Earlier  
Posted Nick Remark
#openstack-nova - 2019-11-25
15:07:32 fungi right, unfortunately i think due to their limited bandwidth they're going to focus on boot-from-volume for now and revisit support in nova later
15:07:43 openstackgerrit Matt Riedemann proposed openstack/nova stable/stein: Improve metadata server performance with large security groups https://review.opendev.org/695925
15:08:09 sean-k-mooney fungi: my understading is cidner does not currently support booting form an encyped volume either
15:08:34 fungi right, but they're up for moving forward on the spec to add that
15:08:36 sean-k-mooney fungi: mdbooth mentioned somting about that being inded for cinder backups but nova vms
15:08:58 sean-k-mooney *intended
15:09:15 fungi ahh, i'll take a closer look at the cinder spec to confirm
15:09:16 sean-k-mooney *not for nova vms
15:09:26 fungi thanks again
15:09:35 lyarwood sean-k-mooney: we can boot from an encrypted volume
15:10:21 sean-k-mooney lyarwood: ok but is that only with ceph
15:10:34 lyarwood and yeah, we need to kill off the existing ephemeral disk encryption support in the Libvirt driver before we reintroduce a sane version tbh
15:10:36 sean-k-mooney with isci the volume wouls be mounted on the host
15:10:40 lyarwood sean-k-mooney: nope, that's pretty much any backend
15:10:47 lyarwood sean-k-mooney: nope, that's native
15:11:02 lyarwood sean-k-mooney: native allowed us to support rbd encrypted volumes for the first time
15:11:19 lyarwood sean-k-mooney: everything else was already supported and just switched to being native within QEMU in Queens
15:11:32 sean-k-mooney lyarwood: ok
15:12:07 aarents mriedem: hi, can you confirm that commit message is ok like tht https://review.opendev.org/#/c/670000/ it was the last blocking point.
15:12:20 sean-k-mooney but we do still mont the voluems on the host via the kernel right they are just but encypeted?
15:12:29 sean-k-mooney lyarwood: im asking because fo the local caching spec
15:13:31 sean-k-mooney that was implying that iscsi based volumes are mounted on the host and passed to qemu as a block deice wo they could add a caching layer
15:13:55 lyarwood sean-k-mooney: yeah so for iSCSI/LVM etc we still end up with host devices but these are never decrypted on the host now
15:14:04 sean-k-mooney i assume we use qemus native encryption support to use the encyped volumes form teh host
15:14:13 sean-k-mooney cool
15:14:46 sean-k-mooney fungi: so basicly we would like to get to the same state for non boot form volume guests
15:18:38 mriedem lyarwood: do we even have *any* in-tree docs about encryption features in nova today?
15:18:56 mriedem would probably be good to level set from there
15:19:23 lyarwood mriedem: do releasenotes count /s
15:19:27 mriedem no
15:19:33 lyarwood aww, okay then no
15:19:40 lyarwood mriedem: and yeah that's a valid point
15:19:45 mriedem i hope you already knew the answer to that
15:20:38 lyarwood mriedem: https://www.urbandictionary.com/define.php?term=%2Fs yarp I did sorry
15:21:14 mriedem you should have jk lol'ed me with a winking smiley
15:21:18 mriedem that's more my speed
15:21:50 fungi lyarwood: sean-k-mooney: mriedem: thanks a bunch, that's all very useful info
15:22:22 lyarwood I'll fire a few roflcopters next time mriedem :)
15:22:46 fungi and a lolercoaster for good measure?
15:23:06 lyarwood rude not to
15:24:14 mriedem lol ;P
15:34:44 mriedem aarents: dansmith: +2 https://review.opendev.org/#/c/670000/
15:41:27 openstack bug 1829479 in OpenStack Compute (nova) "The allocation table has residual records when instance is evacuated and the source physical node is removed" [Medium,In progress] https://launchpad.net/bugs/1829479 - Assigned to Matt Riedemann (mriedem)
15:41:27 openstackgerrit Matt Riedemann proposed openstack/nova stable/stein: Add functional recreate test for bug 1829479 and bug 1817833 https://review.opendev.org/695932
15:41:28 openstack bug 1817833 in OpenStack Compute (nova) "Check compute_id existence when nova-compute reports info to placement" [Medium,In progress] https://launchpad.net/bugs/1817833 - Assigned to Matt Riedemann (mriedem)
15:45:39 openstackgerrit Eric Fried proposed openstack/nova master: DNM: Test openstacksdk weakrefs https://review.opendev.org/695934
15:48:57 openstack bug 1852610 in OpenStack Compute (nova) stein "API allows source compute service/node deletion while instances are pending a resize confirm/revert" [Undecided,New] https://launchpad.net/bugs/1852610
15:48:57 openstackgerrit Matt Riedemann proposed openstack/nova stable/stein: Add functional recreate test for bug 1852610 https://review.opendev.org/695935
15:53:03 openstack bug 1852610 in OpenStack Compute (nova) stein "API allows source compute service/node deletion while instances are pending a resize confirm/revert" [Undecided,New] https://launchpad.net/bugs/1852610
15:53:03 openstackgerrit Matt Riedemann proposed openstack/nova stable/stein: Add functional recreate revert resize test for bug 1852610 https://review.opendev.org/695938
16:14:07 openstackgerrit Matt Riedemann proposed openstack/nova stable/stein: Block deleting compute services with in-progress migrations https://review.opendev.org/695940
16:21:55 openstackgerrit Kashyap Chamarthy proposed openstack/nova master: libvirt: Remove MIN_{LIBVIRT,QEMU}_FILE_BACKED_VERSION https://review.opendev.org/695942
16:30:09 aarents mriedem: thanks
16:38:05 mriedem could i get a couple of stable cores to look at these https://review.opendev.org/#/q/topic:bug/1849409+branch:stable/rocky ?
16:40:54 lyarwood mriedem: ack looking
16:43:58 openstackgerrit Stephen Finucane proposed openstack/nova master: nova-net: Remove 'nova-network' binary https://review.opendev.org/686816
16:43:58 openstackgerrit Stephen Finucane proposed openstack/nova master: nova-net: Remove 'nova-dhcpbridge' binary https://review.opendev.org/686815
16:43:59 openstackgerrit Stephen Finucane proposed openstack/nova master: nova-net: Remove associate, disassociate network APIs https://review.opendev.org/686814
16:43:59 openstackgerrit Stephen Finucane proposed openstack/nova master: docs: Blast most references to nova-network https://review.opendev.org/686817
16:44:00 openstackgerrit Stephen Finucane proposed openstack/nova master: WIP https://review.opendev.org/686818
16:48:12 gibi sean-k-mooney: heads up, as the neutron meeting is at the US slot this week I won't be awake
16:51:48 lyarwood stephenfin: https://review.opendev.org/#/q/topic:bug/1853495 - would you mind taking a look at this today if you have time?
16:52:48 stephenfin yup, burning through some reviews atm
16:54:38 mriedem lyarwood: questoin in that nova change
16:55:39 lyarwood mriedem: I think the ref is wrong or cinderclient changes it, let me grep around and confirm.
16:58:08 lyarwood mriedem: https://github.com/openstack/nova/blob/6fea2682364cddf66c499936a8c66895ef94dd5b/nova/volume/cinder.py#L313 - my bad, it's us.
16:58:09 mriedem https://github.com/openstack/cinder/blob/62b69b51aab32500d3aa76677011f9db4bf4c14c/cinder/api/v2/views/volumes.py#L81
16:58:17 stephenfin lyarwood, mriedem: looks like we do funky stuff in nova/volume/cinder.py via '_untranslate_volume_summary_view'
16:58:19 mriedem ah
16:58:20 stephenfin nice
17:05:13 openstackgerrit Merged openstack/nova master: api-guide: flesh out flavor extra specs and image properties https://review.opendev.org/695776
17:05:19 openstackgerrit Merged openstack/nova master: api-guide: flesh out networking concepts https://review.opendev.org/695777
17:05:25 openstackgerrit Merged openstack/nova master: api-guide: flesh out todos in user doc https://review.opendev.org/695778
17:06:08 mriedem lyarwood: some questions in there
17:06:44 lyarwood mriedem: looking
17:07:24 mriedem so volume_type on volume create is optional and if not specified the cinder scheduler picks one (and there is a default backend),
17:07:44 mriedem the api-ref talks a bit about when volume_type is required but doesn't mention for encrypted volumes built from snapshots, which volume_type is clearly required due to the bug
17:08:05 mriedem i'm just wondering if we should only pass the volume_type if the original volume was encrypted=True
17:09:16 mriedem i might have answered my own question though,
17:09:25 mriedem i don't think you can delete a volume type in cinder while there are volumes using it,
17:09:32 mriedem and i don't think you can delete a volume that has snapshots
17:09:34 lyarwood yeah you can't I was just checking that
17:09:34 mriedem smcginnis: ^?
17:09:49 lyarwood and again yes AFAIK you can't remove volumes with snapshots
17:10:09 lyarwood so copying over volume_type from the original if one isn't provided should be safe
17:10:17 mriedem so maybe this is fine and if it turns out there is some weird problem later we fix that as necessary
17:10:45 mriedem i'm guessing you'll want to backport this too so hopefully we're all good
17:11:51 lyarwood yup indeed, I tried to keep it as self contained as possible
17:18:03 smcginnis mriedem: Correct.
17:18:16 smcginnis Don't have the full context here, but the plan described sounds good to me.
17:30:18 openstackgerrit Ghanshyam Mann proposed openstack/nova master: Add test coverage of existing os-services policies https://review.opendev.org/669181
17:32:33 openstackgerrit Merged openstack/nova stable/stein: Use admin neutron client to see if instance has qos ports https://review.opendev.org/694668
17:40:44 mriedem stephenfin: you should fix this in your series somewhere https://review.opendev.org/#/c/686816/12/doc/source/install/get-started-compute.rst@28
17:45:37 openstackgerrit Ghanshyam Mann proposed openstack/nova master: Introduce scope_types in os-services https://review.opendev.org/645427
17:52:05 gmann johnthetubaguy: did not get this comment. we can re-use the check_str itself - https://review.opendev.org/#/c/645452/14/nova/policies/base.py@69
17:53:34 johnthetubaguy gmann: the use case I was thinking about is having a nova specific read only role, its nice if that only needs one rule changing
17:57:39 openstackgerrit John Garbutt proposed openstack/nova master: WIP: Enforce unified limits using oslo.limit https://review.opendev.org/615180
17:59:39 gmann johnthetubaguy: and the currently defined check_str like SYSTEM_READER use those rule instead of direct check_str ?
18:04:18 gmann johnthetubaguy: got it. i did not think the override case.
18:05:09 johnthetubaguy gmann: no worries, we could in theory add it later, but probably good to add it from the start

Earlier   Later