Friday, 2017-09-29

*** catintheroof has quit IRC00:06
stevelle001Anyone able to help me refine this search: looking for design decisions leading to tokens always being returned in headers, instead of in body00:14
*** thorst has quit IRC00:15
SamYaplestevelle001: you want to find a conversation/spec that talks about whether the auth tokens should be passed via the hedears or in the body?00:24
*** alex_xu has joined #openstack-keystone00:25
*** alex_xu has quit IRC00:25
*** alex_xu has joined #openstack-keystone00:25
*** thorst has joined #openstack-keystone00:26
*** rcernin has quit IRC00:29
stevelle001SamYaple: that's what I'm hoping for, particularly in terms of the operations which create tokens00:29
stevelle001also hello again00:30
SamYapleim not sure tht exists, if i understand you correctly. The auth header is parsed by keystonemiddleware, and middleware doesnt dig into the body is my undertanding00:35
SamYaplestevelle001: hi!00:35
*** zhurong has joined #openstack-keystone00:38
*** itlinux has joined #openstack-keystone00:38
stevelle001I'm only interested in the keystone api itself, not how the header is used on other service APIs (handled by the middleware).  See https://github.com/openstack/keystone-specs/blob/master/attic/v3/identity-api-v3.rst "While token objects do have identifiers, they are not passed in resource URL's nor are they included in the objects themselves." I'm00:40
stevelle001trying to get a clear idea of why the OS_TOKEN isn't in the resource.00:40
*** thorst has quit IRC00:40
stevelle001I know I'm not asking that very clearly00:40
*** aselius has quit IRC00:45
SamYapleOh i see you question now. I don't have an answer for you though. someone else will come along though, im sure00:46
*** thorst has joined #openstack-keystone00:47
*** thorst has quit IRC00:51
samueldmqstevelle001: SamYaple: hi, that's somewhat a historical decision00:52
stevelle001I figured as much00:52
samueldmqbut I think it had something to do with being safer to be transmitted at the header? I'm not sure00:52
SamYapleeasier to parse maybe00:52
samueldmqbut I think kmalloc may know it00:52
*** erlon has quit IRC00:53
stevelle001I assumed it was to prevent security issues -> logging the response body. wanted to find the discussion to consider fully00:54
kmallocYep00:55
kmallocMostly to help eliminate logging, especially of the request itself containing secure data.00:55
stevelle001request payloads are not treated the same, only response00:56
stevelle001was hoping to get a little insight into that too00:56
stevelle001I couldn't find a cve for this when I looked00:56
*** thorst has joined #openstack-keystone00:58
*** thorst has quit IRC01:00
*** thorst has joined #openstack-keystone01:00
*** thorst_ has joined #openstack-keystone01:01
*** thorst has quit IRC01:04
*** thorst_ has quit IRC01:05
*** panbalag has joined #openstack-keystone01:07
*** tommylikehu has joined #openstack-keystone01:11
*** panbalag has left #openstack-keystone01:11
*** Shunli has joined #openstack-keystone01:27
*** sbezverk has joined #openstack-keystone01:31
*** markvoelker has joined #openstack-keystone01:38
*** itlinux has quit IRC01:39
*** jamesbenson has joined #openstack-keystone01:44
*** jamesbenson has quit IRC01:49
*** zhurong has quit IRC01:50
*** zhurong has joined #openstack-keystone01:58
*** thorst has joined #openstack-keystone02:02
*** gyee has quit IRC02:09
*** markvoelker has quit IRC02:13
*** dave-mcc_ has quit IRC02:13
*** rcernin has joined #openstack-keystone02:20
*** itlinux has joined #openstack-keystone02:24
*** spotz has quit IRC02:29
*** lbragstad has joined #openstack-keystone02:31
*** ChanServ sets mode: +o lbragstad02:31
*** spotz has joined #openstack-keystone02:37
*** jamesbenson has joined #openstack-keystone02:38
*** itlinux has quit IRC02:50
*** markvoelker has joined #openstack-keystone03:10
*** zhurong has quit IRC03:12
*** markvoelker has quit IRC03:42
*** cfriesen has quit IRC03:48
*** lbragstad has quit IRC04:00
*** links has joined #openstack-keystone04:02
*** zhurong has joined #openstack-keystone04:20
*** markvoelker has joined #openstack-keystone04:39
*** tonytan4ever has joined #openstack-keystone04:42
*** tonytan4ever_brb has quit IRC04:43
*** aojea has joined #openstack-keystone04:46
*** aojea has quit IRC04:50
*** jamesbenson has quit IRC04:59
*** markvoelker has quit IRC05:12
*** Shunli has quit IRC05:15
*** rcernin has quit IRC05:15
*** tonytan4ever has quit IRC05:15
*** tonytan4ever has joined #openstack-keystone05:15
*** pcaruana has joined #openstack-keystone05:24
*** aojea has joined #openstack-keystone05:26
*** pcaruana has quit IRC05:29
*** rcernin has joined #openstack-keystone05:52
openstackgerritJamie Lennox proposed openstack/keystone master: Remove middleware reference to PARAMS_ENV and CONTEXT_ENV  https://review.openstack.org/50841005:59
openstackgerritJamie Lennox proposed openstack/keystone master: Move auth header definitions into authorization  https://review.openstack.org/50841105:59
openstackgerritJamie Lennox proposed openstack/keystone master: Remove the TokenAuth middleware  https://review.openstack.org/50841205:59
*** aojea has quit IRC06:00
*** josecastroleon has quit IRC06:00
*** markvoelker has joined #openstack-keystone06:09
*** aojea has joined #openstack-keystone06:10
*** tonytan4ever_brb has joined #openstack-keystone06:10
*** tonytan4ever has quit IRC06:12
*** masber has joined #openstack-keystone06:15
*** jmlowe has quit IRC06:20
*** tonytan4ever_brb has quit IRC06:42
*** markvoelker has quit IRC06:43
*** jamesbenson has joined #openstack-keystone06:48
*** jamesbenson has quit IRC06:52
*** ioggstream has joined #openstack-keystone06:58
*** pcaruana has joined #openstack-keystone07:04
*** aojea has quit IRC07:30
*** masber has quit IRC07:31
*** iogg has joined #openstack-keystone07:35
*** ioggstream has quit IRC07:39
*** markvoelker has joined #openstack-keystone07:40
*** markvoelker has quit IRC08:12
*** jaosorior has joined #openstack-keystone08:37
*** sbezverk has quit IRC08:38
*** belmoreira has joined #openstack-keystone08:38
*** iogg is now known as ioggstream09:01
*** markvoelker has joined #openstack-keystone09:09
*** aojea has joined #openstack-keystone09:15
*** markvoelker has quit IRC09:43
*** aojea has quit IRC09:49
*** adriant has quit IRC10:06
*** stevemar has quit IRC10:06
*** stevemar has joined #openstack-keystone10:07
*** aojea has joined #openstack-keystone10:09
*** aojea has quit IRC10:12
*** aojea has joined #openstack-keystone10:12
*** aojea_ has joined #openstack-keystone10:18
*** aojea has quit IRC10:19
*** adriant has joined #openstack-keystone10:22
*** jamesbenson has joined #openstack-keystone10:24
*** masber has joined #openstack-keystone10:28
*** jamesbenson has quit IRC10:28
*** masber has quit IRC10:32
*** aojea_ has quit IRC10:35
*** zhurong has quit IRC10:36
*** markvoelker has joined #openstack-keystone10:40
*** aojea has joined #openstack-keystone10:50
*** markvoelker has quit IRC11:12
*** sapd_ has quit IRC11:17
*** sapd_ has joined #openstack-keystone11:17
*** sapd_ has quit IRC11:17
*** sapd_ has joined #openstack-keystone11:18
*** edmondsw has quit IRC11:21
*** sapd_ has quit IRC11:23
*** sapd_ has joined #openstack-keystone11:24
*** aojea has quit IRC11:27
*** suramya_ has joined #openstack-keystone11:29
*** raildo has joined #openstack-keystone11:55
*** stevelle001 has quit IRC11:56
*** thorst has quit IRC12:00
*** thorst has joined #openstack-keystone12:00
*** sapd__ has joined #openstack-keystone12:03
*** sapd__ has quit IRC12:03
*** sapd_ has quit IRC12:03
*** sapd__ has joined #openstack-keystone12:04
*** markvoelker has joined #openstack-keystone12:09
*** tonytan4ever has joined #openstack-keystone12:13
*** edmondsw has joined #openstack-keystone12:13
*** tonytan4ever has quit IRC12:18
*** aojea has joined #openstack-keystone12:20
*** markvoelker has quit IRC12:29
*** markvoelker has joined #openstack-keystone12:29
*** 07IAA8DSW has joined #openstack-keystone12:29
*** 5EXAACMRJ has joined #openstack-keystone12:29
*** 07IAA8DSW has quit IRC12:33
*** 5EXAACMRJ has quit IRC12:34
*** jmlowe has joined #openstack-keystone12:35
*** hoonetorg has joined #openstack-keystone12:35
*** panbalag has joined #openstack-keystone12:38
*** catintheroof has joined #openstack-keystone13:03
Dinesh_BhorHi all, can anyone take a look at this and add his/her opinion? http://lists.openstack.org/pipermail/openstack-dev/2017-September/122725.html13:14
*** lbragstad has joined #openstack-keystone13:15
*** ChanServ sets mode: +o lbragstad13:15
*** ioggstream has quit IRC13:20
*** efried is now known as fried_rice13:21
Dinesh_Bhorlbragstad, dstanek: It will be great if you reply to this or add comment on the bug directly: http://lists.openstack.org/pipermail/openstack-dev/2017-September/122725.html13:21
*** tonytan4ever has joined #openstack-keystone13:27
*** dansmith is now known as superdan13:34
*** links has quit IRC13:39
*** suramya_ has quit IRC13:43
*** Dinesh_Bhor has quit IRC13:48
knikollao/13:53
*** cfriesen has joined #openstack-keystone13:56
*** sbezverk has joined #openstack-keystone13:59
*** jamesbenson has joined #openstack-keystone14:00
*** jamesbenson has quit IRC14:04
*** aojea has quit IRC14:16
openstackgerritColleen Murphy proposed openstack/keystonemiddleware master: Rename auth_uri to www_authenticate_uri  https://review.openstack.org/50852214:21
openstackgerritColleen Murphy proposed openstack/keystonemiddleware master: Rename auth_uri to www_authenticate_uri  https://review.openstack.org/50852214:21
*** aojea has joined #openstack-keystone14:24
openstackgerritColleen Murphy proposed openstack/keystonemiddleware master: Rename auth_uri to www_authenticate_uri  https://review.openstack.org/50852214:28
*** jaosorior has quit IRC14:33
gagehugoo/14:37
knikollagagehugo: o/14:40
*** aojea has quit IRC14:42
*** aojea has joined #openstack-keystone14:46
*** knasim-wrs has joined #openstack-keystone14:53
knasim-wrshi experts, quick question on keystone admin and public apps... before Newton, when keystone was running under eventlets we had certain operations that were not allowed over publicURL. But now with gunicorn running 2 separate app instances, I don't see any distinction between admin and public apps15:01
*** rcernin has quit IRC15:01
knasim-wrswhat does the keystone-admin app provide that the keystone-public app doesn't?15:01
lbragstadknasim-wrs: good question - the keystone-admin app and keystone-public app was a thing we had to do with the v2.0 API15:01
lbragstadthe v2.0 API isolated admin functionality to keystone-admin and public functionality to the keystone-public app15:02
lbragstadwhen we implemented v3, we combined both applications and manage policy for what you can and can't do in the application itself15:02
lbragstadthat way you don't have to host two separate identity applications for full functionality15:02
knasim-wrsso we are on Identity V3, does that mean I can have one or the other and it'd be equal? Right now I have 2 gunicorn apps (port 35357 and 5000)15:03
lbragstadsome of that history is actually documented https://docs.openstack.org/keystone/latest/contributor/http-api.html15:03
lbragstadv3 doesn't care or change functionality if it is run on 5000 versus 3535715:04
lbragstadthe v3 api should be the same regardless15:04
knasim-wrsthanks a lot Lance. This is very helpful for us15:05
lbragstadknasim-wrs: anytime!15:05
*** aojea has quit IRC15:05
knasim-wrsnow that we are migrating to Ocata, I can get rid of one of the app15:06
lbragstadknasim-wrs: so long as you aren't deploying v2.0 in anyway15:06
lbragstadknasim-wrs: but yeah, that would be awesome, because we removed almost all v2.0 bits in queens15:06
knasim-wrsthanks Lance. I'll keep that in mind, last I remembered as of Newton, Neutron was still using Identity V2 so need to make sure its moved onto V3 in Ocata/Pike15:07
*** aselius has joined #openstack-keystone15:08
lbragstadknasim-wrs: we had a big push to move everything to v315:09
*** belmoreira has quit IRC15:14
*** aojea has joined #openstack-keystone15:15
*** panbalag has quit IRC15:21
*** dave-mccowan has joined #openstack-keystone15:21
*** aojea has quit IRC15:25
lbragstadFYI - http://lists.openstack.org/pipermail/openstack-dev/2017-September/122886.html15:30
*** d0ugal has joined #openstack-keystone15:31
knasim-wrsthanks Lance. One more question:15:33
knasim-wrsto prevent people from deleting the admin user or the services users / services project, I've added hacks inside the Keystone code but I realize that it'd be better to do this as RBAC rules15:34
*** chlong has quit IRC15:35
knasim-wrssomething like: identity:delete_project: not services:%(target.project.name)15:35
knasim-wrsdoes RBAC allow NOT rules?15:36
openstackgerritLance Bragstad proposed openstack/keystone master: Add policy for project tags  https://review.openstack.org/48675715:37
lbragstadknasim-wrs: oslo.policy appears to support it - but i've never experiemented with NOT specifically https://docs.openstack.org/oslo.policy/latest/reference/api/oslo_policy.policy.html15:39
knasim-wrsthanks a bunch Lance!15:39
lbragstadgagehugo: i think you're changes are failing because of https://review.openstack.org/#/c/508511/15:39
lbragstadknasim-wrs: yep - let me know how that works for you15:40
*** nkinder has quit IRC15:40
gagehugo:(15:40
lbragstadgagehugo: i added a depends on to https://review.openstack.org/#/c/486757/15:41
lbragstadwe'll see if that clears things up15:41
gagehugolbragstad thanks!15:41
gagehugoI figured things will just move slow until the issues with zuul3 get fixed15:41
lbragstadyeah...15:42
lbragstadi'm going through keystone changes to see if there is anything else that might affect us15:42
gagehugorip those changes I made for skipping jobs15:44
*** nkinder has joined #openstack-keystone15:44
gagehugoI'm reading the new zuul stuff now15:44
lbragstadwe haven't had a lot of stuff enter the gate recently so we might not seem15:47
lbragstadsee much*15:47
gagehugooh they have the skipping in there now, cool15:51
gagehugohttps://git.openstack.org/cgit/openstack-infra/project-config/tree/zuul.d/projects.yaml#n1683415:52
knikollairrelevant-files, i like the naming.15:52
gagehugoknikolla ++15:53
knikollagagehugo: ksm doesn't have that section15:53
gagehugoyeah I'll edit https://review.openstack.org/#/c/504243/ for zuul315:54
knikollagagehugo: cool!15:54
openstackgerritGage Hugo proposed openstack/python-keystoneclient master: DNM: This is a change that makes keystoneclient.session.Session explode  https://review.openstack.org/50320715:57
*** zzzeek has quit IRC15:58
*** zzzeek has joined #openstack-keystone15:59
*** sbezverk has quit IRC16:04
*** ioggstream has joined #openstack-keystone16:12
lbragstadgagehugo: https://review.openstack.org/#/c/484483/ passes though16:18
gagehugo\o/16:20
*** jmlowe has quit IRC16:20
lbragstadonly one comment on that patch, just to make sure we don't miss updating the specification16:21
openstackgerritGage Hugo proposed openstack/keystone master: Add project tags api-ref documentation and reno  https://review.openstack.org/47239616:21
*** jamesbenson has joined #openstack-keystone16:23
*** itlinux has joined #openstack-keystone16:23
gagehugolbragstad https://review.openstack.org/#/c/508339/16:24
*** ioggstream has quit IRC16:26
*** pcaruana has quit IRC16:26
*** jamesbenson has quit IRC16:27
lbragstadgagehugo: nice - thanks!16:28
SamYaplelbragstad: so my issue *was* timeouts. lots of em16:34
SamYapleone of the nova tables had like a million entries (and no indexing) so the db was returning ultraslow like16:34
SamYaplesomehow that manifested in middleware getting NotFound exceptions16:35
lbragstadSamYaple: whoa...16:35
lbragstadit's totally opaque16:35
SamYapleindeed. but its fixed now16:35
SamYapleso now you can say "ive seen that before!" if it pops up again16:36
*** edmondsw has quit IRC16:37
*** itlinux has quit IRC16:44
*** gyee has joined #openstack-keystone16:45
*** lnxnut_ has joined #openstack-keystone16:46
*** itlinux has joined #openstack-keystone16:47
gagehugolbragstad https://review.openstack.org/#/c/507694/ is definitely WIP, I had to whiteboard out the inheritance for those tests :(16:53
lbragstadgagehugo: ack - i assume the classes that inherit LDAPIdentity somehow inherit the unit.TestCase class16:54
gagehugothere's one in the test_backend_ldap_pool that does16:55
gagehugoand another that inherits just LDAPIdentity16:55
gagehugoI need to look over it again, there is definitely no reason that each of those tests need to be ran ~8 times16:57
*** itlinux has quit IRC17:02
*** aahh has joined #openstack-keystone17:07
*** jamesbenson has joined #openstack-keystone17:25
*** NM has joined #openstack-keystone17:35
*** edmondsw has joined #openstack-keystone17:37
*** jmlowe has joined #openstack-keystone17:41
*** dave-mccowan has quit IRC17:41
*** thorst has quit IRC17:45
*** raildo has quit IRC17:45
*** raildo has joined #openstack-keystone17:51
*** david-lyle has quit IRC17:56
lbragstadsamueldmq: https://review.openstack.org/#/c/504459/1 looks good, couple suggestions on things we can add17:56
*** david-lyle has joined #openstack-keystone17:56
*** NM has quit IRC18:04
*** hoonetorg has quit IRC18:06
*** NM has joined #openstack-keystone18:15
*** boris_42_ has joined #openstack-keystone18:15
aahh@lbragstad : any idea why would we encounter this error on devstack http://www.paste.org/8630018:19
aahhhavent modified any files in it18:19
lbragstadaahh: that looks like a pbr bug18:21
lbragstador something is wrong with the dependencies installed18:21
aahhwas working all good until few minutes back , any suggestions on how to fix18:23
lbragstadyou could try reinstalling some of the dependencies, or the package that is giving you problems and retry?18:27
lbragstadhttps://ask.openstack.org/en/question/88600/installation-of-openstack-fails-with-attributeerror-module-object-has-no-attribute-add_metaclass/18:27
lbragstadsounds like there might be conflicting versions of the same package on the system18:27
lbragstadweird stuff happens when system and local packages are both installed18:27
* lbragstad steps away to grab lunch quick18:29
knasim-wrs@lbragstad: the "not" operations worked in Keystone RBAC. Thanks!18:35
*** thorst has joined #openstack-keystone18:45
*** thorst has quit IRC18:50
*** ayoung has joined #openstack-keystone18:53
ayounglbragstad, is gagehugo not working on 968696 anymore?  Are you going to drive on with my Nova fix for it?18:54
*** lbragstad has quit IRC19:03
*** lbragstad has joined #openstack-keystone19:07
*** ChanServ sets mode: +o lbragstad19:07
lbragstadayoung: yeah - we need to reassess after the ptg discussions19:08
lbragstadif gagehugo isn't able to pick it back up i can try and carve out cycles for it19:08
lbragstad(not sure if those messages came through)19:08
gagehugoayoung I wasn't sure if we were continuing with is_admin_project19:08
ayoungI thought the idea was to eventually go for the Service Roles, but since those are undefined now, and we can transition from is_admin_project to service roles (I think) this gives a path forward.  Was not going to push, though19:09
lbragstadgagehugo: i think you dropped yourself from that bug prior to all the discussions in Denver, right?19:09
gagehugolbragstad I stopped working on it once global roles because a thing19:11
gagehugoand I wasn't sure what direction we were going in19:12
lbragstadgagehugo: ack19:12
lbragstadthat makes sense19:12
lbragstadat the PTG jamielennox made a bunch of point about providing a path from one to the other since is_admin_project is technically in the wild19:12
lbragstadpart of that roadmap consisted of building a thing in oslo.policy/context that projects should consume19:13
lbragstadthat knows how to handle system roles and is_admin_project equally19:13
lbragstadthus, shielding the projects from having to care about the implementation detals19:13
lbragstaddetails*19:13
ayoungService scoped roles could have is_admin_project set to true19:14
ayoungtokens with Service scoped roles could have is_admin_project set to true19:14
lbragstada system scoped token and a token with is_admin_project are the same thing19:15
lbragstadessentially19:15
openstackgerritLance Bragstad proposed openstack/keystone master: Remove v2.0 identity APIs  https://review.openstack.org/49978319:17
openstackgerritLance Bragstad proposed openstack/keystone master: Remove v2.0 token APIs  https://review.openstack.org/49978419:18
openstackgerritLance Bragstad proposed openstack/keystone master: Remove v2.0 auth APIs  https://review.openstack.org/50446519:18
openstackgerritGage Hugo proposed openstack/keystone master: Add project tags api-ref documentation and reno  https://review.openstack.org/47239619:18
*** knasim-wrs has quit IRC19:19
*** catintheroof has quit IRC19:20
*** catintheroof has joined #openstack-keystone19:20
ayounglbragstad, so, we can continue to work on getting the projects to enforce on is_admin_project, which will be a 1-to-1 match with Service scoped rules in the future, and and can add the logic in oslo context once we have service scoped roles implemented.19:24
*** catintheroof has quit IRC19:24
ayoungbut, I'm not going to be writing any more code for a bit...new role and all that19:24
lbragstadayoung: yeah - thats fine, i figured you'd be busy with other things19:26
ayoungso gagehugo if you want to take https://review.openstack.org/#/c/384148/  and work on it in conjunction with the Nova team, please go ahead and do so, as I think it is the single most important thing that needs to happen in Keystone right now19:26
ayoungEven if the rules change, that patch is probably the basis for any other implementation you are going to end up with, so please take it and run with it19:26
ayoungsame with https://review.openstack.org/#/c/257636/  .  lbragstad perhaps the best thing to do is to take that patch and make it look like you want19:28
gagehugoayoung sure19:28
openstackgerritGage Hugo proposed openstack/keystone master: Add project tags api-ref documentation and reno  https://review.openstack.org/47239619:29
ayounglbragstad, gagehugo the one sticking point on the keystone review was that I put the service_role into is_admin_project.  This is for services out there, and I think would translate almost directly to a service scoped roles.  Do you two agree?19:30
lbragstadayoung: we haven't gotten to service roles yet, or service scoping19:30
ayounglbragstad, that does not matter19:30
lbragstadi could see that coming later if system scoping pans out the way we need it to19:31
ayoungthe question is whether the current usage of the service role should be considered is_admin_project only19:31
gagehugothat will be nice if it does translate directly19:31
ayoungand I think it needs to be19:31
ayoungit is, IIUC, only ever assigned to a service user for validating tokens19:31
ayounglbragstad, look at it this way:  would it ever make sense to grant the service_role to someone for an operation scoped to a project?  Seems to contradict the meaning of service there19:34
ayoungand...I don't think we actually currently use that for anything.19:34
ayoung$ grep -rni service_role keystone/* | fpaste19:34
ayoungUploading (0.6KiB)...19:34
ayounghttps://paste.fedoraproject.org/paste/UJqHAtz8LeRFVBUyT~WGSQ19:34
ayoungonly in unit tests.  I can remove that line if you want.19:35
*** thorst has joined #openstack-keystone19:35
ayoungand, since we don't use it, I am OK with removing it19:35
lbragstadayoung: i need to dig into the patch, i haven't look at it recently19:36
ayoungah...we do use it, just via the constants19:36
lbragstadthere's a lot of discussion there and it looks like jamielennox had comments19:37
ayoung$ grep -rni RULE_SERVICE_OR_ADMIN keystone/* | fpaste19:37
ayoungUploading (0.6KiB)...19:37
ayounghttps://paste.fedoraproject.org/paste/Jrmn84weUIuKojBJH4cSWQ19:37
ayounglbragstad, that was his one comment19:37
ayoungservice is a role that is assigned to, say the nova service user that calls back to Keystone in order to validate tokens and check revoke status19:38
ayoungseems to me to be a hole if we were to let a project level admin or lower perform that operation.  So scoping it to a project does not make sense.19:38
ayoungIf we had a global role for token operations, it would be used here instead19:39
*** rarora has joined #openstack-keystone19:50
*** aojea has joined #openstack-keystone20:09
*** aojea has quit IRC20:13
openstackgerritLance Bragstad proposed openstack/keystone master: Use stestr directly instead of ostestr  https://review.openstack.org/50861120:37
lbragstadmtreinish: ^20:37
*** jmlowe has quit IRC20:50
kmalloclbragstad: are we clear for removing 2.0 stuff now?20:54
kmalloclbragstad: looks like the depends on stuff has been droppeD?20:54
lbragstadkmalloc: one of the patches merged and the other didn't need to be a dependency20:54
lbragstada rebase of https://review.openstack.org/#/c/499783/7 should do the trick20:55
lbragstadwe'll see what the tests say but i'm not expecting any real issues20:55
kmallocgreat. I'll shove it through if it's all happy20:55
lbragstadawesome - there is a bunch of stuff queued up behind it20:56
kmallocyep20:56
lbragstadalso - https://review.openstack.org/#/c/508611/ would be good to review20:56
*** thorst has quit IRC21:10
*** wxy has quit IRC21:13
*** raildo has quit IRC21:17
*** aojea has joined #openstack-keystone21:18
*** edmondsw has quit IRC21:20
openstackgerritJamie Lennox proposed openstack/keystone master: Check policy_complete on keystone request  https://review.openstack.org/50861921:24
*** mwheckmann has quit IRC21:26
openstackgerritJamie Lennox proposed openstack/keystone master: Move auth header definitions into authorization  https://review.openstack.org/50841121:27
openstackgerritJamie Lennox proposed openstack/keystone master: Remove the TokenAuth middleware  https://review.openstack.org/50841221:27
jamielennoxayoung: a present on that: https://review.openstack.org/#/c/507726/21:29
*** thorst has joined #openstack-keystone21:30
*** thorst has quit IRC21:35
openstackgerritJamie Lennox proposed openstack/keystone master: Remove the TokenAuth middleware  https://review.openstack.org/50841221:48
*** hoonetorg has joined #openstack-keystone21:50
*** thorst has joined #openstack-keystone21:52
*** thorst has quit IRC21:56
*** jamesbenson has quit IRC22:05
*** NM has quit IRC22:17
openstackgerritLance Bragstad proposed openstack/keystone master: Remove v2.0 identity APIs  https://review.openstack.org/49978322:18
openstackgerritLance Bragstad proposed openstack/keystone master: Remove v2.0 token APIs  https://review.openstack.org/49978422:18
openstackgerritLance Bragstad proposed openstack/keystone master: Remove v2.0 auth APIs  https://review.openstack.org/50446522:18
openstackgerritLance Bragstad proposed openstack/keystone master: Remove v2.0 test plumbing  https://review.openstack.org/50674822:18
*** d0ugal has quit IRC22:23
*** aahh has quit IRC22:23
*** aojea has quit IRC22:32
*** aojea has joined #openstack-keystone22:40
*** aojea has quit IRC22:45
*** thorst has joined #openstack-keystone22:53
*** aojea has joined #openstack-keystone22:57
*** aojea has quit IRC23:02
openstackgerritJamie Lennox proposed openstack/keystonemiddleware master: Issue a deprecation warning for validating PKI tokens  https://review.openstack.org/50863123:06
openstackgerritJamie Lennox proposed openstack/keystonemiddleware master: gitignore .stestr folder  https://review.openstack.org/50863223:10
*** lbragstad has quit IRC23:35
*** fried_rice is now known as efried_thbagh23:40
*** zhurong has joined #openstack-keystone23:52
*** gyee has quit IRC23:53

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!