-
Notifications
You must be signed in to change notification settings - Fork 24
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[EPIC] IaaS standards #285
Comments
Discussion on how to best proceed with these standards / item that could be standardized in todays meeting with @josephineSei , @markus-hentsch and @mbuechse We agreed to
|
Somehow editing the description of this issue does not show me the correct version. So maybe one of you can include this: |
I opened an issue for the Security Groups: #473 . |
I discussed with @josephineSei which topics might not be covered yet by SCS standardization appropriately yet and what kind of potential might exist regarding those. Key rotationWe thought about the possibility of creating a standard or guide for cryptographic key rotation in SCS and had a look at involved components. Cinder Volumes:
Ephemeral Storage (Nova):
Images (Glance):
Keystone token provider:
PKI / TLS
Summary: LUKS encryption key rotation (concerns Nova and Cinder) would require an upstream contribution and would either be weak cryptographically (when changing only key slots) or require a lot of effort to get right (online reencryption). Glance image key rotation could be established using guidelines and a manual process but the implementation is not ready yet. BackupsWe briefly discussed the potential necessity of some form of backup guide for user data due to the following considerations:
... so the state seems pretty messy. We see potential here to at least formulate a guide to better assist users seeking to implement a backup concept. Footnotes
|
@markus-hentsch and I further discussed the possible need to:
|
Topics till EOF: |
General
Standard for Standards & Documentation
Mandatory Openstack Services
Computing
Flavor naming, flavor selection, and flavor discoverability:
SCS-
flavors ... #295Standard flavors
OpenStack powered Compute 2022.11
Storage
Volume types
Network
public network
Network Time Protocoll
DNS
L3 loadbalancer (OVN)
externalTrafficPolicy: Local
Neutron Policy Standard
Images
Image Meta Data
Standard Images
Identity
Domain admin role: Allow project creation, user management as self-service (resellers)
Identity federation via OIDC: Federate users from federated clouds
Security
Baseline security
Database(s)
Entropy in VMs
Key Store
Encryption
Security Groups
Backup and Redundancy
Taxonomy of Backups
User Backup
Volume Backup
Definition of Availability Zones: Availability expectations when spreading over AZs
Definition of Region: What is shared?
Unsorted/unclassified
Metadata source (w/ user-data, vendor-data)
MetaData API
The text was updated successfully, but these errors were encountered: