Monday, 2017-04-03

*** jamielennox|away is now known as jamielennox01:06
*** diazjf has joined #openstack-barbican01:07
*** Guest54099 has joined #openstack-barbican01:48
*** namnh has joined #openstack-barbican01:48
*** Guest54099 has quit IRC01:56
*** noslzzp has quit IRC02:08
openstackgerritDave McCowan proposed openstack/barbican master: (draft, do not merge) Set Devstack Variable Properly  https://review.openstack.org/45084402:10
*** catintheroof has joined #openstack-barbican02:55
*** dave-mccowan has joined #openstack-barbican02:55
*** dave-mcc_ has quit IRC02:57
*** dave-mccowan has quit IRC03:05
*** namnh has quit IRC03:06
*** catintheroof has quit IRC04:10
*** diazjf has quit IRC04:20
*** dimtruck is now known as zz_dimtruck05:24
*** zz_dimtruck is now known as dimtruck05:24
*** dimtruck is now known as zz_dimtruck05:33
*** mkoderer has joined #openstack-barbican06:15
*** andreas_s has joined #openstack-barbican06:50
*** pcaruana has joined #openstack-barbican06:57
*** jaosorior has joined #openstack-barbican06:57
*** zz_dimtruck is now known as dimtruck07:01
*** dimtruck is now known as zz_dimtruck07:11
*** zz_dimtruck is now known as dimtruck08:02
*** openstackgerrit has quit IRC08:03
*** dimtruck is now known as zz_dimtruck08:12
*** mjblack has quit IRC08:33
*** mjblack has joined #openstack-barbican08:38
*** zz_dimtruck is now known as dimtruck09:02
*** dimtruck is now known as zz_dimtruck09:12
*** zz_dimtruck is now known as dimtruck10:03
*** dimtruck is now known as zz_dimtruck10:13
*** openstackgerrit has joined #openstack-barbican10:19
openstackgerritNam Nguyen Hoai proposed openstack/barbican master: Fix bug in barbican-plugin-grenade  https://review.openstack.org/45267910:19
openstackgerritNam Nguyen Hoai proposed openstack/barbican master: Fix bug in barbican-plugin-grenade  https://review.openstack.org/45267910:25
*** zz_dimtruck is now known as dimtruck11:04
*** dimtruck is now known as zz_dimtruck11:14
*** diazjf has joined #openstack-barbican11:47
*** diazjf has quit IRC11:49
*** jgr is now known as jgrassler11:49
*** zz_dimtruck is now known as dimtruck12:05
*** dimtruck is now known as zz_dimtruck12:15
*** jaosorior is now known as jaosorior_brb12:36
*** mjblack has quit IRC12:52
*** mjblack has joined #openstack-barbican12:55
*** zz_dimtruck is now known as dimtruck13:06
*** dimtruck is now known as zz_dimtruck13:15
*** catintheroof has joined #openstack-barbican13:31
*** jaosorior_brb is now known as jaosorior13:33
*** noslzzp has joined #openstack-barbican13:48
*** zz_dimtruck is now known as dimtruck14:06
*** peter-hamilton has joined #openstack-barbican14:10
*** jmckind has joined #openstack-barbican14:16
*** gcb has joined #openstack-barbican14:18
*** jmckind has quit IRC14:18
*** dimtruck is now known as zz_dimtruck14:19
*** rpi has joined #openstack-barbican14:20
*** zz_dimtruck is now known as dimtruck14:33
*** jmckind has joined #openstack-barbican14:43
*** chlong has joined #openstack-barbican14:45
*** diazjf has joined #openstack-barbican14:52
*** diazjf has quit IRC15:03
*** diazjf has joined #openstack-barbican15:17
*** agrebennikov has joined #openstack-barbican15:17
*** dave-mccowan has joined #openstack-barbican15:21
*** agrebennikov has quit IRC15:27
openstackgerritDave McCowan proposed openstack/barbican master: (draft, do not merge) Set Devstack Variable Properly  https://review.openstack.org/45084415:29
gcbhi barbican core reviewers , I'm gcb , PTL of Oslo, as we discussed in the dev ML,  castellan-core group will include oslo and barbican core reviewers, I will add both of team members in group castellan-core15:31
*** arunkant has quit IRC15:40
*** pcaruana has quit IRC15:53
*** andreas_s has quit IRC15:56
*** gcb has quit IRC16:03
openstackgerritKaitlin Farr proposed openstack/barbican master: Add date filter functional tests  https://review.openstack.org/43624416:15
*** namnh has joined #openstack-barbican16:19
namnhdave-mccowan: Hello Mr.Mccowan, I've uploaded a patch to fix a bug in barbican-plugin-grenade, I already tested it on my local. Could you please review it for me. https://review.openstack.org/#/c/452679/2.16:40
dave-mccowanHi Nam.  Thanks!  I'll take a look.16:40
namnhdave-mccowan: thanks, one more thing, today I won't attend our weekly meeting, so I would like to update the status of my task to you16:43
namnhdave-mccowan: 1. I will find the problem and fix bug in the gate job for grenade.16:44
namnhdave-mccowan: 2. After that, I'll update a document for operators, I am preparing this patch [2]. it would be great if the patch [2] get your comment, I will sumarry and update new patch set16:45
namnh[2] https://review.openstack.org/#/c/449022/16:46
namnhdave-mccowan: finally, I will raise a tag "supports-upgrade" for Barbican :)16:46
dave-mccowannamnh awesome!  thanks!16:48
namnhdave-mccowan: Is that all jobs to get "support-upgrade" tag for Barbican?16:50
dave-mccowannamnh that is my recollection.  i double check the list later today and let you know if there is anything else i see missing.16:51
namnhdave-mccowan: I see, thanks for your support.16:52
namnhdave-mccowan: I have another information. Currenlty, there is a project (Tacker) is trying to apply barbican.16:55
dave-mccowannamnh i saw a note last week on the email list.  do you know the people working on it?  do they need help?16:57
namnhYes, I know: https://review.openstack.org/#/c/445543/16:57
namnhI also answered some questions from the author of the patch set16:58
namnhdave-mccowan: Yes, I know: https://review.openstack.org/#/c/445543/16:59
namnhdave-mccowan: I also answered some questions from the author of the patch set16:59
dave-mccowannamnh thanks for the pointer.  i will review that patch and also bring it up at the meeting today.16:59
*** diazjf has quit IRC17:00
*** kfarr has joined #openstack-barbican17:02
*** chlong has quit IRC17:05
namnhdave-mccowan: you're welcome. have a nice day. :)17:13
dave-mccowannamnh thanks.   have a nice night.  I'll try to catch you tomorrow. :-)17:13
*** namnh has left #openstack-barbican17:14
*** chlong has joined #openstack-barbican17:21
*** jaosorior is now known as jaosorior_away17:29
*** jamielennox is now known as jamielennox|away17:50
*** peter-hamilton has quit IRC18:01
*** jmckind has quit IRC18:13
*** diazjf has joined #openstack-barbican18:28
*** sapcc-bot1 has joined #openstack-barbican18:40
*** sapcc-bot has quit IRC18:40
dave-mccowanHappy Monday Barbicaneers!  Weekly IRC meeting starts in 1 hour, 15 minutes.18:43
*** dimtruck is now known as zz_dimtruck18:46
*** zz_dimtruck is now known as dimtruck18:53
*** diazjf has quit IRC18:56
*** diazjf has joined #openstack-barbican19:01
*** diazjf has quit IRC19:02
*** agrebennikov has joined #openstack-barbican19:06
agrebennikovhey Barbican folks, I have a question regarding the functionality of the secrets containers please.19:07
agrebennikovIf I got my secret created19:07
agrebennikovis there a way to update it down the road with another cert?19:08
agrebennikovthe usecase is pretty common - using barbican with neutron lbaas19:08
agrebennikovwhen the load balance from the lbaas backend gets the cert from barbican there is no way to update the neutron load balancer with the new secret seems so19:09
agrebennikovso the only way to update the cert within the balancer is to update the barbican secret and trigger the balancer to re-request the cert (while adding the pool member for example)19:10
agrebennikovany help is greatly appreciated19:10
*** diazjf has joined #openstack-barbican19:17
*** chlong has quit IRC19:37
*** dimtruck is now known as zz_dimtruck19:45
*** chlong has joined #openstack-barbican19:51
dave-mccowanhi agrebennikov19:53
dave-mccowanagrebennikov let me confirm your question...19:54
agrebennikovdave-mccowan, sure19:54
dave-mccowanyou have a container with secrets that comprise a certificate.  you would like to update the container with new secrets to comprise an update certificate?19:55
agrebennikovcorrect19:55
*** diazjf has quit IRC19:55
agrebennikovso that I don't have to re-create the balancer entirely19:55
agrebennikovright now from my understanding there is a update-secret function19:56
agrebennikovbut it is just for uploading the stuff into the container once19:56
dave-mccowanagrebennikov let me check.  i know we added the capability to update some things, but not all things.  i want to double check that your use case is supported.19:58
agrebennikovdave-mccowan, are you referring to some very recent changes?19:58
dave-mccowanno, at least a couple cycles ago19:58
agrebennikovbecause right now we are unfortunately stuck with liberty and have some limited ability to port things form mitaka back to it19:59
agrebennikovso we ported the client support for update19:59
agrebennikovand turned out that "update" form the server's perspective is completely not what we wanted to get19:59
agrebennikov:)19:59
dave-mccowani have an IRC meeting to go to right now.  i'll get back to you in a little bit.20:00
agrebennikovall right, really appreciate it20:01
dave-mccowanagrebennikov i know we can't update a secret directly.  maybe can change the container to point to new secrets.  i just need to check of that is specifically allowed for certificate containers.20:01
agrebennikovabsolutely20:01
dave-mccowanalee kfarr ping IRC meeting20:03
*** jamielennox|away is now known as jamielennox20:05
johnsomWas there an LBaaS/Octavia question?20:23
agrebennikovjohnsom, well, kind of20:23
agrebennikovnot necessarily octavia though20:24
dave-mccowanagrebennikov i confirmed that barbican only support container update for containers of type "generic".  you can not change the contents of a certificate container.20:24
agrebennikovdave-mccowan, that's really bad then :(20:24
agrebennikovis there any reason for not implementing that?20:24
johnsomWhen you get new/renewed certificates you create a new container then do a listener update call to LBaaS/Octavia with the new IDs.  It will update the load balancer20:24
*** zz_dimtruck is now known as dimtruck20:25
dave-mccowanagrebennikov i think the idea is to put the consumer in charge of when to update20:25
johnsomagrebennikov It's by design and a very good thing.20:25
agrebennikovjohnsom, well, it is basically has to be handled by the neutron part then?20:25
johnsomOtherwise there would need to be notifications of some sort send out to the services using the certs that it changed, this way the user lets us know when they are ready for the certs to change.20:26
agrebennikovbecause in my particular case I have contrail, and it has its own kind of implementation of everything20:26
agrebennikovjohnsom, I actually thought about it as well20:26
agrebennikovok, let me then go check the contrain-neutron part20:27
agrebennikovthanks a lot folks!20:27
johnsomNo problem20:27
*** diazjf has joined #openstack-barbican20:31
*** diazjf has quit IRC20:32
agrebennikovjohnsom, the listener-update (at least from the CLI perspective) allows to only update the description, pool and the limit20:34
agrebennikovjohnsom, https://docs.openstack.org/cli-reference/neutron.html20:34
agrebennikovjohnsom, or do I need to go with raw json?20:34
johnsomYeah, it looks like the CLI didn't get the memo...20:35
agrebennikovcan you point me to the code please?20:35
johnsomhttps://github.com/openstack/neutron-lbaas/blob/master/neutron_lbaas/extensions/loadbalancerv2.py#L22120:35
agrebennikovoh, there you go20:36
agrebennikovgreat!20:36
johnsomAll of the cert IDs are update-able20:36
johnsomagrebennikov That will be fixed with the OpenStack client implementation underway now...20:36
agrebennikovbut I mean I can just use neutron cli anyway20:37
johnsomI think the horizon dashboard also allows you to update them20:37
agrebennikov(maybe requires a little hack though)20:37
agrebennikovnot in liberty for sure :)20:37
johnsomOh! liberty, umm, yeah, no.20:37
agrebennikovso cli is fine with the customer for now20:38
agrebennikovbut probably current client will not allow to issue that command, I'll have to unlock it20:39
*** dimtruck is now known as zz_dimtruck20:48
*** zz_dimtruck is now known as dimtruck20:48
*** diazjf has joined #openstack-barbican21:14
*** diazjf has quit IRC21:33
*** kfarr has quit IRC21:38
*** alee_ has joined #openstack-barbican21:40
*** sapcc-bot1 has quit IRC22:31
*** sapcc-bot has joined #openstack-barbican22:31
*** chlong has quit IRC22:38
*** catintheroof has quit IRC22:44

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!