| Posted | Nick | Remark | |
|---|---|---|---|
| #openstack-nova - 2022-11-10 | |||
| 14:17:48 | sean-k-mooney | yep hence why i was sugging adding it to the ptl/guide to make sur ethat they ensure there is an acitive admin and review the membership each cycle | |
| 14:18:30 | sean-k-mooney | so post elect old ptl adds new ptl and removes self if they dont want to continue reviewing secuirty isues | |
| 14:19:04 | sean-k-mooney | new ptl reviews membership and makes what ever updated make sense at start of their tenure | |
| 14:19:37 | sean-k-mooney | for ptlless project this can be delicated to secuirty liasion | |
| 14:21:46 | fungi | right, exactly | |
| 14:23:05 | frickler | tonyb is still around fwiw, but I think more active in requirements | |
| 14:23:29 | fungi | oh, you're right. he was gone for a couple of years but has returned to us recently | |
| 14:41:32 | sean-k-mooney | ya moved to openshift didnt like it and came back a few months ago i belive | |
| 17:00:37 | bauzas | fungi: sean-k-mooney: sorry folks, was missing the convo, surely we can discuss this between cores | |
| 17:01:09 | bauzas | in the meantime, you can add me in the nova-coresec team | |
| 17:23:31 | fungi | bauzas: will do now | |
| 17:25:15 | fungi | bauzas: you're a member and admin now, and can make whatever changes to that group you need | |
| 17:31:22 | bauzas | fungi: ack | |
| 17:31:25 | bauzas | thanks | |
| 17:31:58 | bauzas | fungi: DM me anytime you want me to look at something private | |
| 17:32:08 | bauzas | I could miss a reported bug | |
| 17:32:33 | fungi | yep, gladly | |
| 17:46:29 | melwitt | I didn't even know about https://launchpad.net/~nova-coresec/+members until just now 😂 | |
| 18:07:51 | sean-k-mooney | i only knew about it becasue when i have been added to security bugs in the past i noticed it was there | |
| 18:09:47 | bauzas | see ya | |
| 18:09:55 | sean-k-mooney | o/ | |
| 18:25:30 | opendevreview | sean mooney proposed openstack/nova master: [DMN] test removal of CAP_DAC_OVERRIDE https://review.opendev.org/c/openstack/nova/+/810906 | |
| #openstack-nova - 2022-11-11 | |||
| 00:17:17 | opendevreview | melanie witt proposed openstack/nova master: libvirt: Configure and teardown ephemeral encryption secrets https://review.opendev.org/c/openstack/nova/+/826754 | |
| 00:17:18 | opendevreview | melanie witt proposed openstack/nova master: imagebackend: Cache the key manager when disk is encrypted https://review.opendev.org/c/openstack/nova/+/826756 | |
| 00:17:18 | opendevreview | melanie witt proposed openstack/nova master: imagebackend: Add support to libvirt_info for LUKS based encryption https://review.opendev.org/c/openstack/nova/+/826755 | |
| 00:17:19 | opendevreview | melanie witt proposed openstack/nova master: Follow up changes for ephemeral encryption https://review.opendev.org/c/openstack/nova/+/853254 | |
| 00:17:19 | opendevreview | melanie witt proposed openstack/nova master: libvirt: Introduce support for qcow2 with LUKS https://review.opendev.org/c/openstack/nova/+/772273 | |
| 00:30:36 | opendevreview | melanie witt proposed openstack/nova master: DNM test ephemeral encryption + resize: qcow2, raw https://review.opendev.org/c/openstack/nova/+/862416 | |
| 01:01:37 | opendevreview | melanie witt proposed openstack/nova master: Follow up changes for ephemeral encryption https://review.opendev.org/c/openstack/nova/+/853254 | |
| 01:01:37 | opendevreview | melanie witt proposed openstack/nova master: libvirt: Introduce support for qcow2 with LUKS https://review.opendev.org/c/openstack/nova/+/772273 | |
| 01:55:09 | opendevreview | melanie witt proposed openstack/nova master: libvirt: Introduce support for qcow2 with LUKS https://review.opendev.org/c/openstack/nova/+/772273 | |
| 02:19:16 | opendevreview | melanie witt proposed openstack/nova master: Follow up changes for ephemeral encryption https://review.opendev.org/c/openstack/nova/+/853254 | |
| 04:28:50 | opendevreview | melanie witt proposed openstack/nova master: libvirt: Introduce support for qcow2 with LUKS https://review.opendev.org/c/openstack/nova/+/772273 | |
| 05:59:25 | opendevreview | melanie witt proposed openstack/nova master: DNM test ephemeral encryption + resize: qcow2, raw https://review.opendev.org/c/openstack/nova/+/862416 | |
| 10:42:41 | opendevreview | Rajesh Tailor proposed openstack/nova master: Correct config help message related options https://review.opendev.org/c/openstack/nova/+/864259 | |
| 14:47:03 | opendevreview | Merged openstack/nova master: Correct config help message related options https://review.opendev.org/c/openstack/nova/+/864259 | |
| 16:03:20 | dansmith | sean-k-mooney: gmann: can we get this landed? | |
| 16:03:55 | dansmith | this makes us actually use a raw image for ceph like we're supposed to do, and also inflates it to the larger size | |
| 16:04:18 | dansmith | which already pressurized something that works fine with 16MB images (swap on the worker) | |
| 16:04:45 | dansmith | glance is planning a new locations API this cycle and I want to make sure we're testing that with a non-trivial-sized real image | |
| 16:05:58 | sean-k-mooney | dansmith: link? | |
| 16:06:09 | dansmith | lol paste fail | |
| 16:06:10 | dansmith | https://review.opendev.org/c/openstack/nova/+/860864 | |
| 16:18:12 | sean-k-mooney | ya that looks fine to me | |
| 17:30:37 | gmann | dansmith: +A, lgtm. i was waiting for devstack patch but ok with doing it in playbook itself | |
| 17:30:48 | dansmith | thanks | |
| 19:12:17 | opendevreview | Merged openstack/nova master: Test ceph-multistore with a real image https://review.opendev.org/c/openstack/nova/+/860864 | |
| #openstack-nova - 2022-11-12 | |||
| 06:12:48 | opendevreview | melanie witt proposed openstack/nova master: libvirt: Introduce support for qcow2 with LUKS https://review.opendev.org/c/openstack/nova/+/772273 | |
| #openstack-nova - 2022-11-14 | |||
| 03:35:35 | opendevreview | Ghanshyam proposed openstack/nova-specs master: Policy service role spec https://review.opendev.org/c/openstack/nova-specs/+/864379 | |
| 03:51:09 | opendevreview | Jorhson Deng proposed openstack/nova master: Remove the redundance code in HostState.update https://review.opendev.org/c/openstack/nova/+/864274 | |
| 03:53:20 | opendevreview | Jorhson Deng proposed openstack/nova master: Remove the redundance code in HostState.update https://review.opendev.org/c/openstack/nova/+/864274 | |
| 03:56:52 | opendevreview | Jorhson Deng proposed openstack/nova master: Remove the redundance code in HostState.update https://review.opendev.org/c/openstack/nova/+/864275 | |
| 05:19:59 | opendevreview | Ghanshyam proposed openstack/placement master: Policy defaults improvement spec https://review.opendev.org/c/openstack/placement/+/864385 | |
| 08:45:31 | Uggla | Good morning nova | |
| 08:59:43 | sahid | o/ | |
| 09:00:46 | sahid | sean-k-mooney, bauzas anything missing regarding evacuate feature? do you think you will be able to have look on it for this release? | |
| 09:05:52 | sahid | feel free to let me know if i can be helpful on anything | |
| 09:32:07 | gibi | o/ | |
| 09:59:19 | bauzas | sahid: I'll look at your spec tomorrow | |
| 10:02:41 | sahid | cool thank you bauzas | |
| 10:03:15 | bauzas | sahid: as a reminder, we'll have our spec review day tomorrow, so just make sure to look at the new comments tomorrow afternoon if you can | |
| 10:49:40 | sahid_ | bauzas: sure ACK | |
| 13:04:06 | opendevreview | Takashi Natsume proposed openstack/nova master: Add a hacking rule for the setDaemon method https://review.opendev.org/c/openstack/nova/+/854653 | |
| 15:19:49 | opendevreview | Sylvain Bauza proposed openstack/nova master: Handle mdev devices in libvirt 7.7+ https://review.opendev.org/c/openstack/nova/+/838976 | |
| 15:19:49 | opendevreview | Sylvain Bauza proposed openstack/nova master: Reproducer for bug 1951656 https://review.opendev.org/c/openstack/nova/+/850673 | |
| 15:19:50 | opendevreview | Sylvain Bauza proposed openstack/nova master: Deprecate mdev creation and hardfail on reboot when missing. https://review.opendev.org/c/openstack/nova/+/864418 | |
| 15:38:47 | opendevreview | ribaudr proposed openstack/nova-specs master: Allow local scaphandre directory to be mapped to an instance using virtiofs https://review.opendev.org/c/openstack/nova-specs/+/861881 | |
| 16:14:55 | opendevreview | ribaudr proposed openstack/nova-specs master: Allow local scaphandre directory to be mapped to an instance using virtiofs https://review.opendev.org/c/openstack/nova-specs/+/861881 | |
| 19:33:21 | gmann | dansmith: can you review these specs related to RBAC (service role for nova and dropping system scope for placement) https://review.opendev.org/c/openstack/nova-specs/+/864379 https://review.opendev.org/c/openstack/placement/+/864385 | |
| 19:34:21 | gmann | dansmith: also can you help to understand placement APIs, they should be consider as internal APIs or external? I am considering later and not proposing service role to them | |
| 19:41:56 | dansmith | gmann: hmm, well, | |
| 19:42:07 | dansmith | we kinda want people to use placement for some things, mostly admin-related though | |
| 19:42:18 | dansmith | but it's very much internal other than that | |
| 19:42:34 | dansmith | nova should use an account with the service role to talk to placement I think | |
| 19:43:26 | gmann | dansmith: so we need to keep policy open for admin-or-service role. or there are few APIs we can keep only service role ? | |
| 19:44:35 | dansmith | gmann: we probably need to review.. the problem is that when something goes wrong, an admin deleting a stale allocation or something can be required, | |
| 19:44:50 | dansmith | and even things like allocation candidates can be useful for admins | |
| 19:45:14 | dansmith | so yeah I think probably admin-or-service for much of it probably makes sense, but we should probably review all the rules to be sure | |
| 19:45:52 | sean-k-mooney | so admin-or-service makes sense for things like the external events api | |
| 19:46:05 | sean-k-mooney | but things like the host-aggrates api should be admin only | |
| 19:46:28 | gmann | ok, I think spec is ok then and we can review every rule while doing code change | |
| 19:46:33 | sean-k-mooney | the os-assisated-volume-extend api would also be admin-or-service | |
| 19:46:54 | gmann | sean-k-mooney: we are making them as service role only - this is for nova https://review.opendev.org/c/openstack/nova-specs/+/864379 | |
| 19:47:14 | sean-k-mooney | service only would work but it has an upgrade impact | |
| 19:47:22 | gmann | I think I covered all internal APIs there but if anything missing please comment | |
| 19:47:26 | sean-k-mooney | so service only woudl be be the end state we woudl like | |
| 19:47:31 | gmann | yeah | |
| 19:47:55 | dansmith | sean-k-mooney: he's asking about placement | |
| 19:47:59 | sean-k-mooney | im fine with service only by the way if its behind the new default falg | |
| 19:48:04 | sean-k-mooney | oh placment | |
| 19:48:34 | sean-k-mooney | thats a more interesting case | |
| 19:49:09 | sean-k-mooney | im kind fo conflicted | |
| 19:49:56 | sean-k-mooney | on one hand it would be nice to be able to use placment standalone but if we ignore that usecase | |
| 19:50:44 | sean-k-mooney | the allcoations endpoint proaably shoudl be service only however we would stant nova-manage heal allcotions to still work | |
| 19:51:02 | sean-k-mooney | perhaps readonly access for admin | |
| 19:51:39 | sean-k-mooney | i dont know. admin-or-service could be applied ot all the admin apis as a first step but i dont knwo if we want to prevent an admin form doing some things | |
| 19:52:45 | sean-k-mooney | like im tempeted to say the rp and invetory create/update apis shoudl be service only but we allow admins to add traits via the api or tweak the allcoation ratios | |
| 19:53:25 | sean-k-mooney | the reshape api proably shoudl be service only but im not sure any others fall into that | |
| 19:53:31 | sean-k-mooney | usecase | |
| 19:54:49 | dansmith | admins deleting stale allocations though... | |