openstackgerrit | Brant Knudson proposed openstack/keystone: Remove the default driver logic for resource and assignment https://review.openstack.org/263470 | 00:03 |
---|---|---|
*** jrist has joined #openstack-keystone | 00:04 | |
*** gordc has quit IRC | 00:10 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Remove the default driver logic for resource and assignment https://review.openstack.org/263470 | 00:18 |
*** browne has quit IRC | 00:24 | |
*** thetrav has joined #openstack-keystone | 00:26 | |
*** jasonsb has joined #openstack-keystone | 00:28 | |
*** dims has joined #openstack-keystone | 00:33 | |
openstackgerrit | guang-yee proposed openstack/keystone: wsgi: fix base_url finding https://review.openstack.org/226464 | 00:34 |
*** dims_ has quit IRC | 00:34 | |
*** lhcheng_ has quit IRC | 00:35 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Remove the default driver logic for resource and assignment https://review.openstack.org/263470 | 00:43 |
*** spandhe has joined #openstack-keystone | 00:45 | |
*** richm has quit IRC | 00:59 | |
*** browne has joined #openstack-keystone | 01:08 | |
*** zqfan has joined #openstack-keystone | 01:09 | |
*** _zouyee has joined #openstack-keystone | 01:10 | |
*** fawadkhaliq has quit IRC | 01:18 | |
*** shaleh has quit IRC | 01:23 | |
*** _cjones_ has quit IRC | 01:24 | |
openstackgerrit | zhangguoqing proposed openstack/keystone: Change LOG.warn to LOG.warning https://review.openstack.org/263113 | 01:27 |
*** _zouyee has quit IRC | 01:30 | |
*** dave-mccowan has quit IRC | 01:48 | |
*** fawadkhaliq has joined #openstack-keystone | 02:00 | |
*** davechen has joined #openstack-keystone | 02:00 | |
*** diazjf has joined #openstack-keystone | 02:03 | |
*** _zouyee has joined #openstack-keystone | 02:22 | |
*** dims has quit IRC | 02:25 | |
davechen | stevemar: we need to make the decision - https://review.openstack.org/#/c/261205/ vs. https://review.openstack.org/#/c/262364/. | 02:25 |
davechen | stevemar: each one got a sponsor. :) | 02:26 |
*** henrynash has joined #openstack-keystone | 02:28 | |
*** ChanServ sets mode: +v henrynash | 02:28 | |
*** spandhe has quit IRC | 02:29 | |
*** dims has joined #openstack-keystone | 02:46 | |
*** Nirupama has joined #openstack-keystone | 03:02 | |
*** diazjf has quit IRC | 03:05 | |
*** diazjf has joined #openstack-keystone | 03:12 | |
*** diazjf has quit IRC | 03:13 | |
*** dims has quit IRC | 03:14 | |
*** topol has joined #openstack-keystone | 03:31 | |
*** ChanServ sets mode: +v topol | 03:31 | |
*** ccard__ has joined #openstack-keystone | 03:31 | |
*** ccard_ has quit IRC | 03:35 | |
*** topol has quit IRC | 03:35 | |
openstackgerrit | henry-nash proposed openstack/keystone: Modify rules for domain specific role assignments https://review.openstack.org/263549 | 03:39 |
stevemar | davechen: i'm in favor of pushing the fix through :) | 03:40 |
*** EinstCrazy has joined #openstack-keystone | 03:44 | |
*** david-lyle_ has joined #openstack-keystone | 03:49 | |
*** links has joined #openstack-keystone | 03:52 | |
davechen | stevemar: i'd like to see you to push it through. :-D | 03:55 |
openstackgerrit | Dave Chen proposed openstack/keystone: Add schema for federation protocol https://review.openstack.org/263161 | 03:55 |
*** browne1 has joined #openstack-keystone | 04:08 | |
*** browne has quit IRC | 04:10 | |
*** magesh has joined #openstack-keystone | 04:18 | |
*** fangxu has quit IRC | 04:23 | |
*** magesh has quit IRC | 04:29 | |
stevemar | bknudson_: i'm not clear on what you are asking about regarding deprecation here: https://review.openstack.org/#/c/263470/ | 04:48 |
stevemar | the method "default_resource_driver" and similar? | 04:48 |
*** fawadkhaliq has quit IRC | 04:54 | |
*** fawadkhaliq has joined #openstack-keystone | 04:55 | |
*** spandhe has joined #openstack-keystone | 05:01 | |
*** PsionTheory has quit IRC | 05:03 | |
*** spandhe_ has joined #openstack-keystone | 05:08 | |
*** david-lyle_ has quit IRC | 05:09 | |
*** spandhe has quit IRC | 05:10 | |
*** spandhe_ is now known as spandhe | 05:10 | |
openstackgerrit | Dave Chen proposed openstack/keystone: Remove redundant check after enforcing schema validation https://review.openstack.org/262768 | 05:13 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: WIP - remove ldap backends for assignment and resource https://review.openstack.org/263559 | 05:15 |
*** Nirupama has quit IRC | 05:16 | |
*** _cjones_ has joined #openstack-keystone | 05:26 | |
*** jaosorior has joined #openstack-keystone | 05:37 | |
openstackgerrit | Merged openstack/keystone: Test: make enforce_type=True in CONF.set_override https://review.openstack.org/263031 | 05:39 |
*** ChanServ changes topic to ""In Vino Veritas" | Mitaka 2 soon! (check schedule) - see blueprints and bugs at: https://launchpad.net/keystone/+milestone/mitaka-2" | 05:40 | |
notmorgan | stevemar: convince topol to get a bouncer | 05:44 |
*** gyee has quit IRC | 06:01 | |
*** jaosorior has quit IRC | 06:05 | |
*** jaosorior has joined #openstack-keystone | 06:26 | |
*** spandhe has quit IRC | 06:33 | |
*** fangxu has joined #openstack-keystone | 06:36 | |
*** spandhe has joined #openstack-keystone | 06:36 | |
*** Nirupama has joined #openstack-keystone | 06:37 | |
*** Magesh has joined #openstack-keystone | 06:42 | |
Magesh | Hi | 06:42 |
Magesh | During keystone configuration i am getting error | 06:43 |
Magesh | i runed below command | 06:43 |
Magesh | su -s /bin/sh -c "keystone-manage db_sync" keystone | 06:43 |
Magesh | getting below error | 06:44 |
Magesh | No handlers could be found for logger "oslo_config.cfg" | 06:44 |
*** shoutm has quit IRC | 06:45 | |
Magesh | please me | 06:46 |
openstackgerrit | henry-nash proposed openstack/keystone: Modify rules for domain specific role assignments https://review.openstack.org/263549 | 06:48 |
openstackgerrit | lei zhang proposed openstack/keystone: Define paste entrypoints https://review.openstack.org/263155 | 06:51 |
notmorgan | Magesh: that's a new one | 06:53 |
notmorgan | Magesh: what version of openstack (kilo? Liberty? master?) | 06:53 |
notmorgan | also the logger error should be a non-issue. | 06:53 |
notmorgan | but you should have more output | 06:53 |
Magesh | hi | 06:54 |
Magesh | Liberty | 06:54 |
notmorgan | ok | 06:54 |
notmorgan | hm. | 06:54 |
Magesh | this output only i am getting | 06:55 |
Magesh | No handlers could be found for logger "oslo_config.cfg" | 06:55 |
*** urulama has left #openstack-keystone | 06:55 | |
notmorgan | so if you run keystone-manage db_versioin | 06:55 |
notmorgan | what do you get? | 06:55 |
notmorgan | the logging error should be a non-issue | 06:55 |
notmorgan | and somethingyou vcould avoid | 06:55 |
notmorgan | s/avoid/ignore | 06:55 |
*** EinstCrazy has quit IRC | 06:56 | |
*** EinstCrazy has joined #openstack-keystone | 06:56 | |
*** EinstCrazy has quit IRC | 06:56 | |
*** thetrav has quit IRC | 06:56 | |
Magesh | [root@controller ~]# keystone-manage db_version No handlers could be found for logger "oslo_config.cfg" 75 | 06:56 |
notmorgan | that should be fine | 06:57 |
notmorgan | ignore the "no handlers bit" | 06:57 |
notmorgan | version 75 is fine | 06:57 |
notmorgan | i think | 06:57 |
* notmorgan 2xchecks liberty | 06:58 | |
notmorgan | Magesh: yeah that is a non-issue | 06:58 |
notmorgan | 75 is correct version for liberty | 06:58 |
notmorgan | the 'No handlers could be found for logger "oslo_config.cfg"' is erroneous | 06:59 |
Magesh | shall i proceed next steps | 06:59 |
notmorgan | yep | 06:59 |
notmorgan | you should be ok | 06:59 |
Magesh | Thank you | 07:00 |
notmorgan | np | 07:00 |
openstackgerrit | Yatin Kumbhare proposed openstack/python-keystoneclient: Fix for the deprecated library function https://review.openstack.org/263594 | 07:02 |
*** _cjones_ has quit IRC | 07:17 | |
*** oomichi has quit IRC | 07:24 | |
*** belmoreira has joined #openstack-keystone | 07:30 | |
*** e0ne has joined #openstack-keystone | 07:43 | |
*** martinus__ has joined #openstack-keystone | 07:47 | |
davechen | marekd: thanks you for the review! | 07:50 |
marekd | davechen: no problem. i am getting back to the business. | 07:51 |
marekd | starting from tomorrow :P | 07:51 |
davechen | marekd: great to hear that. | 07:52 |
davechen | marked: looks like it's a long vacation. :) | 07:53 |
*** browne1 has quit IRC | 08:18 | |
*** spandhe has quit IRC | 08:26 | |
*** fhubik has joined #openstack-keystone | 08:37 | |
*** tobe has joined #openstack-keystone | 08:41 | |
*** tobe has quit IRC | 08:41 | |
*** fhubik is now known as fhubik_brb | 08:44 | |
*** jsheeren has joined #openstack-keystone | 08:45 | |
*** lhcheng has joined #openstack-keystone | 08:48 | |
*** ChanServ sets mode: +v lhcheng | 08:48 | |
*** fawadkhaliq has quit IRC | 08:56 | |
*** yangyape_ has joined #openstack-keystone | 08:56 | |
*** fawadkhaliq has joined #openstack-keystone | 08:59 | |
*** Magesh has quit IRC | 09:04 | |
*** thiagop has quit IRC | 09:09 | |
*** iurygregory has quit IRC | 09:09 | |
*** fhubik_brb is now known as fhubik | 09:16 | |
openstackgerrit | zhangguoqing proposed openstack/keystone: Change LOG.warn to LOG.warning https://review.openstack.org/263113 | 09:17 |
*** jistr has joined #openstack-keystone | 09:21 | |
openstackgerrit | Ravi Shekhar Jethani proposed openstack/keystone: Do not use __builtin__ in python3 https://review.openstack.org/262773 | 09:31 |
*** fhubik is now known as fhubik_brb | 09:42 | |
*** jaosorior has quit IRC | 09:44 | |
*** jaosorior has joined #openstack-keystone | 09:44 | |
*** davechen has left #openstack-keystone | 09:47 | |
*** jaosorior has quit IRC | 09:56 | |
*** jaosorior has joined #openstack-keystone | 09:56 | |
*** fhubik_brb is now known as fhubik | 09:56 | |
openstackgerrit | Ankit Agrawal proposed openstack/keystone: Fix users in group and groups for user exact filters https://review.openstack.org/263158 | 09:56 |
*** mhickey has joined #openstack-keystone | 09:58 | |
*** lhcheng has quit IRC | 10:00 | |
*** yangyape_ has quit IRC | 10:02 | |
*** boris-42 has quit IRC | 10:03 | |
*** fhubik is now known as fhubik_brb | 10:31 | |
*** fhubik_brb is now known as fhubik | 10:44 | |
*** dims has joined #openstack-keystone | 10:47 | |
*** jsheeren has quit IRC | 10:58 | |
*** DeliangFan has joined #openstack-keystone | 11:12 | |
DeliangFan | Hi, I meet some questions about federation. Does a keystone service provider support both OpenID and SAML protocol? If it does, how should I configure the keystone and apache plugin? | 11:18 |
DeliangFan | Thank you very much! | 11:18 |
*** fhubik is now known as fhubik_brb | 11:22 | |
*** aix has quit IRC | 11:25 | |
openstackgerrit | Merged openstack/keystone: Fix the incompatible issue in response header https://review.openstack.org/261205 | 11:25 |
*** daemontool has joined #openstack-keystone | 11:35 | |
*** ericksonsantos has joined #openstack-keystone | 11:43 | |
*** bradjones has joined #openstack-keystone | 11:44 | |
*** bradjones has quit IRC | 11:44 | |
*** bradjones has joined #openstack-keystone | 11:44 | |
*** ccard has quit IRC | 12:11 | |
*** mhickey has quit IRC | 12:12 | |
*** mhickey has joined #openstack-keystone | 12:13 | |
*** fhubik_brb is now known as fhubik | 12:13 | |
*** mhickey has quit IRC | 12:15 | |
*** fawadkhaliq has quit IRC | 12:15 | |
*** mhickey has joined #openstack-keystone | 12:15 | |
*** fawadkhaliq has joined #openstack-keystone | 12:16 | |
*** pauloewerton has joined #openstack-keystone | 12:18 | |
*** iurygregory has joined #openstack-keystone | 12:19 | |
*** mhickey is now known as mhickey_ | 12:20 | |
*** fhubik has quit IRC | 12:21 | |
*** mhickey_ has quit IRC | 12:23 | |
*** mhickey has joined #openstack-keystone | 12:24 | |
*** belmoreira has quit IRC | 12:42 | |
*** raildo-afk is now known as raildo | 12:47 | |
*** fawadkhaliq has quit IRC | 12:47 | |
*** fawadkhaliq has joined #openstack-keystone | 12:48 | |
*** fangxu has quit IRC | 12:54 | |
*** fangxu has joined #openstack-keystone | 12:55 | |
*** links has quit IRC | 13:10 | |
*** gordc has joined #openstack-keystone | 13:12 | |
*** aix has joined #openstack-keystone | 13:14 | |
*** edmondsw has joined #openstack-keystone | 13:27 | |
*** topol has joined #openstack-keystone | 13:42 | |
*** ChanServ sets mode: +v topol | 13:42 | |
*** dslevin has quit IRC | 13:45 | |
openstackgerrit | Merged openstack/keystone: Add schema for identity provider https://review.openstack.org/262663 | 13:48 |
*** topol has quit IRC | 13:49 | |
*** iurygregory has quit IRC | 13:55 | |
openstackgerrit | Merged openstack/keystone: Add schema for federation protocol https://review.openstack.org/263161 | 13:55 |
*** DeliangFan has quit IRC | 13:57 | |
*** _zouyee has quit IRC | 13:58 | |
*** dslev has joined #openstack-keystone | 14:02 | |
*** fawadkhaliq has quit IRC | 14:04 | |
*** Nirupama has quit IRC | 14:08 | |
*** petertr7_away is now known as petertr7 | 14:13 | |
dolphm | dstanek: you will be happy to learn that the next version of gerrit (not what we have deployed) supports "commentby:self" to find reviews where you've previously commented | 14:15 |
lbragstad | dolphm do you happen to know what davechen is referencing here - in his comment about https://review.openstack.org/#/c/215212/14/keystone/contrib/endpoint_filter/core.py on https://review.openstack.org/#/c/215715/14 ? | 14:17 |
dolphm | lbragstad: yes... | 14:19 |
*** woodster_ has joined #openstack-keystone | 14:19 | |
*** ericksonsantos has quit IRC | 14:22 | |
dolphm | lbragstad: see ayoung's comment in 215212? "remove_endpoint_to_project" should have been "remove_endpoint_from_project". that mistake wasn't caught by automated testing, which is what he's saying he wants to add in 215715. he wants to avoid that same type of mistake again. | 14:23 |
dolphm | lbragstad: tl;dr i broke endpoint filtering when caching was enabled (the cache wasn't properly utilized) because i overrode the wrong method. davechen learned from my mistake :P | 14:24 |
*** links has joined #openstack-keystone | 14:24 | |
*** jsavak has joined #openstack-keystone | 14:25 | |
lbragstad | dolphm ah, ok | 14:27 |
lbragstad | looks like someone went in and fixed that | 14:27 |
dolphm | lbragstad: yes | 14:27 |
dolphm | lbragstad: might have been davechen? | 14:27 |
*** jsavak has quit IRC | 14:33 | |
*** iurygregory has joined #openstack-keystone | 14:33 | |
*** jsavak has joined #openstack-keystone | 14:34 | |
*** _zouyee has joined #openstack-keystone | 14:43 | |
bknudson_ | stevemar: we never deprecated using the default driver for the backends. | 14:46 |
*** links has quit IRC | 14:49 | |
openstackgerrit | Paulo Ewerton Gomes Fragoso proposed openstack/keystone: Add backend support for deleting a projects list https://review.openstack.org/245916 | 14:53 |
*** richm has joined #openstack-keystone | 14:54 | |
*** slberger has joined #openstack-keystone | 14:54 | |
*** jsavak has quit IRC | 15:00 | |
openstackgerrit | Dave Chen proposed openstack/keystone: Remove useless entrypoints https://review.openstack.org/263756 | 15:01 |
*** jsavak has joined #openstack-keystone | 15:01 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 15:02 | |
*** jsavak has quit IRC | 15:06 | |
*** slberger has left #openstack-keystone | 15:06 | |
*** fawadkhaliq has joined #openstack-keystone | 15:07 | |
*** slberger has joined #openstack-keystone | 15:08 | |
*** breitz has quit IRC | 15:12 | |
*** breitz has joined #openstack-keystone | 15:12 | |
*** timcline has joined #openstack-keystone | 15:19 | |
*** jsavak has joined #openstack-keystone | 15:23 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Revert "Test: make enforce_type=True in CONF.set_override" https://review.openstack.org/263767 | 15:23 |
*** breitz has quit IRC | 15:29 | |
*** topol has joined #openstack-keystone | 15:29 | |
*** ChanServ sets mode: +v topol | 15:29 | |
*** topol has quit IRC | 15:29 | |
*** breitz has joined #openstack-keystone | 15:30 | |
*** jsavak has quit IRC | 15:31 | |
*** jsavak has joined #openstack-keystone | 15:32 | |
*** dslev has quit IRC | 15:35 | |
*** ayoung has quit IRC | 15:41 | |
*** csoukup has joined #openstack-keystone | 15:49 | |
*** petertr7 is now known as petertr7_away | 15:51 | |
*** dslevin has joined #openstack-keystone | 15:54 | |
*** aix has quit IRC | 15:55 | |
*** petertr7_away is now known as petertr7 | 15:58 | |
*** dslevin has quit IRC | 16:06 | |
*** tonytan4ever has joined #openstack-keystone | 16:09 | |
*** topol has joined #openstack-keystone | 16:12 | |
*** ChanServ sets mode: +v topol | 16:12 | |
*** dave-mccowan has joined #openstack-keystone | 16:15 | |
*** _zouyee has quit IRC | 16:15 | |
*** dslev has joined #openstack-keystone | 16:17 | |
*** diazjf has joined #openstack-keystone | 16:21 | |
*** jbell8 has joined #openstack-keystone | 16:24 | |
*** zeus has quit IRC | 16:24 | |
*** PsionTheory has joined #openstack-keystone | 16:25 | |
openstackgerrit | werner mendizabal proposed openstack/keystone-specs: Multifactor Authentication https://review.openstack.org/130376 | 16:26 |
*** woodster_ has quit IRC | 16:26 | |
*** vgridnev has joined #openstack-keystone | 16:27 | |
*** zeus has joined #openstack-keystone | 16:29 | |
*** zeus is now known as Guest54332 | 16:30 | |
*** vgridnev_ has joined #openstack-keystone | 16:32 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add caching to role assignments https://review.openstack.org/215715 | 16:32 |
*** vgridnev has quit IRC | 16:32 | |
*** ayoung has joined #openstack-keystone | 16:35 | |
*** ChanServ sets mode: +v ayoung | 16:35 | |
*** phalmos has joined #openstack-keystone | 16:42 | |
openstackgerrit | Tom Cocozzello proposed openstack/keystone: List assignments with names https://review.openstack.org/249958 | 16:42 |
*** aix has joined #openstack-keystone | 16:43 | |
openstackgerrit | Yatin Kumbhare proposed openstack/python-keystoneclient: Fix for the deprecated library function https://review.openstack.org/263594 | 16:47 |
*** _cjones_ has joined #openstack-keystone | 16:53 | |
*** ericksonsantos has joined #openstack-keystone | 16:55 | |
*** diazjf has quit IRC | 16:56 | |
*** ninag has joined #openstack-keystone | 16:58 | |
*** browne has joined #openstack-keystone | 16:59 | |
*** diazjf has joined #openstack-keystone | 16:59 | |
*** Guest54332 is now known as zeus | 17:01 | |
*** zeus has quit IRC | 17:01 | |
*** zeus has joined #openstack-keystone | 17:01 | |
*** ayoung has quit IRC | 17:03 | |
*** rderose has joined #openstack-keystone | 17:06 | |
*** gyee has joined #openstack-keystone | 17:08 | |
*** ChanServ sets mode: +v gyee | 17:08 | |
*** mhickey has quit IRC | 17:10 | |
*** e0ne has quit IRC | 17:11 | |
*** jsavak has quit IRC | 17:11 | |
*** jsavak has joined #openstack-keystone | 17:12 | |
*** shaleh has joined #openstack-keystone | 17:17 | |
*** jistr has quit IRC | 17:19 | |
*** petertr7 is now known as petertr7_away | 17:23 | |
*** vgridnev_ has quit IRC | 17:24 | |
*** fawadkhaliq has quit IRC | 17:25 | |
*** spandhe has joined #openstack-keystone | 17:27 | |
*** dims has quit IRC | 17:29 | |
*** petertr7_away is now known as petertr7 | 17:29 | |
openstackgerrit | Yatin Kumbhare proposed openstack/python-keystoneclient: Fix for the deprecated library function https://review.openstack.org/263594 | 17:30 |
*** spandhe has quit IRC | 17:32 | |
*** haneef_ has quit IRC | 17:33 | |
*** lhcheng has joined #openstack-keystone | 17:33 | |
*** ChanServ sets mode: +v lhcheng | 17:33 | |
stevemar | bknudson_: why revert https://review.openstack.org/#/c/263767/ ? | 17:34 |
openstackgerrit | Tom Cocozzello proposed openstack/keystone: List assignments with names https://review.openstack.org/249958 | 17:36 |
*** dims has joined #openstack-keystone | 17:36 | |
bknudson_ | stevemar: why was it merged? the commit message says it's a test. | 17:37 |
*** aix has quit IRC | 17:38 | |
*** jaosorior has quit IRC | 17:44 | |
*** fawadkhaliq has joined #openstack-keystone | 17:44 | |
*** jaosorior has joined #openstack-keystone | 17:44 | |
*** haneef has joined #openstack-keystone | 17:44 | |
*** jaosorior has quit IRC | 17:45 | |
*** jaosorior has joined #openstack-keystone | 17:45 | |
samueldmq | yeah, finally finished my reservations for the midcycle o/ | 17:46 |
shaleh | samueldmq: it was a struggle for us yesterday. The booking system kept failing. | 17:47 |
stevemar | bknudson_: i think the author meant that the code only affects tests | 17:49 |
bknudson_ | stevemar: oh... weird way to word the commit message | 17:50 |
samueldmq | shaleh: about the same here, long time to book (7 hours ?) and bad UX to find good and cheap) flights | 17:50 |
samueldmq | shaleh: still worst from where I am (Brazil) at this point, lots of people travelling | 17:50 |
samueldmq | shaleh: but yeah, I got it :) | 17:51 |
shaleh | samueldmq: why is it a busy travel time? | 17:51 |
samueldmq | shaleh: school vacancies ? lots of people travelling to the US | 17:51 |
shaleh | samueldmq: ah. Classes are back in session then here in the States. | 17:52 |
*** phalmos has quit IRC | 17:53 | |
shaleh | samueldmq: for Guang and me the corp booking site would timeout and drrrraaagggg on forever. I ended up calling the agency when it half booked me for a flight + hotel. | 17:53 |
samueldmq | shaleh: yeah sometimes much easier | 17:54 |
samueldmq | shaleh: where are you based at the US ? | 17:54 |
shaleh | Silicon Valley, near San Francisco and Oakland. | 17:54 |
samueldmq | stevemar: weird you don't have any privileged mode in this channel | 17:55 |
*** ChanServ sets mode: +o stevemar | 17:56 | |
samueldmq | shaleh: cool, for me the worst part is that I will go to Sao Paulo (2k kilometers towards the south), then back (more 2k) to then go to US | 17:56 |
stevemar | samueldmq: there we go | 17:57 |
dstanek | Meeting today? | 17:57 |
samueldmq | stevemar: I was hesitating to talk to that stevemar :) | 17:58 |
shaleh | samueldmq: yeah, plane routing can be fun. My wife's home town does not have direct flights. You always end up taking a short hour or so flight after the longer cross country jump. | 17:58 |
stevemar | samueldmq: i wouldn't have trusted him either | 17:58 |
stevemar | dstanek: yep | 17:58 |
samueldmq | dstanek: good question :) and hey o/ | 17:58 |
samueldmq | stevemar: :-) | 17:58 |
dstanek | Technically today is my last vacation day, but i thought I'd join the meeting | 17:59 |
samueldmq | shaleh: hey I know that feeling :-) | 17:59 |
stevemar | courtesy ping for ajayaa, amakarov, ayoung, breton, browne, davechen, david8hu, dolphm, dstanek, ericksonsantos, geoffarnold, gyee, henrynash, hogepodge, htruta, jamielennox, joesavak, lbragstad, lhcheng, marekd, morganfainberg, nkinder, raildo, rodrigods, roxanaghe, samueldmq, shaleh, stevemar, tsymanczyk, topol, vivekd, wanghong, claudiub, rderose, samleon, xek, MaxPC, tjcocozz head on over to -meeting | 18:00 |
hogepodge | o/ | 18:00 |
*** lhcheng_ has joined #openstack-keystone | 18:03 | |
*** e0ne has joined #openstack-keystone | 18:05 | |
*** lhcheng has quit IRC | 18:06 | |
*** dprince has joined #openstack-keystone | 18:10 | |
*** fangxu has quit IRC | 18:10 | |
dprince | jamielennox: hi, quick question on keystone defaults. Should we set our auth_uri to /v3? or just go versionless? https://review.openstack.org/#/c/248500/ | 18:11 |
*** tonytan4ever has quit IRC | 18:11 | |
*** rderose has quit IRC | 18:15 | |
jamielennox | dprince: versionless should work, it'd really depend on where all those values are going in the puppet manifests (and i'm not sure) | 18:17 |
*** rderose has joined #openstack-keystone | 18:19 | |
dprince | jamielennox: mostly it gets used directly in the keystone_authtoken sections for the auth_uri settings | 18:19 |
dprince | jamielennox: will go with versionless then which should prefer v3 now right? | 18:20 |
jamielennox | dprince: the recommended at the moment is to set auth_type=password and use versionless | 18:20 |
jamielennox | i know the puppet team was working on that but i don't know how far they got | 18:21 |
dprince | jamielennox: cool, yeah we still have v2 hard coded in many places | 18:21 |
jamielennox | dprince: i'd love to remove that, there's nothing i know of that still won't work with v2 | 18:22 |
jamielennox | ah, still wont work with v3 | 18:22 |
*** tonytan4ever has joined #openstack-keystone | 18:24 | |
odyssey4me | jamielennox dprince if you're still using ceilometer/aodh, then v3 doesn't work all the way yet for Liberty and below... :( | 18:26 |
*** dslev has quit IRC | 18:26 | |
dprince | odyssey4me: okay, good to know | 18:27 |
jamielennox | odyssey4me: really? that's a shame, i didn't know ceilometer used keystone directly at all | 18:27 |
dprince | yeah, I think we have an issue w/ v3 in TripleO related to the Ironic inspector too. I need to look more closely at it as well | 18:27 |
odyssey4me | jamielennox https://review.openstack.org/237537 is in ceilometer master, so it'll be in Mitaka - but the team won't backport it to Liberty (I tried) | 18:28 |
odyssey4me | Aodh has https://review.openstack.org/250218 in review to get v3 API support | 18:29 |
jamielennox | i'll have a look at those | 18:31 |
*** timcline has quit IRC | 18:33 | |
odyssey4me | dprince if you're interested, we have full v3 configs for nova, cinder, glance, heat, horizon, neutron, swift set out in our liberty branch in the role templates: https://github.com/openstack/openstack-ansible/tree/liberty/playbooks/roles - feel free to use them as a reference :) | 18:33 |
*** spandhe has joined #openstack-keystone | 18:36 | |
*** dslev has joined #openstack-keystone | 18:36 | |
*** jsavak has quit IRC | 18:39 | |
*** fangxu has joined #openstack-keystone | 18:40 | |
*** fawadkhaliq has quit IRC | 18:40 | |
*** jaosorior has quit IRC | 18:43 | |
*** ayoung has joined #openstack-keystone | 18:47 | |
*** ChanServ sets mode: +v ayoung | 18:47 | |
openstackgerrit | Merged openstack/keystoneauth: Wrong usage of "a" https://review.openstack.org/262382 | 18:49 |
*** ninag has quit IRC | 18:56 | |
*** tonytan_brb has joined #openstack-keystone | 18:57 | |
*** ninag has joined #openstack-keystone | 18:57 | |
*** tonytan4ever has quit IRC | 18:59 | |
*** ninag_ has joined #openstack-keystone | 18:59 | |
stevemar | jamielennox: how is DOA-kerb broken? | 18:59 |
*** jsavak has joined #openstack-keystone | 19:00 | |
stevemar | we didn't remove ksc-kerb | 19:00 |
jamielennox | stevemar: i would need to double check, but if DOA-kerb is still using ksc plugins and DOA is using ksa it's wrong | 19:00 |
stevemar | ohhh | 19:00 |
stevemar | should DOA-kerb even exist any longer? | 19:01 |
jamielennox | from memory we don't use the setuptools entrypoints so it may still work for now | 19:01 |
stevemar | is it used out in the wild? | 19:01 |
*** ninag__ has joined #openstack-keystone | 19:01 | |
openstackgerrit | Paulo Ewerton Gomes Fragoso proposed openstack/python-keystoneclient: Handle EmptyCatalog exception in list federated projects https://review.openstack.org/243153 | 19:01 |
jamielennox | stevemar: if we can get DOA to do a similar extras thing as KSA then we can roll it in | 19:01 |
*** ninag has quit IRC | 19:01 | |
lhcheng_ | jamielennox: Latest DOA is now using ksa | 19:02 |
jamielennox | stevemar: red hat had intentions for it and it was being packaged | 19:02 |
jamielennox | stevemar: as for actual usage i'm not sure | 19:02 |
*** tonytan_brb has quit IRC | 19:02 | |
*** tonytan4ever has joined #openstack-keystone | 19:03 | |
gyee | notmorgan, I'll add some language in the spec to address secret key management | 19:04 |
*** ninag_ has quit IRC | 19:04 | |
stevemar | lhcheng_: jamielennox so how's it work for DOA to pull in the logic from DOA-kerb... | 19:04 |
gyee | rotation is part of it | 19:04 |
notmorgan | gyee: if this is just adding the totp auth method - this isn't MFA and i stand by that | 19:04 |
gyee | its really part of enterprise security workflow | 19:04 |
stevemar | lhcheng_: jamielennox how do you specify keystoneauth[kerberos] in the requirements file along with keystoneauth? | 19:05 |
gyee | notmorgan, you're right, the spec by itself is not MFA, its getting us there | 19:05 |
notmorgan | gyee: or look at working at the other bits. | 19:05 |
notmorgan | i will maintain a -1 at just adding totp | 19:05 |
stevemar | or just handle the imports if they fail | 19:05 |
notmorgan | because it's not really a benefit and adds a false sense of security | 19:05 |
gyee | totp even by itself is better than password | 19:06 |
notmorgan | gyee: only sortof | 19:06 |
notmorgan | not measurably really. | 19:06 |
samueldmq | ping | 19:07 |
samueldmq | oops | 19:07 |
gyee | up to you guys, I can only take it so far, if we don't want it, less work for me :) | 19:07 |
*** jsavak has quit IRC | 19:07 | |
*** jsavak has joined #openstack-keystone | 19:07 | |
jamielennox | stevemar: i would need to look again but i don't think you have to | 19:08 |
notmorgan | i am for MFA but the other parts of the MFA work would be where i'd put the effort in. | 19:08 |
jamielennox | stevemar: you had to have doa-kerberos installed, and then from DOA setup you specified the plugin in doa-kerberos to be used for auth | 19:09 |
jamielennox | stevemar: so doa-kerberos had a dep on doa and ksc-kerberos, but not the other way around | 19:09 |
jamielennox | if having ksa[kerberos] as a dependency in doa-kerberos is a problem then we need to fix something | 19:10 |
gyee | the other part require schema additions, which is kinda late for Mitaka, it would be for N | 19:10 |
gyee | stevemar, what say you, should I even bother to touch up that spec? | 19:11 |
gyee | dstanek, looks like the browns clean house | 19:14 |
*** ninag__ has quit IRC | 19:14 | |
*** ninag has joined #openstack-keystone | 19:15 | |
*** ninag has quit IRC | 19:15 | |
*** ninag has joined #openstack-keystone | 19:15 | |
*** thiagop has joined #openstack-keystone | 19:17 | |
dstanek | gyee: it was full of garbage anyway :-) | 19:18 |
gyee | dstanek, yeah, can't wait for the draft already | 19:19 |
ayoung | bknudson_, please review https://review.openstack.org/#/c/242614/ "Implement Implied Roles" | 19:20 |
bknudson_ | ayoung: I'll add it to my list | 19:20 |
ayoung | bknudson_, thanks. Ask me if there are any questions | 19:21 |
bknudson_ | I'm sure I'll have questions | 19:21 |
dstanek | gyee: yeah, i'm not feeling all that great yet. http://www.sbnation.com/lookit/2015/12/23/10661252/cleveland-browns-vs-barnyard-chickens | 19:22 |
gyee | hah, funny, but sad | 19:23 |
*** ninag has quit IRC | 19:26 | |
*** ninag has joined #openstack-keystone | 19:26 | |
*** ninag has quit IRC | 19:27 | |
*** ninag has joined #openstack-keystone | 19:28 | |
stevemar | gyee: i don't know if it's worth pursuing | 19:28 |
stevemar | our plate is pretty full | 19:28 |
*** timcline has joined #openstack-keystone | 19:34 | |
ayoung | MFA to me still means Museum if Fine Art . | 19:34 |
*** phalmos has joined #openstack-keystone | 19:36 | |
*** timcline has quit IRC | 19:38 | |
*** daemontool has quit IRC | 19:39 | |
gyee | ayoung FTW! | 19:40 |
*** daemontool has joined #openstack-keystone | 19:41 | |
notmorgan | ayoung: "if Fine Art"? | 19:41 |
ayoung | i and o are right next to each other on the keyboard | 19:41 |
*** dslev has quit IRC | 19:42 | |
gyee | the man has a rather large middle finger | 19:42 |
gyee | stevemar, notmorgan, alrighty then, lets kill that spec and start a new one on the framework changes for N then | 19:43 |
notmorgan | gyee: sounds good | 19:43 |
openstackgerrit | Ron De Rose proposed openstack/keystone: Shadow users: unified identity https://review.openstack.org/262045 | 19:45 |
*** daemontool has quit IRC | 19:47 | |
*** daemontool has joined #openstack-keystone | 19:48 | |
*** daemontool has quit IRC | 19:51 | |
*** ninag has quit IRC | 19:56 | |
*** ayoung has quit IRC | 19:59 | |
*** ninag has joined #openstack-keystone | 20:00 | |
*** ninag_ has joined #openstack-keystone | 20:01 | |
*** jbell8 has quit IRC | 20:01 | |
*** jsavak has quit IRC | 20:01 | |
*** jsavak has joined #openstack-keystone | 20:02 | |
*** ninag has quit IRC | 20:04 | |
*** ninag_ has quit IRC | 20:05 | |
*** timcline has joined #openstack-keystone | 20:06 | |
*** ayoung has joined #openstack-keystone | 20:10 | |
*** ChanServ sets mode: +v ayoung | 20:10 | |
*** jsavak has quit IRC | 20:11 | |
*** jsavak has joined #openstack-keystone | 20:11 | |
*** KarthikB has joined #openstack-keystone | 20:13 | |
*** jsavak has quit IRC | 20:17 | |
*** gyee has quit IRC | 20:25 | |
*** e0ne has quit IRC | 20:28 | |
*** rderose has quit IRC | 20:37 | |
*** phalmos has quit IRC | 20:40 | |
*** ninag has joined #openstack-keystone | 20:49 | |
*** jsavak has joined #openstack-keystone | 20:49 | |
*** fangxu has quit IRC | 20:53 | |
lbragstad | nonameentername looks like there was a bunch of discussion around MFA in the meeting today - http://eavesdrop.openstack.org/irclogs/%23openstack-meeting/%23openstack-meeting.2016-01-05.log.html#t2016-01-05T18:22:08 | 20:55 |
lbragstad | nonameentername incase you want to review it | 20:55 |
shaleh | nonameentername: essentially the MFA has been scuttled for Mitaka. gyee will work with you on preparing something for N that addresses the concerns raised. | 20:56 |
*** sripriya has joined #openstack-keystone | 20:59 | |
*** ayoung has quit IRC | 21:02 | |
*** pauloewerton has quit IRC | 21:14 | |
*** chlong has quit IRC | 21:22 | |
*** zzzeek has quit IRC | 21:22 | |
*** zzzeek has joined #openstack-keystone | 21:22 | |
*** phalmos has joined #openstack-keystone | 21:28 | |
*** spandhe is now known as spandhe_1 | 21:29 | |
*** petertr7 is now known as petertr7_away | 21:29 | |
bknudson_ | I'm not having much luck getting otp to work... I tried otpauth and the FreeOTP app but not getting the same code. | 21:29 |
*** gyee has joined #openstack-keystone | 21:30 | |
*** ChanServ sets mode: +v gyee | 21:30 | |
*** timcline has quit IRC | 21:30 | |
*** topol has quit IRC | 21:32 | |
*** gyee has quit IRC | 21:34 | |
*** gyee has joined #openstack-keystone | 21:41 | |
*** ChanServ sets mode: +v gyee | 21:41 | |
*** petertr7_away is now known as petertr7 | 21:50 | |
*** jorge_munoz has quit IRC | 21:53 | |
*** timcline has joined #openstack-keystone | 21:55 | |
*** ninag has quit IRC | 22:00 | |
*** ninag has joined #openstack-keystone | 22:01 | |
*** jsavak has quit IRC | 22:05 | |
*** ninag has quit IRC | 22:05 | |
*** jsavak has joined #openstack-keystone | 22:05 | |
*** harlowja has quit IRC | 22:09 | |
*** harlowja has joined #openstack-keystone | 22:10 | |
*** jorge_munoz has joined #openstack-keystone | 22:10 | |
*** thiagop has quit IRC | 22:11 | |
*** dslev has joined #openstack-keystone | 22:12 | |
openstackgerrit | Jorge Munoz proposed openstack/keystone: Reduce revoke events for disabled domains and projects. https://review.openstack.org/253273 | 22:16 |
*** dslev_ has joined #openstack-keystone | 22:17 | |
*** spandhe_1 has quit IRC | 22:19 | |
*** boris-42 has joined #openstack-keystone | 22:20 | |
*** dims has quit IRC | 22:20 | |
*** dslev has quit IRC | 22:20 | |
*** spandhe has joined #openstack-keystone | 22:22 | |
*** fangxu has joined #openstack-keystone | 22:22 | |
stevemar | tjcocozz: can i review the list w/ names stuff now? | 22:23 |
stevemar | is it no longer WIP WIP WIP | 22:23 |
*** dims has joined #openstack-keystone | 22:25 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: WIP: Add cache layer on the top of manager https://review.openstack.org/263933 | 22:31 |
samueldmq | dstanek: dolphm: this is a poc for introducing a separate cache layer for the sake of code clarity | 22:31 |
samueldmq | dstanek: dolphm: ^ pinging you both because I remember to have talked to you last year about it | 22:32 |
samueldmq | still wip but would be great to get some feedback on | 22:32 |
samueldmq | stevemar: cc ^ | 22:33 |
*** edmondsw has quit IRC | 22:33 | |
*** edmondsw has joined #openstack-keystone | 22:37 | |
*** dave-mccowan has quit IRC | 22:37 | |
*** petertr7 is now known as petertr7_away | 22:37 | |
*** edmondsw has quit IRC | 22:37 | |
*** dprince has quit IRC | 22:40 | |
*** timcline has quit IRC | 22:40 | |
*** KarthikB has quit IRC | 22:43 | |
notmorgan | samueldmq: that doesn't seem to mirror the functionality | 22:47 |
notmorgan | samueldmq: but... | 22:48 |
notmorgan | samueldmq: oh i see you made the resource_api = memoizer | 22:48 |
samueldmq | notmorgan: yes, it basically put the memoizer on the top of the api, and then we separate the business logic from caching things | 22:49 |
samueldmq | notmorgan: which makes the code cleaner (that's what I think, at least) | 22:49 |
notmorgan | samueldmq: sure. I would however not make the memoizer a required argument | 22:50 |
notmorgan | i would make it something you can apply to any manager | 22:50 |
notmorgan | and i would consider hacking .__getattribute__ in the manager to look at the memoizer first and call in that way instead | 22:50 |
samueldmq | notmorgan: hm, tried it, but got conflicts because it looks like __getattr__ isn't called if we implement __getattribute__ | 22:51 |
samueldmq | notmorgan: but sure that's an option too, and is doable | 22:51 |
notmorgan | you have to be very careful | 22:51 |
notmorgan | i don't particularly like adding in extra layers of abstraction tbh | 22:52 |
notmorgan | just because it makes it harder to see. | 22:53 |
notmorgan | but *shrug* i kindof avoid working on keystone server atm. | 22:53 |
samueldmq | notmorgan: I see, I am considering that option too (using __getatribute__, let's see what others think too) | 22:54 |
samueldmq | notmorgan: thanks for stepping in and giving feedback | 22:54 |
*** KarthikB has joined #openstack-keystone | 22:58 | |
*** daemontool has joined #openstack-keystone | 23:00 | |
*** zqfan has quit IRC | 23:01 | |
*** jsavak has quit IRC | 23:04 | |
*** woodster_ has joined #openstack-keystone | 23:07 | |
*** slberger has left #openstack-keystone | 23:07 | |
*** phalmos has quit IRC | 23:09 | |
*** csoukup has quit IRC | 23:12 | |
*** chlong has joined #openstack-keystone | 23:12 | |
*** diazjf has quit IRC | 23:12 | |
*** chlong has quit IRC | 23:14 | |
*** doug-fis_ has joined #openstack-keystone | 23:15 | |
*** doug-fish has quit IRC | 23:17 | |
*** dims has quit IRC | 23:20 | |
*** spandhe has quit IRC | 23:23 | |
*** dims has joined #openstack-keystone | 23:25 | |
*** doug-fis_ has quit IRC | 23:25 | |
*** KarthikB has quit IRC | 23:25 | |
*** chlong has joined #openstack-keystone | 23:30 | |
*** gordc has quit IRC | 23:33 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 23:35 | |
*** oomichi has joined #openstack-keystone | 23:37 | |
*** tonytan4ever has quit IRC | 23:39 | |
*** daemontool has quit IRC | 23:40 | |
openstackgerrit | henry-nash proposed openstack/keystone-specs: Clarify project hierarchy and parent usage within the API https://review.openstack.org/200624 | 23:41 |
*** dslev_ has quit IRC | 23:46 | |
*** ninag has joined #openstack-keystone | 23:47 | |
*** ninag has quit IRC | 23:47 | |
*** lhcheng_ has quit IRC | 23:50 | |
*** shoutm has joined #openstack-keystone | 23:56 | |
openstackgerrit | henry-nash proposed openstack/keystone-specs: Be consistent in how we give error codes in the Identity spec https://review.openstack.org/263960 | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!