Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-17 Thread Clark, Robert Graham
06:12 To: OpenStack Development Mailing List (not for usage questions) Subject: Re: [openstack-dev] [Magnum] TLS Support in Magnum Clint, Hi! It’s good to hear from you! On Jun 16, 2015, at 8:58 PM, Clint Byrum cl...@fewbar.commailto:cl...@fewbar.com wrote: I don't understand at all what you

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-17 Thread Fox, Kevin M
: Tuesday, June 16, 2015 10:12 PM To: OpenStack Development Mailing List (not for usage questions) Subject: Re: [openstack-dev] [Magnum] TLS Support in Magnum Clint, Hi! It’s good to hear from you! On Jun 16, 2015, at 8:58 PM, Clint Byrum cl...@fewbar.commailto:cl...@fewbar.com wrote: I don't

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-16 Thread Fox, Kevin M
, Kevin From: Clint Byrum Sent: Monday, June 15, 2015 6:10:27 PM To: openstack-dev Subject: Re: [openstack-dev] [Magnum] TLS Support in Magnum Excerpts from Fox, Kevin M's message of 2015-06-15 15:59:18 -0700: No, I was confused by your statement: When we create a bay

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-16 Thread Clint Byrum
Mailing List (not for usage questions) openstack-dev@lists.openstack.orgmailto:openstack-dev@lists.openstack.org Subject: Re: [openstack-dev] [Magnum] TLS Support in Magnum Out of the box, vms usually can contact the controllers though the routers nat, but not visa versa. So its preferable

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-16 Thread Adrian Otto
@lists.openstack.orgmailto:openstack-dev@lists.openstack.orgmailto:openstack-dev@lists.openstack.org Subject: Re: [openstack-dev] [Magnum] TLS Support in Magnum Out of the box, vms usually can contact the controllers though the routers nat, but not visa versa. So its preferable for guest agents

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-16 Thread Steven Dake (stdake)
To: OpenStack Development Mailing List (not for usage questions) openstack-dev@lists.openstack.orgmailto:openstack-dev@lists.openstack.org Subject: Re: [openstack-dev] [Magnum] TLS Support in Magnum Out of the box, vms usually can contact the controllers though the routers nat, but not visa versa. So

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-16 Thread 大塚元央
Hi, Tom 2015年6月16日(火) 3:00 Tom Cammann tom.camm...@hp.com: At the summit we talked about using Magnum as a CA and signing the certificates, and we seemed to have some consensus about doing this with the possibility of using Anchor. This would take a lot of the onus off of the user to

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-15 Thread Fox, Kevin M
: Sunday, June 14, 2015 11:09 PM To: OpenStack Development Mailing List (not for usage questions) Subject: Re: [openstack-dev] [Magnum] TLS Support in Magnum Madhuri, On Jun 14, 2015, at 10:30 PM, Madhuri Rai madhuri.ra...@gmail.commailto:madhuri.ra...@gmail.com wrote: Hi All, This is to bring

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-15 Thread Fox, Kevin M
://review.openstack.org/#/c/190732/ - Unscoped Service Catalog. Thanks, Kevin From: Madhuri Rai [madhuri.ra...@gmail.com] Sent: Sunday, June 14, 2015 10:30 PM To: OpenStack Development Mailing List (not for usage questions) Subject: [openstack-dev] [Magnum] TLS Support

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-15 Thread Madhuri
Adrian, On Tue, Jun 16, 2015 at 2:39 AM, Adrian Otto adrian.o...@rackspace.com wrote: Madhuri, On Jun 15, 2015, at 12:47 AM, Madhuri Rai madhuri.ra...@gmail.com wrote: Hi, Thanks Adrian for the quick response. Please find my response inline. On Mon, Jun 15, 2015 at 3:09 PM, Adrian

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-15 Thread Adam Young
:* Re: [openstack-dev] [Magnum] TLS Support in Magnum Madhuri, On Jun 14, 2015, at 10:30 PM, Madhuri Rai madhuri.ra...@gmail.com mailto:madhuri.ra...@gmail.com wrote: Hi All, This is to bring the blueprint secure-kubernetes https://blueprints.launchpad.net/magnum/+spec

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-15 Thread Madhuri
) *Subject:* Re: [openstack-dev] [Magnum] TLS Support in Magnum Madhuri, On Jun 14, 2015, at 10:30 PM, Madhuri Rai madhuri.ra...@gmail.com wrote: Hi All, This is to bring the blueprint secure-kubernetes https://blueprints.launchpad.net/magnum/+spec/secure-kubernetes in discussion. I have

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-15 Thread Clint Byrum
Excerpts from Fox, Kevin M's message of 2015-06-15 15:59:18 -0700: No, I was confused by your statement: When we create a bay, we have an ssh keypair that we use to inject the ssh public key onto the nova instances we create. It sounded like you were using that keypair to inject a public

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-15 Thread Tom Cammann
@lists.openstack.orgmailto:openstack-dev@lists.openstack.org Subject: Re: [openstack-dev] [Magnum] TLS Support in Magnum Hi, Thanks Adrian for the quick response. Please find my response inline. On Mon, Jun 15, 2015 at 3:09 PM, Adrian Otto adrian.o...@rackspace.commailto:adrian.o

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-15 Thread Adrian Otto
List (not for usage questions) openstack-dev@lists.openstack.orgmailto:openstack-dev@lists.openstack.org Subject: Re: [openstack-dev] [Magnum] TLS Support in Magnum Hi, Thanks Adrian for the quick response. Please find my response inline. On Mon, Jun 15, 2015 at 3:09 PM, Adrian Otto

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-15 Thread Egor Guz
@lists.openstack.orgmailto:openstack-dev@lists.openstack.org Subject: Re: [openstack-dev] [Magnum] TLS Support in Magnum Hi, Thanks Adrian for the quick response. Please find my response inline. On Mon, Jun 15, 2015 at 3:09 PM, Adrian Otto adrian.o...@rackspace.commailto:adrian.o...@rackspace.com wrote: Madhuri

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-15 Thread Adrian Otto
Madhuri, On Jun 15, 2015, at 12:47 AM, Madhuri Rai madhuri.ra...@gmail.commailto:madhuri.ra...@gmail.com wrote: Hi, Thanks Adrian for the quick response. Please find my response inline. On Mon, Jun 15, 2015 at 3:09 PM, Adrian Otto adrian.o...@rackspace.commailto:adrian.o...@rackspace.com

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-15 Thread Fox, Kevin M
, June 15, 2015 11:18 AM To: OpenStack Development Mailing List (not for usage questions) Subject: Re: [openstack-dev] [Magnum] TLS Support in Magnum Tom, On Jun 15, 2015, at 10:59 AM, Tom Cammann tom.camm...@hp.com wrote: My main issue with having the user generate the keys/certs for the kube

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-15 Thread Madhuri
] [Magnum] TLS Support in Magnum Hi, Thanks Adrian for the quick response. Please find my response inline. On Mon, Jun 15, 2015 at 3:09 PM, Adrian Otto adrian.o...@rackspace.com mailto:adrian.o...@rackspace.com wrote: Madhuri, On Jun 14, 2015, at 10:30 PM, Madhuri Rai madhuri.ra

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-15 Thread Fox, Kevin M
From: Adrian Otto [adrian.o...@rackspace.com] Sent: Monday, June 15, 2015 3:17 PM To: OpenStack Development Mailing List (not for usage questions) Subject: Re: [openstack-dev] [Magnum] TLS Support in Magnum Kevin, On Jun 15, 2015, at 1:25 PM, Fox, Kevin M kevin@pnnl.gov wrote: Why not just

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-15 Thread Adrian Otto
...@rackspace.com] Sent: Monday, June 15, 2015 3:17 PM To: OpenStack Development Mailing List (not for usage questions) Subject: Re: [openstack-dev] [Magnum] TLS Support in Magnum Kevin, On Jun 15, 2015, at 1:25 PM, Fox, Kevin M kevin@pnnl.gov wrote: Why not just push the ssh keypair via cloud

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-15 Thread Fox, Kevin M
Awesome. Thanks. :) Kevin From: Adrian Otto [adrian.o...@rackspace.com] Sent: Monday, June 15, 2015 4:13 PM To: OpenStack Development Mailing List (not for usage questions) Subject: Re: [openstack-dev] [Magnum] TLS Support in Magnum Kevin, We currently

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-15 Thread Adrian Otto
Madhuri, On Jun 14, 2015, at 10:30 PM, Madhuri Rai madhuri.ra...@gmail.commailto:madhuri.ra...@gmail.com wrote: Hi All, This is to bring the blueprint secure-kuberneteshttps://blueprints.launchpad.net/magnum/+spec/secure-kubernetes in discussion. I have been trying to figure out what could

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-15 Thread Madhuri Rai
Hi, Thanks Adrian for the quick response. Please find my response inline. On Mon, Jun 15, 2015 at 3:09 PM, Adrian Otto adrian.o...@rackspace.com wrote: Madhuri, On Jun 14, 2015, at 10:30 PM, Madhuri Rai madhuri.ra...@gmail.com wrote: Hi All, This is to bring the blueprint

Re: [openstack-dev] [Magnum] TLS Support in Magnum

2015-06-15 Thread Adrian Otto
Mailing List (not for usage questions) Subject: Re: [openstack-dev] [Magnum] TLS Support in Magnum Tom, On Jun 15, 2015, at 10:59 AM, Tom Cammann tom.camm...@hp.com wrote: My main issue with having the user generate the keys/certs for the kube nodes is that the keys have to be insecurely moved

[openstack-dev] [Magnum] TLS Support in Magnum

2015-06-14 Thread Madhuri Rai
Hi All, This is to bring the blueprint secure-kubernetes https://blueprints.launchpad.net/magnum/+spec/secure-kubernetes in discussion. I have been trying to figure out what could be the possible change area to support this feature in Magnum. Below is just a rough idea on how to proceed further