*** SheenaG has quit IRC | 00:04 | |
*** rm_you has quit IRC | 00:09 | |
*** rm_you has joined #openstack-barbican | 00:15 | |
*** kfarr has joined #openstack-barbican | 00:16 | |
*** jamielennox is now known as jamielennox|away | 00:29 | |
hockeynut | Daviey I did reply so they were on the pathset 27 | 00:38 |
---|---|---|
hockeynut | patchset | 00:38 |
*** jamielennox|away is now known as jamielennox | 00:39 | |
*** zz_dimtruck is now known as dimtruck | 01:02 | |
*** elmiko is now known as _elmiko | 01:04 | |
*** bitblt has quit IRC | 01:45 | |
openstackgerrit | Kaitlin Farr proposed openstack/castellan: Add managed objects hierarchy https://review.openstack.org/191884 | 01:53 |
*** gyee has quit IRC | 02:28 | |
openstackgerrit | Merged openstack/kite: Drop use of 'oslo' namespace package https://review.openstack.org/195777 | 02:35 |
*** xaeth_afk is now known as xaeth | 02:58 | |
*** yuanying has quit IRC | 03:16 | |
*** crc32 has joined #openstack-barbican | 03:21 | |
*** jamielennox is now known as jamielennox|away | 03:22 | |
*** xaeth is now known as xaeth_afk | 03:28 | |
*** jamielennox|away is now known as jamielennox | 03:31 | |
*** dave-mccowan has quit IRC | 03:33 | |
*** xaeth_afk is now known as xaeth | 03:36 | |
*** kfarr1 has joined #openstack-barbican | 03:38 | |
*** kfarr has quit IRC | 03:39 | |
openstackgerrit | Merged openstack/barbican: Adding script for rewrapping p11 KEKs https://review.openstack.org/196270 | 03:45 |
*** xaeth is now known as xaeth_afk | 03:57 | |
*** alee has quit IRC | 03:59 | |
*** yuanying has joined #openstack-barbican | 04:08 | |
*** alee has joined #openstack-barbican | 04:11 | |
*** woodster_ has quit IRC | 04:41 | |
*** arunkant_ has quit IRC | 05:02 | |
*** alee has quit IRC | 05:38 | |
*** alee has joined #openstack-barbican | 05:51 | |
*** ig0r_ has joined #openstack-barbican | 05:52 | |
*** ig0r__ has quit IRC | 05:55 | |
*** everjeje has joined #openstack-barbican | 05:59 | |
*** crc32 has quit IRC | 06:23 | |
*** kfarr1 has quit IRC | 06:35 | |
*** nickrmc83 has joined #openstack-barbican | 07:09 | |
*** dimtruck is now known as zz_dimtruck | 07:10 | |
*** shohel has joined #openstack-barbican | 07:21 | |
*** jaosorior has joined #openstack-barbican | 07:55 | |
openstackgerrit | Merged openstack/barbican: Completed localization tagging for plugin directory https://review.openstack.org/199155 | 09:33 |
*** DTadrzak has joined #openstack-barbican | 09:37 | |
DTadrzak | Hello guys I want to ask about a version Object in Barbican. Tell me if barbican need a Version Object and if somebody has been working on it? | 09:40 |
jaosorior | Can you ellaborate on what you mean by Version Object? | 09:41 |
jaosorior | DTadrzak: Is this what you're talking about? http://docs.openstack.org/developer/swift/overview_object_versioning.html | 09:41 |
DTadrzak | https://review.openstack.org/#/c/174318/2 | 09:42 |
jaosorior | wait..wrong link: http://docs.openstack.org/developer/oslo.versionedobjects/ | 09:42 |
jaosorior | that's the one | 09:42 |
jaosorior | DTadrzak: Well, there are some questions in that blueprint that Grzegorz Grasza has not answered | 09:42 |
jaosorior | if you're interested, can you answer the questions we posed there? | 09:42 |
DTadrzak | i will ask Grzegorz to answer your question ASAP | 09:43 |
jaosorior | alright | 09:43 |
jaosorior | DTadrzak: Also, if he could provide a more detailed description of what the versionedobjects actually are trying to solve, we would appreciate it a lot, since it seems that some people are still figuring out the real use-cases for such a library | 09:46 |
DTadrzak | jaosorior: Well generally It will allow to have a communication via rpc with different version of our project it's very useful in case of Rolling upgrades for more details plz provide your question to this spec i will ask Grzegorz to answer your questions. ok :)? | 09:59 |
*** mmdurrant has quit IRC | 10:09 | |
*** nickrmc83 has quit IRC | 10:17 | |
*** nickrmc83 has joined #openstack-barbican | 10:25 | |
jaosorior | DTadrzak: sure | 10:34 |
*** yuanying has quit IRC | 10:41 | |
*** arunkant_ has joined #openstack-barbican | 10:59 | |
*** arunkant_ has quit IRC | 11:08 | |
*** arunkant has joined #openstack-barbican | 11:18 | |
*** arunkant has quit IRC | 11:24 | |
*** shohel has quit IRC | 11:34 | |
*** dave-mccowan has joined #openstack-barbican | 11:34 | |
*** shohel has joined #openstack-barbican | 11:57 | |
*** mmdurrant has joined #openstack-barbican | 11:59 | |
*** darrenmoffat has quit IRC | 12:21 | |
*** darrenmoffat has joined #openstack-barbican | 12:22 | |
*** shohel has quit IRC | 12:45 | |
*** pserebryakov has joined #openstack-barbican | 12:47 | |
*** shohel has joined #openstack-barbican | 12:47 | |
*** alee has quit IRC | 12:51 | |
*** kfarr has joined #openstack-barbican | 13:01 | |
*** kfarr has quit IRC | 13:06 | |
*** _elmiko is now known as elmiko | 13:15 | |
*** arunkant has joined #openstack-barbican | 13:23 | |
*** arunkant_ has joined #openstack-barbican | 13:31 | |
*** arunkant has quit IRC | 13:35 | |
*** pserebryakov has quit IRC | 14:00 | |
*** alee has joined #openstack-barbican | 14:05 | |
*** pglass has joined #openstack-barbican | 14:05 | |
*** SheenaG has joined #openstack-barbican | 14:15 | |
*** kfarr has joined #openstack-barbican | 14:19 | |
jaosorior | alee: Got some time to review this CR? https://review.openstack.org/#/c/199142/ | 14:23 |
alee | jaosorior, so you opted not to put the storage of the private key in the _save_secrets() method? | 14:27 |
alee | jaosorior, thats fine - just wondering about your reasoning. | 14:28 |
jaosorior | my initial reasoning was that I didn't feel like save_secrets should have the knowledge of the type, but let me make a quick fix to see how it looks like if it was done that way | 14:28 |
alee | jaosorior, you should fix the coverage failure too. | 14:29 |
alee | jaosorior, I dont have a strong feeling either way on where that code should live -- I'll be ok with what you have - once coverage is fixed. | 14:30 |
jaosorior | let me check the coverage part. The test that covers that is functional (actually can only be verified in dogtag at the moment) and that is not taken into account for the coverage | 14:32 |
*** kebray has joined #openstack-barbican | 14:41 | |
*** kebray has quit IRC | 14:44 | |
*** kebray has joined #openstack-barbican | 14:45 | |
*** zz_dimtruck is now known as dimtruck | 14:47 | |
*** jhfeng has joined #openstack-barbican | 14:49 | |
*** silos has joined #openstack-barbican | 14:52 | |
*** Kevin_Bishop has joined #openstack-barbican | 14:56 | |
alee | redrobot, is woodster around? | 14:56 |
redrobot | alee I don't see him at his desk | 14:57 |
*** xaeth_afk is now known as xaeth | 14:57 | |
alee | redrobot, has there been any discussion of talks to be submitted at Tokyo? I believe the deadline is next week. | 14:59 |
redrobot | alee we had a brain storming session here at the Rack the other day... let me pull up my notes. | 14:59 |
openstackgerrit | Steve Heyman proposed openstack/barbican: Add retry server and functional tests to DevStack https://review.openstack.org/170896 | 15:02 |
jaosorior | has anybody seen kfox1111? I actually went ahead and added some feedback to his blueprint https://review.openstack.org/#/c/190404/ but he never replied :/ | 15:03 |
redrobot | alee So, we've got a few abstracts we'll be submitting: | 15:08 |
redrobot | alee High Availability Barbican: Deployment lessons learned and best practices - iguethz | 15:08 |
redrobot | alee Deploying Barbican: Backend comparisons or Which HSM/Secret Store/CA is right for me? - redrobot and reaperhulk | 15:10 |
jhfeng | openstack-dev mailing list currently doesn't have "barbican" project in filtering option. It would be nice be added. | 15:10 |
*** dave-mccowan has quit IRC | 15:10 | |
redrobot | alee thought you might be interested in talking about DogTag on that last one | 15:10 |
alee | redrobot, sure :) | 15:11 |
alee | redrobot, those both sound like good talks | 15:12 |
alee | redrobot, and I'll be happy to tag along as a co-presenter on the second. make my case for going to Tokyo stronger :) | 15:13 |
redrobot | alee Key Federation - not sure about the title yet, another Racker is driving this one. He's coordinating with HP/IBM/Cern to talk about audit and identity federation as well. | 15:13 |
alee | redrobot, reaperhulk - do you need anything from me on that talk? | 15:13 |
*** diazjf has joined #openstack-barbican | 15:13 | |
redrobot | alee "Why aren't you barbicaneeng" by chellygel ... thinking this would be a panel where users can ask questions about Barbican usage/missing features. | 15:14 |
redrobot | alee I'm on the hook to write the abstract | 15:14 |
redrobot | alee I'll run it by you on Monday. | 15:14 |
alee | sounds good. | 15:14 |
*** arunkant__ has joined #openstack-barbican | 15:15 | |
redrobot | alee Barbican Threat Models: what it does and does not protect you from by reaperhulk | 15:15 |
redrobot | alee and the last one: Testing your live Barbican Deployment by hockeynut | 15:15 |
*** arunkant has joined #openstack-barbican | 15:17 | |
jhfeng | performance is another good topic if anyone have some experience on it. release M is for perf, right ? | 15:18 |
*** arunkant_ has quit IRC | 15:18 | |
alee | redrobot, cool - we're going to be running some demos at the Red Hat booth that will hopefully include for example, deployment of FreeIPA/Dogtag/barbican in RDO to do volume encryption, issuance of certs using certmonger. Need to think if there is a talk to come out of that. | 15:19 |
alee | redrobot, perf would be nice and you guys may be able to talk to that. | 15:20 |
*** arunkant__ has quit IRC | 15:20 | |
redrobot | jhfeng alee agreed... not sure if we'll have enough data to give a good talk this cycle though | 15:21 |
*** dave-mccowan has joined #openstack-barbican | 15:22 | |
*** jamielennox is now known as jamielennox|away | 15:23 | |
*** kfarr has quit IRC | 15:27 | |
hockeynut | redrobot is there an etherpad for these abstracts? | 15:28 |
redrobot | hockeynut nope | 15:29 |
hockeynut | redrobot want one? | 15:29 |
*** kfarr has joined #openstack-barbican | 15:29 | |
*** jamielennox|away is now known as jamielennox | 15:32 | |
*** rm_you has quit IRC | 15:33 | |
*** rm_you has joined #openstack-barbican | 15:33 | |
redrobot | hockeynut I don't have a preference. I'll probably put mine on an etherpad so alee can read it. | 15:34 |
*** shohel has quit IRC | 15:35 | |
hockeynut | ok | 15:35 |
*** nickrmc83 has quit IRC | 15:50 | |
*** mdarby has joined #openstack-barbican | 15:56 | |
*** shohel has joined #openstack-barbican | 15:59 | |
*** bitblt has joined #openstack-barbican | 16:03 | |
*** shohel has quit IRC | 16:04 | |
*** jamielennox is now known as jamielennox|away | 16:21 | |
*** kfarr1 has joined #openstack-barbican | 16:21 | |
*** kfarr has quit IRC | 16:24 | |
*** chadlung has joined #openstack-barbican | 16:27 | |
*** jamielennox|away is now known as jamielennox | 16:29 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Add Private Key to the resulting container if stored-key order https://review.openstack.org/199142 | 16:35 |
jhfeng | just FYI, "barbican" now is in the openstack-dev mailing project filtering option list. You can use it to filter your openstack-dev emails. | 16:36 |
*** kfarr1 has quit IRC | 16:39 | |
*** bitblt has quit IRC | 16:45 | |
*** shohel has joined #openstack-barbican | 16:46 | |
*** tkelsey has joined #openstack-barbican | 16:47 | |
*** kfarr has joined #openstack-barbican | 16:55 | |
*** mmdurrant has quit IRC | 16:57 | |
*** mmdurrant has joined #openstack-barbican | 16:58 | |
silos | kfox1111: posted a commment on your blueprint: https://review.openstack.org/#/c/190404/ | 17:06 |
*** alee is now known as alee_lunch | 17:11 | |
openstackgerrit | Merged openstack/barbican: Imported Translations from Transifex https://review.openstack.org/199902 | 17:14 |
*** silos has left #openstack-barbican | 17:21 | |
*** mdarby has quit IRC | 17:36 | |
*** chadlung has quit IRC | 17:52 | |
*** jhfeng has quit IRC | 18:01 | |
*** jhfeng has joined #openstack-barbican | 18:02 | |
*** rellerreller has joined #openstack-barbican | 18:04 | |
*** chadlung has joined #openstack-barbican | 18:15 | |
*** jhfeng has quit IRC | 18:16 | |
*** tkelsey has quit IRC | 18:18 | |
*** chadlung has quit IRC | 18:20 | |
*** chadlung has joined #openstack-barbican | 18:21 | |
*** alee_lunch is now known as alee | 18:24 | |
*** silos has joined #openstack-barbican | 18:25 | |
*** chadlung has quit IRC | 18:33 | |
openstackgerrit | Fernando Diaz proposed openstack/python-barbicanclient: Allow Barbican Client Secret Update Functionality https://review.openstack.org/196876 | 18:34 |
*** chadlung has joined #openstack-barbican | 18:35 | |
*** jaosorior has quit IRC | 18:36 | |
*** chadlung has quit IRC | 18:42 | |
*** tkelsey has joined #openstack-barbican | 18:46 | |
*** tkelsey has quit IRC | 18:51 | |
*** everjeje has quit IRC | 18:58 | |
*** jhfeng has joined #openstack-barbican | 18:59 | |
*** arunkant_ has joined #openstack-barbican | 19:07 | |
*** arunkant has quit IRC | 19:10 | |
*** jhfeng has quit IRC | 19:17 | |
*** jhfeng has joined #openstack-barbican | 19:18 | |
*** mdarby has joined #openstack-barbican | 19:24 | |
*** dave-mccowan has quit IRC | 19:40 | |
*** diazjf has quit IRC | 19:42 | |
*** diazjf has joined #openstack-barbican | 19:43 | |
*** rellerreller has quit IRC | 19:43 | |
*** spotz has joined #openstack-barbican | 19:52 | |
*** crc32 has joined #openstack-barbican | 19:55 | |
*** SheenaG has quit IRC | 20:06 | |
*** dave-mccowan has joined #openstack-barbican | 20:08 | |
*** SheenaG has joined #openstack-barbican | 20:18 | |
*** SheenaG has left #openstack-barbican | 20:18 | |
*** kfarr has quit IRC | 20:23 | |
*** gyee has joined #openstack-barbican | 20:28 | |
*** mmdurrant_ has joined #openstack-barbican | 20:36 | |
mmdurrant_ | Sorry, there are two of me now and I don’t have access to kill my process at home. | 20:37 |
*** gyee has quit IRC | 20:38 | |
*** kfarr has joined #openstack-barbican | 20:40 | |
*** gyee has joined #openstack-barbican | 20:41 | |
mmdurrant_ | So when I create a container in Barbican as a user, should I also expect Barbican to create default ACLs for the container so said user has read access? | 20:43 |
redrobot | mmdurrant_ nope. the main access control is RBAC | 20:44 |
redrobot | mmdurrant_ ACL is an additional/complementary access control. | 20:44 |
redrobot | mmdurrant_ being able to create a secret implies that you have a role that can also retrieve the secret | 20:45 |
redrobot | mmdurrant_ so an ACL entry is not necessary | 20:45 |
*** mdarby has quit IRC | 20:46 | |
mmdurrant_ | Interesting… doing so as the admin user and authenticating as admin, through the public REST API I get permission denied so apparently I don’t have the roles configured correctly. Thanks redrobot | 20:46 |
*** kfarr has quit IRC | 20:47 | |
*** tkelsey has joined #openstack-barbican | 20:47 | |
*** tkelsey has quit IRC | 20:52 | |
openstackgerrit | Fernando Diaz proposed openstack/python-barbicanclient: Allow Barbican Client Secret Update Functionality https://review.openstack.org/196876 | 20:54 |
*** kfarr has joined #openstack-barbican | 21:01 | |
*** xaeth is now known as xaeth_afk | 21:06 | |
*** gyee has quit IRC | 21:34 | |
*** jamielennox is now known as jamielennox|away | 21:37 | |
*** chadlung has joined #openstack-barbican | 21:38 | |
*** gyee has joined #openstack-barbican | 21:41 | |
*** dave-mcc_ has joined #openstack-barbican | 21:45 | |
*** DTadrzak has quit IRC | 21:47 | |
*** DTadrzak has joined #openstack-barbican | 21:47 | |
*** jamielennox|away is now known as jamielennox | 21:48 | |
*** dave-mccowan has quit IRC | 21:49 | |
*** kfarr has quit IRC | 21:50 | |
*** nelsnelson has joined #openstack-barbican | 21:54 | |
mmdurrant_ | OK, I’m getting a little frustrated now. I get “File "/opt/stack/barbican/barbican/queue/__init__.py", line 19, in <module> | 22:00 |
mmdurrant_ | import oslo_messaging as messaging | 22:00 |
mmdurrant_ | ImportError: No module named oslo_messaging” | 22:00 |
mmdurrant_ | oslo.messaging exists | 22:00 |
mmdurrant_ | And this is something I’ve seen frequently - is the oslo project moving away from oslo_* to oslo.* ? | 22:00 |
mmdurrant_ | There doesn’t appear to be much consistency in that regard | 22:00 |
redrobot | mmdurrant_ yes, oslo is changing all their namespaces. maybe you have an old version? newer versions introduce the underscore naming scheme. | 22:02 |
*** silos has left #openstack-barbican | 22:03 | |
mmdurrant_ | I pull pretty regularly - my adventures with the master branch yesterday were… interesting. I try to stick to the stable ones as there is less churn and less unpredictability. | 22:04 |
*** kfarr has joined #openstack-barbican | 22:04 | |
*** Kevin_Bishop has quit IRC | 22:06 | |
*** diazjf has left #openstack-barbican | 22:06 | |
*** kfarr has left #openstack-barbican | 22:06 | |
mmdurrant_ | I’ll try master today. When devstack’ing barbican, it seems the most important parts are: ensuring the contrib/lib/barbican file is in devstack and the 70-barbican.sh is in extras.d so when devstack reads “barbican” in enabled services, it has the files necessary to install it | 22:08 |
rm_work | i had some scripts around setting up octavia/neutronlbaas/barbican | 22:09 |
rm_work | can see if they are helpful for you, though they are a little outdated | 22:09 |
*** pglass has quit IRC | 22:10 | |
rm_work | mmdurrant_: https://gist.github.com/rm-you/d7fbe613d525f12dc447 | 22:12 |
rm_work | mmdurrant_: but as i said, it may be outdated, haven't tested in a while | 22:13 |
*** jhfeng has quit IRC | 22:23 | |
mmdurrant_ | rm_work: tyvm | 22:29 |
*** spotz is now known as spotz_zzz | 22:32 | |
*** alee has quit IRC | 22:33 | |
*** chadlung has quit IRC | 22:44 | |
*** chadlung has joined #openstack-barbican | 22:45 | |
*** chadlung has quit IRC | 22:48 | |
*** chadlung has joined #openstack-barbican | 22:48 | |
*** chadlung has quit IRC | 22:51 | |
*** chadlung has joined #openstack-barbican | 22:52 | |
*** chadlung_ has joined #openstack-barbican | 22:57 | |
*** chadlung has quit IRC | 22:57 | |
*** shohel has quit IRC | 22:58 | |
*** tkelsey has joined #openstack-barbican | 23:02 | |
*** chadlung_ has quit IRC | 23:05 | |
*** chadlung has joined #openstack-barbican | 23:05 | |
*** tkelsey has quit IRC | 23:06 | |
*** mdarby has joined #openstack-barbican | 23:07 | |
*** mdarby has quit IRC | 23:07 | |
*** chadlung has quit IRC | 23:10 | |
*** chadlung has joined #openstack-barbican | 23:10 | |
*** chadlung_ has joined #openstack-barbican | 23:13 | |
*** chadlung has quit IRC | 23:13 | |
*** chadlung_ has quit IRC | 23:20 | |
*** chadlung has joined #openstack-barbican | 23:20 | |
*** chadlung has quit IRC | 23:22 | |
*** chadlung_ has joined #openstack-barbican | 23:23 | |
*** chadlung_ has quit IRC | 23:26 | |
*** chadlung has joined #openstack-barbican | 23:26 | |
*** alee has joined #openstack-barbican | 23:26 | |
*** yuanying has joined #openstack-barbican | 23:28 | |
*** chadlung has quit IRC | 23:29 | |
*** openstack has joined #openstack-barbican | 23:38 | |
*** nelsnelson has quit IRC | 23:42 | |
*** chlong has quit IRC | 23:49 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!