*** zaitcev_ has joined #openstack-swift | 00:01 | |
*** ChanServ sets mode: +v zaitcev_ | 00:02 | |
*** zaitcev has quit IRC | 00:06 | |
*** diablo_rojo has joined #openstack-swift | 00:37 | |
*** tkajinam_ has joined #openstack-swift | 01:26 | |
*** tkajinam has quit IRC | 01:28 | |
*** psachin has joined #openstack-swift | 02:12 | |
*** renich has joined #openstack-swift | 02:24 | |
renich | Good $time_of_day, OpenStackers! | 02:24 |
---|---|---|
renich | I am having a bit of an issue with a newly installed keystone/swift cluster. Stein is the version. | 02:25 |
renich | it turns out that: swift stat works fine for the admin user, but it doesn't work for my demouser. | 02:25 |
renich | Also, all operations with openstack work for the admin user. The odd part is that: openstack token issue works for the demouser but not any container or object operations. | 02:26 |
renich | I dunno what is causing it. It's really odd. | 02:26 |
renich | This is how I created demouser: https://paste.fedoraproject.org/paste/8vHla6tqE45v1L~tlCflmw | 02:27 |
timburke | renich, what operator_roles do you have set for keystoneauth in your proxy-server.conf? significantly, is demorole included there? | 02:48 |
timburke | (it doesn't necessarily have to be -- it kinda all depends on how you want auth to work for your cluster) | 02:49 |
timburke | for example, if the user should only have access to a particular container or set of containers, you could have the admin user create the container(s) and set appropriate container ACLs for the user | 02:50 |
renich | timburke: no, it's not. I set admin, user | 03:00 |
renich | ah, OK! I get it. But, for example, regular users should be operators in general, right? | 03:01 |
renich | OK, so, I need to create the admin and user roles, right? In order to be able to grant operator privileges to those roles. | 03:03 |
renich | timburke: you were totally right. I added the user role to demoproject and it works fine now. Interesting! The idea of not adding the user role and controlling per-container access to users is awesome as well. | 03:07 |
timburke | i'm torn about it, honestly -- it's a lot of power, but it seems easy to have it become overly complicated, and discoverability becomes an issue | 03:09 |
*** psachin has quit IRC | 03:17 | |
*** psachin has joined #openstack-swift | 03:18 | |
*** diablo_rojo has quit IRC | 03:40 | |
*** renich has quit IRC | 05:29 | |
*** renich has joined #openstack-swift | 05:30 | |
*** renich has quit IRC | 05:50 | |
*** rdejoux has joined #openstack-swift | 07:07 | |
*** pcaruana has joined #openstack-swift | 07:10 | |
*** tesseract has joined #openstack-swift | 07:13 | |
*** ccamacho has joined #openstack-swift | 07:24 | |
*** rpittau|afk is now known as rpittau | 07:35 | |
*** tkajinam_ has quit IRC | 08:10 | |
openstackgerrit | Christian Schwede proposed openstack/swift master: Fix misleading error msg if swift.conf unreadable https://review.opendev.org/581280 | 08:31 |
openstackgerrit | Christian Schwede proposed openstack/swift master: Fix misleading error msg if swift.conf unreadable https://review.opendev.org/581280 | 08:33 |
*** e0ne has joined #openstack-swift | 08:39 | |
*** mvkr has quit IRC | 09:39 | |
*** mvkr has joined #openstack-swift | 09:53 | |
*** tesseract has quit IRC | 10:44 | |
*** tesseract has joined #openstack-swift | 10:46 | |
*** rcernin has quit IRC | 10:48 | |
tdasilva | cschwede!!! | 10:49 |
cschwede | tdasilva: me? what did i break? ;) | 10:52 |
tdasilva | cschwede: heh, it's goot to see you around! | 10:56 |
mattoliverau | +100 | 11:35 |
*** baojg has quit IRC | 11:46 | |
*** tomha has joined #openstack-swift | 11:59 | |
*** tomha has quit IRC | 12:09 | |
*** tomha has joined #openstack-swift | 12:11 | |
*** tomha has quit IRC | 12:16 | |
*** psachin has quit IRC | 12:31 | |
*** csmart has quit IRC | 12:33 | |
*** csmart has joined #openstack-swift | 12:36 | |
*** NM has joined #openstack-swift | 13:07 | |
*** pcaruana has quit IRC | 13:31 | |
*** pcaruana has joined #openstack-swift | 13:33 | |
*** ianychoi has quit IRC | 13:41 | |
*** mikecmpbll has joined #openstack-swift | 13:53 | |
*** mahatic has quit IRC | 13:56 | |
*** tonyb has quit IRC | 13:56 | |
*** zaitcev_ has quit IRC | 13:56 | |
*** MooingLemur has quit IRC | 13:56 | |
*** cwright has quit IRC | 13:56 | |
*** MooingLe1ur has joined #openstack-swift | 13:56 | |
*** openstackstatus has quit IRC | 13:58 | |
*** cwright has joined #openstack-swift | 14:00 | |
timburke | \o/ cschwede! | 14:05 |
openstackgerrit | Thiago da Silva proposed openstack/swift master: Create segment container w/ same policy as primary https://review.opendev.org/687577 | 14:30 |
openstackgerrit | Clay Gerrard proposed openstack/swift master: WIP: Allow internal clients to use null namespace https://review.opendev.org/682138 | 14:46 |
clayg | tdasilva: p 687577 looks obviously correct - i'm doing a quick once over | 14:51 |
patchbot | https://review.opendev.org/#/c/687577/ - swift - Create segment container w/ same policy as primary - 1 patch set | 14:51 |
tdasilva | clayg: thanks! | 14:51 |
tdasilva | clayg: I'm looking at p 682138 and wondering if I should rebase p 682382 on top of it | 14:52 |
patchbot | https://review.opendev.org/#/c/682138/ - swift - WIP: Allow internal clients to use null namespace - 9 patch sets | 14:52 |
patchbot | https://review.opendev.org/#/c/682382/ - swift - WIP: New Object Versioning mode - 11 patch sets | 14:52 |
clayg | tdasilva: i wouldn't yet - it's still unstable and timburke and I are having some problems with the null-byte in queries - it's all a mess 😞 | 14:56 |
clayg | tdasilva: i'm in the middle of making the RESERVED_BYTE a constant in prepreation for having to go with \x01\x01 or something since the null-byte is starting to look sketchy 😢 | 14:58 |
clayg | we definately still need a reserved delimiter for name/version and a way to have system containers... but maybe the null-byte isn't the answer to our prayers we were hoping for - dunno | 14:59 |
*** diablo_rojo has joined #openstack-swift | 15:06 | |
tdasilva | clayg: i'm back to wondering if we could claim something like \x01 to be a reserved_byte going forward. User's won't be able to create new container/object with it. If they have existing data, we could add the "shunt" option is the listing middleware to not filter it out. | 15:06 |
tdasilva | clayg: it does mean that for those cluster we would leak system containers, but it's not different behavior from what they have today | 15:07 |
tdasilva | clayg: i.e., users can see 'versions' and '+segments' container today | 15:07 |
clayg | I agree having something actually reserved - like \x01 - would be way better than having something reserved by convention like \x01\x01 | 15:08 |
clayg | aws s3 allows keys with \x01 in the name - but like us - not \x00 | 15:08 |
clayg | timburke: suggested quite reasonably, that allowing them isn't the same as clients using them | 15:09 |
clayg | we could potentially "reclaim" \x01-\x08" or something similar - and call it 'reserved" w/o breaking clients | 15:09 |
clayg | OTOH, maybe someone is using it - or something in the future will say "but this works in s3" | 15:09 |
clayg | asides from the dubious handling in like queryies sqlite3 has done pretty well with it's null-byte handling despite being "undefined" - as best I can tell the marker/prefix queries are working perfectly - so I haven't given up hope | 15:11 |
clayg | but i'm also running a fever - so don't listen to me 🤒 | 15:11 |
openstackgerrit | Thiago da Silva proposed openstack/swift master: Create segment container w/ same policy as primary https://review.opendev.org/687577 | 15:24 |
tdasilva | clayg: sorry for the noise ^^^ | 15:28 |
clayg | No worries, you just changed the req to seg-req? | 15:30 |
*** NM has quit IRC | 15:31 | |
tdasilva | clayg: yep! | 15:36 |
*** rpittau is now known as rpittau|afk | 15:45 | |
*** openstackgerrit has quit IRC | 15:52 | |
*** BjoernT has joined #openstack-swift | 15:56 | |
*** ccamacho has quit IRC | 16:03 | |
*** zaitcev has joined #openstack-swift | 16:11 | |
*** ChanServ sets mode: +v zaitcev | 16:11 | |
*** rdejoux has quit IRC | 16:34 | |
timburke | clayg, i wonder if we could add a restriction that all objects/containers that include a null byte must start with a null byte... i mean, the prefix/marker/end_marker tests you've done sure indicate that > and < work just fine with NUL -- maybe we tack on a " AND name >= '\x01' " if allow_null is false... | 16:39 |
*** gyee has joined #openstack-swift | 16:58 | |
*** mikecmpbll has quit IRC | 17:02 | |
*** e0ne has quit IRC | 17:02 | |
*** NM has joined #openstack-swift | 17:03 | |
*** tomha has joined #openstack-swift | 17:40 | |
*** tomha has quit IRC | 17:48 | |
zaitcev | https://www.zdnet.com/article/suse-drops-openstacks/ | 17:54 |
*** e0ne has joined #openstack-swift | 18:25 | |
*** e0ne has quit IRC | 19:00 | |
*** pcaruana has quit IRC | 19:07 | |
*** e0ne has joined #openstack-swift | 19:08 | |
*** umbSublime has joined #openstack-swift | 19:08 | |
*** mgagne has quit IRC | 19:11 | |
*** tesseract has quit IRC | 19:20 | |
*** e0ne has quit IRC | 19:56 | |
*** rdejoux has joined #openstack-swift | 20:10 | |
mattoliverau | Yup, not gonna lie, I only knew about 24 hours before that article.. if that. It hasn't been a good few days, and I'm still in shock :( | 20:27 |
* timburke hugs mattoliverau | 20:27 | |
*** pcaruana has joined #openstack-swift | 20:33 | |
*** pcaruana has quit IRC | 20:40 | |
kota_ | morning | 20:57 |
kota_ | suse!? | 20:57 |
alecuyer | hello, ouch that's sad news :/ | 20:59 |
timburke | meeting time! | 21:00 |
*** NM has quit IRC | 21:34 | |
*** diablo_rojo has quit IRC | 21:47 | |
*** BjoernT has quit IRC | 22:02 | |
*** rdejoux has quit IRC | 22:06 | |
*** rcernin has joined #openstack-swift | 22:14 | |
*** tkajinam has joined #openstack-swift | 23:02 | |
*** openstackstatus has joined #openstack-swift | 23:19 | |
*** ChanServ sets mode: +v openstackstatus | 23:19 | |
*** gyee has quit IRC | 23:27 | |
*** NM has joined #openstack-swift | 23:54 | |
*** NM has quit IRC | 23:58 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!