| kmalloc | SamYaple: roles can exist only in a single domain? | 00:02 |
|---|---|---|
| kmalloc | when was that added? | 00:02 |
| *** oikiki has quit IRC | 00:03 | |
| *** oikiki has joined #openstack-keystone | 00:05 | |
| SamYaple | kmalloc: idk. forever ago | 00:06 |
| SamYaple | let me check | 00:06 |
| SamYaple | i think its always be apart of the v3 api | 00:06 |
| *** sbezverk has quit IRC | 00:06 | |
| kmalloc | ah mitaka | 00:07 |
| SamYaple | nope 3.6 | 00:07 |
| SamYaple | yea | 00:07 |
| kmalloc | no it was was very recent | 00:07 |
| kmalloc | (for a value of recent) | 00:07 |
| kmalloc | the answer is: I doubt anyone uses it | 00:07 |
| SamYaple | seems like a decent idea. make it literally imposible for any user or group outside of a domain to use the role | 00:08 |
| SamYaple | good for auditing | 00:08 |
| kmalloc | eh. it's a bit wonky | 00:08 |
| kmalloc | and i don't know if it works liek that. | 00:08 |
| SamYaple | no im doing that right now | 00:08 |
| SamYaple | just it seemed like an edge feature so i was worried about unknown future breakage | 00:09 |
| kmalloc | its really easy to screw it all up. this is another case of *eh* not sure why we even bothered | 00:09 |
| SamYaple | dont want to rely on something thats going to break because no one uses it | 00:09 |
| kmalloc | and now we're stuck with it | 00:09 |
| SamYaple | yea that | 00:09 |
| SamYaple | i bet you the way im using it was the original rationale | 00:09 |
| SamYaple | ah looks like it was made with the intention of allowing cloud providers to provide roles to customers that made sense to them, but it does work like i thought it did | 00:15 |
| SamYaple | it piggy-backs off of implied roles | 00:16 |
| SamYaple | so this actually seems like the core gets used and tested alot | 00:17 |
| *** thorst has joined #openstack-keystone | 00:29 | |
| *** thorst has quit IRC | 00:32 | |
| *** Shunli has joined #openstack-keystone | 00:42 | |
| *** AlexeyAbashkin has joined #openstack-keystone | 00:42 | |
| *** AlexeyAbashkin has quit IRC | 00:47 | |
| *** thorst has joined #openstack-keystone | 01:10 | |
| *** thorst has quit IRC | 01:20 | |
| openstackgerrit | zhengliuyang proposed openstack/keystone master: Improper handle about building list of token deletion https://review.openstack.org/475100 | 01:36 |
| *** AlexeyAbashkin has joined #openstack-keystone | 01:45 | |
| *** markvoelker has joined #openstack-keystone | 01:47 | |
| *** AlexeyAbashkin has quit IRC | 01:49 | |
| *** aselius has quit IRC | 01:53 | |
| *** thorst has joined #openstack-keystone | 01:59 | |
| *** thorst has quit IRC | 02:00 | |
| *** mgagne has quit IRC | 02:19 | |
| *** markvoelker has quit IRC | 02:21 | |
| *** chris_hultin has quit IRC | 02:21 | |
| *** comstud has quit IRC | 02:22 | |
| *** chris_hultin|AWA has joined #openstack-keystone | 02:22 | |
| *** mgagne has joined #openstack-keystone | 02:22 | |
| *** mgagne is now known as Guest53680 | 02:22 | |
| *** chris_hultin|AWA is now known as chris_hultin | 02:22 | |
| *** comstud has joined #openstack-keystone | 02:23 | |
| *** oikiki has quit IRC | 02:32 | |
| *** oikiki has joined #openstack-keystone | 02:39 | |
| *** dave-mccowan has quit IRC | 02:41 | |
| *** AlexeyAbashkin has joined #openstack-keystone | 02:43 | |
| *** AlexeyAbashkin has quit IRC | 02:48 | |
| *** links has joined #openstack-keystone | 02:51 | |
| *** oikiki has quit IRC | 03:00 | |
| *** thorst has joined #openstack-keystone | 03:10 | |
| *** thorst has quit IRC | 03:15 | |
| *** nicolasbock has quit IRC | 03:16 | |
| *** markvoelker has joined #openstack-keystone | 03:18 | |
| *** wes_dillingham has quit IRC | 03:35 | |
| *** edmondsw has joined #openstack-keystone | 03:38 | |
| *** jaosorior has joined #openstack-keystone | 03:45 | |
| *** edmondsw has quit IRC | 03:45 | |
| *** markvoelker has quit IRC | 03:51 | |
| *** daidv has quit IRC | 04:00 | |
| *** daidv has joined #openstack-keystone | 04:01 | |
| *** mvk has joined #openstack-keystone | 04:20 | |
| *** pcaruana has joined #openstack-keystone | 04:27 | |
| *** mvk has quit IRC | 04:31 | |
| *** aojea has joined #openstack-keystone | 04:33 | |
| *** zxy has quit IRC | 04:37 | |
| *** aojea has quit IRC | 04:37 | |
| *** mvk has joined #openstack-keystone | 04:45 | |
| *** markvoelker has joined #openstack-keystone | 04:49 | |
| *** mvk has quit IRC | 04:50 | |
| *** pcaruana has quit IRC | 04:56 | |
| *** cristicalin has joined #openstack-keystone | 05:10 | |
| *** thorst has joined #openstack-keystone | 05:11 | |
| *** thorst has quit IRC | 05:15 | |
| *** jaosorior has quit IRC | 05:17 | |
| *** chlong has joined #openstack-keystone | 05:20 | |
| *** markvoelker has quit IRC | 05:22 | |
| *** cristicalin has quit IRC | 05:23 | |
| *** edmondsw has joined #openstack-keystone | 05:27 | |
| *** pcaruana has joined #openstack-keystone | 05:30 | |
| *** jaosorior has joined #openstack-keystone | 05:30 | |
| *** oikiki has joined #openstack-keystone | 05:31 | |
| *** edmondsw has quit IRC | 05:32 | |
| *** pcaruana has quit IRC | 05:39 | |
| *** rcernin has joined #openstack-keystone | 05:41 | |
| *** cristicalin has joined #openstack-keystone | 05:43 | |
| *** oikiki has quit IRC | 05:49 | |
| *** spectr has quit IRC | 05:58 | |
| *** spectr has joined #openstack-keystone | 05:58 | |
| *** cristicalin has quit IRC | 06:17 | |
| *** markvoelker has joined #openstack-keystone | 06:19 | |
| *** markvoelker has quit IRC | 06:52 | |
| *** pcaruana has joined #openstack-keystone | 07:07 | |
| *** thorst has joined #openstack-keystone | 07:12 | |
| *** edmondsw has joined #openstack-keystone | 07:15 | |
| *** thorst has quit IRC | 07:17 | |
| *** edmondsw has quit IRC | 07:20 | |
| *** tesseract has joined #openstack-keystone | 07:22 | |
| *** AlexeyAbashkin has joined #openstack-keystone | 07:24 | |
| *** spectr has quit IRC | 07:26 | |
| *** tesseract has quit IRC | 07:26 | |
| *** rcernin has quit IRC | 07:26 | |
| *** pcaruana has quit IRC | 07:26 | |
| *** mvk has joined #openstack-keystone | 07:37 | |
| *** spectr has joined #openstack-keystone | 07:40 | |
| *** pcaruana has joined #openstack-keystone | 07:40 | |
| *** rcernin has joined #openstack-keystone | 07:40 | |
| *** spectr has quit IRC | 07:43 | |
| *** pcaruana has quit IRC | 07:44 | |
| *** pcaruana has joined #openstack-keystone | 07:44 | |
| *** spectr has joined #openstack-keystone | 07:44 | |
| *** markvoelker has joined #openstack-keystone | 07:50 | |
| *** ioggstream has joined #openstack-keystone | 07:55 | |
| *** AlexeyAbashkin has quit IRC | 08:10 | |
| *** AlexeyAbashkin has joined #openstack-keystone | 08:11 | |
| *** thorst has joined #openstack-keystone | 08:12 | |
| *** thorst has quit IRC | 08:17 | |
| *** markvoelker has quit IRC | 08:23 | |
| *** itlinux has joined #openstack-keystone | 08:33 | |
| *** itlinux has quit IRC | 08:36 | |
| *** johnthetubaguy has quit IRC | 08:39 | |
| *** johnthetubaguy has joined #openstack-keystone | 08:40 | |
| *** thorst has joined #openstack-keystone | 08:41 | |
| *** thorst has quit IRC | 08:45 | |
| *** aojea has joined #openstack-keystone | 08:47 | |
| *** rcernin has quit IRC | 08:59 | |
| *** spectr has quit IRC | 08:59 | |
| *** pcaruana has quit IRC | 08:59 | |
| *** AlexeyAbashkin has quit IRC | 09:03 | |
| *** AlexeyAbashkin has joined #openstack-keystone | 09:03 | |
| *** edmondsw has joined #openstack-keystone | 09:04 | |
| *** edmondsw has quit IRC | 09:08 | |
| *** rcernin has joined #openstack-keystone | 09:12 | |
| *** spectr has joined #openstack-keystone | 09:12 | |
| *** pcaruana has joined #openstack-keystone | 09:13 | |
| *** AlexeyAbashkin has quit IRC | 09:15 | |
| *** AlexeyAbashkin has joined #openstack-keystone | 09:15 | |
| *** markvoelker has joined #openstack-keystone | 09:20 | |
| *** Shunli has quit IRC | 09:22 | |
| *** belmoreira has joined #openstack-keystone | 09:29 | |
| *** chlong has quit IRC | 09:40 | |
| *** markvoelker has quit IRC | 09:53 | |
| *** itlinux has joined #openstack-keystone | 10:00 | |
| *** sbezverk has joined #openstack-keystone | 10:14 | |
| *** daidv has quit IRC | 10:15 | |
| *** itlinux has quit IRC | 10:21 | |
| *** aojea has quit IRC | 10:22 | |
| *** aojea has joined #openstack-keystone | 10:23 | |
| *** belmoreira has quit IRC | 10:26 | |
| *** aojea has quit IRC | 10:27 | |
| *** thorst has joined #openstack-keystone | 10:42 | |
| *** thorst_ has joined #openstack-keystone | 10:45 | |
| *** aojea has joined #openstack-keystone | 10:46 | |
| *** jaosorior has quit IRC | 10:47 | |
| *** thorst has quit IRC | 10:47 | |
| *** aojea has quit IRC | 10:47 | |
| *** pcaruana has quit IRC | 10:48 | |
| *** thorst_ has quit IRC | 10:49 | |
| *** markvoelker has joined #openstack-keystone | 10:50 | |
| openstackgerrit | Colleen Murphy proposed openstack/keystone-specs master: Propose JWT as a new token provider https://review.openstack.org/511806 | 11:00 |
| cmurphy | lbragstad: kmalloc ^ please feel free to submit changes if you feel like it | 11:01 |
| *** nicolasbock has joined #openstack-keystone | 11:09 | |
| *** raildo has joined #openstack-keystone | 11:09 | |
| *** nicolasbock has quit IRC | 11:14 | |
| *** aojea has joined #openstack-keystone | 11:18 | |
| *** edmondsw has joined #openstack-keystone | 11:20 | |
| *** erlon has joined #openstack-keystone | 11:23 | |
| *** markvoelker has quit IRC | 11:23 | |
| *** aojea has quit IRC | 11:23 | |
| *** nicolasbock has joined #openstack-keystone | 11:26 | |
| *** thorst has joined #openstack-keystone | 11:53 | |
| *** jdennis has quit IRC | 11:54 | |
| *** MaxPC has joined #openstack-keystone | 12:12 | |
| *** wes_dillingham has joined #openstack-keystone | 12:13 | |
| *** markvoelker has joined #openstack-keystone | 12:15 | |
| *** aojea has joined #openstack-keystone | 12:19 | |
| *** aojea has quit IRC | 12:23 | |
| openstackgerrit | Colleen Murphy proposed openstack/keystone-specs master: Propose JWT as a new token provider https://review.openstack.org/511806 | 12:24 |
| *** efried is now known as fried_rice | 12:26 | |
| openstackgerrit | prashkre proposed openstack/keystone master: Handle ldap size limit exeeded exception https://review.openstack.org/511822 | 12:29 |
| *** dave-mccowan has joined #openstack-keystone | 12:42 | |
| *** links has quit IRC | 12:45 | |
| *** dave-mccowan has quit IRC | 12:47 | |
| *** pcaruana has joined #openstack-keystone | 12:48 | |
| *** panbalag has joined #openstack-keystone | 12:55 | |
| *** spectr has quit IRC | 12:57 | |
| *** josecastroleon has quit IRC | 12:59 | |
| *** panbalag has left #openstack-keystone | 12:59 | |
| *** spectr has joined #openstack-keystone | 13:01 | |
| *** jistr is now known as jistr|mtg | 13:08 | |
| *** jmlowe has quit IRC | 13:12 | |
| *** aojea has joined #openstack-keystone | 13:20 | |
| *** aojea has quit IRC | 13:24 | |
| *** jdennis has joined #openstack-keystone | 13:33 | |
| *** chlong has joined #openstack-keystone | 13:33 | |
| *** rcernin has quit IRC | 13:44 | |
| *** dansmith is now known as superdan | 13:47 | |
| *** dave-mccowan has joined #openstack-keystone | 13:48 | |
| *** d0ugal has quit IRC | 13:48 | |
| lbragstad | cmurphy: woo! | 13:49 |
| *** dave-mcc_ has joined #openstack-keystone | 13:55 | |
| gagehugo | o/ | 13:56 |
| *** dave-mccowan has quit IRC | 13:57 | |
| *** jmlowe has joined #openstack-keystone | 13:59 | |
| *** d0ugal has joined #openstack-keystone | 14:03 | |
| *** slunkad has quit IRC | 14:11 | |
| *** aojea has joined #openstack-keystone | 14:20 | |
| *** catintheroof has joined #openstack-keystone | 14:23 | |
| *** aojea has quit IRC | 14:25 | |
| *** Dinesh_Bhor has quit IRC | 14:34 | |
| *** dave-mcc_ is now known as dave-mccowan | 14:35 | |
| *** magicboiz has joined #openstack-keystone | 14:36 | |
| lbragstad | cmurphy: thanks again for taking the time to write that up - nicely done | 14:40 |
| cmurphy | lbragstad: i had a lot of run reading rfcs late into the night :) | 14:41 |
| cmurphy | fun* | 14:41 |
| lbragstad | cmurphy: i can tell! | 14:41 |
| lbragstad | because you distilled the information nicely :) | 14:41 |
| cmurphy | :D | 14:42 |
| *** rcernin has joined #openstack-keystone | 14:45 | |
| *** spectr has quit IRC | 14:46 | |
| *** MaxPC has quit IRC | 14:52 | |
| knikolla | o/ | 14:54 |
| *** jistr|mtg is now known as jistr | 14:58 | |
| *** rcernin has quit IRC | 15:03 | |
| *** bhagyashris has quit IRC | 15:16 | |
| *** aojea has joined #openstack-keystone | 15:21 | |
| *** alex_xu has quit IRC | 15:22 | |
| *** aojea has quit IRC | 15:25 | |
| *** alex_xu has joined #openstack-keystone | 15:31 | |
| *** gyee has joined #openstack-keystone | 15:32 | |
| lbragstad | if anyone is looking for reviews - more eyes on https://review.openstack.org/#/c/484483/31 and https://review.openstack.org/#/c/486757/24 would be good | 15:49 |
| lbragstad | gagehugo: responded - https://review.openstack.org/#/c/499726/12 | 15:51 |
| *** chlong has quit IRC | 15:53 | |
| *** AlexeyAbashkin has quit IRC | 15:55 | |
| *** MaxPC has joined #openstack-keystone | 16:08 | |
| *** magicboiz has quit IRC | 16:12 | |
| *** magicboiz has joined #openstack-keystone | 16:13 | |
| *** lnxnut_ has quit IRC | 16:16 | |
| knikolla | lbragstad: looking. | 16:18 |
| *** aojea has joined #openstack-keystone | 16:22 | |
| *** pcaruana has quit IRC | 16:23 | |
| *** aojea has quit IRC | 16:27 | |
| *** fried_rice is now known as fried_rice_injer | 16:28 | |
| *** fried_rice_injer is now known as friedrice_injera | 16:29 | |
| kmalloc | cmurphy: niiicE! | 16:31 |
| kmalloc | cmurphy: added comments (lbragstad cc) | 16:37 |
| *** wes_dillingham has quit IRC | 16:42 | |
| lbragstad | kmalloc: awesome - i can spin a new version today | 16:45 |
| *** wes_dillingham has joined #openstack-keystone | 16:53 | |
| *** ioggstream has quit IRC | 17:02 | |
| *** magicboiz has quit IRC | 17:03 | |
| *** magicboiz has joined #openstack-keystone | 17:05 | |
| *** mvk has quit IRC | 17:14 | |
| samueldmq | lbragstad: cmurphy: kmalloc would be great to get a couple of eyes on bug 1718747 | 17:15 |
| openstack | bug 1718747 in OpenStack Identity (keystone) "Unable to delete domain with users in it" [High,In progress] https://launchpad.net/bugs/1718747 - Assigned to Samuel de Medeiros Queiroz (samueldmq) | 17:15 |
| samueldmq | #link https://review.openstack.org/#/q/status:open+topic:bug/1718747 | 17:15 |
| samueldmq | I've got patches for keystone master + backport and tests in tempest | 17:15 |
| *** magicboiz has quit IRC | 17:19 | |
| *** magicboiz has joined #openstack-keystone | 17:19 | |
| lbragstad | samueldmq: sure thing - I saw the patches posted for review, I'll take a look after lunch | 17:20 |
| samueldmq | thanks | 17:21 |
| samueldmq | FYI jenkins is passing on them all, it's zull -1 there | 17:21 |
| *** aojea has joined #openstack-keystone | 17:23 | |
| *** catintheroof has quit IRC | 17:25 | |
| *** catintheroof has joined #openstack-keystone | 17:25 | |
| *** AlexeyAbashkin has joined #openstack-keystone | 17:27 | |
| *** mvk has joined #openstack-keystone | 17:27 | |
| *** aojea has quit IRC | 17:27 | |
| *** AlexeyAbashkin has quit IRC | 17:28 | |
| *** catintheroof has quit IRC | 17:29 | |
| *** nicolasbock has quit IRC | 17:42 | |
| SamYaple | oh nice cmurphy! JWT would be sweer | 17:45 |
| SamYaple | sweet* | 17:45 |
| SamYaple | ive done a good bit with them fairly recently | 17:46 |
| *** aselius has joined #openstack-keystone | 17:53 | |
| *** Guest53680 is now known as mgagne | 18:14 | |
| *** mgagne has quit IRC | 18:14 | |
| *** mgagne has joined #openstack-keystone | 18:14 | |
| *** aojea has joined #openstack-keystone | 18:23 | |
| openstackgerrit | Merged openstack/keystone master: Updated from global requirements https://review.openstack.org/511015 | 18:24 |
| samueldmq | cmurphy: lbragstad: why do we need bearer tokens? as we do recheck/revalidate entities (projects, user,roles,etc) at token validation time? | 18:24 |
| samueldmq | I might be missing something really basic | 18:24 |
| *** magicboiz has quit IRC | 18:25 | |
| lbragstad | even though we rebuild the entire context at validation time, the token is still considered a bearer token | 18:25 |
| lbragstad | (because it gives the power to the bearer) | 18:25 |
| *** magicboiz has joined #openstack-keystone | 18:25 | |
| lbragstad | so if I create a token and give it to you, there is nothing preventing keystone from thinking you're me | 18:26 |
| lbragstad | in order to get over the bearer token hurdle, we'd need to be able to assert the token belongs to the person or thing that passed it to keystone | 18:26 |
| lbragstad | (signed requests or something like that) | 18:27 |
| lbragstad | (which might require some out-of-band trust relationship between the user and keystone) | 18:27 |
| *** aojea has quit IRC | 18:28 | |
| lbragstad | i think we need bearer tokens - at least for the time being, because we don't have any other way to operator | 18:29 |
| lbragstad | operate* | 18:30 |
| lbragstad | you'd need to teach keystone and all the other services to do something like validate signed requests | 18:30 |
| samueldmq | lbragstad: (because it gives the power to the bearer) ... | 18:30 |
| samueldmq | hmm I though it was because the token itself was bearer, like carrying info within it | 18:30 |
| lbragstad | yeah - so if you steal a token of mine, you can do anything i can do | 18:31 |
| openstackgerrit | Gage Hugo proposed openstack/keystone master: Implement backend logic for project tags https://review.openstack.org/499726 | 18:31 |
| openstackgerrit | Gage Hugo proposed openstack/keystone master: Implement project tags logic into manager https://review.openstack.org/499727 | 18:31 |
| openstackgerrit | Gage Hugo proposed openstack/keystone master: Implement project tags API controller and router https://review.openstack.org/499728 | 18:31 |
| samueldmq | such as roles, etc | 18:31 |
| samueldmq | lbragstad: hmm I got it | 18:31 |
| samueldmq | thanks for clarifying | 18:31 |
| lbragstad | yep | 18:31 |
| lbragstad | at least that's my take on it | 18:32 |
| samueldmq | we would need yet another mechanism to check the user in validation time ... | 18:32 |
| lbragstad | i remember having an extensive conversation with dolphm in 2015 about finding a way to do away with bearer tokens | 18:32 |
| lbragstad | but - we didn't really take it anywhere | 18:32 |
| *** jmlowe has quit IRC | 18:33 | |
| *** catintheroof has joined #openstack-keystone | 18:33 | |
| gagehugo | lbragstad moved that logic into the manager | 18:34 |
| lbragstad | gagehugo: awesome - did that fix things for you? | 18:34 |
| gagehugo | yup, I added a test for that situation as well | 18:34 |
| lbragstad | sweet | 18:34 |
| gagehugo | when filtering on tags & some attribute | 18:35 |
| * lbragstad goes to review more project tags stuff | 18:35 | |
| gagehugo | addressed your comments too because I was already rebasing everything | 18:35 |
| gagehugo | gonna step away for a bit, I'll be on later | 18:35 |
| *** magicboiz has quit IRC | 19:07 | |
| *** magicboiz has joined #openstack-keystone | 19:08 | |
| *** friedrice_injera is now known as fried_rice | 19:12 | |
| lbragstad | cool - i think my comments are all addressed | 19:13 |
| lbragstad | samueldmq: is the bug here that we can't delete a domain with stuff in it or that we issue a 500 instead of something else? https://bugs.launchpad.net/keystone/+bug/1718747 | 19:13 |
| openstack | Launchpad bug 1718747 in OpenStack Identity (keystone) "Unable to delete domain with users in it" [High,In progress] - Assigned to Samuel de Medeiros Queiroz (samueldmq) | 19:13 |
| samueldmq | lbragstad: we can't delete domain with contents at all | 19:14 |
| samueldmq | the foreign key fails when trying to delete the domain in the database | 19:15 |
| lbragstad | samueldmq: was it possible to delete a domain with things in it before? | 19:17 |
| samueldmq | lbragstad: yes but only before newton I guess | 19:17 |
| samueldmq | because the FK did not exist | 19:17 |
| lbragstad | hug | 19:17 |
| lbragstad | huh* | 19:17 |
| samueldmq | lbragstad: actually, it fails if you've done the migraiton | 19:17 |
| samueldmq | that adds the fk | 19:18 |
| samueldmq | in the model we don't have the fk, do new deployments will be fine | 19:18 |
| samueldmq | and things in hte domain is restricted to users | 19:18 |
| samueldmq | groups in the domain are fine. there is no fk for that case | 19:18 |
| lbragstad | so if you delete a domain that has group it in, it deletes the groups automatically? | 19:19 |
| *** magicboiz has quit IRC | 19:20 | |
| *** MaxPC has quit IRC | 19:23 | |
| *** aojea has joined #openstack-keystone | 19:24 | |
| lbragstad | cc samueldmq ^ | 19:28 |
| samueldmq | lbragstad: yes | 19:29 |
| samueldmq | keystoen deletes the domain first, and as a result of the notification sent | 19:29 |
| samueldmq | it deletes users and groups in that domain | 19:29 |
| *** aojea has quit IRC | 19:29 | |
| lbragstad | ah | 19:29 |
| samueldmq | however the users have a fk pointing back to domain, so they can't be deleted after the domain is deleted | 19:29 |
| samueldmq | the domain delete fails with: user.domain_id -> project.id fk failed ! | 19:30 |
| samueldmq | lbragstad: the fk is added here https://github.com/openstack/keystone/blob/2bd88d3/keystone/common/sql/expand_repo/versions/014_expand_add_domain_id_to_user_table.py#L140-L141 | 19:31 |
| samueldmq | and does not exist in the model | 19:31 |
| samueldmq | lbragstad: wonder what we'd like to do to make model + migration consistent | 19:31 |
| samueldmq | add another migration to remove the fk? or add the fk in the model? | 19:31 |
| lbragstad | adding the FK to the model shouldn't require a migration | 19:31 |
| openstackgerrit | prashkre proposed openstack/keystone master: Handle ldap size limit exeeded exception https://review.openstack.org/511822 | 19:32 |
| *** AlexeyAbashkin has joined #openstack-keystone | 19:40 | |
| *** AlexeyAbashkin has quit IRC | 19:44 | |
| *** wes_dillingham has quit IRC | 19:53 | |
| openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Propose JWT as a new token provider https://review.openstack.org/511806 | 20:00 |
| *** jmlowe has joined #openstack-keystone | 20:02 | |
| *** gyee has quit IRC | 20:03 | |
| *** raildo has quit IRC | 20:10 | |
| *** MaxPC has joined #openstack-keystone | 20:21 | |
| *** thorst has quit IRC | 20:23 | |
| *** thorst has joined #openstack-keystone | 20:23 | |
| *** aojea has joined #openstack-keystone | 20:25 | |
| *** thorst has quit IRC | 20:28 | |
| *** aojea has quit IRC | 20:30 | |
| *** thorst has joined #openstack-keystone | 20:44 | |
| *** edmondsw has quit IRC | 20:45 | |
| *** thorst has quit IRC | 20:48 | |
| *** MaxPC has quit IRC | 21:08 | |
| *** catintheroof has quit IRC | 21:10 | |
| openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add a new table for system role assignments https://review.openstack.org/507993 | 21:13 |
| openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement backend logic for system roles https://review.openstack.org/507994 | 21:13 |
| *** wes_dillingham has joined #openstack-keystone | 21:13 | |
| lbragstad | samueldmq: targeting this to the releases you've proposed backports for - https://bugs.launchpad.net/keystone/+bug/1718747 | 21:26 |
| openstack | Launchpad bug 1718747 in OpenStack Identity (keystone) "Unable to delete domain with users in it" [High,In progress] - Assigned to Samuel de Medeiros Queiroz (samueldmq) | 21:26 |
| *** aojea has joined #openstack-keystone | 21:26 | |
| *** aojea has quit IRC | 21:30 | |
| *** wes_dillingham has quit IRC | 21:32 | |
| *** dave-mccowan has quit IRC | 21:34 | |
| *** thorst has joined #openstack-keystone | 21:38 | |
| *** AlexeyAbashkin has joined #openstack-keystone | 21:39 | |
| *** thorst has quit IRC | 21:42 | |
| *** wes_dillingham has joined #openstack-keystone | 21:44 | |
| *** AlexeyAbashkin has quit IRC | 21:44 | |
| *** wes_dillingham has quit IRC | 22:09 | |
| openstackgerrit | Lance Bragstad proposed openstack/keystone master: Fix list in caching documentation https://review.openstack.org/511974 | 22:13 |
| *** aojea has joined #openstack-keystone | 22:26 | |
| *** aojea has quit IRC | 22:30 | |
| *** AlexeyAbashkin has joined #openstack-keystone | 22:39 | |
| *** AlexeyAbashkin has quit IRC | 22:43 | |
| kmalloc | lbragstad: adding an FK to a model doesn't require a migration... unles the FK doesn't exist | 22:56 |
| kmalloc | which case the schema must be made to match | 22:56 |
| kmalloc | samueldmq: ^ | 22:56 |
| kmalloc | but an FK even in the model shouldn't break things | 22:56 |
| kmalloc | it might be be cascade delete | 22:56 |
| kmalloc | which case, you need to fix the FK. IIRC we explicitly chose to *not* allow cascade delete on anything in domain | 22:57 |
| kmalloc | basically, delete the domain resources explicitly before deleting the domain | 22:57 |
| kmalloc | i don't think this is a bug in the way it's written, it might be an intentional choice. | 22:58 |
| kmalloc | [likely] | 22:58 |
| *** wes_dillingham has joined #openstack-keystone | 23:11 | |
| *** wes_dillingham has quit IRC | 23:13 | |
| *** fried_rice is now known as efried | 23:23 | |
| *** aojea has joined #openstack-keystone | 23:27 | |
| *** aojea has quit IRC | 23:31 | |
| *** AlexeyAbashkin has joined #openstack-keystone | 23:39 | |
| *** AlexeyAbashkin has quit IRC | 23:43 | |
| *** superdan is now known as dansmith | 23:47 | |
| *** markvoelker has quit IRC | 23:49 | |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!