Wednesday, 2022-06-01

opendevreviewAlexandre arents proposed openstack/keystone master: Federation: add support for projects_json assertion  https://review.opendev.org/c/openstack/keystone/+/84409806:16
*** whoami-rajat__ is now known as whoami-rajat07:35
opendevreviewAlexandre arents proposed openstack/keystone master: Federation: add support for projects_json assertion  https://review.opendev.org/c/openstack/keystone/+/84409808:09
opendevreviewTakashi Kajinami proposed openstack/keystonemiddleware master: setup.cfg: Replace dashes by underscores  https://review.opendev.org/c/openstack/keystonemiddleware/+/82799411:18
*** dviroel|afk is now known as dviroel12:21
*** dviroel_ is now known as dviroel13:15
*** dviroel is now known as dviroel|lunch15:08
*** dviroel|lunch is now known as dviroel16:20
pas-ha[m]hi all,  I have a question about app creds - are they supported for federated users? I map a user to a group that has roles on a project. I can see the user created in the appropriate domain, but I do not see any roles for this user via `openstack role assignment list --user` and this user can not create app creds - keystone fails with smth like "no roles found for user or group <uuid> on project,domain or system <uuid>"...17:28
pas-ha[m]running OpenStack Victoria17:29
pas-ha[m]I also do not see the user in the group when I run `openstack group contains ...`17:29
pas-ha[m]at the same time when I do `openstack token issue --debug` I can see a normal response with roles inside17:36
pas-ha[m]and I can get a token alright or login to Horizon17:36
gmanndmendiza[m]: knikolla[m] need review in this keystone-temepst-plugin stable jobs patch https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/83807018:14
*** timburke_ is now known as timburke20:59
*** dviroel is now known as dviroel|out21:34

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!