Wednesday, 2018-12-12

rm_workoh no, i'm off the courtesy-ping list!08:38
rm_workalso, your meeting is too early T_T so early T_T08:38
Luzirm_work, i think redrobot wanted to create an etherpad for the agenda, maybe he can add the courtesy-oing list there, so people can add themself again?08:42
rm_workit's fine, I just want to mess with redrobot :P18:09
redrobotohai rm_work !18:09
rm_workredrobot: your meetings are too early18:11
redrobotrm_work, you West Coast again?18:19
rm_workpresently sunnyvale18:19
redrobotrm_work, nice!  ... yeah, maybe we can change the meeting time.  As it is only Luzi and I show up regularly18:20
rm_workI mean that said, I probably don't have a whole lot to add ATM18:20
rm_workoctavia cleaned up its barbican story a lot18:20
rm_workwe just store a single pkcs12 file as one secret now <_<18:20
rm_workand auto-create ACLs18:22
FrankZhangrm_work: recently I'm doing some experiment on enabling TLS lb on Octavia with Barbican in openstack ansible setup. While barbican has strict policy that won't allow Octavia has access to the PKCS12 secret. Does this happen on your side?21:13
rm_workwhich release?21:16
rm_workhopefully rocky?21:16
rm_workFrankZhang: wait are you at RAX21:17
rm_workif so, queens may have some issue? johnsom is looking at it <_<21:17
FrankZhangyeah I'm, I was testing queens, rocky should be quite similar21:17
rm_worki'm aware of your problem :P21:18
FrankZhangrm_work: I'm working with johnsom21:18
rm_workrocky has different patches21:18
rm_workwith regard to barbican ACL work, I *think*21:18
rm_workbut yeah, i'd just wait for michael's research21:18
FrankZhangrm_work: osa barbican has one flaw which public endpoint won't allow admin GET secret normally but have to give '--insecure' flag21:19
FrankZhangI'm guessing the weird cert requirement causing other service has trouble communicating to barbican21:20
rm_workyeah, so I fixed the barbican-client issue with using alternative endpoints a few months ago21:21
rm_workit should be released now21:21
rm_workso you should be able to use the internal/admin endpoint21:21
FrankZhangrm_work: yeah, thanks for the patching, it got merged to queens weeks ago. The href of secret is still marked as public endpoint, though I don't think it matters.21:23
rm_workright, the client will now respect the setting of the current config21:23
rm_workreplacing the endpoint in the stored secret21:23
rm_workso you shouldn't have to deal with --insecure or the cert issue at all21:23
FrankZhangOpenstack Ansible stable queens didn't have your barbican client patch, so I was working on finding the way to get OSA barbican client up-to-date21:24
rm_workyou can ping xgerman for OSA issues, right? :P21:25
FrankZhangcool, I believed he knew the issue already. Since folks in RAX all didn't have successful instance to implement TLS octavia lb with barbican, johnsom mentioned you have some experience. Like to hear any tip of conifg you did.21:29
johnsomThe --insecure issue is an OSA deployment issue. Somehow that barbican public endpoint is using the wrong cert. But that is an openstack-ansible channel question/bug IMO.21:32
johnsomThe other endpoints don't need the --insecure even though they are also HTTPS, so I think something just isn't getting setup right.21:33
johnsomThe RBAC issue with the 403's, that one is going to take some time to figure out. I threw every role at the account I could think of, but I still got 403, so just need to set it up local and dig.21:34
FrankZhangjohnsom: I can setup one queens vm without octavia and barbican. And you can do some experiment on it.21:36
