Add dependency between nova-compute and vaultlocker#10
Open
rodrigogansobarbieri wants to merge 1 commit intoopenstack-charmers:masterfrom
Open
Add dependency between nova-compute and vaultlocker#10rodrigogansobarbieri wants to merge 1 commit intoopenstack-charmers:masterfrom
rodrigogansobarbieri wants to merge 1 commit intoopenstack-charmers:masterfrom
Conversation
If vaultlocker fails to decrypt and mount /var/lib/nova/instances, nova will start anyway and may create instances with their disks on the root filesystem's disk, which may not be encrypted. This patch creates a dependency between the nova-compute and vaultlocker services, so if vaultlocker fails nova-compute will not be started. Closes-bug: #1863358
Contributor
|
I think this specialises vaultlocker towards nova-compute to much. Would an alternative approach be to use overrides on the nova-compute systemd configuration to ensure that it runs after the required vaultlocker units have been started successfully? |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
If vaultlocker fails to decrypt and mount
/var/lib/nova/instances, nova will start anyway
and may create instances with their disks on the
root filesystem's disk, which may not be encrypted.
This patch creates a dependency between the nova-compute
and vaultlocker services, so if vaultlocker fails
nova-compute will not be started.
Closes-bug: #1863358