*** tkimball has joined #openstack | 00:00 | |
*** gyee has quit IRC | 00:00 | |
*** bobh has joined #openstack | 00:04 | |
*** poopcat has joined #openstack | 00:05 | |
*** bobh has quit IRC | 00:08 | |
*** bobh has joined #openstack | 00:09 | |
*** r-daneel has quit IRC | 00:10 | |
*** bobh has quit IRC | 00:13 | |
*** dhill_ has joined #openstack | 00:28 | |
*** dhill_ has quit IRC | 00:29 | |
*** dhill_ has joined #openstack | 00:29 | |
*** SunWuKung has joined #openstack | 00:33 | |
*** foul_owl has quit IRC | 00:37 | |
*** SunWuKung has quit IRC | 00:45 | |
*** kei-ichi has quit IRC | 00:47 | |
*** kei-ichi has joined #openstack | 00:49 | |
*** dhill_ has quit IRC | 00:49 | |
*** foul_owl has joined #openstack | 00:52 | |
*** donghm has joined #openstack | 00:59 | |
*** gregoryo has joined #openstack | 01:07 | |
*** bucketm0use has quit IRC | 01:10 | |
*** bucketm0use has joined #openstack | 01:10 | |
*** ircuser-1 has quit IRC | 01:27 | |
*** brokencycle has quit IRC | 01:38 | |
*** Son_Goku has joined #openstack | 01:48 | |
*** mdih has joined #openstack | 01:50 | |
*** SumitNaiksatam has joined #openstack | 01:56 | |
*** mrsoul has quit IRC | 01:59 | |
*** Son_Goku has quit IRC | 02:01 | |
*** rchavik has joined #openstack | 02:07 | |
*** Obi-Wan has quit IRC | 02:26 | |
*** gnufied has quit IRC | 02:29 | |
*** Bhujay has joined #openstack | 02:30 | |
*** Bhujay has quit IRC | 02:30 | |
*** Bhujay has joined #openstack | 02:31 | |
*** Nel1x has joined #openstack | 02:36 | |
*** rmcallis has joined #openstack | 02:39 | |
*** rmcall has quit IRC | 02:41 | |
*** Bhujay has quit IRC | 02:51 | |
*** mdih has quit IRC | 02:51 | |
*** bobh has joined #openstack | 02:53 | |
*** bobh has quit IRC | 02:55 | |
*** rmcall has joined #openstack | 02:56 | |
*** bobh has joined #openstack | 02:56 | |
*** rmcallis has quit IRC | 02:57 | |
*** bobh has quit IRC | 02:57 | |
*** bobh_ has joined #openstack | 03:08 | |
*** bobh_ has quit IRC | 03:11 | |
*** dnickelson has quit IRC | 03:19 | |
*** neatherweb_ has quit IRC | 03:27 | |
*** dhill_ has joined #openstack | 03:35 | |
*** Petersingh has joined #openstack | 03:39 | |
*** dhill_ has quit IRC | 03:40 | |
*** dhill_ has joined #openstack | 03:43 | |
*** bobh_ has joined #openstack | 03:44 | |
*** janki has joined #openstack | 03:57 | |
*** bobh_ has quit IRC | 04:01 | |
*** poopcat has quit IRC | 04:03 | |
*** rvd has joined #openstack | 04:06 | |
*** e0ne has joined #openstack | 04:11 | |
*** Nel1x has quit IRC | 04:14 | |
*** neatherweb_ has joined #openstack | 04:19 | |
*** Croata has quit IRC | 04:24 | |
*** e0ne has quit IRC | 04:24 | |
*** gkadam has joined #openstack | 04:28 | |
*** Bhujay has joined #openstack | 04:32 | |
*** Bhujay has quit IRC | 04:34 | |
*** tkimball has quit IRC | 04:36 | |
*** albertom has quit IRC | 04:40 | |
*** markvoelker has joined #openstack | 04:41 | |
*** Son_Goku has joined #openstack | 04:45 | |
*** magicrhesus has quit IRC | 04:56 | |
*** Son_Goku has quit IRC | 04:57 | |
*** magicrhesus has joined #openstack | 04:57 | |
*** ircuser-1 has joined #openstack | 05:03 | |
*** Son_Goku has joined #openstack | 05:17 | |
*** shyambiradar has joined #openstack | 05:21 | |
*** Petersingh is now known as Petersingh|afk | 05:30 | |
*** sauvin has joined #openstack | 05:31 | |
*** nicolasbock has joined #openstack | 05:34 | |
*** mosulica has joined #openstack | 05:43 | |
*** Petersingh|afk is now known as Petersingh | 05:43 | |
*** cah_link has joined #openstack | 05:43 | |
*** Son_Goku has quit IRC | 05:52 | |
*** shyambiradar has quit IRC | 05:53 | |
*** Arsenick has quit IRC | 05:58 | |
*** mdih has joined #openstack | 06:00 | |
*** mosulica has quit IRC | 06:05 | |
*** ymasson has quit IRC | 06:06 | |
*** Croata has joined #openstack | 06:10 | |
*** mosulica has joined #openstack | 06:16 | |
*** mosulica has quit IRC | 06:21 | |
*** agurenko has joined #openstack | 06:21 | |
*** hamdyk has joined #openstack | 06:21 | |
*** mosulica has joined #openstack | 06:22 | |
*** egonzalez has joined #openstack | 06:24 | |
*** Emine has joined #openstack | 06:28 | |
*** mosulica has quit IRC | 06:31 | |
*** mosulica has joined #openstack | 06:32 | |
*** nicolasbock has quit IRC | 06:35 | |
*** pcaruana has joined #openstack | 06:38 | |
*** nicolasbock has joined #openstack | 06:41 | |
*** Croata has quit IRC | 06:48 | |
*** cloudrancher has quit IRC | 06:50 | |
*** cloudrancher has joined #openstack | 06:52 | |
*** cloudrancher has quit IRC | 06:52 | |
*** foul_owl has quit IRC | 06:53 | |
*** mosulica has quit IRC | 06:59 | |
*** Son_Goku has joined #openstack | 07:04 | |
*** ChrisNBlum_away has joined #openstack | 07:06 | |
*** shakalaka has joined #openstack | 07:07 | |
*** ChrisNBlum_away is now known as ChrisNBlum | 07:10 | |
*** foul_owl has joined #openstack | 07:10 | |
*** mosulica has joined #openstack | 07:10 | |
*** shyambiradar has joined #openstack | 07:11 | |
*** Obi-Wan has joined #openstack | 07:12 | |
*** rmart04 has joined #openstack | 07:14 | |
*** ChrisNBlum has quit IRC | 07:15 | |
*** ChrisNBlum has joined #openstack | 07:15 | |
*** Bhujay has joined #openstack | 07:16 | |
*** rcernin has quit IRC | 07:16 | |
*** donghm has quit IRC | 07:18 | |
*** Petersingh is now known as Petersingh|bomga | 07:18 | |
*** Bhujay has quit IRC | 07:22 | |
*** agurenko has quit IRC | 07:25 | |
*** mattgo has joined #openstack | 07:25 | |
*** rmart04_ has joined #openstack | 07:26 | |
*** rmart04 has quit IRC | 07:26 | |
*** rmart04_ is now known as rmart04 | 07:26 | |
*** agurenko has joined #openstack | 07:28 | |
*** Son_Goku has quit IRC | 07:34 | |
*** shyambiradar has quit IRC | 07:38 | |
*** shyambiradar has joined #openstack | 07:39 | |
*** Bhujay has joined #openstack | 07:40 | |
*** Son_Goku has joined #openstack | 07:44 | |
*** assassin has quit IRC | 07:48 | |
*** skazi has quit IRC | 07:54 | |
*** gildub has quit IRC | 07:57 | |
*** Son_Goku has quit IRC | 08:01 | |
*** mikecmpbll has joined #openstack | 08:05 | |
*** shyambiradar has quit IRC | 08:11 | |
*** rmart04 has quit IRC | 08:13 | |
*** mattgo has quit IRC | 08:16 | |
*** jpich has joined #openstack | 08:19 | |
*** aojea has joined #openstack | 08:22 | |
*** skazi has joined #openstack | 08:23 | |
*** shyambiradar has joined #openstack | 08:26 | |
*** ChrisNBlum is now known as ChrisNBlum_away | 08:26 | |
*** janki has quit IRC | 08:36 | |
*** skazi has quit IRC | 08:36 | |
*** ktibi has joined #openstack | 08:37 | |
*** J0ck3r has joined #openstack | 08:37 | |
*** brokencycle has joined #openstack | 08:37 | |
J0ck3r | Hello good morning/afternoon, do you know if it's possible to integrate keycloak as SSO for Openstack? I am searching for guides or information but i can't see any | 08:38 |
---|---|---|
*** gmoro has joined #openstack | 08:43 | |
*** aojea has quit IRC | 08:54 | |
*** rmart04 has joined #openstack | 09:00 | |
*** ktibi has quit IRC | 09:00 | |
*** ktibi has joined #openstack | 09:01 | |
*** ChrisNBlum_away is now known as ChrisNBlum | 09:02 | |
egonzalez | J0ck3r, https://access.redhat.com/solutions/3010401 | 09:06 |
*** shyambiradar has quit IRC | 09:06 | |
*** electrofelix has joined #openstack | 09:11 | |
*** salmankhan has joined #openstack | 09:14 | |
*** josecastroleon has quit IRC | 09:14 | |
*** janki has joined #openstack | 09:15 | |
*** shyambiradar has joined #openstack | 09:15 | |
*** gregoryo has quit IRC | 09:16 | |
*** josecastroleon has joined #openstack | 09:19 | |
J0ck3r | egonzalez: thanks a lot ... this was the unique page that i have found .... but i was not sure because it says SOLUTION UNVERIFIED | 09:21 |
*** shyambiradar has quit IRC | 09:38 | |
*** goutham1 has joined #openstack | 09:41 | |
goutham1 | HI all i a facing this issue in rally when i try to create a deployment it throws this error Env manager got invalid spec: | 09:41 |
goutham1 | rally deployment create --fromenv --name=existing | 09:42 |
goutham1 | Env manager got invalid spec: | 09:42 |
goutham1 | ["There is no Platform plugin with name: 'existing@openstack'"] | 09:42 |
*** sm806 has quit IRC | 09:51 | |
*** donghm has joined #openstack | 09:55 | |
*** damnlie_ has quit IRC | 09:55 | |
*** goutham1 has quit IRC | 10:04 | |
*** Emine has quit IRC | 10:04 | |
*** Emine has joined #openstack | 10:04 | |
*** Son_Goku has joined #openstack | 10:07 | |
*** neiljerram has joined #openstack | 10:08 | |
*** gunix1 has joined #openstack | 10:08 | |
neiljerram | Good morning everyone. | 10:10 |
neiljerram | I am struggling with a problem in Queens where I can do novaclient.images.list() if novaclient is for the admin tenant, but I get 401 if novaclient is for some other tenant/project. | 10:10 |
neiljerram | This was working in a Pike installation, and using Keystone v2 for authentication. In my Queens install I don't have Keystone v2 so am now using Keystone v3 for auth. | 10:10 |
*** gunix1 is now known as gunix | 10:10 | |
neiljerram | Any thoughts? | 10:10 |
*** mattgo has joined #openstack | 10:11 | |
neiljerram | I believe any tenant/project should be able to list images, right? | 10:11 |
neiljerram | When I do novaclient.images.list() with a non-admin tenant, and get 401, there is no new logging in nova-api.log. (Whereas when I do a successful list with the admin tenant, I see a 200 log line in nova-api.log.) | 10:11 |
neiljerram | Therefore I guess that this 401 is coming from some middleware before nova-api? But I don't know how to debug or see any logging for that middleware... | 10:11 |
*** gkadam has quit IRC | 10:13 | |
*** ChrisNBlum is now known as ChrisNBlum_away | 10:13 | |
*** gkadam has joined #openstack | 10:13 | |
*** mattgo has quit IRC | 10:15 | |
*** mdih has quit IRC | 10:25 | |
*** goutham1 has joined #openstack | 10:26 | |
*** shyambiradar has joined #openstack | 10:28 | |
*** goutham1 has quit IRC | 10:34 | |
*** Son_Goku has quit IRC | 10:37 | |
*** neatherweb_ has quit IRC | 10:40 | |
*** gildub has joined #openstack | 10:43 | |
umbSublime | neiljerram: I'd suggest ussing openstacksdk/shade for this type of things :) | 10:46 |
neiljerram | umbSublime, Would that make an important difference? | 10:47 |
umbSublime | you can specify keystone version at least | 10:48 |
umbSublime | and it uses the more modern clouds.yaml config file over openrc/env_vars | 10:48 |
neiljerram | My guess is that what I need is to better understand how keystone v3 users work, and/or to be able to debug the middleware that does stuff before the request gets to nova-api. | 10:50 |
neiljerram | (And I guess that that would be independent of the client toolkit.) | 10:51 |
*** dhill_ has quit IRC | 10:51 | |
neiljerram | Re "you can specify keystone version at least" - my deployment only has keystone v3, and I believe my client code is using that. | 10:52 |
neiljerram | Re "it uses the more modern clouds.yaml config file over openrc/env_vars" - I'm doing things programmatically in Python, so I don't think that's involving any openrc or env vars or YAML... | 10:53 |
*** mattgo has joined #openstack | 10:59 | |
*** georgem1 has joined #openstack | 11:00 | |
*** shyambiradar has quit IRC | 11:07 | |
*** shyambiradar has joined #openstack | 11:10 | |
*** aojea has joined #openstack | 11:20 | |
*** luizbag has joined #openstack | 11:22 | |
*** donghm has quit IRC | 11:24 | |
*** shyambiradar has quit IRC | 11:24 | |
*** shyambiradar has joined #openstack | 11:25 | |
*** morazi has joined #openstack | 11:28 | |
*** bobh_ has joined #openstack | 11:31 | |
*** shyambiradar has quit IRC | 11:32 | |
*** Son_Goku has joined #openstack | 11:32 | |
*** aojea has quit IRC | 11:33 | |
*** mdih has joined #openstack | 11:40 | |
*** ChrisNBlum_away is now known as ChrisNBlum | 11:42 | |
*** smhanes has joined #openstack | 11:43 | |
*** aojea has joined #openstack | 11:45 | |
*** shiriru_ has joined #openstack | 11:52 | |
*** shyambiradar has joined #openstack | 11:56 | |
*** aojea has quit IRC | 11:58 | |
*** boazel has joined #openstack | 12:01 | |
*** neatherweb_ has joined #openstack | 12:03 | |
*** dhill_ has joined #openstack | 12:06 | |
*** J0ck3r has quit IRC | 12:09 | |
neiljerram | Can a non-admin user get a token for itself? Or does the flow need to be that an admin user gets the token for the non-admin user? | 12:11 |
*** mattgo has quit IRC | 12:13 | |
*** neatherweb_ has quit IRC | 12:14 | |
*** mattgo has joined #openstack | 12:15 | |
*** Petersingh_ has joined #openstack | 12:15 | |
*** shiriru_ has quit IRC | 12:16 | |
*** shiriru_ has joined #openstack | 12:16 | |
*** schmots has joined #openstack | 12:17 | |
*** shiriru_ has quit IRC | 12:18 | |
*** Son_Goku has quit IRC | 12:19 | |
*** Petersingh|bomga has quit IRC | 12:19 | |
*** shiriru_ has joined #openstack | 12:21 | |
*** georgem1 has quit IRC | 12:29 | |
*** lathiat_ has quit IRC | 12:30 | |
*** lathiat has joined #openstack | 12:31 | |
*** rchavik has quit IRC | 12:37 | |
*** Petersingh_ is now known as Petersingh | 12:41 | |
*** tpsilva has joined #openstack | 12:44 | |
*** lbragstad has joined #openstack | 12:46 | |
*** ianychoi has quit IRC | 12:49 | |
*** Petersingh has quit IRC | 12:49 | |
*** shyambiradar has quit IRC | 12:55 | |
*** sudodude has joined #openstack | 12:56 | |
*** josecastroleon has quit IRC | 12:57 | |
*** josecastroleon has joined #openstack | 12:57 | |
sudodude | I have a SAN with quite low throughput and I believe instance creation is timing out because of it. Is there a way to adjust how many new instances and block devices (if using Cinder) are being spawned at once? | 12:58 |
*** brokencycle has quit IRC | 12:58 | |
*** Be-El has joined #openstack | 13:01 | |
Be-El | hi | 13:01 |
*** georgem1 has joined #openstack | 13:01 | |
Be-El | are there any particular keystone policies restricting which endpoints are visible in the catalog (openstack catalog list)? | 13:02 |
Be-El | our domain admin accounts are not able to list cinder and sahara endpoint, the endpoints list for these services are empty | 13:02 |
*** Son_Goku has joined #openstack | 13:02 | |
*** gnufied has joined #openstack | 13:03 | |
*** josecastroleon has quit IRC | 13:03 | |
*** josecastroleon has joined #openstack | 13:04 | |
*** egonzalez has quit IRC | 13:06 | |
*** bdperkin has quit IRC | 13:07 | |
*** gnufied has quit IRC | 13:11 | |
*** gildub has quit IRC | 13:11 | |
*** schmots_ has joined #openstack | 13:20 | |
*** schmots has quit IRC | 13:21 | |
*** schmots_ is now known as schmots | 13:21 | |
*** pron has quit IRC | 13:22 | |
*** shiriru_ is now known as help | 13:27 | |
*** help is now known as shiriru | 13:28 | |
*** Son_Goku has quit IRC | 13:28 | |
*** Son_Goku has joined #openstack | 13:33 | |
*** jistr is now known as jistr|call | 13:39 | |
*** mamercad has joined #openstack | 13:39 | |
*** RickDeckard has joined #openstack | 13:40 | |
*** bobh_ has quit IRC | 13:44 | |
*** rvd has quit IRC | 13:47 | |
*** bdperkin has joined #openstack | 13:49 | |
*** Son_Goku has quit IRC | 13:51 | |
*** gnufied has joined #openstack | 13:57 | |
*** gnufied__ has joined #openstack | 13:57 | |
*** gnufied has quit IRC | 13:57 | |
*** Son_Goku has joined #openstack | 13:58 | |
*** jistr|call is now known as jistr | 13:59 | |
*** josecastroleon has quit IRC | 14:08 | |
*** josecastroleon has joined #openstack | 14:19 | |
*** gkadam_ has joined #openstack | 14:26 | |
*** hamdyk has quit IRC | 14:28 | |
*** gkadam has quit IRC | 14:30 | |
*** georgem1 has quit IRC | 14:30 | |
*** Son_Goku has quit IRC | 14:33 | |
gregwork | are instances with ports on a provider network able to leverage external DHCP sources? | 14:33 |
*** guhcampos has joined #openstack | 14:34 | |
*** Son_Goku has joined #openstack | 14:35 | |
*** dxiri has joined #openstack | 14:39 | |
*** saint_ has joined #openstack | 14:40 | |
*** guhcampos has quit IRC | 14:41 | |
*** guhcampos has joined #openstack | 14:42 | |
*** Son_Goku has quit IRC | 14:46 | |
*** RickDeckard has quit IRC | 14:49 | |
*** agurenko has quit IRC | 14:50 | |
*** Son_Goku has joined #openstack | 14:50 | |
*** RickDeckard has joined #openstack | 14:54 | |
*** forgotmynick has joined #openstack | 14:54 | |
*** aojea has joined #openstack | 14:55 | |
*** shiriru has quit IRC | 14:55 | |
*** Son_Goku has quit IRC | 15:00 | |
*** ivve has quit IRC | 15:03 | |
*** janki has quit IRC | 15:03 | |
*** Son_Goku has joined #openstack | 15:03 | |
*** aojea has quit IRC | 15:06 | |
*** aojea has joined #openstack | 15:07 | |
*** rmart04 has quit IRC | 15:07 | |
*** windslown has quit IRC | 15:11 | |
*** side_control has quit IRC | 15:14 | |
*** mosulica has quit IRC | 15:17 | |
*** side_control has joined #openstack | 15:19 | |
neiljerram | Be-El, I'm not sure, but I think I'm seeing something like that too. | 15:20 |
*** Son_Goku has quit IRC | 15:21 | |
*** Bhujay has quit IRC | 15:21 | |
Be-El | neiljerram: i took a closer look at the keystone source code....keystone does not reports endpoints in the catalog if no project_id is given (-> domain admin) | 15:21 |
neiljerram | I've been struggling for a while with creating a keystone v3 non-admin user that can do basic things. | 15:21 |
Be-El | neiljerram: so domain admins cannot manage project quotas for cinder.... | 15:21 |
neiljerram | Be-El, I think that's consistent with my observations. I've found that with code like the following tnova.images.list() gives an Empty Service Catalog exception: | 15:23 |
neiljerram | tauth = identity.Password(auth_url=auth_url, | 15:23 |
neiljerram | username="tenant2", | 15:23 |
neiljerram | password="password", | 15:23 |
neiljerram | #project_name="tenant2", | 15:23 |
neiljerram | #project_domain_id="default", | 15:23 |
neiljerram | user_domain_id="default") | 15:23 |
neiljerram | tsess = session.Session(auth=tauth) | 15:23 |
neiljerram | tnova = NovaClient(2, session=tsess) | 15:23 |
neiljerram | On the other hand, if I uncomment the project lines, I get 401 Authentication required. | 15:24 |
*** Son_Goku has joined #openstack | 15:25 | |
Be-El | nova should work.....see https://github.com/openstack/keystone/blob/master/keystone/catalog/backends/sql.py#L262 | 15:25 |
Be-El | the affected services are only those which use project_id or tenant_id in their url | 15:25 |
Be-El | listing images works with our domain admin accounts (openstack queens) | 15:26 |
*** Son_Goku has quit IRC | 15:27 | |
neiljerram | OK, sorry, I misread you; my problem is with non-admin users. | 15:27 |
Be-El | do you use the standard keystone v3 policy file? | 15:28 |
*** schmots_ has joined #openstack | 15:29 | |
*** schmots has quit IRC | 15:29 | |
*** schmots_ is now known as schmots | 15:29 | |
Be-El | if you use the openstack command line client with that configuration, you can run it with --debug....the json formatted token also contain the catalog visible to the openstack user | 15:31 |
spotz | Be-El: double check the policy.json file for glance(I think you said images?) | 15:38 |
Be-El | spotz: no, glance urls are not project specific | 15:39 |
Be-El | spotz: and it's not a policy problem in my case | 15:40 |
spotz | Be-El: Ok just really saw the non-admins part of the convo:) | 15:41 |
*** rmart04 has joined #openstack | 15:48 | |
*** mattgo has quit IRC | 15:48 | |
*** Be-El has quit IRC | 15:51 | |
*** morazi_ has joined #openstack | 15:54 | |
neiljerram | spotz, In my install there isn't any Nova policy file; I believe I have the standard ones in place for Keystone and Glance. | 15:54 |
*** morazi has quit IRC | 15:54 | |
spotz | Ok just saw the email come to the list so hopefully someone not on channel may have some insight | 15:55 |
*** SumitNaiksatam has quit IRC | 15:59 | |
*** woojay has joined #openstack | 16:02 | |
*** jpich has quit IRC | 16:08 | |
*** Bhujay has joined #openstack | 16:08 | |
neiljerram | spotz, Yes, fingers crossed for that! | 16:13 |
*** mikecmpbll has quit IRC | 16:21 | |
*** mikecmpbll has joined #openstack | 16:22 | |
*** sudodude has quit IRC | 16:25 | |
*** rmart04 has quit IRC | 16:25 | |
*** rmart04 has joined #openstack | 16:25 | |
*** gkadam_ has quit IRC | 16:32 | |
*** mikecmpbll has quit IRC | 16:33 | |
*** rmart04 has quit IRC | 16:35 | |
*** ktibi has quit IRC | 16:37 | |
*** Son_Goku has joined #openstack | 16:37 | |
lbragstad | neiljerram: iiuc, it sounds like your concern is going to be address by a large cross-project effort | 16:38 |
lbragstad | addressed* | 16:38 |
*** morazi_ has quit IRC | 16:40 | |
neiljerram | lbragstad, Thanks! Although that would be weird, because I'm only trying to do something with a Keystone v3-created user that I've been able to do for ages with a Keystone v2-created user... | 16:41 |
neiljerram | lbragstad, But can you point me to more specifics about this effort? | 16:41 |
*** bugzy has quit IRC | 16:48 | |
lbragstad | neiljerram: sorry - let me parse what you're trying to do again | 16:50 |
*** aojea has quit IRC | 16:51 | |
neiljerram | lbragstad, thank you | 16:52 |
lbragstad | neiljerram: reading your note to the ML | 16:52 |
lbragstad | you get a 401 using v3? | 16:53 |
*** skazi has joined #openstack | 16:53 | |
*** Son_Goku has quit IRC | 16:54 | |
*** morazi_ has joined #openstack | 16:55 | |
neiljerram | lbragstad, yes | 16:56 |
lbragstad | can you verify the user has a role on the project? | 16:57 |
lbragstad | v2.0 would automatically create a role assignment on the users default project | 16:57 |
*** schmots_ has joined #openstack | 16:57 | |
lbragstad | v3 didn't maintain that same contract | 16:57 |
*** Son_Goku has joined #openstack | 16:58 | |
*** salmankhan has quit IRC | 16:58 | |
*** schmots has quit IRC | 16:58 | |
*** schmots_ is now known as schmots | 16:58 | |
neiljerram | OK, that could be it. Let me just pastebin my code for creating that user... | 16:59 |
neiljerram | https://pastebin.com/DbnYd89y | 17:00 |
lbragstad | yeah - the user you're creating at line 15 doesn't have a role assignment on the tenant you're creating on line 6 | 17:01 |
lbragstad | you'll need an extra step are you create the user to give them a role assignment on the tenant from line 6 | 17:02 |
*** RickDeckard has quit IRC | 17:02 | |
lbragstad | neiljerram: historical context https://bugs.launchpad.net/keystone/+bug/1662911 | 17:03 |
openstack | Launchpad bug 1662911 in OpenStack Identity (keystone) "v3 API create_user does not use default_project_id" [Undecided,Invalid] | 17:03 |
neiljerram | Awesome, thank you. | 17:08 |
lbragstad | neiljerram: did the work? | 17:08 |
lbragstad | that* | 17:09 |
neiljerram | So it sounds like I need a call like keystone3.roles.grant(<role>, user=<user>, project=<project>) | 17:09 |
neiljerram | But what should the <role> be? | 17:09 |
lbragstad | yep - exactly | 17:09 |
lbragstad | whatever role that use should have | 17:09 |
lbragstad | in v2.0 this was pulled from config | 17:09 |
lbragstad | and by default it was the "member" role i believe | 17:09 |
neiljerram | Is there a "default" role? I think "admin" would be more than I should need here. | 17:09 |
neiljerram | OK, cool, so I should be able to find some default non-admin role. Let's see... | 17:10 |
neiljerram | Actually this will take me a little while, as my Queens rig is now torn down. I'll report back here a bit later! | 17:11 |
lbragstad | neiljerram: sounds good - keep in mind that some of this stuff is undergoing a lot of changes | 17:11 |
lbragstad | we're reworking a lot of the policy/rbac stuff across services, especially in keystone | 17:11 |
lbragstad | to improve the usability of it | 17:11 |
*** RickDeckard has joined #openstack | 17:12 | |
lbragstad | http://specs.openstack.org/openstack/keystone-specs/specs/keystone/ongoing/policy-security-roadmap.html provides a 10,000 ft view if you're interested in the context or backstory | 17:12 |
neiljerram | Sounds good. I'll take a look. TBH it's pretty hard to get into as a v3 newbie, right now. | 17:12 |
lbragstad | let me know if i can help clarify things, or just swing by #openstack-keystone | 17:13 |
lbragstad | there are a bunch of people there that can help | 17:13 |
*** forgotmynick has quit IRC | 17:13 | |
neiljerram | will do, thanks! | 17:13 |
*** AhmadMahmoudi has joined #openstack | 17:13 | |
lbragstad | np | 17:13 |
*** AhmadMahmoudi has quit IRC | 17:14 | |
*** AhmadMahmoudi has joined #openstack | 17:14 | |
*** gnufied__ has quit IRC | 17:24 | |
*** mdih has quit IRC | 17:29 | |
*** RickDeckard has quit IRC | 17:33 | |
*** RickDeckard has joined #openstack | 17:33 | |
*** ChrisNBlum is now known as ChrisNBlum_away | 17:38 | |
*** gnufied__ has joined #openstack | 17:39 | |
*** Bhujay has quit IRC | 17:39 | |
*** lihi has quit IRC | 17:44 | |
*** lihi has joined #openstack | 17:45 | |
*** rmart04 has joined #openstack | 17:47 | |
*** gyee has joined #openstack | 17:47 | |
*** rmart04 has quit IRC | 17:50 | |
*** rmart04 has joined #openstack | 17:51 | |
*** poopcat has joined #openstack | 17:58 | |
*** SumitNaiksatam has joined #openstack | 18:00 | |
*** georgem1 has joined #openstack | 18:01 | |
*** RickDeckard has quit IRC | 18:03 | |
*** RickDeckard has joined #openstack | 18:04 | |
*** forgotmynick has joined #openstack | 18:05 | |
*** skazi has quit IRC | 18:26 | |
*** electrofelix has quit IRC | 18:31 | |
*** cloudrancher has joined #openstack | 18:34 | |
*** cah_link has quit IRC | 18:35 | |
*** eldritch has quit IRC | 18:40 | |
*** linuxdaemon has quit IRC | 18:44 | |
*** linuxdaemon has joined #openstack | 18:52 | |
*** morazi_ has quit IRC | 18:52 | |
*** morazi has joined #openstack | 18:54 | |
*** rmart04 has quit IRC | 19:02 | |
*** RickDeckard has quit IRC | 19:03 | |
*** schmots has quit IRC | 19:04 | |
*** schmots_ has joined #openstack | 19:04 | |
*** RickDeckard has joined #openstack | 19:07 | |
*** eldritch has joined #openstack | 19:11 | |
*** skazi has joined #openstack | 19:12 | |
*** th3g1z has quit IRC | 19:19 | |
*** mikemcowie has joined #openstack | 19:22 | |
*** SumitNaiksatam has left #openstack | 19:25 | |
*** ptx0 has quit IRC | 19:33 | |
*** pcaruana has quit IRC | 19:33 | |
*** mikemcowie has quit IRC | 19:35 | |
*** mikemcowie has joined #openstack | 19:36 | |
*** ymasson has joined #openstack | 19:42 | |
*** aojea has joined #openstack | 19:47 | |
*** Son_Goku has quit IRC | 19:56 | |
*** schmots_ has quit IRC | 19:57 | |
*** RickDeckard has quit IRC | 20:01 | |
*** RickDeckard has joined #openstack | 20:01 | |
*** mikemcowie has quit IRC | 20:05 | |
*** muo has quit IRC | 20:07 | |
*** mamercad has quit IRC | 20:08 | |
*** muo has joined #openstack | 20:09 | |
*** nicolasbock has quit IRC | 20:11 | |
*** ptx0_ has joined #openstack | 20:15 | |
*** cloudrancher has quit IRC | 20:18 | |
*** ptx0_ is now known as ptx0 | 20:20 | |
*** mikecmpbll has joined #openstack | 20:22 | |
*** schmots has joined #openstack | 20:24 | |
*** georgem1 has quit IRC | 20:38 | |
*** guhcampos has quit IRC | 20:40 | |
*** yamahata_ has joined #openstack | 20:47 | |
*** lbragstad has quit IRC | 20:51 | |
*** yamahata_ is now known as yamahata__ | 21:04 | |
*** RickDeckard has quit IRC | 21:04 | |
*** yamahata__ is now known as yamahata | 21:05 | |
*** RickDeckard has joined #openstack | 21:06 | |
*** RickDeckard has quit IRC | 21:11 | |
*** RickDeckard has joined #openstack | 21:12 | |
*** dosaboy has joined #openstack | 21:14 | |
*** yamahata has quit IRC | 21:17 | |
*** rmart04 has joined #openstack | 21:18 | |
*** yamahata has joined #openstack | 21:20 | |
*** rmart04 has quit IRC | 21:20 | |
*** schmots has quit IRC | 21:22 | |
*** isq has joined #openstack | 21:22 | |
*** slaweq has quit IRC | 21:26 | |
*** rmart04 has joined #openstack | 21:30 | |
*** luizbag has quit IRC | 21:33 | |
*** rmart04 has quit IRC | 21:34 | |
*** iyamahat has joined #openstack | 21:35 | |
*** iyamahat has quit IRC | 21:36 | |
*** iyamahat has joined #openstack | 21:37 | |
*** iyamahat has quit IRC | 21:41 | |
*** iyamahat has joined #openstack | 21:42 | |
*** isq_ has joined #openstack | 21:47 | |
*** isq has quit IRC | 21:48 | |
*** lbragstad has joined #openstack | 21:55 | |
*** RickDeckard has quit IRC | 21:56 | |
*** RickDeckard has joined #openstack | 21:57 | |
*** mchlumsky has quit IRC | 21:58 | |
*** RickDeckard has quit IRC | 22:02 | |
*** neiljerram has quit IRC | 22:08 | |
*** rcernin has joined #openstack | 22:09 | |
*** slaweq has joined #openstack | 22:11 | |
*** imacdonn has quit IRC | 22:12 | |
*** imacdonn has joined #openstack | 22:12 | |
*** tobasco is now known as tobias-urdin | 22:14 | |
*** slaweq has quit IRC | 22:15 | |
*** Son_Goku has joined #openstack | 22:33 | |
*** forgotmynick has quit IRC | 22:34 | |
*** skazi has quit IRC | 22:44 | |
*** aojea has quit IRC | 22:46 | |
*** boazel has quit IRC | 22:48 | |
*** Son_Goku has quit IRC | 23:05 | |
*** gyee has quit IRC | 23:06 | |
*** tpsilva has quit IRC | 23:10 | |
*** slaweq has joined #openstack | 23:11 | |
*** gildub has joined #openstack | 23:11 | |
*** Son_Goku has joined #openstack | 23:15 | |
*** slaweq has quit IRC | 23:16 | |
*** AhmadMahmoudi has quit IRC | 23:19 | |
*** Son_Goku has quit IRC | 23:25 | |
*** RickDeckard has joined #openstack | 23:31 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!