*** ducttape_ has quit IRC | 00:11 | |
*** ducttape_ has joined #openstack-meeting-cp | 00:16 | |
*** ducttape_ has quit IRC | 00:26 | |
*** ducttape_ has joined #openstack-meeting-cp | 00:32 | |
*** david-lyle has quit IRC | 00:42 | |
*** diablo_rojo has quit IRC | 00:46 | |
*** david-lyle has joined #openstack-meeting-cp | 01:04 | |
*** Rockyg has quit IRC | 03:12 | |
*** ducttape_ has quit IRC | 03:47 | |
*** gouthamr has quit IRC | 03:49 | |
*** ricolin has joined #openstack-meeting-cp | 03:55 | |
*** ducttape_ has joined #openstack-meeting-cp | 04:12 | |
*** ducttape_ has quit IRC | 04:27 | |
*** ducttape_ has joined #openstack-meeting-cp | 04:28 | |
*** ducttape_ has quit IRC | 04:38 | |
*** ducttape_ has joined #openstack-meeting-cp | 05:39 | |
*** ducttape_ has quit IRC | 05:48 | |
*** cartik has joined #openstack-meeting-cp | 06:12 | |
*** david-lyle_ has joined #openstack-meeting-cp | 07:37 | |
*** alij has joined #openstack-meeting-cp | 07:42 | |
*** ducttape_ has joined #openstack-meeting-cp | 07:45 | |
*** ducttape_ has quit IRC | 07:52 | |
*** alij has quit IRC | 07:52 | |
*** alij has joined #openstack-meeting-cp | 07:52 | |
*** alij has quit IRC | 07:55 | |
*** alij has joined #openstack-meeting-cp | 08:09 | |
*** alij has quit IRC | 08:09 | |
*** david-lyle_ has quit IRC | 08:28 | |
*** alij has joined #openstack-meeting-cp | 08:31 | |
*** stevemar has quit IRC | 08:33 | |
*** stevemar has joined #openstack-meeting-cp | 08:35 | |
*** alij has quit IRC | 08:36 | |
*** ricolin has quit IRC | 09:24 | |
*** ricolin has joined #openstack-meeting-cp | 09:38 | |
*** luzC- has joined #openstack-meeting-cp | 09:42 | |
*** lbragstad_ has joined #openstack-meeting-cp | 09:43 | |
*** topol_ has joined #openstack-meeting-cp | 09:44 | |
*** dolphm_ has joined #openstack-meeting-cp | 09:44 | |
*** dims_ has joined #openstack-meeting-cp | 09:44 | |
*** dansmith_ has joined #openstack-meeting-cp | 09:44 | |
*** dims has quit IRC | 09:45 | |
*** topol has quit IRC | 09:45 | |
*** dansmith has quit IRC | 09:45 | |
*** luzC has quit IRC | 09:45 | |
*** dolphm has quit IRC | 09:45 | |
*** lbragstad has quit IRC | 09:45 | |
*** rosmaita has quit IRC | 09:45 | |
*** dolphm_ is now known as dolphm | 09:45 | |
*** dansmith_ is now known as dansmith | 09:45 | |
*** luzC- is now known as luzC | 09:45 | |
*** rosmaita has joined #openstack-meeting-cp | 09:46 | |
*** dansmith is now known as Guest44492 | 09:46 | |
*** cartik has quit IRC | 09:46 | |
*** ducttape_ has joined #openstack-meeting-cp | 09:48 | |
*** ducttape_ has quit IRC | 09:56 | |
* ricolin test | 10:03 | |
*** alij has joined #openstack-meeting-cp | 10:32 | |
*** alij has quit IRC | 10:32 | |
*** MarkBaker has joined #openstack-meeting-cp | 11:20 | |
*** sdague has joined #openstack-meeting-cp | 11:38 | |
*** ducttape_ has joined #openstack-meeting-cp | 11:47 | |
*** ricolin has quit IRC | 11:54 | |
*** ducttape_ has quit IRC | 12:20 | |
*** david-lyle has quit IRC | 12:24 | |
*** ducttape_ has joined #openstack-meeting-cp | 12:32 | |
*** _ducttape_ has joined #openstack-meeting-cp | 12:34 | |
*** _ducttape_ has quit IRC | 12:36 | |
*** _ducttape_ has joined #openstack-meeting-cp | 12:36 | |
*** ducttape_ has quit IRC | 12:37 | |
*** MarkBaker has quit IRC | 12:39 | |
*** _ducttape_ has quit IRC | 12:51 | |
*** ducttape_ has joined #openstack-meeting-cp | 12:51 | |
*** lbragstad_ is now known as lbragstad | 13:29 | |
*** ducttape_ has quit IRC | 13:31 | |
*** gouthamr has joined #openstack-meeting-cp | 13:34 | |
*** gouthamr has quit IRC | 13:35 | |
*** ricolin has joined #openstack-meeting-cp | 13:36 | |
*** ducttape_ has joined #openstack-meeting-cp | 14:10 | |
*** lamt has joined #openstack-meeting-cp | 14:26 | |
*** Guest44492 is now known as dansmith | 14:28 | |
*** dansmith is now known as Guest94046 | 14:28 | |
*** ducttape_ has quit IRC | 14:31 | |
*** ducttape_ has joined #openstack-meeting-cp | 14:31 | |
*** Guest94046 is now known as dansmith | 14:35 | |
*** _ducttape_ has joined #openstack-meeting-cp | 14:37 | |
*** ducttape_ has quit IRC | 14:38 | |
*** lamt has quit IRC | 15:01 | |
*** lamt has joined #openstack-meeting-cp | 15:12 | |
*** gouthamr has joined #openstack-meeting-cp | 15:23 | |
*** diablo_rojo_phon has joined #openstack-meeting-cp | 15:27 | |
*** gouthamr has quit IRC | 15:30 | |
*** spilla has joined #openstack-meeting-cp | 15:48 | |
*** raj_singh_ has joined #openstack-meeting-cp | 15:48 | |
*** scottda is now known as scottda_phone | 15:56 | |
*** edmondsw has joined #openstack-meeting-cp | 16:00 | |
lbragstad | #startmeeting policy | 16:00 |
---|---|---|
openstack | Meeting started Wed Feb 8 16:00:47 2017 UTC and is due to finish in 60 minutes. The chair is lbragstad. Information about MeetBot at http://wiki.debian.org/MeetBot. | 16:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 16:00 |
*** openstack changes topic to " (Meeting topic: policy)" | 16:00 | |
openstack | The meeting name has been set to 'policy' | 16:00 |
*** ruan_20 has joined #openstack-meeting-cp | 16:00 | |
lbragstad | ping raildo, ktychkova, dolphm, dstanek, rderose, htruta, atrmr, gagehugo, lamt, thinrichs, edmondsw, ruan, ayoung, stevemar, ravelar, morgan, raj_singh | 16:01 |
lbragstad | agenda #link https://etherpad.openstack.org/p/keystone-policy-meeting | 16:01 |
*** gagehugo has joined #openstack-meeting-cp | 16:01 | |
dstanek | howdy | 16:02 |
lbragstad | not sure if johnthetubaguy is around? | 16:02 |
lamt | o/ | 16:02 |
lbragstad | dstanek gagehugo edmondsw o/ | 16:02 |
rderose | o/ | 16:02 |
lbragstad | lamt o/ | 16:02 |
gagehugo | o/ | 16:02 |
edmondsw | o/ | 16:03 |
ruan_20 | o/ | 16:03 |
lbragstad | we'll give folks another minute to join before we get started | 16:03 |
lbragstad | agenda #link https://etherpad.openstack.org/p/keystone-policy-meeting for those who need it | 16:04 |
*** Rockyg has joined #openstack-meeting-cp | 16:04 | |
lbragstad | #topic Nova's policy goals for Pike | 16:05 |
*** openstack changes topic to "Nova's policy goals for Pike (Meeting topic: policy)" | 16:05 | |
lbragstad | we don't have much for announcements - so we can jump right in | 16:05 |
lbragstad | johnthetubaguy proposed a set of goals nova wants to accomplish for Pike | 16:05 |
lbragstad | #link https://review.openstack.org/#/c/427872/ | 16:06 |
johnthetubaguy | we have a talk at the nova-api meeting today about things, we may be shifting focus a bit after that | 16:06 |
johnthetubaguy | but its stuff we are actively discussing right now | 16:06 |
lbragstad | johnthetubaguy this one? #link http://eavesdrop.openstack.org/#Nova_API_Meeting | 16:07 |
johnthetubaguy | yeah | 16:07 |
lbragstad | johnthetubaguy awesome - i'll see if I can swing by | 16:08 |
*** ravelar has joined #openstack-meeting-cp | 16:08 | |
lbragstad | that spec has a lot of relevance with this meeting - so feel free to review it | 16:08 |
lbragstad | I'm attempting to keep tabs on it - but i assume it will make for some good discussion at the PTG | 16:09 |
lbragstad | which moves into our next topic | 16:09 |
lbragstad | #topic Keystone specs for richer policy | 16:09 |
*** openstack changes topic to "Keystone specs for richer policy (Meeting topic: policy)" | 16:09 | |
johnthetubaguy | so I could cover quickly the discussion if that helps | 16:10 |
lbragstad | after seeing the work johnthetubaguy did for nova - i took a stab at doing the same for keystone #link https://review.openstack.org/#/q/status:open+project:openstack/keystone-specs+branch:master+topic:bp/richer-policy | 16:10 |
johnthetubaguy | sorry half in a stand up that was running long | 16:10 |
johnthetubaguy | ah, cool | 16:10 |
lbragstad | johnthetubaguy go for it | 16:10 |
johnthetubaguy | so we are thinking we should focus on the docs | 16:10 |
*** jaugustine has joined #openstack-meeting-cp | 16:10 | |
lbragstad | johnthetubaguy new docs or existing ones? | 16:11 |
johnthetubaguy | so using olso.polcy | 16:11 |
johnthetubaguy | let me get a link | 16:11 |
johnthetubaguy | #link http://docs.openstack.org/developer/nova/sample_policy.html | 16:12 |
johnthetubaguy | this is what nova today generates from the code | 16:12 |
lbragstad | johnthetubaguy nice | 16:12 |
*** antwash has joined #openstack-meeting-cp | 16:12 | |
*** scottda_phone is now known as scottda | 16:12 | |
johnthetubaguy | so there is one doc comment in there alreday | 16:13 |
lbragstad | johnthetubaguy are the docs going to describe what each operation does? | 16:13 |
johnthetubaguy | is terrible, but we have a route forward there | 16:13 |
johnthetubaguy | so there is a nice way to think about this | 16:13 |
johnthetubaguy | operators should be able to read this sample policy file, and no longer have to read the code | 16:13 |
*** raj_singh_ has quit IRC | 16:14 | |
johnthetubaguy | if thats true, we did it right | 16:14 |
lbragstad | johnthetubaguy so exactly like configu | 16:14 |
johnthetubaguy | thats what we are doing for the configuration | 16:14 |
johnthetubaguy | yeah | 16:14 |
lbragstad | configuration* | 16:14 |
johnthetubaguy | if you search for os_compute_api:os-attach-interfaces:create | 16:14 |
johnthetubaguy | it has a quick note | 16:14 |
johnthetubaguy | its almost good enough actually, and its just a one liner | 16:14 |
*** stvnoyes has quit IRC | 16:14 | |
lbragstad | so - would it look like? #link https://github.com/openstack/keystone/blob/029476272fb869c6413aa4e70f4cae6f890e598f/keystone/conf/auth.py#L22-L28 | 16:15 |
*** stvnoyes has joined #openstack-meeting-cp | 16:15 | |
johnthetubaguy | so in the code we have this | 16:15 |
johnthetubaguy | https://github.com/openstack/nova/blob/4f91ed3a547965ed96a22520edcfb783e7936e95/nova/policies/attach_interfaces.py#L25 | 16:15 |
johnthetubaguy | so yeah, basically the same | 16:15 |
johnthetubaguy | right now all our rules have to be registered, and you get the chance to specify the docs | 16:15 |
lbragstad | ah - so the RuleDefault as a description attribute | 16:16 |
johnthetubaguy | yeah | 16:16 |
johnthetubaguy | the other side of this: | 16:16 |
johnthetubaguy | https://github.com/openstack/nova/blob/master/tox.ini#L91 | 16:16 |
johnthetubaguy | its basically just like config | 16:16 |
lbragstad | aha | 16:17 |
lbragstad | when did the RuleDefault object get a description attribute? | 16:17 |
johnthetubaguy | there is the upgrade conversation if we want to do renames, but basically I am thinking in pike we might focus on just getting some docs in there | 16:17 |
johnthetubaguy | lbragstad: not sure actually | 16:17 |
lbragstad | i swear i checked for that last week | 16:17 |
johnthetubaguy | https://github.com/openstack/oslo.policy/blob/9e3d46b1707152094cc2c2bdd45e22898d79140c/oslo_policy/policy.py#L791 | 16:18 |
* johnthetubaguy shrugs | 16:18 | |
johnthetubaguy | seems like it got added with rule default | 16:19 |
lbragstad | huh - cool | 16:19 |
johnthetubaguy | that was always our intention at least | 16:19 |
johnthetubaguy | https://github.com/openstack/oslo.policy/commit/bb1127232695c07eb8e3622714b7de7cf7219ccc | 16:19 |
johnthetubaguy | auto gen docs that match the config | 16:19 |
lbragstad | so the auto generation already pulls the description | 16:19 |
johnthetubaguy | yep | 16:19 |
lbragstad | it looks like | 16:19 |
lbragstad | that's aweesome | 16:19 |
lbragstad | that is essentially the next topic i had on the agenda | 16:20 |
johnthetubaguy | so yeah, for pike, we plan to fill that in | 16:20 |
dstanek | johnthetubaguy: i like this idea | 16:20 |
edmondsw | so just docs... any thought being given to the code changes that need to happen, like https://review.openstack.org/#/c/384148/ | 16:20 |
dstanek | johnthetubaguy: you don't do anything dynamic with the rules through right? like at import time change the stuff that is in the list (besides the % operator stuff)? | 16:21 |
edmondsw | and one of the things I find most confusing in nova is that scope is restricted to the current project via code in some places (like it should be) but in other places you have to worry about scope in the policy file | 16:21 |
edmondsw | good luck making that clear in docs... | 16:21 |
johnthetubaguy | so right now, I have put about 1 billion things on the table to consider, I need to trim that down into some stages | 16:21 |
edmondsw | it needs to be fixed in code | 16:21 |
johnthetubaguy | dstanek: dynamic? why would you want that? | 16:21 |
johnthetubaguy | edmondsw: yeah, thats on the "to fix" list, admin vs non admin used to be hardcoded to, but we have carefully removed that now, baby steps | 16:22 |
edmondsw | cool | 16:22 |
dstanek | johnthetubaguy: i wouldn't :-) | 16:22 |
dstanek | johnthetubaguy: i was just wondering if you guys did that | 16:22 |
johnthetubaguy | dstanek: heh, no worries | 16:22 |
johnthetubaguy | dstanek: I don't see any use case for it, most folks want to audit policy, dynamic seems to fight that somewhat | 16:22 |
lbragstad | johnthetubaguy the registration steps is what determines if you're going to use the default or a policy defined in an existing policy.json/yml file somewhere, right? | 16:23 |
johnthetubaguy | the registration step is the default | 16:23 |
johnthetubaguy | we don't have any policy file in tree any more | 16:23 |
lbragstad | aha | 16:23 |
johnthetubaguy | by default Nova works with no policy file being present on the disk | 16:23 |
*** david-lyle has joined #openstack-meeting-cp | 16:23 | |
edmondsw | johnthetubaguy, I would love to be involved in helping you fix the project scope check issue when you can get to it | 16:23 |
dstanek | johnthetubaguy: yeah, i agree. i was thinking that someone will eventually want to change policy based on config, or something else | 16:23 |
dstanek | then it's hard to know what is happening | 16:23 |
johnthetubaguy | edmondsw: cool, more hands on there could really help | 16:24 |
johnthetubaguy | dstanek: now available capabilities of the system is a different thing, policy always stays static for me, like you say | 16:24 |
lbragstad | johnthetubaguy so far nova is the only project to put policy into code, right? | 16:24 |
johnthetubaguy | lbragstad: AFAIK, yes | 16:24 |
edmondsw | cinder has a spec for it, but didn't make ocata | 16:25 |
lbragstad | so for keystone - that'd be our first step #link https://review.openstack.org/#/c/428453/ | 16:25 |
johnthetubaguy | so there is some fun tooling that helps you merge a file with the defaults in the code, and to help find what duplicates you have in your file, to help with upgrades | 16:25 |
edmondsw | lbragstad +1 | 16:25 |
johnthetubaguy | haven't had feedback on if that works for people yet, but its what they asked for | 16:25 |
smcginnis | Really no progress on that on the Cinder side for now. | 16:26 |
lbragstad | we might be able to coordinate parallel efforts to fill in descriptions as we do that? | 16:26 |
dstanek | lbragstad: this should be pretty easy to get in right? you haven't heard of any pushback have you? | 16:26 |
lbragstad | dstanek no real pushback yet - but i'm continuing to advertise it | 16:26 |
lbragstad | and still looking for feedback and people to help out with the effort | 16:27 |
lbragstad | (the sooner we do that the sooner we'll be on the same page as nova/other projects) | 16:27 |
lbragstad | which would make doing what johnthetubaguy wants easier | 16:27 |
dstanek | lbragstad: let push in it before the haters have a chance to see it :-D | 16:27 |
lbragstad | dstanek :) | 16:27 |
johnthetubaguy | so there are some interesting thoughts earlier on turning the policy file upside down | 16:28 |
lbragstad | "nothing to see here, move along citizen, move along" | 16:28 |
lbragstad | johnthetubaguy how so? | 16:28 |
johnthetubaguy | right now we say { p1: admin_or_owner, p2: admin, p3:admin ...} | 16:28 |
johnthetubaguy | as in define who can do each rule | 16:28 |
johnthetubaguy | but as an operator really you want to see | 16:29 |
johnthetubaguy | { owner_can_do: [p1], admin_can_do: [p2, p3] } | 16:29 |
johnthetubaguy | or something like that | 16:29 |
edmondsw | +1 | 16:29 |
lamt | +1 | 16:29 |
lbragstad | ++ | 16:29 |
edmondsw | that was popular quickly :) | 16:29 |
lbragstad | i imagine that would play into capability APIs nicely | 16:30 |
johnthetubaguy | so its totally sdague who brought that up, it seems to make sense | 16:30 |
lbragstad | nova and cinder both have specs for capability APIs | 16:30 |
johnthetubaguy | now that pivot might make sense before we add lots of roles | 16:30 |
sdague | I think the more important thing, is this could be new stanzas in the policy | 16:31 |
sdague | which wouldn't conflict with existing ones | 16:31 |
sdague | so there is a smooth transition across as it's additive | 16:31 |
lbragstad | sdague ++ | 16:31 |
edmondsw | how would they not conflict? | 16:31 |
johnthetubaguy | they take preference, and it looks different to the old cruft | 16:32 |
johnthetubaguy | interesting | 16:32 |
lbragstad | you would have to define both to be consistent, but then tell the enforcement point which one to use? | 16:32 |
johnthetubaguy | I would say the new one wins, or you just fail to start if it conflicts | 16:32 |
johnthetubaguy | but it means the old one still works | 16:33 |
lbragstad | right | 16:33 |
johnthetubaguy | and the new one would work | 16:33 |
johnthetubaguy | which is more important | 16:33 |
lbragstad | so - that would be an alternative to the richer policy roles? | 16:33 |
edmondsw | so it's not the old way OR checks from the new way? | 16:34 |
lbragstad | or a prerequisite? | 16:34 |
johnthetubaguy | a way of making the richer policy defaults easier to deal with maybe? | 16:34 |
johnthetubaguy | I quite like it as a prerequisite myself, the more I think about it | 16:34 |
edmondsw | I assume the new way still lets you do things besides just check role... e.g. operator can do p1 if xyz | 16:34 |
lbragstad | put policy into code -> redefine policy by role instead of operation -> introduce more granular roles ? | 16:35 |
johnthetubaguy | for the record, there is loads to go through here, which is why I think I want to focus on getting the docs started :) | 16:35 |
lbragstad | johnthetubaguy yeah - i would think that'd be something we'd have to do regardless | 16:35 |
johnthetubaguy | lbragstad: I nova I we have some other de-cruft-i-fy bits that edmondsw hinted at earlier, but yeah, something like that | 16:35 |
johnthetubaguy | lbragstad: totally | 16:35 |
johnthetubaguy | hmm, typing failed me there | 16:36 |
johnthetubaguy | insert some grammar bits as you see fit | 16:36 |
lbragstad | i was able to parse it :) | 16:36 |
lbragstad | so - does anyone see any red flags with the policy in code + documentation around the current operations? | 16:37 |
edmondsw | these new stanzas being organized by role is pretty much the opposite of the approach ayoung was pushing to pull role checks out to middleware | 16:37 |
edmondsw | you wouldn't do both | 16:38 |
johnthetubaguy | so we would never be able to have all policy checks in middleware, unless it implemented most of our API for us | 16:39 |
johnthetubaguy | now it would bring consistency, but the APIs already existing, and they aren't consistent enough | 16:39 |
edmondsw | yeah, that wasn't the proposal... just to do role checks, not the rest | 16:39 |
edmondsw | I think I like this better, at first glance | 16:39 |
johnthetubaguy | having said that, maybe we want a "can access nova API" role check for all requests, that could be a thing I see people liking | 16:39 |
edmondsw | this = sdague's proposal | 16:39 |
johnthetubaguy | so we can still have standards to help with names etc | 16:40 |
johnthetubaguy | but in reality we still need a list of all the rules, with documentation, else no one will have a clue whats going on | 16:40 |
sdague | edmondsw: don't consider this as formal as a proposal at this point, it is an observation of the way that admins think about and want to interact with our stuff | 16:40 |
lbragstad | johnthetubaguy ++ | 16:41 |
lbragstad | johnthetubaguy that should only make "standardizing" a set of roles easier | 16:41 |
johnthetubaguy | they are solving a different set of problems of course, some of this is agreeing on the most important problems to solve | 16:41 |
sdague | also, having fought over all the complexity of roles for even the most basic things today in working through issues to cut the stable/ocata branch, I am skeptical the current course and speed on roles is helping operators | 16:42 |
edmondsw | sdague i.e., someone else should drive that if they think it's a good idea? :) | 16:42 |
edmondsw | sdague can you elaborate on that last comment a bit more? | 16:42 |
sdague | edmondsw: https://bugs.launchpad.net/keystone/+bug/1662911 | 16:43 |
openstack | Launchpad bug 1662911 in OpenStack Identity (keystone) "v3 API create_user does not use default_project_id" [Undecided,New] | 16:43 |
sdague | anyway, this is probably going to divert from the core discussion here | 16:43 |
sdague | I think the important thing on policy is to remember that it is an interface for operators for them to clearly express their intent of how they expect the system to work | 16:44 |
johnthetubaguy | sdague: ++ | 16:44 |
sdague | and if that expression doesn't align with the way people think about it, they will introduce bugs and security issues | 16:44 |
johnthetubaguy | something tells me we need less granular rules for many things | 16:45 |
johnthetubaguy | an operator cares about reading servers for a project, not listing, getting, filter, etc | 16:45 |
lbragstad | johnthetubaguy less granular than what we have today? | 16:46 |
sdague | johnthetubaguy: right, though that's a project artifact | 16:46 |
johnthetubaguy | maybe grouped or hierarchical | 16:46 |
lbragstad | ah - so grouping similar operations | 16:46 |
johnthetubaguy | the other thing is we let people basically make the API non-interoperable today, which also feels bad (and I don't just mean fix it with API discoverability) | 16:46 |
johnthetubaguy | s/API/capability/ | 16:46 |
sdague | johnthetubaguy: yeh, one thing at a time | 16:47 |
johnthetubaguy | yeah, sorry, as you see, I keep getting carried away | 16:47 |
lbragstad | i think this is good - because it helps us figure out what the big picture should be | 16:47 |
johnthetubaguy | the doc would should help us better understand what we have today, and should help operators come back with more interesting questions | 16:47 |
sdague | because I think the biggest concrete concern today is the system is confusing enough that it is really easy to have a giant security hole and not realize it | 16:47 |
johnthetubaguy | sdague: +1000 | 16:48 |
lbragstad | sdague ++ | 16:48 |
johnthetubaguy | "oh that rule means any user can destroy my cloud now, whoops" | 16:48 |
lbragstad | so - it still sounds like in order to do any of this we will need in-code policy | 16:49 |
johnthetubaguy | I think so | 16:49 |
lbragstad | or in-code policy will make it much easier | 16:49 |
johnthetubaguy | yeah, that | 16:49 |
lbragstad | does anyone disagree with that assessment? | 16:50 |
*** ricolin has quit IRC | 16:50 | |
edmondsw | johnthetubaguy, I think we need to allow folks to customize listing, getting, etc individually... but I would love to see sensible defaults that use common rules... e.g. "os_compute_api:servers:show": "os_compute_api:servers:list" so if you want to change both you only have to change the list one | 16:51 |
* johnthetubaguy is hoping thats the silence of agreement | 16:51 | |
edmondsw | or a new rule that both show and list point to by default, and you change that to change them both | 16:51 |
johnthetubaguy | yeah, I am really meaning about adding a new rule as a default, at least at first | 16:52 |
johnthetubaguy | having said that, I don't really get the use case for different rules for each of those | 16:52 |
*** david-lyle has quit IRC | 16:52 | |
edmondsw | 99.8% of the time they're the same, but I do have cases where I've customized them differently | 16:53 |
lbragstad | edmondsw can you share the 0.2%? | 16:53 |
johnthetubaguy | but was the 0.2% a real deal break, or just because you could? | 16:53 |
edmondsw | I'll have to go find them... | 16:53 |
edmondsw | I think they were pretty important | 16:53 |
johnthetubaguy | edmondsw: would be great to get data on that | 16:54 |
johnthetubaguy | now if enable list would create a ddos, thats probably a slightly different case | 16:54 |
lbragstad | FYI - we're at the 5 minute mark | 16:55 |
lbragstad | edmondsw would you be interesting in bringing those use cases to the meeting next week? | 16:58 |
edmondsw | I will try to run them down | 16:58 |
lbragstad | edmondsw cool | 16:58 |
lbragstad | does anyone have any last minute things? | 16:58 |
lbragstad | johnthetubaguy sdague thanks for sharing | 16:59 |
johnthetubaguy | thanks, was a good discussion | 16:59 |
lbragstad | do we want to propose the upside-down-policy thing? | 17:00 |
lbragstad | in a spec or something like that? | 17:00 |
lbragstad | either way - i can look into that. thanks for coming everyone! | 17:01 |
lbragstad | #endmeeting | 17:01 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings" | 17:01 | |
johnthetubaguy | I don't have the bandwidth right now I am afraid | 17:01 |
openstack | Meeting ended Wed Feb 8 17:01:16 2017 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 17:01 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/policy/2017/policy.2017-02-08-16.00.html | 17:01 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/policy/2017/policy.2017-02-08-16.00.txt | 17:01 |
openstack | Log: http://eavesdrop.openstack.org/meetings/policy/2017/policy.2017-02-08-16.00.log.html | 17:01 |
*** ravelar has left #openstack-meeting-cp | 17:04 | |
*** gagehugo has left #openstack-meeting-cp | 17:09 | |
*** david-lyle has joined #openstack-meeting-cp | 17:12 | |
*** _ducttape_ has quit IRC | 17:19 | |
*** ducttape_ has joined #openstack-meeting-cp | 17:20 | |
*** breitz has left #openstack-meeting-cp | 17:28 | |
*** topol_ is now known as topol | 17:33 | |
*** gouthamr has joined #openstack-meeting-cp | 17:45 | |
*** gouthamr has quit IRC | 17:50 | |
*** diablo_rojo has joined #openstack-meeting-cp | 17:55 | |
*** robcresswell has quit IRC | 18:35 | |
*** soren has quit IRC | 18:35 | |
*** nikhil has quit IRC | 18:35 | |
*** patrickeast has quit IRC | 18:37 | |
*** ediardo has quit IRC | 18:37 | |
*** DuncanT has quit IRC | 18:37 | |
*** igormarnat_ has quit IRC | 18:37 | |
*** asingh_ has quit IRC | 18:37 | |
*** ildikov has quit IRC | 18:37 | |
*** ducttape_ has quit IRC | 18:39 | |
*** spilla has left #openstack-meeting-cp | 18:44 | |
*** morgan has quit IRC | 18:45 | |
*** scottda has quit IRC | 18:45 | |
*** sballe_ has quit IRC | 18:45 | |
*** TheJulia has quit IRC | 18:45 | |
*** ameade has quit IRC | 18:45 | |
*** antwash has left #openstack-meeting-cp | 18:45 | |
*** DuncanT has joined #openstack-meeting-cp | 19:31 | |
*** ameade has joined #openstack-meeting-cp | 19:32 | |
*** DuncanT has quit IRC | 19:35 | |
*** sballe_ has joined #openstack-meeting-cp | 19:37 | |
*** ducttape_ has joined #openstack-meeting-cp | 19:40 | |
*** scottda has joined #openstack-meeting-cp | 19:44 | |
*** soren has joined #openstack-meeting-cp | 19:48 | |
*** DuncanT has joined #openstack-meeting-cp | 19:51 | |
*** robcresswell has joined #openstack-meeting-cp | 19:55 | |
*** david-lyle has quit IRC | 19:57 | |
*** ildikov_ has joined #openstack-meeting-cp | 20:01 | |
*** ildikov_ is now known as ildikov | 20:01 | |
*** nikhil has joined #openstack-meeting-cp | 20:03 | |
*** ducttape_ has quit IRC | 20:04 | |
*** ducttape_ has joined #openstack-meeting-cp | 20:05 | |
*** TheJulia has joined #openstack-meeting-cp | 20:05 | |
*** patrickeast has joined #openstack-meeting-cp | 20:05 | |
*** edtubill has joined #openstack-meeting-cp | 20:05 | |
*** edtubill has left #openstack-meeting-cp | 20:06 | |
*** morgan has joined #openstack-meeting-cp | 20:12 | |
*** ediardo has joined #openstack-meeting-cp | 20:12 | |
*** igormarnat_ has joined #openstack-meeting-cp | 20:13 | |
*** david-lyle has joined #openstack-meeting-cp | 20:15 | |
*** asingh_ has joined #openstack-meeting-cp | 20:16 | |
*** david-lyle has quit IRC | 20:20 | |
*** MarkBaker has joined #openstack-meeting-cp | 20:39 | |
*** MarkBaker has quit IRC | 20:46 | |
*** ducttape_ has quit IRC | 20:47 | |
*** ducttape_ has joined #openstack-meeting-cp | 21:27 | |
*** jaugustine has quit IRC | 22:13 | |
*** gouthamr has joined #openstack-meeting-cp | 22:20 | |
*** MarkBaker has joined #openstack-meeting-cp | 22:24 | |
*** edmondsw has quit IRC | 22:41 | |
*** edtubill has joined #openstack-meeting-cp | 22:54 | |
*** edtubill has quit IRC | 23:05 | |
*** ducttape_ has quit IRC | 23:48 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!