*** markvoelker has quit IRC | 00:09 | |
*** markvoelker has joined #openstack-glance | 00:09 | |
*** markvoelker has quit IRC | 00:14 | |
*** Sravan has quit IRC | 00:20 | |
*** Sravan has joined #openstack-glance | 00:39 | |
*** markvoelker has joined #openstack-glance | 01:10 | |
*** Sravan has quit IRC | 01:25 | |
*** markvoelker has quit IRC | 01:44 | |
*** sapd1_ has quit IRC | 02:13 | |
openstackgerrit | Andriy Shevchenko proposed openstack/python-glanceclient master: Update min tox version to 2.0 https://review.openstack.org/612110 | 02:29 |
---|---|---|
*** _alastor_ has joined #openstack-glance | 02:33 | |
*** awalende has joined #openstack-glance | 02:35 | |
*** _alastor_ has quit IRC | 02:38 | |
*** awalende has quit IRC | 02:39 | |
*** markvoelker has joined #openstack-glance | 02:41 | |
*** bhagyashris has joined #openstack-glance | 02:50 | |
*** markvoelker has quit IRC | 03:13 | |
*** udesale has joined #openstack-glance | 03:54 | |
*** belmoreira has quit IRC | 04:10 | |
*** markvoelker has joined #openstack-glance | 04:10 | |
*** jlvillal has quit IRC | 04:14 | |
*** jlvillal has joined #openstack-glance | 04:14 | |
*** Sravan has joined #openstack-glance | 04:22 | |
*** Sravan has quit IRC | 04:32 | |
*** _alastor_ has joined #openstack-glance | 04:35 | |
*** _alastor_ has quit IRC | 04:39 | |
*** markvoelker has quit IRC | 04:44 | |
*** zzzeek has quit IRC | 04:49 | |
*** zzzeek has joined #openstack-glance | 04:52 | |
*** irclogbot_1 has quit IRC | 04:57 | |
*** Sravan has joined #openstack-glance | 05:00 | |
*** Sravan has quit IRC | 05:04 | |
*** Sravan has joined #openstack-glance | 05:07 | |
*** ratailor has joined #openstack-glance | 05:09 | |
*** Sravan has quit IRC | 05:10 | |
*** Sravan has joined #openstack-glance | 05:11 | |
*** Sravan has quit IRC | 05:16 | |
*** pdeore has joined #openstack-glance | 05:25 | |
*** Sravan has joined #openstack-glance | 05:25 | |
*** Sravan has quit IRC | 05:27 | |
*** Sravan has joined #openstack-glance | 05:28 | |
*** abhishekk has joined #openstack-glance | 05:28 | |
*** udesale has quit IRC | 05:33 | |
Sravan | hi | 05:36 |
Sravan | i wanted to remove a controller node that is down from deployment and add a new controller node using kolla-ansible | 05:37 |
Sravan | can you please let me know how it can be done? | 05:37 |
Sravan | without using destroy | 05:37 |
*** markvoelker has joined #openstack-glance | 05:41 | |
*** Sravan has quit IRC | 05:42 | |
*** udesale has joined #openstack-glance | 05:43 | |
*** Sravan has joined #openstack-glance | 05:43 | |
*** Sravan has quit IRC | 05:43 | |
*** itlinux has quit IRC | 05:45 | |
*** itlinux has joined #openstack-glance | 06:11 | |
*** markvoelker has quit IRC | 06:14 | |
*** itlinux has quit IRC | 06:16 | |
openstackgerrit | Felipe Monteiro proposed openstack/glance master: Add Policy enforcement for several Metadata Definition delete APIs https://review.openstack.org/584530 | 06:24 |
*** mosulica has joined #openstack-glance | 06:36 | |
*** Luzi has joined #openstack-glance | 06:48 | |
*** markvoelker has joined #openstack-glance | 07:11 | |
*** itlinux has joined #openstack-glance | 07:12 | |
*** belmoreira has joined #openstack-glance | 07:16 | |
*** abhishekk has quit IRC | 07:17 | |
*** itlinux has quit IRC | 07:17 | |
*** rcernin has quit IRC | 07:25 | |
*** takamatsu has joined #openstack-glance | 07:39 | |
*** markvoelker has quit IRC | 07:43 | |
*** udesale has quit IRC | 07:58 | |
*** udesale has joined #openstack-glance | 08:03 | |
*** udesale has quit IRC | 08:07 | |
*** udesale has joined #openstack-glance | 08:08 | |
*** pcaruana has joined #openstack-glance | 08:11 | |
*** tkajinam has quit IRC | 08:12 | |
*** itlinux has joined #openstack-glance | 08:22 | |
*** itlinux has quit IRC | 08:22 | |
*** ratailor has quit IRC | 08:35 | |
*** _alastor_ has joined #openstack-glance | 08:36 | |
*** _alastor_ has quit IRC | 08:40 | |
*** markvoelker has joined #openstack-glance | 08:41 | |
*** itlinux has joined #openstack-glance | 08:41 | |
*** itlinux has quit IRC | 08:42 | |
*** priteau has joined #openstack-glance | 08:59 | |
*** markvoelker has quit IRC | 09:14 | |
*** ratailor has joined #openstack-glance | 09:28 | |
*** Florian has quit IRC | 09:28 | |
*** abhishekk has joined #openstack-glance | 09:51 | |
*** bhdn has quit IRC | 09:53 | |
*** awalende has joined #openstack-glance | 09:54 | |
*** bhagyashris has quit IRC | 09:55 | |
*** markvoelker has joined #openstack-glance | 10:11 | |
*** MattMan has quit IRC | 10:30 | |
*** MattMan has joined #openstack-glance | 10:30 | |
*** abhishekk has quit IRC | 10:35 | |
*** priteau has quit IRC | 10:41 | |
*** markvoelker has quit IRC | 10:43 | |
*** lpetrut has joined #openstack-glance | 10:46 | |
*** udesale has quit IRC | 11:10 | |
*** markvoelker has joined #openstack-glance | 11:40 | |
*** pdeore has quit IRC | 11:41 | |
*** awalende has quit IRC | 11:42 | |
*** awalende has joined #openstack-glance | 11:42 | |
*** awalende has quit IRC | 11:44 | |
*** awalende has joined #openstack-glance | 11:44 | |
*** awalende has quit IRC | 12:01 | |
*** awalende has joined #openstack-glance | 12:01 | |
*** awalende has quit IRC | 12:02 | |
*** awalende has joined #openstack-glance | 12:02 | |
*** rosmaita has joined #openstack-glance | 12:04 | |
*** ratailor has quit IRC | 12:06 | |
*** mvkr has quit IRC | 12:09 | |
*** markvoelker has quit IRC | 12:14 | |
*** udesale has joined #openstack-glance | 12:55 | |
*** markvoelker has joined #openstack-glance | 13:11 | |
*** itlinux has joined #openstack-glance | 13:12 | |
*** mvkr has joined #openstack-glance | 13:13 | |
*** itlinux has quit IRC | 13:21 | |
*** itlinux has joined #openstack-glance | 13:22 | |
*** itlinux has quit IRC | 13:28 | |
*** itlinux has joined #openstack-glance | 13:32 | |
*** itlinux has quit IRC | 13:37 | |
*** zul has joined #openstack-glance | 13:40 | |
*** jmlowe has quit IRC | 13:41 | |
*** itlinux has joined #openstack-glance | 13:42 | |
*** markvoelker has quit IRC | 13:43 | |
*** itlinux has quit IRC | 13:47 | |
*** jmlowe has joined #openstack-glance | 14:07 | |
*** itlinux has joined #openstack-glance | 14:22 | |
*** zul has quit IRC | 14:25 | |
*** zul has joined #openstack-glance | 14:25 | |
*** itlinux has quit IRC | 14:30 | |
*** _alastor_ has joined #openstack-glance | 14:38 | |
*** markvoelker has joined #openstack-glance | 14:41 | |
*** _alastor_ has quit IRC | 14:43 | |
*** itlinux has joined #openstack-glance | 14:52 | |
*** udesale has quit IRC | 14:53 | |
*** itlinux has quit IRC | 14:56 | |
*** itlinux has joined #openstack-glance | 14:56 | |
*** itlinux has quit IRC | 14:57 | |
*** awalende has quit IRC | 15:05 | |
*** awalende has joined #openstack-glance | 15:05 | |
*** awalende has quit IRC | 15:07 | |
*** awalende has joined #openstack-glance | 15:07 | |
*** awalende has quit IRC | 15:07 | |
*** awalende has joined #openstack-glance | 15:11 | |
*** markvoelker has quit IRC | 15:14 | |
*** shananigans has joined #openstack-glance | 15:14 | |
*** awalende has quit IRC | 15:15 | |
*** Luzi has quit IRC | 15:19 | |
*** jmlowe has quit IRC | 15:23 | |
*** jmlowe has joined #openstack-glance | 15:24 | |
*** jmlowe has quit IRC | 15:34 | |
*** jmlowe has joined #openstack-glance | 15:45 | |
*** lpetrut has quit IRC | 15:45 | |
*** _alastor_ has joined #openstack-glance | 16:00 | |
*** mosulica has quit IRC | 16:08 | |
*** markvoelker has joined #openstack-glance | 16:11 | |
*** jaypipes has quit IRC | 16:36 | |
*** jaypipes has joined #openstack-glance | 16:36 | |
*** markvoelker has quit IRC | 16:44 | |
*** Florian has joined #openstack-glance | 16:53 | |
*** pcaruana has quit IRC | 16:57 | |
*** Vadmacs has joined #openstack-glance | 17:24 | |
*** lpetrut has joined #openstack-glance | 17:27 | |
*** lpetrut has quit IRC | 17:40 | |
*** markvoelker has joined #openstack-glance | 17:41 | |
*** Sravan has joined #openstack-glance | 17:44 | |
*** Sravan has quit IRC | 18:01 | |
*** Sravan has joined #openstack-glance | 18:03 | |
*** Sravan has quit IRC | 18:10 | |
*** markvoelker has quit IRC | 18:14 | |
*** Sravan has joined #openstack-glance | 18:15 | |
*** Sravan has quit IRC | 18:29 | |
*** mvkr has quit IRC | 18:36 | |
*** lpetrut has joined #openstack-glance | 18:39 | |
*** fiddletwix has joined #openstack-glance | 18:49 | |
*** Sravan has joined #openstack-glance | 18:58 | |
*** mvkr has joined #openstack-glance | 19:07 | |
*** markvoelker has joined #openstack-glance | 19:11 | |
*** lpetrut has quit IRC | 19:18 | |
*** Sravan has quit IRC | 19:27 | |
*** jmlowe has quit IRC | 19:37 | |
*** jmlowe has joined #openstack-glance | 19:38 | |
*** Sravan has joined #openstack-glance | 19:42 | |
*** markvoelker has quit IRC | 19:44 | |
*** Sravan has quit IRC | 19:57 | |
openstackgerrit | Cyril Roelandt proposed openstack/glance master: Add an oslo.policy.enforcer entrypoint https://review.openstack.org/637985 | 19:58 |
*** Sravan has joined #openstack-glance | 19:58 | |
*** openstackgerrit has quit IRC | 20:09 | |
*** Florian has quit IRC | 20:12 | |
*** Sravan has quit IRC | 20:28 | |
*** Sravan has joined #openstack-glance | 20:31 | |
*** Vadmacs has quit IRC | 20:38 | |
*** markvoelker has joined #openstack-glance | 20:41 | |
*** Sravan has quit IRC | 20:50 | |
*** jmlowe has quit IRC | 20:57 | |
*** markvoelker has quit IRC | 21:13 | |
*** Sravan has joined #openstack-glance | 21:25 | |
*** Sravan has quit IRC | 21:30 | |
*** Sravan has joined #openstack-glance | 22:05 | |
*** Sravan has quit IRC | 22:08 | |
*** markvoelker has joined #openstack-glance | 22:10 | |
*** Sravan has joined #openstack-glance | 22:13 | |
*** rcernin has joined #openstack-glance | 22:26 | |
*** markvoelker has quit IRC | 22:44 | |
*** tkajinam has joined #openstack-glance | 22:55 | |
fiddletwix | having issues with image visibility in ocata, I specify visibility "private" and the image is owned by one project/tenant and yet its visible to other tenants. I can change visibility to community with an empty member list and that seems to work but I would think private would also work. | 22:55 |
fiddletwix | and is this the right place for this question? :) | 22:55 |
rosmaita | fiddletwix: right place | 22:56 |
rosmaita | fiddletwix: pretty unlikely that a private image is visible to users not in that project/tenant | 22:58 |
rosmaita | usually when this is reported it has to do with policies | 22:58 |
rosmaita | an admin user *can* see the private images in other projects | 22:59 |
rosmaita | the default admin role is 'admin' | 22:59 |
rosmaita | so check to see if a user who can see the images in another project has that role | 23:00 |
rosmaita | if so, you may have bigger problems, because admins can delete the images in other projects | 23:00 |
fiddletwix | ok, let me check that users role in that project | 23:01 |
rosmaita | also, check what your definition is for 'context_is_admin' in /etc/glance/policy.json | 23:01 |
fiddletwix | that was it, the user had admin rights and that wasn't supposed to be the case! | 23:02 |
rosmaita | ok, glad you found it ... better remove those admin rights immediately! | 23:03 |
fiddletwix | already done! thankfully this was in dev so nothing too terrible | 23:03 |
rosmaita | cool | 23:04 |
rosmaita | fiddletwix: this situation has been happening more and more frequently lately ... were you working from a blog post or something? | 23:04 |
rosmaita | i've been seeing several people trying to create a "user admin" for a tenant ... you don't need to do that, the default permissions make any user in a tenant have full CRUD powers within that tenant | 23:06 |
fiddletwix | no, working with a vendor provided OS and just diving in learning this stuff. I'm reasonably new to OS operations but as soon as you said "check admin" rights the bells went off in my head | 23:06 |
fiddletwix | yeah, vendor didn't quite explain that right :/ | 23:06 |
rosmaita | thanks, just checking | 23:06 |
fiddletwix | sure thing | 23:06 |
*** shananigans has quit IRC | 23:06 | |
rosmaita | fiddletwix: you may want to take a look at the new policy configuration howto in cinder ... it's a bit different from glance, but the general idea is the same | 23:07 |
rosmaita | https://docs.openstack.org/cinder/latest/configuration/block-storage/policy-config-HOWTO.html | 23:07 |
rosmaita | one key difference is that glance does not have defaults defined in code, so you MUST use a policy.json file with glance | 23:08 |
fiddletwix | aah, good to know. policies were the next thing we were going to dive into to get a more refined RBAC | 23:11 |
fiddletwix | right now we've kept it simple, admin and member. didn't realize admin spanned projects. learning as I go but thats why I am testing in dev | 23:12 |
*** imacdonn has joined #openstack-glance | 23:32 | |
*** imacdonn_ has joined #openstack-glance | 23:32 | |
*** imacdonn_ has quit IRC | 23:32 | |
*** jmlowe has joined #openstack-glance | 23:40 | |
*** markvoelker has joined #openstack-glance | 23:41 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!