<div dir="ltr">We are going to have a design session at the summit entirely dedicated to Murano guest agent security and isolation. Everyone is welcomed to attend and discuss security requirements, concerns and possible solutions.</div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature"><div dir="ltr"><span style="border-collapse:separate;color:rgb(0,0,0);font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;font-size:medium"><span style="font-family:arial;font-size:small">Sincerely yours,<br>Stan Lagun<br>Principal Software Engineer @ Mirantis</span></span><br><span style="border-collapse:separate;color:rgb(0,0,0);font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;font-size:medium"><span style="font-family:arial;font-size:small"><br><a href="mailto:slagun@mirantis.com" target="_blank"></a></span></span></div></div></div>
<br><div class="gmail_quote">On Tue, May 12, 2015 at 8:32 PM, Fox, Kevin M <span dir="ltr"><<a href="mailto:Kevin.Fox@pnnl.gov" target="_blank">Kevin.Fox@pnnl.gov</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div>
<div style="direction:ltr;font-family:Tahoma;color:#000000;font-size:10pt">Barbican has the same issue. If Barbican is for storing secrets, how do you get a secret to the VM so it can get its secrets from Barbican? Aaarrrrggg! :)<br>
<br>
I've been working on a solution here:<br>
<a href="https://blueprints.launchpad.net/barbican/+spec/vm-integration" target="_blank">https://blueprints.launchpad.net/barbican/+spec/vm-integration</a><br>
<br>
We're planning on talking more about that spec at the summit though.<br>
<br>
I've heard through the grape vine that Amazon lets you have a machine account that is associated with the vm. I'm not sure that's true or not, but some kind of keystone account integration into nova might help...<br>
<br>
Thanks,<br>
Kevin<br>
<div style="font-family:Times New Roman;color:#000000;font-size:16px">
<hr>
<div style="direction:ltr"><font color="#000000" face="Tahoma" size="2"><b>From:</b> Georgy Okrokvertskhov [<a href="mailto:gokrokvertskhov@mirantis.com" target="_blank">gokrokvertskhov@mirantis.com</a>]<br>
<b>Sent:</b> Tuesday, May 12, 2015 10:06 AM<br>
<b>To:</b> OpenStack Development Mailing List (not for usage questions)<div><div class="h5"><br>
<b>Subject:</b> Re: [openstack-dev] [Murano] [Mistral] SSH workflow action<br>
</div></div></font><br>
</div><div><div class="h5">
<div></div>
<div>
<div dir="ltr">There is one thing which still bothers me. It is authentication. Right now with separate RabbitMQ instance we keep VMs authentication isolated from OpenStack infra.
<div>This is still a problem if you want to use webhooks (Heat autoscaling, Murano actions) via our own authentication models. If we plan to use Zaqar it will be interesting to know how Zaqar solves this issue. Frankly, I don't think that this is a good idea
to use Keystone credentials or tokens for MQ clients on VMs. This topic, probably, deserves its own e-mail thread.</div>
<div><br>
</div>
<div>It will be interesting to discuss this with Keystone team. What is it is possible to have a token which is restricted to be authenticated to specific API URL like GET /v1/queues/<queue-id>/</div>
<div><br>
</div>
<div><br>
</div>
<div>Thanks</div>
<div>Gosha</div>
<div><br>
</div>
<div><br>
</div>
</div>
<div class="gmail_extra"><br>
<div class="gmail_quote">On Tue, May 12, 2015 at 8:58 AM, Fox, Kevin M <span dir="ltr">
<<a href="mailto:Kevin.Fox@pnnl.gov" target="_blank">Kevin.Fox@pnnl.gov</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
+1<br>
________________________________________<br>
From: Zane Bitter [<a href="mailto:zbitter@redhat.com" target="_blank">zbitter@redhat.com</a>]<br>
Sent: Monday, May 11, 2015 6:15 PM<br>
To: <a href="mailto:openstack-dev@lists.openstack.org" target="_blank">openstack-dev@lists.openstack.org</a><br>
<span>Subject: Re: [openstack-dev] [Murano] [Mistral] SSH workflow action<br>
<br>
</span>
<div>
<div>Hello!<br>
<br>
This looks like a perfect soapbox from which to talk about my favourite<br>
issue ;)<br>
<br>
You're right about the ssh idea, for the reasons discussed related to<br>
networking and a few more that weren't (e.g. users shouldn't have to and<br>
generally don't want to give their private SSH keys to cloud services).<br>
I didn't know, or had forgotten, about the message queue implementation<br>
in Murano and while I think that's the correct shape for the solution,<br>
as long as the service in question is not multi-tenant capable it's a<br>
non-starter for a public clouds at least and probably many private<br>
clouds as well (after all, if you don't need multi-tenancy then why are<br>
you using OpenStack?).<br>
<br>
There's been a tendency within the application-facing OpenStack projects<br>
to hack together whatever local solutions to problems that we can in<br>
order to make progress without being held up by other projects. Let's<br>
take a moment to acknowledge that Heat is both the earliest and the<br>
biggest offender here, and that I am as culpable as anyone in the<br>
current state of affairs. There are multiple reasons for how things have<br>
gone - part of it is that it turned out we developed services in the<br>
wrong order, starting at too high a level. Part of it, frankly, is due<br>
to that element of the community that maintains a hostile position<br>
toward application-facing services and have used their influence in the<br>
community to maintain a disincentive against integrating projects<br>
together.[1] (If deployment of your project is discouraged that's one<br>
thing, but if it depends on another project whose deployment is also<br>
being discouraged then the hurdle you have to jump over is twice the<br>
height.)<br>
<br>
That said, I think we're at the point where we are hurting ourselves<br>
more than anyone else is by failing to come up with coherent,<br>
cross-project solutions.<br>
<br>
The problem articulated in this thread is not an isolated one. It's part<br>
of a more general pattern that affects a lot of projects: we need a way<br>
for the cloud to communicate to applications running in it. Angus<br>
started a recent discussion of this already on the list.[2] The<br>
requirements, IMHO, are roughly:<br>
<br>
* Reliability - we must be able to guarantee delivery to applications<br>
* Asynchrony - the cloud cannot block on user-controlled processes<br>
* Multitenancy - this is table stakes for OpenStack<br>
* Access control - even within tenants, we need to trust guest VMs<br>
minimally<br>
<br>
IMNSHO Zaqar messages are the obvious choice for the transport here. (Or<br>
something very similar in shape to Zaqar - but it'd be much better to<br>
join forces with the Zaqar team to improve it where necessary than to<br>
start a new project.) I really believe that if we work together to come<br>
up with consistent solutions to these problems that keep popping up<br>
across OpenStack, we can prove wrong all the naysayers who think that<br>
application-facing services are only for proprietary clouds. I wrote up<br>
my vision for why that's important and what there first steps are here:<br>
<br>
<a href="http://www.zerobanana.com/archive/2015/04/24#a-vision-for-openstack" target="_blank">http://www.zerobanana.com/archive/2015/04/24#a-vision-for-openstack</a><br>
<br>
Note that there are some subtleties that not everyone here will be able<br>
to contribute directly to fixing. For example, as I highlight in that<br>
post, Keystone is built around the concept that applications never talk<br>
to the cloud. But there are lots of other things people can work on now<br>
that would really make a big difference. For Mistral and Murano<br>
specifically, and in rough order of priority:<br>
<br>
* Add an action in Mistral for sending a message to a Zaqar queue.<br>
This is easy and there's no reason you couldn't do it right now.<br>
* Encourage any deployers and distributors you know (or, ahem, may<br>
work for ;) to make Zaqar available as an option.<br>
* Add a way to trigger a Mistral workflow with a Zaqar message. This<br>
is one piece in the puzzle to build user-configurable messaging flows<br>
between OpenStack services.[3]<br>
* Make Zaqar an alternative to Rabbit for communicating to the Murano<br>
agent.<br>
* Use your experience in implementing notifications over email and the<br>
like in Mistral to help the Zaqar team to add the notification features<br>
they've long been planning. These could take the form of microservices<br>
listening on a Zaqar queue. You get the reliable, asynchronous queuing<br>
semantics for free and *every* service and user can benefit from your work.<br>
<br>
Imagine if there were one place where we implemented reliable queuing<br>
semantics at cloud scale, and when we added e.g. long-polling or<br>
WebSockets everyone could benefit immediately.[4] Imagine if there were<br>
one place for notifications, at cloud scale, for operators to secure.<br>
(How many webhook implementations are there in OpenStack right now? How<br>
many of them are actually secure against malicious users?) One format<br>
for messages between services so that users can connect up their own<br>
custom pipelines. We're not that far away! All of this is within reach<br>
if we work together.<br>
<br>
Thanks for reading. Please grab me at summit if you want to know more; I<br>
am always happy to bend the ear of anyone who will listen at length on<br>
this topic. As usual, I'll be the tall dude with the weird accent ;)<br>
<br>
cheers,<br>
Zane.<br>
<br>
<br>
[1] <a href="https://review.openstack.org/#/c/180112/" target="_blank">https://review.openstack.org/#/c/180112/</a><br>
[2]<br>
<a href="http://lists.openstack.org/pipermail/openstack-dev/2015-April/060748.html" target="_blank">http://lists.openstack.org/pipermail/openstack-dev/2015-April/060748.html</a><br>
[3]<br>
<a href="http://lists.openstack.org/pipermail/openstack-dev/2015-April/062617.html" target="_blank">http://lists.openstack.org/pipermail/openstack-dev/2015-April/062617.html</a><br>
[4]<br>
<a href="http://lists.openstack.org/pipermail/openstack-dev/2015-April/062619.html" target="_blank">http://lists.openstack.org/pipermail/openstack-dev/2015-April/062619.html</a><br>
<br>
<br>
On 06/05/15 11:42, Filip Blaha wrote:<br>
> Hello<br>
><br>
> We are considering implementing actions on services of a murano<br>
> environment via mistral workflows. We are considering whether mistral<br>
> std.ssh action could be used to run some command on an instance. Example<br>
> of such action in murano could be restart action on Mysql DB service.<br>
> Mistral workflow would ssh to that instance running Mysql and run<br>
> "service mysql restart". From my point of view trying to use SSH to<br>
> access instances from mistral workflow is not good<br>
> idea but I would like to confirm it.<br>
><br>
> The biggest problem I see there is openstack networking. Mistral service<br>
> running on some openstack node would not be able to access instance via<br>
> its fixed IP (e.g. 10.0.0.5) via SSH. Instance could accessed via ssh<br>
> from namespace of its gateway router e.g. "ip netns exec qrouter-... ssh<br>
> <a href="mailto:cirros@10.0.0.5" target="_blank">cirros@10.0.0.5</a>" but I think it is not good to rely on implementation<br>
> detail of neutron and use it. In multinode openstack deployment it<br>
> could be even more complicated.<br>
><br>
> In other words I am asking whether we can use std.ssh mistral action to<br>
> access instances via ssh on theirs fixed IPs? I think no but I would<br>
> like to confirm it.<br>
><br>
> Thanks<br>
> Filip<br>
><br>
> __________________________________________________________________________<br>
> OpenStack Development Mailing List (not for usage questions)<br>
> Unsubscribe: <a href="http://OpenStack-dev-request@lists.openstack.org?subject:unsubscribe" target="_blank">
OpenStack-dev-request@lists.openstack.org?subject:unsubscribe</a><br>
> <a href="http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev" target="_blank">
http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev</a><br>
<br>
<br>
__________________________________________________________________________<br>
OpenStack Development Mailing List (not for usage questions)<br>
Unsubscribe: <a href="http://OpenStack-dev-request@lists.openstack.org?subject:unsubscribe" target="_blank">
OpenStack-dev-request@lists.openstack.org?subject:unsubscribe</a><br>
<a href="http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev" target="_blank">http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev</a><br>
<br>
__________________________________________________________________________<br>
OpenStack Development Mailing List (not for usage questions)<br>
Unsubscribe: <a href="http://OpenStack-dev-request@lists.openstack.org?subject:unsubscribe" target="_blank">
OpenStack-dev-request@lists.openstack.org?subject:unsubscribe</a><br>
<a href="http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev" target="_blank">http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev</a><br>
</div>
</div>
</blockquote>
</div>
<br>
<br clear="all">
<div><br>
</div>
-- <br>
<div>
<div dir="ltr"><font color="#999999"><span style="background-color:rgb(255,255,255)">Georgy Okrokvertskhov<br>
Architect,<br>
<span style="font-family:arial;font-size:small">OpenStack Platform Products,</span><br>
Mirantis</span><br>
<a href="http://www.mirantis.com/" target="_blank">http://www.mirantis.com</a><br>
Tel. +1 650 963 9828<br>
Mob. +1 650 996 3284</font><br>
</div>
</div>
</div>
</div>
</div></div></div>
</div>
</div>
<br>__________________________________________________________________________<br>
OpenStack Development Mailing List (not for usage questions)<br>
Unsubscribe: <a href="http://OpenStack-dev-request@lists.openstack.org?subject:unsubscribe" target="_blank">OpenStack-dev-request@lists.openstack.org?subject:unsubscribe</a><br>
<a href="http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev" target="_blank">http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev</a><br>
<br></blockquote></div><br></div>