*** jamesmcarthur has joined #openstack-keystone | 00:04 | |
*** jamesmcarthur has quit IRC | 00:35 | |
*** markvoelker has joined #openstack-keystone | 00:41 | |
*** markvoelker has quit IRC | 00:45 | |
*** jamesmcarthur has joined #openstack-keystone | 01:05 | |
*** jamesmcarthur_ has joined #openstack-keystone | 01:10 | |
*** jamesmcarthur has quit IRC | 01:11 | |
openstackgerrit | Merged openstack/keystonemiddleware master: Blacklist bandit 1.6.0 & cap sphinx for 2.7 https://review.opendev.org/659610 | 01:40 |
---|---|---|
*** whoami-rajat has joined #openstack-keystone | 02:00 | |
*** joshualyle has joined #openstack-keystone | 02:39 | |
*** dave-mccowan has quit IRC | 02:55 | |
*** tkajinam has quit IRC | 03:03 | |
*** tkajinam has joined #openstack-keystone | 03:04 | |
*** tkajinam has quit IRC | 03:20 | |
*** jamesmcarthur_ has quit IRC | 03:23 | |
*** tkajinam has joined #openstack-keystone | 03:28 | |
*** jamesmcarthur has joined #openstack-keystone | 03:54 | |
*** jamesmcarthur has quit IRC | 03:59 | |
*** vishakha has joined #openstack-keystone | 04:08 | |
*** itlinux has quit IRC | 04:46 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Remove [token]/ infer_roles https://review.opendev.org/659500 | 04:55 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Remove [token]/ infer_roles https://review.opendev.org/659500 | 04:59 |
*** jamesmcarthur has joined #openstack-keystone | 05:01 | |
*** pcaruana has joined #openstack-keystone | 05:02 | |
*** jamesmcarthur has quit IRC | 05:07 | |
*** vishalmanchanda has joined #openstack-keystone | 05:10 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Pep8 environment to run on delta code only https://review.opendev.org/659225 | 05:11 |
*** pcaruana has quit IRC | 05:11 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Remove [signing] config https://review.opendev.org/659434 | 05:26 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Remove [token]/ infer_roles https://review.opendev.org/659500 | 05:30 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Remove [signing] config https://review.opendev.org/659434 | 05:32 |
*** jistr is now known as jistr|mtg | 06:20 | |
*** jamesmcarthur has joined #openstack-keystone | 06:35 | |
*** markvoelker has joined #openstack-keystone | 06:36 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Remove [signing] config https://review.opendev.org/659434 | 06:37 |
*** jamesmcarthur has quit IRC | 06:39 | |
*** starborn has joined #openstack-keystone | 06:47 | |
*** trident has quit IRC | 07:03 | |
*** trident has joined #openstack-keystone | 07:05 | |
*** tesseract has joined #openstack-keystone | 07:06 | |
*** markvoelker has quit IRC | 07:09 | |
*** rcernin has quit IRC | 07:19 | |
*** pcaruana has joined #openstack-keystone | 07:21 | |
*** jamesmcarthur has joined #openstack-keystone | 07:25 | |
*** jamesmcarthur has quit IRC | 07:30 | |
*** pcaruana has quit IRC | 07:39 | |
*** markvoelker has joined #openstack-keystone | 08:06 | |
*** tkajinam has quit IRC | 08:12 | |
*** xek has joined #openstack-keystone | 08:36 | |
*** xek has quit IRC | 08:38 | |
*** markvoelker has quit IRC | 08:39 | |
*** jistr|mtg is now known as jistr | 08:46 | |
*** xek has joined #openstack-keystone | 08:48 | |
*** awalende has joined #openstack-keystone | 09:05 | |
*** openstackstatus has quit IRC | 09:13 | |
*** openstackstatus has joined #openstack-keystone | 09:14 | |
*** ChanServ sets mode: +v openstackstatus | 09:14 | |
*** yan0s has joined #openstack-keystone | 09:15 | |
*** jamesmcarthur has joined #openstack-keystone | 09:26 | |
*** jamesmcarthur has quit IRC | 09:31 | |
*** markvoelker has joined #openstack-keystone | 09:35 | |
*** markvoelker has quit IRC | 10:09 | |
*** ileixe has quit IRC | 10:46 | |
*** awalende has quit IRC | 10:58 | |
*** awalende has joined #openstack-keystone | 10:59 | |
*** markvoelker has joined #openstack-keystone | 11:06 | |
*** ccstone has quit IRC | 11:22 | |
*** schaney_ has quit IRC | 11:22 | |
*** schaney_ has joined #openstack-keystone | 11:23 | |
*** jamesmcarthur has joined #openstack-keystone | 11:27 | |
*** dave-mccowan has joined #openstack-keystone | 11:28 | |
*** jamesmcarthur has quit IRC | 11:33 | |
*** markvoelker has quit IRC | 11:39 | |
*** joshualyle has quit IRC | 11:40 | |
*** jamesmcarthur has joined #openstack-keystone | 11:43 | |
*** awalende has quit IRC | 11:44 | |
*** awalende has joined #openstack-keystone | 11:45 | |
*** thirose has quit IRC | 11:48 | |
*** awalende has quit IRC | 11:52 | |
*** awalende has joined #openstack-keystone | 11:54 | |
*** raildo has joined #openstack-keystone | 11:54 | |
*** jamesmcarthur has quit IRC | 11:55 | |
*** jamesmcarthur has joined #openstack-keystone | 12:00 | |
*** markvoelker has joined #openstack-keystone | 12:08 | |
*** jamesmcarthur has quit IRC | 12:16 | |
*** jamesmcarthur has joined #openstack-keystone | 12:16 | |
*** jamesmcarthur has quit IRC | 12:32 | |
*** jamesmcarthur has joined #openstack-keystone | 12:42 | |
erolg | Hi everyone, I want to ask something. I saw that there is a default roles like reader, member and admin. They were implemented in Rocky release according to this spec: https://specs.openstack.org/openstack/keystone-specs/specs/keystone/rocky/define-default-roles.html | 12:42 |
erolg | But when I try reader or observer role. There is no diffrence with member role. I can create and delete resources via horizon | 12:43 |
erolg | Then I checked nova and neutron policy files I couldnt find any permission mapped to the reader or observer role . (I generated policy samples via oslopolicy) | 12:46 |
erolg | Other projects weren't implement these roles yet. Am I right? | 12:49 |
*** jamesmcarthur has quit IRC | 13:39 | |
*** itlinux has joined #openstack-keystone | 13:42 | |
*** vishakha has quit IRC | 13:44 | |
*** bbobrov has quit IRC | 13:47 | |
*** jamesmcarthur has joined #openstack-keystone | 13:48 | |
*** erolg has quit IRC | 13:53 | |
*** schaney__ has joined #openstack-keystone | 13:56 | |
*** jamesmcarthur_ has joined #openstack-keystone | 13:59 | |
*** gary_perkins_ has joined #openstack-keystone | 14:00 | |
*** lifeless_ has joined #openstack-keystone | 14:01 | |
*** Anticime1 has joined #openstack-keystone | 14:01 | |
*** schaney_ has quit IRC | 14:06 | |
*** lifeless has quit IRC | 14:06 | |
knikolla | cmurphy: for the new expiring users, do you think the TTL should be on the domain or the idp? if we push it to the domain, that could potentially work for non-federated users as well. (ex ldap) | 14:06 |
*** jamesmcarthur has quit IRC | 14:06 | |
*** markvoelker has quit IRC | 14:06 | |
*** johnthetubaguy has quit IRC | 14:06 | |
*** gary_perkins has quit IRC | 14:06 | |
*** Anticimex has quit IRC | 14:06 | |
*** edmondsw_ has quit IRC | 14:06 | |
*** problem_v has quit IRC | 14:06 | |
*** dtruong has quit IRC | 14:06 | |
*** awalende has quit IRC | 14:07 | |
*** problem_v has joined #openstack-keystone | 14:07 | |
knikolla | where by ttl, i mean the default setting for users of that domain/idp. | 14:07 |
*** dtruong has joined #openstack-keystone | 14:08 | |
*** awalende has joined #openstack-keystone | 14:11 | |
*** itlinux has quit IRC | 14:13 | |
*** awalende has quit IRC | 14:15 | |
*** erolg has joined #openstack-keystone | 14:45 | |
cmurphy | erolg: that's correct, the roles exist in keystone but we haven't coordinated updating the policies across all the services yet | 14:51 |
cmurphy | knikolla: hmm, do we want it to work for non-federated users? | 14:51 |
cmurphy | knikolla: is there ever a case where a user in an idp could map to more than one domain? | 14:51 |
knikolla | cmurphy: AFAIK, all users from an idp map to the same domain, but there could be multiple idps sharing a domain. | 14:52 |
cmurphy | knikolla: i think we'd still want it on the idp then | 14:54 |
knikolla | cmurphy: alright, cool. | 14:54 |
erolg | cmurphy, Do you know which services already update their policy for reader role? | 14:54 |
cmurphy | erolg: only keystone | 14:56 |
erolg | cmurphy, thanks a lot :) | 14:56 |
*** yan0s has quit IRC | 15:13 | |
*** awalende has joined #openstack-keystone | 15:15 | |
*** awalende has quit IRC | 15:19 | |
*** starborn has quit IRC | 15:20 | |
*** vishakha has joined #openstack-keystone | 15:53 | |
cmurphy | keystone team meeting in 4 minutes in #openstack-meeting-alt | 15:56 |
vishakha | o/ | 16:01 |
vishakha | cmurphy: I wanted to confirm this fast8 is to be merged with every keystone module? | 16:01 |
*** errr has left #openstack-keystone | 16:04 | |
*** erolg has quit IRC | 16:08 | |
*** gyee has joined #openstack-keystone | 16:15 | |
*** whoami-rajat has quit IRC | 16:49 | |
*** itlinux has joined #openstack-keystone | 16:58 | |
cmurphy | knikolla: could you review https://review.opendev.org/659876 ? | 17:10 |
*** whoami-rajat has joined #openstack-keystone | 17:15 | |
*** itlinux has quit IRC | 17:22 | |
openstackgerrit | Gage Hugo proposed openstack/keystonemiddleware master: Remove PKI/PKIZ support https://review.opendev.org/613675 | 17:38 |
*** jamesmcarthur_ has quit IRC | 17:42 | |
*** itlinux has joined #openstack-keystone | 17:44 | |
gyee | oh a moment of silence for PKI/PKIZ, could've been *useful* for multi-site | 17:51 |
*** jamesmcarthur has joined #openstack-keystone | 17:58 | |
*** jamesmcarthur has quit IRC | 18:02 | |
*** jamesmcarthur has joined #openstack-keystone | 18:12 | |
*** jmlowe has quit IRC | 18:18 | |
*** xek_ has joined #openstack-keystone | 18:21 | |
*** jamesmcarthur_ has joined #openstack-keystone | 18:22 | |
*** xek has quit IRC | 18:24 | |
*** jamesmcarthur has quit IRC | 18:24 | |
*** xek__ has joined #openstack-keystone | 18:30 | |
*** xek_ has quit IRC | 18:33 | |
*** itlinux has quit IRC | 18:40 | |
*** xek has joined #openstack-keystone | 18:49 | |
*** xek__ has quit IRC | 18:50 | |
*** gyee has quit IRC | 19:07 | |
*** vishakha has quit IRC | 19:11 | |
cmurphy | forgot to mention in the meeting - i'll be traveling tomorrow and then in the wrong timezone until monday | 19:18 |
*** gyee has joined #openstack-keystone | 19:19 | |
gagehugo | ok | 19:26 |
*** whoami-rajat has quit IRC | 19:29 | |
openstackgerrit | Merged openstack/keystone master: [docs] remove deprecated ubuntu package from installation https://review.opendev.org/656860 | 19:32 |
*** jamesmcarthur_ has quit IRC | 19:44 | |
* bnemec wonders what the UTC offset of "wrong" is ;-) | 19:52 | |
schaney__ | Hey guys! a few of my team members attended the Denver Stein Keystone PTG and the mentioned that the stance on this topic https://review.opendev.org/#/c/323499/ (admins can specify projectID) has changed. Hoping one of the project maintainers can confirm. | 19:57 |
schaney__ | there may be some more recent documentation/discussion but I was not able to find it | 19:58 |
*** jamesmcarthur has joined #openstack-keystone | 20:02 | |
schaney__ | looks like this topic was discussed in the recent 4/16 meeting as well http://eavesdrop.openstack.org/meetings/keystone/2019/keystone.2019-04-16-16.00.log.html | 20:33 |
*** xek has quit IRC | 20:49 | |
*** dave-mccowan has quit IRC | 20:50 | |
*** dave-mccowan has joined #openstack-keystone | 20:56 | |
bnemec | cmurphy: I saw you mentioned Lance is out for a bit. I assume that means he won't be looking at the review I added him to this morning. :-) | 20:58 |
bnemec | Any idea whenabouts he's going to be back? | 20:58 |
cmurphy | schaney__: we're starting to discuss the possibility of it, ayoung wrote up a summary here https://adam.younglogic.com/2019/05/sync-keystones-api/#settable-identifiers | 20:58 |
cmurphy | bnemec: i do not know | 20:59 |
schaney__ | cmurphy: thanks! I will stay tuned. | 21:01 |
*** jamesmcarthur has quit IRC | 21:11 | |
*** dave-mccowan has quit IRC | 21:40 | |
*** raildo has quit IRC | 21:45 | |
*** itlinux has joined #openstack-keystone | 21:49 | |
*** itlinux has quit IRC | 21:54 | |
*** rcernin has joined #openstack-keystone | 22:05 | |
*** tesseract has quit IRC | 22:07 | |
ayoung | schaney__, So I think we can do it, but we would need to add an additional policy cut point to differntiate normal project cretion from synchronization | 22:24 |
*** itlinux has joined #openstack-keystone | 22:26 | |
*** ayoung has quit IRC | 22:31 | |
*** rcernin has quit IRC | 22:40 | |
*** rcernin has joined #openstack-keystone | 22:41 | |
*** itlinux has quit IRC | 22:43 | |
*** tkajinam has joined #openstack-keystone | 22:59 | |
*** joshualyle has joined #openstack-keystone | 23:14 | |
schaney__ | ayoung: great! is the policy cut point like a different API route? | 23:17 |
*** itlinux has joined #openstack-keystone | 23:45 | |
*** itlinux_ has joined #openstack-keystone | 23:47 | |
*** itlinux has quit IRC | 23:49 | |
*** itlinux_ has quit IRC | 23:57 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!