*** gildub has quit IRC | 00:00 | |
*** RichardRaseley has quit IRC | 00:00 | |
*** doug-fish has joined #openstack-keystone | 00:02 | |
*** doug-fish has quit IRC | 00:06 | |
*** jamielennox is now known as jamielennox|away | 00:08 | |
*** su_zhang has joined #openstack-keystone | 00:11 | |
*** tonytan4ever has quit IRC | 00:14 | |
*** su_zhang has quit IRC | 00:16 | |
*** roxanaghe has joined #openstack-keystone | 00:16 | |
*** doug-fish has joined #openstack-keystone | 00:17 | |
*** nbalaji has quit IRC | 00:18 | |
*** doug-fish has quit IRC | 00:21 | |
*** jamielennox|away is now known as jamielennox | 00:21 | |
*** EinstCrazy has quit IRC | 00:24 | |
shaleh | stevemar_: yay on py26 death | 00:26 |
---|---|---|
*** gildub has joined #openstack-keystone | 00:36 | |
jamielennox | bknudson: there are a lot of places throughout tests that reguire updating the middleware location. is it a strict -1 for you? | 00:43 |
jamielennox | i can do it it's just going to make the patch more far reaching and i don't see it gains anything | 00:43 |
*** mylu has quit IRC | 00:43 | |
*** mylu has joined #openstack-keystone | 00:44 | |
*** mylu has quit IRC | 00:45 | |
*** mylu has joined #openstack-keystone | 00:46 | |
openstackgerrit | Sean Perry proposed openstack/keystone: Use unit.new_group_ref consistently https://review.openstack.org/243276 | 00:46 |
*** mylu has quit IRC | 00:52 | |
*** mylu has joined #openstack-keystone | 00:52 | |
*** doug-fish has joined #openstack-keystone | 00:56 | |
*** itlinux has joined #openstack-keystone | 00:59 | |
*** doug-fish has quit IRC | 01:00 | |
*** EinstCrazy has joined #openstack-keystone | 01:03 | |
*** mylu has quit IRC | 01:06 | |
*** mylu has joined #openstack-keystone | 01:07 | |
*** btully has quit IRC | 01:10 | |
*** mylu has quit IRC | 01:11 | |
*** fangzhou has joined #openstack-keystone | 01:15 | |
*** shaleh has quit IRC | 01:19 | |
*** doug-fish has joined #openstack-keystone | 01:22 | |
*** doug-fish has quit IRC | 01:27 | |
*** jbell8 has quit IRC | 01:35 | |
*** itlinux has quit IRC | 01:46 | |
*** su_zhang has joined #openstack-keystone | 01:48 | |
*** su_zhang has quit IRC | 01:56 | |
*** btully has joined #openstack-keystone | 01:57 | |
*** mylu has joined #openstack-keystone | 01:58 | |
*** mylu has quit IRC | 02:00 | |
*** mylu has joined #openstack-keystone | 02:00 | |
*** doug-fish has joined #openstack-keystone | 02:02 | |
*** mylu has quit IRC | 02:05 | |
*** doug-fish has quit IRC | 02:06 | |
*** mylu has joined #openstack-keystone | 02:11 | |
*** mylu has quit IRC | 02:13 | |
*** mylu has joined #openstack-keystone | 02:14 | |
*** gyee has quit IRC | 02:14 | |
*** thedodd has quit IRC | 02:16 | |
*** thedodd has joined #openstack-keystone | 02:17 | |
*** mylu has quit IRC | 02:19 | |
*** thedodd has quit IRC | 02:21 | |
*** doug-fish has joined #openstack-keystone | 02:28 | |
*** spandhe has quit IRC | 02:29 | |
*** EinstCrazy has quit IRC | 02:29 | |
*** ninag has joined #openstack-keystone | 02:29 | |
*** doug-fish has quit IRC | 02:33 | |
*** ninag has quit IRC | 02:34 | |
*** lnxnut has joined #openstack-keystone | 02:37 | |
openstackgerrit | Merged openstack/keystone: Pass kwargs when using revoke_api.list_events() https://review.openstack.org/243743 | 02:53 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/238264 | 02:55 |
*** dims has quit IRC | 02:57 | |
*** dims has joined #openstack-keystone | 03:07 | |
*** doug-fish has joined #openstack-keystone | 03:07 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: Remove CA key from configuration as it is not required https://review.openstack.org/244414 | 03:09 |
*** mylu has joined #openstack-keystone | 03:11 | |
*** doug-fish has quit IRC | 03:11 | |
*** su_zhang has joined #openstack-keystone | 03:13 | |
*** dims has quit IRC | 03:14 | |
*** dims has joined #openstack-keystone | 03:16 | |
*** spandhe has joined #openstack-keystone | 03:18 | |
*** dims has quit IRC | 03:25 | |
*** diazjf has joined #openstack-keystone | 03:31 | |
*** diazjf has quit IRC | 03:34 | |
*** doug-fish has joined #openstack-keystone | 03:34 | |
*** diazjf has joined #openstack-keystone | 03:36 | |
*** spandhe has quit IRC | 03:37 | |
*** doug-fish has quit IRC | 03:38 | |
*** mylu has quit IRC | 03:43 | |
*** mylu has joined #openstack-keystone | 03:43 | |
*** doug-fish has joined #openstack-keystone | 03:45 | |
*** roxanaghe has quit IRC | 03:47 | |
*** roxanaghe has joined #openstack-keystone | 03:47 | |
*** doug-fish has quit IRC | 03:49 | |
*** stevemar_ has quit IRC | 03:49 | |
*** stevemar_ has joined #openstack-keystone | 03:50 | |
*** ChanServ sets mode: +o stevemar_ | 03:50 | |
*** roxanaghe has quit IRC | 03:52 | |
*** su_zhang has quit IRC | 03:52 | |
*** stevemar_ has quit IRC | 03:53 | |
openstackgerrit | Dave Chen proposed openstack/keystone: Change `region` to `region_id` for endpoint reference https://review.openstack.org/167534 | 03:53 |
*** richm has quit IRC | 03:54 | |
*** lhcheng has quit IRC | 04:13 | |
*** btully has quit IRC | 04:15 | |
*** spandhe has joined #openstack-keystone | 04:15 | |
openstackgerrit | Dave Chen proposed openstack/keystonemiddleware: update middlewarearchitecture.rst https://review.openstack.org/219162 | 04:20 |
openstackgerrit | Dave Chen proposed openstack/keystonemiddleware: Configuration is outdated https://review.openstack.org/220545 | 04:21 |
*** spandhe has quit IRC | 04:23 | |
*** lhcheng has joined #openstack-keystone | 04:28 | |
*** ChanServ sets mode: +v lhcheng | 04:28 | |
*** mylu has quit IRC | 04:47 | |
*** mylu has joined #openstack-keystone | 04:48 | |
notmorgan | py26 death is win | 04:48 |
* notmorgan looks at the lack of stevemar and needs to corner steve about a bouncer. | 04:49 | |
*** lhcheng has quit IRC | 04:49 | |
*** mylu has quit IRC | 04:52 | |
*** mylu has joined #openstack-keystone | 04:53 | |
*** lhcheng has joined #openstack-keystone | 05:01 | |
*** ChanServ sets mode: +v lhcheng | 05:01 | |
*** links has joined #openstack-keystone | 05:07 | |
openstackgerrit | Jamie Lennox proposed openstack/keystone: Move AuthContext middleware into its own file https://review.openstack.org/243882 | 05:13 |
openstackgerrit | Jamie Lennox proposed openstack/keystone: Perform middleware tests with webtest https://review.openstack.org/244440 | 05:13 |
*** fawadkhaliq has joined #openstack-keystone | 05:14 | |
*** diazjf has quit IRC | 05:26 | |
openstackgerrit | Deepti Ramakrishna proposed openstack/keystone: Reject user creation using admin token without domain https://review.openstack.org/196942 | 05:42 |
*** jaosorior has joined #openstack-keystone | 05:42 | |
*** mflobo has joined #openstack-keystone | 05:44 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/243923 | 05:53 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystoneauth: Updated from global requirements https://review.openstack.org/243924 | 05:53 |
*** btully has joined #openstack-keystone | 05:54 | |
*** jaosorior has quit IRC | 06:07 | |
*** doug-fish has joined #openstack-keystone | 06:10 | |
*** lhcheng has quit IRC | 06:13 | |
*** jerrygb has quit IRC | 06:14 | |
*** doug-fish has quit IRC | 06:15 | |
*** jaosorior has joined #openstack-keystone | 06:15 | |
*** mylu has quit IRC | 06:21 | |
*** browne has quit IRC | 06:23 | |
*** jbell8 has joined #openstack-keystone | 06:34 | |
*** gb21 has joined #openstack-keystone | 06:39 | |
*** links has quit IRC | 06:45 | |
*** jasonsb has quit IRC | 06:49 | |
*** jasonsb has joined #openstack-keystone | 06:51 | |
*** jasonsb has quit IRC | 06:55 | |
*** gildub has quit IRC | 06:56 | |
*** woodster_ has quit IRC | 06:59 | |
*** josecastroleon has joined #openstack-keystone | 07:03 | |
*** links has joined #openstack-keystone | 07:05 | |
*** mflobo has left #openstack-keystone | 07:10 | |
openstackgerrit | Jamie Lennox proposed openstack/keystone: Use our own request in base wsgi class https://review.openstack.org/244472 | 07:11 |
*** sirushti has quit IRC | 07:14 | |
*** fangzhou has quit IRC | 07:14 | |
*** tsymancz1k has quit IRC | 07:16 | |
*** hideme_ has quit IRC | 07:16 | |
*** hideme_ has joined #openstack-keystone | 07:17 | |
*** sirushti has joined #openstack-keystone | 07:17 | |
*** jasonsb has joined #openstack-keystone | 07:20 | |
*** stevemar_ has joined #openstack-keystone | 07:21 | |
*** ChanServ sets mode: +o stevemar_ | 07:21 | |
*** stevemar_ has quit IRC | 07:24 | |
*** jasonsb has quit IRC | 07:25 | |
*** tsymanczyk has joined #openstack-keystone | 07:31 | |
*** tsymanczyk is now known as Guest12051 | 07:32 | |
*** gildub has joined #openstack-keystone | 07:42 | |
*** henrynash has quit IRC | 07:51 | |
*** aix has joined #openstack-keystone | 07:55 | |
*** josecastroleon has quit IRC | 07:59 | |
*** josecastroleon has joined #openstack-keystone | 08:08 | |
*** lhcheng has joined #openstack-keystone | 08:09 | |
*** ChanServ sets mode: +v lhcheng | 08:09 | |
*** fhubik has joined #openstack-keystone | 08:15 | |
*** fhubik is now known as fhubik_brb | 08:15 | |
*** akanksha_ has joined #openstack-keystone | 08:22 | |
*** gb21 has quit IRC | 08:22 | |
*** miyagishi_t has joined #openstack-keystone | 08:24 | |
*** ninag has joined #openstack-keystone | 08:32 | |
openstackgerrit | Pranesh Pandurangan proposed openstack/keystone: eventlet: handle system that misses TCP_KEEPIDLE https://review.openstack.org/226773 | 08:34 |
*** gb21 has joined #openstack-keystone | 08:34 | |
*** btully has quit IRC | 08:36 | |
*** ninag has quit IRC | 08:36 | |
openstackgerrit | Sean Perry proposed openstack/keystone: Use unit.new_role_ref consistently https://review.openstack.org/242704 | 08:39 |
openstackgerrit | Sean Perry proposed openstack/keystone: Use unit.new_group_ref consistently https://review.openstack.org/243276 | 08:39 |
*** fhubik_brb is now known as fhubik | 08:39 | |
*** Pablo|off| has joined #openstack-keystone | 08:40 | |
openstackgerrit | Sean Perry proposed openstack/keystone: WIP Use unit.new_user_ref consistently https://review.openstack.org/243877 | 08:40 |
*** henrynash has joined #openstack-keystone | 08:41 | |
*** ChanServ sets mode: +v henrynash | 08:41 | |
openstackgerrit | Julien Danjou proposed openstack/keystone: eventlet: handle system that misses TCP_KEEPIDLE https://review.openstack.org/226773 | 08:44 |
*** Pablo|off| is now known as pcaruana | 08:48 | |
openstackgerrit | Merged openstack/keystone-specs: Correct a few token examples https://review.openstack.org/244266 | 08:49 |
*** rcernin has joined #openstack-keystone | 08:50 | |
openstackgerrit | Sean Perry proposed openstack/keystone: Use new_service_ref instead of manually created dict https://review.openstack.org/244499 | 08:51 |
openstackgerrit | Sean Perry proposed openstack/keystone: Use new_service_ref instead of manually created dict https://review.openstack.org/244499 | 08:52 |
*** lhcheng has quit IRC | 08:53 | |
*** jbell8 has quit IRC | 08:56 | |
*** fhubik is now known as fhubik_brb | 09:00 | |
*** jistr has joined #openstack-keystone | 09:03 | |
*** zqfan has joined #openstack-keystone | 09:04 | |
*** aix has quit IRC | 09:19 | |
*** bdossant has joined #openstack-keystone | 09:19 | |
*** fhubik_brb is now known as fhubik | 09:19 | |
*** aix has joined #openstack-keystone | 09:21 | |
*** henrynash has quit IRC | 09:29 | |
tyagiprince2010 | Hey I want to understand all the keystone components.. Can anyone help me build the basics so that I could easily grab the keystone documentation. | 09:45 |
tyagiprince2010 | I find some things in keystone doc going over my head. :P | 09:45 |
*** openstackgerrit has quit IRC | 09:46 | |
*** openstackgerrit has joined #openstack-keystone | 09:47 | |
tyagiprince2010 | I just need to know what all keystone uses.. I will read all those components separately and then get back to keystone doc | 09:49 |
marekd | tyagiprince2010: you cna start understanding how the workflow works.... | 10:01 |
marekd | tyagiprince2010: take some examples and try to explore them - gow instance how authentication works | 10:01 |
marekd | or adding the user. | 10:01 |
marekd | tyagiprince2010: for auth take a look at /auth/ directory | 10:01 |
marekd | /auth/controllers | 10:02 |
marekd | /auth/controllers.py | 10:02 |
marekd | or, better, /auth/routers.py -> then you will see which function is called when when user calls routes | 10:02 |
marekd | this should help you match code with actions like authenticating, doing this or that. | 10:03 |
marekd | if not auth, then try understanding how CRUD operations for some objects work. | 10:04 |
marekd | typically routers.py and controllers.py files are the good way to start | 10:04 |
openstackgerrit | Sean Perry proposed openstack/keystone: Use unit.new_project_ref consistently https://review.openstack.org/244523 | 10:05 |
openstackgerrit | Sean Perry proposed openstack/keystone: Use unit.new_project_ref consistently https://review.openstack.org/244523 | 10:06 |
tyagiprince2010 | marekd: thanks.. I will start looking at the code.. | 10:06 |
tyagiprince2010 | marekd: I am using pki tokens.. and theres some problem with the cache in keystone.. so i want to understand keystone caching better | 10:07 |
marekd | tyagiprince2010: dont use pki | 10:12 |
marekd | why pki btw? | 10:12 |
openstackgerrit | Sean Perry proposed openstack/keystone: WIP Use unit.new_user_ref consistently https://review.openstack.org/243877 | 10:12 |
marekd | tyagiprince2010: it's on your devstack or somewhere in production? | 10:12 |
openstackgerrit | Sean Perry proposed openstack/keystone: WIP Use unit.new_user_ref consistently https://review.openstack.org/243877 | 10:12 |
openstackgerrit | Sean Perry proposed openstack/keystone: Use unit.new_service_ref() consistently https://review.openstack.org/238283 | 10:13 |
tyagiprince2010 | it is in a development phase only in a 3 node setup.. The thing is I was using uuid previously but there it goes to keystone to validate everytime.. | 10:13 |
marekd | tyagiprince2010: yes, it does, but what's the problem with your small 3 node setup? | 10:14 |
tyagiprince2010 | and i dont want each service to consult keystone every time a request is made.. so i changed to pki | 10:14 |
tyagiprince2010 | It is going to be big :P | 10:14 |
openstackgerrit | Sean Perry proposed openstack/keystone: Use unit.new_region_ref() consistently https://review.openstack.org/238302 | 10:14 |
tyagiprince2010 | this is just a poc i am working on right now | 10:14 |
openstackgerrit | Sean Perry proposed openstack/keystone: Use unit.new_domain_ref consistently https://review.openstack.org/242615 | 10:14 |
marekd | tyagiprince2010: i still think you will be good with uuid unless you grow really big. | 10:15 |
openstackgerrit | Sean Perry proposed openstack/keystone: Use unit.new_role_ref consistently https://review.openstack.org/242704 | 10:15 |
openstackgerrit | Sean Perry proposed openstack/keystone: Use unit.new_group_ref consistently https://review.openstack.org/243276 | 10:15 |
openstackgerrit | Sean Perry proposed openstack/keystone: WIP Use unit.new_user_ref consistently https://review.openstack.org/243877 | 10:15 |
marekd | tyagiprince2010: on the other hand - fernet token also consults keystone every time and fernet is going to be next default format. | 10:15 |
openstackgerrit | Sean Perry proposed openstack/keystone: Use unit.new_project_ref consistently https://review.openstack.org/244523 | 10:15 |
tyagiprince2010 | whats the problem with pki? | 10:15 |
marekd | tyagiprince2010: it's huuuuge | 10:15 |
openstackgerrit | Sean Perry proposed openstack/keystone: Use new_service_ref instead of manually created dict https://review.openstack.org/244499 | 10:15 |
tyagiprince2010 | but there are ways to compress it | 10:16 |
tyagiprince2010 | pkiz is there | 10:16 |
marekd | tyagiprince2010: everything bigger than 255 bytes will cause some problems at some point. | 10:16 |
*** openstackgerrit has quit IRC | 10:16 | |
marekd | tyagiprince2010: of course you are free to use pki(z) if you want, but keystone is going to deprecate it at some point and Fernet tokens are to way to go. | 10:16 |
*** openstackgerrit has joined #openstack-keystone | 10:17 | |
tyagiprince2010 | marekd: what makes pki that big? | 10:18 |
marekd | service catalog | 10:18 |
tyagiprince2010 | marekd: also could you provide me some doc which tells about the token? also that fernet is going to be the next default and pki is going to deprecate | 10:19 |
marekd | https://www.openstack.org/summit/tokyo-2015/videos/presentation/deep-dive-into-keystone-tokens-and-lessons-learned | 10:20 |
marekd | tyagiprince2010: enough material for starters :-) | 10:21 |
marekd | enjoy! | 10:21 |
tyagiprince2010 | marekd: Thank you.. appreciate your help :) | 10:22 |
marekd | tyagiprince2010: no problemo. | 10:22 |
*** jaosorior has quit IRC | 10:27 | |
*** jaosorior has joined #openstack-keystone | 10:27 | |
openstackgerrit | Grzegorz Grasza (xek) proposed openstack/keystone: Unit test for checking that migrations don't cause downtime https://review.openstack.org/241603 | 10:34 |
openstackgerrit | Grzegorz Grasza (xek) proposed openstack/keystone: Unit test for checking that migrations don't cause downtime https://review.openstack.org/241603 | 10:35 |
*** akanksha_ has quit IRC | 10:38 | |
*** jistr_ has joined #openstack-keystone | 10:48 | |
*** aix_ has joined #openstack-keystone | 10:48 | |
*** jistr has quit IRC | 10:49 | |
*** rcernin has quit IRC | 10:49 | |
*** rcernin has joined #openstack-keystone | 10:50 | |
*** aix has quit IRC | 10:51 | |
*** aix_ has quit IRC | 10:53 | |
*** jistr_ has quit IRC | 10:54 | |
*** aix_ has joined #openstack-keystone | 11:05 | |
*** jistr_ has joined #openstack-keystone | 11:05 | |
*** e0ne has joined #openstack-keystone | 11:09 | |
*** fhubik is now known as fhubik_brb | 11:11 | |
*** jamielennox is now known as jamielennox|away | 11:12 | |
*** fhubik_brb is now known as fhubik | 11:13 | |
*** dims_ has joined #openstack-keystone | 11:14 | |
*** urulama has quit IRC | 11:14 | |
*** jerrygb has joined #openstack-keystone | 11:15 | |
*** urulama has joined #openstack-keystone | 11:15 | |
*** gildub has quit IRC | 11:17 | |
*** jerrygb has quit IRC | 11:19 | |
*** jasonsb has joined #openstack-keystone | 11:23 | |
*** jasonsb has quit IRC | 11:28 | |
*** toddnni has quit IRC | 11:28 | |
*** josecastroleon has quit IRC | 11:30 | |
samueldmq | morning keystoners | 11:35 |
*** fawadkhaliq has quit IRC | 11:35 | |
*** lnxnut has quit IRC | 11:39 | |
*** jaosorior has quit IRC | 11:56 | |
*** jaosorior has joined #openstack-keystone | 11:56 | |
*** jaosorior has quit IRC | 12:06 | |
*** peter-hamilton has joined #openstack-keystone | 12:07 | |
*** marzif has joined #openstack-keystone | 12:08 | |
*** jaosorior has joined #openstack-keystone | 12:16 | |
*** peter-hamilton has quit IRC | 12:18 | |
*** ninag has joined #openstack-keystone | 12:19 | |
*** josecastroleon has joined #openstack-keystone | 12:19 | |
*** jistr_ is now known as jistr | 12:20 | |
*** miyagishi_t has quit IRC | 12:21 | |
*** ninag has quit IRC | 12:23 | |
*** gordc has joined #openstack-keystone | 12:34 | |
*** woodster_ has joined #openstack-keystone | 12:43 | |
*** pauloewerton has joined #openstack-keystone | 12:44 | |
*** tyagiprince2010 has quit IRC | 12:55 | |
*** arif-ali has quit IRC | 13:01 | |
*** fhubik is now known as fhubik_brb | 13:02 | |
openstackgerrit | Paulo Ewerton Gomes Fragoso proposed openstack/python-keystoneclient: Handle EmptyCatalog exception in list federated projects https://review.openstack.org/243153 | 13:04 |
*** peter-hamilton has joined #openstack-keystone | 13:11 | |
*** jerrygb has joined #openstack-keystone | 13:15 | |
*** jerrygb_ has joined #openstack-keystone | 13:18 | |
*** jerrygb has quit IRC | 13:22 | |
*** arif-ali has joined #openstack-keystone | 13:24 | |
*** dims_ has quit IRC | 13:24 | |
*** jasonsb has joined #openstack-keystone | 13:25 | |
*** doug-fish has joined #openstack-keystone | 13:26 | |
*** dims has joined #openstack-keystone | 13:26 | |
*** henrynash has joined #openstack-keystone | 13:26 | |
*** ChanServ sets mode: +v henrynash | 13:26 | |
*** fhubik_brb is now known as fhubik | 13:27 | |
*** jasonsb has quit IRC | 13:29 | |
*** edmondsw has joined #openstack-keystone | 13:32 | |
*** stevemar_ has joined #openstack-keystone | 13:38 | |
*** ChanServ sets mode: +o stevemar_ | 13:38 | |
*** jerrygb_ has quit IRC | 13:39 | |
*** jaosorior has quit IRC | 13:45 | |
*** lhcheng has joined #openstack-keystone | 13:45 | |
*** ChanServ sets mode: +v lhcheng | 13:45 | |
*** boris-42 has quit IRC | 13:48 | |
*** su_zhang has joined #openstack-keystone | 13:49 | |
*** lhcheng has quit IRC | 13:49 | |
*** henrynash has quit IRC | 13:51 | |
*** e0ne has quit IRC | 13:51 | |
*** e0ne has joined #openstack-keystone | 13:52 | |
*** richm has joined #openstack-keystone | 13:54 | |
*** EinstCrazy has joined #openstack-keystone | 14:01 | |
*** e0ne has quit IRC | 14:04 | |
*** andrey-mp has joined #openstack-keystone | 14:06 | |
*** lhcheng has joined #openstack-keystone | 14:08 | |
*** ChanServ sets mode: +v lhcheng | 14:08 | |
*** lhcheng has quit IRC | 14:13 | |
*** e0ne has joined #openstack-keystone | 14:13 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Refactor test use of new_*_ref https://review.openstack.org/237205 | 14:14 |
*** EinstCrazy has quit IRC | 14:19 | |
*** marzif has quit IRC | 14:20 | |
*** jerrygb has joined #openstack-keystone | 14:22 | |
*** kashyap has joined #openstack-keystone | 14:23 | |
*** roxanaghe has joined #openstack-keystone | 14:23 | |
*** bdossant has quit IRC | 14:27 | |
*** fawadkhaliq has joined #openstack-keystone | 14:31 | |
*** roxanaghe has quit IRC | 14:31 | |
*** roxanaghe has joined #openstack-keystone | 14:31 | |
lbragstad | bknudson the admin guide you think the FAQ should be proposed to is this one, right - https://github.com/openstack/openstack-manuals/tree/master/doc/admin-guide-cloud/source ? | 14:32 |
*** petertr7_away is now known as petertr7 | 14:33 | |
bknudson | lbragstad: it should show up in here: http://docs.openstack.org/admin-guide-cloud/identity_management.html | 14:33 |
lbragstad | bknudson yep, ok.. | 14:33 |
lbragstad | that looks like the right place. | 14:33 |
bknudson | https://github.com/openstack/openstack-manuals/blob/master/doc/admin-guide-cloud/source/identity_management.rst | 14:33 |
*** roxanaghe has quit IRC | 14:36 | |
marekd | stevemar_: where cn i find etherpad with the list of keystone design sessions etherpads ? | 14:38 |
bknudson | marekd: https://wiki.openstack.org/wiki/Design_Summit/Mitaka/Etherpads | 14:40 |
marekd | thank you | 14:40 |
*** su_zhang has quit IRC | 14:41 | |
*** EinstCrazy has joined #openstack-keystone | 14:46 | |
*** petertr7 is now known as petertr7_away | 14:47 | |
*** petertr7_away is now known as petertr7 | 14:49 | |
openstackgerrit | Marek Denis proposed openstack/keystone-specs: Make keystone fully fledged SAML2 Service Provider https://review.openstack.org/244694 | 14:52 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Document release notes process https://review.openstack.org/244343 | 14:55 |
*** dims has quit IRC | 15:01 | |
*** EinstCrazy has quit IRC | 15:01 | |
*** jasonsb has joined #openstack-keystone | 15:01 | |
*** BAKfr has quit IRC | 15:06 | |
*** tyagiprince2010 has joined #openstack-keystone | 15:06 | |
*** dims has joined #openstack-keystone | 15:07 | |
*** stevemar_ has quit IRC | 15:08 | |
*** BAKfr has joined #openstack-keystone | 15:09 | |
*** btully has joined #openstack-keystone | 15:12 | |
*** fhubik is now known as fhubik_brb | 15:14 | |
xek | breton, Hi, are you sure a bp with a spec is needed for introducing the unit test blocking alters and drops? or are you thinking about a wider case of issues with rolling upgrades? | 15:14 |
*** lnxnut has joined #openstack-keystone | 15:16 | |
*** andrey-mp has quit IRC | 15:16 | |
*** slberger has joined #openstack-keystone | 15:17 | |
*** EinstCrazy has joined #openstack-keystone | 15:19 | |
openstackgerrit | ChangBo Guo(gcb) proposed openstack/keystone: Use the oslo.utils.reflection to extract the class name https://review.openstack.org/241494 | 15:20 |
*** marzif has joined #openstack-keystone | 15:21 | |
*** ninag has joined #openstack-keystone | 15:27 | |
*** stevemar_ has joined #openstack-keystone | 15:29 | |
*** ChanServ sets mode: +o stevemar_ | 15:29 | |
*** timcline has joined #openstack-keystone | 15:31 | |
*** fhubik_brb is now known as fhubik | 15:31 | |
openstackgerrit | Merged openstack/keystone: Use unit.new_service_ref() consistently https://review.openstack.org/238283 | 15:39 |
*** fawadkhaliq has quit IRC | 15:40 | |
*** lhcheng has joined #openstack-keystone | 15:42 | |
*** ChanServ sets mode: +v lhcheng | 15:42 | |
openstackgerrit | Merged openstack/keystone: Use unit.new_region_ref() consistently https://review.openstack.org/238302 | 15:44 |
openstackgerrit | Merged openstack/keystone: Use unit.new_domain_ref consistently https://review.openstack.org/242615 | 15:44 |
*** lhcheng has quit IRC | 15:45 | |
*** bdossant has joined #openstack-keystone | 15:45 | |
*** petertr7 is now known as petertr7_away | 15:46 | |
*** lhcheng has joined #openstack-keystone | 15:47 | |
*** ChanServ sets mode: +v lhcheng | 15:47 | |
*** tonytan4ever has joined #openstack-keystone | 15:49 | |
*** petertr7_away is now known as petertr7 | 15:49 | |
*** aix_ has quit IRC | 15:52 | |
*** shaleh has joined #openstack-keystone | 15:55 | |
shaleh | stevemar_: sorry for the hassle with my ref reviews. I keep hitting random gate failures that are (usually) not my fault | 15:55 |
*** aix has joined #openstack-keystone | 15:56 | |
breton | xek: both | 15:58 |
*** zeus has quit IRC | 16:00 | |
*** zeus has joined #openstack-keystone | 16:01 | |
*** zeus is now known as Guest53786 | 16:01 | |
*** csoukup has joined #openstack-keystone | 16:02 | |
*** shaleh has quit IRC | 16:02 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/238264 | 16:03 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/238264 | 16:06 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/238264 | 16:07 |
*** jbell8 has joined #openstack-keystone | 16:08 | |
*** fhubik has quit IRC | 16:09 | |
*** zqfan is now known as zqfan_afk | 16:11 | |
*** shaleh has joined #openstack-keystone | 16:14 | |
*** thedodd has joined #openstack-keystone | 16:16 | |
*** thedodd has quit IRC | 16:16 | |
*** stevemar_ has quit IRC | 16:17 | |
*** links has quit IRC | 16:18 | |
*** stevemar_ has joined #openstack-keystone | 16:18 | |
*** ChanServ sets mode: +o stevemar_ | 16:18 | |
shaleh | stevemar_: thanks for sheperding my reviews. Sorry for the hassle. The gates have not liked me the last few days. Weird, random failures. | 16:20 |
shaleh | most of it was not my fault :-) | 16:20 |
*** Guest53786 is now known as zeus | 16:21 | |
*** zeus has quit IRC | 16:21 | |
*** zeus has joined #openstack-keystone | 16:21 | |
openstackgerrit | Sean Perry proposed openstack/keystone: Use new_domain_ref instead of manually created ref https://review.openstack.org/244737 | 16:21 |
*** urulama has quit IRC | 16:22 | |
shaleh | of course I found 3 places I missed that did not match any of my greps | 16:22 |
*** urulama has joined #openstack-keystone | 16:22 | |
*** jbonjean has left #openstack-keystone | 16:24 | |
*** toddnni has joined #openstack-keystone | 16:27 | |
*** ninag has quit IRC | 16:27 | |
*** jorge_munoz has quit IRC | 16:27 | |
openstackgerrit | werner mendizabal proposed openstack/keystone: Consolidate the fernet provider validate_v3_token() https://review.openstack.org/196877 | 16:27 |
openstackgerrit | Sean Perry proposed openstack/keystone: Use new_region_ref instead of manually created dict https://review.openstack.org/244745 | 16:28 |
*** jorge_munoz has joined #openstack-keystone | 16:32 | |
*** peter-hamilton has quit IRC | 16:33 | |
*** EinstCrazy has quit IRC | 16:35 | |
*** fawadkhaliq has joined #openstack-keystone | 16:40 | |
*** r-daneel has joined #openstack-keystone | 16:42 | |
*** itlinux has joined #openstack-keystone | 16:44 | |
*** roxanaghe has joined #openstack-keystone | 16:45 | |
*** jorge_munoz has quit IRC | 16:48 | |
*** aix has quit IRC | 16:49 | |
*** rcernin has quit IRC | 16:50 | |
*** petertr7 is now known as petertr7_away | 16:52 | |
*** davechen has joined #openstack-keystone | 16:53 | |
*** urulama has quit IRC | 16:56 | |
*** gyee has joined #openstack-keystone | 16:56 | |
*** ChanServ sets mode: +v gyee | 16:56 | |
*** urulama has joined #openstack-keystone | 16:57 | |
*** petertr7_away is now known as petertr7 | 16:59 | |
*** marzif has quit IRC | 16:59 | |
*** josecastroleon has quit IRC | 16:59 | |
*** marzif has joined #openstack-keystone | 17:00 | |
*** e0ne has quit IRC | 17:02 | |
*** marzif has quit IRC | 17:05 | |
*** marzif has joined #openstack-keystone | 17:06 | |
*** pcaruana has quit IRC | 17:06 | |
openstackgerrit | Sean Perry proposed openstack/keystone: Use new_domain_ref instead of manually created ref https://review.openstack.org/244737 | 17:08 |
openstackgerrit | Julien Danjou proposed openstack/python-keystoneclient: httpclient: remove unused debug kwargs https://review.openstack.org/236739 | 17:09 |
*** tyagiprince2010 has quit IRC | 17:12 | |
*** lhcheng has quit IRC | 17:13 | |
*** exploreshaifali has joined #openstack-keystone | 17:13 | |
*** shaleh has quit IRC | 17:14 | |
*** diazjf has joined #openstack-keystone | 17:14 | |
*** jorge_munoz has joined #openstack-keystone | 17:14 | |
*** lhcheng has joined #openstack-keystone | 17:15 | |
*** ChanServ sets mode: +v lhcheng | 17:15 | |
*** marzif has quit IRC | 17:20 | |
*** rcernin has joined #openstack-keystone | 17:24 | |
*** navid_ has joined #openstack-keystone | 17:27 | |
*** navid__ has joined #openstack-keystone | 17:27 | |
*** navid_ has left #openstack-keystone | 17:30 | |
*** navid__ has left #openstack-keystone | 17:30 | |
*** navid_ has joined #openstack-keystone | 17:31 | |
*** josecastroleon has joined #openstack-keystone | 17:32 | |
*** mylu has joined #openstack-keystone | 17:35 | |
*** EinstCrazy has joined #openstack-keystone | 17:35 | |
*** petertr7 is now known as petertr7_away | 17:40 | |
*** spandhe has joined #openstack-keystone | 17:40 | |
*** navid_ has quit IRC | 17:41 | |
*** EinstCrazy has quit IRC | 17:42 | |
*** aix has joined #openstack-keystone | 17:43 | |
*** tonytan4ever has quit IRC | 17:44 | |
*** david-lyle has quit IRC | 17:46 | |
*** e0ne has joined #openstack-keystone | 17:50 | |
*** bdossant has quit IRC | 17:50 | |
*** mylu has quit IRC | 17:52 | |
*** mylu has joined #openstack-keystone | 17:53 | |
*** mylu has quit IRC | 17:57 | |
*** mylu has joined #openstack-keystone | 17:57 | |
*** su_zhang has joined #openstack-keystone | 17:58 | |
*** timcline has quit IRC | 17:59 | |
*** mylu has quit IRC | 17:59 | |
*** su_zhang has quit IRC | 18:03 | |
*** su_zhang has joined #openstack-keystone | 18:04 | |
*** josecastroleon has quit IRC | 18:16 | |
*** jistr has quit IRC | 18:22 | |
*** shaleh has joined #openstack-keystone | 18:25 | |
*** timcline has joined #openstack-keystone | 18:25 | |
*** toddnni has quit IRC | 18:25 | |
*** tonytan4ever has joined #openstack-keystone | 18:27 | |
*** browne has joined #openstack-keystone | 18:29 | |
*** mylu has joined #openstack-keystone | 18:31 | |
shaleh | What is with the gates? I am getting lots of failures that have nothing to do with my changes. | 18:32 |
*** petertr7_away is now known as petertr7 | 18:32 | |
*** su_zhang has quit IRC | 18:32 | |
*** mylu has quit IRC | 18:32 | |
*** mylu has joined #openstack-keystone | 18:32 | |
*** navid_ has joined #openstack-keystone | 18:33 | |
*** diazjf has quit IRC | 18:38 | |
*** fawadkhaliq has quit IRC | 18:39 | |
*** mylu has quit IRC | 18:40 | |
*** mylu has joined #openstack-keystone | 18:41 | |
gyee | shaleh, let me introduce you to your new friend, recheck | 18:41 |
shaleh | gyee, I almost need a bot to type that into each of my submits | 18:41 |
gyee | not a bad idea :) | 18:42 |
*** jbell8 has quit IRC | 18:42 | |
*** EmilienM has quit IRC | 18:42 | |
*** su_zhang has joined #openstack-keystone | 18:45 | |
*** mylu has quit IRC | 18:45 | |
*** EmilienM has joined #openstack-keystone | 18:45 | |
*** e0ne has quit IRC | 18:47 | |
*** petertr7 is now known as petertr7_away | 18:47 | |
*** su_zhang has quit IRC | 18:47 | |
openstackgerrit | Nathan Kinder proposed openstack/keystone: Remove hardcoded LDAP group schema from emulated enabled mix-in https://review.openstack.org/244173 | 18:50 |
*** su_zhang has joined #openstack-keystone | 18:51 | |
stevemar_ | shaleh: np, yeah, the gate is finnicky at times | 18:55 |
shaleh | stevemar_, I keep seeing it failing due to timing or inability to launch components | 18:55 |
*** tonytan_brb has joined #openstack-keystone | 18:56 | |
*** petertr7_away is now known as petertr7 | 18:56 | |
*** gyee has quit IRC | 18:56 | |
*** tonytan4ever has quit IRC | 18:59 | |
*** tonytan4ever has joined #openstack-keystone | 19:01 | |
*** tonytan_brb has quit IRC | 19:01 | |
*** shaleh is now known as shaleh|wawy | 19:01 | |
*** itlinux has quit IRC | 19:02 | |
*** urulama has quit IRC | 19:02 | |
*** urulama has joined #openstack-keystone | 19:03 | |
openstackgerrit | Michael Krotscheck proposed openstack/keystone: Added CORS support to Keystone https://review.openstack.org/241317 | 19:08 |
openstackgerrit | Michael Krotscheck proposed openstack/keystone: Added CORS support to Keystone https://review.openstack.org/241317 | 19:08 |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystonemiddleware: Last sync from oslo-incubator https://review.openstack.org/244813 | 19:10 |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/python-keystoneclient: Last sync from oslo-incubator https://review.openstack.org/244825 | 19:12 |
*** diazjf has joined #openstack-keystone | 19:14 | |
*** aix has quit IRC | 19:15 | |
*** toddnni has joined #openstack-keystone | 19:15 | |
*** zqfan_afk has quit IRC | 19:16 | |
*** navid__ has joined #openstack-keystone | 19:18 | |
*** navid_ has quit IRC | 19:18 | |
*** mylu has joined #openstack-keystone | 19:20 | |
*** davechen has quit IRC | 19:21 | |
*** flriegel has joined #openstack-keystone | 19:22 | |
*** csoukup has quit IRC | 19:23 | |
*** fangzhou has joined #openstack-keystone | 19:23 | |
*** mylu has quit IRC | 19:25 | |
*** su_zhang has quit IRC | 19:28 | |
boltR | hello | 19:29 |
boltR | in v2 keystone, if a user had three projects A, B, C | 19:29 |
boltR | and he had a scoped token for A, but deleted C | 19:30 |
boltR | would the scoped token for A be invalidated as well? | 19:30 |
*** flriegel has quit IRC | 19:34 | |
*** navid__ has quit IRC | 19:35 | |
*** arunkant_ has joined #openstack-keystone | 19:36 | |
*** flriegel has joined #openstack-keystone | 19:39 | |
*** med_ is now known as openstackgerrit_ | 19:39 | |
*** navid_ has joined #openstack-keystone | 19:39 | |
*** openstackgerrit_ is now known as med_ | 19:40 | |
krotscheck | tjcocozz: Response to your comment. I'm don't quite understand how our patches are different, could you clarify? | 19:40 |
*** shaleh|wawy is now known as shaleh | 19:41 | |
*** csoukup has joined #openstack-keystone | 19:41 | |
* tjcocozz is looking | 19:41 | |
krotscheck | tjcocozz: Thanks :) | 19:42 |
*** x58 has quit IRC | 19:47 | |
*** x58 has joined #openstack-keystone | 19:48 | |
openstackgerrit | Jorge Munoz proposed openstack/keystone: Consolidate the fernet provider issue_v2_token() https://review.openstack.org/197647 | 19:49 |
tjcocozz | krotscheck, responded | 19:50 |
lhcheng | boltR: I think so.. when a role assignment is removed from a user, the token of that user gets invalidated. | 19:51 |
lhcheng | boltR: this behavior is to prevent the user from further accessing the system in case a privilege got removed from the user. | 19:53 |
*** topol has joined #openstack-keystone | 19:58 | |
*** ChanServ sets mode: +v topol | 19:58 | |
krotscheck | tjcocozz: GOtcha. So, on an entirely different note, I feel like adding this test - i.e. testing for _all_ extension points - should be a different patch than trying to add this specific one. | 20:00 |
*** doug-fish has quit IRC | 20:01 | |
krotscheck | tjcocozz: Which then leads to the question of yak shaving. Should the addition of this particular middleware be blocked because that section of the code doesn't have a test to cover it yet? | 20:01 |
*** jbell8 has joined #openstack-keystone | 20:03 | |
tjcocozz | krotscheck, i was thining about that maybe make a dependent patch that adds the test? I will leave that last question up to one of the cores. | 20:04 |
krotscheck | tjcocozz: If that's the case, is it my responsibility to manage that patch? I've got other work I have to do. | 20:04 |
*** RichardRaseley has joined #openstack-keystone | 20:04 | |
*** thiagop has quit IRC | 20:04 | |
*** pauloewerton has quit IRC | 20:04 | |
*** iurygregory has quit IRC | 20:04 | |
tjcocozz | krotscheck, i can do it if you would like? | 20:04 |
krotscheck | tjcocozz: You seem to understand the problem space better than I. | 20:05 |
*** diegoadolfo has quit IRC | 20:05 | |
krotscheck | tjcocozz: Tell ya what. I'll remove the second assertion and propose that, and you can iterate on the test and make sure the factories are resolved proprely | 20:05 |
*** ericksonsantos has quit IRC | 20:05 | |
*** doug-fish has joined #openstack-keystone | 20:05 | |
openstackgerrit | Michael Krotscheck proposed openstack/keystone: Added CORS support to Keystone https://review.openstack.org/241317 | 20:06 |
tjcocozz | krotscheck, will do. | 20:06 |
krotscheck | tjcocozz: Works for me, thanks :) | 20:07 |
tjcocozz | krotscheck, do you think i should make a dependent patch for the other tests? | 20:07 |
*** urulama has quit IRC | 20:07 | |
krotscheck | You mean the other extension points? | 20:08 |
tjcocozz | krotscheck, yes | 20:08 |
*** urulama has joined #openstack-keystone | 20:08 | |
krotscheck | I don't really have an opinion on that, TBH. Do any of the cores have an opinion? | 20:08 |
*** itlinux has joined #openstack-keystone | 20:15 | |
*** topol has quit IRC | 20:17 | |
*** raildo is now known as raildo-afk | 20:17 | |
*** itlinux has quit IRC | 20:18 | |
tjcocozz | krotscheck, I think an update to the commit message saying "This patch adds tests for all the entrypoints in paste.filter_factory" should do the trick. | 20:19 |
*** shaleh is now known as shaleh|away | 20:19 | |
*** itlinux has joined #openstack-keystone | 20:20 | |
*** tonytan4ever has quit IRC | 20:22 | |
*** diazjf has quit IRC | 20:22 | |
*** diazjf has joined #openstack-keystone | 20:23 | |
*** diazjf has quit IRC | 20:27 | |
*** diazjf has joined #openstack-keystone | 20:28 | |
*** diazjf has quit IRC | 20:28 | |
*** itlinux has quit IRC | 20:29 | |
openstackgerrit | Michael Krotscheck proposed openstack/keystone: Added CORS support to Keystone https://review.openstack.org/241317 | 20:32 |
*** tyagiprince2010 has joined #openstack-keystone | 20:32 | |
*** itlinux has joined #openstack-keystone | 20:33 | |
*** topol has joined #openstack-keystone | 20:33 | |
*** ChanServ sets mode: +v topol | 20:33 | |
tyagiprince2010 | hey I want to know what happens when the authentication component is in delegated mode.. | 20:33 |
tyagiprince2010 | also if it is useful..? | 20:34 |
tyagiprince2010 | I am talking about the middleware architecture | 20:34 |
tyagiprince2010 | http://docs.openstack.org/developer/keystonemiddleware/middlewarearchitecture.html#authcomponentdelegated | 20:36 |
tyagiprince2010 | heres the link where i read about it | 20:36 |
*** tonytan4ever has joined #openstack-keystone | 20:36 | |
*** fangzhou has quit IRC | 20:40 | |
*** csoukup has quit IRC | 20:40 | |
tyagiprince2010 | anyone?? | 20:40 |
tyagiprince2010 | need help | 20:41 |
*** RichardRaseley has quit IRC | 20:44 | |
*** davechen_ has joined #openstack-keystone | 20:45 | |
*** davechen_ is now known as davechen | 20:45 | |
tyagiprince2010 | People need help with the auth middleware | 20:45 |
*** mylu has joined #openstack-keystone | 20:47 | |
* davechen slaps lhcheng around a bit with a large fishbot | 20:50 | |
*** mylu has quit IRC | 20:55 | |
*** mylu has joined #openstack-keystone | 20:55 | |
*** mylu has quit IRC | 20:55 | |
*** mylu has joined #openstack-keystone | 20:56 | |
*** csoukup has joined #openstack-keystone | 20:57 | |
*** gyee has joined #openstack-keystone | 20:58 | |
*** ChanServ sets mode: +v gyee | 20:58 | |
*** su_zhang has joined #openstack-keystone | 20:59 | |
*** mylu has quit IRC | 21:00 | |
*** mylu has joined #openstack-keystone | 21:01 | |
*** navid_ has quit IRC | 21:01 | |
*** mylu has quit IRC | 21:03 | |
*** mylu has joined #openstack-keystone | 21:03 | |
*** su_zhang has quit IRC | 21:03 | |
*** mylu_ has joined #openstack-keystone | 21:04 | |
*** mylu has quit IRC | 21:05 | |
tyagiprince2010 | Hey people need help with keystone | 21:05 |
tyagiprince2010 | been reading the documentation for days.. | 21:06 |
tyagiprince2010 | marekd: hey sorry to disturb you again.. can i ask you something about the middleware | 21:06 |
*** itlinux has quit IRC | 21:07 | |
*** mylu_ has quit IRC | 21:07 | |
*** topol has quit IRC | 21:07 | |
*** topol has joined #openstack-keystone | 21:07 | |
*** ChanServ sets mode: +v topol | 21:07 | |
*** fangzhou has joined #openstack-keystone | 21:08 | |
*** flriegel has quit IRC | 21:09 | |
*** mylu has joined #openstack-keystone | 21:10 | |
*** mylu has quit IRC | 21:11 | |
*** mylu has joined #openstack-keystone | 21:12 | |
*** topol has quit IRC | 21:12 | |
*** mylu has quit IRC | 21:14 | |
*** mylu has joined #openstack-keystone | 21:14 | |
*** kashyap has left #openstack-keystone | 21:19 | |
*** mylu has quit IRC | 21:19 | |
*** toddnni has quit IRC | 21:23 | |
*** jbell8 has quit IRC | 21:24 | |
*** stevemar_ has quit IRC | 21:25 | |
*** su_zhang has joined #openstack-keystone | 21:26 | |
*** bdossant has joined #openstack-keystone | 21:27 | |
*** mylu has joined #openstack-keystone | 21:27 | |
*** petertr7 is now known as petertr7_away | 21:28 | |
*** petertr7_away is now known as petertr7 | 21:32 | |
*** mylu has quit IRC | 21:34 | |
*** RichardRaseley has joined #openstack-keystone | 21:39 | |
openstackgerrit | werner mendizabal proposed openstack/keystone: Consolidate the fernet provider validate_v3_token() https://review.openstack.org/196877 | 21:46 |
*** tellesnobrega is now known as tellesnobrega_af | 21:47 | |
openstackgerrit | Jorge Munoz proposed openstack/keystone: Consolidate the fernet provider issue_v2_token() https://review.openstack.org/197647 | 21:49 |
openstackgerrit | Dave Chen proposed openstack/keystone: Using the right format to render the docstring correctly https://review.openstack.org/226225 | 21:50 |
*** davechen has quit IRC | 21:51 | |
*** e0ne has joined #openstack-keystone | 21:54 | |
*** jbell8 has joined #openstack-keystone | 21:58 | |
*** spandhe has quit IRC | 21:58 | |
*** fangzhou_ has joined #openstack-keystone | 21:59 | |
*** lhcheng has quit IRC | 21:59 | |
*** lhcheng has joined #openstack-keystone | 22:00 | |
*** ChanServ sets mode: +v lhcheng | 22:00 | |
*** fangzhou has quit IRC | 22:00 | |
*** fangzhou_ is now known as fangzhou | 22:00 | |
*** jasonsb has quit IRC | 22:00 | |
*** bdossant has quit IRC | 22:00 | |
*** petertr7 is now known as petertr7_away | 22:04 | |
*** jamielennox|away is now known as jamielennox | 22:05 | |
*** exploreshaifali has quit IRC | 22:05 | |
*** timcline has quit IRC | 22:06 | |
*** topol has joined #openstack-keystone | 22:08 | |
*** ChanServ sets mode: +v topol | 22:08 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/243923 | 22:09 |
*** david-lyle has joined #openstack-keystone | 22:16 | |
openstackgerrit | Jamie Lennox proposed openstack/python-keystoneclient: Map keystoneclient exceptions to keystoneauth https://review.openstack.org/243869 | 22:16 |
*** henrynash has joined #openstack-keystone | 22:18 | |
*** ChanServ sets mode: +v henrynash | 22:18 | |
*** boris-42 has joined #openstack-keystone | 22:19 | |
*** bdossant has joined #openstack-keystone | 22:19 | |
*** bdossant has quit IRC | 22:20 | |
*** dims_ has joined #openstack-keystone | 22:23 | |
henrynash | samueldmq: ping | 22:24 |
*** dims has quit IRC | 22:25 | |
*** bdossant has joined #openstack-keystone | 22:26 | |
*** bdossant has quit IRC | 22:26 | |
*** maxabidi has joined #openstack-keystone | 22:26 | |
*** urulama has quit IRC | 22:29 | |
*** urulama has joined #openstack-keystone | 22:29 | |
*** lnxnut has quit IRC | 22:32 | |
*** gildub has joined #openstack-keystone | 22:34 | |
openstackgerrit | Merged openstack/python-keystoneclient: update incorrect docstring for regions https://review.openstack.org/243857 | 22:37 |
samueldmq | henrynash: pong | 22:38 |
henrynash | hi | 22:38 |
*** BAKfr has quit IRC | 22:38 | |
henrynash | so I have an idea about projects, names and domains…. | 22:38 |
samueldmq | henrynash: hi :) | 22:38 |
samueldmq | henrynash: sure | 22:39 |
henrynash | what if we said that a project name must be unique within its parent (this is in addition to the other enforcements like also unique within a domain) | 22:39 |
samueldmq | henrynash: makes sense to me | 22:40 |
*** BAKfr has joined #openstack-keystone | 22:40 | |
henrynash | what this would do (I think) is stop there ever being two projcets of the same name under a project acting as a domain | 22:40 |
*** ayoung has quit IRC | 22:40 | |
henrynash | so we’d never encounter that rather ackward problem | 22:40 |
henrynash | it would slighly affect the UX | 22:41 |
samueldmq | henrynash: yes, but we can hit that during migration ? | 22:41 |
samueldmq | henrynash: I think that's okay, makes clear what project you're refering to when you have its parent name | 22:41 |
samueldmq | henrynash: like putting hte same name for 2 brothers, that also looks confusing in real world | 22:42 |
henrynash | I dont see how….we can hit that a project has the same name as its domain….but we can avoid the case when there is a regular project and an is_domain project under the same parent | 22:42 |
henrynash | which is the confusing one, I think | 22:42 |
*** gildub_ has joined #openstack-keystone | 22:42 | |
henrynash | since there can’t be any sub-domains yet at migration time, we can make sure that when any are created there name don’t c;ash with any of the siblings | 22:43 |
samueldmq | henrynash: so today we have project names unique within a domain, right ? | 22:43 |
henrynash | yes | 22:43 |
samueldmq | henrynash: so I agree with you we can't hit that issue | 22:43 |
samueldmq | hmm, that's interesting | 22:43 |
openstackgerrit | Jamie Lennox proposed openstack/keystone: Use our own request in base wsgi class https://review.openstack.org/244472 | 22:45 |
henrynash | right now, when we create a sub-domain (well teh proposed code for this), we check that the projecj name is unique among other doamins….but we don’t check if the namei is unque against other regular project siblings of teh parent | 22:45 |
samueldmq | henrynash: but wait .. not sure I get what's the difference, unique in domain looks to be more restrict than unique for a given parent , | 22:45 |
samueldmq | henrynash: as tehy're all in the same domain anyway ? | 22:45 |
henrynash | ah, but no…when you are creating a sub-domain…we only check it’s unique comaprd with otehr domains (which includes its parent)…but not other projects that might be part of its parent | 22:46 |
henrynash | (unless I’m confusing myslelf :-) ) | 22:47 |
samueldmq | henrynash: ah, I think we should be checking its uniqueness (as a project) in its parent domain | 22:47 |
henrynash | yes…ignore is_domain_ness….just make sure you are nique with the direct siblings of the parent | 22:48 |
henrynash | (as well as the other checks like uniaue against all other domains) | 22:48 |
samueldmq | henrynash: if it can act as a project and as a domain, so it must follow the uniqueness rules for both domains (no other domain with the same name) AND for projects (no other project with the same name in the parent domain) | 22:48 |
samueldmq | henrynash: yes, I think we are thinking the same | 22:49 |
henrynash | wel..it doesn’t have to unqiue caompared with all projects in the tree of the parent domain…just those at the samelevel as it | 22:49 |
*** RichardRaseley has quit IRC | 22:50 | |
samueldmq | henrynash: why not ? that's how we check for a normal project, right ? | 22:50 |
samueldmq | henrynash: if we put still another different rule, maybe we will make it still more confusing and complext to understand , | 22:51 |
henrynash | yes, but not against projects that are in anothe domain | 22:51 |
samueldmq | henrynash: in terms of api ;. :) | 22:51 |
samueldmq | henrynash: yep, not in another domain, but only in the owning domain | 22:52 |
samueldmq | like: domain A contains 20 projects and a subdomain Z | 22:52 |
samueldmq | subdomain Z cannot have the same name as any of the 20 projects in domain 1 | 22:52 |
samueldmq | domain A* | 22:52 |
henrynash | so that is more restrictive that it has to be | 22:52 |
samueldmq | that project can act as a project too, and in that case it shouldn't be any different than a regular project ? | 22:53 |
samueldmq | that domain can act as a project too* | 22:54 |
henrynash | yes, but not in domain A | 22:54 |
henrynash | in domain Z | 22:54 |
*** tonytan4ever has quit IRC | 22:54 | |
samueldmq | henrynash: who's the domain of Z ? itself ? | 22:54 |
henrynash | so if had VMs in the project acting as domain Z, they’d have to be part of domain Z | 22:56 |
samueldmq | henrynash: so in that case I agree with you | 22:56 |
henrynash | not domain A | 22:56 |
openstackgerrit | Jamie Lennox proposed openstack/keystone: Perform middleware tests with webtest https://review.openstack.org/244440 | 22:56 |
*** stevemar_ has joined #openstack-keystone | 22:56 | |
*** ChanServ sets mode: +o stevemar_ | 22:56 | |
henrynash | but I think I probably need to go and think on this some more!!! | 22:56 |
samueldmq | henrynash: nice, so what's the motivaion again to restrict its name in its level? | 22:56 |
*** pumaranikar has joined #openstack-keystone | 22:57 | |
henrynash | well, we never have the problem seaching by project name will return two results (e.g. the auth problem) | 22:57 |
samueldmq | henrynash: hmm, I think we don't have a problem maybe ? | 22:58 |
samueldmq | henrynash: Z cannot be seen as a project starting from A | 22:59 |
*** stevemar_ has quit IRC | 22:59 | |
samueldmq | henrynash: A only knows its own projects and that there is a domain called Z (knows nothing about what's withing Z) | 22:59 |
samueldmq | henrynash: if one needs to get a token in Z as a project, refer to domain Z | 22:59 |
samueldmq | ? | 22:59 |
henrynash | it’s the addressing problem in auth, I think….right now if I want a project scoped token and I said “Domain A, Project Z”…….it might be confusing if there two projects named Z under it | 23:01 |
samueldmq | henrynash: yep, but Z can't be seen as a project from A | 23:01 |
samueldmq | Z is a domain if you look from A | 23:02 |
henrynash | not in listing projects no | 23:02 |
samueldmq | henrynash: if you list the hierarchy in A, it will list Z as project ? | 23:02 |
samueldmq | and also the subprjects of Z ? | 23:02 |
henrynash | no, | 23:02 |
henrynash | sorry, that “no” was agreeingwith you ! | 23:03 |
samueldmq | yes, so I don't see the problem anymore | 23:03 |
samueldmq | if you want a token like: 'project=Z and domain=A' you may be refering to another project in A that's called Z | 23:03 |
samueldmq | not to the is_domain project Z in A (that can only be seen as a domain from there) | 23:04 |
henrynash | hmm, even I’m not sure now :-)….but we had to add special code in auth | 23:04 |
henrynash | maybe that was the case when you have Domain A containg a Project called A (that could hapen after migration)... | 23:04 |
*** mylu has joined #openstack-keystone | 23:04 | |
samueldmq | but that does make sense, doesn't it ? ^ :-) | 23:04 |
openstackgerrit | gordon chung proposed openstack/pycadf: make generate_uuid return valid uuid https://review.openstack.org/240979 | 23:04 |
henrynash | ….and if you say I want a token to Domain A, Project A - which do you mean | 23:05 |
henrynash | (and we added code to say you mean the regualar project A, not the project acting as domain A) | 23:06 |
samueldmq | yes, as we do today | 23:06 |
henrynash | in which case, my solution doesn’t help :-( | 23:06 |
samueldmq | hmm, yep that was the case | 23:07 |
henrynash | ok, let me crawl back under the desk and go think some more….my gut tells me there is goodness in this, but since I can’t articulate it….back to the drawing board!!! | 23:07 |
samueldmq | henrynash: sure, I will mull it a bit too | 23:08 |
samueldmq | also we need to think about how unlikely ? it can be | 23:08 |
*** toddnni has joined #openstack-keystone | 23:08 | |
*** mylu has quit IRC | 23:08 | |
*** mylu has joined #openstack-keystone | 23:08 | |
samueldmq | before putting tooo much effort in solving it | 23:08 |
henrynash | :-) | 23:09 |
*** csoukup has quit IRC | 23:09 | |
*** henrynash has quit IRC | 23:11 | |
*** gildub_ has quit IRC | 23:11 | |
*** gildub has quit IRC | 23:11 | |
*** mylu has quit IRC | 23:12 | |
*** jamielennox is now known as jamielennox|away | 23:13 | |
*** aix has joined #openstack-keystone | 23:18 | |
*** darrenc is now known as darrenc_afk | 23:18 | |
*** gyee has quit IRC | 23:19 | |
*** gyee has joined #openstack-keystone | 23:21 | |
*** ChanServ sets mode: +v gyee | 23:21 | |
*** jamielennox|away is now known as jamielennox | 23:22 | |
*** mylu has joined #openstack-keystone | 23:24 | |
*** topol has quit IRC | 23:25 | |
*** topol has joined #openstack-keystone | 23:25 | |
*** ChanServ sets mode: +v topol | 23:25 | |
*** tyagiprince2010 has quit IRC | 23:29 | |
*** mylu has quit IRC | 23:29 | |
*** topol has quit IRC | 23:30 | |
*** ayoung has joined #openstack-keystone | 23:30 | |
*** ChanServ sets mode: +v ayoung | 23:30 | |
openstackgerrit | Merged openstack/keystone-specs: Augment token to indicate if it is scoped to the admin project https://review.openstack.org/242232 | 23:31 |
*** jbell8 has quit IRC | 23:32 | |
*** gordc has quit IRC | 23:35 | |
*** mylu has joined #openstack-keystone | 23:37 | |
*** darrenc_afk is now known as darrenc | 23:39 | |
*** slberger has left #openstack-keystone | 23:41 | |
*** mylu has quit IRC | 23:47 | |
*** mylu has joined #openstack-keystone | 23:47 | |
*** gildub has joined #openstack-keystone | 23:47 | |
*** gildub_ has joined #openstack-keystone | 23:48 | |
*** ayoung has quit IRC | 23:50 | |
*** pumaranikar has quit IRC | 23:50 | |
*** jbell8 has joined #openstack-keystone | 23:50 | |
*** BrAsS_mOnKeY has quit IRC | 23:51 | |
*** mylu has quit IRC | 23:52 | |
*** mhu has quit IRC | 23:53 | |
*** BrAsS_mOnKeY has joined #openstack-keystone | 23:55 | |
*** mhu has joined #openstack-keystone | 23:56 | |
*** e0ne has quit IRC | 23:56 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!