Page MenuHomePhabricator

Learn about Barbican
Open, Stalled, MediumPublic

Description

Current questions:

  • is the horizon UI reasonable for our use cases?

    Nope! The upstream barbican_ui project doesn't work at all with Horizon/Train. We can retest with eventual future versions.
  • how should we actually store the secrets?
  • is there any semi-secure way to integrate with puppet?

Event Timeline

Change 629460 had a related patch set uploaded (by Andrew Bogott; owner: Andrew Bogott):
[labs/private@master] Added bogus secrets for barbican testing

https://gerrit.wikimedia.org/r/629460

Change 629460 merged by Andrew Bogott:
[labs/private@master] Added bogus secrets for barbican testing

https://gerrit.wikimedia.org/r/629460

Change 629472 had a related patch set uploaded (by Andrew Bogott; owner: Andrew Bogott):
[operations/puppet@production] OpenStack: add initial manifests for OpenStack Barbican, a secrets API

https://gerrit.wikimedia.org/r/629472

Change 629680 had a related patch set uploaded (by Andrew Bogott; owner: Andrew Bogott):
[operations/puppet@production] wmcs codfw1dev haproxy: add proxy for barbican api

https://gerrit.wikimedia.org/r/629680

Change 629472 merged by Andrew Bogott:
[operations/puppet@production] OpenStack: add initial manifests for OpenStack Barbican, a secrets API

https://gerrit.wikimedia.org/r/629472

Change 629680 merged by Andrew Bogott:
[operations/puppet@production] wmcs codfw1dev haproxy: add proxy for barbican api

https://gerrit.wikimedia.org/r/629680

Change 629793 had a related patch set uploaded (by Andrew Bogott; owner: Andrew Bogott):
[openstack/horizon/deploy@master] Add barbican_ui

https://gerrit.wikimedia.org/r/629793

Change 629793 merged by Andrew Bogott:
[openstack/horizon/deploy@master] Add barbican_ui

https://gerrit.wikimedia.org/r/629793

Change 629795 had a related patch set uploaded (by Andrew Bogott; owner: Andrew Bogott):
[openstack/horizon/deploy@train] Add barbican_ui

https://gerrit.wikimedia.org/r/629795

Change 629795 merged by Andrew Bogott:
[openstack/horizon/deploy@train] Add barbican_ui

https://gerrit.wikimedia.org/r/629795

Change 629814 had a related patch set uploaded (by Andrew Bogott; owner: Andrew Bogott):
[openstack/horizon/wheels@train] Updated wheels for barbican support

https://gerrit.wikimedia.org/r/629814

Change 629814 merged by Andrew Bogott:
[openstack/horizon/wheels@train] Updated wheels for barbican support

https://gerrit.wikimedia.org/r/629814

Change 630194 had a related patch set uploaded (by Andrew Bogott; owner: Andrew Bogott):
[openstack/horizon/deploy@train] Don't install barbican panels

https://gerrit.wikimedia.org/r/630194

Change 630194 merged by Andrew Bogott:
[openstack/horizon/deploy@train] Don't install barbican panels

https://gerrit.wikimedia.org/r/630194

Andrew changed the task status from Open to Stalled.Oct 20 2020, 4:33 PM
Andrew triaged this task as Medium priority.

the Horizon UI doesn't work especially well in our current Horizon release, so I'm stalling this until we can do some upgrades.

I've worked more with the horizon UI but still don't have it working. It appears to be largely abandoned so to get things in shape I would probably need to adopt the project, at least temporarily.

The cli seems to work fine.

The next step might be to support barbican but only via the CLI and only with application credentials. That should be fairly simple to set up (it might even work already in codfw1dev).

Should this be blocked pending https endpoints? Maybe!