| *** jmasud has quit IRC | 00:10 | |
| *** jamesmcarthur has joined #openstack-meeting | 00:46 | |
| *** jmasud has joined #openstack-meeting | 00:54 | |
| *** jamesmcarthur has quit IRC | 01:00 | |
| *** jamesmcarthur has joined #openstack-meeting | 01:01 | |
| *** jamesmcarthur has quit IRC | 01:06 | |
| *** jamesmcarthur has joined #openstack-meeting | 01:15 | |
| *** jmasud has quit IRC | 01:32 | |
| *** jmasud has joined #openstack-meeting | 01:37 | |
| *** jmasud has quit IRC | 01:46 | |
| *** ociuhandu has joined #openstack-meeting | 02:25 | |
| *** jmasud has joined #openstack-meeting | 02:28 | |
| *** ociuhandu has quit IRC | 02:29 | |
| *** evrardjp has quit IRC | 02:33 | |
| *** evrardjp has joined #openstack-meeting | 02:33 | |
| *** whoami-rajat has quit IRC | 02:49 | |
| *** jmasud has quit IRC | 03:03 | |
| *** jamesmcarthur has quit IRC | 03:38 | |
| *** jamesmcarthur has joined #openstack-meeting | 03:38 | |
| *** psachin has joined #openstack-meeting | 03:42 | |
| *** jamesmcarthur has quit IRC | 03:43 | |
| *** jmasud has joined #openstack-meeting | 04:04 | |
| *** jamesmcarthur has joined #openstack-meeting | 04:08 | |
| *** shanuintouch has joined #openstack-meeting | 04:43 | |
| *** vishalmanchanda has joined #openstack-meeting | 04:54 | |
| *** jmasud has quit IRC | 05:12 | |
| *** jmasud has joined #openstack-meeting | 05:16 | |
| *** udesale has joined #openstack-meeting | 05:34 | |
| *** manubk has joined #openstack-meeting | 06:14 | |
| *** jamesmcarthur has quit IRC | 06:36 | |
| *** jamesmcarthur has joined #openstack-meeting | 06:49 | |
| *** jmasud has quit IRC | 06:50 | |
| *** jmasud has joined #openstack-meeting | 07:01 | |
| *** Luzi has joined #openstack-meeting | 07:01 | |
| *** rpittau|afk is now known as rpittau | 07:19 | |
| *** jmasud has quit IRC | 07:43 | |
| *** tosky has joined #openstack-meeting | 07:50 | |
| *** whoami-rajat has joined #openstack-meeting | 07:56 | |
| *** jamesmcarthur has quit IRC | 08:05 | |
| *** jmasud has joined #openstack-meeting | 08:37 | |
| *** jmasud has quit IRC | 08:38 | |
| *** jmasud has joined #openstack-meeting | 08:49 | |
| *** jmasud has quit IRC | 08:50 | |
| *** ricolin has joined #openstack-meeting | 08:54 | |
| *** cgoncalves has quit IRC | 08:58 | |
| *** cgoncalves has joined #openstack-meeting | 09:00 | |
| *** e0ne has joined #openstack-meeting | 09:06 | |
| *** e0ne has quit IRC | 09:08 | |
| *** cgoncalves has quit IRC | 09:14 | |
| *** manubk has quit IRC | 09:15 | |
| *** cgoncalves has joined #openstack-meeting | 09:16 | |
| *** jbadiapa has joined #openstack-meeting | 09:25 | |
| *** ralonsoh_ has joined #openstack-meeting | 10:18 | |
| *** ralonsoh has quit IRC | 10:20 | |
| *** jbadiapa has quit IRC | 10:57 | |
| *** jamesmcarthur has joined #openstack-meeting | 12:03 | |
| *** jamesmcarthur has quit IRC | 12:04 | |
| *** jamesmcarthur has joined #openstack-meeting | 12:05 | |
| *** jamesmcarthur has quit IRC | 12:37 | |
| *** njohnston has joined #openstack-meeting | 12:44 | |
| *** e0ne has joined #openstack-meeting | 12:46 | |
| *** jamesmcarthur has joined #openstack-meeting | 12:46 | |
| *** jamesmcarthur has quit IRC | 12:51 | |
| *** jamesmcarthur has joined #openstack-meeting | 12:53 | |
| *** psachin has quit IRC | 12:53 | |
| *** rosmaita has joined #openstack-meeting | 12:56 | |
| *** eharney has joined #openstack-meeting | 12:59 | |
| *** jamesmcarthur has quit IRC | 13:00 | |
| Luzi | #startmeeting image_encryption | 13:00 |
|---|---|---|
| openstack | Meeting started Mon May 3 13:00:29 2021 UTC and is due to finish in 60 minutes. The chair is Luzi. Information about MeetBot at http://wiki.debian.org/MeetBot. | 13:00 |
| openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 13:00 |
| *** openstack changes topic to " (Meeting topic: image_encryption)" | 13:00 | |
| openstack | The meeting name has been set to 'image_encryption' | 13:00 |
| Luzi | #topic Roll Call | 13:00 |
| *** openstack changes topic to "Roll Call (Meeting topic: image_encryption)" | 13:00 | |
| fungi | ohai | 13:00 |
| Luzi | hi fungi, lets wait for redrobot | 13:01 |
| *** jamesmcarthur has joined #openstack-meeting | 13:02 | |
| *** jamesmcarthur has quit IRC | 13:04 | |
| *** jamesmcarthur_ has joined #openstack-meeting | 13:04 | |
| Luzi | redrobot, are you there? | 13:05 |
| rosmaita | o/ | 13:07 |
| *** jamesmcarthur_ has quit IRC | 13:08 | |
| *** stand has quit IRC | 13:08 | |
| Luzi | hi rosmaita | 13:12 |
| Luzi | well it seems redrobot is not available today... | 13:12 |
| Luzi | so i will ask them tomorrow in the barbican meeting about the secret consumers | 13:12 |
| rosmaita | sounds good | 13:13 |
| Luzi | ptg made it at least clear to me, that the secret consumer api is waiting for the microversions. and the microversion were/are waiting for the secure polices | 13:13 |
| rosmaita | thanks, that helps me understand the holdup | 13:14 |
| fungi | i tried to give a summary to the tc during the ptg as well, notes start at line 51 here at the moment: | 13:15 |
| fungi | #link https://etherpad.opendev.org/p/tc-xena-ptg TC Xena PTG notes | 13:15 |
| rosmaita | cool, thanks for that summary | 13:16 |
| rosmaita | Luzi: don't know if this will help, but cinder is also interested in the consumer API to harden our current handling of encryption keys for encrypted volumes | 13:17 |
| Luzi | i know, we talked about it in the autumn ptg | 13:17 |
| fungi | during the security sig session we talked about reviving past conversations around making barbican a base service, but step 1 would be finding use cases it enables. that might be one | 13:18 |
| rosmaita | yes, in order to have encrypted volumes in cinder, you must have a key manager service | 13:18 |
| rosmaita | #link https://docs.openstack.org/cinder/latest/configuration/block-storage/volume-encryption.html | 13:19 |
| fungi | thanks! | 13:19 |
| Luzi | rosmaita, do you use python-barbicanclient or castellan to interact with barbican= | 13:19 |
| fungi | gagehugo: ^ for reference | 13:19 |
| Luzi | ? | 13:19 |
| rosmaita | i think castellan directly, but i believe that requires python-barbicanclient | 13:20 |
| fungi | more importantly, would users of that feature be interacting with barbican, or is it all filtered through the cinder api? | 13:20 |
| Luzi | volume encryption is transparant to users | 13:21 |
| fungi | like, should users be able to supply keys for encrypting volumes, and if so should they do that through the cinder api or barbican? | 13:21 |
| rosmaita | well, we don't want them interacting with barbican, because without the consumer API, they can delete in-use keys | 13:21 |
| *** jamesmcarthur has joined #openstack-meeting | 13:21 | |
| fungi | sure, i mean hypothetical future with consumer api | 13:21 |
| rosmaita | keys are supplied automatically (generated by barbican) | 13:21 |
| rosmaita | we haven't found a reliable way for users to upload keys that work | 13:22 |
| rosmaita | too many moving parts | 13:22 |
| fungi | so for this purpose, castellan and "a castellan-supported keystore" is sufficient i suppose | 13:22 |
| rosmaita | yes, though, red hat, for instance, uses barbican | 13:23 |
| fungi | got it. so doesn't support the argument for adding barbican to the base services list since we already have it covered by https://governance.openstack.org/tc/reference/base-services.html#current-list-of-base-services | 13:24 |
| fungi | #link https://governance.openstack.org/tc/reference/base-services.html#current-list-of-base-services base services list | 13:24 |
| rosmaita | well, maybe not | 13:26 |
| rosmaita | we also have the upload-volume-to-image workflow | 13:26 |
| rosmaita | forget that | 13:26 |
| fungi | heh | 13:27 |
| rosmaita | as long as you configure cinder and glance correctly, should work with another keystore | 13:27 |
| fungi | makes sense, thanks | 13:27 |
| rosmaita | though we only test with barbican | 13:27 |
| fungi | anyway, i didn't mean to hijack the meeting with tangential topics | 13:27 |
| fungi | sorry about that | 13:27 |
| Luzi | no worries | 13:27 |
| Luzi | its more interesting than only have a discussion about waiting :D | 13:28 |
| rosmaita | :) | 13:28 |
| fungi | so was the barbican clarification on consumer api and microversions the only real takeaway from the ptg? | 13:28 |
| Luzi | mainly, | 13:28 |
| fungi | and the "add microversion 1.1" change is still wip, since almost 9 months... any indication where the discussion on making it no longer wip is taking place? barbican meetings? | 13:30 |
| rosmaita | Luzi: what are your plans for CI on this? I'm thinking maybe tests in cinder-tempest-plugin since the library will be in os-brick. I wonder whether it makes sense to work on the os-brick part and get that working even without the consumer API? | 13:32 |
| Luzi | yes in the barbican meetings, at least it should be there - i did not hear that secure polices were the reason the microversion were on hold until the ptg :/ | 13:32 |
| fungi | oh, the policy work is the blocker? i missed that | 13:33 |
| rosmaita | i think it may be a project bandwidth issue, not a technical issue | 13:33 |
| fungi | sure, we're all far too familiar with that struggle | 13:34 |
| Luzi | rosmaita, the os-brick part can be done without the secret consumer - but after that? how long would that be just dead code? | 13:34 |
| Luzi | yeah the barbican team has much to do :/ | 13:34 |
| rosmaita | well, as long as we get some CI on it, it can be run all the time | 13:35 |
| rosmaita | will probably require some devstack patches to enable whatever config you need in the services | 13:35 |
| Luzi | okay, i think looking into the cinder-tempest-plugin would be a good start | 13:35 |
| rosmaita | but we already use barbican for the encrypted volume tests in cinder-tempest-plugin, so a lot of what you will need is there | 13:36 |
| rosmaita | because you really could release this feature without consumer API | 13:36 |
| rosmaita | wouldn't have to worry about data leakage :) | 13:37 |
| Luzi | well thats only the case if glance is okay with it | 13:37 |
| rosmaita | it's kind of a bad hack, but you could do what cinder did with the cinder_encryption_key_deletion_policy metadata | 13:38 |
| Luzi | and image encryption requires users to interact with secrets | 13:38 |
| fungi | up-side to zuul is you can implement the job completely in proposed changes with depends-on to the various features you need in different projects, and completely run it | 13:39 |
| fungi | so you don't have to wait for reviewers to approve stuff | 13:40 |
| rosmaita | without the consumer API, the danger is that an end user might delete an in-use key by mistake ... is that correct? | 13:40 |
| Luzi | yes it is | 13:40 |
| rosmaita | and once the consumer api is available, there will only be a minor change in the workflow, i think | 13:41 |
| Luzi | so you propose to release the feature and add secret consumers later? | 13:43 |
| rosmaita | well, at least get it "almost" ready | 13:43 |
| rosmaita | glance team is ok with releasing stuff as EXPERIMENTAL | 13:43 |
| Luzi | well that would help i think. | 13:43 |
| rosmaita | i'm just worried that if consumer api isn't available until M-3, this whole thing has to wait for Y | 13:44 |
| Luzi | rosmaita, me too :/ | 13:44 |
| rosmaita | i'm trying to find our release note from adding automatic key handling to glance | 13:44 |
| rosmaita | we have a warning in there about the keys | 13:45 |
| * redrobot sneaks in through the back door | 13:45 | |
| Luzi | i will talk to the glance team, if they are okay with having only experimental image encryption, than i will start working on this | 13:46 |
| rosmaita | found it, it's in the glance release notes | 13:46 |
| fungi | redrobot: we saved a seat for you | 13:46 |
| rosmaita | https://docs.openstack.org/releasenotes/glance/train.html#new-features | 13:46 |
| rosmaita | third bullet point | 13:46 |
| Luzi | yeah, i have to discuss this with the glance team | 13:47 |
| Luzi | hi redrobot | 13:47 |
| rosmaita | even if they don't want to release it, we can get everything in place and not tell anyone about it until it's ready | 13:48 |
| Luzi | i will look through the remaining work - it should be the cinder part and the tests | 13:49 |
| Luzi | glance is just missing the secret consumer part and os-brick should also be ready | 13:50 |
| rosmaita | ok, cool | 13:50 |
| Luzi | redrobot, did you catch up and do you have any updates? | 13:50 |
| rosmaita | i think your brick patch needed tests | 13:50 |
| rosmaita | or have you added them an i am out of date? | 13:51 |
| Luzi | https://review.opendev.org/c/openstack/os-brick/+/709432/7 | 13:52 |
| Luzi | do you mean unit tests? | 13:52 |
| redrobot | Trying to catch up... sorry no updates on Barbican things. I've been trying to squash a Hashicorp Vault bug | 13:52 |
| rosmaita | Luzi: yes, i am out of date on your patch! | 13:53 |
| Luzi | to many tasks for only one redrobot :( | 13:53 |
| Luzi | yeah it has unit tests :) | 13:53 |
| rosmaita | Luzi: when you get a chance, please resolve the merge conflict on that (it's probably in requirements or lower-constraints), which will re-run the CI | 13:54 |
| rosmaita | i'll put it on my list to get that reviewed early this week | 13:54 |
| Luzi | yes, i will do that | 13:54 |
| rosmaita | ty | 13:54 |
| Luzi | okay do you have anything else you want to talk about? | 13:55 |
| rosmaita | yeah, i think if you can get an end-to-end test in cinder-tempest-plugin that would be fantastic | 13:55 |
| rosmaita | and you would be ready for the consumer api | 13:55 |
| *** zaneb has joined #openstack-meeting | 13:56 | |
| rosmaita | cinder-tempest-plugin also has tests that interact with glance, so that part is there too | 13:56 |
| Luzi | okay thank you | 13:57 |
| *** zaneb has quit IRC | 13:58 | |
| Luzi | if thats all, thank you for joining today and have a nice week | 13:58 |
| Luzi | #endmeeting image_encryption | 13:58 |
| *** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 13:58 | |
| openstack | Meeting ended Mon May 3 13:58:33 2021 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 13:58 |
| openstack | Minutes: http://eavesdrop.openstack.org/meetings/image_encryption/2021/image_encryption.2021-05-03-13.00.html | 13:58 |
| openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/image_encryption/2021/image_encryption.2021-05-03-13.00.txt | 13:58 |
| openstack | Log: http://eavesdrop.openstack.org/meetings/image_encryption/2021/image_encryption.2021-05-03-13.00.log.html | 13:58 |
| *** zaneb has joined #openstack-meeting | 13:58 | |
| *** rosmaita has left #openstack-meeting | 14:00 | |
| *** Luzi has quit IRC | 14:08 | |
| *** shanuintouch has quit IRC | 14:41 | |
| *** dklyle has joined #openstack-meeting | 14:48 | |
| *** zbr has quit IRC | 14:51 | |
| *** zbr has joined #openstack-meeting | 14:52 | |
| *** e0ne has quit IRC | 15:02 | |
| *** jmasud has joined #openstack-meeting | 15:07 | |
| *** macz_ has joined #openstack-meeting | 15:26 | |
| *** macz_ has quit IRC | 15:38 | |
| *** e0ne has joined #openstack-meeting | 15:38 | |
| *** jmasud has quit IRC | 15:44 | |
| *** dklyle has quit IRC | 15:48 | |
| *** macz_ has joined #openstack-meeting | 15:48 | |
| *** dklyle has joined #openstack-meeting | 15:48 | |
| *** udesale has quit IRC | 15:51 | |
| *** lbragstad_ is now known as lbragstad | 15:51 | |
| *** jmasud has joined #openstack-meeting | 15:59 | |
| *** rpittau is now known as rpittau|afk | 16:32 | |
| *** gyee has joined #openstack-meeting | 16:46 | |
| *** SWDevAngel has joined #openstack-meeting | 17:04 | |
| *** e0ne has quit IRC | 17:33 | |
| *** jamesmcarthur has quit IRC | 17:40 | |
| *** jamesmcarthur has joined #openstack-meeting | 17:57 | |
| *** jamesmcarthur has quit IRC | 18:13 | |
| *** jamesmcarthur has joined #openstack-meeting | 18:15 | |
| *** e0ne has joined #openstack-meeting | 18:16 | |
| *** jamesmcarthur has quit IRC | 18:17 | |
| *** jamesmcarthur has joined #openstack-meeting | 18:30 | |
| *** jmasud has quit IRC | 18:42 | |
| *** bbowen has quit IRC | 18:44 | |
| *** bbowen has joined #openstack-meeting | 18:47 | |
| *** jamesmcarthur has quit IRC | 18:49 | |
| *** jamesmcarthur has joined #openstack-meeting | 18:51 | |
| *** dklyle has quit IRC | 19:01 | |
| *** david-lyle has joined #openstack-meeting | 19:02 | |
| *** vishalmanchanda has quit IRC | 19:13 | |
| *** jmasud has joined #openstack-meeting | 19:16 | |
| *** jamesmcarthur has quit IRC | 19:18 | |
| *** manpreet has joined #openstack-meeting | 19:35 | |
| *** jamesmcarthur has joined #openstack-meeting | 19:44 | |
| *** jmasud has quit IRC | 19:50 | |
| *** jamesmcarthur has quit IRC | 19:52 | |
| *** jamesmcarthur has joined #openstack-meeting | 19:52 | |
| *** gyee has quit IRC | 19:53 | |
| *** cgoncalves has quit IRC | 19:53 | |
| *** SpamapS has quit IRC | 19:53 | |
| *** lbragstad has quit IRC | 19:54 | |
| *** priteau has quit IRC | 19:54 | |
| *** icey has quit IRC | 19:54 | |
| *** gyee has joined #openstack-meeting | 19:55 | |
| *** cgoncalves has joined #openstack-meeting | 19:55 | |
| *** SpamapS has joined #openstack-meeting | 19:55 | |
| *** lbragstad has joined #openstack-meeting | 19:55 | |
| *** priteau has joined #openstack-meeting | 19:55 | |
| *** icey has joined #openstack-meeting | 19:55 | |
| *** SWDevAngel has quit IRC | 20:03 | |
| *** armax has joined #openstack-meeting | 20:05 | |
| *** armax has left #openstack-meeting | 20:06 | |
| *** jamesmcarthur has quit IRC | 20:13 | |
| *** jamesmcarthur has joined #openstack-meeting | 20:14 | |
| *** ircuser-1 has joined #openstack-meeting | 20:27 | |
| *** jbadiapa has joined #openstack-meeting | 20:31 | |
| *** slaweq_ has joined #openstack-meeting | 20:35 | |
| *** jbadiapa has quit IRC | 20:41 | |
| *** jmasud has joined #openstack-meeting | 20:51 | |
| *** slaweq_ has quit IRC | 20:56 | |
| *** jamesmcarthur has quit IRC | 21:02 | |
| *** timburke has joined #openstack-meeting | 21:31 | |
| *** manpreet has quit IRC | 21:44 | |
| *** jamesmcarthur has joined #openstack-meeting | 21:54 | |
| *** e0ne has quit IRC | 21:56 | |
| *** jamesmcarthur has quit IRC | 21:59 | |
| *** whoami-rajat has quit IRC | 22:03 | |
| *** ralonsoh_ has quit IRC | 22:09 | |
| *** bcafarel has quit IRC | 22:30 | |
| *** bcafarel has joined #openstack-meeting | 22:31 | |
| *** eharney has quit IRC | 22:47 | |
| *** tosky has quit IRC | 22:50 | |
| *** eharney has joined #openstack-meeting | 23:00 | |
| *** jamesmcarthur has joined #openstack-meeting | 23:07 | |
| *** rcernin has joined #openstack-meeting | 23:07 | |
| *** jamesmcarthur has quit IRC | 23:13 | |
| *** jamesmcarthur has joined #openstack-meeting | 23:17 | |
| *** jamesmcarthur has quit IRC | 23:22 | |
| *** macz_ has quit IRC | 23:24 | |
| *** jmasud has quit IRC | 23:32 | |
| *** jmasud has joined #openstack-meeting | 23:45 | |
| *** jamesmcarthur has joined #openstack-meeting | 23:49 | |
| *** jamesmcarthur has quit IRC | 23:54 | |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!