*** baojg has quit IRC | 00:00 | |
*** baojg has joined #openstack-meeting | 00:00 | |
*** baojg has quit IRC | 00:00 | |
*** baojg has joined #openstack-meeting | 00:01 | |
*** baojg has quit IRC | 00:01 | |
*** baojg has joined #openstack-meeting | 00:02 | |
*** baojg has quit IRC | 00:02 | |
*** baojg has joined #openstack-meeting | 00:02 | |
*** baojg has quit IRC | 00:03 | |
*** baojg has joined #openstack-meeting | 00:03 | |
*** baojg has quit IRC | 00:04 | |
*** baojg has joined #openstack-meeting | 00:04 | |
*** baojg has quit IRC | 00:04 | |
*** baojg has joined #openstack-meeting | 00:05 | |
*** baojg has quit IRC | 00:05 | |
*** baojg has joined #openstack-meeting | 00:06 | |
*** baojg has quit IRC | 00:06 | |
*** baojg has joined #openstack-meeting | 00:06 | |
*** baojg has quit IRC | 00:07 | |
*** baojg has joined #openstack-meeting | 00:07 | |
*** baojg has quit IRC | 00:08 | |
*** baojg has joined #openstack-meeting | 00:08 | |
*** baojg has quit IRC | 00:08 | |
*** baojg has joined #openstack-meeting | 00:09 | |
*** baojg has quit IRC | 00:09 | |
*** baojg has joined #openstack-meeting | 00:10 | |
*** baojg has quit IRC | 00:10 | |
*** baojg has joined #openstack-meeting | 00:10 | |
*** baojg has quit IRC | 00:11 | |
*** baojg has joined #openstack-meeting | 00:12 | |
*** baojg has quit IRC | 00:12 | |
*** baojg has joined #openstack-meeting | 00:13 | |
*** baojg has quit IRC | 00:13 | |
*** baojg has joined #openstack-meeting | 00:14 | |
*** baojg has quit IRC | 00:14 | |
*** baojg has joined #openstack-meeting | 00:14 | |
*** baojg has quit IRC | 00:15 | |
*** baojg has joined #openstack-meeting | 00:15 | |
*** baojg has quit IRC | 00:16 | |
*** baojg has joined #openstack-meeting | 00:16 | |
*** baojg has quit IRC | 00:16 | |
*** baojg has joined #openstack-meeting | 00:17 | |
*** baojg has quit IRC | 00:17 | |
*** baojg has joined #openstack-meeting | 00:18 | |
*** baojg has quit IRC | 00:18 | |
*** baojg has joined #openstack-meeting | 00:18 | |
*** baojg has quit IRC | 00:19 | |
*** Liang__ has joined #openstack-meeting | 00:49 | |
*** yamamoto has quit IRC | 01:49 | |
*** apetrich has quit IRC | 01:57 | |
*** yamamoto has joined #openstack-meeting | 02:05 | |
*** yamamoto has quit IRC | 02:05 | |
*** yamamoto has joined #openstack-meeting | 02:05 | |
*** yamamoto has quit IRC | 02:09 | |
*** baojg has joined #openstack-meeting | 02:19 | |
*** yamamoto has joined #openstack-meeting | 02:23 | |
*** yamamoto has quit IRC | 02:23 | |
*** baojg has quit IRC | 02:24 | |
*** ykatabam has quit IRC | 02:25 | |
*** yamamoto has joined #openstack-meeting | 03:10 | |
*** ykatabam has joined #openstack-meeting | 03:17 | |
*** rbudden has joined #openstack-meeting | 03:23 | |
*** whoami-rajat has joined #openstack-meeting | 03:24 | |
*** psachin has joined #openstack-meeting | 03:25 | |
*** markvoelker has joined #openstack-meeting | 03:37 | |
*** zaneb has quit IRC | 03:40 | |
*** ricolin has joined #openstack-meeting | 03:43 | |
*** baojg has joined #openstack-meeting | 03:44 | |
*** yamamoto has quit IRC | 03:45 | |
*** yamamoto has joined #openstack-meeting | 03:46 | |
*** yamamoto has quit IRC | 03:46 | |
*** ricolin has quit IRC | 03:49 | |
*** ykatabam has quit IRC | 03:50 | |
*** ricolin has joined #openstack-meeting | 03:50 | |
*** ykatabam has joined #openstack-meeting | 03:54 | |
*** ykatabam has joined #openstack-meeting | 03:54 | |
*** rbudden has quit IRC | 03:58 | |
*** imsurit has joined #openstack-meeting | 04:11 | |
*** yamamoto has joined #openstack-meeting | 04:13 | |
*** Lucas_Gray has joined #openstack-meeting | 04:33 | |
*** dtrainor has joined #openstack-meeting | 04:35 | |
*** yamamoto has quit IRC | 04:43 | |
*** Wryhder has joined #openstack-meeting | 04:48 | |
*** Lucas_Gray has quit IRC | 04:49 | |
*** Wryhder is now known as Lucas_Gray | 04:49 | |
*** yamamoto has joined #openstack-meeting | 04:54 | |
*** rubasov has quit IRC | 05:08 | |
*** kopecmartin has joined #openstack-meeting | 05:12 | |
*** yamamoto has quit IRC | 05:12 | |
*** yaawang has quit IRC | 05:13 | |
*** yaawang has joined #openstack-meeting | 05:13 | |
*** ykatabam has quit IRC | 05:16 | |
*** ykatabam has joined #openstack-meeting | 05:16 | |
*** ykatabam has joined #openstack-meeting | 05:22 | |
*** ykatabam has quit IRC | 05:26 | |
*** Lucas_Gray has quit IRC | 05:27 | |
*** vishalmanchanda has joined #openstack-meeting | 05:27 | |
*** rcernin has quit IRC | 05:27 | |
*** Lucas_Gray has joined #openstack-meeting | 05:30 | |
*** Luzi has joined #openstack-meeting | 05:44 | |
*** Lucas_Gray has quit IRC | 05:44 | |
*** hyunsikyang has joined #openstack-meeting | 06:11 | |
*** ircuser-1 has quit IRC | 06:15 | |
*** pcaruana has joined #openstack-meeting | 06:36 | |
*** pcaruana has quit IRC | 06:40 | |
*** ykatabam has joined #openstack-meeting | 06:43 | |
*** rcernin has joined #openstack-meeting | 06:44 | |
*** rubasov has joined #openstack-meeting | 06:44 | |
*** whoami-rajat has quit IRC | 06:50 | |
*** zbr has quit IRC | 06:50 | |
*** fungi has quit IRC | 06:50 | |
*** verdurin has quit IRC | 06:50 | |
*** cmurphy has quit IRC | 06:50 | |
*** ildikov has quit IRC | 06:50 | |
*** persia has quit IRC | 06:50 | |
*** mugsie has quit IRC | 06:50 | |
*** niceplace_ has quit IRC | 06:50 | |
*** melwitt has quit IRC | 06:50 | |
*** rajinir has quit IRC | 06:50 | |
*** jhesketh has quit IRC | 06:50 | |
*** rsimai has joined #openstack-meeting | 06:51 | |
*** imsurit has quit IRC | 06:55 | |
*** yamamoto has joined #openstack-meeting | 07:01 | |
*** hyunsikyang__ has joined #openstack-meeting | 07:07 | |
*** ttsiouts has joined #openstack-meeting | 07:08 | |
*** hyunsikyang has quit IRC | 07:11 | |
*** hemna has quit IRC | 07:13 | |
*** _pewp_ has quit IRC | 07:14 | |
*** _pewp_ has joined #openstack-meeting | 07:14 | |
*** hemna has joined #openstack-meeting | 07:15 | |
*** melwitt has joined #openstack-meeting | 07:16 | |
*** niceplace_ has joined #openstack-meeting | 07:16 | |
*** rajinir has joined #openstack-meeting | 07:16 | |
*** jhesketh has joined #openstack-meeting | 07:16 | |
*** whoami-rajat has joined #openstack-meeting | 07:16 | |
*** zbr has joined #openstack-meeting | 07:16 | |
*** fungi has joined #openstack-meeting | 07:16 | |
*** verdurin has joined #openstack-meeting | 07:16 | |
*** cmurphy has joined #openstack-meeting | 07:16 | |
*** ildikov has joined #openstack-meeting | 07:16 | |
*** persia has joined #openstack-meeting | 07:16 | |
*** mugsie has joined #openstack-meeting | 07:16 | |
*** panda has quit IRC | 07:19 | |
*** panda has joined #openstack-meeting | 07:21 | |
*** zerick_ has quit IRC | 07:21 | |
*** zerick has joined #openstack-meeting | 07:23 | |
*** slaweq has joined #openstack-meeting | 07:25 | |
*** geguileo has joined #openstack-meeting | 07:26 | |
*** ttsiouts has quit IRC | 07:36 | |
*** ttsiouts has joined #openstack-meeting | 07:36 | |
*** ricolin_ has joined #openstack-meeting | 07:39 | |
*** ttsiouts has quit IRC | 07:41 | |
*** ricolin has quit IRC | 07:42 | |
*** yamamoto has quit IRC | 07:43 | |
*** ttsiouts has joined #openstack-meeting | 07:46 | |
*** tssurya has joined #openstack-meeting | 07:52 | |
*** lpetrut has joined #openstack-meeting | 08:00 | |
*** helenafm has joined #openstack-meeting | 08:15 | |
*** yamamoto has joined #openstack-meeting | 08:20 | |
*** niceplace_ has quit IRC | 08:26 | |
*** melwitt has quit IRC | 08:26 | |
*** rajinir has quit IRC | 08:26 | |
*** jhesketh has quit IRC | 08:26 | |
*** whoami-rajat has quit IRC | 08:27 | |
*** zbr has quit IRC | 08:27 | |
*** fungi has quit IRC | 08:27 | |
*** verdurin has quit IRC | 08:27 | |
*** cmurphy has quit IRC | 08:27 | |
*** ildikov has quit IRC | 08:27 | |
*** persia has quit IRC | 08:27 | |
*** mugsie has quit IRC | 08:27 | |
*** yamamoto has quit IRC | 08:27 | |
*** yamamoto has joined #openstack-meeting | 08:28 | |
*** panda has quit IRC | 08:29 | |
*** ykatabam has left #openstack-meeting | 08:30 | |
*** panda has joined #openstack-meeting | 08:31 | |
*** persia has joined #openstack-meeting | 08:35 | |
*** whoami-rajat has joined #openstack-meeting | 08:36 | |
*** zbr has joined #openstack-meeting | 08:36 | |
*** ildikov has joined #openstack-meeting | 08:36 | |
*** niceplace has joined #openstack-meeting | 08:36 | |
*** fungi has joined #openstack-meeting | 08:36 | |
*** melwitt has joined #openstack-meeting | 08:36 | |
*** verdurin has joined #openstack-meeting | 08:37 | |
*** mugsie has joined #openstack-meeting | 08:37 | |
*** jhesketh has joined #openstack-meeting | 08:37 | |
*** e0ne has joined #openstack-meeting | 08:45 | |
*** yamamoto has quit IRC | 08:52 | |
*** rcernin has quit IRC | 08:55 | |
*** e0ne has quit IRC | 09:00 | |
*** ralonsoh has joined #openstack-meeting | 09:02 | |
*** Liang__ is now known as LiangFang | 09:07 | |
*** imsurit has joined #openstack-meeting | 09:10 | |
*** lpetrut has quit IRC | 09:10 | |
*** e0ne has joined #openstack-meeting | 09:12 | |
*** LiangFang has quit IRC | 09:24 | |
*** e0ne has quit IRC | 09:25 | |
*** yamamoto has joined #openstack-meeting | 09:26 | |
*** yamamoto has quit IRC | 09:35 | |
*** imsurit_ofc has joined #openstack-meeting | 09:40 | |
*** imsurit has quit IRC | 09:42 | |
*** imsurit_ofc is now known as imsurit | 09:42 | |
*** ricolin_ has quit IRC | 09:47 | |
*** imsurit_ofc has joined #openstack-meeting | 10:02 | |
*** imsurit has quit IRC | 10:02 | |
*** imsurit_ofc is now known as imsurit | 10:02 | |
*** yamamoto has joined #openstack-meeting | 10:06 | |
*** johnsom has quit IRC | 10:06 | |
*** walshh_ has quit IRC | 10:06 | |
*** walshh_ has joined #openstack-meeting | 10:07 | |
*** johnsom has joined #openstack-meeting | 10:07 | |
*** vishalmanchanda has quit IRC | 10:11 | |
*** vishalmanchanda has joined #openstack-meeting | 10:11 | |
*** ttsiouts has quit IRC | 10:19 | |
*** ttsiouts has joined #openstack-meeting | 10:19 | |
*** yamamoto has quit IRC | 10:19 | |
*** ttsiouts has quit IRC | 10:24 | |
*** imsurit has quit IRC | 10:37 | |
*** yamamoto has joined #openstack-meeting | 10:46 | |
*** yamamoto has quit IRC | 10:46 | |
*** yamamoto has joined #openstack-meeting | 10:48 | |
*** carloss has joined #openstack-meeting | 10:50 | |
*** yamamoto has quit IRC | 10:53 | |
*** ttsiouts has joined #openstack-meeting | 10:56 | |
*** imsurit has joined #openstack-meeting | 11:04 | |
*** njohnston has joined #openstack-meeting | 11:06 | |
*** ijw has joined #openstack-meeting | 11:06 | |
*** ijw has quit IRC | 11:11 | |
*** imsurit has quit IRC | 11:14 | |
*** yamamoto has joined #openstack-meeting | 11:19 | |
*** baojg has quit IRC | 11:19 | |
*** tesseract has joined #openstack-meeting | 11:20 | |
*** baojg has joined #openstack-meeting | 11:25 | |
*** pcaruana has joined #openstack-meeting | 11:32 | |
*** psachin has quit IRC | 11:36 | |
*** rosmaita has joined #openstack-meeting | 11:40 | |
*** baojg has quit IRC | 11:45 | |
*** baojg has joined #openstack-meeting | 11:45 | |
*** baojg has quit IRC | 11:46 | |
*** baojg has joined #openstack-meeting | 11:46 | |
*** baojg has quit IRC | 11:47 | |
*** baojg has joined #openstack-meeting | 11:47 | |
*** baojg has quit IRC | 11:47 | |
*** baojg has joined #openstack-meeting | 11:48 | |
*** baojg has quit IRC | 11:48 | |
*** tesseract has quit IRC | 11:48 | |
*** baojg has joined #openstack-meeting | 11:49 | |
*** baojg has quit IRC | 11:49 | |
*** baojg has joined #openstack-meeting | 11:49 | |
*** baojg has quit IRC | 11:50 | |
*** baojg has joined #openstack-meeting | 11:50 | |
*** baojg has quit IRC | 11:51 | |
*** baojg has joined #openstack-meeting | 11:51 | |
*** tesseract has joined #openstack-meeting | 11:51 | |
*** baojg has quit IRC | 11:51 | |
*** baojg has joined #openstack-meeting | 11:52 | |
*** baojg has quit IRC | 11:52 | |
*** baojg has joined #openstack-meeting | 11:53 | |
*** raildo has joined #openstack-meeting | 11:53 | |
*** baojg has quit IRC | 11:53 | |
*** baojg has joined #openstack-meeting | 11:53 | |
*** baojg has quit IRC | 11:54 | |
*** baojg has joined #openstack-meeting | 11:54 | |
*** baojg has quit IRC | 11:55 | |
*** baojg has joined #openstack-meeting | 11:55 | |
*** baojg has quit IRC | 11:55 | |
*** baojg has joined #openstack-meeting | 11:56 | |
*** baojg has quit IRC | 11:56 | |
*** baojg has joined #openstack-meeting | 11:56 | |
*** baojg has quit IRC | 11:57 | |
*** baojg has joined #openstack-meeting | 11:57 | |
*** baojg has quit IRC | 11:58 | |
*** baojg has joined #openstack-meeting | 11:58 | |
*** baojg has quit IRC | 11:59 | |
*** baojg has joined #openstack-meeting | 11:59 | |
*** baojg has quit IRC | 11:59 | |
*** baojg has joined #openstack-meeting | 12:00 | |
*** baojg has quit IRC | 12:00 | |
*** baojg has joined #openstack-meeting | 12:00 | |
*** baojg has quit IRC | 12:01 | |
*** baojg has joined #openstack-meeting | 12:01 | |
*** baojg has quit IRC | 12:02 | |
*** dviroel has joined #openstack-meeting | 12:03 | |
*** needssleep is now known as TheJulia | 12:04 | |
*** ttsiouts has quit IRC | 12:15 | |
*** ttsiouts has joined #openstack-meeting | 12:15 | |
*** ttsiouts has quit IRC | 12:18 | |
*** ttsiouts has joined #openstack-meeting | 12:18 | |
*** apetrich has joined #openstack-meeting | 12:26 | |
*** ricolin_ has joined #openstack-meeting | 12:30 | |
*** ricolin__ has joined #openstack-meeting | 12:31 | |
*** ricolin_ has quit IRC | 12:35 | |
*** yamamoto has quit IRC | 12:35 | |
*** electrofelix has joined #openstack-meeting | 12:36 | |
*** jbadiapa has joined #openstack-meeting | 12:46 | |
*** tidwellr has quit IRC | 12:53 | |
*** gagehugo has joined #openstack-meeting | 12:56 | |
*** electrofelix has quit IRC | 12:56 | |
*** yamamoto has joined #openstack-meeting | 12:57 | |
*** yamamoto has quit IRC | 12:57 | |
*** lpetrut has joined #openstack-meeting | 12:58 | |
Luzi | #startmeeting image_encryption | 13:01 |
---|---|---|
openstack | Meeting started Mon Jul 15 13:01:10 2019 UTC and is due to finish in 60 minutes. The chair is Luzi. Information about MeetBot at http://wiki.debian.org/MeetBot. | 13:01 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 13:01 |
*** Lucas_Gray has joined #openstack-meeting | 13:01 | |
*** openstack changes topic to " (Meeting topic: image_encryption)" | 13:01 | |
openstack | The meeting name has been set to 'image_encryption' | 13:01 |
efried | o/ | 13:01 |
Luzi | #topic Roll Call | 13:01 |
*** openstack changes topic to "Roll Call (Meeting topic: image_encryption)" | 13:01 | |
gagehugo | o/ | 13:01 |
rosmaita | o/ | 13:01 |
*** mhen has joined #openstack-meeting | 13:02 | |
Luzi | hi everyone | 13:02 |
mhen | o/ | 13:02 |
hemna | yough | 13:05 |
Luzi | I have pinged Barbican and Cinder folks | 13:05 |
rosmaita | Luzi: eharney has a conflict this week, but said he will read through the meeting logs | 13:05 |
Luzi | ah thanks for the info rosmaita | 13:06 |
rosmaita | (i have a conflict and will disappear at 13:20) | 13:06 |
Luzi | well i wanted to talk about the Barbican Consumer API first, but no one is here at this point | 13:08 |
Luzi | #topic Barbican Consumer API Update | 13:08 |
*** openstack changes topic to "Barbican Consumer API Update (Meeting topic: image_encryption)" | 13:08 | |
Luzi | for the key handling in Glance, and now also Nova, we depend on the Consumer API of Barbican | 13:09 |
Luzi | #link https://review.opendev.org/#/c/662013/ | 13:09 |
Luzi | the spec was merged but I am not sure who is working on it, right now | 13:09 |
Luzi | I will ask them about it tomorrow in the Barbican meeting | 13:11 |
Luzi | #topic Image Encryption Specs | 13:11 |
*** openstack changes topic to "Image Encryption Specs (Meeting topic: image_encryption)" | 13:11 | |
Luzi | Since the Summit, we edited all Specs, especially the nova one. | 13:13 |
*** belmoreira has joined #openstack-meeting | 13:13 | |
Luzi | I would like to gather all open questions here, because most of them should be addressed in all specs. | 13:14 |
efried | I'll look at the nova one again today | 13:14 |
efried | If Sean is happy with the changes since my last upvote, I should be able to +2 it. | 13:14 |
efried | Luzi: You'll want to hunt down another core at that point. | 13:15 |
Luzi | thanks efried, I will do that. this meeting is also intended to get more people involved and reading / knowing about what we are doing :) | 13:16 |
efried | do you remember who you talked to in Denver about this? johnthetubaguy or dansmith would be good reviewers -- esp. if either one of them is familiar with the topic from the PTG. | 13:16 |
efried | (FYI mriedem is out this week) | 13:17 |
Luzi | i doubt that :D i seem to always get different nova developers to talk to :D | 13:17 |
Luzi | for everyone else, we added a slightly adjusted key-handling to the nova spec to also cover server shelve and cross-cell resize - in these cases temporary images could also be encrypted | 13:19 |
efried | But that ^ encryption is temporary and the key is not provided by or visible to the user, right? | 13:19 |
rosmaita | (i have to leave, will read through the meeting log; thanks for organizing this, Luzi) | 13:21 |
*** rosmaita has left #openstack-meeting | 13:21 | |
Luzi | efried, it is a little bit more complex but can be also used for a simple snapshot | 13:22 |
Luzi | a.k.a. server image create | 13:22 |
efried | Luzi: Forgive my ignorance, but how are 'barbican' and 'castellan' related? | 13:24 |
Luzi | you can look at it this way: castellan is the oslo-library to provide a key-storage-backend, which is Barbican | 13:24 |
Luzi | an access abstraction layer basically | 13:25 |
*** enriquetaso has joined #openstack-meeting | 13:25 | |
efried | ah, okay. I remember looking at this a few years ago, and barbican was ripped out of nova in favor of castellan, so that makes sense | 13:26 |
efried | castellan itself doesn't have a service-types-authority entry | 13:26 |
efried | But also, there are no configurables in nova for barbican. E.g. a way to provide creds to the service, declare where the endpoint is, etc. | 13:27 |
efried | is any of that going to be necessary for the image encryption effort? | 13:27 |
efried | (Apologies if this is in the spec -- it's been a couple of weeks since I read it last.) | 13:28 |
mhen | efried, see https://docs.openstack.org/ocata/config-reference/compute/config-options.html | 13:28 |
mhen | there are options for Barbican endpoint etc. | 13:28 |
Luzi | still in Stein | 13:29 |
mhen | e.g. "barbican_endpoint" | 13:29 |
Luzi | and it definitely works :D | 13:30 |
* mhen confirms this | 13:30 | |
efried | aha, now I see we're importing castellan options | 13:31 |
efried | https://opendev.org/openstack/nova/src/branch/master/nova/conf/key_manager.py | 13:31 |
*** hemna has quit IRC | 13:33 | |
efried | but we're not allowing any customization? | 13:33 |
*** electrofelix has joined #openstack-meeting | 13:33 | |
efried | ah, that set_defaults thing is setting them up. | 13:33 |
efried | blam https://docs.openstack.org/nova/latest/configuration/config.html#key-manager | 13:34 |
efried | where are these coming from? https://docs.openstack.org/nova/latest/configuration/config.html#barbican | 13:35 |
jungleboyj | o/ | 13:35 |
*** belmoreira has quit IRC | 13:35 | |
efried | The reason I'm getting into this is because we'd like to be using common keystoneauth1 options and creating a ksa Adapter for services like this. | 13:35 |
efried | ...and soon using openstacksdk Connection instead. | 13:36 |
*** hemna has joined #openstack-meeting | 13:37 | |
Luzi | well, I don't know how Barbican can / will handle this, but I yould also ask them that tomorrow | 13:37 |
efried | Anyone know what openstacksdk affordance for barbican looks like these days? | 13:37 |
Luzi | i didn't look into openstacksdk after it was clear, that we have to use another library | 13:38 |
*** belmoreira has joined #openstack-meeting | 13:38 | |
efried | "use another library"? | 13:39 |
Luzi | for the encryption and decryption code | 13:39 |
Luzi | as cinder will not use openstacksdk | 13:40 |
Luzi | os_brick is what we are looking into right now | 13:40 |
Luzi | Well I would really like to talk to eharny about the cinder part again, maybe I will have to join the cinder meeting | 13:44 |
efried | jungleboyj is here, can he address? | 13:44 |
jungleboyj | I am here, but eharney is the one with the concerns. | 13:45 |
efried | Luzi: You mean all the encryption/decryption will be brokered by some other library, like os_brick, even from nova flows? | 13:45 |
jungleboyj | efried: I think that was what we talked about at the PTG. | 13:45 |
Luzi | yes one part | 13:45 |
jungleboyj | Rather than creating some new library since both already use it. | 13:45 |
*** eharney has joined #openstack-meeting | 13:45 | |
efried | so where do the conf options live (auth etc)? | 13:46 |
*** rbudden has joined #openstack-meeting | 13:46 | |
efried | Do we load that stuff up from nova.conf and pass it down into os_brick? Or does os_brick have its own central conf that it loads up so the admin only has to fill that stuff out once? | 13:46 |
Luzi | efried, because the encryption and decryption is needed in noca, cinder and a potential client (and ironic later on) - we would really like to use a library | 13:46 |
*** rbudden has quit IRC | 13:47 | |
efried | yeah, I like that idea. | 13:47 |
mhen | efried, the auth and key retrieval part from Barbican will still happen in Nova | 13:47 |
jungleboyj | efried: That is a good question. os_brick doesn't have its own conf right now. | 13:47 |
efried | right, so this is my point | 13:47 |
efried | if we're needing to use keys from multiple different places | 13:47 |
mhen | only the specific decryption/encryption process will be handled by the library, but the key will have been already acquired by that point | 13:47 |
efried | Okay, so each project (nova, cinder, ironic) that ties into this flow will need its own, separate, duplicate conf for barbican to retrieve the keys. And then those get passed into the os-brick methods. | 13:48 |
mhen | efried, correct | 13:49 |
efried | that's not ideal ux | 13:49 |
efried | but | 13:49 |
efried | I see how it's potentially better than asking os-brick to do the key retrieval? | 13:49 |
efried | also | 13:49 |
efried | I guess the agents for nova/cinder/ironic/etc might not even be running on the same host | 13:50 |
efried | Okay, so coming full circle: nova (among others) is going to have to talk to barbican to do its key retrieval, and then pass that key down into these os-brick methods. | 13:51 |
*** belmoreira has quit IRC | 13:51 | |
efried | so what would be neat is if nova could use common ksa-isms to talk to barbican | 13:51 |
efried | and/or openstacksdk | 13:51 |
hemna | os-brick doesn't really know anything about the services per say, and shouldn't | 13:51 |
hemna | it's a standalone lib | 13:51 |
hemna | anything that os-brick needs should get passed in to do it's work | 13:52 |
efried | I think I (finally) understand that now :) | 13:52 |
hemna | it's consumed by the services as a lib, basically | 13:52 |
mhen | efried, pardon my ignorance but what does "ksa-isms" refer to? | 13:52 |
efried | mhen: keystoneauth1 is a library that provides a common set of classes (various *Auth subclasses for auth, Session for http, and Adapter for catalog/endpoint/versioning/etc) | 13:56 |
efried | as of several years ago, nova was set up to talk to various services (cinder, ironic, glance, neutron, ...) through their clients, with wildly differing config opts for each | 13:57 |
efried | so we did some work to make them all use common conf options from keystoneauth1 | 13:57 |
Luzi | ah I see, that does make sense | 13:58 |
efried | so that the admin would be able to have one way to set up their conf for those various services. | 13:58 |
efried | (they still have to set up those same conf options for each service) | 13:58 |
*** belmoreira has joined #openstack-meeting | 13:58 | |
efried | we got a good start of everything except cinder... and barbican | 13:59 |
efried | and now, we're doing some work to cut over to openstacksdk | 13:59 |
efried | and cutting out the clients entirely | 13:59 |
efried | but that's (currently) dependent on the services supporting keystoneauth1 conf | 13:59 |
efried | which barbican (as I'm now discovering, pawing through the code) clearly does not. | 14:00 |
efried | anyway | 14:00 |
efried | I think this is a separate issue | 14:00 |
efried | we clearly have to support the legacy configuration for barbican anyway | 14:00 |
efried | but if you are going to be using the existing barbican conf | 14:01 |
efried | you're going to be sharing with the ephemeral lvm encryption that's already in place for libvirt. | 14:01 |
mhen | efried, that's exactly what we are doing currently | 14:01 |
efried | and... is that okay? | 14:01 |
efried | intentional, by design? | 14:02 |
*** baojg has joined #openstack-meeting | 14:02 | |
mhen | I don't see any issue with that, we are only sharing the connection to Barbican - the access control is still done through the user's token | 14:02 |
Luzi | well we are already over the time | 14:03 |
Luzi | thank you all for joining, we can also talk in another channel | 14:03 |
efried | sorry I hijacked the meeting | 14:03 |
Luzi | #endmeeting image_encryption | 14:04 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 14:04 | |
openstack | Meeting ended Mon Jul 15 14:04:00 2019 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 14:04 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/image_encryption/2019/image_encryption.2019-07-15-13.01.html | 14:04 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/image_encryption/2019/image_encryption.2019-07-15-13.01.txt | 14:04 |
openstack | Log: http://eavesdrop.openstack.org/meetings/image_encryption/2019/image_encryption.2019-07-15-13.01.log.html | 14:04 |
mhen | efried, if you still have any concerns about this, please bring them up next week | 14:04 |
efried | mhen: I'd like to continue the discussion, if you're available | 14:04 |
mhen | efried, sure | 14:04 |
Luzi | efried, you haven't :D this meetin is about asking questions | 14:04 |
jungleboyj | Luzi: Thanks! | 14:05 |
efried | #openstack-image-encryption ? | 14:05 |
efried | mhen, Luzi: ^ | 14:05 |
Luzi | #join openstack-image-encryption | 14:07 |
efried | it's /join | 14:07 |
*** baojg has quit IRC | 14:07 | |
*** baojg has joined #openstack-meeting | 14:20 | |
*** belmoreira has quit IRC | 14:26 | |
*** artom has quit IRC | 14:26 | |
*** gagehugo has left #openstack-meeting | 14:28 | |
*** tesseract has quit IRC | 14:28 | |
*** belmoreira has joined #openstack-meeting | 14:29 | |
*** tesseract has joined #openstack-meeting | 14:30 | |
*** dklyle has joined #openstack-meeting | 14:38 | |
*** TxGirlGeek has joined #openstack-meeting | 14:39 | |
*** belmoreira has quit IRC | 14:39 | |
*** irclogbot_2 has quit IRC | 14:41 | |
*** belmoreira has joined #openstack-meeting | 14:45 | |
*** verdurin has quit IRC | 14:47 | |
*** ericyoung has quit IRC | 14:49 | |
*** ericyoung has joined #openstack-meeting | 14:49 | |
*** irclogbot_3 has joined #openstack-meeting | 14:51 | |
*** Luzi has quit IRC | 14:52 | |
*** belmoreira has quit IRC | 14:52 | |
*** belmoreira has joined #openstack-meeting | 14:55 | |
*** yamamoto has joined #openstack-meeting | 14:59 | |
*** beekneemech is now known as bnemec | 15:01 | |
*** tesseract has quit IRC | 15:02 | |
*** tesseract has joined #openstack-meeting | 15:03 | |
*** hemna has quit IRC | 15:07 | |
*** yamamoto has quit IRC | 15:07 | |
*** ricolin__ has quit IRC | 15:11 | |
*** ricolin_ has joined #openstack-meeting | 15:11 | |
*** ttsiouts has quit IRC | 15:13 | |
*** ttsiouts has joined #openstack-meeting | 15:13 | |
*** verdurin has joined #openstack-meeting | 15:14 | |
*** shilpasd has joined #openstack-meeting | 15:16 | |
*** ttsiouts has quit IRC | 15:18 | |
*** ttsiouts has joined #openstack-meeting | 15:21 | |
*** hemna has joined #openstack-meeting | 15:24 | |
*** igordc has joined #openstack-meeting | 15:27 | |
*** hemna has quit IRC | 15:29 | |
*** hemna has joined #openstack-meeting | 15:31 | |
*** gyee has joined #openstack-meeting | 15:31 | |
*** lpetrut has quit IRC | 15:36 | |
*** cmurphy has joined #openstack-meeting | 15:44 | |
*** njohnston has quit IRC | 15:50 | |
*** njohnston has joined #openstack-meeting | 15:51 | |
*** jamesmcarthur has joined #openstack-meeting | 15:54 | |
*** hemna has quit IRC | 15:59 | |
*** diablo_rojo has joined #openstack-meeting | 16:00 | |
*** ttsiouts has quit IRC | 16:07 | |
*** ttsiouts has joined #openstack-meeting | 16:08 | |
*** tssurya has quit IRC | 16:11 | |
*** ijw has joined #openstack-meeting | 16:11 | |
*** ttsiouts has quit IRC | 16:13 | |
*** kopecmartin is now known as kopecmartin|off | 16:13 | |
*** Lucas_Gray has quit IRC | 16:17 | |
*** ijw_ has joined #openstack-meeting | 16:25 | |
*** ijw_ has quit IRC | 16:29 | |
*** ijw has quit IRC | 16:29 | |
*** belmoreira has quit IRC | 16:30 | |
*** artom has joined #openstack-meeting | 16:39 | |
*** mattw4 has joined #openstack-meeting | 16:42 | |
*** artom has quit IRC | 16:43 | |
*** helenafm has quit IRC | 16:49 | |
*** ricolin_ has quit IRC | 16:50 | |
*** belmoreira has joined #openstack-meeting | 16:58 | |
*** iyamahat has joined #openstack-meeting | 16:59 | |
*** SWDevAngel has joined #openstack-meeting | 17:02 | |
*** mattw4 has quit IRC | 17:02 | |
*** belmoreira has quit IRC | 17:02 | |
*** lpetrut has joined #openstack-meeting | 17:03 | |
*** igordc has quit IRC | 17:07 | |
*** e0ne has joined #openstack-meeting | 17:12 | |
*** baojg has quit IRC | 17:14 | |
*** artom has joined #openstack-meeting | 17:15 | |
*** baojg has joined #openstack-meeting | 17:15 | |
*** baojg has quit IRC | 17:15 | |
*** baojg has joined #openstack-meeting | 17:15 | |
*** baojg has quit IRC | 17:16 | |
*** baojg has joined #openstack-meeting | 17:16 | |
*** baojg has quit IRC | 17:17 | |
*** baojg has joined #openstack-meeting | 17:17 | |
*** baojg has quit IRC | 17:17 | |
*** baojg has joined #openstack-meeting | 17:18 | |
*** baojg has quit IRC | 17:18 | |
*** mattw4 has joined #openstack-meeting | 17:19 | |
*** baojg has joined #openstack-meeting | 17:19 | |
*** baojg has quit IRC | 17:19 | |
*** baojg has joined #openstack-meeting | 17:19 | |
*** baojg has quit IRC | 17:20 | |
*** baojg has joined #openstack-meeting | 17:20 | |
*** baojg has quit IRC | 17:21 | |
*** baojg has joined #openstack-meeting | 17:21 | |
*** baojg has quit IRC | 17:21 | |
*** baojg has joined #openstack-meeting | 17:22 | |
*** baojg has quit IRC | 17:22 | |
*** ralonsoh has quit IRC | 17:22 | |
*** baojg has joined #openstack-meeting | 17:23 | |
*** baojg has quit IRC | 17:23 | |
*** baojg has joined #openstack-meeting | 17:23 | |
*** baojg has quit IRC | 17:24 | |
*** baojg has joined #openstack-meeting | 17:24 | |
*** baojg has quit IRC | 17:25 | |
*** altlogbot_3 has quit IRC | 17:25 | |
*** baojg has joined #openstack-meeting | 17:25 | |
*** baojg has quit IRC | 17:25 | |
*** irclogbot_3 has quit IRC | 17:26 | |
*** baojg has joined #openstack-meeting | 17:26 | |
*** baojg has quit IRC | 17:26 | |
*** irclogbot_0 has joined #openstack-meeting | 17:29 | |
*** TxGirlGeek has quit IRC | 17:29 | |
*** altlogbot_1 has joined #openstack-meeting | 17:29 | |
*** altlogbot_1 has quit IRC | 17:31 | |
*** TxGirlGeek has joined #openstack-meeting | 17:32 | |
*** irclogbot_0 has quit IRC | 17:32 | |
*** iyamahat has quit IRC | 17:32 | |
*** lpetrut has quit IRC | 17:33 | |
*** yamahata has quit IRC | 17:33 | |
*** irclogbot_1 has joined #openstack-meeting | 17:39 | |
*** altlogbot_1 has joined #openstack-meeting | 17:40 | |
*** tesseract has quit IRC | 17:45 | |
*** ekcs has joined #openstack-meeting | 17:48 | |
*** iyamahat has joined #openstack-meeting | 17:49 | |
*** ijw has joined #openstack-meeting | 17:53 | |
*** diablo_rojo has quit IRC | 17:57 | |
*** igordc has joined #openstack-meeting | 18:05 | |
*** vishalmanchanda has quit IRC | 18:07 | |
*** yamahata has joined #openstack-meeting | 18:09 | |
*** diablo_rojo has joined #openstack-meeting | 18:21 | |
*** electrofelix has quit IRC | 18:31 | |
*** brault has joined #openstack-meeting | 18:36 | |
*** panda has quit IRC | 18:38 | |
*** panda has joined #openstack-meeting | 18:40 | |
*** hemna has joined #openstack-meeting | 18:40 | |
*** brault has quit IRC | 18:41 | |
*** brault has joined #openstack-meeting | 18:44 | |
*** brault has quit IRC | 18:51 | |
*** belmoreira has joined #openstack-meeting | 19:22 | |
*** lee1 has joined #openstack-meeting | 19:23 | |
*** lee1 is now known as lyarwood | 19:23 | |
*** baojg has joined #openstack-meeting | 19:27 | |
*** diablo_rojo has quit IRC | 19:31 | |
*** baojg has quit IRC | 19:32 | |
*** belmoreira has quit IRC | 19:40 | |
*** eharney has quit IRC | 19:49 | |
*** jamesmcarthur has quit IRC | 19:51 | |
*** e0ne has quit IRC | 19:52 | |
*** e0ne has joined #openstack-meeting | 19:53 | |
*** altlogbot_1 has quit IRC | 20:10 | |
*** altlogbot_0 has joined #openstack-meeting | 20:13 | |
*** pcaruana has quit IRC | 20:29 | |
*** slaweq has quit IRC | 20:31 | |
*** diablo_rojo has joined #openstack-meeting | 20:34 | |
*** TxGirlGeek has quit IRC | 20:35 | |
*** slaweq has joined #openstack-meeting | 20:39 | |
*** eharney has joined #openstack-meeting | 20:41 | |
*** jamesmcarthur has joined #openstack-meeting | 20:42 | |
*** slaweq has quit IRC | 20:43 | |
*** TxGirlGeek has joined #openstack-meeting | 20:46 | |
*** e0ne has quit IRC | 21:03 | |
*** artom has quit IRC | 21:07 | |
*** e0ne has joined #openstack-meeting | 21:19 | |
*** e0ne has quit IRC | 21:20 | |
*** e0ne has joined #openstack-meeting | 21:22 | |
*** e0ne has quit IRC | 21:24 | |
*** e0ne has joined #openstack-meeting | 21:24 | |
*** enriquetaso has quit IRC | 21:26 | |
*** baojg has joined #openstack-meeting | 21:28 | |
*** baojg has quit IRC | 21:32 | |
*** e0ne has quit IRC | 21:39 | |
*** raildo has quit IRC | 21:59 | |
*** diablo_rojo has quit IRC | 22:03 | |
*** whoami-rajat has quit IRC | 22:04 | |
*** jamesmcarthur has quit IRC | 22:04 | |
*** ircuser-1 has joined #openstack-meeting | 22:23 | |
*** yamamoto has joined #openstack-meeting | 22:45 | |
*** ykatabam has joined #openstack-meeting | 23:12 | |
*** carloss has quit IRC | 23:19 | |
*** rcernin has joined #openstack-meeting | 23:29 | |
*** enriquetaso has joined #openstack-meeting | 23:29 | |
*** baojg has joined #openstack-meeting | 23:29 | |
*** e0ne has joined #openstack-meeting | 23:31 | |
*** mattw4 has quit IRC | 23:32 | |
*** baojg has quit IRC | 23:33 | |
*** jamesmcarthur has joined #openstack-meeting | 23:35 | |
*** e0ne has quit IRC | 23:36 | |
*** e0ne has joined #openstack-meeting | 23:38 | |
*** e0ne has quit IRC | 23:42 | |
*** TxGirlGeek has quit IRC | 23:45 | |
*** yamamoto has quit IRC | 23:49 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!