*** nellysmitt has joined #openstack-keystone | 00:04 | |
*** nellysmitt has quit IRC | 00:08 | |
*** henrynash has quit IRC | 00:09 | |
*** henrynash has joined #openstack-keystone | 00:09 | |
*** ChanServ sets mode: +v henrynash | 00:09 | |
*** tellesnobrega_ has quit IRC | 00:52 | |
*** tellesnobrega_ has joined #openstack-keystone | 00:58 | |
*** lhcheng has quit IRC | 00:58 | |
*** lhcheng has joined #openstack-keystone | 00:59 | |
*** lhcheng has quit IRC | 01:04 | |
*** htruta_ has joined #openstack-keystone | 01:12 | |
*** stevemar has joined #openstack-keystone | 01:29 | |
*** ChanServ sets mode: +v stevemar | 01:29 | |
*** _cjones_ has quit IRC | 01:39 | |
*** _cjones_ has joined #openstack-keystone | 01:42 | |
*** _cjones_ has quit IRC | 01:44 | |
*** NM has joined #openstack-keystone | 01:53 | |
*** NM has quit IRC | 01:59 | |
*** nellysmitt has joined #openstack-keystone | 02:05 | |
*** nellysmitt has quit IRC | 02:09 | |
*** sluo_wfh has joined #openstack-keystone | 02:17 | |
*** erkules_ has joined #openstack-keystone | 02:25 | |
*** erkules has quit IRC | 02:27 | |
*** r-daneel has quit IRC | 02:32 | |
*** r-daneel has joined #openstack-keystone | 02:33 | |
*** htruta_ has quit IRC | 02:41 | |
*** dims has quit IRC | 02:47 | |
*** r-daneel has quit IRC | 02:51 | |
*** henrynash has quit IRC | 03:16 | |
*** samuelms_ has quit IRC | 03:16 | |
*** henrynash has joined #openstack-keystone | 03:17 | |
*** ChanServ sets mode: +v henrynash | 03:17 | |
*** NM has joined #openstack-keystone | 03:23 | |
*** kobtea has joined #openstack-keystone | 03:25 | |
*** kobtea has quit IRC | 03:29 | |
*** david-ly_ has joined #openstack-keystone | 03:35 | |
*** david-lyle_afk has quit IRC | 03:37 | |
*** ayoung has quit IRC | 03:37 | |
*** NM has quit IRC | 03:39 | |
*** nellysmitt has joined #openstack-keystone | 04:05 | |
*** nellysmitt has quit IRC | 04:10 | |
*** yasu_ has joined #openstack-keystone | 04:15 | |
*** yasu_ has quit IRC | 04:43 | |
*** KanagarajM has joined #openstack-keystone | 04:52 | |
*** tellesnobrega_ has quit IRC | 05:07 | |
*** henrynash has quit IRC | 05:08 | |
*** tellesnobrega_ has joined #openstack-keystone | 05:08 | |
*** henrynash has joined #openstack-keystone | 05:09 | |
*** ChanServ sets mode: +v henrynash | 05:09 | |
*** _cjones_ has joined #openstack-keystone | 05:13 | |
*** _cjones_ has quit IRC | 05:13 | |
*** kobtea has joined #openstack-keystone | 05:14 | |
*** kobtea has quit IRC | 05:18 | |
*** mitz_ has quit IRC | 05:41 | |
*** ajayaa has joined #openstack-keystone | 05:42 | |
*** mitz_ has joined #openstack-keystone | 05:44 | |
*** dims has joined #openstack-keystone | 05:48 | |
*** dims has quit IRC | 05:52 | |
*** yasu_ has joined #openstack-keystone | 05:54 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Imported Translations from Transifex https://review.openstack.org/136243 | 06:02 |
---|---|---|
*** nellysmitt has joined #openstack-keystone | 06:06 | |
henrynash | samuelms: We have, in the past, used the term “effective” for what you get after expansion (it’s what the ?option is for the REST API), so I’d be tempted to go for list_effective_assignments_for_user_and_project | 06:11 |
*** nellysmitt has quit IRC | 06:11 | |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Turn our auth plugin into a token interface https://review.openstack.org/137268 | 06:12 |
*** oomichi has quit IRC | 06:32 | |
*** mzbik has joined #openstack-keystone | 06:38 | |
*** k4n0 has joined #openstack-keystone | 07:00 | |
*** kobtea has joined #openstack-keystone | 07:02 | |
*** kobtea has quit IRC | 07:07 | |
*** ukalifon1 has joined #openstack-keystone | 07:07 | |
openstackgerrit | jun xie proposed openstack/keystone: Fix the copy-pasted help info for db_version https://review.openstack.org/137729 | 07:23 |
*** ukalifon1 has quit IRC | 07:31 | |
*** oomichi_ has joined #openstack-keystone | 07:42 | |
*** oomichi_ has quit IRC | 07:44 | |
*** stevemar has quit IRC | 07:44 | |
*** ukalifon has joined #openstack-keystone | 07:51 | |
*** nellysmitt has joined #openstack-keystone | 08:07 | |
*** nellysmitt has quit IRC | 08:12 | |
openstackgerrit | Sergey Kraynev proposed openstack/python-keystoneclient: Using correct keyword for region in v3 https://review.openstack.org/118383 | 08:12 |
*** yasu_ has quit IRC | 08:14 | |
*** _cjones_ has joined #openstack-keystone | 08:14 | |
*** _cjones_ has quit IRC | 08:19 | |
*** yasu_ has joined #openstack-keystone | 08:20 | |
*** jistr has joined #openstack-keystone | 08:22 | |
*** oomichi_ has joined #openstack-keystone | 08:24 | |
*** ukalifon has quit IRC | 08:25 | |
*** erkules_ is now known as erkules | 08:29 | |
*** k4n0 has quit IRC | 08:56 | |
*** oomichi_ has quit IRC | 09:22 | |
*** eglynn-officeafk is now known as eglynn-office | 09:22 | |
*** nellysmitt has joined #openstack-keystone | 09:35 | |
*** f13o has quit IRC | 09:36 | |
*** jamielennox is now known as jamielennox|away | 10:05 | |
*** jistr has quit IRC | 10:11 | |
*** sluo_wfh has quit IRC | 10:12 | |
josecastroleon | jamielennox: are you around? | 10:31 |
josecastroleon | i have a very nice bug (kerberos related) | 10:32 |
josecastroleon | let's say: non desired behavior | 10:33 |
*** jistr has joined #openstack-keystone | 10:34 | |
samuelms | henrynash, yep I know that terminology .. but how could we call the set before the expansion? | 10:46 |
samuelms | henrynash, morning :-) | 10:46 |
samuelms | henrynash, anyway.. I'll reorganize the code such way we have no need to a new terminology .. this will mess up people's brains | 10:50 |
*** henrynash has quit IRC | 10:51 | |
*** henrynash has joined #openstack-keystone | 10:52 | |
*** ChanServ sets mode: +v henrynash | 10:52 | |
*** tellesnobrega_ has quit IRC | 11:01 | |
*** KanagarajM has quit IRC | 11:04 | |
*** aix has joined #openstack-keystone | 11:08 | |
*** NM has joined #openstack-keystone | 11:12 | |
*** henrynash has quit IRC | 11:19 | |
*** NM has quit IRC | 11:35 | |
*** kobtea has joined #openstack-keystone | 11:40 | |
*** yasu_ has quit IRC | 11:43 | |
*** kobtea has quit IRC | 11:45 | |
*** NM has joined #openstack-keystone | 11:48 | |
*** yasu_ has joined #openstack-keystone | 11:54 | |
*** NM has quit IRC | 11:55 | |
*** diegows has joined #openstack-keystone | 12:01 | |
openstackgerrit | Ilya Pekelny proposed openstack/keystone: Migrate_repo init version helper https://review.openstack.org/137640 | 12:24 |
openstackgerrit | Ilya Pekelny proposed openstack/keystone: Add primary key to the endpoint_group id column. https://review.openstack.org/137638 | 12:24 |
openstackgerrit | Ilya Pekelny proposed openstack/keystone: Add index to the revocation_event.revoked_at. https://review.openstack.org/137639 | 12:24 |
openstackgerrit | Ilya Pekelny proposed openstack/keystone: Comparision of database models and migrations. https://review.openstack.org/80630 | 12:24 |
openstackgerrit | Ilya Pekelny proposed openstack/keystone: Share engine between migration helpers. https://review.openstack.org/137778 | 12:24 |
openstackgerrit | Ilya Pekelny proposed openstack/keystone: Use metadata.create_all() to fill a test database https://review.openstack.org/93558 | 12:25 |
*** NM has joined #openstack-keystone | 12:29 | |
*** yasu_ has quit IRC | 12:33 | |
*** ukalifon1 has joined #openstack-keystone | 12:35 | |
*** afazekas has joined #openstack-keystone | 12:48 | |
*** NM has quit IRC | 12:48 | |
*** ajayaa has quit IRC | 12:51 | |
*** eglynn-office is now known as eglynn-lunch | 12:54 | |
*** NM has joined #openstack-keystone | 12:54 | |
*** ukalifon1 has quit IRC | 13:00 | |
*** mzbik has quit IRC | 13:01 | |
openstackgerrit | Sergey Kraynev proposed openstack/python-keystoneclient: Using correct keyword for region in v3 https://review.openstack.org/118383 | 13:02 |
*** NM has quit IRC | 13:04 | |
*** mzbik has joined #openstack-keystone | 13:06 | |
*** boris-42 has quit IRC | 13:17 | |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone-specs: API doc for Inherited Role Assignments to Projects https://review.openstack.org/130277 | 13:18 |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone-specs: Fixes HEAD return code for OS-INHERIT extension https://review.openstack.org/137782 | 13:18 |
*** NM has joined #openstack-keystone | 13:19 | |
*** mzbik_ has joined #openstack-keystone | 13:21 | |
*** NM has quit IRC | 13:24 | |
*** mzbik has quit IRC | 13:24 | |
openstackgerrit | Andre Aranha proposed openstack/keystone-specs: Modify the policy file https://review.openstack.org/135408 | 13:28 |
*** dims has joined #openstack-keystone | 13:41 | |
openstackgerrit | Andre Aranha proposed openstack/keystone-specs: Modify the policy file https://review.openstack.org/135408 | 13:45 |
*** eglynn-lunch is now known as eglynn-office | 13:46 | |
*** henrynash has joined #openstack-keystone | 13:46 | |
*** ChanServ sets mode: +v henrynash | 13:46 | |
*** NM has joined #openstack-keystone | 13:53 | |
openstackgerrit | Merged openstack/keystonemiddleware: Updated from global requirements https://review.openstack.org/135965 | 14:01 |
openstackgerrit | Merged openstack/keystone: Updated from global requirements https://review.openstack.org/136616 | 14:02 |
eglynn-office | quick question anyone? | 14:04 |
eglynn-office | prior to the advent of domains, am I right in assuming that the admin role is intended to a global thing? | 14:04 |
eglynn-office | say user 'bob' has the admin role in the project 'dev', but not in the project 'finance' | 14:05 |
eglynn-office | should bob be able to apply administrative actions to resources associated with the 'finance' tenant? | 14:06 |
rodrigods | eglynn-office, no | 14:06 |
rodrigods | eglynn-office, bob would need a role in 'finance' tenant as well | 14:07 |
eglynn-office | rodrigods: so how do typical RBAC rules of form "role:admin" capture that distinction between "having the admin role" and "having the admin role in a particular project"? | 14:09 |
eglynn-office | rodrigods: e.g. https://github.com/openstack/nova/blob/master/etc/nova/policy.json#L27 | 14:12 |
*** gordc has joined #openstack-keystone | 14:13 | |
eglynn-office | rodrigods: I always thought that meant "a caller can stop a server if they own the server *or* have the admin role in the user/project associated with the call" | 14:13 |
*** gordc has joined #openstack-keystone | 14:13 | |
eglynn-office | (even if that project is different to the tenant associated with the server) | 14:14 |
*** NM has quit IRC | 14:16 | |
eglynn-office | rodrigods: this bug seems to line up with my original understanding of admin-ness being global ... https://bugs.launchpad.net/keystone/+bug/968696 | 14:30 |
uvirtbot | Launchpad bug 968696 in keystone ""admin"-ness not properly scoped" [High,Confirmed] | 14:30 |
*** ajayaa has joined #openstack-keystone | 14:34 | |
rodrigods | eglynn-office, it checks the role against your token scope | 14:34 |
*** NM has joined #openstack-keystone | 14:36 | |
eglynn-office | rodrigods: "it" being the policy enforcer? | 14:37 |
rodrigods | eglynn-office, yes | 14:39 |
*** NM has quit IRC | 14:39 | |
*** diegows has quit IRC | 14:41 | |
rodrigods | eglynn-office, actually... if the rule is just "role:admin", you need only the admin role to be listed in your token | 14:42 |
rodrigods | eglynn-office, to enforce by project, you need a rule like: https://github.com/openstack/keystone/blob/master/etc/policy.v3cloudsample.json#L37 | 14:43 |
rodrigods | eglynn-office, you are right by considering the admin-ess as being global for the default policy.json (v2) | 14:43 |
*** kobtea has joined #openstack-keystone | 14:45 | |
eglynn-office | rodrigods: a-ha, thanks for the confirmation | 14:46 |
eglynn-office | rodrigods: ... so in "domain_id:%(target.project.domain_id)s" is target.project.domain_id=="the domain containing the project associated with the target resource"? | 14:46 |
rodrigods | eglynn-office, exactly! :) | 14:48 |
openstackgerrit | Boris Bobrov proposed openstack/python-keystoneclient: Add self-installation to venv deployment https://review.openstack.org/137613 | 14:48 |
*** kobtea has quit IRC | 14:50 | |
rodrigods | eglynn-office, here you have a good explanation about how you use different rules: https://review.openstack.org/#/c/137476/2/openstack/common/policy.py | 14:50 |
eglynn-office | rodrigods: a-ha, thank you sir! | 14:54 |
*** diegows has joined #openstack-keystone | 14:57 | |
*** stevemar has joined #openstack-keystone | 15:02 | |
*** ChanServ sets mode: +v stevemar | 15:02 | |
*** marekd is now known as marekd|away | 15:02 | |
*** samuelms is now known as samuelms-away | 15:34 | |
*** r-daneel has joined #openstack-keystone | 15:41 | |
*** mzbik_ has quit IRC | 15:44 | |
*** mflobo has quit IRC | 15:58 | |
*** thiagop has quit IRC | 16:00 | |
*** nellysmitt has quit IRC | 16:04 | |
*** dims has quit IRC | 16:07 | |
*** _cjones_ has joined #openstack-keystone | 16:08 | |
*** josecastroleon has quit IRC | 16:08 | |
*** mitz- has joined #openstack-keystone | 16:10 | |
*** mitz_ has quit IRC | 16:10 | |
*** stevemar has quit IRC | 16:13 | |
*** stevemar has joined #openstack-keystone | 16:14 | |
*** ChanServ sets mode: +v stevemar | 16:14 | |
openstackgerrit | Andre Aranha proposed openstack/keystone: Make the policy v3 as default https://review.openstack.org/137828 | 16:23 |
*** NM has joined #openstack-keystone | 16:27 | |
*** shakamunyi has joined #openstack-keystone | 16:30 | |
*** shakamunyi has quit IRC | 16:31 | |
*** kobtea has joined #openstack-keystone | 16:34 | |
*** shakamunyi has joined #openstack-keystone | 16:34 | |
openstackgerrit | Ilya Pekelny proposed openstack/keystone: Migrate_repo init version helper https://review.openstack.org/137640 | 16:38 |
openstackgerrit | Ilya Pekelny proposed openstack/keystone: Share engine between migration helpers. https://review.openstack.org/137778 | 16:38 |
openstackgerrit | Ilya Pekelny proposed openstack/keystone: Add primary key to the endpoint_group id column. https://review.openstack.org/137638 | 16:38 |
openstackgerrit | Ilya Pekelny proposed openstack/keystone: Add index to the revocation_event.revoked_at. https://review.openstack.org/137639 | 16:38 |
openstackgerrit | Ilya Pekelny proposed openstack/keystone: Comparision of database models and migrations. https://review.openstack.org/80630 | 16:38 |
*** kobtea has quit IRC | 16:38 | |
openstackgerrit | Ilya Pekelny proposed openstack/keystone: Use metadata.create_all() to fill a test database https://review.openstack.org/93558 | 16:38 |
*** nellysmitt has joined #openstack-keystone | 16:45 | |
*** afazekas has quit IRC | 17:00 | |
*** ajayaa has quit IRC | 17:03 | |
*** dims has joined #openstack-keystone | 17:08 | |
*** dims has quit IRC | 17:13 | |
*** Kieleth has quit IRC | 17:15 | |
*** ajayaa has joined #openstack-keystone | 17:16 | |
*** dims has joined #openstack-keystone | 17:18 | |
*** dims has quit IRC | 17:21 | |
*** shakayumi has joined #openstack-keystone | 17:21 | |
openstackgerrit | henry-nash proposed openstack/keystone-specs: Add support for domain specific roles. https://review.openstack.org/133855 | 17:23 |
*** shakamunyi has quit IRC | 17:25 | |
*** dims has joined #openstack-keystone | 17:30 | |
*** dims has quit IRC | 17:34 | |
openstackgerrit | henry-nash proposed openstack/keystone-specs: Replace the concept of extensions in Keystone. https://review.openstack.org/133809 | 17:38 |
*** jistr has quit IRC | 17:53 | |
*** _cjones_ has quit IRC | 18:02 | |
*** _cjones_ has joined #openstack-keystone | 18:08 | |
*** boris-42 has joined #openstack-keystone | 18:09 | |
openstackgerrit | henry-nash proposed openstack/keystone-specs: Add support for domain specific roles. https://review.openstack.org/133855 | 18:14 |
*** eglynn-office is now known as eglynn-officeafk | 18:30 | |
*** Guest68123 has joined #openstack-keystone | 18:31 | |
*** NM has quit IRC | 18:36 | |
*** Guest68123 has quit IRC | 18:37 | |
*** nellysmitt has quit IRC | 18:44 | |
openstackgerrit | henry-nash proposed openstack/keystone-specs: Add support for domain specific roles. https://review.openstack.org/133855 | 18:49 |
*** harlowja_away is now known as harlowja_ | 18:57 | |
*** aix has quit IRC | 18:58 | |
*** ajayaa has quit IRC | 19:01 | |
*** dims has joined #openstack-keystone | 19:13 | |
*** dims has quit IRC | 19:18 | |
*** ajayaa has joined #openstack-keystone | 19:23 | |
*** NM has joined #openstack-keystone | 19:35 | |
*** NM has quit IRC | 19:44 | |
*** zzzeek has joined #openstack-keystone | 19:44 | |
*** _cjones_ has quit IRC | 19:49 | |
*** kobtea has joined #openstack-keystone | 20:11 | |
*** kobtea has quit IRC | 20:16 | |
*** NM has joined #openstack-keystone | 20:29 | |
*** NM has quit IRC | 20:32 | |
*** boris-42 has quit IRC | 20:37 | |
*** nellysmitt has joined #openstack-keystone | 20:45 | |
*** pc-m has quit IRC | 20:45 | |
*** nellysmitt has quit IRC | 20:49 | |
*** _cjones_ has joined #openstack-keystone | 20:49 | |
*** boris-42 has joined #openstack-keystone | 20:49 | |
*** nellysmitt has joined #openstack-keystone | 20:52 | |
*** nellysmitt has quit IRC | 20:57 | |
*** nellysmitt has joined #openstack-keystone | 20:59 | |
*** nellysmitt has quit IRC | 21:00 | |
*** raildo has quit IRC | 21:00 | |
*** _cjones_ has quit IRC | 21:05 | |
*** _cjones_ has joined #openstack-keystone | 21:23 | |
*** NM has joined #openstack-keystone | 21:24 | |
*** NM has quit IRC | 21:34 | |
*** NM has joined #openstack-keystone | 21:40 | |
*** NM has quit IRC | 21:44 | |
*** dims has joined #openstack-keystone | 22:18 | |
*** harlowja_ is now known as harlowja_away | 22:21 | |
*** jamielennox|away is now known as jamielennox | 22:22 | |
*** dims has quit IRC | 22:23 | |
*** stevemar has quit IRC | 22:30 | |
*** _cjones_ has quit IRC | 22:34 | |
*** tellesnobrega_ has joined #openstack-keystone | 22:37 | |
*** tellesnobrega_ has quit IRC | 22:40 | |
*** _cjones_ has joined #openstack-keystone | 22:42 | |
*** boris-42 has quit IRC | 22:57 | |
openstackgerrit | Jamie Lennox proposed openstack/python-keystoneclient: Add wrapper plugins https://review.openstack.org/137864 | 23:14 |
*** gordc has quit IRC | 23:19 | |
*** kobtea has joined #openstack-keystone | 23:48 | |
*** openstackstatus has quit IRC | 23:53 | |
*** openstack has joined #openstack-keystone | 23:53 | |
*** openstackstatus has joined #openstack-keystone | 23:54 | |
*** ChanServ sets mode: +v openstackstatus | 23:54 | |
*** kobtea has quit IRC | 23:54 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!