*** jamesmcarthur has joined #openstack-keystone | 00:17 | |
*** markvoelker has joined #openstack-keystone | 00:20 | |
*** markvoelker has quit IRC | 00:25 | |
*** itlinux_ has joined #openstack-keystone | 00:46 | |
*** itlinux has quit IRC | 00:49 | |
*** jamesmcarthur has quit IRC | 01:33 | |
*** jamesmcarthur has joined #openstack-keystone | 02:14 | |
*** jamesmcarthur has quit IRC | 02:37 | |
*** masayukig has joined #openstack-keystone | 02:41 | |
*** markvoelker has joined #openstack-keystone | 02:55 | |
*** markvoelker has quit IRC | 03:00 | |
*** jamesmcarthur has joined #openstack-keystone | 03:04 | |
*** rcernin_ has joined #openstack-keystone | 03:15 | |
*** rcernin has quit IRC | 03:15 | |
*** jamesmcarthur has quit IRC | 03:33 | |
*** markvoelker has joined #openstack-keystone | 04:20 | |
*** markvoelker has quit IRC | 04:25 | |
*** itlinux has joined #openstack-keystone | 04:31 | |
*** itlinux_ has quit IRC | 04:34 | |
*** beekneemech has quit IRC | 05:16 | |
*** bnemec has joined #openstack-keystone | 05:20 | |
*** jaosorior has joined #openstack-keystone | 05:51 | |
*** dancn has joined #openstack-keystone | 05:53 | |
*** shyamb has joined #openstack-keystone | 05:54 | |
*** rcernin_ has quit IRC | 06:18 | |
*** dancn has quit IRC | 06:33 | |
*** takamatsu has joined #openstack-keystone | 06:34 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Add tests for domain users for policy association https://review.opendev.org/678467 | 06:37 |
---|---|---|
*** dancn has joined #openstack-keystone | 06:40 | |
*** takamatsu has quit IRC | 06:42 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Add tests for project users for policy association https://review.opendev.org/678471 | 06:48 |
*** trident has quit IRC | 07:01 | |
*** itlinux has quit IRC | 07:03 | |
*** itlinux has joined #openstack-keystone | 07:04 | |
*** trident has joined #openstack-keystone | 07:10 | |
*** jawad_axd has joined #openstack-keystone | 07:13 | |
*** xek has joined #openstack-keystone | 07:25 | |
*** shyamb has quit IRC | 07:27 | |
*** shyam89 has joined #openstack-keystone | 07:27 | |
*** shyam89 has quit IRC | 07:30 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Remove system policy and its association from policy.v3cloudsample.json https://review.opendev.org/678475 | 07:31 |
*** ivve has joined #openstack-keystone | 07:54 | |
*** markvoelker has joined #openstack-keystone | 08:02 | |
*** markvoelker has quit IRC | 08:07 | |
*** tkajinam has quit IRC | 08:30 | |
openstackgerrit | Nikita Kalyanov proposed openstack/keystone master: Fix caching behavior https://review.opendev.org/677239 | 09:05 |
*** rcernin_ has joined #openstack-keystone | 09:13 | |
*** rcernin_ has quit IRC | 09:42 | |
*** markvoelker has joined #openstack-keystone | 10:05 | |
*** markvoelker has quit IRC | 10:10 | |
*** xek has quit IRC | 10:11 | |
*** jaosorior has quit IRC | 10:26 | |
*** xek has joined #openstack-keystone | 10:26 | |
*** markvoelker has joined #openstack-keystone | 10:35 | |
*** markvoelker has quit IRC | 10:40 | |
*** shyamb has joined #openstack-keystone | 10:46 | |
*** tesseract has joined #openstack-keystone | 11:12 | |
*** shyamb has quit IRC | 11:14 | |
*** shyamb has joined #openstack-keystone | 11:24 | |
*** vishakha has joined #openstack-keystone | 11:25 | |
*** cp has quit IRC | 11:41 | |
*** cp has joined #openstack-keystone | 11:42 | |
*** jaosorior has joined #openstack-keystone | 11:44 | |
*** jroll has quit IRC | 11:44 | |
*** jroll has joined #openstack-keystone | 11:45 | |
*** rcernin_ has joined #openstack-keystone | 11:53 | |
*** markvoelker has joined #openstack-keystone | 12:00 | |
*** shyamb has quit IRC | 12:24 | |
*** rcernin_ has quit IRC | 12:32 | |
*** xek_ has joined #openstack-keystone | 12:42 | |
*** xek_ has quit IRC | 12:47 | |
*** jamesmcarthur has joined #openstack-keystone | 12:47 | |
*** jmlowe has quit IRC | 12:56 | |
*** jmlowe has joined #openstack-keystone | 13:15 | |
*** dave-mccowan has joined #openstack-keystone | 13:20 | |
*** elbragstad is now known as lbragstad | 13:31 | |
lbragstad | o/ | 13:36 |
*** jamesmcarthur has quit IRC | 13:44 | |
*** jamesmcarthur has joined #openstack-keystone | 13:47 | |
*** psousa1 has joined #openstack-keystone | 13:49 | |
psousa1 | Hi there, I'm trying to configure keystone with 2 regions, but have some doubts about the endpoints connectivity. When I try to connect to the remote site it always tries to connect to the internal api network GET call to identity for http://192.168.24.11:35357/v3/services, instead of the external routed network. Is there a way to change this behavior? Thanks | 13:52 |
*** jamesmcarthur has quit IRC | 13:52 | |
*** jawad_axd has quit IRC | 13:53 | |
openstackgerrit | Alex Schultz proposed openstack/keystoneauth master: Cleanup session on delete https://review.opendev.org/674139 | 14:12 |
*** jamesmcarthur has joined #openstack-keystone | 14:21 | |
openstackgerrit | Lance Bragstad proposed openstack/keystoneauth master: Expose irreversible override with Session connect_retries https://review.opendev.org/678576 | 14:24 |
*** jamesmcarthur has quit IRC | 14:28 | |
*** zigo has joined #openstack-keystone | 14:30 | |
lbragstad | zaneb nice catch on the connect_retries default args | 14:35 |
zaneb | I'm not even sure that's a problem, but it seemed worth pointing out | 14:38 |
*** markvoelker has quit IRC | 14:41 | |
lbragstad | yeah | 14:41 |
lbragstad | as a developer, i think it would be weird to set retries on the session and not be able to override them for a specific request | 14:42 |
lbragstad | but - maybe that's not a likely case | 14:42 |
lbragstad | idk | 14:42 |
*** markvoelker has joined #openstack-keystone | 14:44 | |
kmalloc | lbragstad: ah, can't reset back to 0? | 14:55 |
lbragstad | i haven't been able to - that's what i tried to do in the test | 14:56 |
lbragstad | https://review.opendev.org/#/c/678576/ | 14:56 |
kmalloc | i know you can override to a different non-zero value | 14:56 |
lbragstad | https://review.opendev.org/#/c/678576/1/keystoneauth1/tests/unit/test_session.py@472 | 14:56 |
lbragstad | yeah - you could do something like call_args = {'connect_retries': 4} | 14:57 |
kmalloc | i added that test | 14:57 |
lbragstad | you can override up - but you can't override down(?) | 14:57 |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: Expiring User Group Membership Model https://review.opendev.org/677469 | 14:57 |
kmalloc | you can override down | 14:57 |
kmalloc | just not to 0 | 14:57 |
kmalloc | https://review.opendev.org/#/c/676648/4/keystoneauth1/tests/unit/test_session.py | 14:57 |
kmalloc | https://www.irccloud.com/pastebin/yA68a9e5/ | 14:58 |
kmalloc | ^ | 14:58 |
*** dancn has quit IRC | 14:58 | |
lbragstad | ok - so you can't unset then | 14:59 |
kmalloc | yeah | 14:59 |
kmalloc | which we should support. | 14:59 |
lbragstad | cool | 14:59 |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: Expiring Group Membership Driver https://review.opendev.org/678586 | 14:59 |
gagehugo | o/ | 15:00 |
kmalloc | so we can't land the patch until we can unset it, i think i know where it is. give me a sec | 15:00 |
kmalloc | lbragstad: we need to check is not none | 15:01 |
kmalloc | and set defaults to none not 0 | 15:01 |
lbragstad | can we do that? | 15:01 |
kmalloc | connect_retries = connect_retries or self._connect_retries | 15:01 |
kmalloc | changing the default is fine. | 15:01 |
kmalloc | because behavior is the same | 15:01 |
lbragstad | if someone left if unset - then they'd be assuming the new default of None | 15:02 |
knikolla | o/ | 15:02 |
lbragstad | it unset* | 15:02 |
kmalloc | which, behavior should be: none is == 0 retries (logic wise), so we do something like: | 15:02 |
lbragstad | and if someone set it explicitly, then they should observe the same behavior, yeah, ok | 15:02 |
kmalloc | if connect_retries is None: | 15:03 |
kmalloc | connect_retries = self._session_retries <-- should default to 0 | 15:03 |
kmalloc | so connect_retries always overrides. | 15:04 |
lbragstad | ok | 15:06 |
lbragstad | cool | 15:06 |
kmalloc | simple fix and we need to test the zero case as well | 15:08 |
lbragstad | i didn't write a case for overriding to something smaller that wasn't 0 | 15:09 |
kmalloc | lbragstad: but i did in the patch ;) | 15:09 |
lbragstad | ah | 15:09 |
kmalloc | so, we're good on that front | 15:09 |
kmalloc | and i could write the inverse but i'm not super worried, any non-zero and a zero case should be fine | 15:09 |
kmalloc | though maybe it should be if is not None and not < 0 | 15:10 |
kmalloc | a negative retry is... weird? | 15:10 |
lbragstad | yeah - i don't think that makes sense for retry logic | 15:14 |
lbragstad | we could validate input is None or >=0 | 15:15 |
lbragstad | do we even test negative interger cases? | 15:15 |
kmalloc | no we don't, afaik | 15:16 |
kmalloc | i would just validate like: if connect_retries is None or connect_retries < 0 | 15:17 |
kmalloc | and in the session one, just force it to be 0 or above. | 15:17 |
kmalloc | behavior should be 100% the same | 15:17 |
kmalloc | unrelated, i know this isn't passing (pending a tempest change): https://review.opendev.org/#/c/678322/ adds support for resource options to roles and projects | 15:18 |
*** jamesmcarthur has joined #openstack-keystone | 15:18 | |
kmalloc | the followup is almost ready, adds immutable | 15:18 |
kmalloc | it need a couple more tests and a fix to ldap tests (remove them?) | 15:19 |
kmalloc | it would have been done already but had an issue that took a chunk of my time last night/today | 15:19 |
*** jamesmcarthur has quit IRC | 15:22 | |
*** jamesmcarthur has joined #openstack-keystone | 15:22 | |
bnemec | Hey, can someone provide a sanity check on https://review.opendev.org/#/c/662830 ? | 15:31 |
bnemec | It looks reasonable to me, but I would like if someone from keystone could say "that's not totally wrong". :-) | 15:32 |
*** gyee has joined #openstack-keystone | 15:45 | |
*** xek has quit IRC | 15:51 | |
*** ivve has quit IRC | 16:00 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Add tests for domain users for policy association https://review.opendev.org/678467 | 16:12 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Add tests for project users for policy association https://review.opendev.org/678471 | 16:15 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Remove system policy and its association from policy.v3cloudsample.json https://review.opendev.org/678475 | 16:16 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: [WIP] Generate PDF documentation https://review.opendev.org/669982 | 16:32 |
*** jamesmcarthur has quit IRC | 16:40 | |
*** tesseract has quit IRC | 16:57 | |
lbragstad | kmalloc gyee pretty easy stable backport https://review.opendev.org/#/c/678610/ | 16:58 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: [WIP] Generate PDF documentation https://review.opendev.org/669982 | 17:02 |
*** jamesmcarthur has joined #openstack-keystone | 17:04 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: [WIP] Generate PDF documentation https://review.opendev.org/669982 | 17:08 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: [WIP] Generate PDF documentation https://review.opendev.org/669982 | 17:11 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: [WIP] Generate PDF documentation https://review.opendev.org/669982 | 17:12 |
gyee | lbragstad, looks like kmalloc A+ it already :-) | 17:24 |
kmalloc | yup | 17:27 |
*** jamesmcarthur has quit IRC | 17:29 | |
lbragstad | oh - sweet | 17:31 |
*** psousa1 has quit IRC | 17:45 | |
*** jamesmcarthur has joined #openstack-keystone | 17:49 | |
*** jamesmcarthur has quit IRC | 17:58 | |
*** jamesmcarthur has joined #openstack-keystone | 18:12 | |
kmalloc | lbragstad: bandit issue(s) hitting that backport | 18:25 |
lbragstad | bah | 18:26 |
lbragstad | broken gate? | 18:26 |
kmalloc | yep, bandit is detecting a header as a password | 18:26 |
*** trident has quit IRC | 18:40 | |
*** trident has joined #openstack-keystone | 18:40 | |
lbragstad | kmalloc looks like bandit completely fails for me locally | 18:50 |
lbragstad | it's getting 302 when it tries to pull the upper constrains file defined in tox.ini on stable/queens | 18:50 |
kmalloc | oh fun | 18:53 |
kmalloc | that is a bug we need to fix, needs to point to opendev | 18:53 |
kmalloc | rather than openstack.org | 18:54 |
*** markvoelker has quit IRC | 18:57 | |
*** xek_ has joined #openstack-keystone | 18:58 | |
*** ivve has joined #openstack-keystone | 18:59 | |
lbragstad | kmalloc lets see if https://review.opendev.org/#/c/678636/ helps | 19:00 |
*** markvoelker has joined #openstack-keystone | 19:11 | |
lbragstad | kmalloc what's the story behind https://opendev.org/openstack/keystone/src/branch/master/keystone/conf/__init__.py#L189-L197 ? | 19:20 |
lbragstad | doesn't ``keystone.conf [cache] enabled`` default to true? | 19:21 |
lbragstad | ah - nevermind... https://opendev.org/openstack/oslo.cache/src/branch/master/oslo_cache/_opts.py#L67-L68 | 19:21 |
lbragstad | it defaults to false, but we override it to make sure its always on | 19:22 |
openstackgerrit | Merged openstack/keystone master: Implement system reader and member for policies https://review.opendev.org/676162 | 19:28 |
kmalloc | lbragstad: yep | 19:29 |
*** andrein has joined #openstack-keystone | 19:30 | |
andrein | Hello everyone, I'm setting up LDAP authentication via the multi-domain feature. I was able to configure my domain, and I've got as far as "You are not authorized for any projects or domains" when I login with my LDAP account. I think it's time to add my LDAP user to my project, but the project is in the default domain. Can I do that, or do I need to create a new project, role etc in the LDAP domain? | 19:34 |
*** jamesmcarthur has quit IRC | 19:53 | |
*** xek_ has quit IRC | 20:00 | |
*** andrein has quit IRC | 20:08 | |
*** andrein has joined #openstack-keystone | 20:09 | |
*** xek has joined #openstack-keystone | 20:13 | |
*** vishakha has quit IRC | 20:16 | |
*** david-lyle has quit IRC | 20:25 | |
*** jmlowe has quit IRC | 20:38 | |
*** dklyle has joined #openstack-keystone | 20:39 | |
lbragstad | kmalloc you can limit upper constraints in tox.ini? | 20:46 |
lbragstad | andrein role assignments are not strictly bound to a single domain | 20:47 |
lbragstad | andrein you can have a user in domain A and they can have role assignments on project in domain B or they can have role assignments on domain B itself | 20:47 |
*** xek has quit IRC | 21:07 | |
kmalloc | for bandit | 21:11 |
kmalloc | because it is a linter | 21:11 |
kmalloc | ytou have to | 21:11 |
*** trident has quit IRC | 21:14 | |
lbragstad | hmm | 21:15 |
lbragstad | kmalloc i see where we have lower bounds using test-requirements.txt but i don't see an example of us limiting an upper bound | 21:16 |
kmalloc | we did previously | 21:16 |
lbragstad | i tried digging for an eample | 21:18 |
lbragstad | example* | 21:18 |
lbragstad | nothing jumped out at me | 21:18 |
lbragstad | i know we've done that using setup.cfg | 21:18 |
kmalloc | ah i think it was setup.cfg | 21:19 |
kmalloc | but anyway | 21:19 |
*** trident has joined #openstack-keystone | 21:20 | |
*** markvoelker has quit IRC | 21:21 | |
lbragstad | ok - so start there? | 21:21 |
lbragstad | hmm - we seem to do that with extras | 21:22 |
lbragstad | er - [extras] | 21:22 |
kmalloc | hmm | 21:23 |
kmalloc | yeah i would try that | 21:23 |
lbragstad | interesting... bandit isn't even in https://opendev.org/openstack/requirements/raw/branch/stable/queens/upper-constraints.txt | 21:23 |
lbragstad | i wonder if that's what we need to do | 21:23 |
*** trident has quit IRC | 21:25 | |
*** trident has joined #openstack-keystone | 21:33 | |
andrein | lbragstad, thanks for clearing it up, I tried it and it worked :) I've assigned myself the admin role on the admin project and I can see everything. Except some minor bugs in Horizon, it looks like It works as expected. | 21:34 |
lbragstad | andrein good deal | 21:36 |
kmalloc | i think linters are weird. | 21:41 |
kmalloc | but thats just as far as i recall | 21:41 |
lbragstad | just commented on the patch - but 1.5.1 works for me locally | 21:45 |
lbragstad | the move to bandit 1.6.0 must have included that new token change | 21:45 |
lbragstad | i asked in #openstack-requirements if there is a process around adding that particular library to stable/queens upper-constraints.txt | 21:46 |
kmalloc | yeah 1.6.0 was as far as i know, was one that had issues | 21:54 |
kmalloc | for other reasons | 21:54 |
*** markvoelker has joined #openstack-keystone | 22:05 | |
*** trident has quit IRC | 22:05 | |
*** markvoelker has quit IRC | 22:10 | |
*** trident has joined #openstack-keystone | 22:14 | |
*** ivve has quit IRC | 22:32 | |
*** dklyle has quit IRC | 22:40 | |
*** jmlowe has joined #openstack-keystone | 22:41 | |
lbragstad | kmalloc updated the bandit review on stable/queens - https://review.opendev.org/#/c/678696/1 | 22:45 |
*** rcernin has joined #openstack-keystone | 22:45 | |
*** tkajinam has joined #openstack-keystone | 23:02 | |
*** dave-mccowan has quit IRC | 23:11 | |
kmalloc | lbragstad: +2 waiting on zuul | 23:13 |
kmalloc | then +A | 23:13 |
lbragstad | kmalloc ty sir | 23:19 |
*** dklyle has joined #openstack-keystone | 23:26 | |
openstackgerrit | John Dennis proposed openstack/keystone master: Federation mapping debug should show direct_maps values https://review.opendev.org/678700 | 23:37 |
*** markvoelker has joined #openstack-keystone | 23:41 | |
*** markvoelker has quit IRC | 23:46 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!