Thursday, 2023-01-05

*** tkajinam is now known as Guest29904:46
opendevreviewHervĂ© Beraud proposed openstack/oslo.limit master: Get ready for tox 4  https://review.opendev.org/c/openstack/oslo.limit/+/86934210:31
*** dviroel|ourt is now known as dviroel11:45
*** dasm|off is now known as dasm13:50
spatelHello Folk! 14:30
spatelWhat is the difference between shared keystone Vs Keystone federation? 14:31
*** dviroel is now known as dviroel|lunch16:01
d34dh0r53spatel: I'm not directly familiar with the term shared keystone, but I believe that you may be referring to Keystone-to-Keystone federation in which keystone acts as both the SP and IdP (https://docs.openstack.org/keystone/latest/admin/federation/introduction.html#keystone-to-keystone).  Federation is using keystone as the SP and federating authentication to an external17:07
d34dh0r53IdP via either OIDC (https://docs.openstack.org/keystone/latest/admin/federation/introduction.html#openid-connect-authentication-flow) or SAML (https://docs.openstack.org/keystone/latest/admin/federation/introduction.html#id2)17:07
d34dh0r53does that answer your question?17:07
spatelThanks!! when i said shared keystone means cloud1 and cloud2 both using same keystone instances. 17:08
d34dh0r53ahh, ok17:09
spatelI am looking for solution where building two region (east and west) so how do i consolidate users/pass/auth etc.. 17:09
*** dviroel|lunch is now known as dviroel17:10
spatelI would like to have single Horizon or any dashboard to select region instead of maintain two keystone. 17:10
d34dh0r53hmm, I would look at federated authentication or ldap backed keystone17:11
spatelHmm! that is what i am thinking. 17:11
spatelcurrently we have LDAP (freeIPA for keyston) but doesn't have option to select region east / west in horizon etc. 17:12
spatelTrying to understand how does public cloud company use openstack keystone for their solution17:12
d34dh0r53perhaps using a realm per region on something like keycloak backed by freeipa and then specifying each region (realm) as a different domain in keystone/horizon17:21
spatelhmm17:42
*** dviroel is now known as dviroel|afk21:19
*** dasm is now known as dasm|off22:33

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!