Earlier  
Posted Nick Remark
#openstack-nova - 2018-09-24
18:27:05 sean-k-mooney AJaeger: looking at the list everything that is left is for stable branches
18:27:25 sean-k-mooney AJaeger: the trove change is likely the wrong channel
18:27:48 AJaeger sean-k-mooney: yeah, don't know why the query includes that one ;( Adn yes, it's all stable changes...
18:27:53 lyarwood AJaeger: ack will do
18:28:06 AJaeger thanks, lyarwood. If you have questions, feel free to ask ...
18:28:21 AJaeger lyarwood: and ignore the trove one, please
18:28:58 lyarwood AJaeger: ack, I can't +2 that anyway :)
18:29:39 openstackgerrit Alessandro Pilotti proposed openstack/python-novaclient master: Fixes Python3 issue in decoding password https://review.openstack.org/604870
18:31:41 melwitt AJaeger: thanks for the heads up
18:32:36 AJaeger melwitt: once those 15 changes are in, the python3-first goal is done for nova ;)
18:33:10 AJaeger Only 13, I miscounted
18:33:14 melwitt coolness, I'll make sure we get those in
18:33:37 AJaeger great
18:33:55 AJaeger you have at least changes that pass everywhere - compared to other projects ;/
18:34:29 melwitt that's fortunate :)
18:35:34 AJaeger indeed
18:38:13 openstackgerrit Lee Yarwood proposed openstack/nova master: scheduler: Increase alternate count in smaller environments https://review.openstack.org/593074
18:38:13 openstack bug 1787606 in OpenStack Compute (nova) "Multi instance creation rescheduling fails due to a lack of alternates" [Medium,In progress] https://launchpad.net/bugs/1787606 - Assigned to Lee Yarwood (lyarwood)
18:38:13 openstackgerrit Lee Yarwood proposed openstack/nova master: Add regression for bug 1787606 https://review.openstack.org/593073
18:45:56 openstackgerrit Lee Yarwood proposed openstack/nova master: Add regression test for bug#1784353 https://review.openstack.org/587014
18:45:56 openstackgerrit Lee Yarwood proposed openstack/nova master: fixtures: Track volume attachments within CinderFixtureNewAttachFlow https://review.openstack.org/587013
18:45:57 openstackgerrit Lee Yarwood proposed openstack/nova master: conductor: Recreate volume attachments during a reschedule https://review.openstack.org/587071
18:54:57 AJaeger all approved - thanks, mriedem and lyarwood !
19:11:10 openstackgerrit Merged openstack/os-traits stable/rocky: import zuul job settings from project-config https://review.openstack.org/601403
19:11:12 openstackgerrit Merged openstack/os-traits stable/queens: import zuul job settings from project-config https://review.openstack.org/601398
19:11:17 openstackgerrit Merged openstack/os-traits stable/pike: import zuul job settings from project-config https://review.openstack.org/601393
19:13:51 karimull mreidem : thanks for the info..will look into hooks.
19:14:26 openstackgerrit Matt Riedemann proposed openstack/python-novaclient master: Add support changes-before for microversion 2.66 https://review.openstack.org/603549
19:19:14 karimull mreidem : efried: is there a way in nova I can branch out of normal processing of instance launch and try to work on the image before libvirt is called or with in libvirt is also fine
19:20:51 karimull mreidem:efried : basically I'm looking to decrypt an image before it is launched...
19:22:17 efried karimull: I have way more questions than answers.
19:22:24 efried Are you the only one who has ever wanted to work with encrypted images?
19:22:53 efried Is the image encrypted in glance, and then you want to decrypt it while/after you copy it to the instance's boot disk?
19:23:18 karimull may be :)
19:23:52 karimull efried : exactly
19:23:53 efried I guess what I'm getting at is, either what you're doing is wild and crazy and you shouldn't be doing it - upstream or down - or it's something that more people want to do and is either already supported or should be proposed formally upstream.
19:24:26 efried Me, I don't know anything about it, I'm afraid.
19:25:13 efried seems weird that you're maintaining the image encrypted in glance, but want it decrypted *before* you boot the instance.
19:25:24 efried It's as if you trust glance less than you trust instances
19:25:40 karimull efried :I could see volume encryption blue but nothing on image
19:28:51 karimull efried : I'm making sure if this is feasible before proposing a formal blue print
19:29:14 efried karimull: Okay, so you do intend to propose it upstream?
19:29:41 karimull efried : yes
19:29:51 efried I see. Have you talked to the glance folks about it?
19:30:50 karimull efried : not yet
19:31:19 melwitt we added support for trusted image certificate validation in rocky https://specs.openstack.org/openstack/nova-specs/specs/rocky/implemented/nova-validate-certificates.html
19:31:45 dansmith presumably they want encryption
19:31:49 dansmith but that came before, AFAIK
19:32:01 melwitt but I don't know of any support for encrypted images in glance
19:32:34 melwitt yeah, was just mentioning it in case it might be useful
19:33:12 melwitt that's the extent of the handling of "untrusted glance" that I know about
19:33:16 dansmith oh I thought the encryption support was already there
19:33:36 dansmith maybe I'm thinking of encrypted block
19:34:46 melwitt I'm not sure, it might be there. trying to find out. an earlier iteration of the trusted certs stuff mentioned image encryption
19:35:02 dansmith yeah
19:35:24 dansmith looks like just signatures though in the tree
19:35:26 efried assuming the decrypt would happen chunk-wise, it's not in the nova glance code.
19:35:26 karimull I have not seen any support for encrypted image in glance..
19:36:15 karimull wanted to support user defined encryption of image at nova compute for more flexibility
19:36:44 efried karimull: Point is, assuming it's not already there, you would likely be looking to make your changes in a lot of the same places as the bp melwitt mentioned ( https://review.openstack.org/#/q/topic:bp/nova-validate-certificates+(status:open+OR+status:merged) )
19:39:12 karimull by using Castellan which support key manager interface and by having a plugin in nova to perform user defined decryption process it will be more transparent..just a thought still framing on all possibilities
19:39:53 karimull efried: will look into that blueprint..
19:39:58 melwitt karimull: are you thinking this would be transparent to glance? like you would encrypt the image before uploading to glance using your nova keypair, for example, and then you'd like nova to decrypt it? we would need the private key for that though and we don't store them
19:40:16 karimull yes
19:40:47 dansmith that's where castellan or barbican comes in
19:41:04 dansmith nova gets a key the user provides there to decrypt
19:41:25 melwitt right.. ok
19:41:34 dansmith AFAIK, glance needs to look at the image when you upload it so it's not like you can do this without glance at all I think
19:41:43 dansmith unless there is some way to tell glance not to look at the image, but I'm not sure
19:42:17 karimull user will get the key from either barbican or from their own KMS and encrypt and upload the image with information in meta data , using that information and castellan libraries key will be retrieved for decryption of image
19:42:21 dansmith unless you care about hiding the boot content from everything other than nova, this is pretty easy to do internal to the image without a lot of fanfare
19:43:22 dansmith also, you'd probably want to make sure we don't cache the decrypted image, especially if the cache is on shared storage
19:43:27 dansmith gets out of hand pretty quick :)
19:43:44 karimull ok
19:46:29 karimull dansmith: wanted to decrypt the image at compute host before it is launched..is this possible?..if we can have hooks at libvirt or nova-compute level wanted to make it a plugin
19:46:43 dansmith karimull: we don't have plugins
19:47:02 dansmith we have some aging hooks that are slowly being removed from the code
19:47:35 dansmith but obviously doing the decryption on the compute host is where it would need to happen
19:49:28 karimull having a plugin kind of functionality will give user flexibility to use their own decryption process..hence look in that way..do we have any similar way to do it in Nova
19:50:00 karimull dansmith : looking*
19:50:24 dansmith we don't have plugins
19:55:39 dansmith mriedem: jaypipes: what's the fix for this? https://bugs.launchpad.net/nova/+bug/1793747
19:55:40 openstack Launchpad bug 1793747 in OpenStack Compute (nova) "Fails to boot instance using Blazar flavor if compute host names are in uppercase" [High,Triaged] - Assigned to Neha Alhat (nehaalhat)
19:58:26 dansmith I don't even think I get what the problem is
19:59:14 openstackgerrit Merged openstack/nova stable/ocata: Cleanup RP and HM records while deleting a compute service. https://review.openstack.org/603749
19:59:20 dansmith oh, I see, I was looking at the wrong thing.. we're lower()ing all the hostnames
20:02:12 dansmith s10: okay I got all those backports you tagged me on
20:04:08 s10 dansmith: thank you, finally we will get this fixes in queens after two month of waiting :)
20:04:27 dansmith s10: we just got a queens release this morning though right?
20:04:35 dansmith might already be time to queue up another one :)
20:06:43 mriedem and we just released that blazar regression https://review.openstack.org/#/c/585334/
20:07:04 jaypipes dansmith: the fix for this is not having such fragile friggin code? :(
20:07:04 mriedem dansmith: i don't know what the fix is for that bug
20:07:16 jaypipes fix one thing, breaks another. :(
20:07:23 dansmith jaypipes: yeah we should totes just depend on our backend database ignoring case for us :)
20:07:41 dansmith mriedem: we could try to lower() the hostname everywhere else, but I kinda think the original "fix" was broken
20:08:01 jaypipes dansmith: the user expects a case-insensitive search.
20:08:02 dansmith if they pass a hostname that is different from what the machine reports, they should expect it to not work
20:08:32 dansmith jaypipes: I don't
20:08:42 dansmith the aggregate code must not be validating hostnames when you go to add one right?

Earlier   Later