Wednesday, 2019-11-20

*** awalende has joined #openstack-barbican01:57
*** awalende has quit IRC02:02
*** pcaruana has joined #openstack-barbican05:25
*** jmlowe has quit IRC05:46
*** awalende has joined #openstack-barbican05:58
*** awalende has quit IRC06:02
*** dpawlik has joined #openstack-barbican07:14
*** tosky has joined #openstack-barbican07:35
*** awalende has joined #openstack-barbican07:47
*** dpawlik has quit IRC07:56
*** njohnston_ has joined #openstack-barbican08:06
*** njohnston has quit IRC08:07
*** ade_lee has quit IRC08:12
*** ade_lee has joined #openstack-barbican08:12
*** dpawlik has joined #openstack-barbican08:21
*** ivve has joined #openstack-barbican08:36
*** tosky has quit IRC09:13
*** tosky has joined #openstack-barbican09:14
*** awalende has quit IRC09:43
*** dpawlik has quit IRC09:45
*** awalende has joined #openstack-barbican09:48
*** awalende has quit IRC09:52
*** awalende has joined #openstack-barbican09:52
*** jaosorior has joined #openstack-barbican09:57
*** dpawlik has joined #openstack-barbican10:20
*** dpawlik has quit IRC10:24
*** dpawlik has joined #openstack-barbican10:51
*** dpawlik has quit IRC11:12
*** raildo has joined #openstack-barbican11:53
*** dave-mccowan has quit IRC12:17
*** pcaruana has quit IRC12:24
*** awalende has quit IRC12:26
*** pcaruana has joined #openstack-barbican12:50
*** awalende has joined #openstack-barbican12:52
*** awalende has quit IRC12:56
*** dave-mccowan has joined #openstack-barbican13:21
*** dpawlik has joined #openstack-barbican13:39
*** jaosorior has quit IRC14:18
*** mmethot has quit IRC14:34
*** mmethot has joined #openstack-barbican14:35
*** openstackgerrit has joined #openstack-barbican14:53
openstackgerritSven Wegener proposed openstack/barbican master: consumers: Expose container attributes for policy checking  https://review.opendev.org/67460514:53
*** dpawlik has quit IRC15:08
*** efried has joined #openstack-barbican15:17
efriedo/ barbican!15:17
redrobotefried, 👋15:51
efriedDunno if you've been following, but that py3 patch has become interesting.15:51
efriedthough I actually showed up to ask a rather more esoteric question...15:51
efriedis there a limit to the size of the, ahem, "passphrase" I can store in barbican?15:51
redrobotefried, yes, there's a configurable size limit for a secret15:52
efriedor is it theoretically possible to (ab)use barbican as a pseudo- (but more secure) swift?15:52
redrobotwe purposely did not want to be "encrypted swift"15:52
redrobotso the limit is pretty small15:52
redrobot10K by default IIRC15:52
efriedOkay. So even if I can get under 10K (I can) it would be a non-recommended use case.15:53
efriedI reckon that answers my question :)15:53
redrobotefried, https://opendev.org/openstack/barbican/src/branch/master/barbican/common/config.py#L50-L5215:53
redrobotyou can change that to increase the limit15:53
redrobotbut yea, we don't recommend going much bigger15:54
redrobotdefinitely not into the MBs or GBs15:54
efriedwell, it's more of a philosophical question, it sounds like.15:54
efriedI'm pretty sure the thing I want to store would be well under 10K anyway15:54
efriedand really I guess it's more of a question for the key manager (castellan) shim than anything else15:55
efriedbecause my actual use case is going to involve a home-grown backend.15:55
redrobotYeah, Castellan basically just shovels stuff back and forth15:55
redrobotif your key service backend allows big files, then I don't think Castellan would care15:56
efriedexcept for the "did not want to be encrypted swift" philosophy. Does that statement apply to castellan as well, do you reckon, or barbican specifically?15:57
redrobotefried, barbican specifically ... but I think it's true of key managers in general15:57
redrobotHardware HSMs have very limited storage for example15:57
efriedI mean, it makes sense. It's a *key* manager, not a "random data blob" manager.15:58
*** jmlowe has joined #openstack-barbican16:00
*** ivve has quit IRC16:09
*** jmlowe has quit IRC16:10
efriedgmann: Is there anything I can do to help with https://review.opendev.org/#/c/695052/ (barbican py3 gating)?16:15
efriedkinda sounds like you've got the same issue elsewhere too?16:15
gmannefried: yeah it was strange behavior which i could not figured out last night. AJaeger pointed out about branch variant playing the magic role here so we need this to fix barbican grenade https://review.opendev.org/#/c/689458/16:16
*** dpawlik has joined #openstack-barbican16:18
efriedgmann: forgive my ignorance, but grenade uses the prior release's stable branch for the 'old' side?16:18
gmannefried: that is devstack of old branch but job definition or say inventory has t be from master (or the branch where gate is running)16:19
gmannso for master gate grenade job should 1. use the job definition of master 2.  install the stable/train devstack on node 3. perform upgrade on that node by stop service and update the source code (no new devstack installation)16:20
gmannif 1st happen then it takes the code changes of your patch which makes greande to do py3-> py316:21
gmannmeans old node devstack installation will be on py3 instead of py216:21
gmanndave-mccowan: we need to get these backport in https://review.opendev.org/#/q/I24a46d0d7476203feccb1250d4ce3ad94b2e0ecd16:27
*** dpawlik has quit IRC16:29
efriedgmann: sorry, still confused. Does the fact that https://review.opendev.org/#/c/681972/ (master) has merged mean that we should now be able to recheck https://review.opendev.org/#/c/695052/ (gate on py3)? Or do we have to wait for the train cherry-pick to merge?16:35
*** dpawlik has joined #openstack-barbican16:35
*** jaosorior has joined #openstack-barbican16:40
gmannefried: need to wait for cherry-pick of train and might be all stable branch. what happened is: zuul gets the job definition (same name) from master and stable/* branch which were different with branch variant. branch variant on stable/train satisfied the criteria  to run on master gate so does zuul picked that job definition instead of master+your patch change.16:40
*** dpawlik has quit IRC16:41
*** dpawlik has joined #openstack-barbican17:12
*** dpawlik has quit IRC17:21
*** dpawlik has joined #openstack-barbican17:35
openstackgerritMerged openstack/barbican stable/train: Don't use branch matching  https://review.opendev.org/68945817:50
*** jaosorior has quit IRC17:50
*** dpawlik has quit IRC17:51
*** jaosorior has joined #openstack-barbican17:57
*** jmlowe has joined #openstack-barbican18:17
*** jaosorior has quit IRC18:22
*** tosky has quit IRC18:55
dave-mccowanredrobot  ^^19:27
redrobotdave-mccowan, 🎉🎉🎉19:29
*** awalende has joined #openstack-barbican19:31
*** awalende_ has joined #openstack-barbican19:36
*** awalende has quit IRC19:39
*** awalende_ has quit IRC19:41
*** awalende has joined #openstack-barbican19:41
*** awalende_ has joined #openstack-barbican19:51
*** awalende has quit IRC19:54
*** awalende has joined #openstack-barbican20:05
*** awalende_ has quit IRC20:06
*** awalende_ has joined #openstack-barbican20:06
*** awalende has quit IRC20:10
*** awalende has joined #openstack-barbican20:17
*** awalende has quit IRC20:19
*** awalende_ has quit IRC20:20
*** jmlowe has quit IRC20:43
efriedredrobot et al: https://review.opendev.org/#/c/695052/ is green now. Do you want me to change the commit message at all?20:51
redrobotefried, lgtm20:56
efriedcool20:56
*** awalende has joined #openstack-barbican21:14
*** awalende has quit IRC21:19
*** raildo has quit IRC21:20
*** tosky has joined #openstack-barbican21:41
*** pcaruana has quit IRC21:42
*** awalende has joined #openstack-barbican22:11
*** awalende has quit IRC22:15
*** dave-mccowan has quit IRC22:29
gmannseems like barbican stable/stein is brokenon fedora_latest job - https://review.opendev.org/#/q/status:open+project:openstack/barbican+branch:stable/stein23:38
gmannanyone know the reason or fix ?23:38
gmannit seems broken since 8 months - https://review.opendev.org/#/c/650415/23:39
gmannredrobot: seems like fedora_latest was made non voting in this but not in stable branches - https://review.opendev.org/#/c/662543/1623:55
gmanni am not sure if we can backport the whole thing of 662543. I will make the direct patch to stable/stein to make the job n-v and backport from there23:58

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!