*** germs has quit IRC | 00:01 | |
*** jistr has quit IRC | 00:02 | |
*** jistr has joined #openstack-keystone | 00:03 | |
*** odyssey4me has quit IRC | 00:14 | |
*** odyssey4me has joined #openstack-keystone | 00:14 | |
*** itlinux has joined #openstack-keystone | 00:23 | |
*** jroll has quit IRC | 00:24 | |
*** annp has quit IRC | 00:50 | |
*** annp has joined #openstack-keystone | 00:51 | |
*** markvoelker_ has joined #openstack-keystone | 01:02 | |
*** markvoelker has quit IRC | 01:06 | |
*** annp has quit IRC | 01:12 | |
*** annp has joined #openstack-keystone | 01:13 | |
*** gyankum has joined #openstack-keystone | 01:14 | |
*** felipemonteiro__ has joined #openstack-keystone | 01:36 | |
*** sapd has joined #openstack-keystone | 01:42 | |
*** harlowja has quit IRC | 01:50 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Expose a bug that list_limit doesn't work correctly https://review.openstack.org/558150 | 01:52 |
---|---|---|
openstackgerrit | wangxiyuan proposed openstack/keystone master: Fix list_limit doesn't work correctly for domain https://review.openstack.org/558151 | 01:52 |
*** germs has joined #openstack-keystone | 01:57 | |
*** germs has quit IRC | 01:57 | |
*** germs has joined #openstack-keystone | 01:57 | |
*** germs has quit IRC | 02:01 | |
*** AlexeyAbashkin has joined #openstack-keystone | 02:02 | |
*** AlexeyAbashkin has quit IRC | 02:06 | |
*** harlowja has joined #openstack-keystone | 02:31 | |
*** daidv has joined #openstack-keystone | 02:32 | |
*** daidv_ has joined #openstack-keystone | 02:33 | |
*** bhagyashris has quit IRC | 02:46 | |
*** bhagyashris has joined #openstack-keystone | 02:48 | |
*** daidv_ has quit IRC | 02:49 | |
*** zhurong has joined #openstack-keystone | 02:55 | |
*** gyan_ has joined #openstack-keystone | 03:04 | |
*** gyankum has quit IRC | 03:04 | |
*** AlexeyAbashkin has joined #openstack-keystone | 03:04 | |
*** gyan__ has joined #openstack-keystone | 03:05 | |
*** gyan_ has quit IRC | 03:09 | |
*** AlexeyAbashkin has quit IRC | 03:09 | |
*** jmlowe has quit IRC | 03:09 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Enable Foreign keys for sql backend unit test https://review.openstack.org/558029 | 03:19 |
*** spzala has joined #openstack-keystone | 03:24 | |
*** spzala has quit IRC | 03:24 | |
*** links has joined #openstack-keystone | 03:32 | |
*** nicolasbock has quit IRC | 03:40 | |
*** jmlowe has joined #openstack-keystone | 03:41 | |
*** felipemonteiro__ has quit IRC | 03:43 | |
*** ykarel|away has joined #openstack-keystone | 03:49 | |
*** zhurong has quit IRC | 03:52 | |
*** harlowja has quit IRC | 03:55 | |
*** annp has quit IRC | 03:57 | |
*** daidv has quit IRC | 03:57 | |
*** germs has joined #openstack-keystone | 03:57 | |
*** germs has quit IRC | 03:57 | |
*** germs has joined #openstack-keystone | 03:58 | |
*** daidv has joined #openstack-keystone | 03:58 | |
*** annp has joined #openstack-keystone | 03:58 | |
*** germs has quit IRC | 04:02 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Expose a bug that list_limit doesn't work correctly https://review.openstack.org/558150 | 04:03 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Fix list_limit doesn't work correctly for domain https://review.openstack.org/558151 | 04:03 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Enable Foreign keys for sql backend unit test https://review.openstack.org/558029 | 04:03 |
*** ykarel|away is now known as ykarel | 04:05 | |
*** markvoelker_ has quit IRC | 04:16 | |
*** jaosorior has joined #openstack-keystone | 04:57 | |
*** deepak_ has quit IRC | 04:58 | |
*** deepak_ has joined #openstack-keystone | 05:10 | |
*** marius1 has quit IRC | 05:17 | |
*** germs has joined #openstack-keystone | 05:58 | |
*** germs has quit IRC | 05:58 | |
*** germs has joined #openstack-keystone | 05:58 | |
*** germs has quit IRC | 06:02 | |
*** daidv has quit IRC | 06:13 | |
*** pcichy has quit IRC | 06:17 | |
*** markvoelker has joined #openstack-keystone | 06:17 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Expose a bug that list_limit doesn't work correctly https://review.openstack.org/558150 | 06:29 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Fix list_limit doesn't work correctly for domain https://review.openstack.org/558151 | 06:29 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Enable Foreign keys for sql backend unit test https://review.openstack.org/558029 | 06:29 |
*** martinus__ has joined #openstack-keystone | 06:32 | |
*** namnh has joined #openstack-keystone | 06:34 | |
*** markvoelker has quit IRC | 06:51 | |
*** pcaruana has joined #openstack-keystone | 06:53 | |
*** voelzmo has joined #openstack-keystone | 06:57 | |
*** belmoreira has joined #openstack-keystone | 06:58 | |
*** deepak_ has quit IRC | 06:59 | |
*** tesseract has joined #openstack-keystone | 07:00 | |
*** afazekas has quit IRC | 07:01 | |
*** afazekas has joined #openstack-keystone | 07:01 | |
*** ykarel_ has joined #openstack-keystone | 07:04 | |
*** gyan_ has joined #openstack-keystone | 07:04 | |
*** gyan__ has quit IRC | 07:04 | |
*** ykarel has quit IRC | 07:04 | |
*** links has quit IRC | 07:05 | |
*** links has joined #openstack-keystone | 07:05 | |
*** gyan__ has joined #openstack-keystone | 07:05 | |
*** ykarel__ has joined #openstack-keystone | 07:06 | |
*** gyan_ has quit IRC | 07:09 | |
*** ykarel_ has quit IRC | 07:09 | |
*** deepak_ has joined #openstack-keystone | 07:11 | |
*** voelzmo has quit IRC | 07:16 | |
*** josecastroleon has joined #openstack-keystone | 07:22 | |
*** ykarel__ is now known as ykarel | 07:30 | |
*** voelzmo has joined #openstack-keystone | 07:38 | |
*** jaosorior has quit IRC | 07:38 | |
*** jaosorior has joined #openstack-keystone | 07:44 | |
*** markvoelker has joined #openstack-keystone | 07:47 | |
*** voelzmo has quit IRC | 07:50 | |
*** AlexeyAbashkin has joined #openstack-keystone | 07:53 | |
*** germs has joined #openstack-keystone | 07:59 | |
*** germs has quit IRC | 07:59 | |
*** germs has joined #openstack-keystone | 07:59 | |
*** germs has quit IRC | 08:03 | |
*** links has quit IRC | 08:04 | |
*** dmellado has quit IRC | 08:08 | |
*** dmellado has joined #openstack-keystone | 08:08 | |
*** links has joined #openstack-keystone | 08:14 | |
*** zhurong has joined #openstack-keystone | 08:16 | |
*** voelzmo has joined #openstack-keystone | 08:20 | |
*** markvoelker has quit IRC | 08:21 | |
*** voelzmo has quit IRC | 08:25 | |
*** voelzmo has joined #openstack-keystone | 08:31 | |
*** dklyle has quit IRC | 08:40 | |
*** dklyle has joined #openstack-keystone | 08:41 | |
*** pcichy has joined #openstack-keystone | 09:00 | |
*** namnh has quit IRC | 09:04 | |
*** annp has quit IRC | 09:04 | |
*** namnh has joined #openstack-keystone | 09:05 | |
*** annp has joined #openstack-keystone | 09:05 | |
*** voelzmo has quit IRC | 09:16 | |
*** voelzmo has joined #openstack-keystone | 09:16 | |
*** markvoelker has joined #openstack-keystone | 09:18 | |
*** aloga has quit IRC | 09:21 | |
*** aloga has joined #openstack-keystone | 09:21 | |
*** dmellado has quit IRC | 09:23 | |
*** dmellado has joined #openstack-keystone | 09:23 | |
*** voelzmo has quit IRC | 09:32 | |
*** voelzmo has joined #openstack-keystone | 09:32 | |
*** voelzmo has quit IRC | 09:33 | |
*** voelzmo has joined #openstack-keystone | 09:33 | |
*** voelzmo has quit IRC | 09:33 | |
*** voelzmo has joined #openstack-keystone | 09:36 | |
*** voelzmo has quit IRC | 09:37 | |
*** voelzmo has joined #openstack-keystone | 09:37 | |
*** voelzmo has quit IRC | 09:37 | |
*** markvoelker has quit IRC | 09:52 | |
*** voelzmo has joined #openstack-keystone | 10:09 | |
*** voelzmo has quit IRC | 10:14 | |
*** zhurong has quit IRC | 10:21 | |
*** voelzmo has joined #openstack-keystone | 10:26 | |
*** zhurong has joined #openstack-keystone | 10:33 | |
*** nicolasbock has joined #openstack-keystone | 10:33 | |
*** namnh has quit IRC | 10:38 | |
*** markvoelker has joined #openstack-keystone | 10:48 | |
*** voelzmo has quit IRC | 10:55 | |
*** voelzmo has joined #openstack-keystone | 11:00 | |
*** rcernin has quit IRC | 11:20 | |
*** markvoelker has quit IRC | 11:22 | |
*** voelzmo has quit IRC | 11:36 | |
*** voelzmo has joined #openstack-keystone | 11:37 | |
*** voelzmo has quit IRC | 11:37 | |
*** voelzmo has joined #openstack-keystone | 11:37 | |
*** voelzmo has quit IRC | 11:38 | |
*** voelzmo has joined #openstack-keystone | 11:39 | |
*** voelzmo has quit IRC | 11:39 | |
*** voelzmo has joined #openstack-keystone | 11:39 | |
*** voelzmo has quit IRC | 11:39 | |
*** mkosobucki has quit IRC | 12:00 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Expose a bug that the domain can't be deleted https://review.openstack.org/558488 | 12:01 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Fix 500 error when deleting domain https://review.openstack.org/558489 | 12:01 |
*** raildo has joined #openstack-keystone | 12:10 | |
*** voelzmo has joined #openstack-keystone | 12:12 | |
*** odyssey4me has quit IRC | 12:15 | |
*** odyssey4me has joined #openstack-keystone | 12:15 | |
*** voelzmo has quit IRC | 12:17 | |
*** markvoelker has joined #openstack-keystone | 12:19 | |
*** gyan__ has quit IRC | 12:21 | |
*** markvoelker has quit IRC | 12:23 | |
*** markvoelker has joined #openstack-keystone | 12:24 | |
*** voelzmo has joined #openstack-keystone | 12:25 | |
*** edmondsw has quit IRC | 12:28 | |
*** edmondsw has joined #openstack-keystone | 12:28 | |
*** voelzmo has quit IRC | 12:29 | |
*** voelzmo has joined #openstack-keystone | 12:29 | |
*** edmondsw has quit IRC | 12:32 | |
*** jroll has joined #openstack-keystone | 12:37 | |
*** mchlumsky has joined #openstack-keystone | 12:39 | |
*** lbragstad has joined #openstack-keystone | 12:50 | |
*** ChanServ sets mode: +o lbragstad | 12:50 | |
*** mchlumsky has quit IRC | 12:50 | |
*** mchlumsky has joined #openstack-keystone | 12:52 | |
*** edmondsw has joined #openstack-keystone | 12:58 | |
zigo | samueldmq: Could I ask you to review this? https://review.openstack.org/#/c/554152/ | 13:02 |
zigo | It has already 1x +2 and 3x +1 (and that's a backport...) | 13:03 |
*** jdennis has quit IRC | 13:03 | |
*** jdennis has joined #openstack-keystone | 13:03 | |
lbragstad | zigo: either kmalloc can kick that through or someone from the stable team | 13:06 |
zigo | lbragstad: Oh, is there a different core reviewer set for stable? | 13:06 |
lbragstad | kmalloc: is currently our only stable/core | 13:06 |
lbragstad | otherwise, we rely on the stable team to help us push those things through | 13:06 |
*** ykarel is now known as ykarel|away | 13:20 | |
*** ykarel|away has quit IRC | 13:25 | |
*** dklyle has quit IRC | 13:27 | |
*** felipemonteiro__ has joined #openstack-keystone | 13:29 | |
*** spilla has joined #openstack-keystone | 13:40 | |
*** d0ugal has quit IRC | 13:41 | |
*** d0ugal has joined #openstack-keystone | 13:44 | |
*** d0ugal has quit IRC | 13:44 | |
*** d0ugal has joined #openstack-keystone | 13:44 | |
*** zhurong has quit IRC | 13:48 | |
*** ykarel|away has joined #openstack-keystone | 13:51 | |
*** ykarel|away is now known as ykarel | 13:51 | |
*** yankcrime has joined #openstack-keystone | 13:57 | |
*** germs has joined #openstack-keystone | 14:01 | |
*** germs has quit IRC | 14:01 | |
*** germs has joined #openstack-keystone | 14:01 | |
*** germs has quit IRC | 14:06 | |
*** r-daneel has joined #openstack-keystone | 14:06 | |
lbragstad | just a heads up - my availability is going to be hit or miss today with office hours | 14:11 |
lbragstad | i have a few internal meetings i have to attend | 14:11 |
knikolla | o/ | 14:18 |
*** voelzmo has quit IRC | 14:19 | |
*** voelzmo has joined #openstack-keystone | 14:19 | |
*** voelzmo has quit IRC | 14:20 | |
*** voelzmo has joined #openstack-keystone | 14:20 | |
*** voelzmo has quit IRC | 14:20 | |
*** voelzmo has joined #openstack-keystone | 14:21 | |
*** voelzmo has quit IRC | 14:21 | |
*** voelzmo has joined #openstack-keystone | 14:21 | |
*** voelzmo has quit IRC | 14:22 | |
*** voelzmo has joined #openstack-keystone | 14:22 | |
yankcrime | can anyone help me troubleshoot an issues with federation? i'm successfully authenticating against an oidc-based idp, but for some reason my user doesn't seem to get added to the group specified in my mapping | 14:22 |
*** voelzmo has quit IRC | 14:23 | |
yankcrime | there's nothing jumping out at me in my keystone logs (with debug etc.), in fact the entries around mapping echo the right group id | 14:24 |
yankcrime | so i'm kind of scratching my head at this point | 14:24 |
yankcrime | (this is on pike) | 14:24 |
knikolla | yankcrime: how are you checking that the user was not added to the group? | 14:26 |
lbragstad | yankcrime: when you get a token as that user, do you see any project assignments that the group as in the token response? | 14:26 |
*** itlinux has quit IRC | 14:28 | |
yankcrime | knikolla: `openstack group contains user` | 14:30 |
knikolla | yankcrime: users are not actually added to the group. they will only contain that group when they receive a token. you can see that they have access to projects that that group has, but they are not listed as members of the group. | 14:31 |
gagehugo | o/ | 14:34 |
lbragstad | yankcrime: if you get a token with your federated user, you should be able to list all projects you have access to | 14:35 |
lbragstad | (using the GET /v3/auth/projects API) | 14:35 |
lbragstad | that list should coincide with the assignments that group has | 14:36 |
lbragstad | the actual relationship between the user and the group is ephemeral in the federated case | 14:36 |
*** links has quit IRC | 14:37 | |
yankcrime | thanks lbragstad - i can see the projects ok, i just get permission denied when i attempt to do anything as this user | 14:38 |
lbragstad | hmm | 14:40 |
lbragstad | that sounds like it's policy related | 14:42 |
lbragstad | that might depend on if you are using custom policy definitions | 14:43 |
lbragstad | or what roles the federated user is getting via the group assignments | 14:44 |
lbragstad | another thing you could try is to assign a role directly to the shadow user created when you authenticated | 14:45 |
yankcrime | yeah, if i do that it works fine | 14:46 |
lbragstad | oh - cool | 14:46 |
lbragstad | with the same role as what's in the group assignment? | 14:46 |
yankcrime | well if i add the user explicitly to the group then it works fine | 14:46 |
lbragstad | oh | 14:46 |
*** jamielennox has quit IRC | 14:47 | |
*** gmann_ has quit IRC | 14:47 | |
*** wlmbasson has quit IRC | 14:48 | |
*** felipemonteiro_ has joined #openstack-keystone | 14:48 | |
lbragstad | something sounds off there | 14:48 |
*** Rhvs has quit IRC | 14:48 | |
*** Rhys has joined #openstack-keystone | 14:49 | |
yankcrime | so from keystone's logs when logging in i can see: | 14:49 |
yankcrime | 2018-04-03 15:40:58.994 18 DEBUG keystone.federation.utils [req-1fcf031a-e31e-4809-a184-b1bbf9fbda4e - - - - -] rules: [{u'remote': [{u'type': u'HTTP_OIDC_SUB'}, {u'type': u'HTTP | 14:49 |
yankcrime | _OIDC_ISS', u'any_one_of': [u'https://aai-dev.egi.eu/oidc/']}], u'local': [{u'group': {u'id': u'180edcc5cb954f5e8dff8d9903f70572'}, u'user': {u'name': u'{0}'}}]}] process /usr/li | 14:49 |
yankcrime | b/python2.7/site-packages/keystone/federation/utils.py:518 | 14:49 |
yankcrime | which is the right group id | 14:49 |
yankcrime | and if i add that shadow user to that group manually it all works fine | 14:49 |
*** gmann_ has joined #openstack-keystone | 14:50 | |
*** wlmbasson has joined #openstack-keystone | 14:50 | |
*** jamielennox has joined #openstack-keystone | 14:50 | |
lbragstad | hmm | 14:51 |
lbragstad | is the token response exactly the same before and after you add the shadow user to the group? | 14:51 |
yankcrime | good question, let me check | 14:52 |
*** david-lyle has joined #openstack-keystone | 14:52 | |
*** felipemonteiro__ has quit IRC | 14:52 | |
*** felipemonteiro_ has quit IRC | 15:02 | |
*** felipemonteiro_ has joined #openstack-keystone | 15:02 | |
*** jdennis has quit IRC | 15:05 | |
*** belmoreira has quit IRC | 15:05 | |
*** felipemonteiro__ has joined #openstack-keystone | 15:07 | |
*** belmoreira has joined #openstack-keystone | 15:08 | |
*** felipemonteiro_ has quit IRC | 15:11 | |
*** jdennis has joined #openstack-keystone | 15:13 | |
*** wxy| has joined #openstack-keystone | 15:17 | |
*** felipemonteiro has joined #openstack-keystone | 15:20 | |
*** itlinux has joined #openstack-keystone | 15:22 | |
*** felipemonteiro__ has quit IRC | 15:23 | |
*** felipemonteiro has quit IRC | 15:25 | |
lbragstad | kmalloc: qq | 15:31 |
lbragstad | kmalloc: what are your thoughts on making bootstrap more accessible to tests? | 15:32 |
*** tesseract has quit IRC | 15:32 | |
*** itlinux has quit IRC | 15:36 | |
lbragstad | essentially getting rid of all of this - https://github.com/openstack/keystone/blob/a6adc72e3e7ff4ff0bff0702e69ebd8f697d6261/keystone/tests/unit/core.py#L725-L797 | 15:38 |
lbragstad | or at least providing a replacement for it | 15:38 |
lbragstad | i'm running into a lot of cases where i just want a basic set of things available, like when an operator runs bootstrap, and then just have the test class setup additional resources | 15:39 |
lbragstad | instead of 1.) a duplicate process for bootstrapping basic information for tests and 2.) extra things created for tests that don't use them | 15:40 |
*** belmoreira has quit IRC | 15:42 | |
*** itlinux has joined #openstack-keystone | 15:44 | |
knikolla | lbragstad: i'll be skipping the weekly meeting. but i'll spend office hours doing spec reviews. | 15:46 |
lbragstad | knikolla: cool - sounds good | 15:47 |
kmalloc | lbragstad: hmm | 15:47 |
kmalloc | lbragstad: that sounds fine to me. | 15:48 |
lbragstad | keystone.tests.unit.core.TestCase just loads a bunch of thinsg... | 15:48 |
lbragstad | and i imagine most of it isn't actually used by stuff | 15:48 |
lbragstad | but there are some tests that need more resources created than what is provided there | 15:49 |
*** jmlowe has quit IRC | 15:49 | |
*** fiddletwix has joined #openstack-keystone | 15:50 | |
*** jdennis has quit IRC | 15:52 | |
*** jdennis has joined #openstack-keystone | 15:55 | |
kmalloc | well, bootstrap has always been expected to be expanded as we need, if we want to do it for tests, lets do it | 15:58 |
*** germs has joined #openstack-keystone | 16:02 | |
*** germs has quit IRC | 16:02 | |
*** germs has joined #openstack-keystone | 16:02 | |
lbragstad | ++ | 16:03 |
lbragstad | i have some more questions about that | 16:03 |
lbragstad | but i'll ping after the meeting | 16:03 |
*** ykarel is now known as ykarel|afk | 16:04 | |
*** germs has quit IRC | 16:07 | |
kmalloc | okie | 16:07 |
kmalloc | i'll be post-coffee, so easier to comprehend | 16:07 |
*** mgagne_ has quit IRC | 16:11 | |
*** mgagne_ has joined #openstack-keystone | 16:11 | |
*** spzala has joined #openstack-keystone | 16:21 | |
*** timothyb89_ is now known as timothyb89 | 16:22 | |
*** jdennis has quit IRC | 16:24 | |
*** jmlowe has joined #openstack-keystone | 16:26 | |
*** links has joined #openstack-keystone | 16:26 | |
*** mvk has quit IRC | 16:30 | |
*** jmlowe has quit IRC | 16:31 | |
*** AlexeyAbashkin has quit IRC | 16:31 | |
*** Krenair has quit IRC | 16:39 | |
*** afazekas has quit IRC | 16:39 | |
*** afazekas has joined #openstack-keystone | 16:39 | |
*** jmlowe has joined #openstack-keystone | 16:42 | |
*** jmlowe has quit IRC | 16:43 | |
*** d0ugal_ has joined #openstack-keystone | 16:44 | |
*** Krenair has joined #openstack-keystone | 16:46 | |
*** d0ugal has quit IRC | 16:47 | |
*** jmlowe has joined #openstack-keystone | 16:56 | |
lbragstad | #startmeeting keystone-office-hours | 17:01 |
openstack | Meeting started Tue Apr 3 17:01:42 2018 UTC and is due to finish in 60 minutes. The chair is lbragstad. Information about MeetBot at http://wiki.debian.org/MeetBot. | 17:01 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 17:01 |
*** openstack changes topic to " (Meeting topic: keystone-office-hours)" | 17:01 | |
*** ChanServ changes topic to "Rocky release schedule: https://releases.openstack.org/rocky/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/wmyzbFq5/keystone-rocky-roadmap" | 17:01 | |
openstack | The meeting name has been set to 'keystone_office_hours' | 17:01 |
lbragstad | just fyi - i have a few meetings to be in the next couple hours, but i'll try and check in here/multitask | 17:03 |
*** david-lyle has quit IRC | 17:04 | |
*** wxy| has quit IRC | 17:07 | |
*** esp has joined #openstack-keystone | 17:10 | |
lbragstad | for those who are familiar with ldap - i took a shot at documenting some how-tos for ldap backed development environments https://review.openstack.org/#/c/557997/ | 17:12 |
*** links has quit IRC | 17:13 | |
*** pcichy has quit IRC | 17:14 | |
eandersson | looks great lbragstad | 17:16 |
*** annp has quit IRC | 17:17 | |
*** annp has joined #openstack-keystone | 17:18 | |
*** idlemind has quit IRC | 17:18 | |
*** itlinux has quit IRC | 17:29 | |
* gagehugo steps out for lunch | 17:32 | |
*** AlexeyAbashkin has joined #openstack-keystone | 17:37 | |
lbragstad | eandersson: thanks for looking :) | 17:40 |
*** AlexeyAbashkin has quit IRC | 17:42 | |
*** itlinux has joined #openstack-keystone | 17:43 | |
*** felipemonteiro has joined #openstack-keystone | 17:43 | |
*** ykarel|afk has quit IRC | 17:46 | |
*** r-daneel has quit IRC | 17:50 | |
*** r-daneel has joined #openstack-keystone | 17:50 | |
*** thomasduval has joined #openstack-keystone | 17:52 | |
*** jmlowe has quit IRC | 18:00 | |
*** AlexeyAbashkin has joined #openstack-keystone | 18:02 | |
*** germs has joined #openstack-keystone | 18:03 | |
*** david-lyle has joined #openstack-keystone | 18:04 | |
*** AlexeyAbashkin has quit IRC | 18:06 | |
*** germs has quit IRC | 18:08 | |
*** thomasduval has quit IRC | 18:16 | |
*** tmcm has joined #openstack-keystone | 18:36 | |
tmcm | hello | 18:36 |
tmcm | doc/keystone-install-ubuntu.rst says: | 18:36 |
tmcm | "Before the Queens release, keystone needed to be run on two separate ports to | 18:36 |
tmcm | accomodate the Identity v2 API which ran a separate admin-only service | 18:36 |
tmcm | commonly on port 35357. With the removal of the v2 API, keystone can be run | 18:36 |
tmcm | on the same port for all interfaces." | 18:36 |
tmcm | does that mean the glance installation instructions that refer to "auth_url=http://controller:35357" should be modified to refer to :5000? | 18:37 |
tmcm | in other words, there is a discrepancy between the two installation documents | 18:37 |
*** isssp has joined #openstack-keystone | 18:38 | |
*** pcaruana has quit IRC | 18:44 | |
*** kencjohnston_ has joined #openstack-keystone | 18:45 | |
*** dstanek_ has joined #openstack-keystone | 18:45 | |
*** Chealion_ has joined #openstack-keystone | 18:46 | |
*** EmilienM_ has joined #openstack-keystone | 18:46 | |
*** EmilienM has quit IRC | 18:47 | |
*** mordred has quit IRC | 18:47 | |
*** dstanek has quit IRC | 18:47 | |
*** ispp has quit IRC | 18:47 | |
*** brad[] has quit IRC | 18:47 | |
*** Chealion has quit IRC | 18:47 | |
*** kencjohnston has quit IRC | 18:47 | |
*** Chealion_ is now known as Chealion | 18:47 | |
*** EmilienM_ is now known as EmilienM | 18:48 | |
*** EmilienM has quit IRC | 18:49 | |
*** EmilienM has joined #openstack-keystone | 18:49 | |
*** mordred has joined #openstack-keystone | 18:54 | |
*** AlexeyAbashkin has joined #openstack-keystone | 18:55 | |
*** dmellado has quit IRC | 18:56 | |
lbragstad | tmcm: yeah - that's likely the case | 18:57 |
*** voelzmo has joined #openstack-keystone | 18:58 | |
*** dmellado has joined #openstack-keystone | 18:58 | |
*** AlexeyAbashkin has quit IRC | 19:00 | |
*** dmellado has quit IRC | 19:12 | |
tmcm | so, we SHOULD or SHOULD NOT use the admin wsgi in queens? | 19:13 |
tmcm | on ubuntu specifically | 19:16 |
*** voelzmo has quit IRC | 19:17 | |
*** voelzmo has joined #openstack-keystone | 19:19 | |
*** dmellado has joined #openstack-keystone | 19:21 | |
*** jmlowe has joined #openstack-keystone | 19:23 | |
*** harlowja has joined #openstack-keystone | 19:23 | |
*** marius1 has joined #openstack-keystone | 19:24 | |
*** dmellado has quit IRC | 19:31 | |
*** mvk has joined #openstack-keystone | 19:37 | |
*** pcaruana has joined #openstack-keystone | 19:38 | |
*** brad[] has joined #openstack-keystone | 19:48 | |
*** pcaruana has quit IRC | 19:50 | |
*** dmellado has joined #openstack-keystone | 19:55 | |
*** david-lyle is now known as dklyle | 20:02 | |
tmcm | using the ldap driver, is there a way to have it fallback to sql for e.g., the service users like glance, neutron, etc? | 20:06 |
knikolla | tmcm: you can have different drivers for different domains | 20:13 |
knikolla | https://docs.openstack.org/keystone/latest/admin/identity-domain-specific-config.html | 20:13 |
*** tmcm has quit IRC | 20:15 | |
*** gagehugo has quit IRC | 20:17 | |
*** gagehugo has joined #openstack-keystone | 20:18 | |
*** itlinux has quit IRC | 20:19 | |
*** itlinux has joined #openstack-keystone | 20:21 | |
*** sapd has quit IRC | 20:30 | |
*** sapd has joined #openstack-keystone | 20:30 | |
*** sapd has quit IRC | 20:30 | |
*** sapd has joined #openstack-keystone | 20:31 | |
*** felipemonteiro_ has joined #openstack-keystone | 20:33 | |
*** marius1 has quit IRC | 20:35 | |
*** felipemonteiro has quit IRC | 20:36 | |
kmalloc | tmcm: it is also recommended that keystone be run on HTTP[S] instead of port 5000 or 35357. | 20:43 |
kmalloc | standard HTTP[S] ports* | 20:43 |
lbragstad | kmalloc: another bootstrap question for you | 20:52 |
kmalloc | yeah | 20:52 |
lbragstad | the argument parser for bootstrap has defaults, but if i want to pull the bootstrap logic out into it's own class so that it's easier to hook into the tests, should the defaults move with it? | 20:53 |
kmalloc | i'd say no | 20:53 |
lbragstad | so - keep the new object really generic | 20:53 |
kmalloc | yeah | 20:53 |
lbragstad | and unopinionated | 20:53 |
kmalloc | mostly because bootstrap is opinionated to get an install running | 20:53 |
kmalloc | tests do not adhere to those concepts | 20:53 |
kmalloc | don't do acrobatics to make the test look like you want it to | 20:54 |
kmalloc | tests should be explicit - and defaults can be bundled into the same mechanism we use to do the setup vs. encoding "real world standup" defaults into the core object | 20:54 |
kmalloc | s/same// | 20:55 |
kmalloc | fwiw, i've learned a lot about SR-IOV today | 20:55 |
kmalloc | it's cool tech, it's a bit weird how it's implemented. | 20:55 |
lbragstad | hmm - ok, i think i can make that work | 20:56 |
*** raildo has quit IRC | 20:57 | |
*** martinus__ has quit IRC | 21:00 | |
*** edmondsw has quit IRC | 21:09 | |
*** edmondsw has joined #openstack-keystone | 21:09 | |
*** itlinux has quit IRC | 21:13 | |
*** edmondsw has quit IRC | 21:14 | |
*** jmlowe has quit IRC | 21:19 | |
*** esp has left #openstack-keystone | 21:23 | |
*** spilla has quit IRC | 21:28 | |
*** rcernin has joined #openstack-keystone | 21:53 | |
*** AlexeyAbashkin has joined #openstack-keystone | 22:00 | |
*** spzala has quit IRC | 22:04 | |
*** AlexeyAbashkin has quit IRC | 22:05 | |
*** voelzmo has quit IRC | 22:31 | |
*** felipemonteiro_ has quit IRC | 22:35 | |
*** lbragstad has quit IRC | 22:36 | |
*** voelzmo has joined #openstack-keystone | 22:41 | |
*** voelzmo has quit IRC | 22:46 | |
*** voelzmo has joined #openstack-keystone | 22:48 | |
*** lbragstad has joined #openstack-keystone | 22:53 | |
*** ChanServ sets mode: +o lbragstad | 22:53 | |
lbragstad | #endmeeting | 22:53 |
*** voelzmo has quit IRC | 22:53 | |
*** tmcm has joined #openstack-keystone | 23:03 | |
*** itlinux has joined #openstack-keystone | 23:08 | |
*** r-daneel has quit IRC | 23:18 | |
*** threestrands has joined #openstack-keystone | 23:36 | |
*** threestrands has quit IRC | 23:37 | |
*** threestrands has joined #openstack-keystone | 23:38 | |
*** threestrands has quit IRC | 23:38 | |
*** threestrands has joined #openstack-keystone | 23:38 | |
*** threestrands has quit IRC | 23:39 | |
*** threestrands has joined #openstack-keystone | 23:39 | |
*** threestrands has quit IRC | 23:39 | |
*** threestrands has joined #openstack-keystone | 23:39 | |
*** threestrands has quit IRC | 23:40 | |
*** threestrands has joined #openstack-keystone | 23:41 | |
*** threestrands has quit IRC | 23:41 | |
*** threestrands has joined #openstack-keystone | 23:41 | |
*** spzala has joined #openstack-keystone | 23:45 | |
*** voelzmo has joined #openstack-keystone | 23:59 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!