*** stingaci has quit IRC | 00:02 | |
*** stingaci has joined #openstack-keystone | 00:03 | |
*** ngupta has quit IRC | 00:11 | |
openstackgerrit | Anthony Washington proposed openstack/keystone master: Move ec2 credential policies to DocumentedRuleDefault https://review.openstack.org/449235 | 00:12 |
---|---|---|
*** rderose has quit IRC | 00:14 | |
*** faizy_ has quit IRC | 00:15 | |
*** stingaci_ has joined #openstack-keystone | 00:19 | |
*** stingaci has quit IRC | 00:22 | |
*** stingaci has joined #openstack-keystone | 00:24 | |
*** stingaci_ has quit IRC | 00:26 | |
*** thorst has quit IRC | 00:27 | |
*** stingaci has quit IRC | 00:27 | |
*** zhurong has joined #openstack-keystone | 00:42 | |
*** ngupta has joined #openstack-keystone | 01:12 | |
*** thorst has joined #openstack-keystone | 01:12 | |
*** shuyingya has joined #openstack-keystone | 01:14 | |
*** guoshan has joined #openstack-keystone | 01:14 | |
*** MasterOfBugs has quit IRC | 01:16 | |
*** liujiong has joined #openstack-keystone | 01:28 | |
*** ngupta has quit IRC | 01:33 | |
*** ngupta has joined #openstack-keystone | 01:33 | |
*** MasterOfBugs has joined #openstack-keystone | 01:40 | |
ayoung | lbragstad, any idea how the sql filters work? | 01:58 |
ayoung | was that all bknudson? | 02:00 |
ayoung | or some of it was henrynash | 02:00 |
ayoung | damn Keystone devs have turned over | 02:00 |
ayoung | samueldmq, you did some of the filter work, right? | 02:01 |
*** thorst has joined #openstack-keystone | 02:13 | |
*** thorst has quit IRC | 02:18 | |
*** antwash has quit IRC | 02:38 | |
dstanek | ayoung: lol. | 03:02 |
dstanek | ayoung: what are you looking to know about filters? | 03:03 |
*** zhurong has quit IRC | 03:03 | |
*** lamt has joined #openstack-keystone | 03:04 | |
*** rajpatel has joined #openstack-keystone | 03:04 | |
*** dave-mccowan has quit IRC | 03:05 | |
*** nicolasbock has quit IRC | 03:05 | |
*** ngupta has quit IRC | 03:10 | |
*** zhurong has joined #openstack-keystone | 03:13 | |
*** thorst has joined #openstack-keystone | 03:14 | |
*** lamt has quit IRC | 03:18 | |
*** thorst has quit IRC | 03:18 | |
*** lamt has joined #openstack-keystone | 03:19 | |
*** links has joined #openstack-keystone | 03:40 | |
SamYaple | dstanek: i think ayoung was just trying to ping alot of people all nonchalant | 03:42 |
*** Dinesh_Bhor has joined #openstack-keystone | 03:44 | |
*** lamt has quit IRC | 03:45 | |
*** lamt has joined #openstack-keystone | 03:51 | |
*** zhurong has quit IRC | 04:00 | |
*** lamt has quit IRC | 04:00 | |
*** guoshan has quit IRC | 04:04 | |
*** lamt has joined #openstack-keystone | 04:07 | |
*** ngupta has joined #openstack-keystone | 04:10 | |
*** lamt has quit IRC | 04:13 | |
*** lamt has joined #openstack-keystone | 04:14 | |
*** thorst has joined #openstack-keystone | 04:15 | |
*** lamt has quit IRC | 04:15 | |
*** gyee has quit IRC | 04:17 | |
*** zhurong has joined #openstack-keystone | 04:18 | |
*** thorst has quit IRC | 04:19 | |
*** zhurong has quit IRC | 04:25 | |
*** shuyingya has quit IRC | 04:29 | |
*** shuyingy_ has joined #openstack-keystone | 04:29 | |
*** namnh has joined #openstack-keystone | 04:32 | |
*** zhurong has joined #openstack-keystone | 05:00 | |
*** rocky is now known as xuhaigang | 05:01 | |
*** jamielennox is now known as jamielennox|away | 05:12 | |
*** thorst has joined #openstack-keystone | 05:15 | |
*** jamielennox|away is now known as jamielennox | 05:17 | |
*** shuyingy_ has quit IRC | 05:17 | |
*** shuyingya has joined #openstack-keystone | 05:17 | |
*** rajpatel has quit IRC | 05:20 | |
*** thorst has quit IRC | 05:20 | |
*** adriant has quit IRC | 05:36 | |
*** richm has quit IRC | 05:44 | |
*** pradeep has joined #openstack-keystone | 05:54 | |
breton | ayoung: i know how they work | 06:01 |
*** arturb has joined #openstack-keystone | 06:04 | |
*** rcernin has joined #openstack-keystone | 06:06 | |
*** thorst has joined #openstack-keystone | 06:16 | |
*** ngupta_ has joined #openstack-keystone | 06:32 | |
*** ngupta has quit IRC | 06:34 | |
*** Shunli has joined #openstack-keystone | 06:34 | |
*** Shunli has quit IRC | 06:35 | |
*** thorst has quit IRC | 06:36 | |
*** Shunli has joined #openstack-keystone | 06:36 | |
*** Shunli has quit IRC | 06:37 | |
*** Shunli has joined #openstack-keystone | 06:38 | |
*** tesseract has joined #openstack-keystone | 06:40 | |
*** pradeep has quit IRC | 06:52 | |
*** voelzmo has joined #openstack-keystone | 06:59 | |
*** pcaruana has joined #openstack-keystone | 06:59 | |
*** voelzmo has quit IRC | 07:08 | |
*** shuyingya has quit IRC | 07:17 | |
*** shuyingya has joined #openstack-keystone | 07:17 | |
*** aojea has joined #openstack-keystone | 07:29 | |
*** aojea_ has joined #openstack-keystone | 07:30 | |
*** thorst has joined #openstack-keystone | 07:32 | |
*** aojea has quit IRC | 07:33 | |
*** jamielennox is now known as jamielennox|away | 07:34 | |
*** thorst has quit IRC | 07:37 | |
*** faizy has joined #openstack-keystone | 07:41 | |
*** shuyingy_ has joined #openstack-keystone | 07:48 | |
*** shuyingya has quit IRC | 07:51 | |
*** zzzeek has quit IRC | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:00 | |
*** jaosorior has joined #openstack-keystone | 08:03 | |
*** zhurong has quit IRC | 08:09 | |
*** MasterOfBugs has quit IRC | 08:19 | |
*** dmk0202 has joined #openstack-keystone | 08:22 | |
*** zhurong has joined #openstack-keystone | 08:26 | |
*** jamielennox|away is now known as jamielennox | 08:28 | |
*** openstackgerrit has quit IRC | 08:33 | |
*** shuyingy_ has quit IRC | 08:55 | |
*** shuyingya has joined #openstack-keystone | 08:55 | |
*** Aqsa has joined #openstack-keystone | 09:04 | |
*** shuyingy_ has joined #openstack-keystone | 09:13 | |
*** shuyingya has quit IRC | 09:17 | |
*** thorst has joined #openstack-keystone | 09:34 | |
*** thorst has quit IRC | 09:38 | |
*** zhurong has quit IRC | 09:42 | |
*** davechen has quit IRC | 10:00 | |
*** davechen has joined #openstack-keystone | 10:00 | |
*** xuhaigang has quit IRC | 10:03 | |
*** nicolasbock has joined #openstack-keystone | 10:04 | |
*** liujiong has quit IRC | 10:09 | |
*** richm has joined #openstack-keystone | 10:14 | |
*** xuhaigang has joined #openstack-keystone | 10:18 | |
*** thorst has joined #openstack-keystone | 10:34 | |
*** thorst has quit IRC | 10:39 | |
*** ArchiFleKs has joined #openstack-keystone | 10:48 | |
samueldmq | morning keystone | 10:51 |
*** jaosorior has quit IRC | 10:55 | |
*** shuyingy_ has quit IRC | 11:00 | |
*** shuyingya has joined #openstack-keystone | 11:00 | |
*** shuyingya has quit IRC | 11:00 | |
*** shuyingya has joined #openstack-keystone | 11:00 | |
*** jaosorior has joined #openstack-keystone | 11:01 | |
ArchiFleKs | Hi I'm a noob in python and I'm trying to use the get_url function here : https://review.openstack.org/#/c/455353/3/magnum/drivers/heat/template_def.py but it seems to always picked up the publicURL, can someone help ? | 11:10 |
*** mugsie has joined #openstack-keystone | 11:10 | |
*** mugsie has quit IRC | 11:10 | |
*** mugsie has joined #openstack-keystone | 11:10 | |
*** zhurong has joined #openstack-keystone | 11:12 | |
*** xuhaigang has quit IRC | 11:12 | |
ayoung | dstanek, you up now, or was that last night? | 11:26 |
ayoung | breton, same question | 11:27 |
ayoung | samueldmq, good morning | 11:28 |
samueldmq | ayoung: o/ | 11:29 |
ayoung | samueldmq, hey, wiring up a new API, and the filters seem likethey are set up, but not working | 11:29 |
ayoung | specifically. the routes stuff, need to filter on service | 11:29 |
samueldmq | ayoung: the filter logic is all here https://github.com/openstack/keystone/blob/master/keystone/common/sql/core.py#L294 | 11:30 |
ayoung | samueldmq, yeah, and I think that is all set | 11:30 |
samueldmq | ayoung: in the SQL layer. if a filter is honored, it will be removed from the list | 11:30 |
*** med_ has joined #openstack-keystone | 11:30 | |
ayoung | samueldmq, the SQL driver is pretty simple | 11:30 |
samueldmq | ayoung: the controller will ultimately have the list of filters not honored so far, and then will have the opportunity to do so | 11:30 |
*** med_ is now known as Guest45512 | 11:30 | |
ayoung | samueldmq, so I tested this way: | 11:31 |
ayoung | curl -H"X-Auth-Token:$TOKEN" http://192.168.122.180/identity/v3/routes?service=identity | 11:31 |
ayoung | and it returns the same list as curl -H"X-Auth-Token:$TOKEN" http://192.168.122.180/identity/v3/routes | 11:31 |
ayoung | nothing in the routers, controllers, or sql makes explicit use of the filters, but they are passed along | 11:32 |
samueldmq | ayoung: ah, let me look | 11:32 |
ayoung | I lie | 11:32 |
ayoung | https://review.openstack.org/#/c/401808/19/keystone/assignment/controllers.py | 11:32 |
ayoung | samueldmq, I think I need to add the filters to the parameter list there? | 11:32 |
samueldmq | ayoung: exactly | 11:33 |
ayoung | samueldmq, look at tghe list_routes call | 11:33 |
ayoung | OK... | 11:33 |
samueldmq | ayoung: in the protected() thing | 11:33 |
ayoung | ah | 11:33 |
ayoung | filter_protected | 11:33 |
ayoung | I have a bunch of code to remove from that review, too. I was trying to do too much | 11:33 |
samueldmq | ayoung: yes, like this https://github.com/openstack/keystone/blob/master/keystone/identity/controllers.py#L223-L225 | 11:33 |
ayoung | samueldmq, thanks. I knew I was missing something simple | 11:34 |
samueldmq | ayoung: ++ it's a bit painful to review, too big, would be nice to decouple it a bit | 11:34 |
samueldmq | ayoung: no problem, glad I was able to help | 11:34 |
ayoung | samueldmq, I was trying to make business logic for setting the whole set of rules at once. | 11:34 |
ayoung | I think that we can defer that, or even drop it | 11:34 |
ayoung | it is not going to happen that often | 11:35 |
*** voelzmo has joined #openstack-keystone | 11:37 | |
*** thorst has joined #openstack-keystone | 11:43 | |
*** rocky_ has joined #openstack-keystone | 11:45 | |
*** guoshan has joined #openstack-keystone | 11:46 | |
breton | i see you've figured things out. Good. | 11:46 |
*** edmondsw has joined #openstack-keystone | 11:52 | |
dstanek | ayoung: both | 11:52 |
dstanek | g'morn samueldmq | 11:52 |
*** openstackgerrit has joined #openstack-keystone | 11:54 | |
openstackgerrit | ayoung proposed openstack/keystone master: Route based RBAC Management Interface https://review.openstack.org/401808 | 11:54 |
samueldmq | ayoung: agreed, starting simple is not a bad idea | 12:05 |
samueldmq | dstanek: morning | 12:05 |
*** dave-mccowan has joined #openstack-keystone | 12:09 | |
*** chlong has joined #openstack-keystone | 12:13 | |
ayoung | dstanek, is devstack no longer doing the screen thing? | 12:15 |
*** Aqsa has quit IRC | 12:15 | |
*** Aqsa has joined #openstack-keystone | 12:17 | |
ayoung | samueldmq, in a devstack on Fedora, how do they expect a keystone restart? systemd? | 12:18 |
ayoung | Ah...good. | 12:21 |
ayoung | THat worked | 12:21 |
*** guoshan has quit IRC | 12:24 | |
*** guoshan has joined #openstack-keystone | 12:25 | |
samueldmq | ayoung: I had no idea :) | 12:26 |
*** ngupta_ has quit IRC | 12:27 | |
*** ngupta has joined #openstack-keystone | 12:27 | |
*** stingaci has joined #openstack-keystone | 12:29 | |
*** guoshan has quit IRC | 12:29 | |
*** guoshan has joined #openstack-keystone | 12:30 | |
dstanek | ayoung: afaik it still uses screen | 12:32 |
dstanek | are you seeing something different? | 12:32 |
breton | dstanek: servce httpd restart | 12:34 |
breton | i guess | 12:34 |
*** stingaci has quit IRC | 12:34 | |
openstackgerrit | Peter Sabaini proposed openstack/keystone master: Make flushing tokens more robust https://review.openstack.org/454351 | 12:42 |
*** ngupta has quit IRC | 12:43 | |
*** lamt has joined #openstack-keystone | 12:44 | |
*** guoshan has quit IRC | 12:45 | |
*** zhurong has quit IRC | 12:45 | |
*** lamt has quit IRC | 12:46 | |
chrome0 | samueldmq : hopefully managed to fiddle my micropatch in place with the ^^. I promise I'll try to torture gerrit less next time. | 12:49 |
*** namnh has quit IRC | 12:50 | |
samueldmq | chrome0: hey. that's okay, I also learned to use gerrit by making mistakes :) | 12:51 |
chrome0 | cheers, and thanks for reviewing | 12:51 |
samueldmq | chrome0: no problem, thank you! feel free to ask/discuss and fix bugs at any time :) | 12:55 |
chrome0 | Hehe | 12:56 |
dstanek | chrome0: you can't possilbly torture gerrit more than i have in the past :-) | 12:56 |
chrome0 | dstanek : I know my way around python, but the git + gerrit combo is ... hard for me :-) | 12:59 |
*** shuyingya has quit IRC | 13:00 | |
*** Shunli has quit IRC | 13:03 | |
*** dougshelley66 has left #openstack-keystone | 13:06 | |
*** jaosorior has quit IRC | 13:06 | |
*** aojea has joined #openstack-keystone | 13:08 | |
*** ngupta has joined #openstack-keystone | 13:09 | |
*** aojea_ has quit IRC | 13:11 | |
*** ngupta has quit IRC | 13:14 | |
*** jaosorior has joined #openstack-keystone | 13:14 | |
*** shuyingya has joined #openstack-keystone | 13:24 | |
*** pcaruana has quit IRC | 13:27 | |
*** shuyingya has quit IRC | 13:28 | |
*** aojea_ has joined #openstack-keystone | 13:30 | |
*** mpjetta has joined #openstack-keystone | 13:31 | |
*** aojea has quit IRC | 13:34 | |
*** links has quit IRC | 13:35 | |
*** mpjetta has quit IRC | 13:38 | |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone master: Small refactoring in tests development docs https://review.openstack.org/457640 | 13:40 |
*** rojo16 has joined #openstack-keystone | 13:41 | |
rodrigods | lbragstad, restored this one: https://review.openstack.org/#/c/420893/ | 13:43 |
lbragstad | rodrigods cool - thanks | 13:43 |
lbragstad | rodrigods we need to follow up with dstanek and morgan on that one | 13:43 |
rodrigods | lbragstad, ++ | 13:43 |
lbragstad | rodrigods thanks for doing that and keeping the ball rolling | 13:44 |
rojo16 | Hey I'm trying to get Keystone federation to work with Openid connect. I need to boot a vm using my google credentials (or external idp creds). The keystoneauth1.identity oidc stuff don't seem to work. Can someone help me out? | 13:44 |
rodrigods | lbragstad, np, we think that backporting the fix for that is important | 13:44 |
*** rojo16_ has joined #openstack-keystone | 13:48 | |
*** lamt has joined #openstack-keystone | 13:48 | |
dstanek | rodrigods: keep is abandoned :-P | 13:50 |
rodrigods | dstanek, why? :( | 13:51 |
rodrigods | dstanek, it is not the fix that drops the FKs | 13:51 |
*** rojo16_ has quit IRC | 13:53 | |
dstanek | rodrigods: no not the one you just restore....the one i don't like was abandoned with a 'for now' comment | 13:53 |
rodrigods | dstanek, ahh :) | 13:53 |
dstanek | just having fun | 13:55 |
*** lamt has quit IRC | 14:02 | |
*** shuyingya has joined #openstack-keystone | 14:03 | |
*** ngupta has joined #openstack-keystone | 14:04 | |
*** ngupta has quit IRC | 14:04 | |
*** ngupta has joined #openstack-keystone | 14:05 | |
*** lamt has joined #openstack-keystone | 14:05 | |
*** Guest45512 is now known as med_ | 14:05 | |
*** med_ has quit IRC | 14:05 | |
*** med_ has joined #openstack-keystone | 14:05 | |
*** pcaruana has joined #openstack-keystone | 14:10 | |
*** rajpatel has joined #openstack-keystone | 14:15 | |
*** dave-mccowan has quit IRC | 14:24 | |
rojo16 | has anyone implemented keystone federation with openid connect, specifically authenticating through python keystoneclient | 14:28 |
rojo16 | ? | 14:28 |
*** mpjetta has joined #openstack-keystone | 14:31 | |
*** rojo16 has quit IRC | 14:35 | |
*** aojea_ has quit IRC | 14:40 | |
*** dave-mccowan has joined #openstack-keystone | 14:44 | |
*** richm has quit IRC | 14:50 | |
knikolla | o/ | 15:02 |
knikolla | such emptiness in todays agenda | 15:04 |
*** rcernin has quit IRC | 15:09 | |
*** edtubill has joined #openstack-keystone | 15:11 | |
*** ngupta has quit IRC | 15:11 | |
*** ngupta has joined #openstack-keystone | 15:13 | |
*** catintheroof has joined #openstack-keystone | 15:22 | |
*** rajpatel has quit IRC | 15:24 | |
*** mvk has quit IRC | 15:28 | |
*** rajpatel has joined #openstack-keystone | 15:33 | |
*** shuyingya has quit IRC | 15:38 | |
*** pcaruana has quit IRC | 15:41 | |
*** phalmos has joined #openstack-keystone | 15:42 | |
*** ngupta has quit IRC | 15:46 | |
*** ngupta has joined #openstack-keystone | 15:46 | |
*** aojea has joined #openstack-keystone | 15:59 | |
*** richm has joined #openstack-keystone | 16:00 | |
*** ngupta has quit IRC | 16:02 | |
*** ngupta has joined #openstack-keystone | 16:04 | |
*** voelzmo has quit IRC | 16:05 | |
*** ngupta has quit IRC | 16:06 | |
*** voelzmo has joined #openstack-keystone | 16:06 | |
*** ngupta has joined #openstack-keystone | 16:06 | |
*** gyee has joined #openstack-keystone | 16:09 | |
*** voelzmo has quit IRC | 16:10 | |
*** Aqsa has quit IRC | 16:13 | |
*** stingaci has joined #openstack-keystone | 16:22 | |
*** aojea has quit IRC | 16:36 | |
*** aojea has joined #openstack-keystone | 16:37 | |
*** aojea has quit IRC | 16:41 | |
*** dave-mccowan has quit IRC | 16:41 | |
*** jaosorior has quit IRC | 16:43 | |
*** phalmos has quit IRC | 16:44 | |
*** dave-mccowan has joined #openstack-keystone | 16:45 | |
*** harlowja_ has joined #openstack-keystone | 16:50 | |
*** harlowja has quit IRC | 16:52 | |
*** dmk0202 has quit IRC | 16:52 | |
*** rderose has joined #openstack-keystone | 17:15 | |
*** Aqsa has joined #openstack-keystone | 17:18 | |
*** luisnho223 has joined #openstack-keystone | 17:19 | |
luisnho223 | hey guys. I'm new to Openstack and I like to understand how authentication with REST API works. Documentation from Openstack is not much clear to me and i don't know how to POST a request for authentication | 17:21 |
luisnho223 | i know i have to send a POST request to http://url:5000/identity/v3/auth/tokens but don't know how to send it | 17:22 |
luisnho223 | i already installed advanced rest client but don't know how to get the token | 17:22 |
lbragstad | luisnho223 you can use any number of utilities, from curl (https://www.lifewire.com/curl-definition-2184508) to postman (https://www.getpostman.com/) | 17:23 |
luisnho223 | well I know that but i don't know how to to insert in the POST JSON form to receive th sucessful response | 17:25 |
luisnho223 | with curl and even with REST API | 17:26 |
lbragstad | with curl you're going to have to build a request and use curl to send it - let me find an example that will help explain this a little better | 17:27 |
lbragstad | luisnho223 https://docs.openstack.org/developer/keystone/devref/api_curl_examples.html | 17:27 |
lbragstad | luisnho223 have you seen ^ those yet? | 17:28 |
luisnho223 | @lbragstad i was looking for this! Every api example i found on internet was out of date | 17:29 |
luisnho223 | and i can use this also with advanced rest client | 17:30 |
luisnho223 | one more question: the url to send the request is http://localhost:5000/v3/auth/tokens or http://localhost:5000/identity/v3/auth/tokens? | 17:31 |
luisnho223 | it seems different | 17:32 |
lbragstad | luisnho223 it depends on the deployment configuration of the cloud you're interacting with | 17:32 |
luisnho223 | and in my devstack i have the /identity/ in the compute APIs | 17:32 |
lbragstad | luisnho223 then you should use /identity/v3/auth/tokens/ | 17:33 |
lbragstad | using anther path might result in a 404 since the path won't resolve | 17:33 |
luisnho223 | ok ty for all the help! It really helped me a lot... Sorry for being newbie xD | 17:33 |
lbragstad | luisnho223 anytime - let us know if you have any more questions | 17:36 |
lbragstad | luisnho223 FYI - the token will be in the header | 17:36 |
luisnho223 | it is represented by audit_id? | 17:37 |
lbragstad | luisnho223 nope - when you authenticate | 17:38 |
lbragstad | upon successful authentication you'll get a token back in the response header | 17:38 |
lbragstad | X-Subject-Token: <token> | 17:38 |
luisnho223 | oh... with advanced rest client I'm not getting that :/ | 17:39 |
lbragstad | luisnho223 what client are you using? | 17:40 |
ayoung | luisnho223, there is a whole curl set of examples online | 17:40 |
luisnho223 | nvm... just found it on details | 17:40 |
lbragstad | ayoung https://docs.openstack.org/developer/keystone/devref/api_curl_examples.html right? | 17:40 |
lbragstad | ayoung or do we have another set of examples somewhere else? | 17:40 |
luisnho223 | thank you for the help :) yes im using that examples | 17:41 |
ayoung | https://docs.openstack.org/developer/keystone/devref/api_curl_examples.html yep looks like the same link | 17:41 |
luisnho223 | i just found out the tokens :) | 17:41 |
lbragstad | luisnho223 good deal | 17:41 |
ayoung | luisnho223, I also wrote up: http://adam.younglogic.com/2013/09/keystone-v3-api-examples/ a while ago | 17:41 |
*** dougshelley66 has joined #openstack-keystone | 17:41 | |
ayoung | but I don't think it is any better than the official docs | 17:41 |
ayoung | luisnho223, also, if you call `openstack token issue` from the CLI you get back a token. Add in --debug and you can see what it passes back and forth | 17:42 |
luisnho223 | i found out your blog and i tried with that json file but no success | 17:42 |
luisnho223 | but now i know how to do it | 17:42 |
luisnho223 | i just need to parse the header | 17:42 |
luisnho223 | and save the token | 17:43 |
*** luisnho223 has quit IRC | 17:49 | |
*** nicolasbock has quit IRC | 18:01 | |
*** faizy has quit IRC | 18:11 | |
knikolla | ayoung: let's resync up on the rbac work | 18:16 |
dstanek | lbragstad: what time is the policy hangout again? | 18:17 |
lbragstad | tomorrow at 11 dstanek | 18:19 |
dstanek | ok, so 12 EST | 18:20 |
dstanek | i thought that was at the same time as our rax mtg | 18:20 |
lbragstad | dstanek oh - let me double check | 18:21 |
lbragstad | dstanek i'm seeing our rax meeting at 10am central | 18:21 |
dstanek | hmmm...i wonder why my gcal is messed up | 18:22 |
*** tesseract has quit IRC | 18:22 | |
dstanek | yeah, somehome my google calendar is wrong. i see it find through outlook | 18:23 |
lbragstad | dstanek interesting - i see it at 10am and out policy hangout is at 11am, so that should be good (unless i missed a meeting update, but i just checked my email and i don't see one) | 18:25 |
breton | ayoung: have you already made the pitch? :) | 18:25 |
breton | ayoung: i accidently ran into it when was googling novnc | 18:26 |
*** nicolasbock has joined #openstack-keystone | 18:27 | |
dstanek | lbragstad: i removed and readded by work calendar to my google calendar and in now shows correctly as 11EST | 18:30 |
lbragstad | dstanek awesome | 18:30 |
*** edtubill has quit IRC | 18:30 | |
*** ngupta_ has joined #openstack-keystone | 18:31 | |
*** ngupta has quit IRC | 18:35 | |
*** phalmos has joined #openstack-keystone | 18:44 | |
*** rajpatel has quit IRC | 18:45 | |
*** ngupta has joined #openstack-keystone | 18:47 | |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone master: Basic overview of tempest and devstack plugins https://review.openstack.org/457768 | 18:47 |
rodrigods | lbragstad, ^ | 18:47 |
rodrigods | i'll be adding these docs in small chunks, to ease the reviews | 18:48 |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone master: Basic overview of tempest and devstack plugins https://review.openstack.org/457768 | 18:49 |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: Remove LDAP delete logic and associated tests https://review.openstack.org/424344 | 18:50 |
*** ngupta_ has quit IRC | 18:51 | |
*** rajpatel has joined #openstack-keystone | 18:52 | |
lbragstad | rodrigods that's perfect, thanks for doing that | 18:54 |
rm_work | did you guys have a release today? | 19:04 |
rm_work | or merge something possibly breaking? | 19:04 |
rm_work | looks like no merges today | 19:04 |
*** dave-mccowan has quit IRC | 19:06 | |
*** antwash has joined #openstack-keystone | 19:12 | |
rm_work | kk found the issue I think, devstack change w/r/t keystone wsgi | 19:16 |
*** phalmos has quit IRC | 19:25 | |
*** phalmos has joined #openstack-keystone | 19:29 | |
*** dave-mccowan has joined #openstack-keystone | 19:32 | |
*** phalmos has quit IRC | 19:35 | |
breton | rm_work: i saw that something changed today | 19:35 |
rm_work | yeah we just figured it out | 19:35 |
rm_work | keystone changed to run without a port | 19:35 |
rm_work | and our devstack config had it hardcoded | 19:36 |
breton | rm_work: https://review.openstack.org/#/c/456344/ this | 19:36 |
rm_work | yep | 19:36 |
rm_work | that was it | 19:36 |
rm_work | thanks for looking! :) | 19:36 |
*** rderose has quit IRC | 19:38 | |
*** aojea has joined #openstack-keystone | 19:49 | |
*** david-lyle has joined #openstack-keystone | 19:53 | |
*** Adobeman has joined #openstack-keystone | 20:04 | |
*** mvk has joined #openstack-keystone | 20:15 | |
*** openstackgerrit has quit IRC | 20:33 | |
*** ngupta has quit IRC | 20:36 | |
*** stingaci has quit IRC | 20:46 | |
*** stingaci has joined #openstack-keystone | 20:46 | |
*** adriant has joined #openstack-keystone | 20:47 | |
*** david-lyle has quit IRC | 20:49 | |
*** stingaci has quit IRC | 20:53 | |
ayoung | knikolla, I'm back...was on kid duty for abit | 21:01 |
ayoung | and dog duty | 21:01 |
ayoung | breton, pitch? I think you are thinking of the meeting tomorrow | 21:02 |
ayoung | that is the video chat | 21:02 |
knikolla | ayoung: o/ | 21:02 |
ayoung | knikolla, right now I need to figure out how to do the matching | 21:02 |
ayoung | I think I want to use route.mapping | 21:02 |
ayoung | routes that is | 21:02 |
ayoung | knikolla, I have some sample code though for showing proof of concept stuff: | 21:03 |
ayoung | I have a devstack setup with the keystone server change applied, and using your kc changes I can create & list routes | 21:03 |
ayoung | knikolla, let me paste: | 21:05 |
ayoung | knikolla, http://paste.openstack.org/show/607052/ will read a json file and create the routes | 21:06 |
ayoung | here is the simplistic one for identity | 21:06 |
ayoung | http://paste.openstack.org/show/607053/ | 21:06 |
ayoung | that only has a catch all rule | 21:06 |
ayoung | here is an exhaustive one for compute, generated from the compute API | 21:07 |
ayoung | https://da.gd/mfU5a -> https://paste.fedoraproject.org/paste/xhygXLW7b0E9Jpos9mihpF5M1UNdIGYhyRLivL9gydE=/ | 21:07 |
ayoung | knikolla, to list roles: | 21:07 |
ayoung | make that routes https://paste.fedoraproject.org/paste/qqwbWLV41WGoDxnyxeIa1V5M1UNdIGYhyRLivL9gydE=/ | 21:08 |
ayoung | and delete | 21:08 |
ayoung | https://da.gd/Ann7 -> https://paste.fedoraproject.org/paste/oRf7FWylKOSas67DE-Qtwl5M1UNdIGYhyRLivL9gydE=/ | 21:08 |
ayoung | so now we need somthing that will take the URL, break off the parts we don't care about, and say: here is the matching rule | 21:09 |
knikolla | and plug that in to ksm | 21:09 |
*** david-lyle has joined #openstack-keystone | 21:10 | |
*** edmondsw has quit IRC | 21:11 | |
knikolla | ayoung: quick question. will the matching be done in ksm or keystone server? in other words, will ksm send the route to the server and let the server match it, or will ksm have the routes/roles and do it itself? | 21:11 |
*** dmk0202 has joined #openstack-keystone | 21:11 | |
ayoung | ksm | 21:11 |
ayoung | knikolla, I want it as a function in kc called from ksm | 21:11 |
ayoung | ksm will fetch what it needs and make the call | 21:11 |
*** thorst has quit IRC | 21:11 | |
ayoung | and cache whatever it can | 21:11 |
*** edmondsw has joined #openstack-keystone | 21:11 | |
ayoung | knikolla, right now I see it making 2 calls: list_routes and list_roles | 21:12 |
ayoung | that assumes that role_inference is expanded in the tokens | 21:12 |
ayoung | we might want to add a helper API to get the data in the right form for enforcement, but that can be done after we have a working proof of concept | 21:13 |
ayoung | I actually pulled it out of the current server patch to simplify things | 21:13 |
knikolla | i see | 21:13 |
ayoung | knikolla, one more errand, back in a bit. Take a loot at the code I posted and we can talk in about 15 | 21:13 |
knikolla | ayoung: ok | 21:14 |
*** edmondsw has quit IRC | 21:16 | |
*** chris_hultin|AWA is now known as chris_hultin | 21:18 | |
*** antwash has quit IRC | 21:18 | |
knikolla | rodrigods: u there? | 21:25 |
knikolla | rodrigods: FYI this broke the devstack plugin in the functional gate https://review.openstack.org/#/c/456344/ | 21:26 |
*** rderose has joined #openstack-keystone | 21:26 | |
breton | ayoung: the pitch about RBAC :) | 21:27 |
breton | ayoung: RBAC-Middleware-pitch | 21:27 |
*** Aqsa has quit IRC | 21:28 | |
*** openstackgerrit has joined #openstack-keystone | 21:30 | |
openstackgerrit | Peter Sabaini proposed openstack/keystone master: Make flushing tokens more robust https://review.openstack.org/454351 | 21:30 |
*** thorst has joined #openstack-keystone | 21:32 | |
ayoung | breton, so that is tomorrow, but knikolla and I are talking through it now. | 21:36 |
*** rajpatel has quit IRC | 21:37 | |
*** thorst has quit IRC | 21:37 | |
*** aojea has quit IRC | 21:39 | |
*** ngupta has joined #openstack-keystone | 21:40 | |
*** rderose has quit IRC | 21:41 | |
*** aojea has joined #openstack-keystone | 21:44 | |
*** aojea has quit IRC | 21:45 | |
knikolla | ayoung: i'll be heading off soon. | 21:51 |
knikolla | any tasks you want me to work on? | 21:51 |
ayoung | knikolla, yeah, can you address the code review comments on the server piece? | 21:52 |
ayoung | get the API doc started? | 21:52 |
knikolla | ayoung: yes. will do that. | 21:52 |
knikolla | was waiting to sync up with you to prevent conflicts on the server piece. | 21:52 |
ayoung | knikolla, I'm going to get a Proof of concept working with the route matching, and I'd like to hand it off to you from there. Maybe tomorrow afternoon? | 21:52 |
ayoung | I think the server is functional enough for now | 21:53 |
knikolla | ayoung: sounds good. | 21:53 |
*** thorst has joined #openstack-keystone | 21:53 | |
*** MasterOfBugs has joined #openstack-keystone | 21:55 | |
*** david-lyle has quit IRC | 21:55 | |
*** rderose has joined #openstack-keystone | 21:56 | |
*** rderose has quit IRC | 21:57 | |
*** thorst has quit IRC | 21:58 | |
*** dmk0202 has quit IRC | 21:59 | |
*** catintheroof has quit IRC | 22:01 | |
*** ianw_pto is now known as ianw | 22:12 | |
*** aojea has joined #openstack-keystone | 22:27 | |
*** aojea has quit IRC | 22:33 | |
*** thorst has joined #openstack-keystone | 22:41 | |
*** thorst has quit IRC | 22:43 | |
*** thorst has joined #openstack-keystone | 22:43 | |
*** thorst has quit IRC | 22:47 | |
*** stingaci has joined #openstack-keystone | 22:53 | |
*** david-lyle has joined #openstack-keystone | 22:53 | |
*** david-lyle has quit IRC | 22:56 | |
*** aloga has quit IRC | 22:57 | |
*** phalmos has joined #openstack-keystone | 22:59 | |
*** aloga has joined #openstack-keystone | 23:03 | |
*** phalmos has quit IRC | 23:04 | |
openstackgerrit | ayoung proposed openstack/python-keystoneclient master: WIP - Client functions for Routes https://review.openstack.org/452893 | 23:06 |
openstackgerrit | ayoung proposed openstack/python-keystoneclient master: DO NOT MERGE: proof of concept for RBAC matching https://review.openstack.org/457818 | 23:06 |
ayoung | knikolla, all the POC code is in the review. Including how to do the matching | 23:06 |
*** chris_hultin is now known as chris_hultin|AWA | 23:09 | |
*** Aqsa has joined #openstack-keystone | 23:11 | |
*** thorst has joined #openstack-keystone | 23:15 | |
*** ngupta has quit IRC | 23:23 | |
*** ngupta has joined #openstack-keystone | 23:24 | |
*** ngupta has quit IRC | 23:28 | |
*** d0ugal has quit IRC | 23:32 | |
*** aojea has joined #openstack-keystone | 23:33 | |
*** aloga has quit IRC | 23:37 | |
*** aojea has quit IRC | 23:38 | |
*** lamt has quit IRC | 23:40 | |
*** d0ugal has joined #openstack-keystone | 23:41 | |
*** aloga has joined #openstack-keystone | 23:41 | |
*** Nakato has joined #openstack-keystone | 23:46 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!