Friday, 2020-07-17

*** vishakha has quit IRC00:02
*** xek_ has quit IRC00:32
*** gyee has quit IRC00:33
*** rcernin has quit IRC00:34
*** rcernin has joined #openstack-keystone00:39
*** markvoelker has joined #openstack-keystone02:13
*** markvoelker has quit IRC02:18
*** also_stingrayza has joined #openstack-keystone03:06
*** stingrayza has quit IRC03:09
*** markvoelker has joined #openstack-keystone03:48
*** markvoelker has quit IRC03:53
*** vishalmanchanda has joined #openstack-keystone04:01
*** diurnalist has quit IRC04:23
*** rcernin has quit IRC04:47
*** rcernin has joined #openstack-keystone04:57
*** rcernin has quit IRC05:12
*** rcernin has joined #openstack-keystone05:20
*** shyamb has joined #openstack-keystone05:29
*** shyamb has quit IRC05:45
*** markvoelker has joined #openstack-keystone05:49
*** shyamb has joined #openstack-keystone05:53
*** markvoelker has quit IRC05:54
*** shyam89 has joined #openstack-keystone06:03
sri_lbragstad: ack,06:05
*** shyamb has quit IRC06:06
*** rcernin has quit IRC06:19
*** rcernin has joined #openstack-keystone06:32
*** rcernin has quit IRC06:46
*** diurnalist has joined #openstack-keystone06:47
*** diurnalist has quit IRC06:51
*** rcernin has joined #openstack-keystone06:53
*** rcernin has quit IRC07:06
*** bengates has joined #openstack-keystone07:10
*** shyam89 has quit IRC07:17
*** rcernin has joined #openstack-keystone07:34
*** rcernin has quit IRC07:42
*** rcernin has joined #openstack-keystone07:46
*** rcernin has quit IRC07:50
*** diurnalist has joined #openstack-keystone07:58
*** diurnalist has quit IRC08:03
*** also_stingrayza is now known as stingrayza08:08
*** carthaca has joined #openstack-keystone08:12
*** shyamb has joined #openstack-keystone08:24
*** shyam89 has joined #openstack-keystone08:36
*** shyamb has quit IRC08:39
*** spatel has joined #openstack-keystone08:49
*** xek_ has joined #openstack-keystone08:51
*** spatel has quit IRC08:53
*** diurnalist has joined #openstack-keystone09:10
*** diurnalist has quit IRC09:14
*** shyamb has joined #openstack-keystone09:24
*** shyam89 has quit IRC09:25
*** rcernin has joined #openstack-keystone09:29
*** shyam89 has joined #openstack-keystone09:41
*** shyamb has quit IRC09:44
*** rcernin has quit IRC09:48
*** tkajinam has quit IRC09:52
*** shyamb has joined #openstack-keystone09:56
*** shyam89 has quit IRC10:00
*** shyamb has quit IRC10:12
*** shyamb has joined #openstack-keystone10:32
*** shyamb has quit IRC10:47
*** shyamb has joined #openstack-keystone11:20
*** raildo has joined #openstack-keystone11:41
*** diurnalist has joined #openstack-keystone11:45
*** xek_ has quit IRC11:50
*** diurnalist has quit IRC11:50
*** vishakha has joined #openstack-keystone12:11
*** shyamb has quit IRC12:13
vishakhaknikolla cmurphy I wanted to have your opinions on the bug #link https://bugs.launchpad.net/keystone/+bug/1862802. Is it feasible to raise exception when no domain_id is being passed while created user or any other entity?12:13
openstackLaunchpad bug 1862802 in OpenStack Identity (keystone) "Avoid the default domain usage when the Domain is not specified in the project creation" [Wishlist,Triaged] - Assigned to Vishakha Agarwal (vishakha.agarwal)12:13
*** spatel has joined #openstack-keystone12:50
*** spatel has quit IRC12:55
*** diurnalist has joined #openstack-keystone12:57
*** diurnalist has quit IRC13:01
*** xek_ has joined #openstack-keystone14:01
*** bengates has quit IRC14:02
*** bengates has joined #openstack-keystone14:04
*** diurnalist has joined #openstack-keystone14:08
*** bengates has quit IRC14:08
*** diurnalist has quit IRC14:13
sri_vishakha: hi, quick question,  when i enabled the "enforce_scope = True"  flag, domain admin is not able to assign a roles to users with in the domain, is the expected behavior  ?14:13
vishakhasri_: Domain admins should be able to assign roles to user in the same domain.14:21
sri_vishakha: when i try to assign role I am getting "You are not authorized to find role with the name 'admin'." http://paste.openstack.org/show/796049/14:25
sri_vishakha: it looks like i am missing something14:25
vishakhasri_: Are you able to list roe assignments for domain $ openstack role assignment list --names --domain <domain-name> ?14:31
vishakharole*14:32
sri_vishakha: I can list the roles from system account, not from domain admin account14:34
sri_https://www.irccloud.com/pastebin/8wYFfTbT/14:34
vishakhaDomain admin doesnt have the power to list roles in the whole system but it should be able to list role assignments in the domain over which the user is admin.14:36
vishakhasri_: ^^14:36
*** diurnalist has joined #openstack-keystone14:37
sri_vishakha:  yes your right, but i am not able to list the roles in the domain also, http://paste.openstack.org/show/796051/14:39
*** xek_ has quit IRC14:41
vishakhasri_: After sourcing keystonerc_user1 could you share the env variables?14:43
sri_vishakha: http://paste.openstack.org/show/796052/14:46
*** bengates has joined #openstack-keystone14:53
*** bengates has quit IRC14:54
*** bengates has joined #openstack-keystone14:54
vishakhasri_: I am not sure what is missing here.  All is looking good to me15:09
*** bnemec is now known as beekneemech15:10
vishakhalbragstad ^^ need some help here15:10
lbragstadsri_ how are you creating the grant?15:13
lbragstador the role assignment?15:13
*** bengates has quit IRC15:14
sri_https://www.irccloud.com/pastebin/VaQld2Qf/15:14
sri_lbragstad: something like this ^^15:15
lbragstadtrying something quick, one sec15:15
*** bengates has joined #openstack-keystone15:15
*** bengates_ has joined #openstack-keystone15:16
*** bengates_ has quit IRC15:17
*** bengates_ has joined #openstack-keystone15:17
*** bengates has quit IRC15:19
lbragstadsri_ yeah - it works15:25
*** gyee has joined #openstack-keystone15:26
lbragstadi think the issue you're hitting is because python-openstackclient will attempt to list resources to figure out if you're giving it an ID or a name15:26
lbragstadand domain admins aren't allowed to list all resources in a deployment (like roles)15:26
sri_lbragstad: I see, is it work workaround to fix the that issue ?15:28
lbragstadsri_ if you make the request to keystone directly, it will work15:29
lbragstadi'm working on a paste15:29
sri_lbragstad:  Ok, thanks :)15:29
lbragstadsri_ http://paste.openstack.org/show/796056/15:35
lbragstadsri_ here is what i used for clouds.yaml http://paste.openstack.org/show/796057/15:36
lbragstadthis is the API i invoked manually - https://docs.openstack.org/api-ref/identity/v3/index.html?expanded=assign-role-to-user-on-project-detail#assign-role-to-user-on-project15:38
sri_lbragstad: got it, we have talking  keystone api,  nice, do you want me file a  bug report ?15:38
lbragstadsri_ if you do - i would make it against python-openstackclient since there isn't really anything to do in keystone15:38
lbragstadhttps://storyboard.openstack.org/#!/project/openstack/python-openstackclient15:39
lbragstad^ in case you need the link15:39
lbragstadi'm checking to see if there is already a story open for this15:40
sri_lbragstad: sure,  how to i found out  which projects are currently working with  ""enforce_scope = True"" this policy's15:41
sri_lbragstad: testing one by one ? :)15:41
lbragstadsri_ there is a popup team focused on implementing this across projects - https://governance.openstack.org/tc/reference/popup-teams.html#secure-default-policies15:41
lbragstadthey're probably the best folks to ask about progress across openstack15:42
lbragstadto date, nova and keystone have implemented scope checks15:42
lbragstadother projects are in different phases of adopting that work, though15:42
sri_lbragstad: understood, thank you :)15:43
sri_vishakha: thank you15:44
lbragstadsri_ no problem - good luck15:45
lbragstadhttps://wiki.openstack.org/wiki/Consistent_and_Secure_Default_Policies_Popup_Team has more information15:46
sri_lbragstad: 👍15:48
cmurphyvishakha: note the part of the description "Since we can't change the current behavior of V3, because it will be api-breaking. We need to fix it in the Keystone microversion." and the tag "fix-requires-microversion" and the priority "wishlist" we're using the bug to document the behavior for now but we can't fix it unless we have a v4 API or microversions16:08
*** kklimonda has quit IRC16:20
*** kklimonda has joined #openstack-keystone16:21
*** bengates_ has quit IRC16:24
*** markvoelker has joined #openstack-keystone16:59
*** vishalmanchanda has quit IRC17:20
*** TheJulia has quit IRC18:22
*** TheJulia has joined #openstack-keystone18:23
*** johnsom has quit IRC18:24
*** johnsom has joined #openstack-keystone18:25
*** kmalloc has quit IRC18:53
*** kmalloc has joined #openstack-keystone18:53
*** masayukig has quit IRC18:58
*** masayukig has joined #openstack-keystone18:59
*** jamespage has quit IRC19:24
*** jamespage has joined #openstack-keystone19:25
openstackgerritBen Nemec proposed openstack/oslo.limit master: Move keystoneauth options to oslo_limit_keystoneauth  https://review.opendev.org/73388119:27
*** johnthetubaguy has quit IRC19:56
*** johnthetubaguy has joined #openstack-keystone19:58
*** hemna has quit IRC19:59
*** hemna has joined #openstack-keystone19:59
*** johnthetubaguy has quit IRC20:05
*** johnthetubaguy has joined #openstack-keystone20:08
*** johnthetubaguy has quit IRC20:14
*** johnthetubaguy has joined #openstack-keystone20:17
*** johnthetubaguy has quit IRC20:32
*** sapd1_x has quit IRC20:32
*** sapd1_x has joined #openstack-keystone20:33
*** spatel has joined #openstack-keystone20:34
*** markvoelker has quit IRC20:42
*** vishakha has quit IRC20:48
*** raildo has quit IRC21:11
*** gyee has quit IRC21:40
*** gyee has joined #openstack-keystone21:45
*** also_stingrayza has joined #openstack-keystone21:49
*** melwitt is now known as jgwentworth21:49
*** stingrayza has quit IRC21:52
*** lbragstad has quit IRC21:56
*** lbragstad has joined #openstack-keystone21:56
*** markvoelker has joined #openstack-keystone22:22
*** markvoelker has quit IRC22:27
*** markvoelker has joined #openstack-keystone22:47
*** markvoelker has quit IRC22:52
*** gyee has quit IRC23:01
openstackgerritJason Anderson proposed openstack/keystone master: Support for deprovisioning federated assignments  https://review.opendev.org/74178523:08
*** diurnalist has quit IRC23:16
*** diurnalist has joined #openstack-keystone23:29
*** diurnalist has quit IRC23:38

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!