*** markvoelker has joined #openstack-keystone | 00:00 | |
*** markvoelker has quit IRC | 00:04 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Restricting domain_id changing https://review.openstack.org/207218 | 00:09 |
---|---|---|
openstackgerrit | Merged openstack/keystoneauth: Set reasonable defaults for TCP Keep-Alive https://review.openstack.org/205276 | 00:20 |
*** ayoung has quit IRC | 01:23 | |
*** dimsum__ has quit IRC | 01:24 | |
*** jack_ has joined #openstack-keystone | 01:36 | |
*** dimsum__ has joined #openstack-keystone | 01:53 | |
*** topol has joined #openstack-keystone | 01:57 | |
*** ChanServ sets mode: +v topol | 01:57 | |
*** markvoelker has joined #openstack-keystone | 02:01 | |
*** dimsum__ has quit IRC | 02:04 | |
*** markvoelker has quit IRC | 02:05 | |
*** jack_ has quit IRC | 02:46 | |
*** hakimo has joined #openstack-keystone | 02:52 | |
*** hakimo_ has quit IRC | 02:54 | |
*** archers has joined #openstack-keystone | 02:58 | |
*** markvoelker has joined #openstack-keystone | 03:16 | |
*** markvoelker has quit IRC | 03:21 | |
*** jamielennox|away is now known as jamielennox | 03:38 | |
*** archers has quit IRC | 03:44 | |
*** geoffarnold has quit IRC | 04:12 | |
*** geoffarnold has joined #openstack-keystone | 04:13 | |
*** topol has quit IRC | 04:14 | |
*** jamielennox is now known as jamielennox|away | 04:42 | |
*** browne has quit IRC | 04:54 | |
*** jungler has quit IRC | 04:56 | |
*** jungler has joined #openstack-keystone | 04:57 | |
*** ankita_wagh has joined #openstack-keystone | 04:57 | |
*** browne has joined #openstack-keystone | 04:59 | |
*** topol has joined #openstack-keystone | 05:15 | |
*** ChanServ sets mode: +v topol | 05:15 | |
*** markvoelker has joined #openstack-keystone | 05:17 | |
*** topol has quit IRC | 05:19 | |
*** markvoelker has quit IRC | 05:22 | |
*** jiaxi has joined #openstack-keystone | 05:53 | |
*** ankita_wagh has quit IRC | 06:15 | |
*** hrou has quit IRC | 06:20 | |
*** josecastroleon has joined #openstack-keystone | 07:00 | |
*** josecastroleon has quit IRC | 07:02 | |
openstackgerrit | Andrey Pavlov proposed openstack/keystonemiddleware: update to global requirements https://review.openstack.org/208190 | 07:10 |
openstackgerrit | Andrey Pavlov proposed openstack/keystonemiddleware: Adding parse of protocol v4 of AWS auth to ec2_token https://review.openstack.org/205440 | 07:12 |
*** geoffarnold has quit IRC | 07:18 | |
*** markvoelker has joined #openstack-keystone | 07:18 | |
*** geoffarnold has joined #openstack-keystone | 07:18 | |
*** markvoelker has quit IRC | 07:23 | |
*** btully has quit IRC | 07:31 | |
*** btully has joined #openstack-keystone | 07:31 | |
*** browne1 has joined #openstack-keystone | 08:02 | |
*** browne has quit IRC | 08:02 | |
*** henrynash has joined #openstack-keystone | 08:14 | |
*** ChanServ sets mode: +v henrynash | 08:14 | |
*** ankita_wagh has joined #openstack-keystone | 08:27 | |
*** ankita_wagh has quit IRC | 08:27 | |
*** ankita_wagh has joined #openstack-keystone | 08:28 | |
*** ankita_wagh has quit IRC | 08:32 | |
openstackgerrit | henry-nash proposed openstack/keystone: Improve List Role Assignments Filters Performance https://review.openstack.org/137202 | 08:46 |
openstackgerrit | henry-nash proposed openstack/keystone: Enable listing of role assignments in a project hierarchy https://review.openstack.org/208152 | 08:47 |
*** henrynash has quit IRC | 09:14 | |
*** markvoelker has joined #openstack-keystone | 09:19 | |
*** ankita_wagh has joined #openstack-keystone | 09:19 | |
*** belmoreira has joined #openstack-keystone | 09:21 | |
*** markvoelker has quit IRC | 09:24 | |
*** henrynash has joined #openstack-keystone | 09:37 | |
*** ChanServ sets mode: +v henrynash | 09:37 | |
*** ankita_wagh has quit IRC | 09:40 | |
*** ankita_wagh has joined #openstack-keystone | 09:41 | |
*** henrynash has quit IRC | 09:43 | |
*** ankita_wagh has quit IRC | 09:45 | |
*** rdo has quit IRC | 09:49 | |
*** rdo has joined #openstack-keystone | 09:51 | |
*** henrynash has joined #openstack-keystone | 10:11 | |
*** ChanServ sets mode: +v henrynash | 10:11 | |
*** henrynash has quit IRC | 10:12 | |
*** navid_ has quit IRC | 10:13 | |
*** topol has joined #openstack-keystone | 10:17 | |
*** ChanServ sets mode: +v topol | 10:17 | |
*** markvoelker has joined #openstack-keystone | 10:20 | |
*** topol has quit IRC | 10:21 | |
*** henrynash has joined #openstack-keystone | 10:22 | |
*** ChanServ sets mode: +v henrynash | 10:22 | |
*** navid_ has joined #openstack-keystone | 10:25 | |
*** markvoelker has quit IRC | 10:26 | |
*** henrynash has quit IRC | 10:26 | |
*** henrynash has joined #openstack-keystone | 10:34 | |
*** ChanServ sets mode: +v henrynash | 10:34 | |
*** henrynash has quit IRC | 10:40 | |
*** lhcheng has quit IRC | 11:11 | |
*** marzif_ has joined #openstack-keystone | 11:28 | |
*** dimsum__ has joined #openstack-keystone | 12:43 | |
*** topol has joined #openstack-keystone | 12:47 | |
*** ChanServ sets mode: +v topol | 12:47 | |
*** dimsum__ has quit IRC | 12:50 | |
*** topol has quit IRC | 12:51 | |
*** dimsum__ has joined #openstack-keystone | 12:57 | |
*** markvoelker has joined #openstack-keystone | 13:07 | |
*** topol has joined #openstack-keystone | 13:08 | |
*** ChanServ sets mode: +v topol | 13:08 | |
*** markvoelker has quit IRC | 13:12 | |
*** topol has quit IRC | 13:12 | |
*** jack_ has joined #openstack-keystone | 13:25 | |
*** BrAsS_mOnKeY has quit IRC | 14:18 | |
*** markvoelker has joined #openstack-keystone | 14:38 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Add LimitRequestBody to sample httpd config https://review.openstack.org/208208 | 14:42 |
*** hrou has joined #openstack-keystone | 14:42 | |
*** markvoelker has quit IRC | 14:43 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Remove sizelimit middleware from paste.ini https://review.openstack.org/208209 | 14:47 |
*** jack_ has quit IRC | 15:07 | |
*** piyanai has joined #openstack-keystone | 15:11 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Cleanup use of iteritems https://review.openstack.org/206785 | 15:14 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Use dict.items() rather than six.iteritems() https://review.openstack.org/200762 | 15:14 |
*** piyanai has quit IRC | 15:24 | |
*** topol has joined #openstack-keystone | 15:25 | |
*** ChanServ sets mode: +v topol | 15:25 | |
*** topol has quit IRC | 15:29 | |
*** piyanai has joined #openstack-keystone | 15:39 | |
*** albertom has quit IRC | 15:44 | |
*** htruta has quit IRC | 15:45 | |
*** htruta has joined #openstack-keystone | 15:45 | |
*** albertom has joined #openstack-keystone | 15:46 | |
*** piyanai has quit IRC | 15:50 | |
*** piyanai has joined #openstack-keystone | 15:52 | |
*** piyanai has quit IRC | 15:58 | |
openstackgerrit | Brant Knudson proposed openstack/keystonemiddleware: Docstring updates https://review.openstack.org/208213 | 16:00 |
openstackgerrit | Ghe Rivero proposed openstack/keystone: Create neutron service in sample_data.sh https://review.openstack.org/208215 | 16:04 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Remove oslo import hacking check https://review.openstack.org/208216 | 16:11 |
*** e0ne has joined #openstack-keystone | 16:23 | |
openstackgerrit | Brant Knudson proposed openstack/python-keystoneclient: Remove check for requests version https://review.openstack.org/208217 | 16:25 |
openstackgerrit | Brant Knudson proposed openstack/python-keystoneclient: Clarify setting socket_options https://review.openstack.org/208218 | 16:25 |
*** e0ne has quit IRC | 16:28 | |
*** henrynash has joined #openstack-keystone | 17:09 | |
*** ChanServ sets mode: +v henrynash | 17:09 | |
*** henrynash has quit IRC | 17:13 | |
*** alejandrito has joined #openstack-keystone | 17:30 | |
*** markvoelker has joined #openstack-keystone | 17:40 | |
*** lhcheng has joined #openstack-keystone | 17:43 | |
*** ChanServ sets mode: +v lhcheng | 17:43 | |
*** markvoelker has quit IRC | 17:44 | |
*** ankita_wagh has joined #openstack-keystone | 18:01 | |
*** henrynash has joined #openstack-keystone | 18:03 | |
*** ChanServ sets mode: +v henrynash | 18:03 | |
*** _cjones_ has joined #openstack-keystone | 18:11 | |
*** _cjones_ has quit IRC | 18:15 | |
*** josecastroleon has joined #openstack-keystone | 18:27 | |
*** topol has joined #openstack-keystone | 18:39 | |
*** ChanServ sets mode: +v topol | 18:39 | |
*** hrou has quit IRC | 18:51 | |
*** browne1 has quit IRC | 18:52 | |
*** ankita_wagh has quit IRC | 18:55 | |
*** clayton has quit IRC | 18:56 | |
*** morganfainberg has quit IRC | 18:56 | |
*** gsilvis has quit IRC | 18:56 | |
*** Qlawy has quit IRC | 18:56 | |
*** esp has quit IRC | 18:56 | |
*** kfjohnson has quit IRC | 18:56 | |
*** esp has joined #openstack-keystone | 18:56 | |
*** Qlawy has joined #openstack-keystone | 18:56 | |
*** Qlawy has quit IRC | 18:56 | |
*** Qlawy has joined #openstack-keystone | 18:56 | |
*** gsilvis has joined #openstack-keystone | 18:56 | |
*** morganfainberg has joined #openstack-keystone | 18:56 | |
*** ChanServ sets mode: +v morganfainberg | 18:56 | |
*** kfjohnson has joined #openstack-keystone | 18:56 | |
*** clayton has joined #openstack-keystone | 18:56 | |
*** mylu has joined #openstack-keystone | 18:57 | |
*** freerunner has quit IRC | 19:10 | |
*** notmyname has quit IRC | 19:10 | |
*** SpamapS has quit IRC | 19:10 | |
*** med_ has quit IRC | 19:10 | |
*** breton has quit IRC | 19:10 | |
*** tobasco has quit IRC | 19:10 | |
*** baffle has quit IRC | 19:10 | |
*** larsks has quit IRC | 19:10 | |
*** blogan has quit IRC | 19:10 | |
*** baffle has joined #openstack-keystone | 19:10 | |
*** notmyname has joined #openstack-keystone | 19:10 | |
*** breton has joined #openstack-keystone | 19:10 | |
*** SpamapS has joined #openstack-keystone | 19:10 | |
*** tobasco has joined #openstack-keystone | 19:11 | |
*** larsks has joined #openstack-keystone | 19:11 | |
*** blogan has joined #openstack-keystone | 19:11 | |
*** freerunner has joined #openstack-keystone | 19:11 | |
*** med_ has joined #openstack-keystone | 19:11 | |
*** med_ is now known as Guest5314 | 19:11 | |
*** dimsum__ has quit IRC | 19:14 | |
*** josecastroleon has quit IRC | 19:14 | |
*** rdo has quit IRC | 19:17 | |
*** rdo has joined #openstack-keystone | 19:19 | |
*** browne has joined #openstack-keystone | 19:24 | |
*** lhcheng has quit IRC | 19:31 | |
*** topol has quit IRC | 19:38 | |
*** mylu has quit IRC | 19:39 | |
*** markvoelker has joined #openstack-keystone | 19:40 | |
*** markvoelker has quit IRC | 19:45 | |
*** lhcheng has joined #openstack-keystone | 19:51 | |
*** ChanServ sets mode: +v lhcheng | 19:51 | |
*** afazekas has joined #openstack-keystone | 20:00 | |
*** afazekas has quit IRC | 20:06 | |
*** dimsum__ has joined #openstack-keystone | 20:15 | |
*** dims_ has joined #openstack-keystone | 20:17 | |
*** ankita_wagh has joined #openstack-keystone | 20:20 | |
*** dimsum__ has quit IRC | 20:20 | |
*** afazekas has joined #openstack-keystone | 20:32 | |
*** alejandrito has quit IRC | 20:37 | |
*** e0ne has joined #openstack-keystone | 20:41 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Honor domain operations in project table https://review.openstack.org/143763 | 20:43 |
*** e0ne has quit IRC | 20:44 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Restricting domain_id changing https://review.openstack.org/207218 | 20:45 |
*** dims_ has quit IRC | 20:50 | |
*** dimsum__ has joined #openstack-keystone | 20:51 | |
*** markvoelker has joined #openstack-keystone | 20:56 | |
*** dimsum__ has quit IRC | 20:57 | |
*** ankita_wagh has quit IRC | 20:57 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: List projects filtering by is_domain flag https://review.openstack.org/158398 | 20:57 |
*** ankita_wagh has joined #openstack-keystone | 20:58 | |
*** markvoelker has quit IRC | 21:01 | |
*** dimsum__ has joined #openstack-keystone | 21:01 | |
*** browne1 has joined #openstack-keystone | 21:14 | |
*** browne has quit IRC | 21:15 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Restrict inherited role assignments to subdomains https://review.openstack.org/164180 | 21:16 |
*** afazekas has quit IRC | 21:18 | |
*** belmoreira has quit IRC | 21:19 | |
*** chris has joined #openstack-keystone | 21:21 | |
*** chris is now known as Guest58084 | 21:21 | |
*** hrou has joined #openstack-keystone | 21:22 | |
*** dobson has quit IRC | 21:28 | |
*** lhcheng has quit IRC | 21:33 | |
*** dobson has joined #openstack-keystone | 21:33 | |
openstackgerrit | Merged openstack/keystone: Add groups in scoped federated tokens https://review.openstack.org/207167 | 21:34 |
*** topol has joined #openstack-keystone | 21:38 | |
*** ChanServ sets mode: +v topol | 21:38 | |
*** topol has quit IRC | 21:43 | |
openstackgerrit | henry-nash proposed openstack/keystone: Improve List Role Assignments Filters Performance https://review.openstack.org/137202 | 21:48 |
*** BrAsS_mOnKeY has joined #openstack-keystone | 21:51 | |
*** BrAsS_mOnKeY has quit IRC | 21:57 | |
*** BrAsS_mOnKeY has joined #openstack-keystone | 21:59 | |
*** jsavak has joined #openstack-keystone | 22:04 | |
*** dims_ has joined #openstack-keystone | 22:05 | |
*** dimsum__ has quit IRC | 22:06 | |
*** henrynash has quit IRC | 22:13 | |
*** jsavak has quit IRC | 22:30 | |
*** markvoelker has joined #openstack-keystone | 22:57 | |
*** markvoelker has quit IRC | 23:02 | |
*** jamielennox|away is now known as jamielennox | 23:06 | |
bigjools | morning jamielennox | 23:09 |
jamielennox | bigjools: hello - you coming over today? | 23:09 |
bigjools | jamielennox: not sure at the moment. I'll probably come tomorrow though. | 23:09 |
bigjools | jamielennox: question for you, if someone is using LDAP for plain users, what's the general solution for local admin users? | 23:11 |
jamielennox | bigjools: so it's one backend per domain, so generally we get people to put the service users in LDAP as well | 23:12 |
bigjools | I thought maybe multi-domains would work but Horizon doesn't support that | 23:12 |
jamielennox | what do you mean for local admin specifically | 23:12 |
bigjools | an admin user that's decoupled from needed LDAP | 23:13 |
bigjools | needing* | 23:13 |
jamielennox | yea, i'd go for another domain | 23:13 |
bigjools | Also keystone seems to have bugs using multiple domains https://bugs.launchpad.net/keystone/+bug/1479578 | 23:14 |
openstack | Launchpad bug 1479578 in Keystone "Domain-specific config breaks some ops" [Undecided,New] | 23:14 |
jamielennox | horizon does support it | 23:14 |
bigjools | so if I want to log in, it lets me choose a domain now? I couldn't get that working at least with Kilo, are you talking about master? | 23:15 |
*** alejandrito has joined #openstack-keystone | 23:15 | |
morganfainberg | jamielennox: https://bugs.launchpad.net/keystoneauth/+bug/1476822 | 23:20 |
openstack | Launchpad bug 1476822 in keystoneauth "default service_type atribute in url_for method should be 'identity'" [Undecided,In progress] - Assigned to Paulo Ewerton (pauloewerton) | 23:20 |
jamielennox | bigjools: i thought it was in kilo, there's a horizon option for selecting domain i think, let me look | 23:20 |
bigjools | jamielennox: there is, but it doesn't work for actually logging in, at least in my testing | 23:21 |
jamielennox | bigjools: ok, cause i'm looking for the config option and i can't find it | 23:21 |
bigjools | IOW it just sticks to the default domain | 23:21 |
jamielennox | what's the issue you see? | 23:22 |
bigjools | it's in local_settings | 23:22 |
bigjools | basically I set up a second domain with its own domain-specific config that was connected to LDAP | 23:22 |
bigjools | but you can't log in as any of its users, only local sql ones in the default domain | 23:23 |
jamielennox | so you hvae v3 auth set up? | 23:23 |
bigjools | as far as I can tell, yes | 23:23 |
bigjools | I don't know whether it's meant to search all domains or if it's supposed to add a domain drop-down so you can select | 23:24 |
jamielennox | bigjools: https://github.com/openstack/horizon/blob/master/openstack_dashboard/local/local_settings.py.example#L57 | 23:25 |
jamielennox | but i thought there was something where you could have like a drop down | 23:25 |
bigjools | rargh, I must have missed that | 23:25 |
bigjools | well, let me check | 23:25 |
bigjools | damn, had missed it! | 23:26 |
jamielennox | :) | 23:27 |
jamielennox | good - because i wasn't sure what to suggest next | 23:27 |
bigjools | heh | 23:27 |
bigjools | So. Much. Config. | 23:27 |
jamielennox | yea - that one's unfortunate but it makes sense | 23:27 |
jamielennox | often you will want to have one horizon instance per domain | 23:27 |
jamielennox | and the enter a domain name on login isn't a great UX | 23:28 |
bigjools | no :( | 23:28 |
bigjools | jamielennox: what do you think to the idea of having a meta ID driver that can chain users from multiple other drivers? | 23:32 |
jamielennox | bigjools: it's certainly doable but it would be very client specific and so wouldn't be upstream | 23:34 |
bigjools | client specific? | 23:34 |
jamielennox | i was going to say domain specific but not like keystone domains | 23:35 |
jamielennox | deployment specific | 23:35 |
bigjools | I would argue that's not the case, given the replies I had on the dev list | 23:36 |
jamielennox | bigjools: i think the thing i would question here is why do you have local admin users rather than give admin roles to real users? | 23:36 |
bigjools | Because not all users are in LDAP | 23:37 |
bigjools | or more to the point, not all admins might be there | 23:37 |
bigjools | if you're running a managed service, you'll want admin users that are not part of a customer's LDAP | 23:38 |
jamielennox | so this is i guess a bigger bug bear of mine with REALM != DOMAIN | 23:39 |
jamielennox | but ignore that | 23:40 |
bigjools | words are hard :) | 23:40 |
jamielennox | ideally the per-domain thing is the right way to do it | 23:41 |
jamielennox | well i think they should be different concepts altogether | 23:41 |
bigjools | I am desperate for a flat white and there's no damn milk in the house. This is a disaster. | 23:47 |
bigjools | ok so how would you envisage Horizon's UI for multi-domain login if the existing one is not good? | 23:48 |
jamielennox | bigjools: come here then | 23:55 |
*** dimsum__ has joined #openstack-keystone | 23:55 | |
*** dims_ has quit IRC | 23:57 | |
*** markvoelker has joined #openstack-keystone | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!