Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1305024 - RFE: Support native QEMU volume encryption
RFE: Support native QEMU volume encryption
Status: CLOSED ERRATA
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-nova (Show other bugs)
unspecified
Unspecified Unspecified
high Severity high
: Upstream M3
: 13.0 (Queens)
Assigned To: Lee Yarwood
Archit Modi
: FutureFeature, Triaged
Depends On: 1305022 1406796 1518998 1631239 1333141 1406803
Blocks: 1273812 1301026 1442136 1230405 1305044
  Show dependency treegraph
 
Reported: 2016-02-05 06:13 EST by Pablo Iranzo Gómez
Modified: 2018-09-20 05:33 EDT (History)
29 users (show)

See Also:
Fixed In Version: openstack-nova-17.0.0-0.20180223162252.a4a53bf.el7ost
Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of: 1305022
: 1305044 (view as bug list)
Environment:
Last Closed: 2018-06-27 09:26:22 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Knowledge Base (Solution) 2137751 None None None 2016-02-05 06:42 EST
OpenStack gerrit 437070 None master: MERGED nova-specs: Libvirt: Native LUKS file and host device decryption by QEMU (I40a775e7c902de169900a7d53eadb47f8144ae81) 2018-02-28 08:18 EST
OpenStack gerrit 460243 None master: MERGED nova: libvirt: Collocate encryptor and volume driver calls (Ica323b87fa85a454fca9d46ada3677f18fe50022) 2018-02-28 08:18 EST
OpenStack gerrit 464008 None master: MERGED nova: libvirt: Introduce disk encryption config classes (I84ff4368c3ecbb0954c12c2119cae30d11833393) 2018-02-28 08:18 EST
OpenStack gerrit 490824 None master: MERGED nova-specs: Libvirt: Native LUKS decryption by QEMU (Iade56845e954d815b7f59e42a0d06b3f08ea33af) 2018-02-28 08:17 EST
OpenStack gerrit 523958 None master: MERGED nova: libvirt: QEMU native LUKS decryption for encrypted volumes (Ibfa64f18bbd2fb70db7791330ed1a64fe61c1355) 2018-02-28 08:17 EST
Red Hat Product Errata RHEA-2018:2086 normal SHIPPED_LIVE Red Hat OpenStack Platform 13.0 Enhancement Advisory 2018-06-28 15:51:39 EDT

  None (edit)
Comment 2 Daniel Berrange 2016-02-05 06:49:28 EST
The volume encryption in Nova was only ever designed to work with block device based volumes. Support for network attached volumes (RBD) or file based volumes (NFS) is a future RFE upstream, pending on QEMU support for LUKS. So the report is testing a feature which is known to not exist at this time. As such I'm marking this an RFE, since its not a bug.
Comment 6 Stephen Gordon 2016-09-29 11:44:46 EDT
Dan what's the state of the QEMU dependenc
Comment 7 Daniel Berrange 2016-09-29 11:50:58 EDT
QEMU has general support for LUKS encryption of raw files and block devices in QEMU 2.6.0 onwards, but to make effective use of it in OpenStack, particularly for NFS, we need qcow2 integration. That work is still pending.
Comment 8 Sean Cohen 2016-12-21 10:29:42 EST
(In reply to Daniel Berrange from comment #7)
> QEMU has general support for LUKS encryption of raw files and block devices
> in QEMU 2.6.0 onwards, but to make effective use of it in OpenStack,
> particularly for NFS, we need qcow2 integration. That work is still pending.


Native integration of LUKS and qcow2 is targeted at 7.4, adding bug 1406803 dependancy. 
Seam
Comment 20 errata-xmlrpc 2018-06-27 09:26:22 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2018:2086

Note You need to log in before you can comment on or make changes to this bug.