*** eharney has quit IRC | 00:06 | |
*** eharney has joined #openstack-meeting | 00:18 | |
*** ijw_ has joined #openstack-meeting | 00:20 | |
*** gyee has quit IRC | 00:22 | |
*** tetsuro has quit IRC | 00:23 | |
*** ijw has quit IRC | 00:23 | |
*** ijw_ has quit IRC | 00:24 | |
*** markvoelker has joined #openstack-meeting | 00:26 | |
*** brinzhang has joined #openstack-meeting | 00:28 | |
*** markvoelker has quit IRC | 00:30 | |
*** enriquetaso has quit IRC | 00:47 | |
*** larainema has joined #openstack-meeting | 01:01 | |
*** slaweq has joined #openstack-meeting | 01:11 | |
*** slaweq has quit IRC | 01:15 | |
*** jamesmcarthur has joined #openstack-meeting | 01:17 | |
*** markvoelker has joined #openstack-meeting | 01:25 | |
*** markvoelker has quit IRC | 01:30 | |
*** zhubx has quit IRC | 01:41 | |
*** zhubx has joined #openstack-meeting | 01:41 | |
*** zhubx has quit IRC | 01:42 | |
*** zhubx has joined #openstack-meeting | 01:42 | |
*** ricolin has joined #openstack-meeting | 01:48 | |
*** jamesmcarthur has quit IRC | 01:48 | |
*** jamesmcarthur has joined #openstack-meeting | 01:49 | |
*** jamesmcarthur has quit IRC | 01:49 | |
*** jamesmcarthur has joined #openstack-meeting | 01:49 | |
*** ricolin has quit IRC | 02:04 | |
*** ricolin has joined #openstack-meeting | 02:05 | |
*** jamesmcarthur has quit IRC | 02:06 | |
*** ekcs has quit IRC | 02:06 | |
*** apetrich has quit IRC | 02:10 | |
*** slaweq has joined #openstack-meeting | 02:12 | |
*** slaweq has quit IRC | 02:16 | |
*** jamesmcarthur has joined #openstack-meeting | 02:18 | |
*** ricolin has quit IRC | 02:32 | |
*** brault has joined #openstack-meeting | 02:32 | |
*** ricolin has joined #openstack-meeting | 02:32 | |
*** brault has quit IRC | 02:36 | |
*** jamesmcarthur has quit IRC | 02:37 | |
*** jamesmcarthur has joined #openstack-meeting | 02:49 | |
*** jamesmcarthur has quit IRC | 02:59 | |
*** zhubx has quit IRC | 03:05 | |
*** zhubx has joined #openstack-meeting | 03:05 | |
*** psachin has joined #openstack-meeting | 03:10 | |
*** ykatabam has quit IRC | 03:13 | |
*** rcernin has quit IRC | 03:13 | |
*** ricolin has quit IRC | 03:21 | |
*** yaawang has quit IRC | 03:26 | |
*** yaawang has joined #openstack-meeting | 03:27 | |
*** ykatabam has joined #openstack-meeting | 04:03 | |
*** rcernin has joined #openstack-meeting | 04:05 | |
*** slaweq has joined #openstack-meeting | 04:11 | |
*** slaweq has quit IRC | 04:16 | |
*** jamesmcarthur has joined #openstack-meeting | 05:00 | |
*** jamesmcarthur has quit IRC | 05:04 | |
*** Luzi has joined #openstack-meeting | 05:05 | |
*** zhubx has quit IRC | 05:16 | |
*** boxiang has joined #openstack-meeting | 05:17 | |
*** boxiang has quit IRC | 05:20 | |
*** boxiang has joined #openstack-meeting | 05:21 | |
*** markvoelker has joined #openstack-meeting | 05:31 | |
*** markvoelker has quit IRC | 05:36 | |
*** boxiang has quit IRC | 05:45 | |
*** boxiang has joined #openstack-meeting | 05:46 | |
*** boxiang has quit IRC | 05:47 | |
*** boxiang has joined #openstack-meeting | 05:48 | |
*** rcernin_ has joined #openstack-meeting | 05:52 | |
*** pwu has joined #openstack-meeting | 05:54 | |
*** rcernin has quit IRC | 05:55 | |
*** ykatabam has quit IRC | 05:57 | |
*** ykatabam has joined #openstack-meeting | 06:03 | |
*** slaweq has joined #openstack-meeting | 06:11 | |
*** slaweq has quit IRC | 06:16 | |
*** zhubx has joined #openstack-meeting | 06:16 | |
*** boxiang has quit IRC | 06:16 | |
*** zhubx has quit IRC | 06:19 | |
*** zhubx has joined #openstack-meeting | 06:19 | |
*** lpetrut has joined #openstack-meeting | 06:20 | |
*** zhubx has quit IRC | 06:20 | |
*** boxiang has joined #openstack-meeting | 06:21 | |
*** markvoelker has joined #openstack-meeting | 06:31 | |
*** markvoelker has quit IRC | 06:36 | |
*** pwu has quit IRC | 06:37 | |
*** brault has joined #openstack-meeting | 06:37 | |
*** ricolin has joined #openstack-meeting | 06:38 | |
*** brault has quit IRC | 06:40 | |
*** brault has joined #openstack-meeting | 06:40 | |
*** ircuser-1 has quit IRC | 06:44 | |
*** ircuser-1 has joined #openstack-meeting | 06:47 | |
*** slaweq has joined #openstack-meeting | 06:58 | |
*** _pewp_ has quit IRC | 07:11 | |
*** _pewp_ has joined #openstack-meeting | 07:12 | |
*** ykatabam has quit IRC | 07:26 | |
*** slaweq has quit IRC | 07:27 | |
*** jbadiapa has joined #openstack-meeting | 07:28 | |
*** slaweq has joined #openstack-meeting | 07:31 | |
*** apetrich has joined #openstack-meeting | 07:37 | |
*** rcernin_ has quit IRC | 07:40 | |
*** trident has quit IRC | 07:40 | |
*** trident has joined #openstack-meeting | 07:49 | |
*** priteau has joined #openstack-meeting | 07:54 | |
*** rcernin_ has joined #openstack-meeting | 07:58 | |
*** ralonsoh has joined #openstack-meeting | 08:04 | |
*** lpetrut has quit IRC | 08:08 | |
*** markvoelker has joined #openstack-meeting | 08:10 | |
*** e0ne has joined #openstack-meeting | 08:11 | |
*** markvoelker has quit IRC | 08:15 | |
*** e0ne has quit IRC | 08:20 | |
*** e0ne has joined #openstack-meeting | 08:34 | |
*** brinzhang has quit IRC | 08:36 | |
*** brinzhang has joined #openstack-meeting | 08:37 | |
*** e0ne has quit IRC | 08:59 | |
*** e0ne has joined #openstack-meeting | 09:27 | |
*** e0ne has quit IRC | 09:27 | |
*** apetrich has quit IRC | 09:47 | |
*** radeks has joined #openstack-meeting | 10:09 | |
*** markvoelker has joined #openstack-meeting | 10:11 | |
*** radeks_ has joined #openstack-meeting | 10:14 | |
*** radeks has quit IRC | 10:16 | |
*** markvoelker has quit IRC | 10:20 | |
*** e0ne has joined #openstack-meeting | 10:21 | |
*** e0ne has quit IRC | 10:27 | |
*** jawad_axd has joined #openstack-meeting | 10:29 | |
*** apetrich has joined #openstack-meeting | 10:44 | |
*** radeks_ has quit IRC | 10:51 | |
*** carloss has joined #openstack-meeting | 10:53 | |
*** radeks has joined #openstack-meeting | 10:53 | |
*** radeks has quit IRC | 10:58 | |
*** e0ne has joined #openstack-meeting | 11:00 | |
*** tesseract has joined #openstack-meeting | 11:15 | |
*** zhubx has joined #openstack-meeting | 11:16 | |
*** radeks has joined #openstack-meeting | 11:17 | |
*** boxiang has quit IRC | 11:18 | |
*** Lucas_Gray has joined #openstack-meeting | 11:19 | |
*** e0ne has quit IRC | 11:20 | |
*** e0ne has joined #openstack-meeting | 11:23 | |
*** lpetrut has joined #openstack-meeting | 11:24 | |
*** lpetrut has quit IRC | 11:30 | |
*** e0ne has quit IRC | 11:32 | |
*** brault has quit IRC | 11:37 | |
*** dviroel has joined #openstack-meeting | 11:38 | |
*** e0ne has joined #openstack-meeting | 11:40 | |
*** Lucas_Gray has quit IRC | 11:45 | |
*** zhubx has quit IRC | 11:50 | |
*** njohnston has joined #openstack-meeting | 12:00 | |
*** brault has joined #openstack-meeting | 12:03 | |
*** markvoelker has joined #openstack-meeting | 12:10 | |
*** e0ne has quit IRC | 12:11 | |
*** markvoelker has quit IRC | 12:16 | |
*** apetrich has quit IRC | 12:16 | |
*** rfolco has joined #openstack-meeting | 12:28 | |
*** larainema has quit IRC | 12:32 | |
*** markvoelker has joined #openstack-meeting | 12:38 | |
*** Lucas_Gray has joined #openstack-meeting | 12:40 | |
*** markvoelker has quit IRC | 12:42 | |
*** Luzi has quit IRC | 12:44 | |
*** markvoelker has joined #openstack-meeting | 12:44 | |
*** markvoelker has quit IRC | 12:44 | |
*** markvoelker has joined #openstack-meeting | 12:45 | |
*** lpetrut has joined #openstack-meeting | 12:52 | |
*** panda|rover|off is now known as panda|rover | 12:53 | |
*** enriquetaso has joined #openstack-meeting | 13:00 | |
*** mriedem has joined #openstack-meeting | 13:07 | |
*** zbr has quit IRC | 13:08 | |
*** zbr has joined #openstack-meeting | 13:16 | |
*** apetrich has joined #openstack-meeting | 13:23 | |
*** baojg has quit IRC | 13:27 | |
*** kaisers has quit IRC | 13:29 | |
*** dklyle has quit IRC | 13:35 | |
*** dklyle has joined #openstack-meeting | 13:35 | |
*** priteau has quit IRC | 13:35 | |
*** e0ne has joined #openstack-meeting | 13:40 | |
*** rcernin_ has quit IRC | 13:41 | |
*** e0ne has quit IRC | 13:43 | |
*** AlanClark has joined #openstack-meeting | 13:46 | |
*** hongbin has joined #openstack-meeting | 13:48 | |
*** lpetrut has quit IRC | 13:51 | |
*** zbitter has quit IRC | 13:53 | |
*** zbitter has joined #openstack-meeting | 13:54 | |
*** rcernin_ has joined #openstack-meeting | 13:56 | |
*** jawad_axd has quit IRC | 13:56 | |
*** mordred has quit IRC | 13:57 | |
*** d34dh0r53 has quit IRC | 13:57 | |
*** jawad_axd has joined #openstack-meeting | 13:57 | |
*** jawad_axd has quit IRC | 13:57 | |
*** jawad_axd has joined #openstack-meeting | 13:58 | |
*** mordred has joined #openstack-meeting | 13:59 | |
*** jawad_ax_ has joined #openstack-meeting | 14:00 | |
*** d34dh0r53 has joined #openstack-meeting | 14:01 | |
*** jawad_axd has quit IRC | 14:02 | |
*** jawad_ax_ has quit IRC | 14:04 | |
*** jawad_axd has joined #openstack-meeting | 14:09 | |
*** jawad_axd has quit IRC | 14:13 | |
*** davee_ has quit IRC | 14:22 | |
*** e0ne has joined #openstack-meeting | 14:22 | |
*** Lucas_Gray has quit IRC | 14:32 | |
*** Wryhder has joined #openstack-meeting | 14:32 | |
*** Wryhder is now known as Lucas_Gray | 14:33 | |
*** Lucas_Gray has quit IRC | 14:35 | |
*** jamesmcarthur has joined #openstack-meeting | 14:42 | |
*** AlanClark has quit IRC | 14:45 | |
*** AlanClark has joined #openstack-meeting | 14:45 | |
*** jbadiapa has quit IRC | 14:47 | |
*** nickthetait has joined #openstack-meeting | 14:52 | |
*** mhen has joined #openstack-meeting | 14:52 | |
*** gagehugo has joined #openstack-meeting | 14:57 | |
*** jbadiapa has joined #openstack-meeting | 15:00 | |
gagehugo | #startmeeting security | 15:00 |
---|---|---|
openstack | Meeting started Thu Aug 29 15:00:48 2019 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:00 |
*** openstack changes topic to " (Meeting topic: security)" | 15:00 | |
openstack | The meeting name has been set to 'security' | 15:00 |
gagehugo | #link https://etherpad.openstack.org/p/security-agenda agenda | 15:01 |
gagehugo | o/ | 15:01 |
mhen | o/ | 15:01 |
nickthetait | hi hi | 15:01 |
nickthetait | ahem | 15:01 |
nickthetait | o/ | 15:01 |
*** diablo_rojo has joined #openstack-meeting | 15:01 | |
* fungi is half-here | 15:01 | |
*** AlanClark has quit IRC | 15:02 | |
*** AlanClark has joined #openstack-meeting | 15:02 | |
gagehugo | #topic OSSA-2019-004 | 15:03 |
*** openstack changes topic to "OSSA-2019-004 (Meeting topic: security)" | 15:03 | |
gagehugo | #link https://security.openstack.org/ossa/OSSA-2019-004.html | 15:03 |
gagehugo | Hot off the press | 15:04 |
gagehugo | thanks fungi for handling that | 15:04 |
fungi | no sweat | 15:05 |
*** baojg has joined #openstack-meeting | 15:05 | |
fungi | the public workflow is a lot easier than dealing with embargoes ;) | 15:05 |
nickthetait | for sure! | 15:06 |
fungi | note that deliverable technically isn't vulnerability:managed | 15:06 |
fungi | but handling it was related to a wip governance change i've proposed | 15:07 |
fungi | Update vulnerability:managed policy | 15:07 |
*** jamesmcarthur has quit IRC | 15:07 | |
fungi | er... | 15:07 |
fungi | note that deliverable technically isn't vulnerability:managed | 15:07 |
fungi | #link https://review.opendev.org/678426 Update vulnerability:managed policy | 15:07 |
*** jamesmcarthur has joined #openstack-meeting | 15:07 | |
fungi | clearly i'm not as thoroughly caffeinated as i should be | 15:07 |
* nickthetait takes a sip of tea | 15:08 | |
fungi | anyway, feedback is encouraged on that since it's a bit of a paradigm shift in how the openstack vmt has been operating for a number of years | 15:08 |
nickthetait | what is the change in process? | 15:09 |
fungi | it's more of a change in policy | 15:09 |
fungi | summary is: turn the risk assessment requirement into more of a recommendation, but also lower the number of embargoed bugs the vmt needs to track by setting a hard limit on how long a report can remain private | 15:10 |
nickthetait | ok that sounds sensible | 15:10 |
fungi | also clarifies that extended-maintenance branches are "best effort" | 15:10 |
fungi | and that the vmt doesn't track or publish advisories about software components which might be included in release artifacts but which are not themselves written by openstack | 15:11 |
fungi | (for example, vulnerable glibc in a kolla image) | 15:11 |
*** jawad_axd has joined #openstack-meeting | 15:11 | |
nickthetait | I'll commit to doing a full review of that today | 15:13 |
*** e0ne has quit IRC | 15:14 | |
fungi | yeah, the only major changes are the risk assessment and the max embargo period, the rest are just clarifications | 15:16 |
*** jawad_axd has quit IRC | 15:16 | |
gagehugo | cool | 15:18 |
gagehugo | #topic Open Discussion | 15:18 |
*** openstack changes topic to "Open Discussion (Meeting topic: security)" | 15:18 | |
gagehugo | Floor is open if anyone has anything | 15:18 |
nickthetait | I have good news :D | 15:18 |
* fungi braces for good news | 15:18 | |
gagehugo | good news is always good | 15:18 |
nickthetait | https://docs.openstack.org/security-guide/ now says "last updated during Train" | 15:18 |
nickthetait | landed at like 5am today hehe | 15:19 |
nickthetait | a few other major changes were merged yesterday too | 15:19 |
gagehugo | yup, a lot of good cleanup has gone in | 15:19 |
gagehugo | thanks for doing all those nickthetait | 15:19 |
nickthetait | yep! | 15:19 |
nickthetait | two other minor ones waiting on reviews | 15:20 |
nickthetait | #link https://review.opendev.org/#/c/677494/ | 15:20 |
nickthetait | #link https://review.opendev.org/#/c/677513/ | 15:20 |
nickthetait | Also have a question about this | 15:22 |
nickthetait | #link https://bugs.launchpad.net/ossp-security-documentation/+bug/1703353 | 15:22 |
openstack | Launchpad bug 1703353 in OpenStack Security Guide Documentation "Need sections on api audit / cadf" [High,Confirmed] | 15:22 |
nickthetait | is it still relevant/needed | 15:22 |
nickthetait | I'm not clear on what content it is asking for | 15:22 |
gagehugo | sure | 15:22 |
gagehugo | lemme find some links | 15:23 |
gagehugo | (as someone who's org uses cadf) I'd say sure it's relevant | 15:23 |
nickthetait | :) | 15:25 |
gagehugo | #link https://www.dmtf.org/standards/cadf | 15:25 |
gagehugo | there's some specs on CADF itself (only 183 pages) | 15:25 |
gagehugo | and the audit middleware is good too | 15:26 |
gagehugo | #link https://docs.openstack.org/keystonemiddleware/latest/audit.html | 15:26 |
gagehugo | and keystone has a page that dives into more details about the event notifications themselves | 15:27 |
gagehugo | #link https://docs.openstack.org/keystone/latest/admin/event_notifications.html | 15:27 |
gagehugo | nickthetait: have you configured event notifications for openstack before? | 15:28 |
nickthetait | i sure haven't | 15:28 |
gagehugo | I can help out with that one, I've done it for our cloud | 15:28 |
nickthetait | this would be a new page under the compliance chapter? | 15:28 |
gagehugo | either that, or monitoring and logging | 15:29 |
nickthetait | ok | 15:29 |
*** jbadiapa has quit IRC | 15:30 | |
gagehugo | as CADF events are notifications from events in openstack (project create, user auth, server create, etc.) | 15:30 |
nickthetait | gotcha | 15:31 |
nickthetait | well thats it from me | 15:31 |
gagehugo | nickthetait: I'll see if I can throw something together for that | 15:32 |
gagehugo | imo it would be good to have a guide on how to do it, I had to wing it myself and I wish I had a clearer guide | 15:32 |
nickthetait | throw a comment on that bug and I'll work my magic and turn it into documentation | 15:33 |
gagehugo | will do | 15:33 |
gagehugo | #action: gagehugo to leave a comment on https://bugs.launchpad.net/ossp-security-documentation/+bug/1703353 | 15:33 |
openstack | Launchpad bug 1703353 in OpenStack Security Guide Documentation "Need sections on api audit / cadf" [High,Confirmed] | 15:33 |
gagehugo | anything else? | 15:34 |
mhen | I've got another small topic I'd want to address | 15:34 |
mhen | sorry, I haven't been able to attend the last two meetings | 15:35 |
gagehugo | mhen: sure! | 15:35 |
gagehugo | the last couple meetings were fairly non-existant so no worries | 15:35 |
mhen | but I started a discussion before about Cinder suddenly deciding to change the policy format standard | 15:35 |
mhen | was there any update on that so far? | 15:35 |
gagehugo | mhen: I still have a sticky note on my monitor to dig into that | 15:35 |
gagehugo | no update yet, sorry | 15:36 |
mhen | no problem | 15:36 |
gagehugo | it's on my todo list though :) | 15:36 |
mhen | today I happened to notice that Cinder still used .json in Pike | 15:36 |
mhen | but changed it in Queens | 15:36 |
mhen | and so far it still seems to be the only one | 15:36 |
gagehugo | hmm ok | 15:36 |
nickthetait | what format is it changing to? | 15:36 |
mhen | .yaml | 15:36 |
nickthetait | ah | 15:36 |
mhen | it overrides oslo_policy's default | 15:36 |
mhen | which no other OpenStack service does currently afaik | 15:37 |
mhen | so, any expectation about services behaving consistently is now broken | 15:37 |
gagehugo | There was an effort to move all policy files to yaml (for comment support), but it seems that multiple projects are inconsistent about describing that they support | 15:37 |
nickthetait | ugh messy | 15:37 |
mhen | biggest problem is, services ignore any format that is not the default | 15:38 |
mhen | *their defaut ;) | 15:38 |
mhen | *default | 15:38 |
mhen | jeez | 15:38 |
mhen | :D | 15:38 |
nickthetait | hehe | 15:38 |
*** bcafarel has quit IRC | 15:38 | |
mhen | had this again today, an infrastructure upgraded from Pike to Queens and then things started to break because the policy file for Cinder (previously working .json) was now ignored | 15:39 |
fungi | any idea if that has improved since queens? | 15:41 |
fungi | we've had two more releases since then and are about to have another | 15:41 |
mhen | last time I checked (2 weeks ago), the master branch still had the same overriding code in Cinder | 15:41 |
mhen | #link https://github.com/openstack/cinder/blob/master/cinder/policy.py#L31 | 15:42 |
mhen | compare to | 15:42 |
mhen | #link https://github.com/openstack/cinder/blob/stable/pike/cinder/policy.py#L26 | 15:42 |
gagehugo | It looks like it's an issue when upgrading and there not being clear direction that your policies will suddenly start getting ignored because they're not the correct file format, when it worked fine previous release | 15:43 |
mhen | exactly | 15:43 |
gagehugo | and some services work, and others don't | 15:43 |
smcginnis | It could have been better, but that was documented in the upgrade notes: https://docs.openstack.org/releasenotes/cinder/queens.html#upgrade-notes | 15:44 |
* fungi wonders if folks don't read upgrade notes when upgrading | 15:44 | |
smcginnis | Usually not. ;) | 15:44 |
gagehugo | "The sample file is YAML (because unlike JSON, YAML allows comments). If you prefer, you may use a JSON policy file." | 15:46 |
gagehugo | I assume you need to specify your policy file though | 15:46 |
smcginnis | "The policy file to be used may be specified in the /etc/cinder/cinder.conf" | 15:46 |
nickthetait | well thats annoying but not unfixable for an operator | 15:46 |
mhen | if you wanna use .json, you have to set 'policy_file' in the config starting with Queens | 15:46 |
fungi | ahh, so it does continue to support json, you just need to add a config line | 15:48 |
mhen | yes | 15:48 |
fungi | and i guess the upgrade notes weren't clear enough on that point | 15:48 |
nickthetait | so the line smcginnis quoted should really say "starting with Queens if you want to use .json, you must set 'policy_file' in /etc/cinder/cinder.conf"? | 15:48 |
smcginnis | Well, .json or whatever other file you want to use other than the default. | 15:49 |
nickthetait | "Starting with Queens .yaml is the default format. If you want to use any other format you must set 'policy_file' in /etc/cinder/cinder.conf" | 15:50 |
gagehugo | I assume the nova issue you saw mhen might be similar | 15:51 |
mhen | yes, it's imply vice versa, defaulting to .json - ignoring .yaml | 15:51 |
mhen | I just mentioned it as a comparison | 15:51 |
mhen | so that you can't use a single consistent format if relying on defaults across the components | 15:52 |
mhen | I agree that it wasn't entirely undocumented and is an avoidable problem. However, I see this more as a general issue considering that OpenStack components should have consistent and sensible defaults across the board when it comes to security critical configuration, in my opinion. | 15:52 |
mhen | especially, since from my experience the documentation about which format to choose for which component is very scattered and even misleading at times | 15:52 |
*** bcafarel has joined #openstack-meeting | 15:52 | |
gagehugo | So a good path forward would be to improve the documentation then, that's something we can do. | 15:53 |
gagehugo | mhen: nickthetait is already helping us with our misleading documentation :) | 15:54 |
gagehugo | (and quite outdated) | 15:54 |
* nickthetait strongly agrees with mhen | 15:54 | |
mhen | from a security point of view, I don't fully understand how Cinder is allowed to go it's own way so light-minded | 15:54 |
nickthetait | is there anything we can do outside docs? | 15:54 |
mhen | convince Cinder to stay in line again ;) | 15:55 |
nickthetait | the complexity does impact the security of a deployment | 15:55 |
nickthetait | harder to maintain your current stance through an upgrade | 15:56 |
fungi | did cinder "go its own way" or did the rest of the services simply not get around to implementing the new interface yet? | 15:56 |
fungi | but i do agree that a coordinated transition for something like this across most projects would have been nicer for deployers | 15:57 |
gagehugo | I think there's inconsistencies, if nova is indeed defaulting to json still | 15:57 |
smcginnis | Cinder followed what the community release goal was to implement policy in code. Part of that was using oslo_policy which sets the default. (IIRC) | 15:57 |
mhen | gagehugo, every service but Cinder does afaik | 15:58 |
*** hongbin has quit IRC | 15:58 | |
gagehugo | I thought keystone does yaml now | 15:58 |
* gagehugo digs though release notes | 15:58 | |
gagehugo | mhen: or do you mean in the Queens release? | 15:58 |
mhen | but Cinder forcibly overrides the oslo_policy default, https://github.com/openstack/cinder/blob/master/cinder/policy.py#L31 | 15:58 |
smcginnis | Ah, that was an oversight then. So is it worse to be different now or to make people change yet again? | 15:59 |
mhen | I work with Queens on a daily basis, so yeah - I didn't check all current master branches | 15:59 |
*** gyee has joined #openstack-meeting | 16:00 | |
gagehugo | we're out of time, we can continue this in #openstack-security, thanks for coming everyone | 16:00 |
nickthetait | later | 16:01 |
gagehugo | #endmeeting | 16:01 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 16:01 | |
openstack | Meeting ended Thu Aug 29 16:01:14 2019 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 16:01 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/security/2019/security.2019-08-29-15.00.html | 16:01 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/security/2019/security.2019-08-29-15.00.txt | 16:01 |
openstack | Log: http://eavesdrop.openstack.org/meetings/security/2019/security.2019-08-29-15.00.log.html | 16:01 |
*** nickthetait has left #openstack-meeting | 16:01 | |
fungi | thanks gagehugo! | 16:03 |
gagehugo | smcginnis: thanks for helping with clarifying things! | 16:06 |
smcginnis | gagehugo: No problem, thanks for pointing out the issue. I wasn't aware of it's impact. | 16:07 |
*** markvoelker has quit IRC | 16:15 | |
*** markvoelker has joined #openstack-meeting | 16:15 | |
*** markvoelker has quit IRC | 16:27 | |
*** brinzhang has quit IRC | 16:35 | |
*** brinzhang has joined #openstack-meeting | 16:36 | |
*** brinzhang has quit IRC | 16:36 | |
*** brinzhang has joined #openstack-meeting | 16:37 | |
*** brinzhang has quit IRC | 16:38 | |
*** brinzhang has joined #openstack-meeting | 16:39 | |
*** markvoelker has joined #openstack-meeting | 16:40 | |
*** igordc has joined #openstack-meeting | 16:44 | |
*** jamesmcarthur has quit IRC | 16:50 | |
*** tesseract has quit IRC | 16:50 | |
*** e0ne has joined #openstack-meeting | 17:02 | |
*** ijw has joined #openstack-meeting | 17:02 | |
*** e0ne has quit IRC | 17:04 | |
*** e0ne has joined #openstack-meeting | 17:04 | |
*** e0ne has quit IRC | 17:04 | |
*** jbadiapa has joined #openstack-meeting | 17:07 | |
*** panda|rover is now known as panda|rover|off | 17:18 | |
*** enriquetaso has quit IRC | 17:21 | |
*** jawad_axd has joined #openstack-meeting | 17:26 | |
*** jawad_axd has quit IRC | 17:29 | |
*** e0ne has joined #openstack-meeting | 17:35 | |
*** e0ne has quit IRC | 17:35 | |
*** ralonsoh has quit IRC | 17:43 | |
*** ekcs has joined #openstack-meeting | 17:43 | |
*** psachin has quit IRC | 17:44 | |
*** AlanClark has quit IRC | 17:53 | |
*** ricolin has quit IRC | 17:55 | |
*** dougwig has joined #openstack-meeting | 18:12 | |
*** radeks has quit IRC | 18:15 | |
*** ijw has quit IRC | 18:19 | |
*** ijw has joined #openstack-meeting | 18:19 | |
*** ijw has quit IRC | 18:21 | |
*** ijw has joined #openstack-meeting | 18:22 | |
*** ijw has quit IRC | 18:23 | |
*** ijw has joined #openstack-meeting | 18:24 | |
*** ijw has quit IRC | 18:26 | |
*** ijw has joined #openstack-meeting | 18:27 | |
*** brault has quit IRC | 18:27 | |
*** ijw_ has joined #openstack-meeting | 18:28 | |
*** e0ne has joined #openstack-meeting | 18:29 | |
*** ijw_ has quit IRC | 18:29 | |
*** ijw has quit IRC | 18:32 | |
*** ijw_ has joined #openstack-meeting | 18:32 | |
*** ijw_ has quit IRC | 18:32 | |
*** e0ne has quit IRC | 18:32 | |
*** ijw has joined #openstack-meeting | 18:35 | |
*** ijw_ has joined #openstack-meeting | 18:36 | |
*** ijw_ has quit IRC | 18:37 | |
*** ijw has quit IRC | 18:38 | |
*** ijw has joined #openstack-meeting | 18:39 | |
*** ijw has quit IRC | 18:43 | |
*** e0ne has joined #openstack-meeting | 18:55 | |
*** hongbin has joined #openstack-meeting | 18:58 | |
*** enriquetaso has joined #openstack-meeting | 19:01 | |
*** e0ne has quit IRC | 19:01 | |
*** ijw has joined #openstack-meeting | 19:01 | |
*** e0ne has joined #openstack-meeting | 19:03 | |
*** hongbin has quit IRC | 19:03 | |
*** ijw has quit IRC | 19:04 | |
*** slaweq has quit IRC | 19:04 | |
*** e0ne has quit IRC | 19:04 | |
*** e0ne has joined #openstack-meeting | 19:05 | |
*** ijw has joined #openstack-meeting | 19:05 | |
*** e0ne has quit IRC | 19:05 | |
*** armstrong has joined #openstack-meeting | 19:11 | |
*** slaweq has joined #openstack-meeting | 19:11 | |
*** armstrong_ has joined #openstack-meeting | 19:13 | |
*** armstrong has quit IRC | 19:15 | |
*** armstrong_ is now known as armstrong | 19:15 | |
*** slaweq has quit IRC | 19:15 | |
*** enriquetaso has quit IRC | 19:21 | |
*** enriquetaso has joined #openstack-meeting | 19:21 | |
*** diablo_rojo has quit IRC | 19:27 | |
*** enriquetaso has quit IRC | 19:44 | |
*** brault has joined #openstack-meeting | 19:48 | |
*** eharney has quit IRC | 19:50 | |
*** brault has quit IRC | 19:52 | |
*** slaweq has joined #openstack-meeting | 19:59 | |
*** slaweq has quit IRC | 20:04 | |
*** slaweq has joined #openstack-meeting | 20:11 | |
*** slaweq has quit IRC | 20:16 | |
*** eharney has joined #openstack-meeting | 20:17 | |
*** ijw_ has joined #openstack-meeting | 20:20 | |
*** ijw has quit IRC | 20:24 | |
*** jamesmcarthur has joined #openstack-meeting | 20:36 | |
*** lpetrut has joined #openstack-meeting | 20:45 | |
*** lpetrut has quit IRC | 20:51 | |
*** efried has joined #openstack-meeting | 21:01 | |
efried | #startmeeting nova | 21:01 |
openstack | Meeting started Thu Aug 29 21:01:08 2019 UTC and is due to finish in 60 minutes. The chair is efried. Information about MeetBot at http://wiki.debian.org/MeetBot. | 21:01 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 21:01 |
*** openstack changes topic to " (Meeting topic: nova)" | 21:01 | |
openstack | The meeting name has been set to 'nova' | 21:01 |
mriedem | o/ | 21:01 |
aspiers | o/ | 21:01 |
*** ijw_ has quit IRC | 21:02 | |
efried | #link agenda https://wiki.openstack.org/wiki/Meetings/Nova#Agenda_for_next_meeting | 21:06 |
efried | if it's just the three of us, I'm going to skip the agenda and just ask if y'all want to talk about anything. | 21:06 |
mriedem | not really | 21:07 |
*** ijw has joined #openstack-meeting | 21:07 | |
efried | These 2100 meetings seem to be pretty sparse of late. Wondering if we should move or drop them. I think the only people who miss the 1400 ones routinely are west-coasters | 21:07 |
aspiers | Nothing really, just to say that stephenfin stuck SEV on the runway this morning and it should all be ready to go | 21:07 |
aspiers | I just cut it over to use his new scheduler/utils.py thing | 21:07 |
efried | cool | 21:07 |
efried | glad to see that merged. It's gonna make some things simpler | 21:08 |
efried | There's this: | 21:08 |
efried | (melwitt): I'm out on PTO today and tomorrow but wanted to seek approval for a specless blueprint https://blueprints.launchpad.net/nova/+spec/policy-rule-for-host-status-unknown | 21:08 |
efried | I have uploaded code to hopefully help with approval: https://review.opendev.org/679181 | 21:08 |
aspiers | but the thing with moving vcpus etc. over to requested_resources still needs to be done, right? | 21:08 |
efried | aspiers: Yes | 21:08 |
aspiers | it's all gradually beginning to make a bit more sense to me | 21:09 |
*** rfolco has quit IRC | 21:09 | |
efried | That 'host status UNKNOWN' thing sounds really familiar. | 21:09 |
efried | I thought we already talked about this a couple weeks ago. | 21:09 |
efried | o look, notes in the whiteboard | 21:10 |
*** slaweq has joined #openstack-meeting | 21:11 | |
efried | So... without digging into this more, I'm not going to be able to render an opinion | 21:11 |
efried | mriedem: can you tell at a glance whether this conforms to your suggestions? | 21:12 |
mriedem | i haven't reviewed the change | 21:12 |
efried | If we get your ack, we can kind of assume gibi's, based on his note there | 21:12 |
efried | would be nice to get lbragstad's nod too | 21:13 |
efried | but... does it really make sense for us to be approving a blueprint two weeks before FF? | 21:13 |
mriedem | i'd rather not | 21:13 |
mriedem | especially when it touches the api | 21:13 |
mriedem | and the code was posted yesterday | 21:14 |
efried | yeah, unless there's some reason this is important enough to preempt cores reviewing other stuff that's been approved & coded for a long time, I don't think it makes sense to add this straw to the camel's back. | 21:14 |
*** slaweq has quit IRC | 21:15 | |
efried | without melwitt here to argue that justification, I think we have to assume | 21:15 |
* efried draws red X | 21:16 | |
mriedem | :x duh duh duh | 21:17 |
efried | okay, anything else to talk about? | 21:17 |
mriedem | not from me | 21:18 |
efried | allllrightythen | 21:18 |
efried | o/ | 21:18 |
efried | #endmeeting | 21:18 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 21:18 | |
openstack | Meeting ended Thu Aug 29 21:18:26 2019 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 21:18 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/nova/2019/nova.2019-08-29-21.01.html | 21:18 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/nova/2019/nova.2019-08-29-21.01.txt | 21:18 |
openstack | Log: http://eavesdrop.openstack.org/meetings/nova/2019/nova.2019-08-29-21.01.log.html | 21:18 |
*** rcernin_ has quit IRC | 21:25 | |
*** jamesmcarthur has quit IRC | 21:26 | |
*** markvoelker has quit IRC | 21:32 | |
*** jamesmcarthur has joined #openstack-meeting | 21:38 | |
*** rfolco has joined #openstack-meeting | 21:42 | |
*** jamesmcarthur has quit IRC | 21:43 | |
*** jamesmcarthur has joined #openstack-meeting | 21:59 | |
*** jamesmcarthur has quit IRC | 22:04 | |
*** jamesmcarthur has joined #openstack-meeting | 22:10 | |
*** slaweq has joined #openstack-meeting | 22:11 | |
*** number80 has quit IRC | 22:12 | |
*** eharney has quit IRC | 22:12 | |
*** slaweq has quit IRC | 22:15 | |
*** jamesmcarthur has quit IRC | 22:17 | |
*** ijw has quit IRC | 22:18 | |
*** armstrong has quit IRC | 22:22 | |
*** jamesmcarthur has joined #openstack-meeting | 22:31 | |
*** diablo_rojo has joined #openstack-meeting | 22:32 | |
*** ijw has joined #openstack-meeting | 22:34 | |
*** markvoelker has joined #openstack-meeting | 22:35 | |
*** jamesmcarthur has quit IRC | 22:35 | |
*** ijw has quit IRC | 22:37 | |
*** ijw has joined #openstack-meeting | 22:38 | |
*** markvoelker has quit IRC | 22:40 | |
*** rcernin has joined #openstack-meeting | 22:43 | |
*** markvoelker has joined #openstack-meeting | 23:01 | |
*** ykatabam has joined #openstack-meeting | 23:08 | |
*** markvoelker has quit IRC | 23:11 | |
*** ykatabam has quit IRC | 23:43 | |
*** brinzhang has quit IRC | 23:53 | |
*** brinzhang has joined #openstack-meeting | 23:54 | |
*** gyee has quit IRC | 23:55 | |
*** hongbin has joined #openstack-meeting | 23:59 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!