openstackgerrit | Merged openstack/barbican: Use environmental variables for NewRelic https://review.openstack.org/220865 | 00:06 |
---|---|---|
*** su_zhang_ has quit IRC | 00:08 | |
*** everjeje has joined #openstack-barbican | 00:11 | |
*** chlong has joined #openstack-barbican | 00:22 | |
*** vivek-ebay has quit IRC | 00:29 | |
*** vivek-ebay has joined #openstack-barbican | 00:32 | |
*** vivek-ebay has quit IRC | 00:32 | |
*** zz_dimtruck is now known as dimtruck | 00:35 | |
*** gyee has quit IRC | 00:59 | |
*** dimtruck is now known as zz_dimtruck | 01:06 | |
*** woodster_ has quit IRC | 01:19 | |
*** vivek-ebay has joined #openstack-barbican | 01:25 | |
*** su_zhang_ has joined #openstack-barbican | 01:26 | |
*** su_zhang_ has quit IRC | 01:30 | |
*** vivek-ebay has quit IRC | 01:31 | |
*** zz_dimtruck is now known as dimtruck | 01:33 | |
*** vivek-ebay has joined #openstack-barbican | 01:34 | |
*** vivek-ebay has quit IRC | 01:39 | |
*** dimtruck is now known as zz_dimtruck | 01:42 | |
openstackgerrit | Merged openstack/python-barbicanclient: Fix incorrect error when performing Barbican Secret Update https://review.openstack.org/228720 | 01:49 |
*** nelsnelson has quit IRC | 01:51 | |
*** nelsnelson has joined #openstack-barbican | 01:52 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-barbicanclient: Updated from global requirements https://review.openstack.org/226846 | 01:58 |
*** nelsnelson has quit IRC | 02:05 | |
*** nelsnelson has joined #openstack-barbican | 02:05 | |
*** jhfeng has joined #openstack-barbican | 02:12 | |
*** dave-mccowan has quit IRC | 02:14 | |
*** chlong has quit IRC | 02:27 | |
*** chlong has joined #openstack-barbican | 02:42 | |
*** nelsnelson has quit IRC | 02:44 | |
*** nelsnelson has joined #openstack-barbican | 02:46 | |
*** stevemar has joined #openstack-barbican | 02:54 | |
*** edtubill has joined #openstack-barbican | 02:58 | |
*** stevemar has quit IRC | 02:59 | |
*** nelsnelson has quit IRC | 03:02 | |
*** silos has joined #openstack-barbican | 03:03 | |
*** edtubill has quit IRC | 03:04 | |
*** kebray has joined #openstack-barbican | 03:07 | |
*** kebray has quit IRC | 03:09 | |
*** kebray has joined #openstack-barbican | 03:10 | |
*** silos has left #openstack-barbican | 03:18 | |
*** stevemar_ has joined #openstack-barbican | 03:28 | |
*** stevemar_ has quit IRC | 03:41 | |
*** stevemar has joined #openstack-barbican | 03:42 | |
*** nelsnelson has joined #openstack-barbican | 03:51 | |
*** xaeth_afk is now known as xaeth | 04:02 | |
*** stevemar_ has joined #openstack-barbican | 04:07 | |
*** stevemar has quit IRC | 04:09 | |
*** vivek-ebay has joined #openstack-barbican | 04:10 | |
*** jaosorior has joined #openstack-barbican | 04:25 | |
*** stevemar has joined #openstack-barbican | 04:34 | |
*** stevemar_ has quit IRC | 04:34 | |
*** stevemar has quit IRC | 04:39 | |
*** jhfeng has quit IRC | 04:46 | |
*** stevemar has joined #openstack-barbican | 04:50 | |
*** nelsnelson has quit IRC | 04:55 | |
*** stevemar has quit IRC | 05:05 | |
*** stevemar has joined #openstack-barbican | 05:06 | |
*** mragupat has joined #openstack-barbican | 05:06 | |
*** stevemar has quit IRC | 05:10 | |
*** xaeth is now known as xaeth_afk | 05:11 | |
*** vivek-ebay has quit IRC | 05:22 | |
openstackgerrit | Christopher Solis proposed openstack/barbican: Update Devstack documentation https://review.openstack.org/230276 | 05:37 |
*** su_zhang_ has joined #openstack-barbican | 05:43 | |
*** stevemar has joined #openstack-barbican | 05:50 | |
*** stevemar_ has joined #openstack-barbican | 05:51 | |
*** nelsnelson has joined #openstack-barbican | 05:51 | |
*** stevemar has quit IRC | 05:55 | |
*** nelsnelson has quit IRC | 05:56 | |
*** su_zhang_ has quit IRC | 06:07 | |
*** jaosorior has quit IRC | 06:14 | |
*** mragupat has quit IRC | 06:30 | |
*** shohel has joined #openstack-barbican | 06:31 | |
*** kebray has quit IRC | 06:45 | |
*** jaosorior has joined #openstack-barbican | 06:48 | |
*** nelsnelson has joined #openstack-barbican | 06:52 | |
*** nelsnelson has quit IRC | 06:57 | |
*** chlong has quit IRC | 07:31 | |
*** openstackgerrit has quit IRC | 07:46 | |
*** openstackgerrit has joined #openstack-barbican | 07:46 | |
*** nelsnelson has joined #openstack-barbican | 07:53 | |
*** nelsnelson has quit IRC | 07:58 | |
*** stevemar_ has quit IRC | 08:01 | |
*** stevemar has joined #openstack-barbican | 08:02 | |
*** stevemar has quit IRC | 08:06 | |
*** jaosorior has quit IRC | 08:58 | |
*** darrenmoffat has quit IRC | 08:59 | |
*** darrenmoffat has joined #openstack-barbican | 09:00 | |
*** jaosorior has joined #openstack-barbican | 09:04 | |
*** openstack has joined #openstack-barbican | 09:21 | |
*** openstackstatus has joined #openstack-barbican | 09:22 | |
*** ChanServ sets mode: +v openstackstatus | 09:22 | |
*** nelsnelson has joined #openstack-barbican | 09:36 | |
*** nelsnelson has quit IRC | 09:41 | |
*** ig0r_ has joined #openstack-barbican | 10:55 | |
*** ig0r_ has quit IRC | 10:56 | |
*** nelsnelson has joined #openstack-barbican | 11:24 | |
*** nelsnelson has quit IRC | 11:29 | |
openstackgerrit | Victor Stinner proposed openstack/barbican: py3: Enable more tests to Python 3.4 https://review.openstack.org/230406 | 12:39 |
*** peter-hamilton has joined #openstack-barbican | 12:51 | |
*** rellerreller has joined #openstack-barbican | 12:53 | |
*** zz_dimtruck is now known as dimtruck | 12:55 | |
*** woodster_ has joined #openstack-barbican | 12:56 | |
*** dave-mccowan has joined #openstack-barbican | 13:00 | |
*** Praston has joined #openstack-barbican | 13:06 | |
*** dimtruck is now known as zz_dimtruck | 13:17 | |
*** peter-hamilton_ has joined #openstack-barbican | 13:31 | |
*** peter-hamilton has quit IRC | 13:34 | |
*** peter-hamilton_ is now known as peter-hamilton | 13:35 | |
*** zz_dimtruck is now known as dimtruck | 13:35 | |
*** nelsnelson has joined #openstack-barbican | 13:49 | |
*** stevemar has joined #openstack-barbican | 13:50 | |
*** stevemar has quit IRC | 13:50 | |
*** peter-hamilton has quit IRC | 13:56 | |
*** dimtruck is now known as zz_dimtruck | 13:59 | |
*** zz_dimtruck is now known as dimtruck | 14:00 | |
*** stevemar has joined #openstack-barbican | 14:02 | |
*** stevemar_ has joined #openstack-barbican | 14:05 | |
*** stevemar has quit IRC | 14:06 | |
*** jhfeng has joined #openstack-barbican | 14:12 | |
*** shohel has quit IRC | 14:16 | |
*** su_zhang_ has joined #openstack-barbican | 14:24 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-barbicanclient: Updated from global requirements https://review.openstack.org/230468 | 14:35 |
*** kfarr has joined #openstack-barbican | 14:37 | |
*** jaosorior has quit IRC | 14:41 | |
*** jaosorior has joined #openstack-barbican | 14:42 | |
*** peter-hamilton has joined #openstack-barbican | 14:42 | |
*** stevemar_ is now known as stevemar | 14:43 | |
*** silos has joined #openstack-barbican | 14:44 | |
*** jaosorior has quit IRC | 14:45 | |
*** jaosorior has joined #openstack-barbican | 14:45 | |
*** vivek-ebay has joined #openstack-barbican | 14:49 | |
*** vivek-ebay has quit IRC | 14:53 | |
redrobot | mornin' alee and dave-mccowan | 14:56 |
* dave-mccowan waves. good morning! | 14:56 | |
*** kebray has joined #openstack-barbican | 14:57 | |
*** edtubill has joined #openstack-barbican | 14:59 | |
redrobot | alee I'm not sure we'll be able to backport the dogtag stuff... the release managers have to approve the backports. :-\ | 15:01 |
alee | redrobot, why not? can we make the case that its needed for magnum? | 15:02 |
redrobot | alee maybe? ... I'll keep you posted. | 15:03 |
alee | redrobot, and that right now at least dogtag is essentially the only production backend for barbican ca plugins | 15:03 |
alee | redrobot, its not like dogtag is a red haired step child .. | 15:04 |
dave-mccowan | also, it's a plugin, with no change to base code. so, very low risk change. and also very important. i consider it security-impact. if snakeoil is the only supported plugin, then we have no secure option. | 15:04 |
alee | redrobot, dave-mccowan agreed - its a plugin on par with the kmip or pkcs11 plugin on the secret side of things. If there were a change that were needed in the pkcs11 plugin, there would be no issue - why would there be an issue now? | 15:08 |
redrobot | alee dave-mccowan just to be clear there is no issue now... just giving you a heads up that the rel mgr has to approve the patches | 15:09 |
*** chlong has joined #openstack-barbican | 15:10 | |
alee | redrobot, ok - although I would think they would defer to the PTL's judgement | 15:10 |
dave-mccowan | redrobot cool. anything you need from us? | 15:11 |
*** xaeth_afk is now known as xaeth | 15:13 | |
rellerreller | alee careful with the red haired comments :) I'm reading the logs now. | 15:22 |
alee | rellerreller, I stand corrected -- red haired stepchildren are awesome :) | 15:23 |
rellerreller | alee :) | 15:24 |
*** ccneill has joined #openstack-barbican | 15:25 | |
*** vivek-ebay has joined #openstack-barbican | 15:27 | |
*** kfarr_ has joined #openstack-barbican | 15:31 | |
*** jmckind has joined #openstack-barbican | 15:34 | |
*** spotz_zzz is now known as spotz | 15:34 | |
*** kfarr has quit IRC | 15:35 | |
*** mixos has joined #openstack-barbican | 15:45 | |
*** jmckind has quit IRC | 15:56 | |
*** su_zhang_ has quit IRC | 15:58 | |
*** jhfeng_ has joined #openstack-barbican | 16:00 | |
*** silos1 has joined #openstack-barbican | 16:01 | |
*** jhfeng has quit IRC | 16:02 | |
*** silos has quit IRC | 16:04 | |
*** jaosorior has quit IRC | 16:09 | |
*** vivek-ebay has quit IRC | 16:16 | |
dave-mccowan | redrobot ping | 16:22 |
redrobot | dave-mccowan pong | 16:22 |
dave-mccowan | redrobot do you need a bug associated with the dogtag patch for it to backport? | 16:23 |
redrobot | dave-mccowan yeah | 16:23 |
*** dimtruck is now known as zz_dimtruck | 16:23 | |
*** jhfeng_ has quit IRC | 16:23 | |
*** jhfeng has joined #openstack-barbican | 16:44 | |
*** jhfeng has quit IRC | 16:45 | |
*** jhfeng has joined #openstack-barbican | 16:49 | |
*** diazjf has joined #openstack-barbican | 16:51 | |
*** jhfeng has quit IRC | 17:03 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Add name to Castellan Objects and Barbican Key Manager https://review.openstack.org/220850 | 17:04 |
*** vivek-ebay has joined #openstack-barbican | 17:05 | |
*** jhfeng has joined #openstack-barbican | 17:07 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Updated from global requirements https://review.openstack.org/230560 | 17:15 |
*** su_zhang_ has joined #openstack-barbican | 17:17 | |
*** vivek-ebay has quit IRC | 17:18 | |
*** vivek-ebay has joined #openstack-barbican | 17:20 | |
*** nelsnelson has quit IRC | 17:25 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Add name to Castellan Objects and Barbican Key Manager https://review.openstack.org/220850 | 17:40 |
*** darrenmoffat has quit IRC | 17:45 | |
rellerreller | kfarr_ ping | 17:47 |
*** kfarr_ has quit IRC | 17:49 | |
*** gyee has joined #openstack-barbican | 17:50 | |
*** kfarr has joined #openstack-barbican | 17:52 | |
kfarr | rellerreller, here! | 17:52 |
rellerreller | kfarr I had note in diazjf review of 220850 | 17:54 |
rellerreller | kfarr should the equals method in subclasses use self._name or self.name? | 17:54 |
kfarr | rellerreller, about the private variables? | 17:55 |
rellerreller | kfarr I feel like self.name because it is a property of parent class, but this is probably more style than substance. | 17:55 |
rellerreller | kfarr yes | 17:55 |
*** jhfeng has quit IRC | 17:56 | |
rellerreller | I think this will be the last issue before diazjf can merge his feature. | 17:56 |
diazjf | rellerreller, kfarr, thanks for all the help reviewing this | 17:56 |
kfarr | rellerreller, I think it's fine using the private attributes! | 17:57 |
kfarr | diazjf thanks for all the the help contributing code! | 17:57 |
diazjf | kfarr, my pleasure. | 17:58 |
diazjf | rellerreller, so all thats left is modifiying test __eq__ for all objects? | 17:59 |
rellerreller | kfarr sounds good | 17:59 |
rellerreller | diazjf that's it | 17:59 |
rellerreller | diazjf fix that and then we can merge. | 17:59 |
diazjf | rellerreller, awesome, I'll hgave something up after some coffeeeeee | 17:59 |
diazjf | thanks | 17:59 |
*** nelsnelson has joined #openstack-barbican | 18:00 | |
*** jhfeng has joined #openstack-barbican | 18:01 | |
*** darrenmoffat has joined #openstack-barbican | 18:09 | |
*** vivek-ebay has quit IRC | 18:27 | |
*** diazjf has quit IRC | 18:35 | |
*** su_zhang_ has quit IRC | 18:36 | |
*** su_zhang_ has joined #openstack-barbican | 18:37 | |
*** vivek-ebay has joined #openstack-barbican | 18:38 | |
*** zz_dimtruck is now known as dimtruck | 18:39 | |
*** kfarr has quit IRC | 18:39 | |
*** peter-hamilton has quit IRC | 18:39 | |
*** vivek-ebay has quit IRC | 18:43 | |
*** su_zhang_ has quit IRC | 18:43 | |
*** su_zhang_ has joined #openstack-barbican | 18:44 | |
*** mixos has quit IRC | 18:45 | |
*** everjeje has quit IRC | 18:50 | |
silos1 | rellerreller: ping | 18:52 |
rellerreller | silos1 pong | 18:52 |
silos1 | rellerreller: Is there documentation on how to setup castellan using barbican? | 18:52 |
rm_work | it should be as simple as setting the config values for castellan to use the barbican driver | 18:53 |
rm_work | and having barbican running | 18:53 |
rellerreller | silos1 I am not sure. kfarr is the best person for that. | 18:53 |
silos1 | rellerreller, rm_work: Ah ok. Thanks. | 18:53 |
rellerreller | rm_work silos1 you will also need to configure the barbican plugin to wherever keystone and barbican are running. | 18:53 |
*** vivek-ebay has joined #openstack-barbican | 18:54 | |
rm_work | ah yes | 18:54 |
rm_work | I assume there should be sane defaults for that, at least for devstack | 18:54 |
rm_work | that can just be updated | 18:54 |
rellerreller | Yes, I think there are some defaults or comments on what to put there. | 18:54 |
silos1 | rellerreller, rm_work: Ok thanks. I'll dig around for those then. | 18:55 |
*** diazjf has joined #openstack-barbican | 18:55 | |
*** Praston has quit IRC | 19:00 | |
*** everjeje has joined #openstack-barbican | 19:03 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Add name to Castellan Objects and Barbican Key Manager https://review.openstack.org/220850 | 19:07 |
diazjf | rellerreller, kfarr, should be all good to go. | 19:07 |
*** peter-hamilton has joined #openstack-barbican | 19:08 | |
diazjf | dave-mccowan, I'm gonna work on getting a non-draft version of https://review.openstack.org/#/c/229995/ up by Monday. Any suggestions? | 19:08 |
*** jmckind has joined #openstack-barbican | 19:12 | |
*** su_zhang_ has quit IRC | 19:20 | |
*** su_zhang_ has joined #openstack-barbican | 19:21 | |
dave-mccowan | diazjf from a rules or policy perspective, we should definitely find a way to make it flexible and extensible. your blueprint mentions geography based rules; mine mentions time and count based rules. i don't have any specific ideas on how to do that though. :- | 19:23 |
rellerreller | diazjf you are not going to like this but I found an issue with the testing code. | 19:23 |
rellerreller | diazjf I left instructions on how to fix it. It's not your fault. We missed the issue before, and you built on top of it. | 19:23 |
rellerreller | diazjf It should be a quick fix, but I was hoping to land your patch now. | 19:24 |
rellerreller | kfarr see the note on the review that I left. We need to patch the test__ne__ tests. | 19:25 |
diazjf | rellerreller, yeah that makes perfect sense, it seemed a little weird to me. | 19:25 |
rellerreller | diazjf the good news is that it will be a quick fix. I want this patch. I like the name attribute. | 19:26 |
diazjf | dave-mccowan, the idea behind it would be for the user to define their own metadata that way it can be used for anything. Kinda like metadata in swift containers, etc. | 19:26 |
diazjf | rellerreller, I'm glad! | 19:27 |
*** alee has quit IRC | 19:27 | |
*** alee has joined #openstack-barbican | 19:27 | |
dave-mccowan | diazjf if that's the extent of it, then couldn't a user could put his own JSON in the existing description field? did I read too much into your blueprint? i thought you were proposing enforcing access based on the contents of meta data. | 19:30 |
*** stevemar has quit IRC | 19:35 | |
*** david-lyle has quit IRC | 19:35 | |
diazjf | dave-mccowan, currently for a secret there is no description or anything a user can manipulate, other than name. Since user metadata is edittable the user can write services to allow/disallow certain secrets from being access based on metadata. I'll add a couple of use cases | 19:35 |
*** david-lyle has joined #openstack-barbican | 19:35 | |
*** nelsnelson has quit IRC | 19:37 | |
diazjf | dave-mccowan, its very useful for access control since a user can pretty much create their own access control | 19:39 |
diazjf | based of anything | 19:40 |
diazjf | any suggestions | 19:40 |
*** su_zhan__ has joined #openstack-barbican | 19:40 | |
dave-mccowan | diazjf got it. interesting approach (building services outside of barbican)... that does seem like a good way to create a policy engine that can be both flexible and extensible. i had thought there was a description field for secrets, but there isn't. i wonder what i was thinking about. :-) | 19:41 |
*** rellerreller has quit IRC | 19:41 | |
*** su_zha___ has joined #openstack-barbican | 19:44 | |
*** su_zha___ has quit IRC | 19:44 | |
*** su_zhang_ has quit IRC | 19:44 | |
diazjf | dave-mccowan, thanks, I'm excited on adding this feature. | 19:44 |
*** su_zhan__ has quit IRC | 19:44 | |
*** david-ly_ has joined #openstack-barbican | 19:45 | |
*** david-lyle has quit IRC | 19:49 | |
*** david-ly_ has quit IRC | 19:49 | |
redrobot | dave-mccowan did you open a bug for the dogtag plugin? | 19:51 |
*** peter-hamilton has quit IRC | 19:51 | |
dave-mccowan | no, i didn't. alee? i can if you want. | 19:52 |
dave-mccowan | redrobot doing it now. | 19:53 |
alee | dave-mccowan, thanks | 19:55 |
dave-mccowan | https://bugs.launchpad.net/barbican/+bug/1502320 | 19:55 |
openstack | Launchpad bug 1502320 in Barbican "Need Secure Plugin for SubCA Feature" [Undecided,New] | 19:55 |
redrobot | dave-mccowan thanks! | 19:56 |
*** su_zhang_ has joined #openstack-barbican | 19:57 | |
*** mixos has joined #openstack-barbican | 19:59 | |
*** silos1 has left #openstack-barbican | 20:00 | |
*** jhfeng has quit IRC | 20:10 | |
*** david-lyle has joined #openstack-barbican | 20:24 | |
*** kebray has quit IRC | 20:26 | |
openstackgerrit | Merged openstack/barbican: Updated from global requirements https://review.openstack.org/230560 | 20:26 |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Add name to Castellan Objects and Barbican Key Manager https://review.openstack.org/220850 | 20:30 |
*** vivek-ebay has quit IRC | 20:30 | |
*** ccneill has quit IRC | 20:38 | |
*** ccneill has joined #openstack-barbican | 20:44 | |
openstackgerrit | Merged openstack/barbican: py3: Enable more tests to Python 3.4 https://review.openstack.org/230406 | 20:50 |
openstackgerrit | Merged openstack/barbican: Fix db_manage to initialize mysql from base https://review.openstack.org/228718 | 20:50 |
*** dimtruck is now known as zz_dimtruck | 21:03 | |
*** jhfeng has joined #openstack-barbican | 21:08 | |
*** stevemar has joined #openstack-barbican | 21:12 | |
*** jmckind_ has joined #openstack-barbican | 21:12 | |
*** su_zhang_ has quit IRC | 21:14 | |
*** jmckind has quit IRC | 21:15 | |
*** nelsnelson has joined #openstack-barbican | 21:21 | |
*** vivek-ebay has joined #openstack-barbican | 21:23 | |
*** nelsnelson has quit IRC | 21:23 | |
*** nelsnels_ has joined #openstack-barbican | 21:23 | |
*** jmckind_ has quit IRC | 21:26 | |
*** su_zhang_ has joined #openstack-barbican | 21:38 | |
*** xaeth is now known as xaeth_afk | 21:41 | |
*** edtubill has quit IRC | 21:47 | |
*** diazjf has left #openstack-barbican | 21:50 | |
*** su_zhang_ has quit IRC | 22:00 | |
*** dave-mccowan has quit IRC | 22:08 | |
*** stevemar has quit IRC | 22:14 | |
*** stevemar has joined #openstack-barbican | 22:14 | |
*** mixos has quit IRC | 22:14 | |
*** stevemar has quit IRC | 22:18 | |
*** su_zhang_ has joined #openstack-barbican | 22:26 | |
*** vivek-ebay has quit IRC | 22:27 | |
*** spotz is now known as spotz_zzz | 22:35 | |
*** david-lyle has quit IRC | 22:45 | |
*** david-lyle has joined #openstack-barbican | 22:47 | |
*** ccneill has quit IRC | 23:03 | |
*** gyee has quit IRC | 23:04 | |
*** su_zhang_ has quit IRC | 23:05 | |
*** vivek-ebay has joined #openstack-barbican | 23:08 | |
*** jhfeng has quit IRC | 23:12 | |
*** everjeje has quit IRC | 23:20 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!