*** edmondsw has joined #openstack-keystone | 00:23 | |
*** edmondsw has quit IRC | 00:28 | |
*** ngupta has joined #openstack-keystone | 00:30 | |
openstackgerrit | Merged openstack/keystoneauth master: Add bindep.txt file https://review.openstack.org/458242 | 00:34 |
---|---|---|
*** thorst has joined #openstack-keystone | 00:37 | |
*** thorst has quit IRC | 00:42 | |
*** jerrygb has joined #openstack-keystone | 00:50 | |
*** catintheroof has quit IRC | 00:52 | |
*** mpjetta has joined #openstack-keystone | 00:55 | |
*** jerrygb has quit IRC | 00:56 | |
*** gyee has quit IRC | 01:03 | |
*** MasterOfBugs has quit IRC | 01:07 | |
*** topol has joined #openstack-keystone | 01:12 | |
*** thorst has joined #openstack-keystone | 01:13 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth master: Port the missing version data discovery tests from ksc https://review.openstack.org/458286 | 01:20 |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth master: Allow passing a LATEST sentinel to discover version https://review.openstack.org/458287 | 01:20 |
jamielennox | mordred, samueldmq: ok, so ^ is part of what you are doing (cleaned up and tests) | 01:21 |
jamielennox | but the more i think of it the less likely i think you really want a LATEST at all | 01:21 |
*** thorst has quit IRC | 01:25 | |
*** MasterOfBugs has joined #openstack-keystone | 01:25 | |
*** shuyingya has joined #openstack-keystone | 01:26 | |
jamielennox | mordred: so version=(2,1) will match anything 2.1 and above, 2.1, 2.2, etc because they are deemed backwards compatible with 2.1 | 01:29 |
jamielennox | there is almost no way you really want to say get_endpoint('identity', LATEST) | 01:29 |
jamielennox | because v2 and v3 are completely different | 01:30 |
jamielennox | so 2, 0 and 3, 0 should be sufficient there | 01:30 |
*** thorst has joined #openstack-keystone | 01:33 | |
*** guoshan has joined #openstack-keystone | 01:35 | |
*** david-lyle has quit IRC | 01:35 | |
*** thorst has quit IRC | 01:36 | |
*** liujiong has joined #openstack-keystone | 01:42 | |
*** jerrygb has joined #openstack-keystone | 01:43 | |
*** xuhaigang has quit IRC | 01:45 | |
*** shuyingya has quit IRC | 01:45 | |
*** shuyingya has joined #openstack-keystone | 01:47 | |
*** david-lyle has joined #openstack-keystone | 01:50 | |
*** dave-mcc_ has joined #openstack-keystone | 01:51 | |
*** dave-mccowan has quit IRC | 01:53 | |
*** xuhaigang has joined #openstack-keystone | 01:58 | |
*** thorst has joined #openstack-keystone | 02:07 | |
*** dave-mccowan has joined #openstack-keystone | 02:11 | |
*** zhurong has joined #openstack-keystone | 02:11 | |
*** Shunli has joined #openstack-keystone | 02:11 | |
*** dave-mcc_ has quit IRC | 02:13 | |
*** clayton has joined #openstack-keystone | 02:17 | |
*** xuhaigang has quit IRC | 02:22 | |
*** thorst has quit IRC | 02:23 | |
*** shuyingy_ has joined #openstack-keystone | 02:26 | |
*** shuying__ has joined #openstack-keystone | 02:29 | |
*** shuyingy_ has quit IRC | 02:29 | |
*** shuyingya has quit IRC | 02:30 | |
*** topol has quit IRC | 02:33 | |
*** ngupta has quit IRC | 02:38 | |
*** ngupta has joined #openstack-keystone | 02:38 | |
*** xuhaigang has joined #openstack-keystone | 02:42 | |
openstackgerrit | zhengliuyang proposed openstack/keystone master: Add filter explain in api ref about parents_as_list and subtree_as_list I create a project and its child, then show the project with subtree_as_list, but the subtree list in response is null. I can not find problem via api ref about this parameter, until https://review.openstack.org/458307 | 02:51 |
*** thorst has joined #openstack-keystone | 02:54 | |
*** ngupta has quit IRC | 02:54 | |
*** jerrygb has quit IRC | 02:55 | |
*** topol has joined #openstack-keystone | 03:05 | |
*** topol has quit IRC | 03:10 | |
*** zhurong has quit IRC | 03:21 | |
*** thorst has joined #openstack-keystone | 03:26 | |
*** zhurong has joined #openstack-keystone | 03:28 | |
*** balan has joined #openstack-keystone | 03:30 | |
*** zhurong has quit IRC | 03:31 | |
*** nicolasbock has quit IRC | 03:31 | |
balan | any help much appriciated | 03:31 |
*** thorst has quit IRC | 03:44 | |
*** balan has quit IRC | 03:50 | |
*** ngupta has joined #openstack-keystone | 03:55 | |
*** edmondsw has joined #openstack-keystone | 04:00 | |
*** guoshan has quit IRC | 04:01 | |
*** edmondsw has quit IRC | 04:04 | |
*** dave-mccowan has quit IRC | 04:07 | |
*** jerrygb has joined #openstack-keystone | 04:15 | |
*** MasterOfBugs has quit IRC | 04:20 | |
*** zhurong has joined #openstack-keystone | 04:31 | |
*** jerrygb has quit IRC | 04:32 | |
*** jerrygb has joined #openstack-keystone | 04:32 | |
*** stingaci has joined #openstack-keystone | 04:33 | |
*** stingaci has quit IRC | 04:38 | |
*** thorst has joined #openstack-keystone | 04:41 | |
*** thorst has quit IRC | 04:46 | |
*** jerrygb has quit IRC | 04:47 | |
*** dikonoor has joined #openstack-keystone | 05:18 | |
*** lamt has joined #openstack-keystone | 05:19 | |
*** aojea has joined #openstack-keystone | 05:21 | |
*** aojea has quit IRC | 05:39 | |
*** thorst has joined #openstack-keystone | 05:42 | |
*** richm has quit IRC | 05:44 | |
*** xuhaigang has left #openstack-keystone | 05:45 | |
*** xuhaigang has joined #openstack-keystone | 05:46 | |
*** thorst has quit IRC | 05:46 | |
*** xuhaigang has joined #openstack-keystone | 05:47 | |
*** adriant has quit IRC | 05:50 | |
*** edmondsw has joined #openstack-keystone | 06:00 | |
*** edmondsw has quit IRC | 06:05 | |
*** zhurong has quit IRC | 06:12 | |
*** arturb has joined #openstack-keystone | 06:14 | |
*** lamt has quit IRC | 06:14 | |
*** liujiong has quit IRC | 06:20 | |
*** liujiong_lj has joined #openstack-keystone | 06:20 | |
*** lamt has joined #openstack-keystone | 06:22 | |
*** david-lyle has quit IRC | 06:23 | |
*** voelzmo has joined #openstack-keystone | 06:27 | |
*** lamt has quit IRC | 06:27 | |
*** rcernin has joined #openstack-keystone | 06:28 | |
*** david-lyle has joined #openstack-keystone | 06:37 | |
*** pcaruana has joined #openstack-keystone | 06:40 | |
*** Aqsam has joined #openstack-keystone | 06:43 | |
*** topol has joined #openstack-keystone | 06:46 | |
*** topol has quit IRC | 06:50 | |
*** tesseract has joined #openstack-keystone | 06:56 | |
*** d0ugal has quit IRC | 06:56 | |
*** david-lyle has quit IRC | 07:02 | |
*** david-lyle has joined #openstack-keystone | 07:03 | |
*** jaosorior_away is now known as jaosorior | 07:11 | |
*** zhurong has joined #openstack-keystone | 07:12 | |
*** jhesketh has quit IRC | 07:14 | |
*** aojea has joined #openstack-keystone | 07:16 | |
*** aojea has quit IRC | 07:18 | |
*** aojea has joined #openstack-keystone | 07:18 | |
*** jamielennox has quit IRC | 07:28 | |
*** odyssey4me has joined #openstack-keystone | 07:41 | |
*** jamielennox has joined #openstack-keystone | 07:42 | |
*** thorst has joined #openstack-keystone | 07:44 | |
*** jhesketh has joined #openstack-keystone | 07:44 | |
*** MasterOfBugs has joined #openstack-keystone | 07:44 | |
*** liujiong has joined #openstack-keystone | 07:51 | |
*** liujiong_lj has quit IRC | 07:52 | |
*** shuying__ has quit IRC | 07:55 | |
*** zzzeek has quit IRC | 08:00 | |
*** shuyingya has joined #openstack-keystone | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:00 | |
*** thorst has quit IRC | 08:03 | |
*** xuhaigang has quit IRC | 08:09 | |
*** stingaci has joined #openstack-keystone | 08:35 | |
*** stingaci has quit IRC | 08:39 | |
*** MasterOfBugs has quit IRC | 08:42 | |
*** david-lyle has quit IRC | 08:47 | |
*** shuyingy_ has joined #openstack-keystone | 08:53 | |
*** shuyingya has quit IRC | 08:56 | |
*** faizy_ has joined #openstack-keystone | 09:08 | |
*** faizy_ has quit IRC | 09:09 | |
*** faizy_ has joined #openstack-keystone | 09:09 | |
*** faizy_ has quit IRC | 09:11 | |
*** faizy has quit IRC | 09:11 | |
openstackgerrit | Anton Studenov proposed openstack/keystoneauth master: Fix version parser for IdentityPlugin https://review.openstack.org/458411 | 09:21 |
*** thorst has joined #openstack-keystone | 10:00 | |
*** nicolasbock has joined #openstack-keystone | 10:02 | |
*** thorst has quit IRC | 10:04 | |
openstackgerrit | Shan Guo proposed openstack/keystone master: Trivial Fix: fix typo in test comments https://review.openstack.org/458427 | 10:08 |
*** topol has joined #openstack-keystone | 10:08 | |
*** aojea has quit IRC | 10:08 | |
*** topol has quit IRC | 10:13 | |
*** richm has joined #openstack-keystone | 10:13 | |
*** liujiong has quit IRC | 10:16 | |
*** zhurong has quit IRC | 10:19 | |
*** goutham has joined #openstack-keystone | 10:19 | |
goutham | Hi all | 10:20 |
goutham | i need your help in setting up multiregion in devstack | 10:20 |
goutham | can anyone help? | 10:20 |
*** aojea has joined #openstack-keystone | 10:22 | |
goutham | I have two devstack setups and i want to create multi-region setup | 10:33 |
goutham | things done-- | 10:33 |
goutham | 1- Create endpoints of regiontwo services in Region1 | 10:33 |
goutham | 2- modify keystone_authtoken section of conf files of regiontwo's services like nova and cinder to regionone's keystone. | 10:34 |
goutham | but still i am getting this error "cannot discover suitable url for plugin" | 10:35 |
goutham | I have done the same steps in mitaka & newton it worked then but, its not working in ocata did i miss anything? | 10:35 |
*** stingaci has joined #openstack-keystone | 10:36 | |
*** aojea has quit IRC | 10:39 | |
*** stingaci has quit IRC | 10:41 | |
*** aojea has joined #openstack-keystone | 10:47 | |
*** thorst has joined #openstack-keystone | 11:01 | |
*** thorst has quit IRC | 11:06 | |
*** markvoelker has quit IRC | 11:06 | |
*** markvoelker has joined #openstack-keystone | 11:06 | |
*** raildo has joined #openstack-keystone | 11:06 | |
*** mvk has quit IRC | 11:06 | |
*** jaosorior has quit IRC | 11:09 | |
*** markvoelker has quit IRC | 11:11 | |
*** topol has joined #openstack-keystone | 11:16 | |
*** zhurong has joined #openstack-keystone | 11:18 | |
*** jaosorior has joined #openstack-keystone | 11:20 | |
*** thorst has joined #openstack-keystone | 11:26 | |
*** lennyb has quit IRC | 11:29 | |
*** lennyb has joined #openstack-keystone | 11:30 | |
*** openstackgerrit has quit IRC | 11:32 | |
*** Shunli has quit IRC | 11:46 | |
*** jerrygb has joined #openstack-keystone | 11:49 | |
*** jerrygb has quit IRC | 11:54 | |
*** jerrygb has joined #openstack-keystone | 12:09 | |
*** edmondsw has joined #openstack-keystone | 12:12 | |
*** jerrygb has quit IRC | 12:14 | |
*** mvk has joined #openstack-keystone | 12:15 | |
mordred | jamielennox: well - I mean, in shade we definitely do want "latest either 2 or 3" - but also want to know what version we got back so that we know which versions of our code to use | 12:24 |
mordred | jamielennox: but let me read more scrollback | 12:25 |
*** guoshan has joined #openstack-keystone | 12:26 | |
mordred | unless a user has requested a specific version - which is more of an escape hatch for if a cloud advertises a version but it's broken | 12:26 |
*** dave-mccowan has joined #openstack-keystone | 12:26 | |
*** catintheroof has joined #openstack-keystone | 12:27 | |
mordred | an example of this is glance, which some clouds have both v1 and v2 deployed, but for some reason have image upload blocked on v2 but not on v1 - so a user of those clouds wants to tell shade to not use v2, even though it finds it can | 12:27 |
*** catintheroof has quit IRC | 12:30 | |
*** catintheroof has joined #openstack-keystone | 12:30 | |
*** markvoelker has joined #openstack-keystone | 12:39 | |
*** catintheroof has quit IRC | 12:40 | |
*** catintheroof has joined #openstack-keystone | 12:41 | |
*** catintheroof has quit IRC | 12:41 | |
*** catintheroof has joined #openstack-keystone | 12:41 | |
*** catintheroof has quit IRC | 12:43 | |
*** catintheroof has joined #openstack-keystone | 12:43 | |
*** openstackgerrit has joined #openstack-keystone | 12:45 | |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone master: Writing API & Scenario Tests docs https://review.openstack.org/458207 | 12:45 |
*** jerrygb has joined #openstack-keystone | 12:56 | |
*** guoshan has quit IRC | 12:58 | |
*** guoshan has joined #openstack-keystone | 12:58 | |
*** guoshan has quit IRC | 13:00 | |
*** guoshan_ has joined #openstack-keystone | 13:00 | |
*** lamt has joined #openstack-keystone | 13:03 | |
*** shuyingy_ has quit IRC | 13:05 | |
*** shuyingya has joined #openstack-keystone | 13:05 | |
andreykurilin | hi folks! Recently, small we found incompatibility of several checks in keystoneauth with latest format of auth_url . Can someone look at proposed fix ? https://review.openstack.org/#/c/458411/ | 13:13 |
*** mpjetta has quit IRC | 13:14 | |
jamielennox | goutham: ^ could be your problem | 13:14 |
goutham | yea | 13:14 |
goutham | i saw that i felt the same | 13:14 |
jamielennox | andreykurilin: but that /v2 in url is a fallback for when discovery fails - and in devstack discovery should not fail | 13:15 |
jamielennox | but i need to go to bed, i'll have a look tomorrow | 13:15 |
jamielennox | night | 13:15 |
*** guoshan_ has quit IRC | 13:16 | |
andreykurilin | jamielennox: I did not say that it failed at devstack :P | 13:16 |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone master: Writing API & Scenario Tests docs https://review.openstack.org/458207 | 13:16 |
*** Aurelgad1o has quit IRC | 13:19 | |
*** Aurelgadjo has joined #openstack-keystone | 13:19 | |
*** lamt has quit IRC | 13:23 | |
*** prashkre has joined #openstack-keystone | 13:25 | |
*** ig0r_ has joined #openstack-keystone | 13:34 | |
*** shuyingya has quit IRC | 13:38 | |
*** david-lyle has joined #openstack-keystone | 13:46 | |
prashkre | lbragstad: Hi Lance. I found an issue with v3/role_assignments?effective&include_names API. | 13:49 |
*** goutham has quit IRC | 13:50 | |
prashkre | lbragstad: I have configured ldap server as identity backend in my env, then added a role to user1 and removed user1 from ldap identity server. | 13:51 |
*** chlong has joined #openstack-keystone | 13:51 | |
prashkre | since role assingment still exits in assignment table, /v3/role_assignments?effective&include_names&scope.project.id=076a023e1e394b2c8adf6035cfacba4e will get all role assingments from db and include_names request param will try to get username from identity backend based on user_id in roles, so it is failing whole API with "Could not find user: user1." | 13:51 |
*** lamt has joined #openstack-keystone | 13:55 | |
*** shuyingya has joined #openstack-keystone | 13:56 | |
prashkre | lbragstad: https://github.com/openstack/keystone/blob/master/keystone/assignment/core.py#L941 here it is trying to get the user from identity backend and failing. I guess we should handle the user not found | 13:56 |
*** shuyingya has quit IRC | 13:57 | |
*** shuyingya has joined #openstack-keystone | 13:57 | |
breton | prashkre: you should file a bugreport | 13:58 |
prashkre | breton: sure. will open a bug for this. | 14:01 |
lbragstad | prashkre ++ | 14:01 |
lbragstad | prashkre let me know when you open the report | 14:02 |
prashkre | lbragstad: sure. | 14:02 |
*** topol has quit IRC | 14:04 | |
*** lamt has quit IRC | 14:09 | |
*** david-lyle has quit IRC | 14:14 | |
*** ngupta has quit IRC | 14:17 | |
*** ngupta has joined #openstack-keystone | 14:17 | |
*** mpjetta has joined #openstack-keystone | 14:18 | |
*** guoshan has joined #openstack-keystone | 14:19 | |
*** lucasxu has joined #openstack-keystone | 14:26 | |
*** dikonoor has quit IRC | 14:26 | |
prashkre | lbragstad: raised a bug https://bugs.launchpad.net/keystone/+bug/1684820 for issue reported above | 14:29 |
openstack | Launchpad bug 1684820 in OpenStack Identity (keystone) "GET /role_assignments?include_names API is blocked with 404 error when a user doesn't exists in identity backend" [Undecided,New] | 14:29 |
kencjohnston | What is the status of the v2 service in Pike? | 14:32 |
knikolla | kencjohnston: you mean the identity v2 api? | 14:34 |
kencjohnston | knikolla yes. | 14:35 |
*** shuyingya has quit IRC | 14:35 | |
knikolla | kencjohnston: deprecated | 14:35 |
kencjohnston | knikolla Got it. Thanks. | 14:35 |
knikolla | kencjohnston: will be removed in mitaka+4. | 14:35 |
knikolla | that means queen, if i'm not wrong. | 14:36 |
knikolla | queens* | 14:36 |
knikolla | v2 auth though, will stay for a while longer. | 14:37 |
*** spzala has joined #openstack-keystone | 14:37 | |
*** topol has joined #openstack-keystone | 14:46 | |
*** guoshan has quit IRC | 14:47 | |
*** lamt has joined #openstack-keystone | 14:49 | |
*** stephen_m has joined #openstack-keystone | 14:50 | |
*** guoshan_ has joined #openstack-keystone | 14:51 | |
*** guoshan_ has quit IRC | 14:53 | |
*** rcernin has quit IRC | 15:01 | |
*** chris_hultin|AWA is now known as chris_hultin | 15:01 | |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone master: Writing API & Scenario Tests docs https://review.openstack.org/458207 | 15:02 |
*** lamt has quit IRC | 15:03 | |
*** yingwei has joined #openstack-keystone | 15:07 | |
*** chris_hultin is now known as chris_hultin|AWA | 15:12 | |
*** spzala has quit IRC | 15:12 | |
*** david-lyle has joined #openstack-keystone | 15:13 | |
*** spzala has joined #openstack-keystone | 15:13 | |
*** pcaruana has quit IRC | 15:14 | |
*** lucasxu has quit IRC | 15:16 | |
*** lucasxu has joined #openstack-keystone | 15:17 | |
*** spzala has quit IRC | 15:17 | |
*** blake has joined #openstack-keystone | 15:21 | |
*** lamt has joined #openstack-keystone | 15:24 | |
*** voelzmo has quit IRC | 15:29 | |
*** lamt has quit IRC | 15:35 | |
*** lucasxu has quit IRC | 15:39 | |
*** Aqsam has quit IRC | 15:40 | |
*** lucasxu has joined #openstack-keystone | 15:41 | |
*** lucasxu has quit IRC | 15:42 | |
*** lucasxu has joined #openstack-keystone | 15:43 | |
*** lamt has joined #openstack-keystone | 15:44 | |
*** spzala has joined #openstack-keystone | 15:44 | |
blake | jamielennox: I noticed the ADFSPassword plugin in keystoneauth1 does not have a registered entry point in setup.cfg. Is this just an oversight? | 15:45 |
*** rderose has joined #openstack-keystone | 15:45 | |
*** aojea has quit IRC | 15:52 | |
*** david-lyle has quit IRC | 15:59 | |
*** afazekas_ is now known as afazekas | 16:00 | |
*** ig0r_ has quit IRC | 16:01 | |
*** dave-mccowan has quit IRC | 16:06 | |
*** david-lyle has joined #openstack-keystone | 16:07 | |
*** zhurong has quit IRC | 16:11 | |
*** dikonoor has joined #openstack-keystone | 16:12 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystoneauth master: Updated from global requirements https://review.openstack.org/455926 | 16:18 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/ldappool master: Updated from global requirements https://review.openstack.org/458580 | 16:18 |
*** dave-mccowan has joined #openstack-keystone | 16:21 | |
breton | https://www.openstack.org/assets/survey/April2017SurveyReport.pdf | 16:22 |
breton | so, people use Keystone more than Nova! | 16:22 |
*** dave-mcc_ has joined #openstack-keystone | 16:23 | |
lbragstad | nice - i need to read that | 16:23 |
breton | either we are great | 16:23 |
breton | or we are just tied to other openstack and people suffer | 16:23 |
lbragstad | :) | 16:24 |
*** dave-mccowan has quit IRC | 16:26 | |
*** ngupta has quit IRC | 16:27 | |
*** spzala has quit IRC | 16:29 | |
*** tesseract has quit IRC | 16:34 | |
breton | > Which OpenStack identity service (Keystone) drivers are in use? | 16:35 |
breton | i think we should drop the question from the next survey | 16:35 |
breton | and ask about source for authentication | 16:35 |
lbragstad | breton as in SQL, LDAP, federation, etc.. ? | 16:36 |
breton | lbragstad: yep | 16:38 |
breton | > performance improvements: 39% | 16:39 |
breton | so... what issues with performance do we have? | 16:39 |
lbragstad | breton well - unless you have caching enabled, we do a lot of weird things | 16:39 |
lbragstad | like fetching a user multiple times in a single request for example | 16:40 |
breton | i suggested it some time ago | 16:40 |
breton | and gonna suggest it again | 16:40 |
breton | lets make memcache a hard requirement for keystone and make caching enabled by default | 16:40 |
lbragstad | breton well - we can't exactly do that because of python-memcached | 16:41 |
breton | we have a hard requirement of the database. Lets have the same hard requirement of cache | 16:41 |
breton | lbragstad: why not? | 16:41 |
lbragstad | python-memcached has some py3 issues | 16:42 |
lbragstad | which morgan is more familiar with than i am | 16:42 |
* breton sighs | 16:42 | |
lbragstad | but it sounded like those wouldn't be an issue if we moved to pymemcached | 16:43 |
*** rderose has quit IRC | 16:43 | |
morgan | python-memcached is inconsistent and seems to have some py3 issues still | 16:44 |
*** lucasxu has quit IRC | 16:44 | |
morgan | pymemcached is much more actively maintained, is better designed, etc | 16:44 |
morgan | it is not a drop-in replacement though | 16:44 |
lbragstad | but pymemcached doesn't, at least i don't think | 16:44 |
morgan | pymemcache has no issues with py3 | 16:44 |
morgan | and is a good library | 16:45 |
lbragstad | yeah - i'm sure we'd have to rework some stuff | 16:45 |
lbragstad | but we'll have to do it anyway for py3 things | 16:45 |
morgan | so, my answer is... i don't want to make caching ahard reuirement with python-memcached | 16:45 |
lbragstad | so - it seems like a relatively small price to pay for what we'd get | 16:45 |
morgan | it is not a ton of code to write a pymemcached dogpile backend | 16:45 |
morgan | and pymemcached is already in G-R | 16:45 |
lbragstad | yeah | 16:46 |
lbragstad | but - i don't see a reason why we couldn't make that a hard requirement after that work is done | 16:46 |
morgan | lbragstad: i know this is a beastly patch... https://review.openstack.org/#/c/438701/ but that should get eyes | 16:46 |
morgan | again | 16:46 |
lbragstad | aha - yes | 16:46 |
lbragstad | i will look today | 16:47 |
morgan | lbragstad: agreed. i'd say: pymemcached used by default, then caching a hard requirement | 16:47 |
morgan | keystone assumes caching (in the R release, no disabling it?) | 16:47 |
lbragstad | yeah | 16:47 |
breton | morgan: why pymemcache is not a drop-in replacement? What is different? | 16:49 |
*** jaosorior has quit IRC | 16:49 | |
morgan | breton: the interface is not the same as pythong-memcache | 16:50 |
morgan | simply it isn't .get/.set/.delete/.delete_multi...etc | 16:50 |
morgan | it is something slightly different. so you can't just say import pymemcache, instantiate client | 16:51 |
morgan | it needs different code paths | 16:51 |
*** yingwei has quit IRC | 16:52 | |
breton | ok. I just recently migrated from pymemcache to python-mecached and it took to just re-init the client | 16:52 |
*** lucasxu has joined #openstack-keystone | 16:55 | |
*** mvk has quit IRC | 17:03 | |
morgan | it's set_multi vs set_many | 17:04 |
morgan | and some few other minor semantic changes | 17:04 |
*** stingaci has joined #openstack-keystone | 17:05 | |
morgan | add, replace | 17:05 |
morgan | etc | 17:05 |
morgan | pymemcache more accurately maps to actual memcache commands | 17:05 |
*** spzala has joined #openstack-keystone | 17:06 | |
breton | morgan: https://github.com/pinterest/pymemcache/blob/master/pymemcache/client/base.py#L320 :) | 17:08 |
*** spzala has quit IRC | 17:10 | |
morgan | cool they added it then | 17:10 |
morgan | when we originally looked at pymemcache it didn't have the compat stuff | 17:11 |
*** david-lyle_ has joined #openstack-keystone | 17:17 | |
*** david-lyle has quit IRC | 17:17 | |
*** aojea has joined #openstack-keystone | 17:17 | |
*** spzala has joined #openstack-keystone | 17:18 | |
*** aojea has quit IRC | 17:22 | |
*** spzala has quit IRC | 17:22 | |
*** david-lyle_ has quit IRC | 17:23 | |
*** ig0r_ has joined #openstack-keystone | 17:25 | |
*** mvk has joined #openstack-keystone | 17:25 | |
*** spzala has joined #openstack-keystone | 17:29 | |
breton | i see that pymemcache has pool of clients. What is this for? Same thing as our memcachepool? | 17:30 |
*** aojea has joined #openstack-keystone | 17:37 | |
*** aojea has quit IRC | 17:42 | |
*** lamt has quit IRC | 17:49 | |
*** raildo has quit IRC | 18:03 | |
*** raildo has joined #openstack-keystone | 18:11 | |
*** voelzmo has joined #openstack-keystone | 18:12 | |
*** stingaci has quit IRC | 18:14 | |
*** rmascena has joined #openstack-keystone | 18:14 | |
*** raildo has quit IRC | 18:16 | |
*** stingaci has joined #openstack-keystone | 18:18 | |
*** rmascena has quit IRC | 18:21 | |
*** MasterOfBugs has joined #openstack-keystone | 18:21 | |
*** voelzmo has quit IRC | 18:21 | |
*** raildo has joined #openstack-keystone | 18:21 | |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone master: Writing API & Scenario Tests docs https://review.openstack.org/458207 | 18:29 |
*** lamt has joined #openstack-keystone | 18:31 | |
*** Aqsa has joined #openstack-keystone | 18:37 | |
prashkre | lbragstad: raised another bug https://bugs.launchpad.net/keystone/+bug/1684994. pls take a look. | 18:38 |
openstack | Launchpad bug 1684994 in OpenStack Identity (keystone) "POST v3/auth/tokens API is returning unexpected 500 error when ldap credentials are incorrect" [Undecided,New] | 18:38 |
*** jerrygb has quit IRC | 18:39 | |
*** lucasxu has quit IRC | 18:44 | |
*** lucasxu has joined #openstack-keystone | 18:44 | |
*** dikonoor has quit IRC | 18:45 | |
prashkre | lbragstad: On https://bugs.launchpad.net/keystone/+bug/1684820, shall we catch user not found exception at https://github.com/openstack/keystone/blob/master/keystone/assignment/core.py#L941 and skip adding role to role_assign_list or just skip adding username to new_assign dict before adding to role_assign_list | 18:48 |
openstack | Launchpad bug 1684820 in OpenStack Identity (keystone) "GET /role_assignments?include_names API is blocked with 404 error when a user doesn't exists in identity backend" [Undecided,New] | 18:48 |
lbragstad | prashkre ack - i plan on doing some bug triage later today, i can take a look then | 18:48 |
lbragstad | prashkre thanks for the heads up | 18:49 |
prashkre | lbragstad: sure. will catch you tomorrow. thank you | 18:49 |
lbragstad | prashkre no problem | 18:49 |
*** jerrygb has joined #openstack-keystone | 18:51 | |
*** prashkre_ has joined #openstack-keystone | 18:55 | |
*** prashkre has quit IRC | 18:58 | |
*** lucasxu has quit IRC | 19:00 | |
*** lucasxu has joined #openstack-keystone | 19:01 | |
*** lucasxu has quit IRC | 19:04 | |
*** jerrygb has quit IRC | 19:07 | |
*** prashkre__ has joined #openstack-keystone | 19:26 | |
*** prashkre_ has quit IRC | 19:28 | |
*** david-lyle has joined #openstack-keystone | 19:33 | |
*** jerrygb has joined #openstack-keystone | 19:36 | |
*** voelzmo has joined #openstack-keystone | 19:42 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: Remove LDAP delete logic and associated tests https://review.openstack.org/424344 | 19:50 |
*** spzala has quit IRC | 19:54 | |
*** spzala has joined #openstack-keystone | 19:55 | |
*** voelzmo has quit IRC | 19:59 | |
*** spzala has quit IRC | 20:00 | |
*** aojea has joined #openstack-keystone | 20:06 | |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone master: Writing API & Scenario Tests docs https://review.openstack.org/458207 | 20:09 |
*** prashkre__ has quit IRC | 20:09 | |
*** aojea has quit IRC | 20:10 | |
openstackgerrit | Merged openstack/ldappool master: Updated from global requirements https://review.openstack.org/458580 | 20:11 |
openstackgerrit | Merged openstack/keystoneauth master: Updated from global requirements https://review.openstack.org/455926 | 20:11 |
*** spotz is now known as spotz_zzz | 20:15 | |
*** spotz_zzz is now known as spotz | 20:17 | |
*** raildo has quit IRC | 20:22 | |
*** aojea_ has joined #openstack-keystone | 20:27 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Move user policies to DocumentedRuleDefault https://review.openstack.org/449240 | 20:31 |
*** aojea_ has quit IRC | 20:31 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Move token revocation to DocumentedRuleDefault https://review.openstack.org/449255 | 20:34 |
*** aojea has joined #openstack-keystone | 20:46 | |
*** edmondsw has quit IRC | 20:51 | |
*** aojea has quit IRC | 20:51 | |
*** edmondsw has joined #openstack-keystone | 20:51 | |
*** stephen_m has quit IRC | 20:55 | |
*** edmondsw has quit IRC | 20:56 | |
*** Aqsa has quit IRC | 20:56 | |
*** david-lyle has quit IRC | 20:57 | |
*** thorst has quit IRC | 21:11 | |
cmurphy | knikolla: not sure how far you got with mod_proxy_uwsgi and federation but I think I got it working with shibboleth https://github.com/cmurphy/federated-devstack/blob/dc70023c4078281a7398c8b7ad160b68581ab6f4/playbooks/configure-shibboleth.yml#L35-L58 | 21:19 |
*** edmondsw has joined #openstack-keystone | 21:20 | |
*** edmondsw has quit IRC | 21:25 | |
knikolla | cmurphy: Awesome! I'll test it and update the devstack plugin | 21:25 |
*** catintheroof has quit IRC | 21:34 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: Update Devstack plugin for uwsgi and mod_proxy_uwsgi https://review.openstack.org/458665 | 21:44 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Cleanup policy generation https://review.openstack.org/458666 | 21:45 |
*** blake has quit IRC | 21:45 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: Update Devstack plugin for uwsgi and mod_proxy_uwsgi https://review.openstack.org/458665 | 21:47 |
lbragstad | stevemar around? | 22:01 |
*** thorst has joined #openstack-keystone | 22:06 | |
*** thorst has quit IRC | 22:07 | |
lbragstad | stevemar do you know what generates https://docs.openstack.org/developer/keystone/sample_config.html when the docs build? | 22:14 |
lbragstad | stevemar i'd like to use that tooling to do the same for sample policy files | 22:14 |
*** spzala has joined #openstack-keystone | 22:17 | |
*** spzala has quit IRC | 22:17 | |
*** topol has quit IRC | 22:20 | |
*** Yash_ has joined #openstack-keystone | 22:22 | |
Yash_ | Hi people | 22:22 |
Yash_ | I need help with an issue | 22:23 |
Yash_ | http://paste.openstack.org/show/607409/ | 22:23 |
lbragstad | stevemar nevermind - i figured it out | 22:24 |
Yash_ | I am getting "The service catalog is empty." error when trying to create new identity service | 22:24 |
lbragstad | Yash_ looks like the client can't find the identity service | 22:25 |
lbragstad | Yash_ do you have access to the host that keystone is running on? | 22:25 |
*** jamielennox is now known as jamielennox|away | 22:25 | |
Yash_ | @lbragstad : Yes | 22:26 |
Yash_ | @lbragstad : But like if I issue token issue command, that works | 22:26 |
lbragstad | Yash_ `keystone-manage boostrap` is intended to bootstrap your keystone host with an identity endpoint - https://docs.openstack.org/developer/keystone/man/keystone-manage.html | 22:27 |
lbragstad | which should populate in the service catalog | 22:27 |
Yash_ | @lbragstad : so that means it didn't get bootstrapped properly | 22:28 |
lbragstad | Yash_ i don't think its that it was boostrapped wrong | 22:28 |
lbragstad | Yash_ it just looks like keystone doesn't have any endpoints yet | 22:28 |
lbragstad | which is causing the empty catalog | 22:28 |
Yash_ | @lbragstad: Thanks for the information, I will look into this :) | 22:29 |
*** jamielennox|away is now known as jamielennox | 22:29 | |
lbragstad | Yash_ i'm digging around for a link that might help | 22:30 |
lbragstad | Yash_ but you can generate the help text using `keystone-manage help bootstrap` | 22:30 |
Yash_ | @lbragstad : Sure....thanks again | 22:30 |
lbragstad | Yash_ here are some docs - https://github.com/openstack/openstack-manuals/blob/5774575e6b97fd25a439aed096137413acba8d44/doc/install-guide/source/keystone-install.rst | 22:31 |
lbragstad | for example `# keystone-manage bootstrap --bootstrap-password ADMIN_PASS \ | 22:31 |
lbragstad | --bootstrap-admin-url http://controller:35357/v3/ \ | 22:31 |
lbragstad | --bootstrap-internal-url http://controller:5000/v3/ \ | 22:31 |
lbragstad | --bootstrap-public-url http://controller:5000/v3/ \ | 22:31 |
lbragstad | --bootstrap-region-id RegionOne` | 22:31 |
Yash_ | @lbragstad : Got it | 22:33 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Include sample policy file in documentation https://review.openstack.org/458677 | 22:38 |
lbragstad | cc stevemar ^ | 22:38 |
*** thorst has joined #openstack-keystone | 22:39 | |
lbragstad | Yash_ hopefully that helps, come ask questions if you need more help | 22:39 |
Yash_ | @lbragstad : I got rid of service catalog error, I have a new issue Forbidden: You are not authorized to perform the requested action: identity:list_endpoints. (HTTP 403) | 22:47 |
*** stingaci has quit IRC | 22:52 | |
*** thorst has quit IRC | 22:56 | |
*** Yash_ has quit IRC | 23:02 | |
*** Yash_ has joined #openstack-keystone | 23:28 | |
Yash_ | Hi people | 23:33 |
Yash_ | I am getting Forbidden: You are not authorized to perform the requested action: identity:create_domain. (HTTP 403) error | 23:33 |
Yash_ | On looking into documentation it says : 403 Forbidden This status code is returned when the request is successfully authenticated but not authorized to perform the requested action. | 23:33 |
Yash_ | I followed instructions on https://docs.openstack.org/newton/install-guide-ubuntu/keystone-install.html | 23:34 |
Yash_ | I bootstrapped the keystone | 23:34 |
Yash_ | But still I am getting this error | 23:34 |
Yash_ | Can anyone please help me with this? | 23:34 |
*** markvoelker has quit IRC | 23:39 | |
*** topol has joined #openstack-keystone | 23:40 | |
*** lamt has quit IRC | 23:41 | |
*** jerrygb has quit IRC | 23:45 | |
*** thorst has joined #openstack-keystone | 23:53 | |
*** topol has quit IRC | 23:55 | |
*** topol has joined #openstack-keystone | 23:55 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!