)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"a5486925e97e7cc7cbbf99beb045dcfd9d9335d6","unresolved":true,"context_lines":[{"line_number":34,"context_line":"My understanding is that all the data (realms configuration and session)"},{"line_number":35,"context_line":"are kept in an H2 database.  This is probably sufficient for now and even"},{"line_number":36,"context_line":"production use with Zuul, but we should probably switch to mariadb before"},{"line_number":37,"context_line":"any heavy (eg gerrit, etc) production use."},{"line_number":38,"context_line":""},{"line_number":39,"context_line":"This is a partial implementation of https://docs.opendev.org/opendev/infra-specs/latest/specs/central-auth.html"},{"line_number":40,"context_line":""}],"source_content_type":"text/x-gerrit-commit-message","patch_set":9,"id":"bd3fb77c_f3be6fce","line":37,"updated":"2021-12-03 20:47:34.000000000","message":"Does this need to be backed up?\n\nWe can add it later, but it\u0027s probably easier to get the job dependencies right but just doing it now, if so","commit_id":"c2faef9d646e6cecac23ac8e1aa2315de167bed8"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"782c85f4635cddf563d099a4871057e456eee8a2","unresolved":false,"context_lines":[{"line_number":34,"context_line":"My understanding is that all the data (realms configuration and session)"},{"line_number":35,"context_line":"are kept in an H2 database.  This is probably sufficient for now and even"},{"line_number":36,"context_line":"production use with Zuul, but we should probably switch to mariadb before"},{"line_number":37,"context_line":"any heavy (eg gerrit, etc) production use."},{"line_number":38,"context_line":""},{"line_number":39,"context_line":"This is a partial implementation of https://docs.opendev.org/opendev/infra-specs/latest/specs/central-auth.html"},{"line_number":40,"context_line":""}],"source_content_type":"text/x-gerrit-commit-message","patch_set":9,"id":"8ace19b8_0bc57b7d","line":37,"updated":"2021-12-03 22:15:54.000000000","message":"I think so, because I think that\u0027s where it will store user mappings if we do federated IDs with openstackid.\n\nBut I\u0027m not positive, and because of the flaw in openstackid that disallows use with localhost, I can\u0027t really be positive what we\u0027re going to need to back up.  So I think I\u0027d like to avoid sinking effort into that now and deal with it when we decide this is production-worthy (we\u0027ll want it in its own domain then too, so it\u0027s going to be a redeployment).","commit_id":"c2faef9d646e6cecac23ac8e1aa2315de167bed8"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"7a696c92e3d515856425061f4fbf00ef1f58965a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"f91bd1e5_6ab10b45","updated":"2021-12-01 14:00:34.000000000","message":"This seems to be an implementation of https://docs.opendev.org/opendev/infra-specs/latest/specs/central-auth.html, would be good to link to that somewhere.\n\nThat document also states that we likely want a dedicated domain for this service, should we start with that directly instead of having to move later?","commit_id":"3e7eeba1cebaca43df6936554964910f020d690b"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"63d2aa9ff2c51f35c06ee3e809a6afe9cec53014","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"6da73fa0_0dbb2c66","updated":"2021-12-03 03:23:52.000000000","message":"A few nits inline, but generally LGTM.  if you want to ignore, or do in follow-ons, fine","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"}],"doc/source/keycloak.rst":[{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"032cea362d0617fa6b85ff2850215d7f91e6be3e","unresolved":true,"context_lines":[{"line_number":13,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":14,"context_line":""},{"line_number":15,"context_line":":Hosts:"},{"line_number":16,"context_line":"  * http://keycloak.opendev.org"},{"line_number":17,"context_line":":Ansible:"},{"line_number":18,"context_line":"  * https://opendev.org/opendev/system-config"},{"line_number":19,"context_line":"  * :git_file:`playbooks/roles/keycloak`"}],"source_content_type":"text/x-rst","patch_set":7,"id":"52c33ca6_8682d72e","line":16,"range":{"start_line":16,"start_character":4,"end_line":16,"end_character":8},"updated":"2021-12-03 10:18:42.000000000","message":"https?","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"032cea362d0617fa6b85ff2850215d7f91e6be3e","unresolved":true,"context_lines":[{"line_number":29,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"Apache is configured as a reverse proxy and there is an internal H2"},{"line_number":32,"context_line":"database stored at `/var/keycloak/data`."}],"source_content_type":"text/x-rst","patch_set":7,"id":"1efc2187_6d6382fa","line":32,"range":{"start_line":32,"start_character":19,"end_line":32,"end_character":39},"updated":"2021-12-03 10:18:42.000000000","message":"``/var/keycloak/data`` for nice monospace font","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"}],"inventory/service/groups.yaml":[{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"314ecda0bd37c90492f64a390c4c2c823e6d5abc","unresolved":false,"context_lines":[{"line_number":191,"context_line":"    - grafana[0-9]*.opendev.org"},{"line_number":192,"context_line":"    - graphite*.opendev.org"},{"line_number":193,"context_line":"    - health[0-9]*.openstack.org"},{"line_number":194,"context_line":"    - keycloak[0-9]*.open*.org"},{"line_number":195,"context_line":"    - nb[0-9]*.opendev.org"},{"line_number":196,"context_line":"    - nl[0-9]*.open*.org"},{"line_number":197,"context_line":"    - paste[0-9]*.opendev.org"}],"source_content_type":"text/x-yaml","patch_set":8,"id":"73bad0f5_66aec5f7","line":194,"updated":"2021-12-03 17:18:26.000000000","message":"Any reason it\u0027s not just opendev.org? Is there a plan to also have openstack.org hosts?","commit_id":"cc9dda41893c1a1c81d8d53f319bb5f973f42b9f"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"89095e939456abb96e40e4fff7d8f3ab6acffb6b","unresolved":false,"context_lines":[{"line_number":191,"context_line":"    - grafana[0-9]*.opendev.org"},{"line_number":192,"context_line":"    - graphite*.opendev.org"},{"line_number":193,"context_line":"    - health[0-9]*.openstack.org"},{"line_number":194,"context_line":"    - keycloak[0-9]*.open*.org"},{"line_number":195,"context_line":"    - nb[0-9]*.opendev.org"},{"line_number":196,"context_line":"    - nl[0-9]*.open*.org"},{"line_number":197,"context_line":"    - paste[0-9]*.opendev.org"}],"source_content_type":"text/x-yaml","patch_set":8,"id":"8200b533_2db0d729","line":194,"updated":"2021-12-03 17:23:55.000000000","message":"Nope, copypasta.  I got it right above but missed this.  Will fix.","commit_id":"cc9dda41893c1a1c81d8d53f319bb5f973f42b9f"}],"inventory/service/host_vars/keycloak01.opendev.org.yaml":[{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"3df67b90382852e59d3ea23cb277ae2481a80370","unresolved":false,"context_lines":[{"line_number":1,"context_line":"letsencrypt_certs:"},{"line_number":2,"context_line":"  keycloak01-opendev-org-main:"},{"line_number":3,"context_line":"    - keycloak.opendev.org"},{"line_number":4,"context_line":"    - keycloak01.opendev.org"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"8e9808e4_ed24b0bb","line":4,"updated":"2021-12-03 16:40:24.000000000","message":"It looks like a mixed bag, actually, I see plenty of examples both ways.  If this is important, perhaps the rest should be changed?  And maybe the role should use the dict key (\"keycloak01-opendev-org-main\") as the file instead?","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"63d2aa9ff2c51f35c06ee3e809a6afe9cec53014","unresolved":true,"context_lines":[{"line_number":1,"context_line":"letsencrypt_certs:"},{"line_number":2,"context_line":"  keycloak01-opendev-org-main:"},{"line_number":3,"context_line":"    - keycloak.opendev.org"},{"line_number":4,"context_line":"    - keycloak01.opendev.org"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"6bf81e6f_f470c4ca","line":4,"updated":"2021-12-03 03:23:52.000000000","message":"we\u0027ve generally ordered this the other way, with the first element (which give the cert name) being the servername (01) and then the generic alias after.  probably prefer to see this switched as it makes a little more sense in the file layout of the certs.","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"}],"playbooks/roles/keycloak/README.rst":[{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"032cea362d0617fa6b85ff2850215d7f91e6be3e","unresolved":true,"context_lines":[{"line_number":1,"context_line":"Run an Keycloak server."}],"source_content_type":"text/x-rst","patch_set":7,"id":"7e5a4e46_ef3bc2f4","line":1,"range":{"start_line":1,"start_character":4,"end_line":1,"end_character":6},"updated":"2021-12-03 10:18:42.000000000","message":"a?","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"}],"playbooks/roles/keycloak/tasks/main.yaml":[{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"032cea362d0617fa6b85ff2850215d7f91e6be3e","unresolved":true,"context_lines":[{"line_number":1,"context_line":"- name: Ensure docker-compose directory exists"},{"line_number":2,"context_line":"  file:"},{"line_number":3,"context_line":"    state: directory"},{"line_number":4,"context_line":"    path: /etc/keycloak-docker"},{"line_number":5,"context_line":""},{"line_number":6,"context_line":"- name: Write settings file"},{"line_number":7,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"0492697a_40a23199","line":4,"updated":"2021-12-03 10:18:42.000000000","message":"Be explicit about owner/group/mode here?","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"3df67b90382852e59d3ea23cb277ae2481a80370","unresolved":false,"context_lines":[{"line_number":1,"context_line":"- name: Ensure docker-compose directory exists"},{"line_number":2,"context_line":"  file:"},{"line_number":3,"context_line":"    state: directory"},{"line_number":4,"context_line":"    path: /etc/keycloak-docker"},{"line_number":5,"context_line":""},{"line_number":6,"context_line":"- name: Write settings file"},{"line_number":7,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"fc83e266_5b572006","line":4,"updated":"2021-12-03 16:40:24.000000000","message":"We aren\u0027t in other similar roles; this runs as root and that behavior is expected.","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"032cea362d0617fa6b85ff2850215d7f91e6be3e","unresolved":true,"context_lines":[{"line_number":6,"context_line":"- name: Write settings file"},{"line_number":7,"context_line":"  template:"},{"line_number":8,"context_line":"    src: docker-compose.yaml.j2"},{"line_number":9,"context_line":"    dest: /etc/keycloak-docker/docker-compose.yaml"},{"line_number":10,"context_line":""},{"line_number":11,"context_line":"- name: Ensure data directory exists"},{"line_number":12,"context_line":"  file:"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"3aa46725_4e8b350e","line":9,"updated":"2021-12-03 10:18:42.000000000","message":"dito","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"032cea362d0617fa6b85ff2850215d7f91e6be3e","unresolved":true,"context_lines":[{"line_number":12,"context_line":"  file:"},{"line_number":13,"context_line":"    state: directory"},{"line_number":14,"context_line":"    path: /var/keycloak/data"},{"line_number":15,"context_line":"    owner: \"1000\""},{"line_number":16,"context_line":"    group: \"root\""},{"line_number":17,"context_line":"    mode: \"0755\""},{"line_number":18,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":7,"id":"c2218845_e4d4d493","line":15,"updated":"2021-12-03 10:18:42.000000000","message":"I\u0027m assuming that this is the userid that is hardcoded inside the container? Maybe add a comment about this? I guess we\u0027d later want to get this more in line with our uid scheme.","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"3df67b90382852e59d3ea23cb277ae2481a80370","unresolved":false,"context_lines":[{"line_number":12,"context_line":"  file:"},{"line_number":13,"context_line":"    state: directory"},{"line_number":14,"context_line":"    path: /var/keycloak/data"},{"line_number":15,"context_line":"    owner: \"1000\""},{"line_number":16,"context_line":"    group: \"root\""},{"line_number":17,"context_line":"    mode: \"0755\""},{"line_number":18,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":7,"id":"702aea1d_47311ff5","line":15,"updated":"2021-12-03 16:40:24.000000000","message":"Yes.","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"032cea362d0617fa6b85ff2850215d7f91e6be3e","unresolved":true,"context_lines":[{"line_number":19,"context_line":"- name: Ensure log directory exists"},{"line_number":20,"context_line":"  file:"},{"line_number":21,"context_line":"    state: directory"},{"line_number":22,"context_line":"    path: /var/keycloak/log"},{"line_number":23,"context_line":"    owner: \"1000\""},{"line_number":24,"context_line":"    group: \"root\""},{"line_number":25,"context_line":"    mode: \"0755\""}],"source_content_type":"text/x-yaml","patch_set":7,"id":"0becf648_5881641e","line":22,"updated":"2021-12-03 10:18:42.000000000","message":"I\u0027d prefer /var/log/keycloak if possible","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"3df67b90382852e59d3ea23cb277ae2481a80370","unresolved":false,"context_lines":[{"line_number":19,"context_line":"- name: Ensure log directory exists"},{"line_number":20,"context_line":"  file:"},{"line_number":21,"context_line":"    state: directory"},{"line_number":22,"context_line":"    path: /var/keycloak/log"},{"line_number":23,"context_line":"    owner: \"1000\""},{"line_number":24,"context_line":"    group: \"root\""},{"line_number":25,"context_line":"    mode: \"0755\""}],"source_content_type":"text/x-yaml","patch_set":7,"id":"f2af99a7_a54dc514","line":22,"updated":"2021-12-03 16:40:24.000000000","message":"We could do that; we seem to be trending toward keeping all the container mapped directories together.","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"}],"playbooks/roles/keycloak/templates/docker-compose.yaml.j2":[{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"d11e91018ee3024dec8517f344d725fe5ffba3d0","unresolved":true,"context_lines":[{"line_number":4,"context_line":""},{"line_number":5,"context_line":"services:"},{"line_number":6,"context_line":"  keycloak:"},{"line_number":7,"context_line":"    image: docker.io/jboss/keycloak"},{"line_number":8,"context_line":"    network_mode: host"},{"line_number":9,"context_line":"    restart: always"},{"line_number":10,"context_line":"    environment:"}],"source_content_type":"text/x-jinja2","patch_set":6,"id":"61383e92_00cb07bc","line":7,"updated":"2021-12-01 22:03:36.000000000","message":"Just noting that this image doesn\u0027t appear to do a tag for the latest release of each major release. In that case pulling latest (as this does) is probably our best option. Then maybe when we get closer to production we can think about pinning it appropriately if that becomes necessary.","commit_id":"f82695fcb863abb8795be56f4095031eb30f0053"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"d11e91018ee3024dec8517f344d725fe5ffba3d0","unresolved":true,"context_lines":[{"line_number":13,"context_line":"      - DB_VENDOR\u003dh2"},{"line_number":14,"context_line":"    command:"},{"line_number":15,"context_line":"      -Djboss.bind.address.private\u003d127.0.0.1"},{"line_number":16,"context_line":"      -Djboss.bind.address\u003d0.0.0.0"},{"line_number":17,"context_line":"    volumes:"},{"line_number":18,"context_line":"      - /var/keycloak/data:/opt/jboss/keycloak/standalone/data"},{"line_number":19,"context_line":"      - /var/keycloak/log:/opt/jboss/keycloak/standalone/log"}],"source_content_type":"text/x-jinja2","patch_set":6,"id":"a7ad4923_45f463b1","line":16,"updated":"2021-12-01 22:03:36.000000000","message":"Do we need to bind to 0.0.0.0 if we are reverse proxying with apache?","commit_id":"f82695fcb863abb8795be56f4095031eb30f0053"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"92153ac53ed3b6e98155cc519333615a5ad8c247","unresolved":false,"context_lines":[{"line_number":13,"context_line":"      - DB_VENDOR\u003dh2"},{"line_number":14,"context_line":"    command:"},{"line_number":15,"context_line":"      -Djboss.bind.address.private\u003d127.0.0.1"},{"line_number":16,"context_line":"      -Djboss.bind.address\u003d0.0.0.0"},{"line_number":17,"context_line":"    volumes:"},{"line_number":18,"context_line":"      - /var/keycloak/data:/opt/jboss/keycloak/standalone/data"},{"line_number":19,"context_line":"      - /var/keycloak/log:/opt/jboss/keycloak/standalone/log"}],"source_content_type":"text/x-jinja2","patch_set":6,"id":"8a7d6938_c7463631","line":16,"updated":"2021-12-02 21:14:12.000000000","message":"Nope, fixed.","commit_id":"f82695fcb863abb8795be56f4095031eb30f0053"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"92153ac53ed3b6e98155cc519333615a5ad8c247","unresolved":false,"context_lines":[{"line_number":17,"context_line":"    volumes:"},{"line_number":18,"context_line":"      - /var/keycloak/data:/opt/jboss/keycloak/standalone/data"},{"line_number":19,"context_line":"      - /var/keycloak/log:/opt/jboss/keycloak/standalone/log"},{"line_number":20,"context_line":"    command: []"}],"source_content_type":"text/x-jinja2","patch_set":6,"id":"7a21b10b_1f2b7e33","line":20,"updated":"2021-12-02 21:14:12.000000000","message":"Er, actually we need to remove this because it\u0027s shadowing the command above (which we need to do to add the private address which for some reason isn\u0027t detected correctly in our setup (possibly ipv6 related).","commit_id":"f82695fcb863abb8795be56f4095031eb30f0053"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"d11e91018ee3024dec8517f344d725fe5ffba3d0","unresolved":true,"context_lines":[{"line_number":17,"context_line":"    volumes:"},{"line_number":18,"context_line":"      - /var/keycloak/data:/opt/jboss/keycloak/standalone/data"},{"line_number":19,"context_line":"      - /var/keycloak/log:/opt/jboss/keycloak/standalone/log"},{"line_number":20,"context_line":"    command: []"}],"source_content_type":"text/x-jinja2","patch_set":6,"id":"da2fb1c5_17f0db65","line":20,"updated":"2021-12-01 22:03:36.000000000","message":"Is this a noop? Maybe we can drop the line?","commit_id":"f82695fcb863abb8795be56f4095031eb30f0053"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"6a4ab8ab19087e9fd89e9b4475763746350556ce","unresolved":true,"context_lines":[{"line_number":17,"context_line":"    volumes:"},{"line_number":18,"context_line":"      - /var/keycloak/data:/opt/jboss/keycloak/standalone/data"},{"line_number":19,"context_line":"      - /var/keycloak/log:/opt/jboss/keycloak/standalone/log"},{"line_number":20,"context_line":"    command: []"}],"source_content_type":"text/x-jinja2","patch_set":6,"id":"559aeac2_e5e5a2e2","line":20,"in_reply_to":"da2fb1c5_17f0db65","updated":"2021-12-01 22:32:53.000000000","message":"https://github.com/keycloak/keycloak-containers/blob/main/server/Dockerfile#L32 shows why this is done. They set flags to the entrypoint this way looks like. We are removing the flags here.","commit_id":"f82695fcb863abb8795be56f4095031eb30f0053"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"032cea362d0617fa6b85ff2850215d7f91e6be3e","unresolved":true,"context_lines":[{"line_number":1,"context_line":"# Version 2 is the latest that is supported by docker-compose in"},{"line_number":2,"context_line":"# Ubuntu Xenial."},{"line_number":3,"context_line":"version: \u00272\u0027"},{"line_number":4,"context_line":""},{"line_number":5,"context_line":"services:"}],"source_content_type":"text/x-jinja2","patch_set":7,"id":"fb1c628f_ad6c620c","line":2,"updated":"2021-12-03 10:18:42.000000000","message":"This is probably just copied from somewhere, but is xenial still relevant?","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"3df67b90382852e59d3ea23cb277ae2481a80370","unresolved":false,"context_lines":[{"line_number":1,"context_line":"# Version 2 is the latest that is supported by docker-compose in"},{"line_number":2,"context_line":"# Ubuntu Xenial."},{"line_number":3,"context_line":"version: \u00272\u0027"},{"line_number":4,"context_line":""},{"line_number":5,"context_line":"services:"}],"source_content_type":"text/x-jinja2","patch_set":7,"id":"5ef1414f_1979d0dc","line":2,"updated":"2021-12-03 16:40:24.000000000","message":"Yes, we put this in every docker-compose file so that people know why we chose version 2.  We should specify the lowest level necessary.","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"}],"playbooks/roles/keycloak/templates/keycloak.vhost.j2":[{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"92153ac53ed3b6e98155cc519333615a5ad8c247","unresolved":false,"context_lines":[{"line_number":38,"context_line":"      nokeepalive ssl-unclean-shutdown \\"},{"line_number":39,"context_line":"      downgrade-1.0 force-response-1.0"},{"line_number":40,"context_line":"  # MSIE 7 and newer should be able to use keepalive"},{"line_number":41,"context_line":"  BrowserMatch \"MSIE [17-9]\" ssl-unclean-shutdown"},{"line_number":42,"context_line":""},{"line_number":43,"context_line":"  RewriteEngine on"},{"line_number":44,"context_line":""}],"source_content_type":"text/x-jinja2","patch_set":6,"id":"971f1ecf_01acbdfc","line":41,"updated":"2021-12-02 21:14:12.000000000","message":"This is copy-pasta to match our existing vhosts.","commit_id":"f82695fcb863abb8795be56f4095031eb30f0053"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"d11e91018ee3024dec8517f344d725fe5ffba3d0","unresolved":true,"context_lines":[{"line_number":38,"context_line":"      nokeepalive ssl-unclean-shutdown \\"},{"line_number":39,"context_line":"      downgrade-1.0 force-response-1.0"},{"line_number":40,"context_line":"  # MSIE 7 and newer should be able to use keepalive"},{"line_number":41,"context_line":"  BrowserMatch \"MSIE [17-9]\" ssl-unclean-shutdown"},{"line_number":42,"context_line":""},{"line_number":43,"context_line":"  RewriteEngine on"},{"line_number":44,"context_line":""}],"source_content_type":"text/x-jinja2","patch_set":6,"id":"b497e132_fa809824","line":41,"updated":"2021-12-01 22:03:36.000000000","message":"We might be able to say no more old IE support. The cipher list above probably does that too.","commit_id":"f82695fcb863abb8795be56f4095031eb30f0053"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"ca874344e44f488adce524bb388088d02042f8af","unresolved":false,"context_lines":[{"line_number":30,"context_line":"  SSLCipherSuite ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:!AES256:!aNULL:!eNULL:!MD5:!DSS:!PSK:!SRP"},{"line_number":31,"context_line":"  SSLHonorCipherOrder on"},{"line_number":32,"context_line":""},{"line_number":33,"context_line":"  SSLCertificateFile /etc/letsencrypt-certs/keycloak.opendev.org/keycloak.opendev.org.cer"},{"line_number":34,"context_line":"  SSLCertificateKeyFile /etc/letsencrypt-certs/keycloak.opendev.org/keycloak.opendev.org.key"},{"line_number":35,"context_line":"  SSLCertificateChainFile /etc/letsencrypt-certs/keycloak.opendev.org/ca.cer"},{"line_number":36,"context_line":""}],"source_content_type":"text/x-jinja2","patch_set":9,"id":"da20b884_63054ec6","line":33,"updated":"2021-12-03 21:21:38.000000000","message":"I bet that explains Apache failing to load its config. It might be a good idea to collect its logs to make diagnosing failures there easier in the future.","commit_id":"c2faef9d646e6cecac23ac8e1aa2315de167bed8"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"782c85f4635cddf563d099a4871057e456eee8a2","unresolved":false,"context_lines":[{"line_number":30,"context_line":"  SSLCipherSuite ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:!AES256:!aNULL:!eNULL:!MD5:!DSS:!PSK:!SRP"},{"line_number":31,"context_line":"  SSLHonorCipherOrder on"},{"line_number":32,"context_line":""},{"line_number":33,"context_line":"  SSLCertificateFile /etc/letsencrypt-certs/keycloak.opendev.org/keycloak.opendev.org.cer"},{"line_number":34,"context_line":"  SSLCertificateKeyFile /etc/letsencrypt-certs/keycloak.opendev.org/keycloak.opendev.org.key"},{"line_number":35,"context_line":"  SSLCertificateChainFile /etc/letsencrypt-certs/keycloak.opendev.org/ca.cer"},{"line_number":36,"context_line":""}],"source_content_type":"text/x-jinja2","patch_set":9,"id":"2cafed57_75b7e0fb","line":33,"updated":"2021-12-03 22:15:54.000000000","message":"Okay, then I think we should switch this back to the other thing since that would mean that we have to template this for the hostname and that seems unecssary.","commit_id":"c2faef9d646e6cecac23ac8e1aa2315de167bed8"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"a5486925e97e7cc7cbbf99beb045dcfd9d9335d6","unresolved":true,"context_lines":[{"line_number":30,"context_line":"  SSLCipherSuite ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:!AES256:!aNULL:!eNULL:!MD5:!DSS:!PSK:!SRP"},{"line_number":31,"context_line":"  SSLHonorCipherOrder on"},{"line_number":32,"context_line":""},{"line_number":33,"context_line":"  SSLCertificateFile /etc/letsencrypt-certs/keycloak.opendev.org/keycloak.opendev.org.cer"},{"line_number":34,"context_line":"  SSLCertificateKeyFile /etc/letsencrypt-certs/keycloak.opendev.org/keycloak.opendev.org.key"},{"line_number":35,"context_line":"  SSLCertificateChainFile /etc/letsencrypt-certs/keycloak.opendev.org/ca.cer"},{"line_number":36,"context_line":""}],"source_content_type":"text/x-jinja2","patch_set":9,"id":"aa5425f0_c5f9f202","line":33,"updated":"2021-12-03 20:47:34.000000000","message":"This should now go to keycloak01 after taking my prior suggestion to swap it around","commit_id":"c2faef9d646e6cecac23ac8e1aa2315de167bed8"}],"playbooks/zuul/run-base.yaml":[{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"032cea362d0617fa6b85ff2850215d7f91e6be3e","unresolved":true,"context_lines":[{"line_number":58,"context_line":"        - group_vars/registry.yaml"},{"line_number":59,"context_line":"        - group_vars/gitea.yaml"},{"line_number":60,"context_line":"        - group_vars/gitea-lb.yaml"},{"line_number":61,"context_line":"        - group_vars/keycloak.yaml"},{"line_number":62,"context_line":"        - group_vars/kerberos-kdc.yaml"},{"line_number":63,"context_line":"        - group_vars/letsencrypt.yaml"},{"line_number":64,"context_line":"        - group_vars/meetpad.yaml"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"607a6837_c46b9289","line":61,"updated":"2021-12-03 10:18:42.000000000","message":"Nit: \"key\" after \"ker\" to keep at least some kind of local ordering","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"3df67b90382852e59d3ea23cb277ae2481a80370","unresolved":false,"context_lines":[{"line_number":58,"context_line":"        - group_vars/registry.yaml"},{"line_number":59,"context_line":"        - group_vars/gitea.yaml"},{"line_number":60,"context_line":"        - group_vars/gitea-lb.yaml"},{"line_number":61,"context_line":"        - group_vars/keycloak.yaml"},{"line_number":62,"context_line":"        - group_vars/kerberos-kdc.yaml"},{"line_number":63,"context_line":"        - group_vars/letsencrypt.yaml"},{"line_number":64,"context_line":"        - group_vars/meetpad.yaml"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"2495bc6d_a8ac3bb7","line":61,"updated":"2021-12-03 16:40:24.000000000","message":"This list is already very much not in alphabetical order.","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"}],"testinfra/test_keycloak.py":[{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"63d2aa9ff2c51f35c06ee3e809a6afe9cec53014","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":7,"id":"ba8ba4e7_8f6ea080","line":23,"updated":"2021-12-03 03:23:52.000000000","message":"probably be good to validate this through the apache proxy as well.\n\nmight be a good idea to validate the /server-status url here (the bit blocked in apache) to confirm as well","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"a5486925e97e7cc7cbbf99beb045dcfd9d9335d6","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":9,"id":"02d75c0f_69237d07","line":23,"updated":"2021-12-03 20:47:34.000000000","message":"any reason to not validate the server-status page via the apache proxy here?  seems like it would be good validation it was actually responding","commit_id":"c2faef9d646e6cecac23ac8e1aa2315de167bed8"}],"zuul.d/system-config-run.yaml":[{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"92153ac53ed3b6e98155cc519333615a5ad8c247","unresolved":false,"context_lines":[{"line_number":706,"context_line":"      - playbooks/roles/keycloak/"},{"line_number":707,"context_line":"      - playbooks/roles/install-docker/"},{"line_number":708,"context_line":"      - playbooks/roles/iptables/"},{"line_number":709,"context_line":"      - testinfra/test_keycloak.py"},{"line_number":710,"context_line":""},{"line_number":711,"context_line":"- job:"},{"line_number":712,"context_line":"    name: system-config-run-meetpad"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"92b41993_5389f740","line":709,"updated":"2021-12-02 21:14:12.000000000","message":"Done.","commit_id":"f82695fcb863abb8795be56f4095031eb30f0053"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"d11e91018ee3024dec8517f344d725fe5ffba3d0","unresolved":true,"context_lines":[{"line_number":706,"context_line":"      - playbooks/roles/keycloak/"},{"line_number":707,"context_line":"      - playbooks/roles/install-docker/"},{"line_number":708,"context_line":"      - playbooks/roles/iptables/"},{"line_number":709,"context_line":"      - testinfra/test_keycloak.py"},{"line_number":710,"context_line":""},{"line_number":711,"context_line":"- job:"},{"line_number":712,"context_line":"    name: system-config-run-meetpad"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"3e910e53_d888241d","line":709,"updated":"2021-12-01 22:03:36.000000000","message":"We should also add these files to the list:\n\n  inventory/service/host_vars/keycloak01.opendev.org.yaml\n  playbooks/zuul/templates/group_vars/keycloak.yaml.j2","commit_id":"f82695fcb863abb8795be56f4095031eb30f0053"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"3df67b90382852e59d3ea23cb277ae2481a80370","unresolved":false,"context_lines":[{"line_number":701,"context_line":"        - playbooks/service-keycloak.yaml"},{"line_number":702,"context_line":"    files:"},{"line_number":703,"context_line":"      - inventory/service/host_vars/keycloak01.opendev.org.yaml"},{"line_number":704,"context_line":"      - playbooks/bridge.yaml"},{"line_number":705,"context_line":"      - playbooks/letsencrypt.yaml"},{"line_number":706,"context_line":"      - playbooks/service-keycloak.yaml"},{"line_number":707,"context_line":"      - playbooks/roles/keycloak/"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"ddc551aa_8c6cabdb","line":704,"updated":"2021-12-03 16:40:24.000000000","message":"I think this change raced your work.","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"63d2aa9ff2c51f35c06ee3e809a6afe9cec53014","unresolved":true,"context_lines":[{"line_number":701,"context_line":"        - playbooks/service-keycloak.yaml"},{"line_number":702,"context_line":"    files:"},{"line_number":703,"context_line":"      - inventory/service/host_vars/keycloak01.opendev.org.yaml"},{"line_number":704,"context_line":"      - playbooks/bridge.yaml"},{"line_number":705,"context_line":"      - playbooks/letsencrypt.yaml"},{"line_number":706,"context_line":"      - playbooks/service-keycloak.yaml"},{"line_number":707,"context_line":"      - playbooks/roles/keycloak/"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"c1ea038f_e2c7c704","line":704,"range":{"start_line":704,"start_character":6,"end_line":704,"end_character":29},"updated":"2021-12-03 03:23:52.000000000","message":"this should actually be playbooks/install-ansible.yaml (see https://review.opendev.org/c/opendev/system-config/+/820281)","commit_id":"c107490104e2a7d9e1c1272e2131a21ceddf1af6"}]}
