*** mtreinish has quit IRC | 00:12 | |
openstackgerrit | James E. Blair proposed openstack/keystoneauth master: Zuul: Remove project name https://review.openstack.org/541080 | 00:19 |
---|---|---|
*** edmondsw has joined #openstack-keystone | 00:21 | |
*** gongysh has joined #openstack-keystone | 00:21 | |
*** edmondsw has quit IRC | 00:25 | |
*** r-daneel has quit IRC | 00:29 | |
*** mtreinish has joined #openstack-keystone | 00:37 | |
*** dave-mccowan has joined #openstack-keystone | 00:42 | |
*** Supun has joined #openstack-keystone | 00:50 | |
*** gongysh has quit IRC | 01:09 | |
*** Supun has quit IRC | 01:23 | |
*** sapd__ has quit IRC | 02:04 | |
*** sapd has joined #openstack-keystone | 02:06 | |
*** edmondsw has joined #openstack-keystone | 02:09 | |
*** itlinux has joined #openstack-keystone | 02:13 | |
*** edmondsw has quit IRC | 02:14 | |
*** gongysh has joined #openstack-keystone | 02:18 | |
*** harlowja has quit IRC | 02:18 | |
*** markvoelker has joined #openstack-keystone | 02:22 | |
*** markvoelker has quit IRC | 02:24 | |
*** markvoelker has joined #openstack-keystone | 02:31 | |
*** itlinux has quit IRC | 02:43 | |
*** dave-mccowan has quit IRC | 02:48 | |
*** markvoelker has quit IRC | 02:56 | |
*** markvoelker has joined #openstack-keystone | 02:59 | |
*** dave-mccowan has joined #openstack-keystone | 03:09 | |
*** markvoelker has quit IRC | 03:11 | |
*** markvoelker has joined #openstack-keystone | 03:14 | |
*** d0ugal_ has joined #openstack-keystone | 03:16 | |
*** d0ugal has quit IRC | 03:19 | |
*** markvoelker has quit IRC | 03:25 | |
*** gyee has quit IRC | 03:29 | |
*** markvoelker has joined #openstack-keystone | 03:30 | |
*** dave-mccowan has quit IRC | 03:33 | |
*** gongysh has quit IRC | 03:33 | |
*** markvoelker has quit IRC | 03:42 | |
*** edmondsw has joined #openstack-keystone | 03:58 | |
*** abhi89 has joined #openstack-keystone | 03:58 | |
*** gongysh has joined #openstack-keystone | 04:01 | |
*** edmondsw has quit IRC | 04:02 | |
*** gongysh has quit IRC | 04:11 | |
*** gongysh has joined #openstack-keystone | 04:14 | |
*** gongysh has quit IRC | 04:30 | |
*** harlowja has joined #openstack-keystone | 04:46 | |
*** zhurong has quit IRC | 05:07 | |
*** harlowja has quit IRC | 05:11 | |
*** links has joined #openstack-keystone | 05:12 | |
*** itlinux has joined #openstack-keystone | 05:17 | |
*** gongysh has joined #openstack-keystone | 05:19 | |
vish_18 | lbragstad: thanks | 05:24 |
*** daidv has quit IRC | 05:26 | |
*** edmondsw has joined #openstack-keystone | 05:46 | |
*** edmondsw has quit IRC | 05:50 | |
*** itlinux has quit IRC | 05:55 | |
*** d0ugal_ has quit IRC | 06:14 | |
*** d0ugal_ has joined #openstack-keystone | 06:23 | |
*** threestrands has quit IRC | 06:40 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone master: Imported Translations from Zanata https://review.openstack.org/540583 | 06:47 |
*** josecastroleon has quit IRC | 07:08 | |
*** zhurong has joined #openstack-keystone | 07:09 | |
*** AlexeyAbashkin has joined #openstack-keystone | 07:32 | |
*** martinus__ has joined #openstack-keystone | 07:34 | |
*** rcernin has quit IRC | 07:37 | |
*** AlexeyAbashkin has quit IRC | 07:39 | |
*** bhagyashris has quit IRC | 07:42 | |
*** AlexeyAbashkin has joined #openstack-keystone | 07:48 | |
*** StefanPaetowJisc has joined #openstack-keystone | 08:04 | |
*** StefanPaetowJisc has quit IRC | 08:14 | |
*** pcaruana has joined #openstack-keystone | 08:14 | |
*** StefanPaetowJisc has joined #openstack-keystone | 08:17 | |
*** tesseract has joined #openstack-keystone | 08:22 | |
*** bhagyashris has joined #openstack-keystone | 08:25 | |
*** StefanPaetowJisc has quit IRC | 08:27 | |
*** zhurong has quit IRC | 08:38 | |
*** StefanPaetowJisc has joined #openstack-keystone | 08:47 | |
*** frti has joined #openstack-keystone | 08:48 | |
*** Suramya has joined #openstack-keystone | 08:49 | |
*** gongysh has quit IRC | 08:53 | |
*** d0ugal_ has quit IRC | 08:57 | |
*** d0ugal has joined #openstack-keystone | 08:57 | |
*** d0ugal has quit IRC | 08:57 | |
*** d0ugal has joined #openstack-keystone | 08:57 | |
*** StefanPaetowJisc has quit IRC | 09:02 | |
*** zhurong has joined #openstack-keystone | 09:02 | |
*** gongysh has joined #openstack-keystone | 09:04 | |
*** threestrands has joined #openstack-keystone | 09:06 | |
*** jaosorior has quit IRC | 09:06 | |
*** StefanPaetowJisc has joined #openstack-keystone | 09:17 | |
*** threestrands has quit IRC | 09:21 | |
*** frti_ has joined #openstack-keystone | 09:21 | |
*** edmondsw has joined #openstack-keystone | 09:22 | |
*** wxy has quit IRC | 09:22 | |
*** frti_ has quit IRC | 09:25 | |
*** frti has quit IRC | 09:25 | |
*** edmondsw has quit IRC | 09:27 | |
*** hoonetorg has quit IRC | 09:28 | |
*** jaosorior has joined #openstack-keystone | 09:29 | |
*** hoonetorg has joined #openstack-keystone | 09:41 | |
*** StefanPaetowJisc has quit IRC | 09:56 | |
*** StefanPaetowJisc has joined #openstack-keystone | 09:57 | |
*** StefanPaetowJisc has quit IRC | 10:00 | |
*** StefanPaetowJisc has joined #openstack-keystone | 10:02 | |
*** amrith has left #openstack-keystone | 10:04 | |
*** StefanPaetowJisc has quit IRC | 10:05 | |
*** StefanPaetowJisc has joined #openstack-keystone | 10:08 | |
vish_18 | cmurphy: As I am new to keystone. | 10:23 |
*** StefanPaetowJisc has quit IRC | 10:23 | |
vish_18 | cmurphy: in this bug https://review.openstack.org/#/c/537322/ | 10:24 |
vish_18 | cmurphy: can you help for the solution | 10:24 |
vish_18 | cmurphy: I also had a query... do keystone maintains any list of valid drivers that can be used as backend? | 10:25 |
-openstackstatus- NOTICE: Our Zuul infrastructure is currently experiencing some problems and processing jobs very slowly, we're investigating. Please do not approve or recheck changes for now. | 10:30 | |
*** StefanPaetowJisc has joined #openstack-keystone | 10:32 | |
*** dtruong has quit IRC | 10:35 | |
*** StefanPaetowJisc has quit IRC | 10:35 | |
*** dtruong has joined #openstack-keystone | 10:35 | |
cmurphy | vish_18: no we don't maintain a list of external drivers, we only know about the ones we maintain in-tree | 10:38 |
cmurphy | vish_18: if there a new bug open for https://review.openstack.org/#/c/537322/ ? i would try to solve that first | 10:39 |
cmurphy | s/if/is | 10:39 |
vish_18 | cmurphy: should I lock a new bug for this? | 10:44 |
*** sambetts|afk is now known as sambetts | 10:54 | |
*** edmondsw has joined #openstack-keystone | 11:10 | |
*** edmondsw has quit IRC | 11:15 | |
*** StefanPaetowJisc has joined #openstack-keystone | 11:18 | |
*** StefanPaetowJisc has quit IRC | 11:23 | |
*** StefanPaetowJisc has joined #openstack-keystone | 11:25 | |
*** nicolasbock has joined #openstack-keystone | 11:26 | |
*** StefanPaetowJisc has quit IRC | 11:29 | |
cmurphy | vish_18: you can create a new one or we could consider it the same bug and use Partial-Bug in the commit messages to track it, my only point in my comment on the patch is that we shouldn't say Closes-Bug yet because the original bug is not reproduceable right now, the new issue needs to be resolved first | 11:31 |
*** StefanPaetowJisc has joined #openstack-keystone | 11:37 | |
*** StefanPaetowJisc has quit IRC | 11:38 | |
*** links has quit IRC | 11:41 | |
*** raildo has joined #openstack-keystone | 11:48 | |
*** links has joined #openstack-keystone | 11:54 | |
*** gongysh has quit IRC | 11:57 | |
*** abhi89 has quit IRC | 11:57 | |
*** Supun has joined #openstack-keystone | 11:57 | |
*** abhi89 has joined #openstack-keystone | 12:24 | |
*** StefanPaetowJisc has joined #openstack-keystone | 12:39 | |
*** gongysh has joined #openstack-keystone | 12:54 | |
*** links has quit IRC | 12:55 | |
*** takamatsu has joined #openstack-keystone | 12:56 | |
*** AlexeyAbashkin has quit IRC | 12:59 | |
*** zhurong_ has joined #openstack-keystone | 13:01 | |
*** AlexeyAbashkin has joined #openstack-keystone | 13:01 | |
*** abhi89 has quit IRC | 13:05 | |
*** abhi89 has joined #openstack-keystone | 13:06 | |
*** zhurong has quit IRC | 13:08 | |
*** links has joined #openstack-keystone | 13:08 | |
*** edmondsw has joined #openstack-keystone | 13:13 | |
*** jaosorior has quit IRC | 13:23 | |
*** AlexeyAbashkin has quit IRC | 13:25 | |
*** Supun has quit IRC | 13:27 | |
*** AlexeyAbashkin has joined #openstack-keystone | 13:27 | |
*** Supun has joined #openstack-keystone | 13:28 | |
*** dave-mccowan has joined #openstack-keystone | 13:30 | |
*** dave-mcc_ has joined #openstack-keystone | 13:34 | |
*** StefanPaetowJisc has quit IRC | 13:34 | |
*** dave-mccowan has quit IRC | 13:35 | |
*** abhi89 has quit IRC | 13:38 | |
*** AlexeyAbashkin has quit IRC | 13:38 | |
*** StefanPaetowJisc has joined #openstack-keystone | 13:39 | |
*** zhurong_ has quit IRC | 13:52 | |
*** jmlowe has quit IRC | 13:55 | |
*** jaosorior has joined #openstack-keystone | 14:04 | |
*** jrist has quit IRC | 14:11 | |
*** jrist has joined #openstack-keystone | 14:12 | |
*** StefanPaetowJisc has quit IRC | 14:15 | |
*** david-lyle has quit IRC | 14:34 | |
*** AlexeyAbashkin has joined #openstack-keystone | 14:35 | |
*** links has quit IRC | 14:38 | |
*** StefanPaetowJisc has joined #openstack-keystone | 14:38 | |
*** abhi89 has joined #openstack-keystone | 14:38 | |
*** spilla has joined #openstack-keystone | 14:42 | |
*** abhi89 has quit IRC | 14:43 | |
*** abhi89 has joined #openstack-keystone | 14:44 | |
*** abhi89 has quit IRC | 14:49 | |
*** jmlowe has joined #openstack-keystone | 14:57 | |
*** StefanPaetowJisc has quit IRC | 15:00 | |
*** StefanPaetowJisc has joined #openstack-keystone | 15:00 | |
*** Supun has quit IRC | 15:08 | |
*** mnaser has quit IRC | 15:11 | |
*** ayoung has joined #openstack-keystone | 15:11 | |
*** mnaser has joined #openstack-keystone | 15:12 | |
openstackgerrit | Suramya proposed openstack/keystone master: Reorganize api-ref: v3-ext trust.inc https://review.openstack.org/531772 | 15:17 |
*** hrybacki has quit IRC | 15:19 | |
*** hrybacki has joined #openstack-keystone | 15:19 | |
lbragstad | Suramya: i opened a bug - https://bugs.launchpad.net/keystone/+bug/1747694 | 15:23 |
openstack | Launchpad bug 1747694 in OpenStack Identity (keystone) "Trust documentation lists support for paging" [Undecided,New] | 15:23 |
lbragstad | i wasn't able to get those query strings to work | 15:23 |
cmurphy | haha i was just about to comment on that | 15:23 |
cmurphy | it's not supported at all, must have been copied from somewhere else | 15:23 |
lbragstad | other APIs in keystone don't support paging either, so i think we're safe to remove query parameters | 15:24 |
lbragstad | i agree cmurphy, it must have been bad copy/pasta | 15:24 |
Suramya | lbragstad: cmurphy: I see :D, updating the patchset. | 15:25 |
cmurphy | thanks! | 15:26 |
lbragstad | Suramya: if you want to put Closes-Bug: 1747694 in the commit message, it'll take care of that bug, too | 15:30 |
openstack | bug 1747694 in OpenStack Identity (keystone) "Trust documentation lists support for paging" [Medium,Confirmed] https://launchpad.net/bugs/1747694 | 15:30 |
*** StefanPaetowJisc has quit IRC | 15:31 | |
sjmc7 | hi all. i have a question about federated mapping rules. the docs state that the first rule matched gets returned, but does that mean that if a user is in multiple groups it’s not possible to have that result in a different role grant for each group? | 15:34 |
Suramya | lbragstad: yes ack | 15:34 |
openstackgerrit | Suramya proposed openstack/keystone master: Reorganize api-ref: v3-ext trust.inc https://review.openstack.org/531772 | 15:34 |
*** ayoung has quit IRC | 15:35 | |
*** StefanPaetowJisc has joined #openstack-keystone | 15:38 | |
*** med_ has quit IRC | 15:38 | |
*** Supun has joined #openstack-keystone | 15:39 | |
cmurphy | sjmc7: you can use the 'whitelist' condition to match multiple groups | 15:42 |
cmurphy | users don't have roles in groups so you wouldn't need to create different role grants for them | 15:42 |
sjmc7 | but i can have a user end up in multiple groups? | 15:43 |
*** Supun has quit IRC | 15:44 | |
sjmc7 | so if my user’s SAML claims indicate two groups A and B, if i have two mapping rules, one whitelisting A and one B, won’t keystone just match the frst and stop? | 15:44 |
openstackgerrit | Suramya proposed openstack/keystone master: Reorganize api-ref: v3-ext trust.inc https://review.openstack.org/531772 | 15:45 |
cmurphy | sjmc7: check the third example down from this section https://docs.openstack.org/keystone/latest/advanced-topics/federation/federated_identity.html#mappings-examples where it has <other_condition> [ ] you would have "whitelist" as the other condition and the group names in the list, then in your "groups": "{N}" part of the local rules that should end up expanding into multiple groups, one for each | 15:45 |
cmurphy | match | 15:46 |
sjmc7 | multiple groups doesn’t seem to work | 15:46 |
sjmc7 | it ends up as a group named ‘[“A”, “B”]’ | 15:46 |
sjmc7 | i found a related bug report last week that indicated only group_ids supported multiple values | 15:47 |
sjmc7 | one sec | 15:47 |
sjmc7 | https://bugs.launchpad.net/keystone/+bug/1575368 | 15:47 |
openstack | Launchpad bug 1575368 in OpenStack Identity (keystone) "Federation Unable to handle multiple groups" [Undecided,Invalid] | 15:47 |
sjmc7 | suggestion was to use group_id but that only works if you have the IDs | 15:47 |
sjmc7 | that is an old bug but i seem to still be getting the behavior | 15:48 |
*** david-lyle has joined #openstack-keystone | 15:51 | |
cmurphy | :( | 15:51 |
*** pcaruana has quit IRC | 15:51 | |
*** samueldmq has quit IRC | 15:52 | |
cmurphy | i would not have expected it to work that way for names, i feel like that's a bug | 15:52 |
*** samueldmq has joined #openstack-keystone | 15:52 | |
*** StefanPaetowJisc has quit IRC | 15:52 | |
sjmc7 | i had a quick look at the code friday and it looked like for a “group” element it’s trying to find a single one (versus group_ids which is explicitly many but does no lookup) | 15:53 |
openstackgerrit | Suramya proposed openstack/keystone master: Reorganize api-ref: v3-ext trust.inc https://review.openstack.org/531772 | 15:53 |
sjmc7 | which i guess makes sense since the domain might not be the same across all of them, though it does make it a bit inconvenient | 15:54 |
*** StefanPaetowJisc has joined #openstack-keystone | 15:55 | |
cmurphy | seems incompatible with the point of having a whitelist condition, we should fix it | 15:56 |
sjmc7 | ok. i was also getting errors for groups that weren’t matched (so i had to whitelist to only those i knew existed); my expectation was that unknown group assertions would have been ignored | 15:58 |
sjmc7 | that’s not such a big deal as whitelisting all the ones i know about isn’t that onerous but i wasn’t clear why that was the case | 15:59 |
sjmc7 | should i add a comment on that bug asking if there’s any chance to get someone to look at it? | 15:59 |
sjmc7 | there’s a comment on there that it isn’t really a bug at all which i guess is why it was marked invalid | 16:00 |
*** r-daneel has joined #openstack-keystone | 16:01 | |
cmurphy | sjmc7: i think i might suggest filing a new bug saying this is about group names, you can reference the old bug from it | 16:04 |
cmurphy | idk lbragstad ^ | 16:05 |
*** jaosorior has quit IRC | 16:06 | |
lbragstad | cmurphy: that sounds reasonable | 16:07 |
sjmc7 | ok, thanks | 16:14 |
*** wlmbasson has quit IRC | 16:15 | |
*** gmann has quit IRC | 16:33 | |
*** gmann has joined #openstack-keystone | 16:33 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Drop domain id foreign key from user table https://review.openstack.org/539347 | 16:33 |
*** itlinux has joined #openstack-keystone | 16:34 | |
*** brad[] has quit IRC | 16:45 | |
knikolla | o/ | 16:50 |
*** jmlowe has quit IRC | 16:53 | |
*** jmlowe has joined #openstack-keystone | 16:53 | |
*** StefanPaetowJisc has quit IRC | 17:01 | |
*** gongysh has quit IRC | 17:02 | |
*** gyee has joined #openstack-keystone | 17:02 | |
*** gongysh has joined #openstack-keystone | 17:06 | |
*** gongysh has quit IRC | 17:08 | |
knikolla | lbragstad: here? quick q | 17:17 |
*** r-daneel has quit IRC | 17:22 | |
*** r-daneel has joined #openstack-keystone | 17:22 | |
*** AlexeyAbashkin has quit IRC | 17:25 | |
*** AlexeyAbashkin has joined #openstack-keystone | 17:25 | |
*** vish_18 has quit IRC | 17:25 | |
*** spilla has quit IRC | 17:27 | |
*** AlexeyAbashkin has quit IRC | 17:29 | |
*** mtreinish has quit IRC | 17:43 | |
*** spilla has joined #openstack-keystone | 17:46 | |
*** mtreinish has joined #openstack-keystone | 17:50 | |
*** jose-phillips has left #openstack-keystone | 17:51 | |
lbragstad | knikolla: sure - what's up? | 17:53 |
knikolla | lbragstad: for https://bugs.launchpad.net/keystone/+bug/1658641 i'm redoing it to add two new args to the mapping_purge command, --only-invalid and --remove-assignments | 17:55 |
openstack | Launchpad bug 1658641 in OpenStack Identity (keystone) "Moving/disabling LDAP users break Keystone queries depending on role ID" [Medium,In progress] - Assigned to Kristi Nikolla (knikolla) | 17:55 |
knikolla | and have the mapping backend return the list of purged ids, so that i can do the removal from keystone-manage rather than identity driver | 17:55 |
knikolla | just getting early feedback so that i don't go too far in the wrong direction | 17:56 |
lbragstad | knikolla: that seems sane.. | 17:56 |
lbragstad | are the APIs you're adding to the mapping backend going to be internal only? | 17:57 |
knikolla | no new apis added. the only change is in the mapping driver/backend, which will return the (entitytype, public_id) of the purged mappings. | 17:57 |
knikolla | the others are keystone-manage commands which use that. | 17:57 |
knikolla | and remove assignments based on the returned list. | 17:58 |
lbragstad | ok - yeah, that seems ok | 17:58 |
lbragstad | i don't see any red flags with that | 17:59 |
lbragstad | it's not adding an end user API | 17:59 |
knikolla | lbragstad: yup. i don't feel comfortable adding the functionality to remove assignments without a new command. since while mappings are regeneratable, assignments are not. | 18:00 |
knikolla | hence, --only-invalid --remove-assignments combination of commands. | 18:00 |
*** tesseract has quit IRC | 18:00 | |
*** sambetts is now known as sambetts|afk | 18:01 | |
*** david-lyle has quit IRC | 18:20 | |
*** brad[] has joined #openstack-keystone | 18:21 | |
*** brad[] has quit IRC | 18:34 | |
*** harlowja has joined #openstack-keystone | 18:35 | |
*** jessegler has joined #openstack-keystone | 18:40 | |
*** gmann has quit IRC | 18:43 | |
*** ayoung has joined #openstack-keystone | 18:46 | |
*** brad[] has joined #openstack-keystone | 18:46 | |
*** AlexeyAbashkin has joined #openstack-keystone | 19:00 | |
lbragstad | #startmeeting keystone | 19:00 |
openstack | Meeting started Tue Feb 6 19:00:27 2018 UTC and is due to finish in 60 minutes. The chair is lbragstad. Information about MeetBot at http://wiki.debian.org/MeetBot. | 19:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 19:00 |
*** openstack changes topic to " (Meeting topic: keystone)" | 19:00 | |
*** ChanServ changes topic to "Queens release schedule: https://releases.openstack.org/queens/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/5F0h9Hoe/keystone" | 19:00 | |
openstack | The meeting name has been set to 'keystone' | 19:00 |
cmurphy | lbragstad: i think you started with the wrong meeting name | 19:01 |
*** ayoung has quit IRC | 19:06 | |
*** r-daneel_ has joined #openstack-keystone | 19:08 | |
*** david-lyle has joined #openstack-keystone | 19:08 | |
*** david-lyle has quit IRC | 19:08 | |
*** david-lyle has joined #openstack-keystone | 19:09 | |
*** r-daneel has quit IRC | 19:09 | |
*** r-daneel_ is now known as r-daneel | 19:09 | |
lbragstad | bah... | 19:19 |
lbragstad | #endmeeting keystone | 19:19 |
*** openstack changes topic to "Queens release schedule: https://releases.openstack.org/queens/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/5F0h9Hoe/keystone" | 19:19 | |
openstack | Meeting ended Tue Feb 6 19:19:34 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 19:19 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/keystone/2018/keystone.2018-02-06-19.00.html | 19:19 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/keystone/2018/keystone.2018-02-06-19.00.txt | 19:19 |
openstack | Log: http://eavesdrop.openstack.org/meetings/keystone/2018/keystone.2018-02-06-19.00.log.html | 19:19 |
lbragstad | #startmeeting keystone-office-hours | 19:19 |
openstack | Meeting started Tue Feb 6 19:19:41 2018 UTC and is due to finish in 60 minutes. The chair is lbragstad. Information about MeetBot at http://wiki.debian.org/MeetBot. | 19:19 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 19:19 |
*** openstack changes topic to " (Meeting topic: keystone-office-hours)" | 19:19 | |
*** ChanServ changes topic to "Queens release schedule: https://releases.openstack.org/queens/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/5F0h9Hoe/keystone" | 19:19 | |
openstack | The meeting name has been set to 'keystone_office_hours' | 19:19 |
lbragstad | sorry about that | 19:19 |
cmurphy | lol | 19:19 |
gagehugo | :) | 19:20 |
lbragstad | cmurphy: https://review.openstack.org/#/c/529914/ looks ok to me, but it'd be good to get your feedback on it whenever you have a minute | 19:51 |
cmurphy | lbragstad: yeah i'm looking at it now | 19:52 |
lbragstad | wunderbar | 19:55 |
openstackgerrit | Eric Fried proposed openstack/keystoneauth master: DNM: Debug nova-next failure: user headers https://review.openstack.org/541425 | 19:57 |
openstackgerrit | Eric Fried proposed openstack/keystoneauth master: DNM: Debug nova-next failure: invalidate https://review.openstack.org/541429 | 20:02 |
openstackgerrit | Eric Fried proposed openstack/keystoneauth master: DNM: Debug nova-next failure: connection params https://review.openstack.org/541431 | 20:04 |
lbragstad | kmalloc: https://review.openstack.org/#/c/541074/ finishes up the self.<api> refactor in tests | 20:08 |
lbragstad | https://review.openstack.org/#/c/531915/ closes a bug, too | 20:10 |
*** r-daneel_ has joined #openstack-keystone | 20:16 | |
*** r-daneel has quit IRC | 20:17 | |
*** r-daneel_ is now known as r-daneel | 20:17 | |
*** Exhar has joined #openstack-keystone | 20:23 | |
*** jessegler has quit IRC | 20:28 | |
*** raildo has quit IRC | 20:40 | |
kmalloc | lbragstad: sorry missed the meeting, was picking up Brie from the airport | 20:53 |
lbragstad | no worries | 20:53 |
cmurphy | lbragstad: +2 but with comments, maybe knikolla could take a look? https://review.openstack.org/#/c/529914/ | 20:54 |
*** takamatsu has quit IRC | 21:01 | |
kmalloc | lbragstad: +2/+A on both of those 1074 and 1915 | 21:01 |
lbragstad | fantastic | 21:01 |
lbragstad | quick question | 21:04 |
lbragstad | our install guide goes through port 35357 | 21:04 |
lbragstad | and does the install based on that port | 21:04 |
lbragstad | thoughts on rewriting the install guide to use uwsgi + apache instead? | 21:05 |
lbragstad | and ProxyPass? | 21:05 |
lbragstad | so something like this for uwsgi https://github.com/openstack/openstack-ansible-os_keystone/blob/master/templates/keystone-uwsgi.ini.j2 and something like this for apache https://github.com/openstack/openstack-ansible-os_keystone/blob/master/templates/keystone-httpd.conf.j2#L109-L110 ? | 21:06 |
cmurphy | +1 but you might need to coordinate with distros who are shipping default vhost files | 21:07 |
lbragstad | with the removal of v2.0, we don't actually need both ports | 21:07 |
lbragstad | yeah - that's a good point | 21:08 |
gagehugo | so just 5000? | 21:09 |
lbragstad | well - it could be up to the deployers discretion | 21:10 |
lbragstad | because the port would only get used in the ProxyPass statement in apache configuration | 21:10 |
lbragstad | apache would be doing something like `ProxyPass /identity uwsgi://127.0.0.1:5000/` | 21:10 |
lbragstad | or `ProxyPass /identity uwsgi://127.0.0.1:8443/` | 21:11 |
lbragstad | and uwsgi would be running keystone on that port | 21:12 |
lbragstad | but you could also specify that port in apache, too i suppose | 21:13 |
lbragstad | https://github.com/openstack/openstack-ansible-os_keystone/blob/master/templates/keystone-httpd.conf.j2#L71-L72 | 21:13 |
lbragstad | kinda like what osa does ^ | 21:13 |
gagehugo | yea | 21:14 |
lbragstad | so you could specify http:$CONTROLLER_IP:5000/identity | 21:15 |
lbragstad | wait - actually | 21:15 |
lbragstad | it would be http://$CONTROLLER_IP/identity | 21:15 |
lbragstad | which would route to uwsgi internally on port 5000 | 21:16 |
lbragstad | if i'm understand the apache config correctly | 21:16 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Update sample configuration file for Queens https://review.openstack.org/541447 | 21:20 |
*** AlexeyAbashkin has quit IRC | 21:21 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: WIP - Add opts --only-invalid and --remove-assignment for mapping_purge https://review.openstack.org/487579 | 21:30 |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: WIP - Add opts --invalid and --assignments for mapping_purge https://review.openstack.org/487579 | 21:31 |
*** threestrands has joined #openstack-keystone | 21:32 | |
*** threestrands has quit IRC | 21:32 | |
*** threestrands has joined #openstack-keystone | 21:32 | |
*** Suramya has quit IRC | 21:33 | |
*** jessegler has joined #openstack-keystone | 21:37 | |
*** dave-mcc_ has quit IRC | 21:41 | |
lbragstad | cmurphy: do you know who maintains the package files for suse? | 21:42 |
cmurphy | lbragstad: yes | 21:42 |
*** jmlowe has quit IRC | 21:42 | |
cmurphy | my team | 21:42 |
cmurphy | can def help there | 21:43 |
lbragstad | sweet | 21:43 |
lbragstad | i kinda went down a rabbit hole looking for the debian packagers | 21:43 |
lbragstad | https://github.com/openstack/deb-keystone | 21:43 |
lbragstad | i think that's where they used to be | 21:43 |
* lbragstad wonders if hrybacki knows who maintains the redhat package files for keystone | 21:44 | |
gagehugo | lol | 21:44 |
cmurphy | i think the debian packages moved off of openstack infra | 21:44 |
cmurphy | but we don't have docs for debian anyways, need to engage the ubuntu people | 21:45 |
gagehugo | think the raspbian package for keystone is icehouse | 21:45 |
cmurphy | lol | 21:45 |
lbragstad | nice | 21:45 |
lbragstad | get it while it's hot | 21:45 |
hrybacki | oh jeez, ayoung might still be in charge of them? I'm sure that falls on my team however | 21:46 |
lbragstad | cmurphy: this looks like the right ubuntu team? https://wiki.openstack.org/wiki/Packaging/Ubuntu | 21:47 |
cmurphy | hrybacki: it's not just using delorean? | 21:47 |
cmurphy | lbragstad: yeah that looks right? | 21:48 |
hrybacki | cmurphy: I know that's involved but I'm not sure what's pushing the last leg of that (RDO->OSP) The pipeline is kind of confusing | 21:48 |
hrybacki | s/kind of// | 21:49 |
cmurphy | lbragstad: btw we're crunching to get a huge release out the door this month so i'm not going to want to propose major changes to the keystone package till march | 21:49 |
lbragstad | ack | 21:50 |
*** itlinux has quit IRC | 21:50 | |
lbragstad | so - even though we don't include v2.0 in Queens, you think we should push of refactoring the entire install guide to include uwsgi + apache on a single port until later/ | 21:50 |
cmurphy | ah actually scratch that, our release is based on pike so i can probably do whatever with the queens packages | 21:51 |
lbragstad | ok | 21:52 |
lbragstad | cool | 21:52 |
lbragstad | i was thinking it would be nice to have the install guide reflect the removal of v2.0 | 21:54 |
lbragstad | i'm just wondering if it will be too late for that | 21:54 |
lbragstad | i kinda spaced on the whole default package files thing... | 21:54 |
*** itlinux has joined #openstack-keystone | 21:54 | |
lbragstad | and how that is not controlled in our repository | 21:55 |
hrybacki | lots of moving parts to juggle | 22:04 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Remove all v2.0 APIs except the ec2tokens API https://review.openstack.org/540141 | 22:14 |
*** openstackgerrit has quit IRC | 22:16 | |
*** openstackgerrit has joined #openstack-keystone | 22:19 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove v2 and v2-admin API documentation https://review.openstack.org/540529 | 22:19 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Update curl request documentation to remove v2.0 https://review.openstack.org/539342 | 22:19 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove v2.0 extension documentation https://review.openstack.org/540525 | 22:19 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove v2.0 from documentation guides https://review.openstack.org/540499 | 22:19 |
cmurphy | oops sorry :( | 22:21 |
lbragstad | cmurphy: you're good - thanks for fixing that | 22:22 |
lbragstad | getting some information on the ubuntu packages http://paste.openstack.org/show/664081/ | 22:24 |
lbragstad | ^ because they don't have logging on that channel | 22:24 |
lbragstad | but the TL;DR is that it is here - https://git.launchpad.net/~ubuntu-server-dev/ubuntu/+source/keystone/tree/debian/keystone.conf | 22:24 |
*** jmlowe has joined #openstack-keystone | 22:28 | |
cmurphy | lbragstad: we still have this in ksm http://git.openstack.org/cgit/openstack/keystonemiddleware/tree/keystonemiddleware/auth_token/_auth.py#n66 :( we should probably fix that | 22:28 |
*** rcernin has joined #openstack-keystone | 22:28 | |
lbragstad | yeah... we have a card for all that https://trello.com/c/rP53zMgc/16-remove-v20-api-support-from-libraries | 22:29 |
lbragstad | cmurphy: that can be fixed in rocky, yeah? | 22:33 |
*** martinus__ has quit IRC | 22:37 | |
*** edmondsw has quit IRC | 22:37 | |
*** edmondsw has joined #openstack-keystone | 22:38 | |
cmurphy | lbragstad: yeah i guess? some people are going to have broken paste configs and it's not going to be clear why | 22:38 |
cmurphy | http://git.openstack.org/cgit/openstack/keystonemiddleware/tree/keystonemiddleware/auth_token/__init__.py#n889 | 22:38 |
cmurphy | i think this is what broke tripleo's CI, someone might think they're all converted to v3 but the weirdness in ksm's auth plugin handler can trick you | 22:40 |
*** edmondsw has quit IRC | 22:42 | |
lbragstad | hmm | 22:43 |
lbragstad | if we were go to a single port with package installs, would there be a recommended port to listen on? | 22:43 |
lbragstad | 35357 or 5000? | 22:43 |
cmurphy | 80/443 :) | 22:44 |
lbragstad | ++ | 22:45 |
lbragstad | full conversation from #openstack-pkg http://paste.openstack.org/show/664112/ | 22:47 |
lbragstad | looks like we'll get some assistance from the ubuntu folks! | 22:47 |
*** itlinux has quit IRC | 22:53 | |
*** spilla has quit IRC | 23:05 | |
cmurphy | #endmeeting | 23:07 |
*** openstack changes topic to "Queens release schedule: https://releases.openstack.org/queens/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/5F0h9Hoe/keystone" | 23:07 | |
openstack | Meeting ended Tue Feb 6 23:07:22 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 23:07 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/keystone_office_hours/2018/keystone_office_hours.2018-02-06-19.19.html | 23:07 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/keystone_office_hours/2018/keystone_office_hours.2018-02-06-19.19.txt | 23:07 |
openstack | Log: http://eavesdrop.openstack.org/meetings/keystone_office_hours/2018/keystone_office_hours.2018-02-06-19.19.log.html | 23:07 |
lbragstad | cmurphy: thanks... i'm failing meetings today | 23:08 |
cmurphy | :) | 23:08 |
*** r-daneel has quit IRC | 23:12 | |
*** r-daneel has joined #openstack-keystone | 23:13 | |
*** StefanPaetowJisc has joined #openstack-keystone | 23:29 | |
*** brad[] has quit IRC | 23:29 | |
gagehugo | lbragstad https://www.notebookcheck.net/Loose-screws-Partial-recall-of-the-Lenovo-ThinkPad-X1-Carbon-2017.281634.0.html | 23:39 |
lbragstad | gagehugo: have you noticed issues? | 23:52 |
*** StefanPaetowJisc has quit IRC | 23:55 | |
*** StefanPaetowJisc has joined #openstack-keystone | 23:57 | |
*** StefanPaetowJisc has quit IRC | 23:59 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!