| *** jamesmcarthur has joined #openstack-keystone | 00:03 | |
| *** jamesmcarthur has quit IRC | 00:08 | |
| *** jamesmcarthur has joined #openstack-keystone | 00:12 | |
| *** jamesmcarthur has quit IRC | 00:16 | |
| *** ayoung has joined #openstack-keystone | 00:37 | |
| *** markvoelker has joined #openstack-keystone | 00:42 | |
| *** markvoelker has quit IRC | 00:44 | |
| *** markvoelker has joined #openstack-keystone | 00:45 | |
| *** whoami-rajat has joined #openstack-keystone | 01:19 | |
| *** irclogbot_1 has quit IRC | 01:44 | |
| *** edmondsw_ has quit IRC | 01:48 | |
| *** jamesmcarthur has joined #openstack-keystone | 01:50 | |
| *** Dinesh_Bhor has joined #openstack-keystone | 01:57 | |
| *** ileixe has joined #openstack-keystone | 02:53 | |
| *** Nel1x has quit IRC | 03:02 | |
| *** jamesmcarthur has quit IRC | 03:03 | |
| *** Nel1x has joined #openstack-keystone | 03:21 | |
| *** shyamb has joined #openstack-keystone | 04:05 | |
| *** Nel1x has quit IRC | 04:10 | |
| *** pcaruana has joined #openstack-keystone | 04:49 | |
| *** pcaruana has quit IRC | 04:55 | |
| *** shyamb has quit IRC | 04:56 | |
| *** jamesmcarthur has joined #openstack-keystone | 05:05 | |
| *** jamesmcarthur has quit IRC | 05:06 | |
| *** jamesmcarthur has joined #openstack-keystone | 05:06 | |
| *** jamesmcarthur has quit IRC | 05:10 | |
| *** shyamb has joined #openstack-keystone | 05:15 | |
| *** mkrai has joined #openstack-keystone | 05:34 | |
| mkrai | Hi, while setting up devstack I get this error http://paste.openstack.org/show/748981/ | 05:35 |
|---|---|---|
| mkrai | I checked that auth | 05:35 |
| mkrai | I checked that auth_url is correctly set in environment variable | 05:35 |
| *** phasespace has quit IRC | 06:01 | |
| *** jaosorior has joined #openstack-keystone | 06:05 | |
| *** pcaruana has joined #openstack-keystone | 06:30 | |
| openstackgerrit | Colleen Murphy proposed openstack/keystone master: Convert user_id back to string https://review.openstack.org/650615 | 06:31 |
| *** markvoelker has quit IRC | 06:43 | |
| *** awalende has joined #openstack-keystone | 07:10 | |
| *** shyamb has quit IRC | 07:19 | |
| *** awalende has quit IRC | 07:19 | |
| *** shyamb has joined #openstack-keystone | 07:19 | |
| *** phasespace has joined #openstack-keystone | 07:19 | |
| *** awalende has joined #openstack-keystone | 07:20 | |
| *** awalende has quit IRC | 07:24 | |
| *** awalende has joined #openstack-keystone | 07:24 | |
| *** awalende has quit IRC | 07:39 | |
| *** awalende has joined #openstack-keystone | 07:42 | |
| *** tkajinam has quit IRC | 08:11 | |
| *** rcernin has quit IRC | 08:19 | |
| *** mkrai has quit IRC | 08:38 | |
| *** markvoelker has joined #openstack-keystone | 08:45 | |
| *** zigo_ has joined #openstack-keystone | 08:45 | |
| *** zigo_ is now known as zigo | 08:50 | |
| *** tobberydberg has quit IRC | 09:12 | |
| *** markvoelker has quit IRC | 09:18 | |
| *** tobberydberg has joined #openstack-keystone | 09:25 | |
| *** shyamb has quit IRC | 09:35 | |
| *** markvoelker has joined #openstack-keystone | 10:16 | |
| *** markvoelker has quit IRC | 10:49 | |
| *** markvoelker has joined #openstack-keystone | 11:15 | |
| *** mvkr has quit IRC | 11:34 | |
| *** pcaruana has quit IRC | 11:47 | |
| *** edmondsw has joined #openstack-keystone | 12:04 | |
| *** raildo has joined #openstack-keystone | 12:04 | |
| *** jamesmcarthur has joined #openstack-keystone | 12:17 | |
| *** mvkr has joined #openstack-keystone | 12:29 | |
| *** jamesmcarthur has quit IRC | 12:30 | |
| *** mchlumsky has joined #openstack-keystone | 12:37 | |
| *** pcaruana has joined #openstack-keystone | 12:38 | |
| *** mchlumsky has quit IRC | 12:41 | |
| *** mchlumsky has joined #openstack-keystone | 12:42 | |
| *** jamesmcarthur has joined #openstack-keystone | 12:48 | |
| *** needssleep is now known as TheJulia | 12:49 | |
| *** jroll has quit IRC | 12:50 | |
| *** jroll has joined #openstack-keystone | 12:50 | |
| *** awalende has quit IRC | 12:59 | |
| *** awalende has joined #openstack-keystone | 12:59 | |
| *** ab-a has joined #openstack-keystone | 13:03 | |
| *** awalende has quit IRC | 13:04 | |
| knikolla | o/ | 13:07 |
| *** lbragstad has joined #openstack-keystone | 13:08 | |
| *** ChanServ sets mode: +o lbragstad | 13:08 | |
| openstackgerrit | Colleen Murphy proposed openstack/keystone master: Convert user_id back to string https://review.openstack.org/650615 | 13:10 |
| *** cmorpheus is now known as cmurphy | 13:11 | |
| *** whoami-rajat has quit IRC | 13:28 | |
| *** pcaruana has quit IRC | 13:31 | |
| *** pcaruana has joined #openstack-keystone | 13:36 | |
| *** whoami-rajat has joined #openstack-keystone | 13:38 | |
| *** jmlowe has quit IRC | 13:52 | |
| *** phasespace has quit IRC | 14:02 | |
| gagehugo | o/ | 14:24 |
| lbragstad | o/ | 14:26 |
| *** spotz has joined #openstack-keystone | 14:27 | |
| *** jmlowe has joined #openstack-keystone | 14:28 | |
| cmurphy | \o | 14:31 |
| *** mchlumsky has quit IRC | 14:43 | |
| *** mchlumsky has joined #openstack-keystone | 14:46 | |
| *** lbragstad has quit IRC | 14:46 | |
| *** lbragstad has joined #openstack-keystone | 14:47 | |
| *** ChanServ sets mode: +o lbragstad | 14:47 | |
| *** phasespace has joined #openstack-keystone | 15:16 | |
| *** gyee has joined #openstack-keystone | 15:20 | |
| *** itlinux_ has quit IRC | 15:33 | |
| *** itlinux has joined #openstack-keystone | 16:28 | |
| ayoung | kmalloc, got a customer interested in using mariadb async replication from a central keystone to remotes. All installs done via TripleO. THought? | 17:26 |
| kmalloc | Hmmmm | 17:26 |
| ayoung | As I can see it, there problem points are going to be the data installed into the remote sites during install | 17:27 |
| kmalloc | If it is not bi-directional replication (not master/master with the remotes) it is probably ok. | 17:27 |
| ayoung | I think all service catalogs are region 1 | 17:27 |
| ayoung | and the nova etc users will have distinct passwords | 17:27 |
| ayoung | but all be in the same database | 17:27 |
| ayoung | I think you can sync paswords, though, | 17:28 |
| kmalloc | You can. But conflicts because we key on name for unique in some cases could be hard. | 17:28 |
| ayoung | they would have different userids, but I think all the config files only have usernames | 17:28 |
| kmalloc | If it is multi-master | 17:28 |
| ayoung | I wonder if they could install the lower clusters, shut them down, run the sync, update the config files, and bring it back up? | 17:29 |
| kmalloc | Probably | 17:29 |
| ayoung | I don't think OOO supports service users in LDAP | 17:42 |
| ayoung | let me check. | 17:42 |
| ayoung | I think the installer puts services users in the default domain | 17:42 |
| *** jamesmcarthur_ has joined #openstack-keystone | 17:46 | |
| *** jamesmcarthur has quit IRC | 17:49 | |
| *** itlinux has quit IRC | 18:19 | |
| *** johnsom has quit IRC | 18:20 | |
| *** johnsom has joined #openstack-keystone | 18:21 | |
| *** BlackDex has quit IRC | 18:22 | |
| *** BlackDex has joined #openstack-keystone | 18:22 | |
| ayoung | kmalloc, I told them not to do it. Upgrades | 18:41 |
| kmalloc | ah | 18:41 |
| ayoung | It really is something we need to work on with the TripleO team | 18:41 |
| ayoung | or maybe edge? | 18:42 |
| openstackgerrit | Raildo Mascena proposed openstack/keystone master: [WIP]Fixing dn_to_id function for cases were id it's not in the DN https://review.openstack.org/649177 | 18:48 |
| *** mvkr has quit IRC | 18:51 | |
| *** jmlowe has quit IRC | 18:56 | |
| *** eandersson_ is now known as eandersson | 18:57 | |
| *** jamesmcarthur_ has quit IRC | 19:04 | |
| cmurphy | lbragstad: kmalloc need stable reviews for this stein boilerplate | https://review.openstack.org/#/q/status:open+(project:openstack/keystone+OR+project:openstack/keystoneauth+OR+project:openstack/keystonemiddleware)+branch:stable/stein │ | 19:11 |
| kmalloc | done | 19:13 |
| * kmalloc goes back to PTO. | 19:13 | |
| * lbragstad goes back to tinkering with ansible | 19:14 | |
| lbragstad | unrelated: i wish i would have found this *years* ago https://docs.ansible.com/ansible/latest/modules/github_key_module.html | 19:14 |
| eandersson | A silly question but local_users has a primary key and auto increment for id. | 19:32 |
| eandersson | Would it be possible to change this id to a uuid? | 19:32 |
| eandersson | auto increment makes async replication difficult :p | 19:33 |
| *** jamesmcarthur has joined #openstack-keystone | 19:34 | |
| *** jamesmcarthur_ has joined #openstack-keystone | 19:35 | |
| *** jamesmcarthur has quit IRC | 19:39 | |
| kmalloc | eandersson: uuid is a terrible PK | 19:39 |
| eandersson | sure - but auto increment and primary key is not great either for replication | 19:40 |
| eandersson | not sure what the better alternative is | 19:40 |
| kmalloc | autoinc | 19:40 |
| kmalloc | you can set a skip value, so node 1 does, 1, 3, 5 etc | 19:40 |
| kmalloc | and node 2 does 2,4,6 | 19:40 |
| eandersson | assuming you can do that | 19:41 |
| kmalloc | uuids are terrible for PK indexing in most mysql cases. And internal PKs should not be exposed, especially if it's a FK to another table | 19:41 |
| kmalloc | async multimaster is also a terrible idea with an application like keystone | 19:42 |
| kmalloc | this is just my opinion though. | 19:43 |
| kmalloc | honestly, i'd rather see all the PKs in keystone move to autoinc. | 19:44 |
| kmalloc | to be consistent | 19:44 |
| eandersson | I just want to offer a good experience to our customers | 19:44 |
| kmalloc | what are you trying to solve exactly? a 100% shared keystone across many micro sites? | 19:45 |
| eandersson | and unfortunately my expertise within databases, and database replications is limited | 19:45 |
| openstackgerrit | Colleen Murphy proposed openstack/keystone master: Convert user_id back to string https://review.openstack.org/650615 | 19:45 |
| eandersson | pretty much | 19:45 |
| * kmalloc is going to get yelled at by his better half for doing "work". | 19:45 | |
| eandersson | I mean we have had this running for many years | 19:45 |
| kmalloc | well not yelled at...just a stern glare | 19:45 |
| kmalloc | :P | 19:45 |
| *** jamesmcarthur_ has quit IRC | 19:45 | |
| eandersson | and it works great in general, but as some applications started generating local users | 19:46 |
| kmalloc | is it because you need domains/projects/user_ids to be consistent or are you using tokens from one environment in anotheR? | 19:46 |
| eandersson | it started causing issues | 19:46 |
| eandersson | as most of our users are backed by ldap | 19:46 |
| *** ceryx has joined #openstack-keystone | 19:46 | |
| eandersson | domains/projects + tokens | 19:46 |
| eandersson | is what we care about | 19:46 |
| eandersson | to be available in all other regions | 19:46 |
| eandersson | available + consistent | 19:46 |
| kmalloc | so, the general way i'd do that is central management with read-only remote replicas. | 19:47 |
| eandersson | tokens are easy of course due to fernet | 19:47 |
| kmalloc | assuming your CRMS is managing user data to LDAP. | 19:47 |
| kmalloc | manage users/projects/domains centrally, then the remote sites could receive 100% of the replication | 19:47 |
| kmalloc | it can scale to probably ~20+ sites, though i think there are issues scaling this upwards of 100, even wtih async | 19:48 |
| eandersson | How would that even work? How do you move writes to one region, and all reads to local region? | 19:48 |
| eandersson | or do you proxy writes to a central region? | 19:49 |
| kmalloc | oslo.db should support read vs write connections | 19:49 |
| kmalloc | i *think* we have that in keystone | 19:49 |
| eandersson | Are you going to Denver kmalloc ? | 19:49 |
| kmalloc | nope | 19:49 |
| kmalloc | i wont be in denver | 19:49 |
| *** jmlowe has joined #openstack-keystone | 20:00 | |
| *** dave-mccowan has joined #openstack-keystone | 20:06 | |
| *** whoami-rajat has quit IRC | 20:08 | |
| openstackgerrit | Raildo Mascena proposed openstack/keystone master: [WIP]Fixing dn_to_id function for cases were id it's not in the DN https://review.openstack.org/649177 | 20:09 |
| *** jamesmcarthur has joined #openstack-keystone | 20:11 | |
| *** pcaruana has quit IRC | 20:25 | |
| *** whoami-rajat has joined #openstack-keystone | 21:45 | |
| *** mchlumsky has quit IRC | 21:52 | |
| *** rcernin has joined #openstack-keystone | 22:14 | |
| *** lbragstad has quit IRC | 22:14 | |
| *** raildo has quit IRC | 22:37 | |
| *** dave-mccowan has quit IRC | 22:58 | |
| *** tkajinam has joined #openstack-keystone | 23:00 | |
| *** jamesmcarthur has quit IRC | 23:22 | |
| *** jamesmcarthur has joined #openstack-keystone | 23:56 | |
| *** whoami-rajat has quit IRC | 23:58 | |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!