*** david-lyle has joined #openstack-keystone | 00:08 | |
*** david-lyle has quit IRC | 00:15 | |
*** lamt has quit IRC | 00:18 | |
*** browne has quit IRC | 00:18 | |
openstackgerrit | Merged openstack/keystoneauth master: Remove pbr warnerrors in favor of sphinx check https://review.openstack.org/439797 | 00:22 |
---|---|---|
*** thorst has joined #openstack-keystone | 00:25 | |
*** spzala has joined #openstack-keystone | 00:25 | |
*** dave-mccowan has joined #openstack-keystone | 00:26 | |
*** thorst has quit IRC | 00:29 | |
openstackgerrit | Merged openstack/keystoneauth master: Allow users to specify request matchers in Betamax https://review.openstack.org/443254 | 00:35 |
*** catintheroof has quit IRC | 00:46 | |
*** zhurong has joined #openstack-keystone | 00:47 | |
*** Shunli has joined #openstack-keystone | 00:50 | |
*** ngupta has quit IRC | 00:53 | |
*** david-lyle has joined #openstack-keystone | 00:54 | |
*** ngupta has joined #openstack-keystone | 00:54 | |
*** david-lyle has quit IRC | 00:54 | |
*** ngupta has quit IRC | 00:59 | |
*** dave-mccowan has quit IRC | 01:02 | |
*** thorst has joined #openstack-keystone | 01:02 | |
openstackgerrit | Merged openstack/keystoneauth master: Updated from global requirements https://review.openstack.org/439317 | 01:11 |
*** liujiong has joined #openstack-keystone | 01:11 | |
*** namnh has joined #openstack-keystone | 01:21 | |
openstackgerrit | Merged openstack/keystone master: Remove pbr warnerrors in favor of sphinx check https://review.openstack.org/439674 | 01:21 |
*** MasterOfBugs has quit IRC | 01:22 | |
*** adrian_otto has quit IRC | 01:46 | |
*** dave-mcc_ has joined #openstack-keystone | 01:50 | |
*** david-lyle has joined #openstack-keystone | 01:52 | |
*** guoshan has joined #openstack-keystone | 02:00 | |
*** thorst has joined #openstack-keystone | 02:03 | |
*** thorst has quit IRC | 02:08 | |
*** spzala has quit IRC | 02:10 | |
*** phalmos_ has quit IRC | 02:12 | |
*** markvoelker has quit IRC | 02:23 | |
*** erlon has quit IRC | 02:25 | |
*** knangia has quit IRC | 02:31 | |
*** rderose has quit IRC | 02:38 | |
*** ngupta has joined #openstack-keystone | 02:39 | |
*** ngupta has quit IRC | 02:41 | |
*** ngupta has joined #openstack-keystone | 02:42 | |
*** dave-mcc_ has quit IRC | 02:54 | |
*** thorst has joined #openstack-keystone | 02:54 | |
*** thorst has quit IRC | 02:54 | |
*** namnh_ has joined #openstack-keystone | 02:54 | |
*** namnh has quit IRC | 02:56 | |
*** ravelar has quit IRC | 02:57 | |
*** prashkre has joined #openstack-keystone | 03:01 | |
*** nicolasbock has joined #openstack-keystone | 03:10 | |
*** frontrunner has joined #openstack-keystone | 03:15 | |
*** thorst has joined #openstack-keystone | 03:16 | |
*** thorst has quit IRC | 03:17 | |
*** nicolasbock has quit IRC | 03:19 | |
*** markvoelker has joined #openstack-keystone | 03:24 | |
*** markvoelker has quit IRC | 03:29 | |
*** guoshan has quit IRC | 03:46 | |
*** namnh_ has quit IRC | 03:59 | |
*** frontrunner has quit IRC | 04:05 | |
*** jamielennox is now known as jamielennox|away | 04:13 | |
*** links has joined #openstack-keystone | 04:17 | |
*** thorst has joined #openstack-keystone | 04:17 | |
*** thorst has quit IRC | 04:22 | |
*** chris_hultin|AWA is now known as chris_hultin | 04:24 | |
*** prashkre has quit IRC | 04:24 | |
*** prashkre has joined #openstack-keystone | 04:24 | |
*** markvoelker has joined #openstack-keystone | 04:25 | |
*** guoshan has joined #openstack-keystone | 04:26 | |
*** markvoelker has quit IRC | 04:29 | |
*** guoshan has quit IRC | 04:31 | |
*** chris_hultin is now known as chris_hultin|AWA | 04:43 | |
*** prashkre has quit IRC | 04:43 | |
*** jamielennox|away is now known as jamielennox | 04:47 | |
*** ravelar has joined #openstack-keystone | 04:54 | |
*** Trident has quit IRC | 05:13 | |
*** thorst has joined #openstack-keystone | 05:18 | |
*** ngupta has quit IRC | 05:19 | |
*** ngupta has joined #openstack-keystone | 05:20 | |
*** guoshan has joined #openstack-keystone | 05:21 | |
*** thorst has quit IRC | 05:23 | |
*** ngupta has quit IRC | 05:24 | |
*** guoshan has quit IRC | 05:25 | |
*** markvoelker has joined #openstack-keystone | 05:25 | |
*** jose-phillips has quit IRC | 05:30 | |
*** markvoelker has quit IRC | 05:30 | |
*** adriant has quit IRC | 05:50 | |
*** links has quit IRC | 06:04 | |
openstackgerrit | Gage Hugo proposed openstack/keystone-specs master: Add Project tags https://review.openstack.org/431785 | 06:12 |
*** edmondsw has joined #openstack-keystone | 06:13 | |
*** guoshan has joined #openstack-keystone | 06:15 | |
*** links has joined #openstack-keystone | 06:16 | |
*** murugesh_ has joined #openstack-keystone | 06:16 | |
murugesh_ | Hi There, I have configured swift mitaka on centos 7 | 06:17 |
*** edmondsw has quit IRC | 06:17 | |
murugesh_ | when i run "swift stat --debug" command on keystone server | 06:18 |
*** prashkre has joined #openstack-keystone | 06:19 | |
murugesh_ | i get 503 service unavailable error | 06:19 |
*** thorst has joined #openstack-keystone | 06:19 | |
*** guoshan has quit IRC | 06:19 | |
murugesh_ | when i check log of /var/log/swift/swift.log i see below error | 06:20 |
murugesh_ | proxy-server: Unable to validate token: Identity server rejected authorization necessary to fetch token data | 06:21 |
*** thorst has quit IRC | 06:24 | |
*** henrynash has joined #openstack-keystone | 06:35 | |
*** jose-phillips has joined #openstack-keystone | 06:37 | |
*** venki1 has joined #openstack-keystone | 06:39 | |
*** rrr has joined #openstack-keystone | 06:40 | |
*** venki1 has left #openstack-keystone | 06:42 | |
*** rrr has quit IRC | 06:42 | |
*** richm has quit IRC | 06:43 | |
*** rcernin has joined #openstack-keystone | 06:44 | |
*** henrynash has quit IRC | 06:53 | |
*** links has quit IRC | 06:58 | |
*** guoshan has joined #openstack-keystone | 07:09 | |
*** jamielennox is now known as jamielennox|away | 07:09 | |
*** jose-phillips has quit IRC | 07:12 | |
*** guoshan has quit IRC | 07:13 | |
*** links has joined #openstack-keystone | 07:15 | |
*** thorst has joined #openstack-keystone | 07:20 | |
*** jose-phillips has joined #openstack-keystone | 07:20 | |
*** tesseract has joined #openstack-keystone | 07:22 | |
*** thorst has quit IRC | 07:24 | |
*** h5t4_ has joined #openstack-keystone | 07:25 | |
*** jamielennox|away is now known as jamielennox | 07:27 | |
*** guoshan has joined #openstack-keystone | 07:44 | |
*** Jack_I has joined #openstack-keystone | 07:58 | |
*** prashkre has quit IRC | 08:00 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystoneauth master: Remove unused test requirement pycrypto https://review.openstack.org/443318 | 08:06 |
*** guoshan has quit IRC | 08:08 | |
*** guoshan has joined #openstack-keystone | 08:17 | |
*** thorst has joined #openstack-keystone | 08:21 | |
*** thorst has quit IRC | 08:25 | |
*** pnavarro has joined #openstack-keystone | 08:26 | |
*** jaosorior has joined #openstack-keystone | 08:28 | |
openstackgerrit | Tuan Luong-Anh proposed openstack/keystonemiddleware master: Indicating the location tests directory in oslo_debug_helper https://review.openstack.org/443487 | 08:34 |
*** henrynash has joined #openstack-keystone | 08:37 | |
*** henrynash has quit IRC | 08:41 | |
*** henrynash has joined #openstack-keystone | 08:44 | |
*** prashkre has joined #openstack-keystone | 08:45 | |
*** markvoelker has joined #openstack-keystone | 08:46 | |
*** guoshan has quit IRC | 08:54 | |
*** guoshan has joined #openstack-keystone | 08:56 | |
*** zzzeek has quit IRC | 09:00 | |
*** zzzeek has joined #openstack-keystone | 09:02 | |
*** pnavarro has quit IRC | 09:04 | |
*** thorst has joined #openstack-keystone | 09:22 | |
*** Dave____ has joined #openstack-keystone | 09:24 | |
*** namnh has joined #openstack-keystone | 09:26 | |
*** Dave has quit IRC | 09:29 | |
*** Dave____ is now known as Dave | 09:29 | |
*** thorst has quit IRC | 09:31 | |
*** Shunli has quit IRC | 09:31 | |
*** guoshan has quit IRC | 09:34 | |
*** guoshan has joined #openstack-keystone | 09:34 | |
*** pnavarro has joined #openstack-keystone | 09:43 | |
*** edmondsw has joined #openstack-keystone | 09:50 | |
*** edmondsw has quit IRC | 09:54 | |
*** namnh has quit IRC | 10:06 | |
*** tovin07 has quit IRC | 10:11 | |
*** richm has joined #openstack-keystone | 10:14 | |
*** liujiong has quit IRC | 10:19 | |
*** edmondsw has joined #openstack-keystone | 10:22 | |
*** edmondsw has quit IRC | 10:26 | |
openstackgerrit | Merged openstack/keystoneauth master: Remove unused test requirement pycrypto https://review.openstack.org/443318 | 10:27 |
*** Jack_I has quit IRC | 10:28 | |
*** Jack_I has joined #openstack-keystone | 10:29 | |
*** guoshan has quit IRC | 10:33 | |
*** mvk has quit IRC | 10:48 | |
*** henrynash has joined #openstack-keystone | 11:05 | |
*** mvk has joined #openstack-keystone | 11:27 | |
*** thorst has joined #openstack-keystone | 11:28 | |
*** nicolasbock has joined #openstack-keystone | 11:32 | |
*** markvoelker has quit IRC | 11:33 | |
*** thorst has quit IRC | 11:33 | |
*** prashkre has quit IRC | 11:41 | |
*** raildo has joined #openstack-keystone | 12:01 | |
*** prashkre has joined #openstack-keystone | 12:03 | |
*** zhurong has quit IRC | 12:08 | |
*** henrynash has quit IRC | 12:14 | |
*** henrynash has joined #openstack-keystone | 12:17 | |
*** rdo has joined #openstack-keystone | 12:20 | |
*** henrynash has quit IRC | 12:20 | |
*** rdo_ has quit IRC | 12:22 | |
*** thorst has joined #openstack-keystone | 12:37 | |
*** thiagolib has joined #openstack-keystone | 12:52 | |
*** dave-mccowan has joined #openstack-keystone | 12:57 | |
*** jaosorior is now known as jaosorior_brb | 13:03 | |
*** edmondsw has joined #openstack-keystone | 13:12 | |
*** frontrunner has joined #openstack-keystone | 13:20 | |
*** murugesh_ has quit IRC | 13:29 | |
*** chlong_ has joined #openstack-keystone | 13:33 | |
*** lamt has joined #openstack-keystone | 13:58 | |
*** spilla has joined #openstack-keystone | 13:59 | |
lbragstad | sigmavirus https://review.openstack.org/#/c/443661/ | 14:26 |
*** lamt has quit IRC | 14:27 | |
*** lamt has joined #openstack-keystone | 14:31 | |
*** links has quit IRC | 14:35 | |
*** jaosorior_brb is now known as jaosorior | 14:43 | |
*** adrian_otto has joined #openstack-keystone | 14:45 | |
*** ngupta has joined #openstack-keystone | 14:48 | |
*** lamt has quit IRC | 14:53 | |
*** prashkre has quit IRC | 15:06 | |
*** thorst is now known as thorst_afk | 15:06 | |
*** lamt has joined #openstack-keystone | 15:09 | |
*** spzala has joined #openstack-keystone | 15:15 | |
*** ravelar has quit IRC | 15:16 | |
*** chlong_ has quit IRC | 15:17 | |
*** rderose has joined #openstack-keystone | 15:18 | |
*** agrebennikov has joined #openstack-keystone | 15:20 | |
*** rderose has quit IRC | 15:23 | |
*** rderose has joined #openstack-keystone | 15:24 | |
*** ravelar has joined #openstack-keystone | 15:27 | |
*** adrian_otto has quit IRC | 15:32 | |
openstackgerrit | Richard Avelar proposed openstack/keystone master: Validate rolling upgrade is run in order https://review.openstack.org/437441 | 15:33 |
lbragstad | notmorgan jamielennox quick question on ksc, we talked about deprecating it at the PTG | 15:40 |
notmorgan | I said I'd like to. | 15:40 |
notmorgan | don't thing we can | 15:40 |
notmorgan | think* | 15:40 |
lbragstad | notmorgan jamielennox but if i remember the deprecations session correctly, deprecating ksc is contingent on talking to dtroyer_zz and mordred ? | 15:40 |
notmorgan | if shade and OSC stop using it... poasible | 15:41 |
lbragstad | notmorgan did that conversation happen? | 15:41 |
notmorgan | well, me for shade | 15:41 |
notmorgan | and that is happening. | 15:41 |
notmorgan | iirc dtroyer_zz wasn't opposed. | 15:42 |
notmorgan | but it is a ton of work | 15:42 |
lbragstad | ok - that's what i figured | 15:42 |
lbragstad | i was just looking through some of the python-keystoneclient reviews and wondering if some of them were still applicable if our plan is to deprecate it | 15:43 |
openstackgerrit | Richard Avelar proposed openstack/keystone master: Validate rolling upgrade is run in order https://review.openstack.org/437441 | 15:43 |
notmorgan | I would love to just let ksc not get new code and push on dropping it completely. | 15:44 |
notmorgan | I don't know how viable that is. | 15:44 |
lbragstad | right | 15:44 |
lbragstad | doesn't sound like we can do that until we know work will be done in shade and osc to not use ksc | 15:44 |
notmorgan | shade is actively in process | 15:44 |
lbragstad | cool - do you think that is something that will be done this release? | 15:45 |
notmorgan | I am working on fixing tests, once that is done, actual calls will be fixed | 15:45 |
mordred | yah. notmorgan will have ksc erradicated soon :) | 15:45 |
lbragstad | not that it needs to, i'm just curious | 15:45 |
notmorgan | god I hope so | 15:45 |
lbragstad | ok - cool | 15:45 |
notmorgan | if it isn't done early in this cycle I'm quitting keystone core | 15:45 |
* mordred hands notmorgan an extra pie | 15:45 | |
notmorgan | my eyes will be bleeding too much | 15:45 |
mordred | notmorgan: who needs eyes? | 15:46 |
notmorgan | I won't be able to review code anymore or write it :P | 15:46 |
mordred | notmorgan: dictation? | 15:46 |
lbragstad | so it sounds like we really just need to follow up with dtroyer_zz | 15:46 |
breton | huh | 15:47 |
mordred | notmorgan: speaking of: https://review.openstack.org/#/c/443693/ is an occ patch that fixes a ksc workaround we have in occ | 15:47 |
breton | how do i get a list of projects without ksc? | 15:47 |
lbragstad | breton osc | 15:47 |
mordred | breton: either use OSC or shade or REST | 15:47 |
lbragstad | which would have to be changed to call keystone directly instead of relying on ksc | 15:47 |
mordred | yup | 15:47 |
breton | but | 15:47 |
breton | why | 15:47 |
lbragstad | because its another library we have to maintain that doesn't really buy us much | 15:48 |
mordred | yah - and osc is the command line tool - there's no need to have two | 15:48 |
mordred | other than hysterical raisins | 15:48 |
notmorgan | "hey Google, write some.code" "line break, line break, Dee ee eff space make underscore keystone underscore endpoint open paren self..." | 15:48 |
notmorgan | mordred lbragstad ++ | 15:49 |
notmorgan | well we don't have CLI in ksc | 15:49 |
breton | and nobody uses it to query stuff from their python scripts? | 15:50 |
notmorgan | that was killed a while ago, KSC for thin wrapping of the API and provides next to zero value | 15:50 |
notmorgan | use rest or shade | 15:50 |
mordred | yah - basically ALL of the python client library wrappers actually make things more complex than add value | 15:50 |
mordred | ++ | 15:50 |
rodrigods | wow | 15:51 |
lbragstad | and when you have as many projects under the openstack umbrella as we do - it might be arguable better to not have all those thin wrappers everywhere | 15:51 |
rodrigods | you are all rebels | 15:51 |
notmorgan | ++ | 15:52 |
notmorgan | shade is a great wrapper if you need it | 15:52 |
notmorgan | if you don't, use the rest API. | 15:53 |
*** larsks has joined #openstack-keystone | 15:53 | |
notmorgan | shade provides real value as it fixes cloud differences. we don't need two (or a ton) of things doing that | 15:53 |
rodrigods | ^ that's basically how tempest does | 15:53 |
notmorgan | if KSC had done that at some point, shade might not have existed. it exists now though, so let's drop KSC :) | 15:54 |
rodrigods | i mean, uses the rest API | 15:54 |
larsks | I have a keystone server that reports api version 3.4. My client is calling /v3/role_assignments?include_names=True, but is not getting any names in the response. Was that feature added post-3.4? | 15:54 |
mordred | rodrigods: yup. turns out using the REST API works really well | 15:55 |
mordred | rodrigods: unless you have to deal with a bunch of different cloud versions all at the same time - in which case, like notmorgan said, you probably want shade anyway | 15:55 |
rodrigods | mordred, hmm | 15:56 |
dolphm | larsks: this says include_names was introduced in 3.6 https://developer.openstack.org/api-ref/identity/v3/?expanded=list-roles-detail,list-role-assignments-detail#list-role-assignments | 15:56 |
knikolla | o/ | 15:57 |
larsks | dolphm: ah, thanks. I was looking at the "new in..." details at the top of the page and missed the per-call notation. | 15:57 |
*** rcernin has quit IRC | 15:58 | |
*** jaosorior has quit IRC | 15:59 | |
*** chris_hultin|AWA is now known as chris_hultin | 16:00 | |
breton | who's going to fix all the http://codesearch.openstack.org/?q=from%20keystoneclient%20import&i=nope&files=&repos= ? | 16:02 |
dolphm | breton: +1 | 16:03 |
breton | "import keystoneclient" shows 236 files | 16:04 |
breton | "from keystoneclient" 976 files | 16:05 |
*** links has joined #openstack-keystone | 16:07 | |
lbragstad | yeah - if this is something we end up doing, it certainly isn't going to happen overnight | 16:09 |
lbragstad | dstanek are you still not a fan of the design here? https://review.openstack.org/#/c/261188/23 | 16:10 |
*** h5t4_ has quit IRC | 16:11 | |
dstanek | lbragstad: yeah. it's a hacky way to do it | 16:11 |
lbragstad | dstanek i haven't reviewed it in a long time - trying to catch back up on it now | 16:14 |
mordred | lbragstad, breton: well, a non-zero number of those are in keystoneclient, deb-keystoneclient, keystonemiddleware and deb-keystonemiddleware :) | 16:14 |
mordred | so there's work for sure, but some of it may fall out naturally | 16:15 |
rderose | notmorgan samueldmq: "Security Hardening: PCI DSS and security compliance within Keystone" (Accepted) | 16:17 |
dstanek | lbragstad: i can't look at it anymore. the thought of it makes me cry and seeing the code may make my eyes bleed. | 16:17 |
lbragstad | dstanek what the biggest thing you don't agree with about the design? | 16:18 |
*** jaosorior has joined #openstack-keystone | 16:19 | |
dstanek | adding attributes to the python builtin types | 16:20 |
dstanek | lbragstad: if we plan on deprecating it anyway we don't need this change right? | 16:21 |
*** aasthad has joined #openstack-keystone | 16:22 | |
lbragstad | dstanek well - i assume if we deprecate ksc, then we'll have to put some equivalent into osc | 16:22 |
lbragstad | does osc already do this? | 16:22 |
openstackgerrit | Richard Avelar proposed openstack/keystone master: Add group_members_are_ids to whitelisted options https://review.openstack.org/442048 | 16:23 |
dstanek | lbragstad: we wouldn't have to. we're already providing the header in the response | 16:24 |
dstanek | i hope they wouldn't implement it with this sort of design | 16:24 |
lbragstad | dstanek oh - so for osc this isn't a problem | 16:25 |
dolphm | dstanek: what patch are you talking about? | 16:25 |
lbragstad | dolphm https://review.openstack.org/#/c/261188 | 16:25 |
dstanek | lbragstad: if they don't expose it then they may have some work to do, but this wouldn't change that | 16:26 |
dolphm | oh, this conversation | 16:26 |
dolphm | man, this is old | 16:26 |
lbragstad | i know :( | 16:27 |
dstanek | dolphm: when will it end? | 16:27 |
dolphm | dstanek: whenever you end it | 16:27 |
lbragstad | that's why i want to come to consensus on it | 16:27 |
dolphm | i 100% defer to dstanek on that patch | 16:27 |
lbragstad | dolphm you seemed ok with the patch in previous reviews | 16:27 |
dolphm | lbragstad: and then i listened to dstanek and backed away slowly | 16:28 |
lbragstad | bah | 16:28 |
lbragstad | dstanek so - your issue is solely based on the design of the approach and not the problem itself? | 16:29 |
dstanek | lbragstad: yes. i proposed an alternative solution. i just need to finish tests for it | 16:30 |
lbragstad | ok - cool | 16:30 |
dstanek | at PTG we discussed this would be a good way forward if we were still keeping ksc. | 16:31 |
*** adrian_otto has joined #openstack-keystone | 16:31 | |
samueldmq | rderose: notmorgan \o/ | 16:38 |
*** thorst_afk is now known as thorst | 16:38 | |
rderose | samueldmq: you got the "live" demo portion ;) | 16:38 |
rderose | haha | 16:39 |
*** knangia has joined #openstack-keystone | 16:39 | |
lbragstad | dstanek cool - well i updated with my comments | 16:40 |
lbragstad | dstanek thanks for filling me in! | 16:40 |
samueldmq | rderose: ok, now we will have a demo which will be using a machine entirely setup by the engineer who developed these features! | 16:41 |
rderose | haha | 16:41 |
samueldmq | so.... it's not my fault if it doesn't work as expected. thanks ron | 16:41 |
*** spzala has quit IRC | 16:46 | |
*** browne has joined #openstack-keystone | 16:55 | |
*** phalmos has joined #openstack-keystone | 16:56 | |
*** lucasxu has joined #openstack-keystone | 16:57 | |
openstackgerrit | Merged openstack/keystone master: Add in-code comment to clarify pattern in tests https://review.openstack.org/441187 | 17:05 |
openstackgerrit | Merged openstack/keystone master: Fix the typo https://review.openstack.org/443512 | 17:06 |
openstackgerrit | Merged openstack/keystone master: Test for fernet rotation recovery after disk full https://review.openstack.org/442554 | 17:06 |
*** 7GHAAIPWH has joined #openstack-keystone | 17:06 | |
*** lucasxu has quit IRC | 17:08 | |
*** markvoelker has joined #openstack-keystone | 17:08 | |
openstackgerrit | Merged openstack/keystone master: Fix the s3tokens endpoint https://review.openstack.org/437012 | 17:08 |
* dtroyer_zz in a short break… | 17:08 | |
dtroyer_zz | dropping KSC has to have a replacement for OSC… I'm not sure we want to use shade in OSC, and it seems goofy to do the REST wrappers twice… | 17:09 |
timburke | thanks rderose! | 17:09 |
dtroyer_zz | I would totally be in favor of ksc-lite that only takes a Session object and goes and does the REST work | 17:10 |
dtroyer_zz | lbragstad, mordred, notmorgan ^^^ | 17:11 |
*** ngupta has quit IRC | 17:11 | |
lbragstad | dtroyer_zz is that something we could do with ksa? | 17:11 |
*** mvk has quit IRC | 17:12 | |
*** ngupta has joined #openstack-keystone | 17:12 | |
notmorgan | lbragstad: it couldn't be baked into ksa | 17:13 |
*** ravelar1 has joined #openstack-keystone | 17:15 | |
*** lucasxu has joined #openstack-keystone | 17:17 | |
*** lucasxu has quit IRC | 17:17 | |
*** ngupta has quit IRC | 17:18 | |
rderose | timburke: you bet! | 17:18 |
*** ngupta has joined #openstack-keystone | 17:18 | |
*** prashkre has joined #openstack-keystone | 17:20 | |
lbragstad | notmorgan dtroyer_zz got it | 17:23 |
lbragstad | dtroyer_zz notmorgan so moving forward all ksc would only be a super thin wrapper? | 17:24 |
lbragstad | or is that something that should live in osc? | 17:24 |
*** jaugustine has joined #openstack-keystone | 17:26 | |
*** jaosorior has quit IRC | 17:29 | |
lbragstad | knikolla do we have a release note going somewhere for the removal of the LDAP write stuff? | 17:33 |
*** jaugustine has quit IRC | 17:37 | |
dtroyer_zz | I'll do it in OSC if nobody else wants to use it | 17:40 |
lbragstad | dtroyer_zz cool - that'd be awesome | 17:41 |
*** tesseract has quit IRC | 17:42 | |
lbragstad | dtroyer_zz best way to communicate that? mailing list? | 17:43 |
*** ngupta has quit IRC | 17:43 | |
*** ngupta has joined #openstack-keystone | 17:43 | |
*** mvk has joined #openstack-keystone | 17:47 | |
*** prashkre has quit IRC | 17:48 | |
*** browne has quit IRC | 17:50 | |
*** prashkre has joined #openstack-keystone | 17:51 | |
*** lucasxu has joined #openstack-keystone | 17:58 | |
*** links has quit IRC | 18:04 | |
*** adrian_otto has quit IRC | 18:05 | |
*** 7GHAAIPWH has quit IRC | 18:08 | |
*** 7IZAAPDYC has joined #openstack-keystone | 18:09 | |
openstackgerrit | Merged openstack/keystone master: Change is_admin_project to False by default https://review.openstack.org/438035 | 18:19 |
*** browne has joined #openstack-keystone | 18:36 | |
*** ngupta has quit IRC | 18:36 | |
*** ngupta has joined #openstack-keystone | 18:37 | |
knikolla | lbragstad: yes https://github.com/openstack/keystone/blob/master/releasenotes/notes/removed-as-of-ocata-436bb4b839e74494.yaml#L6-L7 | 18:44 |
*** henrynash has joined #openstack-keystone | 18:50 | |
*** thiagolib has quit IRC | 18:51 | |
*** 7IZAAPDYC has quit IRC | 18:54 | |
lbragstad | knikolla ah - sweet | 18:54 |
*** henrynash_ has joined #openstack-keystone | 18:54 | |
lbragstad | knikolla i didn't know that was there - thanks! | 18:54 |
*** henrynash has quit IRC | 18:55 | |
*** henrynash_ is now known as henrynash | 18:55 | |
*** adrian_otto has joined #openstack-keystone | 18:55 | |
*** h5t4 has joined #openstack-keystone | 18:55 | |
*** henrynash has quit IRC | 18:59 | |
lbragstad | ravelar1 o/ | 18:59 |
*** henrynash has joined #openstack-keystone | 18:59 | |
ravelar1 | lbragstad o/ | 19:00 |
lbragstad | about https://review.openstack.org/#/c/371165/ ? | 19:00 |
lbragstad | ravelar1 maybe a better place to start is to see if https://bugs.launchpad.net/keystone/+bug/1511775 is still applicable | 19:00 |
openstack | Launchpad bug 1511775 in OpenStack Identity (keystone) "Revoking a role revokes the unscoped token for a user" [Medium,In progress] | 19:00 |
lbragstad | I assume it is, but updating it with fresh information might not be a bad idea since a lot as changed in the token provider | 19:01 |
ravelar1 | lbragstad well, worked on it 7 months ago but after the performance gain in revocations with https://review.openstack.org/#/c/382107/ | 19:01 |
ravelar1 | I wasn't sure if it was still necessary | 19:01 |
ravelar1 | lbragstad, ah I will check it out | 19:02 |
lbragstad | ravelar1 yeah - that's the big question, because according to https://bugs.launchpad.net/keystone/+bug/1511775 a fix is still necessary if we're revoking unscoped tokens on role removal | 19:02 |
openstack | Launchpad bug 1511775 in OpenStack Identity (keystone) "Revoking a role revokes the unscoped token for a user" [Medium,In progress] | 19:02 |
*** henrynash has quit IRC | 19:04 | |
ravelar1 | lbragstad hmm I remember the reason I was given https://review.openstack.org/#/c/371165/ initially was for revocation performance | 19:04 |
ravelar1 | lbragstad however, that bug reminds me of something else I looked at that was really similar to this bug that I solved a few months ago. Let me see if I can find it | 19:04 |
lbragstad | ravelar1 yeah - that was a problem, but the patch you landed should have mitigated a lot of those specific issues | 19:05 |
lbragstad | ravelar1 https://bugs.launchpad.net/keystone/+bug/1511775 is more about an issue with revocation and token validation - it doesn't really have much to do with performance | 19:05 |
openstack | Launchpad bug 1511775 in OpenStack Identity (keystone) "Revoking a role revokes the unscoped token for a user" [Medium,In progress] | 19:05 |
ravelar1 | lbragstad right, ahh I remember now, what I had looked at that involved a bug for revoking was deleting a group revoked all user tokens | 19:06 |
ravelar1 | lbragstad let me look into this | 19:06 |
lbragstad | revoking an unscoped token because a user had a role removed from a project is poor user experience | 19:06 |
lbragstad | ravelar1 yeah - there was a patch recently that closed that specific issue | 19:07 |
lbragstad | ravelar1 it was solved by not persisting the revocation event at all | 19:07 |
ravelar1 | lbragstad yeah I worked on that lol | 19:07 |
lbragstad | ravelar1 ok yeah, i thought you did | 19:07 |
lbragstad | my guess is that we should be able to solve https://bugs.launchpad.net/keystone/+bug/1511775 with a similar pattern | 19:08 |
openstack | Launchpad bug 1511775 in OpenStack Identity (keystone) "Revoking a role revokes the unscoped token for a user" [Medium,In progress] | 19:08 |
ravelar1 | lbragstad I'm on board | 19:08 |
lbragstad | (by relying on the roles calculated at validation time instead of a revocation event) | 19:08 |
lbragstad | ideally - there is nothing stopping us from *not* persisting any more role+project or role+domain revocation events, since they are not irrelevant with how we do token validation now | 19:09 |
lbragstad | at least as far as i can tell | 19:09 |
ravelar1 | lbragstad I see. I don't have much time before meetings hit today, would it be okay if I play with this till then and get back to you tomorrow? | 19:09 |
lbragstad | ravelar1 yeah - no rush | 19:09 |
ravelar1 | lbragstad have to get reacquainted with this old stuff lol | 19:10 |
lbragstad | ravelar1 i was more or less just throwing it out there so that we don't forget about it | 19:10 |
ravelar1 | lbragstad good call, I already had | 19:10 |
lbragstad | that's also all the more reason to finishing knocking out the remaining bits of revocation clean up | 19:10 |
ravelar1 | lbragstad yeah especially given that we've cleaned up revocations and token provider since then | 19:11 |
lbragstad | right | 19:11 |
ravelar1 | kk im on it | 19:11 |
lbragstad | ravelar1 thanks! | 19:12 |
ravelar1 | lbragstad np! happy to help | 19:13 |
*** david-lyle has quit IRC | 19:14 | |
*** ngupta has quit IRC | 19:14 | |
*** ngupta has joined #openstack-keystone | 19:15 | |
*** MasterOfBugs has joined #openstack-keystone | 19:26 | |
*** h5t4 has quit IRC | 19:27 | |
*** h5t4 has joined #openstack-keystone | 19:28 | |
*** ngupta has quit IRC | 19:31 | |
*** ngupta has joined #openstack-keystone | 19:32 | |
*** ngupta_ has joined #openstack-keystone | 19:44 | |
*** ngupta has quit IRC | 19:45 | |
*** adrian_otto1 has joined #openstack-keystone | 19:52 | |
*** david-lyle has joined #openstack-keystone | 19:53 | |
robcresswell | ayoung, crinkle, david-lyle, dolphm, dstanek, edtubill, kenji-i, knikolla, lbragstad, r1chardj0n3s, rderose, robcresswell, stevemar <- Keystone/Horizon meeting reminder. 5 mins in #openstack-meeting-cp | 19:53 |
dstanek | robcresswell: aye | 19:54 |
dstanek | i like the 5 minute warning | 19:54 |
robcresswell | dstanek: Its in the etherpad, thought I might as well use it | 19:55 |
robcresswell | Probably just be a quick one this week though | 19:55 |
*** adrian_otto has quit IRC | 19:56 | |
lbragstad | robcresswell o/ thanks | 19:56 |
*** henrynash has joined #openstack-keystone | 20:02 | |
*** ayoung has quit IRC | 20:03 | |
*** henrynash has quit IRC | 20:06 | |
knikolla | lbragstad: thanks for reviewing the ldap patch. i responded to your comments. | 20:09 |
lbragstad | knikolla yep - i'll update my review since the main concerns i had were around the release note | 20:12 |
*** chris_hultin is now known as chris_hultin|AWA | 20:14 | |
notmorgan | dolphm: answered your question re the sql model mixin. but in short, unless we can guarantee the test has loaded all the models at that point (import) we can't guarantee the whitelist | 20:14 |
notmorgan | dolphm: i am trying some work with metaclasses, but it will require some restructuring. i think it is safe to do the restructuring actually, since we always use one of the mixins. | 20:15 |
*** adriant has joined #openstack-keystone | 20:19 | |
openstackgerrit | Anusha Unnam proposed openstack/oslo.policy master: Seperate each policy rule with new line https://review.openstack.org/443332 | 20:20 |
*** Anticimex has quit IRC | 20:21 | |
*** dave-mccowan has quit IRC | 20:30 | |
*** Anticimex has joined #openstack-keystone | 20:31 | |
*** Anticimex has quit IRC | 20:40 | |
*** Anticimex has joined #openstack-keystone | 20:40 | |
*** ayoung has joined #openstack-keystone | 20:42 | |
*** ngupta has joined #openstack-keystone | 20:44 | |
*** dave-mcc_ has joined #openstack-keystone | 20:47 | |
*** ngupta_ has quit IRC | 20:47 | |
*** chlong_ has joined #openstack-keystone | 20:47 | |
*** raildo has quit IRC | 20:51 | |
*** frontrunner has quit IRC | 20:57 | |
cmurphy | stevemar: notmorgan I found a fun bug in ldappool if you have time to take a look https://review.openstack.org/#/c/443264/ | 20:59 |
*** chris_hultin|AWA is now known as chris_hultin | 21:00 | |
notmorgan | cmurphy: easy +2/+A | 21:01 |
cmurphy | ty notmorgan | 21:02 |
*** henrynash has joined #openstack-keystone | 21:03 | |
openstackgerrit | Merged openstack/ldappool master: Don't call start_tls_s() twice https://review.openstack.org/443264 | 21:05 |
*** ayoung has quit IRC | 21:06 | |
*** Jack_I has quit IRC | 21:10 | |
*** gyee has joined #openstack-keystone | 21:11 | |
*** henrynash has quit IRC | 21:14 | |
*** prashkre has quit IRC | 21:15 | |
*** Guest88274 has joined #openstack-keystone | 21:19 | |
*** Guest88274 has quit IRC | 21:19 | |
*** henrynash has joined #openstack-keystone | 21:21 | |
*** adriant has quit IRC | 21:21 | |
*** henrynash has quit IRC | 21:23 | |
*** jaosorior has joined #openstack-keystone | 21:25 | |
*** ngupta_ has joined #openstack-keystone | 21:27 | |
*** ngupta has quit IRC | 21:31 | |
*** ngupta_ has quit IRC | 21:32 | |
*** jaosorior has quit IRC | 21:33 | |
*** dave-mcc_ has quit IRC | 21:36 | |
gagehugo | does anyone know if speakers are getting a free ticket for the boston summit? | 21:36 |
*** ayoung has joined #openstack-keystone | 21:40 | |
*** dave-mccowan has joined #openstack-keystone | 21:45 | |
*** jose-phi_ has joined #openstack-keystone | 21:51 | |
*** gyee has quit IRC | 21:51 | |
*** aojea has joined #openstack-keystone | 21:52 | |
*** jose-phillips has quit IRC | 21:52 | |
knikolla | gagehugo: yes they do | 21:55 |
browne | gagehugo: you get a free ticket if you attend the PTG also | 21:57 |
gagehugo | ok wasn't sure if they changed that or not | 22:00 |
gagehugo | I know they changed how ATC discounts worked | 22:00 |
*** adriant has joined #openstack-keystone | 22:03 | |
*** edmondsw has quit IRC | 22:03 | |
*** ayoung has quit IRC | 22:03 | |
*** ravelar has quit IRC | 22:05 | |
*** jose-phi_ has quit IRC | 22:14 | |
*** jose-phillips has joined #openstack-keystone | 22:19 | |
*** gyee has joined #openstack-keystone | 22:24 | |
*** adrian_otto1 has quit IRC | 22:28 | |
*** adrian_otto has joined #openstack-keystone | 22:30 | |
*** lucasxu has quit IRC | 22:31 | |
*** edmondsw has joined #openstack-keystone | 22:33 | |
*** edmondsw has quit IRC | 22:38 | |
*** thorst has quit IRC | 22:39 | |
*** catintheroof has joined #openstack-keystone | 22:39 | |
*** jamielennox is now known as jamielennox|away | 22:42 | |
*** jamielennox|away is now known as jamielennox | 22:45 | |
*** gyee has quit IRC | 22:48 | |
*** adrian_otto has quit IRC | 22:49 | |
*** blancos has joined #openstack-keystone | 22:50 | |
*** obedmr has left #openstack-keystone | 22:50 | |
*** spilla has quit IRC | 22:54 | |
*** blancos has quit IRC | 22:56 | |
*** simondodsley has quit IRC | 22:57 | |
*** gyee has joined #openstack-keystone | 23:00 | |
*** thorst has joined #openstack-keystone | 23:03 | |
*** gyee has quit IRC | 23:04 | |
*** aojea has quit IRC | 23:05 | |
*** gyee has joined #openstack-keystone | 23:07 | |
*** thorst has quit IRC | 23:07 | |
*** ravelar1 is now known as ravelar | 23:08 | |
*** chlong_ has quit IRC | 23:21 | |
*** ngupta has joined #openstack-keystone | 23:25 | |
*** h5t4 has quit IRC | 23:26 | |
*** h5t4 has joined #openstack-keystone | 23:28 | |
*** gyee has quit IRC | 23:33 | |
*** guoshan has joined #openstack-keystone | 23:34 | |
*** phalmos has quit IRC | 23:36 | |
*** ayoung has joined #openstack-keystone | 23:37 | |
*** dave-mccowan has quit IRC | 23:43 | |
*** h5t4 has quit IRC | 23:43 | |
*** larsks has left #openstack-keystone | 23:46 | |
*** MasterOfBugs has quit IRC | 23:53 | |
*** MasterOfBugs has joined #openstack-keystone | 23:53 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!