Earlier  
Posted Nick Remark
#openstack-nova - 2022-05-17
17:33:36 sean-k-mooney levy14: it was based on https://cloud.google.com/compute/docs/instances/verifying-instance-identity
17:33:46 jrosser sean-k-mooney: I totally ran out of time to take that further
17:34:18 jrosser but still interesting if it can be made to work with an external thing like step-ca (that was my use case)
17:34:34 sean-k-mooney jrosser: maybe you can expalin it to levy14 and they could find resouce to work on it
17:35:45 sean-k-mooney jrosser: i have not been following keystoen recently but i belive tehy are also working on some oath/openid connect supprot this cycle
17:35:52 sean-k-mooney not sure if that is related
17:36:09 sean-k-mooney this https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext
17:37:01 levy14 in any case, adding it to the agenda and we'll see next time
17:37:11 levy14 thanks for the links
17:42:11 jrosser levy14: I have POC code to insert a signed jwt into the metadata
17:44:17 jrosser https://github.com/bbc/nova/commit/c0e9a98fb96d0dff73d0a5c5e7ebad8078fd85a1
17:45:03 sean-k-mooney jrosser: didnt knwo you worked for/with the bbc
17:45:10 sean-k-mooney or that they used openstack
17:45:18 sean-k-mooney thats cool
17:45:30 jrosser we use it in the R&D labs
17:45:59 sean-k-mooney even still that is nice to hear
17:46:08 sean-k-mooney even if its only for R&D
17:46:12 sean-k-mooney and not production
17:47:30 sean-k-mooney jrosser: your poc is that integrated with keystone in any way. can the jwt token be sued to auth with keystone
17:47:37 sean-k-mooney to then bootstrap to calling barbican
17:47:55 sean-k-mooney or did you just use it for the vm verifcation usecase
17:48:18 jrosser the idea (pretty much copied from what GCP do) is that you could validate that jwt against a published CA cert at some well known location
17:48:33 sean-k-mooney ya ok
17:48:34 jrosser and that is sufficient to say that the VM is what it claims to be
17:49:03 sean-k-mooney so keystone i think now support using jwt to auth and get a keystone token
17:49:24 sean-k-mooney so your poc is not tied into that
17:49:48 jrosser right - though i guess the JWT payload can be pretty arbitrary so i'm not sure how much that would intersect
17:53:58 jrosser hmmm hashicorp vault can authenticate with a JWT
17:54:09 jrosser now that would be really interesting to make work
17:55:47 sean-k-mooney jrosser: levy14's usecases is to use something to allow the vm to auth to barbican
17:56:13 sean-k-mooney jrosser: basically so that you dont need to sotre creds in teh applicaitons configs
17:56:35 jrosser right - i believe that such things are very straightforward in aws
17:56:44 sean-k-mooney jrosser: and since keystone now accpets jwt tokes to auth with my theory was
17:57:05 sean-k-mooney if we added a jwt token in the metadta you coudl use that to get a keystone token and then use that to call barbican
17:57:55 sean-k-mooney and sicne jwt tokesn can expire you could allow that only for x mintues after teh server is booted for intial bootstrap
17:58:59 sean-k-mooney anyway its not my usecase so i wont worry about it for now
17:59:12 sean-k-mooney but it could be a ncie feature if openstack could provide a simialr workflow
17:59:29 sean-k-mooney its proably not a nova feature however
17:59:31 sean-k-mooney ot not mainly
17:59:39 sean-k-mooney a nova feature
18:09:45 jrosser seems it is fernet or jws for keystone, not a mixture
18:10:02 jrosser and it does seem more clean to have keystone issue a token then then is in the metadata
18:10:37 sean-k-mooney well for there usecase tehy are tryign to prevent having to put credeitals in the vm to begin with
18:10:45 sean-k-mooney so they need somthign to bootstrap form
18:11:06 sean-k-mooney i think k8s solves this by definign env vars that are only accepable in the container
18:11:12 sean-k-mooney so you can get your pods secret
18:11:28 sean-k-mooney the metadta serivce is the closest thing we have to that
18:13:21 jrosser oh i am confusing the existing jws stuff in keystone with that new jwt auth patch
#openstack-nova - 2022-05-18
00:01:44 opendevreview Merged openstack/nova stable/yoga: Adds regression test for bug LP#1944619 https://review.opendev.org/c/openstack/nova/+/838788
00:01:52 opendevreview Merged openstack/nova stable/yoga: Fix pre_live_migration rollback https://review.opendev.org/c/openstack/nova/+/836014
01:10:17 opendevreview Merged openstack/nova stable/ussuri: [stable-only] Drop lower-constraints job https://review.opendev.org/c/openstack/nova/+/838033
03:18:03 opendevreview Brin Zhang proposed openstack/nova master: Replaces tenant_id with project_id from List/Update Servers APIs https://review.opendev.org/c/openstack/nova/+/764292
03:18:03 opendevreview Brin Zhang proposed openstack/nova master: Replace all_tenants with all_projects in List Server APIs https://review.opendev.org/c/openstack/nova/+/765311
03:18:04 opendevreview Brin Zhang proposed openstack/nova master: Replaces tenant_id with project_id from Rebuild Server API https://review.opendev.org/c/openstack/nova/+/766380
03:18:04 opendevreview Brin Zhang proposed openstack/nova master: Replaces tenant_id with project_id from List SG API https://review.opendev.org/c/openstack/nova/+/766726
03:18:05 opendevreview Brin Zhang proposed openstack/nova master: Replaces tenant_id with project_id from Flavor Access APIs https://review.opendev.org/c/openstack/nova/+/767704
06:53:59 bauzas good morning Nova
07:32:04 Uggla bauzas, o/
07:32:43 Uggla bauzas, did you sleep well after the spicy food ?
07:34:51 tobias-urdin good morning o/
07:35:21 gibi good morning
07:37:15 gibi hehh my old E/// wifi account still works in the local E/// building
07:41:59 tobias-urdin sean-k-mooney: maybe u could check this libvirt blocker when u are online https://review.opendev.org/c/openstack/nova/+/838976
07:53:17 bauzas Uggla: yes indeed ;)
08:04:25 kashyap gibi: Good luck with the preso!
08:05:47 bauzas gibi: break a leg ;)
08:06:37 bauzas Free (French operator) <3 you missed me
08:07:10 bauzas (I missed you* actually)
08:08:46 opendevreview Brin Zhang proposed openstack/nova master: Replaces tenant_id with project_id from List/Show usage APIs https://review.opendev.org/c/openstack/nova/+/768509
08:08:47 opendevreview Brin Zhang proposed openstack/nova master: Replace tenants* with projects* of policies https://review.opendev.org/c/openstack/nova/+/765315
08:30:40 opendevreview Brin Zhang proposed openstack/nova master: Replace tenant_id with project_id in os-quota-sets path https://review.opendev.org/c/openstack/nova/+/768851
08:30:41 opendevreview Brin Zhang proposed openstack/nova master: Replace tenant_id with project_id in Limits API https://review.opendev.org/c/openstack/nova/+/768862
08:30:41 opendevreview Brin Zhang proposed openstack/nova master: Replace tenant* with project* in codes https://review.opendev.org/c/openstack/nova/+/769329
08:30:42 opendevreview Brin Zhang proposed openstack/nova master: Replace os-simple-tenant-usage with os-simple-project-usage https://review.opendev.org/c/openstack/nova/+/842288
08:35:18 brinzhang0 bauzas: hi, I would you like to review the remove_tenant series patches https://review.opendev.org/q/topic:bp%252Fremove-tenant-id
08:35:32 bauzas brinzhang0: sure, I'll do
08:35:41 brinzhang0 thx
09:25:38 sean-k-mooney gibi: does https://review.opendev.org/c/openstack/tempest/+/842140/3/tempest/api/compute/base.py#482= make sense
09:25:56 sean-k-mooney the jobs failed on the test we were trying to fix so its obviouly not working in its current form
09:42:32 Uggla sean-k-mooney, can you have a quick look at my comment on https://review.opendev.org/c/openstack/nova-specs/+/831506 and tell me what you think about it ?
09:45:25 sean-k-mooney im just reading a differnt one but suer ill look at it soon
09:46:09 Uggla sean-k-mooney, thx
09:49:25 sean-k-mooney cool one -1 down for the day now for the next :P
09:50:02 sean-k-mooney Uggla: i dont see a new comment form you since the last ones i posted
09:50:14 sean-k-mooney which one specifically did you want me to look at
09:55:00 sean-k-mooney bauzas: before you do
09:55:10 sean-k-mooney bauzas: can you respond to gmann on yoru spec
09:55:18 bauzas sean-k-mooney: sure, will look
09:55:30 sean-k-mooney bauzas: can you pull in the change to allow @ in the keypair name
09:56:27 sean-k-mooney https://review.opendev.org/c/openstack/nova-specs/+/785674
09:56:42 sean-k-mooney this comment https://review.opendev.org/c/openstack/nova-specs/+/840217/3#message-81ccda58cd8f18ba84569bec794083b5572eb1e0=
09:57:03 bauzas gosh, I got lost with all the back-and-forths
09:57:11 bauzas and I forgot to upload my comments
09:57:59 bauzas oh, merging with another spec, I see
09:58:12 sean-k-mooney its a really trivial spec so if you can merge that into your it woudl be nice to do both in one micro verion
09:58:19 sean-k-mooney ya it just add ing @ and .
09:58:22 sean-k-mooney to the regex
09:58:38 sean-k-mooney so you can name the keypair me@my.domain
09:59:54 sean-k-mooney bauzas: if your ok with that we could also make that update as a FUP
10:00:04 sean-k-mooney assuming that works for gmann

Earlier   Later