)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"91193745338871a9e3b355d8d4c8c6a916fc4270","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"798d5b2e_156d0815","updated":"2026-08-05 21:13:56.000000000","message":"recheck openstacksdk possible false failure coupled with nv job timeout.","commit_id":"23b9efe93ed7212cb1b886adabb43613192e9dec"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"8f2a04739a4e196a9ef9807c2ef71c3b26c46bfb","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"5e557cf6_96d4805f","updated":"2026-08-07 17:46:41.000000000","message":"recheck openstacsdk functional test race condition?","commit_id":"23b9efe93ed7212cb1b886adabb43613192e9dec"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"2d234bf9c6cd00d98d71a10ad166d623f6790635","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"28448309_a74d3489","updated":"2026-08-06 18:44:43.000000000","message":"recheck transient ci failure","commit_id":"23b9efe93ed7212cb1b886adabb43613192e9dec"}],"doc/source/admin/security.rst":[{"author":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"change_message_id":"4ac67a35d21e4c6f8f5d5ad9d40ba7198299effa","unresolved":true,"context_lines":[{"line_number":456,"context_line":"Alternatively, when using Keystone authentication"},{"line_number":457,"context_line":"(``auth_strategy\u003dkeystone``), the same effect can be achieved"},{"line_number":458,"context_line":"with custom policy rules. Add the following to the"},{"line_number":459,"context_line":":ironic-doc:`policy.yaml file \u003cconfiguration/sample-policy.html\u003e`::"},{"line_number":460,"context_line":""},{"line_number":461,"context_line":"    # Deny IPA ramdisk node lookup"},{"line_number":462,"context_line":"    \"baremetal:driver:ipa_lookup\": \"!\""}],"source_content_type":"text/x-rst","patch_set":1,"id":"0b48a55d_a3d76f6e","line":459,"updated":"2026-08-10 13:23:12.000000000","message":"So what\u0027s not clear to me from an operator standpoint is that if I\u0027m using keystone does this mean I don\u0027t need a split-horizon deployment to have a secure Ironic API? Will the custom policy protect these endpoints and then still allow IPA to work.","commit_id":"23b9efe93ed7212cb1b886adabb43613192e9dec"},{"author":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"change_message_id":"de973d9941c32e1bc9fe3f603d13020b5119181f","unresolved":false,"context_lines":[{"line_number":456,"context_line":"Alternatively, when using Keystone authentication"},{"line_number":457,"context_line":"(``auth_strategy\u003dkeystone``), the same effect can be achieved"},{"line_number":458,"context_line":"with custom policy rules. Add the following to the"},{"line_number":459,"context_line":":ironic-doc:`policy.yaml file \u003cconfiguration/sample-policy.html\u003e`::"},{"line_number":460,"context_line":""},{"line_number":461,"context_line":"    # Deny IPA ramdisk node lookup"},{"line_number":462,"context_line":"    \"baremetal:driver:ipa_lookup\": \"!\""}],"source_content_type":"text/x-rst","patch_set":1,"id":"a5000bdb_43989234","line":459,"in_reply_to":"0b48a55d_a3d76f6e","updated":"2026-08-10 14:12:54.000000000","message":"Done","commit_id":"23b9efe93ed7212cb1b886adabb43613192e9dec"}]}
