*** markvoelker has joined #openstack-keystone | 00:03 | |
*** markvoelker has quit IRC | 00:07 | |
*** dave-mccowan has quit IRC | 00:11 | |
*** gyee has quit IRC | 00:15 | |
*** jamesmcarthur has joined #openstack-keystone | 00:20 | |
*** markvoelker has joined #openstack-keystone | 00:35 | |
*** markvoelker has quit IRC | 00:49 | |
*** jamesmcarthur has quit IRC | 01:11 | |
*** dustinc has quit IRC | 01:22 | |
*** whoami-rajat has joined #openstack-keystone | 01:25 | |
*** shyamb has joined #openstack-keystone | 01:26 | |
*** rodrigods has joined #openstack-keystone | 01:42 | |
*** dave-mccowan has joined #openstack-keystone | 01:52 | |
*** lbragstad has quit IRC | 01:56 | |
*** lbragstad has joined #openstack-keystone | 02:09 | |
*** ChanServ sets mode: +o lbragstad | 02:09 | |
*** jamesmcarthur has joined #openstack-keystone | 02:20 | |
*** dave-mccowan has quit IRC | 02:23 | |
*** erus has joined #openstack-keystone | 02:24 | |
*** jamesmcarthur has quit IRC | 02:25 | |
*** jamesmcarthur has joined #openstack-keystone | 02:38 | |
*** jamesmcarthur has quit IRC | 02:43 | |
*** shyam89 has joined #openstack-keystone | 02:50 | |
*** shyamb has quit IRC | 02:53 | |
*** itlinux has joined #openstack-keystone | 03:05 | |
*** shyam89 has quit IRC | 03:08 | |
*** zzzeek has quit IRC | 03:10 | |
*** shyamb has joined #openstack-keystone | 03:11 | |
*** jamesmcarthur has joined #openstack-keystone | 03:14 | |
*** zzzeek has joined #openstack-keystone | 03:16 | |
rm_work | anyone run into issues recently running unit tests on a macbook? | 03:23 |
---|---|---|
rm_work | i'm running it again to try to get the major error, i lost it to scrollback | 03:24 |
*** jamesmcarthur has quit IRC | 03:31 | |
*** jamesmcarthur has joined #openstack-keystone | 03:31 | |
*** shyamb has quit IRC | 03:52 | |
*** shyamb has joined #openstack-keystone | 03:52 | |
*** shyamb has quit IRC | 03:58 | |
rm_work | ah there it is | 04:01 |
rm_work | "ValueError: option error" on 5915 tests out of 6322 T_T | 04:01 |
rm_work | lbragstad: you had a +2 on the other version of https://review.openstack.org/#/c/599447/ but this one was technically first so the other was abandoned | 04:05 |
rm_work | if you wanted to do something with this one ;) | 04:05 |
rm_work | anyway, my error seems to be with something in the python-ldap lib | 04:17 |
rm_work | not sure why though, no version seems to work, so i'm guessing it's local | 04:17 |
rm_work | erg, looks like this: https://mail.python.org/pipermail/python-ldap/2016q3/003777.html | 04:30 |
rm_work | wonder what workarounds people are using | 04:30 |
*** erus has quit IRC | 04:31 | |
*** jamesmcarthur has quit IRC | 04:40 | |
*** dklyle has quit IRC | 04:44 | |
*** dklyle has joined #openstack-keystone | 04:45 | |
openstackgerrit | Merged openstack/keystone master: Use ForbiddenAction for invalid action instead of Forbidden https://review.openstack.org/643890 | 05:23 |
*** shyamb has joined #openstack-keystone | 05:39 | |
*** shyamb has quit IRC | 05:41 | |
*** shyamb has joined #openstack-keystone | 05:41 | |
*** shyamb has quit IRC | 06:32 | |
*** shyamb has joined #openstack-keystone | 06:36 | |
*** lbragstad has quit IRC | 06:38 | |
*** markvoelker has joined #openstack-keystone | 06:51 | |
*** jaosorior has quit IRC | 06:55 | |
*** jaosorior has joined #openstack-keystone | 06:57 | |
*** itlinux has quit IRC | 06:57 | |
*** itlinux has joined #openstack-keystone | 06:58 | |
*** shyamb has quit IRC | 07:13 | |
*** pcaruana has joined #openstack-keystone | 07:14 | |
*** shyamb has joined #openstack-keystone | 07:16 | |
*** itlinux has quit IRC | 07:21 | |
*** pcaruana has quit IRC | 07:33 | |
*** pcaruana has joined #openstack-keystone | 07:34 | |
*** shyamb has quit IRC | 07:53 | |
*** zzzeek has quit IRC | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:02 | |
*** awalende has joined #openstack-keystone | 08:11 | |
*** phasespace has joined #openstack-keystone | 08:22 | |
*** shyamb has joined #openstack-keystone | 08:41 | |
*** dklyle has quit IRC | 09:08 | |
*** dklyle has joined #openstack-keystone | 09:09 | |
*** kukacz has quit IRC | 09:11 | |
*** xek has joined #openstack-keystone | 09:15 | |
*** tkajinam has quit IRC | 09:18 | |
*** kukacz has joined #openstack-keystone | 09:28 | |
*** kukacz has quit IRC | 09:29 | |
*** kukacz has joined #openstack-keystone | 09:30 | |
*** shyamb has quit IRC | 09:31 | |
*** shyamb has joined #openstack-keystone | 09:34 | |
*** kukacz has quit IRC | 09:39 | |
*** kukacz has joined #openstack-keystone | 09:39 | |
*** shyamb has quit IRC | 09:45 | |
*** dustinc has joined #openstack-keystone | 10:03 | |
*** rcernin has quit IRC | 11:24 | |
openstackgerrit | Merged openstack/oslo.policy master: Update master for stable/stein https://review.openstack.org/644075 | 11:56 |
*** dave-mccowan has joined #openstack-keystone | 11:57 | |
*** raildo has joined #openstack-keystone | 12:08 | |
*** dustinc has quit IRC | 12:20 | |
*** markvoelker has quit IRC | 12:24 | |
*** mchlumsky has joined #openstack-keystone | 12:33 | |
*** erus has joined #openstack-keystone | 12:37 | |
coreycb | cmurphy: thanks for the review on https://review.openstack.org/#/c/643670/. who should I seek out to get another +2 on that? | 12:43 |
*** erus has quit IRC | 12:43 | |
*** erus has joined #openstack-keystone | 12:44 | |
cmurphy | needscoffee: knikolla gagehugo wxy-xiyuan ^ | 12:44 |
coreycb | thanks | 12:46 |
*** mchlumsky has quit IRC | 12:56 | |
*** mchlumsky has joined #openstack-keystone | 12:58 | |
*** jmlowe has quit IRC | 13:19 | |
erus | o/ | 13:22 |
*** lbragstad has joined #openstack-keystone | 13:34 | |
*** ChanServ sets mode: +o lbragstad | 13:34 | |
*** erus has quit IRC | 13:34 | |
cmurphy | lbragstad: o/ coreycb is looking for reviews on https://review.openstack.org/#/c/643670/ | 13:35 |
*** erus has joined #openstack-keystone | 13:35 | |
lbragstad | ack | 13:35 |
lbragstad | cmurphy we're good with https://review.openstack.org/#/c/599447/ yeah? | 13:36 |
cmurphy | lbragstad: yep | 13:36 |
cmurphy | got some other reviews to fix the rocky ci if you are looking for things to do https://review.openstack.org/643599 https://review.openstack.org/642716 | 13:39 |
lbragstad | i'm +2 on both of those, thanks for giving stable/rocky some love | 13:43 |
lbragstad | i can single approve if needed - i don't see kmalloc around | 13:43 |
* cmurphy pats stable/rocky on the head | 13:44 | |
cmurphy | he still has his casual friday nick so i don't think he's around | 13:44 |
lbragstad | aha | 13:45 |
lbragstad | casual tuesdays can totally be a thing | 13:45 |
*** erus has quit IRC | 13:45 | |
cmurphy | lol | 13:45 |
cmurphy | coreycb: should we wait to merge https://review.openstack.org/613648 until we have the backport for https://review.openstack.org/#/c/643670/ ? | 13:47 |
lbragstad | i assume we still need https://review.openstack.org/#/c/641128/ and https://review.openstack.org/#/c/642026/ merged before we can officially cut rc1 | 13:49 |
cmurphy | i think so | 13:49 |
cmurphy | or else we would definitely need an rc2 | 13:49 |
lbragstad | ++ | 13:51 |
gagehugo | o/ | 13:51 |
cmurphy | yay gagehugo | 13:51 |
cmurphy | can you review those ^ | 13:51 |
gagehugo | looking | 13:52 |
cmurphy | also wondering if we need to be fixing https://bugs.launchpad.net/keystone/+bug/1819957 for rc1, or if we even can considering it touches keystonemiddleware which is frozen? | 13:52 |
openstack | Launchpad bug 1819957 in keystonemiddleware "Caching with stale data when a server disconnects due to network partition and reconnects" [High,Triaged] - Assigned to Morgan Fainberg (mdrnstm) | 13:52 |
cmurphy | hopefully kmalloc is around today | 13:53 |
cmurphy | thanks gagehugo | 13:54 |
gagehugo | \o/ | 13:54 |
*** whoami-rajat has quit IRC | 13:55 | |
needscoffee | rm_work: unit tests on os x have been flaky for years. Has to do with a few things, incluodng the lack of updated open source libraries/headers at the system level (brew doesn't solve it) | 14:02 |
rm_work | Yeah, figured it out | 14:03 |
rm_work | It was bad system ldap lib | 14:03 |
needscoffee | rm_work: not recommended and I gave up maintaining it around mitaka (I think I was the last person to maintain it) | 14:03 |
rm_work | Brew did actually fix it in my case :( | 14:04 |
rm_work | Err, :) | 14:04 |
needscoffee | Yep, the fix is replacing the lib or changing ldap python each download. It broke other things when I tried the former. | 14:04 |
rm_work | Had to install openldap with Brew and export the includes path | 14:04 |
rm_work | Seems to work fine | 14:05 |
needscoffee | Yeah, I really don't recommend that . | 14:05 |
rm_work | It's cask-only otherwise so doesn't interfere with the system | 14:05 |
rm_work | I just export it in whatever she'll I'm doing tox stuff in | 14:05 |
needscoffee | I had to do a system reinstall when I did that..*shrug* | 14:06 |
needscoffee | But fwiw, os x is not a maintained platform for tests for keystone | 14:06 |
needscoffee | So things might break randomy | 14:06 |
rm_work | That's ... Weird. Brew is very well sandboxed from what I've experienced | 14:06 |
needscoffee | Or not mirror Linux testing | 14:07 |
rm_work | Anywho, kk | 14:07 |
needscoffee | Brew was not as good years ago | 14:07 |
needscoffee | And I do mean years. | 14:07 |
rm_work | Yeah I maintain osx testing compatability in Octavia, it can definitely be a pain | 14:07 |
needscoffee | I used a VM that pulled in via export (vagrant) the local filesystem for keystone. | 14:08 |
needscoffee | When things were too painful on os x | 14:09 |
cmurphy | hey needscoffee | 14:09 |
cmurphy | i have some questions for you | 14:09 |
*** needscoffee is now known as kmalloc | 14:09 | |
kmalloc | cmurphy: ask away | 14:09 |
cmurphy | kmalloc: https://bugs.launchpad.net/keystone/+bug/1819957 severe enough for rc1/rc2? | 14:09 |
openstack | Launchpad bug 1819957 in keystonemiddleware "Caching with stale data when a server disconnects due to network partition and reconnects" [High,Triaged] - Assigned to Morgan Fainberg (mdrnstm) | 14:09 |
kmalloc | I am pre-coffee, but here. | 14:09 |
kmalloc | Probably good to land it.if we can | 14:10 |
kmalloc | It is a 2-line fix. | 14:10 |
cmurphy | what about for keystonemiddleware, do we need an ffe for that? | 14:10 |
kmalloc | We can either fix oslo-cache or in keystone and middleware | 14:10 |
kmalloc | And yes, we need to fix it there too. | 14:11 |
kmalloc | I am thinking keystone/ksm is easier to fix and cache in train and forward | 14:11 |
kmalloc | This requires back ports as well | 14:11 |
*** erus has joined #openstack-keystone | 14:12 | |
kmalloc | Oslo-cache in train and forward | 14:12 |
kmalloc | I am happy to fix in either place though | 14:12 |
erus | hi kmalloc :) | 14:12 |
cmurphy | whichever you think is best | 14:12 |
kmalloc | bnemec: ^cc re fixing in oslo-cache vs in keystone/ksm | 14:12 |
* bnemec reads | 14:13 | |
kmalloc | cmurphy: I'll check back-portability | 14:13 |
kmalloc | If it is easier to catch both with oslo-cache I'll try to do that | 14:13 |
kmalloc | It is on my "today" list | 14:13 |
kmalloc | Including backports | 14:14 |
* bnemec notes that every Tuesday is casual Tuesday when you WFH | 14:14 | |
* bnemec reads the actual relevant parts of the discussion | 14:14 | |
cmurphy | :P | 14:14 |
kmalloc | bnemec: ah, going for the pajama irc-ing? ;) | 14:14 |
* kmalloc had a Dr appointment yesterday and was mostly offline. | 14:15 | |
coreycb | cmurphy: sorry for the delay. it wouldn't hurt to merge the 2 backports at the same time. | 14:15 |
kmalloc | cmurphy: anything else? | 14:15 |
cmurphy | coreycb: okay | 14:15 |
cmurphy | kmalloc: next question, did you get anywhere with https://bugs.launchpad.net/keystone/+bug/1801873 ? | 14:15 |
openstack | Launchpad bug 1801873 in OpenStack Identity (keystone) "Unable to delete domains when users was managed by LDAP back-end" [Medium,New] | 14:15 |
kmalloc | I have not. | 14:16 |
cmurphy | okay i'll try to look into it | 14:16 |
kmalloc | I know where the code needs to be fixed, it isnt fun (tests are gross for ldap) | 14:16 |
*** xek_ has joined #openstack-keystone | 14:17 | |
kmalloc | It wasnt a bad rabbit hole, but it went deeper than I expected. | 14:17 |
bnemec | Aren't they always? | 14:17 |
cmurphy | it always does T.T | 14:17 |
*** mvkr has quit IRC | 14:18 | |
bnemec | kmalloc: I agree re: Fixing in Keystone vs. oslo.cache for this cycle. | 14:18 |
cmurphy | kmalloc: last question, are you going to take https://bugs.launchpad.net/keystone/+bug/1817313 or should i look at it? | 14:18 |
openstack | Launchpad bug 1817313 in OpenStack Identity (keystone) "RBAC Enforcer Programming Error raised for malformed federation protocol request" [High,Triaged] | 14:18 |
bnemec | I feel like it's easier to do another release of a service project than an Oslo lib at this point. | 14:18 |
kmalloc | bnemec: keystonemiddleware isn't exactly easy to release this late in | 14:19 |
kmalloc | About the same pain as oslo lib | 14:19 |
*** xek has quit IRC | 14:19 | |
cmurphy | yeah :/ | 14:19 |
kmalloc | cmurphy: I'll hop on that one | 14:19 |
bnemec | kmalloc: Oh, the fix is in middleware, not keystone itself? | 14:19 |
kmalloc | bnemec: both | 14:19 |
cmurphy | yay thanks kmalloc | 14:19 |
kmalloc | And impacts anything using oslo-cache | 14:19 |
bnemec | kmalloc: If we fix it in oslo.cache does that mean you don't need to fix both? | 14:19 |
kmalloc | Admittedly, a small number of things | 14:20 |
kmalloc | Correct | 14:20 |
kmalloc | But it also.needs to be backported | 14:20 |
kmalloc | And ksm didn't use oslo-cache that long ago | 14:20 |
bnemec | If we're going to backport it for stein anyway we might as well just merge the fix now and get it in for release. | 14:20 |
kmalloc | So it might be easier to backport a non-oslo cache fix | 14:20 |
bnemec | Ah | 14:21 |
kmalloc | I need to check. | 14:21 |
bnemec | It's pretty clear I don't know what I'm talking about here so I will most likely support whatever you suggest. :-) | 14:22 |
*** phasespace has quit IRC | 14:32 | |
*** dustinc has joined #openstack-keystone | 14:36 | |
*** jamesmcarthur has joined #openstack-keystone | 14:39 | |
*** mvkr has joined #openstack-keystone | 14:47 | |
*** itlinux has joined #openstack-keystone | 14:47 | |
*** jmlowe has joined #openstack-keystone | 14:54 | |
knikolla | o/ | 14:57 |
knikolla | ildikov: o/ | 14:57 |
erus | \o | 14:58 |
knikolla | hey erus :) | 14:58 |
ildikov | knikolla: hi | 14:58 |
erus | hi knikolla how are you? :) | 14:58 |
ildikov | knikolla: I wanted to ask you if you're still working on this patch: https://review.openstack.org/#/c/484121/ ? | 14:59 |
*** awalende has quit IRC | 15:10 | |
openstackgerrit | erus proposed openstack/keystone master: Add new attribute to the federation protocol API https://review.openstack.org/637305 | 15:12 |
*** awalende has joined #openstack-keystone | 15:16 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: Added keystone identity provider installation to Devstack plugin https://review.openstack.org/484121 | 15:16 |
*** awalende has quit IRC | 15:16 | |
ildikov | knikolla: thanks :) | 15:17 |
knikolla | ildikov: just revised based on comments, but it seems the rebase was weird. giving it a look. | 15:17 |
ildikov | I hope it's just some small hiccup | 15:18 |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: Added keystone identity provider installation to Devstack plugin https://review.openstack.org/484121 | 15:22 |
*** whoami-rajat has joined #openstack-keystone | 15:22 | |
knikolla | ildikov: yeah, i just hand't pulled in a while, haha. | 15:23 |
ildikov | :) | 15:23 |
knikolla | cmurphy: i'll answer here if that's okay with you | 15:25 |
knikolla | both samltest and k2k are configured alongside each other, and the tests are separate | 15:28 |
knikolla | the id and endpoints are hardcoded for k2k tests https://review.openstack.org/#/c/580041/3/keystone_tempest_plugin/tests/scenario/test_federated_authentication.py | 15:28 |
*** jmlowe has quit IRC | 15:29 | |
openstackgerrit | Merged openstack/keystone master: PY3: Ensure LDAP searches use unicode attributes https://review.openstack.org/643670 | 15:29 |
knikolla | we can switch to keystone-only at a later date. | 15:30 |
cmurphy | knikolla: oh I see, so we can't stop relying on samltest | 15:31 |
knikolla | We can, but feels safer to run both for a bit. | 15:32 |
cmurphy | is there a real difference in what they're testing? they're both basically going through /OS-FEDERATION/identity_providers/%s/protocols/%s/auth | 15:34 |
knikolla | cmurphy: the difference is on how you get the saml assertion. | 15:35 |
knikolla | and there was a weird inconsistency in one of the headers when getting an unscoped token from the assertion | 15:35 |
cmurphy | ah yeah | 15:36 |
knikolla | but essentially you are right. we're just getting the headers from shibboleth. | 15:36 |
*** yan0s has joined #openstack-keystone | 15:41 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystone-specs master: Renewable Application Credentials https://review.openstack.org/604201 | 15:49 |
*** raildo has quit IRC | 15:51 | |
*** raildo has joined #openstack-keystone | 15:51 | |
cmurphy | yay ^ | 15:53 |
kmalloc | oh hi. i might be awake now | 15:58 |
kmalloc | yay coffee | 15:58 |
cmurphy | yay | 15:58 |
*** wxy| has joined #openstack-keystone | 15:59 | |
knikolla | i've almost entirely ditched my office for coffee shops | 15:59 |
*** jaosorior has quit IRC | 16:02 | |
*** ayoung has joined #openstack-keystone | 16:04 | |
*** jamesmcarthur has quit IRC | 16:04 | |
*** jamesmcarthur has joined #openstack-keystone | 16:05 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: Add documentation for service tokens https://review.openstack.org/631110 | 16:12 |
*** itlinux has quit IRC | 16:17 | |
*** itlinux has joined #openstack-keystone | 16:44 | |
*** wxy| has quit IRC | 16:45 | |
*** mvkr has quit IRC | 16:47 | |
lbragstad | in other news | 16:55 |
lbragstad | apparently nova has a policy vision documents that has existed since 2014 o.) | 16:55 |
lbragstad | o.0 | 16:55 |
cmurphy | wow | 16:56 |
lbragstad | https://docs.openstack.org/nova/latest/reference/policy-enforcement.html | 16:56 |
*** mriedem has joined #openstack-keystone | 17:02 | |
*** jmlowe has joined #openstack-keystone | 17:02 | |
mriedem | lbragstad: we should avoid mentioning configuring services' [keystone_authtoken] section to use www_authenticate_uri yeah? that's a v2 relic right? | 17:02 |
cmurphy | no, www_authenticate_uri is required, not v2-specific | 17:03 |
lbragstad | www_authenticate_uri is a more descriptive of an old and confusing alternative we were using | 17:03 |
mriedem | hmm, ok, context: https://review.openstack.org/#/c/643938/5/doc/source/install/from-pypi.rst@139 | 17:03 |
cmurphy | www_authenticate_uri and auth_url should both be set | 17:04 |
mriedem | hmm | 17:07 |
mriedem | we don't have www_authenticate_uri in any of the nova install docs, | 17:07 |
mriedem | or the placement install docs for the distro-based instructions | 17:07 |
mriedem | nor is it set by devstack http://logs.openstack.org/76/644576/1/check/tempest-full-py3/7769ef9/controller/logs/etc/placement/placement_conf.txt.gz | 17:08 |
mriedem | so it seems entirely optional | 17:08 |
cmurphy | well, it is kind of optional because of how openstackclient works | 17:10 |
cmurphy | what it does is if it doesn't see a token in the X-Auth-Token header it sets the WWW-Authenticate header in its response to the user | 17:10 |
cmurphy | to yell at them to go authenticate | 17:10 |
cmurphy | but most clients sidestep that and go to keystone first anyways | 17:11 |
*** jmlowe has quit IRC | 17:13 | |
knikolla | lbragstad: cmurphy: I +A-ed the first two patches on https://etherpad.openstack.org/p/keystone-stein-rc2-tracking . should i have unapprove and wait for RC1 first? | 17:19 |
cmurphy | knikolla: no let's go for it | 17:20 |
*** gyee has joined #openstack-keystone | 17:24 | |
lbragstad | thanks knikolla | 17:27 |
knikolla | i'll keep reviewing then | 17:28 |
*** erus has quit IRC | 17:31 | |
*** yan0s has quit IRC | 17:33 | |
*** jmlowe has joined #openstack-keystone | 17:34 | |
*** jamesmcarthur has quit IRC | 17:39 | |
* lbragstad steps away for lunch | 17:53 | |
*** jamesmcarthur has joined #openstack-keystone | 17:54 | |
*** mriedem has left #openstack-keystone | 17:58 | |
*** itlinux has quit IRC | 18:02 | |
*** jmlowe has quit IRC | 18:04 | |
*** jamesmcarthur has quit IRC | 18:12 | |
openstackgerrit | Merged openstack/keystone master: Add schema placeholders for Stein https://review.openstack.org/642026 | 18:14 |
*** jamesmcarthur has joined #openstack-keystone | 18:14 | |
*** jamesmcarthur has quit IRC | 18:14 | |
*** jamesmcarthur has joined #openstack-keystone | 18:14 | |
*** rafaelweingartne has joined #openstack-keystone | 18:21 | |
rafaelweingartne | Hello Keystone guys, is it possible to map users from an IdP to a domain that is different from the domain to which the IdP is registered? | 18:21 |
rafaelweingartne | I mean, in the mapping, when creating a user, I can define the "domain" for this user | 18:21 |
rafaelweingartne | however, this is not working. Keystone is always adding the user to the IdP domain | 18:22 |
knikolla | rafaelweingartne: nope, it seems to be hardcoded. https://github.com/openstack/keystone/blob/2e5b58caa7f1f39b04458aecd1bc3360031169bb/keystone/identity/core.py#L1437-L1438 | 18:26 |
rafaelweingartne | ah, that broke all of our assumptions :( | 18:29 |
rafaelweingartne | do you know the reason to hard code it? | 18:30 |
rafaelweingartne | I mean, the attribute mappings are allowing such configs, so it seems natural to accept whatever is mapped in the attribute mapping rules | 18:30 |
*** jmlowe has joined #openstack-keystone | 18:47 | |
rafaelweingartne | I have another question. What would happen if I map a local user in OpenStack that is in a different domain from the domain of the IdP | 18:53 |
rafaelweingartne | would it work? | 18:53 |
rafaelweingartne | I am testing this case, and I seem to get in an infinite loop, but I am not finding an error in the log file | 18:54 |
knikolla | rafaelweingartne: can i see the mapping you are using? | 18:55 |
knikolla | i remember last playing around with mapping to local users over 2 years ago and it didn't seem to work too well. | 18:56 |
rafaelweingartne | sure | 18:56 |
rafaelweingartne | what is the openstack paste URL? | 18:57 |
knikolla | paste.openstack.org | 18:57 |
*** jmlowe has quit IRC | 18:58 | |
rafaelweingartne | http://paste.openstack.org/show/748056/ | 18:59 |
rafaelweingartne | BTW: when I configure my user to have "openstack-user-status" attribute as "member", then my user is mapped, and I am able to login | 19:01 |
rafaelweingartne | the problem is that this creates a new user in the domain of the IdP | 19:01 |
rafaelweingartne | I would like to be able to override that domain configuration | 19:01 |
knikolla | rafaelweingartne: i don't think "project" will work when setting type to local. | 19:11 |
*** awalende has joined #openstack-keystone | 19:11 | |
rafaelweingartne | no, it will not | 19:12 |
rafaelweingartne | I have checked the code, when usign local, Keystone only uses the local reference of the user | 19:12 |
knikolla | yeah, i'd say there's too much going on right now in your mappings. try a simpler version with type "local" to figure out which of the sections is causing the loop. | 19:13 |
knikolla | but outside of that, you can't currently create a shadow user in a different domain. | 19:13 |
*** awalende has quit IRC | 19:16 | |
*** jmlowe has joined #openstack-keystone | 19:16 | |
rafaelweingartne | but the local mapping works ... | 19:17 |
rafaelweingartne | shame on me... | 19:17 |
rafaelweingartne | I forgot to add the user to the group | 19:17 |
rafaelweingartne | that is why it was not able to login | 19:17 |
rafaelweingartne | Thanks! | 19:18 |
rafaelweingartne | Sometimes all we need is somebody to talk | 19:18 |
*** phasespace has joined #openstack-keystone | 19:18 | |
*** rafaelweingartne has quit IRC | 19:25 | |
knikolla | glad it worked! | 19:36 |
*** jamesmcarthur has quit IRC | 19:41 | |
*** jamesmcarthur has joined #openstack-keystone | 19:42 | |
*** jamesmcarthur has quit IRC | 19:45 | |
*** jamesmcarthur_ has joined #openstack-keystone | 19:45 | |
*** jmlowe has quit IRC | 19:47 | |
*** jamesmcarthur_ has quit IRC | 20:02 | |
*** jamesmcarthur has joined #openstack-keystone | 20:03 | |
*** jmlowe has joined #openstack-keystone | 20:07 | |
*** jamesmcarthur has quit IRC | 20:08 | |
*** jamesmcarthur has joined #openstack-keystone | 20:08 | |
*** dustinc is now known as dustinc|afk | 20:09 | |
*** itlinux has joined #openstack-keystone | 20:13 | |
*** xek_ has quit IRC | 21:11 | |
*** dustinc|afk is now known as dustinc | 21:21 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add keystone's technical vision reflection https://review.openstack.org/641374 | 21:35 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Only validate tokens once per request https://review.openstack.org/641499 | 21:40 |
lbragstad | ^ *should* be ready for reviews, but the tests is kind ugly | 21:40 |
*** itlinux has quit IRC | 21:40 | |
* lbragstad runs to daycare quick | 21:40 | |
rm_work | hmm, having another test issue, this time *can't* replicate on my mac, only in my ci pipeline | 21:43 |
rm_work | anyone ever seen this test be flaky for any reason before? keystone.tests.unit.test_cli.TestGroupMappingPurgeFunctional.test_purge_by_group_type | 21:43 |
rm_work | also, why are there cli tests in the keystone service? | 21:43 |
cmurphy | it's the keystone-manage cli | 21:46 |
rm_work | ahh k | 21:46 |
rm_work | http://paste.openstack.org/show/748071/ is what i'm getting | 21:50 |
rm_work | seems to fail consistently in my CI, i'm still looking into it but if anyone has already seen this before, would love to know :D | 21:51 |
rm_work | ah this is on rocky | 21:52 |
*** whoami-rajat has quit IRC | 21:52 | |
cmurphy | hmm we haven't seen that on the rocky ci | 21:54 |
rm_work | hmm k | 21:54 |
*** pcaruana has quit IRC | 22:08 | |
*** jamesmcarthur has quit IRC | 22:08 | |
*** mvkr has joined #openstack-keystone | 22:09 | |
*** itlinux has joined #openstack-keystone | 22:16 | |
*** rcernin has joined #openstack-keystone | 22:16 | |
*** itlinux has quit IRC | 22:27 | |
*** jamesmcarthur has joined #openstack-keystone | 22:30 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement domain reader functionality for user API https://review.openstack.org/623319 | 22:33 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement domain member functionality for user API https://review.openstack.org/623320 | 22:34 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement domain admin functionality for user API https://review.openstack.org/623321 | 22:34 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add explicit testing for project users and the user API https://review.openstack.org/623322 | 22:34 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove user policies from policy.v3cloudsample.json https://review.openstack.org/623323 | 22:34 |
kmalloc | thats an odd one rm_work | 22:34 |
rm_work | hmm, when i run the test by itself in the CI env, it passes, as well as if i just run the whole test_cli | 22:34 |
rm_work | but fails if i run the entire suite | 22:34 |
kmalloc | that sounds like something is keeping state in your environjment incorrectly | 22:35 |
lbragstad | lower-constraints on master seems to be hosed | 22:35 |
rm_work | something is fishy here | 22:35 |
rm_work | not sure what that'd be | 22:35 |
rm_work | let me try running with parallelism off | 22:35 |
kmalloc | lbragstad: ugh. | 22:35 |
*** raildo has quit IRC | 22:35 | |
rm_work | unfortunately since it only fails as part of the full suite, testing these theories takes a while | 22:35 |
lbragstad | kmalloc i'm not missing something am i? http://logs.openstack.org/18/624218/9/gate/openstack-tox-lower-constraints/e538a6e/testr_results.html.gz | 22:36 |
kmalloc | no it's on our end | 22:37 |
kmalloc | we need to remap an import | 22:37 |
lbragstad | ah | 22:37 |
kmalloc | i think. | 22:37 |
kmalloc | no ... | 22:37 |
lbragstad | sounds like something we'll need to get into rc forsure when | 22:37 |
lbragstad | then* | 22:37 |
kmalloc | that isn't the root but we should fix | 22:37 |
kmalloc | DeprecationWarning: 'werkzeug.wsgi.DispatcherMiddleware' has moved to 'werkzeug.middleware.dispatcher.DispatcherMiddleware'. This import is deprecated as of version 0.15 and will be removed in version 1.0. | 22:38 |
kmalloc | so we need to import the new location | 22:38 |
kmalloc | to start. | 22:38 |
cmurphy | what the | 22:38 |
kmalloc | werkzeug changed the location | 22:38 |
kmalloc | werkzeug is the basis of flask | 22:38 |
kmalloc | we import directly from werkzeug for the dispatcher (used for healthcheck etc) | 22:39 |
cmurphy | on lower constraints? isn't the point of those that those are pinned to a specific version? | 22:39 |
kmalloc | oh wait LC? | 22:39 |
kmalloc | well LC might have been bumped up. | 22:39 |
kmalloc | which hit that. | 22:39 |
lbragstad | for example - https://review.openstack.org/#/c/624218/ | 22:39 |
kmalloc | but we need to fix that **anyway** | 22:39 |
kmalloc | it might be obscuring the real cause of the error | 22:40 |
kmalloc | it looks lik that deprecation warning is the issue though | 22:40 |
cmurphy | i guess Werkzeug isn't pinned in lower-constraints.txt, fastest fix is probably to pin it there, but i'm confused that it hit lower-constraints and not the regular tests | 22:43 |
lbragstad | ^ that's my question | 22:43 |
lbragstad | er - i share that same confusion | 22:44 |
*** jamesmcarthur has quit IRC | 22:45 | |
*** jamesmcarthur has joined #openstack-keystone | 22:46 | |
cmurphy | py37: Werkzeug==0.14.1, lower-constraints: Werkzeug==0.15.0 | 22:49 |
cmurphy | oh they released 5 hours ago | 22:49 |
cmurphy | maybe mirror wasn't synced yet for one job | 22:50 |
*** jamesmcarthur has quit IRC | 22:52 | |
cmurphy | ah okay so what happened is upper-constraints.txt *does* pin Werkzeug to 0.14.1 but our lower-constraints.txt *doesn't* pin it | 22:54 |
*** tkajinam has joined #openstack-keystone | 22:57 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Pin Werkzeug in lower-constraints https://review.openstack.org/644695 | 22:58 |
* cmurphy -> bed | 22:58 | |
kmalloc | well we should fix this in either case in our code. | 23:03 |
cmurphy | but we don't have to until they raise the upper constraint in requirements | 23:03 |
kmalloc | fair point | 23:06 |
kmalloc | not RC critical | 23:06 |
*** mchlumsky has quit IRC | 23:08 | |
*** jamesmcarthur has joined #openstack-keystone | 23:14 | |
*** jamesmcarthur has quit IRC | 23:30 | |
*** jamesmcarthur has joined #openstack-keystone | 23:51 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!