*** david-lyle_ has joined #openstack-barbican | 00:22 | |
*** david-lyle_ has quit IRC | 00:27 | |
*** chlong has quit IRC | 00:54 | |
*** chlong has joined #openstack-barbican | 01:11 | |
*** chlong is now known as chlong_POffice | 01:21 | |
*** hdd has joined #openstack-barbican | 01:41 | |
*** david-lyle_ has joined #openstack-barbican | 02:25 | |
*** david-lyle_ has quit IRC | 02:29 | |
*** nkinder has quit IRC | 03:15 | |
*** nkinder has joined #openstack-barbican | 03:35 | |
*** nkinder has quit IRC | 03:47 | |
*** david-lyle_ has joined #openstack-barbican | 04:26 | |
*** david-lyle_ has quit IRC | 04:32 | |
*** notmyname has quit IRC | 04:36 | |
*** notmyname has joined #openstack-barbican | 04:48 | |
*** akshayb_07 has joined #openstack-barbican | 05:25 | |
akshayb_07 | Hello, I was trying to setup OpenStack barbican. I am able to create orders and secrets using admin user. However it returns 4xx Forbidden when I try with some other user. I think this is because of default policy.json. How can I enable general users to access barbican API? I am not sure if this is a right channel to post the query. If not can anyone point me to the right channel? | 05:35 |
---|---|---|
*** jsheeren has joined #openstack-barbican | 05:38 | |
*** hdd has quit IRC | 06:22 | |
*** david-lyle_ has joined #openstack-barbican | 06:29 | |
*** andreas_s has joined #openstack-barbican | 06:32 | |
*** david-lyle_ has quit IRC | 06:33 | |
*** pcaruana has joined #openstack-barbican | 06:37 | |
akshayb_07 | Hello, I was trying to setup OpenStack barbican. I am able to create orders and secrets using admin user. However it returns 4xx Forbidden when I try with some other user. I think this is because of default policy.json. How can I enable general users to access barbican API? I am not sure if this is a right channel to post the query. If not can anyone point me to the right channel? | 07:12 |
*** alee has joined #openstack-barbican | 07:57 | |
*** yfujioka has joined #openstack-barbican | 08:07 | |
*** yfujioka has quit IRC | 08:08 | |
*** david-lyle_ has joined #openstack-barbican | 08:31 | |
*** david-lyle_ has quit IRC | 08:36 | |
*** david-lyle_ has joined #openstack-barbican | 09:32 | |
*** david-lyle_ has quit IRC | 09:36 | |
*** hwcomcn has joined #openstack-barbican | 09:50 | |
*** hwcomcn has quit IRC | 09:51 | |
*** hwcomcn has joined #openstack-barbican | 09:52 | |
*** hwcomcn has quit IRC | 09:55 | |
*** hwcomcn has joined #openstack-barbican | 09:58 | |
*** hwcomcn has quit IRC | 10:03 | |
*** hwcomcn has joined #openstack-barbican | 10:04 | |
*** hwcomcn has quit IRC | 10:05 | |
*** hwcomcn has joined #openstack-barbican | 10:06 | |
openstackgerrit | Merged openstack/barbican: dogtag: Only call initialize() if crypto is not None https://review.openstack.org/344271 | 10:38 |
*** slunkad_ has quit IRC | 11:06 | |
*** slunkad_ has joined #openstack-barbican | 11:08 | |
*** david-lyle_ has joined #openstack-barbican | 11:34 | |
*** david-lyle_ has quit IRC | 11:39 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Updated from global requirements https://review.openstack.org/345431 | 12:58 |
*** woodster_ has joined #openstack-barbican | 13:19 | |
*** lixiaoy1 has quit IRC | 13:30 | |
*** lixiaoy1 has joined #openstack-barbican | 13:34 | |
*** david-lyle_ has joined #openstack-barbican | 13:36 | |
*** david-lyle_ has quit IRC | 13:41 | |
*** hwcomcn has quit IRC | 14:04 | |
*** randallburt has joined #openstack-barbican | 14:11 | |
*** randallburt1 has joined #openstack-barbican | 14:16 | |
*** randallburt has quit IRC | 14:18 | |
*** jsheeren has quit IRC | 14:19 | |
*** alee has quit IRC | 14:23 | |
*** alee has joined #openstack-barbican | 14:23 | |
*** catintheroof has joined #openstack-barbican | 14:24 | |
catintheroof | hi guys, quick question, does anyone knows how to read the secret metadata (key/values) using the python-barbicanclient ? | 14:25 |
catintheroof | i dont see metadata on a secret object | 14:25 |
*** spotz_zzz is now known as spotz | 14:27 | |
*** spotz is now known as spotz_zzz | 14:29 | |
*** michauds has joined #openstack-barbican | 14:30 | |
*** spotz_zzz is now known as spotz | 14:32 | |
*** jmckind has joined #openstack-barbican | 14:32 | |
*** zz_dimtruck is now known as dimtruck | 14:35 | |
*** jmckind_ has joined #openstack-barbican | 14:36 | |
*** jmckind has quit IRC | 14:39 | |
catintheroof | sorry, user defined secret metadata | 14:55 |
*** jmckind_ has quit IRC | 14:55 | |
*** jmckind has joined #openstack-barbican | 14:57 | |
catintheroof | i can see that there's a blueprint, is there something done regarding this ? https://blueprints.launchpad.net/python-barbicanclient/+spec/add-user-metadata | 15:03 |
woodster_ | catintheroof: my guess is that nothing has been done on this blueprint, but diazjf would know for sure | 15:23 |
* woodster_ generally I think we are always looking for barbican client help | 15:24 | |
*** akshayb_07 has quit IRC | 15:24 | |
woodster_ | alee: do you know if jaosorior has been working on barbican client things such as above ^^^^? | 15:25 |
*** pcaruana has quit IRC | 15:26 | |
alee | woodster_, I don't think he has | 15:26 |
catintheroof | woodster_, alee oka, will wait for him, since i cant do nothing without this | 15:26 |
catintheroof | i was thinking to do somethign like _fetch_payload on the client.py | 15:27 |
catintheroof | but that would be ....less than optimal | 15:27 |
alee | catintheroof, jaosorior is going to be out this week on PTO. | 15:27 |
alee | catintheroof, he's periodically in contact - but I would not expect him to do much this week | 15:28 |
catintheroof | alee, what a shame, this blueprint is out since 2015.10 | 15:29 |
woodster_ | catintheroof: I think redrobot (PTL) is on vacation. Perhaps diazjf is out as well. I'm 90% sure nothing has been done on that blueprint but if you can wait that's probably prudent I suppose :) | 15:29 |
alee | catintheroof, if you wanted to put up a patch/design though - we could certainly take a look at it. | 15:29 |
catintheroof | alee, i had problems understanding client.py big time, but i need this done, if not, i would have to drop barbican usage in my company just because programatically i cant read metadata | 15:31 |
catintheroof | alee, do you know a way that is not metadata to say something like this secret is an OPENSTACK type, this one AWS type and this one AZURE type | 15:32 |
alee | catintheroof, I'm sure adding metadata retrieval to the client will be a relatively easy thing to do - and should not take too long | 15:32 |
alee | catintheroof, the use case you're descrbing is I think exactly what the metadata is for | 15:33 |
*** dave-mccowan has joined #openstack-barbican | 15:33 | |
*** andreas_s has quit IRC | 15:33 | |
catintheroof | alee, yeahp, that's why i think i need to do it. but after doing the READING part ... i think i would need the WRITING one, so ...i can do the reading one (far from whats expected) in the client, and push to have the "right way" from you guys | 15:35 |
catintheroof | alee, who would be wise to talk to to get this done? | 15:35 |
catintheroof | alee, diazjf ? | 15:36 |
alee | woodster_, anyone other than jaosorior been working on the client? | 15:36 |
alee | catintheroof, diazjf would have been my guess | 15:36 |
alee | catintheroof, if you put a patch up - it will get attention from the client guys | 15:36 |
alee | catintheroof, even if to tell you its all wrong .. do it this way instead | 15:37 |
*** david-lyle_ has joined #openstack-barbican | 15:37 | |
catintheroof | alee, will do, thanks | 15:38 |
woodster_ | alee: yeah, I'm not aware of folks working on the client actively other than jaosorior | 15:38 |
*** gyee has joined #openstack-barbican | 15:39 | |
woodster_ | catintheroof: if you put up a CR for that probably low risk someone else is working on it, but might get some refactor feedback | 15:39 |
catintheroof | woodster_, will try to do my best | 15:40 |
catintheroof | woodster_, alee thank you all | 15:40 |
woodster_ | catintheroof: alee I also haven't been tracking the barbican client vs openstack client efforts (such as if the latter is replacing the former at some point) | 15:42 |
*** david-lyle_ has quit IRC | 15:43 | |
catintheroof | woodster_, alee that is what supposed to happen, tha thing is that the python-barbicanclient doesnt support it (user metadata) | 15:44 |
woodster_ | catintheroof: probably ok to proceed on the barbican client path for now, with possible movement of code to the openstack client in the future | 15:45 |
catintheroof | woodster_, absolutely | 15:46 |
*** diazjf has joined #openstack-barbican | 15:47 | |
*** kfarr has joined #openstack-barbican | 15:47 | |
*** dave-mccowan has quit IRC | 16:14 | |
catintheroof | woodster_, alee where can i put the draft of the "getter" for the user_metadata property of the barbican client ? | 16:19 |
catintheroof | so you can take it a look ? | 16:19 |
woodster_ | catintheroof: alee if it's not a lot of code maybe just put up a CR referencing that blueprint? | 16:21 |
catintheroof | woodster_, sorry my ignorance, CR = ??? and nope, is not a lot of code, is very little | 16:21 |
woodster_ | catintheroof: CR = change request. Have you put up any gerrit reviews before? | 16:23 |
catintheroof | woodster_, yes, but since im modifying the ubuntu packages barbican client, im not modifying the cloned client, so, how can i submit just my change ? or maybe just the code to take it a look ? | 16:25 |
woodster_ | catintheroof: I'm not following you on that....packaging happens after a release is cut I figure. So the first step would be just to modify the source I'd think via a CR. | 16:28 |
woodster_ | alee: zigo ^^^^ do you have insight on the barbican python client packaging process? | 16:29 |
catintheroof | woodster_, i mean this ... | 16:30 |
alee | woodster_, catintheroof sorry - in meeting -- will respond later .. | 16:30 |
catintheroof | woodster_, i allways git cloned the code, modified it and then did a gerrit thing to generate a new gerrit topic, but since im not using barbican code from github, i need to put my code where to generate a CR in a easy way ? | 16:31 |
catintheroof | woodster_, sorry if im not making myself clear | 16:31 |
woodster_ | catintheroof: so you have already setup gerrit things via this then?: http://docs.openstack.org/infra/manual/developers.html | 16:34 |
catintheroof | yeahp | 16:35 |
catintheroof | woodster_, ^^ | 16:35 |
*** david-lyle_ has joined #openstack-barbican | 16:35 | |
woodster_ | catintheroof: so did you clone from here originally?: https://github.com/openstack/python-barbicanclient | 16:35 |
catintheroof | woodster_, nope, modifying the code from the version that the ubuntu packages installed on a server from the mitaka repos | 16:36 |
woodster_ | catintheroof: ah got you. I'd say just clone https://github.com/openstack/python-barbicanclient and then git checkout -b bp/<name of blueprint>, then 'cherry pick' your Ubuntu changes onto that branch (probably a copy pasta thing across git repos anyway). As long as not may lines of code, shouldn't be too intense to copy those over | 16:38 |
catintheroof | woodster_, and after that ? what is the process (commands) to generate the CR ? | 16:40 |
woodster_ | catintheroof: that link above is the official docs on the workflow, but this older wiki might also help out: https://github.com/cloudkeep/barbican/wiki/Gerrit-Review-Process | 16:41 |
catintheroof | woodster_, thanks so much ! will try to do it | 16:41 |
catintheroof | woodster_, cause is working already, and works like a charm | 16:41 |
*** diazjf has quit IRC | 16:45 | |
*** kfarr has quit IRC | 16:47 | |
woodster_ | catintheroof: yeah it would be good to have that feature in the client. It would be good to eventually have unit tests for the feature, but putting the CR up is a good first step. Running tox tests beforehand is good to do as well, though gerrit will do that eventually too. | 16:48 |
*** haplo37__ has joined #openstack-barbican | 16:50 | |
*** hdd has joined #openstack-barbican | 16:53 | |
*** diazjf has joined #openstack-barbican | 16:59 | |
*** david-lyle_ has quit IRC | 17:01 | |
*** nkinder has joined #openstack-barbican | 17:01 | |
*** david-lyle_ has joined #openstack-barbican | 17:07 | |
*** hdd has quit IRC | 17:09 | |
*** hdd has joined #openstack-barbican | 17:11 | |
*** diazjf has quit IRC | 17:12 | |
arunkant | can any cores review this..it has been pending for a while | 17:12 |
arunkant | https://review.openstack.org/#/c/311830/ | 17:12 |
*** pcaruana has joined #openstack-barbican | 17:23 | |
*** david-lyle_ is now known as david-lyle | 17:57 | |
*** alee is now known as alee_dinner | 18:16 | |
*** alee_dinner has quit IRC | 18:19 | |
*** michauds has quit IRC | 18:42 | |
*** michauds has joined #openstack-barbican | 18:58 | |
*** diazjf has joined #openstack-barbican | 19:00 | |
zigo | catintheroof: woodster_: Indeed, we do package using a git tag as reference. Without a tag, there wont be any update in the upstream code, unless we add a Debian specific patch. Though those are to fix issues/bugs, and we always prefer things to happen upstream first. Usually, we write these patches at the distro level and send them upstream via gerrit, hoping to remove them on the next new upstream release upload. | 19:10 |
zigo | catintheroof: What are you willing to change exactly? | 19:11 |
zigo | BTW, things happen in Debian first, before they move to Ubuntu. | 19:12 |
catintheroof | zigo, woodster_ i've added this > http://paste.openstack.org/show/541642/ to secrets.py to get the user metadata to the python-barbicanclient | 19:22 |
catintheroof | zigo, i need to find some time to generate a CR | 19:23 |
*** chlong_POffice has quit IRC | 19:30 | |
*** chlong_POffice has joined #openstack-barbican | 19:31 | |
woodster_ | zigo: thanks for the info. I'm thinking a code CR would be a good thing here for the next release for sure | 19:33 |
woodster_ | catintheroof: that looks good (though I think the last two lines need to be indented over). Generating the CR should be very easy once you have gerrit setup and the barbican client repo cloned | 19:33 |
catintheroof | woodster_, will do ;) | 19:36 |
*** kfarr has joined #openstack-barbican | 19:55 | |
*** gyee has quit IRC | 20:01 | |
openstackgerrit | Sebastian Jeuk proposed openstack/barbican: Fixed title in ACLs section of API Guide https://review.openstack.org/347007 | 20:02 |
*** alee has joined #openstack-barbican | 20:05 | |
openstackgerrit | Sebastian Jeuk proposed openstack/barbican: Fixed typo in ACL section of API Guide https://review.openstack.org/347007 | 20:07 |
woodster_ | catintheroof: you can join openstack-meeting-alt now for the barbican weekly meeting | 20:10 |
catintheroof | joined XD | 20:11 |
alee | woodster_, what kind of permissions/ roles are needed to delete a secret? | 20:15 |
alee | arunkant, ^^ ? | 20:16 |
woodster_ | alee: I think only an admin role can delete secrets. arunkant's CR allows owners to delete their own secrets | 20:17 |
alee | woodster_, oh, that CR has not yet landed? | 20:17 |
arunkant | alee..yes | 20:17 |
alee | woodster_, I thought owners could delete their own secrets | 20:17 |
alee | arunkant, which CR is that? | 20:18 |
arunkant | https://review.openstack.org/#/c/311830/ | 20:18 |
woodster_ | arunkant: ^^^^ I left some comments out there please | 20:19 |
arunkant | woodster_ ..looking into it..will address soon | 20:19 |
woodster_ | arunkant: fairly minor I think | 20:20 |
alee | arunkant, I'll review too once you address woodster_ comments | 20:20 |
* woodster_ thought that was already in the code base for some reason | 20:20 | |
arunkant | woodster_, alee: okay..its minor label change..will do now | 20:20 |
openstackgerrit | Arun Kant proposed openstack/barbican: User with creator role can delete his/her own secret and container https://review.openstack.org/311830 | 20:25 |
arunkant | alee, woodster_ .. please review new patch for above change. | 20:25 |
woodster_ | arunkant: can you update the doc too? That's a good feature to advertise in the docs I think | 20:26 |
arunkant | woodster_ , let me see if we have any restriction listed around this in docs..I will update that. | 20:28 |
woodster_ | arunkant: This was one place I saw something: https://github.com/openstack/barbican/blob/master/doc/source/admin-guide-cloud/access_control.rst#role-based-access-control-rbac | 20:29 |
woodster_ | arunkant: I thought we had an RBAC table at one time but didn't find it | 20:29 |
arunkant | woodster_: I did not find anything in API doc..http://docs-draft.openstack.org/30/311830/6/check/gate-barbican-docs/876ed6d//doc/build/html/api/reference/secrets.html#delete-v1-secrets-uuid | 20:30 |
woodster_ | arunkant: actually, look in the section below that one...Default Policy | 20:31 |
woodster_ | arunkant: https://github.com/openstack/barbican/blob/master/doc/source/admin-guide-cloud/access_control.rst#default-policy | 20:36 |
*** diazjf has quit IRC | 20:38 | |
openstackgerrit | Arun Kant proposed openstack/barbican: User with creator role can delete his/her own secret and container https://review.openstack.org/311830 | 20:38 |
woodster_ | arunkant: nice, thanks! | 20:40 |
openstackgerrit | Arun Kant proposed openstack/barbican: User with creator role can delete his/her own secret and container https://review.openstack.org/311830 | 20:42 |
arunkant | woodster_ ..please review again..minor correction: https://review.openstack.org/#/c/311830/8..9/doc/source/admin-guide-cloud/access_control.rst | 20:42 |
woodster_ | arunkant: done thanks | 20:43 |
arunkant | woodster_, gr8..thanks | 20:43 |
woodster_ | alee: fyi ^^^^ | 20:44 |
alee | woodster_, arunkant looking | 20:45 |
*** gyee has joined #openstack-barbican | 20:53 | |
*** chlong_POffice has quit IRC | 20:56 | |
*** gyee has quit IRC | 21:03 | |
*** haplo37__ has quit IRC | 21:03 | |
*** diazjf has joined #openstack-barbican | 21:08 | |
*** chlong_POffice has joined #openstack-barbican | 21:10 | |
alee | arunkant, done | 21:21 |
arunkant | alee, thanks | 21:22 |
*** dimtruck is now known as zz_dimtruck | 21:23 | |
*** hdd has quit IRC | 21:26 | |
*** diazjf has quit IRC | 21:35 | |
*** diazjf has joined #openstack-barbican | 21:38 | |
*** zz_dimtruck is now known as dimtruck | 21:43 | |
*** spotz is now known as spotz_zzz | 22:24 | |
*** hdd has joined #openstack-barbican | 22:24 | |
*** diazjf has quit IRC | 22:39 | |
*** michauds has quit IRC | 22:42 | |
*** jmckind has quit IRC | 22:54 | |
*** hdd has quit IRC | 22:57 | |
*** chlong_POffice has quit IRC | 23:25 | |
*** randallburt1 has quit IRC | 23:29 | |
*** chlong_POffice has joined #openstack-barbican | 23:42 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!