*** mlavalle has quit IRC | 00:02 | |
*** _erlon_ has quit IRC | 00:16 | |
*** sapd1 has quit IRC | 00:38 | |
*** pmannidi has joined #openstack-nova | 00:40 | |
*** cz3 has joined #openstack-nova | 00:41 | |
*** swp20 has joined #openstack-nova | 00:41 | |
*** martinkennelly has quit IRC | 00:44 | |
*** LinPeiWen has joined #openstack-nova | 00:45 | |
openstackgerrit | norman shen proposed openstack/nova-specs master: Speed up server details https://review.opendev.org/c/openstack/nova-specs/+/791620 | 00:46 |
---|---|---|
*** alex_xu_ has joined #openstack-nova | 00:50 | |
*** swp20 has quit IRC | 00:52 | |
*** alex_xu_ has quit IRC | 00:56 | |
*** alex_xu_ has joined #openstack-nova | 01:12 | |
openstackgerrit | norman shen proposed openstack/nova-specs master: Speed up server details https://review.opendev.org/c/openstack/nova-specs/+/791620 | 01:15 |
*** LinPeiWen has quit IRC | 01:16 | |
*** __ministry has joined #openstack-nova | 01:20 | |
openstackgerrit | Wenping Song proposed openstack/nova-specs master: Add no user token when get Cyborg client https://review.opendev.org/c/openstack/nova-specs/+/787178 | 01:30 |
*** melwitt has quit IRC | 01:55 | |
*** swp20 has joined #openstack-nova | 01:56 | |
*** melwitt has joined #openstack-nova | 01:56 | |
*** brinzhang has joined #openstack-nova | 01:56 | |
*** xinranwang has joined #openstack-nova | 01:58 | |
*** swp20 is now known as wenpingsong | 01:59 | |
*** melwitt has quit IRC | 02:09 | |
*** melwitt has joined #openstack-nova | 02:10 | |
*** k_mouza has joined #openstack-nova | 02:16 | |
*** k_mouza has quit IRC | 02:20 | |
*** LinPeiWen has joined #openstack-nova | 02:21 | |
*** hamalq has quit IRC | 02:24 | |
openstackgerrit | Kevin Zhao proposed openstack/nova master: Support Cpu Compararion on Aarch64 Platform https://review.opendev.org/c/openstack/nova/+/763928 | 02:24 |
*** hamalq has joined #openstack-nova | 02:24 | |
*** amodi has quit IRC | 02:50 | |
*** vegarl has quit IRC | 02:50 | |
*** ozzzo has quit IRC | 02:50 | |
*** yoctozepto has quit IRC | 02:50 | |
*** jlvillal has quit IRC | 02:50 | |
*** hack-char has quit IRC | 02:50 | |
*** BLZbubba has quit IRC | 02:50 | |
*** jlvillal has joined #openstack-nova | 02:50 | |
*** ozzzo has joined #openstack-nova | 02:50 | |
*** vegarl has joined #openstack-nova | 02:50 | |
*** yoctozepto has joined #openstack-nova | 02:50 | |
*** hack-char has joined #openstack-nova | 02:50 | |
*** BLZbubba has joined #openstack-nova | 02:50 | |
*** alex_xu has quit IRC | 02:52 | |
*** alex_xu_ has quit IRC | 02:59 | |
*** alex_xu has joined #openstack-nova | 03:00 | |
*** mkrai has joined #openstack-nova | 03:02 | |
*** hamalq has quit IRC | 03:10 | |
*** hamalq has joined #openstack-nova | 03:11 | |
*** amodi has joined #openstack-nova | 03:13 | |
*** wenpingsong has quit IRC | 03:18 | |
*** vishalmanchanda has joined #openstack-nova | 03:34 | |
*** hamalq has quit IRC | 03:40 | |
*** hamalq has joined #openstack-nova | 03:41 | |
*** alex_xu has quit IRC | 03:48 | |
*** hamalq has quit IRC | 03:50 | |
*** hamalq has joined #openstack-nova | 03:51 | |
*** mkrai has quit IRC | 03:59 | |
*** mkrai has joined #openstack-nova | 04:01 | |
*** hamalq has quit IRC | 04:07 | |
*** ratailor has joined #openstack-nova | 04:45 | |
*** links has joined #openstack-nova | 04:46 | |
*** ratailor has quit IRC | 04:55 | |
*** ratailor has joined #openstack-nova | 04:59 | |
*** xinranwang has quit IRC | 05:04 | |
*** ratailor_ has joined #openstack-nova | 05:16 | |
*** ratailor has quit IRC | 05:19 | |
*** pmannidi has quit IRC | 05:43 | |
*** pmannidi has joined #openstack-nova | 05:45 | |
*** brinzhang has quit IRC | 05:47 | |
*** mnasiadka has left #openstack-nova | 05:57 | |
openstackgerrit | norman shen proposed openstack/nova master: Saving security group to info_cache https://review.opendev.org/c/openstack/nova/+/786348 | 06:11 |
*** arne_wiebalck has quit IRC | 06:20 | |
*** arne_wiebalck has joined #openstack-nova | 06:20 | |
openstackgerrit | norman shen proposed openstack/nova master: Saving security group to info_cache https://review.opendev.org/c/openstack/nova/+/786348 | 06:31 |
*** lpetrut has joined #openstack-nova | 06:32 | |
*** lpetrut has quit IRC | 06:35 | |
*** alex_xu has joined #openstack-nova | 06:40 | |
*** dklyle has quit IRC | 06:43 | |
*** ralonsoh has joined #openstack-nova | 06:47 | |
*** ratailor__ has joined #openstack-nova | 07:06 | |
*** ratailor_ has quit IRC | 07:09 | |
*** mkrai has quit IRC | 07:11 | |
openstackgerrit | norman shen proposed openstack/nova master: Saving security group to info_cache https://review.opendev.org/c/openstack/nova/+/786348 | 07:16 |
*** tosky has joined #openstack-nova | 07:18 | |
*** rpittau|afk is now known as rpittau | 07:22 | |
*** andrewbonney has joined #openstack-nova | 07:34 | |
*** alex_xu has quit IRC | 07:34 | |
lyarwood | gibi: https://review.opendev.org/c/openstack/nova/+/790660 - I just W+'d this again after the rebase btw | 07:53 |
* lyarwood is getting bored of gate failures this week | 07:53 | |
lyarwood | gibi: https://review.opendev.org/c/openstack/nova/+/793219/ can you take a look at this so ^ can land? | 07:53 |
openstackgerrit | norman shen proposed openstack/nova master: Saving security group to info_cache https://review.opendev.org/c/openstack/nova/+/786348 | 08:07 |
*** lucasagomes has joined #openstack-nova | 08:09 | |
bauzas | lyarwood: I can take a look | 08:10 |
lyarwood | thanks | 08:10 |
*** k_mouza has joined #openstack-nova | 08:16 | |
*** martinkennelly has joined #openstack-nova | 08:16 | |
*** avolkov has joined #openstack-nova | 08:19 | |
*** k_mouza has quit IRC | 08:21 | |
gibi | lyarwood: looking too | 08:23 |
openstackgerrit | Merged openstack/nova-specs master: QoS minimum guaranteed packet rate https://review.opendev.org/c/openstack/nova-specs/+/785014 | 08:31 |
*** ttx has quit IRC | 08:33 | |
*** ttx has joined #openstack-nova | 08:34 | |
bauzas | sean-k-mooney: sorry, I didn't wanted to hold the pps spec from gibi when I said 'I'll look at the spec' | 08:50 |
bauzas | sean-k-mooney: it was just for knowing what was your concern | 08:50 |
bauzas | anyway, merged now :) | 08:51 |
openstackgerrit | norman shen proposed openstack/nova master: Saving security group to info_cache https://review.opendev.org/c/openstack/nova/+/786348 | 08:52 |
gibi | bauzas,sean-k-mooney: thanks | 08:57 |
gibi | I have feedback from Rodolfo on the neutron side so I will continue with that | 08:57 |
*** dosaboy has quit IRC | 09:04 | |
openstackgerrit | norman shen proposed openstack/nova master: Saving security group to info_cache https://review.opendev.org/c/openstack/nova/+/786348 | 09:19 |
*** mkrai has joined #openstack-nova | 09:27 | |
*** mgoddard has joined #openstack-nova | 09:35 | |
openstackgerrit | norman shen proposed openstack/nova master: Saving security group to info_cache https://review.opendev.org/c/openstack/nova/+/786348 | 09:41 |
openstackgerrit | Dmitrii Shcherbakov proposed openstack/nova-specs master: Integration With Off-path Network Backends https://review.opendev.org/c/openstack/nova-specs/+/787458 | 09:43 |
openstackgerrit | Lee Yarwood proposed openstack/nova stable/wallaby: image_meta: Provide image_ref as the id when fetching from instance https://review.opendev.org/c/openstack/nova/+/793354 | 09:54 |
*** k_mouza has joined #openstack-nova | 09:59 | |
*** k_mouza has quit IRC | 10:01 | |
*** k_mouza has joined #openstack-nova | 10:01 | |
*** k_mouza has quit IRC | 10:01 | |
*** k_mouza has joined #openstack-nova | 10:02 | |
openstackgerrit | Lee Yarwood proposed openstack/nova stable/victoria: libvirt: make cross cell resize spawn from snapshot image https://review.opendev.org/c/openstack/nova/+/793356 | 10:02 |
openstackgerrit | Lee Yarwood proposed openstack/nova stable/victoria: image_meta: Provide image_ref as the id when fetching from instance https://review.opendev.org/c/openstack/nova/+/793357 | 10:02 |
slaweq | lyarwood: hi, can You maybe check https://review.opendev.org/c/openstack/nova/+/787252 ? | 10:26 |
slaweq | thx in advance | 10:26 |
openstackgerrit | norman shen proposed openstack/nova master: Saving security group to info_cache https://review.opendev.org/c/openstack/nova/+/786348 | 10:31 |
*** macz_ has joined #openstack-nova | 10:32 | |
*** macz_ has quit IRC | 10:36 | |
*** avolkov has quit IRC | 10:38 | |
*** mgoddard has quit IRC | 10:41 | |
*** k_mouza has quit IRC | 10:43 | |
*** k_mouza has joined #openstack-nova | 10:46 | |
*** jangutter has joined #openstack-nova | 10:48 | |
openstackgerrit | Lee Yarwood proposed openstack/nova stable/ussuri: Add regression test for bug #1928063 https://review.opendev.org/c/openstack/nova/+/793372 | 10:49 |
openstackgerrit | Lee Yarwood proposed openstack/nova stable/ussuri: libvirt: make cross cell resize spawn from snapshot image https://review.opendev.org/c/openstack/nova/+/793373 | 10:49 |
openstackgerrit | Lee Yarwood proposed openstack/nova stable/ussuri: image_meta: Provide image_ref as the id when fetching from instance https://review.opendev.org/c/openstack/nova/+/793374 | 10:49 |
openstack | bug 1928063 in OpenStack Compute (nova) "SEV enabled instance unable to hard reboot" [Medium,In progress] https://launchpad.net/bugs/1928063 - Assigned to Lee Yarwood (lyarwood) | 10:49 |
*** jangutter has quit IRC | 10:50 | |
*** mkrai has quit IRC | 10:55 | |
*** hoonetorg has quit IRC | 11:05 | |
*** jangutter has joined #openstack-nova | 11:15 | |
*** jangutter has quit IRC | 11:26 | |
*** jangutter has joined #openstack-nova | 11:34 | |
*** k_mouza has quit IRC | 11:40 | |
*** k_mouza has joined #openstack-nova | 11:40 | |
*** hoonetorg has joined #openstack-nova | 11:58 | |
*** mgoddard has joined #openstack-nova | 12:00 | |
*** tesseract has joined #openstack-nova | 12:15 | |
openstackgerrit | norman shen proposed openstack/nova master: Saving security group to info_cache https://review.opendev.org/c/openstack/nova/+/786348 | 12:57 |
*** jraju__ has joined #openstack-nova | 12:59 | |
*** links has quit IRC | 13:00 | |
*** ociuhandu has joined #openstack-nova | 13:13 | |
*** ratailor__ has quit IRC | 13:15 | |
openstackgerrit | norman shen proposed openstack/nova master: Saving security group to info_cache https://review.opendev.org/c/openstack/nova/+/786348 | 13:23 |
*** viks____ has joined #openstack-nova | 13:32 | |
openstackgerrit | norman shen proposed openstack/nova master: Saving security group to info_cache https://review.opendev.org/c/openstack/nova/+/786348 | 13:43 |
bauzas | gibi: gentle reminder that all the Red Hat folks should be off tomorrow | 13:51 |
bauzas | and like every year, I have this PTO just for my lawn mower... | 13:52 |
gibi | bauzas: thanks for the reminder | 13:54 |
gibi | for all RH folks, have a nice day off! | 13:54 |
*** sapd1 has joined #openstack-nova | 13:56 | |
sean-k-mooney | :) actully im taking monday off too | 14:02 |
*** macz_ has joined #openstack-nova | 14:02 | |
sean-k-mooney | but thank you none the less | 14:02 |
*** macz_ has quit IRC | 14:02 | |
*** links has joined #openstack-nova | 14:05 | |
*** jraju__ has quit IRC | 14:05 | |
*** jawad_axd has quit IRC | 14:07 | |
*** jawad_axd has joined #openstack-nova | 14:07 | |
*** ociuhandu has quit IRC | 14:11 | |
*** jawad_axd has quit IRC | 14:12 | |
*** martinkennelly has quit IRC | 14:17 | |
*** ociuhandu has joined #openstack-nova | 14:19 | |
openstackgerrit | norman shen proposed openstack/nova master: Saving security group to info_cache https://review.opendev.org/c/openstack/nova/+/786348 | 14:20 |
*** jawad_axd has joined #openstack-nova | 14:38 | |
*** mgariepy has quit IRC | 14:43 | |
*** dklyle has joined #openstack-nova | 14:55 | |
*** mgariepy has joined #openstack-nova | 14:57 | |
*** pmannidi has quit IRC | 14:59 | |
*** macz_ has joined #openstack-nova | 15:05 | |
*** macz_ has quit IRC | 15:05 | |
*** jawad_axd has quit IRC | 15:13 | |
openstackgerrit | norman shen proposed openstack/nova master: Saving security group to info_cache https://review.opendev.org/c/openstack/nova/+/786348 | 15:15 |
* lyarwood is off on both Friday and Monday FWIW | 15:20 | |
*** macz_ has joined #openstack-nova | 15:24 | |
*** mgoddard has quit IRC | 15:25 | |
*** masayukig has quit IRC | 15:33 | |
*** tinwood has quit IRC | 15:33 | |
*** DinaBelova has quit IRC | 15:33 | |
*** masayukig has joined #openstack-nova | 15:34 | |
*** tinwood has joined #openstack-nova | 15:34 | |
*** DinaBelova has joined #openstack-nova | 15:34 | |
melwitt | same for me | 15:34 |
*** cz3 has quit IRC | 15:36 | |
melwitt | lyarwood: sorry if this has been mentioned before but are you familiar with this failure setting up ceph "Error EPERM: configuring pool size as 1 is disabled by default." this is on stable/victoria https://zuul.opendev.org/t/openstack/build/7de187da76af48aab23337c4f9d16f9c/log/job-output.txt#5403 | 15:36 |
*** masterpe has quit IRC | 15:38 | |
*** sean-k-mooney[m] has quit IRC | 15:39 | |
*** lyarwood has quit IRC | 15:39 | |
*** macz_ has quit IRC | 15:41 | |
* gibi prepares for the cricket noises for the next 4 days | 15:42 | |
gibi | btw if the IRC cutover happens during the weekend then I will make sure privatly guide people to the other IRC server where our discussions will be logged | 15:42 |
*** ociuhandu has quit IRC | 15:43 | |
*** ociuhandu has joined #openstack-nova | 15:43 | |
*** DinaBelova has quit IRC | 15:44 | |
*** macz_ has joined #openstack-nova | 15:45 | |
*** DinaBelova has joined #openstack-nova | 15:50 | |
*** martinkennelly has joined #openstack-nova | 15:51 | |
*** ociuhandu has quit IRC | 15:51 | |
melwitt | hm maybe that's not actually from setting up ceph | 15:57 |
openstackgerrit | Lee Yarwood proposed openstack/nova master: WIP libvirt: Do not destroy volume secrets during resume_state_on_host_boot https://review.opendev.org/c/openstack/nova/+/793463 | 15:57 |
melwitt | ok it looks like it's failing here https://github.com/openstack/nova/blob/stable/victoria/gate/live_migration/hooks/ceph.sh#L47 | 16:02 |
*** ociuhandu has joined #openstack-nova | 16:03 | |
*** macz_ has quit IRC | 16:03 | |
*** macz_ has joined #openstack-nova | 16:05 | |
*** ociuhandu has quit IRC | 16:08 | |
*** lyarwood has joined #openstack-nova | 16:12 | |
*** rpittau is now known as rpittau|afk | 16:12 | |
melwitt | looks like it's installing the pacific release... that doesn't seem right | 16:13 |
melwitt | it's using the train uca, which is right | 16:13 |
*** ociuhandu has joined #openstack-nova | 16:14 | |
*** ociuhandu has quit IRC | 16:14 | |
melwitt | "Monitors now have config option mon_allow_pool_size_one, which is disabled by default. However, if enabled, user now have to pass the --yes-i-really-mean-it flag to osd pool set size 1, if they are really sure of configuring pool size 1." https://docs.ceph.com/en/latest/releases/pacific/ | 16:19 |
melwitt | there we go. so I guess I first try a recheck and see if the installation of the pacific release was a spurious thing that isn't consistently happening | 16:20 |
* melwitt checks other stable/victoria test runs first | 16:21 | |
*** lyarwood has quit IRC | 16:22 | |
*** macz_ has quit IRC | 16:22 | |
*** tesseract has quit IRC | 16:23 | |
*** macz_ has joined #openstack-nova | 16:24 | |
melwitt | last passing run was on May 21 and was installing the expected release nautilus | 16:25 |
*** lyarwood has joined #openstack-nova | 16:28 | |
*** lucasagomes has quit IRC | 16:29 | |
melwitt | and I do find a few other failures of the same thing since May 25 | 16:29 |
*** mlavalle has joined #openstack-nova | 16:34 | |
*** bnemec has quit IRC | 16:36 | |
melwitt | hm, the ceph version is yellow "version is not current" https://openstack-ci-reports.ubuntu.com/reports/cloud-archive/train_versions.html not sure what that means. the version listed there is the one we want (nautilus) so I don't know why we're getting pacific | 16:37 |
*** masterpe has joined #openstack-nova | 16:39 | |
*** jmlowe has quit IRC | 16:40 | |
*** jmlowe has joined #openstack-nova | 16:41 | |
*** macz_ has quit IRC | 16:42 | |
*** macz_ has joined #openstack-nova | 16:47 | |
gmann | dansmith: did you see my reply on this does it make sense? https://review.opendev.org/c/openstack/nova-specs/+/793011/1/specs/xena/approved/allow-project-admin-list-hypervisors.rst#66 | 16:48 |
*** jawad_axd has joined #openstack-nova | 16:48 | |
dansmith | gmann: I did not | 16:48 |
gmann | k | 16:48 |
gmann | gibi: stephenfin I replied to this comment if I understand it correctly. can you check this - https://review.opendev.org/c/openstack/nova-specs/+/793011/2/specs/xena/approved/allow-project-admin-list-hypervisors.rst#81 | 16:49 |
dansmith | gmann: replied | 16:52 |
*** viks____ has quit IRC | 16:59 | |
*** mgoddard has joined #openstack-nova | 16:59 | |
*** ralonsoh has quit IRC | 17:01 | |
melwitt | gmann, dansmith: I skimmed over that spec on tuesday and was thinking, it depends on how you're defining project-admin. if you're defining it as system-admin scoped down to only a project, then showing the hostnames makes sense. if it's not that, then the obfuscated names make sense. I'm curious what lbragstad would say was the intended meaning/use | 17:01 |
*** hamalq has joined #openstack-nova | 17:01 | |
dansmith | melwitt: yeah, I thought it was more the latter (obviously). I'm not sure what the point of the former is in most cases | 17:02 |
dansmith | I thought the problem was that they wanted some people to be able to violate scheduling restraints and bust locks and reset instance state, but not muck with aggregates and system-level stuff | 17:02 |
melwitt | yeah, I'm not sure. I haven't acquired a solid understanding of what project-admin is supposed to be, from a secure rbac design perspective | 17:03 |
dansmith | I think if you take the public cloud case, we need to know if project-admin is supposed to be a low-level sysadmin on the cloud side, or a high-level power user on the customer side | 17:04 |
dansmith | I have been assuming the latter | 17:04 |
dansmith | I guess the former could be some customer-dedicated support person, but I would expect those cases to be pretty uncommon | 17:05 |
melwitt | yeah. one of the use cases that comes to mind first for me (bc a customer wanted this) was a role where some people could do live migrations but not be admin (live the global admin we have today) | 17:07 |
melwitt | *like the global admin | 17:07 |
dansmith | yeah exactly | 17:07 |
dansmith | that might be a role and not all-of-admin I would think, | 17:07 |
melwitt | so then you will ask, can that live migration person force to a specific host? | 17:08 |
dansmith | but I would guess you mostly want those people migrating to hosts symbolically and not having to know the hostname | 17:08 |
melwitt | I know this is whack but I was just thinking I wonder if it would be legit to use obfuscated host for target host | 17:08 |
*** cz3 has joined #openstack-nova | 17:09 | |
dansmith | I don't think it is today, but I think that if we want to delegate live migration to a non-system-admin, that'd be the goal: let them use the obfuscated host | 17:09 |
melwitt | yeah I doubt it's possible today but I wonder if it would be legit to add it for this project-admin use case | 17:09 |
sean-k-mooney | melwitt: the issue with using the hashed host is reversing it | 17:09 |
dansmith | but, as noted in my follow up a few minutes ago, I think host uuid would be a good compromise.. not project-scoped like the hostid, but otherwise opaque | 17:09 |
dansmith | sean-k-mooney: right, hence using the uuid | 17:10 |
melwitt | ah yeah, that's even better | 17:10 |
dansmith | so assume project admins can be trusted with non-project-scoped host identifiers, but without needing to expose actual dns names to them | 17:10 |
sean-k-mooney | host uuid hum | 17:10 |
sean-k-mooney | is that any safer tehn hostname | 17:11 |
dansmith | they would be able to correlate their hostids to uuids, which regular users can't do, and that would let them collude with other project admins to determine *some* details, | 17:11 |
sean-k-mooney | marginally perhaps | 17:11 |
dansmith | sean-k-mooney: hostnames contain machine model numbers, deployment dates, network and topology details, etc | 17:11 |
sean-k-mooney | ya they can | 17:11 |
dansmith | host123-dl360g1-legacy.old-building.example.com | 17:11 |
sean-k-mooney | i was more thinink about targeting a host form a different project | 17:12 |
sean-k-mooney | to land something on the same host intionally | 17:12 |
dansmith | right, like I said, there's some possibility for collusion between project admins, | 17:12 |
dansmith | but only to co-locate a thing, not to know infra details | 17:12 |
dansmith | and if you're granting the user the ability to target hosts, then you're kinda opening that up a bit anyway | 17:13 |
sean-k-mooney | what about using a semtric key instad of a hash for the host id | 17:13 |
dansmith | you could do it covertly withou the uuid by measuring latency or something | 17:13 |
sean-k-mooney | well rather a reversable key | 17:13 |
dansmith | sean-k-mooney: how is that better? it's reversible, but we still have to calculate it on every query | 17:13 |
sean-k-mooney | it can be asmetic | 17:13 |
sean-k-mooney | we will just have to decyprt it | 17:13 |
dansmith | we could just hash all the things in their aggregate as quick as reversing | 17:13 |
sean-k-mooney | we could yes | 17:14 |
gmann | do not we return host name in GET /servers today? | 17:14 |
dansmith | I bet md5 or whatever we use is fast enough to just do it forwards for every host in their aggregate if we're going to go to that trouble | 17:14 |
gmann | hostID is obfuscated | 17:14 |
dansmith | gmann: no, we return a project-scoped hash of the hostname for non-admins | 17:14 |
melwitt | gmann: we don't unless you're admin admin | 17:14 |
gmann | yeah i mean for admin | 17:14 |
gmann | project admin i mean | 17:14 |
dansmith | gmann: but that's system admin | 17:14 |
dansmith | right now | 17:14 |
sean-k-mooney | gmann: host id is a hach of the host uuid and the porject id | 17:14 |
melwitt | yeah, I would agree the admin of today is a system admin, they can do literally everything | 17:15 |
melwitt | go across projects and all that | 17:15 |
sean-k-mooney | dansmith: are you realisticaly think of adding a project-host mapping table in the nova-api | 17:16 |
gmann | ah right, i thought it is SYSTEM+ Project scoped https://github.com/openstack/nova/blob/master/nova/policies/extended_server_attributes.py#L27 | 17:16 |
dansmith | melwitt: and administer the system at things like the aggregate level | 17:16 |
dansmith | sean-k-mooney: no | 17:16 |
sean-k-mooney | just using the uuid un hased | 17:16 |
sean-k-mooney | *hashed | 17:16 |
dansmith | yeah, I think that's a reasonable compromise | 17:17 |
sean-k-mooney | how would they discover it? | 17:17 |
dansmith | if not, then I think we have to calculate the hash on the fly when we're using a obfuscated directed boot | 17:17 |
melwitt | gmann: yeah that's what I was saying earlier is the root question that would guide what to do here. I do note though that if it were SYSTEM + limited to a project, the hostnames wouldn't be any better than the host uuids right? since you're silo'ed within a project | 17:17 |
dansmith | sean-k-mooney: they can see it in the hypervisors list, that's what the spec is proposing.. to expose that in part to project admins | 17:17 |
sean-k-mooney | right i was wondering if we were going to keep that | 17:18 |
gmann | melwitt: i see | 17:18 |
dansmith | sean-k-mooney: and I'm saying we should do that, but not expose the hostname, and then make the requested_destination take either | 17:18 |
sean-k-mooney | so we would be retrunign only a subset of the columns to them | 17:18 |
dansmith | sean-k-mooney: as we do for server detail | 17:18 |
sean-k-mooney | ok i think that can work | 17:18 |
melwitt | gmann: like I mean, if you're not allowed to migrate a server across a project boundary, I'm not sure what additional the real hostname gets you. or rather do you "need" to know it | 17:18 |
sean-k-mooney | is the uuid the only feild we should show them | 17:19 |
sean-k-mooney | im not sure they need to see uptrime ectra | 17:19 |
dansmith | sean-k-mooney: s/show/hide/ you mean? | 17:19 |
dansmith | sean-k-mooney: they need most of what hypervisors show them in terms of used/free memory to make a decision I think, but yeah we could hide more in there | 17:19 |
dansmith | sean-k-mooney: you should go review the spec :) | 17:19 |
gmann | dansmith: sean-k-mooney we can show with 'None or 'Unknown' value and keep response field consistent | 17:20 |
sean-k-mooney | its on my list but i was also going to finish up soon | 17:20 |
dansmith | gmann: unknown isn't right, but maybe "<hidden>" or something | 17:20 |
sean-k-mooney | gmann: am i would prefer to not have the filed there | 17:20 |
gmann | melwitt: yeah but for booting server we need real name | 17:20 |
*** jawad_axd has quit IRC | 17:20 | |
dansmith | sean-k-mooney: agree, I'd rather just exclude that field | 17:20 |
gmann | yeah <hidden> work | 17:20 |
dansmith | gmann: we would need to make it take hostname or host-uuid | 17:21 |
melwitt | gmann: today you do but we're talking about adding the ability to use the uuid | 17:21 |
dansmith | right | 17:21 |
gmann | sean-k-mooney: but we return those field for system admin and not for project admin is difficult way to read it | 17:21 |
sean-k-mooney | i dont think thats hard | 17:21 |
gmann | melwitt: dansmith yeah i get the point of uuid | 17:21 |
sean-k-mooney | we now have 9 personas | 17:21 |
sean-k-mooney | instead of 2 | 17:21 |
gmann | and obfuscated uuid right | 17:21 |
dansmith | gmann: no, can't be obfuscated | 17:22 |
sean-k-mooney | so we should expect that for some api system admin will see more then project admin | 17:22 |
dansmith | gmann: it's opaque, but not scoped or obfuscated further | 17:22 |
gmann | sean-k-mooney: 7 for nova | 17:22 |
*** k_mouza_ has joined #openstack-nova | 17:22 | |
sean-k-mooney | 7? | 17:23 |
sean-k-mooney | i was expecting 6 or 9 | 17:23 |
sean-k-mooney | either domain has no menaing or it does | 17:23 |
gmann | actually 5. we do not have system member | 17:23 |
gmann | i counted the combination also | 17:23 |
sean-k-mooney | ideally nova itself woudl be runnign as system member but ok | 17:24 |
gmann | dansmith: and having mapping in DB? | 17:24 |
dansmith | gmann: no, no mapping. we'd have to map every project and every host | 17:24 |
sean-k-mooney | gmann: dansmith is suggesting just using the current uuid | 17:25 |
sean-k-mooney | which i think is an ok comprmise | 17:25 |
dansmith | gmann: using the uuid lets us look up t he host in O(1), which is what we want. It exposes a 1:1 identifier that the project admin can use, but without any details that are often embedded in hostnames | 17:25 |
*** k_mouza has quit IRC | 17:25 | |
sean-k-mooney | its slightly better then the hostname for the reason he gave above | 17:25 |
sean-k-mooney | but still allows effiecnt scheduling | 17:26 |
dansmith | right | 17:26 |
gmann | and with uuid non-admn or project admin cannot get host detail so make sense | 17:26 |
dansmith | right | 17:26 |
gmann | got it | 17:26 |
sean-k-mooney | ya we would reject a /hypervior/detail request with a project admin token | 17:26 |
dansmith | you're exposing a little more of the system to the project-admin, so they can direct servers, but not everything that a hostname might encode in it | 17:27 |
dansmith | sean-k-mooney: no, we have to support that | 17:27 |
gmann | btw why we do obfuscated hostID in GET API ? | 17:27 |
dansmith | sean-k-mooney: they want to be able to see some details of the hosts | 17:27 |
sean-k-mooney | well ok yes | 17:27 |
sean-k-mooney | but not all the fileds | 17:27 |
dansmith | gmann: so that users can't tell that they are on the same host across coke/pepsi | 17:27 |
gmann | ohk, | 17:27 |
openstackgerrit | Lee Yarwood proposed openstack/nova master: WIP libvirt: Do not destroy volume secrets during _hard_reboot https://review.opendev.org/c/openstack/nova/+/793463 | 17:28 |
dansmith | gmann: okay, so .. all good? | 17:28 |
gmann | one last one, on new policy | 17:29 |
sean-k-mooney | there is one other advantage | 17:29 |
*** andrewbonney has quit IRC | 17:29 | |
gmann | this one https://review.opendev.org/c/openstack/nova-specs/+/793011/2/specs/xena/approved/allow-project-admin-list-hypervisors.rst#41 | 17:29 |
sean-k-mooney | if im not mistaken we do not support using the uuid with the old az hack | 17:29 |
gmann | any objection on adding new policy to let operator to list all hypervisors ? | 17:29 |
sean-k-mooney | so they can bypass the sculder with --availabit-zone <zone>:<hostname> | 17:29 |
sean-k-mooney | if we give the the uuid right | 17:30 |
dansmith | gmann: no, I think that makes sense if they want to allow that | 17:30 |
*** hamalq has quit IRC | 17:30 | |
gmann | cool | 17:30 |
gmann | I will update the spec accordingly. | 17:31 |
gmann | thanks dansmith melwitt sean-k-mooney | 17:31 |
*** hamalq has joined #openstack-nova | 17:31 | |
dansmith | gmann: cool, sorry for missing your reply earlier | 17:31 |
sean-k-mooney | oh to remove the aggreate metadtata requirement | 17:31 |
sean-k-mooney | form an end user perspecitv i would not be able to tell the diffrenece | 17:31 |
gmann | dansmith: np! I too missed to ask that day itself. | 17:31 |
sean-k-mooney | so that policy would not be an interop issue so i think its ok to add one yes | 17:32 |
sean-k-mooney | ok i am going to finish up for the day. ill see everyon on our new home on tuesday o/ | 17:33 |
dansmith | sean-k-mooney: enjoy o/ | 17:33 |
melwitt | have a good weekend o/ | 17:33 |
*** sean-k-mooney has quit IRC | 17:34 | |
dansmith | wow | 17:35 |
dansmith | not used to seeing that :P | 17:35 |
melwitt | 😆 | 17:37 |
artom | He's been making big improvement in keeping a regular work schedule | 17:39 |
artom | (I sound like his dad) | 17:39 |
gmann | lucky redhatters :) long weekend | 17:39 |
gmann | I miss Tokyo in that term for many long weekend and three golden weeks in a year | 17:40 |
*** macz_ has quit IRC | 17:58 | |
*** bnemec has joined #openstack-nova | 18:02 | |
*** macz_ has joined #openstack-nova | 18:16 | |
*** hamalq has quit IRC | 18:20 | |
*** hamalq has joined #openstack-nova | 18:21 | |
*** iurygregory has quit IRC | 18:25 | |
*** k_mouza_ has quit IRC | 18:26 | |
*** k_mouza has joined #openstack-nova | 19:04 | |
*** k_mouza has quit IRC | 19:25 | |
*** k_mouza has joined #openstack-nova | 19:26 | |
*** k_mouza_ has joined #openstack-nova | 19:31 | |
*** k_mouza has quit IRC | 19:31 | |
*** k_mouza has joined #openstack-nova | 19:31 | |
*** k_mouza__ has joined #openstack-nova | 19:34 | |
*** k_mouza_ has quit IRC | 19:34 | |
*** k_mouza has quit IRC | 19:37 | |
*** k_mouza has joined #openstack-nova | 19:38 | |
*** artom has quit IRC | 19:39 | |
*** k_mouza_ has joined #openstack-nova | 19:39 | |
*** k_mouza__ has quit IRC | 19:41 | |
*** k_mouza has quit IRC | 19:43 | |
*** k_mouza has joined #openstack-nova | 19:43 | |
*** k_mouza_ has quit IRC | 19:47 | |
*** jawad_axd has joined #openstack-nova | 19:54 | |
*** jawad_axd has quit IRC | 19:58 | |
*** flaviof has left #openstack-nova | 20:04 | |
*** eharney has quit IRC | 20:10 | |
*** slaweq has quit IRC | 20:32 | |
*** iurygregory has joined #openstack-nova | 20:49 | |
*** hamalq has quit IRC | 20:51 | |
*** hamalq has joined #openstack-nova | 20:51 | |
*** vishalmanchanda has quit IRC | 20:54 | |
*** links has quit IRC | 20:55 | |
*** jmlowe has quit IRC | 20:58 | |
*** jmlowe has joined #openstack-nova | 21:00 | |
*** jawad_axd has joined #openstack-nova | 21:42 | |
*** slaweq has joined #openstack-nova | 21:48 | |
*** cz3 has quit IRC | 22:10 | |
*** hamalq has quit IRC | 22:11 | |
*** hamalq has joined #openstack-nova | 22:12 | |
*** jawad_axd has quit IRC | 22:16 | |
*** slaweq has quit IRC | 22:24 | |
*** macz_ has quit IRC | 23:07 | |
*** tosky has quit IRC | 23:12 | |
*** pmannidi has joined #openstack-nova | 23:17 | |
openstackgerrit | Ghanshyam proposed openstack/nova-specs master: Allow project admin to list hypervisors https://review.opendev.org/c/openstack/nova-specs/+/793011 | 23:23 |
gmann | dansmith: melwitt ^^ | 23:23 |
*** jawad_axd has joined #openstack-nova | 23:34 | |
*** mlavalle has quit IRC | 23:47 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!