*** tqtran has quit IRC | 00:01 | |
*** harlowja has quit IRC | 00:06 | |
*** ayoung has quit IRC | 00:08 | |
*** stingaci has quit IRC | 00:25 | |
*** harlowja has joined #openstack-keystone | 00:34 | |
*** raildo_ has quit IRC | 00:35 | |
openstackgerrit | ayoung proposed openstack/keystone: API based RBAC Management Interface https://review.openstack.org/401808 | 00:43 |
---|---|---|
*** ayoung has joined #openstack-keystone | 00:53 | |
*** ChanServ sets mode: +v ayoung | 00:53 | |
*** jamielennox is now known as jamielennox|away | 00:57 | |
*** jamielennox|away is now known as jamielennox | 01:01 | |
*** Zer0Byte__ has quit IRC | 01:05 | |
*** asettle has joined #openstack-keystone | 01:08 | |
*** asettle has quit IRC | 01:13 | |
*** markvoelker has joined #openstack-keystone | 01:14 | |
*** zhangqiankun has joined #openstack-keystone | 01:16 | |
jamielennox | lbragstad: or whomever, https://review.openstack.org/#/c/406647/ needs to go into a release soon | 01:18 |
*** markvoelker has quit IRC | 01:19 | |
*** liujiong has joined #openstack-keystone | 01:21 | |
*** zhangjl has joined #openstack-keystone | 01:25 | |
*** harlowja has quit IRC | 01:25 | |
*** zhangqiankun has quit IRC | 01:33 | |
stevemar | jamielennox: do we not have any fixtures for tokens in keystone server side ? | 01:33 |
stevemar | nvm, i think we're good | 01:35 |
openstackgerrit | Merged openstack/keystoneauth: Remove discover from test-requirements https://review.openstack.org/411153 | 01:37 |
*** guoshan has joined #openstack-keystone | 01:40 | |
*** jamielennox is now known as jamielennox|away | 01:41 | |
*** mvk has quit IRC | 01:46 | |
*** jamielennox|away is now known as jamielennox | 01:47 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: expose v3policy failure with is_admin_token https://review.openstack.org/411562 | 01:54 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: modify cloud_admin rule so it loads properly https://review.openstack.org/411563 | 01:54 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: expose v3policy failure with is_admin_token https://review.openstack.org/411562 | 01:55 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: modify cloud_admin rule so it loads properly https://review.openstack.org/411563 | 01:56 |
stevemar | jamielennox: if you want to have a chuckle ^ | 01:56 |
jamielennox | stevemar: oh yea, at one point heat copied that from us and i had to fix it | 02:00 |
jamielennox | stevemar: so that actually works if the token is a v3 token | 02:00 |
jamielennox | because we dump the whole otken into the credential dict | 02:01 |
jamielennox | whic is dumb | 02:01 |
stevemar | jamielennox: yeah i just want the damn samples we provide to work | 02:01 |
stevemar | ya know, load | 02:02 |
jamielennox | did we add is_admin_project to our policy? | 02:02 |
jamielennox | i think i did | 02:02 |
jamielennox | but i had a whole plan of standardizing around oslo.context which got held up by the views stuff | 02:02 |
stevemar | jamielennox: we sure did | 02:05 |
stevemar | jamielennox: to the "standard" one | 02:05 |
stevemar | oh wait... we didn't | 02:05 |
stevemar | some other projects did | 02:05 |
stevemar | jamielennox: http://codesearch.openstack.org/?q=is_admin_project&i=nope&files=.*json&repos= | 02:07 |
stevemar | cinder, heat, searchlight | 02:07 |
stevemar | but for some reason *we* couldn't get it right | 02:07 |
jamielennox | lol | 02:07 |
jamielennox | i know ayoung went around and did a few | 02:07 |
*** asettle has joined #openstack-keystone | 02:09 | |
stevemar | i'm quite grumbly about it | 02:13 |
*** asettle has quit IRC | 02:13 | |
jamielennox | our policy/context stuff is worse than almost every project because we thought we were different | 02:14 |
stevemar | jamielennox: i'd agree with that | 02:27 |
samueldmq | for https://review.openstack.org/#/c/406647/ | 02:28 |
samueldmq | gerrit ui says to me | 02:28 |
samueldmq | Updatedin the future | 02:28 |
*** markvoelker has joined #openstack-keystone | 02:31 | |
*** markvoelker has quit IRC | 02:36 | |
stevemar | jamielennox: can you review https://review.openstack.org/#/c/408908/ | 02:41 |
jamielennox | stevemar: i never particularly cared about that, but ok | 02:43 |
stevemar | samueldmq: gerrit is a time traveler | 02:44 |
samueldmq | stevemar: hehe yep. So we technically approved that patch before jamielennox posted to review ;) | 02:47 |
*** zhangqiankun has joined #openstack-keystone | 02:51 | |
*** zhangqiankun has quit IRC | 02:53 | |
*** zhangqiankun has joined #openstack-keystone | 02:53 | |
*** lastops has joined #openstack-keystone | 02:54 | |
openstackgerrit | yunfeng zhou proposed openstack/keystone: Replace logging with oslo_log. https://review.openstack.org/411600 | 02:57 |
openstackgerrit | yunfeng zhou proposed openstack/keystone: Replace logging with oslo_log. https://review.openstack.org/411600 | 02:58 |
*** zhiyan has quit IRC | 03:02 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: expose v3policy failure with is_admin_token https://review.openstack.org/411562 | 03:04 |
openstackgerrit | Ron De Rose proposed openstack/keystone: expose v3policy failure with is_admin_token https://review.openstack.org/411562 | 03:07 |
*** ngupta has joined #openstack-keystone | 03:09 | |
*** ngupta has quit IRC | 03:09 | |
*** ngupta has joined #openstack-keystone | 03:09 | |
*** asettle has joined #openstack-keystone | 03:10 | |
stevemar | lbragstad: o/ | 03:10 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Replace logging with oslo_log. https://review.openstack.org/411600 | 03:10 |
stevemar | rderose: you can just punt the change through, it was a minor change | 03:11 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: modify cloud_admin rule so it loads properly https://review.openstack.org/411563 | 03:11 |
rderose | stevemar: ah, okay | 03:12 |
stevemar | rderose: i won't de-core you for that | 03:12 |
stevemar | :P | 03:12 |
stevemar | just explain why in the message | 03:12 |
stevemar | rderose: there is a follow-on change to fix the bug :) | 03:12 |
rderose | stevemar: haha | 03:12 |
rderose | stevemar: cool | 03:13 |
*** asettle has quit IRC | 03:14 | |
openstackgerrit | Merged openstack/keystoneauth: Don't issue deprecation warning when nesting adapters https://review.openstack.org/406647 | 03:24 |
*** tqtran has joined #openstack-keystone | 03:33 | |
*** tqtran has quit IRC | 03:40 | |
stevemar | jamielennox: propose a release? | 03:47 |
jamielennox | auth_tokne? | 03:47 |
stevemar | jamielennox: no, keystoneauth, i thought you wanted one after ^ merges? | 03:54 |
stevemar | rderose / samueldmq / lbragstad last call for https://review.openstack.org/#/c/411392/ before spec freeze ;) | 03:54 |
stevemar | jamielennox: also, whats up with https://bugs.launchpad.net/neutron/+bug/1602081 ? | 03:57 |
openstack | Launchpad bug 1602081 in OpenStack Identity (keystone) "Use oslo.context's policy dict" [High,In progress] - Assigned to Jamie Lennox (jamielennox) | 03:57 |
stevemar | i think i asked you before? sorry i don't remember | 03:57 |
jamielennox | umm, it all got held up because of the crappy way we do context in keystone | 04:00 |
jamielennox | the next step involved a lot of controller refactor and led to views | 04:00 |
jamielennox | there's probably an easier way, though views is the right one | 04:00 |
stevemar | jamielennox: you managed to fix it in all the other spots :P | 04:03 |
*** catintheroof has quit IRC | 04:06 | |
*** catintheroof has joined #openstack-keystone | 04:06 | |
*** catintheroof has quit IRC | 04:06 | |
*** asettle has joined #openstack-keystone | 04:10 | |
openstackgerrit | Merged openstack/keystoneauth: Replace six.iteritems() with .items() https://review.openstack.org/408908 | 04:11 |
*** guoshan has quit IRC | 04:12 | |
*** asettle has quit IRC | 04:15 | |
*** dave-mccowan has quit IRC | 04:26 | |
*** mvk has joined #openstack-keystone | 04:34 | |
*** ngupta has quit IRC | 04:34 | |
*** nicolasbock has quit IRC | 04:34 | |
*** edmondsw has joined #openstack-keystone | 04:37 | |
*** edmondsw has quit IRC | 04:42 | |
*** bjolo_ has joined #openstack-keystone | 04:42 | |
*** GB21 has joined #openstack-keystone | 04:47 | |
openstackgerrit | Merged openstack/keystone: Add doctor checks for ldap symptoms https://review.openstack.org/409292 | 04:47 |
stevemar | i just had a flashback of this time last year when someone a bunch of openstack channels with SW the force awakens spoilers | 04:49 |
stevemar | hope it doesn't happen again :( | 04:49 |
*** udesale has joined #openstack-keystone | 04:51 | |
*** g2 has quit IRC | 04:54 | |
*** BrAsS_mOnKeY has joined #openstack-keystone | 04:54 | |
openstackgerrit | Merged openstack/keystone-specs: Versioned federation mappings https://review.openstack.org/411392 | 04:55 |
stevemar | jamielennox: if you see henry can you get him to review https://review.openstack.org/#/c/411563/3 | 04:58 |
*** GB21 has quit IRC | 04:59 | |
*** BrAsS_mOnKeY is now known as g2 | 05:01 | |
*** asettle has joined #openstack-keystone | 05:11 | |
*** guoshan has joined #openstack-keystone | 05:13 | |
*** asettle has quit IRC | 05:15 | |
*** guoshan has quit IRC | 05:18 | |
morgan | stevemar: oh hai | 05:21 |
*** links has joined #openstack-keystone | 05:21 | |
openstackgerrit | Merged openstack/keystone: expose v3policy failure with is_admin_token https://review.openstack.org/411562 | 05:26 |
*** tqtran has joined #openstack-keystone | 05:37 | |
*** GB21 has joined #openstack-keystone | 05:38 | |
*** ngupta has joined #openstack-keystone | 05:42 | |
*** tqtran has quit IRC | 05:42 | |
*** jaosorior has joined #openstack-keystone | 06:02 | |
*** sorrison has quit IRC | 06:04 | |
*** dikonoor has joined #openstack-keystone | 06:12 | |
*** rcernin has quit IRC | 06:13 | |
*** guoshan has joined #openstack-keystone | 06:14 | |
*** guoshan has quit IRC | 06:18 | |
*** guoshan has joined #openstack-keystone | 06:19 | |
*** ngupta has quit IRC | 06:27 | |
*** ngupta has joined #openstack-keystone | 06:27 | |
*** ngupta has quit IRC | 06:31 | |
*** rcernin has joined #openstack-keystone | 06:37 | |
*** richm has quit IRC | 06:41 | |
*** rcernin has quit IRC | 06:43 | |
*** rcernin has joined #openstack-keystone | 06:54 | |
*** asettle has joined #openstack-keystone | 07:12 | |
*** asettle has quit IRC | 07:17 | |
*** adriant has quit IRC | 07:20 | |
*** mvk has quit IRC | 07:22 | |
*** mvk has joined #openstack-keystone | 07:31 | |
*** tobberydberg has joined #openstack-keystone | 07:35 | |
*** tqtran has joined #openstack-keystone | 07:39 | |
*** tqtran has quit IRC | 07:43 | |
openstackgerrit | pangliye proposed openstack/keystone: Use assertGreater(len(x), y) instead of assertTrue(len(x) > y) https://review.openstack.org/411679 | 07:45 |
*** GB21 has quit IRC | 07:51 | |
*** pcaruana has joined #openstack-keystone | 07:56 | |
*** tesseract has joined #openstack-keystone | 07:57 | |
*** tesseract is now known as Guest31304 | 07:58 | |
*** bjolo_ has quit IRC | 08:01 | |
*** jamielennox is now known as jamielennox|away | 08:07 | |
*** zhugaoxiao has quit IRC | 08:09 | |
*** zhugaoxiao has joined #openstack-keystone | 08:10 | |
openstackgerrit | yunfeng zhou proposed openstack/keystone: replace assertTrue with assertIs https://review.openstack.org/411689 | 08:11 |
*** jamielennox|away is now known as jamielennox | 08:14 | |
openstackgerrit | yunfeng zhou proposed openstack/keystone: replace assertTrue with assertIs. https://review.openstack.org/411689 | 08:15 |
*** GB21 has joined #openstack-keystone | 08:19 | |
*** amoralej|off is now known as amoralej | 08:31 | |
*** jaosorior has quit IRC | 08:32 | |
*** jaosorior has joined #openstack-keystone | 08:33 | |
*** asettle has joined #openstack-keystone | 08:34 | |
*** guoshan has quit IRC | 08:34 | |
*** guoshan has joined #openstack-keystone | 08:35 | |
*** asettle has quit IRC | 08:39 | |
*** hogepodge has quit IRC | 08:42 | |
*** udesale has quit IRC | 08:44 | |
*** hogepodge has joined #openstack-keystone | 08:44 | |
*** dikonoor has quit IRC | 08:46 | |
*** med_ has quit IRC | 08:53 | |
*** jaosorior has quit IRC | 08:55 | |
*** med_ has joined #openstack-keystone | 08:57 | |
*** med_ is now known as Guest67717 | 08:57 | |
*** zzzeek has quit IRC | 09:00 | |
*** udesale has joined #openstack-keystone | 09:00 | |
*** pooja_j has joined #openstack-keystone | 09:00 | |
*** zzzeek has joined #openstack-keystone | 09:02 | |
*** itisha has joined #openstack-keystone | 09:17 | |
*** GB21 has quit IRC | 09:24 | |
*** ngupta has joined #openstack-keystone | 09:30 | |
*** aloga has quit IRC | 09:31 | |
*** aloga has joined #openstack-keystone | 09:32 | |
*** trananhkma has quit IRC | 09:32 | |
*** asettle has joined #openstack-keystone | 09:33 | |
*** ngupta has quit IRC | 09:34 | |
*** GB21 has joined #openstack-keystone | 09:35 | |
*** tqtran has joined #openstack-keystone | 09:41 | |
*** tqtran has quit IRC | 09:45 | |
*** jamielennox is now known as jamielennox|away | 09:48 | |
*** jamielennox|away is now known as jamielennox | 09:55 | |
*** mvk has quit IRC | 09:56 | |
*** edmondsw has joined #openstack-keystone | 10:01 | |
*** edmondsw has quit IRC | 10:06 | |
*** mvk has joined #openstack-keystone | 10:09 | |
*** openstackgerrit has quit IRC | 10:18 | |
*** tobberydberg has quit IRC | 10:27 | |
*** ngupta has joined #openstack-keystone | 10:31 | |
*** liujiong has quit IRC | 10:33 | |
*** guoshan has quit IRC | 10:33 | |
*** zhangjl has left #openstack-keystone | 10:34 | |
*** ngupta has quit IRC | 10:35 | |
*** GB21 has quit IRC | 10:52 | |
*** GB21 has joined #openstack-keystone | 10:54 | |
*** guoshan has joined #openstack-keystone | 11:01 | |
*** richm has joined #openstack-keystone | 11:09 | |
*** guoshan has quit IRC | 11:11 | |
*** dgonzalez has quit IRC | 11:22 | |
*** guoshan has joined #openstack-keystone | 11:23 | |
*** dgonzalez has joined #openstack-keystone | 11:24 | |
*** jaosorior has joined #openstack-keystone | 11:38 | |
*** tobberydberg has joined #openstack-keystone | 11:44 | |
*** guoshan has quit IRC | 11:46 | |
*** nicolasbock has joined #openstack-keystone | 11:46 | |
*** GB21 has quit IRC | 11:50 | |
*** guoshan has joined #openstack-keystone | 11:59 | |
*** edmondsw has joined #openstack-keystone | 12:09 | |
*** openstackgerrit has joined #openstack-keystone | 12:10 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Use assertGreater(len(x), y) instead of assertTrue(len(x) > y) https://review.openstack.org/411679 | 12:10 |
stevemar | morgan: heyo | 12:22 |
morgan | stevemar: zzzzzzzzzzzz | 12:23 |
stevemar | morgan: you better be sleepin! | 12:23 |
stevemar | morning to the east coasters o/ | 12:24 |
stevemar | afternoon to the euros o/ | 12:24 |
morgan | stevemar: been packing | 12:24 |
stevemar | evening to the apac folks o/ | 12:24 |
morgan | moving today | 12:24 |
stevemar | morgan: good luck | 12:24 |
stevemar | morgan: driving up a uhaul? | 12:24 |
morgan | nope | 12:25 |
morgan | hired movers | 12:25 |
morgan | they're showing up in ~4hrs | 12:25 |
morgan | trying to sleep a little. | 12:25 |
morgan | but... a little stressed :PO | 12:25 |
stevemar | morgan: sleeping is definitely encouraged :) | 12:25 |
*** edmondsw has quit IRC | 12:30 | |
*** edmondsw has joined #openstack-keystone | 12:30 | |
*** ngupta has joined #openstack-keystone | 12:32 | |
*** dave-mccowan has joined #openstack-keystone | 12:33 | |
*** catintheroof has joined #openstack-keystone | 12:34 | |
*** dikonoor has joined #openstack-keystone | 12:34 | |
*** edmondsw has quit IRC | 12:35 | |
*** ngupta has quit IRC | 12:36 | |
*** links has quit IRC | 12:42 | |
*** edmondsw has joined #openstack-keystone | 12:43 | |
*** markvoelker has joined #openstack-keystone | 12:45 | |
*** dikonoor has quit IRC | 12:45 | |
*** edmondsw has quit IRC | 13:30 | |
*** edmondsw has joined #openstack-keystone | 13:31 | |
*** edmondsw has quit IRC | 13:35 | |
*** edmondsw has joined #openstack-keystone | 13:38 | |
*** amoralej is now known as amoralej|lunch | 13:47 | |
*** ngupta has joined #openstack-keystone | 13:55 | |
*** edmondsw has quit IRC | 13:59 | |
*** edmondsw has joined #openstack-keystone | 13:59 | |
*** chlong has quit IRC | 14:00 | |
*** guoshan has quit IRC | 14:01 | |
*** edmondsw has quit IRC | 14:04 | |
*** edmondsw has joined #openstack-keystone | 14:06 | |
*** dave-mccowan has quit IRC | 14:14 | |
*** edmondsw has quit IRC | 14:15 | |
*** edmondsw has joined #openstack-keystone | 14:15 | |
*** GB21 has joined #openstack-keystone | 14:16 | |
*** edmondsw has quit IRC | 14:19 | |
*** mrsoul has quit IRC | 14:22 | |
*** Dinesh_Bhor has quit IRC | 14:32 | |
rderose | rodrigods: around? | 14:35 |
*** amoralej|lunch is now known as amoralej | 14:36 | |
*** ngupta has quit IRC | 14:38 | |
*** edmondsw has joined #openstack-keystone | 14:39 | |
*** ngupta has joined #openstack-keystone | 14:39 | |
*** edmondsw has quit IRC | 14:42 | |
*** edmondsw has joined #openstack-keystone | 14:43 | |
stevemar | quiet day today :O | 14:45 |
rderose | tell me about it :) | 14:48 |
*** dave-mccowan has joined #openstack-keystone | 14:52 | |
rodrigods | rderose, yep | 14:57 |
rodrigods | i mean, i am now :) | 14:57 |
rderose | :) | 14:57 |
rderose | cool | 14:57 |
rderose | rodrigods: can you point me to what you want me to do on this one: https://review.openstack.org/#/c/399157/ | 14:57 |
rderose | rodrigods: also, can you push this one through: https://review.openstack.org/#/c/409946/ | 14:58 |
rderose | rodrigods: only made a change to the commit msg on that one | 14:58 |
rodrigods | rderose, the docs one is the thing about documenting the return code when trying to update the domain_id | 14:59 |
rderose | rodrigods: ah, okay | 14:59 |
rderose | rodrigods: thanks! | 15:00 |
rodrigods | np :) | 15:01 |
*** itisha has quit IRC | 15:02 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone: Add anonymous bind to get_connection method https://review.openstack.org/407561 | 15:02 |
rodrigods | stevemar, around? how far did you get when playing with devstack's ldap plugin? | 15:03 |
*** GB21 has quit IRC | 15:05 | |
*** Dave has quit IRC | 15:09 | |
*** Dave has joined #openstack-keystone | 15:12 | |
*** jaosorior has quit IRC | 15:15 | |
stevemar | rodrigods: 0 progress! | 15:15 |
*** edmondsw has quit IRC | 15:15 | |
*** edmondsw has joined #openstack-keystone | 15:16 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: Update docs to require domain_id when registering Identity Providers https://review.openstack.org/399157 | 15:16 |
stevemar | crinkle: o/ | 15:18 |
stevemar | crinkle: is your patch to fix the issue you pointed out in the one by kam? | 15:18 |
crinkle | stevemar: yes | 15:20 |
*** edmondsw has quit IRC | 15:21 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: WIP - Require domain_id when registering Identity Providers https://review.openstack.org/399684 | 15:21 |
openstackgerrit | Ron De Rose proposed openstack/keystone: Update docs to require domain_id when registering Identity Providers https://review.openstack.org/399157 | 15:21 |
*** chlong has joined #openstack-keystone | 15:21 | |
stevemar | crinkle: cool, i'll get eyes on it then | 15:21 |
crinkle | thanks stevemar | 15:22 |
stevemar | rderose: what happened to https://review.openstack.org/#/c/399684/ ? patch 28 had a bunch of stuff, patch 29 only has migrations? | 15:22 |
rderose | stevemar: what the @!#$!@#$%!#@! | 15:22 |
rderose | stevemar: I just rebased the doc patch and not sure what I did | 15:23 |
stevemar | rderose: want me to fix? | 15:23 |
rderose | stevemar: sure! | 15:23 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Require domain_id when registering Identity Providers https://review.openstack.org/399684 | 15:26 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: WIP - Set the domain for federated users https://review.openstack.org/408332 | 15:26 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Update docs to require domain_id when registering Identity Providers https://review.openstack.org/399157 | 15:26 |
rderose | stevemar: whew, thanks | 15:26 |
stevemar | rderose: np, happens | 15:26 |
rderose | :) | 15:26 |
*** dave-mccowan has quit IRC | 15:27 | |
*** tobberyd_ has joined #openstack-keystone | 15:27 | |
*** tobberydberg has quit IRC | 15:31 | |
*** tobberyd_ has quit IRC | 15:32 | |
lbragstad | stevemar o/ | 15:33 |
stevemar | lbragstad: howdy | 15:33 |
lbragstad | stevemar you rang earlier? | 15:34 |
stevemar | rderose: delete your old branches and download the new ones with `git review -d <patch no>` | 15:34 |
stevemar | lbragstad: i did? | 15:34 |
stevemar | pffft | 15:34 |
stevemar | no idea why | 15:34 |
lbragstad | stevemar hm - ok cool | 15:34 |
lbragstad | stevemar that was easy | 15:34 |
*** GB21 has joined #openstack-keystone | 15:34 | |
lbragstad | stevemar i'm trying to PTO today - but i didn't make it very far | 15:34 |
stevemar | lbragstad: just close the laptop and walk away | 15:35 |
rderose | stevemar: okay | 15:35 |
stevemar | ocata-2 is closed up and released! https://launchpad.net/keystone/+milestone/ocata-2 and https://releases.openstack.org/ocata/#ocata-keystone | 15:35 |
*** edmondsw has joined #openstack-keystone | 15:37 | |
*** dave-mccowan has joined #openstack-keystone | 15:40 | |
rderose | stevemar: ++ | 15:44 |
openstackgerrit | Merged openstack/keystone: Use assertGreater(len(x), y) instead of assertTrue(len(x) > y) https://review.openstack.org/411679 | 15:44 |
*** tqtran has joined #openstack-keystone | 15:45 | |
stevemar | rderose: reviewing your patch now | 15:46 |
stevemar | crinkle: you're up next | 15:46 |
rderose | stevemar: sweet!! | 15:46 |
stevemar | then spilla's and gagehugo's | 15:46 |
stevemar | rderose: shouldn't the stuff in the contract happen in migrate? | 15:48 |
rderose | stevemar: yes, if we want to do triggers | 15:48 |
rderose | stevemar: otherwise, it has to go in contract because that is when all of the new code has been deployed | 15:48 |
rderose | stevemar: because you are not likely to have a lot of idps, I think it is okay to do in contract as it's not going to cause any kind locking issues | 15:49 |
*** tqtran has quit IRC | 15:50 | |
stevemar | rderose: we could do it in data_migration without triggers, but in case someone creates an idp while some nodes are upgraded ... then it'll fail cause no domain id? | 15:52 |
stevemar | are not upgraded* | 15:52 |
stevemar | so either we fail during migrate at the code level, or fail at contract due to race condition | 15:52 |
rderose | stevemar: yes, during date migration, you have old code and new code, so it's possible for someone to create an idp without a domain (old code) | 15:53 |
stevemar | i think the odds of someone creating an IdP during an upgrade are super slim, since it's normally the same admin that upgrades and creates and idp | 15:53 |
stevemar | an* | 15:53 |
rderose | stevemar: I don't think it will fail in contract phase because only new code and race condition would be really, really slim | 15:54 |
stevemar | i'd prefer to have this in the data_migration since we've moving data around, and we have a bug that will try to restrict certain things from happening in each phase... see https://bugs.launchpad.net/keystone/+bug/1615024 | 15:54 |
openstack | Launchpad bug 1615024 in OpenStack Identity (keystone) "Forbid invalid operations in expand, migrate, and contract repositories" [Medium,In progress] - Assigned to Henry Nash (henry-nash) | 15:54 |
rderose | stevemar: we'd only be updating a handful of records, so it would happen very quickly | 15:54 |
stevemar | we could of course make an exception for this migration, but i'd prefer not to :) | 15:55 |
stevemar | dolphm: ^ | 15:55 |
dolphm | i'm on vacation | 15:56 |
rderose | stevemar: but we do allow exceptions: https://github.com/openstack/keystone/blob/master/keystone/tests/unit/test_sql_banned_operations.py#L271 | 15:56 |
dolphm | rderose: data migrations absolutely cannot happen in any phase other than migrate, and you need triggers, period. | 15:57 |
dolphm | any other way, the migration process is not safe. | 15:57 |
dolphm | rderose: and no, we don't allow exceptions | 15:57 |
rderose | stevemar: again, the problem with doing it in the data migration is without triggers, I can't guarantee that all of the data is migrated | 15:57 |
rderose | stevemar dolphm: I'll have to think through the complexity of doing this with triggers. The likelihood that it will cause is issue is so small that it doesn't feel justified. Let me give it some thought though. | 15:59 |
dolphm | as soon as we allow an exception, we've effectively dropped support for zero downtime migrations | 16:01 |
*** Guest31304 has quit IRC | 16:02 | |
SamYaple | dolphm: make an exception! then youll match the rest of openstack | 16:03 |
* SamYaple grumbles | 16:03 | |
dolphm | SamYaple: ha | 16:07 |
*** udesale has quit IRC | 16:16 | |
*** ravelar has joined #openstack-keystone | 16:23 | |
*** rcernin has quit IRC | 16:23 | |
*** pcaruana has quit IRC | 16:25 | |
mgagne | I'm having an issue with token validation. I'm getting "ValueError: too many values to unpack" in Keystone. traceback and logs here: https://gist.github.com/mgagne/019df98f36d34b928215f1543d738596 | 16:28 |
mgagne | can anyone help me debug the problem? | 16:28 |
*** chlong has quit IRC | 16:29 | |
*** adrian_otto has joined #openstack-keystone | 16:32 | |
stevemar | mgagne: ah | 16:37 |
stevemar | mgagne: running liberty? | 16:41 |
mgagne | Mitaka (for Keystone) | 16:41 |
stevemar | mgagne: the latest mitaka? | 16:42 |
mgagne | so I see that the service validating the token uses auth-version v2.0, the service (Ironic) could be still running liberty, I tried to update the keystonemiddleware, tried switching to 35357 and v3 | 16:42 |
stevemar | we backported a fix for that i thought | 16:42 |
mgagne | stevemar: yes, latest from like Monday | 16:42 |
stevemar | mgagne: ah https://github.com/openstack/keystone/commit/f1d9c54ef07c61cb80def5779802cc4daf45f4cb | 16:42 |
stevemar | well damn | 16:42 |
mgagne | running 005a1a9a9c16b5d33dc756ef159b884242763616 | 16:42 |
*** ravelar has quit IRC | 16:43 | |
mgagne | and I also tried disabling cache (in keystone) to make sure it isn't the source of the problem | 16:43 |
mgagne | could cache still be used even with enabled = False ? | 16:43 |
stevemar | mgagne: ah one more things... | 16:43 |
stevemar | https://bugs.launchpad.net/keystone/+bug/1600394 | 16:43 |
openstack | Launchpad bug 1600394 in OpenStack Identity (keystone) "memcache raising "too many values to unpack"" [Medium,Fix released] - Assigned to Brant Knudson (blk-u) | 16:43 |
stevemar | mgagne: Another way to fix this is to ensure that keystone is not forked after it's initialized. This can be done in uwsgi by setting lazy-apps=true (see https://review.openstack.org/#/c/357539/10/templates/keystone-uwsgi.ini.j2 ) | 16:44 |
*** browne has joined #openstack-keystone | 16:44 | |
mgagne | I'm using mod_wsgi and afaik, cache has been disabled to remove this variable from the equation | 16:44 |
mgagne | also the unpack exception is not in the memcache lib but in the fernet formatter disassemble function | 16:45 |
mgagne | I tried to dump the payload and found the unpacked value isn't a tuple/list as expected but a single string | 16:45 |
andrewbogott | I wrote to openstack@ about this already but… can I get advice about security concerns with opening up the keystone admin API? I want my users to be able to enumerate projects (which requires the admin endpoint) but I don't want to accidentally give them rights outside of those set up with roles and policy.json. | 16:47 |
stevemar | mgagne: you have to file a new bug then | 16:48 |
stevemar | mgagne: if it's not one of those two fixes then maybe we never fixed it correctly :( | 16:48 |
stevemar | andrewbogott: i've been meaning to reply to that! | 16:49 |
andrewbogott | stevemar: I can be patient :) | 16:49 |
stevemar | andrewbogott: we can chat | 16:49 |
stevemar | andrewbogott: sounds like you're using v2? | 16:49 |
andrewbogott | no, v3 | 16:49 |
andrewbogott | at least, as far as I know | 16:49 |
andrewbogott | I have some older services that are still using v2 | 16:50 |
stevemar | andrewbogott: yeah, if you modified the policy file, the only way that works is with v3 | 16:50 |
stevemar | andrewbogott: but in v3 we don't have a concept of 'admin api' or 'public api', just send everything to :5000 | 16:51 |
andrewbogott | oh? | 16:51 |
andrewbogott | then I wonder why the client is hitting the admin port at all? | 16:51 |
stevemar | it was only in v2 that 'admin' requests should be sent to :35357, and 'public' requests go to :5000 | 16:51 |
stevemar | if a v3 request comes in at 35357 it's treated the same as if it were on 5000, IIRC... | 16:52 |
andrewbogott | This must mean that the openstack cmdline client I'm testing with explicitly loads the v2 client, huh? | 16:52 |
andrewbogott | Anyway, that implies that there's no real security difference between opening 5000 and 35357, correct? | 16:53 |
*** chlong has joined #openstack-keystone | 16:53 | |
stevemar | andrewbogott: for v3, nope | 16:53 |
stevemar | andrewbogott: yeah, i was going to say it's probably the client either loading v2 or sending requests to the admin "endpoint" by default | 16:54 |
andrewbogott | well… you say 'for v3' but when it comes to security I can't exactly control which api version a potential attacker is going to choose :) | 16:54 |
stevemar | :) | 16:56 |
stevemar | andrewbogott: i don't think we need to open up 35357 | 16:56 |
stevemar | andrewbogott: check your client tooling to make sure it's using v3 and you should be OK | 16:56 |
andrewbogott | My client tooling is… whatever openstack client package comes standard with my distro | 16:57 |
andrewbogott | but maybe I can import a newer package, will check | 16:57 |
* andrewbogott digs in client code to figure out why it's redirecting | 17:03 | |
*** ngupta has quit IRC | 17:03 | |
*** rcernin has joined #openstack-keystone | 17:04 | |
openstackgerrit | Merged openstack/keystone: replace assertTrue with assertIs. https://review.openstack.org/411689 | 17:04 |
openstackgerrit | Merged openstack/keystone: Make user to nonlocal_user a 1:1 relationship https://review.openstack.org/409946 | 17:05 |
*** adrian_otto has quit IRC | 17:08 | |
stevemar | andrewbogott: you can do a --debug with OSC | 17:12 |
stevemar | rderose: samueldmq rodrigods please respond to https://review.openstack.org/#/c/409946/8 | 17:13 |
stevemar | i have no idea why we're creating things in the contract repo all of a sudden | 17:13 |
stevemar | we have http://docs.openstack.org/developer/keystone/devref/development_best_practices.html#database-migrations for a reason | 17:13 |
rderose | stevemar: just posted a comment | 17:16 |
stevemar | rderose: noted, but it would have been nice to confirm that before merging a migration | 17:17 |
stevemar | i appreciate the tempo and speed of reviews but i don't want to sacrifice quality | 17:17 |
rderose | stevemar: confirming? I pursued merging because I thought it was a contraction | 17:17 |
rderose | stevemar: I don't think quality was sacrificed, but... understand | 17:18 |
stevemar | rderose: in the dev docs, indicies are created in the expand | 17:18 |
*** ravelar has joined #openstack-keystone | 17:18 | |
rderose | stevemar: not an index, but a uniqueconstraint | 17:19 |
stevemar | yes i'm aware they are different | 17:19 |
rderose | :) | 17:19 |
stevemar | rderose: propose a patch to update the dev docs then | 17:19 |
stevemar | if something is missing | 17:20 |
rderose | stevemar: will do | 17:20 |
stevemar | rderose: i'm touchy about migrations | 17:20 |
stevemar | they're the one thing we can't revert | 17:20 |
*** tqtran has joined #openstack-keystone | 17:20 | |
rderose | stevemar: yeah, true | 17:20 |
rderose | stevemar: understand | 17:20 |
stevemar | i'd rather we 2x, 3x check those <rant over> | 17:21 |
rderose | stevemar: understand your concern, but that migration is 2 LOC and it wasn't rushed <ron's rant over> | 17:27 |
*** lamt has joined #openstack-keystone | 17:34 | |
*** ayoung has quit IRC | 17:35 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: Require domain_id when registering Identity Providers https://review.openstack.org/399684 | 17:36 |
andrewbogott | stevemar: even the very latest git version of python-keystoneclient has default interface='admin' for HTTPClient | 17:37 |
andrewbogott | so that makes me think that I'm going to be hitting this issue all over the place | 17:37 |
rodrigods | stevemar, rderose migrations are tricky, but i think they were done correctly | 17:37 |
rodrigods | stevemar, next time will wait for you to take a look before approving | 17:38 |
rodrigods | i mean... for changes like that | 17:38 |
*** adrian_otto has joined #openstack-keystone | 17:38 | |
*** Zer0Byte__ has joined #openstack-keystone | 17:44 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: Update docs to require domain_id when registering Identity Providers https://review.openstack.org/399157 | 17:50 |
*** ngupta has joined #openstack-keystone | 17:53 | |
*** lamt has quit IRC | 18:00 | |
*** asettle has quit IRC | 18:01 | |
*** asettle has joined #openstack-keystone | 18:01 | |
*** zhugaoxiao has quit IRC | 18:02 | |
*** zhugaoxiao has joined #openstack-keystone | 18:03 | |
*** asettle has quit IRC | 18:06 | |
*** ngupta has quit IRC | 18:11 | |
*** ngupta has joined #openstack-keystone | 18:11 | |
*** ngupta has quit IRC | 18:13 | |
*** ngupta has joined #openstack-keystone | 18:13 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: Update docs to require domain_id when registering Identity Providers https://review.openstack.org/399157 | 18:14 |
stevemar | andrewbogott: using using OSC there is an option you can specify to use the public one | 18:14 |
stevemar | andrewbogott: we chagned the name, it's either interface or endpoint-type | 18:14 |
stevemar | check the help | 18:14 |
andrewbogott | stevemar: the httpclient initializer has args like this: service_type='identity', endpoint_type='admin', | 18:16 |
stevemar | andrewbogott: endpoint_type is the one you want | 18:16 |
andrewbogott | um, sorry, mispasted, one second... | 18:16 |
andrewbogott | ok, digging more... | 18:17 |
stevemar | andrewbogott: but if you manage to specify that at the client level, your problem should be solved | 18:17 |
stevemar | may involve some diggin' | 18:17 |
*** GB21 has quit IRC | 18:18 | |
andrewbogott | stevemar: but there's no scenario where that will work with the openstack commandline client, right? | 18:18 |
openstackgerrit | Ron De Rose proposed openstack/keystone: WIP - Set the domain for federated users https://review.openstack.org/408332 | 18:19 |
andrewbogott | stevemar: Is the subtext here that with v2 the admin endpoint is indeed dangerous to expose? | 18:19 |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Force users to immediately change their password upon first use https://review.openstack.org/403916 | 18:27 |
*** ravelar has quit IRC | 18:28 | |
*** adrian_otto has quit IRC | 18:30 | |
*** asettle has joined #openstack-keystone | 18:31 | |
*** asettle has quit IRC | 18:32 | |
*** ravelar has joined #openstack-keystone | 18:36 | |
stevemar | andrewbogott: with OSC you should be able to set it with ``--os-interface public`` | 18:42 |
stevemar | should be able to just append that to the command | 18:42 |
stevemar | sorry, i thought i said that more clearly earlier :) | 18:43 |
andrewbogott | stevemar: unrecognized arguments: --os-interface public | 18:44 |
andrewbogott | but maybe I'm back to needing a newer version | 18:44 |
*** haplo37_ has quit IRC | 18:44 | |
andrewbogott | yeah, ok, here's a version that works | 18:45 |
andrewbogott | so this is promising, thanks | 18:45 |
stevemar | andrewbogott: np, if you end up figuring it out please let me know, i'll reply to the ML in case someone else has the same question | 18:45 |
andrewbogott | 'k | 18:45 |
openstackgerrit | Ron De Rose proposed openstack/keystone: Update docs to require domain_id when registering Identity Providers https://review.openstack.org/399157 | 18:48 |
*** itisha has joined #openstack-keystone | 18:52 | |
*** ravelar has quit IRC | 18:53 | |
*** haplo37_ has joined #openstack-keystone | 18:54 | |
andrewbogott | well… now I'm trapped in dependency hell :( upgrading that package is going to take all day | 19:05 |
openstackgerrit | Ron De Rose proposed openstack/keystone: Update docs to require domain_id when registering Identity Providers https://review.openstack.org/399157 | 19:06 |
stevemar | andrewbogott: spin up a virtualenv | 19:07 |
andrewbogott | we're a .deb only shop. | 19:07 |
openstackgerrit | Ron De Rose proposed openstack/keystone: Update docs to require domain_id when registering Identity Providers https://review.openstack.org/399157 | 19:08 |
stevemar | andrewbogott: figured a quick virtualenv to verify it's correct would do the trick :) | 19:09 |
andrewbogott | true | 19:09 |
andrewbogott | I guess I can verify that this works on trusty before diving in to getting it installed on a jessie box | 19:10 |
stevemar | virtualenv test_interface; source test_interface/bin/activate; pip install --upgrade python-openstackclient; openstack blahhh; deactive; rm -rf test_interface | 19:10 |
stevemar | yeah, i hate it when an operator has to upgrade client libs just to validate something | 19:10 |
stevemar | it's silly | 19:10 |
*** phalmos has joined #openstack-keystone | 19:11 | |
openstackgerrit | Merged openstack/keystone: Replace logging with oslo_log. https://review.openstack.org/411600 | 19:15 |
stevemar | gagehugo: o/ | 19:17 |
andrewbogott | stevemar: with 1.7.0 it works! So once I get the dozen or so packages I need for jessie and add OS_INTERFACE=public I'll be in business. | 19:21 |
andrewbogott | Want me to follow up on the ml or do you have more to add there? | 19:21 |
stevemar | andrewbogott: you can follow up, and i'll fill in any holes (if any) | 19:22 |
andrewbogott | ok. Thanks! | 19:22 |
stevemar | andrewbogott: glad to hear it worked! | 19:22 |
stevemar | andrewbogott: btw, openstack CLI is now at 3.5.0 so theres A LOT of new stuff | 19:22 |
stevemar | andrewbogott: all sorts of networking, volume and compute commands | 19:23 |
andrewbogott | yeah, the packagers should maybe start including latest-release versions of the client as patches to the older version archives | 19:23 |
*** phalmos has quit IRC | 19:25 | |
stevemar | rderose: did you see SW yet? aren't you the big fan? | 19:25 |
stevemar | andrewbogott: yeah, unfortunately we release a lot more often than the distros :( | 19:26 |
stevemar | ah well | 19:26 |
rderose | stevemar: huge fan | 19:27 |
andrewbogott | stevemar: in theory canonical and mirantis maintain per-version release repos. Those only include e.g. the liberty client with the liberty packages though, even though the n or o clients will work fine with the older services. | 19:27 |
rderose | stevemar: tomorrow :) | 19:27 |
stevemar | andrewbogott: i think the latest release of OSC will work with a juno (or maybe kilo) cloud :) | 19:28 |
stevemar | rderose: it's getting great reviews, i have to avoid social media sites for the next few days | 19:29 |
rderose | stevemar: yeah, I'm excited | 19:30 |
rderose | stevemar: i turned off social media weeks ago :) | 19:30 |
*** asettle has joined #openstack-keystone | 19:33 | |
*** asettle has quit IRC | 19:36 | |
*** asettle has joined #openstack-keystone | 19:36 | |
*** lamt has joined #openstack-keystone | 19:37 | |
*** asettle has quit IRC | 19:39 | |
*** mbeierl has joined #openstack-keystone | 19:41 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Add reason to notifications for PCI-DSS https://review.openstack.org/396752 | 19:42 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Add reason to notifications for PCI-DSS https://review.openstack.org/396752 | 19:43 |
mbeierl | I am having a hard time getting a heat endpoint reliably across OpenStack distros. Here is my latest code: http://pastebin.com/dvpeLkht, but I am getting "The service catalog is empty" when looking for the orchestration endpoint. And, yes it does exist in keystone service-list | grep orchestration | 19:45 |
mbeierl | Is there any guides on getting service endpoints that can handle both v2 and v3 auth? | 19:46 |
*** amoralej is now known as amoralej|off | 19:48 | |
*** lamt has quit IRC | 19:48 | |
*** lamt has joined #openstack-keystone | 19:50 | |
*** navid_ has joined #openstack-keystone | 19:52 | |
navid_ | hi have a question, the project id is unique throughout the keystone or domain | 19:53 |
*** ngupta has quit IRC | 19:54 | |
*** ngupta has joined #openstack-keystone | 19:54 | |
*** clenimar has quit IRC | 19:55 | |
*** ravelar has joined #openstack-keystone | 19:56 | |
*** ngupta has quit IRC | 19:59 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Add reason to notifications for PCI-DSS https://review.openstack.org/396752 | 20:00 |
stevemar | navid_: throughout keystone | 20:01 |
navid_ | thanks @stevemar | 20:02 |
*** navid_ has quit IRC | 20:07 | |
*** ravelar has quit IRC | 20:14 | |
mgagne | I found the issue with unpack value. I restarted the nova-compute service which was poking ironic-api which made token validation request. | 20:18 |
mgagne | only thing I found is %3D (=) appended to the token id in the previous request. now there is none. | 20:21 |
*** ayoung has joined #openstack-keystone | 20:29 | |
*** ChanServ sets mode: +v ayoung | 20:29 | |
*** ravelar has joined #openstack-keystone | 20:33 | |
*** chlong has quit IRC | 20:48 | |
*** ravelar has quit IRC | 20:50 | |
openstackgerrit | Sami Makki proposed openstack/oslo.policy: Closes-Bug #1650599 https://review.openstack.org/411986 | 20:53 |
openstack | bug 1650599 in oslo.policy "Dead code in oslo_policy/shell.py" [Undecided,New] https://launchpad.net/bugs/1650599 - Assigned to Sami Makki (smakki) | 20:53 |
*** asettle has joined #openstack-keystone | 20:59 | |
*** asettle has quit IRC | 21:00 | |
*** itisha has quit IRC | 21:02 | |
*** catintheroof has quit IRC | 21:10 | |
gagehugo | stevemar: I'm awake now, thanks for fixing the releasenotes | 21:10 |
*** catintheroof has joined #openstack-keystone | 21:11 | |
*** catintheroof has quit IRC | 21:15 | |
*** lamt has quit IRC | 21:16 | |
*** lamt has joined #openstack-keystone | 21:20 | |
*** ngupta has joined #openstack-keystone | 21:25 | |
*** iurygregory has quit IRC | 21:27 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone: Add anonymous bind to get_connection method https://review.openstack.org/407561 | 21:28 |
*** adrian_otto has joined #openstack-keystone | 21:42 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: Update docs to require domain_id when registering Identity Providers https://review.openstack.org/399157 | 21:43 |
openstackgerrit | Ron De Rose proposed openstack/keystone: Update docs to require domain_id when registering Identity Providers https://review.openstack.org/399157 | 21:45 |
stevemar | gagehugo: awake eh | 21:45 |
stevemar | gagehugo: :) | 21:45 |
stevemar | gagehugo: gonna try out your notification stuff over the weekend | 21:46 |
gagehugo | stevemar: slowly recovering from being sick :( | 21:49 |
*** adrian_otto has quit IRC | 21:49 | |
stevemar | gagehugo: oh noes, feel better | 21:49 |
gagehugo | stevemar: thanks | 21:50 |
gagehugo | stevemar: lemme know if you notice any issues with testing | 21:50 |
*** kiran-r has joined #openstack-keystone | 21:58 | |
*** edmondsw has quit IRC | 22:07 | |
*** kiran-r has quit IRC | 22:07 | |
*** edmondsw has joined #openstack-keystone | 22:07 | |
stevemar | gagehugo: wilco | 22:08 |
*** adrian_otto has joined #openstack-keystone | 22:12 | |
*** edmondsw has quit IRC | 22:12 | |
*** dave-mccowan has quit IRC | 22:25 | |
*** adrian_otto has quit IRC | 22:31 | |
*** dave-mccowan has joined #openstack-keystone | 22:51 | |
*** dave-mccowan has quit IRC | 22:56 | |
*** chris_hultin|AWA is now known as chris_hultin | 22:56 | |
*** adrian_otto has joined #openstack-keystone | 23:12 | |
*** ngupta has quit IRC | 23:27 | |
*** ngupta has joined #openstack-keystone | 23:28 | |
*** chris_hultin is now known as chris_hultin|AWA | 23:29 | |
*** ngupta has quit IRC | 23:30 | |
*** ngupta has joined #openstack-keystone | 23:30 | |
*** lamt has quit IRC | 23:37 | |
*** kiran-r has joined #openstack-keystone | 23:54 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!