*** pdesai has quit IRC | 00:19 | |
*** everjeje has quit IRC | 00:27 | |
*** ccneill has quit IRC | 00:29 | |
*** jamielennox is now known as jamielennox|away | 00:33 | |
*** jmckind has quit IRC | 00:37 | |
*** mixos has joined #openstack-barbican | 00:45 | |
*** mixos has quit IRC | 01:01 | |
openstackgerrit | Jason Fritcher proposed openstack/barbican-specs: Blueprint defining healthcheck API endpoint. https://review.openstack.org/207317 | 01:19 |
---|---|---|
*** su_zhang has quit IRC | 01:25 | |
*** diazjf has joined #openstack-barbican | 01:40 | |
*** dave-mccowan has quit IRC | 01:42 | |
*** mixos has joined #openstack-barbican | 01:50 | |
*** diazjf has quit IRC | 02:02 | |
*** mixos has quit IRC | 02:05 | |
*** diazjf has joined #openstack-barbican | 02:17 | |
*** jamielennox|away is now known as jamielennox | 02:34 | |
*** dave-mccowan has joined #openstack-barbican | 02:57 | |
*** yfujioka has quit IRC | 03:16 | |
*** yuanying has quit IRC | 03:17 | |
*** dave-mccowan has quit IRC | 03:22 | |
*** kfarr has quit IRC | 03:34 | |
*** diazjf has quit IRC | 03:59 | |
*** david-lyle has joined #openstack-barbican | 04:07 | |
*** diazjf has joined #openstack-barbican | 04:13 | |
*** yuanying has joined #openstack-barbican | 04:14 | |
*** kebray has joined #openstack-barbican | 04:41 | |
*** jamielennox is now known as jamielennox|away | 05:01 | |
openstackgerrit | Fernando Diaz proposed openstack/barbican-specs: Blueprint defining user defined metadata for Barbican Secrets https://review.openstack.org/229995 | 05:15 |
*** su_zhang has joined #openstack-barbican | 05:21 | |
*** jaosorior has joined #openstack-barbican | 05:31 | |
*** gyee has quit IRC | 05:52 | |
*** su_zhang has quit IRC | 05:56 | |
*** ig0r__ has quit IRC | 06:05 | |
*** ig0r__ has joined #openstack-barbican | 06:10 | |
openstackgerrit | Fernando Diaz proposed openstack/python-barbicanclient: Allow tox to be able to run independent functional tests https://review.openstack.org/243420 | 06:13 |
*** _edmund has quit IRC | 06:18 | |
*** jaosorior has quit IRC | 06:30 | |
*** diazjf has quit IRC | 06:38 | |
*** kebray has quit IRC | 06:42 | |
*** kebray has joined #openstack-barbican | 06:46 | |
*** alee_ has quit IRC | 06:49 | |
openstackgerrit | Merged openstack/barbican: Move Key gen script to cmd folder https://review.openstack.org/239753 | 06:49 |
*** alee has quit IRC | 06:52 | |
*** alee_ has joined #openstack-barbican | 06:52 | |
*** alee has joined #openstack-barbican | 06:53 | |
openstackgerrit | Fernando Diaz proposed openstack/python-barbicanclient: Allow Barbican Secrets to be Updated via File https://review.openstack.org/242635 | 06:56 |
*** jaosorior has joined #openstack-barbican | 07:00 | |
*** woodster_ has quit IRC | 07:09 | |
*** openstackgerrit has quit IRC | 07:46 | |
*** openstackgerrit has joined #openstack-barbican | 07:47 | |
*** zigo has quit IRC | 08:01 | |
*** zigo has joined #openstack-barbican | 08:03 | |
openstackgerrit | Pradeep Kumar Singh proposed openstack/barbican: remove default=None for config options https://review.openstack.org/243442 | 08:09 |
*** openstackgerrit has quit IRC | 08:31 | |
*** openstackgerrit has joined #openstack-barbican | 08:31 | |
*** shohel has joined #openstack-barbican | 08:33 | |
*** shohel has quit IRC | 08:47 | |
*** kebray has quit IRC | 08:56 | |
*** shohel has joined #openstack-barbican | 09:07 | |
*** jamielennox|away is now known as jamielennox | 10:24 | |
*** jaosorior has quit IRC | 10:25 | |
*** jaosorior has joined #openstack-barbican | 10:25 | |
*** jaosorior has quit IRC | 10:27 | |
*** jaosorior has joined #openstack-barbican | 10:27 | |
*** ig0r__ has quit IRC | 10:40 | |
*** ccneill has joined #openstack-barbican | 12:39 | |
*** stevemar_ has joined #openstack-barbican | 13:11 | |
*** everjeje has joined #openstack-barbican | 13:12 | |
*** ccneill has quit IRC | 13:13 | |
*** alee has quit IRC | 13:18 | |
*** alee_ has quit IRC | 13:19 | |
*** stevemar_ has quit IRC | 13:20 | |
*** stevemar_ has joined #openstack-barbican | 13:21 | |
*** nelsnelson has joined #openstack-barbican | 13:32 | |
*** su_zhang has joined #openstack-barbican | 13:33 | |
*** woodster_ has joined #openstack-barbican | 13:56 | |
*** stevemar_ has quit IRC | 14:04 | |
*** rellerreller has joined #openstack-barbican | 14:11 | |
*** stevemar_ has joined #openstack-barbican | 14:13 | |
openstackgerrit | Merged openstack/barbican: Fix Database Migrations Documentation https://review.openstack.org/242250 | 14:20 |
*** mixos has joined #openstack-barbican | 14:25 | |
*** mixos has quit IRC | 14:30 | |
*** su_zhang has quit IRC | 14:30 | |
*** jmckind has joined #openstack-barbican | 14:31 | |
*** alee has joined #openstack-barbican | 14:32 | |
*** lisaclark__ has joined #openstack-barbican | 14:46 | |
*** lisaclark_ has quit IRC | 14:47 | |
*** lisaclark__ is now known as lisaclark_ | 14:47 | |
*** stevemar_ has quit IRC | 14:53 | |
*** stevemar_ has joined #openstack-barbican | 14:54 | |
*** dave-mccowan has joined #openstack-barbican | 15:08 | |
*** spotz_zzz is now known as spotz | 15:09 | |
*** edtubill has joined #openstack-barbican | 15:14 | |
*** jhfeng has joined #openstack-barbican | 15:17 | |
*** rhagarty_ has quit IRC | 15:33 | |
*** mixos has joined #openstack-barbican | 15:37 | |
*** rhagarty has joined #openstack-barbican | 15:38 | |
*** rhagarty has quit IRC | 15:40 | |
*** rhagarty has joined #openstack-barbican | 15:40 | |
*** rhagarty_ has joined #openstack-barbican | 15:42 | |
*** rhagarty has quit IRC | 15:45 | |
*** silos has joined #openstack-barbican | 15:45 | |
*** everjeje has quit IRC | 15:57 | |
*** woodster_ has quit IRC | 15:59 | |
*** kebray has joined #openstack-barbican | 16:01 | |
*** darrenmoffat has quit IRC | 16:13 | |
*** darrenmoffat has joined #openstack-barbican | 16:14 | |
*** ccneill has joined #openstack-barbican | 16:20 | |
*** diazjf has joined #openstack-barbican | 16:25 | |
*** leecalcote has joined #openstack-barbican | 16:27 | |
*** leecalcote has quit IRC | 16:27 | |
*** leecalcote has joined #openstack-barbican | 16:28 | |
*** jamielennox has quit IRC | 16:28 | |
*** su_zhang has joined #openstack-barbican | 16:31 | |
*** su_zhang has quit IRC | 16:33 | |
*** jamielennox has joined #openstack-barbican | 16:41 | |
*** gyee has joined #openstack-barbican | 16:52 | |
*** gyee has quit IRC | 17:25 | |
*** jmckind is now known as jmckind_ | 17:26 | |
*** leecalcote has quit IRC | 17:28 | |
*** gyee has joined #openstack-barbican | 17:28 | |
openstackgerrit | Fernando Diaz proposed openstack/python-barbicanclient: Allow Barbican Secrets to be Updated via File https://review.openstack.org/242635 | 17:36 |
jaosorior | dave-mccowan: Hey man, how's it going? Hey, what's the deal with this Marshall thingie? | 17:37 |
dave-mccowan | comparing Marshal to the Nova/Cinder option: for Marshal the encryption is visible to the guest VM. for Nova/Cinder the encryption in invisible to guest VM. depending on the use case, one or the other might be preferable. | 17:38 |
jaosorior | makes sense | 17:39 |
dave-mccowan | then... comparing Marshal, with just using OSC to grab a key... Marshal is special purposed for disk encryption, by providing the connection to dm-crypt and bitlocker. currently it connects to Barbican API directly, but I think Castellan would be a better option to support more use cases. | 17:43 |
dave-mccowan | jaosorior, edtubill thoughts? | 17:44 |
jaosorior | well... not really sure; I guess if for disk encryption castellanw as already being used, I guess it would make sense for Marshall to use that too | 17:46 |
dave-mccowan | i'd like to see Marshall support multiple KMS options. By using Castellan, it could use Barbican or an HSM directly. Now, it only support Barbican. If we don't use Castellan, then we'd need to add multiple plugins directly in Marshall to support different KMS. | 17:48 |
jaosorior | uhm; in that case using Castellan makes more sense, yeah | 17:48 |
*** pdesai has joined #openstack-barbican | 17:49 | |
*** rellerreller has quit IRC | 17:59 | |
*** shohel has quit IRC | 18:03 | |
openstackgerrit | Dave McCowan proposed openstack/barbican: Refactor Base64 use and other changes for Python3 https://review.openstack.org/233633 | 18:06 |
openstackgerrit | Fernando Diaz proposed openstack/barbican-specs: Blueprint for allowing file input to Barbican Client https://review.openstack.org/243753 | 18:08 |
*** su_zhang has joined #openstack-barbican | 18:11 | |
*** alee is now known as alee_lunch | 18:13 | |
*** diazjf has quit IRC | 18:14 | |
jhfeng | dave-mccowan: will this marshal agent run in VM kernel or userspace ? | 18:16 |
dave-mccowan | the agent runs in userspace | 18:17 |
jhfeng | dave-mccowan: thanks, still reading its wiki | 18:19 |
*** diazjf has joined #openstack-barbican | 18:20 | |
*** mixos has quit IRC | 18:21 | |
jkf | Anyone around who I can get some final approvals from for my health check blueprint? https://review.openstack.org/#/c/207317/ | 18:21 |
jkf | Also, my pkcs11 changes went up yesterday, for anyone who wants to review and give feedback. https://review.openstack.org/#/c/243291/ | 18:22 |
jhfeng | jkf: I'll take a look it. I also have a p11 session pool patch. maybe our changes are overlapped | 18:24 |
jhfeng | https://review.openstack.org/#/c/243202/ | 18:24 |
*** jaosorior has quit IRC | 18:25 | |
jkf | jhfeng: I saw your change yesterday. While I don't implement session pooling in my module, it does handle sessions a little better than the original module. | 18:25 |
*** jaosorior has joined #openstack-barbican | 18:25 | |
jkf | I am also looking for iterate on that to either a single persistent session, or a small pool, depending on what performance looks like at scale. | 18:26 |
jhfeng | jkf: have you measured any perf improvement with your patch ? | 18:27 |
jhfeng | jkf: single session wouldn't work. need pool | 18:27 |
jkf | At a small scale, yes. Caching of the project keks provides the biggest win so far. | 18:27 |
jhfeng | jkf: cool | 18:28 |
*** jaosorior has quit IRC | 18:29 | |
*** jaosorior has joined #openstack-barbican | 18:29 | |
jkf | jhfeng: How're you using barbican such that a single session wouldn't work? | 18:29 |
*** su_zhang has quit IRC | 18:32 | |
jhfeng | jkf: in multithreads/ multiprocess case, the 2nd thread will get P11 failure because another operation is using the session | 18:32 |
*** su_zhang has joined #openstack-barbican | 18:32 | |
jkf | Ah, ok. How has threading been working out for Barbican? I've been considering it for my deployment. | 18:33 |
jhfeng | unless you change session to that can be shared | 18:33 |
jhfeng | changing process number in /etc/barbican/vassals/barbican-api.ini | 18:35 |
jhfeng | i also added threads in it. looks like 'threads' is not in default | 18:36 |
*** mixos has joined #openstack-barbican | 18:36 | |
openstackgerrit | Fernando Diaz proposed openstack/python-barbicanclient: Update Readme to include new/updated CLI commands https://review.openstack.org/243772 | 18:37 |
jkf | Gotcha, I didn't think anyone was actually doing threading with Barbican. I'll have to go look at my code again with that in mind. | 18:38 |
jkf | I already predict one issue, in that the new module holds open a single session to do key caching operations on. Might need to mutex wrap that to serialize key caching. Should only affect the first time a project kek is loaded though. | 18:40 |
*** su_zhang has quit IRC | 18:41 | |
jhfeng | jkf: you may need my fix for initializing p11 crypto plugin manager in multithreading env | 18:45 |
jhfeng | https://review.openstack.org/#/c/241712/ | 18:46 |
*** su_zhang has joined #openstack-barbican | 18:46 | |
jkf | jhfeng: Thanks, I'll take a look. | 18:46 |
*** su_zhang has quit IRC | 18:47 | |
jhfeng | jvrbanac: please also review above patch | 18:47 |
*** su_zhang has joined #openstack-barbican | 18:47 | |
*** dave-mcc_ has joined #openstack-barbican | 18:58 | |
*** dave-mccowan has quit IRC | 18:58 | |
*** dave-mccowan has joined #openstack-barbican | 18:59 | |
*** mixos has quit IRC | 19:03 | |
*** dave-mcc_ has quit IRC | 19:03 | |
*** mixos has joined #openstack-barbican | 19:04 | |
*** kfarr has joined #openstack-barbican | 19:09 | |
edtubill | dave-mccowan: sounds interesting, I guess my only issue is that you have to expose barbican in the network for the VM to connect to it. | 19:11 |
edtubill | dave-mccowan:I also wanted to get your opinion for this patch: https://review.openstack.org/#/c/239798/ | 19:12 |
edtubill | dave-mccowan: it looks like there are competing ideas for how block encryption should be done. | 19:13 |
dave-mccowan | edtubill yep. in the marshall use case, barbican would be on the data network, instead of on the management network. not necessarily pro or con, i think, just a different use case. | 19:13 |
*** su_zhang has quit IRC | 19:16 | |
edtubill | dave-mccowan: I can see that. Is another advantage that you don't have to do different implementations for iSCSI, Ceph, ... ? | 19:17 |
*** su_zhang has joined #openstack-barbican | 19:17 | |
dave-mccowan | good point, i hadn't thought about that. but, i think that would be case. | 19:18 |
dave-mccowan | the same code could also be used on bare metal too... | 19:18 |
jkf | Is it just me, or is the devstack gate broken right now? | 19:22 |
dave-mccowan | jkf my rebase just finished with the expected results | 19:24 |
edtubill | dave-mccowan: that sounds cool, I'm still going through the docs for it. I guess this is for the use case where you want to provide block encryption to the customer VM directly and it's going to be a solution that will sit beside the current solutions which are at the compute host dmcrypt level (non competing). | 19:24 |
dave-mccowan | just two deployment options. i'm not sure if a single customer would want to use both, but certainly Marshal fits a niche and is not intended to replace the current deployment options. | 19:27 |
jkf | dave-mccowan: I asked because I noticed your recent refactor base64 change had a devstack gate failure as well. | 19:27 |
*** mixos has quit IRC | 19:28 | |
dave-mccowan | yea... the same failures i had before, i was rebasing before fixing. are you seeing an API timeout error? that one seems to be popping up more frequently these days. | 19:29 |
jkf | Not sure, I'm having a hard time figuring out why devstack is failing. First time dealing with devstack in the gate. | 19:30 |
diazjf | redrobot, notmyname, I created an etherpad with what was discussed yesterday on Castellan in Swift's keymaster: https://etherpad.openstack.org/p/swifjt-keymaster-with-castellan any input would be great! :) | 19:30 |
dave-mccowan | jkf what's your CR number? | 19:32 |
jkf | dave-mccowan: to me it looks like its failing to install packages during setup. | 19:32 |
jkf | https://review.openstack.org/#/c/243291/ | 19:33 |
dave-mccowan | jkf that looks like a transient gate failure to me. i agree it looks like package install failed, long before barbican comes into the picture. | 19:35 |
jkf | So I can just recheck it then? | 19:35 |
*** alee_lunch is now known as alee | 19:35 | |
dave-mccowan | yep | 19:36 |
jkf | sweet, thanks! :) | 19:36 |
*** mixos has joined #openstack-barbican | 19:56 | |
*** diazjf has quit IRC | 19:58 | |
openstackgerrit | Elvin Tubillara proposed openstack/barbican-specs: Create spec for cron job garbage collector for barbican database https://review.openstack.org/243806 | 19:59 |
*** nelsnelson has quit IRC | 19:59 | |
*** nelsnelson has joined #openstack-barbican | 20:01 | |
*** diazjf has joined #openstack-barbican | 20:02 | |
*** jhfeng has quit IRC | 20:05 | |
*** jhfeng has joined #openstack-barbican | 20:14 | |
*** rellerreller has joined #openstack-barbican | 20:15 | |
*** gyee has quit IRC | 20:18 | |
*** mixos has quit IRC | 20:19 | |
*** jhfeng has quit IRC | 20:24 | |
*** jmckind_ is now known as jmckind | 20:26 | |
*** mixos has joined #openstack-barbican | 20:29 | |
*** mixos has quit IRC | 20:30 | |
*** pdesai has quit IRC | 20:30 | |
*** su_zhang has quit IRC | 20:32 | |
*** jmckind is now known as jmckind_ | 20:34 | |
*** mixos has joined #openstack-barbican | 20:41 | |
*** rellerreller has quit IRC | 20:43 | |
*** dave-mccowan has quit IRC | 20:48 | |
*** dave-mccowan has joined #openstack-barbican | 20:50 | |
*** dave-mcc_ has joined #openstack-barbican | 20:52 | |
*** dave-mccowan has quit IRC | 20:55 | |
*** jaosorior has quit IRC | 20:58 | |
*** diazjf has quit IRC | 20:59 | |
*** su_zhang has joined #openstack-barbican | 21:06 | |
*** jamielennox is now known as jamielennox|away | 21:25 | |
*** woodster_ has joined #openstack-barbican | 21:27 | |
*** diazjf has joined #openstack-barbican | 21:39 | |
*** jhfeng has joined #openstack-barbican | 21:39 | |
*** silos has left #openstack-barbican | 21:41 | |
*** mixos has quit IRC | 21:52 | |
*** jmckind has joined #openstack-barbican | 21:55 | |
*** mixos has joined #openstack-barbican | 21:56 | |
*** jmckind has quit IRC | 21:56 | |
*** jmckind has joined #openstack-barbican | 21:57 | |
*** jmckind_ has quit IRC | 21:57 | |
*** jmckind has quit IRC | 21:58 | |
*** jmckind has joined #openstack-barbican | 21:58 | |
*** jmckind has quit IRC | 21:59 | |
*** jmckind has joined #openstack-barbican | 22:00 | |
openstackgerrit | Fernando Diaz proposed openstack/barbican: Add user_meta column to Secrets Database https://review.openstack.org/242645 | 22:00 |
*** jmckind has quit IRC | 22:00 | |
*** jmckind has joined #openstack-barbican | 22:01 | |
*** jmckind has quit IRC | 22:03 | |
*** jmckind has joined #openstack-barbican | 22:03 | |
*** jmckind has quit IRC | 22:04 | |
*** mixos has quit IRC | 22:06 | |
*** pdesai has joined #openstack-barbican | 22:12 | |
*** jamielennox|away is now known as jamielennox | 22:24 | |
*** mixos has joined #openstack-barbican | 22:25 | |
*** mixos has quit IRC | 22:27 | |
*** diazjf has quit IRC | 22:33 | |
*** reaperhulk_ has joined #openstack-barbican | 22:35 | |
*** reaperhulk has joined #openstack-barbican | 22:35 | |
*** reaperhulk_ has quit IRC | 22:42 | |
*** reaperhulk_ has joined #openstack-barbican | 22:43 | |
*** reaperhulk_ has quit IRC | 22:44 | |
*** spotz is now known as spotz_zzz | 22:46 | |
*** reaperhulk has quit IRC | 22:47 | |
*** reaperhulk has joined #openstack-barbican | 22:47 | |
*** alee has quit IRC | 22:50 | |
*** edtubill has quit IRC | 22:51 | |
*** su_zhang has quit IRC | 23:17 | |
*** jhfeng has quit IRC | 23:21 | |
*** stevemar_ has quit IRC | 23:25 | |
*** stevemar_ has joined #openstack-barbican | 23:26 | |
*** stevemar_ has quit IRC | 23:30 | |
*** su_zhang has joined #openstack-barbican | 23:33 | |
*** su_zhang has quit IRC | 23:34 | |
*** kfarr has quit IRC | 23:42 | |
*** alee has joined #openstack-barbican | 23:52 | |
*** su_zhang has joined #openstack-barbican | 23:52 | |
*** su_zhang has quit IRC | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!