*** thedodd has joined #openstack-keystone | 00:13 | |
*** arosen1 has joined #openstack-keystone | 00:54 | |
*** arosen1 has quit IRC | 00:59 | |
openstackgerrit | Marek Denis proposed a change to openstack/keystone: Filter SAML2 assertion parameters with certain prefix. https://review.openstack.org/80946 | 01:04 |
---|---|---|
*** arosen1 has joined #openstack-keystone | 01:08 | |
*** flaper87 is now known as flaper87|afk | 02:12 | |
*** devlaps has quit IRC | 02:30 | |
*** thedodd has quit IRC | 02:39 | |
*** mberlin1 has joined #openstack-keystone | 02:52 | |
*** mberlin has quit IRC | 02:53 | |
*** devlaps has joined #openstack-keystone | 03:01 | |
*** arosen1 has quit IRC | 03:01 | |
*** arosen2 has joined #openstack-keystone | 03:02 | |
*** devlaps1 has joined #openstack-keystone | 03:02 | |
*** devlaps has quit IRC | 03:03 | |
*** devlaps1 has quit IRC | 03:08 | |
*** devlaps has joined #openstack-keystone | 03:30 | |
*** devlaps has quit IRC | 03:35 | |
*** devlaps has joined #openstack-keystone | 04:01 | |
*** devlaps has quit IRC | 04:05 | |
*** daneyon has joined #openstack-keystone | 04:38 | |
*** daneyon has quit IRC | 04:45 | |
*** devlaps has joined #openstack-keystone | 05:01 | |
*** nkinder has quit IRC | 05:03 | |
*** devlaps has quit IRC | 05:05 | |
*** devlaps has joined #openstack-keystone | 06:01 | |
*** thedodd has joined #openstack-keystone | 06:02 | |
openstackgerrit | Jenkins proposed a change to openstack/keystone: Imported Translations from Transifex https://review.openstack.org/78525 | 06:02 |
*** devlaps has quit IRC | 06:05 | |
*** thedodd has quit IRC | 06:20 | |
*** thedodd has joined #openstack-keystone | 06:39 | |
*** thedodd has quit IRC | 06:47 | |
*** arosen2 has quit IRC | 06:50 | |
*** arosen1 has joined #openstack-keystone | 06:51 | |
*** arosen1 has quit IRC | 07:00 | |
*** devlaps has joined #openstack-keystone | 07:01 | |
*** arosen1 has joined #openstack-keystone | 07:01 | |
*** devlaps has quit IRC | 07:05 | |
*** zhiyan_ is now known as zhiyan | 07:18 | |
*** devlaps has joined #openstack-keystone | 08:01 | |
*** devlaps has quit IRC | 08:05 | |
*** devlaps has joined #openstack-keystone | 09:01 | |
*** devlaps has quit IRC | 09:05 | |
*** flaper87|afk is now known as flaper87 | 09:10 | |
*** YorikSar has quit IRC | 09:13 | |
*** YorikSar has joined #openstack-keystone | 09:15 | |
*** morganfainberg is now known as morganfainberg_Z | 09:58 | |
*** devlaps has joined #openstack-keystone | 10:01 | |
*** david_lyle_ has joined #openstack-keystone | 10:04 | |
*** devlaps has quit IRC | 10:05 | |
*** david-lyle has quit IRC | 10:07 | |
*** leseb has joined #openstack-keystone | 10:18 | |
*** huats_ has joined #openstack-keystone | 10:48 | |
*** huats has quit IRC | 10:53 | |
*** harlowja_away has quit IRC | 10:54 | |
*** marekd|away has quit IRC | 10:54 | |
*** marekd|away has joined #openstack-keystone | 10:54 | |
*** devlaps has joined #openstack-keystone | 11:01 | |
*** devlaps has quit IRC | 11:06 | |
*** Daviey_ has joined #openstack-keystone | 11:28 | |
*** marekd|away has quit IRC | 11:29 | |
*** bknudson has quit IRC | 11:29 | |
*** lbragstad has quit IRC | 11:29 | |
*** zhiyan has quit IRC | 11:29 | |
*** Daviey has quit IRC | 11:29 | |
*** sudorandom has quit IRC | 11:29 | |
*** chmouel has quit IRC | 11:29 | |
*** Daviey_ is now known as Daviey | 11:29 | |
*** arosen1 has quit IRC | 11:33 | |
*** chmouel has joined #openstack-keystone | 11:36 | |
*** sudorandom has joined #openstack-keystone | 11:45 | |
*** marekd|away has joined #openstack-keystone | 11:45 | |
*** bknudson has joined #openstack-keystone | 11:45 | |
*** lbragstad has joined #openstack-keystone | 11:45 | |
*** zhiyan has joined #openstack-keystone | 11:45 | |
*** devlaps has joined #openstack-keystone | 12:01 | |
*** devlaps has quit IRC | 12:05 | |
openstackgerrit | David Stanek proposed a change to openstack/keystone: Use assertIsNone when comparing against None https://review.openstack.org/78118 | 12:11 |
openstackgerrit | David Stanek proposed a change to openstack/keystone: Adds style checks to ease reviewer burden https://review.openstack.org/78119 | 12:11 |
openstackgerrit | David Stanek proposed a change to openstack/keystone: Add a space after the hash for block comments https://review.openstack.org/78116 | 12:11 |
openstackgerrit | David Stanek proposed a change to openstack/keystone: Removes the use of mutables as default args https://review.openstack.org/78117 | 12:11 |
*** leseb_ has joined #openstack-keystone | 12:17 | |
*** leseb has quit IRC | 12:18 | |
*** jamielennox|away has quit IRC | 12:21 | |
*** jamielenz has joined #openstack-keystone | 12:28 | |
*** jamielenz has quit IRC | 12:32 | |
*** jamielennox|away has joined #openstack-keystone | 12:36 | |
*** zhiyan is now known as zhiyan_ | 12:46 | |
*** devlaps has joined #openstack-keystone | 13:01 | |
*** devlaps has quit IRC | 13:05 | |
*** lbragstad1 has joined #openstack-keystone | 13:15 | |
*** lbragstad has quit IRC | 13:22 | |
*** zhiyan_ has quit IRC | 13:22 | |
*** sudorandom has quit IRC | 13:22 | |
*** sudorandom has joined #openstack-keystone | 13:22 | |
*** zhiyan_ has joined #openstack-keystone | 13:24 | |
*** devlaps has joined #openstack-keystone | 14:01 | |
*** devlaps has quit IRC | 14:05 | |
*** leseb_ has quit IRC | 14:14 | |
*** wchrisj has joined #openstack-keystone | 14:31 | |
dstanek | dolphm, bknudson: https://review.openstack.org/#/c/80946 looks good to me. is this something we should not +A until after we release? | 14:39 |
dolphm | dstanek: i'm happy to have it in icehouse | 14:41 |
dstanek | dolphm: sounds good - i'll change my +1 to a +2 | 14:42 |
dstanek | dolphm: is your services patch good to go? i fixed some pep8 issues, but i noticed you had it as WIP | 14:42 |
*** david_lyle_ has quit IRC | 14:48 | |
dolphm | dstanek: no - it's got legit test failures i think | 14:50 |
dolphm | dstanek: i was trying to do in one patch what bknudson did in 3 or 4... i think i made a mess of it | 14:50 |
bknudson | it's easy to make a mess out of multiple patches too | 14:51 |
bknudson | what do you think about changing devstack to not set keystone config file readable only by the user? | 14:52 |
bknudson | i.e., would be 644 | 14:52 |
dolphm | bknudson: why? | 14:53 |
bknudson | as it is, we can't write a tempest test that does 'keystone-manage db_version' | 14:53 |
bknudson | and that command has broken a couple of times lately | 14:53 |
bknudson | there are tests for the nova-manage command already... we haven't had any for keystone-manage | 14:54 |
bknudson | I tried writing one and it fails because it can't find the config file, probably because it doesn't have access | 14:55 |
*** leseb has joined #openstack-keystone | 14:55 | |
dolphm | bknudson: but tempest isn't guaranteed to be on the same box as keystone anyway -- are there other tests that make that assumption? | 14:57 |
bknudson | dolphm: I think in that case you would disable the tests, there's a config CONF.cli.has_manage | 14:58 |
bknudson | http://git.openstack.org/cgit/openstack/tempest/tree/tempest/cli/simple_read_only/test_nova_manage.py#n44 | 14:59 |
dolphm | bknudson: are there other keystone-manage tests then? | 14:59 |
bknudson | dolphm: there are no existing keystone-manage tests | 14:59 |
dolphm | hmm | 14:59 |
bknudson | there's a lot of keystone functionality that's not covered by tempest | 14:59 |
dolphm | bknudson: how is that tested for nova then? they're conf should be 0600 too | 14:59 |
dolphm | their* | 15:00 |
bknudson | dolphm: their conf is not 0600. | 15:00 |
dolphm | bknudson: what is it? | 15:00 |
bknudson | -rw-r--r-- 1 bknudson bknudson 2679 Mar 21 09:56 /etc/nova/nova.conf | 15:00 |
bknudson | -rw------- 1 bknudson bknudson 38819 Mar 22 11:57 /etc/keystone/keystone.conf | 15:00 |
dolphm | bknudson: hmm, well considering it's devstack... link me to the review and i'll +1 :) | 15:01 |
*** devlaps has joined #openstack-keystone | 15:01 | |
dolphm | bknudson: i'd definitely cite nova's precedence in the commit message | 15:01 |
bknudson | ok, will propose the change | 15:01 |
*** devlaps has quit IRC | 15:05 | |
*** leseb has quit IRC | 15:07 | |
*** leseb has joined #openstack-keystone | 15:09 | |
bknudson | dolphm: https://review.openstack.org/#/c/82358/ | 15:10 |
dolphm | bknudson: +1 | 15:20 |
dolphm | bknudson: i assume the tempest user can't "sudo -u keystone keystone-manage" either, right? | 15:21 |
bknudson | dolphm: I haven't tried it. I hope not. | 15:22 |
bknudson | I hope the tempest user can't rm -rf / | 15:22 |
dolphm | bknudson: why do you hope not? | 15:22 |
*** packet has joined #openstack-keystone | 15:22 | |
*** packet has quit IRC | 15:24 | |
bknudson | I'm afraid that I'd break tempest if I try to sudo -- doesn't it prompt for input? | 15:25 |
dolphm | bknudson: it's worth a shot IMO -- if it can sudo, hopefully it's passwordless | 15:31 |
bknudson | dolphm: ok, we'll see what happens: https://review.openstack.org/#/c/82309/ | 15:40 |
openstackgerrit | A change was merged to openstack/keystone: Filter SAML2 assertion parameters with certain prefix. https://review.openstack.org/80946 | 15:45 |
*** leseb has joined #openstack-keystone | 15:47 | |
*** leseb has quit IRC | 15:51 | |
marekd|away | dolphm: dstanek bknudson : ^^ yay, thanks! | 15:56 |
dolphm | marekd|away: ++ | 15:57 |
dstanek | marekd|away: you did the hard part | 15:57 |
marekd|away | dstanek: thanks! | 15:57 |
*** marekd|away is now known as marekd | 15:58 | |
*** devlaps has joined #openstack-keystone | 16:01 | |
marekd | dolphm: there is one last thing i need to address: another endpoint to be specified in the apache virtualhost configuration. But my concern is I still don't know whether we can send normal auth JSON query. I would rather opt for something like: https://github.com/zaccone/keystone/blob/federated-apache/keystone/auth/routers.py#L41 and https://github.com/zaccone/keystone/blob/federated-apache/keystone/auth/controllers.py#L309 | 16:04 |
dolphm | marekd: it's *REALLY* late to be making proposals like this now -- if you need to make that change, PLEASE get it into review ASAP | 16:05 |
*** devlaps has quit IRC | 16:05 | |
marekd | dolphm: ok, working. | 16:08 |
*** wchrisj has quit IRC | 16:11 | |
openstackgerrit | A change was merged to openstack/python-keystoneclient: Don't use a connection pool unless provided https://review.openstack.org/82007 | 16:17 |
*** devlaps has joined #openstack-keystone | 16:21 | |
*** devlaps has quit IRC | 16:26 | |
*** thedodd has joined #openstack-keystone | 16:36 | |
*** leseb has joined #openstack-keystone | 16:48 | |
*** leseb has quit IRC | 16:53 | |
*** YorikSar has quit IRC | 16:56 | |
openstackgerrit | Brant Knudson proposed a change to openstack/keystone: Fix doc build errors with SQLAlchemy 0.9 https://review.openstack.org/82367 | 16:57 |
*** YorikSar has joined #openstack-keystone | 16:58 | |
openstackgerrit | Brant Knudson proposed a change to openstack/keystone: Fix doc build errors with SQLAlchemy 0.9 https://review.openstack.org/82367 | 17:07 |
*** YorikSar has quit IRC | 17:13 | |
openstackgerrit | Brant Knudson proposed a change to openstack/keystone: Updated from global requirements https://review.openstack.org/82372 | 17:14 |
*** YorikSar has joined #openstack-keystone | 17:25 | |
*** shakamunyi has joined #openstack-keystone | 17:26 | |
*** arosen1 has joined #openstack-keystone | 17:31 | |
*** shakamunyi has quit IRC | 17:36 | |
*** shakamunyi has joined #openstack-keystone | 17:39 | |
*** leseb has joined #openstack-keystone | 17:49 | |
*** shakamunyi has quit IRC | 17:51 | |
*** leseb has quit IRC | 17:53 | |
*** shakamunyi has joined #openstack-keystone | 18:06 | |
openstackgerrit | Marek Denis proposed a change to openstack/keystone: Add dedicated URL for issuing unscoped federation tokens. https://review.openstack.org/82375 | 18:12 |
marekd | dolphm: bknudson : ^^ | 18:13 |
*** marekd is now known as marekd|away | 18:14 | |
*** shakamunyi has quit IRC | 18:43 | |
*** leseb has joined #openstack-keystone | 18:50 | |
*** leseb has quit IRC | 18:55 | |
*** leseb has joined #openstack-keystone | 19:51 | |
*** leseb has quit IRC | 19:52 | |
*** leseb has joined #openstack-keystone | 19:53 | |
*** leseb has quit IRC | 19:57 | |
*** thedodd has quit IRC | 20:12 | |
*** leseb has joined #openstack-keystone | 20:21 | |
*** arosen1 has quit IRC | 20:24 | |
*** arosen1 has joined #openstack-keystone | 20:38 | |
*** devlaps has joined #openstack-keystone | 21:38 | |
openstackgerrit | Brant Knudson proposed a change to openstack/keystone: Reduce environment logging https://review.openstack.org/82391 | 22:50 |
openstackgerrit | Brant Knudson proposed a change to openstack/keystone: Cleaner LDAP debug logging https://review.openstack.org/82395 | 22:59 |
openstackgerrit | David Stanek proposed a change to openstack/keystone: Always include 'enabled' field in service response https://review.openstack.org/82205 | 23:01 |
*** leseb has quit IRC | 23:02 | |
*** devlaps has quit IRC | 23:03 | |
openstackgerrit | John Dennis proposed a change to openstack/keystone: code hygiene; use six.text_type, escape regexp's, use key function https://review.openstack.org/82396 | 23:05 |
openstackgerrit | John Dennis proposed a change to openstack/keystone: Refactor LDAP API https://review.openstack.org/82397 | 23:05 |
openstackgerrit | John Dennis proposed a change to openstack/keystone: Properly handle unicode & utf-8 in LDAP https://review.openstack.org/82398 | 23:05 |
openstackgerrit | John Dennis proposed a change to openstack/keystone: Expand the use of non-ascii values in ldap test https://review.openstack.org/82399 | 23:05 |
*** jamielennox|away is now known as jamielennox | 23:08 | |
openstackgerrit | Brant Knudson proposed a change to openstack/keystone: Filter out uninteresting log messages https://review.openstack.org/82402 | 23:13 |
*** leseb has joined #openstack-keystone | 23:21 | |
*** flaper87 is now known as flaper87|afk | 23:21 | |
*** leseb has quit IRC | 23:27 | |
openstackgerrit | Brant Knudson proposed a change to openstack/keystone: Cleanup revocation query https://review.openstack.org/82403 | 23:28 |
*** nkinder has joined #openstack-keystone | 23:42 | |
openstackgerrit | Jamie Lennox proposed a change to openstack/python-keystoneclient: Add a positional decorator https://review.openstack.org/77026 | 23:52 |
openstackgerrit | Jamie Lennox proposed a change to openstack/python-keystoneclient: Start using positional decorator https://review.openstack.org/77055 | 23:52 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!