OpenStack not installed with consistent uid/gid for glance/cinder/nova users

Bug #1657202 reported by Gaurang Tapase
12
This bug affects 2 people
Affects Status Importance Assigned to Milestone
Juju Charms Collection
Invalid
Undecided
Unassigned
cinder (Ubuntu)
Fix Released
Medium
Unassigned
glance (Ubuntu)
Fix Released
Medium
Unassigned
gnocchi (Ubuntu)
New
Undecided
Unassigned
nova (Ubuntu)
Fix Released
Medium
Unassigned

Bug Description

For a shared/clustered filesystem (GPFS) backend, one of the requirement is to have a common uid/gid for nova/cinder/glance users across all nodes when nova/cinder/glance services are deployed. This is typically required in HA environment where these services run on more than one units. This is to have required minimal permissions to the directories which are accessed by these services. Otherwise, we have to set 777 permissions on these directories to make things work.

James Page (james-page)
summary: - OpenStack charm doesn't deploy glance/cinedr/nova with consistent
- uid/gid across multiple nodes
+ OpenStack not installed with consistent uid/gid for glance/cinder/nova
+ users
Changed in charms:
status: New → Invalid
Revision history for this message
James Page (james-page) wrote :

Gaurang

Please use the following allocations in any workarounds you might do in the short term:

    64060 | nova | OpenStack Compute
    64061 | cinder | OpenStack Block Storage
    64062 | glance | OpenStack Image

We'll work these into the queens packaging soon.

James Page (james-page)
Changed in nova (Ubuntu):
status: New → Fix Committed
importance: Undecided → Medium
milestone: none → ubuntu-18.04
Changed in glance (Ubuntu):
milestone: none → ubuntu-18.04
Changed in cinder (Ubuntu):
milestone: none → ubuntu-18.04
Changed in glance (Ubuntu):
importance: Undecided → Medium
Changed in cinder (Ubuntu):
importance: Undecided → Medium
Changed in glance (Ubuntu):
status: New → Fix Committed
James Page (james-page)
Changed in cinder (Ubuntu):
status: New → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package nova - 2:17.0.0~b2-0ubuntu2

---------------
nova (2:17.0.0~b2-0ubuntu2) bionic; urgency=medium

  * d/nova-common.postinst: Use reserved uid/gid for nova user/group,
    ensuring consistency across deployments (LP: #1657202).

 -- James Page <email address hidden> Tue, 12 Dec 2017 15:20:52 +0000

Changed in nova (Ubuntu):
status: Fix Committed → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package glance - 2:16.0.0~b2-0ubuntu2

---------------
glance (2:16.0.0~b2-0ubuntu2) bionic; urgency=medium

  * d/glance-common.postinst: Use reserved uid/gid for glance user/group,
    ensuring consistency across deployments (LP: #1657202).
  * d/glance-common.install,rules: Skip install of rootwrap.conf as this
    is also shipped in glance-store.

 -- James Page <email address hidden> Tue, 12 Dec 2017 15:21:39 +0000

Changed in glance (Ubuntu):
status: Fix Committed → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package cinder - 2:12.0.0~b2-0ubuntu2

---------------
cinder (2:12.0.0~b2-0ubuntu2) bionic; urgency=medium

  * d/cinder-common.postinst: Use reserved uid/gid for cinder user/group,
    ensuring consistency across deployments (LP: #1657202).

 -- James Page <email address hidden> Tue, 12 Dec 2017 15:22:10 +0000

Changed in cinder (Ubuntu):
status: Fix Committed → Fix Released
Revision history for this message
Nobuto Murata (nobuto) wrote :

Excuse me for reviving an old bug report, but Gnocchi also requires a static uid/gid to support NFS use case.

https://gnocchi.xyz/intro.html
> If you need to scale the number of server with the file driver, you can export and share the data via NFS among all Gnocchi processes.

Revision history for this message
Nobuto Murata (nobuto) wrote :
Revision history for this message
Nobuto Murata (nobuto) wrote :

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=983635
> 64065 | gnocchi | Gnocchi - Metric as a Service

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.