*** markvoelker has joined #openstack-keystone | 00:12 | |
*** jasonsb has joined #openstack-keystone | 00:12 | |
*** henrynash has quit IRC | 00:32 | |
*** oomichi has joined #openstack-keystone | 00:41 | |
*** shoutm has quit IRC | 00:51 | |
*** topol has joined #openstack-keystone | 01:01 | |
*** ChanServ sets mode: +v topol | 01:01 | |
*** wanghua has joined #openstack-keystone | 01:14 | |
*** topol has quit IRC | 01:17 | |
*** topol has joined #openstack-keystone | 01:17 | |
*** ChanServ sets mode: +v topol | 01:17 | |
*** davechen has joined #openstack-keystone | 01:18 | |
*** davechen1 has joined #openstack-keystone | 01:25 | |
*** chlong has joined #openstack-keystone | 01:25 | |
*** davechen has quit IRC | 01:29 | |
jamielennox | any one around? want to bounce some policy ideas | 01:54 |
---|---|---|
jamielennox | notmorgan, stevemar: most likely around | 01:54 |
notmorgan | jamielennox: i am not really here. | 01:54 |
jamielennox | notmorgan: lol, still replied - not really like don't do it, or you need convincing | 01:55 |
notmorgan | i just finished cooking dinner [okj... a late lunch] | 01:56 |
notmorgan | and cleaning | 01:56 |
jamielennox | so try again later | 01:57 |
notmorgan | but i'm here. | 01:57 |
notmorgan | if ya need | 01:57 |
jamielennox | notmorgan: you're probably the other person most involved in this stuff | 01:58 |
notmorgan | which stuff? | 01:58 |
jamielennox | policy, service -> service communication, auth plugins | 01:58 |
notmorgan | explain? | 01:58 |
jamielennox | alright, it's the same stuff i've been stuck on for a while, and i've started going in circles | 01:59 |
* notmorgan also starts get some hot water so tea can be brewed. | 01:59 | |
notmorgan | s/get// | 01:59 |
jamielennox | to do any form of service token validation we need keystone to own a few different pieces | 02:00 |
jamielennox | actually start more simply | 02:00 |
jamielennox | to do enforcement with a service token we need two major pieces | 02:01 |
jamielennox | policy enforcement to understand service tokens | 02:01 |
jamielennox | add service tokens to context and send them around in rpc and from service->service | 02:01 |
jamielennox | i would prefer to solve this in a general way so that keystone owns chunks of that communication process | 02:02 |
notmorgan | hmm. | 02:02 |
jamielennox | so that we can do things like add new parameters to the list of things that policy is enforced on | 02:03 |
jamielennox | and standardize that, so that it's not user in some policy files and user_id in others | 02:03 |
jamielennox | that bit is not too bad, i can see two ways to do that and i think i'm just being indecisive there | 02:05 |
jamielennox | because policy and auth_token are in the same process i was going to add a to_policy_dict to the user plugin | 02:06 |
*** henrynash has joined #openstack-keystone | 02:26 | |
*** ChanServ sets mode: +v henrynash | 02:26 | |
*** fangxu has joined #openstack-keystone | 03:04 | |
*** davechen has joined #openstack-keystone | 03:25 | |
*** davechen1 has quit IRC | 03:27 | |
*** davechen1 has joined #openstack-keystone | 03:37 | |
*** davechen has quit IRC | 03:40 | |
*** henrynash has quit IRC | 03:43 | |
*** links has joined #openstack-keystone | 03:54 | |
*** Nirupama has joined #openstack-keystone | 04:00 | |
openstackgerrit | FelixLi proposed openstack/keystone: Add colon to separate parameter and description https://review.openstack.org/263111 | 04:47 |
stevemar | jamielennox: i'm around now | 04:59 |
jamielennox | stevemar: ah - thanks, let me ponder it for another day or so | 04:59 |
stevemar | jamielennox: just read the problem | 05:01 |
stevemar | i'm exhausted and about to hit the bed, so your extra-thinking is well timed | 05:01 |
jamielennox | stevemar: yea, it's a bit conceptual and i'm just looking to kind of figure it out - so later | 05:02 |
openstackgerrit | zhangguoqing proposed openstack/keystone: Change LOG.warn to LOG.warning https://review.openstack.org/263113 | 05:05 |
openstackgerrit | zhangguoqing proposed openstack/keystoneauth: Change LOG.warn to LOG.warning https://review.openstack.org/263116 | 05:21 |
*** GB21 has joined #openstack-keystone | 05:33 | |
openstackgerrit | FelixLi proposed openstack/keystone: Add colon to separate parameter and description https://review.openstack.org/263111 | 05:35 |
*** markvoelker has quit IRC | 05:39 | |
*** fangxu has quit IRC | 05:58 | |
*** henrynash has joined #openstack-keystone | 06:01 | |
*** ChanServ sets mode: +v henrynash | 06:01 | |
*** jrist has quit IRC | 06:01 | |
*** maestro has joined #openstack-keystone | 06:03 | |
*** topol has quit IRC | 06:11 | |
*** topol has joined #openstack-keystone | 06:11 | |
*** ChanServ sets mode: +v topol | 06:11 | |
*** markvoelker has joined #openstack-keystone | 06:40 | |
*** markvoelker has quit IRC | 06:45 | |
*** chlong has quit IRC | 06:55 | |
jamielennox | notmorgan, mordred: https://review.openstack.org/#/c/263151/ and https://review.openstack.org/#/c/253793/ are why we need a list | 07:08 |
*** henrynash has quit IRC | 07:11 | |
openstackgerrit | lei zhang proposed openstack/keystone: Define paste entrypoints https://review.openstack.org/263155 | 07:13 |
*** topol has quit IRC | 07:14 | |
*** topol has joined #openstack-keystone | 07:15 | |
*** ChanServ sets mode: +v topol | 07:15 | |
*** oomichi has quit IRC | 07:17 | |
openstackgerrit | FelixLi proposed openstack/keystone: Add colon to separate parameter and description https://review.openstack.org/263111 | 07:20 |
*** urulama has joined #openstack-keystone | 07:22 | |
*** topol has quit IRC | 07:26 | |
*** fangxu has joined #openstack-keystone | 07:26 | |
*** belmoreira has joined #openstack-keystone | 07:29 | |
openstackgerrit | Ankit Agrawal proposed openstack/keystone: Fix users and groups exact filters https://review.openstack.org/263158 | 07:32 |
openstackgerrit | Dave Chen proposed openstack/keystone: Add schema for federation protocol https://review.openstack.org/263161 | 07:41 |
*** jrist has joined #openstack-keystone | 08:10 | |
openstackgerrit | Dave Chen proposed openstack/keystone: Remove redundant check after enforcing schema validation https://review.openstack.org/262768 | 08:19 |
openstackgerrit | Merged openstack/keystone: Fix some inconsistency in docstrings https://review.openstack.org/250219 | 08:23 |
*** xek_ is now known as xek | 08:29 | |
openstackgerrit | FelixLi proposed openstack/keystone: Add colon to separate parameter and description https://review.openstack.org/263111 | 08:31 |
*** jed56 has joined #openstack-keystone | 08:32 | |
*** bmwiedemann has joined #openstack-keystone | 08:39 | |
*** martinus__ has joined #openstack-keystone | 08:39 | |
bmwiedemann | hi. do you know how I can get a 2nd +2 on https://review.openstack.org/#/c/252355/ ? | 08:40 |
bmwiedemann | this has been troubling PKI tokens for a long time now. | 08:40 |
*** lhcheng has joined #openstack-keystone | 08:40 | |
*** ChanServ sets mode: +v lhcheng | 08:40 | |
*** markvoelker has joined #openstack-keystone | 08:41 | |
*** _zouyee has joined #openstack-keystone | 08:43 | |
*** maestro has quit IRC | 08:44 | |
*** lhcheng has quit IRC | 08:45 | |
*** markvoelker has quit IRC | 08:45 | |
*** davechen1 is now known as davechen | 08:47 | |
*** agireud has quit IRC | 08:51 | |
*** links has quit IRC | 09:00 | |
*** oomichi has joined #openstack-keystone | 09:00 | |
*** fhubik has joined #openstack-keystone | 09:00 | |
*** fhubik is now known as fhubik_brb | 09:01 | |
*** bmwiedemann has left #openstack-keystone | 09:02 | |
*** links has joined #openstack-keystone | 09:04 | |
*** maestro has joined #openstack-keystone | 09:08 | |
*** jistr has joined #openstack-keystone | 09:12 | |
*** maestro has left #openstack-keystone | 09:12 | |
*** fhubik_brb is now known as fhubik | 09:21 | |
*** agireud has joined #openstack-keystone | 09:31 | |
openstackgerrit | Julien Danjou proposed openstack/keystone: wsgi: fix base_url finding https://review.openstack.org/226464 | 09:36 |
*** davechen has left #openstack-keystone | 09:37 | |
*** agireud has quit IRC | 09:39 | |
openstackgerrit | FelixLi proposed openstack/keystone: Add return value https://review.openstack.org/263111 | 09:41 |
*** alexpro has joined #openstack-keystone | 09:44 | |
*** agireud has joined #openstack-keystone | 09:46 | |
*** goodygum has joined #openstack-keystone | 09:50 | |
*** fhubik is now known as fhubik_brb | 09:58 | |
*** openstackgerrit has quit IRC | 10:02 | |
*** openstackgerrit has joined #openstack-keystone | 10:02 | |
openstackgerrit | Jude Augustine Job proposed openstack/python-keystoneclient: Changing the endpoints method for tokens https://review.openstack.org/263196 | 10:13 |
*** aix has joined #openstack-keystone | 10:15 | |
openstackgerrit | lei zhang proposed openstack/keystone: Add migration to make service type unique https://review.openstack.org/263197 | 10:17 |
openstackgerrit | lei zhang proposed openstack/keystone: Make service type unique https://review.openstack.org/263197 | 10:23 |
*** jistr has quit IRC | 10:24 | |
*** fhubik_brb has quit IRC | 10:24 | |
*** jistr has joined #openstack-keystone | 10:30 | |
*** jistr has quit IRC | 10:30 | |
*** fangxu has quit IRC | 10:33 | |
*** fangxu has joined #openstack-keystone | 10:33 | |
*** samueldmq1 is now known as samueldmq | 10:34 | |
*** markvoelker has joined #openstack-keystone | 10:42 | |
*** urulama has quit IRC | 10:42 | |
*** urulama has joined #openstack-keystone | 10:42 | |
*** mhickey has joined #openstack-keystone | 10:45 | |
*** markvoelker has quit IRC | 10:46 | |
*** Ephur has joined #openstack-keystone | 10:48 | |
*** fhubik_brb has joined #openstack-keystone | 10:49 | |
*** GB21 has quit IRC | 11:06 | |
*** e0ne has joined #openstack-keystone | 11:06 | |
*** GB21 has joined #openstack-keystone | 11:18 | |
*** daemontool has joined #openstack-keystone | 11:29 | |
*** urulama has quit IRC | 11:32 | |
*** urulama has joined #openstack-keystone | 11:33 | |
*** fhubik_brb is now known as fhubik | 11:40 | |
*** dims has joined #openstack-keystone | 11:40 | |
*** dims has quit IRC | 11:40 | |
*** dims has joined #openstack-keystone | 11:41 | |
*** jistr has joined #openstack-keystone | 11:41 | |
*** GB21 has quit IRC | 11:51 | |
*** martinus__ has quit IRC | 11:51 | |
*** fhubik is now known as fhubik_brb | 11:57 | |
*** fhubik_brb is now known as fhubik | 12:00 | |
*** chlong has joined #openstack-keystone | 12:03 | |
*** _zouyee has quit IRC | 12:05 | |
*** iurygregory has joined #openstack-keystone | 12:08 | |
*** markvoelker has joined #openstack-keystone | 12:12 | |
*** markvoelker has quit IRC | 12:17 | |
*** gordc has joined #openstack-keystone | 12:24 | |
*** arif-ali has quit IRC | 12:27 | |
*** topol has joined #openstack-keystone | 12:28 | |
*** ChanServ sets mode: +v topol | 12:28 | |
*** doug-fish has joined #openstack-keystone | 12:31 | |
*** topol has quit IRC | 12:33 | |
*** nodir has joined #openstack-keystone | 12:34 | |
*** links has quit IRC | 12:34 | |
*** raildo-afk is now known as raildo | 12:36 | |
*** nodir has quit IRC | 12:38 | |
*** lhcheng has joined #openstack-keystone | 12:41 | |
*** ChanServ sets mode: +v lhcheng | 12:41 | |
openstackgerrit | zhangguoqing proposed openstack/keystoneauth: Change LOG.warn to LOG.warning https://review.openstack.org/263116 | 12:43 |
*** lhcheng has quit IRC | 12:45 | |
*** pauloewerton has joined #openstack-keystone | 12:47 | |
samueldmq | hey keystoners ! | 12:48 |
breton | o/ | 12:48 |
samueldmq | breton: hey, you a bot ? | 12:49 |
samueldmq | :) | 12:49 |
breton | :) | 12:49 |
breton | a little | 12:49 |
*** jistr has quit IRC | 12:50 | |
raildo | and we're all back! happy new keystone year :) | 12:51 |
*** _zouyee has joined #openstack-keystone | 12:53 | |
*** markvoelker has joined #openstack-keystone | 12:55 | |
*** arif-ali has joined #openstack-keystone | 12:55 | |
samueldmq | raildo: :) | 12:58 |
*** jistr has joined #openstack-keystone | 13:02 | |
*** dave-mccowan has joined #openstack-keystone | 13:08 | |
*** fhubik is now known as fhubik_brb | 13:11 | |
*** fhubik_brb is now known as fhubik | 13:14 | |
*** edmondsw has joined #openstack-keystone | 13:20 | |
*** chlong has quit IRC | 13:20 | |
*** daemontool has quit IRC | 13:33 | |
*** chlong has joined #openstack-keystone | 13:33 | |
*** daemontool has joined #openstack-keystone | 13:33 | |
*** daemontool has quit IRC | 13:33 | |
*** daemontool has joined #openstack-keystone | 13:34 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/python-keystoneclient: Implements base classes for functional tests https://review.openstack.org/253971 | 13:35 |
*** fhubik is now known as fhubik_brb | 13:37 | |
*** fhubik_brb is now known as fhubik | 13:38 | |
*** Nirupama has quit IRC | 13:44 | |
*** thiagop has joined #openstack-keystone | 13:49 | |
*** urulama has quit IRC | 13:50 | |
*** urulama has joined #openstack-keystone | 13:50 | |
*** links has joined #openstack-keystone | 13:56 | |
*** fawadkhaliq has joined #openstack-keystone | 13:59 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/python-keystoneclient: Implements base classes for functional tests https://review.openstack.org/253971 | 14:02 |
*** richm has joined #openstack-keystone | 14:06 | |
*** slberger has joined #openstack-keystone | 14:06 | |
*** links has quit IRC | 14:07 | |
*** nodir has joined #openstack-keystone | 14:17 | |
openstackgerrit | Paulo Ewerton Gomes Fragoso proposed openstack/python-keystoneclient: Handle EmptyCatalog exception in list federated projects https://review.openstack.org/243153 | 14:18 |
*** tjcocozz has joined #openstack-keystone | 14:18 | |
*** ayoung has joined #openstack-keystone | 14:23 | |
*** ChanServ sets mode: +v ayoung | 14:23 | |
openstackgerrit | Paulo Ewerton Gomes Fragoso proposed openstack/keystone: Manager support for project cascade update https://review.openstack.org/243584 | 14:23 |
*** breitz has joined #openstack-keystone | 14:30 | |
*** jistr has quit IRC | 14:30 | |
*** jistr has joined #openstack-keystone | 14:31 | |
mordred | jamielennox: doh | 14:33 |
*** nodir has quit IRC | 14:36 | |
openstackgerrit | Raildo Mascena proposed openstack/keystone: Deprecating API v2.0 https://review.openstack.org/251530 | 14:42 |
*** nodir has joined #openstack-keystone | 14:43 | |
*** fhubik is now known as fhubik_brb | 14:44 | |
*** urulama has quit IRC | 14:54 | |
*** urulama has joined #openstack-keystone | 14:54 | |
stevemar | morning all | 14:54 |
stevemar | holy hell is it cold outside | 14:55 |
* stevemar is glad he works remotely | 14:55 | |
*** csoukup has joined #openstack-keystone | 14:57 | |
*** belmoreira has quit IRC | 14:58 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 15:01 | |
*** _zouyee has quit IRC | 15:02 | |
*** jsavak has joined #openstack-keystone | 15:05 | |
*** jaosorior has joined #openstack-keystone | 15:07 | |
*** jaosorior has quit IRC | 15:08 | |
*** fhubik_brb is now known as fhubik | 15:15 | |
*** fhubik is now known as fhubik_brb | 15:15 | |
*** thiagop is now known as thiagop-lunch | 15:17 | |
*** fhubik_brb is now known as fhubik | 15:18 | |
odyssey4me | HNY to everyone | 15:20 |
* odyssey4me wonders how https://bugs.launchpad.net/keystone/+bug/1528981 happened... is there no Apache/wsgi/fernet token check in the gate? | 15:20 | |
openstack | Launchpad bug 1528981 in OpenStack Identity (keystone) "keystone fernet cannot work with mod wsgi anymore" [High,In progress] - Assigned to Dave Chen (wei-d-chen) | 15:20 |
bknudson_ | odyssey4me: there's no fernet gate test yet. there were issues in tempest for a while. | 15:23 |
*** timcline has joined #openstack-keystone | 15:23 | |
dolphm | bknudson_: the gate for opentack/openstack-ansible failed | 15:23 |
bknudson_ | can we get the ansible tests running in keystone? | 15:24 |
stevemar | dolphm: i didn't event know there was an openstack-ansible gate | 15:25 |
dolphm | bknudson_: it's basically a tempest run against an apache+fernet deploy of keystone | 15:25 |
odyssey4me | heh, we could probably do something like that - we're able to build out all sorts of things with it | 15:25 |
bknudson_ | eventually apache+fernet will be the default gate | 15:28 |
bknudson_ | I think ayoung has a change to make fernet the default | 15:28 |
*** petertr7 is now known as petertr7_away | 15:29 | |
ayoung | bknudson_, yeah,...didn't pass check yet, though | 15:29 |
*** fhubik is now known as fhubik_brb | 15:29 | |
bknudson_ | devstack probably needs to change to set up fernet | 15:29 |
bknudson_ | or maybe keystone could change so that it does the fernet setup if it's not setup alreayd? | 15:30 |
*** fhubik_brb is now known as fhubik | 15:30 | |
ayoung | https://review.openstack.org/#/c/258650/ bknudson_ odyssey4me | 15:30 |
lbragstad | bknudson_ ++ I think we could do that | 15:30 |
ayoung | odyssey4me, feel free to take it and run with it if you want. | 15:30 |
dolphm | bknudson_: that was sort of on my long-term wishlist | 15:30 |
*** nodir has quit IRC | 15:30 | |
lbragstad | I don't think that would be a terrible patch either | 15:31 |
dolphm | bknudson_: to have keystone attempt a fernet setup if it's configured to use fernet, and happens to have write permission on the fernet keys dir | 15:31 |
dolphm | (and it's not setup) | 15:31 |
*** nkinder has joined #openstack-keystone | 15:31 | |
ayoung | its still failing python27 | 15:31 |
ayoung | keystone.tests.unit.test_v3_federation.FederatedTokenTestsMethodToken.test_issue_unscoped_token_with_remote_no_attribute [0.678764s] ... FAILED | 15:32 |
dolphm | ayoung: yeah, it needs keystone-manage fernet-setup and whatnot | 15:32 |
ayoung | dolphm, do we need to do that for every test? Any way we can do a reusable setup for that? | 15:32 |
ayoung | I'd rather not regen keys for each token test.... | 15:32 |
dolphm | ayoung: there's a fixture already in place, and yes - you could add it to the base test class | 15:33 |
lbragstad | ayoung - https://github.com/openstack/keystone/blob/7b62b36960ad3615b9fe3b0c95330c3cf4eec67f/keystone/tests/unit/ksfixtures/key_repository.py | 15:33 |
*** jorge_munoz has joined #openstack-keystone | 15:33 | |
*** petertr7_away is now known as petertr7 | 15:34 | |
*** nodir has joined #openstack-keystone | 15:35 | |
*** fhubik is now known as fhubik_brb | 15:37 | |
*** ninag has joined #openstack-keystone | 15:38 | |
ayoung | lbragstad, that seems to be creating and cleaning up the temp dir each run. Am i reading that code wrong? | 15:39 |
*** fhubik_brb is now known as fhubik | 15:40 | |
lbragstad | ayoung you're right, but I believe that's the only fixture we have for the fernet key repository currently | 15:40 |
*** tonytan4ever has joined #openstack-keystone | 15:41 | |
openstackgerrit | Jorge Munoz proposed openstack/keystone: Reduce revoke events for disabled domains and projects. https://review.openstack.org/253273 | 15:41 |
openstackgerrit | Jorge Munoz proposed openstack/keystone: Reduce revoke events for disabled domains and projects. https://review.openstack.org/253273 | 15:42 |
*** topol has joined #openstack-keystone | 15:42 | |
*** ChanServ sets mode: +v topol | 15:42 | |
*** doug-fish has quit IRC | 15:45 | |
*** mtreinish has quit IRC | 15:46 | |
openstackgerrit | Jorge Munoz proposed openstack/keystone: Reduce revoke events for disabled domains and projects. https://review.openstack.org/253273 | 15:47 |
*** mtreinish has joined #openstack-keystone | 15:48 | |
*** doug-fish has joined #openstack-keystone | 15:51 | |
*** doug-fish has quit IRC | 15:56 | |
openstackgerrit | Harshada Mangesh Kakad proposed openstack/keystone: Fixing the deprecated library function. https://review.openstack.org/262731 | 15:58 |
*** jsavak has quit IRC | 16:02 | |
*** jsavak has joined #openstack-keystone | 16:04 | |
*** phalmos has joined #openstack-keystone | 16:08 | |
*** henrynash has joined #openstack-keystone | 16:09 | |
*** ChanServ sets mode: +v henrynash | 16:09 | |
*** urulama has quit IRC | 16:19 | |
*** urulama has joined #openstack-keystone | 16:20 | |
*** fhubik is now known as fhubik_brb | 16:25 | |
*** arunkant has joined #openstack-keystone | 16:25 | |
*** aix has quit IRC | 16:26 | |
*** fhubik_brb is now known as fhubik | 16:27 | |
*** thiagop-lunch is now known as thiagop | 16:32 | |
*** diazjf has joined #openstack-keystone | 16:32 | |
*** fhubik has quit IRC | 16:34 | |
*** jsavak has quit IRC | 16:34 | |
*** jsavak has joined #openstack-keystone | 16:35 | |
*** dmsimard has left #openstack-keystone | 16:37 | |
lbragstad | dstanek ping, I have a question on your comment here - https://review.openstack.org/#/c/254258/1 | 16:42 |
lbragstad | dstanek do you just want to see specific tests that test format that include a call to assertValidUnscopedTokenResponse ? | 16:44 |
*** jsavak has quit IRC | 16:45 | |
*** Ephur has quit IRC | 16:45 | |
*** jsavak has joined #openstack-keystone | 16:46 | |
lbragstad | maybe stevemar can answer that, too ^ | 16:48 |
*** e0ne has quit IRC | 16:48 | |
*** _cjones_ has joined #openstack-keystone | 16:49 | |
openstackgerrit | Swapnil Kulkarni (coolsvap) proposed openstack/keystone: Replace deprecated LOG.warn with warning https://review.openstack.org/263339 | 16:50 |
*** jsavak has quit IRC | 16:51 | |
*** david8hu has joined #openstack-keystone | 16:59 | |
*** nodir has quit IRC | 16:59 | |
*** jsavak has joined #openstack-keystone | 16:59 | |
*** diazjf has quit IRC | 17:06 | |
*** shaleh has joined #openstack-keystone | 17:07 | |
*** gyee has joined #openstack-keystone | 17:14 | |
*** ChanServ sets mode: +v gyee | 17:14 | |
*** jistr has quit IRC | 17:23 | |
*** henrynash has quit IRC | 17:26 | |
*** urulama has quit IRC | 17:32 | |
*** urulama has joined #openstack-keystone | 17:33 | |
*** nodir has joined #openstack-keystone | 17:35 | |
openstackgerrit | Swapnil Kulkarni (coolsvap) proposed openstack/keystone: Replace deprecated LOG.warn with warning https://review.openstack.org/263339 | 17:38 |
*** diazjf has joined #openstack-keystone | 17:40 | |
*** petertr7 is now known as petertr7_away | 17:41 | |
*** jsavak has quit IRC | 17:41 | |
*** henrynash has joined #openstack-keystone | 17:48 | |
*** ChanServ sets mode: +v henrynash | 17:48 | |
*** henrynash has quit IRC | 17:55 | |
*** timcline has quit IRC | 18:03 | |
*** mhickey has quit IRC | 18:04 | |
*** harlowja has quit IRC | 18:04 | |
*** harlowja has joined #openstack-keystone | 18:04 | |
*** thiagop has quit IRC | 18:07 | |
*** iurygregory has quit IRC | 18:07 | |
*** pauloewerton has quit IRC | 18:07 | |
*** jasonsb has quit IRC | 18:08 | |
openstackgerrit | Timothy Symanczyk proposed openstack/oslo.policy: Don't crash on RoleCheck when roles not present https://review.openstack.org/262329 | 18:09 |
*** thiagop has joined #openstack-keystone | 18:09 | |
*** doug-fish has joined #openstack-keystone | 18:10 | |
*** pauloewerton has joined #openstack-keystone | 18:10 | |
*** iurygregory has joined #openstack-keystone | 18:10 | |
*** vgridnev has joined #openstack-keystone | 18:11 | |
*** tonytan4ever has quit IRC | 18:11 | |
*** jsavak has joined #openstack-keystone | 18:13 | |
*** raildo is now known as raildo-afk | 18:20 | |
*** e0ne has joined #openstack-keystone | 18:23 | |
*** thiagop has quit IRC | 18:23 | |
*** thiagop has joined #openstack-keystone | 18:24 | |
*** fangxu has quit IRC | 18:24 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add checks for token data creep using jsonschema https://review.openstack.org/254258 | 18:30 |
*** openstackgerrit has quit IRC | 18:32 | |
*** openstackgerrit has joined #openstack-keystone | 18:32 | |
*** nodir has left #openstack-keystone | 18:32 | |
*** timcline has joined #openstack-keystone | 18:32 | |
*** tonytan4ever has joined #openstack-keystone | 18:33 | |
*** petertr7_away is now known as petertr7 | 18:36 | |
*** doug-fish has quit IRC | 18:38 | |
*** urulama has quit IRC | 18:39 | |
*** urulama has joined #openstack-keystone | 18:40 | |
*** doug-fish has joined #openstack-keystone | 18:41 | |
*** david-lyle_ has joined #openstack-keystone | 18:42 | |
*** lhcheng has joined #openstack-keystone | 18:42 | |
*** ChanServ sets mode: +v lhcheng | 18:42 | |
*** lhcheng_ has joined #openstack-keystone | 18:44 | |
openstackgerrit | Fernando Diaz proposed openstack/keystone: Opt-out certain Keystone Notifications https://review.openstack.org/253780 | 18:44 |
*** raildo-afk is now known as raildo | 18:46 | |
*** diazjf has quit IRC | 18:47 | |
*** lhcheng has quit IRC | 18:47 | |
*** jsavak has quit IRC | 18:49 | |
*** doug-fish has quit IRC | 18:49 | |
*** doug-fish has joined #openstack-keystone | 18:50 | |
*** doug-fish has quit IRC | 18:51 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Add is_domain parameter to get_project_by_name https://review.openstack.org/210600 | 18:53 |
*** boris-42 has quit IRC | 18:53 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add checks for domain scoped data creep https://review.openstack.org/253671 | 18:54 |
*** jsavak has joined #openstack-keystone | 18:55 | |
*** diazjf has joined #openstack-keystone | 18:56 | |
*** fangxu has joined #openstack-keystone | 18:56 | |
*** Ephur has joined #openstack-keystone | 19:00 | |
*** jsavak has quit IRC | 19:01 | |
*** jsavak has joined #openstack-keystone | 19:02 | |
*** fangxu_ has joined #openstack-keystone | 19:05 | |
*** fangxu has quit IRC | 19:06 | |
*** fangxu_ is now known as fangxu | 19:06 | |
*** dslevin has quit IRC | 19:06 | |
raildo | tjcocozz: are you around? | 19:08 |
tjcocozz | raildo, yes | 19:08 |
*** jsavak has quit IRC | 19:08 | |
raildo | tjcocozz: hey :) i'm trying to apply your comment: https://review.openstack.org/#/c/251530/9/keystone/common/controller.py | 19:08 |
tjcocozz | raildo, how is it going? | 19:09 |
stevemar | dstanek: can you look at the hacking failure here: https://review.openstack.org/#/c/263113/1 the author is trying to update LOG.warn -> LOG.warning, but it's failing for him | 19:09 |
raildo | but I'm getting an error "TypeError: Can't get class name." | 19:09 |
*** jsavak has joined #openstack-keystone | 19:09 | |
raildo | tjcocozz: I think that the reason is that a function that are calling this method and not a class | 19:10 |
tjcocozz | raildo, let me download your patch and try it | 19:10 |
raildo | tjcocozz: but i'm not sure | 19:10 |
raildo | tjcocozz: thanks! | 19:10 |
raildo | tjcocozz: when I printed the stdout: f will be '<function get_all_projects at 0x7fb938e9a398>' | 19:11 |
*** dslevin has joined #openstack-keystone | 19:12 | |
tjcocozz | raildo, that makes sense. I wonder if we need to use http://docs.openstack.org/developer/oslo.utils/api/reflection.html#oslo_utils.reflection.get_callable_name | 19:13 |
raildo | tjcocozz: makes sense for me | 19:14 |
raildo | tjcocozz: using get_callable_name it works :) | 19:19 |
raildo | tjcocozz: the difference is that it return the full name of the fuction, for example: 'keystone.resource.controllers.get_all_projects' instead of only 'get_all_projects' | 19:20 |
tjcocozz | raildo, running a test with a break point. debug is taking a while to run :( you may need to make sure keystone uses the correct version of the oslo.utils library? | 19:20 |
*** david-lyle_ has quit IRC | 19:20 | |
*** openstackstatus has quit IRC | 19:20 | |
tjcocozz | raildo, set fully_qualified=False in the signature | 19:21 |
tjcocozz | reflection.get_callable_name( | 19:21 |
tjcocozz | value, fully_qualified=False) | 19:21 |
*** openstackstatus has joined #openstack-keystone | 19:22 | |
*** ChanServ sets mode: +v openstackstatus | 19:22 | |
raildo | tjcocozz: I think that this method, doesn't have this option https://github.com/openstack/oslo.utils/blob/master/oslo_utils/reflection.py#L113 | 19:22 |
tjcocozz | raildo, looks like we won't use it... | 19:24 |
*** browne has joined #openstack-keystone | 19:25 | |
openstackgerrit | Timothy Symanczyk proposed openstack/oslo.policy: Don't crash on RoleCheck when roles not present https://review.openstack.org/262329 | 19:33 |
raildo | tjcocozz: what do you think in send a patch to add the fully_qualified option on this method on oslo, and later, we update this here? | 19:38 |
raildo | tjcocozz: and keep with the way that we are doing for now | 19:39 |
*** vijay__ has joined #openstack-keystone | 19:39 | |
tjcocozz | raildo, that may be the best option for now. | 19:39 |
tjcocozz | raildo, I don' | 19:41 |
*** fawadkhaliq has quit IRC | 19:41 | |
tjcocozz | t think that is the best idea anymore it looks like that method is used to get the full path https://github.com/openstack/oslo.utils/blob/master/oslo_utils/reflection.py#L116 | 19:41 |
*** fawadkhaliq has joined #openstack-keystone | 19:42 | |
raildo | tjcocozz: ok, so I'll keep with the full path :) | 19:42 |
raildo | tjcocozz: I'll send a patch with the change in a few minutes, thanks | 19:42 |
openstackgerrit | werner mendizabal proposed openstack/keystone-specs: Multifactor Authentication https://review.openstack.org/130376 | 19:43 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Reuse project scoped token check for trusts https://review.openstack.org/253672 | 19:45 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add checks for domain scoped data creep https://review.openstack.org/253671 | 19:45 |
tjcocozz | raildo, do you think using the full path is the correct thing to do, don't we just want the function name there? | 19:45 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add checks for project scoped data creep to tests https://review.openstack.org/253670 | 19:45 |
*** dims_ has joined #openstack-keystone | 19:46 | |
raildo | tjcocozz: I think that makes sense use the oslo method on it, maybe only the fuction name would be better, but the full path doesn't sounds wrong for me | 19:46 |
raildo | maybe a core opinion on it? stevemar, ayoung ^ | 19:46 |
stevemar | hmmm | 19:47 |
stevemar | ? | 19:47 |
stevemar | patch? | 19:47 |
*** dims has quit IRC | 19:47 | |
raildo | stevemar: https://review.openstack.org/#/c/251530/9/keystone/common/controller.py | 19:48 |
stevemar | raildo: tjcocozz can be done in a later patch i suppose | 19:49 |
tjcocozz | stevemar, thats what i was thinking since it looks like reflections doesn't have the exact method we are looking for. | 19:52 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Removes project.domain_id FK https://review.openstack.org/233274 | 19:53 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Change project name constraints https://review.openstack.org/158372 | 19:53 |
*** Ephur has quit IRC | 19:53 | |
stevemar | tjcocozz: yar | 19:53 |
raildo | stevemar: tjcocozz agreed | 19:53 |
stevemar | tjcocozz: looks like class name is only supported | 19:53 |
*** daemontool has quit IRC | 19:59 | |
*** maxabidi has joined #openstack-keystone | 20:00 | |
*** woodster_ has joined #openstack-keystone | 20:06 | |
openstackgerrit | Raildo Mascena proposed openstack/keystone: Deprecating API v2.0 https://review.openstack.org/251530 | 20:10 |
*** andrewbogott is now known as phys_on_andrews_ | 20:21 | |
*** aix has joined #openstack-keystone | 20:22 | |
*** phys_on_andrews_ is now known as andrewbogott | 20:23 | |
*** vijay__ has quit IRC | 20:27 | |
*** vgridnev has quit IRC | 20:30 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Tests for projects acting as domains https://review.openstack.org/211219 | 20:35 |
*** timcline has quit IRC | 20:38 | |
openstackgerrit | Tom Cocozzello proposed openstack/keystone: remove irrelevant parenthesis https://review.openstack.org/263415 | 20:38 |
*** pauloewerton has quit IRC | 20:38 | |
*** henrynash has joined #openstack-keystone | 20:44 | |
*** ChanServ sets mode: +v henrynash | 20:44 | |
*** fangxu has quit IRC | 20:46 | |
*** tonytan4ever has quit IRC | 20:48 | |
*** raildo is now known as raildo-afk | 20:51 | |
*** jsavak has quit IRC | 20:55 | |
*** jsavak has joined #openstack-keystone | 20:55 | |
*** PsionTheory has joined #openstack-keystone | 20:56 | |
*** doug-fish has joined #openstack-keystone | 20:56 | |
*** e0ne has quit IRC | 21:01 | |
*** tonytan4ever has joined #openstack-keystone | 21:04 | |
*** maxabidi has quit IRC | 21:04 | |
*** fangxu has joined #openstack-keystone | 21:04 | |
*** timcline has joined #openstack-keystone | 21:05 | |
openstackgerrit | henry-nash proposed openstack/keystone: Implement Implied Roles https://review.openstack.org/242614 | 21:15 |
*** petertr7 is now known as petertr7_away | 21:20 | |
openstackgerrit | henry-nash proposed openstack/keystone-specs: Clarify project hierarchy and parent usage within the API https://review.openstack.org/200624 | 21:20 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Expose method list inconsistency in federation api https://review.openstack.org/229125 | 21:21 |
openstackgerrit | henry-nash proposed openstack/keystone: Add tests for role management with v3policy file https://review.openstack.org/261846 | 21:27 |
openstackgerrit | henry-nash proposed openstack/keystone: Add CRUD support for domain specific roles https://review.openstack.org/261870 | 21:28 |
openstackgerrit | henry-nash proposed openstack/keystone: Modify rules in the v3 policy sample for domain specifc roles https://review.openstack.org/262078 | 21:28 |
openstackgerrit | henry-nash proposed openstack/keystone: Modify implied roles to honor domain specific roles https://review.openstack.org/263064 | 21:31 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Expose method list inconsistency in federation api https://review.openstack.org/229125 | 21:40 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Tests for projects acting as domains https://review.openstack.org/211219 | 21:57 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Removes project.domain_id FK https://review.openstack.org/233274 | 21:57 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Change project name constraints https://review.openstack.org/158372 | 21:57 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Add is_domain parameter to get_project_by_name https://review.openstack.org/210600 | 21:57 |
ayoung | henrynash, you are actively working on Implement Implied Roles right now? | 21:58 |
*** jsavak has quit IRC | 22:01 | |
anteaya | bknudson_: date +%V gives you the ISO week number | 22:08 |
bknudson_ | date -d"2016-01-01" "+%V" is 53 | 22:10 |
bknudson_ | weird | 22:10 |
bknudson_ | date -d"2015-01-01" "+%V" is 01 | 22:11 |
*** topol has quit IRC | 22:18 | |
*** ninag has quit IRC | 22:24 | |
*** Ephur has joined #openstack-keystone | 22:25 | |
*** timcline has quit IRC | 22:29 | |
openstackgerrit | Tom Cocozzello proposed openstack/keystone: List assignments with names https://review.openstack.org/249958 | 22:33 |
*** e0ne has joined #openstack-keystone | 22:34 | |
samueldmq | mordred: jamielennox: the patch for base classes for ksclient functional tests is now reviewable | 22:38 |
samueldmq | https://review.openstack.org/#/c/253971/ | 22:38 |
samueldmq | it uses os-client-config make_client call, which is now available in its latests release :D | 22:38 |
samueldmq | that implies the job is now passing jenkins | 22:38 |
samueldmq | s/the job/the change | 22:38 |
jamielennox | samueldmq: was actually just looking at that | 22:39 |
*** darrenc is now known as darrenc_afk | 22:39 | |
stevemar | henrynash: can you take a look at: https://review.openstack.org/#/c/263158/1 | 22:40 |
henrynash | stevemar: yes, was looking earlier…will do say later | 22:40 |
stevemar | henrynash: thanks boss | 22:43 |
*** slberger has left #openstack-keystone | 22:44 | |
samueldmq | jamielennox: nice :) | 22:44 |
samueldmq | jamielennox: I will put some focus on implementing the tests themselves from now | 22:45 |
jamielennox | samueldmq: reviewd - +1 only for a nit | 22:45 |
*** tonytan4ever has quit IRC | 22:46 | |
*** henrynash has quit IRC | 22:47 | |
samueldmq | jamielennox: looking now | 22:47 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Remove the default driver logic for resource and assignment https://review.openstack.org/263470 | 22:52 |
stevemar | bknudson_: i added this: https://review.openstack.org/#/c/263470/ but I am still stuck on a silly test error, not sure if you're able to help out | 22:52 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Remove the default driver logic for resource and assignment https://review.openstack.org/263470 | 22:53 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/python-keystoneclient: Implements base classes for functional tests https://review.openstack.org/253971 | 22:53 |
samueldmq | jamielennox: done ^ | 22:53 |
bknudson_ | stevemar: I can take a look. | 22:54 |
*** darrenc_afk is now known as darrenc | 22:54 | |
samueldmq | btw, happy new year keystoners :) | 22:54 |
bknudson_ | stevemar: btw - we probably should make sure that devstack sets all the drivers correctly. | 22:55 |
bknudson_ | I was looking at devstack today and I don't think it's setting the role backend. | 22:55 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Remove LDAP Resource and LDAP Assignment backends https://review.openstack.org/231872 | 22:56 |
stevemar | bknudson_: oh jeez | 22:56 |
samueldmq | bknudson_: very likely because that appeared in a new refactoring (last cycle?) | 22:56 |
stevemar | bknudson_: okay, i'll add that to the todo list | 22:56 |
*** woodster_ has quit IRC | 22:56 | |
* samueldmq thinks stevemar has todo lists, and todo list of todo lists | 22:58 | |
stevemar | samueldmq: all the todo lists | 22:58 |
stevemar | heading out for a bit | 22:59 |
*** diazjf has quit IRC | 22:59 | |
stevemar | see y'all later | 22:59 |
bknudson_ | just periscope it. | 22:59 |
samueldmq | stevemar: hehe enjoy | 23:00 |
*** Ephur has quit IRC | 23:00 | |
bknudson_ | https://review.openstack.org/#/c/263470/ fails unit tests because our test setup is a joke. | 23:02 |
*** phalmos has quit IRC | 23:05 | |
*** e0ne has quit IRC | 23:11 | |
*** edmondsw has quit IRC | 23:17 | |
openstackgerrit | ayoung proposed openstack/keystone: Implement Implied Roles https://review.openstack.org/242614 | 23:24 |
*** csoukup has quit IRC | 23:27 | |
openstackgerrit | Eric Brown proposed openstack/keystonemiddleware: Use oslo_config choices support https://review.openstack.org/160031 | 23:30 |
*** boris-42 has joined #openstack-keystone | 23:33 | |
openstackgerrit | Eric Brown proposed openstack/keystonemiddleware: Use oslo_config choices support https://review.openstack.org/160031 | 23:34 |
openstackgerrit | Eric Brown proposed openstack/keystonemiddleware: Use oslo_config choices support https://review.openstack.org/160031 | 23:37 |
*** sigmavirus24 is now known as sigmavirus24_awa | 23:46 | |
*** jrist has quit IRC | 23:50 | |
*** breitz has quit IRC | 23:55 | |
*** breitz has joined #openstack-keystone | 23:56 | |
*** shoutm has joined #openstack-keystone | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!