)]}'
{"ansible/group_vars/all.yml":[{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"e4d01c4cb5ae38cb4cbb8344b883e42c08087754","unresolved":false,"context_lines":[{"line_number":748,"context_line":"kolla_enable_tls_internal: \"no\""},{"line_number":749,"context_line":"kolla_enable_tls_external: \"{{ kolla_enable_tls_internal if kolla_same_external_internal_vip | bool else \u0027no\u0027 }}\""},{"line_number":750,"context_line":"kolla_certificates_dir: \"{{ node_config }}/certificates\""},{"line_number":751,"context_line":"kolla_external_fqdn_cert: \"{{ kolla_certificates_dir }}/haproxy.pem\""},{"line_number":752,"context_line":"kolla_internal_fqdn_cert: \"{{ kolla_certificates_dir }}/haproxy-internal.pem\""},{"line_number":753,"context_line":"kolla_external_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy.crt\""},{"line_number":754,"context_line":"kolla_internal_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy-internal.crt\""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"df33271e_8b7a8721","line":751,"range":{"start_line":751,"start_character":64,"end_line":751,"end_character":67},"updated":"2020-03-24 16:53:33.000000000","message":"why do we distinct one types of cert (.pem) over another types of cert (.crt)?","commit_id":"c3bc91d4314ac0f8ad81c7de14b55a88e36cea3e"},{"author":{"_account_id":30810,"name":"James Kirsch","email":"generalfuzz@gmail.com","username":"generalfuzz"},"change_message_id":"3a91d0cdffb54a008d0f45c543952a27136cd856","unresolved":false,"context_lines":[{"line_number":748,"context_line":"kolla_enable_tls_internal: \"no\""},{"line_number":749,"context_line":"kolla_enable_tls_external: \"{{ kolla_enable_tls_internal if kolla_same_external_internal_vip | bool else \u0027no\u0027 }}\""},{"line_number":750,"context_line":"kolla_certificates_dir: \"{{ node_config }}/certificates\""},{"line_number":751,"context_line":"kolla_external_fqdn_cert: \"{{ kolla_certificates_dir }}/haproxy.pem\""},{"line_number":752,"context_line":"kolla_internal_fqdn_cert: \"{{ kolla_certificates_dir }}/haproxy-internal.pem\""},{"line_number":753,"context_line":"kolla_external_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy.crt\""},{"line_number":754,"context_line":"kolla_internal_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy-internal.crt\""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"df33271e_74ea8475","line":751,"range":{"start_line":751,"start_character":64,"end_line":751,"end_character":67},"in_reply_to":"df33271e_510e7234","updated":"2020-03-24 22:21:41.000000000","message":"We need to name is a .crt file for the \"update-ca-certificates\" or \"update-ca-trust\" command to append the cert into the global \"ca-certficates.crt\" for the container. I just tried this with the same file named \".pem\" and it was ignored.\n\nhttps://superuser.com/questions/437330/how-do-you-add-a-certificate-authority-ca-to-ubuntu","commit_id":"c3bc91d4314ac0f8ad81c7de14b55a88e36cea3e"},{"author":{"_account_id":30810,"name":"James Kirsch","email":"generalfuzz@gmail.com","username":"generalfuzz"},"change_message_id":"e444fb223cb4b9a5e49d1ccd768f6f9ab3c76c88","unresolved":false,"context_lines":[{"line_number":748,"context_line":"kolla_enable_tls_internal: \"no\""},{"line_number":749,"context_line":"kolla_enable_tls_external: \"{{ kolla_enable_tls_internal if kolla_same_external_internal_vip | bool else \u0027no\u0027 }}\""},{"line_number":750,"context_line":"kolla_certificates_dir: \"{{ node_config }}/certificates\""},{"line_number":751,"context_line":"kolla_external_fqdn_cert: \"{{ kolla_certificates_dir }}/haproxy.pem\""},{"line_number":752,"context_line":"kolla_internal_fqdn_cert: \"{{ kolla_certificates_dir }}/haproxy-internal.pem\""},{"line_number":753,"context_line":"kolla_external_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy.crt\""},{"line_number":754,"context_line":"kolla_internal_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy-internal.crt\""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"df33271e_f8f310e6","line":751,"range":{"start_line":751,"start_character":64,"end_line":751,"end_character":67},"in_reply_to":"df33271e_5c3af997","updated":"2020-03-25 19:24:26.000000000","message":"sounds like this is not something we are going to fix in this change.","commit_id":"c3bc91d4314ac0f8ad81c7de14b55a88e36cea3e"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"fca56fada9def61eea9da2022497111113259b58","unresolved":false,"context_lines":[{"line_number":748,"context_line":"kolla_enable_tls_internal: \"no\""},{"line_number":749,"context_line":"kolla_enable_tls_external: \"{{ kolla_enable_tls_internal if kolla_same_external_internal_vip | bool else \u0027no\u0027 }}\""},{"line_number":750,"context_line":"kolla_certificates_dir: \"{{ node_config }}/certificates\""},{"line_number":751,"context_line":"kolla_external_fqdn_cert: \"{{ kolla_certificates_dir }}/haproxy.pem\""},{"line_number":752,"context_line":"kolla_internal_fqdn_cert: \"{{ kolla_certificates_dir }}/haproxy-internal.pem\""},{"line_number":753,"context_line":"kolla_external_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy.crt\""},{"line_number":754,"context_line":"kolla_internal_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy-internal.crt\""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"df33271e_510e7234","line":751,"range":{"start_line":751,"start_character":64,"end_line":751,"end_character":67},"in_reply_to":"df33271e_6eabd188","updated":"2020-03-24 17:40:47.000000000","message":"Ah, no idea. I guess we can still amend that?","commit_id":"c3bc91d4314ac0f8ad81c7de14b55a88e36cea3e"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"9e7765175cf9cafe6fa49253d0a0e48d334e9596","unresolved":false,"context_lines":[{"line_number":748,"context_line":"kolla_enable_tls_internal: \"no\""},{"line_number":749,"context_line":"kolla_enable_tls_external: \"{{ kolla_enable_tls_internal if kolla_same_external_internal_vip | bool else \u0027no\u0027 }}\""},{"line_number":750,"context_line":"kolla_certificates_dir: \"{{ node_config }}/certificates\""},{"line_number":751,"context_line":"kolla_external_fqdn_cert: \"{{ kolla_certificates_dir }}/haproxy.pem\""},{"line_number":752,"context_line":"kolla_internal_fqdn_cert: \"{{ kolla_certificates_dir }}/haproxy-internal.pem\""},{"line_number":753,"context_line":"kolla_external_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy.crt\""},{"line_number":754,"context_line":"kolla_internal_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy-internal.crt\""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"df33271e_5c3af997","line":751,"range":{"start_line":751,"start_character":64,"end_line":751,"end_character":67},"in_reply_to":"df33271e_74ea8475","updated":"2020-03-25 11:55:49.000000000","message":"Well, we can rename on fly.","commit_id":"c3bc91d4314ac0f8ad81c7de14b55a88e36cea3e"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"7c30159f5c9e6515a4c04ee6e8d1b85e6cd37f6c","unresolved":false,"context_lines":[{"line_number":748,"context_line":"kolla_enable_tls_internal: \"no\""},{"line_number":749,"context_line":"kolla_enable_tls_external: \"{{ kolla_enable_tls_internal if kolla_same_external_internal_vip | bool else \u0027no\u0027 }}\""},{"line_number":750,"context_line":"kolla_certificates_dir: \"{{ node_config }}/certificates\""},{"line_number":751,"context_line":"kolla_external_fqdn_cert: \"{{ kolla_certificates_dir }}/haproxy.pem\""},{"line_number":752,"context_line":"kolla_internal_fqdn_cert: \"{{ kolla_certificates_dir }}/haproxy-internal.pem\""},{"line_number":753,"context_line":"kolla_external_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy.crt\""},{"line_number":754,"context_line":"kolla_internal_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy-internal.crt\""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"df33271e_ab24abc7","line":751,"range":{"start_line":751,"start_character":64,"end_line":751,"end_character":67},"in_reply_to":"df33271e_8b7a8721","updated":"2020-03-24 17:08:14.000000000","message":".crt usually also hold PEM. I didn\u0027t get the question.\n\nI see this only does refactor the parent directory path variable.","commit_id":"c3bc91d4314ac0f8ad81c7de14b55a88e36cea3e"},{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"98dd5f0ba1126e4de66c97443d61d307af8c99cc","unresolved":false,"context_lines":[{"line_number":748,"context_line":"kolla_enable_tls_internal: \"no\""},{"line_number":749,"context_line":"kolla_enable_tls_external: \"{{ kolla_enable_tls_internal if kolla_same_external_internal_vip | bool else \u0027no\u0027 }}\""},{"line_number":750,"context_line":"kolla_certificates_dir: \"{{ node_config }}/certificates\""},{"line_number":751,"context_line":"kolla_external_fqdn_cert: \"{{ kolla_certificates_dir }}/haproxy.pem\""},{"line_number":752,"context_line":"kolla_internal_fqdn_cert: \"{{ kolla_certificates_dir }}/haproxy-internal.pem\""},{"line_number":753,"context_line":"kolla_external_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy.crt\""},{"line_number":754,"context_line":"kolla_internal_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy-internal.crt\""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"df33271e_6eabd188","line":751,"range":{"start_line":751,"start_character":64,"end_line":751,"end_character":67},"in_reply_to":"df33271e_ab24abc7","updated":"2020-03-24 17:23:46.000000000","message":"I just asked why for some certs we use .pem, but for others .crt - both are extensions used for PEM certificates ;-) it just looks kind of weird.","commit_id":"c3bc91d4314ac0f8ad81c7de14b55a88e36cea3e"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"26f59590b31097ecd4a811c1c871766570469c9f","unresolved":false,"context_lines":[{"line_number":748,"context_line":"kolla_enable_tls_internal: \"no\""},{"line_number":749,"context_line":"kolla_enable_tls_external: \"{{ kolla_enable_tls_internal if kolla_same_external_internal_vip | bool else \u0027no\u0027 }}\""},{"line_number":750,"context_line":"kolla_certificates_dir: \"{{ node_config }}/certificates\""},{"line_number":751,"context_line":"kolla_external_fqdn_cert: \"{{ kolla_certificates_dir }}/haproxy.pem\""},{"line_number":752,"context_line":"kolla_internal_fqdn_cert: \"{{ kolla_certificates_dir }}/haproxy-internal.pem\""},{"line_number":753,"context_line":"kolla_external_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy.crt\""},{"line_number":754,"context_line":"kolla_internal_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy-internal.crt\""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"df33271e_705f1072","line":751,"range":{"start_line":751,"start_character":64,"end_line":751,"end_character":67},"in_reply_to":"df33271e_f8f310e6","updated":"2020-03-26 09:09:46.000000000","message":"++, totally orthogonal.","commit_id":"c3bc91d4314ac0f8ad81c7de14b55a88e36cea3e"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d93a0ad525a57d68f784e4f1657ebe26bee0dbb2","unresolved":false,"context_lines":[{"line_number":753,"context_line":"kolla_external_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy.crt\""},{"line_number":754,"context_line":"kolla_internal_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy-internal.crt\""},{"line_number":755,"context_line":"kolla_copy_ca_into_containers: \"no\""},{"line_number":756,"context_line":"kolla_verify_backend_tls: \"yes\""},{"line_number":757,"context_line":"haproxy_backend_cacert: \"{{ \u0027ca-certificates.crt\u0027 if kolla_base_distro in [\u0027debian\u0027, \u0027ubuntu\u0027] else \u0027ca-bundle.trust.crt\u0027 }}\""},{"line_number":758,"context_line":"haproxy_backend_cacert_dir: \"/etc/ssl/certs\""},{"line_number":759,"context_line":"kolla_enable_tls_backend: \"no\""}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_e5e96eb7","line":756,"range":{"start_line":756,"start_character":13,"end_line":756,"end_character":24},"updated":"2020-03-30 19:39:50.000000000","message":"Let\u0027s be consistent on backend_tls vs tls_backend. tls_backend is more consistent with kolla_enable_tls_internal.","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d93a0ad525a57d68f784e4f1657ebe26bee0dbb2","unresolved":false,"context_lines":[{"line_number":757,"context_line":"haproxy_backend_cacert: \"{{ \u0027ca-certificates.crt\u0027 if kolla_base_distro in [\u0027debian\u0027, \u0027ubuntu\u0027] else \u0027ca-bundle.trust.crt\u0027 }}\""},{"line_number":758,"context_line":"haproxy_backend_cacert_dir: \"/etc/ssl/certs\""},{"line_number":759,"context_line":"kolla_enable_tls_backend: \"no\""},{"line_number":760,"context_line":"kolla_backend_internal_cert: \"\""},{"line_number":761,"context_line":"kolla_backend_internal_key: \"\""},{"line_number":762,"context_line":""},{"line_number":763,"context_line":"####################"},{"line_number":764,"context_line":"# Kibana options"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_85d8621e","line":761,"range":{"start_line":760,"start_character":0,"end_line":761,"end_character":30},"updated":"2020-03-30 19:39:50.000000000","message":"kolla_tls_backend_cert/key","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d56a323d34df8eba97a9cbc9c23ea80646ddfc3","unresolved":false,"context_lines":[{"line_number":757,"context_line":"haproxy_backend_cacert: \"{{ \u0027ca-certificates.crt\u0027 if kolla_base_distro in [\u0027debian\u0027, \u0027ubuntu\u0027] else \u0027ca-bundle.trust.crt\u0027 }}\""},{"line_number":758,"context_line":"haproxy_backend_cacert_dir: \"/etc/ssl/certs\""},{"line_number":759,"context_line":"kolla_enable_tls_backend: \"no\""},{"line_number":760,"context_line":"kolla_tls_backend_cert: \"{{ kolla_certificates_dir }}/ca/backend.crt\""},{"line_number":761,"context_line":"kolla_tls_backend_key: \"\""},{"line_number":762,"context_line":""},{"line_number":763,"context_line":"####################"}],"source_content_type":"text/x-yaml","patch_set":10,"id":"df33271e_2bd56e1c","line":760,"range":{"start_line":760,"start_character":54,"end_line":760,"end_character":56},"updated":"2020-04-03 10:30:21.000000000","message":"It\u0027s not a CA cert unless it\u0027s self-signed.","commit_id":"4716d7a792e76397103bdcbd2ab7924506482112"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d56a323d34df8eba97a9cbc9c23ea80646ddfc3","unresolved":false,"context_lines":[{"line_number":758,"context_line":"haproxy_backend_cacert_dir: \"/etc/ssl/certs\""},{"line_number":759,"context_line":"kolla_enable_tls_backend: \"no\""},{"line_number":760,"context_line":"kolla_tls_backend_cert: \"{{ kolla_certificates_dir }}/ca/backend.crt\""},{"line_number":761,"context_line":"kolla_tls_backend_key: \"\""},{"line_number":762,"context_line":""},{"line_number":763,"context_line":"####################"},{"line_number":764,"context_line":"# Kibana options"}],"source_content_type":"text/x-yaml","patch_set":10,"id":"df33271e_4bdef23d","line":761,"range":{"start_line":761,"start_character":0,"end_line":761,"end_character":21},"updated":"2020-04-03 10:30:21.000000000","message":"If we\u0027re defining a default for one we might as well do the other too. backend.key?","commit_id":"4716d7a792e76397103bdcbd2ab7924506482112"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"c89f069f5f6203b1fd5b1b089f46524400ab6ad5","unresolved":false,"context_lines":[{"line_number":757,"context_line":"haproxy_backend_cacert: \"{{ \u0027ca-certificates.crt\u0027 if kolla_base_distro in [\u0027debian\u0027, \u0027ubuntu\u0027] else \u0027ca-bundle.trust.crt\u0027 }}\""},{"line_number":758,"context_line":"haproxy_backend_cacert_dir: \"/etc/ssl/certs\""},{"line_number":759,"context_line":"kolla_enable_tls_backend: \"no\""},{"line_number":760,"context_line":"kolla_tls_backend_cert: \"{{ kolla_certificates_dir }}/private/backend/backend.crt\""},{"line_number":761,"context_line":"kolla_tls_backend_key: \"{{ kolla_certificates_dir }}/private/backend/backend.key\""},{"line_number":762,"context_line":""},{"line_number":763,"context_line":"####################"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"df33271e_90f2b999","line":760,"range":{"start_line":760,"start_character":25,"end_line":760,"end_character":81},"updated":"2020-04-06 13:54:47.000000000","message":"Let\u0027s adapt the certificates role to a sensible default, not the other way around.\n\n{{ kolla_certificates_dir }}/backend.crt","commit_id":"f255026f82a53f4f45078f425f1cbbbbc8daa24a"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"c89f069f5f6203b1fd5b1b089f46524400ab6ad5","unresolved":false,"context_lines":[{"line_number":758,"context_line":"haproxy_backend_cacert_dir: \"/etc/ssl/certs\""},{"line_number":759,"context_line":"kolla_enable_tls_backend: \"no\""},{"line_number":760,"context_line":"kolla_tls_backend_cert: \"{{ kolla_certificates_dir }}/private/backend/backend.crt\""},{"line_number":761,"context_line":"kolla_tls_backend_key: \"{{ kolla_certificates_dir }}/private/backend/backend.key\""},{"line_number":762,"context_line":""},{"line_number":763,"context_line":"####################"},{"line_number":764,"context_line":"# Kibana options"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"df33271e_70ef35b0","line":761,"updated":"2020-04-06 13:54:47.000000000","message":"ditto","commit_id":"f255026f82a53f4f45078f425f1cbbbbc8daa24a"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"9edb51afad0f05f051d103a97ad00d31a32329ad","unresolved":false,"context_lines":[{"line_number":747,"context_line":"haproxy_enable_external_vip: \"{{ \u0027no\u0027 if kolla_same_external_internal_vip | bool else \u0027yes\u0027 }}\""},{"line_number":748,"context_line":"kolla_enable_tls_internal: \"no\""},{"line_number":749,"context_line":"kolla_enable_tls_external: \"{{ kolla_enable_tls_internal if kolla_same_external_internal_vip | bool else \u0027no\u0027 }}\""},{"line_number":750,"context_line":"kolla_certificates_dir: \"{{ node_config }}/certificates\""},{"line_number":751,"context_line":"kolla_external_fqdn_cert: \"{{ kolla_certificates_dir }}/haproxy.pem\""},{"line_number":752,"context_line":"kolla_internal_fqdn_cert: \"{{ kolla_certificates_dir }}/haproxy-internal.pem\""},{"line_number":753,"context_line":"kolla_external_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy.crt\""},{"line_number":754,"context_line":"kolla_internal_fqdn_cacert: \"{{ kolla_certificates_dir }}/ca/haproxy-internal.crt\""},{"line_number":755,"context_line":"kolla_copy_ca_into_containers: \"no\""},{"line_number":756,"context_line":"kolla_verify_tls_backend: \"yes\""},{"line_number":757,"context_line":"haproxy_backend_cacert: \"{{ \u0027ca-certificates.crt\u0027 if kolla_base_distro in [\u0027debian\u0027, \u0027ubuntu\u0027] else \u0027ca-bundle.trust.crt\u0027 }}\""}],"source_content_type":"text/x-yaml","patch_set":13,"id":"df33271e_9f02b36e","line":754,"range":{"start_line":750,"start_character":0,"end_line":754,"end_character":82},"updated":"2020-04-07 09:30:05.000000000","message":"Could you update etc/kolla/globals.yml to match these new defaults?\n\nAlso, there is a reference to {{ node_config }}/certificates in doc/source/admin/advanced-configuration.rst.","commit_id":"16d2c722b83aaf0297b5795bdc07e1dd463a3d67"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"2cb21578ae9486cf6bec314c78cb9b33f2b7a1a7","unresolved":false,"context_lines":[{"line_number":758,"context_line":"haproxy_backend_cacert_dir: \"/etc/ssl/certs\""},{"line_number":759,"context_line":"kolla_enable_tls_backend: \"no\""},{"line_number":760,"context_line":"kolla_tls_backend_cert: \"{{ kolla_certificates_dir }}/backend-cert.pem\""},{"line_number":761,"context_line":"kolla_tls_backend_key: \"{{ kolla_certificates_dir }}/backend-key.pem\""},{"line_number":762,"context_line":""},{"line_number":763,"context_line":"####################"},{"line_number":764,"context_line":"# Kibana options"}],"source_content_type":"text/x-yaml","patch_set":14,"id":"df33271e_aa558f52","line":761,"range":{"start_line":761,"start_character":65,"end_line":761,"end_character":68},"updated":"2020-04-08 10:03:22.000000000","message":"ok, we\u0027re going for a key with .pem... Seems to be fairly equal between .key and .pem for keys in a small sample of tutorials (possibly more .key).\n\nWe do still have the keystone key generated as .key though, so let\u0027s be consistent one way or the other.","commit_id":"b810fd5bb235f628c35bf5c22e96d32954e394c2"},{"author":{"_account_id":30810,"name":"James Kirsch","email":"generalfuzz@gmail.com","username":"generalfuzz"},"change_message_id":"31e47189bd279c44ae43ba64b5f1015b1592d2dd","unresolved":false,"context_lines":[{"line_number":758,"context_line":"haproxy_backend_cacert_dir: \"/etc/ssl/certs\""},{"line_number":759,"context_line":"kolla_enable_tls_backend: \"no\""},{"line_number":760,"context_line":"kolla_tls_backend_cert: \"{{ kolla_certificates_dir }}/backend-cert.pem\""},{"line_number":761,"context_line":"kolla_tls_backend_key: \"{{ kolla_certificates_dir }}/backend-key.pem\""},{"line_number":762,"context_line":""},{"line_number":763,"context_line":"####################"},{"line_number":764,"context_line":"# Kibana options"}],"source_content_type":"text/x-yaml","patch_set":14,"id":"df33271e_ddd25134","line":761,"range":{"start_line":761,"start_character":65,"end_line":761,"end_character":68},"in_reply_to":"df33271e_aa558f52","updated":"2020-04-08 16:25:42.000000000","message":"I will go will .pem for the key. That is what lets encrypt generates.","commit_id":"b810fd5bb235f628c35bf5c22e96d32954e394c2"}],"ansible/inventory/all-in-one":[{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"a1312e14b955afa95968c2f8a0525ca9befa966c","unresolved":false,"context_lines":[{"line_number":37,"context_line":""},{"line_number":38,"context_line":"[tls-backend:children]"},{"line_number":39,"context_line":"control"},{"line_number":40,"context_line":"monitoring"},{"line_number":41,"context_line":""},{"line_number":42,"context_line":"[grafana:children]"},{"line_number":43,"context_line":"monitoring"}],"source_content_type":"application/octet-stream","patch_set":13,"id":"df33271e_c234604d","line":40,"range":{"start_line":40,"start_character":0,"end_line":40,"end_character":10},"updated":"2020-04-07 09:41:35.000000000","message":"which one of those changed roles runs on the monitoring node?","commit_id":"16d2c722b83aaf0297b5795bdc07e1dd463a3d67"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"110fc223606b5a97965ce488599090f3812b2e9b","unresolved":false,"context_lines":[{"line_number":37,"context_line":""},{"line_number":38,"context_line":"[tls-backend:children]"},{"line_number":39,"context_line":"control"},{"line_number":40,"context_line":"monitoring"},{"line_number":41,"context_line":""},{"line_number":42,"context_line":"[grafana:children]"},{"line_number":43,"context_line":"monitoring"}],"source_content_type":"application/octet-stream","patch_set":13,"id":"df33271e_c25bc084","line":40,"range":{"start_line":40,"start_character":0,"end_line":40,"end_character":10},"in_reply_to":"df33271e_c234604d","updated":"2020-04-07 09:45:21.000000000","message":"None yet, but the service-cert-copy role will be applied to various services in time. We could stick to control if you prefer.","commit_id":"16d2c722b83aaf0297b5795bdc07e1dd463a3d67"},{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"632e7d1bacad8239febf5c050e4c448c4ee72154","unresolved":false,"context_lines":[{"line_number":37,"context_line":""},{"line_number":38,"context_line":"[tls-backend:children]"},{"line_number":39,"context_line":"control"},{"line_number":40,"context_line":"monitoring"},{"line_number":41,"context_line":""},{"line_number":42,"context_line":"[grafana:children]"},{"line_number":43,"context_line":"monitoring"}],"source_content_type":"application/octet-stream","patch_set":13,"id":"df33271e_0203e843","line":40,"range":{"start_line":40,"start_character":0,"end_line":40,"end_character":10},"in_reply_to":"df33271e_c25bc084","updated":"2020-04-07 09:47:38.000000000","message":"Well, then if it becomes required - we can add it in a respective change ;-)","commit_id":"16d2c722b83aaf0297b5795bdc07e1dd463a3d67"}],"ansible/inventory/multinode":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d56a323d34df8eba97a9cbc9c23ea80646ddfc3","unresolved":false,"context_lines":[{"line_number":29,"context_line":"[storage]"},{"line_number":30,"context_line":"storage01"},{"line_number":31,"context_line":""},{"line_number":32,"context_line":"[tls-backend:children]"},{"line_number":33,"context_line":"control"},{"line_number":34,"context_line":"network"},{"line_number":35,"context_line":"compute"}],"source_content_type":"application/octet-stream","patch_set":10,"id":"df33271e_ab7fbe12","line":32,"updated":"2020-04-03 10:30:21.000000000","message":"Can we move this below the top-level groups, maybe under baremetal?","commit_id":"4716d7a792e76397103bdcbd2ab7924506482112"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d56a323d34df8eba97a9cbc9c23ea80646ddfc3","unresolved":false,"context_lines":[{"line_number":31,"context_line":""},{"line_number":32,"context_line":"[tls-backend:children]"},{"line_number":33,"context_line":"control"},{"line_number":34,"context_line":"network"},{"line_number":35,"context_line":"compute"},{"line_number":36,"context_line":"storage"},{"line_number":37,"context_line":"monitoring"},{"line_number":38,"context_line":""},{"line_number":39,"context_line":"[deployment]"}],"source_content_type":"application/octet-stream","patch_set":10,"id":"df33271e_0ba6aac1","line":36,"range":{"start_line":34,"start_character":0,"end_line":36,"end_character":7},"updated":"2020-04-03 10:30:21.000000000","message":"These should not be hosting API services by default.\n\nThese should also be added for the all-in-one inventory.","commit_id":"4716d7a792e76397103bdcbd2ab7924506482112"}],"ansible/roles/certificates/tasks/generate.yml":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d56a323d34df8eba97a9cbc9c23ea80646ddfc3","unresolved":false,"context_lines":[{"line_number":164,"context_line":"        -out {{ item }}"},{"line_number":165,"context_line":"      with_items:"},{"line_number":166,"context_line":"        - \"{{ kolla_certificates_dir }}/private/backend/backend.crt\""},{"line_number":167,"context_line":"    - name: Creating backend CA Certificate File"},{"line_number":168,"context_line":"      copy:"},{"line_number":169,"context_line":"        src: \"{{ kolla_certificates_dir }}/private/backend/backend.crt\""},{"line_number":170,"context_line":"        dest: \"{{ kolla_tls_backend_cert }}\""}],"source_content_type":"text/x-yaml","patch_set":10,"id":"df33271e_6bfe566b","line":167,"range":{"start_line":167,"start_character":29,"end_line":167,"end_character":31},"updated":"2020-04-03 10:30:21.000000000","message":"This is not the CA location. We should copy it to the haproxy CA cert location though, similar to how it\u0027s done for the others.\n\n{{ haproxy_backend_cacert_dir }}/{{ haproxy_backend_cacert }}","commit_id":"4716d7a792e76397103bdcbd2ab7924506482112"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"9edb51afad0f05f051d103a97ad00d31a32329ad","unresolved":false,"context_lines":[{"line_number":15,"context_line":""},{"line_number":16,"context_line":"- name: Ensuring private backend directory exist"},{"line_number":17,"context_line":"  file:"},{"line_number":18,"context_line":"    path: \"{{ kolla_certificates_dir }}/private/backend\""},{"line_number":19,"context_line":"    state: \"directory\""},{"line_number":20,"context_line":"    recurse: yes"},{"line_number":21,"context_line":"    mode: \"0770\""}],"source_content_type":"text/x-yaml","patch_set":13,"id":"df33271e_bf8217c7","line":18,"range":{"start_line":18,"start_character":11,"end_line":18,"end_character":55},"updated":"2020-04-07 09:30:05.000000000","message":"Could iterate over these instead:\n\n- kolla_tls_backend_cert | dirname\n- kolla_tls_backend_key | dirname","commit_id":"16d2c722b83aaf0297b5795bdc07e1dd463a3d67"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"9edb51afad0f05f051d103a97ad00d31a32329ad","unresolved":false,"context_lines":[{"line_number":163,"context_line":"        -key {{ kolla_tls_backend_key }} \\"},{"line_number":164,"context_line":"        -out {{ item }}"},{"line_number":165,"context_line":"      with_items:"},{"line_number":166,"context_line":"        - \"{{ kolla_certificates_dir }}/private/backend/backend.crt\""},{"line_number":167,"context_line":"    - name: Creating backend Certificate file"},{"line_number":168,"context_line":"      copy:"},{"line_number":169,"context_line":"        src: \"{{ kolla_certificates_dir }}/private/backend/backend.crt\""}],"source_content_type":"text/x-yaml","patch_set":13,"id":"df33271e_dfa8bbda","line":166,"range":{"start_line":166,"start_character":11,"end_line":166,"end_character":67},"updated":"2020-04-07 09:30:05.000000000","message":"Might as well go straight to kolla_tls_backend_cert, as you have done for the key.","commit_id":"16d2c722b83aaf0297b5795bdc07e1dd463a3d67"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"2cb21578ae9486cf6bec314c78cb9b33f2b7a1a7","unresolved":false,"context_lines":[{"line_number":15,"context_line":""},{"line_number":16,"context_line":"- name: Ensuring private backend certificate directory exists"},{"line_number":17,"context_line":"  file:"},{"line_number":18,"context_line":"    path: \"kolla_tls_backend_cert | dirname\""},{"line_number":19,"context_line":"    state: \"directory\""},{"line_number":20,"context_line":"    recurse: yes"},{"line_number":21,"context_line":"    mode: \"0770\""}],"source_content_type":"text/x-yaml","patch_set":14,"id":"df33271e_cac45362","line":18,"range":{"start_line":18,"start_character":11,"end_line":18,"end_character":43},"updated":"2020-04-08 10:03:22.000000000","message":"Needs {{ }}","commit_id":"b810fd5bb235f628c35bf5c22e96d32954e394c2"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"2cb21578ae9486cf6bec314c78cb9b33f2b7a1a7","unresolved":false,"context_lines":[{"line_number":24,"context_line":""},{"line_number":25,"context_line":"- name: Ensuring private backend key directory exists"},{"line_number":26,"context_line":"  file:"},{"line_number":27,"context_line":"    path: \"kolla_tls_backend_key | dirname\""},{"line_number":28,"context_line":"    state: \"directory\""},{"line_number":29,"context_line":"    recurse: yes"},{"line_number":30,"context_line":"    mode: \"0770\""}],"source_content_type":"text/x-yaml","patch_set":14,"id":"df33271e_2aa17faa","line":27,"range":{"start_line":27,"start_character":11,"end_line":27,"end_character":42},"updated":"2020-04-08 10:03:22.000000000","message":"ditto","commit_id":"b810fd5bb235f628c35bf5c22e96d32954e394c2"}],"ansible/roles/certificates/templates/openssl-kolla-backend.cnf.j2":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d56a323d34df8eba97a9cbc9c23ea80646ddfc3","unresolved":false,"context_lines":[{"line_number":8,"context_line":"stateOrProvinceName \u003d NC"},{"line_number":9,"context_line":"localityName \u003d RTP"},{"line_number":10,"context_line":"organizationalUnitName \u003d kolla"},{"line_number":11,"context_line":"commonName \u003d {{ kolla_internal_fqdn }}"},{"line_number":12,"context_line":""},{"line_number":13,"context_line":"[v3_req]"},{"line_number":14,"context_line":"subjectAltName \u003d @alt_names"}],"source_content_type":"text/x-jinja2","patch_set":10,"id":"df33271e_0b67ca4e","line":11,"range":{"start_line":11,"start_character":0,"end_line":11,"end_character":38},"updated":"2020-04-03 10:30:21.000000000","message":"I think we can drop this","commit_id":"4716d7a792e76397103bdcbd2ab7924506482112"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d56a323d34df8eba97a9cbc9c23ea80646ddfc3","unresolved":false,"context_lines":[{"line_number":15,"context_line":""},{"line_number":16,"context_line":"[alt_names]"},{"line_number":17,"context_line":"{% for host in groups[\u0027tls-backend\u0027]%}"},{"line_number":18,"context_line":"{% if \u0027ansible_host\u0027 in hostvars[host] %}"},{"line_number":19,"context_line":"IP.{{ loop.index }} \u003d {{hostvars[host][\u0027ansible_host\u0027]}}"},{"line_number":20,"context_line":"{% else %}"},{"line_number":21,"context_line":"IP.{{ loop.index }} \u003d {{ host }}"},{"line_number":22,"context_line":"{% endif %}"},{"line_number":23,"context_line":"{% endfor %}"}],"source_content_type":"text/x-jinja2","patch_set":10,"id":"df33271e_0bccea32","line":22,"range":{"start_line":18,"start_character":0,"end_line":22,"end_character":11},"updated":"2020-04-03 10:30:21.000000000","message":"Ok, looking cleaner. I expect ansible_host will work in CI, since we define it as the node\u0027s IP. We can\u0027t assume that though and need to move to the fact-based kolla_address lookup.","commit_id":"4716d7a792e76397103bdcbd2ab7924506482112"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"9edb51afad0f05f051d103a97ad00d31a32329ad","unresolved":false,"context_lines":[{"line_number":14,"context_line":""},{"line_number":15,"context_line":"[alt_names]"},{"line_number":16,"context_line":"{% for host in groups[\u0027tls-backend\u0027]%}"},{"line_number":17,"context_line":"{% if \u0027ansible_host\u0027 in hostvars[\u0027api\u0027 | kolla_address(host)] %}"},{"line_number":18,"context_line":"IP.{{ loop.index }} \u003d {{hostvars[\u0027api\u0027 | kolla_address(host)][\u0027ansible_host\u0027]}}"},{"line_number":19,"context_line":"{% else %}"},{"line_number":20,"context_line":"IP.{{ loop.index }} \u003d {{ \u0027api\u0027 | kolla_address(host) }}"},{"line_number":21,"context_line":"{% endif %}"}],"source_content_type":"text/x-jinja2","patch_set":13,"id":"df33271e_1f8ce37d","line":18,"range":{"start_line":17,"start_character":0,"end_line":18,"end_character":79},"updated":"2020-04-07 09:30:05.000000000","message":"This doesn\u0027t really make sense. You can drop it and keep the else.","commit_id":"16d2c722b83aaf0297b5795bdc07e1dd463a3d67"}],"ansible/roles/certificates/templates/openssl-kolla-internal.cnf.j2":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d38e85f4492061fafe876e57fea3370e98b2a17","unresolved":false,"context_lines":[{"line_number":1,"context_line":"[req]"},{"line_number":2,"context_line":"prompt \u003d no"},{"line_number":3,"context_line":"distinguished_name \u003d req_distinguished_name"},{"line_number":4,"context_line":"req_extensions \u003d v3_req"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_1d6722b9","line":1,"updated":"2020-04-02 17:30:09.000000000","message":"Perhaps it would be cleaner to generate a third certificate for the backends?","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d93a0ad525a57d68f784e4f1657ebe26bee0dbb2","unresolved":false,"context_lines":[{"line_number":14,"context_line":"subjectAltName \u003d @alt_names"},{"line_number":15,"context_line":""},{"line_number":16,"context_line":"[alt_names]"},{"line_number":17,"context_line":"{% if kolla_internal_fqdn !\u003d kolla_internal_vip_address %}"},{"line_number":18,"context_line":"DNS.1 \u003d {{ kolla_internal_fqdn }}"},{"line_number":19,"context_line":"{% for host in hostvars %}"},{"line_number":20,"context_line":"{% if host not in ansible_play_hosts %}"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_cba706a7","line":17,"range":{"start_line":17,"start_character":6,"end_line":17,"end_character":55},"updated":"2020-03-30 19:39:50.000000000","message":"The DNS vs IP split makes sense for the FQDN/VIP, but for the backend we always use an IP.","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d38e85f4492061fafe876e57fea3370e98b2a17","unresolved":false,"context_lines":[{"line_number":14,"context_line":"subjectAltName \u003d @alt_names"},{"line_number":15,"context_line":""},{"line_number":16,"context_line":"[alt_names]"},{"line_number":17,"context_line":"{% if kolla_internal_fqdn !\u003d kolla_internal_vip_address %}"},{"line_number":18,"context_line":"DNS.1 \u003d {{ kolla_internal_fqdn }}"},{"line_number":19,"context_line":"{% for host in hostvars %}"},{"line_number":20,"context_line":"{% if host not in ansible_play_hosts %}"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_fd423e3d","line":17,"range":{"start_line":17,"start_character":6,"end_line":17,"end_character":55},"in_reply_to":"df33271e_9cb0a645","updated":"2020-04-02 17:30:09.000000000","message":"The FQDNs referred to here resolve to the VIP, rather than a machine IP. We generally use IPs for everything else in Kolla Ansible (for better or worse). We probably should document that the backend certs need to reference the server\u0027s IP on the internal API network.","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":30810,"name":"James Kirsch","email":"generalfuzz@gmail.com","username":"generalfuzz"},"change_message_id":"d8ad55bde8c59528b077737c3a199372bc082730","unresolved":false,"context_lines":[{"line_number":14,"context_line":"subjectAltName \u003d @alt_names"},{"line_number":15,"context_line":""},{"line_number":16,"context_line":"[alt_names]"},{"line_number":17,"context_line":"{% if kolla_internal_fqdn !\u003d kolla_internal_vip_address %}"},{"line_number":18,"context_line":"DNS.1 \u003d {{ kolla_internal_fqdn }}"},{"line_number":19,"context_line":"{% for host in hostvars %}"},{"line_number":20,"context_line":"{% if host not in ansible_play_hosts %}"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_9cb0a645","line":17,"range":{"start_line":17,"start_character":6,"end_line":17,"end_character":55},"in_reply_to":"df33271e_cba706a7","updated":"2020-03-31 05:29:07.000000000","message":"If machines are assigned a fqdn (os1.server.com), and we are using self signed certs, it is possible to use the machine domain name as the validated dns name for the cert. Should we document that backend servers must be defined with ips for verification of self signed certs to work?","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d93a0ad525a57d68f784e4f1657ebe26bee0dbb2","unresolved":false,"context_lines":[{"line_number":28,"context_line":"{% else %}"},{"line_number":29,"context_line":"IP.1 \u003d {{ kolla_internal_fqdn }}"},{"line_number":30,"context_line":"{% for host in hostvars %}"},{"line_number":31,"context_line":"{% if host not in ansible_play_hosts %}"},{"line_number":32,"context_line":"{% if \u0027ansible_host\u0027 in hostvars[host] %}"},{"line_number":33,"context_line":"IP.{{ loop.index + 1 }} \u003d {{hostvars[host][\u0027ansible_host\u0027]}}"},{"line_number":34,"context_line":"{% else %}"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_4bb5b6cc","line":31,"range":{"start_line":31,"start_character":6,"end_line":31,"end_character":36},"updated":"2020-03-30 19:39:50.000000000","message":"I don\u0027t really get this logic","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":30810,"name":"James Kirsch","email":"generalfuzz@gmail.com","username":"generalfuzz"},"change_message_id":"d8ad55bde8c59528b077737c3a199372bc082730","unresolved":false,"context_lines":[{"line_number":28,"context_line":"{% else %}"},{"line_number":29,"context_line":"IP.1 \u003d {{ kolla_internal_fqdn }}"},{"line_number":30,"context_line":"{% for host in hostvars %}"},{"line_number":31,"context_line":"{% if host not in ansible_play_hosts %}"},{"line_number":32,"context_line":"{% if \u0027ansible_host\u0027 in hostvars[host] %}"},{"line_number":33,"context_line":"IP.{{ loop.index + 1 }} \u003d {{hostvars[host][\u0027ansible_host\u0027]}}"},{"line_number":34,"context_line":"{% else %}"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_fc8a9267","line":31,"range":{"start_line":31,"start_character":6,"end_line":31,"end_character":36},"in_reply_to":"df33271e_4bb5b6cc","updated":"2020-03-31 05:29:07.000000000","message":"This is to ensure we are not including the ansible host ip in the list. Can you suggest a different approach?","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d38e85f4492061fafe876e57fea3370e98b2a17","unresolved":false,"context_lines":[{"line_number":28,"context_line":"{% else %}"},{"line_number":29,"context_line":"IP.1 \u003d {{ kolla_internal_fqdn }}"},{"line_number":30,"context_line":"{% for host in hostvars %}"},{"line_number":31,"context_line":"{% if host not in ansible_play_hosts %}"},{"line_number":32,"context_line":"{% if \u0027ansible_host\u0027 in hostvars[host] %}"},{"line_number":33,"context_line":"IP.{{ loop.index + 1 }} \u003d {{hostvars[host][\u0027ansible_host\u0027]}}"},{"line_number":34,"context_line":"{% else %}"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_1db9e213","line":31,"range":{"start_line":31,"start_character":6,"end_line":31,"end_character":36},"in_reply_to":"df33271e_fc8a9267","updated":"2020-04-02 17:30:09.000000000","message":"I would suggest we add a variable that defines a group or list of groups to iterate over. The \u0027control\u0027 group might be a sensible default since that is where API servers are typically hosted.","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d93a0ad525a57d68f784e4f1657ebe26bee0dbb2","unresolved":false,"context_lines":[{"line_number":29,"context_line":"IP.1 \u003d {{ kolla_internal_fqdn }}"},{"line_number":30,"context_line":"{% for host in hostvars %}"},{"line_number":31,"context_line":"{% if host not in ansible_play_hosts %}"},{"line_number":32,"context_line":"{% if \u0027ansible_host\u0027 in hostvars[host] %}"},{"line_number":33,"context_line":"IP.{{ loop.index + 1 }} \u003d {{hostvars[host][\u0027ansible_host\u0027]}}"},{"line_number":34,"context_line":"{% else %}"},{"line_number":35,"context_line":"IP.{{ loop.index + 1 }} \u003d {{ host }}"},{"line_number":36,"context_line":"{% endif %}"},{"line_number":37,"context_line":"{% endif %}"},{"line_number":38,"context_line":"{% endfor %}"},{"line_number":39,"context_line":"{% endif %}"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_cbd546e7","line":36,"range":{"start_line":32,"start_character":0,"end_line":36,"end_character":11},"updated":"2020-03-30 19:39:50.000000000","message":"The address that we configure for the backend in HAProxy is:\n\nhost_ip \u003d \u0027api\u0027 | kolla_address(host)","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"1b078b83be7648216f0df8eb64033c3920244986","unresolved":false,"context_lines":[{"line_number":29,"context_line":"IP.1 \u003d {{ kolla_internal_fqdn }}"},{"line_number":30,"context_line":"{% for host in hostvars %}"},{"line_number":31,"context_line":"{% if host not in ansible_play_hosts %}"},{"line_number":32,"context_line":"{% if \u0027ansible_host\u0027 in hostvars[host] %}"},{"line_number":33,"context_line":"IP.{{ loop.index + 1 }} \u003d {{hostvars[host][\u0027ansible_host\u0027]}}"},{"line_number":34,"context_line":"{% else %}"},{"line_number":35,"context_line":"IP.{{ loop.index + 1 }} \u003d {{ host }}"},{"line_number":36,"context_line":"{% endif %}"},{"line_number":37,"context_line":"{% endif %}"},{"line_number":38,"context_line":"{% endfor %}"},{"line_number":39,"context_line":"{% endif %}"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_10f22907","line":36,"range":{"start_line":32,"start_character":0,"end_line":36,"end_character":11},"in_reply_to":"df33271e_00731b4f","updated":"2020-04-06 13:37:30.000000000","message":"The task for gathering facts you see is just executed against localhost, so we don\u0027t get facts for all hosts.\n\ngather-facts.yml is a playbook, so you can import it like this:\n\n- import_playbook: gather-facts.yml\n\nYou can also add a \u0027when\u0027 condition, with the gotcha that it will not pick up the default in group_vars/all.yml:\n\n- import_playbook: gather-facts.yml\n  when: kolla_enable_tls_backend | default(false) | bool","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":30810,"name":"James Kirsch","email":"generalfuzz@gmail.com","username":"generalfuzz"},"change_message_id":"6cc78abd1d156bdb572fa83dd6ed86b3af4dc994","unresolved":false,"context_lines":[{"line_number":29,"context_line":"IP.1 \u003d {{ kolla_internal_fqdn }}"},{"line_number":30,"context_line":"{% for host in hostvars %}"},{"line_number":31,"context_line":"{% if host not in ansible_play_hosts %}"},{"line_number":32,"context_line":"{% if \u0027ansible_host\u0027 in hostvars[host] %}"},{"line_number":33,"context_line":"IP.{{ loop.index + 1 }} \u003d {{hostvars[host][\u0027ansible_host\u0027]}}"},{"line_number":34,"context_line":"{% else %}"},{"line_number":35,"context_line":"IP.{{ loop.index + 1 }} \u003d {{ host }}"},{"line_number":36,"context_line":"{% endif %}"},{"line_number":37,"context_line":"{% endif %}"},{"line_number":38,"context_line":"{% endfor %}"},{"line_number":39,"context_line":"{% endif %}"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_00731b4f","line":36,"range":{"start_line":32,"start_character":0,"end_line":36,"end_character":11},"in_reply_to":"df33271e_0bd7ca4c","updated":"2020-04-04 17:07:51.000000000","message":"Sorry, but I need a little more help here. First off, when executing the certificates role via: \"kolla-ansible -i ~/multinode certificates\" the first thing that is put in stdout:\n\nPLAY [Apply role certificates] ****************************************************************************************************************\n\nTASK [Gathering Facts] *************************************************************************\n\nso it may already be executing.\n\nWhen I try to import it using:\n\n- name: gather facts\n  include_role:\n    name: gather-facts.yml\n\nor \n\n- name: gather facts\n  import_role:\n    name: gather-facts.yml\n\nThe output is:\n\nTASK [gather facts] ***************************************************************************************************************************\n[WARNING]: Ignoring invalid path provided to plugin path: \u0027/root/kolla-ansible/ansible/gather-facts.yml\u0027 is not a directory\n\nand it will still fail with:\n\n\"FilterError: Interface \u0027bond0\u0027 not present on host \u0027139.178.85.203\u0027\"}","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"71beebb0d40c30c9c9964d937ce20c85f36d8aa4","unresolved":false,"context_lines":[{"line_number":29,"context_line":"IP.1 \u003d {{ kolla_internal_fqdn }}"},{"line_number":30,"context_line":"{% for host in hostvars %}"},{"line_number":31,"context_line":"{% if host not in ansible_play_hosts %}"},{"line_number":32,"context_line":"{% if \u0027ansible_host\u0027 in hostvars[host] %}"},{"line_number":33,"context_line":"IP.{{ loop.index + 1 }} \u003d {{hostvars[host][\u0027ansible_host\u0027]}}"},{"line_number":34,"context_line":"{% else %}"},{"line_number":35,"context_line":"IP.{{ loop.index + 1 }} \u003d {{ host }}"},{"line_number":36,"context_line":"{% endif %}"},{"line_number":37,"context_line":"{% endif %}"},{"line_number":38,"context_line":"{% endfor %}"},{"line_number":39,"context_line":"{% endif %}"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_0bd7ca4c","line":36,"range":{"start_line":32,"start_character":0,"end_line":36,"end_character":11},"in_reply_to":"df33271e_3c9ae312","updated":"2020-04-03 10:09:43.000000000","message":"We have a gather-facts.yml playbook which could be imported from the certificates.yml playbook. We might want to make that conditional on generating backend TLS certs.","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":30810,"name":"James Kirsch","email":"generalfuzz@gmail.com","username":"generalfuzz"},"change_message_id":"0b14619b20fa4994b550cb7e5d8c495e4b5629cf","unresolved":false,"context_lines":[{"line_number":29,"context_line":"IP.1 \u003d {{ kolla_internal_fqdn }}"},{"line_number":30,"context_line":"{% for host in hostvars %}"},{"line_number":31,"context_line":"{% if host not in ansible_play_hosts %}"},{"line_number":32,"context_line":"{% if \u0027ansible_host\u0027 in hostvars[host] %}"},{"line_number":33,"context_line":"IP.{{ loop.index + 1 }} \u003d {{hostvars[host][\u0027ansible_host\u0027]}}"},{"line_number":34,"context_line":"{% else %}"},{"line_number":35,"context_line":"IP.{{ loop.index + 1 }} \u003d {{ host }}"},{"line_number":36,"context_line":"{% endif %}"},{"line_number":37,"context_line":"{% endif %}"},{"line_number":38,"context_line":"{% endfor %}"},{"line_number":39,"context_line":"{% endif %}"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_3c9ae312","line":36,"range":{"start_line":32,"start_character":0,"end_line":36,"end_character":11},"in_reply_to":"df33271e_5d652ab4","updated":"2020-04-02 22:56:16.000000000","message":"Can you elaborate on how to perform this?","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d38e85f4492061fafe876e57fea3370e98b2a17","unresolved":false,"context_lines":[{"line_number":29,"context_line":"IP.1 \u003d {{ kolla_internal_fqdn }}"},{"line_number":30,"context_line":"{% for host in hostvars %}"},{"line_number":31,"context_line":"{% if host not in ansible_play_hosts %}"},{"line_number":32,"context_line":"{% if \u0027ansible_host\u0027 in hostvars[host] %}"},{"line_number":33,"context_line":"IP.{{ loop.index + 1 }} \u003d {{hostvars[host][\u0027ansible_host\u0027]}}"},{"line_number":34,"context_line":"{% else %}"},{"line_number":35,"context_line":"IP.{{ loop.index + 1 }} \u003d {{ host }}"},{"line_number":36,"context_line":"{% endif %}"},{"line_number":37,"context_line":"{% endif %}"},{"line_number":38,"context_line":"{% endfor %}"},{"line_number":39,"context_line":"{% endif %}"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_5d652ab4","line":36,"range":{"start_line":32,"start_character":0,"end_line":36,"end_character":11},"in_reply_to":"df33271e_7c87a2b6","updated":"2020-04-02 17:30:09.000000000","message":"We would need to gather facts in order to determine the IPs.","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":30810,"name":"James Kirsch","email":"generalfuzz@gmail.com","username":"generalfuzz"},"change_message_id":"d8ad55bde8c59528b077737c3a199372bc082730","unresolved":false,"context_lines":[{"line_number":29,"context_line":"IP.1 \u003d {{ kolla_internal_fqdn }}"},{"line_number":30,"context_line":"{% for host in hostvars %}"},{"line_number":31,"context_line":"{% if host not in ansible_play_hosts %}"},{"line_number":32,"context_line":"{% if \u0027ansible_host\u0027 in hostvars[host] %}"},{"line_number":33,"context_line":"IP.{{ loop.index + 1 }} \u003d {{hostvars[host][\u0027ansible_host\u0027]}}"},{"line_number":34,"context_line":"{% else %}"},{"line_number":35,"context_line":"IP.{{ loop.index + 1 }} \u003d {{ host }}"},{"line_number":36,"context_line":"{% endif %}"},{"line_number":37,"context_line":"{% endif %}"},{"line_number":38,"context_line":"{% endfor %}"},{"line_number":39,"context_line":"{% endif %}"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_7c87a2b6","line":36,"range":{"start_line":32,"start_character":0,"end_line":36,"end_character":11},"in_reply_to":"df33271e_cbd546e7","updated":"2020-03-31 05:29:07.000000000","message":"For some reason, this is failing locally with:\n\n\"FilterError: Interface \u0027bond0\u0027 not present on host \u0027139.178.85.203\u0027\n\nbond0 is definitely present on that host and the interface I use (ad this function works in other places)","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"}],"ansible/roles/certificates/templates/openssl-kolla.cnf.j2":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d38e85f4492061fafe876e57fea3370e98b2a17","unresolved":false,"context_lines":[{"line_number":16,"context_line":"[alt_names]"},{"line_number":17,"context_line":"{% if kolla_external_fqdn !\u003d kolla_external_vip_address %}"},{"line_number":18,"context_line":"DNS.1 \u003d {{ kolla_external_fqdn }}"},{"line_number":19,"context_line":"{% for host in hostvars %}"},{"line_number":20,"context_line":"{% if host not in ansible_play_hosts %}"},{"line_number":21,"context_line":"{% if \u0027ansible_host\u0027 in hostvars[host] %}"},{"line_number":22,"context_line":"DNS.{{ loop.index + 1 }} \u003d {{hostvars[host][\u0027ansible_host\u0027]}}"},{"line_number":23,"context_line":"{% else %}"},{"line_number":24,"context_line":"DNS.{{ loop.index + 1 }} \u003d {{ host }}"},{"line_number":25,"context_line":"{% endif %}"},{"line_number":26,"context_line":"{% endif %}"},{"line_number":27,"context_line":"{% endfor %}"},{"line_number":28,"context_line":"{% else %}"},{"line_number":29,"context_line":"IP.1 \u003d {{ kolla_external_fqdn }}"},{"line_number":30,"context_line":"{% for host in hostvars %}"},{"line_number":31,"context_line":"{% if host not in ansible_play_hosts %}"},{"line_number":32,"context_line":"{% if \u0027ansible_host\u0027 in hostvars[host] %}"},{"line_number":33,"context_line":"IP.{{ loop.index + 1 }} \u003d {{hostvars[host][\u0027ansible_host\u0027]}}"},{"line_number":34,"context_line":"{% else %}"},{"line_number":35,"context_line":"IP.{{ loop.index + 1 }} \u003d {{ host }}"},{"line_number":36,"context_line":"{% endif %}"},{"line_number":37,"context_line":"{% endif %}"},{"line_number":38,"context_line":"{% endfor %}"},{"line_number":39,"context_line":"{% endif %}"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_fdfa3eba","line":38,"range":{"start_line":19,"start_character":0,"end_line":38,"end_character":12},"updated":"2020-04-02 17:30:09.000000000","message":"If we had a separate certificate we wouldn\u0027t need this.","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"}],"ansible/roles/haproxy-config/templates/haproxy_single_service_listen.cfg.j2":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d93a0ad525a57d68f784e4f1657ebe26bee0dbb2","unresolved":false,"context_lines":[{"line_number":61,"context_line":"        {% else %}"},{"line_number":62,"context_line":"            {% set backend_tls_info \u003d \u0027\u0027 %}"},{"line_number":63,"context_line":"            {% if tls_backend|bool %}"},{"line_number":64,"context_line":"    option httpchk"},{"line_number":65,"context_line":"                {% set haproxy_health_check_final \u003d haproxy_health_check_ssl %}"},{"line_number":66,"context_line":"                {% if kolla_verify_backend_tls|bool %}"},{"line_number":67,"context_line":"                    {% set backend_tls_info \u003d \u0027ssl verify required ca-file %s\u0027|format(haproxy_backend_cacert) %}"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_2b1672a9","line":64,"range":{"start_line":64,"start_character":4,"end_line":64,"end_character":18},"updated":"2020-03-30 19:39:50.000000000","message":"Why are we only setting this for HTTPS? This would also be applied to a plain TLS (not HTTPS) connection, since we\u0027re not checking service_mode.","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":30810,"name":"James Kirsch","email":"generalfuzz@gmail.com","username":"generalfuzz"},"change_message_id":"d8ad55bde8c59528b077737c3a199372bc082730","unresolved":false,"context_lines":[{"line_number":61,"context_line":"        {% else %}"},{"line_number":62,"context_line":"            {% set backend_tls_info \u003d \u0027\u0027 %}"},{"line_number":63,"context_line":"            {% if tls_backend|bool %}"},{"line_number":64,"context_line":"    option httpchk"},{"line_number":65,"context_line":"                {% set haproxy_health_check_final \u003d haproxy_health_check_ssl %}"},{"line_number":66,"context_line":"                {% if kolla_verify_backend_tls|bool %}"},{"line_number":67,"context_line":"                    {% set backend_tls_info \u003d \u0027ssl verify required ca-file %s\u0027|format(haproxy_backend_cacert) %}"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_375a5529","line":64,"range":{"start_line":64,"start_character":4,"end_line":64,"end_character":18},"in_reply_to":"df33271e_2b1672a9","updated":"2020-03-31 05:29:07.000000000","message":"We only want to use https to verify HAProxy connections when the backend is TLS. This way connections to backend server will be properly terminated. \n\nAre you implying that this should be set in other other service modes as well?","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d38e85f4492061fafe876e57fea3370e98b2a17","unresolved":false,"context_lines":[{"line_number":61,"context_line":"        {% else %}"},{"line_number":62,"context_line":"            {% set backend_tls_info \u003d \u0027\u0027 %}"},{"line_number":63,"context_line":"            {% if tls_backend|bool %}"},{"line_number":64,"context_line":"    option httpchk"},{"line_number":65,"context_line":"                {% set haproxy_health_check_final \u003d haproxy_health_check_ssl %}"},{"line_number":66,"context_line":"                {% if kolla_verify_backend_tls|bool %}"},{"line_number":67,"context_line":"                    {% set backend_tls_info \u003d \u0027ssl verify required ca-file %s\u0027|format(haproxy_backend_cacert) %}"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_9d297238","line":64,"range":{"start_line":64,"start_character":4,"end_line":64,"end_character":18},"in_reply_to":"df33271e_375a5529","updated":"2020-04-02 17:30:09.000000000","message":"Based on https://cbonte.github.io/haproxy-dconv/1.8/configuration.html#4-option%20httpchk, this option converts the check/check-ssl TCP/TLS health check into an HTTP(s) health check. That seems like a fairly useful thing to do when service_mode is \u0027http\u0027, but here it could also be \u0027tcp\u0027 (see L54).\n\nI\u0027d say this should be a separate, explicit change.","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"}],"ansible/roles/haproxy-config/templates/haproxy_single_service_split.cfg.j2":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d93a0ad525a57d68f784e4f1657ebe26bee0dbb2","unresolved":false,"context_lines":[{"line_number":81,"context_line":"    {% else %}"},{"line_number":82,"context_line":"        {% set backend_tls_info \u003d \u0027\u0027 %}"},{"line_number":83,"context_line":"        {% if tls_backend|bool %}"},{"line_number":84,"context_line":"option httpchk"},{"line_number":85,"context_line":"            {% set haproxy_health_check_final \u003d haproxy_health_check_ssl %}"},{"line_number":86,"context_line":"            {% if kolla_verify_backend_tls|bool %}"},{"line_number":87,"context_line":"                {% set backend_tls_info \u003d \u0027ssl verify required ca-file %s\u0027|format(haproxy_backend_cacert) %}"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_a5e3e6d8","line":84,"updated":"2020-03-30 19:39:50.000000000","message":"indentation","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d38e85f4492061fafe876e57fea3370e98b2a17","unresolved":false,"context_lines":[{"line_number":81,"context_line":"    {% else %}"},{"line_number":82,"context_line":"        {% set backend_tls_info \u003d \u0027\u0027 %}"},{"line_number":83,"context_line":"        {% if tls_backend|bool %}"},{"line_number":84,"context_line":"option httpchk"},{"line_number":85,"context_line":"            {% set haproxy_health_check_final \u003d haproxy_health_check_ssl %}"},{"line_number":86,"context_line":"            {% if kolla_verify_backend_tls|bool %}"},{"line_number":87,"context_line":"                {% set backend_tls_info \u003d \u0027ssl verify required ca-file %s\u0027|format(haproxy_backend_cacert) %}"}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"df33271e_1dd442e8","line":84,"in_reply_to":"df33271e_a5e3e6d8","updated":"2020-04-02 17:30:09.000000000","message":"or remove from this change, based on other comments.","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"}],"ansible/roles/haproxy/tasks/config.yml":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"c89f069f5f6203b1fd5b1b089f46524400ab6ad5","unresolved":false,"context_lines":[{"line_number":145,"context_line":"- name: Copying over extra CA certificates"},{"line_number":146,"context_line":"  become: true"},{"line_number":147,"context_line":"  copy:"},{"line_number":148,"context_line":"    src: \"{{ node_config }}/certificates/ca/\""},{"line_number":149,"context_line":"    dest: \"{{ node_config_directory }}/{{ item.key }}/ca-certificates\""},{"line_number":150,"context_line":"    mode: \"0644\""},{"line_number":151,"context_line":"  when:"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"df33271e_10d069c9","line":148,"range":{"start_line":148,"start_character":13,"end_line":148,"end_character":40},"updated":"2020-04-06 13:54:47.000000000","message":"kolla_certificates_dir","commit_id":"f255026f82a53f4f45078f425f1cbbbbc8daa24a"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"c89f069f5f6203b1fd5b1b089f46524400ab6ad5","unresolved":false,"context_lines":[{"line_number":159,"context_line":"- name: Copying over backend certificate"},{"line_number":160,"context_line":"  become: true"},{"line_number":161,"context_line":"  copy:"},{"line_number":162,"context_line":"    src: \"{{ kolla_tls_backend_cert }}\""},{"line_number":163,"context_line":"    dest: \"{{ node_config_directory }}/{{ item.key }}/ca-certificates\""},{"line_number":164,"context_line":"    mode: \"0644\""},{"line_number":165,"context_line":"  when:"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"df33271e_105b4987","line":162,"range":{"start_line":162,"start_character":13,"end_line":162,"end_character":35},"updated":"2020-04-06 13:54:47.000000000","message":"It\u0027s a cert, not a CA cert. We\u0027ll need a different variable for the backend CA, or we could state that the backend CA should be included in the regular {{ certificates }}/ca/\" path and remove this task.","commit_id":"f255026f82a53f4f45078f425f1cbbbbc8daa24a"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"c89f069f5f6203b1fd5b1b089f46524400ab6ad5","unresolved":false,"context_lines":[{"line_number":167,"context_line":"    - kolla_enable_tls_backend | bool"},{"line_number":168,"context_line":"    - inventory_hostname in groups[item.value.group]"},{"line_number":169,"context_line":"    - kolla_copy_ca_into_containers | bool"},{"line_number":170,"context_line":"  with_dict: \"{{ haproxy_services }}\""},{"line_number":171,"context_line":"  notify:"},{"line_number":172,"context_line":"    - \"Restart {{ item.key }} container\""},{"line_number":173,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":12,"id":"df33271e_9020f9f9","line":170,"range":{"start_line":170,"start_character":2,"end_line":170,"end_character":37},"updated":"2020-04-06 13:54:47.000000000","message":"It\u0027s not required for keepalived, just haproxy.","commit_id":"f255026f82a53f4f45078f425f1cbbbbc8daa24a"},{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"a1312e14b955afa95968c2f8a0525ca9befa966c","unresolved":false,"context_lines":[{"line_number":149,"context_line":"    dest: \"{{ node_config_directory }}/haproxy/ca-certificates\""},{"line_number":150,"context_line":"    mode: \"0644\""},{"line_number":151,"context_line":"  when:"},{"line_number":152,"context_line":"    - inventory_hostname in groups[\"haproxy\"]"},{"line_number":153,"context_line":"    - kolla_copy_ca_into_containers | bool"},{"line_number":154,"context_line":"  notify:"},{"line_number":155,"context_line":"    - Restart haproxy container"}],"source_content_type":"text/x-yaml","patch_set":13,"id":"df33271e_c2aaa083","line":152,"range":{"start_line":152,"start_character":6,"end_line":152,"end_character":45},"updated":"2020-04-07 09:41:35.000000000","message":"can we not hardcode the group name? just do it like in earlier step.","commit_id":"16d2c722b83aaf0297b5795bdc07e1dd463a3d67"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"2cb21578ae9486cf6bec314c78cb9b33f2b7a1a7","unresolved":false,"context_lines":[{"line_number":144,"context_line":""},{"line_number":145,"context_line":"- name: Copying over extra CA certificates"},{"line_number":146,"context_line":"  vars:"},{"line_number":147,"context_line":"      service: \"{{ haproxy_services[\u0027haproxy\u0027] }}\""},{"line_number":148,"context_line":"  become: true"},{"line_number":149,"context_line":"  copy:"},{"line_number":150,"context_line":"    src: \"{{ kolla_certificates_dir }}/ca/\""}],"source_content_type":"text/x-yaml","patch_set":14,"id":"df33271e_caa733a7","line":147,"range":{"start_line":147,"start_character":6,"end_line":147,"end_character":13},"updated":"2020-04-08 10:03:22.000000000","message":"nit: indentation","commit_id":"b810fd5bb235f628c35bf5c22e96d32954e394c2"}],"ansible/roles/haproxy/templates/haproxy_main.cfg.j2":[{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"78bfdfd33dd045ca63e9107114e4a5c6a7fe9869","unresolved":false,"context_lines":[{"line_number":18,"context_line":"    ssl-default-bind-options no-sslv3 no-tlsv10 no-tlsv11"},{"line_number":19,"context_line":"    tune.ssl.default-dh-param 4096"},{"line_number":20,"context_line":"    {% endif %}"},{"line_number":21,"context_line":"    {% if kolla_enable_tls_internal | bool or kolla_enable_tls_external | bool %}"},{"line_number":22,"context_line":"    ca-base {{ haproxy_backend_cacert_dir }}"},{"line_number":23,"context_line":"    {% endif %}"},{"line_number":24,"context_line":""}],"source_content_type":"text/x-jinja2","patch_set":22,"id":"df33271e_54c39c89","line":21,"range":{"start_line":21,"start_character":10,"end_line":21,"end_character":78},"updated":"2020-04-09 16:36:27.000000000","message":"while I generally doubt one would run backend tls w/o any of these, I think this should depend on backend tls","commit_id":"b475643c112f49701db2fb3d1493987888c97c8a"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d2c7c1ce64e515aa5fac6d2c468bf77a618cfd97","unresolved":false,"context_lines":[{"line_number":18,"context_line":"    ssl-default-bind-options no-sslv3 no-tlsv10 no-tlsv11"},{"line_number":19,"context_line":"    tune.ssl.default-dh-param 4096"},{"line_number":20,"context_line":"    {% endif %}"},{"line_number":21,"context_line":"    {% if kolla_enable_tls_internal | bool or kolla_enable_tls_external | bool %}"},{"line_number":22,"context_line":"    ca-base {{ haproxy_backend_cacert_dir }}"},{"line_number":23,"context_line":"    {% endif %}"},{"line_number":24,"context_line":""}],"source_content_type":"text/x-jinja2","patch_set":22,"id":"df33271e_b48f88cb","line":21,"range":{"start_line":21,"start_character":10,"end_line":21,"end_character":78},"in_reply_to":"df33271e_54c39c89","updated":"2020-04-09 16:52:11.000000000","message":"Was going to comment similar, but you could disable backend TLS globally but enable per-service. Maybe safest to just add this unconditionally.","commit_id":"b475643c112f49701db2fb3d1493987888c97c8a"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"24b48b091b4bf2f8300682485de8f3b382c2b35b","unresolved":false,"context_lines":[{"line_number":18,"context_line":"    ssl-default-bind-options no-sslv3 no-tlsv10 no-tlsv11"},{"line_number":19,"context_line":"    tune.ssl.default-dh-param 4096"},{"line_number":20,"context_line":"    {% endif %}"},{"line_number":21,"context_line":"    {% if kolla_enable_tls_internal | bool or kolla_enable_tls_external | bool %}"},{"line_number":22,"context_line":"    ca-base {{ haproxy_backend_cacert_dir }}"},{"line_number":23,"context_line":"    {% endif %}"},{"line_number":24,"context_line":""}],"source_content_type":"text/x-jinja2","patch_set":22,"id":"df33271e_2b38329e","line":21,"range":{"start_line":21,"start_character":10,"end_line":21,"end_character":78},"in_reply_to":"df33271e_b48f88cb","updated":"2020-04-09 18:30:56.000000000","message":"Yeah, makes sense. This is only for base, should work.","commit_id":"b475643c112f49701db2fb3d1493987888c97c8a"}],"ansible/roles/keystone/defaults/main.yml":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d93a0ad525a57d68f784e4f1657ebe26bee0dbb2","unresolved":false,"context_lines":[{"line_number":148,"context_line":"####################"},{"line_number":149,"context_line":"# TLS"},{"line_number":150,"context_line":"####################"},{"line_number":151,"context_line":"keystone_tls_backend_enabled: \"{{ kolla_enable_tls_backend }}\""}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_65eefeb4","line":151,"range":{"start_line":151,"start_character":0,"end_line":151,"end_character":28},"updated":"2020-03-30 19:39:50.000000000","message":"nit: keystone_enable_tls_backend would be more consistent.","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"}],"ansible/roles/keystone/tasks/copy-certs.yml":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d93a0ad525a57d68f784e4f1657ebe26bee0dbb2","unresolved":false,"context_lines":[{"line_number":4,"context_line":"    role: service-cert-copy"},{"line_number":5,"context_line":"  vars:"},{"line_number":6,"context_line":"    project_services: \"{{ keystone_services }}\""},{"line_number":7,"context_line":"  notify:"},{"line_number":8,"context_line":"    - Restart {{ item.key }} container"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_45401aa6","line":8,"range":{"start_line":7,"start_character":0,"end_line":8,"end_character":38},"updated":"2020-03-30 19:39:50.000000000","message":"Would be better to do this inside the role. We might need to add a \u0027listen\u0027 attribute to the \u0027Restart keystone container\u0027 handler.","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":30810,"name":"James Kirsch","email":"generalfuzz@gmail.com","username":"generalfuzz"},"change_message_id":"d8ad55bde8c59528b077737c3a199372bc082730","unresolved":false,"context_lines":[{"line_number":4,"context_line":"    role: service-cert-copy"},{"line_number":5,"context_line":"  vars:"},{"line_number":6,"context_line":"    project_services: \"{{ keystone_services }}\""},{"line_number":7,"context_line":"  notify:"},{"line_number":8,"context_line":"    - Restart {{ item.key }} container"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_f2d91b57","line":8,"range":{"start_line":7,"start_character":0,"end_line":8,"end_character":38},"in_reply_to":"df33271e_45401aa6","updated":"2020-03-31 05:29:07.000000000","message":"I agree, however: \u0027notify\u0027 is not a valid attribute for a TaskInclude. Not sure how we can get around this.","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"71beebb0d40c30c9c9964d937ce20c85f36d8aa4","unresolved":false,"context_lines":[{"line_number":4,"context_line":"    role: service-cert-copy"},{"line_number":5,"context_line":"  vars:"},{"line_number":6,"context_line":"    project_services: \"{{ keystone_services }}\""},{"line_number":7,"context_line":"  notify:"},{"line_number":8,"context_line":"    - Restart {{ item.key }} container"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_4b10b200","line":8,"range":{"start_line":7,"start_character":0,"end_line":8,"end_character":38},"in_reply_to":"df33271e_53399aa1","updated":"2020-04-03 10:09:43.000000000","message":"I\u0027m not sure which include you\u0027re talking about, but all of the tasks in the service-cert-copy role are using the copy module. You\u0027ve also now add a notify to them all, so we just need to remove this one.","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":30810,"name":"James Kirsch","email":"generalfuzz@gmail.com","username":"generalfuzz"},"change_message_id":"0b14619b20fa4994b550cb7e5d8c495e4b5629cf","unresolved":false,"context_lines":[{"line_number":4,"context_line":"    role: service-cert-copy"},{"line_number":5,"context_line":"  vars:"},{"line_number":6,"context_line":"    project_services: \"{{ keystone_services }}\""},{"line_number":7,"context_line":"  notify:"},{"line_number":8,"context_line":"    - Restart {{ item.key }} container"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_53399aa1","line":8,"range":{"start_line":7,"start_character":0,"end_line":8,"end_character":38},"in_reply_to":"df33271e_bdfef667","updated":"2020-04-02 22:56:16.000000000","message":"Unfortunately, not to the include task.\n\nhttps://github.com/HadrienPatte/ansible-role-jellyfin/pull/4\nhttps://github.com/ansible/ansible/issues/26537\nhttps://github.com/ansible/ansible/issues/67084","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d38e85f4492061fafe876e57fea3370e98b2a17","unresolved":false,"context_lines":[{"line_number":4,"context_line":"    role: service-cert-copy"},{"line_number":5,"context_line":"  vars:"},{"line_number":6,"context_line":"    project_services: \"{{ keystone_services }}\""},{"line_number":7,"context_line":"  notify:"},{"line_number":8,"context_line":"    - Restart {{ item.key }} container"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_bdfef667","line":8,"range":{"start_line":7,"start_character":0,"end_line":8,"end_character":38},"in_reply_to":"df33271e_f2d91b57","updated":"2020-04-02 17:30:09.000000000","message":"You can add a notify to the individual tasks in the role. 2 of 3 already have it.","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"}],"ansible/roles/keystone/templates/wsgi-keystone.conf.j2":[{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"df566b41c9aa409bf8a203dd957596d1aee6b8a1","unresolved":false,"context_lines":[{"line_number":6,"context_line":"{% endif %}"},{"line_number":7,"context_line":"{% set binary_path \u003d \u0027/usr/bin\u0027 if keystone_install_type \u003d\u003d \u0027binary\u0027 else \u0027/var/lib/kolla/venv/bin\u0027 %}"},{"line_number":8,"context_line":"{% if keystone_enable_tls_backend | bool %}"},{"line_number":9,"context_line":"LoadModule ssl_module /usr/lib/apache2/modules/mod_ssl.so"},{"line_number":10,"context_line":"{% endif %}"},{"line_number":11,"context_line":"Listen {{ api_interface_address | put_address_in_context(\u0027url\u0027) }}:{{ keystone_public_listen_port }}"},{"line_number":12,"context_line":"Listen {{ api_interface_address | put_address_in_context(\u0027url\u0027) }}:{{ keystone_admin_listen_port }}"}],"source_content_type":"text/x-jinja2","patch_set":22,"id":"df33271e_7404e04a","line":9,"range":{"start_line":9,"start_character":22,"end_line":9,"end_character":57},"updated":"2020-04-09 16:49:36.000000000","message":"also, we are running on an edge case here; this would normally fail in centos (the path is different) but ssl_module is already enabled so it gets ignored","commit_id":"b475643c112f49701db2fb3d1493987888c97c8a"}],"ansible/roles/service-cert-copy/defaults/main.yml":[{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"e4d01c4cb5ae38cb4cbb8344b883e42c08087754","unresolved":false,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"config_directory: \"{{ project_name }}\""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"df33271e_4bb7dfd6","line":2,"range":{"start_line":2,"start_character":0,"end_line":2,"end_character":38},"updated":"2020-03-24 16:53:33.000000000","message":"why multiply vars, if you can just use project_name?","commit_id":"c3bc91d4314ac0f8ad81c7de14b55a88e36cea3e"},{"author":{"_account_id":30810,"name":"James Kirsch","email":"generalfuzz@gmail.com","username":"generalfuzz"},"change_message_id":"3a91d0cdffb54a008d0f45c543952a27136cd856","unresolved":false,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"config_directory: \"{{ project_name }}\""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"df33271e_14c338ef","line":2,"range":{"start_line":2,"start_character":0,"end_line":2,"end_character":38},"in_reply_to":"df33271e_4bb7dfd6","updated":"2020-03-24 22:21:41.000000000","message":"We will need to override this for certain services. Nova, for example needs to only use \"nova-api\" directory.","commit_id":"c3bc91d4314ac0f8ad81c7de14b55a88e36cea3e"}],"ansible/roles/service-cert-copy/tasks/main.yml":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d93a0ad525a57d68f784e4f1657ebe26bee0dbb2","unresolved":false,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"- name: Copying over extra CA certificates"},{"line_number":3,"context_line":"  become: true"},{"line_number":4,"context_line":"  copy:"},{"line_number":5,"context_line":"    src: \"{{ kolla_certificates_dir }}/ca/\""}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_eb9c8a6b","line":2,"updated":"2020-03-30 19:39:50.000000000","message":"{{ project_name }} | ...","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d93a0ad525a57d68f784e4f1657ebe26bee0dbb2","unresolved":false,"context_lines":[{"line_number":6,"context_line":"    dest: \"{{ node_config_directory }}/{{ item.key }}/ca-certificates\""},{"line_number":7,"context_line":"    mode: \"0644\""},{"line_number":8,"context_line":"  when:"},{"line_number":9,"context_line":"    - item.value.enabled | bool"},{"line_number":10,"context_line":"    - kolla_copy_ca_into_containers | bool"},{"line_number":11,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":12,"context_line":"  notify:"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_ab96024b","line":9,"range":{"start_line":9,"start_character":6,"end_line":9,"end_character":31},"updated":"2020-03-30 19:39:50.000000000","message":"This is covered by select_services_enabled_and_mapped_to_host","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d93a0ad525a57d68f784e4f1657ebe26bee0dbb2","unresolved":false,"context_lines":[{"line_number":18,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ inventory_hostname }}/{{ project_name }}.pem\""},{"line_number":19,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ inventory_hostname }}.pem\""},{"line_number":20,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ project_name }}.pem\""},{"line_number":21,"context_line":"      - \"{{ kolla_certificates_dir }}/ca/haproxy-internal.crt\""},{"line_number":22,"context_line":"      - \"{{ kolla_backend_internal_cert }}\""},{"line_number":23,"context_line":"    backend_tls_cert: \"{{ lookup(\u0027first_found\u0027, certs) }}\""},{"line_number":24,"context_line":"  copy:"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_2bc95225","line":21,"range":{"start_line":21,"start_character":6,"end_line":21,"end_character":62},"updated":"2020-03-30 19:39:50.000000000","message":"This is the cert for the VIP. Seems like these being the same is a testing corner case, which we could cover by setting kolla_backend_internal_cert.","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d93a0ad525a57d68f784e4f1657ebe26bee0dbb2","unresolved":false,"context_lines":[{"line_number":23,"context_line":"    backend_tls_cert: \"{{ lookup(\u0027first_found\u0027, certs) }}\""},{"line_number":24,"context_line":"  copy:"},{"line_number":25,"context_line":"    src: \"{{ backend_tls_cert }}\""},{"line_number":26,"context_line":"    dest: \"{{ node_config_directory }}/{{ config_directory }}/{{ project_name }}.pem\""},{"line_number":27,"context_line":"    mode: \"0644\""},{"line_number":28,"context_line":"    force: no"},{"line_number":29,"context_line":"  become: true"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_0b69ee1f","line":26,"range":{"start_line":26,"start_character":42,"end_line":26,"end_character":58},"updated":"2020-03-30 19:39:50.000000000","message":"Should be item.key","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":30810,"name":"James Kirsch","email":"generalfuzz@gmail.com","username":"generalfuzz"},"change_message_id":"d8ad55bde8c59528b077737c3a199372bc082730","unresolved":false,"context_lines":[{"line_number":23,"context_line":"    backend_tls_cert: \"{{ lookup(\u0027first_found\u0027, certs) }}\""},{"line_number":24,"context_line":"  copy:"},{"line_number":25,"context_line":"    src: \"{{ backend_tls_cert }}\""},{"line_number":26,"context_line":"    dest: \"{{ node_config_directory }}/{{ config_directory }}/{{ project_name }}.pem\""},{"line_number":27,"context_line":"    mode: \"0644\""},{"line_number":28,"context_line":"    force: no"},{"line_number":29,"context_line":"  become: true"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_501b9e7f","line":26,"range":{"start_line":26,"start_character":42,"end_line":26,"end_character":58},"in_reply_to":"df33271e_0b69ee1f","updated":"2020-03-31 05:29:07.000000000","message":"This is config_directory since it doesn\u0027t always match with service name. For example, nova-api uses backend, but directory on container is /etc/nova - not /etc/nova-api","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d38e85f4492061fafe876e57fea3370e98b2a17","unresolved":false,"context_lines":[{"line_number":23,"context_line":"    backend_tls_cert: \"{{ lookup(\u0027first_found\u0027, certs) }}\""},{"line_number":24,"context_line":"  copy:"},{"line_number":25,"context_line":"    src: \"{{ backend_tls_cert }}\""},{"line_number":26,"context_line":"    dest: \"{{ node_config_directory }}/{{ config_directory }}/{{ project_name }}.pem\""},{"line_number":27,"context_line":"    mode: \"0644\""},{"line_number":28,"context_line":"    force: no"},{"line_number":29,"context_line":"  become: true"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_ddf65a8f","line":26,"range":{"start_line":26,"start_character":42,"end_line":26,"end_character":58},"in_reply_to":"df33271e_501b9e7f","updated":"2020-04-02 17:30:09.000000000","message":"This is the configuration directory of the container on the host, not in the container e.g. /etc/kolla/nova-api/nova.pem","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d93a0ad525a57d68f784e4f1657ebe26bee0dbb2","unresolved":false,"context_lines":[{"line_number":25,"context_line":"    src: \"{{ backend_tls_cert }}\""},{"line_number":26,"context_line":"    dest: \"{{ node_config_directory }}/{{ config_directory }}/{{ project_name }}.pem\""},{"line_number":27,"context_line":"    mode: \"0644\""},{"line_number":28,"context_line":"    force: no"},{"line_number":29,"context_line":"  become: true"},{"line_number":30,"context_line":"  when:"},{"line_number":31,"context_line":"    - item.value.enabled | bool"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_4bd496bd","line":28,"range":{"start_line":28,"start_character":4,"end_line":28,"end_character":13},"updated":"2020-03-30 19:39:50.000000000","message":"This will prevent the file from being updated if it changes.","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d93a0ad525a57d68f784e4f1657ebe26bee0dbb2","unresolved":false,"context_lines":[{"line_number":28,"context_line":"    force: no"},{"line_number":29,"context_line":"  become: true"},{"line_number":30,"context_line":"  when:"},{"line_number":31,"context_line":"    - item.value.enabled | bool"},{"line_number":32,"context_line":"    - item.value.haproxy is defined"},{"line_number":33,"context_line":"    - kolla_enable_tls_backend | bool"},{"line_number":34,"context_line":"    - item.value.haproxy.values() | selectattr(\u0027tls_backend\u0027, \u0027defined\u0027) |  selectattr(\u0027tls_backend\u0027, \u0027equalto\u0027, true)"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_abd1e225","line":31,"range":{"start_line":31,"start_character":6,"end_line":31,"end_character":31},"updated":"2020-03-30 19:39:50.000000000","message":"This is covered by select_services_enabled_and_mapped_to_host","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d93a0ad525a57d68f784e4f1657ebe26bee0dbb2","unresolved":false,"context_lines":[{"line_number":30,"context_line":"  when:"},{"line_number":31,"context_line":"    - item.value.enabled | bool"},{"line_number":32,"context_line":"    - item.value.haproxy is defined"},{"line_number":33,"context_line":"    - kolla_enable_tls_backend | bool"},{"line_number":34,"context_line":"    - item.value.haproxy.values() | selectattr(\u0027tls_backend\u0027, \u0027defined\u0027) |  selectattr(\u0027tls_backend\u0027, \u0027equalto\u0027, true)"},{"line_number":35,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":36,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_0581f2c3","line":33,"range":{"start_line":33,"start_character":0,"end_line":33,"end_character":37},"updated":"2020-03-30 19:39:50.000000000","message":"Let\u0027s just use the haproxy.tls_backend flag.","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d93a0ad525a57d68f784e4f1657ebe26bee0dbb2","unresolved":false,"context_lines":[{"line_number":31,"context_line":"    - item.value.enabled | bool"},{"line_number":32,"context_line":"    - item.value.haproxy is defined"},{"line_number":33,"context_line":"    - kolla_enable_tls_backend | bool"},{"line_number":34,"context_line":"    - item.value.haproxy.values() | selectattr(\u0027tls_backend\u0027, \u0027defined\u0027) |  selectattr(\u0027tls_backend\u0027, \u0027equalto\u0027, true)"},{"line_number":35,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"- name: \"{{ project_name }} | Copying over backend internal TLS key\""}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_2ba312b4","line":34,"updated":"2020-03-30 19:39:50.000000000","message":"How about this:\n\nitem.value.haproxy.values() | selectattr(\u0027enabled\u0027, \u0027bool\u0027) | selectattr(\u0027tls_backend\u0027, \u0027defined\u0027) | selectattr(\u0027tls_backend\u0027, \u0027bool\u0027) | list | length \u003e 0","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":30810,"name":"James Kirsch","email":"generalfuzz@gmail.com","username":"generalfuzz"},"change_message_id":"d8ad55bde8c59528b077737c3a199372bc082730","unresolved":false,"context_lines":[{"line_number":31,"context_line":"    - item.value.enabled | bool"},{"line_number":32,"context_line":"    - item.value.haproxy is defined"},{"line_number":33,"context_line":"    - kolla_enable_tls_backend | bool"},{"line_number":34,"context_line":"    - item.value.haproxy.values() | selectattr(\u0027tls_backend\u0027, \u0027defined\u0027) |  selectattr(\u0027tls_backend\u0027, \u0027equalto\u0027, true)"},{"line_number":35,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"- name: \"{{ project_name }} | Copying over backend internal TLS key\""}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_50155e9b","line":34,"in_reply_to":"df33271e_2ba312b4","updated":"2020-03-31 05:29:07.000000000","message":"The conditional check \u0027item.value.haproxy.values() | selectattr(\u0027enabled\u0027, \u0027bool\u0027) | selectattr(\u0027tls_backend\u0027, \u0027defined\u0027) | selectattr(\u0027tls_backend\u0027, \u0027bool\u0027) | list | length \u003e 0\u0027 failed. \n\nThe error was: no test named \u0027bool\u0027","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d38e85f4492061fafe876e57fea3370e98b2a17","unresolved":false,"context_lines":[{"line_number":31,"context_line":"    - item.value.enabled | bool"},{"line_number":32,"context_line":"    - item.value.haproxy is defined"},{"line_number":33,"context_line":"    - kolla_enable_tls_backend | bool"},{"line_number":34,"context_line":"    - item.value.haproxy.values() | selectattr(\u0027tls_backend\u0027, \u0027defined\u0027) |  selectattr(\u0027tls_backend\u0027, \u0027equalto\u0027, true)"},{"line_number":35,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"- name: \"{{ project_name }} | Copying over backend internal TLS key\""}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_bd443675","line":34,"in_reply_to":"df33271e_50155e9b","updated":"2020-04-02 17:30:09.000000000","message":"That\u0027s annoying. It\u0027s because bool is a filter rather than a test. The problem is that we often use \u0027no\u0027 for false, but this evaluates as truthy unless you pass it through the bool filter.\n\nI think our options include building an incredibly complex filter chain, making a custom filter to munge the haproxy data, or making a custom jinja test that uses the bool filter.","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d93a0ad525a57d68f784e4f1657ebe26bee0dbb2","unresolved":false,"context_lines":[{"line_number":32,"context_line":"    - item.value.haproxy is defined"},{"line_number":33,"context_line":"    - kolla_enable_tls_backend | bool"},{"line_number":34,"context_line":"    - item.value.haproxy.values() | selectattr(\u0027tls_backend\u0027, \u0027defined\u0027) |  selectattr(\u0027tls_backend\u0027, \u0027equalto\u0027, true)"},{"line_number":35,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"- name: \"{{ project_name }} | Copying over backend internal TLS key\""},{"line_number":38,"context_line":"  vars:"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_c57a6aef","line":35,"updated":"2020-03-30 19:39:50.000000000","message":"notify:\n    - \"Restart {{ item.key }} container\"","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d93a0ad525a57d68f784e4f1657ebe26bee0dbb2","unresolved":false,"context_lines":[{"line_number":34,"context_line":"    - item.value.haproxy.values() | selectattr(\u0027tls_backend\u0027, \u0027defined\u0027) |  selectattr(\u0027tls_backend\u0027, \u0027equalto\u0027, true)"},{"line_number":35,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"- name: \"{{ project_name }} | Copying over backend internal TLS key\""},{"line_number":38,"context_line":"  vars:"},{"line_number":39,"context_line":"    keys:"},{"line_number":40,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ inventory_hostname }}/{{ project_name }}.key\""}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df33271e_6ba99a8e","line":37,"updated":"2020-03-30 19:39:50.000000000","message":"Same for this task","commit_id":"fe6aeb3a7332a3a315f1a75ba02453c3ede54be4"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"eb653bfcf67735663e814640ecac7ede44cb7ff6","unresolved":false,"context_lines":[{"line_number":26,"context_line":"  become: true"},{"line_number":27,"context_line":"  when:"},{"line_number":28,"context_line":"    - item.value.haproxy is defined"},{"line_number":29,"context_line":"    - item.value.haproxy.values() | selectattr(\u0027enabled\u0027, \u0027defined\u0027) |  selectattr(\u0027enabled\u0027, \u0027equalto\u0027, true)"},{"line_number":30,"context_line":"    - item.value.haproxy.values() | selectattr(\u0027tls_backend\u0027, \u0027defined\u0027) |  selectattr(\u0027tls_backend\u0027, \u0027equalto\u0027, true)"},{"line_number":31,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":32,"context_line":"  notify:"},{"line_number":33,"context_line":"    - \"Restart {{ item.key }} container\""}],"source_content_type":"text/x-yaml","patch_set":8,"id":"df33271e_18fc50b3","line":30,"range":{"start_line":29,"start_character":0,"end_line":30,"end_character":118},"updated":"2020-04-02 17:41:07.000000000","message":"If we assume that all backends will either be tls or none will, then this works. I think that\u0027s safe. Something like this might work to incorporate the bool filter:\n\n- item.value.haproxy.values() | selectattr(\u0027enabled\u0027, \u0027defined\u0027) | map(attribute\u003d\u0027enabled\u0027) | map(\u0027bool\u0027) | list | length \u003e 0\n- item.value.haproxy.values() | selectattr(\u0027tls_backend\u0027, \u0027defined\u0027) | map(attribute\u003d\u0027tls_backend\u0027) | map(\u0027bool\u0027) | list | length \u003e 0\n\nAlternatively we build some magic select_services_with_haproxy_tls_backend filter.","commit_id":"88ab722ce239977a1ab6670e0c761f6c2a19797f"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d56a323d34df8eba97a9cbc9c23ea80646ddfc3","unresolved":false,"context_lines":[{"line_number":26,"context_line":"  become: true"},{"line_number":27,"context_line":"  when:"},{"line_number":28,"context_line":"    - item.value.haproxy is defined"},{"line_number":29,"context_line":"    - item.value.haproxy.values() | selectattr(\u0027enabled\u0027, \u0027defined\u0027) | map(attribute\u003d\u0027enabled\u0027) | map(\u0027bool\u0027) | list | length \u003e 0"},{"line_number":30,"context_line":"    - item.value.haproxy.values() | selectattr(\u0027tls_backend\u0027, \u0027defined\u0027) | map(attribute\u003d\u0027tls_backend\u0027) | map(\u0027bool\u0027) | list | length \u003e 0"},{"line_number":31,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":32,"context_line":"  notify:"},{"line_number":33,"context_line":"    - \"Restart {{ item.key }} container\""}],"source_content_type":"text/x-yaml","patch_set":10,"id":"df33271e_0bf50a57","line":30,"range":{"start_line":29,"start_character":6,"end_line":30,"end_character":137},"updated":"2020-04-03 10:30:21.000000000","message":"I think I missed a bit. We need to filter out false values using select:\n\n- item.value.haproxy.values() | selectattr(\u0027enabled\u0027, \u0027defined\u0027) | map(attribute\u003d\u0027enabled\u0027) | map(\u0027bool\u0027) | select | list | length \u003e 0\n- item.value.haproxy.values() | selectattr(\u0027tls_backend\u0027, \u0027defined\u0027) | map(attribute\u003d\u0027tls_backend\u0027) | map(\u0027bool\u0027) | | select | list | length \u003e 0","commit_id":"4716d7a792e76397103bdcbd2ab7924506482112"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d56a323d34df8eba97a9cbc9c23ea80646ddfc3","unresolved":false,"context_lines":[{"line_number":48,"context_line":"  when:"},{"line_number":49,"context_line":"    - item.value.haproxy is defined"},{"line_number":50,"context_line":"    - item.value.haproxy.values() | selectattr(\u0027enabled\u0027, \u0027defined\u0027) | map(attribute\u003d\u0027enabled\u0027) | map(\u0027bool\u0027) | list | length \u003e 0"},{"line_number":51,"context_line":"    - item.value.haproxy.values() | selectattr(\u0027tls_backend\u0027, \u0027defined\u0027) | map(attribute\u003d\u0027tls_backend\u0027) | map(\u0027bool\u0027) | list | length \u003e 0"},{"line_number":52,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":53,"context_line":"  notify:"},{"line_number":54,"context_line":"    - \"Restart {{ item.key }} container\""}],"source_content_type":"text/x-yaml","patch_set":10,"id":"df33271e_6be8167b","line":51,"updated":"2020-04-03 10:30:21.000000000","message":"ditto","commit_id":"4716d7a792e76397103bdcbd2ab7924506482112"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"c89f069f5f6203b1fd5b1b089f46524400ab6ad5","unresolved":false,"context_lines":[{"line_number":32,"context_line":"  notify:"},{"line_number":33,"context_line":"    - \"Restart {{ item.key }} container\""},{"line_number":34,"context_line":""},{"line_number":35,"context_line":"- name: \"{{ project_name }} | Copying over backend internal TLS certificate for global container certificate file\""},{"line_number":36,"context_line":"  copy:"},{"line_number":37,"context_line":"    src: \"{{ kolla_tls_backend_cert }}\""},{"line_number":38,"context_line":"    dest: \"{{ node_config_directory }}/{{ item.key }}/ca-certificates\""},{"line_number":39,"context_line":"    mode: \"0644\""},{"line_number":40,"context_line":"  become: true"},{"line_number":41,"context_line":"  when:"},{"line_number":42,"context_line":"    - kolla_tls_backend_cert is defined"},{"line_number":43,"context_line":"    - item.value.haproxy is defined"},{"line_number":44,"context_line":"    - item.value.haproxy.values() | selectattr(\u0027enabled\u0027, \u0027defined\u0027) | map(attribute\u003d\u0027enabled\u0027) | map(\u0027bool\u0027) | select | list | length \u003e 0"},{"line_number":45,"context_line":"    - item.value.haproxy.values() | selectattr(\u0027tls_backend\u0027, \u0027defined\u0027) | map(attribute\u003d\u0027tls_backend\u0027) | map(\u0027bool\u0027) | select | list | length \u003e 0"},{"line_number":46,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":47,"context_line":"  notify:"},{"line_number":48,"context_line":"    - \"Restart {{ item.key }} container\""},{"line_number":49,"context_line":""},{"line_number":50,"context_line":"- name: \"{{ project_name }} | Copying over backend internal TLS key\""},{"line_number":51,"context_line":"  vars:"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"df33271e_d0044181","line":48,"range":{"start_line":35,"start_character":0,"end_line":48,"end_character":40},"updated":"2020-04-06 13:54:47.000000000","message":"I don\u0027t think this is right. The cert isn\u0027t necessarily a CA, unless it\u0027s self-signed. Why not drop the cert in the {{ certificates }}/ca/ directory when it\u0027s generated, then the first task in this file will copy it into place.","commit_id":"f255026f82a53f4f45078f425f1cbbbbc8daa24a"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"9edb51afad0f05f051d103a97ad00d31a32329ad","unresolved":false,"context_lines":[{"line_number":14,"context_line":"- name: \"{{ project_name }} | Copying over backend internal TLS certificate\""},{"line_number":15,"context_line":"  vars:"},{"line_number":16,"context_line":"    certs:"},{"line_number":17,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ inventory_hostname }}/{{ project_name }}.pem\""},{"line_number":18,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ inventory_hostname }}.pem\""},{"line_number":19,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ project_name }}.pem\""},{"line_number":20,"context_line":"      - \"{{ kolla_tls_backend_cert }}\""},{"line_number":21,"context_line":"    backend_tls_cert: \"{{ lookup(\u0027first_found\u0027, certs) }}\""},{"line_number":22,"context_line":"  copy:"},{"line_number":23,"context_line":"    src: \"{{ backend_tls_cert }}\""}],"source_content_type":"text/x-yaml","patch_set":13,"id":"df33271e_02976892","line":20,"range":{"start_line":17,"start_character":0,"end_line":20,"end_character":38},"updated":"2020-04-07 09:30:05.000000000","message":"I still find the mix of .pem and .crt a bit confusing. We have a default backend cert with .crt, but the project and host specific lookups use .pem, as is the destination. I think this will trip people up.\n\nIf there is a requirement for .crt for the CA cert, let\u0027s not let that influence the cert\u0027s extension. Ansible has a splitext filter if you need to rename the cert in the certificates role when copying the CA cert into place. Alternatively just set the name explicitly to backend.crt (or use a role variable).","commit_id":"16d2c722b83aaf0297b5795bdc07e1dd463a3d67"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"c5a00fa4c5e57a2fd57950263cf51c194468cc0f","unresolved":false,"context_lines":[{"line_number":34,"context_line":""},{"line_number":35,"context_line":"- name: \"{{ project_name }} | Copying over backend internal TLS key\""},{"line_number":36,"context_line":"  vars:"},{"line_number":37,"context_line":"    keys:"},{"line_number":38,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ inventory_hostname }}/{{ project_name }}.key\""},{"line_number":39,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ inventory_hostname }}.key\""},{"line_number":40,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ project_name }}.key\""},{"line_number":41,"context_line":"      - \"{{ kolla_tls_backend_key }}\""},{"line_number":42,"context_line":"    backend_tls_key: \"{{ lookup(\u0027first_found\u0027, keys) }}\""},{"line_number":43,"context_line":"  copy:"}],"source_content_type":"text/x-yaml","patch_set":17,"id":"df33271e_18ea0774","line":40,"range":{"start_line":37,"start_character":0,"end_line":40,"end_character":61},"updated":"2020-04-08 16:42:32.000000000","message":"These are still .key","commit_id":"f70630916e0c74af5add48101331af8c2a7506eb"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6e772926fb98d1c277a1fc0d4cedf3c280eb2042","unresolved":false,"context_lines":[{"line_number":37,"context_line":"    keys:"},{"line_number":38,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ inventory_hostname }}/{{ project_name }}.pem\""},{"line_number":39,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ inventory_hostname }}.pem\""},{"line_number":40,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ project_name }}.pem\""},{"line_number":41,"context_line":"      - \"{{ kolla_tls_backend_key }}\""},{"line_number":42,"context_line":"    backend_tls_key: \"{{ lookup(\u0027first_found\u0027, keys) }}\""},{"line_number":43,"context_line":"  copy:"}],"source_content_type":"text/x-yaml","patch_set":18,"id":"df33271e_8cda5814","line":40,"updated":"2020-04-08 17:06:00.000000000","message":"-key.pem","commit_id":"1d400bca11f19e52ad9eb75219de2bfbcf9faa6d"}],"doc/source/admin/advanced-configuration.rst":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"9edb51afad0f05f051d103a97ad00d31a32329ad","unresolved":false,"context_lines":[{"line_number":196,"context_line":"the cacert in the container. For example, if the self-signed certificate task"},{"line_number":197,"context_line":"was used and the deployment is on ubuntu, the path would be:"},{"line_number":198,"context_line":"\"/etc/pki/ca-trust/source/anchors/kolla-customca-haproxy-internal.crt\""},{"line_number":199,"context_line":""},{"line_number":200,"context_line":".. _service-config:"},{"line_number":201,"context_line":""},{"line_number":202,"context_line":"OpenStack Service Configuration in Kolla"}],"source_content_type":"text/x-rst","patch_set":13,"id":"df33271e_a2f5dcef","line":199,"updated":"2020-04-07 09:30:05.000000000","message":"We will need some documentation for this. It can be added separately.","commit_id":"16d2c722b83aaf0297b5795bdc07e1dd463a3d67"}],"releasenotes/notes/copy-certificate-authority-into-containers-860cbda3384dd731.yaml":[{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"e4d01c4cb5ae38cb4cbb8344b883e42c08087754","unresolved":false,"context_lines":[{"line_number":14,"context_line":"  - |"},{"line_number":15,"context_line":"    Python Requests library will not trust self-signed or privately signed CAs"},{"line_number":16,"context_line":"    even if they are added into the OS trusted CA folder and update-ca-trust is"},{"line_number":17,"context_line":"    executed. This is also true for the , regardless of Python version. For"},{"line_number":18,"context_line":"    services that rely on the Python Requests library, either CA verification"},{"line_number":19,"context_line":"    must be explicitly disabled in the service or the path to the CA"},{"line_number":20,"context_line":"    certificate must be configured using the ``openstack_cacert`` parameter."}],"source_content_type":"text/x-yaml","patch_set":4,"id":"df33271e_8bc8c755","line":17,"range":{"start_line":17,"start_character":14,"end_line":17,"end_character":70},"updated":"2020-03-24 16:53:33.000000000","message":"huh?","commit_id":"c3bc91d4314ac0f8ad81c7de14b55a88e36cea3e"}],"releasenotes/notes/encrypt-backend-haproxy-keystone-fb96285d74fb464c.yaml":[{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"78bfdfd33dd045ca63e9107114e4a5c6a7fe9869","unresolved":false,"context_lines":[{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    Added configuration options to enable backend TLS encryption from HAProxy"},{"line_number":5,"context_line":"    to the Keystone service. When used in conjunction with enabling TLS for"},{"line_number":6,"context_line":"    service API endpoints, network communcation will be encrypted end to end,"},{"line_number":7,"context_line":"    from client through HAProxy to the Keystone service."}],"source_content_type":"text/x-yaml","patch_set":22,"id":"df33271e_744b402a","line":6,"range":{"start_line":6,"start_character":35,"end_line":6,"end_character":47},"updated":"2020-04-09 16:36:27.000000000","message":"nit: communication","commit_id":"b475643c112f49701db2fb3d1493987888c97c8a"}],"tests/check-config.sh":[{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"78bfdfd33dd045ca63e9107114e4a5c6a7fe9869","unresolved":false,"context_lines":[{"line_number":16,"context_line":"    for f in $(sudo find /etc/kolla \\"},{"line_number":17,"context_line":"                -not -regex /etc/kolla/config.* \\"},{"line_number":18,"context_line":"                -not -regex /etc/kolla/certificates.* \\"},{"line_number":19,"context_line":"                -not -regex .*pem \\"},{"line_number":20,"context_line":"                -not -regex .*key \\"},{"line_number":21,"context_line":"                -not -regex \".*ca-certificates.*\" \\"},{"line_number":22,"context_line":"                -not -path /etc/kolla \\"}],"source_content_type":"text/x-sh","patch_set":22,"id":"df33271e_f460f0a7","line":19,"range":{"start_line":19,"start_character":28,"end_line":19,"end_character":33},"updated":"2020-04-09 16:36:27.000000000","message":"more like .*\\.pem","commit_id":"b475643c112f49701db2fb3d1493987888c97c8a"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"78bfdfd33dd045ca63e9107114e4a5c6a7fe9869","unresolved":false,"context_lines":[{"line_number":17,"context_line":"                -not -regex /etc/kolla/config.* \\"},{"line_number":18,"context_line":"                -not -regex /etc/kolla/certificates.* \\"},{"line_number":19,"context_line":"                -not -regex .*pem \\"},{"line_number":20,"context_line":"                -not -regex .*key \\"},{"line_number":21,"context_line":"                -not -regex \".*ca-certificates.*\" \\"},{"line_number":22,"context_line":"                -not -path /etc/kolla \\"},{"line_number":23,"context_line":"                -not -name admin-openrc.sh \\"}],"source_content_type":"text/x-sh","patch_set":22,"id":"df33271e_d465ecb6","line":20,"range":{"start_line":20,"start_character":28,"end_line":20,"end_character":33},"updated":"2020-04-09 16:36:27.000000000","message":"ditto","commit_id":"b475643c112f49701db2fb3d1493987888c97c8a"}],"tests/templates/globals-default.j2":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d56a323d34df8eba97a9cbc9c23ea80646ddfc3","unresolved":false,"context_lines":[{"line_number":119,"context_line":"kolla_enable_tls_internal: \"yes\""},{"line_number":120,"context_line":"kolla_copy_ca_into_containers: \"yes\""},{"line_number":121,"context_line":"kolla_enable_tls_backend: \"yes\""},{"line_number":122,"context_line":"kolla_tls_backend_key: \"/etc/kolla/certificates/private/backend/backend.key\""},{"line_number":123,"context_line":"{% if base_distro \u003d\u003d \"ubuntu\" or base_distro \u003d\u003d \"debian\" %}"},{"line_number":124,"context_line":"openstack_cacert: \"/usr/local/share/ca-certificates/kolla-customca-haproxy-internal.crt\""},{"line_number":125,"context_line":"{% endif %}"}],"source_content_type":"text/x-jinja2","patch_set":10,"id":"df33271e_ebfb8643","line":122,"range":{"start_line":122,"start_character":0,"end_line":122,"end_character":21},"updated":"2020-04-03 10:30:21.000000000","message":"The certificates role should probably copy this into place.","commit_id":"4716d7a792e76397103bdcbd2ab7924506482112"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"f74d27c17b72ffd5ec11431fc1b8acaa180bd4db","unresolved":false,"context_lines":[{"line_number":117,"context_line":"{% if tls_enabled %}"},{"line_number":118,"context_line":"kolla_enable_tls_external: \"yes\""},{"line_number":119,"context_line":"kolla_enable_tls_internal: \"yes\""},{"line_number":120,"context_line":"kolla_verify_internal_ca_certs: \"no\""},{"line_number":121,"context_line":"kolla_copy_ca_into_containers: \"yes\""},{"line_number":122,"context_line":"{% if base_distro \u003d\u003d \"ubuntu\" or base_distro \u003d\u003d \"debian\" %}"},{"line_number":123,"context_line":"openstack_cacert: \"/usr/local/share/ca-certificates/kolla-customca-haproxy-internal.crt\""}],"source_content_type":"text/x-jinja2","patch_set":14,"id":"df33271e_8a088b2d","side":"PARENT","line":120,"updated":"2020-04-08 10:10:06.000000000","message":"I\u0027m interested to know which part of this change allows us to remove this. Is it a bug fix that should be backported to Train?","commit_id":"9643dd54e26760d6249eed2ecb2712da28b05882"},{"author":{"_account_id":30810,"name":"James Kirsch","email":"generalfuzz@gmail.com","username":"generalfuzz"},"change_message_id":"31e47189bd279c44ae43ba64b5f1015b1592d2dd","unresolved":false,"context_lines":[{"line_number":117,"context_line":"{% if tls_enabled %}"},{"line_number":118,"context_line":"kolla_enable_tls_external: \"yes\""},{"line_number":119,"context_line":"kolla_enable_tls_internal: \"yes\""},{"line_number":120,"context_line":"kolla_verify_internal_ca_certs: \"no\""},{"line_number":121,"context_line":"kolla_copy_ca_into_containers: \"yes\""},{"line_number":122,"context_line":"{% if base_distro \u003d\u003d \"ubuntu\" or base_distro \u003d\u003d \"debian\" %}"},{"line_number":123,"context_line":"openstack_cacert: \"/usr/local/share/ca-certificates/kolla-customca-haproxy-internal.crt\""}],"source_content_type":"text/x-jinja2","patch_set":14,"id":"df33271e_06cf4eb0","side":"PARENT","line":120,"in_reply_to":"df33271e_8a088b2d","updated":"2020-04-08 16:25:42.000000000","message":"This parameter isn\u0027t used anywhere - accidentally went in with the CI test txn. Doesn\u0027t need a backport since the tls CI test is new to Ussuri","commit_id":"9643dd54e26760d6249eed2ecb2712da28b05882"}],"tests/templates/inventory.j2":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"6d56a323d34df8eba97a9cbc9c23ea80646ddfc3","unresolved":false,"context_lines":[{"line_number":48,"context_line":""},{"line_number":49,"context_line":"[tls-backend:children]"},{"line_number":50,"context_line":"control"},{"line_number":51,"context_line":"network"},{"line_number":52,"context_line":"compute"},{"line_number":53,"context_line":"storage"},{"line_number":54,"context_line":"monitoring"},{"line_number":55,"context_line":""},{"line_number":56,"context_line":"[baremetal:children]"}],"source_content_type":"text/x-jinja2","patch_set":10,"id":"df33271e_2b972eee","line":53,"range":{"start_line":51,"start_character":0,"end_line":53,"end_character":7},"updated":"2020-04-03 10:30:21.000000000","message":"As in multinode.","commit_id":"4716d7a792e76397103bdcbd2ab7924506482112"}]}
