*** pdesai has quit IRC | 00:05 | |
*** mp11 has quit IRC | 00:16 | |
*** su_zhang has quit IRC | 00:21 | |
*** su_zhang has joined #openstack-barbican | 00:21 | |
*** ccneill has quit IRC | 00:22 | |
*** rellerreller has joined #openstack-barbican | 00:26 | |
*** dave-mcc_ has joined #openstack-barbican | 00:27 | |
*** dave-mccowan has quit IRC | 00:28 | |
*** mp1 has joined #openstack-barbican | 00:31 | |
*** mp1 has quit IRC | 00:36 | |
*** jamielennox|away is now known as jamielennox | 00:55 | |
*** rellerreller has quit IRC | 00:59 | |
*** jamielennox is now known as jamielennox|away | 01:23 | |
*** cheneydc has joined #openstack-barbican | 01:29 | |
*** dave-mcc_ has quit IRC | 02:09 | |
*** dave-mccowan has joined #openstack-barbican | 02:10 | |
*** su_zhang has quit IRC | 02:11 | |
*** Nirupama has joined #openstack-barbican | 02:15 | |
*** jhfeng has joined #openstack-barbican | 02:19 | |
*** jhfeng has quit IRC | 02:20 | |
*** jamielennox|away is now known as jamielennox | 02:44 | |
*** zz_dimtruck is now known as dimtruck | 02:44 | |
*** yuanying_ has joined #openstack-barbican | 03:21 | |
*** yuanying has quit IRC | 03:24 | |
*** yuanying has joined #openstack-barbican | 03:41 | |
*** yuanying_ has quit IRC | 03:44 | |
*** pdesai has joined #openstack-barbican | 03:47 | |
*** yuanying has quit IRC | 04:05 | |
*** yuanying has joined #openstack-barbican | 04:06 | |
*** su_zhang has joined #openstack-barbican | 04:06 | |
*** yuanying_ has joined #openstack-barbican | 04:07 | |
*** yuanying has quit IRC | 04:07 | |
*** kebray has joined #openstack-barbican | 04:09 | |
*** jamielennox is now known as jamielennox|away | 04:10 | |
*** kebray has quit IRC | 04:14 | |
*** kebray_ has joined #openstack-barbican | 04:14 | |
*** woodster_ has quit IRC | 04:16 | |
*** sidx64 has joined #openstack-barbican | 04:25 | |
*** sidx64_Cern has joined #openstack-barbican | 04:28 | |
*** sidx64 has quit IRC | 04:31 | |
*** jamielennox|away is now known as jamielennox | 04:39 | |
*** fnaval has quit IRC | 04:47 | |
*** sidx64_Cern is now known as sidx64 | 04:53 | |
*** pdesai has quit IRC | 05:09 | |
*** dave-mccowan has quit IRC | 05:10 | |
*** jamielennox is now known as jamielennox|away | 05:13 | |
*** fnaval has joined #openstack-barbican | 05:16 | |
*** cheneydc has quit IRC | 05:26 | |
*** Nirupama has quit IRC | 05:32 | |
*** gyee has quit IRC | 05:32 | |
*** Nirupama has joined #openstack-barbican | 05:47 | |
*** cheneydc has joined #openstack-barbican | 05:52 | |
*** dimtruck is now known as zz_dimtruck | 06:00 | |
*** alee has quit IRC | 06:06 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Introduce Castellan Credential Objects https://review.openstack.org/270602 | 06:34 |
---|---|---|
openstackgerrit | Fernando Diaz proposed openstack/castellan: Introduce Castellan Credential Objects https://review.openstack.org/270602 | 06:47 |
*** fnaval has quit IRC | 06:52 | |
*** fnaval has joined #openstack-barbican | 06:52 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: WIP: Introduce Castellan Credential Factory https://review.openstack.org/273863 | 06:58 |
openstackgerrit | Fernando Diaz proposed openstack/castellan: WIP: Introduce Castellan Credential Factory https://review.openstack.org/273863 | 07:15 |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Allow Barbican Key Manager to accept different auth credentials https://review.openstack.org/273872 | 07:15 |
*** fnaval_ has joined #openstack-barbican | 07:17 | |
*** fnaval has quit IRC | 07:20 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Allow Barbican Key Manager to accept different auth credentials https://review.openstack.org/273872 | 07:31 |
*** scheuran has joined #openstack-barbican | 07:33 | |
*** su_zhang has quit IRC | 07:52 | |
*** kebray_ has quit IRC | 08:01 | |
*** Nirupama has quit IRC | 08:25 | |
*** Nirupama has joined #openstack-barbican | 08:41 | |
*** cheneydc has quit IRC | 10:01 | |
*** openstackgerrit has quit IRC | 10:17 | |
*** openstackgerrit has joined #openstack-barbican | 10:17 | |
*** dave-mccowan has joined #openstack-barbican | 10:59 | |
*** sidx64_Cern has joined #openstack-barbican | 11:10 | |
*** sidx64 has quit IRC | 11:14 | |
*** dave-mccowan has quit IRC | 11:17 | |
*** sid_cerner has joined #openstack-barbican | 11:48 | |
*** sid_cerner is now known as sidx64 | 11:48 | |
*** sidx64_Cern has quit IRC | 11:51 | |
*** sidx64 has quit IRC | 12:35 | |
*** DuncanT has quit IRC | 12:36 | |
*** ptoohill has quit IRC | 12:36 | |
*** DuncanT has joined #openstack-barbican | 12:37 | |
*** ptoohill has joined #openstack-barbican | 12:38 | |
*** cheneydc has joined #openstack-barbican | 12:47 | |
*** sidx64 has joined #openstack-barbican | 12:48 | |
*** anteaya has joined #openstack-barbican | 13:00 | |
*** anteaya has quit IRC | 13:06 | |
*** rellerreller has joined #openstack-barbican | 13:39 | |
*** su_zhang has joined #openstack-barbican | 13:41 | |
*** Nirupama has quit IRC | 13:53 | |
*** woodster_ has joined #openstack-barbican | 14:01 | |
*** dave-mccowan has joined #openstack-barbican | 14:15 | |
*** zz_dimtruck is now known as dimtruck | 14:18 | |
*** edtubill has joined #openstack-barbican | 14:24 | |
*** cheneydc has quit IRC | 14:26 | |
*** kebray has joined #openstack-barbican | 14:30 | |
*** dimtruck is now known as zz_dimtruck | 14:41 | |
*** zz_dimtruck is now known as dimtruck | 14:42 | |
*** cheneydc has joined #openstack-barbican | 14:52 | |
*** dimtruck is now known as zz_dimtruck | 14:55 | |
openstackgerrit | Elvin Tubillara proposed openstack/barbican: Simple soft deletion cleanup script https://review.openstack.org/269903 | 15:00 |
*** jhfeng has joined #openstack-barbican | 15:00 | |
*** rellerreller has quit IRC | 15:03 | |
*** rellerreller has joined #openstack-barbican | 15:08 | |
*** rellerreller has quit IRC | 15:09 | |
*** rellerreller has joined #openstack-barbican | 15:10 | |
*** zz_dimtruck is now known as dimtruck | 15:18 | |
*** kebray has quit IRC | 15:21 | |
*** jaosorior has joined #openstack-barbican | 15:23 | |
*** kebray has joined #openstack-barbican | 15:37 | |
*** mp1 has joined #openstack-barbican | 15:39 | |
*** mp1 has quit IRC | 15:41 | |
*** mp1 has joined #openstack-barbican | 15:44 | |
*** mp1 has joined #openstack-barbican | 15:45 | |
*** silos has joined #openstack-barbican | 15:48 | |
*** mp1 has joined #openstack-barbican | 15:48 | |
*** mp1 has quit IRC | 15:48 | |
*** mp1 has joined #openstack-barbican | 15:49 | |
*** kebray has quit IRC | 15:51 | |
*** rellerreller has quit IRC | 15:55 | |
*** kebray has joined #openstack-barbican | 15:56 | |
*** sidx64 has quit IRC | 15:58 | |
*** rellerreller has joined #openstack-barbican | 15:59 | |
*** david-lyle has joined #openstack-barbican | 16:02 | |
*** kebray has quit IRC | 16:05 | |
*** kebray has joined #openstack-barbican | 16:06 | |
*** su_zhang has quit IRC | 16:08 | |
*** cheneydc has quit IRC | 16:08 | |
*** su_zhang has joined #openstack-barbican | 16:13 | |
*** ccneill has joined #openstack-barbican | 16:16 | |
*** diazjf has joined #openstack-barbican | 16:16 | |
*** diazjf has quit IRC | 16:16 | |
*** diazjf has joined #openstack-barbican | 16:17 | |
*** rtmorgan has joined #openstack-barbican | 16:19 | |
*** woodster_ has quit IRC | 16:26 | |
*** spotz_zzz is now known as spotz | 16:31 | |
*** edtubill has quit IRC | 16:32 | |
*** kebray has quit IRC | 16:36 | |
*** pwp has joined #openstack-barbican | 16:41 | |
*** fnaval_ has quit IRC | 16:48 | |
*** jaosorior has quit IRC | 16:49 | |
*** su_zhang has quit IRC | 16:52 | |
*** gariveradlt has joined #openstack-barbican | 16:55 | |
*** scheuran has quit IRC | 16:57 | |
*** kebray has joined #openstack-barbican | 17:02 | |
*** mp1 has quit IRC | 17:04 | |
*** mp1 has joined #openstack-barbican | 17:05 | |
*** silos has quit IRC | 17:06 | |
*** fnaval has joined #openstack-barbican | 17:09 | |
*** silos has joined #openstack-barbican | 17:12 | |
*** pwp has quit IRC | 17:12 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Add created property to Managed Objects https://review.openstack.org/238150 | 17:16 |
*** spotz is now known as spotz_zzz | 17:19 | |
*** ccneill_ has joined #openstack-barbican | 17:31 | |
*** openstackgerrit has quit IRC | 17:32 | |
*** openstackgerrit has joined #openstack-barbican | 17:32 | |
*** ccneill has quit IRC | 17:34 | |
*** pwp has joined #openstack-barbican | 17:36 | |
*** pwp has quit IRC | 17:38 | |
*** pwp has joined #openstack-barbican | 17:38 | |
*** mp1 has quit IRC | 17:43 | |
*** edtubill has joined #openstack-barbican | 17:55 | |
*** ccneill__ has joined #openstack-barbican | 17:57 | |
*** ccneill_ has quit IRC | 18:00 | |
*** pdesai has joined #openstack-barbican | 18:01 | |
*** mp1 has joined #openstack-barbican | 18:04 | |
*** silos has quit IRC | 18:10 | |
*** su_zhang has joined #openstack-barbican | 18:20 | |
*** dimtruck is now known as zz_dimtruck | 18:21 | |
*** su_zhang has quit IRC | 18:22 | |
*** su_zhang has joined #openstack-barbican | 18:22 | |
*** kfarr has joined #openstack-barbican | 18:28 | |
*** ccneill__ has quit IRC | 18:34 | |
*** gyee has joined #openstack-barbican | 18:37 | |
*** zz_dimtruck is now known as dimtruck | 18:38 | |
*** gariveradlt has quit IRC | 18:46 | |
*** gariveradlt has joined #openstack-barbican | 18:49 | |
*** silos has joined #openstack-barbican | 18:53 | |
*** ccneill__ has joined #openstack-barbican | 18:57 | |
*** whydidyoustealmy has joined #openstack-barbican | 19:03 | |
*** ccneill__ is now known as ccneill | 19:04 | |
*** lvh_ has joined #openstack-barbican | 19:07 | |
*** jkf_ has joined #openstack-barbican | 19:08 | |
*** lbragstad_ has joined #openstack-barbican | 19:11 | |
*** barra204 has quit IRC | 19:12 | |
*** arunkant has quit IRC | 19:12 | |
*** lvh has quit IRC | 19:12 | |
*** jkf has quit IRC | 19:12 | |
*** lbragstad has quit IRC | 19:12 | |
*** lbragstad_ is now known as lbragstad | 19:12 | |
*** jkf_ is now known as jkf | 19:12 | |
*** silos has quit IRC | 19:12 | |
*** arunkant has joined #openstack-barbican | 19:16 | |
*** gariveradlt has quit IRC | 19:26 | |
*** mp1 has quit IRC | 19:28 | |
*** pdesai has quit IRC | 19:30 | |
*** su_zhang has quit IRC | 19:32 | |
*** su_zhang has joined #openstack-barbican | 19:32 | |
*** silos has joined #openstack-barbican | 19:32 | |
silos | rellerreller: ping | 19:33 |
rellerreller | silos pong | 19:33 |
silos | rellerreller: are you familiar with the glance image signing feature? Saw some apl e-mails floating around and wanted to poke your brain about something | 19:34 |
*** su_zhang has quit IRC | 19:34 | |
silos | *apl email usernames | 19:34 |
*** su_zhang has joined #openstack-barbican | 19:34 | |
rellerreller | silos what about it? | 19:34 |
rellerreller | silos I am familiar with it. | 19:34 |
silos | rellerreller. I'm confused why they create a pair of asymmetric keys. I never see the public key being used for verification. I think I might be missing something but do you know what the public key is actually used for? | 19:35 |
rellerreller | silos the image is signed with the private key. The public key/certificate is then used in two places. | 19:36 |
rellerreller | silos Glance will use the public key to verify the integrity of the image as it is uploaded to Glance. | 19:37 |
rellerreller | silos if the signature check fails then the image is not uploaded. | 19:37 |
rellerreller | silos Nova also uses the public key. When Nova is given a signed image it must first validate the signature. If the signature check fails then the image is not launched. | 19:38 |
kfarr | silos, check out this spec (problem description section) https://specs.openstack.org/openstack/glance-specs/specs/liberty/image-signing-and-verification-support.html#problem-description | 19:38 |
rellerreller | silos does that make sense? | 19:38 |
silos | rellerreller: yea that makes sense. I just don't see in the tutorial here, https://etherpad.openstack.org/p/liberty-glance-image-signing-instructions, where the public key actually gets used. It seems like the private key is doing everything. | 19:41 |
silos | kfarr: thanks! I've been reading through it. | 19:41 |
rellerreller | silos not sure where that came from. | 19:42 |
*** su_zhang has quit IRC | 19:43 | |
*** su_zhang has joined #openstack-barbican | 19:43 | |
kfarr | rellerreller Those instructions came from Brianna from when she went to the liberty glance mid-cycle | 19:43 |
silos | rellerreller: Okay. I'll just read through the spec more that kfarr sent. I know the pubkey gets attached to the cert on creation so it just seemed weird in that tutorial they created a public key before creating the cert. I was wondering what they were doing with it but I think it's just a step that's messing with my brain. | 19:44 |
silos | kfarr, rellerreller: thanks for the help! | 19:46 |
*** su_zhang has quit IRC | 19:46 | |
*** su_zhang has joined #openstack-barbican | 19:47 | |
*** su_zhang has quit IRC | 19:53 | |
*** whydidyoustealmy is now known as barra204 | 19:53 | |
*** su_zhang has joined #openstack-barbican | 19:53 | |
diazjf | rellerreller, kfarr, I'll setup the hangout in 5 -10 mins | 19:57 |
rellerreller | diazjf I'm trying to wrap up things here. | 19:57 |
*** gyee has quit IRC | 19:57 | |
diazjf | rellerreller, sure just ping me when you get a chance | 19:57 |
diazjf | edtubil, silos, jhfeng, I'd like you guys to join in as well | 19:58 |
diazjf | edtubill ^ | 19:58 |
edtubill | diazjf: sure | 19:59 |
rellerreller | diazjf I'm going to sign off and be back in 2 minutes. | 20:00 |
*** rellerreller has quit IRC | 20:00 | |
jhfeng | diazjf: is this for BYOK ? | 20:00 |
diazjf | jhfeng yup | 20:01 |
diazjf | I'll post the link in 5 mins | 20:01 |
*** rellerreller has joined #openstack-barbican | 20:03 | |
rellerreller | diazjf I'm ready | 20:03 |
diazjf | rellerreller perfect setting up now | 20:03 |
kfarr | brb | 20:05 |
diazjf | spec: https://review.openstack.org/#/c/271517/ hangout: https://hangouts.google.com/hangouts/_/fiu.edu/byok | 20:05 |
diazjf | rellerreller, kfarr, silos, edtubill, jhfeng | 20:05 |
*** su_zhang has quit IRC | 20:06 | |
*** silos has quit IRC | 20:11 | |
*** pwp has quit IRC | 20:12 | |
*** pwp has joined #openstack-barbican | 20:13 | |
redrobot | arunkant ping | 20:16 |
arunkant | redrobot: pong | 20:16 |
redrobot | arunkant hi! do you have a second to talk about my bug ? | 20:16 |
arunkant | redorobot: Yes. | 20:17 |
redrobot | arunkant ok, so I wanted to explain the bug I'm seeing in my deployment | 20:17 |
redrobot | arunkant I have a pretty straightforward setup | 20:18 |
redrobot | arunkant with a single Load Balancer, and a few API nodes behind it | 20:18 |
redrobot | arunkant like so: http://i.imgur.com/UKycd1D.png | 20:18 |
redrobot | arunkant in this case, the conf file in both API nodes is set identically such that the conf files both have the LB DNS entry as the host_href | 20:19 |
redrobot | arunkant this makes the URLs all use the LB hostname, and all is well | 20:20 |
redrobot | arunkant the bug I'm seeing is that when I go to get the Version, the URL I get back depends on whether the LB sent the request to api-n01 or api-n02 | 20:20 |
redrobot | so the Versions is returning api-n01.example.com sometimes, and other times it returns api-n0.example.com | 20:20 |
redrobot | * n02 | 20:21 |
redrobot | obviously this is wrong, for this scenario regardless of host, the URL should always point to the LB | 20:21 |
redrobot | arunkant does that make sense? | 20:21 |
*** silos has joined #openstack-barbican | 20:21 | |
arunkant | redrobot: So n01 or n02 are the servers which are receiving barbican requests.. | 20:22 |
redrobot | arunkant correct | 20:22 |
arunkant | redrobot: yes it makes sense | 20:22 |
redrobot | arunkant and because my LB changes the destination from the LB url to the node URL to forward it, I end up getting the wrong version back | 20:22 |
redrobot | * wrong url back | 20:22 |
redrobot | arunkant with the patch I proposed, the Version will also use the configuration url so regardless of n01 or n02, I will always get the right url back. does that make sense? | 20:23 |
redrobot | arunkant now, if I understand your use case, you need to be able to serve from 2 different URLS | 20:24 |
redrobot | arunkant but for some reason, this needs to be the same deployment | 20:24 |
redrobot | arunkant does that sound like the use case you're thinking of? | 20:24 |
diazjf | jhfeng, can you join | 20:25 |
arunkant | redrobot: version logic derives hostname from wsgi request..so why hostname will have n01 or n02 as that's not the client..its the server | 20:25 |
redrobot | arunkant it's because haproxy is modifying the request. | 20:25 |
redrobot | arunkant haproxy changes the destination to the hostname to forward the request | 20:26 |
redrobot | arunkant ... well actually it's repose, but that's beside the point | 20:26 |
redrobot | arunkant the point is that every single url in barbican is using the CONF value except for the version resource | 20:26 |
arunkant | Okay...so its the similar to setup we have.. We set X-Forwarded-For header which then reflects correctly in hostname | 20:26 |
redrobot | arunkant correct, so we're running barbican in a container, and in our setup the Version always returns the name of the container... and since it's not configurable, I have no way to fix it without the patch I submitted | 20:27 |
*** mp1 has joined #openstack-barbican | 20:28 | |
*** mp1 has quit IRC | 20:28 | |
redrobot | arunkant now, as I understand your use case, you want to guarantee that users accessing your single deployment through the external endpoint should see the external endpoint in the URIs | 20:28 |
*** mp1 has joined #openstack-barbican | 20:28 | |
redrobot | arunkant and users accessing the same exact deployment through the different internal endpoint should see that same internal endpoint in the URIs, correct? | 20:28 |
arunkant | redrobot: Yes..that's the concern. I was going to submit a bug and possibly fix to change href conctruction to use same logic as version controller. | 20:29 |
redrobot | arunkant so, my argument is that you don't need to change barbican at all to achieve that | 20:29 |
redrobot | arunkant you can achieve that today | 20:29 |
redrobot | arunkant with the code as it is now, no need to change anything... except land my bugfix so that you don't see the same incorrect URL | 20:30 |
redrobot | arunkant this is what your deployment should look like: http://i.imgur.com/D1uw80O.png | 20:30 |
arunkant | redrobot: Okay..Can you please help me in understanding...how this change will address the issue of accessing from public vs internal client | 20:31 |
redrobot | arunkant so, since you're providing two urls, I assume the client knows which endpoint to use? | 20:31 |
arunkant | redrobot: client just configure/provide interface in barbicanclient and its driven via keystone version discovery using service catalog | 20:32 |
redrobot | arunkant sure, so the client picks "internalUrl" or whatever | 20:33 |
arunkant | right | 20:33 |
redrobot | arunkant and that resolves to either external.example.com or internal.example.com in my drawing | 20:33 |
redrobot | you need to have two load balancers | 20:33 |
redrobot | listening on each of those urls | 20:33 |
redrobot | and two sets of API nodes | 20:33 |
arunkant | yes..two LB and same barbican API instances | 20:34 |
redrobot | arunkant no, you need two different sets of API instances | 20:34 |
redrobot | arunkant that is how you get the current barbican to work for you | 20:34 |
redrobot | arunkant you need one set that is used exclusively by one LB, and another set that is used by the other LB | 20:34 |
arunkant | redrobot: Why you need to have different instances...its the difference of which network they are coming from.. | 20:35 |
redrobot | in one set of API nodes, you set host_href=external.example.com in the other set of API nodes you set host_href=internal.example.com | 20:35 |
redrobot | arunkant this way you can always guarantee that the API node will use the correct LB address | 20:36 |
arunkant | redrobot: Are we saying any service who needs to have public and internal endpoints..they will run two of everything just to allow how client access it. | 20:37 |
redrobot | arunkant yes, if you need to have two distinct endpoints, you need to deploy at least 2 api nodes | 20:37 |
redrobot | arunkant note that you can still share the DB | 20:37 |
redrobot | arunkant and you can still share the HSM | 20:38 |
redrobot | arunkant and the workers can listen on the same queue | 20:38 |
redrobot | arunkant and regardless of what endpoint the client uses, they will be able to access the same object if they provide the same UUID | 20:38 |
*** pwp has quit IRC | 20:38 | |
*** pwp has joined #openstack-barbican | 20:38 | |
arunkant | redrobot: I am not sure that is the intention of having different interfaces in service catalog. No actual deployment will run two sets of nova/glance etc. | 20:39 |
redrobot | arunkant why don't you like this solution? nodes are cheap, that's how you scale barbican | 20:39 |
redrobot | arunkant our nova deployment runs hundreds of nova nodes | 20:39 |
redrobot | arunkant if you want to run a single VM with barbican you're going to have some serious performance issues | 20:40 |
arunkant | redrobot: Its not about how many instances of a service...its about running different configuration, maintaining in different control plane. Its lot of baggage comes with that in terms of maintenance, upgrades etc.. | 20:42 |
*** pwp has quit IRC | 20:44 | |
*** pwp has joined #openstack-barbican | 20:44 | |
arunkant | redrobot: the problem you mentioned earlier, we have solved it by setting X-Forwarded-For header which is a standard way when proxies are involved. | 20:45 |
*** pwp has quit IRC | 20:45 | |
*** pwp has joined #openstack-barbican | 20:46 | |
*** edtubill has quit IRC | 20:47 | |
*** pwp has quit IRC | 20:49 | |
*** rellerreller has quit IRC | 21:00 | |
redrobot | arunkant I disagree | 21:07 |
redrobot | arunkant (sorry had a meeting) | 21:07 |
redrobot | arunkant I think all HREFs should behave the same way throughout the API | 21:07 |
redrobot | arunkant and I insist that my fix for the Version HREF is the correct one at this time. | 21:07 |
arunkant | redrobot: I think..better solution is to have href side fixed so barbican can work across many deployments which follow openstack standard endpoint interface types. | 21:09 |
*** spotz_zzz is now known as spotz | 21:11 | |
redrobot | arunkant you are entitled to your own opinion, however if you want to change the behavior, we should do so via a blueprint. I think that a configurable URL is a better approach for many types of deployments | 21:11 |
arunkant | redrobot: May be its something we can discuss in team meeting to get broader inputs from community | 21:11 |
redrobot | arunkant the issue I'm seeing would not be fixed by X-Forwarded-For headers, since I'm using docker networking, and not just a LB in front of my APIs | 21:11 |
*** pwp has joined #openstack-barbican | 21:11 | |
redrobot | arunkant I think that this bugfix and your proposed change are two different conversations | 21:13 |
redrobot | arunkant we can talk about your proposed change some more, but I think that the inconsistent state we're in right now is bad, and we should land my patch to fix it | 21:14 |
arunkant | redrobot: I am just asking to have broader inputs ..just to see if deployments are there which have more than one endpoints (like ours). | 21:15 |
redrobot | arunkant and I don't want to stop you from doing that.... I just don't think that this fix should be blocked because of that conversation | 21:15 |
*** pwp has quit IRC | 21:16 | |
arunkant | redrobot: From bug fix perspective, for us this will introduce bug on our side but that's never a concern. | 21:17 |
*** pwp has joined #openstack-barbican | 21:18 | |
redrobot | arunkant you have more problems than just this Version URL, since ALL OTHER URIs don't behave this way. | 21:19 |
redrobot | arunkant and like I just explained, you can fix your deployment with a little devops using the deployment diagram I linked earlier | 21:19 |
*** su_zhang has joined #openstack-barbican | 21:20 | |
*** gyee has joined #openstack-barbican | 21:22 | |
arunkant | redrobot: Running a parallel cloud just to differentiate public and internal clients..that not going to fly even if I want to ask them switch. | 21:22 |
*** gyee has quit IRC | 21:22 | |
*** Guest40848 has joined #openstack-barbican | 21:23 | |
arunkant | redrobot: Anyhow, I raised my concern and thoughts about the issue. I believe that you will do the right thing. | 21:24 |
redrobot | arunkant but it's not a parallel cloud. It's just a different set of api nodes behind the second load balancer that you already have.... honestly I don't know how to convince your ops team that the deployment diagram I provided is a good solutinon :( | 21:24 |
*** pwp has quit IRC | 21:24 | |
*** su_zhang has quit IRC | 21:25 | |
redrobot | arunkant are you striving to provide zero-downtime API access? because your ops team is going to have to juggle different sets of api nodes to achieve that as well... | 21:25 |
*** pwp has joined #openstack-barbican | 21:26 | |
arunkant | redrobot: I just now looked how keystone handle that.. https://github.com/openstack/keystone/blob/master/keystone/common/wsgi.py#L371 | 21:26 |
arunkant | redrobot: So keystone provides the option to use which interface or it derives from wsgi request (similar to version logic) | 21:27 |
redrobot | arunkant you're welcome to propose a BP for that change, but I insist that it's a separate concern from my bugfix that will make all urls consistent. | 21:28 |
*** su_zhang has joined #openstack-barbican | 21:32 | |
*** pwp has quit IRC | 21:32 | |
*** pwp has joined #openstack-barbican | 21:35 | |
*** spotz is now known as spotz_zzz | 21:36 | |
*** gyee has joined #openstack-barbican | 21:37 | |
arunkant | redrobot: Is it possible to discuss this in weekly team meeting or that's not an option here? | 21:38 |
*** pwp has quit IRC | 21:38 | |
*** pdesai has joined #openstack-barbican | 21:42 | |
*** spotz_zzz is now known as spotz | 21:42 | |
*** silos has quit IRC | 21:43 | |
*** panatl has joined #openstack-barbican | 21:44 | |
jkf | Any cores around that can look at and +2/+W my padding bug fix for the new pkcs11 code? https://review.openstack.org/#/c/270572 | 21:46 |
jkf | Been sitting for nearly 2 weeks now and I think its ready to come home. :) | 21:47 |
*** silos has joined #openstack-barbican | 21:49 | |
*** pwp has joined #openstack-barbican | 21:55 | |
*** pwp has quit IRC | 21:57 | |
*** pwp has joined #openstack-barbican | 21:58 | |
*** fnaval_ has joined #openstack-barbican | 22:05 | |
*** fnaval has quit IRC | 22:07 | |
*** pwp has quit IRC | 22:12 | |
openstackgerrit | Elvin Tubillara proposed openstack/barbican: Simple soft deletion clean up for barbican-db-manage https://review.openstack.org/269903 | 22:14 |
*** edtubill has joined #openstack-barbican | 22:14 | |
*** kebray has quit IRC | 22:34 | |
arunkant | Hi..can anyone workflow this CR, it has 3 +2.. https://review.openstack.org/#/c/263358/ | 22:35 |
*** jamielennox|away is now known as jamielennox | 22:41 | |
*** silos has left #openstack-barbican | 22:43 | |
*** edtubill has quit IRC | 22:47 | |
*** fnaval_ is now known as fnaval | 22:50 | |
*** dimtruck is now known as zz_dimtruck | 22:56 | |
*** jamielennox is now known as jamielennox|away | 23:05 | |
*** su_zhang has quit IRC | 23:11 | |
*** su_zhang has joined #openstack-barbican | 23:12 | |
*** mp1 has quit IRC | 23:13 | |
*** kfarr has quit IRC | 23:16 | |
*** jhfeng has quit IRC | 23:27 | |
*** su_zhang has quit IRC | 23:51 | |
*** su_zhang has joined #openstack-barbican | 23:51 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!