Tuesday, 2017-12-19

*** d0ugal has joined #openstack-keystone00:04
*** rcernin has quit IRC00:09
*** rcernin_ has joined #openstack-keystone00:09
* lbragstad ducks00:13
openstackgerritLance Bragstad proposed openstack/keystone master: Implement backend logic for system roles  https://review.openstack.org/50799400:14
openstackgerritLance Bragstad proposed openstack/keystone master: Implement manager logic for user+system roles  https://review.openstack.org/51246800:14
openstackgerritLance Bragstad proposed openstack/keystone master: Implement manager logic for group+system roles  https://review.openstack.org/51264100:14
openstackgerritLance Bragstad proposed openstack/keystone master: Add user system grant policies  https://review.openstack.org/51447100:14
openstackgerritLance Bragstad proposed openstack/keystone master: Add group system grant policies  https://review.openstack.org/51472500:14
openstackgerritLance Bragstad proposed openstack/keystone master: Implement controller logic for system user assignments  https://review.openstack.org/51521500:14
openstackgerritLance Bragstad proposed openstack/keystone master: Implement controller logic for system group assignments  https://review.openstack.org/52401700:14
openstackgerritLance Bragstad proposed openstack/keystone master: Add system role assignment documentation  https://review.openstack.org/52430700:14
openstackgerritLance Bragstad proposed openstack/keystone master: Add ability to list all system role assignments  https://review.openstack.org/52440700:14
openstackgerritLance Bragstad proposed openstack/keystone master: Ensure building scope is mutually exclusive  https://review.openstack.org/49809100:14
openstackgerritLance Bragstad proposed openstack/keystone master: Remove private methods for v2.0 and v3 tokens  https://review.openstack.org/52532900:14
openstackgerritLance Bragstad proposed openstack/keystone master: Teach TokenFormatter how to handle system scope  https://review.openstack.org/52533000:14
openstackgerritLance Bragstad proposed openstack/keystone master: Implement system-scope in the token provider API  https://review.openstack.org/52536000:14
openstackgerritLance Bragstad proposed openstack/keystone master: Introduce assertions for system-scoped token testing  https://review.openstack.org/52803700:14
openstackgerritLance Bragstad proposed openstack/keystone master: Implement system-scoped tokens  https://review.openstack.org/52568700:14
openstackgerritLance Bragstad proposed openstack/keystone master: Add release note for system-scope  https://review.openstack.org/52803900:14
openstackgerritLance Bragstad proposed openstack/keystone master: Add configuration option for enforcing system-scope  https://review.openstack.org/52884700:14
lbragstadayoung: that new series introduces the configuration option we talked about00:18
ayoungcool00:18
lbragstadso - every time there is a call being made with a token of the wrong scope, a warning will be logged if an exception isn't raised00:19
*** aojea has joined #openstack-keystone00:23
*** aojea has quit IRC00:28
*** d0ugal has quit IRC00:40
*** rcernin_ has quit IRC00:50
*** d0ugal has joined #openstack-keystone00:51
*** jose-phillips has quit IRC00:53
*** jose-phillips has joined #openstack-keystone00:54
*** catintheroof has joined #openstack-keystone00:56
*** edmondsw has joined #openstack-keystone00:58
*** gyee has quit IRC01:01
*** catintheroof has quit IRC01:21
*** linkmark has quit IRC01:33
openstackgerritOpenStack Proposal Bot proposed openstack/python-keystoneclient master: Updated from global requirements  https://review.openstack.org/52890401:43
*** edmondsw has quit IRC01:53
*** aselius has quit IRC02:05
*** rcernin has joined #openstack-keystone02:11
*** r-daneel has quit IRC02:17
*** aojea has joined #openstack-keystone02:25
*** aojea has quit IRC02:29
openstackgerritwangxiyuan proposed openstack/keystone-specs master: Limits API  https://review.openstack.org/45570902:32
*** AlexeyAbashkin has joined #openstack-keystone02:38
openstackgerritwangxiyuan proposed openstack/keystone master: Add db operation for unified limit  https://review.openstack.org/52408202:39
openstackgerritwangxiyuan proposed openstack/keystone master: Add limit provider  https://review.openstack.org/52410902:39
openstackgerritwangxiyuan proposed openstack/keystone master: [WIP]Expose unified limit APIs  https://review.openstack.org/52411002:39
*** AlexeyAbashkin has quit IRC02:43
*** edmondsw has joined #openstack-keystone03:15
*** edmondsw has quit IRC03:19
*** markvoelker has joined #openstack-keystone03:24
*** dave-mccowan has quit IRC03:51
*** markvoelker has quit IRC03:58
*** bhagyashris has left #openstack-keystone04:00
openstackgerritwangxiyuan proposed openstack/keystone master: Fix sphinx CI failure  https://review.openstack.org/52894904:12
*** aojea has joined #openstack-keystone04:25
*** aojea has quit IRC04:30
*** markvoelker has joined #openstack-keystone04:55
*** markvoelker has quit IRC05:28
*** links has joined #openstack-keystone05:47
openstackgerritQinglin Cheng proposed openstack/keystone master: Create doc/requirements.txt  https://review.openstack.org/52896006:01
*** annp has joined #openstack-keystone06:09
*** afazekas has quit IRC06:11
*** afazekas has joined #openstack-keystone06:11
*** namnh has joined #openstack-keystone06:13
*** aojea has joined #openstack-keystone06:17
openstackgerritQinglin Cheng proposed openstack/python-keystoneclient master: Create doc/requirements.txt  https://review.openstack.org/52896406:21
*** markvoelker has joined #openstack-keystone06:25
*** aojea has quit IRC06:28
openstackgerritDinesh Bhor proposed openstack/python-keystoneclient master: Add Response class to return request-id to caller  https://review.openstack.org/32991306:40
*** aojea has joined #openstack-keystone06:50
*** aojea has quit IRC06:50
*** aojea has joined #openstack-keystone06:50
*** edmondsw has joined #openstack-keystone06:51
*** aojea has quit IRC06:52
*** edmondsw has quit IRC06:55
*** markvoelker has quit IRC06:59
*** aojea has joined #openstack-keystone07:02
*** aojea has quit IRC07:06
*** magicboiz has quit IRC07:25
*** rcernin has quit IRC07:31
*** Dave has quit IRC07:48
*** Dave has joined #openstack-keystone07:49
*** AlexeyAbashkin has joined #openstack-keystone07:52
*** samuelbartel has joined #openstack-keystone07:56
openstackgerritwangqiang-bj proposed openstack/keystone master: remove some misleading info in Update user API doc.  https://review.openstack.org/52898308:01
*** rcernin has joined #openstack-keystone08:02
*** d0ugal has quit IRC08:03
*** d0ugal has joined #openstack-keystone08:07
*** apuimedo has joined #openstack-keystone08:17
*** edmondsw has joined #openstack-keystone08:39
*** edmondsw has quit IRC08:44
*** aojea has joined #openstack-keystone08:45
*** markvoelker has joined #openstack-keystone08:56
*** magicboiz has joined #openstack-keystone09:00
*** magicboiz has quit IRC09:04
*** magicboiz has joined #openstack-keystone09:05
*** aojea has quit IRC09:05
*** aojea_ has joined #openstack-keystone09:08
*** mvk has quit IRC09:25
*** markvoelker has quit IRC09:29
*** josecastroleon has joined #openstack-keystone09:37
*** Dinesh_Bhor has joined #openstack-keystone09:42
*** Dinesh_Bhor has quit IRC09:42
*** mvk has joined #openstack-keystone09:52
*** lxnch has joined #openstack-keystone09:55
*** rarora has quit IRC09:57
*** lxnch_ has quit IRC09:59
*** afazekas has quit IRC10:01
*** namnh has quit IRC10:01
*** josecastroleon has quit IRC10:06
*** josecastroleon has joined #openstack-keystone10:07
*** afazekas has joined #openstack-keystone10:07
openstackgerritQinglin Cheng proposed openstack/python-keystoneclient master: Create doc/requirements.txt  https://review.openstack.org/52896410:25
*** markvoelker has joined #openstack-keystone10:26
*** edmondsw has joined #openstack-keystone10:27
*** mvk has quit IRC10:31
*** edmondsw has quit IRC10:32
*** mvk has joined #openstack-keystone10:32
*** josecastroleon has quit IRC10:37
openstackgerritColleen Murphy proposed openstack/keystone master: Fix the docs job after moving to build-sphinx  https://review.openstack.org/52884510:47
*** markvoelker has quit IRC11:00
openstackgerritColleen Murphy proposed openstack/keystone master: Fix the docs job after moving to build-sphinx  https://review.openstack.org/52884511:07
openstackgerritQinglin Cheng proposed openstack/keystone master: Create doc/requirements.txt  https://review.openstack.org/52896011:18
openstackgerritColleen Murphy proposed openstack/keystone master: Fix the docs job after moving to build-sphinx  https://review.openstack.org/52884511:18
*** AlexeyAbashkin has quit IRC11:22
openstackgerritColleen Murphy proposed openstack/keystone master: Fix the docs job after moving to build-sphinx  https://review.openstack.org/52884511:30
*** AlexeyAbashkin has joined #openstack-keystone11:38
openstackgerritQinglin Cheng proposed openstack/python-keystoneclient master: Create doc/requirements.txt  https://review.openstack.org/52896411:40
*** magicboiz has quit IRC11:42
*** magicboiz has joined #openstack-keystone11:44
openstackgerritQinglin Cheng proposed openstack/keystone master: Create doc/requirements.txt  https://review.openstack.org/52896011:49
*** markvoelker has joined #openstack-keystone11:57
*** raildo has joined #openstack-keystone12:00
openstackgerritwangxiyuan proposed openstack/keystone master: [WIP]Expose unified limit APIs  https://review.openstack.org/52411012:08
*** edmondsw has joined #openstack-keystone12:16
*** annp has quit IRC12:17
*** edmondsw has quit IRC12:20
openstackgerritQinglin Cheng proposed openstack/keystone master: Create doc/requirements.txt  https://review.openstack.org/52896012:23
*** links has quit IRC12:23
*** aojea_ has quit IRC12:24
*** markvoelker has quit IRC12:29
openstackgerritQinglin Cheng proposed openstack/python-keystoneclient master: Create doc/requirements.txt  https://review.openstack.org/52896412:31
*** JoeStack has joined #openstack-keystone12:46
*** zhurong has joined #openstack-keystone13:00
*** davidalles has joined #openstack-keystone13:00
*** JoeStack has quit IRC13:00
*** zhurong has quit IRC13:02
*** zhurong has joined #openstack-keystone13:03
*** davidalles has quit IRC13:08
*** catintheroof has joined #openstack-keystone13:11
*** catintheroof has quit IRC13:12
*** catintheroof has joined #openstack-keystone13:12
*** d0ugal has quit IRC13:14
*** links has joined #openstack-keystone13:18
*** r-daneel has joined #openstack-keystone13:19
*** rcernin has quit IRC13:20
*** r-daneel has quit IRC13:20
*** iurygregory has joined #openstack-keystone13:21
*** d0ugal has joined #openstack-keystone13:23
*** zhurong has quit IRC13:25
*** aojea has joined #openstack-keystone13:25
*** markvoelker has joined #openstack-keystone13:27
*** markvoelker has quit IRC13:28
*** markvoelker has joined #openstack-keystone13:29
*** r-daneel has joined #openstack-keystone13:34
*** d0ugal has quit IRC13:37
*** aojea has quit IRC13:38
*** JoeStack has joined #openstack-keystone13:39
*** d0ugal has joined #openstack-keystone13:39
*** dave-mccowan has joined #openstack-keystone13:45
*** links has quit IRC14:03
*** links has joined #openstack-keystone14:17
ayoungcmurphy, lbragstad, knikolla   When you get a chance, look in to Istio.  I think you will get a sense of what I was trying to do with the RBAC in middleware. It does roughly the same thing, IIUC, which is to provide a centralized place to perform authorization for apps using a Proxy setup.14:37
cmurphyo714:41
*** JoeStack has quit IRC14:42
lbragstadcmurphy: clarkb proposed https://review.openstack.org/#/c/528946/ last night, too... after i mentioned a bunch of things were failing14:42
cmurphylbragstad: our stuff is still broken though14:43
cmurphyhttps://review.openstack.org/#/c/528960 should fix it14:43
cmurphysee https://review.openstack.org/#/c/528866/ , rechecked a couple hours ago and still broken14:44
lbragstadyeah - that looks consistent with the failures I was seeing last night14:46
*** panbalag has joined #openstack-keystone14:49
*** jmlowe has joined #openstack-keystone14:51
cmurphymaybe ajaeger can advise us, or clarkb or mordred when they get online14:52
*** tlam_ has joined #openstack-keystone14:53
openstackgerritSamuel BARTEL proposed openstack/keystone-specs master: Allow admin to specify project id on creation  https://review.openstack.org/32349915:00
*** JoeStack has joined #openstack-keystone15:00
gagehugoo/15:03
*** aojea has joined #openstack-keystone15:07
knikollaayoung: o/ will look into it. sounds interesting.15:09
*** aojea has quit IRC15:09
*** aojea has joined #openstack-keystone15:09
ayoungknikolla, cmurphy cool.  What RH sells with 3scale is also in this space.15:10
openstackgerritAndreas Jaeger proposed openstack/keystone master: Create doc/requirements.txt  https://review.openstack.org/52896015:17
*** JoeStack has quit IRC15:20
*** aojea has quit IRC15:25
lbragstadcmurphy: i'm digging into the http thing a bit more15:31
cmurphylbragstad: the error responses?15:31
lbragstadyeah...15:31
lbragstaddumb question, but do request uris include request body information?15:32
lbragstador is it strictly things on the path?15:32
lbragstadhttps://tools.ietf.org/html/rfc3986#section-1.1.315:32
lbragstadif it does - then 404 seems like the correct thing to do given https://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html15:32
lbragstadi mean, if a service isn't found when dealing with registered limits or project limits, then it's not necessarily a syntax error, the syntax of the request would be correct15:35
lbragstads/would/can/15:35
cmurphyi don't think i understand the question15:35
lbragstad400 Bad Request15:35
lbragstadThe request could not be understood by the server due to malformed syntax. The client SHOULD NOT repeat the request without modifications.15:35
lbragstad^ that's the definition for an http 40015:36
*** slunkad_ has quit IRC15:36
gagehugoyes15:36
lbragstad404 Not Found15:36
lbragstadThe server has not found anything matching the Request-URI. No indication is given of whether the condition is temporary or permanent.15:36
ksalmanI am still trying to figure out why I am still getting 401 when I use interface='public'15:36
lbragstad^ part of the definition for http 40415:37
gagehugobut I thought URIs were the path15:37
lbragstadsince the service/region/limit information is relayed in the body of the request, does that classify as the request URI?15:37
cmurphyyeah the URI is not the body15:37
ayoung426 Upgrade Required.15:37
cmurphyit's just the location15:37
lbragstadok15:37
ayoung45115:37
lbragstadthat's what i was afraid of15:37
ayoungHeh this could be fun15:37
cmurphy:)15:38
ayoungksalman, run it from curl15:38
ksalmanokay15:39
*** slunkad has joined #openstack-keystone15:39
cmurphyhttps://developer.mozilla.org/zh-TW/docs/Web/HTTP/Status/404 "The HTTP 404 Not Found client error response code indicates that the server can't find the requested resource." i think "matching the request-uri" might be an ultra-strict interpretation15:39
lbragstadyeah...15:39
ayoungthis is a case of a dependent resource not found?15:40
lbragstadyes15:40
gagehugohttps://httpstatusdogs.com/15:40
lbragstadat the same time, the syntax could be completely valid, which makes me think a 400 is slightly inappropriate15:40
ayoungWe return 404s in other cases, like when building role assignments, for the user or groups not found15:40
*** aojea has joined #openstack-keystone15:41
* lbragstad is leaning towards HTTP 40415:42
cmurphy+115:43
*** slunkad has quit IRC15:43
ayoung400 is more than just syntax, WFIW.  But I'd go with 404 here for consistancy.  It would be nice if we indicated what object could not be found, though.15:43
gagehugo404 seems fine15:43
ayoung6.5.1.  400 Bad Request15:43
ayoung   The 400 (Bad Request) status code indicates that the server cannot or15:43
ayoung   will not process the request due to something that is perceived to be15:43
ayoung   a client error (e.g., malformed request syntax, invalid request15:43
ayoung   message framing, or deceptive request routing).15:43
ayoungIt does seem slightly more correct to 400 if a bad piece of data is included, regardless of whether that is a link to another object or a poorly formatted SSN.  404 would merely be consistent with what we have done thus far.15:45
lbragstadi'm failing to see how returning a 400 is more correct when a dependent object in the request is missing15:46
lbragstadsyntactically - the request could be valid15:46
ayoungIts not just Syntax15:47
ayounglbragstad, 400 is "you submitted a form with bad data"15:47
lbragstadmessage request framing seems like syntax15:48
lbragstaddo you have a link to where you pulled that definition?15:48
ayoung" something that is perceived to be a client error"15:48
ayoungbut, regardless, we are already doing 404.  Lets stick with that15:48
ayoungmainly because I don't want to rewrite all out other APIs15:49
*** edmondsw has joined #openstack-keystone15:52
cmurphywe're inconsistent15:52
cmurphywxy pointed out https://github.com/openstack/keystone/blob/master/keystone/catalog/core.py#L161-L175 we're returning 40015:52
ayoungAppeal to the API team for a judgement.  I can squint and make either one work.  404 might trip up an automated system to think it posted to the wrong URL, whereas bad data in a post seems like 400, but I agree that seems like a catchall15:54
ayoungIN the bad old days of server generated UI, a bad post to a form would still generate a 200, but you would be redirectedt back to the form page with all the data pre-filled and an angry red underline for the one you missed15:55
ayoungNowadays in an Ajax world, you would probably want to return a 400 to tell the Single Page app that the data was no good, try again, and a 404 would mean "your remote server URL is no longer there"15:56
*** edmondsw has quit IRC15:56
ayoungi.e. a 400 could be fixed with a different payload.   A 404 cannot.15:56
ayoungDoes seem wrong to have the same response code for bad syntax and bad data values15:58
*** slunkad has joined #openstack-keystone15:59
ayoungbut bad syntax means the client is messed up.  If both sides disagree on the doctype, you get  Not Acceptable.  I think that would be a better response for a corrupeted syntax, as your client broke the contract16:00
ayoungheh or the server did, but they hold the cards here16:00
cmurphyhere we go https://specs.openstack.org/openstack/api-wg/guidelines/http.html#failure-code-clarifications16:00
cmurphyit should be a 40016:00
cmurphy"If a request contains a reference to a nonexistent resource in the body (not URI), the code should be 400 Bad Request"16:01
ayoungcmurphy, that seems like a really good thing to fix in t version 4 of our API16:02
cmurphy:)16:02
knikollaayoung: istio looks like a generic version of what i'm doing with mix&match.16:04
ayoungReally?16:04
ayoungknikolla, maybe this is a case of the blind and the elephant...what calls that out to you?16:04
knikollaayoung: a proxy that handles auth and routing between services16:04
knikollai have a proxy that does k2k auth and routing between openstack services in different clouds16:05
ayoungknikolla, ah, I get it.  I was thinking single org, multiple services, but yeah, it would have to handle multi-org as well.16:05
*** josecastroleon has joined #openstack-keystone16:10
lbragstadcmurphy: oh - nice16:13
lbragstadgood find!16:13
*** jmlowe has quit IRC16:13
cmurphyyay for having smart people in the api-sig16:14
lbragstadright?!16:14
lbragstadi was just thinking "someone in our project space has to have hit this before?16:14
lbragstadso - given the justification from the api-sig, we should clearly relay the information in the response16:16
lbragstad400 - service %(service_id)s does not exist16:16
cmurphyyes16:16
cmurphylbragstad: I can submit an update16:19
lbragstadcool16:20
lbragstadcmurphy: ayoung gagehugo thanks for the help16:20
*** tlam_ has quit IRC16:28
openstackgerritColleen Murphy proposed openstack/keystone-specs master: Limits API  https://review.openstack.org/45570916:32
openstackgerritColleen Murphy proposed openstack/keystone-specs master: Limits API  https://review.openstack.org/45570916:34
*** r-daneel has quit IRC16:38
*** gyee has joined #openstack-keystone16:42
*** aojea has quit IRC16:42
openstackgerritColleen Murphy proposed openstack/keystone-specs master: Limits API  https://review.openstack.org/45570916:49
*** AlexeyAbashkin has quit IRC17:01
*** r-daneel has joined #openstack-keystone17:07
cmurphylbragstad: i'll go ahead and approve https://review.openstack.org/#/c/455709 unless you want to get anyone else to look at it?17:21
ksalmanI am trying to use curl now, and going off this https://developer.openstack.org/api-guide/quick-start/api-quick-start.html17:22
ksalmanthe very first curl command is to request a token, which makes sense. However, could I not define OS_PROJECT_NAME and get an admin token? I have admin privileges, and I'd like to operate on resources of all tenants17:23
ksalmanI tried not defining the "scope" in the curl command, naively though that didn't work17:24
ksalman  "badRequest": {17:24
ksalman    "message": "Malformed request URL: URL's project_id '059fd3b805f8425995e8be7174347683' doesn't match Context's project_id 'None'",17:24
ksalman    "code": 40017:24
*** mvk has quit IRC17:25
ksalmanDo i have to enumerate getting tokens on projects one at a time just so i could operate on resources within each project?17:26
lbragstadcmurphy: i think that's in good shape17:27
lbragstadcmurphy: go ahead and push it through17:27
*** samuelbartel has quit IRC17:29
*** tlam_ has joined #openstack-keystone17:34
*** edmondsw has joined #openstack-keystone17:40
*** smatzek has joined #openstack-keystone17:40
ksalmanI suppose that is not a question for this channel =)17:41
*** edmondsw has quit IRC17:44
lbragstadksalman: i think that depends on what you're trying to do to all instances17:45
kmallocO/17:49
kmallocFor, I am being bad a vacation right now.17:49
lbragstadcool - we do have a kmalloc today17:49
kmallocFTR*17:49
ksalmanlbragstad: i have a list of instance and stack uuids from various tenants, and I want to delete them17:49
*** catintheroof has quit IRC17:50
kmallocYes, I -2'd a patch, I'll circle around for that. You owe me ;). I expect a cup coffee on you in Dublin ^_^ :P17:50
openstackgerritMerged openstack/keystone-specs master: Limits API  https://review.openstack.org/45570917:51
*** josecastroleon has quit IRC17:51
lbragstadwxy: woo! ^17:51
*** catintheroof has joined #openstack-keystone17:51
lbragstadkmalloc: since when do we get cups of coffee for -2s?!17:52
* lbragstad missed the memo17:52
*** davidalles has joined #openstack-keystone17:52
davidallesruan_he: Ruan, are you there?17:53
*** r-daneel_ has joined #openstack-keystone18:01
*** r-daneel has quit IRC18:01
*** r-daneel_ is now known as r-daneel18:01
kmalloclbragstad: when i take time out of my vacation to visit the meeting because of a -2 ;)18:02
lbragstadkmalloc: aha - ack... yes, that makes sense18:02
*** catintheroof has quit IRC18:07
*** catintheroof has joined #openstack-keystone18:08
*** spilla has joined #openstack-keystone18:10
*** harlowja has joined #openstack-keystone18:15
*** rmascena has joined #openstack-keystone18:19
openstackgerritMerged openstack/keystone master: Create doc/requirements.txt  https://review.openstack.org/52896018:19
openstackgerritGage Hugo proposed openstack/keystone master: Bump API version and date to 3.9  https://review.openstack.org/52877318:21
*** raildo has quit IRC18:22
*** AlexeyAbashkin has joined #openstack-keystone18:22
*** links has quit IRC18:23
*** apuimedo has quit IRC18:24
*** AlexeyAbashkin has quit IRC18:27
*** aselius has joined #openstack-keystone18:38
*** panbalag has quit IRC18:39
*** tlam_ has quit IRC18:42
*** tlam_ has joined #openstack-keystone18:43
*** AlexeyAbashkin has joined #openstack-keystone18:46
*** catintheroof has quit IRC18:56
*** r-daneel has quit IRC18:57
*** AlexeyAbashkin has quit IRC18:58
lbragstado/19:00
kmalloco/19:00
lbragstadyeah - writing drivers isn't bad19:00
hrybackio/19:00
lbragstadyou have an abstract interface to follow19:00
lbragstad#startmeeting keystone-office-hours19:00
openstackMeeting started Tue Dec 19 19:00:36 2017 UTC and is due to finish in 60 minutes.  The chair is lbragstad. Information about MeetBot at http://wiki.debian.org/MeetBot.19:00
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.19:00
*** openstack changes topic to " (Meeting topic: keystone-office-hours)"19:00
*** ChanServ changes topic to "Queens release schedule: https://releases.openstack.org/queens/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/5F0h9Hoe/keystone"19:00
openstackThe meeting name has been set to 'keystone_office_hours'19:00
cmurphyo/19:00
rmascenadavidalles, let's keep talking here19:00
lbragstadruan?19:00
davidallesyep19:00
davidallesOKi, so the conclusion it: BP is --219:01
rmascenadavidalles, can you ask for ruan join this channel?19:01
kmallocdavidalles: i walked back to a -1, the fernet bits were removed.19:01
davidallesand Orange must work on the 'resources ID' driver19:01
davidallesyep, I did19:01
kmalloci'm a strong -1 on the new API, i would be a -2 on "optional" features.19:01
kmalloci recommend this being a driver.19:01
rmascenadavidalles, the spec can be rewrite to instead of pointing to an API change, to reference that as an new resource driver change19:02
davidallesunderstood; thanks all of you: we found one solution so that Orange will comply to the hard IAM&ACM requirement :)19:02
lbragstadyou could actually inherit the upstream driver and just override the project specific methods19:02
cmurphyyou can write this driver out of tree, then you wouldn't need a new spec or any buy-in from us19:02
lbragstaddavidalles: did k2k comply to that hard requirement?19:02
*** sbezverk has joined #openstack-keystone19:02
knikollaand you can make it out of tree, so no need to wait for our go19:03
*** ruan__he has joined #openstack-keystone19:03
lbragstadright - you just need to make sure you read the release notes for interface changes19:03
davidallesyep: then I will synchro with Ruan and we will comment the BP19:03
kmalloc:)19:03
davidalles:) :)19:03
lbragstadbecause sometimes we do change those interfaces, which will impact your implementation19:03
ruan__hethanks for your comments, we will try to work on that19:03
hrybackilbragstad: kmalloc out-of-tree like we don't need to worry about upstream timelines?19:03
*** r-daneel has joined #openstack-keystone19:03
cmurphyhrybacki: right19:03
knikollahrybacki: yeah, as long as the interface hasn't changed19:04
rmascenahrybacki, yep19:04
lbragstadruan__he: davidalles i'm still really interested in the k2k case19:04
davidalleshave a nice day (or night)19:04
hrybackiack ack19:04
lbragstadi'd like to work on fixing the performance issues there19:04
kmallocdavidalles: please let us know where k2k didn't work.19:04
kmallocesp. if it's related to performance19:04
kmallocruan__he: ^19:04
cmurphyfwiw not that anyone should ever use this but i wrote https://github.com/cmurphy/keystone-json-assignment which could be used as an example, specifically setting up the entry points19:04
davidallesRuan will: he was the guy testing it19:04
kmalloccool19:04
lbragstadruan__he: is it possible for you to forward the information about that setup and the results?19:04
hrybackicmurphy: everyone reads TC blogs :)19:04
kmalloci want to fix the k2k bit if it's slow/notworking19:05
lbragstadright - because we've been pushing people to use it for years19:05
lbragstadand that is going to be critical in making federation a first-class citizen19:05
knikollalbragstad: you'll get a lot of feedback from me in terms of performance in the coming months19:06
knikollawe're very close to production deployment for mixmatch19:06
lbragstadknikolla: ++19:06
kmallocok i need to go eat19:06
*** davidalles has quit IRC19:11
cmurphysomeone please look at https://review.openstack.org/#/c/523524/ :)19:22
cmurphyand https://review.openstack.org/#/c/52235619:22
kmalloccmurphy: +3 on both19:27
cmurphythanks kmalloc19:27
cmurphyi give you permission to go enjoy your vacation :P19:27
*** edmondsw has joined #openstack-keystone19:28
lbragstadwoo!19:28
lbragstadpatches are moving!19:28
lbragstadcmurphy: ruan__he jdennis hrybacki running this by the mailing list http://lists.openstack.org/pipermail/openstack-dev/2017-December/125744.html19:29
*** catintheroof has joined #openstack-keystone19:29
lbragstadhttps://review.openstack.org/#/c/528960/ merged - so we should be good to start rechecking?19:31
cmurphyya i think so19:31
*** edmondsw has quit IRC19:32
lbragstadcool - i have like 20 patches failing :)19:33
cmurphylbragstad: might be good to send that email to the -ops list?19:34
lbragstadyup - i did19:36
cmurphyah cool19:36
lbragstadhttp://lists.openstack.org/pipermail/openstack-operators/2017-December/014697.html19:36
*** edmondsw has joined #openstack-keystone19:37
*** openstack has joined #openstack-keystone19:41
*** ChanServ sets mode: +o openstack19:41
*** edmondsw has quit IRC19:44
*** itlinux has quit IRC19:52
*** itlinux has joined #openstack-keystone19:52
cmurphyI'm not sure about this patch series https://review.openstack.org/#/c/526296/ it's changing the response from 500 -> 400 -> 200, or am I overthinking it?19:59
gagehugoit would return a 400 since we check via schema instead of failing loudly and returning a 500?20:01
cmurphygagehugo: right, i'm fine with that, but then the next change in the series makes it accept a name property instead of just an id20:03
gagehugolooking at that now20:04
cmurphyso something that is illegal in 526296 becomes legal in 52696820:04
gagehugoah I see20:05
gagehugosince that second changes the schema20:06
gagehugobut it currently only uses an id, the name change seems to be adding a new feature?20:12
cmurphyyeah that's true20:14
cmurphy+1 on letting it accept names20:15
gagehugoit might be fine then, if that change is allowing to authorize via role names OR id20:15
*** mvk has joined #openstack-keystone20:16
gagehugobut it is changing what is accepted20:22
cmurphyi feel like it would be okay if the order was just switched, first accept names and then second reject everything else20:23
gagehugosure20:23
gagehugocould those changes be combined?20:26
*** jmlowe has joined #openstack-keystone20:28
cmurphyyeah probably20:31
openstackgerritGage Hugo proposed openstack/keystone master: Reorganize api-ref: v3 credentials  https://review.openstack.org/50445920:35
*** AlexeyAbashkin has joined #openstack-keystone20:37
*** AlexeyAbashkin has quit IRC20:41
*** smatzek has quit IRC20:54
*** catintheroof has quit IRC21:02
*** catintheroof has joined #openstack-keystone21:03
*** catintheroof has quit IRC21:07
openstackgerritColleen Murphy proposed openstack/keystonemiddleware master: Fix docs builds  https://review.openstack.org/52915821:16
*** edmondsw has joined #openstack-keystone21:17
openstackgerritColleen Murphy proposed openstack/keystonemiddleware master: Fix docs builds  https://review.openstack.org/52915821:18
openstackgerritColleen Murphy proposed openstack/python-keystoneclient master: Create doc/requirements.txt  https://review.openstack.org/52896421:20
*** edmondsw has quit IRC21:22
*** rmascena has quit IRC21:27
openstackgerritColleen Murphy proposed openstack/keystoneauth master: Fix docs builds  https://review.openstack.org/52916421:31
lbragstad#endmeeting22:07
lbragstad#startmeeting keystone-office-hours22:07
openstackMeeting started Tue Dec 19 22:07:28 2017 UTC and is due to finish in 60 minutes.  The chair is lbragstad. Information about MeetBot at http://wiki.debian.org/MeetBot.22:07
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.22:07
*** openstack changes topic to " (Meeting topic: keystone-office-hours)"22:07
*** ChanServ changes topic to "Queens release schedule: https://releases.openstack.org/queens/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/5F0h9Hoe/keystone"22:07
openstackThe meeting name has been set to 'keystone_office_hours'22:07
lbragstad#endmeeting22:07
*** openstack changes topic to "Queens release schedule: https://releases.openstack.org/queens/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/5F0h9Hoe/keystone"22:07
openstackMeeting ended Tue Dec 19 22:07:37 2017 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)22:07
openstackMinutes:        http://eavesdrop.openstack.org/meetings/keystone_office_hours/2017/keystone_office_hours.2017-12-19-22.07.html22:07
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/keystone_office_hours/2017/keystone_office_hours.2017-12-19-22.07.txt22:07
openstackLog:            http://eavesdrop.openstack.org/meetings/keystone_office_hours/2017/keystone_office_hours.2017-12-19-22.07.log.html22:07
lbragstadhumm22:07
lbragstadmaybe the bot was restarted during office hours22:08
openstackgerritColleen Murphy proposed openstack/keystonemiddleware master: Fix docs builds  https://review.openstack.org/52915822:08
cmurphy hmm yep 19:41:09             <-- | openstack (~openstack@openstack/openstack) has quit (Remote host closed the connection)22:08
lbragstadaha22:22
*** rcernin has joined #openstack-keystone22:28
*** spilla has quit IRC22:54
*** panbalag has joined #openstack-keystone22:54
*** edmondsw has joined #openstack-keystone23:06
*** edmondsw has quit IRC23:10
openstackgerritMerged openstack/python-keystoneclient master: Updated from global requirements  https://review.openstack.org/52890423:21
openstackgerritGage Hugo proposed openstack/keystone master: Refactor project tags encoding  https://review.openstack.org/52917923:22
openstackgerritGage Hugo proposed openstack/keystone master: Refactor project tags encoding  https://review.openstack.org/52917923:23
*** itlinux has quit IRC23:33
openstackgerritColleen Murphy proposed openstack/keystonemiddleware master: Fix docs builds  https://review.openstack.org/52915823:39
*** catinthe_ has joined #openstack-keystone23:43
*** catintheroof has joined #openstack-keystone23:52
*** catintheroof has quit IRC23:52
*** catintheroof has joined #openstack-keystone23:53
*** catinthe_ has quit IRC23:55
*** catintheroof has quit IRC23:58

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!