| *** dimtruck is now known as zz_dimtruck | 00:00 | |
| openstackgerrit | zhangyanxian proposed openstack/barbican: typo fix https://review.openstack.org/361929 | 00:34 |
|---|---|---|
| openstackgerrit | Jamie Lennox proposed openstack/barbican: Don't inspect oslo.context https://review.openstack.org/369092 | 00:46 |
| openstackgerrit | Jamie Lennox proposed openstack/barbican: Don't inspect oslo.context https://review.openstack.org/369092 | 00:49 |
| *** chlong_ has joined #openstack-barbican | 01:14 | |
| *** michauds has joined #openstack-barbican | 01:18 | |
| *** chlong_ has quit IRC | 01:49 | |
| *** chlong_ has joined #openstack-barbican | 02:06 | |
| *** zz_dimtruck is now known as dimtruck | 02:28 | |
| jamielennox | woodster_: and others here: https://review.openstack.org/#/c/369092/ fixes a problem the release team is having with positional and oslo.context libraries | 02:38 |
| jamielennox | it should be a really simple review when people have a moment and would unblock some release dependency problems | 02:39 |
| woodster_ | jamielennox: should merge in a bit, thanks gain | 02:47 |
| woodster_ | again | 02:47 |
| jamielennox | That was quick, thanks | 02:50 |
| woodster_ | jamielennox: it's fun to merge stuff in every once in a while :) | 02:52 |
| openstackgerrit | Merged openstack/barbican: Don't inspect oslo.context https://review.openstack.org/369092 | 03:18 |
| woodster_ | jamielennox: ^^^ | 03:20 |
| jamielennox | woodster_: woot! thanks | 03:20 |
| woodster_ | jamielennox: good luck unclogging things on your side! | 03:21 |
| openstackgerrit | Merged openstack/python-barbicanclient: Use international logging message https://review.openstack.org/356979 | 03:31 |
| openstackgerrit | Merged openstack/barbican: Fix test suite cleanup https://review.openstack.org/357277 | 03:53 |
| *** michauds has quit IRC | 03:56 | |
| *** jamielennox is now known as jamielennox|away | 04:05 | |
| *** jamielennox|away is now known as jamielennox | 04:08 | |
| *** dimtruck is now known as zz_dimtruck | 04:29 | |
| *** jamielennox is now known as jamielennox|away | 04:41 | |
| *** jamielennox|away is now known as jamielennox | 04:46 | |
| *** jaosorior has joined #openstack-barbican | 05:21 | |
| *** jamielennox is now known as jamielennox|away | 05:53 | |
| *** jamielennox|away is now known as jamielennox | 06:00 | |
| *** jamielennox is now known as jamielennox|away | 06:13 | |
| *** jamielennox|away is now known as jamielennox | 06:30 | |
| *** andreas_s has joined #openstack-barbican | 06:49 | |
| *** shohel has joined #openstack-barbican | 06:50 | |
| *** woodster_ has quit IRC | 06:59 | |
| *** pcaruana has joined #openstack-barbican | 07:02 | |
| *** mmotiani has quit IRC | 07:11 | |
| *** mmotiani has joined #openstack-barbican | 07:16 | |
| *** openstackgerrit has quit IRC | 07:48 | |
| *** openstackgerrit has joined #openstack-barbican | 07:49 | |
| *** tkelsey has joined #openstack-barbican | 08:17 | |
| *** zigo_ is now known as zigo | 08:34 | |
| *** jaosorior is now known as jaosorior_lunch | 09:05 | |
| *** jaosorior_lunch is now known as jaosorior | 10:04 | |
| *** shohel1 has joined #openstack-barbican | 10:04 | |
| *** shohel has quit IRC | 10:05 | |
| *** shohel has joined #openstack-barbican | 10:09 | |
| *** shohel1 has quit IRC | 10:11 | |
| *** shohel has quit IRC | 10:15 | |
| *** permalac has joined #openstack-barbican | 10:17 | |
| *** shohel has joined #openstack-barbican | 10:28 | |
| *** spotz_zzz is now known as spotz | 10:49 | |
| *** permalac has quit IRC | 10:51 | |
| *** shohel has quit IRC | 11:07 | |
| *** spotz is now known as spotz_zzz | 11:16 | |
| *** permalac has joined #openstack-barbican | 12:33 | |
| openstackgerrit | Merged openstack/barbican: Support upper-constratints.txt in tox environments https://review.openstack.org/358404 | 12:55 |
| *** jaosorior has quit IRC | 12:59 | |
| *** jaosorior has joined #openstack-barbican | 13:00 | |
| openstackgerrit | Clenimar Filemon proposed openstack/python-barbicanclient: Cast sets to lists in acl functional tests https://review.openstack.org/351844 | 13:01 |
| *** woodster_ has joined #openstack-barbican | 13:18 | |
| *** zz_dimtruck is now known as dimtruck | 13:42 | |
| arunkant | _woodster: Thanks for comments on multiple backends reviews. Can you please check my reply (especially part 2 review) as I have to make changes based on it. | 13:46 |
| arunkant | woodster_ ^^^ | 13:49 |
| arunkant | Did I have typo again..woodster_ ^^^ | 13:53 |
| woodster_ | arunkant: replied back just now | 14:17 |
| *** dimtruck is now known as zz_dimtruck | 14:24 | |
| *** jmckind has joined #openstack-barbican | 14:25 | |
| *** randallburt has joined #openstack-barbican | 14:31 | |
| *** randallburt1 has joined #openstack-barbican | 14:32 | |
| woodster_ | alee: redrobot In addition to Arun's CR's, this one would be good to land, and it's not too large: https://review.openstack.org/#/c/251168/ It has two +2's but I'd like for one of you two to 'bless'/merge it as it affects consumers API behavior somewhat | 14:32 |
| *** randallburt has quit IRC | 14:35 | |
| *** dave-mccowan has joined #openstack-barbican | 14:41 | |
| *** zz_dimtruck is now known as dimtruck | 14:41 | |
| *** jaosorior has quit IRC | 15:02 | |
| alee | arunkant, woodster_ https://review.openstack.org/#/c/354285 looks pretty good. I will +2 once woodster_ comments are addressed | 15:03 |
| alee | arunkant, woodster_ as far as I can tell, the only thing to do there was to add some asserts in the tests (asuming the unused member variable is removed in a subsequent patch) | 15:05 |
| *** edtubill has joined #openstack-barbican | 15:08 | |
| *** filler has quit IRC | 15:10 | |
| *** sigmavirus|awa has quit IRC | 15:11 | |
| *** _sigmavirus24 has joined #openstack-barbican | 15:12 | |
| *** filler has joined #openstack-barbican | 15:12 | |
| *** mixos has joined #openstack-barbican | 15:26 | |
| woodster_ | alee: agreed | 15:26 |
| alee | arunkant, woodster_ going through part 3 now .. | 15:28 |
| woodster_ | alee: This one is so close once you've caught up on the others :) https://review.openstack.org/#/c/251168/ | 15:28 |
| alee | ok | 15:28 |
| *** dave-mccowan has quit IRC | 15:32 | |
| *** dave-mccowan has joined #openstack-barbican | 15:37 | |
| *** diazjf has joined #openstack-barbican | 15:40 | |
| openstackgerrit | Arun Kant proposed openstack/barbican: Central logic to sync secret store data with conf data (Part 3) https://review.openstack.org/357544 | 15:50 |
| openstackgerrit | Arun Kant proposed openstack/barbican: Adding rest API for secret-stores resource (Part 4) https://review.openstack.org/358162 | 15:50 |
| openstackgerrit | Arun Kant proposed openstack/barbican: Changes for multiple backend conf and friendly plugin names (Part 2) https://review.openstack.org/354285 | 15:50 |
| arunkant | _wooster, alee: Addressed review comments till part 3 .. will work for part 5 review comment. | 15:50 |
| arunkant | woodster_ : ^^^ | 15:51 |
| *** jmckind_ has joined #openstack-barbican | 16:00 | |
| *** jmckind has quit IRC | 16:01 | |
| *** tdink has joined #openstack-barbican | 16:03 | |
| *** andreas_s has quit IRC | 16:07 | |
| *** randallburt1 has quit IRC | 16:17 | |
| *** permalac has quit IRC | 16:20 | |
| alee | arunkant, posted some comments on the previous version of part 3 | 16:25 |
| alee | arunkant, more likely than not, they will still apply | 16:25 |
| arunkant | alee, thanks..let me check | 16:26 |
| *** diazjf has quit IRC | 16:56 | |
| *** pcaruana has quit IRC | 16:59 | |
| *** randallburt has joined #openstack-barbican | 17:02 | |
| *** xek has quit IRC | 17:03 | |
| -openstackstatus- NOTICE: The Gerrit service on review.openstack.org is being restarted now to address current performance problems, but should return to a working state within a few minutes | 17:09 | |
| *** tkelsey has quit IRC | 17:22 | |
| *** xek has joined #openstack-barbican | 17:24 | |
| *** diazjf has joined #openstack-barbican | 17:47 | |
| openstackgerrit | Merged openstack/barbican: Remove consumer check for project_id to match containers https://review.openstack.org/251168 | 17:52 |
| *** dimtruck is now known as zz_dimtruck | 18:03 | |
| *** diazjf has quit IRC | 18:18 | |
| *** diazjf has joined #openstack-barbican | 18:22 | |
| *** david-lyle has quit IRC | 18:23 | |
| openstackgerrit | Merged openstack/python-barbicanclient: Cast sets to lists in acl functional tests https://review.openstack.org/351844 | 18:25 |
| *** david-lyle has joined #openstack-barbican | 18:26 | |
| arunkant | alee: can you check my reply on part 3 (https://review.openstack.org/#/c/357544/8) and please let me know your response. | 18:35 |
| *** pcaruana has joined #openstack-barbican | 18:36 | |
| *** Kevin_Zheng has quit IRC | 18:38 | |
| *** Kevin_Zheng has joined #openstack-barbican | 18:38 | |
| alee | arunkant, replied | 19:15 |
| alee | arunkant, woodster_ redrobot we never did implement active/passive secret stores eh? | 19:15 |
| *** david-lyle has quit IRC | 19:16 | |
| *** dave-mccowan has quit IRC | 19:16 | |
| *** Daviey_ has quit IRC | 19:16 | |
| *** nkinder has quit IRC | 19:16 | |
| *** jamespage has quit IRC | 19:16 | |
| *** reaperhulk has quit IRC | 19:16 | |
| *** cargonza has quit IRC | 19:17 | |
| *** rm_work has quit IRC | 19:17 | |
| *** alee has quit IRC | 19:17 | |
| *** dgonzalez has quit IRC | 19:17 | |
| *** panatl has quit IRC | 19:17 | |
| *** rbradfor has quit IRC | 19:17 | |
| *** madorn has quit IRC | 19:17 | |
| *** beisner has quit IRC | 19:17 | |
| *** jamielennox has quit IRC | 19:17 | |
| *** Guest66666 has quit IRC | 19:17 | |
| *** mathiasb has quit IRC | 19:17 | |
| *** jorgem has quit IRC | 19:17 | |
| *** edtubill has quit IRC | 19:17 | |
| *** zigo has quit IRC | 19:17 | |
| *** zz_dimtruck has quit IRC | 19:17 | |
| *** spotz_zzz has quit IRC | 19:17 | |
| *** filler has quit IRC | 19:17 | |
| *** jgrassler has quit IRC | 19:17 | |
| *** hyakuhei has quit IRC | 19:17 | |
| *** _sigmavirus24 has quit IRC | 19:17 | |
| *** jraim has quit IRC | 19:17 | |
| *** phschwartz has quit IRC | 19:17 | |
| *** tdink has quit IRC | 19:17 | |
| *** alpha_ori has quit IRC | 19:17 | |
| *** Kevin_Zheng has quit IRC | 19:17 | |
| *** woodster_ has quit IRC | 19:17 | |
| *** Kiall_ has quit IRC | 19:17 | |
| *** vipul has quit IRC | 19:17 | |
| *** eglute has quit IRC | 19:18 | |
| *** jvrbanac has quit IRC | 19:18 | |
| *** chlong_ has quit IRC | 19:18 | |
| *** crc32|znc has quit IRC | 19:18 | |
| *** jmckind_ has quit IRC | 19:18 | |
| *** stevemar has quit IRC | 19:18 | |
| *** stupidnic has quit IRC | 19:18 | |
| *** haplo37_ has quit IRC | 19:18 | |
| *** tonyb has quit IRC | 19:18 | |
| *** pcaruana has quit IRC | 19:18 | |
| *** diazjf has quit IRC | 19:18 | |
| *** mixos has quit IRC | 19:18 | |
| *** DuncanT has quit IRC | 19:18 | |
| *** briancurtin has quit IRC | 19:18 | |
| *** kragniz has quit IRC | 19:18 | |
| *** tinwood has quit IRC | 19:18 | |
| *** openstackgerrit has quit IRC | 19:18 | |
| *** mmotiani has quit IRC | 19:18 | |
| *** arunkant has quit IRC | 19:18 | |
| *** julian1 has quit IRC | 19:18 | |
| *** kencjohnston has quit IRC | 19:18 | |
| *** _jungh4ns has quit IRC | 19:18 | |
| *** jroll has quit IRC | 19:18 | |
| *** tonyb has joined #openstack-barbican | 19:21 | |
| *** jmckind has joined #openstack-barbican | 19:23 | |
| *** reaperhulk has joined #openstack-barbican | 19:23 | |
| *** nkinder has joined #openstack-barbican | 19:23 | |
| *** jamespage has joined #openstack-barbican | 19:23 | |
| *** Daviey_ has joined #openstack-barbican | 19:23 | |
| *** dave-mccowan has joined #openstack-barbican | 19:23 | |
| *** crc32|znc has joined #openstack-barbican | 19:23 | |
| *** chlong_ has joined #openstack-barbican | 19:23 | |
| *** pcaruana has joined #openstack-barbican | 19:23 | |
| *** phschwartz has joined #openstack-barbican | 19:23 | |
| *** _sigmavirus24 has joined #openstack-barbican | 19:23 | |
| *** kragniz has joined #openstack-barbican | 19:23 | |
| *** Kiall_ has joined #openstack-barbican | 19:23 | |
| *** Kevin_Zheng has joined #openstack-barbican | 19:23 | |
| *** stupidnic has joined #openstack-barbican | 19:23 | |
| *** david-lyle has joined #openstack-barbican | 19:23 | |
| *** haplo37_ has joined #openstack-barbican | 19:23 | |
| *** edtubill has joined #openstack-barbican | 19:23 | |
| *** zigo has joined #openstack-barbican | 19:23 | |
| *** dimtruck has joined #openstack-barbican | 19:23 | |
| *** spotz_zzz has joined #openstack-barbican | 19:23 | |
| *** stevemar_ has joined #openstack-barbican | 19:23 | |
| *** vipul has joined #openstack-barbican | 19:23 | |
| *** eglute has joined #openstack-barbican | 19:23 | |
| *** jvrbanac has joined #openstack-barbican | 19:23 | |
| *** rm_work has joined #openstack-barbican | 19:23 | |
| *** alee has joined #openstack-barbican | 19:23 | |
| *** dgonzalez has joined #openstack-barbican | 19:23 | |
| *** panatl has joined #openstack-barbican | 19:23 | |
| *** rbradfor has joined #openstack-barbican | 19:23 | |
| *** madorn has joined #openstack-barbican | 19:23 | |
| *** beisner has joined #openstack-barbican | 19:23 | |
| *** jamielennox has joined #openstack-barbican | 19:23 | |
| *** Guest66666 has joined #openstack-barbican | 19:23 | |
| *** mathiasb has joined #openstack-barbican | 19:23 | |
| *** jorgem has joined #openstack-barbican | 19:23 | |
| *** hyakuhei has joined #openstack-barbican | 19:23 | |
| *** openstackgerrit has joined #openstack-barbican | 19:23 | |
| *** mmotiani has joined #openstack-barbican | 19:23 | |
| *** arunkant has joined #openstack-barbican | 19:23 | |
| *** julian1 has joined #openstack-barbican | 19:23 | |
| *** kencjohnston has joined #openstack-barbican | 19:23 | |
| *** _jungh4ns has joined #openstack-barbican | 19:23 | |
| *** jroll has joined #openstack-barbican | 19:23 | |
| *** tdink has joined #openstack-barbican | 19:23 | |
| *** alpha_ori has joined #openstack-barbican | 19:23 | |
| *** filler has joined #openstack-barbican | 19:23 | |
| *** jgrassler has joined #openstack-barbican | 19:23 | |
| *** tinwood has joined #openstack-barbican | 19:24 | |
| *** diazjf has joined #openstack-barbican | 19:24 | |
| alee | arunkant, responded some more | 19:28 |
| *** _jungh4ns has quit IRC | 19:35 | |
| *** briancurtin has joined #openstack-barbican | 19:38 | |
| *** diazjf has quit IRC | 19:40 | |
| *** woodster_ has joined #openstack-barbican | 19:48 | |
| *** DuncanT has joined #openstack-barbican | 20:00 | |
| *** jraim has joined #openstack-barbican | 20:01 | |
| *** cargonza has joined #openstack-barbican | 20:03 | |
| *** pcaruana has quit IRC | 20:11 | |
| *** diazjf has joined #openstack-barbican | 20:12 | |
| *** diazjf has quit IRC | 20:30 | |
| arunkant | alee: ping | 20:32 |
| *** diazjf has joined #openstack-barbican | 20:42 | |
| alee | arunkant, pong | 20:45 |
| arunkant | alee: I thought it will be better to clarify comment Line #192 in https://review.openstack.org/#/c/357544/8/barbican/plugin/util/multiple_backends.py | 20:46 |
| arunkant | alee: trying to understand what is passive behavior? | 20:47 |
| arunkant | alee: and comment 'we need an active/passive field on the secret store.' | 20:48 |
| alee | arunkant, so sometime awhile back we considered adding active /passive secret stores | 20:49 |
| alee | the idea was that one might want to migrate secrets from one secret store to another | 20:49 |
| alee | arunkant, lets say for instance you were using software plugin and then wanted to upgrade to a kmip or dogtag plugin | 20:50 |
| arunkant | alee: just to be clear..do you mean new secrets are created in different secret store (or backend) ..existing secrets still remain there | 20:50 |
| alee | correct - although at some point (out of band) someone could run a migration script that would retrieve a secret from the old store and re-store it in the new store | 20:51 |
| alee | arunkant, and then -- and only then - would the secret_store be retired | 20:52 |
| alee | arunkant, in any case, the question arises .. | 20:53 |
| alee | arunkant, we are providing an interface to allow project admins to select a backend for their secrets | 20:53 |
| alee | but what if I do not want the project admin to select a particular plugin? | 20:54 |
| arunkant | alee: In that case, admin can remove preferred secret store setting .. | 20:55 |
| alee | arunkant, yes but that does not prevent some future admin from adding it | 20:55 |
| alee | that is "project admin" | 20:56 |
| alee | arunkant, the basic problem is that -- right now based on your patches , configured == enabled | 20:56 |
| arunkant | alee: yes, it means it can be used if needed. | 20:57 |
| alee | arunkant, maybe this is a problem no one really cares about -- redrobot , woodster_ ? | 20:58 |
| alee | arunkant, this might also be something that we could resolve in a separate patch. | 20:59 |
| arunkant | alee: if someone does not want secret store to be used at all...then do not add in configuration. | 20:59 |
| alee | arunkant, yes -- but what if there are secrets stored there? | 20:59 |
| alee | arunkant, I still need to be able to get to them | 21:00 |
| alee | arunkant, right now, there is no way for me to say -- I want to keep store X around to retrieve whatecver secrets are there, but I also do not want to store any new secrets there. | 21:02 |
| arunkant | alee: okay. There is a active flag (or status) on a secret store..may be it can be used to restrict that to list only active secret stores. | 21:02 |
| alee | arunkant, ok good -- we dont need another field then | 21:02 |
| arunkant | alee: I think if this is needed, it can be enhanced via that mechanism .. | 21:02 |
| alee | agreed -- no need to do in this patch set | 21:03 |
| alee | should be easy to add | 21:03 |
| arunkant | alee: okay. We can certainly revisit this aspect in next release as there is solution available. | 21:04 |
| alee | yup we can chat about at summit. | 21:04 |
| alee | arunkant, the question still arises though .. | 21:05 |
| arunkant | alee: yes, its change in secret stores list API ..just to include active based on 'status' or flag | 21:05 |
| *** randallburt has quit IRC | 21:05 | |
| alee | arunkant, on startup , should we remove secret stores if there are secrets still stored there? | 21:05 |
| alee | arunkant, if we do - then we end up starting up with many secrets potentially inaccessible | 21:06 |
| arunkant | alee: Currently if secrets are used, then to make it work, related configuration needs to be there | 21:06 |
| alee | with nary a warning | 21:06 |
| alee | sure - but if someone misconfigures , we start up and secrets are broken and we are none the wiser | 21:07 |
| alee | arunkant, I think we should check .. and we should error out. we can also provide an override flag if someone does not care about whatever secrets are there | 21:09 |
| alee | arunkant, after all -- why check project preferred plugins and not secrets? | 21:09 |
| arunkant | alee: Did not change that area as it is existing behavior. preferred plugin is something which was added new that's why added check. | 21:11 |
| alee | arunkant, understood, but we're checking to avoid misconfiguration .. | 21:12 |
| alee | arunkant, I'll defer to what woodster_ and redrobot think about this .. | 21:13 |
| openstackgerrit | Clenimar Filemon proposed openstack/python-barbicanclient: Use keystoneauth https://review.openstack.org/319446 | 21:13 |
| alee | arunkant, back in a little bit/ going for run | 21:14 |
| arunkant | alee: question for that..if we want to have that behavior (check before removal that a secret store is used in existing secret) .. and then want to have flag..what's the default for that | 21:14 |
| alee | arunkant, default is to fail and error out on startup | 21:15 |
| arunkant | alee: it will be different behavior when multiple backend is enabled ..is that okay? | 21:15 |
| arunkant | alee: currently barbican will start without any error. Error will only come when someone tries to use that secret | 21:16 |
| alee | arunkant, meaning that it will just crash and burn if you take away/replace the one plugin you have -- yeah, I can live with that | 21:17 |
| arunkant | alee: which may or may not be significant in that case. | 21:17 |
| arunkant | alee: okay..I will add that flag with default to raise error if any secret is using it.. | 21:18 |
| alee | arunkant, cool , | 21:18 |
| alee | arunkant, of course the admin wont know -- it will the poor user who somehow cannot get his secret! | 21:18 |
| arunkant | alee: other change (active/ passive secret store) can be done later in a separate patch | 21:19 |
| alee | arunkant, agreed | 21:19 |
| *** alee is now known as alee_run | 21:20 | |
| arunkant | alee: one last thing..do you want to have 2 separate method for get_applicable_plugins logic | 21:20 |
| alee_run | arunkant, yeah - I think it makes things clearer | 21:20 |
| arunkant | alee: okay..will do that..thanks | 21:20 |
| alee_run | arunkant, its a small amount of repeat - but it will make more sense in 6 months | 21:21 |
| arunkant | ok | 21:21 |
| *** dave-mccowan has quit IRC | 21:26 | |
| *** gyee has joined #openstack-barbican | 21:28 | |
| *** edtubill has quit IRC | 21:33 | |
| *** tdink has quit IRC | 22:02 | |
| *** diazjf has quit IRC | 22:11 | |
| *** jmckind has quit IRC | 22:13 | |
| *** dave-mccowan has joined #openstack-barbican | 22:15 | |
| *** dave-mccowan has quit IRC | 22:16 | |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!