*** catintheroof has quit IRC | 00:00 | |
*** catintheroof has joined #openstack-glance | 00:00 | |
*** catintheroof has quit IRC | 00:04 | |
*** markvoelker_ has quit IRC | 00:17 | |
*** markvoelker has joined #openstack-glance | 00:25 | |
*** markvoelker has quit IRC | 00:29 | |
*** markvoelker has joined #openstack-glance | 00:34 | |
*** markvoelker has quit IRC | 00:39 | |
*** markvoelker has joined #openstack-glance | 00:43 | |
*** markvoelker has quit IRC | 00:48 | |
*** AlexeyAbashkin has joined #openstack-glance | 00:48 | |
*** AlexeyAbashkin has quit IRC | 00:52 | |
*** markvoelker has joined #openstack-glance | 00:52 | |
*** markvoelker has quit IRC | 00:57 | |
*** markvoelker has joined #openstack-glance | 01:01 | |
*** markvoelker has quit IRC | 01:06 | |
*** markvoelker has joined #openstack-glance | 01:11 | |
*** dalgaaf has quit IRC | 01:14 | |
*** markvoelker has quit IRC | 01:15 | |
*** catintheroof has joined #openstack-glance | 01:19 | |
*** markvoelker has joined #openstack-glance | 01:20 | |
*** catintheroof has quit IRC | 01:21 | |
*** AlexeyAbashkin has joined #openstack-glance | 01:28 | |
*** AlexeyAbashkin has quit IRC | 01:32 | |
*** bjolo has joined #openstack-glance | 01:41 | |
*** links has joined #openstack-glance | 01:44 | |
*** links is now known as Jaison|away | 01:45 | |
*** chlong has joined #openstack-glance | 01:50 | |
*** markvoelker has quit IRC | 01:53 | |
*** markvoelker has joined #openstack-glance | 01:59 | |
*** markvoelker has quit IRC | 02:03 | |
*** masber has quit IRC | 02:07 | |
*** markvoelker has joined #openstack-glance | 02:08 | |
*** markvoelker has quit IRC | 02:12 | |
*** bkopilov_ has quit IRC | 02:12 | |
*** bkopilov has quit IRC | 02:13 | |
*** markvoelker has joined #openstack-glance | 02:17 | |
*** trungnv has quit IRC | 02:18 | |
*** markvoelker has quit IRC | 02:21 | |
*** markvoelker has joined #openstack-glance | 02:26 | |
*** AlexeyAbashkin has joined #openstack-glance | 02:27 | |
*** markvoelker has quit IRC | 02:30 | |
*** AlexeyAbashkin has quit IRC | 02:31 | |
*** markvoelker has joined #openstack-glance | 02:35 | |
*** tonyb has quit IRC | 02:36 | |
*** dalgaaf has joined #openstack-glance | 02:37 | |
*** tonyb has joined #openstack-glance | 02:37 | |
*** markvoelker has quit IRC | 02:40 | |
*** markvoelker has joined #openstack-glance | 02:44 | |
*** lbragstad has joined #openstack-glance | 02:45 | |
*** masber has joined #openstack-glance | 02:49 | |
*** markvoelker has quit IRC | 02:49 | |
*** markvoelker has joined #openstack-glance | 02:53 | |
*** udesale has joined #openstack-glance | 03:08 | |
*** trungnv has joined #openstack-glance | 03:17 | |
*** Jaison|away is now known as links | 03:23 | |
*** rosmaita has quit IRC | 03:26 | |
*** AlexeyAbashkin has joined #openstack-glance | 03:26 | |
*** markvoelker has quit IRC | 03:27 | |
*** AlexeyAbashkin has quit IRC | 03:31 | |
*** bkopilov has joined #openstack-glance | 03:39 | |
*** bkopilov_ has joined #openstack-glance | 03:40 | |
*** nicolasbock has quit IRC | 03:41 | |
*** mtreinish has quit IRC | 03:42 | |
*** mtreinish has joined #openstack-glance | 03:42 | |
*** masber has quit IRC | 03:46 | |
*** udesale has quit IRC | 03:47 | |
*** udesale has joined #openstack-glance | 03:50 | |
*** udesale has quit IRC | 03:52 | |
*** udesale has joined #openstack-glance | 03:52 | |
*** abhishekk has joined #openstack-glance | 03:55 | |
*** lbragstad has quit IRC | 03:58 | |
*** trungnv has quit IRC | 04:10 | |
*** markvoelker has joined #openstack-glance | 04:17 | |
*** markvoelker has quit IRC | 04:22 | |
*** AlexeyAbashkin has joined #openstack-glance | 04:26 | |
*** markvoelker has joined #openstack-glance | 04:27 | |
*** AlexeyAbashkin has quit IRC | 04:31 | |
*** markvoelker has quit IRC | 04:33 | |
*** markvoelker has joined #openstack-glance | 04:34 | |
*** markvoelker has quit IRC | 05:54 | |
*** tshefi has joined #openstack-glance | 05:55 | |
*** e0ne has joined #openstack-glance | 06:07 | |
*** gabor_antal has quit IRC | 06:17 | |
*** gcb has joined #openstack-glance | 06:18 | |
*** masber has joined #openstack-glance | 06:21 | |
*** aavraham has joined #openstack-glance | 06:27 | |
*** pcaruana has joined #openstack-glance | 06:44 | |
*** e0ne has quit IRC | 06:45 | |
*** markvoelker has joined #openstack-glance | 06:50 | |
*** openstackgerrit has joined #openstack-glance | 06:54 | |
openstackgerrit | Nam Nguyen Hoai proposed openstack/python-glanceclient master: Use generic user for both zuul v2 and v3 https://review.openstack.org/512504 | 06:54 |
---|---|---|
*** gabor_antal has joined #openstack-glance | 06:57 | |
*** namnh has joined #openstack-glance | 07:01 | |
*** bkopilov_ has quit IRC | 07:02 | |
*** tesseract has joined #openstack-glance | 07:16 | |
openstackgerrit | Nam Nguyen Hoai proposed openstack/python-glanceclient master: Use generic user for both zuul v2 and v3 https://review.openstack.org/512504 | 07:25 |
*** AlexeyAbashkin has joined #openstack-glance | 07:34 | |
*** trungnv has joined #openstack-glance | 07:43 | |
*** tshefi has quit IRC | 08:48 | |
*** markvoelker has quit IRC | 09:03 | |
*** markvoelker has joined #openstack-glance | 09:04 | |
*** e0ne has joined #openstack-glance | 09:13 | |
*** udesale__ has joined #openstack-glance | 09:19 | |
*** udesale has quit IRC | 09:19 | |
*** udesale__ has quit IRC | 09:22 | |
*** udesale has joined #openstack-glance | 09:22 | |
*** tshefi has joined #openstack-glance | 10:00 | |
*** trungnv has quit IRC | 10:05 | |
*** kuzko has quit IRC | 10:06 | |
*** kuzko has joined #openstack-glance | 10:14 | |
*** mvk has quit IRC | 10:19 | |
*** tshefi_ has joined #openstack-glance | 10:30 | |
*** tshefi has quit IRC | 10:30 | |
*** openstackgerrit has quit IRC | 10:33 | |
*** namnh has quit IRC | 10:36 | |
*** tesseract has quit IRC | 10:43 | |
*** tesseract has joined #openstack-glance | 10:43 | |
*** bkopilov has quit IRC | 10:46 | |
*** mvk has joined #openstack-glance | 10:50 | |
*** nicolasbock has joined #openstack-glance | 11:02 | |
*** mosulica has joined #openstack-glance | 11:21 | |
*** nicolasbock has quit IRC | 11:23 | |
*** nicolasbock has joined #openstack-glance | 11:35 | |
*** udesale has quit IRC | 11:38 | |
*** rosmaita has joined #openstack-glance | 11:39 | |
*** udesale has joined #openstack-glance | 11:44 | |
*** chlong has quit IRC | 12:01 | |
*** udesale has quit IRC | 12:01 | |
*** bkopilov has joined #openstack-glance | 12:20 | |
*** abhishekk has quit IRC | 12:30 | |
*** gabor_antal_ has joined #openstack-glance | 12:37 | |
*** gabor_antal has quit IRC | 12:38 | |
*** lbragstad has joined #openstack-glance | 13:22 | |
*** chlong has joined #openstack-glance | 13:42 | |
*** gcb has quit IRC | 13:45 | |
*** gcb has joined #openstack-glance | 13:47 | |
*** catintheroof has joined #openstack-glance | 13:53 | |
*** e0ne_ has joined #openstack-glance | 14:04 | |
*** e0ne has quit IRC | 14:04 | |
*** catintheroof has quit IRC | 14:11 | |
*** Nil_ has joined #openstack-glance | 14:12 | |
*** aavraham has left #openstack-glance | 14:22 | |
*** chlong has quit IRC | 14:34 | |
*** links has quit IRC | 14:41 | |
*** chlong has joined #openstack-glance | 14:48 | |
*** catintheroof has joined #openstack-glance | 14:51 | |
*** catintheroof has quit IRC | 15:03 | |
*** markvoelker has quit IRC | 15:17 | |
*** markvoelker has joined #openstack-glance | 15:18 | |
*** markvoelker has quit IRC | 15:22 | |
*** mosulica has quit IRC | 15:25 | |
*** AlexeyAbashkin has quit IRC | 15:30 | |
*** AlexeyAbashkin has joined #openstack-glance | 15:30 | |
*** tshefi_ has quit IRC | 15:30 | |
*** AlexeyAbashkin has quit IRC | 15:41 | |
*** e0ne_ has quit IRC | 15:46 | |
*** pcaruana has quit IRC | 16:01 | |
*** mvk has quit IRC | 16:38 | |
*** tesseract has quit IRC | 17:02 | |
*** abhishekk has joined #openstack-glance | 17:16 | |
*** AlexeyAbashkin has joined #openstack-glance | 17:22 | |
*** AlexeyAbashkin has quit IRC | 17:24 | |
*** mvk has joined #openstack-glance | 17:26 | |
*** mvk has quit IRC | 17:48 | |
*** mvk has joined #openstack-glance | 17:49 | |
*** gabor_antal_km has joined #openstack-glance | 17:53 | |
*** gabor_antal_ has quit IRC | 17:53 | |
*** abhishekk has quit IRC | 18:00 | |
*** MVenesio has joined #openstack-glance | 18:11 | |
*** openstackgerrit has joined #openstack-glance | 18:33 | |
openstackgerrit | Cyril Roelandt proposed openstack/glance master: Make ImageTarget behave like a dictionary https://review.openstack.org/512020 | 18:33 |
*** markvoelker has joined #openstack-glance | 19:26 | |
*** AlexeyAbashkin has joined #openstack-glance | 19:40 | |
*** AlexeyAbashkin has quit IRC | 19:44 | |
*** catintheroof has joined #openstack-glance | 19:49 | |
*** e0ne has joined #openstack-glance | 19:52 | |
*** twouters has joined #openstack-glance | 19:52 | |
twouters | hi, I get the following error when I try to add a new (url based) image through horizon: 403 Forbidden You are not authorized to complete get_image_location action. (HTTP 403) | 20:01 |
twouters | I've changed the "get_image_location" policy to "tenant:%(owner)s or role:admin" | 20:03 |
twouters | the user that I'm testing this with is not an admin user | 20:04 |
twouters | (I'm running ocata) | 20:05 |
*** e0ne has quit IRC | 20:13 | |
*** e0ne has joined #openstack-glance | 20:13 | |
*** markvoelker_ has joined #openstack-glance | 20:15 | |
*** chlong has quit IRC | 20:16 | |
*** markvoelker has quit IRC | 20:18 | |
*** e0ne has quit IRC | 20:19 | |
*** AlexeyAbashkin has joined #openstack-glance | 20:22 | |
openstackgerrit | Marco Chiappero proposed openstack/glance master: Add libvirt image metadef for hw_power_governor https://review.openstack.org/512817 | 20:24 |
rosmaita | twouters: you don't need that particular policy setting -- the only people who can get an image's location with the unrestricted policy are the owner and the admin | 20:26 |
*** AlexeyAbashkin has quit IRC | 20:27 | |
twouters | are you sure? the default policy is set to "role:admin", right? | 20:27 |
rosmaita | twouters: here's the default ocata policy file if you want to check: http://git.openstack.org/cgit/openstack/glance/tree/etc/policy.json?h=stable/ocata | 20:29 |
twouters | oh, `"default": "role:admin",` doesn't mean "everything without specific rules are restricted to admins"? :-) | 20:30 |
twouters | the default policy seems to work fine, thanks | 20:31 |
rosmaita | twouters: the 'default' target is used if the policy engine is looking for a target and can't find it. So if you completely left get_image_location out of the file entirely, then the 'default' target would be used, effectively making get_image_location restricted to admin only | 20:33 |
rosmaita | twouters: in the policy language, an empty string means "anybody". You can also use '@' to mean anybody, maybe we should've done that to make it more explicit | 20:34 |
rosmaita | because the policy configuration is fairly confusing | 20:34 |
twouters | yeah, is there some documentation available on that? i don't think this was explained in the glace docs | 20:35 |
*** catintheroof has quit IRC | 20:35 | |
*** catintheroof has joined #openstack-glance | 20:36 | |
twouters | thanks for the information, it all makes sense now :p | 20:36 |
*** catintheroof has quit IRC | 20:36 | |
twouters | rosmaita: shouldn't the *_image_location rules be more restricted by default? (https://wiki.openstack.org/wiki/OSSN/OSSN-0065) | 20:38 |
twouters | restrictive | 20:38 |
rosmaita | twouters: the key thing there is this sentence: "The configuration option 'show_multiple_locations'. If this is set to False, this attack vector is not available." so if you have show_multiple_locations = False (or are using its default value, which is False) you don't need to mess with the individual *_image_location settings | 20:43 |
twouters | I've set it to True because I couldn't create images with a url source without it | 20:45 |
rosmaita | twouters: sorry i missed your earlier question ... i think the best docs on configuring a policy file are in the source code: http://git.openstack.org/cgit/openstack/oslo.policy/tree/oslo_policy/policy.py?h=stable/ocata | 20:48 |
rosmaita | lines 18-221 explain how it's supposed to work | 20:49 |
twouters | oh, cool, thanks | 20:49 |
twouters | I'll have a look at it tomorrow, this will help a lot | 20:50 |
rosmaita | you have to be careful configuring the *_image_location values | 20:50 |
rosmaita | because glance needs to be able to set the image location when you upload the image data | 20:51 |
rosmaita | no matter what backend you are using | 20:51 |
rosmaita | anyway, i should be around tomorrow afternoon | 20:52 |
*** sapd__ has joined #openstack-glance | 20:53 | |
*** sapd_ has quit IRC | 20:53 | |
*** MVenesio has quit IRC | 20:57 | |
openstackgerrit | Marco Chiappero proposed openstack/glance master: Add libvirt image metadef for hw_power_governor https://review.openstack.org/512817 | 20:58 |
*** chlong has joined #openstack-glance | 21:18 | |
*** lbragstad has quit IRC | 22:36 | |
*** catintheroof has joined #openstack-glance | 22:43 | |
*** lin_yang has joined #openstack-glance | 22:56 | |
*** catintheroof has quit IRC | 23:17 | |
*** stewie_925 has joined #openstack-glance | 23:31 | |
stewie_925 | hello guys, is there a valid min-ram range for images? | 23:32 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!