openstackgerrit | Merged openstack/keystone master: Add tempest-full-py3 job to zuul file https://review.openstack.org/617828 | 00:07 |
---|---|---|
*** erus has quit IRC | 01:29 | |
*** erus has joined #openstack-keystone | 01:36 | |
*** Dinesh_Bhor has joined #openstack-keystone | 01:50 | |
*** bzhao__ has joined #openstack-keystone | 02:20 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Add domain_id column for limit https://review.openstack.org/620202 | 02:23 |
*** bzhao__ has quit IRC | 02:27 | |
*** bzhao__ has joined #openstack-keystone | 02:34 | |
*** Dinesh_Bhor has quit IRC | 03:02 | |
*** Dinesh_Bhor has joined #openstack-keystone | 03:13 | |
*** mvkr has quit IRC | 03:47 | |
*** Dinesh_Bhor has quit IRC | 04:10 | |
*** Dinesh_Bhor has joined #openstack-keystone | 04:31 | |
vishakha | knikolla: Thanks for the response. Other than metadata tag, entity id is to be removed from SSO and do we need to add any discovery protocol too? | 05:50 |
*** rcernin has quit IRC | 06:58 | |
*** pcaruana has joined #openstack-keystone | 07:23 | |
*** artem_vasilyev has joined #openstack-keystone | 07:29 | |
artem_vasilyev | hey guys, if anyone has time could you pls review these changes: https://review.openstack.org/#/c/618095/ and https://review.openstack.org/#/c/618712/ | 07:32 |
*** irclogbot_1 has quit IRC | 08:44 | |
*** irclogbot_1 has joined #openstack-keystone | 08:46 | |
*** irclogbot_1 has quit IRC | 08:53 | |
*** irclogbot_1 has joined #openstack-keystone | 08:56 | |
*** amoralej|off is now known as amoralej | 09:01 | |
*** xek has joined #openstack-keystone | 09:01 | |
lbragstad | if anyone would like to take a gander at https://review.openstack.org/#/c/605539/ | 09:11 |
lbragstad | merging that would make it easier to rebase a whole bunch of bug fixes | 09:12 |
*** jackivanov has joined #openstack-keystone | 09:16 | |
*** shrasool has joined #openstack-keystone | 09:17 | |
wxy-xiyuan | lbragstad: for https://review.openstack.org/#/c/605539/24/keystone/common/context.py seems some key-values are missing? https://github.com/openstack/keystone/blob/master/keystone/server/flask/request_processing/middleware/auth_context.py#L422-L430 | 09:31 |
lbragstad | we might be able to add those in | 09:33 |
lbragstad | good catch | 09:33 |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/oslo.policy master: oslopolicy-checker: iterate through rules in sorted order https://review.openstack.org/619724 | 09:36 |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/oslo.policy master: Add ability for policy-checker to read configuration https://review.openstack.org/616659 | 09:37 |
*** xek has quit IRC | 09:44 | |
*** xek has joined #openstack-keystone | 09:48 | |
*** artem_vasilyev has quit IRC | 09:57 | |
*** artem_vasilyev has joined #openstack-keystone | 10:04 | |
*** xek has quit IRC | 10:18 | |
*** xek has joined #openstack-keystone | 10:23 | |
*** jlvillal has joined #openstack-keystone | 10:59 | |
lbragstad | the policy API in keystone is deprecated | 11:29 |
lbragstad | i'm opening bugs for all applicable APIs that aren't using default roles | 11:29 |
lbragstad | but since policy is deprecated, would anyone be opposed to not opening one for that? | 11:29 |
lbragstad | otherwise, I can and just mark it as Low? | 11:30 |
lbragstad | if i'm doing all this for other APIs, I want to be consistent, but also don't want to make it a priority if we have other things to do | 11:30 |
*** raildo has joined #openstack-keystone | 11:37 | |
*** xek has quit IRC | 11:40 | |
*** erus has quit IRC | 12:00 | |
lbragstad | hrybacki https://bugs.launchpad.net/keystone/+bugs?field.tag=default-roles should be a list of nearly all keystone policies that aren't taking default roles into account | 12:02 |
*** erus has joined #openstack-keystone | 12:02 | |
*** rafaelweingartne has joined #openstack-keystone | 12:04 | |
rafaelweingartne | Is it possible to use OpenStack with more than one IdP via OIDC? | 12:04 |
*** amoralej is now known as amoralej|lunch | 12:04 | |
*** xek has joined #openstack-keystone | 12:11 | |
*** Dinesh_Bhor has quit IRC | 12:13 | |
kmalloc | lbragstad: make it a wishlist bug | 12:16 |
kmalloc | lbragstad: policy API is holdover, we can close the bug as won't fix when we get further down the line | 12:17 |
kmalloc | But if someone provides an clean fix we can accept it. | 12:17 |
kmalloc | Don't put effort into it beyond that. | 12:17 |
lbragstad | makes sense | 12:20 |
*** shrasool has quit IRC | 12:27 | |
*** erus has quit IRC | 12:35 | |
*** erus has joined #openstack-keystone | 12:36 | |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Make upgrades more robust with policy overrides https://review.openstack.org/614195 | 12:42 |
openstackgerrit | Merged openstack/oslo.policy master: Correct typo in docs https://review.openstack.org/620148 | 12:50 |
*** takamatsu has quit IRC | 12:58 | |
*** dave-mccowan has joined #openstack-keystone | 13:01 | |
*** amoralej|lunch is now known as amoralej | 13:06 | |
*** dave-mccowan has quit IRC | 13:06 | |
*** rafaelweingartne has quit IRC | 13:09 | |
*** shrasool has joined #openstack-keystone | 13:14 | |
*** takamatsu has joined #openstack-keystone | 13:21 | |
frickler | keystoneclient-devstack-functional seems to be constantly failing for some weeks now, is anybody working on that? e.g. http://logs.openstack.org/39/605539/24/check/keystoneclient-devstack-functional/9fff540/job-output.txt.gz#_2018-11-27_04_39_26_939041 | 13:32 |
*** takamatsu has quit IRC | 13:37 | |
lbragstad | frickler i can take a look | 13:38 |
lbragstad | throwing it on the meeting agenda for today to socialize it a bit | 13:38 |
lbragstad | frickler you brought another failure to use recently, too | 13:39 |
lbragstad | is this related to that? | 13:39 |
* lbragstad can't remember | 13:39 | |
*** takamatsu has joined #openstack-keystone | 13:43 | |
*** jhesketh_ has joined #openstack-keystone | 13:44 | |
frickler | lbragstad: the other failure is with federation testing on bionic, I don't think that that's related | 13:49 |
lbragstad | ok - there was a bug reported for that i think? | 13:49 |
frickler | https://bugs.launchpad.net/ubuntu/+source/xmltooling/+bug/1776489 | 13:49 |
openstack | Launchpad bug 1776489 in xmltooling (Ubuntu) "libxmltooling7 depends on libcurl3, which has been replaced by libcurl4 in Bionic" [Undecided,Confirmed] | 13:49 |
frickler | and https://bugs.launchpad.net/keystone/+bug/1802901 | 13:50 |
openstack | Launchpad bug 1802901 in OpenStack Identity (keystone) "Federation functional job failing on Bionic" [Undecided,New] | 13:50 |
*** jhesketh has quit IRC | 13:50 | |
lbragstad | cool | 13:50 |
frickler | workaround for the latter currently would be to keep the federation job on xenial when we switch everything else to bionic https://review.openstack.org/#/c/611563/4/.zuul.yaml | 13:51 |
lbragstad | ok - good to know | 13:52 |
lbragstad | frickler are you familiar with the test-setup.sh script? specifically how it is invoked? | 14:00 |
lbragstad | looks like the same script is copied across multiple repositories, without much difference | 14:01 |
frickler | lbragstad: there's a generic zuul role that does this: http://git.openstack.org/cgit/openstack-infra/zuul-jobs/tree/roles/test-setup/README.rst | 14:03 |
frickler | lbragstad: but I didn't look at the script itself yet in detail | 14:03 |
lbragstad | gotcha - well the script is failing early on | 14:03 |
lbragstad | here I think https://git.openstack.org/cgit/openstack/keystone/tree/tools/test-setup.sh#n18 | 14:04 |
*** Dinesh_Bhor has joined #openstack-keystone | 14:04 | |
lbragstad | which doesn't seem a whole lot different from https://git.openstack.org/cgit/openstack/nova/tree/tools/test-setup.sh#n18 | 14:05 |
*** Dinesh_Bhor has quit IRC | 14:05 | |
lbragstad | but i'm not sure how nova relies on that for testing (like we do with the ksc functional tests) | 14:05 |
lbragstad | maybe they ksc functional tests are missing a step prior to calling that script | 14:06 |
frickler | lbragstad: nova seems to still be using the old legacy job novaclient-dsvm-functional , most likely the devstack-gate environment is different than what the new zuul v3 setup does | 14:10 |
frickler | lbragstad: but it may indeed be an issue not related to keystone directly, so if you don't have any obvious idea, I'll check with other infra folks | 14:10 |
lbragstad | hmmm | 14:12 |
hrybacki | such organization lbragstad :D | 14:14 |
hrybacki | man after my own heart | 14:14 |
*** mchlumsky has joined #openstack-keystone | 14:23 | |
lbragstad | lol | 14:26 |
* lbragstad hopes it'll be easier for people to pick up | 14:27 | |
*** xek has quit IRC | 14:30 | |
*** xek has joined #openstack-keystone | 14:34 | |
*** mordred has joined #openstack-keystone | 14:36 | |
*** xek_ has joined #openstack-keystone | 14:43 | |
*** artem_vasilyev has quit IRC | 14:44 | |
*** xek has quit IRC | 14:46 | |
knikolla | vishakha: correct. | 14:53 |
*** erus has quit IRC | 14:55 | |
*** erus has joined #openstack-keystone | 14:56 | |
*** edmondsw has joined #openstack-keystone | 14:59 | |
ildikov | lbragstad: hi | 15:03 |
ildikov | lbragstad: are you joining the edge call? | 15:03 |
lbragstad | ildikov o/ | 15:03 |
lbragstad | joining | 15:03 |
ildikov | tnx :) | 15:03 |
ildikov | https://zoom.us/j/879678938 | 15:03 |
ildikov | if anyone else is interested | 15:03 |
*** wxy| has joined #openstack-keystone | 15:36 | |
*** ayoung has joined #openstack-keystone | 15:48 | |
*** dansmith has quit IRC | 16:02 | |
*** dansmith has joined #openstack-keystone | 16:02 | |
*** shrasool has quit IRC | 16:42 | |
hrybacki | ugh, when is the next DST shift, I keep missing the Tuesday meetings... | 16:54 |
gagehugo | lol | 16:55 |
gagehugo | just a few more months | 16:56 |
lbragstad | hrybacki you need to adjust your calendar to use UTC ;) | 16:56 |
*** gyee has joined #openstack-keystone | 16:59 | |
* kmalloc runs off | 17:00 | |
lbragstad | curious if anyone would be willing to look at https://review.openstack.org/#/c/605539/ | 17:00 |
lbragstad | I can rebase a bunch of patches after that mergeds | 17:00 |
lbragstad | merges* | 17:00 |
* knikolla runs to lunch | 17:01 | |
kmalloc | lbragstad: uh | 17:01 |
kmalloc | lbragstad: are you still putting a fully rendered token in the policy (target) dict? | 17:01 |
kmalloc | lbragstad: because *not* doing that will potentially break people. | 17:01 |
kmalloc | lbragstad: it is a real concern. | 17:02 |
lbragstad | yeah - it's still in there https://review.openstack.org/#/c/605539/24/keystone/common/context.py@65 | 17:02 |
lbragstad | values is the target dict | 17:02 |
lbragstad | as is your comment | 17:02 |
kmalloc | cool | 17:03 |
kmalloc | that was the only previous sticking point i had | 17:03 |
lbragstad | cool | 17:03 |
kmalloc | lbragstad: +2 | 17:03 |
kmalloc | lbragstad: https://review.openstack.org/#/c/619260/ that needs eyes | 17:03 |
kmalloc | it's just about equally important | 17:04 |
*** wxy| has quit IRC | 17:04 | |
lbragstad | aha - will review | 17:04 |
kmalloc | i know it is failing | 17:04 |
kmalloc | but i want eyes on the content | 17:04 |
gagehugo | lbragstad: what are you meaning by "these" here: https://review.openstack.org/#/c/617829/1/.zuul.yaml@a195 ? | 17:04 |
kmalloc | so we can fix all at once. | 17:04 |
kmalloc | lbragstad: note that with full-IDP a lot of our policy stuff will be *changed* again | 17:05 |
lbragstad | gagehugo we're not defining anything under line 195 like we were | 17:05 |
kmalloc | since we wont be extracting from a token in all cases. | 17:05 |
kmalloc | but i think it'll be good to support more normalized session-like use | 17:05 |
kmalloc | anyway i need to run, dr appt. | 17:05 |
kmalloc | be back later | 17:05 |
lbragstad | ack | 17:05 |
lbragstad | gagehugo irrelevant-files is empty? | 17:05 |
gagehugo | the old one? | 17:06 |
* gagehugo is confused | 17:06 | |
lbragstad | should it be pointing to something? like on line 136 | 17:06 |
lbragstad | https://review.openstack.org/#/c/617829/1/.zuul.yaml@138 | 17:07 |
gagehugo | It's pointing to "*tempest-irrelevant-files", unless I'm mistaken? | 17:09 |
ayoung | kmalloc, when you get back, I'd like to get your setup for Docker based Keystone Dev. Make it easier than doing from first principals | 17:09 |
gagehugo | https://review.openstack.org/#/c/617829/1/.zuul.yaml@148 | 17:10 |
lbragstad | bah - my diff was garbage | 17:11 |
lbragstad | apparently unified didn't show that properly? | 17:11 |
lbragstad | it's clearer using side-by-side | 17:11 |
*** erus has quit IRC | 17:21 | |
*** erus has joined #openstack-keystone | 17:21 | |
*** jmlowe has quit IRC | 17:32 | |
*** jmlowe has joined #openstack-keystone | 17:33 | |
*** jmlowe has quit IRC | 17:34 | |
*** imacdonn has quit IRC | 17:54 | |
*** imacdonn has joined #openstack-keystone | 17:55 | |
openstackgerrit | Merged openstack/keystone master: Update api-ref to include user options https://review.openstack.org/603319 | 17:58 |
gagehugo | lbragstad: oh lol | 18:00 |
gagehugo | I typically use side-by-side | 18:00 |
*** jmlowe has joined #openstack-keystone | 18:05 | |
*** bnemec has quit IRC | 18:06 | |
*** bnemec has joined #openstack-keystone | 18:06 | |
kmalloc | ayoung: right now i just have a unit test docker story handy | 18:17 |
kmalloc | ayoung: https://gist.github.com/morganfainberg/ab9fd86abfbced49fdb14ea15736aafc | 18:19 |
frickler | lbragstad: cmurphy: https://review.openstack.org/613385 is broken. the job works when running against python-keystoneclient, but fails when run against keystone | 18:19 |
kmalloc | ayoung: i am working on a more generic standup keystone thing | 18:19 |
lbragstad | frickler do we need to revert that? | 18:21 |
frickler | lbragstad: maybe revert as a short term solution, or come up with a proper fix. I can take a closer look tomorrow, maybe since it isn't voting and was broken for 3 weeks it isn't 100% urgent | 18:22 |
lbragstad | true | 18:23 |
lbragstad | i might be able to give you a hand tomorrow if you want to ping me then | 18:23 |
frickler | lbragstad: sure, thx | 18:23 |
lbragstad | no problem - thanks for digging into it | 18:23 |
*** amoralej is now known as amoralej|off | 18:34 | |
openstackgerrit | Merged openstack/keystone master: Move irrelevant-files to project definition https://review.openstack.org/617829 | 18:48 |
*** shrasool has joined #openstack-keystone | 18:53 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Don't emit a notification for the root domain https://review.openstack.org/617846 | 18:58 |
lbragstad | summary for those interested in it https://www.lbragstad.com/blog/openstack-summit-berlin-recap | 19:10 |
*** jlvillal has left #openstack-keystone | 19:10 | |
ayoung | kmalloc, thanks. running the docker build now. What does that do for database? | 19:12 |
ayoung | kmalloc, BTW, I am running from /opt/stack/keystone, so I removed the 3 lines that pull in files from /opt like /opt/bindep.txt Is there any reason to maintain those? | 19:24 |
kmalloc | Just for unit tests now | 19:26 |
ayoung | kmalloc, something not quite right: | 19:26 |
kmalloc | The bindep is so the binary bits are installed in the container | 19:26 |
ayoung | I changed them to ./bindep.txt etc and now | 19:26 |
ayoung | Step 8/13 : ADD ./${OS_PROJECT:-keystone}/bindep.txt ./bindep.txt | 19:26 |
ayoung | lstat keystone/bindep.txt: no such file or directory | 19:26 |
kmalloc | It is Ubuntu specific for now | 19:26 |
kmalloc | Hmm | 19:26 |
ayoung | should it be full path? | 19:27 |
kmalloc | Right. So I always work from outside the keystone directory | 19:27 |
kmalloc | You have an extra ./ Maybe | 19:27 |
ayoung | which order is ADD | 19:28 |
ayoung | Ah...that is it | 19:28 |
kmalloc | Yeah ././ Won't work | 19:28 |
kmalloc | It should...but doesn't. | 19:28 |
kmalloc | I have a docker compose with a DB setup etc, but I haven't published it | 19:29 |
ayoung | I was running in /opt/stack/keystone | 19:29 |
kmalloc | It wasn't kept up like my unit test one. | 19:29 |
ayoung | I have a running mariadb instance | 19:29 |
kmalloc | In the container? | 19:29 |
ayoung | in a separate container | 19:29 |
kmalloc | The /opt/stack | 19:29 |
kmalloc | Part | 19:29 |
ayoung | http://adam.younglogic.com/2017/01/connecting-net-maria-docker/ | 19:29 |
kmalloc | Right. | 19:29 |
ayoung | My old setup was: | 19:30 |
ayoung | http://adam.younglogic.com/2017/01/functional-keystone-docker/ | 19:30 |
kmalloc | I can't read it right now easily | 19:30 |
kmalloc | On mobile. Looking though. | 19:30 |
ayoung | I appreciate the "right now" as it implies that at some point you could read my stuff easily. You are too kind | 19:30 |
kmalloc | Haha just hard to read mobile blogy things | 19:31 |
ayoung | I use the mobile plugin and everything! | 19:31 |
kmalloc | So, the goal is a docker compose and a published loci or otherwise setup container | 19:32 |
kmalloc | Nah, it is this phone | 19:32 |
kmalloc | Having slow loading. | 19:32 |
ayoung | and I just filled up my root fs | 19:33 |
kmalloc | Ultimately, I want the default unit test cases for folks to use is a docker setup like this. (officially recommended) | 19:33 |
kmalloc | So we can easily test diff distros | 19:34 |
kmalloc | I also want a docker compose to standup a clean keystone consistently | 19:34 |
ayoung | What is your plan for Database? External container, or spun up with Keystone? | 19:35 |
*** jmlowe has quit IRC | 19:48 | |
ayoung | kmalloc, so Fedora installer decided I needed 400GiB for /home and only 50 for / and guess where I am running out of disk space on a 1/2 T Drive? | 19:48 |
* ayoung looks into shrinking a partition. again | 19:48 | |
*** jmlowe has joined #openstack-keystone | 19:50 | |
*** ayoung has quit IRC | 19:51 | |
lbragstad | thanks for the review on context objects gagehugo | 20:01 |
gagehugo | lbragstad: :) I'll try to go up the chain | 20:02 |
lbragstad | they are all pretty cookie cutter | 20:02 |
lbragstad | but ping me if you have questions | 20:02 |
gagehugo | will do | 20:02 |
*** jrist has quit IRC | 20:22 | |
gagehugo | lbragstad: dumb question, but in https://review.openstack.org/#/c/620156/1 we are deprecating RULE_ADMIN_REQUIRED for role:reader correct? | 20:30 |
gagehugo | not the actual policy mapping, only the check_str | 20:32 |
*** imacdonn has quit IRC | 20:37 | |
*** imacdonn has joined #openstack-keystone | 20:37 | |
*** jmlowe has quit IRC | 20:45 | |
openstackgerrit | Merged openstack/keystone master: Pass context objects to policy enforcement https://review.openstack.org/605539 | 20:52 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Move to password validation schema https://review.openstack.org/614294 | 20:58 |
*** erus has quit IRC | 21:14 | |
*** raildo has quit IRC | 21:14 | |
*** jrist has joined #openstack-keystone | 21:15 | |
*** erus has joined #openstack-keystone | 21:15 | |
nsmeds | Hey guys, is there any known differences in performance comparing Domains w/ projects vs Projects w/ subprojects? Say when you're getting into the thousands of each. Or should it be similar? | 21:18 |
nsmeds | I'm imaging it makes no difference and is just decision about how you want things organised | 21:18 |
*** imacdonn has quit IRC | 21:20 | |
*** imacdonn has joined #openstack-keystone | 21:24 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Clarify docstrings for domain flask refactor https://review.openstack.org/620409 | 21:26 |
*** jmlowe has joined #openstack-keystone | 21:33 | |
*** xek_ has quit IRC | 21:35 | |
*** pcaruana has quit IRC | 21:46 | |
*** shrasool has quit IRC | 21:55 | |
openstackgerrit | Merged openstack/keystone master: Bump sqlalchemy minimum version to 1.1.0 https://review.openstack.org/613830 | 21:56 |
*** erus has quit IRC | 22:06 | |
*** erus has joined #openstack-keystone | 22:12 | |
*** erus has quit IRC | 22:15 | |
*** shrasool has joined #openstack-keystone | 22:28 | |
*** erus has joined #openstack-keystone | 22:37 | |
*** shrasool has quit IRC | 22:39 | |
*** erus has quit IRC | 22:39 | |
*** shrasool has joined #openstack-keystone | 22:46 | |
*** shrasool has quit IRC | 22:46 | |
openstackgerrit | Merged openstack/keystonemiddleware master: Add py36 tox environment https://review.openstack.org/615843 | 22:55 |
*** rcernin has joined #openstack-keystone | 22:57 | |
*** adriant has quit IRC | 23:07 | |
*** adriant has joined #openstack-keystone | 23:15 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: [WIP] Add functional testing gate https://review.openstack.org/531014 | 23:27 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: [WIP] Add functional testing gate https://review.openstack.org/531014 | 23:32 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: [WIP] Add functional testing gate https://review.openstack.org/531014 | 23:41 |
*** jhesketh_ is now known as jhesketh | 23:51 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!