*** jistr has quit IRC | 00:00 | |
*** jistr has joined #openstack-keystone | 00:01 | |
*** lnxnut has joined #openstack-keystone | 00:11 | |
*** lnxnut has quit IRC | 00:21 | |
*** tonytan4ever has quit IRC | 00:27 | |
*** gyee has joined #openstack-keystone | 00:36 | |
*** itlinux has joined #openstack-keystone | 00:36 | |
*** itlinux has quit IRC | 00:58 | |
*** markvoelker has joined #openstack-keystone | 01:01 | |
*** lnxnut has joined #openstack-keystone | 01:18 | |
*** tonytan4ever has joined #openstack-keystone | 01:20 | |
*** nicolasbock_ has quit IRC | 01:26 | |
*** lnxnut has quit IRC | 01:29 | |
*** itlinux has joined #openstack-keystone | 01:35 | |
*** oikiki has joined #openstack-keystone | 01:37 | |
*** itlinux has quit IRC | 01:42 | |
*** oikiki has quit IRC | 01:44 | |
*** gyee has quit IRC | 01:47 | |
*** catintheroof has joined #openstack-keystone | 02:03 | |
*** catintheroof has quit IRC | 02:19 | |
*** lnxnut has joined #openstack-keystone | 02:26 | |
*** catintheroof has joined #openstack-keystone | 02:29 | |
*** lnxnut has quit IRC | 02:36 | |
*** MasterOfBugs has quit IRC | 02:56 | |
*** erlon has quit IRC | 03:01 | |
*** catintheroof has quit IRC | 03:09 | |
*** itlinux has joined #openstack-keystone | 03:23 | |
*** itlinux has quit IRC | 03:31 | |
*** itlinux has joined #openstack-keystone | 03:32 | |
*** lnxnut has joined #openstack-keystone | 03:34 | |
*** itlinux has quit IRC | 03:41 | |
*** lnxnut has quit IRC | 03:44 | |
*** boris_42_ has quit IRC | 03:44 | |
openstackgerrit | Merged openstack/oslo.policy master: External Policy hook should support SSL https://review.openstack.org/491783 | 03:52 |
---|---|---|
openstackgerrit | Merged openstack/keystone master: Add test GET for member url in the Assignment API https://review.openstack.org/499977 | 03:54 |
*** tristanC has quit IRC | 04:16 | |
*** tristanC has joined #openstack-keystone | 04:23 | |
*** tbh_ has joined #openstack-keystone | 04:31 | |
*** prashkre has joined #openstack-keystone | 04:38 | |
*** lnxnut has joined #openstack-keystone | 04:40 | |
*** prashkre has quit IRC | 05:00 | |
*** lnxnut has quit IRC | 05:06 | |
*** aojea has joined #openstack-keystone | 05:08 | |
*** tonytan4ever has quit IRC | 05:12 | |
*** prashkre has joined #openstack-keystone | 05:17 | |
*** markvoelker has quit IRC | 05:20 | |
*** prashkre has quit IRC | 05:22 | |
*** prashkre has joined #openstack-keystone | 05:26 | |
*** lnxnut has joined #openstack-keystone | 05:33 | |
*** aojea has quit IRC | 05:35 | |
*** lnxnut has quit IRC | 05:37 | |
*** akrzos has quit IRC | 05:54 | |
*** jmlowe has quit IRC | 05:55 | |
*** jmlowe has joined #openstack-keystone | 05:56 | |
*** aojea has joined #openstack-keystone | 05:57 | |
*** oikiki has joined #openstack-keystone | 06:03 | |
*** cfriesen has quit IRC | 06:04 | |
*** prashkre_ has joined #openstack-keystone | 06:08 | |
*** prashkre has quit IRC | 06:08 | |
*** prashkre__ has joined #openstack-keystone | 06:09 | |
*** aojea has quit IRC | 06:10 | |
*** rm_work has quit IRC | 06:11 | |
*** prashkre_ has quit IRC | 06:13 | |
*** rm_work has joined #openstack-keystone | 06:14 | |
*** akrzos has joined #openstack-keystone | 06:22 | |
openstackgerrit | Merged openstack/keystone master: Remove middleware reference to PARAMS_ENV and CONTEXT_ENV https://review.openstack.org/508410 | 06:23 |
*** aselius has quit IRC | 06:28 | |
*** rcernin has joined #openstack-keystone | 06:30 | |
*** edmondsw has joined #openstack-keystone | 06:33 | |
*** lnxnut has joined #openstack-keystone | 06:34 | |
*** edmondsw has quit IRC | 06:37 | |
*** belmoreira has joined #openstack-keystone | 06:38 | |
openstackgerrit | Merged openstack/keystone master: Remove v2.0 token APIs https://review.openstack.org/499784 | 06:39 |
openstackgerrit | Merged openstack/keystone master: Remove v2.0 auth APIs https://review.openstack.org/504465 | 06:40 |
openstackgerrit | Merged openstack/keystone master: Remove v2.0 test plumbing https://review.openstack.org/506748 | 06:40 |
*** tonytan4ever has joined #openstack-keystone | 06:43 | |
*** namnh has joined #openstack-keystone | 06:44 | |
*** tonytan4ever has quit IRC | 06:48 | |
*** pcaruana has joined #openstack-keystone | 06:48 | |
*** ioggstream has joined #openstack-keystone | 06:51 | |
*** tbh_ has quit IRC | 06:51 | |
*** ioggstream has quit IRC | 06:53 | |
*** spectr has quit IRC | 06:54 | |
*** spectr has joined #openstack-keystone | 06:55 | |
*** lnxnut has quit IRC | 06:57 | |
*** tesseract has joined #openstack-keystone | 07:16 | |
*** sdake_ has joined #openstack-keystone | 07:16 | |
*** sdake_ is now known as Guest52279 | 07:17 | |
*** Guest52279 has quit IRC | 07:17 | |
*** markvoelker has joined #openstack-keystone | 07:21 | |
*** tonytan4ever has joined #openstack-keystone | 07:21 | |
openstackgerrit | Merged openstack/keystone master: Refactor removal of duplicate projects/domains https://review.openstack.org/491574 | 07:23 |
*** markvoelker has quit IRC | 07:55 | |
*** prashkre__ has quit IRC | 08:01 | |
*** tonytan4ever has quit IRC | 08:02 | |
*** tonytan4ever has joined #openstack-keystone | 08:02 | |
*** prashkre__ has joined #openstack-keystone | 08:02 | |
*** tonytan4ever has quit IRC | 08:03 | |
*** namnh has quit IRC | 08:14 | |
*** edmondsw has joined #openstack-keystone | 08:21 | |
*** edmondsw has quit IRC | 08:26 | |
*** lnxnut has joined #openstack-keystone | 08:28 | |
openstackgerrit | Colleen Murphy proposed openstack/keystonemiddleware master: Rename auth_uri to www_authenticate_uri https://review.openstack.org/508522 | 08:36 |
*** nkinder has quit IRC | 08:41 | |
*** lnxnut has quit IRC | 08:47 | |
*** jaosorior has quit IRC | 08:51 | |
*** markvoelker has joined #openstack-keystone | 08:52 | |
*** jaosorior has joined #openstack-keystone | 08:56 | |
*** oikiki has quit IRC | 09:11 | |
*** nkinder has joined #openstack-keystone | 09:15 | |
*** markvoelker has quit IRC | 09:26 | |
*** lnxnut has joined #openstack-keystone | 09:45 | |
*** Suramya has joined #openstack-keystone | 09:53 | |
*** lnxnut has quit IRC | 09:56 | |
*** aojea has joined #openstack-keystone | 10:06 | |
*** edmondsw has joined #openstack-keystone | 10:09 | |
*** aojea has quit IRC | 10:10 | |
*** edmondsw has quit IRC | 10:13 | |
*** Suramya has quit IRC | 10:15 | |
*** Suramya has joined #openstack-keystone | 10:20 | |
*** markvoelker has joined #openstack-keystone | 10:23 | |
*** tesseract has quit IRC | 10:40 | |
*** tesseract has joined #openstack-keystone | 10:44 | |
*** lnxnut has joined #openstack-keystone | 10:53 | |
*** prashkre_ has joined #openstack-keystone | 10:54 | |
*** markvoelker has quit IRC | 10:55 | |
*** prashkre__ has quit IRC | 10:57 | |
*** spectr-RH has joined #openstack-keystone | 10:59 | |
*** dave-mccowan has joined #openstack-keystone | 11:01 | |
*** spectr has quit IRC | 11:02 | |
*** lnxnut has quit IRC | 11:03 | |
*** nicolasbock_ has joined #openstack-keystone | 11:03 | |
*** nicolasbock_ has quit IRC | 11:08 | |
*** prashkre_ has quit IRC | 11:09 | |
*** dave-mcc_ has joined #openstack-keystone | 11:11 | |
*** dave-mccowan has quit IRC | 11:13 | |
*** Suramya has quit IRC | 11:15 | |
*** josecastroleon has quit IRC | 11:21 | |
*** markvoelker has joined #openstack-keystone | 11:53 | |
*** raildo has joined #openstack-keystone | 11:57 | |
*** lnxnut has joined #openstack-keystone | 12:00 | |
samueldmq | morning keystone | 12:03 |
samueldmq | this is really good to hear | 12:04 |
samueldmq | "Keystone updated to Pike release at #CERN #Cloud. Most transparent update ever. Thanks to #OpenStack developers" | 12:04 |
samueldmq | #link https://twitter.com/josecastroleon/status/915461266193420288 | 12:04 |
*** lnxnut has quit IRC | 12:11 | |
*** edmondsw has joined #openstack-keystone | 12:16 | |
*** edmondsw_ has joined #openstack-keystone | 12:17 | |
*** edmondsw has quit IRC | 12:21 | |
*** markvoelker has quit IRC | 12:26 | |
*** markvoelker has joined #openstack-keystone | 12:27 | |
*** rodrigods has quit IRC | 12:54 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone master: Remove unnecessary dependency injection https://review.openstack.org/502550 | 12:57 |
*** spectr-RH has quit IRC | 13:00 | |
*** rmascena has joined #openstack-keystone | 13:02 | |
*** pcaruana has quit IRC | 13:02 | |
*** raildo has quit IRC | 13:05 | |
*** lbragstad has joined #openstack-keystone | 13:05 | |
*** ChanServ sets mode: +o lbragstad | 13:05 | |
*** lnxnut has joined #openstack-keystone | 13:08 | |
*** spectr-RH has joined #openstack-keystone | 13:12 | |
*** rmascena has quit IRC | 13:12 | |
*** rmascena has joined #openstack-keystone | 13:13 | |
*** pcaruana has joined #openstack-keystone | 13:15 | |
*** spectr-RH has quit IRC | 13:16 | |
*** rmascena is now known as raildo | 13:16 | |
*** rodrigods has joined #openstack-keystone | 13:17 | |
*** lnxnut has quit IRC | 13:17 | |
*** spectr-RH has joined #openstack-keystone | 13:17 | |
*** rodrigods has quit IRC | 13:17 | |
*** rodrigods has joined #openstack-keystone | 13:17 | |
lbragstad | well - all those patches that removed v2.0 merged last night | 13:18 |
*** chlong_ has joined #openstack-keystone | 13:22 | |
*** lnxnut has joined #openstack-keystone | 13:23 | |
*** catintheroof has joined #openstack-keystone | 13:24 | |
raildo | lbragstad, that's awesome! great job dude | 13:30 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystonemiddleware master: Updated from global requirements https://review.openstack.org/500005 | 13:36 |
*** Suramya has joined #openstack-keystone | 13:38 | |
*** rodrigods has quit IRC | 13:43 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/pycadf master: Updated from global requirements https://review.openstack.org/470137 | 13:43 |
*** rodrigods has joined #openstack-keystone | 13:53 | |
*** edmondsw_ is now known as edmondsw | 14:07 | |
*** rodrigods has quit IRC | 14:08 | |
*** rodrigods has joined #openstack-keystone | 14:09 | |
*** d0ugal has quit IRC | 14:10 | |
*** lkwan_ has joined #openstack-keystone | 14:10 | |
*** d0ugal has joined #openstack-keystone | 14:13 | |
*** d0ugal has quit IRC | 14:13 | |
*** d0ugal has joined #openstack-keystone | 14:13 | |
*** smcginnis has joined #openstack-keystone | 14:14 | |
*** panbalag has joined #openstack-keystone | 14:15 | |
smcginnis | Hey, looking at a requirements job failure. Has anyone seen this before or know if it's a known issue? http://logs.openstack.org/22/509422/1/check/gate-cross-keystone-python35/cef3298/console.html#_2017-10-04_12_40_37_674353 | 14:15 |
*** panbalag has left #openstack-keystone | 14:15 | |
smcginnis | lbragstad: ^? | 14:16 |
lbragstad | smcginnis: let me dig into it quick | 14:18 |
smcginnis | lbragstad: We're running a recheck, so we'll see if it passes next time. | 14:18 |
smcginnis | lbragstad: Just thought I'd check if it was a known issue right now. | 14:19 |
cmurphy | smcginnis: the line you linked looks like a passing test? | 14:19 |
lbragstad | i think it's tripping on the domain bits below it | 14:19 |
smcginnis | cmurphy: Oops. Immediately after that line. | 14:19 |
lbragstad | 2017-10-04 12:40:37.676675 | Invalid domain name: d1bb128a948d4ac8a268272d622b51a0 | 14:20 |
smcginnis | Could not find directory /etc/keystone/domains | 14:20 |
lbragstad | that also seems like something that shouldn't result in a failure? | 14:20 |
lbragstad | it also shouldn't be causing or related to a timeout | 14:20 |
lbragstad | which seems like the real cause? | 14:21 |
cmurphy | i would blame zuulv3 | 14:21 |
smcginnis | Ah, good point it ends up timing out. Maybe just a red herring. | 14:21 |
smcginnis | Please ignore for now. If the recheck hits similar issues I'll dig into then. | 14:22 |
lbragstad | i think it's just unlucky in that it's an informational error right before the timeout | 14:22 |
smcginnis | lbragstad: Yeah, probably right. | 14:22 |
lbragstad | cool - keep us posted if you find out more | 14:22 |
*** pcaruana has quit IRC | 14:33 | |
*** rodrigods has quit IRC | 14:34 | |
*** rodrigods has joined #openstack-keystone | 14:36 | |
*** cfriesen has joined #openstack-keystone | 14:38 | |
*** spectr-RH has quit IRC | 14:41 | |
*** spectr has joined #openstack-keystone | 14:42 | |
*** rodrigods has quit IRC | 14:45 | |
*** rodrigods has joined #openstack-keystone | 14:45 | |
*** pcaruana has joined #openstack-keystone | 14:45 | |
*** lnxnut_ has joined #openstack-keystone | 14:56 | |
*** lnxnut has quit IRC | 14:58 | |
knikolla | o/ | 15:10 |
*** jamesbenson has joined #openstack-keystone | 15:10 | |
*** rcernin has quit IRC | 15:13 | |
*** smcginnis has left #openstack-keystone | 15:13 | |
gagehugo | o/ | 15:14 |
*** Suramya has quit IRC | 15:19 | |
*** erlon has joined #openstack-keystone | 15:24 | |
ayoung | lbragstad, we're not doing the IAM walkthrough during policy today, right? | 15:26 |
lbragstad | ayoung: no - not today i don't think | 15:26 |
lbragstad | ayoung: http://lists.openstack.org/pipermail/openstack-dev/2017-October/123069.html | 15:27 |
lbragstad | i'm hoping we can get some consensus on ^ | 15:27 |
*** pcaruana has quit IRC | 15:28 | |
*** tesseract has quit IRC | 15:29 | |
*** gyee has joined #openstack-keystone | 15:29 | |
ayoung | lbragstad, cool, as I have lunch plans. Won't be there today. Gone next week for training. I can follow up when I get back. | 15:30 |
lbragstad | ayoung: sounds good - that should give us time to get a solid session planned out | 15:30 |
ayoung | ++ | 15:30 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove v2.0 user APIs https://review.openstack.org/509510 | 15:35 |
*** belmoreira has quit IRC | 15:35 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove v2.0 identity API documentation https://review.openstack.org/509510 | 15:36 |
*** mdavidson has quit IRC | 15:39 | |
*** jamesbenson has quit IRC | 15:42 | |
samueldmq | lbragstad: cmurphy what are our current plans for keystone-tempest-plugin in terms of what we want to put there? | 15:44 |
samueldmq | I want to create a tempest test for https://review.openstack.org/#/c/506340/ | 15:45 |
cmurphy | samueldmq: i'm not sure if we have rules but i feel like that would be a candidate to go in the regular tempest suite | 15:49 |
cmurphy | right now the plugin is just doing ldap and federation stuff i think | 15:49 |
*** jamesbenson has joined #openstack-keystone | 15:49 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Remove the v3 to v2 resource test case https://review.openstack.org/509519 | 15:50 |
*** jamesbenson has quit IRC | 15:52 | |
samueldmq | cmurphy: like under https://github.com/openstack/tempest/tree/master/tempest/api/identity/v3 | 15:52 |
samueldmq | ? | 15:52 |
*** jamesbenson has joined #openstack-keystone | 15:53 | |
samueldmq | or better ... https://github.com/openstack/tempest/blob/master/tempest/api/identity/admin/v3/test_domains.py | 15:53 |
samueldmq | cmurphy: anyways, yes I think that makes sense ... thanks | 15:53 |
*** jamesbenson has quit IRC | 15:54 | |
*** jamesbenson has joined #openstack-keystone | 15:55 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Remove deprecated secure_proxy_ssl_header config https://review.openstack.org/499798 | 15:55 |
cmurphy | samueldmq: yeah maybe | 15:55 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Add database migration for project tags https://review.openstack.org/484456 | 15:56 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Implement backend logic for project tags https://review.openstack.org/499726 | 15:56 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone master: Remove unnecessary dependency injection https://review.openstack.org/502550 | 16:00 |
*** aselius has joined #openstack-keystone | 16:06 | |
*** jamesbenson has quit IRC | 16:11 | |
*** jamesbenson has joined #openstack-keystone | 16:16 | |
*** magicboiz has joined #openstack-keystone | 16:18 | |
magicboiz | Hi | 16:18 |
magicboiz | Is it possible to configure LDAP backend + 2FA/One Time Password? | 16:19 |
magicboiz | thanks :) | 16:19 |
kmalloc | magicboiz: in Pike it should be doable, depending on how you want to configure that. if the 2FA is built into your LDAP server auth, it will depend on how that is represented if you're usign keystone's 2FA code... I need to find the docs for you | 16:21 |
kmalloc | (I think it was pike we landed the support, maybe it was late ocata?) | 16:21 |
magicboiz | kmalloc: thanks | 16:28 |
magicboiz | kmalloc: i thought it was possible to ask for user/pass to LDAP backend, and then TOTP passcode inside keystone....this might has no sense :) | 16:29 |
kmalloc | it should be | 16:29 |
kmalloc | we implemented a chunk of that in a recent release | 16:30 |
magicboiz | kmalloc: if you find that doc, please let me know | 16:30 |
kmalloc | looking | 16:30 |
kmalloc | hmm. did we fail to write docs? | 16:32 |
kmalloc | lbragstad: ^ | 16:32 |
kmalloc | i mean, i know we can support it, but it might require reading code to look into it. Also, I am unsure if we finished the keystoneauth mechanisms to support multiple auth plugins at once | 16:33 |
kmalloc | magicboiz: basically we have a mechanism to require a combination of authentication methods. | 16:35 |
kmalloc | magicboiz: but i don't see docs on this, i can point you at the code, but i think horizon and other such tools wont work with it yet, it would only work using the REST API | 16:36 |
lbragstad | i thought i remember patches to ksa to do that kinda stuff | 16:36 |
kmalloc | lbragstad: yeah, i just don't know and we're missing docs =/ | 16:37 |
*** jamesbenson has quit IRC | 16:37 | |
lbragstad | sweet... | 16:37 |
lbragstad | i know we have this - https://docs.openstack.org/keystone/latest/advanced-topics/auth-totp.html | 16:37 |
lbragstad | but that's directly through the API | 16:37 |
lbragstad | that was around the newton time frame because we needed to implement encryption for the credential backend as a prerequisite | 16:39 |
lbragstad | (which was done after I think) | 16:39 |
magicboiz | kmalloc, lbragstad : thanks, I thought the "Per user MFA" was related with these, a kind of auth chain.... | 16:43 |
lbragstad | yeah - it is | 16:43 |
kmalloc | yep | 16:43 |
lbragstad | but we might need to implement support through ksa so it's consumable via a library | 16:43 |
magicboiz | then, the path would be something similar to http://bogott.net/unspecified/?p=2344 (he coded a custom Wmtotp(auth.AuthMethodHandler))... | 16:43 |
*** oikiki has joined #openstack-keystone | 16:50 | |
* lbragstad steps away for a lunch quick | 16:59 | |
*** oikiki has quit IRC | 17:13 | |
*** efried is now known as efried_nomnom | 17:25 | |
*** oikiki has joined #openstack-keystone | 17:28 | |
*** markvoelker has quit IRC | 17:30 | |
*** markvoelker has joined #openstack-keystone | 17:30 | |
*** lbragstad has quit IRC | 17:34 | |
openstackgerrit | Merged openstack/keystone master: Remove the v2.0 validate path from validate_token https://review.openstack.org/389371 | 17:40 |
*** prashkre_ has joined #openstack-keystone | 17:42 | |
*** itlinux has joined #openstack-keystone | 17:49 | |
*** jamesbenson has joined #openstack-keystone | 17:50 | |
*** acormier has joined #openstack-keystone | 17:50 | |
*** itlinux has quit IRC | 17:53 | |
*** dulek_ has joined #openstack-keystone | 17:55 | |
dulek_ | Hi! Is it normal that kestoneuWSGI worker 1 and 2 constantly use 100% CPU on both of my cores? | 17:56 |
dulek_ | (talking about simple DevStack installation) | 17:56 |
*** lbragstad has joined #openstack-keystone | 17:57 | |
*** ChanServ sets mode: +o lbragstad | 17:57 | |
*** MasterOfBugs has joined #openstack-keystone | 18:00 | |
*** itlinux has joined #openstack-keystone | 18:04 | |
*** dulek_ has quit IRC | 18:10 | |
*** itlinux has quit IRC | 18:12 | |
*** jdwidari has joined #openstack-keystone | 18:15 | |
*** jdwidari has quit IRC | 18:15 | |
*** jdwidari has joined #openstack-keystone | 18:18 | |
*** jdwidari has quit IRC | 18:18 | |
*** edmondsw has quit IRC | 18:20 | |
*** jdwidari has joined #openstack-keystone | 18:21 | |
*** edmondsw has joined #openstack-keystone | 18:23 | |
*** edmondsw has quit IRC | 18:28 | |
*** efried_nomnom is now known as efried | 18:32 | |
*** edmondsw has joined #openstack-keystone | 18:48 | |
*** MasterOfBugs has quit IRC | 18:59 | |
*** oomichi is now known as oomichi_afk | 19:05 | |
*** edmondsw has quit IRC | 19:06 | |
*** edmondsw has joined #openstack-keystone | 19:06 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Remove the v3 to v2 resource test case https://review.openstack.org/509519 | 19:08 |
*** prashkre_ has quit IRC | 19:10 | |
*** chlong_ has quit IRC | 19:16 | |
EmilienM | I think https://github.com/openstack/keystone/commit/087b07bfd4f9e212f9d7b36b707babbf945f374f broke tripleo CI | 19:26 |
EmilienM | https://logs.rdoproject.org/openstack-periodic-4hr/periodic-tripleo-ci-centos-7-multinode-1ctlr-featureset005-master/9155f0e/undercloud/var/log/nova/nova-api.log.txt.gz#_2017-10-04_16_36_27_069 | 19:26 |
EmilienM | but I'm not sure at all | 19:26 |
EmilienM | lbragstad: when you have time maybe you can look ^ you're author on the patch | 19:26 |
*** lbragstad has quit IRC | 19:35 | |
*** nicolasbock has joined #openstack-keystone | 19:52 | |
*** ayoung_ has joined #openstack-keystone | 20:03 | |
*** ianw is now known as ianw|pto | 20:04 | |
*** ayoung_ has quit IRC | 20:05 | |
*** ayoung has quit IRC | 20:08 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Implement backend logic for project tags https://review.openstack.org/499726 | 20:08 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Implement project tags logic into manager https://review.openstack.org/499727 | 20:08 |
*** ayoung has joined #openstack-keystone | 20:08 | |
*** lbragstad has joined #openstack-keystone | 20:27 | |
*** ChanServ sets mode: +o lbragstad | 20:27 | |
lbragstad | EmilienM: i think this is probably what broke you https://review.openstack.org/#/c/504465/ | 20:28 |
lbragstad | https://review.openstack.org/#/c/389371/ is removing code that isn't actually used anymore | 20:29 |
EmilienM | ok | 20:29 |
lbragstad | yeah (http://192.168.24.1:35357/v2.0/tokens) is removed | 20:30 |
lbragstad | it looks like keystonemiddleware is looking for v2. 0 | 20:31 |
lbragstad | and not using v3 | 20:31 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Remove the v3 to v2 resource test case https://review.openstack.org/509519 | 20:31 |
lbragstad | that error should go away if keystonemiddleware validates tokens using v3 | 20:32 |
lbragstad | EmilienM: do you have the keystonemiddleware configuration file handy for that change? | 20:32 |
EmilienM | lbragstad: I'm not sure | 20:32 |
EmilienM | let me check | 20:32 |
EmilienM | lbragstad: http://logs.openstack.org/17/507917/5/check/gate-tripleo-ci-centos-7-nonha-multinode-oooq/dc9619d/logs/etc/keystone/ | 20:33 |
EmilienM | lbragstad: which file exactly? | 20:33 |
lbragstad | http://logs.openstack.org/17/507917/5/check/gate-tripleo-ci-centos-7-nonha-multinode-oooq/dc9619d/logs/etc/nova/nova.conf.txt.gz | 20:35 |
lbragstad | the error is coming from nova | 20:35 |
lbragstad | via keystonemiddleware | 20:35 |
EmilienM | lbragstad: what's the config error? | 20:35 |
*** mwhahaha has joined #openstack-keystone | 20:36 | |
EmilienM | auth_uri=http://192.168.24.1:5000/v3 | 20:36 |
EmilienM | should be good no? | 20:36 |
lbragstad | that's auth_uri - which might not be the option you want (cmurphy is actually in the process of fixing that) | 20:36 |
lbragstad | auth_url=http://192.168.24.1:35357 | 20:37 |
EmilienM | auth_url=http://192.168.24.1:35357 | 20:37 |
EmilienM | not good? | 20:37 |
lbragstad | EmilienM: it could be defaulting to v2.0 if that's deployed | 20:37 |
lbragstad | EmilienM: context on what cmurphy is doing | 20:37 |
lbragstad | https://review.openstack.org/#/c/508522/ | 20:37 |
EmilienM | lbragstad: how can we know? | 20:37 |
*** zzzeek has quit IRC | 20:39 | |
lbragstad | https://github.com/openstack/keystonemiddleware/blob/master/keystonemiddleware/auth_token/_auth.py#L62-L66 | 20:39 |
EmilienM | lbragstad: what should we change in our config? | 20:40 |
lbragstad | EmilienM: looking for an example | 20:41 |
cmurphy | you need both auth_url and auth_uri, that looks fine to me | 20:41 |
EmilienM | but we have them no? | 20:41 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Implement project tags API controller and router https://review.openstack.org/499728 | 20:41 |
EmilienM | auth_url=http://192.168.24.1:35357 and auth_uri=http://192.168.24.1:5000/v3 | 20:42 |
EmilienM | it's not good? | 20:42 |
cmurphy | EmilienM: ya i think that's fine | 20:42 |
EmilienM | cmurphy: it doesn't work, https://logs.rdoproject.org/openstack-periodic-4hr/periodic-tripleo-ci-centos-7-multinode-1ctlr-featureset005-master/9155f0e/undercloud/var/log/nova/nova-api.log.txt.gz#_2017-10-04_16_36_27_069 | 20:43 |
EmilienM | Authorization failed for token: NotFound: (http://192.168.24.1:35357/v2.0/tokens): The resource could not be found | 20:43 |
EmilienM | like lbragstad said, https://github.com/openstack/keystonemiddleware/blob/master/keystonemiddleware/auth_token/_auth.py#L62-L66 is maybe a reason | 20:43 |
EmilienM | how does it work in devstack? | 20:43 |
lbragstad | that's what i'm checking - along with osa | 20:44 |
EmilienM | k | 20:44 |
lbragstad | https://github.com/openstack/openstack-ansible-os_nova/blob/master/templates/nova.conf.j2#L183-L193 | 20:44 |
lbragstad | osa nova keystone_authtoken configs | 20:44 |
EmilienM | which is? | 20:45 |
lbragstad | they are pulled from here i think https://github.com/openstack/openstack-ansible-os_keystone/blob/master/defaults/main.yml#L147-L157 | 20:45 |
mwhahaha | EmilienM: make sure we're properly defining the domain and stuff. that was the problem with our neutron bits where it was 'working' because it sliently used v2 | 20:46 |
mwhahaha | we aren't explicitly configuring the domain | 20:48 |
lbragstad | nova also sets https://github.com/openstack/openstack-ansible-os_nova/blob/master/defaults/main.yml#L196 | 20:48 |
lbragstad | actually - it looks like that's set in your config,too | 20:49 |
*** oikiki has quit IRC | 20:49 | |
EmilienM | mwhahaha: should we change default in nova::keystone::authtoken or in keystone::resource::authtoken you think? | 20:50 |
mwhahaha | not sure, the problem in neutron was the cli usage in the provider https://review.openstack.org/#/c/509469/ | 20:50 |
mwhahaha | wondering if it's a similar problem here where some code is improperly falling back without a domain defined | 20:50 |
EmilienM | mwhahaha: I never remember if we want Default or default by default | 20:52 |
mwhahaha | Default i think | 20:52 |
EmilienM | k | 20:52 |
*** panbalag has joined #openstack-keystone | 20:53 | |
EmilienM | mwhahaha: I think we should fix it at the highest level as possible and set the right defaults, so it works out of the box for our users without any change | 20:53 |
EmilienM | mwhahaha: because if we go down to the path of updating nova::keystone::authtoken - we'll have to do it for all modules | 20:53 |
EmilienM | since v2 was removed, i think it's safe to set the default for both params | 20:54 |
mwhahaha | yea | 20:54 |
mwhahaha | but shouldn't the highest level be in the python code itself | 20:55 |
EmilienM | mwhahaha: that's a question for lbragstad or cmurphy | 20:55 |
*** zzzeek has joined #openstack-keystone | 20:57 | |
cmurphy | Default is the *_domain_name and default is the *_domain_id | 20:58 |
EmilienM | cmurphy: ok thanks! | 20:58 |
cmurphy | EmilienM: mwhahaha what do you mean by the highest level? | 20:59 |
EmilienM | let me show | 20:59 |
EmilienM | cmurphy: https://github.com/openstack/puppet-keystone/blob/master/manifests/resource/authtoken.pp#L226-L227 | 20:59 |
EmilienM | I'm about to change the default for these 2 values, and be "Default" | 21:00 |
EmilienM | so all puppet-* who call this Define (all I think) will have Default domain in their *.conf file | 21:00 |
cmurphy | EmilienM: gotcha | 21:00 |
EmilienM | cmurphy: makes sense? | 21:01 |
*** oikiki has joined #openstack-keystone | 21:01 | |
EmilienM | cmurphy: the best option would be to fix it in Keystone itself | 21:01 |
EmilienM | cmurphy: defaulting this param to Default | 21:01 |
EmilienM | I would love this option but not sure if that would work for you | 21:01 |
cmurphy | EmilienM: no i'm pretty sure we're always going to require the domain be set explicitly even if it's Default | 21:02 |
EmilienM | cmurphy: why? | 21:02 |
clarkb | iirc keystone doesn't actually have a default default | 21:02 |
clarkb | its created at run time isn't it and oculd be arbitrary? | 21:03 |
mwhahaha | but if not defined, it shouldn't be falling back to v2 | 21:03 |
mwhahaha | that's the problem | 21:03 |
clarkb | oh defintely, I seem to recall having this argument back when devstack added in v3 support and things got weird | 21:03 |
cmurphy | mwhahaha: yeah that is a problem | 21:04 |
mwhahaha | so it's fine if it needs to be defined, but that should be an error | 21:04 |
clarkb | that things should just work by default but iirc the response was there is no default default | 21:04 |
mwhahaha | not a error cause v2 isn't there | 21:04 |
mwhahaha | so if there's not a default, default it needs to not be defined in puppet and be a required param | 21:05 |
mwhahaha | in keystone the fix needs to be to properly error if the required bits are not passed | 21:05 |
mwhahaha | or kestone auth | 21:05 |
*** panbalag has left #openstack-keystone | 21:05 | |
EmilienM | mwhahaha: so fix in puppet? | 21:06 |
mwhahaha | no | 21:06 |
mwhahaha | puppet's fix is to make it required | 21:06 |
mwhahaha | tripleo needs to pass domain | 21:06 |
mwhahaha | keystone needs to fix handling of requests w/o a domain now that v2 is dead | 21:07 |
EmilienM | mwhahaha: ok | 21:07 |
EmilienM | mwhahaha: so I'll change all modules to require the domain params, and tripleo to use them. Ok? | 21:07 |
mwhahaha | yes | 21:07 |
mwhahaha | edit teh world | 21:07 |
EmilienM | mwhahaha: ok | 21:07 |
clarkb | ya reading devstack its an explicit create of the Default domain then inisets for services keystone auth middle ware to use that daomin, implying it could be a completely arbitrary base/default domain | 21:09 |
clarkb | iirc the weirdness was keystone had to be completely configured and running before we could start or configure any other serices as the domain had to be known or maybe it was the domain uuid | 21:09 |
mwhahaha | yea this seems to be an odd interaction in keystoneauth | 21:10 |
mwhahaha | not necessarily keystone itself | 21:10 |
*** zzzeek has quit IRC | 21:19 | |
*** ayoung has quit IRC | 21:20 | |
*** zzzeek has joined #openstack-keystone | 21:20 | |
*** ayoung has joined #openstack-keystone | 21:23 | |
*** zzzeek has quit IRC | 21:23 | |
*** zzzeek has joined #openstack-keystone | 21:25 | |
*** edmondsw has quit IRC | 21:32 | |
*** edmondsw has joined #openstack-keystone | 21:32 | |
*** raildo has quit IRC | 21:35 | |
*** edmondsw has quit IRC | 21:37 | |
*** catintheroof has quit IRC | 21:41 | |
*** jamesbenson has quit IRC | 21:57 | |
*** acormier has quit IRC | 22:11 | |
*** lbragstad has quit IRC | 22:38 | |
*** edmondsw has joined #openstack-keystone | 22:41 | |
*** edmondsw has quit IRC | 22:46 | |
*** edmondsw has joined #openstack-keystone | 23:13 | |
*** edmondsw has quit IRC | 23:35 | |
*** oikiki has quit IRC | 23:49 | |
*** oikiki has joined #openstack-keystone | 23:56 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!