| *** tosky has quit IRC | 00:00 | |
| *** bengates has joined #openstack-keystone | 00:50 | |
| *** bengates has quit IRC | 00:56 | |
| *** hamalq has quit IRC | 00:56 | |
| *** cp- has quit IRC | 01:58 | |
| *** cp- has joined #openstack-keystone | 02:04 | |
| *** rcernin has quit IRC | 02:06 | |
| *** zzzeek has quit IRC | 02:23 | |
| *** zzzeek has joined #openstack-keystone | 02:24 | |
| *** bengates has joined #openstack-keystone | 02:32 | |
| *** bengates has quit IRC | 02:38 | |
| *** rcernin has joined #openstack-keystone | 02:38 | |
| *** zzzeek has quit IRC | 02:44 | |
| *** cp- has quit IRC | 02:45 | |
| *** zzzeek has joined #openstack-keystone | 02:46 | |
| *** cp- has joined #openstack-keystone | 02:46 | |
| *** zzzeek has quit IRC | 02:51 | |
| *** zzzeek has joined #openstack-keystone | 02:53 | |
| *** zzzeek has quit IRC | 03:13 | |
| *** zzzeek has joined #openstack-keystone | 03:15 | |
| *** bengates has joined #openstack-keystone | 03:43 | |
| *** bengates has quit IRC | 03:49 | |
| *** timburke has quit IRC | 04:01 | |
| *** timburke has joined #openstack-keystone | 04:12 | |
| *** whoami-rajat has joined #openstack-keystone | 04:18 | |
| *** dviroel has quit IRC | 04:45 | |
| *** gyee has quit IRC | 05:20 | |
| *** yoctozepto0 has joined #openstack-keystone | 06:05 | |
| *** yoctozepto has quit IRC | 06:05 | |
| *** yoctozepto0 is now known as yoctozepto | 06:05 | |
| *** xek has joined #openstack-keystone | 07:16 | |
| *** rcernin has quit IRC | 07:22 | |
| *** rcernin has joined #openstack-keystone | 07:52 | |
| *** bengates has joined #openstack-keystone | 08:08 | |
| *** bengates has quit IRC | 08:11 | |
| *** bengates has joined #openstack-keystone | 08:12 | |
| *** bengates has quit IRC | 08:28 | |
| *** bengates has joined #openstack-keystone | 08:29 | |
| *** tosky has joined #openstack-keystone | 08:38 | |
| *** yoctozepto9 has joined #openstack-keystone | 09:55 | |
| *** jhesketh_ has joined #openstack-keystone | 09:57 | |
| *** yoctozepto has quit IRC | 10:03 | |
| *** zzzeek has quit IRC | 10:03 | |
| *** jhesketh has quit IRC | 10:03 | |
| *** irclogbot_0 has quit IRC | 10:03 | |
| *** yoctozepto9 is now known as yoctozepto | 10:03 | |
| *** zzzeek has joined #openstack-keystone | 10:05 | |
| *** irclogbot_0 has joined #openstack-keystone | 10:07 | |
| *** dviroel has joined #openstack-keystone | 11:03 | |
| stephenfin | knikolla: I think I need your ack for a new release of ldappool https://review.opendev.org/c/openstack/releases/+/777584 if you have a moment | 12:49 |
|---|---|---|
| *** Luzi has joined #openstack-keystone | 13:01 | |
| *** bengates has quit IRC | 13:14 | |
| *** bengates has joined #openstack-keystone | 13:20 | |
| *** tkajinam has quit IRC | 13:36 | |
| *** iurygregory has quit IRC | 13:43 | |
| *** iurygregory has joined #openstack-keystone | 13:44 | |
| *** gshippey has joined #openstack-keystone | 13:57 | |
| *** yoctozepto has quit IRC | 14:01 | |
| *** yoctozepto has joined #openstack-keystone | 14:01 | |
| *** Luzi has quit IRC | 14:28 | |
| *** whoami-rajat has quit IRC | 14:38 | |
| *** zzzeek has quit IRC | 14:51 | |
| *** zzzeek has joined #openstack-keystone | 14:53 | |
| *** jmlowe has quit IRC | 14:54 | |
| *** jmlowe has joined #openstack-keystone | 15:15 | |
| *** yuxing has joined #openstack-keystone | 15:37 | |
| *** bengates has quit IRC | 17:17 | |
| *** bengates has joined #openstack-keystone | 17:47 | |
| *** bengates has quit IRC | 17:52 | |
| *** bengates has joined #openstack-keystone | 18:28 | |
| *** bengates has quit IRC | 18:34 | |
| *** raildo has joined #openstack-keystone | 19:07 | |
| *** zzzeek has quit IRC | 19:29 | |
| *** zzzeek has joined #openstack-keystone | 19:29 | |
| *** hamalq has joined #openstack-keystone | 20:02 | |
| andrewbogott | I'm trying to figure out about scoped roles in Keystone Train. I had the impression that I could give a user the admin role in system=all scope and then it would be able to see everything in every project but that seems to not be the case in my test install. Is here some flag I have to set to enable scoped roles? | 20:23 |
| andrewbogott | I was expecting this to be the be-all/end-all: | 20:23 |
| andrewbogott | https://www.irccloud.com/pastebin/KS8RTNdm/ | 20:23 |
| andrewbogott | but that user still can't do anything at all | 20:23 |
| gagehugo | https://docs.openstack.org/keystone/train/configuration/samples/keystone-conf.html | 20:29 |
| gagehugo | enforce_scope under [oslo_policy] | 20:29 |
| gagehugo | system scope is generally reserved for more "system" roles: https://docs.openstack.org/keystone/latest/admin/tokens-overview.html#system-scoped-tokens | 20:35 |
| andrewbogott | thank you! Trying... | 20:35 |
| andrewbogott | yeah — right now I'm just experimenting. I have a system user that's hacked into every project and I would love to have it just work without that :) | 20:35 |
| *** lbragstad_ has joined #openstack-keystone | 20:35 | |
| *** raildo_ has joined #openstack-keystone | 20:35 | |
| *** beekneemech has joined #openstack-keystone | 20:35 | |
| *** mugsie_ has joined #openstack-keystone | 20:36 | |
| *** benj_- has joined #openstack-keystone | 20:36 | |
| *** zigo_ has joined #openstack-keystone | 20:36 | |
| *** adriant has quit IRC | 20:36 | |
| *** benj_ has quit IRC | 20:36 | |
| *** zigo has quit IRC | 20:36 | |
| *** gary_perkins has quit IRC | 20:36 | |
| *** stephenfin has quit IRC | 20:36 | |
| andrewbogott | hm, I'm still missing something | 20:36 |
| *** melwitt has quit IRC | 20:36 | |
| *** gregwork has quit IRC | 20:36 | |
| *** mugsie has quit IRC | 20:36 | |
| *** melwitt has joined #openstack-keystone | 20:36 | |
| *** benj_- is now known as benj_ | 20:37 | |
| *** jmccrory_ has joined #openstack-keystone | 20:37 | |
| *** tosky_ has joined #openstack-keystone | 20:37 | |
| *** jmccrory has quit IRC | 20:37 | |
| *** jmccrory_ is now known as jmccrory | 20:38 | |
| *** bbobrov has quit IRC | 20:38 | |
| *** cp- has quit IRC | 20:38 | |
| *** raildo has quit IRC | 20:38 | |
| *** zzzeek has quit IRC | 20:40 | |
| *** jrosser has quit IRC | 20:40 | |
| *** tosky has quit IRC | 20:40 | |
| *** noonedeadpunk has quit IRC | 20:40 | |
| *** trident has quit IRC | 20:40 | |
| *** ricolin has quit IRC | 20:40 | |
| *** bnemec has quit IRC | 20:40 | |
| *** jrosser has joined #openstack-keystone | 20:40 | |
| *** mnasiadka has quit IRC | 20:41 | |
| *** zzzeek has joined #openstack-keystone | 20:41 | |
| *** bbobrov has joined #openstack-keystone | 20:41 | |
| andrewbogott | odd, I've removed my policy.yaml file entirely but still get a deprecation warning. | 20:41 |
| andrewbogott | Is that a clue? | 20:41 |
| *** tosky_ is now known as tosky | 20:42 | |
| *** lifeless_ has joined #openstack-keystone | 20:42 | |
| *** trident has joined #openstack-keystone | 20:42 | |
| *** mnasiadka has joined #openstack-keystone | 20:42 | |
| *** dasp has quit IRC | 20:43 | |
| *** lifeless has quit IRC | 20:43 | |
| *** lbragstad has quit IRC | 20:43 | |
| *** cp- has joined #openstack-keystone | 20:43 | |
| *** dasp has joined #openstack-keystone | 20:45 | |
| *** xek_ has joined #openstack-keystone | 20:54 | |
| *** xek has quit IRC | 20:56 | |
| andrewbogott | gagehugo: do you have time to walk me through this a bit? I have "identity:list_endpoints": "" and my user has system=all admin and I have enforce_scope = True in keystone.conf | 20:58 |
| andrewbogott | and yet | 20:58 |
| andrewbogott | https://www.irccloud.com/pastebin/1SFJwulD/ | 20:58 |
| andrewbogott | Am I totally misunderstanding how this is meant to work? | 20:59 |
| *** xek_ has quit IRC | 21:05 | |
| gagehugo | I think you need to specify system scope in your clouds.yaml, but Im struggling to find documentation atm | 21:06 |
| andrewbogott | I'm not sure I know what a 'clouds.yaml' is — do you mean in the custom policy? | 21:07 |
| andrewbogott | For what it's worth, I tried removing my policy.yaml and letting it fall back on all defaults and get the same behavior | 21:08 |
| andrewbogott | thank you for looking! | 21:10 |
| gagehugo | whatever credentials you are using for "openstack" | 21:10 |
| gagehugo | openstackcli | 21:10 |
| gagehugo | https://docs.openstack.org/python-openstackclient/train/configuration/index.html | 21:11 |
| *** rcernin has quit IRC | 21:12 | |
| openstackgerrit | Ben Nemec proposed openstack/oslo.policy master: Reinstate double deprecation test logic https://review.opendev.org/c/openstack/oslo.policy/+/777682 | 21:12 |
| andrewbogott | oh, I see… I'm doing all this via environment variables but it's likely equivalent | 21:15 |
| andrewbogott | I gave my 'testadmin' user admin role in a single project and I can access things there. So I'm convinced that I'm not just making a typo in the password :) | 21:17 |
| gagehugo | Try setting OS_SYSTEM_SCOPE to "all" | 21:17 |
| andrewbogott | 'k | 21:19 |
| andrewbogott | no change | 21:19 |
| *** xek has joined #openstack-keystone | 21:21 | |
| gagehugo | might need to make sure OS_PROJECT_* are all unset | 21:23 |
| *** xek has quit IRC | 21:25 | |
| gagehugo | for that "testadmin" user | 21:25 |
| andrewbogott | that did it | 21:25 |
| gagehugo | \o/ | 21:25 |
| andrewbogott | The fact that that works suggests that I don't understand what system scope actually means | 21:26 |
| andrewbogott | Like, having system admin doesn't confer admin on projects? | 21:26 |
| gagehugo | I've not used it much myself yet, but it's more for operations that don't necessarily involve projects/domains | 21:29 |
| gagehugo | modifying endpoints, service management, or listing information about hypervisors | 21:31 |
| andrewbogott | yep, that makes sense as a scope | 21:31 |
| gagehugo | avoiding giving someone "admin" in a project just so they can tweak those things | 21:31 |
| andrewbogott | I just read the sentence 'System administrators are allowed to manage every resource in keystone' and thought they really meant it | 21:31 |
| andrewbogott | I guess maybe what I want is 'admin' on the default domain | 21:31 |
| andrewbogott | hm, nope | 21:32 |
| andrewbogott | I kind of thought that the original use case for scoped roles was to provide a univeral reader. If a system reader can only read system things but not things /in/ the system, and a domain reader can only read domain things but not things /in/ the domain... | 21:34 |
| andrewbogott | then I have misunderstood what this years-long initiative was about :( | 21:34 |
| andrewbogott | But, anyway, not your problem! Thank you for helping me sort this out, I will read some more docs and code and see if what I need is supported. | 21:34 |
| gagehugo | our docs need some improving on system scopes, I had to dig into the osc code to see what value it was looking for | 21:39 |
| *** rcernin has joined #openstack-keystone | 22:09 | |
| *** rcernin has quit IRC | 22:15 | |
| *** rcernin has joined #openstack-keystone | 22:15 | |
| *** lbragstad_ is now known as lbragstad | 22:26 | |
| *** adriant has joined #openstack-keystone | 22:54 | |
| *** tkajinam has joined #openstack-keystone | 22:58 | |
| adriant | knikolla: any chance of getting https://review.opendev.org/c/openstack/keystone-specs/+/618144 looked at again? :) | 22:59 |
| *** gshippey has quit IRC | 23:33 | |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!