Thursday, 2024-09-12

cardoeSo looking at the keystoneauth docs and the OIDC examples aren't as fleshed out. Wondering if anyone's got any other examples. I've seen OVH's and the whole discovery URL, secret id and secret key feels pretty awkward vs other OIDC usage like kube-login with Kubernetes for example. I've locally played with dex and used vexxhost's websso plugin which is definitely a smoother experience but wanted stock.00:17
*** __ministry is now known as Guest321501:18
opendevreviewOpenStack Proposal Bot proposed openstack/keystone master: Imported Translations from Zanata  https://review.opendev.org/c/openstack/keystone/+/92446003:36
gtemacardoe, you are right and this is the same observation we have done. We overall recognized structural challenges when federating OpenStack and next PTG are going to discuss deeper a way forward to improve this04:56
jrossercardoe: it’s not necessary to need the secret id/key in the client particularly for cli use.07:02
jrosserI would like to see what is already done in 3rd party keystoneauth plugins for websso brought into the stock client07:07
opendevreviewMerged openstack/oslo.limit master: Update master for stable/2024.2  https://review.opendev.org/c/openstack/oslo.limit/+/92818810:24
opendevreviewMerged openstack/oslo.policy master: Update master for stable/2024.2  https://review.opendev.org/c/openstack/oslo.policy/+/92820910:54
opendevreviewOpenStack Release Bot proposed openstack/keystone master: Update master for stable/2024.2  https://review.opendev.org/c/openstack/keystone/+/92910214:09
cardoeSo with the project hierarchy bits... there's not a way to federate in a user and give that user permissions to all projects in a domain?23:00
cardoeI played around with creating a group and giving that group a role on the domain but it didn't seem to work.23:00

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!