Tuesday, 2017-10-17

*** dave-mccowan has quit IRC00:00
*** catintheroof has quit IRC00:00
*** dave-mccowan has joined #openstack-keystone00:00
*** catintheroof has joined #openstack-keystone00:00
*** catintheroof has quit IRC00:04
*** edmondsw has joined #openstack-keystone00:13
*** markvoelker_ has quit IRC00:17
*** edmondsw has quit IRC00:18
*** wasmum has quit IRC00:19
*** markvoelker has joined #openstack-keystone00:25
*** markvoelker has quit IRC00:29
*** markvoelker has joined #openstack-keystone00:34
*** markvoelker has quit IRC00:39
*** markvoelker has joined #openstack-keystone00:43
*** aojea has joined #openstack-keystone00:47
*** markvoelker has quit IRC00:48
*** AlexeyAbashkin has joined #openstack-keystone00:48
*** aojea has quit IRC00:52
*** AlexeyAbashkin has quit IRC00:52
*** markvoelker has joined #openstack-keystone00:52
*** markvoelker has quit IRC00:57
*** kiswe has joined #openstack-keystone00:58
*** kiswe has left #openstack-keystone00:58
*** edmondsw has joined #openstack-keystone01:00
*** markvoelker has joined #openstack-keystone01:01
*** Shunli has joined #openstack-keystone01:03
*** markvoelker has quit IRC01:06
*** markvoelker has joined #openstack-keystone01:11
*** markvoelker has quit IRC01:15
*** catintheroof has joined #openstack-keystone01:19
*** markvoelker has joined #openstack-keystone01:20
*** catintheroof has quit IRC01:21
*** AlexeyAbashkin has joined #openstack-keystone01:28
*** AlexeyAbashkin has quit IRC01:32
*** zsli_ has joined #openstack-keystone01:41
*** links has joined #openstack-keystone01:44
*** Shunli has quit IRC01:45
*** links is now known as Jaison|away01:45
*** aojea has joined #openstack-keystone01:48
*** chlong has joined #openstack-keystone01:49
*** daidv_ has joined #openstack-keystone01:52
*** aojea has quit IRC01:52
*** markvoelker has quit IRC01:53
*** markvoelker has joined #openstack-keystone01:59
*** markvoelker has quit IRC02:03
*** masber has quit IRC02:07
*** markvoelker has joined #openstack-keystone02:08
*** markvoelker has quit IRC02:12
*** markvoelker has joined #openstack-keystone02:17
*** markvoelker has quit IRC02:21
*** markvoelker has joined #openstack-keystone02:26
*** AlexeyAbashkin has joined #openstack-keystone02:27
*** markvoelker has quit IRC02:30
*** AlexeyAbashkin has quit IRC02:31
*** markvoelker has joined #openstack-keystone02:35
*** jhesketh has quit IRC02:35
*** jhesketh has joined #openstack-keystone02:38
*** markvoelker has quit IRC02:40
*** wes_dillingham has quit IRC02:43
*** markvoelker has joined #openstack-keystone02:44
*** lbragstad has joined #openstack-keystone02:45
*** ChanServ sets mode: +o lbragstad02:45
lbragstadaahh: the services put keystonemiddleware in their wsgi pipeline and it processes the request as it comes through the service02:46
BenderRodriguezHello everyone02:46
SamYapleo/ BenderRodriguez02:47
*** aojea has joined #openstack-keystone02:49
*** masber has joined #openstack-keystone02:49
*** markvoelker has quit IRC02:49
SamYaplelbragstad: recently (today!) i got openstack/loci autopublishing to images to dockerhub on each commit to openstack/loci. my next step is getting it to publish when a commit merges to keystone/glance/cinder/nova etc. this requires adding a job to the post pipeline of the projects in question. cinder was ok with that https://review.openstack.org/#/c/512398/02:49
SamYapleis this somethign keystone would also +1 ? (infra specifically asked that, at least at this time, the projects ptls +1 a patch like this)02:50
SamYapleit doesnt affect the keystone gates in anyway since its a post job, so this is more of a social issue than a technical one02:50
lbragstadSamYaple: oh - nice02:51
lbragstadSamYaple: i don't think i have a problem with it - are you free tomorrow during the keystone meeting?02:52
SamYaplei can make myself free, yes02:52
SamYaplethe job for cinder builds and pushes to dockerhub in under 5 minutes :) completely usable image afterward02:53
*** markvoelker has joined #openstack-keystone02:53
*** aojea has quit IRC02:53
lbragstadawesome!02:54
lbragstadSamYaple: https://etherpad.openstack.org/p/keystone-weekly-meeting02:54
SamYapleawesome, thanks lbragstad02:58
lbragstadSamYaple: no problem - thanks for checking02:58
SamYapleim on the fence on whether a project should be required to consult, in this case, keystone to add something like this to the post pipeline, or it should be allowed02:58
SamYaplefor now, im just going to be consulting with the projects, see if anyone has a concern02:59
SamYapleim actually more concerned docker will throttle/block it than anything else lol. but if that happens, we can switch to just publishing on tagged versions of projects03:00
*** zsli_ is now known as Shunli03:03
openstackgerritLance Bragstad proposed openstack/keystone master: Implement backend logic for system roles  https://review.openstack.org/50799403:13
openstackgerritLance Bragstad proposed openstack/keystone master: Implement manager logic for user+system roles  https://review.openstack.org/51246803:13
lbragstadSamYaple: I'd be pretty tough to have gripes about someone doing something in post, I'd think03:13
lbragstadIt'd*03:13
SamYaplemy thoughts as well. but we will go the political route first :)03:14
*** jmlowe has joined #openstack-keystone03:17
*** Jaison|away is now known as links03:23
*** dave-mccowan has quit IRC03:24
*** AlexeyAbashkin has joined #openstack-keystone03:26
*** markvoelker has quit IRC03:27
*** AlexeyAbashkin has quit IRC03:31
openstackgerritMerged openstack/keystone master: Move auth header definitions into authorization  https://review.openstack.org/50841103:33
*** nicolasbock has quit IRC03:41
*** mtreinish has quit IRC03:42
*** mtreinish has joined #openstack-keystone03:42
*** masber has quit IRC03:46
*** aojea has joined #openstack-keystone03:49
*** jmlowe has quit IRC03:52
*** aojea has quit IRC03:54
*** lbragstad has quit IRC03:58
*** jmlowe has joined #openstack-keystone04:01
*** sbezverk has quit IRC04:06
*** markvoelker has joined #openstack-keystone04:17
*** markvoelker has quit IRC04:22
*** AlexeyAbashkin has joined #openstack-keystone04:26
*** markvoelker has joined #openstack-keystone04:27
*** AlexeyAbashkin has quit IRC04:31
*** markvoelker has quit IRC04:33
*** markvoelker has joined #openstack-keystone04:34
*** jmlowe has quit IRC04:48
*** aojea has joined #openstack-keystone04:50
*** aojea has quit IRC04:55
*** cfriesen has quit IRC05:10
*** edmondsw has quit IRC05:17
*** aojea has joined #openstack-keystone05:51
*** markvoelker has quit IRC05:54
*** aojea has quit IRC05:56
*** Suramya has joined #openstack-keystone05:58
*** josecastroleon has joined #openstack-keystone06:07
*** masber has joined #openstack-keystone06:21
*** magicboiz has joined #openstack-keystone06:34
*** aojea has joined #openstack-keystone06:38
*** magicboiz has quit IRC06:39
*** magicboiz has joined #openstack-keystone06:39
*** pcaruana has joined #openstack-keystone06:44
*** aojea has quit IRC06:47
*** markvoelker has joined #openstack-keystone06:50
*** ioggstream has joined #openstack-keystone06:51
openstackgerritColleen Murphy proposed openstack/keystone-specs master: (WIP) Repropose application credentials to queens  https://review.openstack.org/51250506:56
openstackgerritNam Nguyen Hoai proposed openstack/python-keystoneclient master: Use generic user for both zuul v2 and v3  https://review.openstack.org/51250906:59
*** namnh has joined #openstack-keystone07:01
*** edmondsw has joined #openstack-keystone07:01
*** edmondsw has quit IRC07:06
*** tesseract has joined #openstack-keystone07:16
openstackgerritDinesh Bhor proposed openstack/keystoneauth master: Add mask_password to sanitize sensitive data  https://review.openstack.org/51252207:20
openstackgerritNam Nguyen Hoai proposed openstack/python-keystoneclient master: Use generic user for both zuul v2 and v3  https://review.openstack.org/51250907:29
*** AlexeyAbashkin has joined #openstack-keystone07:34
*** josecastroleon has quit IRC07:37
*** aojea has joined #openstack-keystone07:44
*** aojea has quit IRC07:48
*** magicboiz has quit IRC08:41
*** aojea has joined #openstack-keystone08:44
*** aojea has quit IRC08:49
*** edmondsw has joined #openstack-keystone08:50
*** edmondsw has quit IRC08:54
*** markvoelker has quit IRC09:03
*** markvoelker has joined #openstack-keystone09:04
*** josecastroleon has joined #openstack-keystone09:08
*** Shunli has quit IRC09:29
*** aojea has joined #openstack-keystone09:45
*** aojea has quit IRC09:50
*** magicboiz has joined #openstack-keystone10:06
*** magicboiz has quit IRC10:11
*** magicboiz has joined #openstack-keystone10:18
*** Suramya_ has joined #openstack-keystone10:18
*** mvk has quit IRC10:19
*** openstackgerrit has quit IRC10:33
*** namnh has quit IRC10:36
*** edmondsw has joined #openstack-keystone10:38
*** edmondsw has quit IRC10:42
*** tesseract has quit IRC10:43
*** tesseract has joined #openstack-keystone10:43
*** aojea has joined #openstack-keystone10:46
*** mvk has joined #openstack-keystone10:50
*** aojea has quit IRC10:50
*** nicolasbock has joined #openstack-keystone11:02
*** ioggstream has quit IRC11:11
*** raildo has joined #openstack-keystone11:14
*** nicolasbock has quit IRC11:23
*** nicolasbock has joined #openstack-keystone11:35
*** chlong has quit IRC12:01
*** openstackgerrit has joined #openstack-keystone12:03
openstackgerritSuramya proposed openstack/keystone master: Reorganize api-ref: v3 domains  https://review.openstack.org/50513512:04
*** edmondsw has joined #openstack-keystone12:09
*** jmlowe has joined #openstack-keystone12:09
*** wes_dillingham has joined #openstack-keystone12:11
*** ioggstream has joined #openstack-keystone12:14
*** dave-mccowan has joined #openstack-keystone12:22
*** aojea has joined #openstack-keystone12:47
*** panbalag has joined #openstack-keystone12:48
*** panbalag has left #openstack-keystone12:49
*** aojea has quit IRC12:52
*** jmlowe has quit IRC13:04
*** jmlowe has joined #openstack-keystone13:09
*** thorst has joined #openstack-keystone13:14
*** jmlowe has quit IRC13:21
*** lbragstad has joined #openstack-keystone13:22
*** ChanServ sets mode: +o lbragstad13:22
magicboizayoung: some days ago I did ask on x509 end-user auth with horizon/keystone. Could you provide some example/doc/URL to check?13:34
magicboizayoung: you answers that mod_ssl was the solution, but I didn't get it.... :(13:35
ayoungmagicboiz, you use federation...13:35
ayoungmagicboiz, you can use the various mods and variables listed here with Federation http://www.freeipa.org/page/Environment_Variables13:36
ayoungmagicboiz, figure out what in the cert you want to use as the username:  probably a DN or CN or something13:36
magicboizayoung: ok, I understand that point, the CERT DN/CN must be built with some specific info, but, how do I get Horizon/Keystone to work with this?13:38
ayoungmagicboiz, have you read up on Federation?13:38
magicboizayoung: also, is this complatible with multi-domain?13:38
ayounghttps://docs.openstack.org/security-guide/identity/federated-keystone.html   talks about how to do it with mod_shib.  Replace that with mod_ssl.13:39
magicboizayoung: I'd read https://docs.openstack.org/security-guide/identity/federated-keystone.html13:39
ayoungmagicboiz, and yes, multi domain is pretty much essential13:39
ayoungmagicboiz, I don't have all the ssl options for you, but when I did it with mod_nss (like ssl) the config looked like this13:39
ayoungmagicboiz, sorry, when I did it with Kerberos it looked like this13:41
ayounghttps://github.com/admiyo/rippowam/blob/master/roles/packstack/templates/keystone-federation.conf.j213:41
josecastroleonhi ayoung13:41
ayoungmagicboiz, I know that there was a whole push for tokenless auth from service users that used mod_ssl, and that did Federation, so look that up13:41
ayoung!]NO ME LO PUEDO CREER!13:42
openstackayoung: Error: Spurious "]".  You may want to quote your arguments with double quotes in order to prevent extra brackets from being evaluated as nested commands.13:42
ayoungjosecastroleon, como te va!13:42
*** chlong has joined #openstack-keystone13:42
josecastroleonupdating services at CERN cloud13:42
josecastroleoni've just seen your comments about x509 auth13:42
josecastroleonwe are not using the federation channel at the moment for authentication methods13:43
josecastroleonwe have a different entry point for kerberos or x509 auth13:43
magicboizayoung, josecastroleon : and what about horizon? I understand that I have to configure apache+mod_ssl as ayoung indicates, but what about horizon?13:44
ayoungjosecastroleon, what do you mean by entrypoint?13:45
magicboizayoung, josecastroleon : and another issue I'm facinf is the classic Load-Balancer in front of keystone/horizon servers, which intercepts SSL traffic.... :(13:45
ayoungmagicboiz, so long as you can get the load balancer to forward the variables to the wsgi app, you are OK13:46
josecastroleonmagicboiz: use tunneling in the loadbalancer13:46
josecastroleonit will pass also the certificates through13:46
josecastroleonwe have /admin /main for normal user/pass token authentication13:46
josecastroleonwe have /krb for kerberos13:47
josecastroleonand then the entry point has KrbMethodNegotiate On13:47
josecastroleonand a /x509 entry that has SSLVerifyClient require in mod_ssl13:47
magicboizayoung, josecastroleon : ok13:48
*** aojea has joined #openstack-keystone13:48
ayoungjosecastroleon, you are not using Federation for Kerb or X509 though, rioght?13:50
josecastroleonayoung: not yet13:50
josecastroleonthe client plugin does not work13:51
ayoungI'm trying to move people away from that.  Everything should be Federated, so your config is Good, vbut magicboiz should do it infront of /OS-FEDEARTION/<idp>/X509 instead13:51
josecastroleonayoung: and then protect the endpoint in apache with mod_ssl13:52
ayoungmagicboiz, to set up federation requires 3 calls to Keystone:  create Idp, create mapping, create protocol13:52
ayoungonce those three have been made, you can test by using Curl against the URL it would generate to see if you get a 404 (not set up right) or a 403 (Un authed)13:52
ayoungassumign you get to the unauthed state, you then set up the HTTPD conf in front of it.13:53
ayoungWe ansiblized this here:13:53
*** aojea has quit IRC13:53
*** catintheroof has joined #openstack-keystone13:53
ayounghttps://github.com/admiyo/rippowam/blob/master/roles/packstack/tasks/keystone-sssd.yml13:54
magicboizayoung: I'll check it, thank you very much. I'm not an expert on keystone so I'll have to test it step by step....13:58
ayoungmagicboiz, right.  I think I have some troubleshooting you can use...1 sec13:59
magicboizayoung: also, I'm testing all things with devstack (instead of packstack or ansible).... I don't know whether this is valid or not...13:59
ayoungmagicboiz, https://adam.younglogic.com/2015/03/key-fed-lookup-redux/   was roughly my method14:00
ayoungdevstack is fine.  It does apache for the Webserver, and you can modify the config14:00
*** cfriesen has joined #openstack-keystone14:01
*** sbezverk has joined #openstack-keystone14:01
josecastroleonayoung: nice14:02
ayoungjosecastroleon, thanks.  I am mostly worried about how people do LDAP.  I really want that to stop being directly wired into Keystone, and instead done via federation, but with out SSSD/mod_lookup_ideneity, we don;'t yet have a module that will handle it14:03
ayoungLDAP really should be fronted via SAML or OpenIDC for use on the web these days.14:03
josecastroleonayoung: fully agree, i may need to revisit our config ;)14:05
ayoungjosecastroleon, it might be a pretty big data migration effort if the userids don't line up, and Federation does the whole autogenerated approach that I so dislike14:06
*** catintheroof has quit IRC14:11
openstackgerritLance Bragstad proposed openstack/keystone master: Implement manager logic for user+system roles  https://review.openstack.org/51246814:20
openstackgerritLance Bragstad proposed openstack/keystone master: Implement manager logic for group+system roles  https://review.openstack.org/51264114:20
*** dave-mccowan has quit IRC14:21
*** chlong has quit IRC14:34
*** dave-mccowan has joined #openstack-keystone14:37
*** josecastroleon has quit IRC14:40
*** links has quit IRC14:41
*** josecastroleon has joined #openstack-keystone14:42
*** chlong has joined #openstack-keystone14:48
*** catintheroof has joined #openstack-keystone14:51
*** catintheroof has quit IRC15:03
*** aloga has quit IRC15:04
*** aloga has joined #openstack-keystone15:04
*** wes_dillingham has quit IRC15:17
*** markvoelker has quit IRC15:17
*** markvoelker has joined #openstack-keystone15:18
*** josecastroleon has quit IRC15:19
*** markvoelker has quit IRC15:22
*** josecastroleon has joined #openstack-keystone15:23
*** AlexeyAbashkin has quit IRC15:30
*** AlexeyAbashkin has joined #openstack-keystone15:30
*** clenimar has quit IRC15:32
*** clenimar has joined #openstack-keystone15:35
*** AlexeyAbashkin has quit IRC15:41
*** aojea has joined #openstack-keystone15:50
*** aojea has quit IRC15:54
*** pcaruana has quit IRC16:01
*** josecastroleon has quit IRC16:03
*** josecastroleon has joined #openstack-keystone16:07
openstackgerritGage Hugo proposed openstack/keystone master: Add JSON schema validation for project tags  https://review.openstack.org/48448316:29
openstackgerritGage Hugo proposed openstack/keystone master: Add policy for project tags  https://review.openstack.org/48675716:29
openstackgerritGage Hugo proposed openstack/keystone master: Implement backend logic for project tags  https://review.openstack.org/49972616:29
openstackgerritGage Hugo proposed openstack/keystone master: Implement project tags logic into manager  https://review.openstack.org/49972716:29
openstackgerritGage Hugo proposed openstack/keystone master: Implement project tags API controller and router  https://review.openstack.org/49972816:29
*** josecastroleon has quit IRC16:29
*** josecastroleon has joined #openstack-keystone16:32
*** mvk has quit IRC16:38
*** ioggstream has quit IRC16:42
*** aojea has joined #openstack-keystone16:50
*** aojea has quit IRC16:55
*** tesseract has quit IRC17:02
*** aadams has joined #openstack-keystone17:17
*** AlexeyAbashkin has joined #openstack-keystone17:22
*** AlexeyAbashkin has quit IRC17:24
*** mvk has joined #openstack-keystone17:26
*** mike92 has joined #openstack-keystone17:36
*** mike92 has quit IRC17:44
lbragstadinteresting spec for folks to review if they have time - https://review.openstack.org/#/c/505345/117:44
lbragstadcurious to get feedback there17:45
*** mvk has quit IRC17:48
*** mike92 has joined #openstack-keystone17:49
*** josecastroleon has quit IRC17:49
*** mvk has joined #openstack-keystone17:49
*** aojea has joined #openstack-keystone17:51
*** josecastroleon has joined #openstack-keystone17:52
*** aojea has quit IRC17:56
lbragstadping ayoung, breton, cmurphy, dstanek, edmondsw, gagehugo, henrynash, hrybacki, knikolla, lamt, lbragstad, lwanderley, kmalloc, rderose, rodrigods, samueldmq, spilla, aselius, dpar, SamYaple17:56
lbragstadfive minute pre-meeting ping17:56
*** ioggstream has joined #openstack-keystone18:10
*** ioggstream has quit IRC18:32
*** josecastroleon has quit IRC18:35
*** aojea has joined #openstack-keystone18:38
*** josecastroleon has joined #openstack-keystone18:38
*** aojea has quit IRC18:47
SamYaplelbragstad: https://review.openstack.org/#/c/512793/18:49
SamYaplethanks again everyone18:49
lbragstadSamYaple: thanks18:52
lbragstad#startmeeting keystone-office-hours19:04
openstackMeeting started Tue Oct 17 19:04:19 2017 UTC and is due to finish in 60 minutes.  The chair is lbragstad. Information about MeetBot at http://wiki.debian.org/MeetBot.19:04
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.19:04
*** openstack changes topic to " (Meeting topic: keystone-office-hours)"19:04
*** dave-mccowan has quit IRC19:04
openstackThe meeting name has been set to 'keystone_office_hours'19:04
lbragstadalrighty - who's around?19:04
*** ChanServ changes topic to "Queens release schedule: https://releases.openstack.org/queens/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/5F0h9Hoe/keystone"19:04
cmurphyo/19:04
knikollao/19:04
lbragstadawesome - preferences on what you want to do?19:05
lbragstadspec review, an implementation review, something focused, bugs?19:05
knikollahmmm.. any priorities?19:06
cmurphydid my office hours dashboard break or are there no bug related patches in gerrit right now?19:06
lbragstador we can divide and conquer19:06
lbragstadcmurphy: there aren't many patches that close bugs19:06
lbragstadwe worked through most of them, or they need fixing19:06
lbragstadknikolla: anything from the meeting :)19:06
* lbragstad fetches his new favorite link19:07
lbragstad#link https://trello.com/b/5F0h9Hoe/keystone?menu=filter&filter=due:week19:07
* cmurphy will go look at project tag things19:07
lbragstadawesome - that'd be good19:08
lbragstadknikolla: kmalloc would be good to get your opinions on https://review.openstack.org/#/c/505345/119:09
knikollalooking19:09
gagehugoo/19:10
* knikolla will review specs then. if there's any implementation patches that need more eyes give me a ping. 19:10
gagehugosorry was reading jwt19:10
lbragstadgagehugo: by all means - keep reading JWT19:11
gagehugothe spec looks good19:11
lbragstadjamielennox: i assume this can be abandon now - https://review.openstack.org/#/c/248524/ ?19:16
lbragstadlamt: you had an interest in the ksm+oslo.cache work didn't you?19:18
lbragstadlamt: i just stumbled across https://review.openstack.org/#/c/268664/19:18
cfriesenlbragstad:  In https://review.openstack.org/#/c/505345/1/specs/keystone/queens/auth-response-restrict-catalog.rs you talk about "getting Morgan's take on this".  I don't know who that is. :)19:20
lbragstadcfriesen: oh - i'm sorry19:20
lbragstadMorgan == kmalloc19:20
cfriesenthanks19:20
lbragstadcfriesen: yep! spec looks good19:20
*** clenimar has quit IRC19:21
cfriesenI'll try and respin shortly19:22
cfriesenhopefully by tomorrow.19:22
*** markvoelker has joined #openstack-keystone19:26
*** dave-mccowan has joined #openstack-keystone19:29
kmalloclbragstad: hehe19:33
kmalloccfriesen: yeah, I had to change my nic to hide ;)19:34
*** AlexeyAbashkin has joined #openstack-keystone19:40
*** aojea has joined #openstack-keystone19:43
*** AlexeyAbashkin has quit IRC19:44
*** MasterOfBugs has joined #openstack-keystone19:47
*** pramodrj07 has joined #openstack-keystone19:47
*** aojea has quit IRC19:48
*** catintheroof has joined #openstack-keystone19:49
*** panbalag has joined #openstack-keystone19:57
*** panbalag has left #openstack-keystone20:00
kmalloclbragstad cfriesen: commented20:06
kmallocbasically i want some metrics showing the benefit(S) of this filtering being server side.20:06
kmallocand be clear this is *not* to provide added security20:09
lbragstadyeah - didn't mean to imply security in my comment20:09
kmallocright, but it highlightsd that people might think it does20:10
lbragstadthough - in hindsight, it probably came across that way20:10
kmallocwe need to be very explicit it provides no added security20:10
lbragstadupdated my comment20:12
*** markvoelker_ has joined #openstack-keystone20:15
*** chlong has quit IRC20:16
mike92Hi. I was wondering if I could ask a question about endpoints in keystone?20:17
openstackgerritMerged openstack/python-keystoneclient master: Use generic user for both zuul v2 and v3  https://review.openstack.org/51250920:17
*** markvoelker has quit IRC20:18
*** AlexeyAbashkin has joined #openstack-keystone20:22
lbragstadmike92: go for it20:24
mike92Thanks. In my deployment, the endpoint url has a dynamic hostname in it. Like https://dyndns.com...  At some points my keystone config processing, the dns may not be running.  In these cases, I want to specify a uri with an explicit ip to the server I know is running the keystone server, like http://127.0.0.1.20:24
mike92Previously, I did this with OS_URL and admin_token.  I could use OS_URL and it didn't matter what the endpoint in keystone was.  Is there something similar I can do in Ocata or Pike?20:25
mike92This would be for the openstack command.  Previously I set OS_URL and openstack worked fine.  Now I have problems because openstack is trying to contact the dyndns address and it's not connecting20:26
*** AlexeyAbashkin has quit IRC20:27
lbragstadmike92: have you tried using OS_AUTH_URL?20:34
lbragstadhttps://docs.openstack.org/python-openstackclient/latest/cli/authentication.html20:34
*** catintheroof has quit IRC20:35
*** catintheroof has joined #openstack-keystone20:36
*** catintheroof has quit IRC20:36
*** raildo has quit IRC20:37
mike92I do have OS_URL_SET, but openstack tries to use the endpoint in keystone during the communication20:38
mike92# echo $OS_AUTH_URL20:38
mike92http://127.0.0.1:35357/v320:38
mike92[root@localhost httpd]# openstack --debug  endpoint list20:38
mike92...20:38
mike92"POST /v3/auth/tokens HTTP/1.1" 201 104420:38
mike92{"token": {"is_domain": false, "methods": ["password"], "roles": [{"id": "03de69ec878843caa16d57c934ede47d", "name": "admin"}], "expires_at": "2017-11-16T20:36:50.000000Z", "project": {"domain": {"id": "default", "name": "Default"}, "id": "2a763d4465b346e4997eb305d3fc87c1", "name": "admin"}, "catalog": [{"endpoints": [{"url": "http://dyndns:35357/", "interface": "admin", "region": null, "region_id": null, "id": "e09499e3203e40198fa42f4f444f599d"}20:38
mike92, {"url": "http://dyndns:35357/", "interface": "internal", "region": null, "region_id": null, "id": "dfbd1a6519ab4c658c1d913d2b025379"}, {"url": "http://dyndns:5000/", "interface": "public", "region": null, "region_id": null, "id": "c99f89d7f0a84364868bb12f4570570a"}], "type": "identity", "id": "295eaf6ea94547b4ae770f0bee7c4504", "name": "keystone"}], "user": {"domain": {"id": "default", "name": "Default"}, "password_expires_at": null, "name": "a20:39
mike92dmin", "id": "395f1f23859245fe84dd1b056935de87"}, "audit_ids": ["V7RQCtHYRpuJj_y8RXDHBA"], "issued_at": "2017-10-17T20:36:50.000000Z"}}20:39
mike92REQ: curl -g -i -X GET http://dyndns:35357/ -H "Accept: application/json" -H "User-Agent: osc-lib/1.7.0 keystoneauth1/3.1.0 python-requests/2.11.1 CPython/2.7.5"20:39
mike92Starting new HTTP connection (1): dyndns20:39
mike92It tries to contact the dyndns address20:39
mike92sorry. I meant I have OS_AUTH_URL set20:39
*** aojea has joined #openstack-keystone20:44
*** dave-mccowan has quit IRC20:48
*** aojea has quit IRC20:49
lbragstadoh - that seems openstack-client specific20:51
lbragstadping dtroyer ^20:52
*** sapd__ has joined #openstack-keystone20:53
*** sapd_ has quit IRC20:53
*** david-lyle has quit IRC20:57
dtroyerOS_URL should only be used if OS_TOKEN is also set, in which case the service catalog is bypassed and OS_URL is used directly to contact the service being used by the command.  This breaks down for any command that talks to multiple services (such as looking up  names/ID on another API).20:59
dtroyerOtherwise we use the Service Catalog to locate the services.21:00
dtroyerYou may have an option to configure different interfaces (public/admin/internal) and select between thise in the service catalog, say setting internal to the IP address then forcing that when you need it21:01
openstackgerritMerged openstack/keystone master: Add JSON schema validation for project tags  https://review.openstack.org/48448321:01
mike92that's an interesting idea.  I'll see if I can get something like to work in my deployment.21:03
gagehugocmurphy it's been awhile since I've looked at that OSC patch21:11
*** david-lyle has joined #openstack-keystone21:13
cmurphy:)21:13
gagehugoit definitely needs some fixing up21:14
mike92Thanks for the help!21:15
openstackgerritGage Hugo proposed openstack/keystone master: Add project tags api-ref documentation and reno  https://review.openstack.org/47239621:16
*** edmondsw has quit IRC21:16
cmurphygagehugo: i didn't look at much besides the docs, i was just using it to start validating the server code21:16
gagehugocmurphy I think it kinda works if I remember right21:16
gagehugolbragstad https://review.openstack.org/#/c/506751/21:18
*** chlong has joined #openstack-keystone21:18
*** edmondsw_ has joined #openstack-keystone21:18
lbragstadhmm - those look like legit failures21:19
gagehugoyeah21:19
gagehugoidk why jenkins/zuul never ran after you last pushed21:20
gagehugothat might have been the previous zuul3 attempt21:20
*** edmondsw_ has quit IRC21:22
*** thorst has quit IRC21:25
*** thorst has joined #openstack-keystone21:26
*** thorst has quit IRC21:30
*** josecastroleon has quit IRC21:34
*** josecastroleon has joined #openstack-keystone21:37
openstackgerritLance Bragstad proposed openstack/keystone master: Deleting an identity provider doesn't invalidate tokens  https://review.openstack.org/51287221:43
lbragstadpartial fix for a bug ^21:43
*** aojea has joined #openstack-keystone21:45
*** aojea has quit IRC21:49
*** erlon has quit IRC21:50
*** thorst has joined #openstack-keystone21:50
*** edmondsw has joined #openstack-keystone21:51
*** thorst has quit IRC21:54
*** edmondsw has quit IRC21:55
*** Suramya_ has quit IRC21:57
*** Suramya has quit IRC21:57
lbragstad#endmeeting22:00
*** openstack changes topic to "Queens release schedule: https://releases.openstack.org/queens/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/5F0h9Hoe/keystone"22:00
openstackMeeting ended Tue Oct 17 22:00:06 2017 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)22:00
openstackMinutes:        http://eavesdrop.openstack.org/meetings/keystone_office_hours/2017/keystone_office_hours.2017-10-17-19.04.html22:00
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/keystone_office_hours/2017/keystone_office_hours.2017-10-17-19.04.txt22:00
openstackLog:            http://eavesdrop.openstack.org/meetings/keystone_office_hours/2017/keystone_office_hours.2017-10-17-19.04.log.html22:00
cmurphyo722:00
lbragstadproductive office hours - thanks all!22:02
*** mike92 has quit IRC22:09
*** wes_dillingham has joined #openstack-keystone22:28
*** dave-mccowan has joined #openstack-keystone22:36
*** lbragstad has quit IRC22:36
*** catintheroof has joined #openstack-keystone22:43
openstackgerritGage Hugo proposed openstack/keystone master: Add project tags api-ref documentation and reno  https://review.openstack.org/47239622:59
*** aadams has quit IRC23:04
*** catintheroof has quit IRC23:17
*** jmlowe has joined #openstack-keystone23:47
openstackgerritMerged openstack/keystone master: Add policy for project tags  https://review.openstack.org/48675723:57

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!