*** markvoelker has quit IRC | 00:08 | |
*** thorst has joined #openstack-keystone | 00:18 | |
*** thorst has quit IRC | 00:20 | |
*** rmcallis has quit IRC | 00:35 | |
*** markvoelker has joined #openstack-keystone | 01:05 | |
*** catintheroof has joined #openstack-keystone | 01:08 | |
*** daidv has joined #openstack-keystone | 01:15 | |
*** Shunli has joined #openstack-keystone | 01:15 | |
*** catintheroof has quit IRC | 01:22 | |
*** markvoelker has quit IRC | 01:38 | |
*** namnh has joined #openstack-keystone | 01:38 | |
*** zzzeek has quit IRC | 01:40 | |
*** zhangjl has joined #openstack-keystone | 01:50 | |
*** daidv has quit IRC | 01:50 | |
*** daidv has joined #openstack-keystone | 01:51 | |
*** itlinux has quit IRC | 02:10 | |
*** thorst has joined #openstack-keystone | 02:21 | |
*** namnh has quit IRC | 02:23 | |
*** daidv has quit IRC | 02:23 | |
*** daidv has joined #openstack-keystone | 02:24 | |
*** namnh has joined #openstack-keystone | 02:24 | |
*** thorst has quit IRC | 02:25 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/pycadf master: Updated from global requirements https://review.openstack.org/470137 | 02:28 |
---|---|---|
*** markvoelker has joined #openstack-keystone | 02:35 | |
*** annp has joined #openstack-keystone | 02:53 | |
*** zsli_ has joined #openstack-keystone | 02:57 | |
*** Shunli has quit IRC | 03:00 | |
*** markvoelker has quit IRC | 03:09 | |
*** namnh has quit IRC | 03:18 | |
*** daidv has quit IRC | 03:18 | |
*** daidv has joined #openstack-keystone | 03:19 | |
*** namnh has joined #openstack-keystone | 03:19 | |
*** daidv has quit IRC | 03:40 | |
*** daidv has joined #openstack-keystone | 03:41 | |
*** rcernin has quit IRC | 03:47 | |
*** rcernin_ has joined #openstack-keystone | 03:47 | |
*** dave-mccowan has quit IRC | 03:48 | |
*** Chealion has joined #openstack-keystone | 03:53 | |
*** markvoelker has joined #openstack-keystone | 04:06 | |
*** namnh has quit IRC | 04:13 | |
*** daidv has quit IRC | 04:13 | |
*** daidv has joined #openstack-keystone | 04:14 | |
*** namnh has joined #openstack-keystone | 04:14 | |
*** Dinesh_Bhor has joined #openstack-keystone | 04:14 | |
*** thorst has joined #openstack-keystone | 04:22 | |
*** thorst has quit IRC | 04:27 | |
*** markvoelker has quit IRC | 04:39 | |
*** nkinder has joined #openstack-keystone | 04:45 | |
*** jaosorior has joined #openstack-keystone | 04:54 | |
*** markvoelker has joined #openstack-keystone | 05:37 | |
*** zhurong has joined #openstack-keystone | 05:48 | |
*** hoonetorg has quit IRC | 06:05 | |
*** markvoelker has quit IRC | 06:10 | |
*** thorst has joined #openstack-keystone | 06:23 | |
*** hoonetorg has joined #openstack-keystone | 06:23 | |
*** prashkre has joined #openstack-keystone | 06:26 | |
*** thorst has quit IRC | 06:27 | |
*** spectr has joined #openstack-keystone | 07:02 | |
*** markvoelker has joined #openstack-keystone | 07:07 | |
*** magicboiz has joined #openstack-keystone | 07:13 | |
*** zehfpuohuq has joined #openstack-keystone | 07:15 | |
*** rcernin_ has quit IRC | 07:17 | |
*** prashkre has quit IRC | 07:17 | |
*** AlexeyAbashkin has joined #openstack-keystone | 07:23 | |
*** magicboiz has quit IRC | 07:26 | |
*** tesseract has joined #openstack-keystone | 07:33 | |
*** markvoelker has quit IRC | 07:40 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystonemiddleware master: Imported Translations from Zanata https://review.openstack.org/514529 | 07:46 |
SamYaple | what does keystone do with rabbitmq? specifically, where does transport_url get consumed? is it just for notifications? | 07:51 |
cmurphy | SamYaple: afaik yes, just for notifications. it will continue to work just fine if you don't configure rabbit | 07:54 |
*** rcernin has joined #openstack-keystone | 08:22 | |
*** thorst has joined #openstack-keystone | 08:24 | |
*** thorst has quit IRC | 08:28 | |
*** arxcruz|pto is now known as arxcruz | 08:30 | |
*** magicboiz has joined #openstack-keystone | 08:32 | |
*** d0ugal has quit IRC | 08:34 | |
*** d0ugal has joined #openstack-keystone | 08:35 | |
*** d0ugal has quit IRC | 08:35 | |
*** d0ugal has joined #openstack-keystone | 08:35 | |
*** d0ugal has quit IRC | 08:35 | |
*** markvoelker has joined #openstack-keystone | 08:37 | |
*** magicboiz has quit IRC | 08:37 | |
*** d0ugal has joined #openstack-keystone | 08:40 | |
*** d0ugal has quit IRC | 08:40 | |
*** d0ugal has joined #openstack-keystone | 08:40 | |
*** d0ugal has quit IRC | 08:40 | |
*** evrardjp has quit IRC | 08:40 | |
*** evrardjp has joined #openstack-keystone | 08:41 | |
SamYaple | cmurphy: yea thats why i was asking, i dont use notifications and havent configured rabbitmq for keystone or glance for years. was just curious. thanks! | 08:41 |
*** magicboiz has joined #openstack-keystone | 08:45 | |
*** d0ugal has joined #openstack-keystone | 08:48 | |
*** d0ugal has quit IRC | 08:48 | |
*** d0ugal has joined #openstack-keystone | 08:48 | |
*** zhangjl has quit IRC | 09:04 | |
*** markvoelker has quit IRC | 09:10 | |
*** magicboiz has quit IRC | 09:20 | |
*** evrardjp has quit IRC | 09:22 | |
*** evrardjp has joined #openstack-keystone | 09:23 | |
*** d0ugal has quit IRC | 09:28 | |
*** magicboiz has joined #openstack-keystone | 09:29 | |
*** zsli_ has quit IRC | 09:29 | |
*** gmann is now known as gmann_afk | 09:29 | |
*** magicboiz has quit IRC | 09:34 | |
*** d0ugal has joined #openstack-keystone | 09:38 | |
*** magicboiz has joined #openstack-keystone | 09:41 | |
*** prashkre has joined #openstack-keystone | 09:43 | |
*** edmondsw has joined #openstack-keystone | 09:47 | |
*** edmondsw has quit IRC | 09:52 | |
*** zhurong has quit IRC | 10:05 | |
*** magicboiz has quit IRC | 10:06 | |
*** markvoelker has joined #openstack-keystone | 10:07 | |
*** annp has quit IRC | 10:17 | |
*** zhurong has joined #openstack-keystone | 10:19 | |
*** thorst has joined #openstack-keystone | 10:25 | |
*** thorst has quit IRC | 10:30 | |
*** markvoelker has quit IRC | 10:41 | |
-openstackstatus- NOTICE: Zuul has been restarted due to an unexpected issue. Please recheck any jobs that were in progress | 10:46 | |
*** aloga has quit IRC | 10:55 | |
*** mvk has quit IRC | 10:55 | |
*** aloga has joined #openstack-keystone | 10:55 | |
*** pcaruana has joined #openstack-keystone | 10:56 | |
*** nicolasbock has joined #openstack-keystone | 11:07 | |
*** namnh has quit IRC | 11:17 | |
*** mvk has joined #openstack-keystone | 11:29 | |
*** dave-mccowan has joined #openstack-keystone | 11:35 | |
*** markvoelker has joined #openstack-keystone | 11:38 | |
*** spectr has quit IRC | 11:59 | |
*** raildo has joined #openstack-keystone | 11:59 | |
*** spectr has joined #openstack-keystone | 12:00 | |
*** raildo has quit IRC | 12:04 | |
*** raildo has joined #openstack-keystone | 12:05 | |
*** thorst has joined #openstack-keystone | 12:09 | |
*** edmondsw has joined #openstack-keystone | 12:09 | |
*** markvoelker has quit IRC | 12:11 | |
*** thorst_ has joined #openstack-keystone | 12:19 | |
*** thorst__ has joined #openstack-keystone | 12:20 | |
*** thorst has quit IRC | 12:23 | |
*** thorst_ has quit IRC | 12:24 | |
*** markvoelker has joined #openstack-keystone | 12:29 | |
*** magicboiz has joined #openstack-keystone | 12:32 | |
*** catintheroof has joined #openstack-keystone | 12:33 | |
*** catintheroof has quit IRC | 12:47 | |
*** catintheroof has joined #openstack-keystone | 12:49 | |
*** magicboiz has quit IRC | 12:50 | |
*** magicboiz has joined #openstack-keystone | 12:50 | |
*** zhurong has quit IRC | 12:50 | |
*** magicboiz has quit IRC | 12:52 | |
*** panbalag has joined #openstack-keystone | 12:52 | |
*** panbalag has left #openstack-keystone | 12:53 | |
*** magicboiz has joined #openstack-keystone | 12:53 | |
*** magicboiz has quit IRC | 12:58 | |
*** rcernin has quit IRC | 12:58 | |
*** mvk has quit IRC | 13:01 | |
*** magicboiz has joined #openstack-keystone | 13:05 | |
*** mvk has joined #openstack-keystone | 13:16 | |
*** magicboiz has quit IRC | 13:25 | |
*** lbragstad has quit IRC | 13:25 | |
*** superdan is now known as dansmith | 13:28 | |
*** lbragstad has joined #openstack-keystone | 13:33 | |
*** ChanServ sets mode: +o lbragstad | 13:33 | |
*** efried is now known as efried_brb | 13:36 | |
*** thorst__ has quit IRC | 13:40 | |
lbragstad | o/ | 13:40 |
*** jdennis has quit IRC | 13:43 | |
*** jdennis has joined #openstack-keystone | 13:46 | |
*** efried_brb is now known as efried | 13:46 | |
*** wes_dillingham has joined #openstack-keystone | 13:56 | |
*** jmlowe has joined #openstack-keystone | 13:59 | |
prashkre | lbragstad: Hi! Gud morning. | 14:02 |
prashkre | lbragstad: could you please take a look at https://review.openstack.org/#/c/515409/ | 14:02 |
*** spilla has joined #openstack-keystone | 14:07 | |
lbragstad | prashkre: sure | 14:13 |
*** lbragstad has quit IRC | 14:13 | |
*** lbragstad has joined #openstack-keystone | 14:13 | |
*** ChanServ sets mode: +o lbragstad | 14:13 | |
*** lbragstad has quit IRC | 14:18 | |
*** lbragstad has joined #openstack-keystone | 14:22 | |
*** ChanServ sets mode: +o lbragstad | 14:22 | |
*** thorst has joined #openstack-keystone | 14:30 | |
*** thorst has quit IRC | 14:31 | |
*** thorst has joined #openstack-keystone | 14:31 | |
*** zzzeek has joined #openstack-keystone | 14:47 | |
*** dikonoor has joined #openstack-keystone | 14:50 | |
*** mvk has quit IRC | 14:51 | |
*** LobsterRoll has joined #openstack-keystone | 15:00 | |
*** wes_dillingham has quit IRC | 15:02 | |
*** LobsterRoll is now known as wes_dillingham | 15:02 | |
openstackgerrit | Merged openstack/keystone master: Consolidate V2Controller functionality https://review.openstack.org/514814 | 15:06 |
openstackgerrit | Merged openstack/keystone master: Update API reference link in README https://review.openstack.org/504196 | 15:06 |
openstackgerrit | Merged openstack/keystone master: Fix endpoint examples in api-ref https://review.openstack.org/499141 | 15:06 |
*** mvk has joined #openstack-keystone | 15:13 | |
*** itlinux has joined #openstack-keystone | 15:19 | |
*** phalmos has joined #openstack-keystone | 15:19 | |
*** wes_dillingham has quit IRC | 15:21 | |
*** wes_dillingham has joined #openstack-keystone | 15:23 | |
*** magicboiz has joined #openstack-keystone | 15:27 | |
*** phalmos has quit IRC | 15:28 | |
*** AlexeyAbashkin has quit IRC | 15:30 | |
*** AlexeyAbashkin has joined #openstack-keystone | 15:31 | |
*** magicboiz has quit IRC | 15:35 | |
*** AlexeyAbashkin has quit IRC | 15:35 | |
*** phalmos has joined #openstack-keystone | 15:35 | |
*** catintheroof has quit IRC | 15:37 | |
*** gyee has joined #openstack-keystone | 15:38 | |
knikolla | o/ | 15:41 |
*** magicboiz has joined #openstack-keystone | 15:41 | |
lbragstad | o/ | 15:42 |
*** spectr has quit IRC | 16:02 | |
*** phalmos_ has joined #openstack-keystone | 16:06 | |
*** catintheroof has joined #openstack-keystone | 16:07 | |
*** phalmos has quit IRC | 16:09 | |
*** itlinux has quit IRC | 16:12 | |
*** catintheroof has quit IRC | 16:12 | |
lbragstad | samueldmq: cmurphy i reworked the documentation organization card into an Epic (sorry for the spam!) | 16:16 |
lbragstad | most of that work is for the Outreachy program, so feel free to remove yourselves from some of those cards if you need to | 16:17 |
*** panbalag has joined #openstack-keystone | 16:17 | |
lbragstad | i kept you both on the cards since you were interested in the original effort | 16:17 |
*** prashkre has quit IRC | 16:22 | |
*** rmcallis has joined #openstack-keystone | 16:28 | |
kmalloc | o/ | 16:29 |
kmalloc | mornin | 16:29 |
cmurphy | lbragstad: i can definitely help with mentorship/reviews if not the actual work itself | 16:29 |
lbragstad | cmurphy: that'd be perfect | 16:30 |
lbragstad | o/ kmalloc | 16:30 |
*** phalmos has joined #openstack-keystone | 16:36 | |
lbragstad | FYI - http://lists.openstack.org/pipermail/openstack-dev/2017-October/124093.html | 16:38 |
*** phalmos_ has quit IRC | 16:39 | |
*** efried is now known as efried_rollin | 16:43 | |
kmalloc | :) | 16:43 |
*** markvoelker_ has joined #openstack-keystone | 16:47 | |
*** markvoelker has quit IRC | 16:49 | |
*** rmcallis has quit IRC | 16:49 | |
*** MaxPC has joined #openstack-keystone | 16:50 | |
MaxPC | hi everyone | 16:50 |
MaxPC | I have a question, not sure this is the best place but figured I might as well try here. | 16:51 |
MaxPC | Is there an operation guide for setting up RBAC ? like a list of recommendations (do's and dont's) | 16:51 |
*** markvoelker_ has quit IRC | 16:51 | |
*** catintheroof has joined #openstack-keystone | 16:52 | |
*** rmcallis has joined #openstack-keystone | 16:53 | |
*** tesseract has quit IRC | 16:55 | |
*** catintheroof has quit IRC | 16:56 | |
lbragstad | MaxPC: unfortunately, I don't think there is | 16:56 |
lbragstad | MaxPC: I think that's partially because there are *so* many things you can do with it today (since it's pretty much just configuration) | 16:57 |
MaxPC | That's what I thought thanks :-) | 16:57 |
lbragstad | MaxPC: is there somethings you're specifically trying to do? | 16:58 |
MaxPC | no, I am working with a cloud operator | 16:58 |
lbragstad | ah | 16:58 |
MaxPC | and they were wondering about that. I suspected there wasn't an easy answer to dos and donts in RBAC | 16:58 |
MaxPC | I was just making sure I didn't miss anything. | 16:59 |
lbragstad | MaxPC: no - not yet... we're working on a bunch of things this release that should make it easier to understand though | 16:59 |
MaxPC | it's always up to the use case but for enterprise things like only giving service or application accounts API access to production environments | 16:59 |
MaxPC | good chance is you don't want devs hitting those, but some companies might :-) | 17:00 |
*** markvoelker has joined #openstack-keystone | 17:00 | |
lbragstad | yeah | 17:01 |
*** markvoelker has quit IRC | 17:05 | |
*** harlowja has joined #openstack-keystone | 17:19 | |
*** mvk has quit IRC | 17:20 | |
*** markvoelker has joined #openstack-keystone | 17:23 | |
*** magicboiz has quit IRC | 17:25 | |
*** catintheroof has joined #openstack-keystone | 17:27 | |
*** markvoelker has quit IRC | 17:28 | |
*** markvoelker has joined #openstack-keystone | 17:30 | |
*** AlexeyAbashkin has joined #openstack-keystone | 17:30 | |
*** itlinux has joined #openstack-keystone | 17:31 | |
*** catintheroof has quit IRC | 17:32 | |
*** panbalag has left #openstack-keystone | 17:32 | |
*** markvoelker has quit IRC | 17:34 | |
*** AlexeyAbashkin has quit IRC | 17:35 | |
*** phalmos_ has joined #openstack-keystone | 17:36 | |
*** catintheroof has joined #openstack-keystone | 17:37 | |
*** phalmos has quit IRC | 17:39 | |
*** magicboiz has joined #openstack-keystone | 17:40 | |
*** diablo_rojo_phon has left #openstack-keystone | 17:41 | |
*** catintheroof has quit IRC | 17:42 | |
*** panbalag has joined #openstack-keystone | 17:42 | |
*** magicboiz has quit IRC | 17:45 | |
*** panbalag has left #openstack-keystone | 17:46 | |
*** jmlowe has quit IRC | 17:47 | |
*** magicboiz has joined #openstack-keystone | 17:51 | |
*** prashkre has joined #openstack-keystone | 18:02 | |
*** dikonoor has quit IRC | 18:02 | |
*** jmlowe has joined #openstack-keystone | 18:04 | |
*** markvoelker has joined #openstack-keystone | 18:05 | |
*** nicolasbock has quit IRC | 18:05 | |
*** markvoelker has quit IRC | 18:09 | |
*** markvoelker has joined #openstack-keystone | 18:10 | |
*** markvoelker has quit IRC | 18:19 | |
*** markvoelker has joined #openstack-keystone | 18:19 | |
*** markvoelker_ has joined #openstack-keystone | 18:20 | |
samueldmq | lbragstad: nice thanks | 18:20 |
samueldmq | re docs reorganisation | 18:20 |
*** wes_dillingham has quit IRC | 18:22 | |
*** markvoelker has quit IRC | 18:23 | |
*** markvoelker has joined #openstack-keystone | 18:32 | |
*** markvoelker_ has quit IRC | 18:33 | |
*** prashkre has quit IRC | 18:35 | |
*** markvoelker has quit IRC | 18:37 | |
*** efried_rollin is now known as efried | 18:37 | |
*** aselius has joined #openstack-keystone | 18:40 | |
*** markvoelker has joined #openstack-keystone | 18:41 | |
*** catintheroof has joined #openstack-keystone | 18:43 | |
*** catintheroof has quit IRC | 18:48 | |
*** catintheroof has joined #openstack-keystone | 18:49 | |
*** mvk has joined #openstack-keystone | 18:53 | |
*** MaxPC has quit IRC | 18:55 | |
*** phalmos has joined #openstack-keystone | 19:06 | |
*** phalmos_ has quit IRC | 19:09 | |
*** AlexeyAbashkin has joined #openstack-keystone | 19:10 | |
*** wes_dillingham has joined #openstack-keystone | 19:18 | |
*** wes_dillingham has quit IRC | 19:33 | |
*** markvoelker has quit IRC | 19:34 | |
*** markvoelker has joined #openstack-keystone | 19:34 | |
*** rmcallis has quit IRC | 19:42 | |
itlinux | hello do we have any steps tips on how to convert from UUID to Fernet? Thanks | 19:50 |
lbragstad | itlinux: what do you mean? like, without downtime? | 19:51 |
itlinux | migrating yes possible without downtime.. of if it's short it's ok.. too | 19:51 |
itlinux | thanks lbragstad: | 19:51 |
lbragstad | clients should try reauthenticating if they get a 401 with a token | 19:52 |
lbragstad | so, if you make the switch and start issuing fernet tokens, all uuid tokens in the deployment will become invalid immediately, regardless of their actual expiration | 19:52 |
lbragstad | in that case, you should have clients attempting to reauthenticate and the new token they get will be a fernet token | 19:53 |
lbragstad | we don't offer a way to migrate more gracefully than that upstream | 19:53 |
lbragstad | but - it is possible https://www.lbragstad.com/blog/migrating-token-formats-without-downtime | 19:53 |
*** jmlowe has quit IRC | 19:57 | |
itlinux | ok.. | 19:58 |
itlinux | no that's ok.. reauth if fine.. | 19:58 |
lbragstad | itlinux: cool - should be a pretty easy switch then, just make sure the key repository matches on all keystone nodes and make the configuration switch | 20:01 |
itlinux | lbragstad: I have this issue.. trying to figure out.. I have two deployments.. one LAB and one POC both have the same LDAP server and AD server.. the POC has a valid cert the LAB self signed.. I can query users on both domains, but the groups only work on the POC for both.. in the LAB the group works for AD but not for LDAP.. so I am trying to figure out..since the LAB is using fernet the other UUID.. but I see a in | 20:02 |
itlinux | both.. Could not find domain: xxxx.com. but I see the resutls.. | 20:02 |
itlinux | what will you suggest I enabled verbose.. | 20:03 |
itlinux | on one of server.. | 20:03 |
itlinux | http://paste.openstack.org/show/625004/ | 20:06 |
itlinux | this is ocata | 20:06 |
itlinux | this is the logs when I query the groups http://paste.openstack.org/show/625005/ | 20:08 |
*** phalmos has quit IRC | 20:16 | |
*** markvoelker has quit IRC | 20:35 | |
*** AlexeyAbashkin has quit IRC | 20:37 | |
lbragstad | itlinux: both keystone nodes are pointing to ldap and ad for identity information/ | 20:38 |
lbragstad | ? | 20:38 |
lbragstad | are you using domain configs? | 20:39 |
itlinux | both keystone are using the same LDAP and AD.. but the AD is not a problem.. | 20:39 |
itlinux | yes | 20:39 |
itlinux | so now I am deploying with UUID and see.. Using OOO | 20:39 |
lbragstad | so AD points to a domain and LDAP points to a different domain? | 20:39 |
itlinux | and check if there is something else.. | 20:39 |
itlinux | yes.. | 20:39 |
itlinux | correct | 20:39 |
itlinux | AD to Dom1 and LDAP to Dom2 | 20:39 |
itlinux | the only other diff is cert.. one is valid the other is self signed.. | 20:40 |
lbragstad | so the LAB keystone deployment has self signed certs for talking to both AD and LDAP? | 20:41 |
lbragstad | but the POC keystone node has valid certs? | 20:41 |
itlinux | yes | 20:41 |
itlinux | AD groups and users ok.. users on LDAP ok but no groups.. that's what's strange.. | 20:42 |
lbragstad | so both POC and LAB keystone nodes allow you to do `openstack user list --domain Dom1` and `openstack group list --domain Dom1` ? | 20:42 |
lbragstad | and that works fine? | 20:43 |
itlinux | for AD yes.. | 20:43 |
lbragstad | Dom1 is mapped to AD, right? | 20:43 |
itlinux | for LDAP does not.. | 20:43 |
itlinux | yes.. | 20:43 |
*** spilla has quit IRC | 20:43 | |
itlinux | I have some logs.. | 20:43 |
itlinux | http://pastebin.mattei.co/index.php/view/68537ebb | 20:44 |
itlinux | http://pastebin.mattei.co/index.php/view/1b6e1626 | 20:44 |
lbragstad | so avast.com is pointing to AD and wavemarket.com is pointing to LDAP | 20:45 |
itlinux | yes | 20:45 |
*** markvoelker has joined #openstack-keystone | 20:45 | |
lbragstad | Could not find domain: wavemarket.com. | 20:46 |
itlinux | I get the same on the POC.. | 20:47 |
itlinux | but the output is correct.. | 20:47 |
lbragstad | is ^ that true for both the POC and LAB keystone nodes? | 20:47 |
itlinux | yes | 20:47 |
lbragstad | hmm | 20:47 |
itlinux | I also get some strange things on the POC let me share this with you! | 20:47 |
lbragstad | cmurphy: would be good to ask about this | 20:47 |
lbragstad | the problem is consistent across both keystone deployments, then... | 20:49 |
lbragstad | yeah? | 20:49 |
*** markvoelker has quit IRC | 20:49 | |
*** markvoelker has joined #openstack-keystone | 20:49 | |
itlinux | https://pasteboard.co/GRnow52.png | 20:50 |
itlinux | see it says maybe.. never seen it before.. :) | 20:50 |
itlinux | but works.. | 20:50 |
* cmurphy reads | 20:50 | |
lbragstad | weird... that's a UI thing i bet, i've never noticed that | 20:51 |
itlinux | ok.. | 20:51 |
lbragstad | keystone doesn't emit "maybe" | 20:51 |
itlinux | if I invert it it fails.. | 20:51 |
lbragstad | when it comes to user enablement | 20:51 |
lbragstad | and if we do, it should be a bug | 20:51 |
itlinux | ahh.. | 20:52 |
itlinux | that's a pretty good one then.. the code has maybe .. | 20:52 |
itlinux | I looked at them while back.. | 20:52 |
itlinux | but not sure how to enable that to show enabled | 20:53 |
itlinux | instead of Maybe | 20:53 |
lbragstad | that would likely have to come from LDAP | 20:53 |
lbragstad | or your domain configuration for LDAP | 20:53 |
itlinux | let me check the AD one sec | 20:53 |
lbragstad | keystone has configuration options that let you specify an attribute to use for 'enabled' | 20:53 |
lbragstad | if an 'enabled' attribute doesn't exist in LDAP | 20:54 |
lbragstad | there is also a bitmask keystone can apply to a property for enabled, too | 20:54 |
cmurphy | "Could not find domain: wavemarket.com." is a totally normal message that happens when you use openstackclient, because it doesn't know whether it's getting an ID or a name and it first tries to GET /domains/wavemarket.com | 20:54 |
lbragstad | https://github.com/openstack/keystone/blob/master/keystone/conf/ldap.py#L159-L166 | 20:55 |
lbragstad | https://github.com/openstack/keystone/blob/master/keystone/conf/ldap.py#L168-L191 | 20:55 |
*** jmlowe has joined #openstack-keystone | 20:55 | |
lbragstad | cmurphy: osc should ask for a list of domains then, right? | 20:56 |
*** phalmos has joined #openstack-keystone | 20:57 | |
cmurphy | lbragstad: nope, it first does GET /domains/wavemarket.com and then failing that it does GET /domains?name=wavemarket.com | 20:57 |
itlinux | so the AD show Enabled ok.. | 20:57 |
cmurphy | lbragstad: well i guess that is requesting a list but filtering on name will only result in one item | 20:58 |
itlinux | I can share the filter I use.. | 20:58 |
*** rmcallis has joined #openstack-keystone | 20:58 | |
lbragstad | cmurphy: aha - that makes sense | 20:58 |
itlinux | maybe you can suggest the right one.. | 20:59 |
lbragstad | itlinux: it could be that your ldap configuration needs to be tweaked | 20:59 |
itlinux | ok what should I look for? | 20:59 |
lbragstad | because the same keystone configuration that works for AD might not work for LDAP | 20:59 |
itlinux | and I can ask the LDAP guy to make the changes.. | 20:59 |
itlinux | 25 min and I will have UUID completed.. | 21:00 |
lbragstad | cmurphy: will have to keep me honest here because she's way more familiar with this than I am | 21:00 |
itlinux | shal see then.. | 21:00 |
lbragstad | itlinux: but - do the users you have in LDAP have an enabled attribute? | 21:00 |
lbragstad | like, consistently? | 21:01 |
cmurphy | i sort of thought enabled was a boolean so i'm confused where "maybe" would come from | 21:01 |
lbragstad | cmurphy: me too, i've never seen that before | 21:01 |
itlinux | not sure.. I can ask..what options should I ask for? | 21:01 |
itlinux | not an LDAP guy.. | 21:01 |
lbragstad | itlinux: it depends on your ldap deployment | 21:02 |
*** markvoelker_ has joined #openstack-keystone | 21:02 | |
lbragstad | if there is an attribute that is guaranteed to be on every user and is a boolean - then you can use https://github.com/openstack/keystone/blob/master/keystone/conf/ldap.py#L159-L166 to map it to keystone's enabled property | 21:02 |
itlinux | ok I will pass this to the LDAP guy.. | 21:03 |
lbragstad | if it's not a boolean, but a numerical value (e.g. enabled = 0 or enabled = 1) then you might be able to use the mask | 21:03 |
lbragstad | https://github.com/openstack/keystone/blob/master/keystone/conf/ldap.py#L180-L191 | 21:03 |
itlinux | ok | 21:03 |
lbragstad | *or* you might have to invert the enabled logic - https://github.com/openstack/keystone/blob/master/keystone/conf/ldap.py#L168-L178 | 21:03 |
cmurphy | you should be able to configure this all in keystone without changing your ldap | 21:04 |
*** markvoelker has quit IRC | 21:04 | |
lbragstad | ++ | 21:04 |
lbragstad | which is reason why there are a bunch of different configuration options for this in keystone | 21:04 |
lbragstad | itlinux: you need to map keystone to understanding your ldap | 21:04 |
itlinux | well Iworked with the lDAP guy to map it.. | 21:05 |
lbragstad | it might be worth double checking that mapping | 21:06 |
lbragstad | just to be sure | 21:06 |
itlinux | ok..here is the filter I use.. | 21:07 |
itlinux | filter user_filter : "(&(objectclass=inetOrgPerson)(!(|(ou:dn:=Inactive)(ou:dn:=Service Keys)(ou:dn:=Service Accounts))))" | 21:07 |
lbragstad | and what does that give you? | 21:09 |
itlinux | users that are enabled and takes off the one inactive.. | 21:10 |
lbragstad | huh | 21:13 |
itlinux | do you have a filter I can test ? | 21:14 |
lbragstad | wasn't what you just pasted the filter that works? | 21:14 |
itlinux | that filter is the one that shows maybe | 21:15 |
*** pcaruana has quit IRC | 21:15 | |
lbragstad | that might be a good question for whoever manages LDAP, since each deployment can vary | 21:19 |
itlinux | ok | 21:20 |
itlinux | I may take it off.. and see.. if that does something.. | 21:20 |
itlinux | without filter.. | 21:20 |
*** dave-mccowan has quit IRC | 21:20 | |
*** jmlowe has quit IRC | 21:35 | |
*** thorst has quit IRC | 21:38 | |
*** raildo has quit IRC | 21:39 | |
*** jmlowe has joined #openstack-keystone | 21:42 | |
*** rodrigods has quit IRC | 21:45 | |
*** rodrigods has joined #openstack-keystone | 21:45 | |
*** rodrigods has quit IRC | 21:45 | |
*** rodrigods has joined #openstack-keystone | 21:45 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/pycadf master: Updated from global requirements https://review.openstack.org/470137 | 21:48 |
*** rcernin has joined #openstack-keystone | 21:51 | |
*** jmlowe has quit IRC | 21:56 | |
itlinux | lbragstad: I added a section for groups and now it works.. :) | 21:57 |
itlinux | will redeploy with Fernet now... | 21:57 |
*** thorst has joined #openstack-keystone | 21:58 | |
lbragstad | itlinux: sweet! | 22:02 |
*** thorst has quit IRC | 22:02 | |
itlinux | yea strange though ;) | 22:02 |
itlinux | LOL! | 22:02 |
*** phalmos has quit IRC | 22:05 | |
*** jmlowe has joined #openstack-keystone | 22:06 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/pycadf master: Updated from global requirements https://review.openstack.org/470137 | 22:13 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/pycadf master: Updated from global requirements https://review.openstack.org/470137 | 22:17 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/pycadf master: Updated from global requirements https://review.openstack.org/470137 | 22:17 |
*** wes_dillingham has joined #openstack-keystone | 22:20 | |
*** rmcallis has quit IRC | 22:25 | |
*** AlexeyAbashkin has joined #openstack-keystone | 22:29 | |
*** wes_dillingham has quit IRC | 22:29 | |
SamYaple | is db_sync safe to do in parallel (is there locking place)? and would that answer hold true across all services? | 22:32 |
SamYaple | or is this an oslo.db question | 22:32 |
*** AlexeyAbashkin has quit IRC | 22:33 | |
lbragstad | SamYaple: parallel? | 22:36 |
lbragstad | like - running db_sync from two separate keystone nodes at the same time? | 22:36 |
SamYaple | yes | 22:42 |
*** wes_dillingham has joined #openstack-keystone | 22:43 | |
SamYaple | lbragstad: im trying to remove potential races in a deploy where all services start/restart at the same time and db_sync | 22:43 |
*** wes_dillingham has quit IRC | 22:43 | |
SamYaple | the less locking logic i have to do, the better | 22:43 |
*** catintheroof has quit IRC | 22:48 | |
lbragstad | yeah - i don't think i'd do that, i think db_sync is written to assume only being run from a single place | 22:56 |
lbragstad | or a single node | 22:56 |
SamYaple | it *seems* to work fine, but ill wrap it in an etcd lock to be safe | 23:00 |
SamYaple | thanks! | 23:00 |
SamYaple | i do have one other question... i cant seem to specify the region with keystone-manage bootstraping without it complaining about foriegn keys https://github.com/SamYaple/home-salt/blob/master/salt/openstack/keystone/container.sls#L17 | 23:02 |
SamYaple | the idea behind that is i shouuld be able to set a specific regionwhen bootstraping right? | 23:02 |
SamYaple | and by complaining i mean stacktracing and crashing | 23:02 |
*** wes_dillingham has joined #openstack-keystone | 23:07 | |
*** panbalag has joined #openstack-keystone | 23:20 | |
*** panbalag has left #openstack-keystone | 23:21 | |
*** dave-mccowan has joined #openstack-keystone | 23:29 | |
*** AlexeyAbashkin has joined #openstack-keystone | 23:29 | |
*** lbragstad has quit IRC | 23:32 | |
*** AlexeyAbashkin has quit IRC | 23:33 | |
*** gyee has quit IRC | 23:33 | |
*** thorst has joined #openstack-keystone | 23:39 | |
*** jmlowe has quit IRC | 23:45 | |
*** jmlowe has joined #openstack-keystone | 23:59 | |
*** aloga has quit IRC | 23:59 | |
*** aloga has joined #openstack-keystone | 23:59 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!