*** guoshan has quit IRC | 00:02 | |
*** david-lyle has joined #openstack-keystone | 00:02 | |
*** david-lyle has quit IRC | 00:07 | |
openstackgerrit | Gage Hugo proposed openstack/keystone: WIP - Allow user to change own expired password https://review.openstack.org/404022 | 00:08 |
---|---|---|
*** jose-phillips has quit IRC | 00:30 | |
*** hoangcx has joined #openstack-keystone | 00:51 | |
*** guoshan has joined #openstack-keystone | 00:59 | |
*** guoshan has quit IRC | 01:03 | |
*** guoshan has joined #openstack-keystone | 01:13 | |
*** jose-phillips has joined #openstack-keystone | 01:27 | |
*** jose-phillips has quit IRC | 01:33 | |
*** jose-phillips has joined #openstack-keystone | 01:34 | |
*** liujiong has joined #openstack-keystone | 01:41 | |
*** jose-phillips has quit IRC | 02:04 | |
*** david-lyle has joined #openstack-keystone | 02:04 | |
*** jose-phillips has joined #openstack-keystone | 02:04 | |
*** david-lyle has quit IRC | 02:08 | |
*** markvoelker has quit IRC | 02:12 | |
*** jose-phillips has quit IRC | 02:21 | |
*** jose-phillips has joined #openstack-keystone | 02:22 | |
*** dave-mccowan has joined #openstack-keystone | 02:41 | |
*** jose-phillips has quit IRC | 03:06 | |
*** markvoelker has joined #openstack-keystone | 03:13 | |
*** markvoelker has quit IRC | 03:17 | |
*** links has joined #openstack-keystone | 03:22 | |
*** dave-mccowan has quit IRC | 03:28 | |
*** namnh has joined #openstack-keystone | 03:52 | |
*** david-lyle has joined #openstack-keystone | 04:05 | |
*** david-lyle has quit IRC | 04:10 | |
*** markvoelker has joined #openstack-keystone | 04:14 | |
*** guoshan has quit IRC | 04:16 | |
*** markvoelker has quit IRC | 04:18 | |
*** guoshan has joined #openstack-keystone | 04:45 | |
*** jose-phillips has joined #openstack-keystone | 05:00 | |
*** guoshan has quit IRC | 05:10 | |
*** udesale has joined #openstack-keystone | 05:10 | |
*** markvoelker has joined #openstack-keystone | 05:14 | |
*** markvoelker has quit IRC | 05:19 | |
*** nicolasbock has joined #openstack-keystone | 05:51 | |
*** liujiong has quit IRC | 05:56 | |
*** liujiong_66 has joined #openstack-keystone | 05:56 | |
*** david-lyle has joined #openstack-keystone | 06:07 | |
*** guoshan has joined #openstack-keystone | 06:10 | |
*** david-lyle has quit IRC | 06:12 | |
*** jose-phillips has quit IRC | 06:16 | |
*** nicolasbock has quit IRC | 06:16 | |
*** guoshan has quit IRC | 06:24 | |
*** guoshan has joined #openstack-keystone | 06:24 | |
*** nicolasbock has joined #openstack-keystone | 06:30 | |
openstackgerrit | Julia Varlamova proposed openstack/keystone: Change DevStack plugin to setup multi-Keystone https://review.openstack.org/399472 | 06:36 |
*** rcernin has joined #openstack-keystone | 06:53 | |
*** tesseract has joined #openstack-keystone | 07:08 | |
*** guoshan has quit IRC | 07:14 | |
*** guoshan has joined #openstack-keystone | 07:14 | |
*** guoshan has quit IRC | 07:24 | |
*** guoshan has joined #openstack-keystone | 07:30 | |
*** AlexeyAbashkin has joined #openstack-keystone | 07:41 | |
*** guoshan_ has joined #openstack-keystone | 08:01 | |
*** guoshan has quit IRC | 08:05 | |
*** david-lyle has joined #openstack-keystone | 08:09 | |
*** david-lyle has quit IRC | 08:13 | |
*** sc68cal has quit IRC | 08:17 | |
-openstackstatus- NOTICE: All CI tests are currently broken since logs.openstack.org is down. Refrain from recheck or approval until this is fixed. | 08:17 | |
*** ChanServ changes topic to "All CI tests are currently broken since logs.openstack.org is down. Refrain from recheck or approval until this is fixed." | 08:17 | |
*** yatin is now known as yatin_on_leave | 08:19 | |
*** sc68cal has joined #openstack-keystone | 08:20 | |
*** guoshan_ has quit IRC | 08:23 | |
*** yatin_on_leave has quit IRC | 08:24 | |
*** guoshan_ has joined #openstack-keystone | 08:25 | |
*** stingaci has joined #openstack-keystone | 08:26 | |
*** guoshan__ has joined #openstack-keystone | 08:28 | |
*** guoshan_ has quit IRC | 08:28 | |
*** guoshan__ has quit IRC | 08:30 | |
*** guoshan has joined #openstack-keystone | 08:30 | |
*** stingaci has quit IRC | 08:31 | |
*** sc68cal has quit IRC | 08:39 | |
*** sc68cal has joined #openstack-keystone | 08:43 | |
*** sheel has joined #openstack-keystone | 08:49 | |
*** guoshan_ has joined #openstack-keystone | 08:51 | |
*** guoshan has quit IRC | 08:51 | |
*** liujiong has joined #openstack-keystone | 08:55 | |
*** liujiong_66 has quit IRC | 08:55 | |
*** zzzeek has quit IRC | 09:00 | |
*** zzzeek has joined #openstack-keystone | 09:00 | |
*** nicolasbock has quit IRC | 09:01 | |
*** guoshan_ has quit IRC | 09:09 | |
*** guoshan has joined #openstack-keystone | 09:09 | |
*** guoshan_ has joined #openstack-keystone | 09:12 | |
*** guoshan has quit IRC | 09:12 | |
*** liujiong_66 has joined #openstack-keystone | 09:19 | |
*** liujiong has quit IRC | 09:21 | |
*** oomichi has quit IRC | 09:21 | |
*** oomichi has joined #openstack-keystone | 09:22 | |
*** liujiong has joined #openstack-keystone | 09:23 | |
*** liujiong_66 has quit IRC | 09:23 | |
*** asettle has joined #openstack-keystone | 09:25 | |
*** guoshan_ has quit IRC | 09:32 | |
*** guoshan has joined #openstack-keystone | 09:33 | |
*** hoangcx has quit IRC | 10:07 | |
*** markvoelker has joined #openstack-keystone | 10:19 | |
*** pkoraca_ has joined #openstack-keystone | 10:23 | |
*** robcresswell_ has joined #openstack-keystone | 10:24 | |
*** aleph1 has joined #openstack-keystone | 10:24 | |
*** markvoelker has quit IRC | 10:24 | |
*** serverascode_ has joined #openstack-keystone | 10:25 | |
*** tesseract has quit IRC | 10:25 | |
*** tesseract has joined #openstack-keystone | 10:26 | |
*** sudorandom_ has joined #openstack-keystone | 10:29 | |
*** sakthi has quit IRC | 10:30 | |
*** tonyb has quit IRC | 10:30 | |
*** d0ugal has quit IRC | 10:30 | |
*** jascott1 has quit IRC | 10:30 | |
*** rha has quit IRC | 10:30 | |
*** dmellado has quit IRC | 10:30 | |
*** timss has quit IRC | 10:30 | |
*** robcresswell has quit IRC | 10:30 | |
*** pkoraca has quit IRC | 10:30 | |
*** serverascode has quit IRC | 10:30 | |
*** charz has quit IRC | 10:30 | |
*** akrzos has quit IRC | 10:30 | |
*** sudorandom has quit IRC | 10:30 | |
*** fungi has quit IRC | 10:30 | |
*** agarner has quit IRC | 10:30 | |
*** mancdaz has quit IRC | 10:30 | |
*** sudorandom_ is now known as sudorandom | 10:30 | |
*** pcaruana has joined #openstack-keystone | 10:31 | |
*** pkoraca_ is now known as pkoraca | 10:31 | |
*** robcresswell_ is now known as robcresswell | 10:32 | |
*** guoshan has quit IRC | 10:32 | |
*** liujiong has quit IRC | 10:34 | |
*** serverascode_ is now known as serverascode | 10:35 | |
*** sakthi has joined #openstack-keystone | 10:36 | |
*** tonyb has joined #openstack-keystone | 10:36 | |
*** d0ugal has joined #openstack-keystone | 10:36 | |
*** rha has joined #openstack-keystone | 10:36 | |
*** jascott1 has joined #openstack-keystone | 10:36 | |
*** dmellado has joined #openstack-keystone | 10:36 | |
*** timss has joined #openstack-keystone | 10:36 | |
*** charz has joined #openstack-keystone | 10:36 | |
*** akrzos has joined #openstack-keystone | 10:36 | |
*** mancdaz has joined #openstack-keystone | 10:36 | |
*** Matias has quit IRC | 10:38 | |
*** fungi has joined #openstack-keystone | 10:39 | |
*** namnh has quit IRC | 10:44 | |
*** guoshan has joined #openstack-keystone | 10:56 | |
*** guoshan has quit IRC | 11:01 | |
*** ChanServ changes topic to "Meeting Agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Ocata goals: https://docs.google.com/spreadsheets/d/156q820cXcEc8Y9YWQgoc_hyOm3AZ2jtMQM3zdDhwGFU/edit?usp=sharing" | 11:08 | |
-openstackstatus- NOTICE: logs.openstack.org is up again. Feel free to recheck any failures. | 11:08 | |
*** david-lyle has joined #openstack-keystone | 11:11 | |
*** david-lyle has quit IRC | 11:15 | |
*** markvoelker has joined #openstack-keystone | 11:20 | |
*** markvoelker has quit IRC | 11:25 | |
*** pcaruana has quit IRC | 11:28 | |
*** brad[] has quit IRC | 11:44 | |
*** brad[] has joined #openstack-keystone | 11:52 | |
*** guoshan has joined #openstack-keystone | 11:57 | |
*** guoshan has quit IRC | 12:02 | |
*** markvoelker has joined #openstack-keystone | 12:21 | |
*** markvoelker has quit IRC | 12:26 | |
*** stingaci has joined #openstack-keystone | 12:28 | |
*** stingaci has quit IRC | 12:32 | |
*** guoshan has joined #openstack-keystone | 12:58 | |
*** guoshan has quit IRC | 13:03 | |
*** david-lyle has joined #openstack-keystone | 13:12 | |
*** david-lyle has quit IRC | 13:17 | |
*** markvoelker has joined #openstack-keystone | 13:22 | |
*** lamt has quit IRC | 13:24 | |
*** markvoelker has quit IRC | 13:27 | |
*** nicolasbock has joined #openstack-keystone | 13:33 | |
*** lamt has joined #openstack-keystone | 13:53 | |
*** guoshan has joined #openstack-keystone | 13:59 | |
openstackgerrit | Merged openstack/keystone: Handle disk write failure when doing Fernet key rotation https://review.openstack.org/413495 | 14:02 |
*** guoshan has quit IRC | 14:04 | |
lbragstad | o/ | 14:16 |
*** markvoelker has joined #openstack-keystone | 14:23 | |
*** markvoelker has quit IRC | 14:27 | |
*** links has quit IRC | 14:27 | |
lbragstad | it's quiet today - folks must still be on vacation | 14:51 |
*** nklenke has joined #openstack-keystone | 14:53 | |
*** nicolasbock has quit IRC | 14:53 | |
*** guoshan has joined #openstack-keystone | 15:00 | |
*** chris_hultin|AWA is now known as chris_hultin | 15:04 | |
*** guoshan has quit IRC | 15:05 | |
*** david-lyle has joined #openstack-keystone | 15:14 | |
*** chris_hultin is now known as chris_hultin|AWA | 15:14 | |
*** dave-mccowan has joined #openstack-keystone | 15:15 | |
*** chris_hultin|AWA is now known as chris_hultin | 15:17 | |
*** david-lyle has quit IRC | 15:18 | |
*** erlon has joined #openstack-keystone | 15:33 | |
*** wasmum has quit IRC | 15:34 | |
*** udesale has quit IRC | 15:35 | |
*** wasmum has joined #openstack-keystone | 15:41 | |
*** wasmum has quit IRC | 15:44 | |
*** guoshan has joined #openstack-keystone | 16:00 | |
*** diazjf has joined #openstack-keystone | 16:04 | |
*** guoshan has quit IRC | 16:05 | |
*** brad[] has quit IRC | 16:11 | |
*** diazjf has quit IRC | 16:14 | |
*** dave-mcc_ has joined #openstack-keystone | 16:17 | |
*** dave-mccowan has quit IRC | 16:19 | |
*** brad[] has joined #openstack-keystone | 16:22 | |
*** dave-mcc_ has quit IRC | 16:24 | |
*** stingaci has joined #openstack-keystone | 16:29 | |
*** tesseract has quit IRC | 16:32 | |
*** stingaci has quit IRC | 16:34 | |
*** crinkle_ has joined #openstack-keystone | 16:54 | |
*** crinkle has quit IRC | 16:56 | |
*** guoshan has joined #openstack-keystone | 17:01 | |
*** asettle has quit IRC | 17:04 | |
*** guoshan has quit IRC | 17:06 | |
*** jose-phillips has joined #openstack-keystone | 17:07 | |
*** david-lyle has joined #openstack-keystone | 17:15 | |
*** david-lyle has quit IRC | 17:20 | |
*** harlowja has joined #openstack-keystone | 17:36 | |
*** bandrus has joined #openstack-keystone | 17:54 | |
*** guoshan has joined #openstack-keystone | 18:02 | |
bandrus | I am in need of some assistance understanding formation of keystone requests, specifically token auth and subsequent commands using openstack CLI... would that be a good topic here or am I better off asking in #openstack-101 or something like that? | 18:06 |
lbragstad | bandrus feel free to ask here | 18:06 |
*** guoshan has quit IRC | 18:06 | |
bandrus | thanks - so firstly I'm trying to understand our infrastructure's endpoints, and seeing if there can be any improvement there... My first question is regarding the service catalog. All keystone endpoints are listed as /v2.0 | 18:08 |
bandrus | I'm wondering what the proper way to change the endpoints to v3 is, or if it's needed, and what potential impact it might have to clients | 18:09 |
lbragstad | bandrus did you set up your deployment using a guide or devstack or something else? | 18:09 |
bandrus | I would say "something else", I'm working on an existing infrastructure and I've been tasked with understanding the endpoints based on a few issues we have open from our customers. e.g. v3 endpoints halfway working... some commands working, some not | 18:10 |
bandrus | what I do notice is that most endpoints in our service catalog have /v2.0 in them, and none have v3, though some v3 requests seem to work. I'm not sure how it "should" look | 18:11 |
lbragstad | bandrus ah - sure... | 18:12 |
lbragstad | bandrus well - keystone's v3 api supports a lot more stuff than the v2.0 api, so if clients are trying to use whatever is in the service catalog to do v3-like operations, but attempting to do that against a v2.0 endpoint, you'd forsure see some strange behavior | 18:13 |
lbragstad | bandrus is the other services talking to keystone (i.e. nova asking keystone to validate a token) that's failing or is it customers trying to use a client of some sort to do v3 things against v2.0? | 18:14 |
*** rcernin has quit IRC | 18:14 | |
bandrus | everything in our infrastructure seems to be working alright, which is why I'm hesitant to make changes - it's mostly when a client tries to do v3 things against the assumed v2.0 endpoints | 18:15 |
lbragstad | bandrus hmm - are you using openstackclient? | 18:17 |
lbragstad | if so - you might have to specify a v3 auth url and make sure to set an identity API version before using openstackclient in order for it to work correctly with v3 | 18:17 |
lbragstad | bandrus for example - http://docs.openstack.org/developer/python-openstackclient/authentication.html#authenticating-using-identity-server-api-v3 | 18:18 |
bandrus | lbragstad: to specify a v3 endpoint, would I need to make sure it's in the service catalog as such? | 18:18 |
lbragstad | bandrus yes and no - you can tell your command line (openstackclient) interface you want to use a specific identity api version by following those ^ steps | 18:19 |
bandrus | okay, so the client can specify v3 even though it's hitting a URL with /v2.0 in the endpoint URL? I am pretty sure it will automatically get the endpoint URL (including /v2.0) from the authentication response, correct? | 18:21 |
lbragstad | bandrus well - your clients are going to use the value specified in OS_AUTH_URL | 18:21 |
lbragstad | bandrus so you could specify OS_AUTH_URL=http://localhost:5000/v3 or OS_AUTH_URL=http://localhost:5000/v2.0 | 18:21 |
lbragstad | and do an `openstack token issue` and the client (openstackclient) would format the request accordingly | 18:22 |
bandrus | lbragstad: is OS_AUTH_URL need to match a keystone endpoint listed in the service catalog? | 18:23 |
lbragstad | bandrus no - not necessarily | 18:23 |
lbragstad | bandrus OS_AUTH_URL is for your client session to talk to keystone | 18:24 |
*** markvoelker has joined #openstack-keystone | 18:24 | |
lbragstad | (i.e. if i wanted to use openstackclient to interact with keystone on the command line, i could set OS_AUTH_URL to use v3 and I'd be using keystone v3 API to get what I need) | 18:24 |
bandrus | lbragstad: I appreciate your help, I'm still trying to understand the auth and request processes fully so I can determine exactly where our problems lie. I'll have some more questions if you don't mind after playing around for a few minutes | 18:28 |
*** markvoelker has quit IRC | 18:29 | |
lbragstad | bandrus no problem - hopefully it helped a little bit | 18:29 |
lbragstad | bandrus just to confirm - your services aren't having any issues, your issues are specific to clients (using horizon or openstackclient)? | 18:29 |
bandrus | lbragstad: correct | 18:30 |
bandrus | I do have some more keystone specific questions, I just need to stew on what conclusions you've helped me come to | 18:30 |
lbragstad | bandrus sounds good - just ping me when you're ready | 18:31 |
bandrus | lbragstad: is there a benefit to configuring OpenStack services to use /v3 over /v2.0? as per this guide... or similar: https://goo.gl/HultSC | 18:41 |
lbragstad | bandrus well - using v3 offers more features and capabilities, but from a services perspective, they just need keystone to be able to validate user tokens | 18:43 |
lbragstad | if you're deployment is taking advantage of multi-domain support, then v3 is going to be something you'll need in order for other services to be able to validate tokens for users outside the default domain | 18:44 |
lbragstad | v2.0 token validation assumes all users are in a single/default domain, but v3 allows multiple domain per deployment | 18:45 |
bandrus | lbragstad: thank you. So to ease over into my keystone-specific questions - one of our user-reported issues mentions using keystone v3 token and an OS_AUTH_URL of the keystone endpoint (v3). This is what I am trying to reproduce. I have generated a token that has been tested with various curl requests and I've set that as OS_ACCESS_TOKEN | 18:47 |
bandrus | to clarify, I'm now attempting to use v3 token with openstackclient | 18:48 |
bandrus | I am guessing I am missing one of the parameters needed to get token requests working with openstackclient, but I'm not sure which it is... | 18:48 |
bandrus | because it asks for password | 18:49 |
lbragstad | aha - I think OS_ACCESS_TOKEN is specific to using keystone oauth plugin | 18:51 |
lbragstad | but i would have to check with stevemar to be sure | 18:51 |
dtroyer | bandrus: you are looking for token_endpoint auth and setting —os-token and --os-url | 18:52 |
lbragstad | bandrus ^ in addition to that, you might need to set --os-password | 18:52 |
lbragstad | dtroyer o/ | 18:52 |
*** harlowja has quit IRC | 18:53 | |
dtroyer | you really shouldn't need anything else to do token_endpoint, that bypasses the initial auth entirely and hands the given token to the client lib directly | 18:53 |
lbragstad | ah - gotcha | 18:54 |
bandrus | dtroyer, --os-access-token-endpoint correct? | 18:54 |
lbragstad | dtroyer otherwise you would need the password in order to perform the initial auth? | 18:54 |
bandrus | this endpoint should correlate to... keystone v3 or the actual service I'm trying to hit? | 18:55 |
dtroyer | that's the point of token_endpoint, to give a presumably valid token straight to the actual API you want to call and skip the get_token() calls | 18:55 |
bandrus | got it | 18:55 |
dtroyer | bandrus: the actual service, which is Identioty v3 for any Identity commands beyond the initial auth sequence | 18:56 |
dtroyer | like project create | 18:56 |
bandrus | dtroyer: in the example of server create... the nova endpoint would be specified? | 18:56 |
dtroyer | yes | 18:56 |
*** chris_hultin is now known as chris_hultin|AWA | 19:01 | |
*** guoshan has joined #openstack-keystone | 19:03 | |
*** guoshan has quit IRC | 19:07 | |
bandrus | dtroyer: would it be common that os-access-token-endpoint be the same as os-endpoint? | 19:12 |
bandrus | i.e. service endpoint | 19:12 |
dtroyer | I don't know what os-access-token-endpoint is | 19:12 |
lbragstad | i think that's for oauth authentication | 19:12 |
bandrus | dtroyer: I had asked earlier if you meant os-access-token-endpoint when you said token_endpoint | 19:12 |
bandrus | but perhaps you meant token_endpoint as the method of auth, and not a parameter to be run with openstackclient | 19:13 |
dtroyer | I must have read past that too quickly then... | 19:13 |
*** dave-mccowan has joined #openstack-keystone | 19:13 | |
dtroyer | —os-auth-type token_endpoint —os-token <token> —os-url <service-url> is the long form, all other auth-related options are ignored (or illegal) for token_auth | 19:14 |
bandrus | ahh! | 19:14 |
dtroyer | normally, the auth-type is detected/assumed when both os-token and -os-url are present so —os-auth-type is not necessary | 19:15 |
bandrus | actually got a request to come back when the endpoint matches that in the service catalog. Thank you dtroyer and lbragstad! | 19:21 |
lbragstad | bandrus awesome - any time! | 19:23 |
bandrus | last question for now: do I essentially need to keep a service catalog handy in order to reference the endpoints manually in making my requests? Obviously that's something that could be automated, but want to make sure it's not something that can be obtained automatically like in password authentication. I think this makes sense since we're essentially bypassing keystone and the service catalog in the keystone response... is | 19:31 |
*** dave-mccowan has quit IRC | 19:32 | |
lbragstad | bandrus are you using the ?no_catalog query parameter when authenticating or validating tokens? | 19:33 |
dtroyer | bandrus: take a look at the similar-but-different admin_token auth type. IIRC it still does the SC lookup, only bypassing the get token bit | 19:34 |
bandrus | okay, in the case of a customer using openstackclient to connect to the cluster - my guess is they are running as such: openstack --os-url https://<glance_endpoint>:9292 --os-token <token> image list | 19:35 |
bandrus | so in that case, they probably just know the endpoints for services they are trying to hit | 19:36 |
dtroyer | I really hope that is an exception and not a normal use case | 19:36 |
dtroyer | some OSc commands will talk to multiple services to do name -> ID lookups for example, those don't work (well) with token_endpoint auth | 19:37 |
dtroyer | as an operator, I would really want to discourage customers from doing that sort of thing, it make you unable to change your service catalog without breaking them | 19:38 |
*** hogepodge has quit IRC | 19:39 | |
bandrus | so upon reading the ticket closer... they specify using "OS_AUTH_URL" of keystone and a token | 19:39 |
dtroyer | that sounds like the admin_token auth (which I don't use), IIRC it wants auth_url to get the service catalog | 19:40 |
dtroyer | that is a much better situation than I thought a minute ago | 19:40 |
dtroyer | it'll still use the SC to find endpoints and the multi-API commands will work | 19:41 |
bandrus | haha, I was just excited to have something working in the form of that less ideal syntax | 19:41 |
dtroyer | it's good to know how to use it, hopefully it is one of those things that you never need, and when you do you'll be happy to know how :) | 19:41 |
bandrus | so in using os-auth-url, the command doesn't seem to like os-token | 19:42 |
*** itisha has joined #openstack-keystone | 19:45 | |
bandrus | I'm more than happy to go do some further reading, I'm finding it hard to find decent documentation on these subjects however... As in "if using this method, this is what is required" | 19:45 |
dtroyer | that may only with with v3 | 19:45 |
dtroyer | there isn't decent docs for this… I'm reading the plugin source to find what arguments are required for admin_token | 19:45 |
dtroyer | and it isn't even clear there | 19:46 |
bandrus | well then, I very much appreciate your help | 19:46 |
dtroyer | hmmmm, I may be meaning v3token auth type rather than admin_token | 19:46 |
bandrus | okay, I do believe they are trying v3token | 19:47 |
lbragstad | dtroyer should we open a doc bug to clear some of that up? or at least track the need? | 19:47 |
dtroyer | lbragstad: maybe? also, jamielennox may have a lot of this written down somewhere that I don't know about | 19:48 |
lbragstad | dtroyer i can make a note to follow up with jamielennox if he isn't already hanging around | 19:49 |
dtroyer | admin_token needs —os-endpoint and —os-token according to keystoneauth/keystoneauth1/loading/_plugins/admin_token.py | 19:49 |
lbragstad | and if he doesn't have it tracked somewhere i'll open one up | 19:49 |
dtroyer | I think v3token wants —os-auth-url and —os-token | 19:50 |
dtroyer | per ../keystoneauth/keystoneauth1/loading/_plugins/identity/v3.py | 19:50 |
dtroyer | can you tell I don't use these often? | 19:50 |
dtroyer | having three similar-yet-different auth type is confusing but back-=compat requires two of them stay around for a while yet | 19:51 |
bandrus | great - I'm playing around... for now, I am getting 404 could not find token (when the same one works when the cinder endpoint is specified directly) - but I'll spend some time generating a new token before wasting anyone's time | 19:54 |
*** edtubill has joined #openstack-keystone | 19:54 | |
bandrus | works great! | 19:55 |
bandrus | thank you again dtroyer and lbragstad. From a user who isn't yet intimately familiar with openstack source, Some documentation that really lays it out would be greatly appreciated. | 19:56 |
lbragstad | bandrus ++ | 19:56 |
*** stingaci has joined #openstack-keystone | 19:56 | |
*** stingaci has quit IRC | 19:56 | |
dtroyer | agreed | 19:57 |
*** guoshan has joined #openstack-keystone | 20:04 | |
*** edtubill has quit IRC | 20:05 | |
*** asettle has joined #openstack-keystone | 20:07 | |
*** guoshan has quit IRC | 20:08 | |
*** asettle has quit IRC | 20:11 | |
*** david-lyle has joined #openstack-keystone | 20:17 | |
*** david-lyle has quit IRC | 20:21 | |
*** rcernin has joined #openstack-keystone | 20:25 | |
*** harlowja has joined #openstack-keystone | 20:49 | |
*** chris_hultin|AWA is now known as chris_hultin | 20:52 | |
*** guoshan has joined #openstack-keystone | 21:04 | |
*** guoshan has quit IRC | 21:09 | |
*** guoshan has joined #openstack-keystone | 22:05 | |
*** guoshan has quit IRC | 22:10 | |
*** markvoelker has joined #openstack-keystone | 22:26 | |
*** markvoelker has quit IRC | 22:30 | |
*** itisha has quit IRC | 22:52 | |
*** guoshan has joined #openstack-keystone | 23:06 | |
*** lamt has quit IRC | 23:10 | |
*** guoshan has quit IRC | 23:10 | |
*** markvoelker has joined #openstack-keystone | 23:26 | |
*** markvoelker has quit IRC | 23:31 | |
kevinbenton | Hi, we've started seeing these warnings in our Neutron logs somewhat recently | 23:42 |
kevinbenton | " A valid token was submitted as a service token, but it was not a valid service token. This is incorrect but backwards compatible behaviour. This will be removed in future releases." | 23:42 |
kevinbenton | coming from keystonemiddleware.auth_token | 23:42 |
kevinbenton | based on the timing of it's appearance, I believe it's on the notification that neutron sends to nova | 23:42 |
kevinbenton | so i suspect our configuration of the credentials used to communicate with nova is not valid | 23:43 |
kevinbenton | What type of credentials should we be using? | 23:43 |
kevinbenton | For reference of how we configure them now, search for "[nova]" in http://logs.openstack.org/32/415632/1/check/gate-tempest-dsvm-neutron-full-ubuntu-xenial/7bd5633/logs/etc/neutron/neutron.conf.txt.gz | 23:44 |
*** chris_hultin is now known as chris_hultin|AWA | 23:45 | |
*** jose-phillips has quit IRC | 23:47 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!