*** dave-mccowan has quit IRC | 00:00 | |
*** zz_dimtruck is now known as dimtruck | 00:06 | |
*** ccneill has quit IRC | 00:10 | |
*** tkelsey has joined #openstack-barbican | 00:11 | |
*** dave-mccowan has joined #openstack-barbican | 00:14 | |
*** tkelsey has quit IRC | 00:15 | |
*** gyee has quit IRC | 00:33 | |
*** dave-mccowan has quit IRC | 00:37 | |
*** rellerreller has quit IRC | 00:58 | |
*** dave-mccowan has joined #openstack-barbican | 00:59 | |
*** pksingh has quit IRC | 01:27 | |
*** pksingh has joined #openstack-barbican | 01:29 | |
*** woodster_ has quit IRC | 01:49 | |
*** dimtruck is now known as zz_dimtruck | 01:50 | |
*** outworlder has joined #openstack-barbican | 01:55 | |
*** outworlder has left #openstack-barbican | 01:55 | |
*** kebray has joined #openstack-barbican | 01:58 | |
*** everjeje has quit IRC | 02:02 | |
*** SheenaG1 has joined #openstack-barbican | 02:03 | |
*** vivek-ebay has quit IRC | 02:22 | |
*** kebray has quit IRC | 02:23 | |
*** vivek-ebay has joined #openstack-barbican | 02:28 | |
*** vivek-ebay has quit IRC | 02:28 | |
*** nkinder has quit IRC | 03:03 | |
*** vivek-ebay has joined #openstack-barbican | 03:37 | |
*** vivek-eb_ has joined #openstack-barbican | 03:43 | |
*** vivek-ebay has quit IRC | 03:43 | |
*** tkelsey has joined #openstack-barbican | 04:12 | |
*** tkelsey has quit IRC | 04:17 | |
openstackgerrit | Dave McCowan proposed openstack/barbican: Implement Models and Repositories for Resource Quotas https://review.openstack.org/205894 | 04:19 |
---|---|---|
*** dave-mccowan has quit IRC | 04:22 | |
*** vivek-ebay has joined #openstack-barbican | 04:35 | |
*** vivek-eb_ has quit IRC | 04:38 | |
pksingh | rm_work: Hi, are you around? | 04:55 |
rm_work | pksingh: yeah | 04:59 |
rm_work | what's up? | 04:59 |
pksingh | rm_work: can you look into http://paste.openstack.org/show/422402/ please | 04:59 |
pksingh | rm_work: exceptions raised in py27 and py34 are different for this case | 05:00 |
rm_work | lol | 05:03 |
rm_work | weird | 05:03 |
rm_work | so let's see | 05:03 |
rm_work | I am guessing in py27, binascii.Error doesn't exist? | 05:03 |
* rm_work checks for himself | 05:03 | |
pksingh | yes i think so | 05:03 |
pksingh | do i need to handle all exception in validator instead of TypeError? | 05:04 |
rm_work | possibly :/ | 05:06 |
rm_work | that would be the easiest | 05:07 |
rm_work | even though catching just Exception is discouraged | 05:07 |
rm_work | at least you have a valid reason for it? | 05:07 |
pksingh | yes | 05:07 |
rm_work | so, see what other projects have done: | 05:08 |
rm_work | http://pcf-decrypt.readthedocs.org/en/latest/_modules/pcf_decrypt.html | 05:08 |
rm_work | they do a quick version check, and set up which error they look for | 05:09 |
rm_work | probably that is cleaner | 05:09 |
pksingh | ok let me check | 05:10 |
rm_work | except DecodeError: | 05:10 |
rm_work | since it will be the correct type | 05:10 |
pksingh | yes thanks, it seems good idea | 05:10 |
pksingh | i will do in same way, i think it should be OK | 05:11 |
rm_work | yeah, should be fine | 05:12 |
pksingh | thanks , you saved my time . great :) | 05:12 |
rm_work | np, back to figuring out someone else's issue too :P | 05:14 |
rm_work | *another someone else's | 05:14 |
rm_work | for some reason it's usually more interesting than doing my own work <_< | 05:15 |
*** vivek-ebay has quit IRC | 05:37 | |
openstackgerrit | Pradeep Kumar Singh proposed openstack/barbican: Make barbican.tests.api.controllers.test_secrets py3 compatible https://review.openstack.org/214963 | 05:58 |
openstackgerrit | Pradeep Kumar Singh proposed openstack/barbican: Make barbican.tests.api.controllers.test_secrets py3 compatible https://review.openstack.org/214963 | 06:08 |
*** tkelsey has joined #openstack-barbican | 06:30 | |
*** tkelsey has quit IRC | 06:35 | |
*** Nirupama has joined #openstack-barbican | 07:03 | |
*** shohel has joined #openstack-barbican | 07:04 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Updated from global requirements https://review.openstack.org/214988 | 07:15 |
*** nickrmc83 has quit IRC | 08:24 | |
*** nickrmc83 has joined #openstack-barbican | 08:24 | |
*** tkelsey has joined #openstack-barbican | 08:27 | |
*** everjeje has joined #openstack-barbican | 08:30 | |
*** tkelsey has quit IRC | 08:39 | |
*** tkelsey has joined #openstack-barbican | 08:45 | |
*** tkelsey has quit IRC | 08:49 | |
*** mmdurrant has quit IRC | 10:09 | |
*** woodster_ has joined #openstack-barbican | 11:48 | |
*** alee_getting_kid has quit IRC | 11:56 | |
*** mmdurrant has joined #openstack-barbican | 11:58 | |
*** chlong has joined #openstack-barbican | 12:46 | |
*** dave-mccowan has joined #openstack-barbican | 12:52 | |
*** chlong has quit IRC | 13:00 | |
*** everjeje has quit IRC | 13:02 | |
*** chlong has joined #openstack-barbican | 13:04 | |
*** alee_ has joined #openstack-barbican | 13:16 | |
*** kfarr has joined #openstack-barbican | 13:19 | |
*** jamielennox is now known as jamielennox|away | 13:30 | |
*** Nirupama has quit IRC | 13:58 | |
*** SheenaG1 has left #openstack-barbican | 14:04 | |
*** jlhinson has joined #openstack-barbican | 14:11 | |
*** rellerreller has joined #openstack-barbican | 14:16 | |
*** spotz_zzz is now known as spotz | 14:20 | |
dave-mccowan | rellerreller thanks for the review! | 14:30 |
dave-mccowan | rellerreller the next two are smaller, if you want to keep rolling: https://review.openstack.org/212967 and https://review.openstack.org/212876 | 14:31 |
rellerreller | dave-mccowan I can probably get to those tomorrow. I'm supposed to work on my other project today. | 14:33 |
alee_ | redrobot, ping | 14:38 |
alee_ | redrobot, jvrbanac - how does one turn on logging in the client? | 14:39 |
alee_ | that is debug logging .. I have a setup where I have volume encryptiom and I see that there are calls being made in cinder through the barbican client that are failing | 14:40 |
alee_ | trying to figure out why... | 14:41 |
*** zz_dimtruck is now known as dimtruck | 14:49 | |
*** pglass has joined #openstack-barbican | 15:02 | |
*** ccneill has joined #openstack-barbican | 15:04 | |
*** pglbutt has joined #openstack-barbican | 15:04 | |
*** ccneill_ has joined #openstack-barbican | 15:06 | |
*** pglass has quit IRC | 15:07 | |
*** ccneill has quit IRC | 15:09 | |
*** ccneill_ is now known as ccneill | 15:12 | |
*** xaeth_afk is now known as xaeth | 15:16 | |
*** shohel has quit IRC | 15:16 | |
*** kfox1111 has quit IRC | 15:19 | |
*** everjeje has joined #openstack-barbican | 15:38 | |
*** arunkant_ has joined #openstack-barbican | 15:39 | |
*** kebray has joined #openstack-barbican | 15:44 | |
*** darrenmoffat has quit IRC | 15:47 | |
*** darrenmoffat has joined #openstack-barbican | 15:48 | |
alee_ | redrobot, rellerreller , jvrbanac ping | 15:48 |
redrobot | alee_ pong | 15:49 |
alee_ | redrobot, hey - how do I confirm that my barbican instance is working with keystone? | 15:49 |
redrobot | alee_ I usually send an unauthenticated request to a route that requires auth to verify the 401, then try the same call with a token procured from the configured keystone. | 15:50 |
alee_ | redrobot, as far as I understand, the only config I need to do is ==> pipeline = keystone_authtoken context apiapp , right? | 15:50 |
redrobot | alee_ the keystone instance needs to have the admin account used for verification (configured in barbican conf) | 15:51 |
alee_ | the user with barbican/orange ? | 15:51 |
redrobot | alee_ so a prereq is running https://github.com/openstack/barbican/blob/master/bin/keystone_data.sh | 15:51 |
redrobot | alee_ yeah, the above linked bash script should create the barbican/orange user | 15:51 |
alee_ | ah wait -- I may have chnges things there .. | 15:51 |
alee_ | redrobot, so just to verify .. | 15:53 |
alee_ | I can do .. openstack token issue | 15:53 |
alee_ | then take the project_id returned? | 15:53 |
alee_ | and use that in the request ? | 15:53 |
redrobot | I'm not familiar with the openstackclient cli (shame on me) | 15:54 |
redrobot | I usually use the keystone cli | 15:54 |
* redrobot makes a note to upgrade to openstackclient | 15:54 | |
redrobot | assuming openstack cli is configured with one of the users provisioned by keystone_data.sh, then the token should include the correct roles to access barbican | 15:54 |
redrobot | alee_ you should get a token_id, not a project_id | 15:55 |
alee_ | hmm .. | 15:57 |
redrobot | then the token can be used in the "X-Auth-Token: {token_here}" header | 15:57 |
alee_ | redrobot, the user must have the creator role? | 16:00 |
alee_ | to store/gen secrets? | 16:00 |
redrobot | alee_ creator or admin | 16:00 |
openstackgerrit | Merged openstack/barbican: Introduce the key-manager:service-admin role https://review.openstack.org/213570 | 16:01 |
alee_ | redrobot, I'm using admin .. | 16:01 |
redrobot | alee_ not sure how to verify this in openstackclient, but you should ensure you're getting a scoped token. | 16:02 |
redrobot | alee_ if you do the req to keystone directly, you should include the project you're scoping to, so that the produced token is scoped | 16:02 |
redrobot | alee_ unscoped tokens will always 401 | 16:03 |
alee_ | redrobot, hmm .. maybe thats it .. looking | 16:03 |
*** tkelsey has joined #openstack-barbican | 16:04 | |
kfarr | redrobot, did you see the comments on the global requirements Castellan patch from 'lifeless'? https://review.openstack.org/#/c/184874/ | 16:08 |
kfarr | redrobot, I could write the updates lifeless is requesting, but I'm not sure what he means | 16:09 |
redrobot | kfarr looking | 16:13 |
redrobot | kfarr ah yes... he's asking us to set up the automated jobs that submit globa-requirements changes to castellan | 16:14 |
kfarr | redrobot, is that an easy thing to do? I'm looking at project-config, but I'm not immediately seeing how to do it | 16:15 |
dave-mccowan | kfarr in zuul/layout.yaml add a "check-requirements" line like other projects have. | 16:16 |
redrobot | kfarr shouldn't be too hard to do... let me see if I can get a patch set up | 16:16 |
kfarr | ok thanks dave-mccowan and redrobot! | 16:17 |
openstackgerrit | Chelsea Winfree proposed openstack/barbican: Add PUT support for generic container types https://review.openstack.org/207249 | 16:22 |
*** vivek-ebay has joined #openstack-barbican | 16:27 | |
redrobot | kfarr should be good to go now | 16:32 |
redrobot | kfarr https://review.openstack.org/#/c/215225/ | 16:33 |
redrobot | kfarr also updated https://review.openstack.org/#/c/184874/ | 16:33 |
dave-mccowan | chellygel ping | 16:35 |
elmiko | redrobot, kfarr, i took a stab at adding a little more usage documentation for castellan https://review.openstack.org/#/c/214827/ | 16:36 |
redrobot | elmiko LGTM! | 16:39 |
elmiko | \o/ | 16:40 |
*** tkelsey has quit IRC | 16:42 | |
alee_ | redrobot, can you tell me what command you use to get a scoped token? | 16:44 |
kfarr | Thanks redrobot!! | 16:48 |
kfarr | elmiko, I'll take a look! | 16:48 |
alee_ | redrobot, ? | 16:49 |
chellygel | dave-mccowan, pong | 16:51 |
chellygel | leaving shortly! | 16:51 |
dave-mccowan | chellygel... i think i answered my question. i added more comments to your review. | 16:52 |
chellygel | awesome, okay | 16:53 |
chellygel | thanks, i'll take a look and update | 16:53 |
dave-mccowan | chellygel cool. if i guessed wrong, you can let me know in gerrit. :-) | 16:53 |
dave-mccowan | alee_ here's one way to do it with curl and keystone v2: curl -d '{"auth": {"tenantName": "service", "passwordCredentials": {"username": "barbican", "password": "orange"}}}' -H "Content-type: application/json" http://192.168.59.110:5000/v2.0/tokens | 16:54 |
redrobot | alee_ sorry, stepped away to grab some food. ^^ is correct, though you should probably add -H "Accept: application/json" as well. | 16:55 |
arunkant_ | alee, you can look in keystone curl examples ..http://docs.openstack.org/developer/keystone/api_curl_examples.html | 16:58 |
alee_ | dave-mccowan, redrobot , arunkant thanks | 17:01 |
*** tkelsey has joined #openstack-barbican | 17:02 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Updated from global requirements https://review.openstack.org/214988 | 17:04 |
alee_ | redrobot, ok - it looks like I am in fact getting scoped tokens | 17:09 |
alee_ | redrobot, but even so, auth is not working -- getting auth required | 17:11 |
alee_ | redrobot, what do I need to do to make barbican talk to keystione? | 17:11 |
*** edtubill has joined #openstack-barbican | 17:11 | |
*** dimtruck is now known as zz_dimtruck | 17:13 | |
redrobot | everything should be in that paste.ini | 17:13 |
redrobot | alee_ ^^ | 17:13 |
*** zz_dimtruck is now known as dimtruck | 17:19 | |
kfarr | redrobot, there's a comment on the python-barbicanclient release patch saying that the release team doesn't have permissions to create the release https://review.openstack.org/#/c/214280/ :/ | 17:29 |
kfarr | Should I just follow this instead? http://docs.openstack.org/infra/manual/creators.html#tagging-a-release | 17:29 |
redrobot | kfarr no, I was talking to a relmgr in the #openstack-relmgr-office channel, and it seems we still need more configuration on our end | 17:30 |
redrobot | kfarr I should have a patch to project-config soon | 17:31 |
kfarr | redrobot, Ok, I'll +1 it :) | 17:31 |
*** rellerreller has quit IRC | 17:33 | |
*** edtubill has left #openstack-barbican | 17:36 | |
*** kebray has quit IRC | 17:36 | |
*** gyee has joined #openstack-barbican | 18:00 | |
*** gyee has quit IRC | 18:00 | |
*** gyee has joined #openstack-barbican | 18:03 | |
*** kebray has joined #openstack-barbican | 18:04 | |
*** tkelsey has quit IRC | 18:10 | |
redrobot | kfarr https://review.openstack.org/#/c/215269/ | 18:16 |
*** dave-mcc_ has joined #openstack-barbican | 18:36 | |
*** dave-mccowan has quit IRC | 18:39 | |
*** vivek-ebay has quit IRC | 18:49 | |
*** vivek-ebay has joined #openstack-barbican | 18:49 | |
*** ccneill has quit IRC | 18:56 | |
*** ccneill has joined #openstack-barbican | 19:05 | |
*** tkelsey has joined #openstack-barbican | 19:13 | |
*** tkelsey has quit IRC | 19:18 | |
*** woodster_ has quit IRC | 19:27 | |
*** jamielennox|away has quit IRC | 19:27 | |
*** DuncanT has quit IRC | 19:28 | |
*** ryanpetrello has quit IRC | 19:28 | |
*** dave-mccowan has joined #openstack-barbican | 19:30 | |
chellygel | dave-mccowan, ping ? | 19:30 |
dave-mccowan | chellygel pong | 19:30 |
chellygel | for the 409 message i was thinking, "Only generic containers can be modified. This container type is not mutable" | 19:30 |
chellygel | sound good to you? | 19:30 |
dave-mccowan | chellygel yep | 19:31 |
*** DuncanT has joined #openstack-barbican | 19:31 | |
*** woodster_ has joined #openstack-barbican | 19:31 | |
*** rm_work is now known as rm_work|away | 19:32 | |
*** dave-mcc_ has quit IRC | 19:33 | |
*** ryanpetrello has joined #openstack-barbican | 19:36 | |
woodster_ | alee_: just noticed your messages...this CR gives more info on setting up Keystone: https://review.openstack.org/#/c/169114/ | 19:40 |
*** jamielennox|away has joined #openstack-barbican | 19:47 | |
*** jamielennox|away is now known as jamielennox | 19:47 | |
alee_ | woodster_, thanks -- actually I got it set up -- what was missing was that I had keystone set up with https: instead of http: | 19:50 |
alee_ | woodster_, so I confirmed now that my barbican works with keystone. now trying to figure out why its not working with cinder | 19:50 |
alee_ | that is cinder -> barbican through keystone | 19:50 |
openstackgerrit | Dave McCowan proposed openstack/barbican: Implement Models and Repositories for Resource Quotas https://review.openstack.org/205894 | 19:50 |
alee_ | for volume encryption | 19:51 |
*** ryanpetrello has quit IRC | 19:52 | |
*** ryanpetrello has joined #openstack-barbican | 19:55 | |
kfarr | alee_ what part is failing? | 19:58 |
alee_ | kfarr, actually -- I got a little further by specifying encryption_auth_url = https://openstack.alee.test:5000/v3 in the keymgr section of cinder.conf | 19:59 |
alee_ | kfarr, now I can see the request actually going to barbican and the kra | 20:00 |
kfarr | alee_ are you using devstack? | 20:00 |
alee_ | and am now confounded by a mismatch between my barbicanclient and the server version | 20:00 |
alee_ | kfarr, packstack | 20:00 |
alee_ | kfarr, its getting there though | 20:01 |
alee_ | redrobot, if I'm using kilo/stable for my server, which version of barbicanclient should I use? | 20:02 |
kfarr | alee_ ok I have not used packstack before, I wish I could help you more with the debugging | 20:03 |
alee_ | kfarr, no worries -- its getting there -- now at least cinder is talking to barbican which is talking to the kra | 20:04 |
kfarr | I think for nova you're going to need to override the barbican url in the config file, too | 20:04 |
alee_ | kfarr, most likely yup | 20:08 |
alee_ | trying latest barbicanclient now .. | 20:08 |
openstackgerrit | Dave McCowan proposed openstack/barbican: Add Quota Enforcement API https://review.openstack.org/212967 | 20:17 |
openstackgerrit | Merged openstack/barbican: Updated from global requirements https://review.openstack.org/214988 | 20:20 |
*** rellerreller has joined #openstack-barbican | 20:51 | |
openstackgerrit | Chelsea Winfree proposed openstack/barbican: Add PUT support for generic container types https://review.openstack.org/207249 | 20:52 |
*** rm_work|away is now known as rm_work | 21:13 | |
*** pglbutt has quit IRC | 21:13 | |
*** xaeth is now known as xaeth_afk | 21:14 | |
*** kebray has quit IRC | 21:17 | |
*** xaeth_afk is now known as xaeth | 21:23 | |
*** rellerreller has quit IRC | 21:43 | |
*** alee_ has quit IRC | 21:47 | |
*** redrobot changes topic to "OpenStack Barbican Development - next milestone liberty-3 on Sept 1-3" | 21:52 | |
*** xaeth is now known as xaeth_afk | 22:15 | |
*** xaeth_afk is now known as xaeth | 22:25 | |
*** chlong has quit IRC | 22:25 | |
*** spotz is now known as spotz_zzz | 22:35 | |
*** kfarr has quit IRC | 22:38 | |
*** alee_ has joined #openstack-barbican | 22:48 | |
*** darrenmoffat has quit IRC | 22:56 | |
*** darrenmoffat has joined #openstack-barbican | 22:58 | |
*** rm_work is now known as rm_work|away | 23:01 | |
*** jlhinson has quit IRC | 23:03 | |
*** arunkant_ has quit IRC | 23:13 | |
*** ccneill has quit IRC | 23:32 | |
*** dimtruck is now known as zz_dimtruck | 23:33 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!