openstackgerrit | Merged openstack/barbican: Remove padding from legacy stored secrets https://review.openstack.org/270572 | 00:04 |
---|---|---|
*** nelsnels_ has joined #openstack-barbican | 00:07 | |
*** nelsnelson has quit IRC | 00:08 | |
*** jhfeng has quit IRC | 00:12 | |
Asha_ | Sorry hockeynut ..I was out of my office for some meeting | 00:17 |
*** hyakuhei has quit IRC | 00:18 | |
Asha_ | Thanks for pointing out the link ..I would go through that and get back | 00:21 |
*** hyakuhei has joined #openstack-barbican | 00:24 | |
*** kebray has joined #openstack-barbican | 00:33 | |
*** Asha_ has quit IRC | 00:36 | |
*** alee_ has quit IRC | 00:38 | |
*** alee has quit IRC | 00:38 | |
*** kebray has quit IRC | 00:40 | |
*** hyakuhei has quit IRC | 00:50 | |
*** spotz_zzz is now known as spotz | 00:52 | |
*** hyakuhei has joined #openstack-barbican | 00:52 | |
*** hyakuhei has quit IRC | 00:55 | |
*** hyakuhei has joined #openstack-barbican | 00:56 | |
*** hyakuhei has quit IRC | 00:59 | |
*** hyakuhei has joined #openstack-barbican | 01:00 | |
openstackgerrit | Merged openstack/barbican: Updated from global requirements https://review.openstack.org/277116 | 01:04 |
*** damia_pi has joined #openstack-barbican | 01:11 | |
*** damia_pi has quit IRC | 01:16 | |
*** chlong has joined #openstack-barbican | 01:18 | |
*** hyakuhei has quit IRC | 01:20 | |
*** hyakuhei has joined #openstack-barbican | 01:32 | |
*** zz_dimtruck is now known as dimtruck | 01:42 | |
*** gyee has quit IRC | 01:48 | |
*** damia_pi has joined #openstack-barbican | 01:49 | |
*** damia_pi has quit IRC | 01:51 | |
*** mragupat has joined #openstack-barbican | 02:08 | |
*** mragupat has quit IRC | 02:08 | |
*** mragupat has joined #openstack-barbican | 02:08 | |
*** openstackgerrit has quit IRC | 02:15 | |
*** chlong has quit IRC | 02:15 | |
*** openstackgerrit has joined #openstack-barbican | 02:24 | |
*** mragupat has quit IRC | 02:24 | |
*** chlong has joined #openstack-barbican | 02:29 | |
*** su_zhang has quit IRC | 02:45 | |
*** woodster_ has quit IRC | 02:46 | |
*** tkelsey has joined #openstack-barbican | 03:08 | |
*** jhfeng has joined #openstack-barbican | 03:11 | |
*** jhfeng has quit IRC | 03:11 | |
*** tkelsey has quit IRC | 03:13 | |
*** lvh has quit IRC | 03:39 | |
*** su_zhang has joined #openstack-barbican | 03:43 | |
*** hyakuhei has quit IRC | 04:15 | |
*** sidx64_Cern has joined #openstack-barbican | 04:15 | |
*** dimtruck is now known as zz_dimtruck | 04:17 | |
*** sid_cerner has joined #openstack-barbican | 04:20 | |
*** hyakuhei has joined #openstack-barbican | 04:21 | |
*** mragupat has joined #openstack-barbican | 04:21 | |
*** woodster_ has joined #openstack-barbican | 04:23 | |
*** sidx64_Cern has quit IRC | 04:24 | |
*** Nirupama has joined #openstack-barbican | 04:25 | |
*** diazjf has joined #openstack-barbican | 04:28 | |
*** jamielennox is now known as jamielennox|away | 05:06 | |
*** dave-mcc_ has quit IRC | 05:15 | |
*** sidx64_Cern has joined #openstack-barbican | 05:23 | |
*** sid_cerner has quit IRC | 05:26 | |
*** fnaval has quit IRC | 05:28 | |
*** jamielennox|away is now known as jamielennox | 05:31 | |
*** hyakuhei has quit IRC | 05:35 | |
*** fnaval has joined #openstack-barbican | 05:44 | |
*** fnaval has quit IRC | 06:10 | |
*** jaosorior has joined #openstack-barbican | 06:10 | |
*** fnaval has joined #openstack-barbican | 06:13 | |
*** mixos has joined #openstack-barbican | 06:34 | |
*** woodster_ has quit IRC | 06:36 | |
*** jaosorior has quit IRC | 06:56 | |
*** tkelsey has joined #openstack-barbican | 07:10 | |
*** tkelsey has quit IRC | 07:14 | |
*** jaosorior has joined #openstack-barbican | 07:20 | |
*** jaosorior has quit IRC | 07:32 | |
*** mixos has quit IRC | 07:32 | |
*** scheuran has joined #openstack-barbican | 07:37 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Updated from global requirements https://review.openstack.org/278897 | 07:38 |
*** diazjf has quit IRC | 07:42 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-barbicanclient: Updated from global requirements https://review.openstack.org/278721 | 07:44 |
*** sidx64 has joined #openstack-barbican | 07:58 | |
*** sidx64_Cern has quit IRC | 08:01 | |
*** tkelsey has joined #openstack-barbican | 08:04 | |
*** jaosorior has joined #openstack-barbican | 08:05 | |
*** shohel has joined #openstack-barbican | 08:20 | |
*** su_zhang has quit IRC | 08:34 | |
*** su_zhang has joined #openstack-barbican | 08:35 | |
*** su_zhang has quit IRC | 08:39 | |
*** mragupat has quit IRC | 08:40 | |
*** openstackgerrit has quit IRC | 08:47 | |
*** openstackgerrit_ has joined #openstack-barbican | 08:47 | |
*** openstackgerrit_ is now known as openstackgerrit | 08:48 | |
*** tkelsey has quit IRC | 09:26 | |
*** scheuran has quit IRC | 09:37 | |
*** scheuran has joined #openstack-barbican | 09:51 | |
*** scheuran has quit IRC | 10:00 | |
*** scheuran has joined #openstack-barbican | 10:02 | |
*** sidx64 has quit IRC | 10:18 | |
*** sidx64 has joined #openstack-barbican | 10:38 | |
*** scheuran has quit IRC | 10:50 | |
*** shohel has quit IRC | 10:56 | |
*** scheuran has joined #openstack-barbican | 11:05 | |
*** peter-hamilton has joined #openstack-barbican | 12:07 | |
*** ig0r_ has joined #openstack-barbican | 12:12 | |
*** su_zhang has joined #openstack-barbican | 12:59 | |
*** spotz is now known as spotz_zzz | 13:00 | |
*** su_zhang has quit IRC | 13:03 | |
*** sidx64 has quit IRC | 13:08 | |
*** woodster_ has joined #openstack-barbican | 13:33 | |
*** rellerreller has joined #openstack-barbican | 13:36 | |
*** Nirupama has quit IRC | 13:43 | |
*** jaosorior has quit IRC | 14:05 | |
*** jaosorior has joined #openstack-barbican | 14:05 | |
*** dave-mccowan has joined #openstack-barbican | 14:08 | |
*** dave-mcc_ has joined #openstack-barbican | 14:11 | |
*** zz_dimtruck is now known as dimtruck | 14:11 | |
*** dave-mccowan has quit IRC | 14:14 | |
*** krotscheck_dcm is now known as krotscheck | 14:15 | |
*** su_zhang has joined #openstack-barbican | 14:23 | |
*** scheuran has quit IRC | 14:35 | |
*** jmckind has joined #openstack-barbican | 14:42 | |
*** hyakuhei has joined #openstack-barbican | 14:54 | |
*** jaosorior has quit IRC | 15:06 | |
*** jhfeng has joined #openstack-barbican | 15:17 | |
*** mragupat has joined #openstack-barbican | 15:18 | |
*** ig0r_ has quit IRC | 15:21 | |
*** woodster_ has quit IRC | 15:36 | |
*** dave-mcc_ has quit IRC | 15:37 | |
*** dave-mccowan has joined #openstack-barbican | 15:37 | |
*** mp1 has joined #openstack-barbican | 15:51 | |
*** spotz_zzz is now known as spotz | 15:55 | |
*** fnaval has quit IRC | 15:57 | |
*** silos has joined #openstack-barbican | 16:01 | |
*** tkelsey has joined #openstack-barbican | 16:11 | |
*** woodster_ has joined #openstack-barbican | 16:11 | |
*** shohel has joined #openstack-barbican | 16:12 | |
*** diazjf has joined #openstack-barbican | 16:18 | |
*** hyakuhei has quit IRC | 16:19 | |
*** fnaval has joined #openstack-barbican | 16:19 | |
*** diazjf1 has joined #openstack-barbican | 16:20 | |
*** mixos has joined #openstack-barbican | 16:21 | |
*** diazjf has quit IRC | 16:22 | |
*** jsavak has joined #openstack-barbican | 16:24 | |
*** peter-hamilton has quit IRC | 16:34 | |
*** mp1 has quit IRC | 16:34 | |
*** hyakuhei has joined #openstack-barbican | 16:38 | |
*** ccneill has joined #openstack-barbican | 16:41 | |
*** scheuran has joined #openstack-barbican | 16:42 | |
*** scheuran has quit IRC | 16:47 | |
*** silos has quit IRC | 16:50 | |
*** silos has joined #openstack-barbican | 16:54 | |
*** nelsnels_ has quit IRC | 16:59 | |
*** mp1 has joined #openstack-barbican | 17:00 | |
*** nelsnelson has joined #openstack-barbican | 17:00 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Introduce Castellan Credential Factory https://review.openstack.org/273863 | 17:01 |
*** gyee has joined #openstack-barbican | 17:05 | |
openstackgerrit | Douglas Mendizábal proposed openstack/barbican: Document Symmetric Secret Type https://review.openstack.org/171488 | 17:14 |
*** mp1 has quit IRC | 17:17 | |
hyakuhei | diazjf1: We need to sync on BYOK | 17:23 |
openstackgerrit | Fernando Diaz proposed openstack/barbican: Cleanup barbican-api-paste pipeline https://review.openstack.org/263000 | 17:26 |
diazjf1 | hyakuhei, hey what's up. Yeah I was meaning to add myself the different project meetings for next week | 17:26 |
hyakuhei | Just flagging it up because we’re never around at the same time :) I think we were going to build a wiki page for it but we didn’t get anywhere…. | 17:27 |
diazjf1 | hyakuhei, I can make the wiki next week. Where on https://wiki.openstack.org/wiki/Security can I add it? Also lmk what you think about https://review.openstack.org/#/c/271517/ :) | 17:30 |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Allow Barbican Key Manager to accept different auth credentials https://review.openstack.org/273872 | 17:31 |
*** jsavak has quit IRC | 17:34 | |
*** rellerreller has quit IRC | 17:42 | |
*** shohel has quit IRC | 17:49 | |
*** silos has quit IRC | 18:00 | |
*** tkelsey has quit IRC | 18:01 | |
*** Kevin_Zheng has quit IRC | 18:35 | |
*** su_zhang has quit IRC | 18:36 | |
*** Kevin_Zheng has joined #openstack-barbican | 18:37 | |
*** gyee has quit IRC | 18:53 | |
*** ccneill has quit IRC | 18:58 | |
*** hyakuhei has quit IRC | 18:59 | |
*** silos has joined #openstack-barbican | 19:05 | |
*** su_zhang has joined #openstack-barbican | 19:07 | |
*** nelsnels_ has joined #openstack-barbican | 19:12 | |
*** nelsnelson has quit IRC | 19:15 | |
*** ccneill has joined #openstack-barbican | 19:24 | |
hockeynut | greetings all - I am (re)working my local barbican and trying to run via barbican-api rather than barbican.sh. As part of that I am trying to see if we can run without needing anything in /etc and I am finding that to be painful. As part of this, I see that we REQUIRE a copy of barbican.conf to be placed into our home directory. Does anyone else think that's silly and should be fixed? | 19:33 |
hockeynut | I would think that all of the config/ini/prop files should be under myLocalbarbican/etc/barbican and not have to be dispersed elsewhere in the system | 19:34 |
silos | hockeynut: I have never seen the use in having the barbican.conf file in the home directory. | 19:34 |
hockeynut | other than "it has to be there" :-) | 19:35 |
hockeynut | wondering if that's an oslo thing or something we can fix | 19:35 |
woodster_ | hockeynut: oslo config looks for (at least to) barbican.conf in the home directory and /etc/barbican folders (not sure the order)...we've called for folks to put into /etc | 19:35 |
silos | hockeynut, woodster_: I believe it looks in the home directory first and if it's there then it doesn't look anywhere else. At least that's what I've seen happen to my deployments. | 19:36 |
woodster_ | hockeynut: the problem with running from your git repo is that the minute you change it for your local needs, it changes from upstream, so it's more convenient and safer to maintain it outside the git repo | 19:36 |
hockeynut | woodster_ true. methinks there might need to be some doc work here to clarify | 19:36 |
*** ccneill has quit IRC | 19:38 | |
hockeynut | but it still seems odd that my home directory is in a search order for a config file | 19:38 |
*** mp1 has joined #openstack-barbican | 19:41 | |
*** ccneill has joined #openstack-barbican | 19:42 | |
*** spotz is now known as spotz_zzz | 19:44 | |
woodster_ | I figure that's the only way for folks that don't have write access to /etc | 19:48 |
*** dimtruck is now known as zz_dimtruck | 19:55 | |
*** zz_dimtruck is now known as dimtruck | 19:55 | |
*** spotz_zzz is now known as spotz | 19:57 | |
*** mixos has quit IRC | 20:02 | |
*** hyakuhei has joined #openstack-barbican | 20:07 | |
*** silos has quit IRC | 20:10 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Allow Barbican Key Manager to accept different auth credentials https://review.openstack.org/273872 | 20:16 |
*** su_zhang has quit IRC | 20:19 | |
*** hyakuhei has quit IRC | 20:20 | |
*** jhfeng has quit IRC | 20:20 | |
*** mp1 has quit IRC | 20:26 | |
*** silos has joined #openstack-barbican | 20:26 | |
*** mp1 has joined #openstack-barbican | 20:26 | |
*** jhfeng has joined #openstack-barbican | 20:30 | |
*** hyakuhei has joined #openstack-barbican | 20:40 | |
redrobot | hockeynut yeah, that's all oslo.config magic. Even the name of the file is inferred from the name of the project. What I usually do is make a symlink from $HOME to my working directory. | 20:44 |
hockeynut | redrobot not a bad idea there. that's why you're PTL and the rest of us are GPS | 20:45 |
*** mp1 has quit IRC | 20:45 | |
*** mp1 has joined #openstack-barbican | 20:46 | |
redrobot | hockeynut one thing I wish we could do is have a --config-file option so you can set where the config should be loaded from instead of having to abide by oslo.config magic conventions | 20:46 |
*** su_zhang has joined #openstack-barbican | 20:50 | |
hockeynut | redrobot pull request accepted? | 20:50 |
redrobot | hockeynut oslo.config documentation kinda sucks... and I haven't been able to figure out how to pass variables to a wgsi process... | 20:51 |
*** su_zhang has quit IRC | 20:56 | |
jkf | redrobot: environment variables? | 20:57 |
*** silos has quit IRC | 21:03 | |
redrobot | jkf that might work... just gotta figure out how to read the env before oslo.config parsing begins. | 21:04 |
*** su_zhang has joined #openstack-barbican | 21:09 | |
*** silos has joined #openstack-barbican | 21:11 | |
*** hyakuhei has quit IRC | 21:15 | |
*** edtubill has joined #openstack-barbican | 21:19 | |
*** jorge_munoz has quit IRC | 21:29 | |
diazjf1 | hockeynut, checkout https://github.com/openstack/oslo.config/blob/master/oslo_config/cfg.py#L572-L579 for the oslo magic, I think this can be overridden with https://github.com/openstack/oslo.config/blob/master/oslo_config/cfg.py#L2082 | 21:37 |
*** chlong has quit IRC | 22:03 | |
*** dimtruck is now known as zz_dimtruck | 22:11 | |
redrobot | Barbican @ Rackspace is live! :D http://go.rackspace.com/cloud-keep.html | 22:19 |
*** zz_dimtruck is now known as dimtruck | 22:20 | |
hockeynut | w00t w00t! | 22:20 |
silos | congrats!! | 22:20 |
openstackgerrit | Douglas Mendizábal proposed openstack/barbican: Document public secret type https://review.openstack.org/171859 | 22:21 |
jkf | redrobot: Congrats! Is that using the new HSM code I wrote? How's it been performing for you? | 22:22 |
*** mragupat has quit IRC | 22:23 | |
redrobot | jkf indeed it is! I think we're only running a few days behind master | 22:23 |
redrobot | jkf maxing out at about 20 rps | 22:23 |
redrobot | jkf good enough for our Early Access program, but we definitely want to improve on it | 22:23 |
diazjf1 | redrobot congrats man! | 22:27 |
jkf | redrobot: Interesting. I'd be interested in hearing more about what you find there. I can hit 25-30/second in my environment, but I haven't put a profiler on the code yet to find bottlenecks. | 22:27 |
jkf | That's on a single process. | 22:27 |
redrobot | jkf we have _some_ newrelic reporting thanks to https://github.com/openstack/barbican/blob/master/barbican/api/app.py#L24-L25 but it's not smart enough to measure the time spent on the HSM | 22:28 |
*** mragupat has joined #openstack-barbican | 22:29 | |
woodster_ | jkf: are you multi-threading at all? | 22:29 |
redrobot | silos diazjf1 thanks, y'all! It took a lot of rackers to make this happen | 22:29 |
jkf | woodster_: No, but I'm thinking of playing with it at some point. | 22:29 |
woodster_ | and a lot of contribs to make the code happen too | 22:30 |
redrobot | woodster_ +1000 that too! | 22:30 |
diazjf1 | woohooo! :) | 22:31 |
redrobot | diazjf1 while I have you here ... Example 2.2 in CR https://review.openstack.org/#/c/171859/4 totally works for me | 22:34 |
redrobot | diazjf1 just went through and copy/pasted it a few times into my shell just to make sure | 22:35 |
redrobot | diazjf1 I get a ref every time. | 22:35 |
diazjf1 | redrobot, I'll take another look in a few mins. I tried copying it from the doc job and it gave me a 400 error | 22:36 |
diazjf1 | redrobot, I was running master as well | 22:36 |
redrobot | diazjf1 strange ... looks like correct JSON to me... maybe PUB_BASE64 didn't get set for you for some reason? | 22:37 |
diazjf1 | redrobot, I did echo it and it was there. Maybe there was some problem when passing it | 22:37 |
diazjf1 | the strange thing is that the other examples which follow a similar flow worked | 22:38 |
diazjf1 | redrobot, I'm starting a new vagrant and will retry it in 15 | 22:45 |
*** ccneill has quit IRC | 22:52 | |
*** ccneill has joined #openstack-barbican | 22:58 | |
*** jmckind has quit IRC | 23:02 | |
*** spotz is now known as spotz_zzz | 23:03 | |
diazjf1 | redrobot, still fails for me. Here's my log http://paste.openstack.org/show/486775/ | 23:04 |
*** mragupat has quit IRC | 23:11 | |
*** jorgem has quit IRC | 23:14 | |
*** jorgem has joined #openstack-barbican | 23:15 | |
*** edtubill has quit IRC | 23:15 | |
*** mp1 has quit IRC | 23:17 | |
*** silos has quit IRC | 23:18 | |
*** jhfeng has quit IRC | 23:18 | |
*** yfujioka has quit IRC | 23:21 | |
diazjf1 | redrobot, I figured it out | 23:24 |
diazjf1 | its because of the spaces in $PUB_BASE64 | 23:25 |
diazjf1 | see http://paste.openstack.org/show/486777/ | 23:25 |
*** mp1 has joined #openstack-barbican | 23:28 | |
*** chlong has joined #openstack-barbican | 23:30 | |
*** mp1 has quit IRC | 23:34 | |
*** mp1 has joined #openstack-barbican | 23:38 | |
*** mp1 has quit IRC | 23:41 | |
*** dimtruck is now known as zz_dimtruck | 23:52 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!