*** spandhe has joined #openstack-keystone | 00:04 | |
*** tqtran has quit IRC | 00:06 | |
*** edtubill has quit IRC | 00:09 | |
*** serverascode has quit IRC | 00:17 | |
*** andrewbogott has quit IRC | 00:17 | |
*** DuncanT has quit IRC | 00:17 | |
*** andreykurilin__ has quit IRC | 00:17 | |
*** jed56 has quit IRC | 00:17 | |
*** briancurtin has quit IRC | 00:17 | |
*** sigmavirus24 has quit IRC | 00:17 | |
*** nikhil has quit IRC | 00:18 | |
*** andrewbogott has joined #openstack-keystone | 00:19 | |
*** serverascode has joined #openstack-keystone | 00:19 | |
*** DuncanT has joined #openstack-keystone | 00:19 | |
*** jed56 has joined #openstack-keystone | 00:20 | |
*** briancurtin has joined #openstack-keystone | 00:20 | |
*** andreykurilin__ has joined #openstack-keystone | 00:21 | |
*** nikhil has joined #openstack-keystone | 00:21 | |
*** sigmavirus24 has joined #openstack-keystone | 00:28 | |
*** slberger has left #openstack-keystone | 00:32 | |
*** zigo has quit IRC | 00:37 | |
*** ddieterly has joined #openstack-keystone | 00:51 | |
*** zigo has joined #openstack-keystone | 01:03 | |
*** ayoung has joined #openstack-keystone | 01:07 | |
*** ChanServ sets mode: +v ayoung | 01:07 | |
*** tonytan4ever has joined #openstack-keystone | 01:10 | |
*** chlong has joined #openstack-keystone | 01:16 | |
*** ddieterly is now known as ddieterly[away] | 01:24 | |
*** ddieterly[away] is now known as ddieterly | 01:24 | |
*** sdake has joined #openstack-keystone | 01:25 | |
*** rk4n has quit IRC | 01:26 | |
*** jorge_munoz has quit IRC | 01:26 | |
*** edtubill has joined #openstack-keystone | 01:30 | |
openstackgerrit | Ryosuke Mizuno proposed openstack/keystone: Add validation rules for create token using a JSON schema https://review.openstack.org/325086 | 01:35 |
---|---|---|
*** ddieterly has quit IRC | 01:50 | |
*** iurygregory_ has quit IRC | 01:50 | |
*** ddieterly has joined #openstack-keystone | 02:01 | |
*** jamielennox has left #openstack-keystone | 02:02 | |
*** jamielennox has joined #openstack-keystone | 02:02 | |
*** ChanServ sets mode: +v jamielennox | 02:02 | |
*** TxGVNN has joined #openstack-keystone | 02:02 | |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Consolidate user agent calculation https://review.openstack.org/319717 | 02:02 |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Create a Config object https://review.openstack.org/319715 | 02:02 |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Make audit middleware use common config object https://review.openstack.org/328046 | 02:02 |
jamielennox | gyee: for you ^ | 02:03 |
*** lhcheng has quit IRC | 02:03 | |
*** lhcheng has joined #openstack-keystone | 02:15 | |
*** ChanServ sets mode: +v lhcheng | 02:15 | |
*** ddieterly has quit IRC | 02:19 | |
*** edtubill has quit IRC | 02:33 | |
*** dave-mccowan has quit IRC | 02:34 | |
*** sheel has joined #openstack-keystone | 02:46 | |
*** richm has quit IRC | 02:52 | |
*** TxGVNN has quit IRC | 02:53 | |
*** tonytan4ever has quit IRC | 02:56 | |
*** edtubill has joined #openstack-keystone | 02:58 | |
*** neophy has joined #openstack-keystone | 03:13 | |
*** markvoelker has quit IRC | 03:14 | |
*** edtubill has quit IRC | 03:15 | |
*** edtubill has joined #openstack-keystone | 03:15 | |
*** lhcheng has quit IRC | 03:30 | |
*** spandhe has quit IRC | 03:37 | |
*** sdake has quit IRC | 03:41 | |
*** pgbridge_ has joined #openstack-keystone | 03:48 | |
*** jaosorior has joined #openstack-keystone | 03:48 | |
*** pgbridge has quit IRC | 03:51 | |
*** pgbridge has joined #openstack-keystone | 03:51 | |
*** lhcheng has joined #openstack-keystone | 03:52 | |
*** ChanServ sets mode: +v lhcheng | 03:52 | |
*** pgbridge_ has quit IRC | 03:55 | |
*** itisha has quit IRC | 04:00 | |
*** links has joined #openstack-keystone | 04:00 | |
stevemar | lbragstad: dolphm nice "OSIC Performance Bot" | 04:20 |
stevemar | success: OSIC Performance Bot is up and running | 04:20 |
stevemar | #success OSIC Performance Bot is up and running | 04:21 |
openstackstatus | stevemar: Added success to Success page | 04:21 |
*** rmizuno has joined #openstack-keystone | 04:28 | |
*** edtubill has quit IRC | 04:33 | |
*** edtubill has joined #openstack-keystone | 04:35 | |
dstanek | yay, OSIC | 04:36 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Fix TOTP transient test failure https://review.openstack.org/327922 | 04:40 |
*** sdake has joined #openstack-keystone | 04:46 | |
jamielennox | sigh, i broke my rule: don't look at audit middleware - lost pretty much the whole day | 04:56 |
gyee | jamielennox, yeah, on it | 04:57 |
*** spandhe has joined #openstack-keystone | 04:58 | |
jamielennox | gyee: i have a couple of nice little cleanups - and i just can't break all the test assumptions | 04:58 |
gyee | jamielennox, I will abandon my other patch so I can base mine on yours | 04:59 |
jamielennox | gyee: yea, it becomes almost trivial at that point | 05:00 |
gyee | yeah | 05:00 |
stevemar | jamielennox: gyee i did the same thing earlier today, i waned to make oslo.messaging required... went down that rabbit hole alright | 05:02 |
jamielennox | stevemar: oh, yea: i found that if you do that we'll change behaviour | 05:02 |
jamielennox | stevemar: https://github.com/openstack/keystonemiddleware/blob/master/keystonemiddleware/audit.py#L426 | 05:03 |
stevemar | oh? i just noticed the tests were all mangled... what i miss? | 05:03 |
stevemar | yep | 05:03 |
jamielennox | stevemar: so whether it emits a message or just logs it is dependant on if the library is installed | 05:03 |
stevemar | i figured we could check if the driver was configured... and not as 'log' | 05:03 |
stevemar | driver = CONF.audit_middleware.driver | 05:04 |
stevemar | if driver and driver != 'log' | 05:04 |
stevemar | just what i thought really quickly today | 05:04 |
stevemar | may not work *shrugs* | 05:05 |
jamielennox | it probably will | 05:05 |
gyee | stevemar, problem is Swift wants everything to be *optional* | 05:05 |
stevemar | gyee: swift doesn't use keystonemiddleware | 05:05 |
jamielennox | i tried to refactor a bit and realize everything tests private methods | 05:06 |
gyee | stevemar, our product have a requirement for auditing, so I am trying to make audit middleware work for Swift | 05:06 |
stevemar | gyee: just dropping it in the pipeline? | 05:06 |
jamielennox | gyee: the dependency will be on keystonemiddleware, not swift | 05:06 |
gyee | problem is Swift only support one logger | 05:06 |
gyee | stevemar, its not that simple | 05:06 |
gyee | I do agree with having everything goes through oslo.messaging as it also support 'log' driver | 05:09 |
gyee | right now I am unable to make Swift use the log driver | 05:09 |
stevemar | gyee: so why does swift have to support oslo.messaging? you can install swift and keystonemiddleware, ksm pulls in whatever it needs, why do you care, as the deployer? | 05:13 |
*** markvoelker has joined #openstack-keystone | 05:15 | |
gyee | stevemar, right now oslo.messaging is optional for audit middleware, and we can't use the log driver even if its there | 05:15 |
gyee | so its a package they don't need | 05:15 |
gyee | but if we can make the log driver work then its a compelling argument | 05:17 |
*** edtubill has quit IRC | 05:17 | |
*** edtubill has joined #openstack-keystone | 05:18 | |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Add a fixture method to add your own token data https://review.openstack.org/328076 | 05:18 |
*** markvoelker has quit IRC | 05:20 | |
*** GB21 has joined #openstack-keystone | 05:22 | |
*** GB21 has quit IRC | 05:28 | |
openstackgerrit | Merged openstack/python-keystoneclient: Add users functional tests https://review.openstack.org/289306 | 05:28 |
*** jamielennox is now known as jamielennox|away | 05:29 | |
notmorgan | dstanek: from our earlier convo: https://twitter.com/MdrnStm/status/741139876150673408 | 05:30 |
notmorgan | oh stevemar is around. | 05:31 |
gyee | notmorgan, first few months baby sleeps a lot so stevemar should have some free time :-) | 05:36 |
*** gyee has quit IRC | 05:45 | |
*** GB21 has joined #openstack-keystone | 05:47 | |
*** GB21 has quit IRC | 05:55 | |
*** GB21 has joined #openstack-keystone | 05:55 | |
*** GB21 has quit IRC | 05:55 | |
*** GB21 has joined #openstack-keystone | 05:56 | |
*** lhcheng_ has joined #openstack-keystone | 06:02 | |
*** chlong has quit IRC | 06:03 | |
*** GB21 has quit IRC | 06:03 | |
*** lhcheng has quit IRC | 06:04 | |
*** yolanda has joined #openstack-keystone | 06:06 | |
*** belmoreira has joined #openstack-keystone | 06:12 | |
*** GB21 has joined #openstack-keystone | 06:14 | |
*** TxGVNN has joined #openstack-keystone | 06:16 | |
*** lunarlamp has joined #openstack-keystone | 06:17 | |
*** chlong has joined #openstack-keystone | 06:20 | |
*** TxGVNN has quit IRC | 06:23 | |
*** openstackgerrit has quit IRC | 06:32 | |
*** openstackgerrit has joined #openstack-keystone | 06:32 | |
*** edtubill has quit IRC | 06:33 | |
*** chlong has quit IRC | 06:35 | |
*** pcaruana has joined #openstack-keystone | 06:40 | |
*** GB21 has quit IRC | 06:48 | |
*** links has quit IRC | 06:55 | |
*** lhcheng has joined #openstack-keystone | 07:05 | |
*** ChanServ sets mode: +v lhcheng | 07:05 | |
*** lhcheng_ has quit IRC | 07:08 | |
*** links has joined #openstack-keystone | 07:10 | |
*** spandhe has quit IRC | 07:10 | |
*** permalac has joined #openstack-keystone | 07:15 | |
*** markvoelker has joined #openstack-keystone | 07:16 | |
*** rcernin has joined #openstack-keystone | 07:17 | |
*** markvoelker has quit IRC | 07:21 | |
*** GB21 has joined #openstack-keystone | 07:24 | |
*** sheel has quit IRC | 07:26 | |
*** sheel has joined #openstack-keystone | 07:27 | |
*** tesseract has joined #openstack-keystone | 07:27 | |
*** agireud has quit IRC | 07:32 | |
*** openstackgerrit has quit IRC | 07:33 | |
*** openstackgerrit has joined #openstack-keystone | 07:33 | |
*** agireud has joined #openstack-keystone | 07:34 | |
*** jamielennox|away is now known as jamielennox | 07:36 | |
*** GB21 has quit IRC | 07:46 | |
*** rk4n has joined #openstack-keystone | 07:46 | |
*** dancn has quit IRC | 07:53 | |
*** dancn has joined #openstack-keystone | 07:55 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/oslo.policy: Imported Translations from Zanata https://review.openstack.org/328142 | 07:55 |
*** dancn has quit IRC | 07:55 | |
*** zzzeek has quit IRC | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:00 | |
*** GB21 has joined #openstack-keystone | 08:07 | |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c https://review.openstack.org/318435 | 08:10 |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c https://review.openstack.org/318435 | 08:10 |
*** markvoelker has joined #openstack-keystone | 08:17 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Imported Translations from Zanata https://review.openstack.org/328160 | 08:20 |
*** fhubik has joined #openstack-keystone | 08:21 | |
*** markvoelker has quit IRC | 08:21 | |
*** sdake has quit IRC | 08:21 | |
*** pnavarro has joined #openstack-keystone | 08:23 | |
*** lhcheng has quit IRC | 08:25 | |
*** woodster_ has quit IRC | 08:28 | |
*** nisha_ has joined #openstack-keystone | 08:29 | |
*** jaosorior has quit IRC | 08:30 | |
*** jaosorior has joined #openstack-keystone | 08:30 | |
nisha_ | Good morning :) | 08:31 |
*** nisha__ has joined #openstack-keystone | 08:40 | |
*** nisha_ has quit IRC | 08:45 | |
*** nisha__ has quit IRC | 08:45 | |
*** nisha_ has joined #openstack-keystone | 08:48 | |
*** nisha__ has joined #openstack-keystone | 08:48 | |
*** nisha_ has quit IRC | 08:50 | |
*** nisha__ is now known as nisha_ | 08:50 | |
*** nisha__ has joined #openstack-keystone | 08:51 | |
*** rk4n has quit IRC | 08:52 | |
*** rk4n has joined #openstack-keystone | 08:53 | |
*** nisha__ has quit IRC | 08:55 | |
*** rk4n_ has joined #openstack-keystone | 08:56 | |
*** rk4n_ has quit IRC | 08:57 | |
*** rk4n has quit IRC | 08:57 | |
*** daemontool has joined #openstack-keystone | 08:59 | |
*** rk4n has joined #openstack-keystone | 09:03 | |
*** henrynash_ has joined #openstack-keystone | 09:10 | |
*** ChanServ sets mode: +v henrynash_ | 09:10 | |
*** mvk has joined #openstack-keystone | 09:22 | |
*** GB21 has quit IRC | 09:35 | |
*** fhubik has quit IRC | 09:39 | |
*** GB21 has joined #openstack-keystone | 09:52 | |
*** henrynash_ has quit IRC | 10:02 | |
*** rk4n has quit IRC | 10:10 | |
*** danpawlik has joined #openstack-keystone | 10:11 | |
*** lhcheng has joined #openstack-keystone | 10:14 | |
*** ChanServ sets mode: +v lhcheng | 10:14 | |
*** daemontool has quit IRC | 10:17 | |
*** markvoelker has joined #openstack-keystone | 10:18 | |
*** lhcheng has quit IRC | 10:19 | |
*** rmizuno has quit IRC | 10:19 | |
*** markvoelker has quit IRC | 10:22 | |
*** danpawlik has left #openstack-keystone | 10:23 | |
*** neophy has quit IRC | 10:23 | |
*** danpawlik has joined #openstack-keystone | 10:23 | |
danpawlik | hi, is somebody there? | 10:24 |
*** daemontool has joined #openstack-keystone | 10:38 | |
*** nisha__ has joined #openstack-keystone | 10:48 | |
*** nisha_ has quit IRC | 10:51 | |
*** rk4n has joined #openstack-keystone | 10:53 | |
*** ddieterly has joined #openstack-keystone | 11:05 | |
*** TxGVNN has joined #openstack-keystone | 11:07 | |
*** GB21 has quit IRC | 11:07 | |
*** dmk0202 has joined #openstack-keystone | 11:10 | |
*** GB21 has joined #openstack-keystone | 11:22 | |
*** dmk0202 has quit IRC | 11:23 | |
*** daemontool has quit IRC | 11:28 | |
*** daemontool has joined #openstack-keystone | 11:28 | |
*** GB21 has quit IRC | 11:35 | |
*** dmk0202 has joined #openstack-keystone | 11:36 | |
*** vnogin has quit IRC | 11:43 | |
*** rk4n has joined #openstack-keystone | 11:45 | |
*** ddieterly has quit IRC | 11:47 | |
*** pcaruana has quit IRC | 11:51 | |
*** rk4n has quit IRC | 11:52 | |
*** rk4n has joined #openstack-keystone | 11:54 | |
*** rodrigods has quit IRC | 11:55 | |
*** rodrigods has joined #openstack-keystone | 11:56 | |
*** danpawlik has quit IRC | 11:56 | |
*** danpawlik has joined #openstack-keystone | 11:56 | |
*** pcaruana has joined #openstack-keystone | 12:07 | |
*** pcaruana has quit IRC | 12:13 | |
*** pcaruana has joined #openstack-keystone | 12:13 | |
*** ayoung has quit IRC | 12:15 | |
*** markvoelker has joined #openstack-keystone | 12:18 | |
*** ddieterly has joined #openstack-keystone | 12:20 | |
*** afred312 has quit IRC | 12:23 | |
*** dmk0202 has quit IRC | 12:25 | |
*** EinstCrazy has joined #openstack-keystone | 12:25 | |
*** lhcheng has joined #openstack-keystone | 12:27 | |
*** ChanServ sets mode: +v lhcheng | 12:27 | |
*** ddieterly has quit IRC | 12:27 | |
*** lhcheng has quit IRC | 12:32 | |
*** gordc has joined #openstack-keystone | 12:37 | |
*** ddieterly has joined #openstack-keystone | 12:37 | |
*** dmk0202 has joined #openstack-keystone | 12:39 | |
*** ddieterly is now known as ddieterly[away] | 12:41 | |
*** nisha__ has quit IRC | 12:47 | |
*** nisha__ has joined #openstack-keystone | 12:48 | |
*** EinstCrazy has quit IRC | 12:54 | |
*** links has quit IRC | 12:54 | |
*** dmk0202 has quit IRC | 12:58 | |
*** dmk0202 has joined #openstack-keystone | 12:59 | |
*** BjoernT has joined #openstack-keystone | 13:00 | |
*** pauloewerton has joined #openstack-keystone | 13:00 | |
*** EinstCrazy has joined #openstack-keystone | 13:02 | |
*** rodrigods has quit IRC | 13:05 | |
*** rodrigods has joined #openstack-keystone | 13:05 | |
*** EinstCrazy has quit IRC | 13:06 | |
*** jaosorior has quit IRC | 13:07 | |
*** edmondsw has joined #openstack-keystone | 13:08 | |
*** richm has joined #openstack-keystone | 13:10 | |
*** EinstCrazy has joined #openstack-keystone | 13:10 | |
*** EinstCrazy has quit IRC | 13:16 | |
*** EinstCrazy has joined #openstack-keystone | 13:16 | |
*** ayoung has joined #openstack-keystone | 13:16 | |
*** ChanServ sets mode: +v ayoung | 13:16 | |
*** jistr is now known as jistr|mtg | 13:20 | |
*** pcaruana has quit IRC | 13:20 | |
*** henrynash_ has joined #openstack-keystone | 13:22 | |
*** ChanServ sets mode: +v henrynash_ | 13:22 | |
*** EinstCrazy has quit IRC | 13:25 | |
*** sheel has quit IRC | 13:25 | |
*** dmk0202 has quit IRC | 13:29 | |
knikolla | hi o/ | 13:31 |
*** gagehugo has joined #openstack-keystone | 13:33 | |
*** TxGVNN has quit IRC | 13:33 | |
*** dave-mccowan has joined #openstack-keystone | 13:33 | |
*** links has joined #openstack-keystone | 13:36 | |
*** andrewbogott has quit IRC | 13:38 | |
*** andrewbogott has joined #openstack-keystone | 13:38 | |
*** pcaruana has joined #openstack-keystone | 13:39 | |
*** henrynash_ has quit IRC | 13:41 | |
*** rderose has joined #openstack-keystone | 13:44 | |
*** afred312 has joined #openstack-keystone | 13:47 | |
*** darosale has joined #openstack-keystone | 13:55 | |
*** nisha__ has quit IRC | 14:00 | |
*** ametts has joined #openstack-keystone | 14:00 | |
*** amakarov_away is now known as amakarov | 14:01 | |
*** links has quit IRC | 14:01 | |
*** rderose_ has joined #openstack-keystone | 14:07 | |
*** jistr|mtg is now known as jistr | 14:09 | |
*** rderose has quit IRC | 14:10 | |
*** fesp has joined #openstack-keystone | 14:24 | |
*** tonytan4ever has joined #openstack-keystone | 14:27 | |
*** fesp has quit IRC | 14:27 | |
*** fesp has joined #openstack-keystone | 14:30 | |
*** fesp has quit IRC | 14:32 | |
*** fesp has joined #openstack-keystone | 14:32 | |
*** jorge_munoz has joined #openstack-keystone | 14:33 | |
openstackgerrit | Merged openstack/keystone: Fix TOTP transient test failure https://review.openstack.org/327922 | 14:39 |
*** amrith has quit IRC | 14:41 | |
*** raddaoui has joined #openstack-keystone | 14:42 | |
*** amrith has joined #openstack-keystone | 14:42 | |
*** timcline has joined #openstack-keystone | 14:45 | |
*** timcline has quit IRC | 14:45 | |
dolphm | stevemar: tested that TOTP patch 9000 times over night -- it definitely fixed the issue :) | 14:45 |
patchbot | dolphm: https://review.openstack.org/#/c/9000/ - keystone - Do not crash when trying to remove a user role (wi... (MERGED) | 14:45 |
*** timcline has joined #openstack-keystone | 14:46 | |
stevemar | dolphm: nice | 14:46 |
dolphm | thanks, patchbot | 14:46 |
stevemar | haha, thats awesome | 14:46 |
dolphm | patch 1 | 14:46 |
patchbot | dolphm: https://review.openstack.org/#/c/1/ - openstack-infra/system-config - Add puppet module for ssh that installs an sshd_co... (MERGED) | 14:46 |
dolphm | patch 2 | 14:46 |
patchbot | dolphm: https://review.openstack.org/#/c/2/ | 14:46 |
stevemar | patch 9000 was a keystone patch | 14:46 |
patchbot | stevemar: https://review.openstack.org/#/c/9000/ - keystone - Do not crash when trying to remove a user role (wi... (MERGED) | 14:46 |
dolphm | patch 3 | 14:46 |
patchbot | dolphm: https://review.openstack.org/#/c/3/ | 14:46 |
dolphm | so helpful | 14:46 |
dolphm | patch 4 | 14:46 |
patchbot | dolphm: https://review.openstack.org/#/c/4/ - openstack-infra/system-config - Add gerrit dev/prod servers to jenkins slave known... (MERGED) | 14:46 |
notmyname | the https://review.openstack.org/#/c/9000/ pattern works too | 14:46 |
dolphm | patch 5 | 14:47 |
patchbot | notmyname: patch 9000 - keystone - Do not crash when trying to remove a user role (wi... (MERGED) | 14:47 |
patchbot | dolphm: https://review.openstack.org/#/c/5/ - openstack-infra/system-config - Fix problem with jenkins known_hosts url. (MERGED) | 14:47 |
notmyname | notmorgan had asked for patchbot to lurk here | 14:47 |
notmyname | it's my bot if you have questions/issues with it | 14:47 |
stevemar | notmyname: oh it's fine :) | 14:47 |
stevemar | wacky friday fun | 14:47 |
notmyname | FWIW https://github.com/notmyname/Patches | 14:48 |
dolphm | notmyname: i definitely find it useful - keeps me from clicking every code review link in irc | 14:48 |
notmyname | yeah. that was the frustration that made me write it :-) | 14:49 |
*** flaper87 has quit IRC | 14:52 | |
*** fesp is now known as flaper87 | 14:52 | |
*** flaper87 has quit IRC | 14:52 | |
*** flaper87 has joined #openstack-keystone | 14:52 | |
*** flaper87 has quit IRC | 14:55 | |
*** flaper87 has joined #openstack-keystone | 14:55 | |
*** daemontool has quit IRC | 14:57 | |
notmorgan | notmyname: ++ | 15:00 |
notmorgan | notmyname: i think i want to issue a PR for it so it has a delay in saying the same patch again | 15:01 |
notmorgan | patch 1 | 15:01 |
patchbot | notmorgan: https://review.openstack.org/#/c/1/ - openstack-infra/system-config - Add puppet module for ssh that installs an sshd_co... (MERGED) | 15:01 |
notmorgan | patch 1 | 15:01 |
patchbot | notmorgan: https://review.openstack.org/#/c/1/ - openstack-infra/system-config - Add puppet module for ssh that installs an sshd_co... (MERGED) | 15:01 |
notmorgan | patch 1 | 15:01 |
patchbot | notmorgan: https://review.openstack.org/#/c/1/ - openstack-infra/system-config - Add puppet module for ssh that installs an sshd_co... (MERGED) | 15:01 |
notmorgan | notmyname: like 10 or 30s | 15:01 |
notmyname | sure. go for it. patches welcome :-) | 15:01 |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password table changes https://review.openstack.org/314284 | 15:02 |
notmorgan | notmyname: :) | 15:02 |
notmorgan | notmyname: just realize it's going to consume a chunk more memory that way, so as long as you're ok with that | 15:02 |
notmorgan | notmyname: since it needs something like an ordereddict of patches it's said in the last XXX window | 15:03 |
*** spandhe has joined #openstack-keystone | 15:04 | |
bknudson | make it so that we can update commit messages by posting commands to irc. | 15:05 |
notmorgan | bknudson: you should totally write that bot | 15:05 |
bknudson | and cherry-pick changes | 15:06 |
*** spandhe_ has joined #openstack-keystone | 15:07 | |
*** spandhe has quit IRC | 15:09 | |
*** spandhe_ is now known as spandhe | 15:09 | |
*** tesseract has quit IRC | 15:09 | |
*** pcaruana has quit IRC | 15:13 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password history requirements https://review.openstack.org/328339 | 15:13 |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password history requirements https://review.openstack.org/328339 | 15:13 |
*** rcernin has quit IRC | 15:19 | |
*** EinstCrazy has joined #openstack-keystone | 15:21 | |
*** flaper87 has quit IRC | 15:27 | |
dstanek | well i give up on lxd for today. back to real work | 15:27 |
*** pushkaru has joined #openstack-keystone | 15:30 | |
openstackgerrit | Merged openstack/keystone: Change LocalUser sql model to eager loading https://review.openstack.org/327817 | 15:34 |
*** pnavarro has quit IRC | 15:34 | |
bknudson | dstanek: "The Legion of Extraordinary Dancers" ? | 15:34 |
dstanek | bknudson: that would have been more productive i think | 15:35 |
*** belmoreira has quit IRC | 15:41 | |
*** EinstCrazy has quit IRC | 15:44 | |
*** EinstCrazy has joined #openstack-keystone | 15:44 | |
*** KevinE_ has joined #openstack-keystone | 15:45 | |
*** rk4n has quit IRC | 15:49 | |
*** EinstCrazy has quit IRC | 15:51 | |
*** EinstCrazy has joined #openstack-keystone | 15:52 | |
*** ametts has quit IRC | 15:55 | |
openstackgerrit | Matthew Edmonds proposed openstack/keystone: exception sensitive cache/audit changes https://review.openstack.org/273218 | 15:57 |
openstackgerrit | Dolph Mathews proposed openstack/keystoneauth: Make the kerberos plugin loadable https://review.openstack.org/321814 | 15:59 |
*** roxanaghe has joined #openstack-keystone | 15:59 | |
dstanek | notmorgan: where you still going to work on https://bugs.launchpad.net/keystone/+bug/1572341 ? | 16:02 |
openstack | Launchpad bug 1572341 in OpenStack Identity (keystone) "Failed migration 90 -> 91 Can't DROP 'ixu_user_name_domain_id'" [High,Triaged] | 16:02 |
*** ametts has joined #openstack-keystone | 16:08 | |
*** EinstCrazy has quit IRC | 16:11 | |
notmorgan | dstanek: i keep meaning to | 16:11 |
notmorgan | dstanek: its unfortunately a really unfun migration to fix :( | 16:12 |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password table changes https://review.openstack.org/314284 | 16:17 |
*** afred312 has quit IRC | 16:18 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 16:19 |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 16:23 |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password history requirements https://review.openstack.org/328339 | 16:25 |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password strength requirements https://review.openstack.org/320586 | 16:29 |
*** ayoung has quit IRC | 16:33 | |
*** rderose_ has quit IRC | 16:37 | |
*** spandhe has quit IRC | 16:44 | |
openstackgerrit | Thomas Goirand proposed openstack/keystone: Add missing testresources build-requirement https://review.openstack.org/328383 | 16:45 |
*** rderose has joined #openstack-keystone | 16:46 | |
*** rk4n has joined #openstack-keystone | 16:49 | |
*** sdake has joined #openstack-keystone | 16:50 | |
breton | zigo: https://bugs.launchpad.net/keystone/+bug/1572202 this looks like a duplicate of your bug | 16:56 |
openstack | Launchpad bug 1572202 in OpenStack Identity (keystone) "testresources needs to be explicitly required for tests" [Medium,In progress] - Assigned to David Stanek (dstanek) | 16:56 |
zigo | Indeed. | 16:56 |
zigo | That's in fact indirectly needed by oslo.db | 16:57 |
zigo | I was tempted to add a runtime depends on testresources for oslo.db, but I'm not sure if that's really what I should do. | 16:57 |
breton | you've seen https://review.openstack.org/#/c/307878/, right? | 16:57 |
patchbot | breton: patch 307878 - keystone - Explicitly require testresources for tests (ABANDONED) | 16:57 |
dstanek | breton: zigo: i should probably mark that bug as closed | 16:59 |
zigo | Right. | 16:59 |
rodrigods | dstanek, ping... do you have a Mitaka (or more recent) federation setup ready? | 16:59 |
dstanek | rodrigods: define ready? | 17:00 |
rodrigods | dstanek, somehow working heh | 17:00 |
*** rderose_ has joined #openstack-keystone | 17:01 | |
breton | rodrigods: i have. Need anything to test? | 17:02 |
rodrigods | breton, yeah, think I've found a bug here, but shadow users should have fixed it (i'm using liberty) | 17:02 |
dstanek | rodrigods: i have a node that works against testshib | 17:03 |
rodrigods | dstanek, breton in a meeting, back in a hour or so to explain the issue :) | 17:04 |
dstanek | zigo: breton: what's the other bug? | 17:04 |
*** rderose has quit IRC | 17:05 | |
breton | dstanek: https://bugs.launchpad.net/bugs/1591281 | 17:06 |
openstack | Launchpad bug 1591281 in OpenStack Identity (keystone) "Missing test-requirement: testresources" [Undecided,In progress] - Assigned to Thomas Goirand (thomas-goirand) | 17:06 |
*** ebalduf_ has joined #openstack-keystone | 17:06 | |
*** rderose_ has quit IRC | 17:08 | |
dstanek | breton: does updating tox fix the issue? | 17:09 |
*** ayoung has joined #openstack-keystone | 17:14 | |
*** ChanServ sets mode: +v ayoung | 17:14 | |
breton | dstanek: i don't know. Please ask zigo. I just saw that it's a duplicate. | 17:16 |
*** Guest5 has joined #openstack-keystone | 17:17 | |
*** dan_nguyen has joined #openstack-keystone | 17:19 | |
dstanek | zigo: ^? | 17:19 |
zigo | #1591281 | 17:21 |
zigo | That's my bug. | 17:21 |
zigo | #1572202 the other one | 17:22 |
*** ebalduf_ has quit IRC | 17:22 | |
*** sdake has quit IRC | 17:22 | |
dstanek | zigo: does having an updated tox fix the issue? | 17:23 |
zigo | Not in downstream distros. | 17:23 |
*** afred312 has joined #openstack-keystone | 17:25 | |
*** spandhe has joined #openstack-keystone | 17:34 | |
*** rderose has joined #openstack-keystone | 17:38 | |
*** gyee has joined #openstack-keystone | 17:44 | |
*** ChanServ sets mode: +v gyee | 17:44 | |
*** amakarov is now known as amakarov_away | 17:45 | |
*** pushkaru has quit IRC | 17:49 | |
rodrigods | dstanek, breton, so... I have a mapping that looks like that: https://paste.fedoraproject.org/377179/14655787/ - it maps to a user by its id. And it results in a unscoped token like that: https://paste.fedoraproject.org/377182/55789851/ . The local user with that ID has access to project 6da4ec769c904fd7b89378328b704792, but when I try to scope the token, I receive: User 4629ae2d7298417ea38d005361c75b20 has no access to project 6da4ec769c9 | 17:50 |
rodrigods | 04fd7b89378328b704792 | 17:50 |
rodrigods | dstanek, breton looks like this error: https://bugs.launchpad.net/keystone/+bug/1590426 | 17:52 |
openstack | Launchpad bug 1590426 in OpenStack Identity (keystone) "Keystone Federated Identity assertion name not included in token" [Undecided,New] - Assigned to Adam Young (ayoung) | 17:52 |
*** permalac has quit IRC | 17:54 | |
*** catintheroof has joined #openstack-keystone | 17:59 | |
dstanek | rodrigods: does that user or group have roles on the project? | 17:59 |
rodrigods | dstanek, the user has, the group... let me check | 17:59 |
dstanek | rodrigods: how to you know the federated user's id ahead of time | 18:00 |
rodrigods | dstanek, the group doesn't | 18:00 |
rodrigods | dstanek, just wanted to map to a local user | 18:00 |
*** gyee has quit IRC | 18:00 | |
rodrigods | dstanek, let me add a role to the group | 18:01 |
dstanek | rodrigods: is this k2k and you have the same user ids on both sides? | 18:01 |
rodrigods | dstanek, no... regular federation, I was hoping that providing a user_id, it would map to an existing user | 18:02 |
rodrigods | not create an ephemeral one... but you right | 18:02 |
rodrigods | missing group assignment should be the cause | 18:02 |
dstanek | rodrigods: i'd be interested to know if that use could be a scoped token when logging in directly to keystone | 18:03 |
rodrigods | dstanek, anyway... the issue is that... If I list projects via /auth/projects using that token (without the group assignment), the project is returned | 18:03 |
*** rk4n has quit IRC | 18:03 | |
rodrigods | dstanek, keystone messes up the ephemeral user and the local user because the ID | 18:04 |
*** lhcheng has joined #openstack-keystone | 18:13 | |
*** ChanServ sets mode: +v lhcheng | 18:13 | |
*** lhcheng has quit IRC | 18:13 | |
*** lhcheng has joined #openstack-keystone | 18:13 | |
*** barjavel.freenode.net sets mode: +v lhcheng | 18:13 | |
*** lhcheng_ has joined #openstack-keystone | 18:17 | |
*** lhcheng has quit IRC | 18:17 | |
*** browne has joined #openstack-keystone | 18:21 | |
*** roxanaghe has quit IRC | 18:21 | |
openstackgerrit | Matthew Edmonds proposed openstack/keystone: fix ldap delete_user group member cleanup https://review.openstack.org/327358 | 18:21 |
openstackgerrit | Dolph Mathews proposed openstack/keystonemiddleware: Create a Config object https://review.openstack.org/319715 | 18:22 |
edmondsw | dolphm, addressed your _LW comment | 18:22 |
edmondsw | good catch, tx | 18:22 |
openstackgerrit | Dolph Mathews proposed openstack/keystonemiddleware: Consolidate user agent calculation https://review.openstack.org/319717 | 18:22 |
openstackgerrit | Dolph Mathews proposed openstack/keystonemiddleware: Make audit middleware use common config object https://review.openstack.org/328046 | 18:23 |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Disable inactive users requirements https://review.openstack.org/328447 | 18:25 |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Disable inactive users requirements https://review.openstack.org/328447 | 18:26 |
*** gyee has joined #openstack-keystone | 18:27 | |
*** ChanServ sets mode: +v gyee | 18:27 | |
*** julim has quit IRC | 18:46 | |
*** roxanagh_ has joined #openstack-keystone | 18:47 | |
*** yolanda has quit IRC | 18:53 | |
*** pushkaru has joined #openstack-keystone | 18:54 | |
*** edmondsw has quit IRC | 18:56 | |
*** darosale has quit IRC | 18:58 | |
*** spandhe has quit IRC | 18:59 | |
*** yolanda has joined #openstack-keystone | 19:03 | |
*** amrith is now known as _amrith_ | 19:06 | |
samueldmq | ayoung: henrynash: could anyone of you look at patch 327358 ? I have a question there about expected behavior of LDAP query | 19:12 |
patchbot | samueldmq: https://review.openstack.org/#/c/327358/ - keystone - fix ldap delete_user group member cleanup | 19:12 |
*** mvk_ has joined #openstack-keystone | 19:12 | |
ayoung | samueldmq, um...hate that | 19:14 |
ayoung | Don't use Keystone to manage LDAP | 19:14 |
samueldmq | ayoung: we already do, that just fixes what we're supposed to provide :) | 19:15 |
ayoung | samueldmq, you are right, that section he removed is needs to be put back | 19:15 |
*** mvk has quit IRC | 19:16 | |
dolphm | nonameentername: can you review this? https://review.openstack.org/#/c/281086/ | 19:16 |
patchbot | dolphm: patch 281086 - keystoneauth - Support TOTP auth plugin | 19:16 |
nonameentername | dolphm: yeah, I'll take a look at it | 19:17 |
samueldmq | ayoung: thanks, group_filter needs to always be honored, that's what I thought | 19:18 |
samueldmq | ayoung: left a review I checked this with you, thanks | 19:18 |
ayoung | samueldmq, I really want to do away with LDAP and move to using SSSD. It makes LDAP just another form of Federation. | 19:19 |
*** pnavarro has joined #openstack-keystone | 19:23 | |
*** ddieterly has joined #openstack-keystone | 19:25 | |
notmorgan | ayoung: SSSD, unfortunately, still (haven't tried 16.04) did not work well on non-redhat systems. | 19:27 |
ayoung | notmorgan, so I heard, but I've not tried to run it myself | 19:27 |
notmorgan | ayoung: it seems to have a nice suite of packages for suse, but suse is a lot closer to rhel than debian/ubuntu | 19:28 |
ayoung | notmorgan, I just mean that for the deploys that my team does, and our customers | 19:28 |
notmorgan | ayoung: right. which, unless we get sssd working well, likely means carrying your own plugins. | 19:28 |
ayoung | I think mod_lookup_identity can actually do straight LDAP, too, but have not tried | 19:28 |
notmorgan | ayoung: i would rather have it work well and be testable fwiw | 19:28 |
ayoung | notmorgan, nope. No need to . Generic Federation works fine | 19:29 |
ayoung | Kerberos + SSSD uses the FedKerb plugin | 19:29 |
notmorgan | ayoung: *shrug*. also writable ldap... when do we get to delete that? | 19:29 |
ayoung | notmorgan, not soon enough | 19:29 |
* notmorgan asks because of that ^ patch. | 19:29 | |
notmorgan | ugh, after newton :( | 19:30 |
notmorgan | boo. | 19:30 |
* notmorgan was looking forward to rm-rfing more ldap things. | 19:30 | |
ayoung | notmorgan, I think that patch is probably a mistake... | 19:31 |
notmorgan | i was about to -2 it but... it is a legitimate bug that likely should have a fix backported to liberty where this was supported | 19:31 |
notmorgan | "supported" | 19:32 |
* notmorgan adds air quotes. | 19:32 | |
notmorgan | ayoung: if it was strictly a fix for newton i'd just say "not worth it" | 19:32 |
ayoung | notmorgan, why is it a legitimate bug? | 19:32 |
notmorgan | ayoung: but if we're dealing with a backportable fix to where this is "supported" we might need to handle this case. | 19:33 |
ayoung | the only way I can see anyone getting in that situation is by either dpoing direct LDAP manipulation or messing up thei ldap config | 19:33 |
ayoung | so...meh | 19:33 |
ayoung | won't hold it up, won't +2 | 19:33 |
notmorgan | pretty much i am willing to say for liberty backport i'll suport it if it is really an issue | 19:34 |
notmorgan | but if otherwise not a winner of a path to go down. | 19:34 |
notmorgan | ayoung: i just commented on the patch | 19:39 |
notmorgan | ayoung: i think the unfiltered group get is a broken thing. | 19:40 |
notmorgan | ayoung: *think* | 19:40 |
ayoung | notmorgan, yeah, that part is spurious | 19:40 |
notmorgan | the filter remove is bad and justified for a -1 in the list | 19:41 |
*** browne has quit IRC | 19:42 | |
*** rk4n has joined #openstack-keystone | 19:44 | |
dolphm | dstanek: your follow up is requested on https://review.openstack.org/#/c/261188/ | 19:47 |
patchbot | dolphm: patch 261188 - python-keystoneclient - Add wrapper classes for return-request-id-to-caller | 19:47 |
*** sdake has joined #openstack-keystone | 19:52 | |
*** mvk has joined #openstack-keystone | 19:55 | |
*** mvk_ has quit IRC | 19:58 | |
*** lhcheng has joined #openstack-keystone | 19:59 | |
*** ChanServ sets mode: +v lhcheng | 19:59 | |
*** lhcheng_ has quit IRC | 19:59 | |
*** ametts has quit IRC | 20:00 | |
dstanek | dolphm: shore | 20:01 |
dstanek | dolphm: i still think that's a terrible idea | 20:02 |
dolphm | dstanek: the approach or the idea? | 20:02 |
dstanek | dolphm: the idea of adding an attribute to a builtin type | 20:03 |
dstanek | i think it was bknudson that had the idea to have different return values based on a flag to the client. then deprecate the old way | 20:03 |
*** pnavarro has quit IRC | 20:03 | |
dstanek | not only is it terrible OOP, but imo it would be too easy to keep creating bugs like list(list_with_id) | 20:04 |
*** julim has joined #openstack-keystone | 20:07 | |
dolphm | dstanek: different return values? | 20:08 |
*** roxanagh_ has quit IRC | 20:08 | |
dstanek | a list or boolean for backward compat, but a response object of some sort if you ask for it | 20:09 |
dstanek | that way we can properly relay metadata like: was this a cached response, etc | 20:10 |
notmorgan | the adding of attributes to base objects in python just makes me cry a little | 20:10 |
shewless | dstanek: hey I didn't forget about you. I just haven't had much luck. I hacked the metadata to say port 5000 for everything and I get a slightly different error but mostly just banging into brick walls | 20:12 |
*** ametts has joined #openstack-keystone | 20:15 | |
*** lhcheng has quit IRC | 20:17 | |
*** lhcheng has joined #openstack-keystone | 20:19 | |
*** ChanServ sets mode: +v lhcheng | 20:19 | |
dstanek | shewless: why not try to get a public instance working against testshib as a starting point? | 20:21 |
*** lhcheng has quit IRC | 20:24 | |
shewless | dstanek: I suppose that may be a good idea. any recommendations of a free cloud service to use? :) | 20:24 |
*** ametts has quit IRC | 20:30 | |
dstanek | shewless: i don't know of any free ones. i work at rackspace so i use theirs. | 20:33 |
dstanek | shewless: you should be able to experiment for just a few bucks though | 20:33 |
shewless | dstanek: cool. I might just create a shib IDP at my work so I can own both sides.. we'll see. thanks for all of your help so far | 20:40 |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 20:41 |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 20:42 |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password history requirements https://review.openstack.org/328339 | 20:42 |
*** iurygregory has quit IRC | 20:43 | |
*** ayoung has quit IRC | 20:49 | |
*** pauloewerton has quit IRC | 20:49 | |
*** adrian_otto has joined #openstack-keystone | 20:52 | |
*** tonytan_brb has joined #openstack-keystone | 20:53 | |
*** tonytan4ever has quit IRC | 20:54 | |
*** tonytan_brb is now known as tonytan4ever | 20:54 | |
*** roxanaghe has joined #openstack-keystone | 20:55 | |
*** lhcheng has joined #openstack-keystone | 21:00 | |
*** ChanServ sets mode: +v lhcheng | 21:00 | |
*** edmondsw has joined #openstack-keystone | 21:00 | |
edmondsw | ayoung notmorgan samueldmq I think everyone's misunderstanding https://review.openstack.org/#/c/327358 | 21:01 |
edmondsw | please see my response | 21:01 |
notmorgan | edmondsw: if list_user_groups is ever called outside of delete, you can't remove the filter | 21:02 |
notmorgan | edmondsw: you can provide a swtich to not filter where you need it | 21:02 |
notmorgan | edmondsw: but iirc that is not something we can just dump filter on. | 21:02 |
edmondsw | notmorgan, a) it's not and b) that would depend on how this theoretical caller worked | 21:02 |
*** roxanaghe has quit IRC | 21:02 | |
notmorgan | edmondsw: also i do want to ask, is this a bug in liberty as well? | 21:03 |
edmondsw | yes | 21:03 |
*** roxanaghe has joined #openstack-keystone | 21:03 | |
notmorgan | blah | 21:03 |
*** KevinE_ has quit IRC | 21:03 | |
notmorgan | if it was only newton/mitaka i'd probably say "meh" | 21:03 |
*** lhcheng has quit IRC | 21:05 | |
edmondsw | notmorgan looks like it's even in kilo | 21:05 |
notmorgan | yeah but kilo is EOLing | 21:06 |
notmorgan | so, i don't think we'll land the patch before kilo is dead. | 21:07 |
edmondsw | list_user_groups_filtered is the method you should call (and that other places do call) when you want filtering... | 21:07 |
notmorgan | so see my comment. i reversed my -1 | 21:07 |
edmondsw | you don't have to pass hints to call that... if you don't want hints, say None | 21:07 |
notmorgan | basically i think this is a clear mixed use backend/manually edited/managed so keystone isn't really being authoritative to it's data store | 21:08 |
notmorgan | i can see how you land here but ugh. | 21:08 |
edmondsw | yeah, I agree with that | 21:08 |
edmondsw | easiest way to land here would be to run one way for a while, then at some point change the group_filter conf setting | 21:08 |
notmorgan | edmondsw: yeah as i said in my comment | 21:09 |
notmorgan | which... is very likely to just totally hork everything anyway | 21:09 |
notmorgan | edmondsw: are you really hitting this? | 21:10 |
notmorgan | edmondsw: i mean, you've seen this in the wild? | 21:10 |
edmondsw | no, I saw it while I was fixing something different that I was hitting, and thought I was trying to be a good citizen | 21:10 |
notmorgan | edmondsw: phew | 21:10 |
notmorgan | :) | 21:10 |
notmorgan | ok | 21:10 |
notmorgan | i was worried that we had a bigger issue | 21:10 |
edmondsw | I'm not stupid enough to use keystone for read/write LDAP... ;) | 21:11 |
notmorgan | so i'm inclined to accept this for the logging / not bail out stuff. | 21:11 |
notmorgan | but if someone hits this in the wild i'm going to ask how broken their systems are / have been | 21:11 |
notmorgan | ;) | 21:11 |
edmondsw | sure :) | 21:11 |
stevemar | edmondsw: i was wondering why you brought up that bug :) | 21:11 |
notmorgan | edmondsw: i was also going to prod you on how you got wedged into that scenario if you were really troubleshooting it from a "broken prod system" | 21:12 |
edmondsw | Next time I should probably start the bug with NOTE: I'M NOT STUPID ENOUGH TO ACTUALLY GET MYSELF INTO THIS SITUATION BUT I NOTICED... | 21:12 |
stevemar | :) | 21:12 |
stevemar | its all we ask! | 21:12 |
notmorgan | edmondsw: so, i would easily +2 just the logging fixes not bail out- and i'm "ok" with accepting the fix as is. | 21:12 |
notmorgan | but fwiw it's very edge-case-y | 21:13 |
edmondsw | sure | 21:13 |
*** itlinux has quit IRC | 21:13 | |
notmorgan | and i would say "lets not even bother backporting" unless you feel very strongly about it. which means... do we need to fix it? | 21:13 |
notmorgan | and if you're feeling strong enough about it to warrant a real fix + backports. i'll say "sure" | 21:13 |
notmorgan | (and you're going to backport it) | 21:14 |
* notmorgan lets edmondsw decide :) | 21:14 | |
notmorgan | stevemar: (see what i did there? :P) | 21:14 |
edmondsw | I just wanted to throw up the fix, as I said, to be a good citizen. | 21:15 |
stevemar | let's just accept it :) | 21:15 |
edmondsw | personally I would merge it into master, so we have it and don't have someone else seeing this either in review or in the field | 21:15 |
notmorgan | stevemar: wfm, though someone else has to backport | 21:15 |
edmondsw | but not backport... it can get backported if someone actually hits it and needs it backported | 21:16 |
notmorgan | i'll thats my contingency for accepting it. | 21:16 |
*** gagehugo has quit IRC | 21:16 | |
notmorgan | because lets be fair, write ldap dies next cycle ;) | 21:16 |
edmondsw | finally! | 21:16 |
notmorgan | now... if steve +2s you don't need my approval | 21:16 |
notmorgan | and no backport needed, since dolph +2'd | 21:16 |
edmondsw | come on stevemar! | 21:17 |
* notmorgan tosses stevemar under that bus. | 21:17 | |
stevemar | edmondsw: i haven't looked at the code yet, just glanced at the bug and i assumed you fixed it | 21:18 |
stevemar | edmondsw: give me a few, i | 21:18 |
edmondsw | np | 21:18 |
stevemar | i'm setting up a new slack channel, again | 21:18 |
*** lhcheng has joined #openstack-keystone | 21:20 | |
*** ChanServ sets mode: +v lhcheng | 21:20 | |
mnaser | is there any way of creating a token under a certain user/tenant without access to their credentials (as an admin of course) | 21:22 |
*** browne has joined #openstack-keystone | 21:24 | |
*** roxanaghe has quit IRC | 21:25 | |
stevemar | mnaser: not really | 21:25 |
edmondsw | mnaser I sure hope not | 21:25 |
stevemar | mnaser: like if i was an admin, i could create a token for you and hand it over? | 21:26 |
lbragstad | like "as an admin, i'm going to create a token for user john.smith and give it to them"? | 21:27 |
*** jorge_munoz has quit IRC | 21:28 | |
dolphm | mnaser: trusts with impersonation let you do that, but the resulting tokens are flagged as such | 21:29 |
mnaser | correct to what lbragstad said | 21:30 |
*** itlinux has joined #openstack-keystone | 21:30 | |
mnaser | i guess the use case is we want to pass on a token to our control panel for it to do what it has to do | 21:30 |
mnaser | and the user is already authenticated by our billing system, and we know user A => tenant ABC | 21:30 |
*** Guest5 has quit IRC | 21:32 | |
mnaser | i guess unless we implement an auth driver to auth with our billing, but i prefer not to touch internals of keystone | 21:33 |
mnaser | also another use case is when we terminate tenants, we have a very (annoying and risky) system that gets all resources by using things like all_tenants and then filtering down, this could be ultra scary if something goes wrong | 21:35 |
*** ddieterly is now known as ddieterly[away] | 21:35 | |
mnaser | if we can scope in as a user, life would be much easier | 21:35 |
*** sdake has quit IRC | 21:36 | |
*** sdake has joined #openstack-keystone | 21:41 | |
edmondsw | notmorgan, since you brought up backporting... here's the review for my backport of the much more significant issue that led me to the LDAP read/write one were were just discussing | 21:42 |
edmondsw | https://review.openstack.org/#/c/327703/ | 21:42 |
patchbot | edmondsw: patch 327703 - keystone (stable/mitaka) - Honor ldap_filter on filtered group list | 21:42 |
dstanek | shewless: i think i can get my hands on an adfs server for testing. i'll let you know if i have trouble | 21:43 |
*** sdake_ has joined #openstack-keystone | 21:43 | |
*** sdake has quit IRC | 21:45 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 21:49 | |
*** itlinux has quit IRC | 21:50 | |
*** spandhe has joined #openstack-keystone | 21:51 | |
*** rderose has quit IRC | 21:53 | |
*** edmondsw has quit IRC | 21:53 | |
*** roxanaghe has joined #openstack-keystone | 21:58 | |
*** gabriel-bezerra has joined #openstack-keystone | 21:59 | |
gabriel-bezerra | hi folks, I'm trying to run a devstack with kilo version for some backporting work but am facing an issue with pycadf version | 21:59 |
gabriel-bezerra | The 'pycadf<0.9.0,>=0.8.0' distribution was not found and is required by keystone | 22:00 |
*** ddieterly[away] is now known as ddieterly | 22:00 | |
gabriel-bezerra | pip search pycadf shows version 2.3.0 installed | 22:01 |
*** dave-mccowan has quit IRC | 22:02 | |
bknudson | that's way too new | 22:05 |
bknudson | gabriel-bezerra: I think you might have to check out the right level of /opt/stack/requirements? I had this problem earlier this week but already forgot how I worked around it. | 22:05 |
*** catintheroof has quit IRC | 22:06 | |
bknudson | I probably tried pip installing the right version... but then I feel like that didn't work... | 22:06 |
gabriel-bezerra | bknudson: I could just find this conflict... | 22:07 |
gabriel-bezerra | /opt/stack/keystone/requirements.txt:35:pycadf<0.9.0,>=0.8.0 | 22:07 |
gabriel-bezerra | /opt/stack/requirements/global-requirements.txt:143:pycadf>=1.1.0,!=2.0.0 # Apache-2.0 | 22:07 |
gabriel-bezerra | yes, pip installing didn't work :( | 22:07 |
gabriel-bezerra | I'll check if my branch version for requirments is right | 22:08 |
*** pushkaru has quit IRC | 22:08 | |
gabriel-bezerra | thanks for the suggestion, bknudson | 22:08 |
*** pushkaru has joined #openstack-keystone | 22:08 | |
bknudson | y, look there. | 22:08 |
*** pushkaru has quit IRC | 22:14 | |
stevemar | gabriel-bezerra: looks like your requirements aren't from the kilo version | 22:15 |
gabriel-bezerra | stevemar: yes, right that. I've just found how to specify requirements branch in local.conf | 22:18 |
gabriel-bezerra | I'll try that now | 22:18 |
gabriel-bezerra | thanks | 22:18 |
*** adrian_otto has quit IRC | 22:22 | |
*** lhcheng has quit IRC | 22:30 | |
*** pushkaru has joined #openstack-keystone | 22:33 | |
*** julim has quit IRC | 22:39 | |
*** vgridnev_ has joined #openstack-keystone | 22:41 | |
*** scarlisle has quit IRC | 22:44 | |
*** BjoernT has quit IRC | 22:46 | |
*** henrynash_ has joined #openstack-keystone | 22:49 | |
*** ChanServ sets mode: +v henrynash_ | 22:49 | |
*** timcline has quit IRC | 22:50 | |
*** timcline has joined #openstack-keystone | 22:51 | |
*** timcline has quit IRC | 22:55 | |
stevemar | lbragstad: thank you for responding to the perf. comments on the mailing list | 22:57 |
*** pushkaru has quit IRC | 22:59 | |
notmorgan | lbragstad: i added some stuff on top to flesh out a bit more in the responses. | 22:59 |
notmorgan | lbragstad: also thanks for doing the work! | 22:59 |
notmorgan | stevemar: ^ cc | 22:59 |
* stevemar nods at notmorgan | 23:00 | |
*** ddieterly has quit IRC | 23:00 | |
* notmorgan wants to go for a run... | 23:03 | |
*** adrian_otto has joined #openstack-keystone | 23:16 | |
*** gordc has quit IRC | 23:22 | |
*** tonytan4ever has quit IRC | 23:27 | |
*** spandhe has quit IRC | 23:35 | |
*** spandhe has joined #openstack-keystone | 23:43 | |
*** spandhe has quit IRC | 23:52 | |
*** pgbridge has quit IRC | 23:55 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!