Thursday, 2020-04-16

*** brinzhang has joined #openstack-glance00:13
*** Liang__ has joined #openstack-glance01:09
*** brinzhang_ has joined #openstack-glance02:04
*** brinzhang has quit IRC02:08
*** brinzhang has joined #openstack-glance02:08
*** brinzhang_ has quit IRC02:09
*** lifeless_ is now known as liffeless02:40
*** liffeless is now known as lifeless02:40
*** threestrands has joined #openstack-glance03:29
*** gyee has quit IRC04:02
*** evrardjp has quit IRC04:37
*** evrardjp has joined #openstack-glance04:37
*** udesale has joined #openstack-glance04:43
*** ratailor has joined #openstack-glance05:00
*** ratailor has quit IRC05:01
*** ratailor has joined #openstack-glance05:06
*** happyhemant has joined #openstack-glance08:14
*** threestrands has quit IRC08:45
*** tkajinam has quit IRC08:50
openstackgerritOpenStack Proposal Bot proposed openstack/glance master: Imported Translations from Zanata  https://review.opendev.org/71915509:17
*** Liang__ has quit IRC09:42
*** smcginnis has quit IRC09:52
*** lpetrut has joined #openstack-glance09:56
*** mgoddard has joined #openstack-glance10:06
mgoddardHi, is anyone around?10:06
mgoddardI have a question about TLS termination10:06
mgoddardhi abhishekk, around?10:10
abhishekkmgoddard, in a meeting10:10
mgoddardabhishekk: np10:10
abhishekkwill be free in an hour10:10
mgoddardhi abhishekk11:35
*** ratailor has quit IRC11:50
*** nikparasyr has joined #openstack-glance11:52
*** smcginnis has joined #openstack-glance12:01
*** udesale_ has joined #openstack-glance12:31
*** udesale has quit IRC12:34
jokke_mgoddard: still here, what's up?13:29
mgoddardhi jokke_13:29
mgoddardI saw that TLS termination is no longer supported by glance13:30
mgoddardwe're just looking at adding TLS termination for backend servers in kolla-ansible13:30
mgoddardnormally we do this using httpd, but glance docs recommend against this13:31
mgoddardso we tried using key_file/cert_file then found they had been removed13:31
mgoddardis there a recommended way to achieve this?13:31
jokke_mgoddard: yeah, that's related to how reverse proxying in apache works. That will dump the whole image to /tmp/ before sending the request to glance upon upload. Use for example HAProxy for terminating the ssl/tls it's good behaving, is well tested and fairly lightweight (well specially vs. httpd)13:33
jokke_other approach is to use for example stunnel if you want to have the connection between your load balancer and glance being encrypted ... same applies what comes to behavior, usage and overhead13:34
jokke_My personal preferred operating mode is having HAProxy as loadbalancer terminating external and stunnel between HAProxy and glance-api13:36
jokke_but HAProxy - HAProxy - glance-api is perfectly fine as well13:37
mgoddardwe use haproxy as a load balancer. stunnel seems like a reasonable solution13:38
mgoddardthanks for the info jokke_13:38
jokke_yeah, it's super light, it's been stable and well behaving for years and doesn't try to do anything fancy <313:39
jokke_NP!13:39
abhishekkmgoddard, sorry was busy in other stuff13:49
mgoddardabhishekk: no problem, jokke_ answered my question13:49
abhishekkmgoddard, cool,13:49
abhishekkjokke_, rosmaita smcginnis weekly meeting in 3 minutes at #openstack-meeting13:58
*** jdillaman has joined #openstack-glance14:22
*** lpetrut has quit IRC14:34
*** gyee has joined #openstack-glance14:42
*** happyhemant has quit IRC15:14
*** mgoddard has left #openstack-glance16:15
*** udesale_ has quit IRC16:35
*** evrardjp has quit IRC16:37
*** evrardjp has joined #openstack-glance16:37
*** nikparasyr has quit IRC16:42
*** servagem has joined #openstack-glance17:23
*** rcernin has quit IRC17:37
*** servagem has quit IRC20:35
*** rcernin has joined #openstack-glance22:39
*** tkajinam has joined #openstack-glance22:39
*** threestrands has joined #openstack-glance23:14
*** threestrands has quit IRC23:15
*** threestrands has joined #openstack-glance23:15
*** rosmaita has quit IRC23:43
*** rosmaita has joined #openstack-glance23:56

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!