Monday, 2020-11-30

*** zzzeek has quit IRC00:00
*** zzzeek has joined #openstack-glance00:04
*** zzzeek has quit IRC00:08
*** zzzeek has joined #openstack-glance00:11
*** ratailor has joined #openstack-glance03:52
*** zzzeek has quit IRC05:02
*** zzzeek has joined #openstack-glance05:04
*** udesale has joined #openstack-glance05:32
*** evrardjp has quit IRC05:33
*** evrardjp has joined #openstack-glance05:33
*** udesale_ has joined #openstack-glance05:34
*** udesale has quit IRC05:36
*** zzzeek has quit IRC05:39
*** zzzeek has joined #openstack-glance05:42
*** m75abrams has joined #openstack-glance06:35
*** ratailor has quit IRC06:43
*** zzzeek has quit IRC06:45
*** nikparasyr has joined #openstack-glance06:46
*** zzzeek has joined #openstack-glance06:47
*** belmoreira has joined #openstack-glance07:01
*** zzzeek has quit IRC07:06
*** zzzeek has joined #openstack-glance07:06
*** ralonsoh has joined #openstack-glance07:06
*** whoami-rajat__ has joined #openstack-glance07:21
*** zzzeek has quit IRC07:27
*** zzzeek has joined #openstack-glance07:28
*** zzzeek has quit IRC07:37
*** zzzeek has joined #openstack-glance07:40
*** udesale_ has quit IRC07:59
*** zzzeek has quit IRC08:13
*** ajitha has joined #openstack-glance08:15
*** zzzeek has joined #openstack-glance08:15
*** udesale_ has joined #openstack-glance08:19
*** udesale_ has quit IRC08:48
*** ratailor has joined #openstack-glance08:58
*** k_mouza has joined #openstack-glance09:25
*** k_mouza has quit IRC09:30
*** k_mouza has joined #openstack-glance09:34
*** udesale_ has joined #openstack-glance09:36
*** zzzeek has quit IRC09:37
*** zzzeek has joined #openstack-glance09:40
*** udesale_ has quit IRC10:00
*** baojg has joined #openstack-glance10:47
*** udesale_ has joined #openstack-glance10:49
*** k_mouza has quit IRC11:10
*** k_mouza has joined #openstack-glance11:22
*** udesale_ has quit IRC11:27
*** ratailor has quit IRC12:09
*** ratailor has joined #openstack-glance12:09
*** Luzi has joined #openstack-glance12:37
*** zzzeek has quit IRC12:44
*** zzzeek has joined #openstack-glance12:44
*** zzzeek has quit IRC12:49
*** zzzeek has joined #openstack-glance12:50
*** zzzeek has quit IRC12:59
*** zzzeek has joined #openstack-glance13:02
*** zzzeek has quit IRC13:06
*** zzzeek has joined #openstack-glance13:08
*** zzzeek has quit IRC13:12
*** zzzeek has joined #openstack-glance13:14
*** Luzi has quit IRC13:32
*** lbragstad has quit IRC13:39
*** lbragstad has joined #openstack-glance13:47
openstackgerritAbhishek Kekane proposed openstack/glance master: PoC Implement secure RBAC for image actions  https://review.opendev.org/c/openstack/glance/+/76475413:54
*** rosmaita has joined #openstack-glance13:54
*** zzzeek has quit IRC13:56
*** zzzeek has joined #openstack-glance13:58
*** ratailor has quit IRC14:00
*** jv has joined #openstack-glance14:17
*** takamatsu has joined #openstack-glance15:14
lbragstadabhishekk i'm not sure if you've seen the changes i've proposed, yet15:30
lbragstadabhishekk but let me know if you have any questions or need to walk through anything15:30
abhishekklbragstad, I have commented on the base patch15:30
abhishekkI didn't understood role:all and system_scope:all15:32
lbragstadabhishekk yes - you're right15:32
lbragstadi'll fix that15:32
abhishekkack, then I will rebase my patch on top of yours15:32
abhishekkfor task and images15:32
abhishekklbragstad, when will be next open hours or meeting with glance squad?15:36
lbragstadabhishekk the next office hours is tomorrow at 18 UTC15:38
lbragstadsorry - thursday i think15:38
abhishekkI will be around if it is on Thursday, will try if it is tomorrow15:39
*** m75abrams has quit IRC16:02
*** nikparasyr has left #openstack-glance16:07
*** zzzeek has quit IRC16:11
*** zzzeek has joined #openstack-glance16:14
ade_leeabhishekk, hey -- any idea who else we can ask to review https://review.opendev.org/c/openstack/glance/+/756158 and https://review.opendev.org/c/openstack/glance_store/+/756157 ?16:19
-openstackstatus- NOTICE: The Gerrit service on review.opendev.org is being restarted quickly to troubleshoot high load and poor query caching performance, downtime should be less than 5 minutes16:20
abhishekkade_lee rosmaita or smcginnis16:48
rosmaitaade_lee: is that md5 stuff?16:48
ade_leerosmaita, yup16:48
rosmaitaok, count on me to take a look16:49
ade_leerosmaita, great thanks!16:49
smcginnisWill try to take a look shortly as well.16:57
ade_leesmcginnis, thanks!16:57
rosmaitaade_lee: is the idea that glance_store is just computing and recording a value, so the hash is not being "used in a security context"?  But if an image consumer computed the hash themselves and then compared it to the recorded value, the image consumer would be using the hash in a security context?17:14
rosmaitawhat I'm asking about is the "False" here: https://review.opendev.org/c/openstack/glance_store/+/756157/3/glance_store/_drivers/cinder.py#83217:15
*** baojg has quit IRC17:21
*** k_mouza has quit IRC18:07
*** mloza has joined #openstack-glance18:14
mlozahello, is there a way to only allow RAW images being uploaded via CLI?18:15
*** belmoreira has quit IRC18:22
*** k_mouza has joined #openstack-glance18:26
*** k_mouza has quit IRC18:27
*** gyee has joined #openstack-glance18:28
*** k_mouza has joined #openstack-glance18:41
rosmaitamloza: are you OK with the API only allowing RAW images to be uploaded?18:42
openstackgerritMerged openstack/glance_store master: Replace md5 with oslo version  https://review.opendev.org/c/openstack/glance_store/+/75615718:43
*** k_mouza has quit IRC18:45
*** k_mouza has joined #openstack-glance19:08
mlozarosmaita: yes19:18
mlozaI don't want tenants to upload qcow2 images19:18
mlozaso I would like to restrict to RAW images only19:19
rosmaitamloza: there are config opts for disk_formats and container_formats in glance-api.conf19:20
rosmaitawhatever you have there is used in the glance image schema19:20
rosmaitaso users can only create images with those formats19:20
rosmaitabut19:20
rosmaitaglance doesn't validate what's actually uploaded19:21
rosmaitait only controls what users can say the formats are19:21
*** hoonetorg has quit IRC19:25
*** hoonetorg has joined #openstack-glance19:26
*** k_mouza has quit IRC19:37
*** rosmaita has quit IRC19:45
*** rosmaita has joined #openstack-glance19:46
*** k_mouza has joined #openstack-glance20:11
*** ralonsoh has quit IRC20:36
*** k_mouza has quit IRC20:39
*** k_mouza has joined #openstack-glance20:46
*** k_mouza has quit IRC20:48
*** k_mouza has joined #openstack-glance20:48
*** k_mouza has quit IRC20:59
*** k_mouza has joined #openstack-glance21:00
*** vesper11 has quit IRC21:01
*** zzzeek has quit IRC21:08
*** whoami-rajat__ has quit IRC21:08
*** zzzeek has joined #openstack-glance21:12
*** k_mouza has quit IRC21:20
lbragstadgmann ping21:30
lbragstadgmann i noticed you need oslo.policy 3.6.0 and i'm updating that dependency in another patch21:35
lbragstadwould you be opposed to putting your patch on https://review.opendev.org/c/openstack/glance/+/764236/2 if i update it to include 3.6.0?21:35
openstackgerritLance Bragstad proposed openstack/glance master: Bump requirements to perpare for secure RBAC  https://review.opendev.org/c/openstack/glance/+/76423621:49
openstackgerritLance Bragstad proposed openstack/glance master: Add basic/common personas to base policies  https://review.opendev.org/c/openstack/glance/+/76424121:49
openstackgerritLance Bragstad proposed openstack/glance master: Implement secure RBAC for image tags  https://review.opendev.org/c/openstack/glance/+/76424221:49
openstackgerritLance Bragstad proposed openstack/glance master: Implement secure RBAC for metadef namespaces  https://review.opendev.org/c/openstack/glance/+/76424721:49
openstackgerritLance Bragstad proposed openstack/glance master: Implement secure RBAC for metadef objects  https://review.opendev.org/c/openstack/glance/+/76424821:49
openstackgerritLance Bragstad proposed openstack/glance master: Implement secure RBAC for metadef resource types  https://review.opendev.org/c/openstack/glance/+/76424921:49
openstackgerritLance Bragstad proposed openstack/glance master: Implement secure RBAC for metadef properties  https://review.opendev.org/c/openstack/glance/+/76425021:49
openstackgerritLance Bragstad proposed openstack/glance master: Implement secure RBAC for metadef tags  https://review.opendev.org/c/openstack/glance/+/76425121:49
openstackgerritLance Bragstad proposed openstack/glance master: Implement secure RBAC for metadef namespaces  https://review.opendev.org/c/openstack/glance/+/76424721:54
openstackgerritLance Bragstad proposed openstack/glance master: Implement secure RBAC for metadef objects  https://review.opendev.org/c/openstack/glance/+/76424821:54
openstackgerritLance Bragstad proposed openstack/glance master: Implement secure RBAC for metadef resource types  https://review.opendev.org/c/openstack/glance/+/76424921:54
openstackgerritLance Bragstad proposed openstack/glance master: Implement secure RBAC for metadef properties  https://review.opendev.org/c/openstack/glance/+/76425021:54
openstackgerritLance Bragstad proposed openstack/glance master: Implement secure RBAC for metadef tags  https://review.opendev.org/c/openstack/glance/+/76425121:54
*** jv has quit IRC22:03
*** ajitha has quit IRC22:08
-openstackstatus- NOTICE: The Gerrit service on review.opendev.org is being restarted quickly to make further query caching and Git garbage collection adjustments, downtime should be less than 5 minutes22:36
gmannlbragstad: nice, that is fine. i can rebase on top of yours22:41
gmannlbragstad: also are we merging the rbac patches without tests as I saw you are starting the work in many projects? like designate merged those without testing.22:42
*** k_mouza has joined #openstack-glance22:48
lbragstadgmann that wasn't the plan - i started proposing these to get the discussion rolling23:02
lbragstadand i haven't implied that we won't include tests23:03
*** rcernin has joined #openstack-glance23:03
lbragstadmy guess is that i'll have to go back through after and add tests23:04
lbragstadgmann biab23:04
gmanni see, +123:08
*** tkajinam has quit IRC23:10
*** tkajinam has joined #openstack-glance23:11
*** k_mouza has quit IRC23:17

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!