opendevreview | Alexandre arents proposed openstack/keystone master: Federation: add support for projects_json assertion https://review.opendev.org/c/openstack/keystone/+/844098 | 06:16 |
---|---|---|
*** whoami-rajat__ is now known as whoami-rajat | 07:35 | |
opendevreview | Alexandre arents proposed openstack/keystone master: Federation: add support for projects_json assertion https://review.opendev.org/c/openstack/keystone/+/844098 | 08:09 |
opendevreview | Takashi Kajinami proposed openstack/keystonemiddleware master: setup.cfg: Replace dashes by underscores https://review.opendev.org/c/openstack/keystonemiddleware/+/827994 | 11:18 |
*** dviroel|afk is now known as dviroel | 12:21 | |
*** dviroel_ is now known as dviroel | 13:15 | |
*** dviroel is now known as dviroel|lunch | 15:08 | |
*** dviroel|lunch is now known as dviroel | 16:20 | |
pas-ha[m] | hi all, I have a question about app creds - are they supported for federated users? I map a user to a group that has roles on a project. I can see the user created in the appropriate domain, but I do not see any roles for this user via `openstack role assignment list --user` and this user can not create app creds - keystone fails with smth like "no roles found for user or group <uuid> on project,domain or system <uuid>"... | 17:28 |
pas-ha[m] | running OpenStack Victoria | 17:29 |
pas-ha[m] | I also do not see the user in the group when I run `openstack group contains ...` | 17:29 |
pas-ha[m] | at the same time when I do `openstack token issue --debug` I can see a normal response with roles inside | 17:36 |
pas-ha[m] | and I can get a token alright or login to Horizon | 17:36 |
gmann | dmendiza[m]: knikolla[m] need review in this keystone-temepst-plugin stable jobs patch https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/838070 | 18:14 |
*** timburke_ is now known as timburke | 20:59 | |
*** dviroel is now known as dviroel|out | 21:34 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!