*** joehuang has joined #openstack-tricircle | 01:30 | |
shinobu_ | hi joehuang | 01:45 |
---|---|---|
shinobu_ | what do you think of handling credential? | 01:45 |
joehuang | do you mean in Nova/Cinder APIGW | 01:45 |
shinobu_ | from me, we need to be more careful for that as i described | 01:45 |
joehuang | yes | 01:46 |
shinobu_ | joehuang: yes | 01:46 |
joehuang | if the API will be forwarded to the bottom Nova/Cinder | 01:46 |
joehuang | then the token validation and policy control will be done in the bottom OpenStack | 01:46 |
joehuang | and we will also add policy controll on the Nova/Cinder API-GW if necessary | 01:47 |
shinobu_ | joehuang: oh, i'm talking about not token, but password for admin or whatever | 01:47 |
shinobu_ | joehuang: those kind of messages should not be sent with plain text. | 01:48 |
joehuang | maybe we don't need to double controll for all APIs, but some of them will terminate the process in the Nova/Cinder APIGW, for example, quota management, we need policy control | 01:49 |
joehuang | sure | 01:49 |
joehuang | admin and password should not being transfered in plain text | 01:49 |
shinobu_ | joehuang: i just want to make sure there is not mismatch between us. | 01:50 |
shinobu_ | joehuang: thanks for your agreement | 01:50 |
joehuang | how do you manage the password configuration item in production cloud in nova.conf and cinder.conf? | 01:51 |
shinobu_ | is there any situation that password in nova.conf and cinder.conf need to be changed? | 01:53 |
shinobu_ | if end users forget about that, they have to change but. | 01:54 |
joehuang | it's not used for end user | 01:54 |
joehuang | but mainly used by the service for the token validation | 01:54 |
joehuang | for example admin_password in http://docs.openstack.org/liberty/config-reference/content/list-of-compute-config-options.html | 01:55 |
joehuang | in the [keystone_authtoken] section | 01:55 |
shinobu_ | handling configuration file itself, this is a different story to me. | 01:56 |
shinobu_ | do you want the tricircle to modify configuration files as well? | 01:57 |
joehuang | Tricircle will not modify configuration files, other configuration management software will update the configuration file if needed. And Tricircle will only re-load the configuration after the process is re-started. | 02:03 |
shinobu_ | joehuang: that's what i'm expecting. | 02:04 |
joehuang | great | 02:09 |
joehuang | hi, Shinobu, There is update in the function _add_network_segment in Neutron, which will lead to the failure of our check and gate test, and block all new patches to be merged. Please review on the patch https://review.openstack.org/#/c/344524/. Thanks | 02:13 |
shinobu_ | joehuang: checked | 02:38 |
joehuang | thanks | 02:45 |
*** yinxiulin has joined #openstack-tricircle | 02:48 | |
yinxiulin | •Hello,my name's yinxiulin, come from jiangxi,and glad to meet you ! | 02:49 |
joehuang | welcome xiulin, welcome to join tircircle :) | 02:58 |
yinxiulin | thanks | 02:59 |
shinobu_ | yinxiulin: thank you for your *great* contribution in advance. | 03:02 |
*** yinxiulin has quit IRC | 03:04 | |
*** yinxiulin has joined #openstack-tricircle | 03:09 | |
*** gongysh has joined #openstack-tricircle | 03:34 | |
*** gongysh has quit IRC | 03:43 | |
joehuang | hi, xiulin, could you register a bug for the error code 500 returned by Nova/Cinder APIGW, John Garbutt comment on big-tent application "The above shows many "expected" 500 errors, which is something we explicitly call a bug in OpenStack APIs." | 03:56 |
joehuang | https://review.openstack.org/#/c/338796/ | 03:56 |
yinxiulin | OK | 03:57 |
shinobu_ | yinxiulin: are you still there? | 07:36 |
yinxiulin | yes | 07:41 |
shinobu_ | yinxiulin: what's your email address. i'm just asking you | 07:43 |
yinxiulin | yinxiulin@huawei.com | 07:44 |
shinobu_ | thank you | 07:44 |
yinxiulin | welcome | 07:45 |
*** joehuang has quit IRC | 09:50 | |
*** yinxiulin has quit IRC | 09:51 | |
*** gongysh has joined #openstack-tricircle | 09:54 | |
*** gongysh has quit IRC | 11:26 | |
*** longxiongqiu has joined #openstack-tricircle | 12:46 | |
*** longxiongqiu has quit IRC | 13:58 | |
*** gongysh has joined #openstack-tricircle | 14:08 | |
*** gongysh has quit IRC | 15:20 | |
*** gongysh has joined #openstack-tricircle | 16:47 | |
*** gongysh has quit IRC | 19:41 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!