Thursday, 2015-10-15

*** wwwjfy has joined #openstack-keystone00:00
*** slberger1 has left #openstack-keystone00:00
*** doug-fish has quit IRC00:00
*** wwwjfy_ has quit IRC00:00
*** jbell8 has quit IRC00:05
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements  https://review.openstack.org/23382000:05
*** su_zhang has quit IRC00:05
*** jbell8 has joined #openstack-keystone00:07
*** jbell8 has quit IRC00:08
*** mylu has quit IRC00:12
*** mylu has joined #openstack-keystone00:13
*** mylu has quit IRC00:17
*** EinstCrazy has quit IRC00:18
*** shadower has quit IRC00:23
*** shadower has joined #openstack-keystone00:23
*** su_zhang has joined #openstack-keystone00:26
*** _cjones_ has quit IRC00:26
ayounggyee thanks.00:29
*** edmondsw has quit IRC00:29
*** _hrou_ has quit IRC00:31
*** mylu has joined #openstack-keystone00:32
*** roxanaghe has quit IRC00:38
dolphmlbragstad: https://github.com/dolph/fernet-spec/commit/2688de4d318bda3fcfa2a4808418a06948c9039a00:50
*** topol has joined #openstack-keystone00:53
*** ChanServ sets mode: +v topol00:53
*** browne has quit IRC00:58
*** EinstCra_ has joined #openstack-keystone01:01
*** su_zhang has quit IRC01:04
*** roxanaghe has joined #openstack-keystone01:10
*** hrou has joined #openstack-keystone01:14
*** jasonsb has quit IRC01:16
*** gildub has quit IRC01:17
openstackgerritJamie Lennox proposed openstack/keystoneauth: Return None from generic plugin if failure  https://review.openstack.org/23504801:20
*** mylu has quit IRC01:24
*** richm has quit IRC01:35
*** spandhe has quit IRC01:43
*** links has joined #openstack-keystone01:46
*** wwwjfy has quit IRC01:53
*** jbell8 has joined #openstack-keystone01:55
*** csoukup has joined #openstack-keystone01:56
*** gildub has joined #openstack-keystone01:56
*** lhcheng has quit IRC01:58
*** mylu has joined #openstack-keystone02:00
*** roxanaghe has quit IRC02:02
*** atiwari1 has quit IRC02:05
*** r-daneel has quit IRC02:08
*** boris-42 has quit IRC02:08
*** yunpengli has joined #openstack-keystone02:09
*** yunpengli has quit IRC02:09
*** davechen has joined #openstack-keystone02:09
*** lhcheng has joined #openstack-keystone02:10
*** ChanServ sets mode: +v lhcheng02:10
*** stevemar_jays is now known as stevemar_02:15
stevemar_jamielennox: is anything using ksa yet? aside from occ and thus osc?02:17
jamielennoxstevemar_: shade via occ, but otherwise no, i've told everyone to wait until this cycle02:17
jamielennoxstevemar_: i'm finding these bugs as a result of trying to make auth_token use it02:18
stevemar_jamielennox: do we have a gate job in place? a dsvm-full job?02:18
jamielennoxstevemar_: sure - just nothing is using it yet02:18
jamielennoxstevemar_: well osc02:18
stevemar_jamielennox: yeah, osc02:18
stevemar_which the gate uses02:19
jamielennoxright02:19
stevemar_i just don't want to break things :)02:19
stevemar_jamielennox: oh well we have gate-tempest-dsvm-neutron-src-keystoneauth02:19
jamielennoxstevemar_: i think these are pretty safe02:19
jamielennoxmost of them are downright bugs that it doesn't work as is02:19
stevemar_jamielennox: sounds good, i'll review them soon02:21
jamielennoxstevemar_: https://review.openstack.org/#/c/235048/ as well02:21
*** mylu has quit IRC02:25
*** mylu has joined #openstack-keystone02:26
*** mylu has quit IRC02:30
*** mylu has joined #openstack-keystone02:32
davechenjamielennox: seem like you can remove this "from keystoneauth1 import exceptions" from the patch?02:35
jamielennoxdavechen: ah, thanks02:35
openstackgerritJamie Lennox proposed openstack/keystoneauth: Return None from generic plugin if failure  https://review.openstack.org/23504802:36
jamielennoxnormally the syntax checker is pretty good at that stuff02:36
davechenyes, jenkins did a good job.02:37
jamielennoxdavechen: i have one that integrates into the IDE that runs pep8 on the file whenever i save02:38
jamielennoxso i get errors if i do something wrong, not sure what happened that time02:38
davechenwhich IDE you are using?02:40
davechenthis is good option for my as well.02:40
jamielennoxwell i'm using vim and either syntastic or python-mode02:41
jamielennoxi love it, but you've gotta be ok with vim02:41
davecheni love eclipse :)02:41
*** mylu has quit IRC02:42
jamielennoxyea, so i don't know, but i would be really surprised if there wasn't some way of integrating a pep8 checker that runs whenever you save02:42
*** mylu has joined #openstack-keystone02:42
davechenjamielennox: so, keystoneauth just strip something about authentication from KSM, right?02:43
jamielennoxdavechen: i don't follow02:43
davechenjamielennox: I meant what keystoneauth are doing is what we have did in KSM, something about authentication?02:45
*** mylu has quit IRC02:45
*** mylu has joined #openstack-keystone02:46
jamielennoxdavechen: so auth_token middleware has relied on keystoneclient for a while now to do authentication, keystoneauth has extracted a lot of that out of keystoneclient so i'm just trying to make sure we have everything we need in keystoneauth02:46
jamielennoxthere are some compatibility changes that most people wont notice unless you are really closely inspecting token data - and auth_token is02:46
davecheni see.02:47
davechenthx02:47
lhchengsince you guys are talking about KSM, got a question about the caching02:48
lhchengjamielennox: so if no memcache server is configured, the validated token will be stored in memory per process right?02:48
lhchengstored -> cache02:48
jamielennoxlhcheng: yea :(02:50
jamielennoxlhcheng: and there's no way to disable it02:51
jamielennoxit's the cause of a couple of bugs around revocations02:51
*** browne has joined #openstack-keystone02:52
lhchengwill it keep growing  or would the in-memory cache removed expired tokens at some point?02:52
jamielennoxumm, i think it does remove expired tokens02:53
jamielennoxotherwise it can be pretty unbound02:54
jamielennoxi had a review to kill it, but it's a change in behaviour - even if it's dumb behaviour - so it will just take a while02:54
jamielennoxprobably something i can revive now mitaka is open02:54
lhchengjamielennox: I just realized we haven't turned on memcache on KSM :( But we haven't heard any OOM issues though.02:55
lhchengso maybe it does clean up expired token :P02:55
lhchengjamielennox: review to kill the in-memory caching?02:55
jamielennoxlhcheng: yes02:56
lhchengah adding the option to disable it would be a good compromise02:56
lhchengkeep the old behavior as default02:56
*** wwwjfy has joined #openstack-keystone02:57
*** boris-42 has joined #openstack-keystone02:58
openstackgerritDave Chen proposed openstack/keystone: test_backend_sql work with python34  https://review.openstack.org/20535202:59
stevemar_dolphm: thanks for rechecking all the things02:59
*** roxanaghe has joined #openstack-keystone03:00
jamielennoxlhcheng: maybe, i think if it was me though i'd just like a great big warning saying i'm doing something stupid03:01
davechenstevemar_: thanks for your explaination on that patch - https://review.openstack.org/#/c/214775.03:04
openstackgerritMerged openstack/keystone: Fix the referred [app:app_v3] into [pipeline:api_v3]  https://review.openstack.org/22516003:05
davechenstevemar_: I am clear after your expalination and dolphm's review comments.03:05
*** mylu has quit IRC03:06
davechenstevemar_: i think i miss the points that extentsion still here but we just move  them into cores?03:06
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23501603:07
davechenstevemar_: just want to confirm with you after the abandon this wrong fixing - https://review.openstack.org/#/c/234685/03:07
stevemar_davechen: i think its safe to abandon03:10
*** gildub has quit IRC03:11
davechensure.03:11
*** gildub has joined #openstack-keystone03:11
lhchengjamielennox: yeah, that works too03:11
stevemar_davechen: is the autumn festival over? shouldn't you be off relaxing? :)03:14
davechenstevemar_: yes, it is a long holiday here.03:15
davechenstevemar_: one week combined with national day.03:15
davechenstevemar_: just stay in my home and watch so many cars jamed on the road. :)03:16
stevemar_davechen: hehe, sounds like a relaxing time if you don't go out03:17
*** dims_ has quit IRC03:18
*** lhcheng has quit IRC03:19
*** topol has quit IRC03:20
*** mylu has joined #openstack-keystone03:22
jamielennoxrequired plugin CONF arguments are a pain for auth_token middleware03:22
jamielennoxmulti levels of config files, paste specified config files, paste specified arguments03:23
*** darrenc is now known as darrenc_afk03:24
*** topol has joined #openstack-keystone03:31
*** ChanServ sets mode: +v topol03:31
*** lhcheng has joined #openstack-keystone03:32
*** ChanServ sets mode: +v lhcheng03:32
*** _cjones_ has joined #openstack-keystone03:33
*** topol has quit IRC03:36
*** su_zhang has joined #openstack-keystone03:39
*** mylu has quit IRC04:09
openstackgerritMerged openstack/keystone: Refactor: Don't hard code 409 Conflict error codes  https://review.openstack.org/23312804:11
*** mylu has joined #openstack-keystone04:11
stevemar_so happy to see things merging again \o/04:11
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23501604:12
openstackgerritMerged openstack/keystone: add initiator to v2 calls for additional auditing  https://review.openstack.org/23112304:13
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23501604:14
*** _cjones_ has quit IRC04:15
*** _cjones_ has joined #openstack-keystone04:15
openstackgerritMerged openstack/keystone: keystone-paste.ini docs for deployers are out of date  https://review.openstack.org/23489904:17
openstackgerritMerged openstack/keystone: Handle 16-char non-uuid user IDs in payload  https://review.openstack.org/22612104:18
openstackgerritMerged openstack/keystone: Updated from global requirements  https://review.openstack.org/23382004:18
*** dims has joined #openstack-keystone04:18
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23501604:19
*** urulama_ has quit IRC04:20
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23501604:20
*** urulama has joined #openstack-keystone04:21
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23501604:22
*** darrenc_afk is now known as darrenc04:24
*** dims has quit IRC04:24
*** stevema__ has joined #openstack-keystone04:33
*** ChanServ sets mode: +o stevema__04:33
*** stevemar_ has quit IRC04:33
*** spandhe has joined #openstack-keystone04:37
*** mflobo has joined #openstack-keystone04:37
lhchengstevema__: can I get your autograph for this? https://developer.ibm.com/opentech/wp-content/uploads/sites/43/2015/10/KeystoneBookCover2.jpg04:38
lhcheng:)04:38
stevema__lhcheng: of course :P04:38
lhchengsave us a copy! :)04:38
jamielennoxstevema__: oooo04:39
*** mylu has quit IRC04:39
*** hrou has quit IRC04:40
*** gsilvis has quit IRC04:43
stevema__jamielennox: all hail the giant salamander04:43
jamielennoxi wonder if i get all 3 autographs its worth anything on ebay04:45
stevema__jamielennox: it's sentimental value will be huge04:45
jamielennoxi mean i'd love to read it, i'm jsut wondering04:45
stevema__jamielennox: probably not :P04:46
jamielennoxit'll always be on my bedside table then04:49
lhchenglol04:49
openstackgerritEric Brown proposed openstack/keystone: Some small improvements on fernet uuid handling  https://review.openstack.org/23508204:50
*** jbell8 has quit IRC04:51
*** jbell8 has joined #openstack-keystone04:52
lhchengstevema__: quick question on federation mapping.. what if I want each of my federated user to have their own project, how would you set that up?04:56
lhchengis the possible? :)04:57
lhchengthe -> that04:57
stevema__lhcheng: hmmm05:03
stevema__thats going to be a lot of projects05:03
lhchengeach of our user have their own projects, so they can have their own quotas05:05
*** gsilvis has joined #openstack-keystone05:05
openstackgerritMerged openstack/keystoneauth: Fix deprecated options in oslo_config  https://review.openstack.org/23457805:08
lhchengjust thinking what it would take to move from sync user data to keystone, to using federation model05:08
jamielennoxi think that was one of chadwick's things about creating projects dynamically - there's no support for it in keystone you'd have to figure out some way to make them, make a group that gave you the roles on that project05:10
stevema__jamielennox: lhcheng yes, auto-provisioning is what he was saying05:11
stevema__new feature for M? enhance mapping to specify a 'create random project and assign the user a role of member in it'?05:11
jamielennoxyea, we would need to figure out some more enhancements, because there's no point going via groups there05:12
lhchengstevema__: I think there is an ask for auto-provisioning somewhere in ops05:12
stevema__lhcheng: unless you already have the all projects created...05:12
jamielennoxall sorts of issues like deleteing projects05:12
lhchengI have to dig around in the ops ML/etherpad05:13
lhchengjamielennox: yeah, if its 1:1 for user:projects, the group is just an overhead05:13
openstackgerritAlexey Troshkov proposed openstack/python-keystoneclient: Added property 'is domain' to create a project  https://review.openstack.org/23508505:14
stevema__jamielennox: btw, brant addressed your comment here: https://review.openstack.org/#/c/195873/05:15
stevema__lhcheng: ^ if you could look @ that too05:15
stevema__lhcheng: this one is SUPER easy https://review.openstack.org/#/c/233929/05:17
lhchengauto-provisioning was mentioned in here: https://etherpad.openstack.org/p/YVR-ops-federation05:20
lhchengidk if there's a follow-up though05:20
*** dims has joined #openstack-keystone05:21
lhchengstevema__: yay for removing unused code05:21
lhchengis our gate back to normal?05:22
stevema__lhcheng: it sure is05:23
*** dims has quit IRC05:26
jamielennoxcan i do depends-on multiple changes in the same project05:27
jamielennoxi want to WIP upload this keystonemiddleware change, depends-on 3 commits in keysotneauth that aren't dependant on each other05:28
jamielennoxwill it sensibly cherry-pick them all on top of each other or try repeatedly check out different branches05:28
bretonmorning, keystone05:28
jamielennoxguess i can just try it05:28
openstackgerritJamie Lennox proposed openstack/keystonemiddleware: Straighten up exceptions imports  https://review.openstack.org/23508905:32
openstackgerritJamie Lennox proposed openstack/keystonemiddleware: [WIP] Use keystoneauth  https://review.openstack.org/23509005:32
jamielennoxstevema__, lhcheng: the depends-on in https://review.openstack.org/#/c/235090/ is what i would like in for a ksa release05:34
jamielennoxoh, actually i don't need #3 but could be useful05:34
stevema__morning breton05:36
*** roxanaghe has quit IRC05:37
jamielennoxthe amount of code there under represents how long that took05:43
*** jbell8 has quit IRC05:44
lhchengjamielennox: sure, will look at the dependencies05:44
*** jbell8 has joined #openstack-keystone06:00
stevema__jamielennox: is the goal of switching to ksa in ksm to no longer use ksc?06:03
jamielennoxstevema__: no, ksc will always need to hang around for the calls to keystone, CMS validation etc06:04
jamielennoxfetching revocation lists06:05
*** mflobo has left #openstack-keystone06:06
stevema__jamielennox: ah okay06:06
*** Nirupama has joined #openstack-keystone06:06
stevema__jamielennox: that stinks, get it out of there :P06:06
jamielennoxstevema__: well a keystoneclient 2 will be a lot lighter06:07
*** lhcheng has quit IRC06:07
stevema__jamielennox: tru dat06:07
stevema__jamielennox: we need to make a game plan for that in tokyo06:07
stevema__i want it done in M :D06:07
jamielennoxstevema__: it's not that hard actually not that ksa is released06:07
jamielennoxi mean the switch over is hard, the code is easy06:07
stevema__jamielennox: i guess we need to get all the clients switched over to KSA?06:08
jamielennoxstevema__: yea, and the deprecations are going to suck06:08
jamielennoxstevema__: i was hoping to create a v2 branch, but apparently we need to get everything switched over to ksa, then create ksc2 in tree06:08
jamielennoxwhich is going to break the world06:08
stevema__if we switch the clients to ksa then why would ksc2 break the world?06:09
openstackgerritJamie Lennox proposed openstack/keystoneauth: Expose bind data via AccessInfo  https://review.openstack.org/23510706:09
jamielennoxbecause whilst we got part of the way switching clients to use session they still all have the old compat versions inline which rely directly on ksc06:10
jamielennoxso we will need to cut new major versions of all those that remove the old paths06:10
*** su_zhang has quit IRC06:11
stevema__jamielennox: oh you are referring to old versions of the clients06:14
openstackgerritJamie Lennox proposed openstack/keystonemiddleware: [WIP] Use keystoneauth  https://review.openstack.org/23509006:14
jamielennoxstevema__: i guess i just think there is no way we'll remove everyone's dependency on keystoneclient06:15
*** spandhe has quit IRC06:18
*** dims has joined #openstack-keystone06:22
openstackgerritJamie Lennox proposed openstack/keystoneauth: Expose bind data via AccessInfo  https://review.openstack.org/23510706:22
bretonwas the gate fixed?06:23
bretoncan we recheck now?06:23
jamielennoxi think so - i also saw they release requests 2.8.1 which should solve the problem as well06:24
*** lhcheng has joined #openstack-keystone06:25
*** ChanServ sets mode: +v lhcheng06:25
*** ParsectiX has joined #openstack-keystone06:26
*** dims has quit IRC06:27
*** kiran-r has joined #openstack-keystone06:30
stevema__breton: yes, the gate is all fixed now06:33
wwwjfyHi, I have a question about contrib/ec2. get_credentials method asks for all credentials of a user and tries to convert each to ec2 style. Is it by design? I think a type="ec2" filter should be applied06:35
wwwjfyCredentials of other types are also there, so this may return empty/useless entries06:38
*** jamielennox is now known as jamielennox|away06:39
*** tyagiprince2010 has joined #openstack-keystone06:59
tyagiprince2010Hey I need help to change default database in keystone.06:59
tyagiprince2010It is using sqlite i guess. I need to use sql for the same.07:00
tyagiprince2010Please help07:00
tyagiprince2010I deployed keystone from keystone source from github.07:00
stevema__tyagiprince2010: install mysql, change keystone.conf to point to mysql and run keystone-manage db_sync again... what's tripping you up?07:01
tyagiprince2010Okay thanks for replying. The thing is I changed some things in connection string in my keystone.conf07:03
tyagiprince2010connection = mysql://user:prince@localhost/keystone07:03
tyagiprince2010and then i run the keystone-manage db_sync07:04
tyagiprince2010It made a file in my dir keystone.db07:04
tyagiprince2010I guess it is still using sqlite07:04
stevema__tyagiprince2010: check when the file was last modified07:05
stevema__check your mysql settings to see where a new db is created, i think it's under /var by default07:05
stevema__if your connection says mysql, then it should be using that, not sqlite07:06
tyagiprince2010The file is just modified.07:06
tyagiprince2010It says 1 min before07:07
openstackgerritMerged openstack/keystoneauth: Return None from generic plugin if failure  https://review.openstack.org/23504807:07
openstackgerritMerged openstack/keystoneauth: Copy AccessInfo tests from keystoneclient  https://review.openstack.org/23461107:07
tyagiprince2010https://titanpad.com/thn7osiE8S07:07
tyagiprince2010I pasted my code here on titanpad. Please take a look if its fine.07:07
tyagiprince2010do I need to define another tag [sql] here07:09
*** belmoreira has joined #openstack-keystone07:10
stevema__looks fine to me, it's following the convention of sqlalchemy http://docs.sqlalchemy.org/en/rel_0_9/core/engines.html#mysql07:10
stevema__did you restart the keystone service?07:10
openstackgerritMerged openstack/keystone: add placeholder migrations for liberty  https://review.openstack.org/23394307:12
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23501607:13
openstackgerritSteve Martinelli proposed openstack/keystone: Move oauth1 sql migrations to common  https://review.openstack.org/23512107:13
*** browne has quit IRC07:15
*** browne has joined #openstack-keystone07:18
tyagiprince2010It is not getting started now. I changed the admin_token to ADMIN_TOKEN. Does that make any difference07:18
tyagiprince2010It was running in a terminal. I stopped it using ctrl+c and then started keystone-all again07:19
tyagiprince2010but it is not starting again07:19
tyagiprince2010@stevema__07:19
stevema__tyagiprince2010: that's probably why it's not using mysql, what do the logs say about why it can't be started again?07:22
openstackgerritSteve Martinelli proposed openstack/keystone: Move endpoint_policy migrations into keystone core  https://review.openstack.org/17191607:23
openstackgerritSteve Martinelli proposed openstack/keystone: Move federation extension into keystone core  https://review.openstack.org/21477507:23
*** browne has quit IRC07:23
openstackgerritAlexey Troshkov proposed openstack/python-keystoneclient: Added unit test to create project with is_domain property  https://review.openstack.org/23512707:23
openstackgerritSteve Martinelli proposed openstack/keystone: Move federation sql migrations to common  https://review.openstack.org/23453707:23
breton2015-10-15 06:37:23.732 | Bad md5 hash for package http://pypi.region-b.geo-1.openstack.org/packages/source/p/pysaml2/pysaml2-3.0.0.tar.gz#md5=cde880e3d3ae8c2587afbf02e1961624 (from http://pypi.region-b.geo-1.openstack.org/simple/pysaml2/)07:25
tyagiprince2010@stevama__ Yes it started07:26
tyagiprince2010But still is using sqlite instead of mysql07:26
openstackgerritMerged openstack/keystone: Remove bas64utils and tests  https://review.openstack.org/23392907:27
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23501607:28
openstackgerritSteve Martinelli proposed openstack/keystone: Move oauth1 extension into core  https://review.openstack.org/23459807:29
openstackgerritSteve Martinelli proposed openstack/keystone: Move oauth1 sql migrations to common  https://review.openstack.org/23512107:30
stevema__tyagiprince2010: i'm heading out now, it's 0330 local time, try posting to the mailing list or googling, sounds like a configuration issue07:32
tyagiprince2010Thanks07:32
*** stevema__ has quit IRC07:32
*** stevemar_ has joined #openstack-keystone07:33
tyagiprince2010Hey, I want to know the configuration of keystone.conf to setup mysql database instead of sqlite07:33
*** ChanServ sets mode: +o stevemar_07:33
*** stevemar_ has quit IRC07:35
*** pnavarro has joined #openstack-keystone07:37
*** browne has joined #openstack-keystone07:39
openstackgerritAlexey Troshkov proposed openstack/python-keystoneclient: Added unit test to create project with is_domain property  https://review.openstack.org/23508507:42
wwwjfytyagiprince2010: what happened to me was that keystone wasn't using the keystone.conf I expect it to. You may try to add "--config-file /path/to/keystone.conf" to keystone-manage to see if it works07:43
tyagiprince2010It gives an error saying no module named mysqldb on running keystone-manage db_sync.07:46
tyagiprince2010does the keystone service needs to be running while giving this command07:47
wwwjfytyagiprince2010: no. It means you need to install python package07:47
tyagiprince2010python is already there. Its running on wsgi server.07:47
wwwjfytyagiprince2010: I mean a python package. try "pip install MySQL-python"07:49
*** tyagiprince2010 has quit IRC07:52
*** davechen has quit IRC07:53
*** wwwjfy has quit IRC07:54
*** wwwjfy has joined #openstack-keystone07:54
*** davechen has joined #openstack-keystone07:54
*** josecastroleon has joined #openstack-keystone07:55
*** topol has joined #openstack-keystone07:56
*** ChanServ sets mode: +v topol07:56
*** fhubik has joined #openstack-keystone07:56
*** fhubik is now known as fhubik_brb07:56
*** jaosorior has joined #openstack-keystone07:57
*** topol has quit IRC08:00
*** fhubik_brb is now known as fhubik08:02
*** browne has quit IRC08:08
*** marzif has joined #openstack-keystone08:12
*** marzif has quit IRC08:19
*** marzif has joined #openstack-keystone08:20
*** _cjones_ has quit IRC08:20
*** dims has joined #openstack-keystone08:25
*** jistr has joined #openstack-keystone08:30
*** dims has quit IRC08:30
*** uiyice has quit IRC08:33
*** aix has joined #openstack-keystone08:35
*** EinstCra_ has quit IRC08:36
*** EinstCrazy has joined #openstack-keystone08:37
*** tyagiprince2010 has joined #openstack-keystone08:44
tyagiprince2010Hey I want the configuration for setting up keystone with mysql database08:44
tyagiprince2010when I am running the command keystone-manage db_sync, It gives an error msg saying No module for mysqlbd08:45
tyagiprince2010mysqldb*08:45
*** lhcheng has quit IRC08:46
*** jaosorior has quit IRC08:48
wwwjfytyagiprince2010: pip install MySQL-python doesn't work?08:52
tyagiprince2010Now when I am running keystone-manage db_sync, It runs and creates a keystone.db file here in the directory.08:56
tyagiprince2010I guess It is using sqlite08:56
wwwjfythen it shouldn't report the mysqldb error.08:56
*** kiranr has joined #openstack-keystone08:57
wwwjfydo you mean after you installed mysqldb, it uses sqlite?08:57
wwwjfyit doesn't make sense08:57
*** kiran-r has quit IRC08:57
wwwjfydid you run the same command as the one reporting mysqldb error08:58
*** exploreshaifali has joined #openstack-keystone08:59
tyagiprince2010also when I run the command keystone endpoint-list, It shows an error msg. The msg is here : https://tyagiprince.titanpad.com/109:01
wwwjfytyagiprince2010: the keystone client error doesn't tell much, you'd better check keystone server output09:03
*** marzif_ has joined #openstack-keystone09:04
*** marzif has quit IRC09:04
tyagiprince2010keystone server says No module name mysqldb09:11
tyagiprince2010wwwjfy09:13
tyagiprince2010:09:13
wwwjfytyagiprince2010: have you run "pip install MySQL-python"09:14
tyagiprince2010this gives an error on running09:14
wwwjfywhat's the error?09:15
tyagiprince2010https://tyagiprince.titanpad.com/109:15
tyagiprince2010wwwjfy : look here at the link09:15
wwwjfytyagiprince2010: are you running Ubuntu? if yes, install it by "sudo apt-get install libmysqlclient-dev"09:17
tyagiprince2010wwwjfy : Yes, okay i installed it. but still the server is giving the same error. I restarted the server already.09:19
wwwjfytyagiprince2010: you installed MySQL-python?09:19
tyagiprince2010I am using ubuntu. so i ran your apt-get command.09:20
tyagiprince2010wwwjfy :09:20
wwwjfytyagiprince2010: keystone depends on python package MySQL-python, which depends on ubuntu package libmysqlclient-dev, so you need to run the apt-get, and then run "pip install MySQL-python"09:21
tyagiprince2010wwwjfy : okay, i ran both the commands. it is giving some password mismatch error. I guess that problem is resolved. I will try resolving this one and get back to you09:22
wwwjfyok09:23
*** wwwjfy has quit IRC09:25
*** wwwjfy has joined #openstack-keystone09:26
*** e0ne has joined #openstack-keystone09:26
tyagiprince2010wwwjfy : it is giving a different error.09:27
*** gildub has quit IRC09:27
*** dims has joined #openstack-keystone09:27
tyagiprince2010here is the error09:27
tyagiprince20102015-10-15 14:55:10.921 18750 ERROR keystone.common.wsgi ProgrammingError: (_mysql_exceptions.ProgrammingError) (1146, "Table 'keystone.token' doesn't exist") [SQL: u'SELECT token.id AS token_id, token.expires AS token_expires, token.extra AS token_extra, token.valid AS token_valid, token.user_id AS token_user_id, token.trust_id AS token_trust_id \nFROM token \nWHERE token.id = %s'] [parameters: ('02f45c41648bca29309:27
wwwjfytyagiprince2010: you need run the db_sync command09:27
tyagiprince2010i already did. It makes a file keystone.db in the directory but does not populate the mysql's keystone database09:31
tyagiprince2010wwwjfy : so i guess it is still using sqlite09:31
wwwjfytyagiprince2010: so keystone server is using mysql, but db_sync runs on a sqlite db...09:32
*** dims has quit IRC09:32
tyagiprince2010wwwjfy : yeah that might be the case. Is there some configuration that i need to do to change that09:33
wwwjfytyagiprince2010: try keystone-manage --config-file <the path of keystone.conf with mysql configured> db_sync09:33
wwwjfyI guess keystone-manage is using another keystone.conf09:34
tyagiprince2010wwwjfy : yes it populated the db.09:35
tyagiprince2010thanks wwwjfy09:35
wwwjfyglad I helped :)09:35
tyagiprince2010wwwjfy : One more query. when i run any command like keystone user-list, It says wrong credentials. I guess the file that I am sourcing is invalid.09:39
tyagiprince2010and i want to use pkiz for the authentication purpose. so need help to configure that as well.09:40
*** aix has quit IRC09:43
wwwjfytyagiprince2010: I guess your username/password were wrong. I'm not familiar with pkiz, so I'm sorry I cannot help.09:46
wwwjfyfor all the environment problem, you may want to try devstack, which will give you a usable openstack env09:46
*** links has quit IRC09:47
tyagiprince2010i have tried devstack. After that i moved to 3 node setup which i am configuring now. Hoping that it will work fine here on 3 node architecture.09:47
*** exploreshaifali has quit IRC09:48
tyagiprince2010wwwjfy : can't i just install keystone from github and without installing any other service like glance etc, can i check if my keystone is working fine.09:48
openstackgerritBoris Bobrov proposed openstack/keystone: Fix exposition of bug about limiting with ldap  https://review.openstack.org/23422609:49
openstackgerritBoris Bobrov proposed openstack/keystone: Use search_ext_s instead of search_s in ldap  https://review.openstack.org/23299509:49
openstackgerritBoris Bobrov proposed openstack/keystone: Enable limiting in ldap for groups  https://review.openstack.org/23484909:49
openstackgerritBoris Bobrov proposed openstack/keystone: Make @truncated common for all backends  https://review.openstack.org/23306909:49
openstackgerritBoris Bobrov proposed openstack/keystone: Use @truncated in ldap for users  https://review.openstack.org/23307009:49
*** exploreshaifali has joined #openstack-keystone09:50
*** dims has joined #openstack-keystone09:51
*** davechen has left #openstack-keystone09:53
wwwjfytyagiprince2010: sure, it's fine. I thought you just began to use it. :)09:55
wwwjfytyagiprince2010: if you lost admin password, you may use admin_token to do any operation09:56
*** tyagiprince2010 has quit IRC09:57
*** aix has joined #openstack-keystone09:58
*** EinstCrazy has quit IRC10:01
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Merge tag '8.0.0'  https://review.openstack.org/23521510:05
*** aix has quit IRC10:26
*** wwwjfy has quit IRC10:27
*** stevemar_ has joined #openstack-keystone10:34
*** ChanServ sets mode: +o stevemar_10:34
*** aix has joined #openstack-keystone10:37
*** stevemar_ has quit IRC10:38
*** pnavarro is now known as pnavarro|lunch10:45
*** weihan has joined #openstack-keystone10:51
*** kiranr has quit IRC10:59
*** jaosorior has joined #openstack-keystone10:59
*** EinstCrazy has joined #openstack-keystone11:00
*** petertr7_away has quit IRC11:03
*** petertr7_away has joined #openstack-keystone11:06
*** petertr7_away is now known as petertr711:06
*** fhubik is now known as fhubik_brb11:08
*** fhubik_brb is now known as fhubik11:09
*** fhubik is now known as fhubik_brb11:10
*** tyagiprince2010 has joined #openstack-keystone11:12
tyagiprince2010hey i installed keystone on controller node and did some configuration changes.11:12
tyagiprince2010got an error msg. ImportError: No module named persistence.backends.sql11:13
*** jaosorior has quit IRC11:14
tyagiprince2010removing driver from token did solve the issue. but then will keystone be using mysql?11:15
*** davechen has joined #openstack-keystone11:26
*** akscram has quit IRC11:38
*** akscram has joined #openstack-keystone11:38
*** wwwjfy has joined #openstack-keystone11:39
*** su_zhang has joined #openstack-keystone11:45
openstackgerritAlexander Makarov proposed openstack/keystone: Unified delegation model  https://review.openstack.org/20848811:47
openstackgerritAlexander Makarov proposed openstack/keystone: Unified delegation driver  https://review.openstack.org/20960011:47
openstackgerritAlexander Makarov proposed openstack/keystone: Unified delegation model  https://review.openstack.org/20848811:52
openstackgerritAlexander Makarov proposed openstack/keystone: Unified delegation driver  https://review.openstack.org/20960011:52
*** weihan_ has joined #openstack-keystone11:55
*** weihan has quit IRC11:56
*** marzif_ has quit IRC11:57
*** amakarov_away is now known as amakarov11:58
*** marzif_ has joined #openstack-keystone11:58
*** e0ne has quit IRC12:06
*** markvoelker has joined #openstack-keystone12:08
tyagiprince2010hey i installed glance and keystone. Now when i run a command glance image-list, it says wrong credentials.12:08
*** pnavarro|lunch is now known as pnavarro12:09
*** thiagop has joined #openstack-keystone12:13
*** bradjones has joined #openstack-keystone12:16
*** bradjones has quit IRC12:16
*** bradjones has joined #openstack-keystone12:16
*** fhubik_brb is now known as fhubik12:18
*** doug-fis_ has quit IRC12:18
*** doug-fish has joined #openstack-keystone12:18
*** raildo-afk is now known as raildo12:21
*** su_zhang has quit IRC12:25
*** marzif_ has quit IRC12:28
*** marzif_ has joined #openstack-keystone12:28
*** Nirupama has quit IRC12:31
*** tyagiprince2010 has quit IRC12:35
*** stevemar_ has joined #openstack-keystone12:35
*** ChanServ sets mode: +o stevemar_12:35
*** aix has quit IRC12:37
*** aix has joined #openstack-keystone12:37
*** stevemar_ has quit IRC12:38
openstackgerritBoris Bobrov proposed openstack/keystone: Fix exposition of bug about limiting with ldap  https://review.openstack.org/23422612:42
openstackgerritBoris Bobrov proposed openstack/keystone: Use search_ext_s instead of search_s in ldap  https://review.openstack.org/23299512:42
openstackgerritBoris Bobrov proposed openstack/keystone: Enable limiting in ldap for groups  https://review.openstack.org/23484912:42
openstackgerritBoris Bobrov proposed openstack/keystone: Make @truncated common for all backends  https://review.openstack.org/23306912:42
openstackgerritBoris Bobrov proposed openstack/keystone: Use @truncated in ldap for users  https://review.openstack.org/23307012:42
*** afazekas has quit IRC12:43
*** jaosorior has joined #openstack-keystone12:49
*** afazekas has joined #openstack-keystone12:52
*** richm has joined #openstack-keystone12:57
*** su_zhang has joined #openstack-keystone12:58
*** marzif_ has quit IRC13:02
*** marzif_ has joined #openstack-keystone13:03
*** jaosorior has quit IRC13:08
*** marzif_ has quit IRC13:08
*** gordc has joined #openstack-keystone13:10
*** ayoung has quit IRC13:15
*** Ephur has joined #openstack-keystone13:19
*** su_zhang has quit IRC13:19
*** Ephur_ has joined #openstack-keystone13:19
*** Ephur has quit IRC13:23
*** weihan_ has quit IRC13:23
openstackgerritTony Wang proposed openstack/keystone: add `type' filter for list_credentials_for_user  https://review.openstack.org/23521413:24
*** su_zhang has joined #openstack-keystone13:26
*** hrou has joined #openstack-keystone13:29
*** jsavak has joined #openstack-keystone13:34
*** davechen has left #openstack-keystone13:39
*** csoukup has quit IRC13:45
*** jaosorior has joined #openstack-keystone13:50
*** jaosorior has quit IRC13:51
*** fhubik is now known as fhubik_brb13:51
*** ParsectiX has quit IRC13:53
*** sigmavirus24_awa is now known as sigmavirus2413:58
*** phalmos has joined #openstack-keystone14:00
*** fhubik_brb is now known as fhubik14:00
*** su_zhang has quit IRC14:02
*** hrou has quit IRC14:03
*** jaosorior has joined #openstack-keystone14:05
*** r-daneel has joined #openstack-keystone14:10
*** jaosorior has quit IRC14:10
*** stevemar_ has joined #openstack-keystone14:10
*** ChanServ sets mode: +o stevemar_14:10
*** topol has joined #openstack-keystone14:13
*** ChanServ sets mode: +v topol14:13
*** pumaranikar has joined #openstack-keystone14:16
*** ayoung has joined #openstack-keystone14:18
*** ChanServ sets mode: +v ayoung14:18
*** ankurgupta has joined #openstack-keystone14:19
*** jaosorior has joined #openstack-keystone14:19
*** exploreshaifali has quit IRC14:20
*** phalmos has quit IRC14:23
*** rdo has joined #openstack-keystone14:31
*** jbell8 has quit IRC14:32
*** jaosorior has quit IRC14:32
*** pnavarro is now known as pnavarro|off14:33
*** slberger has joined #openstack-keystone14:35
*** dims has quit IRC14:41
*** su_zhang has joined #openstack-keystone14:42
*** dims has joined #openstack-keystone14:42
*** pumaranikar has quit IRC14:42
*** pumaranikar has joined #openstack-keystone14:43
openstackgerritMerged openstack/keystone: Updating sample configuration file  https://review.openstack.org/23501614:43
*** jacorob has quit IRC14:44
*** Guest68187 has quit IRC14:44
*** lbragstad has quit IRC14:44
*** blewis has joined #openstack-keystone14:45
*** blewis is now known as Guest7254914:45
*** dims_ has joined #openstack-keystone14:45
*** jacorob has joined #openstack-keystone14:45
*** lbragstad has joined #openstack-keystone14:46
*** diazjf has joined #openstack-keystone14:46
*** Guest72549 has quit IRC14:48
*** jacorob has quit IRC14:48
*** lbragstad has quit IRC14:48
*** dims has quit IRC14:48
*** petertr7 is now known as petertr7_away14:48
*** dikonoor has joined #openstack-keystone14:49
*** csoukup has joined #openstack-keystone14:50
*** petertr7_away is now known as petertr714:51
*** roxanaghe has joined #openstack-keystone14:51
diazjfhello everyone, does anyone know if keystoneclient.auth.identity.v3.Token authenticates against a V2 endpoint?14:52
*** jacorob has joined #openstack-keystone14:52
*** lbragstad has joined #openstack-keystone14:53
*** jacorob has quit IRC14:54
*** lbragstad has quit IRC14:54
*** jacorob has joined #openstack-keystone14:55
*** lbragstad has joined #openstack-keystone14:56
*** nate_gone is now known as njohnston14:57
*** wwwjfy has quit IRC14:58
bknudson#success keystone liberty release notes look good.14:59
openstackstatusbknudson: Added success to Success page14:59
*** wwwjfy has joined #openstack-keystone15:00
*** jvarlamova_ has joined #openstack-keystone15:02
*** aix has quit IRC15:02
*** jsavak has quit IRC15:04
*** edmondsw has joined #openstack-keystone15:04
lbragstadsamueldmq have i addressed your comment here - https://review.openstack.org/#/c/215715/ ?15:05
*** geoffarnold has joined #openstack-keystone15:06
*** agupt9_ has joined #openstack-keystone15:06
*** agupt9_ has quit IRC15:07
*** geoffarn_ has joined #openstack-keystone15:07
openstackgerritSteve Martinelli proposed openstack/keystone: switch to oslo.cache  https://review.openstack.org/19587315:10
*** geoffarnold has quit IRC15:10
*** thiagop is now known as thiagop-afk15:14
samueldmqlbragstad: hi, looking15:17
*** jbell8 has joined #openstack-keystone15:18
*** arunkant_ has joined #openstack-keystone15:18
*** phalmos has joined #openstack-keystone15:19
*** browne has joined #openstack-keystone15:20
*** pdardeau has joined #openstack-keystone15:23
*** jbell8 has quit IRC15:24
*** urulama has quit IRC15:25
*** urulama has joined #openstack-keystone15:25
*** e0ne has joined #openstack-keystone15:25
*** tonytan4ever has joined #openstack-keystone15:26
*** geoffarn_ has quit IRC15:28
*** geoffarnold has joined #openstack-keystone15:28
*** belmoreira has quit IRC15:28
ayoungdiazjf, yes, but only for the default domain15:29
*** openstackgerrit has quit IRC15:31
*** openstackgerrit has joined #openstack-keystone15:32
*** geoffarnold is now known as geoffarnoldX15:34
samueldmqlbragstad: I am a bit worried about caching role assignments, but I agree that would be a great performance improvement15:34
*** geoffarnoldX is now known as geoffarnold15:34
samueldmqlbragstad: we do need to ensure we are invalidating the cache in all the cases15:34
samueldmqlbragstad: otherwise we would be opening a security hole15:34
samueldmqlbragstad: you agree ?15:34
*** jbell8 has joined #openstack-keystone15:34
*** geoffarnold is now known as geoffarnoldX15:35
dolphmjvarlamova: what's up?15:35
openstackgerritSteve Martinelli proposed openstack/keystone: Move federation extension into keystone core  https://review.openstack.org/21477515:37
dolphmjvarlamova_: ^15:37
dstaneksamueldmq: depends on the expiry of the cache too15:40
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements  https://review.openstack.org/23543515:41
openstackgerritOpenStack Proposal Bot proposed openstack/keystonemiddleware: Updated from global requirements  https://review.openstack.org/23543615:41
*** gordc has quit IRC15:41
samueldmqdstanek: what cache expiry usually looks like ?15:41
samueldmqdstanek: in seconds ? (I honestly have no experience on that)15:42
openstackgerritDolph Mathews proposed openstack/keystone: Correct typo in copyright  https://review.openstack.org/23252815:42
dolphmsamueldmq: look for all the .invalidate() calls in keystone15:43
diazjfayoung does that mean that only the admin user will be able to access the services?15:43
ayoungdiazjf, depends on your setup, but I think you want to move the token validation to V315:44
ayoungstevemar_, so...I think federation should go under identity, shouldn't it?15:45
* ayoung knows he's right, but also that it is too big a pain to actually implement15:45
jvarlamova_dolphm: Stable/kilo branch of python-keystoneclient was broken some time ago due to bug https://bugs.launchpad.net/python-keystoneclient/+bug/1480314, which is fixed now. When a release of stable/kilo branch with this bugfix is planned? I'm wondering because it affects kilo branch of manilaclient project.15:45
openstackLaunchpad bug 1480314 in python-keystoneclient "Branch "stable/kilo" is broken" [Undecided,In progress] - Assigned to Julia Varlamova (jvarlamova)15:45
samueldmqdolphm: yes, that's when we invalidate the cache of GET/LIST methods .. I am just worried about we ensurign we do invalidate properly in all the cases when caching role assignments15:45
*** blewis has joined #openstack-keystone15:46
dstaneksamueldmq: usually seconds yes15:46
samueldmqdolphm: but I agree  it can be a huge improvement15:46
*** blewis is now known as Guest2779915:46
lbragstadsamueldmq cache expiry is controlled through config15:46
samueldmqdolphm: otherwise we would be opening a security hole (in the case we don't invalidate properly), then dstanek said it can be not too bad depending on the cache expiry15:47
samueldmqdstanek: lbragstad nice15:47
samueldmqdstanek: why do we cache on manager vs controller ?15:47
diazjfayoung I'm using https://github.com/openstack/castellan/blob/master/castellan/key_manager/barbican_key_manager.py#L134-L140 but it seems to only be able to be accessed by an admin user. How can I fix this?15:47
samueldmqdstanek: in the controller we would cache the formatted entities, which would be still better, right ? and we would remove the complexity of store/invalidate cache from the manager15:48
dstaneksamueldmq: i'm assuming it's on the manager?15:48
ayoungdiazjf, give the user admin privs15:48
*** gyee has joined #openstack-keystone15:48
*** ChanServ sets mode: +v gyee15:48
ayoungdiazjf, and then go beat up the barbiccan folks15:48
samueldmqdstanek: yes it is on hte manager, and I wonder why we don't do it in the controller level15:48
ayoungbut it s really not their fault, its ours, becasue we can't fix policy15:48
dolphmsamueldmq: we could cache at both, but if you're going to cache at the controller layer, i'd suggest caching externally to keystone in nginx or something instead15:48
dstaneksamueldmq: controller should be cacheable via http15:49
*** geoffarnoldX has quit IRC15:49
*** spandhe has joined #openstack-keystone15:49
*** geoffarnold has joined #openstack-keystone15:49
diazjfayoung, hmm I am using a user with admin priv just on a tenant other than admin and I get back forbidden :(15:49
dolphmsamueldmq: or in middleware15:50
dolphmsamueldmq: if you really want to cache via python15:50
samueldmqdolphm: dstanek nice, but those caches would only look at expiry of the cache, right ?15:51
dstaneksamueldmq: yes, exactly15:51
dolphmsamueldmq: and HTTP headers, like Vary15:51
samueldmqand we provide cache in keystone to be more granular, because we do know exactly when it should be invalidated15:51
dstaneksamueldmq: caching too much is an anti pattern IMO15:52
dolphmdstanek: cache all the things!15:52
samueldmqdstanek: dolphm I still think we could cache in the controller (still keystone internal) vs manager15:53
samueldmqwould make manager code simpler, and we would cache the formatted entities, intead of formattign them all the time15:53
dolphmsamueldmq: by "vs", do you mean "not caching in the manager?15:53
dolphm"15:53
dstaneksamueldmq: i don't. it's better to cache closer to the individual data layers because there is less that would need to make invalidation calls15:53
samueldmqdolphm: yes, instead of caching in the manager, do the cache in the controller15:53
lbragstaddstanek ++15:54
dolphmsamueldmq: no. both, sure. but no.15:54
*** spandhe has quit IRC15:54
dstaneksamueldmq: if you cache at the controller then the controller has to know about all the data that can change to invalidate or everyhting has to know about the controller15:54
dstanekeither way it's a bad architecture15:54
dstaneksamueldmq: that's part of caching too much15:55
samueldmqdstanek: and then that's better to cache in the manager because it takes care of the business logic ..15:55
*** jsavak has joined #openstack-keystone15:55
dolphmsamueldmq: i only really care about the performance of token creation & validation requests, and the handful of other requests involved in the auth flow. everything else can be slow and no one will care.15:55
dstaneksamueldmq: i would actually prefer caching only in the backends, but i think it's too late for that15:56
dolphmsamueldmq: try accomplishing that by caching in the controller layer15:56
samueldmqdolphm: I kind of agree .. since token issue/vlidation is what is more requested15:56
dstanekmanager is a good compromise15:56
*** fhubik has quit IRC15:56
samueldmqdolphm: yeah, but then the manager would need to know that, deleting a user, it would need to invalidate the user's assignments .. which seems to be some 'business logic' ? (and then the manager)15:57
*** ankurgupta has left #openstack-keystone15:57
*** rvba has quit IRC15:58
samueldmqdstanek: dolphm: lbragstad: my point was to only leave the pure business logic in the controller (where the more complicated code normally lives)15:58
samueldmqthen put the cache in another level, I can even see another intermediate level between manager and controller just for cache ?15:58
dolphmsamueldmq: yes, cache invalidation is hard15:58
samueldmqjust cache -> call manager -> invalidate ?15:58
dstaneksamueldmq: controllers shouldn't have real business logic at all; they should really just take web stuff and make calls into busiiness logic15:58
dolphmdstanek: ++15:59
samueldmqcool, I agree15:59
samueldmqdolphm: yes, so wouldn't it be worth it to have a level to control only the cache ? as suggested above ?15:59
samueldmqthen we can properly test it, and code would be clearer16:00
dolphmsamueldmq: we basically have that today, as all caching occurs around manager calls, but you could refactor it to mait it clearer16:00
dolphms/mait/make/16:00
samueldmqand easier to test, imo .. we could simply mock the cache things and assert invalidate was called16:00
samueldmqdolphm: yes, and the refactor would be to crete another level between manager <-> controller, the cache level, or somethingl ike that16:01
samueldmqdstanek: lbragstad ^16:01
*** _cjones_ has joined #openstack-keystone16:01
*** _cjones_ has quit IRC16:02
*** _cjones_ has joined #openstack-keystone16:02
dolphmsamueldmq: you can already enable/disable all caching for testing16:02
*** su_zhang has quit IRC16:03
*** rderose has joined #openstack-keystone16:03
samueldmqdolphm: yes, but my point isn't to disable cache for thetests, it is to clearly have a separate the caching logic, both in the code and tests, invalidation is hard16:04
dolphmsamueldmq: right, you're describing a non-functional refactor for the sake of clarity16:05
dstaneksamueldmq: i agree because i think decorators suck and i'm not a fan of using them to cache - i've been down that road before16:07
samueldmqdolphm: exactly, clarity then simplicity, soundness and stability16:07
samueldmqdstanek: ++ nice16:07
*** geoffarnold has quit IRC16:10
*** geoffarnold has joined #openstack-keystone16:10
*** jsavak has quit IRC16:14
*** jsavak has joined #openstack-keystone16:14
samueldmqI am gonna see how the code would looks like16:21
dolphmsamueldmq: you'd basically re-implement cache_on_arguments somehow in your new cache layer, maybe discard dogpile.cache, and move all the invalidate() calls into your new cache layer16:22
samueldmqdolphm: ++16:23
*** urulama has quit IRC16:27
*** urulama has joined #openstack-keystone16:27
*** e0ne has quit IRC16:30
*** geoffarnold has quit IRC16:31
*** geoffarnold has joined #openstack-keystone16:32
*** jistr has quit IRC16:33
*** diazjf has quit IRC16:34
*** stevemar_ has quit IRC16:35
*** stevemar_ has joined #openstack-keystone16:36
*** ChanServ sets mode: +o stevemar_16:36
*** roxanaghe has quit IRC16:36
*** diazjf has joined #openstack-keystone16:37
*** roxanaghe has joined #openstack-keystone16:37
openstackgerritKent Wang proposed openstack/keystone: Fix Revocation_list calling isotime on str objects  https://review.openstack.org/23548716:38
openstackgerritDolph Mathews proposed openstack/keystone: Promote an arbitrary string to be a docstring  https://review.openstack.org/22991616:38
openstackgerritDolph Mathews proposed openstack/keystone: Add docstring validation  https://review.openstack.org/22968916:38
openstackgerritDolph Mathews proposed openstack/keystone: Fix D204: blank line required after class docstring (PEP257)  https://review.openstack.org/22989816:38
openstackgerritDolph Mathews proposed openstack/keystone: Fix D210: No whitespaces allowed surrounding docstring text (PEP257)  https://review.openstack.org/22985716:38
openstackgerritDolph Mathews proposed openstack/keystone: Fix D202: No blank lines after function docstring (PEP257)  https://review.openstack.org/22988716:38
openstackgerritDolph Mathews proposed openstack/keystone: Fix D300: Use """triple double quotes""" (PEP257)  https://review.openstack.org/22985316:38
openstackgerritDolph Mathews proposed openstack/keystone: Fix D208: Docstring over indented. (PEP257)  https://review.openstack.org/22983716:38
openstackgerritDolph Mathews proposed openstack/keystone: Fix D301: Use r”“” if any backslashes in your docstring (PEP257)  https://review.openstack.org/22985516:38
openstackgerritDolph Mathews proposed openstack/keystone: Fix D402: First line should not be the function's "signature" (PEP257)  https://review.openstack.org/22983916:38
openstackgerritDolph Mathews proposed openstack/keystone: Fix D200: 1 line docstrings should fit with quotes (PEP257)  https://review.openstack.org/22986516:38
dolphm(sorry.)16:38
*** petertr7 is now known as petertr7_away16:41
*** tonytan4ever has quit IRC16:42
*** mylu has joined #openstack-keystone16:43
bknudsonmaybe we can fix the gerrit bot to only post the first change16:48
*** lhcheng has joined #openstack-keystone16:49
*** ChanServ sets mode: +v lhcheng16:49
*** uiyice has joined #openstack-keystone16:50
*** geoffarn_ has joined #openstack-keystone16:53
*** geoffarnold has quit IRC16:53
*** tonytan4ever has joined #openstack-keystone16:55
openstackgerritDolph Mathews proposed openstack/keystone: Promote an arbitrary string to be a docstring  https://review.openstack.org/22991616:57
openstackgerritDolph Mathews proposed openstack/keystone: Add docstring validation  https://review.openstack.org/22968916:57
openstackgerritDolph Mathews proposed openstack/keystone: Fix D204: blank line required after class docstring (PEP257)  https://review.openstack.org/22989816:57
openstackgerritDolph Mathews proposed openstack/keystone: Fix D210: No whitespaces allowed surrounding docstring text (PEP257)  https://review.openstack.org/22985716:57
openstackgerritDolph Mathews proposed openstack/keystone: Fix D202: No blank lines after function docstring (PEP257)  https://review.openstack.org/22988716:57
openstackgerritDolph Mathews proposed openstack/keystone: Fix D300: Use """triple double quotes""" (PEP257)  https://review.openstack.org/22985316:57
openstackgerritDolph Mathews proposed openstack/keystone: Fix D208: Docstring over indented. (PEP257)  https://review.openstack.org/22983716:57
openstackgerritDolph Mathews proposed openstack/keystone: Fix D301: Use r”“” if any backslashes in your docstring (PEP257)  https://review.openstack.org/22985516:57
openstackgerritDolph Mathews proposed openstack/keystone: Fix D402: First line should not be the function's "signature" (PEP257)  https://review.openstack.org/22983916:57
openstackgerritDolph Mathews proposed openstack/keystone: Fix D200: 1 line docstrings should fit with quotes (PEP257)  https://review.openstack.org/22986516:57
dolphm(more sorry.)16:57
dolphmbknudson: i believe git-review uploads the new patchsets one at a time, so that'd be pretty hard16:57
*** jsavak has quit IRC16:59
dolphmi'm going to have to upload most of them one more time, so hold off on reviews!17:00
*** su_zhang has joined #openstack-keystone17:00
openstackgerritAlexander Makarov proposed openstack/keystone: Unified delegation driver  https://review.openstack.org/20960017:02
dstanekdolphm: does flake8_docstrings need to be in g-r?17:02
dolphmdstanek: yes, there's a review up17:02
dolphmdstanek: https://review.openstack.org/#/c/229685/17:03
dstanekdolphm: ah, thx.17:03
dstaneklooks like dhellmann needs to unblock17:04
*** phalmos has quit IRC17:04
*** phalmos has joined #openstack-keystone17:05
samueldmqdolphm: in the case you're going to update the first in that chain.. we need to pin pep257 in keystone too17:06
*** mylu has quit IRC17:06
samueldmqdolphm: just in the case you didn't see my comment in the review (I checked that with infra guys)17:07
*** jsavak has joined #openstack-keystone17:08
dolphmsamueldmq: define "need"17:08
*** dikonoor has quit IRC17:08
samueldmqdolphm: it's the same reason as we need to pin in the g-r (https://review.openstack.org/#/c/229685/10/global-requirements.txt)17:10
dolphmsamueldmq: no, not really. g-r affects CI. local pinning affects local devs17:10
samueldmq"Some requirements, like linters need to be pinned, because they have terrible backwards compatibility stories."17:10
dolphmsamueldmq: so, when a new version of pep257 is released, local devs find out before the gate breaks17:10
*** lbragstad_ has joined #openstack-keystone17:11
*** spandhe has joined #openstack-keystone17:11
samueldmqdolphm:  thought it was the opposite .. g-r can be updated, and local devs can have the fleibility to update the project's requirements later17:12
*** jasonsb_ has joined #openstack-keystone17:12
dolphmsamueldmq: that's true for gating, but does not restrict development workflow17:12
samueldmqdolphm: and I thought CI would install the requirements exactly as they're defined in our test-requirements17:13
*** bitblt has joined #openstack-keystone17:13
*** diazjf has quit IRC17:13
*** gyee has quit IRC17:14
*** geoffarnold has joined #openstack-keystone17:14
*** wwwjfy has quit IRC17:14
dolphmsamueldmq: your soliloquy is accurate17:16
samueldmqdolphm: well, I had checked with mordred on #infra and we had find out that it would need to be pinned too17:17
*** geoffarnold is now known as geoffarnoldX17:18
*** geoffarn_ has quit IRC17:18
samueldmqdolphm: those were the reasons I understood why we needed to pin it as well17:19
samueldmqdolphm: but maybe I am just misunderstanding the workflow/needs, I just wanted to ensure things are properly set17:19
dolphmsamueldmq: i'll add the pin so you don't have to worry about it17:21
openstackgerritDolph Mathews proposed openstack/keystone: Add docstring validation  https://review.openstack.org/22968917:24
samueldmqdolphm: thanks, but that's not about me, I just want to ensure we code as it should be (that's why we do code-reviews)17:24
samueldmqdolphm: I am happy to be wrong if it isn't needed17:24
jvarlamova_dolphm: could you please tell are there any plans about release of keystoneclient stable/kilo branch with fix of bug https://bugs.launchpad.net/python-keystoneclient/+bug/1480314?17:25
openstackLaunchpad bug 1480314 in python-keystoneclient "Branch "stable/kilo" is broken" [Undecided,In progress] - Assigned to Julia Varlamova (jvarlamova)17:25
samueldmqdolphm: that already had my +1 anyway, thanks17:25
dolphmjvarlamova_: is there a review in the release repo?17:25
jvarlamova_dolphm: https://review.openstack.org/#/c/207906/17:28
dolphmjvarlamova_: the release repo: https://github.com/openstack/releases17:29
openstackgerritDolph Mathews proposed openstack/keystone: Fix D208: Docstring over indented. (PEP257)  https://review.openstack.org/22983717:29
openstackgerritDolph Mathews proposed openstack/keystone: Fix D402: First line should not be the function's "signature" (PEP257)  https://review.openstack.org/22983917:30
*** topol has quit IRC17:33
*** geoffarnoldX has quit IRC17:35
*** geoffarnold has joined #openstack-keystone17:35
openstackgerritDolph Mathews proposed openstack/keystone: Promote an arbitrary string to be a docstring  https://review.openstack.org/22991617:36
openstackgerritDolph Mathews proposed openstack/keystone: Fix D204: blank line required after class docstring (PEP257)  https://review.openstack.org/22989817:36
openstackgerritDolph Mathews proposed openstack/keystone: Fix D210: No whitespaces allowed surrounding docstring text (PEP257)  https://review.openstack.org/22985717:36
openstackgerritDolph Mathews proposed openstack/keystone: Fix D202: No blank lines after function docstring (PEP257)  https://review.openstack.org/22988717:36
openstackgerritDolph Mathews proposed openstack/keystone: Fix D300: Use """triple double quotes""" (PEP257)  https://review.openstack.org/22985317:36
openstackgerritDolph Mathews proposed openstack/keystone: Fix D200: 1 line docstrings should fit with quotes (PEP257)  https://review.openstack.org/22986517:36
*** jasonsb__ has joined #openstack-keystone17:37
*** jdennis has quit IRC17:37
*** jasonsb_ has quit IRC17:37
jvarlamova_dolphm: Thanks! In this case I'll propose a request for release.17:37
*** petertr7_away is now known as petertr717:38
openstackgerritMerged openstack/keystone: Create a version package  https://review.openstack.org/20326217:39
*** pnavarro|off has quit IRC17:42
*** gordc has joined #openstack-keystone17:49
*** browne has quit IRC17:52
*** browne has joined #openstack-keystone17:53
*** browne has quit IRC17:54
*** geoffarnold has quit IRC17:56
*** geoffarnold has joined #openstack-keystone17:57
*** jvarlamova_ has quit IRC17:57
*** lbragstad has quit IRC18:00
*** jacorob has quit IRC18:00
*** Guest27799 has quit IRC18:00
*** lbragstad_ is now known as lbragstad18:00
*** roxanaghe has quit IRC18:01
openstackgerritBrant Knudson proposed openstack/keystone: Enable try_except_pass Bandit test  https://review.openstack.org/22573818:01
openstackgerritBrant Knudson proposed openstack/keystone: Enable subprocess_without_shell_equals_true Bandit test  https://review.openstack.org/22569218:01
*** rderose has quit IRC18:01
*** david-lyle has quit IRC18:01
*** david-lyle has joined #openstack-keystone18:02
*** jdennis has joined #openstack-keystone18:04
*** roxanaghe has joined #openstack-keystone18:05
*** hongbin has joined #openstack-keystone18:07
hongbinHi, I am from Magnum. A question here. If I get a v2 token from user, is that a way to convert it to a v3 token?18:08
*** e0ne has joined #openstack-keystone18:09
*** roxanaghe has quit IRC18:13
*** exploreshaifali has joined #openstack-keystone18:13
*** alejandrito has joined #openstack-keystone18:14
*** bitblt has quit IRC18:16
*** geoffarnold has quit IRC18:17
*** geoffarnold has joined #openstack-keystone18:18
*** roxanaghe has joined #openstack-keystone18:21
dhellmannstevemar_: we need to land https://review.openstack.org/#/c/235229/ to open stable/liberty for keystone but it's failing the unit tests there, can you have someone take a look?18:22
lhchenghongbin: I don't think so, you have to request a new v3 token.18:22
stevemar_dhellmann: probably the policy tests18:23
dolphmbknudson: need to backport your policy test removal to stable/liberty18:23
bknudsondolphm: it's proposed...18:23
stevemar_dhellmann: https://review.openstack.org/#/c/235374/ is what shoud fix it18:23
bknudsonI think we need to merge the 218:23
stevemar_but it's currently on the floor18:23
stevemar_bknudson: i think you're right, the two need to go in at the same time18:24
hongbinlhcheng: got it. thx18:24
bknudsonmerge it with https://review.openstack.org/#/c/235229/18:24
bknudsonwant me to do that?18:25
bknudsonshould only take a min18:25
dolphm"with" ?18:25
dolphmoh, into a single patch18:25
*** diazjf has joined #openstack-keystone18:25
bknudsony, should have said squash18:25
dolphmgot it18:25
stevemar_bknudson: you want to do it?18:25
stevemar_dolphm and i can +2/+A18:26
bknudsonworking on it.18:26
dolphmi can click buttons18:26
*** su_zhang has quit IRC18:26
bknudsonI put them in here: https://review.openstack.org/#/c/235229/18:29
bknudsonI'm going to also push a change to switch the default branch to stable/liberty before that catches me out again.18:30
*** hongbin has left #openstack-keystone18:30
dolphmbknudson: that's not already in review?18:30
bknudsonI don't see a review for it.18:31
dolphmweird, i don't see one either18:31
dolphmi thought i reviewed it, but maybe it was for a different project18:31
*** topol has joined #openstack-keystone18:31
*** ChanServ sets mode: +v topol18:31
*** roxanaghe has quit IRC18:31
*** thiagop-afk is now known as thiagop18:33
*** lsmola_ has quit IRC18:35
*** browne has joined #openstack-keystone18:35
dolphmbknudson: ./keystone/tests/unit/test_policy.py:19:1: F401 'six' imported but unused18:35
bknudsonah, easy fix.18:35
*** marzif has joined #openstack-keystone18:35
bknudsonI was in the middle of running the tests.18:36
bknudsonpep8 worked locally for some reason18:36
*** marzif has quit IRC18:36
dolphmbknudson: wait, it is used18:36
dolphmbknudson: L244...18:36
*** marzif has joined #openstack-keystone18:36
bknudsonwow...18:37
openstackgerritSteve Martinelli proposed openstack/keystone: Move endpoint_policy migrations into keystone core  https://review.openstack.org/17191618:37
openstackgerritSteve Martinelli proposed openstack/keystone: Move federation extension into keystone core  https://review.openstack.org/21477518:37
bknudsonpep8==1.5.718:37
dolphmbknudson: oh, your patch isn't based on master18:37
dolphmoh, dammit18:38
bknudsonI just cherry-picked it.18:38
*** roxanaghe has joined #openstack-keystone18:39
dolphmi think i cherry picked your patch onto an old stable/liberty, instead of just checking it out18:39
*** geoffarnold has quit IRC18:39
dolphmor something18:39
dolphmnot really sure, but i'm starting over18:39
*** geoffarn_ has joined #openstack-keystone18:39
dolphmpep8 passed18:39
bknudsonhttps://review.openstack.org/235542 is the .gitreview update.18:40
stevemar_dolphm: i'm gonna pile on: https://review.openstack.org/#/c/195873/18:42
dolphmstevemar_: to what?18:42
*** woodster_ has joined #openstack-keystone18:43
stevemar_dolphm: pile on to your review request queue18:43
*** dims has joined #openstack-keystone18:43
*** roxanaghe has quit IRC18:43
*** HT_sergio has joined #openstack-keystone18:43
*** amakarov is now known as amakarov_away18:44
*** dims_ has quit IRC18:45
openstackgerritDolph Mathews proposed openstack/keystone: Add docstring validation  https://review.openstack.org/22968918:46
dolphmstevemar_: what if i told you it was already in my review queue?18:46
openstackgerritHenrique Truta proposed openstack/keystone: Sub projects acting as domains  https://review.openstack.org/23554418:47
dolphmstevemar_: along with 60+ other patches18:47
bknudsonwatch out he might start throwing things on the field. you know canadians.18:47
*** dims has quit IRC18:47
stevemar_dolphm: you mean i don't get preferential treatment?18:50
stevemar_bknudson: we riot like a boss18:50
*** urulama has quit IRC18:55
*** urulama has joined #openstack-keystone18:55
*** lastops has joined #openstack-keystone18:57
*** lastops has quit IRC18:57
stevemar_osc meeting time!18:59
*** geoffarn_ has quit IRC19:00
openstackgerritSteve Martinelli proposed openstack/python-keystoneclient: auto-generate release history  https://review.openstack.org/22765519:00
*** geoffarnold has joined #openstack-keystone19:01
*** pnavarro|off has joined #openstack-keystone19:03
*** jsavak has quit IRC19:03
*** csoukup has quit IRC19:03
*** jsavak has joined #openstack-keystone19:04
*** diazjf has quit IRC19:05
*** diazjf has joined #openstack-keystone19:06
*** HT_sergio has quit IRC19:07
*** uiyice has left #openstack-keystone19:09
*** dims has joined #openstack-keystone19:11
bretonliberty released!19:16
*** diazjf has quit IRC19:18
*** rvba has joined #openstack-keystone19:19
*** rvba has quit IRC19:19
*** rvba has joined #openstack-keystone19:19
*** ayoung has quit IRC19:19
*** geoffarnold has quit IRC19:21
*** geoffarnold has joined #openstack-keystone19:22
dolphm\o/19:23
*** e0ne has quit IRC19:25
*** jdennis has quit IRC19:27
bretontomorrow is bug fixing day19:30
*** dims has quit IRC19:30
bretonhttps://etherpad.openstack.org/p/keystone-office-hours19:31
*** rderose has joined #openstack-keystone19:37
openstackgerritSteve Martinelli proposed openstack/keystone: Move federation sql migrations to common  https://review.openstack.org/23453719:37
stevemar_breton: damn straight19:38
openstackgerritHenrique Truta proposed openstack/keystone: Create tests for set_default_is_domain in LDAP  https://review.openstack.org/22953619:39
*** geoffarnold is now known as geoffarnoldX19:39
*** geoffarnoldX has quit IRC19:42
*** geoffarnold has joined #openstack-keystone19:43
*** diazjf has joined #openstack-keystone19:46
*** su_zhang has joined #openstack-keystone19:46
*** marzif has quit IRC19:50
*** jdennis has joined #openstack-keystone19:51
*** mestery_ has joined #openstack-keystone19:53
*** gordc has quit IRC20:03
*** geoffarn_ has joined #openstack-keystone20:04
*** geoffarnold has quit IRC20:05
*** rderose has quit IRC20:05
openstackgerritSteve Martinelli proposed openstack/keystone: Move oauth1 extension into core  https://review.openstack.org/23459820:06
openstackgerritSteve Martinelli proposed openstack/keystone: Move oauth1 sql migrations to common  https://review.openstack.org/23512120:06
*** rdo has quit IRC20:07
*** ayoung has joined #openstack-keystone20:08
*** ChanServ sets mode: +v ayoung20:08
openstackgerritHenrique Truta proposed openstack/keystone: Tests for projects acting as domains  https://review.openstack.org/21121920:13
openstackgerritHenrique Truta proposed openstack/keystone: Manager support for projects acting as domains  https://review.openstack.org/21344820:13
openstackgerritHenrique Truta proposed openstack/keystone: Projects acting as domains  https://review.openstack.org/23128920:13
openstackgerritHenrique Truta proposed openstack/keystone: Removes project.domain_id FK  https://review.openstack.org/23327420:13
openstackgerritHenrique Truta proposed openstack/keystone: Change project name constraints  https://review.openstack.org/15837220:13
openstackgerritHenrique Truta proposed openstack/keystone: Add is_domain parameter to get_project_by_name  https://review.openstack.org/21060020:13
htrutahey ayoung, could you mark this patch https://review.openstack.org/#/c/143763/81 as abandoned?20:13
htrutait was split in a 3 or 4, the core of it is in this one: https://review.openstack.org/#/c/231289/ which you're co-author20:13
*** mylu has joined #openstack-keystone20:17
ayounghtruta, cool.  Will do20:18
htrutaayoung: thanks20:18
*** boris-42 has quit IRC20:18
ayounghtruta, excellent20:19
*** mestery_ has quit IRC20:19
*** geoffarn_ has quit IRC20:25
*** geoffarnold has joined #openstack-keystone20:26
*** mylu has quit IRC20:29
openstackgerritSteve Martinelli proposed openstack/keystone: Remove example extension  https://review.openstack.org/23557420:29
*** mylu has joined #openstack-keystone20:29
*** mylu_ has joined #openstack-keystone20:31
*** mylu has quit IRC20:31
*** mestery_ has joined #openstack-keystone20:32
*** mestery_ has quit IRC20:32
*** Guest71541 has joined #openstack-keystone20:32
*** lifeless has quit IRC20:34
openstackgerritTom Cocozzello proposed openstack/keystone: Fix docstring  https://review.openstack.org/23488120:35
stevemar_ayoung: is the revoke extension database migrated automatically?20:37
ayoungstevemar_, I could say yes, but you know that I lie20:37
stevemar_dang20:37
ayoungI make things up20:37
stevemar_hehe20:37
ayoungstevemar_, I think it is easy to check...one sec20:38
stevemar_what's your gut reaction say? :P20:38
ayoungstevemar_, http://git.openstack.org/cgit/openstack/keystone/tree/keystone/common/sql/migration_helpers.py#n3720:39
ayoungstevemar_, http://git.openstack.org/cgit/openstack/keystone/tree/keystone/common/sql/migration_helpers.py#n19820:39
stevemar_ayoung: hmm20:40
stevemar_and it's always run right, no opt-in?20:40
stevemar_i mean, for the entire revoke extension right?20:40
ayoungstevemar_, if you don't specify an extension, the core repo and default extensions are upgraded20:40
*** drjones has joined #openstack-keystone20:41
*** pnavarro|off has quit IRC20:42
*** _cjones_ has quit IRC20:42
stevemar_ayoung: nah, i meant the routes/paths, they are always enabled right? there's nothing in keystone.conf to disable revoke?20:44
openstackgerritHenrique Truta proposed openstack/keystone: Sub projects acting as domains  https://review.openstack.org/23554420:44
openstackgerritHenrique Truta proposed openstack/keystone: Tests for subprojects acting as domains  https://review.openstack.org/23490720:44
*** drjones has quit IRC20:45
*** mylu_ has quit IRC20:45
*** _cjones_ has joined #openstack-keystone20:45
*** mylu has joined #openstack-keystone20:45
*** Guest71541 is now known as dims_20:46
*** geoffarnold has quit IRC20:46
*** geoffarnold has joined #openstack-keystone20:47
openstackgerritTom Cocozzello proposed openstack/keystone: Fix docstring  https://review.openstack.org/23488120:47
openstackgerritBrant Knudson proposed openstack/keystone: Common arguments for fernet payloads assembly  https://review.openstack.org/23016520:47
openstackgerritBrant Knudson proposed openstack/keystone: Normalize fernet payload disassembly  https://review.openstack.org/23018120:47
openstackgerritBrant Knudson proposed openstack/keystone: De-duplicate fernet payload tests  https://review.openstack.org/23019320:47
openstackgerritJulien Danjou proposed openstack/keystone: wsgi: fix base_url finding  https://review.openstack.org/22646420:48
*** mylu has quit IRC20:49
*** mylu_ has joined #openstack-keystone20:49
*** rderose has joined #openstack-keystone20:52
*** petertr7 is now known as petertr7_away20:53
bknudsonrecheck20:55
stevemar_bknudson: no rechecking here20:56
openstackgerritSteve Martinelli proposed openstack/python-keystoneclient: Fix typo that says V3 token only works for v2  https://review.openstack.org/23558121:00
*** mylu_ has quit IRC21:01
*** mylu has joined #openstack-keystone21:02
*** jsavak has quit IRC21:02
*** jsavak has joined #openstack-keystone21:03
morganbknudson: reverify21:03
openstackgerritBrant Knudson proposed openstack/oslo.policy: Use JSON generator  https://review.openstack.org/23442121:04
*** mylu has quit IRC21:05
*** mylu has joined #openstack-keystone21:06
openstackgerritHenrique Truta proposed openstack/keystone: Tests for projects acting as domains  https://review.openstack.org/21121921:06
openstackgerritHenrique Truta proposed openstack/keystone: Bye Bye Domain Table  https://review.openstack.org/16185421:06
openstackgerritHenrique Truta proposed openstack/keystone: Remove domain table references  https://review.openstack.org/16593621:06
openstackgerritHenrique Truta proposed openstack/keystone: Projects acting as domains  https://review.openstack.org/23128921:06
openstackgerritHenrique Truta proposed openstack/keystone: Removes project.domain_id FK  https://review.openstack.org/23327421:06
*** geoffarnold has quit IRC21:08
*** mylu has quit IRC21:08
*** geoffarnold has joined #openstack-keystone21:08
*** mylu has joined #openstack-keystone21:08
*** mylu has quit IRC21:11
*** mylu has joined #openstack-keystone21:11
*** wwwjfy has joined #openstack-keystone21:12
*** mylu has quit IRC21:13
*** mylu has joined #openstack-keystone21:13
*** wwwjfy has quit IRC21:13
*** raildo is now known as raildo-afk21:14
*** jsavak has quit IRC21:15
*** mylu has quit IRC21:15
*** cburgess_ is now known as cburgess21:16
*** su_zhang has quit IRC21:19
*** mylu has joined #openstack-keystone21:21
*** mylu has quit IRC21:24
*** mylu has joined #openstack-keystone21:24
openstackgerritDolph Mathews proposed openstack/keystone: Test revocation race conditions  https://review.openstack.org/22799521:25
*** mylu has quit IRC21:29
*** geoffarnold has quit IRC21:29
*** geoffarnold has joined #openstack-keystone21:30
*** diazjf has quit IRC21:34
*** mylu has joined #openstack-keystone21:36
stevemar_morgan: ayoung: can we kill the kvs backend for revoke?21:36
ayoungstevemar_, lets just kill revoke altogether21:36
morganstevemar_: I thought we already did21:36
stevemar_morgan: looks alive to me: https://github.com/openstack/keystone/blob/master/keystone/contrib/revoke/backends/kvs.py21:37
stevemar_it was deprecated in Juno for 1 cycle :)21:37
stevemar_i think i put in a change a while ago to remove it, but looks like it never happened for $reasons21:38
stevemar_ayoung: i don't think we can kill it just yet21:38
ayoungI can dream21:38
stevemar_plus, why? it's needed21:39
ayoungstevemar_, mostly no21:39
stevemar_fernet will make it not so needed21:39
ayoungrevocations...probably only the "changed password" case is still valid21:39
ayoungall the rest were designed with remote tokens in mind21:39
stevemar_yep21:39
stevemar_but uuids are still used21:39
ayoungnow that we rebuild the token, most of those go away21:39
stevemar_so not yet :)21:39
ayoungeven with uuid, if we rebuild the tokens, the needs for revocations go way21:40
ayoungunless the password changed21:40
ayoungall other cases are bascially "give me the current state for this user"21:40
ayoungso if the user lost a role on a project, the token validation would just not have that role21:40
ayoungsame with disabled projects and domains21:40
*** mylu has quit IRC21:41
ayoungunless a token was revoked by ID for some specific reason, such as log out, or password change, most of the revocation events are superfluous21:41
bknudsonrevoke by ID should turn into revoke by audit_id now21:42
ayoungthat too21:42
bknudsonI mean the event should be audit_id21:42
ayoungbknudson, or we just drop the whole thing21:42
ayoungauthenticate to Nova and pass project ID in as a param21:42
ayoungtokens are dumb21:42
*** aix has joined #openstack-keystone21:42
openstackgerritBrant Knudson proposed openstack/keystone: Update test modules passing on py34  https://review.openstack.org/23163521:46
openstackgerritBrant Knudson proposed openstack/keystone: Handle fernet payload timestamp differences  https://review.openstack.org/23271121:46
openstackgerritBrant Knudson proposed openstack/keystone: Fix fernet key writing for python 3  https://review.openstack.org/23171021:46
openstackgerritBrant Knudson proposed openstack/keystone: Fix fernet padding for python 3  https://review.openstack.org/23171121:46
*** su_zhang has joined #openstack-keystone21:46
*** mylu has joined #openstack-keystone21:48
*** topol has quit IRC21:49
*** gyee has joined #openstack-keystone21:49
*** ChanServ sets mode: +v gyee21:49
*** rderose has quit IRC21:49
*** geoffarnold has quit IRC21:50
*** geoffarnold has joined #openstack-keystone21:51
*** mylu has quit IRC21:52
stevemar_ayoung: meh, i'll move the revoke stuff out of contrib anyway21:52
stevemar_i want all migations out of there21:53
stevemar_endpoint filter and that should be it21:53
stevemar_morgan: what should we do about the ec2 and s3 and user_crud stuff in contrib?21:53
stevemar_brb, going to bank to get yen21:53
stevemar_thats such a cool thing to say21:53
morganstevemar_: those are v2 right?21:53
stevemar_i believe so21:54
morganstevemar_: again I think the only real answer here is to merge things down into a single entry in the paste pipeline21:54
morganstevemar_: then all the old locations can be "stubs"21:54
morganthen this moving isn't going to run afoul of anything reall21:54
morgany21:54
*** su_zhang has quit IRC21:54
morgan[we can repurpose "identity" or something into the "holder" until people upgrade to the single entry]21:54
*** geoffarnold has quit IRC22:01
bretonwhat's the difference between uuid and fernet that makes revocations not needed?22:06
*** geoffarnold has joined #openstack-keystone22:06
*** sigmavirus24 is now known as sigmavirus24_awa22:08
bretonoh, right, we didn't check roles and stuff for uuid22:08
*** pdardeau has quit IRC22:16
*** jamielennox|away is now known as jamielennox22:16
*** pdardeau has joined #openstack-keystone22:16
*** topol has joined #openstack-keystone22:23
*** ChanServ sets mode: +v topol22:23
*** su_zhang has joined #openstack-keystone22:25
openstackgerritStanislaw Pitucha proposed openstack/pycadf: Add authenticate and evaluate actions  https://review.openstack.org/23560122:27
*** su_zhang has quit IRC22:30
*** pdardeau has left #openstack-keystone22:35
*** jbell8 has quit IRC22:37
*** su_zhang has joined #openstack-keystone22:39
*** pumaranikar has quit IRC22:48
openstackgerritJamie Lennox proposed openstack/keystonemiddleware: [WIP] Use keystoneauth  https://review.openstack.org/23509022:48
*** exploreshaifali has quit IRC22:49
*** topol has quit IRC22:49
*** su_zhang has quit IRC22:49
openstackgerritMerged openstack/keystone: Updated from global requirements  https://review.openstack.org/23543522:53
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23560822:57
*** thiagop has quit IRC23:02
*** tonytan4ever has quit IRC23:03
*** jbell8 has joined #openstack-keystone23:03
*** r-daneel has quit IRC23:03
*** geoffarnold is now known as geoffarnoldX23:04
*** gildub has joined #openstack-keystone23:04
*** jbell8 has quit IRC23:05
*** tsymanczyk has quit IRC23:06
*** jbell8 has joined #openstack-keystone23:07
*** tsymancz2k has quit IRC23:07
*** david-lyle has quit IRC23:09
*** david-lyle has joined #openstack-keystone23:09
*** geoffarnoldX is now known as geoffarnold23:10
*** geoffarnold has quit IRC23:11
*** tsymanczyk has joined #openstack-keystone23:12
*** tsymanczyk is now known as Guest4720123:13
*** wwwjfy has joined #openstack-keystone23:13
*** arunkant_ has quit IRC23:13
*** wwwjfy has quit IRC23:15
*** chlong has quit IRC23:16
jamielennoxso depends-on doesn't work for libraries :(23:16
*** tsymancz3k has joined #openstack-keystone23:17
openstackgerritMerged openstack/keystone: More info in RequestContext  https://review.openstack.org/21359523:20
*** darrenc is now known as darrenc_afk23:20
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23560823:22
*** darrenc has joined #openstack-keystone23:28
*** cburgess has quit IRC23:30
*** Guest47201 has quit IRC23:30
*** darrenc_afk has quit IRC23:30
*** tsymancz1k has joined #openstack-keystone23:30
*** cburgess has joined #openstack-keystone23:30
*** miguelgrinberg has quit IRC23:31
*** miguelgrinberg has joined #openstack-keystone23:31
*** SpamapS has quit IRC23:31
*** Ephur_ has quit IRC23:32
*** david8hu has quit IRC23:32
*** david8hu has joined #openstack-keystone23:32
*** _cjones_ has quit IRC23:34
*** hogepodge has quit IRC23:34
*** jbonjean has quit IRC23:34
*** baffle has quit IRC23:34
*** bapalm has quit IRC23:34
*** mtreinish has quit IRC23:34
*** SpamapS has joined #openstack-keystone23:35
*** tsymancz3k has quit IRC23:36
*** tsymancz1k has quit IRC23:36
*** _cjones_ has joined #openstack-keystone23:39
*** jbell8 has quit IRC23:39
*** mtreinish has joined #openstack-keystone23:39
*** bapalm has joined #openstack-keystone23:39
*** baffle has joined #openstack-keystone23:43
*** dstanek has quit IRC23:54
*** tsufiev has quit IRC23:54
*** baffle has quit IRC23:54
*** aix has quit IRC23:54
*** bradjones has quit IRC23:54
*** evrardjp has quit IRC23:54
*** martinus__ has quit IRC23:54
*** jmccrory has quit IRC23:54
*** iurygregory has quit IRC23:54
*** BAKfr has quit IRC23:54
*** brad[] has quit IRC23:54
*** mancdaz has quit IRC23:54
*** arif-ali has quit IRC23:54
*** johnthetubaguy has quit IRC23:54
*** marekd has quit IRC23:54
*** SpamapS has quit IRC23:54
*** cburgess has quit IRC23:54
*** darrenc has quit IRC23:54
*** dims_ has quit IRC23:54
*** ayoung has quit IRC23:54
*** lhcheng has quit IRC23:54
*** SamYaple has quit IRC23:54
*** serverascode has quit IRC23:54
*** jamielennox has quit IRC23:54
*** boltR has quit IRC23:54
*** mitz_ has quit IRC23:54
*** mfisch has quit IRC23:54
*** zigo has quit IRC23:54
*** tonyb has quit IRC23:54
*** krotscheck has quit IRC23:54
*** rharwood has quit IRC23:54
*** gus has quit IRC23:54
*** sigmavirus24_awa has quit IRC23:54
*** eglute has quit IRC23:54
*** d34dh0r53 has quit IRC23:54
*** cloudnull has quit IRC23:54
*** dolphm has quit IRC23:54
*** comstud has quit IRC23:54
*** hockeynut has quit IRC23:54
*** dtroyer has quit IRC23:54
*** sudorandom has quit IRC23:54
*** mgagne has quit IRC23:54
*** ChanServ has quit IRC23:54
*** gyee has quit IRC23:54
*** rvba has quit IRC23:54
*** josecastroleon has quit IRC23:54
*** briancurtin has quit IRC23:54
*** chmouel has quit IRC23:54
*** crinkle has quit IRC23:54
*** jrist has quit IRC23:54
*** ramishra has quit IRC23:54
*** phalmos has quit IRC23:54
*** doug-fish has quit IRC23:54
*** EinstCrazy has quit IRC23:54
*** svasheka has quit IRC23:54
*** nkinder has quit IRC23:54
*** Daviey has quit IRC23:54
*** esp has quit IRC23:54
*** sirushti has quit IRC23:54
*** zzzeek_ has quit IRC23:54
*** tjcocozz has quit IRC23:54
*** rm_work has quit IRC23:54
*** mjb has quit IRC23:54
*** errr has quit IRC23:54
*** Nakato has quit IRC23:54
*** odyssey4me has quit IRC23:54
*** mhu has quit IRC23:54
*** BrAsS_mO- has quit IRC23:54
*** timburke has quit IRC23:54
*** bapalm has quit IRC23:54
*** petertr7_away has quit IRC23:54
*** j_king has quit IRC23:54
*** jimbaker has quit IRC23:54
*** bknudson has quit IRC23:54
*** tristanC has quit IRC23:55
*** hughsaunders has quit IRC23:55
*** jlvillal has quit IRC23:55
*** jlk has quit IRC23:55
*** anteaya has quit IRC23:55
*** david-lyle has quit IRC23:55
*** gildub has quit IRC23:55
*** lbragstad has quit IRC23:55
*** edmondsw has quit IRC23:55
*** wasmum- has quit IRC23:55
*** btully has quit IRC23:55
*** zhiyan has quit IRC23:55
*** jraim has quit IRC23:55
*** nzeer has quit IRC23:55
*** morgan has quit IRC23:55
*** dgonzalez has quit IRC23:55
*** _cjones_ has quit IRC23:55
*** alejandrito has quit IRC23:55
*** openstackgerrit has quit IRC23:55
*** samueldmq has quit IRC23:55
*** rha has quit IRC23:55
*** rodrigods has quit IRC23:55
*** ctracey has quit IRC23:55
*** amit213 has quit IRC23:55
*** ericksonsantos has quit IRC23:55
*** dhellmann has quit IRC23:55
*** gerhardqux has quit IRC23:55
*** EmilienM has quit IRC23:55
*** notmyname has quit IRC23:55
*** mtreinish has quit IRC23:55
*** shadower has quit IRC23:55
*** toddnni has quit IRC23:55
*** daemontool_ has quit IRC23:55
*** pkarikh has quit IRC23:55
*** blogan has quit IRC23:55
*** HenryG has quit IRC23:55
*** d0ugal has quit IRC23:55
*** charz has quit IRC23:55
*** zz_john5223 has quit IRC23:55
*** lars1 has quit IRC23:55
*** Madkiss has quit IRC23:55
*** nonameentername has quit IRC23:55
*** urulama has quit IRC23:55
*** browne has quit IRC23:55
*** richm has quit IRC23:55
*** agireud has quit IRC23:55
*** kfjohnson_ has quit IRC23:55
*** bigjools has quit IRC23:55
*** rbowen has quit IRC23:55
*** alex_xu has quit IRC23:55
*** amakarov_away has quit IRC23:55
*** andreaf has quit IRC23:55
*** raildo-afk has quit IRC23:55
*** grantbow has quit IRC23:55
*** htruta has quit IRC23:55
*** hugokuo has quit IRC23:55
*** david8hu has quit IRC23:55
*** miguelgrinberg has quit IRC23:55
*** woodster_ has quit IRC23:55
*** akscram has quit IRC23:55
*** gsilvis has quit IRC23:55
*** sileht has quit IRC23:55
*** wolsen has quit IRC23:55
*** hideme_ has quit IRC23:55
*** telemonster has quit IRC23:55
*** breton has quit IRC23:55
*** flaper87 has quit IRC23:55
*** kragniz has quit IRC23:55
*** freerunner has quit IRC23:55
*** _fortis has quit IRC23:55
*** opilotte has quit IRC23:55
*** pc-pothole has quit IRC23:55
*** florianf|away has quit IRC23:55
*** mkoderer has quit IRC23:55
*** jdennis has quit IRC23:55
*** jasonsb__ has quit IRC23:55
*** slberger has quit IRC23:55
*** jasondotstar has quit IRC23:55
*** njohnston has quit IRC23:55
*** haneef__ has quit IRC23:55
*** x58 has quit IRC23:55
*** clayton has quit IRC23:55
*** med_ has quit IRC23:55
*** goodygum has quit IRC23:55
*** stevemar_ has quit IRC23:55
*** afazekas has quit IRC23:55
*** pgbridge has quit IRC23:55
*** harlowja has quit IRC23:55
*** arunkant has quit IRC23:55
*** andreykurilin has quit IRC23:55
*** mordred has quit IRC23:55
*** trey has quit IRC23:55
*** ekarlso has quit IRC23:55
*** redrobot has quit IRC23:55
*** zeus has quit IRC23:55
*** Dave has quit IRC23:55
*** tellesnobrega has quit IRC23:55
*** jgriffith has quit IRC23:55
*** rmstar has quit IRC23:55
*** raginbajin has quit IRC23:55
*** dobson has quit IRC23:55
*** jamiec has quit IRC23:55
*** jvarlamova has quit IRC23:55

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!