Monday, 2021-05-17

openstackgerritIan Wienand proposed openstack/diskimage-builder master: Fix DISTRO_NAME in Fedora elements  https://review.opendev.org/c/openstack/diskimage-builder/+/79162700:02
*** yoctozepto has quit IRC00:17
*** yoctozepto has joined #openstack-dib00:17
*** dhill has joined #openstack-dib00:23
openstackgerritMerged openstack/diskimage-builder master: Add fedora-containerfile element  https://review.opendev.org/c/openstack/diskimage-builder/+/79036500:52
*** logan- has quit IRC06:12
*** logan- has joined #openstack-dib06:15
*** iurygregory has quit IRC07:12
*** iurygregory has joined #openstack-dib07:21
*** jenxie has joined #openstack-dib07:47
*** dtantsur|afk is now known as dtantsur08:09
*** sam_wan has joined #openstack-dib08:18
*** sam_wan has quit IRC11:17
*** yoctozepto has quit IRC11:55
openstackgerritHitesh Kumar proposed openstack/diskimage-builder master: Migrate from testr to stestr  https://review.opendev.org/c/openstack/diskimage-builder/+/78924612:10
openstackgerritMerged openstack/diskimage-builder master: Fix DISTRO_NAME in Fedora elements  https://review.opendev.org/c/openstack/diskimage-builder/+/79162712:15
*** yoctozepto has joined #openstack-dib12:31
*** sdanni has joined #openstack-dib13:43
sdanniHi TheJulia! I submitted the keylime-agent element to DIB weeks beofore. ianw and other reviewers think they don't know keylime and want to get insight from ironic people to decide whether the new element should belong to dib or ipa. According to dtantsur, this element is not specific to ipa so it shouldn't belong to ironic. But reviewers haven't reach an agreement yet. What do you think of it? https://review.opendev.org/16:16
sdannic/openstack/diskimage-builder/+/789601.16:16
sdannihttps://review.opendev.org/c/openstack/diskimage-builder/+/789601.16:17
dtantsursdanni: to be clear, I asked rather than claimed on https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/763837 :)16:18
sdannidtantsur: yes! From my understanding, keylime element can be independent from ipa.16:24
sdanniBut it does need to communicate with ironic controller to control the attestation16:25
dtantsurthe key question is whether someone would use this element with something that is not IPA16:26
sdannidtantsur: i guess our integration point is ipa but in theory there's no reason that it has to be exclusive to ipa16:33
dtantsurthen I'll leave it up to the DIB folks to decide if they're willing to take the element16:35
dtantsurI'm not strictly against hosting it in IPA-builder fwiw16:35
*** dtantsur is now known as dtantsur|afk16:36
sdannithanks!16:36
sdanniclarkb, ianw: ^ what's your suggestion?16:47
TheJuliao/ sdanni sorry, I've not had a chance. I was away last week.17:18
TheJuliawithout looking at it, I suspect it should be generally useful to those not running IPA since to run attestation on deployed workload they would either need to install/set it up after the fact or have it in the image.17:20
sdanniyes, I think it should work this way17:25
TheJuliasdanni: so, what is the deal with the emulator?17:27
sdanniTheJulia: we don't have nodes to test with hardware TPM so I use software tpm emulator instead.17:29
clarkbI'll have to defer to ianw on what is maintainable in dib.17:29
clarkbI think the concern on the dib side is we don't have the knowledge or tooling to properly make use of such things so it is likely to bit rot in dib17:30
TheJuliasdanni: Okay, but that should be disjointed from the agent17:31
TheJuliait shouldn't *need* to be inside the running deployed workload17:32
sdanniTheJulia: sure!17:36
TheJuliasdanni: basically, I think the issue at hand is the use cases are not understood by the diskimage-builder reviewers, I'll try to help clarify this with my comments on the change17:44
TheJuliabut, commit message + readme should likely represent it these facts so people grok it.17:44
sdanniTheJulia: cool. I'll update the readme file17:46
TheJuliasdanni: wait until I post my comments17:50
sdannisure!17:50
sdanniTheJulia: thanks for your comments. I'm looking into them now.18:12
TheJuliasdanni: made two more18:12
TheJuliaJust thinking from a general case18:12
sdannialright18:16
*** iurygregory has quit IRC22:10
*** iurygregory has joined #openstack-dib22:19

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!