)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"bc5620a3059d294cfcc5521417f4f912ffb25ff6","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"4b43fe7d_43fb841c","updated":"2026-08-05 20:25:28.000000000","message":"For what it is worth, I do agree, and we can likely go ahead and put a knob in to \"disable the use of the auth\" settings from ironic.conf, for noew, it would need to ship as true, but signal the default is changing. If we backport with that signaling, we... might be able to get away with changing that default behavior in short order.","commit_id":"5184d388a15e4fdb3007e73ead2d754272ee0230"},{"author":{"_account_id":35233,"name":"Adam Rozman","email":"adam.rozman@est.tech","username":"rozzix"},"change_message_id":"1764c86a53da76faed87fa02edac8754422f6e6d","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"087ab9f6_b624b662","updated":"2026-08-04 17:55:26.000000000","message":"Please read my response on the launchpad ticket, I don\u0027t think this is a practical way of solving the concern, as the issue this change addresses is a very specific BMAAS case . I wrote down my opinion and also dispute that this is a CVE.","commit_id":"5184d388a15e4fdb3007e73ead2d754272ee0230"},{"author":{"_account_id":35233,"name":"Adam Rozman","email":"adam.rozman@est.tech","username":"rozzix"},"change_message_id":"10df1c1f67a2f8860b1e876804458a4611adcc54","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"5dba017b_b5b3fa1e","in_reply_to":"087ab9f6_b624b662","updated":"2026-08-04 18:00:57.000000000","message":"Keep in mind that this issue affects those who allow \"untrusted\" tenants to configure ironic nodes / provide images for the nodes from anywhere online. Maintaining a list of trusted \"addresses\" will be very quickly unmaintainable for the exact same BMAAS platforms, as the users could have a legitimate need for multiple hundreds of addresses.","commit_id":"5184d388a15e4fdb3007e73ead2d754272ee0230"},{"author":{"_account_id":35233,"name":"Adam Rozman","email":"adam.rozman@est.tech","username":"rozzix"},"change_message_id":"10b20756d6af3d141b710bb84203fa6f43c77381","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":2,"id":"8edd7697_3336e089","in_reply_to":"1966b2ee_925045ef","updated":"2026-08-07 10:20:55.000000000","message":"Or if yo mean a knob to disable checking the allow list then , yeah that I agree with too.","commit_id":"5184d388a15e4fdb3007e73ead2d754272ee0230"},{"author":{"_account_id":35233,"name":"Adam Rozman","email":"adam.rozman@est.tech","username":"rozzix"},"change_message_id":"4fa7d7a1cdcd3b9bd82dc587c46f446b31523392","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":2,"id":"1966b2ee_925045ef","in_reply_to":"26e68f46_ad758005","updated":"2026-08-07 10:15:50.000000000","message":"There is a knob already\u003e image_server_auth_strategy , that can be set to \"noauth\" and then auth is disabled. This is why I am pressing on the fact that \"the Admin has to intentionally enable this feature\".","commit_id":"5184d388a15e4fdb3007e73ead2d754272ee0230"},{"author":{"_account_id":35233,"name":"Adam Rozman","email":"adam.rozman@est.tech","username":"rozzix"},"change_message_id":"8f1f91028bd004c984165b91f993e41c954773ca","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"5af5bc8f_1e186e5e","in_reply_to":"4888c3cf_73bdb9e1","updated":"2026-08-05 08:21:00.000000000","message":"Thanks for the clear explanation, I have also extended my reply on the bug. I agree with you, the only thing where I differ is related to the followup work. \n\nThis scenario is induced fundamentally by admin level misconfiguration as you wrote the situation is that \"BMaaS cloud where they are hard coding credentials but have hundreds of download endpoints, then they are creating an untenable situation to begin based upon their operational context\". \n\nHow I see the situation is the following:\n\"The issue could be also present with just 2 download endpoints. The admins allowed tenants to use their own image servers. Admins enabled basic_auth with a single set of creds. The same creds are transmitted to all image servers. The admins who did all that missconfiguration can do more mistakes too. Admins can also leave the \"trusted hosts\" list empty. \"\n\nBased on what Jay wrote and the nature of the issue I agree with you that your change is needed. Where I differ is the option to provide basic_auth creds in global config has to be also removed  and moved to node level.  When admins would enable \"basic_auth\" for  they would never risk leaking credential in a multi tenant scenario.\n\nTo summarize, I have no issue with this change as you have confirmed that this change does not addresses everything. I would say based on the bug discussion on https://launchpad.net/bugs/2162816, modifying the credential handling is not optional to resolve the security concerns, but that can be indeed a separate change.","commit_id":"5184d388a15e4fdb3007e73ead2d754272ee0230"},{"author":{"_account_id":35233,"name":"Adam Rozman","email":"adam.rozman@est.tech","username":"rozzix"},"change_message_id":"4fa7d7a1cdcd3b9bd82dc587c46f446b31523392","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"c206bc04_b5389d40","in_reply_to":"4b43fe7d_43fb841c","updated":"2026-08-07 10:15:50.000000000","message":"There is a knob already\u003e image_server_auth_strategy , that can be set to \"noauth\" and then auth is disabled.","commit_id":"5184d388a15e4fdb3007e73ead2d754272ee0230"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"332208a5d3cb86aad3c81492556e5f7ca6ec5d01","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":2,"id":"26e68f46_ad758005","in_reply_to":"5af5bc8f_1e186e5e","updated":"2026-08-05 16:36:13.000000000","message":"I think you\u0027ve made a pretty compelling argument (here and in the bug) for an additional knob; one which will turn the feature entirely off, defaulted to \"feature is turned off\".","commit_id":"5184d388a15e4fdb3007e73ead2d754272ee0230"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"cb784ec0167ba6833383632549c9b4bec8621bc0","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"4888c3cf_73bdb9e1","in_reply_to":"5dba017b_b5b3fa1e","updated":"2026-08-04 18:47:12.000000000","message":"So, FWIW, the current state represents discussion of the ironic cores ecurity team *and* discussion and extension after initially being posted to allow a globbing style of configuration which could allow operators to greatly reduce the need to have strictly specific FQDN records. Meaning the goal here is to meet the first item as noted in the launchpad bug. Frankly, if someone is running a BMaaS cloud where they are hard coding credentials but have hundreds of download endpoints, then they are creating an untenable situation to begin based upon their operational context. Ideally, they instead force everything through a known/good validated artifact process.\n\nBut taking a step back, it is more an operational/administrative burden, but one where communication is absolutely critical. As an example, $operator may have approved list of hosts, and may require local mirrors. If someone wants to use a private one, that either needs to be added to the list, OR they need to collaborate on process. Either way forces communication and engagement which is critical regardless.\n\nThat doesn\u0027t exclude additional credential passing from being a future thing, but it needs to be split and the direct first step is this level of work, if there is interest, additional work can go into an additional feature. In the end, *both* paths are acceptable.\n\nThe bottom line is the code, today, does the wrong thing, this change attempts to remedy that or at least provide a remedy, and we need to fix it and can\u0027t frame the fix as a feature.","commit_id":"5184d388a15e4fdb3007e73ead2d754272ee0230"},{"author":{"_account_id":35233,"name":"Adam Rozman","email":"adam.rozman@est.tech","username":"rozzix"},"change_message_id":"2c473903df6d810a54994455cd7d29a86fb08b53","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"becc20c8_9415b716","in_reply_to":"8edd7697_3336e089","updated":"2026-08-07 10:21:25.000000000","message":"Done","commit_id":"5184d388a15e4fdb3007e73ead2d754272ee0230"},{"author":{"_account_id":35233,"name":"Adam Rozman","email":"adam.rozman@est.tech","username":"rozzix"},"change_message_id":"10b20756d6af3d141b710bb84203fa6f43c77381","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"3fdd23ed_b8902927","in_reply_to":"c206bc04_b5389d40","updated":"2026-08-07 10:20:55.000000000","message":"Or if yo mean a knob to disable checking the allow list then , yeah that I agree with too.","commit_id":"5184d388a15e4fdb3007e73ead2d754272ee0230"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"8912bf66ae37a47f6c699f2c1a733c439137ad67","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":5,"id":"2db277c5_6606e952","updated":"2026-08-18 14:26:28.000000000","message":"-1 specifically for the weirdly-worded thing in the docs about RFE to allow these to be set in instance_info","commit_id":"808a4acba935ce01e5d0e754387a3dab1de1bb4b"}],"doc/source/admin/user-image-basic-auth.rst":[{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"6e2a0a7825d6f0f17ac689e1287fe523afcf9eef","unresolved":true,"context_lines":[{"line_number":95,"context_line":"   effect. When ``image_server_auth_hosts`` is not set, the behavior"},{"line_number":96,"context_line":"   depends on ``image_server_auth_permit_unknown_hosts``. Starting"},{"line_number":97,"context_line":"   in 2026.2, ``image_server_auth_permit_unknown_hosts`` defaults to"},{"line_number":98,"context_line":"   ``False`` and credentials are not sent to any host unless"},{"line_number":99,"context_line":"   ``image_server_auth_hosts`` is configured."},{"line_number":100,"context_line":""},{"line_number":101,"context_line":".. note::"}],"source_content_type":"text/x-rst","patch_set":4,"id":"60ee4ef3_1226b6c0","line":98,"updated":"2026-08-12 08:56:59.000000000","message":"nit: it\u0027s not the case until the next patch","commit_id":"c0527a7170faeaf485fe68d712515f6940798fd0"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"1f225f2d0c16335fa4966f71e77e320f229aef32","unresolved":true,"context_lines":[{"line_number":95,"context_line":"   effect. When ``image_server_auth_hosts`` is not set, the behavior"},{"line_number":96,"context_line":"   depends on ``image_server_auth_permit_unknown_hosts``. Starting"},{"line_number":97,"context_line":"   in 2026.2, ``image_server_auth_permit_unknown_hosts`` defaults to"},{"line_number":98,"context_line":"   ``False`` and credentials are not sent to any host unless"},{"line_number":99,"context_line":"   ``image_server_auth_hosts`` is configured."},{"line_number":100,"context_line":""},{"line_number":101,"context_line":".. note::"}],"source_content_type":"text/x-rst","patch_set":4,"id":"c9aaf96e_974bd319","line":98,"in_reply_to":"60ee4ef3_1226b6c0","updated":"2026-08-17 15:50:53.000000000","message":"... weird, I thoguht I fixed this.","commit_id":"c0527a7170faeaf485fe68d712515f6940798fd0"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"8912bf66ae37a47f6c699f2c1a733c439137ad67","unresolved":true,"context_lines":[{"line_number":98,"context_line":"   configure ``image_server_auth_hosts`` or set"},{"line_number":99,"context_line":"   ``image_server_auth_permit_unknown_hosts`` to ``False``. The default"},{"line_number":100,"context_line":"   of ``image_server_auth_permit_unknown_hosts`` will change to"},{"line_number":101,"context_line":"   ``False`` in the 2026.2 release, after which credentials are not sent"},{"line_number":102,"context_line":"   to any host unless ``image_server_auth_hosts`` is configured."},{"line_number":103,"context_line":""},{"line_number":104,"context_line":".. note::"}],"source_content_type":"text/x-rst","patch_set":5,"id":"abced676_9e933c20","line":101,"updated":"2026-08-18 14:26:28.000000000","message":"I thought we were trying to get specific release name/numbers outta docs? IMO this is fine","commit_id":"808a4acba935ce01e5d0e754387a3dab1de1bb4b"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"d39f53e9bc5cb4843300c00cc66b57088ef75b4b","unresolved":true,"context_lines":[{"line_number":98,"context_line":"   configure ``image_server_auth_hosts`` or set"},{"line_number":99,"context_line":"   ``image_server_auth_permit_unknown_hosts`` to ``False``. The default"},{"line_number":100,"context_line":"   of ``image_server_auth_permit_unknown_hosts`` will change to"},{"line_number":101,"context_line":"   ``False`` in the 2026.2 release, after which credentials are not sent"},{"line_number":102,"context_line":"   to any host unless ``image_server_auth_hosts`` is configured."},{"line_number":103,"context_line":""},{"line_number":104,"context_line":".. note::"}],"source_content_type":"text/x-rst","patch_set":5,"id":"f208b01e_8529d96a","line":101,"in_reply_to":"abced676_9e933c20","updated":"2026-08-18 15:33:47.000000000","message":"Fair, yeah, the pattern we\u0027re trying to avoid is this static context set which reads as \"in this release we did y\", but it is uch more a case by case basis because we specifically had the pattern in the docs of where we would frame features with versions first, but the later versions it was always true.","commit_id":"808a4acba935ce01e5d0e754387a3dab1de1bb4b"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"8912bf66ae37a47f6c699f2c1a733c439137ad67","unresolved":true,"context_lines":[{"line_number":137,"context_line":"   credentials to be sent. Operators are encouraged to configure"},{"line_number":138,"context_line":"   ``image_server_auth_hosts`` before the 2026.2 release."},{"line_number":139,"context_line":""},{"line_number":140,"context_line":"In the future, it is desirable to allow users to supply per-node HTTP"},{"line_number":141,"context_line":"image server credentials via ``instance_info``, removing the reliance"},{"line_number":142,"context_line":"on global credentials. This capability is not yet implemented."}],"source_content_type":"text/x-rst","patch_set":5,"id":"99627bde_e97dd578","line":140,"updated":"2026-08-18 14:26:28.000000000","message":"This sounds like we\u0027re billboarding a feature that exists. I would recommend either removing this, or linking to an RFE bug describing the future-looking behavior.","commit_id":"808a4acba935ce01e5d0e754387a3dab1de1bb4b"}],"ironic/common/image_service.py":[{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"6e2a0a7825d6f0f17ac689e1287fe523afcf9eef","unresolved":true,"context_lines":[{"line_number":157,"context_line":"            \u0027image_server_auth_permit_unknown_hosts \u0027"},{"line_number":158,"context_line":"            \u0027is False.\u0027, image_href)"},{"line_number":159,"context_line":"        return False"},{"line_number":160,"context_line":"    hostname \u003d parsed.hostname"},{"line_number":161,"context_line":"    if not hostname:"},{"line_number":162,"context_line":"        return False"},{"line_number":163,"context_line":"    for entry in permitted_hosts:"}],"source_content_type":"text/x-python","patch_set":4,"id":"74fb2187_7326f46b","line":160,"updated":"2026-08-12 08:56:59.000000000","message":"This is not going to distinguish between `example.com` and `example.com:8080`. I\u0027d rather be cautious and use `netloc` or somehow else consider port as part of the host name.","commit_id":"c0527a7170faeaf485fe68d712515f6940798fd0"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"8912bf66ae37a47f6c699f2c1a733c439137ad67","unresolved":true,"context_lines":[{"line_number":157,"context_line":"            \u0027image_server_auth_permit_unknown_hosts \u0027"},{"line_number":158,"context_line":"            \u0027is False.\u0027, image_href)"},{"line_number":159,"context_line":"        return False"},{"line_number":160,"context_line":"    hostname \u003d parsed.hostname"},{"line_number":161,"context_line":"    if not hostname:"},{"line_number":162,"context_line":"        return False"},{"line_number":163,"context_line":"    for entry in permitted_hosts:"}],"source_content_type":"text/x-python","patch_set":4,"id":"db670b0e_6640b255","line":160,"in_reply_to":"53f13a01_9184ff41","updated":"2026-08-18 14:26:28.000000000","message":"I think it\u0027s OK to omit the port here. Thinking about use cases for this security, in the situation where you don\u0027t trust project-scoped managers, that\u0027s not a situation where you\u0027d be putting hostnames those operators control in the allowlist anyway (...and if you did, they would still be in control of all posts on it).","commit_id":"c0527a7170faeaf485fe68d712515f6940798fd0"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"1f225f2d0c16335fa4966f71e77e320f229aef32","unresolved":true,"context_lines":[{"line_number":157,"context_line":"            \u0027image_server_auth_permit_unknown_hosts \u0027"},{"line_number":158,"context_line":"            \u0027is False.\u0027, image_href)"},{"line_number":159,"context_line":"        return False"},{"line_number":160,"context_line":"    hostname \u003d parsed.hostname"},{"line_number":161,"context_line":"    if not hostname:"},{"line_number":162,"context_line":"        return False"},{"line_number":163,"context_line":"    for entry in permitted_hosts:"}],"source_content_type":"text/x-python","patch_set":4,"id":"53f13a01_9184ff41","line":160,"in_reply_to":"74fb2187_7326f46b","updated":"2026-08-17 15:50:53.000000000","message":"The intent is the hostname, not the port. Do we feel we need to support port and protocol definitions as well? Or are we good with just hostnames?\n\nI guess the question ends up being how far at that point?","commit_id":"c0527a7170faeaf485fe68d712515f6940798fd0"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"6e2a0a7825d6f0f17ac689e1287fe523afcf9eef","unresolved":true,"context_lines":[{"line_number":1425,"context_line":"            and CONF.deploy.image_server_user"},{"line_number":1426,"context_line":"            and CONF.deploy.image_server_password"},{"line_number":1427,"context_line":"            and is_host_auth_permitted("},{"line_number":1428,"context_line":"                node.instance_info.get(\u0027image_source\u0027, \u0027\u0027))):"},{"line_number":1429,"context_line":"        # Fallback to image_server_user and image_server_password"},{"line_number":1430,"context_line":"        # if configured on the deploy interface and the image"},{"line_number":1431,"context_line":"        # source host is permitted to receive credentials."}],"source_content_type":"text/x-python","patch_set":4,"id":"868883e9_286f5f3d","line":1428,"updated":"2026-08-12 08:56:59.000000000","message":"Are you sure this function is not called for non-image_source cases?","commit_id":"c0527a7170faeaf485fe68d712515f6940798fd0"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"1f225f2d0c16335fa4966f71e77e320f229aef32","unresolved":true,"context_lines":[{"line_number":1425,"context_line":"            and CONF.deploy.image_server_user"},{"line_number":1426,"context_line":"            and CONF.deploy.image_server_password"},{"line_number":1427,"context_line":"            and is_host_auth_permitted("},{"line_number":1428,"context_line":"                node.instance_info.get(\u0027image_source\u0027, \u0027\u0027))):"},{"line_number":1429,"context_line":"        # Fallback to image_server_user and image_server_password"},{"line_number":1430,"context_line":"        # if configured on the deploy interface and the image"},{"line_number":1431,"context_line":"        # source host is permitted to receive credentials."}],"source_content_type":"text/x-python","patch_set":4,"id":"b1564a6d_de30a1cc","line":1428,"in_reply_to":"868883e9_286f5f3d","updated":"2026-08-17 15:50:53.000000000","message":"Its definitely called in non-image_source cases for any attribute. The reasoning largely being consistency across all image interactions.","commit_id":"c0527a7170faeaf485fe68d712515f6940798fd0"}],"ironic/conf/deploy.py":[{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"81f29538bf64e1c1eff1390295a3ca61e475e3fb","unresolved":true,"context_lines":[{"line_number":63,"context_line":"                       \"from. If configured, only matching hosts will \""},{"line_number":64,"context_line":"                       \"be sent credentials. This is a security feature \""},{"line_number":65,"context_line":"                       \"to prevent leakage of image server credentials \""},{"line_number":66,"context_line":"                       \"to untrusted hosts.\")),"},{"line_number":67,"context_line":"    cfg.URIOpt(\u0027external_http_url\u0027,"},{"line_number":68,"context_line":"               schemes\u003d[\u0027http\u0027, \u0027https\u0027],"},{"line_number":69,"context_line":"               help\u003d_(\"URL of the ironic-conductor node\u0027s HTTP server for \""}],"source_content_type":"text/x-python","patch_set":1,"id":"fc16793d_8522bf0c","line":66,"updated":"2026-08-04 16:59:08.000000000","message":"Should we permit globbing here? e.g. *.example.com","commit_id":"47f9b662d0b75f74a7924867483771d4931c5244"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"5807d2ab3eb1e94868a1e251fd3cb5c77b55e71a","unresolved":true,"context_lines":[{"line_number":63,"context_line":"                       \"from. If configured, only matching hosts will \""},{"line_number":64,"context_line":"                       \"be sent credentials. This is a security feature \""},{"line_number":65,"context_line":"                       \"to prevent leakage of image server credentials \""},{"line_number":66,"context_line":"                       \"to untrusted hosts.\")),"},{"line_number":67,"context_line":"    cfg.URIOpt(\u0027external_http_url\u0027,"},{"line_number":68,"context_line":"               schemes\u003d[\u0027http\u0027, \u0027https\u0027],"},{"line_number":69,"context_line":"               help\u003d_(\"URL of the ironic-conductor node\u0027s HTTP server for \""}],"source_content_type":"text/x-python","patch_set":1,"id":"5e453af1_397d9e63","line":66,"in_reply_to":"fc16793d_8522bf0c","updated":"2026-08-04 17:02:48.000000000","message":"I was thinking that it might be good originally, but I\u0027d rather operators have explicit control of their environments. Because someone may have delegated DNS control of my_evil_subdomain.example.com, or they may even re-delegate that further to untrusted endpoints.","commit_id":"47f9b662d0b75f74a7924867483771d4931c5244"}],"releasenotes/notes/image-server-auth-hosts-cve-2162816-3eb3ee215084ba53.yaml":[{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"8912bf66ae37a47f6c699f2c1a733c439137ad67","unresolved":true,"context_lines":[{"line_number":14,"context_line":"    its default will change to ``False`` in 2026.2. Operators"},{"line_number":15,"context_line":"    using ``http_basic`` should configure both options. See"},{"line_number":16,"context_line":"    `bug 2162816 \u003chttps://bugs.launchpad.net/ironic/+bug/2162816\u003e`_"},{"line_number":17,"context_line":"    for details."}],"source_content_type":"text/x-yaml","patch_set":5,"id":"8e714989_9769bd62","line":17,"updated":"2026-08-18 14:26:28.000000000","message":"Should we mention this also impacts oci:// using basic auth?","commit_id":"808a4acba935ce01e5d0e754387a3dab1de1bb4b"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"d39f53e9bc5cb4843300c00cc66b57088ef75b4b","unresolved":true,"context_lines":[{"line_number":14,"context_line":"    its default will change to ``False`` in 2026.2. Operators"},{"line_number":15,"context_line":"    using ``http_basic`` should configure both options. See"},{"line_number":16,"context_line":"    `bug 2162816 \u003chttps://bugs.launchpad.net/ironic/+bug/2162816\u003e`_"},{"line_number":17,"context_line":"    for details."}],"source_content_type":"text/x-yaml","patch_set":5,"id":"f24a9f18_845a5b0e","line":17,"in_reply_to":"8e714989_9769bd62","updated":"2026-08-18 15:33:47.000000000","message":"Likely should that it is capable of falling back and thus the same filtering logic applies.","commit_id":"808a4acba935ce01e5d0e754387a3dab1de1bb4b"}]}
