Tuesday, 2019-06-25

*** wxy-xiyuan has joined #openstack-keystone01:08
*** rcernin has quit IRC01:48
*** rcernin has joined #openstack-keystone01:48
*** whoami-rajat has joined #openstack-keystone02:07
*** rcernin has quit IRC02:42
*** rcernin has joined #openstack-keystone02:42
*** rcernin has quit IRC03:04
*** rcernin has joined #openstack-keystone03:04
*** lbragstad has joined #openstack-keystone03:18
*** mnaser has quit IRC03:19
*** mnaser has joined #openstack-keystone03:20
*** gagehugo has quit IRC03:22
*** gagehugo has joined #openstack-keystone03:22
*** gagehugo has quit IRC03:25
*** gagehugo has joined #openstack-keystone03:28
*** rcernin has quit IRC03:30
*** rcernin has joined #openstack-keystone03:31
openstackgerritLance Bragstad proposed openstack/oslo.limit master: WIP put together example and smooth out issues  https://review.opendev.org/66724203:53
lbragstadjohnthetubaguy those docs should render with the example ^03:54
*** lbragstad has quit IRC03:59
*** pcaruana has joined #openstack-keystone05:56
*** pcaruana has quit IRC05:57
*** pcaruana has joined #openstack-keystone05:57
*** eivis has joined #openstack-keystone06:14
eivisYo! Do we have here alive people ?06:15
openstackgerritVishakha Agarwal proposed openstack/keystone master: Remove [signing] config  https://review.opendev.org/65943406:19
*** rcernin has quit IRC06:41
*** altlogbot_2 has quit IRC06:46
*** dancn has joined #openstack-keystone06:48
*** altlogbot_1 has joined #openstack-keystone06:49
*** altlogbot_1 has quit IRC06:50
*** altlogbot_0 has joined #openstack-keystone06:55
*** tesseract has joined #openstack-keystone07:11
*** xek has joined #openstack-keystone07:22
*** Emine has joined #openstack-keystone07:33
openstackgerritVishakha Agarwal proposed openstack/python-keystoneclient master: Blacklist bandit 1.6.0 & cap sphinx for 2.7  https://review.opendev.org/66060908:22
*** tkajinam has quit IRC08:27
*** tkajinam has joined #openstack-keystone08:28
*** Dinesh_Bhor has quit IRC08:29
*** tkajinam has quit IRC08:29
*** imacdonn has quit IRC08:42
*** imacdonn has joined #openstack-keystone08:42
*** Dinesh_Bhor has joined #openstack-keystone09:01
*** jaosorior has joined #openstack-keystone09:03
*** jaosorior has quit IRC09:11
openstackgerritVishakha Agarwal proposed openstack/python-keystoneclient master: Follow bandit B105: hardcoded_password_string  https://review.opendev.org/66730409:39
openstackgerritVishakha Agarwal proposed openstack/python-keystoneclient master: Blacklist bandit 1.6.0 & cap sphinx for 2.7  https://review.opendev.org/66060909:41
*** gmann has quit IRC09:57
*** Dinesh_Bhor has quit IRC10:16
eivisHello10:55
eivisIt would be great to discuss about keystone ldap10:56
eivisanyone ?10:56
*** gmann has joined #openstack-keystone10:58
eivisgmann10:58
eivisbe a man and discuss with me10:58
*** jaosorior has joined #openstack-keystone10:59
*** jaosorior has quit IRC11:02
*** jaosorior has joined #openstack-keystone11:03
*** lbragstad has joined #openstack-keystone11:33
*** raildo has joined #openstack-keystone12:07
*** dave-mccowan has joined #openstack-keystone13:06
*** dancn has quit IRC13:09
*** whoami-rajat has quit IRC13:16
*** dave-mccowan has quit IRC13:18
*** dave-mccowan has joined #openstack-keystone13:31
*** openstackgerrit has quit IRC13:48
kmalloceivis: sometimes folks are on different time zones, most folks here tend to be US time zones. Please be patient. What issues are you having with keystone/ldap?14:07
*** Dinesh_Bhor has joined #openstack-keystone14:25
*** Dinesh_Bhor has quit IRC14:40
eivisI understand it ;)14:55
lbragstadjohnthetubaguy so - i think i have a working example for oslo.limit14:56
eiviswell I have pretty big count of users in AD and i would like to add two diffrent tree in same domain15:02
eivisis it possible ?15:02
eivisand on one tree i have around 14k users, is there any chances that keyston would handle it?15:03
eivisOr is there any way to integrate LDAP, but users on keystone would appear only after first login ?15:04
eivisI tried to increase max_request_body_size = 114688 on keystone.conf but still no luck InternalServerError: Number of User/Group entities returned by LDAP exceeded size limit. Contact your LDAP administrator. (HTTP 500)15:07
eivisLDAP has right limit15:08
kmalloceivis: for appearing after the first login, using ADFS and federation via SAML would do that, but it would require ECP SAML each login15:19
kmalloceivis: that is a large number of users, at HPE we had at one point ~100k users in AD/LDAP that hooked into keystone, the only place we really had issues was when listing the users.15:20
kmalloceivis: you can add an explicit filter that would allow access for two different trees, though typically deployers use a tree per domain.15:21
*** vishakha has joined #openstack-keystone15:25
*** xek has quit IRC15:26
*** yan0s has joined #openstack-keystone15:30
knikollahave to miss the keystone meeting. have a scheduling conflict.15:31
cmurphyokay thanks knikolla15:33
*** xek has joined #openstack-keystone15:34
*** jaosorior has quit IRC15:38
*** jaosorior has joined #openstack-keystone15:38
*** Emine has quit IRC15:39
*** openstackgerrit has joined #openstack-keystone15:39
openstackgerritLance Bragstad proposed openstack/oslo.limit master: WIP put together example and smooth out issues  https://review.opendev.org/66724215:39
*** xek has quit IRC15:43
kmalloccmurphy: if you didn't see earlier, the resource-options changes are next on my list todo15:43
kmallocnow that i am home, no more dr. appt craziness, etc.15:43
kmalloceivis: ldap trees that big are somewhat unwieldy an to work with within keystone.15:44
cmurphythanks kmalloc15:45
cmurphymeeting in 15 minutes in #openstack-meeting-alt15:45
kmalloccmurphy: mostly it's a sql migration (new table, data migrate) and then we just link in the code in the other subsystems we want to add ROs for15:46
kmallocshould become a fairly easy pattern to follow.15:46
cmurphykmalloc: are you going to do new tables for all drivers, like we have with user_option? or one table for all?15:46
kmallocone table for all15:47
cmurphycoolbeans15:47
kmallocas we discussed earlier, unless we changed our minds15:47
cmurphyno i just forgot15:47
kmallocthe sql migration will be user-ROs -> new table, and then we can replicate the pattern.15:47
cmurphysounds good15:48
kmalloceach resource will need a unique identifier that can be referenced to load the options15:48
kmallocso, the way I see it is a resource option will become somewhat generic e.g. "immutable" and then each resource that can support it will be in a whitelist15:49
kmallocso the load from DB code will check to make sure the option is allowed for say, users before populating the element into the data structure when returned15:50
kmalloci'll add a keystone-manage command to "cleanup" any invalid options in the case we remove support for an option in the future15:50
kmallocor a bug mis-attributes an option to a resource that is not allowed.15:50
kmallocunfortunately, FKs wont work because you can't FK to multiple tables (as far as i know)15:51
kmallocso we'll need an in-line cleanup15:52
kmallocso deleiting a user will need to signal to cleanup the ROs for the user.15:52
* kmalloc wonders if there is a better way to handle that15:52
openstackgerritColleen Murphy proposed openstack/keystone master: Switch order of precedence for unit test deps  https://review.opendev.org/66471215:53
cmurphymeeting now in #openstack-meeting-alt16:02
*** yan0s has quit IRC16:05
*** tesseract has quit IRC16:35
*** tesseract has joined #openstack-keystone16:36
openstackgerritLance Bragstad proposed openstack/oslo.limit master: WIP put together example and smooth out issues  https://review.opendev.org/66724216:57
*** tesseract has quit IRC16:59
*** efried has joined #openstack-keystone18:02
efriedlbragstad: Hey mon, is https://review.opendev.org/#/c/602201/ (unified limits in nova) looking sane?18:03
efriedwas this discussed at the PTG? (I would have been pretty checked out during the keystone xproj, recovering some brain)18:04
openstackgerritMerged openstack/oslo.limit master: Remove ProjectClaim object from oslo.limit  https://review.opendev.org/66570818:12
openstackgerritMerged openstack/oslo.limit master: Remove verification functionality  https://review.opendev.org/66570918:12
openstackgerritMerged openstack/oslo.limit master: Remove __enter__ and __exit__ methods from Enforcer  https://review.opendev.org/66571018:12
lbragstadefried i can take a look18:14
lbragstadefried we were just talking about an example - it's tailored for nova18:16
lbragstadhttps://review.opendev.org/#/c/667242/4/doc/source/user/example.py18:17
lbragstad^ that's a best guess at what a service, like nova, might do to start using all this stuff18:19
openstackgerritMerged openstack/oslo.limit master: Add skeleton enforce() method to Enforcer  https://review.opendev.org/66571118:27
*** jdennis has quit IRC18:35
openstackgerritLance Bragstad proposed openstack/oslo.limit master: Add ksa connection logic  https://review.opendev.org/66608518:53
openstackgerritLance Bragstad proposed openstack/oslo.limit master: Add ksa connection logic  https://review.opendev.org/66608519:24
openstackgerritLance Bragstad proposed openstack/oslo.limit master: Flush out basic enforcer and model relationship  https://review.opendev.org/66644419:24
*** pcaruana has quit IRC19:38
openstackgerritRaildo Mascena proposed openstack/keystone master: Fixing dn_to_id function for cases were id is not in the DN  https://review.opendev.org/64917719:45
openstackgerritLance Bragstad proposed openstack/oslo.limit master: Add usage example  https://review.opendev.org/66724219:54
openstackgerritLance Bragstad proposed openstack/oslo.limit master: Implement flat enforcement model  https://review.opendev.org/66745219:54
*** vishakha has quit IRC19:55
cmurphymidcycle details and doodle poll http://lists.openstack.org/pipermail/openstack-discuss/2019-June/007344.html20:44
*** openstackgerrit has quit IRC21:18
*** jdennis has joined #openstack-keystone21:20
*** Emine has joined #openstack-keystone21:45
*** tobberydberg has quit IRC21:49
*** tobberydberg has joined #openstack-keystone21:51
*** eivis has quit IRC21:51
efriedThanks for the nod lbragstad21:54
*** raildo has quit IRC22:03
*** Emine has quit IRC22:07
lbragstadefried yessir22:17
*** tkajinam has joined #openstack-keystone22:56
*** rcernin has joined #openstack-keystone23:05
*** brett-soric has joined #openstack-keystone23:10
*** brett-soric has left #openstack-keystone23:56

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!