cinder/cinder/tests/unit/keymgr
Alan Bishop 189a1096da Migrate fixed_key encryption keys to Barbican
Assist users who are switching from the legacy ConfKeyManager to
Barbican by automatically migrating any existing keys. Key migration
is executed in its own thread spawned on cinder-volume startup. Two
factors are used to determine whether existing keys need to be
migrated.

1) The ConfKeyManager's fixed_key config value is set (not None).
   This indicates volumes may exist that were encrypted using the
   ConfKeyManager.
2) Barbican is the current key manager.

When the both conditions are met, each instance of the cinder-volume
service scans its volumes in the database, looking for volumes using
the ConfKeyManager's all-zeros encryption key ID. If a volume has an
all-zeros key ID, the same secret (derived from the fixed_key) is stored
in Barbican, and all database references to that volume's key ID are
replaced with the new Barbican key ID.

Implements: blueprint migrate-fixed-key-to-barbican
Change-Id: Ic70f45762cf4e426c222415e49b947a328282ca0
2017-12-01 15:30:32 -05:00
..
__init__.py Move unit tests into dedicated directory 2015-04-21 18:40:40 -06:00
fake.py Replace key manager with Castellan 2016-08-29 10:19:10 +08:00
test_conf_key_mgr.py Implement keymgr list() method 2017-09-07 07:27:48 -05:00
test_migration.py Migrate fixed_key encryption keys to Barbican 2017-12-01 15:30:32 -05:00