Earlier  
Posted Nick Remark
#openstack-nova - 2020-10-29
17:06:29 sean-k-mooney but you could propose a new feature for it. its not a bug that it does not do it today however
17:07:34 sean-k-mooney legochen: filtering az by availablity would be an api change and would need a spec
17:07:58 sean-k-mooney legochen: normally you would do it via host aggreates and then tell your users to not specify an az
17:08:08 sean-k-mooney legochen: with aggreates you can make it transparent
17:08:33 sean-k-mooney az are really ment to be useable by all users
17:10:13 legochen As OpenStack has the ability to provide multi-tenancy use case. But, seems hard to do access-control for resources when we use only one control plane.
17:11:09 sean-k-mooney legochen: well the point is you shoudl not be doing access contol via AZs
17:11:20 sean-k-mooney you shoudl be doing that with host aggreates
17:11:23 legochen thanks sean for the information. I’m still new to openstack, this is my first week to join openstack IRC. not that sure the process to discuss the requirements or features.
17:12:08 sean-k-mooney AZs in openstack are very different the AZs in aws or other cloud plathforms
17:12:33 sean-k-mooney they are really just a host aggreate with a metadta key set to give them an az name
17:12:56 sean-k-mooney as a result we dont really have a way to eaislly add rbac style filtering on them
17:12:56 melwitt yeah, AZ are a user-facing grouping mechanism
17:13:45 sean-k-mooney it could be done but partioning of the cloud is ment to be somethign the operator know about rather then the user
17:13:49 melwitt "host aggregates" are the access-control-based counterparts that nova uses underneath. and an AZ can be composed of one or more host aggregates
17:13:58 legochen I have came up with this doc - I’m going to use domain to manage differet kind of users. I’m looking for a feature support that can do access control by “domain” level instead of only by “project” level. https://docs.google.com/document/d/1Cv3FB3HLc70o4EcFh9aLxzPVszRgulkADnmJxmT65a8/edit#
17:14:28 sean-k-mooney legochen: this has come up before
17:14:33 sean-k-mooney last cycle
17:14:49 sean-k-mooney i can recal exactly what we discussed but nova has no concept of a domain
17:15:01 sean-k-mooney legochen: domain exist only in keystone not other services
17:15:12 melwitt legochen: here is a helpful doc that explains AZ vs host aggregate https://docs.openstack.org/nova/latest/admin/aggregates.html
17:16:11 legochen sean-k-mooney: legochen: domain exist only in keystone not other services. <= but, have future plan for other services for supporting that?
17:16:32 sean-k-mooney legochen: no
17:16:41 sean-k-mooney not that im aware of
17:18:12 legochen oh no…….hmm, just thinking if OpenStack could support both doamin/project based access control, it really add more flexibility for OpenStack admin to manage multiple organizations :)
17:18:27 sean-k-mooney the best solution i can think off quickly would be to use https://docs.openstack.org/nova/latest/reference/isolate-aggregates.html
17:18:58 sean-k-mooney and then add a prefilter to translate a users domain into a CUSTOM_DOMAIN_<domain> trait
17:19:41 sean-k-mooney legochen: it would be a lot of work to do and it might cause issue with keystone federation if all service had to support domain directly
17:20:11 sean-k-mooney using isolated aggreate with a prefilter to do the domain to trait traslation would be a very small change
17:20:26 sean-k-mooney and it would work i think in most cases
17:21:40 sean-k-mooney its basically what https://docs.openstack.org/nova/latest/admin/aggregates.html#tenant-isolation-with-placement does
17:21:48 sean-k-mooney but based on domains not project ids
17:21:59 legochen thanks, … keystone brings up the domain feature, but, only for authentication stuff, not actually use it for management services. seems not that logical :(
17:22:01 sean-k-mooney im prettysure that is what we said to do at the last ptg
17:22:50 sean-k-mooney legochen: domains are really a way of providing limit admin to people so they can manage flavor/quotas within that domain
17:24:23 sean-k-mooney legochen: if you were to do it the way im proposing you would basicaly copy paste https://github.com/openstack/nova/blob/master/nova/scheduler/request_filter.py#L91-L132
17:24:35 sean-k-mooney and replace the project id with the domain
17:25:14 sean-k-mooney well really the TENANT_METADATA_KEY with a DOMAIN_METADATA_KEY
17:26:15 openstackgerrit Ghanshyam Mann proposed openstack/nova master: Modify glance's copy_image permission for nova-ceph-multistore https://review.opendev.org/760422
17:26:48 sean-k-mooney so in https://github.com/openstack/nova/blob/master/nova/scheduler/request_filter.py#L107-L114 just swap project_id for the domain and TENANT_METADATA_KEY for DOMAIN_METADATA_KEY and the rest is more or less the same
17:27:04 sean-k-mooney legochen: its less then 100 lines fo code + tests and docs
17:27:31 openstackgerrit Ghanshyam Mann proposed openstack/nova master: DNM: testing copy private image with admin https://review.opendev.org/760128
17:27:40 sean-k-mooney but the important thing is you woudl be useing aggreate not AZs to map domains to hosts
17:28:39 sean-k-mooney legochen: if this is something you really need i woudl suggest addign it to https://etherpad.opendev.org/p/nova-wallaby-ptg so we can discuss it tommorow in the ptg
17:28:48 legochen yeah, but is it possible to let error promot could happen when users specify to a AZ that they don’t have permission to access?
17:29:16 legochen thank you sean :)
17:29:20 sean-k-mooney well they will get a novalid host error today
17:29:56 sean-k-mooney we could add an api check maybe it would have too check the aggreate metadata but that is proably ok
17:30:09 legochen hmm, no valid host could be caused by multiple reasons.
17:30:20 sean-k-mooney :) yes
17:30:54 sean-k-mooney gmann: do we need a microverion to convert no valid host into something else basically a 400 or 403
17:31:27 sean-k-mooney legochen: i think if we added the api check we coudl only do it with a new microversion so request with teh old microversion would not be checked
17:32:21 gmann sean-k-mooney: no as long as it return any existing error code (like 400 and 403).
17:32:23 sean-k-mooney based on https://docs.openstack.org/nova/latest/contributor/microversions.html#when-do-i-need-a-new-microversion
17:32:34 gmann we convert it to 200 or new error code then yes
17:32:38 legochen that would be great to clearly explain what’s going on in the error message :) do you think it is worth to do
17:33:01 sean-k-mooney gmann: today it would be a 200 but then later it will fail with no valid host
17:33:08 sean-k-mooney the az filter would block it
17:33:18 sean-k-mooney so it would be a 200 to 400 or 403
17:33:23 sean-k-mooney on server create
17:34:11 sean-k-mooney legochen: gmann lets talk about this in the ptg tomorow if we have time
17:34:55 gmann sean-k-mooney: i see then we need microversion bump hoping server creation happening successfully previously
17:35:21 legochen okay, I’ll attend.
17:35:22 gmann sean-k-mooney: I will be in TC sessions tomorrow but discussing in PTG good idea
17:35:46 sean-k-mooney gmann: it would need a spec in anycase
17:36:12 gmann yeah
17:37:29 sean-k-mooney it would be very similar to https://github.com/openstack/nova/commit/732e202e81142a8ea462a9ebcde9a7226a62a60b
17:37:49 sean-k-mooney except based on domains not project_ids but otherwise identical
17:41:26 sean-k-mooney added right at the end of https://etherpad.opendev.org/p/nova-wallaby-ptg
17:41:44 sean-k-mooney legochen: ^ line 862 currently.
17:41:56 sean-k-mooney legochen: feel free to add addtional detail
17:42:43 legochen okay, will do in the morning, it is about 2:00am in my time :)
17:42:49 legochen ttyl
17:43:23 legochen and thank you!
19:59:53 openstackgerrit Ade Lee proposed openstack/nova master: Replace md5 with oslo version https://review.opendev.org/756434
20:38:58 openstackgerrit Lee Yarwood proposed openstack/nova-specs master: WIP/DNM - Image defined ephemeral storage encryption https://review.opendev.org/752284
20:55:01 openstack bugzilla.redhat.com bug 1884920 in openssh "Cannot ssh into CentOS 6 using ssh key authentication" [Low,Closed: notabug] - Assigned to jjelen
20:55:01 lyarwood PSA for anyone upgrading to F33, you will need https://bugzilla.redhat.com/show_bug.cgi?id=1884920#c2
20:57:56 openstackgerrit Lee Yarwood proposed openstack/nova master: WIP image_meta: Add ephemeral encryption properties https://review.opendev.org/760454
20:57:56 openstackgerrit Lee Yarwood proposed openstack/nova master: WIP Add encryption fields to BlockDeviceMapping https://review.opendev.org/760453
20:57:57 openstackgerrit Lee Yarwood proposed openstack/nova master: WIP scheduler: Add an ephemeral encryption pre filter https://review.opendev.org/760456
20:57:57 openstackgerrit Lee Yarwood proposed openstack/nova master: WIP virt: Add ephemeral encryption flag https://review.opendev.org/760455
22:20:06 sean-k-mooney lyarwood: wait why are rsa keys not accepted
22:21:58 sean-k-mooney oh its just rsa with sha1
22:22:59 sean-k-mooney rsa-sha2-512/256 should be accpeted
22:23:15 openstack bugzilla.redhat.com bug 1881301 in openssh "openssh-clients do not accept PubkeyAcceptedKeyTypes rsa-sha2-512/256" [Unspecified,Post] - Assigned to jjelen
22:23:15 sean-k-mooney https://bugzilla.redhat.com/show_bug.cgi?id=1881301 really does seam like a bug
22:24:39 sean-k-mooney ECDSA isnt nessisarlly more secure then rsa dpening on the key lenght
22:30:41 sean-k-mooney NIST SP800-90 Dual Ec for example should not be used https://en.wikipedia.org/wiki/Dual_EC_DRBG
22:38:39 sean-k-mooney https://en.wikipedia.org/wiki/EdDSA#Ed25519 and https://en.wikipedia.org/wiki/Curve448 are secure and standraised in https://tools.ietf.org/html/rfc7748 i assume fedora has disabled the orginil nist algortiom
#openstack-nova - 2020-10-30
03:05:49 openstackgerrit Shi Yan proposed openstack/nova master: Remove unused bindir config option https://review.opendev.org/760331
03:52:24 openstackgerrit wu.shiming proposed openstack/os-vif master: Remove the unused coding style modules https://review.opendev.org/760491
04:33:49 openstackgerrit Shi Yan proposed openstack/nova master: Remove unused bindir config option https://review.opendev.org/760331
07:30:47 openstackgerrit Xinran WANG proposed openstack/nova-specs master: SRIOV Enabled Nic Support Specification https://review.opendev.org/742785
08:00:33 bauzas good morning Nova
08:10:12 gibi good morning
09:12:31 openstackgerrit Balazs Gibizer proposed openstack/nova master: Prevent starting services with older than N-1 computes https://review.opendev.org/738482
09:17:31 gibi dansmith: updated for W ^^
09:44:51 openstackgerrit Balazs Gibizer proposed openstack/nova master: Add upgrade check about old computes https://review.opendev.org/760520
09:46:00 gibi dansmith: and here is the related upgrade check ^

Earlier   Later