*** martinus__ has quit IRC | 00:01 | |
*** martinus__ has joined #openstack-keystone | 00:03 | |
*** roxanaghe has quit IRC | 00:16 | |
*** xenogear has quit IRC | 00:17 | |
*** sdake_ has quit IRC | 00:17 | |
*** sdake has joined #openstack-keystone | 00:17 | |
*** nk2527 has quit IRC | 00:18 | |
*** tqtran has quit IRC | 00:25 | |
*** adrian_otto has quit IRC | 00:27 | |
*** esp has quit IRC | 00:29 | |
*** itsuugo has quit IRC | 00:40 | |
*** itsuugo has joined #openstack-keystone | 00:40 | |
*** browne has quit IRC | 00:43 | |
*** dave-mccowan has joined #openstack-keystone | 00:43 | |
*** itsuugo has quit IRC | 00:45 | |
*** itsuugo has joined #openstack-keystone | 00:46 | |
*** itsuugo has quit IRC | 00:51 | |
*** itsuugo has joined #openstack-keystone | 00:53 | |
*** asettle has joined #openstack-keystone | 00:59 | |
openstackgerrit | Merged openstack/keystone: Fix links on configure_federation documentation https://review.openstack.org/369741 | 01:02 |
---|---|---|
*** gyee has quit IRC | 01:03 | |
*** asettle has quit IRC | 01:04 | |
*** xenogear has joined #openstack-keystone | 01:10 | |
*** itsuugo has quit IRC | 01:10 | |
*** itsuugo has joined #openstack-keystone | 01:11 | |
dstanek | samueldmq: ? | 01:11 |
dstanek | samueldmq: oh, the comment for the test describes the corner case | 01:12 |
*** nk2527 has joined #openstack-keystone | 01:14 | |
samueldmq | dstanek: ah yes, "slight clock skew" | 01:15 |
samueldmq | dstanek: thanks | 01:15 |
dstanek | samueldmq: ma pleasure | 01:16 |
*** itsuugo has quit IRC | 01:26 | |
*** jamielennox is now known as jamielennox|away | 01:26 | |
*** itsuugo has joined #openstack-keystone | 01:27 | |
*** itsuugo has quit IRC | 01:39 | |
*** itsuugo has joined #openstack-keystone | 01:41 | |
*** davechen has joined #openstack-keystone | 01:42 | |
*** sdake_ has joined #openstack-keystone | 01:45 | |
*** sdake_ has quit IRC | 01:45 | |
*** sdake_ has joined #openstack-keystone | 01:45 | |
*** sdake has quit IRC | 01:47 | |
*** itsuugo has quit IRC | 01:52 | |
tonyb | I was lookign for ayoung. Anyone that can help me with his requests-kerberos [requirements) FFE? | 01:54 |
*** itsuugo has joined #openstack-keystone | 01:54 | |
*** fangxu has quit IRC | 01:58 | |
*** fangxu has joined #openstack-keystone | 02:00 | |
stevemar_ | tonyb: whaddup | 02:05 |
*** adriant has quit IRC | 02:05 | |
tonyb | stevemar_: I get that the requests-kerberos is marked as py27/py26 | 02:07 |
stevemar_ | tonyb: right, that has been my understanding for a while | 02:07 |
tonyb | stevemar_: ayoung says "Getting this restriction removed means we don't have to edit away the tests for Kerberos in python3" | 02:07 |
stevemar_ | tonyb: but apparently it's now py3 friendly? | 02:07 |
tonyb | what does that actually mean? where are the tests being blacklisted? | 02:07 |
tonyb | stevemar_: Can this be done in Ocata and then backported? | 02:08 |
stevemar_ | tonyb: i think it can definitely be done in ocata | 02:08 |
stevemar_ | tonyb: let me take a peek, 1 sec | 02:08 |
tonyb | stevemar_: that'd be great. | 02:08 |
stevemar_ | tonyb: fwiw, the only repo that would be affected is https://github.com/openstack/keystoneauth/ | 02:10 |
tonyb | stevemar_: that explains why I did understand while I was looking at keystone ;P | 02:11 |
stevemar_ | :) | 02:13 |
stevemar_ | tonyb: looking at keystoneauth1, we pull in requests-kerberos (which claims py2/3), which pulls in pykerberos (which also claims py2/3) | 02:13 |
stevemar_ | so i'm not sure why we were blacklisting this, maybe one of those libs wasn't py3 friendly before (i think this was ayoung's point) | 02:14 |
stevemar_ | yes, it is: | 02:14 |
stevemar_ | "The requests-kerberos package was marked as available for only python 2.6 and python 2.7 because pykerberos did not support python 3. This has since been fixed, however we don't directly have a kerberos dependency we can increase so just leave this unbound." | 02:14 |
stevemar_ | tonyb: i have no idea why that is in quotes, there's no citation | 02:15 |
tonyb | stevemar_: I kinda glossed over that ;P | 02:16 |
stevemar_ | tonyb: his comment about tests is referring to the py3-blacklist thing we did in keystone | 02:17 |
stevemar_ | i guess ayoung didn't want to do that, so he just limited the kerb plugin to py26/27 | 02:17 |
stevemar_ | tonyb: maybe he wants this for newton cause of tripleo stuff | 02:18 |
stevemar_ | i'm not sure why he needs it in | 02:18 |
stevemar_ | tonyb: did i make this more confusing :) | 02:19 |
stevemar_ | laundry is done, yay | 02:19 |
tonyb | stevemar_: No you confirmed a bunch of stuff for me which is good. | 02:19 |
*** woodster_ has quit IRC | 02:19 | |
tonyb | stevemar_: a quick git ls-files | grep blacklist doesn't have any hits in keystone or keystoneauth | 02:20 |
openstackgerrit | Merged openstack/keystone: Add edge case tests for disabling a trustee https://review.openstack.org/356607 | 02:20 |
stevemar_ | tonyb: give me 5 minutes to push a patch for keystoneauth so we can see if anything fails | 02:20 |
tonyb | stevemar_: Thanks. | 02:20 |
openstackgerrit | Steve Martinelli proposed openstack/keystoneauth: remove py26/py27 restriction for requests-kerberos https://review.openstack.org/369783 | 02:21 |
tonyb | stevemar_: interestingly my get-all-users doesn't find that keystoneauth uses requests-kerberos, so that's a bug | 02:21 |
stevemar_ | tonyb: do you check for setuptools' optional install? | 02:22 |
stevemar_ | tonyb: https://github.com/openstack/keystoneauth/blob/master/setup.cfg#L26-L36 | 02:22 |
tonyb | yeah I do .... | 02:22 |
stevemar_ | hmm | 02:22 |
*** ayoung has joined #openstack-keystone | 02:23 | |
*** ChanServ sets mode: +v ayoung | 02:23 | |
stevemar_ | tonyb: theres the man of the hour -- ayoung in the flesh | 02:23 |
ayoung | AMBUSH! | 02:23 |
ayoung | stevemar_, OOC, is the baby on your lap right now? | 02:24 |
stevemar_ | ayoung: the only question i couldn't answer from tonyb is why you need the requests-kerb FFE, i assumed tripleo | 02:24 |
stevemar_ | ayoung: sleeping :) | 02:24 |
ayoung | stevemar_, so, in order to have the auth plugins built for both py27 and py34/5 | 02:25 |
tonyb | grab him! | 02:25 |
ayoung | its really python3 support for something that works in python2, so more a Fedora thing | 02:25 |
ayoung | tonyb, I was a wrestler. You might want to rethink the grabbing | 02:25 |
tonyb | ayoung: :) | 02:25 |
ayoung | tonyb, its not a super critical, but it is also a low risk FFE | 02:26 |
ayoung | I didnt realize we had intentionally ignored the Kerberos py3 stuff. | 02:26 |
ayoung | I am thinking more community than distribution here | 02:26 |
ayoung | does something need to be in the global reqs to be pulled in for testing, or just for requirem,ents? | 02:27 |
tonyb | ayoung: The implementation and the ideal are different | 02:28 |
ayoung | tonyb, the reason I ask is the tests for py3 were skipped before. I could leave them that way and release, but I'd rather run the tests | 02:28 |
tonyb | ayoung: we dpn't verify that extras in setup.cfg match g-r so you can do what you're asking but the idea is that requirement is co-installable | 02:28 |
*** adriant has joined #openstack-keystone | 02:29 | |
tonyb | ayoung: but you could enable them in the next newton point release, it's not now or never | 02:29 |
ayoung | I's rather get this approved across the board. It would be dumb to tell people that they can't use python3 and kerberos due to something that has already been fixed | 02:29 |
ayoung | and we do already have the dep, just not the py3 versions | 02:29 |
ayoung | tonyb, I need to fix the Kerberos plugins now | 02:30 |
ayoung | the question is whether I do a complete fix or hack off the tests for py3 | 02:30 |
stevemar_ | tonyb: ayoung the other question in this is -- will this trigger a relrease of keystoneauth, and subsequently a relrelease of a bunch of other things? | 02:30 |
ayoung | I;d rather have the tests run | 02:30 |
tonyb | ayoung: and if the dep was right today would that code land by Friday or woul you need a keystone FFE? | 02:30 |
ayoung | stevemar_, once my path lands, I will *request* a release for something that is broken (bugfix) | 02:31 |
ayoung | here is the fix: | 02:31 |
ayoung | its KSA, not keystone server | 02:31 |
tonyb | stevemar_: Well the re-release *should* be limted to keystone unless we then need to bump the minimum on keystoneauth | 02:31 |
stevemar_ | tonyb: fwiw, KSA has passing unit tests with https://review.openstack.org/#/c/369783/ | 02:31 |
ayoung | https://review.openstack.org/#/c/368017/ and https://review.openstack.org/#/c/368288/5 with the second one being the important one | 02:32 |
stevemar_ | tonyb: true, only keystoneauth will be re-released | 02:32 |
tonyb | stevemar_, ayoung: where does python-keystoneclient-kerberos fit in the conversation? | 02:32 |
ayoung | Dead. All dead. | 02:33 |
stevemar_ | tonyb: it's dead jim | 02:33 |
ayoung | needs to go away | 02:33 |
tonyb | stevemar_: okay that makes life better | 02:33 |
ayoung | it was an impl of an auth plugin, but in the Py KClient style | 02:33 |
stevemar_ | tonyb: i've deprecated the whole repo last cycle, i'll probably attic it in O | 02:33 |
ayoung | when we moved to KSA we redid it using extras | 02:33 |
stevemar_ | yarp | 02:33 |
tonyb | stevemar_: okay. It's the only otehr thing using requests-kerberos AFAICT (modulo the bug in my scripts we just uncovered) | 02:34 |
ayoung | stevemar_, I have not tested the kerbers auth plugin, but I realize I can do that now...don't need an actual kerberso set up to see if the plugin loads | 02:34 |
stevemar_ | tonyb: we're not accepting any patches there, so its a non-issue | 02:36 |
tonyb | stevemar_: sure. | 02:36 |
stevemar_ | its strictly isolated to keystoneauth | 02:36 |
ayoung | hmmm...it has soemthign wrong, but it might be workable...let's see | 02:36 |
stevemar_ | ayoung: i'm thinking this can wait til O, as much as the community would benefit from it | 02:37 |
ayoung | stevemar_, these are bugs | 02:38 |
ayoung | I can skip getting the Py3 if it is going to cause heartburn, but it really is the same library we already ship | 02:38 |
stevemar_ | ayoung: they are, but we can backport the fixes once they land in O | 02:38 |
*** dave-mccowan has quit IRC | 02:38 | |
ayoung | stevemar_, or release an update of KSA | 02:39 |
ayoung | if KSA comes out late, it is fine by me, we will be able to grab it for RDO and OSP. I just don't want to be selfish | 02:39 |
tonyb | brb just need to pay someone ... | 02:39 |
ayoung | small, unmarked, nonsequential bills only | 02:40 |
stevemar_ | ayoung: the next ksa lib release will happen until first week of oct, and it can have as many fixes as you want | 02:40 |
ayoung | OK. That works for me | 02:40 |
stevemar_ | that'll be 2.13.0 | 02:40 |
ayoung | stevemar_, I just need the Global reqs updated by then | 02:40 |
stevemar_ | ayoung: tonyb can answer that one for ya :) | 02:41 |
ayoung | stevemar_, yeah, but he's talking to a guy about a horse | 02:41 |
tonyb | *sigh* | 02:42 |
*** martinus__ has quit IRC | 02:42 | |
* tonyb admits he set himself up for those ;P | 02:42 | |
tonyb | stevemar_: ayoung ksa 2.13.0 will that be from stable/newton? or master? | 02:42 |
tonyb | trying to work out if I can state 100% the g-r update will be in .... | 02:43 |
stevemar_ | but i think once we close out these FFEs, the sooner the requirements team can create a stable/newton branch | 02:43 |
stevemar_ | hehe | 02:43 |
stevemar_ | ayoung: what did you say in today's meeting, it was funny | 02:43 |
stevemar_ | 18:41:33 <stevemar> #topic Newton post-mortem | 02:43 |
stevemar_ | 18:41:42 <ayoung> He was killed by an apple | 02:43 |
stevemar_ | tonyb: master | 02:43 |
stevemar_ | tonyb: it'll be a business-as-usual release | 02:43 |
*** chrisshattuck has joined #openstack-keystone | 02:43 | |
ayoung | stevemar_, truth be told, I think Newton died of self administered mercury poisoning | 02:44 |
*** martinus__ has joined #openstack-keystone | 02:44 | |
ayoung | Isaac Newton/Cause of death | 02:44 |
ayoung | Kidney stone | 02:44 |
tonyb | okay from master I have no problem sayign the g-r chnage will be in. | 02:44 |
ayoung | Cool. We can wait until then | 02:45 |
tonyb | so I *think* we just agreeed to say "no" to the requessts-kerberos FFE as we can do it from master in the next couple of weeks | 02:45 |
tonyb | ayoung: doing it on master means we can if desired bump the minimum also .... | 02:46 |
ayoung | tonyb, so, when should I look for that? I'll hold of on bugging people about the review until then. 1st wek of Octish? | 02:47 |
tonyb | ayoung: Yeah no later than that. | 02:47 |
tonyb | ayoung: add yourself as a reviewer on https://review.openstack.org/#/c/368530/ and you'll see the -2 go real soon | 02:48 |
tonyb | ayoung: I can also pop in here and poke you, jamielennox|away and stevemar_ | 02:48 |
stevemar_ | why am i an underscore now | 02:49 |
*** stevemar_ is now known as stevemar | 02:49 | |
stevemar | fixed | 02:49 |
tonyb | stevemar: :) | 02:49 |
stevemar | tonyb: on a separate note, how are you feeling about the keystonemiddleware bump? | 02:49 |
stevemar | errr, not bump, rather a blacklist | 02:50 |
tonyb | stevemar: I was just about to re-read your email to look at that ;P | 02:50 |
stevemar | tonyb: there is also the oslo.log one, which is all kinds of ugh, but i'll let you catch up on keystonemiddleware first :) | 02:51 |
tonyb | stevemar: I really don't want to think about oslo.log | 02:51 |
stevemar | tonyb: and the 100 projects it'll cause to respin, yeah... | 02:51 |
*** fangxu has quit IRC | 02:58 | |
tonyb | stevemar: keystonemiddleware ... I'm so conflicted | 02:58 |
tonyb | stevemar: part of me wants to say: We know we're broken with lower bounds packagers should be using u-c and move on | 02:59 |
tonyb | stevemar: but I know that's wrong so I feel like we should fix it :/ | 02:59 |
stevemar | tonyb: totally get you there | 03:03 |
stevemar | tonyb: it's the lowest of the packages, and there are 9 others you can use | 03:03 |
tonyb | :) | 03:03 |
stevemar | tonyb: i don't know enough about how packagers and deployers use global-requirements | 03:03 |
stevemar | i agree, it is wrong that it's there, but... will anyone even notice? | 03:03 |
tonyb | stevemar: part of the problem is it varies from distro to distro | 03:03 |
tonyb | stevemar: also there's the contrast on what we'd like vs what people can actually do | 03:04 |
*** esp has joined #openstack-keystone | 03:04 | |
stevemar | tonyb: the only plus side is that most of the server side projects are going through their RC phase, i'm not sure any have proposed RC candidates yet | 03:07 |
tonyb | stevemar: none have AFAICT so we have a very small window that makes this okay | 03:08 |
tonyb | well less "okay" and more "not terrible" | 03:08 |
stevemar | :) | 03:08 |
tonyb | stevemar: there are a whole bunch of projects that'd need to merge g-r updates | 03:10 |
tonyb | stevemar: I'm sure it'll use up some of my brownie points but I think I should +W the ksm FFE | 03:14 |
* stevemar shrugs at tonyb | 03:17 | |
stevemar | ¯\_(ツ)_/¯ | 03:17 |
tonyb | :) | 03:17 |
tonyb | Actually I'm going to flip-flop the other way. I can't make this decision that will add another thing to 37 projects most of which are trying to get RC1 done. | 03:20 |
tonyb | then the realease mangers will ned to double check they have a correct ksm | 03:20 |
*** itsuugo has quit IRC | 03:21 | |
*** tqtran has joined #openstack-keystone | 03:22 | |
*** itsuugo has joined #openstack-keystone | 03:23 | |
*** fangxu has joined #openstack-keystone | 03:24 | |
*** tqtran has quit IRC | 03:26 | |
stevemar | tonyb: see what dhellmann says, he always has great insight into these things | 03:27 |
tonyb | stevemar: sure. | 03:28 |
stevemar | tonyb: gah, ksm 4.0.0 is so old | 03:30 |
stevemar | it was introduced in M | 03:30 |
stevemar | why anyone would use that now, beyond me | 03:30 |
tonyb | stevemar: Sure, the good news is in about a week you can bump it to 4.9.0 :) | 03:30 |
*** adrian_otto has joined #openstack-keystone | 03:31 | |
stevemar | :) | 03:31 |
tonyb | stevemar: I totally agree. It's a small "correctness" issue but one I'm commited to fixing in Ocata | 03:31 |
tonyb | stevemar: testing lower-bounds in projecst that support constraints is actually pretty easy now | 03:32 |
tonyb | stevemar: I only worked out how to do it last week so too late for Newton :( | 03:32 |
stevemar | rderose: did you just +W your first patch? | 03:32 |
stevemar | tonyb: great to hear that | 03:32 |
*** itsuugo has quit IRC | 03:32 | |
stevemar | tonyb: looking forward to it | 03:32 |
tonyb | stevemar: you signing up to be a test subject? | 03:33 |
*** itsuugo has joined #openstack-keystone | 03:34 | |
stevemar | tonyb: i'll happily assign the keystone project to be a test subject, my days of being a guinea pig are over | 03:37 |
tonyb | stevemar: okay. Thanks. | 03:38 |
*** chrisshattuck has quit IRC | 03:39 | |
*** david_cu has joined #openstack-keystone | 03:41 | |
*** itsuugo has quit IRC | 03:48 | |
*** itsuugo has joined #openstack-keystone | 03:49 | |
*** oomichi has joined #openstack-keystone | 03:53 | |
oomichi | stevemar: hi, thanks for your comment on https://bugs.launchpad.net/keystone/+bug/1622806 | 03:53 |
openstack | Launchpad bug 1622806 in OpenStack Identity (keystone) "v3 Credential APIs return credential in blob attribute as string instead of json object" [Undecided,Opinion] | 03:54 |
oomichi | stevemar: can we get more feedback? We will release keystone clients from Tempest for testing, and we'd like to confirm current API is intentional or not | 03:55 |
*** adrian_otto has quit IRC | 03:56 | |
*** adrian_otto has joined #openstack-keystone | 03:56 | |
stevemar | oomichi: the current API is definitely intentional | 03:57 |
openstackgerrit | Ha Van Tu proposed openstack/keystone: Refactor Keystone admin-endpoint API https://review.openstack.org/369808 | 03:57 |
stevemar | oomichi: i'll admit it's strange, but I inherited the weirdness, and i don't intend to break it :) | 03:58 |
*** hoangcx has joined #openstack-keystone | 03:59 | |
*** itsuugo has quit IRC | 03:59 | |
*** itsuugo has joined #openstack-keystone | 04:00 | |
openstackgerrit | Merged openstack/keystone: Remove unused method from keystone.common.utils https://review.openstack.org/368954 | 04:02 |
*** itsuugo has quit IRC | 04:10 | |
*** itsuugo has joined #openstack-keystone | 04:12 | |
*** hoangcx has left #openstack-keystone | 04:16 | |
*** adrian_otto has quit IRC | 04:18 | |
*** itsuugo has quit IRC | 04:19 | |
*** itsuugo has joined #openstack-keystone | 04:22 | |
openstackgerrit | Merged openstack/keystone: Consistently round down timestamps https://review.openstack.org/368244 | 04:23 |
tonyb | stevemar: I found my bug so now I see 2 users of requests-kerberos \o/ | 04:28 |
stevemar | tonyb: oh, what was the issue? | 04:28 |
*** esp has quit IRC | 04:29 | |
tonyb | stevemar: 'requests-kerberos>=0.6: python_version == "2.7" or python_version == "2.6"' from setup.cfg I wasn't converting the ':' to ';' so it parsed as invalid and I had debug infor turned off :( | 04:30 |
stevemar | ahh | 04:30 |
stevemar | mystery solved, for now :) | 04:31 |
tonyb | :) | 04:31 |
*** esp has joined #openstack-keystone | 04:32 | |
*** fangxu has quit IRC | 04:36 | |
stevemar | tonyb: i am gonna bug you again, and get you to remark on https://bugs.launchpad.net/keystone/+bug/1623168 | 04:40 |
openstack | Launchpad bug 1623168 in OpenStack Identity (keystone) "referencing versionutils.deprecated.NEWTON in oslo.log <3.4.0" [Medium,Confirmed] | 04:40 |
stevemar | tonyb: eh, i guess prometheanfire already commented on the review: https://review.openstack.org/#/c/366418/ | 04:41 |
*** itsuugo has quit IRC | 04:42 | |
tonyb | stevemar: Sure looking at it now. | 04:43 |
*** jaosorior has joined #openstack-keystone | 04:44 | |
*** itsuugo has joined #openstack-keystone | 04:44 | |
*** itsuugo has quit IRC | 04:51 | |
*** itsuugo has joined #openstack-keystone | 04:53 | |
*** roxanaghe has joined #openstack-keystone | 04:56 | |
*** jaosorior has quit IRC | 05:00 | |
*** jaosorior has joined #openstack-keystone | 05:01 | |
*** mordred has quit IRC | 05:16 | |
*** roxanaghe has quit IRC | 05:19 | |
*** roxanaghe has joined #openstack-keystone | 05:20 | |
*** mordred has joined #openstack-keystone | 05:20 | |
*** joerch has quit IRC | 05:22 | |
*** esp has quit IRC | 05:26 | |
*** itsuugo has quit IRC | 05:28 | |
*** ChanServ sets mode: +o stevemar | 05:28 | |
*** itsuugo has joined #openstack-keystone | 05:29 | |
*** rcernin has joined #openstack-keystone | 05:33 | |
*** richm has quit IRC | 05:40 | |
*** jamielennox|away is now known as jamielennox | 05:40 | |
*** itsuugo has quit IRC | 05:43 | |
*** itsuugo has joined #openstack-keystone | 05:45 | |
*** itsuugo has quit IRC | 05:52 | |
*** itsuugo has joined #openstack-keystone | 05:53 | |
davechen | henrynash: did you figure out how to run testcase with the DB other than sqlite? like we use to do the live test? | 05:59 |
davechen | henrynash: run it locally it always skipped, but gate test it well, any idea how to run it locally? | 06:00 |
*** roxanaghe has quit IRC | 06:04 | |
*** itsuugo has quit IRC | 06:07 | |
*** adriant has quit IRC | 06:08 | |
*** itsuugo has joined #openstack-keystone | 06:09 | |
*** fangxu has joined #openstack-keystone | 06:26 | |
*** itsuugo has quit IRC | 06:27 | |
*** itsuugo has joined #openstack-keystone | 06:29 | |
*** jaosorior has quit IRC | 06:29 | |
*** jaosorior has joined #openstack-keystone | 06:30 | |
*** pcaruana has joined #openstack-keystone | 06:32 | |
*** itsuugo has quit IRC | 06:34 | |
*** aswadr_ has joined #openstack-keystone | 06:34 | |
*** itsuugo has joined #openstack-keystone | 06:35 | |
*** code-R has joined #openstack-keystone | 06:38 | |
openstackgerrit | Dave Chen proposed openstack/keystone: Add foreign keys to trust table https://review.openstack.org/368422 | 06:40 |
openstackgerrit | Dave Chen proposed openstack/keystone: Invalidate trust when the trustor or trustee is deleted https://review.openstack.org/369354 | 06:40 |
*** itsuugo has quit IRC | 06:40 | |
*** iurygregory has quit IRC | 06:40 | |
*** iurygregory has joined #openstack-keystone | 06:40 | |
*** code-R_ has joined #openstack-keystone | 06:41 | |
*** mlovell has quit IRC | 06:41 | |
*** itsuugo has joined #openstack-keystone | 06:41 | |
*** joerch has joined #openstack-keystone | 06:42 | |
*** code-R has quit IRC | 06:44 | |
openstackgerrit | Ha Van Tu proposed openstack/keystone: Refactor Keystone admin-tenant API v2 https://review.openstack.org/369849 | 06:44 |
*** mlovell has joined #openstack-keystone | 06:45 | |
*** namnh has joined #openstack-keystone | 06:48 | |
*** itsuugo has quit IRC | 06:49 | |
*** itsuugo has joined #openstack-keystone | 06:50 | |
*** EinstCrazy has joined #openstack-keystone | 06:55 | |
*** tesseract- has joined #openstack-keystone | 06:57 | |
*** EinstCra_ has joined #openstack-keystone | 06:58 | |
*** EinstCrazy has quit IRC | 06:58 | |
*** diltram has quit IRC | 07:00 | |
*** EinstCra_ has quit IRC | 07:04 | |
*** jistr is now known as jistr|mtgs | 07:09 | |
*** jistr|mtgs is now known as jistr|mtg | 07:09 | |
*** baffle has quit IRC | 07:09 | |
*** diltram has joined #openstack-keystone | 07:09 | |
*** baffle has joined #openstack-keystone | 07:10 | |
*** bjolo has quit IRC | 07:13 | |
*** bjolo has joined #openstack-keystone | 07:15 | |
*** tqtran has joined #openstack-keystone | 07:26 | |
*** jaosorior has quit IRC | 07:27 | |
*** EinstCrazy has joined #openstack-keystone | 07:27 | |
*** jaosorior has joined #openstack-keystone | 07:27 | |
*** jaosorior has quit IRC | 07:29 | |
*** jaosorior has joined #openstack-keystone | 07:30 | |
*** tqtran has quit IRC | 07:31 | |
*** EinstCrazy has quit IRC | 07:32 | |
*** amoralej|off is now known as amoralej | 07:39 | |
*** itsuugo has quit IRC | 07:39 | |
*** EinstCrazy has joined #openstack-keystone | 07:40 | |
*** itsuugo has joined #openstack-keystone | 07:41 | |
*** EinstCrazy has quit IRC | 07:41 | |
*** jpena|off is now known as jpena | 07:42 | |
*** zzzeek has quit IRC | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:00 | |
*** permalac has joined #openstack-keystone | 08:03 | |
openstackgerrit | Ha Van Tu proposed openstack/keystone: Refactor Keystone admin-tokens and admin-users v2 https://review.openstack.org/369883 | 08:08 |
*** pnavarro has joined #openstack-keystone | 08:09 | |
*** code-R_ has quit IRC | 08:13 | |
*** asettle has joined #openstack-keystone | 08:29 | |
*** oomichi has quit IRC | 08:31 | |
*** oomichi has joined #openstack-keystone | 08:32 | |
*** andreykurilin has joined #openstack-keystone | 08:36 | |
openstackgerrit | Dave Chen proposed openstack/keystone: Refactor: Generate entity id in a consistent way https://review.openstack.org/368432 | 08:37 |
*** itsuugo has quit IRC | 08:51 | |
*** itsuugo has joined #openstack-keystone | 08:52 | |
*** davechen has left #openstack-keystone | 08:54 | |
*** itsuugo has quit IRC | 09:02 | |
*** itsuugo has joined #openstack-keystone | 09:03 | |
*** mvk has quit IRC | 09:19 | |
*** bjolo_ has joined #openstack-keystone | 09:20 | |
*** bjolo has quit IRC | 09:20 | |
*** code-R has joined #openstack-keystone | 09:27 | |
*** tqtran has joined #openstack-keystone | 09:28 | |
*** sdake_ has quit IRC | 09:28 | |
*** code-R_ has joined #openstack-keystone | 09:29 | |
openstackgerrit | Ha Van Tu proposed openstack/keystone: Refactor Keystone admin-tokens and admin-users v2 https://review.openstack.org/369883 | 09:31 |
openstackgerrit | Ha Van Tu proposed openstack/keystone: Refactor Keystone admin-tenant API v2 https://review.openstack.org/369849 | 09:31 |
*** tqtran has quit IRC | 09:32 | |
*** code-R has quit IRC | 09:32 | |
*** itsuugo has quit IRC | 09:33 | |
*** itsuugo has joined #openstack-keystone | 09:35 | |
*** permalac has quit IRC | 09:38 | |
*** daemontool has joined #openstack-keystone | 09:46 | |
*** mvk has joined #openstack-keystone | 09:52 | |
*** jaosorior is now known as jaosorior_lunch | 09:54 | |
*** richm has joined #openstack-keystone | 10:08 | |
openstackgerrit | Itxaka Serrano Garcia proposed openstack/keystone: Allow compatibility with keystonemiddleware 4.0.0 https://review.openstack.org/370011 | 10:26 |
*** jaosorior_lunch is now known as jaosorior | 10:27 | |
*** fangxu has quit IRC | 10:29 | |
*** fangxu has joined #openstack-keystone | 10:29 | |
*** EinstCrazy has joined #openstack-keystone | 10:30 | |
*** itsuugo has quit IRC | 10:36 | |
*** itsuugo has joined #openstack-keystone | 10:37 | |
openstackgerrit | Itxaka Serrano Garcia proposed openstack/keystone: Allow compatibility with keystonemiddleware 4.0.0 https://review.openstack.org/370011 | 10:41 |
*** EinstCrazy has quit IRC | 10:48 | |
*** itsuugo has quit IRC | 10:48 | |
*** itsuugo has joined #openstack-keystone | 10:49 | |
*** itsuugo has quit IRC | 10:56 | |
*** itsuugo has joined #openstack-keystone | 10:58 | |
*** nicolasbock has joined #openstack-keystone | 11:07 | |
*** itsuugo has quit IRC | 11:10 | |
*** itsuugo has joined #openstack-keystone | 11:11 | |
*** thebloggu has joined #openstack-keystone | 11:12 | |
*** jpena is now known as jpena|lunch | 11:17 | |
*** amoralej is now known as amoralej|lunch | 11:18 | |
*** itsuugo has quit IRC | 11:24 | |
*** itsuugo has joined #openstack-keystone | 11:26 | |
*** namnh has quit IRC | 11:29 | |
*** tqtran has joined #openstack-keystone | 11:29 | |
*** tqtran has quit IRC | 11:34 | |
*** openstackgerrit has quit IRC | 11:34 | |
*** openstackgerrit has joined #openstack-keystone | 11:34 | |
*** asettle has quit IRC | 11:42 | |
*** asettle has joined #openstack-keystone | 11:43 | |
*** asettle has quit IRC | 11:47 | |
*** dave-mccowan has joined #openstack-keystone | 11:47 | |
*** woodster_ has joined #openstack-keystone | 11:49 | |
*** itsuugo has quit IRC | 11:54 | |
*** edmondsw has joined #openstack-keystone | 11:55 | |
*** itsuugo has joined #openstack-keystone | 11:56 | |
stevemar | o/ | 12:02 |
*** asettle has joined #openstack-keystone | 12:07 | |
*** lamt has quit IRC | 12:17 | |
*** thebloggu has quit IRC | 12:19 | |
*** pauloewerton has joined #openstack-keystone | 12:25 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Allow compatibility with keystonemiddleware 4.0.0 https://review.openstack.org/370011 | 12:30 |
openstackgerrit | Boris Bobrov proposed openstack/keystone: Allow compatibility with keystonemiddleware 4.0.0 https://review.openstack.org/370011 | 12:32 |
stevemar | breton: doh! | 12:32 |
*** itsuugo has quit IRC | 12:32 | |
*** Guest98165 is now known as zeus | 12:32 | |
*** zeus has quit IRC | 12:33 | |
*** zeus has joined #openstack-keystone | 12:33 | |
*** itsuugo has joined #openstack-keystone | 12:33 | |
*** gordc has joined #openstack-keystone | 12:35 | |
*** itsuugo has quit IRC | 12:38 | |
*** itsuugo has joined #openstack-keystone | 12:39 | |
stevemar | dolphm: when you get a chance: https://review.openstack.org/#/c/369618/8 | 12:42 |
*** lamt has joined #openstack-keystone | 12:48 | |
*** itsuugo has quit IRC | 12:50 | |
*** itsuugo has joined #openstack-keystone | 12:52 | |
*** jpena|lunch is now known as jpena | 12:55 | |
*** amoralej|lunch is now known as amoralej | 12:56 | |
*** jaosorior has quit IRC | 13:01 | |
*** jaosorior has joined #openstack-keystone | 13:01 | |
*** afred312 has joined #openstack-keystone | 13:04 | |
*** afred312 has quit IRC | 13:14 | |
*** lamt has quit IRC | 13:18 | |
*** jistr|mtg is now known as jistr | 13:24 | |
*** tqtran has joined #openstack-keystone | 13:31 | |
*** zhugaoxiao has quit IRC | 13:35 | |
*** tqtran has quit IRC | 13:35 | |
*** itsuugo has quit IRC | 13:42 | |
*** markvoelker has joined #openstack-keystone | 13:43 | |
*** itsuugo has joined #openstack-keystone | 13:44 | |
*** jistr is now known as jistr|mtg | 13:49 | |
*** itsuugo has quit IRC | 13:50 | |
*** itsuugo has joined #openstack-keystone | 13:52 | |
*** lamt has joined #openstack-keystone | 13:52 | |
*** ddieterly has joined #openstack-keystone | 13:52 | |
*** woodburn has quit IRC | 13:54 | |
*** afred312 has joined #openstack-keystone | 13:56 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Allow compatibility with keystonemiddleware 4.0.0 https://review.openstack.org/370011 | 13:56 |
stevemar | dolphm: also when you get a chance... https://review.openstack.org/#/c/370011/5 | 13:57 |
*** sdake has joined #openstack-keystone | 13:58 | |
*** gagehugo_ has joined #openstack-keystone | 13:59 | |
breton | bug 1623091 needs to be reassigned again | 14:02 |
openstack | bug 1623091 in OpenStack Identity (keystone) "keystonemidleware dependency should be > 4.0.0" [Medium,In progress] https://launchpad.net/bugs/1623091 - Assigned to Steve Martinelli (stevemar) | 14:02 |
stevemar | breton: your comment made me lol | 14:04 |
*** rodrigods has quit IRC | 14:06 | |
*** rodrigods has joined #openstack-keystone | 14:06 | |
*** lamt has quit IRC | 14:06 | |
*** gagehugo_ has quit IRC | 14:07 | |
breton | dstanek: i also was wrong about expiration time none being 600. I've just checked dogpile code and could not find anything like this. Not sure why i saw that yesterday in the debugger. | 14:08 |
*** ayoung has quit IRC | 14:08 | |
aloga | stevemar: o/ | 14:09 |
*** Daviey_ is now known as Daviey | 14:12 | |
*** gagehugo has joined #openstack-keystone | 14:13 | |
frickler | so how should keystoneclient behave if e.g. both user_domain_name and user_domain_id are specified? currently it looks like _id is used and _name ignored, is this expected and documented? | 14:14 |
frickler | see https://bugs.launchpad.net/glance-store/+bug/1620999 for context | 14:14 |
openstack | Launchpad bug 1620999 in glance_store "glance_store ignores user_domain_name and project_domain_name settings" [Undecided,New] | 14:14 |
*** spedione|AWAY is now known as spedione | 14:16 | |
*** code-R_ has quit IRC | 14:17 | |
*** code-R has joined #openstack-keystone | 14:17 | |
*** raildo has joined #openstack-keystone | 14:22 | |
breton | can we get 409 Conflict on PATCH /v3/services/{service_id}? | 14:23 |
*** tonytan4ever has joined #openstack-keystone | 14:24 | |
breton | frickler: it is in keystoneauth | 14:25 |
breton | 43 if self.user_domain_id: | 14:25 |
breton | 44 user['domain'] = {'id': self.user_domain_id} | 14:25 |
breton | 45 elif self.user_domain_name: | 14:25 |
breton | 46 user['domain'] = {'name': self.user_domain_name} | 14:25 |
breton | frickler: so i think it's expected. Not sure it's documented though. | 14:27 |
breton | and i think it won't be fixed for compatibility reasons | 14:30 |
*** ravelar has joined #openstack-keystone | 14:31 | |
*** jaosorior has quit IRC | 14:31 | |
*** Marcellin__ has joined #openstack-keystone | 14:31 | |
*** pnavarro has quit IRC | 14:32 | |
stevemar | aloga: ahoy | 14:34 |
aloga | stevemar: howdy | 14:34 |
*** esp has joined #openstack-keystone | 14:34 | |
*** woodburn has joined #openstack-keystone | 14:36 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: Fixes password created_at errors due to the server_default https://review.openstack.org/367025 | 14:41 |
stevemar | rderose: thanks for the fix | 14:43 |
stevemar | aloga: i know you sent me that email ages ago | 14:43 |
stevemar | aloga: i still don't have an answer for you :( | 14:43 |
aloga | stevemar: ahaha :) | 14:43 |
aloga | stevemar: no worries, good to know that you are aware of it | 14:43 |
stevemar | aloga: aside from -- let's make our CLI work with openidconnect the same way GCE and launchpad work with it | 14:43 |
stevemar | aloga: where a browser pops up after invoking the CLI for the first time, and it saves an access token somewhere for a long time | 14:44 |
aloga | stevemar: then that's the way it's implemented right now, except the access token part (that is not saved) | 14:44 |
*** esp has quit IRC | 14:45 | |
aloga | stevemar: anyway, this would require an extra plugin on the keystone server side | 14:45 |
aloga | stevemar: so that we query the oidc userinfo endpoint to obtain any additional claim for an access token | 14:46 |
stevemar | aloga: fetching the claims from keystone (the shadowed user) or from the identity provider? | 14:47 |
aloga | from the idp | 14:47 |
stevemar | aloga: damn | 14:47 |
*** raildo has quit IRC | 14:47 | |
aloga | stevemar: :( | 14:47 |
*** raildo has joined #openstack-keystone | 14:47 | |
stevemar | brb | 14:47 |
aloga | stevemar: ok, ping me whenever you're back | 14:48 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add unit tests for isotime() https://review.openstack.org/370182 | 14:51 |
lbragstad | rderose rodrigods ^ | 14:51 |
lbragstad | addressed your comments there since the original patch merged | 14:51 |
stevemar | aloga: back | 14:52 |
rodrigods | lbragstad, nice! thanks for adding the test | 14:52 |
rodrigods | will review in a bit | 14:52 |
aloga | stevemar: o/ | 14:52 |
lbragstad | rodrigods no problem - thanks | 14:52 |
openstackgerrit | Ron De Rose proposed openstack/keystone: Fixes password created_at errors due to the server_default https://review.openstack.org/367025 | 14:53 |
lbragstad | rodrigods I actually couldn't find any existing tests for that method | 14:53 |
rodrigods | lbragstad, imagined that | 14:53 |
*** ddieterly is now known as ddieterly[away] | 14:54 | |
*** itsuugo has quit IRC | 14:54 | |
aloga | stevemar: roughly speaking, the access_token carries only some claims (oauth2.0), but not all the openid stuff, that is to be retrieved from the userinfo endpoint | 14:54 |
aloga | stevemar: some oidc providers (like google) serialize these claims in the access token | 14:55 |
aloga | stevemar: but this is not mandatory | 14:55 |
stevemar | aloga: would you be open to creating a keystone-spec for this issue? | 14:55 |
*** itsuugo has joined #openstack-keystone | 14:56 | |
breton | why all the hype about oauth2 lately? | 14:57 |
stevemar | breton: no idea' | 14:59 |
*** ddieterly[away] is now known as ddieterly | 14:59 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: Fixes password created_at errors due to the server_default https://review.openstack.org/367025 | 15:00 |
*** ddieterly has quit IRC | 15:01 | |
*** jistr|mtg is now known as jistr | 15:01 | |
*** LamT_ has quit IRC | 15:01 | |
aloga | stevemar: yes, but I cannot promise a deadline | 15:02 |
*** BjoernT has joined #openstack-keystone | 15:03 | |
*** david-lyle_ has joined #openstack-keystone | 15:06 | |
*** david-lyle_ has quit IRC | 15:06 | |
dolphm | stevemar: where do we test federation outside of keystone's own tests, and keystone's tempest plugin? don't we test against shib somewhere? | 15:11 |
*** ddieterly has joined #openstack-keystone | 15:13 | |
*** lamt has joined #openstack-keystone | 15:15 | |
*** ddieterly has quit IRC | 15:17 | |
*** ddieterly has joined #openstack-keystone | 15:18 | |
breton | henrynash: rodrigods: could you please revisit https://review.openstack.org/#/c/339294/13 ? | 15:18 |
*** dnalezyty has joined #openstack-keystone | 15:19 | |
rodrigods | breton, sure, will take a look later today | 15:19 |
*** dnalezyty has quit IRC | 15:19 | |
stevemar | dolphm: we do not | 15:23 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Switch fernet to be the default token provider. https://review.openstack.org/345688 | 15:23 |
stevemar | dolphm: and the tempest tests only test keystone APIs, just CRUD stuff | 15:23 |
dolphm | stevemar: boo, i was hoping we had more than just the API coverage | 15:23 |
stevemar | dolphm: i wish | 15:23 |
stevemar | dolphm: i've wanted to / have been advocating that for many releases now | 15:23 |
*** joerch has quit IRC | 15:23 | |
rodrigods | dolphm, stevemar, WIP for that effort: https://review.openstack.org/324769 and https://review.openstack.org/#/c/320623/ | 15:24 |
*** adrian_otto has joined #openstack-keystone | 15:27 | |
dolphm | rodrigods: awesome | 15:29 |
rodrigods | dolphm, will revisit the devstack plugin once I have free cycles (expect to be soon) | 15:30 |
dolphm | rodrigods: good to hear | 15:30 |
rodrigods | dolphm, the test itself runs successfully in manual deployments | 15:31 |
*** ddieterly is now known as ddieterly[away] | 15:31 | |
BjoernT | dolphm: can you briefly describe how token caching work inside the keystone client ? I see odd behaviors of cinder-api, not caching tokens correctly | 15:31 |
*** rcernin has quit IRC | 15:34 | |
stevemar | dolphm / lbragstad i need reviews for https://review.openstack.org/#/c/369618/ and https://review.openstack.org/#/c/370011/ please and thank you :) | 15:36 |
* stevemar is eager to get a mitaka release out this week too! | 15:36 | |
*** pcaruana has quit IRC | 15:40 | |
*** roxanaghe has joined #openstack-keystone | 15:41 | |
*** ddieterly[away] has quit IRC | 15:41 | |
*** code-R has quit IRC | 15:43 | |
*** daemontool_ has joined #openstack-keystone | 15:45 | |
*** BjoernT has quit IRC | 15:45 | |
*** daemontool has quit IRC | 15:48 | |
breton | i would like to hear dstanek's opinion on https://review.openstack.org/#/c/369618/ too | 15:49 |
*** ddieterly has joined #openstack-keystone | 15:50 | |
*** roxanaghe has quit IRC | 15:51 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Adds tests for verify_length_and_trunc_password() https://review.openstack.org/370239 | 15:51 |
stevemar | breton: for sure | 15:51 |
*** code-R has joined #openstack-keystone | 15:52 | |
breton | harlowja: where will the meeting be? | 15:52 |
*** BjoernT has joined #openstack-keystone | 15:52 | |
dstanek | breton: i just figured out the other bug... so i can go ahead and take a look in just a few | 15:53 |
*** ayoung has joined #openstack-keystone | 15:57 | |
*** ChanServ sets mode: +v ayoung | 15:57 | |
*** fangxu has quit IRC | 15:57 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add unit tests for isotime() https://review.openstack.org/370182 | 15:59 |
*** gyee has joined #openstack-keystone | 16:01 | |
*** browne has joined #openstack-keystone | 16:03 | |
*** ayoung has quit IRC | 16:04 | |
lbragstad | does anyone know if setup_remote_pydev_debug is used anywhere? Seems like a helper method but I don't see it used anywhere in keystone/ | 16:06 |
openstackgerrit | Richard Avelar proposed openstack/keystone: Reduce revoke events for disabled domains/projects https://review.openstack.org/370252 | 16:07 |
stevemar | lbragstad: i was going to remove that too, but notmorgan said to keep it around | 16:07 |
stevemar | i trust him | 16:07 |
lbragstad | stevemar ah - makes sense | 16:07 |
lbragstad | i wonder what the reason was | 16:07 |
stevemar | lbragstad: i assume magic | 16:08 |
lbragstad | out keystone.common.utils module seems to have a bunch of unused or untested things | 16:08 |
stevemar | lbragstad: that's not unusual | 16:08 |
lbragstad | stevemar that's a scary reason to keep something around ;) | 16:08 |
stevemar | is there a tool that analyses if functions are unused? | 16:08 |
dstanek | stevemar: nothing really good | 16:09 |
stevemar | dstanek: https://pypi.python.org/pypi/vulture ? | 16:09 |
dstanek | stevemar: yep, nothing good. you still have to do a good amount of due diligenge to make sure things are not actually used | 16:11 |
*** jpena is now known as jpena|off | 16:11 | |
stevemar | lbragstad: dstanek if you want a starting point... http://paste.openstack.org/show/576298/ | 16:12 |
stevemar | dstanek: seems that way, yeah | 16:12 |
lbragstad | oh man... | 16:13 |
*** antonbud has joined #openstack-keystone | 16:14 | |
*** ddieterly has quit IRC | 16:16 | |
*** ravelar has quit IRC | 16:19 | |
*** esp has joined #openstack-keystone | 16:20 | |
*** amoralej is now known as amoralej|off | 16:21 | |
*** code-R has quit IRC | 16:21 | |
*** ddieterly has joined #openstack-keystone | 16:27 | |
stevemar | lbragstad: you could probably filter those through a grep and get a basic set of dead functions | 16:30 |
lbragstad | yeah - some of those don't necessarily apply but I can start poking at it | 16:31 |
openstackgerrit | Ron De Rose proposed openstack/keystone: Fixes password created_at errors due to the server_default https://review.openstack.org/367025 | 16:31 |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Add an "observer" role to policy.json https://review.openstack.org/274157 | 16:31 |
stevemar | lbragstad: dead for sure: https://github.com/openstack/keystone/blob/8ebeb6415efd26498f498c2080710f2dd04241af/keystone/common/fernet_utils.py#L71 | 16:31 |
stevemar | lbragstad: these: https://github.com/openstack/keystone/blob/0340cd0150af04f950e2b868c932dfee2dbf8530/keystone/common/utils.py#L203-L220 | 16:32 |
*** rcernin has joined #openstack-keystone | 16:34 | |
stevemar | lbragstad: this, but ravelar is looking at it: https://github.com/openstack/keystone/blob/0340cd0150af04f950e2b868c932dfee2dbf8530/keystone/models/revoke_model.py#L55-L60 | 16:34 |
*** roxanaghe has joined #openstack-keystone | 16:35 | |
*** tesseract- has quit IRC | 16:35 | |
stevemar | lbragstad: yeh, theres definitely some valid stuff to remove | 16:36 |
stevemar | lots of false positives though | 16:36 |
lbragstad | stevemar we still test these apparently - https://github.com/openstack/keystone/blob/0340cd0150af04f950e2b868c932dfee2dbf8530/keystone/common/utils.py#L203-L220 | 16:37 |
lbragstad | stevemar http://104.130.175.68/master/ | 16:38 |
stevemar | lbragstad: not sure how... | 16:38 |
lbragstad | looks like it's called from the ec2 controller? | 16:39 |
*** ddieterly is now known as ddieterly[away] | 16:39 | |
*** ddieterly[away] is now known as ddieterly | 16:46 | |
*** mvk has quit IRC | 16:47 | |
*** roxanaghe has quit IRC | 16:50 | |
*** ravelar has joined #openstack-keystone | 16:53 | |
*** lamt has quit IRC | 16:54 | |
*** roxanaghe has joined #openstack-keystone | 16:57 | |
*** ravelar has quit IRC | 16:58 | |
*** jed56 has joined #openstack-keystone | 16:59 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Remove unused _convert_to_integers() method https://review.openstack.org/370305 | 17:01 |
*** adrian_otto has quit IRC | 17:03 | |
harlowja | breton let me double check, making sure that people are actually gonna show up :-P | 17:05 |
harlowja | kfox1111 u poked anyone in k8s ? | 17:05 |
harlowja | i still am learning the whole (how do u schedule a meeting thing, ha) | 17:05 |
*** ddieterly is now known as ddieterly[away] | 17:06 | |
harlowja | so breton notmorgan let me just double check first | 17:07 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add unit tests for isotime() https://review.openstack.org/370182 | 17:12 |
*** ddieterly[away] has quit IRC | 17:16 | |
*** lamt has joined #openstack-keystone | 17:17 | |
*** adrian_otto has joined #openstack-keystone | 17:17 | |
*** asettle has quit IRC | 17:17 | |
*** asettle has joined #openstack-keystone | 17:18 | |
*** gagehugo has quit IRC | 17:18 | |
*** adrian_otto has quit IRC | 17:19 | |
notmorgan | harlowja: ? | 17:19 |
*** antonbud has quit IRC | 17:19 | |
*** adrian_otto has joined #openstack-keystone | 17:20 | |
*** daemontool_ has quit IRC | 17:21 | |
*** fangxu has joined #openstack-keystone | 17:25 | |
*** asettle has quit IRC | 17:26 | |
*** ddieterly has joined #openstack-keystone | 17:30 | |
harlowja | notmorgan rescheduling | 17:31 |
harlowja | still learning how to actually connect with the k8s way of doing meetings | 17:31 |
notmorgan | harlowja: okie | 17:31 |
harlowja | which seems to be in a google doc somewhere | 17:31 |
harlowja | lol | 17:31 |
notmorgan | just let me know when. | 17:31 |
harlowja | cool | 17:31 |
*** tqtran has joined #openstack-keystone | 17:34 | |
crinkle | what should the config option [saml]/idp_sso_endpoint point to on a keystone IdP? i have a URI ending in /v3/OS-FEDERATION/saml2/sso like the example but I'm seeing "unable to locate compatible SSO service for provider", probably because it doesn't resolve | 17:34 |
*** adrian_otto has quit IRC | 17:34 | |
rodrigods | crinkle, is that for websso or ecp? | 17:37 |
rodrigods | websso, right? | 17:37 |
crinkle | rodrigods: websso | 17:37 |
*** tqtran has quit IRC | 17:38 | |
*** Alexey_Abashkin has joined #openstack-keystone | 17:38 | |
rodrigods | crinkle, k2k with websso? | 17:39 |
rodrigods | stevemar, it still not possible, right? ^ (without some tweaks) | 17:39 |
crinkle | rodrigods: yes | 17:39 |
crinkle | aha | 17:39 |
*** gagehugo has joined #openstack-keystone | 17:40 | |
*** ddieterly is now known as ddieterly[away] | 17:40 | |
rodrigods | crinkle, for k2k we do a crippled ecp, so basically, the SP side doesn't care about the sso endpoint in the metadata | 17:41 |
rderose | stevemar: this one is ready: https://review.openstack.org/#/c/367025/ | 17:41 |
*** AlexeyAbashkin has quit IRC | 17:41 | |
crinkle | rodrigods: is there documentation or a blog post you could point me to about that? | 17:46 |
rodrigods | crinkle, about what? making k2k websso possible? | 17:46 |
crinkle | rodrigods: about "crippled ecp" | 17:46 |
crinkle | or is that what the Keystone2Keystone ksa plugin is doing? | 17:47 |
crinkle | because i have that working | 17:47 |
*** ravelar has joined #openstack-keystone | 17:47 | |
rodrigods | crinkle, ah... not sure where to find... but if you check the complete ecp flow in wikipedia and compare on what we do for k2k | 17:47 |
rodrigods | you will see that we "jump" some initial steps | 17:47 |
rodrigods | crinkle, and ksa plugin implements exactly that | 17:48 |
rodrigods | for example... compare the steps of the saml ecp plugin with the k2k one | 17:48 |
crinkle | okay i understand now | 17:48 |
*** ddieterly[away] has quit IRC | 17:50 | |
crinkle | in what context is the idp_sso_endpoint option useful then? | 17:51 |
*** adrian_otto has joined #openstack-keystone | 17:54 | |
*** tqtran has joined #openstack-keystone | 17:54 | |
*** adrian_otto has quit IRC | 18:01 | |
*** adrian_otto has joined #openstack-keystone | 18:02 | |
*** BjoernT has quit IRC | 18:03 | |
*** mvk has joined #openstack-keystone | 18:03 | |
*** adrian_otto has quit IRC | 18:10 | |
*** adrian_otto has joined #openstack-keystone | 18:10 | |
*** itsuugo has quit IRC | 18:19 | |
*** itsuugo has joined #openstack-keystone | 18:20 | |
*** chrisshattuck has joined #openstack-keystone | 18:43 | |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Test that rolling upgrade repos are in lockstep https://review.openstack.org/370370 | 18:45 |
*** tonytan4ever has quit IRC | 18:51 | |
*** ayoung has joined #openstack-keystone | 19:01 | |
*** ChanServ sets mode: +v ayoung | 19:01 | |
*** pcaruana has joined #openstack-keystone | 19:07 | |
*** ddieterly has joined #openstack-keystone | 19:20 | |
*** adrian_otto has quit IRC | 19:22 | |
*** jed56 has quit IRC | 19:25 | |
*** sdake_ has joined #openstack-keystone | 19:29 | |
stevemar | crinkle: it may be used in the assertion for something, i forget the details | 19:31 |
*** aswadr_ has quit IRC | 19:32 | |
stevemar | crinkle: but there were a bunch of those things that needed to be configured (with not null values) to actually produce a meaningful assertion | 19:32 |
stevemar | lbragstad: did i read the meeting transcript correctly? you are gonna update the install guide?!? :) | 19:33 |
*** sdake has quit IRC | 19:33 | |
lbragstad | stevemar yeah - working on fixing up some of the issues now | 19:33 |
crinkle | stevemar: ah okay | 19:33 |
crinkle | thanks stevemar and rodrigods | 19:34 |
* stevemar thanks lbragstad | 19:34 | |
stevemar | crinkle: what do you have cooking? | 19:34 |
stevemar | crinkle: nobody whips up a k2k PoC for fun | 19:35 |
lbragstad | stevemar no problem | 19:35 |
crinkle | stevemar: just want to enhance/correct the federation docs, this stuff is not super easy to figure out | 19:35 |
knikolla | k2k is fun | 19:41 |
stevemar | crinkle: i would appreciate that immensely | 19:43 |
*** asettle has joined #openstack-keystone | 19:43 | |
stevemar | knikolla: you have a strange sense of fun | 19:43 |
knikolla | stevemar: stockholm syndrome i guess | 19:45 |
stevemar | knikolla: :) | 19:45 |
*** fangxu has quit IRC | 19:48 | |
*** pnavarro has joined #openstack-keystone | 19:52 | |
*** tonytan4ever has joined #openstack-keystone | 19:52 | |
*** hoonetorg has quit IRC | 19:53 | |
*** tonytan4ever has quit IRC | 19:53 | |
*** tonytan4ever has joined #openstack-keystone | 19:54 | |
*** chrisshattuck has quit IRC | 19:54 | |
*** can8dnSix has joined #openstack-keystone | 19:55 | |
*** pcaruana has quit IRC | 20:00 | |
*** lamt has quit IRC | 20:01 | |
*** lamt has joined #openstack-keystone | 20:07 | |
*** hoonetorg has joined #openstack-keystone | 20:08 | |
*** can8dnSix has quit IRC | 20:08 | |
*** can8dnSix has joined #openstack-keystone | 20:13 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: Fixes password created_at errors due to the server_default https://review.openstack.org/367025 | 20:16 |
*** pauloewerton has quit IRC | 20:21 | |
*** tonytan4ever has quit IRC | 20:22 | |
*** rcernin has quit IRC | 20:36 | |
*** rcernin has joined #openstack-keystone | 20:40 | |
*** rcernin has quit IRC | 20:41 | |
*** rcernin has joined #openstack-keystone | 20:41 | |
*** rcernin has quit IRC | 20:42 | |
*** rcernin has joined #openstack-keystone | 20:42 | |
*** pnavarro has quit IRC | 20:47 | |
*** fangxu has joined #openstack-keystone | 20:53 | |
*** can8dnSix has quit IRC | 20:59 | |
*** gyee has quit IRC | 21:04 | |
*** ddieterly is now known as ddieterly[away] | 21:05 | |
*** jlwhite has joined #openstack-keystone | 21:08 | |
*** roxanaghe has quit IRC | 21:09 | |
*** roxanaghe has joined #openstack-keystone | 21:14 | |
dstanek | mfisch: have you taken a look at https://review.openstack.org/#/c/369618 ? it's a mitaka backport for the cache invalidation issue. you were seeing this on mitaka right? | 21:20 |
*** edmondsw has quit IRC | 21:21 | |
*** asettle has quit IRC | 21:25 | |
*** ddieterly[away] is now known as ddieterly | 21:31 | |
openstackgerrit | Merged openstack/keystone: Add unit tests for isotime() https://review.openstack.org/370182 | 21:33 |
*** joerch has joined #openstack-keystone | 21:45 | |
openstackgerrit | Richard Avelar proposed openstack/keystone: Reduce revoke events for disabled domains/projects https://review.openstack.org/370252 | 21:46 |
*** dave-mccowan has quit IRC | 21:48 | |
*** asettle has joined #openstack-keystone | 21:53 | |
*** tonytan4ever has joined #openstack-keystone | 21:53 | |
openstackgerrit | Richard Avelar proposed openstack/keystone: Reduce revoke events for disabled domains/projects https://review.openstack.org/370252 | 21:53 |
*** ravelar has quit IRC | 21:54 | |
*** tonytan4ever has quit IRC | 21:58 | |
openstackgerrit | Merged openstack/keystone: Allow compatibility with keystonemiddleware 4.0.0 https://review.openstack.org/370011 | 22:05 |
*** esp has quit IRC | 22:11 | |
*** asettle has quit IRC | 22:12 | |
*** esp has joined #openstack-keystone | 22:12 | |
*** spedione is now known as spedione|AWAY | 22:13 | |
*** browne has quit IRC | 22:13 | |
*** gyee has joined #openstack-keystone | 22:17 | |
*** gordc has quit IRC | 22:20 | |
*** itsuugo has quit IRC | 22:26 | |
*** itsuugo has joined #openstack-keystone | 22:28 | |
*** lamt has quit IRC | 22:29 | |
*** sdake_ has quit IRC | 22:40 | |
*** chrisshattuck has joined #openstack-keystone | 22:40 | |
*** rcernin has quit IRC | 22:43 | |
*** itsuugo has quit IRC | 22:52 | |
*** itsuugo has joined #openstack-keystone | 22:53 | |
*** ddieterly has quit IRC | 22:53 | |
*** roxanaghe has quit IRC | 22:54 | |
*** roxanaghe has joined #openstack-keystone | 22:55 | |
*** adrian_otto has joined #openstack-keystone | 22:56 | |
*** lamt has joined #openstack-keystone | 23:06 | |
*** itsuugo has quit IRC | 23:10 | |
*** itsuugo has joined #openstack-keystone | 23:11 | |
*** browne has joined #openstack-keystone | 23:13 | |
*** chrisshattuck has quit IRC | 23:20 | |
*** jamielennox is now known as jamielennox|away | 23:22 | |
*** chrisshattuck has joined #openstack-keystone | 23:23 | |
*** chrisshattuck has quit IRC | 23:25 | |
*** adriant has joined #openstack-keystone | 23:28 | |
openstackgerrit | Merged openstack/keystone: Remove unused _convert_to_integers() method https://review.openstack.org/370305 | 23:43 |
openstackgerrit | Merged openstack/keystone: Remove unused read_cached_file method from utils https://review.openstack.org/370228 | 23:43 |
*** browne has quit IRC | 23:45 | |
*** itsuugo has quit IRC | 23:57 | |
*** itsuugo has joined #openstack-keystone | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!