Friday, 2015-10-16

*** mancdaz has joined #openstack-keystone00:05
*** brad[] has joined #openstack-keystone00:05
*** BAKfr has joined #openstack-keystone00:05
*** iurygregory has joined #openstack-keystone00:05
*** jmccrory has joined #openstack-keystone00:05
*** martinus__ has joined #openstack-keystone00:05
*** evrardjp has joined #openstack-keystone00:05
*** bradjones|away has joined #openstack-keystone00:05
*** aix has joined #openstack-keystone00:05
*** baffle has joined #openstack-keystone00:05
*** jbonjean has joined #openstack-keystone00:05
*** dstanek has joined #openstack-keystone00:05
*** tsufiev has joined #openstack-keystone00:05
*** cameron.freenode.net sets mode: +v dstanek00:05
*** hogepodge has joined #openstack-keystone00:07
*** petertr7 has joined #openstack-keystone00:07
*** jdennis has joined #openstack-keystone00:07
*** jasonsb__ has joined #openstack-keystone00:07
*** afazekas has joined #openstack-keystone00:07
*** jasondotstar has joined #openstack-keystone00:07
*** pgbridge has joined #openstack-keystone00:07
*** dobson has joined #openstack-keystone00:07
*** arunkant has joined #openstack-keystone00:07
*** andreykurilin has joined #openstack-keystone00:07
*** mordred has joined #openstack-keystone00:07
*** njohnston has joined #openstack-keystone00:07
*** haneef__ has joined #openstack-keystone00:07
*** jamiec has joined #openstack-keystone00:07
*** x58 has joined #openstack-keystone00:07
*** trey has joined #openstack-keystone00:07
*** ekarlso has joined #openstack-keystone00:07
*** redrobot has joined #openstack-keystone00:07
*** zeus has joined #openstack-keystone00:07
*** Dave has joined #openstack-keystone00:07
*** clayton has joined #openstack-keystone00:07
*** med_ has joined #openstack-keystone00:07
*** tellesnobrega has joined #openstack-keystone00:07
*** jgriffith has joined #openstack-keystone00:07
*** goodygum has joined #openstack-keystone00:07
*** raginbajin has joined #openstack-keystone00:07
*** rmstar has joined #openstack-keystone00:07
*** mtreinish has joined #openstack-keystone00:07
*** shadower has joined #openstack-keystone00:07
*** toddnni has joined #openstack-keystone00:07
*** daemontool_ has joined #openstack-keystone00:07
*** pkarikh has joined #openstack-keystone00:07
*** blogan has joined #openstack-keystone00:07
*** HenryG has joined #openstack-keystone00:07
*** d0ugal has joined #openstack-keystone00:07
*** charz has joined #openstack-keystone00:07
*** Madkiss has joined #openstack-keystone00:07
*** zz_john5223 has joined #openstack-keystone00:07
*** lars1 has joined #openstack-keystone00:07
*** nonameentername has joined #openstack-keystone00:07
*** Nakato has joined #openstack-keystone00:08
*** zzzeek_ has joined #openstack-keystone00:08
*** tjcocozz has joined #openstack-keystone00:08
*** rm_work has joined #openstack-keystone00:08
*** mjb has joined #openstack-keystone00:08
*** errr has joined #openstack-keystone00:08
*** odyssey4me has joined #openstack-keystone00:08
*** mhu has joined #openstack-keystone00:08
*** BrAsS_mO- has joined #openstack-keystone00:08
*** timburke has joined #openstack-keystone00:08
*** jvarlamova has joined #openstack-keystone00:08
*** david8hu has joined #openstack-keystone00:08
*** miguelgrinberg has joined #openstack-keystone00:08
*** woodster_ has joined #openstack-keystone00:08
*** akscram has joined #openstack-keystone00:08
*** gsilvis has joined #openstack-keystone00:08
*** sileht has joined #openstack-keystone00:08
*** wolsen has joined #openstack-keystone00:08
*** hideme_ has joined #openstack-keystone00:08
*** telemonster has joined #openstack-keystone00:08
*** breton has joined #openstack-keystone00:08
*** flaper87 has joined #openstack-keystone00:08
*** kragniz has joined #openstack-keystone00:08
*** florianf|away has joined #openstack-keystone00:08
*** freerunner has joined #openstack-keystone00:08
*** _fortis has joined #openstack-keystone00:08
*** opilotte has joined #openstack-keystone00:08
*** pc-pothole has joined #openstack-keystone00:08
*** mkoderer has joined #openstack-keystone00:08
*** urulama has joined #openstack-keystone00:08
*** browne has joined #openstack-keystone00:08
*** richm has joined #openstack-keystone00:08
*** agireud has joined #openstack-keystone00:08
*** rbowen has joined #openstack-keystone00:08
*** kfjohnson_ has joined #openstack-keystone00:08
*** bigjools has joined #openstack-keystone00:08
*** alex_xu has joined #openstack-keystone00:08
*** amakarov_away has joined #openstack-keystone00:08
*** andreaf has joined #openstack-keystone00:08
*** raildo-afk has joined #openstack-keystone00:08
*** grantbow has joined #openstack-keystone00:08
*** htruta has joined #openstack-keystone00:08
*** hugokuo has joined #openstack-keystone00:08
*** aix has quit IRC00:11
*** david-lyle has joined #openstack-keystone00:11
*** lbragstad has joined #openstack-keystone00:11
*** edmondsw has joined #openstack-keystone00:11
*** wasmum- has joined #openstack-keystone00:11
*** btully has joined #openstack-keystone00:11
*** zhiyan has joined #openstack-keystone00:11
*** jraim has joined #openstack-keystone00:11
*** nzeer has joined #openstack-keystone00:11
*** morgan has joined #openstack-keystone00:11
*** dgonzalez has joined #openstack-keystone00:11
*** cameron.freenode.net sets mode: +v morgan00:11
*** _cjones_ has joined #openstack-keystone00:12
*** alejandrito has joined #openstack-keystone00:12
*** openstackgerrit has joined #openstack-keystone00:12
*** samueldmq has joined #openstack-keystone00:12
*** rha has joined #openstack-keystone00:12
*** rodrigods has joined #openstack-keystone00:12
*** ctracey has joined #openstack-keystone00:12
*** amit213 has joined #openstack-keystone00:12
*** ericksonsantos has joined #openstack-keystone00:12
*** dhellmann has joined #openstack-keystone00:12
*** gerhardqux has joined #openstack-keystone00:12
*** EmilienM has joined #openstack-keystone00:12
*** notmyname has joined #openstack-keystone00:12
*** bapalm has joined #openstack-keystone00:12
*** j_king has joined #openstack-keystone00:12
*** jimbaker has joined #openstack-keystone00:12
*** bknudson has joined #openstack-keystone00:12
*** jlk has joined #openstack-keystone00:12
*** tristanC has joined #openstack-keystone00:12
*** hughsaunders has joined #openstack-keystone00:12
*** jlvillal has joined #openstack-keystone00:12
*** anteaya has joined #openstack-keystone00:12
*** cameron.freenode.net sets mode: +v bknudson00:12
*** gildub has joined #openstack-keystone00:13
*** harlowja has joined #openstack-keystone00:13
*** gyee has joined #openstack-keystone00:14
*** rvba has joined #openstack-keystone00:14
*** josecastroleon has joined #openstack-keystone00:14
*** briancurtin has joined #openstack-keystone00:14
*** chmouel has joined #openstack-keystone00:14
*** jrist has joined #openstack-keystone00:14
*** crinkle has joined #openstack-keystone00:14
*** ramishra has joined #openstack-keystone00:14
*** cameron.freenode.net sets mode: +v gyee00:14
*** wasmum- has quit IRC00:14
*** david-lyle has quit IRC00:14
*** alejandrito has quit IRC00:15
*** wwwjfy has joined #openstack-keystone00:16
*** doug-fish has joined #openstack-keystone00:16
*** EinstCrazy has joined #openstack-keystone00:16
*** svasheka has joined #openstack-keystone00:16
*** nkinder has joined #openstack-keystone00:16
*** Daviey has joined #openstack-keystone00:16
*** esp has joined #openstack-keystone00:16
*** sirushti has joined #openstack-keystone00:16
*** wasmum has joined #openstack-keystone00:17
*** wasmum has quit IRC00:17
*** wasmum has joined #openstack-keystone00:17
*** EinstCrazy has quit IRC00:17
*** SpamapS has joined #openstack-keystone00:17
*** cburgess has joined #openstack-keystone00:17
*** darrenc has joined #openstack-keystone00:17
*** dims_ has joined #openstack-keystone00:17
*** ayoung has joined #openstack-keystone00:17
*** lhcheng has joined #openstack-keystone00:17
*** SamYaple has joined #openstack-keystone00:17
*** serverascode has joined #openstack-keystone00:17
*** krotscheck has joined #openstack-keystone00:17
*** jamielennox has joined #openstack-keystone00:17
*** boltR has joined #openstack-keystone00:17
*** mitz_ has joined #openstack-keystone00:17
*** mfisch has joined #openstack-keystone00:17
*** cloudnull has joined #openstack-keystone00:17
*** zigo has joined #openstack-keystone00:17
*** tonyb has joined #openstack-keystone00:17
*** rharwood has joined #openstack-keystone00:17
*** gus has joined #openstack-keystone00:17
*** sigmavirus24_awa has joined #openstack-keystone00:17
*** eglute has joined #openstack-keystone00:17
*** d34dh0r53 has joined #openstack-keystone00:17
*** dolphm has joined #openstack-keystone00:17
*** cameron.freenode.net sets mode: +vvvo ayoung lhcheng jamielennox dolphm00:17
*** comstud has joined #openstack-keystone00:17
*** hockeynut has joined #openstack-keystone00:17
*** dtroyer has joined #openstack-keystone00:17
*** mgagne has joined #openstack-keystone00:17
*** sudorandom has joined #openstack-keystone00:17
*** johnthetubaguy has joined #openstack-keystone00:19
*** arif-ali has joined #openstack-keystone00:19
*** marekd has joined #openstack-keystone00:19
*** dims_ has quit IRC00:20
*** shadower has quit IRC00:23
*** shadower has joined #openstack-keystone00:23
*** harlowja has quit IRC00:24
*** dims_ has joined #openstack-keystone00:26
*** dims_ has quit IRC00:27
*** dims_ has joined #openstack-keystone00:27
*** ChanServ has joined #openstack-keystone00:30
*** cameron.freenode.net sets mode: +o ChanServ00:30
*** jbonjean has quit IRC00:30
*** jbonjean has joined #openstack-keystone00:30
*** harlowja has joined #openstack-keystone00:31
*** stevemar_ has joined #openstack-keystone00:31
*** ChanServ sets mode: +o stevemar_00:31
*** wwwjfy has quit IRC00:32
*** wwwjfy has joined #openstack-keystone00:32
*** wwwjfy has left #openstack-keystone00:32
stevemar_jamielennox: feel like +A'ing https://review.openstack.org/#/c/227655/ ? it's already got 2x+200:36
stevemar_jamielennox: also, welcome aboard :)00:36
*** wwwjfy has joined #openstack-keystone00:36
jamielennoxstevemar_: done00:37
stevemar_\o/00:37
jamielennoxstevemar_: and yay!00:37
stevemar_https://review.openstack.org/#/c/235581/ what about a 1 character change? :P00:38
jamielennoxcan i just A that00:40
jamielennoxstevemar_: swap for https://review.openstack.org/#/c/235107/200:40
jamielennoxi said that earlier but i think it netsplit00:40
stevemar_jamielennox: up to you if you want to A it :P00:41
stevemar_i won't tattle00:41
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements  https://review.openstack.org/23564600:42
openstackgerritOpenStack Proposal Bot proposed openstack/keystonemiddleware: Updated from global requirements  https://review.openstack.org/23543600:42
*** chlong has joined #openstack-keystone00:43
jamielennoxstevemar_: so do you have plans on a ksa release?00:44
jamielennoxi know ksc got one00:44
jamielennoxksm as well by the look of it00:44
openstackgerritOpenStack Proposal Bot proposed openstack/python-keystoneclient-kerberos: Updated from global requirements  https://review.openstack.org/23565600:46
jamielennoxoh, we need to do a release of ^ too00:46
*** browne has quit IRC00:48
openstackgerritMerged openstack/oslo.policy: Add test for invalid JSON  https://review.openstack.org/23429700:55
*** wasmum has quit IRC00:56
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements  https://review.openstack.org/23564600:56
openstackgerritOpenStack Proposal Bot proposed openstack/keystonemiddleware: Updated from global requirements  https://review.openstack.org/23543600:57
stevemar_jamielennox: alright, just looking at all the bits that need to line up00:57
*** EinstCrazy has joined #openstack-keystone00:58
openstackgerritLin Hua Cheng proposed openstack/keystoneauth: Minor fix for AccessInfo project_scoped accessor  https://review.openstack.org/23561600:58
jamielennoxstevemar_: shouldn't do it on a friday either but if we can get all the bits then can go early next week00:58
stevemar_jamielennox: agreed00:59
*** mylu has joined #openstack-keystone01:00
openstackgerritOpenStack Proposal Bot proposed openstack/oslo.policy: Updated from global requirements  https://review.openstack.org/23568301:00
openstackgerritOpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements  https://review.openstack.org/23569001:00
openstackgerritMerged openstack/python-keystoneclient-kerberos: Updated from global requirements  https://review.openstack.org/23565601:00
stevemar_jamielennox: what aobut https://review.openstack.org/#/c/225453/601:01
jamielennoxstevemar_: +201:03
jamielennoxstevemar_: there's a previous +2 from bknudson as well so i think you can just tick that one off01:04
stevemar_yep, saw that01:04
openstackgerritMerged openstack/oslo.policy: Fix a typo in policy.py  https://review.openstack.org/23411001:07
openstackgerritOpenStack Proposal Bot proposed openstack/oslo.policy: Updated from global requirements  https://review.openstack.org/23568301:07
*** lhcheng has quit IRC01:08
openstackgerritAlexey Troshkov proposed openstack/python-keystoneclient: This is patch adds option is_domain to create the project. When using this option, the client creates a project as domain in keystone.  https://review.openstack.org/23508501:08
*** miyagishi_t has joined #openstack-keystone01:09
openstackgerritAlexey Troshkov proposed openstack/python-keystoneclient: This is patch adds option is_domain to create the project.  When using this option, the client creates a project as domain in keystone.  https://review.openstack.org/23508501:13
stevemar_jamielennox: anything needed for ksc-kerb01:16
openstackgerritAlexey Troshkov proposed openstack/python-keystoneclient: Add option is_domain  https://review.openstack.org/23508501:16
jamielennoxstevemar_: i have up https://review.openstack.org/#/c/233864/ which is somewhat of a revert of an earlier patch01:17
stevemar_y, i see that01:17
stevemar_i'm going to +2 dolphm's stuff01:17
jamielennoxhttps://github.com/openstack/python-keystoneclient-kerberos/commit/a7c6a7c04c0b0c4c2da3ee77532439844ead52d301:17
stevemar_same as the other repos01:17
*** davechen1 has joined #openstack-keystone01:18
jamielennoxi haven't seen that docstring one01:18
jamielennoxbut we did that in others as well?01:18
jamielennoxthe fixed flake8_docstrings==0.2.1.post1 is weird to me01:19
stevemar_jamielennox: i'm sure it'll be unfixed soon enough01:19
stevemar_the immutable __all__ can be merged now01:20
jamielennoxyea, i +Aed that one - i don't really see the point, but whatever01:20
*** david-lyle has joined #openstack-keystone01:21
openstackgerritMerged openstack/python-keystoneclient-kerberos: Make __all__ immutable  https://review.openstack.org/23004501:21
*** davechen has joined #openstack-keystone01:22
openstackgerritSteve Martinelli proposed openstack/python-keystoneclient-kerberos: Use stevedore.sphinxext to populate a new page listing all available drivers.  https://review.openstack.org/22154701:22
jamielennoxstevemar_: i haven't seen ^ at work yet01:23
stevemar_jamielennox: hmm?01:24
*** jasonsb__ has quit IRC01:24
stevemar_i dont follow01:24
jamielennoxthe sphinext thing01:24
jamielennoxthat could be really useful01:24
*** davechen1 has quit IRC01:24
stevemar_jamielennox: yes01:25
stevemar_i am hoping to try that with osc's plugins01:25
stevemar_should be "fun"01:25
stevemar_jamielennox: no docs page for ksc-kerb?01:25
stevemar_http://docs.openstack.org/developer/python-keystoneclient-kerberos01:25
jamielennoxstevemar_: no idea01:26
stevemar_that's #nobueno01:26
jamielennoxthat's bad right?01:27
stevemar_whoa, no release since april?!01:27
stevemar_yes01:27
*** jamielennox has left #openstack-keystone01:27
*** jamielennox has joined #openstack-keystone01:27
*** ChanServ sets mode: +v jamielennox01:27
jamielennoxstevemar_: it's not a plugin that needs to change much01:27
stevemar_i suppose not01:27
stevemar_still, we should have docs01:28
jamielennoxyup01:28
stevemar_is this something that will eventually get gobbled up by ksa?01:28
jamielennoxdepends on what the outcome of that extra dependencies is01:28
stevemar_i think we are good on that front01:29
stevemar_but i'd like to confirm in tokyo01:29
jamielennoxthe only reason it's seperate is because of the deps so if we merge that back then yes it'll got into ksa01:29
stevemar_yep requests-kerberos>=0.6;python_version=='2.7' or python_version=='2.6' # MIT01:29
stevemar_same with ksc-saml201:29
*** wwwjfy_ has joined #openstack-keystone01:30
davechenstevemar_, morgan, jamielennox: all of endpoint filter stuff should be merged with keystone.catalog, right?01:32
davechenI saw there is some disscussion about this in the channel.01:32
stevemar_davechen: yep, you can follow what i did with the federation and oauth bits01:32
jamielennoxstevemar_: oh, yea at least previously requests-kerberos was py27 only, i think i saw something about py3 but haven't followed up01:33
davechenoaky, I will upadate it, stevemar_01:33
davecheni think this will be splited into two bits - https://review.openstack.org/#/c/167675/ and https://review.openstack.org/#/c/183377/.01:34
*** wwwjfy has quit IRC01:34
davechendstanek: ping? are you around?01:34
stevemar_davechen: oh wow, i had no idea there was a patch for it01:35
*** wwwjfy_ has quit IRC01:35
openstackgerritMerged openstack/python-keystoneclient: auto-generate release history  https://review.openstack.org/22765501:36
davechenstevemar_: both of them are addressing endpoint filter, so I am going to just focus on this - https://review.openstack.org/#/c/183377/.01:37
stevemar_davechen: good call01:37
stevemar_davechen: yes, you've done good :) just merge it with catalog01:38
stevemar_and then i will add it to my super long chain of commits01:39
stevemar_then jamielennox will review them all :P01:39
davechenstevemar_: cool. :)01:39
jamielennoxvoluntold01:39
davechenstevemar_: should be easy for  jamielennox to review, all of these start from his first commit. :)01:40
*** edmondsw has quit IRC01:40
*** mylu has quit IRC01:43
*** spandhe has quit IRC01:44
*** pumaranikar has joined #openstack-keystone01:45
*** mylu has joined #openstack-keystone01:45
*** hidekazu has joined #openstack-keystone01:46
*** marzif has joined #openstack-keystone01:47
openstackgerritHidekazu Nakamura proposed openstack/keystone: Update development environment set up doc  https://review.openstack.org/22302001:50
openstackgerritMerged openstack/python-keystoneclient: Fix typo that says V3 token only works for v2  https://review.openstack.org/23558101:51
*** mylu has quit IRC01:52
stevemar_davechen: jamielennox that is true :)01:52
*** mylu has joined #openstack-keystone01:52
jamielennoxwhilst that first patch took a while you are both assuming i remember anything about why i did it that way01:53
davechenhehe, good response.01:54
jamielennoxstevemar_: osc is python2 only?01:55
stevemar_jamielennox: good question01:56
jamielennoxstevemar_: it failed to pip install on python3, but i'm running a seriously messed up environment01:56
stevemar_jamielennox: i could say that one of the libs we depend on probably isn't py301:57
stevemar_but honestly, i just haven't bothered to try01:57
jamielennoxtablib appears not01:57
*** mylu has quit IRC01:57
stevemar_we removed that though01:57
stevemar_i wonder if swiftclient is01:57
openstackgerritMerged openstack/keystoneauth: Add url as a deprecated alias for endpoint  https://review.openstack.org/22545301:58
openstackgerritMerged openstack/keystoneauth: Expose bind data via AccessInfo  https://review.openstack.org/23510701:59
*** richm has quit IRC02:00
*** woodster_ has quit IRC02:09
*** pumaranikar has quit IRC02:10
*** mylu has joined #openstack-keystone02:11
*** dims_ has quit IRC02:14
*** dims_ has joined #openstack-keystone02:14
*** mylu has quit IRC02:15
*** mylu has joined #openstack-keystone02:15
*** mylu has quit IRC02:17
openstackgerritMerged openstack/python-keystoneclient-kerberos: Use optional authentication  https://review.openstack.org/23386402:18
ayoungstevemar_, not that I don't trust you or jamielennox but technically https://review.openstack.org/#/c/225453/6  is a violation of the "don't railroad through a change all from one company"  policy now.02:21
*** mylu has joined #openstack-keystone02:21
openstackgerritSteve Martinelli proposed openstack/keystone: Move revoke extension into core  https://review.openstack.org/23570402:22
stevemar_ayoung: !!02:22
ayoungfeel free to ping me for those...I am more than willing to +A things that are reasonable like that02:22
stevemar_ayoung: true, good point, i am not quite used to thinking of jamielennox as same company yet :)02:23
ayoungstevemar_, you think it is hard for *you*02:23
stevemar_hehe02:23
*** mylu has quit IRC02:24
ayoungstevemar_, OTOH, morgan is now fair game again....02:24
*** mylu has joined #openstack-keystone02:24
stevemar_ayoung: true02:24
*** mylu has quit IRC02:26
*** mylu has joined #openstack-keystone02:27
openstackgerritMerged openstack/keystoneauth: Allow fetching oslo.config Opts from plugins  https://review.openstack.org/22761102:27
*** mylu has quit IRC02:27
*** spandhe has joined #openstack-keystone02:27
*** mylu has joined #openstack-keystone02:28
ayoungstevemar_, If what  Matt says on https://review.openstack.org/#/c/233480/ is correct we have a problem:  so many things expect admin unscoped to work, and he's claiming there are APIs that need Admin scoped to work...02:28
*** hightall has joined #openstack-keystone02:28
*** mylu has quit IRC02:29
ayoungstevemar_, here's the crux;  if the resource is unscoped (like a hypervisor)  what should we realistically scope it to?02:29
ayoungtermie said way back when "the admin project"02:30
*** lhcheng has joined #openstack-keystone02:30
*** ChanServ sets mode: +v lhcheng02:30
ayoungso...lets say we have an admim project...how do we communicate that to the other services?02:30
*** mylu has joined #openstack-keystone02:32
jamielennoxayoung, stevemar_: crap, that's going to be a pain02:32
*** mylu has quit IRC02:33
*** mylu has joined #openstack-keystone02:34
ayoungjamielennox,  https://review.openstack.org/#/c/233480  ?  he's got to be wrong02:35
jamielennoxayoung: that's a lot of comments02:35
ayoungjamielennox, Its like, no one wants to engage to solve the problem, just to say "No"02:36
jamielennoxayoung: i'll admit i don't really like the solution, i just havent come up with anything better yet02:36
ayoungI would really appreciate some +1 type suppor on that one.  Or an alternative. A viable alternative02:36
jamielennox:)02:37
*** mylu_ has joined #openstack-keystone02:37
ayoungjamielennox, the solution is to do this, then say "existing policy is scope check only" and make RBAC a separate check02:37
jamielennoxdoes nova etc really just ignore project scope if they get admin/02:37
ayoungthere are many APIs wehere there is no scope02:37
ayounglike add Hypervisor02:37
ayounganything not scoped to a proejct...02:38
*** mylu has quit IRC02:38
*** mylu_ has quit IRC02:38
ayoungso this is implicitly communciation "this is the admin project" via the only mechanism we have02:39
*** mylu has joined #openstack-keystone02:39
*** mylu has quit IRC02:40
*** hightall has quit IRC02:40
*** mylu has joined #openstack-keystone02:40
ayoungjamielennox, part of the problem is that we have the v3 cloud sample file implying that editing the policy files is an acceptable thing to do, but we no way of communicating what is supposed to be in that file02:41
ayoungit should be jinja {{ admin_project_id }}  or something02:41
* ayoung thinking in yaml now02:41
*** wwwjfy has joined #openstack-keystone02:41
jamielennoxyea, this was the point about service scoped tokens right02:41
jamielennoxto be able to do that sorta stuff02:42
jamielennoxwe can't even make it domain admin any more02:42
jamielennoxayoung: how do you seperate admin on project from admin on service then?02:44
jamielennoxif you limit admin to only being allowed on an admin project02:45
jamielennoxthat rules out regular project admin tasks02:45
*** browne has joined #openstack-keystone02:45
morgan.02:45
morgantest02:45
jamielennoxmorgan: roger02:46
morganok cool02:46
*** hightall has joined #openstack-keystone02:46
ayoungheh..that was the most appropriate use of roger ever02:46
ayoungroger was the old phonetic alphabet for R02:47
ayoungR was sent in mosrse code for 'received'02:47
ayoungOf course, over the readio, it is no more suyllables to say 'received' than 'roger' but the Army is nothing if not in love with traditions02:47
ayoungjamielennox, the short answer is that we stop using  admin for project scoped resources and use a differen role02:48
*** dims_ has quit IRC02:49
ayounglets call it manager and be done with it02:49
jamielennoxayoung: both problems then involve fixing policies02:49
*** dims_ has joined #openstack-keystone02:49
ayoungjamielennox, m,ome causes less pain02:49
ayoungmine02:49
ayoungjamielennox, I have yet to find a policy that checks both scope and role=='admin'02:50
ayounghttp://git.openstack.org/cgit/openstack/nova/tree/etc/nova/policy.json02:50
ayoungits all "rule:admin_or_owner",02:50
ayoung"admin_or_owner":  "is_admin:True or project_id:%(project_id)s",02:50
*** lifeless has joined #openstack-keystone02:51
ayoung"context_is_admin":  "role:admin",02:51
*** dims_ has quit IRC02:51
*** topol has joined #openstack-keystone02:51
*** ChanServ sets mode: +v topol02:51
*** dims_ has joined #openstack-keystone02:51
jamielennoxayoung: policy shouldn't let you even pass without a scope02:54
jamielennoxouch, context_is_admin is just wrong02:54
ayoungjamielennox, and yet it does.02:54
ayoungjamielennox, remember, roles were origianlly global02:54
ayoungsomeone on Keystone changed that02:54
ayoungI was trying to figure out with git blame who it was02:55
jamielennoxso why don't we just change context_is_admin to "role:admin and project_id in XXX,YYY,ZZZ"02:55
jamielennox(i don't know how to write that in policy)02:55
*** dikonoor has joined #openstack-keystone02:55
*** mylu has quit IRC02:56
*** mylu has joined #openstack-keystone03:02
*** mylu has quit IRC03:05
openstackgerritOpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements  https://review.openstack.org/23569003:06
ayoungjamielennox, look at this http://git.openstack.org/cgit/openstack/keystone/commit/?id=e8fb989b8b07f3209300ecba043bdf14c94d497f03:06
ayoungjamielennox, what would you put in the policuy file for XXX,YYY,ZZZ03:07
jamielennoxwtf is that03:07
ayoungwe could say "and project_name=admin" but now with multiple domains03:07
jamielennoxhow did that make it into an upstream produce03:07
ayoungjamielennox, heh I have no idea03:07
ayoungit was done a long long time ago03:07
ayoung2012-02-1303:07
ayoungchange groups to roles...03:07
jamielennoxayoung: it feels like we are fighting the other services at this point03:08
ayoungjamielennox, actually, my change is the only way to do it without fighting them03:08
ayoungits ack of the status quo03:08
ayoungbut, yes, we are fighting them03:08
jamielennoxayoung: i've been leaving the review because tokyo is just over a week away and i think we'll have this debate many times03:09
ayounghttp://git.openstack.org/cgit/openstack/keystone/commit/?id=6c60d6c783656f35657b6cb462d93390fc689ac003:09
jamielennoxwe being everyone not just you & me03:09
*** tobe has joined #openstack-keystone03:11
jamielennoxneed lunch, back soon03:11
*** mylu has joined #openstack-keystone03:13
ayoungit goes back to KSL https://github.com/termie/keystonelight/blob/master/keystone/identity/core.py#L12003:15
*** gyee has quit IRC03:15
openstackgerritSteve Martinelli proposed openstack/keystone: Move revoke sql migrations to common  https://review.openstack.org/23571203:27
openstackgerritMerged openstack/oslo.policy: Updated from global requirements  https://review.openstack.org/23568303:32
*** mylu has quit IRC03:47
*** mylu has joined #openstack-keystone03:49
*** jamielennox has quit IRC03:51
*** jamielennox has joined #openstack-keystone03:52
*** ChanServ sets mode: +v jamielennox03:52
*** mylu has quit IRC03:53
*** mylu has joined #openstack-keystone03:53
*** mylu_ has joined #openstack-keystone03:54
*** mylu has quit IRC03:57
*** mylu has joined #openstack-keystone03:59
*** mylu_ has quit IRC03:59
*** dims_ has quit IRC04:29
*** marzif has quit IRC04:36
*** spandhe_ has joined #openstack-keystone04:43
*** spandhe has quit IRC04:44
*** spandhe_ is now known as spandhe04:44
*** mylu has quit IRC04:44
*** mylu has joined #openstack-keystone04:45
*** mylu has quit IRC04:49
*** roxanaghe has joined #openstack-keystone04:51
*** roxanaghe has quit IRC05:01
*** lhcheng has quit IRC05:04
*** lhcheng has joined #openstack-keystone05:21
*** ChanServ sets mode: +v lhcheng05:21
openstackgerritSteve Martinelli proposed openstack/keystone: use extras for fernet token support  https://review.openstack.org/23573105:27
*** jamielennox is now known as jamielennox|away05:30
openstackgerritLin Hua Cheng proposed openstack/keystoneauth: Refactored AccessInfo.project_scoped accessor  https://review.openstack.org/23561605:39
*** miyagishi_t has quit IRC05:41
*** miyagishi_t_ has joined #openstack-keystone05:44
*** pnavarro|off has joined #openstack-keystone05:47
stevemar_lhcheng: if you're still up https://review.openstack.org/#/c/195873/05:47
stevemar_it would be great to get that one in before i have to rebase it again :)05:48
lhchengstevemar_: oh yeah, I starred the patch last night.05:51
*** roxanaghe has joined #openstack-keystone05:51
lhchenggoing to take a look now05:51
*** roxanaghe has quit IRC05:52
stevemar_lhcheng: ty sir!05:54
stevemar_you are a gentleman and a scholar05:54
lhchenghah05:54
lhchenganytime!05:55
*** miyagishi_t_ has quit IRC05:56
davechentwo night owls :)05:57
stevemar_davechen: who needs sleep anyway06:00
*** browne1 has joined #openstack-keystone06:00
*** pnavarro|off has quit IRC06:02
*** browne has quit IRC06:02
lhchengdavechen: we're staying late to keep you company06:02
davechenlhcheng: i am crying...06:02
davechen:)06:03
lhchenglol06:03
davecheni am caculating how long are you need to sleep?06:03
*** jbell8 has joined #openstack-keystone06:04
davechenrole models !06:04
lhchengI still get much, I go to work a bit later06:05
*** exploreshaifali has joined #openstack-keystone06:15
lhchengstevemar_: posted a question on the patch, let me know if that makes sense06:15
*** chlong has quit IRC06:15
stevemar_lhcheng: eeeee yaaaa06:19
stevemar_lhcheng: i'll post a follow up patch to change those :P06:20
lhchengstevemar_: cool06:21
*** ParsectiX has joined #openstack-keystone06:22
openstackgerritSteve Martinelli proposed openstack/keystone: fix deprecation warnings in cache backends  https://review.openstack.org/23574806:24
stevemar_lhcheng: ^06:24
stevemar_i wanted to squeeze that one in over night, instead of waiting around for reviews on a friday06:25
stevemar_but good catch!06:25
lhchengstevemar_: doing one more pass, checking again06:25
stevemar_lhcheng: ty sir!06:26
*** dims_ has joined #openstack-keystone06:26
*** dims_ has quit IRC06:28
*** tobe has quit IRC06:28
stevemar_lhcheng: fwiw, this one is "interesting" https://review.openstack.org/#/c/235747/06:28
lhchengoh yeah, I saw that popped up06:29
lhchengcurious to see the generated output06:29
stevemar_though it's easier to see the generated docs06:29
stevemar_yeah06:29
stevemar_it's not the best06:29
stevemar_but i'm surprised that it worked06:29
lhchengit only generate the docs that has the entry point?06:30
bretono/06:30
stevemar_lhcheng: yep, you can put nonsense as the entrypoint, and if it doesn't find it, nada06:35
stevemar_lhcheng: bed time for me06:35
*** spandhe has quit IRC06:35
stevemar_see you all in a few hours!06:35
*** stevemar_ has quit IRC06:35
lhchengstevemar_: alright, just finishing up the last pass06:35
*** stevemar_ has joined #openstack-keystone06:36
*** ChanServ sets mode: +o stevemar_06:36
lhchengstevemar_: good night06:36
*** EinstCrazy has quit IRC06:37
davechensweat dream! lhcheng, stevemar_06:37
*** spandhe has joined #openstack-keystone06:37
*** EinstCrazy has joined #openstack-keystone06:38
*** stevemar_ has quit IRC06:38
*** tobe has joined #openstack-keystone06:39
*** tyagiprince2010 has joined #openstack-keystone06:42
*** gildub has quit IRC06:48
*** spandhe has quit IRC06:54
*** mylu has joined #openstack-keystone06:56
*** mylu has quit IRC07:01
*** tobe has quit IRC07:01
*** EinstCra_ has joined #openstack-keystone07:04
*** EinstCrazy has quit IRC07:05
*** EinstCrazy has joined #openstack-keystone07:05
*** EinstCr__ has joined #openstack-keystone07:06
*** EinstCra_ has quit IRC07:07
*** EinstCrazy has quit IRC07:10
*** tobe has joined #openstack-keystone07:18
*** lsmola_ has joined #openstack-keystone07:21
*** exploreshaifali has quit IRC07:21
*** e0ne has joined #openstack-keystone07:27
*** dims_ has joined #openstack-keystone07:28
*** browne1 has quit IRC07:30
*** dims_ has quit IRC07:33
*** ParsectiX has quit IRC07:39
*** EinstCrazy has joined #openstack-keystone07:46
*** jvarlamova has quit IRC07:48
*** EinstCr__ has quit IRC07:48
*** fhubik has joined #openstack-keystone07:51
*** e0ne has quit IRC07:54
*** pnavarro|off has joined #openstack-keystone07:56
*** belmoreira has joined #openstack-keystone07:56
*** mylu has joined #openstack-keystone07:57
*** ParsectiX has joined #openstack-keystone07:59
*** mylu has quit IRC08:01
*** jaosorior has joined #openstack-keystone08:04
*** tyagiprince2010 has quit IRC08:06
*** ParsectiX has quit IRC08:07
*** jaosorior has quit IRC08:10
*** jbell8 has quit IRC08:13
*** jbell8 has joined #openstack-keystone08:14
*** jistr has joined #openstack-keystone08:24
*** ParsectiX has joined #openstack-keystone08:28
*** dims_ has joined #openstack-keystone08:29
*** dims_ has quit IRC08:35
openstackgerritDave Chen proposed openstack/keystone: Move endpoint filter into keystone core  https://review.openstack.org/18337708:39
*** e0ne has joined #openstack-keystone08:39
*** ParsectiX has quit IRC08:45
*** hidekazu has left #openstack-keystone08:56
*** lhcheng has quit IRC08:58
*** f13o has joined #openstack-keystone09:05
openstackgerritDave Chen proposed openstack/keystone: Move endpoint_filter migrations into keystone core  https://review.openstack.org/18698809:07
*** florianf|away is now known as florianf09:09
*** ParsectiX has joined #openstack-keystone09:12
*** tyagiprince2010 has joined #openstack-keystone09:14
*** hightall has quit IRC09:29
*** dims_ has joined #openstack-keystone09:31
*** dims_ has quit IRC09:37
*** aix has joined #openstack-keystone09:42
*** dims_ has joined #openstack-keystone09:48
*** davechen has left #openstack-keystone09:50
*** jaosorior has joined #openstack-keystone09:56
*** mylu has joined #openstack-keystone09:58
*** jaosorior has quit IRC10:01
*** mylu has quit IRC10:02
*** fhubik has quit IRC10:13
openstackgerritMerged openstack/keystone: switch to oslo.cache  https://review.openstack.org/19587310:13
*** bradjones|away is now known as bradjones10:15
*** exploreshaifali has joined #openstack-keystone10:16
*** pnavarro|off has quit IRC10:18
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23560810:19
*** pnavarro|off has joined #openstack-keystone10:29
*** pnavarro|off has quit IRC10:32
*** tyagiprince2010 has quit IRC10:34
dstanekbug day is here!10:37
*** EinstCrazy has quit IRC10:49
*** wwwjfy has quit IRC10:52
*** njohnston is now known as nate_gone10:54
*** lsmola_ has quit IRC11:02
*** jaosorior has joined #openstack-keystone11:10
*** fhubik has joined #openstack-keystone11:19
*** jaosorior has quit IRC11:25
*** stevemar_ has joined #openstack-keystone11:52
*** ChanServ sets mode: +o stevemar_11:53
*** wwwjfy has joined #openstack-keystone11:54
*** EinstCrazy has joined #openstack-keystone11:55
*** stevemar_ has quit IRC11:55
*** kiranr has joined #openstack-keystone12:02
ayoungdstanek, good, put a +1 on this: https://review.openstack.org/#/c/233480/12:10
*** jaosorior has joined #openstack-keystone12:10
*** alejandrito has joined #openstack-keystone12:13
*** exploreshaifali has quit IRC12:15
*** jaosorior has quit IRC12:20
dstanekayoung: oh, good. an easy one :-)12:22
ayoungdstanek, the corner the Nova folks have painted us in to is nice and tight.12:23
ayoungdstanek so effectively what he is saying is that in order to be able to set a quota on a project, you get the ability to do any other admin action that is unscoped, like add a hypervisor12:23
*** raildo-afk is now known as raildo12:25
*** gordc has joined #openstack-keystone12:28
bretonwhy are all patches in merge conflict?12:31
bretonthe whole front page is in merge conflicts.12:31
dstanekbreton: the ones i am looking at are not in merge conflict12:32
*** ajaya has joined #openstack-keystone12:34
bretondstanek: you've filtered them by Verified+1, haven't you?12:36
dstanekbreton: not that i know of12:37
dstanekordered by 'updated' though12:37
*** ayoung has quit IRC12:38
*** jbell8 has quit IRC12:41
*** jaosorior has joined #openstack-keystone12:42
*** kiran-r has joined #openstack-keystone12:43
bretonhttps://bugs.launchpad.net/keystone/+bug/1506594 -- should we implement the trimming in keystone? Or in ksc? Or mark as invalid?12:44
openstackLaunchpad bug 1506594 in Keystone "Keystone endpoint can not resolve DNS" [Undecided,New]12:44
openstackgerritMerged openstack/keystone: Correct typo in copyright  https://review.openstack.org/23252812:45
openstackgerritMerged openstack/keystone: Enable subprocess_without_shell_equals_true Bandit test  https://review.openstack.org/22569212:46
*** amakarov_away is now known as amakarov12:46
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23560812:47
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23560812:48
*** chlong has joined #openstack-keystone12:48
bretondstanek:12:49
*** kiran-r has quit IRC12:50
*** tobe has quit IRC12:50
dstanekbreton: ?12:51
bretonwhat do you think about bug 1506594?12:51
openstackbug 1506594 in Keystone "Keystone endpoint can not resolve DNS" [Undecided,New] https://launchpad.net/bugs/150659412:51
breton> should we implement the trimming in keystone? Or in ksc? Or mark as invalid?12:52
*** dikonoor has quit IRC12:53
*** thiagop has joined #openstack-keystone12:53
dstanekbreton: just commented on the bug. i don't think we should automatically strip anything12:57
dstaneki think a small amount of validation may be good though12:57
dstaneklbragstad: thoughts? ^12:57
raildo#BugDay \o/12:58
*** ayoung has joined #openstack-keystone12:59
*** ChanServ sets mode: +v ayoung12:59
tjcocozz\o/13:00
ayoungdstanek, http://venturebeat.com/2015/10/15/source-red-hat-is-buying-ansible-for-more-than-100m/13:00
dstanekayoung: yeah, i saw that this morning. maybe you guys can fix their broken13:00
*** davechen has joined #openstack-keystone13:01
dstanekraildo: grab a bug!13:01
ayoungdstanek, maybe this means we can get Puppet out of our installer.13:01
raildodstanek: I will! Do you have any recommendation sir?13:01
davechendstanek: here is a bug - https://bugs.launchpad.net/keystone/+bug/1429576 :)13:03
openstackLaunchpad bug 1429576 in Keystone "region field in 'new_endpoint_ref' is never effective." [Low,In progress] - Assigned to Dave Chen (wei-d-chen)13:03
dstanekraildo: not in particular. i would say pick one that you can make some progress on today13:03
davechendstanek: i think we need relax the validation to allow the empty request body.13:03
raildodstanek: ok13:04
davechendstanek: I didn't aware that region is allowed to be created with empty request body13:05
davechendstanek: what do you think? sir13:05
openstackgerritBoris Bobrov proposed openstack/keystone: Forbid non-stripped endpoint urls  https://review.openstack.org/23590613:05
*** ayoung has quit IRC13:05
breton^13:05
davechendstanek: sorry, i posed the wrong link13:06
davechendstanek: here it is - https://bugs.launchpad.net/keystone/+bug/150174013:06
openstackLaunchpad bug 1501740 in Keystone "Creating a region without request parameters failed." [Medium,Confirmed] - Assigned to Dave Chen (wei-d-chen)13:06
*** wwwjfy has quit IRC13:07
*** wwwjfy has joined #openstack-keystone13:08
dstanekdavechen: good question, i'll take a look in a second13:08
*** ayoung has joined #openstack-keystone13:09
*** ChanServ sets mode: +v ayoung13:09
*** jlk has quit IRC13:09
davechendstanek: thanks!13:09
openstackgerritHenrique Truta proposed openstack/keystone: Tests for projects acting as domains  https://review.openstack.org/21121913:10
openstackgerritHenrique Truta proposed openstack/keystone: Projects acting as domains  https://review.openstack.org/23128913:10
openstackgerritHenrique Truta proposed openstack/keystone: Removes project.domain_id FK  https://review.openstack.org/23327413:10
ayounghtruta, deal with these if you want https://review.openstack.org/#/c/212819/1/keystoneclient/common/cms.py13:10
*** jlk has joined #openstack-keystone13:11
*** jlk has quit IRC13:11
*** jlk has joined #openstack-keystone13:11
htrutaayoung: I can see it later... I'm going with this one for now: https://review.openstack.org/#/c/134095/313:11
dstanekdavechen: replied on the bug. does that make sense?13:13
davechendstanek: good idea, this looks like a better approach.13:15
*** su_zhang has joined #openstack-keystone13:20
*** richm has joined #openstack-keystone13:20
lbragstaddstanek reading back13:21
davechendstanek: may not finish this in the bug squashing day, but will fix it ASAP.13:21
*** nate_gone is now known as njohnston13:22
dstanekdavechen: np13:22
dstaneklbragstad: just the validation stuff13:22
lbragstaddstanek breton interesting...13:22
lbragstadis that *always* the case with whitespace in a url?13:23
bretonlbragstad: I've proposed a fix https://review.openstack.org/23590613:23
*** ajaya has quit IRC13:23
lbragstadbreton awesome... reveiewing13:23
bretonI wonder whether we need a migration for it.13:23
bretonnah, we don't need. If anybody has such urls in his db, their openstack is broken.13:25
lbragstadbreton well, if a deployment previously had whitespace in their urls everything would break13:25
lbragstadbreton your change just makes getting to the broken place a little harder13:25
*** richm has quit IRC13:27
htrutadstanek: for this case https://review.openstack.org/#/c/134095/3/keystone/tests/unit/test_v3_catalog.py does an exception.Conflict seem correct to you?13:28
bretonif a deployment previously had whitespace in their urls they would not even start working13:29
dstaneklbragstad: yes, i'm pretty sure that's always the case13:29
*** fhubik is now known as fhubik_brb13:29
lbragstadbreton ++, i think that looks good13:30
dstanekhtruta: i don't think so because i think a conflict is something specific, but let me take a look ...13:30
*** richm has joined #openstack-keystone13:31
*** davechen has quit IRC13:31
*** jaosorior has quit IRC13:32
dstanekhtruta: yeah, i don't think conflict is correct.13:33
raildohtruta: it's a DbduplicateEntry13:34
raildoi guess...13:34
htrutadstanek: I thought so, because of this one: https://github.com/openstack/keystone/blob/master/keystone/tests/unit/test_backend.py#L80213:34
dstanekhtruta: hmm...yeah, i think that's incorrect and should probably be a validation error13:35
dstanekbut who knows maybe that's an openstack thing13:36
htrutadstanek, raildo: yep... the sql backend raises oslo_db.exception.DBDuplicateEntry, which seems to be a 500 error13:36
dstanekhmm.. maybe dolphm, bknudson or morgan have something to say about that? (our use of 409)13:37
dstanektechnically i think it's ok, but seems odd to me13:37
htrutadstanek: for me too. I thought of catching this exception and raising a ValidationError13:38
dstanekhtruta: we should get some input here first13:38
bknudsonvalidationerror means the client did something wrong on this request13:38
*** jsavak has joined #openstack-keystone13:38
htrutadstanek: ++13:38
bretonwhat do you think about bug 1503755 ? It has some comments from lbragstad and dolphm, but is still [undecided,new]13:39
openstackbug 1503755 in Keystone "Admin with project-scoped token unable to grant, check, list, revoke roles for domain group/user" [Undecided,New] https://launchpad.net/bugs/150375513:39
bretonI'd say it's invalid13:39
htrutabknudson: so, when a unique constraint fails, it seems like the client has done something wrong. validationerror, right?13:39
ayounginvalid13:40
ayoungproject scoped tokens are not domain scoped tokens13:40
bknudsonhtruta: a 400 error is the correct response there13:40
lbragstadbreton yeah, i guess given dolphm's comment it would be invalid13:40
bknudsonI'm not going to say it's a validationerror, the exception should be specific to the problem.13:40
*** fhubik_brb is now known as fhubik13:42
*** edmondsw has joined #openstack-keystone13:47
bretoncould someone mark bug 1489260 as won't fix? It was discussed there why.13:50
openstackbug 1489260 in Keystone "trust details unavailable for admin token" [Medium,Triaged] https://launchpad.net/bugs/148926013:50
htrutabknudson: thx13:50
htrutadstanek: so, I guess I'll treat the exception and raise a validationerror13:51
dstanekhtruta: sounds good to me13:51
bknudsondstanek: is there an etherpad for the office hours tracking?13:51
bknudsonnever mind, found it: https://etherpad.openstack.org/p/keystone-office-hours13:52
bretonhttps://etherpad.openstack.org/p/keystone-office-hours13:52
*** njohnston is now known as nate_gone13:53
*** pumaranikar has joined #openstack-keystone13:55
*** davechen1 has joined #openstack-keystone14:04
*** nzeer has left #openstack-keystone14:06
*** ParsectiX has quit IRC14:06
*** jsavak has quit IRC14:06
*** jsavak has joined #openstack-keystone14:07
* breton shrugs14:07
bretonwhat else to fix?14:07
davechen1Anyone interesting in reviewing two pure doc changes in ksm? - https://review.openstack.org/#/c/219162/ and https://review.openstack.org/#/c/220545/14:09
lbragstadis anyone familiar with the parent_as_list/parent_as_ids calls?14:09
davechen1both of them are trying to close the bug tracked in the lp.14:09
lbragstadsame with the subtree_as_list/subtree_as_ids calls14:10
lbragstadhtruta samueldmq ^14:10
bretonI marked bug 1480334 as invalid and then thought that maybe it should be marked some other way. Maybe keystone should be removed from the list of affected projects at all?14:10
openstackbug 1480334 in oslo.config "can't use "$" in password for ldap authentication" [Undecided,Won't fix] https://launchpad.net/bugs/148033414:10
htrutalbragstad: I guess I can say I am14:10
htrutame and raildo14:10
lbragstadhtruta awesome, quick question for you14:10
lbragstadhtruta I was able to recreate this, Tim and I didn't do anything wrong did we? https://bugs.launchpad.net/keystone/+bug/150665314:11
openstackLaunchpad bug 1506653 in Keystone "Retrieving either a project's parents or subtree as_list does not work" [High,Confirmed]14:11
dstanekbreton: there are lots of things to fix :-)14:11
htrutalbragstad: looking14:12
*** kiranr has quit IRC14:12
bretondstanek: suggest one?14:12
dstanekbreton: i say pick ones that interest you.14:12
*** sigmavirus24_awa is now known as sigmavirus2414:13
htrutalbragstad: which role did your user have on project 3?14:14
raildolbragstad: to return the projects in subtree_as_list you must need have role assignments in the subprojects14:14
lbragstadhtruta i did all of this with the admin user14:14
raildoor use inherited roles...14:14
lbragstadhmm14:15
htrutathe same that raildo said applies to parents_as_list14:15
raildoyeap14:15
lbragstadis subtree_as_list suppose to have the same response as subtree_as_ids?14:15
htrutalbragstad: in which case?14:16
raildolbragstad: if you have role in every subproject, yes14:16
bretonmany bugs have fixes, but little reviews14:16
breton*but with little reviews14:16
htrutabreton: an easy review for you... https://review.openstack.org/#/c/207218/ bknudson has already reviewed14:17
lbragstadhtruta, as an admin, i can get the ids of the parents of the tree - http://cdn.pasteraw.com/abdd3la2924agvsl1ihbqmn6yxhhw6v14:17
lbragstadhtruta as an admin, but i'm unable to get the same information using the parents_as_list - http://cdn.pasteraw.com/ajjc1owd5efcr6xwtsdbj7nqcq6cw6e14:17
lbragstadwhat i mean, is technically, it's the same information, right?14:17
htrutalbragstad: you shouldn't see this, because parents_as_list has much more information than parents_as_ids14:18
openstackgerritMerged openstack/keystonemiddleware: Updated from global requirements  https://review.openstack.org/23543614:18
bretonhtruta: > Restricts the update of a domain_id for a project, (even with the14:18
breton'domain_id_immutable' property set to False), allowing it only for14:18
bretonroot projects that have no children of its own14:18
bretonwhy allow update of domain id?14:18
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements  https://review.openstack.org/23564614:18
lbragstadhtruta but i can still see the ids of those projects with project_as_ids14:19
bretonwhy can't we have it immutable for all projects?14:19
htrutabreton: we allow it today in every way. We are restricting and deprecating it. It takes 2 cycles for it :/14:19
lbragstadhtruta just trying to understand why ids aren't important from a security perspective14:19
lbragstadin this particular case14:19
raildolbragstad: subtree_as_ids returns a dict of ids for every project in the hierarchy (even if you not have a role assignment in the projects)14:19
raildolbragstad: subtree_as_list returns a list of projects that you have role assignments14:20
lbragstadraildo yeah, that makes sense14:20
dstanekbreton: i'm trying to target reviews that have bugs listed :-) we need to make progress from all ends14:20
bretonhtruta: 2 cycles or 1? The patch says 114:21
lbragstadraildo i get that subtree_as_list returns more information14:21
*** petertr7 is now known as petertr7_away14:21
htrutabreton: 1, sorry. 1 full cycle deprecated14:21
*** nate_gone is now known as njohnston14:21
htrutalbragstad: I'm trying to find the discussion of this14:21
lbragstadhtruta cool, is it captured in the review?14:21
*** davechen1 has left #openstack-keystone14:21
lbragstadhtruta or in a review?14:21
raildolbragstad:  we have some explanation about this two behaviours here: https://github.com/openstack/keystone-specs/blob/master/api/v3/identity-api-v3.rst#get-project14:23
*** su_zhang has quit IRC14:23
raildolbragstad: So I think that bug is invalid14:23
bknudsonif you've got bug fixes you'd like reviewed, put them in https://etherpad.openstack.org/p/keystone-office-hours so they're easy to find.14:23
lbragstadraildo reading14:23
*** su_zhang has joined #openstack-keystone14:24
bknudsonalso it will allow us to track what got done during the office hours14:24
raildolbragstad: or maybe, we can explain better in the docs :)14:25
lbragstadraildo yeah, i think the bug is invalid, but i think we could improve the docs14:25
lbragstadraildo ++14:25
lbragstadraildo the docs don't say anything about a behavioral different around role assignments14:25
raildolbragstad: ok, I'll do that today :)14:25
*** ayoung has quit IRC14:25
raildoagreed14:26
lbragstadraildo perfect! if you want to propose it as "Related-Bug: 1506653"14:26
openstackbug 1506653 in Keystone "Retrieving either a project's parents or subtree as_list does not work" [High,Confirmed] https://launchpad.net/bugs/150665314:26
lbragstadraildo I'm going to leave some comments on the bug and explain that a new patch is on the way14:26
raildolbragstad: ++14:26
lbragstadraildo htruta  thanks for the context/explanation!14:26
raildolbragstad: no problem :)14:27
*** petertr7_away is now known as petertr714:27
dstanekalso for bugs that already have reviews you could go ahead and review them!14:27
htrutalbragstad, raildo, ok14:28
*** rderose has joined #openstack-keystone14:28
*** tonytan4ever has joined #openstack-keystone14:31
*** e0ne has quit IRC14:31
*** r-daneel has joined #openstack-keystone14:32
*** zz_john5223 is now known as john522314:33
*** phalmos has joined #openstack-keystone14:35
*** fhubik has quit IRC14:36
*** jsavak has quit IRC14:37
*** jistr has quit IRC14:37
*** jsavak has joined #openstack-keystone14:38
*** slberger has joined #openstack-keystone14:39
*** phalmos has quit IRC14:39
*** jistr has joined #openstack-keystone14:41
*** hightall has joined #openstack-keystone14:45
openstackgerritBrant Knudson proposed openstack/keystone: AuthContextMiddleware admin token handling  https://review.openstack.org/19893114:49
*** lbragstad has quit IRC14:51
*** lbragstad has joined #openstack-keystone14:51
*** e0ne has joined #openstack-keystone14:53
*** ajaya has joined #openstack-keystone14:56
slbergerIf token caching is enabled, are fernet tokens cached in anyway?  like their validation14:56
dolphmslberger: good question -- i actually don't think so, but let me check14:57
bknudsonthe auth_token middleware treats fernet tokens same as uuid tokens14:57
bknudsonit doesn't have any code to identity fernet tokens14:57
dolphmoh yeah, they're definitely cached in middleware14:58
dolphmi was thinking in keystone14:58
dolphmthere are definitely MEMOIZE wrappers here: https://github.com/openstack/keystone/blob/master/keystone/token/provider.py#L247-L26514:58
bknudsonis there token caching in keystone?14:58
bknudsonah, well that's not token format specific either14:59
dolphmbknudson: on requests with X-Auth-Token?14:59
bknudsondolphm: hopefully the same code is called for X-Auth-Token and X-Subject-Token.15:00
bknudsonmaybe that's too much to hope for.15:01
dolphmbknudson: lol it should be. those two are the only path into the token providers for validation IIRC15:01
*** rderose has quit IRC15:02
*** su_zhang has quit IRC15:06
*** chlong has quit IRC15:09
*** weihan has joined #openstack-keystone15:09
*** su_zhang has joined #openstack-keystone15:09
*** diazjf has joined #openstack-keystone15:11
*** david-ly_ has joined #openstack-keystone15:11
*** david-lyle has quit IRC15:11
openstackgerritLance Bragstad proposed openstack/keystone-specs: Improve get project query strings  https://review.openstack.org/23597115:12
lbragstadit has been agreed that we are going to put things for review in the etherpad, right?15:13
tjcocozzlbragstad, yes but the section wasn't created last time I checked15:14
lbragstadtjcocozz cool, doing that now15:15
tjcocozzlbragstad, thanks15:15
*** jistr is now known as jistr|mtg15:18
bknudsonlbragstad: could you move it to the top so it's easier to track?15:18
*** roxanaghe has joined #openstack-keystone15:18
bknudsonI don't care about the rest of the content on the page now15:18
lbragstadbknudson absolutely15:18
*** stevemar_ has joined #openstack-keystone15:18
*** ChanServ sets mode: +o stevemar_15:18
*** stevemar_ has quit IRC15:19
*** ayoung has joined #openstack-keystone15:19
*** ChanServ sets mode: +v ayoung15:19
*** stevemar_ has joined #openstack-keystone15:19
*** ChanServ sets mode: +o stevemar_15:19
*** urulama has quit IRC15:19
*** josecastroleon has quit IRC15:20
*** urulama has joined #openstack-keystone15:20
*** roxanaghe has quit IRC15:22
*** john5223 is now known as zz_john522315:24
*** timcline has joined #openstack-keystone15:25
*** jbell8 has joined #openstack-keystone15:26
*** jbell8 has quit IRC15:28
*** jlk has quit IRC15:30
openstackgerritTom Cocozzello proposed openstack/keystonemiddleware: Configure filter factories for PasteDeploy  https://review.openstack.org/23383915:31
openstackgerritMerged openstack/keystone: fix deprecation warnings in cache backends  https://review.openstack.org/23574815:31
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23560815:33
*** e0ne has quit IRC15:37
bknudson#success keystone switched to oslo.cache15:37
openstackstatusbknudson: Added success to Success page15:37
stevemar_bknudson: \o/15:37
*** diazjf has quit IRC15:37
lbragstadstevemar_ bknudson speaking of that, i just started rebasing https://review.openstack.org/#/c/215212/ :)15:37
lbragstadand i actually have a question15:38
bknudsonhopefully it's minimal? just change section to group15:38
*** diazjf has joined #openstack-keystone15:38
*** e0ne has joined #openstack-keystone15:38
bknudsonoh, you've got your own region15:38
lbragstadour keytone.common.cache module has a configure_cache method now15:38
*** _cjones_ has quit IRC15:39
lbragstadso, do we move stuff like https://review.openstack.org/#/c/215212/13/keystone/server/backends.py to keystone.common.cache.core.py?15:39
*** jistr|mtg has quit IRC15:39
bknudsonsince we've got 2 of them now it's probably best to move it into keystone.common.cache15:40
*** jistr has joined #openstack-keystone15:40
lbragstadbknudson ok, so cache.configure_cache_region(catalog.COMPUTED_CATALOG_REGION) will always be handled by our keystone.common.cache15:40
bknudsonif it's only used in keystone.catalog.core then put it in there.15:41
*** jbell8 has joined #openstack-keystone15:42
*** browne has joined #openstack-keystone15:45
openstackgerritSteve Martinelli proposed openstack/keystone: Move endpoint_policy migrations into keystone core  https://review.openstack.org/17191615:46
openstackgerritSteve Martinelli proposed openstack/keystone: Move federation extension into keystone core  https://review.openstack.org/21477515:47
openstackgerritSteve Martinelli proposed openstack/keystone: Move federation sql migrations to common  https://review.openstack.org/23453715:47
openstackgerritBrant Knudson proposed openstack/keystone: Update test modules passing on py34  https://review.openstack.org/23163515:48
openstackgerritBrant Knudson proposed openstack/keystone: Handle fernet payload timestamp differences  https://review.openstack.org/23271115:48
openstackgerritBrant Knudson proposed openstack/keystone: Fix fernet key writing for python 3  https://review.openstack.org/23171015:48
openstackgerritBrant Knudson proposed openstack/keystone: Fix fernet padding for python 3  https://review.openstack.org/23171115:48
openstackgerritSteve Martinelli proposed openstack/keystone: Move oauth1 extension into core  https://review.openstack.org/23459815:48
openstackgerritSteve Martinelli proposed openstack/keystone: Move oauth1 sql migrations to common  https://review.openstack.org/23512115:48
openstackgerritSteve Martinelli proposed openstack/keystone: Move revoke extension into core  https://review.openstack.org/23570415:49
lbragstadwhat about the make_region() stuff here - https://review.openstack.org/#/c/215212/13/keystone/catalog/core.py ?15:49
openstackgerritSteve Martinelli proposed openstack/keystone: Move revoke sql migrations to common  https://review.openstack.org/23571215:49
lbragstadbknudson ^15:49
openstackgerritSteve Martinelli proposed openstack/keystone: Move endpoint filter into keystone core  https://review.openstack.org/18337715:49
bknudsonlbragstad: sure, if the region is only used in keystone.catalog.core, do it there.15:50
lbragstadbknudson ok15:50
stevemar_yay no more merge conflicts15:50
stevemar_!!15:50
openstackstevemar_: Error: "!" is not a valid command.15:50
stevemar_screw you openstack bot15:50
stevemar_i'll tell you what's an error or not15:50
bknudsongetting closer getting test_fernet_provider passing on py3 with the change to oslo.cache.15:51
lbragstadawesome15:51
stevemar_bknudson: i'm glad oslo.cache is in :)15:52
stevemar_-2000 lines is good15:52
bknudsonwe should have a real chance at python3 support in M.15:52
dstanekbreton: this one is ayoung's and i think that all is needed is some tests https://bugs.launchpad.net/keystone/+bug/124016315:53
openstackLaunchpad bug 1240163 in python-keystoneclient "Can't store a PKI token with a large catalog" [Medium,In progress] - Assigned to Adam Young (ayoung)15:53
ayoungdstanek, yep.  Please!15:53
dstanekhaneef__: yt?15:54
slbergerMore caching questions, So looking at the default config everything is cached by default when global caching is enabled?  so if I want to cache something like tokens or revocations they are already taken care of when I enable global caching?15:55
stevemar_when i get back, i'll be squashing bugs!15:55
*** su_zhang has quit IRC15:56
*** diazjf has quit IRC15:57
*** hightall has quit IRC15:57
*** topol has quit IRC15:58
*** e0ne has quit IRC15:59
* tjcocozz squashes bugs like she squashes grapes http://i.imgur.com/XVP8bYS.gif16:00
*** e0ne has joined #openstack-keystone16:00
*** diazjf has joined #openstack-keystone16:02
lbragstad#fail16:02
dstaneklbragstad: i don't think they setup a failbot yet16:03
*** gyee has joined #openstack-keystone16:03
*** ChanServ sets mode: +v gyee16:03
lbragstaddstanek we should get on that16:03
*** mylu has joined #openstack-keystone16:04
*** _cjones_ has joined #openstack-keystone16:04
morganslberger: yes. Caching is on for each subsystem when you turn global caching on. You can turn token caching for example, explicitly off if you want.16:04
morganstevemar_: good luck bug squashing ;)16:05
*** stevemar_ has quit IRC16:10
*** belmoreira has quit IRC16:11
*** stevemar_ has joined #openstack-keystone16:11
*** ChanServ sets mode: +o stevemar_16:11
*** ayoung has quit IRC16:14
*** stevemar_ has quit IRC16:16
*** roxanaghe has joined #openstack-keystone16:18
*** roxanaghe has quit IRC16:19
*** lhcheng has joined #openstack-keystone16:19
*** ChanServ sets mode: +v lhcheng16:19
*** roxanaghe has joined #openstack-keystone16:19
*** e0ne has quit IRC16:22
*** rvba has quit IRC16:25
*** urulama has quit IRC16:25
*** urulama has joined #openstack-keystone16:25
*** bradjones has quit IRC16:26
*** tonytan4ever has quit IRC16:30
*** jistr has quit IRC16:33
*** spandhe has joined #openstack-keystone16:36
*** roxanaghe has quit IRC16:37
*** spandhe_ has joined #openstack-keystone16:37
*** jaosorior has joined #openstack-keystone16:37
*** jaosorior has quit IRC16:37
*** jaosorior has joined #openstack-keystone16:37
*** roxanaghe has joined #openstack-keystone16:38
*** wwwjfy has quit IRC16:39
*** weihan has quit IRC16:39
*** spandhe has quit IRC16:40
*** spandhe_ is now known as spandhe16:40
*** jaosorior has quit IRC16:40
*** jaosorior has joined #openstack-keystone16:41
*** weihan has joined #openstack-keystone16:43
*** diazjf has quit IRC16:43
*** mylu has quit IRC16:44
*** phalmos has joined #openstack-keystone16:46
*** browne has quit IRC16:46
*** weihan has quit IRC16:48
*** weihan has joined #openstack-keystone16:48
*** diazjf has joined #openstack-keystone16:48
*** spandhe has quit IRC16:49
*** diazjf has quit IRC16:51
dstanektjcocozz: let me know if that comment makes sense16:52
*** roxanaghe has quit IRC16:52
*** diazjf has joined #openstack-keystone16:53
openstackgerritHenrique Truta proposed openstack/keystone: Constraint to prevent duplicates endpoints  https://review.openstack.org/13409516:53
dstanektjcocozz: https://pythonhosted.org/setuptools/setuptools.html#dynamic-discovery-of-services-and-plugins16:53
*** dims_ has quit IRC16:54
*** dims_ has joined #openstack-keystone16:55
*** diazjf has quit IRC16:56
*** weihan has quit IRC16:56
*** phalmos has quit IRC16:57
openstackgerritLance Bragstad proposed openstack/keystone-specs: Improve get project query strings  https://review.openstack.org/23597116:59
*** roxanaghe has joined #openstack-keystone16:59
*** roxanaghe has quit IRC16:59
htrutabreton: about your comment here: https://review.openstack.org/#/c/207218/21/keystone/identity/core.py17:00
openstackgerritLance Bragstad proposed openstack/keystone: Add caching to get_catalog  https://review.openstack.org/21521217:00
htrutathe method you've suggested to put the check has a not from henrynash: https://github.com/openstack/keystone/blob/master/keystone/common/controller.py#L68417:00
htrutaI think it's better if we don't touch it, right?17:00
*** jsavak has quit IRC17:02
*** jsavak has joined #openstack-keystone17:03
*** jaosorior has quit IRC17:09
dstanekany reason not to close this one? https://bugs.launchpad.net/keystone/+bug/149049717:10
openstackLaunchpad bug 1490497 in Keystone "pep8-incompliant filenames missing in gate console logs" [Undecided,Incomplete]17:10
*** stevemar_ has joined #openstack-keystone17:10
*** ChanServ sets mode: +o stevemar_17:10
bknudsondstanek: I've never seen that error.17:12
openstackgerritDolph Mathews proposed openstack/keystone: Test revocation race conditions  https://review.openstack.org/22799517:12
dstanekbknudson: me either. i think it is a random infa thing17:12
bknudsonwe don't need the gate to tell us what files are involved pep8 fails. run it on your local system.17:12
*** jasonsb has joined #openstack-keystone17:13
openstackgerritDolph Mathews proposed openstack/keystone: Fix D208: Docstring over indented. (PEP257)  https://review.openstack.org/22983717:13
openstackgerritDolph Mathews proposed openstack/keystone: Fix D402: First line should not be the function's "signature" (PEP257)  https://review.openstack.org/22983917:13
openstackgerritDolph Mathews proposed openstack/keystone: Fix D300: Use """triple double quotes""" (PEP257)  https://review.openstack.org/22985317:14
openstackgerritDolph Mathews proposed openstack/keystone: Fix D210: No whitespaces allowed surrounding docstring text (PEP257)  https://review.openstack.org/22985717:14
openstackgerritDolph Mathews proposed openstack/keystone: Fix D200: 1 line docstrings should fit with quotes (PEP257)  https://review.openstack.org/22986517:14
openstackgerritDolph Mathews proposed openstack/keystone: Fix D202: No blank lines after function docstring (PEP257)  https://review.openstack.org/22988717:14
openstackgerritDolph Mathews proposed openstack/keystone: Fix D204: blank line required after class docstring (PEP257)  https://review.openstack.org/22989817:14
openstackgerritDolph Mathews proposed openstack/keystone: Promote an arbitrary string to be a docstring  https://review.openstack.org/22991617:14
stevemar_dstanek: o/17:16
stevemar_dstanek: hows the squishing going?17:16
dstanekstevemar_: yo17:16
lbragstaddstanek do we know what the bug count was at when we started today?17:17
dstanekstevemar_: overall number of bugs is slightly down and we have several things in the gate (hopefully tied to bugs)17:17
stevemar_dstanek: nice17:17
stevemar_i'm gonna take a crack at it in a few minutes17:18
*** phalmos has joined #openstack-keystone17:18
openstackgerritHenrique Truta proposed openstack/keystone: Restricting domain_id update  https://review.openstack.org/20721817:18
dstaneklbragstad: yes, i have a report here; it was something like 311 total and now down to 30717:19
lbragstadAwesome!17:19
dstanekafter lunch i can get more deets17:19
openstackgerritMerged openstack/keystone: Forbid non-stripped endpoint urls  https://review.openstack.org/23590617:19
lbragstaddstanek sounds like a plan17:20
openstackgerritDolph Mathews proposed openstack/keystone: Promote an arbitrary string to be a docstring  https://review.openstack.org/22991617:21
openstackgerritDolph Mathews proposed openstack/keystone: Add docstring validation  https://review.openstack.org/22968917:21
openstackgerritDolph Mathews proposed openstack/keystone: Fix D204: blank line required after class docstring (PEP257)  https://review.openstack.org/22989817:21
openstackgerritDolph Mathews proposed openstack/keystone: Fix D210: No whitespaces allowed surrounding docstring text (PEP257)  https://review.openstack.org/22985717:21
openstackgerritDolph Mathews proposed openstack/keystone: Fix D202: No blank lines after function docstring (PEP257)  https://review.openstack.org/22988717:21
openstackgerritDolph Mathews proposed openstack/keystone: Fix D300: Use """triple double quotes""" (PEP257)  https://review.openstack.org/22985317:21
openstackgerritDolph Mathews proposed openstack/keystone: Fix D208: Docstring over indented. (PEP257)  https://review.openstack.org/22983717:21
openstackgerritDolph Mathews proposed openstack/keystone: Fix D402: First line should not be the function's "signature" (PEP257)  https://review.openstack.org/22983917:21
openstackgerritDolph Mathews proposed openstack/keystone: Fix D200: 1 line docstrings should fit with quotes (PEP257)  https://review.openstack.org/22986517:21
*** petertr7 is now known as petertr7_away17:21
lbragstaddolphm I take it those are ready for review new?17:23
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23560817:23
stevemar_dolphm: did the requirements change merge?17:26
*** su_zhang has joined #openstack-keystone17:27
*** kfox1111 has joined #openstack-keystone17:28
kfox1111question.. http://dolphm.com/benchmarking-openstack-keystone-token-formats/ implies you can have region specific keystone's that validate each other's tokens.17:28
kfox1111is that true or did I misunderstand something?17:28
morgankfox1111: it's totally doable17:29
openstackgerritAlexander Makarov proposed openstack/keystone-specs: Unified delegation spec  https://review.openstack.org/18981617:29
kfox1111cool. does it work with horizon?17:29
*** jsavak has quit IRC17:29
*** jsavak has joined #openstack-keystone17:30
morgankfox1111: uhm... sortof... but you still need to sync the identity backend/etc since the way fernet does the lookups17:30
*** browne has joined #openstack-keystone17:30
kfox1111so, each region gets a keystone server, and you share gallera or something?17:30
morganyah or similar17:31
kfox1111so, its basically one keystone cluster though.17:31
morganyep17:31
kfox1111you wouldn't want to have different domains in different regions?17:31
lhchengkfox1111: horizon should work with fernet, twc is already using it.17:31
kfox1111cool.17:32
morgansure, but if you are building a cloud that meshes like that do you really want different domains?17:32
kfox1111was looking forward to just setup one keystone with ldap, and then federate to each region with a keystone, but horizon's just too far away for that for now.17:32
*** wwwjfy has joined #openstack-keystone17:32
kfox1111morgan: probably not. just trying to figure out whats possible. :)17:32
morganfwiw: ldap replicates better than sql17:33
kfox1111you never know when a subtile trick like that may pay off. :)17:33
morganacross WAN17:33
kfox1111... but I didn't think you could put projects/etc in ldap, just users/groups?17:33
*** su_zhang has quit IRC17:33
morganyou can't17:33
morganwell you *can* but don't it's going away this cycle17:33
kfox1111yeah. thats what I've been telling others.17:34
*** su_zhang has joined #openstack-keystone17:34
kfox1111ok. so, for multi region for now, its best to ldap -> keystone pool (one+ per region for performance) -> shared gallera.17:35
kfox1111+ farnet tokens.17:35
lbragstadkfox1111 that an interesting case, because if you have a global identity backend for all your keystone nodes, but each region has a different resource/catalog backend, then a user can validate a token across region keystone, but they won't be able to validate a project or domain scoped token across regions.17:35
openstackgerritHenrique Truta proposed openstack/keystone: Constraint to prevent duplicates endpoints  https://review.openstack.org/13409517:36
kfox1111I thought the shared mysql whould cover that case?17:36
kfox1111I guess I mean, ldap via the keystone domain plugin, not external authentication.17:37
kfox1111so keystone's basically just a single cluster, with closeish members to the region for quicker validation?17:38
kfox1111oh, but I guess that probably doesn't matter much with farnet tokens?17:38
*** roxanaghe has joined #openstack-keystone17:39
lbragstadkfox1111 yep, if you have a shared backend it covers that case17:39
kfox1111k.17:39
kfox1111are farnet tokens compatible with v2, or alternately, does every openstack service now support v3 exclusively?17:40
*** e0ne has joined #openstack-keystone17:40
kfox1111last I tried, too many services only worked with v2. :/17:40
lbragstadkfox1111 they are compatible with v2.017:40
kfox1111ok. cool.17:40
lbragstadkfox1111 but the rules around domains and v2.0 still apply17:41
kfox1111I'd really like to get to v3 only. :/17:41
kfox1111yeah. I understand.17:41
kfox1111we set the ldap domain to be default for that reason.17:41
lbragstadkfox1111 makes sense17:41
kfox1111all the services that need a domain other then ldap knew enough to speak v3.17:41
kfox1111well, except it woudl be awesome to have all service accounts in a non default domain.17:42
kfox1111but that wasn't supported. :/17:42
kfox1111is the fernet token stuff backward/forwards compatable? kilo + liberty hybrid clouds?17:42
lbragstadkfox1111 we have some back-ports proposed to the stable/branches to make them backword and forward compatible17:44
lbragstadthrough a kilo -> liberty upgrade17:44
kfox1111k. so today it doesn't work though?17:44
kfox1111trying to share a keystone between regions and want to ensure the shared keystone stays stable if we have to upgrade one region, and not another for a while.17:45
kfox1111(different sla's)17:45
lbragstadwithout https://review.openstack.org/#/c/231057/ merging, there is a possibility liberty keystone won't recognize kilo keystone fernet tokens17:45
kfox1111ah.17:46
htrutadolphm: any thoughts on bug 1017606 ?17:46
openstackbug 1017606 in Keystone "Mixing references to 'Tenants' and 'Projects' is confusing" [Medium,Confirmed] https://launchpad.net/bugs/101760617:46
lbragstad^ that patch makes it so that we can validate fernet tokens regardless of padding17:46
kfox1111thanks.17:46
lbragstadkfox1111 np17:46
openstackgerritBrant Knudson proposed openstack/keystone: Allow the PBR_VERSION env to pass through tox  https://review.openstack.org/22440717:46
*** topol has joined #openstack-keystone17:56
*** ChanServ sets mode: +v topol17:56
stevemar_anyone want to review a whole bunch of patches to move extensions? :D17:56
stevemar_https://review.openstack.org/#/q/status:open+project:openstack/keystone+branch:master+topic:bp/replace-extensions,n,z17:56
bknudsonstevemar_: you understand https://review.openstack.org/#/c/234531/ -- can you explain it to me?17:57
amakarovstevemar_, not "a whole" - Jenkins already reviewed half of them, so it's "half of a bunch" ;)17:58
stevemar_amakarov: good point!17:58
stevemar_bknudson: let me find the code in pysaml2, 1 sec17:58
amakarovstevemar_, isn't there a CR to move trusts into the core?17:59
amakarovstevemar_, sorry, that's an old memory - trust isn't in contrib already :)18:01
bknudsonamakarov: trusts aren't part of the core api18:02
*** phalmos has quit IRC18:02
bknudsonhttp://specs.openstack.org/openstack/keystone-specs/api/v3/identity-api-v3-os-trust-ext.html18:03
amakarovbknudson, I'm curious: what are the criteria to consider some API to be "core" and other - not to be?18:05
openstackgerritLance Bragstad proposed openstack/keystone-specs: Improve get project query strings  https://review.openstack.org/23597118:05
bknudsonamakarov: core API are defined in http://specs.openstack.org/openstack/keystone-specs/api/v3/identity-api-v3.html , the rest are not18:05
stevemar_bknudson: ah there we go, the file '/etc/keystone/ssl/certs/signing_cert.pem' isn't generated by default when you perform `keystone-manage ssl_setup`18:05
stevemar_so change it to something that exists by default18:06
bknudsonpeople shouldn't be using that anyways18:06
lbragstadlhcheng updated those docs that you commented on ^18:06
lbragstadlhcheng that was a good question, i had to go test it ut18:06
lbragstadout*18:06
stevemar_amakarov: trusts are enabled by default, and not in contrib18:07
*** phalmos has joined #openstack-keystone18:07
stevemar_they are really part of core keystone, no idea why they were called extensions18:07
lhchenglbragstad: great, thanks!18:07
*** jsavak has quit IRC18:07
*** jsavak has joined #openstack-keystone18:08
*** jasonsb has quit IRC18:09
*** jasonsb has joined #openstack-keystone18:10
*** jasonsb has quit IRC18:10
*** jasonsb has joined #openstack-keystone18:12
*** fhubik has joined #openstack-keystone18:14
*** stevemar_ has quit IRC18:17
*** stevemar_ has joined #openstack-keystone18:18
*** ChanServ sets mode: +o stevemar_18:18
amakarovstevemar_, bknudson thanks, I think I'll file a bp for that at least18:19
bknudsonamakarov: we already have bp replace-extensions18:19
bknudsonamakarov: actually it's move-extensions18:20
amakarovbknudson, just wanted to ask why it's "replace" )18:21
amakarovbknudson, so what about adding trusts there?18:22
*** stevemar_ has quit IRC18:22
bknudsonamakarov: that covers all of the extensions18:22
openstackgerritLance Bragstad proposed openstack/keystone: Add caching to role assignments  https://review.openstack.org/21571518:23
amakarovbknudson, thank you for clarification!18:23
*** stevemar_ has joined #openstack-keystone18:25
*** ChanServ sets mode: +o stevemar_18:25
*** amakarov is now known as amakarov_away18:27
*** su_zhang has quit IRC18:28
*** diazjf has joined #openstack-keystone18:29
*** timcline has quit IRC18:31
*** timcline has joined #openstack-keystone18:32
lbragstaddstanek ping18:34
lbragstaddstanek i have some questions on https://review.openstack.org/#/c/134095/ - but i'm not sure if i'm just thinking about it wrong18:34
openstackgerritHenrique Truta proposed openstack/keystone: Constraint to prevent duplicates endpoints  https://review.openstack.org/13409518:36
lbragstaddstanek let's say you have a compute service with service id c05f46 in some Region18:36
lbragstad^ that change would make it so that you can only have three endpoints for that service in that region, right? You'd have an admin endpoint, a public endpoint and an internal endpoint18:38
htrutalbragstad: yep18:38
lbragstadwhat if i want more endpoints than that?18:38
lbragstadsay i have a lot of endpoints for my compute service18:39
*** su_zhang has joined #openstack-keystone18:39
lbragstadif we made that constraint unique between service_id + region_id + interface + url, it wouldn't be as limiting18:40
morganhm. redhat buying ansible18:40
morgannot really surprised there I guess18:40
htrutalbragstad: how would horizon handle that?18:40
*** dims_ is now known as dimsum__18:41
lbragstadhtruta is horizon only suppose to know about one?18:42
*** roxanaghe has quit IRC18:42
htrutalbragstad: I don't know, I'm just wondering what problems it might cause18:42
lbragstadhtruta i'm just thinking about it in the sense that I have more than three service endpoints in my deployment18:43
*** roxanaghe has joined #openstack-keystone18:44
lbragstadand I go to upgrade the schema in my deployment18:44
openstackgerritDolph Mathews proposed openstack/keystone: Explain default domain in docs for other services  https://review.openstack.org/23209818:45
*** spandhe has joined #openstack-keystone18:46
lbragstadtimcline https://bugs.launchpad.net/keystone/+bug/137693718:47
openstackLaunchpad bug 1376937 in Keystone "No way to prevent duplicates in endpoints" [Medium,In progress] - Assigned to Henrique Truta (henriquetruta)18:47
htrutalbragstad: is it okay to have two urls to the same service? if so, we must put url at the constraint too18:47
lbragstadhtruta that was one of the suggestions that dolphm  made in the bug report18:48
htrutalbragstad: makes sense.18:49
*** urulama has quit IRC18:49
*** urulama has joined #openstack-keystone18:49
htrutalbragstad: changing the focus a little bit, this shouldn't return true if we pass MII, right? https://review.openstack.org/#/c/212819/1/keystoneclient/common/cms.py L29318:52
raildolbragstad: https://bugs.launchpad.net/keystone/+bug/1506986 makes sense?18:52
openstackLaunchpad bug 1506986 in Keystone "documentation needs to be clarified about differences between subtree_as_ids and subtree_as_list" [Undecided,New]18:52
openstackgerritLance Bragstad proposed openstack/keystone-specs: Add even more clarity to scope docs  https://review.openstack.org/22994918:56
lbragstadraildo looks good, we should probably just track that in the already opened bug. working a fix for it here, too - https://review.openstack.org/#/c/235971/318:57
raildolbragstad: sure18:58
*** woodster_ has joined #openstack-keystone19:00
raildolbragstad:  so you can just update the commit message to close this bug :D19:00
*** jsavak has quit IRC19:01
lbragstadraildo yep19:01
*** jsavak has joined #openstack-keystone19:02
openstackgerritHenrique Truta proposed openstack/python-keystoneclient: Shorten PKI Token Identifier to MI  https://review.openstack.org/21281919:02
*** gordc has quit IRC19:02
lbragstadbknudson responded - https://review.openstack.org/#/c/235971/3/api/v3/identity-api-v3.rst19:03
*** david-ly_ has quit IRC19:04
*** david-lyle has joined #openstack-keystone19:05
openstackgerritLance Bragstad proposed openstack/keystone-specs: Add even more clarity to scope docs  https://review.openstack.org/22994919:06
openstackgerritDolph Mathews proposed openstack/keystone: Explain default domain in docs for other services  https://review.openstack.org/23209819:13
openstackgerritMerged openstack/keystonemiddleware: Straighten up exceptions imports  https://review.openstack.org/23508919:19
*** jdennis has quit IRC19:19
*** ajaya has quit IRC19:22
openstackgerritLance Bragstad proposed openstack/keystone-specs: Improve get project query strings  https://review.openstack.org/23597119:24
openstackgerritLance Bragstad proposed openstack/keystone-specs: Improve get project query strings  https://review.openstack.org/23597119:25
dstaneklbragstad: back from lunch19:27
lbragstaddstanek how was it?19:27
bknudsonlbragstad: must have been good because it took 3 1/2 hours.19:28
lbragstadbknudson and now it's almost coffee break time!19:29
dstaneklbragstad: not great. errand time :-(19:29
dstanekbknudson: :-)19:29
*** weihan has joined #openstack-keystone19:30
lbragstaddstanek i had a couple questions i wanted to bounce off of you here - https://review.openstack.org/#/c/134095/19:33
dstanekshore19:34
dstaneklbragstad: dolphm's suggestion to include url is interesting19:35
*** ayoung has joined #openstack-keystone19:35
*** ChanServ sets mode: +v ayoung19:35
lbragstaddstanek yeah, it was originally suggested in the bug report19:35
stevemar_dstanek: combining errands with lunch is never fun :(19:36
kfox1111so, key rotation should be done on one node, and the results pushed to the other keystone members. what about compute nodes / service nodes? They need the public keys somehow?19:39
lbragstadkfox1111 nope, the keys should only be shared across the keystone nodes19:40
dolphmkfox1111: auth_token calls back to keystone to validate, fernet doesn't do offline/distributed validation like PKI19:42
dolphmkfox1111: we *could* but that, but fernet uses symmetric crypto, so there's a lot of risk involved19:43
openstackgerritLance Bragstad proposed openstack/keystone-specs: Improve get project query strings  https://review.openstack.org/23597119:45
*** timcline_ has joined #openstack-keystone19:45
*** roxanaghe has quit IRC19:45
*** timcline has quit IRC19:46
*** roxanaghe has joined #openstack-keystone19:46
dolphmlbragstad: nice update on https://review.openstack.org/#/c/215212/19:47
*** jbell8 has quit IRC19:47
kfox1111so wouldn't pki perform better multiregion then?19:48
lbragstadbknudson stable backport related to your comment - https://review.openstack.org/#/c/236071/19:48
kfox1111or does the services end up contacting keystone anyway even with pki?19:48
bknudsonlbragstad: that one was clean?19:48
lbragstadbknudson yeah, no conflicts19:48
bknudsonlbragstad: there's no cherry-picked-from line19:48
*** jbell8 has joined #openstack-keystone19:48
lbragstadbknudson hmm, you're right. I used git review -x 21522119:49
bknudsonuse -X19:49
bknudsonotherwise it doesn't add the line19:49
dolphmkfox1111: i can't recommend PKI at all right now19:50
bknudsonkfox1111: the services talk to keystone for pki to get the certificates and to get the revocation list19:50
lbragstadbknudson done, thanks19:50
*** dramakri has joined #openstack-keystone19:51
*** e0ne has quit IRC19:51
kfox1111I thought they skipped talking to keystone for validate though, and that in theory all they needed was in the token. so they only had to talk to keystone occationally to get the revocation list.19:51
kfox1111which would make the traffic to keystone very infrequent.19:51
dolphmkfox1111: they need to verify the token's integrity & authenticity still19:52
kfox1111that could be done on the service by just validating the signature on the token with keystone's public key I think?19:52
bknudsonon validate it'll only talk to keystone when the revocation list is past its expiration19:52
kfox1111wouldn't take a contact back to keystone.19:52
dolphmkfox1111: correct19:53
bknudsonnote that PKI tokens are also ~8K in size.19:53
bknudsonso there's a definite tradeoff19:53
dolphmkfox1111: ^^ more generally, i'd strongly advise against considering PKI today for anything beyond academic purposes - there are simply one too many severe, unresolvable bugs. 18 months ago i believe i would have told you the exact opposite :-/19:53
kfox1111yeah. latency of connections vs fault tollerence.19:53
lbragstadthey have the possibility to be greater than that depending on the size of your deployment19:53
kfox1111keystone in theory could go totally down with pki and existing stuff should still work.19:53
kfox1111at least until the revocation lists expire.19:53
dolphmkfox1111: correct19:53
kfox1111so might be preferable for cross country datacenters?19:54
kfox1111ah. ok.19:54
kfox1111bugs are a different matter entirely.19:54
dolphmkfox1111: if your fernet keys are globally distributed, you get some similar benefits19:54
dolphmkfox1111: don't get me wrong, there are outstanding bugs against fernet as well, but none that i'm aware of that would truly impede adoption in production (and there are several production deployments), just some caveats we're working to resolve19:55
kfox1111assuming the mysql backend is replicated locally.. yeah..19:55
kfox1111k.19:56
dolphmkfox1111: correct19:56
dolphmkfox1111: https://bugs.launchpad.net/keystone/+bugs?field.tag=fernet19:56
dolphmkfox1111: https://bugs.launchpad.net/keystone/+bugs?field.tag=pki19:57
*** mylu has joined #openstack-keystone19:57
kfox1111hmm.. this one may be a show stopper... https://bugs.launchpad.net/keystone/+bug/149746119:57
openstackLaunchpad bug 1497461 in Keystone "Fernet tokens fail for some users with LDAP identity backend" [High,Fix committed] - Assigned to Eric Brown (ericwb)19:58
lbragstadkfox1111 that has been fixed in master19:58
*** su_zhang has quit IRC19:58
lbragstadkfox1111 are you targeting a specific release?19:58
kfox1111but not liberty. so backporting at least...19:58
dolphmlbragstad: ooh, but i haven't seen a kilo backport19:58
dolphmkfox1111: backport for liberty is in review19:58
lbragstaddolphm yeah, that could use a backport to kilo (i have no idea if it would conflict?)19:59
brownekfox1111: kilo backport will be soon19:59
dolphmlbragstad: should not19:59
lbragstadspeaking of kilo backports - https://review.openstack.org/#/c/236071/19:59
dolphmbrowne: thanks19:59
brownelbragstad: yeah there are conflicts and some other fernet related fixes that should also go back to kilo20:00
dolphmbrowne: are you proposing them, or do you have a list?20:00
brownedolphm: i haven't put them together yet. i'll make a list20:01
lbragstadbrowne that would be great, i haven't been doing a great job of tracking everything that has, or hasn't, gone all the way back to kilo20:01
kfox1111k. thanks.20:01
brownei think the float to int was one.  but i don't know the commit20:02
dolphmbrowne: that one is not an end-user facing bug though, just a pain to cherry pick around :)20:02
browneoh ok20:02
dolphmbrowne: i would +2 a backport though, nonetheless, as a trivial refactor20:03
dolphmpardon the ridiculous URL, but this is a query for fernet bugs tagged as potential kilo backports: https://bugs.launchpad.net/keystone/+bugs?field.searchtext=&orderby=-importance&field.status%3Alist=FIXCOMMITTED&field.status%3Alist=FIXRELEASED&assignee_option=any&field.assignee=&field.bug_reporter=&field.bug_commenter=&field.subscriber=&field.structural_subscriber=&field.tag=kilo-backport-potential+fernet+&field.tags_combin20:03
dolphmator=ALL&field.has_cve.used=&field.omit_dupes.used=&field.omit_dupes=on&field.affects_me.used=&field.has_patch.used=&field.has_branches.used=&field.has_branches=on&field.has_no_branches.used=&field.has_no_branches=on&field.has_blueprints.used=&field.has_blueprints=on&field.has_no_blueprints.used=&field.has_no_blueprints=on&search=Search20:03
morganbrowne: also +2 a backport (you have two stable keystone maintainers saying to backport for an easy +2 ;)20:03
dolphmshortened: http://bit.ly/1LeEDSU20:04
morgandolphm: bit.ly!!20:04
brownecool, let me put those together20:04
dolphmmorgan: i... did20:04
morgandolphm: hehe20:04
dolphmmorgan: i got yelled at in some openstack channel for using a bit.ly link recently, because it wasn't archive worthy20:05
dolphmso, have both!20:05
lbragstadbrowne here is the int -> float one - https://review.openstack.org/#/c/232010/220:05
brownelbragstad: thanks20:05
morganOh dolphm have you tried http://www.stochasticity.com/beers/your-father-smelt-elderberries20:05
lbragstadbrowne I assume that one is going back to both liberty and kilo?20:05
morgandolphm: i think we need an official openstack url shortener20:05
dramakribknudson: can I bug you on a bug-related questions? ;-)20:06
bknudsondramakri: sure20:06
brownelbragstad: it would yes.  o20:06
bknudsonyou can bug the whole channel20:06
dramakribknudson: can you please take a look at this bug - https://bugs.launchpad.net/keystone/+bug/1434000 ? I have written my thoughts, let me know what you think?20:06
openstackLaunchpad bug 1434000 in Keystone "user creation without domain using admin_token should fail nicer" [Low,In progress] - Assigned to Deepti Ramakrishna (dramakri)20:06
lbragstadbrowne ok, i'll propose them20:06
brownelbragstad: thx20:06
*** roxanaghe has quit IRC20:07
*** diazjf has quit IRC20:09
*** tonytan4ever has joined #openstack-keystone20:09
htrutadstanek: bug 1473489 looks invalid, right?20:10
openstackbug 1473489 in Keystone "Identity API v3 does not accept more than one query parameter" [Medium,Incomplete] https://launchpad.net/bugs/1473489 - Assigned to Alexey Miroshkin (amirosh)20:10
stevemar_ouch20:11
dstanekhtruta: i'm going to say yes :-)20:12
dstanekthe example is clearly wrong20:12
dstaneki didn't notice that dolphm responded after me20:12
lbragstadbrowne stable/liberty - https://review.openstack.org/#/c/236078/20:13
htrutadstanek: cool. can you mark it as invalid?20:13
brownelbragstad: thanks!20:15
lbragstadbrowne that change conflicts a lot with kilo, might need to have some other stuff go before it20:16
htrutaguys, we should not encourage anyone to use domain scoped tokens, right? I think bug 1378036 is invalid as well20:16
openstackbug 1378036 in Keystone "Keystone unit tests should use domain scoped token" [Low,Triaged] https://launchpad.net/bugs/1378036 - Assigned to Anh Huynh (anhx-huynh)20:16
*** jsavak has quit IRC20:17
htrutait was triaged 1 year ago20:17
dolphmhtruta: why not?20:17
bretondomain-scoped tokens are the mainstream now20:18
dolphmit's a big refactor, but the assertion is correct. we should be dogfooding the new policy model in tests20:18
htrutadolphm: with reseller, we are replicating the domains operations to projects, and we'll be able to do it all with project scoped tokens20:18
htrutawe have a bp for that20:18
dstanekhtruta: but we have domain scoped tokens now and we support that right?20:19
htrutahttps://blueprints.launchpad.net/keystone/+spec/add-isdomain-to-token20:19
dolphmdstanek: ++20:19
*** diazjf has joined #openstack-keystone20:20
bretonhtruta: I just don't want to have the code for this check to be spread in different places20:20
htrutadstanek, dolphm: yes, correct20:21
htrutaalthough this is a long term change, I don't know if it's worth to spend much effort in that20:22
bretonhtruta: *the one we were talking about in https://github.com/openstack/keystone/blob/master/keystone/common/controller.py#L68420:23
*** jsavak has joined #openstack-keystone20:24
bretonmaybe someome could review https://review.openstack.org/#/c/234849/ ? It's about a bug.20:25
htrutabreton: I see... but I agree with henry that it makes more sense being at manager20:26
lbragstadbrowne stable/kilo - https://review.openstack.org/#/c/236083/20:28
* lbragstad steps away to get coffee20:30
openstackgerritBrant Knudson proposed openstack/keystone: Handle fernet payload timestamp differences  https://review.openstack.org/23271120:34
openstackgerritBrant Knudson proposed openstack/keystone: Fix fernet padding for python 3  https://review.openstack.org/23171120:34
*** mylu has quit IRC20:37
openstackgerritDeepti Ramakrishna proposed openstack/keystone: Reject user creation using admin token without explicitly passing the domain.  https://review.openstack.org/19694220:37
*** mylu has joined #openstack-keystone20:37
openstackgerritMerged openstack/oslo.policy: Add test for raising default exception  https://review.openstack.org/23430920:42
*** mylu has quit IRC20:45
dolphmhave a good weekend before our 3-week-work-week, everyone :)20:45
openstackgerritMerged openstack/oslo.policy: Add test for enforce with rule doesn't exist  https://review.openstack.org/23431020:48
openstackgerritMerged openstack/oslo.policy: Use JSON generator  https://review.openstack.org/23442120:48
brownelbragstad: I resolved the conflicts.  doesn't look like the int-> float thing was necessary.  https://review.openstack.org/#/c/236092/20:50
kfox1111does keystone need rabbit at all?20:50
kfox1111coming up with the bare minimum keystone cluster for multiregion.20:51
kfox1111haproxy/keystone/gallera?20:51
*** ankurgupta has joined #openstack-keystone20:56
openstackgerritTom Cocozzello proposed openstack/keystonemiddleware: Define entry points for filter factories for Paste Deployment  https://review.openstack.org/23383920:56
openstackgerritDeepti Ramakrishna proposed openstack/keystone: Reject user creation using admin token without explicitly passing the domain.  https://review.openstack.org/19694220:57
*** ankurgupta has left #openstack-keystone20:57
dramakridolphm: sorry about this patch - https://review.openstack.org/#/c/196942/ earlier. Now I have fixed the merge conflicts.20:58
*** raildo is now known as raildo-afk20:59
openstackgerritBrant Knudson proposed openstack/keystone: Handle fernet payload timestamp differences  https://review.openstack.org/23271120:59
openstackgerritBrant Knudson proposed openstack/keystone: Fix fernet padding for python 3  https://review.openstack.org/23171120:59
openstackgerritBrant Knudson proposed openstack/keystone: Fix key_repository_signature method for python3  https://review.openstack.org/23609620:59
*** su_zhang has joined #openstack-keystone21:00
lbragstadbrowne ok21:02
*** roxanagh_ has joined #openstack-keystone21:03
*** timcline_ has quit IRC21:06
*** njohnston is now known as nate_gone21:07
openstackgerritHenrique Truta proposed openstack/keystone: Improves domain name case sensitivity tests  https://review.openstack.org/23610321:09
stevemar_bknudson: you got a clever way of how to do this? https://review.openstack.org/#/c/171916/18/keystone/tests/unit/test_sql_upgrade.py21:11
*** jsavak has quit IRC21:11
*** rbowen has quit IRC21:16
*** jbell8 has quit IRC21:23
dstaneklbragstad: http://paste.openstack.org/show/476563/ with ~9 things gating right now21:35
*** diegows has joined #openstack-keystone21:38
*** dims_ has joined #openstack-keystone21:38
*** jasonsb has quit IRC21:38
dstaneklbragstad: that's keystone only running a larger report now21:39
openstackgerritSteve Martinelli proposed openstack/keystone: Move endpoint_policy migrations into keystone core  https://review.openstack.org/17191621:40
*** dimsum__ has quit IRC21:40
*** phalmos has quit IRC21:41
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23560821:43
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23560821:44
*** dims_ has quit IRC21:45
*** david-ly_ has joined #openstack-keystone21:50
*** david-lyle has quit IRC21:50
*** tonytan4ever has quit IRC21:51
*** jdennis has joined #openstack-keystone21:52
*** diegows has quit IRC21:53
stevemar_#topic21:56
stevemar_whoopsy21:56
*** stevemar_ changes topic to "Liberty is Out yay!! \o/ | Etherpads for summit https://wiki.openstack.org/wiki/Design_Summit/Mitaka/Etherpads#Keystone"21:57
stevemar_etherpads ^^21:57
gyeeyay, we got liberty21:58
*** alejandrito has quit IRC21:59
stevemar_gyee: but no freedom :(22:01
*** stevemar_ has quit IRC22:01
*** sigmavirus24 is now known as sigmavirus24_awa22:01
*** stevemar_ has joined #openstack-keystone22:02
*** ChanServ sets mode: +o stevemar_22:02
*** tonytan4ever has joined #openstack-keystone22:04
*** roxanaghe has joined #openstack-keystone22:05
*** su_zhang has quit IRC22:06
*** stevemar_ has quit IRC22:06
*** roxanagh_ has quit IRC22:06
*** jbell8 has joined #openstack-keystone22:07
*** stevemar_ has joined #openstack-keystone22:07
*** ChanServ sets mode: +o stevemar_22:07
*** dimsum__ has joined #openstack-keystone22:08
openstackgerritMerged openstack/keystone: Updated from global requirements  https://review.openstack.org/23564622:10
*** pumaranikar has quit IRC22:11
bknudsonstevemar_: move the original migration out to another file or something?22:11
openstackgerritMerged openstack/keystone: Correct the filename  https://review.openstack.org/23453322:11
openstackgerritMerged openstack/keystone: Fix some nits in `configure_federation.rst`  https://review.openstack.org/23409122:11
*** gsilvis has quit IRC22:11
*** stevemar_ has quit IRC22:12
*** diazjf has quit IRC22:15
*** dimsum__ has quit IRC22:16
*** dimsum__ has joined #openstack-keystone22:17
*** jbell8 has quit IRC22:25
*** jbell8 has joined #openstack-keystone22:27
openstackgerritMerged openstack/keystone: Allow the PBR_VERSION env to pass through tox  https://review.openstack.org/22440722:28
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23560822:29
openstackgerritDeepti Ramakrishna proposed openstack/keystone: Reject user creation using admin token without explicitly passing the domain.  https://review.openstack.org/19694222:30
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23560822:31
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23560822:32
*** martinus__ has quit IRC22:32
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23560822:33
*** martinus__ has joined #openstack-keystone22:33
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23560822:34
*** btully has quit IRC22:36
*** tonytan4ever has quit IRC22:36
*** btully has joined #openstack-keystone22:38
*** slberger has left #openstack-keystone22:46
openstackgerritMerged openstack/keystone: Update test modules passing on py34  https://review.openstack.org/23163522:49
openstackgerritMerged openstack/keystone: Fix fernet key writing for python 3  https://review.openstack.org/23171022:49
*** wwwjfy has quit IRC22:50
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23560822:51
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23560822:52
*** dimsum__ has quit IRC22:52
*** jbell8 has quit IRC22:57
*** jbell8 has joined #openstack-keystone22:58
*** jbell8 has quit IRC23:03
*** pgbridge has quit IRC23:07
*** marzif has joined #openstack-keystone23:08
*** dimsum__ has joined #openstack-keystone23:08
*** roxanaghe has quit IRC23:17
*** roxanaghe has joined #openstack-keystone23:22
*** marzif has quit IRC23:24
*** lhcheng has quit IRC23:25
*** lhcheng has joined #openstack-keystone23:29
*** ChanServ sets mode: +v lhcheng23:29
*** su_zhang has joined #openstack-keystone23:37
*** su_zhang has quit IRC23:37
*** su_zhang has joined #openstack-keystone23:38
*** woodster_ has quit IRC23:39
*** gsilvis has joined #openstack-keystone23:43
*** su_zhang has quit IRC23:52
*** gsilvis_ has joined #openstack-keystone23:55
openstackgerritDeepti Ramakrishna proposed openstack/keystone: Reject user creation using admin token without explicitly passing the domain.  https://review.openstack.org/19694223:55
*** _cjones_ has quit IRC23:56
*** _cjones_ has joined #openstack-keystone23:56
*** gsilvis has quit IRC23:56
*** browne has quit IRC23:56

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!