#7194 ODCS: Create secret private volume to share secrets between Koji runroot tasks.
Closed: It's all good 5 years ago by mohanboddu. Opened 6 years ago by jkaluza.

This is follow-up of meeting we have with @Kellin, @puiteriwjk, @mboddu, @ralph and others about using ODCS for alpha/beta composes. More info about motivation can be found here: https://docs.google.com/document/d/1VLOgxmdHL6eXMK1dZAsimJ1U3gtppntdeQkM-x8cG8I/edit#heading=h.sn2sv4429w9

In order to make ODCS scalable and keep using read-only access for /mnt/fedora_koji, we decided to run ODCS tasks in Koji runroot. That means that even the pungi running in Koji runroot task needs to be able to spawn another runroot task and therefore it needs some secret files like keytab.

The advised solution for that was creating new secret volume which could be mounted in ODCS pungi runroot task and pungi in that runroot task can read kerberos keytab from that storage.

ODCS backend/frontend would not have access to that directory.

This ticket is official request for such storage.


From our grooming discussion on #fedora-releng channel on Apr 12 2019

[16:12:59] <+nirik> .releng 7194
[16:13:00] <zodbot> nirik: Issue #7194: ODCS: Create secret private volume to share secrets between Koji runroot tasks. - releng - Pagure.io - https://pagure.io/releng/issue/7194
[16:13:19] <+nirik> no idea where this one is. we aren't using odcs for composes, so perhaps it's still wanted?
[16:13:32] <mizdebsk> odcs doesn't use runroot and it doesn't need this volume any longer
[16:13:46] <+nirik> great. I was thinking that was the case.
[16:13:57] <+nirik> proposal: closed -> whatever
[16:14:16] <+nirik> invalid, or it's all good...

Metadata Update from @mohanboddu:
- Issue close_status updated to: It's all good
- Issue status updated to: Closed (was: Open)

5 years ago

Login to comment on this ticket.

Metadata