*** erus has quit IRC | 00:17 | |
*** jamesmcarthur has joined #openstack-keystone | 01:41 | |
*** jamesmcarthur has quit IRC | 01:48 | |
*** whoami-rajat has joined #openstack-keystone | 03:07 | |
*** jamesmcarthur has joined #openstack-keystone | 03:39 | |
*** jamesmcarthur has quit IRC | 04:32 | |
openstackgerrit | Merged openstack/keystone master: Add manager for access rules config https://review.openstack.org/637436 | 05:37 |
---|---|---|
openstackgerrit | Merged openstack/keystone master: Add a permissive mode for access rules config https://review.openstack.org/637438 | 05:39 |
*** jaosorior has joined #openstack-keystone | 05:52 | |
openstackgerrit | Merged openstack/keystone master: Add SQL migrations for app cred access rules https://review.openstack.org/631936 | 06:00 |
openstackgerrit | Merged openstack/keystone master: Add driver support for app cred access rules https://review.openstack.org/631937 | 06:00 |
*** phasespace has quit IRC | 06:57 | |
*** pcaruana has joined #openstack-keystone | 07:00 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Implement domain reader for role_assignments https://review.openstack.org/638587 | 07:02 |
*** rcernin has quit IRC | 07:03 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Implement domain reader for role_assignments https://review.openstack.org/638587 | 07:30 |
*** xek has joined #openstack-keystone | 08:14 | |
*** tkajinam has quit IRC | 08:17 | |
*** dmellado has quit IRC | 08:20 | |
*** needssleep has quit IRC | 09:01 | |
*** awalende has joined #openstack-keystone | 09:23 | |
*** dmellado_ has joined #openstack-keystone | 11:04 | |
*** dmellado_ is now known as dmellado | 11:05 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: WIP : Implement system reader for grant API https://review.openstack.org/642421 | 11:21 |
*** dave-mccowan has joined #openstack-keystone | 11:22 | |
*** dave-mccowan has quit IRC | 11:42 | |
*** edmondsw has joined #openstack-keystone | 11:47 | |
*** raildo has joined #openstack-keystone | 11:48 | |
*** markvoelker has quit IRC | 12:14 | |
*** mchlumsky has quit IRC | 12:40 | |
*** mchlumsky has joined #openstack-keystone | 12:42 | |
*** mpasserini has joined #openstack-keystone | 12:44 | |
mpasserini | Hi, I tried activating policy.v3cloudsample.json but it does not seem to work for me… I noticied that if I run "oslopolicy-policy-generator --namespace keystone" as root I see the new policy… but if I run it as a normal user I see the default policy | 12:45 |
mpasserini | any idea why this happens? | 12:45 |
*** jamesmcarthur has joined #openstack-keystone | 12:48 | |
*** efried has joined #openstack-keystone | 13:16 | |
efried | o/ | 13:16 |
efried | Can I please get a consult on https://review.openstack.org/#/c/642410/ ? | 13:16 |
efried | I want to make sure it makes semantic sense before I start quibbling with the grammar. | 13:16 |
openstackgerrit | Pavlo Shchelokovskyy proposed openstack/keystone master: Add hint for order of keys during distribution https://review.openstack.org/638397 | 13:18 |
mpasserini | I'm reading https://bugs.launchpad.net/keystone/+bug/1783659 , are domains in Keystone working at all? It looks like we can't delegate domain_admin roles to somebody | 13:25 |
openstack | Launchpad bug 968696 in OpenStack Identity (keystone) "duplicate for #1783659 "admin"-ness not properly scoped" [High,In progress] - Assigned to Lance Bragstad (lbragstad) | 13:25 |
*** jamesmcarthur has quit IRC | 13:30 | |
*** jamesmcarthur has joined #openstack-keystone | 13:31 | |
*** lbragstad has joined #openstack-keystone | 13:35 | |
*** ChanServ sets mode: +o lbragstad | 13:35 | |
*** jamesmcarthur has quit IRC | 13:36 | |
*** beekneemech is now known as bnemec | 13:43 | |
*** jamesmcarthur has joined #openstack-keystone | 13:45 | |
*** jamesmcarthur_ has joined #openstack-keystone | 13:49 | |
*** jamesmcarthur has quit IRC | 13:53 | |
*** efried has quit IRC | 13:57 | |
*** erus has joined #openstack-keystone | 14:08 | |
erus | o/ | 14:09 |
cmurphy | mpasserini: depends on what you mean by working, the bug of admin-ness-everywhere still applies with the default policies but you can customize your policies to avoid it | 14:19 |
cmurphy | hmm efried disappeared | 14:19 |
*** dave-mccowan has joined #openstack-keystone | 14:20 | |
mpasserini | cmurphy, by default policy do you mean policy.v3cloudsample.json ? | 14:23 |
cmurphy | mpasserini: no, that policy is not the default, it's an example of a way to customize it | 14:24 |
mpasserini | ok, so I tried using policy.v3cloudsample.json and admin could see everything.. | 14:25 |
mpasserini | both in his domain, but also in domains he didn't belong to | 14:25 |
knikolla | o/ | 14:34 |
gagehugo | o/ | 14:35 |
erus | o/ | 14:37 |
lbragstad | mpasserini unfortunately, the policy.v3cloudsample.json file isn't officially supported and isn't tested as extensively as the default policies in code | 14:40 |
*** awalende has quit IRC | 14:49 | |
*** FlorianFa has joined #openstack-keystone | 14:50 | |
*** FlorianFa has quit IRC | 14:52 | |
*** FlorianFa has joined #openstack-keystone | 14:52 | |
mpasserini | ok :( | 14:53 |
lbragstad | mpasserini what release are you using? | 14:55 |
mpasserini | Queens | 14:55 |
lbragstad | ok | 14:55 |
lbragstad | well, for what it's worth, we're working on efforts, starting in Stein, to improve the defaults, increase testing, and remove policies from policy.v3cloudsample.json | 14:56 |
lbragstad | http://lists.openstack.org/pipermail/openstack-discuss/2019-March/003552.html is a summary of that work | 14:58 |
*** vishakha has quit IRC | 15:25 | |
kmalloc | o/ | 15:29 |
knikolla | dst got me needing more coffee | 15:30 |
*** vishakha has joined #openstack-keystone | 15:33 | |
vishakha | lbragstad: Hello. For https://review.openstack.org/#/c/638587/ I added a patch in tempest https://review.openstack.org/#/c/641959/. pl have a look. | 15:36 |
lbragstad | vishakha awesome - i'll take a look today | 15:36 |
vishakha | lbragstad: thanks a lot | 15:37 |
lbragstad | no problem - thanks for writing the patches | 15:37 |
*** jamesmcarthur_ has quit IRC | 15:38 | |
*** jamesmcarthur has joined #openstack-keystone | 15:38 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Remove publish-loci post job https://review.openstack.org/642502 | 15:48 |
cmurphy | would appreciate quick reviews on that ^ we need it so that we can update our rpms | 15:48 |
lbragstad | done - i'll watch for zuul and +W | 15:55 |
vishakha | lbragstad: Also I started over grant API but facing some issues writing the test cases https://review.openstack.org/#/c/642421/1/keystone/tests/unit/protection/v3/test_grant.py. I was taking the reference of Api-ref document for the rest api calls . https://developer.openstack.org/api-ref/identity/v3/?expanded=check-user-for-a-system-role-assignment-detail#check-user-for-a-system-role-assignment. But when | 15:55 |
vishakha | using head getting some strange error. | 15:55 |
cmurphy | lbragstad: you know you can +W and if zuul doesn't like it it won't merge it? | 15:56 |
lbragstad | cmurphy yeah - i got my hand slapped for doing that a long time ago, but that was also a long time ago | 15:56 |
*** jamesmcarthur has quit IRC | 15:57 | |
*** jamesmcarthur has joined #openstack-keystone | 15:57 | |
lbragstad | vishakha i assume https://review.openstack.org/#/c/642421/1/keystone/tests/unit/protection/v3/test_grant.py@56 makes the error repeatable? | 15:57 |
lbragstad | cmurphy my hesitation/FUD probably isn't relevant anymore | 15:58 |
cmurphy | i think zuul was always designed to prevent merging if it didn't pass ci | 15:58 |
lbragstad | true - when i was advised to not do that was when we were still using Jenkins | 15:59 |
cmurphy | ah | 15:59 |
vishakha | lbragstad: it is showing assertion error - I AM A TEAPOT (418) | 15:59 |
lbragstad | lol | 15:59 |
*** jamesmcarthur has quit IRC | 16:00 | |
vishakha | :) | 16:00 |
lbragstad | vishakha commented | 16:01 |
*** jamesmcarthur has joined #openstack-keystone | 16:01 | |
vishakha | thanks for the quick comment | 16:01 |
vishakha | lbragstad: it worked | 16:02 |
lbragstad | no more 418? | 16:03 |
vishakha | yes | 16:03 |
lbragstad | ++ | 16:03 |
*** erus has quit IRC | 16:15 | |
*** erus has joined #openstack-keystone | 16:18 | |
*** pcaruana has quit IRC | 16:23 | |
*** pcaruana has joined #openstack-keystone | 16:23 | |
kmalloc | Hmm | 16:36 |
kmalloc | The teapot error saves us again from a broken test! | 16:37 |
lbragstad | broken teapots are the worst | 16:42 |
*** nsmeds has left #openstack-keystone | 16:45 | |
*** gyee has joined #openstack-keystone | 16:46 | |
*** kklimonda_ has quit IRC | 17:14 | |
*** kklimonda has joined #openstack-keystone | 17:14 | |
hrybacki | kmalloc: o/ | 17:35 |
hrybacki | what happens in KSM if a memcached instance disappears? | 17:35 |
hrybacki | (assuming you have caching enabled and using memcached per norm) | 17:36 |
kmalloc | in theory, the memcache instance is failed out and causes a minimal amount of slow down. | 17:38 |
kmalloc | and the caching is always a cache miss | 17:38 |
kmalloc | if you have multiple servers, then the cache is rebalanced via a hash | 17:38 |
kmalloc | and the previously cached data is a miss, new data is placed in the current servers. if the server comes back in, the hash rebalance probably causes some misses | 17:39 |
hrybacki | let's say we only have a single memcached server running, it goes down, and is taking minutes (for whatever reason) to come back up | 17:40 |
hrybacki | is this going to hold everything up or is ksm going to ignore it after X failed set/gets? | 17:40 |
*** jamesmcarthur has quit IRC | 17:40 | |
kmalloc | should ignore if memcache(d) interface is written correctly | 17:40 |
kmalloc | after a nominal timeout | 17:41 |
*** jamesmcarthur has joined #openstack-keystone | 17:41 | |
kmalloc | in the past we had a big delay. | 17:41 |
kmalloc | but that was bug related. | 17:41 |
hrybacki | hmm. it's a good thing tripleo doesn't make this more complicated /s | 17:42 |
*** jamesmcarthur has quit IRC | 17:45 | |
lbragstad | i'm not sure if people here have a strong preference for gathering around tables with food - but i added some ideas to the etherpad https://etherpad.openstack.org/p/DEN-keystone-forum-sessions | 17:50 |
*** jamesmcarthur has joined #openstack-keystone | 18:20 | |
*** jamesmcarthur has quit IRC | 18:26 | |
*** jamesmcarthur has joined #openstack-keystone | 18:47 | |
*** raildo has quit IRC | 19:16 | |
*** raildo has joined #openstack-keystone | 19:16 | |
*** raildo_ has joined #openstack-keystone | 19:18 | |
*** raildo has quit IRC | 19:21 | |
*** xek has quit IRC | 19:23 | |
*** xek has joined #openstack-keystone | 19:23 | |
*** xek has quit IRC | 19:43 | |
*** xek has joined #openstack-keystone | 19:43 | |
*** itlinux has joined #openstack-keystone | 20:30 | |
*** itlinux has quit IRC | 20:34 | |
*** vishakha has quit IRC | 20:45 | |
*** phasespace has joined #openstack-keystone | 20:55 | |
*** jamesmcarthur has quit IRC | 20:56 | |
*** itlinux has joined #openstack-keystone | 20:56 | |
*** erus has quit IRC | 21:14 | |
*** raildo_ has quit IRC | 21:17 | |
*** xek has quit IRC | 21:18 | |
*** whoami-rajat has quit IRC | 21:25 | |
*** dave-mccowan has quit IRC | 21:36 | |
*** pcaruana has quit IRC | 21:45 | |
*** itlinux has quit IRC | 21:55 | |
*** lbragstad has quit IRC | 22:40 | |
*** lbragstad has joined #openstack-keystone | 22:43 | |
*** ChanServ sets mode: +o lbragstad | 22:43 | |
*** threestrands has joined #openstack-keystone | 22:50 | |
*** tkajinam has joined #openstack-keystone | 22:56 | |
*** TheJulia has joined #openstack-keystone | 23:00 | |
openstackgerrit | Merged openstack/keystone master: Remove publish-loci post job https://review.openstack.org/642502 | 23:22 |
*** threestrands has quit IRC | 23:45 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!