*** stevemar_ has joined #openstack-keystone | 00:00 | |
*** ChanServ sets mode: +o stevemar_ | 00:00 | |
*** Daviey has quit IRC | 00:04 | |
*** EinstCrazy has quit IRC | 00:05 | |
*** mylu has joined #openstack-keystone | 00:16 | |
*** su_zhang has joined #openstack-keystone | 00:19 | |
lbragstad | stevemar_ yeah, i know :-/ | 00:22 |
---|---|---|
*** shadower has quit IRC | 00:23 | |
*** shadower has joined #openstack-keystone | 00:23 | |
lbragstad | stevemar_ i was reviewing code on friday and noticed that the names contained status codes. Since we landed a recent refactor, I thought it would be useful to change those, too. | 00:23 |
lbragstad | stevemar_ it was totally and "oh, squirrel!" moment | 00:24 |
lbragstad | s/and/an/ | 00:24 |
*** dimsum__ has joined #openstack-keystone | 00:24 | |
*** wwwjfy has joined #openstack-keystone | 00:26 | |
lbragstad | https://www.youtube.com/watch?v=SSUXXzN26zg | 00:26 |
*** hrou has joined #openstack-keystone | 00:28 | |
*** akanksha_ has quit IRC | 00:28 | |
*** akanksha_ has joined #openstack-keystone | 00:30 | |
*** dimsum__ has quit IRC | 00:31 | |
*** wwwjfy has quit IRC | 00:34 | |
*** wwwjfy has joined #openstack-keystone | 00:39 | |
*** diazjf has joined #openstack-keystone | 00:41 | |
*** diazjf has left #openstack-keystone | 00:42 | |
*** topol has joined #openstack-keystone | 00:49 | |
*** ChanServ sets mode: +v topol | 00:49 | |
*** chlong has joined #openstack-keystone | 00:51 | |
*** diegows has quit IRC | 00:55 | |
*** dimsum__ has joined #openstack-keystone | 00:57 | |
*** topol has quit IRC | 00:57 | |
*** mestery has quit IRC | 00:57 | |
*** topol has joined #openstack-keystone | 00:58 | |
*** ChanServ sets mode: +v topol | 00:58 | |
*** ayoung has joined #openstack-keystone | 00:58 | |
*** ChanServ sets mode: +v ayoung | 00:58 | |
*** mylu_ has joined #openstack-keystone | 00:59 | |
*** mylu has quit IRC | 00:59 | |
*** dimsum__ has quit IRC | 01:00 | |
*** topol has quit IRC | 01:02 | |
*** EinstCrazy has joined #openstack-keystone | 01:03 | |
*** gildub has joined #openstack-keystone | 01:13 | |
*** dimsum__ has joined #openstack-keystone | 01:20 | |
*** su_zhang has quit IRC | 01:25 | |
*** tellesnobrega is now known as tellesnobrega_af | 01:25 | |
*** dimsum__ has quit IRC | 01:27 | |
*** dimsum__ has joined #openstack-keystone | 01:31 | |
*** su_zhang has joined #openstack-keystone | 01:31 | |
*** su_zhang has quit IRC | 01:34 | |
*** ozialien has quit IRC | 01:37 | |
*** ozialien has joined #openstack-keystone | 01:37 | |
*** phalmos has joined #openstack-keystone | 01:41 | |
*** wwwjfy has quit IRC | 01:42 | |
*** csoukup has joined #openstack-keystone | 01:46 | |
*** btully has quit IRC | 01:51 | |
*** davechen has joined #openstack-keystone | 01:51 | |
*** davechen1 has joined #openstack-keystone | 01:56 | |
*** su_zhang has joined #openstack-keystone | 01:58 | |
*** davechen has quit IRC | 01:58 | |
*** davechen has joined #openstack-keystone | 02:00 | |
*** davechen1 has quit IRC | 02:02 | |
*** su_zhang has quit IRC | 02:03 | |
*** su_zhang has joined #openstack-keystone | 02:04 | |
*** phalmos has quit IRC | 02:05 | |
*** davechen1 has joined #openstack-keystone | 02:07 | |
*** davechen has quit IRC | 02:09 | |
*** davechen has joined #openstack-keystone | 02:12 | |
*** davechen1 has quit IRC | 02:15 | |
*** mylu_ has quit IRC | 02:16 | |
*** mylu has joined #openstack-keystone | 02:18 | |
*** chlong has quit IRC | 02:18 | |
*** GB21 has quit IRC | 02:24 | |
*** david-ly_ has joined #openstack-keystone | 02:31 | |
*** dimsum__ has quit IRC | 02:32 | |
*** david-lyle has quit IRC | 02:33 | |
*** diazjf has joined #openstack-keystone | 02:37 | |
*** diazjf has left #openstack-keystone | 02:38 | |
*** topol has joined #openstack-keystone | 02:44 | |
*** ChanServ sets mode: +v topol | 02:44 | |
*** wwwjfy has joined #openstack-keystone | 02:50 | |
*** tobe has joined #openstack-keystone | 03:04 | |
openstackgerrit | ayoung proposed openstack/keystone: Strip admin roles from non-admin projects and domains https://review.openstack.org/233480 | 03:19 |
ayoung | jamielennox, ^^ Oh yes I did. | 03:19 |
*** marzif has joined #openstack-keystone | 03:22 | |
*** topol has quit IRC | 03:31 | |
*** chlong has joined #openstack-keystone | 03:32 | |
*** dimsum__ has joined #openstack-keystone | 03:32 | |
*** roxanaghe has joined #openstack-keystone | 03:33 | |
*** david-lyle has joined #openstack-keystone | 03:37 | |
*** dimsum__ has quit IRC | 03:38 | |
*** david-ly_ has quit IRC | 03:40 | |
*** dimsum__ has joined #openstack-keystone | 03:40 | |
*** diazjf has joined #openstack-keystone | 03:45 | |
*** diazjf has left #openstack-keystone | 03:46 | |
*** su_zhang has quit IRC | 03:47 | |
*** roxanaghe has quit IRC | 03:48 | |
stevemar_ | lbragstad: oh it's cool, run with it | 03:48 |
*** dimsum__ has quit IRC | 03:50 | |
*** roxanaghe has joined #openstack-keystone | 03:50 | |
jamielennox | ayoung: interesting stop gap, will need to think about it some more | 03:52 |
stevemar_ | lbragstad: your chain is now gating | 03:53 |
stevemar_ | jamielennox: it is interesting | 03:53 |
jamielennox | stevemar_: it feels like a stop gap, and i'm wondering if it's a stop gap that is going to require configuration changes is there something more permanent we could do | 03:54 |
*** su_zhang has joined #openstack-keystone | 03:55 | |
ayoung | jamielennox, its also due to code inertia. And due to the fact that admin as a role was origianlly global, that is kindof how everyone thinks of it. | 03:56 |
ayoung | But, THe other thing it does is (I think) frees us to split to scope check from the role check, so long as the role 'admin' is handled specifically, the exisint p[olicy files for nova nad neutorn work as a scope check only already | 03:57 |
ayoung | so we can put the role check into middleware, and base it on the URL as opposed to the project | 03:57 |
ayoung | The existing policy files don't actually check any role aside from admin. This lets that continue to work | 03:58 |
jamielennox | ayoung: so essentially give in to the fact that 'admin' is a special role | 03:58 |
ayoung | yep | 03:58 |
jamielennox | that works ok for the people who set the config option | 03:58 |
ayoung | jamielennox, and doesn't break people who don't | 03:58 |
jamielennox | i'm not sure cementing that assumption is a good idea if people don't | 03:58 |
ayoung | I think I've tilted at this windmill long enough to know I am not going to defeat it | 03:59 |
stevemar_ | jamielennox: ayoung pose the question on the operations feedback etherpad | 03:59 |
jamielennox | well it's going to take a really long time | 03:59 |
*** su_zhang has quit IRC | 03:59 | |
stevemar_ | https://etherpad.openstack.org/p/TYO-ops-feedback-into-PWG | 04:00 |
ayoung | jamielennox, time that, unfortunately, I can not afford to spend. I need to work on things that will have actual effect. | 04:00 |
ayoung | And, this sidsteps the issue | 04:00 |
jamielennox | so what i think would be cool is some proper policy testing to see if removing admin will even work | 04:00 |
ayoung | stevemar_, what | 04:00 |
ayoung | what's your gut reaction? | 04:00 |
stevemar_ | ayoung: i do feel like its a stop gap as well, i'm pretty sure folks do rely on the "admin" role heavily, so it could work | 04:01 |
jamielennox | my gut reaction is that this is still an operator change, and if the operator is savvy enough to understand the option they should be able to manage their roles | 04:01 |
jamielennox | having said that | 04:01 |
jamielennox | i realize it hasn't happened yet | 04:01 |
ayoung | jamielennox, the feedback we've gotten is that no one changes their policy files | 04:02 |
stevemar_ | ayoung: definitely not | 04:02 |
stevemar_ | i mean, i agree, they definitely do not change policy files | 04:02 |
ayoung | I think this is the right approach. In the future, we can do something smarter, but it requires a lot of infrastructure to get us there | 04:03 |
ayoung | implied roles, dynamic policy, all that won;t get adopted for 2+ cycles after it is merged at the earliest | 04:03 |
ayoung | and this change is backportable | 04:03 |
jamielennox | yea, i'll think about it a bit more, and it's a bit annoying that it rules out using admin for project specific admin, but we might have burnt that bridge | 04:04 |
jamielennox | stevemar_: can you have a look at: https://review.openstack.org/#/c/227611/ | 04:04 |
ayoung | jamielennox, it means that project specific admin needs a different role name | 04:04 |
jamielennox | ayoung: yep | 04:04 |
ayoung | and I think that I would recommend that anyway | 04:04 |
jamielennox | ayoung: well it's a misinterpration of the other projects (openstack projects) really | 04:05 |
jamielennox | having admin should still be specific to the scope they are in | 04:05 |
ayoung | gloabl roles were there first. We were the ones that changed it. | 04:05 |
* ayoung not sure who it was. | 04:05 | |
stevemar_ | hehe, so many random white space changes: https://review.openstack.org/#/c/233480/1/keystone/tests/unit/test_v3_assignment.py | 04:06 |
jamielennox | maybe if i have some more self guided time in the future i can try and climb that mountain... | 04:06 |
stevemar_ | i think we could make this a bit slicker | 04:06 |
ayoung | stevemar_, must be the autopep8...damnit | 04:07 |
stevemar_ | :) | 04:07 |
ayoung | stevemar_, I had that happen on another changeset, too. Is that a pep8 violation being fixed there? | 04:08 |
jamielennox | ayoung: can i give you an easy couple as well: https://review.openstack.org/#/c/229161/ https://review.openstack.org/#/c/212344/ | 04:08 |
stevemar_ | ayoung: nah, the code is currently pep8 compliant | 04:16 |
ayoung | stevemar_, I bet that there is an exception in there, and autopep8 is not being run with that exception enabled | 04:17 |
ayoung | stevemar_, but, no big deal. I can reverse those lines. Just that the autopep -i approach makes the pep8 thing so much easier to deal with, it would be nice if we could make that work | 04:17 |
*** su_zhang has joined #openstack-keystone | 04:19 | |
*** david_cu has joined #openstack-keystone | 04:28 | |
*** david_cu has quit IRC | 04:36 | |
stevemar_ | ayoung: gyee had some comments | 04:41 |
*** btully has joined #openstack-keystone | 04:44 | |
*** chlong has quit IRC | 04:45 | |
openstackgerrit | Merged openstack/keystone: Refactor: change 404 status codes in test names https://review.openstack.org/233124 | 04:48 |
*** dimsum__ has joined #openstack-keystone | 04:51 | |
*** hrou has quit IRC | 04:51 | |
*** dimsum__ has quit IRC | 04:54 | |
*** chlong has joined #openstack-keystone | 04:57 | |
openstackgerrit | Merged openstack/keystone: Refactor: change 400 status codes in test names https://review.openstack.org/233125 | 05:07 |
openstackgerrit | Merged openstack/keystone: Refactor: change 410 status codes in test names https://review.openstack.org/233126 | 05:07 |
*** roxanaghe has quit IRC | 05:10 | |
*** marzif has quit IRC | 05:10 | |
*** Nirupama has joined #openstack-keystone | 05:11 | |
*** amakarov has joined #openstack-keystone | 05:13 | |
*** tsufiev_ has joined #openstack-keystone | 05:13 | |
openstackgerrit | Merged openstack/keystonemiddleware: Seperate standalone cache tests https://review.openstack.org/212344 | 05:20 |
openstackgerrit | Merged openstack/keystonemiddleware: Use request helpers for token_info/token_auth https://review.openstack.org/229161 | 05:25 |
*** roxanaghe has joined #openstack-keystone | 05:25 | |
*** roxanaghe has quit IRC | 05:30 | |
*** stevemar_ has quit IRC | 05:34 | |
*** mylu has quit IRC | 05:40 | |
*** jtomasek has joined #openstack-keystone | 05:50 | |
*** su_zhang has quit IRC | 05:53 | |
*** dimsum__ has joined #openstack-keystone | 05:54 | |
*** stevemar_ has joined #openstack-keystone | 05:54 | |
*** ChanServ sets mode: +o stevemar_ | 05:54 | |
*** gildub has quit IRC | 05:58 | |
*** dimsum__ has quit IRC | 05:59 | |
*** jaosorior has joined #openstack-keystone | 06:03 | |
*** mflobo1 has left #openstack-keystone | 06:10 | |
*** mflobo has joined #openstack-keystone | 06:11 | |
*** mflobo has left #openstack-keystone | 06:14 | |
*** roxanaghe has joined #openstack-keystone | 06:27 | |
*** stevemar_ has quit IRC | 06:27 | |
*** stevemar_ has joined #openstack-keystone | 06:28 | |
*** ChanServ sets mode: +o stevemar_ | 06:28 | |
*** roxanaghe has quit IRC | 06:31 | |
*** rudolfvriend has joined #openstack-keystone | 06:32 | |
*** stevemar_ has quit IRC | 06:33 | |
davechen | lhcheng: here? | 06:41 |
*** dimsum__ has joined #openstack-keystone | 06:55 | |
*** kiran-r has joined #openstack-keystone | 06:59 | |
*** dimsum__ has quit IRC | 07:01 | |
*** browne has quit IRC | 07:09 | |
*** aix has joined #openstack-keystone | 07:10 | |
*** flaper87 has quit IRC | 07:17 | |
*** flaper87 has joined #openstack-keystone | 07:17 | |
*** dixiaoli has joined #openstack-keystone | 07:21 | |
*** dixiaoli has quit IRC | 07:23 | |
*** ParsectiX has joined #openstack-keystone | 07:26 | |
*** roxanaghe has joined #openstack-keystone | 07:28 | |
*** akanksha_ has quit IRC | 07:28 | |
*** btully has quit IRC | 07:29 | |
*** stevemar_ has joined #openstack-keystone | 07:29 | |
*** ChanServ sets mode: +o stevemar_ | 07:29 | |
*** roxanaghe has quit IRC | 07:32 | |
*** stevemar_ has quit IRC | 07:34 | |
*** kiran-r has quit IRC | 07:36 | |
*** henrynash has quit IRC | 07:46 | |
*** pnavarro|off has joined #openstack-keystone | 07:51 | |
*** fhubik has joined #openstack-keystone | 07:55 | |
*** rudolfvriend has quit IRC | 07:56 | |
*** dimsum__ has joined #openstack-keystone | 07:57 | |
*** pnavarro|off has quit IRC | 07:58 | |
*** dimsum__ has quit IRC | 08:02 | |
*** mjb has quit IRC | 08:03 | |
*** rm_work has quit IRC | 08:03 | |
*** mjb has joined #openstack-keystone | 08:05 | |
*** urulama has joined #openstack-keystone | 08:05 | |
*** rm_work has joined #openstack-keystone | 08:05 | |
*** Guest2082 is now known as d0ugal | 08:09 | |
*** d0ugal has joined #openstack-keystone | 08:09 | |
*** btully has joined #openstack-keystone | 08:09 | |
*** marzif has joined #openstack-keystone | 08:13 | |
*** btully has quit IRC | 08:14 | |
*** marzif has quit IRC | 08:14 | |
*** marzif has joined #openstack-keystone | 08:15 | |
*** marzif_ has joined #openstack-keystone | 08:16 | |
*** marzif has quit IRC | 08:20 | |
*** lhcheng has quit IRC | 08:20 | |
*** e0ne has joined #openstack-keystone | 08:24 | |
*** fmarco76 has joined #openstack-keystone | 08:32 | |
*** fmarco76 has quit IRC | 08:33 | |
jamielennox | morgan, dolphm, bknudson: I'd really like to get this backport in if you can have a look https://review.openstack.org/#/c/225516/ | 08:34 |
*** chlong has quit IRC | 08:35 | |
*** jvarlamova has quit IRC | 08:36 | |
*** pnavarro|off has joined #openstack-keystone | 08:36 | |
*** pnavarro|off has quit IRC | 08:44 | |
*** jistr has joined #openstack-keystone | 08:46 | |
*** ParsectiX has quit IRC | 08:55 | |
*** dimsum__ has joined #openstack-keystone | 08:58 | |
*** aix has quit IRC | 08:58 | |
*** dimsum__ has quit IRC | 09:04 | |
*** fhubik is now known as fhubik_brb | 09:07 | |
*** marzif_ has quit IRC | 09:08 | |
*** marzif_ has joined #openstack-keystone | 09:09 | |
*** wwwjfy has quit IRC | 09:10 | |
*** aix has joined #openstack-keystone | 09:12 | |
*** fhubik_brb is now known as fhubik | 09:15 | |
*** breton has quit IRC | 09:19 | |
*** ParsectiX has joined #openstack-keystone | 09:20 | |
*** marzif_ has quit IRC | 09:21 | |
openstackgerrit | Marek Denis proposed openstack/keystone: Adds a base class for functional tests https://review.openstack.org/203142 | 09:23 |
openstackgerrit | Marek Denis proposed openstack/keystone: Federation Identity Provider functional tests https://review.openstack.org/203258 | 09:25 |
openstackgerrit | Marek Denis proposed openstack/keystone: Functional tests for federation mapping CRUD https://review.openstack.org/231574 | 09:25 |
*** yuwen has joined #openstack-keystone | 09:33 | |
*** kurtrao has joined #openstack-keystone | 09:36 | |
*** ParsectiX has quit IRC | 09:41 | |
*** fhubik is now known as fhubik_brb | 09:44 | |
yuwen | I want to ask some questions about Keystone Federation feature in Kilo. | 09:50 |
yuwen | refer to http://docs.openstack.org/developer/keystone/configure_federation.html, | 09:50 |
yuwen | we can config the keystone as an Identity Provider (IdP). | 09:50 |
yuwen | in the doc, idp_sso_endpoint=https://keystone.example.com/v3/OS-FEDERATION/saml2/sso | 09:50 |
yuwen | when SP single sign on the keystone, it occurs 404 https://keystone.example.com/v3/OS-FEDERATION/saml2/sso not found | 09:50 |
yuwen | Is there any step missed in the http://docs.openstack.org/developer/keystone/configure_federation.html to config the IDP, in the section of [saml] of the keystone.conf | 09:50 |
*** chlong has joined #openstack-keystone | 09:50 | |
yuwen | what the basic steps of keystone IDP configuration? | 09:50 |
yuwen | Can I use keystone(Kilo) IDP as a SAML2.0 Identity Provider? | 09:50 |
yuwen | Can I use WSO2 Identity Server as a SP to integrate Keystone IDP? | 09:50 |
*** davechen has left #openstack-keystone | 09:54 | |
*** topol has joined #openstack-keystone | 09:56 | |
*** ChanServ sets mode: +v topol | 09:56 | |
*** breton has joined #openstack-keystone | 09:58 | |
*** marzif has joined #openstack-keystone | 09:58 | |
*** dimsum__ has joined #openstack-keystone | 10:00 | |
*** topol has quit IRC | 10:00 | |
*** EinstCrazy has quit IRC | 10:01 | |
*** andreykurilin has joined #openstack-keystone | 10:03 | |
andreykurilin | hi everyone! novaclient's functional tests are broken and fails related to keystone - http://logs.openstack.org/77/232677/1/check/gate-novaclient-dsvm-functional/2de31bc/logs/apache/keystone.txt.gz#_2015-10-12_08_52_48_073819 Does anyone can help me? | 10:03 |
*** urulama has quit IRC | 10:04 | |
*** urulama has joined #openstack-keystone | 10:04 | |
*** breton has quit IRC | 10:04 | |
*** dimsum__ has quit IRC | 10:06 | |
*** e0ne_ has joined #openstack-keystone | 10:06 | |
*** wwwjfy has joined #openstack-keystone | 10:07 | |
*** e0ne has quit IRC | 10:09 | |
openstackgerrit | Marek Denis proposed openstack/keystone: Functional tests for federation mapping CRUD https://review.openstack.org/231574 | 10:11 |
*** fhubik_brb is now known as fhubik | 10:12 | |
*** fhubik is now known as fhubik_brb | 10:13 | |
*** e0ne_ has quit IRC | 10:14 | |
*** yuwen has quit IRC | 10:14 | |
openstackgerrit | Marek Denis proposed openstack/keystone: Adds a base class for functional tests https://review.openstack.org/203142 | 10:16 |
*** e0ne has joined #openstack-keystone | 10:19 | |
samueldmq | morning | 10:19 |
openstackgerrit | Marek Denis proposed openstack/keystone: Federation Identity Provider functional tests https://review.openstack.org/203258 | 10:30 |
*** roxanaghe has joined #openstack-keystone | 10:33 | |
openstackgerrit | Marek Denis proposed openstack/keystone: Functional tests for federation mapping CRUD https://review.openstack.org/231574 | 10:36 |
*** roxanaghe has quit IRC | 10:39 | |
*** breton has joined #openstack-keystone | 10:45 | |
*** ParsectiX has joined #openstack-keystone | 10:47 | |
marekd | bknudson: so, did you figure out what is going on with the functional tests? Some people had some objections about the way we are planning to do it today. | 10:54 |
*** EinstCrazy has joined #openstack-keystone | 10:58 | |
*** dikonoor has joined #openstack-keystone | 10:58 | |
*** EinstCrazy has quit IRC | 10:59 | |
*** EinstCrazy has joined #openstack-keystone | 11:00 | |
*** dimsum__ has joined #openstack-keystone | 11:01 | |
*** fhubik_brb is now known as fhubik | 11:03 | |
*** tobe has quit IRC | 11:06 | |
*** tobe has joined #openstack-keystone | 11:06 | |
*** dimsum__ has quit IRC | 11:07 | |
*** Nirupama has quit IRC | 11:15 | |
*** tobe has quit IRC | 11:15 | |
*** tobe has joined #openstack-keystone | 11:16 | |
*** dimsum__ has joined #openstack-keystone | 11:22 | |
*** stevemar_ has joined #openstack-keystone | 11:31 | |
*** ChanServ sets mode: +o stevemar_ | 11:31 | |
*** e0ne has quit IRC | 11:31 | |
*** stevemar_ has quit IRC | 11:35 | |
*** roxanaghe has joined #openstack-keystone | 11:36 | |
*** fhubik is now known as fhubik_brb | 11:38 | |
*** shaifali__ has joined #openstack-keystone | 11:41 | |
*** roxanaghe has quit IRC | 11:42 | |
*** fhubik_brb is now known as fhubik | 11:49 | |
*** urulama has quit IRC | 11:53 | |
*** urulama has joined #openstack-keystone | 11:54 | |
*** su_zhang has joined #openstack-keystone | 12:00 | |
*** fhubik is now known as fhubik_brb | 12:04 | |
*** woodster_ has joined #openstack-keystone | 12:11 | |
*** shaifali__ has quit IRC | 12:16 | |
*** shaifali__ has joined #openstack-keystone | 12:17 | |
*** jaosorior has quit IRC | 12:18 | |
*** e0ne has joined #openstack-keystone | 12:19 | |
*** shaifali__ is now known as exploreshaifail | 12:20 | |
*** fhubik_brb is now known as fhubik | 12:22 | |
*** nisha has joined #openstack-keystone | 12:24 | |
*** Daviey has joined #openstack-keystone | 12:26 | |
*** markvoelker has joined #openstack-keystone | 12:26 | |
*** rha has joined #openstack-keystone | 12:32 | |
*** edmondsw has joined #openstack-keystone | 12:36 | |
*** roxanaghe has joined #openstack-keystone | 12:38 | |
*** roxanaghe has quit IRC | 12:43 | |
*** nisha has quit IRC | 12:45 | |
*** fhubik is now known as fhubik_brb | 12:46 | |
*** exploreshaifail has quit IRC | 12:53 | |
*** hrou has joined #openstack-keystone | 12:58 | |
*** mestery has joined #openstack-keystone | 13:06 | |
*** jaosorior has joined #openstack-keystone | 13:09 | |
*** alexpro has joined #openstack-keystone | 13:09 | |
*** alexpro has quit IRC | 13:12 | |
*** alexpro has joined #openstack-keystone | 13:13 | |
*** alexpro has quit IRC | 13:13 | |
*** njirap has joined #openstack-keystone | 13:16 | |
*** annasort has joined #openstack-keystone | 13:17 | |
*** alexpro has joined #openstack-keystone | 13:20 | |
bknudson | marekd: I don't know how we're planning to do it... is that written down somewhere? | 13:23 |
*** dimsum__ is now known as dims | 13:27 | |
*** dims is now known as Guest2821 | 13:27 | |
*** fhubik_brb is now known as fhubik | 13:27 | |
marekd | bknudson: there are some reviews that i started to work on. | 13:28 |
bknudson | I don't get why we're adding functional tests when the ones we have now don't get run | 13:29 |
marekd | bknudson: for instance https://review.openstack.org/#/c/203258/ and | 13:30 |
marekd | bknudson: which tests do we have now? | 13:31 |
marekd | bknudson: which *functional* tests do we have today | 13:31 |
*** stevemar_ has joined #openstack-keystone | 13:32 | |
*** ChanServ sets mode: +o stevemar_ | 13:32 | |
*** timcline has joined #openstack-keystone | 13:33 | |
*** timcline has quit IRC | 13:35 | |
*** Guest2821 is now known as dims__ | 13:35 | |
*** su_zhang has quit IRC | 13:36 | |
*** stevemar_ has quit IRC | 13:36 | |
*** csoukup has quit IRC | 13:38 | |
*** topol has joined #openstack-keystone | 13:42 | |
*** ChanServ sets mode: +v topol | 13:42 | |
*** wwwjfy has quit IRC | 13:47 | |
*** nate_gone is now known as njohnston | 13:50 | |
*** wwwjfy has joined #openstack-keystone | 13:50 | |
*** ngupta has joined #openstack-keystone | 13:52 | |
*** brad[] has joined #openstack-keystone | 13:53 | |
*** diazjf has joined #openstack-keystone | 13:58 | |
*** dims__ has quit IRC | 14:01 | |
*** ParsectiX has quit IRC | 14:02 | |
*** dims__ has joined #openstack-keystone | 14:02 | |
*** fhubik is now known as fhubik_brb | 14:04 | |
*** csoukup has joined #openstack-keystone | 14:06 | |
*** btully has joined #openstack-keystone | 14:07 | |
*** ngupta has quit IRC | 14:09 | |
*** fhubik_brb is now known as fhubik | 14:10 | |
marekd | dstanek: would be nice if you could take a look at a first pass on idp,mapping and protocols tests. Chain starts here: https://review.openstack.org/#/c/203258/ | 14:13 |
*** krotscheck has joined #openstack-keystone | 14:16 | |
*** tobe has quit IRC | 14:16 | |
*** tobe has joined #openstack-keystone | 14:19 | |
*** ngupta has joined #openstack-keystone | 14:19 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:20 | |
*** davechen has joined #openstack-keystone | 14:20 | |
*** davechen has left #openstack-keystone | 14:20 | |
*** topol has quit IRC | 14:23 | |
*** topol has joined #openstack-keystone | 14:24 | |
*** ChanServ sets mode: +v topol | 14:24 | |
*** exploreshaifali_ has joined #openstack-keystone | 14:24 | |
*** phalmos has joined #openstack-keystone | 14:28 | |
*** topol has quit IRC | 14:29 | |
*** timcline has joined #openstack-keystone | 14:31 | |
*** richm has joined #openstack-keystone | 14:32 | |
*** breton has quit IRC | 14:33 | |
*** breton has joined #openstack-keystone | 14:34 | |
*** breton has left #openstack-keystone | 14:34 | |
*** breton has joined #openstack-keystone | 14:34 | |
*** mestery has quit IRC | 14:34 | |
*** su_zhang has joined #openstack-keystone | 14:35 | |
*** tonytan4ever has joined #openstack-keystone | 14:36 | |
*** jsavak has joined #openstack-keystone | 14:38 | |
*** browne has joined #openstack-keystone | 14:44 | |
*** timcline has quit IRC | 14:44 | |
*** timcline has joined #openstack-keystone | 14:44 | |
*** dikonoor has quit IRC | 14:45 | |
*** ngupta has quit IRC | 14:47 | |
*** edmondsw has quit IRC | 14:49 | |
*** edmondsw has joined #openstack-keystone | 14:53 | |
*** fhubik is now known as fhubik_brb | 14:54 | |
*** fhubik_brb is now known as fhubik | 14:57 | |
*** slberger has joined #openstack-keystone | 14:59 | |
*** phalmos has quit IRC | 15:00 | |
*** phalmos has joined #openstack-keystone | 15:01 | |
*** HenryG_ is now known as HenryG | 15:03 | |
*** topol has joined #openstack-keystone | 15:08 | |
*** ChanServ sets mode: +v topol | 15:08 | |
*** fhubik is now known as fhubik_brb | 15:08 | |
*** ngupta has joined #openstack-keystone | 15:14 | |
*** hrou has quit IRC | 15:15 | |
*** hrou has joined #openstack-keystone | 15:15 | |
*** fhubik_brb is now known as fhubik | 15:20 | |
openstackgerrit | ayoung proposed openstack/keystone: Strip admin roles from non-admin projects and domains https://review.openstack.org/233480 | 15:20 |
*** zz_john5223 is now known as john5223 | 15:24 | |
*** urulama has quit IRC | 15:28 | |
openstackgerrit | ayoung proposed openstack/keystone: Strip admin roles from non-admin projects and domains https://review.openstack.org/233480 | 15:28 |
*** urulama has joined #openstack-keystone | 15:28 | |
*** exploreshaifali_ has quit IRC | 15:33 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Fix use of TokenNotFound https://review.openstack.org/227004 | 15:35 |
*** mylu has joined #openstack-keystone | 15:37 | |
*** roxanaghe has joined #openstack-keystone | 15:39 | |
*** tobe has quit IRC | 15:40 | |
bknudson | requirements change to bump oslo.cache: https://review.openstack.org/#/c/233689/ | 15:42 |
*** kiran-r has joined #openstack-keystone | 15:42 | |
*** BAKfr has quit IRC | 15:43 | |
*** BAKfr has joined #openstack-keystone | 15:46 | |
bknudson | anyone else having problems running tox -e py27? | 15:49 |
openstackgerrit | Boris Bobrov proposed openstack/keystone: Use search_ext_s instead of search_s in ldap https://review.openstack.org/232995 | 15:49 |
openstackgerrit | Boris Bobrov proposed openstack/keystone: Make @truncated common for all backends https://review.openstack.org/233069 | 15:49 |
openstackgerrit | Boris Bobrov proposed openstack/keystone: Use @truncated in ldap https://review.openstack.org/233070 | 15:49 |
bknudson | pkg_resources.ContextualVersionConflict: (requests 2.8.0 (/opt/stack/keystone/.tox/py27/lib/python2.7/site-packages), Requirement.parse('requests!=2.8.0,>=2.5.2'), set(['oslo.policy'])) | 15:53 |
*** BAKfr has quit IRC | 15:55 | |
*** su_zhang has quit IRC | 15:56 | |
*** BAKfr has joined #openstack-keystone | 15:58 | |
*** su_zhang has joined #openstack-keystone | 15:58 | |
*** fhubik is now known as fhubik_brb | 16:02 | |
*** fhubik_brb is now known as fhubik | 16:02 | |
*** fhubik has quit IRC | 16:02 | |
*** pumaranikar has joined #openstack-keystone | 16:03 | |
*** slberger1 has joined #openstack-keystone | 16:04 | |
*** slberger has quit IRC | 16:04 | |
*** mylu has quit IRC | 16:04 | |
*** blogan_ is now known as blogan | 16:14 | |
openstackgerrit | Merged openstack/keystone: Refactor: change 403 status codes in test names https://review.openstack.org/233127 | 16:19 |
*** su_zhang has quit IRC | 16:20 | |
*** gyee has joined #openstack-keystone | 16:22 | |
*** ChanServ sets mode: +v gyee | 16:22 | |
*** pumaranikar has quit IRC | 16:23 | |
*** aix has quit IRC | 16:31 | |
*** jistr has quit IRC | 16:42 | |
*** amit213 has quit IRC | 16:45 | |
*** amit213 has joined #openstack-keystone | 16:46 | |
openstackgerrit | Boris Bobrov proposed openstack/keystone: Use @truncated in ldap https://review.openstack.org/233070 | 16:47 |
breton | bknudson: in the gates | 16:49 |
breton | https://jenkins01.openstack.org/job/gate-keystone-python27/739/consoleFull | 16:50 |
*** ozialien has quit IRC | 16:56 | |
*** wwwjfy has quit IRC | 16:56 | |
*** kiran-r has quit IRC | 16:57 | |
*** geoffarnold has joined #openstack-keystone | 16:57 | |
*** doug-fish has quit IRC | 16:58 | |
*** geoffarn_ has joined #openstack-keystone | 16:58 | |
*** tonytan4ever has quit IRC | 16:59 | |
*** stevemar_ has joined #openstack-keystone | 17:02 | |
*** ChanServ sets mode: +o stevemar_ | 17:02 | |
*** geoffarnold has quit IRC | 17:02 | |
*** doug-fish has joined #openstack-keystone | 17:02 | |
*** browne has quit IRC | 17:02 | |
*** su_zhang has joined #openstack-keystone | 17:03 | |
*** doug-fish has quit IRC | 17:07 | |
openstackgerrit | Marek Denis proposed openstack/keystone: Functional tests for federation protocols CRUD https://review.openstack.org/233733 | 17:07 |
*** stevemar_ has quit IRC | 17:07 | |
*** doug-fish has joined #openstack-keystone | 17:09 | |
*** spandhe has joined #openstack-keystone | 17:10 | |
*** hrou has quit IRC | 17:13 | |
*** doug-fish has quit IRC | 17:13 | |
marekd | bknudson: ^^ this is one example of functional tests. Are you thinking we should reuse old code and simply make them talk to a remote real keystone? | 17:16 |
*** tonytan4ever has joined #openstack-keystone | 17:17 | |
marekd | dstanek: ^^ same | 17:19 |
*** njirap has quit IRC | 17:19 | |
*** geoffarn_ has quit IRC | 17:19 | |
*** geoffarnold has joined #openstack-keystone | 17:19 | |
*** doug-fish has joined #openstack-keystone | 17:21 | |
*** lhcheng has joined #openstack-keystone | 17:24 | |
*** ChanServ sets mode: +v lhcheng | 17:24 | |
*** doug-fish has quit IRC | 17:25 | |
ayoung | david8hu, pleaseremove -1 from https://review.openstack.org/#/c/233480 | 17:32 |
david8hu | ayoung, Only if you buy beer in Tokyo :) | 17:33 |
ayoung | Don't -1 just because you have a question: I'll be sure to answer all questions before merge, but a -1 just keeps people from looking at it | 17:33 |
ayoung | david8hu, I'll buy beer anyway | 17:33 |
ayoung | david8hu, I also have an additional copy of the t-shirt for the person that makes the biggest contribution to closing the bug | 17:34 |
david8hu | ayoung, sure, will remove it for the beer; ) | 17:34 |
*** jasonsb has joined #openstack-keystone | 17:34 | |
ayoung | remove because you want the bug fixed. THe beer is a given | 17:34 |
ayoung | david8hu, this is a real "acceptance of things I cannot change" patch | 17:35 |
ayoung | I've tried all the harder ways, and those paths are closed. I have some ideas of things we can do after this that do not require changes in the other projects. | 17:36 |
*** doug-fish has joined #openstack-keystone | 17:36 | |
david8hu | ayoung, Our best friend Jenkins also gave a -1. BTW, how does it solve the admin-ness problem since glance admin should not have the super admin role. | 17:37 |
ayoung | david8hu, you can always make the policy stricter for glance. This does not change that. It just keeps "I got admin on a project and now I am admin everywhere" from happening | 17:38 |
ayoung | splitting glance from nova from neutron...byond the scope, but still solvable problems | 17:38 |
ayoung | david8hu, But understand that wanting to split based on service is only one of many ways to split. Wanna hear my real plan for world domination? | 17:39 |
david8hu | ayoung, I am listening. | 17:39 |
ayoung | david8hu, OK...leave the policy in the remote service alone. Its job is going to be just the scope match | 17:40 |
ayoung | The role match is a separate layer. We do that first, and in middleware | 17:40 |
ayoung | So there are two checks: a dynamic policy check, and a static policy check | 17:40 |
*** geoffarn_ has joined #openstack-keystone | 17:41 | |
ayoung | Solving the glance vs nova will be done with dynamic policy | 17:41 |
*** geoffarnold has quit IRC | 17:41 | |
david8hu | dynamic check == role chk? | 17:41 |
david8hu | static check == scope chk? | 17:42 |
*** browne has joined #openstack-keystone | 17:42 | |
ayoung | david8hu, yep | 17:43 |
ayoung | david8hu, so we grandfather 'admin' in as an artifact | 17:43 |
ayoung | its a bypass: | 17:44 |
ayoung | but we'll limit it only to the special project/domain where it is used to unsick a sick system | 17:44 |
ayoung | gyee, ^^ read up my conversation with david8hu as it applies to you too | 17:44 |
ayoung | your question too, I should say | 17:45 |
david8hu | ayoung, cloud_admin rule is already doing that today with admin domain. Addiing admin project check to cloud_admin is a straight forward policy change. What am I missing here? | 17:47 |
*** pnavarro|off has joined #openstack-keystone | 17:47 | |
ayoung | david8hu, the fact that *no one* changes policy.json | 17:47 |
ayoung | It is considered code, and they are not allowed to by, ehem, policy | 17:47 |
ayoung | david8hu, add into that the fact that there is a serious amount of wrokflow here; | 17:48 |
ayoung | we don't by default define an admin domain | 17:48 |
ayoung | cloud_admin is not a default rule | 17:48 |
ayoung | er role | 17:48 |
ayoung | and making that work would require templatizing every single policy file for every service and distributing them via puppet, ansible, cfengine, or carrie pidgeon, whatever they use for config management | 17:49 |
ayoung | Its why I was pushing dynamic policy, but I can;'t get headway on it | 17:49 |
ayoung | so...we ignore the other projects and solve it in Keystone, or we leave the bug as "will not fix" | 17:49 |
*** diazjf has quit IRC | 17:49 | |
*** jasonsb has quit IRC | 17:50 | |
*** jasonsb_ has joined #openstack-keystone | 17:50 | |
lifeless | ayoung: eh, I thought we knew that folk *do* change it | 17:54 |
ayoung | lifeless, very very very few | 17:54 |
ayoung | lifeless, this: https://review.openstack.org/#/c/233480 | 17:54 |
lifeless | ayoung: I'm moderately sure (would need to ask to confirm) that HP cloud changes it | 17:54 |
ayoung | lifeless, it won't affect them if they opt out | 17:55 |
ayoung | lifeless, its a config option that has to be explicitly enabled, just reduces "who" gets the admin token | 17:55 |
lifeless | yeah | 17:55 |
lifeless | so it seems reasonable, if policy files aren't editable | 17:56 |
lifeless | though I think I'd like to see us have consensus on that | 17:56 |
lifeless | like - if editing them is a use case, we should go back to these orgs that aren't editing and tell them they should | 17:56 |
lifeless | but I'll freely admit I'm not across all the policy discussions - I've been lurking on those threads | 17:57 |
lifeless | (EBANDWIDTH) | 17:57 |
lifeless | so if we already have consensus that they aren't editable, and that the folk doing so are unsupported... | 17:57 |
lifeless | then great | 17:57 |
gyee | ayoung, yes | 17:58 |
gyee | lifeless, yes, we do customize policy to suite the product needs | 17:58 |
ayoung | gyee, so you guys probably have a wreckaround for 968696 anyway, right? | 17:59 |
david8hu | ayoung, taking care of in the stock default policy is more consistent with v3sample. Unless, of course, you are thinking of removing "domain_id:admin_domain_id" from v3sample polocy and have admin_domain_id populated through keystone.conf? | 17:59 |
ayoung | david8hu, huh? | 17:59 |
gyee | david8hu is wreckarounding it | 17:59 |
gyee | :) | 18:00 |
david8hu | lol | 18:00 |
*** doug-fish has quit IRC | 18:00 | |
*** pumaranikar has joined #openstack-keystone | 18:01 | |
*** doug-fish has joined #openstack-keystone | 18:01 | |
*** pnavarro|off has quit IRC | 18:01 | |
*** geoffarn_ has quit IRC | 18:01 | |
*** geoffarnold has joined #openstack-keystone | 18:02 | |
ayoung | My new hobby: pretending to be messed up by autocorrect | 18:03 |
ayoung | I actually mistyped it and liked the newer version better | 18:03 |
*** doug-fis_ has joined #openstack-keystone | 18:03 | |
david8hu | ayoung, In your proposal, there is going to be a admin_domain_id in keystone.conf? For those deploying policy.v3cloudsample.json, admin_domain_id is defined in the policy file. | 18:04 |
david8hu | ayoung, It is a bit of inconsistency | 18:04 |
ayoung | david8hu, you can get away without setting it in the config file, and then things work as before | 18:04 |
ayoung | Its why I made them vary indepednantly . | 18:04 |
*** geoffarnold is now known as geoffarnoldX | 18:05 | |
ayoung | There is a gap, though; if you don't set the domain token, I think that you can actually sent a domain scoped token to nova with admin in the scope and then it will match the policy check and pass | 18:05 |
*** doug-fish has quit IRC | 18:05 | |
*** henrynash has joined #openstack-keystone | 18:06 | |
*** ChanServ sets mode: +v henrynash | 18:06 | |
bknudson | opened a bug for the unit test failures https://bugs.launchpad.net/keystone/+bug/1505326 | 18:06 |
openstack | Launchpad bug 1505326 in Keystone "Unit tests failing with requests 2.8.0" [Undecided,New] | 18:06 |
ayoung | bknudson, thanks | 18:08 |
*** chrisshattuck has joined #openstack-keystone | 18:11 | |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Test revocation race conditions https://review.openstack.org/227995 | 18:11 |
bknudson | looks like it's keystoneclient is the culprit | 18:13 |
*** su_zhang has quit IRC | 18:16 | |
odyssey4me | bknudson yeah, we just hit that - everything was fine this morning, then this afternoon it all blew up :/ | 18:20 |
cloudnull | ^ ++ | 18:20 |
ayoung | david8hu, but, essentially, this closes the hole on a default install, which is what we really need. | 18:23 |
*** geoffarnoldX has quit IRC | 18:23 | |
*** geoffarnold has joined #openstack-keystone | 18:23 | |
bknudson | here's the release proposal: https://review.openstack.org/#/c/233761/ | 18:24 |
*** su_zhang has joined #openstack-keystone | 18:24 | |
*** diazjf has joined #openstack-keystone | 18:25 | |
bknudson | I guess it's a holiday in canada so no PTL | 18:26 |
bknudson | they have a lot of holidays | 18:27 |
*** su_zhang has quit IRC | 18:31 | |
dolphm | #success stevemar takes his first holiday as keystone PTL | 18:35 |
openstackstatus | dolphm: Added success to Success page | 18:35 |
*** jsavak has quit IRC | 18:37 | |
*** diazjf has left #openstack-keystone | 18:38 | |
david8hu | ayoung, I am not a big fan of going through keystone.conf and tell keystone which role is admin. It should be a policy thing. But, I do understand what you are trying to accomplish. That is why I think we should make the policy.v3cloudsample.json the default keystone policy. | 18:38 |
*** jsavak has joined #openstack-keystone | 18:38 | |
ayoung | david8hu, we can't | 18:38 |
ayoung | I wish we could...but the problem is not a Keystone problem | 18:39 |
ayoung | Keystone is unique; it could look in its config file to find out what is the admin project/domain | 18:39 |
ayoung | but we need to keep that value in sync across all of the remote services | 18:39 |
ayoung | and I could not even get the Keystone core team to agree on the absolute basics of dynamic policy, never mind the remote projects...it just won't happen | 18:40 |
ayoung | so, I through being a purist: lets fix the bug and move on with our lives | 18:40 |
*** doug-fis_ is now known as doug-fish | 18:41 | |
bknudson | keystonemiddleware release proposal: https://review.openstack.org/#/c/233763/ | 18:41 |
*** geoffarn_ has joined #openstack-keystone | 18:44 | |
*** geoffarnold has quit IRC | 18:45 | |
*** diazjf has joined #openstack-keystone | 18:49 | |
*** wwwjfy has joined #openstack-keystone | 18:53 | |
*** pumaranikar has quit IRC | 18:54 | |
bknudson | it's columbus day here so what am I doing | 18:54 |
bknudson | oops, indigenous peoples day. | 18:55 |
*** wwwjfy has quit IRC | 18:55 | |
*** pumaranikar has joined #openstack-keystone | 18:56 | |
*** tsymancz1k has quit IRC | 18:57 | |
*** tsymancz4k has quit IRC | 18:57 | |
*** tsymancz1k has joined #openstack-keystone | 18:57 | |
morgan | Hm. | 18:57 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Refactor: Don't hard code 409 Conflict error codes https://review.openstack.org/233128 | 19:00 |
*** geoffarn_ has quit IRC | 19:04 | |
morgan | ayoung: commented on your policy/admin patch | 19:06 |
*** geoffarnold has joined #openstack-keystone | 19:06 | |
*** amakarov is now known as amakarov_away | 19:06 | |
*** john5223 is now known as zz_john5223 | 19:06 | |
morgan | ayoung: i think you are on the right path at least fkr keystone purposes | 19:06 |
ayoung | morgan all I know is I am on the path of least resistance | 19:07 |
bknudson | it would be interesting to find out why there's so much resistance | 19:07 |
ayoung | But I don't think we have a choice. Updating policy is a non-starter | 19:07 |
ayoung | bknudson, I'll be willing to wax poetic over that in TOkyo over libations | 19:07 |
ayoung | its not entirely unjustified; there are really no good solutions the way the problem is currently defined | 19:08 |
morgan | I am just saying it is def. an easy win and solves a glaring hole even with full dynamic policy with little added code | 19:09 |
bknudson | I don't think what's proposed here is going to work. The service users need admin | 19:09 |
morgan | bknudson: not in v3 (with a proper policy). We could also make the service tenant have admin rights | 19:09 |
*** doug-fish has quit IRC | 19:09 | |
bknudson | right, the problem is improper policy... but we're saying we can't change policy | 19:10 |
*** doug-fish has joined #openstack-keystone | 19:10 | |
morgan | Well in v2 we dont really use policy | 19:10 |
bknudson | not sure where v2 came from? | 19:10 |
morgan | But anyway | 19:10 |
morgan | This is not an unreasonable approach nor far off the mark imo | 19:11 |
*** roxanaghe has quit IRC | 19:11 | |
*** spandhe_ has joined #openstack-keystone | 19:11 | |
morgan | Maybe we just need a way to specify service tenant too or something. This is a wuick fix that solves the immediate issue. | 19:11 |
morgan | And allows us to do less "big bang" to get the rest done down the line | 19:12 |
*** tsymancz4k has joined #openstack-keystone | 19:12 | |
*** spandhe has quit IRC | 19:12 | |
*** spandhe_ is now known as spandhe | 19:12 | |
*** zz_john5223 is now known as john5223 | 19:14 | |
*** john5223 is now known as zz_john5223 | 19:15 | |
*** zz_john5223 is now known as john5223 | 19:20 | |
*** arunkant has joined #openstack-keystone | 19:27 | |
ayoung | bknudson, service users can have admin in the admin project. What is the problem? | 19:32 |
bknudson | service users get a token scoped to the service project | 19:33 |
ayoung | is that the devstack setup? | 19:33 |
bknudson | y, that's how devstack sets it up | 19:33 |
ayoung | bknudson, I was trying to avoid making it a list, but we could do that. | 19:33 |
bknudson | nova and neutron get admin role | 19:33 |
ayoung | is that just to validate tokens? | 19:34 |
bknudson | nope, they use the service user to also do some kind of notification | 19:34 |
odyssey4me | bknudson so here's a funny - the requests issue for me is coming up in L, not M | 19:35 |
bknudson | odyssey4me: :( we've got a lot of work to do. | 19:36 |
bknudson | we'll probably have to release new versions of all the libs in L with new reqs updates | 19:36 |
bknudson | we can't even do releases now because the docs fail to build | 19:36 |
*** spandhe_ has joined #openstack-keystone | 19:37 | |
odyssey4me | bknudson :( even if I introduce a global pin for openstack-ansible, I get issues somewhere else | 19:38 |
ayoung | bknudson, could we make the services project the admin project? | 19:39 |
odyssey4me | it would seem that perhaps some libraries have released new versions today, so all hell is breaking loose while we try to finalise a liberty release :/ | 19:39 |
*** spandhe has quit IRC | 19:39 | |
*** spandhe_ is now known as spandhe | 19:39 | |
bknudson | ayoung: I don't see why not. | 19:39 |
bknudson | odyssey4me: I don't think the openstack releases are breaking anything? that shouldn't cause problems | 19:41 |
bknudson | otherwise we'll have to go back and cap all the openstack libs in stable/liberty, too | 19:42 |
*** hrou has joined #openstack-keystone | 19:42 | |
*** harlowja has quit IRC | 19:44 | |
*** spandhe has quit IRC | 19:47 | |
*** spandhe has joined #openstack-keystone | 19:48 | |
*** geoffarnold has quit IRC | 19:48 | |
*** geoffarnold has joined #openstack-keystone | 19:48 | |
lbragstad | dolphm responded - https://review.openstack.org/#/c/201742/ | 19:49 |
*** jsavak has quit IRC | 19:49 | |
dolphm | lbragstad: you can check that the fix was backported to all branches here https://review.openstack.org/#/q/Ia87fc785afe624fde0ad191cc6f031eb7605096e,n,z | 19:52 |
dolphm | lbragstad: i've never backported through branches sequentially unless there's a merge conflict or test failure as a result of the backport. then the rewritten patch should be backported further. there's no reason to do that here. | 19:52 |
lbragstad | dolphm works for me, thanks for the explanation | 19:53 |
*** diazjf has quit IRC | 19:55 | |
*** spandhe_ has joined #openstack-keystone | 19:55 | |
*** stevemar_ has joined #openstack-keystone | 19:56 | |
*** ChanServ sets mode: +o stevemar_ | 19:56 | |
*** spandhe has quit IRC | 19:57 | |
*** spandhe_ is now known as spandhe | 19:57 | |
*** diazjf has joined #openstack-keystone | 19:58 | |
*** stevemar_ has quit IRC | 19:59 | |
*** jtomasek has quit IRC | 20:04 | |
*** su_zhang has joined #openstack-keystone | 20:12 | |
*** njohnston is now known as nate_gone | 20:16 | |
*** exploreshaifali has joined #openstack-keystone | 20:18 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Remove oslo.policy implementation tests from keystone https://review.openstack.org/233800 | 20:20 |
*** jaosorior has quit IRC | 20:20 | |
*** geoffarn_ has joined #openstack-keystone | 20:22 | |
*** geoffarnold has quit IRC | 20:23 | |
*** pnavarro|off has joined #openstack-keystone | 20:24 | |
*** harlowja has joined #openstack-keystone | 20:24 | |
*** roxanaghe has joined #openstack-keystone | 20:26 | |
*** pnavarro|off has quit IRC | 20:30 | |
*** geoffarn_ is now known as geoffarnold | 20:33 | |
*** geoffarnold is now known as geoffarnoldX | 20:34 | |
*** pnavarro|off has joined #openstack-keystone | 20:43 | |
*** geoffarnold has joined #openstack-keystone | 20:43 | |
*** geoffarnoldX has quit IRC | 20:43 | |
*** e0ne has quit IRC | 20:48 | |
*** diazjf has quit IRC | 20:53 | |
*** wwwjfy has joined #openstack-keystone | 20:54 | |
*** diazjf has joined #openstack-keystone | 20:55 | |
*** wwwjfy has quit IRC | 20:59 | |
*** ngupta has quit IRC | 21:00 | |
*** edmondsw has quit IRC | 21:01 | |
*** stevemar_ has joined #openstack-keystone | 21:04 | |
*** ChanServ sets mode: +o stevemar_ | 21:04 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/233820 | 21:07 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystonemiddleware: Updated from global requirements https://review.openstack.org/233821 | 21:07 |
*** nate_gone is now known as njohnston | 21:07 | |
*** ngupta has joined #openstack-keystone | 21:11 | |
*** pnavarro|off has quit IRC | 21:15 | |
*** geoffarnold has quit IRC | 21:17 | |
*** geoffarn_ has joined #openstack-keystone | 21:17 | |
*** zhiyan has quit IRC | 21:20 | |
*** jraim has quit IRC | 21:21 | |
*** serverascode has quit IRC | 21:21 | |
*** briancurtin has quit IRC | 21:22 | |
*** ctracey has quit IRC | 21:22 | |
stevemar_ | dolphm: thanks for rewriting the bug description for the version package | 21:24 |
*** nzeer has quit IRC | 21:25 | |
stevemar_ | ayoung: you should like this change https://review.openstack.org/#/c/203262/10 | 21:28 |
stevemar_ | theres a lot less cruft in the top level keystone directory now | 21:28 |
stevemar_ | \o/ | 21:28 |
ayoung | stevemar_, works for me | 21:28 |
stevemar_ | bknudson: oh damn, oslo.policy broke up a bit eh | 21:29 |
openstackgerrit | Tom Cocozzello proposed openstack/keystonemiddleware: Configure filter factories for PasteDeploy https://review.openstack.org/233839 | 21:29 |
lbragstad | stevemar_ bknudson yeah i think https://github.com/openstack/keystone/commit/6f5fce4937584297d810453f9290d69cf58aa644 did something? | 21:29 |
bknudson | stevemar_: y, it broke neutron too, I guess. | 21:29 |
bknudson | the release of requests also broke keystone unit tests. | 21:30 |
stevemar_ | bknudson: and sphinx release broke releases | 21:30 |
stevemar_ | everything is broken! | 21:30 |
bknudson | I think it's because the broken requests gets pulled in by keystoneclient and keystonemiddleware | 21:30 |
lbragstad | yep; http://logs.openstack.org/28/233128/2/check/gate-keystone-python27/2a4f717/testr_results.html.gz | 21:30 |
bknudson | because the released versions of keystoneclient and ksm don't have requests!=2.8.0 | 21:31 |
bknudson | so I proposed new releases of ksc and ksm. | 21:31 |
lbragstad | bknudson do you have links? | 21:31 |
bknudson | lbragstad: https://review.openstack.org/#/c/233761/ and https://review.openstack.org/#/c/233763/ | 21:32 |
odyssey4me | bknudson it also concerns me that the blocking of requests 2.8.0 has been held back from stable/liberty: https://review.openstack.org/232917 | 21:34 |
bknudson | odyssey4me: I'm going to give stable/liberty tox -e py27 a try. | 21:36 |
bknudson | yep, it fails | 21:36 |
odyssey4me | bknudson :/ | 21:36 |
bknudson | same as master | 21:36 |
odyssey4me | so stable/liberty is more like drunk/liberty right now :p | 21:36 |
stevemar_ | odyssey4me: hehe | 21:37 |
bknudson | it's really stable since we can't merge anything | 21:37 |
*** geoffarn_ has quit IRC | 21:38 | |
*** geoffarnold has joined #openstack-keystone | 21:39 | |
*** pumaranikar has quit IRC | 21:41 | |
lbragstad | so, what's the process for back-porting dependency fixes? | 21:41 |
*** phalmos has quit IRC | 21:41 | |
*** tonytan4ever has quit IRC | 21:42 | |
jamielennox | bknudson: i had heard of a problem with requests 2.8.0 but i haven't done anything about it, most of the other projects reacted and fixed it | 21:42 |
bknudson | lbragstad: there's stable/ branches in openstack/requirements and the proposal bot will update. | 21:42 |
*** doug-fish has quit IRC | 21:42 | |
jamielennox | did they release a new requests with a fix? | 21:43 |
bknudson | jamielennox: how'd they fix it? | 21:43 |
jamielennox | some did some mocking to there unit tests, but i thought they were blacklisting the release and fixing upstream | 21:43 |
*** doug-fish has joined #openstack-keystone | 21:43 | |
bknudson | jamielennox: it's blacklisted but keystone pulls in the latest release due to keystoneclient and ksm. | 21:44 |
bknudson | the latest release is 2.8.0 and broken | 21:44 |
lbragstad | bknudson ah, makes sense | 21:44 |
*** doug-fis_ has joined #openstack-keystone | 21:46 | |
*** diazjf has left #openstack-keystone | 21:46 | |
*** doug-fi__ has joined #openstack-keystone | 21:47 | |
*** tsymancz4k has quit IRC | 21:47 | |
*** tsymancz1k has quit IRC | 21:47 | |
*** doug-fish has quit IRC | 21:48 | |
bknudson | all the tests pass on stable/kilo | 21:48 |
bknudson | we capped dependencies in stable/kilo | 21:48 |
*** doug-fish has joined #openstack-keystone | 21:50 | |
*** doug-fis_ has quit IRC | 21:50 | |
*** doug-fi__ has quit IRC | 21:51 | |
*** csoukup has quit IRC | 21:53 | |
*** doug-fish has quit IRC | 21:54 | |
*** topol has quit IRC | 21:57 | |
*** nzeer has joined #openstack-keystone | 21:59 | |
*** geoffarnold has quit IRC | 21:59 | |
*** geoffarnold has joined #openstack-keystone | 22:00 | |
*** tsymancz1k has joined #openstack-keystone | 22:02 | |
*** doug-fish has joined #openstack-keystone | 22:02 | |
*** urulama has quit IRC | 22:02 | |
*** tsymancz2k has joined #openstack-keystone | 22:02 | |
*** urulama has joined #openstack-keystone | 22:03 | |
*** jraim has joined #openstack-keystone | 22:03 | |
jamielennox | stevemar_, bknudson: can you have a look at https://review.openstack.org/#/c/225516/ - there's not many people with stable privs | 22:04 |
bknudson | jamielennox: not much point since it's already +W | 22:04 |
bknudson | you want me to stop it? | 22:04 |
jamielennox | bknudson: wow, no | 22:05 |
jamielennox | bknudson: must have cached an older version...? no idea, but it only had 2 +1s when i looked - thanks anyway | 22:05 |
bknudson | I thought stable/kilo was frozen (according to the -dev ml) | 22:07 |
*** doug-fish has quit IRC | 22:07 | |
jamielennox | why? | 22:07 |
bknudson | jamielennox: http://lists.openstack.org/pipermail/openstack-dev/2015-October/076159.html | 22:07 |
bknudson | freeze before release | 22:07 |
*** sigmavirus24 is now known as sigmavirus24_awa | 22:09 | |
*** dims_ has joined #openstack-keystone | 22:09 | |
jamielennox | there doesn't seem to be a resolution there | 22:09 |
bknudson | jamielennox: I guess that was the wrong link, here's the latest http://lists.openstack.org/pipermail/openstack-dev/2015-October/076408.html | 22:09 |
bknudson | says stable/kilo is frozen | 22:09 |
bknudson | release tomorrow | 22:09 |
jamielennox | bah, i was really ohping this would be in it | 22:10 |
*** su_zhang has quit IRC | 22:11 | |
*** dims__ has quit IRC | 22:11 | |
*** timcline has quit IRC | 22:12 | |
*** ctracey has joined #openstack-keystone | 22:13 | |
*** ngupta has quit IRC | 22:14 | |
jamielennox | lbragstad: replied to https://review.openstack.org/#/c/229751/ | 22:19 |
ayoung | jamielennox, bummer. Federation is pretty broke without that | 22:19 |
ayoung | jamielennox, we can still apply it to RDO, though. | 22:20 |
*** serverascode has joined #openstack-keystone | 22:21 | |
lbragstad | jamielennox perfect, thanks for the follow up | 22:21 |
*** geoffarn_ has joined #openstack-keystone | 22:21 | |
*** geoffarnold has quit IRC | 22:21 | |
*** stevemar_ has quit IRC | 22:23 | |
*** geoffarn_ is now known as geoffarnoldX | 22:24 | |
*** slberger1 has left #openstack-keystone | 22:24 | |
*** zhiyan has joined #openstack-keystone | 22:25 | |
*** stevemar_ has joined #openstack-keystone | 22:27 | |
*** ChanServ sets mode: +o stevemar_ | 22:27 | |
*** gildub has joined #openstack-keystone | 22:41 | |
*** su_zhang has joined #openstack-keystone | 22:41 | |
*** briancurtin has joined #openstack-keystone | 22:41 | |
*** geoffarnoldX has quit IRC | 22:42 | |
*** geoffarnold has joined #openstack-keystone | 22:42 | |
*** _hrou_ has joined #openstack-keystone | 22:43 | |
*** stevemar_ has quit IRC | 22:47 | |
*** stevemar_ has joined #openstack-keystone | 22:47 | |
*** ChanServ sets mode: +o stevemar_ | 22:47 | |
*** hrou has quit IRC | 22:47 | |
*** su_zhang has quit IRC | 22:48 | |
*** su_zhang has joined #openstack-keystone | 22:51 | |
*** tsymancz1k has quit IRC | 23:00 | |
*** tsymancz2k has quit IRC | 23:01 | |
*** david-ly_ has joined #openstack-keystone | 23:01 | |
*** david-lyle has quit IRC | 23:02 | |
*** geoffarnold has quit IRC | 23:03 | |
*** geoffarnold has joined #openstack-keystone | 23:04 | |
*** david-lyle has joined #openstack-keystone | 23:04 | |
*** david-ly_ has quit IRC | 23:04 | |
*** tsymancz2k has joined #openstack-keystone | 23:10 | |
*** geoffarnold has quit IRC | 23:24 | |
*** geoffarnold has joined #openstack-keystone | 23:25 | |
*** tsymancz4k has joined #openstack-keystone | 23:25 | |
*** stevemar_ has quit IRC | 23:33 | |
openstackgerrit | Merged openstack/keystonemiddleware: Remove auth headers in AuthProtocol https://review.openstack.org/229751 | 23:45 |
*** geoffarnold has quit IRC | 23:46 | |
*** geoffarnold has joined #openstack-keystone | 23:46 | |
openstackgerrit | Jamie Lennox proposed openstack/python-keystoneclient-kerberos: Use optional authentication https://review.openstack.org/233864 | 23:49 |
*** stevemar_ has joined #openstack-keystone | 23:56 | |
*** ChanServ sets mode: +o stevemar_ | 23:56 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Create a version package https://review.openstack.org/203262 | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!