Wednesday, 2016-05-25

*** lhcheng has quit IRC00:03
*** markvoelker has joined #openstack-keystone00:12
*** markvoelker has quit IRC00:16
*** spzala has quit IRC00:18
*** spzala has joined #openstack-keystone00:18
*** tqtran has quit IRC00:21
*** spzala has quit IRC00:23
openstackgerritguang-yee proposed openstack/keystonemiddleware: Determine project name from oslo_config or local config  https://review.openstack.org/32012300:33
openstackgerritguang-yee proposed openstack/keystonemiddleware: Make sure audit can handle API requests which does not require a token  https://review.openstack.org/32072500:33
*** rderose_ has joined #openstack-keystone00:36
jamielennoxgyee: i was playing around with something like that yesterday, reviews started here: https://review.openstack.org/#/c/319715/00:37
patchbotjamielennox: patch 319715 - keystonemiddleware - Create a Config object00:37
jamielennoxgyee: my thought was that we could abstract a config object out of keystonemiddleware that could then be used by all the keystone middlewares00:38
gyeejamielennox, yes, I was thinking of the same thing00:38
gyeeit can be shared by all keystone middleware00:39
jamielennoxyep, so that one just extracts the object so we'd have to give it a bit more smarts for things like config group - but that step would be fairly easy00:40
gyeenot just config, but utilities such as _determine_project, setting user_agent, _determine_version, etc00:40
jamielennoxyep, well the follow on patch to that rolls that all up into a user_agent @property that you can use00:41
gyeejamielennox, should we fix audit middleware first, then refactor? Or you prefer the reverse?00:42
gyeeI am fine either way00:42
jamielennoxgyee: depends how long it takes to get the refactor approved00:42
gyeeI am sorta under-the-gun to get audit working for Swift :-)00:43
jamielennoxgyee: i think you're in trouble right? because you can't configure messaging or anything without a real CONF object and swift doesn't have one00:45
gyeeright, right now they can get around that by putting them in proxy-server.conf00:45
gyeeso _conf_get() is a reasonable workaround00:45
*** spzala has joined #openstack-keystone00:47
gyeeI basically copied that logic from auth_token, minus the local_oslo_config stuff00:47
jamielennoxyea, i'm not a fan of that either00:48
jamielennoxbut still what is creating the global CONF object?00:48
jamielennoxdo you have your own middleware in place?00:48
gyeeI can roll a franken-audit middleware if I have to, but I rather fix it upstream00:49
*** BjoernT has joined #openstack-keystone00:57
*** timcline has joined #openstack-keystone01:02
*** timcline has quit IRC01:02
*** timcline has joined #openstack-keystone01:03
*** markvoelker has joined #openstack-keystone01:13
*** markvoelker has quit IRC01:17
*** ngupta has joined #openstack-keystone01:20
*** sheel has joined #openstack-keystone01:21
*** woodster_ has quit IRC01:28
*** EinstCrazy has joined #openstack-keystone01:30
ayoungjamielennox, I fixed Rippowam to work with Keycloak.01:33
*** spzala has quit IRC01:33
*** ngupta has quit IRC01:35
*** sdake has joined #openstack-keystone01:39
*** cheran has quit IRC01:40
jamielennoxayoung: oh, nice - i tried to run a version of it the other day to test some saml stuff01:49
jamielennoxit's still tied into a number of internal repos01:49
jamielennoxand has a few assumptions i couldn't match01:49
jamielennoxassumptions that are because i don't really have an openstack env to set up machines on :(01:50
ayoungjamielennox, yeah, it is still OSP based..haven;'t even looked at what version.  I'd like to make sure it runs with RDO first, and then do OSP9/10 afterwards01:50
jamielennoxayoung: it'd be good if we could use some of that as the basis for some saml functional testing01:50
ayoungjamielennox, that is one goal01:51
ayoungtripleo + IPA + Keycloak01:51
jamielennoxbecause i looked at OSA's openstack-kyestone module and it's super tied to ubuntu and some IDP that i don't know about01:51
ayoungI need to split the packstack role into packstack-vanilla and "everything after"01:51
jamielennoxoh yea, that was the other side of it - i didn't really want to deploy an entire packstack01:52
ayoungI had something sort-of working with OOO Quickstart, but it broke the other day so jdennis and I just pushed through getting Keycloak working with Rippowam,01:52
*** sdake_ has joined #openstack-keystone01:52
ayoungI'm running another test now, to make sure I kick over the apache server after setting up the SAML routes, and then I'll push/01:53
jamielennoxyea, if i didn't have the hardware to test packstack i definetly don't for OOO01:53
*** sdake has quit IRC01:53
ayoungjamielennox, heh.  If you can't do packstack, what are you developing with?01:53
jamielennoxat the time i wanted just keystone for some saml and eventually k2k tests01:54
jamielennoxi had some ansible for that but who knows where it went01:54
*** diazjf has joined #openstack-keystone01:54
jamielennoxso i was hoping to just do IPA + keystone01:54
jamielennoxgit preferable but RPM ok01:54
*** timcline has quit IRC01:56
ayoungjamielennox, So the rippowam code for IPA would work.  But all of the service customization would be a pain01:56
*** diazjf has quit IRC01:56
ayoungI guess we could split out the Keystone+IPA stuff into its own role01:56
jamielennoxayoung: yep, thats about where i got to01:56
*** spzala has joined #openstack-keystone01:57
ayoungnotmorgan, https://review.openstack.org/#/c/311652/ looks good, with a failure that does not look related to the cache...ran out of hosts to run things on?01:57
patchbotayoung: patch 311652 - keystone - Replace revoke tree with linear search01:57
*** rbridgeman has joined #openstack-keystone02:02
*** julim has joined #openstack-keystone02:04
*** sdake_ has quit IRC02:09
*** iurygregory_ has joined #openstack-keystone02:12
*** gyee has quit IRC02:39
rderose_seeing a lot of patches failing: keystone-coverage-db FAILURE02:42
rderose_is this being worked on?02:43
rderose_or does anyone know why this is failing?02:44
*** agrebennikov has quit IRC03:07
*** rbridgeman has quit IRC03:08
*** BjoernT has quit IRC03:14
*** sdake has joined #openstack-keystone03:15
*** rderose_ has quit IRC03:18
*** tonytan_brb has joined #openstack-keystone03:26
*** lhcheng has joined #openstack-keystone03:27
*** ChanServ sets mode: +v lhcheng03:27
*** sdake has quit IRC03:27
*** tonytan4ever has quit IRC03:29
*** spzala has quit IRC03:34
*** sheel has quit IRC03:35
*** tonytan_brb has quit IRC03:35
*** ayoung has quit IRC03:42
*** sdake has joined #openstack-keystone03:44
*** sheel has joined #openstack-keystone03:46
*** rderose_ has joined #openstack-keystone03:49
openstackgerritMerged openstack/keystone: remove deprecated revoke_by_expiration function  https://review.openstack.org/27113503:57
*** links has joined #openstack-keystone04:01
*** richm has quit IRC04:14
*** TxGVNN has joined #openstack-keystone04:17
*** iurygregory_ has quit IRC04:25
*** lhcheng_ has joined #openstack-keystone04:50
*** jamielennox is now known as jamielennox|away04:50
*** lhcheng has quit IRC04:52
*** jaosorior has joined #openstack-keystone04:59
*** jamielennox|away is now known as jamielennox05:04
*** sdake_ has joined #openstack-keystone05:11
*** GB21 has joined #openstack-keystone05:13
*** dave-mccowan has quit IRC05:13
*** rderose_ has quit IRC05:13
*** sdake has quit IRC05:13
*** rderose_ has joined #openstack-keystone05:27
*** rderose_ has quit IRC05:27
*** agrebennikov has joined #openstack-keystone05:42
*** agrebennikov has quit IRC05:47
*** jamielennox is now known as jamielennox|away05:54
*** daemontool has joined #openstack-keystone05:54
*** ig0r_ has joined #openstack-keystone06:01
*** lhcheng has joined #openstack-keystone06:06
*** ChanServ sets mode: +v lhcheng06:06
*** agrebennikov has joined #openstack-keystone06:07
*** lhcheng_ has quit IRC06:09
*** jamielennox|away is now known as jamielennox06:10
*** ig0r_ has quit IRC06:17
*** jamielennox is now known as jamielennox|away06:21
*** rcernin has joined #openstack-keystone06:21
*** furface has quit IRC06:24
*** furface has joined #openstack-keystone06:26
*** jamielennox|away is now known as jamielennox06:28
*** belmoreira has joined #openstack-keystone06:36
*** henrynash has joined #openstack-keystone06:38
*** ChanServ sets mode: +v henrynash06:38
*** tesseract has joined #openstack-keystone06:47
*** pnavarro has joined #openstack-keystone07:10
*** pnavarro has quit IRC07:17
*** pnavarro has joined #openstack-keystone07:18
*** pnavarro has quit IRC07:18
*** pnavarro has joined #openstack-keystone07:18
*** hoonetorg has quit IRC07:43
*** jaosorior has quit IRC07:45
*** chlong has quit IRC07:46
*** lhcheng has quit IRC07:48
*** pnavarro has quit IRC07:55
*** sdake_ has quit IRC07:56
*** pnavarro has joined #openstack-keystone07:56
*** hoonetorg has joined #openstack-keystone07:56
*** zzzeek has quit IRC08:00
*** zzzeek has joined #openstack-keystone08:00
*** daemontool_ has joined #openstack-keystone08:07
*** daemontool_ has quit IRC08:09
*** daemontool_ has joined #openstack-keystone08:09
*** daemontool has quit IRC08:10
openstackgerritDavanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c  https://review.openstack.org/31843508:10
openstackgerritDavanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c  https://review.openstack.org/31843508:10
*** ig0r_ has joined #openstack-keystone08:20
*** fhubik has joined #openstack-keystone08:23
*** dmk0202 has joined #openstack-keystone08:28
*** _fortis has quit IRC08:32
*** brad[] has quit IRC08:36
*** brad[] has joined #openstack-keystone08:37
*** sdake has joined #openstack-keystone08:43
*** jaosorior has joined #openstack-keystone08:47
*** sdake has quit IRC08:49
*** sdake has joined #openstack-keystone08:51
*** markvoelker has joined #openstack-keystone09:03
*** sdake has quit IRC09:05
*** markvoelker has quit IRC09:08
*** henrynash has quit IRC09:10
*** daemontool_ has quit IRC09:19
*** daemontool_ has joined #openstack-keystone09:19
*** mvk has quit IRC09:22
*** ygl has joined #openstack-keystone09:35
yglHI All09:35
ygli need soem information09:35
ygli am querying the keystone server from a keystone client using --insecure option09:36
yglhow can I make it secure ?09:36
yglcan anyone help me  please ?09:47
*** fhubik has quit IRC09:48
*** tlbr has quit IRC09:49
*** tlbr has joined #openstack-keystone09:52
*** mvk has joined #openstack-keystone09:55
*** markvoelker has joined #openstack-keystone10:04
*** GB21 has quit IRC10:05
*** EinstCrazy has quit IRC10:09
*** markvoelker has quit IRC10:09
*** EinstCrazy has joined #openstack-keystone10:09
*** EinstCrazy has quit IRC10:14
*** rk4n has joined #openstack-keystone10:15
*** TxGVNN has quit IRC10:19
*** mkoshiya has joined #openstack-keystone10:19
mkoshiyaHi, all. could you please review bp/return-request-id-to-caller - https://review.openstack.org/#/c/261188/ and Related Changes.10:22
patchbotmkoshiya: patch 261188 - python-keystoneclient - Add wrapper classes for return-request-id-to-caller10:22
openstackgerritJulien Danjou proposed openstack/keystone: Install necessary files in etc/  https://review.openstack.org/32088010:22
*** al_loew has joined #openstack-keystone10:23
dstanekygl: are you using SSL with a cert that can be validated?10:24
ygldstanek: how and where can I enable it or install it ?10:25
*** mkoshiya has quit IRC10:33
*** ygl has quit IRC10:35
*** _amrith_ is now known as amrith10:40
*** al_loew has quit IRC10:57
*** GB21 has joined #openstack-keystone10:59
*** markvoelker has joined #openstack-keystone11:05
*** markvoelker has quit IRC11:10
*** vnogin has joined #openstack-keystone11:14
*** openstackgerrit has quit IRC11:18
*** openstackgerrit has joined #openstack-keystone11:18
*** gordc has joined #openstack-keystone11:28
*** belmoreira has quit IRC11:31
openstackgerritBertrand Lallau proposed openstack/python-keystoneclient: Remove unused iso8601 requirement  https://review.openstack.org/32091411:32
*** GB21 has quit IRC11:34
*** GB21 has joined #openstack-keystone11:50
*** jaosorior has quit IRC11:56
*** jaosorior has joined #openstack-keystone11:57
*** jamielennox is now known as jamielennox|away11:58
*** jaosorior has quit IRC11:58
*** jaosorior has joined #openstack-keystone11:59
*** rderose has joined #openstack-keystone12:06
*** BlackDex_ is now known as BlackDex12:07
*** jamielennox|away is now known as jamielennox12:07
*** markvoelker has joined #openstack-keystone12:10
samueldmqnotmorgan: what have you and ayoun found out about patch 311652?12:13
patchbotsamueldmq: https://review.openstack.org/#/c/311652/ - keystone - Replace revoke tree with linear search12:13
*** GB21 has quit IRC12:19
*** amrith is now known as _amrith_12:30
*** henrynash has joined #openstack-keystone12:30
*** ChanServ sets mode: +v henrynash12:30
*** ddieterly has joined #openstack-keystone12:33
*** ddieterly has quit IRC12:35
*** ddieterly has joined #openstack-keystone12:35
*** markvoelker has quit IRC12:42
*** markvoelker has joined #openstack-keystone12:48
notmorgansamueldmq: i am with gyee... make it do the work in the db. but i can only argue so much.12:49
*** pauloewerton has joined #openstack-keystone12:58
*** ddieterly has quit IRC12:59
*** edmondsw has joined #openstack-keystone12:59
*** ayoung has joined #openstack-keystone13:01
*** ChanServ sets mode: +v ayoung13:01
*** belmoreira has joined #openstack-keystone13:02
*** ig0r__ has joined #openstack-keystone13:06
yolandahi notmorgan, and other keystone cores, can i get review for https://review.openstack.org/320340 ?13:06
*** dave-mccowan has joined #openstack-keystone13:07
*** ig0r_ has quit IRC13:08
*** zqfan has quit IRC13:13
*** zqfan has joined #openstack-keystone13:15
*** henrynash has quit IRC13:15
*** henrynash has joined #openstack-keystone13:15
*** ChanServ sets mode: +v henrynash13:15
*** jaosorior has quit IRC13:23
openstackgerrithenry-nash proposed openstack/keystone-specs: Microversions  https://review.openstack.org/31518013:27
*** ddieterly has joined #openstack-keystone13:30
*** al_loew has joined #openstack-keystone13:35
*** al_loew has quit IRC13:35
*** ddieterly is now known as ddieterly[away]13:36
*** al_loew has joined #openstack-keystone13:37
*** _amrith_ is now known as amrith13:41
*** BjoernT has joined #openstack-keystone13:42
*** BjoernT is now known as Bjoern_zZzZzZzZ13:42
*** richm has joined #openstack-keystone13:42
*** amrith is now known as _amrith_13:43
*** mou has joined #openstack-keystone13:43
*** _amrith_ is now known as amrith13:44
*** amrith is now known as _amrith_13:45
*** ddieterly[away] is now known as ddieterly13:46
*** tlbr has quit IRC13:47
*** links has quit IRC13:48
*** ngupta has joined #openstack-keystone13:48
*** _amrith_ is now known as amrith13:49
*** amrith is now known as _amrith_13:49
*** tlbr has joined #openstack-keystone13:49
*** phalmos has quit IRC13:49
*** _amrith_ is now known as amrith13:50
*** ametts has joined #openstack-keystone13:51
*** xek has quit IRC13:54
rodrigodsnotmorgan, https://bugs.launchpad.net/nova/+bug/1585652 was wondering if keystoneauth could treat this kind of error? but created in nova anyway13:55
openstackLaunchpad bug 1585652 in OpenStack Compute (nova) "EmptyCatalog not treated during cinderclient creation" [Undecided,New]13:55
*** Bjoern_zZzZzZzZ is now known as BjoernT14:00
*** darosale has joined #openstack-keystone14:01
*** nkinder has quit IRC14:02
*** sheel has quit IRC14:05
*** haplo37_ has joined #openstack-keystone14:10
knikollamorning keystone!14:13
dstanekknikolla: good morning14:14
*** sheel has joined #openstack-keystone14:16
tsufievhello, folks!14:17
tsufievare you aware that some recent devstack change to how keystone is deployed broke horizon?14:18
tsufievmore specifically, http://paste2.org/VHBI9vW014:18
*** timcline has joined #openstack-keystone14:18
*** gagehugo has joined #openstack-keystone14:18
rodrigodssamueldmq, henrynash, ping... should not wait the job for https://review.openstack.org/#/c/320145/ ?14:18
patchbotrodrigods: patch 320145 - keystone - Migrate identity /v3 docs from api-ref repo14:18
knikollahi dstanek! quick question. when a devstack plugin lies in the keystone tree in devstack/plugin.sh. Is it automatically called if keystone is enabled? Till now i’ve been working out of tree and had to do enable_plugin federation git://repo14:19
henrynashrodigods: wait for what?14:19
dstanektsufiev: is that due to the wrong API version?14:20
rodrigodshenrynash, ah ok, the job has been merged: https://review.openstack.org/#/c/320486/14:20
patchbotrodrigods: patch 320486 - openstack-infra/project-config - Add api-ref job for keystone14:20
rodrigodshenrynash, so it should run before merge that patch ^14:20
dstanekknikolla: i'm not really sure. i thought it was automatically called, but #openstack-qa would have the best answer14:21
*** nkinder has joined #openstack-keystone14:21
tsufievdstanek, how could I check if it's wrong?14:21
knikollatsufiev: is there a v3 or v2.0 at the end of the auth url?14:22
henrynashrodigods: ah, I see what you mean….I *think* we’re Ok…..14:22
tsufievknikolla, v314:22
*** henrynash has quit IRC14:23
tsufievthe endpoint url is http://<hostip>:5000/v3, then a request is made to http://<hostip>/identity/users/<userid>/projects to return project list which results in Http40414:23
tsufievany suggestions?14:23
dstanektsufiev: with no version in that url?14:24
knikollatsufiev: http://<hostip>:5000/v3/identity/users/<userid>/projects should be the correct one i believe14:25
samueldmqrodrigods: henrynash: we need that for the job to run14:25
*** ngupta has quit IRC14:25
*** al_loew has quit IRC14:26
*** pushkaru has joined #openstack-keystone14:26
tsufievdstanek, confirmed, no version14:27
tsufievcould it be the case that django_openstack_auth is behind some important keystone/python-keystoneclient change?14:27
*** spzala has joined #openstack-keystone14:30
*** brad[] has quit IRC14:30
dstanektsufiev: not sure. is that a brand new devstack installation?14:31
tsufievdstanek, yes, it is14:31
dstanektsufiev: i can give that a try in a few minutes and see what happens for me14:31
dstanektsufiev: were you just tying to login to horizon when you got the error?14:32
tsufievdstanek, that would be very helpful! Horizon gate is blocked due to this issue, because all integration tests are failing14:32
bknudsonhttps://review.openstack.org/#/c/88736/ -- 434 patch sets14:32
patchbotbknudson: patch 88736 - swift - Updated from global requirements14:32
bknudsonthat must be a record14:32
openstackgerritRon De Rose proposed openstack/keystone: WIP - PCI-DSS Change password requirements  https://review.openstack.org/32015614:32
dstanekbknudson: lol, i saw that on the list this morning14:33
tsufievyes, once I log into it, there is an error 'Unable to get projects list'14:33
dstanekbknudson: maybe you know the solution to tsufiev's problem off the top of your head?14:33
*** phalmos has joined #openstack-keystone14:35
bknudsondstanek: tsufiev: I don't know the solution off the top of my head. The change was to have users prefer the  http://<hostip>/identity endpoint, so this is what keystone advertises.14:36
dstanekit looks like something is just not constructing the urls correctly then14:36
*** amakarov_away is now known as amakarov14:38
bknudsona lot of applications seem to try way too hard to manipulate urls14:38
tsufievlooks like the url is constructed inside keystoneclient14:39
*** ddieterly is now known as ddieterly[away]14:44
tsufievwell, my overall impression is that something in new devstack setup doesn't work particularly well with keystoneclient and django_openstack_auth14:45
knikollatsufiev: bknudson: would this have anything to do with it? https://github.com/openstack/django_openstack_auth/blob/master/openstack_auth/utils.py#L25714:48
*** iurygregory is now known as iury_afk14:48
bknudsonknikolla: that looks broken to begin with.14:50
bknudsonjust based on the comment14:50
bknudsonthis is why keystone provides version discovery14:50
*** EinstCrazy has joined #openstack-keystone14:50
*** ddieterly[away] is now known as ddieterly14:53
*** jaugustine has joined #openstack-keystone14:55
bknudsonrequested a new release of keystone mitaka since the previous release never made it to the tarball download site: https://review.openstack.org/#/c/321044/14:57
patchbotbknudson: patch 321044 - releases - keystone 9.0.2 (mitaka)14:57
tsufievknikolla, bknudson: no, it doesn't seem to be the root cause15:00
tsufieveven if I entirely omit whole function contents (replacing with 'return auth_url' at the beginning), the issue is still there15:01
*** amrith is now known as _amrith_15:01
*** EinstCrazy has quit IRC15:02
tsufievbesides that, if I remove keystone endpoint version suffix from horizon config, I cannot authenticate at all15:03
tsufievDEBUG:keystoneauth.identity.v3.base:Making authentication request to http://192.168.33.12:5000/auth/tokens15:04
tsufievDEBUG:keystoneauth.session:Request returned failure status: 40415:04
*** _amrith_ is now known as amrith15:04
tsufievthat's ^^^ what happens if I remove version suffix15:04
*** amrith is now known as _amrith_15:05
*** sdake has joined #openstack-keystone15:09
*** _amrith_ is now known as amrith15:09
*** yolanda_ has joined #openstack-keystone15:10
*** EinstCrazy has joined #openstack-keystone15:11
*** GB21 has joined #openstack-keystone15:11
openstackgerritMikhail Nikolaenko proposed openstack/keystone: Added app for policy enforcement  https://review.openstack.org/31752915:12
openstackgerritMerged openstack/keystone: Migrate identity /v3 docs from api-ref repo  https://review.openstack.org/32014515:12
*** EinstCrazy has quit IRC15:13
*** sdake_ has joined #openstack-keystone15:13
*** sdake has quit IRC15:13
openstackgerritMerged openstack/keystone: Replace revoke tree with linear search  https://review.openstack.org/31165215:13
*** belmoreira has quit IRC15:14
*** ddieterly is now known as ddieterly[away]15:14
*** bknudson has left #openstack-keystone15:15
*** daemontool_ has quit IRC15:16
*** ddieterly[away] is now known as ddieterly15:17
*** ngupta has joined #openstack-keystone15:17
*** EinstCrazy has joined #openstack-keystone15:18
*** EinstCrazy has quit IRC15:19
*** EinstCrazy has joined #openstack-keystone15:19
ayoungTHE TREE IS DEAD!  https://review.openstack.org/#/c/311652/15:20
patchbotayoung: patch 311652 - keystone - Replace revoke tree with linear search (MERGED)15:20
*** yolanda has quit IRC15:20
*** EinstCrazy has quit IRC15:22
*** pushkaru has quit IRC15:24
*** EinstCrazy has joined #openstack-keystone15:25
*** EinstCrazy has quit IRC15:26
*** roxanaghe has joined #openstack-keystone15:27
*** bknudson has joined #openstack-keystone15:28
*** ChanServ sets mode: +v bknudson15:28
*** EinstCrazy has joined #openstack-keystone15:28
*** roxanaghe has quit IRC15:31
*** ngupta has quit IRC15:32
*** sdake_ has quit IRC15:34
*** EinstCrazy has quit IRC15:35
tsufievfolks, I created a bug https://bugs.launchpad.net/keystone/+bug/1585682 to track recent Horizon/Keystone Devstack issue15:35
openstackLaunchpad bug 1585682 in OpenStack Dashboard (Horizon) "Horizon gating on dsvm-integration job is broken due to recent changes in devstack/keystone" [Critical,New]15:35
*** rderose has quit IRC15:39
*** rderose has joined #openstack-keystone15:44
*** dmk0202 has quit IRC15:49
*** SamYaple has quit IRC15:50
*** SamYaple has joined #openstack-keystone15:52
*** rk4n has quit IRC15:53
*** jaugustine has quit IRC15:53
*** timcline has quit IRC15:59
*** tonytan4ever has joined #openstack-keystone16:00
*** henrynash has joined #openstack-keystone16:02
*** ChanServ sets mode: +v henrynash16:02
notmorgantsufiev: i'm going to bet this is an issue with devstack change16:02
notmorgantsufiev: i think the "prefer web ports" change landed yesterday16:03
*** woodster_ has joined #openstack-keystone16:03
notmorganbknudson: ^ cc on that16:03
bknudsonnotmorgan: revert the change?16:03
notmorganbknudson: not my 1st choice16:03
*** tonytan4ever has quit IRC16:03
notmorganbknudson: just trying to chase down why/what can be fixed if possible first16:04
notmorganbknudson: that is just what it looks like16:04
*** rcernin has quit IRC16:04
* notmorgan is really really against the "OMG REVERT" mode we tend to go with16:04
notmorgani much prefer fail forwards.16:05
openstackgerritRon De Rose proposed openstack/keystone: WIP - PCI-DSS Change password requirements  https://review.openstack.org/32015616:05
bknudsonI'd prefer to have lots of time to work upstream, too, but that's not the case now.16:05
notmorganbknudson: if i didn't have non-work things to deal with right now, i'd chase this down.16:06
notmorganbknudson: but i do :(16:06
notmorganif the only answer is revert... then ping sdague, and revert the change [if it fixes things]16:06
bknudsonI won't have time to work on this, so unless somebody else can work on it then revert is the quickest.16:07
notmorgan@all, anyone willing to chase this down ^ it is likely related to issues with using non-web ports16:08
tsufievnotmorgan, bknudson: what do you think of running horizon integration tests for changes like this in devstack?16:09
david-lyletsufiev: eek16:09
notmorgantsufiev: this has been an on-going issue with the decoupling of tests.16:09
bknudsontsufiev: if you don't want horizon to be broken by devstack changes then run tests.16:09
tsufievhm...16:10
notmorganthe more we decouple the integrated gate the more this is possible16:10
notmorganwe really don't have that many issues16:10
notmorganbut basically you're asking to go back to the integrated gate16:10
bknudsonwe have an issue every time we change keystone config16:10
notmorganbknudson: and it is with a different project16:10
*** links has joined #openstack-keystone16:10
tsufievI think it is still the way it's functioning16:10
*** daemontool has joined #openstack-keystone16:10
tsufievI thought*16:11
notmorgantsufiev: not exactly16:11
notmorganit may also be a stacking issue, keystoneclient change on top of keystone changes on top of devstack changes16:11
notmorganbut it seems devstack changes for keystone tend to break the world because of where we sit in the stack16:12
tsufievyes, I agree, these issues could be difficult to prevent16:12
*** rk4n has joined #openstack-keystone16:12
notmorganthe other issue is that very few people seem able to chase down the keystone related issues like this (i know it's complex)16:13
tsufievdavid-lyle, people in horizon community tend to think 'omg, tests are broken again', when actually that's not their fault at all :(16:13
notmorganbut we can't be "everywhere"16:13
david-lyletsufiev: not always, no16:13
notmorganand can't solve every single issue with every other project around identity16:13
notmorgani do think we do a reasonable job at it though.16:13
*** tesseract has quit IRC16:13
david-lylebut the effective pass rate needs to be much more consistent16:13
notmorgani just don't have a good anwerr16:13
notmorgani also can't guarantee tht issue is the devstack change16:14
notmorganwhen did it start happening?16:14
tsufievnotmorgan, np, I was just thinking how to make overall test pass rate more predictable and prevent situation like that...16:14
tsufievI would say it started yesterday16:14
*** roxanaghe has joined #openstack-keystone16:15
tsufievor even more recently, like 8-10 hours ago16:15
notmorgantsufiev: i just marked the keystone side incomplete, please get us a logstash query showing when it started16:15
notmorganand remark it "new" and ping us. it will help us chase down what landed when and where this started16:16
notmorgantsufiev: especially since i don't want to play revert games if it isn't related16:16
openstackgerritRon De Rose proposed openstack/keystone: WIP - PCI-DSS Change password requirements  https://review.openstack.org/32015616:16
notmorgantsufiev: and like i said, i have non-work things to take care of pretty soon here, so i have to duck out :( or i'd offer to help more16:17
*** ddieterly is now known as ddieterly[away]16:17
*** roxanaghe has quit IRC16:18
openstackgerritRon De Rose proposed openstack/keystone: WIP - PCI-DSS Password strength requirements  https://review.openstack.org/32058616:19
*** lhcheng has joined #openstack-keystone16:19
*** ChanServ sets mode: +v lhcheng16:19
openstackgerritRon De Rose proposed openstack/keystone: WIP - PCI-DSS Password strength requirements  https://review.openstack.org/32058616:19
*** daemontool has quit IRC16:20
*** ddieterly[away] is now known as ddieterly16:20
*** roxanaghe has joined #openstack-keystone16:22
openstackgerritRon De Rose proposed openstack/keystone: WIP - PCI-DSS Password strength requirements  https://review.openstack.org/32058616:22
*** tonytan4ever has joined #openstack-keystone16:23
*** gyee has joined #openstack-keystone16:23
*** ChanServ sets mode: +v gyee16:23
openstackgerritRon De Rose proposed openstack/keystone: Add password table columns to meet PCI-DSS change password requirements  https://review.openstack.org/31428416:24
*** GB21 has quit IRC16:25
notmorganyolanda_: its on my short list - i have some stuff to takee care of non-work related first.16:26
notmorganyolanda_: (have to turn a car in today)16:27
*** roxanaghe has quit IRC16:27
*** sdake has joined #openstack-keystone16:29
openstackgerritRon De Rose proposed openstack/keystone: Add password table columns to meet PCI-DSS change password requirements  https://review.openstack.org/31428416:31
*** ddieterly is now known as ddieterly[away]16:32
openstackgerritRon De Rose proposed openstack/keystone: Add password table columns to meet PCI-DSS change password requirements  https://review.openstack.org/31428416:35
openstackgerritRon De Rose proposed openstack/keystone: WIP - PCI-DSS Change password requirements  https://review.openstack.org/32015616:36
openstackgerritRon De Rose proposed openstack/keystone: WIP - PCI-DSS Password strength requirements  https://review.openstack.org/32058616:36
*** ddieterly[away] is now known as ddieterly16:36
*** ngupta has joined #openstack-keystone16:38
*** KevinE has joined #openstack-keystone16:40
tsufievnotmorgan, entered a query and a date range about 10 minutes ago, logstash is still searching at http://logstash.openstack.org/#/dashboard/file/logstash.json16:40
tsufievanything I'm doing wrong?16:40
KevinEHow does one set the interface to 'auth'?16:41
notmorgantsufiev: you may need to adjust the timestamps.16:41
notmorgantsufiev: erm timewindow16:41
notmorgantsufiev: but it can be slow to search. there is a LOT of data16:41
tsufievlike narrowing it?16:41
notmorgantsufiev: it defaults to 15 minutes16:41
notmorgantsufiev: so you likely need to expand it16:42
tsufiev15 minutes won't say anything about the issue :/16:42
notmorganexactly16:42
tsufievokay, trying with 2 days16:42
notmorganyep16:42
KevinE I'm having a lot of trouble in keystoneclient.auth.identity.base. Even if I try setting my endpoint_type to public, it will fail to contact the ADMIN endpoint16:44
KevinEanyone got a second to help?16:45
*** jaugustine has joined #openstack-keystone16:54
*** roxanaghe has joined #openstack-keystone16:55
*** timcline has joined #openstack-keystone17:00
*** rbridgeman has joined #openstack-keystone17:02
*** rbridgeman_ has joined #openstack-keystone17:03
*** timcline has quit IRC17:04
openstackgerritRudolf Vriend proposed openstack/keystone: Allow domain admins to list users in groups with v3 policy  https://review.openstack.org/32112817:05
*** rbridgeman has quit IRC17:07
*** TxGVNN has joined #openstack-keystone17:10
*** brad[] has joined #openstack-keystone17:18
*** tonytan_brb has joined #openstack-keystone17:19
*** tonytan4ever has quit IRC17:20
*** KevinE has quit IRC17:20
*** timcline has joined #openstack-keystone17:23
*** timcline has quit IRC17:23
*** timcline has joined #openstack-keystone17:24
*** timcline has quit IRC17:24
*** TxGVNN has quit IRC17:24
*** timcline has joined #openstack-keystone17:24
*** ddieterly is now known as ddieterly[away]17:27
*** pnavarro has quit IRC17:27
*** tonytan_brb is now known as tonytan4ever17:28
*** sdake_ has joined #openstack-keystone17:33
*** ngupta has quit IRC17:33
*** sdake has quit IRC17:35
*** BjoernT is now known as Bjoern_zZzZzZzZ17:36
*** lamt has quit IRC17:37
*** rk4n has quit IRC17:39
*** rderose has quit IRC17:40
*** Bjoern_zZzZzZzZ is now known as BjoernT17:40
*** fawadkhaliq has joined #openstack-keystone17:43
*** ngupta has joined #openstack-keystone17:43
*** rderose has joined #openstack-keystone17:43
*** spzala has quit IRC17:44
*** spzala has joined #openstack-keystone17:45
*** spzala_ has joined #openstack-keystone17:48
*** spzala has quit IRC17:50
*** ig0r__ has quit IRC17:51
*** links has quit IRC17:52
*** spzala_ has quit IRC17:53
openstackgerrithenry-nash proposed openstack/keystone: Create V9 driver for identity backend  https://review.openstack.org/30531517:55
*** jed56 has quit IRC17:59
*** mou has quit IRC18:07
*** agrebennikov has quit IRC18:10
*** roxanaghe has quit IRC18:11
*** roxanaghe has joined #openstack-keystone18:12
*** mou has joined #openstack-keystone18:19
*** mvk has quit IRC18:20
*** sdake_ is now known as sdake18:23
*** fawadkhaliq has quit IRC18:23
*** ddieterly[away] is now known as ddieterly18:25
*** spzala has joined #openstack-keystone18:32
dstanektsufiev: i just created a brand new devstack and i couldn't duplicate your issue18:34
tsufievthat's weird18:34
*** sdake_ has joined #openstack-keystone18:34
tsufievlhcheng, ^^18:35
*** roxanagh_ has joined #openstack-keystone18:35
tsufievhonestly, I have no idea what's happening in the devstack right now18:35
tsufievdstanek, maybe your devstack and mine differ by a tiny commit that changes how horizon behaves )?18:36
*** sdake has quit IRC18:37
dstanektsufiev: could be. i have devstack as of 20 mins ago18:37
*** roxanaghe has quit IRC18:38
knikollacompare the latest thing in git log18:39
tsufievit seems that lhcheng has identified the root cause18:42
dstanektsufiev: was it already fixed?18:43
rodrigodshenrynash, ping re: tempest tests18:44
tsufievdstanek, no, the issue lies within django_openstack_auth and was triggered by the recent devstack change which added /identity suffix to the auth_url that django_openstack_auth receives and tries (unsuccessfully) to fix18:44
tsufievhas to be fixed yet18:44
rodrigodshenrynash, https://blueprints.launchpad.net/keystone/+spec/keystone-tempest-plugin-tests you also can ask me any doubts you may have18:44
rodrigodshenrynash, my current plan is to add a scenario test case for federation, but we first need the clients (to make the calls to keystone server), that's why i've added straight forward API tests for idp, sp and mapping18:45
dstanektsufiev: lhcheng: i wonder why i don't run into that18:47
lhchengdstanek: does your keystone run in identity context?   http://<host>/identity18:48
*** sdake_ is now known as sdake18:48
dstaneklhcheng: checking....18:50
dstaneki'm just doing whatever the default is18:50
lhchengdstanek: what is the default in devstack now? I haven't updated mine for a while18:51
dstaneklhcheng: looks like /identity is enabled, but not being used18:53
dstanekso that's why i didn't hit it18:53
*** darosale has quit IRC19:03
*** mvk has joined #openstack-keystone19:05
openstackgerritKristi Nikolla proposed openstack/keystone: WIP - Devstack plugin for Federation  https://review.openstack.org/32062319:09
*** spzala has quit IRC19:12
*** spzala has joined #openstack-keystone19:12
*** rbridgeman_ has quit IRC19:13
*** rderose has quit IRC19:15
*** flwang1 has joined #openstack-keystone19:16
*** spzala has quit IRC19:17
flwang1notmorgan: ping19:18
flwang1notmorgan: could you pls revisit https://review.openstack.org/#/c/310083/ ? thanks19:18
patchbotflwang1: patch 310083 - governance - Add stable and deprecation tags for Zaqar19:18
*** georgem1 has joined #openstack-keystone19:22
*** darosale has joined #openstack-keystone19:34
notmorganflwang1: done.19:35
*** spzala has joined #openstack-keystone19:38
flwang1notmorgan: thank you!19:38
flwang1notmorgan: btw, who can do the workflow +1? thanks19:39
*** spzala has quit IRC19:43
*** ddieterly is now known as ddieterly[away]19:43
notmorganflwang1: that is up to the TC Chair.19:46
notmorganflwang1: and this is something that will be (likey) addressed in the next TC meeting as most of these are.19:46
*** ngupta has quit IRC19:48
ayoungnotmorgan, export OS_AUTH_TYPE=v3fedkerb seems to not be working, and it was last summer.  Did we ever get a final resting place for that auth plugin?19:53
flwang1notmorgan: cool, cheers19:55
ayoungrodrigods, so If I run in debug I see19:56
ayoungoh...maybe I need to clear my other env vars...one sec19:56
ayoungDEBUG: openstackclient.api.auth Auth plugin osc_password selected19:58
ayoungits like it is missing the Kerberos one19:58
ayoungah wait...I need it on my laptop...duh19:58
*** spzala has joined #openstack-keystone19:59
*** flwang1 has quit IRC19:59
ayoungdisregard.  it works19:59
rodrigodsayoung, :)19:59
rodrigodsayoung, was hard to imagine the same plugin was working for horizon but not for cli20:00
*** zqfan has quit IRC20:03
*** spzala has quit IRC20:03
*** ayoung has quit IRC20:04
*** amrith is now known as _amrith_20:05
*** sheel has quit IRC20:05
*** ddieterly[away] is now known as ddieterly20:05
*** ddieterly is now known as ddieterly[away]20:05
*** spzala has joined #openstack-keystone20:07
*** tqtran has joined #openstack-keystone20:10
*** ddieterly[away] is now known as ddieterly20:11
*** raddaoui has joined #openstack-keystone20:12
*** darosale has quit IRC20:14
*** roxanagh_ has quit IRC20:14
*** roxanaghe has joined #openstack-keystone20:14
*** spzala has quit IRC20:16
*** nkinder has quit IRC20:18
*** nkinder has joined #openstack-keystone20:21
*** roxanaghe has quit IRC20:22
*** georgem1 has quit IRC20:25
*** KevinE has joined #openstack-keystone20:33
KevinEWould it be a bad idea to add a parameter in service_catalog.py that looks for an endpoint_override?20:34
*** mou has quit IRC20:37
*** rbridgeman_ has joined #openstack-keystone20:40
*** ngupta has joined #openstack-keystone20:40
*** sdake_ has joined #openstack-keystone20:46
*** sdake has quit IRC20:48
*** KevinE has quit IRC20:52
*** iurygregory has joined #openstack-keystone20:56
*** julim has quit IRC20:56
*** haplo37_ has quit IRC21:01
*** roxanaghe has joined #openstack-keystone21:04
*** nkinder has quit IRC21:07
*** nkinder has joined #openstack-keystone21:07
*** roxanaghe has quit IRC21:07
*** gyee has quit IRC21:07
*** daemontool has joined #openstack-keystone21:07
*** raildo is now known as raildo-afk21:09
*** georgem1 has joined #openstack-keystone21:10
*** georgem1 has quit IRC21:10
*** georgem1 has joined #openstack-keystone21:11
*** darosale has joined #openstack-keystone21:11
openstackgerritwerner mendizabal proposed openstack/keystone: Support encryption of credentials in Keystone  https://review.openstack.org/31716921:13
*** agrebennikov has joined #openstack-keystone21:14
*** clenimar has quit IRC21:14
*** pauloewerton has quit IRC21:17
*** gagehugo_ has joined #openstack-keystone21:19
harlowjanotmorgan 'Morgan Fainberg has added skills: (>^_^)>, ┬─┬ ︵ /(.□. \\), ┬─┬ ノ( ゜-゜ノ), (╯°□°)╯︵ ┻━┻, ಠ_ಠ'21:19
harlowjalol21:19
harlowja+121:19
*** ddieterly is now known as ddieterly[away]21:19
notmorganharlowja: exactly21:19
harlowjaemjoi skill21:19
*** gagehugo has quit IRC21:19
openstackgerritAndrew Laski proposed openstack/oslo.policy: Add sample file generation script and helper methods  https://review.openstack.org/31424421:20
openstackgerritAndrew Laski proposed openstack/oslo.policy: Add equality operator to policy.RuleDefault  https://review.openstack.org/32124221:20
openstackgerritAndrew Laski proposed openstack/oslo.policy: Add helper methods for generating policy info  https://review.openstack.org/32124321:20
*** gagehugo_ has quit IRC21:20
*** gagehugo has joined #openstack-keystone21:21
*** tonytan4ever has quit IRC21:21
*** roxanaghe has joined #openstack-keystone21:22
*** ddieterly[away] is now known as ddieterly21:24
*** _amrith_ is now known as amrith21:26
*** ametts has quit IRC21:28
*** daemontool has quit IRC21:31
*** henrynash has quit IRC21:34
*** flwang1 has joined #openstack-keystone21:36
*** georgem1 has quit IRC21:38
*** jaugustine has quit IRC21:39
*** edmondsw has quit IRC21:41
*** sdake_ has quit IRC21:45
*** flwang1 has quit IRC21:45
*** sdake has joined #openstack-keystone21:51
*** flwang1 has joined #openstack-keystone21:53
*** lhcheng has quit IRC21:59
*** iurygregory has quit IRC22:01
*** darosale has quit IRC22:10
*** ddieterly is now known as ddieterly[away]22:15
*** henrynash has joined #openstack-keystone22:24
*** ChanServ sets mode: +v henrynash22:24
*** sdake has quit IRC22:25
*** timcline has quit IRC22:28
*** ayoung has joined #openstack-keystone22:30
*** ChanServ sets mode: +v ayoung22:30
*** gordc has quit IRC22:31
openstackgerritMerged openstack/keystone: Add API Change Tutorial  https://review.openstack.org/30278922:35
*** ddieterly[away] is now known as ddieterly22:40
*** afred312_ has joined #openstack-keystone22:45
*** afred312 has quit IRC22:47
*** lhcheng has joined #openstack-keystone22:50
*** ChanServ sets mode: +v lhcheng22:50
*** gyee has joined #openstack-keystone22:55
*** ChanServ sets mode: +v gyee22:55
*** ngupta has quit IRC22:57
*** g2` is now known as BrAsS_mOnKeY22:59
*** ddieterly has quit IRC22:59
*** phalmos has quit IRC23:01
*** chlong has joined #openstack-keystone23:05
*** akscram has quit IRC23:07
*** harlowja has quit IRC23:12
notmorgankeystoneauth-cores: https://review.openstack.org/#/c/320340/ this should be pretty straightforward.23:16
patchbotnotmorgan: patch 320340 - keystoneauth - Update keystoneauth fixture to support v323:16
*** sdake has joined #openstack-keystone23:28
*** BjoernT has quit IRC23:30
*** rderose has joined #openstack-keystone23:30
*** henrynash has quit IRC23:33

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!