*** jamesmcarthur has quit IRC | 00:06 | |
*** jamesmcarthur has joined #openstack-keystone | 00:08 | |
*** jamesmcarthur has quit IRC | 00:09 | |
*** jamesmcarthur has joined #openstack-keystone | 00:09 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Update API version for access rules https://review.opendev.org/671374 | 00:13 |
---|---|---|
*** jamesmcarthur has quit IRC | 00:33 | |
*** jamesmcarthur has joined #openstack-keystone | 00:33 | |
*** jamesmcarthur has quit IRC | 00:39 | |
*** gyee has quit IRC | 00:46 | |
ileixe | cmurphy: yes I saw your comments in my report. I understand what's diffrerence | 01:07 |
ileixe | Thanks cmurphy and vishakha :) | 01:07 |
*** jamesmcarthur has joined #openstack-keystone | 01:09 | |
ileixe | And.. one more thing to ask, what's the best practice for multi region deployment keystone community says? | 01:10 |
ileixe | I consider federation though, I felt it looks like for the hybrid or many many cloud | 01:10 |
ileixe | I just want to maintain multi region (geologically seperated) deployment with one source(LDAP). Federdations looks heavy for the use case. | 01:11 |
ileixe | Could you guys shed light on ? T_ T | 01:12 |
*** jamesmcarthur has quit IRC | 01:15 | |
*** jamielennox has joined #openstack-keystone | 01:16 | |
*** imacdonn has quit IRC | 01:16 | |
*** imacdonn has joined #openstack-keystone | 01:17 | |
*** joshualyle has quit IRC | 01:23 | |
*** whoami-rajat has joined #openstack-keystone | 01:31 | |
*** ileixe has quit IRC | 01:37 | |
*** jamesmcarthur has joined #openstack-keystone | 01:40 | |
*** ileixe has joined #openstack-keystone | 01:45 | |
*** jamielennox has quit IRC | 02:52 | |
*** jamesmcarthur has quit IRC | 02:54 | |
*** jamesmcarthur has joined #openstack-keystone | 02:55 | |
*** jamesmcarthur has quit IRC | 02:59 | |
*** redrobot has quit IRC | 03:32 | |
*** jamesmcarthur has joined #openstack-keystone | 03:35 | |
*** Guest99405 has joined #openstack-keystone | 03:39 | |
*** jamesmcarthur has quit IRC | 05:10 | |
*** shyamb has joined #openstack-keystone | 05:15 | |
*** shyamb has quit IRC | 05:39 | |
*** pcaruana has joined #openstack-keystone | 05:44 | |
*** shyamb has joined #openstack-keystone | 05:56 | |
*** joshualyle has joined #openstack-keystone | 06:21 | |
*** sapd1 has quit IRC | 06:37 | |
*** rcernin has quit IRC | 06:44 | |
openstackgerrit | Jose Castro Leon proposed openstack/keystone master: Allow to filter endpoint groups by name https://review.opendev.org/658359 | 06:58 |
*** xek has joined #openstack-keystone | 07:06 | |
*** vishakha has joined #openstack-keystone | 07:07 | |
*** shyamb has quit IRC | 07:27 | |
*** dancn has joined #openstack-keystone | 08:12 | |
*** shyamb has joined #openstack-keystone | 08:19 | |
*** new_student1411 has joined #openstack-keystone | 08:37 | |
*** tkajinam has quit IRC | 08:40 | |
*** xek has quit IRC | 08:42 | |
*** xek has joined #openstack-keystone | 08:43 | |
*** xek has quit IRC | 08:47 | |
*** xek has joined #openstack-keystone | 08:51 | |
*** xek has quit IRC | 08:52 | |
*** xek has joined #openstack-keystone | 09:26 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Remove [signing] config https://review.opendev.org/659434 | 09:26 |
*** jamesmcarthur has joined #openstack-keystone | 10:15 | |
*** jamesmcarthur has quit IRC | 10:19 | |
*** new_student1411 has quit IRC | 10:23 | |
*** shyamb has quit IRC | 10:23 | |
*** shyam89 has joined #openstack-keystone | 10:23 | |
*** new_student1411 has joined #openstack-keystone | 10:23 | |
*** shyam89 has quit IRC | 10:29 | |
*** whoami-rajat has quit IRC | 10:30 | |
*** takamatsu has joined #openstack-keystone | 10:37 | |
*** shyamb has joined #openstack-keystone | 10:46 | |
*** joshualyle has quit IRC | 11:24 | |
*** shyamb has quit IRC | 11:29 | |
*** tesseract has joined #openstack-keystone | 11:38 | |
*** new_student1411 has quit IRC | 11:49 | |
*** kplant has joined #openstack-keystone | 11:58 | |
mnaser | fyi something i just saw in #openstack-infra (and i ran into a while back) .. the application credential api is actually functional *even* if an environment does not have application_credential listed as an authentication method | 12:22 |
*** shyamb has joined #openstack-keystone | 12:23 | |
*** mflynn has joined #openstack-keystone | 12:32 | |
*** raildo has joined #openstack-keystone | 12:34 | |
*** stingrayza_ has joined #openstack-keystone | 12:43 | |
*** stingrayza has quit IRC | 12:46 | |
*** new_student1411 has joined #openstack-keystone | 12:47 | |
*** stingrayza has joined #openstack-keystone | 12:51 | |
*** stingrayza_ has quit IRC | 12:55 | |
*** mvkr_ has quit IRC | 12:56 | |
*** shyamb has quit IRC | 13:05 | |
*** Guest99405 is now known as redrobot | 13:13 | |
*** ag-47 has joined #openstack-keystone | 13:17 | |
*** hoonetorg has quit IRC | 13:28 | |
*** ag-47 has quit IRC | 13:32 | |
*** beekneemech has joined #openstack-keystone | 13:36 | |
*** bnemec has quit IRC | 13:37 | |
*** vishakha has quit IRC | 13:42 | |
*** raildo has quit IRC | 13:50 | |
*** whoami-rajat has joined #openstack-keystone | 13:55 | |
*** jamesmcarthur has joined #openstack-keystone | 14:19 | |
*** jamesmcarthur has quit IRC | 14:23 | |
*** jamesmcarthur has joined #openstack-keystone | 14:24 | |
kmalloc | mnaser: right. authenticating with application credentials requires the auth method, app-cred API is part of the API, and APIs are not optional or configurable. Maybe we should explicitly 403 that API if the auth method is not present. Right now the way to handle it would be to update policy.json to disallow the api | 14:26 |
kmalloc | s/configurable/removable | 14:26 |
mnaser | kmalloc: yeah it has caused confusion in the past when the api responds successfully but you cant authenticate with it | 14:27 |
mnaser | but yeah i think a 403 is application_credentials is not configured makes sense... | 14:27 |
kmalloc | mnaser: can you open a bug for us as an RFE for that change? | 14:35 |
kmalloc | mnaser: actually, i'll go ahead and open the bug | 14:35 |
*** lbragstad has joined #openstack-keystone | 14:36 | |
kmalloc | mnaser: https://bugs.launchpad.net/keystone/+bug/1837061 | 14:39 |
openstack | Launchpad bug 1837061 in OpenStack Identity (keystone) "RFE: Application Credential API (CRUD) to 403 if app-cred auth method not enabled" [Wishlist,New] | 14:39 |
kmalloc | mnaser: please feel free to add any other info to the bug. | 14:39 |
*** jamesmcarthur has quit IRC | 14:43 | |
mnaser | kmalloc: added a bit, thanks! :) | 14:47 |
kmalloc | this should be a pretty easy change, just need to confirm everyone is ok with it before we make it. | 14:48 |
cmurphy | ileixe: we don't have much of a best practices guide for multi-region/multi-site, federation is one way but multiple keystones backed by a single distributed ldap is another simpler way, and another way is just using one keystone and just using regular keystone regions for the other openstack services | 14:58 |
cmurphy | kmalloc: mnaser whoa no i don't think we should change the CRUD api to 403 if the auth method is disabled, that would be an api break | 15:00 |
cmurphy | the crud api and the auth api are unrelated apis | 15:00 |
kmalloc | cmurphy: i am simply translating to an RFE so we can document/clearly communicate the change. | 15:00 |
kmalloc | i wasn't advocating for it, just commenting it is an easy change if we decide on the direction. | 15:00 |
kmalloc | having a "paper trail" for confirming/denying the change and discussing it is important | 15:01 |
cmurphy | fair enough | 15:01 |
cmurphy | i'm expressing that i'm against it :) | 15:01 |
kmalloc | cmurphy: please add that to the bug report :) | 15:02 |
cmurphy | o7 | 15:02 |
kmalloc | ^_^ | 15:08 |
kmalloc | also good mornin. | 15:08 |
kmalloc | how's your area of the PNW this morning? | 15:08 |
cmurphy | it's lovely, blue skies right now and will have a high of 75F today | 15:09 |
cmurphy | it's been a very mild summer | 15:09 |
cmurphy | lbragstad: want to take a look at https://review.opendev.org/669790 when you get a minute? | 15:21 |
kmalloc | cmurphy: it's grey and cold here in seattle | 15:21 |
cmurphy | kmalloc: that is unfortunate | 15:22 |
*** hoonetorg has joined #openstack-keystone | 15:26 | |
lbragstad | cmurphy done | 15:36 |
kplant | cmurphy: wouldn't the single keystone be a bad idea due to latency and lack of redundancy? | 15:36 |
cmurphy | lbragstad: tyty | 15:37 |
cmurphy | kplant: on latency, depends on where your regions are and what your latency tolerance is, on redundancy you could have a "single" keystone that is still galera-backed active/active so you could still have some amount of a redundancy | 15:38 |
kplant | true, i guess i meant georedundancy | 15:39 |
kplant | if cloud b uses cloud a's keystone and cloud a is unavailable | 15:39 |
kplant | cloud b would also be unavailable | 15:39 |
cmurphy | yeah you would not have that redundancy | 15:40 |
kplant | it would be nice to be able to stretch that asynchronously across regions | 15:41 |
kplant | cough | 15:41 |
kplant | :> | 15:41 |
kmalloc | kplant: thats the whole edge compute design concern in a nutshell. | 15:48 |
*** ag-47 has joined #openstack-keystone | 15:48 | |
kmalloc | kplant: for the most part synchronous replication across a small (2-20) sites tends to be just fine. The other alternative is isolated per-region keystone but replicate identity (LDAP) store to each site. That would require logging in to each region explicitly, but the information would remain the same per keystone endpoint | 15:49 |
kmalloc | kplant: more than 20 sites it becomes much harder. more than 100 sites, databases are wonky, more than 1000 sites you need something totally different (eventual consistent data store, etc) | 15:50 |
*** dancn has quit IRC | 15:51 | |
*** beekneemech has quit IRC | 15:57 | |
*** bnemec has joined #openstack-keystone | 15:58 | |
*** joshualyle has joined #openstack-keystone | 16:21 | |
*** gyee has joined #openstack-keystone | 16:27 | |
openstackgerrit | Merged openstack/keystone master: update documentation for X.509 tokenless auth https://review.opendev.org/669790 | 16:54 |
cmurphy | need more reviews on https://review.opendev.org/604201 before spec freeze next week | 16:59 |
cmurphy | also looking for more reviews on https://review.opendev.org/633369 so we can do a ksm release | 17:00 |
*** ag-47 has quit IRC | 17:05 | |
*** xek has quit IRC | 17:06 | |
*** raildo has joined #openstack-keystone | 17:30 | |
*** aprice has quit IRC | 17:45 | |
*** hogepodge has quit IRC | 17:45 | |
*** aprice has joined #openstack-keystone | 17:47 | |
*** hogepodge has joined #openstack-keystone | 17:47 | |
gagehugo | cmurphy: ksm done | 18:04 |
cmurphy | thanks gagehugo | 18:05 |
*** irclogbot_3 has quit IRC | 18:07 | |
*** altlogbot_0 has quit IRC | 18:07 | |
*** irclogbot_2 has joined #openstack-keystone | 18:08 | |
*** altlogbot_0 has joined #openstack-keystone | 18:08 | |
openstackgerrit | Raildo Mascena proposed openstack/keystone master: Fixing dn_to_id function for cases were id is not in the DN https://review.opendev.org/649177 | 19:01 |
*** lbragstad has quit IRC | 19:02 | |
*** new_student1411 has quit IRC | 19:05 | |
*** mflynn has quit IRC | 19:13 | |
*** jdennis has quit IRC | 19:37 | |
*** jdennis has joined #openstack-keystone | 19:37 | |
*** jdennis has quit IRC | 19:42 | |
*** jdennis has joined #openstack-keystone | 19:43 | |
*** whoami-rajat has quit IRC | 19:44 | |
openstackgerrit | Merged openstack/keystonemiddleware master: Add validation of app cred access rules https://review.opendev.org/633369 | 19:47 |
*** jdennis has quit IRC | 19:56 | |
*** jdennis has joined #openstack-keystone | 19:56 | |
*** kplant has quit IRC | 19:57 | |
*** pcaruana has quit IRC | 20:01 | |
*** tesseract has quit IRC | 20:05 | |
*** mvkr_ has joined #openstack-keystone | 20:05 | |
*** blake has joined #openstack-keystone | 20:38 | |
*** ayoung has quit IRC | 20:44 | |
*** ayoung has joined #openstack-keystone | 20:50 | |
*** blake has quit IRC | 20:58 | |
*** blake has joined #openstack-keystone | 20:59 | |
*** blake has quit IRC | 20:59 | |
*** raildo has quit IRC | 21:04 | |
*** raildo has joined #openstack-keystone | 21:04 | |
*** raildo has quit IRC | 21:21 | |
*** joshualyle has quit IRC | 21:24 | |
*** beekneemech has joined #openstack-keystone | 21:38 | |
*** beekneemech has quit IRC | 21:38 | |
*** ayoung has quit IRC | 21:52 | |
*** bnemec has quit IRC | 22:03 | |
*** bnemec has joined #openstack-keystone | 22:13 | |
*** bnemec has quit IRC | 22:42 | |
*** bnemec has joined #openstack-keystone | 22:43 | |
*** ivve has quit IRC | 22:54 | |
*** tkajinam has joined #openstack-keystone | 22:58 | |
*** rcernin has joined #openstack-keystone | 23:15 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!