share-encryption

Registered by kiran pawar

The Manila shares volumes for a virtual machine (VM) are currently not being encrypted. This makes the platforms hosting shares for VMs high value targets because an attacker can break into a share-hosting platform and read the data for many different VMs. Another issue is that the physical storage medium could be stolen, remounted, and accessed from a different machine. This blueprint addresses both of these vulnerabilities

The aim of this blueprint is to provide encryption of the share using vendor supported encryption methods. That is the data is being encrypted on backend storage.

Blueprint information

Status:
Started
Approver:
Goutham Pacha Ravi
Priority:
Medium
Drafter:
kiran pawar
Direction:
Approved
Assignee:
kiran pawar
Definition:
Approved
Series goal:
Accepted for flamingo
Implementation:
Started
Milestone target:
milestone icon dalmatian-rc1
Started by
Goutham Pacha Ravi

Related branches

Sprints

Whiteboard

Gerrit topic: https://review.opendev.org/#/q/topic:bp/share-encryption

Addressed by: https://review.opendev.org/c/openstack/manila-specs/+/898999
    Add spec for share encryption

Addressed by: https://review.opendev.org/c/openstack/manila/+/909977
    Add share type encryption

Addressed by: https://review.opendev.org/c/openstack/manila/+/911089
    Use encryption key id during share create

Gerrit topic: https://review.opendev.org/#/q/topic:bp/encryption

Addressed by: https://review.opendev.org/c/openstack/manila-specs/+/940437
    Update spec for share encryption

Addressed by: https://review.opendev.org/c/openstack/manila/+/951669
    [NetApp] Barbican share-server/share encryption support

Addressed by: https://review.opendev.org/c/openstack/manila/+/952152
    Use encryption key ref during share create

Addressed by: https://review.opendev.org/c/openstack/manila-tempest-plugin/+/952368
    Add tests for encryption_key_ref

Addressed by: https://review.opendev.org/c/openstack/manila-tempest-plugin/+/955394
    Add barbican to dummy driver job

Addressed by: https://review.opendev.org/c/openstack/manila/+/955393
    Add barbican set up to devstack

Addressed by: https://review.opendev.org/c/openstack/manila/+/959104
    Refactor key manager code

Addressed by: https://review.opendev.org/c/openstack/manila/+/960379
    Add missing auth plugin options in [barbican] section

Addressed by: https://review.opendev.org/c/openstack/manila/+/960380
    Support region_name for identity API access

(?)

Work Items

This blueprint contains Public information 
Everyone can see this information.

Subscribers

No subscribers.