topol | @here is the new Keystone logo available yet? Asking for a friend | 00:00 |
---|---|---|
*** thumpba_ has joined #openstack-keystone | 00:03 | |
bknudson | get that slack out of here! | 00:03 |
*** julim has quit IRC | 00:03 | |
bknudson | henrynash: I tried renaming the modules the migration worked. | 00:03 |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Allow identity plugins to discover relative version urls https://review.openstack.org/356808 | 00:04 |
jamielennox | topol: i think they were planning to show them off in barcelona - but i'm not sure where i got that impression from | 00:04 |
*** thumpba has quit IRC | 00:05 | |
bknudson | stevemar probably has a shirt with the logo already | 00:05 |
topol | bknudson whats the irc equivalent? I'm clearly old and confused.. mixing and matching across all these chat systems they make us use | 00:05 |
topol | jamielennox thanks | 00:05 |
bknudson | there is no irc equivalent to @here, luckily! | 00:05 |
topol | Ha Ha. bknudson you think you can hide | 00:05 |
bknudson | @here review this!!! | 00:06 |
bknudson | now!!! | 00:06 |
*** su_zhang has joined #openstack-keystone | 00:06 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Add expand, data migration and contract logic to keystone-manage https://review.openstack.org/349939 | 00:10 |
henrynash | bknudson: thanks for working the issues...was on a plane flight late afternoon, hence out of contact | 00:20 |
*** gyee_ has quit IRC | 00:21 | |
*** ravelar has joined #openstack-keystone | 00:22 | |
*** code-R_ has quit IRC | 00:22 | |
*** sdake has joined #openstack-keystone | 00:35 | |
*** roxanaghe has quit IRC | 00:42 | |
*** wangqun has joined #openstack-keystone | 00:46 | |
*** jamielennox is now known as jamielennox|away | 00:48 | |
*** gus has joined #openstack-keystone | 00:48 | |
*** itisha has quit IRC | 00:50 | |
*** tqtran has quit IRC | 00:54 | |
*** spzala has joined #openstack-keystone | 00:59 | |
*** sdake has quit IRC | 00:59 | |
*** adu has quit IRC | 01:00 | |
*** sdake has joined #openstack-keystone | 01:02 | |
*** spzala has quit IRC | 01:03 | |
*** jamielennox|away is now known as jamielennox | 01:04 | |
*** code-R has joined #openstack-keystone | 01:09 | |
*** sdake has quit IRC | 01:11 | |
*** spzala has joined #openstack-keystone | 01:15 | |
*** chrichip has joined #openstack-keystone | 01:19 | |
*** wangqun_ has joined #openstack-keystone | 01:21 | |
*** su_zhang has quit IRC | 01:21 | |
*** su_zhang has joined #openstack-keystone | 01:22 | |
dolphm | henrynash: are you back home now? | 01:23 |
*** wangqun has quit IRC | 01:25 | |
dstanek | topol: go back to slack where you belong! | 01:26 |
*** su_zhang has quit IRC | 01:26 | |
topol | dstanek, I find that truly hurtful | 01:26 |
topol | dstanek, was this hurtful atatck due to my snarky RG III comment? | 01:27 |
topol | If so... then I understand dstanek | 01:27 |
dstanek | topol: no, i've learned to live with bad browns decisions | 01:27 |
dstanek | i get to go tomorrow night to spend more money on beers that i probably should | 01:28 |
*** EinstCrazy has joined #openstack-keystone | 01:32 | |
*** EinstCrazy has quit IRC | 01:32 | |
*** EinstCra_ has joined #openstack-keystone | 01:33 | |
topol | dstanek AWESOME!!! Have fun!!! | 01:33 |
*** code-R has quit IRC | 01:37 | |
*** spzala has quit IRC | 01:38 | |
*** spzala has joined #openstack-keystone | 01:39 | |
*** edmondsw has quit IRC | 01:40 | |
*** hockeynut has joined #openstack-keystone | 01:41 | |
*** Guest81529 has quit IRC | 01:42 | |
*** spzala has quit IRC | 01:43 | |
*** haplo37__ has joined #openstack-keystone | 01:50 | |
*** tqtran has joined #openstack-keystone | 01:51 | |
*** thumpba_ has quit IRC | 01:52 | |
stevemar | o/ | 01:53 |
*** tqtran has quit IRC | 01:56 | |
*** dikonoor has joined #openstack-keystone | 02:02 | |
dolphm | stevemar: go to bed | 02:02 |
stevemar | dolphm: :O | 02:02 |
stevemar | dolphm: k mom | 02:02 |
stevemar | :) | 02:02 |
stevemar | dolphm: i took the evening off, went to play baseball | 02:02 |
stevemar | and now watching olympics | 02:02 |
*** EinstCrazy has joined #openstack-keystone | 02:03 | |
*** davechen has joined #openstack-keystone | 02:04 | |
dstanek | for some definition of fun | 02:06 |
*** EinstCra_ has quit IRC | 02:07 | |
stevemar | dstanek: heyo! | 02:07 |
dstanek | oh man. that's what i get for using 'git add -p' | 02:07 |
dstanek | stevemar: howdy | 02:08 |
stevemar | dstanek: ahoy partner | 02:09 |
openstackgerrit | David Stanek proposed openstack/keystone: Add test for revocation corner case in Fernet https://review.openstack.org/356607 | 02:09 |
dstanek | that's embarrassing :-( | 02:09 |
*** neophy has joined #openstack-keystone | 02:13 | |
stevemar | dstanek: what did ya do? | 02:13 |
*** chrichip has quit IRC | 02:13 | |
*** chrichip has joined #openstack-keystone | 02:15 | |
dstanek | stevemar: when i used 'git add -p' i forgot to add the import to the commit - i used -p so that i could avoid pulling in all of my logging | 02:17 |
stevemar | ah | 02:17 |
*** haplo37__ has quit IRC | 02:20 | |
*** thumpba has joined #openstack-keystone | 02:23 | |
*** EinstCra_ has joined #openstack-keystone | 02:27 | |
*** EinstCrazy has quit IRC | 02:29 | |
*** arunkant__ has joined #openstack-keystone | 02:36 | |
*** arunkant_ has quit IRC | 02:39 | |
*** eandersson_ has joined #openstack-keystone | 02:40 | |
*** jamielennox is now known as jamielennox|away | 02:42 | |
*** chrichip has quit IRC | 02:45 | |
*** chrichip has joined #openstack-keystone | 02:47 | |
*** eandersson_ has quit IRC | 02:47 | |
*** spzala has joined #openstack-keystone | 03:00 | |
*** julim has joined #openstack-keystone | 03:05 | |
*** spzala has quit IRC | 03:05 | |
*** hockeynut has quit IRC | 03:06 | |
*** jamielennox|away is now known as jamielennox | 03:07 | |
*** asettle has joined #openstack-keystone | 03:08 | |
*** thumpba has quit IRC | 03:15 | |
*** asettle has quit IRC | 03:16 | |
*** julim has quit IRC | 03:19 | |
openstackgerrit | Merged openstack/keystone: api-ref: Document domain specific roles https://review.openstack.org/356169 | 03:34 |
*** tonytan4ever has joined #openstack-keystone | 03:36 | |
*** code-R has joined #openstack-keystone | 03:38 | |
*** ravelar has quit IRC | 03:40 | |
*** code-R has quit IRC | 03:43 | |
*** links has joined #openstack-keystone | 03:45 | |
*** code-R has joined #openstack-keystone | 03:47 | |
*** vivek has joined #openstack-keystone | 03:49 | |
*** vivek is now known as Guest82967 | 03:49 | |
*** code-R_ has joined #openstack-keystone | 03:50 | |
Guest82967 | hi | 03:50 |
Guest82967 | does the wildcard * work with cors? | 03:50 |
Guest82967 | I know it is not recommended but in dev environment it will be useful... | 03:50 |
Guest82967 | i tried modifying the kestone.conf for the same but failed... | 03:52 |
*** code-R has quit IRC | 03:52 | |
*** tqtran has joined #openstack-keystone | 03:52 | |
*** tqtran has quit IRC | 03:56 | |
*** spzala has joined #openstack-keystone | 04:01 | |
*** code-R_ has quit IRC | 04:04 | |
*** tonytan4ever has quit IRC | 04:05 | |
*** spzala has quit IRC | 04:07 | |
*** Trixboxer has quit IRC | 04:15 | |
*** Guest82967 has quit IRC | 04:16 | |
*** wangqun_ has quit IRC | 04:17 | |
*** neophy has quit IRC | 04:19 | |
*** wangqun has joined #openstack-keystone | 04:24 | |
*** code-R has joined #openstack-keystone | 04:25 | |
*** neophy has joined #openstack-keystone | 04:26 | |
*** Trixboxer has joined #openstack-keystone | 04:28 | |
*** marekd2 has joined #openstack-keystone | 04:29 | |
*** marekd2 has quit IRC | 04:35 | |
*** code-R has quit IRC | 04:38 | |
*** Ephur has quit IRC | 04:38 | |
*** code-R has joined #openstack-keystone | 04:38 | |
*** su_zhang has joined #openstack-keystone | 04:42 | |
*** dikonoor has quit IRC | 04:46 | |
openstackgerrit | Merged openstack/keystone: Extracted common ldap setup and use in the filter tests https://review.openstack.org/334063 | 04:53 |
openstackgerrit | Merged openstack/keystone: Removes duplicate ldap test setup https://review.openstack.org/334064 | 04:53 |
*** chrichip has quit IRC | 04:53 | |
*** chrichip has joined #openstack-keystone | 04:53 | |
*** code-R has quit IRC | 04:59 | |
*** spzala has joined #openstack-keystone | 05:00 | |
stevemar | henrynash: if you have time: https://review.openstack.org/#/c/350704/2 https://review.openstack.org/#/c/356596/1 and https://review.openstack.org/#/c/356597/1 are all blocking the caching work :) | 05:02 |
patchbot | stevemar: patch 350704 - keystone - Make all token provider behave the same with trusts | 05:02 |
patchbot | stevemar: patch 356596 - keystone - Removes a redundant test from FernetAuthWithTrust | 05:02 |
patchbot | stevemar: patch 356597 - keystone - Removes use of freezegun in test_auth tests | 05:02 |
*** jaosorior has joined #openstack-keystone | 05:03 | |
*** spzala has quit IRC | 05:06 | |
*** tonytan4ever has joined #openstack-keystone | 05:06 | |
*** tonytan4ever has quit IRC | 05:11 | |
*** code-R has joined #openstack-keystone | 05:15 | |
*** eandersson_ has joined #openstack-keystone | 05:24 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/356872 | 05:26 |
*** asettle has joined #openstack-keystone | 05:35 | |
*** asettle has quit IRC | 05:39 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/356872 | 05:50 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystoneauth: Updated from global requirements https://review.openstack.org/356928 | 05:50 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystonemiddleware: Updated from global requirements https://review.openstack.org/356929 | 05:50 |
*** roxanaghe has joined #openstack-keystone | 05:55 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements https://review.openstack.org/356940 | 05:56 |
*** roxanaghe has quit IRC | 05:59 | |
*** spzala has joined #openstack-keystone | 06:03 | |
*** dikonoor has joined #openstack-keystone | 06:05 | |
*** code-R has quit IRC | 06:05 | |
*** spzala has quit IRC | 06:07 | |
*** eandersson_ has quit IRC | 06:07 | |
*** code-R has joined #openstack-keystone | 06:08 | |
*** neophy has quit IRC | 06:08 | |
*** rcernin has joined #openstack-keystone | 06:12 | |
*** code-R_ has joined #openstack-keystone | 06:34 | |
*** code-R has quit IRC | 06:36 | |
*** adriant has quit IRC | 06:52 | |
*** pcaruana has joined #openstack-keystone | 06:52 | |
*** code-R_ has quit IRC | 06:53 | |
*** xek__ has quit IRC | 07:08 | |
*** tesseract- has joined #openstack-keystone | 07:17 | |
*** EinstCra_ has quit IRC | 07:18 | |
*** EinstCrazy has joined #openstack-keystone | 07:34 | |
*** rvba has joined #openstack-keystone | 07:40 | |
*** rvba has quit IRC | 07:40 | |
*** rvba has joined #openstack-keystone | 07:40 | |
*** roxanaghe has joined #openstack-keystone | 07:43 | |
*** roxanaghe has quit IRC | 07:47 | |
*** tqtran has joined #openstack-keystone | 07:54 | |
*** pnavarro has joined #openstack-keystone | 07:56 | |
*** tqtran has quit IRC | 07:59 | |
*** zzzeek has quit IRC | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:01 | |
*** spzala has joined #openstack-keystone | 08:04 | |
*** spzala has quit IRC | 08:08 | |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c https://review.openstack.org/318435 | 08:10 |
*** EinstCra_ has joined #openstack-keystone | 08:21 | |
*** EinstCrazy has quit IRC | 08:25 | |
*** eandersson_ has joined #openstack-keystone | 08:26 | |
*** su_zhang has quit IRC | 08:30 | |
*** su_zhang has joined #openstack-keystone | 08:31 | |
*** su_zhang has quit IRC | 08:35 | |
*** jaosorior has quit IRC | 08:37 | |
*** asettle has joined #openstack-keystone | 08:39 | |
*** jdennis has quit IRC | 08:56 | |
*** roxanaghe has joined #openstack-keystone | 08:58 | |
*** jdennis has joined #openstack-keystone | 08:59 | |
*** dkehn_ has quit IRC | 09:00 | |
*** wangqun_ has joined #openstack-keystone | 09:03 | |
*** spzala has joined #openstack-keystone | 09:04 | |
*** wangqun has quit IRC | 09:05 | |
*** d0ugal has quit IRC | 09:08 | |
*** spzala has quit IRC | 09:09 | |
*** d0ugal has joined #openstack-keystone | 09:12 | |
*** d0ugal_ has joined #openstack-keystone | 09:17 | |
*** d0ugal_ has quit IRC | 09:18 | |
*** d0ugal_ has joined #openstack-keystone | 09:18 | |
*** dkehn_ has joined #openstack-keystone | 09:19 | |
*** d0ugal has quit IRC | 09:20 | |
*** d0ugal_ has quit IRC | 09:20 | |
*** d0ugal has joined #openstack-keystone | 09:20 | |
*** roxanaghe has quit IRC | 09:21 | |
*** EinstCrazy has joined #openstack-keystone | 09:28 | |
*** mvk has quit IRC | 09:29 | |
*** EinstCra_ has quit IRC | 09:32 | |
openstackgerrit | henry-nash proposed openstack/keystone: Add expand, data migration and contract logic to keystone-manage https://review.openstack.org/349939 | 09:39 |
*** jdennis1 has joined #openstack-keystone | 09:52 | |
*** jdennis has quit IRC | 09:52 | |
*** marekd2 has joined #openstack-keystone | 09:53 | |
*** asettle has quit IRC | 09:55 | |
*** asettle has joined #openstack-keystone | 09:55 | |
*** d0ugal has quit IRC | 09:58 | |
*** mvk has joined #openstack-keystone | 09:59 | |
samueldmq | morning keystone | 10:01 |
samueldmq | henrynash: hi, where may I start reviewing this rolling upgrade thing | 10:02 |
samueldmq | ? | 10:02 |
breton | morning | 10:04 |
*** d0ugal has joined #openstack-keystone | 10:04 | |
*** mvk has quit IRC | 10:05 | |
*** spzala has joined #openstack-keystone | 10:05 | |
*** NishaYadav has joined #openstack-keystone | 10:07 | |
NishaYadav | o/ | 10:07 |
NishaYadav | samueldmq, morning | 10:08 |
NishaYadav | stevemar, morning, just saw your comments on the patches, thanks a lot :) | 10:09 |
*** spzala has quit IRC | 10:10 | |
*** davechen has left #openstack-keystone | 10:15 | |
*** mvk has joined #openstack-keystone | 10:20 | |
*** NishaYadav has quit IRC | 10:20 | |
*** nishaYadav has joined #openstack-keystone | 10:20 | |
samueldmq | nishaYadav: morning | 10:25 |
samueldmq | nishaYadav: it would be nice to fix the docs for the EC2 entity | 10:28 |
samueldmq | https://github.com/openstack/python-keystoneclient/blob/master/keystoneclient/v3/ec2.py#L16 | 10:28 |
nishaYadav | samueldmq, sure, will do that in a follow up patch | 10:29 |
samueldmq | nishaYadav: cool, the docs were wrong, so I was very confused on what was causing the failure | 10:30 |
samueldmq | thanks to stevemar o/ | 10:30 |
nishaYadav | ++ :) | 10:31 |
*** EinstCrazy has quit IRC | 10:32 | |
*** code-R has joined #openstack-keystone | 10:33 | |
*** code-R_ has joined #openstack-keystone | 10:40 | |
*** code-R has quit IRC | 10:43 | |
*** roxanaghe has joined #openstack-keystone | 10:45 | |
*** roxanaghe has quit IRC | 10:50 | |
*** amakarov_away is now known as amakarov | 10:53 | |
*** code-R_ has quit IRC | 10:57 | |
*** code-R has joined #openstack-keystone | 10:57 | |
openstackgerrit | Nisha Yadav proposed openstack/python-keystoneclient: Follow up patch for Improve docs for v3 ec2 https://review.openstack.org/357106 | 10:58 |
nishaYadav | samueldmq, ^ please have a look | 10:59 |
samueldmq | nishaYadav: reviewed | 11:02 |
nishaYadav | samueldmq, thanks | 11:05 |
*** spzala has joined #openstack-keystone | 11:06 | |
*** neophy has joined #openstack-keystone | 11:08 | |
*** neophy has quit IRC | 11:09 | |
*** spzala has quit IRC | 11:11 | |
*** spzala has joined #openstack-keystone | 11:23 | |
*** spzala has quit IRC | 11:23 | |
*** asettle has quit IRC | 11:25 | |
*** asettle has joined #openstack-keystone | 11:26 | |
*** GB21 has joined #openstack-keystone | 11:28 | |
openstackgerrit | Merged openstack/python-keystoneclient: Add ec2 functional tests https://review.openstack.org/350245 | 11:29 |
openstackgerrit | Nisha Yadav proposed openstack/python-keystoneclient: Improve docs for v3 tokens https://review.openstack.org/357136 | 11:37 |
nishaYadav | samueldmq, please have a look ^ | 11:38 |
*** code-R has quit IRC | 11:38 | |
*** code-R has joined #openstack-keystone | 11:38 | |
*** haplo37__ has joined #openstack-keystone | 11:42 | |
samueldmq | nishaYadav: reviewed | 11:43 |
samueldmq | nishaYadav: just a couple of minor suggestions .. | 11:43 |
nishaYadav | samueldmq, sure thanks :) | 11:43 |
*** su_zhang has joined #openstack-keystone | 11:43 | |
openstackgerrit | Nisha Yadav proposed openstack/python-keystoneclient: Follow up patch for Improve docs for v3 ec2 https://review.openstack.org/357106 | 11:44 |
nishaYadav | samueldmq, did the changes to former patch | 11:44 |
*** roxanaghe has joined #openstack-keystone | 11:46 | |
*** su_zhang has quit IRC | 11:48 | |
*** code-R has quit IRC | 11:49 | |
*** nishaYadav has quit IRC | 11:50 | |
*** ayoung has quit IRC | 11:50 | |
*** roxanaghe has quit IRC | 11:50 | |
*** tqtran has joined #openstack-keystone | 11:56 | |
*** jpena is now known as jpena|lunch | 12:00 | |
*** tqtran has quit IRC | 12:00 | |
*** code-R has joined #openstack-keystone | 12:03 | |
*** amoralej is now known as amoralej|lunch | 12:08 | |
*** woodster_ has joined #openstack-keystone | 12:10 | |
*** edmondsw has joined #openstack-keystone | 12:15 | |
*** haplo37__ has quit IRC | 12:21 | |
*** wangqun_ has quit IRC | 12:21 | |
*** mvk has quit IRC | 12:21 | |
*** spzala has joined #openstack-keystone | 12:24 | |
*** code-R has quit IRC | 12:24 | |
*** pauloewerton has joined #openstack-keystone | 12:25 | |
*** gordc has joined #openstack-keystone | 12:27 | |
*** spzala has quit IRC | 12:29 | |
*** asettle has quit IRC | 12:34 | |
*** asettle has joined #openstack-keystone | 12:34 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements https://review.openstack.org/356940 | 12:40 |
*** rodrigods has quit IRC | 12:48 | |
*** rodrigods has joined #openstack-keystone | 12:48 | |
*** julim has joined #openstack-keystone | 12:53 | |
*** jpena|lunch is now known as jpena | 12:55 | |
*** raildo has joined #openstack-keystone | 13:00 | |
*** code-R has joined #openstack-keystone | 13:05 | |
*** amoralej|lunch is now known as amoralej | 13:08 | |
*** code-R_ has joined #openstack-keystone | 13:09 | |
*** code-R has quit IRC | 13:13 | |
*** links has quit IRC | 13:16 | |
*** richm has joined #openstack-keystone | 13:17 | |
*** thumpba has joined #openstack-keystone | 13:17 | |
*** adu has joined #openstack-keystone | 13:19 | |
*** ametts has joined #openstack-keystone | 13:20 | |
dikonoor | dstanek: Hi,I have few queries around the shadow user blueprint | 13:28 |
dikonoor | dstanek:https://specs.openstack.org/openstack/keystone-specs/specs/keystone/newton/shadow-users-newton.html | 13:28 |
dikonoor | dstanek: First, the spec says -"Refactor user table into an identity table and a locally-managed password table. Migrate data from the user table to these new tables and ultimately remove the user table. Modify backend code to utilize the new tables." | 13:30 |
lbragstad | dstanek rderose dolphm stevemar samueldmq after collecting my thoughts - I attempted to summarize yesterday's conversation here - https://review.openstack.org/#/c/354495/6 | 13:30 |
patchbot | lbragstad: patch 354495 - keystone - Add conf to support credential encryption | 13:30 |
dikonoor | dstanek:dolphm: However, i don't see a table named "identity" at all | 13:31 |
dikonoor | dstanek:dolphm: Second, when I configure openstack with ldap, there are entries created in user , local_user and nonlocal_user table and lot of information seems to be duplicated across the tables. | 13:32 |
dikonoor | dstanek:dolphm:I read the mitaka and newton specs and I am not completely clear on why we have it this way. | 13:33 |
dikonoor | anyone else who might have the answers ? | 13:35 |
*** BigWillie has joined #openstack-keystone | 13:39 | |
*** spzala has joined #openstack-keystone | 13:42 | |
*** ezpz has joined #openstack-keystone | 13:42 | |
openstackgerrit | Mikhail Nikolaenko proposed openstack/keystone: [WIP] Move fernet utils to backend https://review.openstack.org/356499 | 13:43 |
dstanek | dikonoor: there is no idenity table | 13:43 |
dstanek | even for ldap users there will be a record in the user table | 13:44 |
dikonoor | dstanek: and guess there will be no identity table in future as well.. | 13:44 |
dikonoor | dstanek: and user table will eventually go away? | 13:44 |
dstanek | dikonoor: the user table will not be going away | 13:45 |
dstanek | dikonoor: the second paragraph in the spec does a decent job of describing why we want this change | 13:47 |
dikonoor | dstanek: i will take a look at the code and get back. I am not sure I understand why we need entries in user, local and nonlocal tables | 13:47 |
dstanek | you shouldn't get records in all those tables for an ldap user | 13:49 |
*** BjoernT has joined #openstack-keystone | 13:49 | |
dikonoor | dstanek: what are the tables that should be updated for a ldap user? | 13:50 |
dstanek | dikonoor: although all users will have two records a user plus one of the other | 13:50 |
dstanek | probably user and nonlocal_User | 13:51 |
dikonoor | dstanek: well, thats what i thought it should be | 13:52 |
dstanek | are you seeing something different? | 13:52 |
*** adu has quit IRC | 13:53 | |
dikonoor | dstanek: i initially thought there would be entries in user , password and local_user table for sql users; user and nonlocal_user entries for ldap and custom drivers; | 13:53 |
dikonoor | and entries in user and federated_user for federated users | 13:53 |
dikonoor | but i see entries in user, local_user and nonlocal_user for custom and ldap users; i haven't tried sql and federated users.. | 13:54 |
samueldmq | lbragstad: hi | 13:54 |
samueldmq | lbragstad: why do we need 'database triggers that disables credential create or update' ? | 13:54 |
dikonoor | dstanek: and that's why I got confused. but if you say that's not expected, then let me try it again just so that i can confirm (and open a bug) | 13:55 |
samueldmq | lbragstad: just create triggers to put the data in both columns, and both mitaka and newton code will work correctly | 13:55 |
lbragstad | samueldmq otherwise we run into an issue where the database triggers will copy incorrect data from one column to another | 13:55 |
lbragstad | samueldmq mitaka code won't understand encrypted data | 13:55 |
dstanek | dikonoor: what you said is exactly what i expect to see | 13:55 |
lbragstad | samueldmq and if we want to provide sane default for keystone.conf out of the box - we should make it so newton code only understand encrypted data | 13:56 |
samueldmq | lbragstad: and we don't want to put any logic in keystone | 13:56 |
samueldmq | to duplicate the data | 13:56 |
samueldmq | lbragstad: I agree with your comment there then | 13:56 |
dikonoor | dstanek: ok..thanks for confirming that..I will try and get back | 13:56 |
lbragstad | samueldmq the simplest resolution we found was for force a limited service outage for credentials during the upgrade | 13:57 |
lbragstad | was to force* | 13:57 |
*** edtubill has joined #openstack-keystone | 13:57 | |
*** ayoung has joined #openstack-keystone | 13:57 | |
*** ChanServ sets mode: +v ayoung | 13:57 | |
lbragstad | otherwise copying data back and forth started to become a nightmare | 13:57 |
*** itisha has joined #openstack-keystone | 13:57 | |
openstackgerrit | Eduardo Magalhães proposed openstack/python-keystoneclient: Fix no content return type doc https://review.openstack.org/357236 | 13:58 |
openstackgerrit | Rodrigo Duarte proposed openstack/python-keystoneclient: Fix no content return type doc https://review.openstack.org/357236 | 14:00 |
samueldmq | notmorgan: hey | 14:04 |
*** EinstCrazy has joined #openstack-keystone | 14:04 | |
samueldmq | notmorgan: do you have anything for https://blueprints.launchpad.net/keystone/+spec/serviceid-binding-with-role-definition ? | 14:04 |
samueldmq | nonameentername: there is a commet from you there, as it was supposed to be updated with something after the kilo summit | 14:04 |
samueldmq | nonameentername: not you, notmorgan ^ | 14:04 |
samueldmq | notmorgan: I think that bp is not valid anymore | 14:04 |
*** arunkant__ has quit IRC | 14:07 | |
*** edtubill has quit IRC | 14:10 | |
*** edtubill has joined #openstack-keystone | 14:17 | |
*** asettle has quit IRC | 14:20 | |
*** edtubill has quit IRC | 14:20 | |
*** asettle has joined #openstack-keystone | 14:21 | |
*** asettle has quit IRC | 14:21 | |
*** asettle has joined #openstack-keystone | 14:21 | |
*** edtubill has joined #openstack-keystone | 14:24 | |
*** ravelar has joined #openstack-keystone | 14:25 | |
*** edtubill has quit IRC | 14:27 | |
samueldmq | rderose: hi | 14:28 |
*** haplo37__ has joined #openstack-keystone | 14:28 | |
samueldmq | rderose: can you look at my comment in 351749 ? | 14:28 |
rderose | samueldmq: hey | 14:28 |
rderose | sure | 14:28 |
samueldmq | rderose: hey :) | 14:28 |
*** ravelar has quit IRC | 14:28 | |
samueldmq | rderose: I think that's ready to go | 14:28 |
samueldmq | rderose: looks like that and 343314 are the last ones | 14:29 |
*** gagehugo_ has joined #openstack-keystone | 14:29 | |
*** ravelar has joined #openstack-keystone | 14:29 | |
rderose | samueldmq: yeah, it's definitely a more descriptive name | 14:30 |
rderose | samueldmq: let me change it | 14:30 |
ayoung | rderose, samueldmq what is burning and needs my attention? I've been slacking on reviews, and you guys have been cranking | 14:30 |
rderose | ayoung: how about: https://review.openstack.org/#/c/343314/ | 14:31 |
patchbot | rderose: patch 343314 - keystone - PCI-DSS Minimum password age requirements | 14:31 |
ayoung | rderose, how long was password_change_limit_per_day in there? | 14:33 |
rderose | ayoung: not long, we just added it in Newton | 14:34 |
ayoung | So safe to replace | 14:34 |
rderose | ayoung: yes | 14:34 |
*** edtubill has joined #openstack-keystone | 14:34 | |
rderose | ayoung: yeah, that feature was never implemented, was just the initial idea | 14:34 |
ayoung | ++ | 14:34 |
*** jed56 has quit IRC | 14:35 | |
*** jdennis has joined #openstack-keystone | 14:35 | |
ayoung | rderose, I thought passwords were going into their own table now? | 14:35 |
ayoung | user_ref = session.query(model.User).get(user_id) | 14:35 |
ayoung | still in the user? | 14:35 |
*** jdennis1 has quit IRC | 14:35 | |
rderose | ayoung: they are | 14:35 |
rderose | ayoung: the user model includes a password ref list | 14:36 |
rderose | ayoung: so user -> local_user -> password | 14:36 |
ayoung | rderose, sql alchemy doing the join? | 14:36 |
rderose | ayoung: yes | 14:36 |
ayoung | rderose, do you ahve a test that ensures that everything works if the min age is not set? | 14:37 |
rderose | ayoung: yes | 14:37 |
ayoung | which one? | 14:37 |
rderose | https://review.openstack.org/#/c/343314/50/keystone/tests/unit/test_v3_identity.py | 14:38 |
patchbot | rderose: patch 343314 - keystone - PCI-DSS Minimum password age requirements | 14:38 |
rderose | ayoung: ^ | 14:38 |
ayoung | rderose, lookin | 14:38 |
ayoung | test_admin_password_reset_with_min_password_age_enabled | 14:38 |
rderose | ayoung: sorry, misread | 14:38 |
ayoung | test_changing_password_with_min_password_age( | 14:38 |
rderose | ayoung: everything still works when min age is disabled? | 14:39 |
ayoung | rderose, I am trying to confirm we won't break people that do not have a value set here | 14:39 |
samueldmq | rderose: ayoung brb gotta pick up kid at school | 14:39 |
rderose | ayoung: it's disabled by default | 14:39 |
*** su_zhang has joined #openstack-keystone | 14:39 | |
ayoung | rderose, probably still should be explicitly tested. | 14:39 |
*** spedione|AWAY is now known as spedione | 14:39 | |
ayoung | rderose, its probably OK as is, but look through and find another test that implicitly tests it, would you? | 14:40 |
rderose | ayoung: test_changing_password_with_min_password_age does disable and then tests change_password | 14:41 |
rderose | ayoung: in test_v3_identity.py | 14:41 |
*** edtubill has quit IRC | 14:41 | |
*** d0ugal has quit IRC | 14:41 | |
ayoung | rderose, +2 from me | 14:42 |
ayoung | looks well reviewed and thought out | 14:42 |
rderose | ayoung: sweet! thanks :) | 14:43 |
*** edtubill has joined #openstack-keystone | 14:44 | |
rderose | ayoung: Glad to finally have your input on some of the PCI. I know you've been meaning to weight in, but have been busy. Thanks. | 14:45 |
ayoung | rderose, any others? | 14:45 |
rderose | ayoung: for PCI, no. all of the others have been merged | 14:46 |
*** edtubill has quit IRC | 14:47 | |
*** jaugustine has quit IRC | 14:47 | |
*** edtubill has joined #openstack-keystone | 14:47 | |
*** xenogear has quit IRC | 14:47 | |
*** d0ugal has joined #openstack-keystone | 14:48 | |
*** d0ugal has quit IRC | 14:48 | |
*** d0ugal has joined #openstack-keystone | 14:48 | |
*** nk2527_ has quit IRC | 14:49 | |
*** gagehugo has quit IRC | 14:49 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: Password expires ignore user list https://review.openstack.org/351749 | 14:51 |
*** dmellado|off is now known as dmellado | 14:52 | |
*** tonytan4ever has joined #openstack-keystone | 14:57 | |
rderose | ayoung: ^ this one is not PCI, but related | 14:57 |
*** edtubill has quit IRC | 14:58 | |
samueldmq | rderose: oh 343314 is gating already | 14:59 |
*** edtubill has joined #openstack-keystone | 14:59 | |
samueldmq | rderose: so the bp will be considered implemented after 351749? | 15:00 |
*** michauds has joined #openstack-keystone | 15:00 | |
rderose | samueldmq: yeah, hallelooya! | 15:00 |
rderose | samueldmq: however, 351749 is not PCI, however stevemar tied it to the blueprint | 15:01 |
ayoung | rderose, +2A | 15:01 |
rderose | samueldmq: 343314 is really the last PCI patch, 351749 is just the icing on the cake :) | 15:02 |
rderose | ayoung: sweet! | 15:02 |
*** xenogear has joined #openstack-keystone | 15:02 | |
samueldmq | rderose: changed https://blueprints.launchpad.net/keystone/+spec/pci-dss to implemented | 15:03 |
samueldmq | rderose: well done! | 15:03 |
*** hockeynut has joined #openstack-keystone | 15:04 | |
rderose | samueldmq: thanks! appreciate your reviews :) glad to finally have this off my plate | 15:04 |
samueldmq | \o/ | 15:05 |
samueldmq | #success keystone is now pci-dss compliant | 15:05 |
openstackstatus | samueldmq: Added success to Success page | 15:05 |
*** EinstCrazy has quit IRC | 15:05 | |
*** d0ugal has quit IRC | 15:09 | |
*** edtubill has quit IRC | 15:09 | |
bknudson | sure it is. | 15:12 |
openstackgerrit | Merged openstack/python-keystoneclient: Follow up patch for Improve docs for v3 ec2 https://review.openstack.org/357106 | 15:14 |
*** edtubill has joined #openstack-keystone | 15:15 | |
stevemar | o/ | 15:15 |
stevemar | rderose: i consider it critical :P | 15:16 |
rderose | stevemar: cool | 15:17 |
samueldmq | well, not 100% compliant :p | 15:17 |
samueldmq | stevemar: o/ | 15:17 |
bknudson | you need to pay someone to declare your solution compliant. That's the racket. | 15:18 |
*** mvk has joined #openstack-keystone | 15:19 | |
*** michauds has quit IRC | 15:19 | |
*** arunkant_ has joined #openstack-keystone | 15:21 | |
*** rcernin has quit IRC | 15:22 | |
lbragstad | bknudson believe it or not - I will take donations to say your solution is compliant | 15:22 |
lbragstad | :) | 15:22 |
lbragstad | for two donations I'll even say it's "super certified" | 15:23 |
samueldmq | hehe | 15:23 |
*** d0ugal has joined #openstack-keystone | 15:24 | |
*** su_zhang has quit IRC | 15:28 | |
*** sdake_ has joined #openstack-keystone | 15:29 | |
*** su_zhang has joined #openstack-keystone | 15:29 | |
samueldmq | rderose: can you reply dolph's comment in 351749 | 15:33 |
samueldmq | ? | 15:33 |
*** su_zhang has quit IRC | 15:33 | |
dolphm | samueldmq: we've already discussed it outside of gerrit - i just wanted to file my objection for the record | 15:34 |
samueldmq | dolphm: k, I will let that proceed to the gate then | 15:34 |
*** jaugustine has joined #openstack-keystone | 15:37 | |
*** nk2527 has joined #openstack-keystone | 15:41 | |
*** gagehugo has joined #openstack-keystone | 15:47 | |
stevemar | breton: new "ldap_populate" today? :) | 15:49 |
*** mvk has quit IRC | 15:50 | |
*** gagehugo_ has quit IRC | 15:51 | |
*** michauds has joined #openstack-keystone | 15:52 | |
*** edtubill has quit IRC | 15:53 | |
*** edtubill has joined #openstack-keystone | 15:55 | |
stevemar | i'll let henrynash address the comments here: https://review.openstack.org/#/c/349939/24 | 15:57 |
patchbot | stevemar: patch 349939 - keystone - Add expand, data migration and contract logic to k... | 15:57 |
*** tqtran has joined #openstack-keystone | 15:57 | |
mfisch | crinkle: stevemar: Crinkle's patch has my personal blessing | 15:58 |
mfisch | I told you it would work | 15:58 |
mfisch | ;) | 15:58 |
mfisch | thanks for the fix | 15:58 |
*** tonytan4ever has quit IRC | 16:00 | |
*** edtubill has quit IRC | 16:01 | |
*** tonytan4ever has joined #openstack-keystone | 16:01 | |
dolphm | mfisch: \o/ | 16:02 |
*** tqtran has quit IRC | 16:02 | |
mfisch | I think you should be sure your upgrade tests include caching | 16:03 |
mfisch | fernet implies caching IMHO | 16:03 |
mfisch | as I think 3 wise men once said at a Summit talk | 16:03 |
stevemar | mfisch: most of our upgrade tests are unit tests | 16:04 |
stevemar | and its hard to do caching+unit tests | 16:04 |
stevemar | regardless | 16:04 |
stevemar | thank you for the verification | 16:04 |
stevemar | you are an indispensable resource for the keystone team ! | 16:04 |
dstanek | stevemar: ++ | 16:05 |
stevemar | ayoung: i'm going to bump "views" to O -- reasoning is in the patch | 16:05 |
ayoung | stevemar, works | 16:05 |
dolphm | mfisch: i'm hoping that we'll have a voting job via openstack-ansible that actually does a multi-node rolling upgrade with caching & fernet at some point (hopefully by end of year) | 16:05 |
ayoung | stevemar, so, on the "token expiration" solution from the midcycle, Ithink it needs the is_admin_project fix first | 16:06 |
mfisch | that would be cool | 16:06 |
stevemar | ayoung: i spoke with jamie about bumping the job last night, he is cool with it | 16:06 |
ayoung | we want one project to say "I will accept expired user tokens along with tokens from a nother service iff they have Role R on the admin project" | 16:06 |
stevemar | ayoung: we gotta fix all the services first? | 16:06 |
notmorgan | bknudson: ++ on your response to the #success | 16:06 |
ayoung | so, for example, glance will accept it if the service token has the Nova role | 16:07 |
ayoung | stevemar, that fix is pretty close, actuallly | 16:07 |
ayoung | stevemar, jamielennox has fixes in for most services. I just bugged Neutron and Cinder on the mailing list | 16:07 |
ayoung | looks like Cue also needs some prodding | 16:07 |
ayoung | I think the rest are done | 16:08 |
dstanek | dolphm: is anyone working on that already? | 16:08 |
stevemar | ayoung: oh nice | 16:09 |
stevemar | ayoung: i haven't been tracking that one much | 16:09 |
dolphm | dstanek: my understanding is that it's on the roadmap for the OSIC QE team, but i'd also like to see some investment from the regular OSA community | 16:09 |
stevemar | good to hear | 16:09 |
ayoung | stevemar, I am trying to think along the lines of "how do we integrate 3rd party services into the workload" | 16:09 |
*** gyee has joined #openstack-keystone | 16:09 | |
ayoung | stevemar, we've done a lot of talking about trusted services like nova nad glance | 16:10 |
dstanek | dolphm: nice. that will be great to have | 16:10 |
ayoung | but I am starting to think all of the *aaS services are ina different class | 16:10 |
ayoung | so if a workflow engine calls into Sahara which calls Heat, and each is run by a different Org, we want to be able to let them all do their thing | 16:10 |
ayoung | the part I don't like is we have no way to tell a user "here is what you need to delegate to this service" | 16:11 |
ayoung | its all or nothing, and that is just yucky. ...to use a technical term | 16:11 |
ayoung | I would love to have a pattern likethis: | 16:11 |
dolphm | dstanek: sorry, osic ops, not QE | 16:12 |
ayoung | 1. If a user sends no token, or an expired token, to an API,they get back a 401. | 16:12 |
ayoung | 2. They then get a token with scope but no roles, or a simple role like "just query" | 16:12 |
ayoung | They then get back another 401, but this time with "here is the role I require" | 16:12 |
ayoung | bascially, how OAUTH does things | 16:12 |
ayoung | User then goes and gets a token with that role, and sends it to the service, and now they get the 200 | 16:13 |
*** Ephur has joined #openstack-keystone | 16:13 | |
*** gagehugo_ has joined #openstack-keystone | 16:14 | |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Add rolling upgrade documentation https://review.openstack.org/350793 | 16:15 |
*** nishaYadav has joined #openstack-keystone | 16:15 | |
breton | stevemar: mapping_populate | 16:16 |
*** roxanaghe has joined #openstack-keystone | 16:16 | |
breton | stevemar: today, yes | 16:16 |
openstackgerrit | Merged openstack/keystonemiddleware: Use AccessInfo in UserAuthPlugin instead of custom https://review.openstack.org/338714 | 16:16 |
*** sdake_ has quit IRC | 16:16 | |
*** ametts has quit IRC | 16:16 | |
odyssey4me | dolphm dstanek yep, once N3 is done we've got a guy who'll be largely focused on doing just that - with support from the rest of us... we're very keen to have the rolling upgrade test in place for NEwton's release | 16:17 |
dolphm | odyssey4me: =D | 16:19 |
stevemar | breton: ah yeah, mapping_populate | 16:19 |
*** ametts has joined #openstack-keystone | 16:21 | |
*** michauds has quit IRC | 16:25 | |
*** gagehugo_ has quit IRC | 16:26 | |
*** tesseract- has quit IRC | 16:26 | |
openstackgerrit | Boris Bobrov proposed openstack/keystone: Add mapping_populate command https://review.openstack.org/343028 | 16:27 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Add domain check in domain-specific role implication https://review.openstack.org/351264 | 16:33 |
stevemar | someone (ayoung) want to look at ^ it involves a bug as well, but i think it'll break trusts, there is one failing test | 16:35 |
openstackgerrit | Nisha Yadav proposed openstack/python-keystoneclient: Improve docs for v3 tokens https://review.openstack.org/357136 | 16:35 |
stevemar | breton: nice | 16:37 |
*** thumpba_ has joined #openstack-keystone | 16:37 | |
*** thumpba has quit IRC | 16:39 | |
openstackgerrit | Merged openstack/keystonemiddleware: Updated from global requirements https://review.openstack.org/356929 | 16:40 |
*** itisha has quit IRC | 16:40 | |
*** code-R_ has quit IRC | 16:41 | |
*** sdake has joined #openstack-keystone | 16:43 | |
openstackgerrit | Merged openstack/keystone: PCI-DSS Minimum password age requirements https://review.openstack.org/343314 | 16:43 |
*** nisha_ has joined #openstack-keystone | 16:45 | |
*** nishaYadav has quit IRC | 16:45 | |
*** nisha_ is now known as nishaYadav | 16:45 | |
openstackgerrit | Merged openstack/keystoneauth: Updated from global requirements https://review.openstack.org/356928 | 16:48 |
*** ravelar1 has joined #openstack-keystone | 16:51 | |
*** ravelar has quit IRC | 16:51 | |
*** ankur-gupta-f has joined #openstack-keystone | 16:52 | |
*** d34dh0r53 is now known as RichardLongus | 16:52 | |
*** eandersson_ has quit IRC | 16:54 | |
*** nisha_ has joined #openstack-keystone | 16:56 | |
*** dikonoor has quit IRC | 16:57 | |
*** asettle has quit IRC | 16:58 | |
*** RichardLongus is now known as d34dh0r53 | 16:58 | |
*** asettle has joined #openstack-keystone | 16:58 | |
*** ravelar1 is now known as ravelar | 16:59 | |
*** nishaYadav has quit IRC | 16:59 | |
*** su_zhang has joined #openstack-keystone | 17:01 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/356872 | 17:01 |
*** asettle has quit IRC | 17:03 | |
*** tonytan_brb has joined #openstack-keystone | 17:04 | |
*** nisha_ is now known as nishaYadav | 17:04 | |
*** su_zhang has quit IRC | 17:06 | |
*** tonytan4ever has quit IRC | 17:06 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements https://review.openstack.org/356940 | 17:07 |
*** su_zhang has joined #openstack-keystone | 17:07 | |
*** marekd2 has quit IRC | 17:11 | |
*** marekd2 has joined #openstack-keystone | 17:12 | |
*** marekd2 has quit IRC | 17:17 | |
*** marekd2 has joined #openstack-keystone | 17:17 | |
*** Ephur has quit IRC | 17:18 | |
*** marekd2_ has joined #openstack-keystone | 17:19 | |
*** marekd2 has quit IRC | 17:22 | |
*** Gorian|work has joined #openstack-keystone | 17:23 | |
*** marekd2_ has quit IRC | 17:23 | |
*** tonytan_brb is now known as tonytan4ever | 17:25 | |
*** gyee has quit IRC | 17:28 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Make KeyRepository shareable https://review.openstack.org/356053 | 17:29 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add conf to support credential encryption https://review.openstack.org/354495 | 17:30 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add key_hash and encrypted_blob to credential table https://review.openstack.org/355618 | 17:30 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add create and update methods to credential Manager https://review.openstack.org/355056 | 17:30 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Create a fernet credential provider https://review.openstack.org/354496 | 17:30 |
*** ravelar has quit IRC | 17:32 | |
lbragstad | dolphm still working on the migration pieces - but i rebased on the rest of the henrynash's work | 17:33 |
lbragstad | going to break for lunch | 17:33 |
*** nisha_ has joined #openstack-keystone | 17:33 | |
dolphm | lbragstad: have you dug into writing triggers or anything yet? | 17:33 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/python-keystoneclient: Reuse Domain and Project resouce definitions https://review.openstack.org/357367 | 17:35 |
samueldmq | stevemar: ^ | 17:35 |
samueldmq | stevemar: this fixes what is making 356041 fail | 17:36 |
*** nishaYadav has quit IRC | 17:36 | |
samueldmq | I am not sure we could simply get off of those classes and just re-use the exisitng ones in projects.py and doamins.py | 17:37 |
samueldmq | stevemar: because the Project and Domain classes in auth.py are public symbols | 17:37 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/python-keystoneclient: Add auth functional tests https://review.openstack.org/356041 | 17:37 |
*** tqtran has joined #openstack-keystone | 17:39 | |
*** hockeynut has quit IRC | 17:44 | |
*** nisha_ is now known as nishaYadav | 17:51 | |
*** rcernin has joined #openstack-keystone | 17:51 | |
*** amakarov is now known as amakarov_away | 17:52 | |
stevemar | samueldmq: good question | 17:57 |
*** nisha_ has joined #openstack-keystone | 18:00 | |
*** nisha__ has joined #openstack-keystone | 18:02 | |
*** nishaYadav has quit IRC | 18:04 | |
*** nisha_ has quit IRC | 18:06 | |
*** nisha__ is now known as nishaYadav | 18:07 | |
nishaYadav | I am trying to make an object of class:`keystoneclient.access.AccessInfo`. Can anyone please help me proceed? | 18:11 |
nishaYadav | samueldmq, can you please help with this ^ | 18:14 |
*** ravelar has joined #openstack-keystone | 18:15 | |
nishaYadav | I see this in the doc, def factory(cls, resp=None, body=None, region_name=None, auth_token=None, **kwargs): | 18:18 |
nishaYadav | But don't know what to pass in cls | 18:18 |
samueldmq | nishaYadav: why do you need to create a AccessInfo? is it for the token stuff ? | 18:20 |
nishaYadav | Yeah, I am writing the token functional tests, so for the revoke_token test | 18:22 |
nishaYadav | samueldmq, any other way around? | 18:22 |
bknudson | verify_token will return an accessinfo | 18:23 |
bknudson | also, there's probably a function to get the access info when authenticating, or a way to get the accessinfo for the session token? | 18:23 |
bknudson | the cls argument is provided by the python interpreter. | 18:27 |
stevemar | dhellmann: poke | 18:27 |
* dhellmann grunts | 18:27 | |
stevemar | dhellmann: regarding https://review.openstack.org/#/c/357214/1 why is it such a short release? | 18:28 |
patchbot | stevemar: patch 357214 - releases - proposed ocata schedule | 18:28 |
stevemar | dhellmann: i suppose we could talk in -release... | 18:28 |
dhellmann | stevemar : yeah | 18:28 |
*** spedione is now known as spedione|AWAY | 18:28 | |
samueldmq | bknudson: nice, thanks for the tips, I will try that with nishaYadav | 18:28 |
nishaYadav | bknudson, thanks a lot :) | 18:29 |
*** hockeynut has joined #openstack-keystone | 18:36 | |
*** ayoung has quit IRC | 18:37 | |
*** michauds has joined #openstack-keystone | 18:38 | |
*** nisha_ has joined #openstack-keystone | 18:40 | |
*** nisha__ has joined #openstack-keystone | 18:43 | |
*** nishaYadav has quit IRC | 18:44 | |
*** su_zhang has quit IRC | 18:44 | |
*** nisha__ is now known as nishaYadav | 18:44 | |
*** nisha_ has quit IRC | 18:46 | |
openstackgerrit | Merged openstack/python-keystoneclient: Fix no content return type doc https://review.openstack.org/357236 | 18:47 |
*** catintheroof has joined #openstack-keystone | 18:49 | |
bknudson | when we change the recommendataion for a config change we wind up changing it in probably 7 or 8 repos. | 18:51 |
bknudson | e.g., keystone config help text & doc, devstack, but then also ansible, (and for me, ursula and arrrsula) | 18:52 |
lbragstad | dolphm not yet | 18:52 |
bknudson | would be interesting if we could somehow have the recommended config in the keystone repo somehow (or in a single other repo that the deployers could use) | 18:53 |
lbragstad | dolphm that's what i'm going to look into once I collapse https://review.openstack.org/#/c/317169/33 into https://review.openstack.org/#/c/355618/7 | 18:53 |
patchbot | lbragstad: patch 317169 - keystone - Implement encryption of credentials at rest | 18:53 |
patchbot | lbragstad: patch 355618 - keystone - Add key_hash and encrypted_blob to credential table | 18:53 |
*** gagehugo_ has joined #openstack-keystone | 18:53 | |
*** gagehugo has quit IRC | 18:54 | |
*** gagehugo_ has quit IRC | 18:54 | |
*** gagehugo has joined #openstack-keystone | 18:54 | |
openstackgerrit | Merged openstack/keystone: Add dummy domain_id column to cached role https://review.openstack.org/347543 | 18:55 |
*** gagehugo_ has joined #openstack-keystone | 18:56 | |
*** fifieldt has quit IRC | 19:06 | |
stevemar | bknudson: i think i already asked you, but https://bugs.launchpad.net/keystone/+bug/1609566 -- anything new on that one? | 19:06 |
openstack | Launchpad bug 1609566 in OpenStack Identity (keystone) "500 error from revocation event deserialize" [Medium,In progress] - Assigned to Brant Knudson (blk-u) | 19:06 |
stevemar | should i bump it from newton-3 | 19:06 |
bknudson | stevemar: still looking into it. | 19:07 |
bknudson | I'm trying to create it using our internal dev process, so having to learn that. | 19:07 |
*** spedione|AWAY is now known as spedione | 19:09 | |
stevemar | bknudson: okay, i can hold keep it targeted for a bit | 19:09 |
stevemar | but if we're not able to recreate it consistently, buuuump | 19:09 |
*** spedione is now known as spedione|AWAY | 19:09 | |
*** spedione|AWAY is now known as spedione | 19:10 | |
bknudson | it keeps happening in our psr (perf test) environment, I just haven't been able to figure out how to recreate in my dev environment | 19:10 |
*** julim has quit IRC | 19:13 | |
openstackgerrit | Nisha Yadav proposed openstack/python-keystoneclient: Follow up patch for Add ec2 functional tests https://review.openstack.org/357420 | 19:14 |
openstackgerrit | Merged openstack/keystone: Password expires ignore user list https://review.openstack.org/351749 | 19:14 |
*** julim has joined #openstack-keystone | 19:14 | |
*** gagehugo has quit IRC | 19:14 | |
openstackgerrit | Merged openstack/keystone: Tidy up for late-breaking review comments on keystone-manage https://review.openstack.org/356158 | 19:14 |
*** fifieldt has joined #openstack-keystone | 19:17 | |
*** thumpba_ has quit IRC | 19:29 | |
stevemar | dolphm: thanks for reviews the patches that lead up to the caching fix | 19:30 |
dolphm | stevemar: ++ | 19:31 |
stevemar | dstanek: let me and dolphm know when you're all ready for the cache fix | 19:31 |
stevemar | dstanek: breton liked the latest incarnation of it | 19:31 |
*** su_zhang has joined #openstack-keystone | 19:32 | |
dstanek | stevemar: i'm writing some tests for it now :-) - the code itself hasn't changed, but it's only hand tested | 19:32 |
dolphm | dstanek: sounds artisanal | 19:33 |
dstanek | dolphm: gently hand crafted by a caring developer | 19:33 |
dolphm | dstanek: Hipster+Workflow+1 | 19:33 |
*** dgonzalez has quit IRC | 19:34 | |
dstanek | yours now for the low price of 2(+2)+A! | 19:34 |
*** su_zhang has quit IRC | 19:36 | |
samueldmq | stevemar: replied your question in 357367 | 19:38 |
samueldmq | it would be nice to get someone else's view on it ^ | 19:39 |
samueldmq | and possibly a low priced +2+A | 19:39 |
*** thumpba has joined #openstack-keystone | 19:39 | |
*** dgonzalez has joined #openstack-keystone | 19:45 | |
openstackgerrit | Nisha Yadav proposed openstack/python-keystoneclient: Add tokens functional tests https://review.openstack.org/357435 | 19:48 |
nishaYadav | samueldmq, ^ the link, thanks :) | 19:49 |
*** nishaYadav has quit IRC | 19:52 | |
samueldmq | thanks | 19:53 |
samueldmq | dolphm: henrynash: for the rolling upgrades, do we still have the concept of only making additive changes to the schema? | 19:53 |
samueldmq | and then things can only be removed in the N+1 release? | 19:53 |
samueldmq | what I am thinking is that the contract step can remove things | 19:54 |
samueldmq | then we don't need to wait for N+1 | 19:54 |
dolphm | samueldmq: only in the expand repo | 19:55 |
dolphm | samueldmq: Each of the three new repos has it's own set of banned and whitelisted operations. You shouldn't be able to drop tables, columns, indexes, or triggers in the expand or data migration repos. You shouldn't be able to create tables, columns, indexes, or triggers in the data migration or contraction repos. You shouldn't be able to UPDATE or DELETE data in the expand or contract repos. | 19:55 |
samueldmq | dolphm: perfect | 19:55 |
samueldmq | thanks | 19:55 |
*** ezpz has quit IRC | 19:58 | |
*** su_zhang has joined #openstack-keystone | 20:01 | |
*** su_zhang has quit IRC | 20:01 | |
*** su_zhang has joined #openstack-keystone | 20:01 | |
dolphm | bknudson: i see you renamed the migrations in each repo of henrynash's patch, but you didn't say why... i'm assuming that somehow fixed the issue you were debugging last night? | 20:02 |
dolphm | bknudson: or is it the fact that you made them all no-op's that somehow fixed it? | 20:02 |
bknudson | dolphm: should have just been a rename. It fixed the issue I was debugging last night. | 20:03 |
bknudson | I wasn't trying to make noops | 20:03 |
dolphm | bknudson: can i ask how? | 20:03 |
bknudson | dolphm: hang on I have a meeting. | 20:03 |
dolphm | bknudson: oh, the no-op thing was henry, after you | 20:04 |
dolphm | bknudson: no worries | 20:04 |
*** thumpba has quit IRC | 20:04 | |
*** GB21 has quit IRC | 20:04 | |
bknudson | dolphm: see http://paste.openstack.org/show/560282/ -- sqlalchemy-migrate caches objects (singleton-style) and for some reason it was getting the wrong instance! | 20:08 |
bknudson | didn't look into it enough to figure out why, just figured if I changed the key it wouldn't get confused. | 20:09 |
*** ayoung has joined #openstack-keystone | 20:09 | |
*** ChanServ sets mode: +v ayoung | 20:09 | |
dolphm | bknudson: oh, wow | 20:10 |
dolphm | bknudson: maybe it should key off repo + migrate module name | 20:11 |
*** gyee has joined #openstack-keystone | 20:11 | |
*** ChanServ sets mode: +v gyee | 20:11 | |
bknudson | I don't understand how it gets confused, the key has the whole path: '/opt/stack/keystone/keystone/common/sql/expand_repo/versions/001_make_password_create_at_non_nullable.py' | 20:12 |
bknudson | so there shouldn't be any way for that to match '/opt/stack/keystone/keystone/common/sql/contract_repo/versions/001_make_password_create_at_non_nullable.py' | 20:13 |
dolphm | bknudson: bah, you're right | 20:13 |
*** afred312_ has joined #openstack-keystone | 20:23 | |
*** BigWillie has quit IRC | 20:24 | |
dstanek | i'm not sure why rally hates me so much | 20:24 |
*** afred312 has quit IRC | 20:24 | |
openstackgerrit | Alexander Oughton proposed openstack/keystoneauth: Disables setting of TCP_KEEPCNT when running under the Windows Subsystem for Linux. https://review.openstack.org/357452 | 20:25 |
openstackgerrit | Alexander Oughton proposed openstack/keystoneauth: Disables setting of TCP_KEEPCNT when running under the Windows Subsystem for Linux. https://review.openstack.org/357452 | 20:30 |
dolphm | dstanek: tests keep passing? | 20:37 |
dstanek | dolphm: yeah. going to try to setup two faster nodes that share a db. | 20:37 |
dolphm | dstanek: need bare metal? | 20:38 |
dstanek | dolphm: not sure yet. it's hard to tell if it's a speed thing, a concurrency thing, etc. | 20:38 |
dstanek | dolphm: if this doesn't work i'll let you know | 20:39 |
dolphm | dstanek: ack | 20:39 |
*** pnavarro has quit IRC | 20:40 | |
dstanek | dolphm: i'm doing a few thing concurrently, but unfortunately humans can fork. cooperative multitasking sucks. | 20:40 |
stevemar | dolphm: do you plan on running the script amakarov wrote to validate pre-caching tokens works? | 20:48 |
*** AlexOughton has joined #openstack-keystone | 20:49 | |
stevemar | dolphm: what are we waiting for with https://review.openstack.org/#/c/349939/24 ? theres a lot of back and forth and i'm not sure henry has a to-do? | 20:50 |
patchbot | stevemar: patch 349939 - keystone - Add expand, data migration and contract logic to k... | 20:50 |
dolphm | stevemar: i withdrew my +2 for this https://review.openstack.org/#/c/349939/24/keystone/common/sql/migration_helpers.py@195 | 20:53 |
patchbot | dolphm: patch 349939 - keystone - Add expand, data migration and contract logic to k... | 20:53 |
stevemar | dolphm: _sync_common_repo() is run in the expand_schema? | 20:54 |
dolphm | stevemar: if you're upgrading from mitaka, checkout newton up to this patch, and run db_sync, you won't get any of the legacy migrations at all | 20:54 |
stevemar | dolphm: line221? | 20:55 |
dolphm | stevemar: oh, i missed that... | 20:55 |
dolphm | stevemar: hmm | 20:55 |
stevemar | replied | 20:55 |
dolphm | i guess that works for now | 20:55 |
dolphm | stevemar: i'd like to put some stronger checks around the version numbers of each repo before we run any migrations | 20:55 |
stevemar | dolphm: *shrugs* i can change it to be more explicit and run _sync_common_repo() first before expand | 20:55 |
dolphm | stevemar: can tweak that then | 20:55 |
lbragstad | is anyone here familiar enough with https://github.com/openstack/keystone/blob/master/keystone/tests/unit/test_v3_credential.py#L36-L49 to explain it's use? | 20:55 |
dolphm | stevemar: +2 | 20:56 |
*** spzala has quit IRC | 20:56 | |
dolphm | lbragstad: not really, but i can try | 20:56 |
stevemar | dolphm: now 6 patches are approved lol | 20:57 |
openstackgerrit | Alexander Oughton proposed openstack/keystoneauth: Disables setting of TCP_KEEPCNT when running under the Windows Subsystem for Linux. https://review.openstack.org/357452 | 20:57 |
dolphm | lbragstad: i've never had to work with the ec2 api other than as a reviewer | 20:57 |
lbragstad | dolphm it seems that we are able to pass strings and dicts as blobs | 20:57 |
dolphm | stevemar: gate'em! | 20:57 |
stevemar | yee yee | 20:57 |
dolphm | lbragstad: yeah, a dict should not be accepted as blob | 20:57 |
lbragstad | dolphm just curious because the initial implementation of encrypted credentials expects blobs to be strings | 20:58 |
dolphm | lbragstad: true... | 20:58 |
lbragstad | and the fernet stuff blew up on it - so i started digging and found that surprising | 20:58 |
lbragstad | but - i've never used the ec2 stuff either :) | 20:58 |
dolphm | lbragstad: i've totally forgotten about this. we still support storing dictionaries in that column? do we do json.dumps and json.loads on it somewhere? | 20:59 |
*** raildo has quit IRC | 20:59 | |
stevemar | i guess i can mark the rolling upgrade bp as complete, the bug can stay open | 21:01 |
dolphm | lbragstad: this is kind of an iffy test https://github.com/openstack/keystone/blob/master/keystone/tests/unit/test_v3_credential.py#L326-L331 | 21:01 |
dolphm | stevemar: did you approve the docs? | 21:01 |
stevemar | dolphm: yes, i did | 21:01 |
dolphm | stevemar: then Implemented! | 21:02 |
stevemar | :] | 21:02 |
dolphm | stevemar: i can file some additional bugs on the tests i'd like to see, to keep deployers from shooting themselves in the foot | 21:02 |
stevemar | dolphm: i just remembered that rderose owes me PCI docs | 21:02 |
dolphm | stevemar: and ensure the repos are implemented correctly | 21:02 |
stevemar | dolphm: that would be nice | 21:02 |
*** julim has quit IRC | 21:04 | |
*** dolphm has left #openstack-keystone | 21:04 | |
*** dolphm has joined #openstack-keystone | 21:04 | |
*** ChanServ sets mode: +o dolphm | 21:04 | |
stevemar | someone is actually running keystoneauth with "windows subsystem for linux" https://review.openstack.org/#/c/357452/3/keystoneauth1/session.py | 21:05 |
patchbot | stevemar: patch 357452 - keystoneauth - Disables setting of TCP_KEEPCNT when running under... | 21:05 |
stevemar | the whole bash on windows thing | 21:05 |
dolphm | i thought that was a poorly timed april fool's joke | 21:06 |
stevemar | i suppose not | 21:07 |
*** hockeynut has quit IRC | 21:12 | |
lbragstad | dolphm hmm | 21:12 |
lbragstad | dolphm should i just check if the blob is a dict in the credential manager and convert it to a string if it is? | 21:13 |
lbragstad | before encrypting it? | 21:13 |
*** catintheroof has quit IRC | 21:21 | |
*** ravelar has quit IRC | 21:22 | |
lbragstad | actually - that's weird because how do you tell if you need to convert a blob back to a dict when you're reading it? | 21:24 |
*** edmondsw has quit IRC | 21:25 | |
lbragstad | dolphm I wonder if that is something that was handled with the sql.JsonBlob type? | 21:28 |
*** roxanaghe has quit IRC | 21:33 | |
*** pauloewerton has quit IRC | 21:34 | |
stevemar | dolphm: oh if you have a minute: https://review.openstack.org/#/c/357415/ should be easy, it's a clean cherry pick to fix the upgrade issue with cached tokens | 21:35 |
patchbot | stevemar: patch 357415 - keystone (stable/mitaka) - Add dummy domain_id column to cached role | 21:35 |
*** awayne has joined #openstack-keystone | 21:35 | |
*** BjoernT has quit IRC | 21:56 | |
*** gordc has quit IRC | 22:02 | |
*** julim has joined #openstack-keystone | 22:19 | |
*** su_zhang has quit IRC | 22:23 | |
*** asettle has joined #openstack-keystone | 22:24 | |
*** su_zhang has joined #openstack-keystone | 22:29 | |
*** ntpttr has quit IRC | 22:31 | |
*** asettle has quit IRC | 22:32 | |
*** su_zhang has quit IRC | 22:33 | |
*** ntpttr has joined #openstack-keystone | 22:36 | |
*** su_zhang has joined #openstack-keystone | 22:38 | |
*** tonytan4ever has quit IRC | 22:47 | |
*** spedione is now known as spedione|AWAY | 22:47 | |
openstackgerrit | Boris Bobrov proposed openstack/keystone: Add mapping_populate command https://review.openstack.org/343028 | 22:48 |
openstackgerrit | Boris Bobrov proposed openstack/keystone: Add mapping_populate command https://review.openstack.org/343028 | 22:50 |
*** ametts has quit IRC | 22:51 | |
*** haplo37__ has quit IRC | 23:03 | |
*** michauds has quit IRC | 23:07 | |
*** sdake_ has joined #openstack-keystone | 23:12 | |
*** sdake has quit IRC | 23:13 | |
*** chlong has quit IRC | 23:20 | |
openstackgerrit | Merged openstack/keystone: Make all token provider behave the same with trusts https://review.openstack.org/350704 | 23:25 |
openstackgerrit | Merged openstack/keystone: Removes a redundant test from FernetAuthWithTrust https://review.openstack.org/356596 | 23:25 |
openstackgerrit | Merged openstack/keystone: Removes use of freezegun in test_auth tests https://review.openstack.org/356597 | 23:25 |
*** Guest36352 has joined #openstack-keystone | 23:30 | |
*** Guest36352 has quit IRC | 23:31 | |
*** rcernin has quit IRC | 23:32 | |
*** adriant has joined #openstack-keystone | 23:34 | |
*** lamt_ has joined #openstack-keystone | 23:34 | |
*** jaugustine has quit IRC | 23:40 | |
*** xenogear has quit IRC | 23:40 | |
*** nk2527 has quit IRC | 23:41 | |
*** gagehugo_ has quit IRC | 23:41 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/356872 | 23:44 |
*** Gorian|work has quit IRC | 23:45 | |
*** tonytan4ever has joined #openstack-keystone | 23:47 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements https://review.openstack.org/356940 | 23:49 |
*** tonytan4ever has quit IRC | 23:53 | |
*** gagehugo has joined #openstack-keystone | 23:53 | |
*** ravelar has joined #openstack-keystone | 23:55 | |
*** nk2527 has joined #openstack-keystone | 23:57 | |
*** ravelar has quit IRC | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!