*** erus has quit IRC | 00:42 | |
*** erus has joined #openstack-keystone | 00:52 | |
openstackgerrit | Merged openstack/keystone master: Move "Public ID Generators" to relevant docs https://review.openstack.org/624076 | 01:40 |
---|---|---|
*** vishwanathj has quit IRC | 01:51 | |
*** mhen has quit IRC | 02:30 | |
*** mhen has joined #openstack-keystone | 02:33 | |
openstackgerrit | wangxiyuan proposed openstack/oslo.policy master: Add policy-upgrade tool https://review.openstack.org/613906 | 02:34 |
*** jistr has quit IRC | 02:42 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Release note for domain level limit https://review.openstack.org/624019 | 02:47 |
*** jistr has joined #openstack-keystone | 02:50 | |
*** Dinesh_Bhor has joined #openstack-keystone | 02:57 | |
*** Dinesh_Bhor has quit IRC | 03:13 | |
*** Dinesh_Bhor has joined #openstack-keystone | 03:20 | |
openstackgerrit | Merged openstack/keystone master: Consolidate Keystone docs: federated-identity.rst https://review.openstack.org/547102 | 03:28 |
openstackgerrit | Merged openstack/keystone master: Move SSL recommendation to installation guide https://review.openstack.org/624100 | 03:28 |
openstackgerrit | Merged openstack/keystone master: Move supported clients section to user guide https://review.openstack.org/624115 | 03:28 |
*** bzhao__ has joined #openstack-keystone | 03:28 | |
*** ayoung has quit IRC | 03:44 | |
*** gyee has quit IRC | 03:53 | |
*** markvoelker has joined #openstack-keystone | 03:57 | |
*** markvoelker has quit IRC | 04:02 | |
*** Dinesh_Bhor has quit IRC | 04:56 | |
*** Dinesh_Bhor has joined #openstack-keystone | 04:57 | |
openstackgerrit | Merged openstack/keystone master: Use request_body_json function https://review.openstack.org/612492 | 04:58 |
*** Dinesh_Bhor has quit IRC | 05:17 | |
*** Dinesh_Bhor has joined #openstack-keystone | 05:19 | |
*** jmccrory has quit IRC | 06:34 | |
*** jmccrory has joined #openstack-keystone | 06:40 | |
*** rcernin has quit IRC | 06:43 | |
*** trident has quit IRC | 07:42 | |
*** trident has joined #openstack-keystone | 07:44 | |
*** imacdonn has quit IRC | 08:22 | |
*** imacdonn has joined #openstack-keystone | 08:23 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Consolidate Keystone docs: admin/identity-external-authentication.rst https://review.openstack.org/547087 | 08:39 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Consolidate tokenless X.509 docs https://review.openstack.org/624072 | 08:39 |
*** amoralej|off is now known as amoralej | 08:48 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Consolidate Keystone docs: admin/identity-external-authentication.rst https://review.openstack.org/547087 | 09:01 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Consolidate tokenless X.509 docs https://review.openstack.org/624072 | 09:01 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Update registered limit policies for system admin https://review.openstack.org/621016 | 09:15 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add tests for domain users interacting with registered limits https://review.openstack.org/621017 | 09:15 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add tests for project users interacting with registered limits https://review.openstack.org/621018 | 09:15 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove registered limit policies from policy.v3cloudsample.json https://review.openstack.org/621019 | 09:15 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add limit protection tests https://review.openstack.org/621020 | 09:15 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add limit tests for system member role https://review.openstack.org/621021 | 09:15 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Update limit policies for system admin https://review.openstack.org/621022 | 09:15 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add tests for domain users interacting with limits https://review.openstack.org/621023 | 09:15 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add tests for project users interacting with limits https://review.openstack.org/621024 | 09:15 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove limit policies from policy.v3cloudsample.json https://review.openstack.org/621025 | 09:15 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Consolidate tokenless X.509 docs https://review.openstack.org/624072 | 09:16 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Rename admin guide pages https://review.openstack.org/624327 | 09:27 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Move list limit docs to admin guide https://review.openstack.org/624337 | 09:54 |
*** shrasool has joined #openstack-keystone | 09:56 | |
*** Dinesh_Bhor has quit IRC | 10:10 | |
*** shrasool has quit IRC | 10:26 | |
*** Dinesh_Bhor has joined #openstack-keystone | 10:34 | |
*** shrasool has joined #openstack-keystone | 10:37 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Rename admin guide pages https://review.openstack.org/624327 | 10:44 |
*** erus has quit IRC | 10:52 | |
*** erus has joined #openstack-keystone | 10:52 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Move list limit docs to admin guide https://review.openstack.org/624337 | 10:57 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Move identity sources doc to admin guide https://review.openstack.org/624351 | 10:57 |
*** erus has quit IRC | 10:59 | |
*** tobias-urdin is now known as tobias-urdin|lun | 11:00 | |
*** tobias-urdin|lun is now known as tobias-urdin_afk | 11:01 | |
* lbragstad back in about an hour | 11:05 | |
*** erus has joined #openstack-keystone | 11:09 | |
*** shrasool has quit IRC | 11:21 | |
*** shrasool has joined #openstack-keystone | 11:22 | |
*** shrasool has quit IRC | 11:26 | |
*** tobias-urdin_afk is now known as tobias-urdin | 11:27 | |
*** Dinesh_Bhor has quit IRC | 11:37 | |
openstackgerrit | Merged openstack/keystone master: Implement system reader role in domains API https://review.openstack.org/623334 | 11:39 |
*** amoralej is now known as amoralej|lunch | 12:06 | |
openstackgerrit | Merged openstack/keystone master: Consolidate Keystone docs: admin/identity-external-authentication.rst https://review.openstack.org/547087 | 12:45 |
openstackgerrit | Merged openstack/keystone master: Consolidate tokenless X.509 docs https://review.openstack.org/624072 | 12:45 |
openstackgerrit | Merged openstack/keystone master: Rename admin guide pages https://review.openstack.org/624327 | 12:45 |
openstackgerrit | Merged openstack/keystone master: Move list limit docs to admin guide https://review.openstack.org/624337 | 12:45 |
*** raildo has joined #openstack-keystone | 12:52 | |
*** dave-mccowan has joined #openstack-keystone | 12:54 | |
*** dave-mccowan has quit IRC | 13:01 | |
*** amoralej|lunch is now known as amoralej | 13:16 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Fix links to external-authentication https://review.openstack.org/624391 | 13:23 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add introduction section to federation docs https://review.openstack.org/615384 | 13:44 |
*** aojea_ has joined #openstack-keystone | 13:45 | |
*** imus has joined #openstack-keystone | 14:03 | |
*** mvkr has quit IRC | 14:07 | |
*** dave-mccowan has joined #openstack-keystone | 14:07 | |
*** dave-mccowan has quit IRC | 14:14 | |
*** aojea_ has quit IRC | 14:14 | |
*** shrasool has joined #openstack-keystone | 14:18 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Fix links to external-authentication https://review.openstack.org/624391 | 14:34 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add introduction section to federation docs https://review.openstack.org/615384 | 14:39 |
*** mvkr has joined #openstack-keystone | 14:44 | |
*** markvoelker has joined #openstack-keystone | 15:00 | |
*** itlinux has quit IRC | 15:06 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Remove Certificates for PKI guide https://review.openstack.org/624419 | 15:08 |
*** wxy| has joined #openstack-keystone | 15:14 | |
openstackgerrit | Merged openstack/keystone master: Implement system member role domain test coverage https://review.openstack.org/605849 | 15:35 |
*** aojea_ has joined #openstack-keystone | 15:36 | |
kmalloc | o/ | 15:37 |
cmurphy | \o | 15:39 |
cmurphy | kmalloc: stable review for you https://review.openstack.org/614197 | 15:40 |
kmalloc | lookingh | 15:40 |
kmalloc | cmurphy: +3 | 15:41 |
cmurphy | ty | 15:41 |
lbragstad | friendly reminder that we have the keystone team meeting in about 10 minutes | 15:48 |
knikolla | o/ | 15:50 |
*** markvoelker has quit IRC | 15:55 | |
*** markvoelker has joined #openstack-keystone | 15:56 | |
*** markvoelker has quit IRC | 16:01 | |
*** itlinux has joined #openstack-keystone | 16:22 | |
*** wxy| has quit IRC | 16:49 | |
*** itlinux_ has joined #openstack-keystone | 16:59 | |
*** aojea_ has quit IRC | 17:02 | |
*** aojea_ has joined #openstack-keystone | 17:03 | |
*** itlinux has quit IRC | 17:03 | |
*** aojea_ has quit IRC | 17:07 | |
*** gyee has joined #openstack-keystone | 17:22 | |
lbragstad | in case anyone is interesting in light reading https://review.openstack.org/#/c/619053/5/specs/2019.03/approved/distcloud-2002842-synchronizedKeystone.rst | 17:44 |
lbragstad | ^ that's the formal specification for what the stx folks have for the db replication stuff they're going to do with keystone | 17:44 |
kmalloc | yeah.... | 17:45 |
kmalloc | i'm not a huge fan of db sync like that | 17:48 |
kmalloc | i also see some major concerns with the distribution of the fernet keys | 17:49 |
kmalloc | and a lot of other stuff that seems to be glossed over/handwaved | 17:49 |
* kmalloc still thinks autoprovision is the most correct way to handle this. | 17:49 | |
kmalloc | i'm interested to see how the DB sync bits end up rolling out | 17:50 |
kmalloc | and if it will scale. | 17:50 |
*** gyee has quit IRC | 17:56 | |
lbragstad | i'm curious to see the progress they have on it | 17:57 |
lbragstad | but - it looks like the spec just merged | 17:58 |
*** mchlumsky has quit IRC | 17:59 | |
kmalloc | yeah | 18:02 |
kmalloc | by the time i looked it was approved/merged | 18:03 |
*** mchlumsky has joined #openstack-keystone | 18:03 | |
*** mvkr has quit IRC | 18:04 | |
*** erus has quit IRC | 18:39 | |
*** erus has joined #openstack-keystone | 18:40 | |
*** shrasool_ has joined #openstack-keystone | 18:43 | |
*** shrasool has quit IRC | 18:45 | |
*** shrasool_ is now known as shrasool | 18:45 | |
*** amoralej is now known as amoralej|off | 18:48 | |
*** aojea has joined #openstack-keystone | 18:56 | |
*** mchlumsky has quit IRC | 19:00 | |
*** mchlumsky has joined #openstack-keystone | 19:01 | |
openstackgerrit | Merged openstack/keystone-specs master: Repropose JWT specification for Stein https://review.openstack.org/541903 | 19:07 |
openstackgerrit | Merged openstack/keystone-specs master: Add a note about crypto-agility with JWT https://review.openstack.org/622543 | 19:10 |
openstackgerrit | Merged openstack/keystone master: Fix links to external-authentication https://review.openstack.org/624391 | 19:23 |
openstackgerrit | Merged openstack/keystone master: Add introduction section to federation docs https://review.openstack.org/615384 | 19:24 |
*** lbragstad has quit IRC | 19:30 | |
*** lbragstad has joined #openstack-keystone | 19:31 | |
*** ChanServ sets mode: +o lbragstad | 19:31 | |
*** shrasool has quit IRC | 20:34 | |
*** shrasool has joined #openstack-keystone | 20:35 | |
lbragstad | now that we have the fix from jdennis in oslo.policy - https://github.com/openstack/keystone/blob/master/keystone/common/rbac_enforcer/enforcer.py#L382-L404 is redundant i think? | 21:07 |
*** shrasool has quit IRC | 21:14 | |
jdennis | lbragstad: +1 | 21:16 |
lbragstad | thanks for confirming | 21:17 |
*** mvkr has joined #openstack-keystone | 21:18 | |
*** aojea has quit IRC | 21:19 | |
*** shrasool has joined #openstack-keystone | 21:26 | |
*** shrasool has quit IRC | 21:32 | |
*** markvoelker has joined #openstack-keystone | 21:45 | |
*** erus has quit IRC | 21:48 | |
*** markvoelker has quit IRC | 21:49 | |
*** itlinux_ has quit IRC | 21:57 | |
*** rcernin has joined #openstack-keystone | 21:59 | |
*** markvoelker has joined #openstack-keystone | 22:24 | |
*** itlinux has joined #openstack-keystone | 22:26 | |
*** raildo has quit IRC | 22:39 | |
*** itlinux has quit IRC | 22:45 | |
*** shrasool has joined #openstack-keystone | 22:55 | |
kmalloc | lbragstad: yeah, it is mostly redundant | 23:08 |
kmalloc | lbragstad: though... the "authorizing X" shoudl stay | 23:08 |
kmalloc | lbragstad: https://github.com/openstack/keystone/blob/master/keystone/common/rbac_enforcer/enforcer.py#L388 | 23:08 |
kmalloc | lbragstad: that is not directly represented in the oslo.policy bits | 23:09 |
kmalloc | lbragstad: so https://github.com/openstack/keystone/blob/master/keystone/common/rbac_enforcer/enforcer.py#L391-L404 is redundant | 23:09 |
*** erus has joined #openstack-keystone | 23:35 | |
*** xek_ has joined #openstack-keystone | 23:43 | |
*** xek has quit IRC | 23:46 | |
*** dklyle has joined #openstack-keystone | 23:51 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!