*** pcaruana has quit IRC | 00:02 | |
*** rmascena__ has quit IRC | 00:25 | |
*** tonyb has quit IRC | 00:33 | |
*** tonyb has joined #openstack-barbican | 00:35 | |
*** namnh has joined #openstack-barbican | 00:42 | |
zhongjun_ | alee__ : Hi | 01:53 |
---|---|---|
alee__ | zhongjun_, hi - starting the weekly meeting in a couple minutes | 01:57 |
zhongjun_ | alee__: oh, enjoy your meeting | 01:59 |
alee__ | zhongjun_, you;re welcome to join if you like | 01:59 |
alee__ | its the barbican weekly meeting | 01:59 |
alee__ | #startmeeting barbican | 02:00 |
zhongjun_ | alee__: Which channel | 02:00 |
openstack | Meeting started Tue Apr 24 02:00:24 2018 UTC and is due to finish in 60 minutes. The chair is alee__. Information about MeetBot at http://wiki.debian.org/MeetBot. | 02:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 02:00 |
*** openstack changes topic to " (Meeting topic: barbican)" | 02:00 | |
openstack | The meeting name has been set to 'barbican' | 02:00 |
alee__ | #topic roll call | 02:00 |
*** openstack changes topic to "roll call (Meeting topic: barbican)" | 02:00 | |
alee__ | namnh? | 02:01 |
zhongjun_ | hi | 02:01 |
namnh | alee__: hi alee | 02:01 |
alee__ | hi namnh zhongjun_ | 02:02 |
namnh | i am waitting the weekly meeting | 02:02 |
alee__ | this is it :) | 02:02 |
alee__ | in case you missed it, we moved the meeting to now | 02:03 |
namnh | yes, | 02:03 |
alee__ | because afterthe change to daylight savings time, the time was a little too late in the steate | 02:03 |
alee__ | states | 02:03 |
alee__ | I dont see Jeremy though | 02:04 |
namnh | yeah, it is still good to me | 02:04 |
alee__ | well -lets get started | 02:04 |
alee__ | #topic rocky | 02:05 |
*** openstack changes topic to "rocky (Meeting topic: barbican)" | 02:05 | |
alee__ | milestone 1 build was released last week | 02:05 |
alee__ | I submitted the build on friday morning with dave's help | 02:05 |
alee__ | you probably noticed a bunch of patches meing merged at that time. | 02:06 |
alee__ | we're planning on doing some stable branch releases this week | 02:06 |
alee__ | as well as possibly some client releases | 02:06 |
alee__ | we're still on track for our rocky deliverables .. | 02:07 |
alee__ | https://etherpad.openstack.org/p/barbican-tracker-rocky | 02:07 |
alee__ | although we want to try and get most of our features in by milestone 2 if we can | 02:08 |
alee__ | including the OVO patches | 02:08 |
alee__ | questions/comments on the rocky builds / schedule? | 02:08 |
alee__ | #topic PTG | 02:09 |
*** openstack changes topic to "PTG (Meeting topic: barbican)" | 02:09 | |
alee__ | the next PTG is scheduled for september in denver IIRC | 02:10 |
alee__ | will either of you guys attend? | 02:10 |
alee__ | namnh, zhongjun_ ? | 02:11 |
namnh | i'm not sure about whether i can join, it depends on my company | 02:11 |
namnh | or TSP:) | 02:12 |
zhongjun_ | alee_ I cloud attend to next PTG | 02:12 |
alee__ | namnh, sure - I figured most folks would not know by now -- I just know that the cheaper "early bird pricing" is supposed to expire relatively early | 02:13 |
alee__ | like in the next few weeks | 02:13 |
alee__ | so good to sign up if you plan to attend | 02:13 |
alee__ | zhongjun_, good to know! | 02:13 |
alee__ | also helps me let them know how many will attend for barbican for planning purposes | 02:14 |
namnh | alee__: sure, i will ask some guys in our company | 02:14 |
alee__ | cool | 02:14 |
alee__ | zhongjun_, perhaps a little intro -- I don't think I've seen you attend the weekly meeting before? | 02:15 |
zhongjun_ | I have a simple question | 02:15 |
alee__ | unless I forgot the nick | 02:15 |
zhongjun_ | yes | 02:16 |
zhongjun_ | This is my first time | 02:16 |
alee__ | zhongjun_, great - tell us a little about you, and what your interest in barbican is | 02:16 |
namnh | zhongjun_: welcome to barbican team :) | 02:16 |
alee__ | and welcome :) | 02:16 |
zhongjun_ | I usually work on manila | 02:16 |
zhongjun_ | We are trying to use manila in huawei | 02:17 |
alee__ | ok - and you're trying to integrate using barbican with manila? | 02:18 |
zhongjun_ | But I am a new guy, and I don't know the detail about barbican | 02:19 |
zhongjun_ | alee__ : This is my patches: https://review.openstack.org/#/q/owner:jun.zhongjun2%2540gmail.com+status:merged | 02:19 |
zhongjun_ | alee__ : Not sure now | 02:19 |
zhongjun_ | namnh: thanks | 02:20 |
alee__ | great -- so how can we help you? | 02:20 |
namnh | zhongjun_: cool, what is your question? | 02:21 |
zhongjun_ | In aws cloud, we have host key and data key. But in barbican, I only see the data key named secret | 02:22 |
zhongjun_ | Do we have the API to manage the key and data key in barbican | 02:23 |
zhongjun_ | key: https://docs.aws.amazon.com/kms/latest/APIReference/API_CreateKey.html | 02:23 |
zhongjun_ | datakey: https://docs.aws.amazon.com/kms/latest/APIReference/API_GenerateDataKey.html | 02:24 |
alee__ | zhongjun_, whats the difference between a host key and a data key? | 02:24 |
zhongjun_ | alee__: We generate datakey by key. | 02:25 |
alee__ | zhongjun_, ok - I think I see what you are talking about | 02:25 |
alee__ | zhongjun_, so barbican has a fairly simple interface | 02:26 |
alee__ | zhongjun_, basically , you store, generate or retrieve a secret | 02:26 |
alee__ | and that secret could be some data, a password, or a key | 02:26 |
alee__ | now those secrets are stored in a back-end | 02:27 |
alee__ | and they are of course stored encrypted | 02:27 |
alee__ | the secrets are encrypted using a key encryption key | 02:27 |
alee__ | and if you use for instance the pkcs11 backend, they are stored encrypted by a tenant specific key encryption key | 02:28 |
alee__ | the kek usually never leaves the barbican system though | 02:28 |
alee__ | if you wanted to pre-encrypt you own keys using a kek the user could retrieve, you could do that, but you'd have to manage all of that | 02:29 |
alee__ | thats not in the api | 02:29 |
alee__ | does that make sens? | 02:30 |
alee__ | sense? | 02:30 |
zhongjun_ | So we don't have a API to manage " a tenant specific key encryption key" like the aws does | 02:30 |
alee__ | zhongjun_, right | 02:31 |
zhongjun_ | It is up to the backend | 02:31 |
alee__ | zhongjun_, if you are using the pkcs11 plugin for instance, a tenant specific kek is automatically geerated when the first secret is stored y that tenant | 02:31 |
alee__ | correct | 02:32 |
alee__ | there is no need for the user to explicitly request -- or ever retrieve that kek | 02:32 |
zhongjun_ | Maybe the user want to use the same tenant specific kek | 02:33 |
alee__ | zhongjun_, the barbican api is pretty simple. right now users have no facility to manage their keks | 02:34 |
alee__ | zhongjun_, an interesting idea - which has come up before - would be add this kind of feature | 02:35 |
zhongjun_ | Do we have plan to implement the feature about support user to manage their keks | 02:35 |
alee__ | that is - take a small amount of data and a reference to a secret the user owns - and encrypt the secret with the kek | 02:35 |
alee__ | zhongjun_, there is no such ffeature currently planned | 02:36 |
zhongjun_ | Is there a link? | 02:36 |
alee__ | if you'd like to propose it, feel free to write a spec | 02:36 |
alee__ | zhongjun_, I'd have to check - not sure a spec was ever written for it | 02:36 |
zhongjun_ | okay, thanks, that make sense | 02:37 |
alee__ | if there is enough interest/ use case, we could certainly work to get it in | 02:37 |
zhongjun_ | got it | 02:38 |
alee__ | cool - anything else? | 02:38 |
zhongjun_ | not now | 02:38 |
alee__ | ok | 02:38 |
alee__ | #topic OVO patches | 02:38 |
*** openstack changes topic to "OVO patches (Meeting topic: barbican)" | 02:38 | |
alee__ | namnh, I suggested that we do a google hangout to try and get the reviews on your patches going | 02:39 |
alee__ | since that has helped in the past in terms of getting series od patches approved | 02:39 |
alee__ | unfortunately neither dave nor jeremy are here | 02:40 |
alee__ | and it probably makes sense to do one collectively | 02:40 |
namnh | alee__: it's ok to me. btw, i'd like to notify you about the status of OVO | 02:40 |
alee__ | please do | 02:40 |
namnh | currenly, there two first patch set are really for reviewing | 02:41 |
namnh | https://review.openstack.org/#/c/559014/ | 02:41 |
namnh | https://review.openstack.org/#/c/499004/ | 02:41 |
namnh | i am replacing each resource like secret, order, acl, etc to use OVO | 02:42 |
namnh | on my local | 02:42 |
*** annp has quit IRC | 02:42 | |
namnh | maybe, i will push a patch to replace ACL resource using OVO | 02:42 |
namnh | today | 02:42 |
alee__ | are any of these new classes actually being used in the functional/unit tests? | 02:43 |
namnh | you can see it as an example | 02:43 |
alee__ | eh? | 02:44 |
namnh | it must be, but currently, i am forcusing on changing UT to pass py27 | 02:44 |
alee__ | sorry - just confirming -- in the reviews you listed above, when the various tests run, are they actually using the new OVO classes? | 02:45 |
alee__ | or is there some switch that needs to be toggled - or some further patches that need to land first? | 02:47 |
namnh | as my plan, i will split two phases. Phase 1: I just only add files which have OVO class. Anh phase 2: i will replace barbican's resource (secret, order, container, ...) using OVO | 02:47 |
alee__ | gotcha - just confirming | 02:48 |
namnh | so all of these patchs: https://review.openstack.org/#/q/topic:bp/rolling-upgrade+(status:open+OR+status:merged) for phase 01 | 02:48 |
namnh | and I am doing phase 2 on my local to get suitable OVO class | 02:49 |
namnh | and for now. there are two patch set as i sent the link already for reviewing | 02:49 |
alee__ | namnh, ok -- in reviewing phase 1, then it would be useful for me to understand your methodology | 02:50 |
namnh | yeah, that's what i mean. | 02:51 |
alee__ | ie. I'd like to gain some idea about what your procedure is for converting a barbican object - say secret or transport key | 02:51 |
alee__ | so that I can get a sense if what you are doing is correct | 02:51 |
alee__ | obviously there will be changes needed as you get to phase 2 | 02:51 |
alee__ | and the tests actually run against the objects | 02:52 |
alee__ | that what I was looking for mostly with a google hangout -- just a walkthrough | 02:52 |
alee__ | namnh, does that make sense? | 02:53 |
namnh | yes, tomorrow is good to me | 02:53 |
*** annp has joined #openstack-barbican | 02:54 | |
alee__ | namnh, ok - lets see if we can get a time when we get either dave or jeremy to join too | 02:54 |
alee__ | that way we can get all the needed reviewers to move this along | 02:54 |
alee__ | I worry that if we take too long, we wont get phase 2 in .. | 02:55 |
namnh | i understood, i am trying my best | 02:55 |
alee__ | namnh, no worries - you're doing great -- I just dont want a lack of reviews to hold you up | 02:56 |
namnh | because, I still have a feature in oslo.config, that why i don't update anything last weeek | 02:56 |
namnh | alee__: thanks for understanding | 02:56 |
alee__ | namnh, ack -- I know we're all wearing many hats :) | 02:57 |
namnh | :))) | 02:57 |
alee__ | but I think your patches have not gotten reviews because people are scared of starting on them - and am hoping to kick start some reviews | 02:58 |
alee__ | so please send out an email and we can try to schedule a hangout | 02:58 |
alee__ | the time zone thing is tricky but we should be able to make something work. | 02:59 |
alee__ | #topic anything else? | 02:59 |
*** openstack changes topic to "anything else? (Meeting topic: barbican)" | 02:59 | |
namnh | that's all to me | 03:00 |
namnh | :) | 03:00 |
alee__ | namnh, zhongjun_ thanks for coming -- g'night ! | 03:00 |
alee__ | or g'day as it were .. | 03:00 |
alee__ | #endmeeting | 03:01 |
*** openstack changes topic to "Discussion about development of OpenStack Barbican and its client libraries. - Logs: http://eavesdrop.openstack.org/irclogs/%23openstack-barbican/" | 03:01 | |
openstack | Meeting ended Tue Apr 24 03:01:03 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 03:01 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/barbican/2018/barbican.2018-04-24-02.00.html | 03:01 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/barbican/2018/barbican.2018-04-24-02.00.txt | 03:01 |
openstack | Log: http://eavesdrop.openstack.org/meetings/barbican/2018/barbican.2018-04-24-02.00.log.html | 03:01 |
namnh | alee__: :)) thanks | 03:01 |
namnh | good night to you, i am starting a new working day :)) | 03:01 |
zhongjun_ | Thanks | 03:02 |
*** bkopilov has joined #openstack-barbican | 06:40 | |
bkopilov | Hi Experts , a quick question . i have an openstack with barbican , when trying to create a sign image get : - default default] Secret retrieval attempt not allowed - please review your user/project privileges: PolicyNotAuthorized: secret:get is disallowed by policy | 06:41 |
bkopilov | How can i fix it ? | 06:41 |
*** pcaruana has joined #openstack-barbican | 06:58 | |
*** jaosorior has joined #openstack-barbican | 07:08 | |
openstackgerrit | Nam Nguyen Hoai proposed openstack/barbican master: [WIP] Replace ACL resource to use OVO https://review.openstack.org/563857 | 08:38 |
openstackgerrit | Nam Nguyen Hoai proposed openstack/barbican master: [WIP] Replace ACL resource to use OVO https://review.openstack.org/563857 | 08:41 |
openstackgerrit | Nam Nguyen Hoai proposed openstack/barbican master: [WIP] Replace Transport-key using OVO https://review.openstack.org/563858 | 08:41 |
*** jaosorior has quit IRC | 09:18 | |
*** jaosorior has joined #openstack-barbican | 09:44 | |
*** namnh has quit IRC | 09:54 | |
*** annp has quit IRC | 10:29 | |
*** annp has joined #openstack-barbican | 10:30 | |
*** jaosorior has quit IRC | 10:43 | |
*** annp has quit IRC | 10:46 | |
*** pbourke has quit IRC | 11:18 | |
*** pbourke has joined #openstack-barbican | 11:18 | |
*** alee has joined #openstack-barbican | 11:37 | |
*** alee__ has quit IRC | 11:39 | |
*** jaosorior has joined #openstack-barbican | 11:48 | |
*** abishop has joined #openstack-barbican | 11:52 | |
*** raildo has joined #openstack-barbican | 12:08 | |
*** zhongjun_ has quit IRC | 12:09 | |
*** zhongjun_ has joined #openstack-barbican | 12:09 | |
*** Kevin_Zheng has quit IRC | 12:11 | |
*** Kevin_Zheng has joined #openstack-barbican | 12:12 | |
*** jaosorior has quit IRC | 12:15 | |
*** jaosorior has joined #openstack-barbican | 12:16 | |
*** alee has quit IRC | 12:31 | |
*** portdirect has quit IRC | 12:36 | |
*** portdirect has joined #openstack-barbican | 12:37 | |
*** Dmitrii-Sh has quit IRC | 12:37 | |
*** Dmitrii-Sh has joined #openstack-barbican | 12:37 | |
*** dave-mccowan has joined #openstack-barbican | 13:16 | |
*** dave-mccowan has quit IRC | 13:21 | |
*** dave-mccowan has joined #openstack-barbican | 13:22 | |
*** alee has joined #openstack-barbican | 13:22 | |
*** jmlowe has quit IRC | 13:27 | |
*** jaosorior has quit IRC | 13:55 | |
*** jaosorior has joined #openstack-barbican | 13:55 | |
*** jaosorior has quit IRC | 14:07 | |
*** zhongjun_ has quit IRC | 14:19 | |
*** namnh has joined #openstack-barbican | 14:35 | |
namnh | alee, i just remember that tomorrow is public holiday in vietnam. so i propose the hangout will be changed to the next tomorrow (thursday). what do you think? | 14:53 |
alee | namnh, hey - must be late there! | 14:56 |
alee | namnh, sorry -- did you send an email out to the list already? | 14:57 |
alee | I idn;t see anything | 14:57 |
alee | dave-mccowan, ping | 14:57 |
namnh | alee: not yet, | 14:57 |
alee | dave-mccowan, trying to set up a time for a google hangout to discuss namnh patches | 14:58 |
alee | and start the process going of getting them in | 14:58 |
namnh | alee: you mean the hangout meeting will be the weekly meeting? | 14:58 |
alee | namnh, that was my original idea | 14:58 |
alee | as everyone would be there | 14:59 |
alee | if thats good for you we can try that -- that way hopefully jeremy will be there too | 14:59 |
dave-mccowan | alee ok. are you proposing next Monday? or sometime sooner? | 15:00 |
namnh | alee: sorry, i missed your idea :( | 15:00 |
alee | dave-mccowan, namnh either way | 15:00 |
alee | whatever makes sense for you guys | 15:00 |
alee | if we want to get jeremy there, it might make sense to just schedule for next monday during the weekly meeting | 15:01 |
*** redrobot has joined #openstack-barbican | 15:02 | |
*** redrobot is now known as Guest50424 | 15:03 | |
dave-mccowan | alee 10pm EDT would be better for me. (any night) | 15:03 |
namnh | alee: the weekly meeting is 9.00 am at vietnam, so i think you can change the time earlier, it is more suitable for you | 15:03 |
alee | dave-mccowan, namnh lets do next week during the regular meeting | 15:04 |
alee | which is at 10pm EDT | 15:04 |
alee | earlier is actually trickier for me (getting kids to bed etc.) | 15:05 |
*** jaosorior has joined #openstack-barbican | 15:05 | |
namnh | alee: :))) got it. | 15:05 |
alee | namnh, please go ahead and send out an email so that interested parties can join. | 15:06 |
dave-mccowan | 10pm is OK... for some reason i thought it was 11. | 15:06 |
alee | dave-mccowan, we changed it | 15:06 |
alee | dave-mccowan, you're not reading your openstack-dev emails anymore :) | 15:06 |
namnh | alee: summary, the hangout will be on 10 pm EDT | 15:08 |
alee | (on Monday 30 April) | 15:08 |
namnh | sure, i will send an email right now | 15:09 |
alee | cool thanks | 15:09 |
dave-mccowan | or 0200 UTC on Tuesday May 1 | 15:10 |
dave-mccowan | alee, do you want to update http://git.openstack.org/cgit/openstack-infra/irc-meetings/tree/meetings/barbican-meeting.yaml | 15:10 |
alee | dave-mccowan, yeah - let me do that before I forget .. | 15:11 |
*** Guest50424 has quit IRC | 15:12 | |
*** redrobot has joined #openstack-barbican | 15:23 | |
*** redrobot is now known as Guest92551 | 15:24 | |
*** Guest92551 is now known as redrobot | 15:25 | |
*** pcaruana has quit IRC | 15:51 | |
*** jmlowe has joined #openstack-barbican | 15:55 | |
*** jmlowe has quit IRC | 15:59 | |
*** pbourke has quit IRC | 16:04 | |
*** pbourke has joined #openstack-barbican | 16:04 | |
*** alee_ has joined #openstack-barbican | 16:22 | |
*** alee has quit IRC | 16:26 | |
openstackgerrit | Nam Nguyen Hoai proposed openstack/barbican master: Implement OVO for Barbican [1] https://review.openstack.org/499004 | 16:28 |
openstackgerrit | Nam Nguyen Hoai proposed openstack/barbican master: Initial OVO for Barbican https://review.openstack.org/559014 | 16:28 |
openstackgerrit | Nam Nguyen Hoai proposed openstack/barbican master: [WIP] Implement OVO for Barbican [4] https://review.openstack.org/528972 | 16:29 |
openstackgerrit | Nam Nguyen Hoai proposed openstack/barbican master: [WIP] Implement OVO for Barbican [3] https://review.openstack.org/499419 | 16:29 |
openstackgerrit | Nam Nguyen Hoai proposed openstack/barbican master: [WIP] Replace Transport-key using OVO https://review.openstack.org/563858 | 16:31 |
openstackgerrit | Nam Nguyen Hoai proposed openstack/barbican master: [WIP] Replace Transport-key using OVO https://review.openstack.org/563858 | 16:36 |
openstackgerrit | Nam Nguyen Hoai proposed openstack/barbican master: [WIP] Replace secretstore and secretmeta using OVO https://review.openstack.org/564025 | 16:36 |
openstackgerrit | Nam Nguyen Hoai proposed openstack/barbican master: [WIP] Replace Transport-key using OVO https://review.openstack.org/563858 | 16:43 |
*** pcaruana has joined #openstack-barbican | 16:43 | |
openstackgerrit | Nam Nguyen Hoai proposed openstack/barbican master: [WIP] Replace secretstore and secretmeta using OVO https://review.openstack.org/564025 | 16:43 |
openstackgerrit | Nam Nguyen Hoai proposed openstack/barbican master: [WIP] Implement OVO for Barbican [5] https://review.openstack.org/500244 | 16:56 |
*** namnh has quit IRC | 17:21 | |
*** jaosorior has quit IRC | 17:24 | |
*** namnh has joined #openstack-barbican | 17:25 | |
*** namnh has quit IRC | 17:30 | |
*** namnh has joined #openstack-barbican | 17:31 | |
*** namnh has quit IRC | 17:44 | |
*** namnh has joined #openstack-barbican | 17:45 | |
*** namnh has quit IRC | 17:55 | |
*** bkopilov has quit IRC | 17:59 | |
*** namnh has joined #openstack-barbican | 18:00 | |
*** alee__ has joined #openstack-barbican | 18:05 | |
*** alee_ has quit IRC | 18:08 | |
*** namnh has quit IRC | 18:10 | |
*** bkopilov has joined #openstack-barbican | 18:20 | |
*** pcaruana has quit IRC | 18:32 | |
*** diablo_rojo_ has joined #openstack-barbican | 18:38 | |
*** dims has quit IRC | 19:02 | |
*** fungi has joined #openstack-barbican | 19:03 | |
fungi | alee__: in working on prepping for the storyboard migration, i noticed that the openstack/castellan repository is missing from https://git.openstack.org/cgit/openstack/governance/tree/reference/projects.yaml (is that an oversight?) | 19:07 |
*** dims has joined #openstack-barbican | 19:09 | |
*** raildo has quit IRC | 20:34 | |
*** raildo has joined #openstack-barbican | 20:34 | |
alee__ | fungi, if you grep for castellan, you'll see that its been transferred to oslo control | 20:42 |
*** rmascena has joined #openstack-barbican | 20:44 | |
*** raildo has quit IRC | 20:46 | |
*** rmascena has quit IRC | 20:50 | |
*** jmlowe has joined #openstack-barbican | 20:50 | |
*** jmlowe has quit IRC | 20:52 | |
*** abishop has quit IRC | 21:24 | |
*** namnh has joined #openstack-barbican | 21:37 | |
fungi | alee__: thanks! i totally did not think to check the rest of the projects.yaml for it, and so should have. sorry for the confusion | 21:49 |
*** alee__ has quit IRC | 22:03 | |
*** namnh has quit IRC | 22:07 | |
*** dave-mccowan has quit IRC | 22:15 | |
*** alee__ has joined #openstack-barbican | 22:44 | |
*** redrobot has quit IRC | 23:30 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!