Earlier  
Posted Nick Remark
#openstack-nova - 2022-05-31
16:48:01 sean-k-mooney but it woudl be suffient for the app to bootsrap potenally by issueing an application credetial
16:48:25 levy14 sean-k-mooney: it was just a suggestion. or a way to describe what I expect to happen, don't know which project implements it. I thought I bring it up in nova, as it seems some sort of vm identity is needed for it to work
16:48:46 sean-k-mooney if you want the http request to be intercepted transparently you would need service function chaning or similar to implement that
16:49:08 sean-k-mooney levy14: that the thing vms dont have an identiy
16:49:14 sean-k-mooney they are owned by porjects
16:49:24 sean-k-mooney secrets are owned by users
16:49:28 levy14 sean-k-mooney: maybe they should start having one
16:49:46 sean-k-mooney perhaps
16:49:56 levy14 or secrets in barbican can be set up so that an entire project has access to them?
16:50:14 sean-k-mooney im not sure but that would still not allow nova to access them
16:50:33 sean-k-mooney services and cloud admins cannot acces barbican secrets
16:50:44 levy14 so the possibilities are:
16:50:48 sean-k-mooney that is doen intentiolly for improved security
16:51:01 levy14 1. metadata service
16:51:19 levy14 2. interception of network calls outgoing from a vm
16:52:30 sean-k-mooney those are two possiblities yes
16:52:42 levy14 any other?
16:52:49 sean-k-mooney for 1 you would have to define what the metadata service will provide the vm
16:53:03 levy14 and anyone sees this as a valuable feature for nova?
16:53:05 sean-k-mooney 2 is not in scope of nova
16:53:36 sean-k-mooney levy14: if it was done securly maybe.
16:53:52 sean-k-mooney but i also see it as a non trivial feature
16:54:11 jrosser_ i did some more looking at this after it was discussed ~ 1 week ago
16:54:22 levy14 sean-k-mooney: I am sure is non-trivial
16:54:53 jrosser_ and came to the same conclusion that there was no user associated with a VM so it was not possible to generate a usable token, even though it was possible to assert the identity of the vm
16:55:00 levy14 sean-k-mooney: but I see it very valuable to have
16:55:27 bauzas timebox : we only have 5 mins left
16:55:55 sean-k-mooney levy14: do you feel comfortable wrting a spec propsoal even an incomplete one with your usecases
16:56:09 sean-k-mooney levy14: and or would you be able to implement this with our guidance
16:56:11 bauzas yes, we should rather discuss this by a spec
16:56:31 levy14 sean-k-mooney: I can try writing an (incomplete) spec, I am not up to implement it myself
16:56:41 sean-k-mooney jrosser_: i could see us adding a --application-credetial or something to the api
16:57:00 sean-k-mooney jrosser_: i.e. you precreate one and tell nova to pass it to the guest via the metadtaa service
16:57:03 jrosser_ i think that spcifying a service user for a VM might be enough
16:57:40 jrosser_ anyway this is a rabbit hole and i don't want to disrupt your meeting
16:57:58 bauzas jrosser_: no worries, we don't have other discussions
16:58:47 bauzas at least, looks to me we have a consensus : levy14 will provide an incomplet spec or a backlog one
16:58:54 bauzas levy14: do you know about https://specs.openstack.org/openstack/nova-specs/specs/backlog/index.html ?
16:59:09 jrosser_ tldr was that other $clouds let you associate a service user (thats already in your project) with that VM, and that combined with a JWT from the metadata to auth against keystone would give you a token for that service user
16:59:36 bauzas anyway, we're at the last minute for our meeting
16:59:48 levy14 I saw the page, seemed convoluted. next week I'm at openinfra, but for the week after that I'll try to create a spec.
16:59:50 sean-k-mooney jrosser_: i think the closest thing to a service user we have in openstack in an application credential
17:00:46 bauzas levy14: ok, then, we're done today
17:00:54 bauzas thanks folks
17:00:56 opendevmeet Log: https://meetings.opendev.org/meetings/nova/2022/nova.2022-05-31-16.00.log.html
17:00:56 opendevmeet Minutes (text): https://meetings.opendev.org/meetings/nova/2022/nova.2022-05-31-16.00.txt
17:00:56 opendevmeet Minutes: https://meetings.opendev.org/meetings/nova/2022/nova.2022-05-31-16.00.html
17:00:56 opendevmeet Meeting ended Tue May 31 17:00:56 2022 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)
17:00:56 bauzas #endmeeting
17:01:12 bauzas sean-k-mooney: gibi: elodilles: fwiw, I'll be off tomorrow
17:01:13 elodilles thanks o/
17:01:19 elodilles bauzas: ack
17:01:21 sean-k-mooney bauzas: ack
17:01:38 sean-k-mooney bauzas: for rest of week or you back thursday
17:19:10 bauzas sean-k-mooney: no, only tomorrow
17:19:35 bauzas I have a few appointments so I thought it was better to just take one day off
17:20:24 sean-k-mooney bauzas: cool i did have one topic for the meeting but it can wait till next week
17:20:40 bauzas sean-k-mooney: which meeting ?
17:20:46 sean-k-mooney the nova one
17:20:46 bauzas the upstream nova one ?
17:20:51 sean-k-mooney ya
17:20:57 sean-k-mooney we didnt have time anyway
17:21:02 bauzas hah, we just said that we won't have a meeting next week
17:21:06 sean-k-mooney but i had a previous downstream meeting that ran over
17:21:14 sean-k-mooney oh well it can wai
17:21:17 sean-k-mooney *wait
17:21:19 bauzas sean-k-mooney: but if you want, you can run the meeting
17:21:21 sean-k-mooney its not urgent
17:21:33 sean-k-mooney no its fine i just wanted input on a patch
17:21:39 bauzas sean-k-mooney: this is just that gibi, stephenfin and me at least won't be around
17:22:08 sean-k-mooney bauzas: ya no worreis i frogot summit was next week
17:22:30 sean-k-mooney i was going to turn https://review.opendev.org/c/openstack/nova/+/842359 into a real patch with a release note
17:22:38 sean-k-mooney but wanted to get input form other before i do
17:22:46 sean-k-mooney i.e. is this somethign we want to do
17:22:52 sean-k-mooney before i spend time on it
17:23:40 bauzas hah
17:23:45 bauzas no worries
17:24:02 bauzas I understand your point and we can surely discuss this the other week
17:24:16 bauzas sean-k-mooney: just add your topic in the agenda in order to not forget it
17:25:36 sean-k-mooney sure will do
17:58:36 gibi away
17:58:44 gibi ehh
18:02:41 gibi bauzas: I can take the triage baton next week over a beer :)
18:36:22 opendevreview sean mooney proposed openstack/nova master: update nova to use black for code formating. https://review.opendev.org/c/openstack/nova/+/844120
18:42:43 sean-k-mooney i have run unit and functional test on that locally and they appear to pass so im pretty confident that there has been no effective code change in ^
18:43:25 sean-k-mooney black, pep8 and fast8 also pass and so does pre-commit
18:48:07 gibi sean-k-mooney: thanks
18:48:45 sean-k-mooney lol just realised it updated leet files 1337
18:49:23 sean-k-mooney in my somewhat biased opipion the code is more readable. im also not a black fangirl by any means its jut looks nicer to me
18:58:32 artom Are "Cinder multi-backend feature disabled" a known thing on stable/victoria?
19:45:14 sean-k-mooney am ping me tomorrow but im not sure what that means
19:45:36 sean-k-mooney i assume that is a tempest config option
20:06:02 gmann artom: it is enabled, it is enabled tempest-slow job and in cinder-tempest-lvm-multibackend which pass in victoria
#openstack-nova - 2022-06-01
00:05:12 opendevreview Artom Lifshitz proposed openstack/nova stable/victoria: Add a regression test for bug 1939545 https://review.opendev.org/c/openstack/nova/+/843948
00:05:13 opendevreview Artom Lifshitz proposed openstack/nova stable/victoria: compute: Ensure updates to bdms during pre_live_migration are saved https://review.opendev.org/c/openstack/nova/+/843949
00:19:02 opendevreview melanie witt proposed openstack/nova stable/train: Define new functional test tox env for placement gate to run https://review.opendev.org/c/openstack/nova/+/840777
05:35:57 opendevreview Steve Baker proposed openstack/nova master: Align ironic driver with libvirt secure boot enable https://review.opendev.org/c/openstack/nova/+/844243
08:44:02 opendevreview Rico Lin proposed openstack/nova master: libvirt: Ignore LibvirtConfigObject kwargs https://review.opendev.org/c/openstack/nova/+/830644
08:44:03 opendevreview Rico Lin proposed openstack/nova master: libvirt: Add vIOMMU device to guest https://review.opendev.org/c/openstack/nova/+/830646
08:44:03 opendevreview Rico Lin proposed openstack/nova master: libvirt: Remove unnecessary TODO https://review.opendev.org/c/openstack/nova/+/830645

Earlier   Later