In OpenStack, all of the services, such as nova, neutron, Keystone, and Cinder, use the database to store the state and configuration details.
In OpenStack, all of the services use a single database to store the configuration and state. There is no such policy defined at the granular level access of the database. This means that all of the services which need database access have been granted access and privileges to the database.
So, the nodes, having access to the database, have full permission to execute any statement such as drop, update, and insert.
Now, in this situation, if any component is compromised, it can lead to a disaster. Now, to get rid of this situation, the following are the few steps one should take:
- Communication with the database is only allowed on the management network.
- Enable TLS-based communication for the database...