Bug 1608295 - ceph-nfs defaults to admin keyring, which is not available when distributed to a custom role
Summary: ceph-nfs defaults to admin keyring, which is not available when distributed t...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-tripleo-heat-templates
Version: 13.0 (Queens)
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: z3
: 13.0 (Queens)
Assignee: Giulio Fidente
QA Contact: Yogev Rabl
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-07-25 09:24 UTC by Giulio Fidente
Modified: 2018-11-20 21:54 UTC (History)
6 users (show)

Fixed In Version: openstack-tripleo-heat-templates-8.0.7-2.el7ost
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-11-13 22:27:47 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Launchpad 1783520 0 None None None 2018-07-25 09:29:15 UTC
OpenStack gerrit 587864 0 None stable/queens: MERGED tripleo-heat-templates: Set CephX user for Ganesha (I575cfa5591d0fb4b3a33f707db0f738840f6cbdf) 2018-10-15 14:30:35 UTC
Red Hat Product Errata RHBA-2018:3587 0 None None None 2018-11-13 22:28:27 UTC

Description Giulio Fidente 2018-07-25 09:24:45 UTC
We should configure ceph-nfs to use a non-admin keyring (possibly manila)

Comment 2 Ram Raja 2018-08-01 14:58:52 UTC
(In reply to Giulio Fidente from comment #0)
> We should configure ceph-nfs to use a non-admin keyring (possibly manila)

What are the cephx permissions/caps of this manila cephx ID?


We'll have to make changes here in the generated ganesha.conf,
https://github.com/nfs-ganesha/nfs-ganesha/blob/next/src/config_samples/ceph.conf#L158

https://github.com/nfs-ganesha/nfs-ganesha/blob/next/src/config_samples/ceph.conf#L174

Need to set those two config settings to 'manila'

Comment 3 Giulio Fidente 2018-08-01 15:22:04 UTC
Thanks Ram for helping; the submission does change the two lines you pointed to in comment #2.

The permissions set for the 'manila' keyring are here [1]; please comment you believe those are not sufficient or that should be reviewed

1. https://github.com/openstack/tripleo-heat-templates/blob/master/docker/services/ceph-ansible/ceph-base.yaml#L282-L287

Comment 4 Ram Raja 2018-08-02 12:38:15 UTC
(In reply to Giulio Fidente from comment #3)
> Thanks Ram for helping; the submission does change the two lines you pointed
> to in comment #2.

Missed seeing that. LGTM. Thanks, Giulio!

> 
> The permissions set for the 'manila' keyring are here [1]; please comment
> you believe those are not sufficient or that should be reviewed

The permissions should be sufficient.
> 
> 1.
> https://github.com/openstack/tripleo-heat-templates/blob/master/docker/
> services/ceph-ansible/ceph-base.yaml#L282-L287

Comment 13 errata-xmlrpc 2018-11-13 22:27:47 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2018:3587


Note You need to log in before you can comment on or make changes to this bug.