file based disk images do not get scrubbed on delete
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Compute (nova) |
Opinion
|
Wishlist
|
Unassigned |
Bug Description
Right now, LVM backed instances can be scrubbed (overwritten with zeros using dd) upon deletion. However, there is no such option with file backed images. While it is true that fallocate can handle some of this by returning 0s to the instance when reading any unwritten parts of the file, there are some cases where it is not desirable to enable fallocate.
What would be preferred would be a similar the options cinder has implemented, so the operator can choose to shred or zero out the file, based on their organizations own internal data policies. A zero out option satisfies those that must ensure they scrub tenant data upon deletion, and shred would satisfy those beholden to DoD 5220-22.
This would of course make file backed disks vulnerable to https:/
Attached an initial patch for nova/virt/
Changed in nova: | |
assignee: | nobody → Darla Ahlert (da741q) |
Changed in nova: | |
status: | Opinion → In Progress |
Changed in nova: | |
assignee: | Darla Ahlert (da741q) → nobody |
Changed in nova: | |
status: | In Progress → Confirmed |
Thanks for the patch Pentheus. We use an online code review process for review patches. Could you please follow the steps at https:/ /wiki.openstack .org/wiki/ How_To_ Contribute# If_you. 27re_a_ developer to register and then propose your patch? Thanks!