lbragstad | interesting... | 00:03 |
---|---|---|
lbragstad | i think only a trust id would be required | 00:04 |
*** lbragstad has quit IRC | 01:07 | |
*** takamatsu has quit IRC | 01:37 | |
*** Dinesh_Bhor has joined #openstack-keystone | 01:40 | |
openstackgerrit | zhongshengping proposed openstack/oslo.limit master: Change openstack-dev to openstack-discuss https://review.openstack.org/621795 | 01:47 |
openstackgerrit | zhongshengping proposed openstack/oslo.policy master: Change openstack-dev to openstack-discuss https://review.openstack.org/621812 | 01:47 |
*** Dinesh_Bhor has quit IRC | 01:56 | |
openstackgerrit | zhongshengping proposed openstack/keystone master: Change openstack-dev to openstack-discuss https://review.openstack.org/621824 | 02:00 |
*** gyee has quit IRC | 02:14 | |
*** itlinux has joined #openstack-keystone | 02:23 | |
*** itlinux has quit IRC | 02:33 | |
*** itlinux has joined #openstack-keystone | 02:34 | |
*** Dinesh_Bhor has joined #openstack-keystone | 02:36 | |
*** itlinux has quit IRC | 02:36 | |
eandersson | btw pretty sure we were hitting this https://github.com/openstack/keystone/blob/master/keystone/models/token_model.py#L535 | 02:48 |
eandersson | I do feel like this should be logged as a warning or something, because difficult to know as an admin if this is a widespread issue | 02:48 |
eandersson | and no obvious way to fix it besides rotating out all the trusts | 02:48 |
*** imacdonn has quit IRC | 02:52 | |
*** imacdonn has joined #openstack-keystone | 02:52 | |
openstackgerrit | Brin Zhang proposed openstack/keystone-specs master: Change openstack-dev to openstack-discuss https://review.openstack.org/621893 | 02:59 |
*** jmlowe has joined #openstack-keystone | 03:22 | |
*** dklyle has joined #openstack-keystone | 03:23 | |
*** david-lyle has quit IRC | 03:25 | |
*** dave-mccowan has quit IRC | 03:53 | |
*** itlinux has joined #openstack-keystone | 04:14 | |
*** Nel1x has quit IRC | 04:15 | |
*** Dinesh_Bhor has quit IRC | 05:50 | |
*** Dinesh_Bhor has joined #openstack-keystone | 05:54 | |
*** aojea has joined #openstack-keystone | 06:50 | |
*** takamatsu has joined #openstack-keystone | 06:53 | |
*** aojea has quit IRC | 07:04 | |
*** pcaruana has joined #openstack-keystone | 07:10 | |
*** rcernin has quit IRC | 07:38 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Fix URL resulting 404 for v2 API https://review.openstack.org/622078 | 07:55 |
*** jdennis has quit IRC | 08:05 | |
*** awalende has joined #openstack-keystone | 08:07 | |
*** takamatsu has quit IRC | 08:15 | |
*** trident has quit IRC | 08:31 | |
*** trident has joined #openstack-keystone | 08:32 | |
*** erus has quit IRC | 08:38 | |
*** amoralej|off is now known as amoralej | 08:39 | |
*** erus has joined #openstack-keystone | 08:40 | |
*** hoonetorg has quit IRC | 08:45 | |
*** takamatsu has joined #openstack-keystone | 08:46 | |
*** hoonetorg has joined #openstack-keystone | 08:58 | |
*** takamatsu has quit IRC | 09:14 | |
*** takamatsu has joined #openstack-keystone | 09:16 | |
*** lbragstad has joined #openstack-keystone | 09:24 | |
*** ChanServ sets mode: +o lbragstad | 09:24 | |
*** takamatsu has quit IRC | 09:49 | |
*** takamatsu has joined #openstack-keystone | 09:50 | |
*** takamatsu has quit IRC | 10:13 | |
*** takamatsu has joined #openstack-keystone | 10:50 | |
*** Dinesh_Bhor has quit IRC | 10:52 | |
*** Dinesh_Bhor has joined #openstack-keystone | 10:53 | |
*** Dinesh_Bhor has quit IRC | 11:00 | |
*** takamatsu has quit IRC | 11:04 | |
*** takamatsu has joined #openstack-keystone | 11:05 | |
*** dave-mccowan has joined #openstack-keystone | 12:11 | |
*** lbragstad has quit IRC | 12:21 | |
openstackgerrit | melissaml proposed openstack/pycadf master: Change openstack-dev to openstack-discuss https://review.openstack.org/622286 | 12:22 |
*** lbragstad has joined #openstack-keystone | 12:23 | |
*** ChanServ sets mode: +o lbragstad | 12:23 | |
*** lbragstad has quit IRC | 12:23 | |
*** lbragstad has joined #openstack-keystone | 12:24 | |
*** ChanServ sets mode: +o lbragstad | 12:24 | |
*** lbragsta_ has joined #openstack-keystone | 12:26 | |
*** ChanServ sets mode: +o lbragsta_ | 12:26 | |
*** shrasool has joined #openstack-keystone | 12:29 | |
*** lbragsta_ has quit IRC | 12:31 | |
*** lbragstad has quit IRC | 12:31 | |
*** lbragstad has joined #openstack-keystone | 12:38 | |
*** ChanServ sets mode: +o lbragstad | 12:38 | |
*** amoralej is now known as amoralej|lunch | 12:42 | |
*** shrasool has quit IRC | 12:47 | |
*** shrasool has joined #openstack-keystone | 12:52 | |
knikolla | o/ | 13:07 |
lbragstad | good UGT | 13:08 |
cmurphy | \o | 13:15 |
knikolla | we do store group ids in the token, right? | 13:22 |
knikolla | https://github.com/openstack/keystone/blob/master/keystone/token/token_formatters.py#L148 | 13:23 |
*** aojea_ has joined #openstack-keystone | 13:28 | |
*** shrasool has quit IRC | 13:31 | |
lbragstad | knikolla for federated tokens, yes | 13:36 |
knikolla | lbragstad: yup, thanks. | 13:37 |
knikolla | i woke up early to make sure i finish polishing up the app creds spec before the meeting | 13:37 |
knikolla | so i don't fully trust my bran yet | 13:37 |
knikolla | haha | 13:37 |
knikolla | brain* | 13:38 |
lbragstad | nice | 13:38 |
*** jaosorior has joined #openstack-keystone | 13:45 | |
*** aojea_ has quit IRC | 13:47 | |
*** amoralej|lunch is now known as amoralej | 14:03 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystone-specs master: Renewable Application Credentials https://review.openstack.org/604201 | 14:04 |
knikolla | lbragstad: didn't see your feedback on a prior review, will incorporate it in a later patchset. | 14:05 |
lbragstad | sounds good | 14:06 |
*** raildo_ has joined #openstack-keystone | 14:11 | |
*** raildo_ has quit IRC | 14:13 | |
*** raildo has joined #openstack-keystone | 14:13 | |
*** aojea_ has joined #openstack-keystone | 14:15 | |
*** irclogbot_1 has quit IRC | 14:15 | |
*** trident has quit IRC | 14:18 | |
*** trident has joined #openstack-keystone | 14:21 | |
larsks | Why does the 'password' table in the keystone database permit multiple password entries for a given user? | 14:24 |
cmurphy | larsks: if you use [security_complaicne/unique_last_password_count for pci-dss compliance keystone needs to keep the last N passwords in the db, it doesn't mean users are allowed to use them | 14:28 |
larsks | cmurphy: okay, I thought it might be some sort of history mechanism. Thanks. | 14:28 |
*** wxy| has joined #openstack-keystone | 14:30 | |
*** aojea_ has quit IRC | 14:33 | |
*** imus has joined #openstack-keystone | 14:34 | |
cmurphy | hi imus o/ | 14:34 |
imus | hi | 14:36 |
*** aojea_ has joined #openstack-keystone | 14:40 | |
*** xek has quit IRC | 14:45 | |
*** irclogbot_1 has joined #openstack-keystone | 14:54 | |
*** jdennis has joined #openstack-keystone | 14:54 | |
*** awalende has quit IRC | 14:58 | |
*** itlinux has quit IRC | 15:18 | |
*** jmlowe has quit IRC | 15:26 | |
*** xek has joined #openstack-keystone | 15:30 | |
*** imus has quit IRC | 15:45 | |
*** imus has joined #openstack-keystone | 15:46 | |
*** jmlowe has joined #openstack-keystone | 15:50 | |
*** shrasool has joined #openstack-keystone | 15:50 | |
kmalloc | o/ | 15:54 |
kmalloc | lbragstad: i have the start of an arch diagram, but realistically due to more car insurance issues i haven't had it completed | 15:54 |
kmalloc | lbragstad: it's about 1/3 of the way done (and it needs a lot of love) | 15:55 |
kmalloc | the next bits are the DB / internal architecture | 15:55 |
kmalloc | it also needs to be split into a couple use cases. it was late when i was doing it :P | 15:56 |
kmalloc | i'll keep iterating but here we go | 15:56 |
*** jmlowe has quit IRC | 15:57 | |
erus | Hi o/ | 15:57 |
cmurphy | hi erus | 15:57 |
*** jmlowe has joined #openstack-keystone | 15:57 | |
kmalloc | lbragstad: | 15:57 |
erus | Hello cmurphy how are you? | 15:57 |
kmalloc | first-pass https://usercontent.irccloud-cdn.com/file/6uy9UKfb/Keystone%20IDP%20(initial)%20Diagram.svg | 15:57 |
cmurphy | I'm good, how are you erus ? | 15:57 |
kmalloc | hrm not as intended meant to use the png | 15:58 |
kmalloc | First pass https://usercontent.irccloud-cdn.com/file/Au4e3DXb/Keystone%20IDP%20(initial)%20Diagram.png | 15:58 |
kmalloc | there we go | 15:58 |
erus | I'm really fine cmurphy :) | 15:58 |
lbragstad | good deal | 15:58 |
kmalloc | ^ lbragstad | 15:58 |
lbragstad | cc ildikov ^ | 15:59 |
kmalloc | and that is really rough showing what we're aiming for | 15:59 |
lbragstad | i imagine once it gets smoothed out we can put it somewhere more official | 15:59 |
kmalloc | and general data flow | 15:59 |
kmalloc | yeah, and I plan to have a real DB architecture with the principal object soon as well as cover auto-provision information | 16:00 |
kmalloc | but i wanted *something* to reference for today | 16:00 |
ildikov | +1 | 16:00 |
* ildikov likes diagrams :) | 16:00 | |
kmalloc | ildikov: this diagram is not meant to be official. it's so rough it just gives us some framing | 16:01 |
kmalloc | ildikov: it will get better as I iterate on it | 16:01 |
lbragstad | reminder - the keystone meeting is starting in #openstack-meeting-alt | 16:01 |
kmalloc | yay draw.io being super easy to use. | 16:01 |
ildikov | kmalloc: in my experience starting to draw it is the hardest | 16:01 |
kmalloc | ildikov: i'm just happy i found a nice online tool that i can export to pdf/png etc and it saves as a super small .xml that i can re-upload | 16:02 |
ildikov | It's easier when people can see it and add comments, etc | 16:02 |
*** shrasool has quit IRC | 16:02 | |
*** wxy| has quit IRC | 16:02 | |
ildikov | I think I've heard about that one before, didn't use it too often though | 16:03 |
kmalloc | ildikov: my expectation is that in the nearish future we'll have a target diagram for data flow, a db diagram, and a UI "site-map" diagram | 16:03 |
ildikov | Sounds great!! | 16:03 |
*** wxy| has joined #openstack-keystone | 16:03 | |
ildikov | Will link those from the Edge wikis too | 16:04 |
kmalloc | ildikov: perfect, yeah just don't use that one :P | 16:04 |
kmalloc | yet* | 16:04 |
kmalloc | (the current one) | 16:04 |
ildikov | Nope, I'm a nice person and it's holiday season as well, I wouldn't do that to you :) | 16:05 |
kmalloc | ildikov: <3! You *are* a nice person. | 16:05 |
kmalloc | ;) | 16:05 |
*** xek has quit IRC | 16:12 | |
*** pcaruana has quit IRC | 16:12 | |
ildikov | :) | 16:12 |
*** itlinux has joined #openstack-keystone | 16:18 | |
*** shrasool has joined #openstack-keystone | 16:19 | |
nsmeds | I doubt anyone will ever be as foolish as me - but I thought I'd share another realization that has caused me a great deal of confusion (related to implementing v3cloudsample) | 16:19 |
nsmeds | a lot of the rules compare token's domain_id to target | 16:20 |
kmalloc | nsmeds: yes. | 16:20 |
nsmeds | thus | 16:20 |
nsmeds | THUS | 16:20 |
kmalloc | quite a few actually. | 16:20 |
nsmeds | i must provide the domain *ID* and not the domain name in the request XD | 16:20 |
kmalloc | yup. | 16:20 |
nsmeds | I had expected, since they have a one-too-one relationship | 16:20 |
nsmeds | that providing a domain name would succeed | 16:20 |
* kmalloc can talk at end with absurd things we do with policy enforcement things. | 16:21 | |
nsmeds | nope. | 16:21 |
nsmeds | holy hell I am happy now | 16:21 |
nsmeds | lol | 16:21 |
nsmeds | life finally makes sense | 16:21 |
nsmeds | tbh, that kind of makes it a PITA when working with CLI clients - domain names are fairly easy to remember - domain IDs require the extra step of looking up and copy/pasting for each request | 16:25 |
nsmeds | oh well :shrug: | 16:25 |
openstackgerrit | Merged openstack/ldappool master: Add release notes jobs https://review.openstack.org/615190 | 16:27 |
*** itlinux has quit IRC | 16:29 | |
kmalloc | nsmeds: we could probably add the domain name to the context... | 16:32 |
kmalloc | and/or make the policy less sucky | 16:32 |
*** xek has joined #openstack-keystone | 16:32 | |
*** itlinux has joined #openstack-keystone | 16:36 | |
lbragstad | yeah - that seems reasonable | 16:46 |
openstackgerrit | Merged openstack/ldappool master: Replacing the HTTP protocal with HTTPS in index.rst. https://review.openstack.org/617826 | 16:46 |
nsmeds | kmalloc: well, I get that the more things added to v3cloudsample the more difficult it becomes to read - and tbh I'd expect Keystone/olso.policy to make that conversion in the background - but yeah, having domain name in policy would prevent someone else from having this same issue | 16:47 |
nsmeds | <3 | 16:47 |
*** gyee has joined #openstack-keystone | 16:47 | |
openstackgerrit | Merged openstack/keystone master: Don't emit a notification for the root domain https://review.openstack.org/617846 | 16:57 |
* knikolla lunch... | 16:57 | |
openstackgerrit | Nate Johnston proposed openstack/keystone master: Remove neutron-grenade job https://review.openstack.org/622428 | 17:00 |
cmurphy | kmalloc: knikolla: not sure if you saw my email but erus was interested in doing a kick-off meeting for the internship, are you available to join that now? | 17:00 |
cmurphy | if not it can just be me and erus | 17:01 |
*** wxy| has quit IRC | 17:01 | |
*** shrasool has quit IRC | 17:02 | |
*** shrasool has joined #openstack-keystone | 17:03 | |
*** takamatsu has quit IRC | 17:06 | |
kmalloc | cmurphy: yeah | 17:08 |
kmalloc | i can | 17:08 |
cmurphy | erus: you still around? | 17:08 |
erus | Yup o/ | 17:09 |
cmurphy | i confirmed the openstack asterisk server still works or we could use kmalloc's bluejeans meeting | 17:09 |
kmalloc | lets use bluejeans | 17:09 |
kmalloc | i don't have SIP setup | 17:09 |
erus | Me neither | 17:09 |
cmurphy | wfm | 17:09 |
kmalloc | https://bluejeans.com/4897923615869325 | 17:10 |
*** pcaruana has joined #openstack-keystone | 17:12 | |
cmurphy | erus: joining? ^ | 17:13 |
erus | o/ | 17:14 |
kmalloc | erus: and you can ignore the video part(s)/not enable it. we're just using it instead of asterisk or hangouts. | 17:14 |
kmalloc | erus: https://bluejeans.com/4897923615869325 | 17:14 |
erus | Ok ok | 17:15 |
erus | Sorry I'm downloading the app I have micro and camera disabled in my notebook | 17:16 |
*** xek has quit IRC | 17:16 | |
cmurphy | erus: we can do this another time if you want time to figure out your setup :) | 17:17 |
*** xek has joined #openstack-keystone | 17:17 | |
cmurphy | it should be doable in the browser though | 17:17 |
*** shrasool has quit IRC | 17:17 | |
kmalloc | knikolla: ^ | 17:19 |
kmalloc | knikolla: bluejeans | 17:19 |
*** aojea_ has quit IRC | 17:23 | |
kmalloc | cmurphy: the meeting didn't drop you, did it? | 17:29 |
kmalloc | cmurphy: it shouldn't have | 17:29 |
cmurphy | kmalloc: nope we're good | 17:29 |
kmalloc | cool! | 17:29 |
*** shrasool has joined #openstack-keystone | 17:32 | |
*** jmlowe has quit IRC | 17:38 | |
cmurphy | kmalloc: btw if you could check my email to imus and see if my plan of action makes sense or if you want to suggest a different approach | 17:44 |
kmalloc | cmurphy: looking | 17:45 |
* cmurphy afk for a while | 17:45 | |
kmalloc | i think the plan looks good | 17:45 |
*** amoralej is now known as amoralej|off | 17:54 | |
*** pcaruana has quit IRC | 17:56 | |
erus | Thanks kmalloc and cmurphy :) | 17:57 |
*** xek has quit IRC | 18:06 | |
*** xek has joined #openstack-keystone | 18:06 | |
openstackgerrit | Merged openstack/oslo.policy master: Make upgrades more robust with policy overrides https://review.openstack.org/614195 | 18:11 |
* knikolla back from lunch | 18:13 | |
knikolla | sorry for missing the meeting. | 18:13 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Update role policies for system reader https://review.openstack.org/622524 | 18:25 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add role tests for system member role https://review.openstack.org/622525 | 18:25 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Update role policies for system admin https://review.openstack.org/622526 | 18:25 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add tests for domain users interacting with roles https://review.openstack.org/622527 | 18:25 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add tests for project users interacting with roles https://review.openstack.org/622528 | 18:25 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove role policies from policy.v3cloudsample.json https://review.openstack.org/622529 | 18:25 |
*** shrasool has quit IRC | 18:26 | |
hrybacki | lbragstad: so, feedback from simo was to make the encryption algorithm configurable | 18:26 |
lbragstad | ahh - so supporting more than one algorithm... | 18:26 |
hrybacki | that was if something goes wrong, the operator can adjust w/o waiting on us to add functionality (CVE) | 18:26 |
hrybacki | lbragstad: aye | 18:26 |
lbragstad | what if they switch to fernet? | 18:27 |
*** shrasool has joined #openstack-keystone | 18:27 | |
lbragstad | it theoretically provides crypto-agility, but just using a different provider | 18:27 |
hrybacki | that's an option -- unless they have a requirement for JWT (thinking like, two years down the road when someone has been using it and maybe built up tooling around it) | 18:27 |
lbragstad | eyah | 18:27 |
hrybacki | lbragstad: I can type us as much in the review if that's best for you | 18:29 |
lbragstad | i could probably add a follow on patch to the spec that explicitly clarifies the crypt-agility concern | 18:29 |
* hrybacki nods | 18:30 | |
hrybacki | that would be reasonable | 18:30 |
*** jrist has quit IRC | 18:32 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Add a note about crypto-agility with JWT https://review.openstack.org/622543 | 18:37 |
lbragstad | hrybacki done ^ | 18:37 |
hrybacki | I'll pass it along lbragstad -- thanks! | 18:40 |
lbragstad | no problem - thank you | 18:40 |
kmalloc | nice. | 18:43 |
lbragstad | hrybacki i have a pile of default roles patches for you whenever you're interested ;) | 18:44 |
lbragstad | just FYI | 18:44 |
*** erus has quit IRC | 18:49 | |
hrybacki | lbragstad: I've got some PTO starting the week after next ;) I'll start digging into them then | 18:50 |
openstackgerrit | Merged openstack/keystone master: Change openstack-dev to openstack-discuss https://review.openstack.org/621824 | 18:50 |
*** jmlowe has joined #openstack-keystone | 18:50 | |
lbragstad | hrybacki naw - not that big of a deal | 18:51 |
lbragstad | use your PTO for PTO things | 18:51 |
lbragstad | default roles reviews are not PTO things | 18:51 |
knikolla | lbragstad: good work on the JWT spec! | 18:51 |
lbragstad | thanks :) | 18:51 |
*** erus has joined #openstack-keystone | 18:52 | |
hrybacki | lbragstad: it's tough to find work time to actually engineer these days (years) :| | 18:52 |
kmalloc | lbragstad: oh FYI I'm going to be on PTO shortly until sometime mid january | 18:52 |
lbragstad | kmalloc nice | 18:52 |
lbragstad | hrybacki yeah - never enough hours in the day it seems | 18:52 |
kmalloc | lbragstad: not sure when it starts, but def wont be back until like Jan 12 | 18:53 |
hrybacki | kmalloc: suck me up up into your office sometime so I can apprentice under you ;) | 18:53 |
kmalloc | erm 14 | 18:53 |
kmalloc | hrybacki: for "taking PTO"? :P | 18:53 |
hrybacki | kmalloc: no no, the other office | 18:53 |
kmalloc | the only reason i actually burn the PTO is so i actually take time off | 18:53 |
lbragstad | i imagine some folks will start trickling away for the holidays soon | 18:54 |
*** itlinux has quit IRC | 19:07 | |
* lbragstad goes to find food | 19:09 | |
*** itlinux has joined #openstack-keystone | 19:10 | |
gagehugo | I'll be around until xmas week | 19:16 |
openstackgerrit | Vieri proposed openstack/ldappool master: Change openstack-dev to openstack-discuss https://review.openstack.org/622571 | 19:20 |
*** itlinux has quit IRC | 19:23 | |
*** jmlowe has quit IRC | 19:23 | |
kmalloc | gagehugo: that is the original plan, but with having an extra 2 weeks (on top of what I'm already taking) to burn (and needing the down time) | 19:26 |
kmalloc | gagehugo: i might start my holiday a bit earlier. | 19:26 |
*** jrist has joined #openstack-keystone | 19:29 | |
gagehugo | nice | 19:36 |
gagehugo | I'd do that if I could :) | 19:36 |
* gagehugo unfortunately took too much vacation earlier this year | 19:36 | |
kmalloc | yeah i didn't :P | 19:52 |
kmalloc | i should take vacation more spread out tbh | 19:53 |
*** itlinux has joined #openstack-keystone | 19:53 | |
*** shrasool has quit IRC | 19:55 | |
lbragstad | psa: once https://review.openstack.org/#/c/611443/ gets a couple more reviews, pending feedback, I can propose a new oslo.policy release | 20:14 |
*** jmlowe has joined #openstack-keystone | 20:24 | |
*** xek has quit IRC | 20:31 | |
*** jmlowe has quit IRC | 20:33 | |
*** jrist has quit IRC | 20:39 | |
*** hoonetorg has quit IRC | 20:39 | |
*** aojea has joined #openstack-keystone | 20:39 | |
*** takamatsu has joined #openstack-keystone | 20:44 | |
*** shrasool has joined #openstack-keystone | 20:55 | |
*** hoonetorg has joined #openstack-keystone | 20:57 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: WIP: remove redundant policies from policy.v3cloudsample.json https://review.openstack.org/622589 | 20:57 |
lbragstad | nice - thanks gagehugo | 21:08 |
*** jmlowe has joined #openstack-keystone | 21:12 | |
*** jrist has joined #openstack-keystone | 21:31 | |
*** cosss_ has joined #openstack-keystone | 21:38 | |
*** shrasool has quit IRC | 21:38 | |
cosss_ | Hi! Is there a way to obtain the keystone api version (e.g. 3.11) with the keystoneclient? | 21:39 |
*** jdennis has quit IRC | 21:41 | |
*** aojea has quit IRC | 21:43 | |
*** jdennis has joined #openstack-keystone | 21:58 | |
*** jaosorior has quit IRC | 22:00 | |
*** shrasool has joined #openstack-keystone | 22:02 | |
*** raildo has quit IRC | 22:02 | |
*** timothyb89 has joined #openstack-keystone | 22:08 | |
*** aojea has joined #openstack-keystone | 22:17 | |
*** blake has joined #openstack-keystone | 22:27 | |
*** takamatsu has quit IRC | 22:29 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Update role policies for system reader https://review.openstack.org/622615 | 22:32 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Update system grant policies for system reader https://review.openstack.org/622615 | 22:32 |
*** dave-mccowan has quit IRC | 22:33 | |
*** rcernin has joined #openstack-keystone | 22:34 | |
openstackgerrit | Merged openstack/oslo.policy master: Add domain scope support for scope types https://review.openstack.org/611443 | 22:37 |
lbragstad | sweet! | 22:39 |
*** itlinux has quit IRC | 22:45 | |
*** rcernin_ has joined #openstack-keystone | 22:45 | |
*** rcernin has quit IRC | 22:45 | |
*** shrasool has quit IRC | 22:46 | |
*** jmlowe has quit IRC | 22:46 | |
*** jmlowe has joined #openstack-keystone | 22:48 | |
*** aojea has quit IRC | 22:50 | |
nsmeds | so - you guys have provided a great v3cloudpolicy example for Keystone. Am I correct in assuming nothing similar yet exists for Nova, Neutron, or Cinder? | 22:52 |
nsmeds | was planning to use your example to create similar policy rules for the other services if so. | 22:52 |
kmalloc | cosss_: it should be on the discovery page for keystone, but i am unsure if keystoneclient can do it | 23:02 |
kmalloc | cosss_: keystoneauth should be able to tell you... i think | 23:02 |
openstackgerrit | Merged openstack/oslo.policy master: Change openstack-dev to openstack-discuss https://review.openstack.org/621812 | 23:03 |
*** rcernin_ has quit IRC | 23:12 | |
*** etp has quit IRC | 23:12 | |
*** etp has joined #openstack-keystone | 23:13 | |
*** rcernin has joined #openstack-keystone | 23:13 | |
*** shrasool has joined #openstack-keystone | 23:29 | |
*** shrasool has quit IRC | 23:30 | |
*** aojea has joined #openstack-keystone | 23:42 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!