Comment 20 for bug 1625402

Revision history for this message
Ian Cordasco (icordasc) wrote :

> But I don't think anyone would call defining such variables "non-default" behavior.

Charles, Glance doesn't require Keystone. That said, configuring the identity service is a far cry from setting up tasks to work. Beyond anecdotal from meetings where operators were asked "Do you use tasks?" and they say "I didn't know that existed" I don't know if operators supply every non-required configuration value.

You can also specify a location for glance to store images on the local filesystem, but if people are using ceph, swift, or vmware they're not going to specify that.

"It's optional but people fill in optional config values too" isn't sufficient to make this on by default.

> Thus the work_dir option may be set by the cloud operator for other reasons as well, not only to import an OVA image.

Rahul, every person on this thread associated with Glance has said exactly that. That still doesn't make this on by default (which is the point you and Charles are trying to push). Yes that means people may have a problem with this if they've enabled other tasks. Yes that's exactly what an OSSN would serve to address (educating folks about the potential for attacks by highly trusted users of the cloud if they're using a deprecated API).