*** erus has quit IRC | 00:01 | |
*** erus has joined #openstack-keystone | 00:04 | |
*** itlinux has joined #openstack-keystone | 00:11 | |
*** itlinux has quit IRC | 00:11 | |
*** dklyle has joined #openstack-keystone | 00:53 | |
*** gyee has quit IRC | 01:08 | |
*** dave-mccowan has joined #openstack-keystone | 01:17 | |
*** erus has quit IRC | 01:44 | |
*** Dinesh_Bhor has joined #openstack-keystone | 01:59 | |
*** Dinesh_Bhor has quit IRC | 02:09 | |
*** Dinesh_Bhor has joined #openstack-keystone | 02:10 | |
*** dave-mccowan has quit IRC | 02:14 | |
*** itlinux has joined #openstack-keystone | 02:18 | |
*** mhen has quit IRC | 02:27 | |
*** mhen has joined #openstack-keystone | 02:28 | |
*** gagehugo has quit IRC | 02:55 | |
openstackgerrit | Merged openstack/keystone master: Bump oslo.policy and oslo.context versions https://review.openstack.org/623248 | 03:04 |
---|---|---|
openstackgerrit | Merged openstack/keystone master: Remove example usage from admin guide https://review.openstack.org/624637 | 03:19 |
openstackgerrit | Merged openstack/keystone master: Delete outdated keystonemiddleware doc https://review.openstack.org/624645 | 03:19 |
openstackgerrit | Merged openstack/keystone master: Move identity sources doc to admin guide https://review.openstack.org/624351 | 03:19 |
*** dklyle has quit IRC | 03:22 | |
*** imus has quit IRC | 03:28 | |
*** erus has joined #openstack-keystone | 03:43 | |
*** gagehugo has joined #openstack-keystone | 04:04 | |
*** itlinux has quit IRC | 04:11 | |
*** itlinux has joined #openstack-keystone | 04:43 | |
*** itlinux has quit IRC | 05:11 | |
*** gagehugo has quit IRC | 05:12 | |
*** rcernin has quit IRC | 07:09 | |
*** pcaruana has joined #openstack-keystone | 07:12 | |
*** dklyle has joined #openstack-keystone | 08:07 | |
*** imacdonn has quit IRC | 08:23 | |
*** imacdonn has joined #openstack-keystone | 08:24 | |
*** dklyle has quit IRC | 08:27 | |
*** Dinesh_Bhor has quit IRC | 08:31 | |
*** Dinesh_Bhor has joined #openstack-keystone | 08:32 | |
*** xek has joined #openstack-keystone | 08:32 | |
*** rledisez has joined #openstack-keystone | 08:41 | |
*** amoralej|off is now known as amoralej | 09:02 | |
openstackgerrit | Neha Alhat proposed openstack/python-keystoneclient master: Add return-request-id-to-caller function(v3/contrib) https://review.openstack.org/624898 | 09:09 |
*** trident has quit IRC | 09:16 | |
*** trident has joined #openstack-keystone | 09:19 | |
*** sayalilunkad has quit IRC | 09:31 | |
*** erus has quit IRC | 09:39 | |
*** erus has joined #openstack-keystone | 09:42 | |
*** markvoelker has joined #openstack-keystone | 09:46 | |
*** erus has quit IRC | 09:49 | |
*** erus has joined #openstack-keystone | 09:51 | |
*** erus has quit IRC | 09:57 | |
*** mpasserini1 has joined #openstack-keystone | 10:11 | |
*** erus has joined #openstack-keystone | 10:14 | |
*** trident has quit IRC | 10:15 | |
*** trident has joined #openstack-keystone | 10:15 | |
*** erus has quit IRC | 10:19 | |
*** erus has joined #openstack-keystone | 10:22 | |
*** mvkr has quit IRC | 10:24 | |
*** erus has quit IRC | 10:29 | |
*** sayalilunkad has joined #openstack-keystone | 10:35 | |
*** erus has joined #openstack-keystone | 10:36 | |
*** mvkr has joined #openstack-keystone | 10:56 | |
*** mvkr has quit IRC | 11:16 | |
*** mvkr has joined #openstack-keystone | 11:16 | |
*** tobias-urdin is now known as tobias-urdin_afk | 11:41 | |
*** tobias-urdin_afk is now known as tobias-urdin | 11:42 | |
*** tobias-urdin is now known as tobias-urdin_afk | 11:43 | |
*** amoralej is now known as amoralej|lunch | 12:03 | |
*** raildo has joined #openstack-keystone | 12:08 | |
*** Dinesh_Bhor has quit IRC | 12:14 | |
*** shrasool has joined #openstack-keystone | 12:14 | |
*** markvoelker has quit IRC | 12:24 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Consolidate service catalog docs https://review.openstack.org/624673 | 12:33 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Reorganize admin guide https://review.openstack.org/624972 | 12:33 |
*** tobias-urdin_afk is now known as tobias-urdin | 12:53 | |
*** markvoelker has joined #openstack-keystone | 13:10 | |
openstackgerrit | Ghanshyam Mann proposed openstack/keystone master: Add irrelevant-files for grenade-py3 jobs https://review.openstack.org/624988 | 13:14 |
*** amoralej|lunch is now known as amoralej | 13:27 | |
*** irclogbot_1 has quit IRC | 13:30 | |
*** irclogbot_1 has joined #openstack-keystone | 13:46 | |
*** yan0s has joined #openstack-keystone | 13:48 | |
yan0s | hi all, | 13:48 |
yan0s | can you tell me in which mysql table I can find the user-role relation> | 13:48 |
yan0s | ? | 13:48 |
yan0s | I guess local_user - role | 13:49 |
*** irclogbot_1 has quit IRC | 13:52 | |
*** stuartgr has joined #openstack-keystone | 13:56 | |
*** markvoelker has quit IRC | 14:03 | |
lbragstad | yan0s that's going to be in the assignment and system_assignment tables | 14:05 |
*** irclogbot_1 has joined #openstack-keystone | 14:09 | |
*** imus has joined #openstack-keystone | 14:10 | |
*** mchlumsky has joined #openstack-keystone | 14:22 | |
jrosser | could i get some advice about integration between ceph radosgw and keystone, specifically this https://github.com/openstack/keystonemiddleware/blob/master/keystonemiddleware/s3_token.py | 14:25 |
*** irclogbot_1 has quit IRC | 14:27 | |
jrosser | we are load testing radosgw and each s3 request results in a POST to the s3token keystone endpoint, which is causing enourmous load on the keystone api processes | 14:28 |
yan0s | so I have accidentally deleted the admin role | 14:32 |
yan0s | how can I use the cli client with the OS_TOKEN ? | 14:32 |
yan0s | openstack --os-token $OS_TOKEN --os-url http://10.0.0.28:5000/v3 role add --project admin --user admin admin | 14:33 |
yan0s | this seems not to be enough | 14:33 |
yan0s | I get The request you have made requires authentication. (HTTP 401) | 14:34 |
*** irclogbot_1 has joined #openstack-keystone | 14:35 | |
*** markvoelker has joined #openstack-keystone | 14:36 | |
ayoung | yan0s, needs to be enabled in the config file. Or rerun bootstrap | 14:37 |
ayoung | bootstrap is your best bet, I think; | 14:37 |
ayoung | https://docs.openstack.org/keystone/pike/admin/identity-bootstrap.html | 14:37 |
cmurphy | yes bootstrap will recover the admin role | 14:37 |
yan0s | I'm using juju so I'm not sure that's the best way | 14:42 |
yan0s | for me | 14:42 |
openstackgerrit | Colleen Murphy proposed openstack/keystone-specs master: Add spec for immutable roles https://review.openstack.org/624692 | 14:48 |
cmurphy | yan0s: does juju use the bootstrap command? rerunning it manually should be safe and idempotent | 14:50 |
*** Shilpa has joined #openstack-keystone | 14:59 | |
*** gagehugo has joined #openstack-keystone | 14:59 | |
*** ShilpaSD has quit IRC | 15:02 | |
gagehugo | o/ | 15:02 |
*** itlinux has joined #openstack-keystone | 15:07 | |
*** mpasserini1 has quit IRC | 15:25 | |
*** markvoelker has quit IRC | 15:38 | |
openstackgerrit | Moisés Guimarães de Medeiros proposed openstack/oslo.policy master: WIP: Use oslo.config instead of argparse. https://review.openstack.org/625038 | 16:00 |
*** yan0s has quit IRC | 16:04 | |
*** alexchadin has joined #openstack-keystone | 16:07 | |
*** morgan is now known as kmalloc | 16:09 | |
*** alexchadin has quit IRC | 16:10 | |
kmalloc | jrosser: that isn't surprising. radosgw (and most s3 requests in openstack) do not cache relevant responses. | 16:11 |
kmalloc | cmurphy: ++ on the immutable resource option | 16:11 |
kmalloc | cmurphy: spec. it's also why I added the resource-options-for-all spec :) | 16:11 |
jrosser | kmalloc: are those responses cacheable in theory? | 16:39 |
kmalloc | jrosser: the data / validation is cachable | 16:40 |
kmalloc | but the responses afaik are not | 16:40 |
kmalloc | because it's signed | 16:40 |
kmalloc | it's one of those tough things to deal with | 16:40 |
kmalloc | so you have to cache the key data directly rather than the response from keystone | 16:41 |
kmalloc | it's ... weird. | 16:41 |
kmalloc | jrosser: also ... i thought we punted that middleware over to the swift3 team. | 16:42 |
timburke | yes, and now it's back in upstream swift | 16:43 |
kmalloc | timburke: let me open a bug to officially deprecate that in ksm package then | 16:44 |
timburke | jrosser: as of https://review.openstack.org/#/c/603529/ it's even got caching | 16:44 |
kmalloc | timburke: thanks, i thought so. | 16:44 |
kmalloc | timburke: yay caching! | 16:44 |
jrosser | so if i was wanting to improve this ,, where should i start? | 16:44 |
jrosser | because i'm doing 700 req/sec S3 and thats crippling keystone | 16:45 |
kmalloc | timburke: i'll tag you on my review to officially deprecate in ksm shortly | 16:45 |
kmalloc | timburke: then in a cycle or two we can just drop the KSM code :) | 16:45 |
kmalloc | timburke: will reduce confusion i think | 16:45 |
*** shrasool has quit IRC | 16:45 | |
timburke | jrosser: i *think* https://github.com/openstack/swift/blob/master/swift/common/middleware/s3api/s3token.py should be a drop-in replacement for whichever version you're currently using -- you could try it out, see how it goes | 16:46 |
timburke | kmalloc: sounds good | 16:46 |
kmalloc | cmurphy: i'd like to see immutable expanded to users, projects, roles, etc as well | 16:47 |
kmalloc | cmurphy: ftr. | 16:47 |
cmurphy | kmalloc: okay | 16:48 |
cmurphy | kmalloc: what, if anything, besides roles should default to immutable in bootstrap? | 16:48 |
cmurphy | admin user? | 16:48 |
kmalloc | cmurphy: hmmmmm nothing from bootstrap but the roles imop | 16:48 |
kmalloc | imo* | 16:48 |
cmurphy | mmk | 16:48 |
kmalloc | but the option should be there for the other resources. | 16:48 |
kmalloc | i can totally see folks wanting to secure those things. | 16:49 |
jrosser | timburke: thanks! we'll certainly have a go with that | 16:49 |
kmalloc | and i expect immutable to disable update of anything *except* the immutable flag, so it works like chattr +i does (rough analogue) | 16:49 |
kmalloc | i see resource_options as being like extended attributes in the linux filesystem (in broad strokes) | 16:50 |
*** erus has quit IRC | 16:57 | |
*** erus has joined #openstack-keystone | 16:59 | |
ayoung | kmalloc, what do you think of the following: we have 2 read only roles. one called auditor, which is essentially a read-only admin role. The other is called reader, and is a read only role for member level operations. | 18:03 |
ayoung | would it make sense to align behind that approach? I think the reader vs. auditor split is valuable | 18:05 |
*** gyee has joined #openstack-keystone | 18:09 | |
kmalloc | uhm. | 18:26 |
kmalloc | hmmm. | 18:26 |
kmalloc | so, i think it doesn't matter waht we call it | 18:27 |
kmalloc | i think it's going to come down to what we define the roles as, system and non-system scope | 18:27 |
kmalloc | one reader role, one two. one called auditor, one that is called omg-im-not-really-an-admin | 18:28 |
kmalloc | define what you want the roles to be able to do. | 18:28 |
kmalloc | naming is fairly irrelevant | 18:28 |
lbragstad | i'd rather have one instead of two | 18:30 |
lbragstad | scoping answers part of the question for us | 18:30 |
lbragstad | http://lists.openstack.org/pipermail/openstack-discuss/2018-December/000907.html | 18:30 |
*** mvkr has quit IRC | 18:40 | |
*** jmlowe has quit IRC | 18:47 | |
* lbragstad steps away for lunch | 18:52 | |
*** amoralej is now known as amoralej|off | 19:00 | |
*** imus has quit IRC | 19:04 | |
*** jmlowe has joined #openstack-keystone | 19:12 | |
*** mvkr has joined #openstack-keystone | 19:21 | |
*** pcaruana has quit IRC | 19:47 | |
*** ayoung has quit IRC | 19:49 | |
*** shrasool has joined #openstack-keystone | 19:54 | |
kmalloc | lbragstad: right. As long as we define it and document it | 20:13 |
kmalloc | it'll work | 20:14 |
lbragstad | yeah - i just don't want to have operators needing to deal with one reader role meaning something and another meaning something else | 20:15 |
lbragstad | or having different intended usages | 20:16 |
lbragstad | (e.g., reader is end user specific, but auditor isn't) | 20:16 |
openstackgerrit | Merged openstack/keystone master: Remove message about circular role inferences https://review.openstack.org/624553 | 20:24 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system reader role for projects https://review.openstack.org/624215 | 20:25 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system member role project test coverage https://review.openstack.org/624216 | 20:25 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system admin role in project API https://review.openstack.org/624217 | 20:25 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement domain reader functionality for projects https://review.openstack.org/624218 | 20:25 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement domain member functionality for projects https://review.openstack.org/624219 | 20:25 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement domain admin functionality for projects https://review.openstack.org/624220 | 20:25 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add explicit testing for project users and the project API https://review.openstack.org/624221 | 20:25 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove project policies from policy.v3cloudsample.json https://review.openstack.org/624222 | 20:25 |
kmalloc | lbragstad: i just don't care if it's multiple roles or one as long as it's documented and defined. | 20:35 |
*** jmlowe has quit IRC | 21:01 | |
*** markvoelker has joined #openstack-keystone | 21:11 | |
*** raildo has quit IRC | 21:21 | |
*** jmlowe has joined #openstack-keystone | 21:22 | |
*** xek has quit IRC | 21:26 | |
*** jmlowe has quit IRC | 21:26 | |
*** tobias-urdin has quit IRC | 21:32 | |
*** erus has quit IRC | 21:36 | |
*** erus has joined #openstack-keystone | 21:39 | |
*** erus has quit IRC | 21:44 | |
*** jmlowe has joined #openstack-keystone | 21:50 | |
*** erus has joined #openstack-keystone | 21:57 | |
*** dklyle has joined #openstack-keystone | 22:05 | |
*** markvoelker has quit IRC | 22:06 | |
*** david-lyle has joined #openstack-keystone | 22:09 | |
*** dklyle has quit IRC | 22:12 | |
*** shrasool has quit IRC | 22:18 | |
*** rcernin has joined #openstack-keystone | 22:21 | |
*** david-lyle has quit IRC | 22:23 | |
lbragstad | cmurphy good find on ^ | 22:35 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system reader role for projects https://review.openstack.org/624215 | 22:35 |
lbragstad | er... | 22:35 |
lbragstad | ^ | 22:35 |
lbragstad | i ended up finding several holes in the tests | 22:35 |
lbragstad | i'm sure there are more... but i added some inline comments on the usefulness of some of the functionality | 22:36 |
lbragstad | specifically for project users | 22:36 |
cmurphy | cool | 22:36 |
lbragstad | i'll wait until it gets another look or two before respinning the whole series | 22:36 |
*** itlinux has quit IRC | 22:36 | |
cmurphy | i'll take another look tomorrow | 22:36 |
lbragstad | ack - thanks again | 22:37 |
*** lbragstad has quit IRC | 22:37 | |
*** mchlumsky has quit IRC | 22:45 | |
*** erus has quit IRC | 23:11 | |
*** erus has joined #openstack-keystone | 23:12 | |
*** aloga has quit IRC | 23:32 | |
*** aloga has joined #openstack-keystone | 23:32 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!