Monday, 2018-07-09

*** threestrands has joined #openstack-keystone00:03
*** threestrands has quit IRC00:03
*** threestrands has joined #openstack-keystone00:03
*** toddnni_ has joined #openstack-keystone00:36
*** toddnni has quit IRC00:36
*** toddnni_ is now known as toddnni00:37
*** pcichy has quit IRC00:39
*** pcichy has joined #openstack-keystone00:40
*** alex_xu has quit IRC00:40
*** alex_xu has joined #openstack-keystone00:41
*** edmondsw has joined #openstack-keystone01:04
*** edmondsw has quit IRC01:08
*** threestrands_ has joined #openstack-keystone01:18
*** threestrands_ has quit IRC01:18
*** threestrands_ has joined #openstack-keystone01:18
*** threestrands_ has quit IRC01:19
*** threestrands_ has joined #openstack-keystone01:20
*** threestrands_ has quit IRC01:21
*** threestrands_ has joined #openstack-keystone01:21
*** threestrands_ has quit IRC01:21
*** threestrands_ has joined #openstack-keystone01:21
*** threestrands has quit IRC01:21
*** sapd_ has quit IRC01:54
*** sapd has joined #openstack-keystone01:55
*** sapd_ has joined #openstack-keystone02:22
*** sapd has quit IRC02:22
*** annp has joined #openstack-keystone02:30
*** edmondsw has joined #openstack-keystone02:52
*** edmondsw has quit IRC02:57
*** sapd__ has joined #openstack-keystone03:17
*** sapd_ has quit IRC03:18
*** deepak_mourya has joined #openstack-keystone03:50
*** annp has quit IRC03:56
*** annp has joined #openstack-keystone03:56
*** edmondsw has joined #openstack-keystone04:40
*** edmondsw has quit IRC04:44
*** links has joined #openstack-keystone05:00
*** pooja_jadhav has joined #openstack-keystone05:46
*** martinus__ has joined #openstack-keystone05:57
*** ispp has joined #openstack-keystone06:24
*** edmondsw has joined #openstack-keystone06:28
*** annp has quit IRC06:30
*** annp has joined #openstack-keystone06:30
*** edmondsw has quit IRC06:33
*** rha has joined #openstack-keystone07:02
*** rha has quit IRC07:02
*** rha has joined #openstack-keystone07:02
*** peereb has joined #openstack-keystone07:05
*** tesseract has joined #openstack-keystone07:06
*** rcernin has quit IRC07:08
*** amoralej|off is now known as amoralej07:21
*** tesseract has quit IRC07:25
*** tesseract has joined #openstack-keystone07:27
*** itlinux has joined #openstack-keystone07:32
*** ispp has quit IRC07:32
*** pcichy has quit IRC07:33
*** d0ugal_ has quit IRC07:33
*** d0ugal has joined #openstack-keystone07:33
*** d0ugal has quit IRC07:33
*** d0ugal has joined #openstack-keystone07:33
*** tosky has joined #openstack-keystone07:35
*** pcichy has joined #openstack-keystone07:35
*** pcichy has quit IRC07:36
*** pcichy has joined #openstack-keystone07:37
*** pcichy has joined #openstack-keystone07:38
*** BlackDex has quit IRC07:40
*** BlackDex has joined #openstack-keystone07:41
*** itlinux has quit IRC07:52
*** ispp has joined #openstack-keystone07:54
*** itlinux has joined #openstack-keystone08:00
*** zigo has quit IRC08:03
*** zigo has joined #openstack-keystone08:05
*** threestrands_ has quit IRC08:12
openstackgerritwangxiyuan proposed openstack/keystone master: Remove enable config option of trust feature  https://review.openstack.org/58058708:14
*** edmondsw has joined #openstack-keystone08:16
*** edmondsw has quit IRC08:21
*** ispp has quit IRC08:44
openstackgerritGergely Csatari proposed openstack/keystone master: Clarifications to API & Scenario Tests  https://review.openstack.org/58058908:50
*** vigneshwar has joined #openstack-keystone08:56
*** d0ugal has quit IRC09:17
*** d0ugal has joined #openstack-keystone09:23
*** itlinux has quit IRC09:42
*** ispp has joined #openstack-keystone09:46
*** itlinux has joined #openstack-keystone09:49
*** pcichy has quit IRC10:28
*** itlinux has quit IRC11:39
*** raildo has joined #openstack-keystone11:54
*** amoralej is now known as amoralej|lunch12:03
*** d0ugal has quit IRC12:06
*** d0ugal has joined #openstack-keystone12:08
*** jistr is now known as jistr|mtg12:12
*** edmondsw has joined #openstack-keystone12:24
*** yuxin_ has quit IRC12:25
*** yuxin_ has joined #openstack-keystone12:25
*** yuxin_ has quit IRC12:26
*** yuxin_ has joined #openstack-keystone12:27
*** edmondsw has quit IRC12:29
*** edmondsw has joined #openstack-keystone12:31
*** edmondsw has quit IRC12:35
*** edmondsw has joined #openstack-keystone12:37
hrybackio/12:41
*** edmondsw has quit IRC12:42
*** jmlowe has quit IRC12:45
*** edmondsw has joined #openstack-keystone12:45
knikollao/12:49
*** edmondsw has quit IRC12:49
*** edmondsw has joined #openstack-keystone12:51
*** edmondsw has quit IRC12:53
*** edmondsw has joined #openstack-keystone12:53
openstackgerritGergely Csatari proposed openstack/keystone master: Clarifications to API & Scenario Tests  https://review.openstack.org/58058912:58
*** loicgouarin has joined #openstack-keystone13:03
*** mvk has quit IRC13:03
loicgouarinHi, I tried to use kuryr-kubernetes on openstack and I have trouble with keystoneauth1 that I don't understand.13:03
loicgouarinI have a config file with the following keystone url  https://keystone.lal.in2p3.fr:5000/v313:04
loicgouarinWhen kuryr tries to create a keystone clien I have an error which tells me that it is not possible to connect to the url https://keystone-admin.lal.in2p3.fr:35357/v313:05
loicgouarinI don't understand why the url is not unchanged13:06
loicgouarinNote that I can create subnet, ... using neutron cli13:09
*** amoralej|lunch is now known as amoralej13:11
*** jistr|mtg is now known as jistr13:14
*** wolsen has quit IRC13:18
*** wolsen has joined #openstack-keystone13:20
*** jmlowe has joined #openstack-keystone13:34
*** jistr is now known as jistr|mtg13:36
*** lbragstad has joined #openstack-keystone13:37
*** ChanServ sets mode: +o lbragstad13:37
*** jistr|mtg is now known as jistr14:05
gagehugoo/14:07
lbragstadmorning14:07
kmallocMornin14:12
kmalloclbragstad: we need to stop using exception.NotImplemented() for abstract base classes14:17
lbragstadkmalloc: and just replace it with pass?14:17
kmallocAn http NotImplemented is different than what we are using it for14:17
kmallocNo.14:17
*** spilla has joined #openstack-keystone14:17
kmallocRaise NotImplementedError()14:17
*** links has quit IRC14:18
kmallocHttp not implemented indicates GET or PUT isn't implemented, NotImplementedError is saying "Python code isn't implemented"14:18
lbragstadahh14:18
kmallocA plain 500 rather than 50114:18
kmallocThis is the only case a 500 should be expected in code :)14:19
lbragstadit does seem slightly confusing...14:19
kmallocYeah.14:19
lbragstadsince the python code is what's implementing the GET/PUT/etc...14:19
*** mvk_ has joined #openstack-keystone14:20
kmallocRight, in the cases we don't have a put/post etc, 501 is fine14:20
lbragstadwould it make a different to someone consuming those APIs?14:20
kmallocBut most of these cases we have a put/post/etc and someone failed to write code.14:20
lbragstadwhat's a case where we wouldn't have a PUT/POST/GET/DELETE and should return a 501?14:21
kmalloc(except they didn't because abc, but we did it elsewhere and let it bubble up)14:21
kmallocThe API spec doesn't implemnt post14:21
kmallocThe API is a get/head only.14:21
* lbragstad thought that was always a 40414:22
lbragstadbut maybe that's wrong14:22
kmallocThat is probably wrong.14:22
lbragstadit's that how we treat it today?14:22
kmallocSome cases.14:23
kmallocWe are inconsistent.14:23
kmallocBut the easiest is never raise a 501.14:23
kmallocThat is more correct than we do today.14:23
kmallocEsp. in say, read-only backends.14:23
kmallocRead-only backends (catalog) raise 501 on write ops..14:24
kmallocNot a huge deal, just a "hey, this is wrong" and we should be aware of it.14:24
lbragstadwe should probably write this down in a bug report14:24
kmallocOther things I found when doing flask things.14:24
lbragstadi assume flask makes this type of stuff easier to adhere to14:25
kmallocYeah. On mobile till post coffee. Can write it down after.14:25
kmallocYep.14:25
lbragstadsounds good, thanks14:25
kmallocFlask restful, if we don't implement a get/post/put/whatever method, it 501s.14:25
kmallocBuilt in. :)14:25
kmallocAlso, need to circle up on the policy passthrough, I think we solved the whole reason to support "unknown" rules (passthrough or fail) when we went to in-code.  Someone can no longer remove a line from the policy.json and force a fall-through to the default rule by accident, we fall back on the default in code now.14:28
kmallocPrevious to in-code, removing a line from policy.json meant the enforcement action was unknown, and the default "pass/deny" is used. With in-code, an action is never unknown.14:29
kmallocAs it has a default registered..14:29
*** kimamisa has joined #openstack-keystone15:03
*** peereb has quit IRC15:03
kimamisaHello. I'm facing an issue regarding cache and inherited roles, and I'd like to know if someone already experienced it. I have a role assigned to a user on a domain, with the flag inherited (and also without). When I create a new project in this domain, I expect the role to be assigned on this project, so that when I list the project, I can see the new one created. However, the cache is not disabled, and listing I can't find the new project15:09
kimamisauntil the cache is expired. I triedwhile disabling the role cache, it works directly. Anyone experienced it ? Is it bug material ??15:09
*** felipemonteiro has joined #openstack-keystone15:10
*** felipemonteiro_ has joined #openstack-keystone15:12
*** vigneshwar has quit IRC15:14
*** felipemonteiro has quit IRC15:15
*** felipemonteiro_ has quit IRC15:15
*** felipemonteiro__ has joined #openstack-keystone15:15
lbragstadkimamisa: it sounds like the project cache needs to be invalidated when the inherited role assignment happens15:15
lbragstadkimamisa: does that sound coorect?15:15
kimamisalbragstad: well, the role assignment happened before the project creation in my case15:16
lbragstadoh - so the project creation should invalidate the cache then?15:17
lbragstadwhat release are you using?15:17
kimamisalbragstad: I think the role cache should be invalidated when a new project is created AND there are inherited role in the domain15:17
kimamisaI'm on queens15:18
lbragstadkimamisa: if you'd like to write down that steps you took to recreate in a bug report, you can do that here https://bugs.launchpad.net/keystone/+filebug15:19
*** felipemonteiro__ has quit IRC15:20
kimamisalbragstad: ok. I wanted to check that I wasn't doing anything impossible before reporting a bug. Thanks15:22
lbragstadkimamisa: no problem, we can continue to investigate in the bug report15:22
*** mchlumsky has joined #openstack-keystone15:27
*** felipemonteiro has joined #openstack-keystone15:32
*** mchlumsky has quit IRC15:33
*** gyee has joined #openstack-keystone15:35
*** mchlumsky has joined #openstack-keystone15:35
kimamisalbragstad: launchpad found an old bug which points to one of your comments: https://bugs.launchpad.net/keystone/+bug/178015915:42
openstackLaunchpad bug 1780159 in OpenStack Identity (keystone) "Some inherited projects missing when listing user's projects" [Undecided,Invalid]15:42
kimamisathe bug is exactly what I'm facing. Do you think there is any hope in improving this ?15:44
lbragstadkimamisa: hmmmm15:50
lbragstadayoung: is there a reason to not keep https://bugs.launchpad.net/keystone/+bug/1780159 open?15:51
openstackLaunchpad bug 1780159 in OpenStack Identity (keystone) "Some inherited projects missing when listing user's projects" [Undecided,Invalid]15:51
ayounglbragstad, it was a cache problem15:51
lbragstadright15:51
lbragstadwe don't invalidate the cache in certain inherited role assignment cases15:52
ayoungso, cache is going to introduce delay.15:52
ayoungah...you think it should be cache invalidation...ok, keep it open15:52
ayoungrestored it to the "new" state15:53
lbragstadwe could go either way with it... but dealing with the invalidation directly is a pattern we have in other places15:53
lbragstadkimamisa: in that case, we can reuse that report, can't we?15:53
kimamisayes15:53
kimamisaI almost had the same ready !15:54
lbragstadcool - setting to medium since the workaround is to set low cache TTL for that specific subsystem15:54
lbragstadayoung: thanks for working that report15:55
*** pcichy has joined #openstack-keystone15:57
ayoungCan someone explain K2K to me?16:09
ayoungI get SAML.  WHat I don't get is how it keeps assignment data straight16:09
ayoungsay I have 2 setups,  call em old and new16:09
ayoungand I add a project to old.  How does that show up as anything in new without making a direct call to new to create the project?16:10
openstackgerritMerged openstack/keystone-tempest-plugin master: fix tox python3 overrides  https://review.openstack.org/57386216:10
ayoungif I want to have a rule that says "anything in old Dom 1 gets mirrored in new Dom 5"  there is nothing that keeps people also from assigning to things in new dom 5.  Fine, I get that16:11
*** felipemonteiro_ has joined #openstack-keystone16:12
ayoungwhat makes the new Dom 5 project in the first place, or is it just assumed that you will start with some top level sync, like "let old and new each get a set of domains, and we'll explicitly create projects in the remote ones"  so using a domain level assiugnment?16:12
*** felipemonteiro__ has joined #openstack-keystone16:13
*** ispp has quit IRC16:13
*** felipemonteiro has quit IRC16:15
*** felipemonteiro_ has quit IRC16:17
*** kimamisa has quit IRC16:20
*** dklyle has joined #openstack-keystone16:23
openstackgerritMerged openstack/keystone master: Clarifications to API & Scenario Tests  https://review.openstack.org/58058916:31
*** hoonetorg has quit IRC16:32
*** mvk_ has quit IRC16:33
*** hoonetorg has joined #openstack-keystone16:34
*** pcichy has quit IRC16:44
openstackgerritLance Bragstad proposed openstack/oslo.policy master: Teach Enforcer.enforce to deal with context objects  https://review.openstack.org/57899516:45
openstackgerritLance Bragstad proposed openstack/oslo.policy master: Teach Enforcer.enforce to deal with context objects  https://review.openstack.org/57899516:47
*** tesseract has quit IRC17:15
*** amoralej is now known as amoralej|off17:49
*** blake has joined #openstack-keystone17:59
*** vishakha has quit IRC18:18
*** vishakha has joined #openstack-keystone18:32
*** blake has quit IRC19:01
*** blake has joined #openstack-keystone19:02
*** blake has quit IRC19:06
*** blake has joined #openstack-keystone19:16
*** blake has quit IRC19:20
*** tosky has quit IRC19:23
openstackgerritGage Hugo proposed openstack/keystone master: Add docs for case-insensitivity in keystone  https://review.openstack.org/57664019:24
*** felipemonteiro__ is now known as felipemonteiro19:30
*** blake has joined #openstack-keystone19:37
*** dklyle has quit IRC19:52
*** mvk_ has joined #openstack-keystone20:02
*** jmlowe has quit IRC20:20
*** dklyle has joined #openstack-keystone20:35
lbragstadkmalloc: might need your eyes on the policy bits here and the @protected stuff https://review.openstack.org/#/c/579330/8/keystone/limit/controllers.py20:38
lbragstadcontext: https://review.openstack.org/#/c/579330/2/keystone/limit/controllers.py20:39
kmallocHeaded to the doctor, will look when back.20:39
lbragstadack20:39
*** spilla has quit IRC20:39
kmallocBut #1 priority on my list.20:39
kmallocPost non-code things.20:40
kmalloc:)20:40
lbragstadawesome - thanks20:42
*** spilla has joined #openstack-keystone21:01
*** martinus__ has quit IRC21:19
*** rmascena has joined #openstack-keystone21:23
*** raildo has quit IRC21:26
*** spilla has quit IRC21:27
*** rmascena has quit IRC21:49
*** blake has quit IRC22:16
*** rcernin has joined #openstack-keystone22:20
*** threestrands_ has joined #openstack-keystone22:20
*** threestrands_ has quit IRC22:20
*** threestrands_ has joined #openstack-keystone22:20
*** jappleii__ has joined #openstack-keystone22:23
*** jappleii__ has quit IRC22:24
*** jappleii__ has joined #openstack-keystone22:25
*** threestrands_ has quit IRC22:26
*** felipemonteiro has quit IRC22:28
*** rybridges has quit IRC22:36
*** sonuk_ has joined #openstack-keystone23:21
*** bhagyashri_s has joined #openstack-keystone23:22
*** toddnni has quit IRC23:23
*** jdennis has quit IRC23:23
*** toddnni has joined #openstack-keystone23:24
*** jdennis has joined #openstack-keystone23:24
*** gyee has quit IRC23:25
*** sonuk has quit IRC23:25
*** bhagyashris has quit IRC23:25
*** edmondsw has quit IRC23:26
*** gyee has joined #openstack-keystone23:28

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!