| opendevreview | Oria Weng proposed openstack/python-openstackclient master: [WIP] Migrate 'endpoint group' commands to SDK https://review.opendev.org/c/openstack/python-openstackclient/+/1001447 | 00:33 |
|---|---|---|
| opendevreview | Oria Weng proposed openstack/python-openstackclient master: [WIP] Migrate 'endpoint group' commands to SDK https://review.opendev.org/c/openstack/python-openstackclient/+/1001447 | 00:34 |
| rm_work | cardoe: had my agent get back to your agent 😛 | 08:48 |
| opendevreview | Stephen Finucane proposed openstack/openstacksdk master: Simplify ruff configuration https://review.opendev.org/c/openstack/openstacksdk/+/1000827 | 09:42 |
| opendevreview | Stephen Finucane proposed openstack/openstacksdk master: Enable G, LOG ruff rules https://review.opendev.org/c/openstack/openstacksdk/+/1000828 | 09:42 |
| opendevreview | Stephen Finucane proposed openstack/openstacksdk master: Migrate requirements to pyproject.toml https://review.opendev.org/c/openstack/openstacksdk/+/953484 | 09:42 |
| opendevreview | Stephen Finucane proposed openstack/openstacksdk master: Drop setup.py, setup.cfg https://review.opendev.org/c/openstack/openstacksdk/+/1000825 | 09:42 |
| opendevreview | Stephen Finucane proposed openstack/openstacksdk master: cloud: Remove unnecessary/unused utils https://review.opendev.org/c/openstack/openstacksdk/+/1001475 | 10:00 |
| opendevreview | Stephen Finucane proposed openstack/openstacksdk master: cloud: Remove unnecessary use of _get_entity https://review.opendev.org/c/openstack/openstacksdk/+/1001476 | 10:00 |
| opendevreview | Stephen Finucane proposed openstack/openstacksdk master: cloud: Remove another unnecessary use of _get_entity https://review.opendev.org/c/openstack/openstacksdk/+/1001477 | 10:00 |
| opendevreview | Stephen Finucane proposed openstack/openstacksdk master: cloud: Remove unnecessary use of _get_entity https://review.opendev.org/c/openstack/openstacksdk/+/1001476 | 10:07 |
| opendevreview | Stephen Finucane proposed openstack/openstacksdk master: cloud: Remove another unnecessary use of _get_entity https://review.opendev.org/c/openstack/openstacksdk/+/1001477 | 10:07 |
| stephenfin | cardoe: I've sent https://review.opendev.org/c/openstack/python-openstackclient/+/1000146 on its way, and I'll come back to the websso thing either later today or early tomorrow | 10:35 |
| stephenfin | I'll grab the precursor patches for ksa now though: they look much less involved | 10:38 |
| stephenfin | Ah, looks like you've given the caching situation some thought and come up with https://review.opendev.org/c/openstack/keystoneauth/+/1001419 🙏 That (reworking or extending the existing caching logic) was going to be my proposal, but I wanted to spend some time making sure it made sense before throwing a potentially nonsensical idea out there | 10:40 |
| opendevreview | Merged openstack/openstacksdk master: config: Add profiles helper https://review.opendev.org/c/openstack/openstacksdk/+/1001153 | 11:10 |
| opendevreview | Merged openstack/openstacksdk master: docs: Use literals, not italics https://review.opendev.org/c/openstack/openstacksdk/+/1001154 | 11:10 |
| opendevreview | Merged openstack/openstacksdk master: docs: Rework config guide https://review.opendev.org/c/openstack/openstacksdk/+/1001155 | 11:10 |
| opendevreview | Merged openstack/openstacksdk master: Omit keystone admin endpoint in heat job https://review.opendev.org/c/openstack/openstacksdk/+/1000695 | 11:45 |
| opendevreview | Merged openstack/openstacksdk master: Defer missing-catalog errors until proxy use. https://review.opendev.org/c/openstack/openstacksdk/+/997117 | 11:45 |
| opendevreview | Merged openstack/openstacksdk master: Add extra param fields to get_xy networking methods https://review.opendev.org/c/openstack/openstacksdk/+/995724 | 11:45 |
| opendevreview | Merged openstack/python-openstackclient master: Add network trunk subport commands https://review.opendev.org/c/openstack/python-openstackclient/+/1000146 | 11:45 |
| opendevreview | Merged openstack/openstacksdk master: Simplify ruff configuration https://review.opendev.org/c/openstack/openstacksdk/+/1000827 | 12:21 |
| opendevreview | Merged openstack/openstacksdk master: Enable G, LOG ruff rules https://review.opendev.org/c/openstack/openstacksdk/+/1000828 | 12:28 |
| opendevreview | Merged openstack/openstacksdk master: cloud: Remove unnecessary/unused utils https://review.opendev.org/c/openstack/openstacksdk/+/1001475 | 12:33 |
| opendevreview | Merged openstack/python-openstackclient master: Support compute microversion 2.94 https://review.opendev.org/c/openstack/python-openstackclient/+/872420 | 13:09 |
| opendevreview | Merged openstack/openstacksdk master: block_storage: Add add/remove volumes fields to Group https://review.opendev.org/c/openstack/openstacksdk/+/995940 | 13:21 |
| opendevreview | Merged openstack/openstacksdk master: block_storage: Forward list_volume query param in get_group https://review.opendev.org/c/openstack/openstacksdk/+/995937 | 13:31 |
| opendevreview | Stephen Finucane proposed openstack/keystoneauth master: typing: Use objects from typing https://review.opendev.org/c/openstack/keystoneauth/+/994713 | 16:10 |
| opendevreview | Stephen Finucane proposed openstack/keystoneauth master: pre-commit: Bump versions https://review.opendev.org/c/openstack/keystoneauth/+/1001538 | 16:10 |
| opendevreview | Merged openstack/openstacksdk master: cloud: Remove unnecessary use of _get_entity https://review.opendev.org/c/openstack/openstacksdk/+/1001476 | 16:36 |
| opendevreview | Merged openstack/openstacksdk master: cloud: Remove another unnecessary use of _get_entity https://review.opendev.org/c/openstack/openstacksdk/+/1001477 | 16:36 |
| opendevreview | Merged openstack/python-openstackclient master: Add leak-routes related options for subnets https://review.opendev.org/c/openstack/python-openstackclient/+/998212 | 16:48 |
| opendevreview | Merged openstack/openstacksdk master: baremetal: Add support for runbook traits and description https://review.opendev.org/c/openstack/openstacksdk/+/1000375 | 18:19 |
| cardoe | stephenfin: well if you're good with that approach I'll address rm_work's feedback | 18:33 |
| opendevreview | Oria Weng proposed openstack/openstacksdk master: Identity: Add support for endpoint groups https://review.opendev.org/c/openstack/openstacksdk/+/995762 | 19:39 |
| opendevreview | Rajat Dhasmana proposed openstack/python-openstackclient master: Cinder: Add support for export/import replica https://review.opendev.org/c/openstack/python-openstackclient/+/1001076 | 21:06 |
| opendevreview | Rajat Dhasmana proposed openstack/openstacksdk master: Volume: Add support for export/import replica https://review.opendev.org/c/openstack/openstacksdk/+/1001075 | 21:07 |
| rm_work | cardoe: you are aware I think that most of my reviews on this topic are AI driven, but I do review all the reviews by hand and try to understand before posting, so I THINK everything I posted is legitimate, I've found it to be a good way to learn a new codebase to force the AI to explain it to me in different ways until I get it 😆 | 22:10 |
| rm_work | but I think you're having your agent review my agent reviews so I don't feel too bad | 22:10 |
| cardoe | rm_work: so I agree with most of them | 22:10 |
| cardoe | The one about the SSO token needing to change I don't. | 22:11 |
| rm_work | hmmm | 22:11 |
| cardoe | But that's where you have the escape hatch of "openstack cloud auth delete" | 22:11 |
| rm_work | was that the thing with multiple cloud profiles? | 22:11 |
| cardoe | Yeah I don't think it makes sense to tie one OS_CLOUD entry to one SSO and another to another SSO | 22:12 |
| rm_work | ok well in my case | 22:12 |
| cardoe | You don't have any visibility in doing that. | 22:12 |
| rm_work | I had to scrub the internal example I have but | 22:12 |
| rm_work | I have two profiles that I actually DO use separate SSO for within one cloud | 22:12 |
| rm_work | so if it doesn't support that I may have to patch it internally or ... figure something out | 22:12 |
| rm_work | if it tries to use my normal SSO profile for admin basically, it will cause issues | 22:13 |
| rm_work | or if i login as admin first and then it uses that profile for my normal user cloud entry, that would be bad and somewhat silent | 22:13 |
| cardoe | But there's no way to reasonably select that. | 22:14 |
| cardoe | The selection of the SSO is going to be whatever browser based page you have | 22:14 |
| cardoe | And we cannot pass along any values to the browser via the WebSSO protocol. | 22:14 |
| rm_work | including the clouds.yaml profile name in the key splits them? and for most cases people will only have one or two, and a second login is usually quick | 22:14 |
| cardoe | Hence the CSRF topic. | 22:15 |
| rm_work | do we not build the cache key? | 22:15 |
| cardoe | So I've got ~30 OS_CLOUD's in my clouds.yaml which will share the same SSO | 22:17 |
| cardoe | So I guess I'd want it to be flexible. | 22:19 |
| rm_work | hmmm | 22:19 |
| rm_work | let me see what the cache key is again | 22:19 |
| rm_work | maybe if it includes like ... query params i could just add like ?admin or something | 22:20 |
| rm_work | to the URL lol | 22:20 |
| rm_work | trying to find which CR that was in | 22:20 |
| rm_work | ah got it | 22:24 |
| rm_work | hmmm no that wouldn't work T_T | 22:26 |
| rm_work | could you add like auth_cache_namespace to the clouds.yaml profile and then use hash(auth_cache_namespace + keystoneauth configuration ID) | 22:30 |
| rm_work | which I guess then leads to "which is default" | 22:31 |
| rm_work | I would prefer "explicitly share cache namespace" as required or else don't... so like, defaulting cache namespace to the cloud profile name 😄 because that seems like the least likely to be a security-oops, but I do understand that is the more tedious option for the average user who likely doesn't care (I assume I'm the outlier) | 22:32 |
| opendevreview | Merged openstack/openstacksdk master: [typing] Add proper type hints for role assignment functions https://review.opendev.org/c/openstack/openstacksdk/+/1000095 | 22:54 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!