*** erlon has quit IRC | 00:05 | |
*** lamt has joined #openstack-keystone | 00:11 | |
*** lamt has quit IRC | 00:12 | |
*** ngupta has joined #openstack-keystone | 00:33 | |
*** hoangcx has joined #openstack-keystone | 00:38 | |
*** tovin07 has joined #openstack-keystone | 00:39 | |
Adobeman | is there a... reference of v2 to v3 commands? | 00:44 |
---|---|---|
Adobeman | like translator | 00:44 |
*** esp has quit IRC | 00:47 | |
*** martinlopes has joined #openstack-keystone | 00:47 | |
*** ayoung has quit IRC | 00:51 | |
*** ngupta has quit IRC | 01:03 | |
Adobeman | ok... so I'm following keithtenzer's blog.. I am tempting to translate his v2 command into v3... already getting stuck with first one | 01:05 |
Adobeman | keystone user-role-add --user-id ospadmin --role admin --tenant admin <should become> openstack role add --project admin --user ospadmin admin | 01:06 |
Adobeman | now it just tell me no ospadmin user exist | 01:07 |
*** liujiong has joined #openstack-keystone | 01:08 | |
*** aasthad has quit IRC | 01:12 | |
*** catintheroof has quit IRC | 01:13 | |
*** esp has joined #openstack-keystone | 01:16 | |
*** thorst_afk has joined #openstack-keystone | 01:17 | |
*** jamielennox is now known as jamielennox|away | 01:18 | |
*** guoshan has joined #openstack-keystone | 01:19 | |
*** martinlopes has quit IRC | 01:20 | |
*** jamielennox|away is now known as jamielennox | 01:25 | |
*** dave-mccowan has joined #openstack-keystone | 01:27 | |
*** liuhaijie has joined #openstack-keystone | 01:35 | |
lbragstad | Adobeman as far as a reference that translates keystone client CLI to openstack client? I don't think there is one | 01:36 |
lbragstad | cc stevemar | 01:36 |
lbragstad | or jamielennox ? | 01:36 |
*** liuhaijie has quit IRC | 01:38 | |
*** liuhaijie has joined #openstack-keystone | 01:39 | |
*** thorst_afk has quit IRC | 01:41 | |
stevemar | Adobeman: hmm, that should work | 01:44 |
stevemar | Adobeman: does "openstack user show ospadmin" work? | 01:44 |
*** esp has quit IRC | 01:46 | |
*** liuhaijie has quit IRC | 01:47 | |
*** martinlopes has joined #openstack-keystone | 01:51 | |
*** d-bark has joined #openstack-keystone | 01:53 | |
*** thorst_afk has joined #openstack-keystone | 01:56 | |
*** d-bark has quit IRC | 01:57 | |
*** d-bark has joined #openstack-keystone | 01:58 | |
*** slunkad has quit IRC | 02:08 | |
*** esp has joined #openstack-keystone | 02:18 | |
jamielennox | i mean if you're doing something cross domain you might be missing some flags, but otherwise it looks ok | 02:20 |
*** tqtran has quit IRC | 02:24 | |
Adobeman | stevemar: yes, it worked.. | 02:24 |
Adobeman | what doesnt work is.. | 02:25 |
Adobeman | kind of wish ayoung here.. | 02:25 |
Adobeman | free ipa is up and functional, as ldap server at least.. | 02:25 |
Adobeman | just went through keith's blog on getting keystone to work with freeipa.. | 02:26 |
Adobeman | I believe I put in all the v3 command properly, "translated" from v2.. | 02:26 |
Adobeman | ospadmin/ospuser..etc all created | 02:26 |
Adobeman | it still throwing me a fit | 02:26 |
Adobeman | trying to login as ospadmin into openstack, getting "You are not authorized for any projects or domains." | 02:27 |
Adobeman | ospuser I meant | 02:28 |
Adobeman | odd, keystone said authorization failed | 02:34 |
Adobeman | ipa said it returned something... | 02:34 |
Adobeman | ok, not sure I understand ipa's log | 02:36 |
*** ravelar has quit IRC | 02:36 | |
*** ngupta has joined #openstack-keystone | 02:43 | |
*** thorst_afk has quit IRC | 02:50 | |
*** slunkad has joined #openstack-keystone | 03:00 | |
*** esp has quit IRC | 03:00 | |
*** thorst_afk has joined #openstack-keystone | 03:03 | |
*** thorst_afk has quit IRC | 03:04 | |
openstackgerrit | Anh Tran proposed openstack/keystonemiddleware master: Remove unused logging import https://review.openstack.org/435203 | 03:04 |
*** deepbook5broo has joined #openstack-keystone | 03:34 | |
*** deepbook5broo has left #openstack-keystone | 03:34 | |
*** thorst_afk has joined #openstack-keystone | 03:35 | |
*** thorst_afk has quit IRC | 03:35 | |
*** dave-mccowan has quit IRC | 03:47 | |
*** zhugaoxiao has quit IRC | 03:49 | |
*** david-lyle has quit IRC | 03:49 | |
*** zhugaoxiao has joined #openstack-keystone | 03:50 | |
*** david-lyle has joined #openstack-keystone | 03:50 | |
morgan | Adobeman: you need to grant a role for that user on a project. | 03:51 |
morgan | Adobeman: in keystone, sounds like that is all that is missing | 03:51 |
morgan | this is a keystone-specific thing now vs anything wrong with IPA. | 03:51 |
*** adrian_otto has joined #openstack-keystone | 03:57 | |
*** links has joined #openstack-keystone | 04:03 | |
*** adu has joined #openstack-keystone | 04:04 | |
*** adu has left #openstack-keystone | 04:04 | |
*** guoshan has quit IRC | 04:06 | |
*** prashkre has joined #openstack-keystone | 04:13 | |
*** adrian_otto has quit IRC | 04:14 | |
*** nicolasbock has quit IRC | 04:17 | |
*** adrian_otto has joined #openstack-keystone | 04:34 | |
*** v1k0d3n has quit IRC | 04:40 | |
*** adriant has quit IRC | 04:48 | |
*** ngupta has quit IRC | 04:51 | |
*** tqtran has joined #openstack-keystone | 04:51 | |
*** ngupta has joined #openstack-keystone | 04:52 | |
*** v1k0d3n has joined #openstack-keystone | 04:52 | |
*** adrian_otto has quit IRC | 04:54 | |
*** tqtran has quit IRC | 04:55 | |
*** ngupta has quit IRC | 04:56 | |
*** thorst_afk has joined #openstack-keystone | 04:57 | |
*** thorst_afk has quit IRC | 05:02 | |
*** slunkad has quit IRC | 05:02 | |
*** v1k0d3n has quit IRC | 05:05 | |
*** guoshan has joined #openstack-keystone | 05:06 | |
*** slunkad has joined #openstack-keystone | 05:07 | |
*** rcernin has joined #openstack-keystone | 05:08 | |
*** guoshan has quit IRC | 05:10 | |
*** esp has joined #openstack-keystone | 05:17 | |
*** dikonoor has joined #openstack-keystone | 05:17 | |
*** maestropandy has joined #openstack-keystone | 05:17 | |
*** v1k0d3n has joined #openstack-keystone | 05:18 | |
*** tqtran has joined #openstack-keystone | 05:53 | |
*** tqtran has quit IRC | 05:58 | |
*** esp has quit IRC | 06:06 | |
*** guoshan has joined #openstack-keystone | 06:07 | |
*** guoshan has quit IRC | 06:12 | |
*** guoshan has joined #openstack-keystone | 06:19 | |
*** martinlopes has quit IRC | 06:20 | |
*** rcernin has quit IRC | 06:21 | |
*** jerrygb has joined #openstack-keystone | 06:41 | |
*** richm has quit IRC | 06:42 | |
*** jerrygb has quit IRC | 06:46 | |
*** hoangcx_ has joined #openstack-keystone | 06:57 | |
*** thorst_afk has joined #openstack-keystone | 06:59 | |
*** hoangcx has quit IRC | 06:59 | |
*** jerrygb has joined #openstack-keystone | 07:00 | |
*** rcernin has joined #openstack-keystone | 07:01 | |
*** thorst_afk has quit IRC | 07:03 | |
*** jerrygb has quit IRC | 07:05 | |
*** d-bark has quit IRC | 07:08 | |
*** tesseract has joined #openstack-keystone | 07:11 | |
*** maestropandy has quit IRC | 07:45 | |
*** tqtran has joined #openstack-keystone | 07:55 | |
*** lamt has joined #openstack-keystone | 07:55 | |
*** hoangcx has joined #openstack-keystone | 07:59 | |
*** tqtran has quit IRC | 07:59 | |
*** hoangcx_ has quit IRC | 08:00 | |
*** prashkre_ has joined #openstack-keystone | 08:04 | |
*** prashkre has quit IRC | 08:04 | |
*** lamt has quit IRC | 08:21 | |
*** pcaruana has joined #openstack-keystone | 08:22 | |
*** prashkre has joined #openstack-keystone | 08:47 | |
*** prashkre_ has quit IRC | 08:50 | |
*** pramodrj07 has joined #openstack-keystone | 08:58 | |
*** thorst_afk has joined #openstack-keystone | 08:59 | |
*** zzzeek has quit IRC | 09:00 | |
*** zzzeek has joined #openstack-keystone | 09:00 | |
*** MasterOfBugs has quit IRC | 09:01 | |
*** thorst_afk has quit IRC | 09:04 | |
*** prashkre_ has joined #openstack-keystone | 09:13 | |
*** prashkre has quit IRC | 09:15 | |
*** prashkre__ has joined #openstack-keystone | 09:18 | |
*** prashkre_ has quit IRC | 09:22 | |
*** tovin07 has quit IRC | 09:26 | |
*** jaosorior has joined #openstack-keystone | 09:27 | |
*** maestropandy has joined #openstack-keystone | 09:30 | |
*** maestropandy has left #openstack-keystone | 09:30 | |
*** slunkad has quit IRC | 09:30 | |
*** slunkad has joined #openstack-keystone | 09:35 | |
*** guoshan has quit IRC | 09:53 | |
*** edmondsw has joined #openstack-keystone | 09:54 | |
*** tqtran has joined #openstack-keystone | 09:56 | |
*** edmondsw has quit IRC | 09:58 | |
*** tqtran has quit IRC | 10:00 | |
*** hoangcx has quit IRC | 10:02 | |
*** haplo37_ has quit IRC | 10:03 | |
*** haplo37_ has joined #openstack-keystone | 10:03 | |
*** prashkre_ has joined #openstack-keystone | 10:03 | |
*** prashkre__ has quit IRC | 10:05 | |
*** liujiong has quit IRC | 10:15 | |
*** jaosorior has quit IRC | 10:29 | |
*** jaosorior has joined #openstack-keystone | 10:30 | |
*** jerrygb has joined #openstack-keystone | 10:46 | |
*** jerrygb has quit IRC | 10:50 | |
*** jerrygb has joined #openstack-keystone | 10:51 | |
*** jaosorior has quit IRC | 10:52 | |
*** jaosorior has joined #openstack-keystone | 10:53 | |
*** jerrygb_ has joined #openstack-keystone | 10:54 | |
*** jerrygb has quit IRC | 10:55 | |
*** thorst_afk has joined #openstack-keystone | 11:01 | |
*** prashkre_ has quit IRC | 11:01 | |
*** thorst_afk has quit IRC | 11:05 | |
*** richm has joined #openstack-keystone | 11:11 | |
*** nicolasbock has joined #openstack-keystone | 11:19 | |
*** ayoung has joined #openstack-keystone | 11:28 | |
*** ChanServ sets mode: +v ayoung | 11:28 | |
*** jerrygb_ has quit IRC | 12:10 | |
*** dave-mccowan has joined #openstack-keystone | 12:14 | |
*** jaosorior has quit IRC | 12:16 | |
*** catintheroof has joined #openstack-keystone | 12:23 | |
*** jerrygb has joined #openstack-keystone | 12:29 | |
*** jaosorior has joined #openstack-keystone | 12:30 | |
*** raildo has quit IRC | 12:40 | |
*** raildo has joined #openstack-keystone | 12:41 | |
*** thorst_afk has joined #openstack-keystone | 12:43 | |
*** jerrygb_ has joined #openstack-keystone | 12:45 | |
robcresswell | Whats the deployment % between v2 and v3 nowadays? Is v3-only going to happen anytime soon? | 12:45 |
*** jerrygb has quit IRC | 12:46 | |
*** erlon has joined #openstack-keystone | 12:51 | |
*** dikonoor has quit IRC | 12:55 | |
*** dikonoor has joined #openstack-keystone | 12:55 | |
*** jerrygb_ has quit IRC | 13:02 | |
*** jerrygb has joined #openstack-keystone | 13:02 | |
*** edmondsw has joined #openstack-keystone | 13:07 | |
*** Dinesh_Bhor has quit IRC | 13:14 | |
*** links has quit IRC | 13:36 | |
*** spilla has joined #openstack-keystone | 13:45 | |
*** wllabs has quit IRC | 13:46 | |
*** jaosorior has quit IRC | 13:50 | |
*** jaosorior has joined #openstack-keystone | 13:51 | |
*** slunkad has quit IRC | 13:52 | |
*** jaosorior has quit IRC | 13:56 | |
*** jaosorior has joined #openstack-keystone | 13:56 | |
*** thorst_afk is now known as thorst_ | 13:56 | |
dstanek | robcresswell: i'd love to hear numbers as well. i'm assuming that v2 will be gone as soon as we are able to | 13:57 |
robcresswell | dstanek: Would Keystone consider pushing it themselves? As in, announcing deprecation in P/removal in R | 13:58 |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone master: Rename protocol cascade delete migration file https://review.openstack.org/433644 | 14:05 |
*** chlong has joined #openstack-keystone | 14:15 | |
dstanek | robcresswell: i'm sure we would. i deprecated it serveral releases ago and we had to roll it back because there were complaints | 14:16 |
robcresswell | dstanek: Ah okay. I'll bring it up at the PTG if there's an appropriate time. Perhaps with the new CP work going on too, we can make sure we're at good point to move forward. | 14:18 |
lbragstad | robcresswell we're anxiously awaiting the day we can remove v2.0 stuff | 14:19 |
robcresswell | lbragstad: I believe thats your call now boss :) | 14:19 |
dstanek | robcresswell: sounds good to me | 14:19 |
robcresswell | lbragstad: Any appropriate sessions at the PTG to raise this? | 14:20 |
lbragstad | robcresswell :) | 14:20 |
lbragstad | robcresswell I was just about to check | 14:20 |
lbragstad | robcresswell we have a dedicated session for deprecations/removals schedule for 3:40 on Thursday in the keystone room | 14:21 |
lbragstad | https://etherpad.openstack.org/p/keystone-pike-ptg | 14:21 |
lbragstad | robcresswell would that work? you can add your context here if you'd like - https://etherpad.openstack.org/p/pike-ptg-keystone-deprecations | 14:22 |
*** jaosorior has quit IRC | 14:22 | |
*** jaosorior has joined #openstack-keystone | 14:30 | |
*** agarner_away has quit IRC | 14:42 | |
lbragstad | bug day! | 14:42 |
*** aleph1 has joined #openstack-keystone | 14:43 | |
lbragstad | alright - fwiw, i'm going to be going through bugs today and dropping links here in case anyone feels like picking them up | 14:44 |
lbragstad | i'll be doing the same for reviews that close bugs | 14:44 |
*** spzala has joined #openstack-keystone | 14:45 | |
*** ravelar has joined #openstack-keystone | 14:49 | |
*** aasthad has joined #openstack-keystone | 14:50 | |
*** dikonoor has quit IRC | 14:51 | |
*** jerrygb has quit IRC | 14:59 | |
*** jerrygb has joined #openstack-keystone | 15:00 | |
*** edtubill has joined #openstack-keystone | 15:04 | |
*** jerrygb has quit IRC | 15:04 | |
*** nkinder has joined #openstack-keystone | 15:05 | |
*** iljal has joined #openstack-keystone | 15:08 | |
*** rderose has joined #openstack-keystone | 15:11 | |
*** lucasxu has joined #openstack-keystone | 15:13 | |
*** lamt has joined #openstack-keystone | 15:14 | |
*** ngupta has joined #openstack-keystone | 15:14 | |
*** h5t4 has joined #openstack-keystone | 15:18 | |
*** gabarmas has joined #openstack-keystone | 15:26 | |
lbragstad | this one is looking good in case anyone want to review something - https://review.openstack.org/#/c/182658/20 | 15:26 |
lbragstad | and it closes a bug | 15:26 |
*** iljal has quit IRC | 15:28 | |
gabarmas | Hi guys. What's the best place to get help about keystone? Is there a mail list or some sort of forum somewhere? | 15:28 |
lbragstad | gabarmas o/ | 15:29 |
lbragstad | gabarmas what are you interested in helping with? | 15:29 |
lbragstad | er - sorry | 15:29 |
rodrigods | lbragstad, looks good, but i don't see we assigning too much functions in our code, have the same opinion as you | 15:30 |
*** ngupta has quit IRC | 15:30 | |
lbragstad | i misread your question - I totally thought you were about to volunteer to help with something ;) | 15:30 |
lbragstad | rodrigods i think that one could also use a release note | 15:30 |
gabarmas | haha, I don't think I'm prepared for that. | 15:30 |
lbragstad | gabarmas depending on what your question is - you can usually find a lot of help in the channel | 15:30 |
*** ngupta has joined #openstack-keystone | 15:30 | |
lbragstad | gabarmas this channel specifically* | 15:31 |
lbragstad | gabarmas feel free to ask away - chances are someone here will be able to help you out - or at least point you in the right direction | 15:31 |
*** esp has joined #openstack-keystone | 15:31 | |
gabarmas | Thanks. So I'm trying to leverage it for connecting a kubernetes deployment (in bare metal) to the enterprise LDAP, inspired by this: http://cloudgeekz.com/1128/how-to-setup-active-directory-or-ldap-authentication-for-kubernetes.html | 15:32 |
gabarmas | I think I have made it through most. SSL setup, creating an ldap domain actually, I know that ldap conf file is being read and configuration there looks ok. But I just can't seem to make any of my tests work, so I'm stuck. | 15:33 |
openstackgerrit | Rodrigo Duarte proposed openstack/python-keystoneclient master: do not merge: test ksc gate https://review.openstack.org/435492 | 15:34 |
gabarmas | I was hoping to at least get some logging output from python-ldap (I have set debug_level 4095), but no luck. I'm probably missing something. | 15:36 |
dstanek | gabarmas: what are you doing with keystone? | 15:36 |
dstanek | just trying to use the same LDAP? | 15:37 |
gabarmas | Kubernetes auth options are not too complex, but it does support keystone: https://kubernetes.io/docs/admin/authentication/ | 15:38 |
gabarmas | The link I sent above mentions a way to make kubernetes connect to an AD, using keystone ldap config in the process. I'm trying to do the same, but with my company's openldap. | 15:39 |
*** h5t4 has quit IRC | 15:39 | |
dstanek | gabarmas: are you getting an error trying to use keystone? | 15:42 |
gabarmas | Everything seems to be OK starting it, but when I do a test by curling something like: auth":{"passwordCredentials":{"username": "gabarmas", "password": "xxxxx"}}}, all I get is, in keystone.log: "2017-02-17 14:55:51.719 6127 WARNING keystone.common.wsgi [req-1dbe9023-867c-4b51-b5be-d1dbe2f26165 - - - - -] Authorization failed. The request you have made requires authentication. from 127.0.0.1" | 15:44 |
*** ngupta has quit IRC | 15:44 | |
*** ngupta has joined #openstack-keystone | 15:44 | |
gabarmas | the curl comes back with 401, which is kind of expected. But no sign that ldap is being used (or tried) at all. I have enabled debug output. | 15:45 |
dstanek | gabarmas: do you have debugging enabled? | 15:45 |
gabarmas | Yes, debug = true under [DEFAULT] in keystone.conf, and debug_level = 4095 under [ldap] in domains/keystone.ldap.conf | 15:47 |
gabarmas | I might be missing something important of keystone, so I apologize in advance. I don't have any experience with it prior to this. | 15:50 |
lbragstad | gabarmas no worries - i'm still parsing the how-to | 15:51 |
dstanek | gabarmas: so the config they show looks correct at first glance. are the settings like user_tree_dn all correct? are you able to auth from the command line? | 15:57 |
*** tqtran has joined #openstack-keystone | 16:00 | |
*** spzala has quit IRC | 16:00 | |
gabarmas | You mean ldap settings? Yes, I believe so. But even if they weren't, wouldn't keystone output specific ldap logging? | 16:01 |
gabarmas | Hopefully is just a case of me messing up the ldap config, but I can't see any trace at all that keystone is trying to connect to ldap, so I assumed it wasn't. | 16:02 |
*** tqtran has quit IRC | 16:04 | |
*** rderose has quit IRC | 16:07 | |
dstanek | gabarmas: it's odd that you are not getting and debug log statements | 16:08 |
lbragstad | gabarmas are you accessing keystone via kubectl? | 16:08 |
*** chris_hultin|AWA is now known as chris_hultin | 16:08 | |
lbragstad | gabarmas or are you interacting with keystone directly? | 16:09 |
dstanek | lbragstad: one of the failed attempts was a curl | 16:09 |
lbragstad | aha | 16:09 |
gabarmas | I'm interacting with it directly, either through keystone client (which works alright) or through curl (which doesn't) | 16:09 |
dstanek | gabarmas: oh, so the keystone client actually works for you? | 16:09 |
*** rderose has joined #openstack-keystone | 16:10 | |
lbragstad | interesting | 16:10 |
gabarmas | Wait, using admin_token for auth. | 16:10 |
lbragstad | fwiw - the pike schedule has been released! https://releases.openstack.org/pike/schedule.html | 16:10 |
gabarmas | Can I test ldap credentials using the client? | 16:10 |
*** rderose_ has joined #openstack-keystone | 16:11 | |
dstanek | gabarmas: yes, unset that as the token and provide --os-username and --os-password? i've been using os-client-config so long that i don't remember | 16:12 |
gabarmas | ok, 1 sec | 16:12 |
dstanek | gabarmas: actually i would suggest that you stick with the curl command to reduce the number of variables | 16:12 |
gabarmas | ok :). Maybe there is a step I am missing, regarding read-only LDAP integration. | 16:16 |
gabarmas | Do I need to provision users beforehand? If it is required, I'm not doing any of that. | 16:17 |
dstanek | gabarmas: you don't have any users in your AD? | 16:18 |
gabarmas | I have hundreds. I meant, in keystone, before a user can login. | 16:18 |
dstanek | gabarmas: if you are using ldap as the identity backend then you don't need to have have users in keystone. can you paste curl command you are using to paste.openstack.org? | 16:20 |
*** pcaruana has quit IRC | 16:21 | |
lbragstad | dstanek morgan either of you interested in doing a pycadf review - https://review.openstack.org/#/c/428543/ ? | 16:26 |
lbragstad | https://review.openstack.org/#/c/426411/ is dependent on it | 16:26 |
dstanek | lbragstad: sure | 16:27 |
lbragstad | dstanek thanks! | 16:27 |
*** rderose_ has quit IRC | 16:27 | |
gabarmas | dstanek: here it is: http://paste.openstack.org/show/599436/ | 16:28 |
gabarmas | I copied the relevant logging output. | 16:29 |
*** jaosorior has quit IRC | 16:30 | |
openstackgerrit | Travis Tripp proposed openstack/keystone master: Fix example response formatting https://review.openstack.org/435518 | 16:30 |
dstanek | gabarmas: that's strange. did you restart keystone after you edited the config to use ldap? | 16:34 |
dstanek | gabarmas: also somehow earlier i got the impression that you were using a domain specific config for ldap. is that not true? | 16:34 |
*** rcernin has quit IRC | 16:35 | |
dstanek | gabarmas: ah right you have a keystone.ldap.conf -- is that for a specific domain or did you just name the config like that? | 16:36 |
gabarmas | Wait, maybe that's it. Early this week I run into issues so I tried domains since then. | 16:37 |
gabarmas | I created an ldap domain using the API, named ldap. Before that, keystone would fail saying ldap is not a valid domain name. | 16:38 |
dstanek | gabarmas: domains don't work in v2. you hae to use v3 and specify the domain in the auth request | 16:38 |
dstanek | gabarmas: see https://docs.openstack.org/developer/keystone/devref/api_curl_examples.html#tokens for examples | 16:38 |
gabarmas | I set: "default_domain_id = ldap" in keystone.conf, but now I realize that it is an id, not name. So it might be the issue? | 16:39 |
gabarmas | Ah right, let me give it a go. | 16:39 |
*** tesseract has quit IRC | 16:41 | |
gabarmas | dstanek: Yes that was it. Either setting the domain via using v3 or setting "default_domain_id = <the actual ID>" worked | 16:44 |
dstanek | gabarmas: nice | 16:45 |
gabarmas | Sorry for that, I knew it had to be a stupid thing. Thanks so much for the help! | 16:45 |
*** pramodrj07 has quit IRC | 16:46 | |
*** MasterOfBugs has joined #openstack-keystone | 16:46 | |
*** gabarmas has quit IRC | 16:48 | |
*** nishaYadav_ has joined #openstack-keystone | 16:51 | |
nishaYadav_ | o/ | 16:51 |
*** rderose_ has joined #openstack-keystone | 16:55 | |
*** spzala has joined #openstack-keystone | 17:00 | |
lbragstad | this should be an easy review once the next iteration comes up - https://review.openstack.org/#/c/435518 | 17:00 |
lbragstad | *and* it closes a bug https://bugs.launchpad.net/keystone/+bug/1665706 :) | 17:01 |
openstack | Launchpad bug 1665706 in OpenStack Identity (keystone) "devref api curl examples are hard to read - not formatted" [Undecided,In progress] - Assigned to Travis Tripp (travis-tripp) | 17:01 |
openstackgerrit | Travis Tripp proposed openstack/keystone master: Fix example response formatting https://review.openstack.org/435518 | 17:06 |
dstanek | heya nishaYadav_ | 17:20 |
nishaYadav_ | dstanek: hey :) | 17:20 |
*** lamt has quit IRC | 17:24 | |
*** nishaYadav_ has quit IRC | 17:29 | |
openstackgerrit | Richard Avelar proposed openstack/keystone master: WIP https://review.openstack.org/435545 | 17:29 |
*** lamt has joined #openstack-keystone | 17:33 | |
*** lucasxu has quit IRC | 17:33 | |
*** iljal has joined #openstack-keystone | 17:45 | |
*** jerrygb_ has joined #openstack-keystone | 17:46 | |
*** jerrygb has joined #openstack-keystone | 17:50 | |
*** jerrygb_ has quit IRC | 17:51 | |
*** spzala has quit IRC | 17:53 | |
*** ravelar1 has joined #openstack-keystone | 17:55 | |
*** ravelar1 has quit IRC | 18:01 | |
openstackgerrit | Merged openstack/pycadf master: Make `is_valid` more flexible with uuid validation https://review.openstack.org/428543 | 18:06 |
*** lamt has quit IRC | 18:28 | |
*** iljal has quit IRC | 18:28 | |
*** MasterOfBugs has quit IRC | 18:42 | |
*** tqtran has joined #openstack-keystone | 18:51 | |
*** spzala has joined #openstack-keystone | 18:58 | |
*** spzala has quit IRC | 19:02 | |
-openstackstatus- NOTICE: Restarting gerrit due to performance problems | 19:03 | |
*** spzala has joined #openstack-keystone | 19:04 | |
*** MasterOfBugs has joined #openstack-keystone | 19:06 | |
*** spzala has quit IRC | 19:09 | |
*** gyee has joined #openstack-keystone | 19:14 | |
*** bjolo_ has joined #openstack-keystone | 19:15 | |
*** spzala has joined #openstack-keystone | 19:15 | |
*** spzala has quit IRC | 19:20 | |
*** spzala has joined #openstack-keystone | 19:40 | |
*** gagehugo has quit IRC | 19:44 | |
*** spzala has quit IRC | 19:44 | |
openstackgerrit | Merged openstack/keystone master: Fix multiple uuid warnings with pycadf https://review.openstack.org/426411 | 20:03 |
*** spzala has joined #openstack-keystone | 20:12 | |
*** intlabs is now known as portdirect | 20:13 | |
*** spzala has quit IRC | 20:16 | |
*** lamt has joined #openstack-keystone | 20:17 | |
*** portdirect is now known as portdirect_travl | 20:18 | |
samueldmq | keystone! | 20:23 |
ravelar | samueldmq! | 20:23 |
samueldmq | ravelar: o/ | 20:24 |
ravelar | o/ | 20:24 |
rderose | samueldmq ravelar!! | 20:26 |
rderose | :) | 20:26 |
samueldmq | \o/ | 20:26 |
ravelar | chat slowly coming back to life lol | 20:28 |
ravelar | antwash | 20:29 |
*** lamt has quit IRC | 20:33 | |
antwash | ravelar : \o/ | 20:35 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone master: Updated from global requirements https://review.openstack.org/431886 | 20:35 |
ravelar | antwash rderose samueldmq now its a party | 20:37 |
rderose | oh yeah \o/ | 20:37 |
antwash | just missing :beer: | 20:37 |
samueldmq | oh my irc client supports beer | 20:38 |
ravelar | samueldmq link to the download? | 20:39 |
samueldmq | :) | 20:40 |
lbragstad | what... do... we... got... going on in here? | 20:41 |
lbragstad | virtual tag?! | 20:41 |
lbragstad | :) | 20:41 |
samueldmq | lbragstad: hey tou too joining the party | 20:43 |
samueldmq | you | 20:43 |
lbragstad | always | 20:43 |
samueldmq | :) | 20:44 |
*** jerrygb has quit IRC | 20:44 | |
samueldmq | it's been a crazy week for me | 20:44 |
samueldmq | looking forward to seeing you all next week | 20:44 |
lbragstad | ++ | 20:44 |
lbragstad | yeah - should be fun | 20:44 |
*** raildo has quit IRC | 20:48 | |
*** gagehugo has joined #openstack-keystone | 20:53 | |
ravelar | samueldmq ++ excited | 20:58 |
ravelar | lbragstad ++ | 20:58 |
openstackgerrit | Richard Avelar proposed openstack/python-keystoneclient master: do not merge: test ksc gate https://review.openstack.org/435492 | 21:00 |
openstackgerrit | Merged openstack/keystone master: Fix example response formatting https://review.openstack.org/435518 | 21:00 |
*** browne has joined #openstack-keystone | 21:05 | |
*** gagehugo has quit IRC | 21:07 | |
*** haplo37_ has quit IRC | 21:09 | |
*** rderose_ has quit IRC | 21:09 | |
*** spzala has joined #openstack-keystone | 21:12 | |
*** haplo37_ has joined #openstack-keystone | 21:19 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Create a policies module https://review.openstack.org/435602 | 21:26 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Move default user policies in code https://review.openstack.org/435603 | 21:26 |
openstackgerrit | Anthony Washington proposed openstack/keystone master: WIP: Policy in code https://review.openstack.org/435609 | 21:37 |
*** ngupta_ has joined #openstack-keystone | 21:37 | |
lbragstad | antwash muahahah - noice! | 21:38 |
*** chris_hultin is now known as chris_hultin|AWA | 21:38 | |
antwash | lbragstad : hahaha, we'll get it done eventually | 21:39 |
lbragstad | antwash might isn't passing tests locally | 21:40 |
lbragstad | antwash reviewing yours now | 21:40 |
*** ngupta has quit IRC | 21:40 | |
*** ngupta_ has quit IRC | 21:41 | |
* morgan looks at some reviews before flying | 21:43 | |
antwash | lbragstad : forgot to do pep8 before pushing lol #Rookie | 21:43 |
lbragstad | antwash no worries - i'm about done with my once over. | 21:43 |
antwash | lbragstad : testing locally no | 21:48 |
antwash | now | 21:48 |
lbragstad | antwash posted my comments | 21:49 |
openstackgerrit | Richard Avelar proposed openstack/keystone master: Extend User API to support federated attributes https://review.openstack.org/426449 | 21:50 |
*** bjolo_ has quit IRC | 21:51 | |
*** thorst_ has quit IRC | 21:53 | |
*** jerrygb has joined #openstack-keystone | 21:57 | |
*** spilla has quit IRC | 22:00 | |
*** jerrygb has quit IRC | 22:03 | |
*** ngupta has joined #openstack-keystone | 22:10 | |
*** breton has quit IRC | 22:13 | |
*** gagehugo has joined #openstack-keystone | 22:16 | |
*** dave-mccowan has quit IRC | 22:17 | |
antwash | lbragstad : 1246 test fail ... that's not that bad lol | 22:17 |
lbragstad | antwash all the failures are similar though - so it could be something simple that's just affecting a lot of tests. | 22:18 |
*** breton has joined #openstack-keystone | 22:19 | |
*** edmondsw has quit IRC | 22:23 | |
*** edtubill has quit IRC | 22:28 | |
lbragstad | antwash i reran your patch locally and I only have two failures | 22:30 |
antwash | lbragstad : really! my env must be broke lol | 22:31 |
lbragstad | antwash nope - i don't think it is | 22:31 |
lbragstad | antwash I think we just need to register the rules when we *create* the _ENFORCER object, otherwise we are going to be attempting to register rules that are already registered | 22:32 |
lbragstad | antwash http://cdn.pasteraw.com/insob1rq51t2xx9owrw8itvjwneppwl | 22:32 |
lbragstad | antwash that's why you're seeing issues like - http://cdn.pasteraw.com/6q8sjz2n44u93mj6zrxwakf6bbogl50 | 22:33 |
antwash | lbragstad : yeah I agree, about moving the register rules | 22:36 |
*** edtubill has joined #openstack-keystone | 22:38 | |
openstackgerrit | Anthony Washington proposed openstack/keystone master: Policy in code https://review.openstack.org/435609 | 22:47 |
lbragstad | antwash lol the only failures i'm getting are because you removed checks and they aren't documented - http://cdn.pasteraw.com/b1ltdsg9sutc1vrbgqjs40hsp4qaxxd | 22:48 |
lbragstad | antwash but as far as the API coverage is concerned, it looks like you change work great! | 22:49 |
antwash | lbragstad : well that's good news :) | 22:49 |
antwash | lbragstad : awe that test should be easy to fix, pull a list of the policy keys | 22:52 |
antwash | need to add method if one doesn't already exist | 22:52 |
lbragstad | antwash this assertion is failing for me - https://github.com/openstack/keystone/blob/master/keystone/tests/unit/test_policy.py#L208 | 22:53 |
lbragstad | ^ that's one of the two failures I'm getting locally | 22:53 |
lbragstad | ahhh - that's because it's relying solely on the policy file and not the rules... | 22:54 |
antwash | lbragstad: yeap Line 205 | 22:55 |
*** edmondsw has joined #openstack-keystone | 22:55 | |
antwash | looks like we have some unit test to decouple :) | 22:55 |
lbragstad | antwash yeah - the unit tests are assuming all policy will come from a file | 22:55 |
lbragstad | we can clean that up later thoguh | 22:55 |
lbragstad | http://cdn.pasteraw.com/bm2t6j5xady0609trjartqgljad6ss9 fixes it for me locally | 22:56 |
antwash | running test locally now -- *fingers crossed* it's the same two failing | 22:56 |
antwash | that same fix should fix the other one as well 'test_all_targets_documented` | 22:57 |
lbragstad | antwash i'm not sure | 22:59 |
lbragstad | antwash i think that test fails because it assumes that all the stuff will come from a file | 22:59 |
antwash | well looking at it now, not the exact same solution, but definitely calling policies.list_rules() | 22:59 |
lbragstad | antwash we should refactor that test to use oslo.policy objects | 22:59 |
antwash | yeah it opens the file and dumps in json into a set | 22:59 |
*** edmondsw has quit IRC | 22:59 | |
antwash | but yeah we have an idea how to fix it, shouldn't be a big deal | 23:00 |
*** jerrygb has joined #openstack-keystone | 23:00 | |
lbragstad | yeah - it's just making sure we document things | 23:00 |
lbragstad | so whatever we remove from policy.json should be in the policy_keys still | 23:01 |
*** edtubill has quit IRC | 23:01 | |
lbragstad | test_all_targets_documented should eventually be a hacking check to make sure we define descriptions for policy objects | 23:01 |
antwash | lbgradstad : only two!! ^____^ | 23:13 |
lbragstad | antwash awesome! | 23:13 |
*** spzala has quit IRC | 23:19 | |
*** catintheroof has quit IRC | 23:21 | |
*** catintheroof has joined #openstack-keystone | 23:22 | |
lbragstad | antwash http://cdn.pasteraw.com/1yw3uyf1n2xbd97z4vobqg0xl8i2u6q fixes those two failures for me, but I'm open to more elegant solutions if you find any :) | 23:22 |
*** catintheroof has quit IRC | 23:26 | |
*** thorst has joined #openstack-keystone | 23:27 | |
lbragstad | antwash just a couple last minute comments on https://review.openstack.org/#/c/435609/2 (style nit picks) | 23:31 |
lbragstad | antwash otherwise - great work! | 23:31 |
*** MasterOfBugs has quit IRC | 23:32 | |
*** thorst has quit IRC | 23:32 | |
*** chlong has quit IRC | 23:46 | |
*** ngupta has quit IRC | 23:47 | |
openstackgerrit | Gage Hugo proposed openstack/keystone-specs master: Add User/Project resource tags https://review.openstack.org/431785 | 23:52 |
antwash | lbragstad : just read them, thanks lance for the feedback -- looking forward to getting this pushed to source. | 23:54 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!