*** r-daneel has quit IRC | 00:01 | |
*** itlinux has quit IRC | 00:03 | |
*** mancdaz has quit IRC | 00:12 | |
*** robcresswell has quit IRC | 00:12 | |
*** mancdaz has joined #openstack-keystone | 00:14 | |
*** AlexeyAbashkin has joined #openstack-keystone | 00:16 | |
*** AlexeyAbashkin has quit IRC | 00:21 | |
*** prashkre_ has joined #openstack-keystone | 00:22 | |
*** gongysh has joined #openstack-keystone | 00:35 | |
*** dikonoor has quit IRC | 00:38 | |
*** daidv has quit IRC | 00:39 | |
*** daidv has joined #openstack-keystone | 00:39 | |
*** blake has joined #openstack-keystone | 00:45 | |
*** zhurong has joined #openstack-keystone | 00:48 | |
*** deepak_ has quit IRC | 00:52 | |
*** sambetts|afk has quit IRC | 00:54 | |
*** sambetts_ has joined #openstack-keystone | 00:54 | |
*** d0ugal has quit IRC | 00:55 | |
*** lbragstad has quit IRC | 00:57 | |
*** Dinesh_Bhor has joined #openstack-keystone | 00:58 | |
*** Dinesh_Bhor has quit IRC | 00:59 | |
*** d0ugal has joined #openstack-keystone | 00:59 | |
*** deepak_ has joined #openstack-keystone | 01:03 | |
*** zhurong has quit IRC | 01:13 | |
*** prashkre_ has quit IRC | 01:20 | |
*** gongysh has quit IRC | 01:21 | |
*** Dinesh_Bhor has joined #openstack-keystone | 01:23 | |
*** prashkre_ has joined #openstack-keystone | 01:26 | |
openstackgerrit | Merged openstack/oslo.policy master: Render deprecated policy names when generating files https://review.openstack.org/532685 | 01:28 |
---|---|---|
*** blake has quit IRC | 01:33 | |
*** aselius has quit IRC | 01:35 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: [WIP]Remove foreign key for registered limit https://review.openstack.org/536644 | 01:59 |
*** efried_back_wed has quit IRC | 02:06 | |
*** robcresswell has joined #openstack-keystone | 02:09 | |
*** panbalag has joined #openstack-keystone | 02:13 | |
*** lbragstad has joined #openstack-keystone | 02:14 | |
*** ChanServ sets mode: +o lbragstad | 02:14 | |
*** gongysh has joined #openstack-keystone | 02:15 | |
*** prashkre_ has quit IRC | 02:19 | |
*** efried_back_wed has joined #openstack-keystone | 02:19 | |
*** harlowja has quit IRC | 02:27 | |
*** annp has joined #openstack-keystone | 02:28 | |
*** panbalag has left #openstack-keystone | 02:32 | |
*** dikonoor has joined #openstack-keystone | 03:03 | |
lbragstad | wxy: you have another patch set for the FK removal bit for unified limits, right? | 03:07 |
wxy | lbragstad: yes. I'm debugging now. Will update it right now. | 03:08 |
lbragstad | wxy: no worries - just checking :) | 03:08 |
*** panbalag has joined #openstack-keystone | 03:14 | |
*** panbalag has left #openstack-keystone | 03:14 | |
*** dave-mcc_ has quit IRC | 03:16 | |
*** gongysh has quit IRC | 03:18 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Remove foreign key for registered limit https://review.openstack.org/536644 | 03:23 |
*** gongysh has joined #openstack-keystone | 03:24 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Remove foreign key for registered limit https://review.openstack.org/536644 | 03:25 |
*** annp has quit IRC | 03:29 | |
*** daidv has quit IRC | 03:30 | |
*** blake has joined #openstack-keystone | 03:41 | |
*** daidv has joined #openstack-keystone | 03:44 | |
*** annp has joined #openstack-keystone | 03:47 | |
*** gongysh has quit IRC | 03:55 | |
*** blake has quit IRC | 03:58 | |
openstackgerrit | Merged openstack/keystone master: Move token_formatter to token https://review.openstack.org/527538 | 03:59 |
*** sapd_ has quit IRC | 04:02 | |
*** sapd_ has joined #openstack-keystone | 04:02 | |
*** links has joined #openstack-keystone | 04:02 | |
*** links has quit IRC | 04:07 | |
openstackgerrit | Dinesh Bhor proposed openstack/python-keystoneclient master: Add Response class to return request-id to caller https://review.openstack.org/329913 | 04:14 |
openstackgerrit | Dinesh Bhor proposed openstack/python-keystoneclient master: Add return-request-id-to-caller function(v3) https://review.openstack.org/267456 | 04:14 |
openstackgerrit | Dinesh Bhor proposed openstack/python-keystoneclient master: Add return-request-id-to-caller function(v3/contrib) https://review.openstack.org/268003 | 04:17 |
*** links has joined #openstack-keystone | 04:19 | |
*** gongysh has joined #openstack-keystone | 04:24 | |
*** annp has quit IRC | 04:28 | |
*** daidv has quit IRC | 04:28 | |
*** annp has joined #openstack-keystone | 04:28 | |
*** daidv has joined #openstack-keystone | 04:28 | |
*** david-lyle has quit IRC | 04:30 | |
*** dklyle has joined #openstack-keystone | 04:31 | |
*** blake has joined #openstack-keystone | 04:31 | |
*** dikonoor has quit IRC | 04:33 | |
openstackgerrit | Dinesh Bhor proposed openstack/python-keystoneclient master: Add release notes for return-request-id-to-caller https://review.openstack.org/276644 | 04:35 |
*** gongysh has quit IRC | 04:47 | |
*** dikonoor has joined #openstack-keystone | 05:02 | |
*** vish_18 has joined #openstack-keystone | 05:03 | |
*** gmann has joined #openstack-keystone | 05:03 | |
*** links has quit IRC | 05:06 | |
vish_18 | lbragstad: Hello | 05:06 |
*** links has joined #openstack-keystone | 05:08 | |
*** harlowja has joined #openstack-keystone | 05:12 | |
*** harlowja has quit IRC | 05:13 | |
*** pcaruana has joined #openstack-keystone | 05:24 | |
*** zhurong has joined #openstack-keystone | 05:29 | |
*** pcaruana has quit IRC | 05:36 | |
*** gongysh has joined #openstack-keystone | 05:40 | |
*** prashkre has joined #openstack-keystone | 05:46 | |
*** dikonoor has quit IRC | 05:46 | |
openstackgerrit | lei zhang proposed openstack/keystone master: Remove the deprecated "giturl" option https://review.openstack.org/533466 | 05:51 |
*** prashkre_ has joined #openstack-keystone | 05:55 | |
*** prashkre has quit IRC | 05:55 | |
*** jaosorior has quit IRC | 05:57 | |
*** jaosorior has joined #openstack-keystone | 05:57 | |
*** dikonoor has joined #openstack-keystone | 05:58 | |
*** Dinesh_Bhor has quit IRC | 06:06 | |
*** Dinesh_Bhor has joined #openstack-keystone | 06:06 | |
*** prashkre_ has quit IRC | 06:13 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Add api-ref for unified limits https://review.openstack.org/535688 | 06:20 |
*** blake has quit IRC | 06:42 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Remove foreign key for registered limit https://review.openstack.org/536644 | 06:47 |
*** itlinux has joined #openstack-keystone | 06:56 | |
*** itlinux has quit IRC | 06:59 | |
openstackgerrit | CHARLES WANG proposed openstack/keystone master: Delete users before deleting domains https://review.openstack.org/506340 | 07:03 |
openstackgerrit | CHARLES WANG proposed openstack/keystone master: Delete users before deleting domains https://review.openstack.org/506340 | 07:05 |
*** jrist has quit IRC | 07:15 | |
*** itlinux has joined #openstack-keystone | 07:27 | |
*** pcaruana has joined #openstack-keystone | 07:33 | |
*** rha has quit IRC | 07:44 | |
*** jrist has joined #openstack-keystone | 07:53 | |
*** itlinux has quit IRC | 07:58 | |
*** pcaruana has quit IRC | 07:58 | |
*** rcernin has quit IRC | 08:00 | |
*** AlexeyAbashkin has joined #openstack-keystone | 08:05 | |
*** tesseract has joined #openstack-keystone | 08:09 | |
*** pcaruana has joined #openstack-keystone | 08:13 | |
openstackgerrit | Gao Fei proposed openstack/keystone master: Replace Chinese punctuation with English punctuation https://review.openstack.org/536709 | 08:15 |
*** sapd_ has quit IRC | 08:16 | |
*** sapd_ has joined #openstack-keystone | 08:16 | |
*** abhishek has quit IRC | 08:27 | |
*** sxc731 has joined #openstack-keystone | 08:35 | |
*** daidv has quit IRC | 08:38 | |
*** annp has quit IRC | 08:38 | |
*** annp has joined #openstack-keystone | 08:38 | |
*** daidv has joined #openstack-keystone | 08:38 | |
*** itlinux has joined #openstack-keystone | 08:46 | |
*** sxc731 has quit IRC | 08:47 | |
*** abhi89 has joined #openstack-keystone | 08:47 | |
openstackgerrit | Colleen Murphy proposed openstack/python-keystoneclient master: Add CRUD support for application credentials https://review.openstack.org/534965 | 09:09 |
*** itlinux has quit IRC | 09:12 | |
*** mvk has quit IRC | 09:26 | |
*** dikonoo has joined #openstack-keystone | 09:31 | |
*** tesseract-RH has joined #openstack-keystone | 09:33 | |
*** tesseract-RH has quit IRC | 09:34 | |
*** dikonoor has quit IRC | 09:34 | |
*** tesseract-RH has joined #openstack-keystone | 09:35 | |
*** tesseract has quit IRC | 09:37 | |
*** Dinesh_Bhor has quit IRC | 09:48 | |
*** Dinesh_Bhor has joined #openstack-keystone | 09:49 | |
*** Dinesh_Bhor has quit IRC | 09:49 | |
*** abhi89 has quit IRC | 09:54 | |
*** jaosorior has quit IRC | 09:55 | |
*** markvoelker has quit IRC | 09:59 | |
*** mvk has joined #openstack-keystone | 09:59 | |
*** zhurong has quit IRC | 10:11 | |
*** itlinux has joined #openstack-keystone | 10:15 | |
*** dikonoo has quit IRC | 10:26 | |
*** zhurong has joined #openstack-keystone | 10:30 | |
*** sambetts_ is now known as sambetts | 10:32 | |
*** timothyb89 has quit IRC | 10:32 | |
*** timothyb89 has joined #openstack-keystone | 10:33 | |
*** itlinux has quit IRC | 10:47 | |
*** itlinux has joined #openstack-keystone | 10:53 | |
*** jaosorior has joined #openstack-keystone | 10:53 | |
openstackgerrit | Kairat Kushaev proposed openstack/keystoneauth master: replace lxml with defusedxml https://review.openstack.org/536761 | 10:55 |
*** mvk has quit IRC | 11:02 | |
*** annp has quit IRC | 11:03 | |
*** AlexeyAbashkin has quit IRC | 11:06 | |
*** itlinux has quit IRC | 11:07 | |
*** mvk has joined #openstack-keystone | 11:15 | |
*** dikonoo has joined #openstack-keystone | 11:18 | |
*** AlexeyAbashkin has joined #openstack-keystone | 11:23 | |
*** gongysh has quit IRC | 11:36 | |
*** itlinux has joined #openstack-keystone | 11:45 | |
*** tesseract-RH has quit IRC | 11:52 | |
*** mvenesio has joined #openstack-keystone | 11:54 | |
*** markvoelker has joined #openstack-keystone | 12:00 | |
*** raildo has joined #openstack-keystone | 12:04 | |
*** zhurong has quit IRC | 12:05 | |
*** nicolasbock has joined #openstack-keystone | 12:22 | |
*** markvoelker has quit IRC | 12:33 | |
*** tesseract-RH has joined #openstack-keystone | 12:47 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add api-ref for application credentials https://review.openstack.org/533744 | 12:49 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Enable application_credential auth by default https://review.openstack.org/535469 | 12:49 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Impose limits on application credentials https://review.openstack.org/536543 | 12:49 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add a release note for application credentials https://review.openstack.org/535493 | 12:49 |
*** tesseract-RH has quit IRC | 12:54 | |
*** tesseract has joined #openstack-keystone | 12:55 | |
*** zhurong has joined #openstack-keystone | 12:57 | |
*** zhurong has quit IRC | 13:14 | |
*** dims has quit IRC | 13:22 | |
*** alex_xu has quit IRC | 13:24 | |
*** dims has joined #openstack-keystone | 13:25 | |
*** alex_xu has joined #openstack-keystone | 13:27 | |
*** markvoelker has joined #openstack-keystone | 13:31 | |
lbragstad | vish_18: o/ | 13:37 |
evrardjp | good morning for those who see the sun rising now. | 13:38 |
lbragstad | morning! | 13:39 |
evrardjp | I haven't forgotten the memcached issue. Just saying. | 13:40 |
evrardjp | :D | 13:40 |
*** edmondsw has joined #openstack-keystone | 13:49 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Teach TokenFormatter how to handle system scope https://review.openstack.org/525330 | 13:50 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system-scope in the token provider API https://review.openstack.org/525360 | 13:50 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Introduce assertions for system-scoped token testing https://review.openstack.org/528037 | 13:50 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system-scoped tokens https://review.openstack.org/525687 | 13:50 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add release note for system-scope https://review.openstack.org/528039 | 13:50 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Update documentation to reflect system-scope https://review.openstack.org/530133 | 13:50 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Grant admin a role on the system during bootstrap https://review.openstack.org/530410 | 13:50 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement GET /v3/auth/system https://review.openstack.org/530490 | 13:50 |
*** panbalag has joined #openstack-keystone | 13:52 | |
*** panbalag has quit IRC | 13:56 | |
*** markvoelker has quit IRC | 14:04 | |
*** links has quit IRC | 14:05 | |
*** dave-mccowan has joined #openstack-keystone | 14:10 | |
evrardjp | lp is very slow today... | 14:11 |
*** dave-mcc_ has joined #openstack-keystone | 14:12 | |
*** melwitt has quit IRC | 14:12 | |
*** panbalag has joined #openstack-keystone | 14:14 | |
*** melwitt has joined #openstack-keystone | 14:14 | |
*** dave-mccowan has quit IRC | 14:15 | |
lbragstad | evrardjp: are you guys moving to storyboard? | 14:19 |
*** dklyle has quit IRC | 14:22 | |
evrardjp | I thought about it. | 14:23 |
evrardjp | it changes our processes, and things like that. I don't have an incentive to do so for now, but that might change. | 14:23 |
evrardjp | cmurphy: hello, you might want to have a look at this: https://bugs.launchpad.net/keystone/+bug/1744948 :) | 14:24 |
openstack | Launchpad bug 1744948 in OpenStack Identity (keystone) "allow_application_credential_creation contraint issue with suse + mariadb 10.2" [Undecided,New] | 14:24 |
cmurphy | evrardjp: heh mchandras just told me | 14:25 |
evrardjp | cmurphy: don't tell anyone sometimes we talk together! | 14:25 |
evrardjp | :D | 14:25 |
cmurphy | will look at it today | 14:25 |
evrardjp | thanks. | 14:28 |
*** wxy| has joined #openstack-keystone | 14:28 | |
wxy| | lbragstad: cmurphy: if remove the dependence of FK patch. Some tests will fail. Such as https://review.openstack.org/#/c/524109/40/keystone/tests/unit/limit/test_backends.py@371 | 14:29 |
wxy| | it relays on FKs which is disabled by default in sqlite | 14:30 |
cmurphy | :( | 14:30 |
wxy| | maybe we can add skip decorator for these kind of tests at this moment? | 14:31 |
cmurphy | i would be okay with that | 14:31 |
lbragstad | can we test that it doesn't fail with something other than SQLite? | 14:34 |
cmurphy | i'm not 100% sure but i think those backend tests only run on sqlite, it's only the upgrade tests that can run on mysql and pg | 14:36 |
*** mvk has quit IRC | 14:37 | |
lbragstad | i think you're right... | 14:37 |
wxy| | yeah. It's hard coding to use sqlite AFAIK. | 14:37 |
lbragstad | i've run them locally before | 14:37 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Remove foreign key for registered limit https://review.openstack.org/536644 | 14:39 |
*** wxy| has quit IRC | 14:41 | |
*** markvoelker has joined #openstack-keystone | 14:41 | |
lbragstad | cmurphy: wxy it should be MySQLOpportunisticUpgradeTestCase | 14:48 |
lbragstad | if i remember correctly | 14:48 |
*** dave-mcc_ has quit IRC | 14:55 | |
openstackgerrit | Lance Bragstad proposed openstack/python-keystoneclient master: Add system role functionality https://review.openstack.org/524415 | 14:58 |
*** dave-mccowan has joined #openstack-keystone | 15:05 | |
*** aselius has joined #openstack-keystone | 15:06 | |
dstanek | good morning keystoners | 15:09 |
cmurphy | hello dstanek | 15:12 |
lbragstad | dstanek: o/ | 15:13 |
lbragstad | good to see you around, sir! | 15:13 |
gagehugo | o/ | 15:14 |
*** itlinux has quit IRC | 15:19 | |
*** dikonoo has quit IRC | 15:20 | |
*** links has joined #openstack-keystone | 15:21 | |
lbragstad | interesting read - http://lists.openstack.org/pipermail/openstack-dev/2018-January/126505.html | 15:22 |
lbragstad | cmurphy: are we waiting on something else for https://review.openstack.org/#/c/524423/39 ? | 15:24 |
cmurphy | lbragstad: i want to fix https://bugs.launchpad.net/keystone/+bug/1744948 | 15:27 |
openstack | Launchpad bug 1744948 in OpenStack Identity (keystone) "allow_application_credential_creation contraint issue with suse + mariadb 10.2" [High,Confirmed] - Assigned to Colleen Murphy (krinkle) | 15:27 |
cmurphy | have a patch coming soon | 15:27 |
lbragstad | oh! | 15:27 |
lbragstad | good call | 15:27 |
lbragstad | thanks | 15:27 |
*** abhi89 has joined #openstack-keystone | 15:27 | |
*** spilla has joined #openstack-keystone | 15:35 | |
*** rmascena has joined #openstack-keystone | 15:38 | |
*** raildo has quit IRC | 15:40 | |
*** david-lyle has joined #openstack-keystone | 15:40 | |
*** rmascena is now known as raildo | 15:41 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Fix column rename migration for mariadb 10.2 https://review.openstack.org/536869 | 15:43 |
*** nicolasbock has quit IRC | 15:47 | |
knikolla | o/ | 15:53 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add scope_types to role assignment policies https://review.openstack.org/526165 | 15:54 |
kmalloc | o/ | 15:58 |
*** r-daneel has joined #openstack-keystone | 15:59 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add scope_types to grant policies https://review.openstack.org/526130 | 16:03 |
lbragstad | we have a full house today | 16:03 |
lbragstad | this is awesome :) | 16:03 |
*** openstackgerrit has quit IRC | 16:03 | |
dstanek | lbragstad: :-) | 16:04 |
dstanek | i want to take a look at that sqlite review today.... is that something critical to get in? | 16:04 |
lbragstad | dstanek: we were trying to get that in before the unified limits feature | 16:05 |
dstanek | i'll read through the reviews in a bit then and get it working... what's the tldr; on it? tests not passing? | 16:06 |
lbragstad | the tests pass, but we wanted to make sure we captured or resolved the context you had on it | 16:07 |
lbragstad | and make sure we weren't overlooking something | 16:07 |
dstanek | kk, i'll take a look this afternoon | 16:12 |
lbragstad | thanks dstanek | 16:16 |
kmalloc | it's a wild dstanek | 16:18 |
lbragstad | kmalloc: in case you haven't seen it yet - http://lists.openstack.org/pipermail/openstack-dev/2018-January/126425.html | 16:20 |
lbragstad | more specifically - https://goo.gl/NWdAH7 | 16:20 |
kmalloc | yeah i didn't see that | 16:21 |
kmalloc | *shrug* | 16:21 |
kmalloc | the -dev list has gotten so much traffic i can't even track it (has been like that for about a year) | 16:21 |
lbragstad | yeah - no worries, the important bit is that we're tracking feature freeze patches in that board if you have anything to add or need reviews | 16:22 |
*** tesseract has quit IRC | 16:22 | |
kmalloc | can we not add system scope to ec2? | 16:22 |
kmalloc | stupid question | 16:22 |
kmalloc | but i would much rather not increase the scope of ec2 creds if we don't need to | 16:22 |
lbragstad | good question | 16:23 |
lbragstad | https://review.openstack.org/#/c/526191/4/keystone/common/policies/ec2_credential.py@21 | 16:23 |
kmalloc | yeah | 16:23 |
kmalloc | i just wanted to ask you independant of a review | 16:23 |
lbragstad | because the current check str is a ADMIN_OR_OWNER thing | 16:23 |
kmalloc | right, but we could just not support system | 16:23 |
lbragstad | so if we isolate it to 'system' we have the option to break users | 16:23 |
kmalloc | even with admin/owner | 16:23 |
kmalloc | i'd isolate it to NOT system | 16:24 |
kmalloc | i want ec2 to go away... but thats my personal view. | 16:24 |
lbragstad | but would that mean any project admin has the ability to get secrets? | 16:24 |
kmalloc | so i'd rather treat it as legacy | 16:24 |
kmalloc | crap. you're right | 16:24 |
kmalloc | nvm | 16:24 |
kmalloc | i hate our permission model | 16:24 |
lbragstad | damned if you do and damned if you don't :) | 16:25 |
lbragstad | for those tricky cases, cmurphy and i thought we could just comment it out with reasoning until we get a patch up to correct the permission model and enforcement | 16:25 |
kmalloc | yeah | 16:25 |
*** ksavich has joined #openstack-keystone | 16:26 | |
lbragstad | whoa - we have a ksavich today, too! | 16:26 |
ksavich | haha | 16:27 |
ksavich | whatsup! | 16:27 |
kmalloc | wow | 16:27 |
kmalloc | it's all the fun people we've been missing | 16:27 |
ksavich | how's it going in here? Long time. | 16:28 |
* kmalloc is sitting in a meeting | 16:28 | |
kmalloc | =/ | 16:28 |
kmalloc | sooooo | 16:28 |
kmalloc | could be better :P | 16:28 |
kmalloc | otherwise not too bad | 16:28 |
ksavich | yes, meetings - blech | 16:28 |
lbragstad | it's going, dealing with the feature freeze crunch :) | 16:29 |
ksavich | right on | 16:29 |
ksavich | staying warm I hope | 16:29 |
lbragstad | you know it | 16:31 |
lbragstad | nice write up on the fernet stuff | 16:31 |
ksavich | thanks | 16:31 |
ksavich | well, I nicked a good deal from you guys - so thanks | 16:32 |
lbragstad | :) | 16:32 |
ksavich | now I have to change all of it with mistral workflows | 16:32 |
ksavich | haha | 16:32 |
*** openstackgerrit has joined #openstack-keystone | 16:37 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add scope_types to trust policies https://review.openstack.org/526176 | 16:37 |
*** pcaruana has quit IRC | 16:41 | |
*** wxy has quit IRC | 16:46 | |
*** Suramya has joined #openstack-keystone | 16:52 | |
*** Suramya_ has joined #openstack-keystone | 16:57 | |
*** AlexeyAbashkin has quit IRC | 17:02 | |
*** mvenesio has quit IRC | 17:06 | |
*** mvenesio has joined #openstack-keystone | 17:07 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Document scope_types for project policies https://review.openstack.org/526159 | 17:11 |
*** mvenesio_ has joined #openstack-keystone | 17:14 | |
*** mvenesio has quit IRC | 17:17 | |
*** ksavich has quit IRC | 17:28 | |
*** rderose has joined #openstack-keystone | 17:46 | |
*** gyee has joined #openstack-keystone | 17:47 | |
*** abhi89 has quit IRC | 17:52 | |
*** abhi89 has joined #openstack-keystone | 17:52 | |
*** david-lyle has quit IRC | 18:07 | |
cmurphy | oh hi samueldmq :) i want to talk about one of your old patches after the meeting | 18:10 |
samueldmq | Hey | 18:10 |
samueldmq | Sure! I am not really on the laptop but we can chat | 18:11 |
samueldmq | Always have time for good friends | 18:11 |
samueldmq | BTW I was submitted to an appendectomy last week, still healing for the next few days | 18:12 |
samueldmq | :( | 18:12 |
samueldmq | Oh crap, this is -keystone, sorry folks for spamming | 18:13 |
cmurphy | :) | 18:13 |
gagehugo | get better samueldmq! | 18:13 |
*** abhishek has joined #openstack-keystone | 18:14 | |
*** abhi89 has quit IRC | 18:17 | |
samueldmq | gagehugo: thanks | 18:17 |
*** links has quit IRC | 18:26 | |
*** AlexeyAbashkin has joined #openstack-keystone | 18:31 | |
*** rmascena has joined #openstack-keystone | 18:31 | |
*** dtruong has quit IRC | 18:34 | |
*** panbalag has left #openstack-keystone | 18:34 | |
*** raildo has quit IRC | 18:35 | |
*** AlexeyAbashkin has quit IRC | 18:35 | |
*** links has joined #openstack-keystone | 18:40 | |
*** abhi89 has joined #openstack-keystone | 18:58 | |
*** jessegler has joined #openstack-keystone | 18:59 | |
gagehugo | gonna head home and I'll start reviewing | 18:59 |
cmurphy | samueldmq: kmalloc one of my coworkers is taking on https://review.openstack.org/#/c/506340/ and i want to set him on the right track | 18:59 |
cmurphy | i'm wondering why the notifications aren't working properly there? | 18:59 |
cmurphy | makes me uneasy to be adding new foreign keys there even though i know that ship has sailed with the resource driver | 18:59 |
lbragstad | #startmeeting keystone-office-hours | 19:00 |
openstack | Meeting started Tue Jan 23 19:00:23 2018 UTC and is due to finish in 60 minutes. The chair is lbragstad. Information about MeetBot at http://wiki.debian.org/MeetBot. | 19:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 19:00 |
*** openstack changes topic to " (Meeting topic: keystone-office-hours)" | 19:00 | |
*** ChanServ changes topic to "Queens release schedule: https://releases.openstack.org/queens/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/5F0h9Hoe/keystone" | 19:00 | |
*** abhishek has quit IRC | 19:00 | |
openstack | The meeting name has been set to 'keystone_office_hours' | 19:00 |
*** abhi89 has quit IRC | 19:00 | |
knikolla | o/ | 19:00 |
*** rderose has quit IRC | 19:02 | |
hrybacki | lbragstad: bluejeans.com/u/hrybacki ? | 19:03 |
*** david-lyle has joined #openstack-keystone | 19:04 | |
kmalloc | lbragstad: not sure why it's doing that | 19:15 |
kmalloc | the notifications not working that is | 19:15 |
cmurphy | maybe samueldmq remembers | 19:17 |
*** links has quit IRC | 19:19 | |
lbragstad | hrybacki: https://github.com/openstack/keystone/blob/master/keystone/common/sql/contract_repo/versions/036_contract_rename_application_credential_restriction_column.py#L30-L32 | 19:25 |
cmurphy | so https://review.openstack.org/#/c/536869/ passes in the gate but i'd like to double-check with hwoarang and evrardjp in the europe morning that it solves the issue they were seeing | 19:25 |
cmurphy | oh nm hwoarang +1'd it | 19:27 |
lbragstad | cmurphy: you recreated this using mariadb 10.2 | 19:28 |
cmurphy | lbragstad: yes | 19:28 |
lbragstad | cool | 19:29 |
lbragstad | so your fix is designed to work from a top down run and isolating that migration specifically | 19:29 |
lbragstad | (e.g. as operator should get the fix if they run keystone-manage db_sync or if they target migration 036 again) | 19:30 |
lbragstad | s/as/an/ | 19:30 |
cmurphy | yes if an operator ran into this they would have expand and migrate on version 36 and contract stuck on 35 | 19:31 |
cmurphy | so this would get them unstuck from that state | 19:32 |
lbragstad | got it | 19:32 |
*** harlowja has joined #openstack-keystone | 19:34 | |
*** phalmos has joined #openstack-keystone | 19:35 | |
*** aojea has joined #openstack-keystone | 19:45 | |
*** phalmos_ has joined #openstack-keystone | 19:50 | |
ayoung | lbragstad, cmurphy I was in another meeting during the Keystone one...is there anything I can help move along? | 19:51 |
*** phalmos has quit IRC | 19:51 | |
knikolla | lbragstad: besides a few minor questions on https://review.openstack.org/#/c/525687/ i kicked through the other ones for keystone server. | 19:52 |
ayoung | for example: https://review.openstack.org/#/c/536869/ | 19:52 |
cmurphy | ayoung: yes please review that one, makes me nervous since i introduced the bug in the first place | 19:53 |
ayoung | cmurphy, you have not really arrived until you've generated a CVE | 19:53 |
cmurphy | :) | 19:54 |
ayoung | cmurphy, walk me through it, please | 19:55 |
ayoung | what is 'restricted'? | 19:55 |
cmurphy | ayoung: unrestricted is the new name for the application credential property that was called allow_application_credential_creation in http://specs.openstack.org/openstack/keystone-specs/specs/keystone/queens/application-credentials.html#limitations-imposed | 19:56 |
ayoung | er./..unrestricted. I see it is a column that got dropeed from the table | 19:57 |
cmurphy | the reason for renaming it is in the commit message here https://review.openstack.org/#/c/536347/ | 19:58 |
*** aojea has quit IRC | 19:58 | |
ayoung | cmurphy, this is bringing up memories of unified delegation | 19:59 |
ayoung | "can be used to delete other application credentials and whether it can create and delete trusts" | 19:59 |
cmurphy | it is hacky | 20:00 |
ayoung | cmurphy, so this is why I wanted us to reuse the user/trust mechanism for application credentials. You are going to become an expert on a new auth mechanism, and only you are really going to grok in fully | 20:01 |
ayoung | There are lots of gotcha's like this... | 20:01 |
ayoung | but the change you made seems ok. For the positive thread, this will be a non issue | 20:01 |
ayoung | we see that in check | 20:01 |
cmurphy | ayoung: the majority of my earlier patchsets had this entirely built on trusts, but there were issues with reusing them | 20:01 |
ayoung | cmurphy, no silver bullet...I'm aware | 20:02 |
ayoung | this seems ok | 20:02 |
*** aojea has joined #openstack-keystone | 20:02 | |
*** aojea has quit IRC | 20:02 | |
ayoung | cmurphy, is this column a key or something? | 20:02 |
*** aojea has joined #openstack-keystone | 20:02 | |
ayoung | its not, right? | 20:02 |
cmurphy | ayoung: no it's not | 20:02 |
ayoung | we should stop supporting sqlite | 20:03 |
ayoung | there was a move to run mysql with a ramdisk data store at one point...would deal with the speed issues | 20:04 |
cmurphy | sqlite has been making me very sad the last few days :( | 20:04 |
ayoung | cmurphy, +2 from me. I think this patch is OK. As you say, there is no data yet | 20:04 |
cmurphy | thanks ayoung | 20:05 |
cmurphy | ayoung: lbragstad made a dashboard for other priority reviews https://goo.gl/NWdAH7 | 20:05 |
ayoung | dstanek, ! | 20:06 |
*** sambetts is now known as sambetts|afk | 20:06 | |
ayoung | He has not really been working on that one, tho, has he | 20:06 |
cmurphy | he showed up today and said he'd take a look | 20:06 |
*** itlinux has joined #openstack-keystone | 20:07 | |
*** edmondsw has quit IRC | 20:08 | |
*** edmondsw has joined #openstack-keystone | 20:09 | |
*** Suramya_ has quit IRC | 20:12 | |
*** Suramya has quit IRC | 20:12 | |
*** edmondsw has quit IRC | 20:13 | |
*** edmondsw has joined #openstack-keystone | 20:15 | |
*** chason has quit IRC | 20:16 | |
*** edmondsw has quit IRC | 20:19 | |
lbragstad | cmurphy: i'm having a hell of a time getting mariadb 10.2. setup | 20:24 |
lbragstad | apparently upgrading from mysql to maria is problematic | 20:24 |
cmurphy | lbragstad: heh | 20:24 |
cmurphy | lbragstad: so what i did was created an opensuse tumbleweed vm | 20:25 |
cmurphy | which has mariadb 10.2 | 20:25 |
lbragstad | that's easy | 20:25 |
ayoung | cmurphy, why workflow -1 on https://review.openstack.org/#/c/524423/39 | 20:25 |
*** aojea has quit IRC | 20:26 | |
cmurphy | ayoung: i wanted the db bugfix to make it in first | 20:26 |
*** edmondsw has joined #openstack-keystone | 20:26 | |
ayoung | k | 20:26 |
ayoung | gagehugo, Care to pull the trigger on that? | 20:26 |
ayoung | https://review.openstack.org/#/c/536869/1 | 20:26 |
cmurphy | i think lbragstad is doing his best to manually verify that one | 20:27 |
gagehugo | ayoung looking | 20:27 |
*** chason has joined #openstack-keystone | 20:28 | |
*** mvenesio_ has quit IRC | 20:32 | |
*** panbalag has joined #openstack-keystone | 20:35 | |
*** panbalag has left #openstack-keystone | 20:39 | |
*** mvenesio has joined #openstack-keystone | 20:39 | |
ayoung | cmurphy, we're eon the sql change. why not drop the workflow - on https://review.openstack.org/#/c/524423/39 | 20:41 |
*** mvenesio has quit IRC | 20:43 | |
ayoung | I think we can push through app creds relatively quickly now. | 20:45 |
*** rmascena has quit IRC | 20:47 | |
cmurphy | ayoung: i'm just worried if it lands in the wrong order then we can't claim with certainty that someone doesn't have data in that table | 20:58 |
ayoung | cmurphy, can't have data without the API, right? | 20:58 |
ayoung | We would not support a sql load for data | 20:58 |
*** itlinux has quit IRC | 20:59 | |
cmurphy | ayoung: right, but when https://review.openstack.org/#/c/524423/39 lands then we have an API | 20:59 |
*** nicolasbock has joined #openstack-keystone | 20:59 | |
ayoung | cmurphy, make that review depend on the SQL change then | 21:00 |
cmurphy | i can do that, i just didn't want to respin the whole stack | 21:00 |
cmurphy | but that's not a problem for me | 21:00 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add Application Credentials controller https://review.openstack.org/524423 | 21:03 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add application credential auth plugin https://review.openstack.org/525346 | 21:03 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add api-ref for application credentials https://review.openstack.org/533744 | 21:03 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Enable application_credential auth by default https://review.openstack.org/535469 | 21:03 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Impose limits on application credentials https://review.openstack.org/536543 | 21:03 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add a release note for application credentials https://review.openstack.org/535493 | 21:03 |
*** pramodrj07 has joined #openstack-keystone | 21:03 | |
*** mvk has joined #openstack-keystone | 21:04 | |
lbragstad | omg - database upgrade problems are the bane of my existence... | 21:07 |
* lbragstad just finished scrubbing all remnants of mysql-server and mariadb from his system | 21:08 | |
cmurphy | computers are the worst | 21:08 |
lbragstad | that was super weird... | 21:09 |
lbragstad | i got hung up in some weird state between upgrading from mysql 5.7 to maria 10.0.33 to maria 10.2 | 21:09 |
lbragstad | i could remove packages | 21:09 |
gagehugo | ew | 21:10 |
lbragstad | i couldn't* remove packages | 21:10 |
lbragstad | or finish a clean install | 21:10 |
* gagehugo just followed cmurphy's advice and used a tumbleweed vm | 21:10 | |
lbragstad | but the database service (not sure which version was running) just kept asking for passwords | 21:10 |
lbragstad | then things wouldn't start | 21:10 |
lbragstad | i guess the answer is to process the dependency tree and force purge packages | 21:11 |
lbragstad | and then manually remove configuration directories | 21:11 |
lbragstad | (because apparently purge doesn't do that either) | 21:11 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add Application Credentials controller https://review.openstack.org/524423 | 21:12 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add application credential auth plugin https://review.openstack.org/525346 | 21:12 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add api-ref for application credentials https://review.openstack.org/533744 | 21:12 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Enable application_credential auth by default https://review.openstack.org/535469 | 21:12 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Impose limits on application credentials https://review.openstack.org/536543 | 21:12 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add a release note for application credentials https://review.openstack.org/535493 | 21:12 |
gagehugo | lbragstad did you get it working? | 21:14 |
lbragstad | nope.. | 21:15 |
lbragstad | \o/ | 21:15 |
lbragstad | but... what I *do* have is a development box without a database | 21:15 |
lbragstad | now that i don't have any configuration for a database, i might try installing it again | 21:16 |
*** edmondsw has quit IRC | 21:33 | |
*** edmondsw has joined #openstack-keystone | 21:33 | |
*** edmondsw has quit IRC | 21:38 | |
*** dave-mccowan has quit IRC | 21:43 | |
lbragstad | alright - i'm going to respin the system-scope patches and worry about mariadb 10.2 later | 21:55 |
cmurphy | lol | 22:01 |
*** dave-mccowan has joined #openstack-keystone | 22:02 | |
lbragstad | #endmeeting | 22:05 |
*** openstack changes topic to "Queens release schedule: https://releases.openstack.org/queens/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/5F0h9Hoe/keystone" | 22:05 | |
openstack | Meeting ended Tue Jan 23 22:05:21 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 22:05 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/keystone_office_hours/2018/keystone_office_hours.2018-01-23-19.00.html | 22:05 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/keystone_office_hours/2018/keystone_office_hours.2018-01-23-19.00.txt | 22:05 |
openstack | Log: http://eavesdrop.openstack.org/meetings/keystone_office_hours/2018/keystone_office_hours.2018-01-23-19.00.log.html | 22:05 |
*** rcernin has joined #openstack-keystone | 22:15 | |
lbragstad | ok - i have a database back.. | 22:23 |
lbragstad | https://codefiddle.wordpress.com/2015/12/14/recover-mysql-remove-error/ | 22:23 |
lbragstad | ^ that's what i hit... | 22:23 |
*** jessegler has quit IRC | 22:24 | |
cmurphy | fun | 22:25 |
lbragstad | yeah - super weird because it bricks you from upgrading, but you can uninstall either.. | 22:26 |
lbragstad | so reverting back to 5.7 isn't really an option | 22:26 |
lbragstad | unless you rescrub everything | 22:27 |
*** dave-mccowan has quit IRC | 22:37 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system-scoped tokens https://review.openstack.org/525687 | 22:39 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add release note for system-scope https://review.openstack.org/528039 | 22:41 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Update documentation to reflect system-scope https://review.openstack.org/530133 | 22:41 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Grant admin a role on the system during bootstrap https://review.openstack.org/530410 | 22:41 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement GET /v3/auth/system https://review.openstack.org/530490 | 22:41 |
lbragstad | cmurphy: do you mind if i move https://review.openstack.org/#/c/536869/1 through since it was verified on OSA? | 22:44 |
lbragstad | and we can sync up with evrardjp in the morning? | 22:45 |
cmurphy | lbragstad: yes that's fine, i'm happy hwoarang verified it | 22:46 |
lbragstad | ok - cool | 22:46 |
*** cburgess has quit IRC | 23:00 | |
*** cburgess has joined #openstack-keystone | 23:01 | |
*** mvk has quit IRC | 23:02 | |
*** masber has quit IRC | 23:14 | |
*** mvk has joined #openstack-keystone | 23:17 | |
*** spilla has quit IRC | 23:24 | |
lbragstad | gagehugo: cmurphy thanks for reviewing the unified limit stuff | 23:30 |
cmurphy | no problem | 23:31 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system-scoped tokens https://review.openstack.org/525687 | 23:34 |
openstackgerrit | Lance Bragstad proposed openstack/python-keystoneclient master: Add system role functionality https://review.openstack.org/524415 | 23:38 |
lbragstad | dstanek: any luck with https://review.openstack.org/#/c/126030/25 ? | 23:43 |
gagehugo | :) | 23:43 |
cmurphy | i think i've reviewed everything i can for now, will check for updates in the morning | 23:44 |
lbragstad | thanks cmurphy | 23:50 |
*** dave-mccowan has joined #openstack-keystone | 23:51 | |
lbragstad | we might be able to start queuing up the scope types changes since the unified limit stuff needs a respin, system scope stuff is gating, and so is application credential stuff | 23:52 |
*** ayoung has left #openstack-keystone | 23:59 | |
*** ayoung has quit IRC | 23:59 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!