Friday, 2019-01-04

*** gyee has quit IRC00:45
*** markvoelker has quit IRC00:54
*** markvoelker has joined #openstack-keystone00:54
*** lbragstad has quit IRC00:59
*** markvoelker has quit IRC00:59
*** lbragstad has joined #openstack-keystone01:08
*** ChanServ sets mode: +o lbragstad01:08
*** lbragstad has quit IRC01:09
*** sayalilunkad has quit IRC01:23
*** sayalilunkad has joined #openstack-keystone01:28
*** dave-mccowan has quit IRC01:41
openstackgerritwangxiyuan proposed openstack/keystone master: Invalidate shadow_federated_user cache when deleting protocol  https://review.openstack.org/62813201:46
*** dave-mccowan has joined #openstack-keystone01:48
*** szaher has quit IRC01:51
*** markvoelker has joined #openstack-keystone01:55
*** mhen has quit IRC02:05
*** mhen has joined #openstack-keystone02:06
*** erus has quit IRC02:13
*** markvoelker has quit IRC02:46
*** markvoelker has joined #openstack-keystone02:46
*** lifeless has joined #openstack-keystone03:10
*** cfriesen has quit IRC03:36
*** erus has joined #openstack-keystone03:44
*** shyamb has joined #openstack-keystone03:59
*** sapd1_ has quit IRC04:12
*** sapd1__ has joined #openstack-keystone04:12
*** shyamb has quit IRC04:14
*** dave-mccowan has quit IRC04:25
*** whoami-rajat has joined #openstack-keystone05:22
*** shyamb has joined #openstack-keystone05:37
*** shyamb has quit IRC05:56
*** shyamb has joined #openstack-keystone06:01
*** ayoung has quit IRC06:29
*** rcernin has quit IRC06:47
*** shyamb has quit IRC07:08
*** sapd1__ has quit IRC07:41
*** shyamb has joined #openstack-keystone07:50
*** shyamb has quit IRC07:57
*** markvoelker has quit IRC08:08
*** markvoelker has joined #openstack-keystone08:08
*** markvoelker has quit IRC08:13
*** shyamb has joined #openstack-keystone08:16
*** jaosorior has joined #openstack-keystone08:39
*** xek_ has joined #openstack-keystone09:10
*** shyamb has quit IRC09:17
openstackgerritColleen Murphy proposed openstack/keystone master: Add prerequisites section to keystone-to-keystone  https://review.openstack.org/62784709:46
openstackgerritColleen Murphy proposed openstack/keystone master: Enhance authn sections in federation guide  https://review.openstack.org/62796609:46
openstackgerritColleen Murphy proposed openstack/keystone master: Clean up keystone-to-keystone section  https://review.openstack.org/62796809:46
openstackgerritColleen Murphy proposed openstack/keystone master: Reorganize guide on configuring a keystone SP  https://review.openstack.org/62797209:46
openstackgerritColleen Murphy proposed openstack/keystone master: Add section on configuring protected auth paths  https://review.openstack.org/62797509:46
openstackgerritColleen Murphy proposed openstack/keystone master: Consolidate WebSSO guide into SP instructions  https://review.openstack.org/62797609:46
openstackgerritColleen Murphy proposed openstack/keystone master: Enhance the shibboleth guide  https://review.openstack.org/62798209:46
openstackgerritColleen Murphy proposed openstack/keystone master: Enhance the mellon guide  https://review.openstack.org/62799309:46
openstackgerritColleen Murphy proposed openstack/keystone master: Enhance the openidc guide  https://review.openstack.org/62803709:46
*** markvoelker has joined #openstack-keystone10:09
*** erus has quit IRC11:08
*** erus has joined #openstack-keystone11:09
*** erus has quit IRC11:16
*** erus has joined #openstack-keystone11:22
*** erus has quit IRC11:29
*** shyamb has joined #openstack-keystone11:29
*** erus has joined #openstack-keystone11:38
*** erus has quit IRC11:44
*** erus has joined #openstack-keystone11:52
*** erus has quit IRC11:59
*** raildo has joined #openstack-keystone12:04
*** erus has joined #openstack-keystone12:09
*** lifeless has quit IRC12:42
*** kevko has joined #openstack-keystone13:02
kevkoHi, can someone advice me how to debug slow keystoneclient on debian ? When trying to get token via openstack token issue on debian  ..it takes 5 seconds ... on devstack ubuntu 1.5 ... any ideas how to compare ? ...versions of a clients are the same13:03
cmurphykevko: do you have caching enabled on the keystone server?13:04
*** raildo_ has joined #openstack-keystone13:19
*** raildo has quit IRC13:19
*** markvoelker has quit IRC13:33
*** markvoelker has joined #openstack-keystone13:33
kevkocmurphy: no i don't have13:39
kevkocmurphy: i'm not troubleshooting keystone ...keystone is responding in 0.7 sec ...it is OK , which problem i'm trying to solve is , that client is slow ... and i really don't know why13:40
kevkocmurphy: 1 ,   i've tried to create venv with inherit packages from system and local checkouted openstackclient from git => SLOW,   2, Created pure venv , run the same code = FAST     :(13:42
cmurphykevko: the only reason i can think of for it to be that slow is that caching is disabled or the cache is not warmed up on the first request13:45
cmurphyif it's not that, you can try using the --debug option or some python profiling library to debug the client itself13:46
kevkocmurphy: i tried profiling ...but i am not more clever from it ...13:53
kevkocmurphy: ok, i will try more13:54
kevkothanks for this time13:54
*** mvkr has quit IRC13:57
*** shyamb has quit IRC14:01
*** dave-mccowan has joined #openstack-keystone14:03
*** erus has quit IRC14:07
*** lbragstad has joined #openstack-keystone14:08
*** ChanServ sets mode: +o lbragstad14:08
*** erus has joined #openstack-keystone14:09
*** mvkr has joined #openstack-keystone14:12
lbragstado/14:17
cmurphy\o14:17
erus\o/14:17
aning_lbragstad: ayoung is not online yet ... for the explicit domain IDs, will keystone local users ID be preditable as well?14:19
aning_I read the spec, it mainly talks about domain ids.14:19
aning_and ayoung mentioned sha256(domain_id, federated_user_name) yesterday.14:21
lbragstadby local user ids do you mean SQL users?14:21
aning_Yes, the users in "local" user table. These are the users authenticated locally by keystone.14:22
aning_sorry I mean "user" table.14:23
lbragstadright - i wasn't sure if you were asking about ldap users or sql users14:23
aning_sql users, not ldap14:24
lbragstadi'm not sure if the plan is to make sql user ids predictable14:24
aning_I'm a bit confused since keystone has "federated_user".14:25
aning_Should it be explicitly in the spec?14:25
lbragstadwell, keystone has a federated_user, local_user, nonlocal_user, and user tables14:29
lbragstadnonlocal_user is for users from ldap14:29
aning_Oh well, I think sql users will be covered, since the user model in keystone is, the "user" table holds the unique IDs, and other tables like "local_user" and "federated_user" reference to the ID of "user" table.14:30
lbragstadright14:30
lbragstadi'm not sure if he is planning on doing that work with the domain id work14:30
aning_right, the spec only say "The IDs for users will now fall into the category of “predictable-but-not-settable.” Since the uuid is a hash of the string, and not explicitly setable, the will not be a potential for “User_ID squatting.” where a user pre-allocates an entry to block another user."14:32
aning_maybe just for ldap users.14:32
lbragstadright14:32
lbragstadsome of that already exists for nonlocal users14:32
lbragstadwhere it takes a property from the user reference from ldap and hashes that against the domain id for that user to get the ID14:33
aning_so ldap users can be implemented separately and it won't break anything, since at the end ldap users wil have IDs in "user" table, even it's geneared differently but it's transparent and no different from others.14:35
lbragstadwell - hashing of user ids from ldap is already implemented14:37
lbragstadbut sql users have ids that are randomly generated14:37
aning_that's right.14:37
lbragstad(same with federated users, but that's something ayoung wants to change)14:37
aning_It would be nice for sql users and federated users to have predictable IDs.14:38
aning_That will greatly aid for multiple region deployment.14:39
aning_ayoung mentioned he wants to make project IDs predictable as well.14:41
aning_again, not clear about when it'll be available.14:41
lbragstadi'll see if i can ask him if he is around for the meeting next week (if he doesn't show up before then)14:45
aning_lbragstad: thanks14:46
lbragstadyep14:46
*** lbragstad has quit IRC15:36
*** lbragstad has joined #openstack-keystone15:40
*** ChanServ sets mode: +o lbragstad15:40
openstackgerritColleen Murphy proposed openstack/keystone master: [WIP] Add manager support for app cred capabilities  https://review.openstack.org/62819316:04
openstackgerritColleen Murphy proposed openstack/keystone master: [WIP] Add API changes for app cred capabilities  https://review.openstack.org/62816816:04
openstackgerritColleen Murphy proposed openstack/keystone master: [WIP] Add API for /v3/allowed-requests  https://review.openstack.org/62852416:04
*** jrist has joined #openstack-keystone16:08
*** itlinux has joined #openstack-keystone16:33
*** imus has joined #openstack-keystone16:56
*** whoami-rajat has quit IRC17:27
openstackgerritLance Bragstad proposed openstack/keystone master: Update service provider  policies for system admin  https://review.openstack.org/62015817:59
openstackgerritLance Bragstad proposed openstack/keystone master: Add tests for domain users interacting with sps  https://review.openstack.org/62015917:59
openstackgerritLance Bragstad proposed openstack/keystone master: Add tests for project users interacting with sps  https://review.openstack.org/62016017:59
openstackgerritLance Bragstad proposed openstack/keystone master: Remove service provider policies from v3cloudsample.json  https://review.openstack.org/62016117:59
*** imacdonn has quit IRC17:59
*** imacdonn has joined #openstack-keystone18:00
lbragstadcmurphy i fixed up the release note in 62015818:02
lbragstadit looks like a few other patches landed with the vague wording...18:02
lbragstadonce we have a satisfactory format/wording, i'll update the ones that already landed18:03
cmurphythanks lbragstad18:03
lbragstadnp18:03
*** gyee has joined #openstack-keystone18:04
*** xek_ has quit IRC18:05
*** itlinux_ has joined #openstack-keystone18:33
*** itlinux has quit IRC18:35
lbragstadstepping out for lunch18:36
*** whoami-rajat has joined #openstack-keystone18:57
*** itlinux_ has quit IRC19:40
lbragstadcmurphy maybe sometime next week we can follow up on https://review.openstack.org/#/c/624215/19:59
lbragstadassuming you're going to be around?19:59
cmurphylbragstad: sure19:59
lbragstadawesome20:00
*** lifeless has joined #openstack-keystone20:12
openstackgerritLance Bragstad proposed openstack/keystone master: Add keystone-manage jwt_setup functionality  https://review.openstack.org/61531520:28
openstackgerritLance Bragstad proposed openstack/keystone master: Add configuration options for JWT provider  https://review.openstack.org/62867620:28
*** itlinux has joined #openstack-keystone20:43
lbragstadwxy-xiyuan i pulled your comments about jwt configuration options into another patch - https://review.openstack.org/#/c/628676/20:53
lbragstadi think ^ will need another option or two in order to support rotation20:53
lbragstadbut i left a comment there to kick start a discussion20:54
*** raildo_ has quit IRC21:03
openstackgerritMerged openstack/keystone master: Invalidate shadow_federated_user cache when deleting protocol  https://review.openstack.org/62813221:08
openstackgerritMerged openstack/keystone master: Use common system role definitions for registered limits  https://review.openstack.org/62602821:29
*** imus has quit IRC21:38
*** dave-mccowan has quit IRC21:42
*** itlinux_ has joined #openstack-keystone21:56
*** itlinux has quit IRC21:59
*** xek has joined #openstack-keystone21:59
*** itlinux_ has quit IRC22:24
*** whoami-rajat has quit IRC22:37
*** jaosorior has quit IRC22:42
*** xek has quit IRC23:09
openstackgerritguang-yee proposed openstack/keystone master: correct the description on domain re-enable  https://review.openstack.org/62870523:14
*** openstack has joined #openstack-keystone23:44
*** ChanServ sets mode: +o openstack23:44

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!