Tuesday, 2025-11-25

*** mhen_ is now known as mhen02:30
opendevreviewGhanshyam proposed openstack/oslo.policy master: WIP: Remove enforce_scope config option  https://review.opendev.org/c/openstack/oslo.policy/+/96827102:36
opendevreviewQuentin GROLLEAU proposed openstack/keystone master: Add a new index on revocation_event table  https://review.opendev.org/c/openstack/keystone/+/92973608:02
opendevreviewArnaud Morin proposed openstack/keystone master: Apply sql db expand from 2025.02  https://review.opendev.org/c/openstack/keystone/+/96830009:22
opendevreviewArnaud Morin proposed openstack/keystone master: Rename the migration folder  https://review.opendev.org/c/openstack/keystone/+/96830109:22
amoringtema the glance thing that dmsimard[m] is talking about is: https://review.opendev.org/c/openstack/glance/+/96737112:38
amorinon our side, we are creating a lot of glance images (instances snapshots), so this increased a lot the revocation table size12:39
amorinif zigo is around, maybe he could explain the first index on https://review.opendev.org/c/openstack/keystone/+/929736 ?12:40
zigoI am. Reading.12:40
gtemaoh, that's interesting12:40
zigoWell, I believe the patch header says it all, no ?12:41
gtemazigo: it doesn't explain one of 2 indexes12:42
zigoI just asked my colleague, let's see what he says.12:44
zigoamorin: My colleague replied in the PR. Is this enough?13:20
amorinoh thanks, will check!13:24
opendevreviewTakashi Kajinami proposed openstack/oslo.policy master: Remove support for JSON format policy file  https://review.opendev.org/c/openstack/oslo.policy/+/92971513:45
opendevreviewTakashi Kajinami proposed openstack/oslo.policy master: Remove support for JSON format policy file  https://review.opendev.org/c/openstack/oslo.policy/+/92971513:48
opendevreviewTakashi Kajinami proposed openstack/oslo.policy master: Remove support for JSON format policy file  https://review.opendev.org/c/openstack/oslo.policy/+/92971513:49
Mc-Hi! Small question about federated users with mapped groups : while users seem to have most of the right privileges for the mapped groups when logging in from horizon, the users do not seem to be "actually" added to the groups in the databases (openstack group list --user does not show them) and the creation of application credential fails because (as reported in horizon)13:55
Mc-the user does not have the role assignment for the project, that it got from a mapped group at login - I'm absolutely not sure it's correct but it is as if the federated login issues a temporary token with the rights from the mapping, but does not actually grant them to the user - any idea how to circumvent this ?13:55
gtemaif you say groups are not updated for the user (note that for federated users it is an expiring group membership, not the permanent) - this would explain missing permission. Such group membership is only renewed/refreshed after login for the configured amount of time - maybe this is the problem?14:00
Mc-I'm not sure but would a expiring group membership fully prevent the creation of application credentials for roles of that group ?14:15
Mc-(cannot create them even "just" after login)14:15
gtemanot fully, I mean that if user loged in some time ago the group membership might expire - that would indeed render appcreds unusable. But the point is that you do not see user being member of the group14:16
gtemafrom how how reverse engineered the current logic it is expected that you have groups pre-provisioned. You grant them all necessary roles on projects. The users are then "just" becoming members of that group on the login14:17
Mc-it absolutely "works" within horizon, in the sense that I can do stuff in several projects based on several groups14:21
Mc-ah I'll try to set default_authorization_ttl to non-zero14:22
Mc-... better :D14:25
gtemathis is what I meant with expiring membership. But the user must re-login before this ttl expires or appcred stop working14:26
Mc-that's fine14:26
Mc-gtema: thanks a lot !14:29
gtemawelcome. It should have not been this complex anyway - thats why I completely redo this in keystone ng14:29
opendevreviewArnaud Morin proposed openstack/keystone master: Apply sql db expand from 2025.02  https://review.opendev.org/c/openstack/keystone/+/96830016:15
opendevreviewArnaud Morin proposed openstack/keystone master: Rename the migration folder  https://review.opendev.org/c/openstack/keystone/+/96830116:15
opendevreviewMoutaz Chaara proposed openstack/keystone master: Fix role assignment cache for federated users  https://review.opendev.org/c/openstack/keystone/+/96704816:18
opendevreviewArnaud Morin proposed openstack/keystone master: Rename the migration folder  https://review.opendev.org/c/openstack/keystone/+/96830116:57
opendevreviewArnaud Morin proposed openstack/keystone master: Add a new index on revocation_event table  https://review.opendev.org/c/openstack/keystone/+/92973616:57
opendevreviewMoutaz Chaara proposed openstack/keystone master: Fix role assignment cache for federated users  https://review.opendev.org/c/openstack/keystone/+/96704818:44
opendevreviewArnaud Morin proposed openstack/keystone master: Apply sql db expand from 2025.02  https://review.opendev.org/c/openstack/keystone/+/96830019:00
opendevreviewArnaud Morin proposed openstack/keystone master: Rename the migration folder  https://review.opendev.org/c/openstack/keystone/+/96830119:00
opendevreviewArnaud Morin proposed openstack/keystone master: Add a new index on revocation_event table  https://review.opendev.org/c/openstack/keystone/+/92973619:00
opendevreviewStephen Finucane proposed openstack/oslo.limit master: DNM: Revert "Add typing"  https://review.opendev.org/c/openstack/oslo.limit/+/96837519:08
opendevreviewStephen Finucane proposed openstack/oslo.limit master: DNM: Revert "Fix endpoint query"  https://review.opendev.org/c/openstack/oslo.limit/+/96837619:08
opendevreviewStephen Finucane proposed openstack/oslo.limit master: DNM: Unrevert "Add typing"  https://review.opendev.org/c/openstack/oslo.limit/+/96841121:29
opendevreviewMoutaz Chaara proposed openstack/keystone master: Fix role assignment cache for federated users  https://review.opendev.org/c/openstack/keystone/+/96704823:08

Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!