Thursday, 2026-03-12

*** mrunge_ is now known as mrunge00:54
*** jroll09 is now known as jroll006:28
*** ralonsoh_ is now known as ralonsoh07:50
captHi everyone,   We are currently working on designing credential/secret management for our platform built on OpenStack, and we are trying to reason about it from first principles instead of assuming the default OpenStack approach.  Our requirement is tenant-level secure credential storage (similar to a KMS) where identities/secrets are not stored directly on disk.    We looked at Barbican, but from our understanding it does not fully behave like a ten12:45
captntial store in the way a typical KMS does.  Questions:  Has anyone implemented tenant-level secret storage / credential management on top of OpenStack? Did you extend Barbican, integrate an external KMS (like Hashicorp Vault), or use some other pattern? How do you avoid storing sensitive identities or credentials directly on disk?   Appreciate any thoughts or references. Thanks!12:45
captHi afox do you have any idea on this12:52
opendevreviewGhanshyam Maan proposed openstack/governance master: Update Ghanshyam email id  https://review.opendev.org/c/openstack/governance/+/98032817:16

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!