*** dave-mccowan has quit IRC | 00:10 | |
*** cmart has quit IRC | 00:11 | |
*** dave-mccowan has joined #openstack-keystone | 00:16 | |
*** ayoung has quit IRC | 00:17 | |
*** ayoung has joined #openstack-keystone | 00:18 | |
*** ayoung has quit IRC | 00:40 | |
*** ayoung has joined #openstack-keystone | 00:42 | |
*** ileixe has joined #openstack-keystone | 01:00 | |
*** dave-mccowan has quit IRC | 01:01 | |
*** ayoung has quit IRC | 01:09 | |
*** ayoung has joined #openstack-keystone | 01:10 | |
*** mnasiadka has quit IRC | 01:11 | |
*** jamespage has quit IRC | 01:11 | |
*** manuvakery has quit IRC | 01:11 | |
*** guilhermesp has quit IRC | 01:11 | |
*** kmalloc has quit IRC | 01:12 | |
*** lamt has quit IRC | 01:12 | |
*** wxy-xiyuan has quit IRC | 01:12 | |
*** TheJulia has quit IRC | 01:12 | |
*** mnasiadka has joined #openstack-keystone | 01:12 | |
*** wxy-xiyuan has joined #openstack-keystone | 01:13 | |
*** jamespage has joined #openstack-keystone | 01:13 | |
*** TheJulia has joined #openstack-keystone | 01:13 | |
*** guilhermesp has joined #openstack-keystone | 01:13 | |
*** kmalloc has joined #openstack-keystone | 01:13 | |
*** manuvakery has joined #openstack-keystone | 01:14 | |
*** spatel has joined #openstack-keystone | 01:35 | |
*** nana_ has joined #openstack-keystone | 01:58 | |
*** spatel has quit IRC | 02:01 | |
*** nana_ has quit IRC | 02:02 | |
*** openstackstatus has joined #openstack-keystone | 02:03 | |
*** ChanServ sets mode: +v openstackstatus | 02:03 | |
*** ayoung has quit IRC | 02:54 | |
*** gyee has quit IRC | 02:55 | |
*** ayoung has joined #openstack-keystone | 02:56 | |
*** zzzeek has quit IRC | 02:56 | |
*** zzzeek has joined #openstack-keystone | 02:57 | |
*** zzzeek has quit IRC | 02:58 | |
*** zzzeek has joined #openstack-keystone | 02:59 | |
*** ayoung has quit IRC | 03:12 | |
*** ayoung has joined #openstack-keystone | 03:15 | |
*** ayoung has quit IRC | 03:30 | |
*** ayoung has joined #openstack-keystone | 03:31 | |
*** ayoung has quit IRC | 03:47 | |
*** ayoung has joined #openstack-keystone | 03:48 | |
*** ileixe has quit IRC | 04:46 | |
*** ileixe has joined #openstack-keystone | 04:58 | |
*** ileixe has quit IRC | 05:19 | |
*** awalende has joined #openstack-keystone | 05:28 | |
*** awalende has quit IRC | 05:33 | |
*** Luzi has joined #openstack-keystone | 06:04 | |
*** Blinkiz5 has joined #openstack-keystone | 06:29 | |
*** aloga_ has joined #openstack-keystone | 06:32 | |
*** rcernin has quit IRC | 06:37 | |
*** trident has quit IRC | 06:37 | |
*** jmlowe has quit IRC | 06:39 | |
*** hoonetorg has quit IRC | 06:39 | |
*** brtknr has quit IRC | 06:39 | |
*** aloga has quit IRC | 06:39 | |
*** Blinkiz has quit IRC | 06:39 | |
*** yankcrime has quit IRC | 06:39 | |
*** hugokuo has quit IRC | 06:39 | |
*** evrardjp has quit IRC | 06:39 | |
*** Blinkiz5 is now known as Blinkiz | 06:39 | |
*** spotz has quit IRC | 06:39 | |
*** ileixe has joined #openstack-keystone | 06:40 | |
*** openstackstatus has quit IRC | 06:40 | |
*** spotz has joined #openstack-keystone | 06:42 | |
*** ileixe has quit IRC | 06:45 | |
*** rcernin has joined #openstack-keystone | 06:48 | |
*** trident has joined #openstack-keystone | 06:48 | |
*** jmlowe has joined #openstack-keystone | 06:48 | |
*** hoonetorg has joined #openstack-keystone | 06:48 | |
*** brtknr has joined #openstack-keystone | 06:48 | |
*** hugokuo has joined #openstack-keystone | 06:48 | |
*** evrardjp has joined #openstack-keystone | 06:48 | |
*** rcernin has quit IRC | 07:15 | |
*** trident has quit IRC | 07:15 | |
*** jmlowe has quit IRC | 07:15 | |
*** hoonetorg has quit IRC | 07:15 | |
*** brtknr has quit IRC | 07:15 | |
*** hugokuo has quit IRC | 07:15 | |
*** evrardjp has quit IRC | 07:15 | |
*** rcernin has joined #openstack-keystone | 07:16 | |
*** trident has joined #openstack-keystone | 07:16 | |
*** jmlowe has joined #openstack-keystone | 07:16 | |
*** hoonetorg has joined #openstack-keystone | 07:16 | |
*** brtknr has joined #openstack-keystone | 07:16 | |
*** hugokuo has joined #openstack-keystone | 07:16 | |
*** evrardjp has joined #openstack-keystone | 07:16 | |
*** rcernin has quit IRC | 07:44 | |
*** trident has quit IRC | 07:49 | |
*** trident has joined #openstack-keystone | 07:58 | |
*** tkajinam has quit IRC | 08:00 | |
*** ileixe has joined #openstack-keystone | 08:02 | |
*** ileixe has quit IRC | 08:02 | |
*** ileixe has joined #openstack-keystone | 08:04 | |
*** ayoung has quit IRC | 08:15 | |
*** tesseract has joined #openstack-keystone | 08:15 | |
Blinkiz | Hello. To better understand how OpenStack (keystone) works I would like to see which policy is being checked against every time. I would like to increase logging, is this possible? | 08:19 |
---|---|---|
*** awalende has joined #openstack-keystone | 08:19 | |
Blinkiz | Is it debug = True in [DEFAULT] that is needed? | 08:24 |
*** ayoung has joined #openstack-keystone | 08:26 | |
Blinkiz | Or can I filter it somehow so I can drop all policies requests to a file? | 08:31 |
*** ivve has joined #openstack-keystone | 08:46 | |
*** yan0s has joined #openstack-keystone | 09:11 | |
*** dave-mccowan has joined #openstack-keystone | 09:14 | |
*** amoralej has joined #openstack-keystone | 10:24 | |
amoralej | hi, one job in latest execution of tempes on rdo train has failed with "TokenNotFound: Could not recognize Fernet token" | 10:25 |
amoralej | it just happened in one of the tempest tests | 10:26 |
amoralej | any hint about how to debug? | 10:26 |
amoralej | https://centos.logs.rdoproject.org/weirdo-generic-puppet-openstack-scenario001/12204/weirdo-project/logs/keystone/keystone.txt.gz#_2019-11-14_15_51_40_075 | 10:26 |
*** tesseract has quit IRC | 10:52 | |
*** tesseract has joined #openstack-keystone | 10:52 | |
*** jawad_axd has joined #openstack-keystone | 11:32 | |
*** gshippey has joined #openstack-keystone | 12:02 | |
*** awalende has quit IRC | 12:59 | |
*** awalende has joined #openstack-keystone | 12:59 | |
*** Luzi has quit IRC | 13:05 | |
*** ayoung has quit IRC | 13:13 | |
*** ayoung has joined #openstack-keystone | 13:14 | |
*** awalende has quit IRC | 13:14 | |
*** awalende has joined #openstack-keystone | 13:14 | |
*** awalende has quit IRC | 13:15 | |
*** awalende has joined #openstack-keystone | 13:15 | |
*** Luzi has joined #openstack-keystone | 13:20 | |
*** amoralej is now known as amoralej|lunch | 13:21 | |
*** amoralej|lunch is now known as amoralej | 14:08 | |
*** Luzi has quit IRC | 14:16 | |
*** cmart has joined #openstack-keystone | 14:25 | |
lbragstad | Blinkiz that'd be a good question for the #openstack-oslo channel | 14:29 |
lbragstad | I'm not aware of a way to drop all policy checks to a log file | 14:29 |
Blinkiz | lbragstad: Okay, thanks for answering | 14:29 |
lbragstad | but, I do know you can increase the logging level of libraries to be more verbose | 14:29 |
Blinkiz | lbragstad: Am currently running keystone in debug and I can see in there all requests. | 14:30 |
lbragstad | https://docs.openstack.org/keystone/latest/configuration/config-options.html#DEFAULT.default_log_levels | 14:30 |
lbragstad | if you wanted to turn up oslo.policy logging to 11, you can do that by setting oslo_policy=DEBUG | 14:30 |
lbragstad | and setting ``keystone.conf [DEFAULT] debug=True`` | 14:31 |
Blinkiz | lbragstad: But am really struggling with how to create a domain administrator. It seems to work with python-openstackclient but not within Horizon. Does it exist a guide somewhere? I do think it exist, I have seen it but I can no longer find it. It was a guide that gave example how do create system administrator, domain administrator, reader for a | 14:32 |
Blinkiz | domain, member for a project and a lot more | 14:32 |
*** awalende has quit IRC | 14:33 | |
*** awalende has joined #openstack-keystone | 14:33 | |
Blinkiz | lbragstad: Is these the only three lines that is needed to create a domain with a domain administrator? https://paste.ubuntu.com/p/Wg9DYZ5MT9/ | 14:36 |
Blinkiz | It must say somewhere in OpenStack documentation but I can not find it | 14:36 |
*** jawad_axd has quit IRC | 14:37 | |
*** awalende_ has joined #openstack-keystone | 14:37 | |
*** awalende has quit IRC | 14:38 | |
*** jawad_axd has joined #openstack-keystone | 14:38 | |
lbragstad | Blinkiz so - that's about half of the equation | 14:38 |
lbragstad | Blinkiz each service has a set of policies - either in a file or in code as defaults | 14:39 |
*** awalende_ has quit IRC | 14:39 | |
lbragstad | those policies are what determine if a user can do something in the service | 14:39 |
lbragstad | but - unfortunately, domain's aren't really used outside of keystone (is something that's still propogating through the rest of the community through policy changes) | 14:39 |
lbragstad | to implement a domain user (either admin, member, or reader) you'll likely need to make custom policy changes. | 14:40 |
*** baffle has joined #openstack-keystone | 14:40 | |
*** jawad_ax_ has joined #openstack-keystone | 14:40 | |
lbragstad | the keystone service is the exception there with the Train release, since we've gone through and updated all of our policies to include support for domain users by default | 14:41 |
Blinkiz | lbragstad: custom policy! O no.. It seems so complicated. I thought everything was fixed in Train. | 14:41 |
lbragstad | for keystone it is - yes | 14:42 |
*** jawad_axd has quit IRC | 14:43 | |
Blinkiz | lbragstad: It is a deal breaker that domain administrators work in Horizon. There it will be people that do not understand cli tools that need a gui. | 14:43 |
Blinkiz | Like my reseller customers | 14:44 |
*** jawad_ax_ has quit IRC | 14:45 | |
lbragstad | that work is being tracked in horizon it looks like https://bugs.launchpad.net/horizon/+bug/1600195 | 14:45 |
openstack | Launchpad bug 1600195 in OpenStack Dashboard (Horizon) "Domain admin cannot manage user, group and domain in own domain" [Undecided,In progress] - Assigned to Yaguang Tang (heut2008) | 14:45 |
lbragstad | https://bugs.launchpad.net/horizon/+bug/1706879 | 14:45 |
openstack | Launchpad bug 1706879 in OpenStack Dashboard (Horizon) "Domain admin user unable to navigate to domains panel" [Undecided,New] | 14:45 |
lbragstad | https://bugs.launchpad.net/horizon/+bug/1721736 | 14:45 |
openstack | Launchpad bug 1721736 in OpenStack Dashboard (Horizon) "Horizon does not allow domain admin to create users" [Undecided,New] | 14:45 |
Blinkiz | Oh man.. Am so revealed when I see these bug tickets. I thought it was me! | 14:46 |
Blinkiz | lbragstad: These are old bugs from 2016/2017. Maybe they need a push from keystoners to get the work going | 14:49 |
lbragstad | Blinkiz everyone is aware of the bugs, we really need people who can work on them | 15:00 |
*** cmart has quit IRC | 15:01 | |
*** awalende has joined #openstack-keystone | 15:05 | |
*** awalende has quit IRC | 15:10 | |
*** jaosorior has joined #openstack-keystone | 15:13 | |
*** ivve has quit IRC | 15:24 | |
Blinkiz | lbragstad: Well.. thank you today also for answering my questions. It seems you understand directly what am looking for an giving me explanations that always is spot on. | 15:26 |
Blinkiz | It's soon time for me to leave work. Have a nice evening :) | 15:26 |
lbragstad | Blinkiz glad i could help - enjoy your evening | 15:27 |
*** ayoung has quit IRC | 15:31 | |
*** ayoung has joined #openstack-keystone | 15:32 | |
knikolla | o/ | 15:58 |
knikolla | life is so hard without coffee | 15:59 |
gagehugo | o/ | 16:05 |
gagehugo | knikolla: I'll drink another cup today for you | 16:06 |
knikolla | gagehugo: haha, cheers! | 16:06 |
knikolla | i've found a positive correlation between caffeine and anxiety, so i'm trying to cut down on it. | 16:07 |
gagehugo | fair enough | 16:07 |
gagehugo | I think coffee is the only caffeine I drink now, and it's usually just a cup in the morning | 16:08 |
knikolla | *doing my best homer impersonation* ahhhhh, coffee in the morning | 16:11 |
*** jamesmcarthur has joined #openstack-keystone | 16:12 | |
*** jawad_axd has joined #openstack-keystone | 16:18 | |
*** jamesmcarthur has quit IRC | 16:19 | |
*** jamesmcarthur has joined #openstack-keystone | 16:20 | |
*** jamesmcarthur has quit IRC | 16:21 | |
*** jawad_axd has quit IRC | 16:22 | |
*** jamesmcarthur has joined #openstack-keystone | 16:36 | |
*** yan0s has quit IRC | 16:42 | |
*** cmart has joined #openstack-keystone | 16:47 | |
*** bnemec is now known as beekneemech | 16:52 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: [WIP] Try to recreate 1843464 https://review.opendev.org/684397 | 16:53 |
*** gyee has joined #openstack-keystone | 17:01 | |
*** jamesmcarthur has quit IRC | 17:07 | |
*** jaosorior has quit IRC | 17:11 | |
*** jaosorior has joined #openstack-keystone | 17:39 | |
*** amoralej is now known as amoralej|off | 18:13 | |
*** ivve has joined #openstack-keystone | 18:21 | |
*** jaosorior has quit IRC | 18:26 | |
gyee | cmurphy, should we fix keystoneauth or keystoneclient? https://bugs.launchpad.net/python-keystoneclient/+bug/1780164 and https://bugs.launchpad.net/horizon/+bug/1780164 | 18:31 |
openstack | Launchpad bug 1780164 in python-keystoneclient "httpd leaks open files" [Medium,Confirmed] | 18:31 |
gyee | I thought we need to make the fix in keystoneauth regardless. | 18:38 |
*** jaosorior has joined #openstack-keystone | 18:40 | |
*** jaosorior has quit IRC | 18:50 | |
*** jawad_axd has joined #openstack-keystone | 18:55 | |
*** pcaruana has quit IRC | 18:56 | |
*** tesseract has quit IRC | 19:04 | |
*** jmlowe has quit IRC | 19:12 | |
*** trident has quit IRC | 19:20 | |
*** trident has joined #openstack-keystone | 19:29 | |
*** jmlowe has joined #openstack-keystone | 19:34 | |
cmurphy | gyee: if the fix is for session.py then i would think ksa | 19:38 |
cmurphy | not sure why morgan wontfixed for ksa | 19:39 |
*** jawad_axd has quit IRC | 19:43 | |
gyee | cmurphy, yeah, I don't understand Morgan's comment either. | 20:02 |
*** awalende has joined #openstack-keystone | 20:34 | |
*** awalende has quit IRC | 20:38 | |
*** gshippey has quit IRC | 21:12 | |
*** rcernin has joined #openstack-keystone | 23:17 | |
*** jamesmcarthur has joined #openstack-keystone | 23:18 | |
*** ayoung has quit IRC | 23:41 | |
*** ayoung has joined #openstack-keystone | 23:42 | |
*** jamesmcarthur has quit IRC | 23:43 | |
*** jamesmcarthur has joined #openstack-keystone | 23:47 | |
*** jamesmcarthur has quit IRC | 23:55 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!