*** Swami has quit IRC | 00:02 | |
*** ykatabam has quit IRC | 00:04 | |
*** mjturek has quit IRC | 00:05 | |
*** ykatabam has joined #openstack-meeting | 00:07 | |
*** cloudrancher has joined #openstack-meeting | 00:32 | |
*** annabelleB has joined #openstack-meeting | 00:35 | |
*** annabelleB has quit IRC | 00:37 | |
*** diablo_rojo has quit IRC | 00:39 | |
*** bswartz has joined #openstack-meeting | 00:44 | |
*** longkb has joined #openstack-meeting | 00:51 | |
*** bobh has quit IRC | 01:00 | |
*** tetsuro has joined #openstack-meeting | 01:03 | |
*** markvoelker has joined #openstack-meeting | 01:05 | |
*** markvoelker has quit IRC | 01:09 | |
*** yamahata has quit IRC | 01:14 | |
*** cloudrancher has quit IRC | 01:22 | |
*** imacdonn has quit IRC | 01:22 | |
*** imacdonn has joined #openstack-meeting | 01:22 | |
*** tommylikehu has joined #openstack-meeting | 01:27 | |
*** erlon__ has quit IRC | 01:29 | |
*** tpsilva has quit IRC | 01:40 | |
*** mhen has quit IRC | 01:48 | |
*** tetsuro has quit IRC | 01:49 | |
*** mhen has joined #openstack-meeting | 01:50 | |
*** tetsuro has joined #openstack-meeting | 01:52 | |
*** hyunsikyang has joined #openstack-meeting | 02:01 | |
*** felipemonteiro has quit IRC | 02:16 | |
*** annabelleB has joined #openstack-meeting | 02:22 | |
*** hongbin has joined #openstack-meeting | 02:29 | |
*** annabelleB has quit IRC | 02:31 | |
*** tetsuro has quit IRC | 02:42 | |
*** psachin has joined #openstack-meeting | 02:53 | |
*** rcernin has quit IRC | 03:02 | |
*** bnemec has joined #openstack-meeting | 03:05 | |
*** bnemec has quit IRC | 03:10 | |
*** rcernin has joined #openstack-meeting | 03:28 | |
*** tetsuro has joined #openstack-meeting | 03:35 | |
*** mahatic has quit IRC | 03:37 | |
*** isq_ has joined #openstack-meeting | 03:38 | |
*** yamahata__ has quit IRC | 03:39 | |
*** mahatic has joined #openstack-meeting | 03:40 | |
*** hongbin has quit IRC | 03:57 | |
*** yamamoto has quit IRC | 04:34 | |
*** yamamoto has joined #openstack-meeting | 04:34 | |
*** felipemonteiro has joined #openstack-meeting | 05:24 | |
*** liuyulong has quit IRC | 05:24 | |
*** lbragstad_503 has quit IRC | 05:27 | |
*** lbragstad_503 has joined #openstack-meeting | 05:27 | |
*** annabelleB has joined #openstack-meeting | 05:48 | |
*** felipemonteiro has quit IRC | 06:07 | |
*** annabelleB has quit IRC | 06:08 | |
*** Luzi has joined #openstack-meeting | 06:15 | |
*** longkb has quit IRC | 06:22 | |
*** longkb has joined #openstack-meeting | 06:23 | |
*** e0ne has joined #openstack-meeting | 06:38 | |
*** janki has joined #openstack-meeting | 06:51 | |
*** ykatabam has quit IRC | 07:07 | |
*** rcernin has quit IRC | 07:07 | |
*** lpetrut has joined #openstack-meeting | 07:09 | |
*** janki has quit IRC | 07:19 | |
*** persia has quit IRC | 07:19 | |
*** persia has joined #openstack-meeting | 07:21 | |
*** aojea has joined #openstack-meeting | 07:25 | |
*** ralonsoh has joined #openstack-meeting | 07:26 | |
*** ralonsoh has quit IRC | 07:27 | |
*** ralonsoh has joined #openstack-meeting | 07:28 | |
*** helenafm has joined #openstack-meeting | 07:33 | |
*** apetrich has quit IRC | 07:39 | |
*** a-pugachev has joined #openstack-meeting | 08:00 | |
*** apetrich has joined #openstack-meeting | 08:00 | |
*** e0ne has quit IRC | 08:02 | |
*** slaweq has joined #openstack-meeting | 08:02 | |
*** kopecmartin|off is now known as kopecmartin | 08:02 | |
*** ttsiouts has joined #openstack-meeting | 08:03 | |
*** ttsiouts has quit IRC | 08:09 | |
*** e0ne has joined #openstack-meeting | 08:13 | |
*** ttsiouts has joined #openstack-meeting | 08:15 | |
*** tssurya has joined #openstack-meeting | 08:16 | |
*** cloudrancher has joined #openstack-meeting | 08:21 | |
*** ttsiouts has quit IRC | 08:24 | |
*** tetsuro has quit IRC | 08:25 | |
*** ralonsoh_ has joined #openstack-meeting | 08:29 | |
*** ralonsoh has quit IRC | 08:31 | |
*** ttsiouts has joined #openstack-meeting | 08:31 | |
*** jesusaur has quit IRC | 08:38 | |
*** cloudrancher has quit IRC | 08:39 | |
*** ttsiouts has quit IRC | 08:43 | |
*** ralonsoh_ is now known as ralonsoh | 08:56 | |
*** jesusaur has joined #openstack-meeting | 09:31 | |
*** cloudrancher has joined #openstack-meeting | 09:39 | |
*** ttsiouts has joined #openstack-meeting | 09:40 | |
*** ttsiouts has quit IRC | 09:43 | |
*** ttsiouts has joined #openstack-meeting | 09:51 | |
*** priteau has joined #openstack-meeting | 09:52 | |
*** cloudrancher has quit IRC | 09:54 | |
*** jbadiapa has quit IRC | 09:58 | |
*** ttsiouts has quit IRC | 10:06 | |
*** ttsiouts has joined #openstack-meeting | 10:07 | |
*** yamamoto has quit IRC | 10:11 | |
*** ttsiouts has quit IRC | 10:11 | |
*** yamamoto has joined #openstack-meeting | 10:12 | |
*** cloudrancher has joined #openstack-meeting | 10:13 | |
*** yamamoto has quit IRC | 10:16 | |
*** yamamoto has joined #openstack-meeting | 10:16 | |
*** cloudrancher has quit IRC | 10:21 | |
*** ralonsoh has quit IRC | 10:30 | |
*** ralonsoh has joined #openstack-meeting | 10:31 | |
*** aojea has quit IRC | 10:32 | |
*** cloudrancher has joined #openstack-meeting | 10:35 | |
*** ralonsoh has quit IRC | 10:38 | |
*** ralonsoh has joined #openstack-meeting | 10:39 | |
*** ttsiouts has joined #openstack-meeting | 10:40 | |
*** aojea has joined #openstack-meeting | 10:45 | |
*** ttsiouts has quit IRC | 10:48 | |
*** ttsiouts has joined #openstack-meeting | 10:49 | |
*** aojea has quit IRC | 10:52 | |
*** cloudrancher has quit IRC | 10:52 | |
*** erlon__ has joined #openstack-meeting | 11:11 | |
*** jbadiapa has joined #openstack-meeting | 11:14 | |
*** longkb has quit IRC | 11:19 | |
*** yamamoto has quit IRC | 11:20 | |
*** yamamoto has joined #openstack-meeting | 11:21 | |
*** yamamoto has quit IRC | 11:25 | |
*** njohnston has joined #openstack-meeting | 11:27 | |
*** ykatabam has joined #openstack-meeting | 11:32 | |
*** electrofelix has joined #openstack-meeting | 11:38 | |
*** e0ne has quit IRC | 11:50 | |
*** jangutter has joined #openstack-meeting | 11:52 | |
*** yamamoto has joined #openstack-meeting | 12:03 | |
*** a-pugachev has quit IRC | 12:04 | |
*** tommylikehu has quit IRC | 12:07 | |
*** ttsiouts has quit IRC | 12:11 | |
*** raildo has joined #openstack-meeting | 12:13 | |
*** yamamoto has quit IRC | 12:20 | |
*** yamamoto has joined #openstack-meeting | 12:20 | |
*** apetrich has quit IRC | 12:21 | |
*** ttsiouts has joined #openstack-meeting | 12:23 | |
*** eharney has joined #openstack-meeting | 12:27 | |
*** liuyulong has joined #openstack-meeting | 12:27 | |
*** dims has quit IRC | 12:30 | |
*** dims has joined #openstack-meeting | 12:33 | |
*** apetrich has joined #openstack-meeting | 12:33 | |
*** jesusaur has quit IRC | 12:33 | |
*** lpetrut has quit IRC | 12:33 | |
*** ttsiouts has quit IRC | 12:35 | |
*** mriedem has joined #openstack-meeting | 12:38 | |
*** ttsiouts has joined #openstack-meeting | 12:49 | |
*** psachin has quit IRC | 12:50 | |
*** ykatabam has quit IRC | 13:00 | |
*** bobh has joined #openstack-meeting | 13:01 | |
*** e0ne has joined #openstack-meeting | 13:07 | |
*** takashin has joined #openstack-meeting | 13:08 | |
*** weshay is now known as weshay_meeting | 13:12 | |
*** awaugama has joined #openstack-meeting | 13:15 | |
*** mjturek has joined #openstack-meeting | 13:22 | |
*** felipemonteiro has joined #openstack-meeting | 13:28 | |
*** munimeha1 has joined #openstack-meeting | 13:29 | |
*** lbragstad_503 is now known as lbragstad | 13:32 | |
*** mjturek has quit IRC | 13:43 | |
*** bnemec has joined #openstack-meeting | 13:43 | |
*** mdbooth has joined #openstack-meeting | 13:45 | |
*** annp_ has joined #openstack-meeting | 13:55 | |
gibi | #startmeeting nova | 14:00 |
---|---|---|
openstack | Meeting started Thu Oct 18 14:00:00 2018 UTC and is due to finish in 60 minutes. The chair is gibi. Information about MeetBot at http://wiki.debian.org/MeetBot. | 14:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 14:00 |
*** openstack changes topic to " (Meeting topic: nova)" | 14:00 | |
openstack | The meeting name has been set to 'nova' | 14:00 |
*** cdent has joined #openstack-meeting | 14:00 | |
mriedem | o/ | 14:00 |
Luzi | o/ | 14:00 |
edleafe | \o | 14:00 |
gmann | o/ | 14:00 |
stephenfin | o/ | 14:00 |
tssurya | o/ | 14:00 |
gibi | hello everyone I will be your host today | 14:00 |
takashin | o/ | 14:00 |
* bauzas waves | 14:00 | |
cdent | o/ | 14:00 |
gibi | Let's get started | 14:01 |
gibi | #topic Release News | 14:01 |
*** openstack changes topic to "Release News (Meeting topic: nova)" | 14:01 | |
mdbooth | o/ | 14:01 |
gibi | #link Stein release schedule: https://wiki.openstack.org/wiki/Nova/Stein_Release_Schedule | 14:01 |
gibi | #link Stein runway etherpad: https://etherpad.openstack.org/p/nova-runways-stein | 14:01 |
gibi | #link runway #1: https://blueprints.launchpad.net/nova/+spec/use-nested-allocation-candidates (gibi) [END: 2018-10-23] next patch at https://review.openstack.org/#/c/605785 | 14:01 |
gibi | #link runway #2: https://blueprints.launchpad.net/nova/+spec/api-extensions-merge-stein (gmann) [END: 2018-10-25] https://review.openstack.org/#/q/topic:bp/api-extensions-merge-stein+status:open | 14:01 |
gibi | #link runway #3: <empty> | 14:01 |
gibi | and also the runway queue is empty | 14:01 |
gibi | anything to discuss about release or runways? | 14:02 |
mriedem | just a reminder, | 14:02 |
mriedem | specs don't go into the runways queue, | 14:02 |
mriedem | i had to remove another 2 specs that people posted in there yesterday | 14:02 |
mriedem | i thought mel was going to send a reminder email to the ML but i don't see it | 14:02 |
mriedem | the end | 14:03 |
*** sean-k-mooney has joined #openstack-meeting | 14:03 | |
gibi | mriedem: good point | 14:03 |
gibi | #topic Bugs (stuck/critical) | 14:03 |
*** openstack changes topic to "Bugs (stuck/critical) (Meeting topic: nova)" | 14:03 | |
gibi | no critical bugs | 14:03 |
gibi | #link 50 new untriaged bugs (down 11 since the last meeting): https://bugs.launchpad.net/nova/+bugs?search=Search&field.status=New | 14:03 |
gibi | #link 8 untagged untriaged bugs (up 2 since the last meeting): https://bugs.launchpad.net/nova/+bugs?field.tag=-*&field.status%3Alist=NEW | 14:03 |
gibi | #link bug triage how-to: https://wiki.openstack.org/wiki/Nova/BugTriage#Tags | 14:04 |
gibi | #help need help with bug triage | 14:04 |
gibi | anything about bugs to discuss? | 14:04 |
gibi | Gate status | 14:04 |
gibi | #link check queue gate status http://status.openstack.org/elastic-recheck/index.html | 14:04 |
gibi | 3rd party CI | 14:04 |
gibi | #link 3rd party CI status http://ci-watch.tintri.com/project?project=nova&time=7+days | 14:04 |
gibi | I haven't pushed patch recenty so I don't have experience about the gate | 14:05 |
*** hongbin has joined #openstack-meeting | 14:05 | |
gibi | based on the elastice page it works OK | 14:05 |
gibi | anything about the gate to discuss? | 14:06 |
gibi | #topic Reminders | 14:06 |
*** openstack changes topic to "Reminders (Meeting topic: nova)" | 14:06 | |
gibi | #link Stein Subteam Patches n Bugs: https://etherpad.openstack.org/p/stein-nova-subteam-tracking | 14:06 |
*** longkb has joined #openstack-meeting | 14:06 | |
* efried_pto waves late | 14:06 | |
cdent | If you have opinions about which versions of python the gate should be testing, there's a few review in governance arguing about it | 14:06 |
*** efried_pto is now known as efried | 14:06 | |
*** slaweq has quit IRC | 14:06 | |
gibi | cdent: thanks | 14:07 |
cdent | #link https://review.openstack.org/#/c/610708/ | 14:07 |
cdent | #link https://review.openstack.org/#/c/611080/ | 14:07 |
cdent | #link https://review.openstack.org/#/c/611010/ | 14:07 |
mriedem | would be nice if someone summarized that thread in the ML | 14:07 |
*** slaweq has joined #openstack-meeting | 14:07 | |
mriedem | where could i find a tc member that likes to write... | 14:08 |
sean-k-mooney | cdent: my 2 cents if we drop py 3.5 testing then that cant be our miunum suported version but i dont want to get into that thread here | 14:08 |
cdent | mriedem: I gave up | 14:08 |
mriedem | make the rookies do it | 14:08 |
mriedem | moving on... | 14:09 |
gibi | so one more reminder | 14:09 |
gibi | #link spec review day Tuesday Oct 23: http://lists.openstack.org/pipermail/openstack-dev/2018-October/135795.html | 14:09 |
* gibi started the review day today as he will be off on 23rd | 14:09 | |
gibi | any other reminders? | 14:09 |
mriedem | yes, | 14:09 |
mriedem | if you have forum sessions, | 14:10 |
mriedem | get your etherpad started and linked to https://wiki.openstack.org/wiki/Forum/Berlin2018 | 14:10 |
mriedem | i'm looking at stephenfin and bauzas | 14:10 |
*** ttsiouts has quit IRC | 14:10 | |
stephenfin | ack | 14:10 |
bauzas | mriedem: yup, on my plate | 14:10 |
mriedem | and lee but he's out | 14:10 |
*** apetrich has quit IRC | 14:11 | |
gibi | mriedem: thanks for the reminder | 14:11 |
gibi | #topic Stable branch status | 14:11 |
*** openstack changes topic to "Stable branch status (Meeting topic: nova)" | 14:11 | |
gibi | #link stable/rocky: https://review.openstack.org/#/q/status:open+project:openstack/nova+branch:stable/rocky,n,z | 14:11 |
gibi | #link stable/queens: https://review.openstack.org/#/q/status:open+project:openstack/nova+branch:stable/queens,n,z | 14:11 |
gibi | #link stable/pike: https://review.openstack.org/#/q/status:open+project:openstack/nova+branch:stable/pike,n,z | 14:11 |
gibi | #link stable/ocata: https://review.openstack.org/#/q/status:open+project:openstack/nova+branch:stable/ocata,n,z | 14:11 |
gibi | anything to discuss about stable? | 14:11 |
mriedem | we'll need to do a rocky release soon | 14:12 |
mriedem | b/c we have 2 upgrade impacting issues | 14:12 |
mriedem | https://review.openstack.org/#/c/611315/ and https://review.openstack.org/#/c/611337/ | 14:12 |
mriedem | dansmith: can you +W the latter ^ ? | 14:12 |
dansmith | probably | 14:12 |
mriedem | oh 3 https://review.openstack.org/#/c/610673/ | 14:12 |
mriedem | we like to break upgrades round these parts | 14:13 |
dansmith | queued | 14:13 |
gibi | #topic Subteam Highlights | 14:14 |
*** openstack changes topic to "Subteam Highlights (Meeting topic: nova)" | 14:14 | |
gibi | Cells v2 (dansmith) | 14:14 |
dansmith | gibi: we don't have a meeting anymore, so I think we're not doing this bit now, but, | 14:14 |
mriedem | we should probably remove that section, the meeting is cancelled indefinitely | 14:14 |
gibi | dansmith: ahh good point | 14:14 |
dansmith | I was just saing in channel that the down cell stuff hit a test snag recently which I've now identified, | 14:14 |
gibi | #action gibi update the agenda to permanently remove the cellv2 and the notification section | 14:15 |
dansmith | so we can move forward with that soon | 14:15 |
dansmith | I think that's the major bit of cellsy news of late | 14:15 |
mriedem | gibi: already done | 14:15 |
dansmith | I was going to report it was stalled for that reason, | 14:15 |
dansmith | but the status changed in the last few minutes :) | 14:15 |
gibi | cool, thanks | 14:15 |
gibi | Scheduler (efried) | 14:15 |
efried | #link Minutes from this week's n-sch meeting http://eavesdrop.openstack.org/meetings/nova_scheduler/2018/nova_scheduler.2018-10-15-14.00.html | 14:15 |
efried | It was a short one. The only thing of note was a reminder to folks to review placement extract grenade patches, which spider out from | 14:15 |
efried | #link grenade stuff https://review.openstack.org/#/c/604454/ | 14:15 |
efried | END | 14:15 |
mriedem | https://review.openstack.org/#/q/topic:cd/placement-solo+(status:open) | 14:16 |
gibi | thanks | 14:16 |
gibi | API (gmann) | 14:16 |
gibi | gmann posted the satus as a mail | 14:16 |
gibi | #link http://lists.openstack.org/pipermail/openstack-dev/2018-October/135827.html | 14:17 |
gibi | #topic Stuck Reviews | 14:17 |
*** openstack changes topic to "Stuck Reviews (Meeting topic: nova)" | 14:17 | |
gibi | there is one item on the agenda | 14:17 |
gibi | Fail to live migration if instance has a NUMA topology: https://review.openstack.org/#/c/611088/ | 14:17 |
gibi | stephenfin: do you want to open it up? | 14:18 |
*** cloudrancher has joined #openstack-meeting | 14:18 | |
gibi | or artom | 14:18 |
artom | sup? | 14:18 |
stephenfin | gibi: Yeah, not much to say about it, really | 14:18 |
artom | Oh, that, yeah | 14:18 |
artom | Can of worms: opened :D | 14:18 |
stephenfin | There are review comments there. cfriesen and artom have looked at it, but I imagine it's going to be contentious | 14:19 |
sean-k-mooney | to adress that bug you need artoms | 14:19 |
sean-k-mooney | numa aware live migration spec | 14:19 |
sean-k-mooney | to be implemented | 14:19 |
dansmith | but this is about failing it, not fixing it right? | 14:19 |
stephenfin | As noted, I'd like to start enforcing this. It's a change in behavior but we have a policy of introducing changes in behavior in e.g. the API if there's a clear bug there | 14:19 |
mriedem | the only way anything works is if you accidentally land the server on a dest host that is identical to the source and the available resources are there on the dest, right? | 14:20 |
stephenfin | dansmith: correct | 14:20 |
gibi | spec #link https://review.openstack.org/#/c/599587/ | 14:20 |
stephenfin | mriedem: also correct | 14:20 |
dansmith | I think refusing to intentionally break an instance makes sense | 14:20 |
dansmith | but I imagine we have to allow an override | 14:20 |
sean-k-mooney | mriedem: yes | 14:20 |
*** apetrich has joined #openstack-meeting | 14:20 | |
stephenfin | sean-k-mooney: I want to make this start failing until artom's spec lands | 14:20 |
dansmith | can we refuse unless force and a host is given? | 14:20 |
mriedem | also, can't this be done a higher level than the libvirt driver? | 14:20 |
artom | dansmith, yeah, that's sort of where we've been heading - Chris made the good point of evacuating a server to an identical replacement, so the operator would know it's OK | 14:21 |
dansmith | right where we have visibility to the request | 14:21 |
mriedem | you know if the instance has pci_requests/numa topology from the db | 14:21 |
*** mjturek has joined #openstack-meeting | 14:21 | |
sean-k-mooney | dansmith: i mean if they are using for all bets are off form schduler point of view so sure | 14:21 |
dansmith | artom: aye | 14:21 |
stephenfin | mriedem: Yeah, this is a first pass. We can definitely do it higher/earlier | 14:21 |
*** ttsiouts has joined #openstack-meeting | 14:21 | |
dansmith | stephenfin: so this isn't actually stuck you just wanted discussion? | 14:21 |
stephenfin | It was stuck when I added it | 14:21 |
mriedem | it's not really stuck | 14:22 |
dansmith | that's not what this section is for, yeah | 14:22 |
stephenfin | But it seems I may have talked artom around and I forgot to remove it. We can move on | 14:22 |
gibi | OK | 14:22 |
dansmith | stuck means cores can't agree | 14:22 |
dansmith | okay | 14:22 |
gibi | anything else that is stuck? | 14:22 |
gibi | #topic Open discussion | 14:23 |
*** openstack changes topic to "Open discussion (Meeting topic: nova)" | 14:23 | |
gibi | Image Encryption Proposal (mhen, Luzi) | 14:23 |
gibi | Spec: https://review.openstack.org/#/c/608696/ | 14:23 |
gibi | Library discussion: https://etherpad.openstack.org/p/library-for-image-encryption-and-decryption | 14:23 |
Luzi | hi | 14:23 |
Luzi | as you might have noticed we would like to propose Image Encryption for OpenStack. | 14:23 |
Luzi | we have written specs for Nova, Cinder and Glance so far | 14:23 |
Luzi | the short version: image encryption would affect Nova in two ways: | 14:23 |
Luzi | 1. Nova needs to be able to decrypt an encrypted image, when creating a server from it | 14:24 |
Luzi | 2. Nova should be able to create an encrypted image from a server, with user given encryption key id and other metadata | 14:24 |
gibi | jaypipes left some comments already I also read the spec. I think it is a good start but needs some details around the API impact | 14:25 |
Luzi | we tried our best to answer the questions on the original spec and would appreciate further feedback on this to improve the proposal – we are currently looking into further specifying the API impact as requested | 14:25 |
Luzi | yes, that we are investigating right now, thank you for your comments btw :) | 14:25 |
Luzi | the other thing is: | 14:25 |
Luzi | as already mentioned on the ML, we created an etherpad to discuss the location for the proposed image encryption code: | 14:26 |
mriedem | is there a forum session for this? | 14:26 |
Luzi | except for exceptional cases. | 14:26 |
mriedem | it's more than just nova yes? | 14:26 |
* mdbooth should review that. It looks a bit tied to the libvirt driver, and possibly shouldn't be. | 14:26 | |
Luzi | no sadly not | 14:26 |
Luzi | #link image encryption library discussion https://etherpad.openstack.org/p/library-for-image-encryption-and-decryption | 14:26 |
mriedem | should see if there are still forum session slots available | 14:26 |
sean-k-mooney | this sound like somethink like os-brick | 14:26 |
sean-k-mooney | its not volume based but perhapse there is some overlap | 14:27 |
Luzi | we would like to receive input and comments from all involved projects, so please participate if possible :) | 14:27 |
mriedem | so the image, backup and shelve offload APIs would all have to take encryption ID and metadata parameters for this? | 14:27 |
mriedem | *creat eimage | 14:27 |
mriedem | those are the 3 APIs off the top of my head that create snapshots | 14:28 |
mriedem | and cross-cell resize is going to use shelve | 14:28 |
mriedem | ... | 14:28 |
mriedem | unless the server is created with that information to use later for snapshots | 14:28 |
Luzi | mriedem, that is what we are still investigating | 14:28 |
mriedem | or are we just talking about a proxy? | 14:28 |
mriedem | i.e. can the snapshot image be encrypted in glance after it's created from nova? | 14:29 |
mriedem | anyway, don't need to get into those details here | 14:29 |
mriedem | a forum session would have been nice, | 14:29 |
mriedem | and might still be an option | 14:29 |
mriedem | i doubt they filled all the available slots | 14:29 |
Luzi | not from our perspective | 14:29 |
sean-k-mooney | Luzi: in your proposal are the images encypted or decryped on the host while the instance is running | 14:29 |
mriedem | Luzi: if you or your team aren't going to be at the summit in berlin then yeah ignore me about a forum session | 14:30 |
mdbooth | Remember that LVM ephemeral disk encryption is useless from a security pov, btw | 14:30 |
Luzi | we will be in berlin, but we thought the forums were all full? | 14:30 |
mdbooth | The data is always available unencrypted on the host | 14:31 |
*** mjturek has quit IRC | 14:31 | |
mriedem | i guess the forum is full, so nvm | 14:31 |
*** sambetts|afk is now known as sambetts | 14:31 | |
mriedem | so let's move this to the spec | 14:31 |
Luzi | sean-k-mooney, the decryption happens before the vm is started and the encryption should happen in the case: | 14:32 |
gibi | OK, lets continue discussing this in the spec | 14:32 |
Luzi | ok, thank you :) | 14:32 |
gibi | Luzi: thank you for the spec | 14:32 |
gibi | there is one more item on the agenda | 14:32 |
gibi | #link Per-instance sysinfo serial for libvirt guests (mriedem/Kevin_Zheng) https://blueprints.launchpad.net/nova/+spec/per-instance-libvirt-sysinfo-serial | 14:32 |
mriedem | yar | 14:32 |
gibi | I've read the bp and I'm OK to use the instance.uuid as machine serial | 14:33 |
mriedem | ok so to summarize, the serial number that gets injected into libvirt guests comes from the host | 14:33 |
mriedem | so all guests on a libvirt host have the same serial number in their BIOS | 14:33 |
mdbooth | That sounds like a really good idea, but I think we're going to have to add something to a datamodel to indicate whether the instance was created with this or not | 14:33 |
mriedem | if the guest is running licensed software that relies on the serial, and you migrate the guest, the serial changes and your hit again for the license | 14:33 |
mriedem | so the idea is just make the serial unique to the guest, which would be the uuid | 14:34 |
*** annabelleB has joined #openstack-meeting | 14:34 | |
mriedem | mdbooth: because of migrations and host config? | 14:34 |
mdbooth | +1, but for the same reason you don't want all instances to have their machine id changed when the host is upgraded | 14:34 |
mdbooth | mriedem: Just thinking upgrades, tbh. | 14:35 |
mriedem | the simple implementation is just the libvirt.sysinfo_serial option gains a new choice which is to use the instance uuid | 14:35 |
mriedem | then the host upgrade shouldn't matter... | 14:35 |
mriedem | now if the guest really needs this to not change, and they are migrated between hosts with different config, the behavior could change | 14:36 |
mdbooth | mriedem: Problem with host-wide config is that you can't set it without affecting everything on that host. | 14:36 |
mriedem | in that case, we'd need something on the flavor/image | 14:36 |
mriedem | then it's per-instance and can travel properly via the scheduler | 14:37 |
mdbooth | mriedem: I didn't have a specific suggestion (just read it 2 mins ago), but 'somewhere' | 14:37 |
mdbooth | Anyway, it does sound like something we want | 14:37 |
mriedem | i'm fine with it being a thing on the flavor/image, that allows it to be more dynamic | 14:37 |
gibi | mriedem: if it is flavor/image then that can override the host config and we can keep the old behavior as well | 14:38 |
mriedem | gibi: true, | 14:38 |
mriedem | so is this still specless then or should i draft a small spec? | 14:38 |
mriedem | seems i should | 14:38 |
gibi | just to agree about the name of the extra_spec ;) | 14:38 |
mriedem | os_foo_bars | 14:38 |
mriedem | done | 14:38 |
*** mjturek_ has joined #openstack-meeting | 14:38 | |
mriedem | ok i'll crank out a spec shortly | 14:38 |
mriedem | thanks | 14:39 |
gibi | anything else to discuss? | 14:39 |
mdbooth | gibi: You mean on that topic, or at all? | 14:39 |
gibi | anything for open discussion | 14:40 |
gibi | ? | 14:40 |
* mdbooth wonders if we're in a position to push https://review.openstack.org/#/c/578846/ along | 14:40 | |
*** annabelleB has quit IRC | 14:40 | |
mdbooth | It's a bug which munched a customer's data a while back. | 14:40 |
mdbooth | Testing it is somewhat complex, but I think we might be there now. | 14:41 |
gibi | mdbooth: seems like you need some core review on that patch | 14:42 |
*** felipemonteiro has quit IRC | 14:42 | |
mriedem | you can bug me for it, i just have had too many plates spinning to remember this | 14:42 |
mdbooth | Yep. mriedem was keen to add an evacuate test to the gate, which was a fun exercise :) | 14:42 |
mriedem | yeah that's all done and super hot https://review.openstack.org/#/c/602174/ | 14:43 |
mdbooth | Related: mriedem do you want to push that test to the gate? | 14:43 |
mriedem | idk what that means | 14:43 |
mdbooth | mriedem: Invoke whatever incantations are required to actually start running it. | 14:43 |
mriedem | it's in the nova-live-migration job | 14:44 |
mriedem | once merged, it's there | 14:44 |
mdbooth | Merge those patches, I guess. | 14:44 |
mriedem | i would like all cores to merge all of my patches yes | 14:44 |
mriedem | b/c they are gr8 | 14:44 |
gibi | I've left that two patches open in my browser for tomorrow. If that helps :) | 14:44 |
gibi | any other topic for today? | 14:44 |
mdbooth | gibi: The function test prior to my actual test is the fun bit, btw ;) | 14:45 |
mdbooth | s/actual fix/ | 14:45 |
gibi | mdbooth: ack | 14:45 |
mdbooth | The fix is pretty simple. | 14:45 |
*** cloudrancher has quit IRC | 14:45 | |
mriedem | end it | 14:46 |
mriedem | please god | 14:46 |
gibi | thank you all | 14:46 |
gibi | #endmeeting | 14:46 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 14:46 | |
openstack | Meeting ended Thu Oct 18 14:46:27 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 14:46 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/nova/2018/nova.2018-10-18-14.00.html | 14:46 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/nova/2018/nova.2018-10-18-14.00.txt | 14:46 |
openstack | Log: http://eavesdrop.openstack.org/meetings/nova/2018/nova.2018-10-18-14.00.log.html | 14:46 |
*** gagehugo has joined #openstack-meeting | 14:47 | |
*** takashin has quit IRC | 14:51 | |
*** longkb has quit IRC | 14:54 | |
*** cdent has quit IRC | 14:54 | |
*** Swami has joined #openstack-meeting | 14:56 | |
*** manjeets_ has joined #openstack-meeting | 14:56 | |
*** annp_ has quit IRC | 14:57 | |
*** cloudrancher has joined #openstack-meeting | 14:58 | |
gagehugo | #startmeeting security | 15:00 |
openstack | Meeting started Thu Oct 18 15:00:36 2018 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:00 |
*** openstack changes topic to " (Meeting topic: security)" | 15:00 | |
openstack | The meeting name has been set to 'security' | 15:00 |
*** ttsiouts has quit IRC | 15:00 | |
* fungi is here but also in tc office hour | 15:01 | |
gagehugo | ping eeiden fungi gagehugo lhinds nickthetait browne redrobot | 15:01 |
gagehugo | #link https://etherpad.openstack.org/p/security-agenda | 15:01 |
gagehugo | fungi: o/ | 15:01 |
*** Luzi has quit IRC | 15:01 | |
gagehugo | I will attempt to look at those cinder bugs | 15:01 |
gagehugo | today | 15:01 |
fungi | awesome, thanks! | 15:01 |
*** Kevin_Zheng has joined #openstack-meeting | 15:02 | |
gagehugo | I read the API one more last night, haven't jumped into the scale io one yet | 15:02 |
fungi | #link | 15:02 |
fungi | https://bugs.launchpad.net/ossa/?field.searchtext=&orderby=-importance&search=Search&field.status%3Alist=NEW&field.status%3Alist=CONFIRMED&field.status%3Alist=TRIAGED&field.status%3Alist=INPROGRESS&field.status%3Alist=FIXCOMMITTED&field.status%3Alist=INCOMPLETE_WITH_RESPONSE&field.status%3Alist=INCOMPLETE_WITHOUT_RESPONSE&field.information_type%3Alist=PUBLIC&field.information_type%3Alist=PUBLICSECU | 15:02 |
fungi | RITY&assignee_option=any&field.assignee=&field.bug_reporter=&field.bug_commenter=&field.subscriber=&field.structural_subscriber=&field.tag=&field.tags_combinator=ANY&field.has_cve.used=&field.omit_dupes.used=&field.omit_dupes=on&field.affects_me.used=&field.has_patch.used=&field.has_branches.used=&field.has_branches=on&field.has_no_branches.used=&field.has_no_branches=on&field.has_blueprints.used=& | 15:02 |
fungi | field.has_blueprints=on&field.has_no_blueprints.used=&field.has_no_blueprints=on | 15:02 |
fungi | oh yikes | 15:02 |
gagehugo | lol | 15:02 |
fungi | sorry, didn't realize that url was so huge | 15:02 |
fungi | #undo | 15:03 |
fungi | #link https://bugs.launchpad.net/ossa/ | 15:03 |
*** ttsiouts has joined #openstack-meeting | 15:03 | |
fungi | should show 16 open public ossa bugs for anyone who isn't on the vmt to help with | 15:03 |
gagehugo | ok | 15:03 |
*** sean-k-mooney has left #openstack-meeting | 15:04 | |
gagehugo | other than that, I just have the anchor retirement | 15:04 |
gagehugo | https://review.openstack.org/#/c/611181/ & https://review.openstack.org/#/c/611187/ | 15:04 |
fungi | #link https://bugs.launchpad.net/ossa/?field.information_type%3Alist=PUBLIC&field.information_type%3Alist=PUBLICSECURITY is a shorter query which should show just the public and public security ossa bugs which are open even for people who have visibility into one or more of the private embargoed ones | 15:06 |
gagehugo | other than that, I don't have anything else atm | 15:06 |
*** dklyle has joined #openstack-meeting | 15:06 | |
gagehugo | oh nice | 15:06 |
fungi | #link https://review.openstack.org/611181 Retire project Anchor - step 4 | 15:06 |
fungi | #link https://review.openstack.org/611187 Retire project Anchor - Step 5 | 15:06 |
gagehugo | thanks | 15:07 |
fungi | and yeah, i've been otherwise occupied for the last week so nothing from me today | 15:07 |
gagehugo | we can end early then, thanks fungi! | 15:08 |
fungi | thanks to you as always, gagehugo! | 15:08 |
gagehugo | #endmeeting | 15:09 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 15:09 | |
openstack | Meeting ended Thu Oct 18 15:09:03 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:09 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/security/2018/security.2018-10-18-15.00.html | 15:09 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/security/2018/security.2018-10-18-15.00.txt | 15:09 |
openstack | Log: http://eavesdrop.openstack.org/meetings/security/2018/security.2018-10-18-15.00.log.html | 15:09 |
*** jangutter has left #openstack-meeting | 15:09 | |
*** annabelleB has joined #openstack-meeting | 15:10 | |
*** a-pugachev has joined #openstack-meeting | 15:11 | |
*** e0ne has quit IRC | 15:12 | |
*** eharney has quit IRC | 15:16 | |
*** e0ne has joined #openstack-meeting | 15:18 | |
*** jesusaur has joined #openstack-meeting | 15:20 | |
*** gagehugo has left #openstack-meeting | 15:20 | |
*** gagehugo has joined #openstack-meeting | 15:20 | |
*** yamamoto has quit IRC | 15:21 | |
*** yamamoto has joined #openstack-meeting | 15:22 | |
*** cdent has joined #openstack-meeting | 15:23 | |
*** jamesmcarthur has joined #openstack-meeting | 15:24 | |
*** yamamoto has quit IRC | 15:26 | |
*** annabelleB has quit IRC | 15:27 | |
*** devananda has joined #openstack-meeting | 15:30 | |
*** helenafm has left #openstack-meeting | 15:31 | |
*** annabelleB has joined #openstack-meeting | 15:33 | |
*** ttsiouts has quit IRC | 15:35 | |
*** ttsiouts has joined #openstack-meeting | 15:39 | |
*** gyee has joined #openstack-meeting | 15:43 | |
*** tssurya has quit IRC | 15:44 | |
*** a-pugachev_ has joined #openstack-meeting | 15:45 | |
*** liuyulong has quit IRC | 15:46 | |
*** liuyulong has joined #openstack-meeting | 15:46 | |
*** a-pugachev has quit IRC | 15:47 | |
*** a-pugachev_ is now known as a-pugachev | 15:47 | |
*** manjeets_ has quit IRC | 15:47 | |
*** mjturek_ has quit IRC | 15:49 | |
*** ttsiouts has quit IRC | 15:55 | |
*** ttsiouts has joined #openstack-meeting | 15:56 | |
*** macza has joined #openstack-meeting | 15:56 | |
*** cloudrancher has quit IRC | 15:57 | |
*** cloudrancher has joined #openstack-meeting | 15:59 | |
*** eharney has joined #openstack-meeting | 16:00 | |
*** cdent has quit IRC | 16:00 | |
*** e0ne has quit IRC | 16:00 | |
*** ttsiouts has quit IRC | 16:00 | |
*** cloudrancher has quit IRC | 16:05 | |
*** mriedem is now known as mriedem_lunch | 16:10 | |
*** yamamoto has joined #openstack-meeting | 16:11 | |
*** annabelleB has quit IRC | 16:12 | |
*** liuyulong is now known as liuyulong_zzz | 16:13 | |
*** jamesmcarthur has quit IRC | 16:15 | |
*** dklyle has quit IRC | 16:16 | |
*** dklyle has joined #openstack-meeting | 16:16 | |
*** Swami has quit IRC | 16:21 | |
*** manjeets has joined #openstack-meeting | 16:28 | |
*** jamesmcarthur has joined #openstack-meeting | 16:30 | |
*** macza has quit IRC | 16:33 | |
*** dklyle has quit IRC | 16:37 | |
*** annabelleB has joined #openstack-meeting | 16:39 | |
*** annabelleB has quit IRC | 16:43 | |
*** annabelleB has joined #openstack-meeting | 16:52 | |
*** yamamoto has quit IRC | 16:56 | |
*** yamamoto has joined #openstack-meeting | 16:56 | |
*** yamahata has joined #openstack-meeting | 17:04 | |
*** sambetts is now known as sambetts|afk | 17:07 | |
*** munimeha1 has quit IRC | 17:10 | |
*** ircuser-1 has quit IRC | 17:15 | |
*** mjturek has joined #openstack-meeting | 17:16 | |
*** dklyle has joined #openstack-meeting | 17:30 | |
*** rfolco is now known as rfolco|rucker | 17:31 | |
*** yamamoto has quit IRC | 17:33 | |
*** dklyle has quit IRC | 17:42 | |
*** diablo_rojo has joined #openstack-meeting | 17:44 | |
*** electrofelix has quit IRC | 17:48 | |
*** dklyle has joined #openstack-meeting | 17:50 | |
*** mriedem_lunch is now known as mriedem | 17:51 | |
*** priteau has quit IRC | 17:52 | |
*** munimeha1 has joined #openstack-meeting | 18:02 | |
*** dklyle has quit IRC | 18:02 | |
*** annabelleB has quit IRC | 18:07 | |
*** jamesmcarthur has quit IRC | 18:09 | |
*** apetrich has quit IRC | 18:10 | |
*** diablo_rojo has quit IRC | 18:12 | |
*** diablo_rojo has joined #openstack-meeting | 18:13 | |
*** yamamoto has joined #openstack-meeting | 18:14 | |
*** lbragstad has quit IRC | 18:17 | |
*** a-pugachev_ has joined #openstack-meeting | 18:18 | |
*** dklyle has joined #openstack-meeting | 18:20 | |
*** a-pugachev has quit IRC | 18:22 | |
*** a-pugachev_ is now known as a-pugachev | 18:22 | |
*** apetrich has joined #openstack-meeting | 18:24 | |
*** annabelleB has joined #openstack-meeting | 18:25 | |
*** diablo_rojo has quit IRC | 18:26 | |
*** dklyle has quit IRC | 18:29 | |
*** annabelleB has quit IRC | 18:32 | |
*** weshay_meeting is now known as weshay | 18:33 | |
*** annabelleB has joined #openstack-meeting | 18:34 | |
*** mjturek has quit IRC | 18:35 | |
*** jamesmcarthur has joined #openstack-meeting | 18:37 | |
*** jamesmcarthur has quit IRC | 18:43 | |
*** caboucha has joined #openstack-meeting | 18:43 | |
*** lifeless has joined #openstack-meeting | 18:43 | |
*** diablo_rojo has joined #openstack-meeting | 18:44 | |
*** a-pugachev_ has joined #openstack-meeting | 18:44 | |
*** a-pugachev has quit IRC | 18:46 | |
*** a-pugachev_ is now known as a-pugachev | 18:46 | |
*** lbragstad has joined #openstack-meeting | 18:48 | |
*** mjturek has joined #openstack-meeting | 18:53 | |
*** a-pugachev has quit IRC | 18:56 | |
*** a-pugachev has joined #openstack-meeting | 19:02 | |
*** dklyle has joined #openstack-meeting | 19:07 | |
*** jamesmcarthur has joined #openstack-meeting | 19:12 | |
*** dklyle has quit IRC | 19:14 | |
*** jamesmcarthur has quit IRC | 19:16 | |
*** bobh has quit IRC | 19:17 | |
*** lbragstad has quit IRC | 19:21 | |
*** lbragstad has joined #openstack-meeting | 19:24 | |
*** annabelleB has quit IRC | 19:32 | |
*** tpsilva has joined #openstack-meeting | 19:33 | |
*** diablo_rojo has quit IRC | 19:35 | |
*** apetrich has quit IRC | 19:44 | |
*** devananda has quit IRC | 19:47 | |
*** e0ne has joined #openstack-meeting | 19:52 | |
*** ralonsoh has quit IRC | 20:00 | |
*** ssbarnea_ has joined #openstack-meeting | 20:02 | |
*** eharney has quit IRC | 20:03 | |
*** e0ne has quit IRC | 20:05 | |
*** zaneb has quit IRC | 20:31 | |
*** mjturek has quit IRC | 20:38 | |
*** pcaruana has quit IRC | 20:44 | |
*** cloudrancher has joined #openstack-meeting | 20:46 | |
*** weshay is now known as weshay_pto | 20:52 | |
*** annabelleB has joined #openstack-meeting | 20:54 | |
*** zaneb has joined #openstack-meeting | 20:54 | |
*** dustins has quit IRC | 20:57 | |
*** erlon__ has quit IRC | 21:01 | |
*** raildo has quit IRC | 21:09 | |
*** zaneb has quit IRC | 21:11 | |
*** diablo_rojo has joined #openstack-meeting | 21:12 | |
*** bnemec is now known as bnemec-bbl | 21:20 | |
*** munimeha1 has quit IRC | 21:28 | |
*** walshh_ has quit IRC | 21:29 | |
*** dklyle has joined #openstack-meeting | 21:36 | |
*** diablo_rojo has quit IRC | 21:42 | |
*** diablo_rojo has joined #openstack-meeting | 21:44 | |
*** dklyle has quit IRC | 21:45 | |
*** awaugama has quit IRC | 21:49 | |
*** ssbarnea_ has quit IRC | 21:53 | |
*** jamesmcarthur has joined #openstack-meeting | 21:55 | |
*** jamesmcarthur has quit IRC | 21:59 | |
*** mriedem has quit IRC | 22:12 | |
*** rcernin has joined #openstack-meeting | 22:33 | |
*** bobh has joined #openstack-meeting | 22:37 | |
*** bobh has quit IRC | 22:41 | |
*** ykatabam has joined #openstack-meeting | 22:45 | |
*** a-pugachev has quit IRC | 22:51 | |
*** diablo_rojo has quit IRC | 22:52 | |
*** ircuser-1 has joined #openstack-meeting | 22:52 | |
*** tpsilva has quit IRC | 23:03 | |
*** diablo_rojo has joined #openstack-meeting | 23:03 | |
*** jiaopengju has quit IRC | 23:05 | |
*** hongbin has quit IRC | 23:08 | |
*** jiaopengju has joined #openstack-meeting | 23:08 | |
*** mjturek has joined #openstack-meeting | 23:17 | |
*** erlon__ has joined #openstack-meeting | 23:18 | |
*** zaneb has joined #openstack-meeting | 23:24 | |
*** annabelleB has quit IRC | 23:31 | |
*** jiaopengju has quit IRC | 23:35 | |
*** jiaopengju has joined #openstack-meeting | 23:36 | |
*** jamesmcarthur has joined #openstack-meeting | 23:36 | |
*** diablo_rojo has quit IRC | 23:37 | |
*** jamesmcarthur has quit IRC | 23:39 | |
*** jamesmcarthur has joined #openstack-meeting | 23:39 | |
*** mjturek has quit IRC | 23:42 | |
*** felipemonteiro has joined #openstack-meeting | 23:48 | |
*** bnemec has joined #openstack-meeting | 23:50 | |
*** bnemec-bbl has quit IRC | 23:52 | |
*** jamesmcarthur has quit IRC | 23:55 | |
*** jamesmcarthur has joined #openstack-meeting | 23:58 | |
*** gyee has quit IRC | 23:59 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!