*** markvoelker has quit IRC | 00:17 | |
*** markvoelker has joined #openstack-keystone | 00:17 | |
*** markvoelker has quit IRC | 00:21 | |
*** gyee has quit IRC | 00:29 | |
*** aojea has joined #openstack-keystone | 00:42 | |
*** aojea has quit IRC | 00:46 | |
*** Dinesh_Bhor has joined #openstack-keystone | 01:31 | |
*** Dinesh_Bhor has quit IRC | 01:38 | |
*** Dinesh_Bhor has joined #openstack-keystone | 01:47 | |
*** dave-mccowan has joined #openstack-keystone | 01:56 | |
*** markvoelker has joined #openstack-keystone | 02:18 | |
*** cfriesen has quit IRC | 02:28 | |
*** shyamb has joined #openstack-keystone | 02:36 | |
*** markvoelker has quit IRC | 02:51 | |
kmalloc | holy crap. i think i have it done. | 02:53 |
---|---|---|
kmalloc | auth is running tests locally and then will be pushed up. | 02:53 |
kmalloc | #endmeeting | 02:54 |
*** openstack changes topic to "Stein release schedule: https://releases.openstack.org/stein/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/rj0ECz2c/keystone-stein-roadmap !!NOTE!! This Channel is Logged ( https://tinyurl.com/OpenStackKeystone )" | 02:54 | |
openstack | Meeting ended Wed Oct 3 02:54:02 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 02:54 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/keystone_office_hours/2018/keystone_office_hours.2018-10-02-17.04.html | 02:54 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/keystone_office_hours/2018/keystone_office_hours.2018-10-02-17.04.txt | 02:54 |
kmalloc | (oopse, that went long | 02:54 |
openstack | Log: http://eavesdrop.openstack.org/meetings/keystone_office_hours/2018/keystone_office_hours.2018-10-02-17.04.log.html | 02:54 |
kmalloc | knikolla, ayoung, cmurphy, gagehugo: sorry about the massive patch =/ | 02:54 |
*** shyam89 has joined #openstack-keystone | 02:55 | |
gagehugo | uh oh | 02:56 |
*** shyamb has quit IRC | 02:59 | |
*** Dinesh_Bhor has quit IRC | 03:00 | |
*** Dinesh_Bhor has joined #openstack-keystone | 03:01 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: WIP: Convert auth to flask native dispatching https://review.openstack.org/603461 | 03:07 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: WIP: Convert auth to flask native dispatching https://review.openstack.org/603461 | 03:07 |
*** dave-mccowan has quit IRC | 03:08 | |
*** shyam89 has quit IRC | 03:25 | |
*** shyam89 has joined #openstack-keystone | 03:37 | |
*** markvoelker has joined #openstack-keystone | 03:48 | |
*** Dinesh_Bhor has quit IRC | 04:01 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: WIP: Convert auth to flask native dispatching https://review.openstack.org/603461 | 04:03 |
*** Dinesh_Bhor has joined #openstack-keystone | 04:05 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Convert auth to flask native dispatching https://review.openstack.org/603461 | 04:05 |
kmalloc | there we go | 04:06 |
kmalloc | gagehugo: +1797, -1435 | 04:07 |
kmalloc | gagehugo: =/ | 04:07 |
kmalloc | gagehugo: and that passes local pep8,py27,py35 | 04:08 |
kmalloc | and it should pass temptest. | 04:08 |
kmalloc | tempest* | 04:08 |
*** shyam89 has quit IRC | 04:11 | |
*** Dinesh_Bhor has quit IRC | 04:20 | |
*** markvoelker has quit IRC | 04:21 | |
*** shyamb has joined #openstack-keystone | 04:53 | |
*** Dinesh_Bhor has joined #openstack-keystone | 04:58 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Avoid using dict.get() in assertions https://review.openstack.org/607463 | 05:00 |
*** markvoelker has joined #openstack-keystone | 05:18 | |
*** leeuwenrjj has joined #openstack-keystone | 05:37 | |
*** shyamb has quit IRC | 05:51 | |
*** markvoelker has quit IRC | 05:52 | |
*** Dinesh_Bhor has quit IRC | 06:11 | |
*** shyamb has joined #openstack-keystone | 06:21 | |
*** dims has quit IRC | 06:24 | |
*** dims has joined #openstack-keystone | 06:26 | |
*** dims has quit IRC | 06:34 | |
*** Dinesh_Bhor has joined #openstack-keystone | 06:35 | |
*** dims has joined #openstack-keystone | 06:35 | |
*** pcaruana has joined #openstack-keystone | 06:51 | |
*** mbuil has joined #openstack-keystone | 07:18 | |
*** Dinesh_Bhor has quit IRC | 07:19 | |
*** jroll has quit IRC | 07:19 | |
*** dmellado has quit IRC | 07:19 | |
*** mbuil_ has quit IRC | 07:19 | |
*** odyssey4me has quit IRC | 07:19 | |
*** jroll has joined #openstack-keystone | 07:32 | |
*** dmellado has joined #openstack-keystone | 07:32 | |
*** odyssey4me has joined #openstack-keystone | 07:32 | |
*** shyamb has quit IRC | 07:46 | |
*** rcernin has quit IRC | 07:55 | |
*** jroll has quit IRC | 08:13 | |
*** dmellado has quit IRC | 08:13 | |
*** odyssey4me has quit IRC | 08:13 | |
*** markvoelker has joined #openstack-keystone | 08:18 | |
*** jroll has joined #openstack-keystone | 08:27 | |
*** dmellado has joined #openstack-keystone | 08:27 | |
*** odyssey4me has joined #openstack-keystone | 08:27 | |
*** Emine has joined #openstack-keystone | 08:41 | |
*** shyamb has joined #openstack-keystone | 08:42 | |
*** jroll has quit IRC | 08:51 | |
*** dmellado has quit IRC | 08:51 | |
*** odyssey4me has quit IRC | 08:51 | |
*** markvoelker has quit IRC | 08:51 | |
*** pjrusak has joined #openstack-keystone | 09:01 | |
pjrusak | have a quick question about keystone identity endpoints post queens? i tried to figure out from documentation and kolla/devstack code which ports and endpoints are expected one and it's not clear for me | 09:05 |
*** jroll has joined #openstack-keystone | 09:05 | |
*** dmellado has joined #openstack-keystone | 09:05 | |
*** odyssey4me has joined #openstack-keystone | 09:05 | |
pjrusak | currently devstack setup keystone to listen on 80 whith routes http://service_host/identity/ while kolla deploys keystone with classic manner 35357 and 5000 port. which is the proper way now? | 09:05 |
*** Emine has quit IRC | 09:12 | |
*** Emine has joined #openstack-keystone | 09:25 | |
*** shyamb has quit IRC | 10:01 | |
*** shyamb has joined #openstack-keystone | 10:03 | |
*** Emine has quit IRC | 10:07 | |
*** kukacz has quit IRC | 10:12 | |
*** kukacz has joined #openstack-keystone | 10:13 | |
*** leeuwenrjj has quit IRC | 10:28 | |
*** shyamb has quit IRC | 10:34 | |
*** shyamb has joined #openstack-keystone | 10:41 | |
gmann | cmurphy: gagehugo can you guys check this tempest patch if that is write approach to skip the keystone write operation test - https://review.openstack.org/#/c/585536/7 | 10:46 |
*** mvkr has quit IRC | 10:48 | |
*** leeuwenrjj has joined #openstack-keystone | 10:48 | |
*** markvoelker has joined #openstack-keystone | 10:49 | |
*** mvkr has joined #openstack-keystone | 11:02 | |
*** markvoelker has quit IRC | 11:22 | |
*** shyamb has quit IRC | 11:34 | |
*** shyamb has joined #openstack-keystone | 11:34 | |
*** shyamb has quit IRC | 11:42 | |
*** raildo has joined #openstack-keystone | 11:48 | |
*** shyamb has joined #openstack-keystone | 12:02 | |
*** Emine has joined #openstack-keystone | 12:14 | |
*** dave-mccowan has joined #openstack-keystone | 12:20 | |
*** jdennis has quit IRC | 12:51 | |
*** jdennis has joined #openstack-keystone | 13:05 | |
*** jdennis has quit IRC | 13:05 | |
*** shyamb has quit IRC | 13:05 | |
*** jdennis has joined #openstack-keystone | 13:06 | |
*** shyamb has joined #openstack-keystone | 13:07 | |
*** aojea_ has joined #openstack-keystone | 13:09 | |
*** aojea_ has quit IRC | 13:13 | |
*** aojea_ has joined #openstack-keystone | 13:15 | |
*** mvkr has quit IRC | 13:23 | |
*** aojea_ has quit IRC | 13:28 | |
*** aojea_ has joined #openstack-keystone | 13:29 | |
*** aojea_ has quit IRC | 13:33 | |
*** cfriesen has joined #openstack-keystone | 13:39 | |
*** mvkr has joined #openstack-keystone | 13:50 | |
*** shyamb has quit IRC | 13:58 | |
*** shyamb has joined #openstack-keystone | 14:01 | |
*** adriant has quit IRC | 14:03 | |
*** adriant has joined #openstack-keystone | 14:04 | |
*** leeuwenrjj has quit IRC | 14:20 | |
*** ayoung has quit IRC | 14:20 | |
*** shyamb has quit IRC | 14:24 | |
*** mbeierl has quit IRC | 14:25 | |
*** mbeierl has joined #openstack-keystone | 14:43 | |
*** mbeierl has quit IRC | 14:44 | |
gagehugo | gmann looking | 14:44 |
kmalloc | O/ | 14:56 |
kmalloc | Looks like I need to fix federation, but otherwise good on auth. | 14:56 |
*** Emine has quit IRC | 14:58 | |
*** leeuwenrjj has joined #openstack-keystone | 15:08 | |
*** pcaruana has quit IRC | 15:33 | |
kmalloc | pjrusak: on port 80/443 | 15:56 |
kmalloc | pjrusak: under /identity is the preferred way. | 15:56 |
kmalloc | Proper is very subjective. But our recommendation is standard http ports and sub-url mounting. | 15:57 |
leeuwenrjj | kmalloc, did you get around to create an example for the integration of middleware? | 15:58 |
kmalloc | leeuwenrjj: sorry i did not, i got buried in the current set of patches and dog emergencies. | 15:59 |
kmalloc | leeuwenrjj: i'll probably be able to do it today. i have minimal fixes still needed for the horrible patch to convert auth to flask (and it is super hard to switch that context) | 16:00 |
leeuwenrjj | No worries no rush. Just post it in the IRC if you have it. I'm in Europe so I will go offline soon but I will read it back. Thx! | 16:01 |
*** gyee has joined #openstack-keystone | 16:06 | |
kmalloc | leeuwenrjj: sounds good. | 16:09 |
kmalloc | leeuwenrjj: i expect to be onto that today because i have some other non-code related things to stand up this week too. | 16:09 |
*** aojea has joined #openstack-keystone | 16:15 | |
*** shyamb has joined #openstack-keystone | 16:17 | |
*** aojea has quit IRC | 16:19 | |
*** leeuwenrjj has quit IRC | 16:26 | |
*** shyamb has quit IRC | 16:28 | |
*** dims has quit IRC | 16:28 | |
*** dims_ has joined #openstack-keystone | 16:35 | |
kmalloc | knikolla: need your eyes on a security bug | 16:41 |
*** ayoung has joined #openstack-keystone | 16:48 | |
kmalloc | ayoung: should have auth change done today. it's brutal, but it's ... there | 16:48 |
kmalloc | ayoung: it's passing everything but federation tests, but i think i have that solved now | 16:48 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Convert auth to flask native dispatching https://review.openstack.org/603461 | 16:51 |
kmalloc | knikolla: auth flaskification is ready for eyes. | 16:56 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Convert auth to flask native dispatching https://review.openstack.org/603461 | 17:12 |
kmalloc | also... sorry =/ | 17:12 |
*** tbharath has joined #openstack-keystone | 17:12 | |
tbharath | Hi, I have Openstack queens setup. Is there a way to enable keystone v2 version in Queens setup? | 17:13 |
kmalloc | tbharath: it is not possible. V2 was removed from keystone completely | 17:15 |
kmalloc | tbharath: https://docs.openstack.org/releasenotes/keystone/queens.html#other-notes see the laste note. | 17:15 |
kmalloc | last* | 17:15 |
kmalloc | tbharath: ultimately, v2 had some major security gaps that could not be closed easily. The solution was to migrate (over the course of ~4+ years) to v3. Queens is the release where we forced the issue. barring major security concerns, following the queens release, no APIs will be removed / contracts broken (intentionally, please let us know if something breaks in v3 in unexpected ways) | 17:17 |
tbharath | sure, got it thanks for clarification kmalloc | 17:18 |
kmalloc | tbharath: happy to help. | 17:20 |
*** mvkr has quit IRC | 17:39 | |
*** tbharath has quit IRC | 17:44 | |
*** imacdonn has quit IRC | 18:21 | |
*** imacdonn has joined #openstack-keystone | 18:21 | |
*** pcaruana has joined #openstack-keystone | 18:24 | |
*** itlinux has joined #openstack-keystone | 18:24 | |
*** felipemonteiro has joined #openstack-keystone | 18:29 | |
ayoung | kmalloc, you are a rock. Excellent | 18:30 |
*** mvkr has joined #openstack-keystone | 18:34 | |
ayoung | kmalloc, why changes like if not flask.request.remote_user: | 18:36 |
ayoung | where the request comes from flask as opposed to passing it in as a parameter. It seems more magical, and less explicit | 18:36 |
*** gyee has quit IRC | 18:50 | |
*** pcaruana has quit IRC | 18:50 | |
kmalloc | because the request object is held globally for a request now | 19:04 |
kmalloc | you don't pass requests around, you reference then | 19:04 |
kmalloc | flask.request is the canonical location for the environment/request instance | 19:04 |
kmalloc | similar to flask.g is the global "app" (per request) context. | 19:05 |
kmalloc | simply, flask doesn't pass a request around | 19:05 |
kmalloc | webob does. | 19:05 |
kmalloc | it also means the request object is accessible wherever needed and not needing to be passed from auth controller to auth plugin to notification decorator to the identity_manager.authenticate method | 19:06 |
kmalloc | it's a lot cleaner than trying to find all places that a request is passed through in case something changed something. in this setup, you look for who sets values on flask.request | 19:06 |
kmalloc | so i contest, it is less explicit but not more magical, it is more like "we have a thread local store, use it" | 19:07 |
*** spartakos has joined #openstack-keystone | 19:25 | |
kmalloc | mordred: this is largely taking the same stance we did with CLI moving early to OSC. | 19:37 |
kmalloc | mordred: bah. stupid cross-channel talk. | 19:38 |
mordred | kmalloc: :) | 19:42 |
*** naptastic has joined #openstack-keystone | 20:17 | |
*** spartakos has quit IRC | 20:17 | |
*** gyee has joined #openstack-keystone | 20:24 | |
*** aojea has joined #openstack-keystone | 20:36 | |
*** aojea has quit IRC | 20:38 | |
*** aojea has joined #openstack-keystone | 20:38 | |
*** felipemonteiro has quit IRC | 20:40 | |
*** pjrusak has quit IRC | 20:45 | |
*** raildo has quit IRC | 20:53 | |
*** spartakos has joined #openstack-keystone | 20:54 | |
*** spartakos has quit IRC | 21:08 | |
*** felipemonteiro has joined #openstack-keystone | 21:11 | |
*** spartakos has joined #openstack-keystone | 21:26 | |
*** naptastic has quit IRC | 21:43 | |
openstackgerrit | Merged openstack/keystone master: Add hint back https://review.openstack.org/603964 | 21:51 |
*** itlinux has quit IRC | 22:09 | |
*** spartakos has quit IRC | 22:17 | |
*** rcernin has joined #openstack-keystone | 22:25 | |
*** aojea has quit IRC | 22:43 | |
*** spartakos has joined #openstack-keystone | 23:02 | |
*** Zer0Byte_ has joined #openstack-keystone | 23:09 | |
Zer0Byte_ | hi | 23:09 |
Zer0Byte_ | how i can use api 2.0 with domains? | 23:09 |
*** Zer0Byte_ has quit IRC | 23:37 | |
*** itlinux has joined #openstack-keystone | 23:48 | |
kmalloc | ayoung: thanks for catching the recheck on auth | 23:48 |
*** mchlumsky has quit IRC | 23:49 | |
ayoung | kmalloc, NP. I try to keep the big ones moving | 23:54 |
ayoung | kmalloc, the changes looks ok. I think I would have preferred you left things in auth/controllers.py that moved under api/_shared, but A) I assume you had a reason for that and B) even if you didn't I would not make you reverse it now | 23:56 |
kmalloc | ayoung: shared between auth and os-federation | 23:57 |
kmalloc | ayoung: specifically authenticate_for_token | 23:57 |
kmalloc | ayoung: ultimately, we can deprecate the os-federation entries and move the primary ones under /auth and do the same thing we do for /auth/tokens/projects and just route both paths to the same resource | 23:58 |
kmalloc | ayoung: if you notice at the top of keystone.api._shared.authentication you see a TODO | 23:58 |
kmalloc | # TODO(morgan): Deprecate all auth flows in /v3/OS-FEDERATION, merge this code | 23:59 |
kmalloc | # into keystone.api.auth. For now this is the best place for the code to | 23:59 |
kmalloc | # exist. | 23:59 |
ayoung | kmalloc, and I take it the code refereced HAS to be under api/ for flask reasons? | 23:59 |
kmalloc | no. | 23:59 |
kmalloc | but it's "view" code | 23:59 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!