*** wxy has joined #openstack-keystone | 01:24 | |
*** edmondsw has joined #openstack-keystone | 01:29 | |
*** edmondsw has quit IRC | 01:34 | |
*** openstackgerrit has quit IRC | 01:49 | |
*** jmlowe has quit IRC | 02:13 | |
*** jmlowe has joined #openstack-keystone | 02:14 | |
*** slunkad has quit IRC | 02:17 | |
*** slunkad has joined #openstack-keystone | 02:19 | |
*** idlemind has joined #openstack-keystone | 02:44 | |
*** edmondsw has joined #openstack-keystone | 03:17 | |
*** edmondsw has quit IRC | 03:22 | |
*** pooja_jadhav has joined #openstack-keystone | 04:36 | |
*** openstackgerrit has joined #openstack-keystone | 04:39 | |
openstackgerrit | Tuan Do Anh proposed openstack/keystone master: Change "a SQL" to "an SQL" https://review.openstack.org/579432 | 04:39 |
---|---|---|
*** rcernin has quit IRC | 04:55 | |
*** dklyle has quit IRC | 04:58 | |
*** edmondsw has joined #openstack-keystone | 05:06 | |
*** links has joined #openstack-keystone | 05:09 | |
*** links has quit IRC | 05:09 | |
*** edmondsw has quit IRC | 05:11 | |
*** sonuk_ has joined #openstack-keystone | 05:16 | |
*** sonuk has quit IRC | 05:19 | |
*** rcernin has joined #openstack-keystone | 05:41 | |
*** rcernin has quit IRC | 05:41 | |
*** rcernin has joined #openstack-keystone | 05:41 | |
*** rcernin has quit IRC | 05:41 | |
*** rcernin has joined #openstack-keystone | 05:42 | |
*** blake has joined #openstack-keystone | 05:57 | |
*** peereb has joined #openstack-keystone | 06:00 | |
*** martinus__ has joined #openstack-keystone | 06:12 | |
*** josecastroleon has joined #openstack-keystone | 06:20 | |
*** dmellado has joined #openstack-keystone | 06:23 | |
openstackgerrit | Adrian Turjak proposed openstack/keystone master: Implement auth receipts spec https://review.openstack.org/572286 | 06:29 |
adriant | cmurphy, lbragstad[m], kmalloc: ^ I've removed the WIP, tested in devstack, found the thing that was bugging me about the tests, and was able to issue myself a receipt, and then a token by doing password + totp! | 06:30 |
adriant | My plan right now is if we can get this in by rocky, to then start work in Keystoneauth to make this all play nice and my goal by end of Stein is support in OpenstackClient and Horizon | 06:32 |
*** threestrands has joined #openstack-keystone | 06:33 | |
*** threestrands has quit IRC | 06:33 | |
*** threestrands has joined #openstack-keystone | 06:33 | |
adriant | keystoneauth doesn't follow the release cycle right? So I can probably start work on that and get it in around end of rocky, and then Stein will be all about getting the rest to play nice | 06:34 |
adriant | We also need to add support for user Options to the SDK, and do we have docs for user options? | 06:34 |
adriant | The API ref doesn't mention options, so maybe we should add them there. | 06:35 |
*** threestrands has quit IRC | 06:37 | |
*** nicolasbock has joined #openstack-keystone | 06:39 | |
adriant | We should also consider if we want to expose some element of MFA options to users themselves with a refined policy, but meanwhile I'll add an API in Adjutant for managing those that's based on what I have in adjutant-mfa already. | 06:44 |
*** edmondsw has joined #openstack-keystone | 06:55 | |
*** edmondsw has quit IRC | 07:00 | |
*** josecastroleon has quit IRC | 07:01 | |
*** rcernin has quit IRC | 07:09 | |
*** josecastroleon has joined #openstack-keystone | 07:11 | |
cmurphy | adriant: keystoneauth follows the non-client schedule of the release cycle, so its deadline is the week after keystone's feature freeze https://releases.openstack.org/rocky/schedule.html | 07:14 |
cmurphy | I'm not sure what you mean by options | 07:15 |
*** rha has joined #openstack-keystone | 07:24 | |
*** rha has quit IRC | 07:24 | |
*** rha has joined #openstack-keystone | 07:24 | |
*** tesseract has joined #openstack-keystone | 07:27 | |
*** sapd_ has quit IRC | 07:33 | |
*** sapd_ has joined #openstack-keystone | 07:34 | |
*** sonuk has joined #openstack-keystone | 07:42 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Add project_id filter for listing limit https://review.openstack.org/579330 | 07:43 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: [WIP] Add show hierarchy filter https://review.openstack.org/579331 | 07:43 |
*** blake has quit IRC | 07:43 | |
*** sonuk_ has quit IRC | 07:45 | |
*** vishakha has quit IRC | 07:45 | |
*** vishakha has joined #openstack-keystone | 07:59 | |
*** d0ugal has joined #openstack-keystone | 08:01 | |
*** d0ugal has quit IRC | 08:01 | |
*** d0ugal has joined #openstack-keystone | 08:01 | |
*** josecastroleon has quit IRC | 08:35 | |
openstackgerrit | Neha Alhat proposed openstack/keystonemiddleware master: Register 'split_loggers' conf option https://review.openstack.org/578008 | 08:40 |
*** edmondsw has joined #openstack-keystone | 08:43 | |
*** edmondsw has quit IRC | 08:47 | |
*** sonuk_ has joined #openstack-keystone | 09:10 | |
*** sonuk has quit IRC | 09:13 | |
*** lifeless has quit IRC | 09:17 | |
*** lifeless has joined #openstack-keystone | 09:18 | |
*** AlexeyAbashkin has joined #openstack-keystone | 09:23 | |
*** AlexeyAbashkin has quit IRC | 09:32 | |
*** sanjaik has joined #openstack-keystone | 09:35 | |
*** vigneshwar has joined #openstack-keystone | 09:42 | |
*** vigneshwar has left #openstack-keystone | 09:49 | |
*** vigneshwar has joined #openstack-keystone | 09:49 | |
*** d0ugal has quit IRC | 09:55 | |
*** d0ugal has joined #openstack-keystone | 09:55 | |
*** d0ugal has quit IRC | 09:55 | |
*** d0ugal has joined #openstack-keystone | 09:55 | |
*** sonuk has joined #openstack-keystone | 10:41 | |
*** sonuk_ has quit IRC | 10:43 | |
*** sanjaik has quit IRC | 10:57 | |
*** edmondsw has joined #openstack-keystone | 11:14 | |
*** jroll has quit IRC | 11:36 | |
*** mvk has quit IRC | 11:37 | |
*** jroll has joined #openstack-keystone | 11:40 | |
*** peereb has quit IRC | 11:54 | |
*** raildo has joined #openstack-keystone | 12:16 | |
*** jrist has joined #openstack-keystone | 12:34 | |
*** mvk has joined #openstack-keystone | 12:41 | |
*** tesseract has quit IRC | 13:04 | |
*** tesseract has joined #openstack-keystone | 13:10 | |
*** tesseract has quit IRC | 13:10 | |
*** d0ugal has quit IRC | 13:13 | |
*** raildo has quit IRC | 13:17 | |
*** raildo has joined #openstack-keystone | 13:18 | |
*** raildo has quit IRC | 13:21 | |
*** raildo has joined #openstack-keystone | 13:30 | |
*** d0ugal has joined #openstack-keystone | 13:35 | |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Convert oslo.policy to using stestr https://review.openstack.org/579295 | 13:37 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Convert oslo.policy to using stestr https://review.openstack.org/579295 | 13:38 |
*** tesseract has joined #openstack-keystone | 13:38 | |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Pass dictionary as creds in policy tests https://review.openstack.org/578994 | 13:41 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Teach Enforcer.enforce to deal with context objects https://review.openstack.org/578995 | 13:41 |
knikolla | o/ | 13:56 |
elbragstad | morning | 13:56 |
cmurphy | \o | 13:57 |
*** vegarl has quit IRC | 13:57 | |
elbragstad | some folks are going to be on a short week, yeah? | 13:57 |
* cmurphy nope :'( | 13:58 | |
elbragstad | i can already feel how quiet it is going to be | 13:59 |
*** raildo has quit IRC | 13:59 | |
elbragstad | i'll be in today and tomorrow, but otherwise i'll be trying to be afk | 14:01 |
*** vegarl has joined #openstack-keystone | 14:03 | |
*** hoonetorg has quit IRC | 14:06 | |
*** raildo has joined #openstack-keystone | 14:07 | |
*** xinran__ has joined #openstack-keystone | 14:09 | |
*** vigneshwar has quit IRC | 14:30 | |
kmalloc | O/ | 14:33 |
kmalloc | Morning. | 14:33 |
kmalloc | I am trying to be afkish. But lots to do. | 14:33 |
kmalloc | Will mostly be checking in in the afternoons.. technically on vacation (but massive neck spasm, so stuck laying down) | 14:34 |
elbragstad | feel better =/ | 14:34 |
kmalloc | It is already better, hot compress. But ugh woke up with it today. | 14:38 |
gagehugo | o/ | 14:40 |
kmalloc | Maybe I'll take this week to write a non-sucky mobile Gerrit interface | 14:42 |
kmalloc | Time to learn JavaScript better sometime :P | 14:42 |
kmalloc | elbragstad: is our functional gate unhappy somehow? | 14:43 |
*** elbragstad is now known as lbragstad | 14:43 | |
cmurphy | the next gerrit upgrade will include polygerrit which will be more mobile friendly | 14:43 |
lbragstad | nice | 14:43 |
lbragstad | kmalloc: do you have a link? | 14:43 |
kmalloc | cmurphy: oh that would be nice. The current interface we have had (JavaScript based one) has been awful for years now. | 14:44 |
kmalloc | I used to do most my reviews and such via.phone. | 14:44 |
cmurphy | that sounds painful | 14:45 |
kmalloc | lbragstad: looks like pip errors nvm | 14:45 |
kmalloc | cmurphy: when I lived in Pasadena (and when I was ptl) it wasn't bad. I also did most IRC meetings from my phone. | 14:46 |
lbragstad | that would drive me nuts | 14:46 |
kmalloc | Coffee shop life yo ;) | 14:46 |
lbragstad | i can barely work from my kitchen counter *with* a laptop | 14:46 |
kmalloc | The Gerrit interface was a static page. This whole dynamic frame scrolling thing is tereible | 14:47 |
kmalloc | It sucks on mobile it sucks on desktop. | 14:47 |
kmalloc | I honestly would love to go back to the old ui. | 14:47 |
kmalloc | Basically, over engineered to be "slick". | 14:48 |
ayoung | kmalloc, I need to relearn Javascript at some point | 14:49 |
ayoung | fine something that walks the balance of "Reactuive" and "just in the browser, no server side" | 14:49 |
ayoung | Or, for Gerrit, I should re-learn the Terminal based interface, whatever that was | 14:50 |
lbragstad | gerrty | 14:50 |
cmurphy | gertty | 14:50 |
lbragstad | yeah ^ | 14:51 |
cmurphy | ("tty") | 14:51 |
lbragstad | cmurphy: do you use it? | 14:51 |
cmurphy | no | 14:51 |
cmurphy | the web ui has always been good enough for me | 14:52 |
lbragstad | ah - nevermind... i played with it for about a week, but i had a hard time not using vi key mappings, so it felt super alien to me | 14:52 |
cmurphy | i think the selling point for gertty was doing offline reviews but I don't work in planes often enough to need it | 14:52 |
lbragstad | yeah... i thought the same thing | 14:53 |
*** zzzeek has quit IRC | 14:53 | |
ayoung | Is it still maintained? Wasn't Gertty a pet project of some core dev? | 14:55 |
*** zzzeek has joined #openstack-keystone | 14:55 | |
cmurphy | it's still maintained | 14:55 |
cmurphy | it's jeblair's project | 14:56 |
ayoung | I have a REST question if anyone cares to take a stab at it: For the Policy Merge and editing tool, I want to do things like "convert all rules that have `is_admin:1` to 'rule:is_admin'" And apply it to all the lines of a document. How should I represent that? | 14:56 |
ayoung | I was thinkg the refactoring itslef becomes a top level object, call it an Operator, and then some way of saying applying an Operator to all Rules. | 14:57 |
ayoung | Feels vaguely like a visitor pattern from Gof4. | 14:57 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Convert oslo.policy to using stestr https://review.openstack.org/579295 | 15:00 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Pass dictionary as creds in policy tests https://review.openstack.org/578994 | 15:00 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Teach Enforcer.enforce to deal with context objects https://review.openstack.org/578995 | 15:00 |
openstackgerrit | Merged openstack/oslo.policy master: Add blueprints and releasenotes link to README https://review.openstack.org/579329 | 15:05 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Remove unused util function https://review.openstack.org/579594 | 15:12 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Remove unused util function https://review.openstack.org/579594 | 15:14 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Add note for usage of util function https://review.openstack.org/579594 | 15:49 |
*** gyee has joined #openstack-keystone | 15:58 | |
*** mvk has quit IRC | 16:08 | |
*** dklyle has joined #openstack-keystone | 16:10 | |
*** ksavich has joined #openstack-keystone | 16:13 | |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Bump sphinx to match lower requirements https://review.openstack.org/579169 | 16:21 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Pass dictionary as creds in policy tests https://review.openstack.org/578994 | 16:21 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Teach Enforcer.enforce to deal with context objects https://review.openstack.org/578995 | 16:21 |
*** ksavich has quit IRC | 16:32 | |
*** xinran__ has quit IRC | 16:45 | |
*** alex_xu has quit IRC | 16:50 | |
*** sonuk_ has joined #openstack-keystone | 16:53 | |
*** alex_xu has joined #openstack-keystone | 16:54 | |
*** sonuk has quit IRC | 16:56 | |
*** jrist has quit IRC | 17:00 | |
*** tesseract has quit IRC | 17:02 | |
*** jrist has joined #openstack-keystone | 17:06 | |
*** peereb has joined #openstack-keystone | 17:14 | |
*** vishakha has quit IRC | 17:27 | |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Fix requirements and convert to stests https://review.openstack.org/579169 | 17:28 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Pass dictionary as creds in policy tests https://review.openstack.org/578994 | 17:28 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Teach Enforcer.enforce to deal with context objects https://review.openstack.org/578995 | 17:28 |
*** mvk has joined #openstack-keystone | 17:30 | |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Fix requirements and convert to stestr https://review.openstack.org/579169 | 17:31 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Pass dictionary as creds in policy tests https://review.openstack.org/578994 | 17:31 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Teach Enforcer.enforce to deal with context objects https://review.openstack.org/578995 | 17:31 |
*** felipemonteiro has joined #openstack-keystone | 17:34 | |
*** felipemonteiro has quit IRC | 17:38 | |
*** felipemonteiro has joined #openstack-keystone | 17:39 | |
*** vishakha has joined #openstack-keystone | 17:40 | |
*** felipemonteiro has quit IRC | 17:45 | |
*** fiddletwix has joined #openstack-keystone | 17:45 | |
ayoung | what is the command to generate the policy.json or policy.yaml file now? | 17:45 |
*** felipemonteiro has joined #openstack-keystone | 17:47 | |
lbragstad | tox -e genpolicy | 17:49 |
lbragstad | or you can use the endpoints oslo.policy exposese | 17:50 |
ayoung | lbragstad, TYVM | 17:50 |
lbragstad | exposes* | 17:50 |
lbragstad | oslopolicy-* | 17:50 |
ayoung | ERROR: tox version is 1.4.2, required is at least 2.3.1 | 17:51 |
ayoung | and that is what I get for running RHEL 7 | 17:51 |
ayoung | I think I might end up following dolphm's old pattern of having a venv with all the tooling | 17:51 |
lbragstad | oslopolicy-policy-generator shouldn't require tox | 17:52 |
lbragstad | just pass it the keystone namespace | 17:52 |
ayoung | Heh | 17:52 |
ayoung | chicken and egg time | 17:52 |
ayoung | I don't even have the openstack CLI installed on this machine yet | 17:53 |
lbragstad | ah - | 17:53 |
ayoung | trying to avoid installing tools into the global namespace | 17:53 |
lbragstad | yeah, oslo.policy needs to be installed with keystone | 17:53 |
ayoung | I can see why people depend on containers for development | 17:53 |
*** peereb has quit IRC | 18:07 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Refactor _handle_shadow_and_local_users https://review.openstack.org/579657 | 18:09 |
*** raildo has quit IRC | 18:24 | |
*** raildo has joined #openstack-keystone | 18:26 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Refactor _handle_shadow_and_local_users https://review.openstack.org/579657 | 18:28 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Add docs for case-insensitivity in keystone https://review.openstack.org/576640 | 18:34 |
*** pcichy has quit IRC | 18:38 | |
*** AlexeyAbashkin has joined #openstack-keystone | 18:57 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Refactor _handle_shadow_and_local_users https://review.openstack.org/579657 | 18:59 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Add note for usage of util function https://review.openstack.org/579594 | 19:00 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Refactor _set_domain_id_and_mapping functions https://review.openstack.org/579670 | 19:07 |
*** pcichy has joined #openstack-keystone | 19:11 | |
*** AlexeyAbashkin has quit IRC | 19:17 | |
*** felipemonteiro has quit IRC | 19:26 | |
*** felipemonteiro has joined #openstack-keystone | 19:31 | |
*** d0ugal has quit IRC | 19:34 | |
* kmalloc glares at the ick we've implemented in the controller base. | 20:06 | |
*** aojea has joined #openstack-keystone | 20:10 | |
*** raildo has quit IRC | 20:18 | |
*** blake has joined #openstack-keystone | 20:26 | |
openstackgerrit | Lance Bragstad proposed openstack/oslo.limit master: Convert tox.ini to using stestr https://review.openstack.org/579685 | 20:55 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.limit master: Implement ProjectClaim objects https://review.openstack.org/579686 | 20:55 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.limit master: Implement basic Enforcer context manager https://review.openstack.org/579687 | 20:55 |
*** felipemonteiro has quit IRC | 21:01 | |
openstackgerrit | Lance Bragstad proposed openstack/oslo.limit master: Add .zuul.yaml https://review.openstack.org/579688 | 21:07 |
*** felipemonteiro has joined #openstack-keystone | 21:18 | |
*** nicolasbock has quit IRC | 21:24 | |
*** dklyle has quit IRC | 21:24 | |
*** dklyle has joined #openstack-keystone | 21:25 | |
*** vishakha has quit IRC | 21:33 | |
*** tonytan4ever has joined #openstack-keystone | 21:34 | |
*** martinus__ has quit IRC | 21:35 | |
*** vishakha has joined #openstack-keystone | 21:46 | |
*** felipemonteiro has quit IRC | 22:03 | |
*** tonytan4ever has quit IRC | 22:03 | |
*** tonytan4ever_brb has joined #openstack-keystone | 22:03 | |
*** rcernin has joined #openstack-keystone | 22:18 | |
*** felipemonteiro has joined #openstack-keystone | 22:20 | |
*** felipemonteiro has quit IRC | 22:23 | |
*** dtruong_ has quit IRC | 22:27 | |
*** dtruong has joined #openstack-keystone | 22:28 | |
adriant | cmurphy: what I mean by options: https://github.com/openstack/keystone/commit/ab9237f2c378eb2cf51b492ca9528327fa48b0b6 | 22:47 |
adriant | was unclear that I meant user options | 22:47 |
*** aojea has quit IRC | 22:50 | |
adriant | I couldn't easily find any docs on the MFA user options, yet along user options in general outside of the code itself | 22:50 |
adriant | alone*, but I didn't look tooo hard for them | 22:51 |
adriant | Ok, so the API ref doesn't mention user options, but the sections in the docs that relate to those option for PCI do mention them: https://github.com/openstack/keystone/blob/master/doc/source/admin/identity-security-compliance.rst | 23:01 |
adriant | Just no docs for the MFA related user options, but we can remedy that with a follow up that adds docs for auth receipts and MFA user options at the same time | 23:03 |
*** edmondsw has quit IRC | 23:05 | |
*** edmondsw has joined #openstack-keystone | 23:06 | |
*** edmondsw has quit IRC | 23:11 | |
*** threestrands has joined #openstack-keystone | 23:43 | |
*** gyee has quit IRC | 23:45 | |
openstackgerrit | Merged openstack/keystone master: Added check to avoid keyerror "user['name']" https://review.openstack.org/576433 | 23:48 |
openstackgerrit | Merged openstack/keystone master: Remove token bind capabilities https://review.openstack.org/577524 | 23:48 |
*** mylu has joined #openstack-keystone | 23:51 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!