live-migration without root ssh access

Bug #1375109 reported by Nobuto Murata
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Nova Compute Charm
Triaged
Wishlist
Unassigned
nova-compute (Juju Charms Collection)
Invalid
Wishlist
Unassigned

Bug Description

At this moment, nova-compute charm seems to setup root user SSH access each other for live-migration.
http://bazaar.launchpad.net/~openstack-charmers/charms/trusty/nova-compute/next/view/80/hooks/nova_compute_hooks.py#L70

"SSH login as root" may violate internal security policy especially for enterprise usage. It would be nice if the charm supports other methods like "login as nova (+ rootwrap.d if required)" or options to be away from SSH using SASL or TLS.

Tags: openstack cts
tags: added: openstack
Nobuto Murata (nobuto)
tags: added: cts
Revision history for this message
James Page (james-page) wrote :

This is why we don't enable live migration by default; right now this approach is imposed by upstream nova, so there is not a huge amount we can do about it in the charm as its completely libvirt driven (i.e. no knowledge of rootwrap).

Changed in nova-compute (Juju Charms Collection):
importance: Undecided → Wishlist
status: New → Triaged
James Page (james-page)
Changed in charm-nova-compute:
importance: Undecided → Wishlist
status: New → Triaged
Changed in nova-compute (Juju Charms Collection):
status: Triaged → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.