*** bdpayne_ has joined #openstack-barbican | 00:01 | |
*** bdpayne has quit IRC | 00:04 | |
*** bdpayne_ has quit IRC | 00:14 | |
*** kebray has quit IRC | 00:46 | |
hockeynut | redrobot catching up on the notes here - I see the stuff about tempest. The direction I was given (need to rack my brain to recall where it came from) was that tests are now supposed to be in project repos, not tempest repos | 01:02 |
---|---|---|
hockeynut | and you are correct, it works just fine+dandy | 01:02 |
hockeynut | there was some discussion that woodster_ sent around about experimental gate - that seems to be relevant here | 01:03 |
*** kebray has joined #openstack-barbican | 01:26 | |
*** nkinder has joined #openstack-barbican | 01:29 | |
*** denis_makogon has quit IRC | 02:10 | |
*** denis_makogon has joined #openstack-barbican | 02:10 | |
*** openstackgerrit has quit IRC | 02:33 | |
*** bdpayne has joined #openstack-barbican | 02:33 | |
*** kaitlin-farr has quit IRC | 02:34 | |
*** ayoung has quit IRC | 02:45 | |
*** SheenaG1 has joined #openstack-barbican | 02:47 | |
*** SheenaG11 has joined #openstack-barbican | 02:47 | |
*** SheenaG1 has quit IRC | 02:51 | |
*** ayoung has joined #openstack-barbican | 03:07 | |
*** bdpayne has quit IRC | 03:12 | |
*** bdpayne has joined #openstack-barbican | 03:12 | |
*** ajc_ has joined #openstack-barbican | 03:22 | |
*** openstack has joined #openstack-barbican | 03:41 | |
*** denis_makogon has joined #openstack-barbican | 03:46 | |
*** dolphm has joined #openstack-barbican | 03:46 | |
*** hockeynut_ has joined #openstack-barbican | 03:46 | |
*** xaeth_ has joined #openstack-barbican | 03:46 | |
*** SheenaG1 has joined #openstack-barbican | 03:46 | |
*** juantwo_ has joined #openstack-barbican | 03:46 | |
*** ajc_ has joined #openstack-barbican | 03:46 | |
*** ayoung has joined #openstack-barbican | 03:46 | |
*** nkinder has joined #openstack-barbican | 03:46 | |
*** kebray has joined #openstack-barbican | 03:46 | |
*** arunkant has joined #openstack-barbican | 03:46 | |
*** bubbva has joined #openstack-barbican | 03:46 | |
*** gyee has joined #openstack-barbican | 03:46 | |
*** woodster_ has joined #openstack-barbican | 03:46 | |
*** rm_work has joined #openstack-barbican | 03:46 | |
*** jenkins-keep has joined #openstack-barbican | 03:46 | |
*** toabctl has joined #openstack-barbican | 03:46 | |
*** ryanpetrello has joined #openstack-barbican | 03:46 | |
*** jamielennox has joined #openstack-barbican | 03:46 | |
*** jillysciarilly has joined #openstack-barbican | 03:46 | |
*** alee has joined #openstack-barbican | 03:46 | |
*** reaperhulk has joined #openstack-barbican | 03:46 | |
*** lisaclar- has joined #openstack-barbican | 03:46 | |
*** insequent has joined #openstack-barbican | 03:46 | |
*** dougwig has joined #openstack-barbican | 03:46 | |
*** codekobe___ has joined #openstack-barbican | 03:46 | |
*** erw_ has joined #openstack-barbican | 03:46 | |
*** jraim__ has joined #openstack-barbican | 03:46 | |
*** sld has joined #openstack-barbican | 03:46 | |
*** redrobot has joined #openstack-barbican | 03:46 | |
*** hyakuhei has joined #openstack-barbican | 03:46 | |
*** dstufft has joined #openstack-barbican | 03:46 | |
*** russellb has joined #openstack-barbican | 03:46 | |
*** rm_you has joined #openstack-barbican | 03:46 | |
*** russell_h has joined #openstack-barbican | 03:46 | |
*** jvrbanac has joined #openstack-barbican | 03:46 | |
*** chellygel has joined #openstack-barbican | 03:46 | |
*** lifeless has joined #openstack-barbican | 03:46 | |
*** anteaya has joined #openstack-barbican | 03:46 | |
*** d0ugal has joined #openstack-barbican | 03:46 | |
*** dstanek has joined #openstack-barbican | 03:46 | |
*** bdpayne has joined #openstack-barbican | 03:48 | |
*** bdpayne has quit IRC | 03:50 | |
*** woodster_ has quit IRC | 03:55 | |
*** rm_work has quit IRC | 04:03 | |
*** rm_work has joined #openstack-barbican | 04:08 | |
*** rm_work is now known as rm_work|away | 04:08 | |
*** juantwo_ has quit IRC | 04:41 | |
*** bdpayne has joined #openstack-barbican | 05:05 | |
*** ayoung has quit IRC | 05:10 | |
*** gyee has quit IRC | 05:22 | |
*** bdpayne has quit IRC | 05:23 | |
*** jaosorior has joined #openstack-barbican | 06:04 | |
*** kebray has quit IRC | 06:44 | |
*** ajc__ has joined #openstack-barbican | 07:09 | |
*** ajc_ has quit IRC | 07:10 | |
*** ajc__ has quit IRC | 07:14 | |
*** ajc_ has joined #openstack-barbican | 08:03 | |
*** ajc_ has quit IRC | 08:05 | |
*** ajc_ has joined #openstack-barbican | 08:07 | |
*** ajc_ has quit IRC | 08:07 | |
*** xianghuihui has joined #openstack-barbican | 08:45 | |
*** xianghuihuihui has joined #openstack-barbican | 08:49 | |
*** xianghuihui has quit IRC | 08:49 | |
*** openstackgerrit has joined #openstack-barbican | 09:20 | |
*** Guest22704 has joined #openstack-barbican | 10:32 | |
*** xianghuihuihui has quit IRC | 10:40 | |
*** Guest22704 has quit IRC | 11:03 | |
*** denis_makogon has quit IRC | 11:59 | |
*** denis_makogon has joined #openstack-barbican | 11:59 | |
*** juantwo has joined #openstack-barbican | 12:08 | |
*** SheenaG1 has quit IRC | 13:00 | |
*** nkinder has quit IRC | 13:10 | |
*** xaeth_ is now known as xaeth | 13:27 | |
*** paul_glass has joined #openstack-barbican | 13:43 | |
*** nkinder has joined #openstack-barbican | 13:59 | |
*** Guest22704 has joined #openstack-barbican | 14:07 | |
*** SheenaG1 has joined #openstack-barbican | 14:07 | |
*** LarsN has joined #openstack-barbican | 14:15 | |
*** jorge_munoz has joined #openstack-barbican | 14:22 | |
*** lisaclark has joined #openstack-barbican | 14:34 | |
*** atiwari has joined #openstack-barbican | 14:34 | |
*** ayoung has joined #openstack-barbican | 14:37 | |
openstackgerrit | Arvind Tiwari proposed a change to openstack/barbican: Add asymmtric order validator https://review.openstack.org/118697 | 14:41 |
*** lisaclark has quit IRC | 14:52 | |
*** SheenaG1 has quit IRC | 14:56 | |
alee | atiwari, jvrbanac ping | 14:57 |
atiwari | alee, yes | 14:57 |
alee | atiwari, just to confirm, secrets are stored at the project (tenant) level, right? | 14:58 |
atiwari | correct | 14:58 |
alee | atiwari, did we ever make the change you suggested to restrict secret retrieval to the secret's owner? | 14:58 |
atiwari | no, no one likes my that idea | 14:59 |
atiwari | I still think we need it at some point of time | 14:59 |
alee | atiwari, ok just confirming -- hard to remember what happened that long ago. | 15:00 |
atiwari | k | 15:00 |
alee | atiwari, I think we need a mechanism for solving this problem - just not sure that what you suggested is it | 15:00 |
alee | worth revisiting in K. | 15:00 |
atiwari | alee, I wd love to | 15:01 |
*** paul_glass has quit IRC | 15:03 | |
atiwari | alee, question | 15:04 |
alee | atiwari, go ahead | 15:05 |
atiwari | right now in config, passwords are in clear text. Thinking of adding infrastructure in Barbican system so that we can put encrypted password in config. | 15:06 |
alee | atiwari, ok what did you have in mind? | 15:08 |
atiwari | some how encryption and decryption is done by same barbican system which is going to use the password. | 15:08 |
atiwari | in real deployment the config files will be controlled by chef like system and we can not have password in clear text | 15:09 |
atiwari | bottom line is passwords should not be in clear text in config | 15:10 |
atiwari | thoughts? | 15:10 |
alee | atiwari, solving this problem is tricky - basically there will always be the need for at least one password to unlock the others. | 15:11 |
alee | in dogtag/ rhcs , we have solved this in the past in a number of ways | 15:11 |
alee | 1. storing the passwords in a nss db and requiring just the password for unlocking the db | 15:12 |
atiwari | I think we can solve this by having a separate project specific to Barbican and unwrapping keys will be scoped to that will solve this issue | 15:12 |
alee | 2. using a daemon to collect the password from a user on startup | 15:12 |
alee | the tricky thing for us is that we needed to ensure 100% uptime, | 15:13 |
alee | so that if the server went down and was restarted automatically, the passwords would be available. | 15:13 |
alee | atiwari, forred hat cert server, for our customers that require compliance with STIGs etc. , we have https://fedorahosted.org/nuxwdog/ | 15:14 |
alee | which is a daemon that collects and caches passwords in the kernel keyring | 15:15 |
*** SheenaG1 has joined #openstack-barbican | 15:15 | |
atiwari | correct, let me put more thoughts there | 15:15 |
alee | atiwari, I've been meaning to revisit that to see if there are other ways of doing it, but that approach seems to be working rather well. | 15:16 |
alee | (or at least not breaking) | 15:16 |
atiwari | ok | 15:17 |
alee | anyways - definitely scope for a whole separate design - maybe even separate project | 15:17 |
atiwari | I think you are correct | 15:17 |
atiwari | separate project like the idea :) | 15:18 |
*** mikedillion has joined #openstack-barbican | 15:27 | |
*** lisaclark has joined #openstack-barbican | 15:28 | |
*** lisaclark has quit IRC | 15:28 | |
*** lisaclark has joined #openstack-barbican | 15:28 | |
*** SheenaG1 has quit IRC | 15:28 | |
*** Guest22704 has quit IRC | 15:30 | |
openstackgerrit | Arvind Tiwari proposed a change to openstack/barbican: Add asymmtric order validator https://review.openstack.org/118697 | 15:30 |
*** SheenaG1 has joined #openstack-barbican | 15:31 | |
*** woodster_ has joined #openstack-barbican | 15:41 | |
*** bklei has joined #openstack-barbican | 15:42 | |
jvrbanac | alee, what's up? | 15:43 |
alee | jvrbanac, no worries - atiwari answered my question | 15:43 |
jvrbanac | alee, k | 15:43 |
*** Guest22704 has joined #openstack-barbican | 15:43 | |
*** bklei has left #openstack-barbican | 15:43 | |
*** lisaclark has quit IRC | 15:56 | |
atiwari | alee, should add the secret isolation within a project per owner in https://etherpad.openstack.org/p/barbican-kilo-design-sessions? | 16:04 |
*** paul_glass has joined #openstack-barbican | 16:04 | |
alee | atiwari, sure -- I think we should add all the possible ideas | 16:05 |
*** paul_glass1 has joined #openstack-barbican | 16:05 | |
atiwari | OK, then I will add this | 16:05 |
alee | atiwari, we'll have time to select from them for actual sessions/ informal sessions | 16:05 |
redrobot | alee atiwari So the PTL for Keystone pretty much told us that doing that in Barbican would be really bad idea | 16:05 |
redrobot | alee atiwari I don't see the need for continuing to discuss that for Barbican | 16:06 |
redrobot | alee atiwari we should defer that functionality to Keystone. So this would make sense as a Keystone session, not for Barbican. | 16:06 |
alee | redrobot, I'm not suggesting that the functionality necessarily need be in Barbican, only that a mechanism - keystone/policy / whatever - should probably be there. | 16:08 |
*** paul_glass has quit IRC | 16:08 | |
alee | if it makes sense as a keystone design session, then no prob | 16:08 |
redrobot | alee I think we definitely need to get a better understanding of Keystone policy in barbican | 16:09 |
redrobot | alee IIRC Aadm Young was concerned about the way our policy is set up now. | 16:09 |
alee | yup - perhaps a design session around keystone policy in barbican then ? | 16:10 |
redrobot | yeah, I think that would be very helpful. Especially if we can get a Keystone Policy SME to join us | 16:11 |
alee | because we definitely need to understand what we can do/ what we cannot do/ and what we're missing. | 16:11 |
alee | I then I can corrall ayoung | 16:11 |
ayoung | alee, no one can corrall me | 16:11 |
alee | ayoung, truer words were never spoken .. | 16:12 |
ayoung | technically, those words weren't spoken either. I need to look into a Linux port of Dragon Speaking Naturally. | 16:12 |
alee | redrobot, sorry - I've unleashed a monster .. | 16:13 |
redrobot | lol | 16:13 |
ayoung | redrobot, so we have a new feature that might make policy more interesting | 16:13 |
ayoung | there is a the ability to assign a policy file to a specific endpoint | 16:13 |
ayoung | now, Auth token middleware does not fetch policy files, so we can't really consume it yet. But 'yet' is the operative word | 16:14 |
ayoung | redrobot, let me read up a bit...unles you can summarize the topic? | 16:14 |
*** kebray has joined #openstack-barbican | 16:16 | |
*** kebray has quit IRC | 16:16 | |
atiwari | ayoung, in a nutshell we need ability to isolate secrets which are scoped to a single project based on owner. | 16:17 |
ayoung | redrobot, OK, I think when atiwari and I disucssed this last summit, we were in accord. I've lost the braincells that held that particular discussion, though | 16:17 |
redrobot | ayoung the discussion was that atiwari was suggesting that the check for this should happen in barbican | 16:18 |
redrobot | ayoung and we agreed that this would be Keystone functionality bleeding into Barbican | 16:18 |
redrobot | I'm interested in achieving that without adding authorization logic in barbican | 16:18 |
*** kebray has joined #openstack-barbican | 16:19 | |
*** kebray has joined #openstack-barbican | 16:19 | |
*** kebray has quit IRC | 16:20 | |
redrobot | It would be great if we can achieve it using Policy | 16:20 |
atiwari | redrobot, I was proposing that has to be enforced by the policy engine running at Barbican | 16:20 |
atiwari | and to support policy framework there has to be some improvement needed in Barbican. that was my proposal | 16:21 |
*** kebray has joined #openstack-barbican | 16:21 | |
redrobot | atiwari you do remember Dolph saying that the changes you proposed did not belong in Barbican, yes? | 16:21 |
atiwari | yes | 16:21 |
redrobot | ok, so I'd like to find a solution that Doplh and other Keystone folks agree is the correct way of doing things | 16:22 |
atiwari | redrobot, but other projects like Nova is introducing the concept of owner in it (AFAIK) | 16:23 |
atiwari | to handle Quota like use case | 16:23 |
atiwari | redrobot, another topic | 16:24 |
*** lisaclark has joined #openstack-barbican | 16:25 | |
*** rm_work|away is now known as rm_work | 16:27 | |
redrobot | alee atiwari Regarding the passwords in config files, we've already proposed a solution for this, however no progress has been made https://github.com/cloudkeep/postern | 16:28 |
redrobot | alee atiwari for the general case, anyway... a bit of a chicken-and-egg problem for Barbican itself >_< | 16:29 |
atiwari | redrobot, adding "Ability to manage master key encryption keys" to the etherpad. This will be a custom plugin but need some changes in models. | 16:31 |
atiwari | let me know your thoughts? | 16:31 |
redrobot | atiwari Are proposing adding a new class of plugins? Do you think there are enough different master key management strategies to justify such a plugin? It seems to me that if you have a specific need for a particular master key rotation scheme, then what you need to do is implement your own SecretStore. | 16:33 |
redrobot | atiwari btw, did your talk get accepted? I forgot to ask when the emails went out. | 16:34 |
atiwari | correct this will be customer secretstore, but it will be sharing the models and there we need some improvements. | 16:34 |
atiwari | redrobot, No | 16:34 |
redrobot | atiwari bummer :( | 16:43 |
chellygel | hey alee -- would love to get your opinion: https://etherpad.openstack.org/p/barbican_metadata | 16:56 |
chellygel | + all | 16:56 |
*** kebray has quit IRC | 16:57 | |
*** bdpayne has joined #openstack-barbican | 16:58 | |
alee | chellygel, will look | 16:59 |
chellygel | thank you! | 16:59 |
*** lisaclark has quit IRC | 17:03 | |
*** lisaclark has joined #openstack-barbican | 17:05 | |
openstackgerrit | Constanze Kratel proposed a change to openstack/barbican: Update Getting Started Guide to include tech review feedback https://review.openstack.org/120156 | 17:10 |
*** akoneru has joined #openstack-barbican | 17:11 | |
openstackgerrit | Constanze Kratel proposed a change to openstack/barbican: removed whitespace from pom.xml https://review.openstack.org/120161 | 17:19 |
*** paul_glass1 has quit IRC | 17:38 | |
openstackgerrit | Constanze Kratel proposed a change to openstack/barbican: removed tenant id from code samples https://review.openstack.org/120163 | 17:38 |
*** lisaclark has quit IRC | 17:41 | |
*** lisaclark has joined #openstack-barbican | 17:46 | |
*** gyee has joined #openstack-barbican | 17:46 | |
alee | chellygel, woodster_ added a few comments on meta design | 17:46 |
*** SheenaG1 has quit IRC | 17:47 | |
chellygel | thanks alee ! will look :) | 17:47 |
*** lisaclark has quit IRC | 18:00 | |
*** lisaclark has joined #openstack-barbican | 18:04 | |
*** lisaclark has quit IRC | 18:04 | |
*** SheenaG1 has joined #openstack-barbican | 18:09 | |
*** lisaclark has joined #openstack-barbican | 18:09 | |
*** SheenaG11 has joined #openstack-barbican | 18:10 | |
*** SheenaG1 has quit IRC | 18:13 | |
*** paul_glass has joined #openstack-barbican | 18:25 | |
*** jaosorior has quit IRC | 18:32 | |
*** jaosorior has joined #openstack-barbican | 18:35 | |
*** kebray has joined #openstack-barbican | 18:36 | |
*** kebray has quit IRC | 18:36 | |
*** kebray has joined #openstack-barbican | 18:37 | |
*** Guest22704 has quit IRC | 18:46 | |
*** Stanzi has joined #openstack-barbican | 18:47 | |
*** ametts has joined #openstack-barbican | 19:00 | |
*** Stanzi has quit IRC | 19:02 | |
*** openstackgerrit has quit IRC | 19:02 | |
*** paul_glass has quit IRC | 19:04 | |
*** kebray has quit IRC | 19:12 | |
rm_work | redrobot / woodster_: if one of you is not totally busy, could you pop into #openstack-keystone and at least monitor the conversation I'm having in there? | 19:16 |
*** lisaclark has quit IRC | 19:33 | |
*** lisaclark has joined #openstack-barbican | 19:34 | |
*** openstackgerrit has joined #openstack-barbican | 19:41 | |
*** kebray has joined #openstack-barbican | 19:44 | |
*** kebray has quit IRC | 20:00 | |
*** alee has quit IRC | 20:03 | |
*** bubbva has quit IRC | 20:04 | |
*** bubbva has joined #openstack-barbican | 20:04 | |
*** kebray has joined #openstack-barbican | 20:08 | |
*** alee has joined #openstack-barbican | 20:09 | |
*** lisaclark has quit IRC | 20:10 | |
*** lisaclark has joined #openstack-barbican | 20:11 | |
*** mikedillion has quit IRC | 20:25 | |
*** dolphm has left #openstack-barbican | 20:49 | |
*** lisaclark has quit IRC | 20:59 | |
*** lisaclark has joined #openstack-barbican | 21:00 | |
atiwari | redrobot, yt? | 21:01 |
*** jaosorior has quit IRC | 21:02 | |
*** juantwo has quit IRC | 21:03 | |
*** kebray has quit IRC | 21:10 | |
*** lisaclark has quit IRC | 21:11 | |
*** ametts has quit IRC | 21:13 | |
*** kebray has joined #openstack-barbican | 21:13 | |
*** kebray has quit IRC | 21:13 | |
*** lisaclark has joined #openstack-barbican | 21:14 | |
*** kebray has joined #openstack-barbican | 21:14 | |
*** kebray has quit IRC | 21:14 | |
redrobot | atiwari what's up? | 21:18 |
atiwari | redrobot, can you please validate my https://review.openstack.org/#/c/110817/17/barbican/tasks/keystone_consumer.py | 21:23 |
atiwari | I think this is not the correct way of extending the calss | 21:23 |
atiwari | class | 21:23 |
atiwari | method signature in sub class is modified | 21:23 |
atiwari | wd you mind taking a quick look? | 21:24 |
atiwari | redrobot, ^ | 21:24 |
redrobot | atiwari will do | 21:24 |
atiwari | redrobot, thanks for your time | 21:25 |
atiwari | no rush though | 21:25 |
jamielennox | hey all, 2 +2s on kite stuff: https://review.openstack.org/#/c/119692/2 and https://review.openstack.org/#/c/119693/ its just process stuff for the gate tests | 21:28 |
jamielennox | can someone leave the +A? | 21:28 |
*** kebray has joined #openstack-barbican | 21:34 | |
redrobot | jamielennox done | 21:36 |
jamielennox | redrobot: cheers | 21:36 |
openstackgerrit | A change was merged to openstack/kite: Explicitly import _ translation function https://review.openstack.org/119692 | 21:37 |
*** dolphm has joined #openstack-barbican | 21:43 | |
*** akoneru is now known as akoneru_lunch | 21:46 | |
*** SheenaG11 has quit IRC | 21:54 | |
*** nkinder has quit IRC | 22:02 | |
*** bdpayne_ has joined #openstack-barbican | 22:02 | |
*** bdpayne has quit IRC | 22:03 | |
*** kebray has quit IRC | 22:04 | |
*** lisaclark has quit IRC | 22:05 | |
*** kebray has joined #openstack-barbican | 22:15 | |
*** ayoung has quit IRC | 22:16 | |
*** kebray has quit IRC | 22:16 | |
*** atiwari has quit IRC | 22:23 | |
*** juantwo has joined #openstack-barbican | 22:28 | |
*** juantwo has quit IRC | 22:30 | |
*** jorge_munoz has quit IRC | 22:30 | |
*** juantwo has joined #openstack-barbican | 22:31 | |
*** kebray has joined #openstack-barbican | 22:35 | |
*** akoneru_lunch is now known as akoneru | 22:43 | |
*** kebray has quit IRC | 22:53 | |
*** bdpayne_ has quit IRC | 23:11 | |
*** bdpayne has joined #openstack-barbican | 23:13 | |
*** nkinder has joined #openstack-barbican | 23:18 | |
openstackgerrit | Arun Kant proposed a change to openstack/barbican: Adding keystone notification listener support https://review.openstack.org/110817 | 23:18 |
*** ayoung has joined #openstack-barbican | 23:28 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!