Multiple Regions Deployment with Kolla in kolla-ansible

Bug #1845292 reported by bouabid amine
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
kolla-ansible
In Progress
Medium
Chason Chan

Bug Description

- [X] This doc is inaccurate in this way:
- [X] This is a doc addition request:

Documentation related to multiple regions deployment with kolla-ansible misses to precise that passwords from /etc/kolla/passwords.yml on RegionOne should be shared among the other regions. Also, it must be specified if all the passwords should be shared or just a subset.

Finally, it is necessary to evaluate the related security risks as well as the precautions to be taken to mitigate them (For example in the case of a wide area network deployment (such as NFV))

PS: In our multiple region setup we copied the whole /etc/kolla/passwords.yml to the second region in order to make it work.

Thanks in advance

-----------------------------------
Release: 8.1.0.dev530 on 2019-07-18 10:53:04
SHA: c6d0733b9dee1f2e562271149ce46f6ddc1abd40
Source: https://opendev.org/openstack/kolla-ansible/src/doc/source/user/multi-regions.rst
URL: https://docs.openstack.org/kolla-ansible/latest/user/multi-regions.html

Mark Goddard (mgoddard)
Changed in kolla-ansible:
importance: Undecided → Medium
status: New → Triaged
Revision history for this message
Mark Goddard (mgoddard) wrote :

Thanks for raising this, I agree this is an issue. I imagine we'd only need to share the openstack user passwords between regions, but haven't tested this.

Chason Chan (chen-xing)
Changed in kolla-ansible:
assignee: nobody → Chason Chan (chen-xing)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to kolla-ansible (master)

Fix proposed to branch: master
Review: https://review.opendev.org/685676

Changed in kolla-ansible:
status: Triaged → In Progress
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.