)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"4ff2898a05cebc35c27ad450bab9092f47578ba5","unresolved":true,"context_lines":[{"line_number":4,"context_line":"Commit:     k-s-dean \u003ckyle@stackhpc.com\u003e"},{"line_number":5,"context_line":"CommitDate: 2022-06-30 14:41:34 +0100"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"added firewalld configuration based off enabled services"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"Change-Id: Iea3680142711873984efff2b701347b6a56dd355"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":17,"id":"69938625_13ab6ef8","line":7,"range":{"start_line":7,"start_character":0,"end_line":7,"end_character":5},"updated":"2022-06-30 13:47:31.000000000","message":"Use present tense, so \"Add ...\" instead.\n\nAlso a longer text describing the patch will be helpful once it is ready to be merged.","commit_id":"998116a64a7524285af1403357240059402e7e00"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"539c24b74e1b8ca22f5d907e7281a42896b7389e","unresolved":false,"context_lines":[{"line_number":4,"context_line":"Commit:     k-s-dean \u003ckyle@stackhpc.com\u003e"},{"line_number":5,"context_line":"CommitDate: 2022-06-30 14:41:34 +0100"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"added firewalld configuration based off enabled services"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"Change-Id: Iea3680142711873984efff2b701347b6a56dd355"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":17,"id":"acffe747_e127d4b0","line":7,"range":{"start_line":7,"start_character":0,"end_line":7,"end_character":5},"in_reply_to":"69938625_13ab6ef8","updated":"2022-07-17 16:46:38.000000000","message":"Done","commit_id":"998116a64a7524285af1403357240059402e7e00"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"585104886be07be996a8f86ac210dbb55eb19f07","unresolved":true,"context_lines":[{"line_number":4,"context_line":"Commit:     k-s-dean \u003ckyle@stackhpc.com\u003e"},{"line_number":5,"context_line":"CommitDate: 2022-07-22 14:50:43 +0100"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"adds firewalld configuration based off enable services"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"This change introduces automated configuration of firewalld and adds"},{"line_number":10,"context_line":"a new filter for extracting services from the project_services dict."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":30,"id":"c2d9837b_2a86a193","line":7,"range":{"start_line":7,"start_character":35,"end_line":7,"end_character":45},"updated":"2022-07-25 09:54:17.000000000","message":"on enabled","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"cdb2c54aba22b2e5aa66f21893faf759b3e11669","unresolved":false,"context_lines":[{"line_number":4,"context_line":"Commit:     k-s-dean \u003ckyle@stackhpc.com\u003e"},{"line_number":5,"context_line":"CommitDate: 2022-07-22 14:50:43 +0100"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"adds firewalld configuration based off enable services"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"This change introduces automated configuration of firewalld and adds"},{"line_number":10,"context_line":"a new filter for extracting services from the project_services dict."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":30,"id":"553f0ab9_ed3087b6","line":7,"range":{"start_line":7,"start_character":35,"end_line":7,"end_character":45},"in_reply_to":"c2d9837b_2a86a193","updated":"2022-07-26 17:29:44.000000000","message":"Done","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"585104886be07be996a8f86ac210dbb55eb19f07","unresolved":true,"context_lines":[{"line_number":10,"context_line":"a new filter for extracting services from the project_services dict."},{"line_number":11,"context_line":"the filter selects any enabled services and their haproxy element"},{"line_number":12,"context_line":"and returns them so they can be iterated over."},{"line_number":13,"context_line":"It also enables automated configuration of firewalld from enabled"},{"line_number":14,"context_line":"openstack services and adds them to the defined zone and reloads the"},{"line_number":15,"context_line":"system firewall."},{"line_number":16,"context_line":""}],"source_content_type":"text/x-gerrit-commit-message","patch_set":30,"id":"224ada09_1a7efa15","line":13,"range":{"start_line":13,"start_character":0,"end_line":13,"end_character":3},"updated":"2022-07-25 09:54:17.000000000","message":"It \u003d the filter. But I doubt a filter can do it.","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"cdb2c54aba22b2e5aa66f21893faf759b3e11669","unresolved":false,"context_lines":[{"line_number":10,"context_line":"a new filter for extracting services from the project_services dict."},{"line_number":11,"context_line":"the filter selects any enabled services and their haproxy element"},{"line_number":12,"context_line":"and returns them so they can be iterated over."},{"line_number":13,"context_line":"It also enables automated configuration of firewalld from enabled"},{"line_number":14,"context_line":"openstack services and adds them to the defined zone and reloads the"},{"line_number":15,"context_line":"system firewall."},{"line_number":16,"context_line":""}],"source_content_type":"text/x-gerrit-commit-message","patch_set":30,"id":"55cdaa66_774ce97f","line":13,"range":{"start_line":13,"start_character":0,"end_line":13,"end_character":3},"in_reply_to":"224ada09_1a7efa15","updated":"2022-07-26 17:29:44.000000000","message":"Done","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"585104886be07be996a8f86ac210dbb55eb19f07","unresolved":true,"context_lines":[{"line_number":14,"context_line":"openstack services and adds them to the defined zone and reloads the"},{"line_number":15,"context_line":"system firewall."},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"Change-Id: Iea3680142711873984efff2b701347b6a56dd355"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":30,"id":"ae422751_cbc683f2","line":17,"updated":"2022-07-25 09:54:17.000000000","message":"no blueprints for it? I don\u0027t remember any IRC discussion either. It is neither included in the cycle priorities.","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"d26df99d9a7a39cf085441c115fba2e616137204","unresolved":true,"context_lines":[{"line_number":14,"context_line":"openstack services and adds them to the defined zone and reloads the"},{"line_number":15,"context_line":"system firewall."},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"Change-Id: Iea3680142711873984efff2b701347b6a56dd355"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":30,"id":"65a7ecde_fc77404f","line":17,"in_reply_to":"4cb78caf_eaa98dce","updated":"2022-07-26 09:01:34.000000000","message":"I didn\u0027t mean the blueprint is mandatory, only that there is no other reference to the plan. ;-)","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"20980e92c8ed424bd61d50784433f63688daeee7","unresolved":true,"context_lines":[{"line_number":14,"context_line":"openstack services and adds them to the defined zone and reloads the"},{"line_number":15,"context_line":"system firewall."},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"Change-Id: Iea3680142711873984efff2b701347b6a56dd355"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":30,"id":"f856fe80_ccc3a621","line":17,"in_reply_to":"65a7ecde_fc77404f","updated":"2022-07-26 17:32:10.000000000","message":"This was initially meant to be a fairly small, change but has grown beyond what I originally expected.","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"0c9cde33aa0fa59e4b2da8ddc75c2047f07aafbf","unresolved":true,"context_lines":[{"line_number":14,"context_line":"openstack services and adds them to the defined zone and reloads the"},{"line_number":15,"context_line":"system firewall."},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"Change-Id: Iea3680142711873984efff2b701347b6a56dd355"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":30,"id":"4cb78caf_eaa98dce","line":17,"in_reply_to":"ae422751_cbc683f2","updated":"2022-07-26 08:26:17.000000000","message":"We dropped the use of blueprints some time ago.","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"860e47fba9b3e72961acd0b91be1fc1b0f463be9","unresolved":false,"context_lines":[{"line_number":14,"context_line":"openstack services and adds them to the defined zone and reloads the"},{"line_number":15,"context_line":"system firewall."},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"Change-Id: Iea3680142711873984efff2b701347b6a56dd355"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":30,"id":"69fc612a_01f12e64","line":17,"in_reply_to":"f856fe80_ccc3a621","updated":"2022-07-26 18:15:26.000000000","message":"No worries, I like the feature; just pointing out it is recommended to let others know about feature plans to wrap their heads around them beforehand. 😊","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"860e47fba9b3e72961acd0b91be1fc1b0f463be9","unresolved":true,"context_lines":[{"line_number":4,"context_line":"Commit:     k-s-dean \u003ckyle@stackhpc.com\u003e"},{"line_number":5,"context_line":"CommitDate: 2022-07-26 18:23:57 +0100"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"adds firewalld configuration based on enable services"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"This change introduces automated configuration of firewalld and adds"},{"line_number":10,"context_line":"a new filter for extracting services from the project_services dict."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":31,"id":"312784a6_58c00b88","line":7,"range":{"start_line":7,"start_character":38,"end_line":7,"end_character":45},"updated":"2022-07-26 18:15:26.000000000","message":"nit: enabled","commit_id":"0e5648d20eee9360ad4bd4e7feed01cc0af9c68d"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"92aa3b44148b1db7906e42da7625ee3173ebcb47","unresolved":false,"context_lines":[{"line_number":4,"context_line":"Commit:     k-s-dean \u003ckyle@stackhpc.com\u003e"},{"line_number":5,"context_line":"CommitDate: 2022-07-26 18:23:57 +0100"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"adds firewalld configuration based on enable services"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"This change introduces automated configuration of firewalld and adds"},{"line_number":10,"context_line":"a new filter for extracting services from the project_services dict."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":31,"id":"effcb9fe_867a64c1","line":7,"range":{"start_line":7,"start_character":38,"end_line":7,"end_character":45},"in_reply_to":"312784a6_58c00b88","updated":"2022-07-27 08:57:14.000000000","message":"Done","commit_id":"0e5648d20eee9360ad4bd4e7feed01cc0af9c68d"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"79e55797b2714e693bd05c0897747ba669571daa","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"b8121526_8c61bda9","updated":"2022-06-28 12:46:12.000000000","message":"Thanks","commit_id":"842693ad69a388777358ef37c964afb7bc9ba5c6"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"a8613392ff2f2bede3817fc519db074245bced6f","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":7,"id":"1698d15c_cf0354e3","updated":"2022-06-29 10:33:19.000000000","message":"Will need some docs, probably in doc/source/user/security.rst","commit_id":"e821f5c7812d5b3f49cee0c55152696730e0e325"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"539c24b74e1b8ca22f5d907e7281a42896b7389e","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"254d6715_b4484cc9","in_reply_to":"1698d15c_cf0354e3","updated":"2022-07-17 16:46:38.000000000","message":"Done","commit_id":"e821f5c7812d5b3f49cee0c55152696730e0e325"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"cce785d013fc93749a0ce4f7aa5fe3f348447c45","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":12,"id":"1f9acb3d_fe45b7d3","updated":"2022-06-30 09:58:45.000000000","message":"Could you add a precheck in the haproxy role, that checks that firewalld is running when enable_external_api_firewalld is true. You\u0027ll need to move that variable into group_vars/all.yml.","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"4ff2898a05cebc35c27ad450bab9092f47578ba5","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":17,"id":"c6ac77ba_9fdd4311","updated":"2022-06-30 13:47:31.000000000","message":"The centos8 jobs will always fail nowadays. Maybe you should stack this on top of the centos9 work instead.\n\nAlso please consider at least running the pep8 tests locally to reduce the number of iterations.","commit_id":"998116a64a7524285af1403357240059402e7e00"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"f521a2d9fed849da0742f81d732baf5793da7c79","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":27,"id":"1b3e0254_40644c93","updated":"2022-07-15 12:34:55.000000000","message":"Hi, could you please review this and if happy merge.\n\nKind regards, \n\nKyle","commit_id":"603e2360b7552f36db6a8bf8a0672cec4be3abb6"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"515b41f5d86ddd5f5edf2b8946f9ab041ae1894a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":27,"id":"be152ef7_53b8169d","updated":"2022-07-12 14:22:38.000000000","message":"Thanks Kyle.\n\nI gave this a basic test here: https://review.opendev.org/c/openstack/kolla-ansible/+/849467/\n\nWe can\u0027t really exercise the firewall when running on the same host, but the firewall was enabled, and the right tasks seemed to run, and the tests passed.","commit_id":"603e2360b7552f36db6a8bf8a0672cec4be3abb6"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"ea73ae28cf04940a5b61593c2fa7a6f596ae9545","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":27,"id":"bc7faa6e_3d5ba3b8","updated":"2022-07-16 14:57:34.000000000","message":"please resolve applied comments","commit_id":"603e2360b7552f36db6a8bf8a0672cec4be3abb6"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"3b4c6361eccea619f2e659f420f179db3c6e6b3f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":27,"id":"353bcbd9_e7a92770","in_reply_to":"bc7faa6e_3d5ba3b8","updated":"2022-07-17 16:48:28.000000000","message":"Ack","commit_id":"603e2360b7552f36db6a8bf8a0672cec4be3abb6"},{"author":{"_account_id":17669,"name":"Doug Szumski","email":"doug@stackhpc.com","username":"DougSzumski"},"change_message_id":"168a9455b7b1a593a9e081148d84fcaa55a9030c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":29,"id":"d787a95a_487f0373","updated":"2022-07-22 13:30:19.000000000","message":"Looks good to me, good job Kyle. Nits could be resolved in a follow up commit.","commit_id":"4cc41c430dd38d32ea4c55ab847cf929455f2513"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"990aece759a6b98f0915d820a5228cc6b1ce7954","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":34,"id":"c89fe077_39977dc6","updated":"2022-07-28 12:14:59.000000000","message":"(not w+1 because the master kolla-ansible CI is fried as of now)","commit_id":"8553e52acd79dc8457747def955a749eabf0cb96"}],"ansible/group_vars/all.yml":[{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"585104886be07be996a8f86ac210dbb55eb19f07","unresolved":true,"context_lines":[{"line_number":529,"context_line":"admin_protocol: \"{{ internal_protocol }}\""},{"line_number":530,"context_line":""},{"line_number":531,"context_line":"##################"},{"line_number":532,"context_line":"# Firewall options"},{"line_number":533,"context_line":"##################"},{"line_number":534,"context_line":"disable_firewall: \"true\""},{"line_number":535,"context_line":"enable_external_api_firewalld: \"{{ not disable_firewall | bool and ansible_facts.os_family \u003d\u003d \u0027RedHat\u0027 }}\""}],"source_content_type":"text/x-yaml","patch_set":30,"id":"6d3af2bc_f2f4b79c","line":532,"updated":"2022-07-25 09:54:17.000000000","message":"please duplicate these options in the globals.yml template (comments)","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"cdb2c54aba22b2e5aa66f21893faf759b3e11669","unresolved":false,"context_lines":[{"line_number":529,"context_line":"admin_protocol: \"{{ internal_protocol }}\""},{"line_number":530,"context_line":""},{"line_number":531,"context_line":"##################"},{"line_number":532,"context_line":"# Firewall options"},{"line_number":533,"context_line":"##################"},{"line_number":534,"context_line":"disable_firewall: \"true\""},{"line_number":535,"context_line":"enable_external_api_firewalld: \"{{ not disable_firewall | bool and ansible_facts.os_family \u003d\u003d \u0027RedHat\u0027 }}\""}],"source_content_type":"text/x-yaml","patch_set":30,"id":"f027d798_be1fa42e","line":532,"in_reply_to":"6d3af2bc_f2f4b79c","updated":"2022-07-26 17:29:44.000000000","message":"Done","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"585104886be07be996a8f86ac210dbb55eb19f07","unresolved":true,"context_lines":[{"line_number":532,"context_line":"# Firewall options"},{"line_number":533,"context_line":"##################"},{"line_number":534,"context_line":"disable_firewall: \"true\""},{"line_number":535,"context_line":"enable_external_api_firewalld: \"{{ not disable_firewall | bool and ansible_facts.os_family \u003d\u003d \u0027RedHat\u0027 }}\""},{"line_number":536,"context_line":"external_api_firewalld_zone: \"public\""},{"line_number":537,"context_line":""},{"line_number":538,"context_line":"####################"}],"source_content_type":"text/x-yaml","patch_set":30,"id":"9293ff68_1c667504","line":535,"range":{"start_line":535,"start_character":63,"end_line":535,"end_character":102},"updated":"2022-07-25 09:54:17.000000000","message":"I suggest not to base this default on the os family - unless we already plan to support the alternatives on other distros? AFAIK, firewalld works fine on Debian and Ubuntu.\n\nAlso, disable_firewall has already existed before and would now cause the firewall to be managed by Kolla Ansible unless the user has overridden enable_external_api_firewalld to false. Let\u0027s just default to false as it is a new feature that we offer but don\u0027t force it on the users. That said, we can agree in a future patch to switch it to on by default with an appropriate upgrade note.","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"d26df99d9a7a39cf085441c115fba2e616137204","unresolved":true,"context_lines":[{"line_number":532,"context_line":"# Firewall options"},{"line_number":533,"context_line":"##################"},{"line_number":534,"context_line":"disable_firewall: \"true\""},{"line_number":535,"context_line":"enable_external_api_firewalld: \"{{ not disable_firewall | bool and ansible_facts.os_family \u003d\u003d \u0027RedHat\u0027 }}\""},{"line_number":536,"context_line":"external_api_firewalld_zone: \"public\""},{"line_number":537,"context_line":""},{"line_number":538,"context_line":"####################"}],"source_content_type":"text/x-yaml","patch_set":30,"id":"4f58dcc1_90b10c1f","line":535,"range":{"start_line":535,"start_character":63,"end_line":535,"end_character":102},"in_reply_to":"35cf8bc4_3a97171d","updated":"2022-07-26 09:01:34.000000000","message":"Ack. Makes sense to me.","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"cdb2c54aba22b2e5aa66f21893faf759b3e11669","unresolved":false,"context_lines":[{"line_number":532,"context_line":"# Firewall options"},{"line_number":533,"context_line":"##################"},{"line_number":534,"context_line":"disable_firewall: \"true\""},{"line_number":535,"context_line":"enable_external_api_firewalld: \"{{ not disable_firewall | bool and ansible_facts.os_family \u003d\u003d \u0027RedHat\u0027 }}\""},{"line_number":536,"context_line":"external_api_firewalld_zone: \"public\""},{"line_number":537,"context_line":""},{"line_number":538,"context_line":"####################"}],"source_content_type":"text/x-yaml","patch_set":30,"id":"e78e2493_8f646764","line":535,"range":{"start_line":535,"start_character":63,"end_line":535,"end_character":102},"in_reply_to":"4f58dcc1_90b10c1f","updated":"2022-07-26 17:29:44.000000000","message":"Fixed, set it to false as requested.","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"0c9cde33aa0fa59e4b2da8ddc75c2047f07aafbf","unresolved":true,"context_lines":[{"line_number":532,"context_line":"# Firewall options"},{"line_number":533,"context_line":"##################"},{"line_number":534,"context_line":"disable_firewall: \"true\""},{"line_number":535,"context_line":"enable_external_api_firewalld: \"{{ not disable_firewall | bool and ansible_facts.os_family \u003d\u003d \u0027RedHat\u0027 }}\""},{"line_number":536,"context_line":"external_api_firewalld_zone: \"public\""},{"line_number":537,"context_line":""},{"line_number":538,"context_line":"####################"}],"source_content_type":"text/x-yaml","patch_set":30,"id":"35cf8bc4_3a97171d","line":535,"range":{"start_line":535,"start_character":63,"end_line":535,"end_character":102},"in_reply_to":"9293ff68_1c667504","updated":"2022-07-26 08:26:17.000000000","message":"Fine by me. We (StackHPC) are planning to use firewalld on Ubuntu also, but didn\u0027t want to assume, given it\u0027s not the default firewall there.","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"585104886be07be996a8f86ac210dbb55eb19f07","unresolved":true,"context_lines":[{"line_number":534,"context_line":"disable_firewall: \"true\""},{"line_number":535,"context_line":"enable_external_api_firewalld: \"{{ not disable_firewall | bool and ansible_facts.os_family \u003d\u003d \u0027RedHat\u0027 }}\""},{"line_number":536,"context_line":"external_api_firewalld_zone: \"public\""},{"line_number":537,"context_line":""},{"line_number":538,"context_line":"####################"},{"line_number":539,"context_line":"# OpenStack options"},{"line_number":540,"context_line":"####################"}],"source_content_type":"text/x-yaml","patch_set":30,"id":"fdcf5a92_c69386af","line":537,"updated":"2022-07-25 09:54:17.000000000","message":"btw, what about the internal API?","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"d26df99d9a7a39cf085441c115fba2e616137204","unresolved":false,"context_lines":[{"line_number":534,"context_line":"disable_firewall: \"true\""},{"line_number":535,"context_line":"enable_external_api_firewalld: \"{{ not disable_firewall | bool and ansible_facts.os_family \u003d\u003d \u0027RedHat\u0027 }}\""},{"line_number":536,"context_line":"external_api_firewalld_zone: \"public\""},{"line_number":537,"context_line":""},{"line_number":538,"context_line":"####################"},{"line_number":539,"context_line":"# OpenStack options"},{"line_number":540,"context_line":"####################"}],"source_content_type":"text/x-yaml","patch_set":30,"id":"2325eb6a_93acf0d3","line":537,"in_reply_to":"df78c327_78b3a9ae","updated":"2022-07-26 09:01:34.000000000","message":"I imagined, nice that you have thought about it.","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"0c9cde33aa0fa59e4b2da8ddc75c2047f07aafbf","unresolved":true,"context_lines":[{"line_number":534,"context_line":"disable_firewall: \"true\""},{"line_number":535,"context_line":"enable_external_api_firewalld: \"{{ not disable_firewall | bool and ansible_facts.os_family \u003d\u003d \u0027RedHat\u0027 }}\""},{"line_number":536,"context_line":"external_api_firewalld_zone: \"public\""},{"line_number":537,"context_line":""},{"line_number":538,"context_line":"####################"},{"line_number":539,"context_line":"# OpenStack options"},{"line_number":540,"context_line":"####################"}],"source_content_type":"text/x-yaml","patch_set":30,"id":"df78c327_78b3a9ae","line":537,"in_reply_to":"fdcf5a92_c69386af","updated":"2022-07-26 08:26:17.000000000","message":"This is much harder to do, since you need to open up the backends also (assuming colocated load balancers \u0026 controllers). It could be done one day, but baby steps.","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"860e47fba9b3e72961acd0b91be1fc1b0f463be9","unresolved":true,"context_lines":[{"line_number":531,"context_line":"##################"},{"line_number":532,"context_line":"# Firewall options"},{"line_number":533,"context_line":"##################"},{"line_number":534,"context_line":"disable_firewall: \"true\""},{"line_number":535,"context_line":"enable_external_api_firewalld: \"false\""},{"line_number":536,"context_line":"external_api_firewalld_zone: \"public\""},{"line_number":537,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":31,"id":"5b3bef4b_e89fc9d2","line":534,"updated":"2022-07-26 18:15:26.000000000","message":"this is no longer used now (as I wanted but now need to remove)","commit_id":"0e5648d20eee9360ad4bd4e7feed01cc0af9c68d"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"e8024c4f937a03e591b3e48ad1d04245f2e643eb","unresolved":false,"context_lines":[{"line_number":531,"context_line":"##################"},{"line_number":532,"context_line":"# Firewall options"},{"line_number":533,"context_line":"##################"},{"line_number":534,"context_line":"disable_firewall: \"true\""},{"line_number":535,"context_line":"enable_external_api_firewalld: \"false\""},{"line_number":536,"context_line":"external_api_firewalld_zone: \"public\""},{"line_number":537,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":31,"id":"f93a464f_df456401","line":534,"in_reply_to":"5b3bef4b_e89fc9d2","updated":"2022-07-27 08:54:18.000000000","message":"Done","commit_id":"0e5648d20eee9360ad4bd4e7feed01cc0af9c68d"}],"ansible/roles/haproxy-config/defaults/main.yml":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"a8613392ff2f2bede3817fc519db074245bced6f","unresolved":true,"context_lines":[{"line_number":17,"context_line":""},{"line_number":18,"context_line":"enable_external_api_firewalld: \"{{ not disable_firewall | bool and ansible_facts.os_family \u003d\u003d \"RedHat\" }}\""},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"external_api_firewalld_zone: \"trusted\""}],"source_content_type":"text/x-yaml","patch_set":7,"id":"c6d120f8_ac82c9be","line":20,"range":{"start_line":20,"start_character":30,"end_line":20,"end_character":37},"updated":"2022-06-29 10:33:19.000000000","message":"public probably makes more sense as a default - trusted allows all traffic.","commit_id":"e821f5c7812d5b3f49cee0c55152696730e0e325"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"2b184be54b18eba2ffe962f060e90f6177802296","unresolved":false,"context_lines":[{"line_number":17,"context_line":""},{"line_number":18,"context_line":"enable_external_api_firewalld: \"{{ not disable_firewall | bool and ansible_facts.os_family \u003d\u003d \"RedHat\" }}\""},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"external_api_firewalld_zone: \"trusted\""}],"source_content_type":"text/x-yaml","patch_set":7,"id":"07511219_3eda97f1","line":20,"range":{"start_line":20,"start_character":30,"end_line":20,"end_character":37},"in_reply_to":"c6d120f8_ac82c9be","updated":"2022-06-29 16:49:01.000000000","message":"Done","commit_id":"e821f5c7812d5b3f49cee0c55152696730e0e325"}],"ansible/roles/haproxy-config/handlers/main.yml":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"cce785d013fc93749a0ce4f7aa5fe3f348447c45","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"- name: Restart firewalld"},{"line_number":3,"context_line":"  become: True"},{"line_number":4,"context_line":"  service:"},{"line_number":5,"context_line":"    name: \"firewalld\""}],"source_content_type":"text/x-yaml","patch_set":12,"id":"b9c422c5_cd865df4","line":2,"range":{"start_line":2,"start_character":8,"end_line":2,"end_character":15},"updated":"2022-06-30 09:58:45.000000000","message":"nit: Reload","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"82b93aa43e1a351111a12a8e9369fd704f48f71b","unresolved":false,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"- name: Restart firewalld"},{"line_number":3,"context_line":"  become: True"},{"line_number":4,"context_line":"  service:"},{"line_number":5,"context_line":"    name: \"firewalld\""}],"source_content_type":"text/x-yaml","patch_set":12,"id":"b297f6d7_7b491b91","line":2,"range":{"start_line":2,"start_character":8,"end_line":2,"end_character":15},"in_reply_to":"b9c422c5_cd865df4","updated":"2022-06-30 12:31:42.000000000","message":"Done","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"}],"ansible/roles/haproxy-config/tasks/main.yml":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"79e55797b2714e693bd05c0897747ba669571daa","unresolved":true,"context_lines":[{"line_number":26,"context_line":"  firewalld:"},{"line_number":27,"context_line":"    offline: \"yes\""},{"line_number":28,"context_line":"    permanent: \"yes\""},{"line_number":29,"context_line":"    immediate: \"yes\""},{"line_number":30,"context_line":"    port: \"{{ item.value.port }}/tcp\""},{"line_number":31,"context_line":"    state: \"enabled\""},{"line_number":32,"context_line":"    zone: \"public\""}],"source_content_type":"text/x-yaml","patch_set":3,"id":"63a7ce62_8e59c789","line":29,"range":{"start_line":29,"start_character":16,"end_line":29,"end_character":19},"updated":"2022-06-28 12:46:12.000000000","message":"In Kayobe we default to false for immediate. Would it be more efficient to apply changes with immediate\u003dno, then restart firewalld in a handler?","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"206b6bbafc0e49e593e31c1de9f271a1739869be","unresolved":true,"context_lines":[{"line_number":26,"context_line":"  firewalld:"},{"line_number":27,"context_line":"    offline: \"yes\""},{"line_number":28,"context_line":"    permanent: \"yes\""},{"line_number":29,"context_line":"    immediate: \"yes\""},{"line_number":30,"context_line":"    port: \"{{ item.value.port }}/tcp\""},{"line_number":31,"context_line":"    state: \"enabled\""},{"line_number":32,"context_line":"    zone: \"public\""}],"source_content_type":"text/x-yaml","patch_set":3,"id":"e45f3835_df3af652","line":29,"range":{"start_line":29,"start_character":16,"end_line":29,"end_character":19},"in_reply_to":"63a7ce62_8e59c789","updated":"2022-06-29 08:44:54.000000000","message":"Are you suggesting adding a handler to haproxy-config role or somewhere else. I think it make sense to do it immediately. Otherwise we could have generated the config for firewalld and done the reload all at once.","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"2b184be54b18eba2ffe962f060e90f6177802296","unresolved":false,"context_lines":[{"line_number":26,"context_line":"  firewalld:"},{"line_number":27,"context_line":"    offline: \"yes\""},{"line_number":28,"context_line":"    permanent: \"yes\""},{"line_number":29,"context_line":"    immediate: \"yes\""},{"line_number":30,"context_line":"    port: \"{{ item.value.port }}/tcp\""},{"line_number":31,"context_line":"    state: \"enabled\""},{"line_number":32,"context_line":"    zone: \"public\""}],"source_content_type":"text/x-yaml","patch_set":3,"id":"ee3c8779_4da322c8","line":29,"range":{"start_line":29,"start_character":16,"end_line":29,"end_character":19},"in_reply_to":"a1915265_7d3a8a37","updated":"2022-06-29 16:49:01.000000000","message":"Added a handler","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"565ff8d96509ec040ec744e396085cbe8d577bb1","unresolved":true,"context_lines":[{"line_number":26,"context_line":"  firewalld:"},{"line_number":27,"context_line":"    offline: \"yes\""},{"line_number":28,"context_line":"    permanent: \"yes\""},{"line_number":29,"context_line":"    immediate: \"yes\""},{"line_number":30,"context_line":"    port: \"{{ item.value.port }}/tcp\""},{"line_number":31,"context_line":"    state: \"enabled\""},{"line_number":32,"context_line":"    zone: \"public\""}],"source_content_type":"text/x-yaml","patch_set":3,"id":"a1915265_7d3a8a37","line":29,"range":{"start_line":29,"start_character":16,"end_line":29,"end_character":19},"in_reply_to":"e45f3835_df3af652","updated":"2022-06-29 10:25:24.000000000","message":"We can\u0027t generate the config all at once, since the required context is contained within each role.\n\nThe handler could be in the haproxy-config role for now.","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"79e55797b2714e693bd05c0897747ba669571daa","unresolved":true,"context_lines":[{"line_number":29,"context_line":"    immediate: \"yes\""},{"line_number":30,"context_line":"    port: \"{{ item.value.port }}/tcp\""},{"line_number":31,"context_line":"    state: \"enabled\""},{"line_number":32,"context_line":"    zone: \"public\""},{"line_number":33,"context_line":"  become: true"},{"line_number":34,"context_line":"  when:"},{"line_number":35,"context_line":"    - item.value.port is defined"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"d6a12270_5c7573f0","line":32,"range":{"start_line":32,"start_character":11,"end_line":32,"end_character":17},"updated":"2022-06-28 12:46:12.000000000","message":"Zone should be configurable","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"6a2067c61591e32121695a0cf5cc5a1a3e6378f7","unresolved":false,"context_lines":[{"line_number":29,"context_line":"    immediate: \"yes\""},{"line_number":30,"context_line":"    port: \"{{ item.value.port }}/tcp\""},{"line_number":31,"context_line":"    state: \"enabled\""},{"line_number":32,"context_line":"    zone: \"public\""},{"line_number":33,"context_line":"  become: true"},{"line_number":34,"context_line":"  when:"},{"line_number":35,"context_line":"    - item.value.port is defined"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"b9d9e8ef_41a4d75f","line":32,"range":{"start_line":32,"start_character":11,"end_line":32,"end_character":17},"in_reply_to":"d6a12270_5c7573f0","updated":"2022-06-29 08:52:04.000000000","message":"Done","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"79e55797b2714e693bd05c0897747ba669571daa","unresolved":true,"context_lines":[{"line_number":31,"context_line":"    state: \"enabled\""},{"line_number":32,"context_line":"    zone: \"public\""},{"line_number":33,"context_line":"  become: true"},{"line_number":34,"context_line":"  when:"},{"line_number":35,"context_line":"    - item.value.port is defined"},{"line_number":36,"context_line":"    - item.value.external | default(\u0027false\u0027) | bool"},{"line_number":37,"context_line":"    - item.value.external is defined"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"7290375c_aae0de55","line":34,"updated":"2022-06-28 12:46:12.000000000","message":"Need to filter out disabled haproxy services. Can be done here or in the extract_services filter. If here,\n\n - item.value.enabled | bool","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"6a2067c61591e32121695a0cf5cc5a1a3e6378f7","unresolved":false,"context_lines":[{"line_number":31,"context_line":"    state: \"enabled\""},{"line_number":32,"context_line":"    zone: \"public\""},{"line_number":33,"context_line":"  become: true"},{"line_number":34,"context_line":"  when:"},{"line_number":35,"context_line":"    - item.value.port is defined"},{"line_number":36,"context_line":"    - item.value.external | default(\u0027false\u0027) | bool"},{"line_number":37,"context_line":"    - item.value.external is defined"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"2c5ef930_5309ecdf","line":34,"in_reply_to":"7290375c_aae0de55","updated":"2022-06-29 08:52:04.000000000","message":"done in filter","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"79e55797b2714e693bd05c0897747ba669571daa","unresolved":true,"context_lines":[{"line_number":34,"context_line":"  when:"},{"line_number":35,"context_line":"    - item.value.port is defined"},{"line_number":36,"context_line":"    - item.value.external | default(\u0027false\u0027) | bool"},{"line_number":37,"context_line":"    - item.value.external is defined"},{"line_number":38,"context_line":"    - enable_external_api_firewalld | bool"},{"line_number":39,"context_line":"  with_dict: \"{{ project_services | extract_services }}\""}],"source_content_type":"text/x-yaml","patch_set":3,"id":"7e2c4e3a_3c89b2f2","line":37,"range":{"start_line":37,"start_character":4,"end_line":37,"end_character":36},"updated":"2022-06-28 12:46:12.000000000","message":"This is covered by the condition above","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"6a2067c61591e32121695a0cf5cc5a1a3e6378f7","unresolved":false,"context_lines":[{"line_number":34,"context_line":"  when:"},{"line_number":35,"context_line":"    - item.value.port is defined"},{"line_number":36,"context_line":"    - item.value.external | default(\u0027false\u0027) | bool"},{"line_number":37,"context_line":"    - item.value.external is defined"},{"line_number":38,"context_line":"    - enable_external_api_firewalld | bool"},{"line_number":39,"context_line":"  with_dict: \"{{ project_services | extract_services }}\""}],"source_content_type":"text/x-yaml","patch_set":3,"id":"73d5b106_02a61eb2","line":37,"range":{"start_line":37,"start_character":4,"end_line":37,"end_character":36},"in_reply_to":"7e2c4e3a_3c89b2f2","updated":"2022-06-29 08:52:04.000000000","message":"Done","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"79e55797b2714e693bd05c0897747ba669571daa","unresolved":true,"context_lines":[{"line_number":35,"context_line":"    - item.value.port is defined"},{"line_number":36,"context_line":"    - item.value.external | default(\u0027false\u0027) | bool"},{"line_number":37,"context_line":"    - item.value.external is defined"},{"line_number":38,"context_line":"    - enable_external_api_firewalld | bool"},{"line_number":39,"context_line":"  with_dict: \"{{ project_services | extract_services }}\""}],"source_content_type":"text/x-yaml","patch_set":3,"id":"c279fecd_9c23d7a6","line":38,"updated":"2022-06-28 12:46:12.000000000","message":"Need to add:\n\n - enable_haproxy | bool","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"6a2067c61591e32121695a0cf5cc5a1a3e6378f7","unresolved":false,"context_lines":[{"line_number":35,"context_line":"    - item.value.port is defined"},{"line_number":36,"context_line":"    - item.value.external | default(\u0027false\u0027) | bool"},{"line_number":37,"context_line":"    - item.value.external is defined"},{"line_number":38,"context_line":"    - enable_external_api_firewalld | bool"},{"line_number":39,"context_line":"  with_dict: \"{{ project_services | extract_services }}\""}],"source_content_type":"text/x-yaml","patch_set":3,"id":"d4a17df6_c1d8e48a","line":38,"in_reply_to":"c279fecd_9c23d7a6","updated":"2022-06-29 08:52:04.000000000","message":"Done","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"79e55797b2714e693bd05c0897747ba669571daa","unresolved":true,"context_lines":[{"line_number":36,"context_line":"    - item.value.external | default(\u0027false\u0027) | bool"},{"line_number":37,"context_line":"    - item.value.external is defined"},{"line_number":38,"context_line":"    - enable_external_api_firewalld | bool"},{"line_number":39,"context_line":"  with_dict: \"{{ project_services | extract_services }}\""}],"source_content_type":"text/x-yaml","patch_set":3,"id":"9aac1051_d40b52ec","line":39,"updated":"2022-06-28 12:46:12.000000000","message":"Need to filter out disabled services. Could be done with chained filters, or added to extract_services.\n\n with_dict: \"{{ project_services | select_services_enabled | extract_services }}\"","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"6a2067c61591e32121695a0cf5cc5a1a3e6378f7","unresolved":false,"context_lines":[{"line_number":36,"context_line":"    - item.value.external | default(\u0027false\u0027) | bool"},{"line_number":37,"context_line":"    - item.value.external is defined"},{"line_number":38,"context_line":"    - enable_external_api_firewalld | bool"},{"line_number":39,"context_line":"  with_dict: \"{{ project_services | extract_services }}\""}],"source_content_type":"text/x-yaml","patch_set":3,"id":"fc073bdb_c700c111","line":39,"in_reply_to":"9aac1051_d40b52ec","updated":"2022-06-29 08:52:04.000000000","message":"Done","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d496e064717c3eeb51ab805844c495d1e38f350b","unresolved":true,"context_lines":[{"line_number":37,"context_line":"    - item.value.port is defined"},{"line_number":38,"context_line":"    - item.value.external | default(\u0027false\u0027) | bool"},{"line_number":39,"context_line":"    - enable_external_api_firewalld | bool"},{"line_number":40,"context_line":"  with_dict: \"{{ project_services | select_services_enabled | extract_haproxy_services }}\""}],"source_content_type":"text/x-yaml","patch_set":6,"id":"92b62b2e_3d7a0087","line":40,"range":{"start_line":40,"start_character":36,"end_line":40,"end_character":59},"updated":"2022-06-29 08:16:37.000000000","message":"filter doesn\u0027t exist yet","commit_id":"267ab2b740e0638d3bbab88a9e6ec8b4dea61676"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"2b184be54b18eba2ffe962f060e90f6177802296","unresolved":false,"context_lines":[{"line_number":37,"context_line":"    - item.value.port is defined"},{"line_number":38,"context_line":"    - item.value.external | default(\u0027false\u0027) | bool"},{"line_number":39,"context_line":"    - enable_external_api_firewalld | bool"},{"line_number":40,"context_line":"  with_dict: \"{{ project_services | select_services_enabled | extract_haproxy_services }}\""}],"source_content_type":"text/x-yaml","patch_set":6,"id":"f86e60e9_89a4482d","line":40,"range":{"start_line":40,"start_character":36,"end_line":40,"end_character":59},"in_reply_to":"92b62b2e_3d7a0087","updated":"2022-06-29 16:49:01.000000000","message":"Moved the check to extract_haproxy_services filter","commit_id":"267ab2b740e0638d3bbab88a9e6ec8b4dea61676"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"a8613392ff2f2bede3817fc519db074245bced6f","unresolved":true,"context_lines":[{"line_number":32,"context_line":"    zone: \"{{ external_api_firewalld_zone }}\""},{"line_number":33,"context_line":"  become: true"},{"line_number":34,"context_line":"  when:"},{"line_number":35,"context_line":"    - service.enabled | bool"},{"line_number":36,"context_line":"    - enable_haproxy | bool"},{"line_number":37,"context_line":"    - item.value.port is defined"},{"line_number":38,"context_line":"    - item.value.external | default(\u0027false\u0027) | bool"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"fdb3b36e_02bfb384","line":35,"range":{"start_line":35,"start_character":6,"end_line":35,"end_character":13},"updated":"2022-06-29 10:33:19.000000000","message":"service not defined","commit_id":"e821f5c7812d5b3f49cee0c55152696730e0e325"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"2b184be54b18eba2ffe962f060e90f6177802296","unresolved":false,"context_lines":[{"line_number":32,"context_line":"    zone: \"{{ external_api_firewalld_zone }}\""},{"line_number":33,"context_line":"  become: true"},{"line_number":34,"context_line":"  when:"},{"line_number":35,"context_line":"    - service.enabled | bool"},{"line_number":36,"context_line":"    - enable_haproxy | bool"},{"line_number":37,"context_line":"    - item.value.port is defined"},{"line_number":38,"context_line":"    - item.value.external | default(\u0027false\u0027) | bool"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"de7fc7ef_2c12e65d","line":35,"range":{"start_line":35,"start_character":6,"end_line":35,"end_character":13},"in_reply_to":"fdb3b36e_02bfb384","updated":"2022-06-29 16:49:01.000000000","message":"Done","commit_id":"e821f5c7812d5b3f49cee0c55152696730e0e325"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"98646ca64d07c523bd7aefcdae683593ea28da73","unresolved":true,"context_lines":[{"line_number":38,"context_line":"    - enable_external_api_firewalld | bool"},{"line_number":39,"context_line":"  with_dict: \"{{ project_services | extract_haproxy_services }}\""},{"line_number":40,"context_line":"  notify:"},{"line_number":41,"context_line":"    - \"Restart firewalld\""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"dc1ae88b_c4de239c","line":41,"range":{"start_line":41,"start_character":7,"end_line":41,"end_character":14},"updated":"2022-07-12 08:36:06.000000000","message":"Reload","commit_id":"c9247a81e657eef1a2416171889881b98a980878"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"539c24b74e1b8ca22f5d907e7281a42896b7389e","unresolved":false,"context_lines":[{"line_number":38,"context_line":"    - enable_external_api_firewalld | bool"},{"line_number":39,"context_line":"  with_dict: \"{{ project_services | extract_haproxy_services }}\""},{"line_number":40,"context_line":"  notify:"},{"line_number":41,"context_line":"    - \"Restart firewalld\""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"9e460046_96eaa312","line":41,"range":{"start_line":41,"start_character":7,"end_line":41,"end_character":14},"in_reply_to":"dc1ae88b_c4de239c","updated":"2022-07-17 16:46:38.000000000","message":"Done","commit_id":"c9247a81e657eef1a2416171889881b98a980878"}],"ansible/roles/loadbalancer/tasks/precheck.yml":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"7bf9d4a57182070de716452bef0d88a321877020","unresolved":true,"context_lines":[{"line_number":845,"context_line":"    cmd: \"systemctl is-active firewalld\""},{"line_number":846,"context_line":"  register: firewalld_is_active"},{"line_number":847,"context_line":"  changed_when: false"},{"line_number":848,"context_line":"  failed_when: false"},{"line_number":849,"context_line":""},{"line_number":850,"context_line":"- name: Fail if firewalld is not running"},{"line_number":851,"context_line":"  fail:"}],"source_content_type":"text/x-yaml","patch_set":21,"id":"0259c015_56d4944c","line":848,"updated":"2022-07-07 09:54:20.000000000","message":"when:\n  - enable_external_api_firewalld | bool","commit_id":"4c1bd848fa270ae4256c1cb07df8854f3ebc57e5"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"160d79eeea9559051f557a6ae70ebfdbb5d7749b","unresolved":true,"context_lines":[{"line_number":845,"context_line":"    cmd: \"systemctl is-active firewalld\""},{"line_number":846,"context_line":"  register: firewalld_is_active"},{"line_number":847,"context_line":"  changed_when: false"},{"line_number":848,"context_line":"  failed_when: false"},{"line_number":849,"context_line":""},{"line_number":850,"context_line":"- name: Fail if firewalld is not running"},{"line_number":851,"context_line":"  fail:"}],"source_content_type":"text/x-yaml","patch_set":21,"id":"5909b02f_85bc6f84","line":848,"in_reply_to":"0259c015_56d4944c","updated":"2022-07-07 13:50:34.000000000","message":"Causes the next task to fail....","commit_id":"4c1bd848fa270ae4256c1cb07df8854f3ebc57e5"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"539c24b74e1b8ca22f5d907e7281a42896b7389e","unresolved":false,"context_lines":[{"line_number":845,"context_line":"    cmd: \"systemctl is-active firewalld\""},{"line_number":846,"context_line":"  register: firewalld_is_active"},{"line_number":847,"context_line":"  changed_when: false"},{"line_number":848,"context_line":"  failed_when: false"},{"line_number":849,"context_line":""},{"line_number":850,"context_line":"- name: Fail if firewalld is not running"},{"line_number":851,"context_line":"  fail:"}],"source_content_type":"text/x-yaml","patch_set":21,"id":"49c86d60_a3881cb0","line":848,"in_reply_to":"5909b02f_85bc6f84","updated":"2022-07-17 16:46:38.000000000","message":"Done","commit_id":"4c1bd848fa270ae4256c1cb07df8854f3ebc57e5"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"7bf9d4a57182070de716452bef0d88a321877020","unresolved":true,"context_lines":[{"line_number":855,"context_line":"  when:"},{"line_number":856,"context_line":"    - firewalld_is_active.rc !\u003d 0"},{"line_number":857,"context_line":"    - enable_external_api_firewalld | bool"},{"line_number":858,"context_line":"    - not disable_firewall | bool"}],"source_content_type":"text/x-yaml","patch_set":21,"id":"7ab95649_e04347ab","line":858,"range":{"start_line":858,"start_character":0,"end_line":858,"end_character":33},"updated":"2022-07-07 09:54:20.000000000","message":"Don\u0027t need to include this one.","commit_id":"4c1bd848fa270ae4256c1cb07df8854f3ebc57e5"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"539c24b74e1b8ca22f5d907e7281a42896b7389e","unresolved":false,"context_lines":[{"line_number":855,"context_line":"  when:"},{"line_number":856,"context_line":"    - firewalld_is_active.rc !\u003d 0"},{"line_number":857,"context_line":"    - enable_external_api_firewalld | bool"},{"line_number":858,"context_line":"    - not disable_firewall | bool"}],"source_content_type":"text/x-yaml","patch_set":21,"id":"8bc29032_7d29b4ee","line":858,"range":{"start_line":858,"start_character":0,"end_line":858,"end_character":33},"in_reply_to":"7ab95649_e04347ab","updated":"2022-07-17 16:46:38.000000000","message":"Done","commit_id":"4c1bd848fa270ae4256c1cb07df8854f3ebc57e5"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"585104886be07be996a8f86ac210dbb55eb19f07","unresolved":true,"context_lines":[{"line_number":856,"context_line":"      Please install and configure firewalld."},{"line_number":857,"context_line":"  when:"},{"line_number":858,"context_line":"    - enable_external_api_firewalld | bool"},{"line_number":859,"context_line":"    - firewalld_is_active.rc !\u003d 0"}],"source_content_type":"text/x-yaml","patch_set":30,"id":"79630c9b_881e6c8f","line":859,"updated":"2022-07-25 09:54:17.000000000","message":"the two tasks could be in a block with \"enable_external_api_firewalld | bool\" condition","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"cdb2c54aba22b2e5aa66f21893faf759b3e11669","unresolved":false,"context_lines":[{"line_number":856,"context_line":"      Please install and configure firewalld."},{"line_number":857,"context_line":"  when:"},{"line_number":858,"context_line":"    - enable_external_api_firewalld | bool"},{"line_number":859,"context_line":"    - firewalld_is_active.rc !\u003d 0"}],"source_content_type":"text/x-yaml","patch_set":30,"id":"32afd2ee_107c09b8","line":859,"in_reply_to":"79630c9b_881e6c8f","updated":"2022-07-26 17:29:44.000000000","message":"Done","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"860e47fba9b3e72961acd0b91be1fc1b0f463be9","unresolved":true,"context_lines":[{"line_number":857,"context_line":"      when:"},{"line_number":858,"context_line":"        - firewalld_is_active.rc !\u003d 0"},{"line_number":859,"context_line":"  when:"},{"line_number":860,"context_line":"    - enable_external_api_firewalld | bool"}],"source_content_type":"text/x-yaml","patch_set":31,"id":"e31da134_73e7cbcf","line":860,"updated":"2022-07-26 18:15:26.000000000","message":"please have a newline at the end of the file","commit_id":"0e5648d20eee9360ad4bd4e7feed01cc0af9c68d"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"e8024c4f937a03e591b3e48ad1d04245f2e643eb","unresolved":false,"context_lines":[{"line_number":857,"context_line":"      when:"},{"line_number":858,"context_line":"        - firewalld_is_active.rc !\u003d 0"},{"line_number":859,"context_line":"  when:"},{"line_number":860,"context_line":"    - enable_external_api_firewalld | bool"}],"source_content_type":"text/x-yaml","patch_set":31,"id":"835f60ed_f90c88f6","line":860,"in_reply_to":"e31da134_73e7cbcf","updated":"2022-07-27 08:54:18.000000000","message":"Done","commit_id":"0e5648d20eee9360ad4bd4e7feed01cc0af9c68d"}],"doc/source/reference/deployment-and-bootstrapping/bootstrap-servers.rst":[{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"860e47fba9b3e72961acd0b91be1fc1b0f463be9","unresolved":true,"context_lines":[{"line_number":208,"context_line":"On Red Hat family systems firewalld should be installed by default."},{"line_number":209,"context_line":""},{"line_number":210,"context_line":"To enable configuration of the system firewall set ``disable_firewall``"},{"line_number":211,"context_line":"to ``false``."},{"line_number":212,"context_line":""},{"line_number":213,"context_line":"For further information. See :doc:`../../user/security`"},{"line_number":214,"context_line":""}],"source_content_type":"text/x-rst","patch_set":31,"id":"ab4377f1_4ef68e6b","line":211,"updated":"2022-07-26 18:15:26.000000000","message":"and set something more now as well...","commit_id":"0e5648d20eee9360ad4bd4e7feed01cc0af9c68d"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"e8024c4f937a03e591b3e48ad1d04245f2e643eb","unresolved":false,"context_lines":[{"line_number":208,"context_line":"On Red Hat family systems firewalld should be installed by default."},{"line_number":209,"context_line":""},{"line_number":210,"context_line":"To enable configuration of the system firewall set ``disable_firewall``"},{"line_number":211,"context_line":"to ``false``."},{"line_number":212,"context_line":""},{"line_number":213,"context_line":"For further information. See :doc:`../../user/security`"},{"line_number":214,"context_line":""}],"source_content_type":"text/x-rst","patch_set":31,"id":"4b8abf64_122c847f","line":211,"in_reply_to":"ab4377f1_4ef68e6b","updated":"2022-07-27 08:54:18.000000000","message":"Done","commit_id":"0e5648d20eee9360ad4bd4e7feed01cc0af9c68d"}],"doc/source/user/security.rst":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"cce785d013fc93749a0ce4f7aa5fe3f348447c45","unresolved":true,"context_lines":[{"line_number":79,"context_line":""},{"line_number":80,"context_line":"FirewallD"},{"line_number":81,"context_line":"~~~~~~~~~"},{"line_number":82,"context_line":""},{"line_number":83,"context_line":"Prior to Zed Support kolla would disable any system Firewall leaving"},{"line_number":84,"context_line":"configuration up to the end users. Firewalld is now supported and will configure"},{"line_number":85,"context_line":"ports for each enabled openstack service. Before enabling automatic configuration"}],"source_content_type":"text/x-rst","patch_set":12,"id":"8297e7c7_51eaf489","line":82,"updated":"2022-06-30 09:58:45.000000000","message":"Needs to mention relevant variables, and what values they should take to enable firewall config, ideally with an example:\n\n* disable_firewall\n* enable_external_api_firewalld\n* external_api_firewalld_zone","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"539c24b74e1b8ca22f5d907e7281a42896b7389e","unresolved":false,"context_lines":[{"line_number":79,"context_line":""},{"line_number":80,"context_line":"FirewallD"},{"line_number":81,"context_line":"~~~~~~~~~"},{"line_number":82,"context_line":""},{"line_number":83,"context_line":"Prior to Zed Support kolla would disable any system Firewall leaving"},{"line_number":84,"context_line":"configuration up to the end users. Firewalld is now supported and will configure"},{"line_number":85,"context_line":"ports for each enabled openstack service. Before enabling automatic configuration"}],"source_content_type":"text/x-rst","patch_set":12,"id":"ec54e95b_a6680344","line":82,"in_reply_to":"8297e7c7_51eaf489","updated":"2022-07-17 16:46:38.000000000","message":"Done","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"cce785d013fc93749a0ce4f7aa5fe3f348447c45","unresolved":true,"context_lines":[{"line_number":82,"context_line":""},{"line_number":83,"context_line":"Prior to Zed Support kolla would disable any system Firewall leaving"},{"line_number":84,"context_line":"configuration up to the end users. Firewalld is now supported and will configure"},{"line_number":85,"context_line":"ports for each enabled openstack service. Before enabling automatic configuration"},{"line_number":86,"context_line":"of firewalld, you should ensure that firewalld has proper access rules for ssh"},{"line_number":87,"context_line":"this can be achieved by running"},{"line_number":88,"context_line":"``sudo firewall-cmd --permanent --zone\u003dpublic  --add-service\u003dssh``"}],"source_content_type":"text/x-rst","patch_set":12,"id":"4588123e_e85985d3","line":85,"range":{"start_line":85,"start_character":42,"end_line":85,"end_character":48},"updated":"2022-06-30 09:58:45.000000000","message":"This part should be a separate paragraph, possibly with a heading of Prerequisites","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"cce785d013fc93749a0ce4f7aa5fe3f348447c45","unresolved":true,"context_lines":[{"line_number":82,"context_line":""},{"line_number":83,"context_line":"Prior to Zed Support kolla would disable any system Firewall leaving"},{"line_number":84,"context_line":"configuration up to the end users. Firewalld is now supported and will configure"},{"line_number":85,"context_line":"ports for each enabled openstack service. Before enabling automatic configuration"},{"line_number":86,"context_line":"of firewalld, you should ensure that firewalld has proper access rules for ssh"},{"line_number":87,"context_line":"this can be achieved by running"},{"line_number":88,"context_line":"``sudo firewall-cmd --permanent --zone\u003dpublic  --add-service\u003dssh``"}],"source_content_type":"text/x-rst","patch_set":12,"id":"b38ebe1e_f51c6cd2","line":85,"range":{"start_line":85,"start_character":0,"end_line":85,"end_character":5},"updated":"2022-06-30 09:58:45.000000000","message":"external API ports","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"539c24b74e1b8ca22f5d907e7281a42896b7389e","unresolved":false,"context_lines":[{"line_number":82,"context_line":""},{"line_number":83,"context_line":"Prior to Zed Support kolla would disable any system Firewall leaving"},{"line_number":84,"context_line":"configuration up to the end users. Firewalld is now supported and will configure"},{"line_number":85,"context_line":"ports for each enabled openstack service. Before enabling automatic configuration"},{"line_number":86,"context_line":"of firewalld, you should ensure that firewalld has proper access rules for ssh"},{"line_number":87,"context_line":"this can be achieved by running"},{"line_number":88,"context_line":"``sudo firewall-cmd --permanent --zone\u003dpublic  --add-service\u003dssh``"}],"source_content_type":"text/x-rst","patch_set":12,"id":"b50b7a0a_c197ad89","line":85,"range":{"start_line":85,"start_character":42,"end_line":85,"end_character":48},"in_reply_to":"4588123e_e85985d3","updated":"2022-07-17 16:46:38.000000000","message":"Done","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"539c24b74e1b8ca22f5d907e7281a42896b7389e","unresolved":false,"context_lines":[{"line_number":82,"context_line":""},{"line_number":83,"context_line":"Prior to Zed Support kolla would disable any system Firewall leaving"},{"line_number":84,"context_line":"configuration up to the end users. Firewalld is now supported and will configure"},{"line_number":85,"context_line":"ports for each enabled openstack service. Before enabling automatic configuration"},{"line_number":86,"context_line":"of firewalld, you should ensure that firewalld has proper access rules for ssh"},{"line_number":87,"context_line":"this can be achieved by running"},{"line_number":88,"context_line":"``sudo firewall-cmd --permanent --zone\u003dpublic  --add-service\u003dssh``"}],"source_content_type":"text/x-rst","patch_set":12,"id":"65f22f92_89e50aed","line":85,"range":{"start_line":85,"start_character":0,"end_line":85,"end_character":5},"in_reply_to":"b38ebe1e_f51c6cd2","updated":"2022-07-17 16:46:38.000000000","message":"Done","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"cce785d013fc93749a0ce4f7aa5fe3f348447c45","unresolved":true,"context_lines":[{"line_number":85,"context_line":"ports for each enabled openstack service. Before enabling automatic configuration"},{"line_number":86,"context_line":"of firewalld, you should ensure that firewalld has proper access rules for ssh"},{"line_number":87,"context_line":"this can be achieved by running"},{"line_number":88,"context_line":"``sudo firewall-cmd --permanent --zone\u003dpublic  --add-service\u003dssh``"},{"line_number":89,"context_line":"to ensure that lock out does not occur. Additionally any other ports that need"},{"line_number":90,"context_line":"to be opened on the system should be added before hand."},{"line_number":91,"context_line":"This can be achieved by running"}],"source_content_type":"text/x-rst","patch_set":12,"id":"21797ad1_46170c3c","line":88,"range":{"start_line":88,"start_character":0,"end_line":88,"end_character":66},"updated":"2022-06-30 09:58:45.000000000","message":"We probably don\u0027t want SSH on the public zone.","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"539c24b74e1b8ca22f5d907e7281a42896b7389e","unresolved":false,"context_lines":[{"line_number":85,"context_line":"ports for each enabled openstack service. Before enabling automatic configuration"},{"line_number":86,"context_line":"of firewalld, you should ensure that firewalld has proper access rules for ssh"},{"line_number":87,"context_line":"this can be achieved by running"},{"line_number":88,"context_line":"``sudo firewall-cmd --permanent --zone\u003dpublic  --add-service\u003dssh``"},{"line_number":89,"context_line":"to ensure that lock out does not occur. Additionally any other ports that need"},{"line_number":90,"context_line":"to be opened on the system should be added before hand."},{"line_number":91,"context_line":"This can be achieved by running"}],"source_content_type":"text/x-rst","patch_set":12,"id":"ae1dbaaf_c9c2a08a","line":88,"range":{"start_line":88,"start_character":0,"end_line":88,"end_character":66},"in_reply_to":"21797ad1_46170c3c","updated":"2022-07-17 16:46:38.000000000","message":"Done","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"cce785d013fc93749a0ce4f7aa5fe3f348447c45","unresolved":true,"context_lines":[{"line_number":92,"context_line":"``firewall-cmd --zone\u003dpublic --add-port\u003d8080/tcp --permanent``"},{"line_number":93,"context_line":"Dpendant on your infrastructure security policy you may wish to add a policy of"},{"line_number":94,"context_line":"drop on the public zone this can be achieved by running the following command."},{"line_number":95,"context_line":"``firewall-cmd --permanent --set-target\u003dDROP --zone\u003dpublic`` You should also"},{"line_number":96,"context_line":"ensure that the public zone is the default zone by running"},{"line_number":97,"context_line":"``sudo firewall-cmd --get-active-zones`` if the output of the command is blank"},{"line_number":98,"context_line":"set the active zone by running"}],"source_content_type":"text/x-rst","patch_set":12,"id":"73ddff79_ca609dea","line":95,"range":{"start_line":95,"start_character":0,"end_line":95,"end_character":60},"updated":"2022-06-30 09:58:45.000000000","message":"The default for the public zone is to reject anything not matching a rule (as opposed to silently dropping). Is that not sufficient?","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"82b93aa43e1a351111a12a8e9369fd704f48f71b","unresolved":true,"context_lines":[{"line_number":92,"context_line":"``firewall-cmd --zone\u003dpublic --add-port\u003d8080/tcp --permanent``"},{"line_number":93,"context_line":"Dpendant on your infrastructure security policy you may wish to add a policy of"},{"line_number":94,"context_line":"drop on the public zone this can be achieved by running the following command."},{"line_number":95,"context_line":"``firewall-cmd --permanent --set-target\u003dDROP --zone\u003dpublic`` You should also"},{"line_number":96,"context_line":"ensure that the public zone is the default zone by running"},{"line_number":97,"context_line":"``sudo firewall-cmd --get-active-zones`` if the output of the command is blank"},{"line_number":98,"context_line":"set the active zone by running"}],"source_content_type":"text/x-rst","patch_set":12,"id":"b3f67835_a8ed59c0","line":95,"range":{"start_line":95,"start_character":0,"end_line":95,"end_character":60},"in_reply_to":"73ddff79_ca609dea","updated":"2022-06-30 12:31:42.000000000","message":"Generally its better to silently ignore requests than rejecting them when your on a public network. Better to pretend your not there than announce that a services is running and rejecting your requests.","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"539c24b74e1b8ca22f5d907e7281a42896b7389e","unresolved":false,"context_lines":[{"line_number":92,"context_line":"``firewall-cmd --zone\u003dpublic --add-port\u003d8080/tcp --permanent``"},{"line_number":93,"context_line":"Dpendant on your infrastructure security policy you may wish to add a policy of"},{"line_number":94,"context_line":"drop on the public zone this can be achieved by running the following command."},{"line_number":95,"context_line":"``firewall-cmd --permanent --set-target\u003dDROP --zone\u003dpublic`` You should also"},{"line_number":96,"context_line":"ensure that the public zone is the default zone by running"},{"line_number":97,"context_line":"``sudo firewall-cmd --get-active-zones`` if the output of the command is blank"},{"line_number":98,"context_line":"set the active zone by running"}],"source_content_type":"text/x-rst","patch_set":12,"id":"9b617cc0_335a55c5","line":95,"range":{"start_line":95,"start_character":0,"end_line":95,"end_character":60},"in_reply_to":"b3f67835_a8ed59c0","updated":"2022-07-17 16:46:38.000000000","message":"Done","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"cce785d013fc93749a0ce4f7aa5fe3f348447c45","unresolved":true,"context_lines":[{"line_number":92,"context_line":"``firewall-cmd --zone\u003dpublic --add-port\u003d8080/tcp --permanent``"},{"line_number":93,"context_line":"Dpendant on your infrastructure security policy you may wish to add a policy of"},{"line_number":94,"context_line":"drop on the public zone this can be achieved by running the following command."},{"line_number":95,"context_line":"``firewall-cmd --permanent --set-target\u003dDROP --zone\u003dpublic`` You should also"},{"line_number":96,"context_line":"ensure that the public zone is the default zone by running"},{"line_number":97,"context_line":"``sudo firewall-cmd --get-active-zones`` if the output of the command is blank"},{"line_number":98,"context_line":"set the active zone by running"},{"line_number":99,"context_line":"``sudo firewall-cmd --permanent --zone\u003dpublic --change-interface\u003deth0``"},{"line_number":100,"context_line":"if additional interfaces are required to be added the zone this can be done by"},{"line_number":101,"context_line":"running"},{"line_number":102,"context_line":"``sudo firewall-cmd --permanent --zone\u003dpublic --add-interface\u003d\u003cadditional interface``"},{"line_number":103,"context_line":"To apply changes to the system firewall run ``sudo firewalld-cmd --reload``"},{"line_number":104,"context_line":"For additional information and configuration please see;"},{"line_number":105,"context_line":"https://firewalld.org/documentation/man-pages/firewall-cmd.html"}],"source_content_type":"text/x-rst","patch_set":12,"id":"0d101f9e_0b3ea7bd","line":105,"range":{"start_line":95,"start_character":61,"end_line":105,"end_character":63},"updated":"2022-06-30 09:58:45.000000000","message":"Probably other interfaces would need to be in other zones than public. e.g. we\u0027re not configuring rules for the internal API, so it would need to be in the trusted zone.","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"539c24b74e1b8ca22f5d907e7281a42896b7389e","unresolved":false,"context_lines":[{"line_number":92,"context_line":"``firewall-cmd --zone\u003dpublic --add-port\u003d8080/tcp --permanent``"},{"line_number":93,"context_line":"Dpendant on your infrastructure security policy you may wish to add a policy of"},{"line_number":94,"context_line":"drop on the public zone this can be achieved by running the following command."},{"line_number":95,"context_line":"``firewall-cmd --permanent --set-target\u003dDROP --zone\u003dpublic`` You should also"},{"line_number":96,"context_line":"ensure that the public zone is the default zone by running"},{"line_number":97,"context_line":"``sudo firewall-cmd --get-active-zones`` if the output of the command is blank"},{"line_number":98,"context_line":"set the active zone by running"},{"line_number":99,"context_line":"``sudo firewall-cmd --permanent --zone\u003dpublic --change-interface\u003deth0``"},{"line_number":100,"context_line":"if additional interfaces are required to be added the zone this can be done by"},{"line_number":101,"context_line":"running"},{"line_number":102,"context_line":"``sudo firewall-cmd --permanent --zone\u003dpublic --add-interface\u003d\u003cadditional interface``"},{"line_number":103,"context_line":"To apply changes to the system firewall run ``sudo firewalld-cmd --reload``"},{"line_number":104,"context_line":"For additional information and configuration please see;"},{"line_number":105,"context_line":"https://firewalld.org/documentation/man-pages/firewall-cmd.html"}],"source_content_type":"text/x-rst","patch_set":12,"id":"d746fc0f_9ade5d5e","line":105,"range":{"start_line":95,"start_character":61,"end_line":105,"end_character":63},"in_reply_to":"0d101f9e_0b3ea7bd","updated":"2022-07-17 16:46:38.000000000","message":"Done","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"7bf9d4a57182070de716452bef0d88a321877020","unresolved":true,"context_lines":[{"line_number":103,"context_line":""},{"line_number":104,"context_line":"You can check the current active zones by running the command below."},{"line_number":105,"context_line":"If the output of the command is blank then no zones are configured as active."},{"line_number":106,"context_line":".. code-block:: console"},{"line_number":107,"context_line":""},{"line_number":108,"context_line":"sudo firewall-cmd --get-active-zones"},{"line_number":109,"context_line":""}],"source_content_type":"text/x-rst","patch_set":21,"id":"ff86145d_2647729a","line":106,"updated":"2022-07-07 09:54:20.000000000","message":"I think it needs a blank line before it.\n\nUse tox -e docs to generate docs locally.","commit_id":"4c1bd848fa270ae4256c1cb07df8854f3ebc57e5"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"539c24b74e1b8ca22f5d907e7281a42896b7389e","unresolved":false,"context_lines":[{"line_number":103,"context_line":""},{"line_number":104,"context_line":"You can check the current active zones by running the command below."},{"line_number":105,"context_line":"If the output of the command is blank then no zones are configured as active."},{"line_number":106,"context_line":".. code-block:: console"},{"line_number":107,"context_line":""},{"line_number":108,"context_line":"sudo firewall-cmd --get-active-zones"},{"line_number":109,"context_line":""}],"source_content_type":"text/x-rst","patch_set":21,"id":"32040cff_531ef005","line":106,"in_reply_to":"ff86145d_2647729a","updated":"2022-07-17 16:46:38.000000000","message":"Done","commit_id":"4c1bd848fa270ae4256c1cb07df8854f3ebc57e5"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"7bf9d4a57182070de716452bef0d88a321877020","unresolved":true,"context_lines":[{"line_number":105,"context_line":"If the output of the command is blank then no zones are configured as active."},{"line_number":106,"context_line":".. code-block:: console"},{"line_number":107,"context_line":""},{"line_number":108,"context_line":"sudo firewall-cmd --get-active-zones"},{"line_number":109,"context_line":""},{"line_number":110,"context_line":"You should ensure that the system is reachable via SSH to avoid lockout,"},{"line_number":111,"context_line":"to add ssh to a perticular zone run the following command."}],"source_content_type":"text/x-rst","patch_set":21,"id":"c990af59_3cd43582","line":108,"updated":"2022-07-07 09:54:20.000000000","message":"Indent 3 spaces","commit_id":"4c1bd848fa270ae4256c1cb07df8854f3ebc57e5"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"539c24b74e1b8ca22f5d907e7281a42896b7389e","unresolved":false,"context_lines":[{"line_number":105,"context_line":"If the output of the command is blank then no zones are configured as active."},{"line_number":106,"context_line":".. code-block:: console"},{"line_number":107,"context_line":""},{"line_number":108,"context_line":"sudo firewall-cmd --get-active-zones"},{"line_number":109,"context_line":""},{"line_number":110,"context_line":"You should ensure that the system is reachable via SSH to avoid lockout,"},{"line_number":111,"context_line":"to add ssh to a perticular zone run the following command."}],"source_content_type":"text/x-rst","patch_set":21,"id":"427ae3c4_98b5831c","line":108,"in_reply_to":"c990af59_3cd43582","updated":"2022-07-17 16:46:38.000000000","message":"Done","commit_id":"4c1bd848fa270ae4256c1cb07df8854f3ebc57e5"},{"author":{"_account_id":17669,"name":"Doug Szumski","email":"doug@stackhpc.com","username":"DougSzumski"},"change_message_id":"168a9455b7b1a593a9e081148d84fcaa55a9030c","unresolved":true,"context_lines":[{"line_number":98,"context_line":""},{"line_number":99,"context_line":"Prerequsites"},{"line_number":100,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":101,"context_line":"Before enabling automatic configuration of firewalld, you should ensure"},{"line_number":102,"context_line":"that firewalld has been setup correctly."},{"line_number":103,"context_line":""},{"line_number":104,"context_line":"You can check the current active zones by running the command below."}],"source_content_type":"text/x-rst","patch_set":29,"id":"d28d86e1_a8777fc9","line":101,"updated":"2022-07-22 13:30:19.000000000","message":"nit: It would be nice to advertise the Kayobe part here for automating this","commit_id":"4cc41c430dd38d32ea4c55ab847cf929455f2513"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"c92dd6e41fe6cd93f99c4e9ec88986dc18970abd","unresolved":false,"context_lines":[{"line_number":98,"context_line":""},{"line_number":99,"context_line":"Prerequsites"},{"line_number":100,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":101,"context_line":"Before enabling automatic configuration of firewalld, you should ensure"},{"line_number":102,"context_line":"that firewalld has been setup correctly."},{"line_number":103,"context_line":""},{"line_number":104,"context_line":"You can check the current active zones by running the command below."}],"source_content_type":"text/x-rst","patch_set":29,"id":"033b7b7c_89ac1487","line":101,"in_reply_to":"d28d86e1_a8777fc9","updated":"2022-07-22 13:51:33.000000000","message":"Done","commit_id":"4cc41c430dd38d32ea4c55ab847cf929455f2513"},{"author":{"_account_id":17669,"name":"Doug Szumski","email":"doug@stackhpc.com","username":"DougSzumski"},"change_message_id":"168a9455b7b1a593a9e081148d84fcaa55a9030c","unresolved":true,"context_lines":[{"line_number":109,"context_line":"   sudo firewall-cmd --get-active-zones"},{"line_number":110,"context_line":""},{"line_number":111,"context_line":"You should ensure that the system is reachable via SSH to avoid lockout,"},{"line_number":112,"context_line":"to add ssh to a perticular zone run the following command."},{"line_number":113,"context_line":""},{"line_number":114,"context_line":".. code-block:: console"},{"line_number":115,"context_line":""}],"source_content_type":"text/x-rst","patch_set":29,"id":"bd5c09c6_09cdaca8","line":112,"updated":"2022-07-22 13:30:19.000000000","message":"nit: s/perticular/particular","commit_id":"4cc41c430dd38d32ea4c55ab847cf929455f2513"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"c92dd6e41fe6cd93f99c4e9ec88986dc18970abd","unresolved":false,"context_lines":[{"line_number":109,"context_line":"   sudo firewall-cmd --get-active-zones"},{"line_number":110,"context_line":""},{"line_number":111,"context_line":"You should ensure that the system is reachable via SSH to avoid lockout,"},{"line_number":112,"context_line":"to add ssh to a perticular zone run the following command."},{"line_number":113,"context_line":""},{"line_number":114,"context_line":".. code-block:: console"},{"line_number":115,"context_line":""}],"source_content_type":"text/x-rst","patch_set":29,"id":"5531084b_5ecc465a","line":112,"in_reply_to":"bd5c09c6_09cdaca8","updated":"2022-07-22 13:51:33.000000000","message":"Done","commit_id":"4cc41c430dd38d32ea4c55ab847cf929455f2513"},{"author":{"_account_id":17669,"name":"Doug Szumski","email":"doug@stackhpc.com","username":"DougSzumski"},"change_message_id":"168a9455b7b1a593a9e081148d84fcaa55a9030c","unresolved":true,"context_lines":[{"line_number":136,"context_line":""},{"line_number":137,"context_line":"   sudo firewall-cmd --zone\u003dpublic --add-port\u003d8080/tcp --permanent"},{"line_number":138,"context_line":""},{"line_number":139,"context_line":"Dependant on your infrastructure security policy you may wish to add a policy"},{"line_number":140,"context_line":"of drop on the public zone this can be achieved by running the following"},{"line_number":141,"context_line":"command."},{"line_number":142,"context_line":""}],"source_content_type":"text/x-rst","patch_set":29,"id":"8a9c654f_d5115b5a","line":139,"updated":"2022-07-22 13:30:19.000000000","message":"nit s/Dependant/Dependent","commit_id":"4cc41c430dd38d32ea4c55ab847cf929455f2513"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"c92dd6e41fe6cd93f99c4e9ec88986dc18970abd","unresolved":false,"context_lines":[{"line_number":136,"context_line":""},{"line_number":137,"context_line":"   sudo firewall-cmd --zone\u003dpublic --add-port\u003d8080/tcp --permanent"},{"line_number":138,"context_line":""},{"line_number":139,"context_line":"Dependant on your infrastructure security policy you may wish to add a policy"},{"line_number":140,"context_line":"of drop on the public zone this can be achieved by running the following"},{"line_number":141,"context_line":"command."},{"line_number":142,"context_line":""}],"source_content_type":"text/x-rst","patch_set":29,"id":"e43610f4_0ded9457","line":139,"in_reply_to":"8a9c654f_d5115b5a","updated":"2022-07-22 13:51:33.000000000","message":"Done","commit_id":"4cc41c430dd38d32ea4c55ab847cf929455f2513"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"585104886be07be996a8f86ac210dbb55eb19f07","unresolved":true,"context_lines":[{"line_number":77,"context_line":"passwordless sudo capability. For setting custom owner user and group, user"},{"line_number":78,"context_line":"can set ``config_owner_user`` and ``config_owner_group`` in ``globals.yml``."},{"line_number":79,"context_line":""},{"line_number":80,"context_line":"FirewallD"},{"line_number":81,"context_line":"~~~~~~~~~"},{"line_number":82,"context_line":"Prior to Zed, kolla would disable any system firewall leaving"},{"line_number":83,"context_line":"configuration up to the end users. Firewalld is now supported and will"}],"source_content_type":"text/x-rst","patch_set":30,"id":"aa0fe652_25930a25","line":80,"updated":"2022-07-25 09:54:17.000000000","message":"what about the docs at bootstrap-servers? They still mention no firewall can be configured.","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"cdb2c54aba22b2e5aa66f21893faf759b3e11669","unresolved":false,"context_lines":[{"line_number":77,"context_line":"passwordless sudo capability. For setting custom owner user and group, user"},{"line_number":78,"context_line":"can set ``config_owner_user`` and ``config_owner_group`` in ``globals.yml``."},{"line_number":79,"context_line":""},{"line_number":80,"context_line":"FirewallD"},{"line_number":81,"context_line":"~~~~~~~~~"},{"line_number":82,"context_line":"Prior to Zed, kolla would disable any system firewall leaving"},{"line_number":83,"context_line":"configuration up to the end users. Firewalld is now supported and will"}],"source_content_type":"text/x-rst","patch_set":30,"id":"661affed_878868a0","line":80,"in_reply_to":"aa0fe652_25930a25","updated":"2022-07-26 17:29:44.000000000","message":"I\u0027ve modified the bootstrap-servers doc","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"585104886be07be996a8f86ac210dbb55eb19f07","unresolved":true,"context_lines":[{"line_number":79,"context_line":""},{"line_number":80,"context_line":"FirewallD"},{"line_number":81,"context_line":"~~~~~~~~~"},{"line_number":82,"context_line":"Prior to Zed, kolla would disable any system firewall leaving"},{"line_number":83,"context_line":"configuration up to the end users. Firewalld is now supported and will"},{"line_number":84,"context_line":"configure external api ports for each enabled openstack service."},{"line_number":85,"context_line":""}],"source_content_type":"text/x-rst","patch_set":30,"id":"7d04ca39_bf8a63b9","line":82,"range":{"start_line":82,"start_character":14,"end_line":82,"end_character":20},"updated":"2022-07-25 09:54:17.000000000","message":"Kolla Ansible","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"cdb2c54aba22b2e5aa66f21893faf759b3e11669","unresolved":false,"context_lines":[{"line_number":79,"context_line":""},{"line_number":80,"context_line":"FirewallD"},{"line_number":81,"context_line":"~~~~~~~~~"},{"line_number":82,"context_line":"Prior to Zed, kolla would disable any system firewall leaving"},{"line_number":83,"context_line":"configuration up to the end users. Firewalld is now supported and will"},{"line_number":84,"context_line":"configure external api ports for each enabled openstack service."},{"line_number":85,"context_line":""}],"source_content_type":"text/x-rst","patch_set":30,"id":"1969d4a2_d6957049","line":82,"range":{"start_line":82,"start_character":14,"end_line":82,"end_character":20},"in_reply_to":"7d04ca39_bf8a63b9","updated":"2022-07-26 17:29:44.000000000","message":"Done","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"585104886be07be996a8f86ac210dbb55eb19f07","unresolved":true,"context_lines":[{"line_number":81,"context_line":"~~~~~~~~~"},{"line_number":82,"context_line":"Prior to Zed, kolla would disable any system firewall leaving"},{"line_number":83,"context_line":"configuration up to the end users. Firewalld is now supported and will"},{"line_number":84,"context_line":"configure external api ports for each enabled openstack service."},{"line_number":85,"context_line":""},{"line_number":86,"context_line":"The following variables should be configured in the kolla ``globals.yml``"},{"line_number":87,"context_line":""}],"source_content_type":"text/x-rst","patch_set":30,"id":"71c50e1d_73fdf5be","line":84,"range":{"start_line":84,"start_character":46,"end_line":84,"end_character":56},"updated":"2022-07-25 09:54:17.000000000","message":"nit: OpenStack","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"cdb2c54aba22b2e5aa66f21893faf759b3e11669","unresolved":false,"context_lines":[{"line_number":81,"context_line":"~~~~~~~~~"},{"line_number":82,"context_line":"Prior to Zed, kolla would disable any system firewall leaving"},{"line_number":83,"context_line":"configuration up to the end users. Firewalld is now supported and will"},{"line_number":84,"context_line":"configure external api ports for each enabled openstack service."},{"line_number":85,"context_line":""},{"line_number":86,"context_line":"The following variables should be configured in the kolla ``globals.yml``"},{"line_number":87,"context_line":""}],"source_content_type":"text/x-rst","patch_set":30,"id":"59f87e4b_7cf3cac0","line":84,"range":{"start_line":84,"start_character":46,"end_line":84,"end_character":56},"in_reply_to":"71c50e1d_73fdf5be","updated":"2022-07-26 17:29:44.000000000","message":"Done","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"585104886be07be996a8f86ac210dbb55eb19f07","unresolved":true,"context_lines":[{"line_number":83,"context_line":"configuration up to the end users. Firewalld is now supported and will"},{"line_number":84,"context_line":"configure external api ports for each enabled openstack service."},{"line_number":85,"context_line":""},{"line_number":86,"context_line":"The following variables should be configured in the kolla ``globals.yml``"},{"line_number":87,"context_line":""},{"line_number":88,"context_line":"* external_api_firewalld_zone"},{"line_number":89,"context_line":"    * The default zone to configure ports on for external API Access"}],"source_content_type":"text/x-rst","patch_set":30,"id":"962c7b32_5b872705","line":86,"range":{"start_line":86,"start_character":52,"end_line":86,"end_character":58},"updated":"2022-07-25 09:54:17.000000000","message":"Kolla Ansible\u0027s","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"cdb2c54aba22b2e5aa66f21893faf759b3e11669","unresolved":false,"context_lines":[{"line_number":83,"context_line":"configuration up to the end users. Firewalld is now supported and will"},{"line_number":84,"context_line":"configure external api ports for each enabled openstack service."},{"line_number":85,"context_line":""},{"line_number":86,"context_line":"The following variables should be configured in the kolla ``globals.yml``"},{"line_number":87,"context_line":""},{"line_number":88,"context_line":"* external_api_firewalld_zone"},{"line_number":89,"context_line":"    * The default zone to configure ports on for external API Access"}],"source_content_type":"text/x-rst","patch_set":30,"id":"35aa9cfb_e68bc76e","line":86,"range":{"start_line":86,"start_character":52,"end_line":86,"end_character":58},"in_reply_to":"962c7b32_5b872705","updated":"2022-07-26 17:29:44.000000000","message":"Done","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"585104886be07be996a8f86ac210dbb55eb19f07","unresolved":true,"context_lines":[{"line_number":153,"context_line":""},{"line_number":154,"context_line":"   sudo firewalld-cmd --reload"},{"line_number":155,"context_line":""},{"line_number":156,"context_line":"For additional information and configuration please see;"},{"line_number":157,"context_line":"https://firewalld.org/documentation/man-pages/firewall-cmd.html"}],"source_content_type":"text/x-rst","patch_set":30,"id":"9002dec9_0c66aa30","line":156,"range":{"start_line":156,"start_character":55,"end_line":156,"end_character":56},"updated":"2022-07-25 09:54:17.000000000","message":"nit: should be a colon","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"cdb2c54aba22b2e5aa66f21893faf759b3e11669","unresolved":false,"context_lines":[{"line_number":153,"context_line":""},{"line_number":154,"context_line":"   sudo firewalld-cmd --reload"},{"line_number":155,"context_line":""},{"line_number":156,"context_line":"For additional information and configuration please see;"},{"line_number":157,"context_line":"https://firewalld.org/documentation/man-pages/firewall-cmd.html"}],"source_content_type":"text/x-rst","patch_set":30,"id":"568e7736_9733d391","line":156,"range":{"start_line":156,"start_character":55,"end_line":156,"end_character":56},"in_reply_to":"9002dec9_0c66aa30","updated":"2022-07-26 17:29:44.000000000","message":"Done","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"860e47fba9b3e72961acd0b91be1fc1b0f463be9","unresolved":true,"context_lines":[{"line_number":81,"context_line":"~~~~~~~~~"},{"line_number":82,"context_line":"Prior to Zed, Kolla Ansible would disable any system firewall leaving"},{"line_number":83,"context_line":"configuration up to the end users. Firewalld is now supported and will"},{"line_number":84,"context_line":"configure external api ports for each enabled Openstack service."},{"line_number":85,"context_line":""},{"line_number":86,"context_line":"The following variables should be configured in Kolla Ansible\u0027s"},{"line_number":87,"context_line":"``globals.yml``"}],"source_content_type":"text/x-rst","patch_set":31,"id":"fdc410eb_8956d7d8","line":84,"range":{"start_line":84,"start_character":46,"end_line":84,"end_character":56},"updated":"2022-07-26 18:15:26.000000000","message":"nit: OpenStack","commit_id":"0e5648d20eee9360ad4bd4e7feed01cc0af9c68d"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"e8024c4f937a03e591b3e48ad1d04245f2e643eb","unresolved":false,"context_lines":[{"line_number":81,"context_line":"~~~~~~~~~"},{"line_number":82,"context_line":"Prior to Zed, Kolla Ansible would disable any system firewall leaving"},{"line_number":83,"context_line":"configuration up to the end users. Firewalld is now supported and will"},{"line_number":84,"context_line":"configure external api ports for each enabled Openstack service."},{"line_number":85,"context_line":""},{"line_number":86,"context_line":"The following variables should be configured in Kolla Ansible\u0027s"},{"line_number":87,"context_line":"``globals.yml``"}],"source_content_type":"text/x-rst","patch_set":31,"id":"bffba4b6_c9bb41f7","line":84,"range":{"start_line":84,"start_character":46,"end_line":84,"end_character":56},"in_reply_to":"fdc410eb_8956d7d8","updated":"2022-07-27 08:54:18.000000000","message":"Done","commit_id":"0e5648d20eee9360ad4bd4e7feed01cc0af9c68d"}],"etc/kolla/globals.yml":[{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"860e47fba9b3e72961acd0b91be1fc1b0f463be9","unresolved":false,"context_lines":[{"line_number":212,"context_line":"# Configures firewalld on both ubuntu and centos systems"},{"line_number":213,"context_line":"# for enabled services."},{"line_number":214,"context_line":"# firewalld should be installed beforehand."},{"line_number":215,"context_line":"# disable_firewall: \"true\""},{"line_number":216,"context_line":"# enable_external_api_firewalld: \"false\""},{"line_number":217,"context_line":"# external_api_firewalld_zone: \"public\""},{"line_number":218,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":31,"id":"26377137_41d564c3","line":215,"updated":"2022-07-26 18:15:26.000000000","message":"(note this one we can leave as it is a nice suggestion)","commit_id":"0e5648d20eee9360ad4bd4e7feed01cc0af9c68d"}],"kolla_ansible/filters.py":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"79e55797b2714e693bd05c0897747ba669571daa","unresolved":true,"context_lines":[{"line_number":35,"context_line":""},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"@jinja2.pass_context"},{"line_number":38,"context_line":"def extract_services(context, service):"},{"line_number":39,"context_line":"    \"\"\"Return a list of services"},{"line_number":40,"context_line":"    "},{"line_number":41,"context_line":"      :param context: Jinja2 Context object."}],"source_content_type":"text/x-python","patch_set":3,"id":"ae1822a7_cea10ec3","line":38,"range":{"start_line":38,"start_character":30,"end_line":38,"end_character":37},"updated":"2022-06-28 12:46:12.000000000","message":"Could we call it extract_haproxy_services, to distinguish it from container services?","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"79e55797b2714e693bd05c0897747ba669571daa","unresolved":true,"context_lines":[{"line_number":35,"context_line":""},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"@jinja2.pass_context"},{"line_number":38,"context_line":"def extract_services(context, service):"},{"line_number":39,"context_line":"    \"\"\"Return a list of services"},{"line_number":40,"context_line":"    "},{"line_number":41,"context_line":"      :param context: Jinja2 Context object."}],"source_content_type":"text/x-python","patch_set":3,"id":"586a0bf9_03ee7c21","line":38,"range":{"start_line":38,"start_character":4,"end_line":38,"end_character":20},"updated":"2022-06-28 12:46:12.000000000","message":"Needs unit testing in kolla_ansible/tests/unit/test_filters.py","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"539c24b74e1b8ca22f5d907e7281a42896b7389e","unresolved":false,"context_lines":[{"line_number":35,"context_line":""},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"@jinja2.pass_context"},{"line_number":38,"context_line":"def extract_services(context, service):"},{"line_number":39,"context_line":"    \"\"\"Return a list of services"},{"line_number":40,"context_line":"    "},{"line_number":41,"context_line":"      :param context: Jinja2 Context object."}],"source_content_type":"text/x-python","patch_set":3,"id":"d2d3a378_66888698","line":38,"range":{"start_line":38,"start_character":4,"end_line":38,"end_character":20},"in_reply_to":"586a0bf9_03ee7c21","updated":"2022-07-17 16:46:38.000000000","message":"Done","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"6a2067c61591e32121695a0cf5cc5a1a3e6378f7","unresolved":false,"context_lines":[{"line_number":35,"context_line":""},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"@jinja2.pass_context"},{"line_number":38,"context_line":"def extract_services(context, service):"},{"line_number":39,"context_line":"    \"\"\"Return a list of services"},{"line_number":40,"context_line":"    "},{"line_number":41,"context_line":"      :param context: Jinja2 Context object."}],"source_content_type":"text/x-python","patch_set":3,"id":"47b3ca50_6ba43288","line":38,"range":{"start_line":38,"start_character":30,"end_line":38,"end_character":37},"in_reply_to":"ae1822a7_cea10ec3","updated":"2022-06-29 08:52:04.000000000","message":"Done","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"79e55797b2714e693bd05c0897747ba669571daa","unresolved":true,"context_lines":[{"line_number":42,"context_line":"      :param service: Service definition, dict."},{"line_number":43,"context_line":"      :returns: A Dict."},{"line_number":44,"context_line":"    \"\"\""},{"line_number":45,"context_line":"    global services"},{"line_number":46,"context_line":"    global haproxy"},{"line_number":47,"context_line":"    services \u003d {}"},{"line_number":48,"context_line":"    haproxy \u003d {}"},{"line_number":49,"context_line":"    for key in service:"}],"source_content_type":"text/x-python","patch_set":3,"id":"2b263d21_33f7d173","line":46,"range":{"start_line":45,"start_character":0,"end_line":46,"end_character":18},"updated":"2022-06-28 12:46:12.000000000","message":"Shouldn\u0027t be global","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"6a2067c61591e32121695a0cf5cc5a1a3e6378f7","unresolved":false,"context_lines":[{"line_number":42,"context_line":"      :param service: Service definition, dict."},{"line_number":43,"context_line":"      :returns: A Dict."},{"line_number":44,"context_line":"    \"\"\""},{"line_number":45,"context_line":"    global services"},{"line_number":46,"context_line":"    global haproxy"},{"line_number":47,"context_line":"    services \u003d {}"},{"line_number":48,"context_line":"    haproxy \u003d {}"},{"line_number":49,"context_line":"    for key in service:"}],"source_content_type":"text/x-python","patch_set":3,"id":"62e8fede_88cfd89c","line":46,"range":{"start_line":45,"start_character":0,"end_line":46,"end_character":18},"in_reply_to":"2b263d21_33f7d173","updated":"2022-06-29 08:52:04.000000000","message":"Done","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"79e55797b2714e693bd05c0897747ba669571daa","unresolved":true,"context_lines":[{"line_number":44,"context_line":"    \"\"\""},{"line_number":45,"context_line":"    global services"},{"line_number":46,"context_line":"    global haproxy"},{"line_number":47,"context_line":"    services \u003d {}"},{"line_number":48,"context_line":"    haproxy \u003d {}"},{"line_number":49,"context_line":"    for key in service:"},{"line_number":50,"context_line":"        services \u003d service.get(key)"}],"source_content_type":"text/x-python","patch_set":3,"id":"d0a93aaa_e29a8065","line":47,"range":{"start_line":47,"start_character":4,"end_line":47,"end_character":17},"updated":"2022-06-28 12:46:12.000000000","message":"Nit: no need to declare this.","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"6a2067c61591e32121695a0cf5cc5a1a3e6378f7","unresolved":false,"context_lines":[{"line_number":44,"context_line":"    \"\"\""},{"line_number":45,"context_line":"    global services"},{"line_number":46,"context_line":"    global haproxy"},{"line_number":47,"context_line":"    services \u003d {}"},{"line_number":48,"context_line":"    haproxy \u003d {}"},{"line_number":49,"context_line":"    for key in service:"},{"line_number":50,"context_line":"        services \u003d service.get(key)"}],"source_content_type":"text/x-python","patch_set":3,"id":"d880ed26_746b3eed","line":47,"range":{"start_line":47,"start_character":4,"end_line":47,"end_character":17},"in_reply_to":"d0a93aaa_e29a8065","updated":"2022-06-29 08:52:04.000000000","message":"Done","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"79e55797b2714e693bd05c0897747ba669571daa","unresolved":true,"context_lines":[{"line_number":46,"context_line":"    global haproxy"},{"line_number":47,"context_line":"    services \u003d {}"},{"line_number":48,"context_line":"    haproxy \u003d {}"},{"line_number":49,"context_line":"    for key in service:"},{"line_number":50,"context_line":"        services \u003d service.get(key)"},{"line_number":51,"context_line":"        for key in services:"},{"line_number":52,"context_line":"            if key \u003d\u003d \u0027haproxy\u0027:"}],"source_content_type":"text/x-python","patch_set":3,"id":"67b7ed53_77bd1aed","line":49,"range":{"start_line":49,"start_character":15,"end_line":49,"end_character":22},"updated":"2022-06-28 12:46:12.000000000","message":"The names of service and services seem the wrong way around to me.","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"6a2067c61591e32121695a0cf5cc5a1a3e6378f7","unresolved":false,"context_lines":[{"line_number":46,"context_line":"    global haproxy"},{"line_number":47,"context_line":"    services \u003d {}"},{"line_number":48,"context_line":"    haproxy \u003d {}"},{"line_number":49,"context_line":"    for key in service:"},{"line_number":50,"context_line":"        services \u003d service.get(key)"},{"line_number":51,"context_line":"        for key in services:"},{"line_number":52,"context_line":"            if key \u003d\u003d \u0027haproxy\u0027:"}],"source_content_type":"text/x-python","patch_set":3,"id":"45252aba_5345432d","line":49,"range":{"start_line":49,"start_character":15,"end_line":49,"end_character":22},"in_reply_to":"67b7ed53_77bd1aed","updated":"2022-06-29 08:52:04.000000000","message":"Done","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"79e55797b2714e693bd05c0897747ba669571daa","unresolved":true,"context_lines":[{"line_number":48,"context_line":"    haproxy \u003d {}"},{"line_number":49,"context_line":"    for key in service:"},{"line_number":50,"context_line":"        services \u003d service.get(key)"},{"line_number":51,"context_line":"        for key in services:"},{"line_number":52,"context_line":"            if key \u003d\u003d \u0027haproxy\u0027:"},{"line_number":53,"context_line":"                haproxy.update(services.get(key))"},{"line_number":54,"context_line":"    "},{"line_number":55,"context_line":"    return haproxy"},{"line_number":56,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"3e39e985_87ecdf1c","line":53,"range":{"start_line":51,"start_character":0,"end_line":53,"end_character":49},"updated":"2022-06-28 12:46:12.000000000","message":"No need for a loop. Also, need some sanity check that keys are unique across all haproxy dicts:\n\nservice_haproxy \u003d services.get(\u0027haproxy\u0027)\nif service_haproxy:\n    assert set(haproxy).isdisjoint(set(service_haproxy)), \"haproxy service names should be unique\"\n    haproxy.update(services.get(key))","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"6a2067c61591e32121695a0cf5cc5a1a3e6378f7","unresolved":false,"context_lines":[{"line_number":48,"context_line":"    haproxy \u003d {}"},{"line_number":49,"context_line":"    for key in service:"},{"line_number":50,"context_line":"        services \u003d service.get(key)"},{"line_number":51,"context_line":"        for key in services:"},{"line_number":52,"context_line":"            if key \u003d\u003d \u0027haproxy\u0027:"},{"line_number":53,"context_line":"                haproxy.update(services.get(key))"},{"line_number":54,"context_line":"    "},{"line_number":55,"context_line":"    return haproxy"},{"line_number":56,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"8c713af3_11375af9","line":53,"range":{"start_line":51,"start_character":0,"end_line":53,"end_character":49},"in_reply_to":"3e39e985_87ecdf1c","updated":"2022-06-29 08:52:04.000000000","message":"Done","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d496e064717c3eeb51ab805844c495d1e38f350b","unresolved":true,"context_lines":[{"line_number":45,"context_line":"    haproxy \u003d {}"},{"line_number":46,"context_line":"    for key in services:"},{"line_number":47,"context_line":"        service \u003d services.get(key)"},{"line_number":48,"context_line":"        for key in services:"},{"line_number":49,"context_line":"            if key \u003d\u003d \u0027haproxy\u0027:"},{"line_number":50,"context_line":"                haproxy.update(service.get(key))"},{"line_number":51,"context_line":""}],"source_content_type":"text/x-python","patch_set":6,"id":"6bf3c97c_5727c99e","line":48,"range":{"start_line":48,"start_character":19,"end_line":48,"end_character":27},"updated":"2022-06-29 08:16:37.000000000","message":"service","commit_id":"267ab2b740e0638d3bbab88a9e6ec8b4dea61676"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"6a2067c61591e32121695a0cf5cc5a1a3e6378f7","unresolved":false,"context_lines":[{"line_number":45,"context_line":"    haproxy \u003d {}"},{"line_number":46,"context_line":"    for key in services:"},{"line_number":47,"context_line":"        service \u003d services.get(key)"},{"line_number":48,"context_line":"        for key in services:"},{"line_number":49,"context_line":"            if key \u003d\u003d \u0027haproxy\u0027:"},{"line_number":50,"context_line":"                haproxy.update(service.get(key))"},{"line_number":51,"context_line":""}],"source_content_type":"text/x-python","patch_set":6,"id":"75f0ed91_ac2ba76d","line":48,"range":{"start_line":48,"start_character":19,"end_line":48,"end_character":27},"in_reply_to":"6bf3c97c_5727c99e","updated":"2022-06-29 08:52:04.000000000","message":"Done","commit_id":"267ab2b740e0638d3bbab88a9e6ec8b4dea61676"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"a8613392ff2f2bede3817fc519db074245bced6f","unresolved":true,"context_lines":[{"line_number":45,"context_line":"    haproxy \u003d {}"},{"line_number":46,"context_line":"    for key in services:"},{"line_number":47,"context_line":"        service \u003d services.get(key)"},{"line_number":48,"context_line":"        service_enabled \u003d service.get(\u0027enabled\u0027)"},{"line_number":49,"context_line":"        if service_enabled:"},{"line_number":50,"context_line":"            service_haproxy \u003d service.get(\u0027haproxy\u0027)"},{"line_number":51,"context_line":"            if service_haproxy:"},{"line_number":52,"context_line":"                assert set(haproxy).isdisjoint(set(service_haproxy)), \"haproxy service names should be unique\""}],"source_content_type":"text/x-python","patch_set":7,"id":"b7d3e26c_a031dd21","line":49,"range":{"start_line":48,"start_character":8,"end_line":49,"end_character":27},"updated":"2022-06-29 10:33:19.000000000","message":"We can use the existing function, which handles bools correctly:\n\n if service_enabled(context, service):","commit_id":"e821f5c7812d5b3f49cee0c55152696730e0e325"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"2b184be54b18eba2ffe962f060e90f6177802296","unresolved":false,"context_lines":[{"line_number":45,"context_line":"    haproxy \u003d {}"},{"line_number":46,"context_line":"    for key in services:"},{"line_number":47,"context_line":"        service \u003d services.get(key)"},{"line_number":48,"context_line":"        service_enabled \u003d service.get(\u0027enabled\u0027)"},{"line_number":49,"context_line":"        if service_enabled:"},{"line_number":50,"context_line":"            service_haproxy \u003d service.get(\u0027haproxy\u0027)"},{"line_number":51,"context_line":"            if service_haproxy:"},{"line_number":52,"context_line":"                assert set(haproxy).isdisjoint(set(service_haproxy)), \"haproxy service names should be unique\""}],"source_content_type":"text/x-python","patch_set":7,"id":"91ac1f59_d456e164","line":49,"range":{"start_line":48,"start_character":8,"end_line":49,"end_character":27},"in_reply_to":"b7d3e26c_a031dd21","updated":"2022-06-29 16:49:01.000000000","message":"Done","commit_id":"e821f5c7812d5b3f49cee0c55152696730e0e325"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"585104886be07be996a8f86ac210dbb55eb19f07","unresolved":true,"context_lines":[{"line_number":36,"context_line":""},{"line_number":37,"context_line":"@jinja2.pass_context"},{"line_number":38,"context_line":"def extract_haproxy_services(context, services):"},{"line_number":39,"context_line":"    \"\"\"Return a list of haproxy services"},{"line_number":40,"context_line":""},{"line_number":41,"context_line":"      :param context: Jinja2 Context object."},{"line_number":42,"context_line":"      :param service: Services definition, dict."}],"source_content_type":"text/x-python","patch_set":30,"id":"90bd81a4_5acb923b","line":39,"range":{"start_line":39,"start_character":16,"end_line":39,"end_character":21},"updated":"2022-07-25 09:54:17.000000000","message":"dict","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"cdb2c54aba22b2e5aa66f21893faf759b3e11669","unresolved":false,"context_lines":[{"line_number":36,"context_line":""},{"line_number":37,"context_line":"@jinja2.pass_context"},{"line_number":38,"context_line":"def extract_haproxy_services(context, services):"},{"line_number":39,"context_line":"    \"\"\"Return a list of haproxy services"},{"line_number":40,"context_line":""},{"line_number":41,"context_line":"      :param context: Jinja2 Context object."},{"line_number":42,"context_line":"      :param service: Services definition, dict."}],"source_content_type":"text/x-python","patch_set":30,"id":"cd2a5e07_11015575","line":39,"range":{"start_line":39,"start_character":16,"end_line":39,"end_character":21},"in_reply_to":"90bd81a4_5acb923b","updated":"2022-07-26 17:29:44.000000000","message":"Done","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"}],"kolla_ansible/tests/unit/test_filters.py":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"cce785d013fc93749a0ce4f7aa5fe3f348447c45","unresolved":true,"context_lines":[{"line_number":111,"context_line":""},{"line_number":112,"context_line":"    def test_extract_haproxy_services_empty_dict(self):"},{"line_number":113,"context_line":"        example_service \u003d {}"},{"line_number":114,"context_line":"        actual \u003d filters.extract_haproxy_services(example_service, \u0027\u0027)"},{"line_number":115,"context_line":"        # No change"},{"line_number":116,"context_line":"        self.assertDictEqual(example_service, actual)"},{"line_number":117,"context_line":""}],"source_content_type":"text/x-python","patch_set":12,"id":"7f82bee7_e315d8c3","line":114,"range":{"start_line":114,"start_character":50,"end_line":114,"end_character":69},"updated":"2022-06-30 09:58:45.000000000","message":"self.context, example_service","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"82b93aa43e1a351111a12a8e9369fd704f48f71b","unresolved":false,"context_lines":[{"line_number":111,"context_line":""},{"line_number":112,"context_line":"    def test_extract_haproxy_services_empty_dict(self):"},{"line_number":113,"context_line":"        example_service \u003d {}"},{"line_number":114,"context_line":"        actual \u003d filters.extract_haproxy_services(example_service, \u0027\u0027)"},{"line_number":115,"context_line":"        # No change"},{"line_number":116,"context_line":"        self.assertDictEqual(example_service, actual)"},{"line_number":117,"context_line":""}],"source_content_type":"text/x-python","patch_set":12,"id":"af484df6_0024e643","line":114,"range":{"start_line":114,"start_character":50,"end_line":114,"end_character":69},"in_reply_to":"7f82bee7_e315d8c3","updated":"2022-06-30 12:31:42.000000000","message":"Done","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"cce785d013fc93749a0ce4f7aa5fe3f348447c45","unresolved":true,"context_lines":[{"line_number":113,"context_line":"        example_service \u003d {}"},{"line_number":114,"context_line":"        actual \u003d filters.extract_haproxy_services(example_service, \u0027\u0027)"},{"line_number":115,"context_line":"        # No change"},{"line_number":116,"context_line":"        self.assertDictEqual(example_service, actual)"},{"line_number":117,"context_line":""},{"line_number":118,"context_line":"    def test_extract_haproxy_services_no_haproxy_dict(self):"},{"line_number":119,"context_line":"        example_service \u003d {"}],"source_content_type":"text/x-python","patch_set":12,"id":"b4112681_9d8d0235","line":116,"range":{"start_line":116,"start_character":29,"end_line":116,"end_character":44},"updated":"2022-06-30 09:58:45.000000000","message":"{}","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"82b93aa43e1a351111a12a8e9369fd704f48f71b","unresolved":false,"context_lines":[{"line_number":113,"context_line":"        example_service \u003d {}"},{"line_number":114,"context_line":"        actual \u003d filters.extract_haproxy_services(example_service, \u0027\u0027)"},{"line_number":115,"context_line":"        # No change"},{"line_number":116,"context_line":"        self.assertDictEqual(example_service, actual)"},{"line_number":117,"context_line":""},{"line_number":118,"context_line":"    def test_extract_haproxy_services_no_haproxy_dict(self):"},{"line_number":119,"context_line":"        example_service \u003d {"}],"source_content_type":"text/x-python","patch_set":12,"id":"b653a125_8e1491eb","line":116,"range":{"start_line":116,"start_character":29,"end_line":116,"end_character":44},"in_reply_to":"b4112681_9d8d0235","updated":"2022-06-30 12:31:42.000000000","message":"Done","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"cce785d013fc93749a0ce4f7aa5fe3f348447c45","unresolved":true,"context_lines":[{"line_number":142,"context_line":"                ]"},{"line_number":143,"context_line":"            }"},{"line_number":144,"context_line":"        }"},{"line_number":145,"context_line":"        actual \u003d filters.extract_haproxy_services(example_service, \u0027\u0027)"},{"line_number":146,"context_line":"        self.assertDictEqual({}, actual)"},{"line_number":147,"context_line":""},{"line_number":148,"context_line":"    def test_extract_haproxy_services_haproxy_dict(self):"}],"source_content_type":"text/x-python","patch_set":12,"id":"94ff6cb0_e8343cd6","line":145,"range":{"start_line":145,"start_character":51,"end_line":145,"end_character":70},"updated":"2022-06-30 09:58:45.000000000","message":"self.context, example_service","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"82b93aa43e1a351111a12a8e9369fd704f48f71b","unresolved":false,"context_lines":[{"line_number":142,"context_line":"                ]"},{"line_number":143,"context_line":"            }"},{"line_number":144,"context_line":"        }"},{"line_number":145,"context_line":"        actual \u003d filters.extract_haproxy_services(example_service, \u0027\u0027)"},{"line_number":146,"context_line":"        self.assertDictEqual({}, actual)"},{"line_number":147,"context_line":""},{"line_number":148,"context_line":"    def test_extract_haproxy_services_haproxy_dict(self):"}],"source_content_type":"text/x-python","patch_set":12,"id":"382914b4_5d7f1750","line":145,"range":{"start_line":145,"start_character":51,"end_line":145,"end_character":70},"in_reply_to":"94ff6cb0_e8343cd6","updated":"2022-06-30 12:31:42.000000000","message":"Done","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"cce785d013fc93749a0ce4f7aa5fe3f348447c45","unresolved":false,"context_lines":[{"line_number":230,"context_line":"            }"},{"line_number":231,"context_line":"        }"},{"line_number":232,"context_line":"        actual \u003d filters.extract_haproxy_services(self.context, example_service)"},{"line_number":233,"context_line":"        self.assertDictEqual(expected, actual)"},{"line_number":234,"context_line":""},{"line_number":235,"context_line":"    @mock.patch.object(filters, \u0027service_enabled\u0027)"},{"line_number":236,"context_line":"    @mock.patch.object(filters, \u0027service_mapped_to_host\u0027)"}],"source_content_type":"text/x-python","patch_set":12,"id":"ef99ccee_cacde58e","line":233,"updated":"2022-06-30 09:58:45.000000000","message":"Good test.","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"cce785d013fc93749a0ce4f7aa5fe3f348447c45","unresolved":true,"context_lines":[{"line_number":231,"context_line":"        }"},{"line_number":232,"context_line":"        actual \u003d filters.extract_haproxy_services(self.context, example_service)"},{"line_number":233,"context_line":"        self.assertDictEqual(expected, actual)"},{"line_number":234,"context_line":""},{"line_number":235,"context_line":"    @mock.patch.object(filters, \u0027service_enabled\u0027)"},{"line_number":236,"context_line":"    @mock.patch.object(filters, \u0027service_mapped_to_host\u0027)"},{"line_number":237,"context_line":"    def test_service_enabled_and_mapped_to_host(self, mock_mapped,"}],"source_content_type":"text/x-python","patch_set":12,"id":"1b95300d_1ae397e1","line":234,"updated":"2022-06-30 09:58:45.000000000","message":"Could you add two more tests:\n\n1. two services, each with a haproxy key\n2. two services, each with a haproxy key, with duplicate names in the haproxy dicts - this will test the assert. Use self.assertRaises(AssertionError, ...)","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"82b93aa43e1a351111a12a8e9369fd704f48f71b","unresolved":false,"context_lines":[{"line_number":231,"context_line":"        }"},{"line_number":232,"context_line":"        actual \u003d filters.extract_haproxy_services(self.context, example_service)"},{"line_number":233,"context_line":"        self.assertDictEqual(expected, actual)"},{"line_number":234,"context_line":""},{"line_number":235,"context_line":"    @mock.patch.object(filters, \u0027service_enabled\u0027)"},{"line_number":236,"context_line":"    @mock.patch.object(filters, \u0027service_mapped_to_host\u0027)"},{"line_number":237,"context_line":"    def test_service_enabled_and_mapped_to_host(self, mock_mapped,"}],"source_content_type":"text/x-python","patch_set":12,"id":"21ae65f9_076a5aff","line":234,"in_reply_to":"1b95300d_1ae397e1","updated":"2022-06-30 12:31:42.000000000","message":"Done","commit_id":"4c0fbb6b3234c8b948d7ba17606592bf6bc5d143"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"9972c65e26e9bba186b11bc4a02d92a72486359d","unresolved":true,"context_lines":[{"line_number":510,"context_line":"                ]"},{"line_number":511,"context_line":"            }"},{"line_number":512,"context_line":"        }"},{"line_number":513,"context_line":"        self.assertRaises(exception.FilterError,"},{"line_number":514,"context_line":"                          filters.service_enabled,"},{"line_number":515,"context_line":"                          self.context, example_service)"},{"line_number":516,"context_line":""}],"source_content_type":"text/x-python","patch_set":20,"id":"399af512_b2314908","line":513,"range":{"start_line":513,"start_character":36,"end_line":513,"end_character":47},"updated":"2022-07-04 11:35:27.000000000","message":"AssertionError","commit_id":"84fd1d5cb337cace44bd002509d5c1c8501d8231"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"539c24b74e1b8ca22f5d907e7281a42896b7389e","unresolved":false,"context_lines":[{"line_number":510,"context_line":"                ]"},{"line_number":511,"context_line":"            }"},{"line_number":512,"context_line":"        }"},{"line_number":513,"context_line":"        self.assertRaises(exception.FilterError,"},{"line_number":514,"context_line":"                          filters.service_enabled,"},{"line_number":515,"context_line":"                          self.context, example_service)"},{"line_number":516,"context_line":""}],"source_content_type":"text/x-python","patch_set":20,"id":"67f237d7_7935f284","line":513,"range":{"start_line":513,"start_character":36,"end_line":513,"end_character":47},"in_reply_to":"399af512_b2314908","updated":"2022-07-17 16:46:38.000000000","message":"Done","commit_id":"84fd1d5cb337cace44bd002509d5c1c8501d8231"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"9972c65e26e9bba186b11bc4a02d92a72486359d","unresolved":true,"context_lines":[{"line_number":511,"context_line":"            }"},{"line_number":512,"context_line":"        }"},{"line_number":513,"context_line":"        self.assertRaises(exception.FilterError,"},{"line_number":514,"context_line":"                          filters.service_enabled,"},{"line_number":515,"context_line":"                          self.context, example_service)"},{"line_number":516,"context_line":""},{"line_number":517,"context_line":"    @mock.patch.object(filters, \u0027service_enabled\u0027)"}],"source_content_type":"text/x-python","patch_set":20,"id":"5c3d170c_8a7aefde","line":514,"range":{"start_line":514,"start_character":34,"end_line":514,"end_character":49},"updated":"2022-07-04 11:35:27.000000000","message":"Wrong filter","commit_id":"84fd1d5cb337cace44bd002509d5c1c8501d8231"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"539c24b74e1b8ca22f5d907e7281a42896b7389e","unresolved":false,"context_lines":[{"line_number":511,"context_line":"            }"},{"line_number":512,"context_line":"        }"},{"line_number":513,"context_line":"        self.assertRaises(exception.FilterError,"},{"line_number":514,"context_line":"                          filters.service_enabled,"},{"line_number":515,"context_line":"                          self.context, example_service)"},{"line_number":516,"context_line":""},{"line_number":517,"context_line":"    @mock.patch.object(filters, \u0027service_enabled\u0027)"}],"source_content_type":"text/x-python","patch_set":20,"id":"43f092a9_3482aec5","line":514,"range":{"start_line":514,"start_character":34,"end_line":514,"end_character":49},"in_reply_to":"5c3d170c_8a7aefde","updated":"2022-07-17 16:46:38.000000000","message":"Done","commit_id":"84fd1d5cb337cace44bd002509d5c1c8501d8231"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"ea73ae28cf04940a5b61593c2fa7a6f596ae9545","unresolved":true,"context_lines":[{"line_number":24,"context_line":""},{"line_number":25,"context_line":""},{"line_number":26,"context_line":"class TestFilters(unittest.TestCase):"},{"line_number":27,"context_line":""},{"line_number":28,"context_line":"    def setUp(self):"},{"line_number":29,"context_line":"        # Bandit complains about Jinja2 autoescaping without nosec."},{"line_number":30,"context_line":"        self.env \u003d jinja2.Environment()  # nosec"}],"source_content_type":"text/x-python","patch_set":27,"id":"18a173a1_5b8df16f","side":"PARENT","line":27,"updated":"2022-07-16 14:57:34.000000000","message":"this line was for better formatting","commit_id":"fde5eeec29b7e1492f51429170d075128416dd98"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"539c24b74e1b8ca22f5d907e7281a42896b7389e","unresolved":false,"context_lines":[{"line_number":24,"context_line":""},{"line_number":25,"context_line":""},{"line_number":26,"context_line":"class TestFilters(unittest.TestCase):"},{"line_number":27,"context_line":""},{"line_number":28,"context_line":"    def setUp(self):"},{"line_number":29,"context_line":"        # Bandit complains about Jinja2 autoescaping without nosec."},{"line_number":30,"context_line":"        self.env \u003d jinja2.Environment()  # nosec"}],"source_content_type":"text/x-python","patch_set":27,"id":"6a676d6f_b92b4234","side":"PARENT","line":27,"in_reply_to":"18a173a1_5b8df16f","updated":"2022-07-17 16:46:38.000000000","message":"Done","commit_id":"fde5eeec29b7e1492f51429170d075128416dd98"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"585104886be07be996a8f86ac210dbb55eb19f07","unresolved":false,"context_lines":[{"line_number":514,"context_line":"        self.assertRaises(exception.FilterError,"},{"line_number":515,"context_line":"                          filters.extract_haproxy_services,"},{"line_number":516,"context_line":"                          self.context, example_service)"},{"line_number":517,"context_line":""},{"line_number":518,"context_line":"    @mock.patch.object(filters, \u0027service_enabled\u0027)"},{"line_number":519,"context_line":"    @mock.patch.object(filters, \u0027service_mapped_to_host\u0027)"},{"line_number":520,"context_line":"    def test_service_enabled_and_mapped_to_host(self, mock_mapped,"}],"source_content_type":"text/x-python","patch_set":30,"id":"0e482024_2867ff64","line":517,"updated":"2022-07-25 09:54:17.000000000","message":"nice, this testing is more than thorough for this functionality ;-)","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"0c9cde33aa0fa59e4b2da8ddc75c2047f07aafbf","unresolved":false,"context_lines":[{"line_number":514,"context_line":"        self.assertRaises(exception.FilterError,"},{"line_number":515,"context_line":"                          filters.extract_haproxy_services,"},{"line_number":516,"context_line":"                          self.context, example_service)"},{"line_number":517,"context_line":""},{"line_number":518,"context_line":"    @mock.patch.object(filters, \u0027service_enabled\u0027)"},{"line_number":519,"context_line":"    @mock.patch.object(filters, \u0027service_mapped_to_host\u0027)"},{"line_number":520,"context_line":"    def test_service_enabled_and_mapped_to_host(self, mock_mapped,"}],"source_content_type":"text/x-python","patch_set":30,"id":"a999623b_3da6ac77","line":517,"in_reply_to":"0e482024_2867ff64","updated":"2022-07-26 08:26:17.000000000","message":"Refreshing to use a language that you can actually test, eh?","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"26f8cd5b35ad97b0100be0a5aa6b561ab0ee138c","unresolved":false,"context_lines":[{"line_number":514,"context_line":"        self.assertRaises(exception.FilterError,"},{"line_number":515,"context_line":"                          filters.extract_haproxy_services,"},{"line_number":516,"context_line":"                          self.context, example_service)"},{"line_number":517,"context_line":""},{"line_number":518,"context_line":"    @mock.patch.object(filters, \u0027service_enabled\u0027)"},{"line_number":519,"context_line":"    @mock.patch.object(filters, \u0027service_mapped_to_host\u0027)"},{"line_number":520,"context_line":"    def test_service_enabled_and_mapped_to_host(self, mock_mapped,"}],"source_content_type":"text/x-python","patch_set":30,"id":"9bd75ac3_d3f4675b","line":517,"in_reply_to":"a999623b_3da6ac77","updated":"2022-07-26 08:59:52.000000000","message":"Yeah. After the long Ansible journey, I am now a fan of having things in a regular programming language that works the way it should (TM). In fact, on that note, I have been contemplating the use of Salt for some of my needs.","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"}],"releasenotes/notes/add-firewalld-rules-based-on-enabled-services.yml":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"79e55797b2714e693bd05c0897747ba669571daa","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"features:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    Enables configuring firewalld based on enabled services."},{"line_number":5,"context_line":"    Extracts the required services and checks the external port,"},{"line_number":6,"context_line":"    then adds the ports to the firewalld public zone."},{"line_number":7,"context_line":"    Assumes that firewalld has been installed and configured before hand."}],"source_content_type":"text/x-yaml","patch_set":3,"id":"094aff1e_126c9c57","line":4,"range":{"start_line":4,"start_character":24,"end_line":4,"end_character":33},"updated":"2022-06-28 12:46:12.000000000","message":"for external API services","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"6a2067c61591e32121695a0cf5cc5a1a3e6378f7","unresolved":false,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"features:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    Enables configuring firewalld based on enabled services."},{"line_number":5,"context_line":"    Extracts the required services and checks the external port,"},{"line_number":6,"context_line":"    then adds the ports to the firewalld public zone."},{"line_number":7,"context_line":"    Assumes that firewalld has been installed and configured before hand."}],"source_content_type":"text/x-yaml","patch_set":3,"id":"0d9685b0_6765488d","line":4,"range":{"start_line":4,"start_character":24,"end_line":4,"end_character":33},"in_reply_to":"094aff1e_126c9c57","updated":"2022-06-29 08:52:04.000000000","message":"Done","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"79e55797b2714e693bd05c0897747ba669571daa","unresolved":true,"context_lines":[{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    Enables configuring firewalld based on enabled services."},{"line_number":5,"context_line":"    Extracts the required services and checks the external port,"},{"line_number":6,"context_line":"    then adds the ports to the firewalld public zone."},{"line_number":7,"context_line":"    Assumes that firewalld has been installed and configured before hand."}],"source_content_type":"text/x-yaml","patch_set":3,"id":"dbbcf655_a51bda4d","line":6,"range":{"start_line":6,"start_character":27,"end_line":6,"end_character":47},"updated":"2022-06-28 12:46:12.000000000","message":"a firewalld zone","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"6a2067c61591e32121695a0cf5cc5a1a3e6378f7","unresolved":false,"context_lines":[{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    Enables configuring firewalld based on enabled services."},{"line_number":5,"context_line":"    Extracts the required services and checks the external port,"},{"line_number":6,"context_line":"    then adds the ports to the firewalld public zone."},{"line_number":7,"context_line":"    Assumes that firewalld has been installed and configured before hand."}],"source_content_type":"text/x-yaml","patch_set":3,"id":"6413ec1c_8fbb90c2","line":6,"range":{"start_line":6,"start_character":27,"end_line":6,"end_character":47},"in_reply_to":"dbbcf655_a51bda4d","updated":"2022-06-29 08:52:04.000000000","message":"Done","commit_id":"16781afad94ef685a694e7c12d2746026d1f6558"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"585104886be07be996a8f86ac210dbb55eb19f07","unresolved":true,"context_lines":[{"line_number":4,"context_line":"    Enables configuring firewalld for external API services."},{"line_number":5,"context_line":"    Extracts the required services and checks the external port,"},{"line_number":6,"context_line":"    then adds the ports to a firewalld zone."},{"line_number":7,"context_line":"    Assumes that firewalld has been installed and configured before hand."}],"source_content_type":"text/x-yaml","patch_set":30,"id":"de1a161c_b2c2596a","line":7,"range":{"start_line":7,"start_character":61,"end_line":7,"end_character":72},"updated":"2022-07-25 09:54:17.000000000","message":"nit: this is one word","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"cdb2c54aba22b2e5aa66f21893faf759b3e11669","unresolved":false,"context_lines":[{"line_number":4,"context_line":"    Enables configuring firewalld for external API services."},{"line_number":5,"context_line":"    Extracts the required services and checks the external port,"},{"line_number":6,"context_line":"    then adds the ports to a firewalld zone."},{"line_number":7,"context_line":"    Assumes that firewalld has been installed and configured before hand."}],"source_content_type":"text/x-yaml","patch_set":30,"id":"0381c4af_3671c3ac","line":7,"range":{"start_line":7,"start_character":61,"end_line":7,"end_character":72},"in_reply_to":"de1a161c_b2c2596a","updated":"2022-07-26 17:29:44.000000000","message":"Done","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"585104886be07be996a8f86ac210dbb55eb19f07","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":30,"id":"24ab9b89_efcd66f0","line":8,"updated":"2022-07-25 09:54:17.000000000","message":"could mention the relevant variables (I think ``disable_firewall`` is the one we want to mention) and that it is off (disabled) by default to preserve backward compatibility (but it is a good practice to have the firewall configured)","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"},{"author":{"_account_id":33307,"name":"Kyle Dean","email":"k.s-dean@outlook.com","username":"k-s-dean"},"change_message_id":"cdb2c54aba22b2e5aa66f21893faf759b3e11669","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":30,"id":"f90fc634_8316ff4f","line":8,"in_reply_to":"24ab9b89_efcd66f0","updated":"2022-07-26 17:29:44.000000000","message":"Done","commit_id":"3888a929154f9ada88e0479564e10b7c705cf2ab"}]}
