*** markvoelker has quit IRC | 00:00 | |
*** lbragstad has joined #openstack-keystone | 00:07 | |
*** ChanServ sets mode: +o lbragstad | 00:07 | |
cmurphy | kmalloc: do you think https://review.openstack.org/508619 is something we still need now that we have RBACEnforcer? | 01:17 |
---|---|---|
kmalloc | that is done with the Flask stack, RBACEnforcer, and @unauthenticated_api | 01:18 |
kmalloc | that can be abandoned as we already implemented it | 01:18 |
cmurphy | cool | 01:19 |
*** jamesmcarthur has joined #openstack-keystone | 01:37 | |
*** whoami-rajat has joined #openstack-keystone | 01:53 | |
*** jamesmcarthur has quit IRC | 02:08 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Use openstackdocstheme according to guide https://review.openstack.org/556704 | 02:13 |
*** lbragstad has quit IRC | 02:21 | |
*** nicolasbock has quit IRC | 02:29 | |
*** jamesmcarthur has joined #openstack-keystone | 02:39 | |
*** jamesmcarthur has quit IRC | 02:46 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Use openstackdocstheme according to guide https://review.openstack.org/556704 | 02:48 |
*** lbragstad has joined #openstack-keystone | 03:00 | |
*** ChanServ sets mode: +o lbragstad | 03:00 | |
*** jamesmcarthur has joined #openstack-keystone | 03:02 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Replace support matrix ext with common library https://review.openstack.org/527808 | 03:11 |
*** jamesmcarthur has quit IRC | 03:39 | |
*** jamesmcarthur has joined #openstack-keystone | 03:40 | |
*** erus has joined #openstack-keystone | 03:44 | |
*** jamesmcarthur has quit IRC | 03:45 | |
*** imacdonn has quit IRC | 04:06 | |
*** imacdonn has joined #openstack-keystone | 04:07 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Replace support matrix ext with common library https://review.openstack.org/527808 | 04:10 |
*** jamesmcarthur has joined #openstack-keystone | 04:11 | |
*** jamesmcarthur has quit IRC | 04:18 | |
*** erus has quit IRC | 04:46 | |
*** erus has joined #openstack-keystone | 04:52 | |
*** shyamb has joined #openstack-keystone | 05:03 | |
*** erus has quit IRC | 05:07 | |
*** gyee has quit IRC | 05:08 | |
*** shyamb has quit IRC | 05:09 | |
*** shyamb has joined #openstack-keystone | 05:13 | |
*** lbragstad has quit IRC | 05:55 | |
*** shyamb has quit IRC | 06:13 | |
*** awestin1 has quit IRC | 06:26 | |
*** pcaruana has joined #openstack-keystone | 06:26 | |
*** masayukig has quit IRC | 06:27 | |
*** kmalloc has quit IRC | 06:28 | |
*** TheJulia has quit IRC | 06:29 | |
*** kmalloc has joined #openstack-keystone | 06:30 | |
*** shyamb has joined #openstack-keystone | 06:32 | |
*** hogepodge has quit IRC | 06:32 | |
*** johnsom has quit IRC | 06:32 | |
*** kmalloc has quit IRC | 06:40 | |
*** TheJulia has joined #openstack-keystone | 06:43 | |
*** markvoelker has joined #openstack-keystone | 06:43 | |
*** TheJulia has quit IRC | 06:47 | |
*** TheJulia has joined #openstack-keystone | 06:52 | |
*** kmalloc has joined #openstack-keystone | 06:53 | |
*** johnsom has joined #openstack-keystone | 06:55 | |
*** masayukig has joined #openstack-keystone | 06:55 | |
*** ileixe has quit IRC | 06:56 | |
*** awestin1 has joined #openstack-keystone | 06:56 | |
*** hogepodge has joined #openstack-keystone | 06:56 | |
*** starborn has joined #openstack-keystone | 06:57 | |
*** ileixe has joined #openstack-keystone | 06:59 | |
*** awalende has joined #openstack-keystone | 07:08 | |
*** rcernin has quit IRC | 07:20 | |
*** shyamb has quit IRC | 07:30 | |
*** shyamb has joined #openstack-keystone | 07:37 | |
*** johnsom has quit IRC | 08:04 | |
*** johnsom has joined #openstack-keystone | 08:05 | |
*** masayukig_ has joined #openstack-keystone | 08:05 | |
*** masayukig has quit IRC | 08:05 | |
*** masayukig_ is now known as masayukig | 08:05 | |
*** awestin1 has quit IRC | 08:06 | |
*** awestin1 has joined #openstack-keystone | 08:06 | |
*** shyamb has quit IRC | 08:07 | |
*** phasespace has joined #openstack-keystone | 08:09 | |
openstackgerrit | Jens Harbott (frickler) proposed openstack/keystonemiddleware master: Add a new option to choose the Identity endpoint https://review.openstack.org/651790 | 08:17 |
*** tkajinam has quit IRC | 08:24 | |
*** shyamb has joined #openstack-keystone | 08:54 | |
*** shyamb has quit IRC | 09:34 | |
*** shyamb has joined #openstack-keystone | 09:52 | |
*** rcernin has joined #openstack-keystone | 10:02 | |
*** shyamb has quit IRC | 10:19 | |
*** shyamb has joined #openstack-keystone | 10:19 | |
*** vishakha has joined #openstack-keystone | 10:22 | |
*** raildo has joined #openstack-keystone | 10:41 | |
*** shyamb has quit IRC | 10:48 | |
*** nicolasbock has joined #openstack-keystone | 10:55 | |
*** shyamb has joined #openstack-keystone | 10:59 | |
*** pcaruana has quit IRC | 11:17 | |
*** Zara has joined #openstack-keystone | 11:21 | |
Zara | hi! I'm trying to debug a pike instance where tokens are taking around 0.4secs to POST; seems slow; not found any obvious cause; noticed that backend is set to: `oslo_cache.memcache_pool` which isn't listed in https://docs.openstack.org/keystone/pike/admin/identity-caching-layer.html . wondering if could be related or generally what to look for; am new to keystone. there's a cronjob to flush token | 11:29 |
Zara | s so I don't think it's that. | 11:29 |
Zara | (bit of a confused question, sorry. if anyone has any general keystone troubleshooting advice, I'd be grateful. :)) | 11:29 |
*** phasespace has quit IRC | 11:35 | |
*** pcaruana has joined #openstack-keystone | 12:04 | |
*** shyamb has quit IRC | 12:16 | |
*** jamesmcarthur has joined #openstack-keystone | 12:21 | |
*** jamesmcarthur has quit IRC | 12:30 | |
*** shyamb has joined #openstack-keystone | 12:37 | |
*** ybunker has joined #openstack-keystone | 12:39 | |
*** erus has joined #openstack-keystone | 12:47 | |
*** jamesmcarthur has joined #openstack-keystone | 12:48 | |
*** jamesmcarthur has quit IRC | 12:58 | |
*** shyamb has quit IRC | 13:02 | |
*** shyamb has joined #openstack-keystone | 13:03 | |
*** pcaruana has quit IRC | 13:07 | |
*** lbragstad has joined #openstack-keystone | 13:10 | |
*** ChanServ sets mode: +o lbragstad | 13:10 | |
*** jmlowe has quit IRC | 13:19 | |
*** pcaruana has joined #openstack-keystone | 13:33 | |
*** jmlowe has joined #openstack-keystone | 13:38 | |
*** erus has quit IRC | 13:46 | |
*** markvoelker has quit IRC | 14:07 | |
*** awalende has quit IRC | 14:17 | |
*** awalende has joined #openstack-keystone | 14:18 | |
*** awalende_ has joined #openstack-keystone | 14:21 | |
*** awalende has quit IRC | 14:22 | |
*** awalende_ has quit IRC | 14:25 | |
*** rcernin has quit IRC | 14:27 | |
hrybacki | Zara: do you have a specific question I could help with? | 14:45 |
*** dklyle has quit IRC | 14:49 | |
*** dklyle has joined #openstack-keystone | 14:50 | |
cmurphy | Zara: oslo_cache.memcache_pool should be a valid backend, assuming the memcache servers are up and running | 14:50 |
cmurphy | Zara: are you using uuid or fernet tokens? | 14:50 |
*** jamesmcarthur has joined #openstack-keystone | 14:56 | |
Zara | cmurphy: uuid | 14:59 |
Zara | hrybacki: heh, not yet; looks like cmurphy answered the more specific question buried in my ramble. :) | 15:01 |
hrybacki | Zara: ack | 15:02 |
hrybacki | Zara: so the configuration option you are looking for (in Pike) is here: https://docs.openstack.org/oslo.cache/pike/configuration/index.html | 15:02 |
*** erus has joined #openstack-keystone | 15:06 | |
*** starborn has quit IRC | 15:13 | |
cmurphy | Zara: how are you testing it? using curl /v3/auth/tokens or using openstackclient? for me the openstackclient takes 2.127s on devstack | 15:22 |
*** pcaruana has quit IRC | 15:27 | |
*** pcaruana has joined #openstack-keystone | 15:30 | |
*** pcaruana has quit IRC | 15:40 | |
*** pcaruana has joined #openstack-keystone | 15:46 | |
*** ayoung has joined #openstack-keystone | 15:48 | |
ayoung | I thought I had SASL set up, but I;ll double check | 15:48 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Replace support matrix ext with common library https://review.openstack.org/527808 | 15:48 |
*** gyee has joined #openstack-keystone | 15:50 | |
*** ayoung has quit IRC | 15:50 | |
*** ayoung has joined #openstack-keystone | 15:50 | |
ayoung | clarkb, thanks. I was still usin the password server, but ssl. Not SASL. THat is a big improvement | 15:51 |
vishakha | cmurphy: The latest url is not working in here https://review.openstack.org/#/c/652569/1/specs/keystone/rocky/strict-two-level-enforcement-model.rst? . Should I left this as it is? | 15:54 |
*** erus has quit IRC | 15:54 | |
*** erus has joined #openstack-keystone | 15:54 | |
cmurphy | vishakha: https://docs.openstack.org/keystone/latest/admin/unified-limits.html#flat doesn't work for you? | 15:55 |
*** pcaruana has quit IRC | 15:55 | |
cmurphy | the file changed names | 15:55 |
cmurphy | meeting in 4 minutes in #openstack-meeting-alt | 15:56 |
vishakha | oops got the issue | 15:57 |
vishakha | thanks | 15:57 |
cmurphy | np | 15:57 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone-specs master: NIT : Fix broken link https://review.openstack.org/652569 | 15:59 |
* kmalloc whines, BUT I NEED COFFEE FOR THE MEETING... *makes coffee* | 16:00 | |
cmurphy | :) | 16:00 |
*** pcaruana has joined #openstack-keystone | 16:02 | |
Zara | cmurphy: using the client, with things like `openstack token issue --timing`. | 16:02 |
*** jamesmcarthur has quit IRC | 16:04 | |
*** ybunker has quit IRC | 16:07 | |
*** pcaruana has quit IRC | 16:08 | |
*** erus has quit IRC | 16:08 | |
*** erus has joined #openstack-keystone | 16:08 | |
erus | o/ | 16:09 |
*** shyamb has quit IRC | 16:09 | |
*** jamesmcarthur has joined #openstack-keystone | 16:13 | |
eandersson | Would it be too crazy to make some uuids deterministic? e..g project_id? | 16:16 |
eandersson | We are looking at alternative to database replication | 16:16 |
eandersson | I understand that this wouldn't work in all, if even many deployments, but feel like it could be an option for environments that aren't changing very often. | 16:17 |
kmalloc | eandersson: ayoung has been working on that. | 16:20 |
*** erus has quit IRC | 16:20 | |
eandersson | Nice | 16:21 |
kmalloc | eandersson: but it's not uuids then. it's a sha of <data> and <domain_id> | 16:21 |
kmalloc | but same concept. | 16:21 |
eandersson | Yea exactly | 16:21 |
*** erus has joined #openstack-keystone | 16:21 | |
eandersson | I created a sha1 and used that to generate a uuid | 16:21 |
eandersson | and passed all tests :p | 16:21 |
kmalloc | uuid5 was another option, but we opted for something sha... 256 i think | 16:21 |
eandersson | > data = '%s_%s' % (ref['domain_id'], ref['name']) | 16:22 |
eandersson | > hash = sha1(data.encode('utf-8')).digest() | 16:22 |
eandersson | > ref['id'] = uuid.UUID(bytes=hash[0:16], version=4).hex | 16:22 |
eandersson | I was just doing something like that | 16:22 |
eandersson | Having no clue how to actually do deterministic uuids :p | 16:23 |
kmalloc | note that names *are* mutable | 16:23 |
eandersson | ah did not know that :p | 16:25 |
*** pcaruana has joined #openstack-keystone | 16:36 | |
kmalloc | eandersson: https://review.openstack.org/#/c/612099/ | 16:37 |
kmalloc | fyi | 16:37 |
eandersson | Nice + thanks for sharing | 16:38 |
*** ybunker has joined #openstack-keystone | 16:39 | |
*** erus has quit IRC | 16:39 | |
*** erus has joined #openstack-keystone | 16:39 | |
*** dtruong has quit IRC | 16:40 | |
*** problem_v has quit IRC | 16:40 | |
*** problem_v has joined #openstack-keystone | 16:41 | |
*** dtruong has joined #openstack-keystone | 16:41 | |
openstackgerrit | Merged openstack/keystone-specs master: Repropose unfinished Stein specs to Train https://review.openstack.org/650126 | 16:42 |
openstackgerrit | Merged openstack/keystone-specs master: NIT : Fix broken link https://review.openstack.org/652569 | 16:45 |
*** erus has quit IRC | 16:45 | |
*** erus has joined #openstack-keystone | 16:46 | |
*** jamesmcarthur_ has joined #openstack-keystone | 16:48 | |
*** jamesmcarthur has quit IRC | 16:52 | |
*** markvoelker has joined #openstack-keystone | 16:52 | |
*** markvoelker has quit IRC | 16:56 | |
kmalloc | cmurphy: I'm a slacker, I haven't had breakfast (breffas?) yet. | 16:57 |
*** itlinux has joined #openstack-keystone | 16:59 | |
lbragstad | cmurphy re: cleaning up old specifications and cruft | 17:00 |
lbragstad | http://specs.openstack.org/openstack/keystone-specs/specs/keystone/ongoing/python3.html looks obsolete now? | 17:01 |
cmurphy | lbragstad: lol python3.4 | 17:01 |
cmurphy | yeah looks like we did that | 17:01 |
cmurphy | i don't think we ended up needing those library changes | 17:02 |
lbragstad | looks pretty stale | 17:02 |
lbragstad | but we have 3.7 voting now, so that would have broken i think? | 17:02 |
vishakha | lbragstad: i was looking into some methods for public key distribution in jwt. Can we use a trustable third party instead which will be aware of all the public of all nodes instead of putting keys on the disk? | 17:03 |
cmurphy | lbragstad: yeah i think coreycb did a lot of work to get the ldap libs working with py3 so i think we're set now | 17:03 |
lbragstad | vishakha that's come up a few times in the past, but we've never committed to a solution | 17:03 |
cmurphy | lbragstad: want to propose moving that to implemented? | 17:03 |
lbragstad | for stein? | 17:04 |
cmurphy | i think so? | 17:04 |
lbragstad | sure | 17:04 |
cmurphy | i think it makes more sense to call it done than to say we're not gonna do it | 17:04 |
vishakha | lbragstad: can we add that as a ptg topic to discuss more over it | 17:05 |
cmurphy | btw a few more reviews to highlight https://review.openstack.org/652520 fixes federation ci again https://review.openstack.org/651430 let's requirements team bump werkzeug https://review.openstack.org/652112 followup for doc bugfix | 17:07 |
knikolla | o/ | 17:08 |
cmurphy | hi knikolla | 17:08 |
knikolla | hey cmurphy | 17:09 |
knikolla | just finished reading back on the meeting, sorry for missing it. | 17:10 |
cmurphy | no problem | 17:10 |
cmurphy | Zara: sorry was in a meeting, i would compare with plain curl, and also check if it is consistent for each token request or if it corrects itself after one or a few requests, and also is this sql or ldap users? | 17:12 |
lbragstad | wut in the world... | 17:34 |
lbragstad | cmurphy do you see python3.html in http://specs.openstack.org/openstack/keystone-specs/specs/keystone/ongoing/ ? | 17:35 |
lbragstad | that's not actually in that directory in master | 17:35 |
lbragstad | http://specs.openstack.org/openstack/keystone-specs/ shows the python3.4 stuff in newton | 17:37 |
cmurphy | lbragstad: oh, i think there's an issue with how specs are published and they don't get removed from the old directory when they're moved in git | 17:42 |
lbragstad | weird... | 17:42 |
cmurphy | yeah, if we figure out exactly which ones are stale i can ask the infra team to remove them | 17:42 |
lbragstad | idk how others do this | 17:43 |
lbragstad | but i usually just navigate from http://specs.openstack.org/openstack/keystone-specs/ | 17:43 |
cmurphy | yeah, it's just that whatever rsync options they use don't remove the old files and we always move ours around a lot | 17:44 |
* lbragstad nods | 17:44 | |
*** dklyle has quit IRC | 17:45 | |
bbobrov | wow, my 3-years-old patch went in | 18:10 |
cmurphy | :) | 18:15 |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: Report correct domain in federated user token https://review.openstack.org/653068 | 18:16 |
knikolla | that was easier than i thought | 18:17 |
openstackgerrit | Kristi Nikolla proposed openstack/keystone-specs master: Renewable Application Credentials https://review.openstack.org/604201 | 18:23 |
*** jamesmcarthur_ has quit IRC | 18:25 | |
*** jamesmcarthur has joined #openstack-keystone | 18:26 | |
*** jamesmcarthur has quit IRC | 18:35 | |
openstackgerrit | Ben Nemec proposed openstack/oslo.policy master: Follow the new PTI for document build https://review.openstack.org/549088 | 18:39 |
*** irclogbot_2 has quit IRC | 18:39 | |
*** jamesmcarthur has joined #openstack-keystone | 18:40 | |
*** irclogbot_0 has joined #openstack-keystone | 18:40 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: Report correct domain in federated user token https://review.openstack.org/653068 | 18:56 |
*** vishakha has quit IRC | 19:22 | |
*** itlinux has quit IRC | 19:30 | |
*** jmlowe has quit IRC | 19:33 | |
*** itlinux has joined #openstack-keystone | 19:34 | |
*** ybunker has quit IRC | 19:53 | |
*** dklyle has joined #openstack-keystone | 19:58 | |
*** jamesmcarthur has quit IRC | 20:00 | |
*** jmlowe has joined #openstack-keystone | 20:02 | |
*** pcaruana has quit IRC | 20:19 | |
*** jamesmcarthur has joined #openstack-keystone | 21:01 | |
*** raildo has quit IRC | 21:12 | |
*** mchlumsky_ has quit IRC | 21:23 | |
*** itlinux has quit IRC | 21:53 | |
*** itlinux has joined #openstack-keystone | 22:06 | |
openstackgerrit | Merged openstack/keystone master: Add release note for service token documentation https://review.openstack.org/652112 | 22:24 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Replace support matrix ext with common library https://review.openstack.org/527808 | 22:35 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Fix unscoped federated token formatter https://review.openstack.org/652520 | 22:35 |
*** rcernin has joined #openstack-keystone | 22:38 | |
*** tkajinam has joined #openstack-keystone | 22:54 | |
*** whoami-rajat has quit IRC | 23:02 | |
*** jamesmcarthur has quit IRC | 23:06 | |
*** jamesmcarthur has joined #openstack-keystone | 23:07 | |
*** jamesmcarthur has quit IRC | 23:11 | |
*** itlinux has quit IRC | 23:35 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!