Wednesday, 2024-05-22

opendevreviewMerged openstack/nova master: [doc] Improve description for nova-manage db purge  https://review.opendev.org/c/openstack/nova/+/91974602:44
opendevreviewRajesh Tailor proposed openstack/nova master: Handle neutron-client conflict  https://review.opendev.org/c/openstack/nova/+/91804807:06
zigoHi. Is it still the case that VMs with SEV cannot be live-migrated?12:36
sean-k-mooneyim pretty sure we supprote sev live migration in the inital release12:46
sean-k-mooneyoh apprently not https://docs.openstack.org/nova/latest/admin/sev.html#impermanent-limitations12:46
zigoThat's not what the doc says indeed.12:46
sean-k-mooneywe have not modifyied it but the only reason we woudl not have supported it orginally is if qemu did not supprot it12:47
sean-k-mooneyhttps://lore.kernel.org/all/20190809185434.GH2840@work-vm/T/ there was a patch to enabel it12:48
sean-k-mooneybut i dont know if that ever merged12:48
sean-k-mooneystill listed as todo https://www.qemu.org/docs/master/system/i386/amd-memory-encryption.html#live-migration12:48
tkajinamzigo, as you said the patch has never been merged. sev_mig_blocker is still present in the latest qemu.12:58
tkajinamI'm not aware of any work to implement live migration for SEV instances recently. I guess AMD put more focus on SEV-SNP now12:59
tkajinamIntel is working to implement live migration support in Intel TDX 1.5 . I don't know how long it would take until it reaches upstream (tdx 1.0 is not yet merged upstream afaik) but that's explained explicitly as an upcoming feature13:01
sean-k-mooneytkajinam: well SEV-SNP would depend on live migration supprot for sev in general right13:54
sean-k-mooneyi.e. if amd wanted to supprot live-migration for SEV-SNP i doubt they coudl do that without first closing the general sev gap13:54
zigoOk, thanks for the details.13:55
sean-k-mooneyzigo: on a related not live migration is not currently supproted with vTPM either that is more upsetting as i expect it will be more widely used becasue of microsfot requiring it for windows server13:56
sean-k-mooneyas far as we can tell qemu currently only supprot live migration if you put the vtpm dir on nfs or another shared file system where they do not require the tpm data ot be copied...13:57
zigosean-k-mooney: But the vTPM files are somewhere in /etc/libvirt, no?13:58
sean-k-mooneyby default i think so yes13:59
sean-k-mooneyi woudl have to check the code13:59
sean-k-mooneybut they are not in /var/lib/nova/** as far as i recal13:59
tkajinamsean-k-mooney, yeah I guess so, because SEV-SNP uses SEV as its core with additional protection features > lm support for SEV-SNP would depend on one for SEV14:19
-opendevstatus- NOTICE: There will be a short Gerrit outage while we update to the latest 3.8 release in preparation for next weeks 3.9 upgrade.17:01
opendevreviewsean mooney proposed openstack/nova master: [WIP] retry write_sys call on device busy  https://review.opendev.org/c/openstack/nova/+/92020317:59
opendevreviewMerged openstack/nova-specs master: Remove template files from non-empty directories  https://review.opendev.org/c/openstack/nova-specs/+/91959718:34
opendevreviewMerged openstack/nova master: Stop using split UEC image (mostly)  https://review.opendev.org/c/openstack/nova/+/91973919:03
opendevreviewmelanie witt proposed openstack/nova-specs master: Re-propose specs for ephemeral encryption  https://review.opendev.org/c/openstack/nova-specs/+/90765419:29

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!