*** xek__ has joined #openstack-barbican | 00:37 | |
*** xek_ has quit IRC | 00:39 | |
*** AB2019 has quit IRC | 00:56 | |
*** dave-mccowan has joined #openstack-barbican | 01:14 | |
*** dave-mccowan has quit IRC | 03:52 | |
*** dayou has quit IRC | 06:22 | |
*** dayou has joined #openstack-barbican | 06:23 | |
*** Luzi has joined #openstack-barbican | 07:01 | |
*** moguimar has joined #openstack-barbican | 07:07 | |
*** redrobot has quit IRC | 07:11 | |
*** openstackgerrit has quit IRC | 07:29 | |
*** velizarx has joined #openstack-barbican | 07:49 | |
*** moguimar has quit IRC | 07:52 | |
*** dayou has quit IRC | 08:10 | |
*** dayou has joined #openstack-barbican | 08:28 | |
rm_work | oh no, i'm off the courtesy-ping list! | 08:38 |
---|---|---|
rm_work | also, your meeting is too early T_T so early T_T | 08:38 |
Luzi | rm_work, i think redrobot wanted to create an etherpad for the agenda, maybe he can add the courtesy-oing list there, so people can add themself again? | 08:42 |
*** dayou has quit IRC | 08:43 | |
*** dayou has joined #openstack-barbican | 08:44 | |
*** moguimar has joined #openstack-barbican | 08:47 | |
*** salmankhan has joined #openstack-barbican | 09:00 | |
*** salmankhan has quit IRC | 09:24 | |
*** salmankhan has joined #openstack-barbican | 09:38 | |
*** moguimar has quit IRC | 09:59 | |
*** salmankhan has quit IRC | 10:14 | |
*** salmankhan has joined #openstack-barbican | 10:16 | |
*** salmankhan has quit IRC | 10:21 | |
*** salmankhan has joined #openstack-barbican | 10:21 | |
*** pbourke has quit IRC | 10:26 | |
*** pbourke has joined #openstack-barbican | 10:28 | |
*** velizarx has quit IRC | 11:48 | |
*** salmankhan1 has joined #openstack-barbican | 12:02 | |
*** velizarx has joined #openstack-barbican | 12:03 | |
*** salmankhan has quit IRC | 12:03 | |
*** salmankhan1 is now known as salmankhan | 12:03 | |
*** salmankhan has quit IRC | 12:11 | |
*** raildo has joined #openstack-barbican | 12:20 | |
*** dave-mccowan has joined #openstack-barbican | 12:41 | |
*** velizarx has quit IRC | 13:00 | |
*** moguimar has joined #openstack-barbican | 13:04 | |
*** redrobot has joined #openstack-barbican | 13:08 | |
*** velizarx has joined #openstack-barbican | 13:10 | |
*** salmankhan has joined #openstack-barbican | 13:14 | |
*** salmankhan has quit IRC | 13:35 | |
*** salmankhan has joined #openstack-barbican | 13:35 | |
*** salmankhan has quit IRC | 13:36 | |
*** salmankhan has joined #openstack-barbican | 13:37 | |
*** irclogbot_0 has quit IRC | 14:36 | |
*** mmethot has quit IRC | 14:43 | |
*** mmethot has joined #openstack-barbican | 14:46 | |
*** irclogbot_0 has joined #openstack-barbican | 14:51 | |
*** salmankhan has quit IRC | 15:42 | |
*** Luzi has quit IRC | 15:57 | |
*** velizarx has quit IRC | 16:35 | |
*** velizarx has joined #openstack-barbican | 16:47 | |
*** moguimar has quit IRC | 16:53 | |
*** moguimar has joined #openstack-barbican | 17:03 | |
*** moguimar has quit IRC | 17:03 | |
*** velizarx has quit IRC | 17:08 | |
*** raildo has quit IRC | 17:58 | |
*** raildo has joined #openstack-barbican | 17:58 | |
rm_work | it's fine, I just want to mess with redrobot :P | 18:09 |
redrobot | ohai rm_work ! | 18:09 |
rm_work | redrobot: your meetings are too early | 18:11 |
rm_work | T_T | 18:11 |
redrobot | rm_work, you West Coast again? | 18:19 |
rm_work | yeah | 18:19 |
rm_work | presently sunnyvale | 18:19 |
redrobot | rm_work, nice! ... yeah, maybe we can change the meeting time. As it is only Luzi and I show up regularly | 18:20 |
rm_work | lol | 18:20 |
rm_work | I mean that said, I probably don't have a whole lot to add ATM | 18:20 |
rm_work | octavia cleaned up its barbican story a lot | 18:20 |
rm_work | we just store a single pkcs12 file as one secret now <_< | 18:20 |
rm_work | and auto-create ACLs | 18:22 |
*** raildo_ has joined #openstack-barbican | 18:35 | |
*** raildo has quit IRC | 18:35 | |
*** AB2019_ has joined #openstack-barbican | 19:09 | |
*** AB2019 has joined #openstack-barbican | 19:14 | |
*** salmankhan has joined #openstack-barbican | 19:20 | |
*** salmankhan has quit IRC | 20:18 | |
*** AB2019_ has quit IRC | 20:22 | |
*** salmankhan has joined #openstack-barbican | 20:31 | |
*** jmlowe has quit IRC | 21:10 | |
*** jmlowe has joined #openstack-barbican | 21:11 | |
FrankZhang | rm_work: recently I'm doing some experiment on enabling TLS lb on Octavia with Barbican in openstack ansible setup. While barbican has strict policy that won't allow Octavia has access to the PKCS12 secret. Does this happen on your side? | 21:13 |
*** jmlowe has quit IRC | 21:13 | |
*** jmlowe has joined #openstack-barbican | 21:14 | |
rm_work | which release? | 21:16 |
rm_work | hopefully rocky? | 21:16 |
rm_work | FrankZhang: wait are you at RAX | 21:17 |
rm_work | if so, queens may have some issue? johnsom is looking at it <_< | 21:17 |
FrankZhang | yeah I'm, I was testing queens, rocky should be quite similar | 21:17 |
rm_work | i'm aware of your problem :P | 21:18 |
FrankZhang | rm_work: I'm working with johnsom | 21:18 |
rm_work | rocky has different patches | 21:18 |
rm_work | with regard to barbican ACL work, I *think* | 21:18 |
*** xek__ has quit IRC | 21:18 | |
rm_work | but yeah, i'd just wait for michael's research | 21:18 |
FrankZhang | rm_work: osa barbican has one flaw which public endpoint won't allow admin GET secret normally but have to give '--insecure' flag | 21:19 |
FrankZhang | I'm guessing the weird cert requirement causing other service has trouble communicating to barbican | 21:20 |
rm_work | yeah, so I fixed the barbican-client issue with using alternative endpoints a few months ago | 21:21 |
rm_work | it should be released now | 21:21 |
rm_work | so you should be able to use the internal/admin endpoint | 21:21 |
FrankZhang | rm_work: yeah, thanks for the patching, it got merged to queens weeks ago. The href of secret is still marked as public endpoint, though I don't think it matters. | 21:23 |
rm_work | right, the client will now respect the setting of the current config | 21:23 |
rm_work | replacing the endpoint in the stored secret | 21:23 |
rm_work | so you shouldn't have to deal with --insecure or the cert issue at all | 21:23 |
FrankZhang | Openstack Ansible stable queens didn't have your barbican client patch, so I was working on finding the way to get OSA barbican client up-to-date | 21:24 |
rm_work | you can ping xgerman for OSA issues, right? :P | 21:25 |
FrankZhang | cool, I believed he knew the issue already. Since folks in RAX all didn't have successful instance to implement TLS octavia lb with barbican, johnsom mentioned you have some experience. Like to hear any tip of conifg you did. | 21:29 |
johnsom | The --insecure issue is an OSA deployment issue. Somehow that barbican public endpoint is using the wrong cert. But that is an openstack-ansible channel question/bug IMO. | 21:32 |
johnsom | The other endpoints don't need the --insecure even though they are also HTTPS, so I think something just isn't getting setup right. | 21:33 |
johnsom | The RBAC issue with the 403's, that one is going to take some time to figure out. I threw every role at the account I could think of, but I still got 403, so just need to set it up local and dig. | 21:34 |
FrankZhang | johnsom: I can setup one queens vm without octavia and barbican. And you can do some experiment on it. | 21:36 |
*** salmankhan has quit IRC | 22:03 | |
*** AB2019_ has joined #openstack-barbican | 22:22 | |
*** AB2019 has quit IRC | 22:29 | |
*** AB2019_ is now known as AB2019 | 22:29 | |
*** raildo_ has quit IRC | 23:06 | |
*** ade_lee has quit IRC | 23:12 | |
*** ade_lee has joined #openstack-barbican | 23:13 | |
*** dave-mccowan has quit IRC | 23:19 | |
*** ade_lee has quit IRC | 23:20 | |
*** ade_lee_ has joined #openstack-barbican | 23:21 | |
*** ade_lee_ has quit IRC | 23:21 | |
*** ade_lee has joined #openstack-barbican | 23:21 | |
*** ade_lee has quit IRC | 23:45 | |
*** ade_lee has joined #openstack-barbican | 23:46 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!