Earlier  
Posted Nick Remark
#openstack-nova - 2022-05-31
16:17:23 gmann *I will not travel
16:17:32 bauzas gmann: you'll be missed
16:17:54 bauzas I'll close the vote
16:17:58 bauzas but, before this
16:18:09 bauzas if someone wants run the meeting, he can
16:18:25 bauzas this is just I'm not sure we'll have a quorum then
16:18:47 bauzas let's end the vote
16:18:48 bauzas #endvote
16:18:48 opendevmeet Voted on "Cancel Nova meeting next week ?" Results are
16:18:48 opendevmeet yes (4): Uggla, gmann, elodilles, bauzas
16:19:14 bauzas so,
16:19:25 bauzas I haven't seen interest by someone to run it,
16:19:47 bauzas #agreed June 7th nova meeting is CANCELLED.
16:19:59 bauzas I'll send an email accordingly
16:20:23 bauzas one last point, if some people read our minutes,
16:20:26 bauzas #info We'll provide a Nova meet-and-greet Operators feedback session on Wednesday, June 8, 2:50pm - 3:20pm. Operators are welcome.
16:20:45 bauzas I can proxy any opinions or thoughts at the forum, btw.
16:20:54 bauzas stick around on IRC, you could be pinged
16:21:53 gmann bauzas: good idea. is there any etherpad i can add topic?
16:22:05 bauzas gmann: I surely can create one
16:22:06 gmann I would like to get soem feedback on SRBAC especially on scope thing
16:22:29 gmann thanks, that will be great I will not be there but I think you can discuss it and I will add details in etherpad
16:22:32 bauzas gmann: so you imagine some feedback etherpad, or rather some etherpad for adding notes before and remarks after ?
16:22:40 bauzas ah, I see
16:22:47 gmann bauzas: latter one
16:23:00 bauzas gmann: this is an excellent idea, let's setup this
16:23:05 gmann +1
16:23:28 bauzas gmann: I wish the Forum sessions would have their own etherpads tho
16:23:29 gmann we are trying to get this topic for ope meetup also but getting per project feedback also will be great
16:23:53 gmann bauzas: yeah, that also work, anywhere I can add this topic so that you remember it
16:24:05 bauzas gmann: oh, you meant about operators feedback at our meet-and-greet ? gotcha.
16:24:11 gmann yeah
16:24:26 bauzas gmann: then, I'll start an etherpad and I'll discuss this with gibi as he co-hosts
16:24:34 gmann thanks
16:24:47 bauzas this is a good point, we have a few things we'd like operators to play witgh
16:24:53 bauzas like the unified limits
16:24:58 gmann indeed
16:25:16 bauzas remember tho, operators play old versions, so they couldn't be that helpful
16:25:23 bauzas but this is not a reason to ask
16:25:33 bauzas to not* ask
16:25:39 gmann yeah, just if we can get initial feedback what they think on these new things
16:25:45 bauzas gotcha
16:25:50 bauzas and brilliant idea
16:26:01 bauzas gmann: you're doing my homework !
16:26:12 gmann :)
16:26:35 bauzas ok, next topic, I guess ?
16:27:09 bauzas looks so
16:27:20 bauzas #topic Review priorities
16:27:25 bauzas #link https://review.opendev.org/q/status:open+(project:openstack/nova+OR+project:openstack/placement+OR+project:openstack/os-traits+OR+project:openstack/os-resource-classes+OR+project:openstack/os-vif+OR+project:openstack/python-novaclient+OR+project:openstack/osc-placement)+label:Review-Priority%252B1
16:27:42 bauzas #link https://review.opendev.org/c/openstack/project-config/+/837595 Gerrit policy for Review-prio contributors flag. Naming bikeshed in there.
16:28:14 bauzas #link https://docs.openstack.org/nova/latest/contributor/process.html#what-the-review-priority-label-in-gerrit-are-use-for Documentation we already have
16:28:48 bauzas looks we found a consensus on my proposal for https://review.opendev.org/c/openstack/project-config/+/837595
16:29:04 bauzas sean-k-mooney: could you then please provide a new rev for it ? ^
16:30:38 sean-k-mooney ah i tought you were going to update it but sure
16:31:33 bauzas sean-k-mooney: oh, I can do it
16:32:17 bauzas #action bauzas to update https://review.opendev.org/c/openstack/project-config/+/837595
16:33:10 bauzas sean-k-mooney: no worries, I'll take it
16:33:36 bauzas next topic then
16:33:38 bauzas #topic Stable Branches
16:33:55 bauzas elodilles: feel free to take the mic
16:34:00 elodilles #info ussuri is unblocked, thanks to gmann's tempest pinning patches
16:34:17 bauzas \o/
16:34:21 gmann yeah, and stable/victoria is also pinned with old tempest
16:34:27 elodilles #info stable branches are now unblocked, but intermittent failures need further investigations. melwitt's tracking etherpad: https://etherpad.opendev.org/p/nova-stable-branch-ci
16:34:32 elodilles gmann: thanks! \o/
16:34:33 gmann took almsot 1 week to get all these merged
16:34:42 elodilles :S
16:34:57 elodilles #info placement's stable/branches are unblocked back till victoria (see melwitt's etherpad ^^^)
16:35:12 bauzas \o/ agai,
16:35:17 gmann cyborg-tempest plugin job which is non voting in nova gate also will be fixed by #link https://review.opendev.org/c/openstack/cyborg-tempest-plugin/+/843329
16:36:27 elodilles gmann: ack, thanks for that, too!
16:36:41 elodilles (that's all from my side)
16:36:42 bauzas :)
16:36:51 bauzas greatly appreciated, thanks gmann
16:37:03 gmann np!
16:37:18 bauzas and thanks melwitt for the tracking
16:37:24 bauzas moving on
16:37:29 bauzas we have one last item
16:37:48 bauzas #topic Open discussion
16:38:00 bauzas (levy14) Discuss ability to call Barbican from inside VM without supplying credentials
16:38:03 bauzas levy14: around ?
16:38:06 levy14 yep
16:38:25 levy14 was not around last week to put it on the agenda
16:38:34 bauzas levy14: I'll be honest, I'm not sure we have quorum for discussing your point today, but we can try
16:39:36 levy14 but my org would greatly benefit if any code in a vm could call barbican to fetch secrets. now there are secrets in code, in config files, injected but not properly handled. I'd like to get rid of that.
16:39:59 levy14 without having to put the credentials in the code, I mean
16:40:31 levy14 I see this as a big security improvement for users of nova
16:40:50 sean-k-mooney i actuly see it as the opisite form a nova point of view
16:40:57 sean-k-mooney is potentally a large security whole
16:41:22 sean-k-mooney nova today almost excilulive does not handel any tenatn secrets
16:41:45 bauzas yup, that's what we said
16:41:48 sean-k-mooney nova or admins by default cannot retirve secrets form barbican
16:42:00 sean-k-mooney only the user can
16:42:05 levy14 I understand. but that forces users of nova to improvise. and it's not good what users do. the outcome is nasty.
16:42:32 sean-k-mooney yep thats also true
16:42:46 levy14 if there would be a feature to allow this specific use case, that would make life of nova users much better
16:42:48 sean-k-mooney realisticaly the simpelte way to achive this today id via an external vender data service
16:43:06 sean-k-mooney which could inject a bootstrap token via the metadta api
16:43:25 sean-k-mooney simialr to how nova-join works https://opendev.org/x/novajoin#design
16:43:35 levy14 the problem with that is that I cannot realitically get it implemented across the federation of sites we represent

Earlier   Later