Monday, 2020-04-27

*** threestrands has joined #openstack-keystone02:51
*** evrardjp has quit IRC04:35
*** evrardjp has joined #openstack-keystone04:35
*** vishalmanchanda has joined #openstack-keystone05:18
*** dancn has joined #openstack-keystone06:50
*** xek_ has quit IRC07:03
*** bengates has joined #openstack-keystone07:28
*** bengates has quit IRC07:29
*** bengates has joined #openstack-keystone07:29
*** xek has joined #openstack-keystone08:10
*** rcernin has quit IRC08:13
*** threestrands has quit IRC08:20
*** tkajinam has quit IRC08:23
*** kmalloc has joined #openstack-keystone08:45
*** gshippey has joined #openstack-keystone09:58
openstackgerritMerged openstack/oslo.policy master: Bump default tox env from py37 to py38  https://review.opendev.org/72286010:18
openstackgerritMerged openstack/oslo.policy master: Add py38 package metadata  https://review.opendev.org/72272510:18
*** bengates has quit IRC10:43
*** bengates_ has joined #openstack-keystone10:43
*** kmalloc has quit IRC10:54
openstackgerritVishakha Agarwal proposed openstack/keystone master: Update keystone Making an API Change doc  https://review.opendev.org/72058111:06
kklimondacmurphy: (regarding "more friendly error message in the browser") thanks for your comment, would that change (to make keystone return a custom html page instead of json) be something you'll accept upstream? if so, any suggestions on what to take into account (other than Accept header) when implementing that?11:23
*** raildo has joined #openstack-keystone12:09
openstackgerritVishakha Agarwal proposed openstack/keystone master: Update doc id-manage.rst  https://review.opendev.org/72340312:36
*** lbragstad has joined #openstack-keystone12:59
*** spsurya_ has joined #openstack-keystone13:27
*** tkajinam has joined #openstack-keystone13:42
*** irclogbot_0 has joined #openstack-keystone14:08
*** irclogbot_0 has quit IRC14:12
*** irclogbot_3 has joined #openstack-keystone14:22
*** irclogbot_3 has quit IRC14:25
*** irclogbot_1 has joined #openstack-keystone14:26
*** irclogbot_1 has quit IRC14:29
*** irclogbot_1 has joined #openstack-keystone14:30
*** manuvakery has joined #openstack-keystone14:32
*** irclogbot_1 has quit IRC14:35
*** irclogbot_0 has joined #openstack-keystone14:36
*** irclogbot_0 has quit IRC14:39
*** irclogbot_2 has joined #openstack-keystone14:40
*** irclogbot_2 has quit IRC14:45
*** irclogbot_3 has joined #openstack-keystone14:46
*** beekneemech is now known as bnemec14:50
*** irclogbot_3 has quit IRC14:51
*** irclogbot_0 has joined #openstack-keystone14:52
*** tkajinam has quit IRC14:54
*** irclogbot_0 has quit IRC14:55
*** irclogbot_3 has joined #openstack-keystone14:56
*** irclogbot_3 has quit IRC14:59
*** irclogbot_3 has joined #openstack-keystone15:00
*** irclogbot_3 has quit IRC15:03
*** irclogbot_0 has joined #openstack-keystone15:04
*** irclogbot_0 has quit IRC15:07
*** irclogbot_2 has joined #openstack-keystone15:08
*** irclogbot_2 has quit IRC15:11
*** irclogbot_0 has joined #openstack-keystone15:12
*** irclogbot_0 has quit IRC15:15
*** irclogbot_3 has joined #openstack-keystone15:16
*** irclogbot_3 has quit IRC15:19
*** irclogbot_0 has joined #openstack-keystone15:20
*** irclogbot_0 has quit IRC15:23
*** irclogbot_1 has joined #openstack-keystone15:24
*** irclogbot_1 has quit IRC15:27
*** irclogbot_1 has joined #openstack-keystone15:28
*** irclogbot_1 has quit IRC15:31
*** irclogbot_3 has joined #openstack-keystone15:37
cmurphykklimonda: personally i think it would be accepted. i would look at what we do with the SSO callback HTML page https://opendev.org/openstack/keystone/src/branch/master/keystone/api/auth.py#L105 and also this old review which probably should have been accepted a while ago https://review.opendev.org/632213 for inspiration15:40
bnemecSo, this is bad, right? https://github.com/openstack/nova/blob/347d656c35fdf0c309039a7c1f352f82c6950868/nova/policies/base.py#L3615:41
bnemecAdding a scope check right into the rule basically does an end-run around enforce_scope and doesn't allow deployer to turn it off easily.15:41
cmurphywe ended up doing that in keystone because of the reason in the comment, the ideal end state is to have scope_type=system and rule=role:reader but if enforce_scope is false then it just becomes rule=role:reader which would be too permissive15:48
cmurphyif enforce_scope=true then rule:system_scope:all... is a noop15:49
cmurphyit's ugly but it's all we could come up with :(15:50
bnemecApparently it's breaking new Ussuri deployments of Nova. :-/15:50
cmurphyit should be OR'd with the old rule so that should not be happening15:51
bnemecYeah, the deployment in question is also doing the naughty thing of replacing the policy file with defaults in its entirety.15:51
cmurphyyeah that's just not gonna work15:51
bnemecDo you already have a policy PTG session scheduled? Seems like we might need a cross-project sync on this.15:58
bnemecI'm hearing crazy stuff like "YAML policies don't work" and "we need to support people who are generating entire policy files at deploy time."15:58
cmurphynot yet, i'm leaving it to raildo and gmann to set that up15:59
bnemecAh, good. I was just talking to raildo in the oslo meeting. :-)15:59
raildoyeah, trying my best to catch up everything :)16:00
gmannbnemec: +1, adding PTG discussion can be good. you are adding it on oslo etherpad? or should i do on nova ?16:02
cmurphy"yaml policies don't work" yes they do "we want to generate the policy at deploy time" okay fine you can do that you just need to assign your admin user a role on the system scope16:03
*** raildo has quit IRC16:26
*** vesper11 has quit IRC16:26
*** hoonetorg has quit IRC16:26
*** Blinkiz has quit IRC16:26
*** stingrayza has quit IRC16:26
*** bjoernt has quit IRC16:26
*** irclogbot_3 has quit IRC16:28
*** vesper11 has joined #openstack-keystone16:29
*** irclogbot_0 has joined #openstack-keystone16:29
bnemecgmann: I scheduled Oslo for this time slot, so it will be right away on Monday. I think they wanted cross-project discussions early in the week so that might be good.16:30
bnemecAlthough I imagine Nova is going to have a lot of time scheduled so either probably works.16:30
bnemeccmurphy: Oh good, I'm not crazy then.16:30
bnemecWell, at least not about this. ;-016:30
bnemecErr, ;-)16:30
*** hoonetorg has joined #openstack-keystone16:31
*** raildo has joined #openstack-keystone16:31
gmannbnemec: thanks. let me add the link on nova side and i can check with gibi  for cross project.16:31
*** Blinkiz has joined #openstack-keystone16:32
*** stingrayza has joined #openstack-keystone16:32
*** bjoernt has joined #openstack-keystone16:32
bnemecI'll add it to the Oslo etherpad too and we can decide when/where to have the discussion closer to the time.16:33
*** evrardjp has quit IRC16:35
*** ChanServ has quit IRC16:42
*** ChanServ has joined #openstack-keystone16:45
*** tepper.freenode.net sets mode: +o ChanServ16:45
*** evrardjp has joined #openstack-keystone16:46
*** bengates_ has quit IRC16:47
*** spsurya_ has quit IRC16:55
openstackgerritVishakha Agarwal proposed openstack/keystone master: Update caching-layer.rst  https://review.opendev.org/72362417:16
*** Blinkiz has quit IRC17:26
*** stingrayza has quit IRC17:26
*** bjoernt has quit IRC17:26
*** raildo has quit IRC17:26
*** Blinkiz has joined #openstack-keystone17:29
*** stingrayza has joined #openstack-keystone17:29
*** bjoernt has joined #openstack-keystone17:29
*** raildo has joined #openstack-keystone17:29
*** vishalmanchanda has quit IRC17:34
*** ChanServ has quit IRC17:39
*** ChanServ has joined #openstack-keystone17:42
*** tepper.freenode.net sets mode: +o ChanServ17:42
*** manuvakery has quit IRC17:42
openstackgerritVishakha Agarwal proposed openstack/keystone master: Removes info about deleted function should_cache_fn  https://review.opendev.org/72363017:44
*** hoonetorg has quit IRC18:02
*** dmellado has quit IRC18:17
*** dmellado has joined #openstack-keystone18:24
*** dmellado has quit IRC18:25
*** gshippey has quit IRC18:32
*** dmellado has joined #openstack-keystone18:33
*** xek_ has joined #openstack-keystone18:46
*** xek has quit IRC18:49
*** vishakha has quit IRC19:49
*** xek_ has quit IRC20:21
*** rcernin has joined #openstack-keystone21:14
*** raildo has quit IRC21:56
*** dancn has quit IRC22:06
*** dancn has joined #openstack-keystone22:10
*** dancn has quit IRC22:15
*** tkajinam has joined #openstack-keystone22:49
*** tkajinam has quit IRC22:49
*** tkajinam has joined #openstack-keystone22:50
*** lbragstad has quit IRC22:56

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!