Add paragraph about ephemeral storage encryption in Cloud Administrator Guide

Bug #1490765 reported by Bruce Benjamin
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
openstack-manuals
Fix Released
Medium
Randy Perryman

Bug Description

The images and instances section of the cloud admin guide mentions purging of ephemeral storage without reference to the ephemeral storage encryption feature. A note needs to be added about that.

-----------------------------------
Release: 0.9 on 2015-08-31 22:34
Source: http://git.openstack.org/cgit/openstack/openstack-manuals/tree/doc/admin-guide/source/compute-images-instances.rst
URL: http://docs.openstack.org/admin-guide/compute-images-instances.html

Tags: admin-guide
Shuquan Huang (shuquan)
Changed in openstack-manuals:
assignee: nobody → Shuquan Huang (shuquan)
Changed in openstack-manuals:
status: New → Confirmed
importance: Undecided → Medium
tags: added: admin-guide
removed: admin-guide-cloud
Changed in openstack-manuals:
assignee: Shuquan Huang (shuquan) → nobody
description: updated
Changed in openstack-manuals:
milestone: none → newton
Revision history for this message
Ryan Selden (ryanx-seldon) wrote :

Bruce,

What specifically needs to be added? Are encrypted ephemeral disks not purged on instance delete? I assume we are talking about the Kilo release feature - http://docs.openstack.org/security-guide/tenant-data/data-encryption.html

Thanks

Revision history for this message
Bruce Benjamin (bruce-benjamin) wrote :

Ryan, all ephemeral disks are purged upon instance delete, whether encrypted or not. My thought earlier was that if the purge process left any trace of data (which I have since learned is extremely unlikely), then the use of an encrypted ephemeral disk would have provided additional security if the key was deleted upon the purge. Given the suitable purge process, I don't think this bug is important now, so I think we should close it. Thanks for checking on this.

Revision history for this message
Randy Perryman (randy-perryman) wrote :

question should we mention that purge includes all disk types encrypted or not?

Revision history for this message
Bruce Benjamin (bruce-benjamin) wrote :

Yes, adding that for clarification is a good idea.

Revision history for this message
Randy Perryman (randy-perryman) wrote :

Okay I will take the bug and submit a patch for this.

Changed in openstack-manuals:
assignee: nobody → Randy Perryman (randy-perryman)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to openstack-manuals (master)

Fix proposed to branch: master
Review: https://review.openstack.org/344897

Changed in openstack-manuals:
status: Confirmed → In Progress
Revision history for this message
Randy Perryman (randy-perryman) wrote :

Hi who should I tag to review the patch?

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to openstack-manuals (master)

Reviewed: https://review.openstack.org/344897
Committed: https://git.openstack.org/cgit/openstack/openstack-manuals/commit/?id=f5f8563a6b7c631d0d94ba7d91c470159d7f5b96
Submitter: Jenkins
Branch: master

commit f5f8563a6b7c631d0d94ba7d91c470159d7f5b96
Author: Randy Perryman <email address hidden>
Date: Wed Jul 20 11:52:04 2016 -0400

    Clarifying for when an instance is deleted encrypted or not ephemeral
    storage will be purged.

    Change-Id: I868513fe56d7a58c5a53418a1990e6066bc9c86d
    Closes-Bug: 1490765

Changed in openstack-manuals:
status: In Progress → Fix Released
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix included in openstack/openstack-manuals 15.0.0

This issue was fixed in the openstack/openstack-manuals 15.0.0 release.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.