*** yuanying_ has joined #openstack-security | 00:03 | |
*** yuanying has quit IRC | 00:06 | |
*** yuanying_ has quit IRC | 00:07 | |
*** lamt has quit IRC | 00:14 | |
*** nkinder has quit IRC | 00:29 | |
*** diazjf has joined #openstack-security | 00:39 | |
*** bpokorny has quit IRC | 00:59 | |
*** bpokorny has joined #openstack-security | 01:00 | |
*** hongbin has quit IRC | 01:00 | |
*** yuanying has joined #openstack-security | 01:04 | |
*** bpokorny_ has joined #openstack-security | 01:04 | |
*** dave-mccowan has joined #openstack-security | 01:04 | |
*** bpokorny has quit IRC | 01:06 | |
*** jamielennox is now known as jamielennox|away | 01:07 | |
*** Trident has joined #openstack-security | 01:09 | |
*** lamt has joined #openstack-security | 01:11 | |
*** liujiong has joined #openstack-security | 01:21 | |
*** jamielennox|away is now known as jamielennox | 01:21 | |
*** hanchao has joined #openstack-security | 01:24 | |
hanchao | hello guardians, don't know if this is an security issue that I found in openstack. The thing that I found was once an user is nominated as an admin of a project, this user will have full admin access of everything, even out of his/her project. The more horrible thing is that he/she can even remove the real admin of the whole cloud. Are there anything wrong of my use case? Or anyone who can explain me the reason behind i | 01:29 |
---|---|---|
*** bpokorny has joined #openstack-security | 01:56 | |
*** knangia has joined #openstack-security | 01:59 | |
*** bpokorny_ has quit IRC | 01:59 | |
*** bpokorny has quit IRC | 02:01 | |
*** browne has quit IRC | 02:33 | |
*** xin9972 has quit IRC | 02:36 | |
*** yuanying has quit IRC | 02:58 | |
*** diazjf has quit IRC | 03:09 | |
*** browne has joined #openstack-security | 03:21 | |
*** dave-mccowan has quit IRC | 03:25 | |
*** dave-mccowan has joined #openstack-security | 03:28 | |
openstackgerrit | Khanak Nangia proposed openstack/syntribos: Adding new tests for Syntribos in the tests doc https://review.openstack.org/407831 | 03:33 |
openstackgerrit | Khanak Nangia proposed openstack/syntribos: Adding new tests for Syntribos in the tests doc https://review.openstack.org/407831 | 03:36 |
*** browne has quit IRC | 03:37 | |
*** yuanying has joined #openstack-security | 03:43 | |
*** yuanying has quit IRC | 03:48 | |
*** yuanying has joined #openstack-security | 03:49 | |
*** yuanying has quit IRC | 03:53 | |
*** dave-mccowan has quit IRC | 04:06 | |
*** yuanying has joined #openstack-security | 04:40 | |
*** diazjf has joined #openstack-security | 05:04 | |
*** yuanying has quit IRC | 05:13 | |
*** yuanying has joined #openstack-security | 05:13 | |
*** hyakuhei has quit IRC | 05:14 | |
*** Ryan_Lane_ has joined #openstack-security | 05:14 | |
*** fyxim has quit IRC | 05:14 | |
*** DuncanT_ has joined #openstack-security | 05:15 | |
*** DuncanT has quit IRC | 05:15 | |
*** Ryan_Lane has quit IRC | 05:15 | |
*** Ryan_Lane_ is now known as Ryan_Lane | 05:16 | |
*** DuncanT_ is now known as DuncanT | 05:16 | |
*** jamielennox has quit IRC | 05:16 | |
*** fyxim has joined #openstack-security | 05:18 | |
*** jamielennox has joined #openstack-security | 05:31 | |
*** hyakuhei has joined #openstack-security | 05:31 | |
*** knangia has quit IRC | 05:54 | |
*** diazjf has quit IRC | 06:01 | |
*** markvoelker has quit IRC | 06:05 | |
*** markvoelker has joined #openstack-security | 06:05 | |
*** knangia has joined #openstack-security | 06:08 | |
*** markvoelker has quit IRC | 06:10 | |
*** JAHoagie has joined #openstack-security | 06:30 | |
openstackgerrit | Khanak Nangia proposed openstack/syntribos: Fixing nits in the test-anatomy document https://review.openstack.org/407872 | 06:31 |
openstackgerrit | Khanak Nangia proposed openstack/syntribos: Adding new tests for Syntribos in the tests doc https://review.openstack.org/407831 | 06:47 |
*** yuanying has quit IRC | 07:05 | |
*** markvoelker has joined #openstack-security | 07:06 | |
*** markvoelker has quit IRC | 07:10 | |
*** jamielennox is now known as jamielennox|away | 07:11 | |
*** shohel has joined #openstack-security | 07:11 | |
*** yuanying has joined #openstack-security | 07:17 | |
*** rcernin has joined #openstack-security | 07:34 | |
*** pcaruana has joined #openstack-security | 07:41 | |
*** markvoelker has joined #openstack-security | 08:07 | |
*** yuanying has quit IRC | 08:08 | |
*** markvoelker has quit IRC | 08:11 | |
*** zul has quit IRC | 08:18 | |
*** zul has joined #openstack-security | 08:32 | |
*** JAHoagie has quit IRC | 08:52 | |
*** yuanying has joined #openstack-security | 08:59 | |
*** markvoelker has joined #openstack-security | 09:07 | |
*** markvoelker has quit IRC | 09:12 | |
*** shohel has quit IRC | 09:17 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/407981 | 09:53 |
*** markvoelker has joined #openstack-security | 10:08 | |
*** markvoelker has quit IRC | 10:13 | |
*** liujiong has quit IRC | 10:25 | |
*** DuncanT has quit IRC | 10:33 | |
*** DuncanT has joined #openstack-security | 10:33 | |
*** Serlex has joined #openstack-security | 10:38 | |
*** knangia has quit IRC | 11:04 | |
*** openstackgerrit has quit IRC | 11:32 | |
*** shohel has joined #openstack-security | 11:41 | |
*** hyakuhei has quit IRC | 11:51 | |
*** hyakuhei has joined #openstack-security | 11:51 | |
*** hyakuhei has quit IRC | 11:51 | |
*** hyakuhei has joined #openstack-security | 11:51 | |
*** markvoelker has joined #openstack-security | 12:09 | |
*** dave-mccowan has joined #openstack-security | 12:10 | |
*** markvoelker has quit IRC | 12:15 | |
*** edmondsw_ has joined #openstack-security | 12:26 | |
*** edmondsw_ has quit IRC | 12:50 | |
*** lamt has quit IRC | 13:01 | |
*** markvoelker has joined #openstack-security | 13:12 | |
*** markvoelker has quit IRC | 13:16 | |
*** markvoelker has joined #openstack-security | 13:19 | |
*** openstackgerrit has joined #openstack-security | 13:29 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/anchor: Updated from global requirements https://review.openstack.org/380554 | 13:29 |
*** knangia has joined #openstack-security | 13:41 | |
*** lamt has joined #openstack-security | 13:41 | |
*** bnname has joined #openstack-security | 13:48 | |
*** rcernin has quit IRC | 13:49 | |
*** hanchao has quit IRC | 13:50 | |
*** rcernin has joined #openstack-security | 13:51 | |
*** shohel has quit IRC | 13:53 | |
*** shohel has joined #openstack-security | 13:58 | |
*** shohel has quit IRC | 14:02 | |
*** lamt has quit IRC | 14:03 | |
*** lamt has joined #openstack-security | 14:06 | |
*** _elmiko is now known as elmiko | 14:08 | |
*** shohel has joined #openstack-security | 14:17 | |
*** gouthamr has joined #openstack-security | 14:37 | |
*** bnname has left #openstack-security | 14:41 | |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/407981 | 14:51 |
*** nkinder has joined #openstack-security | 14:57 | |
*** bnname has joined #openstack-security | 15:00 | |
*** bnname has quit IRC | 15:00 | |
*** liverpooler has quit IRC | 15:05 | |
*** liverpooler has joined #openstack-security | 15:05 | |
*** hongbin has joined #openstack-security | 15:07 | |
*** JAHoagie has joined #openstack-security | 15:11 | |
*** nkinder has quit IRC | 15:17 | |
*** dave-mccowan has quit IRC | 15:23 | |
*** nkinder has joined #openstack-security | 15:30 | |
*** dave-mccowan has joined #openstack-security | 15:41 | |
*** xin9972 has joined #openstack-security | 15:45 | |
*** JAHoagie has quit IRC | 15:51 | |
*** shohel has quit IRC | 16:03 | |
*** knangia has quit IRC | 16:04 | |
*** bnname has joined #openstack-security | 16:15 | |
*** pcaruana has quit IRC | 16:18 | |
*** rcernin has quit IRC | 16:19 | |
*** bnname has quit IRC | 16:30 | |
*** bpokorny has joined #openstack-security | 16:37 | |
*** bpokorny has quit IRC | 16:38 | |
*** bpokorny has joined #openstack-security | 16:38 | |
unrahul | dotplus: just gave a workflow.. should be merged in a few mins :) | 16:46 |
openstackgerrit | Merged openstack/syntribos: Respect cli args for initialization check https://review.openstack.org/407217 | 16:52 |
dotplus | unrahul: yup, merged. thanks. | 16:55 |
*** diazjf has joined #openstack-security | 16:57 | |
*** browne has joined #openstack-security | 16:58 | |
unrahul | thank you dotplus for the contribution | 17:02 |
*** bpokorny has quit IRC | 17:02 | |
*** bpokorny has joined #openstack-security | 17:02 | |
dotplus | hopefully, there will be more interesting patches later. Would you be interested in an Ansible role? Would that be something reasonable to include in openstack/syntribos directly? or would that be better located elsewhere? | 17:04 |
*** mdong has joined #openstack-security | 17:07 | |
*** bpokorny has quit IRC | 17:07 | |
unrahul | In what way.. dotplus ? | 17:09 |
unrahul | Ansible that is* | 17:09 |
*** bpokorny has joined #openstack-security | 17:10 | |
*** rcernin has joined #openstack-security | 17:11 | |
*** bpokorny_ has joined #openstack-security | 17:14 | |
*** knangia has joined #openstack-security | 17:14 | |
dotplus | I'm writing an Ansible role that deploys syntribos and a playbook for Jenkins to run it against a test cluster as part of our release process (or even as a gate job). | 17:15 |
*** bpokorny has quit IRC | 17:17 | |
openstackgerrit | Khanak Nangia proposed openstack/syntribos: Adding new tests for Syntribos in the tests doc https://review.openstack.org/407831 | 17:31 |
*** dhellmann has quit IRC | 17:33 | |
unrahul | yup that would be very valuable to syntribos dotplus , we see that as a feature that syntribos needs | 17:34 |
unrahul | dotplus: | 17:34 |
*** vds has quit IRC | 17:34 | |
unrahul | mdong: xin9972 vinaypotluri knangia ^ | 17:35 |
*** gouthamr has quit IRC | 17:37 | |
*** gouthamr has joined #openstack-security | 17:38 | |
openstackgerrit | Merged openstack/syntribos: Fixing nits in the test-anatomy document https://review.openstack.org/407872 | 17:40 |
dotplus | unrahul: is there a bug for this yet? | 17:43 |
*** JAHoagie has joined #openstack-security | 17:54 | |
*** diazjf has quit IRC | 17:56 | |
*** bpokorny_ has quit IRC | 17:59 | |
*** bpokorny has joined #openstack-security | 17:59 | |
*** vds has joined #openstack-security | 18:00 | |
*** dhellmann has joined #openstack-security | 18:00 | |
*** bpokorny has quit IRC | 18:04 | |
*** cleong has joined #openstack-security | 18:06 | |
*** vds has quit IRC | 18:11 | |
*** dhellmann has quit IRC | 18:15 | |
unrahul | nop | 18:15 |
unrahul | this would be more of a blueprint rather than a bug | 18:15 |
unrahul | We could start a blueprint if we all feel it's a value add and a new feature, in this case I think it is, at https://blueprints.launchpad.net/syntribos/ | 18:16 |
unrahul | mdong: what do you think about dotplus proposal on Ansible roles and playbook for jenkins for syntribos | 18:17 |
*** Serlex has quit IRC | 18:41 | |
*** austin987 has quit IRC | 18:56 | |
*** bnname has joined #openstack-security | 18:58 | |
*** bnname_ has joined #openstack-security | 19:08 | |
*** bpokorny has joined #openstack-security | 19:10 | |
*** bpokorny has quit IRC | 19:10 | |
*** bpokorny has joined #openstack-security | 19:11 | |
*** bnname has quit IRC | 19:12 | |
*** diazjf has joined #openstack-security | 19:28 | |
*** gouthamr has quit IRC | 19:30 | |
*** gouthamr has joined #openstack-security | 19:33 | |
*** bpokorny has quit IRC | 19:41 | |
*** bpokorny has joined #openstack-security | 19:41 | |
*** bpokorny has quit IRC | 19:45 | |
*** diazjf has quit IRC | 19:48 | |
*** bpokorny has joined #openstack-security | 19:49 | |
*** diazjf has joined #openstack-security | 19:49 | |
*** lamt has quit IRC | 19:49 | |
*** dhellmann_ has joined #openstack-security | 19:52 | |
mdong | sorry unrahul, just saw this. But I completely agree with you, this is great! dotplus, I’d be especially interested in any feedback for features/fixes that we could do to make it as easy as possible to do this | 19:57 |
unrahul | +2 mdong | 19:59 |
*** dhellmann_ is now known as dhellmann | 19:59 | |
*** vds has joined #openstack-security | 20:06 | |
sigmavirus | unrahul: dotplus so you'd run syntribos against an active cluster? | 20:14 |
unrahul | yes sigmavirus | 20:15 |
sigmavirus | I mean I could understand if you wanted to test a set of known things against an active/production cluster, but I'm not sure you want to fuzz one of those and I'm further uncertain you want the ansible role in the repository with the code | 20:16 |
sigmavirus | At the very least, openstack convention is for operations tooling for a project to live elsewhere | 20:16 |
sigmavirus | But I know the syntribos project likes going against the grain and doing its own thing | 20:17 |
unrahul | :) sigmavirus , well we dont intend to go against conventions, the idea to make modificaiton if needed to syntribos to enable it be part of a gate job (in the future) , such as may be an junit type output formatter etc | 20:18 |
sigmavirus | the openstack gate uses subunit, not junit. They're two different things | 20:18 |
sigmavirus | JUnit formatted output would be more useful for folks running Jenkins (like dotplus) and is definitely valuable though | 20:18 |
unrahul | We have just started talking about the the Ansible roles and other things, so I don't think we would be merging something to syntribos that need not be there. | 20:19 |
*** ccneill has joined #openstack-security | 20:31 | |
*** gouthamr has quit IRC | 20:32 | |
dotplus | well, I haven't finished working on the role for $employer yet, let alone cleaned it up, generalized it, etc. to make it suitable for inclusion upstream. So you have a while to think about where/whether you want it:) | 20:35 |
*** bnname_ has quit IRC | 20:45 | |
*** bnname has joined #openstack-security | 20:46 | |
*** lamt has joined #openstack-security | 20:46 | |
*** bpokorny has quit IRC | 20:59 | |
*** bpokorny has joined #openstack-security | 21:00 | |
*** bpokorny has quit IRC | 21:04 | |
openstackgerrit | Khanak Nangia proposed openstack/syntribos: Adding new tests for Syntribos in the tests doc https://review.openstack.org/407831 | 21:12 |
*** cleong has quit IRC | 21:19 | |
*** diazjf has quit IRC | 21:38 | |
*** jamielennox|away is now known as jamielennox | 21:49 | |
*** bpokorny has joined #openstack-security | 21:52 | |
*** singlethink has joined #openstack-security | 21:53 | |
*** diazjf has joined #openstack-security | 21:55 | |
*** bpokorny has quit IRC | 22:06 | |
*** bpokorny has joined #openstack-security | 22:07 | |
*** dave-mccowan has quit IRC | 22:09 | |
*** bpokorny has quit IRC | 22:11 | |
*** diazjf has quit IRC | 22:16 | |
*** diazjf has joined #openstack-security | 22:30 | |
*** rcernin has quit IRC | 22:48 | |
*** ayoung has quit IRC | 22:48 | |
*** lamt has quit IRC | 22:48 | |
*** bpokorny has joined #openstack-security | 22:49 | |
*** browne has quit IRC | 22:53 | |
*** ccneill has quit IRC | 22:54 | |
*** ccneill has joined #openstack-security | 22:58 | |
*** bnname has quit IRC | 23:01 | |
*** nkinder has quit IRC | 23:10 | |
*** diazjf has quit IRC | 23:12 | |
*** bpokorny has quit IRC | 23:16 | |
*** bpokorny has joined #openstack-security | 23:16 | |
*** bpokorny has quit IRC | 23:20 | |
*** bpokorny has joined #openstack-security | 23:20 | |
*** mdong has quit IRC | 23:23 | |
*** bnname has joined #openstack-security | 23:26 | |
*** jamielennox is now known as jamielennox|away | 23:27 | |
*** elmiko is now known as _elmiko | 23:27 | |
*** jamielennox|away is now known as jamielennox | 23:28 | |
*** browne has joined #openstack-security | 23:41 | |
*** ccneill has quit IRC | 23:42 | |
*** bnname has quit IRC | 23:57 | |
*** bnname has joined #openstack-security | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!