Monday, 2019-03-11

openstackgerritMerged openstack/keystone master: Add manager for access rules config
openstackgerritMerged openstack/keystone master: Add a permissive mode for access rules config
openstackgerritMerged openstack/keystone master: Add SQL migrations for app cred access rules
openstackgerritMerged openstack/keystone master: Add driver support for app cred access rules
openstackgerritVishakha Agarwal proposed openstack/keystone master: Implement domain reader for role_assignments
openstackgerritVishakha Agarwal proposed openstack/keystone master: Implement domain reader for role_assignments
openstackgerritVishakha Agarwal proposed openstack/keystone master: WIP : Implement system reader for grant API
mpasseriniHi, I tried activating policy.v3cloudsample.json but it does not seem to work for me… I noticied that if I run "oslopolicy-policy-generator --namespace keystone" as root I see the new policy…  but if I run it as a normal user I see the default policy12:45
mpasseriniany idea why this happens?12:45
efriedCan I please get a consult on ?13:16
efriedI want to make sure it makes semantic sense before I start quibbling with the grammar.13:16
openstackgerritPavlo Shchelokovskyy proposed openstack/keystone master: Add hint for order of keys during distribution
mpasseriniI'm reading , are domains in Keystone working at all? It looks like we can't delegate domain_admin roles to somebody13:25
openstackLaunchpad bug 968696 in OpenStack Identity (keystone) "duplicate for #1783659 "admin"-ness not properly scoped" [High,In progress] - Assigned to Lance Bragstad (lbragstad)13:25
cmurphympasserini: depends on what you mean by working, the bug of admin-ness-everywhere still applies with the default policies but you can customize your policies to avoid it14:19
cmurphyhmm efried disappeared14:19
mpasserinicmurphy, by default policy do you mean policy.v3cloudsample.json ?14:23
cmurphympasserini: no, that policy is not the default, it's an example of a way to customize it14:24
mpasseriniok, so I tried using policy.v3cloudsample.json and admin could see everything..14:25
mpasseriniboth in his domain, but also in domains he didn't belong to14:25
lbragstadmpasserini unfortunately, the policy.v3cloudsample.json file isn't officially supported and isn't tested as extensively as the default policies in code14:40
mpasseriniok :(14:53
lbragstadmpasserini what release are you using?14:55
lbragstadwell, for what it's worth, we're working on efforts, starting in Stein, to improve the defaults, increase testing, and remove policies from policy.v3cloudsample.json14:56
lbragstad is a summary of that work14:58
vishakhalbragstad: Hello. For I added a patch in tempest pl have a look.15:36
lbragstadvishakha awesome - i'll take a look today15:36
vishakhalbragstad: thanks a lot15:37
lbragstadno problem - thanks for writing the patches15:37
openstackgerritColleen Murphy proposed openstack/keystone master: Remove publish-loci post job
cmurphywould appreciate quick reviews on that ^ we need it so that we can update our rpms15:48
lbragstaddone - i'll watch for zuul and +W15:55
vishakhalbragstad:  Also I started over grant API but facing some issues writing the test cases  I  was taking the reference of Api-ref document for the rest api calls .  But when15:55
vishakhausing head getting some strange error.15:55
cmurphylbragstad: you know you can +W and if zuul doesn't like it it won't merge it?15:56
lbragstadcmurphy yeah - i got my hand slapped for doing that a long time ago, but that was also a long time ago15:56
lbragstadvishakha i assume makes the error repeatable?15:57
lbragstadcmurphy my hesitation/FUD probably isn't relevant anymore15:58
cmurphyi think zuul was always designed to prevent merging if it didn't pass ci15:58
lbragstadtrue - when i was advised to not do that was when we were still using Jenkins15:59
vishakhalbragstad: it is showing assertion error - I AM A TEAPOT (418)15:59
vishakhathanks for the quick comment16:01
vishakhalbragstad:  it worked16:02
lbragstadno more 418?16:03
kmallocThe teapot error saves us again from a broken test!16:37
lbragstadbroken teapots are the worst16:42
*** gyee has joined #openstack-keystone16:46
hrybackikmalloc: o/17:35
hrybackiwhat happens in KSM if a memcached instance disappears?17:35
hrybacki(assuming you have caching enabled and using memcached per norm)17:36
kmallocin theory, the memcache instance is failed out and causes a minimal amount of slow down.17:38
kmallocand the caching is always a cache miss17:38
kmallocif you have multiple servers, then the cache is rebalanced via a hash17:38
kmallocand the previously cached data is a miss, new data is placed in the current servers. if the server comes back in, the hash rebalance probably causes some misses17:39
hrybackilet's say we only have a single memcached server running, it goes down, and is taking minutes (for whatever reason) to come back up17:40
hrybackiis this going to hold everything up or is ksm going to ignore it after X failed set/gets?17:40
kmallocshould ignore if memcache(d) interface is written correctly17:40
kmallocafter a nominal timeout17:41
kmallocin  the past we had a big delay.17:41
kmallocbut that was bug related.17:41
hrybackihmm. it's a good thing tripleo doesn't make this more complicated /s17:42
lbragstadi'm not sure if people here have a strong preference for gathering around tables with food - but i added some ideas to the etherpad
*** vishakha has quit IRC20:45
openstackgerritMerged openstack/keystone master: Remove publish-loci post job
