madhuri | adrian_otto, sdake_ ping | 00:04 |
---|---|---|
*** SourabhP has quit IRC | 00:04 | |
*** jjfreric has quit IRC | 00:12 | |
*** jjfreric has joined #openstack-containers | 00:16 | |
adrian_otto | hi madhuri | 00:16 |
madhuri | hi adrian_otto | 00:16 |
adrian_otto | what's up? | 00:16 |
adrian_otto | I was just commenting on your TLS feature spec. | 00:16 |
madhuri | Just so many things to discuss about TLS support | 00:16 |
madhuri | I was trying to hunt you for long | 00:16 |
adrian_otto | I'm back at work again this week | 00:16 |
madhuri | I and yuanying are working on it | 00:16 |
madhuri | Thank you | 00:16 |
adrian_otto | I agree we have plenty to talka bout | 00:17 |
madhuri | What would be the good time for it? | 00:17 |
madhuri | Is it ok to talk now? | 00:17 |
adrian_otto | I'm about to head out for the day | 00:17 |
adrian_otto | but we can plan a time to do it | 00:17 |
* adrian_otto looks at his calendar | 00:18 | |
madhuri | Sure I really need it like anything | 00:18 |
adrian_otto | maybe tomorrow at 2300 UTC? | 00:18 |
madhuri | Just one point to add Barbican seems to be most suitable option for us in many ways | 00:18 |
adrian_otto | I was the one who originally suggested that we not have that as a dependency | 00:19 |
adrian_otto | but considering that bays need to be scaled... | 00:19 |
adrian_otto | we need a secure place to fetch the cert/key files from | 00:19 |
adrian_otto | and I strongly believe that Barbican is the right tool for that job. | 00:19 |
adrian_otto | what good is a bay that you can't scale | 00:20 |
adrian_otto | that sucks. | 00:20 |
madhuri | Can you make it 23:30 UTC? | 00:20 |
adrian_otto | I can. | 00:20 |
madhuri | Thank you | 00:20 |
adrian_otto | even 30 minutes together should help us converge on this | 00:20 |
madhuri | We can ask others also who want to join | 00:20 |
madhuri | This topic is so big that can't be discussed thoroughly in IRC meetings | 00:21 |
adrian_otto | please email the ML indicating that we are planning a 30 min discussion at that time, and to attend if interested. | 00:21 |
madhuri | Sure | 00:21 |
madhuri | One last thing | 00:21 |
adrian_otto | right, we should plan a series of discussions | 00:21 |
madhuri | Can you introduce us to any Barbican developer? | 00:21 |
*** dims has quit IRC | 00:21 | |
madhuri | That would be a great help | 00:22 |
adrian_otto | yes | 00:22 |
*** dims has joined #openstack-containers | 00:22 | |
adrian_otto | ok, I am making a reminder to do that fist thing tomorrow when I return to work | 00:22 |
madhuri | Thank you | 00:22 |
adrian_otto | also, on the ML thread inviting folks to tomorrow's chat | 00:23 |
madhuri | I will | 00:23 |
adrian_otto | also add [barbican] to the subject line, and ask if they would join in too if possible | 00:23 |
madhuri | Ok | 00:23 |
adrian_otto | ok, talk to you tomorrow! | 00:24 |
madhuri | Thank you again | 00:24 |
*** dims has quit IRC | 00:26 | |
madhuri | adrian_otto, Good night! See you tomorrow | 00:27 |
adrian_otto | :-) | 00:27 |
*** adrian_otto has quit IRC | 00:27 | |
*** sthillma has quit IRC | 00:33 | |
*** sthillma has joined #openstack-containers | 00:34 | |
*** ameybhide has left #openstack-containers | 00:46 | |
*** sdake has joined #openstack-containers | 00:57 | |
*** sdake_ has quit IRC | 01:01 | |
*** suro-patz1 has joined #openstack-containers | 01:03 | |
*** suro-patz2 has joined #openstack-containers | 01:03 | |
*** suro-patz1 has quit IRC | 01:03 | |
*** suro-patz has quit IRC | 01:04 | |
*** jjfreric has quit IRC | 01:05 | |
*** pgogia has quit IRC | 01:05 | |
*** dane_leblanc has joined #openstack-containers | 01:07 | |
sdake | madhuri shoot | 01:07 |
madhuri | Hi sdake | 01:08 |
madhuri | I wanted to discuss about Magnum as a CA | 01:08 |
madhuri | And I arranged a meeting tomorrow at 23:30 UTC | 01:08 |
madhuri | Please join | 01:08 |
sdake | arranged where | 01:09 |
madhuri | At #openstack-containers | 01:12 |
*** sthillma_ has joined #openstack-containers | 01:12 | |
madhuri | Adrian will aslo join | 01:12 |
madhuri | I asked barbican and anchor developers also to join | 01:12 |
madhuri | sdake, Can we discuss some points now? | 01:13 |
*** dane_leblanc has quit IRC | 01:13 | |
sdake | let me see what time that is | 01:14 |
sdake | i am negatory on hard depedencies, but that is just me | 01:14 |
*** suro-patz2 has quit IRC | 01:14 | |
sdake | i am negatory on any stackforge dependencies but that is just me | 01:15 |
*** sthillma has quit IRC | 01:15 | |
*** sthillma_ is now known as sthillma | 01:15 | |
madhuri | I have sent a mail about it. Lets hear from others also | 01:15 |
sdake | we already have neutron as a a hard dependency and lose designs as a result because of it | 01:15 |
*** dane_leblanc has joined #openstack-containers | 01:15 | |
madhuri | Agree | 01:16 |
sdake | i gave feedback in the review... | 01:16 |
madhuri | And also I am not sure how does Openstack accepts stackforge project as a dependency. | 01:16 |
madhuri | Barbican seems to be suitable for all our requirements | 01:17 |
madhuri | But I am not sure again about its adaptibility | 01:17 |
madhuri | Barbican can be used both to generate certificate and store it securely | 01:17 |
madhuri | signed by CAs like Dogtag | 01:18 |
*** sdake_ has joined #openstack-containers | 01:19 | |
sdake_ | the alternative is to write no spec, just code - then there is no record except the code base which can be later altered | 01:19 |
sdake_ | in other words the code is not a premanent choice | 01:20 |
madhuri | sdake, Yes I agree and left the spec as it is | 01:20 |
madhuri | But still it provide lots of comment | 01:20 |
madhuri | And I will surely look at all comments | 01:20 |
madhuri | sdake_, do you read my above comments about Barbican? | 01:21 |
sdake_ | no got disconnected | 01:21 |
*** sdake has quit IRC | 01:21 | |
*** erkules_ has joined #openstack-containers | 01:23 | |
madhuri | Ok I will resend them | 01:23 |
madhuri | Barbican seems to be suitable for all our requirements | 01:23 |
madhuri | But I am not sure again about its adaptibility | 01:24 |
madhuri | Barbican can be used both to generate certificate and store it securely by CA like Dogtag | 01:24 |
*** erkules has quit IRC | 01:26 | |
*** saksham_ has quit IRC | 01:33 | |
*** suro-patz has joined #openstack-containers | 01:37 | |
*** saksham has quit IRC | 01:37 | |
*** sthillma has quit IRC | 01:37 | |
*** suro-patz1 has joined #openstack-containers | 01:38 | |
*** suro-patz has quit IRC | 01:41 | |
*** bitblt has quit IRC | 01:45 | |
*** ybathia has quit IRC | 01:47 | |
*** sthillma has joined #openstack-containers | 01:48 | |
*** erkules_ has quit IRC | 01:51 | |
*** erkules_ has joined #openstack-containers | 01:52 | |
*** eghobo has quit IRC | 01:53 | |
*** unicell1 has quit IRC | 02:00 | |
*** sdake_ has quit IRC | 02:07 | |
*** suro-patz1 has quit IRC | 02:11 | |
*** suro-patz has joined #openstack-containers | 02:12 | |
*** sdake has joined #openstack-containers | 02:15 | |
*** harshs has quit IRC | 02:18 | |
*** achanda has quit IRC | 02:21 | |
*** achanda has joined #openstack-containers | 02:21 | |
*** achanda has quit IRC | 02:22 | |
madhuri | sdake, around | 02:39 |
madhuri | sdake, http://kuberneteslaunch.com/ Kubernetes v1 will be released this July | 02:40 |
sdake | yes i am aware | 02:41 |
madhuri | So we can think of switching on to it | 02:42 |
sdake | yup | 02:42 |
madhuri | And then probably move python-k8sclient to new project | 02:42 |
sdake | yuo | 02:49 |
*** rbrooker has quit IRC | 02:56 | |
openstackgerrit | Hua Wang proposed openstack/magnum: add .idea to .gitignore https://review.openstack.org/199544 | 03:02 |
*** humble_ has joined #openstack-containers | 03:02 | |
openstackgerrit | Hua Wang proposed openstack/magnum: add .idea to .gitignore https://review.openstack.org/199544 | 03:05 |
*** wanghua has quit IRC | 03:06 | |
*** yuanying has quit IRC | 03:16 | |
*** suro-patz has quit IRC | 03:17 | |
*** achanda has joined #openstack-containers | 03:26 | |
*** achanda has quit IRC | 03:34 | |
*** Kennan2 has joined #openstack-containers | 03:35 | |
*** Kennan has quit IRC | 03:36 | |
*** julim has quit IRC | 03:36 | |
*** julim has joined #openstack-containers | 03:37 | |
*** julim has quit IRC | 03:37 | |
*** pgogia has joined #openstack-containers | 03:43 | |
*** dims has joined #openstack-containers | 03:45 | |
*** dims_ has joined #openstack-containers | 03:46 | |
*** dims_ has quit IRC | 03:46 | |
*** dims_ has joined #openstack-containers | 03:46 | |
*** dims has quit IRC | 03:49 | |
*** dane_leblanc has quit IRC | 03:53 | |
*** sthillma_ has joined #openstack-containers | 03:57 | |
*** sthillma has quit IRC | 04:00 | |
*** sthillma_ is now known as sthillma | 04:00 | |
*** achanda has joined #openstack-containers | 04:00 | |
*** Drago has quit IRC | 04:01 | |
*** Marga_ has joined #openstack-containers | 04:02 | |
*** Marga__ has joined #openstack-containers | 04:02 | |
*** eghobo has joined #openstack-containers | 04:05 | |
*** achanda has quit IRC | 04:06 | |
*** Marga_ has quit IRC | 04:07 | |
*** yuanying has joined #openstack-containers | 04:08 | |
*** pgogia has left #openstack-containers | 04:09 | |
openstackgerrit | Hua Wang proposed openstack/magnum: remove unnecessary codes https://review.openstack.org/199850 | 04:09 |
openstackgerrit | Merged openstack/magnum: add .idea to .gitignore https://review.openstack.org/199544 | 04:14 |
*** dims_ has quit IRC | 04:14 | |
*** dims has joined #openstack-containers | 04:15 | |
humble_ | hi, all. we can only create containers in a swarm bay? I find that docker compose can run app. Do we have plans to use it? | 04:18 |
*** dims has quit IRC | 04:20 | |
*** achanda has joined #openstack-containers | 04:24 | |
*** eghobo has quit IRC | 04:27 | |
*** eghobo has joined #openstack-containers | 04:37 | |
*** wanghua has joined #openstack-containers | 04:43 | |
*** sdake has quit IRC | 04:45 | |
*** humble_ has quit IRC | 04:46 | |
*** unicell has joined #openstack-containers | 04:52 | |
*** dims has joined #openstack-containers | 05:01 | |
*** dims_ has joined #openstack-containers | 05:02 | |
*** harshs has joined #openstack-containers | 05:03 | |
*** madhuri has quit IRC | 05:06 | |
*** dims has quit IRC | 05:06 | |
*** jruano has quit IRC | 05:06 | |
*** dims_ has quit IRC | 05:14 | |
*** humble_ has joined #openstack-containers | 05:20 | |
*** wanghua has quit IRC | 05:24 | |
*** sthillma has quit IRC | 05:29 | |
*** eghobo_ has joined #openstack-containers | 05:31 | |
*** sthillma has joined #openstack-containers | 05:31 | |
*** SourabhP has joined #openstack-containers | 05:31 | |
*** eghobo has quit IRC | 05:34 | |
*** eghobo has joined #openstack-containers | 05:44 | |
*** harshs has quit IRC | 05:44 | |
*** eghobo has quit IRC | 05:45 | |
*** fawadkhaliq has joined #openstack-containers | 05:45 | |
*** eghobo_ has quit IRC | 05:46 | |
*** ig0r_ has joined #openstack-containers | 05:52 | |
*** ig0r__ has quit IRC | 05:55 | |
openstackgerrit | Hua Wang proposed openstack/magnum: Code refactor for prepare_service https://review.openstack.org/199875 | 05:57 |
*** j___ has quit IRC | 05:58 | |
*** Kennan2 has quit IRC | 06:02 | |
*** Kennan has joined #openstack-containers | 06:03 | |
*** sdake has joined #openstack-containers | 06:03 | |
*** unicell1 has joined #openstack-containers | 06:06 | |
*** unicell has quit IRC | 06:08 | |
*** sthillma_ has joined #openstack-containers | 06:11 | |
*** suro-patz has joined #openstack-containers | 06:13 | |
*** sthillma has quit IRC | 06:13 | |
*** sthillma_ is now known as sthillma | 06:13 | |
*** j___ has joined #openstack-containers | 06:14 | |
*** dims has joined #openstack-containers | 06:15 | |
*** BertrandN has joined #openstack-containers | 06:19 | |
yuanying | Kennan: arround? | 06:20 |
*** dims has quit IRC | 06:20 | |
yuanying | ironic template was failed because floating ip doesn't create | 06:20 |
*** suro-patz has quit IRC | 06:23 | |
*** liudong has joined #openstack-containers | 06:23 | |
*** BertrandN has quit IRC | 06:27 | |
*** erkules_ is now known as erkules | 06:39 | |
*** erkules has joined #openstack-containers | 06:39 | |
Kennan | yuanying: what env do you use ? I used devstack, all is OK | 06:41 |
Kennan | do you use devstack? | 06:41 |
yuanying | I found the reason | 06:41 |
yuanying | yes devstack | 06:41 |
yuanying | I'll comment it | 06:42 |
yuanying | https://review.openstack.org/#/c/198596/4/magnum/templates/heat-kubernetes/kubecluster-fedora-ironic.yaml | 06:42 |
Kennan | not know, I booted all Successfully | 06:42 |
yuanying | done | 06:42 |
yuanying | please let me know about your devstack environment about neutron subnet | 06:43 |
*** BertrandN has joined #openstack-containers | 06:43 | |
Kennan | yes, it was need set IP_VERSION = 4 for devstack env | 06:43 |
yuanying | oh | 06:43 |
yuanying | ok | 06:43 |
Kennan | I only allow neutron network to create ipv4 now | 06:43 |
Kennan | I did not allow to make it complicated first] | 06:43 |
yuanying | ok | 06:43 |
Kennan | devstack default create one network with two subnets(one ipv4 and one ipv6) | 06:44 |
yuanying | so this should be bug report or wishlist | 06:44 |
Kennan | devstack once was created only with ipv4 network | 06:44 |
Kennan | ipv6 was new added | 06:44 |
Kennan | and customers now many use ipv4, so if ipv6 need support, I could create a new bug | 06:45 |
yuanying | ok | 06:45 |
Kennan | and refine the templates later before those code merged | 06:45 |
Kennan | yuanying: i think ipv6 support can be added later | 06:46 |
yuanying | So we should add document about this limitation when ironic-template is supported in Magnum.. | 06:46 |
yuanying | ok | 06:46 |
Kennan | yes, yuanying: we can added such document, as the document patch not supply now, as many patch now not approved and have some comments | 06:47 |
Kennan | so I could not write doc now | 06:47 |
yuanying | OK, I will test using IP_VERSION = 4 | 06:48 |
yuanying | then if it succeed, I'll take +2 | 06:48 |
Kennan | BTW: yuanying one point | 06:49 |
Kennan | the ironic tftp now seems confict with our magnum NAT rules | 06:50 |
Kennan | sudo iptables -t nat -A POSTROUTING -o br-ex -j MASQUERADE | 06:50 |
Kennan | you should not do that now | 06:50 |
openstackgerrit | Merged openstack/magnum: Fix minion registration failure https://review.openstack.org/198939 | 06:51 |
yuanying | ok | 06:51 |
Kennan | as we assume customer would have really floatiing ip in env | 06:51 |
Kennan | not fork ip like 172,** in devstack | 06:51 |
yuanying | Maybe Ironic doesn't need it | 06:51 |
Kennan | I debugged that issue two days, and found that root cause becasue of our magnum iptables setting | 06:52 |
Kennan | :) | 06:52 |
*** achanda has quit IRC | 06:52 | |
Kennan | let me know if you have any questions. yuanying: | 06:52 |
yuanying | OK, thanks Kennan | 06:53 |
*** wanghua has joined #openstack-containers | 06:56 | |
*** nihilifer has joined #openstack-containers | 06:58 | |
*** humble_ has quit IRC | 06:58 | |
*** humble_ has joined #openstack-containers | 06:59 | |
*** wanghua has quit IRC | 07:03 | |
*** ybathia has joined #openstack-containers | 07:03 | |
*** sdake has quit IRC | 07:03 | |
*** ybathia_ has joined #openstack-containers | 07:04 | |
*** ybathia has quit IRC | 07:07 | |
*** ybathia_ is now known as ybathia | 07:07 | |
*** belmoreira has joined #openstack-containers | 07:15 | |
*** SourabhP has quit IRC | 07:17 | |
*** apuimedo has joined #openstack-containers | 07:18 | |
*** tobe has joined #openstack-containers | 07:18 | |
*** belmoreira has quit IRC | 07:21 | |
*** belmoreira has joined #openstack-containers | 07:28 | |
*** manjeets has joined #openstack-containers | 07:36 | |
*** manjeets has quit IRC | 07:37 | |
*** humble_ has quit IRC | 08:00 | |
*** humble_ has joined #openstack-containers | 08:01 | |
*** sthillma has quit IRC | 08:11 | |
*** saksham has joined #openstack-containers | 08:12 | |
*** saksham has quit IRC | 08:12 | |
*** dims has joined #openstack-containers | 08:16 | |
*** dims has quit IRC | 08:21 | |
openstackgerrit | Hua Wang proposed openstack/magnum: Code refactor for prepare_service https://review.openstack.org/199875 | 08:32 |
*** madhuri has joined #openstack-containers | 08:45 | |
*** wanghua has joined #openstack-containers | 08:46 | |
*** ybathia has quit IRC | 08:50 | |
*** humble_ has quit IRC | 08:50 | |
openstackgerrit | Martin Falatic proposed openstack/magnum: Updated Magnum documentation https://review.openstack.org/199212 | 09:09 |
openstackgerrit | Hua Wang proposed openstack/magnum: Code refactor for prepare_service https://review.openstack.org/199875 | 09:09 |
openstackgerrit | Kai Qiang Wu(Kennan) proposed openstack/magnum: Fix old network_id usage https://review.openstack.org/199458 | 09:10 |
*** ahcorporto has joined #openstack-containers | 09:12 | |
*** nihilifer has quit IRC | 09:13 | |
*** coolsvap|away is now known as coolsvap | 09:15 | |
*** fawadkhaliq has quit IRC | 09:22 | |
openstackgerrit | Hua Wang proposed openstack/magnum: remove unnecessary codes https://review.openstack.org/199850 | 09:25 |
*** coolsvap is now known as coolsvap|away | 09:48 | |
*** nihilifer has joined #openstack-containers | 09:55 | |
*** coolsvap|away is now known as coolsvap | 10:11 | |
*** dims has joined #openstack-containers | 10:17 | |
*** dims has quit IRC | 10:21 | |
*** fawadkhaliq has joined #openstack-containers | 10:22 | |
*** fawadkhaliq has quit IRC | 10:23 | |
*** fawadkhaliq has joined #openstack-containers | 10:23 | |
*** coolsvap is now known as coolsvap|away | 10:25 | |
wanghua | Kennan: ping | 10:27 |
Kennan | hi wanghua, going to leave, what's issue | 10:28 |
wanghua | Kennan: ask one question. next time | 10:28 |
wanghua | Kennan: bye | 10:28 |
Kennan | ok wanghua: other guys/cores can also help you | 10:29 |
Kennan | dont worry about it | 10:29 |
wanghua | Kennan: ok | 10:29 |
* Kennan leave now | 10:30 | |
*** humble_ has joined #openstack-containers | 10:31 | |
*** wanghua has quit IRC | 10:34 | |
*** yuanying has quit IRC | 10:41 | |
openstackgerrit | ZhiQiang Fan proposed openstack/magnum: upadte sample config file https://review.openstack.org/200008 | 10:44 |
*** sdake has joined #openstack-containers | 10:45 | |
*** sdake_ has joined #openstack-containers | 10:46 | |
*** wanghua has joined #openstack-containers | 10:47 | |
*** humble_ has quit IRC | 10:49 | |
*** sdake has quit IRC | 10:50 | |
*** fawadkhaliq has quit IRC | 11:06 | |
*** fawadkhaliq has joined #openstack-containers | 11:08 | |
*** wanghua has quit IRC | 11:17 | |
*** wanghua has joined #openstack-containers | 11:19 | |
*** coolsvap|away is now known as coolsvap | 11:22 | |
*** Daviey has joined #openstack-containers | 11:25 | |
*** sdake_ has quit IRC | 11:33 | |
*** sdake has joined #openstack-containers | 11:42 | |
*** tobe has quit IRC | 11:48 | |
*** zhenguo has quit IRC | 11:50 | |
*** jruano has joined #openstack-containers | 11:56 | |
*** sdake_ has joined #openstack-containers | 11:56 | |
*** sdake has quit IRC | 12:00 | |
*** dims has joined #openstack-containers | 12:17 | |
*** dims has quit IRC | 12:22 | |
*** fawadkhaliq has quit IRC | 12:22 | |
*** sdake has joined #openstack-containers | 12:28 | |
*** sdake_ has quit IRC | 12:31 | |
*** jay-lau-513 has joined #openstack-containers | 12:36 | |
openstackgerrit | Merged openstack/magnum: Code refactor for prepare_service https://review.openstack.org/199875 | 12:38 |
*** dims has joined #openstack-containers | 12:40 | |
*** julim has joined #openstack-containers | 12:44 | |
*** yuanying-alt has joined #openstack-containers | 12:45 | |
*** fawadkhaliq has joined #openstack-containers | 12:45 | |
*** jjfreric has joined #openstack-containers | 12:47 | |
*** pserebryakov has joined #openstack-containers | 12:47 | |
*** jjfreric has quit IRC | 12:52 | |
*** wanghua has quit IRC | 12:56 | |
*** wanghua has joined #openstack-containers | 12:56 | |
*** Marga__ has quit IRC | 13:00 | |
*** dane_leblanc has joined #openstack-containers | 13:00 | |
*** ahcorporto has left #openstack-containers | 13:01 | |
*** fawadkhaliq has quit IRC | 13:01 | |
*** Marga_ has joined #openstack-containers | 13:05 | |
*** dane_leblanc has quit IRC | 13:05 | |
*** Marga_ has quit IRC | 13:07 | |
*** Marga_ has joined #openstack-containers | 13:07 | |
*** jay-lau-513 has quit IRC | 13:09 | |
*** zhenguo has joined #openstack-containers | 13:09 | |
*** jay-lau-513 has joined #openstack-containers | 13:09 | |
openstackgerrit | ZhiQiang Fan proposed openstack/magnum: Upadte sample config file https://review.openstack.org/200008 | 13:12 |
*** rbrooker has joined #openstack-containers | 13:13 | |
*** dane_leblanc has joined #openstack-containers | 13:13 | |
openstackgerrit | ZhiQiang Fan proposed openstack/magnum: Update sample config file https://review.openstack.org/200008 | 13:15 |
*** rpothier has joined #openstack-containers | 13:19 | |
*** dane_leblanc has quit IRC | 13:19 | |
*** jjlehr has joined #openstack-containers | 13:26 | |
*** yuanying-alt has quit IRC | 13:30 | |
*** dboik_ has quit IRC | 13:36 | |
*** jjfreric has joined #openstack-containers | 13:39 | |
*** dane_leblanc has joined #openstack-containers | 13:41 | |
*** rbrooker has quit IRC | 13:51 | |
*** dboik has joined #openstack-containers | 13:56 | |
*** pserebryakov has quit IRC | 14:00 | |
*** Kennan2 has joined #openstack-containers | 14:03 | |
*** Kennan has quit IRC | 14:04 | |
*** jhova has joined #openstack-containers | 14:09 | |
*** hongbin has joined #openstack-containers | 14:17 | |
*** SourabhP has joined #openstack-containers | 14:18 | |
*** hongbin_ has joined #openstack-containers | 14:26 | |
*** macjack has quit IRC | 14:30 | |
*** nihilifer has quit IRC | 14:39 | |
*** kebray has joined #openstack-containers | 14:41 | |
*** harshs has joined #openstack-containers | 14:42 | |
*** kebray has quit IRC | 14:44 | |
*** dims has quit IRC | 14:45 | |
*** PaulCzar has joined #openstack-containers | 14:45 | |
*** kebray has joined #openstack-containers | 14:45 | |
*** adrian_otto has joined #openstack-containers | 14:49 | |
*** dims has joined #openstack-containers | 14:50 | |
*** adrian_otto has quit IRC | 14:55 | |
*** adrian_otto has joined #openstack-containers | 14:55 | |
*** jay-lau-513 has quit IRC | 14:58 | |
*** jay-lau-513 has joined #openstack-containers | 14:59 | |
*** adrian_otto has quit IRC | 15:00 | |
*** achanda has joined #openstack-containers | 15:00 | |
*** sdake_ has joined #openstack-containers | 15:01 | |
*** sdake has quit IRC | 15:05 | |
*** absubram has joined #openstack-containers | 15:05 | |
*** achanda has quit IRC | 15:06 | |
*** sdake_ has quit IRC | 15:09 | |
*** coolsvap is now known as coolsvap|away | 15:09 | |
*** sdake has joined #openstack-containers | 15:10 | |
*** hongbin has quit IRC | 15:13 | |
*** wanghua has quit IRC | 15:14 | |
*** yuanying-alt has joined #openstack-containers | 15:19 | |
*** Drago has joined #openstack-containers | 15:20 | |
*** Drago has quit IRC | 15:20 | |
*** Drago has joined #openstack-containers | 15:20 | |
*** SourabhP has quit IRC | 15:23 | |
*** yuanying-alt has quit IRC | 15:24 | |
*** harshs has quit IRC | 15:29 | |
*** dims has quit IRC | 15:30 | |
openstackgerrit | Merged openstack/magnum: Update sample config file https://review.openstack.org/200008 | 15:30 |
*** dims has joined #openstack-containers | 15:32 | |
*** dims has quit IRC | 15:32 | |
*** dims has joined #openstack-containers | 15:33 | |
*** nihilifer has joined #openstack-containers | 15:34 | |
*** nihilifer has quit IRC | 15:34 | |
*** harshs has joined #openstack-containers | 15:36 | |
*** harshs has quit IRC | 15:47 | |
*** daneyon has joined #openstack-containers | 15:48 | |
*** belmoreira has quit IRC | 15:48 | |
*** j___ has quit IRC | 15:51 | |
*** coolsvap|away is now known as coolsvap | 15:54 | |
*** BertrandN has quit IRC | 16:02 | |
*** bitblt has joined #openstack-containers | 16:03 | |
*** sthillma has joined #openstack-containers | 16:04 | |
*** dims_ has joined #openstack-containers | 16:05 | |
*** sthillma_ has joined #openstack-containers | 16:05 | |
*** unicell1 has quit IRC | 16:05 | |
*** sthillma has quit IRC | 16:08 | |
*** sthillma_ is now known as sthillma | 16:08 | |
*** dims has quit IRC | 16:09 | |
*** fawadkhaliq has joined #openstack-containers | 16:11 | |
*** Marga_ has quit IRC | 16:17 | |
*** yuanying-alt has joined #openstack-containers | 16:20 | |
*** yuanying-alt has quit IRC | 16:24 | |
*** sthillma has quit IRC | 16:33 | |
*** coolsvap is now known as coolsvap|away | 16:36 | |
*** unicell has joined #openstack-containers | 16:40 | |
*** dane_leblanc has quit IRC | 16:41 | |
*** suro-patz has joined #openstack-containers | 16:42 | |
openstackgerrit | Merged openstack/magnum: Fix old network_id usage https://review.openstack.org/199458 | 16:43 |
*** eghobo has joined #openstack-containers | 16:44 | |
*** bitblt has quit IRC | 16:45 | |
*** jruano has quit IRC | 16:46 | |
*** dane_leblanc has joined #openstack-containers | 16:48 | |
*** eghobo_ has joined #openstack-containers | 16:54 | |
*** eghobo has quit IRC | 16:58 | |
*** SourabhP has joined #openstack-containers | 17:03 | |
*** coolsvap|away is now known as coolsvap | 17:08 | |
*** rbrooker has joined #openstack-containers | 17:11 | |
*** harshs has joined #openstack-containers | 17:13 | |
*** sdake has quit IRC | 17:16 | |
*** sdake has joined #openstack-containers | 17:20 | |
*** achanda has joined #openstack-containers | 17:20 | |
*** jjfreric has quit IRC | 17:22 | |
*** saksham has joined #openstack-containers | 17:23 | |
*** jjfreric has joined #openstack-containers | 17:24 | |
*** sdake_ has joined #openstack-containers | 17:26 | |
*** Marga_ has joined #openstack-containers | 17:27 | |
*** sdake has quit IRC | 17:29 | |
*** Marga_ has quit IRC | 17:30 | |
*** Marga_ has joined #openstack-containers | 17:30 | |
*** sdake has joined #openstack-containers | 17:30 | |
*** sdake_ has quit IRC | 17:34 | |
*** dims_ has quit IRC | 17:35 | |
*** saksham has quit IRC | 17:36 | |
*** dims has joined #openstack-containers | 17:37 | |
*** j___ has joined #openstack-containers | 17:38 | |
*** saksham has joined #openstack-containers | 17:39 | |
suro-patz | jay-lau-513: yt? | 17:45 |
*** SourabhP has quit IRC | 17:47 | |
*** sthillma has joined #openstack-containers | 17:47 | |
*** hongbin has joined #openstack-containers | 17:50 | |
*** hongbin_ has quit IRC | 17:50 | |
*** hongbin has quit IRC | 17:52 | |
*** hongbin has joined #openstack-containers | 17:52 | |
suro-patz | updated the blueprint https://blueprints.launchpad.net/magnum/+spec/magnum-service-list | 18:01 |
suro-patz | jay-lau-513: ^^ | 18:01 |
*** ameybhide has joined #openstack-containers | 18:03 | |
*** jjfreric has quit IRC | 18:05 | |
*** jjfreric has joined #openstack-containers | 18:05 | |
*** hongbin has quit IRC | 18:06 | |
*** hongbin has joined #openstack-containers | 18:07 | |
*** yuanying-alt has joined #openstack-containers | 18:09 | |
*** Tango has joined #openstack-containers | 18:09 | |
*** SourabhP has joined #openstack-containers | 18:13 | |
*** yuanying-alt has quit IRC | 18:13 | |
Tango | Hi everyone, is there a link for the easy bugs for beginners? I am helping several new developers who want to start contributing. | 18:17 |
eghobo_ | https://bugs.launchpad.net/magnum/+bugs?field.tag=low-hanging-fruit | 18:19 |
*** sdake is now known as sdae | 18:19 | |
*** sdae is now known as sdake | 18:19 | |
*** dims has quit IRC | 18:21 | |
*** Marga_ has quit IRC | 18:24 | |
*** suro-patz has quit IRC | 18:31 | |
*** sdake_ has joined #openstack-containers | 18:33 | |
*** suro-patz has joined #openstack-containers | 18:33 | |
*** rbrooker has quit IRC | 18:34 | |
*** sdake has quit IRC | 18:36 | |
*** sdake has joined #openstack-containers | 18:37 | |
*** manjeets has joined #openstack-containers | 18:39 | |
*** sdake_ has quit IRC | 18:40 | |
openstackgerrit | Hongbin Lu proposed openstack/magnum: Add template definition of Mesos bay https://review.openstack.org/191476 | 18:48 |
Tango | Thanks eghobo_ | 18:58 |
*** sthillma has quit IRC | 18:58 | |
*** absubram has quit IRC | 19:00 | |
*** coolsvap is now known as coolsvap|away | 19:04 | |
*** Marga_ has joined #openstack-containers | 19:05 | |
*** dims has joined #openstack-containers | 19:10 | |
*** manjeets has quit IRC | 19:12 | |
*** rbrooker has joined #openstack-containers | 19:19 | |
*** sdake has quit IRC | 19:25 | |
*** redrobot has joined #openstack-containers | 19:26 | |
*** sdake has joined #openstack-containers | 19:29 | |
*** Marga_ has quit IRC | 19:38 | |
*** Marga_ has joined #openstack-containers | 19:39 | |
*** eghobo_ has quit IRC | 19:40 | |
*** jjlehr has quit IRC | 19:42 | |
*** jjlehr has joined #openstack-containers | 19:43 | |
*** zhenguo has quit IRC | 19:43 | |
*** sthillma has joined #openstack-containers | 19:46 | |
*** achanda has quit IRC | 19:48 | |
*** eghobo has joined #openstack-containers | 19:49 | |
*** yuanying-alt has joined #openstack-containers | 19:57 | |
*** yuanying-alt has quit IRC | 20:02 | |
*** daneyon has quit IRC | 20:14 | |
*** achanda has joined #openstack-containers | 20:15 | |
*** sdake_ has joined #openstack-containers | 20:15 | |
openstackgerrit | Hongbin Lu proposed openstack/magnum: Add documentation for smart scale down feature https://review.openstack.org/198799 | 20:16 |
openstackgerrit | Hongbin Lu proposed openstack/magnum: Implement bay smart scale down https://review.openstack.org/196526 | 20:16 |
*** manjeets has joined #openstack-containers | 20:17 | |
*** sdake has quit IRC | 20:19 | |
*** sdake_ is now known as sdake | 20:29 | |
*** achanda has quit IRC | 20:36 | |
*** achanda has joined #openstack-containers | 20:49 | |
manjeets | #hongbin even with that you have to go to m-cond server to check reason | 20:51 |
manjeets | I was saying when you list bays if create status is failed it should print reason along with | 20:51 |
sdake | when is 2300 utc? | 20:56 |
sdake | tcammann ping me when your about pls | 20:57 |
sdake | tcammann_ ping me when your about pls | 20:57 |
*** julim has quit IRC | 20:57 | |
sdake | re bay db thing | 20:57 |
hongbin | manjeets: Could you elaborate it? | 21:05 |
*** dims has quit IRC | 21:05 | |
*** dims has joined #openstack-containers | 21:07 | |
manjeets | when you do bay-create it starts and if you list bays sometimes it shows status create_in_progress but if create get failed it does not notify on terminal from where you issued the command | 21:07 |
manjeets | i mean if gets failed it should display there itself | 21:08 |
hongbin | manjeets: Two cases here | 21:10 |
hongbin | If the bay fails and Heat tells the reason of failure and Magnum don't, it will be a bug in Magnum side. | 21:11 |
hongbin | If the bay fails and both Magnum and Heat donot give the reason, then you possibly need to look into Heat to check if anything can be improved. | 21:12 |
manjeets | my point is to display reason at client side where u issued command . I am able to see the reason on m-cond service side | 21:15 |
*** apuimedo has quit IRC | 21:18 | |
hongbin | manjeets: I think Magnum does display failure reason in server side https://bugs.launchpad.net/magnum/+bug/1460091 | 21:25 |
openstack | Launchpad bug 1460091 in Magnum "add an error message field to bay" [Wishlist,Fix committed] - Assigned to Lan Qi song (lqslan) | 21:25 |
hongbin | manjeets: If not, it could be a bug or something needs to be improved. | 21:26 |
manjeets | it does on server side but I suggesting it should give very precise reason of failure on client side | 21:27 |
*** eghobo has quit IRC | 21:28 | |
*** rpothier has quit IRC | 21:33 | |
*** jruano has joined #openstack-containers | 21:33 | |
*** eghobo has joined #openstack-containers | 21:33 | |
*** agireud has joined #openstack-containers | 21:35 | |
sdake | i think what manjeets is asking for is a blocking bay create | 21:35 |
sdake | you should be able to get that information with bay-show manjeets | 21:36 |
*** slagle has quit IRC | 21:36 | |
sdake | if you can't, file a blueprint and we will get to it atsome point :) | 21:36 |
*** sdake_ has joined #openstack-containers | 21:39 | |
openstackgerrit | Hongbin Lu proposed openstack/magnum: Eliminate mutable default arguments https://review.openstack.org/198465 | 21:40 |
*** agireud has quit IRC | 21:41 | |
*** sdake has quit IRC | 21:42 | |
*** dboik has quit IRC | 21:43 | |
*** jjfreric has quit IRC | 21:44 | |
*** dane_leblanc has quit IRC | 21:44 | |
*** dane_leblanc_ has joined #openstack-containers | 21:45 | |
*** yuanying-alt has joined #openstack-containers | 21:46 | |
*** daneyon has joined #openstack-containers | 21:46 | |
*** daneyon_ has joined #openstack-containers | 21:49 | |
*** yuanying-alt has quit IRC | 21:50 | |
*** daneyon has quit IRC | 21:52 | |
openstackgerrit | Zachary Sais proposed openstack/magnum: Add .DS_Store to .gitignore https://review.openstack.org/200281 | 21:54 |
manjeets | ok | 21:54 |
*** daneyon has joined #openstack-containers | 21:56 | |
*** dboik has joined #openstack-containers | 21:56 | |
*** dboik has quit IRC | 21:57 | |
*** eghobo has quit IRC | 21:57 | |
*** daneyon_ has quit IRC | 22:00 | |
*** daneyon_ has joined #openstack-containers | 22:01 | |
*** jjlehr has quit IRC | 22:01 | |
*** jruano has quit IRC | 22:02 | |
*** dims has quit IRC | 22:03 | |
*** dims has joined #openstack-containers | 22:03 | |
*** daneyon has quit IRC | 22:04 | |
*** coolsvap|away is now known as coolsvap | 22:05 | |
*** daneyon_ has quit IRC | 22:11 | |
*** manjeets has quit IRC | 22:13 | |
*** Marga_ has quit IRC | 22:19 | |
*** dane_leblanc_ has quit IRC | 22:40 | |
*** fawadkhaliq has quit IRC | 22:43 | |
*** Tango has quit IRC | 22:48 | |
*** hongbin has quit IRC | 22:56 | |
*** apuimedo has joined #openstack-containers | 22:57 | |
*** zaneb has left #openstack-containers | 23:04 | |
*** eghobo has joined #openstack-containers | 23:06 | |
*** eghobo_ has joined #openstack-containers | 23:09 | |
*** eghobo has quit IRC | 23:12 | |
*** coolsvap is now known as coolsvap|afk | 23:14 | |
*** adrian_otto has joined #openstack-containers | 23:15 | |
madhuri | Good morning all | 23:16 |
eghobo_ | actually it's 4pm in California ;) | 23:19 |
*** zhenguo has joined #openstack-containers | 23:21 | |
*** sicarie has joined #openstack-containers | 23:23 | |
madhuri | :( | 23:23 |
madhuri | adrian_otto, ping | 23:23 |
madhuri | We will have a meeting in 5 minutes about Magnum as a CA | 23:24 |
*** sdake has joined #openstack-containers | 23:24 | |
adrian_otto | madhuri: pong | 23:25 |
adrian_otto | it is good day to everyone :-) | 23:25 |
redrobot | http://www.total-knowledge.com/~ilya/mips/ugt.html | 23:25 |
madhuri | Blueprint link https://blueprints.launchpad.net/magnum/+spec/magnum-as-a-ca | 23:25 |
madhuri | Just checking for the meeting | 23:25 |
madhuri | adrian_otto, Thank you for the introduction | 23:26 |
*** sdake__ has joined #openstack-containers | 23:26 | |
redrobot | madhuri adrian_otto o/ | 23:26 |
adrian_otto | good (UGT) day | 23:26 |
madhuri | Hi redrobot | 23:26 |
madhuri | Is any Barbican or Anchor developer here? | 23:27 |
*** sdake_ has quit IRC | 23:27 | |
redrobot | madhuri I'm the Barbican PTL | 23:27 |
madhuri | Oops. Sorry redrobot | 23:27 |
madhuri | Thank you for joining | 23:27 |
madhuri | Anyone from Anchor team? | 23:28 |
redrobot | madhuri you're welcome :) | 23:28 |
madhuri | tcammann, ping | 23:28 |
adrian_otto | sdake_ sdake ping | 23:28 |
*** yuanying has joined #openstack-containers | 23:28 | |
adrian_otto | sdake__ ping | 23:28 |
sdake__ | yo | 23:29 |
*** chair6 has joined #openstack-containers | 23:29 | |
adrian_otto | hi there, we wanted to pull you into our talk about TLS support | 23:29 |
sdake__ | shoot | 23:29 |
adrian_otto | sdake__: can you join us for a bit? | 23:29 |
sdake__ | yup | 23:29 |
adrian_otto | tx! | 23:29 |
*** sdake has quit IRC | 23:29 | |
madhuri | Ok so to start we wanted to discuss about TLS support in Magnum | 23:30 |
*** sdake__ is now known as sdake | 23:30 | |
adrian_otto | should we log this? | 23:30 |
madhuri | Yes sure adrian_otto | 23:30 |
adrian_otto | #startmeeting containers_tls | 23:30 |
openstack | Meeting started Thu Jul 9 23:30:24 2015 UTC and is due to finish in 60 minutes. The chair is adrian_otto. Information about MeetBot at http://wiki.debian.org/MeetBot. | 23:30 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 23:30 |
openstack | The meeting name has been set to 'containers_tls' | 23:30 |
adrian_otto | o/ | 23:30 |
sdake | o/ | 23:30 |
adrian_otto | who's here? | 23:30 |
madhuri | o/ | 23:30 |
yuanying | o/ | 23:30 |
sicarie | o/ | 23:30 |
redrobot | o/ | 23:30 |
adrian_otto | Madhuri called us together for some discussion about our TLS feature today. | 23:31 |
madhuri | #link https://blueprints.launchpad.net/magnum/+spec/magnum-as-a-ca | 23:31 |
adrian_otto | We'll reference links to the blueprint and spec review | 23:31 |
madhuri | To support TLS in Magnum, we need to generate certs and store them securely | 23:31 |
madhuri | We have few options to do that | 23:32 |
madhuri | So I wanted to discuss which option is the best one | 23:32 |
adrian_otto | #link https://review.openstack.org/194905 Add TLS support in Magnum. | 23:32 |
madhuri | I will get the link here of the ml | 23:32 |
adrian_otto | let's back up one step | 23:32 |
adrian_otto | the reason we care about this at all is that Magnum bays are small distributed systems | 23:32 |
adrian_otto | and the components of those systems typically run on public networks | 23:33 |
adrian_otto | so the various API endpoints need suitable access control | 23:33 |
adrian_otto | Magnum does not adequately secure the kubernetes client-> master or master-> minion communications | 23:33 |
adrian_otto | there is no access control or encryption of those communications | 23:34 |
adrian_otto | so in order for Magnum to be production ready we must address that | 23:34 |
adrian_otto | Kubernetes and Docker Swarm both support TLS, which can be used as a mechanism both for simple access control, and encryption | 23:34 |
adrian_otto | so Madhuri has been working on possible implementations to address this | 23:35 |
adrian_otto | Madhuri, you can lead from this point | 23:35 |
*** yuanying-alt has joined #openstack-containers | 23:35 | |
madhuri | Thank you adrian_otto for the introduction | 23:35 |
madhuri | So Magnum needs certficates and to store them securely | 23:35 |
madhuri | We tried to use Anchor for it | 23:36 |
madhuri | But got some disagreement about it as being stackforge project | 23:36 |
chair6 | that changes tomorrow, when it moves from stackforge -> openstack namespace | 23:36 |
sdake | i think the disageement would disappear if it were optional rather then mandatory madhuri | 23:36 |
adrian_otto | are those objections primarily related to the maturity level of the Anchor software? | 23:36 |
sdake | adrian_otto since its going to the openstack namespace this is a moot point | 23:37 |
madhuri | Yes for that we first thought of adding our own tool to generate certificate for initial release | 23:37 |
sdake | but my argument on this point is we dont want to depend on stackforge projects because they may never make it into the openstack namespace, making our project unshippable | 23:37 |
madhuri | But then we are left with no option for its secure storage | 23:37 |
madhuri | Agree. | 23:37 |
sdake | hard depend | 23:38 |
sdake | soft depend, different story | 23:38 |
*** openstack has joined #openstack-containers | 23:40 | |
adrian_otto | madhuri: In an ideal world we would have a pluggable implementation. I'm not yet convinced that's the right first step. | 23:40 |
adrian_otto | my current attitude is that something that's likely to fit the majority of use cases initially is a good first attempt | 23:41 |
madhuri | adrian_otto, About having our own tool? | 23:41 |
redrobot | currently only Barbican has a concrete implementation, but we have plans to add KMIP support as well, so you could store secrets to a KMIP device directly | 23:41 |
adrian_otto | and refining that based on the ones who don't like it would be a subsequent effort | 23:41 |
*** suro-patz has quit IRC | 23:41 | |
madhuri | adrian_otto, I and yuanying wanted to support Barbican for the first release. | 23:41 |
adrian_otto | redrobot: for those of us not familiar with KMIP, can you describe that in more basic terms? | 23:42 |
redrobot | KMIP is a protocol for storing keys. Some vendors sell Hardware Security Modules that can speak KMIP | 23:42 |
sdake | well here i the bottom line - i'm not writing the code and wont reject reviews with -2 that solve the problem, but i really think a hard dependency is a terrible idea ;) | 23:42 |
adrian_otto | ok, so we should think of that as an interface to an HSM | 23:43 |
*** diga has joined #openstack-containers | 23:43 | |
adrian_otto | sdake, I am sympathetic to that view, and want to discuss that together a bit | 23:43 |
sdake | i dont mind a hard dep on a library | 23:43 |
sdake | as long as its in openstack namespace | 23:43 |
adrian_otto | let's imagine for a moment that we want an implementation that does not rely on Barbican | 23:44 |
madhuri | sdake, That is what I am trying to have a pluggable system for it | 23:44 |
sdake | an as long as a non server-based implementation can be written behind the abstraction | 23:44 |
adrian_otto | we do need some way for a Bay to "keep" the cert/key combination for setting up a new bay node when it scales out | 23:44 |
madhuri | +1 adrian_otto | 23:44 |
adrian_otto | without a secure storage service like Barbican that means storing both on the Bay master node, correct? | 23:44 |
sdake | yes, magnum stores the key info | 23:44 |
madhuri | Yes | 23:45 |
sdake | in magnum itself not on the bay mastter node | 23:45 |
adrian_otto | from a security perspective, I have a mild allergic response to that | 23:45 |
madhuri | adrian_otto, I totally agree | 23:45 |
adrian_otto | basically no more secure than storing a cleartext password in a config file on the master node | 23:45 |
adrian_otto | which as a security best practice is sternly frowned upon | 23:45 |
*** suro-patz has joined #openstack-containers | 23:45 | |
sdake | well sure if someone roots your infrastructure your fked anyway | 23:45 |
adrian_otto | so if we offer that as an option, I don't want it to be on as default | 23:46 |
adrian_otto | and I want a "Use this at your own risk" warning where you turn it on | 23:46 |
sdake | i am talking about the db storing the keys | 23:46 |
sdake | not the bay master | 23:46 |
adrian_otto | that's even less secure | 23:46 |
sdake | if the db were rooted, there is about 10000 ways to cause damage outside magnum | 23:46 |
adrian_otto | because you have a single attack surface that risks all bays | 23:46 |
sdake | that exissts all over openstack today though | 23:47 |
adrian_otto | redrobot: what's your view? | 23:47 |
sdake | sure we slightly add to the problem | 23:47 |
yuanying | And also there is no way to get secure key from k8s master node | 23:47 |
sdake | but its a problem all over openstack services including nova and heat | 23:47 |
madhuri | I agree that storing keys on magnum is insecure way, but still we should support both them implementation. And make it "Use this at your own risks" | 23:48 |
adrian_otto | yuanying: what if each k8s master also had a standalone barbican service on it? | 23:48 |
sdake | groan | 23:48 |
adrian_otto | ok, so back up a bit | 23:48 |
sdake | seems heavy - mysql + rabbit | 23:48 |
adrian_otto | can we agree that we want a secure by default with an insecure option that allows you to deplyo Magnum without Barbican if you want to take the risk? | 23:49 |
*** sthillma has quit IRC | 23:49 | |
sdake | i disagree with your assertion that storing data in the database encrypted is any less secure then storing it encrypted in the barbican database... | 23:49 |
adrian_otto | good, let's debate that for a moment | 23:49 |
*** achanda has quit IRC | 23:49 | |
adrian_otto | with barbican, I get encrypted storage. | 23:49 |
yuanying | If we use barbican, k8s master get key from barbican | 23:50 |
adrian_otto | I think I *also* get an access log of what clients accessed which secrets | 23:50 |
adrian_otto | redrobot: is that true? | 23:50 |
yuanying | but if we use database to store db, how to get the secure key from k8s master | 23:50 |
adrian_otto | and I can remove a secret | 23:50 |
redrobot | adrian_otto so, not with kilo barbican, but we're adding auditing in liberty | 23:50 |
redrobot | so yes, you'd get an audit log of every time the cert/key is accessed | 23:51 |
madhuri | yuanying, Can we get from magnum itself? | 23:51 |
adrian_otto | so I at least have some way to detect unauthorized access | 23:51 |
*** Tango has joined #openstack-containers | 23:52 | |
sdake | an apples to apples comparison is current state of barbican with whatever we would roll | 23:52 |
adrian_otto | madhuri: we could do what sdake is suggesting and have an API call to fetch it from the Magnum db | 23:52 |
madhuri | Yes that is a way | 23:52 |
adrian_otto | or we could run an agent on the bay master node (not as elegant) | 23:52 |
sdake | listen folks, I dont really care strongly enough to -2 a review with a hard dependency, I just think from my years of being punished by taking on hard dependencies, it is something not to be done lightly | 23:52 |
sdake | *EVERY* single project that has failed I have been involved with was because of a hard dependency | 23:53 |
madhuri | +1 sdake | 23:53 |
sdake | granted those projects dont have mojo of magnum | 23:53 |
sdake | so that is why i wouldn't -2 | 23:53 |
sdake | that is the single only reason ;-) | 23:53 |
madhuri | So my point here is support both implementation | 23:53 |
madhuri | I agree Barbican is the most secure way and best suit for us | 23:54 |
adrian_otto | ok, so what if we did an implementation that depended on barbican as a phase I, with a phase II to offer a non-barbican solution that has no external dependency? | 23:54 |
madhuri | But again making it hard dependency is not good | 23:54 |
adrian_otto | with a commitment from our implementers to do both | 23:54 |
yuanying | adrian_otto: agree | 23:54 |
adrian_otto | I think the implementation with barbican will actually be faster, and I want that for Liberty | 23:54 |
*** chair6 has left #openstack-containers | 23:54 | |
sdake | phasing works for me as long as phase 2 doesn't turn into "use barbican" :) | 23:54 |
madhuri | adrian_otto, We tried to use Barbican for generating cert but failed | 23:54 |
madhuri | yuanying, sent a mail for it but no response | 23:54 |
adrian_otto | sdake, we have the stakeholders here to make that commitment | 23:54 |
sdake | implementation speed is more essential then dependency management in this case | 23:55 |
redrobot | madhuri sorry about that. which CA bakend were you using? | 23:55 |
madhuri | We tried to use the default one redrobot | 23:55 |
madhuri | But no CA was listed | 23:55 |
yuanying | and also snake_oil | 23:55 |
redrobot | :( | 23:55 |
madhuri | SnakeOil was also not configured | 23:55 |
madhuri | That's why we moved to other implementation of having our own tool to do it | 23:56 |
* redrobot takes notes to look into default CA errors | 23:56 | |
madhuri | redrobot, Now that you are involved, we can take up Barbican | 23:56 |
madhuri | as our first implementation | 23:56 |
sdake | madhuri I didn't see redrobot make that commitment yet ;) | 23:56 |
madhuri | sdake, I hope he does :) | 23:57 |
madhuri | redrobot, ? | 23:57 |
adrian_otto | so let's make the ask. redrobot: are you willing to allocate some cycles to help us integrate Magnum with Barbican for this purpose? | 23:57 |
redrobot | I would love to see more openstack projects use barbican. | 23:57 |
adrian_otto | it's our highest priority blueprint for this cycle | 23:57 |
madhuri | It's a yes :) | 23:57 |
sdake | yes it is essential | 23:57 |
sdake | failure here is not an option (TM) | 23:58 |
redrobot | yes, I would definitely do whatever I can to help you guys out | 23:58 |
sdake | ok well that wfm | 23:58 |
madhuri | Thank you redrobot | 23:58 |
sdake | as long as we revisit the non-hard dependency model in the future | 23:58 |
adrian_otto | cool, so we are approaching our 30min mark | 23:58 |
sdake | without a "its too hard" | 23:58 |
redrobot | I would like to learn more about the use case though | 23:59 |
adrian_otto | do we have what we need for today, or should we discuss for longer? | 23:59 |
sdake | dependencies = evil :( | 23:59 |
madhuri | Sure sdake | 23:59 |
madhuri | We will implement that also | 23:59 |
*** eghobo has joined #openstack-containers | 23:59 | |
redrobot | sdake rewriting everything is more evil, I think :) | 23:59 |
madhuri | I think this is all I wanted to discuss, to come to a single point | 23:59 |
adrian_otto | redrobot: we will commit to giving you as much detail as you need to help us | 23:59 |
sdake | redrobot we have a doc | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!