*** markvoelker has quit IRC | 00:02 | |
*** dims_ has joined #openstack-keystone | 00:02 | |
*** chlong has joined #openstack-keystone | 00:03 | |
bigjools | will see if I can come over after lunch, depends on the mrs | 00:04 |
---|---|---|
*** dimsum__ has quit IRC | 00:04 | |
*** ankita_w_ has joined #openstack-keystone | 00:11 | |
*** ankita_wagh has quit IRC | 00:14 | |
morganfainberg | bigjools: are you hiding around the sprint area(s) | 00:23 |
bigjools | morganfainberg: I'm at home! | 00:23 |
morganfainberg | bigjools: ahhh | 00:23 |
bigjools | the mrs is out this morning and we have a needy dog that can't be left on her own | 00:24 |
morganfainberg | bigjools: ah ok | 00:28 |
bigjools | I'll try to get over later | 00:29 |
*** Kennan has left #openstack-keystone | 00:29 | |
morganfainberg | jamielennox: https://review.openstack.org/#/c/190532/ if you don't mind taking a look | 00:31 |
morganfainberg | (backlog) | 00:31 |
*** dims_ has quit IRC | 00:50 | |
*** dimsum__ has joined #openstack-keystone | 00:53 | |
*** lhcheng has joined #openstack-keystone | 00:55 | |
*** ChanServ sets mode: +v lhcheng | 00:55 | |
openstackgerrit | Merged openstack/keystoneauth: Expose bug in AccessToken https://review.openstack.org/205094 | 00:56 |
openstackgerrit | Merged openstack/keystoneauth: Fix decorators of properties in AccessToken https://review.openstack.org/205209 | 01:02 |
*** jamielennox is now known as jamielennox|away | 01:08 | |
*** ankita_w_ has quit IRC | 01:15 | |
*** ankita_wagh has joined #openstack-keystone | 01:16 | |
*** dimsum__ has quit IRC | 01:25 | |
*** dimsum__ has joined #openstack-keystone | 01:28 | |
bigjools | jamielennox|away, morganfainberg: I am heading your way now, will be there in around an hour. | 01:30 |
*** jsavak has joined #openstack-keystone | 01:31 | |
*** davechen has joined #openstack-keystone | 01:32 | |
morganfainberg | bigjools: jamielennox|away wandered off but will be back in a couple hours | 01:33 |
morganfainberg | we are here | 01:33 |
bigjools | morganfainberg: which room? | 01:35 |
morganfainberg | grand windsor room | 01:35 |
bigjools | ok cool, see you soon | 01:35 |
morganfainberg | where the afternoon teas were | 01:35 |
*** jsavak has quit IRC | 01:36 | |
*** piyanai has joined #openstack-keystone | 01:39 | |
*** davechen1 has joined #openstack-keystone | 01:46 | |
*** davechen has quit IRC | 01:49 | |
*** davechen has joined #openstack-keystone | 01:54 | |
*** davechen1 has quit IRC | 01:56 | |
*** markvoelker has joined #openstack-keystone | 01:59 | |
*** dimsum__ has quit IRC | 02:02 | |
*** markvoelker has quit IRC | 02:03 | |
*** kiran-r has joined #openstack-keystone | 02:27 | |
*** kiran-r has quit IRC | 02:27 | |
*** topol has joined #openstack-keystone | 02:28 | |
*** ChanServ sets mode: +v topol | 02:28 | |
*** piyanai has quit IRC | 02:29 | |
*** topol has quit IRC | 02:33 | |
*** hakimo_ has joined #openstack-keystone | 02:52 | |
*** piyanai has joined #openstack-keystone | 02:53 | |
*** hakimo has quit IRC | 02:54 | |
*** alejandrito has quit IRC | 03:12 | |
*** topol has joined #openstack-keystone | 03:20 | |
*** ChanServ sets mode: +v topol | 03:20 | |
*** topol has quit IRC | 03:24 | |
*** jecarey has joined #openstack-keystone | 03:33 | |
*** piyanai has quit IRC | 03:58 | |
*** Daviey has quit IRC | 03:59 | |
*** markvoelker has joined #openstack-keystone | 04:00 | |
*** piyanai has joined #openstack-keystone | 04:04 | |
*** markvoelker has quit IRC | 04:04 | |
*** piyanai has quit IRC | 04:06 | |
*** jecarey has quit IRC | 04:17 | |
*** boris-42 has joined #openstack-keystone | 04:18 | |
*** jamielennox|away is now known as jamielennox | 04:38 | |
*** Daviey has joined #openstack-keystone | 04:58 | |
*** kiran-r has joined #openstack-keystone | 05:03 | |
*** Nirupama has joined #openstack-keystone | 05:05 | |
openstackgerrit | Andrey Pavlov proposed openstack/keystonemiddleware: Adding parse of protocol v4 of AWS auth to ec2_token https://review.openstack.org/205440 | 05:19 |
*** urulama has joined #openstack-keystone | 05:20 | |
*** yottatsa has joined #openstack-keystone | 05:21 | |
*** yottatsa has quit IRC | 05:21 | |
*** btully has quit IRC | 05:30 | |
breton | good morning, keystone | 05:34 |
*** yottatsa has joined #openstack-keystone | 05:35 | |
*** afazekas has joined #openstack-keystone | 05:37 | |
*** harlowja has quit IRC | 05:44 | |
*** afazekas has quit IRC | 05:46 | |
*** afazekas has joined #openstack-keystone | 05:49 | |
*** josecastroleon has joined #openstack-keystone | 05:58 | |
*** markvoelker has joined #openstack-keystone | 06:01 | |
*** ParsectiX has joined #openstack-keystone | 06:04 | |
*** markvoelker has quit IRC | 06:05 | |
morganfainberg | sooooo | 06:07 |
morganfainberg | just got almost everything working for uwsgi. soooooo easy | 06:08 |
morganfainberg | dstanek: ^^ | 06:08 |
*** pcaruana has quit IRC | 06:09 | |
*** Kennan has joined #openstack-keystone | 06:11 | |
*** lhcheng has quit IRC | 06:11 | |
morganfainberg | lbragstad, dstanek, dolph, (cc bknudson) : starting a fresh checkout of keystone (keystone-deploy) I get 2015-08-03 05:45:25.211 96 WARNING oslo_log.versionutils [-] Deprecated: direct import of driver is deprecated as of Liberty in favor of entrypoints and may be removed in N. | 06:12 |
morganfainberg | haven't looked if this is a default issue or a keystone-deploy issue | 06:12 |
*** yottatsa has quit IRC | 06:22 | |
*** belmoreira has joined #openstack-keystone | 06:25 | |
*** afazekas has quit IRC | 06:27 | |
*** afazekas has joined #openstack-keystone | 06:31 | |
breton | uwsgi is good | 06:40 |
*** geoffarn_ has joined #openstack-keystone | 06:47 | |
*** geoffarnold has quit IRC | 06:50 | |
*** browne1 has quit IRC | 07:04 | |
*** yottatsa has joined #openstack-keystone | 07:04 | |
*** e0ne has joined #openstack-keystone | 07:06 | |
*** boris-42 has quit IRC | 07:10 | |
*** henrynash has joined #openstack-keystone | 07:12 | |
*** ChanServ sets mode: +v henrynash | 07:12 | |
openstackgerrit | Marek Denis proposed openstack/keystone: Refactor: rename Fernet's unscoped federated payload https://review.openstack.org/202190 | 07:13 |
*** jsheeren has joined #openstack-keystone | 07:17 | |
*** e0ne has quit IRC | 07:21 | |
*** ankita_wagh has quit IRC | 07:28 | |
*** fhubik has joined #openstack-keystone | 07:35 | |
*** vivekd has joined #openstack-keystone | 07:35 | |
*** chlong has quit IRC | 07:38 | |
*** pcaruana has joined #openstack-keystone | 07:40 | |
*** bdossant has joined #openstack-keystone | 07:46 | |
*** mhu has quit IRC | 07:46 | |
*** hrou has quit IRC | 07:47 | |
*** e0ne has joined #openstack-keystone | 07:52 | |
*** e0ne has quit IRC | 07:55 | |
*** jamielennox is now known as jamielennox|away | 07:57 | |
*** yottatsa has quit IRC | 07:57 | |
*** lhcheng has joined #openstack-keystone | 08:00 | |
*** ChanServ sets mode: +v lhcheng | 08:00 | |
*** markvoelker has joined #openstack-keystone | 08:02 | |
*** lhcheng has quit IRC | 08:04 | |
*** markvoelker has quit IRC | 08:06 | |
*** geoffarn_ has quit IRC | 08:10 | |
*** jistr has joined #openstack-keystone | 08:15 | |
*** henrynash has quit IRC | 08:16 | |
*** aix has joined #openstack-keystone | 08:18 | |
openstackgerrit | Merged openstack/keystone: Refactor _populate_roles_for_groups() https://review.openstack.org/207785 | 08:30 |
*** mhu has joined #openstack-keystone | 08:40 | |
ParsectiX | guys here is mandatory to pass project_id http://docs.openstack.org/developer/python-keystoneclient/using-api-v3.html#authenticating-using-sessions | 08:42 |
ParsectiX | ? | 08:42 |
marekd | ParsectiX: as opposed to 'tenant' ? | 08:43 |
ParsectiX | I'm trying to pass only username and password and it fails to auth | 08:44 |
marekd | ParsectiX: with what error? | 08:44 |
*** mhu has quit IRC | 08:44 | |
ParsectiX | keystoneclient.openstack.common.apiclient.exceptions.BadRequest: Expecting to find domain in user - the server could not comply with the request since it is either malformed or otherwise incorrect. The client is assumed to be in error. (HTTP 400) | 08:44 |
marekd | "Expecting to find domain in user" | 08:45 |
ParsectiX | yeap | 08:45 |
marekd | so...? | 08:45 |
ParsectiX | what's that ? | 08:45 |
marekd | add OS_USER_DOMAIN_NAME | 08:45 |
ParsectiX | where can I find this info for an already existing user ? | 08:46 |
ParsectiX | in the RC file does not included. | 08:46 |
marekd | which API are you using? | 08:47 |
marekd | API version | 08:47 |
ParsectiX | V3 | 08:47 |
marekd | so rc files are for v2 for now | 08:47 |
marekd | try domain 'defau;t' | 08:47 |
ParsectiX | ohh okay | 08:47 |
marekd | default | 08:47 |
ParsectiX | no luck | 08:48 |
marekd | ParsectiX: so that's strange because i am getting different error: Set a scope, such as a project or domain, set a project scope with --os-project-name, OS_PROJECT_NAME or auth.project_name, set a domain scope with --os-domain-name, OS_DOMAIN_NAME or auth.domain_name | 08:49 |
marekd | which is more like something you are talking about, but clearly you provided different log. | 08:50 |
ParsectiX | I'm not using the env. variables. I'm trying to pass the values to authentication = v3.Password(...) function | 08:51 |
marekd | ParsectiX: so how did you call it? | 08:52 |
marekd | what params did you provide? | 08:52 |
ParsectiX | auth_url, username, password and now domain_name | 08:53 |
ParsectiX | i set the domain_name=None | 08:53 |
ParsectiX | also tried "default" | 08:53 |
marekd | ParsectiX: did it work with project specified? | 08:53 |
ParsectiX | No | 08:54 |
ParsectiX | I was using this http://docs.openstack.org/developer/python-keystoneclient/using-api-v3.html#non-session-authentication-deprecated | 08:54 |
ParsectiX | and now I'm trying to migrate to use sessions | 08:54 |
marekd | http://www.jamielennox.net/blog/2014/09/15/how-to-use-keystoneclient-sessions/ | 08:56 |
ParsectiX | Thanks let me read it | 08:56 |
marekd | aha, and why asking if it will work without project since it didn't even work the "old way" ? | 08:56 |
ParsectiX | I thought maybe that was the issue | 08:57 |
marekd | aha | 08:57 |
ParsectiX | marekd: Thanks for your help | 08:57 |
marekd | ParsectiX: you welcome | 08:58 |
ParsectiX | marekd: it worked. the issue was to add those two arguments | 09:00 |
ParsectiX | user_domain_name='default', | 09:00 |
ParsectiX | project_domain_name='default' | 09:00 |
marekd | ok | 09:01 |
marekd | col | 09:01 |
marekd | cool | 09:01 |
*** e0ne has joined #openstack-keystone | 09:08 | |
openstackgerrit | Boris Bobrov proposed openstack/keystone-specs: Remove KDS from the list of api extensions https://review.openstack.org/208383 | 09:17 |
*** lexloofer is now known as lxsli | 09:20 | |
*** urulama has quit IRC | 09:21 | |
*** urulama has joined #openstack-keystone | 09:22 | |
breton | http://developer.openstack.org/api-ref-identity-v2-ext.html#os-ksvalidate-ext -- where does this section come from? I can't find any reference to OS-KSVALIDATE in keystone-specs | 09:23 |
*** fhubik is now known as fhubik_afk | 09:26 | |
*** fhubik_afk is now known as fhubik | 09:26 | |
*** fhubik is now known as fhubik_afk | 09:27 | |
ParsectiX | Guys do you have any Doc mapping the old implementations of V2 to V3 ? | 09:36 |
ParsectiX | As an example I used this http://docs.openstack.org/developer/python-keystoneclient/api/keystoneclient.service_catalog.html#module-keystoneclient.service_catalog | 09:36 |
ParsectiX | to get the service catalog | 09:36 |
ParsectiX | and now looking how to do it with V3 | 09:37 |
ParsectiX | and after some research i concluded that those functions are now in endpoint manager | 09:38 |
*** fhubik_afk is now known as fhubik | 09:44 | |
*** marzif_ has quit IRC | 09:46 | |
*** marzif_ has joined #openstack-keystone | 09:47 | |
*** marzif_ has quit IRC | 09:48 | |
*** lhcheng has joined #openstack-keystone | 09:49 | |
*** ChanServ sets mode: +v lhcheng | 09:49 | |
morganfainberg | breton: those api docs are wronf | 09:53 |
morganfainberg | Wrong | 09:53 |
*** lhcheng has quit IRC | 09:53 | |
morganfainberg | breton: use the specs.openstack.org docs | 09:53 |
*** davechen has left #openstack-keystone | 09:54 | |
*** marzif has joined #openstack-keystone | 09:57 | |
breton | morganfainberg: maybe we should ping someone to remove it | 09:58 |
morganfainberg | It is an active docs bug / | 09:59 |
morganfainberg | Been raised before. | 09:59 |
breton | ok. | 09:59 |
morganfainberg | It shouldnt be removed, but updated automatically | 09:59 |
*** markvoelker has joined #openstack-keystone | 10:02 | |
*** yottatsa has joined #openstack-keystone | 10:04 | |
*** aix has quit IRC | 10:06 | |
*** markvoelker has quit IRC | 10:07 | |
*** Kennan has quit IRC | 10:07 | |
*** blogan has quit IRC | 10:08 | |
*** Guest58084 has quit IRC | 10:08 | |
*** HenryG has quit IRC | 10:08 | |
*** HenryG has joined #openstack-keystone | 10:08 | |
*** blogan has joined #openstack-keystone | 10:08 | |
*** Kennan has joined #openstack-keystone | 10:09 | |
*** Guest58084 has joined #openstack-keystone | 10:09 | |
*** lhcheng has joined #openstack-keystone | 10:13 | |
*** ChanServ sets mode: +v lhcheng | 10:13 | |
*** rdo has quit IRC | 10:14 | |
*** rdo has joined #openstack-keystone | 10:16 | |
*** e0ne has quit IRC | 10:16 | |
*** e0ne has joined #openstack-keystone | 10:17 | |
*** lhcheng has quit IRC | 10:18 | |
*** josecastroleon has quit IRC | 10:20 | |
*** dimsum__ has joined #openstack-keystone | 10:34 | |
*** urulama has quit IRC | 10:37 | |
*** urulama has joined #openstack-keystone | 10:38 | |
*** piyanai has joined #openstack-keystone | 10:49 | |
*** e0ne has quit IRC | 10:50 | |
*** pcaruana has quit IRC | 10:57 | |
*** josecastroleon has joined #openstack-keystone | 11:02 | |
*** marzif has quit IRC | 11:09 | |
*** marzif has joined #openstack-keystone | 11:10 | |
*** pcaruana has joined #openstack-keystone | 11:14 | |
*** dims_ has joined #openstack-keystone | 11:18 | |
*** dimsum__ has quit IRC | 11:20 | |
*** marzif has quit IRC | 11:27 | |
*** amakarov_away is now known as amakarov | 11:30 | |
*** edmondsw has joined #openstack-keystone | 11:31 | |
*** kiran-r has quit IRC | 11:31 | |
*** markvoelker has joined #openstack-keystone | 11:33 | |
*** markvoelker has quit IRC | 11:38 | |
*** fhubik is now known as fhubik_afk | 11:39 | |
*** rdo has quit IRC | 11:41 | |
*** rdo has joined #openstack-keystone | 11:42 | |
samueldmq | morning | 11:46 |
samueldmq | morganfainberg: hey | 11:47 |
samueldmq | morganfainberg: you got up early or hadn't went sleep yet or are you in a different tz ? | 11:47 |
samueldmq | morganfainberg: or ... :-) | 11:47 |
*** iurygregory has joined #openstack-keystone | 11:47 | |
morganfainberg | samueldmq: its 2148 here | 11:48 |
samueldmq | morganfainberg: uh where are you today ? | 11:48 |
morganfainberg | 2148, monday night that is | 11:48 |
samueldmq | morganfainberg: Australia? | 11:48 |
morganfainberg | samueldmq: hint - ill see koalas tomorrow | 11:49 |
morganfainberg | Yah | 11:49 |
morganfainberg | Brisbane | 11:49 |
samueldmq | morganfainberg: haha great | 11:49 |
morganfainberg | 3 more days here. | 11:50 |
samueldmq | morganfainberg: was looking for some pics, looks to be a great city | 11:50 |
morganfainberg | Fun so far. Good food etc | 11:50 |
samueldmq | nice, I suppose jamie is there as well | 11:50 |
marekd | morganfainberg: got a few minutes? | 11:51 |
samueldmq | pycon australia ? | 11:51 |
morganfainberg | samueldmq: yes and yes | 11:51 |
morganfainberg | marekd: a few. | 11:51 |
samueldmq | morganfainberg: yes! o/ | 11:51 |
samueldmq | morganfainberg: enjoy | 11:52 |
morganfainberg | marekd: talked with jamielennox|away btw, we have the short list of what is needed for keystoneauth | 11:52 |
morganfainberg | It's about 2-3 real | 11:52 |
marekd | morganfainberg: so, regarding revocations - we support revocation lists for uuid tokens, and do we have anything for fernet? Would it be revocation events? If so, does it work now? | 11:52 |
marekd | morganfainberg: great! | 11:52 |
morganfainberg | Patches. Maybe 5-6 if you count minor tweaks | 11:53 |
morganfainberg | Revocation events are used for fernet exclusively | 11:53 |
morganfainberg | Must use revocation events for fernet. Uuid can be either token revocation list or events | 11:53 |
marekd | morganfainberg: so ksm will query for both revocation lists and revocation events. | 11:53 |
morganfainberg | Ksm will not ever query for the events | 11:54 |
marekd | morganfainberg: how do i decide on what uuid should use (lists vs events) ? | 11:54 |
morganfainberg | Events are keystone side only (during validate) | 11:54 |
breton | marekd: events | 11:54 |
*** markvoelker_ has joined #openstack-keystone | 11:54 | |
breton | marekd: lists show some bad performance | 11:54 |
morganfainberg | But use events. | 11:54 |
marekd | breton: i know. | 11:54 |
*** dims_ has quit IRC | 11:54 | |
marekd | morganfainberg: so a service gets a token, it must send it to keystone in order to validate, and server will basically match token with event. | 11:55 |
morganfainberg | Yes | 11:55 |
morganfainberg | Uuid and fernet require keystone to validate | 11:55 |
marekd | morganfainberg: sure. | 11:55 |
morganfainberg | So it works. | 11:55 |
*** dimsum__ has joined #openstack-keystone | 11:55 | |
marekd | morganfainberg: so how is that better/faster ather than querying token table and checking if it's valid? | 11:56 |
marekd | ah, the process on invalidating tokens may take long so lots of tokesn... | 11:56 |
marekd | is that a reason ? | 11:56 |
*** fhubik_afk is now known as fhubik | 11:56 | |
morganfainberg | It is optimised for a balance of fernet and/or uuid. But if you have tons of tokens token lookup can be slow even with indexes | 11:56 |
marekd | morganfainberg: is ksm by default using revocation events? | 11:57 |
morganfainberg | Uuid will be faster revocations with a small table. However, events are more flexible and dont require table scans/updates of tons of rows | 11:57 |
morganfainberg | Keystonemiddleware doesnt look at revocation events at all directly | 11:57 |
*** htruta_ has joined #openstack-keystone | 11:58 | |
marekd | ksm, uh, right | 11:58 |
marekd | vadliation on server side. | 11:58 |
morganfainberg | Yep | 11:58 |
morganfainberg | Events need some | 11:59 |
marekd | revocation event should be created for every operation like user delete, project delete, domain delete, idp delete etc (same for disabling) | 11:59 |
morganfainberg | Love / profiling and updates. | 11:59 |
morganfainberg | So they can be made faster. But they are the better solution in most cases n | 11:59 |
marekd | morganfainberg: are revocation events some removed from the DB? Like...after some time or upon some action? | 12:01 |
morganfainberg | They are pruned on each new event | 12:01 |
morganfainberg | If they are expired on the next revocation, they are cleaned up. | 12:02 |
marekd | morganfainberg: smart. | 12:03 |
marekd | all the code to look into is actually keystone/contrbi/revoke | 12:04 |
marekd | ? | 12:04 |
marekd | morganfainberg: one more question - how a even "user was deleted" can actually expire? | 12:04 |
morganfainberg | Not sure what youre asking | 12:05 |
*** yottatsa_ has joined #openstack-keystone | 12:05 | |
marekd | morganfainberg: you said " If they are expired on the next revocation, they are cleaned up" | 12:05 |
marekd | morganfainberg: what was expired - tokens or events ? | 12:05 |
*** yottatsa has quit IRC | 12:06 | |
morganfainberg | The events | 12:07 |
*** dimsum__ has quit IRC | 12:08 | |
*** javier_ has joined #openstack-keystone | 12:08 | |
marekd | how can they expire? | 12:08 |
morganfainberg | So if an event is expired, when the next event is issued, we cleanup | 12:08 |
morganfainberg | They last for token_ttl + window | 12:08 |
morganfainberg | You dont need to keep them forever. They basically say "all tokens that match these rules from are invalid if they were issued before x datetime" | 12:09 |
marekd | morganfainberg: do we somewhere keep a time when was last token issued for this user/project/domain/something ? or it's statically calculated. | 12:09 |
morganfainberg | All tokens have an issued at time | 12:10 |
morganfainberg | Events are from the moment they are issued | 12:10 |
marekd | morganfainberg: ok, so expiration time of the event would be now() + tokens_ttl + window | 12:11 |
morganfainberg | So if i revoke all events for user x at midnight, (password change) the event is tied to when that password change occirrd | 12:11 |
morganfainberg | And lasts for the token ttl (config options) and some extra | 12:11 |
morganfainberg | Time | 12:11 |
morganfainberg | Yeah | 12:11 |
marekd | morganfainberg: ok, that's very helpful. | 12:12 |
marekd | thanks! | 12:12 |
marekd | not bothering you too much now! | 12:12 |
morganfainberg | Hehe | 12:12 |
morganfainberg | No worries. | 12:12 |
*** raildo has joined #openstack-keystone | 12:18 | |
*** dimsum__ has joined #openstack-keystone | 12:22 | |
*** yottatsa_ has quit IRC | 12:24 | |
*** marzif has joined #openstack-keystone | 12:24 | |
*** yottatsa has joined #openstack-keystone | 12:24 | |
*** e0ne has joined #openstack-keystone | 12:24 | |
*** marzif has quit IRC | 12:24 | |
*** yottatsa has quit IRC | 12:24 | |
*** javier_ has quit IRC | 12:25 | |
*** marzif has joined #openstack-keystone | 12:25 | |
openstackgerrit | Merged openstack/keystonemiddleware: Merge test-requirements-py3.txt to test-requirements.txt https://review.openstack.org/206044 | 12:26 |
*** dims_ has joined #openstack-keystone | 12:27 | |
*** dims__ has joined #openstack-keystone | 12:29 | |
*** dimsum__ has quit IRC | 12:29 | |
*** yottatsa has joined #openstack-keystone | 12:29 | |
*** Nirupama has quit IRC | 12:30 | |
*** dimsum__ has joined #openstack-keystone | 12:32 | |
*** marzif_ has joined #openstack-keystone | 12:32 | |
*** dims_ has quit IRC | 12:32 | |
*** mflobo has left #openstack-keystone | 12:32 | |
*** daemontool_ has joined #openstack-keystone | 12:33 | |
*** marzif has quit IRC | 12:33 | |
*** dims__ has quit IRC | 12:34 | |
*** chlong has joined #openstack-keystone | 12:35 | |
*** piyanai has quit IRC | 12:36 | |
*** urulama has quit IRC | 12:36 | |
*** urulama has joined #openstack-keystone | 12:37 | |
*** dims_ has joined #openstack-keystone | 12:45 | |
*** dimsum__ has quit IRC | 12:46 | |
*** daemontool_ is now known as marzif | 12:46 | |
*** yottatsa has quit IRC | 12:47 | |
lbragstad | morganfainberg: interesting, you didn't have fatal_deprecations enabled by default did you? | 12:51 |
*** dims_ has quit IRC | 12:53 | |
*** dimsum__ has joined #openstack-keystone | 12:54 | |
*** topol has joined #openstack-keystone | 12:54 | |
*** ChanServ sets mode: +v topol | 12:54 | |
*** dimsum__ is now known as dims | 12:55 | |
*** jsavak has joined #openstack-keystone | 12:57 | |
*** browne has joined #openstack-keystone | 12:57 | |
*** piyanai has joined #openstack-keystone | 12:57 | |
*** topol has quit IRC | 12:59 | |
*** jaosorior has joined #openstack-keystone | 12:59 | |
*** yottatsa has joined #openstack-keystone | 13:01 | |
*** markvoelker_ has quit IRC | 13:02 | |
*** jsavak has quit IRC | 13:04 | |
*** markvoelker has joined #openstack-keystone | 13:04 | |
*** topol has joined #openstack-keystone | 13:04 | |
*** ChanServ sets mode: +v topol | 13:04 | |
*** jsavak has joined #openstack-keystone | 13:04 | |
*** e0ne has quit IRC | 13:08 | |
*** e0ne has joined #openstack-keystone | 13:10 | |
*** aix has joined #openstack-keystone | 13:11 | |
*** browne has quit IRC | 13:13 | |
*** dsirrine has joined #openstack-keystone | 13:15 | |
*** piyanai has quit IRC | 13:19 | |
*** doug-fish has joined #openstack-keystone | 13:21 | |
*** boris-42 has joined #openstack-keystone | 13:22 | |
*** urulama has quit IRC | 13:23 | |
*** urulama has joined #openstack-keystone | 13:23 | |
*** dsirrine has quit IRC | 13:24 | |
*** zzzeek has joined #openstack-keystone | 13:24 | |
*** dsirrine has joined #openstack-keystone | 13:25 | |
*** bapalm has joined #openstack-keystone | 13:27 | |
*** TheIntern has joined #openstack-keystone | 13:30 | |
*** bdossant_ has joined #openstack-keystone | 13:32 | |
*** jsheeren has quit IRC | 13:33 | |
*** bdossant has quit IRC | 13:33 | |
*** ayoung has joined #openstack-keystone | 13:35 | |
*** ChanServ sets mode: +v ayoung | 13:35 | |
*** ayoung is now known as admiyo | 13:35 | |
*** bdossant_ has quit IRC | 13:37 | |
*** piyanai has joined #openstack-keystone | 13:38 | |
*** richm1 has joined #openstack-keystone | 13:38 | |
*** richm1 is now known as richm | 13:38 | |
*** bdossant has joined #openstack-keystone | 13:40 | |
*** tjcocozz has joined #openstack-keystone | 13:40 | |
*** tjcocozz_ has joined #openstack-keystone | 13:40 | |
-openstackstatus- NOTICE: The Gerrit service on review.openstack.org has been restarted in an attempt to improve performance. | 13:40 | |
*** tjcocozz_ has quit IRC | 13:40 | |
*** jistr is now known as jistr|mtg | 13:41 | |
*** marzif_ has quit IRC | 13:43 | |
*** marzif_ has joined #openstack-keystone | 13:44 | |
*** bdossant has quit IRC | 13:44 | |
*** h00327910__ has quit IRC | 13:48 | |
*** bknudson has quit IRC | 13:49 | |
*** browne has joined #openstack-keystone | 13:50 | |
*** vivekd has quit IRC | 13:50 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Unified delegation model https://review.openstack.org/208488 | 13:51 |
*** bapalm_ has joined #openstack-keystone | 13:51 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 13:54 | |
*** bapalm has quit IRC | 13:54 | |
*** piyanai has quit IRC | 13:58 | |
*** jsavak has quit IRC | 14:00 | |
*** jsavak has joined #openstack-keystone | 14:02 | |
*** josecastroleon has quit IRC | 14:02 | |
*** mylu has joined #openstack-keystone | 14:05 | |
*** browne has quit IRC | 14:08 | |
*** ParsectiX has quit IRC | 14:10 | |
*** afazekas has quit IRC | 14:12 | |
*** pballand has quit IRC | 14:12 | |
*** bknudson has joined #openstack-keystone | 14:13 | |
*** ChanServ sets mode: +v bknudson | 14:13 | |
*** fhubik is now known as fhubik_afk | 14:18 | |
*** yottatsa has quit IRC | 14:19 | |
*** jistr|mtg is now known as jistr | 14:20 | |
*** yottatsa has joined #openstack-keystone | 14:20 | |
*** fhubik_afk is now known as fhubik | 14:21 | |
*** jsavak has quit IRC | 14:22 | |
*** jsavak has joined #openstack-keystone | 14:23 | |
*** jiaxi has joined #openstack-keystone | 14:24 | |
*** yottatsa has quit IRC | 14:25 | |
*** yottatsa has joined #openstack-keystone | 14:26 | |
*** admiyo has quit IRC | 14:28 | |
*** yottatsa has quit IRC | 14:31 | |
*** jiaxi has quit IRC | 14:31 | |
*** afazekas has joined #openstack-keystone | 14:32 | |
*** yottatsa has joined #openstack-keystone | 14:33 | |
*** jsavak has quit IRC | 14:35 | |
*** jsavak has joined #openstack-keystone | 14:36 | |
*** jecarey has joined #openstack-keystone | 14:37 | |
*** yottatsa has quit IRC | 14:43 | |
*** admiyo has joined #openstack-keystone | 14:43 | |
*** hrou has joined #openstack-keystone | 14:58 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Remove oslo import hacking check https://review.openstack.org/208216 | 14:59 |
*** piyanai has joined #openstack-keystone | 14:59 | |
*** woodster_ has joined #openstack-keystone | 15:00 | |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone: Honor domain operations in project table https://review.openstack.org/143763 | 15:01 |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone: Change project name constraints https://review.openstack.org/158372 | 15:01 |
*** konstantin-m has joined #openstack-keystone | 15:02 | |
*** bdossant has joined #openstack-keystone | 15:05 | |
konstantin-m | Hello, can anyone please review https://review.openstack.org/#/c/207456/ ? | 15:06 |
*** yottatsa has joined #openstack-keystone | 15:08 | |
*** afazekas has quit IRC | 15:10 | |
*** pcaruana has quit IRC | 15:13 | |
*** diazjf has joined #openstack-keystone | 15:18 | |
*** bdossant has quit IRC | 15:24 | |
*** thedodd has joined #openstack-keystone | 15:28 | |
*** mylu has quit IRC | 15:30 | |
*** mylu has joined #openstack-keystone | 15:31 | |
*** jsavak has quit IRC | 15:33 | |
*** jsavak has joined #openstack-keystone | 15:34 | |
*** pballand has joined #openstack-keystone | 15:34 | |
*** pballand has quit IRC | 15:39 | |
*** mestery is now known as mestery_afk_toda | 15:42 | |
*** mestery_afk_toda is now known as mestery_afk | 15:42 | |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone: Honor domain operations in project table https://review.openstack.org/143763 | 15:44 |
*** belmoreira has quit IRC | 15:45 | |
*** gyee has joined #openstack-keystone | 15:47 | |
*** ChanServ sets mode: +v gyee | 15:47 | |
*** jiaxi_ has joined #openstack-keystone | 15:48 | |
jiaxi_ | dstanek: Hi,David | 15:48 |
jiaxi_ | I met a problem with tox. | 15:49 |
rodrigods | anyone willing to review the first patch in Reseller chain? https://review.openstack.org/#/c/157427/ | 15:49 |
jiaxi_ | when I run the cmd 'tox -i http://pypi.dev.ustack.com/simple -e py27 --notest' | 15:49 |
jiaxi_ | It failed | 15:50 |
jiaxi_ | The relative error info is ' http://pypi.dev.ustack.com/simple/python-keystoneclient/ uses an insecure transport scheme (http). Consider using https if pypi.dev.ustack.com has it available' | 15:50 |
*** openstackgerrit_ has joined #openstack-keystone | 15:54 | |
*** yottatsa has quit IRC | 15:57 | |
openstackgerrit | Brant Knudson proposed openstack/keystonemiddleware: Docstring updates https://review.openstack.org/208213 | 15:58 |
*** yottatsa has joined #openstack-keystone | 16:02 | |
*** _cjones_ has joined #openstack-keystone | 16:03 | |
*** jsavak has quit IRC | 16:04 | |
*** jsavak has joined #openstack-keystone | 16:06 | |
*** rdo has quit IRC | 16:07 | |
*** fhubik is now known as fhubik_afk | 16:07 | |
*** konstantin-m has quit IRC | 16:07 | |
*** rdo has joined #openstack-keystone | 16:08 | |
*** mylu has quit IRC | 16:08 | |
*** yottatsa has quit IRC | 16:09 | |
*** fhubik_afk is now known as fhubik | 16:09 | |
*** mylu has joined #openstack-keystone | 16:10 | |
*** jiaxi_ has quit IRC | 16:11 | |
*** lsmola has quit IRC | 16:11 | |
*** mylu has quit IRC | 16:14 | |
*** Ephur has joined #openstack-keystone | 16:14 | |
*** _cjones_ has quit IRC | 16:16 | |
*** browne has joined #openstack-keystone | 16:21 | |
*** mylu has joined #openstack-keystone | 16:22 | |
*** mylu has quit IRC | 16:25 | |
*** marzif_ has quit IRC | 16:25 | |
samueldmq | dstanek: hey sir, you around ? | 16:27 |
*** jistr has quit IRC | 16:28 | |
*** mylu has joined #openstack-keystone | 16:28 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Documentation for other services https://review.openstack.org/204801 | 16:29 |
*** jdandrea has joined #openstack-keystone | 16:29 | |
*** yottatsa has joined #openstack-keystone | 16:31 | |
*** geoffarnold has joined #openstack-keystone | 16:31 | |
*** lhcheng has joined #openstack-keystone | 16:37 | |
*** ChanServ sets mode: +v lhcheng | 16:37 | |
*** TheIntern has quit IRC | 16:37 | |
*** e0ne has quit IRC | 16:38 | |
*** yottatsa has quit IRC | 16:39 | |
samueldmq | lhcheng: hi | 16:40 |
lhcheng | samueldmq: hello! | 16:40 |
*** urulama has quit IRC | 16:40 | |
*** urulama has joined #openstack-keystone | 16:41 | |
samueldmq | lhcheng: there was a thread earlier today from someone talking about dynamic policies as UI component | 16:41 |
*** Guest23066 has quit IRC | 16:42 | |
samueldmq | lhcheng: the message is from Timur Sufiev from Mirantis and has 'UI for Keystone dynamic policies editing' as subject | 16:43 |
samueldmq | lhcheng: did you see that ? He posted a link of a demo where there is some interface he'd like to re-use for dynamic policies in horizon | 16:43 |
samueldmq | lhcheng: I'd appreciate some of your view on that (with your Horizon cap) | 16:44 |
samueldmq | :-) | 16:44 |
*** yottatsa has joined #openstack-keystone | 16:44 | |
*** browne has quit IRC | 16:45 | |
*** kiran-r has joined #openstack-keystone | 16:46 | |
lhcheng | samueldmq: I've seen the mistral workbook in the last summit | 16:47 |
lhcheng | samueldmq: I think there are some opportunity for concept re-use | 16:47 |
samueldmq | lhcheng: do you think we can re-use some of that for policies ? | 16:48 |
lhcheng | samueldmq: seems like for policy editing, we can use some of the its existing component | 16:48 |
*** yottatsa has quit IRC | 16:48 | |
samueldmq | lhcheng: nice, anyway it will be only for M in Horizon (or later), as we are still trying to finish our side (keystone) this cycle | 16:48 |
samueldmq | lhcheng: hmm, so he is really talking about re-using the UI components | 16:49 |
samueldmq | lhcheng: I will thank him and say we will take his comments/suggestions in consideration when we start creating the horizon side of policies | 16:50 |
samueldmq | lhcheng: or if he's aiming to implement that ... :-) | 16:50 |
lhcheng | samueldmq: yeah, that's what I thought. | 16:51 |
breton | or we can invite him here | 16:51 |
samueldmq | lhcheng: nice | 16:51 |
lhcheng | samueldmq: I think the workbook is oookay.. but there are still a lot things needed. like how to build rules | 16:51 |
lhcheng | samueldmq: otherwise, it is just looks like a fancier input for key/value pairs | 16:52 |
breton | afaik mistral is a not a ready solution, it's a framework | 16:52 |
samueldmq | lhcheng: yes, and we're having some hard times to get our work in policies for this cycle | 16:52 |
samueldmq | lhcheng: waiting a bit more to look how it's going to change over the next cycle is safe to then start looking at the interface details | 16:53 |
samueldmq | lhcheng: if that makes sense .. | 16:53 |
samueldmq | breton: cc ^ | 16:53 |
*** jasonsb has quit IRC | 16:54 | |
*** piyanai has quit IRC | 16:55 | |
*** ankita_wagh has joined #openstack-keystone | 16:55 | |
lhcheng | samueldmq: defining the policy rule should still be the same.. like <rule#1> OR <rule#2>, role:<role_name> | 16:56 |
lhcheng | samueldmq: they could start working on that | 16:57 |
lhcheng | samueldmq: some sort of rule expression builder | 16:57 |
samueldmq | lhcheng: hmm, yes | 16:57 |
*** rdo has quit IRC | 16:57 | |
*** tjcocozz has quit IRC | 16:57 | |
samueldmq | lhcheng: yeah makes sense | 16:57 |
samueldmq | lhcheng: as the role would still be in the same semantics, even though we provide better apis to create them | 16:58 |
lhcheng | samueldmq: I think that would be the hard part for the ui | 16:58 |
samueldmq | lhcheng: I meant rule :( | 16:58 |
samueldmq | lhcheng: why is it the hard part for the ui ? | 16:58 |
*** jsavak has quit IRC | 16:59 | |
lhcheng | samueldmq: expression builder is usually hard to build right | 16:59 |
*** rdo has joined #openstack-keystone | 16:59 | |
*** jsavak has joined #openstack-keystone | 16:59 | |
samueldmq | lhcheng: nice, so as soon as we start talking about it, we get it right earlier :-) | 17:00 |
lhcheng | samueldmq: maybe this is where the new UX project can help | 17:00 |
*** ankita_wagh has quit IRC | 17:00 | |
lhcheng | tsufiev: ^ | 17:00 |
samueldmq | lhcheng: new UX project ? what is that ? | 17:00 |
lhcheng | samueldmq: there was a new UX project approved couple of weeks ago... | 17:00 |
tsufiev | lhcheng, samueldmq: hello! | 17:01 |
samueldmq | lhcheng: ah nice, tsufiev hi, I hadn't noticed you were available | 17:01 |
samueldmq | tsufiev: so we were talking about your email in the ml earlier today :) | 17:01 |
lhcheng | samueldmq: ux is the new openstack project for the month :P http://governance.openstack.org/reference/projects/openstack-ux.html | 17:02 |
tsufiev | samueldmq, yeah, breton already pinged me, but I didn't realize that the discussion is right now ) | 17:02 |
samueldmq | lhcheng: nice I am gonna take a look at it :) | 17:02 |
tsufiev | IMO the hardest part in re-using Merlin UI elements for dynamic policies would be data model adoption | 17:03 |
*** harlowja has joined #openstack-keystone | 17:03 | |
samueldmq | lhcheng: hmmm, and that's the project piet is ptl of ? | 17:03 |
lhcheng | samueldmq: I think interim until there is an election | 17:03 |
tsufiev | at least some domain experts are needed (who know all the possible relations between policy elements) | 17:03 |
samueldmq | lhcheng: nice | 17:03 |
samueldmq | tsufiev: ok so basically each policy file is a set of rules, and each rule is composed by other rules or expressions, where an expression is a role check or scope check | 17:05 |
samueldmq | (neutron has different checks, we need to look at them separately, with admiyo as well) | 17:05 |
lhcheng | samueldmq: do we have a detailed doc somewhere explaining the semantics/expression that can be used in a rule? | 17:06 |
*** pcaruana has joined #openstack-keystone | 17:06 | |
samueldmq | admiyo: hey, you're camouflaged, I found you!! | 17:06 |
samueldmq | lhcheng: hmm, I think so, let me find it | 17:06 |
tsufiev | samueldmq, yeah, I already have kind of superficial acquaintance with policy syntax, what is needed to render them automatically with Merlin is knowing their grammar | 17:06 |
lhcheng | samueldmq: AFAIR, only doc I found was the doc in the policy code :P | 17:07 |
samueldmq | lhcheng: yes I think we only have this one | 17:07 |
samueldmq | lhcheng: ok adding deployer doc on policy is on my todo | 17:07 |
samueldmq | lhcheng: tsufiev https://github.com/openstack/oslo.policy/blob/master/oslo_policy/policy.py#L18-L210 | 17:08 |
*** fhubik is now known as fhubik_afk | 17:08 | |
*** samleon has joined #openstack-keystone | 17:10 | |
*** jsavak has quit IRC | 17:14 | |
tsufiev | samueldmq, added to my bookmarks | 17:14 |
*** jsavak has joined #openstack-keystone | 17:14 | |
*** piyanai has joined #openstack-keystone | 17:17 | |
breton | tsufiev: http://docs.openstack.org/kilo/config-reference/content/policy-json-file.html might also be useful | 17:18 |
*** tqtran has joined #openstack-keystone | 17:19 | |
*** mylu has quit IRC | 17:21 | |
*** e0ne has joined #openstack-keystone | 17:22 | |
*** fhubik_afk is now known as fhubik | 17:23 | |
tsufiev | breton, thanks | 17:23 |
*** spandhe has joined #openstack-keystone | 17:24 | |
*** fhubik is now known as fhubik_afk | 17:29 | |
*** henrynash has joined #openstack-keystone | 17:30 | |
*** ChanServ sets mode: +v henrynash | 17:30 | |
*** browne has joined #openstack-keystone | 17:30 | |
*** chlong has quit IRC | 17:31 | |
*** e0ne has quit IRC | 17:31 | |
*** spandhe_ has joined #openstack-keystone | 17:32 | |
*** hrou has quit IRC | 17:32 | |
*** spandhe has quit IRC | 17:32 | |
*** spandhe_ is now known as spandhe | 17:32 | |
*** fhubik_afk is now known as fhubik | 17:36 | |
*** mylu has joined #openstack-keystone | 17:38 | |
*** diazjf has quit IRC | 17:39 | |
*** e0ne has joined #openstack-keystone | 17:42 | |
*** TheIntern has joined #openstack-keystone | 17:42 | |
*** tjcocozz has joined #openstack-keystone | 17:45 | |
*** fhubik is now known as fhubik_afk | 17:48 | |
*** jsavak has quit IRC | 17:53 | |
*** piyanai has quit IRC | 17:55 | |
*** jsavak has joined #openstack-keystone | 17:56 | |
*** fhubik_afk is now known as fhubik | 17:57 | |
*** piyanai has joined #openstack-keystone | 17:59 | |
*** jasonsb has joined #openstack-keystone | 18:01 | |
*** jsavak has quit IRC | 18:02 | |
*** jsavak has joined #openstack-keystone | 18:02 | |
*** openstackgerrit_ has quit IRC | 18:07 | |
*** piyanai has quit IRC | 18:15 | |
*** piyanai has joined #openstack-keystone | 18:20 | |
*** harlowja has quit IRC | 18:21 | |
*** Kennan has quit IRC | 18:21 | |
*** harlowja has joined #openstack-keystone | 18:21 | |
*** Kennan has joined #openstack-keystone | 18:29 | |
*** diazjf has joined #openstack-keystone | 18:29 | |
*** htruta_ has quit IRC | 18:32 | |
*** mylu has quit IRC | 18:32 | |
*** tjcocozz has quit IRC | 18:36 | |
*** josecastroleon has joined #openstack-keystone | 18:36 | |
*** admiyo has quit IRC | 18:37 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Add LimitRequestBody to sample httpd config https://review.openstack.org/208208 | 18:38 |
*** TheIntern has quit IRC | 18:44 | |
*** htruta_ has joined #openstack-keystone | 18:44 | |
*** kiran-r has quit IRC | 18:45 | |
*** amakarov is now known as amakarov_away | 18:46 | |
*** TheIntern has joined #openstack-keystone | 18:46 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Fixes query.one() return usage in endpoint-policy https://review.openstack.org/208609 | 18:47 |
dstanek | samueldmq: i'll take another look at those reviews for you in a little bit. technically today is a volunteer (vacation) day, but i've been doing other things on breaks | 18:48 |
samueldmq | dstanek: btw this one is a very easy but interesting review ^ :) | 18:48 |
samueldmq | dstanek: nice, I do appreciate your help. Feel free to take a look tomorrow, enjoy your vacation day | 18:49 |
dstanek | samueldmq: cool, i'll look at that to | 18:49 |
dstanek | o | 18:49 |
dstanek | samueldmq: i'm actually volunteering for a local non-profit - doing "hard" labor | 18:49 |
samueldmq | dstanek: very nice :) | 18:50 |
*** tqtran is now known as tqtran-afk | 18:52 | |
*** mylu has joined #openstack-keystone | 18:53 | |
*** urulama has quit IRC | 19:01 | |
*** samleon has quit IRC | 19:02 | |
*** urulama has joined #openstack-keystone | 19:02 | |
*** josecastroleon has quit IRC | 19:06 | |
*** flwang has quit IRC | 19:08 | |
openstackgerrit | Sergey Vilgelm proposed openstack/oslo.policy: [WIP] Add parse_rules method the the Rules class https://review.openstack.org/208617 | 19:10 |
*** e0ne has quit IRC | 19:11 | |
openstackgerrit | Marianne Linhares Monteiro proposed openstack/keystone: List credentials by type https://review.openstack.org/208620 | 19:11 |
raildo | gyee: henrynash ^ Marianne is for our team too :) | 19:13 |
*** jsavak has quit IRC | 19:14 | |
*** jsavak has joined #openstack-keystone | 19:14 | |
*** flwang has joined #openstack-keystone | 19:22 | |
*** fhubik has quit IRC | 19:26 | |
*** ayoung has joined #openstack-keystone | 19:26 | |
*** ChanServ sets mode: +v ayoung | 19:26 | |
*** mylu has quit IRC | 19:30 | |
openstackgerrit | Marianne Linhares Monteiro proposed openstack/keystone: List credentials by type https://review.openstack.org/208620 | 19:31 |
*** mylu has joined #openstack-keystone | 19:33 | |
*** jsavak has quit IRC | 19:33 | |
*** piyanai has quit IRC | 19:47 | |
*** raildo has quit IRC | 19:49 | |
*** jsavak has joined #openstack-keystone | 19:50 | |
lhcheng | bknudson: regarding the default setting of 16k for LimitRequestBody : https://review.openstack.org/#/c/208208/ | 19:53 |
lhcheng | bknudson: I am not sure either what the right setting should be (that it won't have issue when posting a mapping or policy file) | 19:54 |
lhcheng | maybe gyee marekd or samueldmq may have some input ^ | 19:54 |
bknudson | lhcheng: the current max size is 114688 , from http://git.openstack.org/cgit/openstack/keystone/tree/etc/keystone.conf.sample#n1596 | 19:55 |
bknudson | a.k.a 112k | 19:57 |
bknudson | which seems excessive. | 19:57 |
lhcheng | bknudson: do you recall how we came up with the magic number? :) | 19:57 |
bknudson | lhcheng: that's coming from oslo.middleware, so they came up with it there. | 19:58 |
bknudson | that has to work openstack-wide, not just on keystone. | 19:58 |
bknudson | it's not large enough for an image, though. | 19:58 |
lhcheng | bknudson: hmm that may not apply for image, I recall uploading an image at least 20mb in size | 20:01 |
bknudson | ah, nobody uploads images into glance anyways... should be posting them on a web server and giving glance the url. | 20:01 |
lhcheng | yup, they should :) | 20:02 |
lhcheng | bknudson: yeah, 112k sounds excessive. But would changing our sample config to a smaller value means it could break backward compatibility? | 20:03 |
bknudson | sample config can't break anything | 20:03 |
bknudson | I'll make it 112k and we can worry about the value later. | 20:06 |
lhcheng | bknudson: okay, that sounds good to me | 20:06 |
*** piyanai has joined #openstack-keystone | 20:12 | |
*** phalmos has joined #openstack-keystone | 20:13 | |
*** boltR has joined #openstack-keystone | 20:16 | |
boltR | question.. if i disable in a service in keystone v3, will the service still show up in the catalog? | 20:16 |
boltR | if i disable a service* | 20:17 |
phalmos | Is it expected behavior when going from single-domain LDAP to multi-domain LDAP that all existing user roles become invalid and need to be re-done? | 20:19 |
*** opilotte has joined #openstack-keystone | 20:29 | |
opilotte | question: with OS-FEDERATION, is it possible to map multiple group IDs ? | 20:30 |
openstackgerrit | Marianne Linhares Monteiro proposed openstack/keystone: List credentials by type https://review.openstack.org/208620 | 20:31 |
*** hrou has joined #openstack-keystone | 20:44 | |
gyee | opilotte, try using 'groups' | 20:51 |
gyee | lhcheng, bknudson, 16K default should be fine | 20:52 |
gyee | besides, if that's not good enough for a specific deployment, we'll let the deployment script bump it up | 20:52 |
opilotte | gyee: so in identity values (returned by the IdP) 'groups': ['id_1', 'id_2', ...] ? | 20:54 |
gyee | opilotte, groups are names only | 20:55 |
*** diazjf has left #openstack-keystone | 20:55 | |
gyee | for example, “local”: [ | 20:55 |
gyee | { | 20:55 |
gyee | “groups”: {0}, | 20:55 |
gyee | “domain”: {“name”: “Default”} | 20:55 |
gyee | } | 20:55 |
gyee | ], | 20:55 |
gyee | “remote”: [ | 20:55 |
gyee | { | 20:55 |
gyee | “type”: “REMOTE_USER_GROUPS” | 20:55 |
gyee | } | 20:55 |
gyee | ] | 20:55 |
*** jsavak has quit IRC | 20:55 | |
gyee | or "groups": ["group1", "group2"], | 20:55 |
openstackgerrit | Merged openstack/keystone: Refactor: clean up TokenAPITests https://review.openstack.org/203250 | 20:57 |
opilotte | gyee: it works it IDs for me | 20:57 |
*** bapalm_ has quit IRC | 21:00 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/208652 | 21:05 |
gyee | ayoung, u coming to the Ops MidCycle in two weeks? http://www.eventbrite.com/e/openstack-ops-mid-cycle-meetup-tickets-17703258924 | 21:07 |
ayoung | gyee, nope | 21:07 |
gyee | great place to sell your dynamic policy stuff | 21:07 |
ayoung | gyee, please be my proxy | 21:08 |
gyee | ayoung, sure will try | 21:08 |
ayoung | ++ | 21:08 |
gyee | ayoung, I plan on attending OpenStack Silicon Valley as well | 21:08 |
ayoung | ++ | 21:08 |
gyee | lets see if we can find some audience for it | 21:09 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Honor domain operations in project table https://review.openstack.org/143763 | 21:14 |
*** henrynash has quit IRC | 21:16 | |
*** henrynash has joined #openstack-keystone | 21:16 | |
*** ChanServ sets mode: +v henrynash | 21:16 | |
lhcheng | gyee: do they have a free pass for OpenStack Silicon valley? | 21:20 |
lhcheng | gyee: I contacted the organizer, they said they have not offered it "yet" | 21:21 |
gyee | lhcheng, I though you can registered as a foundation member | 21:22 |
gyee | not sure if that'll work | 21:23 |
lhcheng | gyee: I don't see a way to register as foudation member. | 21:24 |
lhcheng | I've sent an email to the organizer 1.5 months back, they told to wait and they'll inform us. | 21:24 |
openstackgerrit | Merged openstack/keystone: Update exported variables for openstack client https://review.openstack.org/208120 | 21:25 |
openstackgerrit | Merged openstack/keystone: Missing ADMIN_USER in sample_data.sh https://review.openstack.org/208121 | 21:25 |
morganfainberg | Im skipping openstack sv | 21:25 |
lhcheng | I guess the organizer don't want more contributors going :P | 21:25 |
gyee | I registered as foundation member three weeks back, maybe it was a glitch/bug in the system :) | 21:25 |
lhcheng | gyee: haha awesome timing :P | 21:25 |
gyee | maybe they'll bounce me at the door, we'll see | 21:26 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/208652 | 21:26 |
lhcheng | gyee: you'll be our keystone rep for openstack sv then :D | 21:26 |
morganfainberg | Im totally going as openstack proposal bot | 21:27 |
morganfainberg | :P | 21:27 |
gyee | hahahah | 21:27 |
morganfainberg | That bot has mad contributions | 21:27 |
*** tqtran-afk is now known as tqtran | 21:27 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/208652 | 21:27 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Improve endpoint filtering docs https://review.openstack.org/208660 | 21:27 |
openstackgerrit | Merged openstack/keystone: Clean up notifications type checking https://review.openstack.org/200733 | 21:30 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/208652 | 21:32 |
openstackgerrit | Merged openstack/keystone: Clean up code to use .items() https://review.openstack.org/200734 | 21:34 |
openstackgerrit | Merged openstack/keystone: Fix test_utils for py34 https://review.openstack.org/203896 | 21:34 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/208652 | 21:35 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/208652 | 21:36 |
*** TheIntern has quit IRC | 21:36 | |
openstackgerrit | Merged openstack/python-keystoneclient: Remove check for requests version https://review.openstack.org/208217 | 21:41 |
openstackgerrit | Merged openstack/python-keystoneclient: Clarify setting socket_options https://review.openstack.org/208218 | 21:42 |
*** piyanai has quit IRC | 21:43 | |
openstackgerrit | Merged openstack/python-keystoneclient: Proper deprecation for Dicover.raw_version_data unstable parameter https://review.openstack.org/205690 | 21:43 |
openstackgerrit | Merged openstack/python-keystoneclient: Proper deprecation for httpclient.request() https://review.openstack.org/205699 | 21:43 |
lbragstad | random noob federation question - the metadata exchange between the service provider and the identity provider is what builds the trust between the two, correct? | 21:44 |
*** jasonsb has quit IRC | 21:51 | |
gyee | lbragstad, yes, saml2 is a digitally signed document, and the SP needs to trust the signing key | 21:52 |
openstackgerrit | Merged openstack/python-keystoneclient: Fix tests passing user, project, and token https://review.openstack.org/205700 | 21:55 |
*** jecarey has quit IRC | 21:56 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Remove unnecessary check from notifications.py https://review.openstack.org/203069 | 22:03 |
*** thedodd has quit IRC | 22:04 | |
*** mylu has quit IRC | 22:08 | |
*** opilotte has quit IRC | 22:08 | |
openstackgerrit | Alberto Murillo proposed openstack/keystone: disable admin_token by default https://review.openstack.org/185464 | 22:18 |
*** piyanai has joined #openstack-keystone | 22:30 | |
*** pauloewerton has quit IRC | 22:33 | |
*** btully has joined #openstack-keystone | 22:43 | |
*** jasonsb has joined #openstack-keystone | 22:45 | |
*** dims_ has joined #openstack-keystone | 22:51 | |
*** dims has quit IRC | 22:52 | |
*** dims has joined #openstack-keystone | 22:53 | |
*** bknudson has quit IRC | 22:56 | |
*** dims_ has quit IRC | 22:56 | |
*** jaosorior has quit IRC | 23:04 | |
*** fangzhou has joined #openstack-keystone | 23:09 | |
*** aix has quit IRC | 23:12 | |
*** piyanai has quit IRC | 23:16 | |
*** darrenc has quit IRC | 23:23 | |
*** darrenc has joined #openstack-keystone | 23:23 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 23:24 | |
*** topol has quit IRC | 23:25 | |
*** dims has quit IRC | 23:29 | |
*** darrenc has quit IRC | 23:35 | |
*** darrenc has joined #openstack-keystone | 23:35 | |
*** phalmos has quit IRC | 23:36 | |
*** darrenc is now known as darrenc_afk | 23:45 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!