Bug 1305024 - RFE: Support native QEMU volume encryption
RFE: Support native QEMU volume encryption
Status: ON_DEV
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-nova (Show other bugs)
unspecified
Unspecified Unspecified
high Severity high
: Upstream M2
: 13.0 (Queens)
Assigned To: Lee Yarwood
Gabriel Szasz
: FutureFeature, Triaged
Depends On: 1305022 1333141 1406796 1406803 1406805
Blocks: 1230405 1273812 1301026 1442136 1305044
  Show dependency treegraph
 
Reported: 2016-02-05 06:13 EST by Pablo Iranzo Gómez
Modified: 2017-10-27 21:47 EDT (History)
23 users (show)

See Also:
Fixed In Version:
Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of: 1305022
: 1305044 (view as bug list)
Environment:
Last Closed:
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Knowledge Base (Solution) 2137751 None None None 2016-02-05 06:42 EST
OpenStack gerrit 437070 None None None 2017-04-25 04:48 EDT
OpenStack gerrit 490824 None None None 2017-09-05 13:22 EDT

  None (edit)
Comment 2 Daniel Berrange 2016-02-05 06:49:28 EST
The volume encryption in Nova was only ever designed to work with block device based volumes. Support for network attached volumes (RBD) or file based volumes (NFS) is a future RFE upstream, pending on QEMU support for LUKS. So the report is testing a feature which is known to not exist at this time. As such I'm marking this an RFE, since its not a bug.
Comment 6 Stephen Gordon 2016-09-29 11:44:46 EDT
Dan what's the state of the QEMU dependenc
Comment 7 Daniel Berrange 2016-09-29 11:50:58 EDT
QEMU has general support for LUKS encryption of raw files and block devices in QEMU 2.6.0 onwards, but to make effective use of it in OpenStack, particularly for NFS, we need qcow2 integration. That work is still pending.
Comment 8 Sean Cohen 2016-12-21 10:29:42 EST
(In reply to Daniel Berrange from comment #7)
> QEMU has general support for LUKS encryption of raw files and block devices
> in QEMU 2.6.0 onwards, but to make effective use of it in OpenStack,
> particularly for NFS, we need qcow2 integration. That work is still pending.


Native integration of LUKS and qcow2 is targeted at 7.4, adding bug 1406803 dependancy. 
Seam

Note You need to log in before you can comment on or make changes to this bug.