Monday, 2024-04-15

Luzi#startmeeting image_encryption13:04
opendevmeetMeeting started Mon Apr 15 13:04:45 2024 UTC and is due to finish in 60 minutes.  The chair is Luzi. Information about MeetBot at http://wiki.debian.org/MeetBot.13:04
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.13:04
opendevmeetThe meeting name has been set to 'image_encryption'13:04
Luzi#topic Roll Call13:04
fungiahoy!13:04
Luzihi13:04
Luzi#topic Image Encryption Spec13:05
LuziSo in the PTG the Nova team approached the Cinder and Glance team with new requirements and ideas for the image encryption.13:05
fungiis there a summary of the new requirements?13:07
LuziWhen we started to evaluate the image encryption a few years ago the tooling to encrypt images with LUKS for endusers were not easy and would have required root privilege and other things13:07
Luzinow qemu has tooling which makes it easier, and my colleague already tested it13:08
fungioh very cool13:08
Luzias Nova and Cinder both use LUKS encryption especially Nonva would like to not have to convert between gpg and LUKS13:08
Luziso with this "new" qemu features and Glance being just a storage for images, we agreed to rework the whole spec to use LUKS instead of GPG13:09
Luziin that way, there are no decrypting mechanisms needed in nova - and cinder will only need to convert from qcow2-LUKS to raw LUKS blocks13:10
Luzi(as far as i did understand it)13:10
fungisounds more efficient too13:10
Luziyeah13:10
Luzibut we still need to standardize all possible metadata in glance and look through all possible workflows13:11
Luziso I wrote a new Spec that incorporates this.13:11
Luzi#link https://review.opendev.org/c/openstack/glance-specs/+/91572613:12
LuziIt is also very fortunate to have the Secret Consumers in Barbican, because we will still need them13:12
Luzithey may even get a bigger role13:13
Luziso... that is a big change13:13
fungiindeed13:13
fungithanks for the update!13:13
Luzibut in the end we hope that with the alignment in all services we will have better overall workflows13:14
fungithe end result sounds like it will be easier to maintain long-term at least13:14
Luziyea13:14
Luzialthough - this could have happened a bit earlier for my taste :D13:14
fungiof course13:15
fungiit's a significant course change which invalidates a lot of earlier work13:15
Luziwell - I will focus on getting the patch through and looking into Cinder and what work need to be done there13:15
fungimaybe this will at least help increase the review priority for the new parts13:16
Luzioverall the feature will be smaller and more easy to review13:16
Luziwhich is good i think13:16
Luziyeah13:17
Luzi#topic Open Discussion13:18
Luzido you have anything you want to talk about?13:18
fungii did not, but other than the new nova requirements was there anything else useful to come out of ptg discussions about image encryption?13:20
Luzihm some things in how nova and cinder are handling the passphrase or key to encrypt decrypt their LUKS - but I think that is mainly a part on their sides, we would focus on Glance13:23
Luzi#link https://etherpad.opendev.org/p/dalmatian-ptg-cinder#L39313:24
fungiinteresting, that's useful to note in the design, i guess13:25
fungithanks!13:25
Luziokay, anything else?13:26
funginothing on my end, nope13:27
Luziokay, thank you for joining this meeting and have a nice week13:28
fungithanks, you too!13:28
Luzi#endmeeting image_encryption13:28
opendevmeetMeeting ended Mon Apr 15 13:28:46 2024 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)13:28
opendevmeetMinutes:        https://meetings.opendev.org/meetings/image_encryption/2024/image_encryption.2024-04-15-13.04.html13:28
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/image_encryption/2024/image_encryption.2024-04-15-13.04.txt13:28
opendevmeetLog:            https://meetings.opendev.org/meetings/image_encryption/2024/image_encryption.2024-04-15-13.04.log.html13:28

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!