Thursday, 2020-05-07

*** vishalmanchanda has quit IRC00:18
*** jamesmcarthur has joined #openstack-keystone00:43
*** jamesmcarthur has quit IRC01:10
*** jamesmcarthur has joined #openstack-keystone01:12
*** spatel has joined #openstack-keystone01:27
*** jamesmcarthur has quit IRC01:36
*** jamesmcarthur has joined #openstack-keystone01:48
*** jamesmcarthur has quit IRC01:48
*** jamesmcarthur has joined #openstack-keystone01:49
*** lbragstad has quit IRC01:52
*** jamesmcarthur has quit IRC01:53
*** jamesmcarthur has joined #openstack-keystone02:10
*** jamesmcarthur has quit IRC02:20
*** spatel has quit IRC02:31
*** jamesmcarthur has joined #openstack-keystone02:33
*** spatel has joined #openstack-keystone02:34
*** spatel has quit IRC02:48
*** jamesmcarthur has quit IRC03:37
*** renich has quit IRC03:38
*** jamesmcarthur has joined #openstack-keystone03:40
*** evrardjp has quit IRC04:36
*** evrardjp has joined #openstack-keystone04:36
openstackgerritMerged openstack/keystone master: Ensure OAuth1 authorized roles are respected  https://review.opendev.org/72588504:37
*** sapd1 has joined #openstack-keystone04:51
*** vishalmanchanda has joined #openstack-keystone05:45
*** jamesmcarthur has quit IRC05:53
*** abdysn has joined #openstack-keystone05:56
*** jamesmcarthur has joined #openstack-keystone05:59
*** jamesmcarthur has quit IRC06:03
*** gyee has quit IRC06:07
*** jamesmcarthur has joined #openstack-keystone06:10
*** jamesmcarthur has quit IRC06:27
*** bengates has joined #openstack-keystone07:19
*** dancn has joined #openstack-keystone07:23
*** TheJulia has quit IRC07:56
*** mnasiadka has quit IRC07:56
*** Anticimex has quit IRC07:56
*** TheJulia has joined #openstack-keystone08:01
*** mnasiadka has joined #openstack-keystone08:01
*** Anticimex has joined #openstack-keystone08:01
*** xek has joined #openstack-keystone08:05
*** vishakha has joined #openstack-keystone08:06
*** lumir_ is now known as shaolin09:21
*** shaolin is now known as lumir09:21
*** irclogbot_1 has quit IRC09:41
*** irclogbot_3 has joined #openstack-keystone09:42
*** hugokuo has quit IRC09:42
*** hugokuo has joined #openstack-keystone09:45
zigoCould we get the security patches +2+w ASAP please ? https://review.opendev.org/#/q/project:openstack/keystone10:29
*** ayoung has quit IRC10:49
*** abdysn has quit IRC12:16
*** raildo has joined #openstack-keystone12:25
*** spatel has joined #openstack-keystone12:58
*** lbragstad has joined #openstack-keystone13:12
*** manuvakery has joined #openstack-keystone13:15
*** jhesketh has quit IRC13:43
*** jhesketh has joined #openstack-keystone13:47
knikollalbragstad: could you please review the stable backports of the sec fixes? ^13:52
lbragstadknikolla looks like they were squashed into a single commit13:54
lbragstadfor backport reasons13:54
knikollayup13:54
lbragstadcool13:54
knikollathe number of reviews and merge conflicts would be over 9000 otherwise13:55
lbragstadmakes sense13:55
lbragstadhttps://review.opendev.org/#/c/725887/1 wasn't included though?13:55
*** ayoung has joined #openstack-keystone13:56
knikollai guess that's because the others are ec2 bugs, and this is auth1, so it made sense to squash those together while keeping this separate13:57
knikollaoauth1*13:57
*** dancn has quit IRC13:58
lbragstadok14:01
*** dancn has joined #openstack-keystone14:03
*** renich has joined #openstack-keystone14:33
cmurphyyeah the oauth1 fix didn't collide with the ec2 fixes so i kept it separate14:34
*** tkajinam has quit IRC14:43
*** dancn has quit IRC14:52
*** vishalmanchanda has quit IRC14:54
lbragstadcmurphy ++14:54
openstackgerritMaurice Escher proposed openstack/keystone master: fix link in release note of bug/1794527  https://review.opendev.org/72617014:55
*** dancn has joined #openstack-keystone14:58
*** renich has quit IRC15:17
*** dancn has quit IRC15:24
*** gyee has joined #openstack-keystone15:32
*** jamesmcarthur has joined #openstack-keystone15:32
gagehugowe generally don't modify release notes from previous releases right?15:37
cmurphyyou can you just need to do it directly in the stable branch https://docs.openstack.org/reno/latest/user/usage.html#updating-stable-branch-release-notes15:41
*** dancn has joined #openstack-keystone15:42
*** spatel has quit IRC15:49
*** spatel has joined #openstack-keystone15:50
*** renich has joined #openstack-keystone16:07
gagehugohmm ok16:34
*** evrardjp has quit IRC16:36
*** evrardjp has joined #openstack-keystone16:36
*** bengates has quit IRC16:45
*** dancn has quit IRC16:54
*** gmann is now known as gmann_afk17:25
*** dancn has joined #openstack-keystone17:43
*** jamesmcarthur has quit IRC17:53
*** jamesmcarthur has joined #openstack-keystone17:59
*** jamesmcarthur has quit IRC18:03
TheJuliaHi, crazy off the wall question. Has there ever been any thoughts or discussion of adding basic auth support to keystoneauth1 since things like openstackclient are so tightly bound to it?18:12
*** ayoung has quit IRC18:13
*** ayoung has joined #openstack-keystone18:16
cmurphyTheJulia: not to keystoneauth, because keystoneauth is only for authing with keystone and keystone doesn't support basic auth. but adding it to keystone has come up before https://review.opendev.org/12545718:20
TheJuliaokay18:21
TheJuliaso tl;dr... keystone is an absolute hard requirement for any auth with any openstack tooling... which explains why noauth has remained dominant18:23
cmurphyTheJulia: no, i would not say that at all18:24
cmurphykeystoneauth is for working with keystone18:24
cmurphyyou don't have to use keystoneauth18:25
TheJuliaI'm still digging into the code path18:26
TheJuliabut if everything is using keystoneauth1 for session tooling18:26
TheJuliafor the actual http client..18:26
TheJuliaAnyway, there are at least 2-3 more layers to the onion to peel back18:26
cmurphyi don't think it's occurred to most projects to support non-keystone auth18:27
cmurphymordred: maybe you want to jump in ^ would we want keystoneauth to support basic auth similar to how it does noauth?18:28
mordredI didn't do it18:31
TheJulialol18:31
* mordred reads18:31
* TheJulia checks off todo item "blame everything on mordred"18:32
mordredyeah. definitely blame it on me18:32
mordredit's an interesting question ... if we didn't have keystoneauth support it, we'd need to support it in sdk - it would be _way_ easier to support it in ksa like noauth is ... because sdk and osc basically do just act as ksa-session/adapter factories18:33
mordredthat said - I could also understand if we didn't want to add that to ksa and if we didn't I think we could figure out how to add it to sdk18:33
mordredTheJulia: tl;dr - I think supporting your auth needs is in scope from an sdk pov - I'm on the fence as to whether ksa should be the place to do it - I could be talked in to being for it or against it by someone with a stronger opinion18:34
cmurphyi feel like most of what you get from keystoneauth is all the bits you need to authenticate with keystone, if you're not using that then you might as well just use a regular requests session and keep it simple18:35
mordredcmurphy: oh - well, also we get the ksa adapter which does a funny mounting thing that nothing else does18:36
mordredbut - yeah18:36
cmurphyah yeah18:36
mordredcmurphy, TheJulia: we _could_ just make a ksa auth plugin in openstacksdk18:36
TheJulianah, nothing to blame on you18:36
mordredso that it's still a ksa auth for our use but the code is managed in sdk18:37
mordredand we could model it on the noauth plugin - maybe even subclass it18:37
*** spatel has quit IRC18:39
TheJuliaOkay, that kind of makes sense18:39
*** jamesmcarthur has joined #openstack-keystone18:39
*** ayoung has quit IRC18:39
TheJuliaand I guess, worst comes to worst until braincells to hack on ^ are beamed in with a transporter (or maybe a very big cup of coffee... or ten), humans can always use curl18:40
TheJuliajust not super friendly18:40
*** ayoung has joined #openstack-keystone18:40
cmurphyi'm not entirely opposed to adding it to ksa either, especially since noauth is kind of a precedent, i just worry a little about scope creep and putting all of the auth kitchen sink into ksa18:43
TheJuliaThat does make sense. I guess part of the question may be how much interest there could be in such. Specifically because I have this feeling the mechanics may need to be different :\18:48
*** gmann_afk is now known as gmann19:06
mordredTheJulia, cmurphy: we could trial-run it in sdk (where there's a little less worry about scope-creep) and if it works out and we're happy we can move it over19:10
TheJulialooks like it could be a plugin and would actually be very simple from what I can tell19:23
TheJuliajust... where because I don't think keystoneauth1 has any concept of external "plugins"19:24
TheJuliawait19:25
TheJuliait does19:25
*** jamesmcarthur_ has joined #openstack-keystone19:58
*** jamesmcarthur_ has quit IRC19:59
*** jamesmcarthur_ has joined #openstack-keystone19:59
*** jamesmcarthur has quit IRC20:00
*** dancn has quit IRC20:51
*** manuvakery has quit IRC21:02
*** vishakha has quit IRC21:14
*** hemna has quit IRC21:26
*** hemna has joined #openstack-keystone21:39
*** raildo has quit IRC21:45
*** renich has quit IRC21:55
*** xek has quit IRC22:04
*** jamesmcarthur_ has quit IRC22:13
*** jamesmcarthur has joined #openstack-keystone22:13
*** renich has joined #openstack-keystone22:15
*** jamesmcarthur has quit IRC22:19
*** jamesmcarthur has joined #openstack-keystone22:33
*** hoonetorg has quit IRC22:34
*** jamesmcarthur has quit IRC22:37
*** jamesmcarthur has joined #openstack-keystone22:38
*** jamesmcarthur has quit IRC22:42
*** hoonetorg has joined #openstack-keystone22:46
*** tkajinam has joined #openstack-keystone22:49
*** jamesmcarthur has joined #openstack-keystone23:01
*** renich has quit IRC23:02
*** renich has joined #openstack-keystone23:02
*** jamesmcarthur has quit IRC23:04
*** jamesmcarthur has joined #openstack-keystone23:05
*** jamesmcarthur has quit IRC23:11
*** jamesmcarthur has joined #openstack-keystone23:11
*** spotz has quit IRC23:16
*** jamesmcarthur has quit IRC23:38
*** jamesmcarthur has joined #openstack-keystone23:38
*** gyee has quit IRC23:54

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!