*** armax has quit IRC | 00:00 | |
*** lseki has quit IRC | 00:09 | |
*** brinzhang has joined #openstack-meeting | 00:17 | |
*** brinzhang_ has quit IRC | 00:20 | |
*** enriquetaso has quit IRC | 00:27 | |
*** armax has joined #openstack-meeting | 00:44 | |
*** nitinuikey has joined #openstack-meeting | 00:46 | |
*** efried has quit IRC | 00:51 | |
*** nitinuikey has quit IRC | 00:53 | |
*** efried has joined #openstack-meeting | 00:59 | |
*** ricolin has joined #openstack-meeting | 01:04 | |
*** tetsuro has joined #openstack-meeting | 01:12 | |
*** radeks_ has joined #openstack-meeting | 01:19 | |
*** radeks_ has quit IRC | 01:24 | |
*** igordc has quit IRC | 01:31 | |
*** bobh has joined #openstack-meeting | 01:34 | |
*** armax has quit IRC | 01:39 | |
*** gyee has quit IRC | 02:00 | |
*** baojg has joined #openstack-meeting | 02:03 | |
*** ykatabam has joined #openstack-meeting | 02:08 | |
*** ykatabam has quit IRC | 02:08 | |
*** ykatabam has joined #openstack-meeting | 02:08 | |
*** slaweq has joined #openstack-meeting | 02:11 | |
*** slaweq has quit IRC | 02:15 | |
*** bobh has quit IRC | 02:19 | |
*** tetsuro has quit IRC | 02:24 | |
*** bobh has joined #openstack-meeting | 02:26 | |
*** tetsuro has joined #openstack-meeting | 02:48 | |
*** bobh has quit IRC | 02:56 | |
*** notmyname has quit IRC | 03:20 | |
*** notmyname has joined #openstack-meeting | 03:20 | |
*** tetsuro has quit IRC | 03:21 | |
*** diablo_rojo has quit IRC | 03:27 | |
*** bobh has joined #openstack-meeting | 03:33 | |
*** bobh has quit IRC | 03:38 | |
*** whoami-rajat has joined #openstack-meeting | 03:41 | |
*** hongbin has joined #openstack-meeting | 03:45 | |
*** hongbin has quit IRC | 03:46 | |
*** psachin has joined #openstack-meeting | 03:55 | |
*** imsurit has joined #openstack-meeting | 03:59 | |
*** slaweq has joined #openstack-meeting | 04:11 | |
*** slaweq has quit IRC | 04:17 | |
*** Luzi has joined #openstack-meeting | 04:25 | |
*** tetsuro has joined #openstack-meeting | 04:28 | |
*** tetsuro has quit IRC | 05:02 | |
*** diablo_rojo has joined #openstack-meeting | 05:21 | |
*** ociuhandu has joined #openstack-meeting | 05:22 | |
*** diablo_rojo has quit IRC | 05:25 | |
*** jamesmcarthur has quit IRC | 05:26 | |
*** dansmith has quit IRC | 05:26 | |
*** ociuhandu has quit IRC | 05:27 | |
*** dansmith has joined #openstack-meeting | 05:28 | |
*** tetsuro has joined #openstack-meeting | 05:43 | |
*** kopecmartin|off is now known as kopecmartin | 05:46 | |
*** iyamahat has quit IRC | 05:48 | |
*** tetsuro has quit IRC | 05:48 | |
*** belmoreira has joined #openstack-meeting | 05:50 | |
*** belmoreira has quit IRC | 05:50 | |
*** radeks has joined #openstack-meeting | 05:52 | |
*** belmoreira has joined #openstack-meeting | 05:52 | |
*** slaweq has joined #openstack-meeting | 06:04 | |
*** radeks has quit IRC | 06:08 | |
*** slaweq has quit IRC | 06:09 | |
*** imsurit has quit IRC | 06:10 | |
*** slaweq has joined #openstack-meeting | 06:11 | |
*** imsurit has joined #openstack-meeting | 06:11 | |
*** takamatsu has joined #openstack-meeting | 06:13 | |
*** slaweq has quit IRC | 06:16 | |
*** bobh has joined #openstack-meeting | 06:19 | |
*** imsurit has quit IRC | 06:21 | |
*** janki has joined #openstack-meeting | 06:22 | |
*** bobh has quit IRC | 06:23 | |
*** ricolin_ has joined #openstack-meeting | 06:26 | |
*** ricolin has quit IRC | 06:29 | |
*** imsurit has joined #openstack-meeting | 06:45 | |
*** e0ne has joined #openstack-meeting | 06:57 | |
*** e0ne has quit IRC | 06:59 | |
*** ykatabam has quit IRC | 06:59 | |
*** belmoreira has quit IRC | 07:01 | |
*** belmoreira has joined #openstack-meeting | 07:03 | |
*** slaweq has joined #openstack-meeting | 07:04 | |
*** _pewp_ has quit IRC | 07:11 | |
*** _pewp_ has joined #openstack-meeting | 07:12 | |
*** pcaruana has quit IRC | 07:12 | |
*** tetsuro has joined #openstack-meeting | 07:13 | |
*** imsurit has quit IRC | 07:17 | |
*** tetsuro has quit IRC | 07:17 | |
*** tesseract has joined #openstack-meeting | 07:20 | |
*** imsurit has joined #openstack-meeting | 07:24 | |
*** belmoreira has quit IRC | 07:28 | |
*** tssurya has joined #openstack-meeting | 07:32 | |
*** belmoreira has joined #openstack-meeting | 07:35 | |
*** ralonsoh has joined #openstack-meeting | 07:39 | |
*** ociuhandu has joined #openstack-meeting | 07:39 | |
*** boxiang has joined #openstack-meeting | 07:40 | |
*** ralonsoh has quit IRC | 07:40 | |
*** ralonsoh has joined #openstack-meeting | 07:40 | |
*** pcaruana has joined #openstack-meeting | 07:42 | |
*** e0ne has joined #openstack-meeting | 07:53 | |
*** ociuhandu has quit IRC | 07:56 | |
*** electrofelix has joined #openstack-meeting | 07:58 | |
*** boxiang has quit IRC | 07:59 | |
*** boxiang has joined #openstack-meeting | 07:59 | |
*** belmoreira has quit IRC | 08:01 | |
*** lpetrut has joined #openstack-meeting | 08:03 | |
*** lpetrut has quit IRC | 08:04 | |
*** lpetrut has joined #openstack-meeting | 08:04 | |
*** belmoreira has joined #openstack-meeting | 08:07 | |
*** belmoreira has quit IRC | 08:09 | |
*** belmoreira has joined #openstack-meeting | 08:11 | |
*** boxiang has quit IRC | 08:17 | |
*** lpetrut has quit IRC | 08:29 | |
*** priteau has joined #openstack-meeting | 08:53 | |
*** belmoreira has quit IRC | 08:54 | |
*** psachin has quit IRC | 09:00 | |
*** cheng1 has quit IRC | 09:02 | |
*** belmoreira has joined #openstack-meeting | 09:03 | |
*** cheng1 has joined #openstack-meeting | 09:03 | |
*** bobh has joined #openstack-meeting | 09:07 | |
*** janki has quit IRC | 09:08 | |
*** janki has joined #openstack-meeting | 09:09 | |
*** bobh has quit IRC | 09:12 | |
*** jchhatbar has joined #openstack-meeting | 09:17 | |
*** janki has quit IRC | 09:17 | |
*** belmoreira has quit IRC | 09:22 | |
*** jchhatbar has quit IRC | 09:25 | |
*** belmoreira has joined #openstack-meeting | 09:26 | |
*** asmita_s has joined #openstack-meeting | 09:27 | |
*** e0ne_ has joined #openstack-meeting | 09:36 | |
*** asmita_s has quit IRC | 09:36 | |
*** yamamoto has joined #openstack-meeting | 09:36 | |
*** e0ne has quit IRC | 09:37 | |
*** priteau has quit IRC | 09:43 | |
*** priteau has joined #openstack-meeting | 09:44 | |
*** priteau has quit IRC | 09:50 | |
*** priteau has joined #openstack-meeting | 09:52 | |
*** belmoreira has quit IRC | 09:53 | |
*** ociuhandu has joined #openstack-meeting | 09:57 | |
*** belmoreira has joined #openstack-meeting | 10:00 | |
*** ociuhandu has quit IRC | 10:01 | |
*** yamamoto has quit IRC | 10:07 | |
*** ricolin__ has joined #openstack-meeting | 10:28 | |
*** yamamoto has joined #openstack-meeting | 10:30 | |
*** yamamoto has quit IRC | 10:30 | |
*** ricolin_ has quit IRC | 10:31 | |
*** bbowen has joined #openstack-meeting | 10:44 | |
*** bbowen has quit IRC | 10:45 | |
*** bbowen has joined #openstack-meeting | 10:46 | |
*** yamamoto has joined #openstack-meeting | 10:51 | |
*** yamamoto has quit IRC | 10:55 | |
*** rcernin has quit IRC | 10:58 | |
*** yamamoto has joined #openstack-meeting | 11:10 | |
*** belmoreira has quit IRC | 11:17 | |
*** belmoreira has joined #openstack-meeting | 11:19 | |
*** ociuhandu has joined #openstack-meeting | 11:20 | |
*** ociuhandu has quit IRC | 11:21 | |
*** panda is now known as panda|eat | 11:25 | |
*** qinhaizhong has joined #openstack-meeting | 11:26 | |
*** e0ne has joined #openstack-meeting | 11:29 | |
*** e0ne_ has quit IRC | 11:30 | |
*** qinhaizhong has quit IRC | 11:31 | |
*** qinhaizhong has joined #openstack-meeting | 11:32 | |
*** qinhaizhong has quit IRC | 11:43 | |
*** imsurit has quit IRC | 11:44 | |
*** raildo has joined #openstack-meeting | 11:45 | |
*** bobh has joined #openstack-meeting | 11:45 | |
*** priteau has quit IRC | 11:46 | |
*** bobh has quit IRC | 11:50 | |
*** jamesmcarthur has joined #openstack-meeting | 11:51 | |
*** ociuhandu has joined #openstack-meeting | 12:01 | |
*** ociuhandu has quit IRC | 12:05 | |
*** jamesmcarthur has quit IRC | 12:06 | |
*** ociuhandu has joined #openstack-meeting | 12:15 | |
*** bobh has joined #openstack-meeting | 12:16 | |
*** Lucas_Gray has joined #openstack-meeting | 12:22 | |
*** ociuhandu has quit IRC | 12:25 | |
*** ociuhandu has joined #openstack-meeting | 12:27 | |
*** ociuhandu has quit IRC | 12:31 | |
*** ociuhandu has joined #openstack-meeting | 12:31 | |
*** Lucas_Gray has quit IRC | 12:32 | |
*** panda|eat is now known as panda | 12:34 | |
*** Lucas_Gray has joined #openstack-meeting | 12:35 | |
*** tssurya_ has joined #openstack-meeting | 12:37 | |
*** tssurya has quit IRC | 12:37 | |
*** tssurya_ is now known as tssurya | 12:37 | |
*** artom has quit IRC | 12:37 | |
*** Lucas_Gray has quit IRC | 12:42 | |
*** jamesmcarthur has joined #openstack-meeting | 12:44 | |
*** belmoreira has quit IRC | 12:48 | |
*** Luzi has quit IRC | 12:55 | |
*** belmoreira has joined #openstack-meeting | 13:06 | |
*** bobh has quit IRC | 13:12 | |
*** enriquetaso has joined #openstack-meeting | 13:13 | |
*** enriquetaso has quit IRC | 13:15 | |
*** yamamoto has quit IRC | 13:21 | |
*** ociuhandu has quit IRC | 13:26 | |
*** dmacpher has joined #openstack-meeting | 13:26 | |
*** ociuhandu has joined #openstack-meeting | 13:27 | |
*** mriedem has joined #openstack-meeting | 13:27 | |
*** priteau has joined #openstack-meeting | 13:28 | |
*** ociuhandu has quit IRC | 13:31 | |
*** lseki has joined #openstack-meeting | 13:33 | |
*** AlanClark has joined #openstack-meeting | 13:36 | |
*** carloss has joined #openstack-meeting | 13:36 | |
*** enriquetaso has joined #openstack-meeting | 13:42 | |
*** yamamoto has joined #openstack-meeting | 13:43 | |
*** eharney has joined #openstack-meeting | 13:46 | |
*** priteau has quit IRC | 13:53 | |
*** lbragstad has joined #openstack-meeting | 13:59 | |
*** priteau has joined #openstack-meeting | 14:01 | |
*** ociuhandu has joined #openstack-meeting | 14:07 | |
*** belmoreira has quit IRC | 14:10 | |
*** ociuhandu has quit IRC | 14:16 | |
*** ociuhandu has joined #openstack-meeting | 14:19 | |
*** AlanClark has quit IRC | 14:22 | |
*** iyamahat has joined #openstack-meeting | 14:22 | |
*** jhesketh has quit IRC | 14:23 | |
*** ociuhandu has quit IRC | 14:23 | |
*** artom has joined #openstack-meeting | 14:25 | |
*** nickthetait has joined #openstack-meeting | 14:27 | |
*** zbitter is now known as zaneb | 14:32 | |
*** mhen has joined #openstack-meeting | 14:43 | |
*** priteau has quit IRC | 14:56 | |
*** gagehugo has joined #openstack-meeting | 14:59 | |
gagehugo | #startmeeting security | 15:00 |
---|---|---|
openstack | Meeting started Thu Aug 1 15:00:12 2019 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:00 |
*** openstack changes topic to " (Meeting topic: security)" | 15:00 | |
openstack | The meeting name has been set to 'security' | 15:00 |
gagehugo | #link https://etherpad.openstack.org/p/security-agenda | 15:00 |
*** thgcorrea has joined #openstack-meeting | 15:00 | |
gagehugo | o/ | 15:00 |
nickthetait | hi | 15:00 |
mhen | o/ | 15:01 |
gagehugo | we will start in a couple minutes | 15:01 |
*** sfernand has joined #openstack-meeting | 15:01 | |
*** yamamoto has quit IRC | 15:02 | |
gagehugo | ok | 15:03 |
gagehugo | #topic Security Bug | 15:03 |
*** openstack changes topic to "Security Bug (Meeting topic: security)" | 15:03 | |
gagehugo | #link https://bugs.launchpad.net/os-vif/+bug/1837252 | 15:04 |
openstack | Launchpad bug 1837252 in os-vif trunk "IFLA_BR_AGEING_TIME of 0 causes flooding across bridges" [High,In progress] - Assigned to sean mooney (sean-k-mooney) | 15:04 |
*** yamamoto has joined #openstack-meeting | 15:04 | |
*** yamamoto has quit IRC | 15:04 | |
gagehugo | if anyone can take a look at ^, it would be appreciated | 15:04 |
gagehugo | it looks a bit similar to other bugs, but there's comments stating that its affecting multiple network backends | 15:05 |
*** yamamoto has joined #openstack-meeting | 15:05 | |
gagehugo | #topic Security Guide Updates | 15:05 |
fungi | hey, sorry, our broadband provider seems to have lost contact with the mainland at 15:00z precisely (i'm back on through a wireless modem for now) | 15:05 |
*** openstack changes topic to "Security Guide Updates (Meeting topic: security)" | 15:05 | |
gagehugo | fungi: oh no | 15:06 |
fungi | it happens with some regularity | 15:06 |
fungi | i need to get around to hooking a wireless modem directly to my home firewall as a backup connection | 15:06 |
gagehugo | nickthetait: I asked cmurphy about the federation guide, it's quite out of date and it would probably be best to just link directly to the keystone federation guide | 15:06 |
gagehugo | #link https://docs.openstack.org/keystone/latest/admin/federation/introduction.html | 15:07 |
nickthetait | ok good deal | 15:07 |
gagehugo | also, one less page for us to keep up-to-date | 15:07 |
nickthetait | exactly | 15:08 |
gagehugo | nickthetait: any other issues currently? | 15:08 |
gagehugo | I saw a bunch of changes got merged | 15:08 |
nickthetait | no issues and yes first changes have landed :) | 15:09 |
gagehugo | \o/ | 15:09 |
nickthetait | one question about checklists | 15:09 |
*** yamamoto has quit IRC | 15:09 | |
gagehugo | sure | 15:09 |
nickthetait | for example https://docs.openstack.org/security-guide/identity/checklist.html | 15:09 |
nickthetait | how can I verify these are relevant and still useful? | 15:09 |
*** ociuhandu has joined #openstack-meeting | 15:10 | |
gagehugo | you would need to be aware of the current state of that project haha | 15:12 |
gagehugo | 04 is not relevent | 15:12 |
gagehugo | PKI tokens are gone | 15:12 |
gagehugo | I think 05 can be changed | 15:12 |
gagehugo | I would need to check the value off the top of my head | 15:13 |
gagehugo | I can't remember* | 15:13 |
*** yamamoto has joined #openstack-meeting | 15:13 | |
*** yamamoto has quit IRC | 15:13 | |
gagehugo | nickthetait: I'll look through those and let you know | 15:13 |
nickthetait | hmm so there will be some serious work to get those sorted out | 15:13 |
nickthetait | thx | 15:14 |
gagehugo | #action gagehugo to look through https://docs.openstack.org/security-guide/identity/checklist.html | 15:14 |
*** yamamoto has joined #openstack-meeting | 15:14 | |
gagehugo | the other services likely will need updates as well | 15:14 |
nickthetait | yes for sure | 15:14 |
gagehugo | #topic Cinder/Nova Policy Follow-Up | 15:15 |
*** openstack changes topic to "Cinder/Nova Policy Follow-Up (Meeting topic: security)" | 15:15 | |
*** bbowen has quit IRC | 15:15 | |
gagehugo | mhen: o/ | 15:15 |
*** bbowen has joined #openstack-meeting | 15:15 | |
mhen | hi :) | 15:15 |
gagehugo | I looked at this briefly, and I saw you commented on that nova ps | 15:16 |
mhen | sorry but I had to give a -1 for now on the ps | 15:16 |
gagehugo | oh no worries | 15:16 |
mhen | I think the proposed documentation change is tackling the problem from the wrong side to be honest | 15:16 |
gagehugo | it probably is :) | 15:16 |
mhen | we could introduce clear statements of all the different cases where either yaml or json is required/expected in the docs | 15:18 |
mhen | but the root problem imo is still that Nova behaves differently than Cinder | 15:18 |
*** yamamoto has quit IRC | 15:18 | |
gagehugo | yeah, each service tends to do that | 15:18 |
gagehugo | I agree though, we can addon to that ps to tackle all of the cases | 15:19 |
gagehugo | I think your comment also clarified more of the issue for me as well | 15:20 |
mhen | by the way, the change required to make one of the services adapt to the other's default in regards to policy format is one line of code only for either | 15:20 |
gagehugo | but I also have been heads-down the last week, so haven't had much time to look deeper into it, but it's calmed down a bit here | 15:20 |
gagehugo | yeah, more to bring them in sync | 15:21 |
mhen | gagehugo, no problem. I hope my comment can help understanding the problem. | 15:21 |
mhen | wouldn't the default policy format (as a security related decision) important to be consistent across OpenStack? | 15:23 |
gagehugo | oh yes | 15:23 |
gagehugo | there's been other policy related groups at various summits as well, so it's not only a "security" topic | 15:24 |
fungi | unified policy management has been a long time need opwnstack-wise | 15:25 |
fungi | er, openstack-wide | 15:25 |
gagehugo | yes | 15:25 |
gagehugo | #action: follow up on nova ps, check cinder's docs/policy generation, attempt to unify them | 15:26 |
mhen | is anybody aware of other component's default format? (aside from Nova and Cinder) I haven't looked into others yet ... | 15:27 |
*** gyee has joined #openstack-meeting | 15:27 | |
gagehugo | keystone's sample is json iirc | 15:27 |
gagehugo | but it generates a yaml if you genpolicy | 15:28 |
mhen | the sample might be misleading btw, it's important what the service is actually trying to parse during startup when no config option is set | 15:28 |
*** tssurya has quit IRC | 15:30 | |
gagehugo | well, services also have policy-in-code as well | 15:31 |
mhen | anyway, if it turns out either Nova or Cinder is the only one using a different default across OpenStack, we could possibly convince them to change it, no? | 15:31 |
gagehugo | If we have a clear directive to get the services to follow the same format, it should be fine | 15:31 |
fungi | i think so, yes. though that may require time if it means behavior changes for folks at upgrade | 15:31 |
gagehugo | that is true | 15:32 |
fungi | in the past we've taken tactics like deprecating the old options and introducing new options which default to the new value but you have to remove the old option for them to take effect | 15:32 |
fungi | stuff like that | 15:32 |
fungi | so that on upgrade the behavior doesn't change, but the defaults do either when you remove the old option or pass the end of the deprecation period when the service no longer recognizes the old option at all | 15:33 |
mhen | non-trivial, I see | 15:34 |
mhen | another option would be to convince Cinder to try looking up a json if yaml isn't found (in case the assumption that Cinder is the only one using yaml per default currently, holds true) | 15:35 |
gagehugo | mhen: so if you specify "policy.yaml" in the config, but you have json, it will look for either? | 15:36 |
*** e0ne has quit IRC | 15:37 | |
mhen | gagehugo, that might actually be a bit problematic. I'd suggest only looking for json as well if 'policy_file' is not explicitly set at all in Cinder | 15:37 |
gagehugo | I believe if you don't specify a file most services use the default in-code policy | 15:38 |
mhen | from my experience, they will also load whatever is their default format if available | 15:39 |
mhen | so, if you place a '/etc/nova/policy.json' it will be loaded if existing even if the config entry isn't specified | 15:39 |
gagehugo | I know that the services all don't work the same, so that could very well be the case | 15:39 |
gagehugo | for some, but not others | 15:39 |
mhen | from a quick browse through the code, it seems both Glance and Keystone also use the oslo.config default setting which is json, which hints at Cinder possibly being the only one loading yaml per default | 15:41 |
mhen | gagehugo, you mean there are services which will not load any policy file at all unless specified in their config as 'policy_file = <path>'? | 15:42 |
gagehugo | mhen: I am not 100% sure, they're all different | 15:43 |
gagehugo | this was one of the pain-points about the policy-in-code movement iirc | 15:43 |
mhen | if that is true, the whole inconsistency situation is a lot worse than I thought :D | 15:44 |
gagehugo | I mean, we explicitly deploy with a custom policy file that we specify in each service's config | 15:44 |
gagehugo | what each service does for "default" behavior though, that's a good quesiton | 15:44 |
gagehugo | question* | 15:45 |
mhen | it's always better to define everything explicitly but sadly not everyone does that | 15:45 |
fungi | yeah, the desire with policy-in-code, if i understand correctly, is that shipping policy as configuration meant a lot of boilerplate users had to manage, so instead it should be possible to get a working deployment with no explicit policy configuration at all (relying on the implicit default policies provided by the services) | 15:45 |
mhen | having sane defaults helps a lot imo | 15:45 |
fungi | well, as does documenting what the explicit equivalent of the implicit defaults looks like | 15:46 |
mhen | sure | 15:46 |
*** jamesmcarthur has quit IRC | 15:46 | |
gagehugo | fungi: yes | 15:47 |
*** ociuhandu has quit IRC | 15:47 | |
*** dmacpher has quit IRC | 15:48 | |
*** priteau has joined #openstack-meeting | 15:50 | |
*** whoami-rajat has quit IRC | 15:51 | |
gagehugo | mhen: so I guess the path forward is to just keep this topic going, and follow up on nova/cinder for now | 15:52 |
mhen | gagehugo, agreed | 15:52 |
gagehugo | ok cool | 15:53 |
gagehugo | #topic open discussion | 15:53 |
*** openstack changes topic to "open discussion (Meeting topic: security)" | 15:53 | |
gagehugo | 7 minutes left, anyone have anything else? | 15:53 |
nickthetait | i do | 15:53 |
nickthetait | https://docs.openstack.org/security-guide/identity/tokens.html | 15:54 |
nickthetait | fernet tokens have been the default for a while now | 15:54 |
nickthetait | ok to delete any non-fernet stuff on that page? | 15:54 |
gagehugo | uh | 15:54 |
gagehugo | yes, but also add JWT tokens | 15:54 |
nickthetait | will do | 15:54 |
gagehugo | lemme grab a link here real quick | 15:54 |
*** moguimar has quit IRC | 15:55 | |
gagehugo | https://docs.openstack.org/keystone/stein/admin/tokens-overview.html#token-providers | 15:55 |
gagehugo | (we could just link to ^ as well) | 15:55 |
nickthetait | ok | 15:55 |
gagehugo | otherwise update the page with info from ^ | 15:56 |
gagehugo | if we are discussing tokens from a security perspective, rather than a deployment one | 15:56 |
nickthetait | yes exactly :) | 15:56 |
gagehugo | ok | 15:57 |
gagehugo | thanks everyone, have a good rest of the week + weekend | 15:57 |
gagehugo | #endmeeting | 15:57 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 15:58 | |
openstack | Meeting ended Thu Aug 1 15:57:59 2019 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:58 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/security/2019/security.2019-08-01-15.00.html | 15:58 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/security/2019/security.2019-08-01-15.00.txt | 15:58 |
mhen | thanks! | 15:58 |
openstack | Log: http://eavesdrop.openstack.org/meetings/security/2019/security.2019-08-01-15.00.log.html | 15:58 |
nickthetait | o/ | 15:58 |
*** armax has joined #openstack-meeting | 15:58 | |
*** rsimai is now known as rsimai_away | 16:03 | |
*** artom has quit IRC | 16:04 | |
*** nickthetait has left #openstack-meeting | 16:07 | |
*** igordc has joined #openstack-meeting | 16:08 | |
*** yaawang has quit IRC | 16:09 | |
*** yaawang has joined #openstack-meeting | 16:13 | |
*** lbragstad has quit IRC | 16:29 | |
*** artom has joined #openstack-meeting | 16:29 | |
*** yaawang has quit IRC | 16:30 | |
*** yaawang has joined #openstack-meeting | 16:32 | |
*** enriquetaso has quit IRC | 16:48 | |
*** igordc has quit IRC | 17:03 | |
*** priteau has quit IRC | 17:05 | |
*** electrofelix has quit IRC | 17:06 | |
*** bobh has joined #openstack-meeting | 17:11 | |
*** bobh has quit IRC | 17:11 | |
*** whoami-rajat has joined #openstack-meeting | 17:15 | |
*** raildo has quit IRC | 17:17 | |
*** ralonsoh has quit IRC | 17:20 | |
*** kopecmartin is now known as kopecmartin|off | 17:24 | |
*** igordc has joined #openstack-meeting | 17:27 | |
*** ricolin__ is now known as ricolin | 17:30 | |
*** igordc has quit IRC | 17:30 | |
*** slaweq has quit IRC | 17:42 | |
*** igordc has joined #openstack-meeting | 17:42 | |
*** ociuhandu has joined #openstack-meeting | 17:44 | |
*** enriquetaso has joined #openstack-meeting | 17:44 | |
*** senrique_ has joined #openstack-meeting | 17:47 | |
*** ociuhandu has quit IRC | 17:48 | |
*** enriquetaso has quit IRC | 17:49 | |
*** yamamoto has joined #openstack-meeting | 17:57 | |
*** slaweq has joined #openstack-meeting | 17:57 | |
*** senrique_ has quit IRC | 17:59 | |
*** yamamoto has quit IRC | 18:04 | |
*** jamesmcarthur has joined #openstack-meeting | 18:23 | |
*** eharney has quit IRC | 18:32 | |
*** eharney has joined #openstack-meeting | 18:36 | |
*** thgcorrea has quit IRC | 18:40 | |
*** diablo_rojo has joined #openstack-meeting | 18:43 | |
*** armstrong has joined #openstack-meeting | 18:50 | |
*** senrique_ has joined #openstack-meeting | 19:17 | |
*** tesseract has quit IRC | 19:23 | |
*** raildo has joined #openstack-meeting | 19:44 | |
*** raildo has quit IRC | 19:59 | |
*** senrique_ has quit IRC | 20:03 | |
*** radez has quit IRC | 20:03 | |
*** eharney has quit IRC | 20:03 | |
*** Luzi has joined #openstack-meeting | 20:06 | |
*** raildo has joined #openstack-meeting | 20:07 | |
*** jamesmcarthur has quit IRC | 20:16 | |
*** raildo has quit IRC | 20:24 | |
*** raildo has joined #openstack-meeting | 20:24 | |
*** diablo_rojo has quit IRC | 20:35 | |
*** e0ne has joined #openstack-meeting | 20:40 | |
*** efried has left #openstack-meeting | 20:49 | |
*** efried has joined #openstack-meeting | 20:49 | |
*** takashin has joined #openstack-meeting | 20:50 | |
efried | #startmeeting nova | 21:00 |
openstack | Meeting started Thu Aug 1 21:00:26 2019 UTC and is due to finish in 60 minutes. The chair is efried. Information about MeetBot at http://wiki.debian.org/MeetBot. | 21:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 21:00 |
*** openstack changes topic to " (Meeting topic: nova)" | 21:00 | |
openstack | The meeting name has been set to 'nova' | 21:00 |
takashin | o/ | 21:00 |
Luzi | O/ | 21:01 |
mriedem | . | 21:01 |
melwitt | o/ | 21:01 |
efried | #link agenda https://wiki.openstack.org/wiki/Meetings/Nova#Agenda_for_next_meeting | 21:02 |
efried | #topic Last meeting | 21:03 |
efried | #link Minutes from last meeting: http://eavesdrop.openstack.org/meetings/nova/2019/nova.2019-07-25-14.00.html | 21:03 |
*** openstack changes topic to "Last meeting (Meeting topic: nova)" | 21:03 | |
efried | action from last time | 21:03 |
efried | efried to (delegate or) ensure releases as appropriate for python-novaclient and os-vif | 21:03 |
efried | ✔ | 21:03 |
efried | other old business? | 21:04 |
efried | #topic Release News | 21:04 |
*** openstack changes topic to "Release News (Meeting topic: nova)" | 21:04 | |
efried | spec freeze exceptions will be discussed in opens | 21:05 |
efried | other release news? | 21:05 |
efried | #topic Bugs (stuck/critical) | 21:05 |
efried | No Critical bugs | 21:05 |
efried | #link 67 new untriaged bugs (-0 since the last meeting): https://bugs.launchpad.net/nova/+bugs?search=Search&field.status=New | 21:05 |
efried | #link 2 untagged untriaged bugs (-1 since the last meeting): https://bugs.launchpad.net/nova/+bugs?field.tag=-*&field.status%3Alist=NEW | 21:05 |
*** openstack changes topic to "Bugs (stuck/critical) (Meeting topic: nova)" | 21:05 | |
efried | anything on bugs? | 21:05 |
efried | #topic Gate status | 21:06 |
efried | #link check queue gate status http://status.openstack.org/elastic-recheck/index.html | 21:06 |
efried | #link 3rd party CI status (seems to be back in action) http://ciwatch.mmedvede.net/project?project=nova | 21:06 |
*** openstack changes topic to "Gate status (Meeting topic: nova)" | 21:06 | |
efried | #topic Reminders | 21:07 |
*** openstack changes topic to "Reminders (Meeting topic: nova)" | 21:07 | |
efried | any? | 21:07 |
mriedem | general reminder, | 21:07 |
mriedem | but if anyone wants to hack on compute osc gaps https://etherpad.openstack.org/p/compute-api-microversion-gap-in-osc | 21:07 |
mriedem | and want help or whatever ping me | 21:07 |
mriedem | i've been semi busy in osc lately | 21:07 |
efried | cool | 21:08 |
efried | #topic Stable branch status | 21:08 |
*** openstack changes topic to "Stable branch status (Meeting topic: nova)" | 21:08 | |
efried | #link stable/stein: https://review.openstack.org/#/q/status:open+(project:openstack/os-vif+OR+project:openstack/python-novaclient+OR+project:openstack/nova)+branch:stable/stein | 21:08 |
efried | #link stable/rocky: https://review.openstack.org/#/q/status:open+(project:openstack/os-vif+OR+project:openstack/python-novaclient+OR+project:openstack/nova)+branch:stable/rocky | 21:08 |
efried | #link stable/queens: https://review.openstack.org/#/q/status:open+(project:openstack/os-vif+OR+project:openstack/python-novaclient+OR+project:openstack/nova)+branch:stable/queens | 21:08 |
mriedem | quite a few stein and rocky changes just flushed this week | 21:08 |
mriedem | lots of rocky and queens yet | 21:09 |
efried | cool | 21:09 |
efried | #topic Sub/related team Highlights | 21:10 |
efried | Placement (cdent) | 21:10 |
efried | #link latest pupdate http://lists.openstack.org/pipermail/openstack-discuss/2019-July/008053.html | 21:10 |
*** openstack changes topic to "Sub/related team Highlights (Meeting topic: nova)" | 21:10 | |
efried | Pretty quiet in placement-land, at least for stuff nova cares about | 21:10 |
efried | API (gmann) | 21:11 |
efried | Did not push the updates on ML. Main updates are below: | 21:11 |
efried | 1. API cleanup code is ready for review and it is on runway. | 21:11 |
efried | 2. I am working on 'Default policy refresh' and making first API policies (os-services) seq of changes up. That will be used to get early feedback and direction we will follow for all the API policies. I should be ready with that by Monday. | 21:11 |
efried | Some followup nits of merged spec are fixed in this, need review on this spec-nits-update patch- https://review.opendev.org/#/c/669196/. | 21:11 |
efried | 3. There are few more API related BPs up for review or under review (you can fetch the links from API updates ML of last week). | 21:11 |
efried | (1st person above is gmann of course) | 21:11 |
efried | #topic Stuck Reviews | 21:11 |
*** openstack changes topic to "Stuck Reviews (Meeting topic: nova)" | 21:11 | |
efried | any? | 21:11 |
efried | #topic Review status page | 21:12 |
efried | #link http://status.openstack.org/reviews/#nova | 21:12 |
efried | Count: 461 (-1); Top score: 1352 (+21) | 21:12 |
efried | #help Pick a patch near the top, shepherd it to closure | 21:12 |
*** openstack changes topic to "Review status page (Meeting topic: nova)" | 21:12 | |
*** Lucas_Gray has joined #openstack-meeting | 21:13 | |
efried | #topic Open discussion | 21:13 |
efried | Train Spec Freeze Exception Process | 21:13 |
*** openstack changes topic to "Open discussion (Meeting topic: nova)" | 21:13 | |
efried | let's do | 21:13 |
efried | #link Nova Part of Image Encryption: https://review.opendev.org/#/c/608696 | 21:13 |
efried | first since Luzi is here | 21:13 |
efried | Luzi: your mic | 21:13 |
Luzi | hi o/ | 21:13 |
Luzi | first: I answered mriedem's questions - it's a good thing to add a trait - i also read your comment efried | 21:14 |
Luzi | mriedem, was that (trait and upgrade) your only concerns? | 21:15 |
mriedem | my main concerns were around handling upgrades and support for non-libvirt computes | 21:15 |
mriedem | i think the trait solves that | 21:15 |
mriedem | trait + some request filter thing | 21:16 |
mriedem | as for the rest, johnthetubaguy and dansmith were most vocal in the forum session from the nova team from what i remember so i'll defer to them on whether or not this should be an exception for train | 21:16 |
Luzi | yes trait + filter, I would add this to the spec | 21:16 |
mriedem | it also depends on the glance and cinder stuff getting done right? or at least glance/barbican? | 21:16 |
Luzi | the cinder spec is merged | 21:16 |
mriedem | sure, but that doesn't mean the code is going to make train | 21:17 |
Luzi | and barbican is working on the secret consumer API | 21:17 |
mriedem | iow, this smells like backlog for U to me, but i'm not blocking it | 21:17 |
mriedem | and like i said i'll defer to john and dan | 21:17 |
efried | mriedem: How long should we be waiting for johnthetubaguy and dansmith to respond? | 21:17 |
mriedem | dan is out this week, and i wouldn't expect him to want to jump on this post-spec freeze first thing when he's back next week (if at all) | 21:18 |
mriedem | john....idk, he's streaky | 21:18 |
mriedem | dragging FFEs past the deadline also sucks | 21:18 |
*** senrique_ has joined #openstack-meeting | 21:18 | |
mriedem | b/c why have a deadline. | 21:18 |
efried | Well | 21:18 |
efried | imo it's for things like this that were really close and just needed a little push over the edge | 21:18 |
mriedem | well i guess i'd try to get dan to take a look by end of next week | 21:19 |
mriedem | once the upgrade related stuff and non-libvirt considerations are written up | 21:19 |
efried | to me, this is a pretty small an non-invasive effort, and obviously the deps have to be met or it won't go, but that's not on us. | 21:19 |
efried | okay, wfm | 21:19 |
mriedem | "small an non-invasive effort" famous last words | 21:19 |
efried | I know, I know. | 21:20 |
mriedem | anything involve multiple nova services let alone multiple openstack services is not small.... | 21:20 |
mriedem | like i said i'm not blocking | 21:20 |
efried | Point is, if all the other stars align, it would suck for it to not make Train purely because "we didn't get the spec approved by the freeze date". | 21:20 |
efried | I would rather punt an approved spec to U | 21:21 |
mriedem | i don't disagree | 21:21 |
mordred | I agree with everything | 21:21 |
mriedem | don't want this to become another john hopkins trusted certs thing | 21:21 |
mriedem | which they pushed for 4 releases or something, landed a thing and then lost their grant and moved on | 21:21 |
mriedem | so who knows if anyone is using ^ or it works anymore | 21:22 |
efried | so okay, we have a plan: | 21:22 |
efried | #action Luzi to update spec per comments | 21:22 |
efried | #action dansmith (and if possible johnthetubaguy) to review and make a call by end of next week | 21:22 |
efried | mriedem is +0 and I'm in favor, so whatever Dan (& John) say goes. | 21:22 |
efried | melwitt: do you have an opinion? | 21:22 |
* mriedem puts curmudgeon pin away | 21:22 | |
efried | since you're the other core in the room? | 21:23 |
melwitt | not really, I haven't been through that spec | 21:23 |
efried | Okay. | 21:23 |
mriedem | would be cool if mnaser et al ops could read it, | 21:23 |
mriedem | since in berlin there was a session about encrypted * and this was one of the items | 21:23 |
mriedem | total hands off user encrypted images | 21:23 |
efried | I added mnaser to the review | 21:24 |
efried | Luzi: Anything else to bring up before we move on? | 21:24 |
Luzi | no | 21:24 |
efried | okay, next: | 21:24 |
efried | #link Use PCPU and VCPU in One Instance: https://review.opendev.org/#/c/668656/ | 21:24 |
mriedem | this came in pretty late | 21:25 |
mriedem | july 2 | 21:25 |
efried | Where we're at on this one is that stephenfin and sean (and we think alex) have agreed on the approach | 21:26 |
efried | and have come up with and documented in the | 21:26 |
efried | #link blueprint https://blueprints.launchpad.net/nova/+spec/use-pcpu-and-vcpu-in-one-instance | 21:26 |
efried | a set of provisos/conditions that must be met | 21:26 |
efried | obviously it's got a hard dep on cpu-resources; ^ states that that must be done a couple weeks before feature freeze or this one dies. | 21:27 |
mriedem | but neither of them have voted on it | 21:28 |
mriedem | at least the latest | 21:28 |
efried | no, it was just updated | 21:28 |
efried | ...per guidance from Stephen & Sean. | 21:29 |
mriedem | i haven't read it in detail nor would i probably grok it | 21:29 |
mriedem | so i'll defer to dan (again) | 21:29 |
mriedem | and he'll ugh it all day long probably | 21:29 |
efried | Was Dan invoved on the cpu-resources work? | 21:29 |
mriedem | pretty sure he was involved in the shape of that spec | 21:29 |
mriedem | at least when jay was involved | 21:29 |
efried | I don't see him involved in that spec review other than one comment back in April. | 21:31 |
mriedem | plus irc, | 21:31 |
mriedem | plus ptg/summit | 21:31 |
mriedem | whatever, anyway, if you ask me i'll say goto dansmith | 21:31 |
mriedem | and he'll probably say goto /dev/null | 21:31 |
mriedem | but he can speak for himself when he's back :) | 21:32 |
efried | Okay. | 21:32 |
efried | I should probably recuse myself here because a) I don't understand the technical side very well, and b) this is an Intel ask. | 21:32 |
efried | so if you're punting, then I guess | 21:33 |
efried | #action dansmith to decide on all the things next week. | 21:33 |
efried | Any other open discussion before we blow this popsicle stand? | 21:33 |
melwitt | I have a thing | 21:33 |
efried | hit it | 21:33 |
melwitt | would like for ppl to look over https://blueprints.launchpad.net/nova/+spec/policy-rule-for-host-status-unknown and let me know if they think it still needs a spec or not | 21:34 |
efried | Heh. Spec freeze exception by killing spec. | 21:34 |
melwitt | because the original proposal evolved into a policy rule thing and I have seen us do new policy rules as wishlist bug before | 21:34 |
melwitt | haha, yeah. I'm not getting my hopes up but wanted to throw it out there, in case it is no longer spec worthy | 21:35 |
efried | oh, this one | 21:35 |
melwitt | so if anyone has feedback about that, let me know. doesn't have to be right now | 21:35 |
mriedem | you mean like https://review.opendev.org/#/c/526558/ | 21:35 |
melwitt | yeah that's the example I was thinking about | 21:35 |
efried | I thought this one was under debate for reasons of "do we really want to expose UNKNOWN" | 21:36 |
mriedem | this is different | 21:36 |
mriedem | this is expose host_status but only if UNKNOWN | 21:36 |
melwitt | the debate was about overwriting the cosmetic instance "status" | 21:36 |
mriedem | not change server status to UNKNOWN if host_status is UNKNOWN | 21:36 |
melwitt | right | 21:36 |
mriedem | which is much more targeted | 21:36 |
efried | is there code for this? | 21:37 |
melwitt | no but there can be. I didn't do anything yet | 21:37 |
mriedem | i'm not against this, | 21:37 |
melwitt | the only potentially weird area on this one is, what to show if host_status it not UNKNOWN. I was thinking empty string rather than omitting the field | 21:38 |
efried | no microversion right? | 21:38 |
mriedem | i think the proposed policy rule needs to conform to the new standards but that's impl details | 21:38 |
mriedem | i also have performance concerns when listing servers, but that's impl | 21:38 |
melwitt | no microversion | 21:38 |
mriedem | if you're adding a new field to the response by default that's a change | 21:38 |
mriedem | host_status was new in 2.16 from what i remember | 21:38 |
mriedem | yup (man my long term memory is outstanding) | 21:39 |
*** artom has quit IRC | 21:39 | |
mriedem | so would it only show up if >= 2.16 and policy passes? | 21:39 |
melwitt | by default for whom? I mean, host_status is there for admins by default. are you saying making it be there by default for non admins would be considered an API change? | 21:39 |
melwitt | yeah | 21:39 |
mriedem | i meant regardless of microversion | 21:40 |
mriedem | if you're >= 2.16 then that's less of an issue | 21:40 |
mriedem | idk about just returning an empty string | 21:40 |
melwitt | oh. yeah, when I said no microversion I meant not adding a new microversion for this | 21:40 |
mriedem | we have some apis that don't return fields based on policy | 21:41 |
melwitt | yeah, I'm not sure either. I was thinking it might be weird to return the field only if it is UNKNOWN | 21:41 |
mriedem | if only there were a spec to discuss this in review.... | 21:41 |
melwitt | because that is not really based on policy. it would be unpredictable | 21:41 |
melwitt | ok, guess that answers my question | 21:41 |
mriedem | well, | 21:41 |
efried | gibi is back next week too, and it was based on his feedback that the latest PS was pushed, yah? | 21:42 |
mriedem | this would be unpredictable w/o a microversion depending on which cloud you're talking to anyway | 21:42 |
mriedem | the docs say, "This attribute appears in the response only if the policy permits." | 21:42 |
mriedem | so i think that means it's cool to not show it if you don't pass policy | 21:42 |
mriedem | and if you do pass policy but the value is not UNKNOWN, we still don't show it | 21:42 |
melwitt | ok, if that is kosher, then that would be easier for me | 21:43 |
mriedem | either way the client needs to handle it | 21:43 |
mriedem | i can leave some comments on the bp whiteboard | 21:43 |
melwitt | thanks | 21:43 |
efried | are we done then? | 21:44 |
melwitt | yeah, I think I'm good | 21:44 |
efried | Okay. Thanks all | 21:44 |
efried | o/ | 21:44 |
efried | #endmeeting | 21:44 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 21:44 | |
openstack | Meeting ended Thu Aug 1 21:44:58 2019 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 21:45 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/nova/2019/nova.2019-08-01-21.00.html | 21:45 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/nova/2019/nova.2019-08-01-21.00.txt | 21:45 |
openstack | Log: http://eavesdrop.openstack.org/meetings/nova/2019/nova.2019-08-01-21.00.log.html | 21:45 |
*** takashin has left #openstack-meeting | 21:45 | |
*** Luzi has quit IRC | 21:46 | |
*** mriedem has quit IRC | 21:53 | |
*** slaweq has quit IRC | 22:10 | |
*** senrique_ has quit IRC | 22:10 | |
*** slaweq has joined #openstack-meeting | 22:11 | |
*** slaweq has quit IRC | 22:16 | |
*** diablo_rojo has joined #openstack-meeting | 22:21 | |
*** patrickeast_ has joined #openstack-meeting | 22:29 | |
*** jamespage_ has joined #openstack-meeting | 22:29 | |
*** dustinc_ has joined #openstack-meeting | 22:29 | |
*** mnasiadka_ has joined #openstack-meeting | 22:30 | |
*** kmalloc_ has joined #openstack-meeting | 22:30 | |
*** patrickeast has quit IRC | 22:37 | |
*** mordred has quit IRC | 22:37 | |
*** mnasiadka has quit IRC | 22:37 | |
*** jamespage has quit IRC | 22:37 | |
*** kmalloc has quit IRC | 22:37 | |
*** dustinc has quit IRC | 22:37 | |
*** patrickeast_ is now known as patrickeast | 22:37 | |
*** mnasiadka_ is now known as mnasiadka | 22:37 | |
*** kmalloc_ is now known as kmalloc | 22:37 | |
*** jamespage_ is now known as jamespage | 22:37 | |
*** dustinc_ is now known as dustinc | 22:37 | |
*** panda has quit IRC | 22:41 | |
*** panda has joined #openstack-meeting | 22:42 | |
*** mordred has joined #openstack-meeting | 22:44 | |
*** e0ne_ has joined #openstack-meeting | 22:45 | |
*** e0ne has quit IRC | 22:46 | |
*** e0ne has joined #openstack-meeting | 22:47 | |
*** e0ne_ has quit IRC | 22:50 | |
*** e0ne has quit IRC | 22:52 | |
*** whoami-rajat has quit IRC | 22:55 | |
*** bbowen has quit IRC | 23:06 | |
*** igordc has quit IRC | 23:10 | |
*** ianychoi has quit IRC | 23:12 | |
*** rcernin has joined #openstack-meeting | 23:21 | |
*** ykatabam has joined #openstack-meeting | 23:25 | |
*** sfernand has quit IRC | 23:51 | |
*** artom has joined #openstack-meeting | 23:52 | |
*** trident has quit IRC | 23:54 | |
*** diablo_rojo is now known as diablo_rojo_ | 23:56 | |
*** diablo_rojo_ is now known as diablo__rojo_ | 23:56 | |
*** diablo__rojo_ is now known as diablo_rojoooooo | 23:57 | |
*** diablo_rojoooooo is now known as diablo_rojo | 23:57 | |
*** trident has joined #openstack-meeting | 23:59 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!