*** tosky has quit IRC | 00:00 | |
*** bengates has joined #openstack-keystone | 00:50 | |
*** bengates has quit IRC | 00:56 | |
*** hamalq has quit IRC | 00:56 | |
*** cp- has quit IRC | 01:58 | |
*** cp- has joined #openstack-keystone | 02:04 | |
*** rcernin has quit IRC | 02:06 | |
*** zzzeek has quit IRC | 02:23 | |
*** zzzeek has joined #openstack-keystone | 02:24 | |
*** bengates has joined #openstack-keystone | 02:32 | |
*** bengates has quit IRC | 02:38 | |
*** rcernin has joined #openstack-keystone | 02:38 | |
*** zzzeek has quit IRC | 02:44 | |
*** cp- has quit IRC | 02:45 | |
*** zzzeek has joined #openstack-keystone | 02:46 | |
*** cp- has joined #openstack-keystone | 02:46 | |
*** zzzeek has quit IRC | 02:51 | |
*** zzzeek has joined #openstack-keystone | 02:53 | |
*** zzzeek has quit IRC | 03:13 | |
*** zzzeek has joined #openstack-keystone | 03:15 | |
*** bengates has joined #openstack-keystone | 03:43 | |
*** bengates has quit IRC | 03:49 | |
*** timburke has quit IRC | 04:01 | |
*** timburke has joined #openstack-keystone | 04:12 | |
*** whoami-rajat has joined #openstack-keystone | 04:18 | |
*** dviroel has quit IRC | 04:45 | |
*** gyee has quit IRC | 05:20 | |
*** yoctozepto0 has joined #openstack-keystone | 06:05 | |
*** yoctozepto has quit IRC | 06:05 | |
*** yoctozepto0 is now known as yoctozepto | 06:05 | |
*** xek has joined #openstack-keystone | 07:16 | |
*** rcernin has quit IRC | 07:22 | |
*** rcernin has joined #openstack-keystone | 07:52 | |
*** bengates has joined #openstack-keystone | 08:08 | |
*** bengates has quit IRC | 08:11 | |
*** bengates has joined #openstack-keystone | 08:12 | |
*** bengates has quit IRC | 08:28 | |
*** bengates has joined #openstack-keystone | 08:29 | |
*** tosky has joined #openstack-keystone | 08:38 | |
*** yoctozepto9 has joined #openstack-keystone | 09:55 | |
*** jhesketh_ has joined #openstack-keystone | 09:57 | |
*** yoctozepto has quit IRC | 10:03 | |
*** zzzeek has quit IRC | 10:03 | |
*** jhesketh has quit IRC | 10:03 | |
*** irclogbot_0 has quit IRC | 10:03 | |
*** yoctozepto9 is now known as yoctozepto | 10:03 | |
*** zzzeek has joined #openstack-keystone | 10:05 | |
*** irclogbot_0 has joined #openstack-keystone | 10:07 | |
*** dviroel has joined #openstack-keystone | 11:03 | |
stephenfin | knikolla: I think I need your ack for a new release of ldappool https://review.opendev.org/c/openstack/releases/+/777584 if you have a moment | 12:49 |
---|---|---|
*** Luzi has joined #openstack-keystone | 13:01 | |
*** bengates has quit IRC | 13:14 | |
*** bengates has joined #openstack-keystone | 13:20 | |
*** tkajinam has quit IRC | 13:36 | |
*** iurygregory has quit IRC | 13:43 | |
*** iurygregory has joined #openstack-keystone | 13:44 | |
*** gshippey has joined #openstack-keystone | 13:57 | |
*** yoctozepto has quit IRC | 14:01 | |
*** yoctozepto has joined #openstack-keystone | 14:01 | |
*** Luzi has quit IRC | 14:28 | |
*** whoami-rajat has quit IRC | 14:38 | |
*** zzzeek has quit IRC | 14:51 | |
*** zzzeek has joined #openstack-keystone | 14:53 | |
*** jmlowe has quit IRC | 14:54 | |
*** jmlowe has joined #openstack-keystone | 15:15 | |
*** yuxing has joined #openstack-keystone | 15:37 | |
*** bengates has quit IRC | 17:17 | |
*** bengates has joined #openstack-keystone | 17:47 | |
*** bengates has quit IRC | 17:52 | |
*** bengates has joined #openstack-keystone | 18:28 | |
*** bengates has quit IRC | 18:34 | |
*** raildo has joined #openstack-keystone | 19:07 | |
*** zzzeek has quit IRC | 19:29 | |
*** zzzeek has joined #openstack-keystone | 19:29 | |
*** hamalq has joined #openstack-keystone | 20:02 | |
andrewbogott | I'm trying to figure out about scoped roles in Keystone Train. I had the impression that I could give a user the admin role in system=all scope and then it would be able to see everything in every project but that seems to not be the case in my test install. Is here some flag I have to set to enable scoped roles? | 20:23 |
andrewbogott | I was expecting this to be the be-all/end-all: | 20:23 |
andrewbogott | https://www.irccloud.com/pastebin/KS8RTNdm/ | 20:23 |
andrewbogott | but that user still can't do anything at all | 20:23 |
gagehugo | https://docs.openstack.org/keystone/train/configuration/samples/keystone-conf.html | 20:29 |
gagehugo | enforce_scope under [oslo_policy] | 20:29 |
gagehugo | system scope is generally reserved for more "system" roles: https://docs.openstack.org/keystone/latest/admin/tokens-overview.html#system-scoped-tokens | 20:35 |
andrewbogott | thank you! Trying... | 20:35 |
andrewbogott | yeah — right now I'm just experimenting. I have a system user that's hacked into every project and I would love to have it just work without that :) | 20:35 |
*** lbragstad_ has joined #openstack-keystone | 20:35 | |
*** raildo_ has joined #openstack-keystone | 20:35 | |
*** beekneemech has joined #openstack-keystone | 20:35 | |
*** mugsie_ has joined #openstack-keystone | 20:36 | |
*** benj_- has joined #openstack-keystone | 20:36 | |
*** zigo_ has joined #openstack-keystone | 20:36 | |
*** adriant has quit IRC | 20:36 | |
*** benj_ has quit IRC | 20:36 | |
*** zigo has quit IRC | 20:36 | |
*** gary_perkins has quit IRC | 20:36 | |
*** stephenfin has quit IRC | 20:36 | |
andrewbogott | hm, I'm still missing something | 20:36 |
*** melwitt has quit IRC | 20:36 | |
*** gregwork has quit IRC | 20:36 | |
*** mugsie has quit IRC | 20:36 | |
*** melwitt has joined #openstack-keystone | 20:36 | |
*** benj_- is now known as benj_ | 20:37 | |
*** jmccrory_ has joined #openstack-keystone | 20:37 | |
*** tosky_ has joined #openstack-keystone | 20:37 | |
*** jmccrory has quit IRC | 20:37 | |
*** jmccrory_ is now known as jmccrory | 20:38 | |
*** bbobrov has quit IRC | 20:38 | |
*** cp- has quit IRC | 20:38 | |
*** raildo has quit IRC | 20:38 | |
*** zzzeek has quit IRC | 20:40 | |
*** jrosser has quit IRC | 20:40 | |
*** tosky has quit IRC | 20:40 | |
*** noonedeadpunk has quit IRC | 20:40 | |
*** trident has quit IRC | 20:40 | |
*** ricolin has quit IRC | 20:40 | |
*** bnemec has quit IRC | 20:40 | |
*** jrosser has joined #openstack-keystone | 20:40 | |
*** mnasiadka has quit IRC | 20:41 | |
*** zzzeek has joined #openstack-keystone | 20:41 | |
*** bbobrov has joined #openstack-keystone | 20:41 | |
andrewbogott | odd, I've removed my policy.yaml file entirely but still get a deprecation warning. | 20:41 |
andrewbogott | Is that a clue? | 20:41 |
*** tosky_ is now known as tosky | 20:42 | |
*** lifeless_ has joined #openstack-keystone | 20:42 | |
*** trident has joined #openstack-keystone | 20:42 | |
*** mnasiadka has joined #openstack-keystone | 20:42 | |
*** dasp has quit IRC | 20:43 | |
*** lifeless has quit IRC | 20:43 | |
*** lbragstad has quit IRC | 20:43 | |
*** cp- has joined #openstack-keystone | 20:43 | |
*** dasp has joined #openstack-keystone | 20:45 | |
*** xek_ has joined #openstack-keystone | 20:54 | |
*** xek has quit IRC | 20:56 | |
andrewbogott | gagehugo: do you have time to walk me through this a bit? I have "identity:list_endpoints": "" and my user has system=all admin and I have enforce_scope = True in keystone.conf | 20:58 |
andrewbogott | and yet | 20:58 |
andrewbogott | https://www.irccloud.com/pastebin/1SFJwulD/ | 20:58 |
andrewbogott | Am I totally misunderstanding how this is meant to work? | 20:59 |
*** xek_ has quit IRC | 21:05 | |
gagehugo | I think you need to specify system scope in your clouds.yaml, but Im struggling to find documentation atm | 21:06 |
andrewbogott | I'm not sure I know what a 'clouds.yaml' is — do you mean in the custom policy? | 21:07 |
andrewbogott | For what it's worth, I tried removing my policy.yaml and letting it fall back on all defaults and get the same behavior | 21:08 |
andrewbogott | thank you for looking! | 21:10 |
gagehugo | whatever credentials you are using for "openstack" | 21:10 |
gagehugo | openstackcli | 21:10 |
gagehugo | https://docs.openstack.org/python-openstackclient/train/configuration/index.html | 21:11 |
*** rcernin has quit IRC | 21:12 | |
openstackgerrit | Ben Nemec proposed openstack/oslo.policy master: Reinstate double deprecation test logic https://review.opendev.org/c/openstack/oslo.policy/+/777682 | 21:12 |
andrewbogott | oh, I see… I'm doing all this via environment variables but it's likely equivalent | 21:15 |
andrewbogott | I gave my 'testadmin' user admin role in a single project and I can access things there. So I'm convinced that I'm not just making a typo in the password :) | 21:17 |
gagehugo | Try setting OS_SYSTEM_SCOPE to "all" | 21:17 |
andrewbogott | 'k | 21:19 |
andrewbogott | no change | 21:19 |
*** xek has joined #openstack-keystone | 21:21 | |
gagehugo | might need to make sure OS_PROJECT_* are all unset | 21:23 |
*** xek has quit IRC | 21:25 | |
gagehugo | for that "testadmin" user | 21:25 |
andrewbogott | that did it | 21:25 |
gagehugo | \o/ | 21:25 |
andrewbogott | The fact that that works suggests that I don't understand what system scope actually means | 21:26 |
andrewbogott | Like, having system admin doesn't confer admin on projects? | 21:26 |
gagehugo | I've not used it much myself yet, but it's more for operations that don't necessarily involve projects/domains | 21:29 |
gagehugo | modifying endpoints, service management, or listing information about hypervisors | 21:31 |
andrewbogott | yep, that makes sense as a scope | 21:31 |
gagehugo | avoiding giving someone "admin" in a project just so they can tweak those things | 21:31 |
andrewbogott | I just read the sentence 'System administrators are allowed to manage every resource in keystone' and thought they really meant it | 21:31 |
andrewbogott | I guess maybe what I want is 'admin' on the default domain | 21:31 |
andrewbogott | hm, nope | 21:32 |
andrewbogott | I kind of thought that the original use case for scoped roles was to provide a univeral reader. If a system reader can only read system things but not things /in/ the system, and a domain reader can only read domain things but not things /in/ the domain... | 21:34 |
andrewbogott | then I have misunderstood what this years-long initiative was about :( | 21:34 |
andrewbogott | But, anyway, not your problem! Thank you for helping me sort this out, I will read some more docs and code and see if what I need is supported. | 21:34 |
gagehugo | our docs need some improving on system scopes, I had to dig into the osc code to see what value it was looking for | 21:39 |
*** rcernin has joined #openstack-keystone | 22:09 | |
*** rcernin has quit IRC | 22:15 | |
*** rcernin has joined #openstack-keystone | 22:15 | |
*** lbragstad_ is now known as lbragstad | 22:26 | |
*** adriant has joined #openstack-keystone | 22:54 | |
*** tkajinam has joined #openstack-keystone | 22:58 | |
adriant | knikolla: any chance of getting https://review.opendev.org/c/openstack/keystone-specs/+/618144 looked at again? :) | 22:59 |
*** gshippey has quit IRC | 23:33 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!