*** zzzeek has quit IRC | 00:06 | |
*** zzzeek has joined #openstack-keystone | 00:08 | |
*** zzzeek has quit IRC | 00:24 | |
*** spatel has joined #openstack-keystone | 00:24 | |
*** zzzeek has joined #openstack-keystone | 00:29 | |
*** spatel has quit IRC | 00:29 | |
*** zzzeek has quit IRC | 00:34 | |
*** zzzeek has joined #openstack-keystone | 00:35 | |
*** hemna has quit IRC | 01:01 | |
*** hemna has joined #openstack-keystone | 01:02 | |
*** openstackgerrit has joined #openstack-keystone | 01:08 | |
openstackgerrit | Ghanshyam Mann proposed openstack/oslo.policy master: [goal] Migrate testing to ubuntu focal https://review.opendev.org/744317 | 01:08 |
---|---|---|
*** gary_perkins_ has quit IRC | 01:47 | |
*** hoonetorg has quit IRC | 01:47 | |
*** hoonetorg has joined #openstack-keystone | 01:48 | |
*** gary_perkins has joined #openstack-keystone | 01:48 | |
*** spatel has joined #openstack-keystone | 02:21 | |
*** zzzeek has quit IRC | 02:47 | |
*** zzzeek has joined #openstack-keystone | 02:51 | |
*** rcernin has quit IRC | 02:59 | |
*** rcernin has joined #openstack-keystone | 03:13 | |
*** zzzeek has quit IRC | 03:19 | |
*** zzzeek has joined #openstack-keystone | 03:21 | |
*** vishalmanchanda has joined #openstack-keystone | 03:52 | |
openstackgerrit | Zihao Wang proposed openstack/python-keystoneclient master: trivial: Drop os-testr https://review.opendev.org/750270 | 03:52 |
*** zzzeek has quit IRC | 04:03 | |
*** zzzeek has joined #openstack-keystone | 04:05 | |
*** whoami-rajat__ has joined #openstack-keystone | 04:15 | |
*** evrardjp has quit IRC | 04:33 | |
*** evrardjp has joined #openstack-keystone | 04:33 | |
*** spatel has quit IRC | 04:37 | |
*** manuvakery has joined #openstack-keystone | 05:39 | |
*** xek has joined #openstack-keystone | 05:40 | |
*** xek has quit IRC | 06:02 | |
*** zzzeek has quit IRC | 06:02 | |
*** zzzeek has joined #openstack-keystone | 06:03 | |
*** jaosorior has quit IRC | 06:14 | |
*** zzzeek has quit IRC | 06:22 | |
*** zzzeek has joined #openstack-keystone | 06:24 | |
*** shyamb has joined #openstack-keystone | 07:13 | |
*** bengates has joined #openstack-keystone | 07:14 | |
*** shyam89 has joined #openstack-keystone | 07:41 | |
*** shyamb has quit IRC | 07:43 | |
*** rcernin has quit IRC | 08:00 | |
*** shyamb has joined #openstack-keystone | 08:11 | |
*** shyam89 has quit IRC | 08:14 | |
*** zzzeek has quit IRC | 08:16 | |
*** zzzeek has joined #openstack-keystone | 08:17 | |
*** zzzeek has quit IRC | 08:47 | |
*** zzzeek has joined #openstack-keystone | 08:50 | |
*** shyamb has quit IRC | 10:13 | |
*** yuxin_ has quit IRC | 10:21 | |
*** shyamb has joined #openstack-keystone | 10:22 | |
*** yuxin_ has joined #openstack-keystone | 10:27 | |
*** shyam89 has joined #openstack-keystone | 10:33 | |
*** shyamb has quit IRC | 10:35 | |
*** yuxin_ has quit IRC | 10:44 | |
*** shyam89 has quit IRC | 10:47 | |
*** jaosorior has joined #openstack-keystone | 10:48 | |
*** zzzeek has quit IRC | 10:48 | |
*** shyamb has joined #openstack-keystone | 10:50 | |
*** zzzeek has joined #openstack-keystone | 10:50 | |
*** yuxin_ has joined #openstack-keystone | 10:57 | |
*** dave-mccowan has joined #openstack-keystone | 10:59 | |
*** dave-mccowan has quit IRC | 11:12 | |
*** dave-mccowan has joined #openstack-keystone | 11:13 | |
*** xek has joined #openstack-keystone | 11:36 | |
*** shyamb has quit IRC | 11:43 | |
*** shyamb has joined #openstack-keystone | 11:45 | |
openstackgerrit | Hervé Beraud proposed openstack/oslo.limit master: Adding pre-commit https://review.opendev.org/742134 | 11:48 |
*** raildo has joined #openstack-keystone | 12:06 | |
*** shyamb has quit IRC | 12:11 | |
*** redrobot has joined #openstack-keystone | 12:17 | |
openstackgerrit | OpenStack Release Bot proposed openstack/pycadf master: Add Python3 wallaby unit tests https://review.opendev.org/750341 | 12:28 |
mnaser | knikolla: have you been able to get something like openstack's cli to be usable with oidc _without_ storing any credentials? | 12:50 |
mnaser | i.e. offline tokens type of thing | 12:50 |
*** xek has quit IRC | 12:50 | |
mnaser | this is mostly for auth against gsuite | 12:51 |
*** Luzi has joined #openstack-keystone | 12:55 | |
*** lbragstad has joined #openstack-keystone | 13:01 | |
knikolla | mnaser: it should be doable, but I haven’t tried. | 13:06 |
mnaser | knikolla: i just found https://github.com/IFCA/keystoneauth-oidc/blob/master/keystoneauth_oidc/plugin.py#L257-L282 | 13:07 |
mnaser | knikolla: i really wish i didn't have to run apache just to be able to do this though :( oh well | 13:07 |
*** beekneemech is now known as bnemec | 13:34 | |
*** Luzi has quit IRC | 13:47 | |
*** xek has joined #openstack-keystone | 13:56 | |
*** jaosorior has quit IRC | 14:16 | |
*** tkajinam has quit IRC | 14:43 | |
jrosser | mnaser: we did that without an Apache | 14:54 |
mnaser | jrosser: something like a oidc proxy? | 14:54 |
jrosser | this is for openstack cli with oidc? | 14:55 |
mnaser | jrosser: correct | 14:55 |
jrosser | just a mo, on my phone :/ | 14:56 |
*** xek has quit IRC | 15:05 | |
jrosser | mnaser: I think actually we did exactly what is in your link ^^ | 15:05 |
*** mailingsam has joined #openstack-keystone | 15:17 | |
mailingsam | Hi All, GM, do you know why keystone project id is not exposed by keystone project create post api? it automatically assigns a unique id, can we allow the API to allow project id and if not provided, create a unique ID? | 15:25 |
*** jmlowe has quit IRC | 15:30 | |
*** jmlowe has joined #openstack-keystone | 15:32 | |
knikolla | mailingsam: that is something that has been proposed a few years ago, read the spec here and its comments for more historical context. https://review.opendev.org/#/c/323499/ | 15:45 |
mnaser | jrosser: but what about horizon ? | 15:48 |
mnaser | that still needs it eh | 15:49 |
mailingsam | Thanks knikolla checking | 16:07 |
jrosser | mnaser: as far as I know yes | 16:14 |
mnaser | jrosser: im wondering if running an oidc proxy might help as a sidecar | 16:14 |
jrosser | we had super weird stuff with HA | 16:15 |
mnaser | jrosser: ah right, session needs to be handled across all of them | 16:16 |
jrosser | needed the apache module to talk to memcached | 16:16 |
mnaser | jrosser: i wonder if something like this can work like https://github.com/oauth2-proxy/oauth2-proxy | 16:18 |
*** bengates has quit IRC | 16:20 | |
jrosser | isn’t keystone more involved than just putting a proxy in front, like the federated user mappings and such are inside keystone itself | 16:21 |
*** vishalmanchanda has quit IRC | 16:21 | |
mnaser | jrosser: right but the ISS needs to still make it's way there i guess | 16:21 |
mnaser | jrosser: it seems like openid auth is relying on 'mappings' anyways | 16:30 |
*** vishakha has joined #openstack-keystone | 16:31 | |
*** ddorahee has joined #openstack-keystone | 16:31 | |
mnaser | so really as long as we pass remote user and issuer it'll be fine | 16:31 |
knikolla | reminder, meeting in ~9 minutes in #openstack-meeting-alt | 16:51 |
*** bnemec has quit IRC | 16:52 | |
*** bnemec has joined #openstack-keystone | 17:02 | |
*** gyee has joined #openstack-keystone | 17:33 | |
*** ddorahee has quit IRC | 17:38 | |
*** mailingsam has quit IRC | 18:15 | |
*** viks____ has quit IRC | 18:58 | |
*** manuvakery has quit IRC | 18:59 | |
*** xek has joined #openstack-keystone | 19:52 | |
*** whoami-rajat__ has quit IRC | 20:14 | |
*** yuxin_ has quit IRC | 20:14 | |
*** zzzeek has quit IRC | 20:16 | |
*** zzzeek has joined #openstack-keystone | 20:17 | |
*** yuxin_ has joined #openstack-keystone | 20:25 | |
*** vishakha has quit IRC | 21:00 | |
*** xek has quit IRC | 21:41 | |
*** raildo has quit IRC | 21:43 | |
gmann | knikolla: can you review this ? need for Focal migration goal - https://review.opendev.org/#/c/743116/ | 21:43 |
knikolla | gmann: done | 22:51 |
gmann | knikolla thanks | 22:52 |
*** tkajinam has joined #openstack-keystone | 22:57 | |
*** tkajinam has quit IRC | 22:57 | |
*** tkajinam has joined #openstack-keystone | 22:58 | |
*** rcernin has joined #openstack-keystone | 23:02 | |
*** zzzeek has quit IRC | 23:33 | |
*** zzzeek has joined #openstack-keystone | 23:35 | |
*** kmalloc has joined #openstack-keystone | 23:37 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!