*** markvoelker has quit IRC | 00:07 | |
*** r-daneel has quit IRC | 00:17 | |
*** adriant has joined #openstack-keystone | 00:19 | |
*** ducttape_ has joined #openstack-keystone | 00:35 | |
*** lucasxu has joined #openstack-keystone | 00:42 | |
*** lucasxu has quit IRC | 00:44 | |
*** lucasxu has joined #openstack-keystone | 00:45 | |
*** shuyingya has joined #openstack-keystone | 00:45 | |
*** lucasxu has quit IRC | 00:47 | |
*** lucasxu has joined #openstack-keystone | 00:50 | |
*** lucasxu has quit IRC | 00:56 | |
*** dave-mccowan has joined #openstack-keystone | 00:57 | |
*** lucasxu has joined #openstack-keystone | 00:58 | |
*** dave-mccowan has quit IRC | 01:02 | |
*** markvoelker has joined #openstack-keystone | 01:03 | |
*** lucasxu has quit IRC | 01:05 | |
*** thorst_afk has joined #openstack-keystone | 01:06 | |
*** namnh has joined #openstack-keystone | 01:07 | |
*** ducttape_ has quit IRC | 01:08 | |
*** thorst_afk has quit IRC | 01:11 | |
*** thorst_afk has joined #openstack-keystone | 01:11 | |
*** thorst_afk has quit IRC | 01:20 | |
*** gyee has quit IRC | 01:25 | |
openstackgerrit | Merged openstack/keystone master: Move user policies to DocumentedRuleDefault https://review.openstack.org/449240 | 01:28 |
---|---|---|
*** zhurong has joined #openstack-keystone | 01:28 | |
*** liujiong has joined #openstack-keystone | 01:34 | |
*** edmondsw has quit IRC | 01:36 | |
*** gongysh has joined #openstack-keystone | 01:41 | |
*** chlong has quit IRC | 01:50 | |
*** lbragstad has joined #openstack-keystone | 01:51 | |
*** ChanServ sets mode: +o lbragstad | 01:51 | |
*** Shunli has joined #openstack-keystone | 01:54 | |
*** thorst_afk has joined #openstack-keystone | 01:56 | |
*** cheran has quit IRC | 02:13 | |
*** piliman974 has quit IRC | 02:25 | |
*** r-daneel has joined #openstack-keystone | 02:26 | |
*** lbragstad has quit IRC | 02:30 | |
*** zhurong has quit IRC | 02:30 | |
*** thorst_afk has quit IRC | 02:32 | |
*** thorst_afk has joined #openstack-keystone | 02:33 | |
*** r-daneel has quit IRC | 02:33 | |
*** thorst_afk has quit IRC | 02:37 | |
*** piliman974 has joined #openstack-keystone | 02:42 | |
*** edmondsw has joined #openstack-keystone | 02:46 | |
*** shuyingya has quit IRC | 02:50 | |
*** shuyingya has joined #openstack-keystone | 02:51 | |
*** edmondsw has quit IRC | 02:51 | |
*** links has joined #openstack-keystone | 02:52 | |
*** shuyingy_ has joined #openstack-keystone | 02:53 | |
*** shuyingya has quit IRC | 02:57 | |
*** aojea has joined #openstack-keystone | 03:04 | |
openstackgerrit | zhengliuyang proposed openstack/keystone master: A clean and simple fix about explicit_unscoped_string https://review.openstack.org/471557 | 03:07 |
*** shuyingy_ has quit IRC | 03:08 | |
*** aojea has quit IRC | 03:08 | |
*** shuyingya has joined #openstack-keystone | 03:08 | |
*** piliman974 has quit IRC | 03:11 | |
*** ducttape_ has joined #openstack-keystone | 03:14 | |
*** thorst_afk has joined #openstack-keystone | 03:43 | |
*** namnh_ has joined #openstack-keystone | 03:54 | |
*** aselius has quit IRC | 03:55 | |
*** namnh has quit IRC | 03:56 | |
*** nicolasbock has joined #openstack-keystone | 03:57 | |
*** namnh has joined #openstack-keystone | 03:57 | |
*** namnh_ has quit IRC | 03:59 | |
*** zhurong has joined #openstack-keystone | 04:00 | |
*** ducttape_ has quit IRC | 04:02 | |
*** thorst_afk has quit IRC | 04:02 | |
*** shuyingy_ has joined #openstack-keystone | 04:11 | |
*** shuyingya has quit IRC | 04:12 | |
*** hoonetorg has quit IRC | 04:29 | |
*** zhurong has quit IRC | 04:30 | |
*** adriant has quit IRC | 04:35 | |
*** edmondsw has joined #openstack-keystone | 04:35 | |
*** adriant has joined #openstack-keystone | 04:39 | |
*** edmondsw has quit IRC | 04:39 | |
*** zhurong has joined #openstack-keystone | 04:40 | |
*** adriant has quit IRC | 04:40 | |
*** adriant has joined #openstack-keystone | 04:41 | |
*** shuyingy_ has quit IRC | 04:42 | |
*** liujiong has quit IRC | 04:43 | |
*** shuyingya has joined #openstack-keystone | 04:46 | |
*** hoonetorg has joined #openstack-keystone | 04:46 | |
*** zig_ has joined #openstack-keystone | 04:56 | |
*** pcaruana has joined #openstack-keystone | 04:56 | |
zig_ | Hello Everyone. I need some help in configuring Keystone with OIDC. I am getting a HTTP 401: Missing entity ID from environment error inspite of having set remote_id_attribute in keystone.conf. Can someone please help me with this | 04:57 |
*** shuyingy_ has joined #openstack-keystone | 05:00 | |
*** shuyingya has quit IRC | 05:00 | |
*** aojea has joined #openstack-keystone | 05:02 | |
breton | zig_: are you sure remote_id_attribute is correct? Why are you sure? | 05:04 |
*** dims has quit IRC | 05:09 | |
*** pcaruana has quit IRC | 05:14 | |
zig_ | breton: i have set remote_id_attribute=HTTP_OIDC_ISS under [oidc] and [federation] section in keystone.conf. | 05:23 |
openstackgerrit | zhengliuyang proposed openstack/keystone master: A simple fix about explicit unscoped string https://review.openstack.org/471557 | 05:37 |
*** namnh_ has joined #openstack-keystone | 05:38 | |
zig_ | breton: Is there any additional parameter that i need to set in the horizon environment? | 05:38 |
*** namnh has quit IRC | 05:39 | |
*** dims has joined #openstack-keystone | 05:41 | |
*** thorst_afk has joined #openstack-keystone | 05:59 | |
Dinesh_Bhor | breton: ping | 06:01 |
Dinesh_Bhor | breton: I just reported a bug: https://bugs.launchpad.net/keystone/+bug/1696308 If you have any info on this then that will help. | 06:03 |
openstack | Launchpad bug 1696308 in OpenStack Identity (keystone) "list revoked tokens API returns 500 InternalServerError" [Undecided,New] | 06:03 |
*** thorst_afk has quit IRC | 06:04 | |
*** zig_ has quit IRC | 06:06 | |
*** aojea has quit IRC | 06:06 | |
*** jaosorior_away is now known as jaosorior | 06:11 | |
*** tobberydberg has joined #openstack-keystone | 06:14 | |
*** tobberydberg has quit IRC | 06:14 | |
*** tobberydberg has joined #openstack-keystone | 06:14 | |
breton | Dinesh_Bhor: list revoked tokens API is for PKI tokens only | 06:15 |
breton | Dinesh_Bhor: if you use uuid tokens, it will not work | 06:15 |
breton | zigo: in horizon no. Why do you think it should be HTTP_OIDC_ISS? | 06:16 |
breton | oh | 06:16 |
breton | zigo: sorry | 06:16 |
Dinesh_Bhor | breton: yeah, but do you think in that case it should return 500? | 06:18 |
*** zig_ has joined #openstack-keystone | 06:21 | |
*** rcernin has joined #openstack-keystone | 06:21 | |
*** zsli_ has joined #openstack-keystone | 06:22 | |
*** edmondsw has joined #openstack-keystone | 06:23 | |
*** Shunli has quit IRC | 06:24 | |
breton | Dinesh_Bhor: i don't know. Maybe it would be nice to return some error, but PKI is deprecated and nobody uses it, and if they do, the call works for them. | 06:26 |
*** edmondsw has quit IRC | 06:28 | |
Dinesh_Bhor | breton: OK, understood. Could you please comment on the bug for the same so that it will help other cores to decide whether to fix it or not? | 06:30 |
cmurphy | zig_: check your horizon configs, make sure you have OPENSTACK_KEYSTONE_URL pointing to the right v3 endpoint and make sure WEBSSO_CHOICES has the name of the federation protocol, which is probably openidc (not oidc) | 06:32 |
cmurphy | zig_: breton HTTP_OIDC_ISS is the right remote_id_attribute for openidc | 06:33 |
zig_ | cmurphy: Thank you. Is it possible for you to have a look at my current configuration, if i include it in paste.openstack? | 06:37 |
cmurphy | zig_: sure, I can try | 06:38 |
zig_ | cmurphy: Thank you. Let me just paste it. I will send the link in a minute. | 06:39 |
zig_ | cmurphy: Please check http://paste.openstack.org/show/611650/. | 06:47 |
cmurphy | zig_: what version are you running? | 06:48 |
zig_ | cmurphy: Newton devstack. And the identity_api_version is 3 | 06:48 |
cmurphy | zig_: you should probably change your oidc secret in the google console :( | 06:51 |
zig_ | cmurphy: oops...thanks for that. I have changed it. | 06:52 |
*** belmoreira has joined #openstack-keystone | 06:55 | |
cmurphy | zig_: is the OPENSTACK_KEYSTONE_URL correct? your keystone is at /identity on that domain? unless the apache vhost is snipped it doesn't look like it is | 06:56 |
cmurphy | zig_: you'll probably want to change it to http://keystonegoogle.com:5000/v3 and also make sure the redirect urls match it | 06:59 |
zig_ | cmurphy: oh ok I will change it. | 06:59 |
*** thorst_afk has joined #openstack-keystone | 07:01 | |
*** afazekas has quit IRC | 07:01 | |
*** afazekas has joined #openstack-keystone | 07:01 | |
cmurphy | zig_: not sure if this would have helped here but setting LOGGING -> 'handlers' -> 'console' -> 'level' to 'DEBUG' in local_settings.py sometimes helps get more information from horizon on auth stuff | 07:02 |
zig_ | cmurphy: Should i replace the OIDCRedirectURI in vhost as well? I am using devstack version so i am not sure if keystone is at /identity :( | 07:03 |
*** pcaruana has joined #openstack-keystone | 07:03 | |
zig_ | cmurphy: I ahve enabled Debug but nothing seems to be logged with this issue :( | 07:04 |
breton | cmurphy: it is not always right. I had to use remote_id_attribute = OIDC-iss some time ago. | 07:04 |
*** thorst_afk has quit IRC | 07:05 | |
breton | zig_: are environment variables getting logged if you enable debug? | 07:05 |
cmurphy | zig_: i don't remember if newton used /identity, but there will be a <Location> thing in the vhost already made by devstack and `openstack endpoint list` will show it | 07:06 |
cmurphy | breton: ah okay | 07:06 |
cmurphy | for google at least i'm pretty sure it's HTTP_OIDC_ISS | 07:06 |
*** liujiong has joined #openstack-keystone | 07:06 | |
breton | cmurphy: you think it is idp-specific? | 07:07 |
breton | cmurphy: my understanding was that the web server sets the variable | 07:07 |
breton | cmurphy: and we just tell keystone what's the name of the variable | 07:07 |
cmurphy | breton: I know that with mod_auth_openidc and google I've used HTTP_OIDC_ISS | 07:08 |
zig_ | cmurphy: openstack endpoint list gives http://127.0.0.1/identity and https://127.0.0.1/identity_admin as the URL | 07:08 |
zig_ | breton: no it doesn't seem to | 07:10 |
*** tesseract has joined #openstack-keystone | 07:11 | |
zig_ | cmurphy: with keystone:5000 i get Internal server error in horizon :( | 07:11 |
cmurphy | zig_: yeah if the endpoint is /identity in keystone then /identity was right in horizon, sorry :( | 07:11 |
breton | zig_: can you post your logs somewhere? | 07:13 |
zig_ | breton: Sure. It's here: http://paste.openstack.org/show/611654/ | 07:15 |
breton | zig_: there should be some more logs. Keystone logs can even be in horizon logs. | 07:18 |
*** aojea has joined #openstack-keystone | 07:22 | |
*** aojea has quit IRC | 07:22 | |
*** aojea has joined #openstack-keystone | 07:23 | |
*** namnh_ has quit IRC | 07:33 | |
*** namnh has joined #openstack-keystone | 07:33 | |
zig_ | breton: mostly the log entries are INFO and Debug. There are some error logs like this ERROR keystone.federation.controllers [req-1e79d981-c5dc-4dd4-8f0e-05253c051da4 baf8a9342d8a44e695e649d5498ac079 c6f14884230942ca87aa01b9e2f895d5 - default default] Missing entity ID from environment. | 07:43 |
zig_ | breton: http://paste.openstack.org/show/611656/ i have appended some more log entries to it. The file is huge :( | 07:45 |
*** pnavarro has joined #openstack-keystone | 07:52 | |
*** rcernin has quit IRC | 07:52 | |
*** rcernin has joined #openstack-keystone | 07:52 | |
breton | zig_: here is what you can do | 07:59 |
breton | zig_: open keystone/federation/controllers.py | 07:59 |
*** zzzeek has quit IRC | 08:00 | |
breton | zig_: find there "def federated_sso_auth" | 08:00 |
*** zzzeek has joined #openstack-keystone | 08:00 | |
breton | zig_: you will see there the message: "Missing entity ID from environment" | 08:00 |
breton | zig_: right after the assignment insert LOG.warning(request.environ) | 08:01 |
*** thorst_afk has joined #openstack-keystone | 08:01 | |
breton | zig_: and look in the logs | 08:01 |
zig_ | breton: Thanks a lot. Will do that | 08:08 |
zig_ | breton: as this is a devstack setup, so restarting apache after making the change should be sufficient right? | 08:10 |
*** zsli_ has quit IRC | 08:11 | |
*** edmondsw has joined #openstack-keystone | 08:11 | |
*** zsli_ has joined #openstack-keystone | 08:12 | |
breton | zig_: yes | 08:12 |
zig_ | breton: I don't understand what could be the reason. But logs aren't getting logged into key.log file now :( | 08:12 |
*** edmondsw has quit IRC | 08:16 | |
zig_ | breton: The only option i can think of is do an unstack followed by stack :( Is there something that you can suggest | 08:19 |
*** thorst_afk has quit IRC | 08:21 | |
*** gongysh has quit IRC | 08:25 | |
breton | zig_: check out apache logs | 08:25 |
*** aojea has quit IRC | 08:28 | |
*** phalmos has quit IRC | 08:29 | |
*** gongysh has joined #openstack-keystone | 08:33 | |
*** aojea has joined #openstack-keystone | 08:33 | |
*** zhurong has quit IRC | 08:47 | |
*** jamielennox is now known as jamielennox|away | 08:50 | |
*** mvk has joined #openstack-keystone | 08:57 | |
*** shuyingy_ has quit IRC | 08:57 | |
*** shuyingya has joined #openstack-keystone | 08:58 | |
*** zhurong has joined #openstack-keystone | 09:02 | |
zig_ | breton: There seems to be some issue with my current devstack run. Could you let me know what is required to be present in the environ variable? I can get back to you once i resolve the devstack issue | 09:03 |
openstackgerrit | Merged openstack/keystoneauth master: Fix html_last_updated_fmt for Python3 https://review.openstack.org/470663 | 09:08 |
*** jamielennox|away is now known as jamielennox | 09:10 | |
*** zig_ has quit IRC | 09:13 | |
*** zig_ has joined #openstack-keystone | 09:14 | |
openstackgerrit | Merged openstack/python-keystoneclient master: Fix html_last_updated_fmt for Python3 https://review.openstack.org/470658 | 09:16 |
*** thorst_afk has joined #openstack-keystone | 09:18 | |
breton | zig_: i have no idea. There should be a variable with entity ID. We need to find that variable and put it to keystone.conf | 09:18 |
zig_ | breton: Oh! Ok i will check that. Thanks breton. | 09:19 |
*** thorst_afk has quit IRC | 09:22 | |
*** namnh_ has joined #openstack-keystone | 09:22 | |
*** namnh has quit IRC | 09:25 | |
*** nishaYadav has joined #openstack-keystone | 09:31 | |
* nishaYadav waves hello o/ | 09:31 | |
*** zsli_ has quit IRC | 09:36 | |
zig_ | breton: I have posted the logs here. http://paste.openstack.org/show/611669/ | 09:44 |
*** nkinder has quit IRC | 09:44 | |
*** zhurong has quit IRC | 09:51 | |
breton | zig_: well, there is nothing federation-related in the logs. At what moment of authentication flow do you get this error? | 09:55 |
*** mvk has quit IRC | 09:55 | |
*** edmondsw has joined #openstack-keystone | 09:59 | |
*** edmondsw has quit IRC | 10:04 | |
*** nicolasbock_ has joined #openstack-keystone | 10:04 | |
*** nicolasbock has quit IRC | 10:06 | |
zig_ | breton: In horizon, i get option to select oidc. On clicking that it should ideally redirect me to the google login page. But instead it gives me authorization HTTP401 error | 10:06 |
*** shuyingy_ has joined #openstack-keystone | 10:07 | |
*** liujiong has quit IRC | 10:09 | |
*** shuyingya has quit IRC | 10:11 | |
breton | zig_: oooh. Then your openidc apache module is misconfigured | 10:13 |
zig_ | breton: Do you suggest any document to fix it? | 10:14 |
*** nishaYadav_ has joined #openstack-keystone | 10:16 | |
*** nishaYadav has quit IRC | 10:18 | |
*** piliman974 has joined #openstack-keystone | 10:19 | |
*** sjain has joined #openstack-keystone | 10:22 | |
*** mvk has joined #openstack-keystone | 10:27 | |
breton | zig_: well, search in google i guess. Keystone shouldn't do anything at this point, it's mod-auth-openidc misconfigured. http://paste.openstack.org/show/611675/ -- this apache config i used for my devstack in a virtualbox | 10:28 |
*** Shunli has joined #openstack-keystone | 10:29 | |
*** Shunli has quit IRC | 10:29 | |
*** namnh has joined #openstack-keystone | 10:30 | |
*** namnh_ has quit IRC | 10:33 | |
zig_ | breton: Thanks for that. Could you please let me know how to set these parameters :OIDCProviderAuthorizationEndpoint, OIDCProviderTokenEndpoint, OIDCProviderUserInfoEndpoint, OIDCProviderTokenEndpointAuth | 10:34 |
breton | zig_: nope, don't know | 10:35 |
openstackgerrit | Samriddhi proposed openstack/keystone master: Move role policies to DocumentedRuleDefault https://review.openstack.org/449251 | 10:40 |
openstackgerrit | Samriddhi proposed openstack/keystone master: Move role policies to DocumentedRuleDefault https://review.openstack.org/471714 | 10:40 |
*** nkinder has joined #openstack-keystone | 10:41 | |
*** shuyingy_ has quit IRC | 10:47 | |
*** shuyingya has joined #openstack-keystone | 10:48 | |
*** sjain has quit IRC | 10:48 | |
*** nishaYadav_ has quit IRC | 10:56 | |
*** namnh has quit IRC | 10:56 | |
*** raildo has joined #openstack-keystone | 11:08 | |
*** aojea has quit IRC | 11:16 | |
*** piliman974 has quit IRC | 11:19 | |
*** piliman974 has joined #openstack-keystone | 11:20 | |
*** Drankis has joined #openstack-keystone | 11:24 | |
*** edmondsw has joined #openstack-keystone | 11:27 | |
*** zig_ has quit IRC | 11:37 | |
*** sjain has joined #openstack-keystone | 11:38 | |
openstackgerrit | Samriddhi proposed openstack/keystone master: Move role policies to DocumentedRuleDefault https://review.openstack.org/471714 | 11:42 |
*** dikonoor has joined #openstack-keystone | 11:45 | |
*** sjain has quit IRC | 11:47 | |
*** thorst_afk has joined #openstack-keystone | 11:49 | |
*** chlong has joined #openstack-keystone | 12:02 | |
*** nishaYadav has joined #openstack-keystone | 12:04 | |
*** gongysh has quit IRC | 12:19 | |
*** gongysh has joined #openstack-keystone | 12:19 | |
*** piliman974 has quit IRC | 12:23 | |
*** gongysh has quit IRC | 12:23 | |
*** piliman974 has joined #openstack-keystone | 12:25 | |
*** nishaYadav_ has joined #openstack-keystone | 12:31 | |
*** nishaYadav has quit IRC | 12:34 | |
*** nishaYadav_ is now known as nishaYadav | 12:36 | |
*** shuyingya has quit IRC | 12:42 | |
*** nishaYadav_ has joined #openstack-keystone | 12:54 | |
*** ducttape_ has joined #openstack-keystone | 12:57 | |
*** nishaYadav has quit IRC | 12:58 | |
*** ducttape_ has quit IRC | 13:06 | |
*** rmascena has joined #openstack-keystone | 13:08 | |
*** raildo has quit IRC | 13:10 | |
*** ducttap__ has joined #openstack-keystone | 13:14 | |
*** nishaYadav__ has joined #openstack-keystone | 13:23 | |
*** aojea has joined #openstack-keystone | 13:23 | |
*** nishaYadav_ has quit IRC | 13:24 | |
*** nishaYadav__ is now known as nishaYadav_ | 13:26 | |
*** links has quit IRC | 13:30 | |
*** r-daneel has joined #openstack-keystone | 13:31 | |
*** r-daneel has quit IRC | 13:33 | |
*** r-daneel has joined #openstack-keystone | 13:33 | |
*** dave-mccowan has joined #openstack-keystone | 13:36 | |
*** dave-mccowan has quit IRC | 13:41 | |
*** chlong has quit IRC | 13:43 | |
*** dave-mccowan has joined #openstack-keystone | 13:45 | |
*** ducttap__ has quit IRC | 13:45 | |
*** ducttape_ has joined #openstack-keystone | 13:46 | |
*** zhurong has joined #openstack-keystone | 13:54 | |
*** ducttape_ has quit IRC | 14:01 | |
*** dave-mccowan has quit IRC | 14:12 | |
*** evgenyf has joined #openstack-keystone | 14:15 | |
*** zhurong has quit IRC | 14:17 | |
*** ducttape_ has joined #openstack-keystone | 14:20 | |
EmilienM | hey folks, I saw debug option in keystone can be changed without restarting keystone. I'm running Keystone with Apache and changed the option to be false, but I still see DEBUG in the logs. Did I miss something? | 14:21 |
evgenyf | Hi Folks! can someone help with keystone KILO issue while using identity v3? "nova list" and other CLI commands response with The request you have made requires authentication. (HTTP 401) | 14:25 |
*** jaosorior is now known as jaosorior_away | 14:31 | |
*** aojea has quit IRC | 14:37 | |
*** iurygregory has quit IRC | 14:42 | |
*** lucasxu has joined #openstack-keystone | 14:44 | |
*** lbragstad has joined #openstack-keystone | 14:52 | |
*** ChanServ sets mode: +o lbragstad | 14:52 | |
knikolla | o/ | 14:55 |
morgan | o/ | 14:58 |
lbragstad | o/ | 14:58 |
*** aselius has joined #openstack-keystone | 15:02 | |
*** Drankis has quit IRC | 15:05 | |
*** dikonoor has quit IRC | 15:05 | |
*** tobberyd_ has joined #openstack-keystone | 15:06 | |
*** nishaYadav_ has quit IRC | 15:10 | |
*** tobberydberg has quit IRC | 15:10 | |
*** rcernin has quit IRC | 15:11 | |
*** tobberyd_ has quit IRC | 15:14 | |
*** piliman974 has quit IRC | 15:17 | |
hrybacki | lbragstad: can't make policy mtg today, heading out to meet family. Anything you need from me in advance? | 15:18 |
lbragstad | hrybacki: sounds good - thanks for the heads up | 15:18 |
lbragstad | hrybacki: enjoy the family! | 15:18 |
hrybacki | NP. Still keeping an eye out on those policy reviews. Looks like we got 1 +1 one the rolecall vote atm | 15:18 |
lbragstad | hrybacki: yep - i saw that this morning | 15:19 |
lbragstad | which is good! | 15:19 |
*** piliman974 has joined #openstack-keystone | 15:19 | |
lbragstad | hrybacki: i plan on reviewing the rest of the policy docs patches today | 15:19 |
hrybacki | ack | 15:20 |
*** dave-mccowan has joined #openstack-keystone | 15:21 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone master: Move grant policies to DocumentedRuleDefault https://review.openstack.org/449244 | 15:23 |
*** chlong has joined #openstack-keystone | 15:27 | |
*** lucasxu has quit IRC | 15:30 | |
*** nishaYadav has joined #openstack-keystone | 15:33 | |
*** rderose has joined #openstack-keystone | 15:34 | |
*** nishaYadav has quit IRC | 15:36 | |
*** gyee has joined #openstack-keystone | 15:41 | |
*** belmoreira has quit IRC | 15:44 | |
*** aojea has joined #openstack-keystone | 15:45 | |
*** spilla has joined #openstack-keystone | 15:46 | |
*** aojea has quit IRC | 15:50 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone master: Move grant policies to DocumentedRuleDefault https://review.openstack.org/449244 | 16:03 |
samueldmq | hrybacki: lbragstad: cmurphy ^ this one for grants is pretty complex when compared to the others | 16:03 |
*** dave-mccowan has quit IRC | 16:05 | |
*** david-lyle has joined #openstack-keystone | 16:07 | |
*** evgenyf has quit IRC | 16:22 | |
*** lucasxu has joined #openstack-keystone | 16:28 | |
*** tesseract has quit IRC | 16:34 | |
*** tobberydberg has joined #openstack-keystone | 16:36 | |
*** tobberydberg has quit IRC | 16:41 | |
*** dave-mccowan has joined #openstack-keystone | 16:42 | |
*** ediardo has quit IRC | 16:45 | |
*** tobberydberg has joined #openstack-keystone | 16:57 | |
*** tobberydberg has quit IRC | 17:02 | |
*** pnavarro has quit IRC | 17:04 | |
*** mvk has quit IRC | 17:10 | |
*** pnavarro has joined #openstack-keystone | 17:17 | |
*** iurygregory has joined #openstack-keystone | 17:18 | |
*** rcernin has joined #openstack-keystone | 17:30 | |
*** aojea has joined #openstack-keystone | 17:42 | |
*** sjain_ has joined #openstack-keystone | 17:55 | |
morgan | cmurphy: good catches on the start of the ksa patch change mordred is working on | 18:01 |
cmurphy | morgan: :) | 18:02 |
* cmurphy helping | 18:02 | |
cmurphy | now to go through the rest of the stack | 18:04 |
morgan | i am holding on some of the rest until the earlier ones are addressed, the stack is deep and i'm not sure what the fixes for compat may do to the upper ends. | 18:04 |
cmurphy | that's probably a good idea | 18:05 |
*** dave-mccowan has quit IRC | 18:12 | |
*** sjain_ has quit IRC | 18:18 | |
*** aojea has quit IRC | 18:20 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone master: Move grant policies to DocumentedRuleDefault https://review.openstack.org/449244 | 18:37 |
samueldmq | lbragstad: done ^ | 18:37 |
lbragstad | samueldmq: woo - sweet | 18:37 |
lbragstad | samueldmq: i'll review | 18:37 |
lbragstad | fyi team - this might be interesting and has a couple reviewed that pertain to us http://lists.openstack.org/pipermail/openstack-dev/2017-June/117967.html | 18:43 |
lbragstad | specifically in oslo.cache and keystone | 18:43 |
*** ayoung has quit IRC | 18:43 | |
*** spilla has quit IRC | 18:56 | |
*** thorst_afk has quit IRC | 19:11 | |
*** thorst_afk has joined #openstack-keystone | 19:15 | |
*** p_arch has joined #openstack-keystone | 19:16 | |
p_arch | Hi - Is there someone who can help me. I'm trying to set up SSL for keystone on Newton and failing miserably. Help please!! | 19:17 |
*** rcernin has quit IRC | 19:17 | |
*** aojea has joined #openstack-keystone | 19:17 | |
*** thorst_afk has quit IRC | 19:20 | |
*** dave-mccowan has joined #openstack-keystone | 19:23 | |
*** thorst_afk has joined #openstack-keystone | 19:29 | |
*** rcernin has joined #openstack-keystone | 19:35 | |
-openstackstatus- NOTICE: The Gerrit service on review.openstack.org is being restarted now to clear some excessive connection counts while we debug the intermittent request failures reported over the past few minutes | 20:05 | |
*** tobberydberg has joined #openstack-keystone | 20:10 | |
*** nicolasbock_ has quit IRC | 20:14 | |
*** tobberydberg has quit IRC | 20:15 | |
lbragstad | samueldmq: just getting around to reviewing https://review.openstack.org/#/c/449244/7/keystone/assignment/routers.py | 20:36 |
samueldmq | lbragstad: yes? | 20:37 |
samueldmq | there are a couple of places where we have get_action rather than get_head, we should look for consistency, but I'd like to have an overview of all we have | 20:37 |
samueldmq | before the move | 20:38 |
lbragstad | samueldmq: interesting | 20:38 |
lbragstad | so does that API not support HEAD methods? | 20:38 |
samueldmq | no | 20:38 |
samueldmq | which is pretty inconsistent | 20:38 |
lbragstad | huh - but the rest of the assignment API does? | 20:38 |
samueldmq | yes | 20:38 |
lbragstad | because it uses get_head_action | 20:38 |
lbragstad | hmmm | 20:38 |
samueldmq | we should migrate all to get_head I guess, and remove the possibility of get_action at all | 20:38 |
lbragstad | that should be backwards compatible | 20:39 |
samueldmq | and will be | 20:39 |
*** pnavarro has quit IRC | 20:39 | |
lbragstad | ok - that makes senes | 20:39 |
lbragstad | samueldmq: i wonder if we should open a bug for that? | 20:39 |
lbragstad | doesn't seem like specification material | 20:39 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Prep for is_admin_project for scoped operations https://review.openstack.org/471911 | 20:40 |
samueldmq | lbragstad: well that would make sense | 20:40 |
lbragstad | samueldmq: a bug report? | 20:40 |
samueldmq | yes | 20:40 |
samueldmq | morgan started that | 20:40 |
lbragstad | samueldmq: cool - i agree | 20:40 |
lbragstad | samueldmq: is there one already created? | 20:41 |
samueldmq | when he said all get apis should have respective heads | 20:41 |
* lbragstad must have missed it | 20:41 | |
samueldmq | the thing is that we didnt migrate 100% or we didnt continue in the approach | 20:41 |
samueldmq | I think it's time to revisit | 20:41 |
lbragstad | samueldmq: do you have a link to the bug report? | 20:41 |
samueldmq | looking | 20:41 |
samueldmq | lbragstad: bug 1370335 | 20:44 |
openstack | bug 1370335 in OpenStack Identity (keystone) "Keystone should support HEAD requests for all GET /v3/* actions" [Wishlist,Fix released] https://launchpad.net/bugs/1370335 - Assigned to Colleen Murphy (krinkle) | 20:44 |
lbragstad | ah | 20:45 |
lbragstad | we should figure out where that isn't true anymore | 20:46 |
lbragstad | samueldmq: ok - finished reviewing, just a couple more wording suggestions that I should have caught when I suggested them the first time around | 20:50 |
lbragstad | samueldmq: should we create a new bug report for the get_head_action inconsistencies you found? | 20:51 |
lbragstad | samueldmq: these are the get_actions i see in the source today - http://paste.openstack.org/show/611770/ | 20:52 |
*** pcaruana has quit IRC | 20:53 | |
*** pcaruana has joined #openstack-keystone | 20:53 | |
*** ayoung has joined #openstack-keystone | 21:08 | |
samueldmq | lbragstad: yes I think a new bug makes sense | 21:09 |
samueldmq | then we study them closer and decide what to do | 21:09 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Flag GET APIs that need corresponding HEAD API https://review.openstack.org/471919 | 21:09 |
lbragstad | samueldmq: done ^ | 21:10 |
samueldmq | lbragstad: reviewed :) | 21:12 |
lbragstad | cmurphy: proposed the original fix, she might have some useful context there, too | 21:16 |
*** pcaruana has quit IRC | 21:16 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Flag GET APIs that need corresponding HEAD API https://review.openstack.org/471919 | 21:18 |
*** edmondsw_ has joined #openstack-keystone | 21:22 | |
*** frickler_ has joined #openstack-keystone | 21:26 | |
*** SamYaple_ has joined #openstack-keystone | 21:27 | |
*** rmascena has quit IRC | 21:27 | |
*** odyssey4me_ has joined #openstack-keystone | 21:28 | |
*** Alex_Oughton has joined #openstack-keystone | 21:29 | |
*** evrardjp has quit IRC | 21:29 | |
*** mtreinish has quit IRC | 21:29 | |
*** AlexOughton has quit IRC | 21:29 | |
*** adriant has quit IRC | 21:29 | |
*** aloga has quit IRC | 21:29 | |
*** SamYaple has quit IRC | 21:29 | |
*** frickler has quit IRC | 21:29 | |
*** edmondsw has quit IRC | 21:29 | |
*** hoonetorg has quit IRC | 21:29 | |
*** odyssey4me has quit IRC | 21:29 | |
*** aloga has joined #openstack-keystone | 21:30 | |
*** mtreinish has joined #openstack-keystone | 21:30 | |
*** hoonetorg has joined #openstack-keystone | 21:30 | |
*** evrardjp has joined #openstack-keystone | 21:30 | |
cmurphy | hi | 21:32 |
gagehugo | cmurphy o/ | 21:33 |
cmurphy | did we miss those in the first pass or did new ones come up? | 21:34 |
lbragstad | cmurphy: that's a good question | 21:38 |
lbragstad | cmurphy: pulling up the change | 21:38 |
lbragstad | cmurphy: i found those by doing a grep | 21:38 |
* lbragstad is super fancy | 21:38 | |
cmurphy | pulling out all the stops | 21:38 |
lbragstad | i even used --exclude-dir | 21:39 |
lbragstad | cmurphy: it looks like there are some get_actions here https://review.openstack.org/#/c/295641/2/keystone/assignment/routers.py | 21:40 |
lbragstad | for the implied roles stuff | 21:40 |
*** piliman974 has quit IRC | 21:40 | |
cmurphy | heh so there is | 21:41 |
lbragstad | specifically looking at get_action='list_implied_roles', | 21:43 |
cmurphy | yeah i don't know what i was thinking | 21:43 |
*** rcernin has quit IRC | 21:44 | |
lbragstad | cmurphy: :) no worries - it's an easy fix | 21:44 |
lbragstad | some of those might be new APIs too | 21:44 |
openstackgerrit | Merged openstack/keystone master: Quotation marks should be included in http url using curl https://review.openstack.org/458736 | 21:44 |
cmurphy | i'm not worried, that was one of my first keystone patches :) | 21:45 |
cmurphy | not that shabby for a noob | 21:45 |
*** lucasxu has quit IRC | 21:45 | |
cmurphy | lbragstad: commented on your patch, i don't think it would be that hard to just fix it rather than marking them? | 21:46 |
lbragstad | cmurphy: good point | 21:46 |
lbragstad | cmurphy: "sir, stop being lazy and just fix the bug" ;) | 21:47 |
cmurphy | :P | 21:47 |
*** catintheroof has joined #openstack-keystone | 21:47 | |
*** thorst_afk has quit IRC | 21:53 | |
*** piliman974 has joined #openstack-keystone | 21:54 | |
*** SamYaple_ has quit IRC | 21:57 | |
*** SamYaple has joined #openstack-keystone | 21:57 | |
*** edmondsw_ has quit IRC | 21:58 | |
*** aojea has quit IRC | 22:18 | |
*** thorst_afk has joined #openstack-keystone | 22:28 | |
*** thorst_afk has quit IRC | 22:32 | |
*** chlong has quit IRC | 22:32 | |
*** adriant has joined #openstack-keystone | 22:37 | |
*** piliman974 has quit IRC | 22:38 | |
*** ayoung has quit IRC | 22:40 | |
*** piliman974 has joined #openstack-keystone | 22:40 | |
*** catintheroof has quit IRC | 22:46 | |
*** lbragstad has quit IRC | 23:00 | |
*** rderose has quit IRC | 23:01 | |
*** thorst_afk has joined #openstack-keystone | 23:02 | |
*** openstack has joined #openstack-keystone | 23:13 | |
*** thorst_afk has quit IRC | 23:17 | |
*** edmondsw has joined #openstack-keystone | 23:18 | |
*** edmondsw has quit IRC | 23:23 | |
*** ducttape_ has quit IRC | 23:24 | |
openstackgerrit | Nicolas Helgeson proposed openstack/keystone master: Added versions to keyston headers https://review.openstack.org/468189 | 23:26 |
*** ducttape_ has joined #openstack-keystone | 23:26 | |
*** ducttape_ has quit IRC | 23:52 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!