*** zhurong has joined #openstack-keystone | 00:20 | |
*** kmalloc has quit IRC | 00:29 | |
*** zhurong has quit IRC | 00:37 | |
*** Dinesh_Bhor has joined #openstack-keystone | 00:37 | |
*** markvoelker has quit IRC | 00:43 | |
*** markvoelker has joined #openstack-keystone | 00:44 | |
*** Dinesh_Bhor has quit IRC | 00:47 | |
*** markvoelker has quit IRC | 00:48 | |
*** zhurong has joined #openstack-keystone | 00:50 | |
*** Dinesh_Bhor has joined #openstack-keystone | 00:51 | |
*** Dinesh_Bhor has quit IRC | 01:01 | |
*** r-daneel has quit IRC | 01:04 | |
*** rcernin has joined #openstack-keystone | 01:09 | |
*** dave-mccowan has joined #openstack-keystone | 01:13 | |
*** Neptu_ has quit IRC | 01:13 | |
*** Neptu has joined #openstack-keystone | 01:16 | |
*** gongysh has joined #openstack-keystone | 01:19 | |
*** markvoelker has joined #openstack-keystone | 01:30 | |
*** zhongjun has joined #openstack-keystone | 01:34 | |
openstackgerrit | wangqiang-bj proposed openstack/keystone master: add 'tags' in request body of projects https://review.openstack.org/537762 | 01:41 |
---|---|---|
*** Dinesh_Bhor has joined #openstack-keystone | 02:02 | |
*** gongysh has quit IRC | 02:03 | |
*** Dinesh_Bhor has quit IRC | 02:05 | |
*** Dinesh_Bhor has joined #openstack-keystone | 02:05 | |
lbragstad | wxy: o/ | 02:07 |
lbragstad | i have a couple patches up to document limits https://review.openstack.org/#/c/538312 and https://review.openstack.org/#/c/538322 | 02:07 |
*** Dinesh_Bhor has quit IRC | 02:08 | |
wxy | lbragstad: yeah, I saw it. I left comment there for `user_id` | 02:08 |
wxy | lbragstad, have you saw that? | 02:09 |
lbragstad | checking | 02:09 |
wxy | https://review.openstack.org/#/c/538312 this one. | 02:09 |
lbragstad | oh - yeah.. good point | 02:10 |
lbragstad | i can make some adjustment to clarify that | 02:10 |
wxy | otherwise they are both awesome. You know, I can't write this kind of doc unobstructed in English. ;) | 02:11 |
*** harlowja has quit IRC | 02:15 | |
lbragstad | i just wanted to make sure you reviewed the model one for sure | 02:20 |
wxy | lbragstad: I think it's good. But I'm not sure we should land it now since the related quota model and APIs code have not been added to Keystone yet. | 02:23 |
lbragstad | which parts? | 02:29 |
wxy | https://review.openstack.org/#/c/538322 ``GET /limits-model`` | 02:30 |
lbragstad | oh yeah | 02:30 |
lbragstad | i can make that more apparent in the NOTE | 02:34 |
wxy | lbragstad: cool. | 02:35 |
*** rcernin has quit IRC | 02:35 | |
lbragstad | wxy: since you were the master mind behind the unified limit implementation, do you have any cleanup bits you wanna do as rocky opens? | 02:43 |
lbragstad | or do you have any ideas about how things should look as we start working on the enforcement models stuff? | 02:43 |
wxy | lbragstad: this is what I'm think these days. I'll update the spec about it. I'm sure it'll be done before PTG. | 02:45 |
*** d0ugal has quit IRC | 02:50 | |
lbragstad | cool | 02:53 |
*** Dinesh_Bhor has joined #openstack-keystone | 02:55 | |
*** Pramod has quit IRC | 03:05 | |
*** Dinesh_Bhor has quit IRC | 03:06 | |
*** mgagne has quit IRC | 03:22 | |
*** melwitt has quit IRC | 03:23 | |
*** chris_hultin has quit IRC | 03:23 | |
*** jamielennox has quit IRC | 03:23 | |
*** mgagne has joined #openstack-keystone | 03:24 | |
*** chris_hultin|AWA has joined #openstack-keystone | 03:24 | |
*** mgagne is now known as Guest87240 | 03:24 | |
*** chris_hultin|AWA is now known as chris_hultin | 03:24 | |
*** melwitt has joined #openstack-keystone | 03:25 | |
*** jamielennox has joined #openstack-keystone | 03:29 | |
*** zhurong has quit IRC | 03:46 | |
*** david-lyle has quit IRC | 04:26 | |
*** david-lyle has joined #openstack-keystone | 04:27 | |
*** dave-mccowan has quit IRC | 04:32 | |
*** vish_18 has quit IRC | 04:37 | |
*** rcernin has joined #openstack-keystone | 04:50 | |
*** harlowja has joined #openstack-keystone | 04:51 | |
*** rcernin has quit IRC | 04:51 | |
*** rcernin has joined #openstack-keystone | 04:52 | |
*** markvoelker has quit IRC | 05:06 | |
*** links has joined #openstack-keystone | 05:07 | |
*** jose-phillips has quit IRC | 05:13 | |
*** jose-phi_ has joined #openstack-keystone | 05:13 | |
*** mylu has quit IRC | 05:24 | |
*** zhurong has joined #openstack-keystone | 05:47 | |
*** threestrands has quit IRC | 05:51 | |
*** threestrands has joined #openstack-keystone | 06:01 | |
*** threestrands has joined #openstack-keystone | 06:01 | |
*** daidv has quit IRC | 06:08 | |
*** zhurong has quit IRC | 06:49 | |
*** wangqiang has joined #openstack-keystone | 06:57 | |
*** wangqiang has quit IRC | 07:00 | |
*** harlowja has quit IRC | 07:01 | |
*** itlinux has joined #openstack-keystone | 07:02 | |
*** wangqiangbj has joined #openstack-keystone | 07:06 | |
*** wangqiangbj has quit IRC | 07:07 | |
*** rcernin has quit IRC | 07:08 | |
*** markvoelker has joined #openstack-keystone | 07:11 | |
*** itlinux has quit IRC | 07:15 | |
*** jaosorior has quit IRC | 07:26 | |
*** gongysh has joined #openstack-keystone | 07:29 | |
*** gongysh has quit IRC | 07:35 | |
*** zhurong has joined #openstack-keystone | 07:38 | |
*** markvoelker has quit IRC | 07:42 | |
*** jaosorior has joined #openstack-keystone | 07:43 | |
*** daidv has joined #openstack-keystone | 07:46 | |
*** pcaruana has joined #openstack-keystone | 07:51 | |
*** AlexeyAbashkin has joined #openstack-keystone | 07:51 | |
*** AlexeyAbashkin has quit IRC | 07:51 | |
*** AlexeyAbashkin has joined #openstack-keystone | 07:52 | |
openstackgerrit | Merged openstack/keystone master: Fix federation unit test https://review.openstack.org/531599 | 08:15 |
*** rcernin has joined #openstack-keystone | 08:16 | |
*** tesseract has joined #openstack-keystone | 08:20 | |
*** itlinux has joined #openstack-keystone | 08:21 | |
*** rcernin has quit IRC | 08:26 | |
openstackgerrit | Merged openstack/keystone master: Handle TZ change in iso8601 >=0.1.12 https://review.openstack.org/538263 | 08:27 |
*** sinese has joined #openstack-keystone | 08:37 | |
*** markvoelker has joined #openstack-keystone | 08:39 | |
*** zhurong_ has joined #openstack-keystone | 08:47 | |
*** edmondsw has joined #openstack-keystone | 08:50 | |
*** wangqiang has joined #openstack-keystone | 08:53 | |
*** namnh has joined #openstack-keystone | 08:54 | |
*** edmondsw has quit IRC | 08:54 | |
*** lxnch_ has quit IRC | 08:56 | |
*** d0ugal has joined #openstack-keystone | 09:05 | |
*** rcernin has joined #openstack-keystone | 09:05 | |
*** markvoelker has quit IRC | 09:12 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Delete SQL users before deleting domain https://review.openstack.org/539347 | 09:16 |
*** abhi89 has joined #openstack-keystone | 09:27 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Delete SQL users before deleting domain https://review.openstack.org/539347 | 09:31 |
abhi89 | cmurphy: Hi Colleen | 09:34 |
cmurphy | abhi89: hi | 09:36 |
abhi89 | i have gone through your video on federated identity & I have a doubt.. | 09:37 |
abhi89 | cmurphy: to get a token we need both username & password.. in federated identity, we get saml assertion saying that the user has been authenticated & then we map the response to format which keystone understands.. but we still don't have the password to get token.. how is this handled? i mean how do we get the token from keystone even though we didnot get password from IdP.. | 09:37 |
cmurphy | abhi89: when you're using a federated auth method you don't need a password to get a token any more | 09:40 |
cmurphy | abhi89: when the federated auth is complete you get an unscoped token, and then you can use the token auth method instead of the password auth method to get a scoped token | 09:42 |
abhi89 | cmurphy: i use /v3/auth/tokens api to get token.. is there any special federated api to get the unscoped token you mentioned | 09:44 |
cmurphy | abhi89: yes there is, it will be either https://developer.openstack.org/api-ref/identity/v3-ext/#request-an-unscoped-os-federation-token or https://developer.openstack.org/api-ref/identity/v3-ext/#web-single-sign-on-authentication-new-in-version-1-2 and those are the locations you'll need to protect with mod_shib or mod_mellon in your apache config | 09:46 |
cmurphy | like so http://www.gazlene.net/demystifying-keystone-federation.html#set-up-apache | 09:47 |
abhi89 | cmurphy: oh ok.. thanks for the info.. on more thing.. we are trying to get federated identity in our openstack based solution.. we use our own dashboard & not horizon.. so will this make any difference.. i mean we can still achieve the federation with just CLI right? | 09:50 |
cmurphy | abhi89: yes it does work with the CLI | 09:50 |
cmurphy | and you can look at horizon to see how it works with federation if you want to implement it, it's pretty simple | 09:51 |
cmurphy | abhi89: well, correction, SAML auth works with the CLI, OpenIDC does not really work | 09:52 |
abhi89 | cmurphy: we will be using SAML and not openIDC so we are good there | 09:52 |
cmurphy | cool | 09:55 |
abhi89 | thanks a lot for the info :) | 09:55 |
cmurphy | no problem | 09:55 |
*** markvoelker has joined #openstack-keystone | 10:09 | |
*** annp has quit IRC | 10:14 | |
*** namnh has quit IRC | 10:15 | |
*** zhurong has quit IRC | 10:19 | |
*** bhagyashri_s is now known as bhagyashris | 10:24 | |
*** sambetts|afk is now known as sambetts | 10:27 | |
*** abhi89 has quit IRC | 10:41 | |
*** markvoelker has quit IRC | 10:42 | |
*** josecastroleon has joined #openstack-keystone | 10:46 | |
*** zhurong_ has quit IRC | 10:48 | |
*** wangqiang has quit IRC | 10:51 | |
*** belmoreira has joined #openstack-keystone | 10:52 | |
*** mvk has quit IRC | 11:01 | |
*** jmlowe has quit IRC | 11:02 | |
*** AlexeyAbashkin has quit IRC | 11:09 | |
*** AlexeyAbashkin has joined #openstack-keystone | 11:15 | |
*** sinese has quit IRC | 11:17 | |
*** mvk has joined #openstack-keystone | 11:30 | |
*** markvoelker has joined #openstack-keystone | 11:39 | |
*** dmellado has joined #openstack-keystone | 11:40 | |
dmellado | Hi everyone | 11:40 |
dmellado | could anyone tell me if it's possible to have devstack create the fallback 5000 and 35357 endpoints? | 11:40 |
*** itlinux has quit IRC | 11:55 | |
*** Supun has joined #openstack-keystone | 11:58 | |
*** threestrands has quit IRC | 12:08 | |
*** dave-mccowan has joined #openstack-keystone | 12:09 | |
*** raildo has joined #openstack-keystone | 12:12 | |
*** markvoelker has quit IRC | 12:12 | |
cmurphy | dmellado: i think if you set KEYSTONE_DEPLOY=mod_wsgi then it uses the ports instead of the uwsgi proxy | 12:19 |
dmellado | cmurphy: I'll be giving it a try, thanks! | 12:20 |
cmurphy | no problem | 12:20 |
*** rcernin has quit IRC | 12:58 | |
*** markvoelker has joined #openstack-keystone | 13:09 | |
*** edmondsw has joined #openstack-keystone | 13:22 | |
*** mvenesio has joined #openstack-keystone | 13:23 | |
*** Supun has quit IRC | 13:26 | |
*** mvenesio has quit IRC | 13:34 | |
*** mvenesio has joined #openstack-keystone | 13:34 | |
*** markvoelker has quit IRC | 13:37 | |
*** alex_xu has quit IRC | 13:37 | |
*** markvoelker has joined #openstack-keystone | 13:37 | |
*** alex_xu has joined #openstack-keystone | 13:39 | |
*** Supun has joined #openstack-keystone | 13:45 | |
*** gongysh has joined #openstack-keystone | 13:49 | |
*** abhi89 has joined #openstack-keystone | 13:53 | |
*** panbalag has joined #openstack-keystone | 13:53 | |
*** panbalag has left #openstack-keystone | 14:00 | |
*** itlinux has joined #openstack-keystone | 14:02 | |
*** sinese has joined #openstack-keystone | 14:02 | |
*** jmlowe has joined #openstack-keystone | 14:04 | |
*** pcaruana has quit IRC | 14:05 | |
*** Supun has quit IRC | 14:07 | |
*** Supun has joined #openstack-keystone | 14:11 | |
*** tobberydberg__ has joined #openstack-keystone | 14:15 | |
*** tobberydberg__ has quit IRC | 14:15 | |
*** tobberydberg__ has joined #openstack-keystone | 14:16 | |
*** pcaruana has joined #openstack-keystone | 14:21 | |
*** sxc731_ has joined #openstack-keystone | 14:23 | |
*** links has quit IRC | 14:27 | |
*** sxc731_ has quit IRC | 14:28 | |
*** sxc731_ has joined #openstack-keystone | 14:38 | |
*** sxc731_ has quit IRC | 14:42 | |
lbragstad | now that we're officially past library freeze | 14:42 |
lbragstad | these are probably going to have to wait until Rocky https://review.openstack.org/#/c/524416/ and https://review.openstack.org/#/c/481284/ | 14:42 |
lbragstad | unfortunately... | 14:42 |
lbragstad | https://review.openstack.org/#/c/526189/ should be ready for another review | 14:46 |
lbragstad | same with https://review.openstack.org/#/c/526171/ | 14:46 |
lbragstad | and https://review.openstack.org/#/c/526197/ https://review.openstack.org/#/c/526203/ and https://review.openstack.org/#/c/525701/ | 14:46 |
lbragstad | that should take care of everything for feature freeze... the application credential stuff is scarily close to actually merging :) | 14:47 |
*** sxc731_ has joined #openstack-keystone | 14:47 | |
*** spilla has joined #openstack-keystone | 14:47 | |
cmurphy | don't say that you'll jinx it | 14:48 |
*** pcaruana has quit IRC | 14:48 | |
dmellado | heh | 14:49 |
cmurphy | crossing all of my limbs that the auth plugin makes it in and if anything else fails i'm just going to unparent the release note patch and get that in and call it done | 14:49 |
*** abhi89 has quit IRC | 14:49 | |
*** sxc731_ has quit IRC | 14:53 | |
lbragstad | i hear ya... | 14:55 |
*** sxc731 has joined #openstack-keystone | 14:55 | |
lbragstad | i mean - the rest of the stuff outside of that is just scope_types | 14:56 |
lbragstad | which can be added anytime really... | 14:56 |
*** Supun has quit IRC | 14:56 | |
openstackgerrit | Merged openstack/keystone master: Use native Zuul v3 tox job https://review.openstack.org/537787 | 14:58 |
*** sxc731 has quit IRC | 14:59 | |
dmellado | hmmm lbragstad cmurphy I'm not sure if I'm doing some odd thing but adding KEYSTONE_DEPLOY=mod_wsgi to my local.conf | 15:01 |
dmellado | is still adding uwsgi | 15:01 |
dmellado | am I missing something? | 15:01 |
*** sxc731 has joined #openstack-keystone | 15:02 | |
bhagyashris | Hi team can any one please tell me where i will catch Morgan Fainberg | 15:02 |
cmurphy | dmellado: not sure :/ i found that by looking at lib/keystone in devstack but i haven't tried to make it work in a while | 15:03 |
lbragstad | it could be an issue with devstack, too... i'm not sure | 15:03 |
cmurphy | bhagyashris: he's kmalloc on irc, i think he's on vacation this week and doesn't seem to be online | 15:04 |
cmurphy | bhagyashris: is there something we can help you with? | 15:04 |
dmellado | cmurphy: lbragstad for the record, this is my dreaded local.conf | 15:05 |
dmellado | https://paste.fedoraproject.org/paste/KVYgPtOLKIDp6kocF0xJgQ | 15:05 |
dmellado | I tired to be specific on the keystone bits | 15:05 |
bhagyashris | cmurphy: Actually i want to discuss with him regarding the comment given on patch https://review.openstack.org/#/c/505764/6 | 15:05 |
*** sxc731 has quit IRC | 15:05 | |
dmellado | tired/tried xD | 15:05 |
*** Supun has joined #openstack-keystone | 15:07 | |
bhagyashris | cmurphy: i have one question is it possible to alias the logger name when we log the messages using the logging.conf | 15:08 |
bhagyashris | cmurphy: i mean is there any provision we can alias the logger name? | 15:08 |
cmurphy | dmellado: yeah, sorry i'm not a devstack expert so i'm not sure what's up without running it myself | 15:09 |
cmurphy | bhagyashris: mordred would be a good person to ask about that | 15:09 |
dmellado | cmurphy: np! thanks for the hint in any case, I'm digging up into lib/apache now | 15:10 |
dmellado | mordred: any hint on that? ^^ | 15:10 |
bhagyashris | cmurphy: ok thank you :) | 15:10 |
bhagyashris | mordred: yeah | 15:10 |
lbragstad | dmellado: someone in #openstack-qa might be able to help there, too | 15:10 |
lbragstad | which is where most of the devstack folks hangout | 15:11 |
dmellado | andreaf: ^^ | 15:11 |
dmellado | lbragstad: thanks, sadly I know xD | 15:11 |
*** sxc731 has joined #openstack-keystone | 15:11 | |
dmellado | devstack changes just so much every time I need to do anything with it xD | 15:11 |
*** alex_xu has quit IRC | 15:11 | |
lbragstad | ah - yes it does | 15:11 |
cmurphy | dmellado: is there a reason you want to run it with ports instead of the default way? | 15:12 |
cmurphy | running on standard ports is encouraged | 15:12 |
dmellado | cmurphy: basically for the sake of backwards compatibility | 15:12 |
dmellado | I need to attach an appliance | 15:12 |
dmellado | which only has ip and port support | 15:12 |
dmellado | so no /foo | 15:12 |
cmurphy | ah :( | 15:12 |
dmellado | I tried port 80 and /identity but no luck | 15:12 |
*** alex_xu has joined #openstack-keystone | 15:13 | |
cmurphy | that should work :/ | 15:13 |
dmellado | my guess it doesn't work well with fqdn, just ips | 15:13 |
dmellado | and I thought that rather than try to attack the appliance itself it would be easier to tweak devstack | 15:14 |
*** pcaruana has joined #openstack-keystone | 15:14 | |
andreaf | dmellado: what's up? I haven't read the whole scroll-back yet | 15:14 |
*** sxc731 has quit IRC | 15:14 | |
dmellado | andreaf: o/ | 15:14 |
dmellado | basically I'm trying to set up a devstack with keystone and mod_wsgi | 15:14 |
dmellado | using KEYSTONE_DEPLOY=mod_wsgi | 15:15 |
dmellado | so I could get back the former 5000 and 35357 endpoints | 15:15 |
dmellado | so far it didn't work, using uwsgi even when I specified that | 15:15 |
dmellado | https://paste.fedoraproject.org/paste/KVYgPtOLKIDp6kocF0xJgQ | 15:15 |
dmellado | this is my fancy local.conf | 15:15 |
andreaf | dmellado: for the v2 api or v3? | 15:15 |
dmellado | hopefully, both | 15:16 |
dmellado | but I'd be fine with whichever | 15:16 |
dmellado | I tried v3 | 15:16 |
cmurphy | lbragstad: https://review.openstack.org/#/c/525346/ is about to fail tempest T.T | 15:16 |
* cmurphy dies | 15:16 | |
andreaf | because v2 had public and admin endpoints, which was the reason for the two ports if I remember correctly | 15:16 |
andreaf | dmellado: but in v3 there's no such distinction anymore | 15:17 |
lbragstad | cmurphy: you've gotta be kidding me... this is ridiculous | 15:17 |
dmellado | andreaf: yeah, but shouldn't it try to at least use mod_wsgi if specified instead of uwsgi? | 15:17 |
mordred | bhagyashris: morning! | 15:17 |
andreaf | dmellado: I don't think any job runs mod_wsgi so there's no guarantee it will work I fear | 15:17 |
* dmellado sighs | 15:18 | |
dmellado | I see, so it'd probably just stopped working at some point | 15:18 |
dmellado | will try to debug through it | 15:18 |
dmellado | thanks in any case andreaf | 15:18 |
mordred | bhagyashris: oh yeah - I keep forgetting - we need to add a constructor parameter to Session ... | 15:18 |
*** itlinux has quit IRC | 15:18 | |
andreaf | dmellado: np - but why do you need the two ports back if I may ask? | 15:19 |
dmellado | basically I need to hook up an appliance | 15:19 |
dmellado | which doesn't work well with the new /identity endpoint | 15:19 |
cmurphy | lbragstad: tempest.api.volume.admin.test_group_snapshots.GroupSnapshotsV319Test.test_reset_group_snapshot_status failed | 15:19 |
* cmurphy kicks cinder | 15:19 | |
dmellado | so I just wanted to get back to the deprecated 5000 and 35357 | 15:19 |
*** Supun has quit IRC | 15:22 | |
cmurphy | lbragstad: oh wait, it's queued behind another cinder change, maybe it'll get a chance to rerun without losing its place in line | 15:22 |
lbragstad | so - the check queue is running at about 5 hours rightn ow | 15:22 |
lbragstad | cmurphy: i hope you're right | 15:23 |
lbragstad | i'm not up-to-date the how zuul does queuing | 15:23 |
lbragstad | in cases like this | 15:24 |
*** david-lyle has quit IRC | 15:24 | |
*** dklyle has joined #openstack-keystone | 15:24 | |
mordred | lbragstad: in the gate, it makes a virtual serial queue containing approved changes for everything that is in the 'integrated' queue | 15:26 |
*** Guest87240 is now known as mgagne | 15:27 | |
*** mgagne has joined #openstack-keystone | 15:27 | |
lbragstad | mordred: we have a change we've been trying to get through the gate for a week https://review.openstack.org/#/c/525346/ | 15:27 |
lbragstad | and it tripped over an unrelated thing again | 15:28 |
mordred | lbragstad: then it tests those changes in parallel, assuming that changes are going to pass - however, if a change ahead of you in the queue fails, zuul ejects it from the queue and rebuilds the queue behind the failure | 15:28 |
lbragstad | damn... | 15:28 |
mordred | lbragstad: yah - it's not been a good week | 15:28 |
cmurphy | i'm hoping that 538314 fails so it can run again | 15:28 |
cmurphy | sorry cinder | 15:28 |
mordred | cmurphy: :) | 15:28 |
lbragstad | can we come up with a James Marsden award for features? | 15:29 |
openstackgerrit | Monty Taylor proposed openstack/keystoneauth master: Split request logging into four different loggers https://review.openstack.org/505764 | 15:33 |
*** Supun has joined #openstack-keystone | 15:33 | |
mordred | bhagyashris: cmurphy: ^^ I think that sohuld address morgan's concerns | 15:34 |
*** links has joined #openstack-keystone | 15:35 | |
cmurphy | thanks mordred | 15:36 |
*** abhi89 has joined #openstack-keystone | 15:38 | |
*** abhishek has joined #openstack-keystone | 15:42 | |
*** phalmos has joined #openstack-keystone | 15:45 | |
*** abhi89 has quit IRC | 15:45 | |
*** jose-phi_ has quit IRC | 16:01 | |
*** abhishek has quit IRC | 16:02 | |
lbragstad | ping raildo, ktychkova, rderose, htruta, hrybacki, atrmr, gagehugo, lamt, thinrichs, edmondsw, ruan_he, ayoung, kmalloc, raj_singh, johnthetubaguy, knikolla, nhelgeson | 16:04 |
lbragstad | reminder about the policy meeting in -cp | 16:04 |
*** Supun has quit IRC | 16:06 | |
*** Supun has joined #openstack-keystone | 16:06 | |
*** efried_hexchat has quit IRC | 16:08 | |
*** daidv has quit IRC | 16:09 | |
*** belmoreira has quit IRC | 16:10 | |
*** daidv has joined #openstack-keystone | 16:11 | |
*** phalmos has quit IRC | 16:11 | |
*** belmoreira has joined #openstack-keystone | 16:18 | |
*** Supun has quit IRC | 16:21 | |
*** prometheanfire has left #openstack-keystone | 16:28 | |
*** r-daneel has joined #openstack-keystone | 16:29 | |
*** Supun has joined #openstack-keystone | 16:36 | |
*** gongysh has quit IRC | 16:38 | |
*** sinese has quit IRC | 16:39 | |
*** pcaruana has quit IRC | 16:39 | |
*** sinese has joined #openstack-keystone | 16:48 | |
*** daidv has quit IRC | 16:52 | |
*** sinese has quit IRC | 16:52 | |
*** daidv has joined #openstack-keystone | 16:53 | |
*** harlowja has joined #openstack-keystone | 17:02 | |
*** belmoreira has quit IRC | 17:08 | |
*** phalmos has joined #openstack-keystone | 17:08 | |
*** Supun has quit IRC | 17:11 | |
*** phalmos has quit IRC | 17:16 | |
lbragstad | cmurphy: knikolla notes sent | 17:16 |
lbragstad | cmurphy: when does https://review.openstack.org/#/c/525346/35 go back in the queue | 17:18 |
cmurphy | lbragstad: it's still in the queue | 17:19 |
cmurphy | it's stuck behind a hung cinder job | 17:19 |
* lbragstad is waiting with a fresh recheck | 17:19 | |
lbragstad | i wonder if using RECHECK versus recheck will make a different | 17:20 |
lbragstad | recheck harder! | 17:20 |
knikolla | haha | 17:20 |
knikolla | recheck, please? | 17:20 |
lbragstad | recheck kthxbye | 17:20 |
*** links has quit IRC | 17:21 | |
*** AlexeyAbashkin has quit IRC | 17:23 | |
*** Supun has joined #openstack-keystone | 17:33 | |
*** tesseract has quit IRC | 17:45 | |
mordred | lbragstad, cmurphy: I was just updating the docs for the split-loggers patch after having added the flag to control it ... and I think I'd like to argue that the original no-flag version was not an breaking change due to the way python logging works | 17:48 |
mordred | lbragstad, cmurphy: currently (before the change) all session traffic is logged to 'keystoneauth.session' - the split change causes it to log to keystoneauth.session.request, keystoneauth.session.body, keystoneauth.session.response and keystoneauth.session.request-id | 17:49 |
mordred | the thing is - anyone who has been doing anything with logging related to the keystoneauth.session logger will still have the same results - since settings for keystoneauth.session apply to keystoneauth.session.* too | 17:50 |
*** rmcall has joined #openstack-keystone | 17:50 | |
*** rmcall has quit IRC | 17:51 | |
mordred | (I've obviously got the update to introduce a flag - but updating the docs made me think about whether it actually was a break or not) | 17:51 |
*** rmcall has joined #openstack-keystone | 17:51 | |
cmurphy | mordred: tbh i haven't looked closely at it but will do so | 17:51 |
openstackgerrit | Monty Taylor proposed openstack/keystoneauth master: Split request logging into four different loggers https://review.openstack.org/505764 | 17:52 |
mordred | cmurphy: there it is with updated docs and a fix for the test | 17:52 |
mordred | cmurphy: compare to PS6 for the 'is this or is this not a break needing the flag introduced in PS7/8' | 17:52 |
mordred | cmurphy: and thanks! | 17:52 |
cmurphy | sure thing | 17:53 |
breton | lbragstad: re https://review.openstack.org/#/c/525772/ | 17:54 |
breton | lbragstad: the patch is good, but | 17:54 |
breton | lbragstad: they use policy not only to check permissions for operations listed in policy.json or policies/ dir, but for some other | 17:57 |
lbragstad | for some other checks/ | 17:59 |
lbragstad | ? | 17:59 |
breton | lbragstad: for example https://github.com/openstack/nova/blob/c1442d3c8cf9ab8a3cc6fe7e169c71e39abe1faf/nova/network/floating_ips.py#L165 | 17:59 |
breton | lbragstad: yes | 17:59 |
breton | lbragstad: so they rely on policies in their code | 17:59 |
lbragstad | mmm yeah - that's going to be something we need to look at | 17:59 |
breton | lbragstad: my guess is that all their is_admin is system scope | 18:00 |
lbragstad | right | 18:00 |
lbragstad | because that's how they have to work around those issues today | 18:00 |
lbragstad | we took a similar approach when adding scope_types to our policies | 18:01 |
breton | lbragstad: but even with your patch project-admin will have is_admin=True | 18:01 |
lbragstad | right - because they still have the admin role, which trips that check | 18:01 |
breton | lbragstad: can we use scope type check in rules? Something like: "context_is_admin": "role:admin and scope:system"? | 18:02 |
lbragstad | breton: we have logic in oslo.policy to handle some of that | 18:03 |
lbragstad | which is enabled through configuration | 18:03 |
lbragstad | https://github.com/openstack/oslo.policy/blob/d72cc34d7a145d1091ca3f2f14e92007ffe16352/oslo_policy/policy.py#L847 | 18:03 |
lbragstad | which gives operators the ability to run things in a backwards compatible way until two things happen | 18:04 |
lbragstad | 1.) projects fix their policies to not queue of 'admin' | 18:04 |
lbragstad | 2.) operators audit their users and grant system level access to the people that need to access those APIs | 18:04 |
breton | ok. I haven't read the spec yet, so i'll go back to my Newton-based setup :p | 18:06 |
ayoung | breton, in newton you can use is_admin project and we'll figure some scripting to port that to service scoped roles in the future | 18:07 |
breton | ayoung: yep. But nova with its is_admin is still there. | 18:07 |
ayoung | ah...but we only got oslo-context working for Keystone this go-round...sorry, You'll need that | 18:07 |
ayoung | breton, oh, yea, you just need to rewrite all the policy rules everywhere | 18:07 |
* lbragstad breaks for lunch | 18:09 | |
*** Supun has quit IRC | 18:14 | |
*** AlexeyAbashkin has joined #openstack-keystone | 18:17 | |
*** phalmos has joined #openstack-keystone | 18:24 | |
*** mvenesio has quit IRC | 18:31 | |
*** mvenesio has joined #openstack-keystone | 18:45 | |
*** AlexeyAbashkin has quit IRC | 18:51 | |
*** mvk has quit IRC | 18:52 | |
*** harlowja has quit IRC | 18:52 | |
cmurphy | okay sweet the hanging cinder change was bumped from the queue so the keystone change is rerunning | 18:54 |
cmurphy | don't jinx it this time | 18:54 |
*** david-lyle_ has joined #openstack-keystone | 18:58 | |
*** dklyle has quit IRC | 19:01 | |
*** freerunner has quit IRC | 19:06 | |
*** NikitaKonovalov has quit IRC | 19:06 | |
*** DinaBelova has quit IRC | 19:06 | |
*** DinaBelova has joined #openstack-keystone | 19:07 | |
*** NikitaKonovalov has joined #openstack-keystone | 19:07 | |
*** freerunner has joined #openstack-keystone | 19:08 | |
*** david-lyle_ is now known as dklyle | 19:08 | |
*** tobberydberg__ has quit IRC | 19:14 | |
*** tobberydberg__ has joined #openstack-keystone | 19:15 | |
*** sambetts is now known as sambetts|afk | 19:19 | |
*** tobberydberg__ has quit IRC | 19:19 | |
* lbragstad stays quiet | 19:24 | |
*** DinaBelova has quit IRC | 19:29 | |
*** freerunner has quit IRC | 19:29 | |
*** NikitaKonovalov has quit IRC | 19:29 | |
*** aojea_ has joined #openstack-keystone | 19:36 | |
*** harlowja has joined #openstack-keystone | 19:37 | |
lbragstad | cmurphy: this might be getting ahead of ourselves | 19:38 |
lbragstad | but what would we replace baremetal/vm with for a name? | 19:38 |
lbragstad | cc johnthetubaguy ^ | 19:38 |
lbragstad | since i think he was the original one to coin the name :) | 19:38 |
cmurphy | it still applies if it's just nova/ironic that needs to talk | 19:39 |
lbragstad | in boston we had an etherpad for that group that had stuff for cinder/neutron on it, too | 19:40 |
cmurphy | idk maybe instead of selecting certain projects we should be selecting topics and then anyone it applies to should attend | 19:41 |
*** aojea__ has joined #openstack-keystone | 19:41 | |
lbragstad | yeah... | 19:41 |
*** gyee has joined #openstack-keystone | 19:42 | |
lbragstad | i'm terrible with naming things... but the question popped up in my head over lunch | 19:42 |
*** DinaBelova has joined #openstack-keystone | 19:42 | |
*** NikitaKonovalov has joined #openstack-keystone | 19:43 | |
*** freerunner has joined #openstack-keystone | 19:43 | |
*** aojea_ has quit IRC | 19:44 | |
*** aojea_ has joined #openstack-keystone | 19:47 | |
*** aojea__ has quit IRC | 19:49 | |
*** aojea__ has joined #openstack-keystone | 19:51 | |
*** tobberydberg__ has joined #openstack-keystone | 19:53 | |
*** tobberydberg__ has quit IRC | 19:54 | |
*** aojea_ has quit IRC | 19:54 | |
*** tobberydberg__ has joined #openstack-keystone | 19:55 | |
*** aojea_ has joined #openstack-keystone | 19:57 | |
*** aojea__ has quit IRC | 20:00 | |
*** aojea_ has quit IRC | 20:06 | |
*** rmascena has joined #openstack-keystone | 20:16 | |
*** DinaBelova has quit IRC | 20:17 | |
*** NikitaKonovalov has quit IRC | 20:17 | |
*** freerunner has quit IRC | 20:17 | |
*** DinaBelova has joined #openstack-keystone | 20:17 | |
*** NikitaKonovalov has joined #openstack-keystone | 20:18 | |
*** raildo has quit IRC | 20:19 | |
*** NikitaKonovalov has quit IRC | 20:21 | |
*** DinaBelova has quit IRC | 20:21 | |
*** DinaBelova has joined #openstack-keystone | 20:22 | |
*** NikitaKonovalov has joined #openstack-keystone | 20:22 | |
*** freerunner has joined #openstack-keystone | 20:23 | |
*** links has joined #openstack-keystone | 20:36 | |
*** DinaBelova has quit IRC | 20:39 | |
*** NikitaKonovalov has quit IRC | 20:39 | |
*** freerunner has quit IRC | 20:39 | |
*** DinaBelova has joined #openstack-keystone | 20:40 | |
*** NikitaKonovalov has joined #openstack-keystone | 20:41 | |
*** freerunner has joined #openstack-keystone | 20:41 | |
*** aojea_ has joined #openstack-keystone | 20:46 | |
*** aojea__ has joined #openstack-keystone | 20:51 | |
*** aojea_ has quit IRC | 20:54 | |
*** aojea_ has joined #openstack-keystone | 20:57 | |
*** tobberydberg__ has quit IRC | 20:58 | |
*** tobberydberg__ has joined #openstack-keystone | 20:58 | |
*** aojea__ has quit IRC | 21:00 | |
*** aojea__ has joined #openstack-keystone | 21:01 | |
*** aojea_ has quit IRC | 21:04 | |
*** aojea_ has joined #openstack-keystone | 21:07 | |
*** tobberydberg__ has quit IRC | 21:08 | |
*** tobberydberg__ has joined #openstack-keystone | 21:08 | |
*** aojea__ has quit IRC | 21:10 | |
*** aojea__ has joined #openstack-keystone | 21:12 | |
*** aojea_ has quit IRC | 21:14 | |
*** rmascena has quit IRC | 21:15 | |
*** aojea_ has joined #openstack-keystone | 21:16 | |
*** mvk has joined #openstack-keystone | 21:18 | |
*** aojea__ has quit IRC | 21:19 | |
*** mchlumsky has joined #openstack-keystone | 21:21 | |
*** aojea__ has joined #openstack-keystone | 21:22 | |
lbragstad | gagehugo: i assume you're good with this https://review.openstack.org/#/c/537762/3 ? | 21:24 |
openstackgerrit | Merged openstack/keystone master: Add application credential auth plugin https://review.openstack.org/525346 | 21:24 |
openstackgerrit | Merged openstack/keystone master: Add api-ref for application credentials https://review.openstack.org/533744 | 21:24 |
lbragstad | O.O | 21:24 |
openstackgerrit | Merged openstack/keystone master: Enable application_credential auth by default https://review.openstack.org/535469 | 21:24 |
lbragstad | YAS!!! | 21:24 |
cmurphy | OMG | 21:24 |
cmurphy | OMG | 21:25 |
cmurphy | OMG | 21:25 |
*** aojea_ has quit IRC | 21:25 | |
* lbragstad tips hat to cmurphy | 21:25 | |
lbragstad | nice work | 21:25 |
cmurphy | ^.^ | 21:25 |
*** aojea_ has joined #openstack-keystone | 21:27 | |
*** rmcall has quit IRC | 21:27 | |
*** aojea__ has quit IRC | 21:29 | |
*** aojea__ has joined #openstack-keystone | 21:32 | |
*** links has quit IRC | 21:32 | |
*** aojea_ has quit IRC | 21:35 | |
*** aojea_ has joined #openstack-keystone | 21:38 | |
*** aojea__ has quit IRC | 21:39 | |
*** aojea__ has joined #openstack-keystone | 21:43 | |
*** aojea_ has quit IRC | 21:46 | |
*** aojea_ has joined #openstack-keystone | 21:49 | |
*** aojea__ has quit IRC | 21:52 | |
*** aojea_ has quit IRC | 21:52 | |
*** spilla has quit IRC | 21:56 | |
lbragstad | fyi - i removed the project tags and system scope osc patches from our review board since we're past library freeze :-/ | 22:09 |
lbragstad | the project tags one looked good, but it needed reviews from python-openstackclient folks | 22:10 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Delete SQL users before deleting domain https://review.openstack.org/539347 | 22:11 |
cmurphy | yeah definitely want to plan further ahead next time we want to add features in osc | 22:13 |
lbragstad | at least we have client support in ksc | 22:16 |
lbragstad | which is something at least | 22:16 |
openstackgerrit | Merged openstack/keystone master: Impose limits on application credentials https://review.openstack.org/536543 | 22:16 |
openstackgerrit | Merged openstack/keystone master: Add a release note for application credentials https://review.openstack.org/535493 | 22:16 |
lbragstad | WOO! | 22:16 |
cmurphy | OMG | 22:17 |
* cmurphy collapses | 22:17 | |
lbragstad | yeah - i'm pretty sure i'm going to sleep friday - monday | 22:18 |
cmurphy | i'm pretty sure my productivity had hit the floor since i've been obsessing over the gate queue | 22:20 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Delete SQL users before deleting domain https://review.openstack.org/539347 | 22:22 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Document flat limit enforcement model https://review.openstack.org/538322 | 22:22 |
lbragstad | cc wxy ^ | 22:22 |
lbragstad | totally - it's like a hurry up and wait situation | 22:22 |
*** rmcall has joined #openstack-keystone | 22:23 | |
*** mvenesio has quit IRC | 22:27 | |
*** mvenesio has joined #openstack-keystone | 22:27 | |
lbragstad | it also makes me feel bad when i propose *more* patches when the gate is already really behind.. | 22:29 |
lbragstad | it's like a big game of jenga | 22:29 |
cmurphy | lol yeah every time something minor made it through the queue it was *sigh* | 22:30 |
lbragstad | "sure, go ahead!" | 22:30 |
*** mvenesio has quit IRC | 22:31 | |
*** edmondsw has quit IRC | 22:32 | |
*** edmondsw has joined #openstack-keystone | 22:33 | |
*** edmondsw has quit IRC | 22:37 | |
*** rmcall has quit IRC | 22:49 | |
gagehugo | woo | 23:13 |
gagehugo | lbragstad yeah lgtm | 23:14 |
*** phalmos has quit IRC | 23:14 | |
*** d0ugal has quit IRC | 23:20 | |
*** rcernin has joined #openstack-keystone | 23:28 | |
*** rcernin has quit IRC | 23:50 | |
*** mchlumsky has quit IRC | 23:56 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!