| carloss | #startmeeting manila | 15:00 |
|---|---|---|
| opendevmeet | Meeting started Thu Jul 9 15:00:08 2026 UTC and is due to finish in 60 minutes. The chair is carloss. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:00 |
| opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:00 |
| opendevmeet | The meeting name has been set to 'manila' | 15:00 |
| carloss | courtesy ping: vhari gouthamr carthaca Sai gireesh Kumar_T Anoop_Shukla dari-c Silvia-Wachira | 15:00 |
| vhari | hi | 15:00 |
| Anoop_Shukla_ | O/ | 15:00 |
| gouthamr | o/ | 15:01 |
| Sai | O/ | 15:01 |
| Kumar_T | o/ | 15:01 |
| carloss | o/ hey there folks | 15:02 |
| carloss | happy to be back | 15:02 |
| vhari | welcome back carloss :) | 15:02 |
| carloss | I think we have some good quorum and a good amount of topics | 15:02 |
| carloss | so let's get started | 15:02 |
| carloss | ty vhari | 15:02 |
| carloss | and thank you all for holding the fort while I was back, also gouthamr for running the meeting in my absence | 15:03 |
| carloss | our meeting agenda for today: | 15:03 |
| carloss | #link https://wiki.openstack.org/wiki/Manila/Meetings | 15:03 |
| carloss | #topic Announcements | 15:03 |
| carloss | #link https://releases.openstack.org/hibiscus/schedule.html (Hibiscus Schedule) | 15:03 |
| carloss | time is flying | 15:03 |
| carloss | and we're past spec freeze | 15:03 |
| gireesh | o/ | 15:04 |
| carloss | I noticed specs getting merged while I was away... great job everyone to keep the specs going | 15:04 |
| * carloss o/ gireesh | 15:04 | |
| carloss | this is R-12 - meaning twelve weeks to go for the hibisucus release | 15:04 |
| carloss | we also have our bugsquash scheduled for next week | 15:05 |
| carloss | which we'll get to in a bit | 15:05 |
| carloss | but | 15:05 |
| carloss | I have another announcement | 15:06 |
| carloss | the 2027.1 release name is: | 15:06 |
| carloss | Indri! | 15:06 |
| carloss | #link https://lists.openstack.org/archives/list/openstack-discuss@lists.openstack.org/message/54H5LEW7Y2NIHGCJVLAQR3SC4XV3J6AJ/ | 15:06 |
| carloss | thanks all for voting | 15:06 |
| carloss | we're back on animal names I guess... we've been alternating :p | 15:07 |
| carloss | animal, long-lasting plastic, animal, soup, animal... | 15:07 |
| carloss | can't wait to see what the next thing is :D | 15:07 |
| carloss | looking forward to the J release name already :p | 15:08 |
| vhari | :) | 15:08 |
| carloss | that's all the announcements I had to share today. Do you have an announcement to share with us? | 15:08 |
| carloss | taking silence as no | 15:10 |
| carloss | #topic Hibiscus Bug Squash | 15:10 |
| * gouthamr all hail our new lemur overlord | 15:10 | |
| carloss | lol | 15:11 |
| carloss | I was chatting to vhari earlier and the trend of in progress bugs seems to continue | 15:11 |
| carloss | and it would be nice to use the bugsquash to focus on reviewing the changes targeting such bugs | 15:11 |
| carloss | that said, I think we can reuse a part of the next week's meeting for a mid point check in | 15:12 |
| vhari | ack, slowly rising to 80+ in progress | 15:13 |
| carloss | considering that the timezones are challenging I was tempted to say we could try something different and avoid a kick off video call and do it on IRC and the etherpad | 15:14 |
| carloss | how would that work? | 15:14 |
| carloss | when we have the list, at the first day of the bugsquash we can look at the bugs that are assigned to us and share a status on them, adding a note to the etherpad | 15:15 |
| kpdev | IRC discussion would be bit slow, otherwise I am fine with that too. | 15:16 |
| carloss | like does it needs reviews, is that a priority for you at the moment, are the assignees correct? | 15:16 |
| carloss | > IRC discussion would be bit slow, otherwise I am fine with that too. | 15:17 |
| carloss | yeah, I agree that it will slow down the discussions because when we are in a meeting room, we can just hash some things out quickly | 15:17 |
| vhari | carloss, I can share the list ahead of time if that helps | 15:17 |
| carloss | vhari: yeah, that way we could likely use the whole week for the bugsquash? | 15:17 |
| carloss | if you all are available next week and prefer the video meeting, we can do this | 15:17 |
| vhari | +1 | 15:18 |
| gouthamr | would prefer an irc chat and ad hoc video | 15:18 |
| carloss | I'd also encourage people to sign up for reviews - I/other reviewers might sign you up as well :) | 15:18 |
| carloss | > would prefer an irc chat and ad hoc video | 15:19 |
| carloss | works for me too | 15:19 |
| carloss | alright, that sounds good. vhari when you have the list, could you please share? That way we could likely have people on it by Monday and that also eliminates some time zone limitations, we can all go through the etherpad on Monday and do the updates I just mentioned | 15:21 |
| vhari | will do carloss | 15:22 |
| carloss | then, we can have a kick-off chat either on Tuesday with everyone's updates on the changes and go through some discussions, reassignments and so on | 15:22 |
| carloss | vhari: tyvm :D | 15:22 |
| carloss | is Tuesday 14:00 UTC okay to everyone for an IRC chat? | 15:22 |
| vhari | yw carloss :) | 15:22 |
| carloss | and we'll use the meeting as a mid point check too | 15:23 |
| carloss | how does that sound? | 15:23 |
| carloss | the idea of the reviews on that week will be to focus on the bugs from the list and try to get as many as we can closed | 15:23 |
| carloss | and try reducing the numbers | 15:24 |
| gouthamr | ++ | 15:24 |
| carloss | awesome | 15:25 |
| carloss | any other thoughts on bugsquash? | 15:25 |
| carloss | we can chat in #openstack-manila on Tuesday | 15:25 |
| gouthamr | nice thought on sharing the list on monday, i for one could use the prep time | 15:25 |
| gouthamr | s/on/prior to | 15:25 |
| carloss | ++ | 15:26 |
| carloss | sounds like a plan | 15:26 |
| carloss | thanks for pitching in | 15:26 |
| carloss | #topic Security policies for back end drivers and communication to external systems | 15:26 |
| carloss | hot topic now | 15:26 |
| carloss | gouthamr: thanks for adding it to the agenda | 15:26 |
| carloss | floor is yours :D | 15:27 |
| carloss | #link https://bugs.launchpad.net/manila/+bug/2157914 (Multiple driver ssl/tls security and default operating behavior issues) | 15:27 |
| carloss | #link https://lists.openstack.org/archives/list/openstack-discuss@lists.openstack.org/thread/44MLENT3AXUML7CYYLNWO6Z7LO6CQT6W/ (OpenStack Security Documentation crisis) | 15:27 |
| gouthamr | ah thanks, was looking for that link | 15:27 |
| gouthamr | alright, so for all the time i've worked on OpenStack, we've wanted a "secure-by-default" architecture.. but, sometimes, we've failed to enforce it.. this bug highlights design choices made in proprietary storage systems that violate that rule | 15:29 |
| gouthamr | their drivers, actually | 15:29 |
| gouthamr | and these choices may be made for a number of reasons: the fact that many storage systems have a trust-based access to begin with.. and they imagine being deployed to be accessed over trusted networks where security can be enforced | 15:30 |
| gouthamr | or the fact that these systems simply don't have the capabilities that we think will make it more secure.. | 15:31 |
| gouthamr | manila is a "security-first" architecture.. we have multiple layers of design that allow for hard isolation guarantees | 15:31 |
| gouthamr | some may argue this is one of the key reasons manila couldn't be a part of cinder service.. because the trust model there is different to begin with | 15:33 |
| gouthamr | so my initial thought was in agreement with the findings that JayF and TheJulia shared.. i think having documentation of our security model, and design choices (and why they were made) would benefit operators | 15:34 |
| gouthamr | so, i'd like to call on maintainers of the drivers flagged to vet the bug report and see if these can be fixed | 15:35 |
| gouthamr | to be secure... if not, is there a choice we can provide where it is secure by default | 15:35 |
| gouthamr | and if not, we need to capture in red letters that deployers are aware of the vulnerable surface and make appropriate choices for their deployments | 15:36 |
| gouthamr | thoughts? | 15:37 |
| gouthamr | *crickets* | 15:39 |
| gouthamr | some of these drivers may lack maintainers | 15:39 |
| carloss | :) | 15:39 |
| carloss | yes - maybe we could try writing a generic email and sharing them to the maintainers email we know? | 15:40 |
| carloss | we've seen some actions being taken by Pure | 15:40 |
| carloss | I think Anoop_Shukla_ also acked it | 15:40 |
| carloss | but I do agree with the direction: we need to have this documented | 15:40 |
| Anoop_Shukla | Sorry..jumping from meetings to meetings | 15:40 |
| gouthamr | yeah, good work from simondodsley on https://review.opendev.org/c/openstack/manila/+/996009 | 15:41 |
| Anoop_Shukla | Agree with the approach | 15:41 |
| Anoop_Shukla | Are we going to have a common documentation for all services including cinder and manila on this direction? | 15:44 |
| Anoop_Shukla | Of security first approach? | 15:45 |
| gouthamr | yes, that's a good point | 15:45 |
| gouthamr | i think so.. it'd be nice to have Security SIG guideline/s around this imo.. JayF suggested a TC stance as well | 15:45 |
| gouthamr | so this could very well be a cross-cutting theme | 15:45 |
| Anoop_Shukla | That would help to have a goal in hibiscus and call the release security hardened :) | 15:46 |
| carloss | ++ | 15:46 |
| gouthamr | but, my concern as i said on the ML is that projects have to probably spear head this first given they know their domain best.. what might be appropriate for a NAS storage driver may not be appropriate for a block storage driver or a network device driver or a dns software etc | 15:47 |
| gouthamr | yeah, it could be the manila project goal for sure | 15:47 |
| carloss | if we're having a generic doc for Manila, I can propose something... we'd also expect that the driver maintainers update their docs with specifics though | 15:49 |
| gouthamr | ++ | 15:51 |
| gouthamr | yeah, let's take some AIs on this.. we can bounce that email to the maintainers we know .. they may be plugged into openstack-discuss, but, our email should highlight what they need to do | 15:52 |
| gouthamr | and when | 15:52 |
| carloss | sure, can do :D | 15:52 |
| carloss | and thanks for bringing this up | 15:53 |
| carloss | i've been watching the discussion while I was on PTO and caught up to everything now | 15:54 |
| carloss | I do like the direction we're going | 15:54 |
| carloss | any other thoughts on this? | 15:55 |
| gouthamr | nothing today.. but, maybe we should reprise this topic in a future meeting and check where we are on this | 15:56 |
| carloss | ++ | 15:56 |
| carloss | sounds great | 15:57 |
| * carloss takes a note to circle back in the upcoming meetings | 15:58 | |
| carloss | alright, we're tight on time and I see we have some bugs that triage was deferred | 15:58 |
| carloss | and a fix that has a request for reviews | 15:58 |
| carloss | i'll look into it | 15:58 |
| vhari | ty carloss | 15:59 |
| carloss | vhari: anything urgent for bug triaging? if so, I think we can do it in #openstack-manila | 15:59 |
| vhari | ++ | 15:59 |
| carloss | alright, let's wrap up | 15:59 |
| carloss | thanks for participating everyone | 16:00 |
| carloss | let's get back to #openstack-manila | 16:00 |
| carloss | have a great day! | 16:00 |
| carloss | #endmeeting | 16:00 |
| opendevmeet | Meeting ended Thu Jul 9 16:00:10 2026 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 16:00 |
| opendevmeet | Minutes: https://meetings.opendev.org/meetings/manila/2026/manila.2026-07-09-15.00.html | 16:00 |
| opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/manila/2026/manila.2026-07-09-15.00.txt | 16:00 |
| opendevmeet | Log: https://meetings.opendev.org/meetings/manila/2026/manila.2026-07-09-15.00.log.html | 16:00 |
| Anoop_Shukla | Good day and evening everyone | 16:00 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!