*** shrasool has quit IRC | 00:00 | |
*** erus has quit IRC | 00:03 | |
*** erus has joined #openstack-keystone | 00:04 | |
*** erus has quit IRC | 00:06 | |
*** itlinux has joined #openstack-keystone | 00:06 | |
*** dklyle has quit IRC | 00:21 | |
*** itlinux_ has joined #openstack-keystone | 00:25 | |
*** itlinux has quit IRC | 00:28 | |
*** dklyle has joined #openstack-keystone | 00:34 | |
*** xek__ has joined #openstack-keystone | 00:37 | |
*** xek_ has quit IRC | 00:39 | |
*** itlinux_ has quit IRC | 00:49 | |
*** dklyle has quit IRC | 01:04 | |
*** dave-mccowan has joined #openstack-keystone | 01:16 | |
*** erus has joined #openstack-keystone | 01:20 | |
*** markvoelker has quit IRC | 01:41 | |
openstackgerrit | Merged openstack/keystone master: Remove Certificates for PKI guide https://review.openstack.org/624419 | 01:57 |
---|---|---|
*** Dinesh_Bhor has joined #openstack-keystone | 02:01 | |
*** erus has quit IRC | 02:03 | |
*** erus has joined #openstack-keystone | 02:15 | |
openstackgerrit | ayoung proposed openstack/keystone master: Remove message about circular role inferences https://review.openstack.org/624553 | 02:25 |
*** jrist has quit IRC | 02:25 | |
*** Dinesh_Bhor has quit IRC | 02:27 | |
*** mhen has quit IRC | 02:28 | |
*** mhen has joined #openstack-keystone | 02:31 | |
*** Dinesh_Bhor has joined #openstack-keystone | 02:33 | |
*** Dinesh_Bhor has quit IRC | 03:34 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: [api-ref] add domain level limit support https://review.openstack.org/624562 | 03:46 |
*** dave-mccowan has quit IRC | 03:52 | |
*** Dinesh_Bhor has joined #openstack-keystone | 04:42 | |
*** fiddletwix has quit IRC | 05:18 | |
*** fiddletwix has joined #openstack-keystone | 05:19 | |
*** itlinux has joined #openstack-keystone | 05:21 | |
*** dklyle has joined #openstack-keystone | 05:51 | |
*** itlinux has quit IRC | 05:51 | |
*** dklyle has quit IRC | 05:56 | |
*** Dinesh_Bhor has quit IRC | 06:13 | |
*** Dinesh_Bhor has joined #openstack-keystone | 06:47 | |
*** masayukig[m] has joined #openstack-keystone | 07:13 | |
*** openstackgerrit has quit IRC | 07:29 | |
*** dklyle has joined #openstack-keystone | 07:29 | |
*** rcernin has quit IRC | 07:30 | |
*** alexchadin has joined #openstack-keystone | 07:31 | |
*** openstackgerrit has joined #openstack-keystone | 07:51 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Move identity sources doc to admin guide https://review.openstack.org/624351 | 07:51 |
*** trident has quit IRC | 07:58 | |
*** trident has joined #openstack-keystone | 08:00 | |
*** amoralej|off is now known as amoralej | 08:12 | |
*** imacdonn has quit IRC | 08:23 | |
*** imacdonn has joined #openstack-keystone | 08:23 | |
*** dklyle has quit IRC | 08:32 | |
*** markvoelker has joined #openstack-keystone | 08:44 | |
*** markvoelker has quit IRC | 08:49 | |
*** markvoelker has joined #openstack-keystone | 09:39 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Split trusts docs between admin and user guide https://review.openstack.org/624622 | 10:17 |
*** Dinesh_Bhor has quit IRC | 10:24 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Remove example usage from admin guide https://review.openstack.org/624637 | 10:34 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Delete outdated keystonemiddleware doc https://review.openstack.org/624645 | 10:40 |
*** Dinesh_Bhor has joined #openstack-keystone | 10:49 | |
*** markvoelker has quit IRC | 11:30 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Consolidate service catalog docs https://review.openstack.org/624673 | 11:30 |
*** erus has quit IRC | 11:32 | |
*** erus has joined #openstack-keystone | 11:32 | |
*** Dinesh_Bhor has quit IRC | 11:33 | |
*** erus has quit IRC | 11:38 | |
*** erus has joined #openstack-keystone | 11:47 | |
*** erus has quit IRC | 11:54 | |
*** rafaelweingartne has joined #openstack-keystone | 11:58 | |
*** erus has joined #openstack-keystone | 12:02 | |
*** markvoelker has joined #openstack-keystone | 12:05 | |
*** raildo has joined #openstack-keystone | 12:20 | |
*** amoralej is now known as amoralej|lunch | 12:29 | |
*** rafaelweingartne has quit IRC | 12:39 | |
*** dave-mccowan has joined #openstack-keystone | 12:40 | |
openstackgerrit | Moisés Guimarães de Medeiros proposed openstack/oslo.policy master: Add ability for policy-checker to read configuration https://review.openstack.org/616659 | 12:43 |
openstackgerrit | Colleen Murphy proposed openstack/keystone-specs master: Add spec for immutable roles https://review.openstack.org/624692 | 13:27 |
*** markvoelker has quit IRC | 13:28 | |
*** amoralej|lunch is now known as amoralej | 13:46 | |
*** markvoelker has joined #openstack-keystone | 14:01 | |
*** irclogbot_1 has quit IRC | 14:32 | |
*** jrist has joined #openstack-keystone | 14:37 | |
*** irclogbot_1 has joined #openstack-keystone | 14:42 | |
gagehugo | o/ | 14:49 |
*** irclogbot_1 has quit IRC | 14:55 | |
lbragstad | hola | 14:56 |
*** markvoelker has quit IRC | 15:18 | |
*** irclogbot_1 has joined #openstack-keystone | 15:20 | |
*** jrist has quit IRC | 15:21 | |
*** alexchadin has quit IRC | 15:22 | |
knikolla | o/ | 15:27 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Consolidate service catalog docs https://review.openstack.org/624673 | 15:29 |
*** mchlumsky has quit IRC | 15:38 | |
*** mchlumsky has joined #openstack-keystone | 15:40 | |
*** jrist has joined #openstack-keystone | 15:54 | |
*** gyee has joined #openstack-keystone | 16:19 | |
*** ayoung has joined #openstack-keystone | 16:24 | |
*** itlinux has joined #openstack-keystone | 16:53 | |
kmalloc | lbragstad: i'm going to add the DB Schema version # to the keystone cache key generator. that should eliminate all "upgrade and data drifted" | 17:06 |
kmalloc | causing an implicit cache pop if the schema version change(s) | 17:07 |
kmalloc | lbragstad: and that can be loaded on startup. | 17:07 |
kmalloc | looking at bug #1793389 | 17:07 |
openstack | bug 1793389 in OpenStack Identity (keystone) "Upgrade to Ocata: Keystone Intermittent Missing 'options' Key" [Undecided,New] https://launchpad.net/bugs/1793389 - Assigned to Lance Bragstad (lbragstad) | 17:07 |
kmalloc | we can consider if we want to backport it down the line | 17:07 |
lbragstad | ok | 17:08 |
*** erus has quit IRC | 17:13 | |
*** erus has joined #openstack-keystone | 17:14 | |
*** erus has quit IRC | 17:19 | |
*** erus has joined #openstack-keystone | 17:21 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system reader role for projects https://review.openstack.org/624215 | 17:44 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system member role project test coverage https://review.openstack.org/624216 | 17:44 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system admin role in project API https://review.openstack.org/624217 | 17:44 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement domain reader functionality for projects https://review.openstack.org/624218 | 17:44 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement domain member functionality for projects https://review.openstack.org/624219 | 17:44 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement domain admin functionality for projects https://review.openstack.org/624220 | 17:44 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add explicit testing for project users and the project API https://review.openstack.org/624221 | 17:44 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove project policies from policy.v3cloudsample.json https://review.openstack.org/624222 | 17:44 |
lbragstad | gmann there is the latest series ^ | 17:44 |
lbragstad | but as far as what i can validate locally with tempest, everything after https://review.openstack.org/#/c/624218/ is going to fail because domain admins in tempest don't have the correct authorization (e.g., an 'admin' on the Default domain can list all projects in the deployment) | 17:46 |
lbragstad | fwiw - if i set CONF.identity.domain_scope = False, all the tests pass for me through the whole series | 17:46 |
lbragstad | curious if anyone else has opinions on ^ | 17:54 |
lbragstad | steps out to shovel snow quick | 17:54 |
*** raildo has quit IRC | 17:58 | |
*** raildo has joined #openstack-keystone | 17:58 | |
*** jrist has quit IRC | 18:33 | |
*** raildo_ has joined #openstack-keystone | 18:35 | |
*** raildo has quit IRC | 18:35 | |
openstackgerrit | Merged openstack/pycadf master: Change openstack-dev to openstack-discuss https://review.openstack.org/622286 | 18:38 |
*** amoralej is now known as amoralej|off | 19:08 | |
openstackgerrit | Merged openstack/keystone master: Implement system admin role in domains API https://review.openstack.org/605850 | 19:29 |
openstackgerrit | Merged openstack/keystone master: Update registered limit policies for system admin https://review.openstack.org/621016 | 19:29 |
*** ayoung has quit IRC | 19:35 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement domain reader functionality for projects https://review.openstack.org/624218 | 19:46 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement domain member functionality for projects https://review.openstack.org/624219 | 19:46 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement domain admin functionality for projects https://review.openstack.org/624220 | 19:47 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add explicit testing for project users and the project API https://review.openstack.org/624221 | 19:47 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove project policies from policy.v3cloudsample.json https://review.openstack.org/624222 | 19:47 |
lbragstad | gmann i put some more context into the commit message of ^ and linked to it here https://review.openstack.org/#/c/624218/ | 19:48 |
lbragstad | gmann actually - nevermind, i got my links mixed up.. i put more context here - https://review.openstack.org/624794 | 20:01 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove duplicate RBAC logging from enforcer https://review.openstack.org/624799 | 20:04 |
*** kmalloc is now known as notmorgan | 20:10 | |
*** notmorgan is now known as morgan | 20:10 | |
*** itlinux_ has joined #openstack-keystone | 20:14 | |
*** itlinux has quit IRC | 20:15 | |
*** jrist has joined #openstack-keystone | 20:30 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Propose a backlogged specification for resource locking https://review.openstack.org/624807 | 20:39 |
lbragstad | cmurphy ^ | 20:39 |
*** dklyle has joined #openstack-keystone | 20:39 | |
*** ayoung has joined #openstack-keystone | 20:42 | |
ayoung | lbragstad, I just modified this bug to make it service scoped specific. It was origianlly Default domain: https://bugs.launchpad.net/keystone/+bug/1808059 | 20:44 |
openstack | Launchpad bug 1808059 in OpenStack Identity (keystone) "admin user should have service scoped admin role" [Undecided,New] | 20:44 |
ayoung | Bootstrap should be the minimum, but if we remove what it currently creates, we will break some tooling | 20:44 |
lbragstad | i'm missing the point | 20:50 |
lbragstad | keystone-manage bootstrap already creates an admin user and grants them the admin role on the system | 20:50 |
ayoung | lbragstad, ah, right...we got that . It was based on a discussion for creating one for the domain] | 20:57 |
lbragstad | system admin support was added in https://review.openstack.org/#/c/530410/ | 20:57 |
ayoung | lbragstad, do we still create the admin project and role on that? | 20:57 |
lbragstad | yes | 20:58 |
lbragstad | the admin user gets an admin role on the admin project for backwards compatibility | 20:58 |
ayoung | so...I wonder if we should stop doing that, or start doing a role on the default domain | 20:58 |
lbragstad | the Default domain should just be another domain, right? | 20:58 |
ayoung | lbragstad, well, yeah, but you should need a domain scoped token to create projects etc | 20:58 |
ayoung | not project scoped, so admin on admin_project is really a throwbak | 20:59 |
ayoung | and...I suspect that people are using that project + Bug968696 to do basic system config | 20:59 |
lbragstad | system administrators can create projects under the default domain | 21:01 |
*** rcernin has joined #openstack-keystone | 21:06 | |
*** jmlowe has quit IRC | 21:10 | |
*** jmlowe has joined #openstack-keystone | 21:11 | |
*** jmlowe has quit IRC | 21:13 | |
*** jmlowe has joined #openstack-keystone | 21:14 | |
*** xek__ has quit IRC | 21:18 | |
morgan | ayoung: that isn't a valid bug still | 21:35 |
morgan | until NFV plugins can consume system scope | 21:36 |
morgan | that is a bug against the NFV stuff first. | 21:36 |
morgan | ayoung: i'd rather not try and trac that with the NFV parts | 21:36 |
*** jonher has joined #openstack-keystone | 21:37 | |
morgan | and it looks like system scope is somewhat handled in bootstrap according to bug #1749268 | 21:40 |
openstack | bug 1749268 in OpenStack Identity (keystone) queens "`keystone-manage bootstrap` doesn't handle system role assignments" [High,Fix committed] https://launchpad.net/bugs/1749268 - Assigned to Lance Bragstad (lbragstad) | 21:40 |
morgan | ayoung: ^ | 21:40 |
cmurphy | lbragstad: uh https://review.openstack.org/624692 | 21:42 |
lbragstad | lol | 21:42 |
lbragstad | at first glance, yours looks more specific than mine, which is probably a good thing :) | 21:43 |
cmurphy | maybe we can combine them | 21:43 |
lbragstad | sure | 21:44 |
openstackgerrit | Merged openstack/keystonemiddleware master: Added request_id and global_request_id to CADF notifications https://review.openstack.org/618712 | 21:58 |
*** itlinux_ has quit IRC | 22:00 | |
*** dklyle has quit IRC | 22:00 | |
*** itlinux has joined #openstack-keystone | 22:00 | |
*** kklimonda_ has joined #openstack-keystone | 22:23 | |
*** awestin1_ has joined #openstack-keystone | 22:24 | |
*** obre_ has joined #openstack-keystone | 22:25 | |
*** andreykurilin has quit IRC | 22:29 | |
*** rledisez has quit IRC | 22:29 | |
*** masayukig[m] has quit IRC | 22:29 | |
*** obre has quit IRC | 22:29 | |
*** awestin1 has quit IRC | 22:29 | |
*** kklimonda has quit IRC | 22:29 | |
*** awestin1_ is now known as awestin1 | 22:29 | |
*** trident has quit IRC | 22:32 | |
*** trident has joined #openstack-keystone | 22:34 | |
*** itlinux has quit IRC | 22:35 | |
*** mchlumsky has quit IRC | 22:57 | |
*** raildo_ has quit IRC | 23:06 | |
*** dave-mccowan has quit IRC | 23:19 | |
*** dklyle has joined #openstack-keystone | 23:35 | |
*** fiddletwix has quit IRC | 23:45 | |
*** dklyle has quit IRC | 23:45 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!