*** tosky has quit IRC | 00:06 | |
*** hamalq has quit IRC | 00:18 | |
*** macz_ has joined #openstack-nova | 00:38 | |
*** zzzeek has quit IRC | 00:42 | |
*** macz_ has quit IRC | 00:43 | |
*** zzzeek has joined #openstack-nova | 00:45 | |
openstackgerrit | norman shen proposed openstack/nova master: DNM: Cpu and memory live resize https://review.opendev.org/760264 | 00:47 |
---|---|---|
*** sapd1_x has joined #openstack-nova | 01:07 | |
*** sapd1_x has quit IRC | 01:18 | |
*** Liang__ has joined #openstack-nova | 01:26 | |
*** brinzhang_ has joined #openstack-nova | 01:31 | |
*** brinzhang has quit IRC | 01:33 | |
*** macz_ has joined #openstack-nova | 01:36 | |
*** macz_ has quit IRC | 01:41 | |
*** martinkennelly has quit IRC | 01:50 | |
*** masayukig has quit IRC | 01:59 | |
*** johnsom has quit IRC | 02:00 | |
*** rpittau|afk has quit IRC | 02:00 | |
*** TheJulia has quit IRC | 02:00 | |
*** rpittau|afk has joined #openstack-nova | 02:00 | |
*** TheJulia has joined #openstack-nova | 02:00 | |
*** masayukig has joined #openstack-nova | 02:01 | |
*** johnsom has joined #openstack-nova | 02:01 | |
*** vdrok has quit IRC | 02:02 | |
*** gyee has quit IRC | 02:02 | |
*** vdrok has joined #openstack-nova | 02:03 | |
*** k_mouza has joined #openstack-nova | 02:06 | |
*** k_mouza has quit IRC | 02:14 | |
*** Yumeng has joined #openstack-nova | 02:52 | |
*** mkrai has joined #openstack-nova | 02:59 | |
*** mkrai has quit IRC | 03:07 | |
*** mkrai_ has joined #openstack-nova | 03:07 | |
*** mkrai_ has quit IRC | 03:40 | |
*** mkrai has joined #openstack-nova | 03:57 | |
*** k_mouza has joined #openstack-nova | 04:15 | |
*** k_mouza has quit IRC | 04:19 | |
*** vishalmanchanda has joined #openstack-nova | 04:25 | |
*** ratailor has joined #openstack-nova | 05:23 | |
*** evrardjp has quit IRC | 05:33 | |
*** evrardjp has joined #openstack-nova | 05:33 | |
*** mkrai has quit IRC | 06:33 | |
*** ralonsoh has joined #openstack-nova | 06:47 | |
*** dklyle has quit IRC | 07:10 | |
*** Liang__ has quit IRC | 07:22 | |
*** Liang__ has joined #openstack-nova | 07:23 | |
*** rcernin has quit IRC | 07:31 | |
*** links has joined #openstack-nova | 07:39 | |
*** mkrai has joined #openstack-nova | 07:55 | |
*** ociuhandu has joined #openstack-nova | 08:00 | |
*** lbragstad has quit IRC | 08:04 | |
*** lbragstad has joined #openstack-nova | 08:04 | |
*** slaweq has joined #openstack-nova | 08:04 | |
*** tesseract has joined #openstack-nova | 08:05 | |
*** andrewbonney has joined #openstack-nova | 08:09 | |
bauzas | good morning Nova | 08:20 |
* bauzas needs to disappear a bit this morning since I have to prepare for the lockdown we'll get tonight for at least one month | 08:21 | |
gibi | bauzas: o/ | 08:24 |
*** macz_ has joined #openstack-nova | 08:31 | |
*** macz_ has quit IRC | 08:36 | |
*** rpittau|afk is now known as rpittau | 08:40 | |
*** xinranwang has joined #openstack-nova | 08:43 | |
*** tosky has joined #openstack-nova | 08:51 | |
*** dtantsur|afk is now known as dtantsur | 08:58 | |
lyarwood | Morning all | 09:01 |
*** rcernin has joined #openstack-nova | 09:18 | |
*** martinkennelly has joined #openstack-nova | 09:21 | |
brinzhang_ | lyarwood: morning^ | 09:27 |
brinzhang_ | lyarwood: hope you can review Add instance_state to ensure volume attachment successful https://review.opendev.org/#/c/758920/ while you have free time | 09:27 |
brinzhang_ | it comes from bug 1897424 | 09:28 |
openstack | bug 1897424 in OpenStack Compute (nova) "attach volume consume too long time, and if attaching another volume at the same time, create the bdm will be timeout" [Wishlist,Incomplete] https://launchpad.net/bugs/1897424 - Assigned to Lee Yarwood (lyarwood) | 09:28 |
lyarwood | brinzhang_: ack yeah it's in my queue | 09:32 |
lyarwood | brinzhang_: thanks for reminding me :) | 09:32 |
brinzhang_ | larywood: np, thanks for your concern :D | 09:33 |
*** dtantsur is now known as dtantsur|brb | 09:44 | |
*** k_mouza has joined #openstack-nova | 09:49 | |
*** derekh has joined #openstack-nova | 09:52 | |
*** slaweq has quit IRC | 10:05 | |
*** rcernin has quit IRC | 10:07 | |
*** tesseract has quit IRC | 10:09 | |
*** tesseract has joined #openstack-nova | 10:11 | |
*** slaweq has joined #openstack-nova | 10:12 | |
*** links has quit IRC | 10:17 | |
*** macz_ has joined #openstack-nova | 10:19 | |
*** macz_ has quit IRC | 10:24 | |
*** zzzeek has quit IRC | 10:28 | |
*** zzzeek has joined #openstack-nova | 10:29 | |
*** mkrai has quit IRC | 10:40 | |
*** Liang__ has quit IRC | 10:41 | |
*** Liang__ has joined #openstack-nova | 10:50 | |
*** mkrai has joined #openstack-nova | 10:55 | |
*** tesseract has quit IRC | 10:58 | |
*** tesseract has joined #openstack-nova | 10:59 | |
*** Liang__ has quit IRC | 10:59 | |
*** LinPeiWen22 has quit IRC | 11:14 | |
*** rcernin has joined #openstack-nova | 11:15 | |
openstackgerrit | Shi Yan proposed openstack/nova master: Remove unused bindir config option https://review.opendev.org/760331 | 11:18 |
*** dave-mccowan has joined #openstack-nova | 11:43 | |
*** dave-mccowan has quit IRC | 11:48 | |
gibi | melwitt, lyarwood, elod: reviewed https://review.opendev.org/#/q/topic:bug/1731668+(status:open+OR+status:merged) and I think this is OK from db/placement perspective. | 11:49 |
*** LinPeiWen has joined #openstack-nova | 11:56 | |
*** spatel has joined #openstack-nova | 11:56 | |
*** dtantsur|brb is now known as dtantsur | 11:57 | |
*** lpetrut has joined #openstack-nova | 11:59 | |
*** spatel has quit IRC | 12:01 | |
elod | thx gibi, I was just about to comment that 'it looks OK to me, but I would ask for other core members to review it' :) | 12:10 |
*** sapd1 has quit IRC | 12:19 | |
*** sapd1 has joined #openstack-nova | 12:20 | |
*** raildo has joined #openstack-nova | 12:27 | |
*** mkrai has quit IRC | 12:30 | |
*** ratailor has quit IRC | 12:43 | |
*** nweinber has joined #openstack-nova | 12:48 | |
elod | sean-k-mooney: a minor thing: I don't want to merge this with your -1 on it o:) -- https://review.opendev.org/#/c/750925/ | 12:48 |
sean-k-mooney | elod: oh ill change that we talked about it on the master version | 12:50 |
sean-k-mooney | i dont really like the change sicne we have never used it for lower constraitns and apparently that is why it was renamed but its was not enought for me to -2 on master and other were happy so its fine | 12:51 |
sean-k-mooney | elod: +1 now | 12:52 |
*** Luzi has joined #openstack-nova | 12:53 | |
sean-k-mooney | elod: this was the master version https://review.opendev.org/#/c/756135/ | 12:53 |
sean-k-mooney | it looks like the review bot version is not a cherry pick but a stable only patch | 12:53 |
sean-k-mooney | but for something this trivail im not sure we care too much that its stable only | 12:54 |
openstackgerrit | Andrey Volkov proposed openstack/nova master: Functional test test_boot_reschedule_with_proper_pci_device_count https://review.opendev.org/760354 | 12:59 |
kashyap | lyarwood: The libvirt/QEMU folks are rushing hither and thither w/ KVM Forum thing in flight; I'm still tryin to get the right eyes on this: https://bugs.launchpad.net/nova/+bug/1901739 | 13:08 |
openstack | Launchpad bug 1901739 in OpenStack Compute (nova) " libvirt.libvirtError: internal error: missing block job data for disk 'vda'" [High,Confirmed] | 13:08 |
kashyap | lyarwood: Peter Krempa would be the right one, based on my Git analysis; but it's probly a holiday in Czech | 13:08 |
tosky | kashyap: it was yesterday | 13:10 |
kashyap | tosky: Oh, sorry. Let me check w/ him again, then :) | 13:10 |
kashyap | tosky: Thank you | 13:10 |
tosky | but then people may have used that for longer holidays :) | 13:11 |
lyarwood | kashyap: ack thanks | 13:12 |
*** sapd1_x has joined #openstack-nova | 13:38 | |
*** rcernin has quit IRC | 13:43 | |
*** macz_ has joined #openstack-nova | 13:55 | |
lyarwood | anyone having issues pushing new patchsets to nova-specs? | 13:58 |
*** macz_ has quit IRC | 14:00 | |
*** sapd1_x has quit IRC | 14:06 | |
*** mlavalle has joined #openstack-nova | 14:17 | |
*** vishalmanchanda has quit IRC | 14:24 | |
elod | sean-k-mooney: thanks, I'll +2 then :) | 14:27 |
*** evrardjp has quit IRC | 14:38 | |
*** evrardjp has joined #openstack-nova | 14:40 | |
*** hamalq has joined #openstack-nova | 14:41 | |
*** liuyulong has joined #openstack-nova | 14:47 | |
*** dklyle has joined #openstack-nova | 14:47 | |
*** macz_ has joined #openstack-nova | 14:52 | |
*** eharney has quit IRC | 14:52 | |
*** legochen has joined #openstack-nova | 14:53 | |
*** lpetrut has quit IRC | 14:56 | |
melwitt | gibi, elod: thank you both for the reviews! so much appreciated, I know that was a tough one. please lmk if there is anything I can review for you. I will fix the nits in the bottom patch | 15:03 |
*** tkajinam has quit IRC | 15:05 | |
*** eharney has joined #openstack-nova | 15:05 | |
*** takamatsu has quit IRC | 15:07 | |
melwitt | lyarwood: easy review for the cherry pick check fix https://review.opendev.org/759118 (it's blocking my stable-only patch, need it back to queens) | 15:08 |
*** takamatsu has joined #openstack-nova | 15:09 | |
openstackgerrit | melanie witt proposed openstack/nova stable/queens: [stable-only] Add functional test for bug 1731668 https://review.opendev.org/756636 | 15:13 |
openstack | bug 1731668 in OpenStack Compute (nova) queens "placement: claim allocations fails with IndexError in _ensure_lookup_table_entry" [Low,In progress] https://launchpad.net/bugs/1731668 - Assigned to melanie witt (melwitt) | 15:13 |
openstackgerrit | melanie witt proposed openstack/nova stable/queens: [stable-only] Use a separate transaction for reading after race https://review.opendev.org/756637 | 15:13 |
lyarwood | melwitt: ack I'll look shortly | 15:17 |
melwitt | thanks | 15:18 |
*** nweinber has quit IRC | 15:23 | |
*** nweinber has joined #openstack-nova | 15:24 | |
*** eharney has quit IRC | 15:39 | |
sean-k-mooney | johnthetubaguy: so i would need to find it again but there is a fuse module that allows you to mount http directoes as a local file system | 15:39 |
sean-k-mooney | so the config drive alternitve was basically mounting metadata on the host and exposing it via cephfs | 15:40 |
sean-k-mooney | allow a config driver style approch without a config drive for guests without networking or whatever | 15:40 |
sean-k-mooney | the other cyborg like storage usecause weas using cyborg or something else to manage local storage on the host that can be exposed as fast epmeral storage withoug using the falvor epmeral option | 15:42 |
sean-k-mooney | that would only be useful if we had the ablity to have multiple device profiles or have a --device attach/detach | 15:42 |
sean-k-mooney | so right now im not proposing the cyborg approch since you cant contole it outside the flavor | 15:43 |
sean-k-mooney | also i have other more important things | 15:43 |
sean-k-mooney | but ya i have wanted to have a cyborg lvm driver for a while that we could use for local storage and testing in the gate since we can test programablity by just downloading the glance image to the volume. | 15:51 |
*** eharney has joined #openstack-nova | 15:51 | |
*** eharney has quit IRC | 15:57 | |
*** LinPeiWen has quit IRC | 16:00 | |
openstackgerrit | Merged openstack/os-vif stable/victoria: Update TOX_CONSTRAINTS_FILE for stable/victoria https://review.opendev.org/750925 | 16:03 |
*** eharney has joined #openstack-nova | 16:10 | |
bauzas | lyarwood: (14:58:48) lyarwood: anyone having issues pushing new patchsets to nova-specs? | 16:21 |
bauzas | lyarwood: oh, are you sure you use SSH over gerrit and not HTTPS ? | 16:21 |
*** liuyulong has quit IRC | 16:39 | |
*** slaweq has quit IRC | 16:44 | |
*** Luzi has quit IRC | 16:46 | |
*** rpittau is now known as rpittau|afk | 16:57 | |
legochen | hi nova experts, I’d like to understand why nova doesn’t provide provide access control for AZ like what network RBAC does :) | 17:01 |
lyarwood | bauzas: ssh://lyarwood@review.opendev.org:29418/openstack/nova-specs.git that's the remote it's trying to push to | 17:01 |
sean-k-mooney | legochen: AZ are just tags on aggreates | 17:01 |
sean-k-mooney | legochen: you can restrict aggeates to tenatns seperatly | 17:01 |
sean-k-mooney | legochen: so you kindo of can do this but no one has really asked for it before | 17:02 |
bauzas | legochen: you have policies on AZs.... | 17:02 |
sean-k-mooney | bauzas: not to filter the list of azs | 17:02 |
sean-k-mooney | bauzas: e.g. you cant just retrun the list of azs you can boot too | 17:02 |
sean-k-mooney | you can restict who can list them or pass them but that it with policy | 17:03 |
bauzas | sean-k-mooney: really? https://docs.openstack.org/api-ref/compute/?expanded=get-availability-zone-information-detail#availability-zones-os-availability-zone | 17:03 |
legochen | For example, we use AZ to group hypervisors for multiple different environments. And we only allow A users to use environment A, B users to use environment B. | 17:03 |
bauzas | legochen: then use aggregate metadata | 17:03 |
bauzas | lyarwood: looks legit | 17:03 |
bauzas | lyarwood: I was planning to bump on F33 tonight, will let you know | 17:04 |
sean-k-mooney | legochen you can do that with https://docs.openstack.org/nova/latest/configuration/config.html#scheduler.limit_tenants_to_placement_aggregate | 17:04 |
sean-k-mooney | and https://docs.openstack.org/nova/latest/configuration/config.html#scheduler.placement_aggregate_required_for_tenants | 17:04 |
legochen | yes, but the user experience is not so good for that case as they still can see that AZ listed. And when they specify that AZ to create VM, no errors will promot immediately. | 17:04 |
legochen | the error happens in scheduling step. | 17:05 |
legochen | users hard to aware of that. | 17:05 |
bauzas | anyway, bailing out, wanting to live the 3 last hours before the lockdown out of home | 17:05 |
sean-k-mooney | legochen: yes that is true we could maybe filter based on the other meatadata | 17:05 |
sean-k-mooney | the only way to do that today is to add custom midelware | 17:06 |
sean-k-mooney | but you could propose a new feature for it. its not a bug that it does not do it today however | 17:06 |
sean-k-mooney | legochen: filtering az by availablity would be an api change and would need a spec | 17:07 |
*** ociuhandu_ has joined #openstack-nova | 17:07 | |
sean-k-mooney | legochen: normally you would do it via host aggreates and then tell your users to not specify an az | 17:07 |
sean-k-mooney | legochen: with aggreates you can make it transparent | 17:08 |
sean-k-mooney | az are really ment to be useable by all users | 17:08 |
legochen | As OpenStack has the ability to provide multi-tenancy use case. But, seems hard to do access-control for resources when we use only one control plane. | 17:10 |
sean-k-mooney | legochen: well the point is you shoudl not be doing access contol via AZs | 17:11 |
sean-k-mooney | you shoudl be doing that with host aggreates | 17:11 |
legochen | thanks sean for the information. I’m still new to openstack, this is my first week to join openstack IRC. not that sure the process to discuss the requirements or features. | 17:11 |
*** ociuhandu has quit IRC | 17:11 | |
*** ociuhandu_ has quit IRC | 17:11 | |
sean-k-mooney | AZs in openstack are very different the AZs in aws or other cloud plathforms | 17:12 |
sean-k-mooney | they are really just a host aggreate with a metadta key set to give them an az name | 17:12 |
melwitt | yeah, AZ are a user-facing grouping mechanism | 17:12 |
sean-k-mooney | as a result we dont really have a way to eaislly add rbac style filtering on them | 17:12 |
*** hamalq has quit IRC | 17:13 | |
*** psachin has joined #openstack-nova | 17:13 | |
sean-k-mooney | it could be done but partioning of the cloud is ment to be somethign the operator know about rather then the user | 17:13 |
melwitt | "host aggregates" are the access-control-based counterparts that nova uses underneath. and an AZ can be composed of one or more host aggregates | 17:13 |
legochen | I have came up with this doc - I’m going to use domain to manage differet kind of users. I’m looking for a feature support that can do access control by “domain” level instead of only by “project” level. https://docs.google.com/document/d/1Cv3FB3HLc70o4EcFh9aLxzPVszRgulkADnmJxmT65a8/edit# | 17:13 |
*** hamalq has joined #openstack-nova | 17:14 | |
sean-k-mooney | legochen: this has come up before | 17:14 |
sean-k-mooney | last cycle | 17:14 |
sean-k-mooney | i can recal exactly what we discussed but nova has no concept of a domain | 17:14 |
sean-k-mooney | legochen: domain exist only in keystone not other services | 17:15 |
melwitt | legochen: here is a helpful doc that explains AZ vs host aggregate https://docs.openstack.org/nova/latest/admin/aggregates.html | 17:15 |
*** ralonsoh has quit IRC | 17:15 | |
legochen | sean-k-mooney: legochen: domain exist only in keystone not other services. <= but, have future plan for other services for supporting that? | 17:16 |
sean-k-mooney | legochen: no | 17:16 |
sean-k-mooney | not that im aware of | 17:16 |
legochen | oh no…….hmm, just thinking if OpenStack could support both doamin/project based access control, it really add more flexibility for OpenStack admin to manage multiple organizations :) | 17:18 |
sean-k-mooney | the best solution i can think off quickly would be to use https://docs.openstack.org/nova/latest/reference/isolate-aggregates.html | 17:18 |
sean-k-mooney | and then add a prefilter to translate a users domain into a CUSTOM_DOMAIN_<domain> trait | 17:18 |
sean-k-mooney | legochen: it would be a lot of work to do and it might cause issue with keystone federation if all service had to support domain directly | 17:19 |
sean-k-mooney | using isolated aggreate with a prefilter to do the domain to trait traslation would be a very small change | 17:20 |
sean-k-mooney | and it would work i think in most cases | 17:20 |
sean-k-mooney | its basically what https://docs.openstack.org/nova/latest/admin/aggregates.html#tenant-isolation-with-placement does | 17:21 |
sean-k-mooney | but based on domains not project ids | 17:21 |
legochen | thanks, … keystone brings up the domain feature, but, only for authentication stuff, not actually use it for management services. seems not that logical :( | 17:21 |
sean-k-mooney | im prettysure that is what we said to do at the last ptg | 17:22 |
sean-k-mooney | legochen: domains are really a way of providing limit admin to people so they can manage flavor/quotas within that domain | 17:22 |
sean-k-mooney | legochen: if you were to do it the way im proposing you would basicaly copy paste https://github.com/openstack/nova/blob/master/nova/scheduler/request_filter.py#L91-L132 | 17:24 |
sean-k-mooney | and replace the project id with the domain | 17:24 |
sean-k-mooney | well really the TENANT_METADATA_KEY with a DOMAIN_METADATA_KEY | 17:25 |
openstackgerrit | Ghanshyam Mann proposed openstack/nova master: Modify glance's copy_image permission for nova-ceph-multistore https://review.opendev.org/760422 | 17:26 |
sean-k-mooney | so in https://github.com/openstack/nova/blob/master/nova/scheduler/request_filter.py#L107-L114 just swap project_id for the domain and TENANT_METADATA_KEY for DOMAIN_METADATA_KEY and the rest is more or less the same | 17:26 |
sean-k-mooney | legochen: its less then 100 lines fo code + tests and docs | 17:27 |
openstackgerrit | Ghanshyam Mann proposed openstack/nova master: DNM: testing copy private image with admin https://review.opendev.org/760128 | 17:27 |
sean-k-mooney | but the important thing is you woudl be useing aggreate not AZs to map domains to hosts | 17:27 |
sean-k-mooney | legochen: if this is something you really need i woudl suggest addign it to https://etherpad.opendev.org/p/nova-wallaby-ptg so we can discuss it tommorow in the ptg | 17:28 |
legochen | yeah, but is it possible to let error promot could happen when users specify to a AZ that they don’t have permission to access? | 17:28 |
legochen | thank you sean :) | 17:29 |
sean-k-mooney | well they will get a novalid host error today | 17:29 |
sean-k-mooney | we could add an api check maybe it would have too check the aggreate metadata but that is proably ok | 17:29 |
legochen | hmm, no valid host could be caused by multiple reasons. | 17:30 |
sean-k-mooney | :) yes | 17:30 |
sean-k-mooney | gmann: do we need a microverion to convert no valid host into something else basically a 400 or 403 | 17:30 |
sean-k-mooney | legochen: i think if we added the api check we coudl only do it with a new microversion so request with teh old microversion would not be checked | 17:31 |
gmann | sean-k-mooney: no as long as it return any existing error code (like 400 and 403). | 17:32 |
sean-k-mooney | based on https://docs.openstack.org/nova/latest/contributor/microversions.html#when-do-i-need-a-new-microversion | 17:32 |
gmann | we convert it to 200 or new error code then yes | 17:32 |
legochen | that would be great to clearly explain what’s going on in the error message :) do you think it is worth to do | 17:32 |
sean-k-mooney | gmann: today it would be a 200 but then later it will fail with no valid host | 17:33 |
sean-k-mooney | the az filter would block it | 17:33 |
sean-k-mooney | so it would be a 200 to 400 or 403 | 17:33 |
sean-k-mooney | on server create | 17:33 |
sean-k-mooney | legochen: gmann lets talk about this in the ptg tomorow if we have time | 17:34 |
gmann | sean-k-mooney: i see then we need microversion bump hoping server creation happening successfully previously | 17:34 |
legochen | okay, I’ll attend. | 17:35 |
gmann | sean-k-mooney: I will be in TC sessions tomorrow but discussing in PTG good idea | 17:35 |
sean-k-mooney | gmann: it would need a spec in anycase | 17:35 |
gmann | yeah | 17:36 |
sean-k-mooney | it would be very similar to https://github.com/openstack/nova/commit/732e202e81142a8ea462a9ebcde9a7226a62a60b | 17:37 |
sean-k-mooney | except based on domains not project_ids but otherwise identical | 17:37 |
sean-k-mooney | added right at the end of https://etherpad.opendev.org/p/nova-wallaby-ptg | 17:41 |
*** k_mouza has quit IRC | 17:41 | |
sean-k-mooney | legochen: ^ line 862 currently. | 17:41 |
sean-k-mooney | legochen: feel free to add addtional detail | 17:41 |
legochen | okay, will do in the morning, it is about 2:00am in my time :) | 17:42 |
legochen | ttyl | 17:42 |
legochen | and thank you! | 17:43 |
*** derekh has quit IRC | 18:07 | |
*** andrewbonney has quit IRC | 18:13 | |
*** dtantsur is now known as dtantsur|afk | 18:18 | |
*** tesseract has quit IRC | 18:21 | |
*** tosky has quit IRC | 18:29 | |
*** psachin has quit IRC | 18:36 | |
*** recyclehero has quit IRC | 18:50 | |
*** recyclehero has joined #openstack-nova | 18:57 | |
*** nweinber has quit IRC | 19:20 | |
*** nweinber has joined #openstack-nova | 19:20 | |
*** vesper11 has quit IRC | 19:35 | |
*** k_mouza has joined #openstack-nova | 19:42 | |
*** k_mouza has quit IRC | 19:46 | |
*** gyee has joined #openstack-nova | 19:57 | |
openstackgerrit | Ade Lee proposed openstack/nova master: Replace md5 with oslo version https://review.opendev.org/756434 | 19:59 |
*** Yumeng has quit IRC | 20:22 | |
*** zzzeek has quit IRC | 20:32 | |
*** zzzeek has joined #openstack-nova | 20:33 | |
*** legochen has quit IRC | 20:35 | |
openstackgerrit | Lee Yarwood proposed openstack/nova-specs master: WIP/DNM - Image defined ephemeral storage encryption https://review.opendev.org/752284 | 20:38 |
*** jamesdenton has quit IRC | 20:47 | |
*** jamesdenton has joined #openstack-nova | 20:54 | |
*** jamesdenton has quit IRC | 20:54 | |
lyarwood | PSA for anyone upgrading to F33, you will need https://bugzilla.redhat.com/show_bug.cgi?id=1884920#c2 | 20:55 |
openstack | bugzilla.redhat.com bug 1884920 in openssh "Cannot ssh into CentOS 6 using ssh key authentication" [Low,Closed: notabug] - Assigned to jjelen | 20:55 |
*** nweinber_ has joined #openstack-nova | 20:55 | |
*** tbachman has joined #openstack-nova | 20:56 | |
*** nweinber has quit IRC | 20:56 | |
openstackgerrit | Lee Yarwood proposed openstack/nova master: WIP Add encryption fields to BlockDeviceMapping https://review.opendev.org/760453 | 20:57 |
openstackgerrit | Lee Yarwood proposed openstack/nova master: WIP image_meta: Add ephemeral encryption properties https://review.opendev.org/760454 | 20:57 |
openstackgerrit | Lee Yarwood proposed openstack/nova master: WIP virt: Add ephemeral encryption flag https://review.opendev.org/760455 | 20:57 |
openstackgerrit | Lee Yarwood proposed openstack/nova master: WIP scheduler: Add an ephemeral encryption pre filter https://review.opendev.org/760456 | 20:57 |
*** legochen has joined #openstack-nova | 21:03 | |
*** nweinber_ has quit IRC | 21:10 | |
*** vesper11 has joined #openstack-nova | 21:14 | |
*** xinranwang has quit IRC | 21:21 | |
*** vesper has joined #openstack-nova | 21:35 | |
*** vesper11 has quit IRC | 21:36 | |
*** tosky has joined #openstack-nova | 21:57 | |
sean-k-mooney | lyarwood: wait why are rsa keys not accepted | 22:20 |
sean-k-mooney | oh its just rsa with sha1 | 22:21 |
sean-k-mooney | rsa-sha2-512/256 should be accpeted | 22:22 |
sean-k-mooney | https://bugzilla.redhat.com/show_bug.cgi?id=1881301 really does seam like a bug | 22:23 |
openstack | bugzilla.redhat.com bug 1881301 in openssh "openssh-clients do not accept PubkeyAcceptedKeyTypes rsa-sha2-512/256" [Unspecified,Post] - Assigned to jjelen | 22:23 |
sean-k-mooney | ECDSA isnt nessisarlly more secure then rsa dpening on the key lenght | 22:24 |
*** slaweq has joined #openstack-nova | 22:27 | |
sean-k-mooney | NIST SP800-90 Dual Ec for example should not be used https://en.wikipedia.org/wiki/Dual_EC_DRBG | 22:30 |
sean-k-mooney | https://en.wikipedia.org/wiki/EdDSA#Ed25519 and https://en.wikipedia.org/wiki/Curve448 are secure and standraised in https://tools.ietf.org/html/rfc7748 i assume fedora has disabled the orginil nist algortiom | 22:38 |
*** slaweq has quit IRC | 22:42 | |
*** rchurch has quit IRC | 22:43 | |
*** rchurch has joined #openstack-nova | 22:45 | |
*** hamalq has quit IRC | 22:57 | |
*** rcernin has joined #openstack-nova | 22:58 | |
*** rcernin has quit IRC | 23:00 | |
*** rcernin has joined #openstack-nova | 23:00 | |
*** ociuhandu has joined #openstack-nova | 23:09 | |
*** ociuhandu has quit IRC | 23:13 | |
*** slaweq has joined #openstack-nova | 23:22 | |
*** jmlowe has quit IRC | 23:24 | |
*** jmlowe has joined #openstack-nova | 23:24 | |
*** mlavalle has quit IRC | 23:30 | |
*** spatel has joined #openstack-nova | 23:47 | |
*** slaweq has quit IRC | 23:55 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!