[openstack-dev] [nova] key management and Cinder volume encryption

Bryan D. Payne bdpayne at acm.org
Wed Sep 4 13:46:57 UTC 2013


> External dependencies are fine, obviously.  The difference is whether we
> actually have code to interface with those external dependencies.  We
> have code to talk to databases and message queues.  There's no code
> right now to interface with anything for key management.
>

Ok, this makes sense.  I generally assume that people deploying OpenStack
have some integration work to do anyway.  So, for me, writing a few python
methods isn't much different than writing a configuration file.  Having
said this, I do understand where you are coming from here.

I do believe that a static key configuration is a useful starting place for
a lot of users.  I spoke with Joel this morning and I think he is going to
try to put together an example key management driver that does this today.
 Such a solution would allow deployers to use their existing orchestration
tools to write a key to a configuration file.

Cheers,
-bryan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstack.org/pipermail/openstack-dev/attachments/20130904/82d2f2b5/attachment.html>


More information about the OpenStack-dev mailing list