*** tosky has quit IRC | 00:10 | |
*** hamalq has quit IRC | 00:26 | |
*** timburke_ has joined #openstack-keystone | 00:32 | |
*** timburke has quit IRC | 00:34 | |
*** timburke_ has quit IRC | 00:42 | |
*** kd has joined #openstack-keystone | 00:50 | |
*** k-s-dean has quit IRC | 00:53 | |
*** timburke has joined #openstack-keystone | 01:03 | |
johnsom | lbragstad_ Hi, so looking at: https://docs.openstack.org/keystone/latest/configuration/policy.html the policy identity:list_endpoints seems to limit it to "role:reader and system_scope:all". This means end users can no longer lookup the service endpoints? This seems to break bunch of openstackclient commands that first lookup the endpont. | 01:21 |
---|---|---|
johnsom | For example, in devstack the demo account can no longer see the endpoints: | 01:21 |
johnsom | https://www.irccloud.com/pastebin/B6Z2JzYz/ | 01:22 |
*** kd has quit IRC | 01:22 | |
lbragstad_ | johnsom i think that was also true in stable/queens, prior to the system-scope/secure rbac overhaul https://opendev.org/openstack/keystone/src/branch/stable/queens/keystone/common/policies/endpoint.py#L27 | 01:23 |
*** lbragstad_ is now known as lbragstad | 01:23 | |
johnsom | Hmm | 01:23 |
lbragstad | most end users typically get that information from GET /v3/auth/tokens | 01:24 |
lbragstad | or POST /v3/auth/tokens - since the tokens themselves contain service catalogs | 01:24 |
johnsom | https://www.irccloud.com/pastebin/pj8EzIUN/ | 01:24 |
johnsom | Admittedly I have not tried the designate OSC client using the demo account before, so I don't know how long this has been broken. | 01:25 |
johnsom | That is a good point, it is in the token response. I wonder why they are querying the list.... | 01:26 |
lbragstad | seems like that particular portion of the osc designate client was written to assume it was called as someone who could also call the endpoint API directly | 01:27 |
johnsom | I will look into the OSC code tomorrow | 01:27 |
lbragstad | (so - assumed to be called as an administrator?) | 01:27 |
johnsom | No idea | 01:27 |
lbragstad | strange - yeah, let me know if you need some help or what you find | 01:27 |
eandersson | Was just replying in qa | 01:51 |
eandersson | This is the same for us in rocky afaik | 01:51 |
eandersson | We always had to use openstack catalog list for "normal" users | 01:51 |
eandersson | I always assumed that endpoint list was just "unfiltered" list for "admins", while catalog list was a "filtered" view for normal users. | 01:58 |
*** redrobot2 has joined #openstack-keystone | 01:59 | |
*** redrobot has quit IRC | 02:03 | |
*** redrobot2 is now known as redrobot | 02:03 | |
*** rcernin has quit IRC | 03:22 | |
*** rcernin has joined #openstack-keystone | 03:33 | |
*** rcernin has quit IRC | 03:41 | |
*** rcernin has joined #openstack-keystone | 03:42 | |
*** vishalmanchanda has joined #openstack-keystone | 04:26 | |
*** manuvakery1 has joined #openstack-keystone | 04:38 | |
*** timburke has quit IRC | 05:28 | |
*** Luzi has joined #openstack-keystone | 05:44 | |
*** jaosorior has joined #openstack-keystone | 07:20 | |
*** rcernin has quit IRC | 08:11 | |
*** xek has joined #openstack-keystone | 08:32 | |
*** bengates has joined #openstack-keystone | 08:32 | |
*** bengates has quit IRC | 08:50 | |
*** bengates has joined #openstack-keystone | 08:51 | |
*** tosky has joined #openstack-keystone | 09:03 | |
*** rcernin has joined #openstack-keystone | 09:17 | |
*** rcernin_ has joined #openstack-keystone | 09:48 | |
*** rcernin has quit IRC | 09:55 | |
*** gshippey has joined #openstack-keystone | 10:09 | |
*** kd has joined #openstack-keystone | 10:31 | |
*** kd has quit IRC | 10:52 | |
*** rcernin_ has quit IRC | 11:32 | |
*** takamatsu has quit IRC | 11:57 | |
*** raildo has joined #openstack-keystone | 12:58 | |
*** k-s-dean has joined #openstack-keystone | 13:39 | |
*** raildo_ has joined #openstack-keystone | 14:08 | |
*** k-s-dean has quit IRC | 14:10 | |
*** k-s-dean has joined #openstack-keystone | 14:10 | |
*** raildo has quit IRC | 14:11 | |
*** vishalmanchanda has quit IRC | 14:25 | |
*** whoami-rajat_ has joined #openstack-keystone | 14:30 | |
*** vishalmanchanda has joined #openstack-keystone | 14:35 | |
*** Luzi has quit IRC | 16:03 | |
*** hamalq has joined #openstack-keystone | 16:31 | |
*** timburke has joined #openstack-keystone | 17:15 | |
*** gyee has joined #openstack-keystone | 17:29 | |
*** bengates has quit IRC | 17:55 | |
*** bengates has joined #openstack-keystone | 17:57 | |
*** bengates has quit IRC | 18:01 | |
*** whoami-rajat_ is now known as whoami-rajat | 18:18 | |
*** raildo__ has joined #openstack-keystone | 18:37 | |
*** k-s-dean has quit IRC | 18:40 | |
*** gyee has quit IRC | 18:46 | |
*** raildo_ has quit IRC | 18:46 | |
*** k-s-dean has joined #openstack-keystone | 18:50 | |
*** gyee has joined #openstack-keystone | 18:53 | |
*** k-s-dean has quit IRC | 18:56 | |
*** raildo_ has joined #openstack-keystone | 19:10 | |
*** raildo__ has quit IRC | 19:12 | |
*** raildo__ has joined #openstack-keystone | 19:13 | |
*** raildo_ has quit IRC | 19:16 | |
*** rcernin_ has joined #openstack-keystone | 19:26 | |
*** rcernin_ has quit IRC | 19:32 | |
*** vishalmanchanda has quit IRC | 19:35 | |
*** k-s-dean has joined #openstack-keystone | 19:41 | |
*** gmann is now known as gmann_afk | 19:41 | |
*** manuvakery1 has quit IRC | 19:56 | |
*** rcernin_ has joined #openstack-keystone | 19:57 | |
*** rcernin_ has quit IRC | 20:02 | |
*** rcernin_ has joined #openstack-keystone | 20:32 | |
*** rcernin_ has quit IRC | 20:37 | |
*** whoami-rajat has quit IRC | 20:40 | |
*** rcernin_ has joined #openstack-keystone | 20:50 | |
*** rcernin_ has quit IRC | 21:04 | |
*** rcernin_ has joined #openstack-keystone | 21:09 | |
*** rcernin_ has quit IRC | 21:15 | |
*** rcernin_ has joined #openstack-keystone | 21:41 | |
*** raildo__ has quit IRC | 22:03 | |
*** gshippey has quit IRC | 22:15 | |
*** gmann_afk is now known as gmann | 22:39 | |
*** k-s-dean has quit IRC | 22:50 | |
*** timburke_ has joined #openstack-keystone | 23:04 | |
*** timburke has quit IRC | 23:06 | |
*** k-s-dean has joined #openstack-keystone | 23:21 | |
*** timburke_ has quit IRC | 23:31 | |
*** timburke_ has joined #openstack-keystone | 23:31 | |
*** hamalq has quit IRC | 23:57 | |
*** hamalq has joined #openstack-keystone | 23:57 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!