Wednesday, 2016-07-13

*** markvoelker has quit IRC00:02
*** ddieterly has joined #openstack-keystone00:04
*** adrian_otto has quit IRC00:05
*** nk2527 has quit IRC00:09
*** markvoelker has joined #openstack-keystone00:11
*** ivasilevskaya has joined #openstack-keystone00:14
*** markvoelker has quit IRC00:14
*** markvoelker has joined #openstack-keystone00:14
*** ravelar159 has joined #openstack-keystone00:21
*** daemontool has quit IRC00:21
*** roxanaghe has quit IRC00:23
*** samueldmq has quit IRC00:28
*** ddieterly is now known as ddieterly[away]00:32
*** ddieterly[away] has quit IRC00:36
*** code-R has joined #openstack-keystone00:38
openstackgerritMerged openstack/oslo.policy: Add Python 3.5 classifier and venv  https://review.openstack.org/34077700:38
*** spzala has joined #openstack-keystone00:38
*** browne has quit IRC00:39
*** code-R_ has joined #openstack-keystone00:40
*** spzala has quit IRC00:43
*** code-R has quit IRC00:43
*** ravelar159 has quit IRC00:55
*** ddieterly has joined #openstack-keystone00:55
*** code-R_ has quit IRC01:03
*** code-R has joined #openstack-keystone01:03
*** code-R_ has joined #openstack-keystone01:04
*** code-R has quit IRC01:04
*** ddieterly has quit IRC01:08
openstackgerritwerner mendizabal proposed openstack/keystone: Support encryption of credentials in Keystone  https://review.openstack.org/31716901:10
*** markvoelker has quit IRC01:25
*** EinstCrazy has joined #openstack-keystone01:28
*** clenimar_ has quit IRC01:29
*** wangqun has joined #openstack-keystone01:36
*** spzala has joined #openstack-keystone01:39
*** clenimar_ has joined #openstack-keystone01:41
*** spzala has quit IRC01:43
openstackgerritMerged openstack/keystone: PCI-DSS Disable inactive users requirements  https://review.openstack.org/32844701:51
stevemarraildo: rodrigods that one page (http://docs.cloudstack.apache.org/projects/cloudstack-administration/en/4.8/accounts.html#) is better than all our docs01:53
*** adrian_otto has joined #openstack-keystone02:00
*** EinstCrazy has quit IRC02:00
*** EinstCrazy has joined #openstack-keystone02:01
*** adrian_otto has quit IRC02:02
*** davechen has joined #openstack-keystone02:04
*** adrian_otto has joined #openstack-keystone02:05
*** EinstCrazy has quit IRC02:10
*** EinstCrazy has joined #openstack-keystone02:11
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Password history requirements  https://review.openstack.org/32833902:14
*** adrian_otto has quit IRC02:18
*** adrian_otto has joined #openstack-keystone02:20
*** ddieterly has joined #openstack-keystone02:23
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Password expires validation  https://review.openstack.org/33336002:25
*** ddieterly has quit IRC02:28
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Password expires validation  https://review.openstack.org/33336002:28
*** adrian_otto has quit IRC02:29
*** ddieterly has joined #openstack-keystone02:32
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Password expires validation  https://review.openstack.org/33336002:34
openstackgerritJamie Lennox proposed openstack/keystone: Handle more auth information via context  https://review.openstack.org/33939002:37
openstackgerritJamie Lennox proposed openstack/keystone: Require auth_context middleware in the pipeline  https://review.openstack.org/33935602:37
*** aastha has quit IRC02:39
*** ddieterly is now known as ddieterly[away]02:44
*** ddieterly[away] has quit IRC02:45
*** amoralej|off has quit IRC02:46
*** amoralej has joined #openstack-keystone02:47
*** gyee has quit IRC02:49
stevemarsomeone available to test a hangout? :)02:51
stevemari posted the hangout link here: https://etherpad.openstack.org/p/keystone-api-sprint02:52
jamielennoxstevemar: i'll look early tomorrow morning and see if people are still around02:55
stevemarjamielennox: anyway you can hop on the hangout for a sec?02:55
stevemari just want to make sure the URL persists02:55
stevemarjamielennox: meh, i just disconnected and tried again, it works02:57
jamielennoxapparnetly i know longer have a plugin installed and firefox is having a freak out02:57
jamielennoxworks now, just lonely :p02:58
*** code-R_ has quit IRC03:00
stevemarjamielennox: haha03:00
*** itisha has quit IRC03:00
*** spzala has joined #openstack-keystone03:00
*** spzala has quit IRC03:05
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Lockout requirements  https://review.openstack.org/34007403:07
*** aastha has joined #openstack-keystone03:13
stevemarjamielennox: anyway you can take a look at https://review.openstack.org/#/c/290464/ and https://review.openstack.org/#/c/290497/ ? i'm anxious to get them in asap03:14
patchbotstevemar: patch 290464 - python-cinderclient - WIP: switch to keystoneauth03:14
patchbotstevemar: patch 290497 - python-glanceclient - switch from keystoneclient to keystoneauth03:14
stevemari don't want the teams to pull the "it's too late in newton" card03:15
jamielennoxstevemar: yep, will do03:15
jamielennoxstevemar: you should remove the WIP tag03:15
stevemarjamielennox: it's failing tests :(03:16
*** woodster_ has quit IRC03:19
jamielennoxstevemar: ok, refreshing envs then i'll take it for a coffee - should i just push if i fix the tests?03:20
stevemarjamielennox: fo sho03:20
*** ravelar159 has joined #openstack-keystone03:24
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Password expires validation  https://review.openstack.org/33336003:24
*** ravelar159 has quit IRC03:29
jamielennoxstevemar: i think the ideal here would be to switch them to os-client-config instead of to ksa directly03:30
jamielennoxmordred and notmorgan dislike it when i get people to use the load_from_argparse_arguments stuff in ksa03:30
stevemarjamielennox: just about all clients are using it03:31
jamielennoxthe ksa.cli stuff?03:32
stevemarthe 'load_from_argparse_arguments'03:33
jamielennoxhmm, that means no OS_CLOUD suport03:33
jamielennoxman cinderclient is in rough shape03:34
*** iurygregory_ has quit IRC03:41
stevemarjamielennox: yes, yes it is :(03:45
jamielennoxstevemar: i want to rip and replace this, but i'm not sure if that will make it too difficult to merge03:45
jamielennoxstevemar: like they have all this test if v2 or v3 is available and do stuff, we have all that support in ksa03:45
stevemaryeah, i had the same thought03:46
stevemarjamielennox: is cinder the one with their own discovery code?03:46
stevemarjamielennox: ignore it for now and rip it out later?03:46
jamielennoxstevemar: they seem to be import keystoneauth.discover, but they're still doing it manually03:46
jamielennoxglance seems to be manually parsing the catalog03:46
jamielennoxyea, fix fast then maybe fix properly later03:47
jamielennoxi've always tried to ignore client shells they suck so muc h03:47
stevemaris the CFP still open?03:48
stevemaroh a whole day left03:48
*** davechen has left #openstack-keystone03:53
*** markvoelker has joined #openstack-keystone03:55
*** KevinE has quit IRC03:59
*** spzala has joined #openstack-keystone04:01
*** fawadkhaliq has joined #openstack-keystone04:01
*** michauds has joined #openstack-keystone04:03
*** links has joined #openstack-keystone04:03
*** rderose has quit IRC04:05
*** spzala has quit IRC04:06
*** tonytan4ever has joined #openstack-keystone04:09
jamielennoxstevemar: fixed the failing test on cinderclient patch, removed WIP header (and gave myself co-author)04:10
*** GB21 has joined #openstack-keystone04:18
*** sdake has joined #openstack-keystone04:22
*** julim has quit IRC04:26
*** dikonoor has joined #openstack-keystone04:26
*** richm has quit IRC04:34
stevemarjamielennox: cool with me04:35
*** fawadkhaliq has quit IRC04:37
stevemarjamielennox: can you review the glanceclient one too, it's passing but could use your opinion on it04:38
stevemar(to double check i didn't do anything crazy)04:38
jamielennoxstevemar: yep i have it open04:38
openstackgerritJamie Lennox proposed openstack/keystoneauth: Add additional_headers to session and adapter  https://review.openstack.org/34129104:38
*** michauds has quit IRC04:40
*** GB21 has quit IRC04:40
jamielennoxstevemar: the glance one does a lot more messing around with the options in shell04:41
*** sdake has quit IRC04:50
jamielennoxstevemar: so i don't like how using default= there in the auth plugin stuff will interact with the auth plugin loader04:52
jamielennoxalthough maybe it doesn't matter04:52
stevemarjamielennox: it's been a while, where is that?04:53
jamielennoxhttps://review.openstack.org/#/c/290497/16/glanceclient/shell.py L11004:53
patchbotjamielennox: patch 290497 - python-glanceclient - switch from keystoneclient to keystoneauth04:53
stevemarjamielennox: i copied that over from the novaclient and neutronclient migration04:54
jamielennoxstevemar: lol, ah this is all so broken04:54
stevemarjamielennox: oh yeah04:55
stevemarjamielennox: right now it's all about not using deprecated keystoneclient stuff04:55
stevemarwe can rm -rf the rest of this later04:55
jamielennoxstevemar: so for speed i would back that out, i'm not sure if glanceclient is even correctly handling the token auth04:55
jamielennoxi left another comment04:55
jamielennoxah - well i will have if i press the button04:56
jamielennoxstevemar: oh, i see, there's really no other way to register specific options without setting default-04:58
*** spzala has joined #openstack-keystone05:01
*** dikonoor has quit IRC05:03
*** spzala has quit IRC05:06
mordredstevemar, jamielennox: heya! any way I can be useful or helpful?05:11
mordredI agree that at least getting things off of ksc in whatever way that makes sense is the best and most important thing05:11
mordred:)05:11
stevemarmordred: i think jamielennox figured it out, mostly?05:12
mordredwoot05:12
stevemarmordred: a review of https://review.openstack.org/#/c/290497/ is always helpful :P05:12
patchbotstevemar: patch 290497 - python-glanceclient - switch from keystoneclient to keystoneauth05:12
jamielennoxmordred: basically we need to move glance and cinder shells to os-client-config instead of fixing the crap they do now05:12
jamielennoxbut i have long stopped trying to fix the individual client shells, there's too many05:13
jamielennoxand they're all broken in different way s05:13
mordredyah - I mostly wanted to get nova/neutron/cinder/glance fixed05:13
mordredand wanted to get them on occ purely to ease transition to osc05:13
mordredbecause yeah .. WOW they're all bad05:13
jamielennoxso maybe osc-lib can fix some of this, but again it's going to be a slightly different way of doing things that they won't adopt correctly05:14
*** GB21 has joined #openstack-keystone05:14
mordredyah - the roadblock I hit with full occ support in python-novaclient was that it was _really_ hard to support all of the weird things they do in a backwards compat manner05:16
mordredso I gave up05:16
jamielennoxand novaclient would be kind of a goal because they're a long way off full OSC support. for glance and cinder - meh?05:18
*** maestropandy has joined #openstack-keystone05:19
mordredyah. turns out a LOT of people use nova cli and it's the hardest05:20
mordredI think very few people use glance cli05:20
jamielennoxpossibly the best thing to do now would be just go through nova cli and deprecate all the stupid old things they do that no one uses any more05:22
mordredjamielennox: btw - on the conversation we had a week or two ago about inferring plugin type from options, I believe I have come around to agreeing with you and I _think_ I've got some thoughts in my head on how to maybe get there05:22
jamielennoxthen worry about it in a year when you can just yank stuff out05:22
mordredyah. I _think_ I may have even done that a little bit already05:22
jamielennoxmordred: oh nice - i think from a ksa perspective it's fairly pure on that but its been widely abused05:23
jamielennoxmordred: my position was always that people don't write their own clouds.yaml anyway so specifying an auth_type was not a big deal05:23
jamielennoxbut yea whatever we can do to get there05:24
jamielennoxgah, i need to move my blog off the ruby base - every time i touch it there's something wrong again05:24
mordredexactly. well, that and 'password' turns out to be a fairly sane default - if your cloud is not doing password, your cloud has likely actively communicated that05:25
jamielennox++05:25
jamielennoxfor a while there i had a plugin proposed that was called CLIDefault or something, which was essentially a merge of password and admin_token05:26
notmorganor your cloud is insane05:26
notmorgani mean...05:26
mordrednotmorgan: yah05:26
notmorganthat is also possible05:26
jamielennoxturns out that anyone using auth_token already knew what they were doing and so again setting --os-auth-type is not a big deal05:26
mordredjamielennox: right - but now that we don't use admin_token for bootstrapping, the main case that was driving the desire to automagically figure out token has gone away05:26
mordredjamielennox: yah05:26
jamielennoxmordred: so that's pretty easy to accomplish, i'm not sure about os-c-c but from ksa i've supported default= in register_argparse_arguments05:28
mordredyah - we have defaults for auth_type in occ too05:28
jamielennoxwhich would just default --os-auth-type to <default> and so register the correct options for help and then load the correct plugin05:29
*** dikonoor has joined #openstack-keystone05:30
*** fawadkhaliq has joined #openstack-keystone05:32
*** fawadkhaliq has quit IRC05:32
*** fawadkhaliq has joined #openstack-keystone05:32
*** fawadkhaliq has quit IRC05:33
*** fawadkhaliq has joined #openstack-keystone05:33
*** fawadkhaliq has quit IRC05:36
*** fawadkhaliq has joined #openstack-keystone05:36
*** jamielennox is now known as jamielennox|away05:43
*** jamielennox|away is now known as jamielennox05:56
*** GB21 has quit IRC05:59
*** spzala has joined #openstack-keystone06:02
*** abhishekk has joined #openstack-keystone06:05
*** spzala has quit IRC06:06
abhishekkjamielennox: hi you around?06:06
jamielennoxabhishekk: yep06:06
abhishekkjamielennox: is it possible to create specs for keystoneauth in keystone-specs or I should write detail blueprint instead?06:07
jamielennoxabhishekk: so there is a folder in keystone-specs that i've used in the past, however it's fairly rare, mostly we just do a bug and maybe a blueprint06:08
jamielennoxabhishekk: what do you have in mind?06:08
abhishekkjamielennox: I want to log request-id mappings in keystoneauth session.py06:09
jamielennoxabhishekk: mappings?06:09
abhishekkjamielennox: caller and caller request-id similar to https://blueprints.launchpad.net/python-cinderclient/+spec/log-request-id06:10
abhishekk*callee06:10
abhishekkmost of the python-clients are using keystoneauth Session client so it will be centralized place for logging these request-ids06:11
jamielennoxabhishekk: so you want to log it?06:11
abhishekkjamielennox: yes06:11
*** GB21 has joined #openstack-keystone06:11
abhishekkjamielennox: it will be logged as a debug log06:12
jamielennoxabhishekk: cool, i don't know if i'd worry about a blueprint for that06:12
jamielennoxabhishekk: currently the debug log logs the curl syntax06:12
jamielennoxisn't the request-id included in that/06:12
abhishekkjamielennox: IMO not06:12
abhishekkjamielennox: and we want both request-ids, caller and callee i.e. nova nad keystone request-ids at one line06:13
abhishekkit will be like: DEBUG keystoneauth.session [req-a654ff07-c540-4cb0-84e3-437855ad9f0e demo demo]06:13
abhishekkGET call to identity06:13
abhishekkfor http://172.26.88.20/identity_v2_admin/v3/auth/tokens06:13
abhishekkused request id req-c139aef9-6abd-4ed5-ba78-3ab5b0d0b12d06:14
abhishekkso the first request-id is of nova and second one is of identity06:14
jamielennoxabhishekk: ok, i'd be fine with that being in the logs and i really don't think you need a blueprint, maybe just file it as a bug06:14
jamielennoxcaller and callee?06:15
abhishekkjamielennox: ok thank you for your time06:15
jamielennoxgah - i always disliked that a single request id wasn't just used for the entire call chain, i never understood the concern about that06:15
jamielennoxmy only concern there is by the time we have 2+ request ids in the debug log line is there going to be room on the screen to read the rest06:16
abhishekkjamielennox: nova is calling keystone then nova is caller and keystone is callee06:16
abhishekkjamielennox: hmm06:17
jamielennoxhow does ksa know caller and callee?06:17
abhishekkjamielennox: I will add this detail information in bug06:17
jamielennoxabhishekk: sounds good, ping me with it when you have it up06:18
abhishekkjamielennox: sure, thank you06:18
*** maestropandy has quit IRC06:24
*** maestropandy has joined #openstack-keystone06:35
*** pcaruana has joined #openstack-keystone06:35
*** aastha has quit IRC06:39
*** agireud has quit IRC06:40
*** agireud has joined #openstack-keystone06:44
*** openstackgerrit has quit IRC06:48
*** openstackgerrit has joined #openstack-keystone06:48
*** sheel has joined #openstack-keystone06:48
*** agireud has quit IRC06:55
*** spzala has joined #openstack-keystone07:02
*** clenimar__ has joined #openstack-keystone07:03
*** henrynash has joined #openstack-keystone07:05
*** ChanServ sets mode: +v henrynash07:05
*** clenimar_ has quit IRC07:06
henrynashraildo: indeed, interesting07:06
*** spzala has quit IRC07:07
openstackgerritJamie Lennox proposed openstack/keystoneauth: Add additional_headers to session and adapter  https://review.openstack.org/34129107:10
*** tesseract- has joined #openstack-keystone07:10
*** jaosorior has joined #openstack-keystone07:11
*** rcernin has joined #openstack-keystone07:13
openstackgerritJamie Lennox proposed openstack/keystone: Handle more auth information via context  https://review.openstack.org/33939007:15
openstackgerritJamie Lennox proposed openstack/keystone: Require auth_context middleware in the pipeline  https://review.openstack.org/33935607:15
*** davechen has joined #openstack-keystone07:16
*** GB21 has quit IRC07:16
*** jed56 has joined #openstack-keystone07:16
*** daemontool has joined #openstack-keystone07:17
*** markvoelker has quit IRC07:19
*** agireud has joined #openstack-keystone07:20
*** markvoelker has joined #openstack-keystone07:21
*** david-lyle has quit IRC07:27
*** EinstCrazy has quit IRC07:30
*** EinstCrazy has joined #openstack-keystone07:31
*** daemontool_ has joined #openstack-keystone07:31
*** david-lyle has joined #openstack-keystone07:32
*** fawadkhaliq has quit IRC07:33
*** daemontool has quit IRC07:34
*** jojden has joined #openstack-keystone07:37
*** markvoelker has quit IRC07:39
*** tonytan4ever has quit IRC07:47
*** tonytan4ever has joined #openstack-keystone07:47
*** jamiec has joined #openstack-keystone07:49
*** tonytan_brb has joined #openstack-keystone07:51
*** tonytan4ever has quit IRC07:54
*** david-lyle has quit IRC07:58
*** zzzeek has quit IRC08:00
*** pcaruana has quit IRC08:00
*** zzzeek has joined #openstack-keystone08:01
*** d0ugal has joined #openstack-keystone08:01
*** spzala has joined #openstack-keystone08:03
*** spzala has quit IRC08:08
*** pnavarro has joined #openstack-keystone08:09
openstackgerritDavanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c  https://review.openstack.org/31843508:10
openstackgerritDavanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c  https://review.openstack.org/31843508:10
*** pcaruana has joined #openstack-keystone08:14
*** jrist_ has joined #openstack-keystone08:14
jojdenhttps://bugs.launchpad.net/oslo.policy/+bug/160220608:16
openstackLaunchpad bug 1602206 in oslo.policy "sample code to implement oslo policy " [Undecided,New]08:16
*** GB21 has joined #openstack-keystone08:17
*** markvoelker has joined #openstack-keystone08:20
*** markvoelker has quit IRC08:25
*** pnavarro has quit IRC08:26
*** GB21 has quit IRC08:31
*** GB21 has joined #openstack-keystone08:33
*** TxGVNN has joined #openstack-keystone08:39
*** chlong has joined #openstack-keystone08:48
*** code-R has joined #openstack-keystone08:48
*** code-R has quit IRC08:49
*** code-R has joined #openstack-keystone08:49
*** code-R has quit IRC08:51
*** code-R_ has joined #openstack-keystone08:51
*** spzala has joined #openstack-keystone09:04
*** spzala has quit IRC09:09
*** henrynash has quit IRC09:11
*** tonytan_brb has quit IRC09:13
*** markvoelker has joined #openstack-keystone09:15
*** pcaruana has quit IRC09:18
*** markvoelker has quit IRC09:20
*** code-R_ has quit IRC09:23
*** ivasilevskaya has left #openstack-keystone09:23
*** code-R has joined #openstack-keystone09:24
*** TxGVNN has quit IRC09:25
*** pcaruana has joined #openstack-keystone09:31
*** TxGVNN has joined #openstack-keystone09:32
*** nisha has joined #openstack-keystone09:35
*** nisha is now known as Guest657209:35
*** GB21 has quit IRC09:40
*** TxGVNN has quit IRC09:43
*** pcaruana has quit IRC09:48
*** pcaruana has joined #openstack-keystone09:48
*** akscram has quit IRC09:49
*** jaosorior has quit IRC09:49
*** pcaruana has quit IRC09:50
*** akscram has joined #openstack-keystone09:50
*** jaosorior has joined #openstack-keystone09:50
*** pcaruana has joined #openstack-keystone09:50
*** pcaruana has quit IRC09:51
*** davechen has left #openstack-keystone09:54
*** code-R has quit IRC09:57
*** pcaruana has joined #openstack-keystone09:57
*** code-R has joined #openstack-keystone09:57
*** mnikolaenko1 has left #openstack-keystone09:58
*** mnikolaenko1 has joined #openstack-keystone09:59
*** kashyap has joined #openstack-keystone10:00
*** jrist_ has quit IRC10:01
*** TxGVNN has joined #openstack-keystone10:02
*** mnikolaenko1 has quit IRC10:02
kashyapHi folks, this is with this morning's DevStack & Keystone current Git:10:03
kashyap2016-07-13 09:10:27.566 | Discovering versions from the identity service failed when creating the password plugin. Attempting to determine version from URL.10:03
kashyap2016-07-13 09:10:27.566 | Could not determine a suitable URL for the plugin10:03
kashyap2016-07-13 09:10:27.601 | Error on exit10:03
*** spzala has joined #openstack-keystone10:05
openstackgerritAlexander Ignatyev proposed openstack/keystone: Support new osprofiler API  https://review.openstack.org/34140110:05
*** mnikolaenko_ has joined #openstack-keystone10:06
openstackgerritThomas Goirand proposed openstack/python-keystoneclient: Fix other-requirements.txt for deb based distros  https://review.openstack.org/34100710:07
*** mnikolaenko_ is now known as MikhailNikolaenk10:09
*** nisha_ has joined #openstack-keystone10:09
*** markvoelker has joined #openstack-keystone10:09
*** spzala has quit IRC10:09
*** Guest6572 has quit IRC10:12
*** MikhailNikolaenk is now known as mnikolaenko_10:12
*** markvoelker has quit IRC10:13
*** tonytan4ever has joined #openstack-keystone10:14
*** wangqun has quit IRC10:14
*** GB21 has joined #openstack-keystone10:15
*** daemontool_ has quit IRC10:16
kashyapOh, disregard me, I think it's the result of a wrong env variable (SERVICE_HOST) accidentally slipped in!10:16
*** kashyap has left #openstack-keystone10:18
*** tonytan4ever has quit IRC10:19
*** daemontool_ has joined #openstack-keystone10:21
*** jamiec has quit IRC10:24
*** jamiec has joined #openstack-keystone10:25
*** jed56 has quit IRC10:25
*** jaosorior is now known as jaosorior_brb10:45
*** jrist has joined #openstack-keystone10:49
*** jrist has quit IRC10:49
*** jrist has joined #openstack-keystone10:49
*** EinstCrazy has quit IRC11:01
*** markvoelker has joined #openstack-keystone11:03
rodrigodsstevemar, yeah, good doc! Looks almost like how specs describes the problems11:03
*** spzala has joined #openstack-keystone11:05
*** markvoelker has quit IRC11:07
*** spzala has quit IRC11:10
*** lamt has joined #openstack-keystone11:11
nisha_hi rodrigods11:13
rodrigodsnisha_, hey :)11:14
*** dikonoor has quit IRC11:26
*** nisha_ has quit IRC11:29
*** nisha has joined #openstack-keystone11:29
*** nisha is now known as Guest8184211:30
*** bjolo has joined #openstack-keystone11:31
*** gordc has joined #openstack-keystone11:31
*** nisha_ has joined #openstack-keystone11:35
*** Guest81842 has quit IRC11:36
nisha_rodrigods, I am trying to fix the issue we had for projects/roles because of test_implied_roles11:36
nisha_rodrigods, https://github.com/openstack/python-keystoneclient/blob/master/keystoneclient/tests/functional/v3/test_implied_roles.py11:36
nisha_rodrigods, as per your suggestion, I am trying to use client_fixtures.py to create roles11:37
rodrigodsnisha_, sure, any issues so far?11:38
nisha_rodrigods, particularly, I replaced            self.client.roles.create(role_def) by11:38
nisha_role = fixtures.Role(self.client)11:38
nisha_self.useFixture(role)11:38
*** nk2527 has joined #openstack-keystone11:38
nisha_rodrigods, above replacement in the     def create_roles(self):11:39
nisha_rodrigods, but I get different key errors, and the test fails11:40
rodrigodsnisha_, you need to remove the "delete_roles"11:41
rodrigodsand also create a fixture for "create_rules"11:41
nisha_rodrigods, Oh, because the fixtures clean themselves up. thanks11:42
nisha_rodrigods, I will write one for rules then and let you know11:43
nisha_rodrigods, thanks :)11:43
openstackgerritKseniya Tychkova proposed openstack/oslo.policy: Adds debug logging for policy file validation  https://review.openstack.org/34144611:44
*** samueldmq has joined #openstack-keystone11:44
*** ChanServ sets mode: +v samueldmq11:44
rodrigodsnisha_, np11:44
samueldmqmorning keystone11:44
*** sdake has joined #openstack-keystone11:48
*** sdake_ has joined #openstack-keystone11:50
*** jrist has quit IRC11:51
*** jrist has joined #openstack-keystone11:51
*** jrist has quit IRC11:51
*** jrist has joined #openstack-keystone11:51
dstaneksamueldmq: o/11:52
samueldmqdstanek: o/11:53
samueldmqI heard today is api-ref day11:53
*** sdake has quit IRC11:54
dstanekyerp11:58
*** tonytan4ever has joined #openstack-keystone12:00
*** pece has joined #openstack-keystone12:01
*** tonytan4ever has quit IRC12:05
nisha_samueldmq, morning12:05
samueldmqnisha_: o/12:06
*** sheel has quit IRC12:06
*** spzala has joined #openstack-keystone12:06
*** jaosorior_brb is now known as jaosorior12:06
*** rvasilets_ has joined #openstack-keystone12:09
openstackgerritRon De Rose proposed openstack/keystone-specs: PCI-DSS Adds password_expires_at to API specs  https://review.openstack.org/34096412:09
rvasilets_Hello. I have deployed devstack? enter `screen -r` and saw those line INFO keystone.common.wsgi [req-ce49a91f-d285-43de-877a-ebc47405e419 b7bf6a80a812445e9454505a0fcfdd6b ceb79313e7dd4301bdb9a09a6fa83d6b - default default] GET http://192.168.122.78/identity_v2_admin/v3/auth/tokens12:09
rvasilets_How can I understand what version of identity I have?12:10
rvasilets_In one url I've got v2 and v3 at the same time)12:10
rvasilets_Is it normal?)12:10
*** spzala has quit IRC12:11
samueldmqrvasilets_: it's using v312:16
samueldmqrvasilets_: the /identity_v2_admin there means it is using the admin port 3535712:17
samueldmqrvasilets_: the v2 api had different behavior on the public and admin ports, that's why htis is called /identity_v2_admin12:17
samueldmqrvasilets_: but maybe this is just a bad naming12:18
*** dikonoor has joined #openstack-keystone12:19
*** kean has quit IRC12:21
*** kean has joined #openstack-keystone12:21
rvasilets_samueldmq, I think its bad naming)12:22
rvasilets_definitely12:23
dstaneki wonder why anything is using v3 on identity_v2_admin12:25
nisha_samueldmq, rodrigods, I am still not able to run the test_implied_roles successfully12:29
rvasilets_dstanek, I'm wonder too? what is going on on my devstack with default options)12:29
*** jed56 has joined #openstack-keystone12:30
nisha_samueldmq, rodrigods, the client fixtures file, http://paste.openstack.org/show/531657/12:30
nisha_samueldmq, rodrigods modified test_implied_roles file and errors, http://paste.openstack.org/show/531663/12:30
rvasilets_okey I have typed 'curl publicURL' and got http://ideone.com/eDIrra its mean that I got two versions of keystone. But what version I will use if I type for example 'optimize action list'12:31
rvasilets_?12:31
rvasilets_or other openstack servise12:31
openstackgerritRon De Rose proposed openstack/keystone-specs: PCI-DSS Adds password_expires_at to API specs  https://review.openstack.org/34096412:31
*** clenimar__ has quit IRC12:32
rvasilets_and if I want to use for now proper  keystone version  how to specify it?12:33
rodrigodsnisha_, can you check the content of the "roles" dict? seems like that's the problem12:33
dstanekrvasilets_: the identity version is likely controlled by identity_api_version in your clouds.yaml12:35
nisha_rodrigods, I tried print roles inside def role_dict12:37
*** markvoelker has joined #openstack-keystone12:38
nisha_rodrigods, that didn't work though12:38
rodrigodsnisha_, you can use pdb, the Python's debug tool12:38
nisha_rodrigods, I used self.assertEqual(roles, "check here") and got this http://paste.openstack.org/show/531665/12:39
*** belmoreira has joined #openstack-keystone12:39
nisha_rodrigods, I will try that too, can you check if above is fine?12:39
rodrigodsnisha_, ok, the issue is the following:12:40
rodrigodsyou are creating several roles with random names12:41
nisha_rodrigods, hmm yes and ?12:41
rodrigodsbut, in the create_rules() method, it expects to have the names defined above12:41
rodrigodsthe exact error is that it is trying to get the key in the "roles" dict using the names defined by "role_defs"12:42
rodrigodsnisha_, in the Roles fixture, you need to pass the custom name so they can be reused in the "inference_rules" dict12:43
nisha_rodrigods, oh okay thanks12:44
rvasilets_dstanek, thank you!12:44
nisha_rodrigods, I will try doing that12:44
*** maestropandy has quit IRC12:46
dstanekrvasilets_: if you have a currect/recent devstack you should be using v3 already12:46
*** sdake_ has quit IRC12:47
*** daemontool_ has quit IRC12:49
*** sdake has joined #openstack-keystone12:49
*** ddieterly has joined #openstack-keystone12:50
*** daemontool_ has joined #openstack-keystone12:50
rvasilets_dstanek, yes. But now I have the case when I need to test watcher project and he is unable to work with v3) So it took me to switch to v2 temporary12:50
*** pauloewerton has joined #openstack-keystone12:50
*** itisha has joined #openstack-keystone12:51
*** GB21 has quit IRC12:51
*** jistr is now known as jistr|cowork12:53
*** woodster_ has joined #openstack-keystone12:58
stevemaro/13:02
stevemarso who is sprinting?!13:02
stevemarsamueldmq: o/13:05
dstanekstevemar: i'm more of a distance guy13:05
samueldmqstevemar: hey, let's start it o/13:05
stevemardstanek: :)13:06
*** spzala has joined #openstack-keystone13:07
*** jaugustine has joined #openstack-keystone13:07
samueldmq#notice Keystone api-ref sprint is open!13:07
samueldmq:)13:07
dstanek#link ?13:08
dstaneki can't find my etherpad link anymore13:08
stevemardstanek: it's in the topic13:08
samueldmq#link https://etherpad.openstack.org/p/keystone-api-sprint13:08
stevemarhttps://etherpad.openstack.org/p/keystone-api-sprint13:08
samueldmqoh, nice to be in the topic13:08
openstackgerritDolph Mathews proposed openstack/keystone: Improve keystone.conf [saml] documentation  https://review.openstack.org/34056613:08
openstackgerritDolph Mathews proposed openstack/keystone: Use URIOpt instead of StrOpt  https://review.openstack.org/34151413:08
stevemarlink for hangout: https://hangouts.google.com/call/3vtkgpv32jabjjcwepweafjf2ee13:08
nisha_rodrigods, thanks a lot for help, the tests are running now :)13:08
rodrigodsnikhil, awesome :)13:09
rodrigodsyw13:09
stevemarnisha_: isn't rodrigods the best?!13:09
rodrigodsstevemar, you are the best13:09
*** richm has joined #openstack-keystone13:10
stevemarrodrigods: not by a long shot :(13:10
*** links has quit IRC13:11
stevemarsamueldmq: dstanek logging on? i am going to stumble my way through making a change to the API :)13:11
samueldmqstevemar: yes, I am going to start migrating OS-FEDERATION13:13
nisha_stevemar, indeed13:14
nisha_stevemar, samueldmq rodrigods I feel so lucky in your company. Everyone is so helpful :D13:14
stevemarsamueldmq: great, i'm going to start on os-revoke :)13:14
nisha_dstanek, too. You saved me so much time yesterday, otherwise I had to reinstall vm13:15
*** sdake has quit IRC13:16
*** adu has joined #openstack-keystone13:16
* stevemar pokes dstanek to go on the hangout13:17
* stevemar is feeling lonely13:17
lamtI can start working on OS-TRUST13:18
*** ddieterly has quit IRC13:18
*** chlong has quit IRC13:20
dstanekstevemar: lol13:20
*** ametts has joined #openstack-keystone13:21
*** samueldmq has quit IRC13:23
*** webmichael has joined #openstack-keystone13:25
nisha_rodrigods, you left a comment on project functional tests patch, when we run the tests in parallel using "testr run --parallel" (that is the default for tox venv):13:25
rodrigodsnisha_, right13:25
nisha_rodrigods, how can I check if all the tests are running successfully now, i.e. Jenkins problem would be solve13:25
nisha_"testr run --parallel" ?13:26
*** julim has joined #openstack-keystone13:26
rodrigodsnisha_, you can run with tox13:26
rodrigodsrunning with and without --parallel was just to confirm the issue13:26
rodrigodsnisha_, run the tests a couple of times to make sure the issue is not happening, since if both tests ends in the same worker it would pass13:27
nisha_rodrigods, alright, I will try that13:28
*** tonytan4ever has joined #openstack-keystone13:30
*** julim has quit IRC13:32
*** julim has joined #openstack-keystone13:33
*** julim has quit IRC13:34
*** julim has joined #openstack-keystone13:34
*** tonytan4ever has quit IRC13:34
openstackgerritDolph Mathews proposed openstack/keystone: Improve keystone.conf [saml] documentation  https://review.openstack.org/34056613:35
openstackgerritDolph Mathews proposed openstack/keystone: Validate SAML keyfile & certfile options  https://review.openstack.org/34152513:35
*** ddieterly has joined #openstack-keystone13:35
*** tonytan4ever has joined #openstack-keystone13:36
*** michauds has joined #openstack-keystone13:39
*** ddieterly has quit IRC13:39
openstackgerritDolph Mathews proposed openstack/keystone: Use URIOpt instead of StrOpt  https://review.openstack.org/34151413:39
*** tonytan_brb has joined #openstack-keystone13:41
*** tonytan_brb is now known as tonytan4ever_13:41
openstackgerritMerged openstack/keystone: Move logic for catalog driver differences to manager  https://review.openstack.org/34013213:42
*** tonytan4ever has quit IRC13:43
openstackgerritDolph Mathews proposed openstack/keystone: Improve keystone.conf [tokenless_auth] documentation  https://review.openstack.org/34059113:44
lbragstadmorning!13:44
*** jaugustine_ has joined #openstack-keystone13:44
*** jaugustine has quit IRC13:44
*** tonytan4ever_ has quit IRC13:44
*** jaugustine_ is now known as jaugustine13:44
*** tonytan4ever has joined #openstack-keystone13:45
*** KevinE has joined #openstack-keystone13:47
*** rderose has joined #openstack-keystone13:48
*** samueldmq has joined #openstack-keystone13:52
*** ChanServ sets mode: +v samueldmq13:52
*** michauds has quit IRC13:55
bjolokolla 2.0.1 when launching vms they get more than one IP from DHCP?13:55
*** samueldmq has quit IRC13:55
bjoloive tried to google but i dont find any info. is that a known issue?13:56
openstackgerritNisha Yadav proposed openstack/python-keystoneclient: Add project functional tests  https://review.openstack.org/33287113:57
*** rderose_ has joined #openstack-keystone13:57
rodrigodsbjolo, maybe you can ask in #openstack-kolla? think there will have more ppl able to help you out13:57
rodrigodsnisha_, ^ the tests passed? :)13:58
bjoloouch sorry13:58
bjolowrong channel :)13:58
nisha_rodrigods, yeah, I ran than many times. Let's wait for Jenkins now :D13:58
rodrigodsnisha_, awesome!13:58
*** samueldmq has joined #openstack-keystone13:58
*** ChanServ sets mode: +v samueldmq13:58
nisha_them*13:58
* samueldmq 's back13:59
*** rderose has quit IRC14:01
*** gagehugo has joined #openstack-keystone14:01
*** raildo has quit IRC14:03
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Lockout requirements  https://review.openstack.org/34007414:06
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Lockout requirements  https://review.openstack.org/34007414:07
*** nisha_ has quit IRC14:08
*** raildo has joined #openstack-keystone14:09
*** code-R has quit IRC14:10
openstackgerritSteve Martinelli proposed openstack/keystone: Create APIs for OS-REVOKE  https://review.openstack.org/34155414:10
stevemardstanek: ^14:10
*** alex_xu has quit IRC14:11
*** sdake has joined #openstack-keystone14:11
*** TxGVNN has quit IRC14:12
*** alex_xu has joined #openstack-keystone14:12
*** samueldmq has quit IRC14:14
*** jaugustine has quit IRC14:15
*** jaugustine has joined #openstack-keystone14:16
*** pnavarro has joined #openstack-keystone14:17
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Adds password_expires_at to API docs  https://review.openstack.org/33631814:19
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Adds password_expires_at to API docs  https://review.openstack.org/33631814:20
*** ddieterly has joined #openstack-keystone14:24
*** samueldmq has joined #openstack-keystone14:25
*** ChanServ sets mode: +v samueldmq14:25
samueldmqstevemar: there is a "definitions" section in the federation docs14:25
samueldmqstevemar: I think those should go in the api-guide docs14:26
samueldmqstevemar: it's kind of a glossary14:26
*** markvoelker has quit IRC14:26
samueldmqanyways that's a next step :)14:27
*** gagehugo_ has joined #openstack-keystone14:27
*** gagehugo has quit IRC14:30
*** gagehugo_ has quit IRC14:31
*** sdake has quit IRC14:31
*** gagehugo has joined #openstack-keystone14:31
*** sdake has joined #openstack-keystone14:31
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Adds password_expires_at to API docs  https://review.openstack.org/33631814:33
lbragstadis anyone else having issues with keystone-coverage-db?14:34
lbragstader the keystone-coverage-db job?14:34
lbragstadI noticed it was failing on one of rderose_'s patches14:35
openstackgerritTin Lam proposed openstack/keystone: Complete OS-TRUST API documentation  https://review.openstack.org/34158414:35
lbragstadcc stevemar ^14:37
*** bjolo has quit IRC14:37
*** ravelar159 has joined #openstack-keystone14:38
*** nisha_ has joined #openstack-keystone14:41
stevemarsamueldmq: we can put those into the api-ref for now i guess14:41
stevemarthen move them over14:41
samueldmqstevemar: ++14:41
stevemarsamueldmq: https://review.openstack.org/#/c/341554/114:41
openstackgerritRon De Rose proposed openstack/keystone-specs: PCI-DSS Adds password_expires_at to API specs  https://review.openstack.org/34096414:41
patchbotstevemar: patch 341554 - keystone - Create APIs for OS-REVOKE14:41
samueldmqstevemar: nice, that was quick!14:42
samueldmqstevemar: I am putting federation in the v3 dir14:42
samueldmqstevemar: rather than v3-ext. can you confirm that is correct ?14:43
openstackgerritRon De Rose proposed openstack/keystone-specs: PCI-DSS Adds password_expires_at to API specs  https://review.openstack.org/34096414:43
stevemarsamueldmq: i would put it in v3-ext for now, we can shuffle things around later14:43
stevemarbut if you're already doing it, then no worries14:43
*** michauds has joined #openstack-keystone14:44
*** markvoelker has joined #openstack-keystone14:44
samueldmqstevemar: gotcha14:45
*** michauds has quit IRC14:45
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Password expires validation  https://review.openstack.org/33336014:46
dstaneksamueldmq: is there any reason why the 'Get effective policy associated with endpoint' and 'Check if a policy is associated with endpoint' were left out of the enpoint policy docs?14:49
dstaneksamueldmq: i'm currently fixing that one up now14:49
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Adds password_expires_at to API docs  https://review.openstack.org/33631814:50
samueldmqdstanek: not that I remember of14:51
samueldmqdstanek: great thanks14:51
*** code-R has joined #openstack-keystone14:51
dstaneksamueldmq: cool, i thought maybe because they are logically endpoint operations14:52
*** adrian_otto has joined #openstack-keystone14:54
*** code-R_ has joined #openstack-keystone14:55
*** adrian_otto has quit IRC14:56
*** adrian_otto has joined #openstack-keystone14:57
*** code-R has quit IRC14:58
*** roxanaghe has joined #openstack-keystone14:59
*** jistr|cowork is now known as jistr|mtg15:00
*** links has joined #openstack-keystone15:01
*** roxanaghe has quit IRC15:02
*** roxanaghe has joined #openstack-keystone15:02
*** slberger has joined #openstack-keystone15:03
*** KevinE has quit IRC15:03
*** KevinE has joined #openstack-keystone15:04
*** phalmos has joined #openstack-keystone15:08
*** timcline has joined #openstack-keystone15:09
*** phalmos_ has joined #openstack-keystone15:10
*** ametts has quit IRC15:10
*** adrian_otto has quit IRC15:11
*** slberger has quit IRC15:13
*** phalmos has quit IRC15:13
*** adrian_otto has joined #openstack-keystone15:13
*** slberger has joined #openstack-keystone15:15
dstanekhttp://developer.openstack.org/api-ref/identity/v3-ext/index.html?expanded=associate-policy-and-service-type-endpoint-detail,show-policy-for-endpoint-detail#show-policy-for-endpoint15:18
dstaneksamueldmq: stevemar: ^ the response params list 'policy' and also things that are in policy. how will a user know that they are not top level?15:18
*** KevinE has quit IRC15:19
openstackgerritSteve Martinelli proposed openstack/keystone: Complete OS-TRUST API documentation  https://review.openstack.org/34158415:21
openstackgerritNisha Yadav proposed openstack/python-keystoneclient: Improve implied-role functional tests  https://review.openstack.org/34161215:22
samueldmqdstanek: not sure I get your question..15:22
*** ametts has joined #openstack-keystone15:23
dstaneksamueldmq: policy is listed as a return param and so it type, but type is actually inside policy15:23
dstaneksamueldmq: stevemar just checked and that seems to be what nova is doing...not idea, but a battle for a different day15:24
samueldmqdstanek: that'd odd15:25
samueldmqthat's15:25
samueldmqdstanek: because policy already owns those attrs15:26
samueldmqack, let's circle back on it another day15:26
samueldmq:)15:26
*** lucas___ has joined #openstack-keystone15:26
*** jistr|mtg is now known as jistr15:27
*** phalmos_ has quit IRC15:27
*** pcaruana has quit IRC15:28
*** phalmos has joined #openstack-keystone15:28
*** thumpba has joined #openstack-keystone15:28
*** aastha has joined #openstack-keystone15:31
openstackgerritNisha Yadav proposed openstack/python-keystoneclient: Add project functional tests  https://review.openstack.org/33287115:32
*** rcernin has quit IRC15:33
openstackgerritNisha Yadav proposed openstack/python-keystoneclient: Add project functional tests  https://review.openstack.org/33287115:34
*** agireud has quit IRC15:34
*** adu has quit IRC15:34
openstackgerritNisha Yadav proposed openstack/python-keystoneclient: Add role functional tests  https://review.openstack.org/33511815:35
*** mordred has quit IRC15:35
openstackgerritNisha Yadav proposed openstack/python-keystoneclient: Improve docs for v3 roles  https://review.openstack.org/33454615:35
openstackgerritRon De Rose proposed openstack/keystone: Create APIs for OS-REVOKE  https://review.openstack.org/34155415:41
openstackgerritSteve Martinelli proposed openstack/keystone: Complete OS-TRUST API documentation  https://review.openstack.org/34158415:41
openstackgerritRon De Rose proposed openstack/keystone: Create APIs for OS-REVOKE  https://review.openstack.org/34155415:42
*** adrian_otto has quit IRC15:43
*** lucas___ has quit IRC15:43
*** edtubill has joined #openstack-keystone15:44
*** adrian_otto has joined #openstack-keystone15:44
openstackgerritSteve Martinelli proposed openstack/keystone: Complete OS-TRUST API documentation  https://review.openstack.org/34158415:44
openstackgerritRon De Rose proposed openstack/keystone: Create APIs for OS-REVOKE  https://review.openstack.org/34155415:45
*** david-lyle has joined #openstack-keystone15:45
*** jrist has quit IRC15:46
*** d0ugal has quit IRC15:46
*** lucas___ has joined #openstack-keystone15:47
*** jojden has quit IRC15:48
*** lucas___ has quit IRC15:48
*** lucas____ has joined #openstack-keystone15:48
*** ametts has quit IRC15:50
*** timcline has quit IRC15:50
*** timcline has joined #openstack-keystone15:51
*** belmoreira has quit IRC15:51
openstackgerritRon De Rose proposed openstack/keystone: Create APIs for OS-REVOKE  https://review.openstack.org/34155415:52
*** david-lyle has quit IRC15:54
*** agireud has joined #openstack-keystone15:54
*** david-lyle_ has joined #openstack-keystone15:55
*** timcline has quit IRC15:56
*** ddieterly is now known as ddieterly[away]15:56
*** julim_ has joined #openstack-keystone15:57
*** catintheroof has joined #openstack-keystone15:58
*** browne has joined #openstack-keystone15:59
openstackgerritTin Lam proposed openstack/keystone: Complete OS-TRUST API documentation  https://review.openstack.org/34158415:59
*** julim has quit IRC16:00
*** rcernin has joined #openstack-keystone16:00
catintheroofhi guys, quick question. does the openstack cli supports to handle domain-specific configuration ? how do i change those configs after i run keystone-manage domain_config_upload ??16:02
*** ddieterly[away] is now known as ddieterly16:02
*** openstackgerrit has quit IRC16:03
*** openstackgerrit has joined #openstack-keystone16:03
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Lockout requirements  https://review.openstack.org/34007416:05
*** tesseract- has quit IRC16:06
samueldmqstevemar: I propose we have a parameters.yml per.inc file16:08
samueldmqstevemar: sharing the same parameters.yml across files causes inconsistencies when different entities have the same attribute16:09
samueldmqstevemar: e.g http://developer.openstack.org/api-ref/identity/v3/?expanded=list-projects-detail#projects16:09
samueldmqsee the enabled parameter, it's actually a description for domain's enabled attr16:10
openstackgerritDolph Mathews proposed openstack/keystone: Improve keystone.conf [token] documentation  https://review.openstack.org/34164616:10
samueldmq:/16:10
openstackgerritNisha Yadav proposed openstack/python-keystoneclient: Improve implied-role functional tests  https://review.openstack.org/34161216:11
*** chrisshattuck has joined #openstack-keystone16:12
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Lockout requirements  https://review.openstack.org/34007416:12
bretoni have a question about parameters.yaml. I see keys like description, description_1, description_N. How do they work?16:12
*** david-lyle has joined #openstack-keystone16:14
*** adrian_otto has quit IRC16:14
bretonor X-Subject-Token. There are 9 uses of X-Subject-Token in the contents of the stanza, bug in parameters.yaml there is only X-Subject-Token and X-Subject-Token_116:15
*** adrian_otto has joined #openstack-keystone16:16
openstackgerritRon De Rose proposed openstack/keystone: Create APIs for OS-REVOKE  https://review.openstack.org/34155416:16
*** adrian_otto has quit IRC16:17
openstackgerritNisha Yadav proposed openstack/python-keystoneclient: Improve implied-role functional tests  https://review.openstack.org/34161216:17
openstackgerritDavid Stanek proposed openstack/keystone: Reorders API calls to match precedence rules  https://review.openstack.org/34164816:17
openstackgerritDavid Stanek proposed openstack/keystone: Adds missing docs to endpoint policy api-ref  https://review.openstack.org/34164916:17
openstackgerritDavid Stanek proposed openstack/keystone: Adds missing parameter to endpoint policy api-ref  https://review.openstack.org/34165016:17
openstackgerritDavid Stanek proposed openstack/keystone: Reorder request params in endpoint policy api-ref  https://review.openstack.org/34165116:17
*** Gio has joined #openstack-keystone16:18
*** Gio has left #openstack-keystone16:18
openstackgerritNisha Yadav proposed openstack/python-keystoneclient: Improve implied-role functional tests  https://review.openstack.org/34161216:23
*** sdake has quit IRC16:24
*** adu has joined #openstack-keystone16:25
openstackgerritDolph Mathews proposed openstack/keystone: Clean up token binding validation code  https://review.openstack.org/34166216:27
nisha_rodrigods, I need some help if you have some time?16:30
*** timcline has joined #openstack-keystone16:34
*** timcline has quit IRC16:38
*** rderose_ has quit IRC16:40
*** sheel has joined #openstack-keystone16:41
bretonit seems16:42
bretonthat it does not work at all16:42
bretonwow.16:42
*** jaosorior has quit IRC16:42
openstackgerritTin Lam proposed openstack/keystone: Complete OS-TRUST API documentation  https://review.openstack.org/34158416:45
*** edmondsw has quit IRC16:45
openstackgerritRichard proposed openstack/keystone: Improve user experience involving token flush  https://review.openstack.org/34116516:47
*** adrian_otto has joined #openstack-keystone16:47
*** agireud has quit IRC16:49
*** roxanagh_ has joined #openstack-keystone16:50
*** gyee has joined #openstack-keystone16:50
*** ChanServ sets mode: +v gyee16:50
stevemarback!16:51
stevemarsamueldmq: i think that is definitely useful16:52
bretonsamueldmq: stevemar: oh, i ran into it too. https://bugs.launchpad.net/keystone/+bug/160277216:53
openstackLaunchpad bug 1602772 in OpenStack Identity (keystone) ""_{n}" suffixes in parameters.yaml are not used" [Undecided,New]16:53
bretonsamueldmq: stevemar: it seems that parameters with suffixes were supposed to work... somehow16:53
*** roxanaghe has quit IRC16:54
dstanekbreton: you just use those entries in the inc files16:54
stevemarbreton: i started to just prefix things cause they overlapped: https://review.openstack.org/#/c/341584/6/api-ref/source/v3-ext/parameters.yaml16:54
patchbotstevemar: patch 341584 - keystone - Complete OS-TRUST API documentation16:54
*** thumpba has quit IRC16:55
bretondstanek: yep. But they are not used currently. For example, there are 19 "name" parameters in api-ref/source/v3/parameters.yaml, not used anywhere16:55
*** GB21 has joined #openstack-keystone16:56
*** lucas____ has quit IRC16:56
*** sdake has joined #openstack-keystone16:56
*** agireud has joined #openstack-keystone16:58
*** julim_ has quit IRC16:58
*** julim has joined #openstack-keystone16:59
openstackgerritSteve Martinelli proposed openstack/keystone: Create APIs for OS-REVOKE  https://review.openstack.org/34155417:00
openstackgerritNisha Yadav proposed openstack/python-keystoneclient: Add region functional tests  https://review.openstack.org/33915817:00
*** links has quit IRC17:01
*** thumpba has joined #openstack-keystone17:04
dstanekbreton: do that have the same definition as the non-suffices ones? i wonder if they should be used and aren't17:04
lbragstaddstanek https://review.openstack.org/#/c/341649/17:07
patchbotlbragstad: patch 341649 - keystone - Adds missing docs to endpoint policy api-ref17:07
bretondstanek: they are different. Some are "project name", some are "user name" etc. They should be used and aren't.17:07
openstackgerritSteve Martinelli proposed openstack/keystone: Complete OS-TRUST API documentation  https://review.openstack.org/34158417:08
*** dikonoor has quit IRC17:10
lbragstaddstanek one comment on https://review.openstack.org/#/c/341650/117:11
patchbotlbragstad: patch 341650 - keystone - Adds missing parameter to endpoint policy api-ref17:11
*** GB21 has quit IRC17:14
*** KevinE has joined #openstack-keystone17:14
*** michauds has joined #openstack-keystone17:14
dstaneklbragstad: i think it has to be on since line since it's a sphinx directive. i can experiment a little though17:16
lbragstaddstanek no worries - i was just curious17:16
*** ddieterly is now known as ddieterly[away]17:17
*** lucas___ has joined #openstack-keystone17:18
*** timcline has joined #openstack-keystone17:18
*** lucas____ has joined #openstack-keystone17:19
*** nisha_ has quit IRC17:19
*** luca_____ has joined #openstack-keystone17:20
*** luca_____ has quit IRC17:21
*** luca_____ has joined #openstack-keystone17:22
*** lucas___ has quit IRC17:22
*** lucas____ has quit IRC17:23
*** michauds has quit IRC17:26
stevemarsamueldmq: do you know if the error response codes were generated?17:29
openstackgerritBoris Bobrov proposed openstack/keystone: Add OS-KSCRUD api-ref  https://review.openstack.org/34170817:30
bretonsamueldmq: are you going to work on splitting parameters.yaml?17:30
bretonsamueldmq: if not, i'll take it17:30
openstackgerritLance Bragstad proposed openstack/keystone: Improve the API documentation for groups  https://review.openstack.org/34171017:31
lbragstadstevemar ^17:32
openstackgerritSteve Martinelli proposed openstack/keystone: Complete OS-TRUST API documentation  https://review.openstack.org/34158417:34
*** michauds has joined #openstack-keystone17:34
openstackgerritLance Bragstad proposed openstack/keystone: List 20X status codes as Normal in domain docs  https://review.openstack.org/34171417:35
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes for auth docs  https://review.openstack.org/34171517:39
bretonsamueldmq: ok, i'm assuming that you don't work on it :)17:40
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes for credential docs  https://review.openstack.org/34171617:41
*** ddieterly[away] is now known as ddieterly17:43
openstackgerritDavid Stanek proposed openstack/keystone: Fixes response codes in endpoint policy api-ref  https://review.openstack.org/34171817:43
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes for policy docs  https://review.openstack.org/34171917:43
openstackgerritSteve Martinelli proposed openstack/keystone: Complete OS-TRUST API documentation  https://review.openstack.org/34158417:43
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes for project docs  https://review.openstack.org/34172017:45
openstackgerritMerged openstack/keystone: Improve keystone.conf [resource] documentation  https://review.openstack.org/33672817:46
knikollabreton: have you had time to work on the devstack plugin?17:46
openstackgerritMerged openstack/keystone: Improve keystone.conf [role] documentation  https://review.openstack.org/34035117:46
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes for region docs  https://review.openstack.org/34172317:47
*** phalmos has quit IRC17:51
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes for role docs  https://review.openstack.org/34172617:52
bretonknikolla: hi. A little. But i was not able to figure out what mapping to use for general case. And i am not sure that we should. IN my opinion, we should not create either idp or mapping, an should leave this to user.17:54
bretonknikolla: all the plugin should do is create a configuration with pre-defined idp name, like idp_117:55
bretonknikolla: in future, we might add more names (idp_2 etc)17:56
bretonknikolla: test writer should create mapping, idp etc17:56
knikollabreton: that's what rodrigo suggested too. i've prepared a patch for that, but wanted to sync up with you before pushing it.17:57
bretonknikolla: i actually tried to write a test with federation set up17:57
bretonknikolla: and figure out what would be more convenient for a test writer17:57
bretonknikolla: i'd say it's better to do the thing i and rodrigods suggest17:58
bretonknikolla: so yeah, if you want to push that, please do17:58
knikollabreton: cool, thanks.17:59
*** gordc has quit IRC17:59
rodrigodsknikolla, breton, ++ you cal also check a pretty general mapping rule being created here: https://review.openstack.org/#/c/324769/8/keystone_tempest_plugin/tests/scenario/test_federated_authentication.py17:59
patchbotrodrigods: patch 324769 - keystone - WIP: Federated authentication via ECP functional t...17:59
rodrigodsline 5417:59
*** ddieterly is now known as ddieterly[away]18:00
*** ametts has joined #openstack-keystone18:00
stevemardstanek: http://developer.openstack.org/api-ref/identity/v2/index.html18:01
bretonknikolla: i will be happy to review it right after the sprint18:01
knikollarodrigods: breton: mapping is not the only issue though. I need to map attributes in shibboleth too.18:02
*** agireud has quit IRC18:02
rodrigodsknikolla, just another config?18:02
knikollarodrigods: yes, however is it IdP specific?18:04
rodrigodsknikolla, yes, what is the IdP that is installed by default?18:05
rodrigodsknikolla, btw, can you point me again to the k2k testing code you have?18:05
knikollarodrigods: i don't know which IdP will be used in the generic federation setting, if you provide me with the configuration you have used for mod_shib for your tests i could use that.18:06
knikollarodrigods: sure, https://github.com/wjdan94/keystone/tree/liberty/tempest_plugin18:06
*** agireud has joined #openstack-keystone18:07
knikollarodrigods: it's a fork of your branch18:07
rodrigodsknikolla, i used mod_auth_mellon + rhsoo18:07
openstackgerritAndrew Laski proposed openstack/oslo.policy: Allow policy file to not exist  https://review.openstack.org/34173218:07
rodrigodsknikolla, but the remote attributes that is translated as a mapping_remote_type in the tests config, can be anything18:07
rodrigodscheck the patch above18:08
bretonknikolla: lets live with default ones18:09
openstackgerritGage Hugo proposed openstack/keystone: Add OS-EP-FILTER to api-ref  https://review.openstack.org/34173418:09
gagehugo^ Im having tox issues, couldn't get api-ref to build18:09
*** pcaruana has joined #openstack-keystone18:09
bretonknikolla: and maybe add a set of pre-defined ones for k2k18:10
*** pnavarro has quit IRC18:10
*** luca_____ has quit IRC18:10
openstackgerritSteve Martinelli proposed openstack/keystone: Add "v2 overview" docs to APIs  https://review.openstack.org/34173918:11
*** lucas___ has joined #openstack-keystone18:12
*** lucas___ has quit IRC18:13
*** lucas___ has joined #openstack-keystone18:13
*** ravelar159 has quit IRC18:13
stevemarlbragstad: breton gagehugo dstanek: https://review.openstack.org/#/c/341739/118:13
patchbotstevemar: patch 341739 - keystone - Add "v2 overview" docs to APIs18:13
knikollarodrigods: breton: alright, i'll give it a test.18:13
rodrigodsknikolla, breton, are we going to use the same keystone as idp/sp in k2k?18:14
bretonrodrigods: for the first version yes18:14
samueldmqbreton: go ahead18:14
knikollabreton: rodrigods: i hope only temporarily.18:14
samueldmqstevemar: not sure I got your question... how the error response are generated in the published docs?18:15
samueldmqstevemar: sorry the delay I was afk in a meeting18:15
*** michauds has quit IRC18:16
*** mordred has joined #openstack-keystone18:19
*** ametts has quit IRC18:24
*** lucas___ has quit IRC18:24
*** ravelar159 has joined #openstack-keystone18:26
*** browne has quit IRC18:26
bretonsamueldmq: in .inc files there are lists of error codes18:26
*** timcline has quit IRC18:26
*** timcline has joined #openstack-keystone18:27
bretonsamueldmq: in api-ref/source/v3/domains.inc for example, there is Error response codes:413,405,404,403,401,400,503,18:27
bretonsamueldmq: how were they generated?18:28
*** ametts has joined #openstack-keystone18:28
*** phalmos has joined #openstack-keystone18:28
*** timcline has quit IRC18:32
samueldmqbreton: that was from the initial conversion from WADL docs18:32
samueldmqbreton: so I assume those were documented there already18:32
*** lucas___ has joined #openstack-keystone18:33
openstackgerritSteve Martinelli proposed openstack/keystone: Add "v2 overview" docs to APIs  https://review.openstack.org/34173918:35
stevemarbreton: ^18:35
*** lucas___ has quit IRC18:37
*** tonytan4ever has quit IRC18:40
mgagnedstanek: fyi, I applied https://review.openstack.org/#/c/327885/ to kilo and it fixed my caching issue with role assignments18:40
patchbotmgagne: patch 327885 - keystone - Fix cache invalidation18:40
*** samueldmq has quit IRC18:40
dstanekmgagne: nice18:41
mgagnedstanek: furthermore, I think we should increase the priority on this bug as I feel it is a security issue too. I suspect (didn't test) that even if a role is removed from a user, that user could still get a token with this role assigned.18:42
*** edtubill has quit IRC18:43
bretonmgagne: that's true18:44
bretonmgagne: it fails some tests, i will restore work on it right after the sprint18:45
*** adrian_otto has quit IRC18:47
dstanekdogpile has caused so many bugs for us18:49
*** rdo has joined #openstack-keystone18:49
openstackgerritSteve Martinelli proposed openstack/keystone: Add "v2 overview" docs to APIs  https://review.openstack.org/34173918:50
*** gordc has joined #openstack-keystone18:51
*** david-lyle has quit IRC18:53
*** sheel has quit IRC18:56
*** edtubill has joined #openstack-keystone18:57
*** sdake has quit IRC18:58
*** browne has joined #openstack-keystone18:58
stevemarthanks everyone for joining the API sprint!!! :)18:59
*** mordred has quit IRC18:59
stevemarhttps://review.openstack.org/#/q/status:open+project:openstack/keystone+branch:master+topic:keystone-api-sprint18:59
openstackgerritDolph Mathews proposed openstack/keystone: Improve keystone.conf [tokenless_auth] documentation  https://review.openstack.org/34059119:00
openstackgerritMerged openstack/keystone: Reorders API calls to match precedence rules  https://review.openstack.org/34164819:00
openstackgerritMerged openstack/keystone: Adds missing docs to endpoint policy api-ref  https://review.openstack.org/34164919:01
openstackgerritMerged openstack/keystone: Adds missing parameter to endpoint policy api-ref  https://review.openstack.org/34165019:01
*** michauds has joined #openstack-keystone19:01
*** webmichael has quit IRC19:02
*** michauds has quit IRC19:06
*** phalmos has quit IRC19:11
lbragstadstevemar are we done?19:11
stevemarlbragstad: no, but i had to go to a meeting with the at&t folks19:11
stevemarlbragstad: i think it's just you and ron now :(19:11
stevemarbreton logged off the call19:11
lbragstadstevemar ah19:11
stevemarso did dstanek19:11
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes for role docs  https://review.openstack.org/34172619:12
*** timcline has joined #openstack-keystone19:13
*** edtubill has quit IRC19:14
*** jed56 has quit IRC19:15
*** pnavarro has joined #openstack-keystone19:17
*** edtubill has joined #openstack-keystone19:17
*** michauds has joined #openstack-keystone19:17
*** timcline has quit IRC19:18
lbragstaddstanek what about times when we have Error response codes: but the list is empty?19:18
lbragstaddstanek should we just remove those?19:18
lbragstadand leave the Normal response codes: since its the only one that has a value in the list?19:18
*** phalmos has joined #openstack-keystone19:19
bknudson_the error response codes are generally useless. It's just standard http19:19
openstackgerritRon De Rose proposed openstack/keystone: Remove unused parameters with underscore suffix in api-ref  https://review.openstack.org/34175719:20
openstackgerritRon De Rose proposed openstack/keystone: Remove unused parameters with underscore suffix in api-ref  https://review.openstack.org/34175719:21
*** agireud has quit IRC19:22
*** michauds has quit IRC19:22
edtubillHi, I'm trying to figure out what the /v3/credential(s) endpoint does. Can someone help me? I'm also trying to figure out what the implications are for giving a user RBAC access to "create_credential".19:22
*** sdake has joined #openstack-keystone19:22
openstackgerritMerged openstack/keystone: Reorder request params in endpoint policy api-ref  https://review.openstack.org/34165119:24
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes in service catalog doc  https://review.openstack.org/34175919:26
*** agireud has joined #openstack-keystone19:27
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes in trust documentation  https://review.openstack.org/34176019:27
openstackgerritMerged openstack/keystone: Create APIs for OS-REVOKE  https://review.openstack.org/34155419:28
*** pnavarro has quit IRC19:28
openstackgerritDolph Mathews proposed openstack/keystone: Validate SAML keyfile & certfile options  https://review.openstack.org/34152519:28
*** edtubill has quit IRC19:28
*** ddieterly[away] is now known as ddieterly19:29
*** michauds has joined #openstack-keystone19:31
*** edtubill has joined #openstack-keystone19:32
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes in OS-INHERIT docs  https://review.openstack.org/34176219:32
openstackgerritKristi Nikolla proposed openstack/keystone: WIP: Devstack plugin for Federation  https://review.openstack.org/32062319:33
*** edmondsw has joined #openstack-keystone19:34
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes in endpoint policy docs  https://review.openstack.org/34176519:34
*** pcaruana has quit IRC19:35
*** michauds has quit IRC19:37
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes in oauth docs  https://review.openstack.org/34176719:38
*** lucas___ has joined #openstack-keystone19:41
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes in v2.0 token docs  https://review.openstack.org/34176819:42
*** michauds has joined #openstack-keystone19:43
openstackgerritDolph Mathews proposed openstack/keystone: Improve keystone.conf [token] documentation  https://review.openstack.org/34164619:43
*** lucas___ has quit IRC19:44
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes in v2.0 admin user docs  https://review.openstack.org/34177019:45
*** can8dnSix has joined #openstack-keystone19:47
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes in oauth docs  https://review.openstack.org/34176719:47
*** edtubill has quit IRC19:48
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes in v2.0 token docs  https://review.openstack.org/34176819:48
*** michauds has quit IRC19:48
*** ddieterly is now known as ddieterly[away]19:49
*** michauds has joined #openstack-keystone19:50
openstackgerritSteve Martinelli proposed openstack/keystone: Correct normal response codes in oauth docs  https://review.openstack.org/34176719:50
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes in service catalog doc  https://review.openstack.org/34175919:50
openstackgerritSteve Martinelli proposed openstack/keystone: Correct normal response codes in v2.0 token docs  https://review.openstack.org/34176819:50
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes in trust documentation  https://review.openstack.org/34176019:51
*** michauds has quit IRC19:51
*** ddieterly[away] is now known as ddieterly19:52
*** edtubill has joined #openstack-keystone19:53
*** browne has quit IRC19:53
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes for role docs  https://review.openstack.org/34172619:53
*** michauds has joined #openstack-keystone19:54
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes in v2.0 tenant docs  https://review.openstack.org/34178119:55
openstackgerritDolph Mathews proposed openstack/keystone: Use URIOpt instead of StrOpt for SAML config  https://review.openstack.org/34151419:56
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes in v2.0 versions doc  https://review.openstack.org/34178219:56
*** sdake has quit IRC19:57
openstackgerritMerged openstack/keystone: List 20X status codes as Normal in domain docs  https://review.openstack.org/34171419:58
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes for v2.0 extensions  https://review.openstack.org/34178319:58
*** michauds has quit IRC20:01
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes for v2.0 versions doc  https://review.openstack.org/34178520:01
openstackgerritGage Hugo proposed openstack/keystone: Add OS-EP-FILTER to api-ref  https://review.openstack.org/34173420:01
openstackgerritGage Hugo proposed openstack/keystone: Add OS-EP-FILTER to api-ref  https://review.openstack.org/34178620:04
openstackgerritGage Hugo proposed openstack/keystone: Add OS-EP-FILTER to api-ref  https://review.openstack.org/34178720:04
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes for project docs  https://review.openstack.org/34172020:05
*** rderose has joined #openstack-keystone20:06
openstackgerritMerged openstack/keystone: Improve the API documentation for groups  https://review.openstack.org/34171020:06
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes for policy docs  https://review.openstack.org/34171920:06
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes for project docs  https://review.openstack.org/34172020:07
*** catintheroof has quit IRC20:07
*** timcline has joined #openstack-keystone20:08
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes for credential docs  https://review.openstack.org/34171620:08
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes for auth docs  https://review.openstack.org/34171520:09
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes for region docs  https://review.openstack.org/34172320:10
*** adrian_otto has joined #openstack-keystone20:10
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes in OS-INHERIT docs  https://review.openstack.org/34176220:11
*** timcline has quit IRC20:12
openstackgerritDolph Mathews proposed openstack/keystone: Improve keystone.conf [signing] documentation  https://review.openstack.org/34179020:12
openstackgerritDolph Mathews proposed openstack/keystone: Improve keystone.conf [shadow_users] documentation  https://review.openstack.org/34179120:14
*** gordc has quit IRC20:15
*** browne has joined #openstack-keystone20:16
*** tonytan4ever has joined #openstack-keystone20:17
*** richm has quit IRC20:18
*** edtubill has quit IRC20:18
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal status codes for v2.0 admin docs  https://review.openstack.org/34179620:20
*** edtubill has joined #openstack-keystone20:22
*** raildo has quit IRC20:22
openstackgerritLance Bragstad proposed openstack/keystone: Correct normal response codes in OS-INHERIT docs  https://review.openstack.org/34176220:22
openstackgerritMerged openstack/keystone: Complete OS-TRUST API documentation  https://review.openstack.org/34158420:23
*** neophy has joined #openstack-keystone20:24
openstackgerritThomas Goirand proposed openstack/keystone: Fix python{3,}-all-dev depends in deb based  https://review.openstack.org/34101020:24
*** julim has quit IRC20:30
rderoseJenkins giving me -1, but everything passes except: gate-keystone-python35-db-nv, which is non-voting20:31
rderoseanyone know why this would happen?  or is gate-keystone-python35-db-nv actually voting?20:31
rderosehttps://review.openstack.org/#/c/340074/20:32
patchbotrderose: patch 340074 - keystone - PCI-DSS Lockout requirements20:32
*** ddieterly is now known as ddieterly[away]20:35
*** clenimar__ has joined #openstack-keystone20:35
*** chrisshattuck has quit IRC20:35
openstackgerritDolph Mathews proposed openstack/keystone: Improve keystone.conf [security_compliance] documentation  https://review.openstack.org/34179720:39
edtubillHi, does anyone here know what would happen if I gave a non admin user access to "create_credential" on keystone? I'm trying to find documentation on what it's used for.20:40
edtubillstevemar:^20:40
openstackgerritRon De Rose proposed openstack/keystone: Remove unused parameters with underscore suffix in api-ref  https://review.openstack.org/34175720:41
*** richm has joined #openstack-keystone20:41
*** richm has quit IRC20:41
*** daemontool_ has quit IRC20:41
*** clenimar__ has quit IRC20:42
*** richm has joined #openstack-keystone20:42
*** richm has quit IRC20:42
*** clenimar_ has joined #openstack-keystone20:42
*** tqtran has joined #openstack-keystone20:42
tqtranstevemar: quick question, is_admin_project mentioned in https://review.openstack.org/#/c/341317/ , is that just for V3 or does V2 also support it?20:42
patchbottqtran: patch 341317 - django_openstack_auth - Add 'is_admin_project' attribute in token20:42
*** david-lyle has joined #openstack-keystone20:43
dstanekedtubill: right now it really isn't used for much20:43
dstanekedtubill: one thing we plan on using it for is TOTP and that would require non-admins have access to create/update/delete their own data20:43
edtubilldstanek: That's cool I was looking into that TOTP too. I was also told it was used with an external heat engine? Is that right?20:45
openstackgerritDolph Mathews proposed openstack/keystone: Improve keystone.conf [signing] documentation  https://review.openstack.org/34179020:45
*** chrisshattuck has joined #openstack-keystone20:47
*** david-lyle has quit IRC20:47
*** neophy has quit IRC20:49
dstanekedtubill: no idea. you'd have to ask heat folks about that20:49
*** david-lyle has joined #openstack-keystone20:49
dstanekedtubill: we have a blueprint to encrypt the data we are storing in there. should be merged this cycle20:50
*** phalmos has quit IRC20:52
openstackgerritDolph Mathews proposed openstack/keystone: Improve keystone.conf [security_compliance] documentation  https://review.openstack.org/34179720:54
*** roxanagh_ has quit IRC20:56
*** pnavarro has joined #openstack-keystone20:58
*** julim has joined #openstack-keystone20:58
edtubilldstanek: oh okay, so I guess I should ask the other projects for who uses the credential endpoint for keystone? I'm trying to figure out if anything bad would happen if I gave "create_credential" to a user of a different role (like if a cloud_admin role had access, could they get access to the admin user). I found the blue print, I'll take a look at it https://review.openstack.org/#/c/284950/8/specs/keystone/newton/credential-encryption.rst.20:58
patchbotedtubill: patch 284950 - keystone-specs - Credential Encryption (MERGED)20:58
*** ddieterly[away] is now known as ddieterly20:58
*** ddieterly has quit IRC20:59
*** roxanaghe has joined #openstack-keystone20:59
*** can8dnSix has quit IRC20:59
*** ddieterly has joined #openstack-keystone21:01
*** timcline has joined #openstack-keystone21:02
*** david-lyle__ has joined #openstack-keystone21:02
*** adu has quit IRC21:04
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Lockout requirements  https://review.openstack.org/34007421:05
*** timcline has quit IRC21:06
*** samueldmq has joined #openstack-keystone21:09
*** ChanServ sets mode: +v samueldmq21:09
*** thumpba has quit IRC21:10
*** ddieterly is now known as ddieterly[away]21:12
*** adu has joined #openstack-keystone21:13
stevemartqtran: that's a v3-isn21:13
stevemarism*21:13
openstackgerritMerged openstack/keystone: Fixes response codes in endpoint policy api-ref  https://review.openstack.org/34171821:14
tqtranyeah i saw the patch for it21:14
tqtranseems like its blank if the condition isnt true, so it would be empty/missing for either version21:15
*** richm has joined #openstack-keystone21:17
*** gagehugo has quit IRC21:20
*** ravelar159 has quit IRC21:22
*** adrian_otto1 has joined #openstack-keystone21:26
*** jlk has left #openstack-keystone21:26
*** david-lyle__ has quit IRC21:28
*** adrian_otto has quit IRC21:29
*** jaugustine has quit IRC21:31
*** ddieterly[away] has quit IRC21:34
*** tonytan4ever has quit IRC21:35
*** daemontool_ has joined #openstack-keystone21:40
*** roxanaghe has quit IRC21:41
*** ravelar159 has joined #openstack-keystone21:43
*** ozialien10 has quit IRC21:43
*** rcernin has quit IRC21:43
openstackgerritClenimar Filemon proposed openstack/keystone: Add is_domain to scope token response examples  https://review.openstack.org/34181521:43
*** ozialien10 has joined #openstack-keystone21:44
*** edtubill has quit IRC21:46
*** pnavarro has quit IRC21:48
openstackgerritRichard proposed openstack/keystone: Improve user experience involving token flush  https://review.openstack.org/34116521:50
rderosebreton: re 341757, if we're not removing the parameters, then what's the fix for this bug?21:50
openstackgerritClenimar Filemon proposed openstack/keystone: Add is_domain to project example responses  https://review.openstack.org/34182021:52
*** ddieterly has joined #openstack-keystone21:53
openstackgerritRichard proposed openstack/keystone: Improve user experience involving token flush  https://review.openstack.org/34116521:53
*** tqtran has quit IRC21:54
*** roxanaghe has joined #openstack-keystone21:57
*** ravelar159 has quit IRC21:58
*** rderose has quit IRC22:01
*** adrian_otto1 has quit IRC22:01
*** pauloewerton has quit IRC22:02
*** adrian_otto has joined #openstack-keystone22:02
*** adu has quit IRC22:02
*** timcline has joined #openstack-keystone22:04
*** rderose has joined #openstack-keystone22:08
*** timcline has quit IRC22:08
*** ddieterly is now known as ddieterly[away]22:10
*** roxanaghe has quit IRC22:12
*** roxanaghe has joined #openstack-keystone22:13
*** gagehugo has joined #openstack-keystone22:17
*** ametts has quit IRC22:20
*** KevinE has quit IRC22:24
openstackgerritClenimar Filemon proposed openstack/keystone: Update identity endpoint in v3 samples  https://review.openstack.org/34182922:25
*** samueldmq has quit IRC22:27
*** jrist has joined #openstack-keystone22:29
*** tonytan4ever has joined #openstack-keystone22:35
*** tonytan4ever has quit IRC22:41
*** ddieterly[away] is now known as ddieterly22:42
*** jrist has quit IRC22:46
*** mordred has joined #openstack-keystone22:48
openstackgerritMerged openstack/keystone: Correct normal response codes in oauth docs  https://review.openstack.org/34176722:49
openstackgerritMerged openstack/keystone: Correct normal response codes in v2.0 token docs  https://review.openstack.org/34176822:50
*** slberger has left #openstack-keystone22:51
jamielennoxstevemar: you feeling confident to push the button on22:53
jamielennoxhttps://review.openstack.org/#/c/339356/22:53
patchbotjamielennox: patch 339356 - keystone - Require auth_context middleware in the pipeline22:53
jamielennoxlast sec ctrl+v fail22:53
openstackgerritSam Leong proposed openstack/keystone-specs: Document current behaviors for role_assignments?include_names and include_subree  https://review.openstack.org/33981222:56
openstackgerritClenimar Filemon proposed openstack/keystone: Update identity endpoint in v2 samples  https://review.openstack.org/34184123:00
*** adu has joined #openstack-keystone23:03
openstackgerritSam Leong proposed openstack/keystone-specs: Document current behaviors for role_assignments?include_names and include_subree  https://review.openstack.org/33981223:04
*** bradjones has quit IRC23:06
*** bradjones has joined #openstack-keystone23:07
*** bradjones has quit IRC23:07
*** bradjones has joined #openstack-keystone23:07
*** tonytan4ever has joined #openstack-keystone23:08
*** ddieterly is now known as ddieterly[away]23:09
*** ddieterly[away] has quit IRC23:11
*** chrisshattuck has quit IRC23:14
*** tonytan4ever has quit IRC23:15
*** tonytan4ever has joined #openstack-keystone23:15
*** rderose has quit IRC23:16
*** spzala has quit IRC23:16
*** spzala has joined #openstack-keystone23:17
*** spzala has quit IRC23:21
*** adu has quit IRC23:26
*** sdake has joined #openstack-keystone23:26
*** edmondsw has quit IRC23:26
*** sdake__ has joined #openstack-keystone23:28
*** sdake has quit IRC23:32
*** sdake__ has quit IRC23:36
*** code-R_ has quit IRC23:38
openstackgerritGage Hugo proposed openstack/keystone: Add OS-EP-FILTER to api-ref  https://review.openstack.org/34178723:44
*** adu has joined #openstack-keystone23:50
*** gagehugo has quit IRC23:53
*** tonytan4ever has quit IRC23:54
*** adu has quit IRC23:55
*** rderose has joined #openstack-keystone23:57

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!