*** gyee has quit IRC | 00:11 | |
*** irclogbot_3 has joined #openstack-keystone | 00:17 | |
*** jamesmcarthur has quit IRC | 00:30 | |
*** ileixe has joined #openstack-keystone | 00:58 | |
*** awalende has joined #openstack-keystone | 01:31 | |
*** itlinux has joined #openstack-keystone | 01:34 | |
*** awalende has quit IRC | 01:36 | |
*** njohnston_ has quit IRC | 01:39 | |
*** jamesmcarthur has joined #openstack-keystone | 01:46 | |
*** jamesmcarthur has quit IRC | 02:03 | |
openstackgerrit | Merged openstack/keystoneauth master: Factor Adapter conf-processing logic into a helper https://review.openstack.org/644251 | 02:46 |
---|---|---|
*** mriedem has joined #openstack-keystone | 03:00 | |
mriedem | is this a known issue? http://logs.openstack.org/76/644576/1/gate/grenade-py3/e8d5a3b/logs/screen-keystone.txt.gz?level=TRACE#_Mar_22_01_10_29_138043 | 03:01 |
mriedem | ah nvm i know what this is | 03:03 |
mriedem | https://review.openstack.org/#/c/644638/ | 03:04 |
*** mriedem has left #openstack-keystone | 03:24 | |
*** whoami-rajat has joined #openstack-keystone | 03:41 | |
*** jamesmcarthur has joined #openstack-keystone | 03:51 | |
*** jamesmcarthur has quit IRC | 04:12 | |
*** ileixe has quit IRC | 04:18 | |
*** TheJulia has quit IRC | 04:31 | |
*** wxy-xiyuan has quit IRC | 04:31 | |
*** coreycb has quit IRC | 04:31 | |
*** wxy-xiyuan has joined #openstack-keystone | 04:31 | |
*** TheJulia has joined #openstack-keystone | 04:31 | |
*** dustinc has quit IRC | 04:31 | |
*** spsurya has quit IRC | 04:31 | |
*** awestin1 has quit IRC | 04:32 | |
*** cosss_ has quit IRC | 04:32 | |
*** kmalloc has quit IRC | 04:32 | |
*** hogepodge has quit IRC | 04:32 | |
*** johnsom has quit IRC | 04:32 | |
*** ayoung has quit IRC | 04:33 | |
*** erus has quit IRC | 04:33 | |
*** erus has joined #openstack-keystone | 04:34 | |
*** coreycb has joined #openstack-keystone | 04:34 | |
*** spsurya has joined #openstack-keystone | 04:34 | |
*** johnsom has joined #openstack-keystone | 04:34 | |
*** awestin1 has joined #openstack-keystone | 04:35 | |
*** hogepodge has joined #openstack-keystone | 04:35 | |
*** dustinc has joined #openstack-keystone | 04:39 | |
*** kmalloc has joined #openstack-keystone | 04:39 | |
*** erus has quit IRC | 04:39 | |
*** cosss_ has joined #openstack-keystone | 04:40 | |
*** erus has joined #openstack-keystone | 04:40 | |
*** jamesmcarthur has joined #openstack-keystone | 04:52 | |
*** erus has quit IRC | 04:52 | |
*** erus has joined #openstack-keystone | 04:52 | |
*** jamesmcarthur has quit IRC | 04:57 | |
openstackgerrit | Merged openstack/keystone master: Update system grant policies for system reader https://review.openstack.org/622615 | 04:58 |
*** ileixe has joined #openstack-keystone | 05:03 | |
*** jdennis has quit IRC | 05:45 | |
*** jdennis has joined #openstack-keystone | 05:48 | |
*** dustinc has quit IRC | 05:50 | |
*** tkajinam has quit IRC | 05:59 | |
*** tkajinam has joined #openstack-keystone | 05:59 | |
*** david-lyle has joined #openstack-keystone | 06:27 | |
*** dklyle has quit IRC | 06:27 | |
*** david-lyle has quit IRC | 06:29 | |
*** dklyle has joined #openstack-keystone | 06:29 | |
*** dims has quit IRC | 06:39 | |
*** dims has joined #openstack-keystone | 06:41 | |
*** rcernin has quit IRC | 07:07 | |
*** whoami-rajat has quit IRC | 07:11 | |
*** pcaruana has joined #openstack-keystone | 07:27 | |
*** whoami-rajat has joined #openstack-keystone | 07:30 | |
*** phasespace has quit IRC | 07:35 | |
*** xek_ has joined #openstack-keystone | 08:08 | |
*** markvoelker has joined #openstack-keystone | 08:12 | |
*** cfey has joined #openstack-keystone | 08:26 | |
*** phasespace has joined #openstack-keystone | 08:27 | |
*** tkajinam has quit IRC | 08:34 | |
*** erus has quit IRC | 08:34 | |
*** erus has joined #openstack-keystone | 08:35 | |
*** shyamb has joined #openstack-keystone | 09:09 | |
*** shyamb has quit IRC | 09:27 | |
*** shyamb has joined #openstack-keystone | 09:27 | |
*** shyamb has quit IRC | 09:39 | |
*** shyamb has joined #openstack-keystone | 10:08 | |
*** cosss_ has quit IRC | 10:59 | |
*** johnsom has quit IRC | 10:59 | |
*** erus has quit IRC | 10:59 | |
*** johnsom has joined #openstack-keystone | 10:59 | |
*** erus has joined #openstack-keystone | 10:59 | |
*** whoami-rajat has quit IRC | 10:59 | |
*** spsurya has quit IRC | 10:59 | |
*** awestin1 has quit IRC | 11:00 | |
*** cosss_ has joined #openstack-keystone | 11:00 | |
*** spsurya has joined #openstack-keystone | 11:01 | |
*** whoami-rajat has joined #openstack-keystone | 11:01 | |
*** awestin1 has joined #openstack-keystone | 11:02 | |
*** phasespace has quit IRC | 11:04 | |
*** ileixe has quit IRC | 11:21 | |
*** shyamb has quit IRC | 11:35 | |
*** shyamb has joined #openstack-keystone | 11:35 | |
*** shyamb has quit IRC | 11:50 | |
*** shyamb has joined #openstack-keystone | 11:51 | |
*** pcaruana has quit IRC | 11:53 | |
*** zbitter has joined #openstack-keystone | 12:05 | |
*** csatari_ has joined #openstack-keystone | 12:07 | |
*** erus has quit IRC | 12:07 | |
*** erus has joined #openstack-keystone | 12:07 | |
*** markvoelker has quit IRC | 12:10 | |
*** ab-a has quit IRC | 12:14 | |
*** zaneb has quit IRC | 12:14 | |
*** csatari has quit IRC | 12:14 | |
*** johnthetubaguy has quit IRC | 12:14 | |
*** csatari_ is now known as csatari | 12:14 | |
*** johnthetubaguy has joined #openstack-keystone | 12:15 | |
*** raildo has joined #openstack-keystone | 12:33 | |
*** pcaruana has joined #openstack-keystone | 12:54 | |
*** altlogbot_3 has quit IRC | 13:01 | |
*** irclogbot_3 has quit IRC | 13:01 | |
*** altlogbot_1 has joined #openstack-keystone | 13:02 | |
*** irclogbot_3 has joined #openstack-keystone | 13:02 | |
*** dklyle has quit IRC | 13:07 | |
*** lbragstad has joined #openstack-keystone | 13:10 | |
*** ChanServ sets mode: +o lbragstad | 13:10 | |
*** shyamb has quit IRC | 13:12 | |
*** dklyle has joined #openstack-keystone | 13:12 | |
*** jmlowe has quit IRC | 13:18 | |
*** lbragstad is now known as elbragstad | 13:19 | |
*** zbitter is now known as zaneb | 13:31 | |
*** efried is now known as fried_rice | 13:58 | |
*** bnemec is now known as beekneemech | 13:59 | |
*** jaosorior has quit IRC | 14:01 | |
*** jmlowe has joined #openstack-keystone | 14:15 | |
*** shyamb has joined #openstack-keystone | 14:18 | |
gagehugo | o/ | 14:34 |
*** erus has quit IRC | 14:34 | |
*** erus has joined #openstack-keystone | 14:35 | |
*** mloza has quit IRC | 14:43 | |
*** shyamb has quit IRC | 14:56 | |
*** jamesmcarthur has joined #openstack-keystone | 15:12 | |
*** altlogbot_1 has quit IRC | 15:21 | |
*** altlogbot_2 has joined #openstack-keystone | 15:25 | |
*** irclogbot_3 has quit IRC | 15:30 | |
*** irclogbot_0 has joined #openstack-keystone | 15:32 | |
*** irclogbot_0 has quit IRC | 15:36 | |
*** irclogbot_1 has joined #openstack-keystone | 15:37 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Remove external-dev and consolidate to contributor https://review.openstack.org/645640 | 15:54 |
*** dustinc has joined #openstack-keystone | 16:08 | |
*** fried_rice is now known as fried_rolls | 16:30 | |
kmalloc | hm. | 16:37 |
kmalloc | so. | 16:37 |
kmalloc | i'll put a separate patch up for oslo.cache that monkey patches the memcache client. | 16:37 |
kmalloc | i *think* i can do it | 16:37 |
*** jamesmcarthur has quit IRC | 17:05 | |
*** stewie925 has joined #openstack-keystone | 17:20 | |
stewie925 | hello guys | 17:20 |
stewie925 | I created a domain called 'local', and created a user 'admin-local' under that 'local' domain and logged back in as 'admin-local' .... | 17:21 |
stewie925 | when i do 'openstack user list' I was expecting to see only admin-local' but i still see users under the 'default' domain | 17:22 |
*** jamesmcarthur has joined #openstack-keystone | 17:22 | |
stewie925 | for my admin-local, my openrc has 'OS_USER_DOMAIN_NAME=local' | 17:23 |
*** jamesmcarthur has quit IRC | 17:27 | |
*** jamesmcarthur has joined #openstack-keystone | 17:34 | |
*** gmann is now known as gmann_afk | 17:52 | |
*** stewie925 has quit IRC | 18:06 | |
*** gmann_afk is now known as gmann | 18:11 | |
openstackgerrit | Merged openstack/keystone master: Implement domain admin functionality for user API https://review.openstack.org/623321 | 18:16 |
*** xek_ has quit IRC | 18:17 | |
*** jamesmcarthur has quit IRC | 18:19 | |
*** jamesmcarthur has joined #openstack-keystone | 18:20 | |
*** jamesmcarthur has quit IRC | 18:24 | |
*** pcaruana has quit IRC | 18:45 | |
*** fried_rolls is now known as fried_rice | 19:07 | |
*** phasespace has joined #openstack-keystone | 19:23 | |
*** jmlowe has quit IRC | 19:40 | |
elbragstad | quick question for the room on the grant API wrt system-scope and default roles | 19:45 |
*** erus has quit IRC | 19:45 | |
elbragstad | we currently require system-administrator (or rule:admin_required) in order for a user to create grants | 19:45 |
*** erus has joined #openstack-keystone | 19:45 | |
elbragstad | with domain-scope, should we open up the grant API, and if so, how much should we open up to those users? | 19:46 |
elbragstad | i mean - users can have role assignments on projects in domains outside of their own domain | 19:47 |
elbragstad | so - if a domain admin wants to manage role assignments within their domain, should they only be able to grant users *within* their domain access to projects *within* their domain? | 19:47 |
cmurphy | elbragstad: i think so | 19:55 |
elbragstad | ok | 19:55 |
elbragstad | to be clear, we don't want to expose that same functionality to project users, right? | 19:56 |
cmurphy | i wouldn't think so | 19:57 |
*** erus has quit IRC | 19:57 | |
cmurphy | you mean project admins? | 19:57 |
elbragstad | just like domain users shouldn't be able to grant other users roles on the domain? | 19:57 |
elbragstad | right | 19:57 |
*** erus has joined #openstack-keystone | 19:58 | |
cmurphy | i think a project admin only has any rights over their own project and since projects can't own users or other projects it wouldn't make sense to allow that there | 19:58 |
elbragstad | what about hmt? | 19:58 |
cmurphy | oh hm | 19:58 |
elbragstad | i'm fine punting that part for now... | 19:59 |
cmurphy | but they still don't have read access to users so i don't think they should assign roles for them | 19:59 |
elbragstad | ok - that's fair | 19:59 |
cmurphy | otoh i could see it being useful | 19:59 |
elbragstad | so - we should keep a "one layer up" mentality it sounds like | 19:59 |
elbragstad | system users can do all the things with grants, because they are operating on the system | 19:59 |
elbragstad | domain users can manage grants for users and project *within* the domain, but that's it.. which works because users and projects need a domain container | 20:00 |
elbragstad | project users are sol as far as grants go (from a self-service perspective) | 20:00 |
elbragstad | and that is mainly because users aren't contained with projects in any way, shape, or form, despite projects muddying the water with HMT | 20:01 |
elbragstad | does that all sound kosher? | 20:01 |
cmurphy | thinking about it from an abuse perspective, i wouldn't want some user out there adding me to projects that i don't know about | 20:01 |
cmurphy | then a bunch of projects show up for me in horizon | 20:02 |
elbragstad | right | 20:02 |
cmurphy | that user would have basically edited my user when they had no rights | 20:02 |
elbragstad | to clarify, you're referencing the project admin, right? | 20:02 |
cmurphy | so yeah agree with everything you said | 20:02 |
cmurphy | right | 20:02 |
elbragstad | ok - cool | 20:02 |
*** cfey has quit IRC | 20:08 | |
*** jmlowe has joined #openstack-keystone | 20:20 | |
*** raildo has quit IRC | 21:12 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system reader functionality for grants https://review.openstack.org/645889 | 21:26 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Make system admin policies consistent for grants https://review.openstack.org/645890 | 21:26 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Make system admin policies consistent for grants https://review.openstack.org/645890 | 21:28 |
*** mchlumsky has quit IRC | 21:30 | |
*** whoami-rajat has quit IRC | 22:41 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!