*** luksky has quit IRC | 00:09 | |
*** tosky has quit IRC | 00:17 | |
*** jamesdenton has quit IRC | 00:57 | |
*** jamesdenton has joined #openstack-ansible | 00:59 | |
*** gshippey has quit IRC | 01:07 | |
*** rh-jlabarre has joined #openstack-ansible | 01:55 | |
*** rh-jlabarre has quit IRC | 01:55 | |
*** rh-jlabarre has joined #openstack-ansible | 01:56 | |
*** rh-jelabarre has quit IRC | 01:56 | |
*** evrardjp has quit IRC | 02:33 | |
*** evrardjp has joined #openstack-ansible | 02:33 | |
*** lkoranda has joined #openstack-ansible | 04:07 | |
*** rohit02 has joined #openstack-ansible | 04:16 | |
*** rh-jlabarre has quit IRC | 04:20 | |
*** miloa has joined #openstack-ansible | 05:22 | |
*** miloa has quit IRC | 05:25 | |
*** yasemind has joined #openstack-ansible | 05:57 | |
*** jbadiapa has joined #openstack-ansible | 06:25 | |
*** pcaruana has joined #openstack-ansible | 06:57 | |
*** rpittau|afk is now known as rpittau | 07:03 | |
*** rohit02 has quit IRC | 07:06 | |
*** luksky has joined #openstack-ansible | 07:07 | |
*** rohit02 has joined #openstack-ansible | 07:07 | |
*** andrewbonney has joined #openstack-ansible | 07:14 | |
*** shyamb has joined #openstack-ansible | 07:27 | |
*** shyam89 has joined #openstack-ansible | 07:27 | |
*** tosky has joined #openstack-ansible | 07:37 | |
*** shyam89 has quit IRC | 07:50 | |
*** shyamb has quit IRC | 07:50 | |
*** shyamb has joined #openstack-ansible | 07:51 | |
*** shyam89 has joined #openstack-ansible | 07:51 | |
*** lkoranda has quit IRC | 07:52 | |
*** lkoranda has joined #openstack-ansible | 07:55 | |
*** lkoranda has quit IRC | 07:57 | |
*** MrClayPole has quit IRC | 08:30 | |
*** MrClayPole has joined #openstack-ansible | 08:37 | |
*** SiavashSardari has joined #openstack-ansible | 08:44 | |
*** shyamb has quit IRC | 09:04 | |
*** shyam89 has quit IRC | 09:04 | |
*** shyam89 has joined #openstack-ansible | 09:04 | |
*** shyamb has joined #openstack-ansible | 09:04 | |
*** shyamb has quit IRC | 09:06 | |
*** shyam89 has quit IRC | 09:06 | |
*** shyamb has joined #openstack-ansible | 09:07 | |
*** shyam89 has joined #openstack-ansible | 09:07 | |
*** rohit02 has quit IRC | 09:20 | |
*** rohit02 has joined #openstack-ansible | 09:21 | |
*** rpittau is now known as rpittau|bbl | 09:23 | |
*** macz_ has joined #openstack-ansible | 09:27 | |
*** macz_ has quit IRC | 09:32 | |
*** macz_ has joined #openstack-ansible | 09:48 | |
*** macz_ has quit IRC | 09:52 | |
*** shyamb has quit IRC | 09:59 | |
*** shyam89 has quit IRC | 09:59 | |
openstackgerrit | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_trove master: Update trove configuration https://review.opendev.org/c/openstack/openstack-ansible-os_trove/+/784571 | 10:10 |
---|---|---|
noonedeadpunk | I think now at least we don't need mysql libs on the deploy host - only for adjutant containers? | 10:20 |
jonher | that's what i figured, i don't think it needs to be built with the mysql libs present, but i'm not sure on all this wheel stuff | 10:21 |
*** SiavashSardari has quit IRC | 10:34 | |
*** yasemind has quit IRC | 10:41 | |
*** shyamb has joined #openstack-ansible | 10:49 | |
*** shyam89 has joined #openstack-ansible | 10:49 | |
*** mgariepy has quit IRC | 11:06 | |
noonedeadpunk | Created a pool regarding meeting https://doodle.com/poll/m554dx4mrsideuzi/ | 11:19 |
*** dpawlik4 has joined #openstack-ansible | 11:40 | |
*** dpawlik4 is now known as dpawlik | 11:42 | |
*** shyam89 has quit IRC | 11:58 | |
*** shyamb has quit IRC | 11:58 | |
andrewbonney | noonedeadpunk: is there a typo? That link doesn't seem to work for me | 12:04 |
noonedeadpunk | andrewbonney: doh, extra slash at the end :( | 12:08 |
noonedeadpunk | https://doodle.com/poll/m554dx4mrsideuzi | 12:08 |
andrewbonney | Ah, simple, thanks | 12:09 |
noonedeadpunk | and I mailed it ;( | 12:09 |
*** macz_ has joined #openstack-ansible | 12:10 | |
*** macz_ has quit IRC | 12:14 | |
*** mgariepy has joined #openstack-ansible | 12:14 | |
noonedeadpunk | If you want me to add some extra fields in the poll - let me know | 12:15 |
*** rh-jlabarre has joined #openstack-ansible | 12:28 | |
*** jamesdenton has quit IRC | 12:38 | |
*** jamesdenton has joined #openstack-ansible | 12:39 | |
*** rpittau|bbl is now known as rpittau | 12:51 | |
openstackgerrit | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_trove master: [doc] Document how to use separate RabbitMQ cluster https://review.opendev.org/c/openstack/openstack-ansible-os_trove/+/784781 | 12:52 |
openstackgerrit | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_trove master: [doc] Document how to use separate RabbitMQ cluster https://review.opendev.org/c/openstack/openstack-ansible-os_trove/+/784781 | 12:53 |
openstackgerrit | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_trove master: [doc] Document how to use separate RabbitMQ cluster https://review.opendev.org/c/openstack/openstack-ansible-os_trove/+/784781 | 12:58 |
*** spatel_ has joined #openstack-ansible | 13:03 | |
*** spatel_ is now known as spatel | 13:03 | |
openstackgerrit | Amy Marrich (spotz) proposed openstack/openstack-ansible-os_trove master: [doc] Document how to use separate RabbitMQ cluster https://review.opendev.org/c/openstack/openstack-ansible-os_trove/+/784781 | 13:25 |
*** rohit02 has quit IRC | 13:45 | |
*** chkumar|ruck is now known as raukadah | 13:52 | |
*** fanfi has quit IRC | 13:56 | |
*** rohit02 has joined #openstack-ansible | 14:09 | |
*** rohit02 has quit IRC | 14:16 | |
*** pabelanger has joined #openstack-ansible | 14:31 | |
pabelanger | o/ | 14:31 |
pabelanger | which channel is doing openstack ansible collection these days? | 14:31 |
pabelanger | sshnaidm: ^ | 14:32 |
sshnaidm | pabelanger, openstack-ansible-sig | 14:34 |
pabelanger | tyty | 14:34 |
*** pabelanger has left #openstack-ansible | 14:34 | |
*** gshippey has joined #openstack-ansible | 14:36 | |
openstackgerrit | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_trove master: Update trove configuration https://review.opendev.org/c/openstack/openstack-ansible-os_trove/+/784571 | 14:49 |
*** macz_ has joined #openstack-ansible | 15:09 | |
*** mgariepy has quit IRC | 15:09 | |
*** macz_ has quit IRC | 15:10 | |
*** macz_ has joined #openstack-ansible | 15:11 | |
*** macz_ has quit IRC | 15:12 | |
*** macz_ has joined #openstack-ansible | 15:13 | |
*** andrewbonney has quit IRC | 15:22 | |
*** hindret has quit IRC | 15:23 | |
*** hindret has joined #openstack-ansible | 15:24 | |
*** andrewbonney has joined #openstack-ansible | 15:24 | |
*** mgariepy has joined #openstack-ansible | 15:29 | |
openstackgerrit | Dmitriy Rabotyagov proposed openstack/openstack-ansible-tests master: Run notify setup when setup_host differs https://review.opendev.org/c/openstack/openstack-ansible-tests/+/785224 | 15:33 |
openstackgerrit | Dmitriy Rabotyagov proposed openstack/openstack-ansible-os_trove master: [doc] Document how to use separate RabbitMQ cluster https://review.opendev.org/c/openstack/openstack-ansible-os_trove/+/784781 | 15:42 |
*** macz_ has quit IRC | 15:45 | |
*** macz_ has joined #openstack-ansible | 15:46 | |
*** sshnaidm is now known as sshnaidm|afk | 16:06 | |
jrosser | noonedeadpunk: have you any experience with making 'reader' role accounts for audit or report generating type purposes? | 16:12 |
noonedeadpunk | jrosser: did just for some services | 16:12 |
noonedeadpunk | But it really means overriding _lot_ of policies | 16:13 |
noonedeadpunk | I wish openstaxck had smth out of the box... | 16:13 |
jrosser | theres a reader role as standard, but it seems quite wierd how that it set up | 16:15 |
noonedeadpunk | rly? I never saw that achieved anywhere (maybe except of the keystone) | 16:17 |
noonedeadpunk | *implemented | 16:17 |
jrosser | oh right well thats probably the super important thing i'm missing :) | 16:17 |
noonedeadpunk | might be haha | 16:18 |
jrosser | yes, what i mean is that they keystone role is there, and i can assign it just fine | 16:18 |
jrosser | but then the behaviour is WTF | 16:18 |
noonedeadpunk | well, there's auditor in barbican actually | 16:18 |
noonedeadpunk | and you can map them. I think there's smth for octavia as well. | 16:18 |
noonedeadpunk | But for most of the services this is just absent | 16:19 |
noonedeadpunk | and you need to write rules and override default stuff | 16:19 |
noonedeadpunk | Probably worth bringing to the TC as the community goal :p | 16:19 |
jrosser | yeah, this is horrid as you end up with full read/write admin being used just to make reports otherwise | 16:20 |
jrosser | because you may well want visibility across all projects | 16:20 |
noonedeadpunk | Well, yeah, full permissions application credentials... | 16:21 |
*** jbadiapa has quit IRC | 16:34 | |
noonedeadpunk | ah, octavia has load-balancer_global_observer and load-balancer_observer | 16:42 |
johnsom | I wrote up a doc for the roles in Octavia here: https://docs.openstack.org/octavia/latest/configuration/policy.html | 16:44 |
jrosser | i wonder what it is thats not wired up properly | 16:44 |
jrosser | https://github.com/openstack/neutron/search?p=1&q=SYSTEM_OR_PROJECT_READER | 16:44 |
johnsom | In case you haven't seen it | 16:44 |
jrosser | becasue to my suprise i was able to boot an instance with my user that only has reader role | 16:44 |
jrosser | and this is likley me totally misunderstanding whats meant by that tbh | 16:44 |
noonedeadpunk | johnsom: yeah, I just did:) The problem here is more that _most_ of the services doesn't have it | 16:44 |
johnsom | Yeah, I know. Nova and Octavia led the charge on that, but I don't know if nova merged their patches for it. In theory the new scopes/default roles get us closer | 16:45 |
*** rpittau is now known as rpittau|afk | 16:46 | |
johnsom | noonedeadpunk Feel free to ping me if you have questions about the Octavia implementation. | 16:48 |
noonedeadpunk | well, actually nova has smth now | 16:49 |
noonedeadpunk | johnsom: sure, thanks for being around! | 16:49 |
jrosser | noonedeadpunk: so yes this is where i'm confused, like keystone has a concept of reader role, and i find the same sort of concepts in nova/neutron code | 16:49 |
noonedeadpunk | none in cinder and glance | 16:50 |
noonedeadpunk | doh. I've started looking through projects and realized that things have landed in W for _lot_ of projects | 17:19 |
noonedeadpunk | https://blueprints.launchpad.net/neutron/+spec/secure-rbac-roles | 17:26 |
noonedeadpunk | and if look through https://codesearch.opendev.org/?q=role%3Areader%20and%20system_scope%3Aall&i=nope&files=&excludeFiles=&repos= most of the project landed that | 17:30 |
noonedeadpunk | eventually, that's the correct link https://wiki.openstack.org/wiki/Consistent_and_Secure_Default_Policies_Popup_Team | 17:35 |
jrosser | hmm so maybe this is all more complete for W | 17:40 |
jrosser | maybe for now i can make an application credential with access rules that only allow it to GET from the api i'm interested in | 17:42 |
*** andrewbonney has quit IRC | 18:13 | |
*** rh-jlabarre has quit IRC | 19:06 | |
*** rh-jelabarre has joined #openstack-ansible | 19:12 | |
*** lvdombrkr has joined #openstack-ansible | 19:31 | |
lvdombrkr | hello all | 19:32 |
lvdombrkr | openstack-ansible is containerized now? | 19:33 |
*** spatel has quit IRC | 19:49 | |
*** spatel_ has joined #openstack-ansible | 19:50 | |
*** spatel_ is now known as spatel | 19:50 | |
*** lvdombrkr has quit IRC | 19:52 | |
*** gshippey has quit IRC | 19:55 | |
*** mgagne has joined #openstack-ansible | 20:21 | |
*** spotz has quit IRC | 20:38 | |
*** spatel has quit IRC | 20:42 | |
openstackgerrit | Merged openstack/openstack-ansible master: Add trove instance key into secrets https://review.opendev.org/c/openstack/openstack-ansible/+/784565 | 21:08 |
*** spotz has joined #openstack-ansible | 21:38 | |
*** macz_ has quit IRC | 23:01 | |
*** tosky has quit IRC | 23:11 | |
*** luksky has quit IRC | 23:11 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!