| *** spandhe has joined #openstack-keystone | 00:04 | |
| *** tqtran has quit IRC | 00:06 | |
| *** edtubill has quit IRC | 00:09 | |
| *** serverascode has quit IRC | 00:17 | |
| *** andrewbogott has quit IRC | 00:17 | |
| *** DuncanT has quit IRC | 00:17 | |
| *** andreykurilin__ has quit IRC | 00:17 | |
| *** jed56 has quit IRC | 00:17 | |
| *** briancurtin has quit IRC | 00:17 | |
| *** sigmavirus24 has quit IRC | 00:17 | |
| *** nikhil has quit IRC | 00:18 | |
| *** andrewbogott has joined #openstack-keystone | 00:19 | |
| *** serverascode has joined #openstack-keystone | 00:19 | |
| *** DuncanT has joined #openstack-keystone | 00:19 | |
| *** jed56 has joined #openstack-keystone | 00:20 | |
| *** briancurtin has joined #openstack-keystone | 00:20 | |
| *** andreykurilin__ has joined #openstack-keystone | 00:21 | |
| *** nikhil has joined #openstack-keystone | 00:21 | |
| *** sigmavirus24 has joined #openstack-keystone | 00:28 | |
| *** slberger has left #openstack-keystone | 00:32 | |
| *** zigo has quit IRC | 00:37 | |
| *** ddieterly has joined #openstack-keystone | 00:51 | |
| *** zigo has joined #openstack-keystone | 01:03 | |
| *** ayoung has joined #openstack-keystone | 01:07 | |
| *** ChanServ sets mode: +v ayoung | 01:07 | |
| *** tonytan4ever has joined #openstack-keystone | 01:10 | |
| *** chlong has joined #openstack-keystone | 01:16 | |
| *** ddieterly is now known as ddieterly[away] | 01:24 | |
| *** ddieterly[away] is now known as ddieterly | 01:24 | |
| *** sdake has joined #openstack-keystone | 01:25 | |
| *** rk4n has quit IRC | 01:26 | |
| *** jorge_munoz has quit IRC | 01:26 | |
| *** edtubill has joined #openstack-keystone | 01:30 | |
| openstackgerrit | Ryosuke Mizuno proposed openstack/keystone: Add validation rules for create token using a JSON schema https://review.openstack.org/325086 | 01:35 |
|---|---|---|
| *** ddieterly has quit IRC | 01:50 | |
| *** iurygregory_ has quit IRC | 01:50 | |
| *** ddieterly has joined #openstack-keystone | 02:01 | |
| *** jamielennox has left #openstack-keystone | 02:02 | |
| *** jamielennox has joined #openstack-keystone | 02:02 | |
| *** ChanServ sets mode: +v jamielennox | 02:02 | |
| *** TxGVNN has joined #openstack-keystone | 02:02 | |
| openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Consolidate user agent calculation https://review.openstack.org/319717 | 02:02 |
| openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Create a Config object https://review.openstack.org/319715 | 02:02 |
| openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Make audit middleware use common config object https://review.openstack.org/328046 | 02:02 |
| jamielennox | gyee: for you ^ | 02:03 |
| *** lhcheng has quit IRC | 02:03 | |
| *** lhcheng has joined #openstack-keystone | 02:15 | |
| *** ChanServ sets mode: +v lhcheng | 02:15 | |
| *** ddieterly has quit IRC | 02:19 | |
| *** edtubill has quit IRC | 02:33 | |
| *** dave-mccowan has quit IRC | 02:34 | |
| *** sheel has joined #openstack-keystone | 02:46 | |
| *** richm has quit IRC | 02:52 | |
| *** TxGVNN has quit IRC | 02:53 | |
| *** tonytan4ever has quit IRC | 02:56 | |
| *** edtubill has joined #openstack-keystone | 02:58 | |
| *** neophy has joined #openstack-keystone | 03:13 | |
| *** markvoelker has quit IRC | 03:14 | |
| *** edtubill has quit IRC | 03:15 | |
| *** edtubill has joined #openstack-keystone | 03:15 | |
| *** lhcheng has quit IRC | 03:30 | |
| *** spandhe has quit IRC | 03:37 | |
| *** sdake has quit IRC | 03:41 | |
| *** pgbridge_ has joined #openstack-keystone | 03:48 | |
| *** jaosorior has joined #openstack-keystone | 03:48 | |
| *** pgbridge has quit IRC | 03:51 | |
| *** pgbridge has joined #openstack-keystone | 03:51 | |
| *** lhcheng has joined #openstack-keystone | 03:52 | |
| *** ChanServ sets mode: +v lhcheng | 03:52 | |
| *** pgbridge_ has quit IRC | 03:55 | |
| *** itisha has quit IRC | 04:00 | |
| *** links has joined #openstack-keystone | 04:00 | |
| stevemar | lbragstad: dolphm nice "OSIC Performance Bot" | 04:20 |
| stevemar | success: OSIC Performance Bot is up and running | 04:20 |
| stevemar | #success OSIC Performance Bot is up and running | 04:21 |
| openstackstatus | stevemar: Added success to Success page | 04:21 |
| *** rmizuno has joined #openstack-keystone | 04:28 | |
| *** edtubill has quit IRC | 04:33 | |
| *** edtubill has joined #openstack-keystone | 04:35 | |
| dstanek | yay, OSIC | 04:36 |
| openstackgerrit | Steve Martinelli proposed openstack/keystone: Fix TOTP transient test failure https://review.openstack.org/327922 | 04:40 |
| *** sdake has joined #openstack-keystone | 04:46 | |
| jamielennox | sigh, i broke my rule: don't look at audit middleware - lost pretty much the whole day | 04:56 |
| gyee | jamielennox, yeah, on it | 04:57 |
| *** spandhe has joined #openstack-keystone | 04:58 | |
| jamielennox | gyee: i have a couple of nice little cleanups - and i just can't break all the test assumptions | 04:58 |
| gyee | jamielennox, I will abandon my other patch so I can base mine on yours | 04:59 |
| jamielennox | gyee: yea, it becomes almost trivial at that point | 05:00 |
| gyee | yeah | 05:00 |
| stevemar | jamielennox: gyee i did the same thing earlier today, i waned to make oslo.messaging required... went down that rabbit hole alright | 05:02 |
| jamielennox | stevemar: oh, yea: i found that if you do that we'll change behaviour | 05:02 |
| jamielennox | stevemar: https://github.com/openstack/keystonemiddleware/blob/master/keystonemiddleware/audit.py#L426 | 05:03 |
| stevemar | oh? i just noticed the tests were all mangled... what i miss? | 05:03 |
| stevemar | yep | 05:03 |
| jamielennox | stevemar: so whether it emits a message or just logs it is dependant on if the library is installed | 05:03 |
| stevemar | i figured we could check if the driver was configured... and not as 'log' | 05:03 |
| stevemar | driver = CONF.audit_middleware.driver | 05:04 |
| stevemar | if driver and driver != 'log' | 05:04 |
| stevemar | just what i thought really quickly today | 05:04 |
| stevemar | may not work *shrugs* | 05:05 |
| jamielennox | it probably will | 05:05 |
| gyee | stevemar, problem is Swift wants everything to be *optional* | 05:05 |
| stevemar | gyee: swift doesn't use keystonemiddleware | 05:05 |
| jamielennox | i tried to refactor a bit and realize everything tests private methods | 05:06 |
| gyee | stevemar, our product have a requirement for auditing, so I am trying to make audit middleware work for Swift | 05:06 |
| stevemar | gyee: just dropping it in the pipeline? | 05:06 |
| jamielennox | gyee: the dependency will be on keystonemiddleware, not swift | 05:06 |
| gyee | problem is Swift only support one logger | 05:06 |
| gyee | stevemar, its not that simple | 05:06 |
| gyee | I do agree with having everything goes through oslo.messaging as it also support 'log' driver | 05:09 |
| gyee | right now I am unable to make Swift use the log driver | 05:09 |
| stevemar | gyee: so why does swift have to support oslo.messaging? you can install swift and keystonemiddleware, ksm pulls in whatever it needs, why do you care, as the deployer? | 05:13 |
| *** markvoelker has joined #openstack-keystone | 05:15 | |
| gyee | stevemar, right now oslo.messaging is optional for audit middleware, and we can't use the log driver even if its there | 05:15 |
| gyee | so its a package they don't need | 05:15 |
| gyee | but if we can make the log driver work then its a compelling argument | 05:17 |
| *** edtubill has quit IRC | 05:17 | |
| *** edtubill has joined #openstack-keystone | 05:18 | |
| openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Add a fixture method to add your own token data https://review.openstack.org/328076 | 05:18 |
| *** markvoelker has quit IRC | 05:20 | |
| *** GB21 has joined #openstack-keystone | 05:22 | |
| *** GB21 has quit IRC | 05:28 | |
| openstackgerrit | Merged openstack/python-keystoneclient: Add users functional tests https://review.openstack.org/289306 | 05:28 |
| *** jamielennox is now known as jamielennox|away | 05:29 | |
| notmorgan | dstanek: from our earlier convo: https://twitter.com/MdrnStm/status/741139876150673408 | 05:30 |
| notmorgan | oh stevemar is around. | 05:31 |
| gyee | notmorgan, first few months baby sleeps a lot so stevemar should have some free time :-) | 05:36 |
| *** gyee has quit IRC | 05:45 | |
| *** GB21 has joined #openstack-keystone | 05:47 | |
| *** GB21 has quit IRC | 05:55 | |
| *** GB21 has joined #openstack-keystone | 05:55 | |
| *** GB21 has quit IRC | 05:55 | |
| *** GB21 has joined #openstack-keystone | 05:56 | |
| *** lhcheng_ has joined #openstack-keystone | 06:02 | |
| *** chlong has quit IRC | 06:03 | |
| *** GB21 has quit IRC | 06:03 | |
| *** lhcheng has quit IRC | 06:04 | |
| *** yolanda has joined #openstack-keystone | 06:06 | |
| *** belmoreira has joined #openstack-keystone | 06:12 | |
| *** GB21 has joined #openstack-keystone | 06:14 | |
| *** TxGVNN has joined #openstack-keystone | 06:16 | |
| *** lunarlamp has joined #openstack-keystone | 06:17 | |
| *** chlong has joined #openstack-keystone | 06:20 | |
| *** TxGVNN has quit IRC | 06:23 | |
| *** openstackgerrit has quit IRC | 06:32 | |
| *** openstackgerrit has joined #openstack-keystone | 06:32 | |
| *** edtubill has quit IRC | 06:33 | |
| *** chlong has quit IRC | 06:35 | |
| *** pcaruana has joined #openstack-keystone | 06:40 | |
| *** GB21 has quit IRC | 06:48 | |
| *** links has quit IRC | 06:55 | |
| *** lhcheng has joined #openstack-keystone | 07:05 | |
| *** ChanServ sets mode: +v lhcheng | 07:05 | |
| *** lhcheng_ has quit IRC | 07:08 | |
| *** links has joined #openstack-keystone | 07:10 | |
| *** spandhe has quit IRC | 07:10 | |
| *** permalac has joined #openstack-keystone | 07:15 | |
| *** markvoelker has joined #openstack-keystone | 07:16 | |
| *** rcernin has joined #openstack-keystone | 07:17 | |
| *** markvoelker has quit IRC | 07:21 | |
| *** GB21 has joined #openstack-keystone | 07:24 | |
| *** sheel has quit IRC | 07:26 | |
| *** sheel has joined #openstack-keystone | 07:27 | |
| *** tesseract has joined #openstack-keystone | 07:27 | |
| *** agireud has quit IRC | 07:32 | |
| *** openstackgerrit has quit IRC | 07:33 | |
| *** openstackgerrit has joined #openstack-keystone | 07:33 | |
| *** agireud has joined #openstack-keystone | 07:34 | |
| *** jamielennox|away is now known as jamielennox | 07:36 | |
| *** GB21 has quit IRC | 07:46 | |
| *** rk4n has joined #openstack-keystone | 07:46 | |
| *** dancn has quit IRC | 07:53 | |
| *** dancn has joined #openstack-keystone | 07:55 | |
| openstackgerrit | OpenStack Proposal Bot proposed openstack/oslo.policy: Imported Translations from Zanata https://review.openstack.org/328142 | 07:55 |
| *** dancn has quit IRC | 07:55 | |
| *** zzzeek has quit IRC | 08:00 | |
| *** zzzeek has joined #openstack-keystone | 08:00 | |
| *** GB21 has joined #openstack-keystone | 08:07 | |
| openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c https://review.openstack.org/318435 | 08:10 |
| openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c https://review.openstack.org/318435 | 08:10 |
| *** markvoelker has joined #openstack-keystone | 08:17 | |
| openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Imported Translations from Zanata https://review.openstack.org/328160 | 08:20 |
| *** fhubik has joined #openstack-keystone | 08:21 | |
| *** markvoelker has quit IRC | 08:21 | |
| *** sdake has quit IRC | 08:21 | |
| *** pnavarro has joined #openstack-keystone | 08:23 | |
| *** lhcheng has quit IRC | 08:25 | |
| *** woodster_ has quit IRC | 08:28 | |
| *** nisha_ has joined #openstack-keystone | 08:29 | |
| *** jaosorior has quit IRC | 08:30 | |
| *** jaosorior has joined #openstack-keystone | 08:30 | |
| nisha_ | Good morning :) | 08:31 |
| *** nisha__ has joined #openstack-keystone | 08:40 | |
| *** nisha_ has quit IRC | 08:45 | |
| *** nisha__ has quit IRC | 08:45 | |
| *** nisha_ has joined #openstack-keystone | 08:48 | |
| *** nisha__ has joined #openstack-keystone | 08:48 | |
| *** nisha_ has quit IRC | 08:50 | |
| *** nisha__ is now known as nisha_ | 08:50 | |
| *** nisha__ has joined #openstack-keystone | 08:51 | |
| *** rk4n has quit IRC | 08:52 | |
| *** rk4n has joined #openstack-keystone | 08:53 | |
| *** nisha__ has quit IRC | 08:55 | |
| *** rk4n_ has joined #openstack-keystone | 08:56 | |
| *** rk4n_ has quit IRC | 08:57 | |
| *** rk4n has quit IRC | 08:57 | |
| *** daemontool has joined #openstack-keystone | 08:59 | |
| *** rk4n has joined #openstack-keystone | 09:03 | |
| *** henrynash_ has joined #openstack-keystone | 09:10 | |
| *** ChanServ sets mode: +v henrynash_ | 09:10 | |
| *** mvk has joined #openstack-keystone | 09:22 | |
| *** GB21 has quit IRC | 09:35 | |
| *** fhubik has quit IRC | 09:39 | |
| *** GB21 has joined #openstack-keystone | 09:52 | |
| *** henrynash_ has quit IRC | 10:02 | |
| *** rk4n has quit IRC | 10:10 | |
| *** danpawlik has joined #openstack-keystone | 10:11 | |
| *** lhcheng has joined #openstack-keystone | 10:14 | |
| *** ChanServ sets mode: +v lhcheng | 10:14 | |
| *** daemontool has quit IRC | 10:17 | |
| *** markvoelker has joined #openstack-keystone | 10:18 | |
| *** lhcheng has quit IRC | 10:19 | |
| *** rmizuno has quit IRC | 10:19 | |
| *** markvoelker has quit IRC | 10:22 | |
| *** danpawlik has left #openstack-keystone | 10:23 | |
| *** neophy has quit IRC | 10:23 | |
| *** danpawlik has joined #openstack-keystone | 10:23 | |
| danpawlik | hi, is somebody there? | 10:24 |
| *** daemontool has joined #openstack-keystone | 10:38 | |
| *** nisha__ has joined #openstack-keystone | 10:48 | |
| *** nisha_ has quit IRC | 10:51 | |
| *** rk4n has joined #openstack-keystone | 10:53 | |
| *** ddieterly has joined #openstack-keystone | 11:05 | |
| *** TxGVNN has joined #openstack-keystone | 11:07 | |
| *** GB21 has quit IRC | 11:07 | |
| *** dmk0202 has joined #openstack-keystone | 11:10 | |
| *** GB21 has joined #openstack-keystone | 11:22 | |
| *** dmk0202 has quit IRC | 11:23 | |
| *** daemontool has quit IRC | 11:28 | |
| *** daemontool has joined #openstack-keystone | 11:28 | |
| *** GB21 has quit IRC | 11:35 | |
| *** dmk0202 has joined #openstack-keystone | 11:36 | |
| *** vnogin has quit IRC | 11:43 | |
| *** rk4n has joined #openstack-keystone | 11:45 | |
| *** ddieterly has quit IRC | 11:47 | |
| *** pcaruana has quit IRC | 11:51 | |
| *** rk4n has quit IRC | 11:52 | |
| *** rk4n has joined #openstack-keystone | 11:54 | |
| *** rodrigods has quit IRC | 11:55 | |
| *** rodrigods has joined #openstack-keystone | 11:56 | |
| *** danpawlik has quit IRC | 11:56 | |
| *** danpawlik has joined #openstack-keystone | 11:56 | |
| *** pcaruana has joined #openstack-keystone | 12:07 | |
| *** pcaruana has quit IRC | 12:13 | |
| *** pcaruana has joined #openstack-keystone | 12:13 | |
| *** ayoung has quit IRC | 12:15 | |
| *** markvoelker has joined #openstack-keystone | 12:18 | |
| *** ddieterly has joined #openstack-keystone | 12:20 | |
| *** afred312 has quit IRC | 12:23 | |
| *** dmk0202 has quit IRC | 12:25 | |
| *** EinstCrazy has joined #openstack-keystone | 12:25 | |
| *** lhcheng has joined #openstack-keystone | 12:27 | |
| *** ChanServ sets mode: +v lhcheng | 12:27 | |
| *** ddieterly has quit IRC | 12:27 | |
| *** lhcheng has quit IRC | 12:32 | |
| *** gordc has joined #openstack-keystone | 12:37 | |
| *** ddieterly has joined #openstack-keystone | 12:37 | |
| *** dmk0202 has joined #openstack-keystone | 12:39 | |
| *** ddieterly is now known as ddieterly[away] | 12:41 | |
| *** nisha__ has quit IRC | 12:47 | |
| *** nisha__ has joined #openstack-keystone | 12:48 | |
| *** EinstCrazy has quit IRC | 12:54 | |
| *** links has quit IRC | 12:54 | |
| *** dmk0202 has quit IRC | 12:58 | |
| *** dmk0202 has joined #openstack-keystone | 12:59 | |
| *** BjoernT has joined #openstack-keystone | 13:00 | |
| *** pauloewerton has joined #openstack-keystone | 13:00 | |
| *** EinstCrazy has joined #openstack-keystone | 13:02 | |
| *** rodrigods has quit IRC | 13:05 | |
| *** rodrigods has joined #openstack-keystone | 13:05 | |
| *** EinstCrazy has quit IRC | 13:06 | |
| *** jaosorior has quit IRC | 13:07 | |
| *** edmondsw has joined #openstack-keystone | 13:08 | |
| *** richm has joined #openstack-keystone | 13:10 | |
| *** EinstCrazy has joined #openstack-keystone | 13:10 | |
| *** EinstCrazy has quit IRC | 13:16 | |
| *** EinstCrazy has joined #openstack-keystone | 13:16 | |
| *** ayoung has joined #openstack-keystone | 13:16 | |
| *** ChanServ sets mode: +v ayoung | 13:16 | |
| *** jistr is now known as jistr|mtg | 13:20 | |
| *** pcaruana has quit IRC | 13:20 | |
| *** henrynash_ has joined #openstack-keystone | 13:22 | |
| *** ChanServ sets mode: +v henrynash_ | 13:22 | |
| *** EinstCrazy has quit IRC | 13:25 | |
| *** sheel has quit IRC | 13:25 | |
| *** dmk0202 has quit IRC | 13:29 | |
| knikolla | hi o/ | 13:31 |
| *** gagehugo has joined #openstack-keystone | 13:33 | |
| *** TxGVNN has quit IRC | 13:33 | |
| *** dave-mccowan has joined #openstack-keystone | 13:33 | |
| *** links has joined #openstack-keystone | 13:36 | |
| *** andrewbogott has quit IRC | 13:38 | |
| *** andrewbogott has joined #openstack-keystone | 13:38 | |
| *** pcaruana has joined #openstack-keystone | 13:39 | |
| *** henrynash_ has quit IRC | 13:41 | |
| *** rderose has joined #openstack-keystone | 13:44 | |
| *** afred312 has joined #openstack-keystone | 13:47 | |
| *** darosale has joined #openstack-keystone | 13:55 | |
| *** nisha__ has quit IRC | 14:00 | |
| *** ametts has joined #openstack-keystone | 14:00 | |
| *** amakarov_away is now known as amakarov | 14:01 | |
| *** links has quit IRC | 14:01 | |
| *** rderose_ has joined #openstack-keystone | 14:07 | |
| *** jistr|mtg is now known as jistr | 14:09 | |
| *** rderose has quit IRC | 14:10 | |
| *** fesp has joined #openstack-keystone | 14:24 | |
| *** tonytan4ever has joined #openstack-keystone | 14:27 | |
| *** fesp has quit IRC | 14:27 | |
| *** fesp has joined #openstack-keystone | 14:30 | |
| *** fesp has quit IRC | 14:32 | |
| *** fesp has joined #openstack-keystone | 14:32 | |
| *** jorge_munoz has joined #openstack-keystone | 14:33 | |
| openstackgerrit | Merged openstack/keystone: Fix TOTP transient test failure https://review.openstack.org/327922 | 14:39 |
| *** amrith has quit IRC | 14:41 | |
| *** raddaoui has joined #openstack-keystone | 14:42 | |
| *** amrith has joined #openstack-keystone | 14:42 | |
| *** timcline has joined #openstack-keystone | 14:45 | |
| *** timcline has quit IRC | 14:45 | |
| dolphm | stevemar: tested that TOTP patch 9000 times over night -- it definitely fixed the issue :) | 14:45 |
| patchbot | dolphm: https://review.openstack.org/#/c/9000/ - keystone - Do not crash when trying to remove a user role (wi... (MERGED) | 14:45 |
| *** timcline has joined #openstack-keystone | 14:46 | |
| stevemar | dolphm: nice | 14:46 |
| dolphm | thanks, patchbot | 14:46 |
| stevemar | haha, thats awesome | 14:46 |
| dolphm | patch 1 | 14:46 |
| patchbot | dolphm: https://review.openstack.org/#/c/1/ - openstack-infra/system-config - Add puppet module for ssh that installs an sshd_co... (MERGED) | 14:46 |
| dolphm | patch 2 | 14:46 |
| patchbot | dolphm: https://review.openstack.org/#/c/2/ | 14:46 |
| stevemar | patch 9000 was a keystone patch | 14:46 |
| patchbot | stevemar: https://review.openstack.org/#/c/9000/ - keystone - Do not crash when trying to remove a user role (wi... (MERGED) | 14:46 |
| dolphm | patch 3 | 14:46 |
| patchbot | dolphm: https://review.openstack.org/#/c/3/ | 14:46 |
| dolphm | so helpful | 14:46 |
| dolphm | patch 4 | 14:46 |
| patchbot | dolphm: https://review.openstack.org/#/c/4/ - openstack-infra/system-config - Add gerrit dev/prod servers to jenkins slave known... (MERGED) | 14:46 |
| notmyname | the https://review.openstack.org/#/c/9000/ pattern works too | 14:46 |
| dolphm | patch 5 | 14:47 |
| patchbot | notmyname: patch 9000 - keystone - Do not crash when trying to remove a user role (wi... (MERGED) | 14:47 |
| patchbot | dolphm: https://review.openstack.org/#/c/5/ - openstack-infra/system-config - Fix problem with jenkins known_hosts url. (MERGED) | 14:47 |
| notmyname | notmorgan had asked for patchbot to lurk here | 14:47 |
| notmyname | it's my bot if you have questions/issues with it | 14:47 |
| stevemar | notmyname: oh it's fine :) | 14:47 |
| stevemar | wacky friday fun | 14:47 |
| notmyname | FWIW https://github.com/notmyname/Patches | 14:48 |
| dolphm | notmyname: i definitely find it useful - keeps me from clicking every code review link in irc | 14:48 |
| notmyname | yeah. that was the frustration that made me write it :-) | 14:49 |
| *** flaper87 has quit IRC | 14:52 | |
| *** fesp is now known as flaper87 | 14:52 | |
| *** flaper87 has quit IRC | 14:52 | |
| *** flaper87 has joined #openstack-keystone | 14:52 | |
| *** flaper87 has quit IRC | 14:55 | |
| *** flaper87 has joined #openstack-keystone | 14:55 | |
| *** daemontool has quit IRC | 14:57 | |
| notmorgan | notmyname: ++ | 15:00 |
| notmorgan | notmyname: i think i want to issue a PR for it so it has a delay in saying the same patch again | 15:01 |
| notmorgan | patch 1 | 15:01 |
| patchbot | notmorgan: https://review.openstack.org/#/c/1/ - openstack-infra/system-config - Add puppet module for ssh that installs an sshd_co... (MERGED) | 15:01 |
| notmorgan | patch 1 | 15:01 |
| patchbot | notmorgan: https://review.openstack.org/#/c/1/ - openstack-infra/system-config - Add puppet module for ssh that installs an sshd_co... (MERGED) | 15:01 |
| notmorgan | patch 1 | 15:01 |
| patchbot | notmorgan: https://review.openstack.org/#/c/1/ - openstack-infra/system-config - Add puppet module for ssh that installs an sshd_co... (MERGED) | 15:01 |
| notmorgan | notmyname: like 10 or 30s | 15:01 |
| notmyname | sure. go for it. patches welcome :-) | 15:01 |
| openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password table changes https://review.openstack.org/314284 | 15:02 |
| notmorgan | notmyname: :) | 15:02 |
| notmorgan | notmyname: just realize it's going to consume a chunk more memory that way, so as long as you're ok with that | 15:02 |
| notmorgan | notmyname: since it needs something like an ordereddict of patches it's said in the last XXX window | 15:03 |
| *** spandhe has joined #openstack-keystone | 15:04 | |
| bknudson | make it so that we can update commit messages by posting commands to irc. | 15:05 |
| notmorgan | bknudson: you should totally write that bot | 15:05 |
| bknudson | and cherry-pick changes | 15:06 |
| *** spandhe_ has joined #openstack-keystone | 15:07 | |
| *** spandhe has quit IRC | 15:09 | |
| *** spandhe_ is now known as spandhe | 15:09 | |
| *** tesseract has quit IRC | 15:09 | |
| *** pcaruana has quit IRC | 15:13 | |
| openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password history requirements https://review.openstack.org/328339 | 15:13 |
| openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password history requirements https://review.openstack.org/328339 | 15:13 |
| *** rcernin has quit IRC | 15:19 | |
| *** EinstCrazy has joined #openstack-keystone | 15:21 | |
| *** flaper87 has quit IRC | 15:27 | |
| dstanek | well i give up on lxd for today. back to real work | 15:27 |
| *** pushkaru has joined #openstack-keystone | 15:30 | |
| openstackgerrit | Merged openstack/keystone: Change LocalUser sql model to eager loading https://review.openstack.org/327817 | 15:34 |
| *** pnavarro has quit IRC | 15:34 | |
| bknudson | dstanek: "The Legion of Extraordinary Dancers" ? | 15:34 |
| dstanek | bknudson: that would have been more productive i think | 15:35 |
| *** belmoreira has quit IRC | 15:41 | |
| *** EinstCrazy has quit IRC | 15:44 | |
| *** EinstCrazy has joined #openstack-keystone | 15:44 | |
| *** KevinE_ has joined #openstack-keystone | 15:45 | |
| *** rk4n has quit IRC | 15:49 | |
| *** EinstCrazy has quit IRC | 15:51 | |
| *** EinstCrazy has joined #openstack-keystone | 15:52 | |
| *** ametts has quit IRC | 15:55 | |
| openstackgerrit | Matthew Edmonds proposed openstack/keystone: exception sensitive cache/audit changes https://review.openstack.org/273218 | 15:57 |
| openstackgerrit | Dolph Mathews proposed openstack/keystoneauth: Make the kerberos plugin loadable https://review.openstack.org/321814 | 15:59 |
| *** roxanaghe has joined #openstack-keystone | 15:59 | |
| dstanek | notmorgan: where you still going to work on https://bugs.launchpad.net/keystone/+bug/1572341 ? | 16:02 |
| openstack | Launchpad bug 1572341 in OpenStack Identity (keystone) "Failed migration 90 -> 91 Can't DROP 'ixu_user_name_domain_id'" [High,Triaged] | 16:02 |
| *** ametts has joined #openstack-keystone | 16:08 | |
| *** EinstCrazy has quit IRC | 16:11 | |
| notmorgan | dstanek: i keep meaning to | 16:11 |
| notmorgan | dstanek: its unfortunately a really unfun migration to fix :( | 16:12 |
| openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password table changes https://review.openstack.org/314284 | 16:17 |
| *** afred312 has quit IRC | 16:18 | |
| openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 16:19 |
| openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 16:23 |
| openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password history requirements https://review.openstack.org/328339 | 16:25 |
| openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password strength requirements https://review.openstack.org/320586 | 16:29 |
| *** ayoung has quit IRC | 16:33 | |
| *** rderose_ has quit IRC | 16:37 | |
| *** spandhe has quit IRC | 16:44 | |
| openstackgerrit | Thomas Goirand proposed openstack/keystone: Add missing testresources build-requirement https://review.openstack.org/328383 | 16:45 |
| *** rderose has joined #openstack-keystone | 16:46 | |
| *** rk4n has joined #openstack-keystone | 16:49 | |
| *** sdake has joined #openstack-keystone | 16:50 | |
| breton | zigo: https://bugs.launchpad.net/keystone/+bug/1572202 this looks like a duplicate of your bug | 16:56 |
| openstack | Launchpad bug 1572202 in OpenStack Identity (keystone) "testresources needs to be explicitly required for tests" [Medium,In progress] - Assigned to David Stanek (dstanek) | 16:56 |
| zigo | Indeed. | 16:56 |
| zigo | That's in fact indirectly needed by oslo.db | 16:57 |
| zigo | I was tempted to add a runtime depends on testresources for oslo.db, but I'm not sure if that's really what I should do. | 16:57 |
| breton | you've seen https://review.openstack.org/#/c/307878/, right? | 16:57 |
| patchbot | breton: patch 307878 - keystone - Explicitly require testresources for tests (ABANDONED) | 16:57 |
| dstanek | breton: zigo: i should probably mark that bug as closed | 16:59 |
| zigo | Right. | 16:59 |
| rodrigods | dstanek, ping... do you have a Mitaka (or more recent) federation setup ready? | 16:59 |
| dstanek | rodrigods: define ready? | 17:00 |
| rodrigods | dstanek, somehow working heh | 17:00 |
| *** rderose_ has joined #openstack-keystone | 17:01 | |
| breton | rodrigods: i have. Need anything to test? | 17:02 |
| rodrigods | breton, yeah, think I've found a bug here, but shadow users should have fixed it (i'm using liberty) | 17:02 |
| dstanek | rodrigods: i have a node that works against testshib | 17:03 |
| rodrigods | dstanek, breton in a meeting, back in a hour or so to explain the issue :) | 17:04 |
| dstanek | zigo: breton: what's the other bug? | 17:04 |
| *** rderose has quit IRC | 17:05 | |
| breton | dstanek: https://bugs.launchpad.net/bugs/1591281 | 17:06 |
| openstack | Launchpad bug 1591281 in OpenStack Identity (keystone) "Missing test-requirement: testresources" [Undecided,In progress] - Assigned to Thomas Goirand (thomas-goirand) | 17:06 |
| *** ebalduf_ has joined #openstack-keystone | 17:06 | |
| *** rderose_ has quit IRC | 17:08 | |
| dstanek | breton: does updating tox fix the issue? | 17:09 |
| *** ayoung has joined #openstack-keystone | 17:14 | |
| *** ChanServ sets mode: +v ayoung | 17:14 | |
| breton | dstanek: i don't know. Please ask zigo. I just saw that it's a duplicate. | 17:16 |
| *** Guest5 has joined #openstack-keystone | 17:17 | |
| *** dan_nguyen has joined #openstack-keystone | 17:19 | |
| dstanek | zigo: ^? | 17:19 |
| zigo | #1591281 | 17:21 |
| zigo | That's my bug. | 17:21 |
| zigo | #1572202 the other one | 17:22 |
| *** ebalduf_ has quit IRC | 17:22 | |
| *** sdake has quit IRC | 17:22 | |
| dstanek | zigo: does having an updated tox fix the issue? | 17:23 |
| zigo | Not in downstream distros. | 17:23 |
| *** afred312 has joined #openstack-keystone | 17:25 | |
| *** spandhe has joined #openstack-keystone | 17:34 | |
| *** rderose has joined #openstack-keystone | 17:38 | |
| *** gyee has joined #openstack-keystone | 17:44 | |
| *** ChanServ sets mode: +v gyee | 17:44 | |
| *** amakarov is now known as amakarov_away | 17:45 | |
| *** pushkaru has quit IRC | 17:49 | |
| rodrigods | dstanek, breton, so... I have a mapping that looks like that: https://paste.fedoraproject.org/377179/14655787/ - it maps to a user by its id. And it results in a unscoped token like that: https://paste.fedoraproject.org/377182/55789851/ . The local user with that ID has access to project 6da4ec769c904fd7b89378328b704792, but when I try to scope the token, I receive: User 4629ae2d7298417ea38d005361c75b20 has no access to project 6da4ec769c9 | 17:50 |
| rodrigods | 04fd7b89378328b704792 | 17:50 |
| rodrigods | dstanek, breton looks like this error: https://bugs.launchpad.net/keystone/+bug/1590426 | 17:52 |
| openstack | Launchpad bug 1590426 in OpenStack Identity (keystone) "Keystone Federated Identity assertion name not included in token" [Undecided,New] - Assigned to Adam Young (ayoung) | 17:52 |
| *** permalac has quit IRC | 17:54 | |
| *** catintheroof has joined #openstack-keystone | 17:59 | |
| dstanek | rodrigods: does that user or group have roles on the project? | 17:59 |
| rodrigods | dstanek, the user has, the group... let me check | 17:59 |
| dstanek | rodrigods: how to you know the federated user's id ahead of time | 18:00 |
| rodrigods | dstanek, the group doesn't | 18:00 |
| rodrigods | dstanek, just wanted to map to a local user | 18:00 |
| *** gyee has quit IRC | 18:00 | |
| rodrigods | dstanek, let me add a role to the group | 18:01 |
| dstanek | rodrigods: is this k2k and you have the same user ids on both sides? | 18:01 |
| rodrigods | dstanek, no... regular federation, I was hoping that providing a user_id, it would map to an existing user | 18:02 |
| rodrigods | not create an ephemeral one... but you right | 18:02 |
| rodrigods | missing group assignment should be the cause | 18:02 |
| dstanek | rodrigods: i'd be interested to know if that use could be a scoped token when logging in directly to keystone | 18:03 |
| rodrigods | dstanek, anyway... the issue is that... If I list projects via /auth/projects using that token (without the group assignment), the project is returned | 18:03 |
| *** rk4n has quit IRC | 18:03 | |
| rodrigods | dstanek, keystone messes up the ephemeral user and the local user because the ID | 18:04 |
| *** lhcheng has joined #openstack-keystone | 18:13 | |
| *** ChanServ sets mode: +v lhcheng | 18:13 | |
| *** lhcheng has quit IRC | 18:13 | |
| *** lhcheng has joined #openstack-keystone | 18:13 | |
| *** barjavel.freenode.net sets mode: +v lhcheng | 18:13 | |
| *** lhcheng_ has joined #openstack-keystone | 18:17 | |
| *** lhcheng has quit IRC | 18:17 | |
| *** browne has joined #openstack-keystone | 18:21 | |
| *** roxanaghe has quit IRC | 18:21 | |
| openstackgerrit | Matthew Edmonds proposed openstack/keystone: fix ldap delete_user group member cleanup https://review.openstack.org/327358 | 18:21 |
| openstackgerrit | Dolph Mathews proposed openstack/keystonemiddleware: Create a Config object https://review.openstack.org/319715 | 18:22 |
| edmondsw | dolphm, addressed your _LW comment | 18:22 |
| edmondsw | good catch, tx | 18:22 |
| openstackgerrit | Dolph Mathews proposed openstack/keystonemiddleware: Consolidate user agent calculation https://review.openstack.org/319717 | 18:22 |
| openstackgerrit | Dolph Mathews proposed openstack/keystonemiddleware: Make audit middleware use common config object https://review.openstack.org/328046 | 18:23 |
| openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Disable inactive users requirements https://review.openstack.org/328447 | 18:25 |
| openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Disable inactive users requirements https://review.openstack.org/328447 | 18:26 |
| *** gyee has joined #openstack-keystone | 18:27 | |
| *** ChanServ sets mode: +v gyee | 18:27 | |
| *** julim has quit IRC | 18:46 | |
| *** roxanagh_ has joined #openstack-keystone | 18:47 | |
| *** yolanda has quit IRC | 18:53 | |
| *** pushkaru has joined #openstack-keystone | 18:54 | |
| *** edmondsw has quit IRC | 18:56 | |
| *** darosale has quit IRC | 18:58 | |
| *** spandhe has quit IRC | 18:59 | |
| *** yolanda has joined #openstack-keystone | 19:03 | |
| *** amrith is now known as _amrith_ | 19:06 | |
| samueldmq | ayoung: henrynash: could anyone of you look at patch 327358 ? I have a question there about expected behavior of LDAP query | 19:12 |
| patchbot | samueldmq: https://review.openstack.org/#/c/327358/ - keystone - fix ldap delete_user group member cleanup | 19:12 |
| *** mvk_ has joined #openstack-keystone | 19:12 | |
| ayoung | samueldmq, um...hate that | 19:14 |
| ayoung | Don't use Keystone to manage LDAP | 19:14 |
| samueldmq | ayoung: we already do, that just fixes what we're supposed to provide :) | 19:15 |
| ayoung | samueldmq, you are right, that section he removed is needs to be put back | 19:15 |
| *** mvk has quit IRC | 19:16 | |
| dolphm | nonameentername: can you review this? https://review.openstack.org/#/c/281086/ | 19:16 |
| patchbot | dolphm: patch 281086 - keystoneauth - Support TOTP auth plugin | 19:16 |
| nonameentername | dolphm: yeah, I'll take a look at it | 19:17 |
| samueldmq | ayoung: thanks, group_filter needs to always be honored, that's what I thought | 19:18 |
| samueldmq | ayoung: left a review I checked this with you, thanks | 19:18 |
| ayoung | samueldmq, I really want to do away with LDAP and move to using SSSD. It makes LDAP just another form of Federation. | 19:19 |
| *** pnavarro has joined #openstack-keystone | 19:23 | |
| *** ddieterly has joined #openstack-keystone | 19:25 | |
| notmorgan | ayoung: SSSD, unfortunately, still (haven't tried 16.04) did not work well on non-redhat systems. | 19:27 |
| ayoung | notmorgan, so I heard, but I've not tried to run it myself | 19:27 |
| notmorgan | ayoung: it seems to have a nice suite of packages for suse, but suse is a lot closer to rhel than debian/ubuntu | 19:28 |
| ayoung | notmorgan, I just mean that for the deploys that my team does, and our customers | 19:28 |
| notmorgan | ayoung: right. which, unless we get sssd working well, likely means carrying your own plugins. | 19:28 |
| ayoung | I think mod_lookup_identity can actually do straight LDAP, too, but have not tried | 19:28 |
| notmorgan | ayoung: i would rather have it work well and be testable fwiw | 19:28 |
| ayoung | notmorgan, nope. No need to . Generic Federation works fine | 19:29 |
| ayoung | Kerberos + SSSD uses the FedKerb plugin | 19:29 |
| notmorgan | ayoung: *shrug*. also writable ldap... when do we get to delete that? | 19:29 |
| ayoung | notmorgan, not soon enough | 19:29 |
| * notmorgan asks because of that ^ patch. | 19:29 | |
| notmorgan | ugh, after newton :( | 19:30 |
| notmorgan | boo. | 19:30 |
| * notmorgan was looking forward to rm-rfing more ldap things. | 19:30 | |
| ayoung | notmorgan, I think that patch is probably a mistake... | 19:31 |
| notmorgan | i was about to -2 it but... it is a legitimate bug that likely should have a fix backported to liberty where this was supported | 19:31 |
| notmorgan | "supported" | 19:32 |
| * notmorgan adds air quotes. | 19:32 | |
| notmorgan | ayoung: if it was strictly a fix for newton i'd just say "not worth it" | 19:32 |
| ayoung | notmorgan, why is it a legitimate bug? | 19:32 |
| notmorgan | ayoung: but if we're dealing with a backportable fix to where this is "supported" we might need to handle this case. | 19:33 |
| ayoung | the only way I can see anyone getting in that situation is by either dpoing direct LDAP manipulation or messing up thei ldap config | 19:33 |
| ayoung | so...meh | 19:33 |
| ayoung | won't hold it up, won't +2 | 19:33 |
| notmorgan | pretty much i am willing to say for liberty backport i'll suport it if it is really an issue | 19:34 |
| notmorgan | but if otherwise not a winner of a path to go down. | 19:34 |
| notmorgan | ayoung: i just commented on the patch | 19:39 |
| notmorgan | ayoung: i think the unfiltered group get is a broken thing. | 19:40 |
| notmorgan | ayoung: *think* | 19:40 |
| ayoung | notmorgan, yeah, that part is spurious | 19:40 |
| notmorgan | the filter remove is bad and justified for a -1 in the list | 19:41 |
| *** browne has quit IRC | 19:42 | |
| *** rk4n has joined #openstack-keystone | 19:44 | |
| dolphm | dstanek: your follow up is requested on https://review.openstack.org/#/c/261188/ | 19:47 |
| patchbot | dolphm: patch 261188 - python-keystoneclient - Add wrapper classes for return-request-id-to-caller | 19:47 |
| *** sdake has joined #openstack-keystone | 19:52 | |
| *** mvk has joined #openstack-keystone | 19:55 | |
| *** mvk_ has quit IRC | 19:58 | |
| *** lhcheng has joined #openstack-keystone | 19:59 | |
| *** ChanServ sets mode: +v lhcheng | 19:59 | |
| *** lhcheng_ has quit IRC | 19:59 | |
| *** ametts has quit IRC | 20:00 | |
| dstanek | dolphm: shore | 20:01 |
| dstanek | dolphm: i still think that's a terrible idea | 20:02 |
| dolphm | dstanek: the approach or the idea? | 20:02 |
| dstanek | dolphm: the idea of adding an attribute to a builtin type | 20:03 |
| dstanek | i think it was bknudson that had the idea to have different return values based on a flag to the client. then deprecate the old way | 20:03 |
| *** pnavarro has quit IRC | 20:03 | |
| dstanek | not only is it terrible OOP, but imo it would be too easy to keep creating bugs like list(list_with_id) | 20:04 |
| *** julim has joined #openstack-keystone | 20:07 | |
| dolphm | dstanek: different return values? | 20:08 |
| *** roxanagh_ has quit IRC | 20:08 | |
| dstanek | a list or boolean for backward compat, but a response object of some sort if you ask for it | 20:09 |
| dstanek | that way we can properly relay metadata like: was this a cached response, etc | 20:10 |
| notmorgan | the adding of attributes to base objects in python just makes me cry a little | 20:10 |
| shewless | dstanek: hey I didn't forget about you. I just haven't had much luck. I hacked the metadata to say port 5000 for everything and I get a slightly different error but mostly just banging into brick walls | 20:12 |
| *** ametts has joined #openstack-keystone | 20:15 | |
| *** lhcheng has quit IRC | 20:17 | |
| *** lhcheng has joined #openstack-keystone | 20:19 | |
| *** ChanServ sets mode: +v lhcheng | 20:19 | |
| dstanek | shewless: why not try to get a public instance working against testshib as a starting point? | 20:21 |
| *** lhcheng has quit IRC | 20:24 | |
| shewless | dstanek: I suppose that may be a good idea. any recommendations of a free cloud service to use? :) | 20:24 |
| *** ametts has quit IRC | 20:30 | |
| dstanek | shewless: i don't know of any free ones. i work at rackspace so i use theirs. | 20:33 |
| dstanek | shewless: you should be able to experiment for just a few bucks though | 20:33 |
| shewless | dstanek: cool. I might just create a shib IDP at my work so I can own both sides.. we'll see. thanks for all of your help so far | 20:40 |
| openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 20:41 |
| openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 20:42 |
| openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password history requirements https://review.openstack.org/328339 | 20:42 |
| *** iurygregory has quit IRC | 20:43 | |
| *** ayoung has quit IRC | 20:49 | |
| *** pauloewerton has quit IRC | 20:49 | |
| *** adrian_otto has joined #openstack-keystone | 20:52 | |
| *** tonytan_brb has joined #openstack-keystone | 20:53 | |
| *** tonytan4ever has quit IRC | 20:54 | |
| *** tonytan_brb is now known as tonytan4ever | 20:54 | |
| *** roxanaghe has joined #openstack-keystone | 20:55 | |
| *** lhcheng has joined #openstack-keystone | 21:00 | |
| *** ChanServ sets mode: +v lhcheng | 21:00 | |
| *** edmondsw has joined #openstack-keystone | 21:00 | |
| edmondsw | ayoung notmorgan samueldmq I think everyone's misunderstanding https://review.openstack.org/#/c/327358 | 21:01 |
| edmondsw | please see my response | 21:01 |
| notmorgan | edmondsw: if list_user_groups is ever called outside of delete, you can't remove the filter | 21:02 |
| notmorgan | edmondsw: you can provide a swtich to not filter where you need it | 21:02 |
| notmorgan | edmondsw: but iirc that is not something we can just dump filter on. | 21:02 |
| edmondsw | notmorgan, a) it's not and b) that would depend on how this theoretical caller worked | 21:02 |
| *** roxanaghe has quit IRC | 21:02 | |
| notmorgan | edmondsw: also i do want to ask, is this a bug in liberty as well? | 21:03 |
| edmondsw | yes | 21:03 |
| *** roxanaghe has joined #openstack-keystone | 21:03 | |
| notmorgan | blah | 21:03 |
| *** KevinE_ has quit IRC | 21:03 | |
| notmorgan | if it was only newton/mitaka i'd probably say "meh" | 21:03 |
| *** lhcheng has quit IRC | 21:05 | |
| edmondsw | notmorgan looks like it's even in kilo | 21:05 |
| notmorgan | yeah but kilo is EOLing | 21:06 |
| notmorgan | so, i don't think we'll land the patch before kilo is dead. | 21:07 |
| edmondsw | list_user_groups_filtered is the method you should call (and that other places do call) when you want filtering... | 21:07 |
| notmorgan | so see my comment. i reversed my -1 | 21:07 |
| edmondsw | you don't have to pass hints to call that... if you don't want hints, say None | 21:07 |
| notmorgan | basically i think this is a clear mixed use backend/manually edited/managed so keystone isn't really being authoritative to it's data store | 21:08 |
| notmorgan | i can see how you land here but ugh. | 21:08 |
| edmondsw | yeah, I agree with that | 21:08 |
| edmondsw | easiest way to land here would be to run one way for a while, then at some point change the group_filter conf setting | 21:08 |
| notmorgan | edmondsw: yeah as i said in my comment | 21:09 |
| notmorgan | which... is very likely to just totally hork everything anyway | 21:09 |
| notmorgan | edmondsw: are you really hitting this? | 21:10 |
| notmorgan | edmondsw: i mean, you've seen this in the wild? | 21:10 |
| edmondsw | no, I saw it while I was fixing something different that I was hitting, and thought I was trying to be a good citizen | 21:10 |
| notmorgan | edmondsw: phew | 21:10 |
| notmorgan | :) | 21:10 |
| notmorgan | ok | 21:10 |
| notmorgan | i was worried that we had a bigger issue | 21:10 |
| edmondsw | I'm not stupid enough to use keystone for read/write LDAP... ;) | 21:11 |
| notmorgan | so i'm inclined to accept this for the logging / not bail out stuff. | 21:11 |
| notmorgan | but if someone hits this in the wild i'm going to ask how broken their systems are / have been | 21:11 |
| notmorgan | ;) | 21:11 |
| edmondsw | sure :) | 21:11 |
| stevemar | edmondsw: i was wondering why you brought up that bug :) | 21:11 |
| notmorgan | edmondsw: i was also going to prod you on how you got wedged into that scenario if you were really troubleshooting it from a "broken prod system" | 21:12 |
| edmondsw | Next time I should probably start the bug with NOTE: I'M NOT STUPID ENOUGH TO ACTUALLY GET MYSELF INTO THIS SITUATION BUT I NOTICED... | 21:12 |
| stevemar | :) | 21:12 |
| stevemar | its all we ask! | 21:12 |
| notmorgan | edmondsw: so, i would easily +2 just the logging fixes not bail out- and i'm "ok" with accepting the fix as is. | 21:12 |
| notmorgan | but fwiw it's very edge-case-y | 21:13 |
| edmondsw | sure | 21:13 |
| *** itlinux has quit IRC | 21:13 | |
| notmorgan | and i would say "lets not even bother backporting" unless you feel very strongly about it. which means... do we need to fix it? | 21:13 |
| notmorgan | and if you're feeling strong enough about it to warrant a real fix + backports. i'll say "sure" | 21:13 |
| notmorgan | (and you're going to backport it) | 21:14 |
| * notmorgan lets edmondsw decide :) | 21:14 | |
| notmorgan | stevemar: (see what i did there? :P) | 21:14 |
| edmondsw | I just wanted to throw up the fix, as I said, to be a good citizen. | 21:15 |
| stevemar | let's just accept it :) | 21:15 |
| edmondsw | personally I would merge it into master, so we have it and don't have someone else seeing this either in review or in the field | 21:15 |
| notmorgan | stevemar: wfm, though someone else has to backport | 21:15 |
| edmondsw | but not backport... it can get backported if someone actually hits it and needs it backported | 21:16 |
| notmorgan | i'll thats my contingency for accepting it. | 21:16 |
| *** gagehugo has quit IRC | 21:16 | |
| notmorgan | because lets be fair, write ldap dies next cycle ;) | 21:16 |
| edmondsw | finally! | 21:16 |
| notmorgan | now... if steve +2s you don't need my approval | 21:16 |
| notmorgan | and no backport needed, since dolph +2'd | 21:16 |
| edmondsw | come on stevemar! | 21:17 |
| * notmorgan tosses stevemar under that bus. | 21:17 | |
| stevemar | edmondsw: i haven't looked at the code yet, just glanced at the bug and i assumed you fixed it | 21:18 |
| stevemar | edmondsw: give me a few, i | 21:18 |
| edmondsw | np | 21:18 |
| stevemar | i'm setting up a new slack channel, again | 21:18 |
| *** lhcheng has joined #openstack-keystone | 21:20 | |
| *** ChanServ sets mode: +v lhcheng | 21:20 | |
| mnaser | is there any way of creating a token under a certain user/tenant without access to their credentials (as an admin of course) | 21:22 |
| *** browne has joined #openstack-keystone | 21:24 | |
| *** roxanaghe has quit IRC | 21:25 | |
| stevemar | mnaser: not really | 21:25 |
| edmondsw | mnaser I sure hope not | 21:25 |
| stevemar | mnaser: like if i was an admin, i could create a token for you and hand it over? | 21:26 |
| lbragstad | like "as an admin, i'm going to create a token for user john.smith and give it to them"? | 21:27 |
| *** jorge_munoz has quit IRC | 21:28 | |
| dolphm | mnaser: trusts with impersonation let you do that, but the resulting tokens are flagged as such | 21:29 |
| mnaser | correct to what lbragstad said | 21:30 |
| *** itlinux has joined #openstack-keystone | 21:30 | |
| mnaser | i guess the use case is we want to pass on a token to our control panel for it to do what it has to do | 21:30 |
| mnaser | and the user is already authenticated by our billing system, and we know user A => tenant ABC | 21:30 |
| *** Guest5 has quit IRC | 21:32 | |
| mnaser | i guess unless we implement an auth driver to auth with our billing, but i prefer not to touch internals of keystone | 21:33 |
| mnaser | also another use case is when we terminate tenants, we have a very (annoying and risky) system that gets all resources by using things like all_tenants and then filtering down, this could be ultra scary if something goes wrong | 21:35 |
| *** ddieterly is now known as ddieterly[away] | 21:35 | |
| mnaser | if we can scope in as a user, life would be much easier | 21:35 |
| *** sdake has quit IRC | 21:36 | |
| *** sdake has joined #openstack-keystone | 21:41 | |
| edmondsw | notmorgan, since you brought up backporting... here's the review for my backport of the much more significant issue that led me to the LDAP read/write one were were just discussing | 21:42 |
| edmondsw | https://review.openstack.org/#/c/327703/ | 21:42 |
| patchbot | edmondsw: patch 327703 - keystone (stable/mitaka) - Honor ldap_filter on filtered group list | 21:42 |
| dstanek | shewless: i think i can get my hands on an adfs server for testing. i'll let you know if i have trouble | 21:43 |
| *** sdake_ has joined #openstack-keystone | 21:43 | |
| *** sdake has quit IRC | 21:45 | |
| *** sigmavirus24 is now known as sigmavirus24_awa | 21:49 | |
| *** itlinux has quit IRC | 21:50 | |
| *** spandhe has joined #openstack-keystone | 21:51 | |
| *** rderose has quit IRC | 21:53 | |
| *** edmondsw has quit IRC | 21:53 | |
| *** roxanaghe has joined #openstack-keystone | 21:58 | |
| *** gabriel-bezerra has joined #openstack-keystone | 21:59 | |
| gabriel-bezerra | hi folks, I'm trying to run a devstack with kilo version for some backporting work but am facing an issue with pycadf version | 21:59 |
| gabriel-bezerra | The 'pycadf<0.9.0,>=0.8.0' distribution was not found and is required by keystone | 22:00 |
| *** ddieterly[away] is now known as ddieterly | 22:00 | |
| gabriel-bezerra | pip search pycadf shows version 2.3.0 installed | 22:01 |
| *** dave-mccowan has quit IRC | 22:02 | |
| bknudson | that's way too new | 22:05 |
| bknudson | gabriel-bezerra: I think you might have to check out the right level of /opt/stack/requirements? I had this problem earlier this week but already forgot how I worked around it. | 22:05 |
| *** catintheroof has quit IRC | 22:06 | |
| bknudson | I probably tried pip installing the right version... but then I feel like that didn't work... | 22:06 |
| gabriel-bezerra | bknudson: I could just find this conflict... | 22:07 |
| gabriel-bezerra | /opt/stack/keystone/requirements.txt:35:pycadf<0.9.0,>=0.8.0 | 22:07 |
| gabriel-bezerra | /opt/stack/requirements/global-requirements.txt:143:pycadf>=1.1.0,!=2.0.0 # Apache-2.0 | 22:07 |
| gabriel-bezerra | yes, pip installing didn't work :( | 22:07 |
| gabriel-bezerra | I'll check if my branch version for requirments is right | 22:08 |
| *** pushkaru has quit IRC | 22:08 | |
| gabriel-bezerra | thanks for the suggestion, bknudson | 22:08 |
| *** pushkaru has joined #openstack-keystone | 22:08 | |
| bknudson | y, look there. | 22:08 |
| *** pushkaru has quit IRC | 22:14 | |
| stevemar | gabriel-bezerra: looks like your requirements aren't from the kilo version | 22:15 |
| gabriel-bezerra | stevemar: yes, right that. I've just found how to specify requirements branch in local.conf | 22:18 |
| gabriel-bezerra | I'll try that now | 22:18 |
| gabriel-bezerra | thanks | 22:18 |
| *** adrian_otto has quit IRC | 22:22 | |
| *** lhcheng has quit IRC | 22:30 | |
| *** pushkaru has joined #openstack-keystone | 22:33 | |
| *** julim has quit IRC | 22:39 | |
| *** vgridnev_ has joined #openstack-keystone | 22:41 | |
| *** scarlisle has quit IRC | 22:44 | |
| *** BjoernT has quit IRC | 22:46 | |
| *** henrynash_ has joined #openstack-keystone | 22:49 | |
| *** ChanServ sets mode: +v henrynash_ | 22:49 | |
| *** timcline has quit IRC | 22:50 | |
| *** timcline has joined #openstack-keystone | 22:51 | |
| *** timcline has quit IRC | 22:55 | |
| stevemar | lbragstad: thank you for responding to the perf. comments on the mailing list | 22:57 |
| *** pushkaru has quit IRC | 22:59 | |
| notmorgan | lbragstad: i added some stuff on top to flesh out a bit more in the responses. | 22:59 |
| notmorgan | lbragstad: also thanks for doing the work! | 22:59 |
| notmorgan | stevemar: ^ cc | 22:59 |
| * stevemar nods at notmorgan | 23:00 | |
| *** ddieterly has quit IRC | 23:00 | |
| * notmorgan wants to go for a run... | 23:03 | |
| *** adrian_otto has joined #openstack-keystone | 23:16 | |
| *** gordc has quit IRC | 23:22 | |
| *** tonytan4ever has quit IRC | 23:27 | |
| *** spandhe has quit IRC | 23:35 | |
| *** spandhe has joined #openstack-keystone | 23:43 | |
| *** spandhe has quit IRC | 23:52 | |
| *** pgbridge has quit IRC | 23:55 | |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!