openstackgerrit | Morgan Fainberg proposed openstack/keystone master: WIP: Remove Dependency Injection https://review.openstack.org/499703 | 00:04 |
---|---|---|
kmalloc | lbragstad, ayoung: there we go, that should do it for at least py27 | 00:05 |
*** thorst has joined #openstack-keystone | 00:08 | |
*** thorst has quit IRC | 00:09 | |
*** tsufiev has quit IRC | 00:16 | |
*** tsufiev has joined #openstack-keystone | 00:20 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: WIP: Remove Dependency Injection https://review.openstack.org/499703 | 00:32 |
*** masber has quit IRC | 00:33 | |
*** masber has joined #openstack-keystone | 00:41 | |
*** masber has quit IRC | 00:47 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Correct error message for request token https://review.openstack.org/525088 | 00:53 |
*** gyee has quit IRC | 00:56 | |
*** zhurong has joined #openstack-keystone | 01:03 | |
*** panbalag has joined #openstack-keystone | 01:07 | |
*** panbalag has left #openstack-keystone | 01:16 | |
*** jdennis has quit IRC | 01:22 | |
lbragstad | kmalloc: nice | 01:27 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system-scope in the token provider API https://review.openstack.org/525360 | 01:29 |
*** jdennis has joined #openstack-keystone | 01:38 | |
lbragstad | ayoung: i attempted to fill in the description here - https://trello.com/c/Mm6GGQ8Q/83-use-oslo-context-for-policy-enforcement | 01:39 |
lbragstad | let me know if that is missing anything | 01:39 |
*** mvk has quit IRC | 01:57 | |
*** Shunli has joined #openstack-keystone | 01:58 | |
*** mvk has joined #openstack-keystone | 01:59 | |
*** zhurong has quit IRC | 02:00 | |
*** zhurong has joined #openstack-keystone | 02:29 | |
*** aselius has quit IRC | 02:32 | |
*** annp has joined #openstack-keystone | 02:33 | |
*** masber has joined #openstack-keystone | 02:39 | |
*** links has joined #openstack-keystone | 03:07 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystonemiddleware master: Updated from global requirements https://review.openstack.org/523737 | 03:07 |
openstackgerrit | wangxiyuan proposed openstack/keystone-specs master: Limits API https://review.openstack.org/455709 | 03:26 |
*** edmondsw has quit IRC | 03:26 | |
*** threestrands has joined #openstack-keystone | 03:27 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-keystoneclient master: Updated from global requirements https://review.openstack.org/523792 | 03:32 |
openstackgerrit | ayoung proposed openstack/keystone master: Enforce policy on oslo-context https://review.openstack.org/523650 | 03:37 |
*** thorst has joined #openstack-keystone | 03:44 | |
*** thorst has quit IRC | 03:46 | |
ayoung | jamielennox, you happy with https://review.openstack.org/523650 ? | 03:49 |
*** thorst has joined #openstack-keystone | 03:53 | |
*** thorst has quit IRC | 03:54 | |
*** ayoung has left #openstack-keystone | 03:58 | |
*** dave-mccowan has quit IRC | 04:00 | |
*** ricolin has joined #openstack-keystone | 04:12 | |
*** zhurong has quit IRC | 04:27 | |
jamielennox | ayoung: sure | 04:33 |
*** nicolasbock has quit IRC | 04:48 | |
*** zhurong has joined #openstack-keystone | 04:54 | |
*** jaosorior has joined #openstack-keystone | 04:55 | |
*** edmondsw has joined #openstack-keystone | 05:14 | |
*** edmondsw has quit IRC | 05:18 | |
*** threestrands has quit IRC | 05:25 | |
*** dklyle has joined #openstack-keystone | 05:25 | |
*** david-lyle has quit IRC | 05:29 | |
*** dklyle has quit IRC | 05:30 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: WIP - Make fernet config and utils generic https://review.openstack.org/523200 | 06:05 |
*** deepika08 has joined #openstack-keystone | 06:08 | |
*** zhurong has quit IRC | 07:16 | |
*** pcaruana has joined #openstack-keystone | 07:32 | |
*** rcernin has quit IRC | 07:48 | |
*** zhurong has joined #openstack-keystone | 07:50 | |
*** zsli_ has joined #openstack-keystone | 08:02 | |
*** zsli__ has joined #openstack-keystone | 08:04 | |
*** zsli__ has quit IRC | 08:04 | |
*** zsli__ has joined #openstack-keystone | 08:05 | |
*** Shunli has quit IRC | 08:05 | |
*** zsli_ has quit IRC | 08:08 | |
*** jaosorior_ has joined #openstack-keystone | 08:10 | |
*** jaosorior has quit IRC | 08:13 | |
*** tesseract has joined #openstack-keystone | 08:24 | |
*** rcernin has joined #openstack-keystone | 08:33 | |
*** belmoreira has joined #openstack-keystone | 08:37 | |
*** pcaruana has quit IRC | 08:40 | |
*** jaosorior_ is now known as jaosorior | 08:47 | |
*** gmann is now known as gmann_afk | 08:56 | |
*** zsli__ has quit IRC | 08:59 | |
*** magicboiz has quit IRC | 09:01 | |
*** magicboiz has joined #openstack-keystone | 09:12 | |
*** magicboiz has quit IRC | 09:17 | |
*** magicboiz has joined #openstack-keystone | 09:17 | |
*** namnh has joined #openstack-keystone | 09:45 | |
*** mvk has quit IRC | 09:54 | |
*** mvk has joined #openstack-keystone | 10:22 | |
*** namnh has quit IRC | 10:29 | |
*** rcernin has quit IRC | 10:30 | |
*** annp has quit IRC | 10:33 | |
*** deepika08 has quit IRC | 10:37 | |
*** daidv has quit IRC | 10:50 | |
*** daidv has joined #openstack-keystone | 11:05 | |
*** edmondsw has joined #openstack-keystone | 11:58 | |
*** nicolasbock has joined #openstack-keystone | 12:03 | |
*** edmondsw has quit IRC | 12:05 | |
*** raildo has joined #openstack-keystone | 12:05 | |
*** zhurong has quit IRC | 12:36 | |
*** mvenesio has joined #openstack-keystone | 12:43 | |
*** zhurong has joined #openstack-keystone | 12:44 | |
*** david-lyle has joined #openstack-keystone | 12:48 | |
*** ricolin_ has joined #openstack-keystone | 12:50 | |
*** ricolin has quit IRC | 12:53 | |
*** david-lyle has quit IRC | 13:01 | |
*** zhurong has quit IRC | 13:02 | |
*** zhurong has joined #openstack-keystone | 13:03 | |
*** edmondsw has joined #openstack-keystone | 13:06 | |
*** ricolin has joined #openstack-keystone | 13:18 | |
*** ricolin_ has quit IRC | 13:20 | |
*** links has quit IRC | 13:22 | |
*** zhurong has quit IRC | 13:27 | |
*** tonytan4ever has joined #openstack-keystone | 13:29 | |
*** tonytan4ever has quit IRC | 13:30 | |
*** ricolin_ has joined #openstack-keystone | 13:46 | |
*** panbalag has joined #openstack-keystone | 13:47 | |
*** ricolin has quit IRC | 13:48 | |
*** panbalag has left #openstack-keystone | 13:49 | |
*** dave-mcc_ has joined #openstack-keystone | 13:59 | |
*** jdennis has quit IRC | 14:04 | |
*** jdennis has joined #openstack-keystone | 14:09 | |
*** thorst has joined #openstack-keystone | 14:09 | |
*** ricolin_ has quit IRC | 14:17 | |
*** magicboiz has quit IRC | 14:40 | |
*** jaosorior has quit IRC | 14:46 | |
*** jmlowe has joined #openstack-keystone | 14:59 | |
*** david-lyle has joined #openstack-keystone | 15:13 | |
*** panbalag has joined #openstack-keystone | 15:15 | |
*** rm_work has quit IRC | 15:32 | |
*** rm_work has joined #openstack-keystone | 15:36 | |
*** david-lyle has quit IRC | 15:39 | |
*** panbalag has left #openstack-keystone | 15:44 | |
*** openstackgerrit has quit IRC | 15:48 | |
*** jmlowe has quit IRC | 15:56 | |
*** jmlowe has joined #openstack-keystone | 15:57 | |
*** jmlowe has quit IRC | 15:59 | |
*** jmlowe has joined #openstack-keystone | 16:00 | |
*** jmlowe has quit IRC | 16:01 | |
*** jmlowe_ has joined #openstack-keystone | 16:01 | |
*** jmlowe_ has quit IRC | 16:02 | |
*** belmoreira has quit IRC | 16:04 | |
*** tonytan4ever has joined #openstack-keystone | 16:09 | |
*** tonytan4ever has quit IRC | 16:10 | |
*** thorst has quit IRC | 16:15 | |
*** iurygregory has quit IRC | 16:23 | |
*** mvk has quit IRC | 16:42 | |
*** openstackgerrit has joined #openstack-keystone | 16:52 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: WIP: Implement system-scoped tokens https://review.openstack.org/525687 | 16:52 |
* lbragstad ducks | 16:54 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add group system grant policies https://review.openstack.org/514725 | 16:55 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement controller logic for system user assignments https://review.openstack.org/515215 | 16:55 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement controller logic for system group assignments https://review.openstack.org/524017 | 16:55 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add system role assignment documentation https://review.openstack.org/524307 | 16:55 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add ability to list all system role assignments https://review.openstack.org/524407 | 16:55 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Ensure building scope is mutually exclusive https://review.openstack.org/498091 | 16:55 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove private methods for v2.0 and v3 tokens https://review.openstack.org/525329 | 16:55 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Teach TokenFormatter how to handle system scope https://review.openstack.org/525330 | 16:55 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system-scope in the token provider API https://review.openstack.org/525360 | 16:55 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: WIP: Implement system-scoped tokens https://review.openstack.org/525687 | 16:55 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add scope_types to endpoint policies https://review.openstack.org/525695 | 17:08 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add scope_types to service policies https://review.openstack.org/525696 | 17:09 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add scope_types to region policies https://review.openstack.org/525698 | 17:10 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add scope_types to endpoint group policies https://review.openstack.org/525700 | 17:12 |
*** spilla has joined #openstack-keystone | 17:14 | |
*** mvk has joined #openstack-keystone | 17:14 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add scope_types to mapping policies https://review.openstack.org/525701 | 17:14 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add scope_types to role policies https://review.openstack.org/525703 | 17:18 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add scope_types to domain policies https://review.openstack.org/525705 | 17:20 |
*** pcaruana has joined #openstack-keystone | 17:22 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add scope_types to group policies https://review.openstack.org/525706 | 17:22 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add scope_types to credential policies https://review.openstack.org/525707 | 17:24 |
*** pcaruana has quit IRC | 17:26 | |
*** pcaruana has joined #openstack-keystone | 17:27 | |
*** iurygregory has joined #openstack-keystone | 17:44 | |
*** pcaruana has quit IRC | 17:58 | |
*** itlinux has joined #openstack-keystone | 17:58 | |
hrybacki | lbragstad: https://hangouts.google.com/call/-WQa70V_B5iL-Tw3jiSqAAEE | 17:58 |
*** jose-phillips has quit IRC | 18:02 | |
*** jose-phillips has joined #openstack-keystone | 18:05 | |
*** mvenesio has quit IRC | 18:16 | |
*** mvenesio has joined #openstack-keystone | 18:17 | |
*** tesseract has quit IRC | 18:21 | |
*** jose-phillips has quit IRC | 18:23 | |
*** spilla has quit IRC | 18:54 | |
*** david-lyle has joined #openstack-keystone | 18:55 | |
lbragstad | #startmeeting keystone-office-hours | 19:00 |
openstack | Meeting started Tue Dec 5 19:00:53 2017 UTC and is due to finish in 60 minutes. The chair is lbragstad. Information about MeetBot at http://wiki.debian.org/MeetBot. | 19:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 19:00 |
*** openstack changes topic to " (Meeting topic: keystone-office-hours)" | 19:00 | |
*** ChanServ changes topic to "Queens release schedule: https://releases.openstack.org/queens/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/5F0h9Hoe/keystone" | 19:00 | |
openstack | The meeting name has been set to 'keystone_office_hours' | 19:00 |
*** david-lyle has quit IRC | 19:01 | |
*** spilla has joined #openstack-keystone | 19:06 | |
cmurphy | o/ | 19:07 |
*** mvenesio has quit IRC | 19:10 | |
*** aselius has joined #openstack-keystone | 19:11 | |
lbragstad | i need to get up to speed on https://review.openstack.org/#/c/522461/ | 19:12 |
cmurphy | lbragstad: this one goes with that one https://review.openstack.org/#/c/523005/ | 19:15 |
lbragstad | i just noticed that, too | 19:15 |
lbragstad | getting up to speed on https://review.openstack.org/#/c/523005 first | 19:15 |
lbragstad | aha- ok | 19:17 |
lbragstad | nevermind, i think i was getting things mixed up | 19:17 |
lbragstad | we should be able to remove https://review.openstack.org/#/c/523005 | 19:18 |
lbragstad | s/remove/merge/ | 19:18 |
gagehugo | o/ | 19:18 |
lbragstad | because it's only removing the usage of those configuration options and removing a couple things we don't need anymore | 19:18 |
lbragstad | which can be done before we deprecate those configuration options | 19:18 |
cmurphy | right it's just removing a function that never gets called | 19:19 |
kmalloc | i don't understand how someone might still be using it in v3? | 19:19 |
kmalloc | lbragstad: the memberid thing | 19:19 |
lbragstad | approving https://review.openstack.org/#/c/523005/ | 19:20 |
cmurphy | ensure_default_role() gets called in bootstrap which creates the _member_ role | 19:20 |
*** jose-phillips has joined #openstack-keystone | 19:20 | |
cmurphy | that's the only place it's actually used | 19:20 |
lbragstad | yeah - iiuc a deployment can run bootstrap and then start using the member id with v3 assignments, and not even expose v2.0 in the deployment | 19:22 |
*** jose-phillips has quit IRC | 19:24 | |
lbragstad | cmurphy: edmondsw boostrap was designed to be idempotent for recovery cases | 19:26 |
lbragstad | so it could be used outside of install day activities | 19:27 |
*** jose-phillips has joined #openstack-keystone | 19:27 | |
edmondsw | lbragstad how so? | 19:27 |
edmondsw | what kind of recovery? | 19:28 |
cmurphy | losing the _member_ role could be recovered from without bootstrap | 19:28 |
lbragstad | if an admin user is deleted, i think | 19:28 |
lbragstad | we had a commit a while back to do this, let me see if i can dig up the context | 19:28 |
edmondsw | to cmurphy's point, I don't think this bit about _member_ would be needed for that case | 19:29 |
lbragstad | https://bugs.launchpad.net/keystone/+bug/1647800 | 19:31 |
openstack | Launchpad bug 1647800 in OpenStack Identity (keystone) newton "keystone-manage bootstrap isn't completely idempotent" [High,Fix released] - Assigned to Lance Bragstad (lbragstad) | 19:31 |
lbragstad | that specific example is for running bootstrap during an upgrade | 19:33 |
lbragstad | maybe it's irrelevant | 19:33 |
cmurphy | lbragstad: what would you like to see in 522461? you want bootstrap to keep creating the role? | 19:34 |
lbragstad | i guess i wanted to make sure we didn't break anything if we wanted to remove it | 19:35 |
lbragstad | outside of the new install case | 19:35 |
cmurphy | my main worry is in deployment tool CI | 19:35 |
lbragstad | i was trying to think of times bootstrap gets run outside of new-install cases | 19:36 |
lbragstad | and i vaguely remembered that change, but it might not be relevant | 19:36 |
cmurphy | on upgrade cases people are reading the release notes anyways | 19:36 |
cmurphy | so they'll know if they have to do something different | 19:36 |
openstackgerrit | Merged openstack/oslo.policy master: Handle deprecation of inspect.getargspec https://review.openstack.org/521979 | 19:37 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Handle deprecation of inspect.getargspec https://review.openstack.org/525740 | 19:43 |
lbragstad | fwiw - we'll have a new version of oslo.policy soon https://review.openstack.org/#/c/525623/1 | 19:46 |
lbragstad | so all https://review.openstack.org/#/q/status:open+project:openstack/keystone+branch:master+topic:add-scope-types should start passing | 19:48 |
cmurphy | \o/ | 19:50 |
lbragstad | opinion time - do we want to hold off on https://bugs.launchpad.net/keystone/+bug/1689644 until we do microversions officially? | 19:57 |
openstack | Launchpad bug 1689644 in OpenStack Identity (keystone) "Keystone does not report microversion headers" [Medium,In progress] - Assigned to Rohan Arora (ra271w) | 19:57 |
lbragstad | knikolla: you said you have something locally for https://bugs.launchpad.net/keystone/+bug/1291157 right? | 19:58 |
openstack | Launchpad bug 1291157 in OpenStack Identity (keystone) "idp deletion should trigger token revocation" [Medium,In progress] - Assigned to Lance Bragstad (lbragstad) | 19:58 |
knikolla | lbragstad: yes, rebased the old review, now getting it to pass tests | 19:58 |
lbragstad | knikolla: awesome | 19:59 |
lbragstad | knikolla: thanks for picking that up | 19:59 |
cmurphy | lbragstad: i think that bug is not really valid, if/when we do microversions then a condition of that being done is having microversion headers | 19:59 |
lbragstad | we can probably close out https://bugs.launchpad.net/keystone/+bug/1662623 today | 20:00 |
openstack | Launchpad bug 1662623 in OpenStack Identity (keystone) "Testing keystone docs are outdated" [Wishlist,In progress] - Assigned to Lance Bragstad (lbragstad) | 20:00 |
lbragstad | cmurphy: yeah... after all the ms discussions, i inclined to agree with you | 20:00 |
lbragstad | i'm inclined* | 20:00 |
lbragstad | cmurphy: close with a comment? | 20:01 |
cmurphy | sure | 20:02 |
*** jrist has quit IRC | 20:05 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: WIP Add Application Credentials manager https://review.openstack.org/524747 | 20:06 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: WIP Add Application Credentials controller https://review.openstack.org/524423 | 20:06 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: WIP Add application credential auth plugin https://review.openstack.org/525346 | 20:06 |
lbragstad | another opinion question - what are peoples thoughts on https://bugs.launchpad.net/keystone/+bug/1642988 ? | 20:08 |
openstack | Launchpad bug 1642988 in OpenStack Identity (keystone) "Optionally encode project IDs in fernet tokens" [Wishlist,Triaged] - Assigned to Jose Castro Leon (jose-castro-leon) | 20:08 |
lbragstad | it doesn't impact API behavior | 20:08 |
lbragstad | and it's opt in for deployers to migrate to fernet | 20:09 |
lbragstad | (or jwt eventually) | 20:09 |
lbragstad | i know cern has project ids that vary in format | 20:10 |
gagehugo | is it because of the dashes? | 20:10 |
lbragstad | yeah | 20:10 |
lbragstad | so when the project id get reinflated | 20:10 |
lbragstad | it gets reinflated without the dashes | 20:10 |
lbragstad | but their backend expects it | 20:10 |
lbragstad | s/it/dashes/ | 20:11 |
lbragstad | so aa53ea1a-d9f8-11e7-957d-00163e88ac80 instead of abf4be76d9f811e7957d00163e88ac80 | 20:13 |
gagehugo | UUID spec says the dashes are optional right? | 20:14 |
lbragstad | that's a good question, i'd have to check | 20:14 |
*** ayoung has joined #openstack-keystone | 20:15 | |
cmurphy | seems like they could extend the token provider to handle it? | 20:16 |
lbragstad | that was our original suggestion back to them | 20:16 |
ayoung | jamielennox, cmurphy lbragstad can we put oslo-context to rest? https://review.openstack.org/#/c/523650/ | 20:16 |
lbragstad | for example - http://cdn.pasteraw.com/htn79m729bk6wuikvgkwaj96phsozsi | 20:16 |
cmurphy | i'm not seeing whether they objected to that idea | 20:18 |
lbragstad | i don't see KwozyMan or jose-castro-leon online either | 20:19 |
cmurphy | ayoung: looking again | 20:19 |
ayoung | cmurphy, thanks. Much smaller now | 20:20 |
lbragstad | ayoung: once we get a new version of oslo.policy - https://review.openstack.org/#/q/status:open+project:openstack/keystone+branch:master+topic:add-scope-types should start passing | 20:20 |
*** efried_cya_wed has quit IRC | 20:20 | |
ayoung | lbragstad, cool. THe policy patch got approved, right? | 20:20 |
lbragstad | oslo.policy patch? | 20:21 |
lbragstad | yes? | 20:21 |
gagehugo | yeah I like the token provider extension | 20:21 |
lbragstad | ayoung: waiting on https://review.openstack.org/#/c/525623/1 | 20:21 |
lbragstad | cmurphy: gagehugo we should update the bug report then | 20:21 |
ayoung | lbragstad, of course.... | 20:21 |
gagehugo | ok | 20:21 |
ayoung | lbragstad, needs one more +2? | 20:21 |
lbragstad | from requirements, yes | 20:22 |
lbragstad | i think so | 20:22 |
ayoung | lbragstad, I only saw a requirements-stable-core group there, but it is roughly the same set of reviewers | 20:24 |
ayoung | dims, can you +2 A that one | 20:25 |
ayoung | https://review.openstack.org/#/c/525623/1 | 20:25 |
lbragstad | ayoung: i think dims is at kubecon this week | 20:25 |
lbragstad | participating in container-things | 20:25 |
ayoung | almost certainly | 20:25 |
lbragstad | ayoung: you weighed in on https://bugs.launchpad.net/keystone/+bug/1642988 once | 20:26 |
openstack | Launchpad bug 1642988 in OpenStack Identity (keystone) "Optionally encode project IDs in fernet tokens" [Wishlist,Triaged] - Assigned to Jose Castro Leon (jose-castro-leon) | 20:26 |
lbragstad | think that is too specific to carry upstream? | 20:26 |
*** efried_cya_wed has joined #openstack-keystone | 20:30 | |
*** edmondsw has quit IRC | 20:30 | |
lbragstad | cmurphy: wxy fwiw - i'm going to try and spend the last hour of office hours proposing the rest of https://review.openstack.org/#/c/524657/ | 20:34 |
lbragstad | oh - actually, it looks like wxy propose a version of that specification with limit IDs | 20:35 |
*** gyee has joined #openstack-keystone | 20:44 | |
*** panbalag has joined #openstack-keystone | 20:52 | |
*** panbalag has quit IRC | 20:54 | |
lbragstad | kmalloc: cmurphy wxy question on unified limits | 20:55 |
lbragstad | we have registered limits and project limits | 20:55 |
kmalloc | yeah | 20:56 |
lbragstad | thoughts on splitting them into their own specs? | 20:56 |
cmurphy | why? | 20:56 |
lbragstad | well - registered limits needs to be done first regardless | 20:56 |
kmalloc | why? | 20:56 |
kmalloc | what cmurphy said | 20:56 |
kmalloc | :P | 20:56 |
lbragstad | because project limits always act as overrides? | 20:56 |
cmurphy | do registered limits have any value if there isn't also project limits? | 20:57 |
lbragstad | kinda the other way around IMO | 20:57 |
kmalloc | i don't think anyone would use registered limits without project limits | 20:57 |
lbragstad | you can't use project limits with a registered limit, at least that how i understand things | 20:58 |
ayoung | cmurphy, TYVM | 20:58 |
cmurphy | ayoung: YW | 20:58 |
cmurphy | lbragstad: you need to have a registered limit in order for the project limit to override it | 20:58 |
cmurphy | project limits are invalid if there's nothing registered | 20:59 |
lbragstad | oh - sorry, s/with/without/ | 20:59 |
lbragstad | yes | 20:59 |
cmurphy | oh yes | 20:59 |
lbragstad | i'm bad at typing lately | 20:59 |
cmurphy | lol | 20:59 |
cmurphy | registered limits have to be done first yes but they're not useful without project limits | 20:59 |
lbragstad | yeah | 21:00 |
lbragstad | ok - so another question | 21:00 |
lbragstad | project limits will always require a project | 21:00 |
kmalloc | yes | 21:00 |
lbragstad | do we put the project in the request body or the path? | 21:00 |
kmalloc | eh, either/or | 21:01 |
lbragstad | POST /limits/{project_id} or just POST /limits with the project id in the body | 21:01 |
cmurphy | i think POST /limits is more rest-y? | 21:01 |
* cmurphy looks up guidelines | 21:01 | |
kmalloc | cmurphy: ++ | 21:01 |
kmalloc | the get /limits/{project_id} is the reference to the id | 21:02 |
lbragstad | ok - that current proposal im reviewing has POST /limits with option project id in the request body | 21:02 |
kmalloc | yeah | 21:02 |
kmalloc | that sounds fin | 21:02 |
kmalloc | e | 21:02 |
cmurphy | yeah that makes sense to me | 21:02 |
lbragstad | ok | 21:02 |
lbragstad | cool | 21:02 |
lbragstad | actually, the current proposal uses the project id from the request context... | 21:04 |
lbragstad | which makes sense, too | 21:04 |
kmalloc | that is also fine | 21:06 |
kmalloc | but the post with the body makes more sense | 21:06 |
kmalloc | since switching scope ... may be painful | 21:06 |
kmalloc | especially with say... admin RBAC future looking | 21:06 |
cmurphy | yeah i feel like it should be explicit in the body | 21:07 |
cmurphy | anyone want to push https://review.openstack.org/#/c/524882 through (or know why that happens?) | 21:09 |
*** nicolasbock has quit IRC | 21:10 | |
lbragstad | cmurphy: done - and that also beats me | 21:16 |
lbragstad | seams like a system level thing? | 21:16 |
lbragstad | https://review.openstack.org/#/c/523524/ will close a bug | 21:16 |
cmurphy | yeah it's something to do with the os, i wasn't able to reproduce it but it was seen in ci and by mordred | 21:17 |
cmurphy | lbragstad: you keep linking that and i always click on it and then i'm sad i can't help :'( | 21:18 |
lbragstad | lol | 21:18 |
lbragstad | regardless - thanks for the review cmurphy | 21:18 |
cmurphy | :) | 21:18 |
lbragstad | it's the thought that counts, amiright?! | 21:18 |
cmurphy | lol | 21:19 |
cmurphy | lbragstad: re service_type/service_id see my and wxy's comments on https://review.openstack.org/#/c/455709/13/specs/keystone/queens/limits-api.rst | 21:20 |
cmurphy | service_type isn't guaranteed unique | 21:20 |
mordred | cmurphy: what did I do? | 21:22 |
cmurphy | mordred: the +00:00 thing | 21:23 |
lbragstad | ?! | 21:23 |
mordred | oh - that | 21:23 |
mordred | JEEZ don't even get me started on that | 21:24 |
lbragstad | i thought services had type built into the unique constraint | 21:25 |
cmurphy | i don't think so http://git.openstack.org/cgit/openstack/keystone/tree/keystone/common/sql/migrate_repo/versions/067_kilo.py#n115 | 21:26 |
lbragstad | bah | 21:26 |
lbragstad | that kinda sucks | 21:26 |
cmurphy | http://paste.openstack.org/show/628219/ | 21:27 |
*** spilla has quit IRC | 21:28 | |
* lbragstad sigh | 21:28 | |
*** spilla has joined #openstack-keystone | 21:28 | |
*** edmondsw has joined #openstack-keystone | 21:30 | |
lbragstad | it looks like i can abandon my follow on to that spec then | 21:32 |
mordred | cmurphy, lbragstad: I know of at least one existing deployment with non-unique service types - as much as it drives me completely bonkers | 21:33 |
*** spilla has quit IRC | 21:33 | |
mordred | I'd, of course, argue that it SHOULD be unique | 21:33 |
mordred | and that people with non-unique service types are making the world a terrible place | 21:33 |
* lbragstad waits for the "this is why we can't have nice things" rant | 21:34 | |
cmurphy | lbragstad: yeah i thnk all work can be done in the original spec | 21:34 |
lbragstad | sweet | 21:34 |
mordred | lbragstad: I figure everyone knows that rant by now ... | 21:35 |
*** itlinux has quit IRC | 21:39 | |
*** itlinux has joined #openstack-keystone | 21:44 | |
*** jrist has joined #openstack-keystone | 21:46 | |
kmalloc | mordred: so.. i agree | 21:51 |
kmalloc | unfortunately... | 21:51 |
kmalloc | mordred: it's an API break if we change that >.< | 21:51 |
kmalloc | mordred: i don't think many people would disagree about service-types need to be unique | 21:52 |
lbragstad | #endmeeting | 22:00 |
*** openstack changes topic to "Queens release schedule: https://releases.openstack.org/queens/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/5F0h9Hoe/keystone" | 22:00 | |
openstack | Meeting ended Tue Dec 5 22:00:03 2017 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 22:00 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/keystone_office_hours/2017/keystone_office_hours.2017-12-05-19.00.html | 22:00 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/keystone_office_hours/2017/keystone_office_hours.2017-12-05-19.00.txt | 22:00 |
openstack | Log: http://eavesdrop.openstack.org/meetings/keystone_office_hours/2017/keystone_office_hours.2017-12-05-19.00.log.html | 22:00 |
*** threestrands has joined #openstack-keystone | 22:05 | |
*** threestrands has quit IRC | 22:05 | |
*** threestrands has joined #openstack-keystone | 22:05 | |
*** rcernin has joined #openstack-keystone | 22:05 | |
*** dave-mcc_ is now known as dave-mccowan | 22:15 | |
*** raildo has quit IRC | 22:21 | |
openstackgerrit | Merged openstack/python-keystoneclient master: Handle UTC+00:00 in datetime strings https://review.openstack.org/524882 | 22:29 |
*** McClymontS has joined #openstack-keystone | 22:32 | |
*** McClymontS has quit IRC | 22:33 | |
openstackgerrit | Merged openstack/python-keystoneclient master: Avoid tox_install.sh for constraints support https://review.openstack.org/524828 | 22:54 |
*** jmlowe has joined #openstack-keystone | 23:09 | |
*** spilla has joined #openstack-keystone | 23:23 | |
*** dave-mccowan has quit IRC | 23:23 | |
*** spilla has quit IRC | 23:24 | |
*** edmondsw has quit IRC | 23:34 | |
*** edmondsw has joined #openstack-keystone | 23:35 | |
*** panbalag has joined #openstack-keystone | 23:37 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: WIP - Make fernet config and utils generic https://review.openstack.org/523200 | 23:38 |
*** panbalag has left #openstack-keystone | 23:38 | |
*** panbalag has joined #openstack-keystone | 23:54 | |
*** panbalag has quit IRC | 23:56 | |
*** edmondsw has quit IRC | 23:57 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!