | 17:59 |
*** pushkaru has joined #openstack-keystone | 17:59 | |
*** rbridgeman has joined #openstack-keystone | 18:00 | |
morgan | ayoung: don't use msgpack | 18:00 |
morgan | ayoung: change the request_local thing to just use json | 18:01 |
ayoung | morgan, looking... | 18:01 |
morgan | the only reason we used msgpack was because the revoke tree was a very complex object | 18:01 |
samueldmq | stevemar: ++ | 18:01 |
* samueldmq nods | 18:01 | |
jamielennox | keystone meeting? | 18:03 |
rderose | ++ | 18:03 |
morgan | jamielennox: cancelled | 18:03 |
morgan | jamielennox: no agenda | 18:03 |
rderose | cool | 18:03 |
stevemar | jamielennox: rderose canned it | 18:03 |
henrynash | we always have an agenda….just not one for the meeting | 18:03 |
*** lhcheng has quit IRC | 18:04 | |
dolphm | i'm sure we could come up with an agenda real quick | 18:04 |
*** markvoelker has quit IRC | 18:04 | |
dstanek | yay! | 18:04 |
dolphm | my summit notes, if anyone is interested http://dolphm.com/openstack-newton-design-summit-outcomes-for-keystone/ | 18:04 |
jamielennox | alright back to bed then | 18:04 |
stevemar | dolphm: nice! | 18:05 |
jamielennox | oh - dolphm, stevemar | 18:05 |
jamielennox | i watched the keystone panel | 18:05 |
dolphm | jamielennox o/ | 18:05 |
stevemar | dolphm: i need to do one too | 18:05 |
stevemar | jamielennox: uh oh | 18:05 |
jamielennox | my sub-users/credential thing nailed that case | 18:05 |
*** markvoelker has joined #openstack-keystone | 18:05 | |
dolphm | jamielennox: what was the question? | 18:05 |
stevemar | jamielennox: which case? | 18:05 |
*** BlackDex has joined #openstack-keystone | 18:05 | |
dstanek | i was surpised that there were no hard questions for the panel. almost like you guys set up a bunch of softballs :-P | 18:05 |
*** frontrunner has quit IRC | 18:05 | |
dolphm | jamielennox: instance users? | 18:06 |
jamielennox | umm, a way to set up a user with less roles that you could give off to other services | 18:06 |
jamielennox | but then expand that for like 5 minutes | 18:06 |
dolphm | dstanek: the questions brad has were relatively soft, but catered to different panel members. a couple of them came up as organic questions anyway | 18:06 |
jamielennox | also - AFAICT you can add/remove/modify shibboleth IDPs without restarting keystone | 18:07 |
dolphm | jamielennox: and it's not oauth delegation which we already support? :P | 18:07 |
jamielennox | shibd runs as a seperate process and configuration to apache which can be reloaded independantly | 18:07 |
*** markvoelker_ has joined #openstack-keystone | 18:07 | |
dolphm | jamielennox: .. you can swap certs and everything? | 18:07 |
*** markvoelker has quit IRC | 18:08 | |
jamielennox | dolphm: almost :) i sent a few people from magnum or something looking at oauth because they were trying to replicate heat's setup | 18:08 |
jamielennox | haven't looked again myself | 18:08 |
stevemar | dolphm: your blog overlaps so much with what i want to write -_- | 18:08 |
dolphm | jamielennox: cool, i'm hoping that API gets some use this cycle. it seems to solve a bunch of problems that people are looking for | 18:08 |
dstanek | jamielennox: dolphm: i can give it a try and see, but from what i'm told you can't | 18:08 |
dolphm | stevemar: that just means we talked a lot :P | 18:09 |
dolphm | stevemar: i also want to watch & recap a few of the main conference sessions that i missed, but i'll do that over the next couple weeks | 18:09 |
stevemar | copy/paste and remove osic and fernet talk | 18:09 |
stevemar | dolphm: yeah, i wanted to write up a "my top summit presentations" | 18:09 |
dolphm | dstanek: i've never tried it myself, but that's how marek did it | 18:09 |
jamielennox | dstanek: it's been a while since i tried, but i'm sure i was able to add a provider then restart only shibd | 18:09 |
dolphm | jamielennox: so, at least federation stops working for a moment? | 18:10 |
stevemar | dolphm: maybe i'll recap the work sessions and fishbowls instead, and outline goals for newton | 18:10 |
dolphm | jamielennox: if so, that's not terrible, but it still doesn't allow domain admins to manage their own federations | 18:10 |
dolphm | stevemar: i'm sure you can disagree or add to some of the things i wrote about as well | 18:11 |
openstackgerrit | Navid Pustchi proposed openstack/python-keystoneclient: Fixing D204, D205, and D207 PEP257 violation. https://review.openstack.org/312192 | 18:11 |
jamielennox | dolphm: so there is an automatic reload if you touch the config file, but there are some things excluded from that and so depending on how apache buffers you'd probably get a temporary federation outzage | 18:12 |
jamielennox | but yea - it doesn't support the domain admin case | 18:12 |
dolphm | jamielennox: that was the original goal, but we catered to operators first and foremost since our domain admin story was weak anyway. it's much more well defined today! | 18:12 |
dolphm | jamielennox: that'd be good to document! i swear we have the opposite documented somewhere -- i.e. bounce everything if you add an IdP to shib, etc | 18:13 |
jamielennox | dolphm: it's been a while since i set it up, but i assume i'll have to again soon and will make sure to doc it | 18:14 |
*** lhcheng has joined #openstack-keystone | 18:15 | |
*** ChanServ sets mode: +v lhcheng | 18:15 | |
*** tonytan4ever has joined #openstack-keystone | 18:19 | |
*** lhcheng has quit IRC | 18:23 | |
stevemar | dolphm: yeah, for sure :) | 18:24 |
*** vgridnev has quit IRC | 18:25 | |
*** edmondsw has quit IRC | 18:32 | |
ayoung | morgan, think we were double caching events | 18:37 |
morgan | ayoung: uhm. we *are* double caching a lot of things. | 18:38 |
ayoung | morgan, going to kill one layer of cacher here | 18:38 |
morgan | do not. | 18:38 |
morgan | wait which layer? | 18:38 |
ayoung | morgan, the sql queries from the backend are already cached | 18:38 |
ayoung | so no need to cache the tree, as that is now just a list | 18:39 |
morgan | ayoung: if you're youching the request_local layer thing, don't | 18:39 |
ayoung | morgan, Oh yes I will! And you can't stop me.... | 18:39 |
ayoung | heh | 18:39 |
morgan | ayoung: you have a spare @memoize somewhere? | 18:39 |
ayoung | morgan, nah, I just mean that I can drop caching the tree, and hold on to the events from the sql layer | 18:39 |
ayoung | I was getting circular references. | 18:39 |
morgan | ayoung: fix the circualr references | 18:40 |
morgan | cache the tree, cache higher up in the business logic where possible. | 18:40 |
ayoung | morgan, nah, no reason to | 18:40 |
ayoung | the logic is much simpler now | 18:40 |
ayoung | morgan, let me get the tests to pass, and you can take a look | 18:40 |
ayoung | and I think I am there now.... | 18:41 |
*** fangxu has quit IRC | 18:41 | |
*** d34dh0r53 is now known as m1r4nt15_b0y | 18:42 | |
ayoung | morgan, the new logic is an interation through the events. The events are an ordered list returned by sql, and cached by the dogtag layer. The tree is no longer built. I think I can even remove the RevokeTree as an abstraction | 18:42 |
morgan | ayoung: ok cool then cache the list_events() call | 18:43 |
morgan | and if revoketree goes away | 18:43 |
morgan | request_locla cache can move to .json | 18:44 |
morgan | which is way faster than msgpack | 18:44 |
ayoung | yeah, this should be good | 18:44 |
*** phalmos has joined #openstack-keystone | 18:46 | |
morgan | ayoung: and using json to serialize will mean it also prevents the complex data structure like the revoke tree again | 18:46 |
ayoung | morgan, I wish I had done this before tackling the "remove spurious revocation events" patch. Its going to be so much simpler | 18:48 |
ayoung | OK, tests pass now | 18:49 |
morgan | ayoung: i actually tried to say you should have done it this order then ;) | 18:49 |
morgan | ayoung: glad it's working out though | 18:49 |
ayoung | morgan, yeah, I didn't realize how easy it would be to pull the code out of the revoke_test, thought I was going to be reimplementing it | 18:49 |
stevemar | how are folks feeling about newton-1 milestone as the spec freeze deadline? | 18:49 |
ayoung | stevemar, what is that June 1? | 18:50 |
morgan | stevemar: i vote the week after | 18:50 |
morgan | stevemar: tbh | 18:50 |
ayoung | http://releases.openstack.org/newton/schedule.html | 18:50 |
*** roxanaghe has quit IRC | 18:50 | |
morgan | stevemar: since our midcycle will be post M2 this time around | 18:50 |
stevemar | true | 18:51 |
ayoung | what are we saying is the norm now? Spec freeze M1, Feature Freeze M2? | 18:51 |
stevemar | ayoung: feature *proposal* freeze is M2 | 18:51 |
stevemar | meaning - get your code up in a patch that is passing jenkins and not WIP! | 18:52 |
ayoung | What is the diff between feature *proposals* and specs? | 18:52 |
ayoung | Ah | 18:52 |
ayoung | OK | 18:52 |
*** roxanaghe has joined #openstack-keystone | 18:52 | |
ayoung | So...lets stick with that, and then be forgiving on spec freeze extensions this time around? | 18:52 |
ayoung | Like, M1 is spec proposal freeze, and it has to be close. | 18:53 |
stevemar | i don't think we have too many specs proposed this time around | 18:54 |
ayoung | So, spec proposal freeze at Newton 1, feature proposal at Newton 2. If a spec is not approaved by Newton 2, the feature gets rejected. | 18:56 |
openstackgerrit | Navid Pustchi proposed openstack/python-keystoneclient: Fixing D202 and D203 PEP257 violation. https://review.openstack.org/312207 | 18:56 |
stevemar | ayoung: i can dig it | 18:56 |
*** yolanda has quit IRC | 18:56 | |
stevemar | i'll whip up an email and blast it to ML | 18:56 |
ayoung | stevemar, I think add in there a guideline to be actiovely reviewing specs. DOn't come in at the last second and -2 something that has been under active development, and the spec is just going back for spelling editing | 18:57 |
*** fangxu has joined #openstack-keystone | 18:57 | |
*** links has quit IRC | 18:58 | |
*** doug-fis_ has joined #openstack-keystone | 18:58 | |
gyee | stevemar, if we are not doing anything with MFA/TOTP, I'll abandon my client side patches, please let me know | 18:59 |
gyee | ayoung, where I can find more doc on certmonger plugin? | 18:59 |
stevemar | gyee: the TOTP auth plugin should still land | 18:59 |
ayoung | gyee, ask me that again in #freeipa | 18:59 |
gyee | stevemar, k, I'll make sure they are up-to-date | 18:59 |
*** clenimar has joined #openstack-keystone | 18:59 | |
ayoung | gyee, ah one sec | 18:59 |
*** doug-fi__ has joined #openstack-keystone | 19:00 | |
gyee | ayoung, http://www.freeipa.org/page/Certmonger, that the latest? | 19:00 |
knikolla | where’s the url which details the dates for the various milestones? | 19:00 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Make keystone exit when fernet keys don't exist https://review.openstack.org/311811 | 19:00 |
ayoung | gyee, there are more docs...hold on | 19:00 |
stevemar | knikolla: http://releases.openstack.org/newton/schedule.html | 19:01 |
dstanek | gyee: is there docs on how to do the tokenless auth? | 19:01 |
stevemar | ayoung: i'm going to move the spec deadline a bit earlier, just so we are not swamped that one week | 19:01 |
ayoung | WFM | 19:02 |
gyee | dstanek, yes, https://github.com/openstack/keystone/blob/master/doc/source/configure_tokenless_x509.rst | 19:02 |
openstackgerrit | Navid Pustchi proposed openstack/python-keystoneclient: Fixing D200 PEP257 violation. https://review.openstack.org/312208 | 19:02 |
*** doug-fish has quit IRC | 19:02 | |
gyee | dstanek, I have a script to generate self-signed PKI, let me know if you want it | 19:03 |
dstanek | gyee: sure, thanks! | 19:03 |
knikolla | stevemar: thanks! | 19:03 |
gyee | ayoung, looking at Anchor doc, I think we may have a bootstrapping problem | 19:03 |
ayoung | gyee, https://git.fedorahosted.org/cgit/certmonger.git/tree/doc/helpers.txt | 19:03 |
ayoung | gyee, also: | 19:03 |
*** doug-fis_ has quit IRC | 19:03 | |
gyee | Anchor can auth via keystone | 19:03 |
dstanek | any few minutes i can save here and there helps. | 19:04 |
gyee | we can start with static accounts | 19:04 |
ayoung | there is a python exampole in the IPA directory | 19:04 |
*** julim has quit IRC | 19:04 | |
*** doug-fi__ has quit IRC | 19:04 | |
gyee | ayoung, k, let me setup Anchor and certmonger locally to see it works | 19:04 |
gyee | if not, I'll give Dogtag a go | 19:04 |
ayoung | gyee, let me find alee, as he wrote a helper not long ago | 19:05 |
gyee | ayoung, helper can be in Python right? | 19:05 |
ayoung | gyee, yes | 19:06 |
ayoung | gyee, I started to write one that was srtaight bash | 19:06 |
ayoung | let me see... | 19:06 |
gyee | cool! | 19:06 |
*** nalind has joined #openstack-keystone | 19:06 | |
nalind | ayoung: hey, you rang? | 19:06 |
*** alee has joined #openstack-keystone | 19:06 | |
ayoung | gyee, nalind was one of the certmonger devs for a while | 19:06 |
ayoung | he knows it bettern I do | 19:06 |
gyee | hi nalind! | 19:06 |
nalind | hi gyee! what's up? | 19:07 |
gyee | I am trying to do some homework on certmonger and Anchor | 19:07 |
alee | gyee, fun stuff ! | 19:07 |
gyee | Anchor is all rest API | 19:07 |
alee | gyee, you trying to write an anchor certmonger plugin? | 19:07 |
gyee | alee, yes | 19:07 |
alee | cool beans | 19:07 |
*** julim has joined #openstack-keystone | 19:07 | |
gyee | should be straight forward once I figure out the administrative stuff | 19:08 |
gyee | s/administrative/boilerplate/ | 19:08 |
ayoung | there was an ipa helper in python | 19:08 |
ayoung | I'm trying to find it now nalind | 19:08 |
alee | gyee, nalind is your guy. although I'll be super curious to see what you come up with. | 19:09 |
gyee | k, will ping you guys if I run into anything, off to hacking land now | 19:09 |
nalind | ayoung: i probably pointed you at https://git.fedorahosted.org/cgit/freeipa.git/tree/install/certmonger/dogtag-ipa-ca-renew-agent-submit, right? | 19:09 |
ayoung | nalind, that was it | 19:10 |
ayoung | gyee, I would start with ^^ | 19:10 |
ayoung | that does the calls got dogtag, so you want to do essentially the same thing. | 19:10 |
ayoung | I should use that for my "chained selfsigned" helper, too | 19:11 |
ayoung | gyee, BTW, you can use the session approach, to. | 19:11 |
gyee | is ipautil using request underneath? | 19:12 |
gyee | maybe I can just do a replacement there | 19:13 |
ayoung | gyee, nah | 19:13 |
ayoung | gyee, its JSON RPC I think | 19:13 |
ayoung | used to be XML RPC | 19:13 |
ayoung | But I think its all JSON RPC now | 19:13 |
ayoung | gyee, just get the original request part working: | 19:14 |
ayoung | request_cert(): | 19:14 |
gyee | yeah, should be OK | 19:14 |
*** navidp has quit IRC | 19:14 | |
ayoung | you an skip all the ldap stuff | 19:14 |
ayoung | I should make a toy helper in python that does the selfsigned | 19:15 |
gyee | right | 19:15 |
gyee | I need to go offline for a few. will update you guys tomorrow | 19:16 |
*** gyee has quit IRC | 19:17 | |
*** csoukup has quit IRC | 19:17 | |
ayoung | nalind, does the certmonger helper have to store the cert,. or is that just a vestige of what Jan was using that code to do, to store the cert in LDAP? | 19:23 |
ayoung | I thought the NSS/OpenSSL storage code was part of certmonger, not the helper | 19:24 |
nalind | ayoung: the daemon normally handles storing keys and certs, and only wants the helper to help it get signing requests to the CA and reading back the results | 19:25 |
nalind | the one in ipa is taking advantage of that to, on replicas, instead retrieve from the directory server a copy of a cert that might have been issued to the primary, and uploaded to the directory server from there | 19:26 |
nalind | wow, that sentence could have been clearer | 19:26 |
ayoung | nalind, We've been pushing people to write certmonger helpers, but C is not the language of choice for most people. I think I Need to write a clear, simple example in Python | 19:27 |
nalind | yeah, i wouldn't expect people to enjoy writing them in C | 19:28 |
*** roxanaghe has quit IRC | 19:28 | |
*** amrith has joined #openstack-keystone | 19:29 | |
*** ericksonsantos has quit IRC | 19:39 | |
*** BjoernT has joined #openstack-keystone | 19:39 | |
ayoung | nalind, I tried to do one in shell: | 19:40 |
ayoung | https://adam.younglogic.com/2016/04/remote-certmongers-local/ | 19:40 |
*** trey has quit IRC | 19:42 | |
*** gordc has quit IRC | 19:42 | |
*** jrist has quit IRC | 19:42 | |
*** david-lyle has quit IRC | 19:42 | |
*** rvba has quit IRC | 19:42 | |
*** kfox1111 has quit IRC | 19:42 | |
*** fangxu has quit IRC | 19:42 | |
*** henrynash has quit IRC | 19:42 | |
*** eandersson has quit IRC | 19:42 | |
*** d0ugal has quit IRC | 19:42 | |
*** xek__ has quit IRC | 19:42 | |
*** nkinder has quit IRC | 19:42 | |
*** fungi has quit IRC | 19:42 | |
*** crinkle has quit IRC | 19:42 | |
*** rdo has quit IRC | 19:42 | |
*** kevinbenton has quit IRC | 19:42 | |
*** hugokuo has quit IRC | 19:42 | |
*** jgriffith has quit IRC | 19:42 | |
*** dobson has quit IRC | 19:42 | |
*** andreaf has quit IRC | 19:42 | |
nalind | ayoung: communicating more of the environment variables that the daemon sets for your helper across to the remote invocation would help | 19:43 |
ayoung | nalind, yeah...ssh makes that difficult to do without writing a wrapper on the remote side | 19:45 |
nalind | ayoung: agreed | 19:45 |
ayoung | was trying to avoid that, or setting up the | 19:45 |
ayoung | ssh config to accept all from the remote side | 19:45 |
ayoung | I might start with a selfsigned one in python | 19:46 |
*** ericksonsantos has joined #openstack-keystone | 19:47 | |
*** yolanda has joined #openstack-keystone | 19:47 | |
*** dmk0202 has joined #openstack-keystone | 19:51 | |
*** david-lyle has joined #openstack-keystone | 19:51 | |
*** fangxu has joined #openstack-keystone | 19:51 | |
*** henrynash has joined #openstack-keystone | 19:51 | |
*** eandersson has joined #openstack-keystone | 19:51 | |
*** d0ugal has joined #openstack-keystone | 19:51 | |
*** xek__ has joined #openstack-keystone | 19:51 | |
*** nkinder has joined #openstack-keystone | 19:51 | |
*** fungi has joined #openstack-keystone | 19:51 | |
*** crinkle has joined #openstack-keystone | 19:51 | |
*** rdo has joined #openstack-keystone | 19:51 | |
*** hugokuo has joined #openstack-keystone | 19:51 | |
*** kevinbenton has joined #openstack-keystone | 19:51 | |
*** jgriffith has joined #openstack-keystone | 19:51 | |
*** dobson has joined #openstack-keystone | 19:51 | |
*** andreaf has joined #openstack-keystone | 19:51 | |
*** wilhelm.freenode.net sets mode: +v henrynash | 19:51 | |
*** fedruantine has quit IRC | 19:51 | |
*** gordc has joined #openstack-keystone | 19:51 | |
*** jrist has joined #openstack-keystone | 19:51 | |
*** rvba has joined #openstack-keystone | 19:51 | |
*** kfox1111 has joined #openstack-keystone | 19:51 | |
*** trey has joined #openstack-keystone | 19:56 | |
*** yolanda has quit IRC | 19:56 | |
*** fangxu has quit IRC | 19:57 | |
bknudson | I wonder if this will work : https://review.openstack.org/#/c/312230/ (keystone doesn't listen on :5000 and :35357 anymore) | 20:07 |
patchbot | bknudson: patch 312230 - openstack-dev/devstack - Keystone httpd stop listening on ports | 20:07 |
*** csoukup has joined #openstack-keystone | 20:07 | |
*** doug-fish has joined #openstack-keystone | 20:08 | |
*** doug-fish has quit IRC | 20:08 | |
bigjools | We don't seem to have foreign key constraints turned on in unit tests, is this deliberate? | 20:10 |
*** amrith is now known as _amrith_ | 20:12 | |
bknudson | bigjools: I don't think sqlite suports fk constraints | 20:13 |
bigjools | sqllite 3 does | 20:13 |
*** mhickey has quit IRC | 20:13 | |
bigjools | either way it seems odd we'd rely on different DB behaviour in unit tests | 20:14 |
bknudson | we're not going to start up mysql or postgresql for unit tests. | 20:14 |
bknudson | the unit tests would take hours to run | 20:14 |
bigjools | do you want them to be right, or quick? :) | 20:15 |
bknudson | it's a balance | 20:15 |
stevemar | bknudson: oh man, i don't see https://review.openstack.org/#/c/312230/ passing at all :) | 20:16 |
patchbot | stevemar: patch 312230 - openstack-dev/devstack - Keystone httpd stop listening on ports | 20:16 |
bknudson | stevemar: sure, but what if it does? | 20:16 |
bigjools | so are people not all using sqllite3? FK constraints could be turned on there. | 20:16 |
bknudson | bigjools: we're probably all using sqlite3 now. | 20:17 |
bigjools | ok - would you take a patch to turn it on then? | 20:17 |
stevemar | bknudson: it'll be a | 20:17 |
bknudson | bigjools: yes, if you propose a patch to turn it on and it passes I don't think anyone will complain | 20:17 |
bigjools | bknudson: cool, thank you. | 20:17 |
stevemar | bknudson: it'll be interesting, it's a yuuuge change, lots of auth_url's will need to be updated | 20:17 |
bknudson | stevemar: are you trying to put a picture in there? that only works in slack. | 20:18 |
stevemar | bknudson: nah, accidentally hit enter | 20:18 |
knikolla | is that what we want in the future? keystone listening on :80 only? | 20:19 |
*** chrisplo has joined #openstack-keystone | 20:19 | |
stevemar | knikolla: yep, with proper subroutes | 20:20 |
stevemar | so... :80/identity :80/compute | 20:20 |
stevemar | etc | 20:20 |
knikolla | stevemar: that’s totally not going to be as hard as getting anyone on v3 | 20:20 |
knikolla | everyone* | 20:21 |
bknudson | I think s3token is going to be a problem, swift is configuring it with port / host | 20:24 |
bknudson | no path | 20:24 |
dstanek | bknudson: bigjools: i have a patch to turn on FK constraints for sqlite, but it only had a luke warm reception | 20:25 |
bknudson | we're luke-warm in general | 20:26 |
dstanek | if it's still interesting i can rebase and try to get it through again | 20:26 |
dstanek | bknudson: more like semi-cold | 20:26 |
bknudson | ice cold | 20:27 |
-openstackstatus- NOTICE: restarting apache on review.openstack.org to pick up security patches. Gerrit web ui may disappear for a short time. | 20:27 | |
bigjools | dstanek: it seems like a major oversight to me | 20:31 |
*** e0ne has joined #openstack-keystone | 20:34 | |
*** roxanaghe has joined #openstack-keystone | 20:34 | |
dstanek | bigjools: depends on your view. i actually don't like that we use a DB in unit tests at all, but that ship has sailed | 20:34 |
bigjools | how would you avoid it? besides mocking everything, which is pretty nasty | 20:35 |
dstanek | a different design and some strategic mocking would work wonders | 20:36 |
dstanek | i with i had the time to start proposing more test/design patches | 20:37 |
*** timcline_ has joined #openstack-keystone | 20:41 | |
*** timcline has quit IRC | 20:41 | |
*** doug-fish has joined #openstack-keystone | 20:42 | |
*** bigjools has quit IRC | 20:43 | |
openstackgerrit | Navid Pustchi proposed openstack/keystone: Fixing D105, D203, and D205 PEP257 https://review.openstack.org/309491 | 20:44 |
*** navidp has joined #openstack-keystone | 20:44 | |
*** bigjools has joined #openstack-keystone | 20:45 | |
navidp | simple patch to review !!! https://review.openstack.org/#/c/309491/' | 20:45 |
patchbot | navidp: patch 309491 - keystone - Fixing D105, D203, and D205 PEP257 | 20:45 |
*** doug-fish has quit IRC | 20:46 | |
*** gyee has joined #openstack-keystone | 20:47 | |
*** ChanServ sets mode: +v gyee | 20:47 | |
*** vgridnev has joined #openstack-keystone | 20:50 | |
*** jaugustine has quit IRC | 20:53 | |
*** doug-fish has joined #openstack-keystone | 21:07 | |
*** doug-fis_ has joined #openstack-keystone | 21:08 | |
*** mylu has joined #openstack-keystone | 21:09 | |
*** doug-fi__ has joined #openstack-keystone | 21:09 | |
openstackgerrit | ayoung proposed openstack/keystone: Replace revoke tree with linear search https://review.openstack.org/311652 | 21:09 |
*** mvk has joined #openstack-keystone | 21:09 | |
*** mylu has quit IRC | 21:10 | |
*** doug-fish has quit IRC | 21:11 | |
openstackgerrit | Clenimar Filemon proposed openstack/keystoneauth: Add is_domain to keystoneauth token https://review.openstack.org/282377 | 21:11 |
*** doug-fis_ has quit IRC | 21:13 | |
*** e0ne has quit IRC | 21:13 | |
*** mylu has joined #openstack-keystone | 21:15 | |
*** raildo is now known as raildo-afk | 21:15 | |
*** vgridnev has quit IRC | 21:17 | |
*** fangxu has joined #openstack-keystone | 21:19 | |
*** gagehugo has quit IRC | 21:20 | |
*** tonytan4ever has quit IRC | 21:21 | |
*** haplo37 has quit IRC | 21:21 | |
*** roxanaghe has quit IRC | 21:23 | |
*** spzala has quit IRC | 21:24 | |
*** pauloewerton has quit IRC | 21:28 | |
*** jsavak has joined #openstack-keystone | 21:30 | |
*** julim has quit IRC | 21:30 | |
*** sdake_ is now known as sdake | 21:33 | |
openstackgerrit | Brant Knudson proposed openstack/keystonemiddleware: s3token config with auth URI https://review.openstack.org/312260 | 21:33 |
*** e0ne has joined #openstack-keystone | 21:34 | |
*** fedruantine has joined #openstack-keystone | 21:36 | |
bknudson | stevemar: that devstack patch failed spectacularly. | 21:37 |
bknudson | looks like tempest issues as per usual. | 21:37 |
*** e0ne has quit IRC | 21:38 | |
*** spzala has joined #openstack-keystone | 21:45 | |
*** spzala has quit IRC | 21:45 | |
*** henrynash has quit IRC | 21:48 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Make all fixture project_ids into uuids https://review.openstack.org/306681 | 21:51 |
*** mylu has quit IRC | 22:04 | |
*** doug-fi__ has quit IRC | 22:04 | |
*** mylu has joined #openstack-keystone | 22:05 | |
*** slberger has left #openstack-keystone | 22:06 | |
*** csoukup has quit IRC | 22:08 | |
*** navidp has quit IRC | 22:08 | |
*** mylu has quit IRC | 22:09 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 22:10 | |
*** tlbr has joined #openstack-keystone | 22:12 | |
*** mylu has joined #openstack-keystone | 22:12 | |
*** jsavak has quit IRC | 22:19 | |
*** jsavak has joined #openstack-keystone | 22:20 | |
*** nalind has quit IRC | 22:20 | |
*** phalmos has quit IRC | 22:25 | |
*** alee has quit IRC | 22:36 | |
*** pushkaru has quit IRC | 22:38 | |
*** mylu has quit IRC | 22:38 | |
*** krotscheck is now known as krotscheck_dcm | 22:44 | |
*** rbridgeman has quit IRC | 22:45 | |
*** ametts has quit IRC | 22:45 | |
*** mylu has joined #openstack-keystone | 22:46 | |
*** mylu has quit IRC | 22:47 | |
*** _amrith_ is now known as amrith | 22:49 | |
*** timcline_ has quit IRC | 22:50 | |
*** edtubill has quit IRC | 22:50 | |
*** dmk0202 has quit IRC | 22:54 | |
*** sdake has quit IRC | 22:55 | |
*** sdake has joined #openstack-keystone | 22:55 | |
*** stingaci has quit IRC | 23:02 | |
*** roxanaghe has joined #openstack-keystone | 23:07 | |
*** pgbridge has quit IRC | 23:10 | |
*** gordc has quit IRC | 23:11 | |
*** jsavak has quit IRC | 23:12 | |
gyee | bknudson, topol, not sure if you guys try it lately, but ldap option with devstack doesn't appear to work | 23:13 |
gyee | enable_service ldap | 23:13 |
gyee | KEYSTONE_IDENTITY_BACKEND=ldap | 23:13 |
*** pushkaru has joined #openstack-keystone | 23:15 | |
*** markvoelker_ has quit IRC | 23:16 | |
*** rbridgeman has joined #openstack-keystone | 23:20 | |
*** alee has joined #openstack-keystone | 23:23 | |
*** BjoernT has quit IRC | 23:24 | |
bknudson | gyee: works for me. | 23:37 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Fix fernet audit ids for v2.0 https://review.openstack.org/311886 | 23:38 |
lbragstad | bknudson fixed ^ | 23:38 |
lbragstad | we should be able to merge that once ayoung's patch lands | 23:38 |
bknudson | ok, thanks | 23:39 |
*** pushkaru has quit IRC | 23:39 | |
gyee | bknudson, I think I have proxy issue, looking into it now | 23:39 |
*** pushkaru has joined #openstack-keystone | 23:40 | |
bknudson | I don't have a proxy so don't have any advice. | 23:40 |
*** pumarani__ has joined #openstack-keystone | 23:44 | |
*** pushkaru has quit IRC | 23:44 | |
*** rbridgeman has quit IRC | 23:45 | |
hoonetorg | https://bugs.launchpad.net/keystone/+bug/1516946/comments/10 | 23:53 |
openstack | Launchpad bug 1516946 in puppet-keystone "keystone WSGI fail: ArgsAlreadyParsedError: arguments already parsed: cannot register CLI option" [Undecided,Invalid] | 23:53 |
hoonetorg | where are these actual wsgi scripts??? | 23:53 |
hoonetorg | i'm using the ones packaged with centos-cloud-openstack-mitaka | 23:54 |
bknudson | hoonetorg: when you install keystone pbr generates wsgi scripts in bin | 23:54 |
hoonetorg | and get ArgsAlreadyParsedError: arguments already parsed: cannot register CLI option | 23:54 |
bknudson | I don't know what centos does | 23:54 |
hoonetorg | bknudson: how to create??? | 23:55 |
bknudson | create a virtualenv, then pip install -e /path/to/keystone | 23:55 |
bknudson | I have no idea how centos would expect you to do it... probably best to ask on a centos channel? | 23:56 |
*** pumarani__ has quit IRC | 23:57 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!