| *** dave-mccowan has quit IRC | 00:10 | |
| *** cmart has quit IRC | 00:11 | |
| *** dave-mccowan has joined #openstack-keystone | 00:16 | |
| *** ayoung has quit IRC | 00:17 | |
| *** ayoung has joined #openstack-keystone | 00:18 | |
| *** ayoung has quit IRC | 00:40 | |
| *** ayoung has joined #openstack-keystone | 00:42 | |
| *** ileixe has joined #openstack-keystone | 01:00 | |
| *** dave-mccowan has quit IRC | 01:01 | |
| *** ayoung has quit IRC | 01:09 | |
| *** ayoung has joined #openstack-keystone | 01:10 | |
| *** mnasiadka has quit IRC | 01:11 | |
| *** jamespage has quit IRC | 01:11 | |
| *** manuvakery has quit IRC | 01:11 | |
| *** guilhermesp has quit IRC | 01:11 | |
| *** kmalloc has quit IRC | 01:12 | |
| *** lamt has quit IRC | 01:12 | |
| *** wxy-xiyuan has quit IRC | 01:12 | |
| *** TheJulia has quit IRC | 01:12 | |
| *** mnasiadka has joined #openstack-keystone | 01:12 | |
| *** wxy-xiyuan has joined #openstack-keystone | 01:13 | |
| *** jamespage has joined #openstack-keystone | 01:13 | |
| *** TheJulia has joined #openstack-keystone | 01:13 | |
| *** guilhermesp has joined #openstack-keystone | 01:13 | |
| *** kmalloc has joined #openstack-keystone | 01:13 | |
| *** manuvakery has joined #openstack-keystone | 01:14 | |
| *** spatel has joined #openstack-keystone | 01:35 | |
| *** nana_ has joined #openstack-keystone | 01:58 | |
| *** spatel has quit IRC | 02:01 | |
| *** nana_ has quit IRC | 02:02 | |
| *** openstackstatus has joined #openstack-keystone | 02:03 | |
| *** ChanServ sets mode: +v openstackstatus | 02:03 | |
| *** ayoung has quit IRC | 02:54 | |
| *** gyee has quit IRC | 02:55 | |
| *** ayoung has joined #openstack-keystone | 02:56 | |
| *** zzzeek has quit IRC | 02:56 | |
| *** zzzeek has joined #openstack-keystone | 02:57 | |
| *** zzzeek has quit IRC | 02:58 | |
| *** zzzeek has joined #openstack-keystone | 02:59 | |
| *** ayoung has quit IRC | 03:12 | |
| *** ayoung has joined #openstack-keystone | 03:15 | |
| *** ayoung has quit IRC | 03:30 | |
| *** ayoung has joined #openstack-keystone | 03:31 | |
| *** ayoung has quit IRC | 03:47 | |
| *** ayoung has joined #openstack-keystone | 03:48 | |
| *** ileixe has quit IRC | 04:46 | |
| *** ileixe has joined #openstack-keystone | 04:58 | |
| *** ileixe has quit IRC | 05:19 | |
| *** awalende has joined #openstack-keystone | 05:28 | |
| *** awalende has quit IRC | 05:33 | |
| *** Luzi has joined #openstack-keystone | 06:04 | |
| *** Blinkiz5 has joined #openstack-keystone | 06:29 | |
| *** aloga_ has joined #openstack-keystone | 06:32 | |
| *** rcernin has quit IRC | 06:37 | |
| *** trident has quit IRC | 06:37 | |
| *** jmlowe has quit IRC | 06:39 | |
| *** hoonetorg has quit IRC | 06:39 | |
| *** brtknr has quit IRC | 06:39 | |
| *** aloga has quit IRC | 06:39 | |
| *** Blinkiz has quit IRC | 06:39 | |
| *** yankcrime has quit IRC | 06:39 | |
| *** hugokuo has quit IRC | 06:39 | |
| *** evrardjp has quit IRC | 06:39 | |
| *** Blinkiz5 is now known as Blinkiz | 06:39 | |
| *** spotz has quit IRC | 06:39 | |
| *** ileixe has joined #openstack-keystone | 06:40 | |
| *** openstackstatus has quit IRC | 06:40 | |
| *** spotz has joined #openstack-keystone | 06:42 | |
| *** ileixe has quit IRC | 06:45 | |
| *** rcernin has joined #openstack-keystone | 06:48 | |
| *** trident has joined #openstack-keystone | 06:48 | |
| *** jmlowe has joined #openstack-keystone | 06:48 | |
| *** hoonetorg has joined #openstack-keystone | 06:48 | |
| *** brtknr has joined #openstack-keystone | 06:48 | |
| *** hugokuo has joined #openstack-keystone | 06:48 | |
| *** evrardjp has joined #openstack-keystone | 06:48 | |
| *** rcernin has quit IRC | 07:15 | |
| *** trident has quit IRC | 07:15 | |
| *** jmlowe has quit IRC | 07:15 | |
| *** hoonetorg has quit IRC | 07:15 | |
| *** brtknr has quit IRC | 07:15 | |
| *** hugokuo has quit IRC | 07:15 | |
| *** evrardjp has quit IRC | 07:15 | |
| *** rcernin has joined #openstack-keystone | 07:16 | |
| *** trident has joined #openstack-keystone | 07:16 | |
| *** jmlowe has joined #openstack-keystone | 07:16 | |
| *** hoonetorg has joined #openstack-keystone | 07:16 | |
| *** brtknr has joined #openstack-keystone | 07:16 | |
| *** hugokuo has joined #openstack-keystone | 07:16 | |
| *** evrardjp has joined #openstack-keystone | 07:16 | |
| *** rcernin has quit IRC | 07:44 | |
| *** trident has quit IRC | 07:49 | |
| *** trident has joined #openstack-keystone | 07:58 | |
| *** tkajinam has quit IRC | 08:00 | |
| *** ileixe has joined #openstack-keystone | 08:02 | |
| *** ileixe has quit IRC | 08:02 | |
| *** ileixe has joined #openstack-keystone | 08:04 | |
| *** ayoung has quit IRC | 08:15 | |
| *** tesseract has joined #openstack-keystone | 08:15 | |
| Blinkiz | Hello. To better understand how OpenStack (keystone) works I would like to see which policy is being checked against every time. I would like to increase logging, is this possible? | 08:19 |
|---|---|---|
| *** awalende has joined #openstack-keystone | 08:19 | |
| Blinkiz | Is it debug = True in [DEFAULT] that is needed? | 08:24 |
| *** ayoung has joined #openstack-keystone | 08:26 | |
| Blinkiz | Or can I filter it somehow so I can drop all policies requests to a file? | 08:31 |
| *** ivve has joined #openstack-keystone | 08:46 | |
| *** yan0s has joined #openstack-keystone | 09:11 | |
| *** dave-mccowan has joined #openstack-keystone | 09:14 | |
| *** amoralej has joined #openstack-keystone | 10:24 | |
| amoralej | hi, one job in latest execution of tempes on rdo train has failed with "TokenNotFound: Could not recognize Fernet token" | 10:25 |
| amoralej | it just happened in one of the tempest tests | 10:26 |
| amoralej | any hint about how to debug? | 10:26 |
| amoralej | https://centos.logs.rdoproject.org/weirdo-generic-puppet-openstack-scenario001/12204/weirdo-project/logs/keystone/keystone.txt.gz#_2019-11-14_15_51_40_075 | 10:26 |
| *** tesseract has quit IRC | 10:52 | |
| *** tesseract has joined #openstack-keystone | 10:52 | |
| *** jawad_axd has joined #openstack-keystone | 11:32 | |
| *** gshippey has joined #openstack-keystone | 12:02 | |
| *** awalende has quit IRC | 12:59 | |
| *** awalende has joined #openstack-keystone | 12:59 | |
| *** Luzi has quit IRC | 13:05 | |
| *** ayoung has quit IRC | 13:13 | |
| *** ayoung has joined #openstack-keystone | 13:14 | |
| *** awalende has quit IRC | 13:14 | |
| *** awalende has joined #openstack-keystone | 13:14 | |
| *** awalende has quit IRC | 13:15 | |
| *** awalende has joined #openstack-keystone | 13:15 | |
| *** Luzi has joined #openstack-keystone | 13:20 | |
| *** amoralej is now known as amoralej|lunch | 13:21 | |
| *** amoralej|lunch is now known as amoralej | 14:08 | |
| *** Luzi has quit IRC | 14:16 | |
| *** cmart has joined #openstack-keystone | 14:25 | |
| lbragstad | Blinkiz that'd be a good question for the #openstack-oslo channel | 14:29 |
| lbragstad | I'm not aware of a way to drop all policy checks to a log file | 14:29 |
| Blinkiz | lbragstad: Okay, thanks for answering | 14:29 |
| lbragstad | but, I do know you can increase the logging level of libraries to be more verbose | 14:29 |
| Blinkiz | lbragstad: Am currently running keystone in debug and I can see in there all requests. | 14:30 |
| lbragstad | https://docs.openstack.org/keystone/latest/configuration/config-options.html#DEFAULT.default_log_levels | 14:30 |
| lbragstad | if you wanted to turn up oslo.policy logging to 11, you can do that by setting oslo_policy=DEBUG | 14:30 |
| lbragstad | and setting ``keystone.conf [DEFAULT] debug=True`` | 14:31 |
| Blinkiz | lbragstad: But am really struggling with how to create a domain administrator. It seems to work with python-openstackclient but not within Horizon. Does it exist a guide somewhere? I do think it exist, I have seen it but I can no longer find it. It was a guide that gave example how do create system administrator, domain administrator, reader for a | 14:32 |
| Blinkiz | domain, member for a project and a lot more | 14:32 |
| *** awalende has quit IRC | 14:33 | |
| *** awalende has joined #openstack-keystone | 14:33 | |
| Blinkiz | lbragstad: Is these the only three lines that is needed to create a domain with a domain administrator? https://paste.ubuntu.com/p/Wg9DYZ5MT9/ | 14:36 |
| Blinkiz | It must say somewhere in OpenStack documentation but I can not find it | 14:36 |
| *** jawad_axd has quit IRC | 14:37 | |
| *** awalende_ has joined #openstack-keystone | 14:37 | |
| *** awalende has quit IRC | 14:38 | |
| *** jawad_axd has joined #openstack-keystone | 14:38 | |
| lbragstad | Blinkiz so - that's about half of the equation | 14:38 |
| lbragstad | Blinkiz each service has a set of policies - either in a file or in code as defaults | 14:39 |
| *** awalende_ has quit IRC | 14:39 | |
| lbragstad | those policies are what determine if a user can do something in the service | 14:39 |
| lbragstad | but - unfortunately, domain's aren't really used outside of keystone (is something that's still propogating through the rest of the community through policy changes) | 14:39 |
| lbragstad | to implement a domain user (either admin, member, or reader) you'll likely need to make custom policy changes. | 14:40 |
| *** baffle has joined #openstack-keystone | 14:40 | |
| *** jawad_ax_ has joined #openstack-keystone | 14:40 | |
| lbragstad | the keystone service is the exception there with the Train release, since we've gone through and updated all of our policies to include support for domain users by default | 14:41 |
| Blinkiz | lbragstad: custom policy! O no.. It seems so complicated. I thought everything was fixed in Train. | 14:41 |
| lbragstad | for keystone it is - yes | 14:42 |
| *** jawad_axd has quit IRC | 14:43 | |
| Blinkiz | lbragstad: It is a deal breaker that domain administrators work in Horizon. There it will be people that do not understand cli tools that need a gui. | 14:43 |
| Blinkiz | Like my reseller customers | 14:44 |
| *** jawad_ax_ has quit IRC | 14:45 | |
| lbragstad | that work is being tracked in horizon it looks like https://bugs.launchpad.net/horizon/+bug/1600195 | 14:45 |
| openstack | Launchpad bug 1600195 in OpenStack Dashboard (Horizon) "Domain admin cannot manage user, group and domain in own domain" [Undecided,In progress] - Assigned to Yaguang Tang (heut2008) | 14:45 |
| lbragstad | https://bugs.launchpad.net/horizon/+bug/1706879 | 14:45 |
| openstack | Launchpad bug 1706879 in OpenStack Dashboard (Horizon) "Domain admin user unable to navigate to domains panel" [Undecided,New] | 14:45 |
| lbragstad | https://bugs.launchpad.net/horizon/+bug/1721736 | 14:45 |
| openstack | Launchpad bug 1721736 in OpenStack Dashboard (Horizon) "Horizon does not allow domain admin to create users" [Undecided,New] | 14:45 |
| Blinkiz | Oh man.. Am so revealed when I see these bug tickets. I thought it was me! | 14:46 |
| Blinkiz | lbragstad: These are old bugs from 2016/2017. Maybe they need a push from keystoners to get the work going | 14:49 |
| lbragstad | Blinkiz everyone is aware of the bugs, we really need people who can work on them | 15:00 |
| *** cmart has quit IRC | 15:01 | |
| *** awalende has joined #openstack-keystone | 15:05 | |
| *** awalende has quit IRC | 15:10 | |
| *** jaosorior has joined #openstack-keystone | 15:13 | |
| *** ivve has quit IRC | 15:24 | |
| Blinkiz | lbragstad: Well.. thank you today also for answering my questions. It seems you understand directly what am looking for an giving me explanations that always is spot on. | 15:26 |
| Blinkiz | It's soon time for me to leave work. Have a nice evening :) | 15:26 |
| lbragstad | Blinkiz glad i could help - enjoy your evening | 15:27 |
| *** ayoung has quit IRC | 15:31 | |
| *** ayoung has joined #openstack-keystone | 15:32 | |
| knikolla | o/ | 15:58 |
| knikolla | life is so hard without coffee | 15:59 |
| gagehugo | o/ | 16:05 |
| gagehugo | knikolla: I'll drink another cup today for you | 16:06 |
| knikolla | gagehugo: haha, cheers! | 16:06 |
| knikolla | i've found a positive correlation between caffeine and anxiety, so i'm trying to cut down on it. | 16:07 |
| gagehugo | fair enough | 16:07 |
| gagehugo | I think coffee is the only caffeine I drink now, and it's usually just a cup in the morning | 16:08 |
| knikolla | *doing my best homer impersonation* ahhhhh, coffee in the morning | 16:11 |
| *** jamesmcarthur has joined #openstack-keystone | 16:12 | |
| *** jawad_axd has joined #openstack-keystone | 16:18 | |
| *** jamesmcarthur has quit IRC | 16:19 | |
| *** jamesmcarthur has joined #openstack-keystone | 16:20 | |
| *** jamesmcarthur has quit IRC | 16:21 | |
| *** jawad_axd has quit IRC | 16:22 | |
| *** jamesmcarthur has joined #openstack-keystone | 16:36 | |
| *** yan0s has quit IRC | 16:42 | |
| *** cmart has joined #openstack-keystone | 16:47 | |
| *** bnemec is now known as beekneemech | 16:52 | |
| openstackgerrit | Gage Hugo proposed openstack/keystone master: [WIP] Try to recreate 1843464 https://review.opendev.org/684397 | 16:53 |
| *** gyee has joined #openstack-keystone | 17:01 | |
| *** jamesmcarthur has quit IRC | 17:07 | |
| *** jaosorior has quit IRC | 17:11 | |
| *** jaosorior has joined #openstack-keystone | 17:39 | |
| *** amoralej is now known as amoralej|off | 18:13 | |
| *** ivve has joined #openstack-keystone | 18:21 | |
| *** jaosorior has quit IRC | 18:26 | |
| gyee | cmurphy, should we fix keystoneauth or keystoneclient? https://bugs.launchpad.net/python-keystoneclient/+bug/1780164 and https://bugs.launchpad.net/horizon/+bug/1780164 | 18:31 |
| openstack | Launchpad bug 1780164 in python-keystoneclient "httpd leaks open files" [Medium,Confirmed] | 18:31 |
| gyee | I thought we need to make the fix in keystoneauth regardless. | 18:38 |
| *** jaosorior has joined #openstack-keystone | 18:40 | |
| *** jaosorior has quit IRC | 18:50 | |
| *** jawad_axd has joined #openstack-keystone | 18:55 | |
| *** pcaruana has quit IRC | 18:56 | |
| *** tesseract has quit IRC | 19:04 | |
| *** jmlowe has quit IRC | 19:12 | |
| *** trident has quit IRC | 19:20 | |
| *** trident has joined #openstack-keystone | 19:29 | |
| *** jmlowe has joined #openstack-keystone | 19:34 | |
| cmurphy | gyee: if the fix is for session.py then i would think ksa | 19:38 |
| cmurphy | not sure why morgan wontfixed for ksa | 19:39 |
| *** jawad_axd has quit IRC | 19:43 | |
| gyee | cmurphy, yeah, I don't understand Morgan's comment either. | 20:02 |
| *** awalende has joined #openstack-keystone | 20:34 | |
| *** awalende has quit IRC | 20:38 | |
| *** gshippey has quit IRC | 21:12 | |
| *** rcernin has joined #openstack-keystone | 23:17 | |
| *** jamesmcarthur has joined #openstack-keystone | 23:18 | |
| *** ayoung has quit IRC | 23:41 | |
| *** ayoung has joined #openstack-keystone | 23:42 | |
| *** jamesmcarthur has quit IRC | 23:43 | |
| *** jamesmcarthur has joined #openstack-keystone | 23:47 | |
| *** jamesmcarthur has quit IRC | 23:55 | |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!