*** markvoelker has joined #openstack-keystone | 00:15 | |
*** takamatsu has quit IRC | 00:29 | |
*** markvoelker has quit IRC | 00:47 | |
*** kukacz has quit IRC | 01:10 | |
*** kukacz has joined #openstack-keystone | 01:12 | |
*** whoami-rajat has joined #openstack-keystone | 01:14 | |
*** vishwanathj has joined #openstack-keystone | 01:25 | |
*** markvoelker has joined #openstack-keystone | 01:44 | |
*** erus1 has quit IRC | 01:44 | |
*** erus1 has joined #openstack-keystone | 01:45 | |
*** Dinesh_Bhor has joined #openstack-keystone | 02:10 | |
*** markvoelker has quit IRC | 02:18 | |
*** shyamb has joined #openstack-keystone | 03:06 | |
*** shyamb has quit IRC | 03:43 | |
*** Dinesh_Bhor has quit IRC | 05:29 | |
*** Dinesh_Bhor has joined #openstack-keystone | 05:32 | |
*** dklyle has quit IRC | 06:09 | |
*** david-lyle has joined #openstack-keystone | 06:09 | |
*** markvoelker has joined #openstack-keystone | 06:56 | |
*** tkajinam_ has joined #openstack-keystone | 07:04 | |
*** tkajinam has quit IRC | 07:06 | |
*** takamatsu has joined #openstack-keystone | 07:28 | |
*** pcaruana has joined #openstack-keystone | 07:35 | |
*** pcaruana has quit IRC | 07:42 | |
*** pcaruana has joined #openstack-keystone | 07:42 | |
*** nishaYadav has joined #openstack-keystone | 07:47 | |
nishaYadav | o/ | 07:48 |
---|---|---|
*** awalende has joined #openstack-keystone | 07:49 | |
*** awalende has quit IRC | 07:52 | |
*** awalende has joined #openstack-keystone | 07:52 | |
*** awalende has quit IRC | 08:06 | |
*** erus1 has quit IRC | 08:06 | |
*** erus1 has joined #openstack-keystone | 08:06 | |
*** awalende has joined #openstack-keystone | 08:22 | |
*** tkajinam_ has quit IRC | 08:24 | |
*** yan0s has joined #openstack-keystone | 08:31 | |
*** erus1 has quit IRC | 08:31 | |
*** erus1 has joined #openstack-keystone | 08:32 | |
*** xek has joined #openstack-keystone | 08:32 | |
*** Emine has joined #openstack-keystone | 08:53 | |
*** tobias-urdin has joined #openstack-keystone | 09:06 | |
*** Dinesh_Bhor has quit IRC | 10:35 | |
*** jdennis has quit IRC | 10:38 | |
openstackgerrit | Yang Youseok proposed openstack/keystonemiddleware master: Add auth invalidation in auth_token for identity endpoint update https://review.openstack.org/633695 | 10:42 |
*** Dinesh_Bhor has joined #openstack-keystone | 10:43 | |
openstackgerrit | Artem Vasilyev proposed openstack/keystone master: Added request_id and global_request_id to cadf notifications https://review.openstack.org/634663 | 10:50 |
openstackgerrit | Artem Vasilyev proposed openstack/keystone master: Added request_id and global_request_id to basic notifications https://review.openstack.org/634663 | 10:53 |
*** claudiub has joined #openstack-keystone | 11:01 | |
*** raildo has joined #openstack-keystone | 12:13 | |
yan0s | has anyone setup apache mellon plugin for keystone federation? | 12:17 |
*** nishaYadav has quit IRC | 12:18 | |
*** Emine has quit IRC | 12:20 | |
*** Emine has joined #openstack-keystone | 12:21 | |
yan0s | I'm having trouble to use the openstack cli client with "OS_AUTH_TYPE=v3samlpassword" | 12:24 |
yan0s | login through the gui works fine | 12:28 |
*** vishakha has joined #openstack-keystone | 12:49 | |
*** raildo has quit IRC | 13:05 | |
*** Dinesh_Bhor has quit IRC | 13:05 | |
*** Dinesh_Bhor has joined #openstack-keystone | 13:11 | |
*** raildo has joined #openstack-keystone | 13:12 | |
*** Dinesh_Bhor has quit IRC | 13:12 | |
*** dave-mccowan has joined #openstack-keystone | 13:20 | |
*** dave-mccowan has quit IRC | 13:25 | |
*** dave-mccowan has joined #openstack-keystone | 13:30 | |
*** edmondsw has quit IRC | 13:40 | |
*** jmlowe has quit IRC | 14:09 | |
*** edmondsw has joined #openstack-keystone | 14:10 | |
*** lbragstad has joined #openstack-keystone | 14:26 | |
*** ChanServ sets mode: +o lbragstad | 14:26 | |
*** zzzeek has quit IRC | 14:31 | |
*** erus1 has quit IRC | 14:32 | |
*** erus1 has joined #openstack-keystone | 14:32 | |
*** zzzeek has joined #openstack-keystone | 14:34 | |
*** awalende has quit IRC | 14:43 | |
*** jenglisch_ is now known as jenglisch | 14:48 | |
*** zzzeek has quit IRC | 14:57 | |
*** zzzeek has joined #openstack-keystone | 14:57 | |
*** erus1 has quit IRC | 15:02 | |
*** Emine has quit IRC | 15:11 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Replace 'tenant_id' with 'project_id' https://review.openstack.org/631706 | 15:14 |
gagehugo | o/ | 15:15 |
lbragstad | \o | 15:16 |
cmurphy | o/ | 15:16 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Replace 'tenant_id' with 'project_id' https://review.openstack.org/631706 | 15:18 |
*** Emine has joined #openstack-keystone | 15:19 | |
*** jmlowe has joined #openstack-keystone | 15:43 | |
*** jistr is now known as jistr|biab | 15:52 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Correcting tests with project_id https://review.openstack.org/634394 | 15:53 |
*** erus1 has joined #openstack-keystone | 16:00 | |
*** erus1 has quit IRC | 16:07 | |
*** zzzeek has quit IRC | 16:23 | |
*** gyee has joined #openstack-keystone | 16:23 | |
*** jistr|biab is now known as jistr | 16:24 | |
*** zzzeek has joined #openstack-keystone | 16:25 | |
*** erus1 has joined #openstack-keystone | 16:34 | |
gyee | lbragstad, looks like we'll need to update x.509 tokenless to support system-scope as well | 16:40 |
lbragstad | ++ | 16:41 |
lbragstad | that rings a bell | 16:41 |
gyee | should I file another bug for that? | 16:41 |
lbragstad | yeah - i think so | 16:41 |
lbragstad | i remember seeing the exception when i was filing the scope bug and it was specific to project/domain support only | 16:41 |
gyee | I finally get around to update my vagrant dev environment to get it working, to some extend | 16:41 |
lbragstad | nice | 16:41 |
lbragstad | have you posted your vagrant file somewhere? | 16:42 |
gyee | not yet, I can put it in my github account | 16:42 |
lbragstad | awesome | 16:42 |
lbragstad | i wouldn't mind an automated way of setting all that up ;) | 16:42 |
gyee | basically, vagrant with ansible provisioner | 16:42 |
lbragstad | does it use devstack? | 16:43 |
gyee | yes | 16:43 |
lbragstad | cool | 16:43 |
gyee | it patches default devstack | 16:43 |
lbragstad | with new libraries or just the tls-proxy service/ | 16:43 |
gyee | no tls-proxy, just vanilla devstack | 16:44 |
lbragstad | ah | 16:44 |
gyee | I am working off the Rocky branch right now. Devstack master branch seem broken, at least as of last Friday. :-) | 16:45 |
lbragstad | huh | 16:47 |
lbragstad | i haven't ran it recently | 16:47 |
lbragstad | at least since last friday | 16:47 |
gyee | it was giving me a bunch of packaging errors, let me try again today | 16:47 |
*** erus1 has quit IRC | 16:56 | |
gyee | lbragstad, also, not sure if this is a known bug, but keystone-admin uwsgi process failed to come up in stable/rocky | 17:03 |
gyee | only keystone-public seem to be working | 17:04 |
lbragstad | hm | 17:04 |
lbragstad | i haven't heard of anything like that happening yet, but i bet it went unnoticed because we no longer have v2.0 up | 17:04 |
gyee | yeah, also, apache2 is not enabled in systemd, so it does not come up on system reboot | 17:05 |
gyee | not sure if that's by design or a bug | 17:05 |
gagehugo | do you need the keystone-admin uwsgi process after v2.0 is gone? | 17:06 |
lbragstad | no - it's optional at this point | 17:06 |
gyee | no, but we are still creating it in apache2 vhosts.d | 17:06 |
gagehugo | ah | 17:06 |
gyee | maybe we need to remove it? | 17:06 |
lbragstad | well... | 17:06 |
lbragstad | we might have to check with the tempest folks | 17:07 |
gagehugo | I've only every setup with the public one since queens | 17:07 |
gagehugo | ever* | 17:07 |
gyee | if its needed, its broken :-) | 17:07 |
lbragstad | pike is still supported | 17:07 |
lbragstad | which has v2.0 | 17:07 |
*** dmellado has quit IRC | 17:07 | |
gyee | I am using stable/rocky | 17:07 |
lbragstad | we might need to keep the infrastructure for deploying the admin app until that is unmaintained since tempest is branchless | 17:08 |
*** dmellado has joined #openstack-keystone | 17:08 | |
* lbragstad shrugs | 17:08 | |
*** dmellado has quit IRC | 17:08 | |
lbragstad | but it's only supported for another month | 17:08 |
lbragstad | https://releases.openstack.org/ | 17:08 |
gyee | nice | 17:09 |
*** dmellado has joined #openstack-keystone | 17:09 | |
lbragstad | https://docs.openstack.org/releasenotes/keystone/queens.html#other-notes | 17:11 |
lbragstad | yeah - it was removed in queens | 17:11 |
lbragstad | so pike will still have reminants of the v2.0 api | 17:11 |
lbragstad | remnants* | 17:11 |
gagehugo | yeah | 17:11 |
lbragstad | that could be why the admin api still still exists in devstack | 17:12 |
lbragstad | stuff still* | 17:12 |
gyee | maybe time to update devstack to not creating that vhost file | 17:12 |
lbragstad | man.. monday's are _terrible_ for typing | 17:12 |
lbragstad | i agree | 17:12 |
lbragstad | as soon as pike is unsupported, we should be safe to simplify all of that | 17:12 |
gyee | this is the error I am encounter when running devstack master branch | 17:13 |
gyee | "Complete output from command /opt/stack/requirements/.venv/bin/python -m pip config list:", "ERROR: unknown command \"config\"", "----------------------------------------", | 17:13 |
*** Emine has quit IRC | 17:18 | |
*** awalende has joined #openstack-keystone | 17:20 | |
lbragstad | interesting | 17:21 |
*** awalende has quit IRC | 17:24 | |
*** yan0s has quit IRC | 17:25 | |
gyee | looks like its using a very old version of pip, 9.0.3 | 17:30 |
*** Emine has joined #openstack-keystone | 17:30 | |
kmalloc | oh man, seattle has a couple inches of snow :P | 18:00 |
kmalloc | this is hilarious | 18:00 |
kmalloc | gyee: yeah use a modern pip, first order | 18:00 |
*** pcaruana has quit IRC | 18:00 | |
gyee | kmalloc, looks like devstack cap it to an older version | 18:07 |
gyee | but I think the problem is maybe somewhere else, virtualenv perhaps | 18:08 |
gyee | but I am still troubleshooting it | 18:08 |
kmalloc | lbragstad: https://review.openstack.org/#/c/605485/17 maintain the 404 | 18:09 |
kmalloc | add a note that it should be a 403, but changing is pending versioning (either microversions *or* v4) | 18:09 |
kmalloc | lbragstad: easy. | 18:09 |
kmalloc | gyee: hm. | 18:09 |
kmalloc | weird. | 18:09 |
lbragstad | i think we're going to have if/else statements in the api code then | 18:09 |
lbragstad | which will be fine, it'll just be messy i thin | 18:10 |
lbragstad | think* | 18:10 |
kmalloc | yep. or you maintain a 404 in all cases with a FIXME IN VERSIONING | 18:21 |
kmalloc | *shrug* | 18:21 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement JWS token provider https://review.openstack.org/614549 | 18:25 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add JWS token provider documentation https://review.openstack.org/633831 | 18:25 |
gyee | lbragstad, kmalloc, so this is the exact problem I am having. https://superuser.com/questions/1400430/python-virtualenv-error-unknown-command-config | 18:37 |
gyee | I am surprised no one else ran into this with devstack | 18:37 |
kmalloc | gyee: huh. i really always use a newer pip *even* if devstack dictates other versions | 18:39 |
kmalloc | gyee: so, i don't see it. | 18:39 |
gyee | how do I tell devstack to use a newer version of pip | 18:42 |
gyee | https://github.com/openstack-dev/devstack/blob/master/tools/cap-pip.txt | 18:43 |
gyee | manually fudge that file? | 18:43 |
*** zzzeek has quit IRC | 18:44 | |
cmurphy | kmalloc: lbragstad commented on 605485 | 18:44 |
lbragstad | cmurphy thanks - i just saw that roll through my email | 18:45 |
lbragstad | cmurphy what makes https://review.openstack.org/#/c/634193/1/keystone/tests/unit/mapping_fixtures.py,unified invalid? | 18:45 |
*** claudiub has quit IRC | 18:45 | |
cmurphy | lbragstad: try it and see | 18:46 |
* cmurphy not really here, back in a few hours | 18:47 | |
*** zzzeek has joined #openstack-keystone | 18:48 | |
kmalloc | cmurphy: thnx | 18:50 |
kmalloc | cmurphy: we can do that | 18:50 |
kmalloc | cmurphy: I dont feel like it would block the change either way. | 18:51 |
kmalloc | the safest bet is 404 maintain | 18:51 |
kmalloc | but if we're not maintainign the 404, then we release note it and go with 403 | 18:51 |
lbragstad | aha - got it | 18:53 |
*** zzzeek has quit IRC | 18:54 | |
*** zzzeek has joined #openstack-keystone | 18:57 | |
lbragstad | kmalloc since you're migration savvy https://review.openstack.org/#/c/621497/7 | 19:06 |
kmalloc | oh noes! | 19:08 |
kmalloc | ok looking | 19:08 |
kmalloc | wait... wut.. *blink* | 19:10 |
kmalloc | ok let me try and get context from the commit message | 19:10 |
kmalloc | so wait, we mis-recreated the tables? | 19:12 |
kmalloc | lbragstad: why are we creating the column in the contract phase? | 19:14 |
kmalloc | lbragstad: really i need more context on waht this is fixing. | 19:14 |
*** opetrenko_mob has joined #openstack-keystone | 19:14 | |
*** opetrenko_mob has quit IRC | 19:19 | |
*** Emine has quit IRC | 19:22 | |
*** vishakha has quit IRC | 19:25 | |
gyee | lbragstad, kmalloc, just want to confirm, system-scope is not something we can facilitate via federation mapping right | 19:26 |
gyee | in other words, once can't get a system-scoped token via federation | 19:26 |
gyee | s/once/one/ | 19:26 |
kmalloc | i don't see why a mapping couldn't do it ... eventually | 19:26 |
kmalloc | but i don't think we have wired up system scope on the mapping side. | 19:26 |
kmalloc | yet | 19:26 |
gyee | k, just want to confirm it doesn't exist right now | 19:28 |
gyee | thanks | 19:28 |
kmalloc | i am fairly certain it does not. | 19:28 |
kmalloc | but i can only keep so much info in my head at once, i might be wrong | 19:29 |
lbragstad | kmalloc it was a sqlite but | 19:31 |
lbragstad | bug* | 19:31 |
kmalloc | right. | 19:31 |
kmalloc | and my question is why not just fix the migration instead of wedging it into the contract phase | 19:32 |
kmalloc | this feels like the wrong place for it | 19:32 |
lbragstad | i think i asked a similar question | 19:32 |
lbragstad | and i think it's because of the order the migrations are run across the repositories | 19:32 |
kmalloc | i'm -1 without more clarity because SQLite is used for testing. | 19:32 |
kmalloc | and we can just retrofit the create to the end of the upgrade/update migration instead of wedging a create into a contract | 19:33 |
lbragstad | because sqlite? | 19:33 |
kmalloc | if someone is using sqlite in production and it breaks them i'm going to just say "uh... no. so nope, not supporting that" | 19:33 |
kmalloc | if we could remove sqlite support, i would. | 19:34 |
kmalloc | but it is really needed for testing. | 19:34 |
lbragstad | dstanek was close to doing that a couple years ago | 19:34 |
*** xek_ has joined #openstack-keystone | 19:34 | |
kmalloc | yeh | 19:35 |
gyee | stupid question: why would you testing something that is not intended for production? :-) | 19:35 |
kmalloc | gyee: sqlite provides a very close analogue in memory only for unit tests | 19:35 |
kmalloc | instead of needing a full MySQL instance (which is very slow in comparison) for our testing | 19:35 |
kmalloc | gyee: it is more convenience to ensure quick unit tests that automatically drop the data when the connection to the in-memory allocated schema is closed. | 19:36 |
kmalloc | gyee: ideally, we wouldn't use SQLite at all | 19:36 |
kmalloc | but even a snap .create_all in SQLA based upon the models and then a drop in MySQL is much much much slower. | 19:37 |
*** xek has quit IRC | 19:37 | |
kmalloc | we could fix the unit tests to not db_sync / stand up a clean schema every time. or we can use SQLite until we have another alternative | 19:38 |
gyee | yeah, I wouldn't waste time on sqlite | 19:39 |
gyee | why not just move that stuff to functional test or something | 19:39 |
kmalloc | again, the unit tests need to have a backend. | 19:46 |
kmalloc | even the non-functional versions. | 19:46 |
kmalloc | so, what are we to do, we need to stand up something for ensuring the logic is working | 19:47 |
kmalloc | so, since it provides a reasonable analoge for now, we keep it | 19:47 |
lbragstad | iirc - if you wire up the unit tests to run again sql, the performance is really bad | 19:48 |
kmalloc | we could do it | 19:48 |
kmalloc | really we could do an in-memory mysql [ndb] or any number of other options | 19:49 |
kmalloc | but SQLite works fine for now | 19:49 |
kmalloc | we have bigger fish / oceans to boil before we get to "remove SQLite from testing" | 19:49 |
*** jaosorior has quit IRC | 19:58 | |
openstackgerrit | Merged openstack/keystone master: Add endpoint tests for system member role https://review.openstack.org/619330 | 20:03 |
*** jmlowe has quit IRC | 20:31 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system reader role for users https://review.openstack.org/605485 | 20:38 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system member role user test coverage https://review.openstack.org/623317 | 20:38 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system admin role in users API https://review.openstack.org/623318 | 20:38 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement domain reader functionality for user API https://review.openstack.org/623319 | 20:38 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement domain member functionality for user API https://review.openstack.org/623320 | 20:38 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement domain admin functionality for user API https://review.openstack.org/623321 | 20:38 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add explicit testing for project users and the user API https://review.openstack.org/623322 | 20:38 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove user policies from policy.v3cloudsample.json https://review.openstack.org/623323 | 20:38 |
lbragstad | for ^ that series, we'll have to figure out how we want to approach getting the domain user tempest test to pass | 20:43 |
lbragstad | https://review.openstack.org/#/c/624794/ should show the issue | 20:43 |
*** whoami-rajat has quit IRC | 20:44 | |
*** opetrenko_and has joined #openstack-keystone | 20:47 | |
*** opetrenko_and has quit IRC | 20:53 | |
*** raildo has quit IRC | 20:59 | |
gyee | found another bug with x.509 tokenless, ephemeral user mapping is also broken | 21:02 |
*** xek__ has joined #openstack-keystone | 21:12 | |
kmalloc | that would make sense. | 21:14 |
kmalloc | tokenless was never meant to map to ephemeral | 21:14 |
kmalloc | as i recall | 21:14 |
*** xek_ has quit IRC | 21:14 | |
kmalloc | it was meant to map to concrete user(s) | 21:15 |
gyee | kmalloc, we also support ephemeral | 21:20 |
gyee | but yeah, it was primarily meant for local users | 21:21 |
kmalloc | yep, hence not surprised it is broken | 21:21 |
kmalloc | happy to take patches (and testing, please testing!!!) to make it work | 21:21 |
gyee | it's a one line fix, let me finish up the testing | 21:21 |
kmalloc | cool | 21:24 |
openstackgerrit | Islam Musleh proposed openstack/keystone master: Converting the API tests to use flask's test_client https://review.openstack.org/630301 | 21:34 |
*** xek__ has quit IRC | 21:35 | |
*** rm_work_ has joined #openstack-keystone | 21:36 | |
*** opetrenko__ has joined #openstack-keystone | 21:39 | |
openstackgerrit | guang-yee proposed openstack/keystone master: Fixes incorrect params passing https://review.openstack.org/634816 | 21:40 |
opetrenko__ | hey, does somebody know how to contact Adam Young? | 21:42 |
*** rm_work has quit IRC | 21:49 | |
*** rm_work_ is now known as rm_work | 21:49 | |
*** Nel1x has joined #openstack-keystone | 21:50 | |
larsks | opetrenko__: he usually hangs out here. you can probably find his email address in the keystone commit log. | 22:00 |
*** jmlowe has joined #openstack-keystone | 22:05 | |
kmalloc | opetrenko__: best bet is to email him if you can't find him here in the channel. Most days he shows up for a tleast a bit. | 22:31 |
opetrenko__ | thx | 22:32 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: WIP - Add flask hook for authentication timings https://review.openstack.org/634826 | 22:43 |
*** tkajinam has joined #openstack-keystone | 22:56 | |
openstackgerrit | Merged openstack/keystone master: Test case for bad type user in assertion https://review.openstack.org/634193 | 23:27 |
*** markvoelker has quit IRC | 23:31 | |
brtknr | Anyone here can tell me why I am able to create a heat stack only as a trustor, not as the trustee but then able to make changes and delete a stack even as a trustee as expected | 23:34 |
brtknr | ? | 23:34 |
*** imacdonn has joined #openstack-keystone | 23:48 | |
lbragstad | brtknr i know heat has some custom policy in place that only allows the stack owner to do things | 23:59 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!