*** bigdogstl has quit IRC | 00:06 | |
*** superdan is now known as dansmith | 00:11 | |
*** bigdogstl has joined #openstack-keystone | 00:18 | |
*** markvoelker has joined #openstack-keystone | 00:20 | |
*** edmondsw has joined #openstack-keystone | 00:24 | |
*** markvoelker has quit IRC | 00:24 | |
*** edmondsw has quit IRC | 00:28 | |
*** Dinesh_Bhor has joined #openstack-keystone | 00:42 | |
*** Dinesh_Bhor has quit IRC | 00:44 | |
*** Dinesh_Bhor has joined #openstack-keystone | 00:44 | |
*** Dinesh_Bhor has quit IRC | 00:45 | |
*** Dinesh_Bhor has joined #openstack-keystone | 00:57 | |
*** daidv has joined #openstack-keystone | 01:27 | |
*** Dinesh_Bhor has quit IRC | 01:28 | |
*** Dinesh_Bhor has joined #openstack-keystone | 01:30 | |
*** Dinesh_Bhor has quit IRC | 01:34 | |
*** Dinesh_Bhor has joined #openstack-keystone | 01:40 | |
*** threestrands_ has joined #openstack-keystone | 01:40 | |
*** threestrands has quit IRC | 01:43 | |
*** Dinesh_Bhor has quit IRC | 01:52 | |
*** Dinesh_Bhor has joined #openstack-keystone | 01:52 | |
*** namnh has joined #openstack-keystone | 01:56 | |
*** Dinesh_Bhor has quit IRC | 02:03 | |
*** itlinux has joined #openstack-keystone | 02:07 | |
*** Dinesh_Bhor has joined #openstack-keystone | 02:14 | |
*** Dinesh_Bhor has quit IRC | 02:23 | |
*** zhurong has joined #openstack-keystone | 02:27 | |
*** itlinux has quit IRC | 02:34 | |
*** Dinesh_Bhor has joined #openstack-keystone | 02:36 | |
*** bigdogstl has quit IRC | 02:40 | |
*** itlinux has joined #openstack-keystone | 02:48 | |
openstackgerrit | lei zhang proposed openstack/keystone master: Remove the deprecated "giturl" option https://review.openstack.org/533466 | 02:51 |
---|---|---|
*** markvoelker has joined #openstack-keystone | 02:51 | |
*** annp has joined #openstack-keystone | 02:54 | |
*** Dinesh_Bhor has quit IRC | 03:04 | |
*** bigdogstl has joined #openstack-keystone | 03:06 | |
*** jappleii__ has joined #openstack-keystone | 03:12 | |
*** jappleii__ has quit IRC | 03:13 | |
*** jappleii__ has joined #openstack-keystone | 03:13 | |
*** threestrands_ has quit IRC | 03:15 | |
*** bigdogstl has quit IRC | 03:18 | |
*** markvoelker has quit IRC | 03:25 | |
*** bigdogstl has joined #openstack-keystone | 03:27 | |
*** bigdogstl has quit IRC | 03:32 | |
*** namnh has quit IRC | 03:34 | |
*** namnh has joined #openstack-keystone | 03:35 | |
openstackgerrit | lei zhang proposed openstack/keystone master: Remove the deprecated "giturl" option https://review.openstack.org/533466 | 03:43 |
*** bigdogstl has joined #openstack-keystone | 03:55 | |
*** edmondsw has joined #openstack-keystone | 04:00 | |
*** bigdogstl has quit IRC | 04:03 | |
*** Dinesh_Bhor has joined #openstack-keystone | 04:04 | |
*** edmondsw has quit IRC | 04:05 | |
*** bigdogstl has joined #openstack-keystone | 04:08 | |
*** Dinesh_Bhor has quit IRC | 04:13 | |
*** itlinux has quit IRC | 04:17 | |
*** bigdogstl has quit IRC | 04:18 | |
*** Dinesh_Bhor has joined #openstack-keystone | 04:36 | |
*** zhurong has quit IRC | 04:39 | |
-openstackstatus- NOTICE: The logs.openstack.org filesystem has been restored to full health. We are attempting to keep logs uploaded between the prior alert and this one, however if your job logs are missing please issue a recheck. | 04:48 | |
*** ChanServ changes topic to "The logs.openstack.org filesystem has been restored to full health. We are attempting to keep logs uploaded between the prior alert and this one, however if your job logs are missing please issue a recheck." | 04:48 | |
*** bigdogstl has joined #openstack-keystone | 04:51 | |
*** ChanServ changes topic to "Queens release schedule: https://releases.openstack.org/queens/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/5F0h9Hoe/keystone" | 04:53 | |
*** Dinesh_Bhor has quit IRC | 04:59 | |
*** Dinesh_Bhor has joined #openstack-keystone | 05:00 | |
*** bigdogstl has quit IRC | 05:10 | |
*** links has joined #openstack-keystone | 05:11 | |
*** bigdogstl has joined #openstack-keystone | 05:17 | |
*** markvoelker has joined #openstack-keystone | 05:22 | |
*** pcaruana has joined #openstack-keystone | 05:23 | |
*** zhurong has joined #openstack-keystone | 05:24 | |
*** bigdogstl has quit IRC | 05:26 | |
*** pcaruana has quit IRC | 05:32 | |
*** edmondsw has joined #openstack-keystone | 05:48 | |
*** edmondsw has quit IRC | 05:53 | |
*** markvoelker has quit IRC | 05:55 | |
*** bigdogstl has joined #openstack-keystone | 05:56 | |
*** bigdogstl has quit IRC | 06:00 | |
*** Dinesh_Bhor has quit IRC | 06:07 | |
*** bigdogstl has joined #openstack-keystone | 06:12 | |
*** Dinesh_Bhor has joined #openstack-keystone | 06:12 | |
*** bigdogstl has quit IRC | 06:22 | |
*** abhishek has joined #openstack-keystone | 06:24 | |
*** abhi89 has quit IRC | 06:28 | |
*** bigdogstl has joined #openstack-keystone | 06:34 | |
*** bigdogstl has quit IRC | 06:39 | |
*** jappleii__ has quit IRC | 07:02 | |
*** bigdogstl has joined #openstack-keystone | 07:03 | |
*** bigdogstl has quit IRC | 07:07 | |
*** sapd_ has quit IRC | 07:16 | |
*** r-daneel has quit IRC | 07:17 | |
*** r-daneel has joined #openstack-keystone | 07:17 | |
*** sapd_ has joined #openstack-keystone | 07:20 | |
*** Dinesh_Bhor has quit IRC | 07:31 | |
*** Dinesh_Bhor has joined #openstack-keystone | 07:33 | |
*** Dinesh_Bhor has quit IRC | 07:33 | |
*** edmondsw has joined #openstack-keystone | 07:36 | |
*** bigdogstl has joined #openstack-keystone | 07:39 | |
*** edmondsw has quit IRC | 07:41 | |
*** bigdogstl has quit IRC | 07:48 | |
*** markvoelker has joined #openstack-keystone | 07:53 | |
*** AlexeyAbashkin has joined #openstack-keystone | 07:54 | |
*** hoonetorg has quit IRC | 07:58 | |
*** rcernin has quit IRC | 07:59 | |
openstackgerrit | Shuo Liu proposed openstack/keystone master: adjust response code order in 'regions-v3.inc' https://review.openstack.org/533542 | 08:01 |
*** hoonetorg has joined #openstack-keystone | 08:11 | |
*** bigdogstl has joined #openstack-keystone | 08:17 | |
*** zhurong has quit IRC | 08:18 | |
*** zhurong has joined #openstack-keystone | 08:21 | |
openstackgerrit | Dinesh Bhor proposed openstack/keystoneauth master: Split request logging into four different loggers https://review.openstack.org/505764 | 08:21 |
*** bigdogstl has quit IRC | 08:26 | |
*** markvoelker has quit IRC | 08:26 | |
openstackgerrit | Shuo Liu proposed openstack/keystone master: adjust response code order in 'authenticate-v3.inc' https://review.openstack.org/533559 | 08:27 |
*** aojea has joined #openstack-keystone | 09:11 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Add limit provider https://review.openstack.org/524109 | 09:17 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Implement policies for limits https://review.openstack.org/530143 | 09:17 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Expose unified limit APIs https://review.openstack.org/524110 | 09:17 |
*** bigdogstl has joined #openstack-keystone | 09:22 | |
openstackgerrit | Shuo Liu proposed openstack/keystone master: Fix wrong url in config-options.rst https://review.openstack.org/533579 | 09:24 |
*** edmondsw has joined #openstack-keystone | 09:25 | |
*** edmondsw has quit IRC | 09:29 | |
*** bigdogstl has quit IRC | 09:29 | |
openstackgerrit | Shuo Liu proposed openstack/keystone master: adjust response code order in 'regions-v3.inc' https://review.openstack.org/533542 | 09:46 |
*** zhurong has quit IRC | 09:46 | |
*** jaosorior has joined #openstack-keystone | 10:03 | |
*** daidv has quit IRC | 10:06 | |
*** bigdogstl has joined #openstack-keystone | 10:08 | |
*** namnh has quit IRC | 10:11 | |
*** mvk has joined #openstack-keystone | 10:13 | |
*** bigdogstl has quit IRC | 10:19 | |
*** markvoelker has joined #openstack-keystone | 10:24 | |
*** sambetts|afk is now known as sambetts | 10:26 | |
*** aojea has quit IRC | 10:39 | |
*** aojea has joined #openstack-keystone | 10:44 | |
*** aojea_ has joined #openstack-keystone | 10:44 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Allow overriding app cred restrictions https://review.openstack.org/533431 | 10:46 |
*** aojea has quit IRC | 10:49 | |
*** annp has quit IRC | 10:51 | |
*** markvoelker has quit IRC | 10:57 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add caching options for application credentials https://review.openstack.org/533609 | 10:57 |
*** bigdogstl has joined #openstack-keystone | 11:03 | |
*** bigdogstl has quit IRC | 11:07 | |
*** bigdogstl has joined #openstack-keystone | 11:12 | |
*** edmondsw has joined #openstack-keystone | 11:13 | |
*** edmondsw has quit IRC | 11:17 | |
*** bigdogstl has quit IRC | 11:17 | |
*** bigdogstl has joined #openstack-keystone | 11:33 | |
*** bigdogstl has quit IRC | 11:41 | |
*** bigdogstl has joined #openstack-keystone | 11:42 | |
*** nicolasbock has joined #openstack-keystone | 11:44 | |
*** pcaruana has joined #openstack-keystone | 11:44 | |
*** bigdogstl has quit IRC | 11:46 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Expose unified limit APIs https://review.openstack.org/524110 | 12:03 |
*** bigdogstl has joined #openstack-keystone | 12:06 | |
*** bigdogstl has quit IRC | 12:11 | |
*** tesseract has joined #openstack-keystone | 12:15 | |
*** mvk has quit IRC | 12:16 | |
*** raildo has joined #openstack-keystone | 12:20 | |
*** bigdogstl has joined #openstack-keystone | 12:33 | |
*** bigdogstl has quit IRC | 12:40 | |
*** bigdogstl has joined #openstack-keystone | 12:41 | |
*** r-daneel_ has joined #openstack-keystone | 12:42 | |
*** r-daneel has quit IRC | 12:43 | |
*** r-daneel_ is now known as r-daneel | 12:43 | |
*** bigdogstl has quit IRC | 12:46 | |
*** bigdogstl has joined #openstack-keystone | 12:50 | |
*** andreaf has quit IRC | 12:53 | |
*** andreaf has joined #openstack-keystone | 12:53 | |
*** markvoelker has joined #openstack-keystone | 12:54 | |
*** edmondsw has joined #openstack-keystone | 12:55 | |
*** bigdogstl has quit IRC | 13:01 | |
*** dikonoor has joined #openstack-keystone | 13:03 | |
*** raildo has quit IRC | 13:04 | |
*** mvk has joined #openstack-keystone | 13:13 | |
*** bigdogstl has joined #openstack-keystone | 13:13 | |
*** bigdogstl has quit IRC | 13:17 | |
*** openstackgerrit has quit IRC | 13:18 | |
*** raildo has joined #openstack-keystone | 13:20 | |
*** r-daneel has quit IRC | 13:21 | |
*** bigdogstl has joined #openstack-keystone | 13:27 | |
*** raildo has quit IRC | 13:28 | |
*** markvoelker has quit IRC | 13:28 | |
*** bigdogstl has quit IRC | 13:32 | |
*** r-daneel has joined #openstack-keystone | 13:38 | |
*** raildo has joined #openstack-keystone | 13:43 | |
*** bigdogstl has joined #openstack-keystone | 13:44 | |
*** bigdogstl has quit IRC | 13:49 | |
*** bigdogstl has joined #openstack-keystone | 14:05 | |
*** bigdogstl has quit IRC | 14:15 | |
*** r-daneel has quit IRC | 14:23 | |
*** openstackgerrit has joined #openstack-keystone | 14:49 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add Application Credentials controller https://review.openstack.org/524423 | 14:49 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add application credential auth plugin https://review.openstack.org/525346 | 14:49 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Allow overriding app cred restrictions https://review.openstack.org/533431 | 14:49 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add caching options for application credentials https://review.openstack.org/533609 | 14:49 |
mordred | cmurphy: I have done a TERRIBLE job at helping with Application Credentials :( | 14:54 |
*** tbh_ has joined #openstack-keystone | 14:55 | |
*** spilla has joined #openstack-keystone | 14:57 | |
cmurphy | mordred: haha it's okay :) | 14:57 |
mordred | cmurphy: does dinesh bhor hang out in channel with a name I can't figure out? | 14:59 |
cmurphy | mordred: I think they are Dinesh_Bhor so they must not be online | 15:01 |
mordred | cmurphy: kk. cool. they're helping with a patch I wrote and I wanted to say thanks :) | 15:02 |
cmurphy | mordred: do you need https://review.openstack.org/#/c/500385/ for anything or could you abandon? | 15:03 |
mordred | cmurphy: abandoned | 15:06 |
cmurphy | tyty | 15:07 |
*** sxc731 has joined #openstack-keystone | 15:10 | |
*** afred312 has quit IRC | 15:11 | |
*** afred312 has joined #openstack-keystone | 15:11 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone-tempest-plugin master: Use openstackdocstheme for docs and release notes https://review.openstack.org/531097 | 15:11 |
*** afred312 has quit IRC | 15:12 | |
*** r-daneel has joined #openstack-keystone | 15:17 | |
*** links has quit IRC | 15:20 | |
*** bigdogstl has joined #openstack-keystone | 15:24 | |
*** markvoelker has joined #openstack-keystone | 15:25 | |
*** phalmos has joined #openstack-keystone | 15:32 | |
*** r-daneel has quit IRC | 15:34 | |
*** r-daneel has joined #openstack-keystone | 15:35 | |
lbragstad | sxc731: without the caching issue, are you seeing the performance you were hoping for? | 15:35 |
sxc731 | lbragstad: it's *markedly* better, thank you! | 15:35 |
lbragstad | you don't have to wait 10 seconds for a page to load? :) | 15:36 |
sxc731 | lbragstad: but I've been wondering about smth else we discussed last wek, namely the potential for individual OS components to do their own validation through keysteonmiddleware... | 15:36 |
lbragstad | yeah | 15:36 |
lbragstad | you can have keystonemiddleware cache token responses | 15:37 |
lbragstad | (avoiding the roundtrip validation back to keystone) | 15:37 |
sxc731 | lbragstad: so just looking at Horizon for a moment, it doesn't even seem to have a dependency on oslo.cache, unless I'm missing smth?? | 15:37 |
lbragstad | the dependency would be from ksm -> oslo.cache | 15:37 |
sxc731 | to be honest, I've only looked at my deployed instance | 15:37 |
lbragstad | https://github.com/openstack/keystonemiddleware/blob/master/requirements.txt#L6 | 15:38 |
sxc731 | Sure, but if I look at an OSA-deployed Horizon, I find ksm but no oslo.cache... | 15:38 |
sxc731 | That seems suspicious, no? | 15:38 |
lbragstad | if you have keystonemiddleware configured to cache tokens, it should be using oslo.cache to do that | 15:39 |
lbragstad | just like you would for caching things in keyston | 15:39 |
lbragstad | keystone* | 15:39 |
lbragstad | so when the middleware is run in front of the service, you should see some performance improvements by caching before you even have to ask keystone for anything | 15:40 |
sxc731 | Hmmm... also, assuming there are components that leverage this ability to hit the ache in process using ksm (which definitely seems a neat idea!) I would epxect they'd need the same config workaround you cooked on Fri, right? | 15:40 |
lbragstad | i would assume so, since the issue appears to be in oslo.cache/pymemcached | 15:41 |
sxc731 | K | 15:41 |
*** bigdogstl has quit IRC | 15:41 | |
sxc731 | So I grepped a little around the OSA roles and couldn't find any role (beside KS itself of course) that references either 'keystone_memcached_servers' (workaround) or 'keystone_cache_backend_argument' (broken version) | 15:43 |
lbragstad | i need to fix up that patch, it's failing a test i assume | 15:44 |
sxc731 | lbragstad: sure, sorry for moving on to the next set of tricky q's so quickly! | 15:49 |
sxc731 | So I just looked again; looks like OSA's os_nova and os_swift roles do have some config that assigns "memcache_servers". So they would both benefit from ksm in-bound caching validation but presumably the potential for other components (particularly Horizon) to do the same is quite significant? | 15:50 |
sxc731 | Suppose that's more a q for the OSA folks again... but still, assuming I'm right, this is another rather baffling discovery!? | 15:51 |
odyssey4me | It is very possible that the configs we're using are a bit dated. A lot of that stuff is not well understood by most consumers, so I know we'd welcome someone who's been paying attention and figuring out the right things. :) | 15:52 |
*** sxc731_ has joined #openstack-keystone | 15:52 | |
sxc731 | odyssey4me: kool. Wil lbragstad's help I'm sure we can figure it out rather expediently and the perf boost might be pretty significant! | 15:53 |
odyssey4me | that would be really great :) | 15:53 |
odyssey4me | thank you guys for taking the time to dig into it | 15:53 |
sxc731 | I assume pretty much _every_ OS component validates tokens (presumably through KSM), right? So pretty much every one of them needs the reference to memcache_servers so they can hit the cache rather than require the slow DB roundtrip? | 15:55 |
*** sxc731_ has quit IRC | 15:56 | |
sxc731 | odyssey4me: no, thank _you_ (& lbragstad of course!) for all the help and support!! | 15:56 |
*** markvoelker has quit IRC | 15:59 | |
*** sxc731_ has joined #openstack-keystone | 15:59 | |
lbragstad | odyssey4me: yeah - i'm not sure if you saw - https://bugs.launchpad.net/oslo.cache/+bug/1743036 | 15:59 |
openstack | Launchpad bug 1743036 in oslo.cache "Multiple memcached back-end instances breaks caching" [Undecided,Confirmed] - Assigned to Morgan Fainberg (mdrnstm) | 15:59 |
*** aojea_ has quit IRC | 16:04 | |
*** aojea has joined #openstack-keystone | 16:04 | |
*** sxc731 has quit IRC | 16:05 | |
*** sxc731 has joined #openstack-keystone | 16:07 | |
sxc731 | osyssey4mw, lbragstad: actually to be fair in the case of that bug 1743036, OSA's config template was almost "too correct" (ie: it was using a new-style config which turned out to be broken if I understood correctly) | 16:07 |
openstack | bug 1743036 in oslo.cache "Multiple memcached back-end instances breaks caching" [Undecided,Confirmed] https://launchpad.net/bugs/1743036 - Assigned to Morgan Fainberg (mdrnstm) | 16:07 |
sxc731 | What I'm talking about now is a different kind of fish: missing memcached config that would enable KS-middleware to hit the cache directly for token validation, from components like Horizon. I'm assuming the perf. benefit might also be quite substantial... | 16:08 |
odyssey4me | that's a really good bug report - @evrardjp see https://bugs.launchpad.net/oslo.cache/+bug/1743036 | 16:08 |
openstack | Launchpad bug 1743036 in oslo.cache "Multiple memcached back-end instances breaks caching" [Undecided,Confirmed] - Assigned to Morgan Fainberg (mdrnstm) | 16:08 |
odyssey4me | I think this relates to another old bug report we have. | 16:09 |
*** hoonetorg has quit IRC | 16:09 | |
lbragstad | sxc731: yeah - it would, but there wouldn't be any revocations in that case | 16:10 |
sxc731 | lbragstad: I thought revocations were also cached? Though I have to admit I don't fully understand how this works... | 16:10 |
odyssey4me | I expect that we'll need to implement a workaround for the stable branches to make it work right as we'll not be able to make newton/ocata use a newer lib I guess. | 16:11 |
lbragstad | sxc731: revocations are cached in keystone, yep. but when the token is validated in keystonemiddleware and keystonemiddleware uses a cached response, revocations won't come into play | 16:11 |
*** itlinux has joined #openstack-keystone | 16:12 | |
lbragstad | (e.g. if i get a token, cache it at the service, invalidate the token, then go do something at the service, the cache isn't invalidated based on the revocation event being stored in keystone) | 16:12 |
sxc731 | lbragstad: meaning it would be possible for a component that uses ksm-caching to bypass revoked tokens? | 16:12 |
lbragstad | sxc731: exactly | 16:12 |
lbragstad | it's a fine line | 16:12 |
sxc731 | Whoa... that's quite the tradeoff! | 16:12 |
lbragstad | (i personally recommend super short ksm cache lifetimes) | 16:13 |
sxc731 | You understand this way better than I do of course but why couldn't ksm also hit the revoked tokens cache? | 16:13 |
evrardjp | odyssey4me: lbragstad I think I had something pending, will check the whole conversation and bug, see how I can help. | 16:13 |
sxc731 | ^short cache lifetimes might still work reasonably well in Horizon use-cases, where - I assume - a large number of services are hit | 16:14 |
lbragstad | we could build that in, but it would require keystone and keystonemiddleware to share the same cache (which might not be the case) | 16:14 |
lbragstad | i don't think we've made it that far yet | 16:14 |
sxc731 | So if I understand correctly, you're suggesting that pushing ksm-caching across many components isn't necessarily advisable in current state of play? | 16:15 |
lbragstad | sxc731: you can totally do it, but it is just worth knowing that ksm won't honor keystone revocation events for the case i just described | 16:16 |
*** sxc731_ has quit IRC | 16:16 | |
*** sxc731_ has joined #openstack-keystone | 16:16 | |
lbragstad | so if you set cache life time to something short on the keystonemiddleware bit, and cache in keystone, too.. then you might only get a negligible hit if you do have to make the roundtrip | 16:16 |
lbragstad | best case: ksm validates a valid token | 16:17 |
lbragstad | worst case: ksm validates a token but putting it on the wire to keystone, which results in a cache miss, keystone validates the token, resulting in a cache set on the way out | 16:17 |
lbragstad | s/but/by/ | 16:18 |
sxc731 | lbragstad: just so I understand, a typical token revocation is someone logging out of Horizon? | 16:18 |
*** bigdogstl has joined #openstack-keystone | 16:18 | |
lbragstad | sxc731: not any more - that used to be the case, but we've been working to make revocation events a smaller and smaller set | 16:19 |
lbragstad | (before, we used to store revocation events for *everything*; like removing a user from a project/domain, etc...) | 16:19 |
lbragstad | but we found that resulted in a *lot* of revocation events being written (and read) from keystone | 16:20 |
*** sxc731_ has quit IRC | 16:20 | |
evrardjp | lbragstad: ok just read the bug details | 16:20 |
lbragstad | sxc731: so we reworked our validation strategy to rebuild the entire authentication context at validation time (instead of relying on values that were true at authentication time) | 16:21 |
lbragstad | sxc731: long story short - revocation events happen when a user explicitly revokes a token or changes a password | 16:21 |
lbragstad | (I think those are the only two cases we use revocation events for) | 16:22 |
lbragstad | evrardjp: o/ afternoon, sir! | 16:22 |
evrardjp | I think my far memory updated that connection string, but got issues, and read the dogpile docs. if I recall correctly, we should probably use another backend for dogpile memcached to have proper clustering, but I might be wrong :) | 16:23 |
*** bigdogstl has quit IRC | 16:23 | |
*** sxc731_ has joined #openstack-keystone | 16:23 | |
evrardjp | happy new year lbragstad :D | 16:23 |
evrardjp | yeah I worked on that https://review.openstack.org/#/c/458029/ | 16:24 |
lbragstad | i was able to get clustering once i did this - https://review.openstack.org/#/c/533314/ | 16:24 |
lbragstad | but i had absolutely no luck with the format described in your commit message :) | 16:24 |
lbragstad | ur:<cache-1>,<cache-2>,<cache-3>:11211 or ur:<cache-1>:11211,<cache-2>:11211,<cache-3>:11211 | 16:25 |
sxc731 | lbragstad: cool, I think I get it; so sounds like revocations are now a fairly infrequent occurrence in a normal system's lifecycle... Maybe such an event could simply invalidate all the caches for example? Then you'd be rid of the annoying edge case... Anyway that's a different discussion... | 16:25 |
*** bigdogstl has joined #openstack-keystone | 16:25 | |
lbragstad | sxc731: right - we do some cache invalidation based on some operations in keystone (e.g. we cache a user's role assignments, but we revoke that if assignments are mucked with) | 16:26 |
lbragstad | evrardjp: once i did memcache_servers = {{ keystone_memcached_servers }} i was able to see cache traffic routed to the entire ring i had setup | 16:27 |
evrardjp | lbragstad: I think it's important to know which one is which, IIRC, we were supposed to drop memcached_servers because it was only used for token cache in UUID tokens, and those servers were colocated within keystone container, IIRC. But that's far in my memory, so I have to double check | 16:28 |
evrardjp | lbragstad: will adapt to your settings then | 16:28 |
evrardjp | for me your patch is good, we just need proper wiring of keystone_memcached_servers then. | 16:28 |
lbragstad | evrardjp: yeah - we have some digging left to do in oslo.cache and python-memcached | 16:29 |
*** dave-mcc_ has joined #openstack-keystone | 16:29 | |
lbragstad | because something there isn't working properly with the backend_argument | 16:29 |
evrardjp | my concern is proper clustering and easy configuration | 16:29 |
lbragstad | ++ | 16:30 |
*** sxc731 has quit IRC | 16:30 | |
evrardjp | yeah, I will accept your patch in the meantime, but let's keep in touch, and thanks! | 16:30 |
lbragstad | evrardjp: sounds good - if kmalloc and i get to the bottom of the oslo.cache issues reasonably soon, i'll come find you guys :) | 16:30 |
sxc731_ | Lbrag | 16:32 |
sxc731_ | sorry | 16:32 |
sxc731_ | If KSM can’t hit the cache in-process presumably it just delegates to KS proper? | 16:33 |
*** itlinux has quit IRC | 16:34 | |
lbragstad | sxc731_: and just validates the token online? | 16:35 |
openstackgerrit | Merged openstack/keystonemiddleware master: Imported Translations from Zanata https://review.openstack.org/533114 | 16:38 |
*** AlexeyAbashkin has quit IRC | 16:39 | |
*** AlexeyAbashkin has joined #openstack-keystone | 16:39 | |
*** tesseract has quit IRC | 16:40 | |
lbragstad | gagehugo: nice work on https://review.openstack.org/#/c/527527/2 - one question inline | 16:41 |
*** gyee has joined #openstack-keystone | 16:43 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Add functional testing gate https://review.openstack.org/531014 | 16:43 |
gagehugo | lbragstad o/ | 16:44 |
gagehugo | I assume doctor checks for the credentials API would be good to have? | 16:44 |
*** itlinux has joined #openstack-keystone | 16:46 | |
*** bigdogstl has quit IRC | 16:46 | |
*** sxc731 has joined #openstack-keystone | 16:47 | |
*** markvoelker has joined #openstack-keystone | 16:47 | |
*** AlexeyAbashkin has quit IRC | 16:47 | |
*** nicolasbock has quit IRC | 16:48 | |
*** nicolasbock has joined #openstack-keystone | 16:50 | |
*** itlinux has quit IRC | 16:55 | |
*** itlinux has joined #openstack-keystone | 16:56 | |
gagehugo | lbragstad are you talking about having the token keys and credential keys checks in the same category? | 16:58 |
lbragstad | gagehugo: well - i was thinking about it... but i guess the first thing we'd need to answer is "is there a reason to have doctor checks for the credential APIs usage of fernet?" | 16:59 |
*** sxc731_ has quit IRC | 17:02 | |
*** itlinux has quit IRC | 17:03 | |
gagehugo | for now I'd say yes, for the future I'm not sure | 17:05 |
*** tbh_ has quit IRC | 17:05 | |
gagehugo | I don't see a reason to change them at this time is what I mean | 17:06 |
*** bigdogstl has joined #openstack-keystone | 17:06 | |
gagehugo | unless I'm missing something | 17:07 |
*** dave-mcc_ has quit IRC | 17:08 | |
*** itlinux has joined #openstack-keystone | 17:12 | |
*** bigdogstl has quit IRC | 17:12 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: WIP Application credentials api-ref https://review.openstack.org/533744 | 17:12 |
*** hoonetorg has joined #openstack-keystone | 17:14 | |
*** efried is now known as efried_rollin | 17:19 | |
*** links has joined #openstack-keystone | 17:21 | |
lbragstad | gagehugo: but we do handle keys differently for the credentail api | 17:38 |
lbragstad | so - maybe that's something | 17:38 |
*** bigdogstl has joined #openstack-keystone | 17:39 | |
gagehugo | then maybe keep them separate I'd say | 17:42 |
*** bigdogstl has quit IRC | 17:44 | |
lbragstad | i know for the credential api we work in the concept of a null key | 17:49 |
lbragstad | and that was for upgrade purposes | 17:50 |
*** links has quit IRC | 17:50 | |
*** dikonoor has quit IRC | 17:52 | |
*** bigdogstl has joined #openstack-keystone | 17:52 | |
*** bigdogstl has quit IRC | 17:58 | |
*** abhishek has quit IRC | 18:04 | |
*** sxc731 has quit IRC | 18:06 | |
*** bigdogstl has joined #openstack-keystone | 18:09 | |
*** mvk has quit IRC | 18:10 | |
*** sambetts is now known as sambetts|afk | 18:14 | |
*** bigdogstl has quit IRC | 18:16 | |
*** kmalloc has joined #openstack-keystone | 18:19 | |
* kmalloc yawns. | 18:19 | |
-openstackstatus- NOTICE: Zuul has been restarted and has lost queue contents; changes in progress will need to be rechecked. | 18:23 | |
*** aojea has quit IRC | 18:36 | |
*** AlexeyAbashkin has joined #openstack-keystone | 18:50 | |
*** aojea has joined #openstack-keystone | 18:51 | |
*** AlexeyAbashkin has quit IRC | 18:55 | |
*** aojea_ has joined #openstack-keystone | 18:57 | |
*** sxc731 has joined #openstack-keystone | 18:58 | |
*** aojea has quit IRC | 18:59 | |
*** aojea has joined #openstack-keystone | 19:02 | |
lbragstad | running an errand over lunch quick, biab | 19:03 |
*** aojea_ has quit IRC | 19:05 | |
*** aojea_ has joined #openstack-keystone | 19:08 | |
*** aojea has quit IRC | 19:11 | |
*** aojea has joined #openstack-keystone | 19:12 | |
*** aojea_ has quit IRC | 19:15 | |
*** aojea_ has joined #openstack-keystone | 19:18 | |
*** bigdogstl has joined #openstack-keystone | 19:20 | |
*** aojea has quit IRC | 19:20 | |
*** aojea has joined #openstack-keystone | 19:23 | |
*** aojea_ has quit IRC | 19:26 | |
*** bigdogstl has quit IRC | 19:28 | |
*** aojea_ has joined #openstack-keystone | 19:29 | |
*** aojea has quit IRC | 19:31 | |
*** aojea has joined #openstack-keystone | 19:34 | |
*** aojea_ has quit IRC | 19:36 | |
*** aojea_ has joined #openstack-keystone | 19:39 | |
openstackgerrit | Dirk Mueller proposed openstack/keystone master: msgpack-python has been renamed to msgpack https://review.openstack.org/533768 | 19:41 |
*** aojea has quit IRC | 19:42 | |
*** aojea has joined #openstack-keystone | 19:46 | |
*** aojea_ has quit IRC | 19:47 | |
*** AlexeyAbashkin has joined #openstack-keystone | 19:51 | |
*** aojea has quit IRC | 19:53 | |
*** efried_rollin is now known as efried | 19:55 | |
*** AlexeyAbashkin has quit IRC | 19:55 | |
*** aojea has joined #openstack-keystone | 20:04 | |
*** aojea_ has joined #openstack-keystone | 20:09 | |
*** aojea has quit IRC | 20:12 | |
*** aojea__ has joined #openstack-keystone | 20:15 | |
*** sxc731 has left #openstack-keystone | 20:16 | |
*** aojea_ has quit IRC | 20:18 | |
*** rmascena has joined #openstack-keystone | 20:19 | |
*** bigdogstl has joined #openstack-keystone | 20:20 | |
*** raildo has quit IRC | 20:21 | |
*** dansmith has quit IRC | 20:22 | |
*** markvoelker has quit IRC | 20:22 | |
*** aojea__ has quit IRC | 20:23 | |
*** bigdogstl has quit IRC | 20:28 | |
*** Guest49522 has joined #openstack-keystone | 20:35 | |
*** Guest49522 is now known as dansmith | 20:40 | |
*** AlexeyAbashkin has joined #openstack-keystone | 20:50 | |
*** AlexeyAbashkin has quit IRC | 20:54 | |
*** bigdogstl has joined #openstack-keystone | 20:58 | |
*** bigdogstl has quit IRC | 21:10 | |
openstackgerrit | Monty Taylor proposed openstack/keystoneauth master: Split request logging into four different loggers https://review.openstack.org/505764 | 21:13 |
openstackgerrit | Monty Taylor proposed openstack/keystoneauth master: Remove PYTHONHASHSEED setting https://review.openstack.org/533798 | 21:13 |
*** aojea has joined #openstack-keystone | 21:13 | |
*** aojea_ has joined #openstack-keystone | 21:18 | |
*** aojea has quit IRC | 21:21 | |
*** aojea has joined #openstack-keystone | 21:23 | |
lbragstad | i gotta step away for a bit but i'll back back online in a couple hours and working through tonight | 21:25 |
*** aojea_ has quit IRC | 21:26 | |
*** nicolasbock has quit IRC | 21:26 | |
*** aojea_ has joined #openstack-keystone | 21:28 | |
gagehugo | ok | 21:29 |
*** aojea has quit IRC | 21:30 | |
*** pcaruana has quit IRC | 21:30 | |
gagehugo | jobs are not very stable today :( | 21:30 |
*** dave-mccowan has joined #openstack-keystone | 21:31 | |
*** jappleii__ has joined #openstack-keystone | 21:32 | |
*** aojea__ has joined #openstack-keystone | 21:33 | |
*** dgonzalez has quit IRC | 21:33 | |
*** bigdogstl has joined #openstack-keystone | 21:33 | |
*** aojea_ has quit IRC | 21:36 | |
*** aojea_ has joined #openstack-keystone | 21:38 | |
*** bigdogstl has quit IRC | 21:38 | |
*** aojea__ has quit IRC | 21:41 | |
*** dgonzalez has joined #openstack-keystone | 21:42 | |
*** aojea__ has joined #openstack-keystone | 21:43 | |
*** lbragstad has quit IRC | 21:44 | |
*** aojea_ has quit IRC | 21:46 | |
*** lbragstad has joined #openstack-keystone | 21:47 | |
*** ChanServ sets mode: +o lbragstad | 21:47 | |
*** aojea_ has joined #openstack-keystone | 21:48 | |
lbragstad | nope :( | 21:49 |
*** AlexeyAbashkin has joined #openstack-keystone | 21:50 | |
*** aojea__ has quit IRC | 21:51 | |
*** aojea__ has joined #openstack-keystone | 21:53 | |
*** AlexeyAbashkin has quit IRC | 21:54 | |
*** aojea_ has quit IRC | 21:57 | |
*** bigdogstl has joined #openstack-keystone | 21:58 | |
*** aojea has joined #openstack-keystone | 21:58 | |
cmurphy | TIL parameters.yaml in api-ref is enforced alphabetical | 21:59 |
cmurphy | did not expect | 21:59 |
*** aojea__ has quit IRC | 22:01 | |
*** bigdogstl has quit IRC | 22:03 | |
*** aojea has quit IRC | 22:07 | |
cmurphy | oh and also grouped by where the parameter is | 22:07 |
*** aojea has joined #openstack-keystone | 22:07 | |
cmurphy | this is so hard to get right | 22:07 |
*** bigdogstl has joined #openstack-keystone | 22:09 | |
*** lbragstad has quit IRC | 22:10 | |
*** mvk has joined #openstack-keystone | 22:11 | |
*** aojea_ has joined #openstack-keystone | 22:12 | |
*** aojea has quit IRC | 22:15 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add Application Credentials controller https://review.openstack.org/524423 | 22:16 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add application credential auth plugin https://review.openstack.org/525346 | 22:16 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Allow overriding app cred restrictions https://review.openstack.org/533431 | 22:16 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add caching options for application credentials https://review.openstack.org/533609 | 22:16 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: WIP Application credentials api-ref https://review.openstack.org/533744 | 22:16 |
*** aojea__ has joined #openstack-keystone | 22:18 | |
*** lbragstad has joined #openstack-keystone | 22:19 | |
*** ChanServ sets mode: +o lbragstad | 22:19 | |
*** aojea_ has quit IRC | 22:20 | |
*** rcernin has joined #openstack-keystone | 22:21 | |
*** aojea has joined #openstack-keystone | 22:22 | |
kmalloc | cmurphy: i wouldn't have expected that either | 22:23 |
lbragstad | cmurphy: yeah - totally fun to debug | 22:23 |
* lbragstad 's been bitten by that before | 22:23 | |
*** bigdogstl has quit IRC | 22:23 | |
*** aojea__ has quit IRC | 22:25 | |
kmalloc | mordred, lbragstad: re https://review.openstack.org/#/c/505764/6 it's going to have to be opt-in for the split loggers | 22:27 |
kmalloc | we can't break behavior that someone might be relying on | 22:27 |
kmalloc | changing the logging output does | 22:27 |
kmalloc | *sorry* =/ | 22:27 |
kmalloc | now... that said, lbragstad can tell me he believes it's ok, and i'll +2 it as is. [provided a clean test run] | 22:28 |
*** aojea_ has joined #openstack-keystone | 22:28 | |
*** spilla has quit IRC | 22:28 | |
lbragstad | kmalloc: i'll add it to my review queue | 22:30 |
kmalloc | lbragstad: it should be quick to review. it's a good concept | 22:30 |
*** bigdogstl has joined #openstack-keystone | 22:30 | |
* kmalloc is going to build some microphones... ^_^ | 22:30 | |
*** aojea has quit IRC | 22:30 | |
kmalloc | cause you cvan totally make awesome vintage mics for cheap if you're willing to solder things | 22:31 |
kmalloc | cmurphy: ^ yesssssssss soldering fun. | 22:31 |
kmalloc | mordred: https://review.openstack.org/#/c/533798/1 if that passes tests, feel free to self-approve. PLEASE approve that one as soon as it is possible to make that a thing. | 22:31 |
kmalloc | ^ any keystoneauth core (the 533798 one) | 22:32 |
cmurphy | kmalloc: :D | 22:32 |
*** aojea has joined #openstack-keystone | 22:32 | |
*** aojea_ has quit IRC | 22:35 | |
*** aojea_ has joined #openstack-keystone | 22:38 | |
*** rmascena has quit IRC | 22:38 | |
*** bigdogstl has quit IRC | 22:39 | |
*** aojea has quit IRC | 22:40 | |
*** aojea__ has joined #openstack-keystone | 22:43 | |
*** aojea_ has quit IRC | 22:45 | |
*** aojea__ has quit IRC | 22:48 | |
*** phalmos has quit IRC | 22:49 | |
*** bigdogstl has joined #openstack-keystone | 22:51 | |
*** markvoelker has joined #openstack-keystone | 22:53 | |
*** markvoelker has quit IRC | 22:58 | |
*** lbragstad has quit IRC | 23:00 | |
*** bigdogstl has quit IRC | 23:01 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add api-ref for application credentials https://review.openstack.org/533744 | 23:03 |
*** bigdogstl has joined #openstack-keystone | 23:17 | |
*** bigdogstl has quit IRC | 23:25 | |
*** itlinux has quit IRC | 23:33 | |
*** r-daneel has quit IRC | 23:33 | |
*** bigdogstl has joined #openstack-keystone | 23:40 | |
*** nicolasbock has joined #openstack-keystone | 23:47 | |
*** lbragstad has joined #openstack-keystone | 23:53 | |
*** ChanServ sets mode: +o lbragstad | 23:53 | |
*** bigdogstl has quit IRC | 23:54 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!