*** Guest27 has joined #openstack-keystone | 00:05 | |
*** Guest27 has quit IRC | 00:05 | |
*** sapd has quit IRC | 00:19 | |
*** edmondsw has joined #openstack-keystone | 00:31 | |
*** edmondsw has quit IRC | 00:35 | |
*** itlinux has quit IRC | 00:39 | |
*** mburrows has quit IRC | 00:45 | |
*** mburrows has joined #openstack-keystone | 00:48 | |
*** mburrows has quit IRC | 00:50 | |
*** mburrows has joined #openstack-keystone | 00:51 | |
*** zhongjun has joined #openstack-keystone | 01:17 | |
adriant | lbragstad, ayoung: a useful side thing for the whole domain vs project thing: https://blueprints.launchpad.net/keystone/+spec/include-domains | 01:30 |
---|---|---|
*** sapd has joined #openstack-keystone | 01:58 | |
*** openstackgerrit has joined #openstack-keystone | 02:01 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Remove password column in password table https://review.openstack.org/551824 | 02:01 |
*** edmondsw has joined #openstack-keystone | 02:19 | |
*** edmondsw has quit IRC | 02:24 | |
*** namnh has joined #openstack-keystone | 02:28 | |
*** sapd has quit IRC | 02:55 | |
*** sapd has joined #openstack-keystone | 02:55 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Remove password column in password table https://review.openstack.org/551824 | 03:12 |
*** dave-mccowan has quit IRC | 03:38 | |
*** zhurong has joined #openstack-keystone | 04:06 | |
*** edmondsw has joined #openstack-keystone | 04:07 | |
*** edmondsw has quit IRC | 04:12 | |
*** jmlowe has quit IRC | 04:24 | |
*** germs has joined #openstack-keystone | 05:06 | |
*** germs has quit IRC | 05:06 | |
*** germs has joined #openstack-keystone | 05:06 | |
*** zhurong has quit IRC | 05:09 | |
*** germs has quit IRC | 05:11 | |
*** edmondsw has joined #openstack-keystone | 05:55 | |
*** david-lyle has quit IRC | 06:00 | |
*** edmondsw has quit IRC | 06:00 | |
*** annp has joined #openstack-keystone | 06:01 | |
*** zhurong has joined #openstack-keystone | 06:06 | |
*** jaosorior has joined #openstack-keystone | 06:06 | |
*** david-lyle has joined #openstack-keystone | 06:07 | |
*** karthi has joined #openstack-keystone | 06:17 | |
*** threestrands_ has joined #openstack-keystone | 06:26 | |
*** BlackDex_ has joined #openstack-keystone | 06:30 | |
*** andymccr_ has joined #openstack-keystone | 06:33 | |
*** threestrands has quit IRC | 06:34 | |
*** Krenair has quit IRC | 06:34 | |
*** andymccr has quit IRC | 06:34 | |
*** BlackDex has quit IRC | 06:34 | |
*** hemna has quit IRC | 06:34 | |
*** Krenair_ has joined #openstack-keystone | 06:35 | |
*** hemna has joined #openstack-keystone | 06:35 | |
openstackgerrit | melissaml proposed openstack/keystonemiddleware master: Follow the new PTI for document build https://review.openstack.org/551857 | 06:44 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Remove password column in password table https://review.openstack.org/551824 | 06:52 |
*** namnh has quit IRC | 06:57 | |
*** annp has quit IRC | 06:57 | |
*** namnh has joined #openstack-keystone | 06:57 | |
*** annp has joined #openstack-keystone | 06:57 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Remove password column in password table https://review.openstack.org/551824 | 07:03 |
*** germs has joined #openstack-keystone | 07:07 | |
*** germs has quit IRC | 07:07 | |
*** germs has joined #openstack-keystone | 07:07 | |
*** rcernin has quit IRC | 07:09 | |
*** germs has quit IRC | 07:11 | |
*** threestrands_ has quit IRC | 07:13 | |
*** oikiki has joined #openstack-keystone | 07:18 | |
*** oikiki has quit IRC | 07:22 | |
*** karthi has quit IRC | 07:39 | |
*** martinus__ has joined #openstack-keystone | 07:41 | |
*** oikiki has joined #openstack-keystone | 07:42 | |
*** edmondsw has joined #openstack-keystone | 07:44 | |
*** edmondsw has quit IRC | 07:48 | |
*** oikiki has quit IRC | 07:54 | |
*** pcaruana has joined #openstack-keystone | 07:56 | |
*** AlexeyAbashkin has joined #openstack-keystone | 07:59 | |
*** tesseract has joined #openstack-keystone | 08:10 | |
*** bhagyashri_s has joined #openstack-keystone | 08:19 | |
*** bhagyashris has quit IRC | 08:21 | |
*** karthi has joined #openstack-keystone | 08:22 | |
*** thomasduval has joined #openstack-keystone | 08:26 | |
*** hoonetorg has quit IRC | 08:36 | |
*** hoonetorg has joined #openstack-keystone | 08:50 | |
*** germs has joined #openstack-keystone | 09:08 | |
*** germs has quit IRC | 09:08 | |
*** germs has joined #openstack-keystone | 09:08 | |
*** germs has quit IRC | 09:12 | |
*** d0ugal_ has quit IRC | 09:19 | |
*** d0ugal has joined #openstack-keystone | 09:19 | |
*** ysandeep has joined #openstack-keystone | 09:32 | |
*** edmondsw has joined #openstack-keystone | 09:32 | |
*** edmondsw has quit IRC | 09:36 | |
ysandeep | ping #openstack-keystone , Hi Guys, I have a quick query as I am doing keystone intergration with AD DS. I was wondering what network (vlan) is used for Keystone to send queries to AD ? Is it posible configure the connection to AD DS using the "OSP management network" ? Can anyone please confirm. | 09:37 |
cmurphy | ysandeep: keystone on its own does not care what network it uses to talk to AD, but it sounds like you're using a deployer that has a preference, so I would ask the people involved with that deployer - I'm guessing maybe OSP means Red Hat OpenStack Platform? which might point to #rdo or #tripleo | 09:42 |
*** vish_18 has joined #openstack-keystone | 09:46 | |
vish_18 | lbragstad: Is it possible to use v3 as well as v2 version of keystone in stable/pike | 09:49 |
ysandeep | cmurphy, Thanks a lot! Yes its Red Hat OSP. I believe if my AD DS's IP range is within my "Management network", I will be successful to send queries over management N/w to AD from Controllers. | 09:50 |
vish_18 | lbragstad: my requirement is to install freezer in pike which supports v2 version of keystone | 09:51 |
vish_18 | lbragstad: kindly help | 09:51 |
cmurphy | vish_18: lbragstad won't be around for a few more hours | 09:52 |
cmurphy | vish_18: pike supports both v2 and v3 | 09:52 |
vish_18 | cmurphy: Can I use both simultaneouly. I mean for a single service I need V2, because rest of the services I have configured with V3 | 09:56 |
cmurphy | vish_18: yes, they are both available at the same time | 09:57 |
vish_18 | cmurphy: How can I configure keystone with both the versions. I am still confused :( | 09:58 |
cmurphy | vish_18: they are both available by default, you don't have to configure anything and you can't turn them off | 09:58 |
cmurphy | if your service wants to use v2 then it makes requests using the v2.0 endpoint, if it wants to use v3 then it makes requests with the v3 endpoint | 09:59 |
vish_18 | cmurphy: When I installed keystone manually i gave the auth URl with version V3. My request for v2 is failing (http://controller:35357/v2.0/auth/tokens | 10:01 |
cmurphy | vish_18: what are you using to make that v2 request? it is expecting a v3 auth url | 10:02 |
vish_18 | cmurphy: https://docs.openstack.org/freezer/pike/user/installation.html installing this | 10:05 |
*** annp has quit IRC | 10:05 | |
vish_18 | cmurphy: Create ENV file: | 10:05 |
vish_18 | cmurphy: OS_AUTH_URL='http://[keystone_uri]:[keystone_port]/v2.0' | 10:05 |
vish_18 | cmurphy: trying to source this env | 10:05 |
cmurphy | vish_18: that looks to be out of date http://git.openstack.org/cgit/openstack/freezer/tree/freezer/openstack/osclients.py#n351 | 10:11 |
cmurphy | i would just use v3 as that auth url | 10:11 |
ysandeep | ping #openstack-keystone cmurphy, One more small Query Regarding Keystone - AD intergration, I have 3 controller and 4 AD DS Domain controller, For firewall filtering between AD DS and OpenStack - I want to open port 636(LDAPS) on firewall, Are you aware if i need to enter Source IP for all three openstack controller or only IP from HAproxy in firewall? Appreciate your help! | 10:18 |
*** namnh has quit IRC | 10:20 | |
cmurphy | ysandeep: i'm not sure to be honest, I guess it depends on whether haproxy masks the source IP, which probably depends on how your haproxy is configured | 10:26 |
ysandeep | cmurphy, Thanks , Me too in confusion whether in HA , Will Only openstack domain controller send request to AD or all 3 controller will send request to AD? | 10:30 |
cmurphy | ysandeep: only one will send the request to AD | 10:31 |
ysandeep | cmurphy, And the one will be the openstack's Domain controller? | 10:32 |
cmurphy | ysandeep: er what is the openstack domain controller? are you talking about keystone or are you talking about AD? | 10:33 |
ysandeep | cmurphy, I mean keystone, As its a HA environment and i have 3 controller, With DC i mean which in PCS STATUS - Current DC: controller-1 (version 1.1.16-12.el7_4.5-94ff4df) - partition with quorum | 10:35 |
cmurphy | so then whichever keystone happened to receive the user request will be the one to make an AD request | 10:37 |
*** zhurong has quit IRC | 10:37 | |
ysandeep | cmurphy, ahh ohk , then in that case i think i need to add all 3 controller in firewall as source ip | 10:38 |
ysandeep | cmurphy, Thanks a lot! for help, Have a great day :) | 10:40 |
*** pcichy has quit IRC | 10:42 | |
vish_18 | cmurphy: thanks a lot. http://git.openstack.org/cgit/openstack/freezer/tree/freezer/openstack/osclients.py#n351 it is for pike? or master? | 10:52 |
cmurphy | vish_18: sorry that was for master but the same is true for pike http://git.openstack.org/cgit/openstack/freezer/tree/freezer/openstack/osclients.py?h=stable/pike#n351 | 10:54 |
vish_18 | cmurphy: thanks | 10:55 |
*** germs has joined #openstack-keystone | 11:08 | |
*** germs has quit IRC | 11:08 | |
*** germs has joined #openstack-keystone | 11:08 | |
*** germs has quit IRC | 11:13 | |
*** BlackDex_ is now known as BlackDex | 11:30 | |
*** Supun has joined #openstack-keystone | 11:33 | |
*** ysandeep has quit IRC | 11:38 | |
openstackgerrit | Nguyen Hai proposed openstack/keystone-specs master: Change keystone-specs webpage from oslosphinx to openstackdocstheme https://review.openstack.org/551974 | 11:38 |
*** jmlowe has joined #openstack-keystone | 12:03 | |
*** jmlowe has quit IRC | 12:08 | |
*** jmlowe has joined #openstack-keystone | 12:10 | |
*** edmondsw has joined #openstack-keystone | 12:13 | |
*** mvk has quit IRC | 12:21 | |
*** Supun has quit IRC | 12:25 | |
*** Supun has joined #openstack-keystone | 12:26 | |
*** raildo has joined #openstack-keystone | 12:33 | |
*** Supun has quit IRC | 12:37 | |
*** mvk has joined #openstack-keystone | 12:37 | |
*** Supun has joined #openstack-keystone | 12:38 | |
*** karthi has quit IRC | 12:50 | |
*** karthi has joined #openstack-keystone | 12:51 | |
*** karthi has quit IRC | 12:51 | |
*** karthi has joined #openstack-keystone | 12:53 | |
*** Supun has quit IRC | 12:55 | |
*** Supun has joined #openstack-keystone | 12:55 | |
*** karthi has quit IRC | 13:05 | |
*** vish_18 has quit IRC | 13:19 | |
*** dave-mccowan has joined #openstack-keystone | 13:29 | |
*** gongysh has joined #openstack-keystone | 13:44 | |
lbragstad | cmurphy: thanks | 13:44 |
*** Supun has quit IRC | 13:45 | |
*** r-daneel has joined #openstack-keystone | 13:50 | |
*** Supun has joined #openstack-keystone | 13:57 | |
*** panbalag has joined #openstack-keystone | 13:59 | |
*** pcaruana has quit IRC | 14:01 | |
*** ispp has joined #openstack-keystone | 14:04 | |
ispp | hi, which repository do you recommend to use keystoneV3 in golang? Im using github.com/openstack/golang-client/ for the moment with V2 | 14:05 |
openstackgerrit | Andreas Jaeger proposed openstack/keystoneauth master: Remove tox_install.sh and align with constraints consumption https://review.openstack.org/550837 | 14:05 |
*** zhongjun has quit IRC | 14:06 | |
mnaser | lbragstad, ayoung, kmalloc: I spoke to the release team about adding a note to a previous stable release and it seems that we can do it with this — https://docs.openstack.org/reno/latest/user/usage.html#updating-stable-branch-release-notes | 14:06 |
mnaser | It’s not ideal because it involves a commit to a stable branch directly but I think that’s better than having users not know about V2 going away | 14:07 |
ayoung | ++ | 14:07 |
cmurphy | thanks mnaser | 14:07 |
cmurphy | that sounds like the best way forward to me | 14:07 |
mnaser | I’m not near a computer right now but if someone can have a look at writing something up it would be useful for users :) | 14:07 |
mnaser | no problem, good luck :) | 14:08 |
*** pcaruana has joined #openstack-keystone | 14:15 | |
cmurphy | https://review.openstack.org/552031 | 14:19 |
lbragstad | nice - thanks | 14:20 |
cmurphy | we could maybe use that ignore-notes thing if we want to have the note exist in master too | 14:21 |
mnaser | I wonder if that release note will only be under 11.0.1 or whatever the next tag will be | 14:27 |
mnaser | And I’m not trying to make life more painful but that might also be confusing :p | 14:28 |
*** pcichy has joined #openstack-keystone | 14:28 | |
cmurphy | i don't always remove major api versions but when i do it's in a bugfix release | 14:29 |
mnaser | :D | 14:29 |
mnaser | “We don’t make mistakes, we make happy accidents” | 14:30 |
cmurphy | lol | 14:30 |
*** pcaruana has quit IRC | 14:30 | |
*** Supun has quit IRC | 14:33 | |
lbragstad | ++ | 14:39 |
*** pcaruana has joined #openstack-keystone | 14:43 | |
*** gongysh has quit IRC | 14:44 | |
*** panbalag1 has joined #openstack-keystone | 14:59 | |
*** panbalag has quit IRC | 15:01 | |
*** panbalag1 has quit IRC | 15:15 | |
*** spilla has joined #openstack-keystone | 15:15 | |
*** ayoung has quit IRC | 15:24 | |
knikolla | o/ | 15:29 |
*** felipemonteiro has joined #openstack-keystone | 15:31 | |
*** gyee has joined #openstack-keystone | 15:41 | |
eandersson | lbragstad, when you have time could you check on https://review.openstack.org/#/c/482364/ | 15:58 |
lbragstad | eandersson: yeah - i should be able to review that today | 15:58 |
eandersson | awesome thanks | 15:58 |
*** pcaruana has quit IRC | 16:12 | |
*** thomasduval has quit IRC | 16:25 | |
*** Supun has joined #openstack-keystone | 16:29 | |
*** felipemonteiro has quit IRC | 16:31 | |
*** felipemonteiro has joined #openstack-keystone | 16:31 | |
*** panbalag has joined #openstack-keystone | 16:40 | |
*** Supun has quit IRC | 16:43 | |
*** panbalag has left #openstack-keystone | 16:49 | |
*** ygl has joined #openstack-keystone | 17:06 | |
ygl | hi all | 17:06 |
ygl | I want to add an existing user to another project also. how to do it ? | 17:07 |
*** ayoung has joined #openstack-keystone | 17:09 | |
ayoung | Would love to know what portion of Keystone functionality is covered by istio | 17:10 |
ygl | can someone help me please | 17:10 |
ygl | I want to add an existing user to another project also. how to do it ? | 17:10 |
ayoung | ygl, change your terminiology and it all becomes easy | 17:10 |
ayoung | ygl you do not "add a user to a project" | 17:10 |
ayoung | you "assign a user a role on a project" | 17:10 |
*** felipemonteiro_ has joined #openstack-keystone | 17:11 | |
ayoung | ygl you using the command line? | 17:11 |
ygl | ayoung: yes | 17:11 |
ayoung | openstack role list | 17:11 |
ayoung | openstack project list | 17:11 |
ayoung | those both give the IDs you need. | 17:11 |
ygl | ayoung: how can I make my user as part of another user project ? | 17:12 |
ayoung | openstack role add --user fred --user-domain Default --project yourprohej --project-domain Default | 17:12 |
ygl | ayoung: ok thanks got it | 17:12 |
*** felipemonteiro has quit IRC | 17:14 | |
ygl | ayoung: i am unable to list users from an LDAP domain. why is it so ? | 17:14 |
ayoung | LDAP sucks | 17:15 |
*** edmondsw has quit IRC | 17:15 | |
ayoung | ygl could be many reasons | 17:15 |
ygl | ayoung: it is saying An unexpected error prevented the server from fulfilling your request. (HTTP 500) (Request-ID: req-0ab4d7e1-c0c7-4094-a7cb-20b609b83beb) | 17:15 |
*** edmondsw has joined #openstack-keystone | 17:15 | |
ayoung | ygl that sounds like a server configuration error, then | 17:15 |
ayoung | hard to diagnose from here | 17:16 |
*** felipemonteiro_ has quit IRC | 17:17 | |
*** felipemonteiro_ has joined #openstack-keystone | 17:17 | |
*** pcaruana has joined #openstack-keystone | 17:18 | |
*** edmondsw has quit IRC | 17:19 | |
*** AlexeyAbashkin has quit IRC | 17:23 | |
*** ygl has quit IRC | 17:24 | |
*** pcaruana has quit IRC | 17:27 | |
aning | Anybody know what this DB query is for? | 17:28 |
aning | SELECT local_user.id AS local_user_id, local_user.user_id AS local_user_user_id, local_user.domain_id AS local_user_domain_id, local_user.name AS local_user_name, local_user.failed_auth_count AS local_user_failed_auth_count, local_user.failed_auth_at AS local_user_failed_auth_at, anon_1.user_id AS anon_1_user_id, anon_1.user_domain_id AS anon_1_user_domain_id | 17:28 |
aning | FROM (SELECT "user".id AS user_id, "user".domain_id AS user_domain_id | 17:28 |
aning | FROM "user" | 17:28 |
aning | WHERE "user".id = '20bd4216910340bc8e6019f6d826f9d7') AS anon_1 JOIN local_user ON anon_1.user_id = local_user.user_id AND anon_1.user_domain_id = local_user.domain_id ORDER BY anon_1.user_id, anon_1.user_domain_id | 17:28 |
aning | I see them from nova and other services ... | 17:28 |
aning | Andybody? | 17:41 |
aning | Anybody? | 17:41 |
lbragstad | aning: that query looks like a keystone query - nova wouldn't be invoking that directly | 17:42 |
lbragstad | nova is probably performing a GET /user/{user_id} call | 17:42 |
lbragstad | or listing users | 17:42 |
lbragstad | if you monitor keystone logs you'll see the API call that is invoked | 17:44 |
aning | ok, actually I saw user.id in the query ("user".id = '20bd4216910340bc8e6019f6d826f9d7') is nova. | 17:45 |
lbragstad | that will be more indicative of what is resulting in that query - it could be a list user call, it could be a token validation, etc... | 17:45 |
aning | so the query is from keystone, but it should be triggered by services, for example to validate a token against keystone | 17:47 |
*** itlinux has joined #openstack-keystone | 17:49 | |
*** edmondsw has joined #openstack-keystone | 17:49 | |
aning | lbragstad: thanks. | 17:50 |
*** ayoung has quit IRC | 17:51 | |
*** r-daneel has quit IRC | 17:52 | |
*** pcaruana has joined #openstack-keystone | 17:53 | |
*** felipemonteiro__ has joined #openstack-keystone | 17:58 | |
*** dave-mccowan has quit IRC | 18:00 | |
*** felipemonteiro_ has quit IRC | 18:02 | |
*** dave-mccowan has joined #openstack-keystone | 18:04 | |
*** d0ugal has quit IRC | 18:05 | |
*** tesseract has quit IRC | 18:06 | |
*** felipemonteiro__ has quit IRC | 18:15 | |
*** felipemonteiro__ has joined #openstack-keystone | 18:16 | |
-openstackstatus- NOTICE: Most jobs in zuul are currently failing due to a recent change to zuul; we are evaluating the issue and will follow up with a recommendation shortly. For the moment, please do not recheck. | 18:17 | |
*** ChanServ changes topic to "Most jobs in zuul are currently failing due to a recent change to zuul; we are evaluating the issue and will follow up with a recommendation shortly. For the moment, please do not recheck." | 18:17 | |
*** pcichy has quit IRC | 18:18 | |
*** d0ugal has joined #openstack-keystone | 18:19 | |
*** oikiki has joined #openstack-keystone | 18:29 | |
*** dtruong has joined #openstack-keystone | 18:30 | |
*** akrzos_ is now known as akrzos | 18:31 | |
*** lbragstad has quit IRC | 18:35 | |
*** eeiden has joined #openstack-keystone | 18:35 | |
*** pcichy has joined #openstack-keystone | 18:37 | |
*** ChanServ changes topic to "Queens release schedule: https://releases.openstack.org/queens/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/wmyzbFq5/keystone-rocky-roadmap" | 18:40 | |
-openstackstatus- NOTICE: Zuul has been restarted without the breaking change; please recheck any changes which failed tests with the error "Accessing files from outside the working dir ... is prohibited." | 18:40 | |
*** felipemonteiro_ has joined #openstack-keystone | 18:44 | |
*** felipemonteiro__ has quit IRC | 18:48 | |
*** pcichy has quit IRC | 18:50 | |
*** harlowja has joined #openstack-keystone | 18:50 | |
*** pcichy has joined #openstack-keystone | 18:50 | |
*** pcichy has quit IRC | 18:55 | |
*** pcichy has joined #openstack-keystone | 18:55 | |
*** lbragstad has joined #openstack-keystone | 18:55 | |
*** ChanServ sets mode: +o lbragstad | 18:55 | |
*** AlexeyAbashkin has joined #openstack-keystone | 18:56 | |
*** AlexeyAbashkin has quit IRC | 19:00 | |
*** openstackgerrit has quit IRC | 19:04 | |
*** Krenair_ is now known as Krenair | 19:21 | |
*** Krenair has joined #openstack-keystone | 19:21 | |
*** r-daneel has joined #openstack-keystone | 19:50 | |
*** r-daneel_ has joined #openstack-keystone | 20:00 | |
*** mvk has quit IRC | 20:01 | |
*** r-daneel has quit IRC | 20:02 | |
*** r-daneel_ is now known as r-daneel | 20:02 | |
*** nicolasbock has joined #openstack-keystone | 20:29 | |
*** oikiki has quit IRC | 20:31 | |
*** felipemonteiro_ has quit IRC | 20:37 | |
*** felipemonteiro_ has joined #openstack-keystone | 20:37 | |
*** oikiki has joined #openstack-keystone | 20:38 | |
*** raildo has quit IRC | 20:57 | |
*** itlinux has quit IRC | 20:57 | |
*** raildo has joined #openstack-keystone | 20:59 | |
*** mvk has joined #openstack-keystone | 21:03 | |
*** r-daneel_ has joined #openstack-keystone | 21:14 | |
*** r-daneel has quit IRC | 21:16 | |
*** r-daneel_ is now known as r-daneel | 21:16 | |
*** raildo has quit IRC | 21:17 | |
*** ayoung has joined #openstack-keystone | 21:34 | |
*** pcaruana has quit IRC | 21:36 | |
*** oikiki has quit IRC | 21:36 | |
*** felipemonteiro__ has joined #openstack-keystone | 21:43 | |
lbragstad | kmalloc: do you remember if we were going to push @controller.protected logic into the manager layer or try and leave it at the controller? | 21:46 |
*** edmondsw has quit IRC | 21:46 | |
kmalloc | uhm. | 21:46 |
kmalloc | i want to say we wanted to keep it in controller | 21:46 |
kmalloc | because we aren't doing PIP in manager. | 21:46 |
*** felipemonteiro_ has quit IRC | 21:46 | |
*** edmondsw has joined #openstack-keystone | 21:46 | |
lbragstad | ok - so the controllers would have at least some business logic in order to handle that enforcement | 21:47 |
kmalloc | yeah, the decision is done in the controller. | 21:47 |
lbragstad | ok | 21:47 |
kmalloc | though... | 21:47 |
kmalloc | can you think of a benefit of pushing down to manager? | 21:47 |
kmalloc | that i'm missing? | 21:47 |
lbragstad | this sounds like a red pill/blue pill question | 21:48 |
kmalloc | i think we mostly chose that model to avoid having to pass the request context down into the manager/pivot point again | 21:48 |
lbragstad | the _only_ thing i can think of is the business logic | 21:48 |
kmalloc | like we used to do ... waaaaaaaay back in the day | 21:48 |
kmalloc | rememeber, we'd need multiple methods then, policy enforced and non, because domain getting user shouldn't care | 21:48 |
*** d0ugal has quit IRC | 21:48 | |
kmalloc | erm, user getting domain info* | 21:49 |
lbragstad | for example; if system_scope: return all project; if domain_scope: return projects in domain; if project_scope: return project + children | 21:49 |
kmalloc | right, but get_user has to get_domain, | 21:49 |
kmalloc | people who get_user may not be able to get_domain | 21:49 |
kmalloc | for example | 21:49 |
kmalloc | we'd need a "internal=True"? and maybe pass from controler to manager via partial to avoid potential circumvention? | 21:50 |
lbragstad | oh... so that would be a reason to keep enforcement in the controller, right? | 21:50 |
kmalloc | yrah | 21:50 |
kmalloc | yeah* | 21:50 |
lbragstad | got it | 21:50 |
kmalloc | i'm just making sure my concern isn't superfluous | 21:50 |
lbragstad | so - maybe the question becomes, do we want managers to be able to freely call back and forth with each other/ | 21:50 |
kmalloc | if it's way way way way way easier to PEP (policy enforcement point) at manager, i'm happy with structuring a mechanism to allow that | 21:50 |
*** Krenair has quit IRC | 21:51 | |
lbragstad | i'm not sure if it will be easier, per se... | 21:52 |
lbragstad | i was just asking myself "does the example I listed above contain logic specific to keystone?" | 21:52 |
lbragstad | and most of the time the answer is yes | 21:52 |
kmalloc | right. | 21:52 |
lbragstad | which leads me to think it should be in the manager | 21:52 |
lbragstad | but - again, it doesn't have to be | 21:52 |
kmalloc | just come up with the best method to allow cross-manager communication | 21:53 |
lbragstad | with RBAC enforcement | 21:53 |
kmalloc | yeah for controller->manager | 21:54 |
lbragstad | but - that also means more context stuff is handled in the manager | 21:54 |
kmalloc | yes | 21:54 |
lbragstad | like you said, we use to do that a long time ago | 21:54 |
*** panbalag has joined #openstack-keystone | 21:55 | |
lbragstad | was there more context there? | 21:55 |
kmalloc | we just did .manager.method(context, normal_Args, .....) | 21:55 |
*** oikiki has joined #openstack-keystone | 21:56 | |
*** Krenair has joined #openstack-keystone | 21:56 | |
kmalloc | and it meant we passed things down. | 21:56 |
kmalloc | which is was painful. | 21:56 |
lbragstad | yeah... i can see how that would lead to more web stuff being done in the manager instead of the controller | 21:57 |
lbragstad | just because it's there | 21:57 |
*** eeiden has quit IRC | 21:59 | |
lbragstad | kmalloc: looks like wxy is interested in picking up the yaml catalog stuff :) https://review.openstack.org/#/c/482364/7 | 22:01 |
lbragstad | gotta run an errand quick, i'll be back online later | 22:01 |
*** pcichy has quit IRC | 22:04 | |
*** martinus__ has quit IRC | 22:15 | |
*** idlemind has joined #openstack-keystone | 22:17 | |
*** oikiki has quit IRC | 22:23 | |
*** edmondsw has quit IRC | 22:24 | |
*** rcernin has joined #openstack-keystone | 22:24 | |
*** edmondsw has joined #openstack-keystone | 22:24 | |
*** edmondsw has quit IRC | 22:29 | |
*** AlexeyAbashkin has joined #openstack-keystone | 22:38 | |
*** AlexeyAbashkin has quit IRC | 22:42 | |
*** spilla has quit IRC | 22:52 | |
*** felipemonteiro__ has quit IRC | 22:54 | |
*** r-daneel has quit IRC | 23:12 | |
*** germs has joined #openstack-keystone | 23:14 | |
*** germs has quit IRC | 23:14 | |
*** germs has joined #openstack-keystone | 23:14 | |
*** germs has quit IRC | 23:18 | |
*** r-daneel has joined #openstack-keystone | 23:39 | |
*** edmondsw has joined #openstack-keystone | 23:41 | |
eandersson | Out of interest, has anyone tried to use Bjoern instead of uwsgi for Keystone? | 23:43 |
*** r-daneel has quit IRC | 23:44 | |
*** r-daneel has joined #openstack-keystone | 23:46 | |
*** edmondsw has quit IRC | 23:46 | |
*** itlinux has joined #openstack-keystone | 23:51 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!