*** igordcard has joined #openstack-ironic | 00:39 | |
*** spandhe has joined #openstack-ironic | 00:45 | |
*** achanda has quit IRC | 00:46 | |
*** romcheg has quit IRC | 00:54 | |
*** devananda has quit IRC | 01:08 | |
*** devananda has joined #openstack-ironic | 01:09 | |
*** igordcard has quit IRC | 01:11 | |
*** igordcard has joined #openstack-ironic | 01:28 | |
*** slagle has quit IRC | 01:30 | |
*** slagle has joined #openstack-ironic | 01:31 | |
*** ParsectiX has quit IRC | 01:42 | |
*** ParsectiX has joined #openstack-ironic | 01:42 | |
*** Haomeng|2 has joined #openstack-ironic | 01:48 | |
*** achanda_ has joined #openstack-ironic | 01:49 | |
*** Haomeng has quit IRC | 01:50 | |
*** igordcard has quit IRC | 01:54 | |
*** achanda_ has quit IRC | 02:54 | |
*** jcoufal has quit IRC | 02:57 | |
*** jerryz_ has joined #openstack-ironic | 03:01 | |
*** anderbubble has joined #openstack-ironic | 03:22 | |
*** spandhe has quit IRC | 03:30 | |
*** chlong has quit IRC | 03:50 | |
*** lazy_prince has quit IRC | 03:59 | |
*** killer_prince has joined #openstack-ironic | 04:00 | |
*** killer_prince is now known as lazy_prince | 04:00 | |
*** rwsu-afk has quit IRC | 04:24 | |
*** subscope has joined #openstack-ironic | 05:05 | |
*** Marga_ has joined #openstack-ironic | 05:35 | |
*** Marga_ has quit IRC | 05:37 | |
*** Marga_ has joined #openstack-ironic | 05:38 | |
*** achanda has joined #openstack-ironic | 05:46 | |
*** r-daneel_ has quit IRC | 05:54 | |
*** gridinv has joined #openstack-ironic | 06:00 | |
*** Marga_ has quit IRC | 06:11 | |
openstackgerrit | Ramakrishnan G proposed openstack/ironic: iscsi_ilo driver to support agent ramdisk https://review.openstack.org/162449 | 06:38 |
---|---|---|
*** gridinv has quit IRC | 06:54 | |
*** ukalifon has joined #openstack-ironic | 06:58 | |
*** jcoufal has joined #openstack-ironic | 07:24 | |
*** ParsectiX has quit IRC | 07:32 | |
*** ParsectiX has joined #openstack-ironic | 07:32 | |
openstackgerrit | Ramakrishnan G proposed openstack/ironic: Refactor node capability methods to ironic/common https://review.openstack.org/162451 | 07:41 |
*** jcoufal has quit IRC | 07:44 | |
*** jcoufal has joined #openstack-ironic | 07:45 | |
*** jerryz_ has quit IRC | 07:47 | |
*** erwan_taf has joined #openstack-ironic | 08:30 | |
*** achanda has quit IRC | 08:30 | |
*** erwan_taf has quit IRC | 08:37 | |
*** gridinv has joined #openstack-ironic | 08:37 | |
*** jerryz_ has joined #openstack-ironic | 08:39 | |
*** andreykurilin_ has joined #openstack-ironic | 08:48 | |
openstackgerrit | Ramakrishnan G proposed openstack/ironic: Add driver interface for RAID configuration https://review.openstack.org/155230 | 08:59 |
*** jistr has joined #openstack-ironic | 09:11 | |
*** subscope has quit IRC | 09:14 | |
*** anderbubble has quit IRC | 09:17 | |
*** jistr has quit IRC | 09:23 | |
*** romcheg has joined #openstack-ironic | 09:26 | |
*** kalpase has joined #openstack-ironic | 09:31 | |
*** gridinv has quit IRC | 10:00 | |
*** ukalifon has quit IRC | 10:06 | |
*** jcoufal has quit IRC | 10:12 | |
*** jcoufal_ has joined #openstack-ironic | 10:12 | |
*** athomas has joined #openstack-ironic | 10:20 | |
*** gridinv has joined #openstack-ironic | 10:39 | |
*** chlong has joined #openstack-ironic | 10:40 | |
*** ParsectiX has quit IRC | 10:46 | |
*** ParsectiX has joined #openstack-ironic | 10:47 | |
*** gridinv has quit IRC | 10:57 | |
*** andreykurilin_ has quit IRC | 11:11 | |
*** romcheg has quit IRC | 11:14 | |
*** igordcard has joined #openstack-ironic | 11:14 | |
*** ParsectiX has quit IRC | 11:15 | |
*** chlong has quit IRC | 11:21 | |
*** Marga_ has joined #openstack-ironic | 11:26 | |
*** ParsectiX has joined #openstack-ironic | 11:29 | |
*** jcoufal_ has quit IRC | 12:01 | |
*** Marga_ has quit IRC | 12:08 | |
*** ParsectiX has quit IRC | 12:37 | |
*** ParsectiX has joined #openstack-ironic | 12:38 | |
*** chlong has joined #openstack-ironic | 12:39 | |
*** jcoufal has joined #openstack-ironic | 12:40 | |
*** pleia2 has quit IRC | 13:01 | |
*** anderbubble has joined #openstack-ironic | 13:26 | |
*** kalpase1 has joined #openstack-ironic | 13:35 | |
*** kalpase has quit IRC | 13:35 | |
*** enikanorov_ has quit IRC | 13:36 | |
*** alexpilotti has joined #openstack-ironic | 13:46 | |
*** ukalifon has joined #openstack-ironic | 13:56 | |
*** Haomeng has joined #openstack-ironic | 14:01 | |
*** Haomeng|2 has quit IRC | 14:04 | |
*** chlong has quit IRC | 14:06 | |
*** jerryz_ has quit IRC | 14:12 | |
*** pleia2 has joined #openstack-ironic | 14:14 | |
*** kalpase1 has left #openstack-ironic | 14:26 | |
*** igordcard has quit IRC | 14:46 | |
*** dtantsur|pto has quit IRC | 14:52 | |
*** ParsectiX has quit IRC | 15:11 | |
*** ParsectiX has joined #openstack-ironic | 15:11 | |
*** PaulCzar has quit IRC | 15:47 | |
*** alexpilotti has quit IRC | 15:48 | |
*** jerryz has joined #openstack-ironic | 15:58 | |
*** r-daneel_ has joined #openstack-ironic | 16:11 | |
*** r-daneel__ has joined #openstack-ironic | 16:12 | |
*** r-daneel_ has quit IRC | 16:16 | |
*** ParsectiX has quit IRC | 16:37 | |
*** ParsectiX has joined #openstack-ironic | 16:37 | |
*** mdbooth has quit IRC | 16:43 | |
*** jerryz has quit IRC | 16:43 | |
*** mdbooth has joined #openstack-ironic | 16:50 | |
*** andreykurilin_ has joined #openstack-ironic | 16:57 | |
*** ijw has quit IRC | 17:05 | |
*** ijw has joined #openstack-ironic | 17:06 | |
*** mdbooth has quit IRC | 17:24 | |
*** gridinv has joined #openstack-ironic | 17:28 | |
*** mdbooth has joined #openstack-ironic | 17:29 | |
*** Marga_ has joined #openstack-ironic | 17:30 | |
*** anderbubble has quit IRC | 17:32 | |
*** andreykurilin_ has quit IRC | 17:38 | |
*** ParsectiX has quit IRC | 17:48 | |
*** ParsectiX has joined #openstack-ironic | 17:48 | |
*** anderbubble has joined #openstack-ironic | 17:48 | |
*** ParsectiX has quit IRC | 17:50 | |
*** ParsectiX has joined #openstack-ironic | 17:51 | |
*** gridinv has quit IRC | 18:07 | |
*** anderbubble has quit IRC | 18:19 | |
*** ParsectiX has quit IRC | 18:22 | |
*** ParsectiX has joined #openstack-ironic | 18:22 | |
*** Marga_ has quit IRC | 18:29 | |
*** achanda has joined #openstack-ironic | 18:35 | |
*** r-daneel__ has quit IRC | 18:47 | |
*** spandhe has joined #openstack-ironic | 18:53 | |
openstackgerrit | Nisha Agarwal proposed openstack/ironic: Automate boot iso creation with in ironic for iscsi-ilo https://review.openstack.org/155900 | 18:59 |
*** jmccrory has joined #openstack-ironic | 19:01 | |
*** ParsectiX has quit IRC | 19:03 | |
*** ParsectiX has joined #openstack-ironic | 19:04 | |
*** andreykurilin_ has joined #openstack-ironic | 19:17 | |
*** achanda has quit IRC | 19:27 | |
*** andreykurilin_ has quit IRC | 19:28 | |
*** ukalifon has quit IRC | 19:32 | |
*** Marga_ has joined #openstack-ironic | 19:32 | |
*** achanda has joined #openstack-ironic | 19:32 | |
*** achanda has quit IRC | 19:34 | |
*** ParsectiX has quit IRC | 19:35 | |
*** ParsectiX has joined #openstack-ironic | 19:35 | |
*** jcoufal has quit IRC | 19:37 | |
openstackgerrit | Nisha Agarwal proposed openstack/ironic: ironic port deletion fails even if node is locked by same process https://review.openstack.org/161861 | 19:39 |
*** achanda has joined #openstack-ironic | 19:40 | |
openstackgerrit | Sirushti Murugesan proposed openstack/ironic: Adds support for deploying whole disk images https://review.openstack.org/150142 | 19:51 |
*** gridinv has joined #openstack-ironic | 19:53 | |
openstackgerrit | Sirushti Murugesan proposed openstack/ironic: Adds support for deploying whole disk images https://review.openstack.org/150142 | 19:59 |
*** spandhe has quit IRC | 20:08 | |
*** anderbubble has joined #openstack-ironic | 20:12 | |
openstackgerrit | Nisha Agarwal proposed openstack/ironic: iLO implementation for hardware inspection https://review.openstack.org/151596 | 20:14 |
*** gridinv has quit IRC | 20:17 | |
*** jmccrory has quit IRC | 20:21 | |
*** achanda has quit IRC | 20:21 | |
*** romcheg has joined #openstack-ironic | 20:24 | |
*** jcoufal has joined #openstack-ironic | 20:31 | |
openstackgerrit | Nisha Agarwal proposed openstack/python-ironicclient: enhanced node-set-provision-state https://review.openstack.org/148804 | 20:34 |
*** Marga_ has quit IRC | 20:59 | |
*** achanda has joined #openstack-ironic | 21:01 | |
*** Marga_ has joined #openstack-ironic | 21:03 | |
*** dhellmann has quit IRC | 21:21 | |
*** dhellmann has joined #openstack-ironic | 21:22 | |
*** dhellmann has quit IRC | 21:23 | |
*** dhellmann has joined #openstack-ironic | 21:24 | |
*** dhellmann has quit IRC | 21:24 | |
*** dhellmann has joined #openstack-ironic | 21:25 | |
*** dhellmann has quit IRC | 21:28 | |
*** dhellmann has joined #openstack-ironic | 21:29 | |
*** chlong has joined #openstack-ironic | 21:38 | |
*** gridinv has joined #openstack-ironic | 21:39 | |
*** jamielennox has joined #openstack-ironic | 21:48 | |
jamielennox | can anyone tell me, is there an ironic specific reason that it keeps fetching new keystone tokens rather than using the user token | 21:49 |
*** igordcard has joined #openstack-ironic | 21:54 | |
*** chlong has quit IRC | 21:56 | |
*** jcoufal has quit IRC | 22:15 | |
*** igordcard has quit IRC | 22:21 | |
*** Marga_ has quit IRC | 22:38 | |
*** Marga_ has joined #openstack-ironic | 22:43 | |
*** igordcard has joined #openstack-ironic | 22:50 | |
*** igordcard has quit IRC | 22:58 | |
*** yuanying has joined #openstack-ironic | 23:10 | |
openstackgerrit | Ghe Rivero proposed openstack/ironic: Use oslo_log lib https://review.openstack.org/157602 | 23:11 |
*** andreykurilin_ has joined #openstack-ironic | 23:14 | |
*** igordcard has joined #openstack-ironic | 23:19 | |
*** Marga_ has quit IRC | 23:24 | |
*** Marga_ has joined #openstack-ironic | 23:26 | |
*** achanda has quit IRC | 23:34 | |
*** chlong has joined #openstack-ironic | 23:35 | |
*** achanda has joined #openstack-ironic | 23:36 | |
openstackgerrit | Ghe Rivero proposed openstack/ironic: Use oslo_log lib https://review.openstack.org/157602 | 23:37 |
jroll | jamielennox: ironic api is admin-only | 23:41 |
jamielennox | jroll: any reason that wouldn't be controlled by the user having admin rights though? | 23:41 |
*** igordcard has quit IRC | 23:41 | |
jamielennox | rather than having ironic get a token for the auth_token user? | 23:41 |
jroll | jamielennox: the nova user? | 23:41 |
jroll | I guess we should back up and figure out exactly which bits we're talking about | 23:42 |
openstackgerrit | Ghe Rivero proposed openstack/ironic: Use strutils from oslo_utils https://review.openstack.org/162497 | 23:42 |
jamielennox | jroll: so i'm generally looking at making openstack use keystone v3 everywhere | 23:44 |
jamielennox | one of the things I did was to change how auth_token middleware was configured with v3 auth | 23:44 |
jamielennox | this broke any service that expected auth_token middleware to be configured to use v2 auth | 23:44 |
jamielennox | ironic does: https://github.com/openstack/ironic/blob/master/ironic/common/keystone.py | 23:45 |
jamielennox | now ignoring that it doesn't cache the catalog at all, and that it does a full authentication to check the expiry date on a token | 23:45 |
jamielennox | I'm just not sure i see why it needs to use the auth_token user at all | 23:46 |
jamielennox | given that the 3 public functions are: get_keystone_url (should be a config option - or better yet from the catalog) | 23:47 |
jamielennox | get_service_url (should be from the catalog) | 23:47 |
jamielennox | damn 4 | 23:47 |
jamielennox | get_admin_auth_token() - which *if* required should be configured independantly | 23:48 |
jamielennox | and token_expires_soon - which i haven't looked into yet but shouldn't need to do auth | 23:48 |
jroll | so I'm not well versed in this and I have to leave in about 3 minutes, but | 23:49 |
jroll | we use tokens for a few things: | 23:49 |
jroll | 1) validating inbound tokens | 23:49 |
jroll | 2) configuring DHCP through neutron | 23:49 |
*** andreykurilin_ has quit IRC | 23:49 | |
jroll | 3) getting image properties and downloading images from glance | 23:50 |
jroll | 4) uploading blobs to swift | 23:50 |
jamielennox | cool - so 1 should be handled by auth_token middleware | 23:50 |
jroll | 5) passing a token to deploy ramdisks on the bare metal machines, so they can talk to the ironic API | 23:50 |
jroll | (I think that's it) | 23:50 |
jamielennox | number 2 i've got covered: https://review.openstack.org/#/c/162037/ | 23:50 |
jamielennox | 5 is interesting | 23:51 |
jroll | 5 is really horrible and makes me sad | 23:52 |
jamielennox | it almost feels like 5 should be a message bus call rather than API with token | 23:52 |
jamielennox | or something else entriely | 23:52 |
jamielennox | client certs? | 23:52 |
jroll | client certs are likely the most reasonable | 23:52 |
jroll | it's all horrible, because this info is passed through DHCP | 23:52 |
jamielennox | so 3 and 4 i guess are what i'm looking at | 23:53 |
jroll | which is pretty insecure, although the time it's available is short and it's restricted to a particular MAC address | 23:53 |
jamielennox | essentially what I guess i want to figure out is do i just add a new section to the ironic config for adding user details to talk to keystone | 23:53 |
jamielennox | or should i actually try and figure out what the auth is doing here, and whether we can just replace it with the user token | 23:53 |
jamielennox | the first option being essentially what i did for neutron | 23:53 |
jroll | yeah, I'm leaning toward the first, most of this is admin stuff, not user-exposed stuff | 23:54 |
jroll | I gotta run; what timezone are you in? | 23:54 |
jamielennox | sydney | 23:54 |
jamielennox | 11am | 23:55 |
jroll | mmm, ok | 23:55 |
jroll | I'm west coast US... pop in here tomorrow morning and we can chat? | 23:55 |
jamielennox | sure | 23:55 |
jamielennox | if you're leaning towards the just replace option then that's much easier | 23:55 |
jamielennox | i was starting that patch when i thought i should come in and ask instead | 23:55 |
jamielennox | because the auth in common/keystone is a little basic | 23:56 |
jroll | yeah, though I'm not sure of all the implications | 23:56 |
jroll | I also don't have keystone v3 in my prod environment, so I'm nervous :) | 23:56 |
jamielennox | jroll: i've never touched ironic and i don't understand most of it :) | 23:56 |
jamielennox | until now | 23:56 |
jroll | heh, same with me for keystone :P | 23:57 |
jroll | but not having v2 support would be a huge pain for me :P | 23:57 |
jamielennox | just to clarify though - it wouldn't be a force up to keystone v3, you'd still be able to configure v2 and if that works then v3 would just be a few different options | 23:57 |
jamielennox | i'm trying to make all this transparent to the services | 23:58 |
jroll | ok, awesome | 23:58 |
jroll | let's talk tomorrow when smarter people than I are around then :) | 23:59 |
jamielennox | sounds good | 23:59 |
jamielennox | night | 23:59 |
jroll | see ya | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!