*** felipemonteiro has joined #openstack-keystone | 00:09 | |
*** gyee has quit IRC | 00:13 | |
*** Nel1x has joined #openstack-keystone | 00:45 | |
*** felipemonteiro has quit IRC | 00:46 | |
*** imacdonn has quit IRC | 00:49 | |
*** imacdonn has joined #openstack-keystone | 00:50 | |
*** markvoelker has joined #openstack-keystone | 01:06 | |
*** harlowja has quit IRC | 01:06 | |
*** markvoelker has quit IRC | 01:40 | |
*** deepak_mourya__ has joined #openstack-keystone | 02:21 | |
*** wlmbasson_ has joined #openstack-keystone | 02:22 | |
*** vishakha_ has joined #openstack-keystone | 02:22 | |
*** BlackDex_ has joined #openstack-keystone | 02:26 | |
*** dave-mccowan has quit IRC | 02:27 | |
*** dansmith has joined #openstack-keystone | 02:28 | |
*** BlackDex has quit IRC | 02:29 | |
*** wlmbasson has quit IRC | 02:29 | |
*** viks_ has quit IRC | 02:29 | |
*** toddnni has quit IRC | 02:29 | |
*** vishakha has quit IRC | 02:29 | |
*** deepak_mourya_ has quit IRC | 02:29 | |
*** htimsnad has quit IRC | 02:29 | |
*** deepak_mourya__ is now known as deepak_mourya_ | 02:29 | |
*** vishakha_ is now known as vishakha | 02:29 | |
*** wlmbasson_ is now known as wlmbasson | 02:29 | |
*** toddnni has joined #openstack-keystone | 02:30 | |
*** felipemonteiro has joined #openstack-keystone | 02:35 | |
*** markvoelker has joined #openstack-keystone | 02:37 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: ADD a test for idp and federated user cascade deleting https://review.openstack.org/591946 | 02:41 |
---|---|---|
*** Nel1x has quit IRC | 02:53 | |
*** markvoelker has quit IRC | 03:11 | |
*** nicolasbock has quit IRC | 03:44 | |
*** felipemonteiro has quit IRC | 03:45 | |
openstackgerrit | Merged openstack/oslo.limit master: add lib-forward-testing-python3 test job https://review.openstack.org/591185 | 03:48 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Enable foreign keys for unit test https://review.openstack.org/558193 | 03:52 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: ADD a test for idp and federated user cascade deleting https://review.openstack.org/591946 | 03:52 |
*** markvoelker has joined #openstack-keystone | 04:08 | |
*** felipemonteiro has joined #openstack-keystone | 04:14 | |
*** viks_ has joined #openstack-keystone | 04:35 | |
*** markvoelker has quit IRC | 04:41 | |
*** shyamb has joined #openstack-keystone | 05:14 | |
*** felipemonteiro has quit IRC | 05:17 | |
*** dmellado has joined #openstack-keystone | 05:27 | |
*** markvoelker has joined #openstack-keystone | 05:38 | |
openstackgerrit | Deepak Mourya proposed openstack/keystone master: Added support for a ``description`` attribute for Identity Roles https://review.openstack.org/484348 | 05:39 |
deepak_mourya_ | wxy-xiyuan: I have rebased the patch, please review the same. https://review.openstack.org/#/c/484348/12 https://review.openstack.org/#/c/484355/ | 05:47 |
*** mbuil has joined #openstack-keystone | 06:03 | |
*** markvoelker has quit IRC | 06:12 | |
*** shyamb has quit IRC | 06:13 | |
*** shyamb has joined #openstack-keystone | 06:14 | |
wxy-xiyuan | deepak_mourya_: the migration script version need to be bumped. | 06:28 |
*** pcaruana has joined #openstack-keystone | 06:33 | |
deepak_mourya_ | wxy-xiyuan: ok, can you please point it out the same on the above specified patch also, so that it will be easy to update. | 06:37 |
wxy-xiyuan | deepak_mourya_: sure | 06:37 |
deepak_mourya_ | wxy-xiyuan: Thank you. :) | 06:38 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Enable foreign keys for unit test https://review.openstack.org/558193 | 06:47 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: ADD a test for idp and federated user cascade deleting https://review.openstack.org/591946 | 06:47 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Change unique_last_password_count default to 0 https://review.openstack.org/593476 | 06:48 |
wxy-xiyuan | lbragstad: we lost db migration placeholder for Rocky. Is it the time to add them now and backport them to stable-R? | 06:50 |
mbuil | cmurphy: I am ready with the logs. If you had some time to help, it would be great if you could help me understand what is failing | 06:58 |
*** shyamb has quit IRC | 06:59 | |
*** rcernin has quit IRC | 06:59 | |
*** shyamb has joined #openstack-keystone | 07:04 | |
*** markvoelker has joined #openstack-keystone | 07:09 | |
*** hoonetorg has quit IRC | 07:17 | |
*** shyamb has quit IRC | 07:22 | |
*** shyamb has joined #openstack-keystone | 07:22 | |
*** hoonetorg has joined #openstack-keystone | 07:29 | |
cmurphy | mbuil: okay I'm here | 07:35 |
*** markvoelker has quit IRC | 07:42 | |
*** shyamb has quit IRC | 07:43 | |
mbuil | cmurphy: good morning! I logged with user "demo" to Horizon. I created that user in the IdP side. When switching to 'mysp' these are the logs that I get in the /var/log/keystone.log from IdP: https://hastebin.com/dexubuqiti.cs. Note the "Invalid user token" message | 07:44 |
mbuil | cmurphy: I guess that message is the response from "POST http://172.29.236.11:5000/v3/auth/OS-FEDERATION/saml2/ecp", right? | 07:45 |
cmurphy | looks like it | 07:47 |
*** hoonetorg has quit IRC | 07:48 | |
cmurphy | mbuil: is 172.29.236.11 the SP? | 07:48 |
mbuil | cmurphy: not exactly, should it be? | 07:49 |
cmurphy | no I guess not | 07:53 |
mbuil | cmurphy: When I registered the SP into the IdP, I registered it using mysp.exmaple.com:5000 and that points to 10.10.100.29:5000. 172.29.236.11:500 points to the local keystone | 07:55 |
cmurphy | so in my env I get a 200 for POST http://192.168.122.196/identity/v3/auth/OS-FEDERATION/saml2/ecp and then that's the end of the story on the IdP, so something is wrong on the SP | 07:56 |
cmurphy | so any interesting logs on the SP? | 07:56 |
mbuil | cmurphy: however, note that both deployments use 172.29.236.11:5000 to point to their local keystone. I was afraid that perhaps it is trying to POST to the remote SP keystone and somehow it is using the local keystone IP from the SP. However, in theory, that is not possible and so it should use "POST http://mysp.examle.com:5000/v3/auth/OS-FEDERATION/saml2/ecp" | 07:58 |
mbuil | cmurphy: is 192.168.122.196 the ip pointing to the local keystone in IdP? | 07:59 |
cmurphy | mbuil: yes that's my IdP | 08:00 |
*** hoonetorg has joined #openstack-keystone | 08:01 | |
mbuil | cmurphy: in the SP I get this (note that I added myself some logs to get list the AUTH_METHODS): https://hastebin.com/alevinapev.py | 08:01 |
mbuil | and the assertion | 08:01 |
cmurphy | mbuil: if you turn on debug = true in keystone.conf it should log the assertion data on its own | 08:04 |
cmurphy | and should also give response codes | 08:05 |
cmurphy | mbuil: is 23c7f532cc0f4ee38db65439521027c4 a project on the SP or the IdP? | 08:09 |
*** jaosorior has quit IRC | 08:10 | |
mbuil | cmurphy:let me check | 08:18 |
mbuil | cmurphy it is a project on the SP | 08:20 |
mbuil | | 23c7f532cc0f4ee38db65439521027c4 | federated_project | | 08:20 |
mbuil | cmurphy: I am in a call until 11, so I might be a bit slow, sorry | 08:20 |
cmurphy | mbuil: okay, if you're able to get logs with debug=true and insecure_debug=true on the SP when you have a chance that would help, I can't really tell what's going on from these logs | 08:22 |
mbuil | cmurphy: I did it but it does not show much more ==> https://hastebin.com/luwitohura.py that is weird | 08:25 |
mbuil | right after restarting keystone service I can see DEBUG logs | 08:25 |
openstackgerrit | Deepak Mourya proposed openstack/keystone master: Added support for a ``description`` attribute for Identity Roles https://review.openstack.org/484348 | 08:26 |
deepak_mourya_ | @wxy-xiyuan I have updated the patch as per your reviews . https://review.openstack.org/#/c/484348/ | 08:28 |
*** obre has joined #openstack-keystone | 08:30 | |
*** shyamb has joined #openstack-keystone | 08:38 | |
*** markvoelker has joined #openstack-keystone | 08:39 | |
openstackgerrit | Deepak Mourya proposed openstack/keystone master: Added support for a ``description`` attribute for Identity Roles https://review.openstack.org/484348 | 08:44 |
wxy-xiyuan | deepak_mourya_: thanks for the update. left some comments there. And since I'm one of the co-author, I'll leave +2 to other reviewers. | 08:57 |
*** jaosorior has joined #openstack-keystone | 09:08 | |
*** markvoelker has quit IRC | 09:13 | |
*** shyamb has quit IRC | 09:20 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add placeholder migrations for Stein https://review.openstack.org/595556 | 09:22 |
deepak_mourya_ | wxy-xiyuan: ok no issue, thanks for the help | 09:26 |
*** shyamb has joined #openstack-keystone | 09:34 | |
*** jaosorior has quit IRC | 09:54 | |
*** markvoelker has joined #openstack-keystone | 10:10 | |
*** shyamb has quit IRC | 10:16 | |
*** chason has quit IRC | 10:39 | |
*** chason has joined #openstack-keystone | 10:41 | |
*** markvoelker has quit IRC | 10:43 | |
*** dave-mccowan has joined #openstack-keystone | 10:46 | |
*** raildo has joined #openstack-keystone | 11:02 | |
*** raildo_ has joined #openstack-keystone | 11:15 | |
*** raildo has quit IRC | 11:15 | |
*** nicolasbock has joined #openstack-keystone | 11:22 | |
*** shyamb has joined #openstack-keystone | 11:29 | |
*** markvoelker has joined #openstack-keystone | 11:40 | |
lbragstad | wxy-xiyuan: oh - good call, yeah we should be able to do that and release an rc2 | 11:48 |
*** shyamb has quit IRC | 11:52 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add placeholder migrations for Rocky https://review.openstack.org/595556 | 11:53 |
cmurphy | lbragstad: ^ | 11:53 |
*** jaosorior has joined #openstack-keystone | 11:54 | |
*** shyamb has joined #openstack-keystone | 11:55 | |
lbragstad | cmurphy: oh - nice | 12:00 |
lbragstad | i literally just wrote my commit message | 12:00 |
cmurphy | heh sorry | 12:00 |
lbragstad | no worries at all, thanks! | 12:00 |
lbragstad | we don't really do a standard number of placeholders do we? | 12:01 |
cmurphy | heh | 12:01 |
lbragstad | 4 should be good, right? | 12:02 |
cmurphy | i think so, we didn't use any of them last time | 12:02 |
lbragstad | true, we also didn't do many migrations in Rocky | 12:02 |
lbragstad | backport https://review.openstack.org/595619 | 12:04 |
lbragstad | any other core willing to kick https://review.openstack.org/#/q/4d3cdd5d21597f796432363155dad81463f70fca through? | 12:08 |
knikolla | o/ | 12:09 |
lbragstad | we should kick https://review.openstack.org/#/c/590404/1 through too | 12:10 |
*** markvoelker has quit IRC | 12:14 | |
*** pcaruana has quit IRC | 12:16 | |
*** pcaruana has joined #openstack-keystone | 12:16 | |
*** raildo_ is now known as raildo | 12:16 | |
*** dims_ is now known as dims | 12:37 | |
*** shyamb has quit IRC | 12:46 | |
*** jaosorior has quit IRC | 13:09 | |
*** BlackDex_ is now known as BlackDex | 13:26 | |
*** marvin_mhg has joined #openstack-keystone | 13:30 | |
*** raildo has quit IRC | 13:35 | |
*** felipemonteiro has joined #openstack-keystone | 13:35 | |
*** raildo has joined #openstack-keystone | 13:36 | |
*** breton has left #openstack-keystone | 13:44 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Make policy file support in fixture optional https://review.openstack.org/595279 | 13:44 |
*** breton has joined #openstack-keystone | 13:44 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Move loadapp to a generic place https://review.openstack.org/595371 | 13:44 |
*** felipemonteiro has quit IRC | 13:46 | |
*** viks_ has quit IRC | 13:49 | |
*** r-daneel has joined #openstack-keystone | 14:07 | |
*** raildo_ has joined #openstack-keystone | 14:11 | |
*** raildo has quit IRC | 14:12 | |
*** r-daneel has quit IRC | 14:37 | |
openstackgerrit | Merged openstack/keystone master: Add placeholder migrations for Rocky https://review.openstack.org/595556 | 15:02 |
*** itlinux__ has joined #openstack-keystone | 15:06 | |
*** itlinux__ is now known as itlinux | 15:15 | |
*** itlinux is now known as 59NAABP8D | 15:15 | |
*** 59NAABP8D has quit IRC | 15:17 | |
*** itlinux has joined #openstack-keystone | 15:18 | |
*** dklyle has quit IRC | 15:20 | |
*** pcaruana has quit IRC | 15:36 | |
*** dklyle has joined #openstack-keystone | 15:37 | |
*** raildo has joined #openstack-keystone | 15:50 | |
*** raildo_ has quit IRC | 15:51 | |
lbragstad | kmalloc: can you kick https://review.openstack.org/#/c/595619/ though as soon as you have a minute? | 15:51 |
lbragstad | dependent for rc ^ | 15:51 |
gagehugo | o/ | 15:57 |
*** itlinux is now known as itlinux-away | 15:58 | |
*** gyee has joined #openstack-keystone | 15:59 | |
*** itlinux-away is now known as itlinux | 16:00 | |
*** itlinux is now known as itlinux-away | 16:00 | |
*** itlinux-away is now known as itlinux | 16:05 | |
*** itlinux is now known as itlinux-away | 16:05 | |
*** itlinux-away is now known as itlinux | 16:06 | |
*** itlinux is now known as itlinux-away | 16:07 | |
*** itlinux-away is now known as itlinux | 16:13 | |
*** itlinux is now known as itlinux-away | 16:14 | |
*** harlowja has joined #openstack-keystone | 16:17 | |
*** itlinux-away is now known as itlinux | 16:18 | |
*** itlinux is now known as itlinux-away | 16:18 | |
*** itlinux-away is now known as itlinux | 16:21 | |
kmalloc | lbragstad: looking | 16:33 |
kmalloc | lbragstad: don't hesitate to comment on things like that and self approve imo | 16:34 |
kmalloc | lbragstad: it's critical / low risk / needed red tape bits. | 16:34 |
kmalloc | lbragstad: i would 100% support self-approval of those things. | 16:34 |
*** harlowja has quit IRC | 16:40 | |
kmalloc | cmurphy: is it ok if I fix the "attribute != id" bit in a patch along side of the current big chain | 17:09 |
kmalloc | cmurphy: i'm really trying to avoid massive test refactoring in a webob->flask change, just a high risk of introducing errors, and the changes are already complex enough | 17:09 |
kmalloc | lbragstad: https://review.openstack.org/#/c/591203/3 i'll get a test written in a separate patch soon | 17:09 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Re-Add scope.system to filters https://review.openstack.org/595837 | 17:11 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Re-Add scope.system to filters https://review.openstack.org/595837 | 17:12 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Re-Add scope.system to filters https://review.openstack.org/595837 | 17:13 |
kmalloc | lbragstad: ^ for role_assignments API | 17:13 |
kmalloc | lbragstad: https://review.openstack.org/#/c/589950/6 needs a followup, but can land as is. | 17:16 |
kmalloc | lbragstad: i need your brain for https://review.openstack.org/#/c/591147/9 | 17:16 |
kmalloc | lbragstad: and how we're moving forward on it | 17:17 |
lbragstad | oh - sweet | 17:24 |
lbragstad | i can take a look | 17:24 |
lbragstad | i have a patch i need opinions on, too | 17:24 |
*** jrist has quit IRC | 17:26 | |
kmalloc | lbragstad: fire away on the patch I need to look at. | 17:31 |
kmalloc | cmurphy: also, auth is not really straight forward to conver to flask. I tried it first and ran into so many pits i opted to run backwards for everything else (easier) and the attack auth specifically once the rest of the APIs are on flask. | 17:32 |
kmalloc | cmurphy: auth is... icky, especially with the way the auth plugins work and data is passed through them. | 17:32 |
kmalloc | cmurphy: i was 15 patches deep and ~2000+lines of change before i stopped and figured moving everything else was more straightforward. | 17:33 |
kmalloc | :P | 17:33 |
kmalloc | it's also because we have some weird inter-dependencies on auth. | 17:33 |
*** jrist has joined #openstack-keystone | 17:41 | |
cmurphy | kmalloc: okay that's fair | 17:48 |
kmalloc | cmurphy: if you're ok with a followup to fix the id vs name, i'll happily do it, just tying to keep massive test refactors and code changes out of a flask conversion patch (I can make the change either before or after, but after is a bit easier) | 17:50 |
cmurphy | kmalloc: you're talking about https://review.openstack.org/#/c/591082/13/keystone/server/flask/common.py right? | 17:50 |
kmalloc | yep | 17:51 |
kmalloc | and my response there. | 17:51 |
cmurphy | that's fine and it's not really that important at all, it's just kind of gnarly looking | 17:51 |
kmalloc | yeah =/ | 17:51 |
kmalloc | i'll do some cleanup passes once I get the current stack into shape. there is some stuff at the latter end that need massaging | 17:51 |
kmalloc | i think i can get all that ugliness cleaned up in a patch or two. then on to domains and *shudder* projects and users. | 17:52 |
kmalloc | then ... auth | 17:52 |
*** N3l1x has joined #openstack-keystone | 18:03 | |
*** r-daneel has joined #openstack-keystone | 18:24 | |
*** r-daneel_ has joined #openstack-keystone | 18:38 | |
*** r-daneel has quit IRC | 18:40 | |
*** r-daneel_ is now known as r-daneel | 18:40 | |
*** pcaruana has joined #openstack-keystone | 18:52 | |
*** pcaruana has quit IRC | 19:09 | |
*** jrist has quit IRC | 19:10 | |
*** jrist has joined #openstack-keystone | 19:23 | |
lbragstad | i don't think system scoped tokens are getting the roles expanded like project scoped tokens are | 19:43 |
lbragstad | yup - https://bugs.launchpad.net/keystone/+bug/1788694 | 20:09 |
openstack | Launchpad bug 1788694 in OpenStack Identity (keystone) "System scoped tokens don't expand role assignments" [Undecided,New] | 20:09 |
gagehugo | oh implied roles | 20:16 |
*** raildo has quit IRC | 20:23 | |
*** david-lyle has joined #openstack-keystone | 21:15 | |
*** dklyle has quit IRC | 21:17 | |
*** rcernin has joined #openstack-keystone | 21:46 | |
*** r-daneel_ has joined #openstack-keystone | 22:08 | |
*** r-daneel has quit IRC | 22:10 | |
*** r-daneel_ is now known as r-daneel | 22:10 | |
*** N3l1x has quit IRC | 22:35 | |
*** threestrands has joined #openstack-keystone | 22:53 | |
kmalloc | gross | 23:16 |
kmalloc | :( | 23:16 |
*** felipemonteiro has joined #openstack-keystone | 23:48 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!