| *** erus has quit IRC | 00:17 | |
| *** jamesmcarthur has joined #openstack-keystone | 01:41 | |
| *** jamesmcarthur has quit IRC | 01:48 | |
| *** whoami-rajat has joined #openstack-keystone | 03:07 | |
| *** jamesmcarthur has joined #openstack-keystone | 03:39 | |
| *** jamesmcarthur has quit IRC | 04:32 | |
| openstackgerrit | Merged openstack/keystone master: Add manager for access rules config https://review.openstack.org/637436 | 05:37 |
|---|---|---|
| openstackgerrit | Merged openstack/keystone master: Add a permissive mode for access rules config https://review.openstack.org/637438 | 05:39 |
| *** jaosorior has joined #openstack-keystone | 05:52 | |
| openstackgerrit | Merged openstack/keystone master: Add SQL migrations for app cred access rules https://review.openstack.org/631936 | 06:00 |
| openstackgerrit | Merged openstack/keystone master: Add driver support for app cred access rules https://review.openstack.org/631937 | 06:00 |
| *** phasespace has quit IRC | 06:57 | |
| *** pcaruana has joined #openstack-keystone | 07:00 | |
| openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Implement domain reader for role_assignments https://review.openstack.org/638587 | 07:02 |
| *** rcernin has quit IRC | 07:03 | |
| openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Implement domain reader for role_assignments https://review.openstack.org/638587 | 07:30 |
| *** xek has joined #openstack-keystone | 08:14 | |
| *** tkajinam has quit IRC | 08:17 | |
| *** dmellado has quit IRC | 08:20 | |
| *** needssleep has quit IRC | 09:01 | |
| *** awalende has joined #openstack-keystone | 09:23 | |
| *** dmellado_ has joined #openstack-keystone | 11:04 | |
| *** dmellado_ is now known as dmellado | 11:05 | |
| openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: WIP : Implement system reader for grant API https://review.openstack.org/642421 | 11:21 |
| *** dave-mccowan has joined #openstack-keystone | 11:22 | |
| *** dave-mccowan has quit IRC | 11:42 | |
| *** edmondsw has joined #openstack-keystone | 11:47 | |
| *** raildo has joined #openstack-keystone | 11:48 | |
| *** markvoelker has quit IRC | 12:14 | |
| *** mchlumsky has quit IRC | 12:40 | |
| *** mchlumsky has joined #openstack-keystone | 12:42 | |
| *** mpasserini has joined #openstack-keystone | 12:44 | |
| mpasserini | Hi, I tried activating policy.v3cloudsample.json but it does not seem to work for me… I noticied that if I run "oslopolicy-policy-generator --namespace keystone" as root I see the new policy… but if I run it as a normal user I see the default policy | 12:45 |
| mpasserini | any idea why this happens? | 12:45 |
| *** jamesmcarthur has joined #openstack-keystone | 12:48 | |
| *** efried has joined #openstack-keystone | 13:16 | |
| efried | o/ | 13:16 |
| efried | Can I please get a consult on https://review.openstack.org/#/c/642410/ ? | 13:16 |
| efried | I want to make sure it makes semantic sense before I start quibbling with the grammar. | 13:16 |
| openstackgerrit | Pavlo Shchelokovskyy proposed openstack/keystone master: Add hint for order of keys during distribution https://review.openstack.org/638397 | 13:18 |
| mpasserini | I'm reading https://bugs.launchpad.net/keystone/+bug/1783659 , are domains in Keystone working at all? It looks like we can't delegate domain_admin roles to somebody | 13:25 |
| openstack | Launchpad bug 968696 in OpenStack Identity (keystone) "duplicate for #1783659 "admin"-ness not properly scoped" [High,In progress] - Assigned to Lance Bragstad (lbragstad) | 13:25 |
| *** jamesmcarthur has quit IRC | 13:30 | |
| *** jamesmcarthur has joined #openstack-keystone | 13:31 | |
| *** lbragstad has joined #openstack-keystone | 13:35 | |
| *** ChanServ sets mode: +o lbragstad | 13:35 | |
| *** jamesmcarthur has quit IRC | 13:36 | |
| *** beekneemech is now known as bnemec | 13:43 | |
| *** jamesmcarthur has joined #openstack-keystone | 13:45 | |
| *** jamesmcarthur_ has joined #openstack-keystone | 13:49 | |
| *** jamesmcarthur has quit IRC | 13:53 | |
| *** efried has quit IRC | 13:57 | |
| *** erus has joined #openstack-keystone | 14:08 | |
| erus | o/ | 14:09 |
| cmurphy | mpasserini: depends on what you mean by working, the bug of admin-ness-everywhere still applies with the default policies but you can customize your policies to avoid it | 14:19 |
| cmurphy | hmm efried disappeared | 14:19 |
| *** dave-mccowan has joined #openstack-keystone | 14:20 | |
| mpasserini | cmurphy, by default policy do you mean policy.v3cloudsample.json ? | 14:23 |
| cmurphy | mpasserini: no, that policy is not the default, it's an example of a way to customize it | 14:24 |
| mpasserini | ok, so I tried using policy.v3cloudsample.json and admin could see everything.. | 14:25 |
| mpasserini | both in his domain, but also in domains he didn't belong to | 14:25 |
| knikolla | o/ | 14:34 |
| gagehugo | o/ | 14:35 |
| erus | o/ | 14:37 |
| lbragstad | mpasserini unfortunately, the policy.v3cloudsample.json file isn't officially supported and isn't tested as extensively as the default policies in code | 14:40 |
| *** awalende has quit IRC | 14:49 | |
| *** FlorianFa has joined #openstack-keystone | 14:50 | |
| *** FlorianFa has quit IRC | 14:52 | |
| *** FlorianFa has joined #openstack-keystone | 14:52 | |
| mpasserini | ok :( | 14:53 |
| lbragstad | mpasserini what release are you using? | 14:55 |
| mpasserini | Queens | 14:55 |
| lbragstad | ok | 14:55 |
| lbragstad | well, for what it's worth, we're working on efforts, starting in Stein, to improve the defaults, increase testing, and remove policies from policy.v3cloudsample.json | 14:56 |
| lbragstad | http://lists.openstack.org/pipermail/openstack-discuss/2019-March/003552.html is a summary of that work | 14:58 |
| *** vishakha has quit IRC | 15:25 | |
| kmalloc | o/ | 15:29 |
| knikolla | dst got me needing more coffee | 15:30 |
| *** vishakha has joined #openstack-keystone | 15:33 | |
| vishakha | lbragstad: Hello. For https://review.openstack.org/#/c/638587/ I added a patch in tempest https://review.openstack.org/#/c/641959/. pl have a look. | 15:36 |
| lbragstad | vishakha awesome - i'll take a look today | 15:36 |
| vishakha | lbragstad: thanks a lot | 15:37 |
| lbragstad | no problem - thanks for writing the patches | 15:37 |
| *** jamesmcarthur_ has quit IRC | 15:38 | |
| *** jamesmcarthur has joined #openstack-keystone | 15:38 | |
| openstackgerrit | Colleen Murphy proposed openstack/keystone master: Remove publish-loci post job https://review.openstack.org/642502 | 15:48 |
| cmurphy | would appreciate quick reviews on that ^ we need it so that we can update our rpms | 15:48 |
| lbragstad | done - i'll watch for zuul and +W | 15:55 |
| vishakha | lbragstad: Also I started over grant API but facing some issues writing the test cases https://review.openstack.org/#/c/642421/1/keystone/tests/unit/protection/v3/test_grant.py. I was taking the reference of Api-ref document for the rest api calls . https://developer.openstack.org/api-ref/identity/v3/?expanded=check-user-for-a-system-role-assignment-detail#check-user-for-a-system-role-assignment. But when | 15:55 |
| vishakha | using head getting some strange error. | 15:55 |
| cmurphy | lbragstad: you know you can +W and if zuul doesn't like it it won't merge it? | 15:56 |
| lbragstad | cmurphy yeah - i got my hand slapped for doing that a long time ago, but that was also a long time ago | 15:56 |
| *** jamesmcarthur has quit IRC | 15:57 | |
| *** jamesmcarthur has joined #openstack-keystone | 15:57 | |
| lbragstad | vishakha i assume https://review.openstack.org/#/c/642421/1/keystone/tests/unit/protection/v3/test_grant.py@56 makes the error repeatable? | 15:57 |
| lbragstad | cmurphy my hesitation/FUD probably isn't relevant anymore | 15:58 |
| cmurphy | i think zuul was always designed to prevent merging if it didn't pass ci | 15:58 |
| lbragstad | true - when i was advised to not do that was when we were still using Jenkins | 15:59 |
| cmurphy | ah | 15:59 |
| vishakha | lbragstad: it is showing assertion error - I AM A TEAPOT (418) | 15:59 |
| lbragstad | lol | 15:59 |
| *** jamesmcarthur has quit IRC | 16:00 | |
| vishakha | :) | 16:00 |
| lbragstad | vishakha commented | 16:01 |
| *** jamesmcarthur has joined #openstack-keystone | 16:01 | |
| vishakha | thanks for the quick comment | 16:01 |
| vishakha | lbragstad: it worked | 16:02 |
| lbragstad | no more 418? | 16:03 |
| vishakha | yes | 16:03 |
| lbragstad | ++ | 16:03 |
| *** erus has quit IRC | 16:15 | |
| *** erus has joined #openstack-keystone | 16:18 | |
| *** pcaruana has quit IRC | 16:23 | |
| *** pcaruana has joined #openstack-keystone | 16:23 | |
| kmalloc | Hmm | 16:36 |
| kmalloc | The teapot error saves us again from a broken test! | 16:37 |
| lbragstad | broken teapots are the worst | 16:42 |
| *** nsmeds has left #openstack-keystone | 16:45 | |
| *** gyee has joined #openstack-keystone | 16:46 | |
| *** kklimonda_ has quit IRC | 17:14 | |
| *** kklimonda has joined #openstack-keystone | 17:14 | |
| hrybacki | kmalloc: o/ | 17:35 |
| hrybacki | what happens in KSM if a memcached instance disappears? | 17:35 |
| hrybacki | (assuming you have caching enabled and using memcached per norm) | 17:36 |
| kmalloc | in theory, the memcache instance is failed out and causes a minimal amount of slow down. | 17:38 |
| kmalloc | and the caching is always a cache miss | 17:38 |
| kmalloc | if you have multiple servers, then the cache is rebalanced via a hash | 17:38 |
| kmalloc | and the previously cached data is a miss, new data is placed in the current servers. if the server comes back in, the hash rebalance probably causes some misses | 17:39 |
| hrybacki | let's say we only have a single memcached server running, it goes down, and is taking minutes (for whatever reason) to come back up | 17:40 |
| hrybacki | is this going to hold everything up or is ksm going to ignore it after X failed set/gets? | 17:40 |
| *** jamesmcarthur has quit IRC | 17:40 | |
| kmalloc | should ignore if memcache(d) interface is written correctly | 17:40 |
| kmalloc | after a nominal timeout | 17:41 |
| *** jamesmcarthur has joined #openstack-keystone | 17:41 | |
| kmalloc | in the past we had a big delay. | 17:41 |
| kmalloc | but that was bug related. | 17:41 |
| hrybacki | hmm. it's a good thing tripleo doesn't make this more complicated /s | 17:42 |
| *** jamesmcarthur has quit IRC | 17:45 | |
| lbragstad | i'm not sure if people here have a strong preference for gathering around tables with food - but i added some ideas to the etherpad https://etherpad.openstack.org/p/DEN-keystone-forum-sessions | 17:50 |
| *** jamesmcarthur has joined #openstack-keystone | 18:20 | |
| *** jamesmcarthur has quit IRC | 18:26 | |
| *** jamesmcarthur has joined #openstack-keystone | 18:47 | |
| *** raildo has quit IRC | 19:16 | |
| *** raildo has joined #openstack-keystone | 19:16 | |
| *** raildo_ has joined #openstack-keystone | 19:18 | |
| *** raildo has quit IRC | 19:21 | |
| *** xek has quit IRC | 19:23 | |
| *** xek has joined #openstack-keystone | 19:23 | |
| *** xek has quit IRC | 19:43 | |
| *** xek has joined #openstack-keystone | 19:43 | |
| *** itlinux has joined #openstack-keystone | 20:30 | |
| *** itlinux has quit IRC | 20:34 | |
| *** vishakha has quit IRC | 20:45 | |
| *** phasespace has joined #openstack-keystone | 20:55 | |
| *** jamesmcarthur has quit IRC | 20:56 | |
| *** itlinux has joined #openstack-keystone | 20:56 | |
| *** erus has quit IRC | 21:14 | |
| *** raildo_ has quit IRC | 21:17 | |
| *** xek has quit IRC | 21:18 | |
| *** whoami-rajat has quit IRC | 21:25 | |
| *** dave-mccowan has quit IRC | 21:36 | |
| *** pcaruana has quit IRC | 21:45 | |
| *** itlinux has quit IRC | 21:55 | |
| *** lbragstad has quit IRC | 22:40 | |
| *** lbragstad has joined #openstack-keystone | 22:43 | |
| *** ChanServ sets mode: +o lbragstad | 22:43 | |
| *** threestrands has joined #openstack-keystone | 22:50 | |
| *** tkajinam has joined #openstack-keystone | 22:56 | |
| *** TheJulia has joined #openstack-keystone | 23:00 | |
| openstackgerrit | Merged openstack/keystone master: Remove publish-loci post job https://review.openstack.org/642502 | 23:22 |
| *** threestrands has quit IRC | 23:45 | |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!