Wednesday, 2019-02-27

adriantcmurphy: 'should' have time next cycle. I'd really hope so.00:06
*** markvoelker has joined #openstack-keystone00:06
*** edmondsw has quit IRC00:17
*** itlinux has joined #openstack-keystone00:22
*** itlinux has quit IRC00:26
*** nsmeds has quit IRC00:27
erusis anyone available? :)00:37
*** markvoelker has quit IRC00:40
*** jamesmcarthur has joined #openstack-keystone00:47
*** awalende has joined #openstack-keystone00:47
*** erus has quit IRC00:47
*** erus has joined #openstack-keystone00:48
kmallocknikolla: o/ you around?00:49
knikollakmalloc: o/00:50
*** awalende has quit IRC00:52
*** lbragstad has quit IRC00:59
*** jamesmcarthur has quit IRC01:01
*** jamesmcarthur has joined #openstack-keystone01:02
erusD:01:02
eruskmalloc knikolla01:03
*** nsmeds has joined #openstack-keystone01:15
*** itlinux has joined #openstack-keystone01:17
*** erus has quit IRC01:31
*** erus has joined #openstack-keystone01:31
*** itlinux has quit IRC01:36
*** markvoelker has joined #openstack-keystone01:37
*** takamatsu_ has quit IRC01:39
*** edmondsw has joined #openstack-keystone01:42
*** takamatsu_ has joined #openstack-keystone01:45
*** lbragstad has joined #openstack-keystone01:58
*** ChanServ sets mode: +o lbragstad01:58
*** whoami-rajat has joined #openstack-keystone02:01
*** markvoelker has quit IRC02:10
*** ileixe has joined #openstack-keystone02:11
ileixeHi guys.02:11
ileixeDoes anybody know current state of dynamic policy? (https://wiki.openstack.org/wiki/DynamicPolicies)02:11
ileixeIs there any change to control policy.json using API? :)02:12
ileixeendpoint_policy looks promsing for my purpose, but I'm not sure what the exact purpose of it.02:14
*** erus has quit IRC02:14
*** gyee has quit IRC02:15
*** erus has joined #openstack-keystone02:15
*** jamesmcarthur has quit IRC02:18
*** jamesmcarthur has joined #openstack-keystone02:20
*** jamesmcarthur has quit IRC02:25
*** Dinesh_Bhor has joined #openstack-keystone02:30
*** rcernin has quit IRC02:32
lbragstadileixe i've never seen that wiki page before02:44
lbragstadlooks like it was last updated just under 4 years ago02:45
ileixeYes it's quite old02:45
lbragstadi think that initiative was abandoned some time ago02:45
ileixeSo you mean does community not pursue to manage policy via API anymore?02:46
lbragstadnot in the sense that wiki is describing02:47
lbragstadbut there are several other policy initiatives underway02:47
lbragstadin addition to oslo.policy functionality that allows you to offload policy enforcement to external systems02:47
lbragstadwhich could expose endpoints to modify policies associated to roles02:48
lbragstadalso - jaosorior has a whole bunch of policy tricks up his sleeve02:51
lbragstadis there a specific use case your looking for?02:51
ileixeAh, yes I know the external system from oslo.policy02:51
lbragstador are you just looking for an API to modify policies?02:51
ileixeUm.. The first thing I was thinking about was whether there was a way for tempest's testcase to know the policy.02:53
*** takamatsu_ has quit IRC02:53
ileixeSince we customized policy a lot, there were many. cases to be failed.02:53
ileixeI do not maintain skip-list so I wonder if policy can be controlled via API, tempest side can configure it.02:54
ileixeIt's my initiative thinking but I think it looks very gereral problem about policy management02:55
*** erus has quit IRC02:55
*** jamesmcarthur has joined #openstack-keystone02:55
*** erus has joined #openstack-keystone02:55
ileixeI do not *want02:56
lbragstadoh - interesting...02:56
lbragstadare you looking to develop tests for the policy changes you've made?02:57
lbragstadto verify they do what you want/expect them to?02:57
ileixeI reported at tempest side (https://bugs.launchpad.net/tempest/+bug/1817811), but now sure the project want to do. :)02:59
openstackLaunchpad bug 1817811 in tempest "Need policy-awared test" [Undecided,New]02:59
lbragstadah02:59
lbragstadi could be wrong02:59
lbragstadbut that sound similar to what the patrole team was trying to solve03:00
lbragstad(in a way)03:00
lbragstadsounds similar*03:00
ileixeOh, never heard of it. I will look over it.03:01
*** jamesmcarthur has quit IRC03:01
lbragstadhttps://docs.openstack.org/patrole/latest/03:01
lbragstadlink to their documentation ^03:01
ileixeThanks lbragstad. You're always very kind to newbie :)03:02
lbragstadileixe anytime - hopefully it helps03:02
*** markvoelker has joined #openstack-keystone03:04
*** erus has quit IRC03:11
*** erus has joined #openstack-keystone03:12
*** itlinux has joined #openstack-keystone03:31
openstackgerritLance Bragstad proposed openstack/keystone master: Implement domain reader for role_assignments  https://review.openstack.org/63858703:52
*** spsurya has joined #openstack-keystone04:15
*** erus has quit IRC04:38
*** erus has joined #openstack-keystone04:38
*** jamesmcarthur has joined #openstack-keystone04:46
*** ileixe has quit IRC04:54
*** itlinux has quit IRC05:01
*** dave-mccowan has quit IRC05:05
*** shyamb has joined #openstack-keystone05:16
*** jamesmcarthur has quit IRC05:19
*** ileixe has joined #openstack-keystone05:42
*** ileixe has quit IRC05:42
*** ileixe has joined #openstack-keystone05:43
jaosoriorlbragstad: o/05:44
lbragstadjaosorior o/05:44
jaosoriorlbragstad: ah, saw you resolved ileixe's issue. cool05:45
lbragstadyup05:45
*** shyamb has quit IRC06:18
*** jamesmcarthur has joined #openstack-keystone06:49
*** markvoelker has quit IRC06:51
*** erus has quit IRC06:53
*** erus has joined #openstack-keystone06:54
*** jamesmcarthur has quit IRC06:54
*** Dinesh_Bhor has quit IRC06:58
*** Dinesh_Bhor has joined #openstack-keystone07:01
*** Dinesh_Bhor has quit IRC07:12
*** erus has quit IRC07:12
*** erus has joined #openstack-keystone07:12
*** shyamb has joined #openstack-keystone07:16
*** takamatsu_ has joined #openstack-keystone07:21
*** jamesmcarthur has joined #openstack-keystone07:51
*** markvoelker has joined #openstack-keystone07:52
*** erus has quit IRC07:55
*** jamesmcarthur has quit IRC07:55
*** erus has joined #openstack-keystone07:56
*** lbragstad has quit IRC08:01
*** Dinesh_Bhor has joined #openstack-keystone08:10
*** pcaruana has joined #openstack-keystone08:13
*** Dinesh_Bhor has quit IRC08:14
*** imacdonn has quit IRC08:18
*** imacdonn_ has joined #openstack-keystone08:18
*** erus has quit IRC08:25
*** markvoelker has quit IRC08:25
*** erus has joined #openstack-keystone08:26
*** pcaruana has quit IRC08:28
*** takamatsu_ has quit IRC08:31
*** tkajinam has quit IRC08:33
*** erus has quit IRC08:33
*** erus has joined #openstack-keystone08:33
*** pcaruana has joined #openstack-keystone08:42
*** pcaruana has quit IRC08:51
*** erus has quit IRC08:51
*** jamesmcarthur has joined #openstack-keystone08:51
*** erus has joined #openstack-keystone08:52
*** jamesmcarthur has quit IRC08:56
*** pcaruana has joined #openstack-keystone08:58
*** pcaruana|afk| has joined #openstack-keystone09:01
*** pcaruana has quit IRC09:03
*** shyamb has quit IRC09:03
*** shyamb has joined #openstack-keystone09:04
*** takamatsu has joined #openstack-keystone09:15
*** shyamb has quit IRC09:21
*** shyamb has joined #openstack-keystone09:22
*** markvoelker has joined #openstack-keystone09:23
*** takamatsu has quit IRC09:44
*** shyamb has quit IRC09:45
*** mvkr has quit IRC09:46
*** shyamb has joined #openstack-keystone09:46
*** jamesmcarthur has joined #openstack-keystone09:52
*** markvoelker has quit IRC09:57
*** jamesmcarthur has quit IRC09:57
*** mvkr has joined #openstack-keystone10:01
*** shyamb has quit IRC10:36
*** shyamb has joined #openstack-keystone10:37
*** erus has quit IRC10:45
*** erus has joined #openstack-keystone10:46
*** markvoelker has joined #openstack-keystone10:53
*** Dinesh_Bhor has joined #openstack-keystone10:57
*** Dinesh_Bhor has quit IRC11:00
*** ileixe has quit IRC11:20
*** takamatsu has joined #openstack-keystone11:24
*** markvoelker has quit IRC11:26
*** shyamb has quit IRC11:44
*** shyamb has joined #openstack-keystone11:44
*** jamesmcarthur has joined #openstack-keystone11:54
*** erus has quit IRC11:54
*** erus has joined #openstack-keystone11:55
*** jamesmcarthur has quit IRC11:59
*** awalende has joined #openstack-keystone12:16
*** raildo has joined #openstack-keystone12:22
*** markvoelker has joined #openstack-keystone12:22
erusmorning o/12:35
*** jamesmcarthur has joined #openstack-keystone12:55
*** markvoelker has quit IRC12:56
*** jamesmcarthur has quit IRC12:59
*** shyamb has quit IRC13:03
*** dave-mccowan has joined #openstack-keystone13:04
*** pcaruana|afk| has quit IRC13:09
*** mchlumsky has joined #openstack-keystone13:15
*** jmlowe has quit IRC13:29
*** jamesmcarthur has joined #openstack-keystone13:48
*** erus has quit IRC13:52
*** markvoelker has joined #openstack-keystone13:53
*** erus has joined #openstack-keystone13:53
*** jmlowe has joined #openstack-keystone14:13
*** jamesmcarthur has quit IRC14:14
*** erus has quit IRC14:19
*** erus has joined #openstack-keystone14:20
*** lbragstad has joined #openstack-keystone14:20
*** ChanServ sets mode: +o lbragstad14:20
*** markvoelker has quit IRC14:25
*** erus has quit IRC14:33
*** erus has joined #openstack-keystone14:33
*** erus has quit IRC14:40
*** erus has joined #openstack-keystone14:41
*** erus has quit IRC14:47
*** erus has joined #openstack-keystone14:47
*** pcaruana has joined #openstack-keystone14:57
*** itlinux has joined #openstack-keystone14:59
*** erus has quit IRC14:59
*** erus has joined #openstack-keystone15:00
*** jamesmcarthur has joined #openstack-keystone15:03
*** erus has quit IRC15:13
*** erus has joined #openstack-keystone15:13
*** aning_ has left #openstack-keystone15:19
*** aning_ has joined #openstack-keystone15:19
*** markvoelker has joined #openstack-keystone15:22
*** erus has quit IRC15:29
*** erus has joined #openstack-keystone15:29
*** itlinux_ has joined #openstack-keystone15:31
*** itlinux has quit IRC15:34
*** erus has quit IRC15:36
*** erus has joined #openstack-keystone15:37
gagehugoo/15:40
*** awalende has quit IRC15:41
*** awalende has joined #openstack-keystone15:42
*** dmellado has quit IRC15:42
*** dmellado has joined #openstack-keystone15:43
*** awalende has quit IRC15:46
*** itlinux_ has quit IRC15:46
openstackgerritLance Bragstad proposed openstack/keystone master: Implement system reader for role_assignments  https://review.openstack.org/60921015:54
openstackgerritLance Bragstad proposed openstack/keystone master: Reorganize role assignment tests for system users  https://review.openstack.org/63830915:54
openstackgerritLance Bragstad proposed openstack/keystone master: Add role assignment test coverage for system members  https://review.openstack.org/63831015:54
openstackgerritLance Bragstad proposed openstack/keystone master: Add role assignment test coverage for system admin  https://review.openstack.org/63831115:54
openstackgerritLance Bragstad proposed openstack/keystone master: Implement domain reader for role_assignments  https://review.openstack.org/63858715:54
openstackgerritLance Bragstad proposed openstack/keystone master: Add role assignment test coverage for domain members  https://review.openstack.org/63859315:54
openstackgerritLance Bragstad proposed openstack/keystone master: Add role assignment test coverage for domain admins  https://review.openstack.org/63859715:54
openstackgerritLance Bragstad proposed openstack/keystone master: Add role assignment testing for project users  https://review.openstack.org/63971815:54
*** markvoelker has quit IRC15:56
*** erus has quit IRC15:56
*** erus has joined #openstack-keystone15:56
knikollao/15:57
openstackgerritLance Bragstad proposed openstack/keystone master: Add role assignment test coverage for domain admins  https://review.openstack.org/63859715:58
openstackgerritLance Bragstad proposed openstack/keystone master: Add role assignment testing for project users  https://review.openstack.org/63971815:58
lbragstado/15:58
kmalloco/16:03
lbragstadgagehugo are you holding off on the +A for https://review.openstack.org/#/c/619280/ ?16:07
lbragstadhttps://review.openstack.org/#/c/622526/4 is a relatively easy series, too16:08
*** erus has quit IRC16:08
*** erus has joined #openstack-keystone16:09
*** takamatsu has quit IRC16:09
gagehugonope :)16:09
gagehugodone16:09
gagehugoalso done16:11
lbragstadwoot16:12
openstackgerritLance Bragstad proposed openstack/keystone master: Remove domain policies from policy.v3cloudsample.json  https://review.openstack.org/60587616:14
openstackgerritLance Bragstad proposed openstack/keystone master: Remove endpoint policies from policy.v3cloudsample.json  https://review.openstack.org/61933316:17
*** dmellado has quit IRC16:32
*** dmellado has joined #openstack-keystone16:34
*** erus has quit IRC16:34
*** erus has joined #openstack-keystone16:35
*** erus has quit IRC16:40
*** erus has joined #openstack-keystone16:41
*** prometheanfire has joined #openstack-keystone16:51
prometheanfirelbragstad: ping (re https://storyboard.openstack.org/#!/story/2003792 )16:52
lbragstadprometheanfire o/16:53
*** markvoelker has joined #openstack-keystone16:53
*** pcaruana has quit IRC16:57
*** gyee has joined #openstack-keystone16:59
*** mvkr has quit IRC17:04
*** jamesmcarthur_ has joined #openstack-keystone17:14
*** erus has quit IRC17:14
*** erus has joined #openstack-keystone17:14
cmurphyjust a reminder if you're reviewing app cred things, https://review.openstack.org/633369 has to go in first - don't be fooled by the red ci, it needs its dependencies merged and released before it will be green17:17
*** jamesmcarthur has quit IRC17:17
* lbragstad made it through the API changes to keystone for app creds17:20
*** erus has quit IRC17:20
lbragstadif we break this up across stein and train, where were we thinking of making that split?17:20
cmurphylbragstad: see note above ^ you didnt' finish yet17:21
*** erus has joined #openstack-keystone17:21
cmurphylbragstad: i split the series so that both keystone/api/* changes are at the tail ends of their series17:21
cmurphyso we can merge everything up until each of those17:21
lbragstadoh - yeah, i was looking at only server changes17:22
lbragstadreviewing the ksm patch17:22
lbragstadi'm wondering if there is anything wrong with exposing the access rule config API in stein...17:23
cmurphyit's got a specific format so if we decide we don't like it or want to discuss it more we'd be out of luck17:24
cmurphyor if we don't like the name i went with17:24
lbragstadsure17:24
lbragstadthat brings up another question17:24
lbragstadwe're planning on this being stable immediately?17:24
cmurphygood question17:25
lbragstadi guess that gets complicated since app creds are already considered stable17:25
cmurphyyeah that17:25
*** markvoelker has quit IRC17:25
lbragstadbut the access rules and access rules config APIs are technically new APIs17:26
lbragstader - endpoints*17:26
cmurphyi feel like we were safe calling the limits APIs experimental because there's not a good way to use them until the other services in openstack are ready for it, with this it's much more user-facing17:26
cmurphyby that i mean we don't have a really official way of saying an api is experimental because the json-home document isn't very well socialized or documented17:27
lbragstadare you saying end users won't see "experimental" things like other service developers might?17:28
lbragstador operators?17:28
cmurphyusers17:28
lbragstadas much as i don't care for a term meaning different things to different people, i can see that point17:29
lbragstadi think that addresses one of the comments i had17:33
lbragstadi think that is plenty of justification to wait for Train to expose the APIs17:33
*** jmlowe has quit IRC17:34
*** erus has quit IRC17:34
*** erus has joined #openstack-keystone17:35
*** dims has quit IRC17:35
cmurphyi'm still on the fence, i wish we weren't under time pressure17:35
cmurphyi know a lot of people really want this feature17:35
lbragstadi hear ya17:35
cmurphybut in any case the ksm change needs to go in in the next like day or none of this matters17:36
lbragstadthis is a pretty involved change though17:36
cmurphyyeah it is17:36
lbragstadthis is all pretty fresh still, so i wouldn't be surprised if the other openstack services haven't looked at this at all yet17:40
*** erus has quit IRC17:40
*** takamatsu has joined #openstack-keystone17:41
*** erus has joined #openstack-keystone17:41
jrosserhello keystone :) could i get your thoughts on this http://lists.openstack.org/pipermail/openstack-discuss/2019-February/002925.html17:45
openstackgerritHervĂ© Beraud proposed openstack/keystonemiddleware master: Remove oslo.cache class _MemcacheClient who have been removed.  https://review.openstack.org/63715417:46
*** erus has quit IRC17:47
*** erus has joined #openstack-keystone17:47
*** dims has joined #openstack-keystone17:48
cmurphyjrosser: will try to weigh in, missed it initially because it didn't tag [keystone] explicitly ;)17:49
jrossercmurphy: thankyou :) there are a couple of references to the heat code where i believe that the wrong endpoint is passed17:50
cmurphylbragstad: i think the main benefit is to end users, services like heat magnum nova i think are waiting until this feature is in before they start building on it17:50
*** takamatsu has quit IRC18:01
lbragstadam i reading the series wrong, or are we only going to be able to merge access rule config internal changes in stein?18:08
lbragstador are we planning on rebasing the migration for access rules later?18:08
lbragstadnevermind18:09
lbragstadi forgot how to gerrit18:09
kmalloccmurphy: i am inlcined to push to train.18:10
kmalloccmurphy: it's why i didn't +2 the API change.18:10
kmalloclbragstad: ^ cc18:11
kmallocbut i'd still +2 the API change if you want it to land *now*18:11
* lbragstad is fine to push til train18:11
lbragstadmainly because i think it would be useful to have a forum session or ptg session where we say "this is all work that's done and here is the *proposed* API"18:12
*** markvoelker has joined #openstack-keystone18:22
cmurphylbragstad: kmalloc okay i'm fine with that, i/suse don't have a burning requirement for it to land this cycle18:24
cmurphywe might also then consider holding off on https://review.openstack.org/636030 since we can't remove it from keystoneauth once it's released18:25
openstackgerritMerged openstack/keystone master: Add tests for domain users interacting with services  https://review.openstack.org/61928018:33
*** erus has quit IRC18:38
*** erus has joined #openstack-keystone18:39
openstackgerritMerged openstack/keystone master: Update role policies for system admin  https://review.openstack.org/62252618:42
*** erus has quit IRC18:44
*** erus has joined #openstack-keystone18:44
*** jmlowe has joined #openstack-keystone18:47
*** jmlowe has quit IRC18:47
lbragstadcmurphy true18:48
*** jmlowe has joined #openstack-keystone18:48
lbragstadcmurphy would you be willing to drive a session on that at the forum and/or ptg?18:48
*** prometheanfire has left #openstack-keystone18:48
*** takamatsu has joined #openstack-keystone18:52
*** markvoelker has quit IRC18:56
cmurphylbragstad: sure18:58
lbragstadawesome19:00
lbragstadthanks19:00
openstackgerritMerged openstack/keystoneauth master: Expose app creds and new attrs in fixtures  https://review.openstack.org/63603019:23
*** lbragstad has quit IRC19:39
*** lbragstad has joined #openstack-keystone19:41
*** ChanServ sets mode: +o lbragstad19:41
*** spsurya has quit IRC19:52
*** markvoelker has joined #openstack-keystone19:53
*** jamesmcarthur_ has quit IRC20:20
*** markvoelker has quit IRC20:26
*** jmlowe has quit IRC20:29
*** dave-mccowan has quit IRC20:38
lbragstadcmurphy for when you're not dealing with app cred things https://review.openstack.org/#/c/622773/1720:39
*** dave-mccowan has joined #openstack-keystone20:45
cmurphylbragstad: o7 thanks for the reminder20:46
lbragstadyup20:46
rm_workHey, heard someone else here was interested in working on an x509 / athenz auth integration plugin -- anyone know who that is? :P20:49
lbragstadgyee is working on it intermittently20:49
*** erus has quit IRC20:49
lbragstadstill looking for more volunteers though20:50
*** erus has joined #openstack-keystone20:50
lbragstadrm_work are you attempting to use it?20:52
rm_workno, we have one internally already on queens but there was a major refactor in the area we patched, and rebasing it up is proving weird20:53
rm_workand then i thought "wait why the heck is this internal"20:53
rm_workand someone else here told me there was community interest in doing one20:53
rm_work(Verizon Media / Oath)20:54
lbragstadby "one" do you mean an implementation for x509 support?20:54
rm_workfor athenz specifically20:54
lbragstadyeah - that's what oath is doing20:54
rm_workyes20:54
rm_worki am at Oath :P20:54
lbragstadrm_work oh - jeeze20:54
lbragstadi didn't realize20:55
rm_worki was told there was someone else in the community20:55
rm_work(I just started here in December so your confusion is understandable)20:55
lbragstadaha20:55
openstackgerritBen Nemec proposed openstack/oslo.policy master: Provide more specific error when namespace is missing  https://review.openstack.org/63982220:55
lbragstadso - the x509 stuff has interest, possibly for edge usecases (as i'm sure you're aware being at oath)20:56
lbragstadso it's been getting time slots in the weekly edge meeting20:56
rm_workhmm k20:57
*** jamesmcarthur has joined #openstack-keystone20:57
lbragstadi think most of the edge interest came out of denver when penick hosted a clinic on how oath does federation for edge20:59
rm_workah21:00
rm_workyes, penick is my manager :D21:00
lbragstadbut ildikov has it on the weekly edge call21:00
lbragstadnice - i know he responded to the initial note to the mailing list about keystone's x509 support21:00
rm_workk21:00
lbragstadnot sure if you've seen that writeup yet?21:00
rm_workwell, may be interested in helping out21:01
rm_worknot yet no21:01
* lbragstad fetches a link21:01
rm_worki avoid the ML in general21:01
rm_workbut i'll look, appreciate linkage :)21:01
lbragstadhttp://lists.openstack.org/pipermail/openstack-discuss/2019-January/002085.html21:01
rm_workthanks21:01
lbragstadit was more or less a brain dump21:02
lbragstadi think it would help some of the things we're doing internally, but i'm waiting to hear back from our internal teams on it21:02
rm_workk21:03
lbragstadbut - i think it would help with federation overall, making it easier to test21:03
rm_workwhere are you now?21:03
lbragstadhuawei21:03
lbragstadon the plus side, y'all wouldn't need to maintain out-of-tree auth drivers for athenz support21:04
* lbragstad heard athenz is deprecating token support and pushing everything to using certificates21:04
rm_workyou may have heard more than me :P21:07
rm_workwe'll see if i end up being the one working on this21:07
rm_workbut if i am... i will need to  ... learn how keystone works. and also learn wtf athenz is and how it works. lol21:08
rm_workright now i'm in info gathering while i try to refactor our existing patch21:08
*** jaosorior has quit IRC21:08
rm_workah so... if it helps, i can just show you what our existing queens patch looks like21:09
rm_workit doesn't seem complex at all21:09
ildikovWe had interest in Keystone prior to that21:09
ildikovOath's use case generated interest in development direction besides reference architectures21:10
lbragstadrm_work i found https://yahoo.github.io/athenz/site/data_model/ helpful21:11
*** erus has quit IRC21:11
ildikovlbragstad: rm_work: we were wondering with csatari to organize hacking days21:11
*** erus has joined #openstack-keystone21:12
lbragstadhttps://github.com/yahoo/openstack-collab/tree/master/keystone-federation-ocata is the last bits i've seen of the athenz auth plugins21:12
ildikovMainly remote/virtual ones and we could try in person at the Summit21:12
lbragstadildikov nice21:12
ildikovAnd thought of the x509 bugs to work on as one potential topic21:13
rm_workso, this is the only patch i see for athenz support, but it looks like it is just the token piece? http://paste.openstack.org/show/Fv2Rl95ipR8dEhfC2GWF/21:13
rm_workso probably i will have to start over21:13
rm_worki assume this relies also on client patches21:13
ildikovI thought to bring it up here too to see if there's interest as we have people around with interest but less Keystone knowledge21:13
ildikovIt could help with learning/progress21:14
rm_worklbragstad: lol yes, thanks for the link to our own docs, somehow no one had sent me that yet >_<21:14
rm_work^^ serious21:15
rm_worki will read this21:15
lbragstadlol21:15
cmurphyjrosser: replied to your thread, maybe lbragstad or kmalloc can fact check me21:15
* jrosser looks21:15
lbragstadrm_work no to be confused with https://openathens.org/21:16
lbragstad^ that tripped me up several times21:16
*** jmlowe has joined #openstack-keystone21:17
lbragstadcmurphy i think your response makes sense21:21
cmurphyhopefully zane or rico can help clear things up21:23
*** markvoelker has joined #openstack-keystone21:23
*** jamesmcarthur has quit IRC21:24
*** jamesmcarthur has joined #openstack-keystone21:24
rm_workah yeah the patch i linked is the same as the one from that repo i guess21:26
rm_workyeah so, i guess just need to discuss with folks what this would need to look like in a generic form upstream21:27
lbragstadhttp://tinyurl.com/yxk22bux would actually get you pretty close21:34
lbragstadthen - users with x509 certificates from athenz could authenticate directly to keystone for tokens21:35
lbragstadbut you would also get the auto-provisioning functionality we have upstream21:35
lbragstadwhich is part of what the athenz plugins do21:35
lbragstadso - the last time i read the athenz auth plugins code, it looked like it did two things 1.) make it so keystone can deal with athenz tokens 2.) auto-provision some resources based on the values in the token21:39
lbragstadif users have x509 certificates issued from athenz, then #1 isn't really needed anymore since you're proving authentication with a certificate and not a token21:40
kmalloccmurphy: ++21:41
lbragstadand since keystone already supports auto-provisioning to some extent, you could create a federated mapping that provisions resources for users coming in with x509 certificates with athenz acting as the identity provider21:41
kmalloccmurphy: if heat is leaning on the KSM options it makes me want to change the option ... it is wrong.21:41
kmalloc:P21:42
lbragstadhttps://docs.openstack.org/keystone/latest/admin/federation/mapping_combinations.html#auto-provisioning is the auto-provisioning documentation21:42
kmalloci thouight we weeded out the use of the KSM options when we did the deprecation last time around for the old name21:42
cmurphyi'm not sure any of us ever went and did that21:51
kmalloci know there were a lot of threads on it in the paste21:51
kmallocpast*21:51
cmurphyand it's hard to control because oslo.config just makes it easy to scoop up any parameters it finds21:51
kmallocanyway, heat should transition away from leaning on the KSM options.21:51
kmallocyeah, i wish we could isolate the namespace(s) better.21:51
kmallocespecially for KSM.21:51
openstackgerritLance Bragstad proposed openstack/keystone master: Add tests for domain users interacting with roles  https://review.openstack.org/62252721:53
*** markvoelker has quit IRC21:56
openstackgerritLance Bragstad proposed openstack/keystone master: Add tests for domain users interacting with roles  https://review.openstack.org/62252721:57
openstackgerritLance Bragstad proposed openstack/keystone master: Add tests for project users interacting with roles  https://review.openstack.org/62252821:57
openstackgerritLance Bragstad proposed openstack/keystone master: Remove role policies from policy.v3cloudsample.json  https://review.openstack.org/62252921:57
*** mchlumsky has quit IRC21:59
openstackgerritMerged openstack/keystone master: Remove domain policies from policy.v3cloudsample.json  https://review.openstack.org/60587622:01
cmurphylbragstad: wxy-xiyuan i had two other questions on https://review.openstack.org/#/c/62277322:05
rm_worklbragstad: sorry, had a meeting pull me away, but thank you for the links and thoughts22:11
lbragstadnp22:11
rm_workIt's going to take me a bit to digest all of this, since it's my first time really looking at the keystone code and how this all works, beyond just being an end user22:12
rm_workAND my first time seeing how athenz works :D22:13
lbragstadno worries22:14
lbragstadit took me a while to wrap my head around the x509 stuff22:15
openstackgerriterus proposed openstack/keystone master: Add new attribute to the federation protocol API  https://review.openstack.org/63730522:30
*** jamesmcarthur has quit IRC22:36
*** jamesmcarthur has joined #openstack-keystone22:36
*** raildo has quit IRC22:37
*** tkajinam has joined #openstack-keystone23:00
*** rcernin has joined #openstack-keystone23:06
*** dave-mccowan has quit IRC23:14
*** erus has quit IRC23:14
*** erus has joined #openstack-keystone23:15
*** dave-mccowan has joined #openstack-keystone23:20
*** itlinux has joined #openstack-keystone23:26
*** awalende has joined #openstack-keystone23:43
*** awalende has quit IRC23:47
*** jamesmcarthur has quit IRC23:55

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!