*** thorst has joined #openstack-keystone | 00:08 | |
*** thorst has quit IRC | 00:09 | |
*** nicolasbock has quit IRC | 00:35 | |
*** nicolasbock has joined #openstack-keystone | 00:42 | |
*** MeltedLux has joined #openstack-keystone | 00:50 | |
*** Shunli has joined #openstack-keystone | 00:58 | |
*** thorst has joined #openstack-keystone | 01:06 | |
*** thorst has quit IRC | 01:06 | |
*** panbalag has joined #openstack-keystone | 01:10 | |
*** aselius has quit IRC | 01:16 | |
*** shengping has joined #openstack-keystone | 01:34 | |
*** shengping has quit IRC | 01:54 | |
*** thorst has joined #openstack-keystone | 02:07 | |
*** erlon has quit IRC | 02:48 | |
*** thorst has quit IRC | 02:48 | |
*** panbalag has quit IRC | 02:58 | |
*** jamesbenson has joined #openstack-keystone | 03:05 | |
*** itlinux has joined #openstack-keystone | 03:12 | |
*** aojea has joined #openstack-keystone | 03:17 | |
*** nicolasbock has quit IRC | 03:21 | |
*** aojea has quit IRC | 03:22 | |
*** gyee has quit IRC | 03:33 | |
*** itlinux has quit IRC | 03:41 | |
*** thorst has joined #openstack-keystone | 03:45 | |
*** jamesbenson has quit IRC | 04:13 | |
*** thorst has quit IRC | 04:16 | |
*** jaosorior has joined #openstack-keystone | 04:19 | |
*** jdennis has joined #openstack-keystone | 04:23 | |
*** spotz_ has joined #openstack-keystone | 04:24 | |
*** bigjools_ has joined #openstack-keystone | 04:25 | |
*** cburgess has quit IRC | 04:29 | |
*** spotz has quit IRC | 04:29 | |
*** jrist has quit IRC | 04:29 | |
*** jdennis1 has quit IRC | 04:29 | |
*** iurygregory has quit IRC | 04:29 | |
*** obre has quit IRC | 04:29 | |
*** bigjools has quit IRC | 04:29 | |
*** chrome0 has quit IRC | 04:29 | |
*** cburgess has joined #openstack-keystone | 04:30 | |
*** chrome0 has joined #openstack-keystone | 04:31 | |
*** john5223_ has quit IRC | 04:32 | |
*** jrist has joined #openstack-keystone | 04:36 | |
*** obre has joined #openstack-keystone | 04:36 | |
*** iurygregory has joined #openstack-keystone | 04:36 | |
*** Shunli has quit IRC | 04:42 | |
*** zhurong has joined #openstack-keystone | 05:13 | |
*** thorst has joined #openstack-keystone | 05:13 | |
*** aojea has joined #openstack-keystone | 05:42 | |
*** thorst has quit IRC | 05:47 | |
*** jamesbenson has joined #openstack-keystone | 06:01 | |
*** jamesbenson has quit IRC | 06:06 | |
*** rcernin has joined #openstack-keystone | 06:39 | |
*** thorst has joined #openstack-keystone | 06:45 | |
*** cfriesen_ has quit IRC | 06:46 | |
*** lamt has quit IRC | 07:16 | |
*** Dinesh_Bhor has quit IRC | 07:17 | |
*** thorst has quit IRC | 07:17 | |
*** Dinesh_Bhor has joined #openstack-keystone | 07:21 | |
*** tesseract has joined #openstack-keystone | 07:21 | |
*** jaosorior has quit IRC | 07:31 | |
*** ioggstream has joined #openstack-keystone | 07:41 | |
*** jaosorior has joined #openstack-keystone | 07:46 | |
*** efried has quit IRC | 08:08 | |
*** zhurong has quit IRC | 08:11 | |
*** thorst has joined #openstack-keystone | 08:14 | |
*** efried has joined #openstack-keystone | 08:19 | |
*** zhurong has joined #openstack-keystone | 08:29 | |
*** chlong has quit IRC | 08:49 | |
*** thorst has quit IRC | 08:50 | |
*** mvk has quit IRC | 09:34 | |
*** jamesbenson has joined #openstack-keystone | 09:38 | |
*** josecastroleon has joined #openstack-keystone | 09:41 | |
*** jamesbenson has quit IRC | 09:42 | |
*** thorst has joined #openstack-keystone | 09:47 | |
*** afazekas is now known as afazekas|seek4fo | 09:48 | |
openstackgerrit | Thomas Duval proposed openstack/oslo.policy master: Modification to add additional information in the HTTPCheck request. https://review.openstack.org/498467 | 09:53 |
---|---|---|
*** josecastroleon has quit IRC | 10:00 | |
*** d0ugal has joined #openstack-keystone | 10:03 | |
*** thorst has quit IRC | 10:18 | |
*** zhurong has quit IRC | 10:20 | |
*** mvk has joined #openstack-keystone | 10:48 | |
*** d0ugal has quit IRC | 10:48 | |
*** nicolasbock has joined #openstack-keystone | 11:00 | |
*** d0ugal has joined #openstack-keystone | 11:02 | |
*** nicolasbock has quit IRC | 11:04 | |
*** timothyb89 has quit IRC | 11:11 | |
*** jaosorior is now known as jaosorior_sick | 11:12 | |
*** thorst has joined #openstack-keystone | 11:15 | |
*** thorst has quit IRC | 11:27 | |
*** pcaruana has joined #openstack-keystone | 11:27 | |
*** panbalag has joined #openstack-keystone | 11:35 | |
*** panbalag has quit IRC | 11:38 | |
*** ioggstream has quit IRC | 11:39 | |
*** dave-mccowan has joined #openstack-keystone | 11:50 | |
*** thorst has joined #openstack-keystone | 11:55 | |
*** dave-mccowan has quit IRC | 12:01 | |
*** dave-mccowan has joined #openstack-keystone | 12:04 | |
*** afazekas|seek4fo is now known as afazekas | 12:09 | |
*** raildo has joined #openstack-keystone | 12:13 | |
*** edmondsw has joined #openstack-keystone | 12:17 | |
*** ioggstream has joined #openstack-keystone | 12:20 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystonemiddleware master: Updated from global requirements https://review.openstack.org/500005 | 12:44 |
*** jmlowe has quit IRC | 12:48 | |
*** Suramya has joined #openstack-keystone | 12:50 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/pycadf master: Updated from global requirements https://review.openstack.org/470137 | 12:52 |
*** panbalag has joined #openstack-keystone | 12:54 | |
*** panbalag has left #openstack-keystone | 12:54 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystonemiddleware master: Updated from global requirements https://review.openstack.org/500005 | 13:01 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/pycadf master: Updated from global requirements https://review.openstack.org/470137 | 13:09 |
openstackgerrit | Suramya proposed openstack/keystone master: Reorganize api-ref: v3 domains https://review.openstack.org/505135 | 13:10 |
*** jistr is now known as jistr|call | 13:12 | |
*** lucasxu has joined #openstack-keystone | 13:14 | |
*** nkinder has quit IRC | 13:23 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystonemiddleware master: Updated from global requirements https://review.openstack.org/500005 | 13:24 |
*** lbragstad has joined #openstack-keystone | 13:27 | |
*** ChanServ sets mode: +o lbragstad | 13:27 | |
*** sbezverk has joined #openstack-keystone | 13:27 | |
*** chlong has joined #openstack-keystone | 13:29 | |
*** josecastroleon has joined #openstack-keystone | 13:30 | |
*** chlong has quit IRC | 13:31 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/pycadf master: Updated from global requirements https://review.openstack.org/470137 | 13:32 |
*** jmlowe has joined #openstack-keystone | 13:34 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystonemiddleware master: Updated from global requirements https://review.openstack.org/500005 | 13:40 |
*** ayoung has quit IRC | 13:44 | |
openstackgerrit | Merged openstack/oslo.policy master: Modification to add additional information in the HTTPCheck request. https://review.openstack.org/498467 | 13:45 |
*** lifeless has quit IRC | 13:46 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/pycadf master: Updated from global requirements https://review.openstack.org/470137 | 13:48 |
*** lifeless has joined #openstack-keystone | 13:54 | |
*** dave-mccowan has quit IRC | 13:54 | |
*** Drankis has joined #openstack-keystone | 14:06 | |
*** alex_xu has quit IRC | 14:18 | |
*** alex_xu has joined #openstack-keystone | 14:21 | |
*** dave-mccowan has joined #openstack-keystone | 14:26 | |
*** jistr|call is now known as jistr | 14:27 | |
*** jamesbenson has joined #openstack-keystone | 14:29 | |
*** jmlowe has quit IRC | 14:31 | |
*** jmlowe has joined #openstack-keystone | 14:37 | |
*** dave-mccowan has quit IRC | 14:38 | |
*** josecastroleon has quit IRC | 14:39 | |
*** Drankis has quit IRC | 14:40 | |
*** alex_xu has quit IRC | 14:44 | |
*** dave-mccowan has joined #openstack-keystone | 14:44 | |
*** jmlowe has quit IRC | 14:48 | |
*** jmlowe has joined #openstack-keystone | 14:48 | |
*** alex_xu has joined #openstack-keystone | 14:49 | |
*** dave-mcc_ has joined #openstack-keystone | 14:49 | |
*** dave-mccowan has quit IRC | 14:51 | |
hrybacki | lbragstad: regarding https://review.openstack.org/#/c/507434 -- I did confirm that the patch is in both master and stable/pike | 14:58 |
*** Suramya has quit IRC | 14:58 | |
lbragstad | hrybacki: so https://review.openstack.org/#/c/507434 is a backport to stable/ocata from https://review.openstack.org/#/c/465530/ which merged to master 30 hours ago | 14:59 |
*** cfriesen_ has joined #openstack-keystone | 15:00 | |
hrybacki | lbragstad: it was cherry-picked against ocata 30 hours ago but on master (now Pike) on Aug 1 IIRC | 15:01 |
knikolla | o/ | 15:01 |
lbragstad | hrybacki: bah - i'm backwards today | 15:01 |
hrybacki | lbragstad: no worries: https://github.com/openstack/keystone/commit/630d9b58fd957e8bb27a99ac5cd73a58826c6fc2 for verifcation | 15:02 |
hrybacki | o/ knikolla | 15:02 |
*** jmlowe has quit IRC | 15:03 | |
*** jmlowe has joined #openstack-keystone | 15:04 | |
*** gyee has joined #openstack-keystone | 15:05 | |
hrybacki | any cores able to review/+2 ^^? I know there are two LP's associated with it and live deployments being affected | 15:05 |
lbragstad | hrybacki: kmalloc and stevemar should kick that through | 15:08 |
hrybacki | lbragstad: ack, thanks | 15:14 |
*** chlong has joined #openstack-keystone | 15:17 | |
*** ayoung has joined #openstack-keystone | 15:19 | |
*** josecastroleon has joined #openstack-keystone | 15:21 | |
gagehugo | o/ | 15:31 |
*** jmlowe has quit IRC | 15:32 | |
*** rcernin has quit IRC | 15:43 | |
*** josecastroleon has quit IRC | 15:44 | |
kmalloc | Will do shortly | 15:51 |
kmalloc | Getting setup for the day | 15:51 |
*** erlon has joined #openstack-keystone | 15:55 | |
*** timothyb89 has joined #openstack-keystone | 16:03 | |
*** sbezverk has quit IRC | 16:03 | |
*** r-daneel has joined #openstack-keystone | 16:12 | |
*** tesseract has quit IRC | 16:24 | |
*** jmlowe has joined #openstack-keystone | 16:35 | |
kmalloc | lbragstad: pushed through | 16:36 |
hrybacki | kmalloc++ | 16:36 |
hrybacki | thanks! | 16:36 |
*** david-lyle has quit IRC | 16:40 | |
*** mvk has quit IRC | 16:44 | |
*** d0ugal has quit IRC | 16:50 | |
*** ioggstream has quit IRC | 16:50 | |
stevemar | lbragstad: ? | 16:53 |
hrybacki | stevemar there was a review being backported but it's now approved | 16:55 |
*** dave-mcc_ has quit IRC | 17:06 | |
kmARC | hi all, I'm trying to figure out how to connect to keystone via CLI. Using openstackclient >v3.0.0 I have multiple options, like v3oidc{clientcredentials,password}. Unfortunately both these result in a HTTP405, Method not allowed error. Reason is, the auth plugin tries to `POST` to my keycloak IDP server at one point, however it says: "Allow: HEAD, GET, OPTIONS" | 17:09 |
kmARC | _authentication_ seems to work, if I give in a wrong password, I get authentication error | 17:09 |
kmARC | The current setup also works with horizon | 17:09 |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/oslo.policy master: External Policy hook should support SSL https://review.openstack.org/491783 | 17:09 |
kmARC | Any insights where I should start looking? | 17:09 |
stevemar | hrybacki: yay | 17:10 |
*** dave-mccowan has joined #openstack-keystone | 17:11 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystonemiddleware master: Updated from global requirements https://review.openstack.org/500005 | 17:11 |
*** david-lyle has joined #openstack-keystone | 17:13 | |
*** pcaruana has quit IRC | 17:14 | |
*** itlinux has joined #openstack-keystone | 17:17 | |
*** tonytan4ever has joined #openstack-keystone | 17:18 | |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/oslo.policy master: http/https check rules as stevedore extensions https://review.openstack.org/507098 | 17:19 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/pycadf master: Updated from global requirements https://review.openstack.org/470137 | 17:19 |
*** nkinder has joined #openstack-keystone | 17:35 | |
*** aselius has joined #openstack-keystone | 17:37 | |
*** itlinux has quit IRC | 17:51 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Specification for system roles https://review.openstack.org/464763 | 17:56 |
lbragstad | knikolla: cmurphy hrybacki kmalloc ^ | 17:57 |
hrybacki | woo | 17:57 |
lbragstad | i reworked the entire global roles specification to fit the conversations from the PTG | 17:57 |
kmalloc | lbragstad: https://review.openstack.org/#/c/507098/6 please note my comment | 17:57 |
*** cfriesen_ has quit IRC | 17:57 | |
kmalloc | oslo.policy related things | 17:57 |
lbragstad | i also added a section that highlights the difference between system and global | 17:57 |
lbragstad | kmalloc: ack | 17:57 |
lbragstad | cc dims ^ | 17:58 |
kmalloc | mordred: https://review.openstack.org/#/c/464763/17 (see above), this is of interest to you, shade, and generally people running/consuming clouds (cc fungi ) would like your views as well | 17:58 |
dims | lbragstad : ack thanks will line it up for later | 17:58 |
mordred | lbragstad, kmalloc: ack. it's open in a window | 17:59 |
kmalloc | lbragstad: one comment, but otherwise that represents what we discussed | 18:03 |
*** cfriesen_ has joined #openstack-keystone | 18:03 | |
kmalloc | lbragstad: i'd like to see what other folks thing | 18:03 |
kmalloc | think* | 18:03 |
lbragstad | same here | 18:03 |
lbragstad | fwiw - it felt way more natural to use the term system over global | 18:03 |
kmalloc | yeah, that bit makes this a lot easier to understand | 18:04 |
lbragstad | right - its a lot more clear what a "system" operation is versus a "global" operation | 18:05 |
kmalloc | dims: removed the -1, entrypoints are a security risk | 18:08 |
lbragstad | I also modified the path to include system, which i think will help if we eventually want make it a hierarchy | 18:08 |
kmalloc | dims: i would, given full license to do so, remove their uses from openstack or at least keystone and all security-related things | 18:09 |
kmalloc | but i wont hold this up. i've voiced my concerns | 18:09 |
dims | kmalloc : if we get to a point when someone can inject a python package to be installed ... they already own you. no? | 18:10 |
dims | kmalloc : ack and thanks | 18:10 |
kmalloc | not really, you can register any entrypoint namespace | 18:10 |
kmalloc | this could allow *any* pythong package to register something that could be loaded by oslo.policy | 18:11 |
kmalloc | and if the module conflicts... you get both back, depending on how things are built in stevedore among other places you could grab the wrong one | 18:11 |
kmalloc | which is name-sorted | 18:11 |
kmalloc | it's ... lets just say entrypoints are not fun in this regard | 18:11 |
dims | understood kmalloc | 18:11 |
*** pcaruana has joined #openstack-keystone | 18:15 | |
cfriesen_ | just wondering if there is any documentation on what caching backends are recommended for keystone. I found https://docs.openstack.org/keystone/latest/admin/identity-caching-layer.html but it doens't really have opinions. | 18:35 |
cfriesen_ | kmalloc: with respect to https://review.openstack.org/#/c/505345/ (limiting the endpoints returned) are you saying that "give me the endpoints for this region/service-type" would be slower than "give me all the endpoints for all service types across ~20 regions"? | 18:36 |
kmalloc | in keystone, yes | 18:41 |
kmalloc | it is likely going to be much slower on the keystone side due to how we pull the data from the db | 18:41 |
kmalloc | in the clinet, parsing the data will be faster. | 18:42 |
kmalloc | it'll be a tradeoff | 18:42 |
kmalloc | cfriesen_: i haven't had time to look at the implications | 18:45 |
hrybacki | anyone here muck with aws / ec2 stuff? | 18:47 |
*** sbezverk has joined #openstack-keystone | 18:54 | |
*** pcaruana has quit IRC | 19:00 | |
*** r-daneel has quit IRC | 19:02 | |
*** r-daneel has joined #openstack-keystone | 19:03 | |
*** tonytan4ever has quit IRC | 19:06 | |
*** tonytan4ever has joined #openstack-keystone | 19:07 | |
cfriesen_ | kmalloc: no worries...I expected that we would be able to retrieve the service based on the type, and then look up the endpoint based on the region and service_id. I assumed this would be faster than retrieving maybe 100+ endpoints and formatting them to send in the response. | 19:09 |
kmalloc | I think we need a lot more index to do that. | 19:10 |
kmalloc | Which is... Painful with the rolling upgrade support. | 19:10 |
*** edmondsw has quit IRC | 19:15 | |
*** edmondsw has joined #openstack-keystone | 19:18 | |
*** edmondsw has quit IRC | 19:23 | |
*** jmlowe has quit IRC | 19:25 | |
*** edmondsw has joined #openstack-keystone | 19:47 | |
*** edmondsw has quit IRC | 19:48 | |
*** edmondsw has joined #openstack-keystone | 19:48 | |
*** markvoelker has quit IRC | 19:48 | |
*** markvoelker has joined #openstack-keystone | 19:49 | |
*** r-daneel has quit IRC | 20:14 | |
*** r-daneel has joined #openstack-keystone | 20:15 | |
*** aselius has quit IRC | 20:17 | |
*** belmoreira has joined #openstack-keystone | 20:32 | |
*** aojea has quit IRC | 20:44 | |
*** belmoreira has quit IRC | 20:44 | |
*** aojea has joined #openstack-keystone | 20:49 | |
lbragstad | kmalloc: ping | 20:50 |
kmalloc | lbragstad: pong | 20:50 |
lbragstad | kmalloc: so you know how we had the system roles discussion | 20:51 |
* kmalloc plays atari with lbragstad | 20:51 | |
kmalloc | uh, yeah | 20:51 |
lbragstad | and we talked about making the system assignment stuff a lot simpler than the existing assignment api (less kwargs and more explicit methods)? | 20:51 |
*** lucasxu has quit IRC | 20:52 | |
lbragstad | kmalloc: do you think it's fine to add a bunch of methods like `list_system_grants_for_user`, `list_system_grants_for_group`, etc... | 20:52 |
kmalloc | hm. | 20:52 |
lbragstad | like - in the assignment backend? | 20:53 |
kmalloc | i don't think it's an issue | 20:53 |
lbragstad | then everything is invoked by the manager? | 20:53 |
kmalloc | yeah. | 20:53 |
lbragstad | ok | 20:53 |
lbragstad | i'm working through the implementation now and realizing how many method signatures are going to be added to that backend | 20:53 |
*** mvk has joined #openstack-keystone | 21:02 | |
*** thorst has quit IRC | 21:09 | |
*** ayoung has quit IRC | 21:10 | |
*** thorst has joined #openstack-keystone | 21:11 | |
*** thorst has quit IRC | 21:15 | |
*** raildo has quit IRC | 21:23 | |
*** thorst has joined #openstack-keystone | 21:29 | |
*** thorst has quit IRC | 21:34 | |
*** itlinux has joined #openstack-keystone | 21:36 | |
*** gyee has quit IRC | 21:44 | |
*** dave-mccowan has quit IRC | 21:45 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add a new table for system role assignments https://review.openstack.org/507993 | 21:45 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement backend logic for system roles https://review.openstack.org/507994 | 21:45 |
*** jamesbenson has quit IRC | 21:55 | |
*** jamesbenson has joined #openstack-keystone | 21:57 | |
*** dave-mccowan has joined #openstack-keystone | 21:57 | |
*** thorst has joined #openstack-keystone | 21:58 | |
*** aojea has quit IRC | 21:58 | |
*** jamesbenson has quit IRC | 21:58 | |
*** jamesbenson has joined #openstack-keystone | 22:00 | |
*** dave-mccowan has quit IRC | 22:03 | |
*** jamesbenson has quit IRC | 22:04 | |
*** edmondsw has quit IRC | 22:23 | |
openstackgerrit | Merged openstack/keystone master: Migrate to stestr https://review.openstack.org/504442 | 22:58 |
*** thorst has quit IRC | 23:30 | |
*** jmlowe has joined #openstack-keystone | 23:32 | |
*** jamesbenson has joined #openstack-keystone | 23:35 | |
*** edmondsw has joined #openstack-keystone | 23:40 | |
*** jamesbenson has quit IRC | 23:40 | |
*** edmondsw has quit IRC | 23:44 | |
*** jmlowe has quit IRC | 23:52 | |
*** jmlowe has joined #openstack-keystone | 23:53 | |
*** r-daneel has quit IRC | 23:58 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!