Heya,
MicroCeph uses dm-crypt for encrypted storage devices during cluster deployment.
The microceph snap has required a manual connection to dm-crypt for some time. As we add more automation around deployment, this extra step is becoming a source of friction for users (additional cognitive load and manual setup).
To my knowledge there were no specific security concerns around the dm-crypt interface that required it to remain a manual connection. Given that, I’d like to request that the dm-crypt interface be changed to auto-connect for the microceph snap.
Thanks for considering this.
This request has not been added to the review queue. It should be placed in the appropriate store-requests subcategory using the subcategory template for classic-confinement, privileged-interfaces and aliases requests.
Thanks for the reminder, bot – post is updated. Please take a look again? cc: @reviewers
This request has been added to the queue for review by the @reviewers team.
Hey @petersabaini
Sorry for the delay,
Linking the original request for extra context: Add dm-crypt interface to microceph
I have no specific concern and I think it makes sense. Thus, +1 from me (#voteFor) for granting microceph auto-connection to `dm-crypt` interface.
Thanks
Hello!
This is a +1 (#voteFor) from me as well for granting microceph auto-connection to the dm-crypt interface given the growing importance of removing this manual step. Thanks!
+2 for, 0 against granting MicroCeph auto-connection to dm-crypt interface. The publisher is vetted. This is now live.
1 Like