| Posted | Nick | Remark | |
|---|---|---|---|
| #openstack-nova - 2022-11-10 | |||
| 17:31:58 | bauzas | fungi: DM me anytime you want me to look at something private | |
| 17:32:08 | bauzas | I could miss a reported bug | |
| 17:32:33 | fungi | yep, gladly | |
| 17:46:29 | melwitt | I didn't even know about https://launchpad.net/~nova-coresec/+members until just now 😂 | |
| 18:07:51 | sean-k-mooney | i only knew about it becasue when i have been added to security bugs in the past i noticed it was there | |
| 18:09:47 | bauzas | see ya | |
| 18:09:55 | sean-k-mooney | o/ | |
| 18:25:30 | opendevreview | sean mooney proposed openstack/nova master: [DMN] test removal of CAP_DAC_OVERRIDE https://review.opendev.org/c/openstack/nova/+/810906 | |
| #openstack-nova - 2022-11-11 | |||
| 00:17:17 | opendevreview | melanie witt proposed openstack/nova master: libvirt: Configure and teardown ephemeral encryption secrets https://review.opendev.org/c/openstack/nova/+/826754 | |
| 00:17:18 | opendevreview | melanie witt proposed openstack/nova master: imagebackend: Cache the key manager when disk is encrypted https://review.opendev.org/c/openstack/nova/+/826756 | |
| 00:17:18 | opendevreview | melanie witt proposed openstack/nova master: imagebackend: Add support to libvirt_info for LUKS based encryption https://review.opendev.org/c/openstack/nova/+/826755 | |
| 00:17:19 | opendevreview | melanie witt proposed openstack/nova master: Follow up changes for ephemeral encryption https://review.opendev.org/c/openstack/nova/+/853254 | |
| 00:17:19 | opendevreview | melanie witt proposed openstack/nova master: libvirt: Introduce support for qcow2 with LUKS https://review.opendev.org/c/openstack/nova/+/772273 | |
| 00:30:36 | opendevreview | melanie witt proposed openstack/nova master: DNM test ephemeral encryption + resize: qcow2, raw https://review.opendev.org/c/openstack/nova/+/862416 | |
| 01:01:37 | opendevreview | melanie witt proposed openstack/nova master: Follow up changes for ephemeral encryption https://review.opendev.org/c/openstack/nova/+/853254 | |
| 01:01:37 | opendevreview | melanie witt proposed openstack/nova master: libvirt: Introduce support for qcow2 with LUKS https://review.opendev.org/c/openstack/nova/+/772273 | |
| 01:55:09 | opendevreview | melanie witt proposed openstack/nova master: libvirt: Introduce support for qcow2 with LUKS https://review.opendev.org/c/openstack/nova/+/772273 | |
| 02:19:16 | opendevreview | melanie witt proposed openstack/nova master: Follow up changes for ephemeral encryption https://review.opendev.org/c/openstack/nova/+/853254 | |
| 04:28:50 | opendevreview | melanie witt proposed openstack/nova master: libvirt: Introduce support for qcow2 with LUKS https://review.opendev.org/c/openstack/nova/+/772273 | |
| 05:59:25 | opendevreview | melanie witt proposed openstack/nova master: DNM test ephemeral encryption + resize: qcow2, raw https://review.opendev.org/c/openstack/nova/+/862416 | |
| 10:42:41 | opendevreview | Rajesh Tailor proposed openstack/nova master: Correct config help message related options https://review.opendev.org/c/openstack/nova/+/864259 | |
| 14:47:03 | opendevreview | Merged openstack/nova master: Correct config help message related options https://review.opendev.org/c/openstack/nova/+/864259 | |
| 16:03:20 | dansmith | sean-k-mooney: gmann: can we get this landed? | |
| 16:03:55 | dansmith | this makes us actually use a raw image for ceph like we're supposed to do, and also inflates it to the larger size | |
| 16:04:18 | dansmith | which already pressurized something that works fine with 16MB images (swap on the worker) | |
| 16:04:45 | dansmith | glance is planning a new locations API this cycle and I want to make sure we're testing that with a non-trivial-sized real image | |
| 16:05:58 | sean-k-mooney | dansmith: link? | |
| 16:06:09 | dansmith | lol paste fail | |
| 16:06:10 | dansmith | https://review.opendev.org/c/openstack/nova/+/860864 | |
| 16:18:12 | sean-k-mooney | ya that looks fine to me | |
| 17:30:37 | gmann | dansmith: +A, lgtm. i was waiting for devstack patch but ok with doing it in playbook itself | |
| 17:30:48 | dansmith | thanks | |
| 19:12:17 | opendevreview | Merged openstack/nova master: Test ceph-multistore with a real image https://review.opendev.org/c/openstack/nova/+/860864 | |
| #openstack-nova - 2022-11-12 | |||
| 06:12:48 | opendevreview | melanie witt proposed openstack/nova master: libvirt: Introduce support for qcow2 with LUKS https://review.opendev.org/c/openstack/nova/+/772273 | |
| #openstack-nova - 2022-11-14 | |||
| 03:35:35 | opendevreview | Ghanshyam proposed openstack/nova-specs master: Policy service role spec https://review.opendev.org/c/openstack/nova-specs/+/864379 | |
| 03:51:09 | opendevreview | Jorhson Deng proposed openstack/nova master: Remove the redundance code in HostState.update https://review.opendev.org/c/openstack/nova/+/864274 | |
| 03:53:20 | opendevreview | Jorhson Deng proposed openstack/nova master: Remove the redundance code in HostState.update https://review.opendev.org/c/openstack/nova/+/864274 | |
| 03:56:52 | opendevreview | Jorhson Deng proposed openstack/nova master: Remove the redundance code in HostState.update https://review.opendev.org/c/openstack/nova/+/864275 | |
| 05:19:59 | opendevreview | Ghanshyam proposed openstack/placement master: Policy defaults improvement spec https://review.opendev.org/c/openstack/placement/+/864385 | |
| 08:45:31 | Uggla | Good morning nova | |
| 08:59:43 | sahid | o/ | |
| 09:00:46 | sahid | sean-k-mooney, bauzas anything missing regarding evacuate feature? do you think you will be able to have look on it for this release? | |
| 09:05:52 | sahid | feel free to let me know if i can be helpful on anything | |
| 09:32:07 | gibi | o/ | |
| 09:59:19 | bauzas | sahid: I'll look at your spec tomorrow | |
| 10:02:41 | sahid | cool thank you bauzas | |
| 10:03:15 | bauzas | sahid: as a reminder, we'll have our spec review day tomorrow, so just make sure to look at the new comments tomorrow afternoon if you can | |
| 10:49:40 | sahid_ | bauzas: sure ACK | |
| 13:04:06 | opendevreview | Takashi Natsume proposed openstack/nova master: Add a hacking rule for the setDaemon method https://review.opendev.org/c/openstack/nova/+/854653 | |
| 15:19:49 | opendevreview | Sylvain Bauza proposed openstack/nova master: Handle mdev devices in libvirt 7.7+ https://review.opendev.org/c/openstack/nova/+/838976 | |
| 15:19:49 | opendevreview | Sylvain Bauza proposed openstack/nova master: Reproducer for bug 1951656 https://review.opendev.org/c/openstack/nova/+/850673 | |
| 15:19:50 | opendevreview | Sylvain Bauza proposed openstack/nova master: Deprecate mdev creation and hardfail on reboot when missing. https://review.opendev.org/c/openstack/nova/+/864418 | |
| 15:38:47 | opendevreview | ribaudr proposed openstack/nova-specs master: Allow local scaphandre directory to be mapped to an instance using virtiofs https://review.opendev.org/c/openstack/nova-specs/+/861881 | |
| 16:14:55 | opendevreview | ribaudr proposed openstack/nova-specs master: Allow local scaphandre directory to be mapped to an instance using virtiofs https://review.opendev.org/c/openstack/nova-specs/+/861881 | |
| 19:33:21 | gmann | dansmith: can you review these specs related to RBAC (service role for nova and dropping system scope for placement) https://review.opendev.org/c/openstack/nova-specs/+/864379 https://review.opendev.org/c/openstack/placement/+/864385 | |
| 19:34:21 | gmann | dansmith: also can you help to understand placement APIs, they should be consider as internal APIs or external? I am considering later and not proposing service role to them | |
| 19:41:56 | dansmith | gmann: hmm, well, | |
| 19:42:07 | dansmith | we kinda want people to use placement for some things, mostly admin-related though | |
| 19:42:18 | dansmith | but it's very much internal other than that | |
| 19:42:34 | dansmith | nova should use an account with the service role to talk to placement I think | |
| 19:43:26 | gmann | dansmith: so we need to keep policy open for admin-or-service role. or there are few APIs we can keep only service role ? | |
| 19:44:35 | dansmith | gmann: we probably need to review.. the problem is that when something goes wrong, an admin deleting a stale allocation or something can be required, | |
| 19:44:50 | dansmith | and even things like allocation candidates can be useful for admins | |
| 19:45:14 | dansmith | so yeah I think probably admin-or-service for much of it probably makes sense, but we should probably review all the rules to be sure | |
| 19:45:52 | sean-k-mooney | so admin-or-service makes sense for things like the external events api | |
| 19:46:05 | sean-k-mooney | but things like the host-aggrates api should be admin only | |
| 19:46:28 | gmann | ok, I think spec is ok then and we can review every rule while doing code change | |
| 19:46:33 | sean-k-mooney | the os-assisated-volume-extend api would also be admin-or-service | |
| 19:46:54 | gmann | sean-k-mooney: we are making them as service role only - this is for nova https://review.opendev.org/c/openstack/nova-specs/+/864379 | |
| 19:47:14 | sean-k-mooney | service only would work but it has an upgrade impact | |
| 19:47:22 | gmann | I think I covered all internal APIs there but if anything missing please comment | |
| 19:47:26 | sean-k-mooney | so service only woudl be be the end state we woudl like | |
| 19:47:31 | gmann | yeah | |
| 19:47:55 | dansmith | sean-k-mooney: he's asking about placement | |
| 19:47:59 | sean-k-mooney | im fine with service only by the way if its behind the new default falg | |
| 19:48:04 | sean-k-mooney | oh placment | |
| 19:48:34 | sean-k-mooney | thats a more interesting case | |
| 19:49:09 | sean-k-mooney | im kind fo conflicted | |
| 19:49:56 | sean-k-mooney | on one hand it would be nice to be able to use placment standalone but if we ignore that usecase | |
| 19:50:44 | sean-k-mooney | the allcoations endpoint proaably shoudl be service only however we would stant nova-manage heal allcotions to still work | |
| 19:51:02 | sean-k-mooney | perhaps readonly access for admin | |
| 19:51:39 | sean-k-mooney | i dont know. admin-or-service could be applied ot all the admin apis as a first step but i dont knwo if we want to prevent an admin form doing some things | |
| 19:52:45 | sean-k-mooney | like im tempeted to say the rp and invetory create/update apis shoudl be service only but we allow admins to add traits via the api or tweak the allcoation ratios | |
| 19:53:25 | sean-k-mooney | the reshape api proably shoudl be service only but im not sure any others fall into that | |
| 19:53:31 | sean-k-mooney | usecase | |
| 19:54:49 | dansmith | admins deleting stale allocations though... | |
| 19:55:13 | dansmith | yeah, reshape can be service only I think | |
| 19:55:14 | sean-k-mooney | without using the nova-manage command? | |
| 19:55:39 | dansmith | I think since placement isn't as user-facing it might make sense to just leave it as admin-or-service | |
| 19:55:44 | sean-k-mooney | i think s/admin/admin-or-owner/ for everythign other then reshape | |
| 19:55:44 | dansmith | at least focus on other stuff | |
| 19:56:05 | gmann | yeah, that is what i was thinking to leave them as admin-or-service | |
| 19:56:05 | dansmith | admin or service you mean? | |
| 19:56:15 | sean-k-mooney | sorry admin-or-service | |
| 19:56:17 | sean-k-mooney | yes | |
| 19:56:23 | dansmith | I assume that when you do things through nova-manage we still use the environment's creds, not the service ones right? | |
| 19:56:40 | sean-k-mooney | i think nova manage uses the creds in the nova.conf | |
| 19:57:03 | sean-k-mooney | i have never actully check however but i always tought it got them form there | |
| 19:57:12 | dansmith | hmm, it just means you might have to have nova.conf and service creds on your workstation if that's where you fix things from | |
| 19:57:22 | dansmith | using regular creds would make more sense to me | |