*** jamielennox|away is now known as jamielennox | 00:01 | |
*** ravelar has quit IRC | 00:02 | |
*** sdake has quit IRC | 00:10 | |
openstackgerrit | Merged openstack/keystone: Clean up the introductory text in the docs https://review.openstack.org/350639 | 00:11 |
---|---|---|
*** ravelar has joined #openstack-keystone | 00:15 | |
*** ravelar has quit IRC | 00:20 | |
*** tonytan4ever has joined #openstack-keystone | 00:33 | |
*** esp has quit IRC | 00:36 | |
*** tonytan4ever has quit IRC | 00:38 | |
*** haplo37__ has quit IRC | 00:40 | |
*** ravelar has joined #openstack-keystone | 00:44 | |
*** ravelar has quit IRC | 00:50 | |
*** code-R has joined #openstack-keystone | 00:53 | |
*** code-R_ has joined #openstack-keystone | 00:54 | |
*** code-R has quit IRC | 00:57 | |
*** esp has joined #openstack-keystone | 01:25 | |
*** esp has quit IRC | 01:33 | |
*** jamielennox is now known as jamielennox|away | 01:34 | |
*** tqtran_ has quit IRC | 01:42 | |
*** ravelar has joined #openstack-keystone | 01:48 | |
*** davechen has joined #openstack-keystone | 01:51 | |
*** ravelar has quit IRC | 01:53 | |
*** akrzos has quit IRC | 01:55 | |
*** akrzos has joined #openstack-keystone | 01:55 | |
*** spzala has joined #openstack-keystone | 01:55 | |
*** EinstCrazy has joined #openstack-keystone | 01:55 | |
*** dmellado has quit IRC | 01:57 | |
*** diazjf has joined #openstack-keystone | 01:57 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Minimum password age requirements https://review.openstack.org/343314 | 02:00 |
*** spzala has quit IRC | 02:00 | |
*** dmellado has joined #openstack-keystone | 02:02 | |
*** richm has quit IRC | 02:06 | |
stevemar | ahhh so much to catch up on | 02:15 |
stevemar | lbragstad: whats up with the perf bot? | 02:15 |
lbragstad | stevemar ? | 02:15 |
stevemar | lbragstad: i left a comment on here: https://review.openstack.org/#/c/309146/ "check performance" but nothing happened | 02:15 |
patchbot | stevemar: patch 309146 - keystone - Pre-cache new tokens | 02:15 |
lbragstad | oooo | 02:15 |
lbragstad | one sec - for some reason if you leave an event stream listening to gerrit events over a long period of time it takes a while | 02:16 |
lbragstad | stevemar i'll rekick it for you | 02:16 |
stevemar | lbragstad: danke | 02:17 |
*** dave-mccowan has quit IRC | 02:19 | |
stevemar | mordred: unicode issues with your patch :( https://review.openstack.org/#/c/344943/6/keystoneauth1/fixture/serializer.py | 02:25 |
patchbot | stevemar: patch 344943 - keystoneauth - Add tests for YamlJsonSerializer | 02:25 |
*** markvoelker has joined #openstack-keystone | 02:26 | |
*** ravelar has joined #openstack-keystone | 02:29 | |
*** dkehn_ has quit IRC | 02:31 | |
*** diazjf has quit IRC | 02:32 | |
*** ddieterly has joined #openstack-keystone | 02:33 | |
*** ravelar has quit IRC | 02:34 | |
stevemar | lbragstad: does perf bot setup memcache? | 02:34 |
*** browne1 has quit IRC | 02:34 | |
lbragstad | stevemar for some things yes - but it's up to whatever openstack-ansible decides to do | 02:35 |
lbragstad | or how osa decides to deploy keystone | 02:35 |
stevemar | hmm | 02:35 |
stevemar | lbragstad: i'm surprised by the validation results of https://review.openstack.org/#/c/309146/ | 02:35 |
patchbot | stevemar: patch 309146 - keystone - Pre-cache new tokens | 02:35 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/350888 | 02:35 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystoneauth: Updated from global requirements https://review.openstack.org/350889 | 02:35 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystonemiddleware: Updated from global requirements https://review.openstack.org/350890 | 02:35 |
stevemar | token creation definitely took longer | 02:36 |
*** ddieterly has quit IRC | 02:36 | |
stevemar | but validation should have had a noticable difference | 02:36 |
*** jamielennox|away is now known as jamielennox | 02:36 | |
lbragstad | interesting | 02:38 |
lbragstad | trying again just to make sure it wasn't a fluke | 02:39 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/oslo.policy: Updated from global requirements https://review.openstack.org/350913 | 02:40 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/pycadf: Updated from global requirements https://review.openstack.org/350921 | 02:41 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements https://review.openstack.org/350922 | 02:41 |
*** dkehn_ has joined #openstack-keystone | 02:44 | |
*** ravelar has joined #openstack-keystone | 02:50 | |
*** itlinux has quit IRC | 02:54 | |
*** itlinux has joined #openstack-keystone | 02:56 | |
*** ravelar has quit IRC | 02:56 | |
*** ravelar has joined #openstack-keystone | 03:01 | |
*** guoshan has joined #openstack-keystone | 03:03 | |
*** guoshan has quit IRC | 03:04 | |
*** sdake has joined #openstack-keystone | 03:04 | |
*** ravelar has quit IRC | 03:06 | |
*** browne has joined #openstack-keystone | 03:11 | |
*** sdake has quit IRC | 03:23 | |
*** browne has quit IRC | 03:23 | |
*** spedione|AWAY is now known as spedione | 03:24 | |
*** spedione is now known as spedione|AWAY | 03:27 | |
*** afred312_ has quit IRC | 03:29 | |
*** jrist has joined #openstack-keystone | 03:34 | |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Refactor audit tests to use create_middleware https://review.openstack.org/336971 | 03:43 |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Use oslo_messaging conf fixture https://review.openstack.org/336970 | 03:43 |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Extract oslo_messaging specific audit tests https://review.openstack.org/334296 | 03:43 |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Return and use an app wherever possible https://review.openstack.org/336972 | 03:43 |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Use the mocking fixture in notifier tests https://review.openstack.org/334295 | 03:44 |
*** markvoelker has quit IRC | 03:46 | |
*** sdake has joined #openstack-keystone | 03:50 | |
*** ayoung has quit IRC | 04:08 | |
openstackgerrit | Merged openstack/keystone: Retry revocation on MySQL deadlock https://review.openstack.org/344924 | 04:13 |
*** nishaYadav has joined #openstack-keystone | 04:14 | |
*** julim has quit IRC | 04:16 | |
*** roxanaghe has joined #openstack-keystone | 04:18 | |
*** nisha_ has joined #openstack-keystone | 04:19 | |
*** nishaYadav has quit IRC | 04:22 | |
*** markvoelker has joined #openstack-keystone | 04:22 | |
openstackgerrit | Merged openstack/keystone: Add schema validation to update user v2 https://review.openstack.org/345022 | 04:26 |
*** markvoelker has quit IRC | 04:26 | |
openstackgerrit | Merged openstack/keystone: Add debug logging for RevokeEvent deserialize problem https://review.openstack.org/350804 | 04:27 |
*** links has joined #openstack-keystone | 04:28 | |
*** sdake has quit IRC | 04:37 | |
*** ravelar has joined #openstack-keystone | 04:39 | |
*** tqtran has joined #openstack-keystone | 04:42 | |
*** ravelar has quit IRC | 04:45 | |
*** tqtran has quit IRC | 04:46 | |
*** nisha__ has joined #openstack-keystone | 04:49 | |
*** nisha_ has quit IRC | 04:52 | |
*** afred312 has joined #openstack-keystone | 04:59 | |
*** afred312 has quit IRC | 05:04 | |
*** jraju has joined #openstack-keystone | 05:04 | |
*** links has quit IRC | 05:06 | |
*** rcernin has joined #openstack-keystone | 05:16 | |
*** markvoelker has joined #openstack-keystone | 05:16 | |
*** davechen has quit IRC | 05:20 | |
*** markvoelker has quit IRC | 05:22 | |
*** roxanaghe has quit IRC | 05:26 | |
openstackgerrit | Merged openstack/python-keystoneclient: Improve docs for v3 roles https://review.openstack.org/334546 | 05:27 |
*** haplo37__ has joined #openstack-keystone | 05:34 | |
*** esp has joined #openstack-keystone | 05:35 | |
openstackgerrit | Merged openstack/keystoneauth: Updated from global requirements https://review.openstack.org/350889 | 05:41 |
*** haplo37__ has quit IRC | 05:42 | |
openstackgerrit | Nisha Yadav proposed openstack/python-keystoneclient: Follow up patch for Improve docs for v3 roles https://review.openstack.org/350990 | 05:44 |
*** roxanaghe has joined #openstack-keystone | 05:45 | |
*** adriant has quit IRC | 05:49 | |
*** roxanaghe has quit IRC | 05:50 | |
*** esp has quit IRC | 05:51 | |
openstackgerrit | Merged openstack/keystonemiddleware: Updated from global requirements https://review.openstack.org/350890 | 05:52 |
*** maestropandy has joined #openstack-keystone | 05:52 | |
openstackgerrit | Nisha Yadav proposed openstack/python-keystoneclient: Add role functional tests https://review.openstack.org/335118 | 05:56 |
*** ravelar has joined #openstack-keystone | 05:57 | |
*** afred312 has joined #openstack-keystone | 06:00 | |
*** ravelar has quit IRC | 06:01 | |
*** afred312 has quit IRC | 06:06 | |
openstackgerrit | Merged openstack/pycadf: Updated from global requirements https://review.openstack.org/350921 | 06:08 |
openstackgerrit | Merged openstack/keystone: Updated from global requirements https://review.openstack.org/350888 | 06:09 |
*** pcaruana has joined #openstack-keystone | 06:10 | |
*** itisha has quit IRC | 06:10 | |
openstackgerrit | Merged openstack/python-keystoneclient: Updated from global requirements https://review.openstack.org/350922 | 06:11 |
*** code-R_ has quit IRC | 06:11 | |
*** code-R has joined #openstack-keystone | 06:12 | |
*** jaosorior has joined #openstack-keystone | 06:20 | |
*** nishaYadav has joined #openstack-keystone | 06:26 | |
*** nisha__ has quit IRC | 06:28 | |
*** mfisch has quit IRC | 06:29 | |
*** belmoreira has joined #openstack-keystone | 06:30 | |
*** LamT has quit IRC | 06:31 | |
*** mfisch has joined #openstack-keystone | 06:34 | |
*** mfisch has quit IRC | 06:34 | |
*** mfisch has joined #openstack-keystone | 06:34 | |
*** tqtran has joined #openstack-keystone | 06:42 | |
*** roxanaghe has joined #openstack-keystone | 06:46 | |
*** tqtran has quit IRC | 06:47 | |
*** jed56 has joined #openstack-keystone | 06:47 | |
openstackgerrit | Merged openstack/oslo.policy: Updated from global requirements https://review.openstack.org/350913 | 06:48 |
*** roxanaghe has quit IRC | 06:50 | |
*** tesseract- has joined #openstack-keystone | 06:53 | |
*** permalac has quit IRC | 06:54 | |
openstackgerrit | henry-nash proposed openstack/keystone: Add the migration phase status table https://review.openstack.org/349703 | 06:55 |
*** spzala has joined #openstack-keystone | 06:56 | |
openstackgerrit | henry-nash proposed openstack/keystone: Add support for rolling upgrades to keystone-manage https://review.openstack.org/349716 | 06:56 |
openstackgerrit | Nisha Yadav proposed openstack/python-keystoneclient: Improve docs for v3 credentials https://review.openstack.org/348506 | 06:57 |
*** spzala has quit IRC | 07:00 | |
openstackgerrit | henry-nash proposed openstack/keystone: Add contract migrations to keystone-manage https://review.openstack.org/349939 | 07:02 |
*** afred312 has joined #openstack-keystone | 07:02 | |
*** code-R has quit IRC | 07:05 | |
*** code-R has joined #openstack-keystone | 07:05 | |
*** afred312 has quit IRC | 07:08 | |
openstackgerrit | henry-nash proposed openstack/keystone: Add contract migrations to keystone-manage https://review.openstack.org/349939 | 07:08 |
*** pnavarro has joined #openstack-keystone | 07:08 | |
*** jpena|off is now known as jpena | 07:13 | |
*** code-R_ has joined #openstack-keystone | 07:17 | |
*** code-R has quit IRC | 07:20 | |
*** openstackgerrit has quit IRC | 07:33 | |
*** openstackgerrit has joined #openstack-keystone | 07:33 | |
*** pnavarro has quit IRC | 07:36 | |
*** pnavarro has joined #openstack-keystone | 07:38 | |
*** mvk has quit IRC | 07:53 | |
*** code-R_ has quit IRC | 07:56 | |
*** markvoelker has joined #openstack-keystone | 07:58 | |
*** zzzeek has quit IRC | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:01 | |
*** afred312 has joined #openstack-keystone | 08:03 | |
*** markvoelker has quit IRC | 08:03 | |
*** pnavarro has quit IRC | 08:07 | |
*** afred312 has quit IRC | 08:08 | |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c https://review.openstack.org/318435 | 08:10 |
*** jaosorior has quit IRC | 08:13 | |
*** jaosorior has joined #openstack-keystone | 08:13 | |
*** timonwong has joined #openstack-keystone | 08:14 | |
*** nishaYadav has quit IRC | 08:22 | |
*** nishaYadav has joined #openstack-keystone | 08:23 | |
openstackgerrit | liyanhang proposed openstack/keystone: Deleted file: etc/keystone.conf.sample https://review.openstack.org/351060 | 08:25 |
openstackgerrit | Jiong Liu proposed openstack/keystone: Delete etc/keystone.conf.sample https://review.openstack.org/351060 | 08:28 |
*** roxanaghe has joined #openstack-keystone | 08:34 | |
*** roxanaghe has quit IRC | 08:38 | |
*** nisha_ has joined #openstack-keystone | 08:41 | |
*** nishaYadav has quit IRC | 08:44 | |
*** tqtran has joined #openstack-keystone | 08:44 | |
*** tqtran has quit IRC | 08:49 | |
*** danpawlik has joined #openstack-keystone | 08:49 | |
*** markvoelker has joined #openstack-keystone | 08:53 | |
*** gb21 has joined #openstack-keystone | 08:55 | |
*** markvoelker has quit IRC | 08:57 | |
*** afred312 has joined #openstack-keystone | 09:04 | |
*** afred312 has quit IRC | 09:08 | |
*** dikonoor has joined #openstack-keystone | 09:14 | |
*** xek_ has joined #openstack-keystone | 09:23 | |
*** xek has quit IRC | 09:24 | |
*** nk2527_ has joined #openstack-keystone | 09:26 | |
*** gagehugo has quit IRC | 09:28 | |
*** jaugustine has quit IRC | 09:28 | |
*** nk2527 has quit IRC | 09:29 | |
*** gb21 has quit IRC | 09:29 | |
*** guoshan has joined #openstack-keystone | 09:32 | |
*** nisha__ has joined #openstack-keystone | 09:37 | |
*** nisha_ has quit IRC | 09:40 | |
*** guoshan has quit IRC | 09:44 | |
*** guoshan has joined #openstack-keystone | 09:45 | |
*** mvk has joined #openstack-keystone | 09:45 | |
*** markvoelker has joined #openstack-keystone | 09:47 | |
*** gagehugo has joined #openstack-keystone | 09:49 | |
*** permalac has joined #openstack-keystone | 09:49 | |
*** nisha__ has quit IRC | 09:52 | |
*** markvoelker has quit IRC | 09:52 | |
*** afred312 has joined #openstack-keystone | 10:04 | |
*** afred312 has quit IRC | 10:09 | |
*** pnavarro has joined #openstack-keystone | 10:15 | |
*** roxanaghe has joined #openstack-keystone | 10:22 | |
*** roxanaghe has quit IRC | 10:26 | |
*** chlong has quit IRC | 10:28 | |
samueldmq | morning keystone | 10:29 |
marekd | samueldmq: hi, Samuel | 10:30 |
samueldmq | marekd: hey | 10:30 |
marekd | samueldmq: how are you ? | 10:30 |
samueldmq | marekd: doing well, thanks. how about you? | 10:30 |
marekd | samueldmq: not bad, i guess | 10:30 |
*** gb21 has joined #openstack-keystone | 10:32 | |
*** timonwong has quit IRC | 10:33 | |
*** davechen has joined #openstack-keystone | 10:38 | |
*** guoshan has quit IRC | 10:40 | |
*** gb21 is now known as GB21 | 10:41 | |
*** markvoelker has joined #openstack-keystone | 10:41 | |
*** chlong has joined #openstack-keystone | 10:41 | |
*** markvoelker has quit IRC | 10:46 | |
*** EinstCrazy has quit IRC | 10:46 | |
openstackgerrit | Béla Vancsics proposed openstack/keystone: Use more specific asserts in tests https://review.openstack.org/351118 | 10:48 |
*** spzala has joined #openstack-keystone | 10:57 | |
*** davechen has left #openstack-keystone | 10:57 | |
*** spzala has quit IRC | 11:01 | |
*** GB21 has quit IRC | 11:01 | |
*** GB21 has joined #openstack-keystone | 11:02 | |
*** afred312 has joined #openstack-keystone | 11:05 | |
dstanek | morning | 11:07 |
*** afred312 has quit IRC | 11:10 | |
samueldmq | dstanek: morning | 11:14 |
* breton sighs | 11:22 | |
breton | morning, keystone | 11:22 |
dstanek | breton: what's up? | 11:23 |
breton | dstanek: keystoneauth raises 404. People see word `keystone` in keystoneauth and start blaming keystone. | 11:25 |
*** chlong has quit IRC | 11:27 | |
dstanek | :-) | 11:27 |
*** chlong has joined #openstack-keystone | 11:28 | |
*** ericksonsantos has quit IRC | 11:34 | |
*** raildo has quit IRC | 11:34 | |
*** markvoelker has joined #openstack-keystone | 11:35 | |
*** gordc has joined #openstack-keystone | 11:39 | |
*** markvoelker has quit IRC | 11:39 | |
*** xek__ has joined #openstack-keystone | 11:41 | |
*** xek_ has quit IRC | 11:42 | |
rderose | dstanek: can I show the locale date/time? | 11:45 |
rderose | dstanek: because I don't think showing the utc would be appropriate | 11:46 |
dstanek | rderose: i'm not sure how accurate that would be, but i would hope that the request header includes the user's locale info | 11:48 |
rderose | dstanek: hmm... | 11:48 |
dstanek | it was just a thought. | 11:48 |
dstanek | even 'try again in X days' would be better for the user experience, although once you get down to the wire it would have to be more precise | 11:49 |
rderose | dstanek: yeah, but try again in x days, I would still need to know their local time | 11:50 |
*** jpena is now known as jpena|lunch | 11:51 | |
rderose | dstanek: but I'll give it some thought | 11:51 |
rderose | dstanek: thx | 11:51 |
*** dave-mccowan has joined #openstack-keystone | 11:55 | |
dstanek | rderose: why do you need their local for that? you don't use their locale to calculate days | 11:56 |
rderose | dstanek: well depending on local time, you could be off by a day | 12:02 |
* dolphm is trying to figure out how best to install skype on linux... | 12:05 | |
lbragstad | dolphm no luck? | 12:05 |
dstanek | rderose: not if the message is 'try again in two days' | 12:05 |
*** markvoelker has joined #openstack-keystone | 12:05 | |
*** afred312 has joined #openstack-keystone | 12:06 | |
dstanek | dolphm: why would you do that to yourself? | 12:06 |
dolphm | dstanek: rderose told me to | 12:06 |
dstanek | i haven't used skype since M$ bought it | 12:07 |
dolphm | wow, they only make a 32 bit version? | 12:07 |
dolphm | dstanek: i haven't either | 12:07 |
dolphm | rderose: this could take a minute http://cdn.pasteraw.com/e0t2v29c58yu63x0t4lxlg6ohpfwpm6 | 12:07 |
*** roxanaghe has joined #openstack-keystone | 12:10 | |
openstackgerrit | Monty Taylor proposed openstack/keystoneauth: Add tests for YamlJsonSerializer https://review.openstack.org/344943 | 12:10 |
mordred | stevemar: ^^ sorry for the test fail yesterday | 12:10 |
*** afred312 has quit IRC | 12:11 | |
mordred | stevemar: it was an incomplete copy over of the fixes I'd made in the shade repo. I'm rather a dummy | 12:11 |
openstackgerrit | Merged openstack/python-keystoneclient: Follow up patch for Improve docs for v3 roles https://review.openstack.org/350990 | 12:12 |
*** timonwong has joined #openstack-keystone | 12:13 | |
*** timonwong has quit IRC | 12:13 | |
*** roxanaghe has quit IRC | 12:15 | |
mordred | dstanek: great question - it gave me an idea for how to make that better | 12:18 |
breton | i have an idea for deprecation v2.0 | 12:21 |
breton | lets hide all v2.0-related docs. | 12:21 |
mordred | ++ | 12:22 |
mordred | I've been doing that for deprecated things in shade, which is a weird concept since shade doens't ever remove things ... but I absolutely remove references to the things that are old and ugly from the docs | 12:23 |
dstanek | mordred: nice | 12:23 |
openstackgerrit | Monty Taylor proposed openstack/keystoneauth: Add tests for YamlJsonSerializer https://review.openstack.org/344943 | 12:25 |
mordred | dstanek: there you go - that should be a bit nicer :) | 12:25 |
*** GB21 has quit IRC | 12:30 | |
*** tqtran has joined #openstack-keystone | 12:45 | |
*** raildo has joined #openstack-keystone | 12:48 | |
*** tqtran has quit IRC | 12:50 | |
*** pauloewerton has joined #openstack-keystone | 12:51 | |
*** wanghua has joined #openstack-keystone | 12:53 | |
*** jsavak has joined #openstack-keystone | 12:56 | |
*** jpena|lunch is now known as jpena | 12:58 | |
*** afred312 has joined #openstack-keystone | 13:07 | |
*** spzala has joined #openstack-keystone | 13:09 | |
*** spzala has quit IRC | 13:09 | |
*** spzala has joined #openstack-keystone | 13:09 | |
*** sdake has joined #openstack-keystone | 13:11 | |
*** afred312 has quit IRC | 13:11 | |
*** markvoelker has quit IRC | 13:13 | |
*** sdake has quit IRC | 13:24 | |
bknudson | we could use <blink> for the v2 pages. | 13:30 |
*** julim has joined #openstack-keystone | 13:31 | |
*** amakarov_away is now known as amakarov | 13:32 | |
dims | bknudson : LOL | 13:36 |
dstanek | bknudson: ++ | 13:38 |
dstanek | do browsers still support that? | 13:39 |
*** ametts has joined #openstack-keystone | 13:45 | |
*** jraju has quit IRC | 13:46 | |
*** ddieterly has joined #openstack-keystone | 13:50 | |
*** markvoelker has joined #openstack-keystone | 13:51 | |
*** richm has joined #openstack-keystone | 13:51 | |
*** sdake has joined #openstack-keystone | 13:54 | |
*** ddieterly has quit IRC | 14:01 | |
*** ddieterly has joined #openstack-keystone | 14:01 | |
*** maestropandy has left #openstack-keystone | 14:01 | |
*** belmoreira has quit IRC | 14:02 | |
openstackgerrit | liyanhang proposed openstack/keystone: Update etc/keystone.conf.sample https://review.openstack.org/351060 | 14:02 |
*** edmondsw has quit IRC | 14:02 | |
*** afred312 has joined #openstack-keystone | 14:07 | |
*** code-R has joined #openstack-keystone | 14:09 | |
*** code-R_ has joined #openstack-keystone | 14:11 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Minimum password age requirements https://review.openstack.org/343314 | 14:11 |
*** afred312 has quit IRC | 14:12 | |
*** jsavak has quit IRC | 14:14 | |
*** code-R has quit IRC | 14:14 | |
bknudson | http://www.daedtech.com/human-cost-tech-debt/?utm_content=buffer1e5b5&utm_medium=social&utm_source=twitter.com&utm_campaign=buffer | 14:17 |
*** jaosorior has quit IRC | 14:17 | |
stevemar | rderose: all the v2 APIs :P | 14:19 |
rderose | stevemar: :) | 14:19 |
rderose | stevemar: are you talking about password_expires_at? | 14:20 |
stevemar | rderose: oh jeez, i meant to reply to breton | 14:23 |
stevemar | late start, haven't slept in that much in a while | 14:23 |
stevemar | rderose: got your email | 14:23 |
*** EinstCrazy has joined #openstack-keystone | 14:23 | |
rderose | stevemar: too early start for me, was up at 5 AM | 14:23 |
rderose | stevemar: need to iron this out with dolph and henry | 14:24 |
stevemar | rderose: the read-only mode detracting the rolling upgrade train was the first thing that crossed my mind | 14:24 |
rderose | stevemar: :) | 14:24 |
rderose | yep | 14:24 |
*** afred312 has joined #openstack-keystone | 14:24 | |
dolphm | yeah, i need to go get coffee still | 14:24 |
stevemar | if switching between R/O and R/W, then we'll need to restart keystone, which i guess is OK if you're using a balancer or haproxy | 14:25 |
rderose | stevemar: true | 14:25 |
*** ravelar has joined #openstack-keystone | 14:27 | |
*** diazjf has joined #openstack-keystone | 14:30 | |
*** catintheroof has joined #openstack-keystone | 14:32 | |
openstackgerrit | David Stanek proposed openstack/keystone: Update etc/keystone.conf.sample https://review.openstack.org/351060 | 14:37 |
openstackgerrit | David Stanek proposed openstack/keystone: Make hash_algorithms order deterministic https://review.openstack.org/351222 | 14:37 |
*** dikonoor has quit IRC | 14:40 | |
*** code-R_ has quit IRC | 14:41 | |
dstanek | stevemar: for not sleeping you are certainly hitting the reviews quickly! | 14:46 |
stevemar | dstanek: ba dum tsst | 14:46 |
dstanek | stevemar: baby keeping you up? | 14:47 |
*** diazjf has quit IRC | 14:52 | |
stevemar | dstanek: some nights yes, some nights no | 14:52 |
stevemar | gagehugo: rebase this bad boy https://review.openstack.org/#/c/348531/ and let's get the BP completed :O | 14:52 |
patchbot | stevemar: patch 348531 - keystone - Add schema validation to create user v2 | 14:52 |
*** yangyapeng has joined #openstack-keystone | 14:53 | |
stevemar | got a nice LDAP bug *with a patch from the author* up for grabs if someone is interested?! https://bugs.launchpad.net/keystone/+bug/1609653 :) | 14:54 |
openstack | Launchpad bug 1609653 in OpenStack Identity (keystone) "keystone ldap does not support Hebrew" [Undecided,New] | 14:54 |
*** yangyapeng has left #openstack-keystone | 14:54 | |
*** edmondsw has joined #openstack-keystone | 14:54 | |
*** code-R has joined #openstack-keystone | 14:55 | |
dstanek | stevemar: i guess that's better than all nights | 14:56 |
*** code-R_ has joined #openstack-keystone | 14:57 | |
gagehugo | stevemar: currently commenting on the minproperties and it will be up | 14:57 |
*** code-R has quit IRC | 15:00 | |
*** gagehugo_ has joined #openstack-keystone | 15:01 | |
*** jaugustine has joined #openstack-keystone | 15:04 | |
*** gagehugo_ has quit IRC | 15:04 | |
*** pgbridge has quit IRC | 15:05 | |
gagehugo | It's up, not sure why the bot didnt catch it | 15:05 |
stevemar | gagehugo: thank you sir | 15:06 |
gagehugo | Gage Hugo proposed openstack/keystone: | 15:07 |
gagehugo | Add schema validation to create user v2 | 15:07 |
gagehugo | https://review.openstack.org/#/c/348531 | 15:07 |
patchbot | gagehugo: patch 348531 - keystone - Add schema validation to create user v2 | 15:07 |
gagehugo | good enough | 15:07 |
gagehugo | I can remove the date if you want, old habit | 15:07 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Add schema validation to create user v2 https://review.openstack.org/348531 | 15:07 |
stevemar | gagehugo, already did it for ya :P | 15:08 |
gagehugo | sweet | 15:08 |
stevemar | gagehugo: just gotta browse to the file in git and ... https://github.com/openstack/keystone/blob/master/keystone/identity/schema.py | 15:08 |
stevemar | you can see at the top: gage hugo Add schema validation to update user v2 | 15:09 |
*** rcernin has quit IRC | 15:09 | |
stevemar | i can get everything i need from that, date wise | 15:09 |
gagehugo | stevemar: ah ok nice | 15:09 |
stevemar | and the change Id, so i can look up the commit in gerrit | 15:09 |
stevemar | lbragstad: odyssey4me does OSA keystone setup memcache? https://github.com/openstack/openstack-ansible-os_keystone | 15:10 |
stevemar | hopefully its early enough that i can catch odyssey4me | 15:11 |
*** danpawlik has quit IRC | 15:11 | |
stevemar | dolphm: maybe you know? ^ | 15:11 |
odyssey4me | stevemar the keystone role itself, no - the playbook you use to consume it should, then it will configure it | 15:11 |
stevemar | odyssey4me: do you know of lbragstad's performance bot? | 15:12 |
odyssey4me | stevemar I know of it - but don't know the details. | 15:12 |
stevemar | odyssey4me: i'm trying to figure out if it sets up memcache: https://github.com/lbragstad/keystone-performance | 15:12 |
odyssey4me | stevemar so the role is downloaded: https://github.com/lbragstad/keystone-performance/blob/master/ansible-role-requirements.yml#L21 | 15:13 |
stevemar | oh yeah, does that mean it's setup? | 15:13 |
odyssey4me | stevemar nope - that's just like having a lib present - something needs to invoke it | 15:14 |
odyssey4me | looking for the playbook | 15:14 |
stevemar | odyssey4me: hmm okay | 15:14 |
stevemar | odyssey4me: thank you for looking | 15:14 |
odyssey4me | nope - I see nothing in https://github.com/lbragstad/keystone-performance/blob/master/setup_database.yml or https://github.com/lbragstad/keystone-performance/blob/master/setup_perf_host.yml | 15:15 |
odyssey4me | there should be another playbook that executes the memcache setup too | 15:16 |
stevemar | odyssey4me: okay, that explains why we didn't see any improvement in a patch that the bot tested | 15:16 |
lbragstad | stevemar we can add that as an issue to the project | 15:16 |
stevemar | odyssey4me: which playbook is that? or is that a whole other yaml fiel? | 15:16 |
odyssey4me | lbragstad you could actually combine those playbooks to some degree - I see quite a bit of duplication | 15:17 |
*** ayoung has joined #openstack-keystone | 15:17 | |
*** ChanServ sets mode: +v ayoung | 15:17 | |
odyssey4me | ah, I see why you did two playbooks - you need to keystone db user created after the db is ready | 15:17 |
lbragstad | eyah | 15:18 |
odyssey4me | you could add the memcache server role to the db setup playbook - just adding it as a role in the role list might be enough to make it happen | 15:18 |
stevemar | lbragstad: i need some sort of validation that pre-caching tokens improves validation much more than it slows down token creation :) | 15:19 |
stevemar | odyssey4me: i like hearing that | 15:19 |
*** EinstCrazy has quit IRC | 15:19 | |
*** NishaYadav has joined #openstack-keystone | 15:19 | |
*** NishaYadav is now known as Guest86438 | 15:20 | |
*** slberger has joined #openstack-keystone | 15:21 | |
*** EinstCrazy has joined #openstack-keystone | 15:22 | |
*** Guest86438 is now known as nisha_ | 15:25 | |
*** catintheroof has quit IRC | 15:25 | |
*** jaugustine has quit IRC | 15:28 | |
*** EinstCrazy has quit IRC | 15:30 | |
*** nisha_ has quit IRC | 15:32 | |
*** code-R_ has quit IRC | 15:33 | |
*** arunkant_ has joined #openstack-keystone | 15:34 | |
bknudson | looking at caching some more ... here's what the keys are like: 'f342eb8d3cebaf171f30dfb2fc2ea507fc404d82', '06e5a20f6e68f2cd48de2b40a71211f2c90a6b71' , etc. | 15:35 |
knikolla | stevemar: i can work on the bug you mentioned over the weekend. | 15:35 |
bknudson | maybe that's not enough entropy? | 15:35 |
stevemar | knikolla: ++ | 15:36 |
stevemar | knikolla: assigned it to you | 15:36 |
bknudson | maybe the reason people are seeing issues with caching is that it's getting the wrong data back due to a key clash. | 15:36 |
stevemar | bknudson: :| | 15:37 |
*** ddieterly is now known as ddieterly[away] | 15:37 | |
*** ddieterly[away] is now known as ddieterly | 15:37 | |
knikolla | stevemar: cool, thanks. | 15:37 |
stevemar | knikolla: it looks like they are encoding/decoding things coming from ldap, but i'm not sure we need it for "enabled" | 15:37 |
*** ddieterly is now known as ddieterly[away] | 15:37 | |
stevemar | hmm "if val.startswith(': '): " | 15:38 |
stevemar | that doesn't look promising | 15:38 |
knikolla | stevemar: it looks hackish | 15:38 |
*** nisha_ has joined #openstack-keystone | 15:38 | |
stevemar | knikolla: just a pinch :\ | 15:39 |
bknudson | btw - I'm hoping we will get results today from the extra logging added by https://review.openstack.org/#/c/350804/ , so thanks for merging quickly. | 15:39 |
patchbot | bknudson: patch 350804 - keystone - Add debug logging for RevokeEvent deserialize problem (MERGED) | 15:39 |
*** ddieterly[away] is now known as ddieterly | 15:40 | |
bknudson | if my theory is correct it should be pretty obvious that the data returned in the cache is not a revokeevent as the code expects. | 15:40 |
stevemar | bknudson: np, i figured that was somehting you needed | 15:40 |
bknudson | the mangling is in oslo.cache: return util.sha1_mangle_key(key) | 15:41 |
*** EinstCrazy has joined #openstack-keystone | 15:42 | |
bknudson | maybe there's a sha256? (or use uuid5?) | 15:42 |
bknudson | is there any other way that we could tell that the data was valid? Maybe put a marker in the value? | 15:44 |
*** pgbridge has joined #openstack-keystone | 15:45 | |
*** code-R has joined #openstack-keystone | 15:45 | |
bknudson | this is what the keys look like for memoized functions before mangling: 'keystone.resource.core:get_project_by_name|demo default' | 15:46 |
*** EinstCrazy has quit IRC | 15:47 | |
*** EinstCrazy has joined #openstack-keystone | 15:48 | |
bknudson | dogpile.cache also supports a length_conditional_mangler -- that might help? http://dogpilecache.readthedocs.io/en/latest/api.html#dogpile.cache.util.length_conditional_mangler | 15:49 |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Trust controller refactoring https://review.openstack.org/351260 | 15:49 |
bknudson | we could set the length to some large value that means keystone values are typically not mangled. | 15:49 |
bknudson | well, tokens would be mangled. | 15:50 |
dstanek | bknudson: values mangled or keys? | 15:50 |
bknudson | dstanek: the keys are mangled. | 15:50 |
dstanek | bknudson: ok, you statement above confused me a little | 15:51 |
bknudson | dstanek: which one? | 15:51 |
dstanek | 'that means keystone values are typically not mangled' | 15:51 |
bknudson | oh, right, I meant the values passed in as the key parameter. | 15:52 |
bknudson | the keys that keystone uses are 'keystone.assignment.core:get_role|f34386884d974f45b1d4b0ea9e383c68' | 15:53 |
bknudson | I should be able to find a token one easy enough. | 15:53 |
bknudson | 'keystone.token.provider:_validate_token|gAAAAABXojZX3JzEheKEpOsvBKsNGbbDjcca1QUvBrp81UOdcElU_ReTpQmWW3vWCW7OAkeesPytCPzo5-6i-Wfk0k0x5ienIJw8s2xJkGPGrIEboCc8ARWd2DEFk9-Dy36cvPC_oAt5-F09Ygd-PMUZV33IVnpmE6TrhaCxdlkOKRucO3l8Cn8' | 15:53 |
openstackgerrit | Mikhail Nikolaenko proposed openstack/keystone: Add domain check in domain-specific role implication https://review.openstack.org/351264 | 15:53 |
dstanek | so you are thinking there is a collision in the keyspace? | 15:53 |
bknudson | dstanek: yes, that key gets mangled using sha1 to 95b0d01f325781d2a4aea39bc9cea1e7a6baa193 | 15:54 |
bknudson | not sure how I could prove this? takes a lot of data | 15:54 |
bknudson | what if some other key gets mangled to the same sha1? then you'd get the wrong data back. | 15:56 |
bknudson | the whole point of memcache is to store a lot of keys. | 15:57 |
*** ametts has quit IRC | 15:57 | |
dstanek | i wonder what the probability of that is | 15:57 |
dstanek | bknudson: i would make sense to keep the function part of the key and just mangle the args | 15:58 |
bknudson | oh, cool. | 15:58 |
dstanek | so your example becomes 'keystone.token.provider:_validate_token|{sha}' | 15:59 |
dstanek | that would easility fit in under the max key length even with my namespace patch | 15:59 |
bknudson | should be easy enough, just find the : | 15:59 |
bknudson | your namespace patch changes the keys? | 15:59 |
dstanek | yes, that way we can actually clear regions | 16:00 |
bknudson | btw, I didn't know about dogpile.cache.util.kwarg_function_key_generator(namespace, fn, to_str=<type 'str'>) -- seems like that would make some of our code simpler. | 16:00 |
dstanek | there is a region specific key with a uuid value. when we store/lookup a key we prepend (or append?) that value so removing a region is just updating the region key | 16:01 |
bknudson | all the keystone instances change the key? | 16:02 |
dstanek | bknudson: it's a subclass of region that forces a different key | 16:02 |
*** browne has joined #openstack-keystone | 16:02 | |
dstanek | https://review.openstack.org/#/c/349704/ | 16:03 |
patchbot | dstanek: patch 349704 - keystone - WIP: region namespace POC for cache invalidation | 16:03 |
bknudson | MN vs CLE about to start. 10 more runs guaranteed! | 16:03 |
*** KevinE has joined #openstack-keystone | 16:03 | |
dstanek | while you're thinking about cache i created https://review.openstack.org/#/c/350942/ too as a possible fix | 16:03 |
patchbot | dstanek: patch 350942 - oslo.cache - WIP: RFC: Set item expiration in memcached | 16:03 |
*** ametts has joined #openstack-keystone | 16:04 | |
*** KevinE has quit IRC | 16:05 | |
*** diazjf has joined #openstack-keystone | 16:05 | |
*** mdavidson has quit IRC | 16:05 | |
bknudson | don't you tell memcache how much memory to use? Doesn't seem like this would have any effect on memory usage. | 16:07 |
*** dikonoor has joined #openstack-keystone | 16:09 | |
*** ddieterly is now known as ddieterly[away] | 16:09 | |
*** raildo has quit IRC | 16:10 | |
*** raildo has joined #openstack-keystone | 16:12 | |
bknudson | browne: you mentioned yesterday you were seeing cache issues? | 16:13 |
browne | yep, until we turned off caching completely | 16:13 |
bknudson | browne: could the symptoms have been caused by the cache returning unexpected values? (Like values stored from the wrong key) | 16:14 |
*** nisha_ has quit IRC | 16:14 | |
browne | yep, definitely a lot of unexpected returned values | 16:14 |
*** pnavarro has quit IRC | 16:15 | |
*** raildo has quit IRC | 16:15 | |
bknudson | I'm considering the way that our cache code uses sha1 to mangle keys, wondering if there's collisions happening when lots of values stored. | 16:15 |
*** KevinE has joined #openstack-keystone | 16:15 | |
*** ddieterly[away] is now known as ddieterly | 16:15 | |
browne | bknudson: https://bugs.launchpad.net/keystone/+bugs?search=Search&field.bug_reporter=ericwb | 16:15 |
*** nisha_ has joined #openstack-keystone | 16:15 | |
*** amakarov is now known as amakarov_away | 16:15 | |
openstackgerrit | Monty Taylor proposed openstack/keystoneauth: Add tests for YamlJsonSerializer https://review.openstack.org/344943 | 16:15 |
*** KevinE has quit IRC | 16:15 | |
mordred | dstanek: yup. I suck. thank you | 16:16 |
browne | bknudson: so in our testing it only occurring when using Rally. so the cache possibly was reacting funny once it got full | 16:16 |
*** KevinE has joined #openstack-keystone | 16:16 | |
dstanek | bknudson: it doesn't have too much of an effect. it may just help the lru decide a little better, but i don't think it's significant | 16:16 |
dstanek | mordred: -) | 16:16 |
bknudson | browne: does rally get a crazy number of tokens? (Not that that should cause a problem for keystone, just wondering why this is seen using rally all the time) | 16:17 |
bknudson | we also see our problem when using rally | 16:17 |
*** roxanaghe has joined #openstack-keystone | 16:17 | |
bknudson | maybe rally does a lot of token revocations? | 16:18 |
browne | the tracebacks started to pop up once Rally was cleaning up resources | 16:18 |
*** raildo has joined #openstack-keystone | 16:18 | |
bknudson | oh, so not individual revocations just users | 16:18 |
openstackgerrit | Merged openstack/keystone: Use more specific asserts in tests https://review.openstack.org/351118 | 16:26 |
breton | how many is "crazy"? | 16:27 |
bknudson | stevemar: so maybe your wish came true -- the cause for the bug I opened is the same as the other cache bugs. | 16:27 |
bknudson | breton: keystone should be able to handle any number of tokens / revocations. Just wondering why deployments don't see this cache issue under normal operation. | 16:28 |
breton | also, what bug are you talking about? | 16:29 |
bknudson | breton: https://bugs.launchpad.net/keystone/+bugs?search=Search&field.bug_reporter=ericwb and https://bugs.launchpad.net/keystone/+bug/1609566 | 16:29 |
openstack | Launchpad bug 1609566 in OpenStack Identity (keystone) "500 error from revocation event deserialize" [High,In progress] - Assigned to Brant Knudson (blk-u) | 16:29 |
breton | bknudson: and what's in revoke_event_data? | 16:30 |
*** nisha_ has quit IRC | 16:30 | |
bknudson | breton: I haven't found out yet what the cache is actually returning | 16:30 |
breton | bknudson: there is a debug proxy in oslo.cache, have you tried using it? | 16:31 |
*** ddieterly is now known as ddieterly[away] | 16:32 | |
openstackgerrit | Merged openstack/keystone: Use URIOpt instead of StrOpt for SAML config https://review.openstack.org/341514 | 16:32 |
bknudson | breton: that's interesting... haven't tried it. | 16:32 |
*** kro_focused is now known as krotscheck | 16:32 | |
bknudson | this is happening in an environment where it's not easy for me to make changes. | 16:32 |
*** EinstCra_ has joined #openstack-keystone | 16:32 | |
bknudson | dstanek pointed to some more info where they looked at the result... | 16:32 |
breton | bknudson: [cache]debug_cache_backend, [DEFAULT]default_log_levels = oslo_cache=DEBUG | 16:33 |
breton | that should enable it | 16:34 |
*** EinstCrazy has quit IRC | 16:35 | |
dstanek | and it that's not enough you can create and add your own proxies | 16:38 |
stevemar | bknudson: nice - i guess? | 16:39 |
*** notmyname has joined #openstack-keystone | 16:40 | |
*** ravelar has quit IRC | 16:43 | |
bknudson | dstanek: see any problem with switching from sha1 to sha256 for the key mangler? | 16:43 |
bknudson | it should lead to less chance of a collision. | 16:44 |
bknudson | I don't have any other guess right now what might be causing the strange behavior | 16:44 |
bknudson | should be an easy change. | 16:44 |
breton | actually we ran rally with 100 rps and haven't seen issues like this, even when tokens were in memcache | 16:45 |
bknudson | what's an rp? | 16:45 |
breton | requests per (second) | 16:45 |
bknudson | the test that's failing for us is booting 500 instances | 16:46 |
breton | wow, nice | 16:46 |
bknudson | I don't know what browne was doing. | 16:46 |
*** tqtran has joined #openstack-keystone | 16:47 | |
dstanek | bknudson: no, i think that would be fine | 16:48 |
browne | bknudson: we were doing a similar boot VM test. think it was 20 concurrent instance boots | 16:50 |
*** KevinE has quit IRC | 16:50 | |
*** itisha has joined #openstack-keystone | 16:51 | |
*** tqtran has quit IRC | 16:51 | |
*** david-lyle has quit IRC | 16:53 | |
*** david-lyle has joined #openstack-keystone | 16:53 | |
*** dikonoor has quit IRC | 16:53 | |
*** ddieterly[away] is now known as ddieterly | 16:54 | |
browne | bknudson: here's an example of v3 token with v2 service catalog | 16:59 |
browne | http://paste.openstack.org/show/549271/ | 16:59 |
*** belmoreira has joined #openstack-keystone | 17:00 | |
*** diazjf has quit IRC | 17:01 | |
*** flaper87 has quit IRC | 17:03 | |
dstanek | browne: i have a theory about that one | 17:03 |
breton | dstanek: would love to hear | 17:06 |
dstanek | breton: trying to prove it now...just need a few minutes to get this test testing | 17:07 |
*** mvk has quit IRC | 17:08 | |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Remove mention of db_sync per backend https://review.openstack.org/351289 | 17:09 |
*** permalac has quit IRC | 17:11 | |
dolphm | dstanek: ^ fixed your mention of db_sync in the architecture doc :P | 17:11 |
dstanek | dolphm: thx, i'll take another look in a few | 17:12 |
*** belmoreira has quit IRC | 17:13 | |
dolphm | dstanek: question on https://review.openstack.org/#/c/350793/ as well | 17:22 |
patchbot | dolphm: patch 350793 - keystone - Add rolling upgrade documentation | 17:22 |
*** daemontool has joined #openstack-keystone | 17:28 | |
*** pnavarro has joined #openstack-keystone | 17:29 | |
openstackgerrit | Boris Bobrov proposed openstack/keystone: Faster id mapping lookup https://review.openstack.org/339294 | 17:31 |
dstanek | breton: no luck. can you only reproduce that under load? | 17:34 |
dstanek | sorry breton i meant browne | 17:34 |
*** Gorian_ has joined #openstack-keystone | 17:36 | |
*** jpena is now known as jpena|away | 17:37 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Fix the spelling of a test name https://review.openstack.org/351318 | 17:37 |
*** dikonoor has joined #openstack-keystone | 17:39 | |
browne | dstanek: yes only under load | 17:46 |
*** spzala has quit IRC | 17:48 | |
*** spzala has joined #openstack-keystone | 17:48 | |
*** ddieterly is now known as ddieterly[away] | 17:49 | |
*** spzala has quit IRC | 17:53 | |
*** tesseract- has quit IRC | 17:53 | |
*** spzala has joined #openstack-keystone | 17:54 | |
*** mvk has joined #openstack-keystone | 17:56 | |
*** julim has quit IRC | 18:02 | |
*** ravelar has joined #openstack-keystone | 18:05 | |
*** julim has joined #openstack-keystone | 18:05 | |
*** tpeoples has quit IRC | 18:12 | |
*** dikonoor has quit IRC | 18:13 | |
*** shaleh has joined #openstack-keystone | 18:14 | |
dstanek | browne: what token format are you using in your test environment? | 18:15 |
*** tqtran has joined #openstack-keystone | 18:17 | |
*** tonytan4ever has joined #openstack-keystone | 18:21 | |
browne | dstanek: fernet | 18:25 |
*** jaugustine has joined #openstack-keystone | 18:28 | |
*** spedione|AWAY has quit IRC | 18:32 | |
*** jpena|away is now known as jpena|off | 18:34 | |
*** spedione|AWAY has joined #openstack-keystone | 18:36 | |
*** spedione|AWAY is now known as spedione | 18:36 | |
*** ayoung has quit IRC | 18:38 | |
*** ddieterly[away] is now known as ddieterly | 18:47 | |
*** daemontool has quit IRC | 18:51 | |
*** daemontool has joined #openstack-keystone | 18:52 | |
dstanek | browne: ok, back from lunch... do you have a sample v2 token that contains a v3 catalog? | 18:54 |
*** ddieterly is now known as ddieterly[away] | 18:55 | |
breton | dstanek: http://paste.openstack.org/show/549271/ | 18:56 |
breton | dstanek: (he posted it earlier) | 18:56 |
dstanek | breton: hmmm...isn't that a v3 token? | 18:57 |
breton | dstanek: > 19:59 < browne> bknudson: here's an example of v3 token with v2 service catalog | 18:58 |
dstanek | breton: ah, i was looking for the opposite | 18:59 |
*** EinstCra_ has quit IRC | 19:00 | |
bknudson | " MemcachedKeyCharacterError: Control/space characters not allowed (key='keystone.resource.core:get_project_by_name|Default None')" -- that's funny | 19:01 |
dstanek | bknudson: yeah a space breaks the protocol | 19:01 |
*** EinstCrazy has joined #openstack-keystone | 19:02 | |
dstanek | although i don't think you can have multple args for a get...meh | 19:02 |
bknudson | seems like the way functions calls are encoded could lead to confusion. | 19:02 |
bknudson | just putting a space between arguments. | 19:02 |
*** jaugustine_ has joined #openstack-keystone | 19:04 | |
*** fifieldt has quit IRC | 19:07 | |
*** slberger has quit IRC | 19:08 | |
*** daemontool_ has joined #openstack-keystone | 19:11 | |
*** EinstCrazy has quit IRC | 19:13 | |
*** sdake_ has joined #openstack-keystone | 19:13 | |
*** daemontool has quit IRC | 19:15 | |
*** sdake has quit IRC | 19:16 | |
bknudson | we ran rally on the latest code but this time we hit https://bugs.launchpad.net/keystone/+bug/1600394 | 19:17 |
openstack | Launchpad bug 1600394 in OpenStack Identity (keystone) "ValueError: too many values to unpack" [Undecided,Incomplete] | 19:17 |
*** roxanaghe has quit IRC | 19:17 | |
stevemar | rally is finding a lot of bugs these days for us | 19:17 |
stevemar | bknudson: i'll switch it to confirmed | 19:18 |
*** fifieldt has joined #openstack-keystone | 19:18 | |
*** haplo37__ has joined #openstack-keystone | 19:20 | |
dstanek | bknudson: are you running against a single node? | 19:20 |
bknudson | dstanek: not even close. | 19:20 |
dstanek | :-) | 19:21 |
bknudson | I think we have 5 keystones. | 19:21 |
*** slberger has joined #openstack-keystone | 19:21 | |
bknudson | for some reason the team doing this testing thought that more keystones would help with the revocation list performance problem. | 19:21 |
bknudson | they don't talk to me when they make these decisions. | 19:22 |
*** spedione has quit IRC | 19:22 | |
stevemar | bknudson: they don't really talk to anyone | 19:22 |
*** ddieterly[away] is now known as ddieterly | 19:23 | |
bknudson | we've got another log file that has the other error! maybe the value was logged. | 19:29 |
*** jaugustine has quit IRC | 19:30 | |
*** agrebennikov has joined #openstack-keystone | 19:30 | |
*** spedione|AWAY has joined #openstack-keystone | 19:30 | |
*** spedione|AWAY is now known as spedione | 19:30 | |
dstanek | bknudson: have you tried changing the key generation already? | 19:32 |
bknudson | dstanek: no, working on it. | 19:32 |
bknudson | dstanek: I'm trying to be fancy and not mangle the string if it's shorter than a sha512 string. | 19:32 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Add schema validation to create user v2 https://review.openstack.org/348531 | 19:33 |
bknudson | dstanek: https://review.openstack.org/#/c/351353/ | 19:33 |
patchbot | bknudson: patch 351353 - oslo.cache - Use sha512 instead of sha1 | 19:33 |
*** mdurrant has joined #openstack-keystone | 19:35 | |
dstanek | even a sha1 seems to have such a low probability of collision....this is crazy | 19:35 |
*** tonytan_brb has joined #openstack-keystone | 19:36 | |
mdurrant | Experiencing an interesting issue since upgrading to mitaka/master... a component we wrote for creating instances based on certain criteria is no longer authenticating to Keystone correctly. We pull the endpoint URL from Keystone so I'm not sure where to start looking. | 19:36 |
mdurrant | I can see it's trying to auth to /identity/tokens, when it should be hitting /identity/v3/auth/tokens | 19:37 |
mdurrant | I checked my keystone endpoint table - everything there looks right. Anyone know where in the code it decides to append "/auth/tokens" ? I know at one point it was either "/auth" or "/tokens" in keystone v2. | 19:38 |
dstanek | bknudson: the 'too many values' bug looks to me like it's getting unexpected data from memcached. like memcache not properly responding. | 19:38 |
bknudson | dstanek: oh... hmmm. | 19:38 |
*** tonytan4ever has quit IRC | 19:38 | |
dstanek | bknudson: the error happens in the memcache.py library in the _expectvalue() method | 19:39 |
dstanek | mdurrant: v2 is/was /tokens and v3 is /auth/tokens | 19:40 |
dstanek | mdurrant: are you upgrading to mitaka or master? | 19:40 |
*** haplo37__ has quit IRC | 19:41 | |
mordred | stevemar: yay my stupid supposed-to-be-quick patch passed check | 19:43 |
*** jrist has quit IRC | 19:43 | |
mdurrant | dstanek: I'm on master now. Can't use mitaka because mitaka's lbaas DB schema is FUBAR | 19:44 |
mdurrant | project id's were backported without requisite migrations | 19:44 |
*** mriedem has joined #openstack-keystone | 19:47 | |
mriedem | keystone v2 was deprecated in mitaka right? | 19:48 |
mriedem | and depecated is a valid api status right? https://wiki.openstack.org/wiki/VersionDiscovery#status | 19:48 |
mdurrant | Ooooooooooooooooooooo | 19:48 |
mdurrant | That very well may be the case | 19:48 |
mriedem | then why is keystone v2 still listed as supported in the api-ref? http://developer.openstack.org/api-ref/identity/v2/ | 19:48 |
mriedem | http://git.openstack.org/cgit/openstack/keystone/tree/api-ref/source/v2/index.rst#n4 | 19:49 |
breton | mriedem: v2.0 is not deprecated | 19:50 |
mriedem | http://docs.openstack.org/releasenotes/keystone/mitaka.html#deprecation-notes | 19:50 |
mriedem | [blueprint deprecated-as-of-mitaka] Deprecated all v2.0 APIs. The keystone team recommends using v3 APIs instead. Most v2.0 APIs will be removed in the ‘Q’ release. However, the authentication APIs and EC2 APIs are indefinitely deprecated and will not be removed in the ‘Q’ release. | 19:50 |
mriedem | there seems to be a communication breakdown here | 19:50 |
breton | oh. | 19:50 |
stevemar | breton: it sure is | 19:51 |
mriedem | someone forgot to update the api-ref docs | 19:51 |
lbragstad | yeah - i think we talked about that in japa | 19:51 |
lbragstad | japan | 19:51 |
mriedem | this is all lbragstad's fault i'm pretty sure | 19:51 |
stevemar | mriedem: for sure | 19:51 |
*** melwitt has joined #openstack-keystone | 19:51 | |
lbragstad | mriedem wouldn't be doing my job it if wasn't :) | 19:51 |
mriedem | should i get my keystone ATC for newton? | 19:51 |
breton | ok, i am surprised | 19:52 |
stevemar | mriedem: do it up, so you can vote to eject me from ptl | 19:52 |
mriedem | do we even have ATCs anymore with the PTG? | 19:52 |
mriedem | sweet | 19:52 |
lbragstad | mriedem I'll review | 19:52 |
stevemar | mriedem: you can then run for ptl so i don't have to! | 19:52 |
lbragstad | stevemar you're never leaving... | 19:52 |
stevemar | lbragstad: i just found a new sucker, errr replacement to take over | 19:53 |
lbragstad | stevemar are we gonna see how many projects mriedem can run at once? | 19:53 |
*** rakhmerov has quit IRC | 19:53 | |
* stevemar leaves for 10 minutes | 19:53 | |
stevemar | hehe | 19:53 |
stevemar | lbragstad: he did 2 just fine | 19:53 |
lbragstad | psh - what's a third? | 19:53 |
*** ayoung has joined #openstack-keystone | 19:56 | |
*** ChanServ sets mode: +v ayoung | 19:56 | |
*** jrist has joined #openstack-keystone | 19:57 | |
*** rakhmerov has joined #openstack-keystone | 19:57 | |
openstackgerrit | Matt Riedemann proposed openstack/keystone: Update the api-ref to mark the v2 API as deprecated https://review.openstack.org/351370 | 20:01 |
lbragstad | dstanek do you have anything for https://review.openstack.org/#/c/349704/ locally? | 20:02 |
patchbot | lbragstad: patch 349704 - keystone - WIP: region namespace POC for cache invalidation | 20:02 |
*** narengan has joined #openstack-keystone | 20:03 | |
dstanek | lbragstad: just lots of debugging code right now | 20:05 |
*** ametts has quit IRC | 20:05 | |
lbragstad | dstanek is there anything I can do to help? | 20:05 |
dstanek | lbragstad: not specifically. i'm just running lots of caching tests and trying to find some patterns in the output/failures | 20:06 |
lbragstad | dstanek just looping specific tests? | 20:06 |
*** ametts has joined #openstack-keystone | 20:10 | |
dstanek | lbragstad: i actually created some shell script too to try to induce errors. basically just a few curl commands | 20:11 |
lbragstad | dstanek ah - I thought you meant using keystone tests | 20:12 |
lbragstad | dstanek from your comment in keystone/__init__.py - where do you think it should live? | 20:13 |
*** markvoelker has quit IRC | 20:13 | |
lbragstad | keystone/common/cache/ ? | 20:13 |
dstanek | lbragstad: probably, but i have to make sure it gets patched early | 20:18 |
dstanek | need to take a dinner break soon | 20:22 |
lbragstad | dstanek ok | 20:22 |
bknudson | Here's the proposed change to oslo.cache to use sha512 rather than sha1: https://review.openstack.org/#/c/351353/ | 20:24 |
patchbot | bknudson: patch 351353 - oslo.cache - Use sha512 when mangling keys to avoid collisions | 20:24 |
*** catintheroof has joined #openstack-keystone | 20:30 | |
*** roxanaghe has joined #openstack-keystone | 20:32 | |
*** pauloewerton has quit IRC | 20:33 | |
*** jrist has quit IRC | 20:38 | |
*** mriedem has left #openstack-keystone | 20:45 | |
mdurrant | Well, the solution was: update the endpoint in the service catalog to have /v3 on the end. Suddenly things work as expected. | 20:45 |
mdurrant | I would swear that somewhere in the keystone client code there is something that decides whether to append /tokens or /auth/tokens depending on the identity api ver, but I'll be darned if I know where it is. | 20:46 |
*** tonytan_brb has quit IRC | 20:48 | |
breton | stevemar lbragstad: if v2 is deprecated, should we change version/controllers.py:122? | 20:48 |
openstackgerrit | Merged openstack/keystoneauth: Add tests for YamlJsonSerializer https://review.openstack.org/344943 | 20:49 |
*** jrist has joined #openstack-keystone | 20:50 | |
mordred | stevemar: ^^ woot! ksa release is now clear | 20:51 |
openstackgerrit | Boris Bobrov proposed openstack/keystone: Report v2.0 as deprecated in version discovery https://review.openstack.org/351396 | 20:52 |
breton | stevemar lbragstad: like this ^ | 20:52 |
stevemar | breton: yeah, probably need to do that | 20:52 |
clenimar | in which practical situation could ironic not to be in the service catalog? | 20:53 |
*** raildo has quit IRC | 20:55 | |
openstackgerrit | Boris Bobrov proposed openstack/keystone: Report v2.0 as deprecated in version discovery https://review.openstack.org/351396 | 21:00 |
*** gordc has quit IRC | 21:13 | |
*** ddieterly is now known as ddieterly[away] | 21:17 | |
*** julim has quit IRC | 21:18 | |
*** julim has joined #openstack-keystone | 21:18 | |
*** adriant has joined #openstack-keystone | 21:23 | |
*** julim has quit IRC | 21:23 | |
*** narengan has quit IRC | 21:25 | |
*** ametts has quit IRC | 21:26 | |
*** spzala has quit IRC | 21:32 | |
*** spzala has joined #openstack-keystone | 21:32 | |
*** slberger has quit IRC | 21:34 | |
*** spzala has quit IRC | 21:36 | |
*** KevinE has joined #openstack-keystone | 21:39 | |
*** KevinE has joined #openstack-keystone | 21:40 | |
openstackgerrit | Merged openstack/keystone: Remove mention of db_sync per backend https://review.openstack.org/351289 | 21:41 |
*** mdurrant has quit IRC | 21:42 | |
*** ayoung has quit IRC | 21:43 | |
*** slberger has joined #openstack-keystone | 21:46 | |
*** pnavarro has quit IRC | 21:48 | |
*** ddieterly[away] is now known as ddieterly | 21:48 | |
*** gagehugo_ has joined #openstack-keystone | 21:49 | |
*** roxanaghe_ has joined #openstack-keystone | 21:59 | |
*** roxanaghe__ has joined #openstack-keystone | 22:03 | |
*** roxanaghe has quit IRC | 22:03 | |
*** diazjf has joined #openstack-keystone | 22:05 | |
*** roxanaghe_ has quit IRC | 22:06 | |
*** diazjf has quit IRC | 22:17 | |
*** ayoung has joined #openstack-keystone | 22:26 | |
*** ChanServ sets mode: +v ayoung | 22:26 | |
bknudson | I wrote a script that does token validate - token revoke in a loop ... now watching it slow to a crawl. | 22:29 |
*** ntpttr has quit IRC | 22:31 | |
*** ntpttr has joined #openstack-keystone | 22:31 | |
openstackgerrit | Merged openstack/keystone: Fix the spelling of a test name https://review.openstack.org/351318 | 22:32 |
*** spzala has joined #openstack-keystone | 22:33 | |
*** spzala has quit IRC | 22:38 | |
*** edmondsw has quit IRC | 22:40 | |
*** roxanaghe has joined #openstack-keystone | 22:49 | |
*** roxanaghe_ has joined #openstack-keystone | 22:50 | |
*** spzala has joined #openstack-keystone | 22:50 | |
*** roxanaghe__ has quit IRC | 22:52 | |
*** roxanaghe has quit IRC | 22:53 | |
*** ddieterly is now known as ddieterly[away] | 22:58 | |
*** ddieterly[away] has quit IRC | 22:58 | |
openstackgerrit | Sam Leong proposed openstack/keystone: Force explicit COMMIT for flush expired tokens https://review.openstack.org/351428 | 23:05 |
*** ayoung has quit IRC | 23:06 | |
*** code-R has quit IRC | 23:07 | |
*** catintheroof has quit IRC | 23:13 | |
*** code-R has joined #openstack-keystone | 23:14 | |
*** code-R has quit IRC | 23:20 | |
*** gagehugo_ has quit IRC | 23:23 | |
*** slberger has left #openstack-keystone | 23:26 | |
*** markvoelker has joined #openstack-keystone | 23:28 | |
*** Gorian_ has quit IRC | 23:28 | |
*** jamielennox is now known as jamielennox|away | 23:30 | |
*** markvoelker_ has joined #openstack-keystone | 23:37 | |
*** markvoelker has quit IRC | 23:41 | |
*** jamielennox|away is now known as jamielennox | 23:41 | |
*** sdake has joined #openstack-keystone | 23:44 | |
jamielennox | hey stevemar, what did you used to use for an openid provider? | 23:45 |
*** EinstCrazy has joined #openstack-keystone | 23:45 | |
*** catintheroof has joined #openstack-keystone | 23:46 | |
*** sdake_ has quit IRC | 23:46 | |
*** haplo37__ has joined #openstack-keystone | 23:53 | |
*** EinstCrazy has quit IRC | 23:53 | |
*** roxanaghe_ has quit IRC | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!