*** adrian_otto has joined #openstack-keystone | 00:02 | |
*** adrian_otto has quit IRC | 00:07 | |
*** adrian_otto has joined #openstack-keystone | 00:11 | |
*** spzala has joined #openstack-keystone | 00:15 | |
*** adrian_otto has quit IRC | 00:16 | |
*** adrian_otto has joined #openstack-keystone | 00:18 | |
*** browne has quit IRC | 00:28 | |
*** markvoelker has quit IRC | 00:30 | |
*** adrian_otto has quit IRC | 00:31 | |
*** david-lyle_ has joined #openstack-keystone | 00:38 | |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone: PCI-DSS functional tests https://review.openstack.org/377010 | 00:39 |
---|---|---|
*** david-lyle has quit IRC | 00:41 | |
*** Marcellin__ has quit IRC | 00:47 | |
*** tqtran has quit IRC | 00:48 | |
*** adu has quit IRC | 00:51 | |
*** GB21 has joined #openstack-keystone | 00:52 | |
*** adu has joined #openstack-keystone | 00:54 | |
openstackgerrit | Rodrigo Duarte proposed openstack/python-keystoneclient: DO NOT MERGE: test revocation search to sql https://review.openstack.org/374999 | 01:15 |
*** EinstCrazy has joined #openstack-keystone | 01:15 | |
*** davechen has joined #openstack-keystone | 01:24 | |
*** alex_xu has quit IRC | 01:27 | |
*** sdake has quit IRC | 01:28 | |
*** alex_xu has joined #openstack-keystone | 01:31 | |
*** markvoelker has joined #openstack-keystone | 01:31 | |
*** harlowja has quit IRC | 01:35 | |
*** markvoelker has quit IRC | 01:36 | |
*** spzala has quit IRC | 01:55 | |
*** haplo37_ has quit IRC | 02:00 | |
*** haplo37_ has joined #openstack-keystone | 02:02 | |
openstackgerrit | Tony Xu proposed openstack/pycadf: Clean oslo.i18n https://review.openstack.org/374522 | 02:07 |
*** ebalduf has joined #openstack-keystone | 02:07 | |
darrenc | hi, I'm testing the install guide and have an issue with installing keystone. Can anyone help? | 02:07 |
darrenc | I'm getting the same issue mentioned here: https://bugs.launchpad.net/openstack-manuals/+bug/1612409 | 02:09 |
openstack | Launchpad bug 1612409 in openstack-manuals "Populate the Identity service database" [Undecided,Invalid] | 02:09 |
*** ebalduf has quit IRC | 02:09 | |
*** richm has quit IRC | 02:24 | |
*** adrian_otto has joined #openstack-keystone | 02:27 | |
*** nicolasbock has quit IRC | 02:29 | |
*** henrynash has quit IRC | 02:30 | |
*** henrynash has joined #openstack-keystone | 02:34 | |
openstackgerrit | Anh Tran proposed openstack/python-keystoneclient: TrivialFix: Using assertTrue() instead of assertEqual(True) https://review.openstack.org/377165 | 02:34 |
*** adrian_otto has quit IRC | 02:35 | |
*** GB21 has quit IRC | 02:37 | |
*** iurygregory_ has quit IRC | 02:38 | |
*** richm has joined #openstack-keystone | 02:41 | |
*** david-lyle_ has quit IRC | 02:48 | |
*** gagehugo has quit IRC | 02:49 | |
*** david-lyle has joined #openstack-keystone | 02:49 | |
openstackgerrit | Anh Tran proposed openstack/pycadf: TrivialFix: Using assertTrue() instead of assertEqual(True) https://review.openstack.org/377172 | 02:53 |
*** GB21 has joined #openstack-keystone | 02:54 | |
*** sdake has joined #openstack-keystone | 02:55 | |
openstackgerrit | Anh Tran proposed openstack/pycadf: TrivialFix: Using assertTrue/False instead of assertEqual() https://review.openstack.org/377172 | 02:56 |
*** david-lyle has quit IRC | 03:04 | |
*** ravelar has quit IRC | 03:04 | |
*** sdake has quit IRC | 03:15 | |
*** adrian_otto has joined #openstack-keystone | 03:16 | |
*** adu has quit IRC | 03:18 | |
*** sdake has joined #openstack-keystone | 03:23 | |
*** markvoelker has joined #openstack-keystone | 03:32 | |
*** markvoelker has quit IRC | 03:38 | |
*** yarkot has quit IRC | 03:39 | |
*** sdake has quit IRC | 03:40 | |
*** sdake has joined #openstack-keystone | 03:41 | |
openstackgerrit | Anh Tran proposed openstack/python-keystoneclient: TrivialFix: Using assertIsNone() instead of assertEqual(None) https://review.openstack.org/377190 | 03:43 |
*** yarkot has joined #openstack-keystone | 03:45 | |
*** aswadr_ has joined #openstack-keystone | 03:45 | |
*** adrian_otto has quit IRC | 03:45 | |
*** tqtran has joined #openstack-keystone | 03:47 | |
*** sdake has quit IRC | 03:47 | |
*** adrian_otto has joined #openstack-keystone | 03:48 | |
openstackgerrit | Dave Chen proposed openstack/keystone: Deprecate `endpoint_filter.sql` backend https://review.openstack.org/375931 | 03:51 |
*** tqtran has quit IRC | 03:52 | |
*** GB21 has quit IRC | 03:53 | |
openstackgerrit | Anh Tran proposed openstack/python-keystoneclient: Import module instead of object https://review.openstack.org/377198 | 03:55 |
*** adrian_otto has quit IRC | 03:57 | |
*** dikonoor has joined #openstack-keystone | 04:08 | |
*** sdake has joined #openstack-keystone | 04:15 | |
*** links has joined #openstack-keystone | 04:19 | |
*** sdake_ has joined #openstack-keystone | 04:22 | |
*** sdake has quit IRC | 04:24 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: create release notes for removed functionality https://review.openstack.org/375914 | 04:26 |
*** roxanaghe has quit IRC | 04:29 | |
*** roxanaghe has joined #openstack-keystone | 04:29 | |
*** tqtran has joined #openstack-keystone | 04:29 | |
openstackgerrit | Anh Tran proposed openstack/keystone: Using assertIsNone() instead of assertIs(None) https://review.openstack.org/377220 | 04:33 |
*** roxanaghe has quit IRC | 04:34 | |
*** GB21 has joined #openstack-keystone | 04:36 | |
*** sdake_ has quit IRC | 04:40 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: remove deprecated items from contrib https://review.openstack.org/374489 | 04:40 |
openstackgerrit | Merged openstack/pycadf: Clean oslo.i18n https://review.openstack.org/374522 | 04:41 |
*** sdake has joined #openstack-keystone | 04:43 | |
*** dikonoor has quit IRC | 04:46 | |
*** sdake_ has joined #openstack-keystone | 04:46 | |
*** sdake has quit IRC | 04:48 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: remove deprecated items from contrib https://review.openstack.org/374489 | 04:49 |
*** jrist has joined #openstack-keystone | 04:51 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: remove deprecated config options https://review.openstack.org/374504 | 04:54 |
*** sdake_ has quit IRC | 04:58 | |
*** jaosorior has joined #openstack-keystone | 05:07 | |
*** jlopezgu has quit IRC | 05:08 | |
*** hugokuo has quit IRC | 05:08 | |
*** hugokuo has joined #openstack-keystone | 05:08 | |
*** jlopezgu has joined #openstack-keystone | 05:10 | |
*** dikonoor has joined #openstack-keystone | 05:11 | |
*** jaosorior has quit IRC | 05:19 | |
*** jaosorior has joined #openstack-keystone | 05:20 | |
*** tonytan4ever has quit IRC | 05:20 | |
*** lamt has quit IRC | 05:21 | |
*** richm has quit IRC | 05:40 | |
*** dikonoor has quit IRC | 05:40 | |
*** code-R has joined #openstack-keystone | 05:45 | |
*** code-R_ has joined #openstack-keystone | 05:47 | |
*** code-R has quit IRC | 05:50 | |
*** jrist has quit IRC | 05:53 | |
breton | morning, keystone | 05:55 |
*** dikonoor has joined #openstack-keystone | 05:59 | |
*** woodster_ has quit IRC | 06:10 | |
*** tqtran has quit IRC | 06:21 | |
*** pcaruana has joined #openstack-keystone | 06:45 | |
*** GB21 has quit IRC | 06:47 | |
*** ravelar has joined #openstack-keystone | 06:53 | |
*** ravelar has quit IRC | 06:58 | |
*** rcernin has joined #openstack-keystone | 06:59 | |
*** GB21 has joined #openstack-keystone | 07:09 | |
*** GB21 has quit IRC | 07:13 | |
*** GB21 has joined #openstack-keystone | 07:13 | |
*** GB21 has quit IRC | 07:15 | |
*** GB21 has joined #openstack-keystone | 07:15 | |
*** tonytan4ever has joined #openstack-keystone | 07:21 | |
*** xek has joined #openstack-keystone | 07:25 | |
*** tonytan4ever has quit IRC | 07:26 | |
*** hoonetorg has quit IRC | 07:42 | |
*** code-R_ has quit IRC | 07:43 | |
*** anteaya has quit IRC | 07:48 | |
*** anteaya has joined #openstack-keystone | 07:49 | |
*** hoonetorg has joined #openstack-keystone | 07:59 | |
*** zzzeek has quit IRC | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:00 | |
*** amoralej|off is now known as amoralej | 08:02 | |
openstackgerrit | Merged openstack/keystone: Remove unused path in the v2 token controller https://review.openstack.org/375607 | 08:09 |
*** tonytan4ever has joined #openstack-keystone | 08:22 | |
*** tonytan4ever has quit IRC | 08:27 | |
*** ChanServ sets mode: +v henrynash | 08:28 | |
*** pnavarro has joined #openstack-keystone | 08:38 | |
*** hoonetorg has quit IRC | 08:51 | |
openstackgerrit | Boris Bobrov proposed openstack/keystone: remove deprecated items from contrib https://review.openstack.org/374489 | 08:55 |
*** GB21 has quit IRC | 08:57 | |
openstackgerrit | Merged openstack/keystone: Remove useless method override https://review.openstack.org/375524 | 09:00 |
*** code-R has joined #openstack-keystone | 09:02 | |
*** hoonetorg has joined #openstack-keystone | 09:02 | |
*** code-R_ has joined #openstack-keystone | 09:09 | |
*** GB21 has joined #openstack-keystone | 09:10 | |
*** namnh has joined #openstack-keystone | 09:11 | |
*** code-R has quit IRC | 09:11 | |
*** jaosorior is now known as jaosorior_lunch | 09:18 | |
*** mvk has quit IRC | 09:27 | |
*** GB21 has quit IRC | 09:28 | |
*** namnh has quit IRC | 09:28 | |
*** GB21 has joined #openstack-keystone | 09:41 | |
*** haplo37_ has quit IRC | 09:56 | |
*** jmccrory has quit IRC | 09:57 | |
openstackgerrit | Stephen Finucane proposed openstack/oslo.policy: Add sphinx extension to build sample policy https://review.openstack.org/376544 | 09:57 |
*** mvk has joined #openstack-keystone | 09:58 | |
*** haplo37_ has joined #openstack-keystone | 09:59 | |
*** jmccrory has joined #openstack-keystone | 10:00 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/377448 | 10:00 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystoneauth: Updated from global requirements https://review.openstack.org/377449 | 10:00 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystonemiddleware: Updated from global requirements https://review.openstack.org/377450 | 10:00 |
*** zeus has quit IRC | 10:01 | |
*** melwitt has quit IRC | 10:01 | |
*** melwitt has joined #openstack-keystone | 10:01 | |
*** melwitt is now known as Guest3203 | 10:02 | |
*** zeus has joined #openstack-keystone | 10:02 | |
*** zeus is now known as Guest71546 | 10:02 | |
*** EinstCrazy has quit IRC | 10:03 | |
*** EinstCrazy has joined #openstack-keystone | 10:04 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/oslo.policy: Updated from global requirements https://review.openstack.org/377537 | 10:06 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/pycadf: Updated from global requirements https://review.openstack.org/377546 | 10:06 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements https://review.openstack.org/377555 | 10:07 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-keystoneclient-kerberos: Updated from global requirements https://review.openstack.org/373686 | 10:07 |
*** EinstCrazy has quit IRC | 10:08 | |
*** mah has joined #openstack-keystone | 10:13 | |
*** richm has joined #openstack-keystone | 10:13 | |
*** asettle has joined #openstack-keystone | 10:17 | |
*** tonytan4ever has joined #openstack-keystone | 10:23 | |
*** sdake has joined #openstack-keystone | 10:27 | |
*** tonytan4ever has quit IRC | 10:28 | |
*** jaosorior_lunch is now known as jaosorior | 10:34 | |
openstackgerrit | Stephen Finucane proposed openstack/oslo.policy: Add sphinx extension to build sample policy https://review.openstack.org/376544 | 10:46 |
*** nicolasbock has joined #openstack-keystone | 10:50 | |
robcresswell | Hi hi. Been mucking around with Horizon locally and Devstack on a VM. Recently, this setup has suddenly started failing; horizon seems to be able to hit keystone, but always returns with "Unable to retrieve authorized projects" | 10:57 |
*** dikonoor has quit IRC | 10:59 | |
robcresswell | Logs show it retrieving the user it seems, but failing on the project list every time. I'm unsure why. I don't suppose this looks familiar to anyone? | 10:59 |
*** prashanth has joined #openstack-keystone | 11:01 | |
*** dikonoor has joined #openstack-keystone | 11:06 | |
*** sdake has quit IRC | 11:12 | |
*** dikonoor has quit IRC | 11:15 | |
openstackgerrit | Kobi Samoray proposed openstack/keystone: Fix a docstring typo in test_v3_resource.py https://review.openstack.org/377618 | 11:25 |
*** amoralej is now known as amoralej|lunch | 11:26 | |
*** dikonoor has joined #openstack-keystone | 11:29 | |
openstackgerrit | Kobi Samoray proposed openstack/keystone: Fix a docstring typo in test_v3_resource.py https://review.openstack.org/377618 | 11:30 |
openstackgerrit | Kobi Samoray proposed openstack/keystone: Fix a docstring typo in test_v3_resource.py https://review.openstack.org/377618 | 11:31 |
*** dikonoo has joined #openstack-keystone | 11:36 | |
*** dikonoor has quit IRC | 11:39 | |
*** dikonoo has quit IRC | 11:49 | |
*** dikonoo has joined #openstack-keystone | 11:59 | |
*** jaosorior has quit IRC | 12:06 | |
*** jaosorior has joined #openstack-keystone | 12:06 | |
openstackgerrit | Anh Tran proposed openstack/keystone: Using assertIsNone(...) instead of assertIs(None, ...) https://review.openstack.org/377220 | 12:10 |
*** rodrigods has quit IRC | 12:12 | |
*** rodrigods has joined #openstack-keystone | 12:12 | |
*** davechen has left #openstack-keystone | 12:15 | |
rodrigods | dstanek, there? have a question that you might be able to respond :) | 12:17 |
openstackgerrit | Kobi Samoray proposed openstack/keystone: Fix a docstring typo in test_v3_resource.py https://review.openstack.org/377618 | 12:18 |
mah | Hi all, I have an OPNFV-Apex deployment,, which is based on TripleO and it stucks at the post install configuration of external neutron network. I have done some tests .. such as source the overcloudrc from the undercloud then try any openstack command, then it fails | 12:24 |
*** amoralej|lunch is now known as amoralej | 12:25 | |
mah | I added --debug to see where it fails and I found here : Making authentication request to http://192.168.162.13:5000/v2.0/tokens | 12:25 |
rodrigods | mah, maybe #tripleo? | 12:25 |
mah | this ip the external ip not the admine | 12:25 |
*** woodster_ has joined #openstack-keystone | 12:25 | |
mah | I asked there but they checked with me from the network configuration and all was fine then one guy recommend to ask here because it may be related to keystone | 12:26 |
*** sdake has joined #openstack-keystone | 12:28 | |
rodrigods | mah, what is the result from that call? (calling /tokens) | 12:28 |
*** asettle_ has joined #openstack-keystone | 12:28 | |
breton | mah: please post the full output | 12:29 |
*** markvoelker has joined #openstack-keystone | 12:29 | |
mah | ok | 12:29 |
mah | http://hastebin.com/abodoleted.sql | 12:30 |
breton | mah: and what happens after line 35? | 12:30 |
*** edmondsw has joined #openstack-keystone | 12:30 | |
*** asettle has quit IRC | 12:31 | |
rodrigods | mah, just hangs there? | 12:31 |
mah | yes | 12:31 |
*** asettle has joined #openstack-keystone | 12:31 | |
mah | while when I do the same thing at the overcloud | 12:31 |
mah | it works fine | 12:31 |
mah | I can get the output there to see difference | 12:31 |
rodrigods | mah, so you can't access from the undercloud? | 12:32 |
rodrigods | a ping doesn't work | 12:32 |
mah | ping works | 12:32 |
mah | and I can access | 12:32 |
mah | http://hastebin.com/rujuvelezo.sql | 12:32 |
mah | here is from overcloud | 12:32 |
mah | works fine | 12:32 |
mah | and you will see the difference is that tried to Post to tokens using external ip | 12:33 |
mah | then changed to use the admin ip | 12:33 |
mah | and changed the port as well from 5000 to 35357 | 12:33 |
rodrigods | mah, hmm | 12:34 |
rodrigods | ayoung, ^ is this related to the versions endpoints issue? | 12:35 |
*** asettle_ has quit IRC | 12:35 | |
rodrigods | mah, what happens if you make the same call from the undercloud? | 12:35 |
*** vaishali_ has joined #openstack-keystone | 12:35 | |
mah | if I make it with sourcing the overcloudrc , it stucks http://hastebin.com/abodoleted.sql | 12:36 |
mah | but if I sourced stackrc it works fine | 12:36 |
*** vaishali_ has quit IRC | 12:36 | |
rodrigods | mah, looks like a network communication problem between the overcloud and the undercloud | 12:36 |
*** vaishali_ has joined #openstack-keystone | 12:36 | |
mah | but they can ping each others normally | 12:36 |
mah | and the deployement of opnfv (tripleo) continues to the end except few steps (post install configurations) | 12:37 |
rodrigods | mah, can you get a token in the overcloud and try to use in another overcloud service from the undercloud? | 12:38 |
mah | I did not tried it | 12:38 |
*** asettle_ has joined #openstack-keystone | 12:39 | |
mah | but I tried to do something else, which is changing the ip of auth_url and port to use the admin network ip and port 35357 .. then it works from undercloud in some cases of openstack commands | 12:39 |
mah | these changes done in overcloudrc | 12:40 |
mah | then source it from undercloud | 12:40 |
mah | at undercloud* | 12:40 |
*** asettle has quit IRC | 12:41 | |
*** asettle_ is now known as asettle | 12:41 | |
*** prashkre_ has joined #openstack-keystone | 12:52 | |
*** prashanth has quit IRC | 12:54 | |
*** tonytan4ever has joined #openstack-keystone | 12:54 | |
*** david-lyle has joined #openstack-keystone | 12:56 | |
*** GB21 has quit IRC | 12:57 | |
*** tonytan4ever has quit IRC | 12:57 | |
*** vaishali_ has quit IRC | 12:59 | |
*** tonytan4ever has joined #openstack-keystone | 13:00 | |
edmondsw | ayoung, saw you told dikonoo yesterday that keystone signing dir is only used with PKI... that's not actually correct. It's also used with revocation for all token types | 13:04 |
ayoung | edmondsw, I thought we killed that | 13:05 |
edmondsw | ayoung, when? | 13:05 |
edmondsw | would have to have been very recently, and maybe dikonoo doesn't have that change in her environment | 13:06 |
edmondsw | if indeed it was changed? | 13:06 |
*** prashkre_ has quit IRC | 13:06 | |
stevemar | o/ | 13:16 |
breton | ayoung: no | 13:16 |
breton | ayoung: it's still alive | 13:17 |
breton | ayoung: and we will discuss it today | 13:17 |
*** rob_d has joined #openstack-keystone | 13:18 | |
*** jaosorior has quit IRC | 13:19 | |
*** Guest71546 is now known as zeus | 13:20 | |
*** jaosorior has joined #openstack-keystone | 13:20 | |
*** zeus has quit IRC | 13:20 | |
*** zeus has joined #openstack-keystone | 13:20 | |
*** mnikolaenko has quit IRC | 13:37 | |
*** woodburn has quit IRC | 13:43 | |
*** mugsie__ is now known as mugsie | 13:45 | |
*** raildo has joined #openstack-keystone | 13:47 | |
*** woodburn has joined #openstack-keystone | 13:49 | |
*** ngupta has joined #openstack-keystone | 13:54 | |
*** guoshan has joined #openstack-keystone | 13:58 | |
*** ravelar has joined #openstack-keystone | 14:11 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Ensure all v2.0 tokens are validated the same way https://review.openstack.org/372655 | 14:12 |
stevemar | lbragstad: you should totally land that patch that includes names for audit events :P | 14:13 |
lbragstad | stevemar ? | 14:14 |
lbragstad | stevemar which one? | 14:14 |
stevemar | lbragstad: eh.. lemme find | 14:14 |
stevemar | lbragstad: https://review.openstack.org/#/c/288643/ | 14:14 |
lbragstad | oh | 14:16 |
lbragstad | stevemar we need to figure out what keystone's stance is on that kind of stuff | 14:16 |
lbragstad | stevemar why do you want that patch landed? | 14:16 |
lbragstad | because it closes a bug? | 14:16 |
breton | lbragstad: yep | 14:17 |
breton | lbragstad: was reported today | 14:17 |
*** pnavarro has quit IRC | 14:18 | |
breton | lbragstad: so more and more people want it | 14:18 |
lbragstad | breton stevemar well - we have a couple different ways to solve that problem | 14:18 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: remove deprecated config options https://review.openstack.org/374504 | 14:19 |
lbragstad | i'm not necessarily convinced people want more stuff in the notification | 14:19 |
stevemar | breton: thanks for the catches | 14:20 |
lbragstad | I wrote about other options here - http://lbragstad.com/improving-auditing-in-keystone/ | 14:20 |
stevemar | lbragstad: i think we can toss them in, with the domain name for groups/projects/users -- with the expectation that names are not unique | 14:20 |
stevemar | lbragstad: theres no reason we can't do both soft deletes and names in notifications | 14:21 |
stevemar | the name approach is a pinch more work, soft deletes are non-trivial | 14:21 |
lbragstad | stevemar if we do both we'll be maintaining two code paths that solve the same problem | 14:21 |
lbragstad | implementing soft deletes means that we'll have to rework all of the keystone api to return deleted entities | 14:22 |
lbragstad | that sounds like a lot of work | 14:22 |
stevemar | lbragstad: right, which is why i doubt it'll land any time soon | 14:22 |
stevemar | lbragstad: i think soft-deletes are a wishlist item | 14:22 |
lbragstad | i think it depends on how critical notification callbacks are | 14:23 |
lbragstad | if soft-deletes are really the way we want to go with this - and the recommended approach, then I'd consider soft deletes a higher priority | 14:24 |
*** sdake has quit IRC | 14:24 | |
lbragstad | putting the name in the notification feels like a band-aid | 14:24 |
lbragstad | only because we would be assuming that's all people want | 14:25 |
lbragstad | and I would guess that it's only a matter of time before we get another request to put a different attribute in the notification | 14:25 |
lbragstad | kinda like a slippery slope | 14:26 |
*** GB21 has joined #openstack-keystone | 14:26 | |
lbragstad | and what it we get to the point where we have attributes X, Y, and Z in the payload - but a certain deployer has security concerns with exposing attribute Y in the payload? | 14:27 |
lbragstad | s/it/if/ | 14:27 |
*** adrian_otto has joined #openstack-keystone | 14:27 | |
lbragstad | I'm just trying to think down the road - once this has been in the wild for a bit | 14:28 |
lbragstad | I think the trade-off is that we already have a notification system in place where we can put whatever we want in the payload - and implementing soft deletes would be starting back at square one | 14:29 |
lbragstad | but making a soft delete call and admin operation and making it so that consumers of the notification have to ask keystone for the specific information they need feels like it addresses future security concerns | 14:31 |
lbragstad | s/and/an/ | 14:31 |
* lbragstad clearly can't type today | 14:31 | |
*** _d34dh0r53_ is now known as d34dh0r53 | 14:34 | |
*** gagehugo has joined #openstack-keystone | 14:35 | |
*** adrian_otto has quit IRC | 14:36 | |
*** sdake has joined #openstack-keystone | 14:37 | |
*** adrian_otto has joined #openstack-keystone | 14:37 | |
*** spedione|AWAY is now known as spedione | 14:39 | |
*** guoshan has quit IRC | 14:44 | |
*** dikonoo has quit IRC | 14:45 | |
*** GB21 has quit IRC | 14:47 | |
stevemar | lbragstad: why would it be a security concern? it goes to an internal message | 14:49 |
stevemar | bus | 14:49 |
lbragstad | stevemar that was a concern dstanek had | 14:53 |
*** adrian_otto has quit IRC | 14:53 | |
*** edtubill has joined #openstack-keystone | 14:55 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: create release notes for removed functionality https://review.openstack.org/375914 | 14:58 |
*** roxanaghe has joined #openstack-keystone | 14:58 | |
*** spzala has joined #openstack-keystone | 15:03 | |
ktychkova_ | stevemar , lbragstad : Hi. I'm the person who want more information in keystone notifications :).Could you please tell me why it is a problem to add in notifications as much info as possible about deleted entities? | 15:05 |
*** pcaruana has quit IRC | 15:06 | |
*** rcernin has quit IRC | 15:07 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Verbose 401/403 debug responses https://review.openstack.org/372433 | 15:09 |
*** woodburn1 has joined #openstack-keystone | 15:10 | |
stevemar | ktychkova_: i'd like to see it happen ;) | 15:11 |
*** woodburn has quit IRC | 15:12 | |
lbragstad | ktychkova_ one of the reservations I have about it is that it requires notifications to put whatever the consuming application needs in the notification | 15:13 |
lbragstad | the whole idea behind the notification callback structure originally was to make it so that the consuming application gets just enough information to make a call back to keystone to get the exact information it needs | 15:14 |
lbragstad | which decouples the keystone notification implementation from whatever application consumes the notification | 15:15 |
ktychkova_ | lbragstad: what information I can get by id of deleted user? I guess nothing. How to understand what user was deleted? | 15:15 |
lbragstad | ktychkova_ that's why i was making the case for soft deletes :) | 15:15 |
lbragstad | ktychkova_ your application could subscribe to notifications and listen for deletion events for user resource types - then it would have to make a call back to keystone asking for deleted user of a particular ID | 15:16 |
*** haplo37__ has joined #openstack-keystone | 15:17 | |
lbragstad | which would return the entire user reference | 15:17 |
ktychkova_ | lbragstad: I understand your point, but this "call back" thing requeres me to store openstack credentials outside of openstack... | 15:18 |
*** openstackgerrit has quit IRC | 15:18 | |
*** openstackgerrit has joined #openstack-keystone | 15:18 | |
lbragstad | ktychkova_ you'd have to do the same pattern if you wanted to consume a PATCH user event | 15:19 |
lbragstad | when a user is updated, the only thing you're told in the notification is that a user of a specific id has something changed... | 15:19 |
lbragstad | you don't know what changed | 15:19 |
lbragstad | you'd have to store credentials in order to get that information today | 15:20 |
*** adrian_otto has joined #openstack-keystone | 15:20 | |
*** adrian_otto has quit IRC | 15:20 | |
amakarov | rodrigods, hi! I've split patch 372433 as you asked | 15:21 |
ktychkova_ | libragstad: I like soft delete feature. It's fine. I just thougt that it is not a big problem to add all user fields in the message. But if it is I can wait for "soft delete" feature | 15:22 |
lbragstad | ktychkova_ would you be able to share your consuming application flow? | 15:22 |
lbragstad | ktychkova_ how do you use the notification in your application? | 15:22 |
rodrigods | amakarov, hmm my suggestion only makes sense if it is possible to add tests to cover the #noqa parts | 15:24 |
ktychkova_ | lbragstad: I actually doing research of possible use cases. So I don't know for sure. But, for example, it is: Keystone -> Ceilometer -> Aodh -> Jenkins/Slack or any of app with REST api | 15:25 |
rodrigods | amakarov, and... it is funny because my score was +1, not -1 | 15:25 |
*** agrebennikov has joined #openstack-keystone | 15:26 | |
lbragstad | ktychkova_ so you'd have ceilometer listen for certain keystone events then kick of a job, or update a slack room? | 15:26 |
amakarov | rodrigods, I think the questionable parts with noqa are better be extracted and handled separately | 15:27 |
ktychkova_ | lbragstad: yes, right | 15:27 |
rodrigods | amakarov, ++ | 15:27 |
amakarov | rodrigods, so first patch still solves the issue, and the second one - reveals another problem | 15:27 |
*** guoshan has joined #openstack-keystone | 15:30 | |
ktychkova_ | lbragstad: please take a look: http://xuctarine.blogspot.ru/2016/09/keystone-notifications-integration-with_26.html | 15:31 |
ktychkova_ | It is just first stage of research and defenetly not a production use case and I'm using openstack credentials from Jenkins | 15:31 |
ktychkova_ | but it will give you an idea in what direction I want to continue work | 15:31 |
lbragstad | ktychkova_ cool - i'll check it out | 15:31 |
lbragstad | ktychkova_ so far, only you and dmitri have expressed an interest in the notification payload | 15:32 |
lbragstad | ktychkova_ i spoke with a few people in Austin about it, but the discussion ended up getting tabled | 15:33 |
lbragstad | ktychkova_ if you're going to be in Barcelona - we should talk to stevemar to see if we can get it rolled into a session | 15:34 |
lbragstad | ktychkova_ are you planning on using CADF notifications or the basic ones? | 15:37 |
breton | how do i switch between basic and cadf? | 15:38 |
lbragstad | breton it's a configuration option | 15:39 |
ktychkova_ | lbragstad: I won't go to the Summit, but if you want to have a session I will find somebody to participate. Jay Pipes from Nova for example. | 15:39 |
ktychkova_ | Since the main use case we a looking for is "owner transfership" - transfer instances from deleted user to somebody | 15:39 |
lbragstad | let me grab a link | 15:39 |
ktychkova_ | CADF | 15:39 |
ktychkova_ | breton: in config file :) | 15:39 |
*** guoshan has quit IRC | 15:40 | |
ktychkova_ | breton: notification_format = cadf | 15:40 |
lbragstad | ktychkova_ yep - breton - https://github.com/openstack/keystone/blob/8143f9ca49032fbfe2f567bb1e0cd6c370aaa8a4/keystone/conf/default.py#L206 | 15:40 |
lbragstad | stevemar do you think we have any room in the schedule for a notification session? | 15:40 |
lbragstad | ktychkova_ it's exciting to hear that you're working on the transfer/cleanup problem | 15:41 |
lbragstad | breton are you working on that, too? | 15:41 |
*** spilla has joined #openstack-keystone | 15:43 | |
breton | lbragstad: nope, just eavesdropping :p | 15:43 |
ktychkova_ | lbragstad: we just made a first research and thinking what step to do next. | 15:43 |
ktychkova_ | Probably it will be a "transfer ownership" in Nova | 15:43 |
lbragstad | ktychkova_ got it - so when you receive a notification the a user has been deleted are you checking the domain/project of the user or something like that? | 15:44 |
*** gagehugo has quit IRC | 15:46 | |
*** adrian_otto has joined #openstack-keystone | 15:46 | |
ktychkova_ | lbragstad: project is important, because you have to specify it in Aodh when creating an alarm | 15:46 |
ktychkova_ | What else will be needed for Nova I don't know so far | 15:46 |
stevemar | lbragstad: we can try | 15:47 |
lbragstad | ktychkova_ ah - that makes sense | 15:47 |
lbragstad | stevemar we could try doing it over a meeting, too | 15:47 |
ktychkova_ | breton: You are going to Barcelona, right? | 15:48 |
stevemar | lbragstad: i added it, earlier too, can you fill in the content? | 15:48 |
lbragstad | stevemar sure | 15:48 |
*** agrebennikov has quit IRC | 15:48 | |
lbragstad | ktychkova_ will you be able to make it to the keystone meeting today in #openstack-meeting at 18:00 UTC | 15:48 |
lbragstad | i assume breton will be there | 15:49 |
lbragstad | s/there/at the meeting/ | 15:49 |
openstackgerrit | Arthur Miranda proposed openstack/python-keystoneclient: Prevent attempts to "filter" find() calls by globally unique IDs https://review.openstack.org/377811 | 15:49 |
*** spedione is now known as chris_hultin | 15:50 | |
ktychkova_ | lbragstad: yes, I will | 15:51 |
breton | ktychkova_: lbragstad: yes | 15:53 |
lbragstad | ktychkova_ cool - stevemar's got you on the agenda here https://etherpad.openstack.org/p/keystone-weekly-meeting | 15:57 |
rob_d | hi all, heat project still uses python-keystoneclient, does this make it impossible for federated users to use heat? - keystoneclient throws 404 when heat tries to determine the federated users role | 15:58 |
*** GB21 has joined #openstack-keystone | 15:58 | |
rob_d | I have heat configured to use trusts but it keeps throwing a 404, federated user can use all other services and heat configured to use un-versioned identity endpoint | 16:00 |
openstackgerrit | Arthur Miranda proposed openstack/python-keystoneclient: Prevent attempts to "filter" find() calls by globally unique IDs https://review.openstack.org/375730 | 16:00 |
*** amakarov has quit IRC | 16:02 | |
*** amakarov has joined #openstack-keystone | 16:02 | |
*** haplo37_ has quit IRC | 16:05 | |
*** gyee has joined #openstack-keystone | 16:05 | |
*** haplo37_ has joined #openstack-keystone | 16:07 | |
*** code-R_ has quit IRC | 16:10 | |
breton | many things to discuss today | 16:14 |
lbragstad | yeah - we have a packed schedule | 16:14 |
openstackgerrit | Merged openstack/pycadf: Updated from global requirements https://review.openstack.org/377546 | 16:14 |
openstackgerrit | Merged openstack/keystoneauth: Updated from global requirements https://review.openstack.org/377449 | 16:15 |
*** code-R has joined #openstack-keystone | 16:16 | |
*** jaosorior has quit IRC | 16:16 | |
*** mvk has quit IRC | 16:17 | |
stevemar | lbragstad: i punched some of my stuff out | 16:18 |
*** agrebennikov has joined #openstack-keystone | 16:21 | |
*** code-R has quit IRC | 16:29 | |
*** ekarlso_ has quit IRC | 16:31 | |
*** ravelar1 has joined #openstack-keystone | 16:34 | |
*** asettle_ has joined #openstack-keystone | 16:34 | |
*** roxanagh_ has joined #openstack-keystone | 16:34 | |
*** tonytan_brb has joined #openstack-keystone | 16:34 | |
*** david-lyle_ has joined #openstack-keystone | 16:35 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: remove deprecated config options https://review.openstack.org/374504 | 16:36 |
*** xek_ has joined #openstack-keystone | 16:36 | |
knikolla | rodrigods: you there? | 16:36 |
*** haplo37__ has quit IRC | 16:36 | |
*** jraim has quit IRC | 16:36 | |
*** samueldmq has quit IRC | 16:36 | |
*** rob_d___ has joined #openstack-keystone | 16:36 | |
*** roxanaghe has quit IRC | 16:36 | |
*** edtubill has quit IRC | 16:36 | |
*** brad[] has quit IRC | 16:36 | |
*** asettle has quit IRC | 16:36 | |
*** aswadr_ has quit IRC | 16:37 | |
*** chrome0_ has quit IRC | 16:37 | |
*** nicolasbock has quit IRC | 16:37 | |
*** akrzos has quit IRC | 16:37 | |
*** Kimmo__ has joined #openstack-keystone | 16:37 | |
*** hugokuo has quit IRC | 16:37 | |
*** Kimmo_ has quit IRC | 16:37 | |
*** richm has quit IRC | 16:37 | |
*** david_cu has quit IRC | 16:37 | |
*** david-lyle has quit IRC | 16:37 | |
*** kragniz has quit IRC | 16:37 | |
*** jlk` has joined #openstack-keystone | 16:37 | |
*** woodburn1 has quit IRC | 16:37 | |
*** serverascode has quit IRC | 16:37 | |
*** morgan has quit IRC | 16:37 | |
*** stevemar has quit IRC | 16:37 | |
*** andrewbogott has quit IRC | 16:37 | |
*** jlk has quit IRC | 16:37 | |
*** mrhillsman has quit IRC | 16:37 | |
*** mfisch has quit IRC | 16:37 | |
*** nonameentername has quit IRC | 16:37 | |
*** stevemar has joined #openstack-keystone | 16:37 | |
*** med_ has quit IRC | 16:37 | |
*** sigmavirus has quit IRC | 16:37 | |
*** nicolasbock has joined #openstack-keystone | 16:37 | |
*** ravelar has quit IRC | 16:37 | |
*** iurygregory has quit IRC | 16:37 | |
*** pleia2 has quit IRC | 16:37 | |
*** code-R has joined #openstack-keystone | 16:37 | |
*** hugokuo_ has joined #openstack-keystone | 16:37 | |
*** redrobot has quit IRC | 16:37 | |
*** hoonetorg has quit IRC | 16:37 | |
*** tsufiev has quit IRC | 16:37 | |
*** mnaser has quit IRC | 16:37 | |
*** _sigmavirus24 has joined #openstack-keystone | 16:37 | |
*** hugokuo_ is now known as hugokuo | 16:37 | |
*** arunkant_ has joined #openstack-keystone | 16:37 | |
*** dmellado has quit IRC | 16:37 | |
*** jdennis1 has quit IRC | 16:37 | |
*** woodburn has joined #openstack-keystone | 16:37 | |
*** jlwhite_ has joined #openstack-keystone | 16:38 | |
*** jlwhite_ has quit IRC | 16:38 | |
*** jlwhite_ has joined #openstack-keystone | 16:38 | |
*** jlwhite has quit IRC | 16:38 | |
*** jlwhite_ is now known as jlwhite | 16:38 | |
*** anteaya has quit IRC | 16:38 | |
*** GB21 has quit IRC | 16:38 | |
*** sileht has quit IRC | 16:38 | |
*** clayton has quit IRC | 16:38 | |
*** mnaser has joined #openstack-keystone | 16:38 | |
*** rob_d has quit IRC | 16:38 | |
*** jidar has quit IRC | 16:38 | |
*** adrian_otto1 has joined #openstack-keystone | 16:38 | |
*** anteaya has joined #openstack-keystone | 16:38 | |
*** zzzeek has quit IRC | 16:38 | |
*** tonytan4ever has quit IRC | 16:38 | |
*** henrynash has quit IRC | 16:38 | |
*** adrian_otto has quit IRC | 16:38 | |
*** x58 has quit IRC | 16:38 | |
*** akrzos_ has joined #openstack-keystone | 16:38 | |
*** xek has quit IRC | 16:38 | |
*** arunkant has quit IRC | 16:38 | |
*** chrome0 has joined #openstack-keystone | 16:38 | |
*** x58 has joined #openstack-keystone | 16:38 | |
*** kragniz1 has joined #openstack-keystone | 16:38 | |
*** jdennis has joined #openstack-keystone | 16:38 | |
*** akrzos_ has quit IRC | 16:38 | |
*** akrzos_ has joined #openstack-keystone | 16:38 | |
*** hoonetorg has joined #openstack-keystone | 16:38 | |
*** dmellado has joined #openstack-keystone | 16:38 | |
*** nonameentername has joined #openstack-keystone | 16:38 | |
*** links has quit IRC | 16:38 | |
*** timss has quit IRC | 16:38 | |
*** dgonzalez has quit IRC | 16:38 | |
*** brad[]` has joined #openstack-keystone | 16:38 | |
*** prashkre_ has joined #openstack-keystone | 16:38 | |
*** henrynash has joined #openstack-keystone | 16:39 | |
*** pleia2 has joined #openstack-keystone | 16:39 | |
*** code-R_ has joined #openstack-keystone | 16:39 | |
*** redrobot has joined #openstack-keystone | 16:39 | |
*** redrobot is now known as Guest27780 | 16:40 | |
*** mrhillsman has joined #openstack-keystone | 16:40 | |
*** _sigmavirus24 is now known as sigmavirus | 16:40 | |
*** sigmavirus has joined #openstack-keystone | 16:40 | |
*** haplo37 has joined #openstack-keystone | 16:40 | |
*** jidar has joined #openstack-keystone | 16:41 | |
*** DuncanT has quit IRC | 16:41 | |
*** tsufiev has joined #openstack-keystone | 16:41 | |
*** code-R has quit IRC | 16:42 | |
*** mfisch has joined #openstack-keystone | 16:42 | |
*** mfisch has quit IRC | 16:42 | |
*** mfisch has joined #openstack-keystone | 16:42 | |
openstackgerrit | Merged openstack/python-keystoneclient: Updated from global requirements https://review.openstack.org/377555 | 16:43 |
openstackgerrit | Richard Avelar proposed openstack/keystone: Change python code revocation search to sql https://review.openstack.org/359371 | 16:44 |
*** prashkre__ has joined #openstack-keystone | 16:44 | |
*** mdurrant_ has joined #openstack-keystone | 16:44 | |
*** asettle_ is now known as asettle | 16:44 | |
*** dgonzalez has joined #openstack-keystone | 16:45 | |
*** slberger has joined #openstack-keystone | 16:45 | |
*** clayton has joined #openstack-keystone | 16:46 | |
*** Guest66676 has quit IRC | 16:46 | |
*** alex_xu has quit IRC | 16:46 | |
*** woodburn1 has joined #openstack-keystone | 16:46 | |
*** amakarov has quit IRC | 16:46 | |
*** cburgess_ has joined #openstack-keystone | 16:46 | |
*** adrian_otto1 has quit IRC | 16:47 | |
*** mnaser has quit IRC | 16:47 | |
*** henrynash_ has joined #openstack-keystone | 16:47 | |
*** cburgess has quit IRC | 16:47 | |
*** pkoraca has quit IRC | 16:47 | |
*** alexander__ has joined #openstack-keystone | 16:47 | |
*** BlackDex has quit IRC | 16:47 | |
*** mlovell has quit IRC | 16:47 | |
*** zeus has quit IRC | 16:47 | |
*** evrardjp has quit IRC | 16:47 | |
*** mdurrant__ has quit IRC | 16:47 | |
*** jlk` has quit IRC | 16:47 | |
*** alexander__ is now known as amakarov | 16:47 | |
*** mfisch` has joined #openstack-keystone | 16:47 | |
*** jlwhite_ has joined #openstack-keystone | 16:47 | |
*** sigmavirus has quit IRC | 16:47 | |
*** dmellado_ has joined #openstack-keystone | 16:47 | |
*** hugokuo has quit IRC | 16:48 | |
*** jidar_ has joined #openstack-keystone | 16:48 | |
*** briancurtin has quit IRC | 16:48 | |
*** BlackDex_ has joined #openstack-keystone | 16:48 | |
*** mrhillsman has quit IRC | 16:48 | |
*** arunkant_ has quit IRC | 16:48 | |
*** ayoung has quit IRC | 16:48 | |
*** jamielennox has quit IRC | 16:48 | |
*** vkmc has quit IRC | 16:48 | |
*** ayoung has joined #openstack-keystone | 16:48 | |
*** ChanServ sets mode: +v ayoung | 16:48 | |
*** zzzeek has joined #openstack-keystone | 16:48 | |
*** x58 has quit IRC | 16:48 | |
*** akrzos_ has quit IRC | 16:48 | |
*** alex_xu_ has joined #openstack-keystone | 16:48 | |
*** mfisch has quit IRC | 16:48 | |
*** prashkre_ has quit IRC | 16:48 | |
*** brad[]` has quit IRC | 16:48 | |
*** kragniz1 has quit IRC | 16:48 | |
*** chrome0 has quit IRC | 16:48 | |
*** x58 has joined #openstack-keystone | 16:48 | |
*** alex_xu_ has quit IRC | 16:48 | |
*** alex_xu_ has joined #openstack-keystone | 16:48 | |
*** akrzos has joined #openstack-keystone | 16:48 | |
*** vkmc- has joined #openstack-keystone | 16:48 | |
openstackgerrit | Merged openstack/keystone: Updated from global requirements https://review.openstack.org/377448 | 16:48 |
*** henrynash has quit IRC | 16:48 | |
*** dmellado has quit IRC | 16:48 | |
*** woodburn has quit IRC | 16:48 | |
*** anteaya has quit IRC | 16:48 | |
*** jlwhite has quit IRC | 16:48 | |
*** chrome0_ has joined #openstack-keystone | 16:48 | |
*** jidar has quit IRC | 16:48 | |
*** jlwhite_ is now known as jlwhite | 16:48 | |
*** med_ has joined #openstack-keystone | 16:48 | |
*** kragniz1 has joined #openstack-keystone | 16:48 | |
*** vkmc- is now known as vkmc | 16:48 | |
*** vkmc has quit IRC | 16:48 | |
*** vkmc has joined #openstack-keystone | 16:48 | |
*** med_ is now known as Guest44064 | 16:48 | |
*** jamielennox has joined #openstack-keystone | 16:48 | |
*** ChanServ sets mode: +v jamielennox | 16:48 | |
*** jlk has joined #openstack-keystone | 16:49 | |
*** hugokuo has joined #openstack-keystone | 16:49 | |
*** jlk has quit IRC | 16:49 | |
*** jlk has joined #openstack-keystone | 16:49 | |
*** _sigmavirus24 has joined #openstack-keystone | 16:49 | |
*** jidar_ is now known as jidar | 16:49 | |
*** Guest3203 is now known as melwitt | 16:49 | |
*** _sigmavirus24 is now known as sigmavirus | 16:49 | |
*** mnaser has joined #openstack-keystone | 16:49 | |
*** mnaser has joined #openstack-keystone | 16:49 | |
*** brad[] has joined #openstack-keystone | 16:49 | |
*** arunkant_ has joined #openstack-keystone | 16:49 | |
*** adrian_otto has joined #openstack-keystone | 16:50 | |
*** sigmavirus is now known as Guest45096 | 16:50 | |
openstackgerrit | Samuel Pilla proposed openstack/keystone: Domain included for role in list_role_assignment https://review.openstack.org/373516 | 16:50 |
*** GB21 has joined #openstack-keystone | 16:50 | |
*** anteaya has joined #openstack-keystone | 16:50 | |
*** Guest45096 is now known as sigmavirus | 16:51 | |
*** sigmavirus has joined #openstack-keystone | 16:51 | |
*** jraim has joined #openstack-keystone | 16:51 | |
*** links has joined #openstack-keystone | 16:51 | |
*** sileht has joined #openstack-keystone | 16:52 | |
*** AndyWojo has quit IRC | 16:52 | |
*** timss has joined #openstack-keystone | 16:52 | |
*** iurygregory has joined #openstack-keystone | 16:53 | |
*** zeus has joined #openstack-keystone | 16:53 | |
*** jefrite has quit IRC | 16:53 | |
*** evrardjp has joined #openstack-keystone | 16:53 | |
*** zeus is now known as Guest66430 | 16:53 | |
*** richm has joined #openstack-keystone | 16:54 | |
*** samueldmq has joined #openstack-keystone | 16:54 | |
*** ChanServ sets mode: +v samueldmq | 16:54 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: Move revocation logic to SQL: Indexes https://review.openstack.org/376523 | 16:54 |
openstackgerrit | Richard Avelar proposed openstack/keystone: Move revocation logic to SQL https://review.openstack.org/359371 | 16:54 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add release note for fernet tokens https://review.openstack.org/376526 | 16:56 |
*** ngupta has quit IRC | 16:56 | |
*** mlovell has joined #openstack-keystone | 16:56 | |
*** ngupta has joined #openstack-keystone | 16:57 | |
*** jefrite has joined #openstack-keystone | 16:57 | |
*** ktychkova has joined #openstack-keystone | 16:57 | |
*** Guest66666 has joined #openstack-keystone | 16:57 | |
*** ktychkova_ has quit IRC | 16:58 | |
*** ktychkova has quit IRC | 16:58 | |
*** ngupta has quit IRC | 16:59 | |
*** ngupta has joined #openstack-keystone | 16:59 | |
*** ktychkova_ has joined #openstack-keystone | 16:59 | |
*** browne has joined #openstack-keystone | 16:59 | |
*** henrynash_ is now known as henrynash | 17:01 | |
*** Guest66430 is now known as zeus` | 17:02 | |
*** zeus` is now known as zeus | 17:02 | |
*** zeus has quit IRC | 17:02 | |
*** zeus has joined #openstack-keystone | 17:02 | |
*** amoralej is now known as amoralej|off | 17:02 | |
*** andrewbogott has joined #openstack-keystone | 17:03 | |
*** roxanagh_ has quit IRC | 17:05 | |
*** frontrunner has joined #openstack-keystone | 17:06 | |
*** roxanaghe has joined #openstack-keystone | 17:08 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Switch fernet to be the default token provider. https://review.openstack.org/345688 | 17:09 |
*** chrome0 has joined #openstack-keystone | 17:09 | |
*** lamt has joined #openstack-keystone | 17:09 | |
*** jidar_ has joined #openstack-keystone | 17:10 | |
*** woodburn1 has quit IRC | 17:10 | |
*** code-R_ has quit IRC | 17:10 | |
*** jidar has quit IRC | 17:10 | |
*** GB21 has quit IRC | 17:10 | |
*** Guest44064 has quit IRC | 17:10 | |
*** zeus has quit IRC | 17:11 | |
*** jidar_ is now known as jidar | 17:11 | |
*** adrian_otto has quit IRC | 17:11 | |
*** stevemar has quit IRC | 17:11 | |
*** woodster_ has quit IRC | 17:11 | |
*** stevemar has joined #openstack-keystone | 17:11 | |
*** andrewbogott has quit IRC | 17:11 | |
*** dmellado_ has quit IRC | 17:11 | |
*** mnaser has quit IRC | 17:11 | |
*** GB21 has joined #openstack-keystone | 17:11 | |
*** frontrunner has quit IRC | 17:11 | |
*** akrzos has quit IRC | 17:11 | |
*** ayoung_ has joined #openstack-keystone | 17:11 | |
*** jdennis has quit IRC | 17:11 | |
*** x58 has quit IRC | 17:11 | |
*** x58 has joined #openstack-keystone | 17:11 | |
*** links has quit IRC | 17:11 | |
*** jlk has quit IRC | 17:11 | |
*** wolsen has quit IRC | 17:11 | |
*** jhesketh has quit IRC | 17:12 | |
*** jraim has quit IRC | 17:12 | |
*** jamielennox has quit IRC | 17:12 | |
*** ayoung has quit IRC | 17:12 | |
*** pleia2 has quit IRC | 17:12 | |
*** ktychkova_ has quit IRC | 17:12 | |
*** Guest66666 has quit IRC | 17:12 | |
*** jraju has joined #openstack-keystone | 17:12 | |
rderose | SpamapS: have a question | 17:12 |
*** chrome0_ has quit IRC | 17:12 | |
*** woodburn has joined #openstack-keystone | 17:12 | |
*** code-R has joined #openstack-keystone | 17:12 | |
*** ktychkova__ has joined #openstack-keystone | 17:12 | |
*** akrzos has joined #openstack-keystone | 17:12 | |
*** tonytan_brb has quit IRC | 17:12 | |
*** adrian_otto has joined #openstack-keystone | 17:12 | |
*** dmellado has joined #openstack-keystone | 17:12 | |
*** jlk has joined #openstack-keystone | 17:12 | |
*** jdennis has joined #openstack-keystone | 17:12 | |
*** jlk has quit IRC | 17:12 | |
*** jlk has joined #openstack-keystone | 17:12 | |
SpamapS | rderose: I'm here. Wassup? | 17:12 |
rderose | Here is what the query would look like: http://paste.openstack.org/show/583126/ (so far) | 17:13 |
*** jhesketh has joined #openstack-keystone | 17:13 | |
rderose | Which would make more sense a compound index that would include most columns or an index on each column? | 17:14 |
rderose | SpamapS ^ | 17:14 |
*** frontrunner has joined #openstack-keystone | 17:14 | |
*** jamielennox has joined #openstack-keystone | 17:14 | |
*** ChanServ sets mode: +v jamielennox | 17:14 | |
*** kragniz1 is now known as kragniz | 17:15 | |
SpamapS | wow | 17:15 |
SpamapS | that's one heck of an OR tree | 17:15 |
*** pleia2 has joined #openstack-keystone | 17:15 | |
SpamapS | so, OR's can only be turned into index range queries | 17:15 |
rderose | SpamapS: the reason why is you could match on user_id or user_id and domain_id... | 17:15 |
SpamapS | except OR + Null | 17:16 |
SpamapS | which can be a ref_or_null | 17:16 |
rderose | hmm... | 17:16 |
*** roxanaghe has quit IRC | 17:17 | |
*** zeus has joined #openstack-keystone | 17:17 | |
*** Guest66666 has joined #openstack-keystone | 17:17 | |
*** harlowja has joined #openstack-keystone | 17:17 | |
openstackgerrit | Arthur Miranda proposed openstack/python-keystoneclient: Prevent attempts to "filter" find() calls by globally unique IDs https://review.openstack.org/375730 | 17:18 |
rderose | SpamapS: still investigating what would be the common values returned, but I think this is a good example of what would be in the token | 17:19 |
* SpamapS still reading | 17:20 | |
rderose | SpamapS: and I think the query logic is sound in trying to match all different combinations; not sure if there would be a better alternative at this point | 17:20 |
*** ngupta has quit IRC | 17:20 | |
*** woodburn1 has joined #openstack-keystone | 17:20 | |
*** ngupta has joined #openstack-keystone | 17:21 | |
*** asettle has quit IRC | 17:21 | |
*** dmellado_ has joined #openstack-keystone | 17:21 | |
*** haplo37_ has quit IRC | 17:21 | |
*** spilla has quit IRC | 17:21 | |
*** alex_xu has joined #openstack-keystone | 17:21 | |
*** dmellado has quit IRC | 17:21 | |
*** stevemar has quit IRC | 17:21 | |
*** mlovell has quit IRC | 17:21 | |
*** stevemar has joined #openstack-keystone | 17:21 | |
*** artmr has joined #openstack-keystone | 17:21 | |
*** zeus is now known as Guest45385 | 17:21 | |
*** rodrigod` has joined #openstack-keystone | 17:21 | |
*** ayoung_ has quit IRC | 17:21 | |
*** sileht has quit IRC | 17:21 | |
*** harlowja_ has joined #openstack-keystone | 17:22 | |
*** Guest66676 has joined #openstack-keystone | 17:22 | |
*** alex_xu_ has quit IRC | 17:22 | |
*** x58 has quit IRC | 17:22 | |
*** BlackDex_ has quit IRC | 17:22 | |
*** zzzeek has quit IRC | 17:22 | |
*** x58 has joined #openstack-keystone | 17:22 | |
*** harlowja has quit IRC | 17:22 | |
*** Guest45385 has quit IRC | 17:22 | |
*** pleia2 has quit IRC | 17:22 | |
*** ktychkova_ has joined #openstack-keystone | 17:22 | |
*** arunkant__ has joined #openstack-keystone | 17:22 | |
*** woodburn has quit IRC | 17:22 | |
*** ktychkova__ has quit IRC | 17:22 | |
*** frontrunner has quit IRC | 17:22 | |
*** Guest27780 has quit IRC | 17:22 | |
*** Guest66666 has quit IRC | 17:22 | |
*** frontrunner has joined #openstack-keystone | 17:22 | |
*** pleia2 has joined #openstack-keystone | 17:23 | |
*** electrichead has joined #openstack-keystone | 17:23 | |
*** zeus- has joined #openstack-keystone | 17:23 | |
*** iurygregory_ has joined #openstack-keystone | 17:23 | |
*** haplo37_ has joined #openstack-keystone | 17:23 | |
*** roxanaghe has joined #openstack-keystone | 17:23 | |
*** pkoraca has joined #openstack-keystone | 17:23 | |
*** serverascode has joined #openstack-keystone | 17:23 | |
*** zeus- is now known as zeus` | 17:24 | |
*** zzzeek has joined #openstack-keystone | 17:24 | |
*** spilla has joined #openstack-keystone | 17:24 | |
*** mlovell has joined #openstack-keystone | 17:24 | |
*** david-lyle_ is now known as david-lyle | 17:24 | |
*** sileht has joined #openstack-keystone | 17:25 | |
openstackgerrit | Alexey Yelistratov proposed openstack/keystone: Add DB operations tracing https://review.openstack.org/294535 | 17:25 |
*** ayoung_ has joined #openstack-keystone | 17:25 | |
*** haplo37| has joined #openstack-keystone | 17:25 | |
*** ChanServ sets mode: +o stevemar | 17:27 | |
*** GB21 has quit IRC | 17:27 | |
*** gagehugo has joined #openstack-keystone | 17:27 | |
*** iurygregory has quit IRC | 17:28 | |
*** arunkant_ has quit IRC | 17:28 | |
*** brad[] has quit IRC | 17:28 | |
*** henrynash has quit IRC | 17:28 | |
*** haplo37 has quit IRC | 17:28 | |
*** raildo has quit IRC | 17:28 | |
*** rodrigods has quit IRC | 17:28 | |
*** iurygregory_ is now known as iurygregory | 17:28 | |
*** frontrunner2 has joined #openstack-keystone | 17:32 | |
*** x58 has quit IRC | 17:32 | |
*** stevemar has quit IRC | 17:32 | |
*** jdennis has quit IRC | 17:32 | |
*** mtreinish has quit IRC | 17:33 | |
*** SamYaple has quit IRC | 17:33 | |
*** zeus` has quit IRC | 17:33 | |
*** harlowja_ has quit IRC | 17:33 | |
*** henrynash has joined #openstack-keystone | 17:33 | |
*** frontrunner has quit IRC | 17:33 | |
*** sileht has quit IRC | 17:34 | |
*** ChanServ sets mode: +v henrynash | 17:34 | |
*** spzala has quit IRC | 17:34 | |
*** raildo has joined #openstack-keystone | 17:34 | |
*** stevemar has joined #openstack-keystone | 17:34 | |
*** harlowja has joined #openstack-keystone | 17:34 | |
*** sileht has joined #openstack-keystone | 17:34 | |
*** mnaser has joined #openstack-keystone | 17:35 | |
*** x58 has joined #openstack-keystone | 17:35 | |
*** BlackDex has joined #openstack-keystone | 17:36 | |
*** spzala has joined #openstack-keystone | 17:36 | |
*** jdennis has joined #openstack-keystone | 17:37 | |
*** ravelar1 has quit IRC | 17:38 | |
*** zeus- has joined #openstack-keystone | 17:38 | |
*** SamYaple has joined #openstack-keystone | 17:38 | |
*** zeus- is now known as zeus` | 17:39 | |
*** aswadr_ has joined #openstack-keystone | 17:39 | |
*** jraim has joined #openstack-keystone | 17:39 | |
*** zeus` is now known as zeus | 17:39 | |
*** zeus has quit IRC | 17:39 | |
*** zeus has joined #openstack-keystone | 17:39 | |
*** mtreinish has joined #openstack-keystone | 17:40 | |
*** x58 has quit IRC | 17:41 | |
*** harlowja has quit IRC | 17:42 | |
*** rodrigod` is now known as rodrigods | 17:42 | |
*** rodrigods has quit IRC | 17:42 | |
*** rodrigods has joined #openstack-keystone | 17:42 | |
*** med_ has joined #openstack-keystone | 17:44 | |
*** andrewbogott has joined #openstack-keystone | 17:45 | |
*** med_ is now known as Guest79278 | 17:45 | |
*** x58 has joined #openstack-keystone | 17:47 | |
*** harlowja has joined #openstack-keystone | 17:47 | |
*** DuncanT has joined #openstack-keystone | 17:47 | |
*** x58 has left #openstack-keystone | 17:50 | |
*** mvk has joined #openstack-keystone | 17:51 | |
*** Marcellin__ has joined #openstack-keystone | 17:51 | |
*** wolsen has joined #openstack-keystone | 17:52 | |
*** tonytan4ever has joined #openstack-keystone | 17:53 | |
*** woodster_ has joined #openstack-keystone | 17:53 | |
*** tqtran has joined #openstack-keystone | 17:53 | |
*** nk2527 has joined #openstack-keystone | 17:54 | |
*** morgan_ has joined #openstack-keystone | 17:54 | |
*** jraju has quit IRC | 17:54 | |
*** AndyWojo has joined #openstack-keystone | 17:57 | |
*** aswadr_ has quit IRC | 17:58 | |
stevemar | meeting time! | 17:59 |
*** briancurtin has joined #openstack-keystone | 18:00 | |
*** code-R has quit IRC | 18:02 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Verbose 401/403 debug responses https://review.openstack.org/372433 | 18:08 |
*** tonytan_brb has joined #openstack-keystone | 18:08 | |
*** Gorian has joined #openstack-keystone | 18:08 | |
*** Gorian is now known as Gorian|work | 18:09 | |
*** harlowja has quit IRC | 18:10 | |
*** crinkle has quit IRC | 18:10 | |
*** andrewbogott has quit IRC | 18:10 | |
*** haplo37| has quit IRC | 18:10 | |
*** pkoraca has quit IRC | 18:10 | |
*** serverascode has quit IRC | 18:10 | |
*** mtreinish_ has joined #openstack-keystone | 18:10 | |
*** haplo37- has joined #openstack-keystone | 18:10 | |
*** tonytan4ever has quit IRC | 18:10 | |
*** mvk has quit IRC | 18:10 | |
*** Guest79278 has quit IRC | 18:10 | |
*** BlackDex has quit IRC | 18:10 | |
*** ayoung_ has quit IRC | 18:10 | |
*** redrobot has joined #openstack-keystone | 18:10 | |
*** BlackDex has joined #openstack-keystone | 18:10 | |
*** redrobot is now known as Guest45079 | 18:11 | |
*** mvk has joined #openstack-keystone | 18:11 | |
*** morgan_ has quit IRC | 18:11 | |
*** mtreinish has quit IRC | 18:11 | |
*** mtreinish_ is now known as mtreinish | 18:11 | |
*** electrichead has quit IRC | 18:11 | |
*** sileht has quit IRC | 18:11 | |
*** crinkle_ has joined #openstack-keystone | 18:11 | |
*** crinkle_ is now known as crinkle | 18:12 | |
*** morgan_ has joined #openstack-keystone | 18:12 | |
*** serverascode has joined #openstack-keystone | 18:12 | |
*** stevemar_ has joined #openstack-keystone | 18:12 | |
*** ChanServ sets mode: +o stevemar_ | 18:12 | |
*** sileht has joined #openstack-keystone | 18:14 | |
*** ayoung_ has joined #openstack-keystone | 18:15 | |
*** ChanServ sets mode: +o stevemar | 18:15 | |
*** stevemar_ is now known as stevemar__ | 18:17 | |
*** stevemar__ has quit IRC | 18:18 | |
*** morgan__ has joined #openstack-keystone | 18:19 | |
*** andrewbogott has joined #openstack-keystone | 18:20 | |
*** stevemar____ has joined #openstack-keystone | 18:20 | |
*** morgan__ is now known as morganfainberg | 18:20 | |
*** morganfainberg has quit IRC | 18:20 | |
*** morganfainberg has joined #openstack-keystone | 18:20 | |
*** morganfainberg has joined #openstack-keystone | 18:20 | |
*** morganfainberg is now known as morgan | 18:20 | |
*** Guest45079 has quit IRC | 18:21 | |
*** morgan_ has quit IRC | 18:21 | |
*** _nonameentername has joined #openstack-keystone | 18:21 | |
*** artmr has quit IRC | 18:21 | |
*** electrichead has joined #openstack-keystone | 18:21 | |
*** sileht has quit IRC | 18:21 | |
*** nonameentername has quit IRC | 18:21 | |
*** electrichead is now known as Guest78091 | 18:22 | |
morgan | wow, this is bad today | 18:22 |
*** ngupta has quit IRC | 18:23 | |
*** ngupta has joined #openstack-keystone | 18:23 | |
*** artmr has joined #openstack-keystone | 18:23 | |
*** harlowja has joined #openstack-keystone | 18:24 | |
*** sileht has joined #openstack-keystone | 18:25 | |
*** pkoraca has joined #openstack-keystone | 18:26 | |
*** code-R has joined #openstack-keystone | 18:28 | |
*** artmr_ has joined #openstack-keystone | 18:30 | |
*** artmr has quit IRC | 18:30 | |
*** brad[] has joined #openstack-keystone | 18:33 | |
*** asettle has joined #openstack-keystone | 18:35 | |
*** sdake has quit IRC | 18:35 | |
openstackgerrit | Merged openstack/python-keystoneclient: TrivialFix: Fixed typo in some files https://review.openstack.org/377338 | 18:41 |
*** asettle has quit IRC | 18:41 | |
*** roxanaghe has quit IRC | 18:42 | |
*** med_ has joined #openstack-keystone | 18:43 | |
*** med_ is now known as Guest40876 | 18:44 | |
*** prashkre__ has quit IRC | 18:47 | |
*** sdake has joined #openstack-keystone | 18:49 | |
*** adrian_otto has quit IRC | 18:55 | |
*** ezpz has joined #openstack-keystone | 18:56 | |
*** brad[] has quit IRC | 18:57 | |
*** DuncanT has quit IRC | 18:58 | |
*** DuncanT has joined #openstack-keystone | 19:00 | |
lbragstad | if folks have an opinion on this or think we need to have a wider discussion we should do so in Barcelona | 19:01 |
*** gagehugo has quit IRC | 19:01 | |
lbragstad | regardless of what we do - i think it would be nice to have a plan in place sometime this release | 19:01 |
anteaya | stevemar: I'm not a guy | 19:02 |
anteaya | and why don't you have a tail in this channel? | 19:02 |
*** stevemar____ has quit IRC | 19:02 | |
stevemar | anteaya: huh, i actually wrote "guys" | 19:03 |
stevemar | anteaya: i thought i kicked that habit | 19:03 |
stevemar | my bad | 19:03 |
anteaya | it is in the archives yeah | 19:04 |
*** gagehugo has joined #openstack-keystone | 19:04 | |
anteaya | I had thought so too | 19:04 |
anteaya | in any case, thanks | 19:04 |
stevemar | anteaya: i logged onto freenode directly, with the tail; but this is my bouncer | 19:04 |
anteaya | ah | 19:04 |
anteaya | steve the bouncer | 19:04 |
stevemar | anteaya: it's good when freenode isn't going wonky | 19:04 |
anteaya | it is good when freenode isn't wonky | 19:05 |
*** gyee has quit IRC | 19:08 | |
rderose | SpamapS: so composite index? since we know what columns will commonly be in the token? | 19:08 |
*** sdake has quit IRC | 19:10 | |
rderose | SpamapS: or, what would you suggest? | 19:11 |
*** haplo37- has quit IRC | 19:11 | |
*** haplo37- has joined #openstack-keystone | 19:12 | |
*** zzzeek has quit IRC | 19:12 | |
*** zzzeek has joined #openstack-keystone | 19:12 | |
bknudson | rderose: all the fields are always in the token. | 19:18 |
rderose | v2 and v3? | 19:18 |
rderose | bknudson: it looks like v3 allows user_id to be None | 19:19 |
bknudson | the code that calls into the revocation events normalizes v2 and v3 tokens and all their formats into a single dict that has all the possible fields | 19:19 |
rderose | ah, nice | 19:20 |
rderose | bknudson: then I think a composite index would make sense, but want to test that out | 19:20 |
bknudson | a composite index will likely work well... try it out and see what the explain says. | 19:22 |
rderose | bknudson: cool, will do | 19:24 |
SpamapS | rderose: sorry, got distracted away. I'm still not sure I have a grasp on the writes:reads ratio. | 19:24 |
rderose | SpamapS: yeah, that's a hard one to answer. | 19:24 |
SpamapS | Is it? | 19:24 |
bknudson | SpamapS: it's likely about 10:1 or 20:1... unfortunately we don't see a lot of token re-use. | 19:24 |
bknudson | but, we also don't see a lot of revocations | 19:25 |
rderose | SpamapS: yeah, because it could vary based on the cloud apps | 19:25 |
SpamapS | I'd think token invalidation from outside keystone itself is rare. Am I wrong in that? | 19:25 |
bknudson | where we see a problem is when automated testing happens that creates and destroys a lot of test users. | 19:25 |
*** ngupta_ has joined #openstack-keystone | 19:25 | |
bknudson | where we see token invalidations is typically coming from horizon invalidating tokens when they log out. | 19:26 |
bknudson | and the automated testing as I mentioned. | 19:26 |
SpamapS | bknudson: hm, if you don't see a lot of revocations, then the revocation_event table specifically should be more like 10000:1 reads:writes | 19:26 |
*** henrynash_ has joined #openstack-keystone | 19:26 | |
*** crinkle_ has joined #openstack-keystone | 19:26 | |
*** cnf has quit IRC | 19:26 | |
*** Marcellin__ has quit IRC | 19:26 | |
*** serverascode has quit IRC | 19:27 | |
*** briancurtin has quit IRC | 19:27 | |
*** stevemar has quit IRC | 19:27 | |
*** mdurrant has joined #openstack-keystone | 19:27 | |
*** sileht has quit IRC | 19:27 | |
*** Marcellin__ has joined #openstack-keystone | 19:27 | |
*** Guest40876 has quit IRC | 19:27 | |
*** ayoung_ has quit IRC | 19:27 | |
*** BlackDex has quit IRC | 19:27 | |
*** SamYaple has quit IRC | 19:27 | |
*** jefrite has quit IRC | 19:27 | |
rderose | SpamapS: so assuming infrequent writes, does an composite index make sense for the reads? | 19:27 |
*** SamYaple has joined #openstack-keystone | 19:27 | |
knikolla | rodrigods: you there? | 19:27 |
*** cnfer has joined #openstack-keystone | 19:27 | |
rodrigods | knikolla, yep | 19:27 |
*** mdurrant_ has quit IRC | 19:27 | |
*** cnfer is now known as cnf | 19:27 | |
rderose | SpamapS: as bknudson said, all the fields are always in the token | 19:27 |
*** henrynash has quit IRC | 19:27 | |
*** crinkle has quit IRC | 19:28 | |
rodrigods | saw your topic in the meeting | 19:28 |
SpamapS | rderose: infrequent writes means more indexes will be cheaper, and thus we can cover all the cases more effectively. | 19:28 |
rodrigods | i was going to say that testing the devstack plugin is in my todo list | 19:28 |
*** serverascode has joined #openstack-keystone | 19:28 | |
knikolla | rodrigods: just ran into an issue a few hours ago, might need your help to iron out the last things | 19:28 |
knikolla | rodrigods: http://paste.openstack.org/show/583135/ | 19:28 |
rodrigods | knikolla, sure, will need to leave in some minutes but we can continue via email | 19:28 |
SpamapS | rderose: the composite of user_id+the date field will likely be the best index in every case, if every token submits all the fields into that OR tree | 19:29 |
rderose | SpamapS: great | 19:29 |
*** ngupta has quit IRC | 19:29 | |
*** henrynash_ is now known as henrynash | 19:29 | |
SpamapS | since user_id is the narrowest scope | 19:29 |
bknudson | the query always has all the fields. | 19:29 |
bknudson | most of them will be IS NULL | 19:29 |
rodrigods | knikolla, hmm looks like keystoneauth sent "saml2"as auth method | 19:29 |
SpamapS | oh, so it has "the fields", but not values? | 19:29 |
rderose | SpamapS: table may not have the values, but token will | 19:30 |
SpamapS | Ok, so every token is always scoped to a user ID? | 19:30 |
rderose | yes | 19:30 |
*** wolsen has quit IRC | 19:30 | |
bknudson | correct, if you look at the query http://paste.openstack.org/show/583126/ | 19:30 |
SpamapS | Ok, so that's your winner | 19:30 |
bknudson | most of the values will be NULL | 19:30 |
*** stevemar has joined #openstack-keystone | 19:30 | |
*** jefrite has joined #openstack-keystone | 19:30 | |
SpamapS | and it will get slower and slower with any non-user-id revocation events. | 19:31 |
bknudson | I think user_id is going to always be set | 19:31 |
SpamapS | Right, but you have that OR IS NULL | 19:31 |
SpamapS | so you can match project scoped events, yes? | 19:31 |
SpamapS | or domain scoped | 19:31 |
knikolla | rodrigods: the documentation is not too great. if you could give the plugin a few spins it would help greatly. | 19:31 |
SpamapS | one thing that might make more sense is to not have those fields | 19:32 |
rodrigods | knikolla, so... saml2 was the name of the auth method in the keystone server | 19:32 |
*** mdurrant_ has joined #openstack-keystone | 19:32 | |
SpamapS | and just always write an event for every user ID that exists at the time of revocation | 19:32 |
knikolla | rodrigods: yeah, and the guide says to change keystone.conf for mapped, as mapped includes saml2 | 19:32 |
rodrigods | knikolla, if received a token with saml2 there, the correct provider would take care | 19:32 |
openstackgerrit | Arthur Miranda proposed openstack/python-keystoneclient: Prevent attempts to "filter" list() calls by globally unique IDs https://review.openstack.org/378001 | 19:32 |
rodrigods | knikolla, but... saml2 was deprecated in favor of mapped | 19:32 |
SpamapS | That will be a more effective strategy than indexing. | 19:32 |
SpamapS | bknudson: rderose ^ | 19:32 |
rodrigods | knikolla, my guess is that keystoneauth hasn't been updated, so it is still sending saml2 | 19:32 |
SpamapS | Just stop using project ID and domain ID and denormalize that table. | 19:32 |
*** ktychkova_ has quit IRC | 19:33 | |
rderose | SpamapS: I think ravelar or lbragstad is working on a patch to remove project_id and domain_id | 19:33 |
SpamapS | well there you go | 19:34 |
SpamapS | if you didn't have all those and's | 19:34 |
knikolla | rodrigods: is the url that needs to be changed or the payload? | 19:34 |
SpamapS | and could drop the is null from the user_id filter | 19:34 |
SpamapS | that becomes a _super_ fast query. | 19:34 |
*** DinaBelova has quit IRC | 19:34 | |
SpamapS | in fact, you could make it an index-only query | 19:34 |
*** htruta has quit IRC | 19:34 | |
bknudson | SpamapS: yes | 19:34 |
bknudson | right, the events typically don't have a user_id ! | 19:34 |
bknudson | the token always has a user_id | 19:34 |
bknudson | when I was testing this I was doing direct token revocations so the audit_id field and the timestamps were set. | 19:34 |
bknudson | sample data: http://paste.openstack.org/show/583161/ | 19:34 |
SpamapS | which means you never even touch the data rows | 19:34 |
bknudson | this is what your table would look like if your users were using horizon so had lots of token revocations | 19:34 |
bknudson | the table would look different if the revocations were because of project disabling or user password changes or whatever else. | 19:34 |
*** ianw has quit IRC | 19:35 | |
*** freerunner has quit IRC | 19:35 | |
*** mkoderer__ has quit IRC | 19:35 | |
*** tonyb has quit IRC | 19:35 | |
SpamapS | audit_id is what? | 19:35 |
*** akscram1 has quit IRC | 19:35 | |
*** rdo_ has quit IRC | 19:35 | |
*** pkoraca has quit IRC | 19:35 | |
*** Marcellin__ has quit IRC | 19:35 | |
bknudson | SpamapS: every token has an audit_id | 19:35 |
*** serverascode has quit IRC | 19:35 | |
*** DuncanT has quit IRC | 19:35 | |
*** pleia2 has quit IRC | 19:35 | |
*** rha has quit IRC | 19:35 | |
*** cnf has quit IRC | 19:35 | |
bknudson | it's unique to the token (like the token_id) | 19:36 |
SpamapS | bknudson: ah, so you can just revoke that one. Makes sense. | 19:36 |
*** mdurrant has quit IRC | 19:36 | |
*** mtreinish has quit IRC | 19:36 | |
*** AndyWojo has quit IRC | 19:36 | |
*** arunkant__ has quit IRC | 19:36 | |
*** vkmc has quit IRC | 19:36 | |
*** amakarov has quit IRC | 19:36 | |
*** bigjools has quit IRC | 19:36 | |
*** akscram1 has joined #openstack-keystone | 19:36 | |
*** stevemar has quit IRC | 19:36 | |
*** zzzeek has quit IRC | 19:36 | |
*** tonyb_ has joined #openstack-keystone | 19:36 | |
bknudson | the nice thing about audit_id is you can't use it to authenticate so you can identity a token without giving out auth info | 19:36 |
*** amakarov has joined #openstack-keystone | 19:36 | |
*** mtreinish has joined #openstack-keystone | 19:36 | |
*** pleia2 has joined #openstack-keystone | 19:36 | |
*** stevemar has joined #openstack-keystone | 19:36 | |
*** ianw has joined #openstack-keystone | 19:36 | |
*** cnf has joined #openstack-keystone | 19:37 | |
*** freerunner has joined #openstack-keystone | 19:37 | |
*** vkmc has joined #openstack-keystone | 19:37 | |
*** arunkant__ has joined #openstack-keystone | 19:37 | |
SpamapS | so, if you could only do user_id and audit_id, plus the issued_before field, then basically your queries are always going to be WHERE (user_id='foo' OR audit_id='bar') AND issued_before >= '1971-01-01 00:00:00' | 19:37 |
bknudson | SpamapS: we don't have to store project_id or domain_id because we can check the db to see if the project is valid. | 19:37 |
*** sileht has joined #openstack-keystone | 19:37 | |
bknudson | same with role_id, trust_id, consumer_id, access_token_id | 19:38 |
bknudson | we only need user_id because tokens are revoked on password change. | 19:38 |
rderose | ravelar: ^ | 19:38 |
*** wolsen has joined #openstack-keystone | 19:38 | |
SpamapS | bknudson: makes sense, and all of those checks are also all single PK reads, which makes them fast. :) | 19:38 |
*** htruta has joined #openstack-keystone | 19:38 | |
bknudson | and memcached | 19:39 |
*** DinaBelova has joined #openstack-keystone | 19:39 | |
rderose | so in this case, I would only need composite index (user_id + issued_before), (audit_id + issued_before)? | 19:39 |
rderose | SpamapS: ^ | 19:39 |
SpamapS | bknudson: actually yes, caching is fantastic in PK checks, because PK's are immutable. | 19:39 |
*** mkoderer__ has joined #openstack-keystone | 19:39 | |
*** bigjools has joined #openstack-keystone | 19:39 | |
*** bigjools has quit IRC | 19:39 | |
*** bigjools has joined #openstack-keystone | 19:39 | |
SpamapS | so you don't have to worry about complicated invalidation ruining your day | 19:40 |
*** rha has joined #openstack-keystone | 19:40 | |
rderose | sweet! | 19:41 |
*** med_ has joined #openstack-keystone | 19:43 | |
SpamapS | Ideally there's a single spot to memoize checks from those fields. | 19:43 |
*** bknudson has quit IRC | 19:43 | |
*** med_ is now known as Guest45789 | 19:43 | |
SpamapS | rderose: so.. about the indexes | 19:43 |
rderose | :) | 19:43 |
SpamapS | rderose: OR's almost never index well together. | 19:43 |
SpamapS | MySQL does try to do a merge based approach if you OR two fields with similar cardinality. | 19:43 |
*** rvba` has quit IRC | 19:44 | |
*** kfox1111 has quit IRC | 19:44 | |
SpamapS | but IIRC, it almost never works out well, and has been mostly factored out of the optimizer | 19:44 |
SpamapS | http://dev.mysql.com/doc/refman/5.7/en/index-merge-optimization.html | 19:44 |
*** wolsen has quit IRC | 19:44 | |
*** stevemar has quit IRC | 19:44 | |
*** DinaBelova has quit IRC | 19:44 | |
*** rha has quit IRC | 19:44 | |
*** haplo37- has quit IRC | 19:44 | |
*** mdavidson has quit IRC | 19:45 | |
*** cnf has quit IRC | 19:45 | |
*** DinaBelova has joined #openstack-keystone | 19:45 | |
*** bknudson_ has joined #openstack-keystone | 19:45 | |
*** ChanServ sets mode: +v bknudson_ | 19:45 | |
*** tonytan_brb has quit IRC | 19:45 | |
*** vkmc has quit IRC | 19:45 | |
*** mkoderer__ has quit IRC | 19:45 | |
*** mkoderer__ has joined #openstack-keystone | 19:45 | |
*** rha has joined #openstack-keystone | 19:46 | |
*** vkmc has joined #openstack-keystone | 19:46 | |
*** ChanServ sets mode: +v henrynash | 19:46 | |
*** rdo has joined #openstack-keystone | 19:47 | |
rderose | SpamapS: I se | 19:47 |
*** haplo37- has joined #openstack-keystone | 19:47 | |
rderose | e | 19:47 |
*** rvba has joined #openstack-keystone | 19:47 | |
*** rvba has quit IRC | 19:47 | |
*** rvba has joined #openstack-keystone | 19:47 | |
rderose | SpamapS bknudson: like the new plan ;) | 19:48 |
SpamapS | rderose: Unfortunately, my experience has been almost 100% negative with index_merge. | 19:48 |
rderose | really | 19:48 |
rderose | okay | 19:49 |
SpamapS | but, I think the one place it is supposed to be good is on EXISTS queries | 19:49 |
SpamapS | because you don't have to wait for the temp table to be built | 19:49 |
*** kfox1111 has joined #openstack-keystone | 19:49 | |
rderose | I see | 19:49 |
*** BlackDex has joined #openstack-keystone | 19:49 | |
*** cnf has joined #openstack-keystone | 19:50 | |
SpamapS | I think it's worth it though | 19:50 |
SpamapS | if you can boil things down to just queries that do an OR on user_id and audit_id, plus an AND on issued_before... I think index_merge will happen, and will be fast. | 19:51 |
*** ravelar has joined #openstack-keystone | 19:51 | |
SpamapS | pretty easy to test too | 19:51 |
*** zzzeek has joined #openstack-keystone | 19:52 | |
*** stevemar has joined #openstack-keystone | 19:52 | |
*** artmr_ has quit IRC | 19:53 | |
rderose | yeah | 19:53 |
*** DuncanT has joined #openstack-keystone | 19:53 | |
SpamapS | rderose: ultimately, the idea is to get to a point where you are a gnat buzzing around the tail of the mysql server.. instead of a cowboy trying to saddle and ride it. ;) | 19:54 |
*** adrian_otto has joined #openstack-keystone | 19:54 | |
bknudson_ | do we want to do this work in a different order? For example, get project_id, etc, out of the revocation events table? | 19:56 |
*** wolsen has joined #openstack-keystone | 19:56 | |
bknudson_ | ** get project_id, etc, out of the revocation events table first? | 19:56 |
*** briancurtin has joined #openstack-keystone | 19:57 | |
*** browne has quit IRC | 20:02 | |
*** serverascode has joined #openstack-keystone | 20:03 | |
*** pkoraca has joined #openstack-keystone | 20:06 | |
*** AndyWojo has joined #openstack-keystone | 20:07 | |
SpamapS | bknudson_: well I think that would be ideal, because it would _massively_ simplify the query | 20:07 |
SpamapS | you don't have to do the explicit OR IS NULL's anymore for instance | 20:07 |
*** adrian_otto has quit IRC | 20:09 | |
*** sdake has joined #openstack-keystone | 20:13 | |
*** adrian_otto has joined #openstack-keystone | 20:13 | |
*** julim has joined #openstack-keystone | 20:15 | |
*** julim has quit IRC | 20:16 | |
rderose | ravelar: ^ | 20:16 |
rderose | bknudson: I think so | 20:17 |
ravelar | the dropped columns are still WIP, but that's the plan | 20:18 |
rderose | ravelar: is there a patch already? | 20:18 |
ravelar | https://review.openstack.org/#/c/371083/4 | 20:19 |
ravelar | https://review.openstack.org/#/c/285134/ which has been picked up again | 20:19 |
ravelar | recent | 20:19 |
rderose | bknudson SpamapS ^ | 20:19 |
SpamapS | btw you don't have to drop the columns to stop using them. :) | 20:20 |
SpamapS | (dropping columns breaks online upgrades, so I suggest not doing that) | 20:20 |
rderose | ravelar: are you taking over 285134? | 20:20 |
rderose | true | 20:20 |
ravelar | lance method should do that without having to drop anything SpamapS | 20:20 |
*** tonytan4ever has joined #openstack-keystone | 20:21 | |
*** code-R has quit IRC | 20:21 | |
*** mrsoul has quit IRC | 20:21 | |
*** code-R has joined #openstack-keystone | 20:21 | |
*** topol has quit IRC | 20:22 | |
*** rvba` has joined #openstack-keystone | 20:22 | |
*** frickler has quit IRC | 20:22 | |
*** bknudson has joined #openstack-keystone | 20:22 | |
*** ChanServ sets mode: +v bknudson | 20:22 | |
*** mkoderer___ has joined #openstack-keystone | 20:22 | |
*** pkoraca has quit IRC | 20:22 | |
*** wolsen has quit IRC | 20:22 | |
*** DuncanT has quit IRC | 20:22 | |
*** bknudson_ has quit IRC | 20:22 | |
*** rvba has quit IRC | 20:23 | |
*** DinaBelova has quit IRC | 20:23 | |
*** lamt has quit IRC | 20:23 | |
*** sdake_ has joined #openstack-keystone | 20:23 | |
SpamapS | ravelar: lance method? | 20:23 |
*** mrsoul has joined #openstack-keystone | 20:23 | |
*** zzzeek has quit IRC | 20:23 | |
*** vkmc has quit IRC | 20:23 | |
ravelar | SpamapS https://review.openstack.org/#/c/371083/ | 20:23 |
*** mkoderer__ has quit IRC | 20:24 | |
*** rdo has quit IRC | 20:24 | |
*** sdake has quit IRC | 20:24 | |
*** arunkant__ has quit IRC | 20:24 | |
*** ravelar has quit IRC | 20:24 | |
*** rdo has joined #openstack-keystone | 20:24 | |
*** vkmc has joined #openstack-keystone | 20:24 | |
*** gyee has joined #openstack-keystone | 20:24 | |
*** ChanServ sets mode: +v gyee | 20:24 | |
*** DinaBelova has joined #openstack-keystone | 20:25 | |
*** ravelar has joined #openstack-keystone | 20:25 | |
*** asettle has joined #openstack-keystone | 20:26 | |
*** zzzeek has joined #openstack-keystone | 20:27 | |
*** arunkant__ has joined #openstack-keystone | 20:27 | |
*** topol_ has joined #openstack-keystone | 20:28 | |
*** ravelar1 has joined #openstack-keystone | 20:30 | |
*** ngupta_ has quit IRC | 20:31 | |
stevemar | SpamapS: lance method's are the best kind of methods | 20:32 |
*** AndyWojo has quit IRC | 20:32 | |
*** serverascode has quit IRC | 20:32 | |
*** briancurtin has quit IRC | 20:32 | |
*** DinaBelova has quit IRC | 20:32 | |
SpamapS | stevemar: obviously | 20:32 |
*** ngupta has joined #openstack-keystone | 20:32 | |
*** DinaBelova2 has joined #openstack-keystone | 20:33 | |
*** topol_ has quit IRC | 20:33 | |
*** ravelar has quit IRC | 20:33 | |
*** vkmc has quit IRC | 20:33 | |
*** rdo has quit IRC | 20:33 | |
*** topol__ has joined #openstack-keystone | 20:33 | |
*** rdo has joined #openstack-keystone | 20:33 | |
*** rakhmerov has quit IRC | 20:33 | |
*** DinaBelova2 is now known as DinaBelova | 20:33 | |
*** vkmc has joined #openstack-keystone | 20:34 | |
*** sc68cal_ is now known as sc68cal | 20:35 | |
*** rakhmerov has joined #openstack-keystone | 20:36 | |
*** ngupta has quit IRC | 20:37 | |
*** frickler has joined #openstack-keystone | 20:37 | |
*** browne has joined #openstack-keystone | 20:38 | |
*** DuncanT has joined #openstack-keystone | 20:39 | |
*** wolsen has joined #openstack-keystone | 20:39 | |
*** code-R has quit IRC | 20:42 | |
*** ezpz has quit IRC | 20:43 | |
*** rakhmerov__ has joined #openstack-keystone | 20:43 | |
*** rakhmerov has quit IRC | 20:43 | |
*** serverascode has joined #openstack-keystone | 20:43 | |
*** mdurrant__ has joined #openstack-keystone | 20:44 | |
*** nkinder has quit IRC | 20:44 | |
*** Anticimex has quit IRC | 20:44 | |
*** DinaBelova has quit IRC | 20:45 | |
*** DinaBelova2 has joined #openstack-keystone | 20:45 | |
*** DinaBelova2 is now known as DinaBelova | 20:46 | |
*** DuncanT has quit IRC | 20:46 | |
*** wolsen has quit IRC | 20:46 | |
*** sdake_ has quit IRC | 20:46 | |
*** jamielennox has quit IRC | 20:46 | |
*** vkmc has quit IRC | 20:46 | |
*** rha has quit IRC | 20:46 | |
*** Anticime1 has joined #openstack-keystone | 20:46 | |
*** mdurrant_ has quit IRC | 20:47 | |
*** sdake has joined #openstack-keystone | 20:47 | |
*** briancurtin has joined #openstack-keystone | 20:47 | |
*** rha has joined #openstack-keystone | 20:47 | |
*** rha has quit IRC | 20:47 | |
*** rha has joined #openstack-keystone | 20:47 | |
*** nkinder has joined #openstack-keystone | 20:48 | |
*** lamt has joined #openstack-keystone | 20:49 | |
*** vkmc has joined #openstack-keystone | 20:50 | |
*** brad[] has joined #openstack-keystone | 20:50 | |
*** gagehugo has quit IRC | 20:51 | |
*** jamielennox has joined #openstack-keystone | 20:51 | |
*** ChanServ sets mode: +v jamielennox | 20:51 | |
*** pkoraca has joined #openstack-keystone | 20:53 | |
*** AndyWojo has joined #openstack-keystone | 20:53 | |
*** raildo has quit IRC | 20:56 | |
*** wolsen has joined #openstack-keystone | 20:56 | |
*** DuncanT has joined #openstack-keystone | 20:57 | |
*** adrian_otto has quit IRC | 21:00 | |
*** adrian_otto has joined #openstack-keystone | 21:03 | |
*** code-R has joined #openstack-keystone | 21:04 | |
*** ddieterly has joined #openstack-keystone | 21:05 | |
*** chris_hultin is now known as chris_hultin|AWA | 21:06 | |
*** woodburn1 has quit IRC | 21:08 | |
*** ngupta has joined #openstack-keystone | 21:09 | |
*** ngupta has quit IRC | 21:11 | |
*** ngupta has joined #openstack-keystone | 21:12 | |
*** code-R has quit IRC | 21:17 | |
*** ddieterly is now known as ddieterly[away] | 21:18 | |
*** ddieterly[away] is now known as ddieterly | 21:21 | |
*** sdake has quit IRC | 21:22 | |
*** ngupta has quit IRC | 21:22 | |
*** woodburn has joined #openstack-keystone | 21:23 | |
*** ngupta has joined #openstack-keystone | 21:23 | |
*** spilla has quit IRC | 21:31 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: WIP - Validate project exists and enabled directly https://review.openstack.org/378047 | 21:39 |
rderose | bknudson: nice! | 21:41 |
*** gagehugo has joined #openstack-keystone | 21:42 | |
*** ngupta has quit IRC | 21:42 | |
bknudson | rderose: lots of work left. | 21:43 |
*** ngupta has joined #openstack-keystone | 21:43 | |
rderose | bknudson: yeah | 21:46 |
rderose | bknudson: the only thing that gives me pause, is that we're now doing extra sql calls | 21:47 |
*** spzala has quit IRC | 21:47 | |
rderose | bknudson: to check for project, domain, role | 21:47 |
rderose | bknudson: but I suppose with caching, it won't matter | 21:47 |
*** spzala has joined #openstack-keystone | 21:48 | |
*** ngupta has quit IRC | 21:48 | |
bknudson | rderose: that's the hope is that the project , domain, etc., data will be cached. | 21:48 |
rderose | yeah, cool | 21:49 |
rderose | this should work | 21:49 |
*** adrian_otto has quit IRC | 21:49 | |
bknudson | next steps are like: | 21:49 |
bknudson | 2) Change the revocation event code to stop checking project, etc. | 21:49 |
bknudson | 3) Create a new table for project_id, etc., revocation events | 21:50 |
rderose | bknudson: are you planning to check if the user still has the role as well? | 21:50 |
bknudson | 4) When revocation event is for project_id, etc., put it to the new table rather than the old one. | 21:50 |
bknudson | 5) When done with old version of code, remove columns from old table. | 21:50 |
rderose | ah, I see | 21:50 |
bknudson | 6) Change list revoke events to get from the other table, too | 21:50 |
rderose | bknudson: why the new table? | 21:51 |
bknudson | rderose: the list events API needs to still return those events. | 21:52 |
bknudson | but checking for revoked doesn't need to | 21:52 |
rderose | I see | 21:52 |
bknudson | so list events API can just UNION the 2 tables. | 21:52 |
*** spzala has quit IRC | 21:52 | |
rderose | that makes sense | 21:53 |
rderose | break the revocation_event table up | 21:53 |
rderose | will this patch include roles assignments as well? | 21:53 |
bknudson | rderose: I figured I'd put all the checks in this patch, unless it gets too hairy | 21:54 |
bknudson | Although I could also put those in follow-on patches so maybe that's better. | 21:54 |
rderose | bknudson: sweet! | 21:55 |
*** slberger has left #openstack-keystone | 21:55 | |
*** tonyb_ is now known as tonyb | 21:56 | |
rderose | bknudson: so the patch that ravelar is working on, he could just check for (user_id or audit_id) and issued_before? What are your thoughts there? | 21:57 |
bknudson | rderose: it'll still have to check for revocations due to the user password changing and for direct token revocation | 21:58 |
rderose | bknudson: perfect | 21:58 |
bknudson | so, right, user_id, audit_id, audit_chain_id. | 21:58 |
rderose | ravelar: ^ | 21:59 |
rderose | ravelar: sound good? | 21:59 |
rderose | woops, ravelar1 ^ | 21:59 |
ravelar1 | rderose bknudson, that works for me. I can update the code to support the proposed patch of reducing revocation event | 22:01 |
ravelar1 | bknudson, just looked at the review, this is going to be a good one | 22:01 |
rderose | ravelar1: and you'll like have your patch depend on bknudson's patch | 22:02 |
rderose | *likely | 22:02 |
rodrigods | just saw bknudson patch | 22:03 |
bknudson | rderose: ravelar1: created an etherpad: https://etherpad.openstack.org/p/key_revocation_event_cleanup | 22:03 |
rodrigods | can we do the same for domains? | 22:03 |
rodrigods | disabled domains | 22:04 |
bknudson | I don't know if I'm going to have time to finish all of this. | 22:04 |
bknudson | rodrigods: yes, we'll also need domains. | 22:04 |
*** iurygregory_ has joined #openstack-keystone | 22:04 | |
rodrigods | ++ | 22:04 |
bknudson | I just wanted to see if it would work and put up a Proof-of-concept | 22:04 |
bknudson | maybe ravelar1 or rderose or someone can pick this up and add the rest? | 22:04 |
rderose | bknudson: yeah, sounds good | 22:05 |
ravelar1 | bknudson ++ | 22:05 |
*** asettle has quit IRC | 22:09 | |
rderose | bknudson ravelar: once 1 and 2 done, we should still see big performance improvements | 22:10 |
rderose | 3-6 really just improves the design | 22:11 |
*** haplo37- has quit IRC | 22:12 | |
*** haplo37- has joined #openstack-keystone | 22:14 | |
*** ravelar1 has quit IRC | 22:20 | |
*** Guest45789 is now known as med_ | 22:22 | |
*** med_ has quit IRC | 22:23 | |
*** med_ has joined #openstack-keystone | 22:23 | |
*** spzala has joined #openstack-keystone | 22:33 | |
*** ngupta has joined #openstack-keystone | 22:44 | |
*** ngupta has quit IRC | 22:44 | |
*** roxanaghe has joined #openstack-keystone | 22:44 | |
*** ngupta has joined #openstack-keystone | 22:44 | |
*** gagehugo has quit IRC | 22:44 | |
*** ddieterly is now known as ddieterly[away] | 22:44 | |
*** roxanaghe has quit IRC | 22:45 | |
*** roxanaghe has joined #openstack-keystone | 22:46 | |
*** frontrunner2 has quit IRC | 22:47 | |
*** ngupta has quit IRC | 22:49 | |
*** alex_xu has quit IRC | 22:50 | |
*** ChanServ sets mode: +o stevemar | 22:52 | |
*** alex_xu has joined #openstack-keystone | 22:52 | |
*** gagehugo has joined #openstack-keystone | 22:54 | |
*** sdake has joined #openstack-keystone | 22:56 | |
*** sdake_ has joined #openstack-keystone | 22:58 | |
*** ddieterly[away] is now known as ddieterly | 22:58 | |
*** ddieterly is now known as ddieterly[away] | 22:59 | |
*** ddieterly[away] has quit IRC | 22:59 | |
*** nicolasbock has quit IRC | 23:01 | |
*** sdake has quit IRC | 23:01 | |
*** nicolasbock has joined #openstack-keystone | 23:02 | |
*** lamt has quit IRC | 23:10 | |
*** Gorian|work has quit IRC | 23:17 | |
*** adrian_otto has joined #openstack-keystone | 23:18 | |
*** markvoelker has quit IRC | 23:19 | |
*** ddieterly has joined #openstack-keystone | 23:29 | |
*** ddieterly is now known as ddieterly[away] | 23:31 | |
*** EinstCrazy has joined #openstack-keystone | 23:47 | |
*** EinstCrazy has quit IRC | 23:48 | |
*** ddieterly[away] is now known as ddieterly | 23:49 | |
*** guoshan has joined #openstack-keystone | 23:49 | |
*** frontrunner has joined #openstack-keystone | 23:49 | |
*** tonytan4ever has quit IRC | 23:55 | |
*** spzala has quit IRC | 23:55 | |
*** spzala_ has joined #openstack-keystone | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!