| *** mhen_ is now known as mhen | 02:17 | |
| opendevreview | Cyril Roelandt proposed openstack/glance_store master: s3: add options to control checksum calculation/validation https://review.opendev.org/c/openstack/glance_store/+/959201 | 03:06 |
|---|---|---|
| opendevreview | Abhishek Kekane proposed openstack/glance master: Add API endpoints for cache clean and prune operations https://review.opendev.org/c/openstack/glance/+/969575 | 10:27 |
| opendevreview | Abhishek Kekane proposed openstack/glance master: Add API endpoints for cache clean and prune operations https://review.opendev.org/c/openstack/glance/+/969575 | 11:11 |
| opendevreview | Merged openstack/glance-specs master: [spec] Download image from suggested stores https://review.opendev.org/c/openstack/glance-specs/+/963239 | 14:00 |
| croeland1 | #startmeeting glance | 14:00 |
| opendevmeet | Meeting started Thu Dec 4 14:00:37 2025 UTC and is due to finish in 60 minutes. The chair is croeland1. Information about MeetBot at http://wiki.debian.org/MeetBot. | 14:00 |
| opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 14:00 |
| opendevmeet | The meeting name has been set to 'glance' | 14:00 |
| croeland1 | #topic roll call | 14:00 |
| croeland1 | o/ | 14:00 |
| mhen | o/ | 14:00 |
| *** croeland1 is now known as croelandt | 14:00 | |
| croelandt | o/ | 14:00 |
| croelandt | #link https://etherpad.openstack.org/p/glance-team-meeting-agenda | 14:00 |
| rosmaita | o/ | 14:01 |
| rosmaita | i just realized that i'm supposed to be in a different meeting now | 14:01 |
| croelandt | always multitask | 14:02 |
| abhishekk | o/ | 14:02 |
| abhishekk | i am not sure rajat is around or not :/ | 14:03 |
| whoami-rajat | hello | 14:03 |
| croelandt | yeah | 14:03 |
| croelandt | let's start | 14:03 |
| abhishekk | hey | 14:03 |
| abhishekk | thanks for attending | 14:04 |
| croelandt | #topic Release/periodic job updates | 14:04 |
| croelandt | Everything good \o/ | 14:04 |
| croelandt | #topic Important stable patches - http://tiny.cc/glance-maintained | 14:04 |
| croelandt | Yeah so Bence's patch are still failing because of the test refactor | 14:04 |
| croelandt | I really have to talk to him about that | 14:04 |
| croelandt | #topic Glance download image from specific store | 14:04 |
| croelandt | #link https://review.opendev.org/c/openstack/glance-specs/+/963239 | 14:04 |
| croelandt | So this was merged or is currently being merged | 14:04 |
| croelandt | thanks Abhishek for working on that | 14:04 |
| croelandt | thanks rosmaita and dansmith for the reviews | 14:05 |
| abhishekk | thank you for reviews and suggestions | 14:05 |
| croelandt | #topic Decompression plugin | 14:05 |
| croelandt | The patches are still under review | 14:05 |
| croelandt | I've fallen behind on reviews, I need to spend some time looking at that | 14:05 |
| whoami-rajat | np, I'm double booked so will do context switching | 14:05 |
| croelandt | #topic Image encryption | 14:05 |
| croelandt | mhen: I see you're here, do you want to say something about this? | 14:06 |
| croelandt | Also whoami-rajat for the Cinder side of encryption | 14:06 |
| mhen | currently checking an edge case with old images and compression in Cinderö | 14:07 |
| mhen | *Cinder | 14:07 |
| mhen | but may not be an issue at all, need to check this | 14:07 |
| mhen | other than that the changes as discussed in the PTG are pretty much done | 14:07 |
| croelandt | what about Nova? | 14:08 |
| abhishekk | mhen: Could you please somewhere on the spec list out the concerns discussed in PTG and what we opted for that, if possible? | 14:09 |
| mhen | Nova has a blueprint now: https://blueprints.launchpad.net/nova/+spec/luks-image-encryption | 14:10 |
| mhen | abhishekk: I could add my summary notes from the PTG to the Glance spec if that helps | 14:11 |
| abhishekk | mhen: that would be great | 14:11 |
| mhen | will do | 14:12 |
| abhishekk | So glance is good to go | 14:12 |
| croelandt | yeah my concern is more about Nova/Cinder | 14:13 |
| abhishekk | ack, | 14:13 |
| croelandt | mhen: do you think your work in Nova/Cinder will be approved? | 14:14 |
| mhen | can't really tell; entirely depends on whether the implementation is now satisfactory for everyone this time | 14:16 |
| abhishekk | I think we should have one more cross project meeting to see where this is heading | 14:17 |
| croelandt | yeah | 14:18 |
| croelandt | this may happen soon :) | 14:18 |
| croelandt | Anything to add on this topic? | 14:18 |
| mhen | not from my side at least | 14:19 |
| rosmaita | cinder has a meeting on friday to review specs | 14:19 |
| croelandt | oh interesting | 14:20 |
| croelandt | is encryption on the agenda? | 14:20 |
| croelandt | are you or whoami-rajat joining this meeting? | 14:20 |
| rosmaita | well, there is a spec for it | 14:20 |
| rosmaita | https://etherpad.opendev.org/p/cinder-festival-of-reviews | 14:20 |
| croelandt | ok can encryption be added to the agenda for tomorrow? | 14:22 |
| rosmaita | and yeah, i will be there | 14:22 |
| croelandt | mhen: ^ | 14:22 |
| croelandt | can mhen join? :) | 14:22 |
| rosmaita | everyone can join! | 14:22 |
| whoami-rajat | croelandt, i will see if it doesn't conflict with the weekend plans :D | 14:22 |
| rosmaita | although to be pedantic, everyone *may* join, whether they can or not is up to them | 14:23 |
| whoami-rajat | it's generally late at night for me | 14:23 |
| mhen | I'll try to attend | 14:23 |
| abhishekk | its late for rajat means its almost early morning for me :P | 14:23 |
| mhen | 14:00 UTC right? | 14:23 |
| croelandt | abhishekk: hahha | 14:23 |
| rosmaita | yes, 1400 UTC | 14:24 |
| mhen | ack | 14:24 |
| croelandt | good | 14:25 |
| croelandt | #topic Open Discussion | 14:25 |
| croelandt | Any topic other than encryption? :) | 14:25 |
| mhen | o/ | 14:25 |
| mhen | https://bugs.launchpad.net/cinder/+bug/2133728 | 14:25 |
| mhen | just so that Glance is aware, Cinder currently allows bypassing its property protection feature | 14:26 |
| mhen | ref: https://docs.openstack.org/glance/latest/admin/property-protections.html | 14:26 |
| mhen | I don't know if a adding warning message on the Glance docs page with a recommendation about restricting that specific Cinder API would be advisable until this is fixed in Cinder? | 14:27 |
| mhen | e.g. setting `volume_extension:volume_image_metadata:set` in the Cinder API RBAC to admin only | 14:27 |
| croelandt | Ideally, fix this in Cinder and then you don't need to mention it in Glance? :D | 14:28 |
| rosmaita | i always thought that for boot from volume, nova fetched the image the volume was created from, and used its properties | 14:29 |
| rosmaita | but apparently, it uses the image properties that are copied onto the volume | 14:29 |
| rosmaita | so that would mean that if an image is deactivated, nova will still let you boot from it if you have created a volume from it first | 14:30 |
| rosmaita | whereas nova will not let you boot from an image that is not 'active' | 14:31 |
| mhen | croelandt: yes but, how long will it take? I just stumbled upon this but personally will not be able to work on this myself in the forseeable future - that's why I was proposing adding a warning for now until somebody is able/willing to address it in Cinder. | 14:31 |
| croelandt | hm | 14:31 |
| croelandt | not sure a warning would be helpful | 14:31 |
| croelandt | also rosmaita volunteered to fix the bug | 14:32 |
| abhishekk | the warning should be in cinder imo | 14:32 |
| rosmaita | not really, cinder has never claimed to have property protections | 14:32 |
| mhen | abhishekk: I respectfully disagree; I discovered the Glance docs page about this feature and thought "neat" - only by accident did I discover that I can bypass this. Somebody that might be enabling this in Glance never reads the Cinder docs because they don't seem relevant to them. | 14:33 |
| abhishekk | ack, croelandt I think we should highlight it then | 14:34 |
| rosmaita | i think we may need to have a bit of a discussion at the next PTG around how image properties are set/consumed for boot-from-volume | 14:35 |
| croelandt | and to think we wanted to get rid of that feature | 14:35 |
| rosmaita | well, if glance gets rid of the feature, then nothing to fix in cinder! | 14:35 |
| mhen | please read the use case example in the bug report and reconsider ;) | 14:36 |
| mhen | (especially concerning the upcoming rework of the confidential computing stuff by takashi) | 14:37 |
| croelandt | rosmaita: we had this one guy write an email 6 months after I sent the survey to inform me that he planned on maybe using the feature | 14:37 |
| croelandt | ok so Glance can document the issue | 14:37 |
| rosmaita | we used it extensively at rackspace, back in the day | 14:37 |
| whoami-rajat | abhishekk, haha, i mean it starts early but it's 2 hours so ends 9:30 our time -- i can work late but meetings are hard at night :( | 14:38 |
| abhishekk | :D | 14:38 |
| rosmaita | i think mhen's workaroud (change the policy setting) is a good idea, i think this hasn't been reported earlier because people don't really use that API much | 14:38 |
| rosmaita | i think most people just expect the image properties to be inherited from the image | 14:39 |
| croelandt | again it's nice you're volunteering to fix this | 14:40 |
| * croelandt is on his way to becoming BDFL | 14:41 | |
| rosmaita | good thing croelandt isn't the boss of me | 14:42 |
| croelandt | this can change! | 14:43 |
| croelandt | though I doubt it | 14:43 |
| croelandt | ok anything else to add about property protections? | 14:43 |
| mhen | nothing from my side | 14:44 |
| mhen | thanks for your consideration! | 14:44 |
| croelandt | ok | 14:45 |
| croelandt | Let's call it a day, then! | 14:45 |
| croelandt | Thanks everyone for joining | 14:45 |
| croelandt | #endmeeting | 14:45 |
| croelandt | hm | 14:46 |
| croelandt | #endmeeting | 14:46 |
| croelandt | Isn't that supposed to give me confirmation? | 14:46 |
| abhishekk | it doesn't want to end us :P | 14:46 |
| mhen | add #please ;D | 14:46 |
| abhishekk | haha | 14:47 |
| abhishekk | #endmeeting | 14:47 |
| croelandt | is the bot dead? :) | 14:48 |
| mhen | we are now in a never-ending meeting for the rest of our lives | 14:48 |
| abhishekk | bring infra in :P | 14:48 |
| rosmaita | no, you started the meeting as croelandt1 | 14:48 |
| rosmaita | so i don't think it's recognizing you now | 14:48 |
| croelandt | oh | 14:48 |
| *** croelandt is now known as croeland1 | 14:48 | |
| abhishekk | hahaha | 14:48 |
| croeland1 | #endmeeting | 14:48 |
| opendevmeet | Meeting ended Thu Dec 4 14:48:45 2025 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 14:48 |
| opendevmeet | Minutes: https://meetings.opendev.org/meetings/glance/2025/glance.2025-12-04-14.00.html | 14:48 |
| opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/glance/2025/glance.2025-12-04-14.00.txt | 14:48 |
| opendevmeet | Log: https://meetings.opendev.org/meetings/glance/2025/glance.2025-12-04-14.00.log.html | 14:48 |
| *** croeland1 is now known as croelandt | 14:48 | |
| abhishekk | finally | 14:48 |
| mhen | :D | 14:48 |
| croelandt | we're free! | 14:48 |
| mhen | rejoice! | 14:49 |
| croelandt | run while you can | 14:49 |
| whoami-rajat | rosmaita, never lets the fun go on for too long (just kidding :D) | 17:34 |
Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!