| *** tkimball has joined #openstack | 00:00 | |
| *** gyee has quit IRC | 00:00 | |
| *** bobh has joined #openstack | 00:04 | |
| *** poopcat has joined #openstack | 00:05 | |
| *** bobh has quit IRC | 00:08 | |
| *** bobh has joined #openstack | 00:09 | |
| *** r-daneel has quit IRC | 00:10 | |
| *** bobh has quit IRC | 00:13 | |
| *** dhill_ has joined #openstack | 00:28 | |
| *** dhill_ has quit IRC | 00:29 | |
| *** dhill_ has joined #openstack | 00:29 | |
| *** SunWuKung has joined #openstack | 00:33 | |
| *** foul_owl has quit IRC | 00:37 | |
| *** SunWuKung has quit IRC | 00:45 | |
| *** kei-ichi has quit IRC | 00:47 | |
| *** kei-ichi has joined #openstack | 00:49 | |
| *** dhill_ has quit IRC | 00:49 | |
| *** foul_owl has joined #openstack | 00:52 | |
| *** donghm has joined #openstack | 00:59 | |
| *** gregoryo has joined #openstack | 01:07 | |
| *** bucketm0use has quit IRC | 01:10 | |
| *** bucketm0use has joined #openstack | 01:10 | |
| *** ircuser-1 has quit IRC | 01:27 | |
| *** brokencycle has quit IRC | 01:38 | |
| *** Son_Goku has joined #openstack | 01:48 | |
| *** mdih has joined #openstack | 01:50 | |
| *** SumitNaiksatam has joined #openstack | 01:56 | |
| *** mrsoul has quit IRC | 01:59 | |
| *** Son_Goku has quit IRC | 02:01 | |
| *** rchavik has joined #openstack | 02:07 | |
| *** Obi-Wan has quit IRC | 02:26 | |
| *** gnufied has quit IRC | 02:29 | |
| *** Bhujay has joined #openstack | 02:30 | |
| *** Bhujay has quit IRC | 02:30 | |
| *** Bhujay has joined #openstack | 02:31 | |
| *** Nel1x has joined #openstack | 02:36 | |
| *** rmcallis has joined #openstack | 02:39 | |
| *** rmcall has quit IRC | 02:41 | |
| *** Bhujay has quit IRC | 02:51 | |
| *** mdih has quit IRC | 02:51 | |
| *** bobh has joined #openstack | 02:53 | |
| *** bobh has quit IRC | 02:55 | |
| *** rmcall has joined #openstack | 02:56 | |
| *** bobh has joined #openstack | 02:56 | |
| *** rmcallis has quit IRC | 02:57 | |
| *** bobh has quit IRC | 02:57 | |
| *** bobh_ has joined #openstack | 03:08 | |
| *** bobh_ has quit IRC | 03:11 | |
| *** dnickelson has quit IRC | 03:19 | |
| *** neatherweb_ has quit IRC | 03:27 | |
| *** dhill_ has joined #openstack | 03:35 | |
| *** Petersingh has joined #openstack | 03:39 | |
| *** dhill_ has quit IRC | 03:40 | |
| *** dhill_ has joined #openstack | 03:43 | |
| *** bobh_ has joined #openstack | 03:44 | |
| *** janki has joined #openstack | 03:57 | |
| *** bobh_ has quit IRC | 04:01 | |
| *** poopcat has quit IRC | 04:03 | |
| *** rvd has joined #openstack | 04:06 | |
| *** e0ne has joined #openstack | 04:11 | |
| *** Nel1x has quit IRC | 04:14 | |
| *** neatherweb_ has joined #openstack | 04:19 | |
| *** Croata has quit IRC | 04:24 | |
| *** e0ne has quit IRC | 04:24 | |
| *** gkadam has joined #openstack | 04:28 | |
| *** Bhujay has joined #openstack | 04:32 | |
| *** Bhujay has quit IRC | 04:34 | |
| *** tkimball has quit IRC | 04:36 | |
| *** albertom has quit IRC | 04:40 | |
| *** markvoelker has joined #openstack | 04:41 | |
| *** Son_Goku has joined #openstack | 04:45 | |
| *** magicrhesus has quit IRC | 04:56 | |
| *** Son_Goku has quit IRC | 04:57 | |
| *** magicrhesus has joined #openstack | 04:57 | |
| *** ircuser-1 has joined #openstack | 05:03 | |
| *** Son_Goku has joined #openstack | 05:17 | |
| *** shyambiradar has joined #openstack | 05:21 | |
| *** Petersingh is now known as Petersingh|afk | 05:30 | |
| *** sauvin has joined #openstack | 05:31 | |
| *** nicolasbock has joined #openstack | 05:34 | |
| *** mosulica has joined #openstack | 05:43 | |
| *** Petersingh|afk is now known as Petersingh | 05:43 | |
| *** cah_link has joined #openstack | 05:43 | |
| *** Son_Goku has quit IRC | 05:52 | |
| *** shyambiradar has quit IRC | 05:53 | |
| *** Arsenick has quit IRC | 05:58 | |
| *** mdih has joined #openstack | 06:00 | |
| *** mosulica has quit IRC | 06:05 | |
| *** ymasson has quit IRC | 06:06 | |
| *** Croata has joined #openstack | 06:10 | |
| *** mosulica has joined #openstack | 06:16 | |
| *** mosulica has quit IRC | 06:21 | |
| *** agurenko has joined #openstack | 06:21 | |
| *** hamdyk has joined #openstack | 06:21 | |
| *** mosulica has joined #openstack | 06:22 | |
| *** egonzalez has joined #openstack | 06:24 | |
| *** Emine has joined #openstack | 06:28 | |
| *** mosulica has quit IRC | 06:31 | |
| *** mosulica has joined #openstack | 06:32 | |
| *** nicolasbock has quit IRC | 06:35 | |
| *** pcaruana has joined #openstack | 06:38 | |
| *** nicolasbock has joined #openstack | 06:41 | |
| *** Croata has quit IRC | 06:48 | |
| *** cloudrancher has quit IRC | 06:50 | |
| *** cloudrancher has joined #openstack | 06:52 | |
| *** cloudrancher has quit IRC | 06:52 | |
| *** foul_owl has quit IRC | 06:53 | |
| *** mosulica has quit IRC | 06:59 | |
| *** Son_Goku has joined #openstack | 07:04 | |
| *** ChrisNBlum_away has joined #openstack | 07:06 | |
| *** shakalaka has joined #openstack | 07:07 | |
| *** ChrisNBlum_away is now known as ChrisNBlum | 07:10 | |
| *** foul_owl has joined #openstack | 07:10 | |
| *** mosulica has joined #openstack | 07:10 | |
| *** shyambiradar has joined #openstack | 07:11 | |
| *** Obi-Wan has joined #openstack | 07:12 | |
| *** rmart04 has joined #openstack | 07:14 | |
| *** ChrisNBlum has quit IRC | 07:15 | |
| *** ChrisNBlum has joined #openstack | 07:15 | |
| *** Bhujay has joined #openstack | 07:16 | |
| *** rcernin has quit IRC | 07:16 | |
| *** donghm has quit IRC | 07:18 | |
| *** Petersingh is now known as Petersingh|bomga | 07:18 | |
| *** Bhujay has quit IRC | 07:22 | |
| *** agurenko has quit IRC | 07:25 | |
| *** mattgo has joined #openstack | 07:25 | |
| *** rmart04_ has joined #openstack | 07:26 | |
| *** rmart04 has quit IRC | 07:26 | |
| *** rmart04_ is now known as rmart04 | 07:26 | |
| *** agurenko has joined #openstack | 07:28 | |
| *** Son_Goku has quit IRC | 07:34 | |
| *** shyambiradar has quit IRC | 07:38 | |
| *** shyambiradar has joined #openstack | 07:39 | |
| *** Bhujay has joined #openstack | 07:40 | |
| *** Son_Goku has joined #openstack | 07:44 | |
| *** assassin has quit IRC | 07:48 | |
| *** skazi has quit IRC | 07:54 | |
| *** gildub has quit IRC | 07:57 | |
| *** Son_Goku has quit IRC | 08:01 | |
| *** mikecmpbll has joined #openstack | 08:05 | |
| *** shyambiradar has quit IRC | 08:11 | |
| *** rmart04 has quit IRC | 08:13 | |
| *** mattgo has quit IRC | 08:16 | |
| *** jpich has joined #openstack | 08:19 | |
| *** aojea has joined #openstack | 08:22 | |
| *** skazi has joined #openstack | 08:23 | |
| *** shyambiradar has joined #openstack | 08:26 | |
| *** ChrisNBlum is now known as ChrisNBlum_away | 08:26 | |
| *** janki has quit IRC | 08:36 | |
| *** skazi has quit IRC | 08:36 | |
| *** ktibi has joined #openstack | 08:37 | |
| *** J0ck3r has joined #openstack | 08:37 | |
| *** brokencycle has joined #openstack | 08:37 | |
| J0ck3r | Hello good morning/afternoon, do you know if it's possible to integrate keycloak as SSO for Openstack? I am searching for guides or information but i can't see any | 08:38 |
|---|---|---|
| *** gmoro has joined #openstack | 08:43 | |
| *** aojea has quit IRC | 08:54 | |
| *** rmart04 has joined #openstack | 09:00 | |
| *** ktibi has quit IRC | 09:00 | |
| *** ktibi has joined #openstack | 09:01 | |
| *** ChrisNBlum_away is now known as ChrisNBlum | 09:02 | |
| egonzalez | J0ck3r, https://access.redhat.com/solutions/3010401 | 09:06 |
| *** shyambiradar has quit IRC | 09:06 | |
| *** electrofelix has joined #openstack | 09:11 | |
| *** salmankhan has joined #openstack | 09:14 | |
| *** josecastroleon has quit IRC | 09:14 | |
| *** janki has joined #openstack | 09:15 | |
| *** shyambiradar has joined #openstack | 09:15 | |
| *** gregoryo has quit IRC | 09:16 | |
| *** josecastroleon has joined #openstack | 09:19 | |
| J0ck3r | egonzalez: thanks a lot ... this was the unique page that i have found .... but i was not sure because it says SOLUTION UNVERIFIED | 09:21 |
| *** shyambiradar has quit IRC | 09:38 | |
| *** goutham1 has joined #openstack | 09:41 | |
| goutham1 | HI all i a facing this issue in rally when i try to create a deployment it throws this error Env manager got invalid spec: | 09:41 |
| goutham1 | rally deployment create --fromenv --name=existing | 09:42 |
| goutham1 | Env manager got invalid spec: | 09:42 |
| goutham1 | ["There is no Platform plugin with name: 'existing@openstack'"] | 09:42 |
| *** sm806 has quit IRC | 09:51 | |
| *** donghm has joined #openstack | 09:55 | |
| *** damnlie_ has quit IRC | 09:55 | |
| *** goutham1 has quit IRC | 10:04 | |
| *** Emine has quit IRC | 10:04 | |
| *** Emine has joined #openstack | 10:04 | |
| *** Son_Goku has joined #openstack | 10:07 | |
| *** neiljerram has joined #openstack | 10:08 | |
| *** gunix1 has joined #openstack | 10:08 | |
| neiljerram | Good morning everyone. | 10:10 |
| neiljerram | I am struggling with a problem in Queens where I can do novaclient.images.list() if novaclient is for the admin tenant, but I get 401 if novaclient is for some other tenant/project. | 10:10 |
| neiljerram | This was working in a Pike installation, and using Keystone v2 for authentication. In my Queens install I don't have Keystone v2 so am now using Keystone v3 for auth. | 10:10 |
| *** gunix1 is now known as gunix | 10:10 | |
| neiljerram | Any thoughts? | 10:10 |
| *** mattgo has joined #openstack | 10:11 | |
| neiljerram | I believe any tenant/project should be able to list images, right? | 10:11 |
| neiljerram | When I do novaclient.images.list() with a non-admin tenant, and get 401, there is no new logging in nova-api.log. (Whereas when I do a successful list with the admin tenant, I see a 200 log line in nova-api.log.) | 10:11 |
| neiljerram | Therefore I guess that this 401 is coming from some middleware before nova-api? But I don't know how to debug or see any logging for that middleware... | 10:11 |
| *** gkadam has quit IRC | 10:13 | |
| *** ChrisNBlum is now known as ChrisNBlum_away | 10:13 | |
| *** gkadam has joined #openstack | 10:13 | |
| *** mattgo has quit IRC | 10:15 | |
| *** mdih has quit IRC | 10:25 | |
| *** goutham1 has joined #openstack | 10:26 | |
| *** shyambiradar has joined #openstack | 10:28 | |
| *** goutham1 has quit IRC | 10:34 | |
| *** Son_Goku has quit IRC | 10:37 | |
| *** neatherweb_ has quit IRC | 10:40 | |
| *** gildub has joined #openstack | 10:43 | |
| umbSublime | neiljerram: I'd suggest ussing openstacksdk/shade for this type of things :) | 10:46 |
| neiljerram | umbSublime, Would that make an important difference? | 10:47 |
| umbSublime | you can specify keystone version at least | 10:48 |
| umbSublime | and it uses the more modern clouds.yaml config file over openrc/env_vars | 10:48 |
| neiljerram | My guess is that what I need is to better understand how keystone v3 users work, and/or to be able to debug the middleware that does stuff before the request gets to nova-api. | 10:50 |
| neiljerram | (And I guess that that would be independent of the client toolkit.) | 10:51 |
| *** dhill_ has quit IRC | 10:51 | |
| neiljerram | Re "you can specify keystone version at least" - my deployment only has keystone v3, and I believe my client code is using that. | 10:52 |
| neiljerram | Re "it uses the more modern clouds.yaml config file over openrc/env_vars" - I'm doing things programmatically in Python, so I don't think that's involving any openrc or env vars or YAML... | 10:53 |
| *** mattgo has joined #openstack | 10:59 | |
| *** georgem1 has joined #openstack | 11:00 | |
| *** shyambiradar has quit IRC | 11:07 | |
| *** shyambiradar has joined #openstack | 11:10 | |
| *** aojea has joined #openstack | 11:20 | |
| *** luizbag has joined #openstack | 11:22 | |
| *** donghm has quit IRC | 11:24 | |
| *** shyambiradar has quit IRC | 11:24 | |
| *** shyambiradar has joined #openstack | 11:25 | |
| *** morazi has joined #openstack | 11:28 | |
| *** bobh_ has joined #openstack | 11:31 | |
| *** shyambiradar has quit IRC | 11:32 | |
| *** Son_Goku has joined #openstack | 11:32 | |
| *** aojea has quit IRC | 11:33 | |
| *** mdih has joined #openstack | 11:40 | |
| *** ChrisNBlum_away is now known as ChrisNBlum | 11:42 | |
| *** smhanes has joined #openstack | 11:43 | |
| *** aojea has joined #openstack | 11:45 | |
| *** shiriru_ has joined #openstack | 11:52 | |
| *** shyambiradar has joined #openstack | 11:56 | |
| *** aojea has quit IRC | 11:58 | |
| *** boazel has joined #openstack | 12:01 | |
| *** neatherweb_ has joined #openstack | 12:03 | |
| *** dhill_ has joined #openstack | 12:06 | |
| *** J0ck3r has quit IRC | 12:09 | |
| neiljerram | Can a non-admin user get a token for itself? Or does the flow need to be that an admin user gets the token for the non-admin user? | 12:11 |
| *** mattgo has quit IRC | 12:13 | |
| *** neatherweb_ has quit IRC | 12:14 | |
| *** mattgo has joined #openstack | 12:15 | |
| *** Petersingh_ has joined #openstack | 12:15 | |
| *** shiriru_ has quit IRC | 12:16 | |
| *** shiriru_ has joined #openstack | 12:16 | |
| *** schmots has joined #openstack | 12:17 | |
| *** shiriru_ has quit IRC | 12:18 | |
| *** Son_Goku has quit IRC | 12:19 | |
| *** Petersingh|bomga has quit IRC | 12:19 | |
| *** shiriru_ has joined #openstack | 12:21 | |
| *** georgem1 has quit IRC | 12:29 | |
| *** lathiat_ has quit IRC | 12:30 | |
| *** lathiat has joined #openstack | 12:31 | |
| *** rchavik has quit IRC | 12:37 | |
| *** Petersingh_ is now known as Petersingh | 12:41 | |
| *** tpsilva has joined #openstack | 12:44 | |
| *** lbragstad has joined #openstack | 12:46 | |
| *** ianychoi has quit IRC | 12:49 | |
| *** Petersingh has quit IRC | 12:49 | |
| *** shyambiradar has quit IRC | 12:55 | |
| *** sudodude has joined #openstack | 12:56 | |
| *** josecastroleon has quit IRC | 12:57 | |
| *** josecastroleon has joined #openstack | 12:57 | |
| sudodude | I have a SAN with quite low throughput and I believe instance creation is timing out because of it. Is there a way to adjust how many new instances and block devices (if using Cinder) are being spawned at once? | 12:58 |
| *** brokencycle has quit IRC | 12:58 | |
| *** Be-El has joined #openstack | 13:01 | |
| Be-El | hi | 13:01 |
| *** georgem1 has joined #openstack | 13:01 | |
| Be-El | are there any particular keystone policies restricting which endpoints are visible in the catalog (openstack catalog list)? | 13:02 |
| Be-El | our domain admin accounts are not able to list cinder and sahara endpoint, the endpoints list for these services are empty | 13:02 |
| *** Son_Goku has joined #openstack | 13:02 | |
| *** gnufied has joined #openstack | 13:03 | |
| *** josecastroleon has quit IRC | 13:03 | |
| *** josecastroleon has joined #openstack | 13:04 | |
| *** egonzalez has quit IRC | 13:06 | |
| *** bdperkin has quit IRC | 13:07 | |
| *** gnufied has quit IRC | 13:11 | |
| *** gildub has quit IRC | 13:11 | |
| *** schmots_ has joined #openstack | 13:20 | |
| *** schmots has quit IRC | 13:21 | |
| *** schmots_ is now known as schmots | 13:21 | |
| *** pron has quit IRC | 13:22 | |
| *** shiriru_ is now known as help | 13:27 | |
| *** help is now known as shiriru | 13:28 | |
| *** Son_Goku has quit IRC | 13:28 | |
| *** Son_Goku has joined #openstack | 13:33 | |
| *** jistr is now known as jistr|call | 13:39 | |
| *** mamercad has joined #openstack | 13:39 | |
| *** RickDeckard has joined #openstack | 13:40 | |
| *** bobh_ has quit IRC | 13:44 | |
| *** rvd has quit IRC | 13:47 | |
| *** bdperkin has joined #openstack | 13:49 | |
| *** Son_Goku has quit IRC | 13:51 | |
| *** gnufied has joined #openstack | 13:57 | |
| *** gnufied__ has joined #openstack | 13:57 | |
| *** gnufied has quit IRC | 13:57 | |
| *** Son_Goku has joined #openstack | 13:58 | |
| *** jistr|call is now known as jistr | 13:59 | |
| *** josecastroleon has quit IRC | 14:08 | |
| *** josecastroleon has joined #openstack | 14:19 | |
| *** gkadam_ has joined #openstack | 14:26 | |
| *** hamdyk has quit IRC | 14:28 | |
| *** gkadam has quit IRC | 14:30 | |
| *** georgem1 has quit IRC | 14:30 | |
| *** Son_Goku has quit IRC | 14:33 | |
| gregwork | are instances with ports on a provider network able to leverage external DHCP sources? | 14:33 |
| *** guhcampos has joined #openstack | 14:34 | |
| *** Son_Goku has joined #openstack | 14:35 | |
| *** dxiri has joined #openstack | 14:39 | |
| *** saint_ has joined #openstack | 14:40 | |
| *** guhcampos has quit IRC | 14:41 | |
| *** guhcampos has joined #openstack | 14:42 | |
| *** Son_Goku has quit IRC | 14:46 | |
| *** RickDeckard has quit IRC | 14:49 | |
| *** agurenko has quit IRC | 14:50 | |
| *** Son_Goku has joined #openstack | 14:50 | |
| *** RickDeckard has joined #openstack | 14:54 | |
| *** forgotmynick has joined #openstack | 14:54 | |
| *** aojea has joined #openstack | 14:55 | |
| *** shiriru has quit IRC | 14:55 | |
| *** Son_Goku has quit IRC | 15:00 | |
| *** ivve has quit IRC | 15:03 | |
| *** janki has quit IRC | 15:03 | |
| *** Son_Goku has joined #openstack | 15:03 | |
| *** aojea has quit IRC | 15:06 | |
| *** aojea has joined #openstack | 15:07 | |
| *** rmart04 has quit IRC | 15:07 | |
| *** windslown has quit IRC | 15:11 | |
| *** side_control has quit IRC | 15:14 | |
| *** mosulica has quit IRC | 15:17 | |
| *** side_control has joined #openstack | 15:19 | |
| neiljerram | Be-El, I'm not sure, but I think I'm seeing something like that too. | 15:20 |
| *** Son_Goku has quit IRC | 15:21 | |
| *** Bhujay has quit IRC | 15:21 | |
| Be-El | neiljerram: i took a closer look at the keystone source code....keystone does not reports endpoints in the catalog if no project_id is given (-> domain admin) | 15:21 |
| neiljerram | I've been struggling for a while with creating a keystone v3 non-admin user that can do basic things. | 15:21 |
| Be-El | neiljerram: so domain admins cannot manage project quotas for cinder.... | 15:21 |
| neiljerram | Be-El, I think that's consistent with my observations. I've found that with code like the following tnova.images.list() gives an Empty Service Catalog exception: | 15:23 |
| neiljerram | tauth = identity.Password(auth_url=auth_url, | 15:23 |
| neiljerram | username="tenant2", | 15:23 |
| neiljerram | password="password", | 15:23 |
| neiljerram | #project_name="tenant2", | 15:23 |
| neiljerram | #project_domain_id="default", | 15:23 |
| neiljerram | user_domain_id="default") | 15:23 |
| neiljerram | tsess = session.Session(auth=tauth) | 15:23 |
| neiljerram | tnova = NovaClient(2, session=tsess) | 15:23 |
| neiljerram | On the other hand, if I uncomment the project lines, I get 401 Authentication required. | 15:24 |
| *** Son_Goku has joined #openstack | 15:25 | |
| Be-El | nova should work.....see https://github.com/openstack/keystone/blob/master/keystone/catalog/backends/sql.py#L262 | 15:25 |
| Be-El | the affected services are only those which use project_id or tenant_id in their url | 15:25 |
| Be-El | listing images works with our domain admin accounts (openstack queens) | 15:26 |
| *** Son_Goku has quit IRC | 15:27 | |
| neiljerram | OK, sorry, I misread you; my problem is with non-admin users. | 15:27 |
| Be-El | do you use the standard keystone v3 policy file? | 15:28 |
| *** schmots_ has joined #openstack | 15:29 | |
| *** schmots has quit IRC | 15:29 | |
| *** schmots_ is now known as schmots | 15:29 | |
| Be-El | if you use the openstack command line client with that configuration, you can run it with --debug....the json formatted token also contain the catalog visible to the openstack user | 15:31 |
| spotz | Be-El: double check the policy.json file for glance(I think you said images?) | 15:38 |
| Be-El | spotz: no, glance urls are not project specific | 15:39 |
| Be-El | spotz: and it's not a policy problem in my case | 15:40 |
| spotz | Be-El: Ok just really saw the non-admins part of the convo:) | 15:41 |
| *** rmart04 has joined #openstack | 15:48 | |
| *** mattgo has quit IRC | 15:48 | |
| *** Be-El has quit IRC | 15:51 | |
| *** morazi_ has joined #openstack | 15:54 | |
| neiljerram | spotz, In my install there isn't any Nova policy file; I believe I have the standard ones in place for Keystone and Glance. | 15:54 |
| *** morazi has quit IRC | 15:54 | |
| spotz | Ok just saw the email come to the list so hopefully someone not on channel may have some insight | 15:55 |
| *** SumitNaiksatam has quit IRC | 15:59 | |
| *** woojay has joined #openstack | 16:02 | |
| *** jpich has quit IRC | 16:08 | |
| *** Bhujay has joined #openstack | 16:08 | |
| neiljerram | spotz, Yes, fingers crossed for that! | 16:13 |
| *** mikecmpbll has quit IRC | 16:21 | |
| *** mikecmpbll has joined #openstack | 16:22 | |
| *** sudodude has quit IRC | 16:25 | |
| *** rmart04 has quit IRC | 16:25 | |
| *** rmart04 has joined #openstack | 16:25 | |
| *** gkadam_ has quit IRC | 16:32 | |
| *** mikecmpbll has quit IRC | 16:33 | |
| *** rmart04 has quit IRC | 16:35 | |
| *** ktibi has quit IRC | 16:37 | |
| *** Son_Goku has joined #openstack | 16:37 | |
| lbragstad | neiljerram: iiuc, it sounds like your concern is going to be address by a large cross-project effort | 16:38 |
| lbragstad | addressed* | 16:38 |
| *** morazi_ has quit IRC | 16:40 | |
| neiljerram | lbragstad, Thanks! Although that would be weird, because I'm only trying to do something with a Keystone v3-created user that I've been able to do for ages with a Keystone v2-created user... | 16:41 |
| neiljerram | lbragstad, But can you point me to more specifics about this effort? | 16:41 |
| *** bugzy has quit IRC | 16:48 | |
| lbragstad | neiljerram: sorry - let me parse what you're trying to do again | 16:50 |
| *** aojea has quit IRC | 16:51 | |
| neiljerram | lbragstad, thank you | 16:52 |
| lbragstad | neiljerram: reading your note to the ML | 16:52 |
| lbragstad | you get a 401 using v3? | 16:53 |
| *** skazi has joined #openstack | 16:53 | |
| *** Son_Goku has quit IRC | 16:54 | |
| *** morazi_ has joined #openstack | 16:55 | |
| neiljerram | lbragstad, yes | 16:56 |
| lbragstad | can you verify the user has a role on the project? | 16:57 |
| lbragstad | v2.0 would automatically create a role assignment on the users default project | 16:57 |
| *** schmots_ has joined #openstack | 16:57 | |
| lbragstad | v3 didn't maintain that same contract | 16:57 |
| *** Son_Goku has joined #openstack | 16:58 | |
| *** salmankhan has quit IRC | 16:58 | |
| *** schmots has quit IRC | 16:58 | |
| *** schmots_ is now known as schmots | 16:58 | |
| neiljerram | OK, that could be it. Let me just pastebin my code for creating that user... | 16:59 |
| neiljerram | https://pastebin.com/DbnYd89y | 17:00 |
| lbragstad | yeah - the user you're creating at line 15 doesn't have a role assignment on the tenant you're creating on line 6 | 17:01 |
| lbragstad | you'll need an extra step are you create the user to give them a role assignment on the tenant from line 6 | 17:02 |
| *** RickDeckard has quit IRC | 17:02 | |
| lbragstad | neiljerram: historical context https://bugs.launchpad.net/keystone/+bug/1662911 | 17:03 |
| openstack | Launchpad bug 1662911 in OpenStack Identity (keystone) "v3 API create_user does not use default_project_id" [Undecided,Invalid] | 17:03 |
| neiljerram | Awesome, thank you. | 17:08 |
| lbragstad | neiljerram: did the work? | 17:08 |
| lbragstad | that* | 17:09 |
| neiljerram | So it sounds like I need a call like keystone3.roles.grant(<role>, user=<user>, project=<project>) | 17:09 |
| neiljerram | But what should the <role> be? | 17:09 |
| lbragstad | yep - exactly | 17:09 |
| lbragstad | whatever role that use should have | 17:09 |
| lbragstad | in v2.0 this was pulled from config | 17:09 |
| lbragstad | and by default it was the "member" role i believe | 17:09 |
| neiljerram | Is there a "default" role? I think "admin" would be more than I should need here. | 17:09 |
| neiljerram | OK, cool, so I should be able to find some default non-admin role. Let's see... | 17:10 |
| neiljerram | Actually this will take me a little while, as my Queens rig is now torn down. I'll report back here a bit later! | 17:11 |
| lbragstad | neiljerram: sounds good - keep in mind that some of this stuff is undergoing a lot of changes | 17:11 |
| lbragstad | we're reworking a lot of the policy/rbac stuff across services, especially in keystone | 17:11 |
| lbragstad | to improve the usability of it | 17:11 |
| *** RickDeckard has joined #openstack | 17:12 | |
| lbragstad | http://specs.openstack.org/openstack/keystone-specs/specs/keystone/ongoing/policy-security-roadmap.html provides a 10,000 ft view if you're interested in the context or backstory | 17:12 |
| neiljerram | Sounds good. I'll take a look. TBH it's pretty hard to get into as a v3 newbie, right now. | 17:12 |
| lbragstad | let me know if i can help clarify things, or just swing by #openstack-keystone | 17:13 |
| lbragstad | there are a bunch of people there that can help | 17:13 |
| *** forgotmynick has quit IRC | 17:13 | |
| neiljerram | will do, thanks! | 17:13 |
| *** AhmadMahmoudi has joined #openstack | 17:13 | |
| lbragstad | np | 17:13 |
| *** AhmadMahmoudi has quit IRC | 17:14 | |
| *** AhmadMahmoudi has joined #openstack | 17:14 | |
| *** gnufied__ has quit IRC | 17:24 | |
| *** mdih has quit IRC | 17:29 | |
| *** RickDeckard has quit IRC | 17:33 | |
| *** RickDeckard has joined #openstack | 17:33 | |
| *** ChrisNBlum is now known as ChrisNBlum_away | 17:38 | |
| *** gnufied__ has joined #openstack | 17:39 | |
| *** Bhujay has quit IRC | 17:39 | |
| *** lihi has quit IRC | 17:44 | |
| *** lihi has joined #openstack | 17:45 | |
| *** rmart04 has joined #openstack | 17:47 | |
| *** gyee has joined #openstack | 17:47 | |
| *** rmart04 has quit IRC | 17:50 | |
| *** rmart04 has joined #openstack | 17:51 | |
| *** poopcat has joined #openstack | 17:58 | |
| *** SumitNaiksatam has joined #openstack | 18:00 | |
| *** georgem1 has joined #openstack | 18:01 | |
| *** RickDeckard has quit IRC | 18:03 | |
| *** RickDeckard has joined #openstack | 18:04 | |
| *** forgotmynick has joined #openstack | 18:05 | |
| *** skazi has quit IRC | 18:26 | |
| *** electrofelix has quit IRC | 18:31 | |
| *** cloudrancher has joined #openstack | 18:34 | |
| *** cah_link has quit IRC | 18:35 | |
| *** eldritch has quit IRC | 18:40 | |
| *** linuxdaemon has quit IRC | 18:44 | |
| *** linuxdaemon has joined #openstack | 18:52 | |
| *** morazi_ has quit IRC | 18:52 | |
| *** morazi has joined #openstack | 18:54 | |
| *** rmart04 has quit IRC | 19:02 | |
| *** RickDeckard has quit IRC | 19:03 | |
| *** schmots has quit IRC | 19:04 | |
| *** schmots_ has joined #openstack | 19:04 | |
| *** RickDeckard has joined #openstack | 19:07 | |
| *** eldritch has joined #openstack | 19:11 | |
| *** skazi has joined #openstack | 19:12 | |
| *** th3g1z has quit IRC | 19:19 | |
| *** mikemcowie has joined #openstack | 19:22 | |
| *** SumitNaiksatam has left #openstack | 19:25 | |
| *** ptx0 has quit IRC | 19:33 | |
| *** pcaruana has quit IRC | 19:33 | |
| *** mikemcowie has quit IRC | 19:35 | |
| *** mikemcowie has joined #openstack | 19:36 | |
| *** ymasson has joined #openstack | 19:42 | |
| *** aojea has joined #openstack | 19:47 | |
| *** Son_Goku has quit IRC | 19:56 | |
| *** schmots_ has quit IRC | 19:57 | |
| *** RickDeckard has quit IRC | 20:01 | |
| *** RickDeckard has joined #openstack | 20:01 | |
| *** mikemcowie has quit IRC | 20:05 | |
| *** muo has quit IRC | 20:07 | |
| *** mamercad has quit IRC | 20:08 | |
| *** muo has joined #openstack | 20:09 | |
| *** nicolasbock has quit IRC | 20:11 | |
| *** ptx0_ has joined #openstack | 20:15 | |
| *** cloudrancher has quit IRC | 20:18 | |
| *** ptx0_ is now known as ptx0 | 20:20 | |
| *** mikecmpbll has joined #openstack | 20:22 | |
| *** schmots has joined #openstack | 20:24 | |
| *** georgem1 has quit IRC | 20:38 | |
| *** guhcampos has quit IRC | 20:40 | |
| *** yamahata_ has joined #openstack | 20:47 | |
| *** lbragstad has quit IRC | 20:51 | |
| *** yamahata_ is now known as yamahata__ | 21:04 | |
| *** RickDeckard has quit IRC | 21:04 | |
| *** yamahata__ is now known as yamahata | 21:05 | |
| *** RickDeckard has joined #openstack | 21:06 | |
| *** RickDeckard has quit IRC | 21:11 | |
| *** RickDeckard has joined #openstack | 21:12 | |
| *** dosaboy has joined #openstack | 21:14 | |
| *** yamahata has quit IRC | 21:17 | |
| *** rmart04 has joined #openstack | 21:18 | |
| *** yamahata has joined #openstack | 21:20 | |
| *** rmart04 has quit IRC | 21:20 | |
| *** schmots has quit IRC | 21:22 | |
| *** isq has joined #openstack | 21:22 | |
| *** slaweq has quit IRC | 21:26 | |
| *** rmart04 has joined #openstack | 21:30 | |
| *** luizbag has quit IRC | 21:33 | |
| *** rmart04 has quit IRC | 21:34 | |
| *** iyamahat has joined #openstack | 21:35 | |
| *** iyamahat has quit IRC | 21:36 | |
| *** iyamahat has joined #openstack | 21:37 | |
| *** iyamahat has quit IRC | 21:41 | |
| *** iyamahat has joined #openstack | 21:42 | |
| *** isq_ has joined #openstack | 21:47 | |
| *** isq has quit IRC | 21:48 | |
| *** lbragstad has joined #openstack | 21:55 | |
| *** RickDeckard has quit IRC | 21:56 | |
| *** RickDeckard has joined #openstack | 21:57 | |
| *** mchlumsky has quit IRC | 21:58 | |
| *** RickDeckard has quit IRC | 22:02 | |
| *** neiljerram has quit IRC | 22:08 | |
| *** rcernin has joined #openstack | 22:09 | |
| *** slaweq has joined #openstack | 22:11 | |
| *** imacdonn has quit IRC | 22:12 | |
| *** imacdonn has joined #openstack | 22:12 | |
| *** tobasco is now known as tobias-urdin | 22:14 | |
| *** slaweq has quit IRC | 22:15 | |
| *** Son_Goku has joined #openstack | 22:33 | |
| *** forgotmynick has quit IRC | 22:34 | |
| *** skazi has quit IRC | 22:44 | |
| *** aojea has quit IRC | 22:46 | |
| *** boazel has quit IRC | 22:48 | |
| *** Son_Goku has quit IRC | 23:05 | |
| *** gyee has quit IRC | 23:06 | |
| *** tpsilva has quit IRC | 23:10 | |
| *** slaweq has joined #openstack | 23:11 | |
| *** gildub has joined #openstack | 23:11 | |
| *** Son_Goku has joined #openstack | 23:15 | |
| *** slaweq has quit IRC | 23:16 | |
| *** AhmadMahmoudi has quit IRC | 23:19 | |
| *** Son_Goku has quit IRC | 23:25 | |
| *** RickDeckard has joined #openstack | 23:31 | |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!