*** dave-mccowan has quit IRC | 00:49 | |
*** dave-mccowan has joined #openstack-keystone | 00:51 | |
*** dave-mccowan has quit IRC | 01:15 | |
openstackgerrit | Merged openstack/keystone master: Allow domain users to access the GET domain API https://review.openstack.org/605851 | 01:30 |
---|---|---|
*** whoami-rajat has joined #openstack-keystone | 01:32 | |
openstackgerrit | Adrian Turjak proposed openstack/keystone master: bump Keystone version for Stein https://review.openstack.org/631369 | 01:43 |
openstackgerrit | Adrian Turjak proposed openstack/keystone master: Add documentation for Auth Receipts and MFA https://review.openstack.org/580535 | 01:43 |
*** ileixe has joined #openstack-keystone | 01:53 | |
*** tkajinam has joined #openstack-keystone | 02:02 | |
*** Dinesh_Bhor has joined #openstack-keystone | 02:02 | |
*** tkajinam is now known as kajinamit | 02:04 | |
*** kajinamit is now known as tkajinam | 02:05 | |
*** adriant has quit IRC | 02:17 | |
*** etp has quit IRC | 02:19 | |
*** adriant has joined #openstack-keystone | 02:20 | |
*** etp has joined #openstack-keystone | 02:21 | |
*** erus has quit IRC | 02:34 | |
*** jenglisch has quit IRC | 02:35 | |
*** chason_ has joined #openstack-keystone | 02:37 | |
*** lifeless has quit IRC | 02:40 | |
*** lifeless has joined #openstack-keystone | 02:41 | |
*** erus has joined #openstack-keystone | 02:45 | |
*** chason has quit IRC | 02:46 | |
*** Krenair has quit IRC | 02:46 | |
*** odyssey4me has quit IRC | 02:46 | |
*** DinaBelova has quit IRC | 02:46 | |
*** larsks has quit IRC | 02:46 | |
*** freerunner has joined #openstack-keystone | 02:46 | |
*** mhen has quit IRC | 02:49 | |
*** mhen has joined #openstack-keystone | 02:51 | |
*** larsks has joined #openstack-keystone | 02:58 | |
*** Krenair has joined #openstack-keystone | 03:03 | |
*** itlinux_ has joined #openstack-keystone | 04:10 | |
*** itlinux has quit IRC | 04:13 | |
*** lifeless has quit IRC | 04:30 | |
*** zzzeek has quit IRC | 04:48 | |
*** zzzeek has joined #openstack-keystone | 04:48 | |
*** rcernin has quit IRC | 05:05 | |
*** rcernin has joined #openstack-keystone | 05:07 | |
*** jaosorior has joined #openstack-keystone | 05:15 | |
*** tkajinam has quit IRC | 05:23 | |
*** shyamb has joined #openstack-keystone | 05:24 | |
*** tkajinam has joined #openstack-keystone | 05:25 | |
*** shyamb has quit IRC | 05:34 | |
*** Dinesh_Bhor has quit IRC | 05:47 | |
*** lifeless has joined #openstack-keystone | 05:51 | |
*** shyamb has joined #openstack-keystone | 05:51 | |
*** Dinesh_Bhor has joined #openstack-keystone | 05:55 | |
*** tkajinam has quit IRC | 06:00 | |
*** shyamb has quit IRC | 06:10 | |
*** shyamb has joined #openstack-keystone | 06:16 | |
*** tkajinam has joined #openstack-keystone | 06:17 | |
*** tkajinam has quit IRC | 06:22 | |
*** vishakha has joined #openstack-keystone | 06:30 | |
*** tkajinam has joined #openstack-keystone | 06:46 | |
*** tkajinam_ has joined #openstack-keystone | 06:55 | |
*** tkajinam has quit IRC | 06:57 | |
*** shyamb has quit IRC | 07:10 | |
*** shyamb has joined #openstack-keystone | 07:10 | |
*** threestrands has quit IRC | 07:17 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Add openstack_groups to assertion https://review.openstack.org/588211 | 07:18 |
*** rcernin has quit IRC | 07:20 | |
*** pcaruana has joined #openstack-keystone | 07:36 | |
*** shyamb has quit IRC | 07:52 | |
*** yan0s has quit IRC | 08:19 | |
*** yan0s has joined #openstack-keystone | 08:20 | |
yan0s | how do I associate a quota class with a user? | 08:23 |
*** jenglisch_ has joined #openstack-keystone | 08:29 | |
*** xek has joined #openstack-keystone | 08:39 | |
*** shyamb has joined #openstack-keystone | 08:52 | |
*** Dinesh_Bhor has quit IRC | 08:53 | |
*** Dinesh_Bhor has joined #openstack-keystone | 08:54 | |
*** ileixe has quit IRC | 08:57 | |
*** david-lyle has joined #openstack-keystone | 09:16 | |
*** dklyle has quit IRC | 09:19 | |
*** david-lyle has quit IRC | 09:29 | |
*** dklyle has joined #openstack-keystone | 09:32 | |
*** shyamb has quit IRC | 09:33 | |
*** shyamb has joined #openstack-keystone | 09:33 | |
*** odyssey4me has joined #openstack-keystone | 09:44 | |
*** david-lyle has joined #openstack-keystone | 09:49 | |
*** dklyle has quit IRC | 09:51 | |
*** david-lyle has quit IRC | 09:56 | |
*** dklyle has joined #openstack-keystone | 10:00 | |
*** shyamb has quit IRC | 10:02 | |
*** shyamb has joined #openstack-keystone | 10:10 | |
*** shyamb has quit IRC | 10:22 | |
*** erus has quit IRC | 10:26 | |
*** erus has joined #openstack-keystone | 10:26 | |
*** erus has quit IRC | 10:34 | |
*** niceplace has quit IRC | 10:40 | |
*** erus has joined #openstack-keystone | 10:41 | |
*** niceplace has joined #openstack-keystone | 10:41 | |
*** erus has quit IRC | 10:49 | |
*** odyssey4me has quit IRC | 10:49 | |
*** Dinesh_Bhor has quit IRC | 10:53 | |
*** erus has joined #openstack-keystone | 11:00 | |
*** shyamb has joined #openstack-keystone | 11:13 | |
*** shyamb has quit IRC | 11:30 | |
*** shyamb has joined #openstack-keystone | 11:31 | |
*** erus has quit IRC | 12:32 | |
*** erus_ has joined #openstack-keystone | 12:36 | |
*** erus has joined #openstack-keystone | 12:37 | |
*** irclogbot_1 has quit IRC | 12:48 | |
*** irclogbot_1 has joined #openstack-keystone | 12:58 | |
*** mvkr has quit IRC | 13:00 | |
*** yan0s has quit IRC | 13:04 | |
*** irclogbot_1 has quit IRC | 13:13 | |
*** shyamb has quit IRC | 13:22 | |
*** edmondsw_ has joined #openstack-keystone | 13:27 | |
*** irclogbot_1 has joined #openstack-keystone | 13:29 | |
*** edmondsw has quit IRC | 13:29 | |
*** edmondsw_ is now known as edmondsw | 13:29 | |
*** yan0s has joined #openstack-keystone | 13:30 | |
*** irclogbot_1 has quit IRC | 13:35 | |
*** GregWaines has joined #openstack-keystone | 13:40 | |
*** mvkr has joined #openstack-keystone | 13:42 | |
*** irclogbot_1 has joined #openstack-keystone | 13:49 | |
*** yan0s has quit IRC | 14:16 | |
*** yan0s has joined #openstack-keystone | 14:36 | |
*** efried has quit IRC | 14:52 | |
aning | lbragstad: A while ago we talked about predictable user IDs. Do we have a clear view of what would be in Stein? nonlocal (ldap) users, sql users, and projects? | 15:05 |
lbragstad | aning i'm not sure - ayoung was driving that work i believe, but i haven't heard from him in a while | 15:06 |
*** GregWaines has quit IRC | 15:08 | |
aning | lbragstad: Will it be eventually covered in release notes? And when will the release note be available (for Stein specifically)? | 15:08 |
*** tkajinam__ has joined #openstack-keystone | 15:11 | |
lbragstad | release notes for keystone can be found here - https://docs.openstack.org/releasenotes/keystone/ and yeah, features are included in those notes | 15:11 |
lbragstad | the official notes for stein will be published once we cut siten | 15:12 |
lbragstad | stein* | 15:12 |
lbragstad | unreleased notes (which will be available for stein) are here - https://docs.openstack.org/releasenotes/keystone/unreleased.html | 15:13 |
lbragstad | ^ but that isn't set in stone until we cut the release | 15:13 |
*** tkajinam_ has quit IRC | 15:13 | |
aning | lbragstad: ok thx | 15:16 |
lbragstad | yep | 15:17 |
*** erus_ has quit IRC | 15:29 | |
*** jmlowe has quit IRC | 15:47 | |
*** mvkr has quit IRC | 15:53 | |
*** jaosorior has quit IRC | 15:56 | |
*** tkajinam_ has joined #openstack-keystone | 15:58 | |
*** tkajinam__ has quit IRC | 16:01 | |
*** xek has quit IRC | 16:03 | |
*** xek has joined #openstack-keystone | 16:03 | |
*** efried has joined #openstack-keystone | 16:05 | |
*** yan0s has quit IRC | 16:10 | |
*** erus has quit IRC | 16:13 | |
*** erus has joined #openstack-keystone | 16:16 | |
openstackgerrit | Islam Musleh proposed openstack/keystone master: Converting the API tests to use flask's test_client https://review.openstack.org/630301 | 16:16 |
*** itlinux_ has quit IRC | 16:41 | |
*** erus has quit IRC | 17:12 | |
*** erus has joined #openstack-keystone | 17:13 | |
*** erus has quit IRC | 17:35 | |
*** erus has joined #openstack-keystone | 17:46 | |
*** jmlowe has joined #openstack-keystone | 19:22 | |
*** mchlumsky has quit IRC | 19:41 | |
*** mchlumsky has joined #openstack-keystone | 19:43 | |
*** ayoung has joined #openstack-keystone | 19:49 | |
ayoung | OK, everyone watch out. I've been thinking again. | 19:49 |
ayoung | What if we gave everyone their own Auth URL? | 19:49 |
ayoung | Like, the users Auth URL was different for everyone, and that way you could completely swap out the whole openstack implementation on them? | 19:50 |
ayoung | the impetus is the problems some people have with upgrades, and also the number of small OpenStack deployments I am seeing out there. | 19:50 |
ayoung | So...say you are running Rocky and want to move to Stein | 19:54 |
ayoung | and you have 100 users. Say you bring up a brand new stein cluster on a subset of your hardward, and want to move people over. If each of those 100 users had their own Auth URL, you could use DNS to determine whether they were pointing to rocky or stein | 19:55 |
ayoung | now, you might say "but all their resources are on rocky, what will they do on stein?" | 19:56 |
ayoung | You could migrate those resources for them | 19:56 |
ayoung | Or, if they are ephemeral, tear them down one night, move them to the new cloud, and let them build them back up. | 19:57 |
ayoung | You could externalize the workload so that that the systemn doesn't matter. | 19:58 |
clarkb | as a user, how would you know your url? And is that any simpler than running new control plane against existing keystone? then upgrade keystone first or last depending on what is easiest for you | 19:58 |
ayoung | now...It makes sense to me to split Keystone from Nova/Glance/Cinder/Neutron for this. | 19:58 |
ayoung | clarkb, that is kindof where I am headed | 19:58 |
clarkb | (keystone is a straightforward upgrade iirc) | 19:58 |
ayoung | right, so the reality is you would want to give people a different service catalog instead | 19:59 |
ayoung | and have the same keystone server while you upgrade Nova, etc | 19:59 |
ayoung | or rather, migrate people from one catalog set to another | 19:59 |
ayoung | With Tripleo, we've turned the microservices into a monolith. I'd like to reverse that | 20:00 |
ayoung | clarkb, there is also the need to link Keystones together, in a start/hub type configurations for scale out and distributed deployments. | 20:01 |
ayoung | you could give people an AUTH URL on the central hub, and once they pick a region, change DNS so that the Auth URL points to the regional Keystone | 20:01 |
ayoung | clarkb, as for your first question, I think it would be based on your federated Identity username | 20:02 |
ayoung | like, for me, I could have an Auth URL of https://ayoung.keystone.provider.net/ | 20:02 |
ayoung | And we'd do DNS trickery to convert from doing K2K from the central hub to an optimized call on the remote hub | 20:03 |
clarkb | gotcha so deterministic (as a user that is important as one of the hardest parts of using the client tooling or sdks (or apis directly) is simply figuring out what your account domain and auth url are | 20:03 |
ayoung | clarkb, yeah, I think so | 20:03 |
ayoung | It also to take Federated Identity into account, so you could have a wildcard DNS for anyone that catches all the non specified ones | 20:04 |
ayoung | We could do lots of things...per project Auth URLS, for example | 20:05 |
ayoung | it would let you link a project to a specific set of endpoints by sending you to the right Keystone server for that project | 20:05 |
ayoung | We've seen a lot of cases where a customer runs is 20+ distinct OpenStack deployments | 20:06 |
ayoung | and before I tell them "that is crazy" I want to have a better approach that I can lay out forthem | 20:07 |
*** pcaruana has quit IRC | 20:09 | |
*** irclogbot_1 has quit IRC | 20:38 | |
*** irclogbot_1 has joined #openstack-keystone | 20:52 | |
*** openstackgerrit has quit IRC | 20:56 | |
*** erus has quit IRC | 20:59 | |
*** erus has joined #openstack-keystone | 21:09 | |
*** jmlowe has quit IRC | 21:19 | |
*** xek has quit IRC | 21:26 | |
*** efried has quit IRC | 21:34 | |
*** efried has joined #openstack-keystone | 21:38 | |
*** itlinux has joined #openstack-keystone | 21:39 | |
*** jmlowe has joined #openstack-keystone | 21:41 | |
*** erus has quit IRC | 21:45 | |
*** erus has joined #openstack-keystone | 21:45 | |
*** rcernin has joined #openstack-keystone | 22:02 | |
*** imacdonn has quit IRC | 22:07 | |
*** imacdonn has joined #openstack-keystone | 22:07 | |
*** imus has quit IRC | 22:10 | |
jamielennox | i think you confuse the user experience too much, particularly the way keystone works i'd expect that you want one keystone and then different versions of nova etc throughout the system | 22:17 |
jamielennox | already because of the multiple deployments problem you have to specify where to go to do your initial handshake that makes openstack harder than other clouds - something i always hoped the DNS discover would solve | 22:17 |
jamielennox | it also feels like you are now providing your username via path | 22:20 |
*** efried has quit IRC | 22:21 | |
*** mvkr has joined #openstack-keystone | 22:23 | |
*** mvkr has quit IRC | 22:36 | |
*** itlinux has quit IRC | 22:49 | |
*** sapd1_ has joined #openstack-keystone | 22:57 | |
*** sapd1 has quit IRC | 23:01 | |
*** erus has quit IRC | 23:17 | |
*** erus has joined #openstack-keystone | 23:18 | |
*** openstackgerrit has joined #openstack-keystone | 23:54 | |
openstackgerrit | Merged openstack/keystone master: Add tests for project users interacting with registered limits https://review.openstack.org/621018 | 23:54 |
openstackgerrit | Merged openstack/keystone master: Remove registered limit policies from policy.v3cloudsample.json https://review.openstack.org/621019 | 23:54 |
*** mchlumsky has quit IRC | 23:57 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!