*** arunkant__ has joined #openstack-barbican | 00:11 | |
*** arunkant_ has quit IRC | 00:14 | |
*** darrenmoffat has quit IRC | 00:28 | |
*** darrenmoffat has joined #openstack-barbican | 00:28 | |
*** kfarr has quit IRC | 01:25 | |
*** arunkant_ has joined #openstack-barbican | 01:48 | |
*** arunkant__ has quit IRC | 01:51 | |
*** arunkant has joined #openstack-barbican | 01:52 | |
openstackgerrit | Merged openstack/barbican: Make db-manage script use same config file as barbican https://review.openstack.org/194665 | 01:54 |
---|---|---|
*** arunkant_ has quit IRC | 01:55 | |
*** arunkant_ has joined #openstack-barbican | 01:56 | |
*** arunkant has quit IRC | 01:59 | |
*** arunkant__ has joined #openstack-barbican | 02:05 | |
*** arunkant_ has quit IRC | 02:08 | |
*** zz_dimtruck is now known as dimtruck | 02:12 | |
*** kebray_ has joined #openstack-barbican | 02:15 | |
*** kebray has quit IRC | 02:18 | |
*** nkinder has joined #openstack-barbican | 02:18 | |
*** nkinder has quit IRC | 02:39 | |
*** nkinder has joined #openstack-barbican | 02:40 | |
*** woodster_ has quit IRC | 02:51 | |
*** nkinder has quit IRC | 02:52 | |
*** nkinder has joined #openstack-barbican | 02:57 | |
*** chlong has quit IRC | 02:57 | |
*** chlong has joined #openstack-barbican | 02:58 | |
*** nkinder has quit IRC | 03:06 | |
*** nkinder has joined #openstack-barbican | 03:06 | |
*** tkelsey has joined #openstack-barbican | 03:08 | |
*** tkelsey has quit IRC | 03:12 | |
*** dave-mccowan has quit IRC | 03:31 | |
*** dave-mccowan has joined #openstack-barbican | 03:34 | |
*** dave-mccowan has quit IRC | 03:52 | |
*** dimtruck is now known as zz_dimtruck | 04:02 | |
*** arunkant_ has joined #openstack-barbican | 04:20 | |
*** arunkant__ has quit IRC | 04:24 | |
*** kebray_ has quit IRC | 05:09 | |
*** shohel has joined #openstack-barbican | 06:02 | |
*** shohel has quit IRC | 06:06 | |
*** shohel has joined #openstack-barbican | 06:20 | |
*** kfarr has joined #openstack-barbican | 06:40 | |
*** kfarr has quit IRC | 06:48 | |
*** chlong has quit IRC | 08:01 | |
*** openstack has quit IRC | 08:25 | |
*** openstack has joined #openstack-barbican | 08:25 | |
*** shohel has quit IRC | 08:45 | |
zigo | Can barbican works with MySQL? | 09:22 |
zigo | I can't get it to do barbican-db-manage upgrade ... | 09:22 |
zigo | hockeynut: ^ | 09:28 |
*** tkelsey has quit IRC | 10:30 | |
*** arunkant__ has joined #openstack-barbican | 10:44 | |
*** arunkant_ has quit IRC | 10:48 | |
*** arunkant_ has joined #openstack-barbican | 10:58 | |
*** arunkant__ has quit IRC | 11:02 | |
*** jaosorior has joined #openstack-barbican | 11:15 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Remove ProjectSecret table-related code https://review.openstack.org/194283 | 11:22 |
*** SheenaG has joined #openstack-barbican | 11:51 | |
*** dave-mccowan has joined #openstack-barbican | 12:26 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Remove ProjectSecret table-related code https://review.openstack.org/194283 | 12:55 |
jaosorior | zigo: How did the packetization go? | 12:58 |
*** nkinder has quit IRC | 13:06 | |
*** SheenaG has left #openstack-barbican | 13:10 | |
*** dave-mccowan has quit IRC | 13:35 | |
*** dave-mccowan has joined #openstack-barbican | 13:51 | |
*** dave-mccowan has quit IRC | 13:56 | |
*** SheenaG has joined #openstack-barbican | 14:03 | |
*** pglass has joined #openstack-barbican | 14:09 | |
*** dave-mccowan has joined #openstack-barbican | 14:09 | |
*** zz_dimtruck is now known as dimtruck | 14:10 | |
*** ccneill_ has joined #openstack-barbican | 14:10 | |
*** ccneill_ has quit IRC | 14:15 | |
*** Kevin_Bishop has joined #openstack-barbican | 14:24 | |
*** pglass has quit IRC | 14:32 | |
*** ccneill_ has joined #openstack-barbican | 14:34 | |
*** pglass has joined #openstack-barbican | 14:34 | |
*** silos has joined #openstack-barbican | 14:34 | |
*** claudiub has joined #openstack-barbican | 14:35 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Updated from global requirements https://review.openstack.org/194830 | 14:37 |
*** ccneill_ has quit IRC | 14:41 | |
redrobot | zigo we use sqlachemy, so in theory it should work with MySQL. | 14:58 |
redrobot | zigo at Rackspace we do all our testing/deployment with PostgreSQL, though. | 14:58 |
zigo | redrobot: http://paste.debian.net/260165/ | 14:59 |
jaosorior | zigo, did you find an issue with MySQL? | 14:59 |
zigo | jaosorior: I believe so, I can't do a db-sync. | 14:59 |
jaosorior | zigo: damn... I use postgres too... uhm... redrobot, do you remember if someone had been testing with MySQL? I remember there was someone but not sure who it was | 15:00 |
redrobot | jaosorior was it arunkant_ maybe? | 15:00 |
zigo | jaosorior: Also, your patch didn't help, I have to put a --dburl param. | 15:00 |
redrobot | zigo so elmiko did a ton of work to get the Kilo release to work with MySQL before it went out. | 15:01 |
jaosorior | zigo: was sq_connection defined in the configuration? | 15:01 |
elmiko | hi | 15:01 |
redrobot | zigo maybe a permissions issue? | 15:01 |
zigo | redrobot: It wouldn't be this kind of trace. | 15:01 |
redrobot | elmiko have you seen this before http://paste.debian.net/260165/ ? | 15:02 |
* elmiko looks | 15:02 | |
jaosorior | zigo: But anyway, I could also upload a patch where you explicitly give it the configuration file. | 15:02 |
zigo | # cat /etc/barbican/barbican-api.conf | grep sql_connection | 15:02 |
zigo | sql_connection = mysql://barbican-common:XXXXXX@localhost/barbicandb | 15:02 |
zigo | So it's set ... | 15:02 |
elmiko | that looks vaguely reminiscent of errors i was seeing | 15:03 |
jaosorior | zigo, do you have a public repo where you have your debian packaging rules and such? | 15:03 |
elmiko | zigo: is it true mysql or mariadb? | 15:03 |
zigo | elmiko: True MySQL. | 15:03 |
elmiko | k | 15:03 |
zigo | jaosorior: Vcs-Browser: http://anonscm.debian.org/gitweb/?p=openstack/barbican.git;a=summary | 15:03 |
zigo | Vcs-Git: git://anonscm.debian.org/openstack/barbican.git | 15:03 |
elmiko | that is similar to errors i was getting, but not the same. usually the errors i got had a more definitive error condition. | 15:04 |
zigo | jaosorior: If you run Sid, you can do: debcheckout -a --git-track='*' barbican | 15:04 |
openstackgerrit | Christopher Solis proposed openstack/barbican-specs: Add spec for multiple-kmip-servers https://review.openstack.org/194298 | 15:05 |
jaosorior | zigo: I see why it didn't work | 15:07 |
zigo | Ah? | 15:07 |
jaosorior | this commit was not in kilo https://review.openstack.org/#/c/187297/ | 15:08 |
jaosorior | and that is needed to get the configurations we need | 15:09 |
jaosorior | instead, there are some helper functions in that module http://anonscm.debian.org/cgit/openstack/barbican.git/tree/barbican/common/config.py | 15:09 |
jaosorior | So there are two options | 15:09 |
jaosorior | either you could try to backport that commit to your branch | 15:09 |
jaosorior | or I could upload a patch that enables the db-manage script to take a config-file as a parameter | 15:10 |
jaosorior | what do you prefer? | 15:10 |
*** nkinder has joined #openstack-barbican | 15:10 | |
jaosorior | so, zigo, any preference? | 15:11 |
zigo | jaosorior: So, i should get this commit and try again? | 15:13 |
jaosorior | zigo: if it's straight forward to backport that commit, then I really think that commit will work | 15:13 |
zigo | jaosorior: Ok, trying then. | 15:13 |
zigo | jaosorior: No, it doesn't apply on master. | 15:14 |
zigo | On kilo, sorry. | 15:14 |
zigo | jaosorior: http://paste.debian.net/260167/ | 15:15 |
jaosorior | zigo: yeah... thought it could be a bit problematic | 15:15 |
zigo | It's going to take me some time to backport it... | 15:16 |
jaosorior | zigo: So now there are other two options: I could try to help out on your branch, and upload a fix there. Or I could do something on our master branch | 15:16 |
zigo | I usually don't package master branch stuff. | 15:17 |
zigo | I'd very much prefer a fix for kilo. | 15:17 |
jaosorior | zigo: Well, you could file a bug and I could fix it on kilo/stable | 15:17 |
zigo | Ok. | 15:18 |
zigo | I'll first try to do the backport of this patch. | 15:18 |
zigo | Though I fail to understand how it could fix alembic migrations. | 15:19 |
jaosorior | zigo: I'm also puzzled by that O_o...and yeah, that HAS to get fixed | 15:20 |
jaosorior | redrobot: any idea on who we could ask for help regarding that? | 15:21 |
zigo | It doesn't seem to touch any alembic stuff at all, and only deals with config stuff ... | 15:21 |
zigo | jaosorior: Isn't there's something to fix in the Alembic migration code rather than this? | 15:21 |
jaosorior | zigo: The patch I was talking about was to fix the issue you had with reading the config file. That's why I said that patch would actually make the patch I submitted work for you | 15:22 |
jaosorior | zigo: Other than that, I haven't really looked that deep into the error you're seeing, would need to install MySQL in my machine to be able to test that | 15:22 |
zigo | jaosorior: I can somehow deal with the config stuff later on, though I think it'd be nice to get the alembic migration code to work with MySQL first. | 15:23 |
zigo | jaosorior: If the patch fixes reading from barbican-api.conf, then I'll backport it, yes. | 15:23 |
zigo | (it doesn't seem hard to do that...) | 15:23 |
zigo | But it's uselss if I don't have a db ... | 15:23 |
chellygel | hockeynut, saw your message, ty | 15:24 |
elmiko | redrobot: man, you've really got your finger on the pulse ;) | 15:24 |
zigo | jaosorior: Does Barbican work with SQLite ? | 15:24 |
redrobot | elmiko I just finally figured out how to get my irc client to ping me when anyone mentions barbican lol | 15:24 |
elmiko | ha! | 15:24 |
hockeynut | chellygel np, working on a CR to get the containers to handle filtering - then will look at how to use orders meta to filter | 15:25 |
jaosorior | zigo: Well, last time I checked you couldn't really do the migration scripts on SQLite, but it does work if you just run the application | 15:25 |
zigo | jaosorior: Did you test with SQLA 1.x ? | 15:25 |
zigo | It fixes lots of stuff wrt SQLite. | 15:25 |
jaosorior | zigo: I'm using Postgres | 15:25 |
jaosorior | but like redrobot said, I think arunkant_ was using MySQL. and I'm not sure what dave-mccowan is using O_o | 15:26 |
zigo | The issue with /usr/lib/python2.7/dist-packages/barbican/model/migration/alembic_migrations/versions/13d127569afa_create_secret_store_metadata_table.py seems to be sa.ForeignKeyConstraint(['secret_id'], ['secrets.id'],), | 15:26 |
elmiko | i thought sqlite was being discouraged upstream by the openstack tc? | 15:26 |
zigo | Then there's another one after that... | 15:26 |
* elmiko hunts for link | 15:27 | |
zigo | /usr/lib/python2.7/dist-packages/barbican/model/migration/alembic_migrations/versions/1e86c18af2dd_add_new_columns_type_meta_containerid.py | 15:27 |
zigo | ProgrammingError: (ProgrammingError) (1146, "Table 'barbicandb.orders' doesn't exist") 'ALTER TABLE orders ADD COLUMN container_id VARCHAR(36)' () | 15:27 |
zigo | jaosorior: Are you saying that Barbican can work without any db? | 15:27 |
jaosorior | zigo: I don't know where I implied that | 15:28 |
jaosorior | zigo: but no | 15:28 |
zigo | jaosorior: You were saying "just run the application" (which was, without running the dbsync). | 15:29 |
jaosorior | the application itself will fill the database | 15:29 |
*** nkinder has quit IRC | 15:30 | |
jaosorior | zigo: https://github.com/openstack/barbican/blob/master/barbican/model/repositories.py#L187 | 15:30 |
elmiko | zigo: re: sqlite migrations, have you seen this https://wiki.openstack.org/wiki/OpenStack_and_SQLAlchemy#SQLite_Support | 15:30 |
zigo | Ah... | 15:30 |
zigo | elmiko: That's wrong since the last version of SQLA 1.0 | 15:31 |
zigo | elmiko: SQLA now supports ALTER tables for SQLite. | 15:31 |
elmiko | zigo: ah ok, my bad | 15:31 |
jaosorior | zigo: So if it's a first time installation then there is no need to run upgrade. But if you're updating, then that's needed | 15:31 |
jaosorior | I gotta go, though I'll be back in some hours | 15:33 |
zigo | Ok, I'll try some more stuff then. | 15:35 |
*** diazjf has joined #openstack-barbican | 15:44 | |
*** kfarr has joined #openstack-barbican | 16:04 | |
*** kfarr1 has joined #openstack-barbican | 16:09 | |
*** kfarr has quit IRC | 16:10 | |
*** kfarr1 has quit IRC | 16:15 | |
*** kfarr has joined #openstack-barbican | 16:16 | |
*** pglass has quit IRC | 16:16 | |
*** pglass has joined #openstack-barbican | 16:16 | |
*** kebray has joined #openstack-barbican | 16:17 | |
kfox1111 | does barbican have a hard spec freeze like nova does? | 16:21 |
zigo | What's the use of barbican-keystone-listener ? | 16:22 |
kfox1111 | I believe its to listen for project/user deletes. | 16:23 |
*** kfarr has quit IRC | 16:25 | |
zigo | kfox1111: So it listen on rabbitmq? | 16:26 |
kfox1111 | I believe so. | 16:26 |
redrobot | kfox1111 yes, hard spec freeze is liberty-2 | 16:35 |
redrobot | zigo kfox1111 that is correct. we listen for project delete events to clean up the db | 16:35 |
kfox1111 | zigo: if setting it up, be careful if you have ceilometer enabled. you have to use a seperate queue for barbican. | 16:37 |
kfox1111 | designate has the same problem. :/ | 16:37 |
kfox1111 | redrobot: ok, thanks. | 16:37 |
*** kebray has quit IRC | 16:38 | |
zigo | redrobot: kfox1111: I get barbican-keystone-listener dying somehow, I'm investigating it. | 16:39 |
zigo | Though everything else seems working (ie barbican-worker and the api thourgh uwsgi are working). | 16:40 |
*** kfarr has joined #openstack-barbican | 16:40 | |
jkf | After looking through my scrollback from earlier this morning, I did a successful alembic migration on mariadb from stable/juno to stable/kilo, although I did have other problems afterward. | 16:41 |
*** dontalton has joined #openstack-barbican | 16:52 | |
*** kebray has joined #openstack-barbican | 16:53 | |
*** gyee_ has joined #openstack-barbican | 16:55 | |
*** kebray has quit IRC | 17:04 | |
*** openstackgerrit has quit IRC | 17:38 | |
*** openstackgerrit has joined #openstack-barbican | 17:38 | |
*** diazjf has quit IRC | 17:42 | |
*** jaosorior has quit IRC | 18:05 | |
*** SheenaG has quit IRC | 18:07 | |
*** xaeth_afk is now known as xaeth | 18:13 | |
*** diazjf has joined #openstack-barbican | 18:14 | |
*** jaosorior has joined #openstack-barbican | 18:16 | |
*** kebray has joined #openstack-barbican | 18:28 | |
*** xaeth is now known as xaeth_afk | 18:28 | |
*** diazjf has quit IRC | 18:28 | |
*** diazjf has joined #openstack-barbican | 18:29 | |
*** kebray has quit IRC | 18:31 | |
openstackgerrit | Douglas Mendizábal proposed openstack/barbican: Remove left over reference to admin endpoint https://review.openstack.org/195251 | 18:32 |
silos | Were there changes to the PyKMIP sample KMIP server recently? I pulled down the latest code and can't seem to run the server now. | 18:32 |
redrobot | silos afaik, the server part of pykmip is yet to be written. | 18:32 |
redrobot | silos but kfarr would know for sure | 18:32 |
silos | ah k. thanks redrobot. | 18:33 |
jaosorior | redrobot | 18:33 |
kfarr | redrobot, a basic, basic server is written | 18:33 |
kfarr | silos, I was watching the merge requests this morning and I think there was a bug | 18:33 |
jaosorior | got a workflow for this one? https://review.openstack.org/#/c/178601/ | 18:33 |
kfarr | and it might be fixed now | 18:33 |
kfarr | try pulling again? | 18:33 |
silos | kfarr: sure. I'll try right now. | 18:33 |
redrobot | jaosorior I was just about to ping people about that | 18:34 |
redrobot | jaosorior trying to get \some\ BPs landed for liberty-1 | 18:34 |
redrobot | jaosorior release manager wanted bps, and I figured this one would be close. | 18:34 |
jaosorior | redrobot: Basically this commit lands a BP https://review.openstack.org/#/c/194283/ | 18:34 |
redrobot | jaosorior maybe kfarr can +W since she's already got a +2 there? | 18:34 |
redrobot | jaosorior k, I'll review that one and poke some peeps for more reviews | 18:35 |
jaosorior | woodster is probably interested in that one | 18:35 |
jaosorior | but yeah, it's the last commit to finish that BP | 18:36 |
silos | kfarr: I think I found the sample server but it doesn't seem to be pulling from the kmipconfig.ini file. It just prints out, "Starting Kmip Server" | 18:36 |
jaosorior | kfarr: Workflow for this? https://review.openstack.org/#/c/178601/ :D | 18:36 |
kfox1111 | any more review love for https://review.openstack.org/#/c/190404 ? :) | 18:36 |
kfarr | joasorior one sec! | 18:36 |
kfarr | silos, ah ok, what is it you expect it should be doing? | 18:37 |
*** stanzi has joined #openstack-barbican | 18:38 | |
silos | kfarr: When I ran it a few weeks ago it was pulling the host, port, and all specs from a kmipconfig.ini file but now it doesn't seem to be doing that. Just wondering if it's suppose to be doing that or that was gotten rid of. | 18:39 |
*** crc32 has joined #openstack-barbican | 18:44 | |
jaosorior | kfarr: thanks for the workflow :D | 18:45 |
jaosorior | kfox1111: will give that spec another read tomorrow | 18:46 |
diazjf | kfox1111, just added a comment | 18:53 |
diazjf | just asked a question on the paths used in the API | 18:53 |
*** stanzi has quit IRC | 18:53 | |
*** stanzi has joined #openstack-barbican | 18:54 | |
kfox1111 | jaosorior: thanks. | 18:54 |
kfox1111 | diazjf: thanks. I'll take a look. :) | 18:54 |
*** SheenaG has joined #openstack-barbican | 18:58 | |
*** stanzi has quit IRC | 18:59 | |
*** nkinder has joined #openstack-barbican | 19:01 | |
diazjf | kfox1111, no prob :) | 19:03 |
*** Kevin_Bishop has quit IRC | 19:04 | |
redrobot | kfarr he what was that hotel that is being built that you mentioned will be ready for the mid-cycle? | 19:04 |
openstackgerrit | Merged openstack/barbican: Display all versions info in versions controller https://review.openstack.org/178601 | 19:07 |
jaosorior | yay! :D | 19:08 |
jaosorior | Now heads up people, barbican-api-paste.ini changed with that commit | 19:09 |
* redrobot makes a note of the ini change | 19:09 | |
silos | kfarr: Think I found the problem. Looks like there was an update to server.py and some stuff got shuffled around. THe server still works just not printing out what it use to. | 19:16 |
*** Kevin_Bishop has joined #openstack-barbican | 19:19 | |
*** nkinder has quit IRC | 19:24 | |
*** stanzi has joined #openstack-barbican | 19:24 | |
kfox1111 | ah... finally have a meeting with the pnnl cert maintainers to figure out how to make progress on getting certs for designate managed subdomains. | 19:27 |
kfox1111 | should come up with some interesting requirements for barbican/designate integration. :) | 19:27 |
redrobot | jvrbanac got a sec to review https://review.openstack.org/#/c/194283/4 | 19:28 |
redrobot | hockeynut how about you? time to review https://review.openstack.org/#/c/194283/4 ? | 19:29 |
*** stanzi has quit IRC | 19:33 | |
*** diazjf has quit IRC | 19:36 | |
kfarr | redrobot: http://homewoodsuites3.hilton.com/en/hotels/maryland/homewood-suites-by-hilton-columbia-laurel-BALCMHW/index.html | 19:37 |
redrobot | kfarr awesome! Thanks! | 19:37 |
kfarr | silos, glad you got it working! Sorry, I have not actually tried running it in awhile | 19:37 |
kfarr | cuz we were mostly testing against hardward | 19:38 |
kfarr | * hardware | 19:38 |
kfox1111 | redrobot: is there a previous migration script that migrated the data out of the table? | 19:38 |
kfox1111 | cause it just drops the table in that review. | 19:38 |
redrobot | kfox1111 yeah http://git.openstack.org/cgit/openstack/barbican/commit/barbican?id=131c34e8824e3cecee6a5759c1f5f31de582c471 | 19:39 |
redrobot | kfox1111 it's CR # 3/3 | 19:39 |
kfox1111 | ah. I see. ok. :) | 19:39 |
kfox1111 | looks good to me. :) | 19:40 |
redrobot | kfox1111 thanks for the review! ... I'll get to yours eventually. Just trying to get this one landed so we can cut liberty-1 | 19:40 |
kfox1111 | np. :) | 19:42 |
kfox1111 | yeah, no rush on mine. so long as its done sometime in liberty. :) | 19:43 |
kfox1111 | I've still got my fingers crossed for the instance user thing in liberty. I'm getting pretty worried about it though. :/ | 19:43 |
kfox1111 | diazjf: thanks for the review. Question. So, I was told there would only ever be one barbican api hostname. so why use the whole secret_ref instead of just the uuid? | 19:47 |
redrobot | kfox1111 premature optimization for federation use cases | 19:47 |
redrobot | kfox1111 eventually we'll support some sort of federation story | 19:48 |
redrobot | kfox1111 so that hybrid cloud users can stand up a barbican inside their perimeter and federate secrets out to the public barbican. | 19:48 |
kfox1111 | but you should contact the api endpoint for that secret rather then pass the whole url to the api for a server not hosting the secret? | 19:49 |
kfox1111 | or is this just a way for the client to store the uuid and the server endpoint info together in one field and the clients expected to be able to parse it? | 19:50 |
redrobot | kfox1111 from the point of view of a client that does not know where a secret is stored, the full ref is necessary. | 19:50 |
*** diazjf has joined #openstack-barbican | 19:50 | |
rm_work | kfox1111: theoretically you could have multiple barbican deployments in your cloud too, i think? | 19:50 |
rm_work | it seems like that would be totally possible | 19:50 |
kfox1111 | yeah, but usually you use regions to handle that. | 19:51 |
rm_work | i mean like, we could have our own for neutron | 19:51 |
rm_work | if we wanted | 19:51 |
kfox1111 | yeah, the region is the contstruct in keystone that lets you have multiple instances of a service. one per region. | 19:51 |
rm_work | right but we could have two or three per region | 19:52 |
diazjf | kfox1111, sorry got disconnected, what were your questions | 19:52 |
kfox1111 | rm_work: I don't think keystone supports that. | 19:52 |
rm_work | it doesn | 19:52 |
rm_work | t | 19:52 |
rm_work | which is why full-ref :P | 19:52 |
kfox1111 | you usually make your single endpoint scalable. | 19:52 |
rm_work | yeah, but it is possible you could have requirements like, using a different kind of HSM | 19:53 |
rm_work | or something like that | 19:53 |
rm_work | i don't know, i'm arguing devil's advocate here | 19:53 |
kfox1111 | so, take cinder with the lvm driver as an example. | 19:53 |
kfox1111 | you may have 4 storage bricks each with lvm. | 19:53 |
kfox1111 | one cinder api in front. the user only ever see's a uuid. | 19:53 |
kfox1111 | the api picks which actual storage brick the requests for a given uuid are bound to when its created. | 19:54 |
kfox1111 | it routes requests to it at the api level. the user never knows if there is just 1, or 100. | 19:54 |
kfox1111 | same with nova. | 19:54 |
rm_work | i could see it being cross-region though, too | 19:54 |
rm_work | why not allow someone to use their barbican secrets from one region, in an app in another | 19:55 |
openstackgerrit | Douglas Mendizábal proposed openstack/barbican: Remove left over reference to admin endpoint https://review.openstack.org/195251 | 19:55 |
kfox1111 | You can, so long as you know the endpoint to send it too. | 19:55 |
rm_work | our service doesn't actually care | 19:55 |
rm_work | yeah, but that'd require the full-ref | 19:55 |
kfox1111 | but none of the UI's do cross region out of the box. | 19:55 |
rm_work | because how would the service know which region to look in based on the UUID> | 19:55 |
kfox1111 | it requires a full-ref, or a uuid and an endpoint. | 19:55 |
rm_work | which is essentially the same thing | 19:56 |
rm_work | since the endpoint would have to be provided by the user | 19:56 |
rm_work | and the full-ref is endpoint+uuid | 19:56 |
kfox1111 | almost. the main difference is, in the full-ref case, | 19:56 |
kfox1111 | the identifier is something you expect the user to be able to understand the contents of and use it in some way. | 19:56 |
kfox1111 | where the uuid is an opaque structure the user isn't expected to understand. | 19:56 |
kfox1111 | its just odly inconsistent with all the other openstack api's. | 19:57 |
kfox1111 | I can see why you want it, | 19:57 |
kfox1111 | but if you can't ever give a full-ref to an api server that the front part of the full-ref specifies, | 19:58 |
kfox1111 | then it would be nice if you could return to it just the uuid as well as the full ref. | 19:58 |
kfox1111 | since its cheeper to store just the uuid. | 19:58 |
kfox1111 | so, for example the heat barbican secret resource coudl store just the uuid. | 19:59 |
kfox1111 | darn. gota meeting to go to. bbiab. | 19:59 |
rm_work | hmm | 19:59 |
rm_work | k | 19:59 |
*** Kevin_Bishop has quit IRC | 20:19 | |
*** Kevin_Bishop has joined #openstack-barbican | 20:24 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Updated from global requirements https://review.openstack.org/194830 | 20:35 |
*** diazjf has quit IRC | 20:40 | |
openstackgerrit | Merged openstack/barbican: Remove ProjectSecret table-related code https://review.openstack.org/194283 | 20:42 |
*** kfarr has quit IRC | 21:03 | |
*** SheenaG has quit IRC | 21:06 | |
*** diazjf has joined #openstack-barbican | 21:10 | |
*** dave-mccowan has quit IRC | 21:12 | |
*** SheenaG has joined #openstack-barbican | 21:19 | |
*** morganfainberg is now known as ayspryn | 21:24 | |
*** ayspryn is now known as morganfainberg | 21:24 | |
*** jaosorior has quit IRC | 21:25 | |
*** silos has left #openstack-barbican | 21:26 | |
diazjf | redrobot, I would like to know more about federated barbican. Any specs on this? | 21:33 |
*** dave-mccowan has joined #openstack-barbican | 21:36 | |
*** SheenaG has quit IRC | 21:43 | |
openstackgerrit | Chelsea Winfree proposed openstack/barbican: Add retry server and functional tests to DevStack https://review.openstack.org/170896 | 21:45 |
redrobot | diazjf nope. just a blip on the roadmap. | 21:46 |
diazjf | redrobot, thanks. I'm interested to see these upcoming items :) | 21:50 |
*** diazjf has left #openstack-barbican | 21:56 | |
*** pglass has quit IRC | 22:00 | |
*** Kevin_Bishop has quit IRC | 22:23 | |
*** SheenaG has joined #openstack-barbican | 22:29 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Updated from global requirements https://review.openstack.org/194830 | 22:39 |
openstackgerrit | Merged openstack/barbican: Change naming convention for Barbican config files https://review.openstack.org/189434 | 22:42 |
kfox1111 | back. finally. | 22:46 |
kfox1111 | so... one of the main options the cert folks said is we can get an ad account and use certutil to manage certs with the microsoft ca. | 22:47 |
kfox1111 | so, we're probably going to want a way to hook that into barbican+designate such that if you have the designate domain foo.cloud.pnnl.gov, your allowed to create server certs for x.foo.cloud.pnnl.gov | 22:48 |
*** arunkant_ has quit IRC | 22:48 | |
*** dimtruck is now known as zz_dimtruck | 22:52 | |
*** arunkant has joined #openstack-barbican | 22:56 | |
*** crc32 has quit IRC | 23:15 | |
*** chlong has joined #openstack-barbican | 23:18 | |
*** stanzi has joined #openstack-barbican | 23:22 | |
*** stanzi has quit IRC | 23:26 | |
*** crc32 has joined #openstack-barbican | 23:33 | |
*** crc32 has quit IRC | 23:48 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!