*** edmondsw has joined #openstack-keystone | 00:16 | |
*** edmondsw has quit IRC | 00:20 | |
*** thorst has joined #openstack-keystone | 00:27 | |
*** ducttape_ has joined #openstack-keystone | 00:31 | |
*** ducttape_ has quit IRC | 00:36 | |
*** aselius has joined #openstack-keystone | 00:45 | |
*** liujiong has joined #openstack-keystone | 01:14 | |
*** Shunli has joined #openstack-keystone | 01:24 | |
*** markvoelker has joined #openstack-keystone | 01:36 | |
*** edmondsw has joined #openstack-keystone | 02:04 | |
*** markvoelker has quit IRC | 02:08 | |
*** edmondsw has quit IRC | 02:09 | |
*** zhurong has joined #openstack-keystone | 02:12 | |
*** lbragstad has joined #openstack-keystone | 02:17 | |
*** ChanServ sets mode: +o lbragstad | 02:17 | |
*** thorst has joined #openstack-keystone | 02:28 | |
*** ducttape_ has joined #openstack-keystone | 02:33 | |
*** thorst has quit IRC | 02:33 | |
*** gongysh has joined #openstack-keystone | 02:33 | |
*** ducttape_ has quit IRC | 02:37 | |
*** openstackgerrit has joined #openstack-keystone | 02:51 | |
openstackgerrit | Samriddhi proposed openstack/keystone master: Added configuration references to documentation https://review.openstack.org/474543 | 02:51 |
---|---|---|
*** aselius has quit IRC | 02:55 | |
openstackgerrit | Samriddhi proposed openstack/keystone master: WIP: Added configuration options using oslo.config https://review.openstack.org/479631 | 03:00 |
*** rajalokan has joined #openstack-keystone | 03:05 | |
*** markvoelker has joined #openstack-keystone | 03:06 | |
*** markvoelker has quit IRC | 03:39 | |
*** links has joined #openstack-keystone | 03:44 | |
*** gongysh has quit IRC | 03:54 | |
*** lbragstad has quit IRC | 03:55 | |
*** thorst has joined #openstack-keystone | 03:58 | |
*** thorst has quit IRC | 04:03 | |
*** goofie has quit IRC | 04:18 | |
*** gongysh has joined #openstack-keystone | 04:26 | |
*** ducttape_ has joined #openstack-keystone | 04:31 | |
*** ducttape_ has quit IRC | 04:35 | |
*** markvoelker has joined #openstack-keystone | 04:36 | |
*** mtreinish has quit IRC | 04:44 | |
*** mtreinish has joined #openstack-keystone | 04:51 | |
*** aojea has joined #openstack-keystone | 05:01 | |
*** markvoelker has quit IRC | 05:08 | |
*** ducttape_ has joined #openstack-keystone | 05:11 | |
*** ducttape_ has quit IRC | 05:16 | |
*** aojea has quit IRC | 05:20 | |
*** aojea has joined #openstack-keystone | 05:21 | |
*** aojea has quit IRC | 05:22 | |
*** aojea has joined #openstack-keystone | 05:23 | |
*** aojea has quit IRC | 05:28 | |
*** aojea has joined #openstack-keystone | 05:28 | |
*** aojea has quit IRC | 05:33 | |
*** tobberydberg has joined #openstack-keystone | 05:34 | |
*** edmondsw has joined #openstack-keystone | 05:40 | |
*** edmondsw has quit IRC | 05:45 | |
*** tobberyd_ has joined #openstack-keystone | 05:56 | |
*** thorst has joined #openstack-keystone | 05:59 | |
*** tobberydberg has quit IRC | 05:59 | |
*** thorst has quit IRC | 06:05 | |
*** markvoelker has joined #openstack-keystone | 06:05 | |
*** tobberyd_ is now known as tobberydberg | 06:17 | |
*** belmoreira has joined #openstack-keystone | 06:36 | |
*** markvoelker has quit IRC | 06:39 | |
*** tobberydberg has quit IRC | 06:53 | |
*** tobberydberg has joined #openstack-keystone | 06:53 | |
*** tobberydberg has quit IRC | 06:54 | |
*** tobberydberg has joined #openstack-keystone | 06:55 | |
*** tobberydberg has quit IRC | 06:59 | |
*** tobberydberg has joined #openstack-keystone | 06:59 | |
*** tesseract has joined #openstack-keystone | 07:02 | |
*** tobberydberg has quit IRC | 07:07 | |
*** tobberydberg has joined #openstack-keystone | 07:07 | |
*** tobberydberg has quit IRC | 07:08 | |
*** tobberydberg has joined #openstack-keystone | 07:09 | |
*** ducttape_ has joined #openstack-keystone | 07:12 | |
*** ducttape_ has quit IRC | 07:17 | |
*** rcernin has joined #openstack-keystone | 07:19 | |
*** edmondsw has joined #openstack-keystone | 07:29 | |
*** edmondsw has quit IRC | 07:33 | |
*** markvoelker has joined #openstack-keystone | 07:36 | |
*** xuhaigang has quit IRC | 07:40 | |
*** d0ugal has joined #openstack-keystone | 07:46 | |
*** d0ugal has quit IRC | 07:46 | |
*** d0ugal has joined #openstack-keystone | 07:46 | |
*** tobberydberg has quit IRC | 07:57 | |
*** tobberydberg has joined #openstack-keystone | 07:57 | |
*** zzzeek has quit IRC | 08:00 | |
*** thorst has joined #openstack-keystone | 08:01 | |
*** zzzeek has joined #openstack-keystone | 08:01 | |
*** xuhaigang has joined #openstack-keystone | 08:04 | |
*** thorst has quit IRC | 08:05 | |
*** tobberydberg has quit IRC | 08:06 | |
*** tobberydberg has joined #openstack-keystone | 08:07 | |
*** tobberydberg has quit IRC | 08:08 | |
*** markvoelker has quit IRC | 08:08 | |
*** tobberydberg has joined #openstack-keystone | 08:09 | |
*** tobberydberg has quit IRC | 08:09 | |
*** tobberydberg has joined #openstack-keystone | 08:09 | |
*** tobberydberg has quit IRC | 08:31 | |
*** tobberydberg has joined #openstack-keystone | 08:31 | |
*** tobberydberg has quit IRC | 08:33 | |
*** tobberydberg has joined #openstack-keystone | 08:33 | |
*** tobberydberg has quit IRC | 08:33 | |
*** tobberydberg has joined #openstack-keystone | 08:34 | |
*** links has quit IRC | 08:37 | |
*** tobberydberg has quit IRC | 08:38 | |
*** tobberydberg has joined #openstack-keystone | 08:39 | |
*** links has joined #openstack-keystone | 08:53 | |
openstackgerrit | Boris Bobrov proposed openstack/keystoneauth master: Change locations of docs for intersphinx https://review.openstack.org/480447 | 08:54 |
*** aojea has joined #openstack-keystone | 09:01 | |
*** tobberydberg has quit IRC | 09:03 | |
*** tobberydberg has joined #openstack-keystone | 09:04 | |
openstackgerrit | Boris Bobrov proposed openstack/python-keystoneclient master: Change locations of docs for intersphinx https://review.openstack.org/480453 | 09:04 |
openstackgerrit | Boris Bobrov proposed openstack/keystoneauth master: Change locations of docs for intersphinx https://review.openstack.org/480447 | 09:05 |
*** markvoelker has joined #openstack-keystone | 09:06 | |
*** tobberydberg has quit IRC | 09:08 | |
*** tobberydberg has joined #openstack-keystone | 09:08 | |
*** Shunli has quit IRC | 09:12 | |
*** ducttape_ has joined #openstack-keystone | 09:13 | |
*** edmondsw has joined #openstack-keystone | 09:17 | |
*** ducttape_ has quit IRC | 09:17 | |
breton | anybody awake? | 09:18 |
breton | could someone please review and approve https://review.openstack.org/#/c/480453/ ? | 09:19 |
knikolla | o/ | 09:21 |
*** edmondsw has quit IRC | 09:21 | |
openstackgerrit | Boris Bobrov proposed openstack/python-keystoneclient master: Bring back intersphinx reference to keystoneauth https://review.openstack.org/480465 | 09:21 |
openstackgerrit | Boris Bobrov proposed openstack/keystonemiddleware master: Change locations of docs for intersphinx https://review.openstack.org/480474 | 09:30 |
*** markvoelker has quit IRC | 09:39 | |
*** sjain has joined #openstack-keystone | 09:46 | |
*** links has quit IRC | 09:49 | |
samueldmq | sjain: hi | 09:51 |
samueldmq | morning | 09:51 |
*** sjain_ has joined #openstack-keystone | 09:53 | |
*** sjain has quit IRC | 09:55 | |
*** thorst has joined #openstack-keystone | 10:02 | |
*** links has joined #openstack-keystone | 10:03 | |
*** thorst has quit IRC | 10:06 | |
*** liujiong has quit IRC | 10:07 | |
*** ayoung has quit IRC | 10:15 | |
openstackgerrit | Stephen Finucane proposed openstack/oslo.policy master: sphinxext: Use field lists in output https://review.openstack.org/480502 | 10:24 |
*** ayoung has joined #openstack-keystone | 10:25 | |
*** markvoelker has joined #openstack-keystone | 10:36 | |
*** tobberydberg has quit IRC | 10:43 | |
*** tobberydberg has joined #openstack-keystone | 10:44 | |
*** zhurong has quit IRC | 10:45 | |
*** thorst has joined #openstack-keystone | 10:47 | |
*** thorst has quit IRC | 10:49 | |
*** thorst has joined #openstack-keystone | 11:00 | |
*** edmondsw has joined #openstack-keystone | 11:05 | |
*** sjain_ has quit IRC | 11:07 | |
*** tobberyd_ has joined #openstack-keystone | 11:08 | |
*** edmondsw has quit IRC | 11:09 | |
*** gongysh has quit IRC | 11:09 | |
*** markvoelker has quit IRC | 11:10 | |
*** tobberydberg has quit IRC | 11:11 | |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/oslo.policy master: import configuration guide content from openstack-manuals repo https://review.openstack.org/478597 | 11:26 |
*** thorst has quit IRC | 11:36 | |
openstackgerrit | Merged openstack/python-keystoneclient master: Change locations of docs for intersphinx https://review.openstack.org/480453 | 11:48 |
*** aojea has quit IRC | 11:54 | |
*** aojea has joined #openstack-keystone | 12:01 | |
*** raildo has joined #openstack-keystone | 12:01 | |
*** aojea has quit IRC | 12:05 | |
*** markvoelker has joined #openstack-keystone | 12:07 | |
*** aojea has joined #openstack-keystone | 12:10 | |
*** gongysh has joined #openstack-keystone | 12:11 | |
*** aojea has quit IRC | 12:15 | |
*** markvoelker has quit IRC | 12:16 | |
*** markvoelker has joined #openstack-keystone | 12:17 | |
*** edmondsw has joined #openstack-keystone | 12:22 | |
*** tobberyd_ is now known as tobberydberg | 12:24 | |
*** jmlowe has quit IRC | 12:28 | |
*** aojea has joined #openstack-keystone | 12:28 | |
*** dims has quit IRC | 12:29 | |
*** sjain has joined #openstack-keystone | 12:30 | |
*** aojea has quit IRC | 12:34 | |
*** sjain has quit IRC | 12:34 | |
*** sjain has joined #openstack-keystone | 12:34 | |
*** ducttape_ has joined #openstack-keystone | 12:36 | |
*** aojea has joined #openstack-keystone | 12:38 | |
*** gongysh has quit IRC | 12:38 | |
*** ducttape_ has quit IRC | 12:41 | |
*** aojea has quit IRC | 12:42 | |
*** thorst has joined #openstack-keystone | 12:44 | |
*** dims has joined #openstack-keystone | 12:44 | |
*** thorst_ has joined #openstack-keystone | 12:45 | |
*** thorst has quit IRC | 12:48 | |
*** sjain has quit IRC | 12:53 | |
*** jsavak has joined #openstack-keystone | 12:56 | |
*** lucasxu has joined #openstack-keystone | 13:00 | |
*** bknudson has joined #openstack-keystone | 13:04 | |
*** jmlowe has joined #openstack-keystone | 13:06 | |
*** sjain has joined #openstack-keystone | 13:12 | |
*** catintheroof has joined #openstack-keystone | 13:18 | |
*** links has quit IRC | 13:24 | |
*** zhurong has joined #openstack-keystone | 13:44 | |
*** jsavak has quit IRC | 13:57 | |
*** aojea has joined #openstack-keystone | 13:59 | |
*** dmellado has joined #openstack-keystone | 14:01 | |
dmellado | hi there, I wanted to ask you a question, I've noticed that there's no longer a 5000 port around there | 14:01 |
dmellado | is this related to the change to uswgi? | 14:01 |
dmellado | if so, how could I get back to having 5000 and 35357 ports around? | 14:02 |
dmellado | ayoung: ^^ rodrigods ^^ | 14:02 |
dmellado | thanks in advance! | 14:02 |
*** aojea has quit IRC | 14:02 | |
*** aojea has joined #openstack-keystone | 14:03 | |
*** ducttape_ has joined #openstack-keystone | 14:03 | |
dmellado | would I recover that by using KEYSTONE_DEPLOY=mod_wsgi ? | 14:04 |
openstackgerrit | Merged openstack/oslo.policy master: import configuration guide content from openstack-manuals repo https://review.openstack.org/478597 | 14:07 |
*** jsavak has joined #openstack-keystone | 14:08 | |
*** zhurong has quit IRC | 14:09 | |
openstackgerrit | Merged openstack/oslo.policy master: switch from oslosphinx to openstackdocstheme https://review.openstack.org/478596 | 14:20 |
breton | dmellado: why would you want it? | 14:21 |
dmellado | just for the sake of doing a test with another service, I know that that's no longer the default way | 14:22 |
dmellado | but for the sake of my test that'd be great of knowing if I could somehow revert that | 14:22 |
dmellado | xD | 14:22 |
dmellado | breton: is that related to the uswgi then? | 14:23 |
ayoung | dmellado, it is a deployment question | 14:29 |
ayoung | are you talking devstack>? | 14:29 |
dmellado | ayoung: yep, I'm talking about devstack | 14:29 |
ayoung | so 5000 is dumb, but if it is gone, it is cuz devstack finally realized that | 14:30 |
ayoung | and so I assume one of us put in a patch | 14:30 |
morgan | Afaik, devstack stopped listening on port 5000 | 14:30 |
dmellado | ayoung: I was thinking about https://github.com/openstack-dev/devstack/blob/master/lib/keystone#L64 | 14:30 |
dmellado | morgan: basically I'm trying to integrate it with mangeiq and that would expect a 5000 endpoint | 14:31 |
*** chlong_ has joined #openstack-keystone | 14:31 | |
morgan | dmellado: the idea is that you should need the high ports for keystone. Port 80 is sufficient | 14:31 |
dmellado | also I was trying to use the python-keystoneclient but couldn't get to connect there | 14:31 |
ayoung | if you have code that is explicitly looking for port 5000 instead of OS_AUTH_URL you are in a state of sin | 14:32 |
dmellado | morgan: so the example of https://github.com/openstack/python-keystoneclient | 14:32 |
ayoung | so, do not expect a deployment to do port anything | 14:32 |
dmellado | auth = v3.Password(auth_url="http://example.com:5000/v3 | 14:32 |
ayoung | getent services https | 14:32 |
morgan | That is a very old example | 14:32 |
dmellado | would now just be http://example.com/identity/v3 | 14:32 |
morgan | That we need to remove | 14:32 |
morgan | Yeah. That looks correct | 14:33 |
ayoung | dmellado, yep | 14:33 |
dmellado | hmmm I see | 14:33 |
dmellado | if just for the sake of testing I'd like to get back to the 5000 and 35357 env | 14:33 |
dmellado | how far in the past should I go? xD | 14:33 |
morgan | You'll need to manually add the elements to the keystone apache config | 14:34 |
morgan | Or ... Back to Ocata? | 14:34 |
dmellado | morgan: so back to ocata should be 'enough'? | 14:34 |
morgan | I think Ocata devstack still had the ports | 14:34 |
morgan | Might be mitaka | 14:34 |
dmellado | so stable/ocata for *both* devstack and ocata | 14:35 |
dmellado | and keystone | 14:35 |
morgan | Basically, you can configure keystone on the ports, but it is highly recommended to use port 80 | 14:35 |
morgan | Even in Ocata, we never tested against port 5000 | 14:35 |
dmellado | how could I configure keystone on that way? | 14:35 |
morgan | It was there just to be sure nothing broke | 14:35 |
morgan | You add listen directives and vhosts on those ports in the apache config | 14:36 |
*** rajalokan has quit IRC | 14:40 | |
dmellado | I see | 14:45 |
dmellado | morgan: sorry for disturbing you | 14:54 |
dmellado | I'm trying devstack stable/ocata | 14:54 |
dmellado | with keystone branch stable/ocata too | 14:54 |
dmellado | and I'm getting into this issue | 14:54 |
dmellado | 2017-07-05 14:52:28.490 | cp: cannot stat '/opt/stack/keystone/etc/policy.json': No such file or directory | 14:54 |
dmellado | does this rings a bell or I just should give up on this attempt xD | 14:55 |
*** bknudson has quit IRC | 14:59 | |
*** lucasxu has quit IRC | 15:00 | |
*** bknudson has joined #openstack-keystone | 15:01 | |
*** liujiong has joined #openstack-keystone | 15:03 | |
*** liujiong has quit IRC | 15:04 | |
*** lbragstad has joined #openstack-keystone | 15:05 | |
*** ChanServ sets mode: +o lbragstad | 15:05 | |
*** belmoreira has quit IRC | 15:06 | |
*** aselius has joined #openstack-keystone | 15:18 | |
*** rcernin has quit IRC | 15:21 | |
*** chlong has joined #openstack-keystone | 15:23 | |
*** chlong has quit IRC | 15:26 | |
ayoung | dmellado, looks like something hates policy | 15:29 |
ayoung | I suspect it has something to do with us generating policy.json instead of checking it in to git | 15:29 |
dmellado | ayoung: I'm redeploying from scratch from stable/ocata and checking | 15:29 |
*** bknudson has quit IRC | 15:30 | |
dmellado | who knows what can had happened with the 'downgrade' | 15:30 |
ayoung | dmellado, yeah, would not expect downgrade to be safe. Never have found it to work in any software product reliably. TOo many assumptions that are not really tested | 15:30 |
* ayoung an optimist | 15:30 | |
dmellado | hehehe | 15:31 |
*** bknudson has joined #openstack-keystone | 15:31 | |
*** lucasxu has joined #openstack-keystone | 15:35 | |
*** gyee has joined #openstack-keystone | 15:36 | |
*** jsavak has quit IRC | 15:37 | |
*** jdennis has quit IRC | 15:46 | |
*** dstepanenko has quit IRC | 15:48 | |
*** jsavak has joined #openstack-keystone | 15:52 | |
sjain | Hi, I'm working on docs and I need to link policy.json sample file somewhere, can anyone pls direct me where I can find one like https://git.openstack.org/cgit/openstack/keystone/plain/etc/policy.json?h=stable/ocata ? | 15:53 |
sjain | is it the yaml file created in doc/source/_static directory? | 15:54 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove duplicate token docs https://review.openstack.org/477638 | 15:56 |
lbragstad | stevemar: samueldmq I addressed your comments ^ | 15:56 |
*** sjain has quit IRC | 15:58 | |
*** chlong_ has quit IRC | 15:58 | |
*** aojea has quit IRC | 16:00 | |
openstackgerrit | Kelly Hall proposed openstack/keystone master: Trim Whitespace from X-Subject-Token https://review.openstack.org/470425 | 16:03 |
*** tobberyd_ has joined #openstack-keystone | 16:08 | |
*** tobberydberg has quit IRC | 16:08 | |
*** tobberyd_ has quit IRC | 16:09 | |
*** tobberydberg has joined #openstack-keystone | 16:09 | |
*** chlong_ has joined #openstack-keystone | 16:15 | |
*** sjain has joined #openstack-keystone | 16:21 | |
*** markvoelker has quit IRC | 16:24 | |
morgan | dmellado: you weren't disturbing me :) | 16:26 |
morgan | dmellado: you need to always deploy devstack clean (in my experience) | 16:26 |
morgan | downgrade is never safe ;) | 16:26 |
*** lucasxu has quit IRC | 16:27 | |
*** tobberydberg has quit IRC | 16:30 | |
*** markvoelker has joined #openstack-keystone | 16:30 | |
*** tobberydberg has joined #openstack-keystone | 16:30 | |
lbragstad | sjain: were you asking based on https://review.openstack.org/#/c/474543/7 ? | 16:31 |
sjain | @lbragstad: yes | 16:31 |
sjain | I have made all the changes | 16:31 |
sjain | just can't find the policy.json file | 16:32 |
lbragstad | sjain: the configuration ref is the last thing keystone needs for the doc-migration i think | 16:32 |
lbragstad | sjain: have you tried generating it? | 16:32 |
sjain | its almost done, the oslo.config part is also complete | 16:32 |
lbragstad | awesome | 16:32 |
sjain | how to do that, I'm not sure | 16:32 |
lbragstad | sjain: here is an example | 16:33 |
lbragstad | https://docs.openstack.org/oslo.policy/latest/user/sphinxpolicygen.html | 16:33 |
sjain | I have found a yaml file in _static directory | 16:33 |
sjain | yes | 16:33 |
sjain | I have included the other files with this only | 16:33 |
sjain | from the openstack manuals, there are 4 sample files ref that need to be included | 16:34 |
sjain | https://review.openstack.org/#/c/474543/7/doc/source/config-ref/samples/index.rst | 16:34 |
sjain | the other 3 I was able to find in etc/ directory | 16:34 |
sjain | or the doc/source/_static directory | 16:35 |
sjain | but I'm not able to find the exact match for policy.json | 16:35 |
lbragstad | sjain: that's because we generate the policy file from source | 16:35 |
lbragstad | we can also do that with the configuration file | 16:36 |
lbragstad | (both keystone.conf and policy.json can be generated) | 16:36 |
sjain | there is a file keystone.policy.yaml.sample in _static, is that the one? | 16:36 |
lbragstad | I'm not sure that the logging configuration can be generated and the keystone paste pipeline can't | 16:36 |
lbragstad | sjain: let me see if i can find the example | 16:37 |
sjain | https://github.com/openstack/keystone/tree/master/etc | 16:37 |
sjain | this keystone-paste is not an example? | 16:37 |
lbragstad | sjain: https://github.com/openstack/keystone/blob/master/etc/keystone-paste.ini is an example | 16:38 |
lbragstad | sjain: but we maintain it manually - instead of generating it | 16:38 |
sjain | okay, so I'll just reference it from here | 16:39 |
sjain | logging example is also there | 16:39 |
lbragstad | yeah | 16:39 |
*** toddnni has quit IRC | 16:39 | |
lbragstad | sjain: you should be able to reference the sample configuration file by doing something like this - https://github.com/openstack/keystone/blob/82f60fe22c405829f8e5f6576f25cf3663b10f73/doc/source/sample_files/sample_config.rst | 16:40 |
sjain | see there are some sample config files already included in docs | 16:40 |
sjain | yeah I was also referencing those | 16:40 |
sjain | in those the entire yaml file is directly used | 16:40 |
sjain | for this case I might need to convert it into json | 16:41 |
sjain | plus once this patch is complete, we may not need those sample_files ^^ | 16:41 |
lbragstad | right | 16:41 |
lbragstad | those can be removed that way we only maintain a single copy that lives in the configuration guide | 16:42 |
sjain | yeah | 16:42 |
sjain | so currently the file policy.json is rendered like this https://docs.openstack.org/ocata/config-reference/identity/samples/policy.json.html | 16:42 |
sjain | in openstack manuals | 16:42 |
lbragstad | sjain: i think what dhellmann is saying here is to link to the _static/ representation of the policy file or generate it using oslo.policy instead of using a remote link | 16:43 |
lbragstad | https://review.openstack.org/#/c/474543/7/doc/source/config-ref/samples/policy-json.rst | 16:43 |
sjain | I agree | 16:43 |
*** toddnni has joined #openstack-keystone | 16:44 | |
sjain | the only issue is that for the policy.json file, we have a yaml file and not a json one in _static directory | 16:44 |
sjain | so for now I'll just include that | 16:45 |
lbragstad | but it should render like this - https://docs.openstack.org/keystone/latest/sample_files/sample_policy.html | 16:45 |
sjain | yes right | 16:46 |
sjain | and what we want is https://docs.openstack.org/ocata/config-reference/identity/samples/policy.json.html | 16:46 |
lbragstad | ohhh | 16:46 |
lbragstad | i see what you mean | 16:46 |
sjain | yeah | 16:46 |
lbragstad | i personally think the .yaml format is fine | 16:46 |
lbragstad | sjain: is there a requirement saying that we have to generate a .json representation? | 16:47 |
sjain | okay | 16:47 |
sjain | None that I know of, it is just around the whole documentation we are saying use these sample files and we have not included a json file in that format | 16:48 |
lbragstad | ah | 16:49 |
lbragstad | the policy file can be in .yaml or .json format | 16:49 |
sjain | I'll probably use the .yaml file for now | 16:49 |
sjain | if needed, we will make changes later | 16:49 |
lbragstad | I'd argue the yaml format is better because it is easier to generate a sample with comments | 16:49 |
lbragstad | comments don't really exist in .json | 16:50 |
sjain | hmm right | 16:50 |
lbragstad | we've tried to do workaround for that in the past, but the yaml format actually supports it | 16:50 |
sjain | okay, so its better to keep it in that format then | 16:51 |
lbragstad | sjain: i would think so - unless asettle or dhellmann has a reason not to | 16:51 |
lbragstad | sjain: does that help? | 16:51 |
sjain | I'll ask them for review, lets see | 16:52 |
sjain | yeah, thanks :) | 16:52 |
lbragstad | sjain: cool - let me know when you need me to look at the next revision :) | 16:52 |
sjain | sure :) | 16:52 |
* lbragstad steps away for a minute | 16:52 | |
*** aojea has joined #openstack-keystone | 17:14 | |
*** aojea has quit IRC | 17:19 | |
*** chlong_ has quit IRC | 17:21 | |
*** sjain___ has joined #openstack-keystone | 17:26 | |
*** sjain has quit IRC | 17:26 | |
*** ducttape_ has quit IRC | 17:31 | |
*** chlong_ has joined #openstack-keystone | 17:33 | |
*** ducttape_ has joined #openstack-keystone | 17:38 | |
openstackgerrit | Samriddhi proposed openstack/keystone master: Added configuration references to documentation https://review.openstack.org/474543 | 17:53 |
sjain___ | Hi I'm trying to setup my environment, can someone please tell me how to step up fernet keys? | 17:57 |
*** bknudson has quit IRC | 17:59 | |
*** bknudson has joined #openstack-keystone | 18:00 | |
raildo | sjain___, depends on which version of Openstack you're doing the setup, is it on master? it's a devstack or a real deployment? | 18:05 |
*** Guest39045 is now known as med_ | 18:05 | |
*** med_ has joined #openstack-keystone | 18:05 | |
sjain___ | devstack I think | 18:06 |
raildo | if you're using the master, I believe that fernet is the default token provider | 18:07 |
sjain___ | okay so how should I set up those | 18:10 |
sjain___ | ? | 18:10 |
sjain___ | I'm trying to use this for setting up the environment, https://docs.openstack.org/keystone/latest/devref/development_best_practices.html | 18:10 |
raildo | sjain___, first of all this is an dev reference, so if you're trying to setup an dev environment that right, if not, you should take a look on the other version. For example on this session related to the token provider: https://docs.openstack.org/ocata/config-reference/identity/token-provider.html | 18:13 |
*** rderose has joined #openstack-keystone | 18:14 | |
sjain___ | raildo: yes, I need to set up the dev environment | 18:16 |
raildo | sjain___, so, did you follow those steps? like copy the keystone.conf file, run the server, create tables? | 18:18 |
raildo | sjain___, if you did so, you're already using fernet tokens in your dev env | 18:19 |
sjain___ | yes I'm getting this error "The request you have made requires authentication (HTTP 401)" | 18:19 |
sjain___ | samueldmq suggested that I should setup fernet tokens | 18:20 |
*** dave-mccowan has joined #openstack-keystone | 18:21 | |
raildo | on which request you got this error? | 18:22 |
sjain___ | when I ran tools/sample_data.sh | 18:23 |
raildo | sjain___, do you have the traceback? | 18:25 |
sjain___ | http://paste.openstack.org/show/614492/ | 18:25 |
raildo | hum... this doesn't looks like a clear environment, since everything already exists, are you running in using a virtual environment for this? | 18:27 |
sjain___ | yes I'm running it on a virtual environment | 18:28 |
raildo | sjain___, Did you tried the bootstrap? https://docs.openstack.org/keystone/latest/configuration.html | 18:30 |
sjain___ | yes I did, same result with that too | 18:30 |
raildo | sjain___, hum... that's weird... | 18:30 |
raildo | sjain___, so, i suggest execute the keystone-manage doctor, so we can figure out if there is any issue on this env, if you to try setup fernet tokens, you should try the keystone-manage fernet_setup command | 18:32 |
sjain___ | raildo: okay, I'll try that | 18:33 |
sjain___ | raildo: what is the exact command? | 18:34 |
raildo | sjain___, keystone-manage doctor | 18:34 |
sjain___ | keystone-manage doctor is giving me an error | 18:35 |
raildo | can you send a paste link with the error? | 18:35 |
sjain___ | http://paste.openstack.org/show/614494/ | 18:35 |
raildo | well this is weird, since it's a supported option in the configuration docs, just do an keystone-manage --help and see if you find any similar there | 18:36 |
raildo | are you sure that you're running this with the master version? | 18:37 |
sjain___ | master version meaning on the master branch? | 18:39 |
raildo | yeap | 18:39 |
sjain___ | yes | 18:39 |
sjain___ | I ran keystone-manage --help, no doctor option | 18:39 |
raildo | ok,did you tried authenticate on Keystone using the openstack cli? | 18:41 |
raildo | https://docs.openstack.org/keystone/latest/configuration.html | 18:42 |
raildo | so, we can check if your whole setup are weird or only this authentication method | 18:42 |
sjain___ | I haven't yet | 18:42 |
sjain___ | which commands should I follow from there? | 18:43 |
raildo | so, I suggest try with the openstack cli, since yoor log are showing that you already created the projects, users, domains... | 18:43 |
sjain___ | I tried openstack --os-token ADMIN --os-url http://127.0.0.1:35357/v2.0/ project list, it gave: __init__() got an unexpected keyword argument 'project_name' | 18:46 |
sjain___ | with openstack user list, it again gave : The request you have made requires authentication. (HTTP 401) | 18:46 |
raildo | sjain___, yeap, you should export the whole variables with the proper values that you have in your keystone.conf file | 18:46 |
openstackgerrit | Merged openstack/keystoneauth master: Change locations of docs for intersphinx https://review.openstack.org/480447 | 18:47 |
raildo | for example: | 18:47 |
*** rcernin has joined #openstack-keystone | 18:47 | |
raildo | http://paste.openstack.org/show/614495/ | 18:47 |
sjain___ | I followed these commands while setting up from here, https://docs.openstack.org/keystone/latest/devref/development_best_practices.html | 18:48 |
sjain___ | I'll try that again | 18:48 |
sjain___ | same error | 18:52 |
raildo | damn, I've to be off for a while, I'll try come back to help with other ways | 18:53 |
sjain___ | okay no prob, thanks :) | 18:54 |
openstackgerrit | Samriddhi proposed openstack/keystone master: Added configuration options using oslo.config https://review.openstack.org/479631 | 18:55 |
*** bknudson has quit IRC | 18:58 | |
*** bknudson has joined #openstack-keystone | 18:59 | |
*** bknudson has quit IRC | 19:01 | |
*** ducttape_ has quit IRC | 19:02 | |
*** jsavak has quit IRC | 19:03 | |
*** bknudson has joined #openstack-keystone | 19:04 | |
*** jsavak has joined #openstack-keystone | 19:04 | |
lbragstad | sjain___: I'm looking at your error | 19:06 |
lbragstad | sjain___: that doesn't look fernet specific | 19:06 |
sjain___ | okay, anything else which can be tried upon? | 19:07 |
lbragstad | sjain___: if keystone is missing fernet keys, but is configured to issued fernet tokens - we throw a 500 and fail to start https://github.com/openstack/keystone/blob/82f60fe22c405829f8e5f6576f25cf3663b10f73/keystone/token/providers/fernet/core.py#L33-L45 | 19:07 |
lbragstad | sjain___: how are you authenticating? | 19:07 |
lbragstad | sjain___: actually - what are you doing when you receive a 401? | 19:08 |
sjain___ | I tried this doc, https://docs.openstack.org/keystone/latest/devref/development_best_practices.html | 19:08 |
sjain___ | openstack user list | 19:09 |
lbragstad | sjain___: ah - i bet that information is stale | 19:09 |
sjain___ | tools/sample_data.sh | 19:09 |
sjain___ | both of these give me this error | 19:09 |
* samueldmq is back | 19:09 | |
lbragstad | sjain___: ah - you're just trying bootstrap your deployment I take it | 19:11 |
samueldmq | lbragstad: I was wondering why we dont just tell our devs to run keystone-manage bootstrap and go from there | 19:11 |
lbragstad | samueldmq: i'm wondering the exact same thing | 19:11 |
samueldmq | as opposed to tools/sample_data (which bootstraps much more data, used by devstack I think) | 19:12 |
lbragstad | i don't really see a reason to support two separate bootstrapping methods | 19:12 |
samueldmq | lbragstad: I think tools/sample_data is used by devstack | 19:12 |
lbragstad | hmm | 19:12 |
samueldmq | if it really is, we could move it to their repo? or maybe put in the devstack plugin/whateve directory | 19:12 |
lbragstad | samueldmq: or help devstack leverage keystone-manage bootstrap | 19:13 |
samueldmq | lbragstad: that'd awesome | 19:13 |
samueldmq | and we keep a single tool and don't confuse people :) | 19:13 |
*** chlong_ has quit IRC | 19:14 | |
samueldmq | lbragstad: for now I think we should ask sjain___ to replace "Initial Sample Data" with "Bootstrapping" | 19:14 |
samueldmq | putting a brief explanation on it + commands | 19:14 |
sjain___ | I tries bootstrapping command too, it didn't work for me | 19:15 |
sjain___ | *tried | 19:15 |
lbragstad | i believe we already have a section on bootstrapping keystone with `keystone-manage` | 19:15 |
samueldmq | sjain___: hmm, something might be wrong in your env then, keystone-manage bootstrap should have worked just fine | 19:15 |
sjain___ | I can add that | 19:15 |
sjain___ | ohh | 19:16 |
samueldmq | lbragstad: I think we have for the operator guide | 19:16 |
sjain___ | so what should I do now? | 19:16 |
lbragstad | sjain___: what trace do you get when you try to use keystone-manage bootstrap? | 19:16 |
* samueldmq #link https://docs.openstack.org/keystone/latest/configuration.html#bootstrapping-keystone-with-keystone-manage-bootstrap | 19:16 | |
lbragstad | samueldmq: yeah | 19:16 |
lbragstad | samueldmq: we also duplicate that documentation in the install guides | 19:16 |
samueldmq | lbragstad: ^ I wouldn't be opposed to putting just the command there and 1-2 lines of explanation | 19:17 |
lbragstad | which i think is probably fine | 19:17 |
samueldmq | and maybe point to the operator for further details | 19:17 |
sjain___ | I don't remember, let me run it again | 19:17 |
samueldmq | lbragstad: yes I think so, those docs have different purposes (testing,prod,etc), but all can/need to benefit from bootstrap | 19:17 |
samueldmq | and operator docs should definitely contain more details | 19:18 |
samueldmq | because it's prod | 19:18 |
sjain___ | samueldmq: lbragstad this I think works, http://paste.openstack.org/show/614501/ | 19:19 |
*** ducttape_ has joined #openstack-keystone | 19:20 | |
sjain___ | what should I try next? | 19:20 |
sjain___ | openstack user list again gives the same error HTTP 401 | 19:21 |
lbragstad | sjain___: ok - so bootstrap worked? | 19:21 |
sjain___ | yes, the output is in that link ^^ | 19:22 |
lbragstad | sjain___: cool - try authenticating as the admin user now | 19:22 |
sjain___ | but after that openstack user list again gave the same error | 19:22 |
lbragstad | samueldmq: i'm grepping the devstack project and I don't see that script used anywhere | 19:22 |
samueldmq | well, it's saying the user/project/etc already exists | 19:22 |
samueldmq | sjain___: ^ which means they have already been created | 19:23 |
lbragstad | sjain___: are you sure you have the right variables sourced? | 19:23 |
samueldmq | you may be passing the wrong password, for example | 19:23 |
sjain___ | they should be | 19:23 |
samueldmq | maybe wrong project, absence of projec | 19:23 |
samueldmq | might be different things ,make suere all your vars have the correct values | 19:23 |
samueldmq | lbragstad: ++ | 19:23 |
lbragstad | sjain___: can you copy/paste the exact bootstrap command you used? | 19:24 |
samueldmq | lbragstad: which is just cool. let's remove it (needs deprecation?) | 19:24 |
lbragstad | samueldmq: i wouldn't think so - but we should take it to the mailing list | 19:24 |
samueldmq | lbragstad: += | 19:24 |
lbragstad | both -dev and -operator mailing lists | 19:24 |
samueldmq | ++ | 19:24 |
lbragstad | just to double check | 19:24 |
sjain___ | I just used keystone-manage bootstrap --bootstrap-password s3cr3t | 19:25 |
samueldmq | lbragstad: there is a tool for searching code in openstack projects | 19:25 |
samueldmq | supported by infra I thing, we could try searching with that | 19:25 |
*** ducttap__ has joined #openstack-keystone | 19:25 | |
sjain___ | then this http://paste.openstack.org/show/614502/ | 19:25 |
lbragstad | samueldmq: http://codesearch.openstack.org/ | 19:25 |
*** ducttape_ has quit IRC | 19:26 | |
samueldmq | lbragstad: looks like just the rpm-packaging project uses it | 19:26 |
samueldmq | I agree with you the emails to the MLs is the right hting | 19:27 |
lbragstad | sjain___: my example adminrc file looks like this - http://paste.openstack.org/show/614503/ | 19:27 |
samueldmq | sjain___: if you go to http://localhost:5000 | 19:27 |
samueldmq | does it return you the discovery json? | 19:27 |
lbragstad | which i use by doing `source adminrc` then `openstack token issue` or whatever command i want | 19:27 |
samueldmq | lbragstad: sjain___: try eliminating the \ in your command | 19:28 |
samueldmq | and using it in a single line. I remember to have seen weird things when trying that for a demo | 19:28 |
sjain___ | okay I'll try that | 19:28 |
lbragstad | samueldmq: i wonder if the rpm-packaging project has an irc channel? | 19:30 |
*** chlong_ has joined #openstack-keystone | 19:30 | |
lbragstad | samueldmq: it doesn't look like they use it - they just package it | 19:30 |
samueldmq | lbragstad: ++ | 19:31 |
*** ducttape_ has joined #openstack-keystone | 19:34 | |
*** jsavak has quit IRC | 19:36 | |
lbragstad | samueldmq: done http://lists.openstack.org/pipermail/openstack-dev/2017-July/119309.html | 19:36 |
samueldmq | lbragstad: nice | 19:37 |
samueldmq | sjain___: have you tried that? | 19:37 |
sjain___ | yes, no luck | 19:37 |
sjain___ | same error | 19:37 |
samueldmq | sjain___: ok, can you get a clean env? | 19:37 |
*** ducttap__ has quit IRC | 19:38 | |
sjain___ | I tried with a new env | 19:38 |
sjain___ | deleted the previous one | 19:38 |
*** jsavak has joined #openstack-keystone | 19:40 | |
*** jsavak has quit IRC | 19:41 | |
*** jsavak has joined #openstack-keystone | 19:41 | |
samueldmq | sjain___: :( | 19:42 |
samueldmq | lbragstad: when simply running uwsgi with default .conf | 19:42 |
samueldmq | does it run on sqlite? | 19:42 |
lbragstad | sjain___: try `openstack project list --os-username admin --os-project-name admin --os-auth-url http://localhost:5000/v3 --os-password s3cr3t` | 19:43 |
lbragstad | samueldmq: that's a good question - i'm not sure | 19:43 |
sjain___ | smae | 19:44 |
sjain___ | *same | 19:44 |
lbragstad | oh | 19:46 |
lbragstad | sjain___: try rerunning bootstrap | 19:48 |
lbragstad | sjain___: with the endpoint and service information | 19:48 |
lbragstad | http://paste.openstack.org/show/614506/ | 19:48 |
sjain___ | same error again :( | 19:50 |
lbragstad | try `openstack token issue --os-username admin --os-project-name admin --os-auth-url http://localhost:5000/v3 --os-password s3cr3t` | 19:51 |
sjain___ | again the same error | 19:53 |
sjain___ | what do these statements do? | 19:53 |
lbragstad | sjain___: hmm - is this a devstack install? | 19:54 |
sjain___ | do they interact with mysql db? | 19:54 |
lbragstad | keystone-manage bootstrap connects to keystone and bypasses authentication to create initial data for keystone to run | 19:54 |
*** chlong_ has quit IRC | 19:55 | |
sjain___ | okay | 19:55 |
sjain___ | devstack install meaning? | 19:55 |
*** tesseract has quit IRC | 19:56 | |
lbragstad | sjain___: did you install the environment using devstack? https://github.com/openstack-dev/devstack/tree/master | 19:56 |
sjain___ | no | 19:56 |
sjain___ | I followed this https://docs.openstack.org/keystone/latest/devref/development_best_practices.html, and directly used the git repo | 19:57 |
lbragstad | sjain___: have you run the keystone-manage db_sync step? | 19:59 |
sjain___ | yes I did | 19:59 |
lbragstad | ok | 19:59 |
sjain___ | that worked fine | 19:59 |
lbragstad | are you running keystone on port 5000 or did you use the exact command above? | 20:00 |
lbragstad | $ uwsgi --http 127.0.0.1:35357 --wsgi-file $(which keystone-wsgi-admin) | 20:00 |
sjain___ | yes its running on port 5000, i checked that in browser | 20:01 |
*** bknudson has quit IRC | 20:01 | |
lbragstad | sjain___: did you install keystone into a virtualenv? | 20:01 |
lbragstad | using `pip install -e path/to/keystone` ? | 20:01 |
sjain___ | no, I don't remember doing that | 20:02 |
lbragstad | sjain___: what happens if you run `which keystone-wsgi-admin`? | 20:02 |
*** bknudson has joined #openstack-keystone | 20:03 | |
lbragstad | sjain___: does it give you the path of a file? | 20:03 |
sjain___ | yes this: /usr/bin/keystone-wsgi-admin | 20:03 |
lbragstad | hmm | 20:03 |
*** tobberyd_ has joined #openstack-keystone | 20:04 | |
lbragstad | i assume you see something similar for `which keystone-wsgi-public` | 20:04 |
sjain___ | hmm right, which keystone-wsgi-public | 20:04 |
lbragstad | ok | 20:04 |
sjain___ | this, /usr/bin/keystone-wsgi-public | 20:04 |
lbragstad | i wonder how you installed keystone? | 20:04 |
*** rcernin has quit IRC | 20:05 | |
sjain___ | I followed each step in that developer best practices | 20:05 |
lbragstad | sjain___: these? https://docs.openstack.org/keystone/latest/devref/development_environment.html | 20:06 |
sjain___ | I'll do one thing, I'll clone a new repo | 20:06 |
sjain___ | yes | 20:06 |
*** tobberydberg has quit IRC | 20:07 | |
sjain___ | I'll do everything on a new repo again | 20:07 |
*** tobberyd_ has quit IRC | 20:09 | |
breton | please review https://review.openstack.org/#/q/is:open+AND+(keystone+OR+keystoneauth+OR+keystonemiddleware+OR++oslo.cache+OR++python-keystoneclient)+AND+topic:doc-migration to unlock our docs | 20:11 |
breton | if gerrit has existing -1, recheck, because it might already get fixed | 20:11 |
breton | *if workflow | 20:12 |
breton | argh | 20:12 |
breton | *if jenkins has -1 | 20:12 |
*** rcernin has joined #openstack-keystone | 20:14 | |
*** bknudson has quit IRC | 20:16 | |
*** bknudson has joined #openstack-keystone | 20:16 | |
openstackgerrit | Raildo Mascena proposed openstack/keystone master: Fixing flushing tokens workflow https://review.openstack.org/480287 | 20:21 |
openstackgerrit | Merged openstack/keystone master: Remove duplicate token docs https://review.openstack.org/477638 | 20:22 |
*** tobberydberg has joined #openstack-keystone | 20:24 | |
lbragstad | breton: thanks - those look good | 20:26 |
*** tobberydberg has quit IRC | 20:27 | |
*** tobberyd_ has joined #openstack-keystone | 20:27 | |
*** sjain___ has quit IRC | 20:28 | |
*** raildo has quit IRC | 20:32 | |
*** chlong_ has joined #openstack-keystone | 20:44 | |
*** thorst_ has quit IRC | 20:55 | |
*** thorst has joined #openstack-keystone | 20:57 | |
*** jmlowe has quit IRC | 21:01 | |
*** thorst has quit IRC | 21:01 | |
*** jsavak has quit IRC | 21:01 | |
*** aojea has joined #openstack-keystone | 21:01 | |
*** aojea has quit IRC | 21:06 | |
*** chlong_ has quit IRC | 21:18 | |
*** rderose has quit IRC | 21:18 | |
*** aojea has joined #openstack-keystone | 21:21 | |
*** rderose has joined #openstack-keystone | 21:22 | |
*** rderose has quit IRC | 21:24 | |
*** rderose_ has joined #openstack-keystone | 21:24 | |
*** edmondsw has quit IRC | 21:31 | |
*** thorst has joined #openstack-keystone | 21:31 | |
*** edmondsw has joined #openstack-keystone | 21:33 | |
openstackgerrit | Merged openstack/keystonemiddleware master: Updated from global requirements https://review.openstack.org/477946 | 21:35 |
*** thorst has quit IRC | 21:35 | |
*** edmondsw has quit IRC | 21:38 | |
*** rderose_ has quit IRC | 22:04 | |
*** rderose has joined #openstack-keystone | 22:04 | |
*** rderose_ has joined #openstack-keystone | 22:05 | |
*** rderose has quit IRC | 22:05 | |
openstackgerrit | Kelly Hall proposed openstack/keystone master: Trims whitespace from request headers https://review.openstack.org/470425 | 22:07 |
*** aojea has quit IRC | 22:09 | |
*** rderose_ has quit IRC | 22:10 | |
*** aojea has joined #openstack-keystone | 22:10 | |
*** edmondsw has joined #openstack-keystone | 22:11 | |
*** aojea has quit IRC | 22:14 | |
*** edmondsw has quit IRC | 22:16 | |
openstackgerrit | Kelly Hall proposed openstack/keystone master: Trims whitespace from request headers https://review.openstack.org/470425 | 22:18 |
*** bknudson has quit IRC | 22:23 | |
*** ayoung has quit IRC | 22:45 | |
*** rcernin has quit IRC | 22:45 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Update security compliance documentation https://review.openstack.org/479357 | 22:47 |
*** thorst has joined #openstack-keystone | 23:12 | |
*** thorst has quit IRC | 23:12 | |
*** ducttape_ has quit IRC | 23:12 | |
*** thorst has joined #openstack-keystone | 23:19 | |
*** ducttape_ has joined #openstack-keystone | 23:23 | |
*** hemna is now known as assbutt | 23:25 | |
*** assbutt is now known as buttass | 23:26 | |
*** buttass is now known as butt | 23:26 | |
*** ducttape_ has quit IRC | 23:28 | |
openstackgerrit | Jaewoo Park proposed openstack/keystone master: WIP: Add project tags https://review.openstack.org/470317 | 23:40 |
*** hoonetorg has quit IRC | 23:47 | |
*** catintheroof has quit IRC | 23:47 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!