*** jmasud has quit IRC | 00:10 | |
*** jamesmcarthur has joined #openstack-meeting | 00:46 | |
*** jmasud has joined #openstack-meeting | 00:54 | |
*** jamesmcarthur has quit IRC | 01:00 | |
*** jamesmcarthur has joined #openstack-meeting | 01:01 | |
*** jamesmcarthur has quit IRC | 01:06 | |
*** jamesmcarthur has joined #openstack-meeting | 01:15 | |
*** jmasud has quit IRC | 01:32 | |
*** jmasud has joined #openstack-meeting | 01:37 | |
*** jmasud has quit IRC | 01:46 | |
*** ociuhandu has joined #openstack-meeting | 02:25 | |
*** jmasud has joined #openstack-meeting | 02:28 | |
*** ociuhandu has quit IRC | 02:29 | |
*** evrardjp has quit IRC | 02:33 | |
*** evrardjp has joined #openstack-meeting | 02:33 | |
*** whoami-rajat has quit IRC | 02:49 | |
*** jmasud has quit IRC | 03:03 | |
*** jamesmcarthur has quit IRC | 03:38 | |
*** jamesmcarthur has joined #openstack-meeting | 03:38 | |
*** psachin has joined #openstack-meeting | 03:42 | |
*** jamesmcarthur has quit IRC | 03:43 | |
*** jmasud has joined #openstack-meeting | 04:04 | |
*** jamesmcarthur has joined #openstack-meeting | 04:08 | |
*** shanuintouch has joined #openstack-meeting | 04:43 | |
*** vishalmanchanda has joined #openstack-meeting | 04:54 | |
*** jmasud has quit IRC | 05:12 | |
*** jmasud has joined #openstack-meeting | 05:16 | |
*** udesale has joined #openstack-meeting | 05:34 | |
*** manubk has joined #openstack-meeting | 06:14 | |
*** jamesmcarthur has quit IRC | 06:36 | |
*** jamesmcarthur has joined #openstack-meeting | 06:49 | |
*** jmasud has quit IRC | 06:50 | |
*** jmasud has joined #openstack-meeting | 07:01 | |
*** Luzi has joined #openstack-meeting | 07:01 | |
*** rpittau|afk is now known as rpittau | 07:19 | |
*** jmasud has quit IRC | 07:43 | |
*** tosky has joined #openstack-meeting | 07:50 | |
*** whoami-rajat has joined #openstack-meeting | 07:56 | |
*** jamesmcarthur has quit IRC | 08:05 | |
*** jmasud has joined #openstack-meeting | 08:37 | |
*** jmasud has quit IRC | 08:38 | |
*** jmasud has joined #openstack-meeting | 08:49 | |
*** jmasud has quit IRC | 08:50 | |
*** ricolin has joined #openstack-meeting | 08:54 | |
*** cgoncalves has quit IRC | 08:58 | |
*** cgoncalves has joined #openstack-meeting | 09:00 | |
*** e0ne has joined #openstack-meeting | 09:06 | |
*** e0ne has quit IRC | 09:08 | |
*** cgoncalves has quit IRC | 09:14 | |
*** manubk has quit IRC | 09:15 | |
*** cgoncalves has joined #openstack-meeting | 09:16 | |
*** jbadiapa has joined #openstack-meeting | 09:25 | |
*** ralonsoh_ has joined #openstack-meeting | 10:18 | |
*** ralonsoh has quit IRC | 10:20 | |
*** jbadiapa has quit IRC | 10:57 | |
*** jamesmcarthur has joined #openstack-meeting | 12:03 | |
*** jamesmcarthur has quit IRC | 12:04 | |
*** jamesmcarthur has joined #openstack-meeting | 12:05 | |
*** jamesmcarthur has quit IRC | 12:37 | |
*** njohnston has joined #openstack-meeting | 12:44 | |
*** e0ne has joined #openstack-meeting | 12:46 | |
*** jamesmcarthur has joined #openstack-meeting | 12:46 | |
*** jamesmcarthur has quit IRC | 12:51 | |
*** jamesmcarthur has joined #openstack-meeting | 12:53 | |
*** psachin has quit IRC | 12:53 | |
*** rosmaita has joined #openstack-meeting | 12:56 | |
*** eharney has joined #openstack-meeting | 12:59 | |
*** jamesmcarthur has quit IRC | 13:00 | |
Luzi | #startmeeting image_encryption | 13:00 |
---|---|---|
openstack | Meeting started Mon May 3 13:00:29 2021 UTC and is due to finish in 60 minutes. The chair is Luzi. Information about MeetBot at http://wiki.debian.org/MeetBot. | 13:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 13:00 |
*** openstack changes topic to " (Meeting topic: image_encryption)" | 13:00 | |
openstack | The meeting name has been set to 'image_encryption' | 13:00 |
Luzi | #topic Roll Call | 13:00 |
*** openstack changes topic to "Roll Call (Meeting topic: image_encryption)" | 13:00 | |
fungi | ohai | 13:00 |
Luzi | hi fungi, lets wait for redrobot | 13:01 |
*** jamesmcarthur has joined #openstack-meeting | 13:02 | |
*** jamesmcarthur has quit IRC | 13:04 | |
*** jamesmcarthur_ has joined #openstack-meeting | 13:04 | |
Luzi | redrobot, are you there? | 13:05 |
rosmaita | o/ | 13:07 |
*** jamesmcarthur_ has quit IRC | 13:08 | |
*** stand has quit IRC | 13:08 | |
Luzi | hi rosmaita | 13:12 |
Luzi | well it seems redrobot is not available today... | 13:12 |
Luzi | so i will ask them tomorrow in the barbican meeting about the secret consumers | 13:12 |
rosmaita | sounds good | 13:13 |
Luzi | ptg made it at least clear to me, that the secret consumer api is waiting for the microversions. and the microversion were/are waiting for the secure polices | 13:13 |
rosmaita | thanks, that helps me understand the holdup | 13:14 |
fungi | i tried to give a summary to the tc during the ptg as well, notes start at line 51 here at the moment: | 13:15 |
fungi | #link https://etherpad.opendev.org/p/tc-xena-ptg TC Xena PTG notes | 13:15 |
rosmaita | cool, thanks for that summary | 13:16 |
rosmaita | Luzi: don't know if this will help, but cinder is also interested in the consumer API to harden our current handling of encryption keys for encrypted volumes | 13:17 |
Luzi | i know, we talked about it in the autumn ptg | 13:17 |
fungi | during the security sig session we talked about reviving past conversations around making barbican a base service, but step 1 would be finding use cases it enables. that might be one | 13:18 |
rosmaita | yes, in order to have encrypted volumes in cinder, you must have a key manager service | 13:18 |
rosmaita | #link https://docs.openstack.org/cinder/latest/configuration/block-storage/volume-encryption.html | 13:19 |
fungi | thanks! | 13:19 |
Luzi | rosmaita, do you use python-barbicanclient or castellan to interact with barbican= | 13:19 |
fungi | gagehugo: ^ for reference | 13:19 |
Luzi | ? | 13:19 |
rosmaita | i think castellan directly, but i believe that requires python-barbicanclient | 13:20 |
fungi | more importantly, would users of that feature be interacting with barbican, or is it all filtered through the cinder api? | 13:20 |
Luzi | volume encryption is transparant to users | 13:21 |
fungi | like, should users be able to supply keys for encrypting volumes, and if so should they do that through the cinder api or barbican? | 13:21 |
rosmaita | well, we don't want them interacting with barbican, because without the consumer API, they can delete in-use keys | 13:21 |
*** jamesmcarthur has joined #openstack-meeting | 13:21 | |
fungi | sure, i mean hypothetical future with consumer api | 13:21 |
rosmaita | keys are supplied automatically (generated by barbican) | 13:21 |
rosmaita | we haven't found a reliable way for users to upload keys that work | 13:22 |
rosmaita | too many moving parts | 13:22 |
fungi | so for this purpose, castellan and "a castellan-supported keystore" is sufficient i suppose | 13:22 |
rosmaita | yes, though, red hat, for instance, uses barbican | 13:23 |
fungi | got it. so doesn't support the argument for adding barbican to the base services list since we already have it covered by https://governance.openstack.org/tc/reference/base-services.html#current-list-of-base-services | 13:24 |
fungi | #link https://governance.openstack.org/tc/reference/base-services.html#current-list-of-base-services base services list | 13:24 |
rosmaita | well, maybe not | 13:26 |
rosmaita | we also have the upload-volume-to-image workflow | 13:26 |
rosmaita | forget that | 13:26 |
fungi | heh | 13:27 |
rosmaita | as long as you configure cinder and glance correctly, should work with another keystore | 13:27 |
fungi | makes sense, thanks | 13:27 |
rosmaita | though we only test with barbican | 13:27 |
fungi | anyway, i didn't mean to hijack the meeting with tangential topics | 13:27 |
fungi | sorry about that | 13:27 |
Luzi | no worries | 13:27 |
Luzi | its more interesting than only have a discussion about waiting :D | 13:28 |
rosmaita | :) | 13:28 |
fungi | so was the barbican clarification on consumer api and microversions the only real takeaway from the ptg? | 13:28 |
Luzi | mainly, | 13:28 |
fungi | and the "add microversion 1.1" change is still wip, since almost 9 months... any indication where the discussion on making it no longer wip is taking place? barbican meetings? | 13:30 |
rosmaita | Luzi: what are your plans for CI on this? I'm thinking maybe tests in cinder-tempest-plugin since the library will be in os-brick. I wonder whether it makes sense to work on the os-brick part and get that working even without the consumer API? | 13:32 |
Luzi | yes in the barbican meetings, at least it should be there - i did not hear that secure polices were the reason the microversion were on hold until the ptg :/ | 13:32 |
fungi | oh, the policy work is the blocker? i missed that | 13:33 |
rosmaita | i think it may be a project bandwidth issue, not a technical issue | 13:33 |
fungi | sure, we're all far too familiar with that struggle | 13:34 |
Luzi | rosmaita, the os-brick part can be done without the secret consumer - but after that? how long would that be just dead code? | 13:34 |
Luzi | yeah the barbican team has much to do :/ | 13:34 |
rosmaita | well, as long as we get some CI on it, it can be run all the time | 13:35 |
rosmaita | will probably require some devstack patches to enable whatever config you need in the services | 13:35 |
Luzi | okay, i think looking into the cinder-tempest-plugin would be a good start | 13:35 |
rosmaita | but we already use barbican for the encrypted volume tests in cinder-tempest-plugin, so a lot of what you will need is there | 13:36 |
rosmaita | because you really could release this feature without consumer API | 13:36 |
rosmaita | wouldn't have to worry about data leakage :) | 13:37 |
Luzi | well thats only the case if glance is okay with it | 13:37 |
rosmaita | it's kind of a bad hack, but you could do what cinder did with the cinder_encryption_key_deletion_policy metadata | 13:38 |
Luzi | and image encryption requires users to interact with secrets | 13:38 |
fungi | up-side to zuul is you can implement the job completely in proposed changes with depends-on to the various features you need in different projects, and completely run it | 13:39 |
fungi | so you don't have to wait for reviewers to approve stuff | 13:40 |
rosmaita | without the consumer API, the danger is that an end user might delete an in-use key by mistake ... is that correct? | 13:40 |
Luzi | yes it is | 13:40 |
rosmaita | and once the consumer api is available, there will only be a minor change in the workflow, i think | 13:41 |
Luzi | so you propose to release the feature and add secret consumers later? | 13:43 |
rosmaita | well, at least get it "almost" ready | 13:43 |
rosmaita | glance team is ok with releasing stuff as EXPERIMENTAL | 13:43 |
Luzi | well that would help i think. | 13:43 |
rosmaita | i'm just worried that if consumer api isn't available until M-3, this whole thing has to wait for Y | 13:44 |
Luzi | rosmaita, me too :/ | 13:44 |
rosmaita | i'm trying to find our release note from adding automatic key handling to glance | 13:44 |
rosmaita | we have a warning in there about the keys | 13:45 |
* redrobot sneaks in through the back door | 13:45 | |
Luzi | i will talk to the glance team, if they are okay with having only experimental image encryption, than i will start working on this | 13:46 |
rosmaita | found it, it's in the glance release notes | 13:46 |
fungi | redrobot: we saved a seat for you | 13:46 |
rosmaita | https://docs.openstack.org/releasenotes/glance/train.html#new-features | 13:46 |
rosmaita | third bullet point | 13:46 |
Luzi | yeah, i have to discuss this with the glance team | 13:47 |
Luzi | hi redrobot | 13:47 |
rosmaita | even if they don't want to release it, we can get everything in place and not tell anyone about it until it's ready | 13:48 |
Luzi | i will look through the remaining work - it should be the cinder part and the tests | 13:49 |
Luzi | glance is just missing the secret consumer part and os-brick should also be ready | 13:50 |
rosmaita | ok, cool | 13:50 |
Luzi | redrobot, did you catch up and do you have any updates? | 13:50 |
rosmaita | i think your brick patch needed tests | 13:50 |
rosmaita | or have you added them an i am out of date? | 13:51 |
Luzi | https://review.opendev.org/c/openstack/os-brick/+/709432/7 | 13:52 |
Luzi | do you mean unit tests? | 13:52 |
redrobot | Trying to catch up... sorry no updates on Barbican things. I've been trying to squash a Hashicorp Vault bug | 13:52 |
rosmaita | Luzi: yes, i am out of date on your patch! | 13:53 |
Luzi | to many tasks for only one redrobot :( | 13:53 |
Luzi | yeah it has unit tests :) | 13:53 |
rosmaita | Luzi: when you get a chance, please resolve the merge conflict on that (it's probably in requirements or lower-constraints), which will re-run the CI | 13:54 |
rosmaita | i'll put it on my list to get that reviewed early this week | 13:54 |
Luzi | yes, i will do that | 13:54 |
rosmaita | ty | 13:54 |
Luzi | okay do you have anything else you want to talk about? | 13:55 |
rosmaita | yeah, i think if you can get an end-to-end test in cinder-tempest-plugin that would be fantastic | 13:55 |
rosmaita | and you would be ready for the consumer api | 13:55 |
*** zaneb has joined #openstack-meeting | 13:56 | |
rosmaita | cinder-tempest-plugin also has tests that interact with glance, so that part is there too | 13:56 |
Luzi | okay thank you | 13:57 |
*** zaneb has quit IRC | 13:58 | |
Luzi | if thats all, thank you for joining today and have a nice week | 13:58 |
Luzi | #endmeeting image_encryption | 13:58 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 13:58 | |
openstack | Meeting ended Mon May 3 13:58:33 2021 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 13:58 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/image_encryption/2021/image_encryption.2021-05-03-13.00.html | 13:58 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/image_encryption/2021/image_encryption.2021-05-03-13.00.txt | 13:58 |
openstack | Log: http://eavesdrop.openstack.org/meetings/image_encryption/2021/image_encryption.2021-05-03-13.00.log.html | 13:58 |
*** zaneb has joined #openstack-meeting | 13:58 | |
*** rosmaita has left #openstack-meeting | 14:00 | |
*** Luzi has quit IRC | 14:08 | |
*** shanuintouch has quit IRC | 14:41 | |
*** dklyle has joined #openstack-meeting | 14:48 | |
*** zbr has quit IRC | 14:51 | |
*** zbr has joined #openstack-meeting | 14:52 | |
*** e0ne has quit IRC | 15:02 | |
*** jmasud has joined #openstack-meeting | 15:07 | |
*** macz_ has joined #openstack-meeting | 15:26 | |
*** macz_ has quit IRC | 15:38 | |
*** e0ne has joined #openstack-meeting | 15:38 | |
*** jmasud has quit IRC | 15:44 | |
*** dklyle has quit IRC | 15:48 | |
*** macz_ has joined #openstack-meeting | 15:48 | |
*** dklyle has joined #openstack-meeting | 15:48 | |
*** udesale has quit IRC | 15:51 | |
*** lbragstad_ is now known as lbragstad | 15:51 | |
*** jmasud has joined #openstack-meeting | 15:59 | |
*** rpittau is now known as rpittau|afk | 16:32 | |
*** gyee has joined #openstack-meeting | 16:46 | |
*** SWDevAngel has joined #openstack-meeting | 17:04 | |
*** e0ne has quit IRC | 17:33 | |
*** jamesmcarthur has quit IRC | 17:40 | |
*** jamesmcarthur has joined #openstack-meeting | 17:57 | |
*** jamesmcarthur has quit IRC | 18:13 | |
*** jamesmcarthur has joined #openstack-meeting | 18:15 | |
*** e0ne has joined #openstack-meeting | 18:16 | |
*** jamesmcarthur has quit IRC | 18:17 | |
*** jamesmcarthur has joined #openstack-meeting | 18:30 | |
*** jmasud has quit IRC | 18:42 | |
*** bbowen has quit IRC | 18:44 | |
*** bbowen has joined #openstack-meeting | 18:47 | |
*** jamesmcarthur has quit IRC | 18:49 | |
*** jamesmcarthur has joined #openstack-meeting | 18:51 | |
*** dklyle has quit IRC | 19:01 | |
*** david-lyle has joined #openstack-meeting | 19:02 | |
*** vishalmanchanda has quit IRC | 19:13 | |
*** jmasud has joined #openstack-meeting | 19:16 | |
*** jamesmcarthur has quit IRC | 19:18 | |
*** manpreet has joined #openstack-meeting | 19:35 | |
*** jamesmcarthur has joined #openstack-meeting | 19:44 | |
*** jmasud has quit IRC | 19:50 | |
*** jamesmcarthur has quit IRC | 19:52 | |
*** jamesmcarthur has joined #openstack-meeting | 19:52 | |
*** gyee has quit IRC | 19:53 | |
*** cgoncalves has quit IRC | 19:53 | |
*** SpamapS has quit IRC | 19:53 | |
*** lbragstad has quit IRC | 19:54 | |
*** priteau has quit IRC | 19:54 | |
*** icey has quit IRC | 19:54 | |
*** gyee has joined #openstack-meeting | 19:55 | |
*** cgoncalves has joined #openstack-meeting | 19:55 | |
*** SpamapS has joined #openstack-meeting | 19:55 | |
*** lbragstad has joined #openstack-meeting | 19:55 | |
*** priteau has joined #openstack-meeting | 19:55 | |
*** icey has joined #openstack-meeting | 19:55 | |
*** SWDevAngel has quit IRC | 20:03 | |
*** armax has joined #openstack-meeting | 20:05 | |
*** armax has left #openstack-meeting | 20:06 | |
*** jamesmcarthur has quit IRC | 20:13 | |
*** jamesmcarthur has joined #openstack-meeting | 20:14 | |
*** ircuser-1 has joined #openstack-meeting | 20:27 | |
*** jbadiapa has joined #openstack-meeting | 20:31 | |
*** slaweq_ has joined #openstack-meeting | 20:35 | |
*** jbadiapa has quit IRC | 20:41 | |
*** jmasud has joined #openstack-meeting | 20:51 | |
*** slaweq_ has quit IRC | 20:56 | |
*** jamesmcarthur has quit IRC | 21:02 | |
*** timburke has joined #openstack-meeting | 21:31 | |
*** manpreet has quit IRC | 21:44 | |
*** jamesmcarthur has joined #openstack-meeting | 21:54 | |
*** e0ne has quit IRC | 21:56 | |
*** jamesmcarthur has quit IRC | 21:59 | |
*** whoami-rajat has quit IRC | 22:03 | |
*** ralonsoh_ has quit IRC | 22:09 | |
*** bcafarel has quit IRC | 22:30 | |
*** bcafarel has joined #openstack-meeting | 22:31 | |
*** eharney has quit IRC | 22:47 | |
*** tosky has quit IRC | 22:50 | |
*** eharney has joined #openstack-meeting | 23:00 | |
*** jamesmcarthur has joined #openstack-meeting | 23:07 | |
*** rcernin has joined #openstack-meeting | 23:07 | |
*** jamesmcarthur has quit IRC | 23:13 | |
*** jamesmcarthur has joined #openstack-meeting | 23:17 | |
*** jamesmcarthur has quit IRC | 23:22 | |
*** macz_ has quit IRC | 23:24 | |
*** jmasud has quit IRC | 23:32 | |
*** jmasud has joined #openstack-meeting | 23:45 | |
*** jamesmcarthur has joined #openstack-meeting | 23:49 | |
*** jamesmcarthur has quit IRC | 23:54 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!