Monday, 2015-12-14

*** markvoelker_ has quit IRC00:10
*** gildub has joined #openstack-keystone00:38
*** chlong has joined #openstack-keystone00:48
*** jasonsb has joined #openstack-keystone00:54
*** EinstCrazy has joined #openstack-keystone00:55
notmorganjamielennox: so.01:05
*** markvoelker has joined #openstack-keystone01:10
*** markvoelker has quit IRC01:15
jamielennoxnotmorgan: yup01:20
notmorganjamielennox: converting keystoneclient to use keystoneauth... it's a fairly sizable change it seems01:20
jamielennoxnotmorgan: it depends how much of a conversion you want to do01:21
notmorganjamielennox: i'm looking to convert only keystoneclient CRUD stuff01:22
notmorgandon't care about session related things that we now consume from ksa01:22
notmorganbasically, leave the session stuff to be officially deprecated as soon as we can(ish)01:22
notmorgan[when all the clients and servers are using ksa]01:22
jamielennoxnotmorgan: so the rest of that stuff should just convert over more or less transparently01:22
jamielennoxwe did the exceptions change over01:22
notmorganit looks like keystoneclient.discover and client?01:23
notmorganand the rest relies on that?01:23
jamielennoxoh, discover is pretty horrible01:23
notmorgandiscover seems to have KSC specific magic in it01:23
notmorganerm keystone*01:23
notmorganyah01:23
jamielennoxi don't really like how discover works at all01:23
notmorganso, should i leave this for you to rewrite that?01:24
jamielennoxnotmorgan: it's horrible but i wasn't going to rewrite it atm - hasn't been a need01:24
notmorganyeah01:24
notmorganso just the base client and discover afaict01:24
notmorganalso: https://review.openstack.org/#/c/250669/ should be an easy +2/+A at this point01:25
notmorganso we can be clear of the old-untested middleware01:25
jamielennoxso that should be a fairly easy deprecation01:25
jamielennoxi just thought we had to wait for another cycle01:25
notmorgani don't think so.01:26
notmorganit's been untested for a long time01:26
notmorganstevemar: ^ cc01:26
notmorganbasically it's not really tested against a real system, it's probably borken01:26
jamielennoxnotmorgan: it's been very well publicised that the keystoneclient middleware is dead01:27
jamielennoxi'd be fine to remove it now01:28
notmorganexactly01:28
notmorgantoss a +2 on it and we hit steve to +A tomorrow?01:28
* jamielennox hasn't had devstack work in like 5 days01:28
notmorganjamielennox: it's working now  better01:28
jamielennoxsomething in tox/tempest01:29
notmorgani've been shepherding thorugh mordred's patches for conversion to ksa01:29
notmorganyeah  tox 2.3.0 was/is broken01:29
notmorganthe nodes with it have been mostly (all?) squashed out01:29
notmorganso it should be done at this point01:29
notmorganwe did land the nova's neutron options removal patch :)01:30
jamielennoxis that really the only dependency we remove :(01:34
jamielennoxwebob can go01:35
jamielennoxnotmorgan: i +2ed it - we need to remove webob as well01:38
notmorgansure will do as a followup01:38
notmorganyeah it is.01:39
notmorgansadly01:39
jamielennoxnotmorgan: done01:40
notmorganjamielennox: ^01:40
notmorganhe01:40
notmorgandid we just both do it?01:40
jamielennoxi don't see the bot messages01:40
notmorganahahaha01:40
notmorganyeah01:40
notmorganwe both did01:40
notmorgani'll abandon mine01:40
jamielennoxi don't mind, pick one the other can approve01:40
notmorgangoing with yours01:41
jamielennoxdid you have to hack up the neutron options patch?01:42
notmorgannah. went through pretty easily01:43
jamielennoxthere's a fallback case01:43
notmorganhad to do extra requests_mock work01:43
notmorganbut it wasn't too bad01:43
jamielennoxso you can do like nova_session options that fall back to generic session options01:43
jamielennoxheat does that a lot01:43
notmorgananyway.01:44
notmorganneed to circle up w/ nova team on the keystoneauth session conversion now01:44
jamielennoxnotmorgan: did you do that list?01:44
notmorganhmm? which list?01:44
jamielennoxksa conversions01:45
notmorganoh no.01:45
notmorganneed to bug mordred about that.01:45
notmorgansee which one of us is doing it01:45
jamielennoxnotmorgan: no worries, cause i can get back into that i just don't want to repeat work01:45
notmorganlets get a list together tomorrow01:45
notmorganand then you can hop in too01:45
notmorganwe can keep landing this stuff01:45
notmorganwith three of us working on it, we can likely land more01:46
notmorganneutron is now fully using KSA, nova is close01:46
notmorganand clients are starting to come together01:47
notmorganthere is a lot of OCC patches that need looks at for novaclient to be converted01:47
*** markvoelker has joined #openstack-keystone03:11
*** markvoelker has quit IRC03:16
*** wanghua has joined #openstack-keystone03:18
*** yuanxu has joined #openstack-keystone03:31
*** yuanxu has quit IRC03:40
mordredthey're all fairly small though03:56
mordredjamielennox: and no, I totallyy didn't work on that etherpad at all04:01
*** grantbow has quit IRC04:02
*** wolsen_ is now known as wolsen04:12
*** Guest45133 is now known as jgriffith04:12
*** aginwala has joined #openstack-keystone04:19
*** dims has joined #openstack-keystone04:20
*** fawadkhaliq has joined #openstack-keystone04:29
*** pumaranikar has joined #openstack-keystone04:32
*** topol has joined #openstack-keystone04:34
*** ChanServ sets mode: +v topol04:34
*** wasmum has quit IRC04:36
*** mgagne has quit IRC04:36
*** mgagne has joined #openstack-keystone04:37
*** mgagne is now known as Guest7323304:37
*** topol has quit IRC04:39
*** wasmum has joined #openstack-keystone04:42
*** ig0r_ has quit IRC04:50
*** ig0r_ has joined #openstack-keystone04:55
*** pumaranikar has quit IRC04:55
stevemarnotmorgan: i totally forgot that keystone CLI had a "bootstrap" command: https://github.com/openstack/python-keystoneclient/blob/master/keystoneclient/contrib/bootstrap/shell.py#L17-L4005:05
*** markvoelker has joined #openstack-keystone05:12
stevemarjamielennox: do we need to deprecate all the plugins/sessions/auth stuff for keystoneclient, or has that already been done?05:14
*** markvoelker has quit IRC05:17
*** aginwala has quit IRC05:26
*** jrist has quit IRC05:36
*** jrist has joined #openstack-keystone05:38
*** jrist has quit IRC05:38
*** jrist has joined #openstack-keystone05:38
stevemarjamielennox: got one for ya: https://review.openstack.org/#/c/257131/05:44
*** dims has quit IRC05:53
*** Nirupama has joined #openstack-keystone05:58
*** ig0r_ has quit IRC06:12
*** alexvictorchan has joined #openstack-keystone06:18
*** zqfan_AFK has joined #openstack-keystone06:23
*** jimbaker` has quit IRC06:25
*** yuanxu has joined #openstack-keystone06:29
*** yuanxu_ has joined #openstack-keystone06:31
*** yuanxu has quit IRC06:32
*** yuanxu_ has quit IRC06:32
*** gildub has quit IRC06:49
stevemarmordred: why is occ using code from keystoneclient.openstack.common.apiclient :O06:49
stevemarerr, wrong occ, https://github.com/openstack/os-cloud-config06:51
*** sudorandom has quit IRC06:59
*** mjb has quit IRC07:00
*** rcernin has joined #openstack-keystone07:02
stevemarjamielennox: around?07:04
*** mjb has joined #openstack-keystone07:05
*** openstackstatus has joined #openstack-keystone07:05
*** ChanServ sets mode: +v openstackstatus07:05
*** boris-42_ has joined #openstack-keystone07:09
*** openstackgerrit has joined #openstack-keystone07:10
*** jamielennox is now known as jamielennox|away07:12
*** markvoelker has joined #openstack-keystone07:13
*** markvoelker has quit IRC07:17
notmorganstevemar: ksc.bootstrap should die with the ksc cli07:24
stevemarnotmorgan: it should07:26
stevemarnotmorgan: doh, it looks like some places still use keystoneclient.middleware: http://codesearch.openstack.org/?q=from%20keystoneclient.middleware&i=nope&files=&repos=07:33
*** sudorandom has joined #openstack-keystone07:33
notmorganclearly we have gaps in testing then. there is no way that works right07:34
notmorganlets spin some changeds for those before release then07:35
*** dims has joined #openstack-keystone07:39
*** rha has joined #openstack-keystone07:40
*** rha has joined #openstack-keystone07:40
*** alexvictorchan has quit IRC07:45
*** chlong has quit IRC07:46
stevemarnotmorgan: yeah, i'm doing that now07:46
*** pnavarro has joined #openstack-keystone08:01
*** pnavarro has quit IRC08:07
*** joseppc has quit IRC08:10
*** joseppc has joined #openstack-keystone08:19
openstackgerrithenry-nash proposed openstack/keystone: Support url safe restriction on new projects and domains  https://review.openstack.org/25698608:27
*** fawadkhaliq has quit IRC08:30
*** fawadkhaliq has joined #openstack-keystone08:31
*** fawadkhaliq has quit IRC08:31
*** fawadkhaliq has joined #openstack-keystone08:32
*** fhubik has joined #openstack-keystone08:43
*** spandhe has quit IRC08:46
*** dancn has joined #openstack-keystone08:46
*** spandhe has joined #openstack-keystone08:47
*** fhubik is now known as fhubik_brb08:48
*** fawadkhaliq has quit IRC08:49
*** fawadkhaliq has joined #openstack-keystone08:49
*** fhubik_brb is now known as fhubik08:53
openstackgerrithenry-nash proposed openstack/keystone: Support url safe restriction on new projects and domains  https://review.openstack.org/25698608:57
*** fhubik is now known as fhubik_brb09:00
stevemarhenrynash: thanks for the work :)09:01
henrynashstevemar: just keep swimming, just keep swimming....09:02
stevemaraint that the truth09:02
stevemarhenrynash: hoping to wake up in time for our call!09:02
stevemarhenrynash: or is it canceled with all the other holiday stuff?09:02
henrynashso Tammy and co wanted to present teh RTC stuff…but have had conflicting reports as to whether they will have it ready….if it’s ready, I’ll keep the call, if not, I’ll cancel09:03
stevemarhenrynash: hmm, nate and i already spoke about that stuff last week for a solid hour09:04
stevemarhe gave me the low down09:04
henrynashok09:05
*** marekd has joined #openstack-keystone09:05
*** ChanServ sets mode: +v marekd09:05
*** fhubik_brb is now known as fhubik09:06
stevemarhenrynash: anywho, i'll show up09:06
henrynashif hear soft snoring, I’ll know who it is....09:07
*** spandhe has quit IRC09:08
stevemarhenrynash: oh it ain't soft09:11
*** jistr has joined #openstack-keystone09:12
henrynash:-)09:12
*** dancn has quit IRC09:12
*** dancn has joined #openstack-keystone09:12
*** markvoelker has joined #openstack-keystone09:14
*** dancn is now known as localbip09:16
*** rm_you has joined #openstack-keystone09:17
*** markvoelker has quit IRC09:18
*** localbip has quit IRC09:18
*** dancn has joined #openstack-keystone09:19
*** dancn has quit IRC09:19
*** dancn has joined #openstack-keystone09:20
*** jrist has quit IRC09:26
*** Guest58914 is now known as BobBall09:26
*** fhubik is now known as fhubik_brb09:27
*** jrist has joined #openstack-keystone09:30
*** jrist has quit IRC09:30
*** jrist has joined #openstack-keystone09:30
*** roxanaghe has joined #openstack-keystone09:35
*** aix has joined #openstack-keystone09:36
*** topol has joined #openstack-keystone09:37
*** ChanServ sets mode: +v topol09:37
*** mhickey has joined #openstack-keystone09:37
*** vgridnev has joined #openstack-keystone09:38
*** ig0r_ has joined #openstack-keystone09:39
*** topol has quit IRC09:41
*** dancn has quit IRC09:45
*** fhubik_brb is now known as fhubik09:46
*** jrist has quit IRC09:46
*** jrist has joined #openstack-keystone09:47
*** henrynash has quit IRC09:49
*** roxanaghe has quit IRC09:51
*** vgridnev has quit IRC09:55
*** vgridnev has joined #openstack-keystone09:56
*** jrist has quit IRC09:57
*** jrist has joined #openstack-keystone09:59
*** jrist has quit IRC09:59
*** jrist has joined #openstack-keystone09:59
*** fawadkhaliq has quit IRC10:05
openstackgerritjaveme proposed openstack/python-keystoneclient: remove the default arguments "{}"  https://review.openstack.org/25417510:05
*** zeus` has quit IRC10:23
*** fawadkhaliq has joined #openstack-keystone10:25
*** rcernin has quit IRC10:25
bretonlbragstad: a script to reproduce the bug with trusts and fernet: http://paste.openstack.org/show/481789/10:35
*** dancn has joined #openstack-keystone10:45
*** dancn has quit IRC10:55
*** dancn has joined #openstack-keystone10:55
*** yuanxu has joined #openstack-keystone10:55
*** yuanxu has quit IRC10:56
*** e0ne has joined #openstack-keystone11:05
*** fhubik is now known as fhubik_brb11:06
*** dims has quit IRC11:13
*** EinstCrazy has quit IRC11:22
openstackgerritMarek Denis proposed openstack/keystone: Adds a base class for functional tests  https://review.openstack.org/20314211:25
*** chlong has joined #openstack-keystone11:39
*** EinstCrazy has joined #openstack-keystone11:44
*** vgridnev has quit IRC11:49
*** raildo-afk is now known as raildo12:10
*** aix has quit IRC12:12
*** doug-fish has joined #openstack-keystone12:23
*** doug-fish has quit IRC12:34
*** vgridnev has joined #openstack-keystone12:34
*** doug-fish has joined #openstack-keystone12:39
*** vgridnev_ has joined #openstack-keystone12:39
*** vgridnev has quit IRC12:39
*** gordc has joined #openstack-keystone12:44
*** markvoelker has joined #openstack-keystone12:45
*** dims has joined #openstack-keystone12:48
*** markvoelker has quit IRC12:49
*** vgridnev_ has quit IRC12:50
*** vgridnev_ has joined #openstack-keystone12:54
*** aix has joined #openstack-keystone12:55
*** vgridnev_ has quit IRC13:05
*** vgridnev has joined #openstack-keystone13:05
*** joseppc has quit IRC13:13
*** henrynash has joined #openstack-keystone13:24
*** ChanServ sets mode: +v henrynash13:24
*** Nirupama has quit IRC13:27
mordredstevemar: it's not?13:30
*** fhubik_brb is now known as fhubik13:33
*** BobBall has quit IRC13:39
*** fhubik is now known as fhubik_brb13:46
*** jaosorior has joined #openstack-keystone13:47
*** fhubik_brb is now known as fhubik13:47
*** pumaranikar has joined #openstack-keystone13:53
*** topol has joined #openstack-keystone13:54
*** ChanServ sets mode: +v topol13:54
*** dslevin_ has joined #openstack-keystone13:55
openstackgerritAlexander Makarov proposed openstack/keystone: Unified delegation driver interface  https://review.openstack.org/20960013:56
*** zeus has joined #openstack-keystone13:57
*** gordc has quit IRC13:57
*** zeus is now known as Guest8325713:57
*** Guest83257 is now known as zeus-13:58
*** zeus- is now known as zeus`13:58
*** richm has joined #openstack-keystone14:02
*** andreykurilin__ has joined #openstack-keystone14:05
openstackgerritAlexander Makarov proposed openstack/keystone: Unified delegation manager skeleton  https://review.openstack.org/25312414:09
openstackgerritAlexander Makarov proposed openstack/keystone: Unified delegation manager skeleton  https://review.openstack.org/25312414:10
*** dims has quit IRC14:11
*** gordc has joined #openstack-keystone14:12
*** dims has joined #openstack-keystone14:19
openstackgerrithenry-nash proposed openstack/keystone: WIP: Add support for strict url safe option on new projects and domains  https://review.openstack.org/25737614:25
*** dims has quit IRC14:28
openstackgerritAlexander Makarov proposed openstack/keystone: Trust manager using unified delegation  https://review.openstack.org/25737814:28
openstackgerritAlexander Makarov proposed openstack/keystone: Unified delegation manager skeleton  https://review.openstack.org/25312414:29
*** dims has joined #openstack-keystone14:30
openstackgerrithenry-nash proposed openstack/keystone: WIP: Add support for strict url safe option on new projects and domains  https://review.openstack.org/25737614:30
*** pumaranikar has quit IRC14:32
openstackgerritHenrique Truta proposed openstack/keystone: Tests for projects acting as domains  https://review.openstack.org/21121914:42
openstackgerritHenrique Truta proposed openstack/keystone: Projects acting as domains  https://review.openstack.org/23128914:42
openstackgerritHenrique Truta proposed openstack/keystone: Removes project.domain_id FK  https://review.openstack.org/23327414:42
openstackgerritHenrique Truta proposed openstack/keystone: Change project name constraints  https://review.openstack.org/15837214:42
openstackgerritHenrique Truta proposed openstack/keystone: Add is_domain parameter to get_project_by_name  https://review.openstack.org/21060014:42
*** markvoelker has joined #openstack-keystone14:43
*** petertr7_away is now known as petertr714:44
openstackgerritMarek Denis proposed openstack/keystone: Adds a base class for functional tests  https://review.openstack.org/20314214:47
*** jimbaker has joined #openstack-keystone14:48
*** jimbaker has quit IRC14:48
*** jimbaker has joined #openstack-keystone14:48
*** zqfan_AFK has quit IRC14:51
*** henrynash has quit IRC14:59
*** henrynash has joined #openstack-keystone15:00
*** ChanServ sets mode: +v henrynash15:00
*** ig0r_ has quit IRC15:04
*** sigmavirus24_awa is now known as sigmavirus2415:05
dolphmbreton: do we have an existing place in the test suite for that?15:08
*** pumaranikar has joined #openstack-keystone15:15
*** davechen has joined #openstack-keystone15:17
*** EinstCrazy has quit IRC15:18
bretondolphm: I could not figure out15:27
*** breitz has quit IRC15:27
*** breitz has joined #openstack-keystone15:28
bretonwe have like several places where tokens are tested15:28
bretonand I couldn't figure out where this test should be15:28
* breton is still debugging15:29
openstackgerritAlexander Makarov proposed openstack/keystone: Trust manager using unified delegation  https://review.openstack.org/25737815:29
*** timcline has joined #openstack-keystone15:30
openstackgerritAlexander Makarov proposed openstack/keystone: Unified delegation manager skeleton  https://review.openstack.org/25312415:31
*** dslevin_ has quit IRC15:36
*** fhubik is now known as fhubik_brb15:37
*** fhubik_brb is now known as fhubik15:37
*** superdan is now known as dansmith15:38
*** flwang1 has joined #openstack-keystone15:40
*** slberger1 has joined #openstack-keystone15:41
*** fhubik is now known as fhubik_brb15:42
*** r-daneel has joined #openstack-keystone15:43
*** fhubik_brb is now known as fhubik15:43
*** jorge_munoz has quit IRC15:43
*** _d34dh0r53_ is now known as d34dh0r5315:47
*** pgbridge has joined #openstack-keystone15:50
*** fhubik is now known as fhubik_brb15:50
*** Ephur has joined #openstack-keystone15:51
*** fhubik_brb is now known as fhubik15:53
*** topol has quit IRC15:53
*** petertr7 is now known as petertr7_away15:54
*** vgridnev has quit IRC15:54
*** jorge_munoz has joined #openstack-keystone15:56
*** tonytan4ever has joined #openstack-keystone15:56
*** fhubik has quit IRC15:56
*** 21WAAGP61 has quit IRC15:57
*** davechen1 has joined #openstack-keystone15:57
*** andreaf_ has joined #openstack-keystone15:57
*** spandhe has joined #openstack-keystone15:58
*** petertr7_away is now known as petertr715:58
*** davechen has quit IRC15:59
*** jistr has quit IRC16:03
openstackgerritGrzegorz Grasza (xek) proposed openstack/keystone: WIP Refactor use of oslo.db.sqlalchemy.session.EngineFacade  https://review.openstack.org/25745816:08
*** spandhe_ has joined #openstack-keystone16:09
*** spandhe has quit IRC16:10
*** spandhe_ is now known as spandhe16:10
*** tonytan4ever has quit IRC16:11
*** petertr7 is now known as petertr7_away16:12
*** inc0 has joined #openstack-keystone16:17
inc0hey guys, quick question16:17
inc0I'm writting upgrade playbook for keystone16:17
inc0and way I want to do it is to do schema migration and after that restart ks one service at the time16:18
inc0but since you are apache backed - will that work?16:18
inc0also can I SIGHUP ks to reload db connections?16:19
stevemarinc0: should just need to restart apache16:20
inc0stevemar, thing is, I don't want to restart all the services at same time16:20
stevemarinc0: upgrade databases using keystone-manage then restart apache16:20
inc0this causes downtime, and it's downtime for every other service16:20
stevemarinc0: only keystone and horizon should be running on apache16:21
inc0stevemar, but everything talks to ks for auth...so if ks is down auth is down and openstack control plane is down16:21
*** andreaf has quit IRC16:21
*** andreaf_ is now known as andreaf16:21
inc0thats why i want to avoid it at all cost16:21
stevemarinc0: yep... i think that's a known issue16:22
inc0well, I think part of it can be avoided16:23
inc0hence my question, can ks really support rolling upgrades16:23
*** tonytan4ever has joined #openstack-keystone16:24
*** EinstCrazy has joined #openstack-keystone16:25
stevemarinc0: we can have no downtown for database migrations, that's possible16:27
inc0ok, so I make migration, db is new16:28
inc0will old services keep working?16:28
*** csoukup has joined #openstack-keystone16:28
stevemarinc0: that's the plan going forward, we are http://specs.openstack.org/openstack/keystone-specs/specs/mitaka/online-schema-migration.html16:29
stevemarinc0: apache restart will always be needed16:29
inc0ok...but if I have 3 ks running on 3 nodes16:29
inc0if I restart one at the time, I don't have downtime then16:30
stevemarinc0: oh, you're assuming you are load balanced or something16:31
inc0yes, ofc16:32
inc0question tho, if I can do this safely? or should I first SIGHUP all the processes to reload db connections and only then I can safely do rolling upgrae?16:32
*** EinstCrazy has quit IRC16:32
stevemarinc0: i'm not clear on what the best practices are, you could drop an email to the operators mailing list to get feedback on what other folks are doing (or join #openstack-operators)16:37
*** dims has quit IRC16:42
openstackgerritBoris Bobrov proposed openstack/keystone: Verify that user is trustee only on issuing token  https://review.openstack.org/25747816:46
*** e0ne has quit IRC16:48
dolphmis gerrit dog slow today for anyone else?16:49
notmorgandolphm: yes16:49
notmorgandolphm: -infra is looking into it16:49
bknudsondolphm: every once in a while gerrit slows down and they reboot it16:49
*** jmccrory has quit IRC16:53
*** gyee has joined #openstack-keystone16:53
*** ChanServ sets mode: +v gyee16:53
openstackgerritHenrique Truta proposed openstack/keystone: Constraint to prevent duplicates endpoints  https://review.openstack.org/13409516:54
dstanekbknudson: java.....16:54
bknudsonthere's no memory leaks in java!16:54
openstackgerritAlexander Makarov proposed openstack/keystone: Trust manager using unified delegation  https://review.openstack.org/25737816:54
dstanekthat's what the call JVM memory management sir16:54
*** jmccrory has joined #openstack-keystone16:55
*** topol has joined #openstack-keystone16:55
*** ChanServ sets mode: +v topol16:55
*** breitz has quit IRC16:56
*** breitz has joined #openstack-keystone16:56
*** rderose has joined #openstack-keystone16:56
*** diazjf has joined #openstack-keystone16:59
*** topol has quit IRC16:59
*** ccard__ has joined #openstack-keystone17:00
*** davechen1 is now known as davechen17:01
*** ccard_ has quit IRC17:02
*** pwp has joined #openstack-keystone17:03
stevemardstanek: ba dum tsst!17:05
*** thiagop has joined #openstack-keystone17:11
openstackgerritBoris Bobrov proposed openstack/keystone: Verify that user is trustee only on issuing token  https://review.openstack.org/25747817:12
*** rderose has quit IRC17:13
bretoncould someone set importance of bug 1524849 please?17:14
openstackbug 1524849 in OpenStack Identity (keystone) "Cannot use trusts with fernet tokens" [Undecided,In progress] https://launchpad.net/bugs/1524849 - Assigned to Boris Bobrov (bbobrov)17:14
bretondolphm: (found a place for a test btw)17:14
dolphmbreton: awesome! and triaged.17:15
dolphmbreton: i'll review the patch today17:15
bretonit turns out that a lot of components already use trusts17:16
bretonmurano, sahara do. Glance has a patch to start using them.17:17
*** aginwala has joined #openstack-keystone17:18
bknudsonbreton: how do they know what roles to use in the trust?17:18
bretonbknudson: I have no idea17:19
odyssey4mehi all, I'm trying to work on configuring an environment with the hybrid ldap/sql back-end, which seems like it should be there but doesn't seem to be working... I'm probably missing something17:19
odyssey4mecan anyone guide me to an appropriate configuration?17:20
*** openstackstatus has quit IRC17:20
*** openstackstatus has joined #openstack-keystone17:22
*** ChanServ sets mode: +v openstackstatus17:22
bretonbknudson: https://review.openstack.org/#/c/241986/17/glance/api/v2/image_data.py they take roles from token17:22
bknudsonbreton: y, so they're not using trusts to limit roles they're using it to extend the token expiration17:24
bknudson:(17:24
bknudsonI'm surprised we allow creating a trust with the same roles. what's the point?17:27
bretonbknudson: yep. We discussed it at the summit, and they should not do what they're doing.17:29
*** pwp has quit IRC17:31
*** petertr7_away is now known as petertr717:31
*** tpeoples has joined #openstack-keystone17:31
*** raies has joined #openstack-keystone17:32
raieshi anyone arround17:32
*** e0ne has joined #openstack-keystone17:34
raiesI started deploying icehouse manualy17:34
*** doug-fish has quit IRC17:35
bretonicehouse? Oh.17:35
raiesI I reached keystone installation, I wanted to set backend as ldap17:35
*** doug-fish has joined #openstack-keystone17:35
raiesAs per current doc I set backend as identity and assignment also17:35
raiesAfter that I don't know hw to proceed with user/role/tenant/ creation and al further steps17:36
raiesas in sql based backend17:36
raiesHow to proceed with this ?17:36
raiesI was folowing this doc for ldap setting - http://docs.openstack.org/admin-guide-cloud/keystone_integrate_identity_backend_ldap.html17:39
*** doug-fish has quit IRC17:40
*** tonytan4ever has quit IRC17:40
*** aix has quit IRC17:42
raiesany help on above ?17:45
*** mhickey has quit IRC17:49
stevemarbreton: how does https://review.openstack.org/#/c/257478/2 fix the fernet issue?17:51
stevemarbreton: can you update the commit message on how it fixes it, it's not immediately clear on how it does17:52
openstackgerritSteve Martinelli proposed openstack/python-keystoneclient: remove the default arguments "{}"  https://review.openstack.org/25417517:59
stevemardolphm: punt this one throgh https://review.openstack.org/#/c/254175/18:00
dolphmstevemar: +A18:00
stevemardolphm: *nod*18:04
stevemardolphm: maybe you can answer my question from above?18:04
stevemardolphm: how does https://review.openstack.org/#/c/257478/2 solve the bug?18:05
*** petertr7 is now known as petertr7_away18:06
openstackgerritAlexander Makarov proposed openstack/keystone: Unified delegation manager skeleton  https://review.openstack.org/25312418:09
dolphmstevemar: all i know is the test makes sense, and fernet must hit that check in the new code path but not the old one because trust + impersonation + fernet test fails without the fix18:10
openstackgerritAlexander Makarov proposed openstack/keystone: Trust manager using unified delegation  https://review.openstack.org/25737818:11
openstackgerritAlexander Makarov proposed openstack/keystone: Trust manager using unified delegation  https://review.openstack.org/25737818:11
*** andreykurilin__ has quit IRC18:12
*** aginwala has quit IRC18:20
*** aginwala has joined #openstack-keystone18:20
openstackgerritFernando Diaz proposed openstack/keystone: Opt-out certain Keystone Notifications  https://review.openstack.org/25378018:22
*** timcline has quit IRC18:23
*** thiagop has quit IRC18:27
bretonah18:30
bretonwill add description now18:30
stevemarbreton: thanks boss!18:31
*** vgridnev has joined #openstack-keystone18:31
*** flwang1 has quit IRC18:34
*** browne has joined #openstack-keystone18:36
openstackgerritAlexander Makarov proposed openstack/keystone: Assignment manager using unified delegation  https://review.openstack.org/25737818:38
*** ig0r_ has joined #openstack-keystone18:39
openstackgerritAlexander Makarov proposed openstack/keystone: Trust manager using unified delegation  https://review.openstack.org/25737818:40
*** aginwala has quit IRC18:41
*** david-lyle_ has joined #openstack-keystone18:42
*** raies has quit IRC18:42
openstackgerritAlexander Makarov proposed openstack/keystone: Assignment manager using unified delegation  https://review.openstack.org/25752718:42
*** spandhe has quit IRC18:43
*** david-lyle has quit IRC18:45
*** timcline has joined #openstack-keystone18:47
*** gordc has quit IRC18:48
*** dslevin_ has joined #openstack-keystone18:48
openstackgerritAlexander Makarov proposed openstack/keystone: Unified delegation model  https://review.openstack.org/20848818:55
*** doug-fish has joined #openstack-keystone18:55
*** aginwala has joined #openstack-keystone18:57
openstackgerritAlexander Makarov proposed openstack/keystone: Unified delegation migration  https://review.openstack.org/23704718:57
*** agireud has joined #openstack-keystone18:57
openstackgerritAlexander Makarov proposed openstack/keystone: Unified delegation migration  https://review.openstack.org/23704719:00
*** doug-fish has quit IRC19:00
*** doug-fish has joined #openstack-keystone19:01
*** doug-fis_ has joined #openstack-keystone19:03
*** gordc has joined #openstack-keystone19:03
*** doug-fis_ has quit IRC19:04
*** doug-fis_ has joined #openstack-keystone19:04
*** gordc has quit IRC19:04
*** doug-fish has quit IRC19:05
openstackgerritMerged openstack/python-keystoneclient: Updated from global requirements  https://review.openstack.org/25652019:07
*** tonytan4ever has joined #openstack-keystone19:09
*** gordc has joined #openstack-keystone19:10
*** diazjf has quit IRC19:15
*** alex_xu has quit IRC19:15
*** alex_xu has joined #openstack-keystone19:16
*** pwp has joined #openstack-keystone19:18
*** EinstCrazy has joined #openstack-keystone19:18
*** fawadkhaliq has quit IRC19:23
*** diazjf has joined #openstack-keystone19:23
*** roxanaghe has joined #openstack-keystone19:24
*** EinstCrazy has quit IRC19:25
*** woodster_ has joined #openstack-keystone19:26
*** topol has joined #openstack-keystone19:26
*** ChanServ sets mode: +v topol19:26
*** petertr7_away is now known as petertr719:27
openstackgerritBoris Bobrov proposed openstack/keystone: Verify that user is trustee only on issuing token  https://review.openstack.org/25747819:27
openstackgerritDan Nguyen proposed openstack/python-keystoneclient: Add include_subtree to role_list_assignments call  https://review.openstack.org/18818419:30
*** gwei3 has joined #openstack-keystone19:32
*** fangxu has joined #openstack-keystone19:32
*** gsilvis has quit IRC19:32
openstackgerritAlexander Makarov proposed openstack/keystone: Assignment manager using unified delegation  https://review.openstack.org/25752719:33
openstackgerritTom Cocozzello proposed openstack/keystone: List assignments with names  https://review.openstack.org/24995819:37
*** petertr7 is now known as petertr7_away19:38
*** gsilvis has joined #openstack-keystone19:39
openstackgerritwerner mendizabal proposed openstack/keystone-specs: Multifactor Authentication  https://review.openstack.org/13037619:41
openstackgerritAlexander Makarov proposed openstack/keystone: Assignment manager using unified delegation  https://review.openstack.org/25752719:42
*** gwei3 has quit IRC19:43
*** gwei3 has joined #openstack-keystone19:43
*** tonytan4ever has quit IRC19:43
openstackgerritayoung proposed openstack/keystone-specs: Service Catalog Subsets by ID  https://review.openstack.org/16090919:44
*** albertom has quit IRC19:45
*** gwei3 has quit IRC19:45
*** maxabidi has joined #openstack-keystone19:50
*** e0ne has quit IRC19:51
*** pwp has quit IRC19:51
*** e0ne has joined #openstack-keystone19:52
*** albertom has joined #openstack-keystone19:52
*** rderose has joined #openstack-keystone19:53
*** rderose has quit IRC19:55
*** rderose has joined #openstack-keystone19:55
notmorganstevemar: gonna take a swing at making devstack use the new bootstrap commands I think19:58
*** tonytan4ever has joined #openstack-keystone20:04
stevemarnotmorgan: do it up20:06
crinklenotmorgan: i'm trying to test out the bootstrap thing, and it seems to work but trying to use it to do things like list or create users returns "The service catalog is empty."20:07
crinklenotmorgan: what am I doing wrong?20:07
*** david-lyle_ has quit IRC20:10
*** david-lyle has joined #openstack-keystone20:12
notmorgancrinkle: so that bootstrap just creates an initial user20:15
notmorgancrinkle: so you need to still do the explicit endpoint setting after auth for the rest of things like endpoint20:15
notmorganand service creation20:15
*** raildo is now known as raildo-afk20:15
notmorgancrinkle: i'll spin up  quick example of it here in a moment.20:16
crinklenotmorgan: so I still need to use the auth token to create an endpoint and service?20:19
notmorgancrinkle: you'll need to do an explciit endpoint auth, will be easier to show give me a moment20:20
crinklenotmorgan: sure20:20
*** dslevin_ has quit IRC20:21
stevemarcrinkle: so in the current install docs, when you first setup keystone, you gotta setup endpoints and services using the admin_token right?20:22
notmorganstevemar: today that is how it is done20:22
stevemarnotmorgan: that's why i wrote 'current install docs'!20:22
stevemarcrinkle: if you boostrap, you should have an admin user that is capable of creating the endpoints and services, in lieu of using the admin_token, the deployer could just use the newly made admin user20:23
*** rderose has quit IRC20:25
crinklestevemar: I think I need to see notmorgan's example, because the only way I know to create an endpoint is with --os-token/--os-url or --os-password/--os-auth-url, one requires the token and one requires an endpoint already be created20:27
stevemarcrinkle: damn! and i was so proud of my wording20:27
crinklestevemar: sorry :)20:27
stevemarcrinkle: we'll wait for notmorgan :)20:27
stevemari think, in the end, this means we can remove auth_token from the pipeline by default20:28
*** flwang1 has joined #openstack-keystone20:28
*** dims has joined #openstack-keystone20:29
dstanekstevemar: notmorgan: that would be very nice and make some of my test setup scripts more readable20:31
stevemardstanek: aye aye20:31
stevemardstanek: but we need a way to get the IDs, otherwise scripts will still be a PITA20:32
*** fangxu has quit IRC20:32
crinklenotmorgan: stevemar oh! i can do openstack token issue with the admin user and then i have what i need :)20:32
dstanekcrinkle: right, you'll have an admin that you can use to do normal keystone operations including all the bootstrap stuff20:33
notmorgancrinkle: that is what i was going to be doing20:34
notmorgancrinkle: so.. yes20:34
crinklecool, it's clicking now20:34
crinklenotmorgan: ty20:34
*** Guest68185 has quit IRC20:35
*** timcline has quit IRC20:39
*** timcline has joined #openstack-keystone20:40
henrynashdstanek, stevemar, notmorgan: relatively simple refactoring to reuse existing code, that would be nice to get in: https://review.openstack.org/#/c/242513/20:42
notmorgani think i'll have a fully working sub-url mounted openstack today20:44
notmorganwheeeeee20:44
* notmorgan has to fix some nova things.20:44
notmorganbut it's close20:44
bknudsonrelated devstack change: https://review.openstack.org/#/c/193894/20:48
bknudsonnotmorgan: were you updating devstack?20:48
stevemarcrinkle: \o/20:49
stevemarhenrynash: looking!20:49
henrynashstevemar: thx20:49
stevemarbknudson: henrynash we need to establish guidelines on stable ABI interfaces20:49
bknudsonstevemar: let's do it!20:50
stevemarbknudson: rm -rf stable_interfaces20:50
stevemarfixed!20:50
henrynashstevemar: guidelines beyond the hoops we jump though to suppoer the old driver interface?20:51
stevemarbknudson: henrynash https://etherpad.openstack.org/p/keystone-stable-interface-guidelines20:52
dstanekhenrynash: legacy code is terrible :-(20:52
notmorganbknudson: uhm i was planning on taking a swing at making devstack use keystone-manage bootstrap20:52
notmorganbknudson: but... otherwise no changes planned20:52
dstanekstevemar: i have some refinements to the docs that i started to make. i could probably finish them today.20:53
notmorganmore eyes on https://review.openstack.org/#/c/255599/ would be useful if that is the direction we want to go20:53
bknudsonnotmorgan: do we want devstack to use path-mounted services?20:53
notmorganbknudson: oh, ideally yes20:53
stevemardstanek: oh sure, i just started to jot ideas here: https://etherpad.openstack.org/p/keystone-stable-interface-guidelines20:53
notmorganbknudson: but i need a fully working POC first20:53
notmorganbknudson: i'm close.20:53
henrynashstevemar: btw, how to I add tox - elegacy_drivers to jenkins?20:53
stevemarhenrynash: we probably need a new job for it,20:55
notmorganstevemar: we would need a new job20:56
stevemarhenrynash: let me do that for you, you have enough things20:56
henrynashstevemar: ok, thanks :-)20:57
openstackgerritAlexander Makarov proposed openstack/keystone: Assignment manager using unified delegation  https://review.openstack.org/25752720:57
henrynashstevemarL: add me as reviewer, since I’d like to know how to do it20:57
stevemarsure20:57
*** gordc has quit IRC20:58
*** henrynash has quit IRC20:59
*** henrynash_ has joined #openstack-keystone20:59
*** ChanServ sets mode: +v henrynash_20:59
*** david-lyle has quit IRC21:01
*** harlowja has quit IRC21:04
stevemarhenrynash_: https://review.openstack.org/#/c/257566/21:05
*** aginwala has quit IRC21:06
*** harlowja has joined #openstack-keystone21:07
*** david-lyle has joined #openstack-keystone21:07
henrynash_stevemar: what does the branch: ^(?!stable/(kilo|liberty).*$ part mean in layout.yaml?21:07
bknudsonhenrynash_: keeps the job from running on stable branches21:08
bknudsonthe job would fail since there's no tox target for it on the old branches21:08
henrynash_stevemar: ah, right, got it! thx21:08
*** dslevin_ has joined #openstack-keystone21:09
openstackgerritMerged openstack/python-keystoneclient: remove the default arguments "{}"  https://review.openstack.org/25417521:10
*** tsymanczyk has joined #openstack-keystone21:10
*** tsymanczyk is now known as Guest6591521:10
*** harlowja_ has joined #openstack-keystone21:11
stevemarhenrynash_: easy as 1-2-3!21:11
henrynash_cue that song…so-re-mi21:12
*** david-lyle has quit IRC21:12
henrynash_do-re-mi even21:12
*** harlowja has quit IRC21:13
*** andreykurilin__ has joined #openstack-keystone21:13
*** jamielennox|away is now known as jamielennox21:17
anteayahenrynash_: I'm happy with 257566 now21:19
anteayahenrynash_: you ask good questions21:19
*** e0ne has quit IRC21:20
*** gordc has joined #openstack-keystone21:20
henrynash_anteya: good21:21
*** e0ne has joined #openstack-keystone21:23
*** aginwala has joined #openstack-keystone21:23
*** alex_xu has quit IRC21:25
*** alex_xu has joined #openstack-keystone21:27
dstanekhenrynash_: what was that refactoring review you wanted me to take a look at? i just blew up my trello board so i lost priority ordering21:35
henrynash_dstanek: https://review.openstack.org/#/c/242513/ thanks21:38
dstanekhenrynash_: thx21:38
*** e0ne has quit IRC21:40
*** fangxu has joined #openstack-keystone21:43
openstackgerritDave Chen proposed openstack/keystone: Update `developing.rst` to remove extensions stuff  https://review.openstack.org/25757321:45
*** alex_xu has quit IRC21:45
davechenstevemar: fyi, i did something in devstack to remove the support for keystone extensions - https://review.openstack.org/#/c/257548/21:47
*** alex_xu has joined #openstack-keystone21:48
openstackgerritDan Nguyen proposed openstack/python-keystoneclient: Add include_subtree to role_list_assignments call  https://review.openstack.org/18818421:50
stevemarthanks davechen, i'll look soon21:51
*** chlong has quit IRC21:51
*** petertr7_away is now known as petertr721:53
davechenstevemar: i am not asking for review, keep your eyes on something important, just a heads up. :)21:56
*** opilotte_ has quit IRC22:04
*** opilotte_ has joined #openstack-keystone22:05
*** timcline has quit IRC22:07
*** opilotte_ has quit IRC22:09
*** opilotte_ has joined #openstack-keystone22:11
*** aginwala has quit IRC22:14
*** jasonsb has quit IRC22:16
openstackgerritKen'ichi Ohmichi proposed openstack/keystone: Enable os_inherit of Keystone v3 API  https://review.openstack.org/25758022:16
*** aginwala has joined #openstack-keystone22:22
*** gildub has joined #openstack-keystone22:26
*** petertr7 is now known as petertr7_away22:26
*** rdo has quit IRC22:28
*** rdo has joined #openstack-keystone22:30
*** EinstCrazy has joined #openstack-keystone22:36
*** lhcheng has joined #openstack-keystone22:36
*** ChanServ sets mode: +v lhcheng22:36
*** vgridnev has quit IRC22:38
*** david-lyle has joined #openstack-keystone22:39
*** tonytan4ever has quit IRC22:40
*** EinstCrazy has quit IRC22:42
*** jasonsb has joined #openstack-keystone22:45
*** lhcheng has quit IRC22:46
*** lhcheng has joined #openstack-keystone22:46
*** ChanServ sets mode: +v lhcheng22:46
*** agireud has quit IRC22:50
*** diazjf has quit IRC22:51
*** lhcheng has quit IRC22:51
*** jamielennox is now known as jamielennox|away23:01
stevemarhenrynash_: your patches for using the assignment table were wonderful to review!23:01
*** jamielennox|away is now known as jamielennox23:01
openstackgerritJorge Munoz proposed openstack/keystone: Reduce revoke events for disabled domains and projects.  https://review.openstack.org/25327323:03
openstackgerritJorge Munoz proposed openstack/keystone: Reduce revoke events for disabled domains and projects.  https://review.openstack.org/25327323:03
*** chlong has joined #openstack-keystone23:05
*** gordc has quit IRC23:09
openstackgerritDan Nguyen proposed openstack/python-keystoneclient: Add include_subtree to role_list_assignments call  https://review.openstack.org/18818423:15
*** doug-fis_ has quit IRC23:18
*** doug-fish has joined #openstack-keystone23:18
*** csoukup has quit IRC23:19
*** doug-fis_ has joined #openstack-keystone23:20
*** doug-fis_ has quit IRC23:21
*** doug-fis_ has joined #openstack-keystone23:22
*** jasonsb has quit IRC23:22
*** sigmavirus24 is now known as sigmavirus24_awa23:22
*** doug-fish has quit IRC23:23
*** davechen has left #openstack-keystone23:24
*** pumaranikar has quit IRC23:31
*** pumaranikar has joined #openstack-keystone23:32
*** jasonsb has joined #openstack-keystone23:34
stevemargyee: is this patch resolved? https://bugs.launchpad.net/keystone/+bug/143740723:38
openstackLaunchpad bug 1437407 in OpenStack Identity (keystone) "With using V3 cloud admin policy, domain admin unable to list role assignment for projects in his domain" [Medium,In progress] - Assigned to Guang Yee (guang-yee)23:38
*** pumaranikar has quit IRC23:39
*** jasonsb has quit IRC23:39
openstackgerritayoung proposed openstack/keystone: Updated Cloudsample  https://review.openstack.org/24072023:39
*** jasonsb has joined #openstack-keystone23:41
*** doug-fis_ has quit IRC23:43
*** maxabidi has quit IRC23:44
*** aginwala has quit IRC23:51
*** slberger1 has left #openstack-keystone23:52
*** aginwala has joined #openstack-keystone23:54
*** pumaranikar has joined #openstack-keystone23:54
*** markvoelker has quit IRC23:55
*** jaosorior has quit IRC23:57

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!