*** gyee has quit IRC | 00:09 | |
*** lbragstad has joined #openstack-keystone | 00:55 | |
*** ChanServ sets mode: +o lbragstad | 00:55 | |
*** jamesmcarthur has quit IRC | 01:09 | |
*** whoami-rajat has joined #openstack-keystone | 02:37 | |
*** lbragstad has quit IRC | 03:51 | |
*** markvoelker has quit IRC | 04:31 | |
*** vishakha has joined #openstack-keystone | 05:43 | |
*** ileixe has quit IRC | 06:01 | |
*** ileixe has joined #openstack-keystone | 06:05 | |
*** pcaruana has joined #openstack-keystone | 06:30 | |
*** markvoelker has joined #openstack-keystone | 06:32 | |
*** markvoelker has quit IRC | 07:06 | |
*** phasespace has quit IRC | 07:08 | |
*** awalende has joined #openstack-keystone | 07:13 | |
*** chrome0 has quit IRC | 07:14 | |
*** ileixe has quit IRC | 07:32 | |
*** ileixe has joined #openstack-keystone | 07:35 | |
*** ileixe has quit IRC | 07:35 | |
*** jonher_ has joined #openstack-keystone | 07:57 | |
*** jonher has quit IRC | 07:58 | |
*** frickler has quit IRC | 07:58 | |
*** jonher_ is now known as jonher | 07:58 | |
*** frickler has joined #openstack-keystone | 07:59 | |
*** rcernin has quit IRC | 08:01 | |
*** markvoelker has joined #openstack-keystone | 08:03 | |
*** ileixe has joined #openstack-keystone | 08:05 | |
*** phasespace has joined #openstack-keystone | 08:08 | |
*** johanssone has quit IRC | 08:18 | |
*** johanssone has joined #openstack-keystone | 08:24 | |
*** markvoelker has quit IRC | 08:36 | |
*** tkajinam has quit IRC | 08:43 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Update the min version of tox https://review.openstack.org/651144 | 09:03 |
---|---|---|
*** jaosorior has quit IRC | 09:24 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystonemiddleware master: Update the min version of tox https://review.openstack.org/651147 | 09:27 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystoneauth master: Update the min version of tox https://review.openstack.org/651149 | 09:30 |
*** jaosorior has joined #openstack-keystone | 09:31 | |
openstackgerrit | Vishakha Agarwal proposed openstack/python-keystoneclient master: Update the min version of tox https://review.openstack.org/651152 | 09:33 |
openstackgerrit | Vishakha Agarwal proposed openstack/ldappool master: Update the min version of tox https://review.openstack.org/651169 | 09:41 |
openstackgerrit | Vishakha Agarwal proposed openstack/pycadf master: Update the min version of tox https://review.openstack.org/651173 | 09:44 |
openstackgerrit | Vishakha Agarwal proposed openstack/oslo.limit master: Update the min version of tox https://review.openstack.org/651176 | 09:50 |
*** gary_perkins_ has quit IRC | 10:11 | |
*** gary_perkins has joined #openstack-keystone | 10:11 | |
openstackgerrit | Stephen Finucane proposed openstack/oslo.policy master: Follow the new PTI for document build https://review.openstack.org/549088 | 10:27 |
openstackgerrit | Stephen Finucane proposed openstack/oslo.policy master: Follow the new PTI for document build https://review.openstack.org/549088 | 10:33 |
*** markvoelker has joined #openstack-keystone | 10:33 | |
*** markvoelker has quit IRC | 11:07 | |
*** mvkr has joined #openstack-keystone | 11:30 | |
*** jmlowe has quit IRC | 12:01 | |
*** jmlowe has joined #openstack-keystone | 12:03 | |
*** jamesmcarthur has joined #openstack-keystone | 12:17 | |
*** jamesmcarthur has quit IRC | 12:34 | |
*** starborn has joined #openstack-keystone | 12:35 | |
*** openstackgerrit has quit IRC | 12:44 | |
*** lbragstad has joined #openstack-keystone | 12:49 | |
*** ChanServ sets mode: +o lbragstad | 12:49 | |
*** jamesmcarthur has joined #openstack-keystone | 12:50 | |
*** jroll has quit IRC | 12:55 | |
*** jroll has joined #openstack-keystone | 12:59 | |
*** mchlumsky has joined #openstack-keystone | 13:00 | |
*** jamesmcarthur has quit IRC | 13:04 | |
*** raildo has joined #openstack-keystone | 13:12 | |
knikolla | o/ | 13:43 |
*** phasespace has quit IRC | 13:48 | |
*** awalende has quit IRC | 13:58 | |
*** awalende has joined #openstack-keystone | 13:59 | |
*** awalende has quit IRC | 14:03 | |
gagehugo | o/ | 14:15 |
*** raildo has quit IRC | 14:22 | |
*** raildo has joined #openstack-keystone | 14:22 | |
cmurphy | o/ | 14:43 |
*** jamesmcarthur has joined #openstack-keystone | 14:47 | |
*** jistr is now known as jistr|call | 14:51 | |
*** lbragstad has quit IRC | 14:56 | |
*** lbragstad has joined #openstack-keystone | 14:56 | |
*** ChanServ sets mode: +o lbragstad | 14:56 | |
cmurphy | anyone want to volunteer topics for the meeting agenda? https://etherpad.openstack.org/p/keystone-weekly-meeting I don't have much for today | 15:14 |
* lbragstad doesn't have anything | 15:18 | |
* gagehugo doesn't have anything either | 15:18 | |
*** awalende has joined #openstack-keystone | 15:33 | |
*** wxy| has joined #openstack-keystone | 15:35 | |
*** gyee has joined #openstack-keystone | 15:35 | |
*** awalende has quit IRC | 15:37 | |
*** erus has joined #openstack-keystone | 15:39 | |
*** dave-mccowan has joined #openstack-keystone | 15:40 | |
*** jamesmcarthur has quit IRC | 15:42 | |
* vishakha got some reviews | 15:43 | |
*** openstackgerrit has joined #openstack-keystone | 15:54 | |
openstackgerrit | Merged openstack/keystone master: Convert user_id back to string https://review.openstack.org/650615 | 15:54 |
*** jistr|call is now known as jistr | 16:00 | |
cmurphy | meeting now in #openstack-meeting-alt | 16:01 |
*** jamesmcarthur has joined #openstack-keystone | 16:05 | |
cmurphy | (if anyone is looking for us there, we ended the meeting early) | 16:16 |
*** jamesmcarthur has quit IRC | 16:23 | |
ayoung | cmurphy, gah | 16:24 |
ayoung | I just realized. Anything to discuss? | 16:24 |
*** phasespace has joined #openstack-keystone | 16:25 | |
cmurphy | ayoung: i didn't have anything | 16:25 |
ayoung | cmurphy, cool. I wanted to point a couple things at you | 16:25 |
ayoung | I repuprosed one of my specs from rbac in middleware to app creds | 16:26 |
ayoung | https://review.openstack.org/#/c/456974/ and I saw you and Lance responded. | 16:27 |
ayoung | Is that a hard "bad idea" or a "we are not sure?" from you two? | 16:28 |
cmurphy | for me it's I'm not sure, I don't like the idea of keystonemiddleware inspecting the contents of a request, especially since this seems like it's just special-casing one of nova's APIs | 16:29 |
openstackgerrit | ayoung proposed openstack/keystone master: Allow an explicit_domain_id parameter when creating a domain https://review.openstack.org/605235 | 16:30 |
cmurphy | I could be convinced if we find some generic way to do it | 16:30 |
lbragstad | i know that nova is planning on doing a bunch of policy work in train, so i'd be curious to see if the current problems are mitigated slightly after they start consuming what we've already done | 16:30 |
cmurphy | but I don't think we can really predict all the ways that a service is going to want to enforce policy, that's why we have it in a consumable oslo library instead of doing it all keystone side | 16:31 |
ayoung | cmurphy, so my comparison other is the JSON RPC format we used in FreeIPA, where the method was inside the posted request body | 16:32 |
ayoung | JSON or YAML would work the same way. I could see making it work for HTML form posting, too | 16:32 |
ayoung | It would not cover all cases, but I think it would be a generally useful way to implement policy. | 16:33 |
ayoung | Not that I see us putting IPA behind Keystone.... | 16:33 |
cmurphy | ayoung: have a link i could look at for how it's done in freeipa? | 16:34 |
ayoung | lets see... | 16:34 |
cmurphy | ayoung: if nova got rid of this problematic API, would you still want to implement this? | 16:35 |
*** erus has quit IRC | 16:35 | |
ayoung | https://adam.younglogic.com/2010/07/talking-to-freeipa-json-web-api-via-curl/ but that does not show payload | 16:35 |
*** erus has joined #openstack-keystone | 16:36 | |
*** wxy| has quit IRC | 16:37 | |
* lbragstad is curious if microversions actually allow nova to fix that API | 16:37 | |
lbragstad | but gmann or melwitt might know | 16:37 |
ayoung | cmurphy, I can get some pasted....there is a demo IPA server | 16:38 |
cmurphy | my complaint with microversions has always been that you can't just drop old microversions right away so you're still stuck with the old api for ages | 16:38 |
lbragstad | i want to saw i remember there being constrains on some of the API changes you could make with microversions | 16:39 |
lbragstad | say* | 16:39 |
cmurphy | hmm i don't know what those are | 16:39 |
lbragstad | i'm not sure if rev'ing the path itself is possible | 16:39 |
cmurphy | app cred access rules don't take microversions into account at all | 16:40 |
lbragstad | should they? | 16:40 |
cmurphy | yeah probably | 16:40 |
cmurphy | right now someone could allow GET /foobar but maybe that means something different for microversion 1.1 vs 1.35 | 16:40 |
cmurphy | probably something to bring up at the forum session | 16:41 |
lbragstad | ++ | 16:42 |
lbragstad | i just made a note | 16:42 |
lbragstad | https://etherpad.openstack.org/p/keystone-train-ptg | 16:42 |
cmurphy | ty | 16:42 |
lbragstad | do you have an etherpad for that specific topic, yet? | 16:42 |
ayoung | cmurphy, http://paste.openstack.org/show/749062/ is one example | 16:42 |
cmurphy | ayoung: there will be a forum session on app creds where we can talk to other teams about the body key check | 16:42 |
gmann | lbragstad: cmurphy you mean for overall policy improvement things or any particular API in problem ? | 16:42 |
ayoung | the method is user_mod, which is roughly comparable to the URL+VERB. | 16:42 |
cmurphy | lbragstad: no i haven't made etherpads for forum sessions yet | 16:42 |
cmurphy | it's on my list for today | 16:42 |
lbragstad | gmann can nova use microversions to get rid of the actions API? | 16:43 |
lbragstad | (where the action is actually in the request body) | 16:43 |
cmurphy | ayoung: "manager" is like a role? | 16:43 |
lbragstad | cmurphy sweet - thanks | 16:43 |
gmann | we can introduce the alternate new API with microversion but cannot get rid of current action API due to what cmurphy mentioned. for older version they stay till min version is bump which seems almost not possible | 16:44 |
*** erus has quit IRC | 16:44 | |
*** erus has joined #openstack-keystone | 16:45 | |
*** jamesmcarthur has joined #openstack-keystone | 16:45 | |
lbragstad | ok | 16:45 |
erus | o/ | 16:46 |
*** gmann is now known as gmann_afk | 17:40 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystone-specs master: Renewable Application Credentials https://review.openstack.org/604201 | 17:54 |
knikolla | reproposed ^^ for train | 17:54 |
cmurphy | \o/ | 17:55 |
*** erus has quit IRC | 17:57 | |
*** erus has joined #openstack-keystone | 17:58 | |
openstackgerrit | Merged openstack/keystoneauth master: Update the min version of tox https://review.openstack.org/651149 | 18:05 |
*** erus has quit IRC | 18:20 | |
*** gmann_afk is now known as gmann | 18:21 | |
*** erus has joined #openstack-keystone | 18:21 | |
cmurphy | lbragstad: i created etherpads for ops feedback and app creds and added them to https://etherpad.openstack.org/p/DEN-keystone-forum-sessions , i'll email jimmy/speakersupport to see if we can get them added to the schedule abstract | 18:37 |
cmurphy | lbragstad: you're moderating the other two sessions, can you do the etherpad creation for those? | 18:38 |
*** adriant has quit IRC | 18:38 | |
lbragstad | yeah - melwitt and i were going to tag team those | 18:38 |
cmurphy | cool | 18:39 |
lbragstad | cmurphy done | 18:50 |
lbragstad | https://etherpad.openstack.org/p/DEN-unified-limits and https://etherpad.openstack.org/p/DEN-granular-policy-and-default-roles | 18:50 |
lbragstad | i'll work on fleshing them out a bit more | 18:50 |
lbragstad | i know melwitt has things to add to that, too | 18:51 |
cmurphy | sweet | 18:52 |
*** vishakha has quit IRC | 18:55 | |
*** jamesmcarthur has quit IRC | 18:55 | |
melwitt | lbragstad: thanks for starting those! | 19:00 |
lbragstad | no problem - feel free to add whatever you'd like | 19:01 |
melwitt | k | 19:01 |
lbragstad | i'm just brain-dumping right now | 19:01 |
melwitt | it's a good way to start IMHO | 19:04 |
*** whoami-rajat has quit IRC | 19:17 | |
* cmurphy schedules team photo for thursday afternoon | 19:18 | |
*** jamesmcarthur has joined #openstack-keystone | 19:21 | |
openstackgerrit | Merged openstack/ldappool master: Update the min version of tox https://review.openstack.org/651169 | 19:21 |
openstackgerrit | Raildo Mascena proposed openstack/keystone master: Fixing dn_to_id function for cases were id is not in the DN https://review.openstack.org/649177 | 19:44 |
*** starborn has quit IRC | 20:03 | |
*** jamesmcarthur has quit IRC | 20:17 | |
*** jamesmcarthur has joined #openstack-keystone | 20:18 | |
*** aning_ has quit IRC | 20:19 | |
*** erus has quit IRC | 20:19 | |
*** erus has joined #openstack-keystone | 20:20 | |
*** aning has joined #openstack-keystone | 20:21 | |
*** pcaruana has quit IRC | 20:31 | |
*** pcaruana has joined #openstack-keystone | 20:33 | |
*** pcaruana has quit IRC | 20:36 | |
*** pcaruana has joined #openstack-keystone | 20:39 | |
*** erus has quit IRC | 20:39 | |
*** erus has joined #openstack-keystone | 20:39 | |
*** jamesmcarthur has quit IRC | 20:44 | |
*** jamesmcarthur has joined #openstack-keystone | 20:45 | |
*** pcaruana has quit IRC | 20:47 | |
openstackgerrit | Merged openstack/oslo.limit master: Update the min version of tox https://review.openstack.org/651176 | 20:54 |
*** jamesmcarthur has quit IRC | 21:11 | |
openstackgerrit | Merged openstack/python-keystoneclient master: Update the min version of tox https://review.openstack.org/651152 | 21:17 |
openstackgerrit | Merged openstack/keystone master: Update the min version of tox https://review.openstack.org/651144 | 21:20 |
openstackgerrit | Merged openstack/keystonemiddleware master: Update the min version of tox https://review.openstack.org/651147 | 21:25 |
*** erus has quit IRC | 21:31 | |
*** erus has joined #openstack-keystone | 21:31 | |
*** mchlumsky has quit IRC | 21:44 | |
*** awalende has joined #openstack-keystone | 22:00 | |
*** erus has quit IRC | 22:02 | |
*** jamesmcarthur has joined #openstack-keystone | 22:03 | |
*** awalende has quit IRC | 22:04 | |
*** thomasmckay has joined #openstack-keystone | 22:11 | |
thomasmckay | looking for a keystone python client dev/expert that i could email intro to another (non-irc using) dev. we are having an issue with integration in quay | 22:12 |
thomasmckay | feel free to email me at redhat.com (email same as nick) | 22:13 |
openstackgerrit | Sean McGinnis proposed openstack/keystonemiddleware master: Fix string format error https://review.openstack.org/651399 | 22:17 |
thomasmckay | "we're trying to determine if there are any users in a project, but when we connect using the admin credentials, we get various errors about incorrect project domain. When we set it to `default`, we get that the service catalog is empty." | 22:21 |
thomasmckay | is the tl;dr from coworker | 22:21 |
mordred | hi thomasmckay - are you using python-keystoneclient or openstacksdk? also - feel free to email me at redhat (also email same as nick) - and it might not be terrible to loop in kmalloc (mfainber) | 22:25 |
mordred | but also- smart people will likely say smarter things here in response to the above - so we can figure out how to loop in your colleague as needed | 22:25 |
*** rcernin has joined #openstack-keystone | 22:28 | |
openstackgerrit | Merged openstack/keystone master: Allow an explicit_domain_id parameter when creating a domain https://review.openstack.org/605235 | 22:36 |
*** erus has joined #openstack-keystone | 22:42 | |
*** jamesmcarthur has quit IRC | 22:42 | |
kmalloc | ++ i'll check email in a bit and maybe can help. | 22:51 |
*** jamesmcarthur has joined #openstack-keystone | 22:52 | |
*** tkajinam has joined #openstack-keystone | 22:53 | |
kmalloc | even on PTO i can toss some brain at the thing :) | 22:53 |
*** jamesmcarthur has quit IRC | 23:03 | |
*** raildo has quit IRC | 23:05 | |
*** jamesmcarthur has joined #openstack-keystone | 23:06 | |
*** prometheanfire has joined #openstack-keystone | 23:10 | |
prometheanfire | https://review.openstack.org/650505 werkzug incompat (new thing) | 23:11 |
prometheanfire | master, not stein | 23:11 |
prometheanfire | not sure if I should hold it back or another quick fix can be done | 23:13 |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone master: Fixing dn_to_id function for cases where id is not in the DN https://review.openstack.org/649177 | 23:13 |
*** jamesmcarthur has quit IRC | 23:14 | |
cmurphy | prometheanfire: this broke our lower constraints job a few weeks ago too, we punted on fixing it properly at the time but i think it's a relatively easy fix | 23:16 |
cmurphy | will look later tonight | 23:17 |
*** jamesmcarthur has joined #openstack-keystone | 23:30 | |
*** jamesmcarthur has quit IRC | 23:30 | |
hogepodge | Has anyone experienced performance issues with recent builds? Using uwsgi I'm getting 503 errors on light loads | 23:33 |
hogepodge | I'll revert to stable Rocky and see if I'm getting the same issues, but I can't even populate the service catalog and users serially without 503 errors. This is fairly new with builds from master | 23:38 |
prometheanfire | cmurphy: ok, I'll hold it back this time then | 23:51 |
*** dklyle has quit IRC | 23:52 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!