[Cinder][Glance][Image Encryption] Discussion about the handling of images with old "cinder_encryption_*"-parameters
Hi everyone, because we will rename some parameters in encrypted images, we should discuss the transition from the old Glance image metadata naming (|cinder_encryption_*|) to the new one (|os_encrypt_*|). Glance and Cinder are affected: * |*_key_deletion_policy| is used to delete Barbican secrets; if Glance and Cinder use different namings here, secret is not properly deleted * if Cinder still uses |cinder_encryption_*|, secret consumers are not registered as the image is not detected as encrypted by Glance * Old image with old parameters may not be detected anymore by Cinder, as soon as the new code is rolled out It may be advisable to introduce a deprecation period and make Glance and Cinder still accept the old metadata names when parsing image metadata. The image encrpytion pop-up team is meeting next Monday 13 UTC in IRC (in openstack-meeting). We can discuss it then, please join the meeting. greetings Luzi
participants (1)
-
Josephine Seifert