[Image-Encryption] current state
Hi from the image-encryption-popupteam, we would like to provide a summary of what happened during the last year: 1. Secret Consumers in Barbican [1] As a foundation for the image encryption - and to not accidentally delete a secret, which is still in use - the Barbican team implemented the secret consumers. Their is still some work ongoing for the API part. We will use this feature whenever a image will be encrypted. 2. Specs We wrote Specs to describe, what we Image Encryption is and how it would affect Glance, Cinder and Nova. The Cinder spec got merged [2] . The Glance spec is still being reviewed [3]. And the nova spec is abandoned [4]. Nova is currently not part anymore, because of a missing ephemeral storage encryption needed for a coherent security mode. 3. WIP-patches We implemented two WIP-patches to let Glance devs get a better idea of how image encryption is affecting Glance. We provided a patch for Glance [5] and one for os-brick [6], which handles the encryption and decryption of images. [1] https://review.opendev.org/#/q/project:openstack/barbican+secret-consumer [2] https://review.opendev.org/#/c/608663/ [3] https://review.opendev.org/#/c/609667/11 [4] https://review.opendev.org/#/c/608696/ [5] https://review.opendev.org/#/c/705445/ [6] https://review.opendev.org/#/c/709432/ We appreciate reviews on the spec and the WIP-patches. greetings Josephine (Luzi) & Markus (mhen)
On 2020-06-19 13:46:35 +0200 (+0200), Josephine Seifert wrote:
Hi from the image-encryption-popupteam,
we would like to provide a summary of what happened during the last year: [...snip all the really good stuff...]
Thanks for putting this together; it's a really great way to catch the rest of the community up on your progress. Occasional summaries like this are especially important in long-running cross-project efforts, so that representatives of individual teams better understand where the specs and implementation they're reviewing fit into the bigger picture. It's also a benefit to prospective users, who can see measurable progress and may even be encouraged to get involved and prioritize assistance from within their respective organizations. -- Jeremy Stanley
participants (2)
-
Jeremy Stanley
-
Josephine Seifert