adriant | am I wrong to assume that if I'm dealing with project and user ids, I'd never really need to do lookup as to domain? Domain is only needed for name based lookups? Like is there actually ever a chance that a project_id or user_id will not be unique across all domains? | 00:07 |
---|---|---|
cmurphy | adriant: they should always be unique across domains | 00:09 |
adriant | cmurphy: ty! cool, thought so, just wanted someone who knew better to confirm | 00:10 |
adriant | I had an action in Adjutant that acted on project and user id, and I realised that needing to supply a domain was pointless, and actually made no sense | 00:10 |
adriant | cool, now ripped out and made a little simpler | 00:13 |
cmurphy | \o/ | 00:13 |
* adriant is trying to make adjutant work in a LDAP based context a bit better | 00:13 | |
*** erus1 has quit IRC | 00:55 | |
*** whoami-rajat has joined #openstack-keystone | 01:27 | |
*** dklyle has quit IRC | 01:46 | |
*** david-lyle has joined #openstack-keystone | 01:46 | |
*** dklyle has joined #openstack-keystone | 01:48 | |
*** david-lyle has quit IRC | 01:50 | |
*** markvoelker has joined #openstack-keystone | 02:10 | |
openstackgerrit | Merged openstack/keystone master: Update mapping policies for system reader https://review.openstack.org/619612 | 02:11 |
*** Dinesh_Bhor has joined #openstack-keystone | 02:14 | |
*** markvoelker has quit IRC | 02:14 | |
*** sapd1 has joined #openstack-keystone | 02:34 | |
*** sapd1 has quit IRC | 02:50 | |
*** shyamb has joined #openstack-keystone | 02:52 | |
*** dims has quit IRC | 02:53 | |
*** shyamb has quit IRC | 03:10 | |
*** markvoelker has joined #openstack-keystone | 03:11 | |
openstackgerrit | Merged openstack/keystone master: Add configuration options for JWS provider https://review.openstack.org/628676 | 03:27 |
*** lbragstad has quit IRC | 03:40 | |
*** markvoelker has quit IRC | 03:44 | |
*** Dinesh_Bhor has quit IRC | 03:58 | |
*** Dinesh_Bhor has joined #openstack-keystone | 04:08 | |
*** markvoelker has joined #openstack-keystone | 04:41 | |
*** spsurya has joined #openstack-keystone | 04:45 | |
*** tkajinam_ has joined #openstack-keystone | 04:47 | |
*** tkajinam has quit IRC | 04:49 | |
*** markvoelker has quit IRC | 05:14 | |
*** shyamb has joined #openstack-keystone | 05:22 | |
*** shyamb has quit IRC | 05:24 | |
*** shyamb has joined #openstack-keystone | 05:24 | |
*** lbragstad has joined #openstack-keystone | 05:43 | |
*** ChanServ sets mode: +o lbragstad | 05:43 | |
*** gyee has quit IRC | 05:54 | |
*** markvoelker has joined #openstack-keystone | 06:12 | |
*** shyamb has quit IRC | 06:24 | |
*** dave-mccowan has quit IRC | 06:41 | |
*** markvoelker has quit IRC | 06:44 | |
*** lbragstad has quit IRC | 06:52 | |
*** shyamb has joined #openstack-keystone | 06:57 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Replace 'tenant_id' with 'project_id' https://review.openstack.org/631706 | 07:07 |
*** pcaruana has joined #openstack-keystone | 07:19 | |
*** markvoelker has joined #openstack-keystone | 07:41 | |
*** markvoelker has quit IRC | 08:14 | |
*** tkajinam_ has quit IRC | 08:17 | |
*** shyamb has quit IRC | 08:47 | |
*** shyamb has joined #openstack-keystone | 08:48 | |
*** rcernin has joined #openstack-keystone | 08:57 | |
openstackgerrit | Merged openstack/keystone master: Add keystone-manage create_jws_keypair functionality https://review.openstack.org/615315 | 09:04 |
openstackgerrit | Merged openstack/keystone master: Add test fixture for the JWS key repository https://review.openstack.org/614547 | 09:04 |
openstackgerrit | Merged openstack/keystone master: Add PyJWT as a requirement https://review.openstack.org/614548 | 09:04 |
*** shyamb has quit IRC | 09:10 | |
*** shyamb has joined #openstack-keystone | 09:11 | |
*** markvoelker has joined #openstack-keystone | 09:12 | |
*** pcaruana has quit IRC | 09:30 | |
*** shyamb has quit IRC | 09:31 | |
*** pcaruana has joined #openstack-keystone | 09:42 | |
*** shyamb has joined #openstack-keystone | 09:44 | |
*** markvoelker has quit IRC | 09:44 | |
*** Dinesh_Bhor has quit IRC | 10:01 | |
*** Dinesh_Bhor has joined #openstack-keystone | 10:06 | |
*** opetrenko has joined #openstack-keystone | 10:18 | |
*** shyamb has quit IRC | 10:18 | |
*** shyamb has joined #openstack-keystone | 10:19 | |
opetrenko | Hello guys. Is it possible to setup two keystones that use shibboleth as IDP that looks into LDAP, so that I can get unscoped token from first keystone, and scope it in second keystone? | 10:20 |
opetrenko | Or do keystone have a way to use "predictable" aka consistent uuid's so that with same user metadata we can get same uuid on different keystones? | 10:27 |
*** markvoelker has joined #openstack-keystone | 10:42 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Correcting tests with project_id https://review.openstack.org/634394 | 10:58 |
*** Dinesh_Bhor has quit IRC | 11:01 | |
*** shyamb has quit IRC | 11:10 | |
*** rcernin has quit IRC | 11:12 | |
*** markvoelker has quit IRC | 11:15 | |
*** shyamb has joined #openstack-keystone | 11:48 | |
*** erus1 has joined #openstack-keystone | 12:00 | |
*** pcaruana has quit IRC | 12:05 | |
*** markvoelker has joined #openstack-keystone | 12:11 | |
*** pcaruana has joined #openstack-keystone | 12:19 | |
*** mvkr has joined #openstack-keystone | 12:24 | |
*** pcaruana|afk| has joined #openstack-keystone | 12:25 | |
*** pcaruana has quit IRC | 12:26 | |
*** pcaruana|afk| is now known as pcaruana | 12:27 | |
*** erus1 has quit IRC | 12:27 | |
*** erus1 has joined #openstack-keystone | 12:27 | |
*** yan0s has joined #openstack-keystone | 12:32 | |
*** markvoelker has quit IRC | 12:45 | |
*** pcaruana has quit IRC | 13:13 | |
cmurphy | we closed more bugs than we opened this week \o/ | 13:14 |
cmurphy | opetrenko: you can set up keystone-to-keystone federation to be able to authenticate with one keystone and use the authentication on another keystone https://docs.openstack.org/keystone/latest/admin/federation/configure_federation.html#keystone-as-an-identity-provider-idp | 13:16 |
opetrenko | cmurphy: the thing is, that I want both keystones to look into shibboleth | 13:16 |
cmurphy | opetrenko: we have work ongoing to ensure uuids are consistent for the same user but it's not complete | 13:16 |
opetrenko | cmurphy:https://review.openstack.org/#/c/605169/9 this? | 13:17 |
cmurphy | opetrenko: yes that's part of it | 13:17 |
opetrenko | can I help somehow? since I need this thing to be implemented :) | 13:18 |
*** pcaruana has joined #openstack-keystone | 13:20 | |
cmurphy | opetrenko: here is the main spec http://specs.openstack.org/openstack/keystone-specs/specs/keystone/stein/explicit-domains-ids.html you can talk to ayoung when he comes online and ask how you can help | 13:20 |
cmurphy | and ping lbragstad when he comes online to see what can be done about his -1 on that review | 13:21 |
opetrenko | cmurphy:thx | 13:21 |
*** yan0s has quit IRC | 13:23 | |
*** yan0s has joined #openstack-keystone | 13:24 | |
*** shyamb has quit IRC | 13:25 | |
*** dave-mccowan has joined #openstack-keystone | 13:34 | |
*** dims has joined #openstack-keystone | 13:41 | |
*** markvoelker has joined #openstack-keystone | 13:42 | |
*** markvoelker has quit IRC | 14:14 | |
*** mchlumsky has joined #openstack-keystone | 14:31 | |
*** dims has quit IRC | 14:38 | |
*** lbragstad has joined #openstack-keystone | 14:39 | |
*** ChanServ sets mode: +o lbragstad | 14:39 | |
*** dims has joined #openstack-keystone | 14:44 | |
*** dims has quit IRC | 15:01 | |
*** markvoelker has joined #openstack-keystone | 15:11 | |
*** dims has joined #openstack-keystone | 15:14 | |
*** dims has quit IRC | 15:19 | |
*** dims has joined #openstack-keystone | 15:20 | |
*** markvoelker has quit IRC | 15:44 | |
*** pcaruana has quit IRC | 15:59 | |
opetrenko | https://github.com/Enacero/docker-keystone-federation - docker-compose with two federated keystones, looking into one shibboleth with ldap. Fernet keys are moved to volume, so both keystones have almost the same configuration | 16:09 |
erus1 | o/ | 16:10 |
lbragstad | opetrenko nice! | 16:10 |
lbragstad | looks like e0ne has a version, too? | 16:10 |
*** yan0s has quit IRC | 16:10 | |
opetrenko | currently in his master is merged pull request from this repo | 16:11 |
opetrenko | but I fixed several errors and they were not merged into e0nes repo | 16:12 |
lbragstad | cool | 16:12 |
knikolla | o/ | 16:31 |
* knikolla caught the flu. | 16:32 | |
knikolla | i blame kmalloc from the other side of the continent. | 16:32 |
kmalloc | o/ | 16:32 |
kmalloc | wait what. | 16:32 |
kmalloc | no. no blaming me for the crud. | 16:33 |
lbragstad | lol | 16:33 |
knikolla | haha | 16:33 |
*** markvoelker has joined #openstack-keystone | 16:41 | |
*** awalende has joined #openstack-keystone | 16:47 | |
*** awalende has quit IRC | 16:52 | |
*** awalende has joined #openstack-keystone | 16:52 | |
*** awalende has quit IRC | 16:57 | |
*** markvoelker has quit IRC | 17:15 | |
*** erus1 has quit IRC | 17:23 | |
*** erus1 has joined #openstack-keystone | 17:23 | |
*** awalende has joined #openstack-keystone | 17:52 | |
*** jistr has quit IRC | 17:57 | |
*** jistr has joined #openstack-keystone | 17:57 | |
*** markvoelker has joined #openstack-keystone | 18:11 | |
*** gyee has joined #openstack-keystone | 18:15 | |
*** awalende has quit IRC | 18:16 | |
*** bnemec has joined #openstack-keystone | 18:29 | |
*** bnemec is now known as bnemec-pto | 18:29 | |
*** markvoelker has quit IRC | 18:45 | |
gagehugo | o/ | 19:39 |
*** markvoelker has joined #openstack-keystone | 19:42 | |
erus1 | \o | 19:48 |
*** lbragstad has quit IRC | 20:02 | |
*** whoami-rajat has quit IRC | 20:07 | |
*** awalende has joined #openstack-keystone | 20:12 | |
*** markvoelker has quit IRC | 20:15 | |
*** lbragstad has joined #openstack-keystone | 20:36 | |
*** ChanServ sets mode: +o lbragstad | 20:36 | |
*** markvoelker has joined #openstack-keystone | 21:11 | |
*** xek has quit IRC | 21:32 | |
*** Nel1x has joined #openstack-keystone | 21:34 | |
*** awalende has quit IRC | 21:44 | |
*** markvoelker has quit IRC | 21:45 | |
*** imus has quit IRC | 22:21 | |
openstackgerrit | Islam Musleh proposed openstack/keystone master: Converting the API tests to use flask's test_client https://review.openstack.org/630301 | 22:26 |
*** erus1 has quit IRC | 22:38 | |
*** erus1 has joined #openstack-keystone | 22:38 | |
*** dave-mccowan has quit IRC | 22:40 | |
*** markvoelker has joined #openstack-keystone | 22:42 | |
*** awalende has joined #openstack-keystone | 22:51 | |
*** markvoelker has quit IRC | 23:14 | |
*** erus1 has quit IRC | 23:14 | |
*** erus1 has joined #openstack-keystone | 23:15 | |
*** takamatsu has quit IRC | 23:26 | |
*** awalende has quit IRC | 23:39 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!