| Summary: | KVM-libgfapi parameter settings need to be defaults | ||
|---|---|---|---|
| Product: | Red Hat Gluster Storage | Reporter: | Ben England <bengland> |
| Component: | glusterd | Assignee: | Bug Updates Notification Mailing List <rhs-bugs> |
| Status: | CLOSED EOL | QA Contact: | storage-qa-internal <storage-qa-internal> |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | 2.1 | CC: | dlambrig, dshetty, jharriga, mpillai, perfbz, sasundar, vagarwal, vbellur |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2015-12-03 17:13:04 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Ben England
2013-10-08 21:03:48 UTC
1) see https://bugzilla.redhat.com/show_bug.cgi?id=1016881#c2 concerning /etc/glusterfs/glusterd.vol parameter. 2) Still needed. 3) It sounds like eventually in Gluster 3.5 the need for this volume parameter will go away, but in the meantime we need to document and train SAs about it. This impacts OpenStack, oVirt, virtually anything that uses libgfapi. Gluster needs to just come up and work securely, with high performance, and reliably, without extensive manual tweaking. 1) above is an undocumented bug, I mean feature, there are no error messages hinting at the root cause, etc. It's been over 1/2 year, so I raised the priority and going to make a very loud noise about it until this gets fixed. Security by port number, seriously? That is the reason given for not changing rpc-auth-allow-insecure default to on. Why don't we use PKI (i.e. public keys) instead? I think in glusterfs-3.7 you've fixed rpc-auth-allow-insecure and server.allow-insecure defaults! duplicate of 1057292, see comment 7 there. Not sure how this was fixed, was it SSL sockets? If stat-prefetch issue was addressed, then we should be ok. I see default for stat-prefetch is "on" on my glusterfs-3.7 volume. looking for clarification of how this was fixed and whether it's fixed in RHGS 3.1. (In reply to Ben England from comment #4) > I think in glusterfs-3.7 you've fixed rpc-auth-allow-insecure and > server.allow-insecure defaults! duplicate of 1057292, see comment 7 there. > Not sure how this was fixed, was it SSL sockets? > > If stat-prefetch issue was addressed, then we should be ok. I see default > for stat-prefetch is "on" on my glusterfs-3.7 volume. I beg to differ. Pls see https://bugzilla.redhat.com/show_bug.cgi?id=1057292#c9 Thank you for submitting this issue for consideration in Red Hat Gluster Storage. The release for which you requested us to review, is now End of Life. Please See https://access.redhat.com/support/policy/updates/rhs/ If you can reproduce this bug against a currently maintained version of Red Hat Gluster Storage, please feel free to file a new report against the current release. |