*** dimtruck is now known as zz_dimtruck | 00:00 | |
openstackgerrit | zhangyanxian proposed openstack/barbican: typo fix https://review.openstack.org/361929 | 00:34 |
---|---|---|
openstackgerrit | Jamie Lennox proposed openstack/barbican: Don't inspect oslo.context https://review.openstack.org/369092 | 00:46 |
openstackgerrit | Jamie Lennox proposed openstack/barbican: Don't inspect oslo.context https://review.openstack.org/369092 | 00:49 |
*** chlong_ has joined #openstack-barbican | 01:14 | |
*** michauds has joined #openstack-barbican | 01:18 | |
*** chlong_ has quit IRC | 01:49 | |
*** chlong_ has joined #openstack-barbican | 02:06 | |
*** zz_dimtruck is now known as dimtruck | 02:28 | |
jamielennox | woodster_: and others here: https://review.openstack.org/#/c/369092/ fixes a problem the release team is having with positional and oslo.context libraries | 02:38 |
jamielennox | it should be a really simple review when people have a moment and would unblock some release dependency problems | 02:39 |
woodster_ | jamielennox: should merge in a bit, thanks gain | 02:47 |
woodster_ | again | 02:47 |
jamielennox | That was quick, thanks | 02:50 |
woodster_ | jamielennox: it's fun to merge stuff in every once in a while :) | 02:52 |
openstackgerrit | Merged openstack/barbican: Don't inspect oslo.context https://review.openstack.org/369092 | 03:18 |
woodster_ | jamielennox: ^^^ | 03:20 |
jamielennox | woodster_: woot! thanks | 03:20 |
woodster_ | jamielennox: good luck unclogging things on your side! | 03:21 |
openstackgerrit | Merged openstack/python-barbicanclient: Use international logging message https://review.openstack.org/356979 | 03:31 |
openstackgerrit | Merged openstack/barbican: Fix test suite cleanup https://review.openstack.org/357277 | 03:53 |
*** michauds has quit IRC | 03:56 | |
*** jamielennox is now known as jamielennox|away | 04:05 | |
*** jamielennox|away is now known as jamielennox | 04:08 | |
*** dimtruck is now known as zz_dimtruck | 04:29 | |
*** jamielennox is now known as jamielennox|away | 04:41 | |
*** jamielennox|away is now known as jamielennox | 04:46 | |
*** jaosorior has joined #openstack-barbican | 05:21 | |
*** jamielennox is now known as jamielennox|away | 05:53 | |
*** jamielennox|away is now known as jamielennox | 06:00 | |
*** jamielennox is now known as jamielennox|away | 06:13 | |
*** jamielennox|away is now known as jamielennox | 06:30 | |
*** andreas_s has joined #openstack-barbican | 06:49 | |
*** shohel has joined #openstack-barbican | 06:50 | |
*** woodster_ has quit IRC | 06:59 | |
*** pcaruana has joined #openstack-barbican | 07:02 | |
*** mmotiani has quit IRC | 07:11 | |
*** mmotiani has joined #openstack-barbican | 07:16 | |
*** openstackgerrit has quit IRC | 07:48 | |
*** openstackgerrit has joined #openstack-barbican | 07:49 | |
*** tkelsey has joined #openstack-barbican | 08:17 | |
*** zigo_ is now known as zigo | 08:34 | |
*** jaosorior is now known as jaosorior_lunch | 09:05 | |
*** jaosorior_lunch is now known as jaosorior | 10:04 | |
*** shohel1 has joined #openstack-barbican | 10:04 | |
*** shohel has quit IRC | 10:05 | |
*** shohel has joined #openstack-barbican | 10:09 | |
*** shohel1 has quit IRC | 10:11 | |
*** shohel has quit IRC | 10:15 | |
*** permalac has joined #openstack-barbican | 10:17 | |
*** shohel has joined #openstack-barbican | 10:28 | |
*** spotz_zzz is now known as spotz | 10:49 | |
*** permalac has quit IRC | 10:51 | |
*** shohel has quit IRC | 11:07 | |
*** spotz is now known as spotz_zzz | 11:16 | |
*** permalac has joined #openstack-barbican | 12:33 | |
openstackgerrit | Merged openstack/barbican: Support upper-constratints.txt in tox environments https://review.openstack.org/358404 | 12:55 |
*** jaosorior has quit IRC | 12:59 | |
*** jaosorior has joined #openstack-barbican | 13:00 | |
openstackgerrit | Clenimar Filemon proposed openstack/python-barbicanclient: Cast sets to lists in acl functional tests https://review.openstack.org/351844 | 13:01 |
*** woodster_ has joined #openstack-barbican | 13:18 | |
*** zz_dimtruck is now known as dimtruck | 13:42 | |
arunkant | _woodster: Thanks for comments on multiple backends reviews. Can you please check my reply (especially part 2 review) as I have to make changes based on it. | 13:46 |
arunkant | woodster_ ^^^ | 13:49 |
arunkant | Did I have typo again..woodster_ ^^^ | 13:53 |
woodster_ | arunkant: replied back just now | 14:17 |
*** dimtruck is now known as zz_dimtruck | 14:24 | |
*** jmckind has joined #openstack-barbican | 14:25 | |
*** randallburt has joined #openstack-barbican | 14:31 | |
*** randallburt1 has joined #openstack-barbican | 14:32 | |
woodster_ | alee: redrobot In addition to Arun's CR's, this one would be good to land, and it's not too large: https://review.openstack.org/#/c/251168/ It has two +2's but I'd like for one of you two to 'bless'/merge it as it affects consumers API behavior somewhat | 14:32 |
*** randallburt has quit IRC | 14:35 | |
*** dave-mccowan has joined #openstack-barbican | 14:41 | |
*** zz_dimtruck is now known as dimtruck | 14:41 | |
*** jaosorior has quit IRC | 15:02 | |
alee | arunkant, woodster_ https://review.openstack.org/#/c/354285 looks pretty good. I will +2 once woodster_ comments are addressed | 15:03 |
alee | arunkant, woodster_ as far as I can tell, the only thing to do there was to add some asserts in the tests (asuming the unused member variable is removed in a subsequent patch) | 15:05 |
*** edtubill has joined #openstack-barbican | 15:08 | |
*** filler has quit IRC | 15:10 | |
*** sigmavirus|awa has quit IRC | 15:11 | |
*** _sigmavirus24 has joined #openstack-barbican | 15:12 | |
*** filler has joined #openstack-barbican | 15:12 | |
*** mixos has joined #openstack-barbican | 15:26 | |
woodster_ | alee: agreed | 15:26 |
alee | arunkant, woodster_ going through part 3 now .. | 15:28 |
woodster_ | alee: This one is so close once you've caught up on the others :) https://review.openstack.org/#/c/251168/ | 15:28 |
alee | ok | 15:28 |
*** dave-mccowan has quit IRC | 15:32 | |
*** dave-mccowan has joined #openstack-barbican | 15:37 | |
*** diazjf has joined #openstack-barbican | 15:40 | |
openstackgerrit | Arun Kant proposed openstack/barbican: Central logic to sync secret store data with conf data (Part 3) https://review.openstack.org/357544 | 15:50 |
openstackgerrit | Arun Kant proposed openstack/barbican: Adding rest API for secret-stores resource (Part 4) https://review.openstack.org/358162 | 15:50 |
openstackgerrit | Arun Kant proposed openstack/barbican: Changes for multiple backend conf and friendly plugin names (Part 2) https://review.openstack.org/354285 | 15:50 |
arunkant | _wooster, alee: Addressed review comments till part 3 .. will work for part 5 review comment. | 15:50 |
arunkant | woodster_ : ^^^ | 15:51 |
*** jmckind_ has joined #openstack-barbican | 16:00 | |
*** jmckind has quit IRC | 16:01 | |
*** tdink has joined #openstack-barbican | 16:03 | |
*** andreas_s has quit IRC | 16:07 | |
*** randallburt1 has quit IRC | 16:17 | |
*** permalac has quit IRC | 16:20 | |
alee | arunkant, posted some comments on the previous version of part 3 | 16:25 |
alee | arunkant, more likely than not, they will still apply | 16:25 |
arunkant | alee, thanks..let me check | 16:26 |
*** diazjf has quit IRC | 16:56 | |
*** pcaruana has quit IRC | 16:59 | |
*** randallburt has joined #openstack-barbican | 17:02 | |
*** xek has quit IRC | 17:03 | |
-openstackstatus- NOTICE: The Gerrit service on review.openstack.org is being restarted now to address current performance problems, but should return to a working state within a few minutes | 17:09 | |
*** tkelsey has quit IRC | 17:22 | |
*** xek has joined #openstack-barbican | 17:24 | |
*** diazjf has joined #openstack-barbican | 17:47 | |
openstackgerrit | Merged openstack/barbican: Remove consumer check for project_id to match containers https://review.openstack.org/251168 | 17:52 |
*** dimtruck is now known as zz_dimtruck | 18:03 | |
*** diazjf has quit IRC | 18:18 | |
*** diazjf has joined #openstack-barbican | 18:22 | |
*** david-lyle has quit IRC | 18:23 | |
openstackgerrit | Merged openstack/python-barbicanclient: Cast sets to lists in acl functional tests https://review.openstack.org/351844 | 18:25 |
*** david-lyle has joined #openstack-barbican | 18:26 | |
arunkant | alee: can you check my reply on part 3 (https://review.openstack.org/#/c/357544/8) and please let me know your response. | 18:35 |
*** pcaruana has joined #openstack-barbican | 18:36 | |
*** Kevin_Zheng has quit IRC | 18:38 | |
*** Kevin_Zheng has joined #openstack-barbican | 18:38 | |
alee | arunkant, replied | 19:15 |
alee | arunkant, woodster_ redrobot we never did implement active/passive secret stores eh? | 19:15 |
*** david-lyle has quit IRC | 19:16 | |
*** dave-mccowan has quit IRC | 19:16 | |
*** Daviey_ has quit IRC | 19:16 | |
*** nkinder has quit IRC | 19:16 | |
*** jamespage has quit IRC | 19:16 | |
*** reaperhulk has quit IRC | 19:16 | |
*** cargonza has quit IRC | 19:17 | |
*** rm_work has quit IRC | 19:17 | |
*** alee has quit IRC | 19:17 | |
*** dgonzalez has quit IRC | 19:17 | |
*** panatl has quit IRC | 19:17 | |
*** rbradfor has quit IRC | 19:17 | |
*** madorn has quit IRC | 19:17 | |
*** beisner has quit IRC | 19:17 | |
*** jamielennox has quit IRC | 19:17 | |
*** Guest66666 has quit IRC | 19:17 | |
*** mathiasb has quit IRC | 19:17 | |
*** jorgem has quit IRC | 19:17 | |
*** edtubill has quit IRC | 19:17 | |
*** zigo has quit IRC | 19:17 | |
*** zz_dimtruck has quit IRC | 19:17 | |
*** spotz_zzz has quit IRC | 19:17 | |
*** filler has quit IRC | 19:17 | |
*** jgrassler has quit IRC | 19:17 | |
*** hyakuhei has quit IRC | 19:17 | |
*** _sigmavirus24 has quit IRC | 19:17 | |
*** jraim has quit IRC | 19:17 | |
*** phschwartz has quit IRC | 19:17 | |
*** tdink has quit IRC | 19:17 | |
*** alpha_ori has quit IRC | 19:17 | |
*** Kevin_Zheng has quit IRC | 19:17 | |
*** woodster_ has quit IRC | 19:17 | |
*** Kiall_ has quit IRC | 19:17 | |
*** vipul has quit IRC | 19:17 | |
*** eglute has quit IRC | 19:18 | |
*** jvrbanac has quit IRC | 19:18 | |
*** chlong_ has quit IRC | 19:18 | |
*** crc32|znc has quit IRC | 19:18 | |
*** jmckind_ has quit IRC | 19:18 | |
*** stevemar has quit IRC | 19:18 | |
*** stupidnic has quit IRC | 19:18 | |
*** haplo37_ has quit IRC | 19:18 | |
*** tonyb has quit IRC | 19:18 | |
*** pcaruana has quit IRC | 19:18 | |
*** diazjf has quit IRC | 19:18 | |
*** mixos has quit IRC | 19:18 | |
*** DuncanT has quit IRC | 19:18 | |
*** briancurtin has quit IRC | 19:18 | |
*** kragniz has quit IRC | 19:18 | |
*** tinwood has quit IRC | 19:18 | |
*** openstackgerrit has quit IRC | 19:18 | |
*** mmotiani has quit IRC | 19:18 | |
*** arunkant has quit IRC | 19:18 | |
*** julian1 has quit IRC | 19:18 | |
*** kencjohnston has quit IRC | 19:18 | |
*** _jungh4ns has quit IRC | 19:18 | |
*** jroll has quit IRC | 19:18 | |
*** tonyb has joined #openstack-barbican | 19:21 | |
*** jmckind has joined #openstack-barbican | 19:23 | |
*** reaperhulk has joined #openstack-barbican | 19:23 | |
*** nkinder has joined #openstack-barbican | 19:23 | |
*** jamespage has joined #openstack-barbican | 19:23 | |
*** Daviey_ has joined #openstack-barbican | 19:23 | |
*** dave-mccowan has joined #openstack-barbican | 19:23 | |
*** crc32|znc has joined #openstack-barbican | 19:23 | |
*** chlong_ has joined #openstack-barbican | 19:23 | |
*** pcaruana has joined #openstack-barbican | 19:23 | |
*** phschwartz has joined #openstack-barbican | 19:23 | |
*** _sigmavirus24 has joined #openstack-barbican | 19:23 | |
*** kragniz has joined #openstack-barbican | 19:23 | |
*** Kiall_ has joined #openstack-barbican | 19:23 | |
*** Kevin_Zheng has joined #openstack-barbican | 19:23 | |
*** stupidnic has joined #openstack-barbican | 19:23 | |
*** david-lyle has joined #openstack-barbican | 19:23 | |
*** haplo37_ has joined #openstack-barbican | 19:23 | |
*** edtubill has joined #openstack-barbican | 19:23 | |
*** zigo has joined #openstack-barbican | 19:23 | |
*** dimtruck has joined #openstack-barbican | 19:23 | |
*** spotz_zzz has joined #openstack-barbican | 19:23 | |
*** stevemar_ has joined #openstack-barbican | 19:23 | |
*** vipul has joined #openstack-barbican | 19:23 | |
*** eglute has joined #openstack-barbican | 19:23 | |
*** jvrbanac has joined #openstack-barbican | 19:23 | |
*** rm_work has joined #openstack-barbican | 19:23 | |
*** alee has joined #openstack-barbican | 19:23 | |
*** dgonzalez has joined #openstack-barbican | 19:23 | |
*** panatl has joined #openstack-barbican | 19:23 | |
*** rbradfor has joined #openstack-barbican | 19:23 | |
*** madorn has joined #openstack-barbican | 19:23 | |
*** beisner has joined #openstack-barbican | 19:23 | |
*** jamielennox has joined #openstack-barbican | 19:23 | |
*** Guest66666 has joined #openstack-barbican | 19:23 | |
*** mathiasb has joined #openstack-barbican | 19:23 | |
*** jorgem has joined #openstack-barbican | 19:23 | |
*** hyakuhei has joined #openstack-barbican | 19:23 | |
*** openstackgerrit has joined #openstack-barbican | 19:23 | |
*** mmotiani has joined #openstack-barbican | 19:23 | |
*** arunkant has joined #openstack-barbican | 19:23 | |
*** julian1 has joined #openstack-barbican | 19:23 | |
*** kencjohnston has joined #openstack-barbican | 19:23 | |
*** _jungh4ns has joined #openstack-barbican | 19:23 | |
*** jroll has joined #openstack-barbican | 19:23 | |
*** tdink has joined #openstack-barbican | 19:23 | |
*** alpha_ori has joined #openstack-barbican | 19:23 | |
*** filler has joined #openstack-barbican | 19:23 | |
*** jgrassler has joined #openstack-barbican | 19:23 | |
*** tinwood has joined #openstack-barbican | 19:24 | |
*** diazjf has joined #openstack-barbican | 19:24 | |
alee | arunkant, responded some more | 19:28 |
*** _jungh4ns has quit IRC | 19:35 | |
*** briancurtin has joined #openstack-barbican | 19:38 | |
*** diazjf has quit IRC | 19:40 | |
*** woodster_ has joined #openstack-barbican | 19:48 | |
*** DuncanT has joined #openstack-barbican | 20:00 | |
*** jraim has joined #openstack-barbican | 20:01 | |
*** cargonza has joined #openstack-barbican | 20:03 | |
*** pcaruana has quit IRC | 20:11 | |
*** diazjf has joined #openstack-barbican | 20:12 | |
*** diazjf has quit IRC | 20:30 | |
arunkant | alee: ping | 20:32 |
*** diazjf has joined #openstack-barbican | 20:42 | |
alee | arunkant, pong | 20:45 |
arunkant | alee: I thought it will be better to clarify comment Line #192 in https://review.openstack.org/#/c/357544/8/barbican/plugin/util/multiple_backends.py | 20:46 |
arunkant | alee: trying to understand what is passive behavior? | 20:47 |
arunkant | alee: and comment 'we need an active/passive field on the secret store.' | 20:48 |
alee | arunkant, so sometime awhile back we considered adding active /passive secret stores | 20:49 |
alee | the idea was that one might want to migrate secrets from one secret store to another | 20:49 |
alee | arunkant, lets say for instance you were using software plugin and then wanted to upgrade to a kmip or dogtag plugin | 20:50 |
arunkant | alee: just to be clear..do you mean new secrets are created in different secret store (or backend) ..existing secrets still remain there | 20:50 |
alee | correct - although at some point (out of band) someone could run a migration script that would retrieve a secret from the old store and re-store it in the new store | 20:51 |
alee | arunkant, and then -- and only then - would the secret_store be retired | 20:52 |
alee | arunkant, in any case, the question arises .. | 20:53 |
alee | arunkant, we are providing an interface to allow project admins to select a backend for their secrets | 20:53 |
alee | but what if I do not want the project admin to select a particular plugin? | 20:54 |
arunkant | alee: In that case, admin can remove preferred secret store setting .. | 20:55 |
alee | arunkant, yes but that does not prevent some future admin from adding it | 20:55 |
alee | that is "project admin" | 20:56 |
alee | arunkant, the basic problem is that -- right now based on your patches , configured == enabled | 20:56 |
arunkant | alee: yes, it means it can be used if needed. | 20:57 |
alee | arunkant, maybe this is a problem no one really cares about -- redrobot , woodster_ ? | 20:58 |
alee | arunkant, this might also be something that we could resolve in a separate patch. | 20:59 |
arunkant | alee: if someone does not want secret store to be used at all...then do not add in configuration. | 20:59 |
alee | arunkant, yes -- but what if there are secrets stored there? | 20:59 |
alee | arunkant, I still need to be able to get to them | 21:00 |
alee | arunkant, right now, there is no way for me to say -- I want to keep store X around to retrieve whatecver secrets are there, but I also do not want to store any new secrets there. | 21:02 |
arunkant | alee: okay. There is a active flag (or status) on a secret store..may be it can be used to restrict that to list only active secret stores. | 21:02 |
alee | arunkant, ok good -- we dont need another field then | 21:02 |
arunkant | alee: I think if this is needed, it can be enhanced via that mechanism .. | 21:02 |
alee | agreed -- no need to do in this patch set | 21:03 |
alee | should be easy to add | 21:03 |
arunkant | alee: okay. We can certainly revisit this aspect in next release as there is solution available. | 21:04 |
alee | yup we can chat about at summit. | 21:04 |
alee | arunkant, the question still arises though .. | 21:05 |
arunkant | alee: yes, its change in secret stores list API ..just to include active based on 'status' or flag | 21:05 |
*** randallburt has quit IRC | 21:05 | |
alee | arunkant, on startup , should we remove secret stores if there are secrets still stored there? | 21:05 |
alee | arunkant, if we do - then we end up starting up with many secrets potentially inaccessible | 21:06 |
arunkant | alee: Currently if secrets are used, then to make it work, related configuration needs to be there | 21:06 |
alee | with nary a warning | 21:06 |
alee | sure - but if someone misconfigures , we start up and secrets are broken and we are none the wiser | 21:07 |
alee | arunkant, I think we should check .. and we should error out. we can also provide an override flag if someone does not care about whatever secrets are there | 21:09 |
alee | arunkant, after all -- why check project preferred plugins and not secrets? | 21:09 |
arunkant | alee: Did not change that area as it is existing behavior. preferred plugin is something which was added new that's why added check. | 21:11 |
alee | arunkant, understood, but we're checking to avoid misconfiguration .. | 21:12 |
alee | arunkant, I'll defer to what woodster_ and redrobot think about this .. | 21:13 |
openstackgerrit | Clenimar Filemon proposed openstack/python-barbicanclient: Use keystoneauth https://review.openstack.org/319446 | 21:13 |
alee | arunkant, back in a little bit/ going for run | 21:14 |
arunkant | alee: question for that..if we want to have that behavior (check before removal that a secret store is used in existing secret) .. and then want to have flag..what's the default for that | 21:14 |
alee | arunkant, default is to fail and error out on startup | 21:15 |
arunkant | alee: it will be different behavior when multiple backend is enabled ..is that okay? | 21:15 |
arunkant | alee: currently barbican will start without any error. Error will only come when someone tries to use that secret | 21:16 |
alee | arunkant, meaning that it will just crash and burn if you take away/replace the one plugin you have -- yeah, I can live with that | 21:17 |
arunkant | alee: which may or may not be significant in that case. | 21:17 |
arunkant | alee: okay..I will add that flag with default to raise error if any secret is using it.. | 21:18 |
alee | arunkant, cool , | 21:18 |
alee | arunkant, of course the admin wont know -- it will the poor user who somehow cannot get his secret! | 21:18 |
arunkant | alee: other change (active/ passive secret store) can be done later in a separate patch | 21:19 |
alee | arunkant, agreed | 21:19 |
*** alee is now known as alee_run | 21:20 | |
arunkant | alee: one last thing..do you want to have 2 separate method for get_applicable_plugins logic | 21:20 |
alee_run | arunkant, yeah - I think it makes things clearer | 21:20 |
arunkant | alee: okay..will do that..thanks | 21:20 |
alee_run | arunkant, its a small amount of repeat - but it will make more sense in 6 months | 21:21 |
arunkant | ok | 21:21 |
*** dave-mccowan has quit IRC | 21:26 | |
*** gyee has joined #openstack-barbican | 21:28 | |
*** edtubill has quit IRC | 21:33 | |
*** tdink has quit IRC | 22:02 | |
*** diazjf has quit IRC | 22:11 | |
*** jmckind has quit IRC | 22:13 | |
*** dave-mccowan has joined #openstack-barbican | 22:15 | |
*** dave-mccowan has quit IRC | 22:16 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!