*** openstack has joined #openstack-keystone | 00:15 | |
*** lbragstad has quit IRC | 00:15 | |
*** cburgess has joined #openstack-keystone | 00:15 | |
*** jamielennox has quit IRC | 00:16 | |
*** jamielennox has joined #openstack-keystone | 00:16 | |
*** szaher has quit IRC | 00:16 | |
*** iurygregory has quit IRC | 00:17 | |
*** zigo has quit IRC | 00:17 | |
*** gyee has quit IRC | 00:17 | |
*** jaosorior has quit IRC | 00:17 | |
*** peterstac has quit IRC | 00:17 | |
*** rha has quit IRC | 00:17 | |
*** charz has quit IRC | 00:17 | |
*** charz has joined #openstack-keystone | 00:18 | |
*** phalmos has joined #openstack-keystone | 00:19 | |
*** breton has joined #openstack-keystone | 00:19 | |
*** ducttape_ has quit IRC | 00:19 | |
*** edmondsw has quit IRC | 00:19 | |
*** rha has joined #openstack-keystone | 00:21 | |
*** PramodJ has quit IRC | 00:22 | |
*** iurygregory has joined #openstack-keystone | 00:24 | |
*** zigo has joined #openstack-keystone | 00:24 | |
*** gyee has joined #openstack-keystone | 00:24 | |
*** peterstac has joined #openstack-keystone | 00:24 | |
*** chrome0 has joined #openstack-keystone | 00:24 | |
*** szaher has joined #openstack-keystone | 00:25 | |
*** thorst has joined #openstack-keystone | 00:26 | |
*** fig_newton has quit IRC | 00:33 | |
*** jaosorior has joined #openstack-keystone | 00:39 | |
openstackgerrit | ayoung proposed openstack/keystone-specs master: Commit to RBAC in middleware in Pike release https://review.openstack.org/452198 | 00:44 |
---|---|---|
openstackgerrit | ayoung proposed openstack/keystone-specs master: Commit to RBAC in middleware in Queens release https://review.openstack.org/452198 | 00:53 |
*** hoonetorg has quit IRC | 00:54 | |
*** harlowja has joined #openstack-keystone | 01:04 | |
*** timburke has quit IRC | 01:07 | |
*** hugokuo has quit IRC | 01:07 | |
*** charz has quit IRC | 01:07 | |
samueldmq | fig_newton: (if you look at the logs for some reason) see keystone-manage bootstrap in https://docs.openstack.org/ocata/install-guide-ubuntu/keystone-install.html | 01:08 |
*** hoonetorg has joined #openstack-keystone | 01:11 | |
*** liujiong has joined #openstack-keystone | 01:13 | |
*** namnh has joined #openstack-keystone | 01:14 | |
*** ducttape_ has joined #openstack-keystone | 01:16 | |
*** zzzeek has quit IRC | 01:18 | |
*** zzzeek has joined #openstack-keystone | 01:18 | |
*** ducttape_ has quit IRC | 01:26 | |
*** markvoelker has quit IRC | 01:27 | |
*** hoonetorg has quit IRC | 01:30 | |
*** ducttap__ has joined #openstack-keystone | 01:31 | |
*** ducttap__ has quit IRC | 01:36 | |
*** thorst has joined #openstack-keystone | 01:38 | |
*** shuyingya has joined #openstack-keystone | 01:48 | |
*** hoonetorg has joined #openstack-keystone | 01:52 | |
*** bknudson has joined #openstack-keystone | 01:52 | |
*** bknudson has quit IRC | 01:55 | |
*** thorst has quit IRC | 01:56 | |
*** thorst has joined #openstack-keystone | 01:56 | |
*** hoonetorg has quit IRC | 01:58 | |
*** thorst has quit IRC | 02:00 | |
*** edmondsw has joined #openstack-keystone | 02:03 | |
*** edmondsw has quit IRC | 02:08 | |
*** hoonetorg has joined #openstack-keystone | 02:12 | |
*** ducttape_ has joined #openstack-keystone | 02:32 | |
*** masber has joined #openstack-keystone | 02:34 | |
*** masuberu has quit IRC | 02:37 | |
*** masuberu has joined #openstack-keystone | 02:38 | |
*** gyee has quit IRC | 02:41 | |
*** masber has quit IRC | 02:42 | |
*** ducttape_ has quit IRC | 02:46 | |
*** zhugaoxiao has joined #openstack-keystone | 02:51 | |
*** gongysh has joined #openstack-keystone | 02:59 | |
*** nicolasbock has joined #openstack-keystone | 03:27 | |
*** markvoelker has joined #openstack-keystone | 03:28 | |
*** tristanC has quit IRC | 03:29 | |
*** tristanC has joined #openstack-keystone | 03:31 | |
*** ducttape_ has joined #openstack-keystone | 03:43 | |
*** edmondsw has joined #openstack-keystone | 03:51 | |
*** edmondsw has quit IRC | 03:56 | |
*** thorst has joined #openstack-keystone | 03:57 | |
*** links has joined #openstack-keystone | 03:58 | |
*** ducttap__ has joined #openstack-keystone | 04:00 | |
*** ducttape_ has quit IRC | 04:00 | |
*** catintheroof has quit IRC | 04:01 | |
*** thorst has quit IRC | 04:01 | |
*** ducttap__ has quit IRC | 04:05 | |
*** ducttape_ has joined #openstack-keystone | 04:08 | |
*** ducttape_ has quit IRC | 04:13 | |
*** ducttape_ has joined #openstack-keystone | 04:16 | |
*** ducttape_ has quit IRC | 04:21 | |
*** ducttape_ has joined #openstack-keystone | 04:21 | |
*** ducttape_ has quit IRC | 04:26 | |
*** jerrygb has joined #openstack-keystone | 04:36 | |
*** ducttape_ has joined #openstack-keystone | 04:39 | |
*** ducttape_ has quit IRC | 04:43 | |
*** aselius has quit IRC | 04:51 | |
*** gongysh has quit IRC | 04:56 | |
*** jerrygb_ has joined #openstack-keystone | 05:01 | |
*** jerrygb has quit IRC | 05:03 | |
*** aselius has joined #openstack-keystone | 05:06 | |
*** pcaruana has joined #openstack-keystone | 05:14 | |
*** pcaruana has quit IRC | 05:30 | |
*** gongysh has joined #openstack-keystone | 05:30 | |
*** frickler_ is now known as frickler | 05:35 | |
*** tobberydberg has joined #openstack-keystone | 05:36 | |
*** f13o has quit IRC | 05:37 | |
*** edmondsw has joined #openstack-keystone | 05:39 | |
*** edmondsw has quit IRC | 05:44 | |
*** ducttape_ has joined #openstack-keystone | 05:53 | |
*** thorst has joined #openstack-keystone | 05:58 | |
*** markvoelker has quit IRC | 06:01 | |
*** thorst has quit IRC | 06:02 | |
*** tesseract has joined #openstack-keystone | 06:40 | |
*** gongysh has quit IRC | 06:41 | |
openstackgerrit | Hemanth Nakkina proposed openstack/keystone-tempest-plugin master: Add functional test cases for v3-ext/OS-OAUTH1 https://review.openstack.org/473245 | 06:43 |
*** links has quit IRC | 06:49 | |
*** pcaruana has joined #openstack-keystone | 06:49 | |
*** mfedosin has joined #openstack-keystone | 06:51 | |
*** rcernin_ has joined #openstack-keystone | 06:53 | |
*** gongysh has joined #openstack-keystone | 07:04 | |
*** links has joined #openstack-keystone | 07:05 | |
*** cmurphy_ is now known as cmurphy | 07:18 | |
*** f13o has joined #openstack-keystone | 07:24 | |
*** edmondsw has joined #openstack-keystone | 07:27 | |
*** dave-mccowan has quit IRC | 07:30 | |
*** sbezverk has quit IRC | 07:31 | |
*** edmondsw has quit IRC | 07:32 | |
*** binoymv has joined #openstack-keystone | 07:34 | |
binoymv | how to find the role of loggedin user ? | 07:35 |
*** pcaruana|afk| has joined #openstack-keystone | 07:35 | |
*** pcaruana|afk| has quit IRC | 07:35 | |
*** pcaruana has quit IRC | 07:36 | |
*** dave-mccowan has joined #openstack-keystone | 07:36 | |
*** pcaruana has joined #openstack-keystone | 07:40 | |
*** links has quit IRC | 07:55 | |
*** thorst has joined #openstack-keystone | 07:58 | |
*** zzzeek has quit IRC | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:00 | |
*** f13o has quit IRC | 08:02 | |
*** thorst has quit IRC | 08:03 | |
*** oomichi has quit IRC | 08:05 | |
*** oomichi has joined #openstack-keystone | 08:07 | |
*** links has joined #openstack-keystone | 08:08 | |
*** aselius has quit IRC | 08:11 | |
*** Guest39557 is now known as asettle | 08:16 | |
*** f13o has joined #openstack-keystone | 08:17 | |
*** Administrator_ has joined #openstack-keystone | 08:17 | |
*** rvba has quit IRC | 08:18 | |
*** zhugaoxiao has quit IRC | 08:20 | |
*** mvk has quit IRC | 08:24 | |
*** phalmos has quit IRC | 08:26 | |
*** rvba has joined #openstack-keystone | 08:26 | |
*** rvba has quit IRC | 08:26 | |
*** rvba has joined #openstack-keystone | 08:26 | |
*** namnh has quit IRC | 08:42 | |
*** openstackgerrit has quit IRC | 08:48 | |
*** mvk has joined #openstack-keystone | 08:53 | |
*** mvk has quit IRC | 08:59 | |
*** f13o has quit IRC | 09:07 | |
*** mvk has joined #openstack-keystone | 09:11 | |
*** edmondsw has joined #openstack-keystone | 09:15 | |
*** f13o has joined #openstack-keystone | 09:18 | |
*** edmondsw has quit IRC | 09:20 | |
samueldmq | morning keystone | 09:24 |
samueldmq | binoymv: hi, knowing the user_id and project_id in which that user is authenticated against | 09:25 |
samueldmq | binoymv: you can do: GET /v3/role_assignments?user_id=<user_id>&project_id=<project_id> | 09:26 |
breton | or just fetch token body | 09:26 |
binoymv | I am loggedin as normail user. For this normail is it possible to get list of users through keystone client . | 09:26 |
samueldmq | binoymv: it depends on whether your policy file allows it or not | 09:36 |
samueldmq | should be in /etc/keystone/policy.json | 09:36 |
samueldmq | breton: ++ | 09:37 |
*** baffle__ has joined #openstack-keystone | 09:42 | |
*** baffle__ has quit IRC | 09:42 | |
*** thorst has joined #openstack-keystone | 09:49 | |
*** thorst has quit IRC | 09:59 | |
*** liujiong has quit IRC | 10:02 | |
*** jerrygb_ has quit IRC | 10:03 | |
*** dims has quit IRC | 10:16 | |
*** thorst has joined #openstack-keystone | 10:17 | |
*** gongysh has quit IRC | 10:18 | |
*** dims has joined #openstack-keystone | 10:21 | |
*** edmondsw has joined #openstack-keystone | 11:03 | |
*** raildo has joined #openstack-keystone | 11:06 | |
*** edmondsw has quit IRC | 11:08 | |
*** sjain has joined #openstack-keystone | 11:11 | |
*** thorst has quit IRC | 11:16 | |
*** thorst has joined #openstack-keystone | 11:47 | |
*** thorst has quit IRC | 11:52 | |
*** ducttape_ has quit IRC | 11:56 | |
*** ducttape_ has joined #openstack-keystone | 11:59 | |
*** tobberyd_ has joined #openstack-keystone | 12:06 | |
*** thorst has joined #openstack-keystone | 12:08 | |
*** tobberydberg has quit IRC | 12:09 | |
*** chlong has joined #openstack-keystone | 12:10 | |
*** ducttape_ has quit IRC | 12:15 | |
*** edmondsw has joined #openstack-keystone | 12:15 | |
*** f13o has quit IRC | 12:33 | |
*** tobberyd_ has quit IRC | 12:36 | |
*** tobberydberg has joined #openstack-keystone | 12:36 | |
*** openstackgerrit has joined #openstack-keystone | 12:46 | |
openstackgerrit | Gyorgy Szombathelyi proposed openstack/keystone-tempest-plugin master: Add requests to requirements.txt https://review.openstack.org/475771 | 12:46 |
*** f13o has joined #openstack-keystone | 12:49 | |
*** lbragstad_ has quit IRC | 12:49 | |
*** bknudson has joined #openstack-keystone | 12:56 | |
-openstackstatus- NOTICE: restarting gerrit to address slowdown issues | 12:56 | |
*** binoymv has left #openstack-keystone | 12:56 | |
*** lucasxu has joined #openstack-keystone | 13:00 | |
*** sjain has quit IRC | 13:09 | |
*** jerrygb has joined #openstack-keystone | 13:15 | |
*** links has quit IRC | 13:18 | |
*** jerrygb_ has joined #openstack-keystone | 13:20 | |
*** jerrygb has quit IRC | 13:20 | |
*** jrist_ is now known as jrist | 13:31 | |
*** jrist has quit IRC | 13:31 | |
*** jrist has joined #openstack-keystone | 13:31 | |
*** ducttape_ has joined #openstack-keystone | 13:33 | |
*** ducttape_ has quit IRC | 13:38 | |
*** shuyingya has quit IRC | 13:47 | |
*** shuyingya has joined #openstack-keystone | 13:48 | |
*** f13o has quit IRC | 13:49 | |
*** pnavarro has joined #openstack-keystone | 13:49 | |
*** shuyingya has quit IRC | 13:52 | |
*** Administrator_ has quit IRC | 14:01 | |
*** Administrator_ has joined #openstack-keystone | 14:02 | |
*** f13o has joined #openstack-keystone | 14:02 | |
*** pnavarro has quit IRC | 14:03 | |
knikolla | o/ morning | 14:16 |
*** aselius has joined #openstack-keystone | 14:17 | |
hrybacki | morning knikolla | 14:19 |
*** jmlowe has joined #openstack-keystone | 14:21 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Add project tags api-ref documentation and reno https://review.openstack.org/472396 | 14:23 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Add project tags api-ref documentation and reno https://review.openstack.org/472396 | 14:25 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Add project tags api-ref documentation and reno https://review.openstack.org/472396 | 14:25 |
*** ducttape_ has joined #openstack-keystone | 14:27 | |
jmlowe | it looks like I have a failed db migration | 14:33 |
jmlowe | going from newton to ocata | 14:33 |
*** spilla has joined #openstack-keystone | 14:35 | |
jmlowe | I was going to do a quick followup with the traceback but it looks like paste.openstack.org is down | 14:36 |
jmlowe | https://pastebin.com/9vyxuJ0F | 14:36 |
*** thorst has quit IRC | 14:37 | |
*** lbragstad_ has joined #openstack-keystone | 14:38 | |
*** ducttape_ has quit IRC | 14:39 | |
hrybacki | lbragstad_: ping | 14:39 |
hrybacki | regarding: https://review.openstack.org/#/c/290253 | 14:39 |
lbragstad_ | hrybacki: checking | 14:39 |
*** ducttape_ has joined #openstack-keystone | 14:39 | |
hrybacki | I'm not so sure that `implied_role create` should take what look like optional parameters -- shouldn't those be two options? | 14:40 |
lbragstad_ | hrybacki: good question - let me follow up since it looks like i reviewed it | 14:40 |
hrybacki | lbragstad_: let me add my comments on a new review | 14:41 |
hrybacki | patchset* | 14:41 |
hrybacki | and then respond to those there? | 14:41 |
lbragstad_ | hrybacki: yes - please | 14:41 |
*** f13o has quit IRC | 14:41 | |
*** lbragstad_ is now known as lbragstad | 14:42 | |
*** ChanServ sets mode: +o lbragstad | 14:42 | |
*** thorst has joined #openstack-keystone | 14:42 | |
hrybacki | lbragstad: updated | 14:44 |
hrybacki | lbragstad: I have no prior exp. with adding to the OSC so lemme know if there is a standard practice I'm ignorant too plz! | 14:45 |
lbragstad | hrybacki: will do | 14:45 |
*** thorst has quit IRC | 14:47 | |
*** rcernin_ has quit IRC | 14:47 | |
*** markvoelker has joined #openstack-keystone | 14:49 | |
*** f13o has joined #openstack-keystone | 14:53 | |
*** tobberyd_ has joined #openstack-keystone | 15:01 | |
*** tobberydberg has quit IRC | 15:05 | |
*** tobberyd_ has quit IRC | 15:06 | |
*** f13o has quit IRC | 15:08 | |
*** sbezverk has joined #openstack-keystone | 15:08 | |
*** jerrygb_ has quit IRC | 15:20 | |
*** f13o has joined #openstack-keystone | 15:20 | |
*** ducttape_ has quit IRC | 15:20 | |
*** ducttape_ has joined #openstack-keystone | 15:21 | |
*** jerrygb has joined #openstack-keystone | 15:21 | |
lbragstad | hrybacki: reviewed | 15:23 |
hrybacki | thanks lbragstad | 15:23 |
*** jerrygb_ has joined #openstack-keystone | 15:27 | |
*** jerrygb has quit IRC | 15:29 | |
*** f13o has quit IRC | 15:30 | |
*** jerrygb has joined #openstack-keystone | 15:31 | |
*** jerrygb_ has quit IRC | 15:32 | |
*** thorst has joined #openstack-keystone | 15:33 | |
lbragstad | samueldmq: ping | 15:33 |
*** thorst has quit IRC | 15:34 | |
*** thorst has joined #openstack-keystone | 15:34 | |
*** jerrygb_ has joined #openstack-keystone | 15:36 | |
*** jerrygb has quit IRC | 15:37 | |
*** gyee has joined #openstack-keystone | 15:38 | |
*** jerrygb_ has quit IRC | 15:42 | |
*** jerrygb has joined #openstack-keystone | 15:43 | |
samueldmq | lbragstad: o/ | 15:56 |
jmlowe | I've moved past my newton to ocata migration problem by bumping the migration rev, I really don't need the triggers to remind me not to add identity providers while I'm upgrading | 16:01 |
lbragstad | samueldmq: o/ | 16:04 |
lbragstad | samueldmq: i was looking through the doc-migration changes | 16:04 |
lbragstad | samueldmq: but i think i answered my question | 16:04 |
lbragstad | I wonder if asettle is around? | 16:05 |
* asettle stands really still | 16:06 | |
asettle | Yesssss | 16:06 |
lbragstad | asettle: o/ | 16:06 |
asettle | o/ hi pals | 16:07 |
lbragstad | not sure if this is documented in your spec | 16:07 |
lbragstad | but is the organization or layout of each projects overall documentation page going to be influenced by the docs team? | 16:07 |
lbragstad | mostly related to https://review.openstack.org/#/c/475119/ | 16:07 |
lbragstad | e.g. all project documentation should have a section labeled "Developer Documentation" that contains useful bits for developers? | 16:08 |
lbragstad | or "Operator Documentation" should contain links to generated configuration and policy files, etc... | 16:08 |
*** thorst has quit IRC | 16:09 | |
*** mvk has quit IRC | 16:09 | |
jmlowe | has anybody seen something like this? http://paste.openstack.org/show/613190/ | 16:10 |
lbragstad | jmlowe: i've seen something similar to that after we landed support for resource options | 16:13 |
lbragstad | jmlowe: are you seeing that with MFA only? | 16:13 |
lbragstad | jmlowe: and on master? | 16:13 |
jmlowe | ocata | 16:13 |
jmlowe | seems to be mfa only, I'm trying to get from newton to ocata, 2 controller on newton, I see that on the new ocata one | 16:14 |
*** nishaYadav has joined #openstack-keystone | 16:14 | |
jmlowe | did I need to create some rule for disabling MFA? | 16:15 |
lbragstad | jmlowe: no i don't think so | 16:15 |
lbragstad | jmlowe: the the ocata code knows how to populate the `options` dictionary for resource | 16:16 |
lbragstad | when it pulls things from the database | 16:16 |
lbragstad | the newton code might not have that logic | 16:16 |
lbragstad | which is why it's probably failing on a key error | 16:16 |
lbragstad | we had a similar issue in a different part of the code - i'm trying to find that fix | 16:16 |
*** tobberydberg has joined #openstack-keystone | 16:16 | |
jmlowe | so if I didn't have my newton ones running things would just work? | 16:16 |
lbragstad | jmlowe: yeah - probably, because ocata should know how to handle that, let me see if i can find the code | 16:17 |
jmlowe | and just so I understand, we have let's say a token being generated by newton but validated by ocata, and the ocata doesn't find the options that would have been generated if ocata had generated the token? | 16:18 |
lbragstad | jmlowe: https://github.com/openstack/keystone/blob/45265c0ddffa399fcb10bed6eac98069decdf910/keystone/common/resource_options.py#L50 | 16:19 |
*** pcaruana has quit IRC | 16:19 | |
lbragstad | jmlowe: it's more so something that happens between keystone and the database | 16:20 |
lbragstad | jmlowe: i don't think its so much the token that's involved | 16:20 |
*** tobberydberg has quit IRC | 16:21 | |
lbragstad | morgan: did a lot of the heavy lifting of that feature | 16:21 |
jmlowe | so should I just take the ocata plunge? | 16:21 |
lbragstad | jmlowe: just to confirm, you're seeing the trace from a newton node, right? | 16:21 |
lbragstad | the ocata nodes are running without issue? | 16:22 |
jmlowe | no, that is from ocata, newtons seem to function without issue | 16:22 |
samueldmq | lbragstad: asettle: I am back | 16:24 |
samueldmq | that's a good question, I am looking at our docs and something I (and sjain) considered as a good improvement | 16:24 |
asettle | Sorry lbragstad I also got distracted | 16:24 |
samueldmq | was to clearly separate the audiences each doc is talking to | 16:24 |
asettle | To answer your question lbragstad no, it's not going to be defined by the docs team | 16:24 |
asettle | As long as it is clearly defined what each thing is for (admin, install, etc) | 16:25 |
asettle | Then that's fine | 16:25 |
asettle | You're welcome to ask for assistance | 16:25 |
samueldmq | asettle: yeah, and I guess the status on that depends on how the projects docs are organized today | 16:25 |
*** nishaYadav_ has joined #openstack-keystone | 16:25 | |
samueldmq | we feel we can make it better here in our side | 16:25 |
lbragstad | jmlowe: so you have two controllers running newton and one running ocata | 16:25 |
jmlowe | correct | 16:25 |
*** thorst has joined #openstack-keystone | 16:25 | |
lbragstad | jmlowe: have you done any database migrations yet? | 16:25 |
jmlowe | I have expanded and migrated | 16:25 |
jmlowe | expansion was a little rough, triggers for identity provider add error didn't really work | 16:26 |
samueldmq | asettle: cool, I will ask sjain to make sure to include you as a reviewer on the changes | 16:27 |
asettle | samueldmq: sounds good :) | 16:27 |
morgan | o/ | 16:28 |
morgan | lbragstad: which feature? | 16:28 |
*** nishaYadav has quit IRC | 16:28 | |
lbragstad | jmlowe: so the database should have the user_option table? | 16:28 |
lbragstad | morgan: jmlowe is hitting an interesting case with user_options | 16:28 |
morgan | oh | 16:28 |
morgan | and rolling upgrades? | 16:28 |
lbragstad | morgan: yeah | 16:28 |
morgan | i thought newton->ocata was... suspect | 16:28 |
morgan | at best | 16:28 |
lbragstad | morgan: two controller nodes on newton | 16:28 |
lbragstad | morgan: one on ocata | 16:29 |
lbragstad | and the ocata nodes is throwing http://paste.openstack.org/show/613190/ | 16:29 |
morgan | yeah that may not work well | 16:29 |
morgan | due to user options table | 16:29 |
lbragstad | i find it strange that the ocata node is throwing that and not the newton nodes... | 16:29 |
morgan | uh | 16:29 |
morgan | did the db schema get fully migrated? | 16:30 |
lbragstad | morgan: that's what i asked | 16:30 |
morgan | or... some other issue with mismatched code | 16:30 |
lbragstad | morgan: jmlowe said he expanded and migrated the database | 16:31 |
morgan | hm | 16:31 |
morgan | that is weird. | 16:31 |
jmlowe | MFA Rules not processed for user `c90888352e064d3b8e0dfef120a41c28`. Rule list: `[]` (Enabled: `True`). check_auth_methods_against_rules /usr/lib/python2. | 16:32 |
jmlowe | 7/site-packages/keystone/auth/core.py:388 | 16:32 |
*** nishaYadav_ has quit IRC | 16:32 | |
jmlowe | does that mean anything? | 16:32 |
*** nishaYadav has joined #openstack-keystone | 16:32 | |
morgan | that means no MFA rules exist | 16:32 |
morgan | and it's an empty list | 16:32 |
morgan | [] | 16:32 |
*** nishaYadav is now known as Guest79794 | 16:32 | |
morgan | that means it should be working as expected | 16:32 |
*** Guest79794 is now known as nishaYadav_ | 16:33 | |
morgan | if a rule list is empty, there is nothing to do | 16:33 |
morgan | and as you see [] list is empty | 16:33 |
jmlowe | ok, yeah, I see, it's not the mfa rules that don't have an options atribute it's the user | 16:34 |
morgan | yes | 16:34 |
morgan | the user object should have an options attr | 16:34 |
morgan | if you look here | 16:35 |
morgan | https://github.com/openstack/keystone/blob/master/keystone/identity/backends/sql_model.py#L230-L237 | 16:35 |
*** thorst has quit IRC | 16:35 | |
lbragstad | jmlowe: this might be a dumb question, but can you confirm the expand and migrate was applied cleanly to the database? | 16:36 |
morgan | that should populate the options dict | 16:36 |
jmlowe | it didn't go smoothly the first time | 16:36 |
jmlowe | I think I have it though, is there a particular migration you have in mind? | 16:37 |
lbragstad | jmlowe: what happened the first time you expanded the database? | 16:37 |
jmlowe | choked on the mysql keystone user not bing "super" so it couldn't create the triggers to throw errors if you tried to add an identity provider | 16:38 |
*** nishaYadav_ has quit IRC | 16:38 | |
morgan | lbragstad: ^ another reason triggers are ill-advised and the work should have been done in the application instead | 16:39 |
* morgan harps on "triggers are a terrible idea" | 16:39 | |
jmlowe | 012_expand_add_domain_id_to_idp.py | 16:39 |
jmlowe | if nothing else, would have been nice to alter the db and make the trigger in separate versions | 16:40 |
jmlowe | subsequent attempts failed due to the domain_id column already having been added to the identity_provider table | 16:41 |
lbragstad | hmm | 16:42 |
*** SamYaple has quit IRC | 16:44 | |
jmlowe | as I understand it if you follow the install guide you will never be able to add triggers, triggers require super and that is a global attribute, the install docs grant all permissions scoped down to the keystone database | 16:44 |
*** SamYaple has joined #openstack-keystone | 16:44 | |
jmlowe | for mysql that is | 16:44 |
*** SamYaple has quit IRC | 16:44 | |
*** SamYaple has joined #openstack-keystone | 16:44 | |
lbragstad | jmlowe: did you follow the process outlined here - https://docs.openstack.org/developer/keystone/upgrading.html#upgrading-without-downtime ? | 16:46 |
jmlowe | pretty much | 16:49 |
jmlowe | with the exception of the whole super problem | 16:50 |
*** sbezverk has quit IRC | 16:51 | |
*** thorst has joined #openstack-keystone | 16:52 | |
samueldmq | asettle: in https://review.openstack.org/#/c/472275 it says "developer, contributor, and user documentation" | 16:54 |
lbragstad | jmlowe: did you have an issue with step 6? | 16:54 |
samueldmq | asettle: what is the distinction between those? | 16:54 |
samueldmq | we have been working with developer, user and operator | 16:55 |
*** zzzeek has quit IRC | 16:55 | |
samueldmq | I guess developer and contributor would mean the same there? | 16:55 |
*** thorst has quit IRC | 16:55 | |
*** thorst has joined #openstack-keystone | 17:00 | |
*** tesseract has quit IRC | 17:00 | |
*** ducttape_ has quit IRC | 17:02 | |
*** sjain has joined #openstack-keystone | 17:11 | |
*** sjain has quit IRC | 17:18 | |
*** catintheroof has joined #openstack-keystone | 17:24 | |
lbragstad | jmlowe: would you be able to open a bug with what you're seeing and we can follow up there, just so we don't lose information or context | 17:28 |
*** lwanderley has joined #openstack-keystone | 17:29 | |
asettle | samueldmq: developer is you guys, contributor is 'how to contribte' and user is our operators and deployers | 17:30 |
samueldmq | asettle: hmm I was not seeing it that way, we may want to re-organize make that clearer in our docs with this cross-project view on the audiences | 17:31 |
samueldmq | thanks for clarifying | 17:31 |
asettle | No problem | 17:31 |
samueldmq | asettle: I guess app developers are users too, then? | 17:31 |
asettle | samueldmq: different kettle of fish. In a sense, yes. But in another sense, they are developers. | 17:34 |
asettle | That's pretty murky waters | 17:34 |
asettle | developer.openstack.org houses the app dev stuff, and docs.openstack.org houses user and contributor documentation | 17:34 |
asettle | The information we are handing to you from the openstack-manuals repo is the user and contributor information | 17:34 |
samueldmq | asettle: okay, good info. I will mull it a bit :) | 17:35 |
samueldmq | to see how we can reorganize ours docs to match that | 17:35 |
asettle | No problem. | 17:47 |
asettle | :) | 17:47 |
*** zzzeek has joined #openstack-keystone | 17:47 | |
*** bhanu has joined #openstack-keystone | 17:52 | |
*** zzzeek has quit IRC | 17:57 | |
*** rderose has joined #openstack-keystone | 17:59 | |
*** henrynash has joined #openstack-keystone | 18:00 | |
*** sjain__ has joined #openstack-keystone | 18:00 | |
*** ducttape_ has joined #openstack-keystone | 18:01 | |
*** sjain__ has quit IRC | 18:01 | |
*** zzzeek has joined #openstack-keystone | 18:03 | |
*** catinthe_ has joined #openstack-keystone | 18:03 | |
*** thorst has quit IRC | 18:05 | |
*** catintheroof has quit IRC | 18:05 | |
*** MasterOfBugs has joined #openstack-keystone | 18:06 | |
*** henrynash has quit IRC | 18:09 | |
*** henrynash has joined #openstack-keystone | 18:11 | |
*** lwanderley has quit IRC | 18:13 | |
*** henrynash has quit IRC | 18:13 | |
*** lwanderley has joined #openstack-keystone | 18:14 | |
*** lwanderley has quit IRC | 18:16 | |
*** rderose has quit IRC | 18:16 | |
*** rderose has joined #openstack-keystone | 18:16 | |
*** lwanderley has joined #openstack-keystone | 18:17 | |
*** henrynash has joined #openstack-keystone | 18:17 | |
*** sjain__ has joined #openstack-keystone | 18:18 | |
*** henrynash has quit IRC | 18:19 | |
*** lwanderley has quit IRC | 18:21 | |
openstackgerrit | Aaron Thomas proposed openstack/keystone master: Trim whitespace from X-Subject-Token https://review.openstack.org/470425 | 18:25 |
*** henrynash has joined #openstack-keystone | 18:27 | |
*** ducttape_ has quit IRC | 18:29 | |
*** henrynash has quit IRC | 18:30 | |
jmlowe | digging in a bit I have {'password_expires_at': None, 'enabled': True, u'email': None, 'id': u'6db8c4ba4bca4dd2a335301f34c5b22a', 'domain_id': u'default', 'name': u'neutron'} as keys to the user_ref dict | 18:31 |
*** henrynash has joined #openstack-keystone | 18:33 | |
*** sbezverk has joined #openstack-keystone | 18:33 | |
sjain__ | lbragstad, samueldmq: this jenkins gate check failed https://review.openstack.org/#/c/466066/, although it was fine initially, the error is related to some requirements but this patch has no change which can raise that, can you please have a look and suggest what needs to be done here? | 18:35 |
*** ducttape_ has joined #openstack-keystone | 18:36 | |
*** henrynash has quit IRC | 18:38 | |
*** bhanu has quit IRC | 18:38 | |
*** henrynash has joined #openstack-keystone | 18:39 | |
lbragstad | sjain__: will do | 18:44 |
gagehugo | https://review.openstack.org/#/c/474648/ might need to be merged in first? | 18:46 |
hrybacki | lbragstad: knikolla sorry I might have missed this -- did we opt to send the poll openstack-dev or to a catered email list? | 18:47 |
* hrybacki goes to work on the Doodle poll | 18:47 | |
*** sjain__ has quit IRC | 18:47 | |
lbragstad | umm - it sounded like a catered list, but i also don't want to be exclusive | 18:48 |
lbragstad | so maybe both? | 18:48 |
lbragstad | send a note for folks we know should participate | 18:48 |
hrybacki | yes | 18:49 |
hrybacki | to both that is | 18:49 |
lbragstad | then a separate note to the mailing list inviting people to participate | 18:49 |
hrybacki | can someone provide me with a catered list? | 18:49 |
* hrybacki nods | 18:49 | |
lbragstad | hrybacki: | 18:49 |
lbragstad | hrybacki: yea | 18:49 |
*** thorst has joined #openstack-keystone | 18:58 | |
*** ducttape_ has quit IRC | 18:59 | |
hrybacki | lbragstad: how does https://doodle.com/poll/epvs95npfvrd3h5e look? | 19:03 |
hrybacki | knikolla ^^ | 19:04 |
hrybacki | knikolla: do you have a description of the office hours already that I can re-use for the email rather than concocting something crazy on my own? | 19:06 |
knikolla | hrybacki: it should be in the etherpad | 19:07 |
knikolla | https://etherpad.openstack.org/p/keystone-office-hours | 19:07 |
hrybacki | knikolla++ | 19:08 |
*** henrynash has quit IRC | 19:08 | |
*** henrynash has joined #openstack-keystone | 19:09 | |
lbragstad | hrybacki: that doodle looks good | 19:09 |
lbragstad | hrybacki: filling it out now ;) | 19:10 |
knikolla | select all the sections! | 19:10 |
lbragstad | hrybacki: your Doodle doesn't support ^A | 19:12 |
hrybacki | lol | 19:13 |
hrybacki | so the calendar feature is better but it doesn't support 'reoccurring dates' | 19:13 |
lbragstad | hrybacki: so for the direct mail | 19:13 |
lbragstad | hrybacki: i'd start with https://etherpad.openstack.org/p/keystone-office-hours | 19:13 |
lbragstad | the attendees there ^ | 19:14 |
hrybacki | ack | 19:14 |
lbragstad | maybe add lamt spilla cmurphy (who is in Germany) | 19:14 |
*** thorst has quit IRC | 19:15 | |
gagehugo | hrybacki voted! | 19:15 |
hrybacki | thanks gagehugo! | 19:15 |
*** thorst has joined #openstack-keystone | 19:15 | |
*** catinthe_ has quit IRC | 19:16 | |
hrybacki | lbragstad: is there a special tag to use for this (mailing list subject) other than openstack-dev and keystone? | 19:18 |
lbragstad | hrybacki: tagwise? no | 19:18 |
hrybacki | ++ | 19:18 |
lbragstad | [openstack-dev] will be there automatically | 19:18 |
lbragstad | so just [keystone] new office hours proposal? | 19:18 |
*** thorst has quit IRC | 19:20 | |
knikolla | lbragstad: we should start tagging bugs by milestones | 19:21 |
*** nicolasbock has quit IRC | 19:21 | |
hrybacki | knikolla: lbragstad draft of email: https://paste.fedoraproject.org/paste/SIkQFE0tdEZZnqLgvpuF9Q | 19:24 |
hrybacki | I chose an announcement time of this Friday at 5PM (EST) -- that way folks know when to get their votes in by | 19:25 |
lbragstad | knikolla: yeah - that would be a good thing especially for m-3 | 19:25 |
lbragstad | hrybacki: "focused on"* in the first sentence? | 19:25 |
hrybacki | good catch | 19:26 |
lbragstad | hrybacki: otherwise +1 | 19:26 |
hrybacki | ack | 19:26 |
*** tobberydberg has joined #openstack-keystone | 19:26 | |
hrybacki | I'll send this out now and try to track down emails from the etherpad folks | 19:26 |
hrybacki | send them another in a BCC | 19:26 |
knikolla | hrybacki: ++ | 19:27 |
knikolla | good work | 19:28 |
lbragstad | hrybacki: i think you just need lamt, knikolla, and yourself | 19:28 |
lbragstad | :) | 19:28 |
hrybacki | alternatively I could just ping them directly on freenode... probably better? | 19:28 |
lbragstad | either or | 19:28 |
hrybacki | lbragstad: knikolla I'll forward y'all the 'manage' link too so that you may see who has participated | 19:29 |
*** edmondsw has quit IRC | 19:29 | |
lbragstad | awesome | 19:29 |
*** henrynash has quit IRC | 19:30 | |
hrybacki | lbragstad: I don't see that openstack-dev tag =/ | 19:31 |
*** rderose has quit IRC | 19:33 | |
*** rderose has joined #openstack-keystone | 19:33 | |
*** ducttape_ has joined #openstack-keystone | 19:33 | |
*** hoonetorg has quit IRC | 19:34 | |
lbragstad | hrybacki: hmm = http://imgur.com/a/J1jDt | 19:34 |
cmurphy | lbragstad: knikolla fwiw i would have been there on friday it just happened to be a four day weekend for me and i was traveling | 19:34 |
hrybacki | weird | 19:34 |
hrybacki | okay :) | 19:34 |
*** ducttape_ has quit IRC | 19:34 | |
lbragstad | cmurphy: no worries - those happen, which is part of the reason why we want to repropose it | 19:35 |
*** ducttape_ has joined #openstack-keystone | 19:35 | |
cmurphy | in general i would think fridays would be better because less likely to have other random dayjob meetings | 19:36 |
lbragstad | yeah - that's a good point | 19:37 |
hrybacki | knikolla: what's your email? | 19:41 |
knikolla | hrybacki: <my nick >@bu.edu | 19:42 |
hrybacki | knikolla: thx | 19:43 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Ensure the endpoint policy API supports HEAD https://review.openstack.org/473885 | 19:44 |
*** hoonetorg has joined #openstack-keystone | 19:50 | |
*** henrynash has joined #openstack-keystone | 19:50 | |
*** henrynash has quit IRC | 19:52 | |
*** zzzeek has quit IRC | 19:53 | |
*** phalmos has joined #openstack-keystone | 19:55 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Add project tags api-ref documentation and reno https://review.openstack.org/472396 | 19:58 |
*** phalmos_ has joined #openstack-keystone | 19:58 | |
*** phalmos has quit IRC | 20:00 | |
*** edmondsw has joined #openstack-keystone | 20:00 | |
*** raildo has quit IRC | 20:03 | |
*** hoonetorg has quit IRC | 20:15 | |
*** jerrygb has quit IRC | 20:19 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Prep for is_admin_project for scoped operations https://review.openstack.org/462670 | 20:33 |
*** hoonetorg has joined #openstack-keystone | 20:36 | |
*** zzzeek has joined #openstack-keystone | 20:42 | |
*** lucasxu has quit IRC | 21:05 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Add project tags api-ref documentation and reno https://review.openstack.org/472396 | 21:11 |
openstackgerrit | Jaewoo Park proposed openstack/keystone master: WIP: Add project tags https://review.openstack.org/470317 | 21:16 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Handle invalid LDAP credentials in exception https://review.openstack.org/475929 | 21:17 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Clarify LDAP invalid credentials exception https://review.openstack.org/475929 | 21:20 |
*** catintheroof has joined #openstack-keystone | 21:25 | |
*** spilla has quit IRC | 21:26 | |
openstackgerrit | Rohan Arora proposed openstack/keystone master: WIP - Added versions to keystone headers https://review.openstack.org/468189 | 21:31 |
*** thorst has joined #openstack-keystone | 21:32 | |
*** dave-mccowan has quit IRC | 21:35 | |
*** pramodrj07 has joined #openstack-keystone | 21:37 | |
*** MasterOfBugs has quit IRC | 21:40 | |
*** thorst has quit IRC | 21:47 | |
*** henrynash has joined #openstack-keystone | 21:50 | |
*** markvoelker has quit IRC | 21:56 | |
*** thorst has joined #openstack-keystone | 21:57 | |
*** markvoelker has joined #openstack-keystone | 22:04 | |
*** thorst has quit IRC | 22:05 | |
*** thorst has joined #openstack-keystone | 22:05 | |
*** thorst has quit IRC | 22:07 | |
*** ducttape_ has quit IRC | 22:11 | |
*** openstack has joined #openstack-keystone | 22:15 | |
*** frickler has quit IRC | 22:15 | |
*** cburgess has quit IRC | 22:15 | |
*** jmlowe has quit IRC | 22:15 | |
*** jrist has quit IRC | 22:15 | |
*** rm_work has joined #openstack-keystone | 22:15 | |
*** Adri2000 has quit IRC | 22:15 | |
*** john5223_ has joined #openstack-keystone | 22:16 | |
*** jrist has joined #openstack-keystone | 22:16 | |
*** cburgess has joined #openstack-keystone | 22:16 | |
*** jmlowe has joined #openstack-keystone | 22:16 | |
*** oomichi has quit IRC | 22:17 | |
*** jrist has quit IRC | 22:18 | |
*** oomichi has joined #openstack-keystone | 22:19 | |
*** jrist has joined #openstack-keystone | 22:20 | |
*** Adri2000 has joined #openstack-keystone | 22:20 | |
*** jrist has joined #openstack-keystone | 22:21 | |
*** edmondsw has quit IRC | 22:23 | |
*** sbezverk has quit IRC | 22:42 | |
*** tobberydberg has quit IRC | 22:45 | |
*** tobberydberg has joined #openstack-keystone | 22:46 | |
*** tobberydberg has quit IRC | 22:51 | |
*** pramodrj07 has quit IRC | 22:52 | |
*** pramodrj07 has joined #openstack-keystone | 22:53 | |
*** mfedosin has quit IRC | 22:56 | |
*** rderose has quit IRC | 23:07 | |
openstackgerrit | Merged openstack/keystone master: Move role policies to DocumentedRuleDefault https://review.openstack.org/449251 | 23:07 |
*** catintheroof has quit IRC | 23:18 | |
*** bknudson has quit IRC | 23:18 | |
*** harlowja has quit IRC | 23:19 | |
*** mvk has joined #openstack-keystone | 23:27 | |
*** sbezverk has joined #openstack-keystone | 23:44 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!