Security Guide - Chapter 43. Encrypted Live Migration Section Cleanup

Bug #1344374 reported by N Dillon
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
openstack-manuals
Fix Released
Undecided
Dan Sneddon

Bug Description

Avoiding 1st/2nd person, cleaning up grammar and wording. Would love to get more info around how to configure that in libvirtd, but I'll do research on it and come back to it.

Currently reads: "If your use case involves keeping live migration enabled, then libvirtd can provide tunneled, encrypted live migrations. That said, this feature is not currently exposed in OpenStack Dashboard, nor the nova-client commands and can only be accessed through manual configuration of libvirtd. Encrypted live migration modifies the live migration process by first copying the instance data from the running hypervisor to libvirtd. From there an encrypted tunnel is created between the libvirtd processes on both hosts. Finally, the destination libvirtd process copies the instance back to the underlying hypervisor."

Recommended Update: "If there is a sufficient business case for keeping live migration enabled, then libvirtd can provide and encrypted tunnel for the live migrations. However this feature is not currently exposed in either the OpenStack Dashboard or nova-client commands, and can only be accessed through manual configuration of libvirtd. The live migration process then changes to the following high-level steps.
1) Instance data is copied from the hypervisor to libvirtd
2) An encrypted tunnel is created between libvirtd processes on both source and destination hosts
3) Destination libvirtd host copies the instances back to an underlying hypervisor"

-----------------------------------
Built: 2014-07-18T16:16:50 00:00
git SHA: d7b47995e6316a4f686f39354880ceb6ea9b664c
URL: http://docs.openstack.org/security-guide/content/security-services-for-instances.html
source File: file:/home/jenkins/workspace/security-doc-tox-doc-publishdocs/security-guide/ch_security-services-for-instances.xml
xml:id: security-services-for-instances

Revision history for this message
N Dillon (sicarie) wrote :

Should probably double-check my grammar and spelling with the recommendation , "then libvirtd can provide and encrypted tunnel for the live migrations." should probably be AN encrypted tunnel

Dan Sneddon (dsneddon)
Changed in openstack-manuals:
assignee: nobody → Dan Sneddon (dsneddon)
status: New → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to security-doc (master)

Reviewed: https://review.openstack.org/108855
Committed: https://git.openstack.org/cgit/openstack/security-doc/commit/?id=3c106fb7496772d6aa65c9f5fff22c05e167e334
Submitter: Jenkins
Branch: master

commit 3c106fb7496772d6aa65c9f5fff22c05e167e334
Author: Dan Sneddon <email address hidden>
Date: Tue Jul 22 18:09:24 2014 -0400

    Cleaning up grammer and wording, avoiding 2nd person

    Updating description of encrypted live migration process to avoid 2nd person
    perspective, cleaning up grammer and wording to improve clarity.

    Change-Id: Ibf0cfac2a4f6c592269c5921397aa3a70c1db4ab
    Closes-Bug: #1344374

Changed in openstack-manuals:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.