)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},"change_message_id":"f7e030ae045bcab96230c983c279ea4490419faf","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"46107cad_18c8edf4","updated":"2026-03-19 16:38:12.000000000","message":"One can already get a system-scoped token as a federated user: https://review.opendev.org/c/openstack/keystone/+/981321/1/keystone/tests/unit/test_v3_federation.py","commit_id":"b901951ee9bbf2cca12a068c8874d670d79b4142"},{"author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"change_message_id":"494dafb5424e306e9a469d015c9e2fd1b9f23cad","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"6bb824f6_94e8f855","updated":"2026-03-19 12:59:25.000000000","message":"this is a very controversial proposal. We need to go through a careful evaluation with a spec and eventually a dedicated PTG discussion. I am strongly concerned about granting any admin capabilities through the federated login. I know for the project it is already there and I can\u0027t do anything about it, but I am not in favor of granting system scope over federation.","commit_id":"b901951ee9bbf2cca12a068c8874d670d79b4142"},{"author":{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},"change_message_id":"4593bc6201d03a8f9148d2859dd3df7a1aa01f12","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"56ddfbfc_cf66e33d","in_reply_to":"46107cad_18c8edf4","updated":"2026-03-19 17:32:47.000000000","message":"https://review.opendev.org/c/openstack/keystone/+/981321 - better link","commit_id":"b901951ee9bbf2cca12a068c8874d670d79b4142"},{"author":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"change_message_id":"111fc403140e00fe72a38e6069e515e06cfcbfa1","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":2,"id":"d69abae8_1360eb37","in_reply_to":"6bb824f6_94e8f855","updated":"2026-08-18 17:08:41.000000000","message":"I absolutely want to grant system scope over federation. A system scope user would be one of my cloud admins. They would have admin access to the Ironic API. I would also want them to have access to make system level changes to neutron like the VLAN allocation ranges which today is gated by a simple project scoped role\u003dadmin in ANY project which is not ideal because a project level admin is definitely not a system level admin. I don\u0027t want credentials stored in keystone and I want to use our company\u0027s SSO and tie all operations back to an individual.","commit_id":"b901951ee9bbf2cca12a068c8874d670d79b4142"}]}
