| Posted | Nick | Remark | |
|---|---|---|---|
| #openstack-nova - 2022-11-09 | |||
| 14:26:30 | admin1 | there are 2 i know of that show this behaviour | |
| 14:26:32 | admin1 | there is no lock | |
| 14:27:00 | sean-k-mooney | so if the ips are the same no need to update the nova db unless the cluster id changed | |
| 14:27:15 | admin1 | cluster name /fsid all is same | |
| 14:27:23 | sean-k-mooney | ya fsid was what i ment | |
| 14:27:29 | admin1 | fsid is the same | |
| 14:27:52 | sean-k-mooney | so if that the same then provide the keyring in the secret is still valid you are porably ok | |
| 14:28:18 | sean-k-mooney | have you tried using that to list the volumes on the pool | |
| 14:32:03 | admin1 | got it | |
| 15:50:26 | clarkb | melwitt: thanks. It does look like bfv is tested, but it does also appear that the image used for rescuing is modified to set its bus and device types? I wonder if that is what we are missing here. The rescue command itself doesn't appear to take those arguments so these would need to be specified before hand on a special image? I guess that lends more weight to having | |
| 15:50:28 | clarkb | dedicated images as a required part of the rescue process? | |
| 16:07:41 | melwitt | clarkb: can be image properties or expressed as extra specs in the flavor. I can test out a change that would add a flavor create setting bus and device types in the test | |
| 16:09:02 | clarkb | melwitt: either way it is something that the cloud or cloud user would need to be aware of. Currently the default rescue behavior is to reuse the same image the rescued node booted off of. This is problematic because of the label specifier collisions, but also because if the image itself is broken you'd still be broken in a rescue. That leads users to using another image, but | |
| 16:09:04 | clarkb | there isn't any clear indication to me as a user that I need to use a special image. | |
| 16:10:15 | opendevreview | Dan Smith proposed openstack/nova master: Test ceph-multistore with a real image https://review.opendev.org/c/openstack/nova/+/860864 | |
| 16:11:05 | clarkb | I suspect the solution here is to make it clear to cloud operators that rescue has requirements x y z (I don't know what they all are yet) and that they should provide an image that meets those requirements | |
| 16:11:57 | melwitt | clarkb: hm yeah you are probably right it's only image properties, this section doesn't mention using a flavor to do it https://docs.openstack.org/nova/latest/user/rescue.html#stable-device-instance-rescue | |
| 16:12:42 | clarkb | also I wonder if nova should drop the default behavior or reusing the running image and instead force people to explicitly provide one | |
| 16:13:07 | clarkb | I suspect there are scenarios where reusing the image would work, but in the vast majority it seems unlikely | |
| 16:13:24 | clarkb | and that would help provide signal that something different is required here | |
| 16:16:46 | melwitt | I think we could do that in a new API microversion to avoid breaking anyone who is using it the old way and succeeding ... but the fact that openstackclient defaults to lowest microversion makes it more difficult to signal imho | |
| 16:18:27 | clarkb | ya and I think users could manually specify the same image if they really did need/want that | |
| 16:18:38 | clarkb | it just wouldn't be provided as a dfeault (which I think users expect to work) | |
| 16:19:27 | melwitt | yeah, I think that makes sense | |
| 17:19:55 | opendevreview | Merged openstack/nova stable/yoga: [compute] always set instance.host in post_livemigration https://review.opendev.org/c/openstack/nova/+/861872 | |
| 17:31:39 | opendevreview | Amit Uniyal proposed openstack/nova stable/ussuri: add regression test case for bug 1978983 https://review.opendev.org/c/openstack/nova/+/862603 | |
| 17:31:40 | opendevreview | Amit Uniyal proposed openstack/nova stable/ussuri: For evacuation, ignore if task_state is not None https://review.opendev.org/c/openstack/nova/+/862604 | |
| 18:45:28 | opendevreview | melanie witt proposed openstack/nova-specs master: Re-propose spec for ephemeral storage encryption https://review.opendev.org/c/openstack/nova-specs/+/864138 | |
| 19:29:37 | darkhorse | Hi team | |
| 19:29:40 | darkhorse | class NovaSession(): | |
| 19:29:40 | darkhorse | def __init__(self): | |
| 19:29:40 | darkhorse | self.auth = v3.Password(KEYSTONE_URL, username=OPENSTACK_ADMIN, password=OPENSTACK_ADMIN_PASS, project_name=ADMIN_PROJECT, user_domain_id=DOMAIN_ID, | |
| 19:29:40 | darkhorse | project_domain_id=PROJECT_DOMAIN_ID) | |
| 19:29:40 | darkhorse | self.sess = session.Session(self.auth) | |
| 19:29:42 | darkhorse | self.nova2 = nova_client.Client(2, session=self.sess) | |
| 19:31:16 | darkhorse | I use this code to create nova session. I want to use internal IP address since my app runs on controller. I set KEYSTONE_URL to internal keystone endpoint address but the client still send requests to nova public ip address. | |
| 19:31:39 | darkhorse | Is there a setting that I can tell the client to use internal address? | |
| 19:34:12 | opendevreview | Dan Smith proposed openstack/nova master: Test ceph-multistore with a real image https://review.opendev.org/c/openstack/nova/+/860864 | |
| 19:57:05 | melwitt | darkhorse: you might try the 'interface' kwarg to Client (interface=$the_name_of_your_internal_endpoint_in_the_service_catalog) which will get passed to the keystone adapter https://docs.openstack.org/keystoneauth/latest/api/keystoneauth1.adapter.html | |
| 19:58:52 | melwitt | there's also endpoint_override to provide the full url but the interface discovery is nicer I think if it works | |
| 20:02:10 | darkhorse | melwitt: thank you i ended up using nova_client.Client(2, session=self.sess, endpoint_type='internal') | |
| 20:02:22 | darkhorse | interface kwarg seems to be deprecated. | |
| 20:03:50 | melwitt | darkhorse: ok cool. it's the other way around I think, endpoint_type is an old name now used as an alias | |
| 20:04:41 | darkhorse | ok thank you. | |
| 22:30:18 | opendevreview | melanie witt proposed openstack/nova-specs master: Re-propose spec for ephemeral encryption for libvirt https://review.opendev.org/c/openstack/nova-specs/+/864147 | |
| 23:44:44 | opendevreview | melanie witt proposed openstack/nova-specs master: Re-propose per process healthchecks https://review.opendev.org/c/openstack/nova-specs/+/864150 | |
| #openstack-nova - 2022-11-10 | |||
| 01:52:34 | opendevreview | Nobuhiro MIKI proposed openstack/nova master: libvirt: add maxphysaddr support https://review.opendev.org/c/openstack/nova/+/864091 | |
| 04:28:37 | opendevreview | melanie witt proposed openstack/nova master: DNM test ephemeral encryption + resize: qcow2, raw https://review.opendev.org/c/openstack/nova/+/862416 | |
| 04:33:24 | opendevreview | melanie witt proposed openstack/nova master: DNM test ephemeral encryption + resize: qcow2, raw https://review.opendev.org/c/openstack/nova/+/862416 | |
| 07:05:13 | opendevreview | melanie witt proposed openstack/nova master: DNM test ephemeral encryption + resize: qcow2, raw https://review.opendev.org/c/openstack/nova/+/862416 | |
| 08:22:41 | opendevreview | Amit Uniyal proposed openstack/nova stable/train: add regression test case for bug 1978983 https://review.opendev.org/c/openstack/nova/+/864168 | |
| 08:22:42 | opendevreview | Amit Uniyal proposed openstack/nova stable/train: For evacuation, ignore if task_state is not None https://review.opendev.org/c/openstack/nova/+/864169 | |
| 08:53:50 | opendevreview | Amit Uniyal proposed openstack/nova stable/train: add regression test case for bug 1978983 https://review.opendev.org/c/openstack/nova/+/864168 | |
| 08:53:51 | opendevreview | Amit Uniyal proposed openstack/nova stable/train: For evacuation, ignore if task_state is not None https://review.opendev.org/c/openstack/nova/+/864169 | |
| 10:22:57 | opendevreview | Amit Uniyal proposed openstack/nova stable/train: add regression test case for bug 1978983 https://review.opendev.org/c/openstack/nova/+/864168 | |
| 10:22:58 | opendevreview | Amit Uniyal proposed openstack/nova stable/train: For evacuation, ignore if task_state is not None https://review.opendev.org/c/openstack/nova/+/864169 | |
| 10:53:00 | opendevreview | Amit Uniyal proposed openstack/nova stable/train: add regression test case for bug 1978983 https://review.opendev.org/c/openstack/nova/+/864168 | |
| 10:53:01 | opendevreview | Amit Uniyal proposed openstack/nova stable/train: For evacuation, ignore if task_state is not None https://review.opendev.org/c/openstack/nova/+/864169 | |
| 11:36:49 | opendevreview | Amit Uniyal proposed openstack/nova stable/train: add regression test case for bug 1978983 https://review.opendev.org/c/openstack/nova/+/864168 | |
| 11:36:50 | opendevreview | Amit Uniyal proposed openstack/nova stable/train: For evacuation, ignore if task_state is not None https://review.opendev.org/c/openstack/nova/+/864169 | |
| 13:59:34 | fungi | bauzas: when you have time, can you recommend some updates for https://launchpad.net/~nova-coresec/+members and the nova entry at https://wiki.openstack.org/wiki/CrossProjectLiaisons#Vulnerability_management ? i get the distinct impression those are extremely stale | |
| 14:01:03 | sean-k-mooney | yes, dan is still about and john says hi form time to time but it would likely be better to 1 include the current ptl and 2 conisder if others on the core team should be there | |
| 14:01:30 | fungi | that's what i was thinking as well | |
| 14:03:07 | fungi | certainly if bauzas wants to be included in nova-coresec then i can set him as an administrator for it and he can make any further adjustments he likes | |
| 14:04:31 | sean-k-mooney | what i was kind of thinking is adding this to the ptl guide to do a reveiw each release and make adding the next ptl be part fo the hand over process | |
| 14:05:07 | opendevreview | ribaudr proposed openstack/nova-specs master: Re-propose "Allow Manila shares to be directly attached to an instance when using libvirt" https://review.opendev.org/c/openstack/nova-specs/+/864206 | |
| 14:05:31 | sean-k-mooney | i dont think i have access to check the audit log for that group but i do suspect its been updated in a while | |
| 14:08:59 | opendevreview | ribaudr proposed openstack/nova-specs master: Re-propose "Allow Manila shares to be directly attached to an instance when using libvirt" https://review.opendev.org/c/openstack/nova-specs/+/864206 | |
| 14:12:04 | fungi | sean-k-mooney: the only administrators in that group haven't been active in the projects for years, so i can guarantee it's not been updated for quite a long while | |
| 14:13:16 | sean-k-mooney | well dansmith is still active | |
| 14:13:45 | sean-k-mooney | but less so oh dan is not an admin | |
| 14:13:48 | sean-k-mooney | ok then yes | |
| 14:16:37 | fungi | i have access to the owner group for that one, so can add/remove members and set any of them as administrator, but i mainly only do so in order to fix situations like this where outgoing leaders didn't transition control of things to incoming leadership | |
| 14:17:48 | sean-k-mooney | yep hence why i was sugging adding it to the ptl/guide to make sur ethat they ensure there is an acitive admin and review the membership each cycle | |
| 14:18:30 | sean-k-mooney | so post elect old ptl adds new ptl and removes self if they dont want to continue reviewing secuirty isues | |
| 14:19:04 | sean-k-mooney | new ptl reviews membership and makes what ever updated make sense at start of their tenure | |
| 14:19:37 | sean-k-mooney | for ptlless project this can be delicated to secuirty liasion | |
| 14:21:46 | fungi | right, exactly | |
| 14:23:05 | frickler | tonyb is still around fwiw, but I think more active in requirements | |
| 14:23:29 | fungi | oh, you're right. he was gone for a couple of years but has returned to us recently | |
| 14:41:32 | sean-k-mooney | ya moved to openshift didnt like it and came back a few months ago i belive | |
| 17:00:37 | bauzas | fungi: sean-k-mooney: sorry folks, was missing the convo, surely we can discuss this between cores | |
| 17:01:09 | bauzas | in the meantime, you can add me in the nova-coresec team | |
| 17:23:31 | fungi | bauzas: will do now | |
| 17:25:15 | fungi | bauzas: you're a member and admin now, and can make whatever changes to that group you need | |
| 17:31:22 | bauzas | fungi: ack | |
| 17:31:25 | bauzas | thanks | |
| 17:31:58 | bauzas | fungi: DM me anytime you want me to look at something private | |
| 17:32:08 | bauzas | I could miss a reported bug | |
| 17:32:33 | fungi | yep, gladly | |
| 17:46:29 | melwitt | I didn't even know about https://launchpad.net/~nova-coresec/+members until just now 😂 | |
| 18:07:51 | sean-k-mooney | i only knew about it becasue when i have been added to security bugs in the past i noticed it was there | |
| 18:09:47 | bauzas | see ya | |
| 18:09:55 | sean-k-mooney | o/ | |
| 18:25:30 | opendevreview | sean mooney proposed openstack/nova master: [DMN] test removal of CAP_DAC_OVERRIDE https://review.opendev.org/c/openstack/nova/+/810906 | |
| #openstack-nova - 2022-11-11 | |||
| 00:17:17 | opendevreview | melanie witt proposed openstack/nova master: libvirt: Configure and teardown ephemeral encryption secrets https://review.opendev.org/c/openstack/nova/+/826754 | |
| 00:17:18 | opendevreview | melanie witt proposed openstack/nova master: imagebackend: Add support to libvirt_info for LUKS based encryption https://review.opendev.org/c/openstack/nova/+/826755 | |
| 00:17:18 | opendevreview | melanie witt proposed openstack/nova master: imagebackend: Cache the key manager when disk is encrypted https://review.opendev.org/c/openstack/nova/+/826756 | |
| 00:17:19 | opendevreview | melanie witt proposed openstack/nova master: libvirt: Introduce support for qcow2 with LUKS https://review.opendev.org/c/openstack/nova/+/772273 | |
| 00:17:19 | opendevreview | melanie witt proposed openstack/nova master: Follow up changes for ephemeral encryption https://review.opendev.org/c/openstack/nova/+/853254 | |