*** stevemar_ has joined #openstack-barbican | 00:00 | |
*** stevemar_ has quit IRC | 00:04 | |
*** nelsnelson has joined #openstack-barbican | 00:07 | |
*** edtubill has quit IRC | 00:49 | |
*** gyee has quit IRC | 01:15 | |
openstackgerrit | Merged openstack/python-barbicanclient: README.rst devstack link not properly displayed https://review.openstack.org/235737 | 01:17 |
---|---|---|
*** tkelsey has joined #openstack-barbican | 01:50 | |
*** tkelsey has quit IRC | 01:54 | |
*** stevemar_ has joined #openstack-barbican | 02:02 | |
*** vivek-ebay has quit IRC | 02:06 | |
openstackgerrit | Merged openstack/barbican: Remove old gate code https://review.openstack.org/219451 | 02:18 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-barbicanclient: Updated from global requirements https://review.openstack.org/237316 | 02:32 |
*** dave-mccowan has quit IRC | 02:38 | |
*** morgan has quit IRC | 03:00 | |
*** pksingh has joined #openstack-barbican | 03:01 | |
openstackgerrit | Pradeep Kumar Singh proposed openstack/barbican: Replace assertFalse(a in b) with assertNotIn(a, b) https://review.openstack.org/237864 | 03:45 |
*** Nirupama has joined #openstack-barbican | 04:08 | |
*** yfujioka has joined #openstack-barbican | 04:26 | |
*** jaosorior has quit IRC | 04:48 | |
*** jaosorior has joined #openstack-barbican | 04:48 | |
*** edtubill has joined #openstack-barbican | 05:07 | |
*** openstackgerrit has quit IRC | 05:16 | |
*** morgan has joined #openstack-barbican | 05:16 | |
*** openstackgerrit has joined #openstack-barbican | 05:17 | |
*** stevemar_ has quit IRC | 05:19 | |
*** stevemar_ has joined #openstack-barbican | 05:19 | |
*** stevemar_ has quit IRC | 05:22 | |
*** morgan has quit IRC | 05:45 | |
*** tkelsey has joined #openstack-barbican | 05:52 | |
*** tkelsey has quit IRC | 05:56 | |
*** jaosorior has quit IRC | 06:00 | |
*** jaosorior has joined #openstack-barbican | 06:01 | |
*** morgan has joined #openstack-barbican | 06:01 | |
*** edtubill has quit IRC | 06:07 | |
*** su_zhang has quit IRC | 06:08 | |
*** pksingh_ has joined #openstack-barbican | 06:37 | |
*** jamielennox is now known as jamielennox|away | 06:37 | |
*** pksingh has quit IRC | 06:41 | |
*** jaosorior has quit IRC | 06:47 | |
*** jaosorior has joined #openstack-barbican | 06:48 | |
*** tkelsey has joined #openstack-barbican | 06:58 | |
*** shohel has joined #openstack-barbican | 07:09 | |
*** jaosorior has quit IRC | 07:16 | |
*** jongchoi has joined #openstack-barbican | 07:30 | |
*** jaosorior has joined #openstack-barbican | 07:35 | |
*** jaosorior has quit IRC | 07:37 | |
*** jaosorior has joined #openstack-barbican | 07:37 | |
*** everjeje has joined #openstack-barbican | 08:27 | |
*** jongchoi has quit IRC | 08:48 | |
*** openstackgerrit has quit IRC | 09:01 | |
*** openstackgerrit has joined #openstack-barbican | 09:01 | |
*** openstackgerrit has quit IRC | 09:31 | |
*** openstackgerrit has joined #openstack-barbican | 09:32 | |
*** jkf has quit IRC | 09:59 | |
*** mmdurrant has quit IRC | 10:09 | |
*** jkf has joined #openstack-barbican | 10:18 | |
*** stevemar_ has joined #openstack-barbican | 10:35 | |
*** stevemar_ has quit IRC | 10:38 | |
*** dave-mccowan has joined #openstack-barbican | 10:55 | |
*** markus_z has joined #openstack-barbican | 11:27 | |
markus_z | We have a barbican bug in Nova, maybe someone of you could help out here: https://bugs.launchpad.net/nova/+bug/1505930 | 11:28 |
openstack | Launchpad bug 1505930 in OpenStack Compute (nova) "Fix key manager service endpoints in devstack Nova ephemeral" [Undecided,Incomplete] - Assigned to Max (max-abidi) | 11:28 |
*** pksingh_ has quit IRC | 11:30 | |
dave-mccowan | markus_z i added a comment to the bug with a suggested fix | 11:42 |
markus_z | dave-mccowan: Cool, thanks! | 11:43 |
*** Nirupama has quit IRC | 11:52 | |
*** peter-hamilton has joined #openstack-barbican | 11:54 | |
*** arunkant has quit IRC | 11:57 | |
*** mmdurrant has joined #openstack-barbican | 11:59 | |
*** openstackgerrit has quit IRC | 12:16 | |
*** openstackgerrit has joined #openstack-barbican | 12:17 | |
*** arunkant has joined #openstack-barbican | 12:28 | |
*** rellerreller has joined #openstack-barbican | 12:35 | |
*** stevemar_ has joined #openstack-barbican | 13:03 | |
*** stevemar_ has quit IRC | 13:07 | |
*** stevemar_ has joined #openstack-barbican | 13:09 | |
*** stevemar_ has quit IRC | 13:12 | |
*** stevemar_ has joined #openstack-barbican | 13:17 | |
*** lisaclark1 has joined #openstack-barbican | 13:29 | |
*** stevemar_ has quit IRC | 13:54 | |
*** DTadrzak has quit IRC | 14:00 | |
*** jongchoi has joined #openstack-barbican | 14:08 | |
*** silos has joined #openstack-barbican | 14:11 | |
*** nkinder has quit IRC | 14:14 | |
*** darrenmoffat has quit IRC | 14:17 | |
*** darrenmoffat has joined #openstack-barbican | 14:18 | |
*** jhfeng has joined #openstack-barbican | 14:19 | |
*** diazjf has joined #openstack-barbican | 14:19 | |
*** edtubill has joined #openstack-barbican | 14:26 | |
*** jongchoi has quit IRC | 14:28 | |
*** su_zhang has joined #openstack-barbican | 14:37 | |
*** edtubill has quit IRC | 14:37 | |
*** edtubill has joined #openstack-barbican | 14:38 | |
*** zz_dimtruck is now known as dimtruck | 14:38 | |
*** su_zhang has quit IRC | 14:42 | |
*** lisaclark1 has quit IRC | 14:43 | |
*** alee_afk is now known as alee | 14:45 | |
*** lisaclark1 has joined #openstack-barbican | 14:46 | |
*** jaosorior has quit IRC | 14:47 | |
*** jaosorior has joined #openstack-barbican | 14:48 | |
*** edtubill has quit IRC | 14:52 | |
*** stevemar_ has joined #openstack-barbican | 14:55 | |
*** stevemar_ has quit IRC | 14:56 | |
*** su_zhang has joined #openstack-barbican | 14:58 | |
*** stevemar_ has joined #openstack-barbican | 14:59 | |
*** stevema__ has joined #openstack-barbican | 15:13 | |
*** stevemar_ has quit IRC | 15:16 | |
*** Kiall has quit IRC | 15:19 | |
*** Kiall has joined #openstack-barbican | 15:20 | |
*** ccneill has joined #openstack-barbican | 15:22 | |
*** edtubill has joined #openstack-barbican | 15:24 | |
*** edtubill has quit IRC | 15:26 | |
openstackgerrit | Christopher Solis proposed openstack/barbican: Create Orders Documentation https://review.openstack.org/236123 | 15:26 |
*** edtubill has joined #openstack-barbican | 15:30 | |
*** ccneill has quit IRC | 15:30 | |
*** shohel has quit IRC | 15:33 | |
*** ccneill has joined #openstack-barbican | 15:34 | |
*** markus_z has quit IRC | 15:52 | |
*** edtubill has quit IRC | 15:52 | |
*** edtubill has joined #openstack-barbican | 15:53 | |
*** stevema__ has quit IRC | 16:00 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Add created property to Managed Objects https://review.openstack.org/238150 | 16:03 |
*** su_zhang has quit IRC | 16:17 | |
rm_work | Hey, if you guys could glance at https://review.openstack.org/#/c/237807/ I think it might be relevant <_< | 16:32 |
rm_work | Would appreciate it | 16:32 |
rm_work | We're trying to solve for some use-cases where our Barbican workflow currently has trouble | 16:32 |
*** stevemar_ has joined #openstack-barbican | 16:36 | |
*** stevemar_ has quit IRC | 16:41 | |
dave-mccowan | rm_work with a passphrase requirement, does that mean that a human is required in the workflow to deploy an LB? (to enter the passphrase) | 16:42 |
rm_work | no, it *is* stored, in our DB | 16:42 |
rm_work | so the necessary data to have a decrypted and usable private key is split between two distinct storage systems | 16:43 |
dave-mccowan | how does the passphrase get into the Neutron DB? | 16:44 |
*** gyee has joined #openstack-barbican | 16:45 | |
*** xaeth_afk is now known as xaeth | 16:47 | |
rm_work | dave-mccowan: passed in via API | 16:47 |
*** jaosorior has quit IRC | 16:50 | |
*** jaosorior has joined #openstack-barbican | 16:50 | |
*** diazjf has quit IRC | 16:50 | |
*** edtubill has quit IRC | 16:51 | |
*** zigo_ has quit IRC | 16:59 | |
*** zigo has joined #openstack-barbican | 17:00 | |
*** everjeje has quit IRC | 17:07 | |
*** su_zhang has joined #openstack-barbican | 17:12 | |
*** lisaclark1 has quit IRC | 17:21 | |
*** kfarr has joined #openstack-barbican | 17:23 | |
*** peter-hamilton has quit IRC | 17:28 | |
*** lisaclark1 has joined #openstack-barbican | 17:30 | |
*** xaeth is now known as xaeth_afk | 17:32 | |
*** stevemar_ has joined #openstack-barbican | 17:32 | |
*** lisaclark1 has quit IRC | 17:32 | |
*** rellerreller has quit IRC | 17:34 | |
*** lisaclark1 has joined #openstack-barbican | 17:34 | |
*** lisaclark1 has quit IRC | 17:35 | |
*** tkelsey has quit IRC | 17:53 | |
*** xaeth_afk is now known as xaeth | 17:53 | |
*** lisaclark1 has joined #openstack-barbican | 17:57 | |
*** stevemar_ has quit IRC | 17:58 | |
*** diazjf has joined #openstack-barbican | 18:01 | |
*** edtubill has joined #openstack-barbican | 18:03 | |
diazjf | kfarr, so I added https://review.openstack.org/#/c/238150/ gonna keep working on it throughout the week. Also for https://review.openstack.org/#/c/235671/ I think its the proper way of getting context since user created(non-openstack) services may rely on keystone and not use oslo.context :) | 18:08 |
*** ccneill has quit IRC | 18:19 | |
*** vivek-ebay has joined #openstack-barbican | 18:22 | |
*** vivek-ebay has quit IRC | 18:22 | |
*** xaeth is now known as xaeth_afk | 18:25 | |
*** lisaclark1 has quit IRC | 18:25 | |
*** vivek-ebay has joined #openstack-barbican | 18:27 | |
*** lisaclark1 has joined #openstack-barbican | 18:28 | |
*** xaeth_afk is now known as xaeth | 18:32 | |
kfarr | diazjf, thanks! I will take a look later today | 18:33 |
openstackgerrit | Christopher Solis proposed openstack/barbican: Update Devstack deployment and docs https://review.openstack.org/230276 | 18:34 |
*** rellerreller has joined #openstack-barbican | 18:43 | |
diazjf | kfarr, thanks :) I'll update some of the comments | 18:49 |
silos | woodster_: ping | 18:52 |
*** xaeth is now known as xaeth_afk | 18:53 | |
*** su_zhang has quit IRC | 18:55 | |
woodster_ | silos: hey there | 19:02 |
*** lisaclark1 has quit IRC | 19:03 | |
silos | woodster_: HEY! I'm meandering around the database/sqlalchemy side of barbican and noticed your name a lot and had a question. Does sqlalchemy do any sanity checks for sql injection/user input? | 19:04 |
*** edtubill has quit IRC | 19:04 | |
woodster_ | silos: I believe it does as long as you aren't doing direct sql (which is possible) | 19:05 |
*** lisaclark1 has joined #openstack-barbican | 19:06 | |
*** stevemar_ has joined #openstack-barbican | 19:07 | |
silos | woodster_: hmmm what do you mean as long as you aren't doing direct sql? | 19:07 |
woodster_ | silos: I think it's possible to not use the sqlalchemy classes to hit the databases...so write direct sql to hit the database. We aren't doing that in barbican as far as I know. | 19:08 |
rm_work | yeah sqlalchemy lets you run a pure string query if you tell it to | 19:10 |
rm_work | which obviously won't do any quoting or anything :/ | 19:10 |
rm_work | otherwise it does param binding and such | 19:11 |
silos | woodster_, rm_work: Ah I see. yea. All I have seen is sqlalchemy so far. | 19:11 |
rm_work | http://docs.sqlalchemy.org/en/rel_0_8/core/tutorial.html#using-text | 19:11 |
silos | woodster_, rm_work: thanks! | 19:11 |
rm_work | the example does binding, but you can avoid it, and in doing so, assume the risks associated | 19:12 |
woodster_ | yep! | 19:12 |
rm_work | ah woodster_, should have had you on that last meeting :( | 19:12 |
rm_work | woodster_: did you get a chance to look at my recent spec? https://review.openstack.org/#/c/237807/ | 19:13 |
woodster_ | rm_work: oh was that the clb integration one? | 19:13 |
rm_work | woodster_: related | 19:13 |
rm_work | yes | 19:13 |
*** stevemar_ has quit IRC | 19:15 | |
*** stevemar_ has joined #openstack-barbican | 19:16 | |
*** stevemar_ has quit IRC | 19:20 | |
rm_work | woodster_: just added more comments in response to reaperhulk | 19:20 |
rm_work | err | 19:20 |
rm_work | damnit | 19:20 |
rm_work | in response to redrobot | 19:20 |
rm_work | "re"-tabcomplete is blah | 19:20 |
*** edtubill has joined #openstack-barbican | 19:24 | |
*** edtubill has quit IRC | 19:25 | |
dave-mccowan | rm_work would the same keystone credentials be able to retrieve the passphrase from neutron and the private key from barbican? | 19:25 |
*** edtubill has joined #openstack-barbican | 19:30 | |
*** edtubill has quit IRC | 19:31 | |
rm_work | dave-mccowan: no | 19:38 |
rm_work | dave-mccowan: passphrase would be set-only | 19:38 |
rm_work | I was careful to specify that | 19:38 |
rm_work | neutron-lbaas would never return it | 19:38 |
*** rellerreller has quit IRC | 19:42 | |
*** su_zhang has joined #openstack-barbican | 19:43 | |
dave-mccowan | rm_work i like the idea in general. two-factor==good. but, i'm suspicious at attempts of two-factor auth that doesn't involve a human providing the second factor. | 19:46 |
rm_work | yeah | 19:46 |
dave-mccowan | looks like you're thinking that way too | 19:46 |
rm_work | I try to stay away from calling it "two-factor" explicitly | 19:46 |
rm_work | it's "two-system" | 19:46 |
*** edtubill has joined #openstack-barbican | 19:52 | |
*** xaeth_afk is now known as xaeth | 20:00 | |
dave-mccowan | does anyone know if barbican-client has "stable" versions that are patched? | 20:00 |
redrobot | dave-mccowan yeah, we do have a stable release | 20:00 |
redrobot | dave-mccowan all stable requirements files cap at a max version | 20:01 |
dave-mccowan | i'm trying to think through the issues when devstack does away with extras.d. all releases of our stuff are going to have to work with the new plugin methods. | 20:03 |
dave-mccowan | does the stable barbican client always run with /master barbican? | 20:03 |
redrobot | dave-mccowan good question... I don't know off the top of my head | 20:04 |
redrobot | dave-mccowan I'm thinking that it probably does.... but the new plugin system should be able to check out stable barbicans if needed. | 20:04 |
rm_work | dave-mccowan: yeah it's possible we may need to backport the plugin support :/ | 20:05 |
dave-mccowan | yep. we need to before mitaka-1. how many versions are supposed to support? | 20:05 |
*** openstackstatus has joined #openstack-barbican | 20:06 | |
*** ChanServ sets mode: +v openstackstatus | 20:06 | |
dave-mccowan | sorry, rm_work, we went the wrong way with your patches to project-config. instead of two gate job versions, we should have made all the barbican releases do the new way. | 20:08 |
*** dimtruck is now known as zz_dimtruck | 20:11 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Add testing documentation to Castellan https://review.openstack.org/235699 | 20:11 |
rm_work | dave-mccowan: yeah :( ah well | 20:12 |
rm_work | dave-mccowan: the latest two | 20:12 |
rm_work | so for mitaka that'd be KL | 20:12 |
rm_work | I think | 20:12 |
rm_work | it should be obvious when doing it, it's all baked into project-config | 20:13 |
rm_work | tons of other examples | 20:13 |
*** lisaclark1 has quit IRC | 20:19 | |
*** zz_dimtruck is now known as dimtruck | 20:19 | |
dave-mccowan | redrobot if i want to propose backport bugs in launchpad, do i need to be a member of barbican-drivers? | 20:26 |
rm_work | Can't you PROPOSE anything as a bug? | 20:26 |
*** tkelsey has joined #openstack-barbican | 20:40 | |
*** lisaclark1 has joined #openstack-barbican | 20:42 | |
*** tkelsey has quit IRC | 20:44 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Add contributing documentation to Castellan https://review.openstack.org/238244 | 20:49 |
*** lisaclark1 has quit IRC | 20:52 | |
*** lisaclark1 has joined #openstack-barbican | 20:57 | |
*** silos has left #openstack-barbican | 20:59 | |
*** lisaclark1 has quit IRC | 20:59 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Adds documentation on creating Oslo RequestContext in Castellan https://review.openstack.org/238248 | 21:01 |
redrobot | dave-mccowan I don't think so... but I can add you to that group if need be. | 21:04 |
*** jongchoi_ has joined #openstack-barbican | 21:10 | |
*** stevemar_ has joined #openstack-barbican | 21:11 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Add documentation links and fixup README.rst https://review.openstack.org/238252 | 21:23 |
rm_work | redrobot: responded again... not clear on what better examples i can provide for the vulnerabilities than what I already walked through in the examples | 21:35 |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Add contributing documentation to Castellan https://review.openstack.org/238244 | 21:36 |
*** diazjf has quit IRC | 21:39 | |
rm_work | redrobot: would you rather try to spend some time figuring this out face-to-face instead of throwing replies back and forth over a review? :P | 21:44 |
*** lisaclark1 has joined #openstack-barbican | 21:44 | |
redrobot | rm_work I'm just not so quick to buy into the whole "two systems are better than one" argument. | 21:45 |
rm_work | It's fairly provable | 21:45 |
rm_work | I can demonstrate clear examples on a whiteboard | 21:45 |
rm_work | if you can refute those examples, then maybe i could be swayed? | 21:45 |
redrobot | rm_work my point is this: Barbican was made for secure storage, so you should use it for that. | 21:46 |
rm_work | we are | 21:46 |
redrobot | but you're not | 21:46 |
rm_work | not using it isn't an option | 21:46 |
rm_work | so we are | 21:46 |
rm_work | if we didn't use it, we'd be back to being hosed | 21:46 |
rm_work | so i'd say it's fairly essential in the equation :P | 21:46 |
*** lisaclark1 has quit IRC | 21:46 | |
redrobot | the argument for Barbican has always been to make it THE secret store for OpenStack | 21:47 |
rm_work | yeah, i get that | 21:47 |
rm_work | and I'm sure 90% of people will be happy with the way it functions now | 21:47 |
redrobot | rm_work for the 10% you're concerned about we should work on Federation | 21:48 |
rm_work | but I don't think it'd be crazy to say "extra security is never a bad thing" | 21:48 |
redrobot | rm_work it's a much better story than your proposal, I htink | 21:48 |
rm_work | I don't disagree that federation would be great | 21:48 |
rm_work | but that is WAAAAAY more of a burden | 21:48 |
redrobot | not necessarily | 21:49 |
rm_work | "you have to run your own cloud now" | 21:49 |
rm_work | versus "you have to remember a password" | 21:49 |
redrobot | well it's not just "remember a password" | 21:49 |
rm_work | they can store the passwords internally using their own security protocols | 21:49 |
rm_work | whatever those may be | 21:49 |
rm_work | we use password-safe and at my old company we used some Vault thing | 21:49 |
rm_work | most companies will already have an analog | 21:50 |
rm_work | and those are not exposed to the cloud | 21:50 |
rm_work | sure, if they were, it would essentially be federation and we'd be set! | 21:50 |
rm_work | but that's a lot more work | 21:50 |
*** lisaclark1 has joined #openstack-barbican | 21:51 | |
*** su_zhang has quit IRC | 21:53 | |
redrobot | rm_work arguably, the security-conscious customer would be willing to put in the extra work. | 21:53 |
redrobot | rm_work I think that the use case you're trying to address gives you a marginally better security story | 21:54 |
redrobot | rm_work at the expense of added complexity for both the user and for LBaaS | 21:54 |
redrobot | rm_work I honestly don't think it's worth it. | 21:54 |
*** su_zhang has joined #openstack-barbican | 21:54 | |
rm_work | well, it's optional, but i don't disagree with added complexity for lbaas | 21:54 |
*** su_zhang has quit IRC | 21:55 | |
*** edtubill has quit IRC | 21:58 | |
*** jongchoi_ has quit IRC | 22:02 | |
*** jongchoi_ has joined #openstack-barbican | 22:04 | |
*** jamielennox|away is now known as jamielennox | 22:07 | |
*** lisaclark1 has quit IRC | 22:10 | |
*** jongchoi_ has quit IRC | 22:10 | |
*** kfarr has quit IRC | 22:10 | |
*** lisaclark1 has joined #openstack-barbican | 22:10 | |
*** lisaclark1 has quit IRC | 22:14 | |
*** xaeth is now known as xaeth_afk | 22:18 | |
*** dimtruck is now known as zz_dimtruck | 22:35 | |
*** su_zhang has joined #openstack-barbican | 22:39 | |
*** jaosorior has quit IRC | 22:48 | |
*** jaosorior has joined #openstack-barbican | 22:48 | |
*** edtubill has joined #openstack-barbican | 22:49 | |
*** jhfeng has quit IRC | 23:02 | |
*** edtubill has quit IRC | 23:34 | |
*** ccneill has joined #openstack-barbican | 23:42 | |
*** ccneill has quit IRC | 23:48 | |
*** peter-hamilton has joined #openstack-barbican | 23:49 | |
*** su_zhang has quit IRC | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!