| *** markvoelker has quit IRC | 00:02 | |
| *** dims_ has joined #openstack-keystone | 00:02 | |
| *** chlong has joined #openstack-keystone | 00:03 | |
| bigjools | will see if I can come over after lunch, depends on the mrs | 00:04 |
|---|---|---|
| *** dimsum__ has quit IRC | 00:04 | |
| *** ankita_w_ has joined #openstack-keystone | 00:11 | |
| *** ankita_wagh has quit IRC | 00:14 | |
| morganfainberg | bigjools: are you hiding around the sprint area(s) | 00:23 |
| bigjools | morganfainberg: I'm at home! | 00:23 |
| morganfainberg | bigjools: ahhh | 00:23 |
| bigjools | the mrs is out this morning and we have a needy dog that can't be left on her own | 00:24 |
| morganfainberg | bigjools: ah ok | 00:28 |
| bigjools | I'll try to get over later | 00:29 |
| *** Kennan has left #openstack-keystone | 00:29 | |
| morganfainberg | jamielennox: https://review.openstack.org/#/c/190532/ if you don't mind taking a look | 00:31 |
| morganfainberg | (backlog) | 00:31 |
| *** dims_ has quit IRC | 00:50 | |
| *** dimsum__ has joined #openstack-keystone | 00:53 | |
| *** lhcheng has joined #openstack-keystone | 00:55 | |
| *** ChanServ sets mode: +v lhcheng | 00:55 | |
| openstackgerrit | Merged openstack/keystoneauth: Expose bug in AccessToken https://review.openstack.org/205094 | 00:56 |
| openstackgerrit | Merged openstack/keystoneauth: Fix decorators of properties in AccessToken https://review.openstack.org/205209 | 01:02 |
| *** jamielennox is now known as jamielennox|away | 01:08 | |
| *** ankita_w_ has quit IRC | 01:15 | |
| *** ankita_wagh has joined #openstack-keystone | 01:16 | |
| *** dimsum__ has quit IRC | 01:25 | |
| *** dimsum__ has joined #openstack-keystone | 01:28 | |
| bigjools | jamielennox|away, morganfainberg: I am heading your way now, will be there in around an hour. | 01:30 |
| *** jsavak has joined #openstack-keystone | 01:31 | |
| *** davechen has joined #openstack-keystone | 01:32 | |
| morganfainberg | bigjools: jamielennox|away wandered off but will be back in a couple hours | 01:33 |
| morganfainberg | we are here | 01:33 |
| bigjools | morganfainberg: which room? | 01:35 |
| morganfainberg | grand windsor room | 01:35 |
| bigjools | ok cool, see you soon | 01:35 |
| morganfainberg | where the afternoon teas were | 01:35 |
| *** jsavak has quit IRC | 01:36 | |
| *** piyanai has joined #openstack-keystone | 01:39 | |
| *** davechen1 has joined #openstack-keystone | 01:46 | |
| *** davechen has quit IRC | 01:49 | |
| *** davechen has joined #openstack-keystone | 01:54 | |
| *** davechen1 has quit IRC | 01:56 | |
| *** markvoelker has joined #openstack-keystone | 01:59 | |
| *** dimsum__ has quit IRC | 02:02 | |
| *** markvoelker has quit IRC | 02:03 | |
| *** kiran-r has joined #openstack-keystone | 02:27 | |
| *** kiran-r has quit IRC | 02:27 | |
| *** topol has joined #openstack-keystone | 02:28 | |
| *** ChanServ sets mode: +v topol | 02:28 | |
| *** piyanai has quit IRC | 02:29 | |
| *** topol has quit IRC | 02:33 | |
| *** hakimo_ has joined #openstack-keystone | 02:52 | |
| *** piyanai has joined #openstack-keystone | 02:53 | |
| *** hakimo has quit IRC | 02:54 | |
| *** alejandrito has quit IRC | 03:12 | |
| *** topol has joined #openstack-keystone | 03:20 | |
| *** ChanServ sets mode: +v topol | 03:20 | |
| *** topol has quit IRC | 03:24 | |
| *** jecarey has joined #openstack-keystone | 03:33 | |
| *** piyanai has quit IRC | 03:58 | |
| *** Daviey has quit IRC | 03:59 | |
| *** markvoelker has joined #openstack-keystone | 04:00 | |
| *** piyanai has joined #openstack-keystone | 04:04 | |
| *** markvoelker has quit IRC | 04:04 | |
| *** piyanai has quit IRC | 04:06 | |
| *** jecarey has quit IRC | 04:17 | |
| *** boris-42 has joined #openstack-keystone | 04:18 | |
| *** jamielennox|away is now known as jamielennox | 04:38 | |
| *** Daviey has joined #openstack-keystone | 04:58 | |
| *** kiran-r has joined #openstack-keystone | 05:03 | |
| *** Nirupama has joined #openstack-keystone | 05:05 | |
| openstackgerrit | Andrey Pavlov proposed openstack/keystonemiddleware: Adding parse of protocol v4 of AWS auth to ec2_token https://review.openstack.org/205440 | 05:19 |
| *** urulama has joined #openstack-keystone | 05:20 | |
| *** yottatsa has joined #openstack-keystone | 05:21 | |
| *** yottatsa has quit IRC | 05:21 | |
| *** btully has quit IRC | 05:30 | |
| breton | good morning, keystone | 05:34 |
| *** yottatsa has joined #openstack-keystone | 05:35 | |
| *** afazekas has joined #openstack-keystone | 05:37 | |
| *** harlowja has quit IRC | 05:44 | |
| *** afazekas has quit IRC | 05:46 | |
| *** afazekas has joined #openstack-keystone | 05:49 | |
| *** josecastroleon has joined #openstack-keystone | 05:58 | |
| *** markvoelker has joined #openstack-keystone | 06:01 | |
| *** ParsectiX has joined #openstack-keystone | 06:04 | |
| *** markvoelker has quit IRC | 06:05 | |
| morganfainberg | sooooo | 06:07 |
| morganfainberg | just got almost everything working for uwsgi. soooooo easy | 06:08 |
| morganfainberg | dstanek: ^^ | 06:08 |
| *** pcaruana has quit IRC | 06:09 | |
| *** Kennan has joined #openstack-keystone | 06:11 | |
| *** lhcheng has quit IRC | 06:11 | |
| morganfainberg | lbragstad, dstanek, dolph, (cc bknudson) : starting a fresh checkout of keystone (keystone-deploy) I get 2015-08-03 05:45:25.211 96 WARNING oslo_log.versionutils [-] Deprecated: direct import of driver is deprecated as of Liberty in favor of entrypoints and may be removed in N. | 06:12 |
| morganfainberg | haven't looked if this is a default issue or a keystone-deploy issue | 06:12 |
| *** yottatsa has quit IRC | 06:22 | |
| *** belmoreira has joined #openstack-keystone | 06:25 | |
| *** afazekas has quit IRC | 06:27 | |
| *** afazekas has joined #openstack-keystone | 06:31 | |
| breton | uwsgi is good | 06:40 |
| *** geoffarn_ has joined #openstack-keystone | 06:47 | |
| *** geoffarnold has quit IRC | 06:50 | |
| *** browne1 has quit IRC | 07:04 | |
| *** yottatsa has joined #openstack-keystone | 07:04 | |
| *** e0ne has joined #openstack-keystone | 07:06 | |
| *** boris-42 has quit IRC | 07:10 | |
| *** henrynash has joined #openstack-keystone | 07:12 | |
| *** ChanServ sets mode: +v henrynash | 07:12 | |
| openstackgerrit | Marek Denis proposed openstack/keystone: Refactor: rename Fernet's unscoped federated payload https://review.openstack.org/202190 | 07:13 |
| *** jsheeren has joined #openstack-keystone | 07:17 | |
| *** e0ne has quit IRC | 07:21 | |
| *** ankita_wagh has quit IRC | 07:28 | |
| *** fhubik has joined #openstack-keystone | 07:35 | |
| *** vivekd has joined #openstack-keystone | 07:35 | |
| *** chlong has quit IRC | 07:38 | |
| *** pcaruana has joined #openstack-keystone | 07:40 | |
| *** bdossant has joined #openstack-keystone | 07:46 | |
| *** mhu has quit IRC | 07:46 | |
| *** hrou has quit IRC | 07:47 | |
| *** e0ne has joined #openstack-keystone | 07:52 | |
| *** e0ne has quit IRC | 07:55 | |
| *** jamielennox is now known as jamielennox|away | 07:57 | |
| *** yottatsa has quit IRC | 07:57 | |
| *** lhcheng has joined #openstack-keystone | 08:00 | |
| *** ChanServ sets mode: +v lhcheng | 08:00 | |
| *** markvoelker has joined #openstack-keystone | 08:02 | |
| *** lhcheng has quit IRC | 08:04 | |
| *** markvoelker has quit IRC | 08:06 | |
| *** geoffarn_ has quit IRC | 08:10 | |
| *** jistr has joined #openstack-keystone | 08:15 | |
| *** henrynash has quit IRC | 08:16 | |
| *** aix has joined #openstack-keystone | 08:18 | |
| openstackgerrit | Merged openstack/keystone: Refactor _populate_roles_for_groups() https://review.openstack.org/207785 | 08:30 |
| *** mhu has joined #openstack-keystone | 08:40 | |
| ParsectiX | guys here is mandatory to pass project_id http://docs.openstack.org/developer/python-keystoneclient/using-api-v3.html#authenticating-using-sessions | 08:42 |
| ParsectiX | ? | 08:42 |
| marekd | ParsectiX: as opposed to 'tenant' ? | 08:43 |
| ParsectiX | I'm trying to pass only username and password and it fails to auth | 08:44 |
| marekd | ParsectiX: with what error? | 08:44 |
| *** mhu has quit IRC | 08:44 | |
| ParsectiX | keystoneclient.openstack.common.apiclient.exceptions.BadRequest: Expecting to find domain in user - the server could not comply with the request since it is either malformed or otherwise incorrect. The client is assumed to be in error. (HTTP 400) | 08:44 |
| marekd | "Expecting to find domain in user" | 08:45 |
| ParsectiX | yeap | 08:45 |
| marekd | so...? | 08:45 |
| ParsectiX | what's that ? | 08:45 |
| marekd | add OS_USER_DOMAIN_NAME | 08:45 |
| ParsectiX | where can I find this info for an already existing user ? | 08:46 |
| ParsectiX | in the RC file does not included. | 08:46 |
| marekd | which API are you using? | 08:47 |
| marekd | API version | 08:47 |
| ParsectiX | V3 | 08:47 |
| marekd | so rc files are for v2 for now | 08:47 |
| marekd | try domain 'defau;t' | 08:47 |
| ParsectiX | ohh okay | 08:47 |
| marekd | default | 08:47 |
| ParsectiX | no luck | 08:48 |
| marekd | ParsectiX: so that's strange because i am getting different error: Set a scope, such as a project or domain, set a project scope with --os-project-name, OS_PROJECT_NAME or auth.project_name, set a domain scope with --os-domain-name, OS_DOMAIN_NAME or auth.domain_name | 08:49 |
| marekd | which is more like something you are talking about, but clearly you provided different log. | 08:50 |
| ParsectiX | I'm not using the env. variables. I'm trying to pass the values to authentication = v3.Password(...) function | 08:51 |
| marekd | ParsectiX: so how did you call it? | 08:52 |
| marekd | what params did you provide? | 08:52 |
| ParsectiX | auth_url, username, password and now domain_name | 08:53 |
| ParsectiX | i set the domain_name=None | 08:53 |
| ParsectiX | also tried "default" | 08:53 |
| marekd | ParsectiX: did it work with project specified? | 08:53 |
| ParsectiX | No | 08:54 |
| ParsectiX | I was using this http://docs.openstack.org/developer/python-keystoneclient/using-api-v3.html#non-session-authentication-deprecated | 08:54 |
| ParsectiX | and now I'm trying to migrate to use sessions | 08:54 |
| marekd | http://www.jamielennox.net/blog/2014/09/15/how-to-use-keystoneclient-sessions/ | 08:56 |
| ParsectiX | Thanks let me read it | 08:56 |
| marekd | aha, and why asking if it will work without project since it didn't even work the "old way" ? | 08:56 |
| ParsectiX | I thought maybe that was the issue | 08:57 |
| marekd | aha | 08:57 |
| ParsectiX | marekd: Thanks for your help | 08:57 |
| marekd | ParsectiX: you welcome | 08:58 |
| ParsectiX | marekd: it worked. the issue was to add those two arguments | 09:00 |
| ParsectiX | user_domain_name='default', | 09:00 |
| ParsectiX | project_domain_name='default' | 09:00 |
| marekd | ok | 09:01 |
| marekd | col | 09:01 |
| marekd | cool | 09:01 |
| *** e0ne has joined #openstack-keystone | 09:08 | |
| openstackgerrit | Boris Bobrov proposed openstack/keystone-specs: Remove KDS from the list of api extensions https://review.openstack.org/208383 | 09:17 |
| *** lexloofer is now known as lxsli | 09:20 | |
| *** urulama has quit IRC | 09:21 | |
| *** urulama has joined #openstack-keystone | 09:22 | |
| breton | http://developer.openstack.org/api-ref-identity-v2-ext.html#os-ksvalidate-ext -- where does this section come from? I can't find any reference to OS-KSVALIDATE in keystone-specs | 09:23 |
| *** fhubik is now known as fhubik_afk | 09:26 | |
| *** fhubik_afk is now known as fhubik | 09:26 | |
| *** fhubik is now known as fhubik_afk | 09:27 | |
| ParsectiX | Guys do you have any Doc mapping the old implementations of V2 to V3 ? | 09:36 |
| ParsectiX | As an example I used this http://docs.openstack.org/developer/python-keystoneclient/api/keystoneclient.service_catalog.html#module-keystoneclient.service_catalog | 09:36 |
| ParsectiX | to get the service catalog | 09:36 |
| ParsectiX | and now looking how to do it with V3 | 09:37 |
| ParsectiX | and after some research i concluded that those functions are now in endpoint manager | 09:38 |
| *** fhubik_afk is now known as fhubik | 09:44 | |
| *** marzif_ has quit IRC | 09:46 | |
| *** marzif_ has joined #openstack-keystone | 09:47 | |
| *** marzif_ has quit IRC | 09:48 | |
| *** lhcheng has joined #openstack-keystone | 09:49 | |
| *** ChanServ sets mode: +v lhcheng | 09:49 | |
| morganfainberg | breton: those api docs are wronf | 09:53 |
| morganfainberg | Wrong | 09:53 |
| *** lhcheng has quit IRC | 09:53 | |
| morganfainberg | breton: use the specs.openstack.org docs | 09:53 |
| *** davechen has left #openstack-keystone | 09:54 | |
| *** marzif has joined #openstack-keystone | 09:57 | |
| breton | morganfainberg: maybe we should ping someone to remove it | 09:58 |
| morganfainberg | It is an active docs bug / | 09:59 |
| morganfainberg | Been raised before. | 09:59 |
| breton | ok. | 09:59 |
| morganfainberg | It shouldnt be removed, but updated automatically | 09:59 |
| *** markvoelker has joined #openstack-keystone | 10:02 | |
| *** yottatsa has joined #openstack-keystone | 10:04 | |
| *** aix has quit IRC | 10:06 | |
| *** markvoelker has quit IRC | 10:07 | |
| *** Kennan has quit IRC | 10:07 | |
| *** blogan has quit IRC | 10:08 | |
| *** Guest58084 has quit IRC | 10:08 | |
| *** HenryG has quit IRC | 10:08 | |
| *** HenryG has joined #openstack-keystone | 10:08 | |
| *** blogan has joined #openstack-keystone | 10:08 | |
| *** Kennan has joined #openstack-keystone | 10:09 | |
| *** Guest58084 has joined #openstack-keystone | 10:09 | |
| *** lhcheng has joined #openstack-keystone | 10:13 | |
| *** ChanServ sets mode: +v lhcheng | 10:13 | |
| *** rdo has quit IRC | 10:14 | |
| *** rdo has joined #openstack-keystone | 10:16 | |
| *** e0ne has quit IRC | 10:16 | |
| *** e0ne has joined #openstack-keystone | 10:17 | |
| *** lhcheng has quit IRC | 10:18 | |
| *** josecastroleon has quit IRC | 10:20 | |
| *** dimsum__ has joined #openstack-keystone | 10:34 | |
| *** urulama has quit IRC | 10:37 | |
| *** urulama has joined #openstack-keystone | 10:38 | |
| *** piyanai has joined #openstack-keystone | 10:49 | |
| *** e0ne has quit IRC | 10:50 | |
| *** pcaruana has quit IRC | 10:57 | |
| *** josecastroleon has joined #openstack-keystone | 11:02 | |
| *** marzif has quit IRC | 11:09 | |
| *** marzif has joined #openstack-keystone | 11:10 | |
| *** pcaruana has joined #openstack-keystone | 11:14 | |
| *** dims_ has joined #openstack-keystone | 11:18 | |
| *** dimsum__ has quit IRC | 11:20 | |
| *** marzif has quit IRC | 11:27 | |
| *** amakarov_away is now known as amakarov | 11:30 | |
| *** edmondsw has joined #openstack-keystone | 11:31 | |
| *** kiran-r has quit IRC | 11:31 | |
| *** markvoelker has joined #openstack-keystone | 11:33 | |
| *** markvoelker has quit IRC | 11:38 | |
| *** fhubik is now known as fhubik_afk | 11:39 | |
| *** rdo has quit IRC | 11:41 | |
| *** rdo has joined #openstack-keystone | 11:42 | |
| samueldmq | morning | 11:46 |
| samueldmq | morganfainberg: hey | 11:47 |
| samueldmq | morganfainberg: you got up early or hadn't went sleep yet or are you in a different tz ? | 11:47 |
| samueldmq | morganfainberg: or ... :-) | 11:47 |
| *** iurygregory has joined #openstack-keystone | 11:47 | |
| morganfainberg | samueldmq: its 2148 here | 11:48 |
| samueldmq | morganfainberg: uh where are you today ? | 11:48 |
| morganfainberg | 2148, monday night that is | 11:48 |
| samueldmq | morganfainberg: Australia? | 11:48 |
| morganfainberg | samueldmq: hint - ill see koalas tomorrow | 11:49 |
| morganfainberg | Yah | 11:49 |
| morganfainberg | Brisbane | 11:49 |
| samueldmq | morganfainberg: haha great | 11:49 |
| morganfainberg | 3 more days here. | 11:50 |
| samueldmq | morganfainberg: was looking for some pics, looks to be a great city | 11:50 |
| morganfainberg | Fun so far. Good food etc | 11:50 |
| samueldmq | nice, I suppose jamie is there as well | 11:50 |
| marekd | morganfainberg: got a few minutes? | 11:51 |
| samueldmq | pycon australia ? | 11:51 |
| morganfainberg | samueldmq: yes and yes | 11:51 |
| morganfainberg | marekd: a few. | 11:51 |
| samueldmq | morganfainberg: yes! o/ | 11:51 |
| samueldmq | morganfainberg: enjoy | 11:52 |
| morganfainberg | marekd: talked with jamielennox|away btw, we have the short list of what is needed for keystoneauth | 11:52 |
| morganfainberg | It's about 2-3 real | 11:52 |
| marekd | morganfainberg: so, regarding revocations - we support revocation lists for uuid tokens, and do we have anything for fernet? Would it be revocation events? If so, does it work now? | 11:52 |
| marekd | morganfainberg: great! | 11:52 |
| morganfainberg | Patches. Maybe 5-6 if you count minor tweaks | 11:53 |
| morganfainberg | Revocation events are used for fernet exclusively | 11:53 |
| morganfainberg | Must use revocation events for fernet. Uuid can be either token revocation list or events | 11:53 |
| marekd | morganfainberg: so ksm will query for both revocation lists and revocation events. | 11:53 |
| morganfainberg | Ksm will not ever query for the events | 11:54 |
| marekd | morganfainberg: how do i decide on what uuid should use (lists vs events) ? | 11:54 |
| morganfainberg | Events are keystone side only (during validate) | 11:54 |
| breton | marekd: events | 11:54 |
| *** markvoelker_ has joined #openstack-keystone | 11:54 | |
| breton | marekd: lists show some bad performance | 11:54 |
| morganfainberg | But use events. | 11:54 |
| marekd | breton: i know. | 11:54 |
| *** dims_ has quit IRC | 11:54 | |
| marekd | morganfainberg: so a service gets a token, it must send it to keystone in order to validate, and server will basically match token with event. | 11:55 |
| morganfainberg | Yes | 11:55 |
| morganfainberg | Uuid and fernet require keystone to validate | 11:55 |
| marekd | morganfainberg: sure. | 11:55 |
| morganfainberg | So it works. | 11:55 |
| *** dimsum__ has joined #openstack-keystone | 11:55 | |
| marekd | morganfainberg: so how is that better/faster ather than querying token table and checking if it's valid? | 11:56 |
| marekd | ah, the process on invalidating tokens may take long so lots of tokesn... | 11:56 |
| marekd | is that a reason ? | 11:56 |
| *** fhubik_afk is now known as fhubik | 11:56 | |
| morganfainberg | It is optimised for a balance of fernet and/or uuid. But if you have tons of tokens token lookup can be slow even with indexes | 11:56 |
| marekd | morganfainberg: is ksm by default using revocation events? | 11:57 |
| morganfainberg | Uuid will be faster revocations with a small table. However, events are more flexible and dont require table scans/updates of tons of rows | 11:57 |
| morganfainberg | Keystonemiddleware doesnt look at revocation events at all directly | 11:57 |
| *** htruta_ has joined #openstack-keystone | 11:58 | |
| marekd | ksm, uh, right | 11:58 |
| marekd | vadliation on server side. | 11:58 |
| morganfainberg | Yep | 11:58 |
| morganfainberg | Events need some | 11:59 |
| marekd | revocation event should be created for every operation like user delete, project delete, domain delete, idp delete etc (same for disabling) | 11:59 |
| morganfainberg | Love / profiling and updates. | 11:59 |
| morganfainberg | So they can be made faster. But they are the better solution in most cases n | 11:59 |
| marekd | morganfainberg: are revocation events some removed from the DB? Like...after some time or upon some action? | 12:01 |
| morganfainberg | They are pruned on each new event | 12:01 |
| morganfainberg | If they are expired on the next revocation, they are cleaned up. | 12:02 |
| marekd | morganfainberg: smart. | 12:03 |
| marekd | all the code to look into is actually keystone/contrbi/revoke | 12:04 |
| marekd | ? | 12:04 |
| marekd | morganfainberg: one more question - how a even "user was deleted" can actually expire? | 12:04 |
| morganfainberg | Not sure what youre asking | 12:05 |
| *** yottatsa_ has joined #openstack-keystone | 12:05 | |
| marekd | morganfainberg: you said " If they are expired on the next revocation, they are cleaned up" | 12:05 |
| marekd | morganfainberg: what was expired - tokens or events ? | 12:05 |
| *** yottatsa has quit IRC | 12:06 | |
| morganfainberg | The events | 12:07 |
| *** dimsum__ has quit IRC | 12:08 | |
| *** javier_ has joined #openstack-keystone | 12:08 | |
| marekd | how can they expire? | 12:08 |
| morganfainberg | So if an event is expired, when the next event is issued, we cleanup | 12:08 |
| morganfainberg | They last for token_ttl + window | 12:08 |
| morganfainberg | You dont need to keep them forever. They basically say "all tokens that match these rules from are invalid if they were issued before x datetime" | 12:09 |
| marekd | morganfainberg: do we somewhere keep a time when was last token issued for this user/project/domain/something ? or it's statically calculated. | 12:09 |
| morganfainberg | All tokens have an issued at time | 12:10 |
| morganfainberg | Events are from the moment they are issued | 12:10 |
| marekd | morganfainberg: ok, so expiration time of the event would be now() + tokens_ttl + window | 12:11 |
| morganfainberg | So if i revoke all events for user x at midnight, (password change) the event is tied to when that password change occirrd | 12:11 |
| morganfainberg | And lasts for the token ttl (config options) and some extra | 12:11 |
| morganfainberg | Time | 12:11 |
| morganfainberg | Yeah | 12:11 |
| marekd | morganfainberg: ok, that's very helpful. | 12:12 |
| marekd | thanks! | 12:12 |
| marekd | not bothering you too much now! | 12:12 |
| morganfainberg | Hehe | 12:12 |
| morganfainberg | No worries. | 12:12 |
| *** raildo has joined #openstack-keystone | 12:18 | |
| *** dimsum__ has joined #openstack-keystone | 12:22 | |
| *** yottatsa_ has quit IRC | 12:24 | |
| *** marzif has joined #openstack-keystone | 12:24 | |
| *** yottatsa has joined #openstack-keystone | 12:24 | |
| *** e0ne has joined #openstack-keystone | 12:24 | |
| *** marzif has quit IRC | 12:24 | |
| *** yottatsa has quit IRC | 12:24 | |
| *** javier_ has quit IRC | 12:25 | |
| *** marzif has joined #openstack-keystone | 12:25 | |
| openstackgerrit | Merged openstack/keystonemiddleware: Merge test-requirements-py3.txt to test-requirements.txt https://review.openstack.org/206044 | 12:26 |
| *** dims_ has joined #openstack-keystone | 12:27 | |
| *** dims__ has joined #openstack-keystone | 12:29 | |
| *** dimsum__ has quit IRC | 12:29 | |
| *** yottatsa has joined #openstack-keystone | 12:29 | |
| *** Nirupama has quit IRC | 12:30 | |
| *** dimsum__ has joined #openstack-keystone | 12:32 | |
| *** marzif_ has joined #openstack-keystone | 12:32 | |
| *** dims_ has quit IRC | 12:32 | |
| *** mflobo has left #openstack-keystone | 12:32 | |
| *** daemontool_ has joined #openstack-keystone | 12:33 | |
| *** marzif has quit IRC | 12:33 | |
| *** dims__ has quit IRC | 12:34 | |
| *** chlong has joined #openstack-keystone | 12:35 | |
| *** piyanai has quit IRC | 12:36 | |
| *** urulama has quit IRC | 12:36 | |
| *** urulama has joined #openstack-keystone | 12:37 | |
| *** dims_ has joined #openstack-keystone | 12:45 | |
| *** dimsum__ has quit IRC | 12:46 | |
| *** daemontool_ is now known as marzif | 12:46 | |
| *** yottatsa has quit IRC | 12:47 | |
| lbragstad | morganfainberg: interesting, you didn't have fatal_deprecations enabled by default did you? | 12:51 |
| *** dims_ has quit IRC | 12:53 | |
| *** dimsum__ has joined #openstack-keystone | 12:54 | |
| *** topol has joined #openstack-keystone | 12:54 | |
| *** ChanServ sets mode: +v topol | 12:54 | |
| *** dimsum__ is now known as dims | 12:55 | |
| *** jsavak has joined #openstack-keystone | 12:57 | |
| *** browne has joined #openstack-keystone | 12:57 | |
| *** piyanai has joined #openstack-keystone | 12:57 | |
| *** topol has quit IRC | 12:59 | |
| *** jaosorior has joined #openstack-keystone | 12:59 | |
| *** yottatsa has joined #openstack-keystone | 13:01 | |
| *** markvoelker_ has quit IRC | 13:02 | |
| *** jsavak has quit IRC | 13:04 | |
| *** markvoelker has joined #openstack-keystone | 13:04 | |
| *** topol has joined #openstack-keystone | 13:04 | |
| *** ChanServ sets mode: +v topol | 13:04 | |
| *** jsavak has joined #openstack-keystone | 13:04 | |
| *** e0ne has quit IRC | 13:08 | |
| *** e0ne has joined #openstack-keystone | 13:10 | |
| *** aix has joined #openstack-keystone | 13:11 | |
| *** browne has quit IRC | 13:13 | |
| *** dsirrine has joined #openstack-keystone | 13:15 | |
| *** piyanai has quit IRC | 13:19 | |
| *** doug-fish has joined #openstack-keystone | 13:21 | |
| *** boris-42 has joined #openstack-keystone | 13:22 | |
| *** urulama has quit IRC | 13:23 | |
| *** urulama has joined #openstack-keystone | 13:23 | |
| *** dsirrine has quit IRC | 13:24 | |
| *** zzzeek has joined #openstack-keystone | 13:24 | |
| *** dsirrine has joined #openstack-keystone | 13:25 | |
| *** bapalm has joined #openstack-keystone | 13:27 | |
| *** TheIntern has joined #openstack-keystone | 13:30 | |
| *** bdossant_ has joined #openstack-keystone | 13:32 | |
| *** jsheeren has quit IRC | 13:33 | |
| *** bdossant has quit IRC | 13:33 | |
| *** ayoung has joined #openstack-keystone | 13:35 | |
| *** ChanServ sets mode: +v ayoung | 13:35 | |
| *** ayoung is now known as admiyo | 13:35 | |
| *** bdossant_ has quit IRC | 13:37 | |
| *** piyanai has joined #openstack-keystone | 13:38 | |
| *** richm1 has joined #openstack-keystone | 13:38 | |
| *** richm1 is now known as richm | 13:38 | |
| *** bdossant has joined #openstack-keystone | 13:40 | |
| *** tjcocozz has joined #openstack-keystone | 13:40 | |
| *** tjcocozz_ has joined #openstack-keystone | 13:40 | |
| -openstackstatus- NOTICE: The Gerrit service on review.openstack.org has been restarted in an attempt to improve performance. | 13:40 | |
| *** tjcocozz_ has quit IRC | 13:40 | |
| *** jistr is now known as jistr|mtg | 13:41 | |
| *** marzif_ has quit IRC | 13:43 | |
| *** marzif_ has joined #openstack-keystone | 13:44 | |
| *** bdossant has quit IRC | 13:44 | |
| *** h00327910__ has quit IRC | 13:48 | |
| *** bknudson has quit IRC | 13:49 | |
| *** browne has joined #openstack-keystone | 13:50 | |
| *** vivekd has quit IRC | 13:50 | |
| openstackgerrit | Alexander Makarov proposed openstack/keystone: Unified delegation model https://review.openstack.org/208488 | 13:51 |
| *** bapalm_ has joined #openstack-keystone | 13:51 | |
| *** sigmavirus24_awa is now known as sigmavirus24 | 13:54 | |
| *** bapalm has quit IRC | 13:54 | |
| *** piyanai has quit IRC | 13:58 | |
| *** jsavak has quit IRC | 14:00 | |
| *** jsavak has joined #openstack-keystone | 14:02 | |
| *** josecastroleon has quit IRC | 14:02 | |
| *** mylu has joined #openstack-keystone | 14:05 | |
| *** browne has quit IRC | 14:08 | |
| *** ParsectiX has quit IRC | 14:10 | |
| *** afazekas has quit IRC | 14:12 | |
| *** pballand has quit IRC | 14:12 | |
| *** bknudson has joined #openstack-keystone | 14:13 | |
| *** ChanServ sets mode: +v bknudson | 14:13 | |
| *** fhubik is now known as fhubik_afk | 14:18 | |
| *** yottatsa has quit IRC | 14:19 | |
| *** jistr|mtg is now known as jistr | 14:20 | |
| *** yottatsa has joined #openstack-keystone | 14:20 | |
| *** fhubik_afk is now known as fhubik | 14:21 | |
| *** jsavak has quit IRC | 14:22 | |
| *** jsavak has joined #openstack-keystone | 14:23 | |
| *** jiaxi has joined #openstack-keystone | 14:24 | |
| *** yottatsa has quit IRC | 14:25 | |
| *** yottatsa has joined #openstack-keystone | 14:26 | |
| *** admiyo has quit IRC | 14:28 | |
| *** yottatsa has quit IRC | 14:31 | |
| *** jiaxi has quit IRC | 14:31 | |
| *** afazekas has joined #openstack-keystone | 14:32 | |
| *** yottatsa has joined #openstack-keystone | 14:33 | |
| *** jsavak has quit IRC | 14:35 | |
| *** jsavak has joined #openstack-keystone | 14:36 | |
| *** jecarey has joined #openstack-keystone | 14:37 | |
| *** yottatsa has quit IRC | 14:43 | |
| *** admiyo has joined #openstack-keystone | 14:43 | |
| *** hrou has joined #openstack-keystone | 14:58 | |
| openstackgerrit | Brant Knudson proposed openstack/keystone: Remove oslo import hacking check https://review.openstack.org/208216 | 14:59 |
| *** piyanai has joined #openstack-keystone | 14:59 | |
| *** woodster_ has joined #openstack-keystone | 15:00 | |
| openstackgerrit | Rodrigo Duarte proposed openstack/keystone: Honor domain operations in project table https://review.openstack.org/143763 | 15:01 |
| openstackgerrit | Rodrigo Duarte proposed openstack/keystone: Change project name constraints https://review.openstack.org/158372 | 15:01 |
| *** konstantin-m has joined #openstack-keystone | 15:02 | |
| *** bdossant has joined #openstack-keystone | 15:05 | |
| konstantin-m | Hello, can anyone please review https://review.openstack.org/#/c/207456/ ? | 15:06 |
| *** yottatsa has joined #openstack-keystone | 15:08 | |
| *** afazekas has quit IRC | 15:10 | |
| *** pcaruana has quit IRC | 15:13 | |
| *** diazjf has joined #openstack-keystone | 15:18 | |
| *** bdossant has quit IRC | 15:24 | |
| *** thedodd has joined #openstack-keystone | 15:28 | |
| *** mylu has quit IRC | 15:30 | |
| *** mylu has joined #openstack-keystone | 15:31 | |
| *** jsavak has quit IRC | 15:33 | |
| *** jsavak has joined #openstack-keystone | 15:34 | |
| *** pballand has joined #openstack-keystone | 15:34 | |
| *** pballand has quit IRC | 15:39 | |
| *** mestery is now known as mestery_afk_toda | 15:42 | |
| *** mestery_afk_toda is now known as mestery_afk | 15:42 | |
| openstackgerrit | Rodrigo Duarte proposed openstack/keystone: Honor domain operations in project table https://review.openstack.org/143763 | 15:44 |
| *** belmoreira has quit IRC | 15:45 | |
| *** gyee has joined #openstack-keystone | 15:47 | |
| *** ChanServ sets mode: +v gyee | 15:47 | |
| *** jiaxi_ has joined #openstack-keystone | 15:48 | |
| jiaxi_ | dstanek: Hi,David | 15:48 |
| jiaxi_ | I met a problem with tox. | 15:49 |
| rodrigods | anyone willing to review the first patch in Reseller chain? https://review.openstack.org/#/c/157427/ | 15:49 |
| jiaxi_ | when I run the cmd 'tox -i http://pypi.dev.ustack.com/simple -e py27 --notest' | 15:49 |
| jiaxi_ | It failed | 15:50 |
| jiaxi_ | The relative error info is ' http://pypi.dev.ustack.com/simple/python-keystoneclient/ uses an insecure transport scheme (http). Consider using https if pypi.dev.ustack.com has it available' | 15:50 |
| *** openstackgerrit_ has joined #openstack-keystone | 15:54 | |
| *** yottatsa has quit IRC | 15:57 | |
| openstackgerrit | Brant Knudson proposed openstack/keystonemiddleware: Docstring updates https://review.openstack.org/208213 | 15:58 |
| *** yottatsa has joined #openstack-keystone | 16:02 | |
| *** _cjones_ has joined #openstack-keystone | 16:03 | |
| *** jsavak has quit IRC | 16:04 | |
| *** jsavak has joined #openstack-keystone | 16:06 | |
| *** rdo has quit IRC | 16:07 | |
| *** fhubik is now known as fhubik_afk | 16:07 | |
| *** konstantin-m has quit IRC | 16:07 | |
| *** rdo has joined #openstack-keystone | 16:08 | |
| *** mylu has quit IRC | 16:08 | |
| *** yottatsa has quit IRC | 16:09 | |
| *** fhubik_afk is now known as fhubik | 16:09 | |
| *** mylu has joined #openstack-keystone | 16:10 | |
| *** jiaxi_ has quit IRC | 16:11 | |
| *** lsmola has quit IRC | 16:11 | |
| *** mylu has quit IRC | 16:14 | |
| *** Ephur has joined #openstack-keystone | 16:14 | |
| *** _cjones_ has quit IRC | 16:16 | |
| *** browne has joined #openstack-keystone | 16:21 | |
| *** mylu has joined #openstack-keystone | 16:22 | |
| *** mylu has quit IRC | 16:25 | |
| *** marzif_ has quit IRC | 16:25 | |
| samueldmq | dstanek: hey sir, you around ? | 16:27 |
| *** jistr has quit IRC | 16:28 | |
| *** mylu has joined #openstack-keystone | 16:28 | |
| openstackgerrit | Brant Knudson proposed openstack/keystone: Documentation for other services https://review.openstack.org/204801 | 16:29 |
| *** jdandrea has joined #openstack-keystone | 16:29 | |
| *** yottatsa has joined #openstack-keystone | 16:31 | |
| *** geoffarnold has joined #openstack-keystone | 16:31 | |
| *** lhcheng has joined #openstack-keystone | 16:37 | |
| *** ChanServ sets mode: +v lhcheng | 16:37 | |
| *** TheIntern has quit IRC | 16:37 | |
| *** e0ne has quit IRC | 16:38 | |
| *** yottatsa has quit IRC | 16:39 | |
| samueldmq | lhcheng: hi | 16:40 |
| lhcheng | samueldmq: hello! | 16:40 |
| *** urulama has quit IRC | 16:40 | |
| *** urulama has joined #openstack-keystone | 16:41 | |
| samueldmq | lhcheng: there was a thread earlier today from someone talking about dynamic policies as UI component | 16:41 |
| *** Guest23066 has quit IRC | 16:42 | |
| samueldmq | lhcheng: the message is from Timur Sufiev from Mirantis and has 'UI for Keystone dynamic policies editing' as subject | 16:43 |
| samueldmq | lhcheng: did you see that ? He posted a link of a demo where there is some interface he'd like to re-use for dynamic policies in horizon | 16:43 |
| samueldmq | lhcheng: I'd appreciate some of your view on that (with your Horizon cap) | 16:44 |
| samueldmq | :-) | 16:44 |
| *** yottatsa has joined #openstack-keystone | 16:44 | |
| *** browne has quit IRC | 16:45 | |
| *** kiran-r has joined #openstack-keystone | 16:46 | |
| lhcheng | samueldmq: I've seen the mistral workbook in the last summit | 16:47 |
| lhcheng | samueldmq: I think there are some opportunity for concept re-use | 16:47 |
| samueldmq | lhcheng: do you think we can re-use some of that for policies ? | 16:48 |
| lhcheng | samueldmq: seems like for policy editing, we can use some of the its existing component | 16:48 |
| *** yottatsa has quit IRC | 16:48 | |
| samueldmq | lhcheng: nice, anyway it will be only for M in Horizon (or later), as we are still trying to finish our side (keystone) this cycle | 16:48 |
| samueldmq | lhcheng: hmm, so he is really talking about re-using the UI components | 16:49 |
| samueldmq | lhcheng: I will thank him and say we will take his comments/suggestions in consideration when we start creating the horizon side of policies | 16:50 |
| samueldmq | lhcheng: or if he's aiming to implement that ... :-) | 16:50 |
| lhcheng | samueldmq: yeah, that's what I thought. | 16:51 |
| breton | or we can invite him here | 16:51 |
| samueldmq | lhcheng: nice | 16:51 |
| lhcheng | samueldmq: I think the workbook is oookay.. but there are still a lot things needed. like how to build rules | 16:51 |
| lhcheng | samueldmq: otherwise, it is just looks like a fancier input for key/value pairs | 16:52 |
| breton | afaik mistral is a not a ready solution, it's a framework | 16:52 |
| samueldmq | lhcheng: yes, and we're having some hard times to get our work in policies for this cycle | 16:52 |
| samueldmq | lhcheng: waiting a bit more to look how it's going to change over the next cycle is safe to then start looking at the interface details | 16:53 |
| samueldmq | lhcheng: if that makes sense .. | 16:53 |
| samueldmq | breton: cc ^ | 16:53 |
| *** jasonsb has quit IRC | 16:54 | |
| *** piyanai has quit IRC | 16:55 | |
| *** ankita_wagh has joined #openstack-keystone | 16:55 | |
| lhcheng | samueldmq: defining the policy rule should still be the same.. like <rule#1> OR <rule#2>, role:<role_name> | 16:56 |
| lhcheng | samueldmq: they could start working on that | 16:57 |
| lhcheng | samueldmq: some sort of rule expression builder | 16:57 |
| samueldmq | lhcheng: hmm, yes | 16:57 |
| *** rdo has quit IRC | 16:57 | |
| *** tjcocozz has quit IRC | 16:57 | |
| samueldmq | lhcheng: yeah makes sense | 16:57 |
| samueldmq | lhcheng: as the role would still be in the same semantics, even though we provide better apis to create them | 16:58 |
| lhcheng | samueldmq: I think that would be the hard part for the ui | 16:58 |
| samueldmq | lhcheng: I meant rule :( | 16:58 |
| samueldmq | lhcheng: why is it the hard part for the ui ? | 16:58 |
| *** jsavak has quit IRC | 16:59 | |
| lhcheng | samueldmq: expression builder is usually hard to build right | 16:59 |
| *** rdo has joined #openstack-keystone | 16:59 | |
| *** jsavak has joined #openstack-keystone | 16:59 | |
| samueldmq | lhcheng: nice, so as soon as we start talking about it, we get it right earlier :-) | 17:00 |
| lhcheng | samueldmq: maybe this is where the new UX project can help | 17:00 |
| *** ankita_wagh has quit IRC | 17:00 | |
| lhcheng | tsufiev: ^ | 17:00 |
| samueldmq | lhcheng: new UX project ? what is that ? | 17:00 |
| lhcheng | samueldmq: there was a new UX project approved couple of weeks ago... | 17:00 |
| tsufiev | lhcheng, samueldmq: hello! | 17:01 |
| samueldmq | lhcheng: ah nice, tsufiev hi, I hadn't noticed you were available | 17:01 |
| samueldmq | tsufiev: so we were talking about your email in the ml earlier today :) | 17:01 |
| lhcheng | samueldmq: ux is the new openstack project for the month :P http://governance.openstack.org/reference/projects/openstack-ux.html | 17:02 |
| tsufiev | samueldmq, yeah, breton already pinged me, but I didn't realize that the discussion is right now ) | 17:02 |
| samueldmq | lhcheng: nice I am gonna take a look at it :) | 17:02 |
| tsufiev | IMO the hardest part in re-using Merlin UI elements for dynamic policies would be data model adoption | 17:03 |
| *** harlowja has joined #openstack-keystone | 17:03 | |
| samueldmq | lhcheng: hmmm, and that's the project piet is ptl of ? | 17:03 |
| lhcheng | samueldmq: I think interim until there is an election | 17:03 |
| tsufiev | at least some domain experts are needed (who know all the possible relations between policy elements) | 17:03 |
| samueldmq | lhcheng: nice | 17:03 |
| samueldmq | tsufiev: ok so basically each policy file is a set of rules, and each rule is composed by other rules or expressions, where an expression is a role check or scope check | 17:05 |
| samueldmq | (neutron has different checks, we need to look at them separately, with admiyo as well) | 17:05 |
| lhcheng | samueldmq: do we have a detailed doc somewhere explaining the semantics/expression that can be used in a rule? | 17:06 |
| *** pcaruana has joined #openstack-keystone | 17:06 | |
| samueldmq | admiyo: hey, you're camouflaged, I found you!! | 17:06 |
| samueldmq | lhcheng: hmm, I think so, let me find it | 17:06 |
| tsufiev | samueldmq, yeah, I already have kind of superficial acquaintance with policy syntax, what is needed to render them automatically with Merlin is knowing their grammar | 17:06 |
| lhcheng | samueldmq: AFAIR, only doc I found was the doc in the policy code :P | 17:07 |
| samueldmq | lhcheng: yes I think we only have this one | 17:07 |
| samueldmq | lhcheng: ok adding deployer doc on policy is on my todo | 17:07 |
| samueldmq | lhcheng: tsufiev https://github.com/openstack/oslo.policy/blob/master/oslo_policy/policy.py#L18-L210 | 17:08 |
| *** fhubik is now known as fhubik_afk | 17:08 | |
| *** samleon has joined #openstack-keystone | 17:10 | |
| *** jsavak has quit IRC | 17:14 | |
| tsufiev | samueldmq, added to my bookmarks | 17:14 |
| *** jsavak has joined #openstack-keystone | 17:14 | |
| *** piyanai has joined #openstack-keystone | 17:17 | |
| breton | tsufiev: http://docs.openstack.org/kilo/config-reference/content/policy-json-file.html might also be useful | 17:18 |
| *** tqtran has joined #openstack-keystone | 17:19 | |
| *** mylu has quit IRC | 17:21 | |
| *** e0ne has joined #openstack-keystone | 17:22 | |
| *** fhubik_afk is now known as fhubik | 17:23 | |
| tsufiev | breton, thanks | 17:23 |
| *** spandhe has joined #openstack-keystone | 17:24 | |
| *** fhubik is now known as fhubik_afk | 17:29 | |
| *** henrynash has joined #openstack-keystone | 17:30 | |
| *** ChanServ sets mode: +v henrynash | 17:30 | |
| *** browne has joined #openstack-keystone | 17:30 | |
| *** chlong has quit IRC | 17:31 | |
| *** e0ne has quit IRC | 17:31 | |
| *** spandhe_ has joined #openstack-keystone | 17:32 | |
| *** hrou has quit IRC | 17:32 | |
| *** spandhe has quit IRC | 17:32 | |
| *** spandhe_ is now known as spandhe | 17:32 | |
| *** fhubik_afk is now known as fhubik | 17:36 | |
| *** mylu has joined #openstack-keystone | 17:38 | |
| *** diazjf has quit IRC | 17:39 | |
| *** e0ne has joined #openstack-keystone | 17:42 | |
| *** TheIntern has joined #openstack-keystone | 17:42 | |
| *** tjcocozz has joined #openstack-keystone | 17:45 | |
| *** fhubik is now known as fhubik_afk | 17:48 | |
| *** jsavak has quit IRC | 17:53 | |
| *** piyanai has quit IRC | 17:55 | |
| *** jsavak has joined #openstack-keystone | 17:56 | |
| *** fhubik_afk is now known as fhubik | 17:57 | |
| *** piyanai has joined #openstack-keystone | 17:59 | |
| *** jasonsb has joined #openstack-keystone | 18:01 | |
| *** jsavak has quit IRC | 18:02 | |
| *** jsavak has joined #openstack-keystone | 18:02 | |
| *** openstackgerrit_ has quit IRC | 18:07 | |
| *** piyanai has quit IRC | 18:15 | |
| *** piyanai has joined #openstack-keystone | 18:20 | |
| *** harlowja has quit IRC | 18:21 | |
| *** Kennan has quit IRC | 18:21 | |
| *** harlowja has joined #openstack-keystone | 18:21 | |
| *** Kennan has joined #openstack-keystone | 18:29 | |
| *** diazjf has joined #openstack-keystone | 18:29 | |
| *** htruta_ has quit IRC | 18:32 | |
| *** mylu has quit IRC | 18:32 | |
| *** tjcocozz has quit IRC | 18:36 | |
| *** josecastroleon has joined #openstack-keystone | 18:36 | |
| *** admiyo has quit IRC | 18:37 | |
| openstackgerrit | Brant Knudson proposed openstack/keystone: Add LimitRequestBody to sample httpd config https://review.openstack.org/208208 | 18:38 |
| *** TheIntern has quit IRC | 18:44 | |
| *** htruta_ has joined #openstack-keystone | 18:44 | |
| *** kiran-r has quit IRC | 18:45 | |
| *** amakarov is now known as amakarov_away | 18:46 | |
| *** TheIntern has joined #openstack-keystone | 18:46 | |
| openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Fixes query.one() return usage in endpoint-policy https://review.openstack.org/208609 | 18:47 |
| dstanek | samueldmq: i'll take another look at those reviews for you in a little bit. technically today is a volunteer (vacation) day, but i've been doing other things on breaks | 18:48 |
| samueldmq | dstanek: btw this one is a very easy but interesting review ^ :) | 18:48 |
| samueldmq | dstanek: nice, I do appreciate your help. Feel free to take a look tomorrow, enjoy your vacation day | 18:49 |
| dstanek | samueldmq: cool, i'll look at that to | 18:49 |
| dstanek | o | 18:49 |
| dstanek | samueldmq: i'm actually volunteering for a local non-profit - doing "hard" labor | 18:49 |
| samueldmq | dstanek: very nice :) | 18:50 |
| *** tqtran is now known as tqtran-afk | 18:52 | |
| *** mylu has joined #openstack-keystone | 18:53 | |
| *** urulama has quit IRC | 19:01 | |
| *** samleon has quit IRC | 19:02 | |
| *** urulama has joined #openstack-keystone | 19:02 | |
| *** josecastroleon has quit IRC | 19:06 | |
| *** flwang has quit IRC | 19:08 | |
| openstackgerrit | Sergey Vilgelm proposed openstack/oslo.policy: [WIP] Add parse_rules method the the Rules class https://review.openstack.org/208617 | 19:10 |
| *** e0ne has quit IRC | 19:11 | |
| openstackgerrit | Marianne Linhares Monteiro proposed openstack/keystone: List credentials by type https://review.openstack.org/208620 | 19:11 |
| raildo | gyee: henrynash ^ Marianne is for our team too :) | 19:13 |
| *** jsavak has quit IRC | 19:14 | |
| *** jsavak has joined #openstack-keystone | 19:14 | |
| *** flwang has joined #openstack-keystone | 19:22 | |
| *** fhubik has quit IRC | 19:26 | |
| *** ayoung has joined #openstack-keystone | 19:26 | |
| *** ChanServ sets mode: +v ayoung | 19:26 | |
| *** mylu has quit IRC | 19:30 | |
| openstackgerrit | Marianne Linhares Monteiro proposed openstack/keystone: List credentials by type https://review.openstack.org/208620 | 19:31 |
| *** mylu has joined #openstack-keystone | 19:33 | |
| *** jsavak has quit IRC | 19:33 | |
| *** piyanai has quit IRC | 19:47 | |
| *** raildo has quit IRC | 19:49 | |
| *** jsavak has joined #openstack-keystone | 19:50 | |
| lhcheng | bknudson: regarding the default setting of 16k for LimitRequestBody : https://review.openstack.org/#/c/208208/ | 19:53 |
| lhcheng | bknudson: I am not sure either what the right setting should be (that it won't have issue when posting a mapping or policy file) | 19:54 |
| lhcheng | maybe gyee marekd or samueldmq may have some input ^ | 19:54 |
| bknudson | lhcheng: the current max size is 114688 , from http://git.openstack.org/cgit/openstack/keystone/tree/etc/keystone.conf.sample#n1596 | 19:55 |
| bknudson | a.k.a 112k | 19:57 |
| bknudson | which seems excessive. | 19:57 |
| lhcheng | bknudson: do you recall how we came up with the magic number? :) | 19:57 |
| bknudson | lhcheng: that's coming from oslo.middleware, so they came up with it there. | 19:58 |
| bknudson | that has to work openstack-wide, not just on keystone. | 19:58 |
| bknudson | it's not large enough for an image, though. | 19:58 |
| lhcheng | bknudson: hmm that may not apply for image, I recall uploading an image at least 20mb in size | 20:01 |
| bknudson | ah, nobody uploads images into glance anyways... should be posting them on a web server and giving glance the url. | 20:01 |
| lhcheng | yup, they should :) | 20:02 |
| lhcheng | bknudson: yeah, 112k sounds excessive. But would changing our sample config to a smaller value means it could break backward compatibility? | 20:03 |
| bknudson | sample config can't break anything | 20:03 |
| bknudson | I'll make it 112k and we can worry about the value later. | 20:06 |
| lhcheng | bknudson: okay, that sounds good to me | 20:06 |
| *** piyanai has joined #openstack-keystone | 20:12 | |
| *** phalmos has joined #openstack-keystone | 20:13 | |
| *** boltR has joined #openstack-keystone | 20:16 | |
| boltR | question.. if i disable in a service in keystone v3, will the service still show up in the catalog? | 20:16 |
| boltR | if i disable a service* | 20:17 |
| phalmos | Is it expected behavior when going from single-domain LDAP to multi-domain LDAP that all existing user roles become invalid and need to be re-done? | 20:19 |
| *** opilotte has joined #openstack-keystone | 20:29 | |
| opilotte | question: with OS-FEDERATION, is it possible to map multiple group IDs ? | 20:30 |
| openstackgerrit | Marianne Linhares Monteiro proposed openstack/keystone: List credentials by type https://review.openstack.org/208620 | 20:31 |
| *** hrou has joined #openstack-keystone | 20:44 | |
| gyee | opilotte, try using 'groups' | 20:51 |
| gyee | lhcheng, bknudson, 16K default should be fine | 20:52 |
| gyee | besides, if that's not good enough for a specific deployment, we'll let the deployment script bump it up | 20:52 |
| opilotte | gyee: so in identity values (returned by the IdP) 'groups': ['id_1', 'id_2', ...] ? | 20:54 |
| gyee | opilotte, groups are names only | 20:55 |
| *** diazjf has left #openstack-keystone | 20:55 | |
| gyee | for example, “local”: [ | 20:55 |
| gyee | { | 20:55 |
| gyee | “groups”: {0}, | 20:55 |
| gyee | “domain”: {“name”: “Default”} | 20:55 |
| gyee | } | 20:55 |
| gyee | ], | 20:55 |
| gyee | “remote”: [ | 20:55 |
| gyee | { | 20:55 |
| gyee | “type”: “REMOTE_USER_GROUPS” | 20:55 |
| gyee | } | 20:55 |
| gyee | ] | 20:55 |
| *** jsavak has quit IRC | 20:55 | |
| gyee | or "groups": ["group1", "group2"], | 20:55 |
| openstackgerrit | Merged openstack/keystone: Refactor: clean up TokenAPITests https://review.openstack.org/203250 | 20:57 |
| opilotte | gyee: it works it IDs for me | 20:57 |
| *** bapalm_ has quit IRC | 21:00 | |
| openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/208652 | 21:05 |
| gyee | ayoung, u coming to the Ops MidCycle in two weeks? http://www.eventbrite.com/e/openstack-ops-mid-cycle-meetup-tickets-17703258924 | 21:07 |
| ayoung | gyee, nope | 21:07 |
| gyee | great place to sell your dynamic policy stuff | 21:07 |
| ayoung | gyee, please be my proxy | 21:08 |
| gyee | ayoung, sure will try | 21:08 |
| ayoung | ++ | 21:08 |
| gyee | ayoung, I plan on attending OpenStack Silicon Valley as well | 21:08 |
| ayoung | ++ | 21:08 |
| gyee | lets see if we can find some audience for it | 21:09 |
| openstackgerrit | Henrique Truta proposed openstack/keystone: Honor domain operations in project table https://review.openstack.org/143763 | 21:14 |
| *** henrynash has quit IRC | 21:16 | |
| *** henrynash has joined #openstack-keystone | 21:16 | |
| *** ChanServ sets mode: +v henrynash | 21:16 | |
| lhcheng | gyee: do they have a free pass for OpenStack Silicon valley? | 21:20 |
| lhcheng | gyee: I contacted the organizer, they said they have not offered it "yet" | 21:21 |
| gyee | lhcheng, I though you can registered as a foundation member | 21:22 |
| gyee | not sure if that'll work | 21:23 |
| lhcheng | gyee: I don't see a way to register as foudation member. | 21:24 |
| lhcheng | I've sent an email to the organizer 1.5 months back, they told to wait and they'll inform us. | 21:24 |
| openstackgerrit | Merged openstack/keystone: Update exported variables for openstack client https://review.openstack.org/208120 | 21:25 |
| openstackgerrit | Merged openstack/keystone: Missing ADMIN_USER in sample_data.sh https://review.openstack.org/208121 | 21:25 |
| morganfainberg | Im skipping openstack sv | 21:25 |
| lhcheng | I guess the organizer don't want more contributors going :P | 21:25 |
| gyee | I registered as foundation member three weeks back, maybe it was a glitch/bug in the system :) | 21:25 |
| lhcheng | gyee: haha awesome timing :P | 21:25 |
| gyee | maybe they'll bounce me at the door, we'll see | 21:26 |
| openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/208652 | 21:26 |
| lhcheng | gyee: you'll be our keystone rep for openstack sv then :D | 21:26 |
| morganfainberg | Im totally going as openstack proposal bot | 21:27 |
| morganfainberg | :P | 21:27 |
| gyee | hahahah | 21:27 |
| morganfainberg | That bot has mad contributions | 21:27 |
| *** tqtran-afk is now known as tqtran | 21:27 | |
| openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/208652 | 21:27 |
| openstackgerrit | Lance Bragstad proposed openstack/keystone: Improve endpoint filtering docs https://review.openstack.org/208660 | 21:27 |
| openstackgerrit | Merged openstack/keystone: Clean up notifications type checking https://review.openstack.org/200733 | 21:30 |
| openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/208652 | 21:32 |
| openstackgerrit | Merged openstack/keystone: Clean up code to use .items() https://review.openstack.org/200734 | 21:34 |
| openstackgerrit | Merged openstack/keystone: Fix test_utils for py34 https://review.openstack.org/203896 | 21:34 |
| openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/208652 | 21:35 |
| openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/208652 | 21:36 |
| *** TheIntern has quit IRC | 21:36 | |
| openstackgerrit | Merged openstack/python-keystoneclient: Remove check for requests version https://review.openstack.org/208217 | 21:41 |
| openstackgerrit | Merged openstack/python-keystoneclient: Clarify setting socket_options https://review.openstack.org/208218 | 21:42 |
| *** piyanai has quit IRC | 21:43 | |
| openstackgerrit | Merged openstack/python-keystoneclient: Proper deprecation for Dicover.raw_version_data unstable parameter https://review.openstack.org/205690 | 21:43 |
| openstackgerrit | Merged openstack/python-keystoneclient: Proper deprecation for httpclient.request() https://review.openstack.org/205699 | 21:43 |
| lbragstad | random noob federation question - the metadata exchange between the service provider and the identity provider is what builds the trust between the two, correct? | 21:44 |
| *** jasonsb has quit IRC | 21:51 | |
| gyee | lbragstad, yes, saml2 is a digitally signed document, and the SP needs to trust the signing key | 21:52 |
| openstackgerrit | Merged openstack/python-keystoneclient: Fix tests passing user, project, and token https://review.openstack.org/205700 | 21:55 |
| *** jecarey has quit IRC | 21:56 | |
| openstackgerrit | Brant Knudson proposed openstack/keystone: Remove unnecessary check from notifications.py https://review.openstack.org/203069 | 22:03 |
| *** thedodd has quit IRC | 22:04 | |
| *** mylu has quit IRC | 22:08 | |
| *** opilotte has quit IRC | 22:08 | |
| openstackgerrit | Alberto Murillo proposed openstack/keystone: disable admin_token by default https://review.openstack.org/185464 | 22:18 |
| *** piyanai has joined #openstack-keystone | 22:30 | |
| *** pauloewerton has quit IRC | 22:33 | |
| *** btully has joined #openstack-keystone | 22:43 | |
| *** jasonsb has joined #openstack-keystone | 22:45 | |
| *** dims_ has joined #openstack-keystone | 22:51 | |
| *** dims has quit IRC | 22:52 | |
| *** dims has joined #openstack-keystone | 22:53 | |
| *** bknudson has quit IRC | 22:56 | |
| *** dims_ has quit IRC | 22:56 | |
| *** jaosorior has quit IRC | 23:04 | |
| *** fangzhou has joined #openstack-keystone | 23:09 | |
| *** aix has quit IRC | 23:12 | |
| *** piyanai has quit IRC | 23:16 | |
| *** darrenc has quit IRC | 23:23 | |
| *** darrenc has joined #openstack-keystone | 23:23 | |
| *** sigmavirus24 is now known as sigmavirus24_awa | 23:24 | |
| *** topol has quit IRC | 23:25 | |
| *** dims has quit IRC | 23:29 | |
| *** darrenc has quit IRC | 23:35 | |
| *** darrenc has joined #openstack-keystone | 23:35 | |
| *** phalmos has quit IRC | 23:36 | |
| *** darrenc is now known as darrenc_afk | 23:45 | |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!