| *** jamesmcarthur has joined #openstack-keystone | 00:05 | |
| *** rcernin has quit IRC | 00:06 | |
| *** jamesmcarthur has quit IRC | 00:10 | |
| *** jamesmcarthur has joined #openstack-keystone | 00:12 | |
| *** rcernin has joined #openstack-keystone | 00:13 | |
| *** jamesmcarthur has quit IRC | 00:16 | |
| *** jamesmcarthur has joined #openstack-keystone | 00:18 | |
| *** jamesmcarthur has quit IRC | 00:21 | |
| *** jamesmcarthur has joined #openstack-keystone | 00:21 | |
| *** tkajinam has quit IRC | 01:55 | |
| *** tkajinam has joined #openstack-keystone | 01:55 | |
| openstackgerrit | Merged openstack/keystone master: Cap jsonschema 3.2.0 as the minimal version https://review.opendev.org/730952 | 02:08 |
|---|---|---|
| *** jamesmcarthur has quit IRC | 02:11 | |
| *** jamesmcarthur has joined #openstack-keystone | 02:11 | |
| *** jamesmcarthur has quit IRC | 02:16 | |
| *** jamesmcarthur has joined #openstack-keystone | 03:29 | |
| *** dave-mccowan has quit IRC | 03:30 | |
| *** jamesmcarthur has quit IRC | 03:32 | |
| *** jamesmcarthur has joined #openstack-keystone | 03:32 | |
| *** jamesmcarthur has quit IRC | 04:08 | |
| *** jamesmcarthur has joined #openstack-keystone | 04:08 | |
| *** jamesmcarthur has quit IRC | 04:09 | |
| *** jamesmcarthur_ has joined #openstack-keystone | 04:09 | |
| *** jamesmcarthur_ has quit IRC | 04:11 | |
| *** gyee has quit IRC | 04:15 | |
| *** diurnalist has quit IRC | 04:16 | |
| *** abdysn has joined #openstack-keystone | 04:56 | |
| *** diurnalist has joined #openstack-keystone | 06:13 | |
| *** diurnalist has quit IRC | 06:18 | |
| *** shyamb has joined #openstack-keystone | 07:05 | |
| *** shyam89 has joined #openstack-keystone | 07:18 | |
| *** shyamb has quit IRC | 07:21 | |
| *** bengates has joined #openstack-keystone | 07:22 | |
| *** bengates has quit IRC | 07:22 | |
| *** bengates has joined #openstack-keystone | 07:22 | |
| *** shyam89 has quit IRC | 07:28 | |
| *** bengates_ has joined #openstack-keystone | 07:39 | |
| *** bengates has quit IRC | 07:43 | |
| *** rcernin has quit IRC | 07:48 | |
| *** shyamb has joined #openstack-keystone | 07:59 | |
| *** shyam89 has joined #openstack-keystone | 08:13 | |
| *** bnemec has quit IRC | 08:14 | |
| *** rcernin has joined #openstack-keystone | 08:14 | |
| *** shyamb has quit IRC | 08:16 | |
| *** bnemec has joined #openstack-keystone | 08:17 | |
| *** stingrayza has joined #openstack-keystone | 08:23 | |
| *** also_stingrayza has quit IRC | 08:24 | |
| *** shyam89 has quit IRC | 08:30 | |
| *** xek has joined #openstack-keystone | 08:38 | |
| *** shyamb has joined #openstack-keystone | 08:47 | |
| *** bengates_ has quit IRC | 08:56 | |
| *** bengates has joined #openstack-keystone | 08:57 | |
| *** xek has quit IRC | 09:01 | |
| *** rcernin has quit IRC | 09:07 | |
| *** shyamb has quit IRC | 09:22 | |
| *** bengates has quit IRC | 09:35 | |
| *** bengates has joined #openstack-keystone | 09:36 | |
| *** shyamb has joined #openstack-keystone | 09:45 | |
| *** dmellado has quit IRC | 09:59 | |
| *** xek has joined #openstack-keystone | 10:06 | |
| *** dmellado has joined #openstack-keystone | 10:07 | |
| *** rcernin has joined #openstack-keystone | 10:15 | |
| *** rcernin has quit IRC | 10:30 | |
| *** shyamb has quit IRC | 10:36 | |
| *** shyamb has joined #openstack-keystone | 10:55 | |
| *** xek has quit IRC | 11:47 | |
| *** raildo has joined #openstack-keystone | 11:59 | |
| *** takamatsu has joined #openstack-keystone | 12:11 | |
| *** shyamb has quit IRC | 12:13 | |
| *** rcernin has joined #openstack-keystone | 12:21 | |
| *** xek has joined #openstack-keystone | 12:53 | |
| *** xek_ has joined #openstack-keystone | 12:55 | |
| *** xek has quit IRC | 12:58 | |
| *** lbragstad has quit IRC | 12:58 | |
| *** lbragstad has joined #openstack-keystone | 13:01 | |
| *** spatel has joined #openstack-keystone | 13:05 | |
| *** dave-mccowan has joined #openstack-keystone | 13:24 | |
| *** rcernin has quit IRC | 13:31 | |
| sri_ | Hi team, quick question , is it possible to create isolated domain admin user in ussuri release ? | 13:39 |
| knikolla | sri_: by isolated domain admin you mean someone that has admin permissions on that domain only? | 13:45 |
| sri_ | knikolla: Yes, Domain administrators arenβt allowed to access system-specific resources or resources outside their domain. | 13:47 |
| *** abdysn has quit IRC | 13:48 | |
| sri_ | Domain admin should be only allow to create project's and user within the domain, | 13:50 |
| sri_ | knikolla: ^ | 13:50 |
| knikolla | sri_: it's... complicated. it is possible if you set the option to enforce_scope to True. | 13:59 |
| sri_ | knikolla: this document describes about what domain admin role supposed to do. https://docs.openstack.org/keystone/latest/admin/service-api-protection.html | 14:01 |
| sri_ | knikolla: But I don't understand how to that. can you please point to me right direction, where do i start ? where do i set this "enforce_scope to True" in keystone.conf | 14:03 |
| *** alistarle has joined #openstack-keystone | 14:07 | |
| knikolla | sri_: you can find a sample keystone.conf with comments for each option here https://docs.openstack.org/keystone/latest/configuration/samples/keystone-conf.html | 14:10 |
| knikolla | there is an enforce_scope option in the [oslo_policy] section. | 14:10 |
| sri_ | knikolla: one I add enforce_scope option, then should i also need to write policy to keystone policy.json file ? to create domain admin account ? | 14:13 |
| knikolla | that shouldn't be necessary, since the policy defaults are specified in code. | 14:14 |
| knikolla | lbragstad: did i get ^ right? | 14:20 |
| *** alistarle has quit IRC | 14:33 | |
| sri_ | knikolla: when I added the option enforce_scope = True, I can't create a project's or users | 14:41 |
| *** tkajinam has quit IRC | 14:47 | |
| *** bengates has quit IRC | 14:49 | |
| *** bengates has joined #openstack-keystone | 14:50 | |
| knikolla | sri_: That is because admin operations now require system level permissions and scoping. So before flipping the enforce_scope switch, add yourself as admin on system. | 14:53 |
| *** hoonetorg has quit IRC | 14:55 | |
| *** irclogbot_3 has quit IRC | 14:55 | |
| *** hoonetorg has joined #openstack-keystone | 14:57 | |
| *** irclogbot_3 has joined #openstack-keystone | 14:57 | |
| *** aning_ has quit IRC | 15:00 | |
| *** diurnalist has joined #openstack-keystone | 15:01 | |
| *** spatel has quit IRC | 15:04 | |
| *** aning has joined #openstack-keystone | 15:06 | |
| *** johnthetubaguy has quit IRC | 15:16 | |
| *** johnthetubaguy has joined #openstack-keystone | 15:20 | |
| *** gyee has joined #openstack-keystone | 15:25 | |
| *** dave-mccowan has quit IRC | 15:28 | |
| *** kmalloc has joined #openstack-keystone | 15:35 | |
| sri_ | knikolla: I need to do some reading, i didn't get what i wanted, but at-least I am on right path, I really appreciate your help. thank you :) | 15:40 |
| *** xek_ has quit IRC | 15:47 | |
| *** bengates has quit IRC | 16:08 | |
| *** johnthetubaguy has quit IRC | 16:17 | |
| *** johnthetubaguy has joined #openstack-keystone | 16:20 | |
| *** vishakha has joined #openstack-keystone | 16:21 | |
| sri_ | knikolla: let me rephrase that ("i didn't get what i wanted") properly, *I am not able to make it work yet. | 16:21 |
| *** manuvakery has joined #openstack-keystone | 17:59 | |
| *** carthaca has quit IRC | 18:00 | |
| openstackgerrit | Merged openstack/keystone master: Support regexes in whitelists/blacklists https://review.opendev.org/730423 | 20:03 |
| *** manuvakery has quit IRC | 20:09 | |
| *** vesper11 has quit IRC | 20:20 | |
| *** vesper11 has joined #openstack-keystone | 20:21 | |
| *** xek_ has joined #openstack-keystone | 20:57 | |
| sri_ | lbragstad: quick question, is policy.v3cloudsample.json deprecated ? | 21:00 |
| *** raildo has quit IRC | 21:00 | |
| lbragstad | sri_ yes - it's technically obsolete in newer branches because we've improved the policy checks | 21:01 |
| sri_ | lbragstad: ack, I was trying to create domain admin, where domain admin can only manage projects and users within the domain, to archive that do i have to create custom policy's ? | 21:03 |
| lbragstad | sri_ it depends on the release you're using | 21:06 |
| lbragstad | i think that's supported with stein - if you explicitly opt into using the new policies | 21:07 |
| sri_ | lbragstad: I am using ussuri release | 21:07 |
| lbragstad | ok - then you should be able to use the new policies | 21:08 |
| lbragstad | you might need to set https://docs.openstack.org/oslo.policy/latest/configuration/index.html#oslo_policy.enforce_new_defaults and https://docs.openstack.org/oslo.policy/latest/configuration/index.html#oslo_policy.enforce_scope to True in your keystone.conf | 21:09 |
| sri_ | lbragstad: I was adding enforce_scope = True option as knikolla suggested, with that option enabled even admin user also not able to create user or domains | 21:09 |
| lbragstad | sri_ are you using a system-scoped token? | 21:10 |
| lbragstad | or are you using a project-scoped token? | 21:10 |
| sri_ | lbragstad: I am not sure, this my rc file http://paste.openstack.org/show/796027/ | 21:11 |
| lbragstad | sri_ that's going to ask keystone for a project-scoped token, which isn't going to work if you want to opt into the new behavior | 21:12 |
| lbragstad | you're going to need to set OS_SYSTEM_SCOPE=all instead of OS_PROJECT_NAME | 21:13 |
| lbragstad | or you can use a clouds.yaml file | 21:13 |
| sri_ | I see, I believe horizion doesn't work with new policies right ? | 21:14 |
| sri_ | lbragstad: ^ | 21:15 |
| lbragstad | sri_ correct, that work is still pending | 21:16 |
| sri_ | lbragstad: understood, you saved my day, Thank you π | 21:18 |
| lbragstad | sri_ were you able to get it working? | 21:18 |
| sri_ | lbragstad: not yet, testing now ! | 21:19 |
| *** markvoelker has joined #openstack-keystone | 21:23 | |
| *** markvoelker has quit IRC | 21:26 | |
| sri_ | lbragstad: with system-scoped token I am able to create users,projects and domains | 21:32 |
| *** markvoelker has joined #openstack-keystone | 21:33 | |
| lbragstad | sri_ cool - good deal | 21:34 |
| *** markvoelker has quit IRC | 21:38 | |
| lbragstad | knikolla yes - i think you got that right (just following up on this) | 21:41 |
| openstackgerrit | Colleen Murphy proposed openstack/keystone-tempest-plugin master: WIP/PoC:Add RBAC tests https://review.opendev.org/686305 | 21:44 |
| sri_ | lbragstad: sorry for silly question, I've created new domain and user with admin role, http://paste.openstack.org/show/796030/ , new domain admin user can't create any project's or users | 21:48 |
| lbragstad | sri_ are they using a domain scoped token? | 21:48 |
| sri_ | oh, no | 21:49 |
| sri_ | lbragstad: I've added OS_DOMAIN_SCOPE=lab to rc, file now I am getting The service catalog is empty. | 21:52 |
| sri_ | lbragstad: keystone log's : http://paste.openstack.org/show/796031/ | 22:06 |
| lbragstad | sri_ i think you need to use OS_DOMAIN_NAME | 22:11 |
| lbragstad | and not OS_DOMAIN_SCOPE | 22:11 |
| sri_ | lbragstad: sorry, yes you're right | 22:14 |
| sri_ | lbragstad: everything is working as i expected π | 22:15 |
| sri_ | lbragstad: let me say it again, you saved my day, Thank you π | 22:15 |
| sri_ | lbragstad: one small issue, I can create project and users but not able to assign any role to users with in the domain, is the expected behavior ? | 22:22 |
| sri_ | lbragstad: do I have add to the role's to user before enabling "enforce_scope = True" ! | 22:37 |
| *** rcernin has joined #openstack-keystone | 22:43 | |
| *** rcernin has quit IRC | 22:47 | |
| *** rcernin has joined #openstack-keystone | 22:54 | |
| sri_ | lbragstad: also when run the openstack network list in the new domain , it's showing default domain private network and router, I think it not suppose show other domain's resources right ? | 22:58 |
| *** tkajinam has joined #openstack-keystone | 23:02 | |
| *** gyee has quit IRC | 23:16 | |
| *** hoonetorg has quit IRC | 23:16 | |
| *** irclogbot_3 has quit IRC | 23:16 | |
| *** gyee has joined #openstack-keystone | 23:22 | |
| *** hoonetorg has joined #openstack-keystone | 23:22 | |
| *** irclogbot_3 has joined #openstack-keystone | 23:22 | |
| lbragstad | sri_ role assignments might not work unless you're using domain specific roles | 23:46 |
| lbragstad | but i'd need to double check | 23:46 |
| lbragstad | also neutron and other services are in the process of adopting all of this, so behavior is going to vary | 23:46 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!