)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"49566c29e13a3a4fc0af2a32c60921b5fbc9dac2","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"a48197b9_93b47700","updated":"2022-09-21 03:54:04.000000000","message":"recheck","commit_id":"d0102d2eb2f90572f0d4c4b8b17d905cf9dd4eb4"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"c0b8e08ac9afe74c45bdc74fba1087e58eb70d38","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"4ff787cf_5b8c0799","updated":"2022-10-10 21:46:01.000000000","message":"This will also need a corresponding update to the base jobs repo where we add host there.","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"9f06f61fc0a6f8e870abeee1785a5399dbe7c20e","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"787e2da1_f3dde873","updated":"2022-10-10 21:04:54.000000000","message":"recheck","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"032b8a14c0867807d8e93684d6aaa79255314614","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"b97ba25b_d99c38e1","in_reply_to":"4ff787cf_5b8c0799","updated":"2022-10-12 03:55:20.000000000","message":"see Icc52d2544afc1faf519a036cda94a3cae10448ee","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"e34eec9035563e542ec91ccbdd4d850c2c90cb8d","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":10,"id":"55dcaf29_25e36365","updated":"2022-10-12 05:29:25.000000000","message":"recheck","commit_id":"b8b3c5dca46694882099553f8d7fd1eeb36332ba"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"eaa54a0e218be6340702eb447ebc24c013b276a7","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":10,"id":"c20c3855_a3cb8b20","updated":"2022-10-12 17:45:15.000000000","message":"recheck","commit_id":"b8b3c5dca46694882099553f8d7fd1eeb36332ba"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"4db8372843ec62e5454a1cad585ce87f42e5fe0a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":14,"id":"740322f5_99d25abf","updated":"2022-10-16 23:40:17.000000000","message":"recheck","commit_id":"db1cedaf046987253a0de75f106169dfcda247c3"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"125c1f6f7a674aaa61cc380c9c810a4102e0aa6b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":15,"id":"8527a46a_4d888aec","updated":"2022-10-24 02:15:51.000000000","message":"I merged this as it failed in gate and then check all for unrelated node reasons, but has passed before.  I\u0027m monitoring this so we can get a host deploeyd","commit_id":"d4c46ecdef0a14da9fdde8a9efe144d83355b3b1"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"24c6ed39c17e9bb7a7de886076c56a2284a8bb39","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":15,"id":"c35e055a_ce1ce71b","updated":"2022-10-23 23:36:05.000000000","message":"merging this based on prior review.  this should make no difference, but i will watch closely","commit_id":"d4c46ecdef0a14da9fdde8a9efe144d83355b3b1"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"1a72fda2b15913b4b8a85bace927f32d632d5508","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":15,"id":"d8d8c19e_e674cbd0","updated":"2022-10-24 00:46:29.000000000","message":"recheck","commit_id":"d4c46ecdef0a14da9fdde8a9efe144d83355b3b1"}],"playbooks/roles/sync-project-config/tasks/main.yaml":[{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"dc4d00e892525dcef6e2eb121e2d0683ca2c4a44","unresolved":true,"context_lines":[{"line_number":5,"context_line":""},{"line_number":6,"context_line":"- name: Update from master on bastion host"},{"line_number":7,"context_line":"  when: infra_prod_run_from_master|bool"},{"line_number":8,"context_line":"  delegate_to: \u0027{{ groups[\"bastion\"][0] }}\u0027"},{"line_number":9,"context_line":"  git:"},{"line_number":10,"context_line":"    repo: https://opendev.org/openstack/project-config"},{"line_number":11,"context_line":"    dest: \u0027{{ project_config_src }}\u0027"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"2fe23d9e_1505d864","line":8,"updated":"2022-10-10 21:38:32.000000000","message":"If we can have this run on multiple bastion hosts to keep them all in sync that might be best? But I guess delegate_to wants a singular delegate.","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"}],"playbooks/zuul/run-base-post.yaml":[{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"dc4d00e892525dcef6e2eb121e2d0683ca2c4a44","unresolved":true,"context_lines":[{"line_number":69,"context_line":"          zuul:"},{"line_number":70,"context_line":"            artifacts:"},{"line_number":71,"context_line":"              - name: ARA report"},{"line_number":72,"context_line":"                url: \u0027{{ groups[\"bastion\"][0] }}/ara-report/\u0027"},{"line_number":73,"context_line":""},{"line_number":74,"context_line":"    - name: Collect ansible configuration"},{"line_number":75,"context_line":"      synchronize:"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"03f3cf5a_270fa8cd","line":72,"updated":"2022-10-10 21:38:32.000000000","message":"See comments in the run-base.yaml playbook about avoiding running tasks on all bastion hosts via line 31 and then using a singular entry here.","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"3e956d368efb8a7a466ac6e33352e3d5e4725e63","unresolved":false,"context_lines":[{"line_number":69,"context_line":"          zuul:"},{"line_number":70,"context_line":"            artifacts:"},{"line_number":71,"context_line":"              - name: ARA report"},{"line_number":72,"context_line":"                url: \u0027{{ groups[\"bastion\"][0] }}/ara-report/\u0027"},{"line_number":73,"context_line":""},{"line_number":74,"context_line":"    - name: Collect ansible configuration"},{"line_number":75,"context_line":"      synchronize:"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"46df23bd_ca51548d","line":72,"in_reply_to":"03f3cf5a_270fa8cd","updated":"2022-10-11 05:57:13.000000000","message":"Ack","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"}],"playbooks/zuul/run-base.yaml":[{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"dc4d00e892525dcef6e2eb121e2d0683ca2c4a44","unresolved":true,"context_lines":[{"line_number":5,"context_line":"    cloud_launcher_disable_job: true"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"# setup opendev CA"},{"line_number":8,"context_line":"- hosts: bastion"},{"line_number":9,"context_line":"  become: true"},{"line_number":10,"context_line":"  tasks:"},{"line_number":11,"context_line":"    - name: Make temporary dir for CA generation"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"6d963d96_0fb494f5","line":8,"updated":"2022-10-10 21:38:32.000000000","message":"This isn\u0027t actually safe to run across multiple bridge nodes is it? The reason being we\u0027ll end up with multiple CAs and that will break mutual trust for certs issued by the different CAs.","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"3e956d368efb8a7a466ac6e33352e3d5e4725e63","unresolved":true,"context_lines":[{"line_number":5,"context_line":"    cloud_launcher_disable_job: true"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"# setup opendev CA"},{"line_number":8,"context_line":"- hosts: bastion"},{"line_number":9,"context_line":"  become: true"},{"line_number":10,"context_line":"  tasks:"},{"line_number":11,"context_line":"    - name: Make temporary dir for CA generation"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"e37ecc77_3789f759","line":8,"in_reply_to":"6d963d96_0fb494f5","updated":"2022-10-11 05:57:13.000000000","message":"PS9 changes this to \"test_bastion[0]\" which should hopefully pick the first entry in the group ... we\u0027ll see!  I can\u0027t find it documented if that works anywhere.","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"032b8a14c0867807d8e93684d6aaa79255314614","unresolved":false,"context_lines":[{"line_number":5,"context_line":"    cloud_launcher_disable_job: true"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"# setup opendev CA"},{"line_number":8,"context_line":"- hosts: bastion"},{"line_number":9,"context_line":"  become: true"},{"line_number":10,"context_line":"  tasks:"},{"line_number":11,"context_line":"    - name: Make temporary dir for CA generation"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"33003c17_3cc674b5","line":8,"in_reply_to":"e37ecc77_3789f759","updated":"2022-10-12 03:55:20.000000000","message":"This does appear to work","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"dc4d00e892525dcef6e2eb121e2d0683ca2c4a44","unresolved":true,"context_lines":[{"line_number":57,"context_line":"        creates: \u0027{{ item.file }}\u0027"},{"line_number":58,"context_line":"      loop:"},{"line_number":59,"context_line":"        - file: \u0027/etc/opendev-ca/ca.key\u0027"},{"line_number":60,"context_line":"          content: \u0027{{ hostvars[groups[\"bastion\"][0]][\"_opendev_ca_key\"][\"content\"] }}\u0027"},{"line_number":61,"context_line":"        - file: \u0027/etc/opendev-ca/ca.crt\u0027"},{"line_number":62,"context_line":"          content: \u0027{{ hostvars[groups[\"bastion\"][0]][\"_opendev_ca_certificate\"][\"content\"] }}\u0027"},{"line_number":63,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":6,"id":"45f45173_d81c2993","line":60,"updated":"2022-10-10 21:38:32.000000000","message":"Here we only trust the CA on the first bastion group member. I think we should update the hosts selection above to match.","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"3e956d368efb8a7a466ac6e33352e3d5e4725e63","unresolved":false,"context_lines":[{"line_number":57,"context_line":"        creates: \u0027{{ item.file }}\u0027"},{"line_number":58,"context_line":"      loop:"},{"line_number":59,"context_line":"        - file: \u0027/etc/opendev-ca/ca.key\u0027"},{"line_number":60,"context_line":"          content: \u0027{{ hostvars[groups[\"bastion\"][0]][\"_opendev_ca_key\"][\"content\"] }}\u0027"},{"line_number":61,"context_line":"        - file: \u0027/etc/opendev-ca/ca.crt\u0027"},{"line_number":62,"context_line":"          content: \u0027{{ hostvars[groups[\"bastion\"][0]][\"_opendev_ca_certificate\"][\"content\"] }}\u0027"},{"line_number":63,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":6,"id":"73ee412b_5284368c","line":60,"in_reply_to":"45f45173_d81c2993","updated":"2022-10-11 05:57:13.000000000","message":"Similar to above; the play is hopefully restricting to the first host","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"dc4d00e892525dcef6e2eb121e2d0683ca2c4a44","unresolved":true,"context_lines":[{"line_number":185,"context_line":"        name: encrypt-logs"},{"line_number":186,"context_line":"      vars:"},{"line_number":187,"context_line":"        encrypt_logs_files: \u0027{{ _run_playbooks_logs.files | map(attribute\u003d\"path\") | list  }}\u0027"},{"line_number":188,"context_line":"        encrypt_logs_artifact_path: \u0027{{ groups[\"bastion\"][0] }}/ansible\u0027"},{"line_number":189,"context_line":"        encrypt_logs_download_script_path: \u0027/var/log/ansible\u0027"},{"line_number":190,"context_line":""},{"line_number":191,"context_line":"    - name: Run test playbook"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"e272ef26_8f456fcd","line":188,"updated":"2022-10-10 21:38:32.000000000","message":"We should probably avoid indexing into the bastion group here since these tasks are running on all bastion hosts. Instead use the ansible fqdn or something that moves with the group entries?","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"3e956d368efb8a7a466ac6e33352e3d5e4725e63","unresolved":true,"context_lines":[{"line_number":185,"context_line":"        name: encrypt-logs"},{"line_number":186,"context_line":"      vars:"},{"line_number":187,"context_line":"        encrypt_logs_files: \u0027{{ _run_playbooks_logs.files | map(attribute\u003d\"path\") | list  }}\u0027"},{"line_number":188,"context_line":"        encrypt_logs_artifact_path: \u0027{{ groups[\"bastion\"][0] }}/ansible\u0027"},{"line_number":189,"context_line":"        encrypt_logs_download_script_path: \u0027/var/log/ansible\u0027"},{"line_number":190,"context_line":""},{"line_number":191,"context_line":"    - name: Run test playbook"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"927f75e1_fcebb64a","line":188,"in_reply_to":"e272ef26_8f456fcd","updated":"2022-10-11 05:57:13.000000000","message":"The idea is that there will never actually be multiple bastion hosts -- but we have just one place we can switch","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"dc4d00e892525dcef6e2eb121e2d0683ca2c4a44","unresolved":true,"context_lines":[{"line_number":216,"context_line":"          zuul:"},{"line_number":217,"context_line":"            artifacts:"},{"line_number":218,"context_line":"              - name: Screenshots"},{"line_number":219,"context_line":"                url: \u0027{{ groups[\"bastion\"][0] }}/screenshots\u0027"},{"line_number":220,"context_line":""},{"line_number":221,"context_line":"    - name: Allow PBR\u0027s git calls to operate in system-config, despite not owning it"},{"line_number":222,"context_line":"      command: git config --global safe.directory /home/zuul/src/opendev.org/opendev/system-config"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"ffaf8f4d_1d2f4b96","line":219,"updated":"2022-10-10 21:38:32.000000000","message":"See above.","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"3e956d368efb8a7a466ac6e33352e3d5e4725e63","unresolved":false,"context_lines":[{"line_number":216,"context_line":"          zuul:"},{"line_number":217,"context_line":"            artifacts:"},{"line_number":218,"context_line":"              - name: Screenshots"},{"line_number":219,"context_line":"                url: \u0027{{ groups[\"bastion\"][0] }}/screenshots\u0027"},{"line_number":220,"context_line":""},{"line_number":221,"context_line":"    - name: Allow PBR\u0027s git calls to operate in system-config, despite not owning it"},{"line_number":222,"context_line":"      command: git config --global safe.directory /home/zuul/src/opendev.org/opendev/system-config"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"c9ffc68a_b3037c13","line":219,"in_reply_to":"ffaf8f4d_1d2f4b96","updated":"2022-10-11 05:57:13.000000000","message":"Ack","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"dc4d00e892525dcef6e2eb121e2d0683ca2c4a44","unresolved":true,"context_lines":[{"line_number":240,"context_line":"              zuul:"},{"line_number":241,"context_line":"                artifacts:"},{"line_number":242,"context_line":"                  - name: testinfra results"},{"line_number":243,"context_line":"                    url: \u0027{{ groups[\"bastion\"][0] }}/test-results.html\u0027"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"ee54ae3d_4639fb32","line":243,"updated":"2022-10-10 21:38:32.000000000","message":"See above.","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"3e956d368efb8a7a466ac6e33352e3d5e4725e63","unresolved":false,"context_lines":[{"line_number":240,"context_line":"              zuul:"},{"line_number":241,"context_line":"                artifacts:"},{"line_number":242,"context_line":"                  - name: testinfra results"},{"line_number":243,"context_line":"                    url: \u0027{{ groups[\"bastion\"][0] }}/test-results.html\u0027"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"a0fe2b17_1e25d313","line":243,"in_reply_to":"ee54ae3d_4639fb32","updated":"2022-10-11 05:57:13.000000000","message":"Ack","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"}],"zuul.d/system-config-run.yaml":[{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"dc4d00e892525dcef6e2eb121e2d0683ca2c4a44","unresolved":true,"context_lines":[{"line_number":74,"context_line":"        # this group.  This should only have one entry -- in a couple"},{"line_number":75,"context_line":"        # of places the jobs use the actual hostname and assume"},{"line_number":76,"context_line":"        # element [0] here is that hostname."},{"line_number":77,"context_line":"        - \u0026bastion_group { name: bastion, nodes: [ bridge.openstack.org ] }"},{"line_number":78,"context_line":"    files:"},{"line_number":79,"context_line":"      - tox.ini"},{"line_number":80,"context_line":"      - playbooks/"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"575e8f93_858e63fe","line":77,"updated":"2022-10-10 21:38:32.000000000","message":"We need the group defined here in addition to our regular groups file because playbooks executed by zuul (run-base.yaml) also use the group? Should we use different group names to make that distinction more clear?","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"3e956d368efb8a7a466ac6e33352e3d5e4725e63","unresolved":false,"context_lines":[{"line_number":74,"context_line":"        # this group.  This should only have one entry -- in a couple"},{"line_number":75,"context_line":"        # of places the jobs use the actual hostname and assume"},{"line_number":76,"context_line":"        # element [0] here is that hostname."},{"line_number":77,"context_line":"        - \u0026bastion_group { name: bastion, nodes: [ bridge.openstack.org ] }"},{"line_number":78,"context_line":"    files:"},{"line_number":79,"context_line":"      - tox.ini"},{"line_number":80,"context_line":"      - playbooks/"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"e3e25ec9_a75abca8","line":77,"in_reply_to":"575e8f93_858e63fe","updated":"2022-10-11 05:57:13.000000000","message":"PS9 changes this to test_bastion to make this distinction clearer","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"032b8a14c0867807d8e93684d6aaa79255314614","unresolved":false,"context_lines":[{"line_number":74,"context_line":"        # this group.  This should only have one entry -- in a couple"},{"line_number":75,"context_line":"        # of places the jobs use the actual hostname and assume"},{"line_number":76,"context_line":"        # element [0] here is that hostname."},{"line_number":77,"context_line":"        - \u0026bastion_group { name: bastion, nodes: [ bridge.openstack.org ] }"},{"line_number":78,"context_line":"    files:"},{"line_number":79,"context_line":"      - tox.ini"},{"line_number":80,"context_line":"      - playbooks/"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"a48c6d72_f952925d","line":77,"in_reply_to":"e3e25ec9_a75abca8","updated":"2022-10-12 03:55:20.000000000","message":"This didn\u0027t really work out; i\u0027ve restored it just to the \"bastion\" host.  We discussed this in the meeting, and it seems this is probably easier to follow.","commit_id":"65ea33fe35da72d4db767bb1be56aa2b3077c960"}]}
