)]}'
{"id":"openstack%2Fnova-specs~608696","triplet_id":"openstack%2Fnova-specs~master~Ib3519f97ca1c6573462b2216433394e86c013e2a","project":"openstack/nova-specs","branch":"master","topic":"bp/image-encryption","hashtags":[],"change_id":"Ib3519f97ca1c6573462b2216433394e86c013e2a","subject":"Spec for the Nova part of Image Encryption","status":"ABANDONED","created":"2018-10-08 15:01:00.000000000","updated":"2019-12-09 09:53:20.000000000","total_comment_count":109,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"5ca7f98bc775e892b5690ad601d0615166ee779e","_number":608696,"virtual_id_number":608696,"owner":{"_account_id":27665,"name":"Markus Hentsch","email":"markus.hentsch@cloudandheat.com","username":"mhen"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},{"_account_id":4393,"name":"Dan Smith","email":"dms@danplanet.com","username":"danms"},{"_account_id":1004,"name":"Mohammed Naser","email":"mnaser@vexxhost.com","username":"mnaser"},{"value":1,"date":"2019-07-23 12:45:44.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},{"date":"2019-12-09 09:46:36.000000000","_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},{"_account_id":27665,"name":"Markus Hentsch","email":"markus.hentsch@cloudandheat.com","username":"mhen"},{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},{"_account_id":9555,"name":"Matthew Booth","email":"mbooth@redhat.com","username":"MatthewBooth"},{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},{"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"recommended":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"disliked":{"_account_id":9555,"name":"Matthew Booth","email":"mbooth@redhat.com","username":"MatthewBooth"},"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},{"value":-1,"date":"2019-08-05 17:32:57.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":4393,"name":"Dan Smith","email":"dms@danplanet.com","username":"danms"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":1004,"name":"Mohammed Naser","email":"mnaser@vexxhost.com","username":"mnaser"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":27665,"name":"Markus Hentsch","email":"markus.hentsch@cloudandheat.com","username":"mhen"},{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},{"value":-1,"date":"2019-11-07 14:34:09.000000000","permitted_voting_range":{"min":-1,"max":1},"_account_id":9555,"name":"Matthew Booth","email":"mbooth@redhat.com","username":"MatthewBooth"},{"value":1,"date":"2019-07-23 16:03:15.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"date":"2019-08-01 14:14:58.000000000","permitted_voting_range":{"min":-1,"max":1},"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},{"value":-1,"date":"2019-07-29 15:24:24.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","value":-1,"default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":4393,"name":"Dan Smith","email":"dms@danplanet.com","username":"danms"},{"date":"2019-08-01 21:54:38.000000000","_account_id":1004,"name":"Mohammed Naser","email":"mnaser@vexxhost.com","username":"mnaser"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},{"value":0,"permitted_voting_range":{"min":-1,"max":0},"_account_id":27665,"name":"Markus Hentsch","email":"markus.hentsch@cloudandheat.com","username":"mhen"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},{"_account_id":9555,"name":"Matthew Booth","email":"mbooth@redhat.com","username":"MatthewBooth"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},{"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},{"date":"2019-07-25 06:19:38.000000000","_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Review-Priority":{"all":[{"value":0,"permitted_voting_range":{"min":0,"max":1},"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},{"value":0,"permitted_voting_range":{"min":0,"max":2},"_account_id":4393,"name":"Dan Smith","email":"dms@danplanet.com","username":"danms"},{"value":0,"permitted_voting_range":{"min":0,"max":1},"_account_id":1004,"name":"Mohammed Naser","email":"mnaser@vexxhost.com","username":"mnaser"},{"value":0,"permitted_voting_range":{"min":0,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"permitted_voting_range":{"min":0,"max":2},"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},{"value":0,"permitted_voting_range":{"min":0,"max":1},"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},{"value":0,"permitted_voting_range":{"min":0,"max":1},"_account_id":27665,"name":"Markus Hentsch","email":"markus.hentsch@cloudandheat.com","username":"mhen"},{"value":0,"permitted_voting_range":{"min":0,"max":2},"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},{"value":0,"permitted_voting_range":{"min":0,"max":1},"_account_id":9555,"name":"Matthew Booth","email":"mbooth@redhat.com","username":"MatthewBooth"},{"value":0,"permitted_voting_range":{"min":0,"max":2},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"permitted_voting_range":{"min":0,"max":1},"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},{"value":0,"permitted_voting_range":{"min":0,"max":1},"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},{"value":0,"permitted_voting_range":{"min":0,"max":2},"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},{"value":0,"permitted_voting_range":{"min":0,"max":1},"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"}],"values":{" 0":"Default Priority","+1":"Contributor Review Promise","+2":"Core Review Promise"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},{"_account_id":1004,"name":"Mohammed Naser","email":"mnaser@vexxhost.com","username":"mnaser"},{"_account_id":4393,"name":"Dan Smith","email":"dms@danplanet.com","username":"danms"},{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},{"_account_id":9555,"name":"Matthew Booth","email":"mbooth@redhat.com","username":"MatthewBooth"},{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},{"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},{"_account_id":27665,"name":"Markus Hentsch","email":"markus.hentsch@cloudandheat.com","username":"mhen"},{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2018-10-11 13:52:45.000000000","updated_by":{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},"reviewer":{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},"state":"REVIEWER"},{"updated":"2018-11-20 10:37:23.000000000","updated_by":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"reviewer":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"state":"REVIEWER"},{"updated":"2018-12-06 00:16:44.000000000","updated_by":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"reviewer":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"state":"REVIEWER"},{"updated":"2019-07-03 13:08:49.000000000","updated_by":{"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},"reviewer":{"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},"state":"REVIEWER"},{"updated":"2019-07-23 12:45:44.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2019-07-23 16:03:15.000000000","updated_by":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"reviewer":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"state":"REVIEWER"},{"updated":"2019-07-25 06:19:38.000000000","updated_by":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"reviewer":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"state":"REVIEWER"},{"updated":"2019-07-29 15:24:24.000000000","updated_by":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"reviewer":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"state":"REVIEWER"},{"updated":"2019-08-01 14:14:58.000000000","updated_by":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"reviewer":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"state":"REVIEWER"},{"updated":"2019-08-01 21:54:38.000000000","updated_by":{"_account_id":1004,"name":"Mohammed Naser","email":"mnaser@vexxhost.com","username":"mnaser"},"reviewer":{"_account_id":1004,"name":"Mohammed Naser","email":"mnaser@vexxhost.com","username":"mnaser"},"state":"REVIEWER"},{"updated":"2019-08-05 17:32:57.000000000","updated_by":{"_account_id":4393,"name":"Dan Smith","email":"dms@danplanet.com","username":"danms"},"reviewer":{"_account_id":4393,"name":"Dan Smith","email":"dms@danplanet.com","username":"danms"},"state":"REVIEWER"},{"updated":"2019-11-07 14:34:09.000000000","updated_by":{"_account_id":9555,"name":"Matthew Booth","email":"mbooth@redhat.com","username":"MatthewBooth"},"reviewer":{"_account_id":9555,"name":"Matthew Booth","email":"mbooth@redhat.com","username":"MatthewBooth"},"state":"REVIEWER"},{"updated":"2019-12-09 09:46:36.000000000","updated_by":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"reviewer":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"state":"REVIEWER"}],"messages":[{"id":"2c2a37e191f094000a76fd96e3adf23834c9157f","author":{"_account_id":27665,"name":"Markus Hentsch","email":"markus.hentsch@cloudandheat.com","username":"mhen"},"date":"2018-10-08 15:01:00.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"332b1efd942514f31ae34d85998c08daec6871e1","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2018-10-08 15:25:32.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/96/608696/1/check/openstack-tox-docs/31235e0/html/ : SUCCESS in 5m 44s\n- openstack-tox-pep8 http://logs.openstack.org/96/608696/1/check/openstack-tox-pep8/9ad30fc/ : SUCCESS in 5m 03s","accounts_in_message":[],"_revision_number":1},{"id":"c543899be644bddcbaeb8c058f63e368fb718552","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2018-10-11 11:32:46.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"fb4ea034cdc524ef1c5d8597f31f89a98ae66fdd","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2018-10-11 13:01:57.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/96/608696/2/check/openstack-tox-docs/c5d9ff9/html/ : SUCCESS in 5m 46s\n- openstack-tox-pep8 http://logs.openstack.org/96/608696/2/check/openstack-tox-pep8/ea753b2/ : SUCCESS in 4m 33s","accounts_in_message":[],"_revision_number":2},{"id":"98ee83bc064f62de935632ab1c71b10648d7579f","author":{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},"date":"2018-10-11 13:52:45.000000000","message":"Patch Set 2: Code-Review-1\n\n(12 comments)\n\nA few relatively minor things, plus some suggestions for implementation using a separate Oslo library for handling the encryption/decryption streaming.","accounts_in_message":[],"_revision_number":2},{"id":"acae2e9d4824c732c4a088b4c5ea3e62a392be02","author":{"_account_id":27665,"name":"Markus Hentsch","email":"markus.hentsch@cloudandheat.com","username":"mhen"},"date":"2018-10-12 14:54:35.000000000","message":"Patch Set 2:\n\n(5 comments)","accounts_in_message":[],"_revision_number":2},{"id":"d2b13c15b837b5b361bcb4f08f4a1f2179268a3f","author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"date":"2018-10-18 10:41:50.000000000","message":"Patch Set 2: Code-Review-1\n\n(4 comments)\n\nI think this is a good start but need to be detailed a bit further (like the API impact).\nCheers,\ngibi","accounts_in_message":[],"_revision_number":2},{"id":"c9e6158d47b95ba267f6445eb0c65a64098923fd","author":{"_account_id":27665,"name":"Markus Hentsch","email":"markus.hentsch@cloudandheat.com","username":"mhen"},"date":"2018-10-18 11:55:14.000000000","message":"Patch Set 2:\n\n(2 comments)","accounts_in_message":[],"_revision_number":2},{"id":"54491fe0a63a0e8d1c3e5e906b9a101aeba66cda","author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"date":"2018-10-19 15:14:10.000000000","message":"Patch Set 2:\n\n(2 comments)\n\nlets detail the API and data model impact besides those I\u0027m good with this.","accounts_in_message":[],"_revision_number":2},{"id":"ee317a142dc751bee4d7a7da3ed9d8feb9b7657e","author":{"_account_id":27665,"name":"Markus Hentsch","email":"markus.hentsch@cloudandheat.com","username":"mhen"},"date":"2018-10-22 13:43:19.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"25feb49c9c375120f88252d16010c30044981c49","author":{"_account_id":27665,"name":"Markus Hentsch","email":"markus.hentsch@cloudandheat.com","username":"mhen"},"date":"2018-10-22 13:50:58.000000000","message":"Patch Set 3:\n\n(9 comments)\n\nI\u0027ve updated the spec to address your suggestions and questions. I also added some more clarifications to the proposed changes as well as the API impact section.","accounts_in_message":[],"_revision_number":3},{"id":"e88b636b466d2ad8ef550c689b1cbc1e7b509c71","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2018-10-22 14:41:27.000000000","message":"Patch Set 3: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/96/608696/3/check/openstack-tox-docs/9dd9e6d/html/ : SUCCESS in 6m 41s\n- openstack-tox-pep8 http://logs.openstack.org/96/608696/3/check/openstack-tox-pep8/f64ad2f/ : SUCCESS in 6m 06s","accounts_in_message":[],"_revision_number":3},{"id":"03ecb89832089d824c53e8ada93a11249c877512","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2018-11-19 14:12:57.000000000","message":"Uploaded patch set 4.","accounts_in_message":[],"_revision_number":4},{"id":"e2782e7fe6f2551fde866f7dfa1029252071305e","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2018-11-19 14:25:04.000000000","message":"Patch Set 4: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/96/608696/4/check/openstack-tox-docs/6a00f3f/html/ : SUCCESS in 6m 06s\n- openstack-tox-pep8 http://logs.openstack.org/96/608696/4/check/openstack-tox-pep8/c0bbe25/ : SUCCESS in 4m 45s","accounts_in_message":[],"_revision_number":4},{"id":"7a3b742587d9351d947ee3c8dbb4a850c1da3d04","author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"date":"2018-11-20 10:37:23.000000000","message":"Patch Set 4: Code-Review-1\n\n(1 comment)\n\nThanks for the update. Overall the spec looks good. \nBased on the extra information in the spec I can foresee a data model impact. See inline. \n\nCheers,\ngibi","accounts_in_message":[],"_revision_number":4},{"id":"96dd7b9c6492a448813e037db3608f960baab8b7","author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"date":"2018-12-06 00:16:44.000000000","message":"Patch Set 4: Code-Review-1\n\n(5 comments)\n\n-1 for the lack of blueprint link and the lack of detail in the Work Items section.\n\nI think the overall idea in this spec sounds good, but I\u0027m noting that there\u0027s not yet consensus on where the shared library should be located (whether to use openstacksdk, os-brick, or other). We might need to start another ML thread about that on openstack-discuss@ to find consensus with a wider audience. The glance spec is also doesn\u0027t look close to consensus/approval yet.","accounts_in_message":[],"_revision_number":4},{"id":"48b55313da2d9bb79fa07c097c8008c39a6a840b","author":{"_account_id":9555,"name":"Matthew Booth","email":"mbooth@redhat.com","username":"MatthewBooth"},"date":"2019-05-20 14:11:27.000000000","message":"Patch Set 4: Code-Review-1\n\n(1 comment)\n\nI\u0027m strongly opposed to this.\n\nWe appear be selling something which promised not to expose unencrypted data internally on OpenStack services. However, we do exactly this except for a small number of volume types (rbd, I think?) which use qemu native encryption. LVM specifically is called out in the spec as an example to be copied, when in fact the opposite is true. When unencrypted, we expose the unencrypted data as a block device on the compute host when exactly the same protection as any other unencrypted disk. And this is without considering the protection afforded to secrets handled by nova after they are obtained by barbican, or how much we can trust barbican if we don\u0027t trust nova.\n\nAdding encryption of glance images to this mix gives us no actual security benefits beyond simply setting permissions on the image to restrict its visibility. Consequently all we\u0027d be adding is complexity. There are no security benefits to doing this.\n\nI would like to see us fully defining the threats we are attempting to mitigate. If we decide that disk encryption mitigates those threats, we need to ensure we have implemented it thoroughly before it\u0027s worth adding encrypted glance images.","accounts_in_message":[],"_revision_number":4},{"id":"3e145fc1f39ec7d84930c89aee6eba0e56b943d6","author":{"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},"date":"2019-05-23 09:36:16.000000000","message":"Patch Set 4:\n\nSo quick replies to some of Matt\u0027s comments before I go into the spec itself.\n\n \u003e (1 comment)\n \u003e \n \u003e I\u0027m strongly opposed to this.\n \u003e \n \u003e We appear be selling something which promised not to expose\n \u003e unencrypted data internally on OpenStack services. However, we do\n \u003e exactly this except for a small number of volume types (rbd, I\n \u003e think?) which use qemu native encryption. \n\nYou\u0027re mixing volumes and ephemeral storage here. Additionally native decryption of LUKS volumes by QEMU is the default now for all _volume_ types (assuming the required versions of Libvirt and QEMU are available).\n\n \u003e LVM specifically is called out in the spec as an example to be copied,\n \u003e when in fact the opposite is true. When unencrypted, we expose the\n \u003e unencrypted data as a block device on the compute host when exactly \n \u003e the same protection as any other unencrypted disk. And this is without\n \u003e considering the protection afforded to secrets handled by nova\n \u003e after they are obtained by barbican, or how much we can trust\n \u003e barbican if we don\u0027t trust nova.\n\nRight and if anything that needs to be addressed by introducing the same native LUKS decryption support that we have for volumes into the imagebackend for the Libvirt virt driver.","accounts_in_message":[],"_revision_number":4},{"id":"f7ca922e73559b71491287cced6d5b0de53eb4ee","author":{"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},"date":"2019-05-23 14:53:00.000000000","message":"Patch Set 4: Code-Review-1\n\n(11 comments)\n\nI\u0027m on board with the data confidentiality at rest use case I just can\u0027t understand why we need to encrypt and stream images using GPG etc when formats such as LUKS potentially simplify alot of the complexity outlined here.","accounts_in_message":[],"_revision_number":4},{"id":"741176132a35bf530cf5571f0d2200c4178cf142","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2019-06-18 13:55:59.000000000","message":"Uploaded patch set 5.","accounts_in_message":[],"_revision_number":5},{"id":"45431432bc07dd4996c9c6e41828021b4eb0ea02","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-06-18 14:14:17.000000000","message":"Patch Set 5: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttp://docs.openstack.org/infra/manual/developers.html#automated-testing\n\n\n- openstack-tox-docs http://logs.openstack.org/96/608696/5/check/openstack-tox-docs/ba54c4b/ : FAILURE in 5m 31s\n- openstack-tox-pep8 http://logs.openstack.org/96/608696/5/check/openstack-tox-pep8/f473cab/ : SUCCESS in 6m 16s","accounts_in_message":[],"_revision_number":5},{"id":"893af26cb71c10a8750f9f9966aceb0911554a24","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2019-06-19 08:04:35.000000000","message":"Uploaded patch set 6.","accounts_in_message":[],"_revision_number":6},{"id":"4c15a11af901512cc3a8c3f0a228fc8f86a0b7db","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-06-19 08:13:05.000000000","message":"Patch Set 6: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttp://docs.openstack.org/infra/manual/developers.html#automated-testing\n\n\n- openstack-tox-docs http://logs.openstack.org/96/608696/6/check/openstack-tox-docs/8bdde5f/ : FAILURE in 5m 47s\n- openstack-tox-pep8 http://logs.openstack.org/96/608696/6/check/openstack-tox-pep8/11e271c/ : SUCCESS in 5m 07s","accounts_in_message":[],"_revision_number":6},{"id":"c82a167298b5d944d03be5faa74736c1876920ab","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2019-06-19 08:15:39.000000000","message":"Uploaded patch set 7.","accounts_in_message":[],"_revision_number":7},{"id":"b28f3e98525b8b90dba19b96f5dd3036f0ef9632","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-06-19 08:33:04.000000000","message":"Patch Set 7: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/96/608696/7/check/openstack-tox-docs/b8de8cf/html/ : SUCCESS in 9m 53s\n- openstack-tox-pep8 http://logs.openstack.org/96/608696/7/check/openstack-tox-pep8/d28ce75/ : SUCCESS in 4m 50s","accounts_in_message":[],"_revision_number":7},{"id":"638895653dca3b47d24a55533a2dcba689f4805c","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-06-24 19:05:55.000000000","message":"Patch Set 7:\n\nThis is nicely described, but pretty high-level. As a Nova maintainer, I\u0027d like to see more detail on which Nova (presumably VM lifecycle) flows are impacted and how.\n\nI would also like to understand the chain of dependencies with other projects. I.e. which pieces are prerequisites of which others?","accounts_in_message":[],"_revision_number":7},{"id":"69e29cb20a13672e2a4d7b7fcda8c6e140d6565e","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2019-07-02 07:35:12.000000000","message":"Uploaded patch set 8.","accounts_in_message":[],"_revision_number":8},{"id":"1cef7ef5fe27549b55007299773974e81d3df219","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2019-07-02 07:37:13.000000000","message":"Patch Set 8:\n\nI added a few more details in the proposed change section.","accounts_in_message":[],"_revision_number":8},{"id":"a634879169698a5be93f6eda6c6bbd02cdb446b8","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-07-02 07:46:39.000000000","message":"Patch Set 8: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/96/608696/8/check/openstack-tox-docs/6f5f6f8/html/ : SUCCESS in 6m 17s\n- openstack-tox-pep8 http://logs.openstack.org/96/608696/8/check/openstack-tox-pep8/c879e3e/ : SUCCESS in 3m 51s","accounts_in_message":[],"_revision_number":8},{"id":"d070a12eaf82ca382458339eec13a7817c2b7cc0","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-07-02 13:57:29.000000000","message":"Patch Set 8: Code-Review+1\n\n(3 comments)\n\nOkay, assuming the deps come together, this seems reasonable and simple and nonintrusive from the Nova side.\n\nWe need to do some paperwork, then I\u0027m +2:\n- File a blueprint [1]. The blueprint name and spec file basename should match.\n- Tag the blueprint in the commit message (e.g. Blueprint: image-encryption) and in the gerrit topic (e.g. bp/image-encryption).\n- Link to the blueprint URL at the top of the spec (see the template [2]).\n\n[1] https://blueprints.launchpad.net/nova/+addspec\n[2] http://specs.openstack.org/openstack/nova-specs/specs/train/approved/train-template.html","accounts_in_message":[],"_revision_number":8},{"id":"25a6cac566bc1c4eab3e2bf582b9e2d0d9fed794","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2019-07-02 21:30:23.000000000","message":"Patch Set 8: Code-Review+1\n\n(3 comments)\n\nover all i think this is well presented.\ni dont normally review the storage side of nova much but is have some\nquetions inline regarding lifecycle opertaiton on an instance with an encryped image.\n\ni am still +1 on this change regardless of the limitation on move operations but we shoudl document them so that operators are aware of the implications of using this feature.","accounts_in_message":[],"_revision_number":8},{"id":"04872aa433693cb77703be4bc813b448c8aae7b2","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2019-07-02 21:46:19.000000000","message":"Patch Set 8: Code-Review-1\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"0c4aeff61f0c2949f1afb1727a4a93d06a641ab0","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-07-02 21:47:36.000000000","message":"Patch Set 8: -Code-Review","accounts_in_message":[],"_revision_number":8},{"id":"1a20c3cfb4532f41d6e93aa7aa28ce881f6b8680","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2019-07-03 11:09:07.000000000","message":"Topic changed from 608696 to bp/image-encryption","accounts_in_message":[],"_revision_number":8},{"id":"8c5d003e26435f95ad385cdc4f41dd45c9b32e1c","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2019-07-03 11:23:34.000000000","message":"Uploaded patch set 9.","accounts_in_message":[],"_revision_number":9},{"id":"3d17eba7d5c6d04bbc0261283ed47d59a42f76e0","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-07-03 11:38:46.000000000","message":"Patch Set 9: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/96/608696/9/check/openstack-tox-docs/e6a52e5/html/ : SUCCESS in 6m 59s\n- openstack-tox-pep8 http://logs.openstack.org/96/608696/9/check/openstack-tox-pep8/3f59ab5/ : SUCCESS in 4m 17s","accounts_in_message":[],"_revision_number":9},{"id":"f6158068621faaa6c3638b14644783078d5b6caa","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2019-07-03 12:06:02.000000000","message":"Topic changed from 608696 to bp/image-encryption","accounts_in_message":[],"_revision_number":9},{"id":"81dc86c81a59b5d0e88df5a9f8ad44e96e65293b","author":{"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},"date":"2019-07-03 13:08:49.000000000","message":"Patch Set 8:\n\n(6 comments)\n\nArgh, this tab has been open so long that I\u0027ve ended up reviewing an older PS. Posting anyway as this LGTM and my nits can be ignored.","accounts_in_message":[],"_revision_number":8},{"id":"bf672ff89fd839989f90e66136733bc5e6acb24b","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-07-03 21:18:54.000000000","message":"Patch Set 9: Code-Review-1\n\nThere were discussions today in IRC [1][2] concluding that more thought needs to be given to the shelve and cross-cell resize operations. TL;DR: we either need to enhance those APIs to allow the admin to request encryption of the snapshots created thereby; or we need to \"remember\" that the instance came from an encrypted image and do so automatically (in which case where does the key come from?)\n\n[1] http://eavesdrop.openstack.org/irclogs/%23openstack-nova/%23openstack-nova.2019-07-03.log.html#t2019-07-03T11:26:32\n[2] http://eavesdrop.openstack.org/irclogs/%23openstack-nova/%23openstack-nova.2019-07-03.log.html#t2019-07-03T13:57:12","accounts_in_message":[],"_revision_number":9},{"id":"e82e7c964907eb01cb666c39ec96cfecdd2adb49","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2019-07-04 12:41:50.000000000","message":"Uploaded patch set 10.","accounts_in_message":[],"_revision_number":10},{"id":"1c7790a4bf426bd55dff89fdeafb6a432010b670","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-07-04 12:51:52.000000000","message":"Patch Set 10: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/96/608696/10/check/openstack-tox-docs/8d3aeb6/html/ : SUCCESS in 6m 09s\n- openstack-tox-pep8 http://logs.openstack.org/96/608696/10/check/openstack-tox-pep8/cb50ae7/ : SUCCESS in 4m 10s","accounts_in_message":[],"_revision_number":10},{"id":"86a0a197d5529e511265609227fc6a76e6ed0b2b","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2019-07-04 12:57:45.000000000","message":"Patch Set 10:\n\nWe changed the encryption part - to use a method we call key-lock. That would be used for shelve, resize and snapshot creation. So we have a symmetry between these behaviors.","accounts_in_message":[],"_revision_number":10},{"id":"d2625eeb69b3dd66793dcd777a9e38117a4d53bc","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2019-07-04 13:32:26.000000000","message":"Patch Set 10: Code-Review+1\n\nthanks for updating\nim happy with the new version assuming other are too\ni think we are in a good position to move forward to the implementation at this point","accounts_in_message":[],"_revision_number":10},{"id":"0166baf57f1b283fa9ffbb3a81bc00fabf2cfb4e","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-07-15 22:14:23.000000000","message":"Patch Set 10: Code-Review-1\n\n(12 comments)\n\nDownvote for missing details on conf options.\n\nOther things are mostly questions, the answers to which may prompt other changes.\n\nThanks!","accounts_in_message":[],"_revision_number":10},{"id":"7523a9b7d1e7c13e35f52ce130c4ccb5fe7f2403","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2019-07-22 11:51:16.000000000","message":"Patch Set 10:\n\n(3 comments)","accounts_in_message":[],"_revision_number":10},{"id":"c0ddfde454db46d09b2f891d49a9c23c752433ea","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2019-07-23 12:37:02.000000000","message":"Uploaded patch set 11.","accounts_in_message":[],"_revision_number":11},{"id":"c93e514607af8dbcfa8a8d68f7ff9463cfa00100","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-07-23 12:45:44.000000000","message":"Patch Set 11: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/96/608696/11/check/openstack-tox-docs/02f8cfe/html/ : SUCCESS in 7m 15s\n- openstack-tox-pep8 http://logs.openstack.org/96/608696/11/check/openstack-tox-pep8/d4e4f94/ : SUCCESS in 6m 16s","accounts_in_message":[],"_revision_number":11},{"id":"e7cdbb41f206ad0731283c7d0bdfb17f495056fc","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-07-23 13:19:53.000000000","message":"Patch Set 11: Code-Review+2\n\n(2 comments)\n\nThanks for fleshing out the config opts. I think this is good to go now.","accounts_in_message":[],"_revision_number":11},{"id":"36d64efbbd9ad800b8cd781da0eca86380b3ca7d","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2019-07-23 16:03:15.000000000","message":"Patch Set 11: Code-Review+1\n\n(2 comments)\n\ni was generally happy with the previous iterations so this still looks good to me.","accounts_in_message":[],"_revision_number":11},{"id":"602a66b2dce324ea4b3808d23ca937ca78b6cc8b","author":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"date":"2019-07-29 15:24:24.000000000","message":"Patch Set 11: Code-Review-1\n\n(5 comments)\n\nI\u0027ve got a few scheduling and upgrade-related concerns in here which I think should be addressed. It\u0027s not clear to me if the compute service changes are generic or specific to each virt driver and if the latter, will this only be implemented by the libvirt driver?\n\nAlso wondering about the createBackup API - I\u0027m OK with not supporting this in that API, but we should call it out.","accounts_in_message":[],"_revision_number":11},{"id":"cc7574044a64e3caa29e6c85ea1fff4c89324211","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-07-29 17:39:12.000000000","message":"Patch Set 11: -Code-Review","accounts_in_message":[],"_revision_number":11},{"id":"bc9e00946d8fde0fab9d1022243c0016408e489f","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-07-29 22:19:35.000000000","message":"Patch Set 11:\n\nSFE requested: http://lists.openstack.org/pipermail/openstack-discuss/2019-July/008096.html","accounts_in_message":[],"_revision_number":11},{"id":"7c49b516612726f7c32cc06ff888a35120aadd7e","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2019-08-01 08:54:31.000000000","message":"Patch Set 11:\n\n(4 comments)","accounts_in_message":[],"_revision_number":11},{"id":"0be7b2535eef73ac8ef6db5830398a5fec2e37ca","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-08-01 14:14:58.000000000","message":"Patch Set 11:\n\n(1 comment)","accounts_in_message":[],"_revision_number":11},{"id":"3e91f464e264ee534a654205af21b483ee9a28f5","author":{"_account_id":1004,"name":"Mohammed Naser","email":"mnaser@vexxhost.com","username":"mnaser"},"date":"2019-08-01 21:54:38.000000000","message":"Patch Set 11:\n\n(5 comments)","accounts_in_message":[],"_revision_number":11},{"id":"a4023bbd4d12baa9ff2a73b5013dfd5cbbc6c035","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2019-08-02 09:16:34.000000000","message":"Patch Set 11:\n\n(2 comments)","accounts_in_message":[],"_revision_number":11},{"id":"268bf194c31df67dc47939ef46bc89528e3beb1a","author":{"_account_id":4393,"name":"Dan Smith","email":"dms@danplanet.com","username":"danms"},"date":"2019-08-05 17:32:57.000000000","message":"Patch Set 11: Code-Review-1\n\n(6 comments)\n\nOn the subject of a freeze exception for this, I feel like this doesn\u0027t really qualify for such a thing based on the current state. There are still quite a few unanswered questions (or at least confusing assertions) in here, and no mention of which virt drivers are going to be supported, or can be supported in the future, etc. I\u0027ve not reviewed this yet, so maybe that\u0027s just my interpretation, but I thought I\u0027d offer it up regardless.\n\nAnyway, threw some first-read comments in here which I think need to be addressed, as well as those from the others which are yet unanswered.","accounts_in_message":[],"_revision_number":11},{"id":"2fddd4a22770fbee7277dfd64a59fa01bde723e4","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-08-08 14:39:15.000000000","message":"Abandoned\n\nAgreed in today\u0027s Nova meeting to deny spec freeze exception for this [1]. As soon as the U release has a name, we\u0027ll add it to nova-specs. At that time, you should restore this and move it to U. (If you want to continue working on it in the interim, you may restore it in the backlog/ directory.)\n\n[1] http://eavesdrop.openstack.org/meetings/nova/2019/nova.2019-08-08-14.01.log.html#l-106","accounts_in_message":[],"_revision_number":11},{"id":"6436904efe057ad18c0f72cad4fb4174ad46e466","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-08-30 13:52:35.000000000","message":"Patch Set 11:\n\nThe nova-specs repository has been populated for ussuri. You may restore and move this spec if needed.","accounts_in_message":[],"_revision_number":11},{"id":"0c8780f85640d38279d8400cd254546897f361e1","author":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"date":"2019-09-09 13:10:23.000000000","message":"Restored\n\nWill be proposed for Ussuri.","accounts_in_message":[],"_revision_number":11},{"id":"6c1baea5185a44f3ebb5a2911a496a3a92ab2a38","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-09-09 13:28:18.000000000","message":"Patch Set 11:\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/d6d2aae98f6e4c9fbd66134a347984a0 : SUCCESS in 10m 46s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/7437ce3d972d41ea95392998c95040b4 : SUCCESS in 3m 24s","accounts_in_message":[],"_revision_number":11},{"id":"d8a4578aa5fb527fca9b6a300aabe7ae1225ff4a","author":{"_account_id":9555,"name":"Matthew Booth","email":"mbooth@redhat.com","username":"MatthewBooth"},"date":"2019-11-07 14:34:09.000000000","message":"Patch Set 11: Code-Review-1\n\n(2 comments)\n\nLots of issues here which I won\u0027t go into now as I plan to speak to you tomorrow. I\u0027m sure there\u0027s a way forward with your use case, though.","accounts_in_message":[],"_revision_number":11},{"id":"a8642c49c4b58deb4c1d3ecef8bfa0ece3f2e444","author":{"_account_id":9555,"name":"Matthew Booth","email":"mbooth@redhat.com","username":"MatthewBooth"},"date":"2019-11-12 12:32:13.000000000","message":"Patch Set 11:\n\nSummary of our discussion was:\n\nYou aren\u0027t going to gain the benefits you\u0027re hoping to gain by using a \u0027streamable\u0027 format in practise. Because the hypervisor can\u0027t directly consume GPG, you\u0027re going to have to decrypt and store the whole thing on the compute host. I would much prefer to see this use encryption which can be directly consumed by the hypervisor, e.g. LUKS.\n\nGiven the above constraints, the risk of this feature is significantly increased because we don\u0027t yet have support for encryption of ephemeral disks[1], so don\u0027t know for sure how that feature would be implemented in practise.\n\nI appreciate that encrypted images are, theoretically at least, a separate problem to ephemeral storage, however IIUC your goal is to get to a place where the user must supply the relevant keys in order to start an instance. In order to get there you\u0027re also going to need encrypted ephemeral support. I suggest a much safer option would be to implement that first.\n\nAn interim alternative is to rely on encrypted volume support, although presumably even there you\u0027ve had to implement support for GPG to LUKS conversion in cinder, or the resulting volume isn\u0027t encrypted?\n\n[1] discounting LVM, which isn\u0027t a model we want to replicate.","accounts_in_message":[],"_revision_number":11},{"id":"e597b0d05da5918fbb653bcaca96ea045e13d4b1","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2019-12-09 09:46:36.000000000","message":"Patch Set 11:\n\nAfter talking to Matthew at the Shanghai Summit, we will abandon this spec for.\n\nMatthew already summarized the problem: What we would like to have (somewhen in the future) is a chain of encrypted resources, which can be transferred into each other.\n\nWith adding the image encryption, openstack would have this chain from encrypted image, encrypted volume and encrypted volume-backed server for the volume side. In nova currently the encrypted ephemeral storage is still missing, therefore we don\u0027t have such a chain of encrypted resources in nova. We wanted to already make nova capable of using encrypted images, but as it seems it might be a better idea to wait until there is an ephemeral storage encryption in nova.\n\nThank you for the discussions at several points. We might come back on this spec in the future. In the mean time, we will provide image encryption in glance and cinder.","accounts_in_message":[],"_revision_number":11},{"id":"5ca7f98bc775e892b5690ad601d0615166ee779e","author":{"_account_id":27665,"name":"Markus Hentsch","email":"markus.hentsch@cloudandheat.com","username":"mhen"},"date":"2019-12-09 09:53:20.000000000","message":"Abandoned\n\nAbandoning this spec for now as a result of the discussions, mainly due to the missing ephemeral storage encryption support needed for a coherent security model concerning image encryption in Nova.","accounts_in_message":[],"_revision_number":11}],"current_revision_number":11,"current_revision":"88518116850638483468f2a9de86f4f2f22013d2","revisions":{"54aa6d5899e82554a24154355a352abd8cb16aef":{"kind":"REWORK","_number":1,"created":"2018-10-08 15:01:00.000000000","uploader":{"_account_id":27665,"name":"Markus Hentsch","email":"markus.hentsch@cloudandheat.com","username":"mhen"},"ref":"refs/changes/96/608696/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/96/608696/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/1"}}},"commit":{"parents":[{"commit":"df5d815cbef010383bb44564b925a90bf53ca761","subject":"Merge \"Placement: support mixing required traits with any traits\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/df5d815cbef010383bb44564b925a90bf53ca761"}]}],"author":{"name":"Markus Hentsch","email":"markus.hentsch@secustack.com","date":"2018-10-08 14:57:25.000000000","tz":120},"committer":{"name":"Markus Hentsch","email":"markus.hentsch@secustack.com","date":"2018-10-08 14:57:25.000000000","tz":120},"subject":"Spec for the Nova part of Image Encryption","message":"Spec for the Nova part of Image Encryption\n\nWe want to propose Image Encryption for Openstack, which would affect Nova, but also Cinder and Glance.\nThis spec contains the details of the Nova part for the Image Encryption. The transformations from\nencrypted images to ephemeral storage as well as creating encrypted images from existing servers are\ndiscussed.\n\nChange-Id: Ib3519f97ca1c6573462b2216433394e86c013e2a\nCo-Authored-By: Josephine Seifert \u003cjosephine.seifert@secustack.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/54aa6d5899e82554a24154355a352abd8cb16aef"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/54aa6d5899e82554a24154355a352abd8cb16aef"}]},"branch":"refs/heads/master"},"ac6e6caba36074c06eca46c7ebb72620fe2c3416":{"kind":"REWORK","_number":2,"created":"2018-10-11 11:32:46.000000000","uploader":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"ref":"refs/changes/96/608696/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/96/608696/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/2"}}},"commit":{"parents":[{"commit":"df5d815cbef010383bb44564b925a90bf53ca761","subject":"Merge \"Placement: support mixing required traits with any traits\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/df5d815cbef010383bb44564b925a90bf53ca761"}]}],"author":{"name":"Markus Hentsch","email":"markus.hentsch@secustack.com","date":"2018-10-08 14:57:25.000000000","tz":120},"committer":{"name":"Josephine Seifert","email":"josephine.seifert@secustack.com","date":"2018-10-11 11:31:17.000000000","tz":120},"subject":"Spec for the Nova part of Image Encryption","message":"Spec for the Nova part of Image Encryption\n\nWe want to propose Image Encryption for Openstack, which would affect Nova,\nbut also Cinder and Glance. This spec contains the details of the Nova part\nfor the Image Encryption. The transformations from encrypted images to\nephemeral storage as well as creating encrypted images from existing servers\nare discussed.\n\nChange-Id: Ib3519f97ca1c6573462b2216433394e86c013e2a\nCo-Authored-By: Josephine Seifert \u003cjosephine.seifert@secustack.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/ac6e6caba36074c06eca46c7ebb72620fe2c3416"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/ac6e6caba36074c06eca46c7ebb72620fe2c3416"}]},"branch":"refs/heads/master"},"c126d32cb756314bb2af5de92471b90c5f146bd6":{"kind":"REWORK","_number":3,"created":"2018-10-22 13:43:19.000000000","uploader":{"_account_id":27665,"name":"Markus Hentsch","email":"markus.hentsch@cloudandheat.com","username":"mhen"},"ref":"refs/changes/96/608696/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/96/608696/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/3"}}},"commit":{"parents":[{"commit":"df5d815cbef010383bb44564b925a90bf53ca761","subject":"Merge \"Placement: support mixing required traits with any traits\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/df5d815cbef010383bb44564b925a90bf53ca761"}]}],"author":{"name":"Markus Hentsch","email":"markus.hentsch@secustack.com","date":"2018-10-08 14:57:25.000000000","tz":120},"committer":{"name":"Markus Hentsch","email":"markus.hentsch@secustack.com","date":"2018-10-22 13:42:52.000000000","tz":120},"subject":"Spec for the Nova part of Image Encryption","message":"Spec for the Nova part of Image Encryption\n\nWe want to propose Image Encryption for Openstack, which would affect Nova,\nbut also Cinder and Glance. This spec contains the details of the Nova part\nfor the Image Encryption. The transformations from encrypted images to\nephemeral storage as well as creating encrypted images from existing servers\nare discussed.\n\nChange-Id: Ib3519f97ca1c6573462b2216433394e86c013e2a\nCo-Authored-By: Josephine Seifert \u003cjosephine.seifert@secustack.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/c126d32cb756314bb2af5de92471b90c5f146bd6"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/c126d32cb756314bb2af5de92471b90c5f146bd6"}]},"branch":"refs/heads/master"},"0af254d5f48950ed8705f917ccce3e12a5cd9ca1":{"kind":"REWORK","_number":4,"created":"2018-11-19 14:12:57.000000000","uploader":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"ref":"refs/changes/96/608696/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/96/608696/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/4"}}},"commit":{"parents":[{"commit":"df5d815cbef010383bb44564b925a90bf53ca761","subject":"Merge \"Placement: support mixing required traits with any traits\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/df5d815cbef010383bb44564b925a90bf53ca761"}]}],"author":{"name":"Markus Hentsch","email":"markus.hentsch@secustack.com","date":"2018-10-08 14:57:25.000000000","tz":120},"committer":{"name":"Josephine Seifert","email":"josephine.seifert@secustack.com","date":"2018-11-19 14:12:17.000000000","tz":60},"subject":"Spec for the Nova part of Image Encryption","message":"Spec for the Nova part of Image Encryption\n\nWe want to propose Image Encryption for Openstack, which would affect Nova,\nbut also Cinder and Glance. This spec contains the details of the Nova part\nfor the Image Encryption. The transformations from encrypted images to\nephemeral storage as well as creating encrypted images from existing servers\nare discussed.\n\nChange-Id: Ib3519f97ca1c6573462b2216433394e86c013e2a\nCo-Authored-By: Josephine Seifert \u003cjosephine.seifert@secustack.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/0af254d5f48950ed8705f917ccce3e12a5cd9ca1"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/0af254d5f48950ed8705f917ccce3e12a5cd9ca1"}]},"branch":"refs/heads/master"},"c38f98e999021c46a26d850ffccfeab7bb65335a":{"kind":"REWORK","_number":5,"created":"2019-06-18 13:55:59.000000000","uploader":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"ref":"refs/changes/96/608696/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/96/608696/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/5"}}},"commit":{"parents":[{"commit":"d796b33774cc4e21c663885a57141e93052e5546","subject":"Merge \"Amend the detach-boot-volume design\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/d796b33774cc4e21c663885a57141e93052e5546"}]}],"author":{"name":"Markus Hentsch","email":"markus.hentsch@secustack.com","date":"2018-10-08 14:57:25.000000000","tz":120},"committer":{"name":"Josephine Seifert","email":"josephine.seifert@secustack.com","date":"2019-06-18 13:55:33.000000000","tz":120},"subject":"Spec for the Nova part of Image Encryption","message":"Spec for the Nova part of Image Encryption\n\nWe want to propose Image Encryption for Openstack, which would affect Nova,\nbut also Cinder and Glance. This spec contains the details of the Nova part\nfor the Image Encryption. The transformations from encrypted images to\nephemeral storage as well as creating encrypted images from existing servers\nare discussed.\n\nChange-Id: Ib3519f97ca1c6573462b2216433394e86c013e2a\nCo-Authored-By: Josephine Seifert \u003cjosephine.seifert@secustack.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/c38f98e999021c46a26d850ffccfeab7bb65335a"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/c38f98e999021c46a26d850ffccfeab7bb65335a"}]},"branch":"refs/heads/master"},"635d14c9b7d2d1ba645751b181396b9b988172a8":{"kind":"REWORK","_number":6,"created":"2019-06-19 08:04:35.000000000","uploader":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"ref":"refs/changes/96/608696/6","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/96/608696/6","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/6"}}},"commit":{"parents":[{"commit":"d796b33774cc4e21c663885a57141e93052e5546","subject":"Merge \"Amend the detach-boot-volume design\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/d796b33774cc4e21c663885a57141e93052e5546"}]}],"author":{"name":"Markus Hentsch","email":"markus.hentsch@secustack.com","date":"2018-10-08 14:57:25.000000000","tz":120},"committer":{"name":"Josephine Seifert","email":"josephine.seifert@secustack.com","date":"2019-06-19 08:04:05.000000000","tz":120},"subject":"Spec for the Nova part of Image Encryption","message":"Spec for the Nova part of Image Encryption\n\nWe want to propose Image Encryption for Openstack, which would affect Nova,\nbut also Cinder and Glance. This spec contains the details of the Nova part\nfor the Image Encryption. The transformations from encrypted images to\nephemeral storage as well as creating encrypted images from existing servers\nare discussed.\n\nChange-Id: Ib3519f97ca1c6573462b2216433394e86c013e2a\nCo-Authored-By: Josephine Seifert \u003cjosephine.seifert@secustack.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/635d14c9b7d2d1ba645751b181396b9b988172a8"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/635d14c9b7d2d1ba645751b181396b9b988172a8"}]},"branch":"refs/heads/master"},"8f079e9345a8a5d2b3e1988b218b6a4d33b84bea":{"kind":"REWORK","_number":7,"created":"2019-06-19 08:15:39.000000000","uploader":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"ref":"refs/changes/96/608696/7","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/96/608696/7","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/7"}}},"commit":{"parents":[{"commit":"d796b33774cc4e21c663885a57141e93052e5546","subject":"Merge \"Amend the detach-boot-volume design\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/d796b33774cc4e21c663885a57141e93052e5546"}]}],"author":{"name":"Markus Hentsch","email":"markus.hentsch@secustack.com","date":"2018-10-08 14:57:25.000000000","tz":120},"committer":{"name":"Josephine Seifert","email":"josephine.seifert@secustack.com","date":"2019-06-19 08:15:17.000000000","tz":120},"subject":"Spec for the Nova part of Image Encryption","message":"Spec for the Nova part of Image Encryption\n\nWe want to propose Image Encryption for Openstack, which would affect Nova,\nbut also Cinder and Glance. This spec contains the details of the Nova part\nfor the Image Encryption. The transformations from encrypted images to\nephemeral storage as well as creating encrypted images from existing servers\nare discussed.\n\nChange-Id: Ib3519f97ca1c6573462b2216433394e86c013e2a\nCo-Authored-By: Josephine Seifert \u003cjosephine.seifert@secustack.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/8f079e9345a8a5d2b3e1988b218b6a4d33b84bea"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/8f079e9345a8a5d2b3e1988b218b6a4d33b84bea"}]},"branch":"refs/heads/master"},"8554ea5c39f9226147673532181dfc600207d81e":{"kind":"REWORK","_number":8,"created":"2019-07-02 07:35:12.000000000","uploader":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"ref":"refs/changes/96/608696/8","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/96/608696/8","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/8 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/8 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/8 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/8"}}},"commit":{"parents":[{"commit":"d796b33774cc4e21c663885a57141e93052e5546","subject":"Merge \"Amend the detach-boot-volume design\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/d796b33774cc4e21c663885a57141e93052e5546"}]}],"author":{"name":"Markus Hentsch","email":"markus.hentsch@secustack.com","date":"2018-10-08 14:57:25.000000000","tz":120},"committer":{"name":"Josephine Seifert","email":"josephine.seifert@secustack.com","date":"2019-07-02 07:34:25.000000000","tz":120},"subject":"Spec for the Nova part of Image Encryption","message":"Spec for the Nova part of Image Encryption\n\nWe want to propose Image Encryption for Openstack, which would affect Nova,\nbut also Cinder and Glance. This spec contains the details of the Nova part\nfor the Image Encryption. The transformations from encrypted images to\nephemeral storage as well as creating encrypted images from existing servers\nare discussed.\n\nChange-Id: Ib3519f97ca1c6573462b2216433394e86c013e2a\nCo-Authored-By: Josephine Seifert \u003cjosephine.seifert@secustack.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/8554ea5c39f9226147673532181dfc600207d81e"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/8554ea5c39f9226147673532181dfc600207d81e"}]},"branch":"refs/heads/master"},"3dfd42705103cb5765f286fe73348d1c4e08a481":{"kind":"REWORK","_number":9,"created":"2019-07-03 11:23:34.000000000","uploader":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"ref":"refs/changes/96/608696/9","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/96/608696/9","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/9 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/9 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/9 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/9"}}},"commit":{"parents":[{"commit":"d796b33774cc4e21c663885a57141e93052e5546","subject":"Merge \"Amend the detach-boot-volume design\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/d796b33774cc4e21c663885a57141e93052e5546"}]}],"author":{"name":"Markus Hentsch","email":"markus.hentsch@secustack.com","date":"2018-10-08 14:57:25.000000000","tz":120},"committer":{"name":"Josephine Seifert","email":"josephine.seifert@secustack.com","date":"2019-07-03 11:21:57.000000000","tz":120},"subject":"Spec for the Nova part of Image Encryption","message":"Spec for the Nova part of Image Encryption\n\nWe want to propose Image Encryption for Openstack, which would affect Nova,\nbut also Cinder and Glance. This spec contains the details of the Nova part\nfor the Image Encryption. The transformations from encrypted images to\nephemeral storage as well as creating encrypted images from existing servers\nare discussed.\n\nblueprint image-encryption\n\nChange-Id: Ib3519f97ca1c6573462b2216433394e86c013e2a\nCo-Authored-By: Josephine Seifert \u003cjosephine.seifert@secustack.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/3dfd42705103cb5765f286fe73348d1c4e08a481"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/3dfd42705103cb5765f286fe73348d1c4e08a481"}]},"branch":"refs/heads/master"},"fa924165b096585a37326b67f4f00cce3cff0c61":{"kind":"REWORK","_number":10,"created":"2019-07-04 12:41:50.000000000","uploader":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"ref":"refs/changes/96/608696/10","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/96/608696/10","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/10 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/10 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/10 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/10"}}},"commit":{"parents":[{"commit":"d796b33774cc4e21c663885a57141e93052e5546","subject":"Merge \"Amend the detach-boot-volume design\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/d796b33774cc4e21c663885a57141e93052e5546"}]}],"author":{"name":"Markus Hentsch","email":"markus.hentsch@secustack.com","date":"2018-10-08 14:57:25.000000000","tz":120},"committer":{"name":"Josephine Seifert","email":"josephine.seifert@secustack.com","date":"2019-07-04 12:41:23.000000000","tz":120},"subject":"Spec for the Nova part of Image Encryption","message":"Spec for the Nova part of Image Encryption\n\nWe want to propose Image Encryption for Openstack, which would affect Nova,\nbut also Cinder and Glance. This spec contains the details of the Nova part\nfor the Image Encryption. The transformations from encrypted images to\nephemeral storage as well as creating encrypted images from existing servers\nare discussed.\n\nblueprint image-encryption\n\nChange-Id: Ib3519f97ca1c6573462b2216433394e86c013e2a\nCo-Authored-By: Josephine Seifert \u003cjosephine.seifert@secustack.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/fa924165b096585a37326b67f4f00cce3cff0c61"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/fa924165b096585a37326b67f4f00cce3cff0c61"}]},"branch":"refs/heads/master"},"88518116850638483468f2a9de86f4f2f22013d2":{"kind":"REWORK","_number":11,"created":"2019-07-23 12:37:02.000000000","uploader":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"ref":"refs/changes/96/608696/11","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/96/608696/11","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/11 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/11 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/11 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/96/608696/11"}}},"commit":{"parents":[{"commit":"d796b33774cc4e21c663885a57141e93052e5546","subject":"Merge \"Amend the detach-boot-volume design\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/d796b33774cc4e21c663885a57141e93052e5546"}]}],"author":{"name":"Markus Hentsch","email":"markus.hentsch@secustack.com","date":"2018-10-08 14:57:25.000000000","tz":120},"committer":{"name":"Josephine Seifert","email":"josephine.seifert@secustack.com","date":"2019-07-23 12:36:16.000000000","tz":120},"subject":"Spec for the Nova part of Image Encryption","message":"Spec for the Nova part of Image Encryption\n\nWe want to propose Image Encryption for Openstack, which would affect Nova,\nbut also Cinder and Glance. This spec contains the details of the Nova part\nfor the Image Encryption. The transformations from encrypted images to\nephemeral storage as well as creating encrypted images from existing servers\nare discussed.\n\nblueprint image-encryption\n\nChange-Id: Ib3519f97ca1c6573462b2216433394e86c013e2a\nCo-Authored-By: Josephine Seifert \u003cjosephine.seifert@secustack.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/88518116850638483468f2a9de86f4f2f22013d2"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/88518116850638483468f2a9de86f4f2f22013d2"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
