Tuesday, 2021-08-31

*** queria is now known as Guest586202:25
*** queria is now known as Guest586302:31
*** rlandy is now known as rlandy|rover11:38
*** queria is now known as queria^afk15:20
mlozahello, I'm having a keystone issue, I gave a user reader role at domain level, the user can list all projects but unable to list all instances19:22
fricklermloza: are you trying to use the --all-projects option? or listing instances for a specific project is failing? anyway this rather sounds like an issue with nova policies than with keystone19:44
mlozafrickler: Both. Both throws 'Policy doesn't allow os_compute_api:servers:detail:get_all_tenants 19:51
mlozahowever, in horizon, I can switch projects and see the instances19:52
mlozaI given a user reader role at system level, same issue and also weird that i cannot list all projects19:55
fricklerget_all_tenants likely is an admin-only operation19:55
fricklerbut you shouldn't be using that when looking at instances for a specific project19:56
fricklerare you using OSC or some other client?19:57
mlozaOSC19:58
mlozaos_compute_api:servers:detail:get_all_tenants19:59
mlozaDefault19:59
mlozarule:system_reader_api19:59
mlozahttps://docs.openstack.org/nova/latest/configuration/policy.html19:59
mlozahttps://paste.opendev.org/show/b7jGPa7irPRR7W3OGRfy/20:02
fricklerhmm, indeed, that would be a bug in nova, then. I can try to reproduce tomorrow if noone else comes along, eod now20:03
mlozaok, thanks20:34
*** rlandy|rover is now known as rlandy|rover|bbl22:16
*** sshnaidm is now known as sshnaidm|afk23:34

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!