*** felipemonteiro has joined #openstack-keystone | 00:00 | |
*** r-daneel has quit IRC | 00:08 | |
*** felipemonteiro has quit IRC | 00:09 | |
*** felipemonteiro has joined #openstack-keystone | 00:14 | |
*** felipemonteiro_ has joined #openstack-keystone | 00:16 | |
*** felipemonteiro has quit IRC | 00:20 | |
*** blake has quit IRC | 00:22 | |
*** r-daneel has joined #openstack-keystone | 00:25 | |
*** felipemonteiro_ has quit IRC | 00:25 | |
*** r-daneel_ has joined #openstack-keystone | 00:29 | |
*** r-daneel has quit IRC | 00:29 | |
*** r-daneel_ is now known as r-daneel | 00:29 | |
*** dineshbhor__ has joined #openstack-keystone | 00:31 | |
*** annp has joined #openstack-keystone | 00:48 | |
*** blake has joined #openstack-keystone | 00:49 | |
*** r-daneel has quit IRC | 00:50 | |
*** blake has quit IRC | 00:52 | |
*** liuzz has joined #openstack-keystone | 01:11 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Unified limit update APIs Refactor https://review.openstack.org/559552 | 01:29 |
---|---|---|
*** r-daneel has joined #openstack-keystone | 01:32 | |
*** r-daneel has quit IRC | 01:37 | |
*** r-daneel has joined #openstack-keystone | 01:40 | |
*** gyee has quit IRC | 01:41 | |
*** boris_42_ has quit IRC | 01:50 | |
*** felipemo_ has joined #openstack-keystone | 02:12 | |
*** itlinux has joined #openstack-keystone | 02:36 | |
*** ayoung has quit IRC | 02:50 | |
*** liuzz_ has joined #openstack-keystone | 02:51 | |
*** liuzz has quit IRC | 02:53 | |
*** ayoung has joined #openstack-keystone | 03:00 | |
*** liuzz has joined #openstack-keystone | 03:26 | |
*** liuzz_ has quit IRC | 03:27 | |
*** bhagyashris has quit IRC | 03:35 | |
*** ayoung has quit IRC | 03:40 | |
*** dave-mccowan has quit IRC | 03:45 | |
*** bhagyashris has joined #openstack-keystone | 03:46 | |
*** liuzz_ has joined #openstack-keystone | 03:52 | |
*** liuzz has quit IRC | 03:53 | |
*** annp has quit IRC | 04:00 | |
*** annp has joined #openstack-keystone | 04:00 | |
*** germs has quit IRC | 04:12 | |
*** ykarel|away has joined #openstack-keystone | 04:16 | |
*** ykarel|away is now known as ykarel | 04:16 | |
*** lifeless_ has quit IRC | 04:22 | |
*** threestrands has quit IRC | 04:47 | |
*** dineshbhor__ has quit IRC | 04:59 | |
*** links has joined #openstack-keystone | 05:00 | |
*** dineshbhor__ has joined #openstack-keystone | 05:02 | |
*** liuzz has joined #openstack-keystone | 05:05 | |
*** liuzz_ has quit IRC | 05:05 | |
*** felipemo_ has quit IRC | 05:07 | |
*** pcaruana has quit IRC | 05:09 | |
*** lifeless has joined #openstack-keystone | 05:17 | |
*** pcichy has quit IRC | 05:40 | |
*** jaosorior has quit IRC | 05:41 | |
*** pcichy has joined #openstack-keystone | 05:55 | |
*** itlinux has quit IRC | 06:17 | |
*** pcaruana has joined #openstack-keystone | 06:17 | |
*** mtreinish has quit IRC | 06:19 | |
*** AlexeyAbashkin has joined #openstack-keystone | 06:20 | |
*** liuzz_ has joined #openstack-keystone | 06:22 | |
*** liuzz has quit IRC | 06:24 | |
*** threestrands has joined #openstack-keystone | 06:27 | |
*** AlexeyAbashkin has quit IRC | 06:33 | |
*** martinus__ has joined #openstack-keystone | 06:47 | |
*** mtreinish has joined #openstack-keystone | 06:58 | |
*** AlexeyAbashkin has joined #openstack-keystone | 06:59 | |
*** evrardjp_ is now known as evrardjp | 07:12 | |
*** tesseract has joined #openstack-keystone | 07:16 | |
*** rcernin has quit IRC | 07:27 | |
*** sapd has quit IRC | 07:27 | |
*** sapd has joined #openstack-keystone | 07:27 | |
*** lifeless has quit IRC | 07:28 | |
*** lifeless has joined #openstack-keystone | 07:35 | |
*** s10 has joined #openstack-keystone | 08:09 | |
*** ykarel is now known as ykarel|lunch | 08:19 | |
*** AlexeyAbashkin has quit IRC | 08:53 | |
*** AlexeyAbashkin has joined #openstack-keystone | 09:04 | |
*** ykarel|lunch is now known as ykarel | 09:09 | |
*** jaosorior has joined #openstack-keystone | 09:15 | |
*** s10 has quit IRC | 09:20 | |
*** links has quit IRC | 09:33 | |
*** links has joined #openstack-keystone | 09:33 | |
*** sonuk has joined #openstack-keystone | 09:33 | |
*** sonuk_ has quit IRC | 09:35 | |
*** dineshbhor__ has quit IRC | 09:53 | |
*** threestrands has quit IRC | 09:54 | |
*** AlexeyAbashkin has quit IRC | 10:03 | |
*** nicolasbock has joined #openstack-keystone | 10:37 | |
*** annp has quit IRC | 11:02 | |
*** AlexeyAbashkin has joined #openstack-keystone | 11:03 | |
*** ykarel_ has joined #openstack-keystone | 11:31 | |
*** ykarel has quit IRC | 11:34 | |
*** ykarel_ is now known as ykarel | 11:34 | |
*** nicolasbock has quit IRC | 11:42 | |
*** raildo has joined #openstack-keystone | 12:05 | |
*** nicolasbock has joined #openstack-keystone | 12:11 | |
*** felipemonteiro has joined #openstack-keystone | 12:26 | |
*** felipemonteiro has quit IRC | 12:47 | |
*** lifeless has quit IRC | 12:48 | |
*** lifeless has joined #openstack-keystone | 12:49 | |
*** edmondsw has joined #openstack-keystone | 12:54 | |
*** AlexeyAbashkin has quit IRC | 12:56 | |
*** dave-mccowan has joined #openstack-keystone | 13:00 | |
*** AlexeyAbashkin has joined #openstack-keystone | 13:04 | |
*** dave-mccowan has quit IRC | 13:05 | |
*** SpamapS has joined #openstack-keystone | 13:06 | |
SpamapS | greetings keystoners | 13:06 |
SpamapS | I have a weird problem going on, trying to figure out what's happening. | 13:06 |
SpamapS | why would `openstack role list` return differenting things if I pass --domain or not, when I have only one domain, and it's the 'default/Default' domain? | 13:07 |
*** felipemonteiro has joined #openstack-keystone | 13:09 | |
*** dave-mccowan has joined #openstack-keystone | 13:10 | |
cmurphy | SpamapS: because there are global roles and their are domain-specific roles, so if you pass --domain default you're asking for roles that are namespaced within the default domain | 13:10 |
SpamapS | cmurphy: ah, that makes sense, ok. Are there global role assignments too? | 13:11 |
cmurphy | SpamapS: no, role assignments are always made with a scope, which can be a project, domain, or the "system" (which sounds like global but it's not exactly) | 13:12 |
SpamapS | oh ok I see, so that's why I have role assignments with project, but no domain | 13:13 |
cmurphy | yes | 13:13 |
SpamapS | We've had a couple of mind bending days because of https://review.openstack.org/575234 | 13:13 |
SpamapS | ugh and now I see that comment and I'm back to o_O | 13:14 |
cmurphy | hmm well there is `openstack role list` and `openstack role assignment list` and the --domain would have different meanings for each | 13:16 |
kmalloc | Domain specific roles are... Weird in their implmentation | 13:16 |
kmalloc | Because you also have to create inferences or they do nothing. | 13:16 |
*** felipemonteiro has quit IRC | 13:16 | |
kmalloc | Our docs suck on this front. | 13:16 |
SpamapS | It's hard to document inference. | 13:17 |
SpamapS | Anyway, I think I understand why I'm seeing what I'm seeing now. | 13:18 |
SpamapS | There may be more later. :-P | 13:18 |
SpamapS | Thanks. :-D | 13:21 |
cmurphy | :) | 13:21 |
*** r-daneel has quit IRC | 13:26 | |
*** AlexeyAbashkin has quit IRC | 13:43 | |
kmalloc | SpamapS: sure thing, come visit us anytime! | 13:45 |
kmalloc | :) | 13:45 |
*** AlexeyAbashkin has joined #openstack-keystone | 13:46 | |
*** dave-mccowan has quit IRC | 13:52 | |
*** Tahvok has quit IRC | 13:54 | |
*** r-daneel has joined #openstack-keystone | 13:56 | |
*** linkmark has quit IRC | 13:57 | |
*** r-daneel_ has joined #openstack-keystone | 13:59 | |
*** r-daneel has quit IRC | 14:00 | |
*** r-daneel_ is now known as r-daneel | 14:00 | |
*** Tahvok has joined #openstack-keystone | 14:02 | |
openstackgerrit | Lance Bragstad proposed openstack/python-keystoneclient master: Add support for registered limits https://review.openstack.org/537668 | 14:02 |
*** ykarel is now known as ykarel|away | 14:04 | |
openstackgerrit | Lance Bragstad proposed openstack/python-keystoneclient master: Add support for project-specific limits https://review.openstack.org/574391 | 14:05 |
*** r-daneel_ has joined #openstack-keystone | 14:06 | |
*** r-daneel has quit IRC | 14:07 | |
*** r-daneel_ is now known as r-daneel | 14:07 | |
kmalloc | lbragstad: hm | 14:12 |
kmalloc | lbragstad: question for you regarding shadow users | 14:12 |
lbragstad | not sure how useful i'll be but i can try :) | 14:13 |
kmalloc | lbragstad: it appears .get_user is only ever returning the local user, how does that work for referencing the shadow user info | 14:13 |
kmalloc | and more specifically, what, if anything, are we doing with LDAP users being shadowed. | 14:13 |
lbragstad | i think that's a separate method... called get_federated_user? | 14:13 |
kmalloc | ah, right. | 14:13 |
kmalloc | but that seems to only affect LIST | 14:14 |
kmalloc | afaict, we don't actually use shadow_user for ... anything outside of mirroring in auth and for authenticate | 14:14 |
kmalloc | it feels like we never got to the point of actually using shadow users effectively.. | 14:15 |
*** links has quit IRC | 14:15 | |
kmalloc | edmondsw: i need your brain re: shadow_users since you helped build it | 14:15 |
lbragstad | that's what rderose and ravelar were working on | 14:15 |
kmalloc | right. | 14:15 |
edmondsw | kmalloc presenting | 14:16 |
kmalloc | so.. TL;DR clearing stale shadow entries should be 100% safe? | 14:16 |
kmalloc | edmondsw: we don't use shadow users really for anything, since rderose and ravelar didn't finish the full integration | 14:16 |
kmalloc | edmondsw: right? | 14:16 |
kmalloc | edmondsw: i have a question about someone getting a conflict due to maybe a stale entry | 14:17 |
kmalloc | LDAP backend. | 14:17 |
kmalloc | if i advise just "clear the stale entry", there is no way a rogue assignment is going to linger around | 14:17 |
kmalloc | because we havent gotten that integration in place yet, right? | 14:17 |
*** mchlumsky has joined #openstack-keystone | 14:21 | |
kmalloc | lbragstad: i advised it is probably safe to drop the LDAP shadow since we're not leaning on it. | 14:24 |
lbragstad | i want to say that was kept around because we wanted to unify all identities | 14:24 |
kmalloc | right | 14:24 |
kmalloc | and we should still do that | 14:24 |
kmalloc | buuuuuut... | 14:24 |
kmalloc | it's not there yet | 14:24 |
*** dave-mccowan has joined #openstack-keystone | 14:26 | |
*** AlexeyAbashkin has quit IRC | 14:32 | |
lbragstad | i really need to sit down sometime and reassess that work | 14:44 |
kmalloc | lbragstad: you and I both | 14:46 |
lbragstad | preferrably before the ptg | 14:47 |
kmalloc | lets set a time and just carve out an hour to bluejeans and discuss where we are at | 14:47 |
kmalloc | or so* | 14:48 |
*** r-daneel_ has joined #openstack-keystone | 14:48 | |
lbragstad | sure | 14:48 |
*** r-daneel has quit IRC | 14:49 | |
*** r-daneel_ is now known as r-daneel | 14:49 | |
openstackgerrit | Harry Rybacki proposed openstack/keystone master: Ensure default roles created during bootstrap https://review.openstack.org/572243 | 14:55 |
hrybacki | lbragstad: did Ozz's comment address your testing concern? | 14:55 |
hrybacki | WRT default roles | 14:55 |
lbragstad | i can check | 14:55 |
lbragstad | i haven't looked yet | 14:55 |
hrybacki | ack tl;dr test coverage touches it but there is not an explicit test for that helper method | 14:56 |
knikolla | o/ | 14:58 |
kmalloc | lbragstad: do you want me to try and isolate https://review.openstack.org/#/c/574735/ from the chain so we can land it sooner? | 14:59 |
kmalloc | lbragstad: i can try and do that today, or i can wrangle some folks to review the preceeding patches | 15:00 |
lbragstad | i can get back to reviewing that today | 15:00 |
kmalloc | (might be quicker since gate -> merge vs check->gate->merge) | 15:00 |
lbragstad | i've been buried in ksc and osc patches | 15:00 |
kmalloc | the other patches are simple | 15:00 |
kmalloc | in comparison | 15:00 |
kmalloc | no functionality changes, just "requirement addition" and scaffolding | 15:01 |
kmalloc | oh, there is one change | 15:01 |
kmalloc | the compression down to just public_endpoint not admin and public endpoint | 15:01 |
kmalloc | admin endpoint is only used in our local testing now (fwiw) | 15:01 |
kmalloc | i'll try to get eyes on osc and ksc patches today as well | 15:01 |
lbragstad | https://review.openstack.org/#/q/topic:bp/unified-limits+status:open+(project:openstack/python-keystoneclient+OR+project:openstack/python-openstackclient) | 15:02 |
lbragstad | the ksc patches should be good to go | 15:04 |
lbragstad | the only one that needs work is the osc patch for project-specific limits | 15:04 |
lbragstad | the osc patch for registered limits needs unit tests yet, but it should have complete coverage from a functional testing perspective | 15:05 |
*** pcaruana has quit IRC | 15:24 | |
*** ykarel_ has joined #openstack-keystone | 15:31 | |
*** ykarel|away has quit IRC | 15:34 | |
*** spilla has joined #openstack-keystone | 15:37 | |
*** germs has joined #openstack-keystone | 15:52 | |
*** germs has quit IRC | 15:52 | |
*** germs has joined #openstack-keystone | 15:52 | |
lbragstad | the osc unit tests kinda blow my mind | 15:53 |
*** linkmark has joined #openstack-keystone | 15:53 | |
*** lifeless has quit IRC | 16:07 | |
*** lifeless has joined #openstack-keystone | 16:08 | |
*** gyee has joined #openstack-keystone | 16:19 | |
*** jmlowe has quit IRC | 16:31 | |
* lbragstad steps away for lunch | 16:32 | |
*** germs has quit IRC | 16:32 | |
*** zzzeek has quit IRC | 16:38 | |
*** germs has joined #openstack-keystone | 16:41 | |
*** germs has quit IRC | 16:41 | |
*** germs has joined #openstack-keystone | 16:41 | |
*** mchlumsky_ has joined #openstack-keystone | 16:42 | |
*** mchlumsky has quit IRC | 16:42 | |
*** zzzeek has joined #openstack-keystone | 16:44 | |
*** germs has quit IRC | 16:47 | |
kmalloc | lbragstad: heh | 17:01 |
*** felipemonteiro has joined #openstack-keystone | 17:25 | |
*** tesseract has quit IRC | 17:30 | |
*** dave-mccowan has quit IRC | 17:30 | |
*** jmlowe has joined #openstack-keystone | 17:42 | |
*** pcaruana has joined #openstack-keystone | 17:43 | |
*** ykarel_ has quit IRC | 17:58 | |
*** pcaruana has quit IRC | 18:01 | |
*** pcaruana has joined #openstack-keystone | 18:06 | |
*** spilla has quit IRC | 18:10 | |
*** spilla has joined #openstack-keystone | 18:11 | |
*** felipemonteiro has quit IRC | 18:19 | |
*** mvenesio has joined #openstack-keystone | 18:27 | |
*** r-daneel has quit IRC | 18:28 | |
*** r-daneel has joined #openstack-keystone | 18:28 | |
openstackgerrit | Lance Bragstad proposed openstack/python-keystoneclient master: Add support for registered limits https://review.openstack.org/537668 | 18:39 |
openstackgerrit | Lance Bragstad proposed openstack/python-keystoneclient master: Add support for project-specific limits https://review.openstack.org/574391 | 18:39 |
lbragstad | kmalloc: knikolla fixed ^ | 18:39 |
*** germs has joined #openstack-keystone | 18:43 | |
*** germs has quit IRC | 18:43 | |
*** germs has joined #openstack-keystone | 18:43 | |
*** germs has quit IRC | 18:47 | |
edmondsw | kmalloc sorry, you caught me while I was presenting to upper mgmt and then it slipped my mind when I got out. | 18:51 |
edmondsw | kmalloc shadow users... I honestly don't know how much they are or are not used with LDAP. I haven't thought about that stuff in a long time and I wasn't all that involved to begin with | 18:52 |
edmondsw | kmalloc you're not talking about code changes, just clearing someones db to get past an issue, right? | 18:52 |
*** dave-mccowan has joined #openstack-keystone | 18:52 | |
edmondsw | I don't think that would be an issue. I'd want to talk more if we're proposing code changes | 18:53 |
*** spilla has quit IRC | 18:57 | |
kmalloc | Nope, just clearing data in a db | 19:13 |
*** felipemonteiro has joined #openstack-keystone | 19:15 | |
*** lifeless has quit IRC | 19:37 | |
*** aojea_ has joined #openstack-keystone | 19:41 | |
*** jmlowe has quit IRC | 19:43 | |
*** lifeless has joined #openstack-keystone | 19:53 | |
*** jmlowe has joined #openstack-keystone | 20:05 | |
*** spilla has joined #openstack-keystone | 20:05 | |
*** raildo has quit IRC | 20:12 | |
*** felipemonteiro has quit IRC | 20:16 | |
*** spilla has quit IRC | 20:16 | |
*** spilla has joined #openstack-keystone | 20:27 | |
lamt | o/ I have a question re: oidc federation: is it possible for the openstack client to use oidc (keycloak atm). I can get horizon to authenticate and it seems oidc returns an access token back correctly, but when it redirects back to /v3/OS-FEDERATION/identity_providers/myidp/protocols/mapped/auth - I run into 'Connection broken: IncompleteRead(0 bytes read)' - not sure if it is the mod_auth_openidc setting. | 20:29 |
*** martinus__ has quit IRC | 20:36 | |
*** spilla has quit IRC | 21:13 | |
*** mvenesio has quit IRC | 21:35 | |
*** mvenesio has joined #openstack-keystone | 21:36 | |
*** mvenesio has quit IRC | 21:40 | |
*** dave-mccowan has quit IRC | 21:45 | |
*** lifeless has quit IRC | 21:49 | |
*** lifeless has joined #openstack-keystone | 21:51 | |
*** jmlowe has quit IRC | 21:52 | |
*** edmondsw has quit IRC | 21:54 | |
*** jmlowe has joined #openstack-keystone | 21:59 | |
*** aojea_ has quit IRC | 22:11 | |
*** mchlumsky_ has quit IRC | 22:16 | |
*** rcernin has joined #openstack-keystone | 22:20 | |
*** nicolasbock has quit IRC | 22:34 | |
knikolla | lamt: yes | 22:48 |
knikolla | https://osticket.massopen.cloud/kb/faq.php?id=16 | 22:48 |
*** boris_42_ has joined #openstack-keystone | 22:48 | |
knikolla | and https://github.com/CCI-MOC/MOCOSPpuppet/blob/master/keystone/templates/wsgi-keystone.erb#L76-L89 | 22:50 |
knikolla | you need to enable oauth20 on that url so that it works with the access token given. | 22:51 |
knikolla | hope that helps. ping me if you need help. | 22:52 |
kmalloc | lbragstad: +2 on the ksc ones | 22:53 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Store JSON Home Resources off the composing router https://review.openstack.org/574735 | 22:54 |
kmalloc | lbragstad: ^ that had 2x+2+A but rebased out of the chain | 22:55 |
kmalloc | now | 22:55 |
kmalloc | lbragstad: want to just push it through? | 22:56 |
*** threestrands has joined #openstack-keystone | 22:56 | |
*** threestrands has quit IRC | 22:56 | |
*** threestrands has joined #openstack-keystone | 22:56 | |
*** dklyle has quit IRC | 22:56 | |
*** dklyle has joined #openstack-keystone | 22:57 | |
*** threestrands has quit IRC | 22:57 | |
*** threestrands has joined #openstack-keystone | 22:57 | |
*** threestrands has quit IRC | 22:57 | |
*** threestrands has joined #openstack-keystone | 22:57 | |
lamt | knikolla: thanks - I will try it out tomorrow | 23:08 |
knikolla | kmalloc: i'll push it | 23:09 |
kmalloc | knikolla: cool thnx | 23:12 |
knikolla | 60% of this week has been meetings so far | 23:13 |
knikolla | i'm happy to look at code | 23:13 |
kmalloc | hehe | 23:13 |
*** itlinux has joined #openstack-keystone | 23:29 | |
*** r-daneel has quit IRC | 23:37 | |
*** lifeless_ has joined #openstack-keystone | 23:42 | |
*** lifeless has quit IRC | 23:43 | |
*** markvoelker has quit IRC | 23:46 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!