[openstack-dev] [nova] key management and Cinder volume encryption

Russell Bryant rbryant at redhat.com
Tue Sep 3 22:31:11 UTC 2013


On 09/03/2013 05:41 PM, Coffman, Joel M. wrote:
>> How can someone use your code without a key manager?
> 
> Some key management mechanism is required although it could be
> simplistic. For example, we’ve tested our code internally with an
> implementation of the key manager interface that returns a single,
> constant key.

I understand Joe's concern.  I've used a similar argument to turn down
other features.  I generally want *everything* we merge to be usable
with the code in the tree.  If it's not usable, I push to have it wait
until it is.

In this case, it's obviously something we should have caught and brought
up earlier.  If there is any possible way a simple implementation of the
key manager interface could be included, then that could probably save
this for Havana.  We could consider a feature freeze exception to give
it a few extra days, but not more than that.

Otherwise, as much as I really hate to say it, this will probably have
to get deferred.

-- 
Russell Bryant



More information about the OpenStack-dev mailing list