*** jamesmcarthur has joined #openstack-keystone | 00:03 | |
*** jamesmcarthur has quit IRC | 00:08 | |
*** jamesmcarthur has joined #openstack-keystone | 00:12 | |
*** jamesmcarthur has quit IRC | 00:16 | |
*** ayoung has joined #openstack-keystone | 00:37 | |
*** markvoelker has joined #openstack-keystone | 00:42 | |
*** markvoelker has quit IRC | 00:44 | |
*** markvoelker has joined #openstack-keystone | 00:45 | |
*** whoami-rajat has joined #openstack-keystone | 01:19 | |
*** irclogbot_1 has quit IRC | 01:44 | |
*** edmondsw_ has quit IRC | 01:48 | |
*** jamesmcarthur has joined #openstack-keystone | 01:50 | |
*** Dinesh_Bhor has joined #openstack-keystone | 01:57 | |
*** ileixe has joined #openstack-keystone | 02:53 | |
*** Nel1x has quit IRC | 03:02 | |
*** jamesmcarthur has quit IRC | 03:03 | |
*** Nel1x has joined #openstack-keystone | 03:21 | |
*** shyamb has joined #openstack-keystone | 04:05 | |
*** Nel1x has quit IRC | 04:10 | |
*** pcaruana has joined #openstack-keystone | 04:49 | |
*** pcaruana has quit IRC | 04:55 | |
*** shyamb has quit IRC | 04:56 | |
*** jamesmcarthur has joined #openstack-keystone | 05:05 | |
*** jamesmcarthur has quit IRC | 05:06 | |
*** jamesmcarthur has joined #openstack-keystone | 05:06 | |
*** jamesmcarthur has quit IRC | 05:10 | |
*** shyamb has joined #openstack-keystone | 05:15 | |
*** mkrai has joined #openstack-keystone | 05:34 | |
mkrai | Hi, while setting up devstack I get this error http://paste.openstack.org/show/748981/ | 05:35 |
---|---|---|
mkrai | I checked that auth | 05:35 |
mkrai | I checked that auth_url is correctly set in environment variable | 05:35 |
*** phasespace has quit IRC | 06:01 | |
*** jaosorior has joined #openstack-keystone | 06:05 | |
*** pcaruana has joined #openstack-keystone | 06:30 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Convert user_id back to string https://review.openstack.org/650615 | 06:31 |
*** markvoelker has quit IRC | 06:43 | |
*** awalende has joined #openstack-keystone | 07:10 | |
*** shyamb has quit IRC | 07:19 | |
*** awalende has quit IRC | 07:19 | |
*** shyamb has joined #openstack-keystone | 07:19 | |
*** phasespace has joined #openstack-keystone | 07:19 | |
*** awalende has joined #openstack-keystone | 07:20 | |
*** awalende has quit IRC | 07:24 | |
*** awalende has joined #openstack-keystone | 07:24 | |
*** awalende has quit IRC | 07:39 | |
*** awalende has joined #openstack-keystone | 07:42 | |
*** tkajinam has quit IRC | 08:11 | |
*** rcernin has quit IRC | 08:19 | |
*** mkrai has quit IRC | 08:38 | |
*** markvoelker has joined #openstack-keystone | 08:45 | |
*** zigo_ has joined #openstack-keystone | 08:45 | |
*** zigo_ is now known as zigo | 08:50 | |
*** tobberydberg has quit IRC | 09:12 | |
*** markvoelker has quit IRC | 09:18 | |
*** tobberydberg has joined #openstack-keystone | 09:25 | |
*** shyamb has quit IRC | 09:35 | |
*** markvoelker has joined #openstack-keystone | 10:16 | |
*** markvoelker has quit IRC | 10:49 | |
*** markvoelker has joined #openstack-keystone | 11:15 | |
*** mvkr has quit IRC | 11:34 | |
*** pcaruana has quit IRC | 11:47 | |
*** edmondsw has joined #openstack-keystone | 12:04 | |
*** raildo has joined #openstack-keystone | 12:04 | |
*** jamesmcarthur has joined #openstack-keystone | 12:17 | |
*** mvkr has joined #openstack-keystone | 12:29 | |
*** jamesmcarthur has quit IRC | 12:30 | |
*** mchlumsky has joined #openstack-keystone | 12:37 | |
*** pcaruana has joined #openstack-keystone | 12:38 | |
*** mchlumsky has quit IRC | 12:41 | |
*** mchlumsky has joined #openstack-keystone | 12:42 | |
*** jamesmcarthur has joined #openstack-keystone | 12:48 | |
*** needssleep is now known as TheJulia | 12:49 | |
*** jroll has quit IRC | 12:50 | |
*** jroll has joined #openstack-keystone | 12:50 | |
*** awalende has quit IRC | 12:59 | |
*** awalende has joined #openstack-keystone | 12:59 | |
*** ab-a has joined #openstack-keystone | 13:03 | |
*** awalende has quit IRC | 13:04 | |
knikolla | o/ | 13:07 |
*** lbragstad has joined #openstack-keystone | 13:08 | |
*** ChanServ sets mode: +o lbragstad | 13:08 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Convert user_id back to string https://review.openstack.org/650615 | 13:10 |
*** cmorpheus is now known as cmurphy | 13:11 | |
*** whoami-rajat has quit IRC | 13:28 | |
*** pcaruana has quit IRC | 13:31 | |
*** pcaruana has joined #openstack-keystone | 13:36 | |
*** whoami-rajat has joined #openstack-keystone | 13:38 | |
*** jmlowe has quit IRC | 13:52 | |
*** phasespace has quit IRC | 14:02 | |
gagehugo | o/ | 14:24 |
lbragstad | o/ | 14:26 |
*** spotz has joined #openstack-keystone | 14:27 | |
*** jmlowe has joined #openstack-keystone | 14:28 | |
cmurphy | \o | 14:31 |
*** mchlumsky has quit IRC | 14:43 | |
*** mchlumsky has joined #openstack-keystone | 14:46 | |
*** lbragstad has quit IRC | 14:46 | |
*** lbragstad has joined #openstack-keystone | 14:47 | |
*** ChanServ sets mode: +o lbragstad | 14:47 | |
*** phasespace has joined #openstack-keystone | 15:16 | |
*** gyee has joined #openstack-keystone | 15:20 | |
*** itlinux_ has quit IRC | 15:33 | |
*** itlinux has joined #openstack-keystone | 16:28 | |
ayoung | kmalloc, got a customer interested in using mariadb async replication from a central keystone to remotes. All installs done via TripleO. THought? | 17:26 |
kmalloc | Hmmmm | 17:26 |
ayoung | As I can see it, there problem points are going to be the data installed into the remote sites during install | 17:27 |
kmalloc | If it is not bi-directional replication (not master/master with the remotes) it is probably ok. | 17:27 |
ayoung | I think all service catalogs are region 1 | 17:27 |
ayoung | and the nova etc users will have distinct passwords | 17:27 |
ayoung | but all be in the same database | 17:27 |
ayoung | I think you can sync paswords, though, | 17:28 |
kmalloc | You can. But conflicts because we key on name for unique in some cases could be hard. | 17:28 |
ayoung | they would have different userids, but I think all the config files only have usernames | 17:28 |
kmalloc | If it is multi-master | 17:28 |
ayoung | I wonder if they could install the lower clusters, shut them down, run the sync, update the config files, and bring it back up? | 17:29 |
kmalloc | Probably | 17:29 |
ayoung | I don't think OOO supports service users in LDAP | 17:42 |
ayoung | let me check. | 17:42 |
ayoung | I think the installer puts services users in the default domain | 17:42 |
*** jamesmcarthur_ has joined #openstack-keystone | 17:46 | |
*** jamesmcarthur has quit IRC | 17:49 | |
*** itlinux has quit IRC | 18:19 | |
*** johnsom has quit IRC | 18:20 | |
*** johnsom has joined #openstack-keystone | 18:21 | |
*** BlackDex has quit IRC | 18:22 | |
*** BlackDex has joined #openstack-keystone | 18:22 | |
ayoung | kmalloc, I told them not to do it. Upgrades | 18:41 |
kmalloc | ah | 18:41 |
ayoung | It really is something we need to work on with the TripleO team | 18:41 |
ayoung | or maybe edge? | 18:42 |
openstackgerrit | Raildo Mascena proposed openstack/keystone master: [WIP]Fixing dn_to_id function for cases were id it's not in the DN https://review.openstack.org/649177 | 18:48 |
*** mvkr has quit IRC | 18:51 | |
*** jmlowe has quit IRC | 18:56 | |
*** eandersson_ is now known as eandersson | 18:57 | |
*** jamesmcarthur_ has quit IRC | 19:04 | |
cmurphy | lbragstad: kmalloc need stable reviews for this stein boilerplate | https://review.openstack.org/#/q/status:open+(project:openstack/keystone+OR+project:openstack/keystoneauth+OR+project:openstack/keystonemiddleware)+branch:stable/stein │ | 19:11 |
kmalloc | done | 19:13 |
* kmalloc goes back to PTO. | 19:13 | |
* lbragstad goes back to tinkering with ansible | 19:14 | |
lbragstad | unrelated: i wish i would have found this *years* ago https://docs.ansible.com/ansible/latest/modules/github_key_module.html | 19:14 |
eandersson | A silly question but local_users has a primary key and auto increment for id. | 19:32 |
eandersson | Would it be possible to change this id to a uuid? | 19:32 |
eandersson | auto increment makes async replication difficult :p | 19:33 |
*** jamesmcarthur has joined #openstack-keystone | 19:34 | |
*** jamesmcarthur_ has joined #openstack-keystone | 19:35 | |
*** jamesmcarthur has quit IRC | 19:39 | |
kmalloc | eandersson: uuid is a terrible PK | 19:39 |
eandersson | sure - but auto increment and primary key is not great either for replication | 19:40 |
eandersson | not sure what the better alternative is | 19:40 |
kmalloc | autoinc | 19:40 |
kmalloc | you can set a skip value, so node 1 does, 1, 3, 5 etc | 19:40 |
kmalloc | and node 2 does 2,4,6 | 19:40 |
eandersson | assuming you can do that | 19:41 |
kmalloc | uuids are terrible for PK indexing in most mysql cases. And internal PKs should not be exposed, especially if it's a FK to another table | 19:41 |
kmalloc | async multimaster is also a terrible idea with an application like keystone | 19:42 |
kmalloc | this is just my opinion though. | 19:43 |
kmalloc | honestly, i'd rather see all the PKs in keystone move to autoinc. | 19:44 |
kmalloc | to be consistent | 19:44 |
eandersson | I just want to offer a good experience to our customers | 19:44 |
kmalloc | what are you trying to solve exactly? a 100% shared keystone across many micro sites? | 19:45 |
eandersson | and unfortunately my expertise within databases, and database replications is limited | 19:45 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Convert user_id back to string https://review.openstack.org/650615 | 19:45 |
eandersson | pretty much | 19:45 |
* kmalloc is going to get yelled at by his better half for doing "work". | 19:45 | |
eandersson | I mean we have had this running for many years | 19:45 |
kmalloc | well not yelled at...just a stern glare | 19:45 |
kmalloc | :P | 19:45 |
*** jamesmcarthur_ has quit IRC | 19:45 | |
eandersson | and it works great in general, but as some applications started generating local users | 19:46 |
kmalloc | is it because you need domains/projects/user_ids to be consistent or are you using tokens from one environment in anotheR? | 19:46 |
eandersson | it started causing issues | 19:46 |
eandersson | as most of our users are backed by ldap | 19:46 |
*** ceryx has joined #openstack-keystone | 19:46 | |
eandersson | domains/projects + tokens | 19:46 |
eandersson | is what we care about | 19:46 |
eandersson | to be available in all other regions | 19:46 |
eandersson | available + consistent | 19:46 |
kmalloc | so, the general way i'd do that is central management with read-only remote replicas. | 19:47 |
eandersson | tokens are easy of course due to fernet | 19:47 |
kmalloc | assuming your CRMS is managing user data to LDAP. | 19:47 |
kmalloc | manage users/projects/domains centrally, then the remote sites could receive 100% of the replication | 19:47 |
kmalloc | it can scale to probably ~20+ sites, though i think there are issues scaling this upwards of 100, even wtih async | 19:48 |
eandersson | How would that even work? How do you move writes to one region, and all reads to local region? | 19:48 |
eandersson | or do you proxy writes to a central region? | 19:49 |
kmalloc | oslo.db should support read vs write connections | 19:49 |
kmalloc | i *think* we have that in keystone | 19:49 |
eandersson | Are you going to Denver kmalloc ? | 19:49 |
kmalloc | nope | 19:49 |
kmalloc | i wont be in denver | 19:49 |
*** jmlowe has joined #openstack-keystone | 20:00 | |
*** dave-mccowan has joined #openstack-keystone | 20:06 | |
*** whoami-rajat has quit IRC | 20:08 | |
openstackgerrit | Raildo Mascena proposed openstack/keystone master: [WIP]Fixing dn_to_id function for cases were id it's not in the DN https://review.openstack.org/649177 | 20:09 |
*** jamesmcarthur has joined #openstack-keystone | 20:11 | |
*** pcaruana has quit IRC | 20:25 | |
*** whoami-rajat has joined #openstack-keystone | 21:45 | |
*** mchlumsky has quit IRC | 21:52 | |
*** rcernin has joined #openstack-keystone | 22:14 | |
*** lbragstad has quit IRC | 22:14 | |
*** raildo has quit IRC | 22:37 | |
*** dave-mccowan has quit IRC | 22:58 | |
*** tkajinam has joined #openstack-keystone | 23:00 | |
*** jamesmcarthur has quit IRC | 23:22 | |
*** jamesmcarthur has joined #openstack-keystone | 23:56 | |
*** whoami-rajat has quit IRC | 23:58 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!