*** jaosorior has quit IRC | 00:51 | |
*** kgriffs is now known as kgriffs|afk | 01:03 | |
*** woodster_ has quit IRC | 01:10 | |
openstackgerrit | Louis Taylor proposed openstack/barbican: Configure colored logging in devstack https://review.openstack.org/156427 | 01:10 |
---|---|---|
*** jamielennox is now known as jamielennox|away | 01:16 | |
*** jamielennox|away is now known as jamielennox | 01:31 | |
*** jamielennox is now known as jamielennox|away | 01:41 | |
*** bdpayne has quit IRC | 01:49 | |
*** woodster_ has joined #openstack-barbican | 02:03 | |
*** jamielennox|away is now known as jamielennox | 02:09 | |
*** alee has joined #openstack-barbican | 02:20 | |
*** alee has quit IRC | 02:57 | |
*** zz_dimtruck is now known as dimtruck | 03:03 | |
*** alee has joined #openstack-barbican | 03:12 | |
*** xaeth_afk is now known as xaeth | 03:53 | |
*** alee has quit IRC | 04:46 | |
*** kebray_ has joined #openstack-barbican | 04:53 | |
*** kebray has quit IRC | 04:57 | |
*** alee has joined #openstack-barbican | 05:07 | |
*** dimtruck is now known as zz_dimtruck | 05:29 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Imported Translations from Transifex https://review.openstack.org/156479 | 06:12 |
*** alee has quit IRC | 06:54 | |
*** alee has joined #openstack-barbican | 07:01 | |
*** alee has quit IRC | 07:09 | |
*** alee has joined #openstack-barbican | 07:37 | |
*** rm_you has quit IRC | 07:52 | |
*** rm_work is now known as rm_work|away | 07:57 | |
*** rm_you has joined #openstack-barbican | 08:09 | |
*** chlong has quit IRC | 08:11 | |
*** rm_you| has joined #openstack-barbican | 08:13 | |
*** rm_you has quit IRC | 08:16 | |
*** kebray_ has quit IRC | 11:35 | |
openstackgerrit | Nathan Reller proposed openstack/barbican: Added secret_type to Secret model https://review.openstack.org/156385 | 11:57 |
openstackgerrit | Nathan Reller proposed openstack/barbican: Added secret_type to Secret model https://review.openstack.org/156385 | 12:22 |
*** xaeth is now known as xaeth_afk | 12:55 | |
*** SheenaG1 has joined #openstack-barbican | 14:43 | |
*** igueths has joined #openstack-barbican | 14:47 | |
*** kgriffs|afk is now known as kgriffs | 14:52 | |
*** SheenaG1 has quit IRC | 14:52 | |
*** SheenaG1 has joined #openstack-barbican | 14:56 | |
*** jaosorior has joined #openstack-barbican | 15:00 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Refactor _lookup for orders controller https://review.openstack.org/156403 | 15:04 |
*** lisaclark1 has joined #openstack-barbican | 15:08 | |
*** dave-mccowan has joined #openstack-barbican | 15:09 | |
*** rellerreller has joined #openstack-barbican | 15:11 | |
*** alee has quit IRC | 15:13 | |
*** stanzi has joined #openstack-barbican | 15:14 | |
openstackgerrit | Douglas Mendizábal proposed openstack/python-barbicanclient: Add hooks for devstack testing https://review.openstack.org/155917 | 15:17 |
*** darrenmoffat has quit IRC | 15:17 | |
*** paul_glass has joined #openstack-barbican | 15:17 | |
*** darrenmoffat has joined #openstack-barbican | 15:18 | |
*** rm_work|away is now known as rm_work | 15:18 | |
*** tsv has joined #openstack-barbican | 15:28 | |
jaosorior | hockeynut: mind giving this a read? https://review.openstack.org/#/c/132091/ would be nice to get that merged today :D | 15:29 |
hockeynut | sure! | 15:29 |
hockeynut | I think I had a dream about quotas last night :-) | 15:30 |
jaosorior | lol | 15:31 |
openstackgerrit | Adam Harwell proposed openstack/castellan: Officially add Certificate Management to scope https://review.openstack.org/156623 | 15:31 |
rm_work | ^^ :) | 15:31 |
reaperhulk | haha, nice rm_work | 15:31 |
SheenaG1 | rm_work: did everyone agree that cert management should be part of it? It felt like that conversation didn't finish | 15:32 |
rm_work | SheenaG1: that's what this is for | 15:32 |
rm_work | SheenaG1: either the CR will land, or it won't :) | 15:33 |
jaosorior | rm_work, SheenaG1: At least I was sold the idea that it makes sense | 15:33 |
SheenaG1 | rm_work: ah, to keep the conversation open | 15:33 |
rm_work | I don't even know how these files got in here to begin with, I would have commented on any review not including Certs to begin with -- I don't think it went through Gerrit | 15:33 |
rm_work | yeah..... pfff redrobot, https://github.com/openstack/castellan/commit/93eb3a9f16bcbbc93866a44e8a58b160420e6b5c no changeID | 15:34 |
openstackgerrit | Merged openstack/barbican-specs: Add Quota support for Barbican resources https://review.openstack.org/132091 | 15:35 |
jaosorior | tsv: ^^ | 15:35 |
*** zz_dimtruck is now known as dimtruck | 15:36 | |
jvrbanac | rellerreller, tossed a couple comments on your CR | 15:36 |
*** alee has joined #openstack-barbican | 15:37 | |
jaosorior | jvrbanac: I responded to those comments | 15:38 |
hockeynut | quotas have merged - dance and sing! | 15:38 |
*** jkf has joined #openstack-barbican | 15:39 | |
jvrbanac | jaosorior, rellerreller, ahh ok... ignore my comments lol | 15:40 |
openstackgerrit | Merged openstack/barbican: Imported Translations from Transifex https://review.openstack.org/156479 | 15:40 |
openstackgerrit | Dave McCowan proposed openstack/barbican: Add subject_dn validator https://review.openstack.org/155640 | 15:40 |
igueths | Lol hockeynut | 15:41 |
tsv | jaosorior, thanks! | 15:41 |
*** kfarr has joined #openstack-barbican | 15:43 | |
*** alee has quit IRC | 15:46 | |
openstackgerrit | Ade Lee proposed openstack/barbican: Added new repository classes and controller classes for CAs https://review.openstack.org/147981 | 15:47 |
openstackgerrit | Ade Lee proposed openstack/barbican: Added mixin class to allow soft deletes https://review.openstack.org/156629 | 15:47 |
*** fern has joined #openstack-barbican | 15:47 | |
openstackgerrit | Merged openstack/python-barbicanclient: Fix serialization of datetime objects https://review.openstack.org/156336 | 15:47 |
*** kebray has joined #openstack-barbican | 15:54 | |
hockeynut | redrobot what does this python SDK mean for Castellan? | 15:57 |
*** kebray has quit IRC | 15:57 | |
rm_work | hockeynut: i was just thinking that | 15:58 |
rm_work | hockeynut: want to ask him in a sec "so how do you feel about having <all of what I want Castellan to do> in SDK? :P | 15:58 |
jaosorior | hockeynut: That's what I was wondering. | 15:58 |
rm_work | I doubt he'll want it, lol | 15:58 |
*** xaeth_afk is now known as xaeth | 15:59 | |
jaosorior | rm_work, hockeynut: I guess it would depend on what the aim of SDK is. If they only intent do be an SDK, meaning, oniy an interface to what the concepts of the project, and the calls to the REST API, like the python-*client's are,; then probably they won't dig Castellan | 15:59 |
rm_work | yeah | 15:59 |
rm_work | I doubt they want to have vendor-plugin type stuff in their repo :P lol | 16:00 |
hockeynut | yep - its more of a least-common denom approach | 16:00 |
hockeynut | so does Castellan sit on top of sdk perhaps? or go right to barbican? | 16:00 |
*** fern has quit IRC | 16:01 | |
jaosorior | rm_work, hockeynut: I'm guessing Castellan would still exist, and would then use SDK as a "backend" or implementation, in the same way it will use python-barbicanclient in the current path | 16:02 |
rm_work | yep | 16:02 |
rm_work | I think so | 16:02 |
hockeynut | jaosorior sounds that way | 16:02 |
*** alee has joined #openstack-barbican | 16:05 | |
openstackgerrit | Merged openstack/barbican: Configure colored logging in devstack https://review.openstack.org/156427 | 16:06 |
kragniz | first barbican patch merged! | 16:06 |
kragniz | \o/ | 16:06 |
hockeynut | congrats kragniz ! | 16:07 |
jaosorior | kragniz: Congrats! | 16:07 |
hockeynut | (I should have put that in different colors!) | 16:07 |
kragniz | heh | 16:07 |
rm_work | woot | 16:11 |
*** stanzi has quit IRC | 16:13 | |
*** stanzi has joined #openstack-barbican | 16:14 | |
rm_work | alee: I am thinking it wouldn't hurt to get all of this done IN the Castellan repo for the time being, until the SDK stuff is more "ready" for Barbican and has time to figure out how they want to handle stuff like Castellan being in their repo -- at which point we could then take all of the working stuff from Castellan that we've iterated on, and put it in their repo | 16:15 |
rm_work | if that makes sense | 16:15 |
SheenaG1 | congrats kragniz (a littleslwow) | 16:16 |
briancurtin | from what i understand of it, that sounds like a good way to go. Castellan by itself how you'd do it today, then Castellan backed by SDK, then if it makes sense, castellan offered by the SDK | 16:17 |
*** kebray has joined #openstack-barbican | 16:17 | |
jaosorior | Anybody has time to review these two CRs? https://review.openstack.org/#/c/156403/ https://review.openstack.org/#/c/156325/ they should be pretty straight forward | 16:18 |
jvrbanac | jaosorior, but you're not biased at all :-P | 16:18 |
rm_work | briancurtin: cool | 16:18 |
*** stanzi has quit IRC | 16:18 | |
jaosorior | jvrbanac: it's called marketing ;) | 16:19 |
jaosorior | woodster_: ping | 16:23 |
woodster_ | jaosorior, hello | 16:24 |
jaosorior | is there a reason why there is no "get_project" call? I'm looking at the repo singleton stuff | 16:25 |
jaosorior | woodster_: ^^ | 16:26 |
woodster_ | jaosorior: https://github.com/openstack/barbican/blob/master/barbican/plugin/crypto/manager.py#L107 | 16:32 |
woodster_ | jaosorior, so that really should be added to those existing factory/singleton repository calls | 16:33 |
jaosorior | woodster_: Where is that stuff documented? Would like to understand it better before coding it in | 16:34 |
*** lisaclark1 has quit IRC | 16:35 | |
jaosorior | woodster_: Found the documentation | 16:37 |
woodster_ | jaosorior, oh sorry Ozz, ok cool. That is all we are using oslo concurrency for right now | 16:38 |
*** lisaclark1 has joined #openstack-barbican | 16:43 | |
*** stanzi has joined #openstack-barbican | 16:45 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Add concurrency decorator to repo factory functions https://review.openstack.org/156656 | 16:47 |
jaosorior | woodster_: That was pretty straight forward ^^ | 16:49 |
*** lisaclark1 has quit IRC | 16:51 | |
*** lisaclark1 has joined #openstack-barbican | 16:55 | |
hockeynut | jaosorior why did you add that concurrency decorator? Was it a timing bug somewhere? | 16:58 |
*** stanzi has quit IRC | 17:04 | |
openstackgerrit | Dave McCowan proposed openstack/barbican: Add subject_dn validator https://review.openstack.org/155640 | 17:07 |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Add concurrency decorator to repo factory functions https://review.openstack.org/156656 | 17:12 |
*** stanzi has joined #openstack-barbican | 17:15 | |
openstackgerrit | Chelsea Winfree proposed openstack/barbican: Changing basic copyright for a section of functional tests https://review.openstack.org/156668 | 17:17 |
*** stanzi has quit IRC | 17:18 | |
*** stanzi has joined #openstack-barbican | 17:19 | |
*** stanzi has quit IRC | 17:23 | |
lisaclark1 | chellygel, jvrbanac: ping | 17:28 |
lisaclark1 | if i want to push a commit to gerrit, what's the gerrit endpoint to point my git to? | 17:28 |
jvrbanac | lisaclark, git review -s | 17:29 |
jvrbanac | lisaclark1, ^ | 17:29 |
*** bdpayne has joined #openstack-barbican | 17:30 | |
*** tkelsey has joined #openstack-barbican | 17:31 | |
*** kebray has quit IRC | 17:33 | |
*** kebray has joined #openstack-barbican | 17:33 | |
*** miqui has quit IRC | 17:37 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Add missing repository factory functions https://review.openstack.org/156680 | 17:48 |
chellygel | plz just need a workflow : https://review.openstack.org/#/c/156668/ | 17:50 |
jaosorior | lets see | 17:50 |
jaosorior | chellygel: done | 17:50 |
chellygel | thanks jaosorior -- udabes | 17:50 |
jvrbanac | jaosorior, questions about your CR | 17:51 |
jaosorior | which | 17:52 |
jvrbanac | jaosorior, https://review.openstack.org/#/c/156403/3/barbican/api/controllers/orders.py L111 | 17:52 |
jvrbanac | jaosorior, Is removing the try/catch appropriate here? | 17:52 |
*** gyee has joined #openstack-barbican | 17:52 | |
jaosorior | well, that function now won't even be called if there is no such secret. Which is what the try-except was for | 17:53 |
jvrbanac | jaosorior, but the exception is for if the Order isn't found | 17:54 |
jvrbanac | jaosorior, atleast that's how it reads | 17:54 |
jaosorior | I don't know why I wrote secret | 17:54 |
jaosorior | yes, so, if the order is not found it used to catch it there | 17:55 |
jaosorior | but now, with that approach that I introduced, if the order is non-existent, then an 404 is thrown already, thus, not even creating that controller, so the delete_order wouldn't be called in the first place | 17:56 |
jvrbanac | jaosorior, interesting... ok | 17:56 |
jaosorior | which is what happens in L136 | 17:57 |
*** lisaclark2 has joined #openstack-barbican | 18:00 | |
*** lisaclark1 has quit IRC | 18:00 | |
jvrbanac | reaperhulk, https://github.com/stackforge/bandit/blob/master/bandit.yaml | 18:08 |
reaperhulk | jvrbanac: yeah I dropped that in as a test | 18:08 |
reaperhulk | We get 10 notifications | 18:08 |
openstackgerrit | Merged openstack/barbican: Changing basic copyright for a section of functional tests https://review.openstack.org/156668 | 18:15 |
openstackgerrit | Merged openstack/barbican: Refactor _lookup for secrets https://review.openstack.org/156325 | 18:15 |
hockeynut | a quick first swag at running bandit...results here: https://gist.github.com/sheyman/6cdedb51276dab77f348 | 18:18 |
openstackgerrit | Dave McCowan proposed openstack/barbican: Add subject_dn validator https://review.openstack.org/155640 | 18:20 |
openstackgerrit | Sheena Gregson proposed openstack/barbican: Updated copyright dates for functional tests/models https://review.openstack.org/156702 | 18:32 |
*** hyakuhei has joined #openstack-barbican | 18:36 | |
hyakuhei | Hey Mid-Cycle type peoples :) | 18:36 |
jaosorior | hyakuhei: yo | 18:40 |
rm_work | heyo | 18:42 |
redrobot | hi hyakuhei ! | 18:45 |
*** hyakuhei has quit IRC | 18:49 | |
woodster_ | hyakuhei, hello | 18:49 |
rm_work | wow, lol: https://lists.freebsd.org/pipermail/freebsd-current/2015-February/054580.html | 18:55 |
*** hyakuhei has joined #openstack-barbican | 18:58 | |
openstackgerrit | Lisa Clark proposed openstack/barbican: Updating copyright on barbican/api files https://review.openstack.org/156708 | 19:00 |
redrobot | rm_work awesome | 19:04 |
rm_work | woodster_: had a nitpick on https://review.openstack.org/#/c/155931/ with consistency of terminology | 19:05 |
rm_work | TLS/SSL | 19:05 |
*** hyakuhei has quit IRC | 19:09 | |
kfarr | alee alembic migrations: https://github.com/cloudkeep/barbican/wiki/Database-Migrations#automatically | 19:10 |
*** lisaclark2 has quit IRC | 19:11 | |
*** hyakuhei has joined #openstack-barbican | 19:13 | |
*** xaeth is now known as xaeth_afk | 19:14 | |
*** lisaclark1 has joined #openstack-barbican | 19:19 | |
*** openstackgerrit has quit IRC | 19:20 | |
*** openstackgerrit has joined #openstack-barbican | 19:20 | |
jaosorior | This one only needs a workflow :D https://review.openstack.org/#/c/156656/ | 19:21 |
openstackgerrit | Merged openstack/barbican: Refactor _lookup for orders controller https://review.openstack.org/156403 | 19:28 |
openstackgerrit | Merged openstack/barbican: Updated copyright dates for functional tests/models https://review.openstack.org/156702 | 19:31 |
SheenaG1 | Got two that just need a workflow | 19:34 |
SheenaG1 | hockeynut, jvrbanac, woodster_ | 19:34 |
SheenaG1 | https://review.openstack.org/#/c/156629/ | 19:34 |
SheenaG1 | https://review.openstack.org/#/c/156656/ | 19:34 |
SheenaG1 | https://review.openstack.org/#/c/155917/ | 19:35 |
SheenaG1 | That last one has like four +2's | 19:35 |
SheenaG1 | But no workflow? :-( | 19:36 |
jaosorior | workflowed | 19:37 |
openstackgerrit | Merged openstack/barbican: Updating copyright on barbican/api files https://review.openstack.org/156708 | 19:38 |
hockeynut | I have a comment on the first one (https://review.openstack.org/#/c/156629/) | 19:41 |
SheenaG1 | alee: hockeynut's comment is on your CR | 19:46 |
*** paul_glass has quit IRC | 20:02 | |
*** rellerreller has quit IRC | 20:05 | |
*** lisaclark1 has quit IRC | 20:07 | |
*** chadlung has joined #openstack-barbican | 20:11 | |
openstackgerrit | Merged openstack/python-barbicanclient: Add hooks for devstack testing https://review.openstack.org/155917 | 20:11 |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Add missing repository factory functions https://review.openstack.org/156680 | 20:13 |
jaosorior | reaperhulk, woodster_: Abandoned the commit related to lockutils. | 20:14 |
reaperhulk | cool | 20:14 |
*** chadlung has quit IRC | 20:17 | |
*** chadlung has joined #openstack-barbican | 20:17 | |
*** lisaclark1 has joined #openstack-barbican | 20:34 | |
*** kebray has quit IRC | 20:43 | |
*** hyakuhei has quit IRC | 20:47 | |
*** lisaclark1 has quit IRC | 20:49 | |
*** kfarr has quit IRC | 20:52 | |
*** hyakuhei has joined #openstack-barbican | 20:54 | |
*** lisaclark1 has joined #openstack-barbican | 20:55 | |
SheenaG1 | For review, everyone | 21:01 |
SheenaG1 | Added mixin class to allow soft deletes (Ade) https://review.openstack.org/#/c/156629/Add missing repository factory functions (Oz) https://review.openstack.org/#/c/156680/Add subject_dn validator (Dave) https://review.openstack.org/#/c/155640/Add secret_type to secret model (Nate) https://review.openstack.org/#/c/156385/ | 21:01 |
SheenaG1 | Eesh | 21:02 |
SheenaG1 | That didn't come across right | 21:02 |
SheenaG1 | Added mixin class to allow soft deletes (Ade) https://review.openstack.org/#/c/156629/ Add missing repository factory functions (Oz) https://review.openstack.org/#/c/156680/ Add subject_dn validator (Dave) https://review.openstack.org/#/c/155640/ Add secret_type to secret model (Nate) https://review.openstack.org/#/c/156385/ | 21:02 |
SheenaG1 | Round 2 | 21:02 |
*** xaeth_afk is now known as xaeth | 21:06 | |
*** stanzi has joined #openstack-barbican | 21:08 | |
jvrbanac | jaosorior, regarding the factory function, is this in relation to the refactor to get rid of passing around repos? | 21:10 |
jvrbanac | jaosorior, ignore me | 21:11 |
jvrbanac | jaosorior, I completely missed your commit msg... | 21:11 |
* jvrbanac is dumb | 21:11 | |
SheenaG1 | But we like him anyway | 21:13 |
rm_work | hey redrobot: http://en.wikipedia.org/wiki/PKCS_12 | 21:25 |
*** stanzi has quit IRC | 21:25 | |
rm_work | ^^ jvrbanac | 21:26 |
*** stanzi has joined #openstack-barbican | 21:26 | |
rm_work | standard? | 21:26 |
rm_work | reaperhulk: what do you think of PKCS12 as the standard for what I am trying to do? :P | 21:28 |
reaperhulk | PKCS12 is commonly used for pairing certificates and private keys | 21:28 |
reaperhulk | It is opaque to barbican | 21:28 |
rm_work | right | 21:28 |
rm_work | but it's essentially what I'm trying to model | 21:28 |
rm_work | and people wanted a standard... | 21:28 |
rm_work | also a great example of how an implementation would work with a system that didn't store metadata linking different secrets -- it's stored as one object | 21:29 |
reaperhulk | you'd have to talk to the others; I am staying out of this one outside of pure cryptographic things ;) | 21:29 |
rm_work | lol | 21:29 |
*** stanzi has quit IRC | 21:30 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Enforce UUID for secret and order IDs https://review.openstack.org/156783 | 21:32 |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Enforce secert and order IDs are valid UUIDs https://review.openstack.org/156783 | 21:34 |
rm_work | jvrbanac: you there? | 21:35 |
*** stanzi has joined #openstack-barbican | 21:35 | |
rm_work | jvrbanac: if we call it a PKCS12 object, does that address your concerns about having a standard? :) | 21:36 |
*** igueths has quit IRC | 21:37 | |
*** lisaclark1 has quit IRC | 21:38 | |
*** SheenaG1 has quit IRC | 21:38 | |
*** jkf has quit IRC | 21:41 | |
*** tsv has quit IRC | 21:44 | |
*** rm_work is now known as rm_work|away | 21:44 | |
*** alee has quit IRC | 21:44 | |
openstackgerrit | Nathan Reller proposed openstack/barbican: Added secret_type to Secret model https://review.openstack.org/156385 | 21:46 |
*** dave-mccowan has quit IRC | 21:47 | |
*** xaeth is now known as xaeth_afk | 21:52 | |
*** stanzi has quit IRC | 21:55 | |
*** gyee has quit IRC | 21:55 | |
*** stanzi has joined #openstack-barbican | 21:56 | |
*** stanzi has quit IRC | 21:59 | |
*** stanzi has joined #openstack-barbican | 22:00 | |
*** stanzi has quit IRC | 22:04 | |
*** stanzi has joined #openstack-barbican | 22:07 | |
*** crc32 has joined #openstack-barbican | 22:12 | |
*** crc32 has quit IRC | 22:18 | |
*** xaeth_afk is now known as xaeth | 22:19 | |
*** stanzi has quit IRC | 22:21 | |
*** stanzi has joined #openstack-barbican | 22:22 | |
*** stanzi has quit IRC | 22:26 | |
*** crc32 has joined #openstack-barbican | 22:31 | |
*** stanzi has joined #openstack-barbican | 22:33 | |
*** gyee has joined #openstack-barbican | 22:49 | |
*** kebray has joined #openstack-barbican | 22:56 | |
*** chlong has joined #openstack-barbican | 23:08 | |
*** stanzi has quit IRC | 23:10 | |
*** stanzi has joined #openstack-barbican | 23:10 | |
*** xaeth is now known as xaeth_afk | 23:13 | |
*** stanzi has quit IRC | 23:15 | |
*** dimtruck is now known as zz_dimtruck | 23:32 | |
*** tkelsey has quit IRC | 23:33 | |
*** chadlung has quit IRC | 23:45 | |
*** chadlung has joined #openstack-barbican | 23:48 | |
*** chadlung_ has joined #openstack-barbican | 23:52 | |
*** chadlung has quit IRC | 23:56 | |
*** chadlung_ has quit IRC | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!