)]}'
{"doc/source/admin/secure-rbac.rst":[{"author":{"_account_id":11292,"name":"Arne Wiebalck","email":"Arne.Wiebalck@cern.ch","username":"wiebalck"},"change_message_id":"a4984fbe839c4ef6112ac2680babeb8bde394697","unresolved":true,"context_lines":[{"line_number":222,"context_line":""},{"line_number":223,"context_line":"   # baremetal node set --lessee \u003cproject_id\u003e \u003cnode\u003e"},{"line_number":224,"context_line":""},{"line_number":225,"context_line":"What is the different between an owner and lessee?"},{"line_number":226,"context_line":"--------------------------------------------------"},{"line_number":227,"context_line":""},{"line_number":228,"context_line":"This is largely covered in `How Project Scoped Works`_ although"}],"source_content_type":"text/x-rst","patch_set":4,"id":"e5741c2a_dafb5e48","line":225,"range":{"start_line":225,"start_character":12,"end_line":225,"end_character":21},"updated":"2021-03-16 17:34:04.000000000","message":"difference","commit_id":"cba1fbf2d304adb1893608c94c090f71251baee7"},{"author":{"_account_id":11292,"name":"Arne Wiebalck","email":"Arne.Wiebalck@cern.ch","username":"wiebalck"},"change_message_id":"a4984fbe839c4ef6112ac2680babeb8bde394697","unresolved":true,"context_lines":[{"line_number":226,"context_line":"--------------------------------------------------"},{"line_number":227,"context_line":""},{"line_number":228,"context_line":"This is largely covered in `How Project Scoped Works`_ although"},{"line_number":229,"context_line":"as noted it is largely in means of access. A ``lessee`` is far more restrive"},{"line_number":230,"context_line":"and an ``owner`` may revoke access to ``lessee``."},{"line_number":231,"context_line":""},{"line_number":232,"context_line":"Access to the underlying baremetal node is not exclusive between the"}],"source_content_type":"text/x-rst","patch_set":4,"id":"11cc9631_9ed968dd","line":229,"range":{"start_line":229,"start_character":68,"end_line":229,"end_character":76},"updated":"2021-03-16 17:34:04.000000000","message":"restrictive","commit_id":"cba1fbf2d304adb1893608c94c090f71251baee7"},{"author":{"_account_id":6618,"name":"Ruby Loo","email":"opensrloo@gmail.com","username":"rloo"},"change_message_id":"c292c317e50db3bead7d5a6bfab5a331ba1181c2","unresolved":true,"context_lines":[{"line_number":208,"context_line":""},{"line_number":209,"context_line":".. code-block:: console"},{"line_number":210,"context_line":""},{"line_number":211,"context_line":"   # baremetal node set --owner \u003cproject_id\u003e \u003cnode\u003e"},{"line_number":212,"context_line":""},{"line_number":213,"context_line":".. note::"},{"line_number":214,"context_line":"   With the default access policy, an ``owner`` is able to change"}],"source_content_type":"text/x-rst","patch_set":6,"id":"0ae9f7da_3d2e5eb7","line":211,"updated":"2021-03-18 13:41:16.000000000","message":"why the \u0027#\u0027?\n\nstill waking up so...","commit_id":"05498a8b440d136f7aa04552cdb153796d8a4a2d"},{"author":{"_account_id":6618,"name":"Ruby Loo","email":"opensrloo@gmail.com","username":"rloo"},"change_message_id":"c292c317e50db3bead7d5a6bfab5a331ba1181c2","unresolved":true,"context_lines":[{"line_number":220,"context_line":""},{"line_number":221,"context_line":".. code-block:: console"},{"line_number":222,"context_line":""},{"line_number":223,"context_line":"   # baremetal node set --lessee \u003cproject_id\u003e \u003cnode\u003e"},{"line_number":224,"context_line":""},{"line_number":225,"context_line":"What is the difference between an owner and lessee?"},{"line_number":226,"context_line":"---------------------------------------------------"}],"source_content_type":"text/x-rst","patch_set":6,"id":"712ec1b6_009d62a2","line":223,"updated":"2021-03-18 13:41:16.000000000","message":"ditto","commit_id":"05498a8b440d136f7aa04552cdb153796d8a4a2d"},{"author":{"_account_id":6618,"name":"Ruby Loo","email":"opensrloo@gmail.com","username":"rloo"},"change_message_id":"c292c317e50db3bead7d5a6bfab5a331ba1181c2","unresolved":true,"context_lines":[{"line_number":226,"context_line":"---------------------------------------------------"},{"line_number":227,"context_line":""},{"line_number":228,"context_line":"This is largely covered in `How Project Scoped Works`_ although"},{"line_number":229,"context_line":"as noted it is largely in means of access. A ``lessee`` is far more"},{"line_number":230,"context_line":"restrictive and an ``owner`` may revoke access to ``lessee``."},{"line_number":231,"context_line":""},{"line_number":232,"context_line":"Access to the underlying baremetal node is not exclusive between the"}],"source_content_type":"text/x-rst","patch_set":6,"id":"b6debbb3_9984e0c4","line":229,"updated":"2021-03-18 13:41:16.000000000","message":"not sure, maybe s/in/a/","commit_id":"05498a8b440d136f7aa04552cdb153796d8a4a2d"}],"ironic/common/glance_service/service_utils.py":[{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"07f2ba621c0600de6ab82c9595349f49d3e6a6ff","unresolved":true,"context_lines":[{"line_number":113,"context_line":"        return True"},{"line_number":114,"context_line":""},{"line_number":115,"context_line":"    # TODO(TheJulia): This is potentially a bug below. Admin context doesn\u0027t"},{"line_number":116,"context_line":"    # necessarilly mean the object is *actually* accessible. We should likely"},{"line_number":117,"context_line":"    # just ask glance... Although everything sbould also have an auth_token"},{"line_number":118,"context_line":"    # as noted above."},{"line_number":119,"context_line":"    if getattr(image, \u0027visibility\u0027, None) \u003d\u003d \u0027public\u0027 or context.is_admin:"}],"source_content_type":"text/x-python","patch_set":3,"id":"c524fef3_d3a656f5","line":116,"updated":"2021-03-15 17:20:49.000000000","message":"I think the problem is that if we don\u0027t have an auth_token, removing this check would allow using any image that ironic has access to (not necessary the user).","commit_id":"5464891b58f4a18c32385aab33a7439ccb3d99f9"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"6b28a902f6096ab22dbd8228750a5f0b7fa676b3","unresolved":true,"context_lines":[{"line_number":113,"context_line":"        return True"},{"line_number":114,"context_line":""},{"line_number":115,"context_line":"    # TODO(TheJulia): This is potentially a bug below. Admin context doesn\u0027t"},{"line_number":116,"context_line":"    # necessarilly mean the object is *actually* accessible. We should likely"},{"line_number":117,"context_line":"    # just ask glance... Although everything sbould also have an auth_token"},{"line_number":118,"context_line":"    # as noted above."},{"line_number":119,"context_line":"    if getattr(image, \u0027visibility\u0027, None) \u003d\u003d \u0027public\u0027 or context.is_admin:"}],"source_content_type":"text/x-python","patch_set":3,"id":"7734cd80_b3828b74","line":116,"in_reply_to":"c524fef3_d3a656f5","updated":"2021-03-15 22:52:48.000000000","message":"I was meaning the lines below, not above which I think your talking about. But this is also true.","commit_id":"5464891b58f4a18c32385aab33a7439ccb3d99f9"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"07f2ba621c0600de6ab82c9595349f49d3e6a6ff","unresolved":true,"context_lines":[{"line_number":114,"context_line":""},{"line_number":115,"context_line":"    # TODO(TheJulia): This is potentially a bug below. Admin context doesn\u0027t"},{"line_number":116,"context_line":"    # necessarilly mean the object is *actually* accessible. We should likely"},{"line_number":117,"context_line":"    # just ask glance... Although everything sbould also have an auth_token"},{"line_number":118,"context_line":"    # as noted above."},{"line_number":119,"context_line":"    if getattr(image, \u0027visibility\u0027, None) \u003d\u003d \u0027public\u0027 or context.is_admin:"},{"line_number":120,"context_line":"        return True"}],"source_content_type":"text/x-python","patch_set":3,"id":"0402ee31_96066fb2","line":117,"updated":"2021-03-15 17:20:49.000000000","message":"nit: should","commit_id":"5464891b58f4a18c32385aab33a7439ccb3d99f9"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"6b28a902f6096ab22dbd8228750a5f0b7fa676b3","unresolved":false,"context_lines":[{"line_number":114,"context_line":""},{"line_number":115,"context_line":"    # TODO(TheJulia): This is potentially a bug below. Admin context doesn\u0027t"},{"line_number":116,"context_line":"    # necessarilly mean the object is *actually* accessible. We should likely"},{"line_number":117,"context_line":"    # just ask glance... Although everything sbould also have an auth_token"},{"line_number":118,"context_line":"    # as noted above."},{"line_number":119,"context_line":"    if getattr(image, \u0027visibility\u0027, None) \u003d\u003d \u0027public\u0027 or context.is_admin:"},{"line_number":120,"context_line":"        return True"}],"source_content_type":"text/x-python","patch_set":3,"id":"7b87bbb2_6449ab0d","line":117,"in_reply_to":"0402ee31_96066fb2","updated":"2021-03-15 22:52:48.000000000","message":"Done","commit_id":"5464891b58f4a18c32385aab33a7439ccb3d99f9"}],"releasenotes/notes/project-scoped-rbac-063c44ba593bb82a.yaml":[{"author":{"_account_id":11292,"name":"Arne Wiebalck","email":"Arne.Wiebalck@cern.ch","username":"wiebalck"},"change_message_id":"a4984fbe839c4ef6112ac2680babeb8bde394697","unresolved":true,"context_lines":[{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    Adds capability to use ``project`` scoped requests in concert with"},{"line_number":5,"context_line":"    ``system`` scoped requests for a composite Role Based Access Control"},{"line_number":6,"context_line":"    (RBAC) model. As Ironic is mainly an administative service,"},{"line_number":7,"context_line":"    this capability has only been extended to API endpoints which are"},{"line_number":8,"context_line":"    not purely administrative in nature. This consists of the following"},{"line_number":9,"context_line":"    API endpoints: nodes, ports, portgroups, volume connectors, volume"}],"source_content_type":"text/x-yaml","patch_set":4,"id":"e4d32570_f5e1f2bb","line":6,"range":{"start_line":6,"start_character":41,"end_line":6,"end_character":54},"updated":"2021-03-16 17:34:04.000000000","message":"Nit: administrative","commit_id":"cba1fbf2d304adb1893608c94c090f71251baee7"},{"author":{"_account_id":11292,"name":"Arne Wiebalck","email":"Arne.Wiebalck@cern.ch","username":"wiebalck"},"change_message_id":"a4984fbe839c4ef6112ac2680babeb8bde394697","unresolved":true,"context_lines":[{"line_number":12,"context_line":"    Project ``scoped`` requests for baremetal allocations, will automatically"},{"line_number":13,"context_line":"    record the ``project_id`` of the reqeustor as the ``owner`` of the node."},{"line_number":14,"context_line":"deprecations:"},{"line_number":15,"context_line":"  - \u003e"},{"line_number":16,"context_line":"    Pre-RBAC support rules have been deprecated. These consist of::"},{"line_number":17,"context_line":"      * admin_api"},{"line_number":18,"context_line":"      * is_member"}],"source_content_type":"text/x-yaml","patch_set":4,"id":"56b47a1f_9c0b6136","line":15,"range":{"start_line":15,"start_character":1,"end_line":15,"end_character":5},"updated":"2021-03-16 17:34:04.000000000","message":"Nit: is this a valid formatting?","commit_id":"cba1fbf2d304adb1893608c94c090f71251baee7"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"79177ae2c3ffd56bc6d4b1751881badb3962a0a5","unresolved":true,"context_lines":[{"line_number":12,"context_line":"    Project ``scoped`` requests for baremetal allocations, will automatically"},{"line_number":13,"context_line":"    record the ``project_id`` of the reqeustor as the ``owner`` of the node."},{"line_number":14,"context_line":"deprecations:"},{"line_number":15,"context_line":"  - \u003e"},{"line_number":16,"context_line":"    Pre-RBAC support rules have been deprecated. These consist of::"},{"line_number":17,"context_line":"      * admin_api"},{"line_number":18,"context_line":"      * is_member"}],"source_content_type":"text/x-yaml","patch_set":4,"id":"32a0a4aa_01c38ad3","line":15,"range":{"start_line":15,"start_character":1,"end_line":15,"end_character":5},"in_reply_to":"56b47a1f_9c0b6136","updated":"2021-03-17 13:19:36.000000000","message":"Yes, amazingly enough it rendered as expected. I just only needed one : char on line 16.","commit_id":"cba1fbf2d304adb1893608c94c090f71251baee7"},{"author":{"_account_id":11292,"name":"Arne Wiebalck","email":"Arne.Wiebalck@cern.ch","username":"wiebalck"},"change_message_id":"6008f95c0ee5054e35672e73166fbefa2f6c9e19","unresolved":true,"context_lines":[{"line_number":10,"context_line":"    targets, and allocations."},{"line_number":11,"context_line":"  - |"},{"line_number":12,"context_line":"    Project ``scoped`` requests for baremetal allocations, will automatically"},{"line_number":13,"context_line":"    record the ``project_id`` of the reqeustor as the ``owner`` of the node."},{"line_number":14,"context_line":"deprecations:"},{"line_number":15,"context_line":"  - \u003e"},{"line_number":16,"context_line":"    Pre-RBAC support rules have been deprecated. These consist of:"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"4838caa5_689c36db","line":13,"range":{"start_line":13,"start_character":37,"end_line":13,"end_character":46},"updated":"2021-03-17 13:26:39.000000000","message":"requestor","commit_id":"abd70e88efa710ea0d82e7bb3f770d61fccf46fe"},{"author":{"_account_id":6618,"name":"Ruby Loo","email":"opensrloo@gmail.com","username":"rloo"},"change_message_id":"c292c317e50db3bead7d5a6bfab5a331ba1181c2","unresolved":true,"context_lines":[{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    Adds capability to use ``project`` scoped requests in concert with"},{"line_number":5,"context_line":"    ``system`` scoped requests for a composite Role Based Access Control"},{"line_number":6,"context_line":"    (RBAC) model. As Ironic is mainly an administrative service,"},{"line_number":7,"context_line":"    this capability has only been extended to API endpoints which are"},{"line_number":8,"context_line":"    not purely administrative in nature. This consists of the following"},{"line_number":9,"context_line":"    API endpoints: nodes, ports, portgroups, volume connectors, volume"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"b3486f14_37f6d40a","line":6,"updated":"2021-03-18 13:41:16.000000000","message":"what about adding a link to https://docs.openstack.org/ironic/latest/admin/secure-rbac.html","commit_id":"05498a8b440d136f7aa04552cdb153796d8a4a2d"},{"author":{"_account_id":6618,"name":"Ruby Loo","email":"opensrloo@gmail.com","username":"rloo"},"change_message_id":"c292c317e50db3bead7d5a6bfab5a331ba1181c2","unresolved":true,"context_lines":[{"line_number":9,"context_line":"    API endpoints: nodes, ports, portgroups, volume connectors, volume"},{"line_number":10,"context_line":"    targets, and allocations."},{"line_number":11,"context_line":"  - |"},{"line_number":12,"context_line":"    Project ``scoped`` requests for baremetal allocations, will automatically"},{"line_number":13,"context_line":"    record the ``project_id`` of the reqeustor as the ``owner`` of the node."},{"line_number":14,"context_line":"deprecations:"},{"line_number":15,"context_line":"  - \u003e"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"6c43bfa1_150628c1","line":12,"updated":"2021-03-18 13:41:16.000000000","message":"nit, no comma","commit_id":"05498a8b440d136f7aa04552cdb153796d8a4a2d"},{"author":{"_account_id":6618,"name":"Ruby Loo","email":"opensrloo@gmail.com","username":"rloo"},"change_message_id":"c292c317e50db3bead7d5a6bfab5a331ba1181c2","unresolved":true,"context_lines":[{"line_number":10,"context_line":"    targets, and allocations."},{"line_number":11,"context_line":"  - |"},{"line_number":12,"context_line":"    Project ``scoped`` requests for baremetal allocations, will automatically"},{"line_number":13,"context_line":"    record the ``project_id`` of the reqeustor as the ``owner`` of the node."},{"line_number":14,"context_line":"deprecations:"},{"line_number":15,"context_line":"  - \u003e"},{"line_number":16,"context_line":"    Pre-RBAC support rules have been deprecated. These consist of:"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"b13652d5_68695a2e","line":13,"updated":"2021-03-18 13:41:16.000000000","message":"s/reqeustor/requestor/","commit_id":"05498a8b440d136f7aa04552cdb153796d8a4a2d"},{"author":{"_account_id":6618,"name":"Ruby Loo","email":"opensrloo@gmail.com","username":"rloo"},"change_message_id":"c292c317e50db3bead7d5a6bfab5a331ba1181c2","unresolved":true,"context_lines":[{"line_number":12,"context_line":"    Project ``scoped`` requests for baremetal allocations, will automatically"},{"line_number":13,"context_line":"    record the ``project_id`` of the reqeustor as the ``owner`` of the node."},{"line_number":14,"context_line":"deprecations:"},{"line_number":15,"context_line":"  - \u003e"},{"line_number":16,"context_line":"    Pre-RBAC support rules have been deprecated. These consist of:"},{"line_number":17,"context_line":"      * admin_api"},{"line_number":18,"context_line":"      * is_member"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"a0195f61_88451573","line":15,"updated":"2021-03-18 13:41:16.000000000","message":"does \u0027\u003e\u0027 work? I thought it was | but maybe that is used for something else. (Am too lazy to look at rendered page)","commit_id":"05498a8b440d136f7aa04552cdb153796d8a4a2d"},{"author":{"_account_id":6618,"name":"Ruby Loo","email":"opensrloo@gmail.com","username":"rloo"},"change_message_id":"c292c317e50db3bead7d5a6bfab5a331ba1181c2","unresolved":true,"context_lines":[{"line_number":35,"context_line":"    impact ``system`` scoped requests. Operators who adopt project scoped"},{"line_number":36,"context_line":"    access may find it necessary to verify or add additional database indexes"},{"line_number":37,"context_line":"    in relation to the node ``uuid`` column as well as ``node_id`` field in"},{"line_number":38,"context_line":"    any table which may recieve heavy project query scope activity."},{"line_number":39,"context_line":"    The ``ironic`` project anticipates that this will be a future work item"},{"line_number":40,"context_line":"    of the project to help improve database performance."},{"line_number":41,"context_line":"upgrade:"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"6edf85de_329242ac","line":38,"updated":"2021-03-18 13:41:16.000000000","message":"s/recieve/receive/","commit_id":"05498a8b440d136f7aa04552cdb153796d8a4a2d"}]}
