*** ayoung has quit IRC | 00:03 | |
*** chlong has joined #openstack-keystone | 00:04 | |
mordred | samueldmq: soon | 00:06 |
---|---|---|
*** alejandrito has quit IRC | 00:08 | |
*** gildub has joined #openstack-keystone | 00:16 | |
*** EinstCrazy has quit IRC | 00:25 | |
*** agireud has quit IRC | 00:30 | |
*** agireud has joined #openstack-keystone | 00:36 | |
*** agireud has quit IRC | 00:36 | |
*** agireud has joined #openstack-keystone | 00:36 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 00:37 | |
*** RichardRaseley has quit IRC | 00:39 | |
*** markvoelker has quit IRC | 00:39 | |
*** aginwala has quit IRC | 00:43 | |
*** nkinder has quit IRC | 00:45 | |
*** miguelgrinberg has joined #openstack-keystone | 00:45 | |
*** aginwala has joined #openstack-keystone | 00:46 | |
*** agireud has quit IRC | 00:51 | |
*** markvoelker has joined #openstack-keystone | 00:55 | |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Disable memory caching of tokens https://review.openstack.org/212345 | 00:57 |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Don't cache signed tokens https://review.openstack.org/190941 | 00:57 |
*** EinstCrazy has joined #openstack-keystone | 01:02 | |
*** dims has quit IRC | 01:04 | |
*** doug-fish has quit IRC | 01:05 | |
*** daemontool has quit IRC | 01:08 | |
*** dims has joined #openstack-keystone | 01:09 | |
*** aginwala has quit IRC | 01:13 | |
*** darrenc_afk is now known as darrenc | 01:13 | |
*** arunkant_ has quit IRC | 01:14 | |
*** aginwala has joined #openstack-keystone | 01:28 | |
*** aginwala has quit IRC | 01:36 | |
*** aginwala has joined #openstack-keystone | 01:38 | |
*** oomichi is now known as oomichi_away | 01:48 | |
*** browne has quit IRC | 01:49 | |
*** agireud has joined #openstack-keystone | 01:51 | |
*** roxanaghe has quit IRC | 01:52 | |
*** roxanaghe has joined #openstack-keystone | 01:54 | |
openstackgerrit | Jamie Lennox proposed openstack/python-keystoneclient: Deprecate adapter https://review.openstack.org/258742 | 01:55 |
*** agireud has quit IRC | 01:59 | |
*** roxanaghe has quit IRC | 02:00 | |
*** agireud has joined #openstack-keystone | 02:02 | |
*** _cjones_ has quit IRC | 02:02 | |
*** _cjones_ has joined #openstack-keystone | 02:03 | |
*** agireud has quit IRC | 02:07 | |
*** _cjones_ has quit IRC | 02:08 | |
*** ayoung has joined #openstack-keystone | 02:18 | |
*** ChanServ sets mode: +v ayoung | 02:18 | |
*** agireud has joined #openstack-keystone | 02:23 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Add some documentation about migrating from ksc https://review.openstack.org/259256 | 02:34 |
openstackgerrit | Merged openstack/keystone: Use list_role_assignments to get projects/domains for user https://review.openstack.org/242513 | 02:39 |
*** kragniz has quit IRC | 02:41 | |
jamielennox | mordred: want to do some friday afternoon approving? | 02:42 |
jamielennox | or whatever time it is now | 02:42 |
jamielennox | damnit | 02:42 |
jamielennox | notmorgan: ^^ | 02:42 |
notmorgan | jamielennox: oh sure. | 02:42 |
notmorgan | why not! | 02:42 |
jamielennox | just so you're both aware i am still getting you confused | 02:42 |
notmorgan | ahahahhahahahahahahaha | 02:42 |
notmorgan | dude | 02:42 |
notmorgan | i even changed my nick:P | 02:42 |
jamielennox | yea, so now mo<tab> just autocompletes without choices | 02:42 |
notmorgan | way better hut? | 02:43 |
notmorgan | huh? | 02:43 |
jamielennox | https://review.openstack.org/#/c/117089/ | 02:43 |
notmorgan | ok looking | 02:44 |
jamielennox | https://review.openstack.org/#/c/244440/ | 02:44 |
*** fangxu has quit IRC | 02:45 | |
notmorgan | might take me a bit, watching a movie and about a 1/2 bottle of wine in for the evening | 02:45 |
jamielennox | notmorgan: that's exactly where i want to catch you for reviews! | 02:45 |
jamielennox | whats the movie? | 02:45 |
notmorgan | Secret Life of Walter Mitty | 02:45 |
notmorgan | really enjoying it | 02:45 |
jamielennox | ah, haven't seen it i'm not a big fan of what's his face | 02:46 |
*** kragniz has joined #openstack-keystone | 02:46 | |
notmorgan | ben stilleR? | 02:47 |
notmorgan | his more serious stuff is good | 02:47 |
notmorgan | almost time to get food. | 02:48 |
*** dims has quit IRC | 02:50 | |
*** aginwala has quit IRC | 02:51 | |
*** agireud has quit IRC | 02:57 | |
openstackgerrit | Merged openstack/keystone: Fix fernet padding for python 3 https://review.openstack.org/231711 | 03:02 |
*** agireud has joined #openstack-keystone | 03:02 | |
openstackgerrit | Merged openstack/keystone: Show defect in list_user_ids that only lists direct user assignments https://review.openstack.org/242564 | 03:04 |
openstackgerrit | Merged openstack/keystone: Fix defect in list_user_ids that only lists direct user assignments https://review.openstack.org/242574 | 03:04 |
openstackgerrit | Merged openstack/keystone: Limiting for fake LDAP https://review.openstack.org/247749 | 03:05 |
*** RA has joined #openstack-keystone | 03:05 | |
*** RA is now known as Guest39668 | 03:06 | |
*** Guest39668 is now known as _RA | 03:08 | |
*** spandhe has quit IRC | 03:09 | |
*** aginwala has joined #openstack-keystone | 03:12 | |
*** aginwala has quit IRC | 03:13 | |
*** links has joined #openstack-keystone | 03:14 | |
*** gyee has quit IRC | 03:40 | |
*** sdake has joined #openstack-keystone | 03:40 | |
*** markvoelker has quit IRC | 03:47 | |
*** fangxu has joined #openstack-keystone | 04:16 | |
*** albertom has quit IRC | 04:28 | |
*** davechen has joined #openstack-keystone | 04:28 | |
*** albertom has joined #openstack-keystone | 04:30 | |
*** markvoelker has joined #openstack-keystone | 04:47 | |
*** david-lyle has quit IRC | 04:50 | |
*** markvoelker has quit IRC | 04:52 | |
*** steveng has joined #openstack-keystone | 05:04 | |
*** steveng has quit IRC | 05:04 | |
notmorgan | jamielennox: just -1'd a couple patches in your deprecate changeset | 05:09 |
notmorgan | jamielennox: mostly because we don't want to report the deprecations to the end users - so we need servers/python-*clients to be mostly KSA first. | 05:09 |
notmorgan | jamielennox: imo | 05:09 |
notmorgan | jamielennox: these are soft -1s but i think we need to hold on this deprecation notice for a bit. | 05:10 |
*** davechen has left #openstack-keystone | 05:14 | |
stevemar | notmorgan: it'll force users and project maintainers to switch over :P | 05:20 |
notmorgan | no it wont | 05:20 |
notmorgan | because the clients are using session | 05:20 |
notmorgan | this is not something the end user has the ability to change | 05:20 |
notmorgan | this is something we need to land in python-*client | 05:20 |
notmorgan | this is like urllib3 saying OMG THIS IS INSECURE because requests says "insecure=True" | 05:21 |
notmorgan | and is expected | 05:21 |
stevemar | notmorgan: when is the line draw? | 05:22 |
*** Nirupama has joined #openstack-keystone | 05:22 | |
stevemar | notmorgan: the six core projects need to be migrated over? all of them? | 05:22 |
stevemar | (all meaning ALL python-*client) | 05:22 |
notmorgan | i'd argue the line is drawn when we have the core/starter edition clients moved | 05:22 |
stevemar | novaclient is done now | 05:23 |
notmorgan | so, glance, neutron, keystoneclient, nova, cinder, osc, uh i'm forgetting one | 05:23 |
notmorgan | did ti all land? last i saw it was in flight | 05:23 |
stevemar | swift | 05:23 |
notmorgan | swift is a special case | 05:23 |
stevemar | i think i saw it +A'ed | 05:23 |
notmorgan | swift wont factor into this. | 05:23 |
notmorgan | swift will go from non-session -> ksa | 05:23 |
stevemar | yes, migrated: https://review.openstack.org/#/c/256056/ | 05:24 |
notmorgan | so, glance neutron, ksc, nova, cinder, heat? | 05:24 |
stevemar | heat isn't technically core | 05:24 |
stevemar | horizon would be | 05:24 |
notmorgan | after that i'm content to say "seriously you're in the minority and we'll help" | 05:24 |
notmorgan | horizon is also a special case | 05:24 |
notmorgan | but getting the majority of actions to not complain to the end user would be ideal | 05:25 |
stevemar | these dudes; http://vmiss.net/wp-content/uploads/2015/11/Messages-Image9548435111.png | 05:25 |
notmorgan | ok | 05:25 |
notmorgan | heat would be a nice-to-have | 05:25 |
notmorgan | but then once glance nova cinder neutron and keystone clients are solid i say deprecate | 05:26 |
notmorgan | i'll hold the -1s until then, but they are soft -1s | 05:26 |
stevemar | you keep mentioning keystoneclient | 05:26 |
notmorgan | and swift will be worked on separately [i have a plan for this soon] and should not be affected cause they don't do session | 05:26 |
notmorgan | yes | 05:26 |
notmorgan | ksc needs to move to use ksa session | 05:26 |
notmorgan | it does not do that yet | 05:27 |
stevemar | oh i guess this guy: https://github.com/openstack/python-keystoneclient/blob/master/keystoneclient/v2_0/client.py#L37 | 05:27 |
notmorgan | yes | 05:27 |
notmorgan | the crud actions/client objects need to use KSA | 05:27 |
stevemar | https://github.com/openstack/python-keystoneclient/blob/master/keystoneclient/v3/client.py#L50 | 05:27 |
notmorgan | :) | 05:27 |
* notmorgan maaaaaay be thinking about this stuff atm | 05:27 | |
notmorgan | ^_^ | 05:27 |
stevemar | thats the first time i thought ksc would need an update | 05:28 |
openstackgerrit | Merged openstack/keystonemiddleware: Configuration is outdated https://review.openstack.org/220545 | 05:44 |
*** markvoelker has joined #openstack-keystone | 05:49 | |
*** markvoelker has quit IRC | 05:54 | |
*** serverascode has quit IRC | 06:05 | |
*** serverascode has joined #openstack-keystone | 06:13 | |
openstackgerrit | Merged openstack/python-keystoneclient: Seperate Client base test class https://review.openstack.org/258230 | 06:18 |
*** mfedosin has joined #openstack-keystone | 06:19 | |
jamielennox | it still concerns me in that diagram how more people use nova than keystone | 06:20 |
jamielennox | so keystoneclient can be said to be done, because we don't have a CLI | 06:21 |
*** david-lyle has joined #openstack-keystone | 06:21 | |
jamielennox | otherwise yea, my plan was to start emitting warnings so people came to us to migrate | 06:22 |
stevemar | jamielennox: we gotta migrate over the client instances of the CRUD part no? | 06:23 |
openstackgerrit | Merged openstack/python-keystoneclient: Make tests run against original client and sessions https://review.openstack.org/117089 | 06:23 |
*** fangxu has quit IRC | 06:27 | |
jamielennox | stevemar: i don't think we have to do anything like that, if it used to work with session it should work with ksa session | 06:46 |
notmorgan | jamielennox: we need to default to ksa sessio | 06:46 |
notmorgan | nis all | 06:47 |
jamielennox | ^ my previously oldest open review merged | 06:47 |
notmorgan | we have the occ things mordred and i have been pushing on | 06:47 |
notmorgan | and as soon as the ksa stuff is default we can say KSC is done, though we should convert CLI if we don't remove it | 06:47 |
jamielennox | first patch: Aug 27, 2014 | 06:47 |
notmorgan | or at least make the CLI say OMG STOP THIS NAO | 06:47 |
jamielennox | not bad | 06:47 |
jamielennox | notmorgan: yea, i did a new version of that spec today | 06:48 |
jamielennox | https://review.openstack.org/#/c/243348/ | 06:48 |
jamielennox | notmorgan, stevemar: also have a read of https://review.openstack.org/#/c/245629/ | 06:48 |
jamielennox | ayoung's admin_project wasn't a thing when i wrote it, but i think it'd still apply | 06:49 |
*** gildub has quit IRC | 06:54 | |
stevemar | jamielennox: commented on https://review.openstack.org/#/c/243348/4 | 07:18 |
*** _cjones_ has joined #openstack-keystone | 07:21 | |
*** gildub has joined #openstack-keystone | 07:26 | |
*** nfdeswqa has joined #openstack-keystone | 07:27 | |
*** e0ne has joined #openstack-keystone | 07:36 | |
*** chlong has quit IRC | 07:37 | |
nfdeswqa | Haha, wow! What a fun time I had tonight. Turns out Kylo Ren is Han and Leia's son, Ben but was seduced to the dark side. He even kills his own dad at the end.. It was really tense. Oh and Rea finds out she has jedi powers and does a mind trick on a storm trooper to escape captivity. She kicks Kylo Ren's ass with a lightsaber too! Luke Skywalker only shows up for 20 seconds at the end though | 07:40 |
nfdeswqa | which is kind of lame. Oh well. | 07:40 |
*** rcernin has joined #openstack-keystone | 07:41 | |
*** markvoelker has joined #openstack-keystone | 07:50 | |
openstackgerrit | Merged openstack/keystone: Handle fernet payload timestamp differences https://review.openstack.org/232711 | 07:50 |
openstackgerrit | Merged openstack/keystone: Fix key_repository_signature method for python3 https://review.openstack.org/236096 | 07:51 |
*** markvoelker has quit IRC | 07:55 | |
*** browne has joined #openstack-keystone | 07:55 | |
*** _RA has quit IRC | 07:58 | |
*** fangxu has joined #openstack-keystone | 07:59 | |
*** fangxu has quit IRC | 08:00 | |
*** jdennis1 has joined #openstack-keystone | 08:00 | |
*** jdennis has quit IRC | 08:01 | |
*** jed56 has joined #openstack-keystone | 08:02 | |
*** _cjones_ has quit IRC | 08:04 | |
*** nfdeswqa has quit IRC | 08:11 | |
stevemar | bump | 08:20 |
stevemar | bump | 08:20 |
stevemar | bump | 08:20 |
stevemar | bump | 08:20 |
stevemar | bump | 08:20 |
stevemar | bump | 08:20 |
stevemar | bump | 08:21 |
stevemar | bump | 08:21 |
stevemar | i will spam the channel for the good of everyone | 08:21 |
stevemar | # A "shared secret" that can be used to bootstrap Keystone. This "token" does | 08:21 |
stevemar | # not represent a user, and carries no explicit authorization. To disable in | 08:21 |
stevemar | # production (highly recommended), remove AdminTokenAuthMiddleware from your | 08:21 |
stevemar | # paste application pipelines (for example, in keystone-paste.ini). (string | 08:21 |
stevemar | # value) | 08:21 |
stevemar | #admin_token = ADMIN | 08:21 |
stevemar | # The base public endpoint URL for Keystone that is advertised to clients | 08:22 |
stevemar | # (NOTE: this does NOT affect how Keystone listens for connections). Defaults | 08:22 |
stevemar | # to the base host URL of the request. E.g. a request to | 08:22 |
stevemar | # http://server:5000/v3/users will default to http://server:5000. You should | 08:22 |
stevemar | # only need to set this value if the base URL contains a path (e.g. /prefix/v3) | 08:22 |
stevemar | # or the endpoint should be found on a different server. (string value) | 08:22 |
stevemar | #public_endpoint = <None> | 08:22 |
stevemar | # The base admin endpoint URL for Keystone that is advertised to clients (NOTE: | 08:22 |
stevemar | # this does NOT affect how Keystone listens for connections). Defaults to the | 08:22 |
stevemar | # base host URL of the request. E.g. a request to http://server:35357/v3/users | 08:22 |
stevemar | # will default to http://server:35357. You should only need to set this value | 08:22 |
stevemar | # if the base URL contains a path (e.g. /prefix/v3) or the endpoint should be | 08:22 |
stevemar | # found on a different server. (string value) | 08:22 |
stevemar | #admin_endpoint = <None> | 08:22 |
stevemar | # Maximum depth of the project hierarchy. WARNING: setting it to a large value | 08:22 |
stevemar | # may adversely impact performance. (integer value) | 08:22 |
stevemar | #max_project_tree_depth = 5 | 08:22 |
stevemar | # Limit the sizes of user & project ID/names. (integer value) | 08:22 |
stevemar | #max_param_size = 64 | 08:22 |
stevemar | # Similar to max_param_size, but provides an exception for token values. | 08:22 |
stevemar | # (integer value) | 08:22 |
stevemar | #max_token_size = 8192 | 08:22 |
stevemar | # Similar to the member_role_name option, this represents the default role ID | 08:22 |
stevemar | # used to associate users with their default projects in the v2 API. This will | 08:22 |
stevemar | # be used as the explicit role where one is not specified by the v2 API. | 08:22 |
stevemar | # (string value) | 08:22 |
stevemar | #member_role_id = 9fe2ff9ee4384b1894a90878d3e92bab | 08:22 |
*** oomichi_away is now known as oomichi | 08:49 | |
*** fhubik has joined #openstack-keystone | 08:55 | |
*** e0ne has quit IRC | 09:01 | |
breton | oh | 09:02 |
breton | star wars spoilers above | 09:03 |
breton | do not read above stevemar's "bump" | 09:03 |
*** browne has quit IRC | 09:05 | |
*** pnavarro has joined #openstack-keystone | 09:06 | |
*** Nirupama has quit IRC | 09:15 | |
*** e0ne has joined #openstack-keystone | 09:17 | |
*** sdake has quit IRC | 09:18 | |
*** mhickey has joined #openstack-keystone | 09:21 | |
*** mfedosin has quit IRC | 09:24 | |
*** jistr has joined #openstack-keystone | 09:25 | |
*** openstackgerrit has quit IRC | 09:32 | |
*** openstackgerrit has joined #openstack-keystone | 09:32 | |
*** e0ne has quit IRC | 09:35 | |
*** EinstCrazy has quit IRC | 09:40 | |
*** alexpro has joined #openstack-keystone | 09:43 | |
*** markvoelker has joined #openstack-keystone | 09:51 | |
*** links has quit IRC | 09:54 | |
*** markvoelker has quit IRC | 09:55 | |
*** Nirupama has joined #openstack-keystone | 10:05 | |
*** links has joined #openstack-keystone | 10:07 | |
*** Nirupama has quit IRC | 10:28 | |
*** fhubik has quit IRC | 10:35 | |
*** e0ne has joined #openstack-keystone | 10:40 | |
*** EinstCrazy has joined #openstack-keystone | 10:41 | |
*** ekarlso has quit IRC | 10:51 | |
*** ekarlso has joined #openstack-keystone | 10:51 | |
*** Nirupama has joined #openstack-keystone | 10:52 | |
*** dims has joined #openstack-keystone | 10:57 | |
*** paul-carlton1 has joined #openstack-keystone | 11:00 | |
paul-carlton1 | jamielennox, You around? | 11:00 |
*** lhcheng has joined #openstack-keystone | 11:04 | |
*** ChanServ sets mode: +v lhcheng | 11:04 | |
*** oomichi is now known as oomichi_away | 11:10 | |
*** urulama has quit IRC | 11:15 | |
*** urulama has joined #openstack-keystone | 11:16 | |
*** oomichi_away has quit IRC | 11:19 | |
*** paul-carlton1 has left #openstack-keystone | 11:22 | |
*** svasheka has quit IRC | 11:24 | |
*** lhinds has joined #openstack-keystone | 11:30 | |
*** lhcheng has quit IRC | 11:35 | |
*** Nirupama has quit IRC | 11:40 | |
*** links has quit IRC | 11:50 | |
*** markvoelker has joined #openstack-keystone | 11:51 | |
*** gildub has quit IRC | 11:55 | |
*** markvoelker has quit IRC | 11:56 | |
*** fhubik has joined #openstack-keystone | 11:56 | |
*** fhubik is now known as fhubik_brb | 11:56 | |
*** mfedosin has joined #openstack-keystone | 12:02 | |
*** fhubik_brb is now known as fhubik | 12:05 | |
*** links has joined #openstack-keystone | 12:06 | |
samueldmq | morning keystoners | 12:08 |
dims | samueldmq : i remember you were doing some policy related stuff, is this of any interest? https://review.openstack.org/#/c/256431/ | 12:13 |
samueldmq | dims: sure, but oslo.policy is only the engine, and in the case we wre to dd that, it'd be in keystone :) | 12:14 |
samueldmq | dims: thanks for the heads up | 12:14 |
dims | samueldmq : oslo.policy is being moved to keystone in governance :) so its keystone's headache now | 12:15 |
*** links has quit IRC | 12:16 | |
samueldmq | dims: yes, we agreed on that in our last meeting, good for everyone I think :) | 12:16 |
samueldmq | dims: I will leave a review there, also perhaps stevemar wants to take a look ^ | 12:16 |
dims | thanks samueldmq | 12:22 |
dims | ktychkova : ^^ | 12:22 |
dims | ktychkova : please follow up with samueldmq bknudson stevemar etc. i'd believe that we may follow the pattern set in say oslo.cache for selecting a specific backend based on configurations | 12:23 |
*** lhcheng_ has joined #openstack-keystone | 12:24 | |
ktychkova | dims: ok, I'll take a look | 12:25 |
samueldmq | ktychkova: hi | 12:25 |
ktychkova | samueldmq: hi | 12:25 |
samueldmq | ktychkova: so you want to consider already existing assingments in a LDAP storage for authorization within openstack | 12:26 |
ktychkova | samueldmq: yes, it is main idea, here is video https://vimeo.com/146109801 - take a look, please | 12:28 |
samueldmq | ktychkova: I believe this should be something that goes in the token | 12:28 |
samueldmq | ktychkova: i.e if we are going to do that, it should be something in keystone, which would put the info in the token, as it does today, and no services would be affected | 12:29 |
samueldmq | ktychkova: sure I will look | 12:29 |
samueldmq | ktychkova: and btw, we already support LDAP Assignment backends in keystone | 12:29 |
samueldmq | ktychkova: but it's deprecated and will be removed | 12:30 |
samueldmq | ktychkova: hmm, actually you want to support the poliy ruels via LDAP right , | 12:32 |
samueldmq | ? | 12:32 |
ktychkova | samueldmq: yes, i want to replace policy.json file | 12:32 |
ktychkova | samueldmq: to store rules and permissions in ldap, not in policy.json file | 12:33 |
samueldmq | ktychkova: hmm, we've had a long story on this :) (cc ayoung ^) | 12:34 |
samueldmq | ktychkova: so today we already support users in LDAP | 12:34 |
*** lhinds has quit IRC | 12:34 | |
samueldmq | ktychkova: we also support roles in LDAP (but deprecated and being removed) | 12:34 |
samueldmq | ktychkova: but we don't support permissions in LDAP | 12:36 |
samueldmq | ktychkova: are you aware of an effort we had to make policy files distributed from keystone to endpoints ? | 12:36 |
samueldmq | ktychkova: so policy changes would be made in keystone and serices would download them automatically | 12:37 |
ktychkova | samueldmq: is not dynamics policies abondend? I saw spec, but is this work still relevant? | 12:39 |
samueldmq | ktychkova: so, yes it is stopped | 12:40 |
ktychkova | samueldmq: my changes is about "where to store policies" | 12:41 |
samueldmq | ktychkova: but I could see your work on that context, where LDAP would be a backend for storing the policies, which are delivered by keystone | 12:41 |
samueldmq | ktychkova: without dynamic policies, if we put on keystone, we have no way to deliver it | 12:43 |
samueldmq | ktychkova: and if we put it on oslo, we will required every service endpoint to configure the LDAP backend | 12:43 |
samueldmq | ktychkova: I will leave a review, let's see wht others think about it too (cc ayoung) | 12:44 |
ktychkova | samueldmq: yes, thanks | 12:44 |
dims | samueldmq : from last oslo meeting, we were told that dynamic policy work was shelved | 12:44 |
samueldmq | dims: yes | 12:44 |
samueldmq | dims: but without it I don't see a good solution for what is being proposed by ktychkova | 12:45 |
samueldmq | dims: but that's my point of view, which may differ from others | 12:46 |
samueldmq | ktychkova: is this a usecase from your organization ? do you need/use this feature? | 12:46 |
dims | samueldmq : ktychkova has some prototype code that works just fine. (talk to backend instead of policy.hson) | 12:46 |
openstackgerrit | Kseniya Tychkova proposed openstack/keystone-specs: Support RBAC with LDAP in oslo.policy https://review.openstack.org/259418 | 12:47 |
dims | samueldmq : not sure why we have to make it more complicated than that | 12:47 |
dims | yes, if the dynamic policy work was actually going on then we would have had a place to do a backend, but clearly it's not going to happen anytime soon | 12:47 |
openstackgerrit | Merged openstack/python-keystoneclient-kerberos: Drop py33 support https://review.openstack.org/257807 | 12:48 |
ktychkova | samueldmq: this feature was requested from several openstack users | 12:48 |
samueldmq | dims: sure, but there are some other points like: are LDAP queries slow ? if so that'd affect the whole cloud as authz checks are ran all the time | 12:48 |
samueldmq | dims: also, each service endpoint will need to configure LDAP backend right ? | 12:48 |
dims | samueldmq : those are all valid points to raise on the review under performance and implementation sections | 12:49 |
samueldmq | ktychkova: cool, I didn't know people stored those rules in LDAP | 12:49 |
samueldmq | dims: ++ | 12:49 |
samueldmq | dims: ktychkova: in the case we store policy rules in LDAP, we also want to get the roles from there too, right ? | 12:51 |
*** markvoelker has joined #openstack-keystone | 12:52 | |
samueldmq | dims: ktychkova: and we just deprecated the role backend (https://github.com/openstack/keystone/blob/master/keystone/assignment/role_backends/ldap.py#L32-L35) | 12:52 |
ktychkova | samueldmq: ok, I'll take a look | 12:54 |
samueldmq | ktychkova: I am also looking at your patch, let's see what others think about it too | 12:56 |
samueldmq | ktychkova: (notice I am not against your work, I just making sure to ask the right questions so we make the best decision) | 12:57 |
*** markvoelker has quit IRC | 12:57 | |
*** andreykurilin__ has joined #openstack-keystone | 12:57 | |
ktychkova | samueldmq: you are welcome for any questions! | 12:58 |
ktychkova | samueldmq: dims: moved spec to keystone https://review.openstack.org/#/c/259418/ | 12:58 |
*** fesp has joined #openstack-keystone | 12:59 | |
*** fhubik is now known as fhubik_brb | 13:00 | |
*** fesp has quit IRC | 13:03 | |
samueldmq | ktychkova: oh, and I had just left a review there :) will put in the new patch | 13:03 |
samueldmq | ktychkova: posted comments, thanks :) | 13:06 |
*** zqfan has quit IRC | 13:11 | |
*** vgridnev has joined #openstack-keystone | 13:12 | |
samueldmq | looks like any core could easily +2+A https://review.openstack.org/#/c/228109/ | 13:18 |
samueldmq | and https://review.openstack.org/#/c/130669/ | 13:21 |
samueldmq | :) | 13:21 |
*** fhubik_brb is now known as fhubik | 13:23 | |
*** raildo-afk is now known as raildo | 13:23 | |
*** links has joined #openstack-keystone | 13:25 | |
*** fhubik is now known as fhubik_brb | 13:26 | |
*** gordc has joined #openstack-keystone | 13:27 | |
*** fhubik_brb is now known as fhubik | 13:30 | |
*** breitz has quit IRC | 13:33 | |
*** breitz has joined #openstack-keystone | 13:34 | |
*** fhubik has quit IRC | 13:42 | |
*** boris-42_ has quit IRC | 13:43 | |
*** doug-fish has joined #openstack-keystone | 13:47 | |
*** e0ne has quit IRC | 13:48 | |
*** e0ne has joined #openstack-keystone | 13:50 | |
*** fhubik has joined #openstack-keystone | 13:52 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-keystoneclient-kerberos: Updated from global requirements https://review.openstack.org/251664 | 13:53 |
*** urulama has quit IRC | 13:53 | |
*** urulama has joined #openstack-keystone | 13:54 | |
*** links has quit IRC | 13:54 | |
*** richm has joined #openstack-keystone | 13:57 | |
*** fhubik is now known as fhubik_brb | 14:22 | |
*** markvoelker has joined #openstack-keystone | 14:23 | |
*** fhubik_brb is now known as fhubik | 14:25 | |
*** markvoelker has quit IRC | 14:27 | |
*** pnavarro has quit IRC | 14:33 | |
*** dslevin has quit IRC | 14:36 | |
*** dansmith is now known as superdan | 14:41 | |
*** jsheeren has joined #openstack-keystone | 14:45 | |
*** dslev has joined #openstack-keystone | 14:45 | |
*** sdake has joined #openstack-keystone | 14:46 | |
*** sdake_ has joined #openstack-keystone | 14:53 | |
*** sdake has quit IRC | 14:53 | |
*** simondodsley has joined #openstack-keystone | 14:59 | |
*** jsheeren has quit IRC | 14:59 | |
*** fhubik is now known as fhubik_brb | 15:03 | |
*** fhubik_brb is now known as fhubik | 15:05 | |
*** david-lyle has quit IRC | 15:08 | |
*** davechen has joined #openstack-keystone | 15:11 | |
*** csoukup has joined #openstack-keystone | 15:15 | |
*** ninag has joined #openstack-keystone | 15:23 | |
*** timcline has joined #openstack-keystone | 15:26 | |
*** spotz_zzz is now known as spotz | 15:32 | |
flaper87 | Hey folks, just wanted to say thanks for all the feedback provided in the "glance trusts" patch: https://review.openstack.org/#/c/241986/ | 15:37 |
*** vgridnev has quit IRC | 15:37 | |
*** dancn has quit IRC | 15:39 | |
*** dancn has joined #openstack-keystone | 15:47 | |
*** fhubik is now known as fhubik_brb | 15:48 | |
*** lhcheng_ has quit IRC | 15:52 | |
*** ctina has joined #openstack-keystone | 15:52 | |
*** pumaranikar has joined #openstack-keystone | 15:53 | |
*** browne has joined #openstack-keystone | 16:01 | |
*** sdake_ has quit IRC | 16:02 | |
*** sdake has joined #openstack-keystone | 16:05 | |
*** mhickey has quit IRC | 16:06 | |
*** lhcheng has joined #openstack-keystone | 16:08 | |
*** ChanServ sets mode: +v lhcheng | 16:08 | |
openstackgerrit | Dave Chen proposed openstack/keystone: Add testcases to check cache invalidation https://review.openstack.org/258785 | 16:14 |
*** rcernin has quit IRC | 16:15 | |
*** diazjf has joined #openstack-keystone | 16:20 | |
*** markvoelker has joined #openstack-keystone | 16:24 | |
*** fhubik_brb is now known as fhubik | 16:26 | |
*** markvoelker has quit IRC | 16:28 | |
*** timcline has quit IRC | 16:30 | |
*** timcline has joined #openstack-keystone | 16:30 | |
*** timcline_ has joined #openstack-keystone | 16:31 | |
*** andreykurilin__ has quit IRC | 16:32 | |
*** timcline has quit IRC | 16:35 | |
*** dims_ has joined #openstack-keystone | 16:37 | |
*** sdake has quit IRC | 16:38 | |
*** sdake has joined #openstack-keystone | 16:39 | |
*** dims has quit IRC | 16:39 | |
*** petertr7_away is now known as petertr7 | 16:42 | |
*** andreykurilin__ has joined #openstack-keystone | 16:45 | |
*** fhubik has quit IRC | 16:45 | |
*** sdake has quit IRC | 16:46 | |
*** sdake has joined #openstack-keystone | 16:47 | |
*** jistr has quit IRC | 16:49 | |
*** ctina has quit IRC | 16:49 | |
*** petertr7 is now known as petertr7_away | 16:52 | |
*** pumaranikar has quit IRC | 16:56 | |
*** pumaranikar has joined #openstack-keystone | 16:56 | |
*** mfedosin has quit IRC | 16:57 | |
*** jorge_munoz has quit IRC | 16:58 | |
*** davechen has quit IRC | 17:00 | |
*** pumaranikar has quit IRC | 17:00 | |
*** pumaranikar has joined #openstack-keystone | 17:01 | |
*** davechen has joined #openstack-keystone | 17:01 | |
*** pwp has joined #openstack-keystone | 17:02 | |
*** gyee has joined #openstack-keystone | 17:06 | |
*** ChanServ sets mode: +v gyee | 17:06 | |
*** arunkant has quit IRC | 17:06 | |
*** e0ne has quit IRC | 17:13 | |
*** sdake has quit IRC | 17:19 | |
*** _cjones_ has joined #openstack-keystone | 17:20 | |
*** arunkant has joined #openstack-keystone | 17:23 | |
*** markvoelker has joined #openstack-keystone | 17:24 | |
*** pwp has quit IRC | 17:28 | |
*** _cjones_ has quit IRC | 17:29 | |
*** markvoelker has quit IRC | 17:29 | |
*** pwp has joined #openstack-keystone | 17:29 | |
*** sdake has joined #openstack-keystone | 17:30 | |
openstackgerrit | Haneef Ali proposed openstack/keystone: Keystone returns internal server error if the the user doesn't send any token. This happens only for fernet token. This review returns 401 for fernet provider similar to other providers https://review.openstack.org/259563 | 17:35 |
*** simondodsley has quit IRC | 17:38 | |
*** _cjones_ has joined #openstack-keystone | 17:40 | |
*** sdake has quit IRC | 17:40 | |
*** pwp has quit IRC | 17:44 | |
openstackgerrit | Fernando Diaz proposed openstack/keystone: Opt-out certain Keystone Notifications https://review.openstack.org/253780 | 17:51 |
*** david-lyle has joined #openstack-keystone | 17:54 | |
breton | has anybody ever set keystone with mod-shib in HA configuration? | 17:56 |
breton | haneef_: | 17:56 |
breton | marekd: | 17:56 |
*** david-lyle has quit IRC | 17:59 | |
*** e0ne has joined #openstack-keystone | 18:00 | |
*** david-lyle has joined #openstack-keystone | 18:00 | |
*** _cjones_ has quit IRC | 18:02 | |
*** rcernin has joined #openstack-keystone | 18:06 | |
*** gordc has quit IRC | 18:06 | |
*** urulama has quit IRC | 18:09 | |
*** urulama has joined #openstack-keystone | 18:10 | |
*** fhubik has joined #openstack-keystone | 18:12 | |
*** fhubik has quit IRC | 18:14 | |
*** fhubik has joined #openstack-keystone | 18:15 | |
*** browne has quit IRC | 18:19 | |
*** e0ne has quit IRC | 18:22 | |
*** _cjones_ has joined #openstack-keystone | 18:24 | |
*** spotz is now known as spotz_zzz | 18:26 | |
*** _cjones_ has quit IRC | 18:26 | |
*** _cjones_ has joined #openstack-keystone | 18:27 | |
*** dancn has quit IRC | 18:28 | |
*** gordc has joined #openstack-keystone | 18:30 | |
*** e0ne has joined #openstack-keystone | 18:31 | |
*** sdake has joined #openstack-keystone | 18:34 | |
*** rcernin has quit IRC | 18:36 | |
*** dancn has joined #openstack-keystone | 18:37 | |
*** e0ne has quit IRC | 18:42 | |
*** pwp has joined #openstack-keystone | 18:44 | |
*** andreykurilin__ has quit IRC | 18:52 | |
*** urulama has quit IRC | 18:54 | |
*** urulama has joined #openstack-keystone | 18:54 | |
marekd | breton: shibboleth has some options for using db for storing cookies. Then first call can be executed with machine A and another with machine B where state will be shared on both machines. | 18:54 |
marekd | breton: i think this is the main concern | 18:55 |
openstackgerrit | Haneef Ali proposed openstack/keystone: Keystone returns internal server error if the the user doesn't send any token. This happens only for fernet token. This review returns 401 for fernet provider similar to other providers https://review.openstack.org/259563 | 18:56 |
*** aix has quit IRC | 18:56 | |
*** fhubik has quit IRC | 18:59 | |
*** diazjf has quit IRC | 19:04 | |
*** jbell8 has joined #openstack-keystone | 19:06 | |
davechen | anyone kown the background for this CI (gate-tempest-dsvm-keystone-eventlet-fullNOT_REGISTERED)? | 19:06 |
*** _cjones_ has quit IRC | 19:08 | |
breton | marekd: yep | 19:09 |
breton | but I fixed it with sticky sessions in haproxy | 19:10 |
lhcheng | davechen: some ci related changes occurred and it hit a node where the change haven't propagated yet. | 19:11 |
marekd | breton: that's also an option | 19:17 |
*** openstackgerrit has quit IRC | 19:17 | |
*** openstackgerrit has joined #openstack-keystone | 19:17 | |
davechen | lhcheng: good to know, which project / team focus on ci related changes? | 19:18 |
lhcheng | davechen: check in the infra room, I hit the NOT_REGISTERED issue when I just added reno job in horizon. Recheck did the trick for me. | 19:20 |
davechen | lhcheng: look like recheck didn't work, hope not all of infra team are in holiday mode. | 19:23 |
*** markvoelker has joined #openstack-keystone | 19:25 | |
*** lhcheng has quit IRC | 19:28 | |
*** markvoelker has quit IRC | 19:30 | |
*** browne has joined #openstack-keystone | 19:38 | |
*** aix has joined #openstack-keystone | 19:38 | |
*** e0ne has joined #openstack-keystone | 19:39 | |
*** e0ne has quit IRC | 19:42 | |
*** vgridnev has joined #openstack-keystone | 19:44 | |
*** diazjf has joined #openstack-keystone | 19:49 | |
*** aginwala has joined #openstack-keystone | 19:49 | |
*** aginwala has quit IRC | 19:55 | |
*** pwp has quit IRC | 19:58 | |
*** sdake_ has joined #openstack-keystone | 20:00 | |
*** pwp has joined #openstack-keystone | 20:00 | |
*** sdake has quit IRC | 20:00 | |
*** jsavak has joined #openstack-keystone | 20:02 | |
*** petertr7_away is now known as petertr7 | 20:02 | |
*** mhickey has joined #openstack-keystone | 20:02 | |
*** aginwala has joined #openstack-keystone | 20:10 | |
*** superdan has quit IRC | 20:12 | |
*** dansmith has joined #openstack-keystone | 20:12 | |
*** aginwala has quit IRC | 20:13 | |
*** aginwala has joined #openstack-keystone | 20:13 | |
*** jsavak has quit IRC | 20:20 | |
*** jamielennox is now known as jamielennox|away | 20:21 | |
*** aginwala has quit IRC | 20:31 | |
*** gordc has quit IRC | 20:38 | |
openstackgerrit | Fernando Diaz proposed openstack/keystone: Opt-out certain Keystone Notifications https://review.openstack.org/253780 | 20:39 |
*** e0ne has joined #openstack-keystone | 20:40 | |
*** raildo is now known as raildo-afk | 20:44 | |
*** petertr7 is now known as petertr7_away | 20:48 | |
*** jidar has joined #openstack-keystone | 20:49 | |
*** e0ne has quit IRC | 20:53 | |
*** petertr7_away is now known as petertr7 | 20:56 | |
*** aginwala has joined #openstack-keystone | 20:58 | |
*** aginwala has quit IRC | 20:58 | |
*** gyee has quit IRC | 21:01 | |
*** jbell8 has quit IRC | 21:06 | |
jidar | hey guys, I'm trying to understand why I would get an auth required error when pulling down the project/tenant list from horizon | 21:06 |
jidar | (and everything else seems to function fine) | 21:06 |
*** pwp has quit IRC | 21:08 | |
*** aginwala has joined #openstack-keystone | 21:09 | |
*** aginwala has quit IRC | 21:10 | |
*** pwp has joined #openstack-keystone | 21:10 | |
*** sdake_ is now known as sdake | 21:13 | |
openstackgerrit | Dave Chen proposed openstack/keystone: Add testcases to check the invalid endpoints is removed https://review.openstack.org/259627 | 21:14 |
*** mfedosin has joined #openstack-keystone | 21:17 | |
*** aginwala has joined #openstack-keystone | 21:24 | |
*** mhickey has quit IRC | 21:25 | |
*** markvoelker has joined #openstack-keystone | 21:26 | |
*** pumaranikar has quit IRC | 21:30 | |
*** markvoelker has quit IRC | 21:31 | |
*** gyee has joined #openstack-keystone | 21:32 | |
*** ChanServ sets mode: +v gyee | 21:32 | |
*** timcline_ has quit IRC | 21:35 | |
*** ninag_ has joined #openstack-keystone | 21:35 | |
*** ninag has quit IRC | 21:37 | |
*** ninag_ has quit IRC | 21:38 | |
*** sdake has quit IRC | 21:40 | |
*** petertr7 is now known as petertr7_away | 21:46 | |
stevemar | davechen: where are you seeing that | 21:50 |
stevemar | ? | 21:50 |
stevemar | oh i see it here: https://review.openstack.org/#/c/259563/ | 21:51 |
stevemar | davechen: we added this change recently: https://review.openstack.org/#/c/257999/ | 21:52 |
davechen | stevemar: oh, thanks boss :) | 21:52 |
stevemar | davechen: np | 21:52 |
stevemar | davechen: we are trying to create 3 different jobs... the main one being apache based | 21:53 |
stevemar | the other 2 are: eventlet based and then uwsgi based | 21:53 |
davechen | i didn't aware we are enabling uwsgi. | 21:53 |
stevemar | we're trying it out | 21:54 |
davechen | stevemar: yes, this is something i will learn in this weekend. | 21:54 |
stevemar | davechen: some folks want to run nginx and uwsgi | 21:54 |
stevemar | instead of apache and mod_wsgi | 21:54 |
*** pwp has quit IRC | 21:54 | |
davechen | stevemar: what's the best advantage of uwsgi? | 21:55 |
*** sdake has joined #openstack-keystone | 21:55 | |
davechen | i will do some research anyway | 21:55 |
davechen | need run with our team mates, thanks for all of those information. | 21:56 |
davechen | stevemar: happy holiday! | 21:56 |
stevemar | davechen: you too! have fun this weekend :) | 21:56 |
*** davechen has left #openstack-keystone | 21:56 | |
*** pwp has joined #openstack-keystone | 22:01 | |
*** pwp has quit IRC | 22:03 | |
*** sdake has quit IRC | 22:03 | |
*** aginwala has quit IRC | 22:03 | |
*** aginwala has joined #openstack-keystone | 22:05 | |
*** gyee has quit IRC | 22:06 | |
*** petertr7_away is now known as petertr7 | 22:10 | |
*** alex_xu has quit IRC | 22:11 | |
*** pwp has joined #openstack-keystone | 22:12 | |
*** alex_xu has joined #openstack-keystone | 22:13 | |
*** pwp has quit IRC | 22:20 | |
*** petertr7 is now known as petertr7_away | 22:21 | |
*** vgridnev has quit IRC | 22:25 | |
*** pwp has joined #openstack-keystone | 22:27 | |
*** pwp has quit IRC | 22:27 | |
*** alex_xu has quit IRC | 22:34 | |
*** alex_xu has joined #openstack-keystone | 22:36 | |
*** aginwala has quit IRC | 22:36 | |
openstackgerrit | Haneef Ali proposed openstack/keystone: Keystone returns internal server error if the the user doesn't send any token. This happens only for fernet token. This review returns 401 for fernet provider similar to other providers https://review.openstack.org/259563 | 22:36 |
*** aginwala has joined #openstack-keystone | 22:38 | |
*** aginwala has quit IRC | 22:39 | |
*** aginwala has joined #openstack-keystone | 22:47 | |
*** aginwala_ has joined #openstack-keystone | 22:49 | |
*** aginwala has quit IRC | 22:49 | |
*** rcernin has joined #openstack-keystone | 22:52 | |
*** urulama has quit IRC | 23:02 | |
*** urulama has joined #openstack-keystone | 23:02 | |
*** rcernin has quit IRC | 23:08 | |
*** markvoelker has joined #openstack-keystone | 23:12 | |
*** aginwala_ has quit IRC | 23:12 | |
*** diazjf has quit IRC | 23:13 | |
*** jbell8 has joined #openstack-keystone | 23:15 | |
*** jbell8 has quit IRC | 23:16 | |
*** markvoelker has quit IRC | 23:17 | |
jidar | can anyone tell me why the openstack client trys to connect to my AdminURL when asking for a project list? | 23:21 |
*** mfedosin has quit IRC | 23:26 | |
*** alex_xu has quit IRC | 23:30 | |
*** alex_xu has joined #openstack-keystone | 23:31 | |
notmorgan | stevemar: sooooo | 23:34 |
notmorgan | stevemar, ayoung: have a cloud up and running with 2 things missing for "completeness" | 23:34 |
notmorgan | stevemar, ayoung: no floating IPs yet and second no console | 23:35 |
ayoung | console meaning websockify? | 23:35 |
*** aginwala has joined #openstack-keystone | 23:35 | |
notmorgan | ayoung: yeah | 23:35 |
notmorgan | ayoung: i actually had it working but needed to tear down the proxys | 23:35 |
ayoung | notmorgan, can you get away without doing floating ips? | 23:35 |
notmorgan | not in my POC | 23:35 |
ayoung | just use public, and focus on IPv56? | 23:35 |
notmorgan | since it's on another openstack cloud | 23:35 |
ayoung | ah | 23:35 |
notmorgan | if it was an actual allocated/routable set of addresses it'd be easier | 23:36 |
notmorgan | i mean... i could *probably* do some hackery to make it work but floating ips will suffice for this POC | 23:36 |
notmorgan | ayoung: since i can allocated IPs to myself and then create specific networks for each and then just allow the neutron to config them for the instances... but that seems like a lot of extra work to show sub-url works | 23:37 |
notmorgan | and it's *nice* | 23:37 |
ayoung | notmorgan, very nice | 23:38 |
notmorgan | next step is run shade functional tests against it | 23:38 |
notmorgan | then document the **** out of it and do a write up | 23:38 |
notmorgan | there are 3 rather serious bugs to address but the list has gotten smaller | 23:39 |
* notmorgan also feels accomplished having hand-configured an entire openstack cloud | 23:39 | |
notmorgan | full multi-node | 23:39 |
*** csoukup has quit IRC | 23:43 | |
*** dims has joined #openstack-keystone | 23:46 | |
*** dims_ has quit IRC | 23:48 | |
*** sdake has joined #openstack-keystone | 23:53 | |
*** dims has quit IRC | 23:57 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!