*** jamesmcarthur has joined #openstack-keystone | 00:05 | |
*** rcernin has quit IRC | 00:06 | |
*** jamesmcarthur has quit IRC | 00:10 | |
*** jamesmcarthur has joined #openstack-keystone | 00:12 | |
*** rcernin has joined #openstack-keystone | 00:13 | |
*** jamesmcarthur has quit IRC | 00:16 | |
*** jamesmcarthur has joined #openstack-keystone | 00:18 | |
*** jamesmcarthur has quit IRC | 00:21 | |
*** jamesmcarthur has joined #openstack-keystone | 00:21 | |
*** tkajinam has quit IRC | 01:55 | |
*** tkajinam has joined #openstack-keystone | 01:55 | |
openstackgerrit | Merged openstack/keystone master: Cap jsonschema 3.2.0 as the minimal version https://review.opendev.org/730952 | 02:08 |
---|---|---|
*** jamesmcarthur has quit IRC | 02:11 | |
*** jamesmcarthur has joined #openstack-keystone | 02:11 | |
*** jamesmcarthur has quit IRC | 02:16 | |
*** jamesmcarthur has joined #openstack-keystone | 03:29 | |
*** dave-mccowan has quit IRC | 03:30 | |
*** jamesmcarthur has quit IRC | 03:32 | |
*** jamesmcarthur has joined #openstack-keystone | 03:32 | |
*** jamesmcarthur has quit IRC | 04:08 | |
*** jamesmcarthur has joined #openstack-keystone | 04:08 | |
*** jamesmcarthur has quit IRC | 04:09 | |
*** jamesmcarthur_ has joined #openstack-keystone | 04:09 | |
*** jamesmcarthur_ has quit IRC | 04:11 | |
*** gyee has quit IRC | 04:15 | |
*** diurnalist has quit IRC | 04:16 | |
*** abdysn has joined #openstack-keystone | 04:56 | |
*** diurnalist has joined #openstack-keystone | 06:13 | |
*** diurnalist has quit IRC | 06:18 | |
*** shyamb has joined #openstack-keystone | 07:05 | |
*** shyam89 has joined #openstack-keystone | 07:18 | |
*** shyamb has quit IRC | 07:21 | |
*** bengates has joined #openstack-keystone | 07:22 | |
*** bengates has quit IRC | 07:22 | |
*** bengates has joined #openstack-keystone | 07:22 | |
*** shyam89 has quit IRC | 07:28 | |
*** bengates_ has joined #openstack-keystone | 07:39 | |
*** bengates has quit IRC | 07:43 | |
*** rcernin has quit IRC | 07:48 | |
*** shyamb has joined #openstack-keystone | 07:59 | |
*** shyam89 has joined #openstack-keystone | 08:13 | |
*** bnemec has quit IRC | 08:14 | |
*** rcernin has joined #openstack-keystone | 08:14 | |
*** shyamb has quit IRC | 08:16 | |
*** bnemec has joined #openstack-keystone | 08:17 | |
*** stingrayza has joined #openstack-keystone | 08:23 | |
*** also_stingrayza has quit IRC | 08:24 | |
*** shyam89 has quit IRC | 08:30 | |
*** xek has joined #openstack-keystone | 08:38 | |
*** shyamb has joined #openstack-keystone | 08:47 | |
*** bengates_ has quit IRC | 08:56 | |
*** bengates has joined #openstack-keystone | 08:57 | |
*** xek has quit IRC | 09:01 | |
*** rcernin has quit IRC | 09:07 | |
*** shyamb has quit IRC | 09:22 | |
*** bengates has quit IRC | 09:35 | |
*** bengates has joined #openstack-keystone | 09:36 | |
*** shyamb has joined #openstack-keystone | 09:45 | |
*** dmellado has quit IRC | 09:59 | |
*** xek has joined #openstack-keystone | 10:06 | |
*** dmellado has joined #openstack-keystone | 10:07 | |
*** rcernin has joined #openstack-keystone | 10:15 | |
*** rcernin has quit IRC | 10:30 | |
*** shyamb has quit IRC | 10:36 | |
*** shyamb has joined #openstack-keystone | 10:55 | |
*** xek has quit IRC | 11:47 | |
*** raildo has joined #openstack-keystone | 11:59 | |
*** takamatsu has joined #openstack-keystone | 12:11 | |
*** shyamb has quit IRC | 12:13 | |
*** rcernin has joined #openstack-keystone | 12:21 | |
*** xek has joined #openstack-keystone | 12:53 | |
*** xek_ has joined #openstack-keystone | 12:55 | |
*** xek has quit IRC | 12:58 | |
*** lbragstad has quit IRC | 12:58 | |
*** lbragstad has joined #openstack-keystone | 13:01 | |
*** spatel has joined #openstack-keystone | 13:05 | |
*** dave-mccowan has joined #openstack-keystone | 13:24 | |
*** rcernin has quit IRC | 13:31 | |
sri_ | Hi team, quick question , is it possible to create isolated domain admin user in ussuri release ? | 13:39 |
knikolla | sri_: by isolated domain admin you mean someone that has admin permissions on that domain only? | 13:45 |
sri_ | knikolla: Yes, Domain administrators arenβt allowed to access system-specific resources or resources outside their domain. | 13:47 |
*** abdysn has quit IRC | 13:48 | |
sri_ | Domain admin should be only allow to create project's and user within the domain, | 13:50 |
sri_ | knikolla: ^ | 13:50 |
knikolla | sri_: it's... complicated. it is possible if you set the option to enforce_scope to True. | 13:59 |
sri_ | knikolla: this document describes about what domain admin role supposed to do. https://docs.openstack.org/keystone/latest/admin/service-api-protection.html | 14:01 |
sri_ | knikolla: But I don't understand how to that. can you please point to me right direction, where do i start ? where do i set this "enforce_scope to True" in keystone.conf | 14:03 |
*** alistarle has joined #openstack-keystone | 14:07 | |
knikolla | sri_: you can find a sample keystone.conf with comments for each option here https://docs.openstack.org/keystone/latest/configuration/samples/keystone-conf.html | 14:10 |
knikolla | there is an enforce_scope option in the [oslo_policy] section. | 14:10 |
sri_ | knikolla: one I add enforce_scope option, then should i also need to write policy to keystone policy.json file ? to create domain admin account ? | 14:13 |
knikolla | that shouldn't be necessary, since the policy defaults are specified in code. | 14:14 |
knikolla | lbragstad: did i get ^ right? | 14:20 |
*** alistarle has quit IRC | 14:33 | |
sri_ | knikolla: when I added the option enforce_scope = True, I can't create a project's or users | 14:41 |
*** tkajinam has quit IRC | 14:47 | |
*** bengates has quit IRC | 14:49 | |
*** bengates has joined #openstack-keystone | 14:50 | |
knikolla | sri_: That is because admin operations now require system level permissions and scoping. So before flipping the enforce_scope switch, add yourself as admin on system. | 14:53 |
*** hoonetorg has quit IRC | 14:55 | |
*** irclogbot_3 has quit IRC | 14:55 | |
*** hoonetorg has joined #openstack-keystone | 14:57 | |
*** irclogbot_3 has joined #openstack-keystone | 14:57 | |
*** aning_ has quit IRC | 15:00 | |
*** diurnalist has joined #openstack-keystone | 15:01 | |
*** spatel has quit IRC | 15:04 | |
*** aning has joined #openstack-keystone | 15:06 | |
*** johnthetubaguy has quit IRC | 15:16 | |
*** johnthetubaguy has joined #openstack-keystone | 15:20 | |
*** gyee has joined #openstack-keystone | 15:25 | |
*** dave-mccowan has quit IRC | 15:28 | |
*** kmalloc has joined #openstack-keystone | 15:35 | |
sri_ | knikolla: I need to do some reading, i didn't get what i wanted, but at-least I am on right path, I really appreciate your help. thank you :) | 15:40 |
*** xek_ has quit IRC | 15:47 | |
*** bengates has quit IRC | 16:08 | |
*** johnthetubaguy has quit IRC | 16:17 | |
*** johnthetubaguy has joined #openstack-keystone | 16:20 | |
*** vishakha has joined #openstack-keystone | 16:21 | |
sri_ | knikolla: let me rephrase that ("i didn't get what i wanted") properly, *I am not able to make it work yet. | 16:21 |
*** manuvakery has joined #openstack-keystone | 17:59 | |
*** carthaca has quit IRC | 18:00 | |
openstackgerrit | Merged openstack/keystone master: Support regexes in whitelists/blacklists https://review.opendev.org/730423 | 20:03 |
*** manuvakery has quit IRC | 20:09 | |
*** vesper11 has quit IRC | 20:20 | |
*** vesper11 has joined #openstack-keystone | 20:21 | |
*** xek_ has joined #openstack-keystone | 20:57 | |
sri_ | lbragstad: quick question, is policy.v3cloudsample.json deprecated ? | 21:00 |
*** raildo has quit IRC | 21:00 | |
lbragstad | sri_ yes - it's technically obsolete in newer branches because we've improved the policy checks | 21:01 |
sri_ | lbragstad: ack, I was trying to create domain admin, where domain admin can only manage projects and users within the domain, to archive that do i have to create custom policy's ? | 21:03 |
lbragstad | sri_ it depends on the release you're using | 21:06 |
lbragstad | i think that's supported with stein - if you explicitly opt into using the new policies | 21:07 |
sri_ | lbragstad: I am using ussuri release | 21:07 |
lbragstad | ok - then you should be able to use the new policies | 21:08 |
lbragstad | you might need to set https://docs.openstack.org/oslo.policy/latest/configuration/index.html#oslo_policy.enforce_new_defaults and https://docs.openstack.org/oslo.policy/latest/configuration/index.html#oslo_policy.enforce_scope to True in your keystone.conf | 21:09 |
sri_ | lbragstad: I was adding enforce_scope = True option as knikolla suggested, with that option enabled even admin user also not able to create user or domains | 21:09 |
lbragstad | sri_ are you using a system-scoped token? | 21:10 |
lbragstad | or are you using a project-scoped token? | 21:10 |
sri_ | lbragstad: I am not sure, this my rc file http://paste.openstack.org/show/796027/ | 21:11 |
lbragstad | sri_ that's going to ask keystone for a project-scoped token, which isn't going to work if you want to opt into the new behavior | 21:12 |
lbragstad | you're going to need to set OS_SYSTEM_SCOPE=all instead of OS_PROJECT_NAME | 21:13 |
lbragstad | or you can use a clouds.yaml file | 21:13 |
sri_ | I see, I believe horizion doesn't work with new policies right ? | 21:14 |
sri_ | lbragstad: ^ | 21:15 |
lbragstad | sri_ correct, that work is still pending | 21:16 |
sri_ | lbragstad: understood, you saved my day, Thank you π | 21:18 |
lbragstad | sri_ were you able to get it working? | 21:18 |
sri_ | lbragstad: not yet, testing now ! | 21:19 |
*** markvoelker has joined #openstack-keystone | 21:23 | |
*** markvoelker has quit IRC | 21:26 | |
sri_ | lbragstad: with system-scoped token I am able to create users,projects and domains | 21:32 |
*** markvoelker has joined #openstack-keystone | 21:33 | |
lbragstad | sri_ cool - good deal | 21:34 |
*** markvoelker has quit IRC | 21:38 | |
lbragstad | knikolla yes - i think you got that right (just following up on this) | 21:41 |
openstackgerrit | Colleen Murphy proposed openstack/keystone-tempest-plugin master: WIP/PoC:Add RBAC tests https://review.opendev.org/686305 | 21:44 |
sri_ | lbragstad: sorry for silly question, I've created new domain and user with admin role, http://paste.openstack.org/show/796030/ , new domain admin user can't create any project's or users | 21:48 |
lbragstad | sri_ are they using a domain scoped token? | 21:48 |
sri_ | oh, no | 21:49 |
sri_ | lbragstad: I've added OS_DOMAIN_SCOPE=lab to rc, file now I am getting The service catalog is empty. | 21:52 |
sri_ | lbragstad: keystone log's : http://paste.openstack.org/show/796031/ | 22:06 |
lbragstad | sri_ i think you need to use OS_DOMAIN_NAME | 22:11 |
lbragstad | and not OS_DOMAIN_SCOPE | 22:11 |
sri_ | lbragstad: sorry, yes you're right | 22:14 |
sri_ | lbragstad: everything is working as i expected π | 22:15 |
sri_ | lbragstad: let me say it again, you saved my day, Thank you π | 22:15 |
sri_ | lbragstad: one small issue, I can create project and users but not able to assign any role to users with in the domain, is the expected behavior ? | 22:22 |
sri_ | lbragstad: do I have add to the role's to user before enabling "enforce_scope = True" ! | 22:37 |
*** rcernin has joined #openstack-keystone | 22:43 | |
*** rcernin has quit IRC | 22:47 | |
*** rcernin has joined #openstack-keystone | 22:54 | |
sri_ | lbragstad: also when run the openstack network list in the new domain , it's showing default domain private network and router, I think it not suppose show other domain's resources right ? | 22:58 |
*** tkajinam has joined #openstack-keystone | 23:02 | |
*** gyee has quit IRC | 23:16 | |
*** hoonetorg has quit IRC | 23:16 | |
*** irclogbot_3 has quit IRC | 23:16 | |
*** gyee has joined #openstack-keystone | 23:22 | |
*** hoonetorg has joined #openstack-keystone | 23:22 | |
*** irclogbot_3 has joined #openstack-keystone | 23:22 | |
lbragstad | sri_ role assignments might not work unless you're using domain specific roles | 23:46 |
lbragstad | but i'd need to double check | 23:46 |
lbragstad | also neutron and other services are in the process of adopting all of this, so behavior is going to vary | 23:46 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!