Re: [openstack-dev] [oslo] proposing Moisés Guimarães for oslo.config core

2018-08-01 Thread Raildo Mascena de Sousa Filho
+1 On Wed, Aug 1, 2018 at 11:49 AM Ben Nemec wrote: > +1 > > On 08/01/2018 08:27 AM, Doug Hellmann wrote: > > Moisés Guimarães (moguimar) did quite a bit of work on oslo.config > > during the Rocky cycle to add driver support. Based on that work, > > and a discussion we have had since then

[openstack-dev] [oslo.config][castellan][tripleo][ptg]Protecting plain text secrets in configuration files

2018-02-02 Thread Raildo Mascena de Sousa Filho
Hello folks, Various regulations and best practices say that passwords and other secret values should not be stored in plain text in configuration files. There are “secret store” services to manage values that should be kept secure. Castellan provides an abstraction API for accessing those

Re: [openstack-dev] [keystone] adding Gage Hugo to keystone core

2018-01-16 Thread Raildo Mascena de Sousa Filho
+1 Congrats Gage, very well deserved! Cheers, On Tue, Jan 16, 2018 at 4:02 PM Lance Bragstad wrote: > Hey folks, > > In today's keystone meeting we made the announcement to add Gage Hugo > (gagehugo) as a keystone core reviewer [0]! Gage has been actively > involved in

Re: [openstack-dev] [oslo][oslo.config] pluggable drivers for oslo.config spec ready for review

2017-11-22 Thread Raildo Mascena de Sousa Filho
Hello folks, Since this topic have been discussed for a while, I'll give some updates on our current progress and which is the next steps for that. Yesterday, The spec for oslo.config drivers has been approved [1] and we started that implementation [2] for that spec. After that, we should be

Re: [openstack-dev] [oslo][oslo.config][ansible][tripleo][kolla][ptg] Pluggable drivers and protect plaintext secrets

2017-08-24 Thread Raildo Mascena de Sousa Filho
So, I didn't find that topic in the TripleO umbrella[1]. Emilien, can you confirm that? If not, I have a suggestion, we can schedule into the reservable rooms and if we confirm that it will be able to do in the TripleO or any other team's agenda, we can remove it. What do you guys think? [1]

Re: [openstack-dev] [barbican] [security] custodia @ PTG

2017-08-18 Thread Raildo Mascena de Sousa Filho
@Dave, unless you prefer to use the Barbican meeting that is (possible > synergies to barbican)? > > Regards, > > Luke > > On Thu, Aug 17, 2017 at 1:10 PM, Raildo Mascena de Sousa Filho < > rmasc...@redhat.com> wrote: > >> Hi Luke, >> >> I'll definite

Re: [openstack-dev] [oslo][oslo.config][ansible][tripleo][kolla][ptg] Pluggable drivers and protect plaintext secrets

2017-08-17 Thread Raildo Mascena de Sousa Filho
Well, it was the first option but unfortunately, Doug doesn't have any free time slot on those days, so we have to postpone that discussion to the end of the week. On Thu, Aug 17, 2017 at 9:41 AM Thierry Carrez <thie...@openstack.org> wrote: > Raildo Mascena de Sousa Filho wrote: &

Re: [openstack-dev] [oslo][oslo.config][ansible][tripleo][kolla][ptg] Pluggable drivers and protect plaintext secrets

2017-08-17 Thread Raildo Mascena de Sousa Filho
Hi all, Should we reserve a room in the extra session ethercalc [0 ] or we already have a time slot scheduled for that discussion? [0] https://ethercalc.openstack.org/Queens-PTG-Discussion-Rooms Cheers, On Tue, Aug 8, 2017 at 7:49 AM

Re: [openstack-dev] [barbican] [security] custodia @ PTG

2017-08-17 Thread Raildo Mascena de Sousa Filho
Hi Luke, I'll definitely be there, sounds like a great idea, so we can clarify a lot of topics and make progress in the community together. Cheers, On Thu, Aug 17, 2017 at 5:52 AM Luke Hinds wrote: > Hi Raildo, > > Both Barbican and Security have an interest in custodia

[openstack-dev] [oslo][oslo.config] Pluggable drivers and protect plaintext secrets

2017-08-04 Thread Raildo Mascena de Sousa Filho
Hi all, We had a couple of discussions with the Oslo team related to implement Pluggable drivers for oslo.config[0] and use those feature to implement support to protect plaintext secret on configuration files[1]. In another hand, due the containerized support on OpenStack services, we have a