*** openstackgerrit has joined #openstack-keystone07:03
openstackgerritwangxiyuan proposed openstack/keystone master: [wip] Domain level unified limit support
openstackgerritwangxiyuan proposed openstack/keystone master: [wip] Domain level unified limit support
dtantsurhi folks! does this ring any bells?
dtantsurI highly suspect could cause it, the failure is around the flask code10:41
dtantsurokay, it seems that this call is missing from many resources:
dtantsurare you sure you did not forget some base implementation?10:46
openstackLaunchpad bug 1792913 in OpenStack Identity (keystone) "Keystone HTTP 500: AttributeError: type object 'GroupsResource' has no attribute '_get_domain_id_from_token'" [Undecided,New]11:03
wxy-xiyuandtantsur: yeah, Felipe has a fix
dtantsurwxy-xiyuan: cool, thanks! created to test the fix11:17
dtantsurI really wonder why the keystone CI did not catch the problem.11:19
wxy-xiyuandtantsur: because the Keystone test code always contains "domain_id" in the request body when test creating group. So code won't go after
dtantsuryeah.. maybe worth adding an openstacksdk CI job? /me just thinking aloud11:21
wxy-xiyuandtantsur: ++ maybe.11:24
wxy-xiyuantempest missed the non-domain_id case as well.
*** raildo has joined #openstack-keystone12:03
*** prashkre has joined #openstack-keystone12:16
johnthetubaguylbragstad: hey, hope you got home OK, just wondering if someone is already working on a summary of the federation discussions at the PTG, I missed those13:13
* cmurphy will work on something13:19
johnthetubaguycmurphy: awesome!13:25
lbragstadwhich is here -
johnthetubaguylbragstad: we have a few users wanting to go all in on federation soon, so just wanted to read through to see if we are seeing all the same things14:04
lbragstadoh - sure14:04
johnthetubaguycool, found that14:05
lbragstadi think the gist of it was that we need to address those bugs14:05
lbragstadand then the "additional work items" were ultimately specifications14:05
lbragstadthat we could start working on14:05
johnthetubaguyits the group membership and federated users, ideally moving to a time based lease so app creds and heat work14:05
johnthetubaguyyeah, stable uuids and things from the edge sessions seemed super interesting14:06
johnthetubaguyI know yankcrime has been looking at this in more detail than me, so hopefully we can help in some way to move things forward14:07
lbragstadwe're certainly open to feedback, especially on the stuff that came up last week regarding the idp proxy bit14:09
lbragstadknikolla said he was going to try writing everything up as a series of specifications14:10
johnthetubaguy(our current plans are using keycloak as a central idp proxy)14:10
kmallocjohnthetubaguy: and fwiw, it is likely keycloak will meet the needs of some other folks before we get keystone in shape to be the proxy14:18
johnthetubaguykmalloc: +1, FWIW, its the group management self-service and self-service two factor enforcement that interests me the most14:20
kmallocjohnthetubaguy: yep14:21
yankcrimestill early days for me on the keycloak stuff14:21
kmallocjohnthetubaguy: hopefully this week i'll have an example of keycloak and dex up for some evaluation for covering those gaps.14:21
yankcrimei've not yet bumped into anything that falls into the 'needs fixing in keystone' category14:21
kmallocjohnthetubaguy: and i expect within a year (provided we week moving forward) keystone could fill most of the needs of either.14:22
kmallocs/week/we keep/14:23
hrybackigagehugo: kmalloc I'm taking swing at projects api this week fyi14:58
gagehugohrybacki: \o/15:00
* knikolla will not be in front of a pc for another hour15:05
knikollaHope everyone had a safe travel back15:05
knikolla(We’ve been using a convoluted keycloak proxy idp setup, so I’ll be happy to help to the extent of my knowledge)15:12
openstackgerritLance Bragstad proposed openstack/oslo.limit master: Render API reference documentation
openstackgerritLance Bragstad proposed openstack/oslo.limit master: Add a conceptual overview to docs
openstackgerritLance Bragstad proposed openstack/oslo.limit master: Allow ProjectClaims to support multiple resources
openstackgerritLance Bragstad proposed openstack/oslo.limit master: Ignore documentation builds
kmallochrybacki: okie15:24
lbragstadknikolla wxy-xiyuan cmurphy kmalloc gagehugo hrybacki any preferences for when we should do the retrospective this week?15:41
knikollalbragstad: doodle poll?15:42
kmallocif it is tuesday or thursday, it has to be after 11am pacific15:42
lbragstad++ yeah - i can throw one together15:42
kmallocotherwise, short of a case of the conference ick (which I don't think can be shared via bluejeans :P) I am good with most times.15:43
kmalloc(aka, today is not my 1st choice, still feeling gross)15:43
knikollaAnother good one is when2meet.com15:43
knikollaSame for not today15:44
hrybackilbragstad: I think we can do most of it async and address items folks want to raise (rather than just be known)15:44
kmallocas long as it doesn't require an account/sign-in knikolla  :)15:44
hrybackimy schedule is not good until Friday15:44
knikollakmalloc: you can set up a per poll username/pass to edit your selection15:44
lbragstadthat'll probably work better for wxy-xiyuan and cmurphy, too15:45
hrybackiI'll re-raise this at tomorrow's mtg15:45
gagehugoyeah not today, I also feel a tad gross15:46
kmalloclbragstad: uh16:09
kmalloclbragstad: next week is a giant question mark for me.16:09
openstackgerritLance Bragstad proposed openstack/oslo.limit master: Use openstackdocstheme for documentation
kmalloclbragstad: chances are I can't commit to any time until the day of.16:09
kmalloclbragstad: more dr. appointments and some big-deal things that could be any day that week16:09
kmalloclbragstad: so, i have to decline all of next week options for the retro16:10
lbragstadkmalloc no worries - if it ends up being a bust for others too we can push it16:10
lbragstadthe retro meeting is kinda tbd depending on the feedback (which is completely async anyway)16:10
lbragstadso long as people add their feedback, that'll be good16:12
lbragstadand we'll see if we even need to have a meeting16:12
*** gyee has joined #openstack-keystone16:12
*** prashkre has joined #openstack-keystone16:59
openstackgerritAndreas Jaeger proposed openstack/keystone master: Use templates for cover and lower-constraints
openstackgerritAndreas Jaeger proposed openstack/keystone-tempest-plugin master: Rename keystone zuul jobs
AJaegerkeystone tempest cores, a tiny cleanup for your consideration - helps to cleanup global job list. Thanks18:08
AJaegerkmalloc: thanks19:37
AJaegerkmalloc: left a comment - it's not just renaming, it's using "your" own keystone jobs19:37
kmallocAJaeger: wfm. still +219:42
*** felipemonteiro has joined #openstack-keystone19:46
ildikovkmalloc: hi :)19:52
ildikovkmalloc: I pinged you to get back to federation testing a little19:53
ildikovkmalloc: we have this etherpad with a few test case ideas:
ildikovkmalloc: would be great to get some feedback and if there's any other effort in this area please add a pointer to that to the etherpad too19:54
ildikovknikolla: lbragstad: cmurphy: ^^19:54
lbragstadoh - nice19:55
hrybackikmalloc: where are the `api_bp` being populated for ? Following a traceback from:
ildikovlbragstad: the etherpad has all testing efforts in it so it's a bit messy, will do some cleanup when I get there :)19:56
kmallochrybacki: post a whole traceback?20:26
hrybackikmalloc: -- all API tests are failing in the same manner -- I broke the app factory IIUC20:28
kmallochrybacki: look at the bottom of say: keystone.api.credentials see the "APIs =20:28
* hrybacki slaps his forehead20:28
kmallocIt's ok, blame flo (hurricanes suck) ^_^20:29
hrybackithanks kmalloc :P20:30
* lbragstad just finished his TC report20:38
lbragstadmy brain is mush20:38
*** felipemonteiro has joined #openstack-keystone21:39
* knikolla just woke up from a longer than planned afternoon nap22:07
*** openstackgerrit has joined #openstack-keystone22:11
openstackgerritMorgan Fainberg proposed openstack/keystone master: Properly normalize domain ids in flask
kmalloclbragstad, knikolla: lovely bug reported by mordred fixed here ^22:11
openstackLaunchpad bug 1793027 in OpenStack Identity (keystone) "Flask doesn't normalize domains sanely in some cases" [Critical,In progress] - Assigned to Morgan Fainberg (mdrnstm)22:11
lbragstadstepping out for a bit but i'm going to be on later22:12
kmallochrybacki: ^ that fix will impact "users" port to flask as wel22:13
*** felipemonteiro has joined #openstack-keystone22:44
openstackgerritFelipe Monteiro proposed openstack/keystone master: fix: Include missing method in flask ResourceBase class

