*** edmondsw has joined #openstack-keystone | 00:08 | |
*** edmondsw has quit IRC | 00:13 | |
*** tlam_ has quit IRC | 00:18 | |
*** threestrands has joined #openstack-keystone | 00:26 | |
*** threestrands has quit IRC | 00:26 | |
*** threestrands has joined #openstack-keystone | 00:26 | |
*** dave-mccowan has quit IRC | 00:35 | |
openstackgerrit | Merged openstack/keystone master: Improve exception logging with 500 response https://review.openstack.org/526939 | 00:53 |
---|---|---|
*** itlinux has joined #openstack-keystone | 00:59 | |
openstackgerrit | Merged openstack/keystone master: Expose a bug when authenticating for a trust-scoped token https://review.openstack.org/522356 | 01:03 |
*** dave-mccowan has joined #openstack-keystone | 01:12 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Expose a bug when authorize request token https://review.openstack.org/526295 | 01:18 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Add schema check for authorize request token https://review.openstack.org/526296 | 01:18 |
*** asettle has quit IRC | 01:19 | |
openstackgerrit | Merged openstack/keystone master: Add schema check for OS-TRUST:trust authentication https://review.openstack.org/522107 | 01:20 |
openstackgerrit | Merged openstack/keystone master: Update keystone testing documentation https://review.openstack.org/523524 | 01:20 |
*** asettle has joined #openstack-keystone | 01:22 | |
*** annp has joined #openstack-keystone | 01:23 | |
*** aselius has quit IRC | 01:32 | |
*** andreykurilin has quit IRC | 01:43 | |
*** andreykurilin has joined #openstack-keystone | 01:46 | |
*** r-daneel has quit IRC | 02:20 | |
*** catintheroof has joined #openstack-keystone | 02:38 | |
*** catintheroof has quit IRC | 02:53 | |
*** gmann has quit IRC | 02:55 | |
*** threestrands has quit IRC | 03:03 | |
*** threestrands has joined #openstack-keystone | 03:04 | |
*** threestrands has quit IRC | 03:04 | |
*** threestrands has joined #openstack-keystone | 03:04 | |
*** threestrands has quit IRC | 03:05 | |
*** threestrands has joined #openstack-keystone | 03:06 | |
*** threestrands has quit IRC | 03:06 | |
*** threestrands has joined #openstack-keystone | 03:06 | |
*** threestrands has quit IRC | 03:07 | |
*** threestrands has joined #openstack-keystone | 03:07 | |
*** dave-mccowan has quit IRC | 03:13 | |
*** edmondsw has joined #openstack-keystone | 03:44 | |
*** edmondsw has quit IRC | 03:49 | |
*** gyee has quit IRC | 03:51 | |
*** threestrands_ has joined #openstack-keystone | 03:57 | |
*** threestrands has quit IRC | 03:57 | |
*** threestrands_ has quit IRC | 03:58 | |
*** zhurong has joined #openstack-keystone | 03:58 | |
*** threestrands_ has joined #openstack-keystone | 03:59 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Refactor project tags encoding https://review.openstack.org/529179 | 04:04 |
*** namnh has joined #openstack-keystone | 04:14 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Add new tables for unified limits https://review.openstack.org/523041 | 04:19 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: [WIP]Add db operation for unified limit https://review.openstack.org/524082 | 04:19 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: [WIP]Add limit provider https://review.openstack.org/524109 | 04:19 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: [WIP]Expose unified limit APIs https://review.openstack.org/524110 | 04:19 |
openstackgerrit | wangqiang-bj proposed openstack/keystone master: remove "Relationship links" in api-doc https://review.openstack.org/529220 | 04:36 |
*** ianw is now known as ianw_pto | 04:57 | |
*** links has joined #openstack-keystone | 04:57 | |
samueldmq | \q lbragstad | 04:59 |
*** namnh has quit IRC | 05:19 | |
*** edmondsw has joined #openstack-keystone | 05:32 | |
*** edmondsw has quit IRC | 05:37 | |
*** AlexeyAbashkin has joined #openstack-keystone | 05:37 | |
*** AlexeyAbashkin has quit IRC | 05:42 | |
*** d0ugal has quit IRC | 06:17 | |
*** d0ugal has joined #openstack-keystone | 06:23 | |
*** threestrands_ has quit IRC | 06:57 | |
openstackgerrit | Merged openstack/keystone master: Updated from global requirements https://review.openstack.org/528866 | 07:03 |
*** rcernin has quit IRC | 07:08 | |
*** edmondsw has joined #openstack-keystone | 07:21 | |
*** edmondsw has quit IRC | 07:25 | |
openstackgerrit | ZhanHan proposed openstack/python-keystoneclient master: Modify a spelling error https://review.openstack.org/529250 | 07:33 |
*** sapd has quit IRC | 07:40 | |
*** sapd has joined #openstack-keystone | 07:41 | |
*** samuelbartel has joined #openstack-keystone | 07:55 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Add new tables for unified limits https://review.openstack.org/523041 | 07:56 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: [WIP]Add db operation for unified limit https://review.openstack.org/524082 | 07:56 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: [WIP]Add limit provider https://review.openstack.org/524109 | 07:56 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: [WIP]Expose unified limit APIs https://review.openstack.org/524110 | 07:56 |
*** zhurong has quit IRC | 08:17 | |
*** AlexeyAbashkin has joined #openstack-keystone | 08:19 | |
*** hoonetorg has quit IRC | 08:19 | |
*** apuimedo has joined #openstack-keystone | 08:23 | |
*** apuimedo has quit IRC | 08:24 | |
*** celebdor has joined #openstack-keystone | 08:24 | |
*** sapd has quit IRC | 08:33 | |
*** hoonetorg has joined #openstack-keystone | 08:33 | |
*** sapd has joined #openstack-keystone | 08:35 | |
*** kmalloc has quit IRC | 08:41 | |
*** magicboiz has quit IRC | 08:48 | |
*** sbezverk has quit IRC | 09:02 | |
*** magicboiz has joined #openstack-keystone | 09:04 | |
*** magicboiz has quit IRC | 09:15 | |
*** magicboiz has joined #openstack-keystone | 09:15 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: [WIP]Add db operation for unified limit https://review.openstack.org/524082 | 09:33 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: [WIP]Add limit provider https://review.openstack.org/524109 | 09:33 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: [WIP]Expose unified limit APIs https://review.openstack.org/524110 | 09:33 |
openstackgerrit | Merged openstack/python-keystoneclient master: Create doc/requirements.txt https://review.openstack.org/528964 | 10:10 |
*** Neptu_ is now known as Neptu | 10:23 | |
*** ruan__he has quit IRC | 10:40 | |
*** annp has quit IRC | 10:53 | |
*** edmondsw has joined #openstack-keystone | 10:57 | |
*** edmondsw has quit IRC | 11:01 | |
*** AlexeyAbashkin has quit IRC | 11:08 | |
*** szaher has quit IRC | 11:36 | |
*** AlexeyAbashkin has joined #openstack-keystone | 11:52 | |
*** panbalag has quit IRC | 11:53 | |
*** slunkad has quit IRC | 11:59 | |
*** slunkad has joined #openstack-keystone | 12:02 | |
*** bhagyashris has joined #openstack-keystone | 12:10 | |
*** dave-mccowan has joined #openstack-keystone | 12:13 | |
bhagyashris | mordred: Hi, Want to discuss about the patch https://review.openstack.org/#/c/505764/4 .Just check the zuul result and report and it's showing 'keystoneauth1.tests.unit.test_session.SessionAuthTests.test_split_loggers' is failing | 12:15 |
bhagyashris | mordred: I have applied the patch on my machine and checked and seems that randomly 2 to 4 unit test cases are failing | 12:15 |
bhagyashris | mordred: any idea why this happening | 12:16 |
*** raildo has joined #openstack-keystone | 12:29 | |
*** edmondsw has joined #openstack-keystone | 12:45 | |
*** edmondsw has quit IRC | 12:49 | |
*** openstackgerrit has quit IRC | 13:13 | |
-openstackstatus- NOTICE: gerrit is being restarted due to extreme slowness | 13:14 | |
*** rmascena has joined #openstack-keystone | 13:35 | |
*** raildo has quit IRC | 13:37 | |
*** panbalag has joined #openstack-keystone | 13:43 | |
*** panbalag has left #openstack-keystone | 13:43 | |
*** catintheroof has joined #openstack-keystone | 13:52 | |
*** catintheroof has quit IRC | 14:02 | |
*** catintheroof has joined #openstack-keystone | 14:04 | |
*** catinthe_ has joined #openstack-keystone | 14:22 | |
lbragstad | samueldmq: o/ | 14:24 |
*** catintheroof has quit IRC | 14:26 | |
*** jmlowe has quit IRC | 14:28 | |
*** tlam_ has joined #openstack-keystone | 14:29 | |
ayoung | lbragstad, I just pulled the trigger on the first of the system scoped patches...and just realized I want to make a change in direction...let me run it past you and you can talk me down off the ledge | 14:30 |
ayoung | lbragstad, I really don't like that we are getting a new table for the dumb reason of the enum values...what if we instead ported the old table over to a new table as well, and put everything in there: | 14:31 |
ayoung | system role assignments as well as the existing role types? | 14:31 |
ayoung | it would mean that your system role table would need to grow an assignment type value. | 14:32 |
ayoung | for a zero uptime upgrade, it would also mean that, during the migration stage, we would...read from both tables while migrating? | 14:33 |
lbragstad | that would have to be in place of `type`? | 14:33 |
ayoung | yeah...not an enum anymore either | 14:33 |
lbragstad | you'd have to lock the assignment table | 14:33 |
lbragstad | https://review.openstack.org/#/c/507993/5/keystone/common/sql/expand_repo/versions/031_expand_system_assignment_table.py | 14:33 |
ayoung | right. | 14:33 |
lbragstad | or write a trigger to port things back and forth | 14:34 |
ayoung | lbragstad, it seems silly to have a new table just cuz we have a new type. We should fix the type thing as part of this, and get a unified table. Am I correct that the only reason we have a new table is cuz of the locked enum, or is there some better reason for it? | 14:34 |
lbragstad | the enum bit was part of it | 14:35 |
lbragstad | but we started thinking about what happens if system breaks out into its own hierarchy | 14:35 |
lbragstad | and wondered if any ramifications of that might justify having system role assignments as their own table? | 14:36 |
ayoung | hierarchy? As in separate from the project hierarchy? | 14:36 |
lbragstad | yes | 14:36 |
lbragstad | this is *way* future looking | 14:36 |
lbragstad | but something that's been kicked around | 14:37 |
ayoung | I get it...it is based on the idea that this is really manageing control of the service catalog, but we don't want to get too close there, either | 14:37 |
lbragstad | well - if you have a bunch of services that make up a 'system' | 14:37 |
ayoung | I 've long thought that everything in Keystone should be namespaced inside some project or domain... | 14:37 |
ayoung | right | 14:38 |
ayoung | and regions | 14:38 |
ayoung | and all that stuff | 14:38 |
lbragstad | then you start getting into granting roles on the services/regions instead of the system as a whole | 14:38 |
*** aojea has joined #openstack-keystone | 14:38 | |
lbragstad | that's seemed useful and powerful when we were discussing it in person | 14:38 |
lbragstad | but certainly something that doesn't need to be in the initial implementation | 14:38 |
lbragstad | IMO | 14:38 |
lbragstad | but we made it a requirement to build for that case so that we could do that in the future if we wantedt o | 14:39 |
lbragstad | another thing i noticed when dealing with a single assignment table for system + project + domain roles assignments, | 14:39 |
lbragstad | is that I think a lot of the logic for the existing assignment backend needs to be refactored into the manager layer | 14:40 |
lbragstad | the existing assignment driver does a lot of things and performs a lot of business logic | 14:40 |
ayoung | lbragstad, so, I think I want to let you drive one with this implementation for this release as designed, and we will do a refactoring reduction next release | 14:42 |
ayoung | I +2Aed https://review.openstack.org/#/c/507993/ and lets drive on with those | 14:42 |
lbragstad | ayoung: you sure? | 14:42 |
ayoung | lbragstad, yeah, because I think what you are going to learn as you implement will aid us greatly | 14:43 |
lbragstad | in what we need to refactor? | 14:43 |
ayoung | and maybe we'll decide to do a V4 of the API with simpler naming. I think we're collecting enough info along those lines I can see it happening in a year or two | 14:43 |
ayoung | I suspect that we'll be able to reunify the assignment tables next release, even with a hierarchy identified. I think the structure we have will support it, but the naming is too disjointed | 14:45 |
lbragstad | that's the important bit, the big thing is being able to unify later if we need to | 14:45 |
ayoung | I like the Kubernetes use of the term namespace. I'd like for us to collapse Project and domain and region into namespace, drop the term domain in favor of IdP for managing users and groups | 14:46 |
lbragstad | yeah | 14:46 |
ayoung | make projects hierarchical, including a way to provide hierarchical URLs | 14:46 |
ayoung | and get it so that a named resource, like a vm or a volume from cinder can be created and owned by one namespace, but manipulated in another. THinking along the lines of INODE vs DENTRY in filesystems | 14:47 |
lbragstad | that'd be interesting | 14:50 |
ayoung | lbragstad, BTW, tjhe second +2 on your table patch came from henry. | 14:50 |
lbragstad | i saw | 14:50 |
ayoung | Was very happy to see that. | 14:50 |
lbragstad | i pestered him for some reviews yesterday :) | 14:50 |
ayoung | :) | 14:51 |
lbragstad | he had a comment on an existing patch set that had been addressed, but i wanted to have him remove his -1 rather than wipe it | 14:51 |
ayoung | lbragstad, BTW, what do you want to do about the policy on the Systems roles? | 14:51 |
ayoung | I really don't like the extension of admin there. | 14:51 |
lbragstad | how do you mean? | 14:51 |
ayoung | lbragstad, its an extension of ADMI_REQUIRED with no scope. Now that we have system roles, lets use them | 14:52 |
*** aojea has quit IRC | 14:52 | |
lbragstad | the assignment of system roles are broken out into their policies | 14:52 |
ayoung | add in a rule that says admin+system | 14:52 |
ayoung | https://review.openstack.org/#/c/514471/6/keystone/common/policies/grant.py | 14:52 |
ayoung | check_str=base.RULE_ADMIN_REQUIRED, | 14:52 |
ayoung | lets add a new rule first | 14:53 |
lbragstad | i don't think we need to because of https://review.openstack.org/#/c/514471/6/keystone/common/policies/grant.py@104 | 14:53 |
ayoung | check_str=base.RULE_SYSTEM_ADMIN_REQUIRED, | 14:53 |
lbragstad | and we're leveraging scope_types | 14:53 |
ayoung | scope_types=['system'], | 14:53 |
* ayoung feels silly | 14:53 | |
lbragstad | yep | 14:53 |
ayoung | lbragstad, that makes me very happy | 14:54 |
lbragstad | oslo.policy has all the plumbing to handle that enforcement for us (and all other projects) | 14:54 |
lbragstad | but i still added a configuration option to toggle the hard enforcement behavior | 14:54 |
lbragstad | and you actually see a *ton* of logs in our tests | 14:55 |
ayoung | lbragstad, what about a keystone-manage extension to convert is_admin_project role assignments to system roles? | 14:55 |
lbragstad | that would work | 14:55 |
ayoung | I'll try to hack that out. I'm going to rebase that patch and +2 them from there on up | 14:55 |
lbragstad | i was thinking that keystone-manage should setup the admin user and give them the admin role on a project and the system | 14:56 |
lbragstad | an operator should be able to use that account to do anything and everything from a keystone perspective | 14:56 |
lbragstad | then, once they audit their users and give them proper roles on projects or the system depending on the case, they can flip the bit | 14:57 |
ayoung | lbragstad, BTW, is there a common Capabilities doc that I can read up on? | 14:58 |
lbragstad | we have a ton of tests that emit logs because our testing infrastructure hasn't accounted for system-scope yet | 14:58 |
lbragstad | like a capabilities API doc? | 14:58 |
ayoung | I want to revise the RBAC in middleware approach based on the common approach to capabilities. I assume someone is driving that somewhere? | 14:58 |
lbragstad | several projects have specifications that detail the work | 14:59 |
lbragstad | but i think cinder is the only one who merged it | 14:59 |
lbragstad | i was actually going to take a stab at writing one for keystone soon | 14:59 |
lbragstad | but - just not enough hours in the day | 15:00 |
*** catinthe_ has quit IRC | 15:02 | |
*** catintheroof has joined #openstack-keystone | 15:03 | |
lbragstad | once we get all the scope_types stuff into keystone https://review.openstack.org/#/q/status:open+project:openstack/keystone+branch:master+topic:add-scope-types | 15:03 |
lbragstad | we should be able to use the Enforcer object to generate a list of things you can do based on a token | 15:03 |
lbragstad | which would be good functionality to have in oslo.policy | 15:04 |
lbragstad | if other projects want to reuse it | 15:04 |
ayoung | lbragstad, I'll look at the cinder one | 15:05 |
ayoung | https://review.openstack.org/#/q/status:merged+project:openstack/cinder-specs+branch:master+topic:bp/discovering-system-capabilities | 15:06 |
lbragstad | yeah - that looks right | 15:06 |
lbragstad | i don't think it's all completely implemented | 15:06 |
ayoung | ``GET /v3.x/{tenant id}/capabilities`` | 15:07 |
ayoung | lbragstad, OK...here is a thought: | 15:07 |
lbragstad | because we have policy issues that need to be worked out yet | 15:07 |
ayoung | from /v3 we add a series of links to /users /groups etc | 15:07 |
*** openstackgerrit has joined #openstack-keystone | 15:07 | |
openstackgerrit | Mehdi Abaakouk (sileht) proposed openstack/keystonemiddleware master: cfg.CONF must not be used directly https://review.openstack.org/526631 | 15:07 |
ayoung | and from those top level links, we add links to the actual APIs for manipulating them. We also add in a link for the capabilities | 15:07 |
*** catintheroof has quit IRC | 15:08 | |
ayoung | I've wanted those intermediate links for a long time...along with the ability to pass Accepts Content-Type of HTML so a user can probe the Keystone server from a browser | 15:08 |
ayoung | heh policy issue as in "what role do you need in order to query the capabilies" policy? | 15:10 |
lbragstad | huh... | 15:12 |
lbragstad | that'd be interesting | 15:12 |
lbragstad | so i could query the capabilities api and get back a list of links | 15:12 |
lbragstad | with things i can do | 15:12 |
lbragstad | i could see that being really cool | 15:14 |
lbragstad | clients could use that to expose functionality | 15:15 |
lbragstad | in a predetermined way | 15:15 |
lbragstad | same with horizon | 15:15 |
knikolla | o/ | 15:23 |
lbragstad | knikolla: o/ | 15:28 |
cmurphy | easy reviews to get the rest of our docs jobs fixed https://review.openstack.org/#/c/529164/ https://review.openstack.org/#/c/529158/ :) | 15:30 |
lbragstad | cmurphy: thanks for respinning those | 15:32 |
lbragstad | +2 | 15:32 |
gagehugo | o/ | 15:42 |
*** pcaruana has joined #openstack-keystone | 15:51 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add a new table for system role assignments https://review.openstack.org/507993 | 15:57 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement backend logic for system roles https://review.openstack.org/507994 | 15:57 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement manager logic for user+system roles https://review.openstack.org/512468 | 15:57 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement manager logic for group+system roles https://review.openstack.org/512641 | 15:57 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add user system grant policies https://review.openstack.org/514471 | 15:57 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add group system grant policies https://review.openstack.org/514725 | 15:57 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add configuration option for enforcing system-scope https://review.openstack.org/528847 | 15:57 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement controller logic for system user assignments https://review.openstack.org/515215 | 15:57 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement controller logic for system group assignments https://review.openstack.org/524017 | 15:57 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add system role assignment documentation https://review.openstack.org/524307 | 15:57 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add ability to list all system role assignments https://review.openstack.org/524407 | 15:57 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Ensure building scope is mutually exclusive https://review.openstack.org/498091 | 15:57 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove private methods for v2.0 and v3 tokens https://review.openstack.org/525329 | 15:58 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Teach TokenFormatter how to handle system scope https://review.openstack.org/525330 | 15:58 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system-scope in the token provider API https://review.openstack.org/525360 | 15:58 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Introduce assertions for system-scoped token testing https://review.openstack.org/528037 | 15:58 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system-scoped tokens https://review.openstack.org/525687 | 15:58 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add release note for system-scope https://review.openstack.org/528039 | 15:58 |
lbragstad | ayoung: sorry - i had to add a new test case ^ | 15:58 |
ayoung | lbragstad, should I push the DB change through again? | 15:59 |
lbragstad | ayoung: thanks | 15:59 |
ayoung | cmurphy, +@A on both those. One question, the test build-openstack-sphinx-docs should exercise those, right? | 16:01 |
lbragstad | i'm wondering what people think of https://review.openstack.org/#/c/528847/2 | 16:02 |
lbragstad | does that configuration option need to be in oslo.policy? | 16:02 |
cmurphy | ayoung: yes, and you'll notice on other ksm changes it's been failing the last couple of days https://review.openstack.org/#/c/526631/ | 16:02 |
lbragstad | instead of in *each* project? | 16:02 |
ayoung | lbragstad, it would certainly be better if it were commonized | 16:04 |
lbragstad | mmmk | 16:04 |
lbragstad | i can whip that up | 16:04 |
ayoung | could we get it into oslo-context? | 16:04 |
lbragstad | mmm | 16:05 |
ayoung | I guess not... | 16:05 |
ayoung | needs to be in the enforcement, not just the data | 16:05 |
lbragstad | would there be an advantage to it being in context? | 16:05 |
ayoung | just that context is supposed to be the common OpenStack specific stuff, whereas policy thus far has been a rules engine, | 16:05 |
ayoung | with the exception of roles | 16:06 |
ayoung | but I think scope requires a change to policy, too, so yeah, needs to be in oslo policy | 16:06 |
lbragstad | if we have a toggle for enforcing scope, we certainly need it at evaluation time | 16:06 |
lbragstad | which is what pushed me to think it should go into oslo.policy | 16:06 |
*** celebdor has quit IRC | 16:15 | |
*** edmondsw has joined #openstack-keystone | 16:21 | |
openstackgerrit | Merged openstack/keystone master: Deprecate member_role_id and member_role_name https://review.openstack.org/522461 | 16:25 |
*** edmondsw has quit IRC | 16:26 | |
*** AlexeyAbashkin has quit IRC | 16:37 | |
*** links has quit IRC | 16:44 | |
*** aselius has joined #openstack-keystone | 16:56 | |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Add configuration option for enforcing scope https://review.openstack.org/529372 | 16:59 |
lbragstad | ayoung: dims i'm likely going to need some guidance there ^ | 17:00 |
ayoung | lbragstad, my guess is we would have to test that manually for a functional test. Some devstack setup with it enabled. | 17:01 |
*** gyee has joined #openstack-keystone | 17:01 | |
*** samuelbartel has quit IRC | 17:01 | |
lbragstad | ayoung: yeah - the problem is that i introduced a kwarg to do this before, but it doesn't make sense to have a kwarg and a configuration option | 17:02 |
lbragstad | (especially since they both defaulted to different values) | 17:03 |
lbragstad | so i'm wondering how to go about fixing that mistake | 17:03 |
lbragstad | but the devstack thing is on my list for later this week or the weekend | 17:03 |
lbragstad | I'd like do stand up one with scoping enabled and another without it enabled and using project assignments | 17:03 |
lbragstad | and see where things tip over, and possible record a demo | 17:04 |
lbragstad | possibly* | 17:04 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Add configuration option for enforcing scope https://review.openstack.org/529372 | 17:05 |
ayoung | remove the kwarg? | 17:10 |
ayoung | I doubt anyone is using it yet | 17:10 |
lbragstad | yeah... i doubt it | 17:13 |
lbragstad | but i'm just not sure on the process | 17:13 |
lbragstad | or if it is acceptable to do that | 17:13 |
lbragstad | i left a comment on the review asking for feedback | 17:14 |
ayoung | ++ | 17:18 |
*** d0ugal has quit IRC | 17:23 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Break TestMappingPurge into multiple tests https://review.openstack.org/471138 | 17:23 |
*** sbezverk has joined #openstack-keystone | 17:25 | |
openstackgerrit | Merged openstack/keystonemiddleware master: Fix docs builds https://review.openstack.org/529158 | 17:35 |
*** d0ugal has joined #openstack-keystone | 17:35 | |
*** magicboiz has quit IRC | 17:45 | |
openstackgerrit | Merged openstack/keystoneauth master: Fix docs builds https://review.openstack.org/529164 | 17:46 |
*** sapd_ has joined #openstack-keystone | 18:01 | |
*** sapd has quit IRC | 18:01 | |
*** panbalag has joined #openstack-keystone | 18:06 | |
*** AlexeyAbashkin has joined #openstack-keystone | 18:08 | |
*** edmondsw has joined #openstack-keystone | 18:09 | |
*** AlexeyAbashkin has quit IRC | 18:13 | |
*** edmondsw has quit IRC | 18:13 | |
*** panbalag has quit IRC | 18:14 | |
*** panbalag has joined #openstack-keystone | 18:30 | |
*** panbalag has left #openstack-keystone | 18:40 | |
*** spilla has joined #openstack-keystone | 18:58 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: WIP Add application credentials db migration https://review.openstack.org/524927 | 19:16 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: WIP Add application credentials driver https://review.openstack.org/524928 | 19:16 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: WIP Add Application Credentials manager https://review.openstack.org/524747 | 19:16 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: WIP Add Application Credentials controller https://review.openstack.org/524423 | 19:16 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: WIP Add application credential auth plugin https://review.openstack.org/525346 | 19:16 |
*** pcaruana has quit IRC | 19:29 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add configuration option for enforcing system-scope https://review.openstack.org/528847 | 19:34 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement controller logic for system user assignments https://review.openstack.org/515215 | 19:37 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement controller logic for system group assignments https://review.openstack.org/524017 | 19:37 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add system role assignment documentation https://review.openstack.org/524307 | 19:37 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add ability to list all system role assignments https://review.openstack.org/524407 | 19:37 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Ensure building scope is mutually exclusive https://review.openstack.org/498091 | 19:37 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove private methods for v2.0 and v3 tokens https://review.openstack.org/525329 | 19:37 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Teach TokenFormatter how to handle system scope https://review.openstack.org/525330 | 19:37 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system-scope in the token provider API https://review.openstack.org/525360 | 19:37 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Introduce assertions for system-scoped token testing https://review.openstack.org/528037 | 19:37 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system-scoped tokens https://review.openstack.org/525687 | 19:37 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add release note for system-scope https://review.openstack.org/528039 | 19:37 |
*** pcaruana has joined #openstack-keystone | 19:48 | |
*** pcaruana has quit IRC | 19:54 | |
openstackgerrit | Gage Hugo proposed openstack/python-keystoneclient master: Add project tags to keystoneclient https://review.openstack.org/481223 | 19:54 |
gagehugo | ^ lbragstad fixed the 'u's showing up I think | 19:54 |
*** edmondsw has joined #openstack-keystone | 19:57 | |
lbragstad | sweet | 19:58 |
lbragstad | i should be able to test that out - i have a bunch of patches installed locally for keystone, ksa, keystoneclient, and openstackclient working on the system scope changes | 19:58 |
lbragstad | but i should be able to review after that | 19:58 |
*** edmondsw has quit IRC | 20:02 | |
gagehugo | sounds good | 20:04 |
*** pcaruana has joined #openstack-keystone | 20:06 | |
*** rmascena__ has joined #openstack-keystone | 20:08 | |
*** rmascena has quit IRC | 20:10 | |
*** rmascena__ is now known as raildo | 20:11 | |
*** pcaruana has quit IRC | 20:13 | |
NobodyCam | Good Morning Keystone Folks. I have a question: could someone point me any old docs on how to decrypt the pkiz tokens? | 20:23 |
*** links has joined #openstack-keystone | 20:41 | |
*** links has quit IRC | 20:47 | |
*** tlam_ has quit IRC | 20:53 | |
*** catintheroof has joined #openstack-keystone | 20:54 | |
*** tlam_ has joined #openstack-keystone | 20:54 | |
*** raildo has quit IRC | 21:01 | |
*** jmlowe has joined #openstack-keystone | 21:04 | |
openstackgerrit | Merged openstack/keystonemiddleware master: cfg.CONF must not be used directly https://review.openstack.org/526631 | 21:05 |
*** aojea has joined #openstack-keystone | 21:21 | |
*** catinthe_ has joined #openstack-keystone | 21:23 | |
*** catintheroof has quit IRC | 21:25 | |
ayoung | cmurphy, care to start kicking the lbragstad commits on System Role on through, since henrynash seems to be on holiday? I'll trade by reviewing anything you got that is priority | 21:29 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: WIP Add Application Credentials manager https://review.openstack.org/524747 | 21:29 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: WIP Add Application Credentials controller https://review.openstack.org/524423 | 21:29 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: WIP Add application credential auth plugin https://review.openstack.org/525346 | 21:29 |
lbragstad | ^ priority :) | 21:29 |
cmurphy | WIP :P | 21:30 |
cmurphy | although early feedback on the auth plugin wouldn't be a bad idea | 21:30 |
cmurphy | ayoung: yes I'll start looking at it | 21:30 |
*** catinthe_ has quit IRC | 21:35 | |
*** catintheroof has joined #openstack-keystone | 21:35 | |
*** threestrands_ has joined #openstack-keystone | 21:36 | |
*** catintheroof has quit IRC | 21:40 | |
cmurphy | lbragstad: I didn't realize https://review.openstack.org/#/c/498091/ was part of the giant stack, i'm pretty sure you could pull it out and we could merge it independently | 21:50 |
cmurphy | and then the stack would be smaller | 21:50 |
lbragstad | yeah - i kept it in there since i figured a subsequent patch would cause a merge conflict | 21:52 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Ensure building scope is mutually exclusive https://review.openstack.org/498091 | 21:53 |
*** tlam_ has quit IRC | 21:53 | |
*** tlam_ has joined #openstack-keystone | 21:53 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove private methods for v2.0 and v3 tokens https://review.openstack.org/525329 | 21:53 |
lbragstad | ok - pulled those two out of the stack | 21:53 |
cmurphy | +A +A | 21:55 |
cmurphy | two less things for me to do tomorrow | 21:55 |
lbragstad | :) | 22:00 |
lbragstad | i'll just wait for those to merge before i rebase the entire stack | 22:01 |
*** aojea has quit IRC | 22:04 | |
*** spilla has quit IRC | 22:18 | |
*** david-lyle has quit IRC | 22:24 | |
*** rcernin has joined #openstack-keystone | 22:32 | |
*** aojea has joined #openstack-keystone | 22:33 | |
*** jappleii__ has joined #openstack-keystone | 22:35 | |
*** threestrands_ has quit IRC | 22:36 | |
*** david-lyle has joined #openstack-keystone | 22:56 | |
*** aojea has quit IRC | 23:06 | |
*** dave-mccowan has quit IRC | 23:17 | |
*** edmondsw has joined #openstack-keystone | 23:33 | |
*** edmondsw has quit IRC | 23:38 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!