*** ganso has quit IRC | 00:08 | |
*** ganso has joined #openstack-keystone | 00:08 | |
*** jamesmcarthur has joined #openstack-keystone | 00:52 | |
*** jamesmcarthur has quit IRC | 00:54 | |
*** jamesmcarthur has joined #openstack-keystone | 00:58 | |
*** zbitter is now known as zaneb | 01:00 | |
*** hoonetorg has quit IRC | 01:01 | |
eandersson | btw for predictable ids and keystone | 01:01 |
---|---|---|
eandersson | How about just letting users choose the uuid when creating resources? | 01:02 |
eandersson | > openstack project create my_project --uuid <my-uuid> | 01:03 |
*** markvoelker has joined #openstack-keystone | 01:13 | |
*** jamesmcarthur has quit IRC | 01:14 | |
*** hoonetorg has joined #openstack-keystone | 01:15 | |
*** whoami-rajat has joined #openstack-keystone | 01:16 | |
*** jamesmcarthur_ has joined #openstack-keystone | 01:18 | |
*** zaneb has quit IRC | 01:25 | |
*** mvkr has quit IRC | 01:32 | |
*** jamesmcarthur_ has quit IRC | 01:34 | |
kmalloc | eandersson: there are a lot of reasons to not do that, most of them revolve around predictability and squatting on IDs that are convienent. | 01:40 |
kmalloc | eandersson: it is generally better if keystone can control the generation based upon data provided and something ekystone controls | 01:41 |
kmalloc | eandersson: also, in a federated environment, you can create (with the right access) data that could provide an escalation/access to resources unintended. | 01:42 |
kmalloc | the inclusion of data owned by keystone at least limits the scope. | 01:42 |
kmalloc | if we allow for --uuid in your example we would need to SHA it with the domain_id. we could include a "user-supplied-seed" that is used in future replication/autoprovisioning in remote environments (and default to using the name if no seed is provided) | 01:43 |
kmalloc | in short, we can't do user supplied without potential issue(s) down the line. | 01:44 |
eandersson | Interesting | 01:44 |
openstackgerrit | Colleen Murphy proposed openstack/keystone-specs master: Add role implication note to basic-default-roles https://review.opendev.org/575144 | 01:46 |
*** jamesmcarthur has joined #openstack-keystone | 02:05 | |
*** jamesmcarthur has quit IRC | 02:12 | |
*** gmann_afk is now known as gmann | 02:16 | |
*** jamesmcarthur has joined #openstack-keystone | 02:18 | |
*** mvkr has joined #openstack-keystone | 02:21 | |
*** vishakha has joined #openstack-keystone | 02:27 | |
*** ileixe has quit IRC | 02:50 | |
*** ileixe has joined #openstack-keystone | 02:53 | |
*** ileixe has quit IRC | 02:53 | |
vishakha | o/ | 02:58 |
*** lbragstad has quit IRC | 03:08 | |
*** ileixe has joined #openstack-keystone | 03:22 | |
*** whoami-rajat has quit IRC | 03:35 | |
*** erus has joined #openstack-keystone | 03:43 | |
openstackgerrit | zhongshengping proposed openstack/keystone master: Replace git.openstack.org URLs with opendev.org URLs https://review.opendev.org/654296 | 03:51 |
*** whoami-rajat has joined #openstack-keystone | 04:06 | |
*** jamesmcarthur has quit IRC | 04:17 | |
*** jamesmcarthur has joined #openstack-keystone | 04:18 | |
*** jamesmcarthur has quit IRC | 04:23 | |
*** ileixe has quit IRC | 04:28 | |
*** jamesmcarthur has joined #openstack-keystone | 04:29 | |
*** ileixe has joined #openstack-keystone | 04:31 | |
*** jamesmcarthur has quit IRC | 04:45 | |
*** jamesmcarthur has joined #openstack-keystone | 04:45 | |
*** jamesmcarthur has quit IRC | 04:50 | |
*** jamesmcarthur has joined #openstack-keystone | 04:50 | |
*** jamesmcarthur has quit IRC | 04:54 | |
*** erus has quit IRC | 04:57 | |
*** sapd1_ has quit IRC | 05:03 | |
*** jamesmcarthur has joined #openstack-keystone | 05:06 | |
*** ileixe has quit IRC | 05:06 | |
*** ileixe has joined #openstack-keystone | 05:09 | |
*** markvoelker has quit IRC | 05:10 | |
*** jamesmcarthur has quit IRC | 05:11 | |
*** sapd1 has joined #openstack-keystone | 05:14 | |
*** jamesmcarthur has joined #openstack-keystone | 05:17 | |
*** jamesmcarthur has quit IRC | 05:22 | |
*** shyamb has joined #openstack-keystone | 05:23 | |
*** jamesmcarthur has joined #openstack-keystone | 05:25 | |
*** sapd1 has quit IRC | 05:29 | |
*** jamesmcarthur has quit IRC | 05:32 | |
*** sapd1 has joined #openstack-keystone | 05:37 | |
*** mvkr has quit IRC | 05:40 | |
*** sapd1 has quit IRC | 05:42 | |
*** mvkr has joined #openstack-keystone | 05:53 | |
*** shyamb has quit IRC | 05:56 | |
*** sapd1 has joined #openstack-keystone | 05:59 | |
*** ileixe has quit IRC | 06:01 | |
*** shyamb has joined #openstack-keystone | 06:01 | |
*** shyamb has quit IRC | 06:03 | |
*** jamesmcarthur has joined #openstack-keystone | 06:11 | |
*** ileixe has joined #openstack-keystone | 06:12 | |
*** jamesmcarthur has quit IRC | 06:15 | |
*** sapd1 has quit IRC | 06:21 | |
*** d34dh0r53 has quit IRC | 06:22 | |
*** cloudnull has quit IRC | 06:22 | |
*** eglute has quit IRC | 06:23 | |
*** pcaruana has joined #openstack-keystone | 06:24 | |
*** sapd1 has joined #openstack-keystone | 06:27 | |
*** ileixe has quit IRC | 06:58 | |
*** ileixe has joined #openstack-keystone | 07:00 | |
*** rcernin has quit IRC | 07:05 | |
*** markvoelker has joined #openstack-keystone | 07:12 | |
*** sapd1 has quit IRC | 07:13 | |
*** sapd1 has joined #openstack-keystone | 07:14 | |
*** phasespace has joined #openstack-keystone | 07:28 | |
openstackgerrit | caoyuan proposed openstack/keystone-tempest-plugin master: Replace git.openstack.org URLs with opendev.org URLs https://review.opendev.org/655018 | 07:36 |
*** yan0s has joined #openstack-keystone | 07:59 | |
yan0s | Hi, I am witnessing a weird behavior with application crdentials | 09:24 |
yan0s | I create an app cred with admin user with scope on project A | 09:25 |
yan0s | the app cred gets project-id of project A | 09:25 |
yan0s | I login via cli with this app cred and I am logged in the ADMIN project... | 09:26 |
*** d34dh0r53 has joined #openstack-keystone | 09:45 | |
*** cloudnull has joined #openstack-keystone | 09:47 | |
*** eglute has joined #openstack-keystone | 09:47 | |
yan0s | false alarm | 09:49 |
yan0s | I still get a weird behavior though | 09:50 |
yan0s | I can list all projects owned by the user that created the app cred | 09:50 |
*** tkajinam has quit IRC | 09:52 | |
*** awestin1 has quit IRC | 09:54 | |
*** pas-ha has quit IRC | 09:54 | |
*** gmann has quit IRC | 09:54 | |
*** pas-ha has joined #openstack-keystone | 09:54 | |
*** awestin1_ has joined #openstack-keystone | 09:54 | |
*** rm_work has quit IRC | 09:55 | |
*** gmann has joined #openstack-keystone | 09:56 | |
*** rm_work has joined #openstack-keystone | 10:06 | |
*** raildo has joined #openstack-keystone | 10:21 | |
*** gmann has quit IRC | 10:44 | |
*** raildo has quit IRC | 10:58 | |
*** raildo has joined #openstack-keystone | 11:00 | |
openstackgerrit | jacky06 proposed openstack/python-keystoneclient master: Replace git.openstack.org URLs with opendev.org URLs https://review.opendev.org/654764 | 11:17 |
*** cloudnull has quit IRC | 11:36 | |
*** cloudnull has joined #openstack-keystone | 11:37 | |
*** Emine has joined #openstack-keystone | 11:44 | |
*** markvoelker has quit IRC | 12:08 | |
*** markvoelker has joined #openstack-keystone | 12:08 | |
*** jamesmcarthur has joined #openstack-keystone | 12:10 | |
*** jamesmcarthur has quit IRC | 12:15 | |
*** jamesmcarthur has joined #openstack-keystone | 12:16 | |
*** jamesmcarthur has quit IRC | 12:32 | |
*** zaneb has joined #openstack-keystone | 12:36 | |
*** jamesmcarthur has joined #openstack-keystone | 12:44 | |
*** lbragstad has joined #openstack-keystone | 12:44 | |
*** ChanServ sets mode: +o lbragstad | 12:44 | |
yan0s | How can a user be considered as "admin" role in the Keystone policy context? | 12:49 |
yan0s | I mean I want a user (other than THE admin user) to be able to create a project | 12:50 |
yan0s | but roles can only be given to a user per project | 12:50 |
*** zaneb has quit IRC | 12:52 | |
*** irclogbot_3 has quit IRC | 12:55 | |
*** irclogbot_0 has joined #openstack-keystone | 12:55 | |
*** jistr is now known as jistr|afk | 12:56 | |
*** altlogbot_2 has quit IRC | 12:57 | |
*** altlogbot_0 has joined #openstack-keystone | 12:58 | |
lbragstad | cmurphy nice work on the restaurant choice - i'm cruising the menu and it looks awesome | 13:40 |
knikolla | o/ | 13:43 |
knikolla | yup, really nice place! | 13:45 |
*** gmann has joined #openstack-keystone | 13:52 | |
cmurphy | :) | 13:54 |
cmurphy | yan0s: by default only admins can create projects, you would have to change the create_project policy in /etc/keystone/policy.yaml to allow other users to do that | 13:56 |
yan0s | cmurphy: you mean user of role "admin" in a domain? | 13:58 |
*** jamesmcarthur has quit IRC | 14:00 | |
gagehugo | o/ | 14:00 |
*** jamesmcarthur has joined #openstack-keystone | 14:00 | |
cmurphy | yan0s: it's a little complicated because we're in a transition period, right now by default you can have role "admin" on any scope - project, domain, or system - and have all admin privileges including the ability to create projects. in the future the default will be locked down so that you specifically have to have the admin role on the system scope to create any project or on a domain to create | 14:02 |
cmurphy | projects within that domain | 14:02 |
*** phasespace has quit IRC | 14:26 | |
*** itlinux has quit IRC | 14:35 | |
yan0s | cmurphy: I think this is the condition in the policy that is failing: domain_id:%(domain_id)s" | 14:35 |
yan0s | cmurphy: What is actually compared here? | 14:35 |
yan0s | "admin_and_matching_domain_id": "rule:admin_required and domain_id:%(domain_id)s" | 14:36 |
cmurphy | yan0s: are you using the policy.v3cloudsample.json policy file? | 14:37 |
cmurphy | the domain_id check is looking for the domain the token is scoped to | 14:38 |
yan0s | yes | 14:38 |
yan0s | so the comparison is between the domain_id the token is scoped to and what? | 14:39 |
yan0s | the user domain id? | 14:39 |
lbragstad | the domain_id in the request if there is one | 14:40 |
lbragstad | for example GET /v3/domains/{domain_id} | 14:40 |
lbragstad | the domain_id from the path is compared to the domain_id in the token, if the token is domain-scoped | 14:40 |
*** erus has joined #openstack-keystone | 14:41 | |
*** yan0s has quit IRC | 14:46 | |
*** jamesmcarthur has quit IRC | 14:48 | |
*** pcaruana has quit IRC | 15:06 | |
*** imdigitaljim has joined #openstack-keystone | 15:07 | |
*** jamesmcarthur has joined #openstack-keystone | 15:07 | |
*** efried has joined #openstack-keystone | 15:08 | |
efried | cmurphy: Can I get a PTL ack on https://review.opendev.org/#/c/653888/ please? | 15:09 |
cmurphy | efried: sure, i didn't think the proposal bot needed ptl affirmation though? | 15:13 |
efried | cmurphy: turns out you're right, I wasn't sure, thanks for the look. | 15:14 |
cmurphy | np | 15:15 |
*** itlinux has joined #openstack-keystone | 15:28 | |
*** raildo_ has joined #openstack-keystone | 15:35 | |
*** raildo has quit IRC | 15:35 | |
*** itlinux has quit IRC | 15:41 | |
*** pcaruana has joined #openstack-keystone | 15:46 | |
kmalloc | o/ | 15:51 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Add yaml-loaded filesystem catalog backend https://review.opendev.org/483514 | 15:54 |
*** itlinux has joined #openstack-keystone | 15:56 | |
bnemec | https://image.slidesharecdn.com/presentation-160623224549/95/kubernetes-101-31-638.jpg?cb=1466722045 | 15:58 |
*** efried is now known as efried_rollin | 16:04 | |
*** altlogbot_0 has quit IRC | 16:09 | |
*** altlogbot_1 has joined #openstack-keystone | 16:12 | |
*** ybunker has joined #openstack-keystone | 16:31 | |
*** itlinux has quit IRC | 16:33 | |
kmalloc | bnemec: yeah, a number of folks still use the templated catalog. the current templated catalog is a trainwreck, yaml at least lets us make it comparable to the DB catalog. | 16:37 |
kmalloc | in functionality (minus the API create/update/delete) | 16:37 |
*** itlinux has joined #openstack-keystone | 16:37 | |
bnemec | kmalloc: I mostly just have a weakness for that meme. :-) | 16:39 |
bnemec | In my defense, I've spent a _lot_ of time staring at Heat/Ansible/Mistral/etc. YAML over the years. | 16:39 |
cmurphy | i'm so sorry for you | 16:40 |
kmalloc | ^^ what cmurphy said. | 16:42 |
bnemec | Appropriate: https://cdn3.whatculture.com/images/2015/05/1XvDIu6y.gif | 16:43 |
*** altlogbot_1 has quit IRC | 16:43 | |
bnemec | Now I get to go stare at Powerpoint slides for a few hours. | 16:43 |
* bnemec wonders what he did to deserve this | 16:43 | |
*** gyee has joined #openstack-keystone | 16:44 | |
*** altlogbot_0 has joined #openstack-keystone | 16:44 | |
*** itlinux has quit IRC | 16:44 | |
*** itlinux has joined #openstack-keystone | 16:50 | |
*** altlogbot_0 has quit IRC | 16:53 | |
*** altlogbot_1 has joined #openstack-keystone | 16:54 | |
*** itlinux has quit IRC | 16:56 | |
kmalloc | bnemec: you work in tech, apparently this is a requirement :P | 17:05 |
bnemec | At least they haven't made me a manager, so I only have to do this every six months. ;-) | 17:07 |
* bnemec belatedly knocks on wood | 17:08 | |
*** itlinux has joined #openstack-keystone | 17:10 | |
*** jamesmcarthur_ has joined #openstack-keystone | 17:13 | |
*** jamesmcarthur has quit IRC | 17:15 | |
*** erus has quit IRC | 17:15 | |
*** erus has joined #openstack-keystone | 17:16 | |
*** markvoelker has quit IRC | 17:21 | |
*** markvoelker has joined #openstack-keystone | 17:22 | |
*** markvoelker has quit IRC | 17:26 | |
*** phasespace has joined #openstack-keystone | 17:30 | |
*** markvoelker has joined #openstack-keystone | 17:37 | |
*** jamesmcarthur_ has quit IRC | 18:08 | |
*** vishakha has quit IRC | 18:13 | |
*** jamesmcarthur has joined #openstack-keystone | 18:19 | |
*** itlinux has quit IRC | 18:50 | |
*** itlinux has joined #openstack-keystone | 18:52 | |
*** itlinux has quit IRC | 18:54 | |
*** openstackgerrit has quit IRC | 18:57 | |
*** itlinux has joined #openstack-keystone | 18:58 | |
*** itlinux has quit IRC | 19:11 | |
*** ybunker has quit IRC | 19:17 | |
*** erus has quit IRC | 19:17 | |
*** erus has joined #openstack-keystone | 19:18 | |
*** itlinux has joined #openstack-keystone | 19:33 | |
*** dave-mccowan has joined #openstack-keystone | 19:56 | |
*** efried_rollin is now known as efried | 20:14 | |
*** pcaruana has quit IRC | 20:39 | |
*** itlinux has quit IRC | 21:16 | |
*** itlinux has joined #openstack-keystone | 21:22 | |
*** itlinux has quit IRC | 21:24 | |
*** whoami-rajat has quit IRC | 21:25 | |
*** itlinux has joined #openstack-keystone | 21:28 | |
*** zaneb has joined #openstack-keystone | 21:35 | |
*** itlinux has quit IRC | 21:41 | |
*** itlinux has joined #openstack-keystone | 21:49 | |
gmann | lbragstad: cmurphy I am keeping system scope testing on Friday 9.30-10.00 - https://ethercalc.openstack.org/Train-PTG-QA-Schedule | 21:54 |
gmann | let me know if it is fine otherwise we can change that slot. | 21:55 |
gmann | you want to discuss this in keystone room or QA ? QA has shared room with infra team, so keystone room might be good ? | 21:56 |
lbragstad | ummm | 21:59 |
lbragstad | i'm looking at https://etherpad.openstack.org/p/keystone-train-ptg | 21:59 |
lbragstad | it looks like system-scope and unified limits are still on the schedule for friday morning, but iirc i thought that was moved to friday afternoon | 21:59 |
lbragstad | per our discussion with efried | 22:00 |
lbragstad | if that's the case, then we probably have availability on friday morning in the keystone room, but i'll have cmurphy confirm to make sure i'm not missing something | 22:00 |
gmann | yeah that is at 15.15 - https://etherpad.openstack.org/p/nova-ptg-train | 22:00 |
efried | I've got Friday 1515-1615: Keystone XPROJ: https://etherpad.openstack.org/p/ptg-train-xproj-nova-keystone | 22:01 |
cmurphy | gmann: i thought we agreed to talk about tempest testing on Thursday morning | 22:01 |
cmurphy | then system scope with nova on friday afternoon | 22:01 |
*** imacdonn has quit IRC | 22:01 | |
gmann | cmurphy: ohk Thursday morning also ok, 10.40 ok for that ? | 22:02 |
*** imacdonn has joined #openstack-keystone | 22:02 | |
cmurphy | gmann: 10:40 should be okay for that, it will have to be in the QA room since keystone doesn't have a room till the afternoon | 22:02 |
*** itlinux has quit IRC | 22:03 | |
cmurphy | lbragstad: we agreed keystone/nova meet friday afternoon but i didn't move the original sessions for those items for internal keystone discussion, i could move them to right before or after nova team meeting if that makes more sense | 22:04 |
gmann | cmurphy: noted. update in schedule. thanks - https://ethercalc.openstack.org/Train-PTG-QA-Schedule | 22:04 |
gmann | for tempest testing. | 22:04 |
cmurphy | thanks gmann | 22:05 |
*** raildo_ has quit IRC | 22:08 | |
*** itlinux has joined #openstack-keystone | 22:09 | |
*** zaneb has quit IRC | 22:14 | |
*** itlinux has quit IRC | 22:15 | |
*** itlinux has joined #openstack-keystone | 22:25 | |
*** tkajinam has joined #openstack-keystone | 22:53 | |
*** rcernin has joined #openstack-keystone | 22:54 | |
*** mvkr has quit IRC | 23:12 | |
*** mchlumsky has quit IRC | 23:23 | |
*** itlinux has quit IRC | 23:33 | |
*** itlinux has joined #openstack-keystone | 23:37 | |
*** itlinux has quit IRC | 23:50 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!