*** topol has quit IRC | 00:01 | |
*** stevemar has quit IRC | 00:13 | |
*** topol has joined #openstack-keystone | 00:17 | |
*** ChanServ sets mode: +v topol | 00:17 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 00:22 | |
*** shadower has quit IRC | 00:23 | |
*** shadower has joined #openstack-keystone | 00:23 | |
*** rdo has quit IRC | 00:27 | |
*** rdo has joined #openstack-keystone | 00:29 | |
*** lhcheng has joined #openstack-keystone | 00:35 | |
*** ChanServ sets mode: +v lhcheng | 00:35 | |
*** diazjf has quit IRC | 00:45 | |
openstackgerrit | Jamie Lennox proposed openstack/keystone: Group tox optional dependencies https://review.openstack.org/218693 | 00:45 |
---|---|---|
*** spandhe has quit IRC | 00:50 | |
*** chlong has joined #openstack-keystone | 00:55 | |
*** shoutm has quit IRC | 01:01 | |
*** vivekd has quit IRC | 01:04 | |
*** vivekd has joined #openstack-keystone | 01:05 | |
*** shoutm has joined #openstack-keystone | 01:09 | |
*** diazjf has joined #openstack-keystone | 01:10 | |
*** EinstCrazy has joined #openstack-keystone | 01:19 | |
*** vivekd has quit IRC | 01:32 | |
*** roxanaghe has joined #openstack-keystone | 01:33 | |
*** marzif__ has joined #openstack-keystone | 01:33 | |
*** tobasco_ has joined #openstack-keystone | 01:36 | |
*** tobasco has quit IRC | 01:37 | |
*** nkinder has quit IRC | 01:37 | |
*** marzif_ has quit IRC | 01:37 | |
*** nkinder has joined #openstack-keystone | 01:37 | |
*** roxanaghe has quit IRC | 01:41 | |
*** aix_ has joined #openstack-keystone | 01:41 | |
*** aix has quit IRC | 01:42 | |
*** shoutm has quit IRC | 01:42 | |
*** shoutm has joined #openstack-keystone | 01:42 | |
*** diazjf has quit IRC | 01:45 | |
*** ankita_wagh has joined #openstack-keystone | 01:45 | |
*** chlong has quit IRC | 01:49 | |
*** diazjf has joined #openstack-keystone | 02:17 | |
*** flwang1 has quit IRC | 02:18 | |
*** flwang1 has joined #openstack-keystone | 02:19 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 02:23 | |
*** lhcheng has quit IRC | 02:25 | |
*** stevemar has joined #openstack-keystone | 02:25 | |
*** ChanServ sets mode: +v stevemar | 02:25 | |
*** stevemar has quit IRC | 02:30 | |
*** ankita_wagh has quit IRC | 02:33 | |
*** roxanaghe has joined #openstack-keystone | 02:52 | |
*** hakimo_ has joined #openstack-keystone | 02:52 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 02:53 | |
*** hakimo has quit IRC | 02:54 | |
*** EinstCrazy has quit IRC | 02:57 | |
*** wwwjfy has joined #openstack-keystone | 02:57 | |
openstackgerrit | Jamie Lennox proposed openstack/keystone: Reject rule if assertion type unset https://review.openstack.org/216088 | 02:58 |
*** roxanaghe has quit IRC | 03:01 | |
*** spandhe has joined #openstack-keystone | 03:23 | |
*** roxanaghe has joined #openstack-keystone | 03:24 | |
*** d34dh0r53 has quit IRC | 03:25 | |
*** eglute has quit IRC | 03:25 | |
*** sigmavirus24_awa has quit IRC | 03:25 | |
*** dolphm has quit IRC | 03:26 | |
openstackgerrit | lei zhang proposed openstack/keystone: Update sample catalog templates https://review.openstack.org/218711 | 03:28 |
*** dolphm has joined #openstack-keystone | 03:31 | |
openstackgerrit | lei zhang proposed openstack/keystone: Update sample catalog templates https://review.openstack.org/218711 | 03:31 |
*** eglute has joined #openstack-keystone | 03:31 | |
*** d34dh0r53 has joined #openstack-keystone | 03:32 | |
*** sigmavirus24_awa has joined #openstack-keystone | 03:33 | |
*** ankita_wagh has joined #openstack-keystone | 03:34 | |
*** links has joined #openstack-keystone | 03:40 | |
*** davechen has joined #openstack-keystone | 03:41 | |
*** lhcheng has joined #openstack-keystone | 03:42 | |
*** ChanServ sets mode: +v lhcheng | 03:42 | |
*** Piet has joined #openstack-keystone | 03:45 | |
*** Piet has quit IRC | 03:45 | |
*** Piet has joined #openstack-keystone | 03:45 | |
*** Piet has quit IRC | 03:48 | |
*** Piet has joined #openstack-keystone | 03:48 | |
*** diazjf has left #openstack-keystone | 03:49 | |
*** Piet has quit IRC | 03:50 | |
*** Piet has joined #openstack-keystone | 03:50 | |
*** roxanaghe has quit IRC | 03:51 | |
*** Piet has quit IRC | 03:53 | |
*** roxanaghe has joined #openstack-keystone | 03:53 | |
*** roxanaghe has quit IRC | 03:55 | |
*** roxanaghe has joined #openstack-keystone | 04:03 | |
*** shoutm has quit IRC | 04:04 | |
*** hrou has joined #openstack-keystone | 04:06 | |
*** shoutm has joined #openstack-keystone | 04:06 | |
*** stevemar has joined #openstack-keystone | 04:23 | |
*** ChanServ sets mode: +v stevemar | 04:23 | |
*** zzzeek has joined #openstack-keystone | 04:30 | |
*** zzzeek has quit IRC | 04:31 | |
*** _hrou_ has joined #openstack-keystone | 04:40 | |
*** hrou has quit IRC | 04:41 | |
*** roxanaghe has quit IRC | 04:45 | |
*** _hrou_ has quit IRC | 04:47 | |
*** jasonsb has joined #openstack-keystone | 04:50 | |
*** ig0r__ has joined #openstack-keystone | 04:59 | |
*** ig0r_ has quit IRC | 04:59 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Move admin_token to base _plugins dir https://review.openstack.org/218727 | 05:11 |
*** topol has quit IRC | 05:21 | |
*** ankita_wagh has quit IRC | 05:23 | |
*** dave-mccowan has quit IRC | 05:29 | |
*** Nirupama has joined #openstack-keystone | 05:30 | |
*** ankita_wagh has joined #openstack-keystone | 05:36 | |
*** ankita_wagh has quit IRC | 05:50 | |
*** markvoelker has joined #openstack-keystone | 05:51 | |
*** markvoelker_ has joined #openstack-keystone | 05:53 | |
*** Spider has quit IRC | 05:54 | |
*** shoutm has quit IRC | 05:54 | |
*** markvoelker has quit IRC | 05:56 | |
*** lhcheng has quit IRC | 05:57 | |
*** ParsectiX has joined #openstack-keystone | 06:07 | |
*** jasonsb has quit IRC | 06:10 | |
*** spandhe has quit IRC | 06:14 | |
*** stevemar has quit IRC | 06:15 | |
*** afazekas_ has joined #openstack-keystone | 06:19 | |
*** lhcheng has joined #openstack-keystone | 06:21 | |
*** ChanServ sets mode: +v lhcheng | 06:21 | |
*** markvoelker has joined #openstack-keystone | 06:22 | |
*** markvoelker_ has quit IRC | 06:25 | |
*** markvoelker_ has joined #openstack-keystone | 06:27 | |
*** henrynash has joined #openstack-keystone | 06:28 | |
*** ChanServ sets mode: +v henrynash | 06:28 | |
*** stevemar has joined #openstack-keystone | 06:29 | |
*** ChanServ sets mode: +v stevemar | 06:29 | |
*** markvoelker has quit IRC | 06:29 | |
*** henrynash has quit IRC | 06:37 | |
*** shoutm has joined #openstack-keystone | 06:43 | |
*** ParsectiX has quit IRC | 06:51 | |
*** ParsectiX has joined #openstack-keystone | 06:52 | |
*** stevemar has quit IRC | 06:53 | |
*** shoutm_ has joined #openstack-keystone | 06:59 | |
*** stevemar has joined #openstack-keystone | 07:00 | |
*** ChanServ sets mode: +v stevemar | 07:00 | |
*** shoutm has quit IRC | 07:00 | |
*** lhcheng has quit IRC | 07:16 | |
*** topol has joined #openstack-keystone | 07:22 | |
*** ChanServ sets mode: +v topol | 07:22 | |
*** topol has quit IRC | 07:26 | |
*** spandhe has joined #openstack-keystone | 07:27 | |
*** fhubik has joined #openstack-keystone | 07:36 | |
stevemar | marekd: poke | 07:40 |
*** spandhe has quit IRC | 08:01 | |
*** katkapilatova has joined #openstack-keystone | 08:06 | |
*** jistr has joined #openstack-keystone | 08:15 | |
*** kiran-r has joined #openstack-keystone | 08:15 | |
*** katkapilatova has left #openstack-keystone | 08:17 | |
*** katkapilatova has joined #openstack-keystone | 08:22 | |
*** pnavarro has joined #openstack-keystone | 08:25 | |
*** katkapilatova has quit IRC | 08:25 | |
*** katkapilatova has joined #openstack-keystone | 08:27 | |
*** markvoelker_ has quit IRC | 08:28 | |
*** aix_ has quit IRC | 08:32 | |
*** aix has joined #openstack-keystone | 08:33 | |
*** shoutm_ has quit IRC | 08:36 | |
*** ParsectiX_ has joined #openstack-keystone | 08:41 | |
*** ParsectiX_ has quit IRC | 08:42 | |
*** fhubik is now known as fhubik_brb | 08:51 | |
*** e0ne has joined #openstack-keystone | 08:59 | |
*** e0ne has quit IRC | 09:09 | |
*** fhubik_brb is now known as fhubik | 09:09 | |
*** e0ne has joined #openstack-keystone | 09:09 | |
*** kodokuu has joined #openstack-keystone | 09:11 | |
kodokuu | Hi, how I can disable revocation in keystone ? Because I have token always valid but keystone revoke and nova fail :/ | 09:13 |
kodokuu | And Why keystone revoke a valid token ? | 09:16 |
*** kodokuu has quit IRC | 09:20 | |
*** markvoelker has joined #openstack-keystone | 09:23 | |
*** kodokuu has joined #openstack-keystone | 09:25 | |
*** markvoelker_ has joined #openstack-keystone | 09:26 | |
*** markvoelker has quit IRC | 09:30 | |
*** markvoelker_ has quit IRC | 09:31 | |
*** ig0r_ has joined #openstack-keystone | 09:37 | |
*** markvoelker has joined #openstack-keystone | 09:37 | |
*** marzif__ has quit IRC | 09:38 | |
*** marzif__ has joined #openstack-keystone | 09:38 | |
*** ig0r__ has quit IRC | 09:39 | |
openstackgerrit | Marek Denis proposed openstack/keystone: IdP deletion triggers token revocation https://review.openstack.org/210456 | 09:43 |
*** aix has quit IRC | 09:49 | |
*** wwwjfy has quit IRC | 09:50 | |
*** davechen has left #openstack-keystone | 09:53 | |
*** vivekd has joined #openstack-keystone | 09:54 | |
*** wwwjfy has joined #openstack-keystone | 09:55 | |
*** marzif__ has quit IRC | 10:12 | |
*** aix has joined #openstack-keystone | 10:18 | |
*** fhubik is now known as fhubik_brb | 10:19 | |
*** topol has joined #openstack-keystone | 10:24 | |
*** ChanServ sets mode: +v topol | 10:24 | |
marekd | stevemar: what's that? | 10:24 |
marekd | stevemar: what's up :P | 10:25 |
*** shoutm has joined #openstack-keystone | 10:27 | |
*** topol has quit IRC | 10:28 | |
*** ParsectiX_ has joined #openstack-keystone | 10:37 | |
*** topol has joined #openstack-keystone | 10:45 | |
*** ChanServ sets mode: +v topol | 10:45 | |
*** marzif__ has joined #openstack-keystone | 10:47 | |
*** shoutm has quit IRC | 10:56 | |
*** pnavarro is now known as pnavarro|lunch | 11:00 | |
openstackgerrit | Vivek Dhayaal proposed openstack/keystone: Stable Keystone Driver Interfaces https://review.openstack.org/209524 | 11:03 |
*** wwwjfy has quit IRC | 11:08 | |
*** e0ne has quit IRC | 11:10 | |
*** shoutm has joined #openstack-keystone | 11:19 | |
*** stevemar has quit IRC | 11:22 | |
*** fhubik_brb is now known as fhubik | 11:24 | |
*** _hrou_ has joined #openstack-keystone | 11:27 | |
*** katkapilatova has left #openstack-keystone | 11:30 | |
*** katkapilatova has joined #openstack-keystone | 11:34 | |
*** katkapilatova has left #openstack-keystone | 11:34 | |
*** katkapilatova has joined #openstack-keystone | 11:36 | |
*** _hrou_ has quit IRC | 11:36 | |
*** marzif__ has quit IRC | 11:42 | |
*** gordc has joined #openstack-keystone | 11:43 | |
*** fhubik is now known as fhubik_brb | 11:43 | |
*** fhubik_brb is now known as fhubik | 11:45 | |
*** openstackgerrit has quit IRC | 11:46 | |
*** openstackgerrit has joined #openstack-keystone | 11:47 | |
*** markvoelker_ has joined #openstack-keystone | 11:51 | |
*** markvoelker has quit IRC | 11:51 | |
*** markvoelker_ has quit IRC | 11:55 | |
*** markvoelker has joined #openstack-keystone | 11:56 | |
*** e0ne has joined #openstack-keystone | 11:59 | |
*** vivekd has quit IRC | 12:07 | |
*** dave-mccowan has joined #openstack-keystone | 12:08 | |
*** petertr7_away is now known as petertr7 | 12:09 | |
*** amakarov_away is now known as amakarov | 12:11 | |
*** raildo-afk is now known as raildo | 12:16 | |
*** ParsectiX_ has quit IRC | 12:21 | |
*** ParsectiX has quit IRC | 12:21 | |
*** ParsectiX has joined #openstack-keystone | 12:22 | |
*** humble__ has quit IRC | 12:27 | |
*** edmondsw has joined #openstack-keystone | 12:32 | |
*** dsirrine has joined #openstack-keystone | 12:32 | |
*** kodokuu has quit IRC | 12:33 | |
*** dikonoor has joined #openstack-keystone | 12:34 | |
*** dikonoo has joined #openstack-keystone | 12:35 | |
*** pnavarro|lunch is now known as pnavarro | 12:42 | |
*** dikonoo has quit IRC | 12:50 | |
*** afazekas__ has joined #openstack-keystone | 12:56 | |
*** afazekas_ has quit IRC | 12:58 | |
breton_ | what's the reason for not having a callback in revocation events when a domain is deleted? https://github.com/openstack/keystone/blob/master/keystone/contrib/revoke/core.py#L128 | 12:59 |
*** wwwjfy has joined #openstack-keystone | 13:02 | |
*** afaranha has joined #openstack-keystone | 13:02 | |
*** afaranha has left #openstack-keystone | 13:02 | |
breton_ | oh, ok, "In order to minimize the risk of an inadvertent deletion of a domain and its entities, a domain must first be disabled" | 13:02 |
*** edmondsw has quit IRC | 13:04 | |
raildo | breton_: yes, but we have the same behaviour for users and projects, and for the other cases there is deleted notifications... maybe because domains only exists on Keystone, and we don't need to notificate other services | 13:04 |
*** h0mer has joined #openstack-keystone | 13:04 | |
h0mer | anyone here ever run into this problem with the openstack dashboard? "An error occurred authenticating. Please try again later." | 13:04 |
*** vivekd has joined #openstack-keystone | 13:06 | |
*** Nirupama has quit IRC | 13:15 | |
*** e0ne has quit IRC | 13:22 | |
*** richm1 has joined #openstack-keystone | 13:25 | |
*** richm1 is now known as richm | 13:25 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add documentation for configuring IdP WebSSO https://review.openstack.org/218353 | 13:27 |
*** zzzeek has joined #openstack-keystone | 13:27 | |
*** _hrou_ has joined #openstack-keystone | 13:28 | |
*** e0ne has joined #openstack-keystone | 13:29 | |
*** links has quit IRC | 13:30 | |
*** ayoung has joined #openstack-keystone | 13:31 | |
*** ChanServ sets mode: +v ayoung | 13:31 | |
*** edmondsw has joined #openstack-keystone | 13:33 | |
*** stevemar has joined #openstack-keystone | 13:34 | |
*** ChanServ sets mode: +v stevemar | 13:34 | |
*** dims has joined #openstack-keystone | 13:36 | |
*** doug-fish has joined #openstack-keystone | 13:39 | |
*** stevemar has quit IRC | 13:39 | |
*** annasort has joined #openstack-keystone | 13:39 | |
*** kiran-r has quit IRC | 13:48 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 13:56 | |
*** tjcocozz has joined #openstack-keystone | 13:59 | |
*** Kennan has quit IRC | 14:03 | |
*** Kennan2 has joined #openstack-keystone | 14:03 | |
*** ParsectiX has quit IRC | 14:04 | |
*** ayoung has quit IRC | 14:04 | |
*** topol has quit IRC | 14:06 | |
*** tjcocozz has quit IRC | 14:07 | |
*** tjcocozz has joined #openstack-keystone | 14:07 | |
*** afazekas__ has quit IRC | 14:08 | |
*** markvoelker has quit IRC | 14:09 | |
*** Ephur has joined #openstack-keystone | 14:09 | |
*** boris-42 has joined #openstack-keystone | 14:11 | |
openstackgerrit | Vivek Dhayaal proposed openstack/keystone: Stable Keystone Driver Interfaces https://review.openstack.org/209524 | 14:14 |
openstackgerrit | Vivek Dhayaal proposed openstack/keystone: Stable Keystone Driver Interfaces https://review.openstack.org/209524 | 14:16 |
*** tjcocozz has quit IRC | 14:21 | |
*** tjcocozz has joined #openstack-keystone | 14:21 | |
*** tonytan4ever has joined #openstack-keystone | 14:22 | |
*** r-daneel has joined #openstack-keystone | 14:22 | |
*** thiagop has joined #openstack-keystone | 14:24 | |
openstackgerrit | Tom Cocozzello proposed openstack/keystone: Ensure request variables have corresponding mappings https://review.openstack.org/217340 | 14:24 |
*** vivekd has quit IRC | 14:27 | |
marekd | tjcocozz: ^^ i thnk this may be overlaping with https://review.openstack.org/#/c/216088/ you may want to take a look | 14:37 |
*** ayoung has joined #openstack-keystone | 14:38 | |
*** ChanServ sets mode: +v ayoung | 14:38 | |
*** tjcocozz_ has joined #openstack-keystone | 14:41 | |
*** tjcocozz has quit IRC | 14:41 | |
*** tjcocozz has joined #openstack-keystone | 14:44 | |
*** jaosorior has joined #openstack-keystone | 14:44 | |
*** tjcocozz has quit IRC | 14:47 | |
*** stevemar has joined #openstack-keystone | 14:48 | |
*** ChanServ sets mode: +v stevemar | 14:48 | |
*** topol has joined #openstack-keystone | 14:50 | |
*** ChanServ sets mode: +v topol | 14:50 | |
marekd | stevemar: Hi, what was that you wanted earlier in the morning? | 14:50 |
*** stevemar has quit IRC | 14:50 | |
*** dims has quit IRC | 14:51 | |
*** petertr7 is now known as petertr7_away | 14:51 | |
*** markvoelker has joined #openstack-keystone | 14:53 | |
*** alextricity has quit IRC | 14:54 | |
*** markvoelker has quit IRC | 14:54 | |
*** markvoelker has joined #openstack-keystone | 14:55 | |
*** jistr is now known as jistr|call | 14:57 | |
*** petertr7_away is now known as petertr7 | 14:59 | |
*** diazjf has joined #openstack-keystone | 15:01 | |
*** csoukup has joined #openstack-keystone | 15:01 | |
*** dims has joined #openstack-keystone | 15:03 | |
*** mpmsimo has joined #openstack-keystone | 15:03 | |
*** ChanServ sets mode: +o dolphm | 15:04 | |
*** mpmsimo1 has joined #openstack-keystone | 15:05 | |
*** shoutm has quit IRC | 15:05 | |
*** gyee has joined #openstack-keystone | 15:07 | |
*** ChanServ sets mode: +v gyee | 15:07 | |
*** mpmsimo has quit IRC | 15:07 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 15:09 | |
*** mpmsimo1 has quit IRC | 15:09 | |
*** phalmos has joined #openstack-keystone | 15:10 | |
*** dave-mccowan has quit IRC | 15:11 | |
*** jorge_munoz has quit IRC | 15:13 | |
*** stevemar has joined #openstack-keystone | 15:16 | |
*** ChanServ sets mode: +v stevemar | 15:16 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 15:17 | |
*** woodster_ has joined #openstack-keystone | 15:18 | |
*** mylu has joined #openstack-keystone | 15:19 | |
*** jorge_munoz has joined #openstack-keystone | 15:19 | |
*** mylu has quit IRC | 15:20 | |
*** mylu has joined #openstack-keystone | 15:20 | |
*** stevemar has quit IRC | 15:21 | |
*** mylu has quit IRC | 15:21 | |
*** mylu has joined #openstack-keystone | 15:21 | |
*** mylu has quit IRC | 15:22 | |
*** mylu has joined #openstack-keystone | 15:22 | |
*** mylu has quit IRC | 15:23 | |
*** thedodd has joined #openstack-keystone | 15:23 | |
*** mylu has joined #openstack-keystone | 15:23 | |
*** claudiub has joined #openstack-keystone | 15:23 | |
*** mylu has quit IRC | 15:24 | |
*** mylu has joined #openstack-keystone | 15:24 | |
*** dave-mccowan has joined #openstack-keystone | 15:25 | |
*** mylu has quit IRC | 15:26 | |
*** mylu has joined #openstack-keystone | 15:27 | |
*** mylu has quit IRC | 15:27 | |
*** mylu has joined #openstack-keystone | 15:27 | |
*** jsavak has joined #openstack-keystone | 15:28 | |
*** mylu has quit IRC | 15:29 | |
*** mylu has joined #openstack-keystone | 15:30 | |
*** mylu has quit IRC | 15:31 | |
*** david-ly_ has joined #openstack-keystone | 15:31 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/214509 | 15:32 |
*** david-ly_ is now known as david-lyle_ | 15:33 | |
*** mylu has joined #openstack-keystone | 15:33 | |
*** mylu has quit IRC | 15:33 | |
*** david-lyle has quit IRC | 15:33 | |
*** mylu has joined #openstack-keystone | 15:33 | |
*** mylu has quit IRC | 15:34 | |
*** mylu has joined #openstack-keystone | 15:34 | |
*** mylu has quit IRC | 15:35 | |
*** david-lyle_ is now known as david-lyle | 15:35 | |
*** mylu has joined #openstack-keystone | 15:35 | |
*** mylu has quit IRC | 15:35 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements https://review.openstack.org/217205 | 15:36 |
*** mylu has joined #openstack-keystone | 15:36 | |
dstanek | morgan: are you tied to Base in the name? I do like the suggestion to be more explicit about the subsystem though | 15:36 |
*** mylu has quit IRC | 15:37 | |
*** fhubik has quit IRC | 15:37 | |
*** mylu has joined #openstack-keystone | 15:38 | |
*** mylu has quit IRC | 15:38 | |
*** mylu has joined #openstack-keystone | 15:39 | |
*** mylu has quit IRC | 15:39 | |
*** mylu has joined #openstack-keystone | 15:41 | |
*** mylu has quit IRC | 15:41 | |
*** mylu has joined #openstack-keystone | 15:42 | |
*** mylu has quit IRC | 15:44 | |
*** mylu has joined #openstack-keystone | 15:44 | |
*** mylu has quit IRC | 15:45 | |
*** mylu has joined #openstack-keystone | 15:45 | |
*** mylu has quit IRC | 15:46 | |
*** mylu has joined #openstack-keystone | 15:47 | |
*** mylu has quit IRC | 15:47 | |
*** mylu has joined #openstack-keystone | 15:48 | |
*** jistr|call is now known as jistr | 15:53 | |
*** mylu has quit IRC | 15:56 | |
*** katkapilatova has left #openstack-keystone | 15:56 | |
*** mylu has joined #openstack-keystone | 15:57 | |
*** stevemar has joined #openstack-keystone | 15:57 | |
*** ChanServ sets mode: +v stevemar | 15:57 | |
*** diegows has joined #openstack-keystone | 15:58 | |
stevemar | marekd: dont worry, i got it :) | 15:58 |
*** mylu has quit IRC | 15:59 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 15:59 | |
*** jsavak has quit IRC | 15:59 | |
*** markvoelker_ has joined #openstack-keystone | 16:00 | |
*** mylu has joined #openstack-keystone | 16:00 | |
*** jsavak has joined #openstack-keystone | 16:00 | |
*** markvoel_ has joined #openstack-keystone | 16:01 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 16:01 | |
*** mylu has quit IRC | 16:02 | |
*** mylu has joined #openstack-keystone | 16:03 | |
*** markvoelker has quit IRC | 16:03 | |
*** mylu has quit IRC | 16:04 | |
*** mylu has joined #openstack-keystone | 16:04 | |
*** mylu has quit IRC | 16:04 | |
openstackgerrit | David Stanek proposed openstack/keystone: Initial support for versioned driver classes https://review.openstack.org/218481 | 16:05 |
*** markvoelker_ has quit IRC | 16:05 | |
*** mylu has joined #openstack-keystone | 16:06 | |
*** mylu has quit IRC | 16:06 | |
*** mylu has joined #openstack-keystone | 16:07 | |
*** mylu has quit IRC | 16:11 | |
*** mylu has joined #openstack-keystone | 16:12 | |
*** kiran-r has joined #openstack-keystone | 16:13 | |
*** jistr has quit IRC | 16:13 | |
marekd | stevemar: hehe, anything you wanted to talk about? | 16:15 |
stevemar | marekd: not important, no biggie :) | 16:15 |
*** c_soukup has joined #openstack-keystone | 16:16 | |
*** mylu has quit IRC | 16:16 | |
*** mylu has joined #openstack-keystone | 16:17 | |
*** vivekd has joined #openstack-keystone | 16:18 | |
*** mylu has quit IRC | 16:18 | |
*** csoukup has quit IRC | 16:19 | |
*** mylu has joined #openstack-keystone | 16:19 | |
*** mylu has quit IRC | 16:20 | |
*** e0ne has quit IRC | 16:20 | |
*** mylu has joined #openstack-keystone | 16:20 | |
*** mylu has quit IRC | 16:20 | |
*** wwwjfy has quit IRC | 16:21 | |
*** mylu has joined #openstack-keystone | 16:22 | |
*** mylu has quit IRC | 16:25 | |
*** ankita_wagh has joined #openstack-keystone | 16:26 | |
*** mylu has joined #openstack-keystone | 16:27 | |
*** mylu has quit IRC | 16:28 | |
*** mylu has joined #openstack-keystone | 16:29 | |
*** tqtran has joined #openstack-keystone | 16:30 | |
*** markvoel_ has quit IRC | 16:31 | |
*** mylu has quit IRC | 16:31 | |
*** markvoelker has joined #openstack-keystone | 16:31 | |
*** markvoelker_ has joined #openstack-keystone | 16:32 | |
*** mylu has joined #openstack-keystone | 16:32 | |
*** mylu has quit IRC | 16:33 | |
*** lifeless has quit IRC | 16:34 | |
*** mylu has joined #openstack-keystone | 16:34 | |
*** mylu has quit IRC | 16:34 | |
*** mylu has joined #openstack-keystone | 16:35 | |
*** mylu has quit IRC | 16:35 | |
*** markvoelker has quit IRC | 16:36 | |
*** mylu has joined #openstack-keystone | 16:36 | |
*** mylu has quit IRC | 16:36 | |
*** mylu has joined #openstack-keystone | 16:37 | |
*** markvoelker_ has quit IRC | 16:37 | |
*** mylu has quit IRC | 16:37 | |
*** mylu has joined #openstack-keystone | 16:38 | |
*** mylu has quit IRC | 16:38 | |
*** roxanaghe has joined #openstack-keystone | 16:38 | |
*** geoffarnold has joined #openstack-keystone | 16:39 | |
*** mylu has joined #openstack-keystone | 16:39 | |
*** mylu has quit IRC | 16:41 | |
*** lifeless has joined #openstack-keystone | 16:41 | |
*** mylu has joined #openstack-keystone | 16:42 | |
*** mylu has quit IRC | 16:42 | |
*** lhcheng has joined #openstack-keystone | 16:43 | |
*** ChanServ sets mode: +v lhcheng | 16:43 | |
*** mylu has joined #openstack-keystone | 16:43 | |
*** jsavak has quit IRC | 16:44 | |
*** jsavak has joined #openstack-keystone | 16:44 | |
*** mylu has quit IRC | 16:47 | |
*** _hrou_ has quit IRC | 16:47 | |
*** mylu has joined #openstack-keystone | 16:48 | |
*** mylu has quit IRC | 16:48 | |
*** ayoung has quit IRC | 16:48 | |
*** mylu has joined #openstack-keystone | 16:48 | |
*** tqtran has quit IRC | 16:51 | |
*** mylu has quit IRC | 16:52 | |
*** mylu has joined #openstack-keystone | 16:53 | |
*** jsavak has quit IRC | 16:53 | |
*** mylu has quit IRC | 16:53 | |
*** jsavak has joined #openstack-keystone | 16:53 | |
*** mylu has joined #openstack-keystone | 16:54 | |
*** mylu has quit IRC | 16:54 | |
*** mylu has joined #openstack-keystone | 16:55 | |
marekd | stevemar: I'd appreciate if you could take a look: I am having an error sqlalchemy.exc.NoSuchTableError: revocation_event | 16:55 |
*** mylu has quit IRC | 16:55 | |
marekd | sqlalchemy.exc.NoSuchTableError: revocation_event | 16:55 |
marekd | https://review.openstack.org/#/c/210456 | 16:55 |
*** dims has quit IRC | 16:55 | |
*** mylu has joined #openstack-keystone | 16:55 | |
*** mylu has quit IRC | 16:56 | |
*** mylu has joined #openstack-keystone | 16:56 | |
*** mylu has quit IRC | 16:57 | |
*** ankita_wagh has quit IRC | 16:57 | |
*** mylu has joined #openstack-keystone | 16:57 | |
stevemar | marekd: after lunch :D | 16:57 |
*** mylu has quit IRC | 16:57 | |
marekd | sure thing! | 16:58 |
marekd | you gotta have your priorities :-) | 16:58 |
*** mylu has joined #openstack-keystone | 16:58 | |
*** mylu has quit IRC | 16:58 | |
*** mylu has joined #openstack-keystone | 16:59 | |
*** mylu has quit IRC | 16:59 | |
*** dsirrine has quit IRC | 16:59 | |
*** mylu has joined #openstack-keystone | 17:00 | |
*** mylu has quit IRC | 17:00 | |
*** mylu has joined #openstack-keystone | 17:01 | |
*** mylu has quit IRC | 17:02 | |
*** mylu has joined #openstack-keystone | 17:03 | |
*** mylu has quit IRC | 17:03 | |
*** c_soukup has quit IRC | 17:03 | |
*** mylu has joined #openstack-keystone | 17:04 | |
*** exploreshaifali has joined #openstack-keystone | 17:04 | |
morgan | dstanek: don't care about the name | 17:04 |
morgan | But the subsystem specifier would be nice. :) | 17:05 |
*** mylu has quit IRC | 17:05 | |
morgan | Drop the "base" (sorry, I couldn't resist) if you want | 17:05 |
morgan | dstanek: I'll see myself out after that pun... | 17:06 |
*** mylu has joined #openstack-keystone | 17:06 | |
*** mylu has quit IRC | 17:06 | |
*** mylu has joined #openstack-keystone | 17:07 | |
*** mylu has quit IRC | 17:07 | |
*** mylu has joined #openstack-keystone | 17:09 | |
*** mylu has quit IRC | 17:09 | |
*** mylu has joined #openstack-keystone | 17:09 | |
*** kiran-r has quit IRC | 17:10 | |
*** mylu has quit IRC | 17:10 | |
*** mylu has joined #openstack-keystone | 17:10 | |
*** mylu has quit IRC | 17:11 | |
*** mylu has joined #openstack-keystone | 17:11 | |
*** tonytan4ever has quit IRC | 17:12 | |
*** mylu has quit IRC | 17:12 | |
*** mylu has joined #openstack-keystone | 17:13 | |
*** mylu has quit IRC | 17:13 | |
lhcheng | stevemar jamielennox david-lyle: I've been pondering about the new option to support the IDP specific WebSSO config for horizon. | 17:13 |
*** mylu has joined #openstack-keystone | 17:14 | |
lhcheng | came up with couple of options so that we can keep backward compatibility of the config: http://paste.openstack.org/show/435226/ | 17:14 |
*** mylu has quit IRC | 17:14 | |
lhcheng | marekd: ^ | 17:15 |
*** mylu has joined #openstack-keystone | 17:15 | |
*** mylu has quit IRC | 17:15 | |
*** mylu has joined #openstack-keystone | 17:15 | |
*** mylu has quit IRC | 17:15 | |
stevemar | lhcheng: looking | 17:16 |
*** mylu has joined #openstack-keystone | 17:17 | |
stevemar | lhcheng: backwards compatibility when it was only in the wild for 1 release? :) | 17:17 |
stevemar | didn't we mark it as experimental | 17:17 |
*** mylu has quit IRC | 17:17 | |
*** rbak has joined #openstack-keystone | 17:17 | |
stevemar | oh i like that 3rd option | 17:17 |
lhcheng | stevemar: not sure if we marked it as experimental | 17:18 |
lhcheng | stevemar: that would be on the keystone side? | 17:18 |
stevemar | i think so | 17:18 |
lhcheng | stevemar: all three options would only require changes on DOA :) no further change need in Horizon. | 17:18 |
stevemar | yep | 17:19 |
stevemar | either way, i like option 3, its backward compat | 17:19 |
david-lyle | lhcheng: i'm with stevemar, I like option 3 | 17:19 |
*** mylu has joined #openstack-keystone | 17:20 | |
david-lyle | it's mo betta | 17:20 |
*** jasonsb has joined #openstack-keystone | 17:20 | |
*** aix has quit IRC | 17:21 | |
lhcheng | david-lyle: can we do another release of DOA when we get this changes in? :) | 17:21 |
david-lyle | lhcheng: I have to to bump Django requirements anyway | 17:21 |
david-lyle | so yes | 17:21 |
stevemar | \o/ | 17:21 |
lhcheng | cool | 17:22 |
david-lyle | Need to look at policy patch too | 17:22 |
lhcheng | david-lyle: awesome | 17:22 |
david-lyle | and maybe through the domain token stuff in | 17:22 |
stevemar | lhcheng: we need to update the keystone docs too, then | 17:22 |
stevemar | i can do that (later) | 17:22 |
lhcheng | stevemar: yup | 17:22 |
*** vivekd has quit IRC | 17:23 | |
*** csoukup has joined #openstack-keystone | 17:23 | |
*** samleon has joined #openstack-keystone | 17:23 | |
lhcheng | will try to post something up later or tom | 17:24 |
rbak | lbragstad: you there? mfisch said you should be able to help me with fernet token question. | 17:25 |
lbragstad | rbak: o/ I can try :) | 17:25 |
*** e0ne has joined #openstack-keystone | 17:26 | |
rbak | lbragstad: I've got a token, and I need to decrypt it to find the tenant it belongs to. When I encrypt a message I can then decrypt it, but if I do a keystone token-get and decrypt that token it says invalidToken. | 17:27 |
rbak | Any ideas what I might be doing wrong? | 17:28 |
dolphm | rbak: validate it against keystone, and let keystone do the heavy lifting | 17:28 |
*** dims has joined #openstack-keystone | 17:29 | |
dolphm | rbak: GET /v3/tokens/auth w/ headers... X-Subject-Token: {token-to-validate} X-Auth-Token: {a-service-token-or-one-with-admin} | 17:29 |
rbak | Unfortunately I'm trying to track connections to keystone by tenant, so if I validate through keystone I create another request I then have to ignore or validate again. | 17:29 |
*** dims_ has joined #openstack-keystone | 17:30 | |
*** dims has quit IRC | 17:30 | |
dolphm | rbak: then call into keystone's code directly -- get a fernet token provider instance and call validate_v3_token() | 17:31 |
rbak | That might work. I'll give it a shot. | 17:31 |
dolphm | rbak: something like... from keystone.token.providers import fernet; fernet.Provider().validate_v3_token(token_to_validate); | 17:31 |
*** ankita_wagh has joined #openstack-keystone | 17:33 | |
*** jasonsb has quit IRC | 17:33 | |
*** jasonsb has joined #openstack-keystone | 17:33 | |
*** jaosorior has quit IRC | 17:35 | |
*** stevemar has quit IRC | 17:35 | |
*** e0ne has quit IRC | 17:36 | |
*** tonytan4ever has joined #openstack-keystone | 17:36 | |
*** jasonsb_ has joined #openstack-keystone | 17:37 | |
lbragstad | rbak: yep, ++ to what dolphm suggested, you should be able to pass the string to the validate_v3_token method | 17:37 |
*** jasonsb has quit IRC | 17:38 | |
*** stevemar has joined #openstack-keystone | 17:38 | |
*** ChanServ sets mode: +v stevemar | 17:38 | |
*** e0ne has joined #openstack-keystone | 17:39 | |
*** mylu has quit IRC | 17:41 | |
*** mylu has joined #openstack-keystone | 17:42 | |
*** stevemar has quit IRC | 17:42 | |
*** ig0r__ has joined #openstack-keystone | 17:43 | |
*** ig0r_ has quit IRC | 17:46 | |
*** aix has joined #openstack-keystone | 17:48 | |
*** doug-fish has quit IRC | 17:51 | |
*** henrynash has joined #openstack-keystone | 17:51 | |
*** ChanServ sets mode: +v henrynash | 17:51 | |
*** doug-fish has joined #openstack-keystone | 17:51 | |
lhcheng | lbragstad: posted a quick question on: https://review.openstack.org/#/c/214766/5/keystone/contrib/federation/routers.py | 17:55 |
lbragstad | lhcheng: responded | 17:57 |
lbragstad | lhcheng: thanks :) | 17:57 |
lhcheng | lbragstad: okay, cool. Just noticed it when I was reading the code again. :) | 17:57 |
*** csoukup has quit IRC | 17:59 | |
*** tsymancz1k has quit IRC | 18:01 | |
*** tsymanczyk has joined #openstack-keystone | 18:02 | |
*** stevemar has joined #openstack-keystone | 18:03 | |
*** ChanServ sets mode: +v stevemar | 18:03 | |
*** csoukup has joined #openstack-keystone | 18:04 | |
*** mylu has quit IRC | 18:06 | |
*** mylu has joined #openstack-keystone | 18:07 | |
*** mylu has quit IRC | 18:11 | |
*** mylu has joined #openstack-keystone | 18:13 | |
*** henrynash has quit IRC | 18:15 | |
*** mylu has quit IRC | 18:16 | |
*** mylu has joined #openstack-keystone | 18:16 | |
*** markvoelker has joined #openstack-keystone | 18:17 | |
*** henrynash has joined #openstack-keystone | 18:18 | |
*** ChanServ sets mode: +v henrynash | 18:18 | |
*** markvoelker has quit IRC | 18:21 | |
*** mylu has quit IRC | 18:21 | |
*** petertr7 is now known as petertr7_away | 18:23 | |
*** petertr7_away is now known as petertr7 | 18:25 | |
*** exploreshaifali has quit IRC | 18:28 | |
*** mylu has joined #openstack-keystone | 18:32 | |
*** gyee has quit IRC | 18:33 | |
*** ankita_w_ has joined #openstack-keystone | 18:33 | |
*** ankita_wagh has quit IRC | 18:37 | |
*** tonytan4ever has quit IRC | 18:38 | |
*** tonytan4ever has joined #openstack-keystone | 18:38 | |
*** tonytan4ever has quit IRC | 18:38 | |
*** ayoung has joined #openstack-keystone | 18:38 | |
*** ChanServ sets mode: +v ayoung | 18:38 | |
*** henrynash has quit IRC | 18:41 | |
*** henrynash has joined #openstack-keystone | 18:42 | |
*** ChanServ sets mode: +v henrynash | 18:42 | |
*** henrynash has quit IRC | 18:43 | |
openstackgerrit | Tom Cocozzello proposed openstack/keystone: Replace deprecated olso_db sqalchemy EngineFacade with enginefacade https://review.openstack.org/218983 | 18:43 |
openstackgerrit | Tom Cocozzello proposed openstack/keystone: Replace deprecated olso_db sqalchemy EngineFacade with enginefacade https://review.openstack.org/218983 | 18:44 |
openstackgerrit | Nina Goradia proposed openstack/keystone: Use oslo.log fixture https://review.openstack.org/217362 | 18:48 |
*** ig0r__ has quit IRC | 18:48 | |
*** stevemar has quit IRC | 18:54 | |
*** ankita_w_ has quit IRC | 18:54 | |
*** ankita_wagh has joined #openstack-keystone | 18:54 | |
*** edmondsw has quit IRC | 18:56 | |
*** tsymanczyk has quit IRC | 18:56 | |
*** edmondsw has joined #openstack-keystone | 18:57 | |
ayoung | morgan, dolphm what should the v3 url be linked to? 35357, or 5000? We have a pretty nasty approach right now: http://git.openstack.org/cgit/openstack/keystone/tree/keystone/controllers.py#n31 | 18:57 |
ayoung | it means that v3 is pretty much broken for people thatdon't make 35357 available | 18:58 |
morgan | I'd say 5000 if we had to pick | 18:58 |
*** tsymanczyk has joined #openstack-keystone | 18:58 | |
morgan | But i'd rather drive towards 443/80 than locking in 5000 | 18:58 |
*** tsymanczyk is now known as Guest71316 | 18:59 | |
morgan | Since 5000 was needed for v2 auth anyway it might be an easier "port already open" sell. | 18:59 |
lbragstad | dstanek: fernet consolidation, per our discussion earlier - https://review.openstack.org/#/q/status:open+project:openstack/keystone+branch:master+topic:consolidate-fernet-provider,n,z | 18:59 |
doug-fish | morgan, marekd I'm looking at your comments on https://review.openstack.org/#/c/209671/4/keystoneauth1/identity/v3/k2k.py and I see what you are saying, but I'm having a complete blank about how REQUEST_ECP_URL and rescoping_plugin _should_ be documented | 19:00 |
*** dikonoor has quit IRC | 19:00 | |
doug-fish | can either of you point me to a relevant example? | 19:00 |
morgan | raildo: ^ cc do you have an example ( jamielennox cc too) | 19:01 |
morgan | doug-fish: i can look post coffee. Trying to eat breakfast at noon here still :P | 19:02 |
doug-fish | :-) understood | 19:02 |
dstanek | lbragstad: thx | 19:04 |
lbragstad | dstanek: no problem | 19:05 |
*** jsavak has quit IRC | 19:05 | |
ayoung | morgan, so I can open this as a bug and make the default that V3 is the same as the public interface? | 19:06 |
*** jsavak has joined #openstack-keystone | 19:06 | |
morgan | Yeah | 19:06 |
morgan | Sounds good to me. | 19:06 |
morgan | But isnt this just catalog driven? | 19:07 |
morgan | So devstack change? | 19:07 |
morgan | Or doc bug? | 19:07 |
ayoung | its code | 19:08 |
ayoung | morgan, http://git.openstack.org/cgit/openstack/keystone/tree/keystone/controllers.py#n31 | 19:08 |
morgan | I think someone else was just complaining about this a week or two ago | 19:08 |
morgan | Might be a bug already / pending fix fwiw | 19:09 |
ayoung | morgan, lets see if it is | 19:09 |
morgan | But yes, i see v3 as defaulting to 5000 as the right course. | 19:10 |
ayoung | I don't see it in the bug report. | 19:12 |
*** hrou has joined #openstack-keystone | 19:12 | |
morgan | Nod. | 19:12 |
dstanek | morgan: are you referring to the bug where we are not generating the right links back when using 35357? | 19:15 |
morgan | Yeah i think that was related | 19:16 |
morgan | ayoung: ^ cc ? | 19:16 |
dstanek | morgan: ayoung: this one https://bugs.launchpad.net/keystone/+bug/1235340 | 19:20 |
openstack | Launchpad bug 1235340 in Keystone "Links always use public endpoint" [Wishlist,Triaged] | 19:20 |
ayoung | dstanek, it looks like it is the same thing, but I can't see how jamie's comment applies to the code I just read | 19:22 |
ayoung | I thihnk it might be slightly different | 19:22 |
*** shaleh has joined #openstack-keystone | 19:23 | |
*** ankita_wagh has quit IRC | 19:24 | |
*** dsirrine has joined #openstack-keystone | 19:25 | |
*** dsirrine_ has joined #openstack-keystone | 19:26 | |
*** petertr7 is now known as petertr7_away | 19:28 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Materialized path mixin for hierarchical models https://review.openstack.org/198418 | 19:29 |
*** dsirrine has quit IRC | 19:30 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Materialized path mixin for hierarchical models https://review.openstack.org/198418 | 19:32 |
*** exploreshaifali has joined #openstack-keystone | 19:33 | |
amakarov | lbragstad, hi! I've done some load-testing ^^ Please look at https://review.openstack.org/#/c/198418/16 : there are test sample and my results | 19:33 |
openstackgerrit | Marianne Linhares Monteiro proposed openstack/keystone: List credentials by type https://review.openstack.org/208620 | 19:33 |
*** diazjf has quit IRC | 19:39 | |
*** diazjf has joined #openstack-keystone | 19:41 | |
*** bknudson has joined #openstack-keystone | 19:42 | |
*** ChanServ sets mode: +v bknudson | 19:42 | |
*** richm has quit IRC | 19:44 | |
*** mriedem has joined #openstack-keystone | 19:47 | |
*** mylu has quit IRC | 19:48 | |
*** petertr7_away is now known as petertr7 | 19:48 | |
*** mylu has joined #openstack-keystone | 19:48 | |
*** Guest71316 has quit IRC | 19:48 | |
openstackgerrit | Matt Riedemann proposed openstack/python-keystoneclient: Mask passwords when logging the HTTP response https://review.openstack.org/219004 | 19:49 |
mriedem | lbragstad: ^ should be near and dear to your heart | 19:49 |
anteaya | anyone know when stevemar is expected online again? | 19:51 |
mriedem | anteaya: you can probably easy get a hold of him on twitter | 19:51 |
mriedem | :) | 19:51 |
mriedem | *easily | 19:51 |
*** richm has joined #openstack-keystone | 19:52 | |
dstanek | anteaya: yeah, he is traveling this week | 19:52 |
anteaya | mriedem: hehe | 19:52 |
anteaya | dstanek: k thanks | 19:52 |
*** mylu has quit IRC | 19:53 | |
*** stevemar has joined #openstack-keystone | 19:54 | |
*** ChanServ sets mode: +v stevemar | 19:54 | |
*** ankita_wagh has joined #openstack-keystone | 19:55 | |
dstanek | is there any reason for us to create/maintain a WADL? https://bugs.launchpad.net/keystone/+bug/1023948 | 19:56 |
openstack | Launchpad bug 1023948 in Keystone "v3api - create WADL for v3 api" [Wishlist,Confirmed] | 19:56 |
*** mylu has joined #openstack-keystone | 19:56 | |
*** stevemar has quit IRC | 19:59 | |
htruta | hey, ayoung... in the mood for and easy +2 ? https://review.openstack.org/#/c/212045/1 | 19:59 |
ayoung | no | 19:59 |
ayoung | but for you I'll look | 20:00 |
htruta | ayoung: cool! | 20:01 |
*** david-lyle has quit IRC | 20:01 | |
htruta | ayoung: you can also look forward in the patches chain, when you fell like it :D | 20:01 |
htruta | but I think that I might be asking too much | 20:02 |
*** mylu has quit IRC | 20:02 | |
ayoung | whithout | 20:02 |
*** tsymanczyk has joined #openstack-keystone | 20:03 | |
ayoung | morgan, dolphm when are we planning on making Fernet non-experimental? | 20:03 |
*** mylu has joined #openstack-keystone | 20:03 | |
*** tsymanczyk is now known as Guest30098 | 20:03 | |
morgan | ayoung: next cycle I think. this one we have had enough hiccups that warrant another round | 20:03 |
morgan | ayoung: timestamps, revocations, etc. a little more baking would be good. | 20:04 |
ayoung | nkinder, ^^ that was kindof what I remembered | 20:04 |
morgan | it could happen this cycle, but I'd rather err on the side of caution | 20:04 |
ayoung | morgan, binding... | 20:04 |
morgan | yah | 20:04 |
morgan | we've improved them significantly and I feel they are stable for real use (mfisch has confirmed this for the most part) | 20:04 |
morgan | I want to also flip devstack to use them by default when we make them "stable" | 20:05 |
morgan | which makes me lean towards post liberty | 20:05 |
*** markvoelker has joined #openstack-keystone | 20:06 | |
*** david-lyle has joined #openstack-keystone | 20:06 | |
ayoung | morgan, I think I am going to propose an alternative internal Fernet format that allows a single role to be specified inside. | 20:06 |
*** petertr7 is now known as petertr7_away | 20:06 | |
ayoung | I was contemplating "subset of a users roles" but it is better to get something of a fixed size | 20:06 |
morgan | ayoung: this is what i like about fernet. the payload is opaque | 20:07 |
ayoung | morgan, well, I wouldn't need a different format for PKI, but that is a different story | 20:07 |
morgan | we don't have to worry about if we need to change the payload [it's just another decoder] | 20:07 |
ayoung | so, this is more working with a limitaion of fernet; we need to keep them fixed length. | 20:08 |
morgan | except pki needs to hold any/all info, we could even make fernet expand roles if we wanted | 20:08 |
ayoung | but...it is a good restriction. It will let us focus on on "one role per token" | 20:08 |
morgan | sure. | 20:08 |
ayoung | I'm thinking toward a 4 level default set of roles: | 20:08 |
ayoung | admin, (project) manager, member, audit (read only) | 20:09 |
*** mylu has quit IRC | 20:09 | |
*** mylu has joined #openstack-keystone | 20:09 | |
morgan | i'd go one layer more | 20:09 |
ayoung | strict hierarchy their. If a user has admin, they can explicitly request member, and on down | 20:09 |
ayoung | ? | 20:09 |
morgan | admin (cloud), admin (domain), manager (project), member, audit | 20:10 |
*** stevemar has joined #openstack-keystone | 20:10 | |
*** ChanServ sets mode: +v stevemar | 20:10 | |
ayoung | I was thinking domain manager. We can reuse the manager role, but it means something different on a domain than on a proejct | 20:10 |
ayoung | so...yes | 20:10 |
morgan | sure | 20:10 |
morgan | but same concept, make sure it is clearly outlined in the proposal | 20:11 |
ayoung | lets keep admin for the top most level only | 20:11 |
morgan | vs. implied :) | 20:11 |
*** mriedem has left #openstack-keystone | 20:11 | |
ayoung | plus, domain manager does not imply project manager. They are parallel | 20:11 |
morgan | sortof. | 20:11 |
*** thedodd has quit IRC | 20:11 | |
*** dims has joined #openstack-keystone | 20:11 | |
*** dims has quit IRC | 20:12 | |
morgan | but like i said, lets just make sure to outline it so no questions arise and we have the domain-manager clearly defined | 20:12 |
*** thedodd has joined #openstack-keystone | 20:12 | |
* morgan is in strong agreement with your idea | 20:12 | |
ayoung | morgan, deal. I wonder if there is a good word to use to distinguish between Domain manager and project manager? | 20:14 |
*** dims_ has quit IRC | 20:14 | |
ayoung | domain is going to be mostly for creating users/groups, or setting up mappings etc | 20:15 |
morgan | i would err to the side of admin here | 20:15 |
morgan | tbh | 20:15 |
morgan | it is an admin-type role | 20:15 |
morgan | maybe we call cloud admin "root" :P | 20:15 |
ayoung | morgan, problem is that admin shows up in too many default policy files | 20:15 |
ayoung | we trip over "admin somewhere is admin anywhere" | 20:15 |
morgan | no i would call it "domain-admin" | 20:15 |
morgan | very specifically | 20:15 |
ayoung | dominatrix | 20:15 |
morgan | ahaha | 20:16 |
*** thedodd has quit IRC | 20:16 | |
ayoung | DOMINATOR | 20:16 |
morgan | but what if I want to use a friendship instead? </mortal kombat> | 20:17 |
morgan | i'd call it cloud-admin, cloud-audit, domain-admin, domain-audit, manager|project-admin [something], member | 20:18 |
morgan | if you want to boil down where i'd draw lines | 20:18 |
morgan | but i wouldn't break it down too much further. | 20:18 |
morgan | to begin with | 20:18 |
morgan | s/cloud/global? s/cloud/root? etc | 20:19 |
*** amakarov is now known as amakarov_away | 20:19 | |
morgan | by providing the qualifier to "admin" we can break the "admin" = "admin everywhere" by just making the role mostly become unused | 20:20 |
ayoung | yep | 20:20 |
ayoung | and, we can put a special rule into keystone preventing people from assigning role admin inside a project etc | 20:20 |
morgan | sure. | 20:21 |
morgan | we may want one other role: "service-user" | 20:21 |
morgan | for validating tokens etc | 20:22 |
morgan | not sure if we care though | 20:22 |
morgan | member on service project would be sufficient. [though service-user makes sense to be a "global" role even though we don't have those anymore, just like cloud-admin and cloud-audit would be the sam] | 20:22 |
morgan | same* | 20:23 |
* morgan shrugs | 20:23 | |
openstackgerrit | Doug Fish proposed openstack/keystoneauth: Update k2k plugin with related code comments https://review.openstack.org/209671 | 20:27 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Unit tests for is_domain field in project's table https://review.openstack.org/212045 | 20:30 |
htruta | ayoung: no 'whithout' anymore ^ | 20:30 |
ayoung | htruta, sorry, that was not enough to bump the -2...but I'll look again | 20:30 |
mfisch | sorry for the delay morgan but +1 for fernet default | 20:30 |
ayoung | making my flights first | 20:30 |
htruta | ayoung: np | 20:31 |
*** diazjf has quit IRC | 20:32 | |
*** jsavak has quit IRC | 20:32 | |
*** jsavak has joined #openstack-keystone | 20:33 | |
openstackgerrit | Doug Fish proposed openstack/python-keystoneclient: Add Keystone2Keystone auth plugin for K2K https://review.openstack.org/207585 | 20:34 |
*** _cjones_ has joined #openstack-keystone | 20:41 | |
*** _cjones_ has quit IRC | 20:42 | |
*** jsavak has quit IRC | 20:43 | |
*** gyee has joined #openstack-keystone | 20:43 | |
*** ChanServ sets mode: +v gyee | 20:43 | |
*** phalmos has quit IRC | 20:46 | |
*** ebalduf has joined #openstack-keystone | 20:52 | |
openstackgerrit | Merged openstack/python-keystoneclient: Updated from global requirements https://review.openstack.org/217205 | 20:53 |
*** diazjf has joined #openstack-keystone | 20:55 | |
*** markvoelker has quit IRC | 20:56 | |
openstackgerrit | David Stanek proposed openstack/keystone: Initial support for versioned driver classes https://review.openstack.org/218481 | 20:56 |
*** dims has joined #openstack-keystone | 20:57 | |
*** jasonsb_ has quit IRC | 21:01 | |
openstackgerrit | David Stanek proposed openstack/keystone: Force SQLite to properly deal with foreign keys https://review.openstack.org/126030 | 21:01 |
*** diazjf has quit IRC | 21:05 | |
*** shaleh_ has joined #openstack-keystone | 21:07 | |
*** stevemar has quit IRC | 21:08 | |
*** diazjf has joined #openstack-keystone | 21:10 | |
*** spandhe has joined #openstack-keystone | 21:10 | |
*** shaleh has quit IRC | 21:11 | |
*** doug-fish has quit IRC | 21:11 | |
*** topol has quit IRC | 21:12 | |
*** jasonsb has joined #openstack-keystone | 21:13 | |
*** mylu has quit IRC | 21:13 | |
openstackgerrit | Timothy Symanczyk proposed openstack/keystone: Only call isotime on datetime objects https://review.openstack.org/219032 | 21:27 |
*** zzzeek has quit IRC | 21:29 | |
*** e0ne has quit IRC | 21:34 | |
*** diazjf has quit IRC | 21:37 | |
*** dsirrine_ has quit IRC | 21:38 | |
morgan | dstanek: +2 on the versioned driver interfaces. One comment I added that can be addressed in a followup | 21:40 |
morgan | dstanek: we should enforce that all arguments to a driver are passed as kwargs | 21:40 |
*** claudiub has quit IRC | 21:40 | |
morgan | dstanek: that way positional argument issues wont ever arise. | 21:40 |
*** Guest30098 is now known as tsymanczyk | 21:42 | |
*** dave-mccowan has quit IRC | 21:46 | |
dstanek | morgan: what kwargs issues are you worried about? | 21:47 |
*** ebalduf has quit IRC | 21:47 | |
morgan | dstanek: if we force the use of kwargs [always kwargs] we never accidently break a driver if we reorder args | 21:47 |
morgan | we could even stylistically force args to be alpha | 21:47 |
morgan | alphabetical order that is | 21:48 |
morgan | it just means no one ever relies on driver.method(arg1, arg2, kwarg1=thing) | 21:48 |
morgan | even if the arg is "positional" by definition we want to have them always passed as a kwarg? (feel free to disagree with me) | 21:49 |
dstanek | morgan: if we version the interface it shouldn't be that big of a deal, i'm not opposed to the idea | 21:50 |
morgan | like i said, just an extra barrier to make it less likely to cause issues | 21:51 |
morgan | with new args on a method | 21:51 |
morgan | except i now think about it... we can't enforce this on 3rd party drivers | 21:52 |
morgan | we can enforce it on ours in gate so the manager doesn't do something silly | 21:52 |
dstanek | morgan: we can inspect how the methods are called if we really, really care | 21:52 |
morgan | if we were doing the py34 model i'd use the kwarg-only notation, but we're not. we might just want a hacking check that we always use kwargs for manager->driver calls? | 21:53 |
morgan | or something. | 21:53 |
*** ninag has joined #openstack-keystone | 21:53 | |
morgan | anyway +2 still on your patch | 21:55 |
morgan | for sure | 21:55 |
morgan | :) | 21:55 |
*** dramakri has joined #openstack-keystone | 22:03 | |
*** thedodd has joined #openstack-keystone | 22:05 | |
*** thiagop has quit IRC | 22:06 | |
*** zzzeek has joined #openstack-keystone | 22:06 | |
dramakri | bkundson: ping.. you had concern around the patch https://review.openstack.org/#/c/196942/ . I have commented my thoughts there. can you please take a look when you get a chance? | 22:10 |
htruta | ayoung: you rock! | 22:11 |
ayoung | htruta, I Approved the patch. THere was a Grenade failrue that I'm certain is spurious. If the patch merge fails, ping me and I'll shepherd it through. | 22:11 |
*** markvoelker has joined #openstack-keystone | 22:11 | |
htruta | ayoung: it is a grenade problem... I've been doing lots of rechecks in the last days | 22:12 |
htruta | ayoung: just fyi, this one: https://review.openstack.org/#/c/213448/ and the one after it are also willing to be approved. put them on your review list as well | 22:13 |
*** sigmavirus24 is now known as sigmavirus24_awa | 22:15 | |
*** markvoelker has quit IRC | 22:16 | |
*** dguerri` is now known as dguerri | 22:27 | |
morgan | htruta: ^ that one needs a rebase | 22:27 |
morgan | htruta: as will the subsequent ones | 22:28 |
*** edmondsw has quit IRC | 22:28 | |
*** ninag has quit IRC | 22:28 | |
htruta | morgan: yes... it's just the "whithout" nit I corrected in the previous one... Didn't want to rebase the patches all the time, because we already had patches we 100+ pacthsets and very few reviews | 22:29 |
morgan | well without the rebase the patches can't be approved FYI. | 22:29 |
*** dguerri is now known as dguerri` | 22:31 | |
ayoung | htruta, rebase should not change the review status. go ahead and do the rebase. | 22:36 |
*** btully has quit IRC | 22:36 | |
ayoung | I'll review after dinner | 22:36 |
htruta | ayoung: ok. I'll do it | 22:41 |
*** fangzhou has joined #openstack-keystone | 22:48 | |
*** richm has quit IRC | 22:48 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Manager support for projects acting as domains https://review.openstack.org/213448 | 22:51 |
htruta | ayoung ^done | 22:52 |
*** csoukup has quit IRC | 22:56 | |
*** rbak has quit IRC | 23:01 | |
*** gordc has quit IRC | 23:02 | |
*** stevemar has joined #openstack-keystone | 23:04 | |
*** ChanServ sets mode: +v stevemar | 23:04 | |
*** exploreshaifali has quit IRC | 23:04 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Change JSON Home for OS-FEDERATION to use /auth/projects|domains https://review.openstack.org/219059 | 23:08 |
*** hrou has quit IRC | 23:09 | |
*** thedodd has quit IRC | 23:12 | |
*** jasonsb has quit IRC | 23:13 | |
jamielennox | lhcheng: I've been experimenting with DOA as well and i came up with option 3 as well | 23:24 |
jamielennox | lhcheng: at the moment WEBSSO_CHOICES is fed directly into the form builder (i always wondered why they chose that format initially) and another dictionary element was the best way | 23:25 |
jamielennox | s/best/easiest | 23:25 |
lhcheng | jamielennox: cool, glad we are all in agreement. | 23:27 |
lhcheng | jamielennox: https://review.openstack.org/#/c/219041/ | 23:27 |
lhcheng | I found a regression in the horizon login page, still digging into it. Will be able to test the flow once I found the issue in horizon. | 23:28 |
*** ankita_wagh has quit IRC | 23:35 | |
*** stevemar has quit IRC | 23:38 | |
jamielennox | dolphm: if you're still around, can you look at my response to https://review.openstack.org/#/c/216088/ - i had to do a rebase so your -1 is gone | 23:38 |
*** pnavarro has quit IRC | 23:38 | |
*** dramakri has left #openstack-keystone | 23:39 | |
*** dramakri has quit IRC | 23:39 | |
*** dave-mccowan has joined #openstack-keystone | 23:41 | |
*** shoutm has joined #openstack-keystone | 23:46 | |
*** btully has joined #openstack-keystone | 23:52 | |
*** diegows has quit IRC | 23:53 | |
*** btully has quit IRC | 23:57 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!