*** jistr has quit IRC | 00:01 | |
*** jistr has joined #openstack-keystone | 00:02 | |
*** masber has joined #openstack-keystone | 00:13 | |
openstackgerrit | Merged openstack/keystone master: Remove keystone.conf if not used https://review.openstack.org/470871 | 00:19 |
---|---|---|
openstackgerrit | Merged openstack/keystone master: Addition of "type" optional attribute to list credentials. https://review.openstack.org/468254 | 00:19 |
openstackgerrit | Merged openstack/keystone master: Remove loading drivers outside of their expected namespaces https://review.openstack.org/466036 | 00:20 |
openstackgerrit | Merged openstack/keystone master: Update DirectMappingError in keystone.exception https://review.openstack.org/470094 | 00:20 |
*** lucasxu has joined #openstack-keystone | 00:22 | |
*** aojea has joined #openstack-keystone | 00:24 | |
*** aojea has quit IRC | 00:28 | |
*** shuyingya has joined #openstack-keystone | 00:38 | |
*** thorst has joined #openstack-keystone | 00:40 | |
*** shuyingya has quit IRC | 00:43 | |
*** thorst has quit IRC | 00:44 | |
*** lucasxu has quit IRC | 00:45 | |
*** lucasxu has joined #openstack-keystone | 00:46 | |
*** lucasxu has quit IRC | 00:58 | |
*** lucasxu has joined #openstack-keystone | 00:59 | |
*** lucasxu has quit IRC | 01:00 | |
*** lucasxu has joined #openstack-keystone | 01:01 | |
*** thorst has joined #openstack-keystone | 01:07 | |
*** thorst has quit IRC | 01:07 | |
*** catintheroof has quit IRC | 01:10 | |
*** gongysh has joined #openstack-keystone | 01:16 | |
*** jamielennox is now known as jamielennox|away | 01:17 | |
*** eandersson has quit IRC | 01:25 | |
*** eandersson has joined #openstack-keystone | 01:26 | |
*** liujiong has joined #openstack-keystone | 01:28 | |
*** shuyingya has joined #openstack-keystone | 01:31 | |
*** namnh has joined #openstack-keystone | 01:33 | |
*** jamielennox|away is now known as jamielennox | 01:34 | |
*** lucasxu has quit IRC | 01:34 | |
*** thorst has joined #openstack-keystone | 01:41 | |
openstackgerrit | Vu Cong Tuan proposed openstack/python-keystoneclient master: Fix html_last_updated_fmt for Python3 https://review.openstack.org/470658 | 01:47 |
*** aselius has quit IRC | 01:56 | |
openstackgerrit | Vu Cong Tuan proposed openstack/keystoneauth master: Fix html_last_updated_fmt for Python3 https://review.openstack.org/470663 | 01:58 |
*** thorst has quit IRC | 02:06 | |
*** Shunli has joined #openstack-keystone | 02:08 | |
*** shuyingya has quit IRC | 02:11 | |
*** shuyingya has joined #openstack-keystone | 02:12 | |
*** thorst has joined #openstack-keystone | 02:26 | |
*** links has joined #openstack-keystone | 02:27 | |
*** links has quit IRC | 02:30 | |
*** links has joined #openstack-keystone | 02:31 | |
*** piliman974 has joined #openstack-keystone | 02:38 | |
*** gagehugo has quit IRC | 02:41 | |
*** thorst has joined #openstack-keystone | 02:42 | |
*** piliman974 has quit IRC | 02:43 | |
*** thorst has joined #openstack-keystone | 02:43 | |
*** piliman974 has joined #openstack-keystone | 02:43 | |
*** thorst has quit IRC | 02:47 | |
*** gagehugo has joined #openstack-keystone | 02:48 | |
*** shuyingya has quit IRC | 03:02 | |
*** shuyingya has joined #openstack-keystone | 03:02 | |
*** zsli_ has joined #openstack-keystone | 03:05 | |
*** Shunli has quit IRC | 03:07 | |
*** Shunli has joined #openstack-keystone | 03:13 | |
*** thorst has joined #openstack-keystone | 03:14 | |
*** zsli_ has quit IRC | 03:16 | |
*** shuyingy_ has joined #openstack-keystone | 03:20 | |
*** shuyingya has quit IRC | 03:24 | |
*** zhurong has joined #openstack-keystone | 03:28 | |
*** thorst has quit IRC | 03:32 | |
*** gagehugo has quit IRC | 03:54 | |
*** piliman974 has quit IRC | 03:54 | |
*** gagehugo has joined #openstack-keystone | 03:56 | |
*** shuyingy_ has quit IRC | 03:58 | |
*** shuyingya has joined #openstack-keystone | 03:59 | |
*** zhurong has quit IRC | 04:27 | |
*** edmondsw has joined #openstack-keystone | 04:41 | |
*** edmondsw has quit IRC | 04:46 | |
*** gongysh has quit IRC | 04:50 | |
*** zhurong has joined #openstack-keystone | 04:54 | |
*** dikonoor has joined #openstack-keystone | 05:07 | |
*** shuyingy_ has joined #openstack-keystone | 05:11 | |
*** gyee has quit IRC | 05:12 | |
*** shuyingya has quit IRC | 05:15 | |
*** thorst has joined #openstack-keystone | 05:29 | |
*** gongysh has joined #openstack-keystone | 05:30 | |
*** thorst has quit IRC | 05:34 | |
*** jaosorior_away is now known as jaosorior | 05:44 | |
*** zsli_ has joined #openstack-keystone | 05:48 | |
*** zsli__ has joined #openstack-keystone | 05:49 | |
*** Shunli has quit IRC | 05:51 | |
*** zsli_ has quit IRC | 05:52 | |
*** zsli_ has joined #openstack-keystone | 05:55 | |
*** aojea has joined #openstack-keystone | 05:55 | |
*** zsli__ has quit IRC | 05:57 | |
*** zsli__ has joined #openstack-keystone | 05:58 | |
*** zsli_ has quit IRC | 06:00 | |
*** dikonoor has quit IRC | 06:09 | |
*** rcernin has joined #openstack-keystone | 06:10 | |
*** aojea has quit IRC | 06:15 | |
*** aojea has joined #openstack-keystone | 06:15 | |
*** aojea has quit IRC | 06:16 | |
*** aojea has joined #openstack-keystone | 06:16 | |
*** thorst has joined #openstack-keystone | 06:30 | |
*** zhurong has quit IRC | 06:32 | |
*** thorst has quit IRC | 06:35 | |
*** pcaruana has joined #openstack-keystone | 06:39 | |
*** zhurong has joined #openstack-keystone | 06:40 | |
*** jaosorior is now known as jaosorior_away | 06:41 | |
*** adriant has quit IRC | 06:42 | |
*** ppiela has quit IRC | 06:47 | |
*** ppiela_ has joined #openstack-keystone | 06:47 | |
*** amrith has quit IRC | 06:48 | |
*** amrith has joined #openstack-keystone | 06:49 | |
*** toddnni has quit IRC | 06:50 | |
*** jrist has quit IRC | 06:50 | |
*** toddnni has joined #openstack-keystone | 06:52 | |
*** tesseract has joined #openstack-keystone | 07:13 | |
*** aojea has quit IRC | 07:24 | |
*** aojea has joined #openstack-keystone | 07:25 | |
*** aojea has quit IRC | 07:29 | |
*** nicolasbock has joined #openstack-keystone | 07:31 | |
*** thorst has joined #openstack-keystone | 07:31 | |
*** thorst has quit IRC | 07:35 | |
openstackgerrit | zhengliuyang proposed openstack/keystone master: Add response example in authenticate-v3.inc Change-Id: Ic7914c34b41a7efaa36d6d0449c2dcb6f2a52d22 https://review.openstack.org/463245 | 07:36 |
*** jrist has joined #openstack-keystone | 07:36 | |
*** jrist has quit IRC | 07:36 | |
*** jrist has joined #openstack-keystone | 07:36 | |
openstackgerrit | zhengliuyang proposed openstack/keystone master: Add response example in authenticate-v3.inc https://review.openstack.org/463245 | 07:37 |
*** jdennis1 has quit IRC | 07:45 | |
*** jdennis has joined #openstack-keystone | 07:45 | |
*** markvoelker has quit IRC | 07:57 | |
*** markvoelker has joined #openstack-keystone | 07:58 | |
*** zzzeek has quit IRC | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:00 | |
*** links has quit IRC | 08:02 | |
*** markvoelker has quit IRC | 08:02 | |
*** edmondsw has joined #openstack-keystone | 08:17 | |
*** links has joined #openstack-keystone | 08:19 | |
*** yunus has joined #openstack-keystone | 08:20 | |
*** edmondsw has quit IRC | 08:22 | |
*** mvk has quit IRC | 08:22 | |
yunus | Dear All, while configuring keystone for ldap i have a problem. Can anyone explain how keystone works while connecting ldap? I give ldap admin user as user inside keystone.conf. But always could not find admin user. Does keystone checks my user inside usertree? But admin user is not inside usertree. If someone knows working mechanism, it will be very grateful for me | 08:25 |
asettle | lbragstad: I'll review today :) | 08:26 |
*** thorst has joined #openstack-keystone | 08:32 | |
*** zhurong has quit IRC | 08:35 | |
*** zhurong has joined #openstack-keystone | 08:40 | |
*** thorst has quit IRC | 08:51 | |
*** hoonetorg has quit IRC | 08:51 | |
*** mvk has joined #openstack-keystone | 08:52 | |
*** jaosorior_away is now known as jaosorior | 08:53 | |
*** aojea has joined #openstack-keystone | 09:02 | |
*** nicolasbock has quit IRC | 09:03 | |
*** jaosorior has quit IRC | 09:04 | |
*** hoonetorg has joined #openstack-keystone | 09:09 | |
*** yunus has quit IRC | 09:09 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone-tempest-plugin master: Fix .gitreview project https://review.openstack.org/471283 | 09:23 |
openstackgerrit | Colleen Murphy proposed openstack/keystone-tempest-plugin master: Add lxml to test-requirements.txt https://review.openstack.org/471284 | 09:23 |
*** tbh_ has joined #openstack-keystone | 09:23 | |
tbh_ | Hi | 09:23 |
tbh_ | To get tokens to what port we have to send request? | 09:24 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Remove the local tempest plugin https://review.openstack.org/471060 | 09:25 |
*** links has quit IRC | 09:25 | |
*** zsli__ has quit IRC | 09:30 | |
*** zhurong has quit IRC | 09:33 | |
*** links has joined #openstack-keystone | 09:43 | |
cmurphy | tbh_: any ports that keystone is listening on can accept token requests, traditionally it's been 5000 and 35357 but it doesn't have to be | 09:48 |
*** thorst has joined #openstack-keystone | 09:48 | |
*** thorst has quit IRC | 09:52 | |
*** tobberydberg has joined #openstack-keystone | 09:52 | |
*** mvk has quit IRC | 09:53 | |
*** mvk has joined #openstack-keystone | 09:58 | |
*** markvoelker has joined #openstack-keystone | 09:59 | |
tbh_ | But when I am trying to get tokens it says 401 | 09:59 |
tbh_ | Am using rdo | 10:00 |
tbh_ | Will it change the curl request format if I am using rdo | 10:01 |
cmurphy | tbh_: 401 usually means your credentials are wrong | 10:03 |
tbh_ | cmurphy Using the same credentials I can log in to horizon | 10:06 |
cmurphy | tbh_: then you'll need to check the keystone logs to figure out what went wrong, setting insecure_debug = true in keystone.conf will help give more detailed information | 10:09 |
*** jamielennox is now known as jamielennox|away | 10:10 | |
*** jamielennox|away is now known as jamielennox | 10:16 | |
*** piliman974 has joined #openstack-keystone | 10:18 | |
d0ugal | If I have a token and a service name, how can I get the endpoint for a service with keystoneclient? | 10:19 |
*** liujiong has quit IRC | 10:23 | |
*** tobberydberg has quit IRC | 10:24 | |
*** gongysh has quit IRC | 10:26 | |
*** markvoelker has quit IRC | 10:32 | |
*** nicolasbock has joined #openstack-keystone | 10:44 | |
*** raildo has joined #openstack-keystone | 10:52 | |
*** nishaYadav has joined #openstack-keystone | 11:12 | |
*** piliman974 has quit IRC | 11:27 | |
tbh_ | cmurphy I am using v2. 0 | 11:28 |
tbh_ | Even in v2.0 we can get tokens from 5000 port? | 11:28 |
*** markvoelker has joined #openstack-keystone | 11:29 | |
*** zhurong has joined #openstack-keystone | 11:31 | |
cmurphy | tbh_: yes, getting a token is something you should be able to do from either port | 11:32 |
tbh_ | Okay cmurphy | 11:32 |
breton | d0ugal: https://review.openstack.org/#/c/465521/1 | 11:37 |
breton | d0ugal: in mistral/context.py i create access_info | 11:38 |
breton | d0ugal: access_info has property .service_catalog | 11:39 |
breton | d0ugal: .service_catalog is an instance of https://github.com/openstack/keystoneauth/blob/master/keystoneauth1/access/service_catalog.py#L28 | 11:40 |
breton | d0ugal: ServiceCatalog has method url_for | 11:40 |
breton | d0ugal: or even better: auth object in mistral/context.py has .get_endpoint(): https://github.com/openstack/keystoneauth/blob/master/keystoneauth1/identity/base.py#L160 | 11:41 |
*** piliman974 has joined #openstack-keystone | 11:41 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone-tempest-plugin master: Cleanup cookiecutter defaults https://review.openstack.org/471283 | 11:46 |
openstackgerrit | Colleen Murphy proposed openstack/keystone-tempest-plugin master: Add lxml to test-requirements.txt https://review.openstack.org/471284 | 11:48 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Remove the local tempest plugin https://review.openstack.org/471060 | 11:48 |
*** rcernin has quit IRC | 11:52 | |
*** pcaruana has quit IRC | 11:53 | |
*** thorst has joined #openstack-keystone | 11:54 | |
*** edmondsw has joined #openstack-keystone | 11:55 | |
*** jaosorior has joined #openstack-keystone | 11:56 | |
*** markvoelker has quit IRC | 12:03 | |
d0ugal | breton: thanks - I'll give that a shot. I'm trying to port a small bit of code from mistral to tripleo :) | 12:06 |
*** rcernin has joined #openstack-keystone | 12:07 | |
*** ducttape_ has joined #openstack-keystone | 12:08 | |
d0ugal | breton: it looks like that code requires the username and password - I only have the token at this point. Maybe what I want to do doesn't make sense. | 12:09 |
*** pcaruana has joined #openstack-keystone | 12:09 | |
*** namnh has quit IRC | 12:09 | |
breton | d0ugal: i was trying to fix that in that patch | 12:12 |
*** zhurong has quit IRC | 12:12 | |
d0ugal | breton: ah, I see | 12:13 |
breton | d0ugal: no time to finish it unfortunatelly | 12:13 |
breton | d0ugal: what's the tripleo bug? | 12:13 |
d0ugal | breton: I don't actually have a bug - I should open one really. I'm trying to remove the tripleo-common dependancy on mistral. This is the only part I don't know how to remove yet. https://github.com/openstack/tripleo-common/blob/master/tripleo_common/actions/base.py#L22 | 12:14 |
*** aojea has quit IRC | 12:14 | |
d0ugal | It is used a few times in that file, just to get the endpoint of each project | 12:14 |
*** dave-mccowan has joined #openstack-keystone | 12:15 | |
*** ducttape_ has quit IRC | 12:19 | |
*** markvoelker has joined #openstack-keystone | 12:20 | |
*** tobberydberg has joined #openstack-keystone | 12:25 | |
*** tobberydberg has quit IRC | 12:29 | |
*** hrybacki|afkish is now known as hrybacki | 12:33 | |
*** shuyingy_ has quit IRC | 12:36 | |
*** catintheroof has joined #openstack-keystone | 12:42 | |
*** evgenyf_ has joined #openstack-keystone | 12:51 | |
evgenyf_ | Hi folks! who can help with keystone issue after switching identity from v2.0 to v3? | 12:51 |
*** baffle has joined #openstack-keystone | 12:54 | |
*** links has quit IRC | 12:56 | |
samueldmq | morning keystone | 12:58 |
lamt | o/ | 12:59 |
samueldmq | evgenyf_: hi, just post the issue here :) | 12:59 |
nishaYadav | samueldmq, morning | 12:59 |
samueldmq | lamt: nishaYadav hey | 12:59 |
*** shuyingya has joined #openstack-keystone | 13:00 | |
*** shuyingya has quit IRC | 13:02 | |
*** shuyingya has joined #openstack-keystone | 13:02 | |
samueldmq | lbragstad: morning, your patches for policy are looking great, I just had minor suggestions but I am basically +2ing them | 13:04 |
samueldmq | I just would like to get cross-project weight on them before we approve | 13:04 |
samueldmq | would be great to get johnthetubaguy's view on those (starting at https://review.openstack.org/#/c/460344) | 13:05 |
*** lucasxu has joined #openstack-keystone | 13:05 | |
*** jrist has quit IRC | 13:07 | |
*** jrist has joined #openstack-keystone | 13:10 | |
evgenyf_ | samueldmq: I use KILO openstack RDO, After changing the policy.json to policy.v3cloudsample.json (renaming it ofcourse) I get the error ConfigFilesNotFoundError: Failed to find some config files: policy.json | 13:11 |
samueldmq | evgenyf_: same permissions? same path from the original policy.json? | 13:12 |
evgenyf_ | same path (/etc/keystone). I changed permissions to 666 and also tried to change the owner, now it's the original (keystone.keystone) | 13:13 |
samueldmq | evgenyf_: and is it still failing ? it shouldn't since that would be basically be changing the content of the original policy.json | 13:14 |
samueldmq | if owner, path and permissions are all the same | 13:15 |
*** spilla has joined #openstack-keystone | 13:16 | |
evgenyf_ | samueldmq: right, and when I put the original file back, the issue remains. weird.. maybe the path for v3 should be different? | 13:17 |
samueldmq | evgenyf_: no, it will be looking for /etc/keystone/policy.json | 13:18 |
samueldmq | if you put the original file back and it doesn't work so there is something wrong with the environment when you were making the transition | 13:19 |
samueldmq | evgenyf_: sorry but I gotta go afk for a bit now, I will be able to help more later if you still haven't figured that out | 13:19 |
samueldmq | (others here may help you too :)) | 13:19 |
evgenyf_ | samueldmq: thank you | 13:21 |
*** piliman974 has quit IRC | 13:26 | |
*** pcaruana has quit IRC | 13:34 | |
openstackgerrit | Samuel Pilla proposed openstack/keystone master: WIP: Add project tags https://review.openstack.org/470317 | 13:36 |
*** rcernin has quit IRC | 13:36 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone-tempest-plugin master: Add lxml to requirements.txt https://review.openstack.org/471284 | 13:40 |
*** piliman974 has joined #openstack-keystone | 13:42 | |
*** tbh_ has quit IRC | 13:42 | |
*** aojea has joined #openstack-keystone | 13:47 | |
*** thorst is now known as thorst_afk | 13:47 | |
*** rcernin has joined #openstack-keystone | 13:49 | |
Tahvok | Hey guys! | 13:50 |
Tahvok | On ocata here. Got a problem connecting using ldap account. In keystone log I get this: https://gist.github.com/Tahvok/b7a9288f0f27fb5b4fca1deb153b5bdd | 13:51 |
*** pcaruana has joined #openstack-keystone | 13:51 | |
Tahvok | You can see it's trying to insert '66048' into 'enabled' column. But it's tinyint, so of course it fails. | 13:51 |
Tahvok | What I could be missing? I've tried running su -s /bin/sh -c "keystone-manage db_sync" keystone again - but to no avail. | 13:52 |
cmurphy | Tahvok: check the user_enabled_attribute in your keystone.conf [ldap] config, it should be some boolean attribute in your ldap user schema, and not something like uidNumber, and also read about user_enabled_mask and user_enabled_default | 13:55 |
*** ducttape_ has joined #openstack-keystone | 13:56 | |
Tahvok | user_enabled_attribute = userAccountControl | 13:56 |
*** ducttape_ has quit IRC | 13:58 | |
Tahvok | Ok, I see. Reading about user_enabled_mask/default now. | 13:58 |
*** ducttape_ has joined #openstack-keystone | 13:58 | |
*** pcaruana has quit IRC | 13:59 | |
*** pcaruana has joined #openstack-keystone | 14:00 | |
*** rcernin has quit IRC | 14:04 | |
*** rcernin has joined #openstack-keystone | 14:05 | |
*** rcernin has quit IRC | 14:07 | |
*** rcernin has joined #openstack-keystone | 14:07 | |
Tahvok | Configured it, and now I get this: https://gist.github.com/Tahvok/5bc8d4354bc43f52fefedf30f206137c | 14:08 |
Tahvok | Writing incorrect credentials will throw 'INVALID_CREDENTIALS' - so I guess I don't have an ldap connection problem | 14:10 |
*** links has joined #openstack-keystone | 14:12 | |
evgenyf_ | Hi folks, need a help with keystone, what is the right way to restart keystone on RDO? what is the service name? | 14:13 |
Tahvok | cmurphy: found this fixed bug: https://bugs.launchpad.net/keystone/+bug/1662762 | 14:13 |
openstack | Launchpad bug 1662762 in OpenStack Identity (keystone) ocata "Authentication for LDAP user fails at MFA rule check" [High,Fix released] - Assigned to Matthew Edmonds (edmondsw) | 14:13 |
Tahvok | I guess there's no fix for ubuntu yet | 14:13 |
*** r-daneel has joined #openstack-keystone | 14:14 | |
cmurphy | Tahvok: ah :( | 14:17 |
cmurphy | evgenyf_: on kilo probably openstack-keystone | 14:17 |
Tahvok | cmurphy: do you know if there's a way to request to include a fix in ubuntu packages? | 14:17 |
*** links has quit IRC | 14:17 | |
*** nishaYadav has quit IRC | 14:18 | |
evgenyf_ | cmurphy: thanks | 14:20 |
cmurphy | Tahvok: i don't know what the official channels are, but it looks like the fix was released for ocata on 8 May so ubuntu will probably get around to it soon | 14:20 |
evgenyf_ | cmurphy: another question if I may, does keystone service get parameters? I restart it after switching identity from v2.0 to 3 and get error "ConfigFilesNotFoundError: Failed to find some config files: policy.json". I print out the path in oslo-config code which throws the exception and the path is None. | 14:23 |
cmurphy | evgenyf_: all the parameters would be set in keystone.conf | 14:24 |
evgenyf_ | cmurphy: the keystone.conf was not touched during the transfer from v2.0 to v3. Do you have an idea why restarting the service caused lost of config file? | 14:26 |
cmurphy | evgenyf_: nothing besides what samueldmq already suggested :( | 14:27 |
lbragstad | samueldmq: awesome, thanks! | 14:28 |
evgenyf_ | cmurphy:thanks for your help | 14:28 |
*** ducttape_ has quit IRC | 14:35 | |
*** pnavarro has joined #openstack-keystone | 14:43 | |
*** spilla has quit IRC | 14:49 | |
*** ducttape_ has joined #openstack-keystone | 14:50 | |
*** rcernin has quit IRC | 14:54 | |
*** aselius has joined #openstack-keystone | 15:15 | |
*** ayoung has quit IRC | 15:28 | |
*** chlong has joined #openstack-keystone | 15:29 | |
*** ayoung has joined #openstack-keystone | 15:35 | |
knikolla | o/ | 15:35 |
*** shuyingya has quit IRC | 15:39 | |
morgan | oh hai | 15:41 |
*** jaosorior is now known as jaosorior_away | 15:47 | |
lbragstad | o/ | 15:48 |
* morgan does a dance | 15:52 | |
morgan | it's interpretive... and reflects the internal structure of keystone (flopping on the floor) | 15:52 |
morgan | :P | 15:52 |
morgan | anyway.. yay weekend, yay being back. | 15:52 |
morgan | lbragstad so... did I miss anything fun? | 15:56 |
lbragstad | well, business as usual | 15:57 |
lbragstad | morgan: vacation was probably more exciting :) | 15:57 |
*** gyee has joined #openstack-keystone | 15:58 | |
*** mvk has quit IRC | 15:58 | |
*** aojea has quit IRC | 15:58 | |
*** piliman974 has quit IRC | 16:14 | |
*** piliman974 has joined #openstack-keystone | 16:15 | |
*** jamielennox is now known as jamielennox|away | 16:26 | |
*** clenimar_ has joined #openstack-keystone | 16:28 | |
*** clenimar_ has quit IRC | 16:28 | |
*** tesseract has quit IRC | 16:32 | |
*** pcaruana has quit IRC | 16:34 | |
*** makoto_ has quit IRC | 16:35 | |
samueldmq | morgan: o/ | 16:55 |
*** piliman974 has quit IRC | 16:57 | |
*** piliman974 has joined #openstack-keystone | 17:04 | |
*** jamielennox|away is now known as jamielennox | 17:05 | |
*** jlvillal is now known as jlvacation | 17:10 | |
*** lucasxu has quit IRC | 17:11 | |
*** aojea has joined #openstack-keystone | 17:16 | |
*** lwanderley has joined #openstack-keystone | 17:17 | |
*** aojea has quit IRC | 17:20 | |
*** lwanderley has quit IRC | 17:21 | |
*** phalmos has joined #openstack-keystone | 17:26 | |
*** lwanderley has joined #openstack-keystone | 17:31 | |
*** sjain has joined #openstack-keystone | 17:32 | |
*** pnavarro has quit IRC | 17:39 | |
*** spilla has joined #openstack-keystone | 17:40 | |
*** lwanderley has quit IRC | 17:40 | |
*** nicolasbock has quit IRC | 17:41 | |
*** lwanderley has joined #openstack-keystone | 17:42 | |
*** nicolasbock has joined #openstack-keystone | 17:42 | |
*** aojea has joined #openstack-keystone | 17:50 | |
openstackgerrit | Samuel Pilla proposed openstack/keystone master: WIP: Add project tags https://review.openstack.org/470317 | 17:51 |
*** pnavarro has joined #openstack-keystone | 17:55 | |
*** phalmos has quit IRC | 17:57 | |
*** ducttape_ has quit IRC | 17:59 | |
*** lucasxu has joined #openstack-keystone | 17:59 | |
*** knikolla_phone has joined #openstack-keystone | 18:00 | |
hrybacki | o/ | 18:00 |
*** phalmos has joined #openstack-keystone | 18:03 | |
evgenyf_ | Folks, can anybody help with the following issue?: I switched my KILO env. from identity v2.0 to v3. Now, Any horizon request related to project fails with "Unable to retrieve instance project information" | 18:04 |
*** lwanderley has quit IRC | 18:13 | |
*** sjain has quit IRC | 18:15 | |
*** sjain has joined #openstack-keystone | 18:15 | |
*** knikolla_phone has quit IRC | 18:19 | |
*** aojea has quit IRC | 18:25 | |
*** ducttape_ has joined #openstack-keystone | 18:28 | |
*** iurygregory has quit IRC | 18:28 | |
*** clenimar has quit IRC | 18:29 | |
*** evgenyf_ has quit IRC | 18:30 | |
*** lwanderley has joined #openstack-keystone | 18:33 | |
*** phalmos has quit IRC | 18:35 | |
*** phalmos has joined #openstack-keystone | 18:38 | |
*** mordred has quit IRC | 18:47 | |
*** mordred has joined #openstack-keystone | 18:48 | |
*** lwanderley has quit IRC | 18:49 | |
*** iurygregory has joined #openstack-keystone | 18:51 | |
*** thorst_afk has quit IRC | 18:54 | |
*** pcaruana has joined #openstack-keystone | 18:56 | |
*** thorst_afk has joined #openstack-keystone | 18:56 | |
*** thorst_afk has quit IRC | 19:00 | |
ayoung | morgan, I'd rather leave it as API keys than call it application passwords. The word Key is at least ambiguous to support multipe mechanisms | 19:01 |
ayoung | API versus Application specifgic? Meh, close enough | 19:01 |
*** aojea has joined #openstack-keystone | 19:02 | |
*** sjain__ has joined #openstack-keystone | 19:02 | |
hrybacki | lbragstad: samueldmq ping regarding policy reviews | 19:02 |
lbragstad | hrybacki: samueldmq o/ | 19:03 |
hrybacki | lbragstad: you taking on any of these? | 19:03 |
* hrybacki has no idea what he is doing but can rebase/attempt to address comments | 19:03 | |
lbragstad | hrybacki: samueldmq so here is the list | 19:03 |
lbragstad | https://review.openstack.org/#/q/topic:bp/policy-docs+project:openstack/keystone+status:open | 19:03 |
lbragstad | hrybacki: those patches are the last few that finish implementing http://specs.openstack.org/openstack/keystone-specs/specs/keystone/pike/policy-docs.html | 19:03 |
*** sjain has quit IRC | 19:03 | |
samueldmq | hrybacki: yes, just rebase on master and address the comments, that's all | 19:04 |
hrybacki | ack | 19:04 |
lbragstad | ok | 19:04 |
hrybacki | samueldmq: you want to take grant, token, role, user and I'll jump on ec2, domain, trust, and implied? | 19:04 |
lbragstad | samueldmq: hrybacki i'll rebase https://review.openstack.org/#/c/449337/ and https://review.openstack.org/#/c/449255/5 on master | 19:04 |
hrybacki | okay, I'll start with https://review.openstack.org/449278 and https://review.openstack.org/449246 | 19:05 |
lbragstad | just fyi - let's keep bp/policy-docs as the topic | 19:06 |
hrybacki | lbragstad: ack | 19:06 |
hrybacki | lbragstad: how are the proposals coming along? I've been updating my +1's and responding to some of the comments. We need those locked in by the 8th? | 19:06 |
samueldmq | hrybacki: lbragstad I will get users and roles: https://review.openstack.org/#/c/449251/ and https://review.openstack.org/#/c/449240/ | 19:08 |
lbragstad | hrybacki: yeah - i updated the ML thread - but i don't think anyone else has reviewed it | 19:08 |
lbragstad | (outside of keystone) | 19:09 |
hrybacki | lbragstad: yeah =/ I direclty linked that thread when folks were asking about operator input too. | 19:09 |
lbragstad | hrybacki: ++ | 19:09 |
lbragstad | i know several folks were out last week due to the holiday | 19:09 |
lbragstad | so hopefully this week we can get some traction on it | 19:10 |
hrybacki | fingers crossed | 19:10 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Move domain config to DocumentedRuleDefault https://review.openstack.org/449337 | 19:12 |
*** thorst_afk has joined #openstack-keystone | 19:14 | |
*** thorst_afk has quit IRC | 19:15 | |
*** thorst_afk has joined #openstack-keystone | 19:16 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Move domain config to DocumentedRuleDefault https://review.openstack.org/449337 | 19:17 |
openstackgerrit | Harry Rybacki proposed openstack/keystone master: Move trust to DocumentedRuleDefault https://review.openstack.org/449278 | 19:18 |
hrybacki | lbragstad: can you walk me through your comments: https://review.openstack.org/#/c/449246/5/keystone/common/policies/implied_role.py I'm not familiar enough with the roles yet | 19:22 |
* hrybacki googles implied roles | 19:23 | |
lbragstad | hrybacki: sure | 19:25 |
lbragstad | hrybacki: implied roles are documented with roles https://developer.openstack.org/api-ref/identity/v3/index.html#roles | 19:26 |
lbragstad | hrybacki: implied roles allows you to do role inheritance | 19:27 |
lbragstad | hrybacki: for example, if i have two roles editor and reader | 19:27 |
lbragstad | i can make the editor role imply the reader role | 19:28 |
* hrybacki nods | 19:28 | |
lbragstad | my main concern in that patch was getting that communicated effectively in the wording of the policy | 19:28 |
lbragstad | which might be something we should do with the implied role documentation anyway - because it seems to be there, too | 19:29 |
hrybacki | yeah, I understand. I'll read up and try to re-word it a bit | 19:29 |
*** harlowja has quit IRC | 19:29 | |
lbragstad | hrybacki: if you find yourself having to reword the documentation https://developer.openstack.org/api-ref/identity/v3/index.html#roles we can hold it off and fix it later | 19:30 |
lbragstad | but i'll defer to your best judgement | 19:30 |
hrybacki | +1 thanks for the links :) | 19:30 |
*** pcaruana has quit IRC | 19:33 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Use DocumentedRuleDefault for token operations https://review.openstack.org/449255 | 19:35 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Use DocumentedRuleDefault for token operations https://review.openstack.org/449255 | 19:40 |
lbragstad | hrybacki: samueldmq ok - i have my patches up and rebased | 19:46 |
lbragstad | i'm gonna take a late lunch to get a run in | 19:46 |
*** spilla has quit IRC | 19:49 | |
*** harlowja has joined #openstack-keystone | 19:50 | |
*** tobberydberg has joined #openstack-keystone | 19:53 | |
hrybacki | o/ | 19:55 |
hrybacki | note to self, stay away from keystone test code | 19:55 |
*** sjain__ has quit IRC | 19:58 | |
*** tobberydberg has quit IRC | 20:02 | |
*** tobberydberg has joined #openstack-keystone | 20:10 | |
*** tobberydberg has quit IRC | 20:14 | |
*** gardlt has joined #openstack-keystone | 20:23 | |
openstackgerrit | Harry Rybacki proposed openstack/keystone master: Move implied role policies to DocumentedRuleDefault https://review.openstack.org/449246 | 20:25 |
hrybacki | lbragstad: updated mine as well. So, the implied roles stuff. The code is a bit confusing and the API doc is certainly incomplete. As a matter of fact, I don't see how (in Pike) to test these via OSC. Am I missing something? | 20:26 |
*** ducttap__ has joined #openstack-keystone | 20:30 | |
*** ducttape_ has quit IRC | 20:31 | |
*** ducttap__ has quit IRC | 20:31 | |
*** ducttape_ has joined #openstack-keystone | 20:31 | |
*** raildo has quit IRC | 20:32 | |
*** aojea has quit IRC | 20:32 | |
*** jamielennox has quit IRC | 20:34 | |
*** aojea has joined #openstack-keystone | 20:35 | |
*** nicolasbock has quit IRC | 20:35 | |
*** aojea has quit IRC | 20:36 | |
*** aojea has joined #openstack-keystone | 20:37 | |
*** ducttape_ has quit IRC | 20:37 | |
*** jamielennox has joined #openstack-keystone | 20:38 | |
*** ducttape_ has joined #openstack-keystone | 20:38 | |
*** piliman974 has quit IRC | 20:40 | |
lbragstad | hrybacki: nope - i don't think osc has support for implied roles | 20:40 |
*** pnavarro has quit IRC | 20:49 | |
*** piliman974 has joined #openstack-keystone | 20:51 | |
*** dave-mccowan has quit IRC | 21:06 | |
lbragstad | cmurphy: this one looks close in case you want to revisit it https://review.openstack.org/#/c/449240/13 | 21:08 |
lbragstad | whenever you have a minute | 21:08 |
breton | ayoung: RBAC via Fortress was not done not because of bad process in keystone | 21:08 |
breton | ayoung: if failed because Fortress did not fit and nobody cared enough about the whole initiative | 21:09 |
ayoung | breton, I just came across this: "Did you know that most new contributions to @kubernetesio occur outside the main repo (kubernetes/kubernetes)? This is great! #stability" | 21:09 |
ayoung | breton, it should be possible to map out how something like that could be prototype, put into production, and validated, in conjunctiojn with keystone, not as a rewrite | 21:10 |
breton | ayoung: is their kubernetes/kubernetes like our openstack/nova? | 21:10 |
ayoung | and I think we are doing something very wrong in our process | 21:10 |
ayoung | breton, yeah...ish | 21:11 |
ayoung | the API server part of Kubernetes does all the Keystone-y bits | 21:11 |
cmurphy | lbragstad: done | 21:11 |
*** lucasxu has quit IRC | 21:11 | |
ayoung | There is no cinder | 21:11 |
ayoung | there is no neutron...or rather a million mini-neutrons | 21:11 |
lbragstad | cmurphy: woo! thank you | 21:11 |
ayoung | glance is either docker upstream or mini-registries that run as apps inside of k8s | 21:12 |
ayoung | I just like the K8S service catalog approach so much better. It allows for extension, etc | 21:12 |
*** thorst_afk has quit IRC | 21:19 | |
*** thorst_afk has joined #openstack-keystone | 21:20 | |
*** thorst_afk has quit IRC | 21:24 | |
*** cheran has joined #openstack-keystone | 21:46 | |
openstackgerrit | Nicolas Helgeson proposed openstack/keystone master: Added versions to keyston headers https://review.openstack.org/468189 | 21:50 |
*** piliman974 has quit IRC | 21:56 | |
*** gardlt has quit IRC | 21:56 | |
*** ducttape_ has quit IRC | 22:01 | |
*** aojea has quit IRC | 22:03 | |
*** ducttape_ has joined #openstack-keystone | 22:07 | |
*** piliman974 has joined #openstack-keystone | 22:25 | |
*** lbragstad has quit IRC | 22:30 | |
*** piliman974 has quit IRC | 22:38 | |
*** piliman974 has joined #openstack-keystone | 22:40 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone-specs master: Application Credentials for application authn https://review.openstack.org/450415 | 22:41 |
*** catintheroof has quit IRC | 22:41 | |
*** ducttap__ has joined #openstack-keystone | 22:44 | |
*** ductta___ has joined #openstack-keystone | 22:46 | |
*** ducttap__ has quit IRC | 22:46 | |
*** ducttape_ has quit IRC | 22:48 | |
*** ducttape_ has joined #openstack-keystone | 22:49 | |
*** ductta___ has quit IRC | 22:49 | |
*** ducttape_ has quit IRC | 22:50 | |
*** thorst_afk has joined #openstack-keystone | 22:50 | |
*** ducttape_ has joined #openstack-keystone | 22:53 | |
*** ducttape_ has quit IRC | 22:53 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone-specs master: Application Credentials for application authn https://review.openstack.org/450415 | 22:53 |
*** ducttape_ has joined #openstack-keystone | 22:57 | |
*** piliman974 has quit IRC | 23:01 | |
*** ducttap__ has joined #openstack-keystone | 23:04 | |
*** ducttape_ has quit IRC | 23:04 | |
*** ducttape_ has joined #openstack-keystone | 23:06 | |
*** ducttap__ has quit IRC | 23:06 | |
*** ducttape_ has quit IRC | 23:08 | |
*** thorst_afk has quit IRC | 23:09 | |
*** ducttap__ has joined #openstack-keystone | 23:12 | |
*** ducttape_ has joined #openstack-keystone | 23:13 | |
*** ducttap__ has quit IRC | 23:17 | |
*** david-lyle has quit IRC | 23:28 | |
*** piliman974 has joined #openstack-keystone | 23:31 | |
*** david-lyle has joined #openstack-keystone | 23:32 | |
*** ducttape_ has quit IRC | 23:51 | |
*** david-lyle has quit IRC | 23:58 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!