*** salv-orlando has joined #openstack-sdks | 00:05 | |
*** salv-orlando has quit IRC | 00:10 | |
*** mrhillsman is now known as mrhillsman_in_mm | 00:11 | |
*** mrhillsman_in_mm is now known as mrhillsman | 00:13 | |
*** openstack has joined #openstack-sdks | 00:17 | |
*** ChanServ sets mode: +o openstack | 00:17 | |
*** sdague has quit IRC | 00:17 | |
*** dave-mccowan has joined #openstack-sdks | 00:21 | |
*** chenyb4 has joined #openstack-sdks | 00:49 | |
*** bobh has joined #openstack-sdks | 01:05 | |
*** bobh has quit IRC | 01:17 | |
*** Matias has quit IRC | 01:20 | |
*** bobh has joined #openstack-sdks | 01:45 | |
*** bobh has quit IRC | 01:53 | |
*** chenyb4 has quit IRC | 02:06 | |
*** salv-orlando has joined #openstack-sdks | 02:07 | |
*** chenyb4 has joined #openstack-sdks | 02:09 | |
*** salv-orlando has quit IRC | 02:12 | |
*** gildub has joined #openstack-sdks | 03:37 | |
openstackgerrit | Logan V proposed openstack/os-client-config master: Add Limestone Networks vendor info https://review.openstack.org/557139 | 03:44 |
---|---|---|
*** dave-mccowan has quit IRC | 03:55 | |
*** salv-orlando has joined #openstack-sdks | 04:08 | |
*** salv-orlando has quit IRC | 04:13 | |
mrhillsman | adriant see - https://github.com/gophercloud/utils/pull/26 | 04:17 |
mrhillsman | generally quick response :) | 04:17 |
mrhillsman | you may be able to help push it through by reviewing/trying it even though jtopjian may not merge it until after jrperritt review | 04:18 |
adriant | mrhillsman: looks good, code (despite not entirely understanding go) makes sense. | 04:25 |
mrhillsman | ++ | 04:26 |
adriant | mrhillsman: and did you file a bug to terraform for the OS_TOKEN value? | 04:28 |
mrhillsman | i did not | 04:28 |
adriant | it might also be worth asking terraform/gophercloud peeps why gophercloud and terraform both differently handle environment variables. | 04:28 |
mrhillsman | jtopjian maintains that as well | 04:28 |
mrhillsman | unfortunately i do not know go well enough to know | 04:29 |
adriant | mrhillsman: want me to submit that bug and potentially ask at the same time? | 04:29 |
mrhillsman | i just started working on learning it about a month ago | 04:30 |
mrhillsman | yeah, i think you should and reference the issue and pr | 04:30 |
adriant | kk | 04:30 |
mrhillsman | thx adriant | 04:30 |
*** gkadam has joined #openstack-sdks | 04:44 | |
*** gkadam has quit IRC | 05:07 | |
*** salv-orlando has joined #openstack-sdks | 05:09 | |
*** salv-orlando has quit IRC | 05:09 | |
*** salv-orlando has joined #openstack-sdks | 05:09 | |
*** e0ne has joined #openstack-sdks | 05:26 | |
adriant | mrhillsman: https://github.com/terraform-providers/terraform-provider-openstack/issues/271 | 05:31 |
*** e0ne has quit IRC | 05:33 | |
adriant | mordred, dtroyer: what exactly is the precedence between: domain_id vs user_domain_id, and project_domain_id ? And the same with domain_name vs user_domain_name, and project_domain_name ? | 05:35 |
adriant | I'd assume (and probably incorrectly) that domain_id comes first in our tools and then if one of the other two is set, they take precedence? | 05:36 |
adriant | mordred: does os-client-config even use OS_DOMAIN_ID and OS_DOMAIN_NAME or the user/project specific ones? I may take a gander at the code | 05:38 |
mrhillsman | cool, thanks for leading the charge on this adriant | 05:38 |
adriant | mrhillsman: np | 05:38 |
adriant | mrhillsman: with MFA slowly becoming a thing in openstack token auth in these tools will be VERY important | 05:38 |
adriant | so it needs to work | 05:39 |
adriant | because screw entering your password + MFA things for every commands | 05:39 |
adriant | that way madness lies | 05:39 |
adriant | I want a nice easy way to auth in the CLI, save me auth'd token somewhere, and then use that, and ideally have that experience consistent. | 05:40 |
mrhillsman | willing to bet quite a few folks are going to be happy as a result | 05:40 |
*** e0ne has joined #openstack-sdks | 05:50 | |
*** e0ne has quit IRC | 06:10 | |
*** gildub has quit IRC | 06:16 | |
*** gildub has joined #openstack-sdks | 06:27 | |
*** pooja_jadhav has quit IRC | 07:21 | |
*** salv-orlando has quit IRC | 07:22 | |
*** pooja_jadhav has joined #openstack-sdks | 07:22 | |
*** salv-orlando has joined #openstack-sdks | 07:22 | |
*** salv-orlando has quit IRC | 07:27 | |
*** salv-orlando has joined #openstack-sdks | 07:45 | |
*** salv-orlando has quit IRC | 07:54 | |
*** ralonsoh has joined #openstack-sdks | 07:54 | |
*** salv-orlando has joined #openstack-sdks | 07:54 | |
*** gildub has quit IRC | 07:58 | |
*** salv-orlando has quit IRC | 07:59 | |
*** jpich has joined #openstack-sdks | 08:04 | |
openstackgerrit | Chen Hanxiao proposed openstack/python-openstackclient master: Add --image-property parameter in 'server create' https://review.openstack.org/535664 | 08:10 |
*** gkadam has joined #openstack-sdks | 08:19 | |
*** e0ne has joined #openstack-sdks | 08:27 | |
*** sdague has joined #openstack-sdks | 08:55 | |
*** cdent has joined #openstack-sdks | 09:11 | |
openstackgerrit | Chris Dent proposed openstack/api-wg master: Add guidance on needing cache-control headers https://review.openstack.org/550468 | 09:12 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-openstackclient master: Updated from global requirements https://review.openstack.org/553257 | 09:22 |
*** dtantsur|afk is now known as dtantsur | 09:46 | |
*** salv-orlando has joined #openstack-sdks | 09:58 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-openstackclient master: Updated from global requirements https://review.openstack.org/553257 | 10:02 |
*** cdent has quit IRC | 10:12 | |
*** chenyb4 has quit IRC | 10:29 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-openstackclient master: Updated from global requirements https://review.openstack.org/553257 | 10:37 |
*** salv-orl_ has joined #openstack-sdks | 10:53 | |
*** salv-orlando has quit IRC | 10:56 | |
*** salv-orlando has joined #openstack-sdks | 10:58 | |
*** salv-orl_ has quit IRC | 10:58 | |
*** cdent has joined #openstack-sdks | 11:01 | |
*** gkadam_ has joined #openstack-sdks | 11:03 | |
*** gkadam__ has joined #openstack-sdks | 11:04 | |
*** salv-orlando has quit IRC | 11:05 | |
*** salv-orlando has joined #openstack-sdks | 11:06 | |
*** gkadam has quit IRC | 11:07 | |
*** gkadam_ has quit IRC | 11:08 | |
*** dave-mccowan has joined #openstack-sdks | 11:09 | |
*** thrash|g0ne is now known as thrash | 11:19 | |
*** dtantsur is now known as dtantsur|brb | 11:31 | |
*** salv-orl_ has joined #openstack-sdks | 11:36 | |
*** salv-orlando has quit IRC | 11:41 | |
*** gkadam__ has quit IRC | 11:44 | |
*** cdent has quit IRC | 12:05 | |
*** bobh has joined #openstack-sdks | 12:06 | |
*** edmondsw has joined #openstack-sdks | 12:06 | |
*** gkadam has joined #openstack-sdks | 12:19 | |
*** bobh has quit IRC | 12:34 | |
*** cdent has joined #openstack-sdks | 12:40 | |
*** chenyb4 has joined #openstack-sdks | 12:40 | |
*** olaph has joined #openstack-sdks | 12:52 | |
*** thrash is now known as thrash|biab | 12:53 | |
*** chenyb4 has quit IRC | 12:53 | |
*** salv-orlando has joined #openstack-sdks | 12:56 | |
*** salv-or__ has joined #openstack-sdks | 12:57 | |
*** fabian_ has joined #openstack-sdks | 12:58 | |
*** salv-orl_ has quit IRC | 12:58 | |
*** fabian_ is now known as chenyb4 | 12:58 | |
*** salv-orlando has quit IRC | 13:02 | |
*** salv-or__ has quit IRC | 13:02 | |
*** salv-orlando has joined #openstack-sdks | 13:03 | |
*** lbragstad has joined #openstack-sdks | 13:04 | |
*** salv-orlando has quit IRC | 13:08 | |
*** dtantsur|brb is now known as dtantsur | 13:15 | |
*** thrash|biab is now known as thrash | 13:34 | |
*** cdent has quit IRC | 13:47 | |
*** cdent has joined #openstack-sdks | 13:48 | |
*** cdent has quit IRC | 13:53 | |
*** salv-orlando has joined #openstack-sdks | 13:53 | |
*** cdent has joined #openstack-sdks | 13:55 | |
mordred | adriant: the user and project versions | 13:55 |
mordred | adriant: OS_DOMAIN_ID and OS_DOMAIN_NAME _can_ be used, but they actually commuicate different information than OS_PROJECT_DOMAIN_NAME and OS_USER_DOMAIN_NAME | 13:56 |
mordred | adriant: OS_DOMAIN_ID and OS_DOMAIN_NAME (or, rather, the keystoneauth parameters domain_name and domain_id) are used to create a domain-scoped token | 13:56 |
mordred | adriant: so, domain_name is not a way to set domain for both user and project - it has a whole other meaning | 13:57 |
mordred | adriant: I *think* somewhere (it might be python-openstackclient) there was an addition of default_domain_name - that could be used to set domain name once for both user and project | 13:58 |
mordred | adriant, mrhillsman: also - token auth is not the answer for api access for MFA clouds ... I'd actually argue that any time anyone (who is not already an openstack service) directly uses token auth something else has fundamentally broken | 14:00 |
mordred | adriant: the answer for API access for MFA is the new App Credential support that landed in Queens | 14:01 |
mordred | THAT SAID - obviously token auth should work - and if it doesn't we should fix it | 14:01 |
*** ralonsoh has quit IRC | 14:29 | |
openstackgerrit | Sami Makki proposed openstack/python-openstackclient master: Fix the `role implies list` command. https://review.openstack.org/557359 | 14:59 |
*** cdent has quit IRC | 15:10 | |
*** chenyb4 has quit IRC | 15:14 | |
EmilienM | dtroyer: do you think it would be possible to cut a tag on osc (based on latest patch that landed: https://review.openstack.org/#/c/553374/)? It's currently blocking TripleO to move forward in Rocky | 15:25 |
*** bobh has joined #openstack-sdks | 15:31 | |
*** bobh has quit IRC | 15:36 | |
*** bobh has joined #openstack-sdks | 15:43 | |
*** bobh has quit IRC | 15:48 | |
*** bobh has joined #openstack-sdks | 15:53 | |
*** bobh has quit IRC | 15:58 | |
*** bobh has joined #openstack-sdks | 16:00 | |
*** bobh has quit IRC | 16:05 | |
*** bobh has joined #openstack-sdks | 16:08 | |
*** cdent has joined #openstack-sdks | 16:18 | |
*** jpich has quit IRC | 16:29 | |
*** olaph has quit IRC | 16:31 | |
*** olaph has joined #openstack-sdks | 16:31 | |
*** thrash is now known as thrash|biab | 16:40 | |
*** e0ne has quit IRC | 17:01 | |
*** thrash|biab is now known as thrash | 17:08 | |
*** dtantsur is now known as dtantsur|afk | 17:10 | |
*** gildub has joined #openstack-sdks | 17:54 | |
*** gkadam has quit IRC | 17:54 | |
*** gildub has quit IRC | 18:17 | |
*** e0ne has joined #openstack-sdks | 18:19 | |
openstackgerrit | Merged openstack/keystoneauth master: Be more helpful when version discovery fails https://review.openstack.org/554044 | 18:39 |
*** corvus is now known as kermitf | 18:42 | |
*** kermitf is now known as corvus | 18:42 | |
dtroyer | mordred: having your +1 on https://review.openstack.org/557479 (DevStack, one more SDK rename) might be nice | 18:56 |
dtroyer | it's why osc's -tips jobs are failing | 18:57 |
mordred | dtroyer: oh poo. sorry - I thought I'd gotten them all | 19:05 |
*** gkadam has joined #openstack-sdks | 19:06 | |
*** olaph1 has joined #openstack-sdks | 19:22 | |
*** olaph has quit IRC | 19:24 | |
*** bobh has quit IRC | 19:37 | |
*** olaph has joined #openstack-sdks | 19:55 | |
*** olaph1 has quit IRC | 19:57 | |
*** bobh has joined #openstack-sdks | 20:01 | |
*** gkadam has quit IRC | 20:12 | |
*** e0ne has quit IRC | 20:48 | |
*** olaph1 has joined #openstack-sdks | 21:16 | |
*** olaph has quit IRC | 21:16 | |
adriant | mordred: ty! That makes more sense, if not also being confusing... | 21:22 |
* adriant hates domains as a concept outside of projects | 21:22 | |
mordred | adriant: I would have liked them better if they had been called "realm" I think | 21:24 |
mordred | adriant: but yeah | 21:24 |
adriant | domains are already projects, but.. the painful and confusing fact that you can scope to a domain, and a project that is a domain... | 21:24 |
adriant | is evil | 21:24 |
adriant | EVIL | 21:24 |
adriant | and as it turns out by giving yourself a role assignment on the same domain/project with both scopes breaks keystone :P | 21:25 |
adriant | you now have a role assignment you can't remove! | 21:25 |
* adriant finds all the best bugs | 21:25 | |
mordred | yay! | 21:27 |
adriant | and mordred: regarding tokens being the answer to MFA. I disagree that appcreds are the answer. When you're using the CLI you don't really want to use app creds. For services, yes, and then you wouldn't do MFA. | 21:27 |
adriant | but for using your own account and needing to do stuff... having to provide a password+totp every time is a nope | 21:27 |
adriant | so basically with my own CLI use, I do it like horizon does. Auth first, store token, use APIs. | 21:28 |
adriant | and MFA in horizon will do the same | 21:28 |
adriant | you front load the MFA, and then once you have a token, everything just works. | 21:28 |
mordred | adriant: what happens when your token expires? | 21:29 |
*** e0ne has joined #openstack-sdks | 21:29 | |
adriant | I get a new one | 21:29 |
adriant | horizon does the same :P | 21:29 |
mordred | nod | 21:29 |
adriant | it logs me out | 21:29 |
mordred | well - yah - but horizon is different :) | 21:29 |
adriant | but using a command line utility is not different than using horizon really | 21:30 |
mordred | it's possible that I have a warped view of cloud interactions as well | 21:30 |
adriant | you have a token based session, but in the case of the cli, it's one token per command | 21:30 |
adriant | that's a lot of tokens | 21:31 |
mordred | adriant: my typical usage locally is either an ansible playbook, or python loaded in a repl | 21:31 |
mordred | so I guess I usually tend to behave more like an automated service than like an interactive user ... | 21:32 |
adriant | yeah, and I use my silly interpreter thing, but off the cli | 21:32 |
mordred | in any case - you make good points, so I will stop telling people they're wrong when they use token directly :) | 21:32 |
adriant | basically one of the things I'll end up doing as part of the MFA work in keystone is an eventual follow up to the openstackclient that adds support for catching and handling the auth-receipts. | 21:33 |
adriant | either into an interactive set of prompts to ask for MFA details | 21:33 |
adriant | or at least just a good error output of what methods were missing | 21:34 |
adriant | with a potential extra command added to the openstack cli that authenticates you, and sets/unsets the right values needed for token auth for future commands | 21:34 |
EmilienM | would it be possible to have a release of osc once https://review.openstack.org/557479 is merged? | 21:34 |
adriant | mordred: so MFA related interactions with the openstackcli consist of: "openstack authenticate" followed by an interactive MFA prompt or two, and then following commands work off token auth. | 21:36 |
adriant | maybe, we need to work out what makes sense once the auth-receipt stuff is implemented in keystone and keystoneauth | 21:36 |
*** cdent has quit IRC | 21:37 | |
*** edmondsw has quit IRC | 21:43 | |
-openstackstatus- NOTICE: the zuul web dashboard will experience a short downtime as we roll out some changes - no job execution should be affected | 21:52 | |
*** harlowja has joined #openstack-sdks | 21:53 | |
*** e0ne has quit IRC | 21:55 | |
*** bobh has quit IRC | 22:17 | |
dtroyer | EmilienM: looks like it merged, I need to get some things going yet, will request the release tomorrow, it's queued up and ready to fire | 22:52 |
EmilienM | woot | 22:52 |
EmilienM | dtroyer: thank you, i'll help a lot | 22:52 |
EmilienM | it'll help a lot I mean | 22:52 |
dtroyer | my apologies for this taking so long… my time for OSC is down to $FAR_TOO_LITTLE | 22:56 |
EmilienM | no worries :) | 23:01 |
*** bobh has joined #openstack-sdks | 23:16 | |
*** salv-orlando has quit IRC | 23:21 | |
*** salv-orlando has joined #openstack-sdks | 23:22 | |
*** olaph has joined #openstack-sdks | 23:23 | |
*** olaph1 has quit IRC | 23:25 | |
*** salv-orlando has quit IRC | 23:27 | |
-openstackstatus- NOTICE: Zuul has been restarted to update to the latest code; existing changes have been re-enqueued, you may need to recheck changes uploaded in the past 10 minutes | 23:59 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!