*** spzala has joined #openstack-keystone | 00:09 | |
*** spzala has quit IRC | 00:14 | |
*** spzala has joined #openstack-keystone | 00:47 | |
*** markvoelker has joined #openstack-keystone | 00:51 | |
*** markvoelker has quit IRC | 00:56 | |
*** anush__ has joined #openstack-keystone | 01:01 | |
*** KevinE has joined #openstack-keystone | 01:01 | |
*** KevinE has joined #openstack-keystone | 01:02 | |
*** anush__ has quit IRC | 01:15 | |
*** spzala has quit IRC | 01:35 | |
*** TxGVNN has joined #openstack-keystone | 01:41 | |
*** trey has quit IRC | 01:41 | |
*** EinstCrazy has joined #openstack-keystone | 01:45 | |
*** markvoelker has joined #openstack-keystone | 01:52 | |
*** markvoelker has quit IRC | 01:57 | |
*** anush__ has joined #openstack-keystone | 01:59 | |
*** EinstCra_ has joined #openstack-keystone | 02:04 | |
*** EinstCrazy has quit IRC | 02:06 | |
*** anush__ has quit IRC | 02:17 | |
*** EinstCrazy has joined #openstack-keystone | 02:21 | |
*** sdake_ has quit IRC | 02:23 | |
*** EinstCra_ has quit IRC | 02:24 | |
*** davechen has joined #openstack-keystone | 02:26 | |
*** KevinE has quit IRC | 02:33 | |
*** KevinE has joined #openstack-keystone | 02:49 | |
*** markvoelker has joined #openstack-keystone | 02:53 | |
*** markvoelker has quit IRC | 02:57 | |
*** roxanaghe has joined #openstack-keystone | 03:06 | |
*** KevinE has joined #openstack-keystone | 03:06 | |
openstackgerrit | yangweiwei proposed openstack/keystone: Error in get revoke_list https://review.openstack.org/333765 | 03:06 |
---|---|---|
*** roxanaghe has quit IRC | 03:07 | |
*** roxanaghe has joined #openstack-keystone | 03:07 | |
*** spzala has joined #openstack-keystone | 03:10 | |
*** pleia2_ is now known as pleia2 | 03:15 | |
*** phalmos has joined #openstack-keystone | 03:23 | |
*** freerunner has quit IRC | 03:23 | |
*** robcresswell has quit IRC | 03:24 | |
*** Tridde has quit IRC | 03:24 | |
*** Trident has joined #openstack-keystone | 03:25 | |
*** Daviey has quit IRC | 03:25 | |
*** Daviey has joined #openstack-keystone | 03:26 | |
*** robcresswell has joined #openstack-keystone | 03:27 | |
*** phalmos has quit IRC | 03:28 | |
*** freerunner has joined #openstack-keystone | 03:29 | |
*** markvoelker has joined #openstack-keystone | 03:54 | |
*** markvoelker has quit IRC | 03:58 | |
*** spzala has quit IRC | 04:05 | |
*** roxanaghe has quit IRC | 04:15 | |
*** links has joined #openstack-keystone | 04:15 | |
*** roxanaghe has joined #openstack-keystone | 04:28 | |
*** KevinE has quit IRC | 04:30 | |
*** roxanaghe has quit IRC | 04:32 | |
*** markvoelker has joined #openstack-keystone | 04:54 | |
*** markvoelker has quit IRC | 04:59 | |
*** davechen has quit IRC | 05:05 | |
openstackgerrit | Merged openstack/keystone: Moves auth plugin test setup closer to its use https://review.openstack.org/334058 | 05:11 |
openstackgerrit | Merged openstack/keystone: Remove unused test code https://review.openstack.org/334059 | 05:12 |
*** KevinE has joined #openstack-keystone | 05:31 | |
*** KevinE has quit IRC | 05:35 | |
*** lunarlamp is now known as mariusv | 05:36 | |
*** davechen has joined #openstack-keystone | 05:38 | |
*** mariusv has quit IRC | 05:43 | |
*** TxGVNN has quit IRC | 05:47 | |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Break out the API piece into its own file https://review.openstack.org/334290 | 05:50 |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Extract a common notifier pattern https://review.openstack.org/334291 | 05:50 |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Refactor create_event onto the api object. https://review.openstack.org/334292 | 05:50 |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Refactor audit api tests into their own file https://review.openstack.org/334293 | 05:50 |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Refactor API tests to not run middleware https://review.openstack.org/334294 | 05:50 |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Use a test notifier to record notifications https://review.openstack.org/334295 | 05:50 |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Extract oslo_messaging specific audit tests https://review.openstack.org/334296 | 05:50 |
*** KevinE has joined #openstack-keystone | 05:52 | |
*** pgreg has joined #openstack-keystone | 05:52 | |
*** markvoelker has joined #openstack-keystone | 05:55 | |
*** pgreg has quit IRC | 05:57 | |
*** KevinE has quit IRC | 05:57 | |
*** KevinE has joined #openstack-keystone | 05:58 | |
*** EinstCrazy has quit IRC | 05:59 | |
*** markvoelker has quit IRC | 06:00 | |
*** spzala has joined #openstack-keystone | 06:05 | |
*** spzala has quit IRC | 06:10 | |
openstackgerrit | yangweiwei proposed openstack/keystone: Error in get revoke_list https://review.openstack.org/333765 | 06:11 |
*** KevinE has quit IRC | 06:16 | |
*** EinstCrazy has joined #openstack-keystone | 06:24 | |
*** rcernin has joined #openstack-keystone | 06:27 | |
*** M00nr41n has joined #openstack-keystone | 06:33 | |
*** KevinE has joined #openstack-keystone | 06:37 | |
*** pcaruana has joined #openstack-keystone | 06:41 | |
*** KevinE has quit IRC | 06:42 | |
*** EinstCrazy has quit IRC | 06:44 | |
*** markvoelker has joined #openstack-keystone | 06:56 | |
*** EinstCrazy has joined #openstack-keystone | 06:56 | |
*** d0ugal has joined #openstack-keystone | 06:58 | |
*** d0ugal has quit IRC | 06:59 | |
*** tesseract- has joined #openstack-keystone | 06:59 | |
*** d0ugal has joined #openstack-keystone | 07:00 | |
*** d0ugal has quit IRC | 07:00 | |
*** d0ugal has joined #openstack-keystone | 07:00 | |
*** markvoelker has quit IRC | 07:01 | |
*** jamielennox is now known as jamielennox|away | 07:01 | |
*** belmoreira has joined #openstack-keystone | 07:09 | |
*** jed56 has joined #openstack-keystone | 07:11 | |
*** sheel has joined #openstack-keystone | 07:12 | |
*** roxanaghe has joined #openstack-keystone | 07:16 | |
*** rvba has joined #openstack-keystone | 07:20 | |
*** rvba has quit IRC | 07:20 | |
*** rvba has joined #openstack-keystone | 07:20 | |
*** roxanaghe has quit IRC | 07:20 | |
*** ebarrera has joined #openstack-keystone | 07:23 | |
*** dmk0202 has joined #openstack-keystone | 07:31 | |
*** TxGVNN has joined #openstack-keystone | 07:41 | |
*** pnavarro has joined #openstack-keystone | 07:51 | |
*** permalac has joined #openstack-keystone | 07:56 | |
*** davechen has left #openstack-keystone | 07:58 | |
*** KevinE has joined #openstack-keystone | 07:59 | |
*** zzzeek has quit IRC | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:02 | |
*** KevinE has quit IRC | 08:04 | |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c https://review.openstack.org/318435 | 08:10 |
*** bjornar_ has joined #openstack-keystone | 08:16 | |
*** rudolfvriend has joined #openstack-keystone | 08:21 | |
openstackgerrit | henry-nash proposed openstack/keystone-specs: Support nested domains to provide additional project namespaces https://review.openstack.org/332940 | 08:28 |
*** itisha has joined #openstack-keystone | 08:28 | |
openstackgerrit | henry-nash proposed openstack/keystone-specs: Support nested domains to provide additional project namespaces https://review.openstack.org/332940 | 08:30 |
*** vgridnev_ has joined #openstack-keystone | 08:31 | |
openstackgerrit | henry-nash proposed openstack/keystone-specs: Support nested domains to provide additional project namespaces https://review.openstack.org/332940 | 08:35 |
*** fawadkhaliq has joined #openstack-keystone | 08:39 | |
*** bjornar_ has quit IRC | 08:39 | |
*** vgridnev_ has quit IRC | 08:52 | |
*** rudolfvriend has quit IRC | 08:54 | |
*** roxanaghe has joined #openstack-keystone | 09:05 | |
*** spzala has joined #openstack-keystone | 09:05 | |
*** spzala has quit IRC | 09:10 | |
*** roxanaghe has quit IRC | 09:14 | |
*** sheel has quit IRC | 09:15 | |
openstackgerrit | henry-nash proposed openstack/keystone-specs: Gate inherited assignements from parent https://review.openstack.org/334364 | 09:16 |
*** KevinE has joined #openstack-keystone | 09:21 | |
*** KevinE has quit IRC | 09:25 | |
openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: WIP - oidc: fix OpenID Connect authorization code grant_type https://review.openstack.org/330006 | 09:26 |
openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: oidc: add discovery document support https://review.openstack.org/330464 | 09:26 |
openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: oidc: remove grant_type argument https://review.openstack.org/330465 | 09:26 |
*** jamielennox|away is now known as jamielennox | 09:26 | |
aloga | jamielennox: I've tried to address your comments in https://review.openstack.org/330464 | 09:31 |
jamielennox | aloga: oh, right - yea that one will be useful, i'm not sure why it wasn't done that way initially | 09:31 |
jamielennox | aloga: stupid gerrit UI - i'm not sure where in the patch order that one is | 09:32 |
aloga | it is after the WIP one, as this one introduced the "authorization_endpoint" parameter | 09:34 |
aloga | I can move it so that it does not depend on the WIP though | 09:34 |
*** mdavidson has joined #openstack-keystone | 09:44 | |
*** nisha has joined #openstack-keystone | 09:46 | |
jamielennox | aloga: ok, i added a few comments that i saw quickly | 09:50 |
jamielennox | nothing serious i don't think | 09:50 |
*** dims has quit IRC | 10:14 | |
*** dims has joined #openstack-keystone | 10:20 | |
*** fawadkhaliq has quit IRC | 10:39 | |
openstackgerrit | henry-nash proposed openstack/keystone-specs: Gate inherited assignments from parent https://review.openstack.org/334364 | 10:39 |
*** KevinE has joined #openstack-keystone | 10:42 | |
*** links has quit IRC | 10:43 | |
*** GB21 has joined #openstack-keystone | 10:45 | |
*** EinstCrazy has quit IRC | 10:45 | |
*** KevinE has quit IRC | 10:47 | |
*** daemontool has joined #openstack-keystone | 10:50 | |
*** TxGVNN has quit IRC | 10:53 | |
*** roxanaghe has joined #openstack-keystone | 10:53 | |
*** links has joined #openstack-keystone | 10:55 | |
*** roxanaghe has quit IRC | 10:58 | |
*** markvoelker has joined #openstack-keystone | 10:59 | |
*** samueldmq has joined #openstack-keystone | 11:01 | |
*** ChanServ sets mode: +v samueldmq | 11:01 | |
samueldmq | morning keystone | 11:01 |
*** markvoelker has quit IRC | 11:03 | |
dstanek | samueldmq: o/ good mornig | 11:04 |
samueldmq | dstanek: o/ | 11:05 |
henrynash | morning…and today I shall be typing from Liechtenstein | 11:05 |
samueldmq | henrynash: o/ | 11:06 |
samueldmq | henrynash: in a tour aroung the world ? | 11:06 |
samueldmq | :) | 11:06 |
henrynash | samueldmq: indeed, trying to keep my european credentials alive | 11:06 |
samueldmq | henrynash: nice | 11:09 |
*** amakarov_away is now known as amakarov | 11:10 | |
* samueldmq does to do coffee in a moka pot | 11:11 | |
samueldmq | https://en.wikipedia.org/wiki/Moka_pot | 11:11 |
* samueldmq goes* | 11:12 | |
henrynash | has run out of cofee. eeek! off to buy coffee | 11:12 |
samueldmq | ++ | 11:12 |
*** bj0rnar has quit IRC | 11:16 | |
*** nisha has quit IRC | 11:16 | |
*** stian_ has quit IRC | 11:17 | |
*** stian_ has joined #openstack-keystone | 11:19 | |
*** bj0rnar has joined #openstack-keystone | 11:19 | |
*** fawadkhaliq has joined #openstack-keystone | 11:20 | |
openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: WIP - oidc: fix OpenID Connect authorization code grant_type https://review.openstack.org/330006 | 11:24 |
openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: oidc: add discovery document support https://review.openstack.org/330464 | 11:24 |
openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: oidc: remove grant_type argument https://review.openstack.org/330465 | 11:24 |
*** jefrite has quit IRC | 11:31 | |
*** jefrite has joined #openstack-keystone | 11:35 | |
*** GB21 has quit IRC | 11:35 | |
openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: move release note into the correct location https://review.openstack.org/334425 | 11:35 |
*** gordc has joined #openstack-keystone | 11:36 | |
*** nisha has joined #openstack-keystone | 11:41 | |
nisha | samueldmq, hi | 11:41 |
samueldmq | nisha: hi, good morning, how are you ? | 11:43 |
nisha | samueldmq, I am good, was working on roles | 11:43 |
nisha | samueldmq, regarding the projects, we still have some issue, the patches failed automated test | 11:44 |
nisha | samueldmq, can you please help me fix them? | 11:44 |
*** agireud has quit IRC | 11:45 | |
samueldmq | nisha: I can help you finding the issue | 11:45 |
samueldmq | nisha: first, go to the change https://review.openstack.org/#/c/332871/ | 11:46 |
patchbot | samueldmq: patch 332871 - python-keystoneclient - Add project functional tests | 11:46 |
samueldmq | nisha: click on the gate that is failing ( gate-keystoneclient-dsvm-functional ) and then click on console | 11:46 |
samueldmq | nisha: looking at the logs, you will see a test failed | 11:49 |
samueldmq | nisha: keystoneclient.tests.functional.v3.test_users.UsersTestCase.test_update_user | 11:49 |
nisha | samueldmq, looking | 11:50 |
samueldmq | nisha: and that test is not related to your patch, so it's an unrelated failure; in those cases you may try leaving a "recheck" message as a comment in the patch | 11:50 |
samueldmq | nisha: then the jobs will re-run | 11:50 |
samueldmq | nisha: but in this case, the issue will be fixed when https://review.openstack.org/#/c/333919/ merges | 11:51 |
patchbot | samueldmq: patch 333919 - keystone - Fixes failure when password is null | 11:51 |
samueldmq | stevemar: dstanek: (other cores): ^ would be nice to get this in, this is causing some gates to fail (e.g keystoneclient functional) | 11:52 |
dstanek | samueldmq: looking at some capstone reviews....once i'm done i'll look at that | 11:52 |
samueldmq | dstanek: thanks | 11:53 |
nisha | samueldmq, got it | 11:54 |
nisha | samueldmq, thanks | 11:54 |
samueldmq | nisha: :) | 11:56 |
*** raildo-a` is now known as raildo | 11:56 | |
*** GB21 has joined #openstack-keystone | 11:58 | |
*** KevinE has joined #openstack-keystone | 12:04 | |
*** daemontool has quit IRC | 12:05 | |
*** daemontool has joined #openstack-keystone | 12:05 | |
*** rodrigods has quit IRC | 12:06 | |
*** rodrigods has joined #openstack-keystone | 12:06 | |
*** nisha_ has joined #openstack-keystone | 12:07 | |
*** KevinE has quit IRC | 12:10 | |
*** amoralej is now known as amoralej|lunch | 12:11 | |
*** nisha has quit IRC | 12:11 | |
*** markvoelker has joined #openstack-keystone | 12:14 | |
*** agireud has joined #openstack-keystone | 12:16 | |
*** nisha_ has quit IRC | 12:28 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 12:30 | |
*** fawadkhaliq has quit IRC | 12:31 | |
*** fawadkhaliq has joined #openstack-keystone | 12:32 | |
*** GB21 has quit IRC | 12:35 | |
*** fawadkhaliq has quit IRC | 12:37 | |
henrynash | Henry’s latest attempts to get round the project naming constraints can be seen at: https://review.openstack.org/#/c/332940/ and https://review.openstack.org/#/c/334364 | 12:37 |
patchbot | henrynash: patch 332940 - keystone-specs - Support nested domains to provide additional proje... | 12:37 |
*** nisha has joined #openstack-keystone | 12:41 | |
nisha | samueldmq, do I need to add doc for create_implied, check_implied , get_implied ,delete_implied, list_role_inferences, too for roles? | 12:42 |
nisha | samueldmq, Also are there any existing docs on them which I can use here for the above methods reference? | 12:53 |
*** amoralej|lunch is now known as amoralej | 12:56 | |
*** nisha has quit IRC | 12:58 | |
*** nisha has joined #openstack-keystone | 12:58 | |
*** real56 has joined #openstack-keystone | 13:00 | |
*** edmondsw has joined #openstack-keystone | 13:01 | |
*** wanghua has joined #openstack-keystone | 13:05 | |
*** spzala has joined #openstack-keystone | 13:06 | |
*** fawadkhaliq has joined #openstack-keystone | 13:09 | |
*** sdake has joined #openstack-keystone | 13:10 | |
*** spzala has quit IRC | 13:10 | |
*** fawadkhaliq has quit IRC | 13:12 | |
*** setuid has joined #openstack-keystone | 13:14 | |
setuid | has anyone managed to get keystone working under liberty on Ubuntu 14.04? I've tried about 40 times across multiple types of hardware, clean installs, etc. and it just dies with '*config-changed*', while all the other nodes are up, but I can't log into horizon, because keystone is DOA. | 13:15 |
setuid | I can ssh into the keystone node, restart keystone, etc. but it just never completes the init during install | 13:16 |
*** EinstCrazy has joined #openstack-keystone | 13:16 | |
*** joaotargino has quit IRC | 13:19 | |
*** spzala has joined #openstack-keystone | 13:19 | |
*** sdake_ has joined #openstack-keystone | 13:20 | |
*** jsavak has joined #openstack-keystone | 13:21 | |
*** sdake has quit IRC | 13:21 | |
*** KevinE has joined #openstack-keystone | 13:26 | |
*** richm has joined #openstack-keystone | 13:27 | |
*** gagehugo has joined #openstack-keystone | 13:28 | |
*** KevinE has quit IRC | 13:30 | |
*** belmoreira has quit IRC | 13:31 | |
openstackgerrit | David Stanek proposed openstack/keystone: Group test_backend_ldap skips for readability https://review.openstack.org/334061 | 13:35 |
dstanek | setuid: what do you mean by dies with config-changed? | 13:40 |
*** _d34dh0r53_ is now known as d34dh0r53 | 13:45 | |
*** woodburn has quit IRC | 13:49 | |
*** gagehugo has quit IRC | 13:49 | |
*** woodburn has joined #openstack-keystone | 13:49 | |
*** rudolfvriend has joined #openstack-keystone | 13:52 | |
stevemar | morning! | 13:52 |
stevemar | samueldmq: that was a major regression so i want to make sure we don't muck things up so far only 2 gate failures (heat and keystoneclient) | 13:53 |
*** ghugo has joined #openstack-keystone | 13:54 | |
samueldmq | stevemar: yes, fyi it's been approved | 13:56 |
samueldmq | nisha: so, yes ... let me find the docs you may be based on | 13:56 |
*** M00nr41n has quit IRC | 13:56 | |
samueldmq | nisha: CRUD of implied roles' docs starting ehre https://github.com/openstack/keystone-specs/blob/master/api/v3/identity-api-v3.rst#create-role-inference-rule | 13:57 |
stevemar | samueldmq: migration errors make me sad :( | 13:59 |
samueldmq | stevemar: yes, me too | 13:59 |
samueldmq | stevemar: did you see my problem description in the bug report ? | 13:59 |
*** ametts has joined #openstack-keystone | 14:00 | |
samueldmq | stevemar: if we create a test to make sure the result of migrations always correspond to the current model, we would avoid hitting that issue again | 14:00 |
*** EinstCrazy has quit IRC | 14:00 | |
* samueldmq still hates how gerrit shows patch dependencies, it looks to be broken sometimes | 14:03 | |
*** mfisch has joined #openstack-keystone | 14:06 | |
*** rderose has joined #openstack-keystone | 14:06 | |
*** mfisch has quit IRC | 14:06 | |
*** mfisch has joined #openstack-keystone | 14:06 | |
*** spzala has quit IRC | 14:09 | |
*** spzala has joined #openstack-keystone | 14:10 | |
nisha | samueldmq, still not getting much :/ | 14:13 |
*** spzala has quit IRC | 14:14 | |
nisha | samueldmq, what does it mean when it a role implied another role? | 14:14 |
nisha | implies* | 14:14 |
samueldmq | nisha: so, roles go in the user's token | 14:16 |
samueldmq | nisha: and define authorization (what API calls that user can perform) | 14:16 |
samueldmq | nisha: if we have Role A implies on both Role B and C, when user requests a token, he/she will get roles B and C | 14:17 |
*** GB21 has joined #openstack-keystone | 14:17 | |
samueldmq | nisha: rather than A, and it would also apply if B and C had impled roles, and so on | 14:17 |
samueldmq | nisha: it makes managing role assignments easier and more powerful, given you only assign 1 role and get many :) | 14:18 |
nisha | samueldmq, hmm, thanks | 14:19 |
*** mkoderer__ has quit IRC | 14:21 | |
*** woodster_ has joined #openstack-keystone | 14:22 | |
*** ayoung has joined #openstack-keystone | 14:22 | |
*** ChanServ sets mode: +v ayoung | 14:22 | |
*** ghugo has left #openstack-keystone | 14:29 | |
openstackgerrit | Merged openstack/keystone: Fixes failure when password is null https://review.openstack.org/333919 | 14:29 |
*** ghugo has joined #openstack-keystone | 14:29 | |
*** ddieterly has joined #openstack-keystone | 14:30 | |
*** TxGVNN has joined #openstack-keystone | 14:31 | |
*** ebarrera has quit IRC | 14:34 | |
*** ghugo has quit IRC | 14:34 | |
*** gagehugo has joined #openstack-keystone | 14:35 | |
nisha | samueldmq, what is the type of role_inference ? | 14:36 |
samueldmq | nisha: in keystoneclient side ? | 14:37 |
nisha | yeah | 14:37 |
nisha | samueldmq, e.g. when we call create_implied(...) | 14:38 |
samueldmq | nisha: https://github.com/openstack/python-keystoneclient/blob/master/keystoneclient/v3/roles.py#L37 | 14:38 |
samueldmq | nisha: thus keystoneclient.v3.roles.InferenceRule | 14:38 |
nisha | oh, thanks | 14:38 |
nisha | :) | 14:38 |
samueldmq | nisha: np | 14:39 |
*** nisha has quit IRC | 14:41 | |
*** nisha has joined #openstack-keystone | 14:42 | |
*** jaugustine has joined #openstack-keystone | 14:44 | |
*** KevinE has joined #openstack-keystone | 14:47 | |
*** ayoung_ has joined #openstack-keystone | 14:48 | |
*** belmoreira has joined #openstack-keystone | 14:50 | |
*** david-lyle_ has joined #openstack-keystone | 14:51 | |
*** KevinE has quit IRC | 14:55 | |
*** david-lyle has quit IRC | 14:55 | |
*** crinkle_ is now known as crinkle | 14:55 | |
*** slberger has joined #openstack-keystone | 14:59 | |
*** spzala has joined #openstack-keystone | 14:59 | |
*** ddieterly is now known as ddieterly[away] | 14:59 | |
*** sdake has joined #openstack-keystone | 15:01 | |
*** KevinE has joined #openstack-keystone | 15:01 | |
*** spzala has quit IRC | 15:01 | |
*** spzala has joined #openstack-keystone | 15:01 | |
ayoung_ | stevemar, notmorgan bknudson_ dolphm samueldmq rodrigods https://etherpad.openstack.org/p/troubleshoot-keystone | 15:01 |
*** jistr is now known as jistr|mtg | 15:01 | |
ayoung_ | lets collect up what we tell people to do every time and post it there | 15:01 |
*** KevinE has quit IRC | 15:02 | |
ayoung_ | lbragstad, you too | 15:02 |
*** mvk_ has quit IRC | 15:02 | |
*** KevinE has joined #openstack-keystone | 15:02 | |
lbragstad | ayoung_ sweet - I'll take a look at it in a few minutes | 15:02 |
ayoung_ | lbragstad, its pretty empty | 15:02 |
ayoung_ | just...we get asked the same questions time and again...lets crowdsource the solutions | 15:03 |
*** sdake_ has quit IRC | 15:03 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Add failed auth attempts logic to meet PCI-DSS https://review.openstack.org/324029 | 15:03 |
rodrigods | ayoung_, ++ this can be pushed as a doc later | 15:05 |
*** krotscheck is now known as krotscheck_dcm | 15:05 | |
ayoung_ | rodrigods, right. for now, we need something flexible to gather the data | 15:05 |
*** pgbridge has joined #openstack-keystone | 15:09 | |
*** david-lyle_ is now known as david-lyle | 15:09 | |
*** ddieterly[away] is now known as ddieterly | 15:09 | |
stevemar | ayoung_: I like the idea | 15:09 |
*** ayoung has quit IRC | 15:09 | |
*** ayoung_ is now known as ayoung | 15:09 | |
ayoung | it should be mostly pointers to other documents. But should be the "here's how to get started" | 15:10 |
*** belmoreira has quit IRC | 15:10 | |
*** ebarrera has joined #openstack-keystone | 15:13 | |
*** jistr|mtg is now known as jistr | 15:16 | |
*** raddaoui has joined #openstack-keystone | 15:21 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Disable inactive users requirements https://review.openstack.org/328447 | 15:24 |
*** jorge_munoz has joined #openstack-keystone | 15:25 | |
openstackgerrit | Merged openstack/keystoneauth: move release note to correct directory https://review.openstack.org/334141 | 15:25 |
*** BjoernT has joined #openstack-keystone | 15:26 | |
*** ebarrera has quit IRC | 15:28 | |
*** dmk0202 has quit IRC | 15:30 | |
henrynash | rderose: hi | 15:33 |
rderose | henrynash: hi | 15:33 |
henrynash | rderose: did you see my comment on the rolling upgrade case? Do you think it is a real issue, or do we handle it somehow already | 15:34 |
henrynash | on: https://review.openstack.org/#/c/328447/ | 15:35 |
patchbot | henrynash: patch 328447 - keystone - PCI-DSS Disable inactive users requirements | 15:35 |
rderose | henrynash: no it is a real issue | 15:35 |
rderose | henrynash: I'm thinking of handling it with a release note that says to check and ensure the value is set after a rolling upgrade. | 15:36 |
*** roxanaghe has joined #openstack-keystone | 15:36 | |
henrynash | rderose: althoug how would a user fix it? | 15:36 |
henrynash | rderose: I don’t think we want to requite peopel to get the sql editors out | 15:36 |
rderose | henrynash: run a sql script to update the column with the current date | 15:37 |
rderose | henrynash: or, if it's not set, I can set it. but that will lead us down a slippery slope in my opinion | 15:38 |
henrynash | rderose: if you like, I’ll write a keystone-manage framwork that would hold this….and then you could add teh actuall fix? In fact, if you like, I’ll fix https://review.openstack.org/#/c/328447/ with such a tool, and then you caould add your code in a follow on patch? | 15:38 |
patchbot | henrynash: patch 328447 - keystone - PCI-DSS Disable inactive users requirements | 15:38 |
henrynash | dorry, wrong link | 15:38 |
*** pcaruana has quit IRC | 15:38 | |
henrynash | https://bugs.launchpad.net/keystone/+bug/1596500 | 15:38 |
openstack | Launchpad bug 1596500 in OpenStack Identity (keystone) "Passwords created_at attribute could remain unset during rolling upgrade" [Undecided,New] | 15:38 |
henrynash | The idea of rolling upgrades was to always have this [service]-manage “end of migration” command that an admin would run when all the nodes of that service had been upgraded….we’ve just never written it before! | 15:39 |
*** tesseract- has quit IRC | 15:40 | |
*** M00nr41n has joined #openstack-keystone | 15:41 | |
rderose | henrynash: that sounds great! | 15:43 |
henrynash | rderose: ok, I’m on it | 15:43 |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Disable inactive users requirements https://review.openstack.org/328447 | 15:44 |
rderose | henrynash: just uploaded the latest | 15:44 |
*** pnavarro has quit IRC | 15:44 | |
*** daemontool has quit IRC | 15:44 | |
*** tonytan4ever has joined #openstack-keystone | 15:44 | |
*** rudolfvriend has quit IRC | 15:45 | |
*** darosale has joined #openstack-keystone | 15:46 | |
*** GB21 has quit IRC | 15:46 | |
*** ddieterly is now known as ddieterly[away] | 15:52 | |
*** links has quit IRC | 15:52 | |
samueldmq | ayoung: nice, great idea | 15:54 |
samueldmq | ayoung: I've been thinking of a FAQ docs for keystone | 15:54 |
samueldmq | ayoung: that's really useful | 15:54 |
*** BjoernT has quit IRC | 15:54 | |
setuid | dstanek, that's the only message I see in the curses gui during install | 15:54 |
setuid | Stays like that for days | 15:55 |
setuid | I kill it, re-run openstack-install, does the same, over and over about 40 times I've tried this weekend | 15:55 |
setuid | at one point, keystone looked green, but neutron had the same error ("*config-changed*"), and I could go no further | 15:55 |
*** rderose has quit IRC | 15:55 | |
dstanek | setuid: oh, i've never used any of those install tools. | 15:56 |
*** ddieterly[away] is now known as ddieterly | 15:56 | |
dstanek | that may be an issue specific to the tool you are using | 15:56 |
setuid | I haven't yet had a single successful openstack install after about 50-60 attempts, using bare metal, virtualbox, vmware, kvm/qemu on my Linux desktop, juju, conjure-up, etc. | 15:56 |
setuid | I didn't realize going into this, that it was in such a fragile/alpha state as a framework | 15:57 |
*** rderose has joined #openstack-keystone | 15:57 | |
dstanek | setuid: openstack in general? | 15:57 |
setuid | Yes | 15:57 |
lbragstad | dstanek links to your test patches? | 15:58 |
dstanek | setuid: i've been able to install using both OSA and RDO without issue. what tools have you been using to install? | 15:58 |
lbragstad | dstanek any specific ones to look at? | 15:58 |
setuid | dstanek, All of the Ubuntu-specific tools, as that's what I'm required to use | 15:59 |
openstackgerrit | Nisha Yadav proposed openstack/python-keystoneclient: Improve docs for v3 roles https://review.openstack.org/334546 | 15:59 |
dstanek | lbragstad: https://review.openstack.org/#/c/334060/3 may be a good place to start | 16:00 |
patchbot | dstanek: patch 334060 - keystone - Adds a backend test fixture | 16:00 |
nisha | samueldmq, have a look please ^ | 16:00 |
dstanek | setuid: what is the tool? i'd like to try to run it | 16:00 |
setuid | openstack-install on 14.04, conjure-up on 16.04, or use maas or juju 'raw' commands | 16:00 |
samueldmq | henrynash: I have a suggestion for naming ... change 334364 | 16:00 |
samueldmq | henrynash: :) | 16:00 |
samueldmq | nisha: looking now | 16:01 |
openstackgerrit | Merged openstack/keystone: Allow user to get themself and their domain https://review.openstack.org/333516 | 16:04 |
*** tqtran has joined #openstack-keystone | 16:05 | |
dstanek | setuid: just created a 14.04. where does openstack-install come from? | 16:10 |
setuid | dstanek, apt-get install openstack && openstack-install | 16:10 |
dstanek | hmmm...that package doesn't seem to be on the rackspace mirrors | 16:11 |
*** BjoernT has joined #openstack-keystone | 16:13 | |
*** BjoernT is now known as Bjoern_zZzZzZzZ | 16:13 | |
setuid | Might be in a ppa | 16:15 |
*** nisha has quit IRC | 16:16 | |
*** ayoung has quit IRC | 16:16 | |
*** nisha has joined #openstack-keystone | 16:16 | |
dstanek | setuid: yeah, i was able to get it installed | 16:16 |
samueldmq | nisha: done, see suggestions inline | 16:17 |
*** pauloewerton has joined #openstack-keystone | 16:17 | |
dstanek | setuid: the tools is pretty cruddy. i was able to break it almost on the first try so now i have to rebuild my vm | 16:17 |
nisha | samueldmq, sure, thanks | 16:17 |
dstanek | setuid: no idea. i select single install and then nothing happens | 16:20 |
setuid | Make sure you're not using vbox, because kvm DOES NOT work in vbox (vbox devs refuse to support it, going on 7 years now) | 16:20 |
dstanek | setuid: i'm using a cloud node at Rackspace | 16:21 |
*** Bjoern_zZzZzZzZ is now known as BjoernT | 16:23 | |
*** slberger has quit IRC | 16:24 | |
*** diazjf has joined #openstack-keystone | 16:26 | |
dstanek | setuid: are you just trying to install to experiment, make a production cloud, or ? | 16:26 |
samueldmq | dstanek: see this http://paste.openstack.org/show/523613/ | 16:27 |
samueldmq | dstanek: without and with your patches for reducing running time of unit tests | 16:28 |
dstanek | samueldmq: nice | 16:28 |
dstanek | samueldmq: how is is the box you are running on? | 16:28 |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Unified delegation model https://review.openstack.org/208488 | 16:29 |
samueldmq | dstanek: it's a 6-core intel xeon @ 2.40GHz | 16:30 |
samueldmq | dstanek: 16gm ram | 16:30 |
*** ayoung has joined #openstack-keystone | 16:31 | |
*** ChanServ sets mode: +v ayoung | 16:31 | |
samueldmq | dstanek: so 12-core when virtualized, so I guess parallel run is helping me to run those fast | 16:31 |
dstanek | samueldmq: much beefier than my current instance. i want to work my way down to a smaller one though | 16:32 |
samueldmq | dstanek: it's a z640 workstation | 16:33 |
samueldmq | dstanek: yes I think we have much to do there | 16:33 |
*** timcline has joined #openstack-keystone | 16:33 | |
dstanek | my really aggressive patches don't apply at all anymore. | 16:33 |
*** timcline has quit IRC | 16:34 | |
lbragstad | dstanek reviewed your test changes, mostly just questions inline. I'm going to break for lunch to get a run in, should be back within the hour though | 16:34 |
samueldmq | dstanek: I'd like to see how is the dependency graph of our test classes ... I believe it's a mess (specially for LDAP tests) | 16:34 |
*** jsavak has quit IRC | 16:34 | |
*** timcline has joined #openstack-keystone | 16:34 | |
*** jsavak has joined #openstack-keystone | 16:35 | |
setuid | dstanek, I am trying to be conversant at an engineering level with openstack | 16:35 |
*** GB21 has joined #openstack-keystone | 16:35 | |
setuid | I understand all of the underlying tech, but the dozens of versions of openstack and hundreds of different (most of them broken) tools out there to install, configure and manage it are confusing | 16:35 |
setuid | Quite literally N-O-T-H-I-N-G works | 16:35 |
dstanek | setuid: you should try one of the tools supported by openstack, like ansible or puppet stuff | 16:37 |
setuid | No can do, have to use the tools provided by the mother ship | 16:38 |
dstanek | setuid: have you engaged them to see why they don't work? | 16:38 |
setuid | Yes, but it's apparently all me :) | 16:38 |
*** ddieterly is now known as ddieterly[away] | 16:39 | |
*** TxGVNN has quit IRC | 16:40 | |
dstanek | setuid: that's what they said? | 16:40 |
dstanek | setuid: if you are trying to understand at the engineering level then you should just use devstack | 16:42 |
*** nisha has quit IRC | 16:42 | |
*** nisha has joined #openstack-keystone | 16:42 | |
*** ddieterly[away] is now known as ddieterly | 16:43 | |
samueldmq | aloga: hi | 16:46 |
samueldmq | aloga: could you see my comment on patch 333850 ? | 16:46 |
patchbot | samueldmq: https://review.openstack.org/#/c/333850/ - keystoneauth - oidc: add tests for plugin loader | 16:46 |
*** slberger has joined #openstack-keystone | 16:46 | |
*** gyee has joined #openstack-keystone | 16:51 | |
*** ChanServ sets mode: +v gyee | 16:51 | |
samueldmq | aloga: nvm, I figured it out, see comment in the review | 16:51 |
*** fawadkhaliq has joined #openstack-keystone | 16:59 | |
*** belmoreira has joined #openstack-keystone | 17:00 | |
*** slberger has quit IRC | 17:01 | |
dstanek | rderose: how safe is it to start reviewing PCI stuff? looks like there has been a lot of churn recently | 17:02 |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Allow test migration by module name https://review.openstack.org/334568 | 17:02 |
*** belmoreira has quit IRC | 17:03 | |
amakarov | dstanek, hi! What do you think of this idea? ^ | 17:04 |
*** real56 has quit IRC | 17:05 | |
*** ayoung has quit IRC | 17:06 | |
*** amoralej is now known as amoralej|off | 17:06 | |
*** slberger has joined #openstack-keystone | 17:08 | |
*** woodster_ has quit IRC | 17:09 | |
openstackgerrit | Nisha Yadav proposed openstack/python-keystoneclient: Improve docs for v3 roles https://review.openstack.org/334546 | 17:10 |
dstanek | amakarov: what does it change? | 17:10 |
amakarov | dstanek, it allows upgrading sql using name rather than version number | 17:11 |
amakarov | in tests | 17:11 |
*** jsavak has quit IRC | 17:11 | |
amakarov | dstanek, so one don't need to update version numbers in migration tests on every rebase | 17:12 |
nisha | samueldmq, did all the changes you suggested :) | 17:13 |
dstanek | amakarov: the self.upgrade(#) statements? | 17:14 |
amakarov | dstanek, yes | 17:15 |
dstanek | amakarov: those don't have to be updated do they? | 17:15 |
amakarov | dstanek, the second one should be changed to self.upgrade_by_name | 17:16 |
amakarov | dstanek, I'll rebase one patch atop of it and use it as an example | 17:17 |
dstanek | amakarov: but does anything actually need to get updated for each release or do you really just like the name better? | 17:17 |
*** slberger has quit IRC | 17:17 | |
amakarov | dstanek, I very often run into situation: I have NNN_add_some_stuff.py migration | 17:18 |
*** slberger has joined #openstack-keystone | 17:18 | |
amakarov | and by the time it's reviewed several other changes are merged | 17:18 |
*** samueldmq has quit IRC | 17:18 | |
stevemar | dstanek: i'm also confused by that patch :) | 17:19 |
amakarov | so I have to upgrade it to NNN+X_add_some_stuff.py | 17:19 |
amakarov | so I have to upgrade tests too | 17:19 |
stevemar | amakarov: ah, you guys have some internal migrations you run? | 17:19 |
amakarov | change self.upgrade(NNN) to self.upgrade(NNN+X) | 17:19 |
amakarov | stevemar, yes | 17:20 |
*** itisha has quit IRC | 17:20 | |
*** samueldmq has joined #openstack-keystone | 17:20 | |
*** ChanServ sets mode: +v samueldmq | 17:20 | |
stevemar | amakarov: i see. and those need to be in the keystone repo? | 17:20 |
samueldmq | nisha: looking again | 17:20 |
stevemar | amakarov: we used to have extensions live in their own module if you recall | 17:21 |
amakarov | stevemar, to be used - yes | 17:21 |
*** ayoung has joined #openstack-keystone | 17:22 | |
*** ChanServ sets mode: +v ayoung | 17:22 | |
samueldmq | amakarov: dstanek: stevemar: unless there is a way to get version +1 by name too, I think calling by version number explicitly is good | 17:22 |
amakarov | stevemar, why not have it in our internal test toolset? | 17:22 |
stevemar | amakarov: just trying to understand the problem :) | 17:22 |
amakarov | samueldmq, and upgrade the numbers on every rebase? | 17:22 |
amakarov | stevemar, ok, I'm planning to update closure table patch for performance testing - let me use it as an example :) | 17:23 |
samueldmq | amakarov: in what scenario ? in the tests ? | 17:23 |
stevemar | amakarov: coolio | 17:23 |
amakarov | samueldmq, yep | 17:23 |
samueldmq | amakarov: I've never seen the need to update version numbers in the tests | 17:24 |
samueldmq | amakarov: they never change after merge | 17:24 |
amakarov | samueldmq, imagine the case: you add a table. You have numbered migration for that. And tests | 17:24 |
*** harlowja has quit IRC | 17:25 | |
stevemar | amakarov: there's also nothing to prevent me from doing 101_add_column and 102_add_column :) | 17:25 |
dstanek | ah i see. so you are reusing our numbers in your tests? | 17:25 |
amakarov | you hone it, address everybody's -1's, and occasionally see, that somebody's numbeerd migration landed | 17:25 |
dstanek | stevemar: ++ the # is the unique part | 17:25 |
dstanek | amakarov: can you start using reserved #s? | 17:26 |
amakarov | dstanek, it would be great, but I still can't figure out how it works :) | 17:27 |
*** samueldmq has quit IRC | 17:28 | |
amakarov | dstanek, can you point me some doc or ML related? | 17:28 |
dstanek | amakarov: is there any way to run run your migrations separately? | 17:28 |
dstanek | ML related to reserved #s? | 17:28 |
amakarov | dstanek, ++ | 17:28 |
stevemar | dstanek: amakarov: i was thinking you guys would do something like this: https://github.com/openstack/keystone/tree/kilo-eol/keystone/contrib/oauth1/migrate_repo/versions | 17:29 |
*** ddieterly is now known as ddieterly[away] | 17:29 | |
amakarov | dstanek, looks like I've missed a big part... AFAIK I have to add my migration in the chain to be able to test it | 17:29 |
dstanek | amakarov: i don't think so... like steve's link you should be able to do it like an extension | 17:30 |
*** jsavak has joined #openstack-keystone | 17:30 | |
*** slberger has quit IRC | 17:30 | |
dstanek | those were always somewhat separate | 17:30 |
stevemar | amakarov: i think dstanek is talking about the 095_placeholder files as the "reserved" numbers | 17:30 |
stevemar | dstanek: indeed they were | 17:30 |
dstanek | stevemar: amakarov: yes. the s/reserved/placeholder/ numbers can be used as a last resort since we don't really use them. but i don't know how they would work if you need a migration that depends on one of ours | 17:31 |
stevemar | dstanek: except we've used 2 of them this time around :| | 17:32 |
dstanek | amakarov: are you actually creating your own migrations that change the keystone schema or are these your own tables? | 17:32 |
dstanek | stevemar: yeah, but that's pretty rare | 17:32 |
dstanek | certainly much less than up using up more and more numbers | 17:32 |
*** harlowja has joined #openstack-keystone | 17:33 | |
amakarov | dstanek, what do you mean by "own tables"? I need to add table to keystone database | 17:33 |
*** nisha has quit IRC | 17:35 | |
amakarov | dstanek, can you please help me with this change https://review.openstack.org/#/c/285521/ ? | 17:35 |
patchbot | amakarov: patch 285521 - keystone - Closure table for HMT | 17:35 |
amakarov | 105 is already landed, so I have to update it | 17:35 |
amakarov | dstanek, after that patch will hang around for some time gathering +'es and -'es, and meanwhile 106 will land, so I'll have to update all versions and loose all reviews | 17:36 |
dstanek | amakarov: ah, so you are just talking about upstream changes landing first and using that number? it sounded like you had your own migrations | 17:37 |
amakarov | dstanek, ++ | 17:37 |
dstanek | amakarov: i'm not sure if there is a good way to solve that unless you somehow enforce that migrations names are unique | 17:38 |
*** samueldmq has joined #openstack-keystone | 17:39 | |
*** ChanServ sets mode: +v samueldmq | 17:39 | |
*** jaugustine has quit IRC | 17:40 | |
amakarov | dstanek, well, will it be enough to check if the requested upgrade name is unique? | 17:41 |
samueldmq | dstanek: amakarov: I am no sure you got my last messages (I got disconnected) | 17:41 |
dstanek | amakarov: how would you do that? | 17:42 |
samueldmq | what about having a test class per migration ? so we'd have a base class with migration_number as a property + pre_migration_checks() and post_migration_checks() as abstract methods | 17:42 |
samueldmq | so every subclass override them | 17:42 |
*** jaugustine has joined #openstack-keystone | 17:42 | |
*** jbell8 has joined #openstack-keystone | 17:42 | |
dstanek | amakarov: the only time you really need to change that number is when you rebase right? how often have you had to do that? | 17:42 |
samueldmq | and the super class would do the upgrade_to -1 -> check_pre -> upgrade -> check_post dance | 17:43 |
samueldmq | dstanek: amakarov ^ | 17:43 |
samueldmq | dstanek: ++ yes I agree the motivation is not right to make such change | 17:43 |
openstackgerrit | Merged openstack/keystoneauth: oidc: add tests for plugin loader https://review.openstack.org/333850 | 17:44 |
amakarov | samueldmq, interesting idea, though I fear it will increase complexity (my idea is also questionable :)) | 17:44 |
*** slberger has joined #openstack-keystone | 17:44 | |
amakarov | dstanek, usually about 10 time per patch related to db change | 17:45 |
dstanek | samueldmq: that won't stop him from having to keep updating the patch though right? | 17:45 |
amakarov | times* | 17:45 |
samueldmq | amakarov: dstanek: I think it'd make it clearer (as individual test cases only would need to focus on the checks) | 17:46 |
samueldmq | dstanek: yes you're right, it doesn't solve that "issue" | 17:46 |
samueldmq | amakarov: 10 times ? you get 10 migrations getting merged before your migration patch does ? | 17:46 |
dstanek | amakarov: that's quite a lot. how long does it take for your patches to merge? | 17:46 |
amakarov | samueldmq, dstanek: usually less than a dozen gets merged per cycle | 17:48 |
samueldmq | amakarov: so your migration patch takes more than a cycle to get merged ? | 17:49 |
samueldmq | amakarov: you only need to rebase and update the migration number when a patch merges using the migration number you're currently setting in your patch too | 17:49 |
dstanek | samueldmq: not even for everyone....just when you need to rebase or at the very end | 17:51 |
dstanek | amakarov: if you be the +2s and the only change that needs to be made to merge is bumping the number then the +A would be very easy to get | 17:51 |
samueldmq | dstanek: ++ | 17:52 |
*** tonytan4ever has quit IRC | 17:52 | |
amakarov | dstanek, samueldmq, not only: on every merge conflict I have to remember it too. because after rebase and conflist resolution I have to bump versions or tests will fail | 17:53 |
openstackgerrit | Merged openstack/keystoneauth: oidc: fix OpenID Connect scope option https://review.openstack.org/333261 | 17:55 |
samueldmq | amakarov: if tests fail, you don't need to remember it yourself; failing tests will tell you so | 17:55 |
samueldmq | :) | 17:55 |
amakarov | samueldmq, "Manual sunset" that is :) | 17:57 |
*** tonytan4ever has joined #openstack-keystone | 18:00 | |
stevemar | dstanek dolphm lbragstad is http://specs.openstack.org/openstack/keystone-specs/specs/keystone/newton/credential-encryption.html for storing fernet keys? | 18:02 |
*** jaugustine has quit IRC | 18:04 | |
*** diazjf1 has joined #openstack-keystone | 18:06 | |
*** jaugustine has joined #openstack-keystone | 18:06 | |
*** diazjf has quit IRC | 18:10 | |
*** nkinder has quit IRC | 18:13 | |
*** amoralej|off is now known as amoralej | 18:15 | |
*** samueldmq has quit IRC | 18:16 | |
*** samueldmq has joined #openstack-keystone | 18:19 | |
*** ChanServ sets mode: +v samueldmq | 18:19 | |
raildo | stevemar: ping, needs your shades knowledge here, this is one of the jobs that are breaking with the keystone v3-only env: https://github.com/openstack-infra/project-config/blob/master/jenkins/jobs/shade.yaml#L16, since it explicity execute this job in a keystone v2 env | 18:20 |
raildo | stevemar: shoud talk with infra team to remove this job? | 18:21 |
*** diazjf has joined #openstack-keystone | 18:21 | |
raildo | stevemar: add a new one with v3? | 18:21 |
dstanek | raildo: is that a test for shade itself? | 18:23 |
raildo | dstanek: yes, every shade patch runs this job | 18:24 |
dstanek | raildo: that would be a good question for mordred | 18:24 |
*** diazjf1 has quit IRC | 18:25 | |
raildo | dstanek: as you can see here: https://review.openstack.org/#/c/315713/ this gate-shade-dsvm-functional-keystone2 | 18:25 |
patchbot | raildo: patch 315713 - openstack-infra/shade - Add floating IPs to server dict ourselves | 18:25 |
lbragstad | stevemar no - I don't think so | 18:26 |
*** iurygregory_ has joined #openstack-keystone | 18:26 | |
lbragstad | stevemar that was for the encryption of the totp mechanism | 18:26 |
lbragstad | nonameentername ^ | 18:26 |
dstanek | lbragstad: stevemar: ++ is was TOTP | 18:26 |
*** ayoung has quit IRC | 18:27 | |
*** tonytan4ever has quit IRC | 18:28 | |
*** ddieterly[away] has quit IRC | 18:29 | |
*** rcernin has quit IRC | 18:34 | |
dstanek | ok, now it really is lunch time! | 18:34 |
samueldmq | dstanek: bon apetit | 18:34 |
*** diazjf has quit IRC | 18:37 | |
*** ddieterly has joined #openstack-keystone | 18:37 | |
*** tonytan4ever has joined #openstack-keystone | 18:38 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Closure table for HMT https://review.openstack.org/285521 | 18:40 |
*** amoralej is now known as amoralej|off | 18:40 | |
*** mwheckmann has joined #openstack-keystone | 18:42 | |
mordred | dstanek: I didn't do it | 18:43 |
mordred | raildo: hiya! | 18:43 |
raildo | mordred: :D | 18:43 |
mordred | raildo: so - shade will always want a devstack with keystone v2 enabled | 18:43 |
*** bjornar_ has joined #openstack-keystone | 18:43 | |
mordred | because shade's purpose in life is to make sure that end-users can use openstack no matter what the deployment is - and there are still public clouds out there that do not have keystone v3 | 18:44 |
mordred | so it's important that shade work with v2 | 18:44 |
samueldmq | mordred: ++ | 18:44 |
mordred | it's entirely possible that we'll need to update the job config for that job in some way | 18:44 |
samueldmq | raildo: I think you should just set V2_ENABLED flag (or whatever it's named) to True explicitly for that job | 18:45 |
samueldmq | mordred: ^ | 18:45 |
raildo | mordred: hum... got it. So I think we have to change a little this job. to use this flag as True | 18:45 |
raildo | https://github.com/openstack-infra/project-config/blob/master/jenkins/jobs/nova.yaml#L29 | 18:45 |
raildo | samueldmq: ++ | 18:45 |
nonameentername | I'm currently working on updating encryption for totp | 18:47 |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Allow test migration by module name https://review.openstack.org/334568 | 18:49 |
*** ddieterly is now known as ddieterly[away] | 18:50 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Closure table for HMT https://review.openstack.org/285521 | 18:54 |
*** diazjf has joined #openstack-keystone | 18:57 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Unified delegation model https://review.openstack.org/208488 | 19:00 |
*** slberger1 has joined #openstack-keystone | 19:02 | |
*** rcernin has joined #openstack-keystone | 19:04 | |
*** slberger has quit IRC | 19:04 | |
*** adu has joined #openstack-keystone | 19:12 | |
*** ddieterly[away] is now known as ddieterly | 19:13 | |
openstackgerrit | werner mendizabal proposed openstack/keystone: Support encryption of credentials in Keystone https://review.openstack.org/317169 | 19:16 |
openstackgerrit | Merged openstack/keystonemiddleware: Pop oslo_config_config before doing paste convert https://review.openstack.org/333734 | 19:19 |
openstackgerrit | Merged openstack/keystonemiddleware: Break out the API piece into its own file https://review.openstack.org/334290 | 19:20 |
*** slberger1 has quit IRC | 19:20 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Add failed auth attempts logic to meet PCI-DSS https://review.openstack.org/324029 | 19:23 |
*** pnavarro has joined #openstack-keystone | 19:28 | |
*** jsavak has quit IRC | 19:31 | |
*** jsavak has joined #openstack-keystone | 19:31 | |
*** pnavarro has quit IRC | 19:32 | |
*** slberger has joined #openstack-keystone | 19:35 | |
*** harlowja has quit IRC | 19:36 | |
*** jefrite has quit IRC | 19:37 | |
*** sdake has quit IRC | 19:38 | |
*** sdake has joined #openstack-keystone | 19:40 | |
*** ayoung has joined #openstack-keystone | 19:42 | |
*** ChanServ sets mode: +v ayoung | 19:42 | |
rderose | lbragstad: you there? | 19:49 |
*** fawadkhaliq has quit IRC | 19:51 | |
*** julim has joined #openstack-keystone | 19:51 | |
*** fawadkhaliq has joined #openstack-keystone | 19:51 | |
*** harlowja has joined #openstack-keystone | 19:52 | |
lbragstad | rderose yep | 19:55 |
rderose | lbragstad: just responded to your comment; want to make sure I'm not missing something, but sounds reasonable to me that the user would be disabled. | 19:56 |
*** fawadkhaliq has quit IRC | 19:56 | |
lbragstad | rderose yeah - I think so too | 19:56 |
lbragstad | dstanek dolphm ^ | 19:56 |
rderose | lbragstad: cool | 19:56 |
*** ravelar159 has joined #openstack-keystone | 20:00 | |
*** slberger has quit IRC | 20:01 | |
*** ravelar159 has quit IRC | 20:01 | |
*** slberger has joined #openstack-keystone | 20:03 | |
*** amakarov is now known as amakarov_away | 20:06 | |
*** jsavak has quit IRC | 20:07 | |
*** jsavak has joined #openstack-keystone | 20:07 | |
*** woodster_ has joined #openstack-keystone | 20:08 | |
*** seldenr has joined #openstack-keystone | 20:12 | |
*** jbell8 has quit IRC | 20:14 | |
*** ddieterly is now known as ddieterly[away] | 20:15 | |
*** GB21 has quit IRC | 20:16 | |
*** samueldmq has quit IRC | 20:17 | |
stevemar | henrynash: oof https://bugs.launchpad.net/keystone/+bug/1596500 is ugly | 20:18 |
openstack | Launchpad bug 1596500 in OpenStack Identity (keystone) "Passwords created_at attribute could remain unset during rolling upgrade" [Undecided,New] - Assigned to Henry Nash (henry-nash) | 20:18 |
*** sdake_ has joined #openstack-keystone | 20:19 | |
stevemar | henrynash: also http://lists.openstack.org/pipermail/openstack-dev/2016-June/098255.html eww | 20:20 |
*** sdake has quit IRC | 20:22 | |
*** ravelar159 has joined #openstack-keystone | 20:22 | |
*** ddieterly[away] is now known as ddieterly | 20:22 | |
*** ravelar_159 has joined #openstack-keystone | 20:27 | |
*** ravelar159 has quit IRC | 20:28 | |
*** adu has quit IRC | 20:32 | |
*** jsavak has quit IRC | 20:32 | |
*** jsavak has joined #openstack-keystone | 20:33 | |
*** ravelar_159 has quit IRC | 20:34 | |
*** GB21 has joined #openstack-keystone | 20:34 | |
*** fawadkhaliq has joined #openstack-keystone | 20:39 | |
*** fawadkhaliq has quit IRC | 20:39 | |
*** fawadkhaliq has joined #openstack-keystone | 20:40 | |
*** slberger has quit IRC | 20:41 | |
*** ravelar159 has joined #openstack-keystone | 20:41 | |
*** slberger has joined #openstack-keystone | 20:42 | |
*** ravelar159 has quit IRC | 20:44 | |
*** fawadkhaliq has quit IRC | 20:45 | |
*** sdake has joined #openstack-keystone | 20:49 | |
dstanek | lbragstad: ? | 20:50 |
*** jlk has quit IRC | 20:51 | |
stevemar | lbragstad: give https://review.openstack.org/#/c/334060/ another look please | 20:51 |
patchbot | stevemar: patch 334060 - keystone - Adds a backend test fixture | 20:51 |
dstanek | stevemar: woot. it passed! | 20:52 |
*** jlk has joined #openstack-keystone | 20:52 | |
*** edmondsw has quit IRC | 20:52 | |
*** jlk has quit IRC | 20:52 | |
*** jlk has joined #openstack-keystone | 20:52 | |
*** sdake_ has quit IRC | 20:53 | |
stevemar | dstanek: whats your response here: https://review.openstack.org/#/c/334061/4/keystone/tests/unit/test_backend_ldap.py | 20:53 |
patchbot | stevemar: patch 334061 - keystone - Group test_backend_ldap skips for readability | 20:53 |
dstanek | lbragstad: i'm looking at some of the tests in the patch that depends on that one | 20:53 |
dstanek | stevemar: ^ | 20:53 |
dstanek | it's possible that they can be deleted, but many of them appear to only be skipped in certain setups | 20:53 |
stevemar | dstanek: otay | 20:54 |
*** catintheroof has joined #openstack-keystone | 20:55 | |
*** diazjf has quit IRC | 20:58 | |
dstanek | stevemar: lbragstad: commented and looking to see if another patch is necessary | 20:58 |
dstanek | unwinding those tests into logic patches was hard enough :-( | 20:59 |
lbragstad | dstanek makes sense | 21:00 |
*** mvk_ has joined #openstack-keystone | 21:01 | |
*** fawadkhaliq has joined #openstack-keystone | 21:01 | |
*** mkrcmari__ has joined #openstack-keystone | 21:05 | |
*** raildo is now known as raildo-afk | 21:07 | |
*** mvk has joined #openstack-keystone | 21:07 | |
*** diazjf has joined #openstack-keystone | 21:08 | |
*** mvk_ has quit IRC | 21:09 | |
*** mkrcmari__ has quit IRC | 21:10 | |
*** sdake_ has joined #openstack-keystone | 21:12 | |
*** sdake has quit IRC | 21:13 | |
*** rderose has quit IRC | 21:15 | |
*** sdake has joined #openstack-keystone | 21:16 | |
*** sdake_ has quit IRC | 21:17 | |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Improve keystone.conf [assignment] documentation https://review.openstack.org/334667 | 21:17 |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Improve keystone.conf [auth] documentation https://review.openstack.org/334668 | 21:17 |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Improve keystone.conf [DEFAULT] documentation https://review.openstack.org/334669 | 21:18 |
*** fawadkhaliq has quit IRC | 21:24 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Allow id string validation to be configurable https://review.openstack.org/334673 | 21:24 |
stevemar | lbragstad: i love that ^ <3 | 21:25 |
*** mvk_ has joined #openstack-keystone | 21:35 | |
*** permalac_ has joined #openstack-keystone | 21:35 | |
*** pauloewerton has quit IRC | 21:35 | |
*** permalac has quit IRC | 21:36 | |
stevemar | dolphm: s/entrypoint/Entry point/g | 21:38 |
*** mvk has quit IRC | 21:38 | |
*** fawadkhaliq has joined #openstack-keystone | 21:39 | |
*** mkrcmari__ has joined #openstack-keystone | 21:41 | |
*** gagehugo has quit IRC | 21:43 | |
*** mkrcmari__ has quit IRC | 21:43 | |
*** fawadkhaliq has quit IRC | 21:43 | |
*** mvk has joined #openstack-keystone | 21:44 | |
*** jaugustine has quit IRC | 21:44 | |
openstackgerrit | Merged openstack/keystonemiddleware: Extract a common notifier pattern https://review.openstack.org/334291 | 21:44 |
openstackgerrit | Merged openstack/keystonemiddleware: Refactor create_event onto the api object. https://review.openstack.org/334292 | 21:44 |
*** mvk_ has quit IRC | 21:44 | |
openstackgerrit | Merged openstack/keystonemiddleware: Refactor audit api tests into their own file https://review.openstack.org/334293 | 21:44 |
*** ddieterly is now known as ddieterly[away] | 21:45 | |
*** fawadkhaliq has joined #openstack-keystone | 21:45 | |
*** fawadkhaliq has quit IRC | 21:49 | |
*** bjornar_ has quit IRC | 21:52 | |
*** ddieterly[away] is now known as ddieterly | 21:53 | |
*** catintheroof has quit IRC | 21:55 | |
*** ddieterly is now known as ddieterly[away] | 21:58 | |
openstackgerrit | Merged openstack/keystone: Adds a backend test fixture https://review.openstack.org/334060 | 22:01 |
*** diazjf has quit IRC | 22:03 | |
*** spzala has quit IRC | 22:05 | |
*** ddieterly[away] is now known as ddieterly | 22:06 | |
*** spzala has joined #openstack-keystone | 22:07 | |
*** jsavak has quit IRC | 22:08 | |
*** fawadkhaliq has joined #openstack-keystone | 22:10 | |
*** slberger has left #openstack-keystone | 22:11 | |
*** spzala has quit IRC | 22:12 | |
*** fawadkhaliq has quit IRC | 22:14 | |
*** raddaoui has quit IRC | 22:17 | |
*** jamielennox is now known as jamielennox|away | 22:21 | |
*** ddieterly has quit IRC | 22:27 | |
*** ametts has quit IRC | 22:28 | |
*** spzala has joined #openstack-keystone | 22:31 | |
ayoung | Someone went to town on the troubleshooting doc | 22:33 |
ayoung | now we need to figure out how to organize it | 22:33 |
*** spzala has quit IRC | 22:36 | |
*** ametts has joined #openstack-keystone | 22:41 | |
*** KevinE has quit IRC | 22:43 | |
*** darosale has quit IRC | 22:43 | |
*** BjoernT has quit IRC | 22:43 | |
*** julim has quit IRC | 22:46 | |
*** ametts has quit IRC | 22:48 | |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Improve keystone.conf [credential] documentation https://review.openstack.org/334702 | 22:51 |
*** dan_nguyen has joined #openstack-keystone | 22:57 | |
*** mvk_ has joined #openstack-keystone | 22:58 | |
*** tonytan4ever has quit IRC | 23:02 | |
*** mvk has quit IRC | 23:02 | |
*** gordc has quit IRC | 23:16 | |
*** walharthi has joined #openstack-keystone | 23:21 | |
*** raddaoui has joined #openstack-keystone | 23:23 | |
*** walharthi has quit IRC | 23:26 | |
*** dan_nguyen has quit IRC | 23:27 | |
*** bj0rnar has quit IRC | 23:28 | |
*** stian_ has quit IRC | 23:29 | |
*** dan_nguyen has joined #openstack-keystone | 23:30 | |
*** fawadkhaliq has joined #openstack-keystone | 23:30 | |
mwheckmann | david-lyle, jamielennox: I'm trying to use Horizon with v3 cloud sample Keystone policy.json so that I can have a domain admin user. Problem is that I get an error on login: 'Token' object has no attribute '__getitem__'. It seems like the policy enforcement code that Horizon uses is looking for 'is_admin_project' to be set in the token. I've configured it in my Keystone conf and applied some | 23:31 |
mwheckmann | of the recent patches to set the value even if we *aren't* in the admin much project, but to no avail.. is this supposed to be working? | 23:31 |
*** dan_nguyen has left #openstack-keystone | 23:31 | |
*** fawadkhaliq has quit IRC | 23:35 | |
*** pgbridge has quit IRC | 23:35 | |
*** bj0rnar has joined #openstack-keystone | 23:37 | |
*** mwheckmann has quit IRC | 23:37 | |
*** stian_ has joined #openstack-keystone | 23:38 | |
*** jamielennox|away is now known as jamielennox | 23:43 | |
*** timcline has quit IRC | 23:48 | |
*** timcline has joined #openstack-keystone | 23:48 | |
openstackgerrit | Sam Leong proposed openstack/keystoneauth: Auth plugin for X.509 tokenless authentication https://review.openstack.org/283905 | 23:49 |
*** seldenr has quit IRC | 23:50 | |
*** timcline has quit IRC | 23:53 | |
*** rderose has joined #openstack-keystone | 23:56 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!