)]}'
{"id":"openstack%2Fkeystone~659600","triplet_id":"openstack%2Fkeystone~master~I9d59b1686298e752e56d61d25313f81dbd9a93ba","project":"openstack/keystone","branch":"master","topic":"bootstrap-ignore","hashtags":[],"change_id":"I9d59b1686298e752e56d61d25313f81dbd9a93ba","subject":"Use ignore_change_password_on_first_use for admin","status":"ABANDONED","created":"2019-05-16 15:29:02.000000000","updated":"2021-06-04 18:16:49.000000000","total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"d73c99d1f0d1055c9a183e894851c62a208b4423","_number":659600,"virtual_id_number":659600,"owner":{"_account_id":9542,"name":"Pavlo Shchelokovskyy","email":"pshchelokovskyy@mirantis.com","username":"pshchelo"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},{"date":"2019-05-21 10:37:58.000000000","_account_id":9542,"name":"Pavlo Shchelokovskyy","email":"pshchelokovskyy@mirantis.com","username":"pshchelo"},{"value":1,"date":"2019-05-16 19:22:41.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"disliked":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"all":[{"value":-1,"date":"2019-05-17 02:46:56.000000000","permitted_voting_range":{"min":-1,"max":1},"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":9542,"name":"Pavlo Shchelokovskyy","email":"pshchelokovskyy@mirantis.com","username":"pshchelo"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","value":-1,"default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},{"value":0,"permitted_voting_range":{"min":-1,"max":0},"_account_id":9542,"name":"Pavlo Shchelokovskyy","email":"pshchelokovskyy@mirantis.com","username":"pshchelo"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},{"_account_id":9542,"name":"Pavlo Shchelokovskyy","email":"pshchelokovskyy@mirantis.com","username":"pshchelo"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2019-05-16 19:22:41.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2019-05-17 02:46:56.000000000","updated_by":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"reviewer":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"state":"REVIEWER"}],"messages":[{"id":"e1b3d94754bd2fde24d2f2736aff533d8a28950c","author":{"_account_id":9542,"name":"Pavlo Shchelokovskyy","email":"pshchelokovskyy@mirantis.com","username":"pshchelo"},"date":"2019-05-16 15:29:02.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"2caaef3b26fc0068cebedbc2973943939e2e4851","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-05-16 19:22:41.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-cover http://logs.openstack.org/00/659600/1/check/openstack-tox-cover/908c9c9/cover/ : SUCCESS in 29m 08s\n- openstack-tox-lower-constraints http://logs.openstack.org/00/659600/1/check/openstack-tox-lower-constraints/1162b31/ : SUCCESS in 29m 57s\n- openstack-tox-pep8 http://logs.openstack.org/00/659600/1/check/openstack-tox-pep8/6c77d87/ : SUCCESS in 6m 16s\n- openstack-tox-py27 http://logs.openstack.org/00/659600/1/check/openstack-tox-py27/2894b05/ : SUCCESS in 25m 42s\n- openstack-tox-py36 http://logs.openstack.org/00/659600/1/check/openstack-tox-py36/8895392/ : SUCCESS in 23m 54s\n- openstack-tox-py37 http://logs.openstack.org/00/659600/1/check/openstack-tox-py37/57a1f16/ : SUCCESS in 24m 23s\n- openstack-tox-docs http://logs.openstack.org/00/659600/1/check/openstack-tox-docs/1ecf04f/html/ : SUCCESS in 7m 58s\n- tempest-full http://logs.openstack.org/00/659600/1/check/tempest-full/19bd00c/ : SUCCESS in 2h 03m 22s\n- neutron-grenade http://logs.openstack.org/00/659600/1/check/neutron-grenade/33007d2/ : SUCCESS in 58m 50s\n- grenade-py3 http://logs.openstack.org/00/659600/1/check/grenade-py3/f9ac0c7/ : SUCCESS in 59m 05s\n- tempest-full-py3 http://logs.openstack.org/00/659600/1/check/tempest-full-py3/895fa00/ : SUCCESS in 1h 35m 13s\n- keystone-dsvm-functional http://logs.openstack.org/00/659600/1/check/keystone-dsvm-functional/f35dd6b/ : SUCCESS in 32m 00s\n- keystone-dsvm-py3-functional http://logs.openstack.org/00/659600/1/check/keystone-dsvm-py3-functional/3702a82/ : SUCCESS in 32m 14s\n- keystone-dsvm-functional-federation-opensuse15 http://logs.openstack.org/00/659600/1/check/keystone-dsvm-functional-federation-opensuse15/62a8343/ : SUCCESS in 34m 56s (non-voting)\n- keystone-dsvm-py3-functional-federation-opensuse15 http://logs.openstack.org/00/659600/1/check/keystone-dsvm-py3-functional-federation-opensuse15/b99144e/ : SUCCESS in 39m 12s (non-voting)\n- keystoneclient-devstack-functional http://logs.openstack.org/00/659600/1/check/keystoneclient-devstack-functional/1d6b251/ : SUCCESS in 12m 07s (non-voting)\n- legacy-tempest-dsvm-ldap-domain-specific-driver http://logs.openstack.org/00/659600/1/check/legacy-tempest-dsvm-ldap-domain-specific-driver/98e1042/ : SUCCESS in 1h 49m 12s (non-voting)","accounts_in_message":[],"_revision_number":1},{"id":"b182099e21416a07923ec3ba3f9aa10219b74116","author":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"date":"2019-05-17 02:46:56.000000000","message":"Patch Set 1: Code-Review-1\n\nI\u0027m not comfortable with this being a hardcoded part of bootstrap. The security_compliance options are optional, they aren\u0027t enabled by default, so by default the admin user should not run into this problem. If the operator does want to consciously set these security_compliance options, they need to know to disable it for the admin user if they don\u0027t want the rules to apply to the user.","accounts_in_message":[],"_revision_number":1},{"id":"73b2a4ee54012c8ad6cebfbe896450deb031e5ed","author":{"_account_id":9542,"name":"Pavlo Shchelokovskyy","email":"pshchelokovskyy@mirantis.com","username":"pshchelo"},"date":"2019-05-21 10:37:58.000000000","message":"Patch Set 1:\n\nColeen, so these are optional but when enabled the admin user is useless for further automation as one can not change this options for the user unless changed password.\n\nWould you be ok if I add more keys to keystone-bootstrap allowing to set those (any supported) options on the admin user right during bootstrapping?","accounts_in_message":[],"_revision_number":1},{"id":"76bf3e254fa54af5da34e9769ec3d08e2d65bc72","author":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"date":"2019-05-21 17:42:38.000000000","message":"Patch Set 1:\n\n\u003e Coleen, so these are optional but when enabled the admin user is\n \u003e useless for further automation as one can not change this options\n \u003e for the user unless changed password.\n \u003e \n \u003e Would you be ok if I add more keys to keystone-bootstrap allowing\n \u003e to set those (any supported) options on the admin user right during\n \u003e bootstrapping?\n\nMy preference would be for the automation to be orchestrated in a way so that the admin user\u0027s options can be configured before the pci options are set in keystone, as that would be cleaner from keystone\u0027s perspective. Understanding that deployment tools aren\u0027t usually set up to make that kind of orchestration easy, I would be okay with adding flags to the bootstrap command to set the user options at bootstrap time.","accounts_in_message":[],"_revision_number":1},{"id":"d73c99d1f0d1055c9a183e894851c62a208b4423","tag":"autogenerated:gerrit:abandon","author":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},"date":"2021-06-04 18:16:49.000000000","message":"Abandoned\n\nAbandoning since there hasn\u0027t been any recent activity, if anyone wants to continue this work, please feel free to restore this or create a new change.","accounts_in_message":[],"_revision_number":1}],"current_revision_number":1,"current_revision":"62d5b8834d11838fdca391cf7846f85e108da04b","revisions":{"62d5b8834d11838fdca391cf7846f85e108da04b":{"kind":"REWORK","_number":1,"created":"2019-05-16 15:29:02.000000000","uploader":{"_account_id":9542,"name":"Pavlo Shchelokovskyy","email":"pshchelokovskyy@mirantis.com","username":"pshchelo"},"ref":"refs/changes/00/659600/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/00/659600/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/00/659600/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/00/659600/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/00/659600/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/00/659600/1"}}},"commit":{"parents":[{"commit":"6d306d936a283f907a9ca89de3f8de3392bbc794","subject":"Merge \"Add manager support for app cred access rules\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/6d306d936a283f907a9ca89de3f8de3392bbc794"}]}],"author":{"name":"Pavlo Shchelokovskyy","email":"shchelokovskyy@gmail.com","date":"2019-05-16 14:36:43.000000000","tz":0},"committer":{"name":"Pavlo Shchelokovskyy","email":"shchelokovskyy@gmail.com","date":"2019-05-16 15:28:59.000000000","tz":0},"subject":"Use ignore_change_password_on_first_use for admin","message":"Use ignore_change_password_on_first_use for admin\n\nusually deployment via configuration mgmt involves rendering config of\nthe service, executing the scripts and then staring a service.\n\nIf password expiry and change password on first use are set in Keystone,\nthe admin user created by bootstrap will be useless for further\nautomation, so let\u0027s create the user with at least\n\u0027ignore_change_password_on_first_use\u0027 set to True, giving automation a\nchance to set any other options on it\n(password_expiry is in days, so presumably automation has time to\nfinish).\n\nChange-Id: I9d59b1686298e752e56d61d25313f81dbd9a93ba\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/62d5b8834d11838fdca391cf7846f85e108da04b"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/62d5b8834d11838fdca391cf7846f85e108da04b"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
