*** lifeless_ is now known as lifeless | 08:41 | |
noonedeadpunk | hey! I'm looking into usage of service_token_roles, but I'm not quite sure I see whole design behind this. All services use `service` role as a defult, but I don't think there's such default role in keystone? and `admin` role can't be used as implied role as well? | 10:44 |
---|---|---|
noonedeadpunk | So basically each service user must be assigned to `admin` and `service` roles? | 10:45 |
noonedeadpunk | And there's kind of no way to make it having only `service` without huge policies re-write? | 10:46 |
noonedeadpunk | well, policy re-write be minor, but it would be required for each service | 10:46 |
noonedeadpunk | what is recommended way to define roles for services? | 10:53 |
opendevreview | bieji proposed openstack/keystone master: https://www.python.org/dev/peps/pep-0506/, using standard library secrets function token_bytes replace with os.urandom https://review.opendev.org/c/openstack/keystone/+/822767 | 15:38 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!