*** nelsnels_ has joined #openstack-barbican | 00:01 | |
*** nelsnelson has quit IRC | 00:03 | |
*** dimtruck is now known as zz_dimtruck | 00:15 | |
*** SheenaG1 has joined #openstack-barbican | 00:23 | |
*** kebray has quit IRC | 00:35 | |
*** kebray has joined #openstack-barbican | 00:36 | |
*** SheenaG1 has quit IRC | 00:53 | |
*** cheneydc has joined #openstack-barbican | 00:55 | |
*** jmckind_ has joined #openstack-barbican | 01:01 | |
*** jmckind has quit IRC | 01:04 | |
*** pdesai has joined #openstack-barbican | 01:13 | |
*** jmckind has joined #openstack-barbican | 01:13 | |
*** spotz is now known as spotz_zzz | 01:15 | |
*** jmckind_ has quit IRC | 01:16 | |
*** jmckind has quit IRC | 01:17 | |
*** SheenaG has joined #openstack-barbican | 01:22 | |
*** pdesai has quit IRC | 01:26 | |
*** david-lyle has quit IRC | 01:36 | |
*** pdesai has joined #openstack-barbican | 01:52 | |
*** jhfeng has joined #openstack-barbican | 02:07 | |
*** jhfeng has quit IRC | 02:12 | |
*** kebray has quit IRC | 02:31 | |
*** diazjf has joined #openstack-barbican | 02:33 | |
*** su_zhang has quit IRC | 02:35 | |
*** kebray has joined #openstack-barbican | 02:36 | |
*** pdesai has quit IRC | 02:58 | |
*** fnaval has quit IRC | 02:58 | |
*** diazjf has quit IRC | 03:08 | |
*** fnaval has joined #openstack-barbican | 03:13 | |
*** yuanying has quit IRC | 03:21 | |
*** yuanying has joined #openstack-barbican | 03:23 | |
*** yuanying has quit IRC | 03:28 | |
*** yuanying has joined #openstack-barbican | 03:33 | |
*** yuanying has quit IRC | 03:40 | |
*** yuanying has joined #openstack-barbican | 03:40 | |
*** SheenaG has quit IRC | 03:47 | |
*** SheenaG has joined #openstack-barbican | 03:48 | |
*** yuanying has quit IRC | 03:56 | |
*** yuanying has joined #openstack-barbican | 03:57 | |
*** yuanying_ has joined #openstack-barbican | 03:58 | |
*** yuanying has quit IRC | 04:01 | |
*** sidx64 has joined #openstack-barbican | 04:14 | |
*** david-lyle has joined #openstack-barbican | 04:25 | |
*** david-lyle has quit IRC | 04:25 | |
*** david-lyle has joined #openstack-barbican | 04:25 | |
*** david-lyle has quit IRC | 04:30 | |
*** mragupat has joined #openstack-barbican | 04:33 | |
*** david-lyle has joined #openstack-barbican | 04:37 | |
*** SheenaG has quit IRC | 05:02 | |
*** fnaval has quit IRC | 05:06 | |
*** su_zhang has joined #openstack-barbican | 05:09 | |
*** kebray_ has joined #openstack-barbican | 05:25 | |
*** kebray has quit IRC | 05:28 | |
*** kebray_ has quit IRC | 05:28 | |
*** kebray has joined #openstack-barbican | 05:28 | |
*** kebray_ has joined #openstack-barbican | 05:45 | |
*** kebray has quit IRC | 05:46 | |
*** dave-mccowan has quit IRC | 05:52 | |
openstackgerrit | Merged openstack/barbican: Updated from global requirements https://review.openstack.org/271637 | 06:00 |
---|---|---|
*** Nirupama has joined #openstack-barbican | 06:18 | |
*** jaosorior has joined #openstack-barbican | 06:27 | |
*** mragupat has quit IRC | 06:28 | |
*** scheuran has joined #openstack-barbican | 07:06 | |
*** scheuran_ has joined #openstack-barbican | 07:19 | |
*** scheuran has quit IRC | 07:21 | |
*** chlong_zzz is now known as chlong | 07:31 | |
*** yfujioka has joined #openstack-barbican | 07:43 | |
*** su_zhang has quit IRC | 08:27 | |
*** kebray_ has quit IRC | 08:43 | |
*** woodster_ has quit IRC | 09:16 | |
*** jaosorior has quit IRC | 09:19 | |
*** jaosorior has joined #openstack-barbican | 09:20 | |
*** jaosorior has quit IRC | 09:25 | |
*** jaosorior has joined #openstack-barbican | 09:25 | |
*** cheneydc has quit IRC | 10:05 | |
*** pcaruana has joined #openstack-barbican | 11:44 | |
*** cheneydc has joined #openstack-barbican | 12:17 | |
openstackgerrit | Michael Krotscheck proposed openstack/barbican: Added CORS support to Barbican https://review.openstack.org/255364 | 12:18 |
*** pcaruana has quit IRC | 12:37 | |
*** dave-mccowan has joined #openstack-barbican | 13:05 | |
*** david-lyle has quit IRC | 13:08 | |
*** chlong has quit IRC | 13:15 | |
*** chlong has joined #openstack-barbican | 13:29 | |
*** Nirupama has quit IRC | 14:08 | |
*** darrenmoffat has quit IRC | 14:10 | |
*** darrenmoffat has joined #openstack-barbican | 14:11 | |
*** david-lyle has joined #openstack-barbican | 14:17 | |
*** david-lyle has quit IRC | 14:44 | |
*** SheenaG has joined #openstack-barbican | 14:46 | |
*** david-lyle has joined #openstack-barbican | 14:48 | |
*** zz_dimtruck is now known as dimtruck | 14:50 | |
*** david-lyle has quit IRC | 14:53 | |
*** su_zhang has joined #openstack-barbican | 14:53 | |
*** spotz_zzz is now known as spotz | 15:02 | |
*** jmckind has joined #openstack-barbican | 15:09 | |
*** diazjf has joined #openstack-barbican | 15:11 | |
*** silos has joined #openstack-barbican | 15:17 | |
*** narengan12 has joined #openstack-barbican | 15:20 | |
*** jmckind has quit IRC | 15:30 | |
*** edtubill has joined #openstack-barbican | 15:31 | |
*** jhfeng has joined #openstack-barbican | 15:34 | |
*** mragupat has joined #openstack-barbican | 15:35 | |
*** jmckind has joined #openstack-barbican | 15:36 | |
*** mp1 has joined #openstack-barbican | 15:36 | |
*** dimtruck is now known as zz_dimtruck | 15:39 | |
*** zz_dimtruck is now known as dimtruck | 15:40 | |
*** su_zhang has quit IRC | 16:03 | |
*** su_zhang has joined #openstack-barbican | 16:06 | |
*** SheenaG has left #openstack-barbican | 16:13 | |
*** david-lyle has joined #openstack-barbican | 16:14 | |
jaosorior | alee: support for Fedora 23 in infra is getting there: http://lists.openstack.org/pipermail/openstack-infra/2016-January/003699.html | 16:16 |
openstackgerrit | Fernando Diaz proposed openstack/python-barbicanclient: WIP: Allow Barbican Secrets to be Stored via File https://review.openstack.org/242635 | 16:17 |
alee | jaosorior, yay | 16:17 |
*** su_zhang has quit IRC | 16:17 | |
*** diazjf has quit IRC | 16:17 | |
*** woodster_ has joined #openstack-barbican | 16:21 | |
*** dgonzalez has quit IRC | 16:23 | |
*** dgonzalez has joined #openstack-barbican | 16:24 | |
*** cheneydc has quit IRC | 16:25 | |
*** diazjf has joined #openstack-barbican | 16:28 | |
*** dimtruck is now known as zz_dimtruck | 16:31 | |
*** david-lyle has quit IRC | 16:38 | |
*** pwp has joined #openstack-barbican | 16:40 | |
*** david-lyle has joined #openstack-barbican | 16:40 | |
*** zz_dimtruck is now known as dimtruck | 16:48 | |
*** scheuran_ has quit IRC | 16:56 | |
*** sidx64 has quit IRC | 17:01 | |
*** jmckind_ has joined #openstack-barbican | 17:13 | |
*** kebray has joined #openstack-barbican | 17:15 | |
*** kebray has quit IRC | 17:15 | |
*** kebray has joined #openstack-barbican | 17:15 | |
*** jmckind has quit IRC | 17:16 | |
*** jaosorior has quit IRC | 17:20 | |
*** jaosorior has joined #openstack-barbican | 17:20 | |
*** jaosorior has quit IRC | 17:21 | |
*** ccneill has joined #openstack-barbican | 17:22 | |
openstackgerrit | Fernando Diaz proposed openstack/python-barbicanclient: Allow Barbican Secrets to be Stored via File https://review.openstack.org/242635 | 17:23 |
*** kebray has quit IRC | 17:28 | |
openstackgerrit | Christopher Solis proposed openstack/barbican: Create Orders Documentation https://review.openstack.org/236123 | 17:31 |
*** kfarr has joined #openstack-barbican | 17:33 | |
*** kebray has joined #openstack-barbican | 17:42 | |
*** narengan12 has quit IRC | 17:42 | |
*** su_zhang has joined #openstack-barbican | 17:53 | |
*** pwp has quit IRC | 17:55 | |
*** kebray has quit IRC | 17:58 | |
*** kebray has joined #openstack-barbican | 18:00 | |
*** kebray has quit IRC | 18:03 | |
*** narengan12 has joined #openstack-barbican | 18:07 | |
*** SheenaG has joined #openstack-barbican | 18:13 | |
*** SheenaG has left #openstack-barbican | 18:13 | |
*** dimtruck is now known as zz_dimtruck | 18:15 | |
*** pdesai has joined #openstack-barbican | 18:16 | |
*** fnaval has joined #openstack-barbican | 18:18 | |
openstackgerrit | Jason Fritcher proposed openstack/barbican: Remove padding from legacy stored secrets https://review.openstack.org/270572 | 18:20 |
*** zz_dimtruck is now known as dimtruck | 18:25 | |
*** pwp has joined #openstack-barbican | 18:26 | |
*** kebray has joined #openstack-barbican | 18:32 | |
*** stack_ has joined #openstack-barbican | 18:33 | |
*** jmckind_ has quit IRC | 18:35 | |
*** narengan12 has quit IRC | 18:37 | |
*** jmckind has joined #openstack-barbican | 18:38 | |
*** pwp has quit IRC | 18:41 | |
*** mp1 has quit IRC | 18:43 | |
*** ccneill has quit IRC | 18:45 | |
*** stack_ is now known as narengan | 18:46 | |
*** silos has quit IRC | 18:49 | |
openstackgerrit | Merged openstack/barbican: Add lock for crypto plugin manager instantiation https://review.openstack.org/241712 | 18:54 |
woodster_ | jkf, jhfeng : I was curious about the thread locks in the p11 code...what issues were you seeing when you added those locks? Was the hsm driver locking up, or were you seeing db access issues? | 18:59 |
*** ccneill has joined #openstack-barbican | 19:01 | |
*** ccneill has quit IRC | 19:01 | |
*** ccneill has joined #openstack-barbican | 19:02 | |
jhfeng | woodster_: in my case, https://review.openstack.org/#/c/241712/ is for fixing https://bugs.launchpad.net/barbican/+bug/1511519 | 19:03 |
openstack | Launchpad bug 1511519 in Barbican "Fail to instantiate cryptoPlugin in multithread env" [Undecided,Fix released] - Assigned to Jeff Feng (jianhua) | 19:03 |
*** pwp has joined #openstack-barbican | 19:04 | |
jhfeng | woodster_ when I doing testing with multiple-thread from client, say 10 threads to do secret PUT requests | 19:05 |
woodster_ | jhfeng: what WSGI container are you using to run Barbican? We are using gunicorn | 19:05 |
woodster_ | jhfeng: so you guys are using multiple threads vs processes it looks like. I'm curious the impact of that on database concurrency with sqlalchemy. Are you tuning sqlalchemy config params at all, or just running defaults? | 19:07 |
jhfeng | multiple threads in server side to do crypto plugin initialization one of succeed, others failed with P11CryptoPluginException: HSM returned response code: 0x191L CKR_CRYPTOKI_ALREADY_INITIALIZED | 19:07 |
jhfeng | we use uWSGI, and use >1 processes ( worker) | 19:07 |
*** pwp has quit IRC | 19:08 | |
jhfeng | I'm using default sqlalchemy config | 19:09 |
*** pwp has joined #openstack-barbican | 19:33 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Add created property to Managed Objects https://review.openstack.org/238150 | 19:37 |
*** kebray has quit IRC | 19:46 | |
diazjf | kfarr, thanks for the reviews :) Can we schedule a hangout sometime next week do discuss BYOK? | 19:54 |
kfarr | diazjf, sure! | 19:54 |
*** pwp has quit IRC | 19:57 | |
*** silos has joined #openstack-barbican | 19:58 | |
*** pwp has joined #openstack-barbican | 20:01 | |
diazjf | kfarr, awesome! Maybe Tuesday or Wednesday. I'll give you a headsup before | 20:01 |
*** pwp has quit IRC | 20:01 | |
*** pwp has joined #openstack-barbican | 20:01 | |
kfarr | Ok, great thanks! If you have it scheduled by Monday's meeting, it could be nice to announce it to everyone | 20:02 |
pwp | redrobot: diazjf: I want to work on test cases for the python-barbican-client. I ran tox -e py27 and it looks like the acls need the most love. Any suggestions? | 20:03 |
diazjf | kfarr, sure that works for me. | 20:04 |
redrobot | pwp sounds good to me. | 20:04 |
*** barra204 has quit IRC | 20:06 | |
diazjf | pwp, barbican client needs some love. | 20:07 |
diazjf | pwp look at orders as well | 20:07 |
*** mp1 has joined #openstack-barbican | 20:26 | |
diazjf | If anyone has any free cycles, can you review https://review.openstack.org/#/c/219135/ | 20:35 |
diazjf | Its just an update to python-barbicanclient testing docs | 20:36 |
*** diazjf has quit IRC | 20:41 | |
*** narengan has quit IRC | 20:48 | |
edtubill | ping woodster_ | 20:49 |
*** narengan has joined #openstack-barbican | 20:52 | |
silos | kfarr: could you check out this patch when you have a chance: https://review.openstack.org/#/c/246546/ | 20:55 |
kfarr | ok silos | 20:56 |
silos | kfarr: thanks! | 20:57 |
woodster_ | edtubill: hello | 20:59 |
kfarr | silos, I'm trying to find more information about Barbican federation. Is this still up to date? https://wiki.openstack.org/wiki/Barbican/Discussion-Federated-Barbican | 21:09 |
silos | kfarr: Not in that wiki. We decided at the mid-cycle to go forward with BYOK and I think diazjf was gonna set up a new wiki for that which would replace all the previous federation talks. | 21:11 |
kfarr | silos, ok, so when you talk about Barbican Federation, that solely means BYOK, and not all that discussion about creating a new "link" type secret in Barbican and all that? | 21:12 |
kfarr | and when you talk about BYOK, does the user store keys in files on their own device or are they getting them out of some separate key manager? | 21:12 |
*** diazjf has joined #openstack-barbican | 21:15 | |
silos | kfarr: Yes. I don't think we decided to move forward with the links or any of the models we initially proposed. As for your second question I don't really know because we still haven't flushed out all the specifics yet of the BYOK model. | 21:16 |
silos | kfarr: I could probably just remove the federation aspect mentioned in the BP. It was really germaine to our previous proposals but probably not the current one. | 21:17 |
silos | *germane | 21:17 |
*** narengan has quit IRC | 21:19 | |
kfarr | silos, ok, yeah that might help a little bit. | 21:20 |
silos | kfarr: no prob. | 21:20 |
silos | kfarr: thx for looking it over | 21:20 |
kfarr | silos, in that first use case, I'm still a little confused, are you talking about hooking up castellan directly to a KMIP device or are you talking about BYOK? | 21:21 |
kfarr | Or is that what you were just saying, that you were going to just remove those last two sentences? | 21:22 |
kfarr | brb | 21:23 |
silos | kfarr: yea. I was going to remove those last two sentences. ok | 21:23 |
kfarr | silos, ok yeah that's helpful, thanks! | 21:27 |
*** kebray has joined #openstack-barbican | 21:45 | |
*** su_zhang has quit IRC | 21:49 | |
*** kebray has quit IRC | 21:50 | |
*** diazjf has quit IRC | 21:51 | |
edtubill | woodster_: For cleaning up the database, before reaping the secret I wanted to set the order's secret_id to null so I could reap the secret without getting a FK error. Do you think this is fine? would I need to update the merged blueprint with this change? | 21:51 |
*** lvh_ is now known as lvh | 22:05 | |
woodster_ | edtubill: maybe the first phase/CRs could focus on just cleaning up secrets that have no FK to an order. Then after that add cleaning up orders. What makes orders sticky is cert order types...those have to stick around for a long time potentially, to support reissues/renewals etc. | 22:13 |
woodster_ | edtubill: nulling out the FK to a secret/container would be a bad experience I'd say | 22:14 |
openstackgerrit | Christopher Solis proposed openstack/barbican-specs: Add a KMIP key manager interface in Castellan https://review.openstack.org/246546 | 22:16 |
edtubill | woodster_: thx, that sounds good, for the first CRs I will skip the soft deleted secrets that have a non soft deleted order pointing to it. | 22:17 |
edtubill | woodster_: also, for the order model I saw that the order retry task child does not get cleaned. Should I do the same and skip if there is a child order_retry_task that is not soft deleted? Line 539: https://github.com/openstack/barbican/blob/master/barbican/model/models.py | 22:18 |
*** diazjf has joined #openstack-barbican | 22:25 | |
*** jmckind_ has joined #openstack-barbican | 22:26 | |
*** jmckind has quit IRC | 22:30 | |
*** jmckind has joined #openstack-barbican | 22:31 | |
*** jmckind_ has quit IRC | 22:33 | |
woodster_ | edtubill: It seems like that could be yet another clean up phase too. That might actually be better to do from teh retry service logic anyway though | 22:35 |
edtubill | woodster_:ok thx! | 22:36 |
woodster_ | edtubill: yeah the delete children is about removing associations from the orders table... the retry table is really an independent entity | 22:36 |
edtubill | woodster_: I think the retry table has a non nullable FK for the order, and the relationship goes from retry->order. So I'm not sure if there is a period in time where there can be a soft deleted order but also a non soft deleted order retry task existing. | 22:38 |
*** jmckind has quit IRC | 22:41 | |
woodster_ | edtubill: well orders only exist in that retry table to be retried. That same retry logic could scan for retry orders that are deletable and then just delete both the retry record and the order...probably would need a cascade rule from retry table to orders. At any rate that could come in later CRs I'd think | 22:42 |
*** dimtruck is now known as zz_dimtruck | 22:43 | |
edtubill | woodster_: ok, I also had one more thing - Can you look at this comment I made here: https://review.openstack.org/#/c/270963/4/barbican/model/models.py | 22:43 |
edtubill | woodster_: I was wondering if all of these cascade rules defined for alchemy would have to be reflected in alembic as well, or does alchemy/alembic automatically handle the cascades? | 22:45 |
*** mp1 has quit IRC | 22:45 | |
*** pwp has quit IRC | 22:48 | |
*** pwp has joined #openstack-barbican | 22:51 | |
*** mp1 has joined #openstack-barbican | 22:51 | |
*** mp1 has quit IRC | 22:56 | |
*** kfarr has quit IRC | 22:57 | |
*** diazjf has quit IRC | 23:01 | |
*** yuanying_ has quit IRC | 23:02 | |
*** su_zhang has joined #openstack-barbican | 23:02 | |
*** silos has left #openstack-barbican | 23:02 | |
*** yuanying has joined #openstack-barbican | 23:12 | |
*** chlong has quit IRC | 23:18 | |
woodster_ | edtubill: taking a look.... | 23:19 |
edtubill | woodster_:thx | 23:20 |
*** mp1 has joined #openstack-barbican | 23:21 | |
*** mragupat has quit IRC | 23:22 | |
edtubill | woodster_: I might be confused on the idea of deleting orphans because the FK of the child is non nullable, so therefore setting cascade delete-orphans might not be possible because the child can't become an orphan (you get a FK error when deleting the parent)? | 23:22 |
*** mp1 has quit IRC | 23:28 | |
*** chlong has joined #openstack-barbican | 23:31 | |
woodster_ | edtubill: that should be true actually | 23:35 |
woodster_ | edtubill: I'm curious why there is both a 'meta' and 'secret_user_metadata' attribute on that CR...seems you only need one or the other (probably just the key/value table one?) | 23:37 |
*** zz_dimtruck is now known as dimtruck | 23:38 | |
edtubill | yeah I'm not sure about that json blob, I guess it's redundant if you have a table of key,values? | 23:38 |
*** ccneill has quit IRC | 23:38 | |
edtubill | I could ask diazjf about that later. | 23:39 |
*** spotz is now known as spotz_zzz | 23:40 | |
*** jhfeng has quit IRC | 23:41 | |
edtubill | woodster_: So I need to go, I want to ask you more questions later (maybe tomorrow) about cascades and if they actually work in barbican. So see you later and thx! | 23:44 |
*** edtubill has quit IRC | 23:45 | |
*** dimtruck is now known as zz_dimtruck | 23:45 | |
*** su_zhang has quit IRC | 23:56 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!