nova-compute can start when instances mount not yet available
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Nova Compute Charm |
New
|
High
|
Unassigned |
Bug Description
Raising this bug on the charm for now but i'm guessing it will need package attention as well.
We have a use case where the nova instances path e.g. /var/lib/
One way to at least mitigate the security risk of having nova-compute blindly creating VMs on an unencrypted disk would be to set instances-path to a location that doesn't exist unless it has been successfully mounted but I know that several deployments are not doing this, perhaps for specific reasons. Therefore we need a way to safeguard against this possibility.
summary: |
- nova-compute starts when instances mount not yet available + nova-compute can start when instances mount not yet available |
It has been highlighted that using a path that is not the default (/var/lib/ nova/instances) would conflict with having apparmor profiles enabled in the charm but since the charm is managing those profiles it should be able to adapt to the configured path.