Improvement about encrypted volume

Registered by Lisa Li

The BP is raised to summarize the bug fix for encrypted volume in Mitaka.
The work includes:
1. As both Cinder and Nova use encryptors, plan to move nova/volume/encryptors to os-brick. So that no duplicated codes are copied between Cinder and Nova.
2. To fix following bugs related to encrypted volume:
cinder wrote unencrypted data to encrypted volumes when creating from an image https://bugs.launchpad.net/cinder/+bug/1482464
Booting encrypted volume with whole image fails https://bugs.launchpad.net/nova/+bug/1465656
Data corrupted in cinder nfs volume with encrypted volume type after detached https://bugs.launchpad.net/nova/+bug/1511255
Input validation for command encryption-type-create https://bugs.launchpad.net/cinder/+bug/1505113
Upload encrypted volume to image https://bugs.launchpad.net/cinder/+bug/1485449

Blueprint information

Status:
Complete
Approver:
Sean McGinnis
Priority:
High
Drafter:
Lisa Li
Direction:
Needs approval
Assignee:
Eric Harney
Definition:
Approved
Series goal:
None
Implementation:
Implemented
Milestone target:
None
Started by
Lisa Li
Completed by
Eric Harney

Related branches

Sprints

Whiteboard

Note: this is not a complete list of bugs related to this area. But, I believe this set of work is complete in Rocky as of https://review.openstack.org/#/q/Ie5af3703eaa8 (eharney)

Added two bugs:
Create encrypted volume from source volume: https://bugs.launchpad.net/cinder/+bug/1572007
Create encrypted volume from snapshot: https://bugs.launchpad.net/cinder/+bug/1572009

Gerrit topic: https://review.openstack.org/#q,topic:create_encrypted_volume_from_image,n,z

Addressed by: https://review.openstack.org/216567
    Create encrypted volumes from images

Gerrit topic: https://review.openstack.org/#q,topic:encrypted_volume,n,z

Addressed by: https://review.openstack.org/341914
    Add encryptor attach/detach in utils

Gerrit topic: https://review.openstack.org/#q,topic:bp/improve-encrypted-volume,n,z

Gerrit topic: https://review.openstack.org/#q,topic:bp/retype-encrypted-volume,n,z

Gerrit topic: https://review.openstack.org/#q,topic:bug/1485449,n,z

Addressed by: https://review.openstack.org/453342
    Glance: attach volume encryption key id to image

Addressed by: https://review.openstack.org/453343
    Create volumes from encrypted images

Addressed by: https://review.openstack.org/453340
    qemu_img_info: report 'luks' images as 'raw'

Addressed by: https://review.openstack.org/453341
    qemu_img_info: Don't autodetect source format

Addressed by: https://review.openstack.org/471392
    Add rel note for create volume from enc. image

(?)

Work Items

This blueprint contains Public information 
Everyone can see this information.