*** bbowen has joined #openstack-meeting | 00:00 | |
*** slaweq has quit IRC | 00:02 | |
*** slaweq has joined #openstack-meeting | 00:10 | |
*** slaweq has quit IRC | 00:15 | |
*** ociuhandu has joined #openstack-meeting | 00:19 | |
*** jamesmcarthur has joined #openstack-meeting | 00:20 | |
*** slaweq has joined #openstack-meeting | 00:21 | |
*** jamesmcarthur has quit IRC | 00:26 | |
*** ociuhandu has quit IRC | 00:26 | |
*** armax has joined #openstack-meeting | 00:36 | |
*** armax has quit IRC | 00:40 | |
*** jamesmcarthur has joined #openstack-meeting | 00:58 | |
*** jamesmcarthur has quit IRC | 01:17 | |
*** ijw has quit IRC | 01:21 | |
*** ijw has joined #openstack-meeting | 01:25 | |
*** armax has joined #openstack-meeting | 01:28 | |
*** ociuhandu has joined #openstack-meeting | 01:29 | |
*** ijw has quit IRC | 01:30 | |
*** ijw has joined #openstack-meeting | 01:30 | |
*** ijw_ has joined #openstack-meeting | 01:33 | |
*** armax has quit IRC | 01:33 | |
*** ociuhandu has quit IRC | 01:34 | |
*** ijw has quit IRC | 01:37 | |
*** ociuhandu has joined #openstack-meeting | 01:59 | |
*** slaweq has quit IRC | 02:02 | |
*** ociuhandu has quit IRC | 02:03 | |
*** ociuhandu has joined #openstack-meeting | 02:04 | |
*** ociuhandu has quit IRC | 02:09 | |
*** armax has joined #openstack-meeting | 02:14 | |
*** armax has quit IRC | 02:20 | |
*** yaawang has quit IRC | 02:24 | |
*** yaawang has joined #openstack-meeting | 02:33 | |
*** armax has joined #openstack-meeting | 02:51 | |
*** ociuhandu has joined #openstack-meeting | 02:51 | |
*** ociuhandu has quit IRC | 02:53 | |
*** ociuhandu has joined #openstack-meeting | 02:55 | |
*** armax has quit IRC | 02:56 | |
*** armax has joined #openstack-meeting | 02:58 | |
*** ociuhandu has quit IRC | 03:03 | |
*** armax has quit IRC | 03:05 | |
*** apetrich has quit IRC | 03:08 | |
*** ricolin has joined #openstack-meeting | 03:47 | |
*** davee_ has joined #openstack-meeting | 04:03 | |
*** ociuhandu has joined #openstack-meeting | 04:03 | |
*** davee___ has quit IRC | 04:04 | |
*** ociuhandu has quit IRC | 04:08 | |
*** baojg has quit IRC | 04:16 | |
*** baojg has joined #openstack-meeting | 04:17 | |
*** Lucas_Gray has joined #openstack-meeting | 04:17 | |
*** e0ne has joined #openstack-meeting | 04:46 | |
*** Lucas_Gray has quit IRC | 05:08 | |
*** vishalmanchanda has joined #openstack-meeting | 05:14 | |
*** lbragstad_ has joined #openstack-meeting | 05:21 | |
*** lbragstad has quit IRC | 05:24 | |
*** ociuhandu has joined #openstack-meeting | 05:30 | |
*** ociuhandu has quit IRC | 05:36 | |
*** links has joined #openstack-meeting | 05:39 | |
*** jamesmcarthur has joined #openstack-meeting | 05:46 | |
*** jamesmcarthur has quit IRC | 05:50 | |
*** ijw has joined #openstack-meeting | 05:56 | |
*** ijw_ has quit IRC | 05:59 | |
*** Luzi has joined #openstack-meeting | 06:06 | |
*** e0ne has quit IRC | 06:32 | |
*** pcaruana has joined #openstack-meeting | 06:32 | |
*** e0ne has joined #openstack-meeting | 06:32 | |
*** e0ne has quit IRC | 06:50 | |
*** ralonsoh has joined #openstack-meeting | 06:51 | |
*** belmoreira has joined #openstack-meeting | 06:53 | |
*** ircuser-1 has quit IRC | 06:55 | |
*** belmoreira has quit IRC | 06:56 | |
*** ociuhandu has joined #openstack-meeting | 07:01 | |
*** ociuhandu has quit IRC | 07:05 | |
*** slaweq has joined #openstack-meeting | 07:08 | |
*** slaweq has quit IRC | 07:37 | |
*** slaweq has joined #openstack-meeting | 07:40 | |
*** ijw_ has joined #openstack-meeting | 07:45 | |
*** ijw has quit IRC | 07:47 | |
*** apetrich has joined #openstack-meeting | 07:52 | |
*** tesseract has joined #openstack-meeting | 08:14 | |
*** ijw_ has quit IRC | 08:24 | |
*** tssurya has joined #openstack-meeting | 08:31 | |
*** rpittau|afk is now known as rpittau | 08:31 | |
*** rsimai has joined #openstack-meeting | 08:43 | |
*** ttx has quit IRC | 08:50 | |
*** ttx has joined #openstack-meeting | 08:50 | |
*** ociuhandu has joined #openstack-meeting | 08:55 | |
*** ociuhandu has quit IRC | 08:56 | |
*** ociuhandu has joined #openstack-meeting | 08:57 | |
*** trident has quit IRC | 09:07 | |
*** trident has joined #openstack-meeting | 09:09 | |
*** e0ne has joined #openstack-meeting | 09:10 | |
*** yaawang has quit IRC | 09:53 | |
*** ociuhandu has quit IRC | 10:04 | |
*** yaawang has joined #openstack-meeting | 10:12 | |
*** lpetrut has joined #openstack-meeting | 10:13 | |
*** ociuhandu has joined #openstack-meeting | 10:28 | |
*** ralonsoh has quit IRC | 11:01 | |
*** ralonsoh has joined #openstack-meeting | 11:03 | |
*** ociuhandu has quit IRC | 11:16 | |
*** ociuhandu has joined #openstack-meeting | 11:17 | |
*** ociuhandu has quit IRC | 11:26 | |
*** ociuhandu has joined #openstack-meeting | 11:26 | |
*** tssurya has quit IRC | 11:29 | |
*** Lucas_Gray has joined #openstack-meeting | 11:43 | |
*** ociuhandu has quit IRC | 11:43 | |
*** ociuhandu has joined #openstack-meeting | 11:45 | |
*** raildo has joined #openstack-meeting | 11:46 | |
*** ociuhandu has quit IRC | 11:50 | |
*** rfolco has joined #openstack-meeting | 12:09 | |
*** ociuhandu has joined #openstack-meeting | 12:24 | |
*** ociuhandu has quit IRC | 12:29 | |
*** rh-jelabarre has joined #openstack-meeting | 12:59 | |
Luzi | #startmeeting image_encryption | 13:00 |
---|---|---|
openstack | Meeting started Mon Dec 2 13:00:32 2019 UTC and is due to finish in 60 minutes. The chair is Luzi. Information about MeetBot at http://wiki.debian.org/MeetBot. | 13:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 13:00 |
*** openstack changes topic to " (Meeting topic: image_encryption)" | 13:00 | |
openstack | The meeting name has been set to 'image_encryption' | 13:00 |
Luzi | #topic Roll Call | 13:00 |
*** openstack changes topic to "Roll Call (Meeting topic: image_encryption)" | 13:00 | |
fungi | welcome back, Luzi! | 13:00 |
Luzi | hi and thank you fungi | 13:00 |
redrobot | o/ | 13:01 |
*** mhen has joined #openstack-meeting | 13:01 | |
mhen | o/ | 13:02 |
Luzi | lets wait a few more minutes for other people | 13:02 |
Luzi | it seems no one else wants to show up | 13:05 |
Luzi | #topic Barbican Consumer API Update | 13:05 |
*** openstack changes topic to "Barbican Consumer API Update (Meeting topic: image_encryption)" | 13:05 | |
Luzi | redrobot, are there news from the Barbican side? | 13:05 |
redrobot | Mornin' ... no news on our end that I can think of. | 13:06 |
Luzi | okay thank you :) | 13:06 |
Luzi | #topic Image Encryption Specs | 13:07 |
*** openstack changes topic to "Image Encryption Specs (Meeting topic: image_encryption)" | 13:07 | |
Luzi | i started updating the glance spec according to the conclusions from the ptg | 13:08 |
*** rh-jelabarre has quit IRC | 13:08 | |
*** rh-jelabarre has joined #openstack-meeting | 13:08 | |
fungi | last week it came up that the nova team wants to hold off implementing local image encryption support until they have working luks support for ephemeral disks | 13:11 |
fungi | i was curious to understand the reasons behind that, so followed up with some nova reviewers in #openstack-nova on it | 13:11 |
fungi | this is because nova's local storage for instances uses the ephemeral disk mechanism to boot the image, and to be able to boot an encrypted image natively qemu only supports luks, not the pgp encryption previously implemented for nova's ephemeral disks | 13:11 |
fungi | so without that prerequisite, images would end up decrypted onto the host's filesystem, eliminating the benefit of encrypting them elsewhere | 13:12 |
*** efried_pto is now known as efried | 13:13 | |
fungi | given their objection, i agree focusing on the boot-from-volume case is reasonable for now, because nova can hand off luks-encrypted cinder volumes to qemu just fine | 13:13 |
mhen | fungi, I believe this only applies when you use 'use_cow_images' flag in Nova config | 13:14 |
*** jamesmcarthur has joined #openstack-meeting | 13:15 | |
Luzi | i think its difficult because we are talking about images and mean images at different stages or so (hard to say in english without knowing a proper word)) | 13:15 |
fungi | however, lacking copy-on-write support means a substantial amount of additional disk used on the host, so i can see why they wouldn't want to give up cow | 13:16 |
Luzi | fungi, as far as i know from mdbooth that still would be a problem even with LUKS encrypted ephemeral storage, because libvirt/nova is not able to write on encrypted cow | 13:17 |
Luzi | but yes it is the same outcoming. We will postpone the nova implementation and thus abandon the spec. | 13:18 |
fungi | oh, got it. so no cow at all for encrypted local storage instances, needs luks support for ephemeral disk mechanism to support booting them without decrypting | 13:19 |
fungi | i get what you mean about stages/phases. i think the nova team wants to be able to avoid exposing images unencrypted on the host first because that's the most precarious/dangerous place for sensitive data (what with hypervisor breakout bugs and the like) | 13:19 |
Luzi | fungi, yes. That's a valid reason from the nova side. | 13:20 |
fungi | so they're more worried about leaking image content on the hypervisor host than elsewhere in the chain | 13:20 |
Luzi | it would just make no sense to protect the image everywhere and then have it plain on the compute host | 13:22 |
fungi | yes | 13:24 |
Luzi | do we need another to reshape the scope of the pop-up-team or should we just wait and hope nova would implement ephemeral storage encryption :D | 13:24 |
fungi | that's an open question, i don't have the answer unfortunately | 13:25 |
fungi | i suspect getting the boot-from-volume case solved first might at least increase interest from others in working on the missing pieces to do the same in nova local storage | 13:25 |
Luzi | fungi, you are right - i think we can leave it as it is right now - it is only mentioned in the disband criteria | 13:27 |
Luzi | #topic Open Discussion | 13:28 |
*** openstack changes topic to "Open Discussion (Meeting topic: image_encryption)" | 13:28 | |
Luzi | are there any other topics you would like to discuss? | 13:28 |
fungi | i don't have any | 13:29 |
*** ociuhandu has joined #openstack-meeting | 13:30 | |
Luzi | thank you all for joining this meeting today :) | 13:30 |
Luzi | #endmeeting image_encryption | 13:30 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 13:30 | |
openstack | Meeting ended Mon Dec 2 13:30:44 2019 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 13:30 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/image_encryption/2019/image_encryption.2019-12-02-13.00.html | 13:30 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/image_encryption/2019/image_encryption.2019-12-02-13.00.txt | 13:30 |
openstack | Log: http://eavesdrop.openstack.org/meetings/image_encryption/2019/image_encryption.2019-12-02-13.00.log.html | 13:30 |
fungi | thanks for chairing, Luzi! | 13:30 |
*** jamesmcarthur has quit IRC | 13:35 | |
*** ociuhandu has quit IRC | 13:55 | |
*** ociuhandu has joined #openstack-meeting | 13:55 | |
*** jroll has quit IRC | 13:57 | |
*** jroll has joined #openstack-meeting | 13:59 | |
*** vishalmanchanda has quit IRC | 14:10 | |
*** ociuhandu has quit IRC | 14:10 | |
*** jamesmcarthur has joined #openstack-meeting | 14:17 | |
*** haleyb|away is now known as haleyb | 14:17 | |
*** ociuhandu has joined #openstack-meeting | 14:22 | |
*** lbragstad_ is now known as lbragstad | 14:22 | |
*** eharney has joined #openstack-meeting | 14:23 | |
*** zaneb has joined #openstack-meeting | 14:32 | |
*** munimeha1 has joined #openstack-meeting | 14:35 | |
*** mriedem has joined #openstack-meeting | 14:48 | |
*** jamesmcarthur has quit IRC | 14:49 | |
*** jamesmcarthur has joined #openstack-meeting | 15:03 | |
*** ociuhandu has quit IRC | 15:14 | |
*** ociuhandu has joined #openstack-meeting | 15:15 | |
*** links has quit IRC | 15:18 | |
*** ociuhandu has quit IRC | 15:21 | |
*** ociuhandu has joined #openstack-meeting | 15:32 | |
*** artom has joined #openstack-meeting | 15:37 | |
*** Luzi has quit IRC | 15:38 | |
*** ociuhandu has quit IRC | 15:38 | |
*** ociuhandu has joined #openstack-meeting | 15:39 | |
*** diablo_rojo has joined #openstack-meeting | 15:43 | |
*** diablo_rojo has quit IRC | 15:44 | |
*** diablo_rojo has joined #openstack-meeting | 15:44 | |
*** ociuhandu has quit IRC | 15:44 | |
*** ociuhandu has joined #openstack-meeting | 15:48 | |
*** Lucas_Gray has quit IRC | 15:48 | |
*** Lucas_Gray has joined #openstack-meeting | 15:53 | |
*** Lucas_Gray has quit IRC | 15:54 | |
*** macz has joined #openstack-meeting | 15:58 | |
*** eharney has quit IRC | 15:59 | |
*** dtrainor has quit IRC | 16:00 | |
*** ociuhandu has quit IRC | 16:01 | |
*** armax has joined #openstack-meeting | 16:05 | |
*** dtrainor has joined #openstack-meeting | 16:10 | |
*** ociuhandu has joined #openstack-meeting | 16:15 | |
*** ociuhandu has quit IRC | 16:19 | |
*** Lucas_Gray has joined #openstack-meeting | 16:20 | |
*** heikkine has joined #openstack-meeting | 16:23 | |
*** jamesmcarthur has quit IRC | 16:24 | |
*** jamesmcarthur has joined #openstack-meeting | 16:26 | |
*** gyee has joined #openstack-meeting | 16:29 | |
*** lbragsta_ has joined #openstack-meeting | 16:36 | |
*** gyee has quit IRC | 16:36 | |
*** rpittau is now known as rpittau|afk | 16:38 | |
*** gyee has joined #openstack-meeting | 16:51 | |
*** trident has quit IRC | 16:51 | |
*** trident has joined #openstack-meeting | 16:53 | |
*** eharney has joined #openstack-meeting | 16:57 | |
*** Lucas_Gray has quit IRC | 17:09 | |
*** Lucas_Gray has joined #openstack-meeting | 17:13 | |
*** ijw has joined #openstack-meeting | 17:15 | |
*** SWDevAngel has joined #openstack-meeting | 17:18 | |
*** Lucas_Gray has quit IRC | 17:23 | |
*** macz has quit IRC | 17:32 | |
*** e0ne has quit IRC | 17:36 | |
*** lbragsta_ has quit IRC | 17:44 | |
*** dmacpher has quit IRC | 17:49 | |
*** dmacpher has joined #openstack-meeting | 17:49 | |
*** macz has joined #openstack-meeting | 17:52 | |
*** ijw has quit IRC | 18:17 | |
*** vishalmanchanda has joined #openstack-meeting | 18:18 | |
*** ricolin has quit IRC | 18:22 | |
*** macz has quit IRC | 18:23 | |
*** macz has joined #openstack-meeting | 18:27 | |
*** macz has quit IRC | 18:27 | |
*** macz has joined #openstack-meeting | 18:28 | |
*** igordc has joined #openstack-meeting | 18:45 | |
*** lpetrut has quit IRC | 19:00 | |
*** macz has quit IRC | 19:01 | |
*** ijw has joined #openstack-meeting | 19:05 | |
*** e0ne has joined #openstack-meeting | 19:14 | |
*** e0ne has quit IRC | 19:19 | |
*** jamesmcarthur has quit IRC | 19:19 | |
*** macz has joined #openstack-meeting | 19:33 | |
*** tesseract has quit IRC | 19:49 | |
*** zbitter has joined #openstack-meeting | 19:53 | |
*** donnyd_ has joined #openstack-meeting | 19:54 | |
*** persia_ has joined #openstack-meeting | 19:56 | |
*** tinwood_ has joined #openstack-meeting | 19:56 | |
*** mugsie_ has joined #openstack-meeting | 19:56 | |
*** ijw_ has joined #openstack-meeting | 19:57 | |
*** macz has quit IRC | 20:02 | |
*** ijw has quit IRC | 20:02 | |
*** zaneb has quit IRC | 20:02 | |
*** ralonsoh has quit IRC | 20:02 | |
*** rsimai has quit IRC | 20:02 | |
*** pcaruana has quit IRC | 20:02 | |
*** brault has quit IRC | 20:02 | |
*** Roamer` has quit IRC | 20:02 | |
*** gibi has quit IRC | 20:02 | |
*** tinwood has quit IRC | 20:02 | |
*** persia has quit IRC | 20:02 | |
*** mugsie has quit IRC | 20:02 | |
*** johanssone has quit IRC | 20:02 | |
*** donnyd has quit IRC | 20:02 | |
*** clarkb has quit IRC | 20:02 | |
*** cmurphy has quit IRC | 20:02 | |
*** donnyd_ is now known as donnyd | 20:02 | |
*** zbitter is now known as zaneb | 20:02 | |
*** johanssone has joined #openstack-meeting | 20:03 | |
*** clarkb has joined #openstack-meeting | 20:03 | |
*** ralonsoh has joined #openstack-meeting | 20:04 | |
*** cmurphy has joined #openstack-meeting | 20:05 | |
*** pcaruana has joined #openstack-meeting | 20:05 | |
*** gyee has quit IRC | 20:09 | |
*** diablo_rojo has quit IRC | 20:14 | |
*** munimeha1 has quit IRC | 20:20 | |
*** ralonsoh has quit IRC | 20:20 | |
*** macz has joined #openstack-meeting | 20:31 | |
*** SWDevAngel has quit IRC | 20:36 | |
*** gyee has joined #openstack-meeting | 20:36 | |
*** ayoung has joined #openstack-meeting | 20:55 | |
*** raildo has quit IRC | 21:01 | |
*** eharney has quit IRC | 21:06 | |
*** mattw4 has joined #openstack-meeting | 21:13 | |
*** diablo_rojo has joined #openstack-meeting | 21:17 | |
*** slaweq has quit IRC | 21:48 | |
*** ykatabam has joined #openstack-meeting | 21:54 | |
*** rcernin has joined #openstack-meeting | 21:57 | |
*** mugsie_ is now known as mugsie | 21:59 | |
*** rcernin has quit IRC | 21:59 | |
*** slaweq has joined #openstack-meeting | 22:08 | |
*** pcaruana has quit IRC | 22:11 | |
*** slaweq has quit IRC | 22:13 | |
*** eharney has joined #openstack-meeting | 22:13 | |
*** vishalmanchanda has quit IRC | 22:21 | |
*** rh-jelabarre has quit IRC | 22:44 | |
*** rcernin has joined #openstack-meeting | 22:57 | |
*** Adri2000 has quit IRC | 23:12 | |
*** diablo_rojo has quit IRC | 23:40 | |
*** diablo_rojo has joined #openstack-meeting | 23:42 | |
*** diablo_rojo has quit IRC | 23:47 | |
*** mriedem has quit IRC | 23:54 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!