*** martinlopes has quit IRC | 00:01 | |
*** masterjcool has joined #openstack-keystone | 00:01 | |
*** martinlopes has joined #openstack-keystone | 00:03 | |
*** d-bark has joined #openstack-keystone | 00:11 | |
*** martinlopes has quit IRC | 00:17 | |
*** browne has joined #openstack-keystone | 00:18 | |
*** thorst_ has joined #openstack-keystone | 00:19 | |
*** adrian_otto has quit IRC | 00:30 | |
*** chlong has joined #openstack-keystone | 00:32 | |
*** spzala has joined #openstack-keystone | 00:35 | |
*** spzala has quit IRC | 00:40 | |
*** ravelar1 has joined #openstack-keystone | 00:42 | |
*** thorst_ has joined #openstack-keystone | 00:46 | |
*** ravelar1 has quit IRC | 00:47 | |
*** hoangcx has joined #openstack-keystone | 00:54 | |
*** dave-mccowan has joined #openstack-keystone | 00:57 | |
*** edmondsw has joined #openstack-keystone | 01:00 | |
*** ravelar has quit IRC | 01:00 | |
*** edmondsw has quit IRC | 01:04 | |
*** chlong has quit IRC | 01:08 | |
*** wxy has joined #openstack-keystone | 01:10 | |
*** liujiong has joined #openstack-keystone | 01:11 | |
*** browne has quit IRC | 01:13 | |
*** browne has joined #openstack-keystone | 01:16 | |
*** spzala has joined #openstack-keystone | 01:16 | |
*** MasterOfBugs has quit IRC | 01:18 | |
*** spzala has quit IRC | 01:21 | |
*** dave-mccowan has quit IRC | 01:23 | |
*** spzala has joined #openstack-keystone | 01:26 | |
*** thorst_ has joined #openstack-keystone | 01:29 | |
*** thorst_ has quit IRC | 01:32 | |
*** browne has quit IRC | 01:36 | |
*** wllabs has quit IRC | 01:36 | |
*** wllabs has joined #openstack-keystone | 01:39 | |
*** ravelar1 has joined #openstack-keystone | 01:44 | |
*** gyee has quit IRC | 01:46 | |
*** guoshan has joined #openstack-keystone | 01:46 | |
*** ravelar1 has quit IRC | 01:48 | |
*** esp has quit IRC | 01:53 | |
*** dave-mccowan has joined #openstack-keystone | 01:57 | |
*** tqtran has quit IRC | 01:59 | |
*** ngupta has joined #openstack-keystone | 02:09 | |
*** d-bark has quit IRC | 02:11 | |
*** thorst_ has joined #openstack-keystone | 02:17 | |
*** thorst_ has quit IRC | 02:18 | |
*** ravelar1 has joined #openstack-keystone | 02:25 | |
*** ravelar1 has quit IRC | 02:30 | |
*** spzala has quit IRC | 02:35 | |
*** thorst_ has joined #openstack-keystone | 02:38 | |
*** thorst_ has quit IRC | 02:40 | |
*** thorst_ has joined #openstack-keystone | 02:43 | |
*** thorst_ has quit IRC | 02:43 | |
*** thorst_ has joined #openstack-keystone | 02:46 | |
*** thorst_ has quit IRC | 02:51 | |
*** thorst_ has joined #openstack-keystone | 03:01 | |
*** thorst_ has quit IRC | 03:03 | |
openstackgerrit | Cao Xuan Hoang proposed openstack/keystone master: Remove logging import unused https://review.openstack.org/434612 | 03:24 |
---|---|---|
*** ravelar1 has joined #openstack-keystone | 03:26 | |
*** ravelar1 has quit IRC | 03:31 | |
*** nicolasbock has quit IRC | 03:42 | |
*** ngupta has quit IRC | 04:01 | |
*** ngupta has joined #openstack-keystone | 04:01 | |
*** links has joined #openstack-keystone | 04:02 | |
*** guoshan has quit IRC | 04:06 | |
*** ngupta has quit IRC | 04:06 | |
*** dave-mccowan has quit IRC | 04:19 | |
*** adrian_otto has joined #openstack-keystone | 04:26 | |
*** nkinder has joined #openstack-keystone | 04:26 | |
*** esp has joined #openstack-keystone | 04:27 | |
*** esp has quit IRC | 04:27 | |
*** adriant has quit IRC | 04:34 | |
*** jerrygb has quit IRC | 04:41 | |
*** masterjcool has quit IRC | 04:55 | |
*** tqtran has joined #openstack-keystone | 04:57 | |
*** tqtran has quit IRC | 05:02 | |
*** thorst_ has joined #openstack-keystone | 05:04 | |
*** erlon has quit IRC | 05:05 | |
*** guoshan has joined #openstack-keystone | 05:07 | |
*** masterjcool has joined #openstack-keystone | 05:07 | |
*** thorst_ has quit IRC | 05:08 | |
*** guoshan has quit IRC | 05:11 | |
*** dikonoor has joined #openstack-keystone | 05:12 | |
*** adrian_otto has quit IRC | 05:15 | |
*** jaosorior has joined #openstack-keystone | 05:31 | |
*** dikonoor has quit IRC | 05:39 | |
*** adrian_otto has joined #openstack-keystone | 05:52 | |
*** masber has quit IRC | 05:53 | |
*** adrian_otto has quit IRC | 05:54 | |
*** dikonoor has joined #openstack-keystone | 05:57 | |
*** guoshan has joined #openstack-keystone | 06:07 | |
*** guoshan has quit IRC | 06:12 | |
*** prashkre has joined #openstack-keystone | 06:17 | |
*** prashkre has quit IRC | 06:22 | |
*** guoshan has joined #openstack-keystone | 06:24 | |
*** edmondsw has joined #openstack-keystone | 06:29 | |
*** edmondsw has quit IRC | 06:34 | |
*** adrian_otto has joined #openstack-keystone | 06:41 | |
*** richm has quit IRC | 06:42 | |
*** hoangcx has quit IRC | 06:55 | |
*** hoangcx has joined #openstack-keystone | 06:58 | |
*** rcernin has joined #openstack-keystone | 07:03 | |
*** thorst_ has joined #openstack-keystone | 07:05 | |
*** thorst_ has quit IRC | 07:10 | |
*** tesseract has joined #openstack-keystone | 07:13 | |
*** gus_ is now known as gus | 07:32 | |
*** hoangcx has quit IRC | 07:44 | |
*** prashkre has joined #openstack-keystone | 07:49 | |
*** adrian_otto has quit IRC | 07:55 | |
*** hoangcx has joined #openstack-keystone | 07:55 | |
*** tqtran has joined #openstack-keystone | 07:59 | |
*** tqtran has quit IRC | 08:03 | |
*** adrian_otto has joined #openstack-keystone | 08:08 | |
*** pcaruana has joined #openstack-keystone | 08:14 | |
*** pcaruana has quit IRC | 08:20 | |
*** adrian_otto has quit IRC | 08:21 | |
*** pcaruana has joined #openstack-keystone | 08:22 | |
*** d0ugal has joined #openstack-keystone | 08:23 | |
*** thorst_ has joined #openstack-keystone | 08:25 | |
*** guoshan has quit IRC | 08:25 | |
*** thorst_ has quit IRC | 08:30 | |
*** zzzeek has quit IRC | 09:00 | |
*** zzzeek has joined #openstack-keystone | 09:00 | |
*** guoshan has joined #openstack-keystone | 09:26 | |
*** guoshan has quit IRC | 09:30 | |
*** openstackgerrit has quit IRC | 09:32 | |
*** tovin07 has quit IRC | 09:58 | |
*** nishaYadav has joined #openstack-keystone | 09:59 | |
*** nishaYadav is now known as Guest66894 | 10:00 | |
*** Guest66894 is now known as nishaYadav_ | 10:00 | |
nishaYadav_ | o/ | 10:01 |
*** tqtran has joined #openstack-keystone | 10:01 | |
*** tqtran has quit IRC | 10:05 | |
*** mvk has quit IRC | 10:17 | |
*** erlon has joined #openstack-keystone | 10:18 | |
*** guoshan has joined #openstack-keystone | 10:21 | |
*** thorst_ has joined #openstack-keystone | 10:26 | |
*** thorst_ has quit IRC | 10:31 | |
*** liujiong has quit IRC | 10:34 | |
*** hoangcx has quit IRC | 10:36 | |
*** nishaYadav__ has joined #openstack-keystone | 10:42 | |
*** nishaYadav_ has quit IRC | 10:45 | |
*** openstackgerrit has joined #openstack-keystone | 10:51 | |
openstackgerrit | Merged openstack/keystone master: Remove the file encoding which is unnecessary https://review.openstack.org/431807 | 10:51 |
*** guoshan has quit IRC | 10:51 | |
*** mvk has joined #openstack-keystone | 10:52 | |
*** prashkre_ has joined #openstack-keystone | 10:53 | |
*** prashkre has quit IRC | 10:56 | |
*** dikonoor has quit IRC | 10:58 | |
*** nicolasbock has joined #openstack-keystone | 11:05 | |
*** prashkre_ has quit IRC | 11:08 | |
*** richm has joined #openstack-keystone | 11:13 | |
*** jaosorior has quit IRC | 11:16 | |
*** jaosorior has joined #openstack-keystone | 11:17 | |
*** dikonoor has joined #openstack-keystone | 11:26 | |
*** des_consolado has joined #openstack-keystone | 11:27 | |
des_consolado | hey this is the output from requesting a token: http://termbin.com/htjp - what do I actually use as the token? I just realised I was using the user id and I don't think that's right? | 11:32 |
*** dikonoor has quit IRC | 12:00 | |
*** tqtran has joined #openstack-keystone | 12:03 | |
*** dave-mccowan has joined #openstack-keystone | 12:05 | |
*** raildo has joined #openstack-keystone | 12:06 | |
*** tqtran has quit IRC | 12:07 | |
*** Anticime1 is now known as Anticimex | 12:07 | |
*** catintheroof has joined #openstack-keystone | 12:14 | |
*** dikonoor has joined #openstack-keystone | 12:36 | |
*** jerrygb has joined #openstack-keystone | 12:42 | |
*** jerrygb has quit IRC | 12:42 | |
*** jerrygb has joined #openstack-keystone | 12:43 | |
*** thorst_ has joined #openstack-keystone | 12:44 | |
*** edmondsw has joined #openstack-keystone | 12:46 | |
*** chlong has joined #openstack-keystone | 12:56 | |
*** prashkre_ has joined #openstack-keystone | 13:09 | |
*** nishaYadav__ has quit IRC | 13:14 | |
*** rvba` is now known as rvba | 13:14 | |
*** dave-mccowan has quit IRC | 13:19 | |
*** catintheroof has quit IRC | 13:20 | |
*** links has quit IRC | 13:39 | |
*** belmoreira has joined #openstack-keystone | 13:46 | |
*** spilla has joined #openstack-keystone | 13:48 | |
breton | des_consolado: you don't need to use any of that | 14:05 |
breton | des_consolado: the token iself is in the headers | 14:05 |
breton | des_consolado: you need to tell curl (or whatever you use) to display them | 14:06 |
*** ravelar has joined #openstack-keystone | 14:11 | |
*** jperry has joined #openstack-keystone | 14:15 | |
*** adrian_otto has joined #openstack-keystone | 14:21 | |
*** adrian_otto has quit IRC | 14:24 | |
des_consolado | breton: ohhhh, this X-Subject-Token I'm guessing, ty! | 14:29 |
*** ngupta has joined #openstack-keystone | 14:42 | |
*** ngupta_ has joined #openstack-keystone | 14:43 | |
breton | des_consolado: yep | 14:43 |
breton | meanwhile i tried out new mapping capabilities, the one with shadow projects | 14:43 |
breton | so far so good | 14:44 |
lbragstad | breton sweet | 14:44 |
*** ngupta has quit IRC | 14:46 | |
*** dave-mccowan has joined #openstack-keystone | 14:54 | |
*** jose-phillips has joined #openstack-keystone | 14:59 | |
*** jose-phillips has quit IRC | 15:01 | |
*** tqtran has joined #openstack-keystone | 15:04 | |
*** chlong has quit IRC | 15:05 | |
*** spzala has joined #openstack-keystone | 15:07 | |
*** tqtran has quit IRC | 15:09 | |
*** lucasxu has joined #openstack-keystone | 15:15 | |
*** lucasxu has quit IRC | 15:18 | |
*** chris_hultin|AWA is now known as chris_hultin | 15:21 | |
stevemar | breton: nice | 15:23 |
breton | soon i'll show it to larger audience, lets see what they can break :p | 15:24 |
lbragstad | breton oh - i'm sure there is going to be a list ;) | 15:25 |
breton | lbragstad: i hope so! | 15:26 |
*** edtubill has joined #openstack-keystone | 15:28 | |
*** lucasxu has joined #openstack-keystone | 15:34 | |
*** rderose has quit IRC | 15:39 | |
*** woodburn has quit IRC | 15:39 | |
*** ravelar1 has joined #openstack-keystone | 15:40 | |
*** ravelar has quit IRC | 15:40 | |
*** ravelar1 is now known as ravelar | 15:49 | |
*** ravelar has joined #openstack-keystone | 15:50 | |
*** ravelar has quit IRC | 15:52 | |
*** ravelar has joined #openstack-keystone | 15:53 | |
*** pas has joined #openstack-keystone | 15:54 | |
pas | hello! can someone tell me what these None terms mean in the keystone v3 policy? https://github.com/openstack/keystone/blob/master/etc/policy.v3cloudsample.json#L97 | 15:55 |
breton | lol | 15:56 |
breton | looks like a bug to me | 15:56 |
pas | should I file a bug? :) | 15:58 |
*** mvk has quit IRC | 16:03 | |
stevemar | breton: that checks if the domain_id is None, no? | 16:03 |
*** lamt has joined #openstack-keystone | 16:03 | |
*** rcernin has quit IRC | 16:03 | |
*** tqtran has joined #openstack-keystone | 16:06 | |
pas | stevemar: wouldn't that be something like domain_id:None ? The attribute name goes before the colon, no? | 16:07 |
dolphm | lbragstad: this is kind of a huge bucket of topics for 40 minutes https://etherpad.openstack.org/p/pike-ptg-keystone-ocata-carry-over | 16:07 |
*** tqtran has quit IRC | 16:10 | |
*** pcaruana has quit IRC | 16:11 | |
*** tesseract has quit IRC | 16:14 | |
breton | stevemar: no idea | 16:14 |
breton | stevemar: it just looks weird | 16:15 |
lbragstad | dolphm yeah - i agree. we have some free slots on thursday afternoon so I can break a couple out of that session into the free sessions | 16:15 |
dolphm | lbragstad: one* lol | 16:15 |
dolphm | lbragstad: any location for the cross-project quota session? | 16:18 |
dolphm | lbragstad: and is it really 3.5 hours? | 16:18 |
lbragstad | dolphm no - one sec | 16:19 |
lbragstad | dolphm ok - sorry | 16:20 |
lbragstad | dolphm just got out of a meeting - so apparently there is no locked down time for the quota discussion yet | 16:20 |
dolphm | lbragstad: k | 16:20 |
dolphm | lbragstad: so it'll be sometime that afternoon, at least? | 16:20 |
lbragstad | but that is going to be happening as part of the Arch WG sessions | 16:21 |
dolphm | lbragstad: good to know | 16:21 |
lbragstad | and according to their etherpad, they don't have a dedicated time slot | 16:21 |
dolphm | lbragstad: link? | 16:21 |
lbragstad | mriedem was also interested in that session and when I asked him about it, he said that he was only expecting to be pinged whenever that discussion was about to happen | 16:22 |
*** ngupta_ has quit IRC | 16:22 | |
*** ngupta has joined #openstack-keystone | 16:22 | |
lbragstad | dolphm checking | 16:23 |
lbragstad | dolphm http://lists.openstack.org/pipermail/openstack-dev/2017-February/111976.html | 16:24 |
lbragstad | dolphm http://lists.openstack.org/pipermail/openstack-dev/2017-February/112302.html | 16:24 |
dolphm | lbragstad: oh, i just meant to their etherpad | 16:24 |
lbragstad | dolphm Architecture WG - https://etherpad.openstack.org/p/ptg-architecture-workgroup | 16:25 |
dolphm | everything on that etherpad affects keystone | 16:25 |
lbragstad | dolphm yeah - the capabilities discussion is also going to be policy/rbac related | 16:26 |
lbragstad | but it's all happening on tuesday | 16:26 |
lbragstad | we have a couple people that will be there all week - but from what I know, most will still be in transit | 16:26 |
*** prashkre_ has quit IRC | 16:29 | |
lbragstad | dolphm it's kinda strange because I'm not sure how I feel about scheduling duplicate sessions wednesday - friday for very similar topics | 16:32 |
dolphm | lbragstad: duplicate vs cross project stuff? | 16:33 |
lbragstad | dolphm creating duplicate sessions as a result of not being in the cross project stuff | 16:33 |
dolphm | lbragstad: ah, well someone should be there to represent! | 16:34 |
dolphm | lbragstad: i think that's the intent of the overall PTG organization... cross-project sessions comes first and will help drive conversations for individual projects later in the week | 16:34 |
lbragstad | dolphm i know breton will be there all week - and he's opted to go to several of those | 16:34 |
*** belmoreira has quit IRC | 16:46 | |
lbragstad | dolphm ok - i broke the ocata carry over session into three separate sessions based on the free slots we had available | 16:48 |
lbragstad | dolphm https://etherpad.openstack.org/p/pike-ptg-keystone-ocata-carry-over | 16:48 |
dolphm | lbragstad: cool | 16:49 |
lbragstad | dolphm does that work a little better? | 16:49 |
dolphm | lbragstad: definitely | 16:49 |
lbragstad | dolphm thanks for pointing that out :) | 16:50 |
dolphm | lbragstad: i'm trying to flesh out my calendar and went NOPE when i saw that time slot :P | 16:50 |
lbragstad | dolphm good! | 16:50 |
lbragstad | gagehugo I assume you're going to be driving the project/user tags discussion? | 16:51 |
gagehugo | lbragstad yes | 16:52 |
lbragstad | gagehugo did you guys also want to talk about microversions? | 16:53 |
lbragstad | I thought that was you, but I don't remember for sure | 16:53 |
gagehugo | lbragstad we are definitely interesting in it, I don't know who put it up as a topic though | 16:54 |
*** browne has joined #openstack-keystone | 16:54 | |
gagehugo | interested* | 16:54 |
lbragstad | ok | 16:54 |
gagehugo | lbragstad: lamt knows a lot more about it than I do | 16:55 |
lamt | lbragstad: microversion is something we are interested in implementing, but last time it was raised, there wasn't much interested. | 16:57 |
lbragstad | lamt would you be interested in driving that discussion? | 16:57 |
*** nkinder has quit IRC | 16:57 | |
lamt | lbragstad : sure | 16:57 |
lbragstad | cool | 16:58 |
*** ngupta has quit IRC | 16:58 | |
*** ngupta has joined #openstack-keystone | 16:58 | |
*** chlong has joined #openstack-keystone | 16:59 | |
*** jaugustine has joined #openstack-keystone | 17:01 | |
*** thorst_ is now known as thorst_afk | 17:05 | |
*** tqtran has joined #openstack-keystone | 17:06 | |
*** esp has joined #openstack-keystone | 17:11 | |
*** aasthad has joined #openstack-keystone | 17:17 | |
stevemar | lbragstad: lamt last i checked it was proposed as a "community wide goal" | 17:32 |
*** ngupta has quit IRC | 17:34 | |
dolphm | i'd personally like to see some serious analysis on the adoption rates & usability of microversions in the wild before we start rapidly iterating every API in openstack | 17:34 |
*** ngupta has joined #openstack-keystone | 17:34 | |
lamt | dolphm: I believe last stevemar and I checked there were 5 projects with microversions - cinder, nova, manila, ironic, and magnum | 17:35 |
lbragstad | hm | 17:36 |
dolphm | lamt: then it would be good to do that analysis on cinder and nova, as the projects with the largest consistent user bases focused on reliability, etc | 17:37 |
lamt | dolphm: sure - I can poke around in cinder | 17:40 |
lbragstad | that'd be some good information | 17:40 |
lbragstad | stevemar was that goal accepted? | 17:40 |
stevemar | lbragstad: it was not | 17:41 |
*** browne has quit IRC | 17:41 | |
stevemar | lbragstad: but i imagine it will be one day | 17:41 |
lbragstad | ok | 17:41 |
dstanek | i would echo dolphm's comment about understanding the real value before jumping in | 17:42 |
dstanek | is there some consolidated information about what the value proposition is? | 17:43 |
dolphm | dstanek: perfect question | 17:44 |
*** prashkre has joined #openstack-keystone | 17:44 | |
*** spotz is now known as spotz_zzz | 17:48 | |
morgan | 035958 | 17:49 |
morgan | 259358 | 17:49 |
morgan | stupid yubikey | 17:50 |
lbragstad | 623758 | 17:50 |
stevemar | morgan: you pulling a sean spiecer and writing out your OTPs? | 17:50 |
stevemar | lol | 17:50 |
stevemar | you are! | 17:50 |
morgan | except he wrote his password | 17:50 |
stevemar | hehe | 17:50 |
morgan | and those OTPs aren't attached to anything | 17:50 |
lbragstad | rule #1 - write important information like passwords on notecards you use for other important things like presentations | 17:50 |
morgan | Rule #2, tweet said note cards | 17:51 |
*** lucasxu has quit IRC | 17:53 | |
*** lucasxu has joined #openstack-keystone | 17:55 | |
gagehugo | lbragstad https://etherpad.openstack.org/p/community-goals | 17:58 |
lbragstad | gagehugo perfect | 17:59 |
*** spotz_zzz is now known as spotz | 17:59 | |
lamt | gagehugo: thanks, I couldn't find that link. | 18:00 |
*** mvk has joined #openstack-keystone | 18:02 | |
*** ngupta has quit IRC | 18:12 | |
*** ngupta has joined #openstack-keystone | 18:12 | |
*** ravelar has quit IRC | 18:13 | |
*** jaugustine_ has joined #openstack-keystone | 18:19 | |
*** jaugustine__ has joined #openstack-keystone | 18:27 | |
*** jaugustine_ has quit IRC | 18:28 | |
*** jaugustine has quit IRC | 18:28 | |
*** jaugustine__ is now known as jaugustine | 18:28 | |
*** pas has quit IRC | 18:34 | |
*** jaosorior has quit IRC | 18:34 | |
prashkre | lbragstad: Hi Lance. Could you please help me on bug https://bugs.launchpad.net/keystone/+bug/1662514 | 18:47 |
openstack | Launchpad bug 1662514 in OpenStack Identity (keystone) "Revoking a non-existing role revokes token for users of same role" [Undecided,New] | 18:47 |
lbragstad | prashkre sure! | 18:49 |
prashkre | while debugging I found revocation event is being created at https://github.com/openstack/keystone/blob/4ef175926db6785f3c48d3b2c8ff43a3466d3344/keystone/assignment/core.py#L371 | 18:49 |
prashkre | Could you please tell me what is happening when we send at notification of revoke grant at https://github.com/openstack/keystone/blob/029476272fb869c6413aa4e70f4cae6f890e598f/keystone/assignment/core.py#L376 | 18:51 |
dstanek | prashkre: looks like we don't get granular enough on what to revoke | 18:51 |
lbragstad | prashkre https://github.com/openstack/keystone/blob/029476272fb869c6413aa4e70f4cae6f890e598f/keystone/assignment/core.py#L343 is sending off a notification that can be picked up by other parts of the system (in this case the token provider is probably picking that up and removing tokens that fit the criteria of the revocation event) | 18:53 |
lbragstad | which is done here - https://github.com/openstack/keystone/blob/029476272fb869c6413aa4e70f4cae6f890e598f/keystone/assignment/core.py#L289-L291 | 18:54 |
lbragstad | dstanek yeah - that is part of the problem too | 18:54 |
lbragstad | but another issue is that we don't validate the role exists before we start revoking this | 18:54 |
lbragstad | things* | 18:54 |
prashkre | yeah. I am thinking of do check for role exists before revocation_event. If role exists then create a revocation entry for each user in the group with user_id which doesn't the tokens of other tokens. | 18:56 |
*** ravelar has joined #openstack-keystone | 18:59 | |
lbragstad | prashkre that would work - it might run up against performance issues if we start removing roles from groups with thousands of users in them though | 19:00 |
dstanek | prashkre: you mean if role assignments exist? | 19:02 |
prashkre | yes. If role exist on groups. | 19:03 |
*** ravelar has quit IRC | 19:04 | |
prashkre | dstanek: If role assignment exists on the group. To revoke the existing tokens of each user we should have entry in revocation_event table. | 19:05 |
dstanek | prashkre: i like the idea of checking to see if anything needs to be done because an assignment does exist, but i'm not fond of changing how the revocation is issued unless we done some analysis to see what is affected | 19:06 |
morgan | i really don't like creating an entry per user if we can avoid it | 19:11 |
morgan | it starts diving into the same issues as an entry per-token | 19:11 |
dstanek | morgan: exactly] | 19:14 |
dstanek | morgan: i do like not sending them if nothing actually changed | 19:15 |
morgan | dstanek: ++++++++ | 19:17 |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Add Policy Documentation https://review.openstack.org/435078 | 19:25 |
lbragstad | cc johnthetubaguy antwash ^ | 19:26 |
*** jidar has joined #openstack-keystone | 19:28 | |
*** jidar has left #openstack-keystone | 19:29 | |
*** edtubill has quit IRC | 19:30 | |
prashkre | With current implementation, revocation_events will have user_id as NULL when role is revoked on group. so when user token validaiton is happening at https://github.com/openstack/keystone/blob/master/keystone/revoke/core.py#L203, in the next calls at https://github.com/openstack/keystone/blob/master/keystone/revoke/backends/sql.py#L93 it brings up only the matching events of token based on OR(project_id, user_id, audit_id). | 19:35 |
prashkre | At this point, can we have a column in the revocation_event table named group_id which is filled up when group_id being revoked. And here we fetch the events whose token.user_id is part of event.group_id. does this seems a good solution? | 19:35 |
prashkre | lbragstad: https://github.com/openstack/keystone/blob/master/keystone/identity/core.py#L1263 this is place where notification being sent for revoke grant tokens. since notification is sent for respective consumers why do we need revocatoin_event on revoke a role on user or group? | 19:50 |
robcresswell | lbragstad: Meeting in ten, I sent out an email as promised :) | 19:51 |
lbragstad | robcresswell ++ I saw that, thank you! | 19:51 |
lbragstad | prashkre yeah - that is how keystone emits notifications. I'm not sure I understood the second bit of your question though | 19:52 |
*** dikonoor has quit IRC | 19:52 | |
lbragstad | prashkre https://bugs.launchpad.net/keystone/+bug/1406776 is also somewhat related to your bug | 19:52 |
openstack | Launchpad bug 1406776 in OpenStack Identity (keystone) "Trying to delete a grant with an invalid role ID causes unnecessary processing" [Low,Triaged] | 19:52 |
*** chlong has quit IRC | 19:56 | |
prashkre | lbragstad: From my analysis, I have dropped patch of code https://github.com/openstack/keystone/blob/master/keystone/assignment/core.py#L363-L370 where revocation_event is being triggred for groups. still the users in the groups whose tokens got revoked with notification being sent by https://github.com/openstack/keystone/blob/master/keystone/assignment/core.py#L376. | 20:00 |
prashkre | so whey we need revocation_event entries when tokens are revoked with notifications. | 20:01 |
*** lamt has quit IRC | 20:03 | |
prashkre | morgan:dstanek: pls help me by reviewing my 2nd solution in previous msgs. | 20:04 |
*** ayoung has quit IRC | 20:07 | |
*** lamt has joined #openstack-keystone | 20:08 | |
*** spzala has quit IRC | 20:19 | |
dstanek | prashkre: one this is revoking the token and the other is doing a notification | 20:19 |
*** lucasxu has quit IRC | 20:19 | |
*** lucasxu has joined #openstack-keystone | 20:19 | |
*** ayoung has joined #openstack-keystone | 20:20 | |
*** ChanServ sets mode: +v ayoung | 20:20 | |
dstanek | prashkre: are you finding somewhere in code that we revoke twice? | 20:22 |
prashkre | dstanek: I am guessing notification is meant to revoke the token. so why we do have revoke of token again. | 20:22 |
dstanek | prashkre: are we revoking it twice? because that would be a bug | 20:23 |
dstanek | prashkre: iirc the callbacks are removing tokens from cache...checking | 20:25 |
*** lucasxu has quit IRC | 20:26 | |
*** lucasxu has joined #openstack-keystone | 20:26 | |
dstanek | prashkre: maybe it's possible to revoke twice based on a config setting? https://github.com/openstack/keystone/blob/master/keystone/token/provider.py#L311 | 20:28 |
lbragstad | dstanek or an in-code option ;) | 20:29 |
dstanek | prashkre: you'll have to experiment and see what's actually happening in there | 20:31 |
dstanek | lbragstad: sssshhhhh... get back to the meeting :-) | 20:32 |
prashkre | dstanek: sure. looking at it. | 20:35 |
*** aleph1 is now known as agarner_away | 20:54 | |
*** ravelar has joined #openstack-keystone | 20:55 | |
*** lucasxu has quit IRC | 21:14 | |
*** lucasxu has joined #openstack-keystone | 21:14 | |
*** prashkre has quit IRC | 21:20 | |
*** dave-mccowan has quit IRC | 21:21 | |
*** ngupta has quit IRC | 21:22 | |
*** ngupta has joined #openstack-keystone | 21:23 | |
*** chris_hultin is now known as chris_hultin|AWA | 21:29 | |
*** ngupta has quit IRC | 21:32 | |
*** ngupta has joined #openstack-keystone | 21:32 | |
*** lucasxu has quit IRC | 21:33 | |
*** MasterOfBugs has joined #openstack-keystone | 21:33 | |
*** lucasxu has joined #openstack-keystone | 21:33 | |
*** jerrygb has quit IRC | 21:41 | |
*** edmondsw has quit IRC | 21:52 | |
*** edmondsw has joined #openstack-keystone | 21:53 | |
*** edmondsw has quit IRC | 21:57 | |
*** ravelar has quit IRC | 22:04 | |
*** chlong has joined #openstack-keystone | 22:05 | |
*** chlong has quit IRC | 22:11 | |
*** ravelar has joined #openstack-keystone | 22:12 | |
*** chris_hultin|AWA is now known as chris_hultin | 22:13 | |
*** bknudson has left #openstack-keystone | 22:14 | |
*** bknudson has joined #openstack-keystone | 22:14 | |
*** ChanServ sets mode: +v bknudson | 22:14 | |
*** dave-mccowan has joined #openstack-keystone | 22:14 | |
*** portdirect is now known as intlabs | 22:17 | |
*** spilla has quit IRC | 22:21 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Force SQLite to properly deal with foreign keys https://review.openstack.org/126030 | 22:27 |
*** adriant has joined #openstack-keystone | 22:34 | |
*** thorst_afk has quit IRC | 22:39 | |
*** martinlopes has joined #openstack-keystone | 22:46 | |
*** lamt has quit IRC | 22:47 | |
*** lamt has joined #openstack-keystone | 22:48 | |
*** ngupta has quit IRC | 22:49 | |
*** lamt has quit IRC | 22:50 | |
*** chris_hultin is now known as chris_hultin|AWA | 22:56 | |
*** jamielennox is now known as jamielennox|away | 23:02 | |
*** catintheroof has joined #openstack-keystone | 23:02 | |
*** thorst_afk has joined #openstack-keystone | 23:03 | |
*** lamt has joined #openstack-keystone | 23:03 | |
*** dave-mccowan has quit IRC | 23:06 | |
*** thorst_afk has quit IRC | 23:07 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone master: Updated from global requirements https://review.openstack.org/431886 | 23:11 |
*** jamielennox|away is now known as jamielennox | 23:14 | |
*** lucasxu has quit IRC | 23:15 | |
*** jperry has quit IRC | 23:28 | |
*** lamt has quit IRC | 23:30 | |
*** martinlopes has quit IRC | 23:36 | |
*** edmondsw has joined #openstack-keystone | 23:49 | |
*** jaugustine has quit IRC | 23:51 | |
*** edmondsw has quit IRC | 23:53 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!