*** markvoelker has joined #openstack-keystone | 00:20 | |
*** markvoelker has quit IRC | 00:24 | |
*** itlinux has joined #openstack-keystone | 00:41 | |
*** harlowja has joined #openstack-keystone | 00:54 | |
*** edmondsw has joined #openstack-keystone | 01:20 | |
*** markvoelker has joined #openstack-keystone | 01:21 | |
*** AlexeyAbashkin has joined #openstack-keystone | 01:22 | |
*** edmondsw has quit IRC | 01:25 | |
*** markvoelker has quit IRC | 01:25 | |
*** AlexeyAbashkin has quit IRC | 01:27 | |
*** daidv-xmas has quit IRC | 01:27 | |
*** daidv_ has joined #openstack-keystone | 01:27 | |
*** daidv has joined #openstack-keystone | 01:27 | |
openstackgerrit | Merged openstack/keystone master: Remove rolling_upgrade_password_hash_compat https://review.openstack.org/527337 | 01:43 |
---|---|---|
*** zhurong has joined #openstack-keystone | 01:43 | |
*** kmalloc has quit IRC | 01:53 | |
*** kmalloc has joined #openstack-keystone | 01:53 | |
*** betherly has quit IRC | 01:53 | |
*** betherly has joined #openstack-keystone | 01:55 | |
*** namnh has joined #openstack-keystone | 02:01 | |
*** daidv_ has quit IRC | 02:03 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Fix list users by name https://review.openstack.org/529914 | 02:09 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Remove duplicated release note https://review.openstack.org/529900 | 02:11 |
lbragstad | wxy: o/ | 02:15 |
wxy | lbragstad: hi | 02:15 |
lbragstad | wxy: how goes it? | 02:15 |
wxy | lbragstad: fine. New year will coming. We'll three-day holiday in China. | 02:16 |
lbragstad | wxy: you'll be out early next week? | 02:17 |
wxy | I'll back on Tuesday next week. | 02:18 |
lbragstad | cool - same here | 02:18 |
lbragstad | i'll get to the unified limit reviews again tomorrow or over the weekend | 02:18 |
wxy | lbragstad: That' cool. I just want to make the patches better today. Such as some points on "project_id", "region_id is None". | 02:20 |
lbragstad | good deal | 02:20 |
lbragstad | they are looking good | 02:20 |
lbragstad | certainly ready for more eyes | 02:20 |
*** markvoelker has joined #openstack-keystone | 02:21 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Fix list users by name https://review.openstack.org/529914 | 02:26 |
*** markvoelker has quit IRC | 02:26 | |
*** harlowja has quit IRC | 02:41 | |
lbragstad | wxy: is there anything i can help without side of reviews? | 02:41 |
*** zhurong has quit IRC | 02:50 | |
wxy | lbragstad: everything goes well now. :) Thanks for your help. | 02:52 |
lbragstad | no problem! | 02:55 |
*** edmondsw has joined #openstack-keystone | 03:08 | |
*** edmondsw has quit IRC | 03:13 | |
*** harlowja has joined #openstack-keystone | 03:33 | |
*** gagehugo has quit IRC | 03:52 | |
*** gagehugo has joined #openstack-keystone | 03:53 | |
*** kmalloc has quit IRC | 03:53 | |
*** gagehugo has quit IRC | 04:08 | |
*** markvoelker has joined #openstack-keystone | 04:23 | |
*** harlowja has quit IRC | 04:24 | |
*** markvoelker has quit IRC | 04:27 | |
*** Suramya has joined #openstack-keystone | 04:40 | |
*** AlexeyAbashkin has joined #openstack-keystone | 04:46 | |
*** AlexeyAbashkin has quit IRC | 04:50 | |
*** edmondsw has joined #openstack-keystone | 04:56 | |
*** edmondsw has quit IRC | 05:01 | |
*** itlinux has quit IRC | 05:15 | |
*** zhurong has joined #openstack-keystone | 05:21 | |
*** markvoelker has joined #openstack-keystone | 05:23 | |
*** markvoelker has quit IRC | 05:28 | |
openstackgerrit | Suramya proposed openstack/keystone master: Re-organize api-ref: v3 inherit.inc https://review.openstack.org/529823 | 05:32 |
*** BenderRodriguez has joined #openstack-keystone | 05:54 | |
*** markvoelker has joined #openstack-keystone | 06:24 | |
*** markvoelker has quit IRC | 06:29 | |
*** edmondsw has joined #openstack-keystone | 06:44 | |
*** edmondsw has quit IRC | 06:49 | |
*** zhurong has quit IRC | 07:03 | |
*** magicboiz has joined #openstack-keystone | 07:24 | |
*** markvoelker has joined #openstack-keystone | 07:25 | |
*** magicboiz has quit IRC | 07:29 | |
*** markvoelker has quit IRC | 07:29 | |
*** magicboiz has joined #openstack-keystone | 07:41 | |
*** zhurong has joined #openstack-keystone | 08:16 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: WIP Add application credentials db migration https://review.openstack.org/524927 | 08:17 |
*** AlexeyAbashkin has joined #openstack-keystone | 08:23 | |
*** edmondsw has joined #openstack-keystone | 08:32 | |
*** edmondsw has quit IRC | 08:37 | |
*** gagehugo has joined #openstack-keystone | 08:59 | |
*** zhurong has quit IRC | 09:14 | |
*** markvoelker has joined #openstack-keystone | 09:26 | |
*** markvoelker has quit IRC | 09:31 | |
*** daidv has quit IRC | 10:09 | |
*** namnh has quit IRC | 10:14 | |
*** edmondsw has joined #openstack-keystone | 10:20 | |
*** edmondsw has quit IRC | 10:25 | |
*** aojea has joined #openstack-keystone | 10:30 | |
*** aojea has quit IRC | 11:10 | |
*** markvoelker has joined #openstack-keystone | 11:27 | |
*** AlexeyAbashkin has quit IRC | 11:28 | |
*** AlexeyAbashkin has joined #openstack-keystone | 11:29 | |
*** markvoelker has quit IRC | 11:32 | |
openstackgerrit | Suramya proposed openstack/keystone master: Reorganize api-ref: v3 os-pki https://review.openstack.org/530459 | 11:44 |
*** aojea has joined #openstack-keystone | 11:49 | |
*** annp has quit IRC | 12:03 | |
*** edmondsw has joined #openstack-keystone | 12:08 | |
*** edmondsw has quit IRC | 12:13 | |
*** raildo has joined #openstack-keystone | 12:31 | |
*** aojea has quit IRC | 12:39 | |
*** nicolasbock has joined #openstack-keystone | 13:02 | |
openstackgerrit | Suramya proposed openstack/keystone master: Reorganize api-ref: v3 policies https://review.openstack.org/530466 | 13:06 |
*** jistr has quit IRC | 13:14 | |
*** jistr has joined #openstack-keystone | 13:16 | |
*** magicboiz has quit IRC | 13:25 | |
*** markvoelker has joined #openstack-keystone | 13:28 | |
*** markvoelker has quit IRC | 13:32 | |
openstackgerrit | Suramya proposed openstack/keystone master: Reorganize api-ref: v3 regions-v3 https://review.openstack.org/530469 | 13:55 |
*** edmondsw has joined #openstack-keystone | 13:57 | |
*** edmondsw has quit IRC | 14:01 | |
lbragstad | Suramya: o/ | 14:35 |
lbragstad | Suramya: thanks for the patches on the api-ref | 14:36 |
Suramya | lbragstad o/ working on more :D | 14:37 |
Suramya | lbragstad: but why is the build for api-ref failing for many in zuul ? | 14:40 |
lbragstad | Suramya: there was something wrong with the job | 14:48 |
lbragstad | infra merged a patch yesterday that fixed it | 14:48 |
lbragstad | https://review.openstack.org/#/c/530087/ | 14:49 |
lbragstad | since that patch merged, you shouldn't be seeing the api ref job failing as much | 14:50 |
lbragstad | cmurphy: i was tinkering around with system-scope and horizon last night | 14:52 |
lbragstad | cmurphy: what are your opinions on having a GET /v3/auth/projects API for system scope? | 14:52 |
Suramya | lbragstad: yes,thats great. | 14:55 |
lbragstad | Suramya: i think two patches are failing because we're changing the section header, but not updating index.rst | 15:00 |
lbragstad | i left a comment here https://review.openstack.org/#/c/530459/1/api-ref/source/v3/os-pki.inc trying to show what i mean | 15:00 |
Suramya | lbragstad: oh yes I get it. Sending the patches for it soon. | 15:01 |
lbragstad | otherwise i think those patches look great | 15:02 |
cmurphy | lbragstad: what would that look like? | 15:03 |
cmurphy | like GET /v3/auth/system -> true/false maybe? | 15:03 |
lbragstad | cmurphy: yeah - maybe similar to how we relaying system scope in authentication responses? | 15:04 |
lbragstad | {"system": {"all": true}} | 15:04 |
lbragstad | so that we can build it out later if needed | 15:04 |
lbragstad | but i hit an issue yesterday working with horizon | 15:04 |
cmurphy | i think having that makes sense | 15:05 |
lbragstad | which uses the GET /auth/projects and GET /auth/domains APIs heavily | 15:05 |
cmurphy | yeah it does | 15:05 |
lbragstad | but GET /v3/role_assignments requires elevated privileges | 15:05 |
lbragstad | i should be able to wip that up today | 15:09 |
cmurphy | cool | 15:10 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Reorganize api-ref: v3-ext federation projects-domains https://review.openstack.org/507008 | 15:15 |
*** markvoelker has joined #openstack-keystone | 15:29 | |
*** markvoelker has quit IRC | 15:33 | |
*** edmondsw has joined #openstack-keystone | 15:45 | |
*** edmondsw has quit IRC | 15:49 | |
*** AlexeyAbashkin has quit IRC | 15:58 | |
*** aojea has joined #openstack-keystone | 16:18 | |
*** aojea_ has joined #openstack-keystone | 16:23 | |
*** aojea has quit IRC | 16:26 | |
*** aojea has joined #openstack-keystone | 16:28 | |
*** aojea_ has quit IRC | 16:31 | |
*** aojea_ has joined #openstack-keystone | 16:33 | |
*** aojea_ has quit IRC | 16:35 | |
*** aojea has quit IRC | 16:36 | |
*** itlinux_ has joined #openstack-keystone | 16:42 | |
*** jmlowe has quit IRC | 16:50 | |
*** kmalloc has joined #openstack-keystone | 16:50 | |
*** AlexeyAbashkin has joined #openstack-keystone | 17:27 | |
*** markvoelker has joined #openstack-keystone | 17:30 | |
*** AlexeyAbashkin has quit IRC | 17:31 | |
*** edmondsw has joined #openstack-keystone | 17:33 | |
*** markvoelker has quit IRC | 17:34 | |
*** edmondsw has quit IRC | 17:38 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement GET /v3/auth/system https://review.openstack.org/530490 | 17:38 |
itlinux_ | hello all .. I am getting this error any tips on how to fix it .."There is either no auth token in the request or the certificate issuer is not trusted. No auth context will be set. fill_context /usr/lib/python2.7/site-packages/keystone/middleware/auth.py:203" | 17:54 |
itlinux_ | thanks | 17:54 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement GET /v3/auth/system https://review.openstack.org/530490 | 17:55 |
lbragstad | itlinux_: i don't think that it an error - it's just a strangely worded log message | 17:55 |
itlinux_ | ok thanks | 17:55 |
lbragstad | itlinux_: https://review.openstack.org/#/c/514810/ | 17:56 |
lbragstad | we've removedit | 17:56 |
itlinux_ | ok.. | 17:56 |
itlinux_ | super.. | 17:57 |
lbragstad | so - you shouldn't be seeing that anymore once you start working with queens | 17:57 |
lbragstad | (it caused more confusion than clarity) | 17:57 |
itlinux_ | ok.. thanks much appreciated.. | 17:57 |
lbragstad | anytime | 17:57 |
itlinux_ | one more question since you are so nice and I wish you the best New Year.. btw.. | 17:58 |
itlinux_ | adding a new domain.. | 17:59 |
itlinux_ | openstack domain create domain.com | 17:59 |
itlinux_ | I have the file already in teh /etc/keystone/domains | 17:59 |
itlinux_ | this is a second domain the first worsk.. | 17:59 |
itlinux_ | works | 17:59 |
itlinux_ | so I copy and changed the info to point to the new one but when I do openstack user list --domain domain.com i do not see any resuts.. | 18:00 |
itlinux_ | ok I got it working ciao | 18:05 |
lbragstad | sorry - just saw this, what was the problem? | 18:20 |
*** itlinux_ has quit IRC | 18:36 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: WIP Add application credentials db migration https://review.openstack.org/524927 | 18:58 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: WIP Add application credentials driver https://review.openstack.org/524928 | 18:58 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: WIP Add Application Credentials manager https://review.openstack.org/524747 | 18:58 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: WIP Add Application Credentials controller https://review.openstack.org/524423 | 18:58 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: WIP Add application credential auth plugin https://review.openstack.org/525346 | 18:58 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Deprecate [trust]/enabled option https://review.openstack.org/530501 | 18:58 |
kmalloc | cmurphy: re "get_role_by_name", suggest always returning a list instead of 200/3xx | 19:09 |
kmalloc | cmurphy: +1 for it as is, will upgrade to +2 if lbragstad says he really wants this version. | 19:10 |
*** edmondsw has joined #openstack-keystone | 19:21 | |
*** edmondsw has quit IRC | 19:25 | |
cmurphy | kmalloc: why a list? | 19:26 |
kmalloc | cmurphy: because roles are non-unique by name | 19:26 |
kmalloc | so, for consistency, i would always return a list of matching roles | 19:27 |
cmurphy | kmalloc: well then i would have to change the name to get_roles_ | 19:27 |
kmalloc | fair enough | 19:28 |
cmurphy | if a list is wanted then list_roles should be used | 19:28 |
kmalloc | i don't see this as valuable as implemented | 19:28 |
kmalloc | when you get a 3xx in many cases suported by the APIs and design | 19:28 |
kmalloc | this feels like a case where you're mostly expecting a list_roles?name=XXXX | 19:29 |
kmalloc | simply because the 3xx case is likely very common | 19:29 |
kmalloc | agian, i +1'd and will upgrade to +2 with not-too-much-convincing | 19:29 |
cmurphy | kmalloc: it's not raising 3xx it's raising 4xx ? | 19:29 |
kmalloc | ambiguous is 3xx, no? | 19:30 |
cmurphy | it's bad request | 19:30 |
kmalloc | .AmbiguityError is 400? | 19:30 |
*** markvoelker has joined #openstack-keystone | 19:31 | |
kmalloc | ah it's validation | 19:31 |
kmalloc | then i am more strongly -1 on this | 19:31 |
kmalloc | vs +1. | 19:31 |
kmalloc | the request shouldn't be bad because the store has multiple matches | 19:31 |
kmalloc | there is nothing the user can do to correct the request to a 200 in that case | 19:32 |
kmalloc | that feels like the wrong reason for a 400 error. | 19:33 |
cmurphy | okay, well the background is i wanted to copy and paste this chunk from the trust controller https://review.openstack.org/#/c/530267/5/keystone/trust/controllers.py into the application credential controller and i wanted to avoid repeating myself | 19:33 |
cmurphy | so maybe there's a better way to do that? put it in a utils module? | 19:33 |
kmalloc | ah. | 19:33 |
kmalloc | hm. | 19:33 |
kmalloc | wait, this isn't going to be a public API? | 19:34 |
* kmalloc might be mis-reading this. | 19:34 | |
kmalloc | i was thinking about this from a REST fronting it as well | 19:34 |
cmurphy | it's not its own roles api but it would be sort of a sub-function of the app cred api | 19:34 |
kmalloc | i would rename the function to "get_unique_role_by_name" | 19:34 |
cmurphy | since you specify roles in your create request | 19:34 |
*** Suramya has quit IRC | 19:34 | |
cmurphy | okay | 19:34 |
kmalloc | and i think it solves my concern | 19:35 |
cmurphy | yay | 19:35 |
cmurphy | that's easy | 19:35 |
kmalloc | it clearly shows by name that it's not meant to handle the multiple-matching-roles case | 19:35 |
*** markvoelker has quit IRC | 19:35 | |
kmalloc | and then +2 from me :) easy. | 19:35 |
kmalloc | it could also be a private function if it is only ever called by _normalize. | 19:36 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Implement get_role_by_name https://review.openstack.org/530267 | 19:37 |
cmurphy | i could make it private | 19:38 |
*** raildo has quit IRC | 19:38 | |
*** itlinux has joined #openstack-keystone | 19:38 | |
kmalloc | wouldn't change my score. was just a side thought | 19:38 |
kmalloc | cmurphy: +2, and will +A as soon as zuul checks in | 19:39 |
cmurphy | i don't really feel like it's a private thing, it's being called by other modules in keystone using the provider_api thing | 19:39 |
kmalloc | since the change is not material (code/functionality) from when lbragstad +2'd | 19:39 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Implement get_unique_role_by_name https://review.openstack.org/530267 | 19:39 |
cmurphy | fixed the commit msg ^ | 19:39 |
kmalloc | re-+2'd | 19:40 |
kmalloc | ;) | 19:40 |
cmurphy | ty | 19:40 |
kmalloc | feel free to self +A if I am not around (I'll comment on the patch to this effect as well). | 19:40 |
*** jmlowe has joined #openstack-keystone | 19:45 | |
*** jmlowe has quit IRC | 19:49 | |
openstackgerrit | Lance Bragstad proposed openstack/python-keystoneclient master: Add system role functionality https://review.openstack.org/524415 | 19:59 |
*** markvoelker has joined #openstack-keystone | 20:31 | |
*** markvoelker has quit IRC | 20:36 | |
cmurphy | kmalloc: lbragstad is DateTimeInt the way forward for all our datetime columns now? should the trust table be using it? | 20:53 |
lbragstad | probably - i think the last time we talked about it DateTImeInt was the best we could do to avoid the timestamp issues with mysql | 20:54 |
lbragstad | afaict we were going to gradually move the rest of the datetime instances we use in keystone to it | 20:54 |
cmurphy | okay i guess i need to do that for trusts first so i can use it in app creds | 20:56 |
lbragstad | does anyone else ever get to the point where their brain starts falling out of their ears when hacking on a devstack? | 21:07 |
*** edmondsw has joined #openstack-keystone | 21:09 | |
*** jmlowe has joined #openstack-keystone | 21:11 | |
lbragstad | i think i've finally got a devstack environment installed locally with all the necessary bits to demo system scope | 21:11 |
cmurphy | \o/ | 21:12 |
lbragstad | i have about 40 patches installed locally, it's a total franken-stack | 21:13 |
cmurphy | ha | 21:13 |
*** edmondsw has quit IRC | 21:13 | |
lbragstad | lol just a mess | 21:13 |
*** jmlowe has quit IRC | 21:16 | |
*** jmlowe has joined #openstack-keystone | 21:37 | |
*** AlexeyAbashkin has joined #openstack-keystone | 22:21 | |
*** AlexeyAbashkin has quit IRC | 22:25 | |
*** nicolasbock has quit IRC | 22:26 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Implement get_unique_role_by_name https://review.openstack.org/530267 | 22:31 |
*** jose-phillips has quit IRC | 22:34 | |
*** nicolasbock has joined #openstack-keystone | 22:39 | |
*** edmondsw has joined #openstack-keystone | 22:57 | |
*** edmondsw has quit IRC | 23:02 | |
*** markvoelker has joined #openstack-keystone | 23:34 | |
*** markvoelker has quit IRC | 23:39 | |
*** Faster-Fanboi has joined #openstack-keystone | 23:58 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!