)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"c6f2b7eb846f17e87d40d7d07da79565c402939b","unresolved":true,"context_lines":[{"line_number":10,"context_line":"is a part of larger patch group that\u0027s goal is"},{"line_number":11,"context_line":"to use Redis + TLS as caching backend."},{"line_number":12,"context_line":"This patch does not include caching feature yet,"},{"line_number":13,"context_line":"however it was done witch caching in mind"},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"Implements: redis-tls"},{"line_number":16,"context_line":"Partially Implements: redis-caching-backend"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":12,"id":"9786f2c0_d0e4e53a","line":13,"range":{"start_line":13,"start_character":20,"end_line":13,"end_character":25},"updated":"2024-03-07 07:17:26.000000000","message":"nit: with","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"bd4839b3d3ec5ab2c9ef3b4c4d5924da2851763e","unresolved":false,"context_lines":[{"line_number":10,"context_line":"is a part of larger patch group that\u0027s goal is"},{"line_number":11,"context_line":"to use Redis + TLS as caching backend."},{"line_number":12,"context_line":"This patch does not include caching feature yet,"},{"line_number":13,"context_line":"however it was done witch caching in mind"},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"Implements: redis-tls"},{"line_number":16,"context_line":"Partially Implements: redis-caching-backend"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":12,"id":"73414f0a_7d4d5561","line":13,"range":{"start_line":13,"start_character":20,"end_line":13,"end_character":25},"in_reply_to":"9786f2c0_d0e4e53a","updated":"2024-03-07 13:39:30.000000000","message":"Acknowledged","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"c6f2b7eb846f17e87d40d7d07da79565c402939b","unresolved":true,"context_lines":[{"line_number":14,"context_line":""},{"line_number":15,"context_line":"Implements: redis-tls"},{"line_number":16,"context_line":"Partially Implements: redis-caching-backend"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"Change-Id: I4b5f5a5afd1f6fff09b6e53c7740a210d78f0e4e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":12,"id":"2316828d_852285e6","line":17,"updated":"2024-03-07 07:17:26.000000000","message":"gerrit is not rendering links to the blueprints, I think that is because this is not in the last section, please try removing this empty line","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"bd4839b3d3ec5ab2c9ef3b4c4d5924da2851763e","unresolved":false,"context_lines":[{"line_number":14,"context_line":""},{"line_number":15,"context_line":"Implements: redis-tls"},{"line_number":16,"context_line":"Partially Implements: redis-caching-backend"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"Change-Id: I4b5f5a5afd1f6fff09b6e53c7740a210d78f0e4e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":12,"id":"a0137a0c_a1984a60","line":17,"in_reply_to":"2316828d_852285e6","updated":"2024-03-07 13:39:30.000000000","message":"Acknowledged","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"4adb4f7d9d86cd0eeb1fb07d79a6f2a31c31767b","unresolved":true,"context_lines":[{"line_number":12,"context_line":"This patch does not include caching feature yet,"},{"line_number":13,"context_line":"however it was done with caching in mind"},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"Depends-On: https://review.opendev.org/c/openstack/kolla-ansible/+/915901"},{"line_number":16,"context_line":"Partially Implements: redis-caching-backend"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"Change-Id: I4b5f5a5afd1f6fff09b6e53c7740a210d78f0e4e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":31,"id":"2ba673cf_e7425d08","line":15,"range":{"start_line":15,"start_character":0,"end_line":15,"end_character":2},"updated":"2024-07-16 15:50:05.000000000","message":"nit: you can remove the \"Depends-On\" when the patch you depend on is in the same repository, just rebase your change on top of it. Gerrit is smart enough to figure the rest out itself.\n\nYou just need Depends-On for Cross-Repository dependencies.\n\nHTH! :)","commit_id":"1ef4dabb02e638d7c555290e98707f33aea5682e"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"5b8b0147ea427ebb2aa645d1c3fc4b2959ae064b","unresolved":false,"context_lines":[{"line_number":12,"context_line":"This patch does not include caching feature yet,"},{"line_number":13,"context_line":"however it was done with caching in mind"},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"Depends-On: https://review.opendev.org/c/openstack/kolla-ansible/+/915901"},{"line_number":16,"context_line":"Partially Implements: redis-caching-backend"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"Change-Id: I4b5f5a5afd1f6fff09b6e53c7740a210d78f0e4e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":31,"id":"04e2916d_120542ee","line":15,"range":{"start_line":15,"start_character":0,"end_line":15,"end_character":2},"in_reply_to":"2ba673cf_e7425d08","updated":"2024-07-17 08:34:57.000000000","message":"Done","commit_id":"1ef4dabb02e638d7c555290e98707f33aea5682e"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"b0d5aa62cba7dbfa3009dd51472eda2c1b74d35e","unresolved":true,"context_lines":[{"line_number":12,"context_line":"This patch does not include caching feature yet,"},{"line_number":13,"context_line":"however it was done with caching in mind"},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"DependsOn: https://review.opendev.org/c/openstack/kolla/+/927741"},{"line_number":16,"context_line":"Partially Implements: redis-caching-backend"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"Change-Id: I4b5f5a5afd1f6fff09b6e53c7740a210d78f0e4e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":38,"id":"445da39a_7e6cfabe","line":15,"range":{"start_line":15,"start_character":0,"end_line":15,"end_character":9},"updated":"2024-09-04 12:46:22.000000000","message":"Depends-On","commit_id":"ea4cdd844a3fe1d06eca2684497cc41a549665fb"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"c70b44a34d07b2108210d3605bc5d3e69a65d29f","unresolved":true,"context_lines":[{"line_number":12,"context_line":"This patch does not include caching feature yet,"},{"line_number":13,"context_line":"however it was done with caching in mind"},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"DependsOn: https://review.opendev.org/c/openstack/kolla/+/927741"},{"line_number":16,"context_line":"Partially Implements: redis-caching-backend"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"Change-Id: I4b5f5a5afd1f6fff09b6e53c7740a210d78f0e4e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":38,"id":"53ae5596_3ffede2e","line":15,"range":{"start_line":15,"start_character":0,"end_line":15,"end_character":9},"in_reply_to":"445da39a_7e6cfabe","updated":"2024-09-04 12:46:51.000000000","message":"is it really needed for Redis?","commit_id":"ea4cdd844a3fe1d06eca2684497cc41a549665fb"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"e747d6b3a83e5dee3b7e937e70e7f332598351ad","unresolved":true,"context_lines":[{"line_number":12,"context_line":"This patch does not include caching feature yet,"},{"line_number":13,"context_line":"however it was done with caching in mind"},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"DependsOn: https://review.opendev.org/c/openstack/kolla/+/927741"},{"line_number":16,"context_line":"Partially Implements: redis-caching-backend"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"Change-Id: I4b5f5a5afd1f6fff09b6e53c7740a210d78f0e4e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":38,"id":"b37b0c5d_0d3bd4d0","line":15,"range":{"start_line":15,"start_character":0,"end_line":15,"end_character":9},"in_reply_to":"53ae5596_3ffede2e","updated":"2024-09-05 07:24:57.000000000","message":"Gnocchi \u003c4.6.3 isn\u0027t working properly with Redis Sentinel TLS, see gnocchi release notes for details https://github.com/gnocchixyz/gnocchi/releases/tag/4.6.3","commit_id":"ea4cdd844a3fe1d06eca2684497cc41a549665fb"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"5d66d37382c34d4984a3a0290c881c5e4310b661","unresolved":true,"context_lines":[{"line_number":12,"context_line":"This patch does not include caching feature yet,"},{"line_number":13,"context_line":"however it was done with caching in mind"},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"DependsOn: https://review.opendev.org/c/openstack/kolla/+/927741"},{"line_number":16,"context_line":"Partially Implements: redis-caching-backend"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"Change-Id: I4b5f5a5afd1f6fff09b6e53c7740a210d78f0e4e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":38,"id":"86c599ba_1e064c30","line":15,"range":{"start_line":15,"start_character":0,"end_line":15,"end_character":9},"in_reply_to":"58a3dbab_0f0e2486","updated":"2024-09-05 13:54:13.000000000","message":"Gnocchi isn\u0027t enabled on CI, that\u0027s why it\u0027s working. It\u0027s not working only when Gnocchi is enabled.","commit_id":"ea4cdd844a3fe1d06eca2684497cc41a549665fb"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"743bccd09c25abdfe35e6f928dad25308739ff90","unresolved":false,"context_lines":[{"line_number":12,"context_line":"This patch does not include caching feature yet,"},{"line_number":13,"context_line":"however it was done with caching in mind"},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"DependsOn: https://review.opendev.org/c/openstack/kolla/+/927741"},{"line_number":16,"context_line":"Partially Implements: redis-caching-backend"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"Change-Id: I4b5f5a5afd1f6fff09b6e53c7740a210d78f0e4e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":38,"id":"193e1f80_b15253cc","line":15,"range":{"start_line":15,"start_character":0,"end_line":15,"end_character":9},"in_reply_to":"8443c78a_71a15046","updated":"2024-09-05 14:56:42.000000000","message":"Done","commit_id":"ea4cdd844a3fe1d06eca2684497cc41a549665fb"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"922426ecd08e6a524d291cdefd114859785bdaa9","unresolved":true,"context_lines":[{"line_number":12,"context_line":"This patch does not include caching feature yet,"},{"line_number":13,"context_line":"however it was done with caching in mind"},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"DependsOn: https://review.opendev.org/c/openstack/kolla/+/927741"},{"line_number":16,"context_line":"Partially Implements: redis-caching-backend"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"Change-Id: I4b5f5a5afd1f6fff09b6e53c7740a210d78f0e4e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":38,"id":"8443c78a_71a15046","line":15,"range":{"start_line":15,"start_character":0,"end_line":15,"end_character":9},"in_reply_to":"86c599ba_1e064c30","updated":"2024-09-05 14:29:14.000000000","message":"so no matter \u0027DependsOn\u0027 or \u0027Depends-On\u0027 in your change because of Gnocchi not enabled on CI. but with \u0027Depends-On\u0027 instead of \u0027DependsOn\u0027 this change wouldn\u0027t be merged without dependent change.","commit_id":"ea4cdd844a3fe1d06eca2684497cc41a549665fb"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"2859a4d3b8f2c3acef6d895614b8e1d8c7b34836","unresolved":true,"context_lines":[{"line_number":12,"context_line":"This patch does not include caching feature yet,"},{"line_number":13,"context_line":"however it was done with caching in mind"},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"DependsOn: https://review.opendev.org/c/openstack/kolla/+/927741"},{"line_number":16,"context_line":"Partially Implements: redis-caching-backend"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"Change-Id: I4b5f5a5afd1f6fff09b6e53c7740a210d78f0e4e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":38,"id":"c81cc9a2_0a62b668","line":15,"range":{"start_line":15,"start_character":0,"end_line":15,"end_character":9},"in_reply_to":"b37b0c5d_0d3bd4d0","updated":"2024-09-05 07:31:39.000000000","message":"Ok. But I don\u0027t see any failed job on CI. is it used and tested?","commit_id":"ea4cdd844a3fe1d06eca2684497cc41a549665fb"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"80e4098dd7726eac1e26a57557ea7e0d003289bf","unresolved":true,"context_lines":[{"line_number":12,"context_line":"This patch does not include caching feature yet,"},{"line_number":13,"context_line":"however it was done with caching in mind"},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"DependsOn: https://review.opendev.org/c/openstack/kolla/+/927741"},{"line_number":16,"context_line":"Partially Implements: redis-caching-backend"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"Change-Id: I4b5f5a5afd1f6fff09b6e53c7740a210d78f0e4e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":38,"id":"58a3dbab_0f0e2486","line":15,"range":{"start_line":15,"start_character":0,"end_line":15,"end_character":9},"in_reply_to":"c5b9c771_74c73790","updated":"2024-09-05 09:40:51.000000000","message":"I\u0027m talking about Redis not working with old Gnocchi, but it work on CI","commit_id":"ea4cdd844a3fe1d06eca2684497cc41a549665fb"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"cbe6e54d709397f01d534a6dad33def7649a82c3","unresolved":true,"context_lines":[{"line_number":12,"context_line":"This patch does not include caching feature yet,"},{"line_number":13,"context_line":"however it was done with caching in mind"},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"DependsOn: https://review.opendev.org/c/openstack/kolla/+/927741"},{"line_number":16,"context_line":"Partially Implements: redis-caching-backend"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"Change-Id: I4b5f5a5afd1f6fff09b6e53c7740a210d78f0e4e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":38,"id":"c5b9c771_74c73790","line":15,"range":{"start_line":15,"start_character":0,"end_line":15,"end_character":9},"in_reply_to":"c81cc9a2_0a62b668","updated":"2024-09-05 08:32:53.000000000","message":"I tested it on in my local environment. \nI don\u0027t see any Zuul scenario for gnocchi.","commit_id":"ea4cdd844a3fe1d06eca2684497cc41a549665fb"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"7de9752a15e62bce9e773bd7788e2136bb85e960","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"1a86ecf8_3e41f91b","updated":"2024-02-16 09:42:08.000000000","message":"reno missing","commit_id":"f8a22eabf37c797d90a51e30f661762affdbff55"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"14c4533d059ac79627b9843719d7c1b3bebae061","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"49f53cf1_f4bc8495","in_reply_to":"1a86ecf8_3e41f91b","updated":"2024-02-16 12:08:04.000000000","message":"Acknowledged","commit_id":"f8a22eabf37c797d90a51e30f661762affdbff55"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"bcd5e99a3301e38bac800b037105903669c65482","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":3,"id":"632e90d2_6a9ffe60","updated":"2024-02-19 14:42:03.000000000","message":"it\u0027s debatable if we really want to disable non TLS ports when enabling TLS.\n\nI support this from a security POV, but I can understand users complaining about it, because it breaks existing flows when enabling TLS.\n\nThen again, the user needs to actively enable this, so all in all I\u0027m in favor of the change.\n\nBut we need to inform the user in the release note about this change.\n\nOtherwise LGTM.","commit_id":"b74011d48fee6592508334b4aad730dfbb277f29"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"517d1d23220c9e53e6b5e76de206ba12b141dcd4","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":3,"id":"da454ff2_7b537787","in_reply_to":"632e90d2_6a9ffe60","updated":"2024-02-20 09:04:20.000000000","message":"Redis + Sentinel setup doesn\u0027t work with both ports open.","commit_id":"b74011d48fee6592508334b4aad730dfbb277f29"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"986c0d589fde53d8564a34b2cc3914ff4acdd87c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"91a19369_a6f24695","in_reply_to":"da454ff2_7b537787","updated":"2024-02-20 09:04:35.000000000","message":"Acknowledged","commit_id":"b74011d48fee6592508334b4aad730dfbb277f29"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"3ddc56be3d77236db4117e2aeee708fd7d15bd57","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":7,"id":"1f850387_f94b87d3","updated":"2024-02-26 16:19:34.000000000","message":"not sure if related, but the job fails with:\n\n\n```\n\nTASK [mariadb : Creating shard root mysql user] ********************************\n\ntask path: /home/zuul/kolla-ansible-venv/share/kolla-ansible/ansible/roles/mariadb/tasks/register.yml:2\n\nMonday 26 February 2024  08:29:25 +0000 (0:00:00.100)       0:01:54.465 ******* \n\nUsing module file /home/zuul/kolla-ansible-venv/share/kolla-ansible/ansible/library/kolla_toolbox.py\n\nPipelining is enabled.\n\n\u003c173.231.255.171\u003e ESTABLISH SSH CONNECTION FOR USER: None\n\n\u003c173.231.255.171\u003e SSH: EXEC ssh -C -o ControlMaster\u003dauto -o ControlPersist\u003d300 -o StrictHostKeyChecking\u003dno -o KbdInteractiveAuthentication\u003dno -o PreferredAuthentications\u003dgssapi-with-mic,gssapi-keyex,hostbased,publickey -o PasswordAuthentication\u003dno -o ConnectTimeout\u003d10 -o \u0027ControlPath\u003d\"/home/zuul/.ansible/cp/477012de08\"\u0027 173.231.255.171 \u0027/bin/sh -c \u0027\"\u0027\"\u0027sudo -H -S -n  -u root /bin/sh -c \u0027\"\u0027\"\u0027\"\u0027\"\u0027\"\u0027\"\u0027\"\u0027\"\u0027echo BECOME-SUCCESS-gagpjchailnbfndfcdnkgipjnfbjuygc ; /usr/bin/python3\u0027\"\u0027\"\u0027\"\u0027\"\u0027\"\u0027\"\u0027\"\u0027\"\u0027 \u0026\u0026 sleep 0\u0027\"\u0027\"\u0027\u0027\n\nEscalation succeeded\n\n\u003c173.231.255.171\u003e (1, b\u0027\\n{\"failed\": true, \"msg\": \"Can not parse the inner module output: b\\\u0027ERROR! Invalid callback for stdout specified: json\\\\\\\\n\\\u0027\", \"exception\": \"  File \\\\\"/tmp/ansible_kolla_toolbox_payload_ok9r7ez7/ansible_kolla_toolbox_payload.zip/ansible/modules/kolla_toolbox.py\\\\\", line 187, in main\\\\n  File \\\\\"/usr/lib/python3.10/json/__init__.py\\\\\", line 346, in loads\\\\n    return _default_decoder.decode(s)\\\\n  File \\\\\"/usr/lib/python3.10/json/decoder.py\\\\\", line 337, in decode\\\\n    obj, end \u003d self.raw_decode(s, idx\u003d_w(s, 0).end())\\\\n  File \\\\\"/usr/lib/python3.10/json/decoder.py\\\\\", line 355, in raw_decode\\\\n    raise JSONDecodeError(\\\\\"Expecting value\\\\\", s, err.value) from None\\\\n\", \"invocation\": {\"module_args\": {\"container_engine\": \"docker\", \"module_name\": \"mysql_user\", \"module_args\": \"{\\\u0027login_host\\\u0027: \\\u0027192.0.2.1\\\u0027, \\\u0027login_port\\\u0027: \\\u00273306\\\u0027, \\\u0027login_user\\\u0027: \\\u0027root\\\u0027, \\\u0027login_password\\\u0027: \\\u0027bTGlSHlNzaLiFgq7VkTnqRJsLuKMOme5iOmTXRdW\\\u0027, \\\u0027name\\\u0027: \\\u0027root\\\u0027, \\\u0027password\\\u0027: \\\u0027bTGlSHlNzaLiFgq7VkTnqRJsLuKMOme5iOmTXRdW\\\u0027, \\\u0027host\\\u0027: \\\u0027%\\\u0027, \\\u0027priv\\\u0027: \\\u0027*.*:ALL,GRANT\\\u0027}\", \"api_version\": \"auto\", \"timeout\": 180, \"module_extra_vars\": null, \"user\": null}}}\\n\u0027, b\u0027/tmp/ansible_kolla_toolbox_payload_ok9r7ez7/ansible_kolla_toolbox_payload.zip/ansible/modules/kolla_toolbox.py:15: DeprecationWarning: The distutils package is deprecated and slated for removal in Python 3.12. Use setuptools or check PEP 632 for potential alternatives\\n\u0027)\n\n\u003c173.231.255.171\u003e Failed to connect to the host via ssh: /tmp/ansible_kolla_toolbox_payload_ok9r7ez7/ansible_kolla_toolbox_payload.zip/ansible/modules/kolla_toolbox.py:15: DeprecationWarning: The distutils package is deprecated and slated for removal in Python 3.12. Use setuptools or check PEP 632 for potential alternatives\n\nThe full traceback is:\n\n  File \"/tmp/ansible_kolla_toolbox_payload_ok9r7ez7/ansible_kolla_toolbox_payload.zip/ansible/modules/kolla_toolbox.py\", line 187, in main\n\n  File \"/usr/lib/python3.10/json/__init__.py\", line 346, in loads\n\n    return _default_decoder.decode(s)\n\n  File \"/usr/lib/python3.10/json/decoder.py\", line 337, in decode\n\n    obj, end \u003d self.raw_decode(s, idx\u003d_w(s, 0).end())\n\n  File \"/usr/lib/python3.10/json/decoder.py\", line 355, in raw_decode\n\n    raise JSONDecodeError(\"Expecting value\", s, err.value) from None\n\nfatal: [primary]: FAILED! \u003d\u003e {\n\n    \"changed\": false,\n\n    \"invocation\": {\n\n        \"module_args\": {\n\n            \"api_version\": \"auto\",\n\n            \"container_engine\": \"docker\",\n\n            \"module_args\": \"{\u0027login_host\u0027: \u0027192.0.2.1\u0027, \u0027login_port\u0027: \u00273306\u0027, \u0027login_user\u0027: \u0027root\u0027, \u0027login_password\u0027: \u0027bTGlSHlNzaLiFgq7VkTnqRJsLuKMOme5iOmTXRdW\u0027, \u0027name\u0027: \u0027root\u0027, \u0027password\u0027: \u0027bTGlSHlNzaLiFgq7VkTnqRJsLuKMOme5iOmTXRdW\u0027, \u0027host\u0027: \u0027%\u0027, \u0027priv\u0027: \u0027*.*:ALL,GRANT\u0027}\",\n\n            \"module_extra_vars\": null,\n\n            \"module_name\": \"mysql_user\",\n\n            \"timeout\": 180,\n\n            \"user\": null\n\n        }\n\n    },\n\n    \"msg\": \"Can not parse the inner module output: b\u0027ERROR! Invalid callback for stdout specified: json\\\\n\u0027\"\n\n}\n\n\nPLAY RECAP *********************************************************************\n\nprimary                    : ok\u003d90   changed\u003d51   unreachable\u003d0    failed\u003d1    skipped\u003d104  rescued\u003d0    ignored\u003d1   \n```\n\ninvestigating..","commit_id":"73bc93353abf9f3cb39d309aa21e3263e1b4d264"},{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"cc365442d35e6eca1be566dd329e64b1c87ee0eb","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"b27a3762_51465f90","updated":"2024-02-26 08:14:12.000000000","message":"recheck (cephadm upgrade jobs should be fixed)","commit_id":"73bc93353abf9f3cb39d309aa21e3263e1b4d264"},{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"691689f0922287ee3dd2c641492f93219e98e3a2","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"e1cdfa64_7aabd929","updated":"2024-02-27 06:46:17.000000000","message":"recheck - new toolbox image landed, hopefully it has the required collections","commit_id":"73bc93353abf9f3cb39d309aa21e3263e1b4d264"},{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"691689f0922287ee3dd2c641492f93219e98e3a2","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"44764940_69563255","in_reply_to":"1f850387_f94b87d3","updated":"2024-02-27 06:46:17.000000000","message":"It was caused by no galaxy collections installed in kolla-toolbox, fixed by a series of backports - should be fine now.","commit_id":"73bc93353abf9f3cb39d309aa21e3263e1b4d264"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"147eb4899033b003cde653ac0f5e097177b5da93","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":8,"id":"613aee28_d2b8211d","updated":"2024-02-27 13:41:55.000000000","message":"it might be good to also provide updated documentation, e.g. the TLS guide naturally doesn\u0027t mention redis at all:\n\nhttps://docs.openstack.org/kolla-ansible/latest/admin/tls.html","commit_id":"401fb65f715c001ee845ecafbf99ca926c39b206"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"08dce2894c0f68a56c418f5139e153e77f6fd4fe","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"d890c2d1_736307f9","in_reply_to":"37bbd809_43c6f8d0","updated":"2024-02-28 16:18:34.000000000","message":"Acknowledged","commit_id":"401fb65f715c001ee845ecafbf99ca926c39b206"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"1cd8f75727377940d174a094c0101015e4cfc813","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":8,"id":"37bbd809_43c6f8d0","in_reply_to":"613aee28_d2b8211d","updated":"2024-02-27 15:48:36.000000000","message":"Ok, I\u0027ll update that tomorrow.","commit_id":"401fb65f715c001ee845ecafbf99ca926c39b206"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"cee9475902ec060901bd74827313f6251537d2f1","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":12,"id":"afea9875_c9eb1c2b","updated":"2024-03-07 08:52:06.000000000","message":"Thank you for your review. I will add your suggested changes later today.","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"c6f2b7eb846f17e87d40d7d07da79565c402939b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":12,"id":"c205b271_508e8c91","updated":"2024-03-07 07:17:26.000000000","message":"it is really difficult to review this without any test job","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"4f0ac57762d0df7841e06d6b6b5e9de381837c99","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":14,"id":"c47c7be7_e134d19e","updated":"2024-03-11 15:21:35.000000000","message":"almost LGTM, see some commments attached.","commit_id":"49ffbb04fc56be90e9e4cf727eb40593357ef04c"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"a2b1f9dc11f8bc8d29770295af4f6555c7745148","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":15,"id":"ede78c63_5b783bdd","updated":"2024-04-15 11:38:31.000000000","message":"Thanks, for review I\u0027ll fix the conditions later.","commit_id":"f782094befbfe762912cf95fdc4b719a030f7329"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"b0f64cd3790274a558cbbb44412afd88ff49bede","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":15,"id":"814a46eb_990b593d","updated":"2024-03-12 14:55:51.000000000","message":"looking into non voting CI failures, but LGTM so far!","commit_id":"f782094befbfe762912cf95fdc4b719a030f7329"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"b13e821c22469e47e785009d9905cb9ec3152f8d","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":20,"id":"ba6c9e5c_d62ff2d2","updated":"2024-05-02 08:34:49.000000000","message":"Thanks for the review. I think the redis string needs ssl arguments, gonna add them later","commit_id":"2eaa18ccc358fb80b45a4f26486812b55bf349ae"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"c84365a0424654973166794e3679e2370e7e15b0","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":20,"id":"dac55e74_46bcae17","updated":"2024-04-30 13:30:23.000000000","message":"almost there I would say, most of this LGTM.","commit_id":"2eaa18ccc358fb80b45a4f26486812b55bf349ae"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"77a08100658982ea587738e80721e09556853e27","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":22,"id":"06e46dd5_c66b362d","updated":"2024-05-14 08:59:02.000000000","message":"Code LGTM, but imho the build failures need some investigation before giving this +1.","commit_id":"035bbe6757b946abc34c93e02055e46412c4f93b"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"672e161120e6f4c0842e7a8c7c1f3d53f932cbdf","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":28,"id":"3c645e56_b2cc9aee","updated":"2024-06-27 15:14:21.000000000","message":"a cautious +1 from me, as the patch is really large. I did re-review it multiple times but my experience tells me it\u0027s easy to overlook something in patches this large.","commit_id":"bcb48862ff5d1c951bb167e9b8d60db590b1b106"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"095cfe49ebfe27033cd966f084bf7b75b5184b28","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":38,"id":"afaf7bf1_19803943","updated":"2024-09-04 09:55:28.000000000","message":"still looking good, let\u0027s wait for CI. :)","commit_id":"ea4cdd844a3fe1d06eca2684497cc41a549665fb"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"0924932357f1d5c5943fea2d6a55b58abec2644d","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":39,"id":"ef9634b5_a25c903e","updated":"2024-09-05 14:45:10.000000000","message":"ideal","commit_id":"26e060ba4cea9e31cc375c6bc21c83b18d4d9793"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"0ee5bc3823ebe5e40e73e12346d7da37eab8adeb","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":39,"id":"f5533e70_dfe245b0","updated":"2024-09-06 07:56:51.000000000","message":"recheck FAILED: Instance failed to become active after resize confirm in test-core-openstack","commit_id":"26e060ba4cea9e31cc375c6bc21c83b18d4d9793"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"e64070b3e10f19f019b0b9a090d7fe126dbcb780","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":39,"id":"a15cbb30_9690a716","updated":"2024-09-06 06:46:47.000000000","message":"recheck podman","commit_id":"26e060ba4cea9e31cc375c6bc21c83b18d4d9793"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"9e6408947d1d660bdb7401c9fa7a33b2448e1f12","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":39,"id":"610c753c_9a114258","in_reply_to":"a15cbb30_9690a716","updated":"2024-09-06 07:56:58.000000000","message":"Done","commit_id":"26e060ba4cea9e31cc375c6bc21c83b18d4d9793"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"d56f161d860644e72639b29ed6f3275e9f136b35","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":43,"id":"b852ef60_ca5295d8","updated":"2025-01-27 07:39:07.000000000","message":"recheck dashboard failure in ubuntu upgrade","commit_id":"fbb64054d468878c5a339638a3b021606af02811"}],"ansible/group_vars/all.yml":[{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"bcd5e99a3301e38bac800b037105903669c65482","unresolved":true,"context_lines":[{"line_number":618,"context_line":"rabbitmq_prometheus_port: \"15692\""},{"line_number":619,"context_line":""},{"line_number":620,"context_line":"redis_username: \"default\""},{"line_number":621,"context_line":"redis_port: \"6379\""},{"line_number":622,"context_line":"redis_sentinel_port: \"26379\""},{"line_number":623,"context_line":"redis_tls_port: \"6443\""},{"line_number":624,"context_line":"redis_sentinel_tls_port: \"26443\""}],"source_content_type":"text/x-yaml","patch_set":3,"id":"4dcc5e17_1aa75975","line":621,"range":{"start_line":621,"start_character":0,"end_line":621,"end_character":10},"updated":"2024-02-19 14:42:03.000000000","message":"just for the record, in this config redis still listens on non encrypted ports, see the docs:\n\nhttps://redis.io/docs/management/security/encryption/\n\nif we want to be able to only listen on TLS encrypted ports we must, afaik, set `redis_port` to `0`.","commit_id":"b74011d48fee6592508334b4aad730dfbb277f29"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"517d1d23220c9e53e6b5e76de206ba12b141dcd4","unresolved":false,"context_lines":[{"line_number":618,"context_line":"rabbitmq_prometheus_port: \"15692\""},{"line_number":619,"context_line":""},{"line_number":620,"context_line":"redis_username: \"default\""},{"line_number":621,"context_line":"redis_port: \"6379\""},{"line_number":622,"context_line":"redis_sentinel_port: \"26379\""},{"line_number":623,"context_line":"redis_tls_port: \"6443\""},{"line_number":624,"context_line":"redis_sentinel_tls_port: \"26443\""}],"source_content_type":"text/x-yaml","patch_set":3,"id":"ce758a9a_4dac73fd","line":621,"range":{"start_line":621,"start_character":0,"end_line":621,"end_character":10},"in_reply_to":"4dcc5e17_1aa75975","updated":"2024-02-20 09:04:20.000000000","message":"Acknowledged","commit_id":"b74011d48fee6592508334b4aad730dfbb277f29"},{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"13ecd321a479ee0314ca8d7e4700e1076313fd21","unresolved":true,"context_lines":[{"line_number":621,"context_line":"redis_port: \"6379\""},{"line_number":622,"context_line":"redis_sentinel_port: \"26379\""},{"line_number":623,"context_line":"# Enabling TLS blocks non-TLS port"},{"line_number":624,"context_line":"redis_enable_tls: \"no\""},{"line_number":625,"context_line":"redis_tls_port: \"6443\""},{"line_number":626,"context_line":"redis_sentinel_tls_port: \"26443\""},{"line_number":627,"context_line":"redis_tls_certfile: \"redis-cert.pem\""}],"source_content_type":"text/x-yaml","patch_set":10,"id":"0c7546fe_c55866b8","line":624,"updated":"2024-02-28 14:27:11.000000000","message":"\"{{ kolla_enable_tls_backend }}\"","commit_id":"623d0f80a33ea09944f3810e7b46e98d511a5edd"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"91bc04094e1817e88ad746fa467810f48209f3ff","unresolved":false,"context_lines":[{"line_number":621,"context_line":"redis_port: \"6379\""},{"line_number":622,"context_line":"redis_sentinel_port: \"26379\""},{"line_number":623,"context_line":"# Enabling TLS blocks non-TLS port"},{"line_number":624,"context_line":"redis_enable_tls: \"no\""},{"line_number":625,"context_line":"redis_tls_port: \"6443\""},{"line_number":626,"context_line":"redis_sentinel_tls_port: \"26443\""},{"line_number":627,"context_line":"redis_tls_certfile: \"redis-cert.pem\""}],"source_content_type":"text/x-yaml","patch_set":10,"id":"c30da1b7_6fda45bf","line":624,"in_reply_to":"0c7546fe_c55866b8","updated":"2024-02-28 15:27:57.000000000","message":"Acknowledged","commit_id":"623d0f80a33ea09944f3810e7b46e98d511a5edd"},{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"13ecd321a479ee0314ca8d7e4700e1076313fd21","unresolved":true,"context_lines":[{"line_number":622,"context_line":"redis_sentinel_port: \"26379\""},{"line_number":623,"context_line":"# Enabling TLS blocks non-TLS port"},{"line_number":624,"context_line":"redis_enable_tls: \"no\""},{"line_number":625,"context_line":"redis_tls_port: \"6443\""},{"line_number":626,"context_line":"redis_sentinel_tls_port: \"26443\""},{"line_number":627,"context_line":"redis_tls_certfile: \"redis-cert.pem\""},{"line_number":628,"context_line":"redis_tls_keyfile: \"redis-key.pem\""}],"source_content_type":"text/x-yaml","patch_set":10,"id":"00e5195a_901f19df","line":625,"updated":"2024-02-28 14:27:11.000000000","message":"I don\u0027t think that\u0027s a good idea - that\u0027s default Kubernetes API port","commit_id":"623d0f80a33ea09944f3810e7b46e98d511a5edd"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"91bc04094e1817e88ad746fa467810f48209f3ff","unresolved":false,"context_lines":[{"line_number":622,"context_line":"redis_sentinel_port: \"26379\""},{"line_number":623,"context_line":"# Enabling TLS blocks non-TLS port"},{"line_number":624,"context_line":"redis_enable_tls: \"no\""},{"line_number":625,"context_line":"redis_tls_port: \"6443\""},{"line_number":626,"context_line":"redis_sentinel_tls_port: \"26443\""},{"line_number":627,"context_line":"redis_tls_certfile: \"redis-cert.pem\""},{"line_number":628,"context_line":"redis_tls_keyfile: \"redis-key.pem\""}],"source_content_type":"text/x-yaml","patch_set":10,"id":"24661079_e22e2a48","line":625,"in_reply_to":"00e5195a_901f19df","updated":"2024-02-28 15:27:57.000000000","message":"Didn\u0027t realize that, I\u0027ll just use another port numbers","commit_id":"623d0f80a33ea09944f3810e7b46e98d511a5edd"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"4d012702ed6f88d4cb300a2729085e7cb9822b21","unresolved":false,"context_lines":[{"line_number":622,"context_line":"redis_sentinel_port: \"26379\""},{"line_number":623,"context_line":"# Enabling TLS blocks non-TLS port"},{"line_number":624,"context_line":"redis_enable_tls: \"{{ kolla_enable_tls_backend }}\""},{"line_number":625,"context_line":"redis_tls_port: \"6378\""},{"line_number":626,"context_line":"redis_sentinel_tls_port: \"26378\""},{"line_number":627,"context_line":"redis_tls_certfile: \"redis-cert.pem\""},{"line_number":628,"context_line":"redis_tls_keyfile: \"redis-key.pem\""}],"source_content_type":"text/x-yaml","patch_set":11,"id":"bd10485e_f200ed23","line":625,"range":{"start_line":625,"start_character":17,"end_line":625,"end_character":21},"updated":"2024-02-28 15:50:45.000000000","message":"at least, according to https://wintelguy.com/port-search/6378 this seems like it\u0027s still a free port :)","commit_id":"f0d34317c0cbda9751544904719e8d3cb6f6948e"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"4d012702ed6f88d4cb300a2729085e7cb9822b21","unresolved":false,"context_lines":[{"line_number":623,"context_line":"# Enabling TLS blocks non-TLS port"},{"line_number":624,"context_line":"redis_enable_tls: \"{{ kolla_enable_tls_backend }}\""},{"line_number":625,"context_line":"redis_tls_port: \"6378\""},{"line_number":626,"context_line":"redis_sentinel_tls_port: \"26378\""},{"line_number":627,"context_line":"redis_tls_certfile: \"redis-cert.pem\""},{"line_number":628,"context_line":"redis_tls_keyfile: \"redis-key.pem\""},{"line_number":629,"context_line":"redis_tls_use_openstack_ca: \"yes\""}],"source_content_type":"text/x-yaml","patch_set":11,"id":"8308cdb8_335eb6f8","line":626,"range":{"start_line":626,"start_character":26,"end_line":626,"end_character":31},"updated":"2024-02-28 15:50:45.000000000","message":"dito","commit_id":"f0d34317c0cbda9751544904719e8d3cb6f6948e"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"7a1d476020f503995e171005de041e8838f6a0e3","unresolved":true,"context_lines":[{"line_number":617,"context_line":"rabbitmq_epmd_port: \"4369\""},{"line_number":618,"context_line":"rabbitmq_prometheus_port: \"15692\""},{"line_number":619,"context_line":""},{"line_number":620,"context_line":"redis_username: \"default\""},{"line_number":621,"context_line":"redis_port: \"6379\""},{"line_number":622,"context_line":"redis_sentinel_port: \"26379\""},{"line_number":623,"context_line":"# Enabling TLS blocks non-TLS port"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"db7365a2_91b23d1b","line":620,"range":{"start_line":620,"start_character":0,"end_line":620,"end_character":14},"updated":"2024-03-06 14:32:37.000000000","message":"not used anywhere. lost something?","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"b0f64cd3790274a558cbbb44412afd88ff49bede","unresolved":false,"context_lines":[{"line_number":617,"context_line":"rabbitmq_epmd_port: \"4369\""},{"line_number":618,"context_line":"rabbitmq_prometheus_port: \"15692\""},{"line_number":619,"context_line":""},{"line_number":620,"context_line":"redis_username: \"default\""},{"line_number":621,"context_line":"redis_port: \"6379\""},{"line_number":622,"context_line":"redis_sentinel_port: \"26379\""},{"line_number":623,"context_line":"# Enabling TLS blocks non-TLS port"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"631f1deb_2769e26d","line":620,"range":{"start_line":620,"start_character":0,"end_line":620,"end_character":14},"in_reply_to":"db7365a2_91b23d1b","updated":"2024-03-12 14:55:51.000000000","message":"Done","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"c84365a0424654973166794e3679e2370e7e15b0","unresolved":true,"context_lines":[{"line_number":955,"context_line":"####################"},{"line_number":956,"context_line":"# Redis options"},{"line_number":957,"context_line":"####################"},{"line_number":958,"context_line":"redis_connection_string: \"redis://{% for host in groups[\u0027redis\u0027] %}{% if host \u003d\u003d groups[\u0027redis\u0027][0] %}admin:{{ redis_master_password }}@{{ \u0027api\u0027 | kolla_address(host) | put_address_in_context(\u0027url\u0027) }}:{{ redis_sentinel_port }}?sentinel\u003dkolla{% else %}\u0026sentinel_fallback\u003d{{ \u0027api\u0027 | kolla_address(host) | put_address_in_context(\u0027url\u0027) }}:{{ redis_sentinel_port }}{% endif %}{% endfor %}{{ redis_connection_string_extras }}\""},{"line_number":959,"context_line":"redis_connection_string_extras: \"\u0026db\u003d0\u0026socket_timeout\u003d60\u0026retry_on_timeout\u003dyes\""},{"line_number":960,"context_line":""},{"line_number":961,"context_line":"####################"}],"source_content_type":"text/x-yaml","patch_set":16,"id":"5378bc92_3cc20c17","line":958,"range":{"start_line":958,"start_character":81,"end_line":958,"end_character":99},"updated":"2024-04-30 13:30:23.000000000","message":"I\u0027m not sure it\u0027s a good idea to give the first redis host in this group some kind of special meaning. Can we avoid that? e.g. hosts in an inventory file can get shuffled around in practice and another hosts ends up being the \"first\", would that be problematic for redis?","commit_id":"7246ee03caad28e08f355123c8ac68bf3993bacb"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"a4ef7dcfd8c77ce40f4a46219947b1fda0804e8a","unresolved":true,"context_lines":[{"line_number":955,"context_line":"####################"},{"line_number":956,"context_line":"# Redis options"},{"line_number":957,"context_line":"####################"},{"line_number":958,"context_line":"redis_connection_string: \"redis://{% for host in groups[\u0027redis\u0027] %}{% if host \u003d\u003d groups[\u0027redis\u0027][0] %}admin:{{ redis_master_password }}@{{ \u0027api\u0027 | kolla_address(host) | put_address_in_context(\u0027url\u0027) }}:{{ redis_sentinel_port }}?sentinel\u003dkolla{% else %}\u0026sentinel_fallback\u003d{{ \u0027api\u0027 | kolla_address(host) | put_address_in_context(\u0027url\u0027) }}:{{ redis_sentinel_port }}{% endif %}{% endfor %}{{ redis_connection_string_extras }}\""},{"line_number":959,"context_line":"redis_connection_string_extras: \"\u0026db\u003d0\u0026socket_timeout\u003d60\u0026retry_on_timeout\u003dyes\""},{"line_number":960,"context_line":""},{"line_number":961,"context_line":"####################"}],"source_content_type":"text/x-yaml","patch_set":16,"id":"defc7a8b_646587a8","line":958,"range":{"start_line":958,"start_character":81,"end_line":958,"end_character":99},"in_reply_to":"3d36e66f_3758ff25","updated":"2024-05-03 16:35:03.000000000","message":"I just updated it so all services that use redis can use TLS, which means they need the certificate in containers. It is quite a big patch now, shall we split it ? I don\u0027t see how though.","commit_id":"7246ee03caad28e08f355123c8ac68bf3993bacb"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"b13e821c22469e47e785009d9905cb9ec3152f8d","unresolved":true,"context_lines":[{"line_number":955,"context_line":"####################"},{"line_number":956,"context_line":"# Redis options"},{"line_number":957,"context_line":"####################"},{"line_number":958,"context_line":"redis_connection_string: \"redis://{% for host in groups[\u0027redis\u0027] %}{% if host \u003d\u003d groups[\u0027redis\u0027][0] %}admin:{{ redis_master_password }}@{{ \u0027api\u0027 | kolla_address(host) | put_address_in_context(\u0027url\u0027) }}:{{ redis_sentinel_port }}?sentinel\u003dkolla{% else %}\u0026sentinel_fallback\u003d{{ \u0027api\u0027 | kolla_address(host) | put_address_in_context(\u0027url\u0027) }}:{{ redis_sentinel_port }}{% endif %}{% endfor %}{{ redis_connection_string_extras }}\""},{"line_number":959,"context_line":"redis_connection_string_extras: \"\u0026db\u003d0\u0026socket_timeout\u003d60\u0026retry_on_timeout\u003dyes\""},{"line_number":960,"context_line":""},{"line_number":961,"context_line":"####################"}],"source_content_type":"text/x-yaml","patch_set":16,"id":"3d36e66f_3758ff25","line":958,"range":{"start_line":958,"start_character":81,"end_line":958,"end_character":99},"in_reply_to":"5378bc92_3cc20c17","updated":"2024-05-02 08:34:49.000000000","message":"It\u0027s connection string for coordination - [Tooz](https://docs.openstack.org/tooz/latest/) library, i am not using it in my cache-related pull requests. From the [documentation](https://docs.openstack.org/tooz/latest/reference/index.html#redis) it seems this is a right way of doing it.\n\nHowever, this is missing ssl-related arguments , we need to add them in.\n\nFor that I need to test it first, so we\u0027re sure they are correctly put in.","commit_id":"7246ee03caad28e08f355123c8ac68bf3993bacb"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"77a08100658982ea587738e80721e09556853e27","unresolved":false,"context_lines":[{"line_number":955,"context_line":"####################"},{"line_number":956,"context_line":"# Redis options"},{"line_number":957,"context_line":"####################"},{"line_number":958,"context_line":"redis_connection_string: \"redis://{% for host in groups[\u0027redis\u0027] %}{% if host \u003d\u003d groups[\u0027redis\u0027][0] %}admin:{{ redis_master_password }}@{{ \u0027api\u0027 | kolla_address(host) | put_address_in_context(\u0027url\u0027) }}:{{ redis_sentinel_port }}?sentinel\u003dkolla{% else %}\u0026sentinel_fallback\u003d{{ \u0027api\u0027 | kolla_address(host) | put_address_in_context(\u0027url\u0027) }}:{{ redis_sentinel_port }}{% endif %}{% endfor %}{{ redis_connection_string_extras }}\""},{"line_number":959,"context_line":"redis_connection_string_extras: \"\u0026db\u003d0\u0026socket_timeout\u003d60\u0026retry_on_timeout\u003dyes\""},{"line_number":960,"context_line":""},{"line_number":961,"context_line":"####################"}],"source_content_type":"text/x-yaml","patch_set":16,"id":"44121184_81d3136f","line":958,"range":{"start_line":958,"start_character":81,"end_line":958,"end_character":99},"in_reply_to":"defc7a8b_646587a8","updated":"2024-05-14 08:59:02.000000000","message":"Acknowledged","commit_id":"7246ee03caad28e08f355123c8ac68bf3993bacb"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"c84365a0424654973166794e3679e2370e7e15b0","unresolved":true,"context_lines":[{"line_number":626,"context_line":"redis_tls_certfile: \"redis-cert.pem\""},{"line_number":627,"context_line":"redis_tls_keyfile: \"redis-key.pem\""},{"line_number":628,"context_line":"redis_tls_use_openstack_ca: \"yes\""},{"line_number":629,"context_line":"# No effect if redis_tls_use_openstack_ca: \"yes\""},{"line_number":630,"context_line":""},{"line_number":631,"context_line":""},{"line_number":632,"context_line":"sahara_internal_fqdn: \"{{ kolla_internal_fqdn }}\""}],"source_content_type":"text/x-yaml","patch_set":20,"id":"b39f6cf1_365914ee","line":629,"range":{"start_line":629,"start_character":0,"end_line":629,"end_character":2},"updated":"2024-04-30 13:30:23.000000000","message":"is this a leftover comment from a previous iteration?","commit_id":"2eaa18ccc358fb80b45a4f26486812b55bf349ae"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"b13e821c22469e47e785009d9905cb9ec3152f8d","unresolved":false,"context_lines":[{"line_number":626,"context_line":"redis_tls_certfile: \"redis-cert.pem\""},{"line_number":627,"context_line":"redis_tls_keyfile: \"redis-key.pem\""},{"line_number":628,"context_line":"redis_tls_use_openstack_ca: \"yes\""},{"line_number":629,"context_line":"# No effect if redis_tls_use_openstack_ca: \"yes\""},{"line_number":630,"context_line":""},{"line_number":631,"context_line":""},{"line_number":632,"context_line":"sahara_internal_fqdn: \"{{ kolla_internal_fqdn }}\""}],"source_content_type":"text/x-yaml","patch_set":20,"id":"ccd19d77_ef0676f5","line":629,"range":{"start_line":629,"start_character":0,"end_line":629,"end_character":2},"in_reply_to":"b39f6cf1_365914ee","updated":"2024-05-02 08:34:49.000000000","message":"Done","commit_id":"2eaa18ccc358fb80b45a4f26486812b55bf349ae"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"77a08100658982ea587738e80721e09556853e27","unresolved":false,"context_lines":[{"line_number":951,"context_line":"####################"},{"line_number":952,"context_line":"# Redis options"},{"line_number":953,"context_line":"####################"},{"line_number":954,"context_line":"redis_tls_args: \"\u0026ssl\u003dtrue\u0026sentinel_ssl\u003dtrue\u0026ssl_ca_certs\u003d{{ openstack_cacert  if redis_tls_use_openstack_ca | bool else \u0027/etc/redis/certs/ca-certificate.pem\u0027 }}\u0026ssl_certfile\u003d/etc/redis/certs/redis-cert.pem\u0026ssl_keyfile\u003d/etc/redis/certs/redis-key.pem\""},{"line_number":955,"context_line":"redis_connection_string: \"redis://{% for host in groups[\u0027redis\u0027] %}{% if host \u003d\u003d groups[\u0027redis\u0027][0] %}default:{{ redis_master_password }}@{{ \u0027api\u0027 | kolla_address(host) | put_address_in_context(\u0027url\u0027) }}:{{ redis_sentinel_tls_port if redis_enable_tls | bool else redis_sentinel_port }}?sentinel\u003dkolla{% else %}\u0026sentinel_fallback\u003d{{ \u0027api\u0027 | kolla_address(host) | put_address_in_context(\u0027url\u0027) }}:{{ redis_sentinel_tls_port if redis_enable_tls | bool else redis_sentinel_port  }}{% endif %}{% endfor %}{{ redis_tls_args if redis_enable_tls | bool  }}{{ redis_connection_string_extras }}\""},{"line_number":956,"context_line":"redis_connection_string_extras: \"\u0026db\u003d0\u0026socket_timeout\u003d60\u0026retry_on_timeout\u003dyes\""},{"line_number":957,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":22,"id":"e6b30175_eae7015c","line":954,"range":{"start_line":954,"start_character":0,"end_line":954,"end_character":2},"updated":"2024-05-14 08:59:02.000000000","message":"style nit: This is still somewhat ugly and long, but I currently have no better idea to simply this. If anybody has, please speak up.","commit_id":"035bbe6757b946abc34c93e02055e46412c4f93b"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"c1e38b205e2bb98aeacdd708821649119385c427","unresolved":true,"context_lines":[{"line_number":903,"context_line":"# Cache Options"},{"line_number":904,"context_line":"####################"},{"line_number":905,"context_line":"cache_enabled: \"yes\""},{"line_number":906,"context_line":"# valid values: [\"memcached\", \"redis\"]"},{"line_number":907,"context_line":"cache_backend: \"memcached\""},{"line_number":908,"context_line":"cache_additional_backend_arguments: {}"},{"line_number":909,"context_line":"memcache_servers: \"{% for host in groups[\u0027memcached\u0027] %}{{ \u0027api\u0027 | kolla_address(host) | put_address_in_context(\u0027memcache\u0027) }}:{{ memcached_port }}{% if not loop.last %},{% endif %}{% endfor %}\""},{"line_number":910,"context_line":"redis_cache_sentinel_servers: \"{% for host in groups[\u0027redis\u0027] %}{{ \u0027api\u0027 | kolla_address(host) | put_address_in_context(\u0027url\u0027) ~ \u0027:\u0027 ~  ( redis_sentinel_tls_port if redis_enable_tls | bool else redis_sentinel_port ) ~ ( \u0027,\u0027 if  loop.revindex \u003e 1  else  \u0027\u0027 )  }}{% endfor %}\""}],"source_content_type":"text/x-yaml","patch_set":28,"id":"160f6a6f_661407c6","line":907,"range":{"start_line":906,"start_character":0,"end_line":907,"end_character":25},"updated":"2024-07-10 15:52:57.000000000","message":"we could add a precheck if the value is set correctly if `cache_enabled` is set.","commit_id":"bcb48862ff5d1c951bb167e9b8d60db590b1b106"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"9ff4fd9e26e9029c894a55f23e210e13b33a94e6","unresolved":false,"context_lines":[{"line_number":903,"context_line":"# Cache Options"},{"line_number":904,"context_line":"####################"},{"line_number":905,"context_line":"cache_enabled: \"yes\""},{"line_number":906,"context_line":"# valid values: [\"memcached\", \"redis\"]"},{"line_number":907,"context_line":"cache_backend: \"memcached\""},{"line_number":908,"context_line":"cache_additional_backend_arguments: {}"},{"line_number":909,"context_line":"memcache_servers: \"{% for host in groups[\u0027memcached\u0027] %}{{ \u0027api\u0027 | kolla_address(host) | put_address_in_context(\u0027memcache\u0027) }}:{{ memcached_port }}{% if not loop.last %},{% endif %}{% endfor %}\""},{"line_number":910,"context_line":"redis_cache_sentinel_servers: \"{% for host in groups[\u0027redis\u0027] %}{{ \u0027api\u0027 | kolla_address(host) | put_address_in_context(\u0027url\u0027) ~ \u0027:\u0027 ~  ( redis_sentinel_tls_port if redis_enable_tls | bool else redis_sentinel_port ) ~ ( \u0027,\u0027 if  loop.revindex \u003e 1  else  \u0027\u0027 )  }}{% endfor %}\""}],"source_content_type":"text/x-yaml","patch_set":28,"id":"494428d6_ab8b9b50","line":907,"range":{"start_line":906,"start_character":0,"end_line":907,"end_character":25},"in_reply_to":"160f6a6f_661407c6","updated":"2024-07-16 10:52:53.000000000","message":"Done","commit_id":"bcb48862ff5d1c951bb167e9b8d60db590b1b106"},{"author":{"_account_id":23084,"name":"Bartosz Bezak","email":"bartosz@stackhpc.com","username":"b.bezak"},"change_message_id":"02fe6d4d9cb65c3a9d44f13552d03f3fe9e23ddd","unresolved":true,"context_lines":[{"line_number":901,"context_line":"redis_connection_string_extras: \"\u0026db\u003d0\u0026socket_timeout\u003d60\u0026retry_on_timeout\u003dyes\""},{"line_number":902,"context_line":""},{"line_number":903,"context_line":"####################"},{"line_number":904,"context_line":"# Cache Options"},{"line_number":905,"context_line":"####################"},{"line_number":906,"context_line":"cache_enabled: \"yes\""},{"line_number":907,"context_line":"# valid values: [\"memcached\", \"redis\"]"}],"source_content_type":"text/x-yaml","patch_set":35,"id":"4293fda9_e959fec1","line":904,"updated":"2024-08-23 14:27:27.000000000","message":"is this really needed in enabling TLS change? probably should be added to separate patch","commit_id":"c5edb65f75208f4517ffff76b166346584b08037"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"f923f112ccbd17a55896ff30a04588f9ca097c89","unresolved":false,"context_lines":[{"line_number":901,"context_line":"redis_connection_string_extras: \"\u0026db\u003d0\u0026socket_timeout\u003d60\u0026retry_on_timeout\u003dyes\""},{"line_number":902,"context_line":""},{"line_number":903,"context_line":"####################"},{"line_number":904,"context_line":"# Cache Options"},{"line_number":905,"context_line":"####################"},{"line_number":906,"context_line":"cache_enabled: \"yes\""},{"line_number":907,"context_line":"# valid values: [\"memcached\", \"redis\"]"}],"source_content_type":"text/x-yaml","patch_set":35,"id":"3784b3a2_5de49335","line":904,"in_reply_to":"4293fda9_e959fec1","updated":"2024-08-26 11:48:38.000000000","message":"Done\n\nI moved cache related changes here\nhttps://review.opendev.org/c/openstack/kolla-ansible/+/927104","commit_id":"c5edb65f75208f4517ffff76b166346584b08037"},{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"f3820d92fde8772bf8382cb7857fda290a87e0a5","unresolved":true,"context_lines":[{"line_number":613,"context_line":"redis_username: \"default\""},{"line_number":614,"context_line":"redis_port: \"6379\""},{"line_number":615,"context_line":"redis_sentinel_port: \"26379\""},{"line_number":616,"context_line":"# Enabling TLS blocks non-TLS port"},{"line_number":617,"context_line":"redis_enable_tls: \"{{ kolla_enable_tls_backend }}\""},{"line_number":618,"context_line":"redis_tls_port: \"6378\""},{"line_number":619,"context_line":"redis_sentinel_tls_port: \"26378\""}],"source_content_type":"text/x-yaml","patch_set":38,"id":"1a108c97_9fcdcdf0","line":616,"updated":"2024-09-13 15:20:25.000000000","message":"Can\u0027t we use the same?","commit_id":"ea4cdd844a3fe1d06eca2684497cc41a549665fb"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"5cf640af8a2f7af618b4d26a17a50f04ca1f6288","unresolved":true,"context_lines":[{"line_number":613,"context_line":"redis_username: \"default\""},{"line_number":614,"context_line":"redis_port: \"6379\""},{"line_number":615,"context_line":"redis_sentinel_port: \"26379\""},{"line_number":616,"context_line":"# Enabling TLS blocks non-TLS port"},{"line_number":617,"context_line":"redis_enable_tls: \"{{ kolla_enable_tls_backend }}\""},{"line_number":618,"context_line":"redis_tls_port: \"6378\""},{"line_number":619,"context_line":"redis_sentinel_tls_port: \"26378\""}],"source_content_type":"text/x-yaml","patch_set":38,"id":"639d6c6f_99771a91","line":616,"in_reply_to":"1a108c97_9fcdcdf0","updated":"2024-09-13 15:44:36.000000000","message":"not sure, the docs only talk about different ports for this:\nhttps://redis.io/docs/latest/operate/oss_and_stack/management/security/encryption/#tls-listening-port\n\nIn general it\u0027s not a good idea to speak a secure encrypted protocol on the same port as a non secure non encrypted protocol because that makes you vulnerable to protocol downgrade attacks (e.g. see STARTTLS usage in mailservers)","commit_id":"ea4cdd844a3fe1d06eca2684497cc41a549665fb"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"ed89316f89d43dccf2a5940187b1f062adc08d3b","unresolved":true,"context_lines":[{"line_number":613,"context_line":"redis_username: \"default\""},{"line_number":614,"context_line":"redis_port: \"6379\""},{"line_number":615,"context_line":"redis_sentinel_port: \"26379\""},{"line_number":616,"context_line":"# Enabling TLS blocks non-TLS port"},{"line_number":617,"context_line":"redis_enable_tls: \"{{ kolla_enable_tls_backend }}\""},{"line_number":618,"context_line":"redis_tls_port: \"6378\""},{"line_number":619,"context_line":"redis_sentinel_tls_port: \"26378\""}],"source_content_type":"text/x-yaml","patch_set":38,"id":"76d71c75_2b81a197","line":616,"in_reply_to":"639d6c6f_99771a91","updated":"2024-10-04 12:59:47.000000000","message":"that was the exact reason I used different port.It might be configured by operator directly thus we would ommit `redis_tls_port`, however I think it\u0027s better that  operator has a simple option of turning TLS on/off without modifying ports","commit_id":"ea4cdd844a3fe1d06eca2684497cc41a549665fb"},{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"d3b92f0148f7677283f5e3a557f8eb91f60d631f","unresolved":false,"context_lines":[{"line_number":613,"context_line":"redis_username: \"default\""},{"line_number":614,"context_line":"redis_port: \"6379\""},{"line_number":615,"context_line":"redis_sentinel_port: \"26379\""},{"line_number":616,"context_line":"# Enabling TLS blocks non-TLS port"},{"line_number":617,"context_line":"redis_enable_tls: \"{{ kolla_enable_tls_backend }}\""},{"line_number":618,"context_line":"redis_tls_port: \"6378\""},{"line_number":619,"context_line":"redis_sentinel_tls_port: \"26378\""}],"source_content_type":"text/x-yaml","patch_set":38,"id":"c5ceba8a_19351b8c","line":616,"in_reply_to":"76d71c75_2b81a197","updated":"2025-05-13 10:13:12.000000000","message":"Acknowledged","commit_id":"ea4cdd844a3fe1d06eca2684497cc41a549665fb"}],"ansible/roles/certificates/tasks/generate-backend.yml":[{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"c6f2b7eb846f17e87d40d7d07da79565c402939b","unresolved":true,"context_lines":[{"line_number":85,"context_line":"    remote_src: true"},{"line_number":86,"context_line":"  with_items:"},{"line_number":87,"context_line":"    - src: \"{{ kolla_tls_backend_cert }}\""},{"line_number":88,"context_line":"      dest: \"{{ kolla_certificates_dir }}/{{ redis_tls_certfile }}\""},{"line_number":89,"context_line":"    - src: \"{{ kolla_tls_backend_key }}\""},{"line_number":90,"context_line":"      dest: \"{{ kolla_certificates_dir }}/{{ redis_tls_keyfile }}\""},{"line_number":91,"context_line":"  when:"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"755fc81a_0e021c5f","line":88,"updated":"2024-03-07 07:17:26.000000000","message":"Why are configurable filenames needed? Can\u0027t we just use a fixed name? that would make a big part of this patch easier","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"bd4839b3d3ec5ab2c9ef3b4c4d5924da2851763e","unresolved":false,"context_lines":[{"line_number":85,"context_line":"    remote_src: true"},{"line_number":86,"context_line":"  with_items:"},{"line_number":87,"context_line":"    - src: \"{{ kolla_tls_backend_cert }}\""},{"line_number":88,"context_line":"      dest: \"{{ kolla_certificates_dir }}/{{ redis_tls_certfile }}\""},{"line_number":89,"context_line":"    - src: \"{{ kolla_tls_backend_key }}\""},{"line_number":90,"context_line":"      dest: \"{{ kolla_certificates_dir }}/{{ redis_tls_keyfile }}\""},{"line_number":91,"context_line":"  when:"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"9ae68023_8aff92b6","line":88,"in_reply_to":"2ff242b8_60f599b9","updated":"2024-03-07 13:39:30.000000000","message":"Acknowledged","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"cee9475902ec060901bd74827313f6251537d2f1","unresolved":true,"context_lines":[{"line_number":85,"context_line":"    remote_src: true"},{"line_number":86,"context_line":"  with_items:"},{"line_number":87,"context_line":"    - src: \"{{ kolla_tls_backend_cert }}\""},{"line_number":88,"context_line":"      dest: \"{{ kolla_certificates_dir }}/{{ redis_tls_certfile }}\""},{"line_number":89,"context_line":"    - src: \"{{ kolla_tls_backend_key }}\""},{"line_number":90,"context_line":"      dest: \"{{ kolla_certificates_dir }}/{{ redis_tls_keyfile }}\""},{"line_number":91,"context_line":"  when:"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"f23a7bbe_4521d6fe","line":88,"in_reply_to":"755fc81a_0e021c5f","updated":"2024-03-07 08:52:06.000000000","message":"I will remove the configuration, and keep it at redis-\u003ccert,key\u003e.pem\n\n I will leave CA configurable, beacause user can use his custom CA  for Redis, for example if he uses external Redis that\u0027s not managed by Kolla.","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"bd74c4f6cf86ce7a7e5ac7edf7d463fa8a81a265","unresolved":true,"context_lines":[{"line_number":85,"context_line":"    remote_src: true"},{"line_number":86,"context_line":"  with_items:"},{"line_number":87,"context_line":"    - src: \"{{ kolla_tls_backend_cert }}\""},{"line_number":88,"context_line":"      dest: \"{{ kolla_certificates_dir }}/{{ redis_tls_certfile }}\""},{"line_number":89,"context_line":"    - src: \"{{ kolla_tls_backend_key }}\""},{"line_number":90,"context_line":"      dest: \"{{ kolla_certificates_dir }}/{{ redis_tls_keyfile }}\""},{"line_number":91,"context_line":"  when:"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"2ff242b8_60f599b9","line":88,"in_reply_to":"f23a7bbe_4521d6fe","updated":"2024-03-07 10:09:43.000000000","message":"On second thought, I think we should let user configure the file names of the certificates before they are copied to containers, in case they want to use their own certificates, so they are not restricted to our naming. However, as soon as the certificate is moved to the containers (copy-certs task) it can be renamed to redis-cert.pem","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"f13fc328b15bf58fa12d4a439a70c64e971e22fd","unresolved":true,"context_lines":[{"line_number":91,"context_line":"      dest: \"{{ kolla_certificates_dir }}/mariadb-key.pem\""},{"line_number":92,"context_line":"  when:"},{"line_number":93,"context_line":"    - database_enable_tls_backend | bool"},{"line_number":94,"context_line":"- name: Copy backend TLS certificate and key for Redis"},{"line_number":95,"context_line":"  copy:"},{"line_number":96,"context_line":"    src: \"{{ item.src }}\""},{"line_number":97,"context_line":"    dest: \"{{ item.dest }}\""}],"source_content_type":"text/x-yaml","patch_set":40,"id":"ed12cc93_c4d00e89","line":94,"updated":"2024-10-31 22:43:23.000000000","message":"need an empty line","commit_id":"5593bb91dfccf513fad1a56da66fdd5f69c0f536"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"6c457a24983b2ccfc8b8bdfa7df7634640abb297","unresolved":false,"context_lines":[{"line_number":91,"context_line":"      dest: \"{{ kolla_certificates_dir }}/mariadb-key.pem\""},{"line_number":92,"context_line":"  when:"},{"line_number":93,"context_line":"    - database_enable_tls_backend | bool"},{"line_number":94,"context_line":"- name: Copy backend TLS certificate and key for Redis"},{"line_number":95,"context_line":"  copy:"},{"line_number":96,"context_line":"    src: \"{{ item.src }}\""},{"line_number":97,"context_line":"    dest: \"{{ item.dest }}\""}],"source_content_type":"text/x-yaml","patch_set":40,"id":"d18aa66e_6a4788de","line":94,"in_reply_to":"ed12cc93_c4d00e89","updated":"2024-11-04 08:47:06.000000000","message":"Done","commit_id":"5593bb91dfccf513fad1a56da66fdd5f69c0f536"}],"ansible/roles/cinder/tasks/config.yml":[{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"7779ba381fa6abf437c7f5cfbe3d0498651be642","unresolved":true,"context_lines":[{"line_number":39,"context_line":""},{"line_number":40,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":41,"context_line":"  when:"},{"line_number":42,"context_line":"    - kolla_copy_ca_into_containers | bool or cinder_enable_tls_backend | bool or redis_enable_tls | bool"},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"- name: Copying over config.json files for services"},{"line_number":45,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"db655fd0_ab110dbe","line":42,"range":{"start_line":42,"start_character":79,"end_line":42,"end_character":105},"updated":"2024-05-28 11:10:15.000000000","message":"not needed here there is a check in the copy-certs.yml included","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"b916f29cf841d0b38522fd1f592d091d1e5b8605","unresolved":false,"context_lines":[{"line_number":39,"context_line":""},{"line_number":40,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":41,"context_line":"  when:"},{"line_number":42,"context_line":"    - kolla_copy_ca_into_containers | bool or cinder_enable_tls_backend | bool or redis_enable_tls | bool"},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"- name: Copying over config.json files for services"},{"line_number":45,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"575bbcbf_4688f7eb","line":42,"range":{"start_line":42,"start_character":79,"end_line":42,"end_character":105},"in_reply_to":"25caef89_96ea7c3a","updated":"2024-05-28 14:18:06.000000000","message":"just for completeness, that check in role service-cert-copy will be removed in https://review.opendev.org/c/openstack/kolla-ansible/+/915901\n\nit should be fine though, as long as nothing else is activating stuff solely on the presence of said certificates, which should not be the case(TM).\n\nBut I didn\u0027t verify this myself (I haven\u0027t come up with a good enough grep yet to verify this globally).","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"9c359ba0627bf08afadcf2bf01d4eafa3c3adfed","unresolved":true,"context_lines":[{"line_number":39,"context_line":""},{"line_number":40,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":41,"context_line":"  when:"},{"line_number":42,"context_line":"    - kolla_copy_ca_into_containers | bool or cinder_enable_tls_backend | bool or redis_enable_tls | bool"},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"- name: Copying over config.json files for services"},{"line_number":45,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"8d70f767_55813dbb","line":42,"range":{"start_line":42,"start_character":79,"end_line":42,"end_character":105},"in_reply_to":"25caef89_96ea7c3a","updated":"2024-05-28 14:21:03.000000000","message":"not done, you move the when case to the copy-certs.yml but need to leave config.yml untouched and check redis_enable_tls in the copy-certs.yml like you did in separate patchset for placement service for example: https://review.opendev.org/c/openstack/kolla-ansible/+/909222/5/ansible/roles/placement/tasks/copy-certs.yml","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"837cc92adb04ca6b27961458fa281bc24921d377","unresolved":true,"context_lines":[{"line_number":39,"context_line":""},{"line_number":40,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":41,"context_line":"  when:"},{"line_number":42,"context_line":"    - kolla_copy_ca_into_containers | bool or cinder_enable_tls_backend | bool or redis_enable_tls | bool"},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"- name: Copying over config.json files for services"},{"line_number":45,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"6b15575e_72184f86","line":42,"range":{"start_line":42,"start_character":79,"end_line":42,"end_character":105},"in_reply_to":"3cbae224_d055bcc1","updated":"2024-05-28 14:30:15.000000000","message":"Sven, could you please attach a link to the discussion here? may be youre right and when cases not needed at all","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"8d46636271892beb0b021489d86241e94e5bd2a8","unresolved":true,"context_lines":[{"line_number":39,"context_line":""},{"line_number":40,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":41,"context_line":"  when:"},{"line_number":42,"context_line":"    - kolla_copy_ca_into_containers | bool or cinder_enable_tls_backend | bool or redis_enable_tls | bool"},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"- name: Copying over config.json files for services"},{"line_number":45,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"f3597d77_61af20ad","line":42,"range":{"start_line":42,"start_character":79,"end_line":42,"end_character":105},"in_reply_to":"4239ae46_f77fee54","updated":"2024-06-04 12:22:08.000000000","message":"So, to provide further context:\n\nIt was suggested - initially by Michal Arbet (aka kevko) - to drop the \"when\" condition from the service-cert-copy role.\n\nThe reasoning behind this is, that we should always copy certificates into containers/services, if they are provided. We don\u0027t need to check if some tls option is set for this, or if a certain type of loadbalancing/SSL proxy is enabled for that, as the user might configure their stuff differently anyway, e.g. using proxysql instead of haproxy for sql traffic.\n\nThis was (shortly) discussed during the weekly kolla meeting at 2024-05-22:\n\nhttps://meetings.opendev.org/irclogs/%23openstack-kolla/%23openstack-kolla.2024-05-22.log.html#t2024-05-22T13:17:34\n\nSo to extend this logic I don\u0027t think we should move these checks around to different roles, that would only spread the complexity from one role to many roles, but we should rather get rid of it completely.\n\nIf you need further reasoning around this topic I suggest you ask kevko or mnasiadka.\n\nI hope this helps clear thinks up a bit?\n\nThanks.","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"f70a389f2876f721fe1e53e31591ac28aab4ac9f","unresolved":true,"context_lines":[{"line_number":39,"context_line":""},{"line_number":40,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":41,"context_line":"  when:"},{"line_number":42,"context_line":"    - kolla_copy_ca_into_containers | bool or cinder_enable_tls_backend | bool or redis_enable_tls | bool"},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"- name: Copying over config.json files for services"},{"line_number":45,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"4239ae46_f77fee54","line":42,"range":{"start_line":42,"start_character":79,"end_line":42,"end_character":105},"in_reply_to":"6b15575e_72184f86","updated":"2024-05-29 12:23:23.000000000","message":"Yes, that would be helpful, perhaps link IRC logs if it was in the IRC","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"d8e6b621c1449b948d7d86f689c8b9551bd3eae1","unresolved":true,"context_lines":[{"line_number":39,"context_line":""},{"line_number":40,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":41,"context_line":"  when:"},{"line_number":42,"context_line":"    - kolla_copy_ca_into_containers | bool or cinder_enable_tls_backend | bool or redis_enable_tls | bool"},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"- name: Copying over config.json files for services"},{"line_number":45,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"3cbae224_d055bcc1","line":42,"range":{"start_line":42,"start_character":79,"end_line":42,"end_character":105},"in_reply_to":"8d70f767_55813dbb","updated":"2024-05-28 14:25:52.000000000","message":"guys, could you both please read Michals reasoning in the linked patchset?\n\nSo far it was afaik agreed by kevko, mnasiadka, frickler and me, that we should unconditionally - so without any \"when:\" - copy any certificates present to containers.\n\nThis simplifies the needed logic a lot.\n\nMost of the discussion took place via IRC so apologies if you missed it. I tried to move the resulting decision over to the review in form of a comment.\n\nIf you think this is wrong, please provide some reasoning why. It might be wrong but that should be explained then, why it is wrong, thank you!","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"f9bfaa6520a5dc8a8c0a6524ef76862fa0837fa2","unresolved":false,"context_lines":[{"line_number":39,"context_line":""},{"line_number":40,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":41,"context_line":"  when:"},{"line_number":42,"context_line":"    - kolla_copy_ca_into_containers | bool or cinder_enable_tls_backend | bool or redis_enable_tls | bool"},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"- name: Copying over config.json files for services"},{"line_number":45,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"25caef89_96ea7c3a","line":42,"range":{"start_line":42,"start_character":79,"end_line":42,"end_character":105},"in_reply_to":"db655fd0_ab110dbe","updated":"2024-05-28 13:42:51.000000000","message":"Done","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"76d4188af3b00ef4b4d3312ee9d143202a01287c","unresolved":false,"context_lines":[{"line_number":39,"context_line":""},{"line_number":40,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":41,"context_line":"  when:"},{"line_number":42,"context_line":"    - kolla_copy_ca_into_containers | bool or cinder_enable_tls_backend | bool or redis_enable_tls | bool"},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"- name: Copying over config.json files for services"},{"line_number":45,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"8cdd8deb_cc094a53","line":42,"range":{"start_line":42,"start_character":79,"end_line":42,"end_character":105},"in_reply_to":"dc79e10a_e7971a85","updated":"2024-06-07 08:18:48.000000000","message":"marking this as resolved, I guess, please reopen if I missed something.","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"ff9bea116904c0265332e012a3a9c3d8e2f7fa61","unresolved":true,"context_lines":[{"line_number":39,"context_line":""},{"line_number":40,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":41,"context_line":"  when:"},{"line_number":42,"context_line":"    - kolla_copy_ca_into_containers | bool or cinder_enable_tls_backend | bool or redis_enable_tls | bool"},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"- name: Copying over config.json files for services"},{"line_number":45,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"dc79e10a_e7971a85","line":42,"range":{"start_line":42,"start_character":79,"end_line":42,"end_character":105},"in_reply_to":"f3597d77_61af20ad","updated":"2024-06-04 12:40:53.000000000","message":"rereading everything let me retract this a bit, and sorry for the confusion this may have caused.\n\nso the original point was to not do special checks for haproxy, and that was agreed upon in the kolla meeting.\n\nbut we should still check if TLS is enabled for the service (doesn\u0027t really make sense to copy certs without TLS being enabled), and we should also check for `kolla_copy_ca_into_containers`, if users have some kind of custom CA.\n\nSo I think e.g. this code is fine: https://opendev.org/openstack/kolla-ansible/src/commit/5109ca657d763c323b0606e1b06482bfe2e8fc3b/ansible/roles/cinder/tasks/copy-certs.yml#L7\n\nto quote it:\n\n`when: kolla_copy_ca_into_containers | bool or cinder_enable_tls_backend | bool`","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"}],"ansible/roles/designate/tasks/config.yml":[{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"7779ba381fa6abf437c7f5cfbe3d0498651be642","unresolved":true,"context_lines":[{"line_number":33,"context_line":""},{"line_number":34,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":35,"context_line":"  when:"},{"line_number":36,"context_line":"    - kolla_copy_ca_into_containers | bool or redis_enable_tls | bool"},{"line_number":37,"context_line":""},{"line_number":38,"context_line":"- name: Copying over config.json files for services"},{"line_number":39,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"cd9bcad1_32b58c8b","line":36,"range":{"start_line":36,"start_character":43,"end_line":36,"end_character":69},"updated":"2024-05-28 11:10:15.000000000","message":"ditto","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"77479d38330869131486be76ec54859db82995e6","unresolved":false,"context_lines":[{"line_number":33,"context_line":""},{"line_number":34,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":35,"context_line":"  when:"},{"line_number":36,"context_line":"    - kolla_copy_ca_into_containers | bool or redis_enable_tls | bool"},{"line_number":37,"context_line":""},{"line_number":38,"context_line":"- name: Copying over config.json files for services"},{"line_number":39,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"b31dbe03_b4e43824","line":36,"range":{"start_line":36,"start_character":43,"end_line":36,"end_character":69},"in_reply_to":"457329e2_d0c03d0e","updated":"2024-06-17 09:51:31.000000000","message":"Done","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"9c359ba0627bf08afadcf2bf01d4eafa3c3adfed","unresolved":true,"context_lines":[{"line_number":33,"context_line":""},{"line_number":34,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":35,"context_line":"  when:"},{"line_number":36,"context_line":"    - kolla_copy_ca_into_containers | bool or redis_enable_tls | bool"},{"line_number":37,"context_line":""},{"line_number":38,"context_line":"- name: Copying over config.json files for services"},{"line_number":39,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"457329e2_d0c03d0e","line":36,"range":{"start_line":36,"start_character":43,"end_line":36,"end_character":69},"in_reply_to":"98efb64b_3ce39688","updated":"2024-05-28 14:21:03.000000000","message":"ditto","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"f9bfaa6520a5dc8a8c0a6524ef76862fa0837fa2","unresolved":false,"context_lines":[{"line_number":33,"context_line":""},{"line_number":34,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":35,"context_line":"  when:"},{"line_number":36,"context_line":"    - kolla_copy_ca_into_containers | bool or redis_enable_tls | bool"},{"line_number":37,"context_line":""},{"line_number":38,"context_line":"- name: Copying over config.json files for services"},{"line_number":39,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"98efb64b_3ce39688","line":36,"range":{"start_line":36,"start_character":43,"end_line":36,"end_character":69},"in_reply_to":"cd9bcad1_32b58c8b","updated":"2024-05-28 13:42:51.000000000","message":"Done","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"}],"ansible/roles/ironic/tasks/config.yml":[{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"7779ba381fa6abf437c7f5cfbe3d0498651be642","unresolved":true,"context_lines":[{"line_number":52,"context_line":""},{"line_number":53,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":54,"context_line":"  when:"},{"line_number":55,"context_line":"    - kolla_copy_ca_into_containers | bool or ironic_enable_tls_backend | bool or redis_enable_tls | bool"},{"line_number":56,"context_line":""},{"line_number":57,"context_line":"- name: Copying over config.json files for services"},{"line_number":58,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"d6103e4b_dbc001aa","line":55,"range":{"start_line":55,"start_character":79,"end_line":55,"end_character":105},"updated":"2024-05-28 11:10:15.000000000","message":"ditto","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"77479d38330869131486be76ec54859db82995e6","unresolved":false,"context_lines":[{"line_number":52,"context_line":""},{"line_number":53,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":54,"context_line":"  when:"},{"line_number":55,"context_line":"    - kolla_copy_ca_into_containers | bool or ironic_enable_tls_backend | bool or redis_enable_tls | bool"},{"line_number":56,"context_line":""},{"line_number":57,"context_line":"- name: Copying over config.json files for services"},{"line_number":58,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"182f0f0b_d5aedf06","line":55,"range":{"start_line":55,"start_character":79,"end_line":55,"end_character":105},"in_reply_to":"95bea0ab_9fe79c99","updated":"2024-06-17 09:51:31.000000000","message":"Done","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"9c359ba0627bf08afadcf2bf01d4eafa3c3adfed","unresolved":true,"context_lines":[{"line_number":52,"context_line":""},{"line_number":53,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":54,"context_line":"  when:"},{"line_number":55,"context_line":"    - kolla_copy_ca_into_containers | bool or ironic_enable_tls_backend | bool or redis_enable_tls | bool"},{"line_number":56,"context_line":""},{"line_number":57,"context_line":"- name: Copying over config.json files for services"},{"line_number":58,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"95bea0ab_9fe79c99","line":55,"range":{"start_line":55,"start_character":79,"end_line":55,"end_character":105},"in_reply_to":"9baa8496_20c8eb11","updated":"2024-05-28 14:21:03.000000000","message":"ditto","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"f9bfaa6520a5dc8a8c0a6524ef76862fa0837fa2","unresolved":false,"context_lines":[{"line_number":52,"context_line":""},{"line_number":53,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":54,"context_line":"  when:"},{"line_number":55,"context_line":"    - kolla_copy_ca_into_containers | bool or ironic_enable_tls_backend | bool or redis_enable_tls | bool"},{"line_number":56,"context_line":""},{"line_number":57,"context_line":"- name: Copying over config.json files for services"},{"line_number":58,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"9baa8496_20c8eb11","line":55,"range":{"start_line":55,"start_character":79,"end_line":55,"end_character":105},"in_reply_to":"d6103e4b_dbc001aa","updated":"2024-05-28 13:42:51.000000000","message":"Done","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"}],"ansible/roles/masakari/tasks/config.yml":[{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"7779ba381fa6abf437c7f5cfbe3d0498651be642","unresolved":true,"context_lines":[{"line_number":60,"context_line":""},{"line_number":61,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":62,"context_line":"  when:"},{"line_number":63,"context_line":"    - kolla_copy_ca_into_containers | bool or redis_enable_tls | bool"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"- name: Copying over masakari.conf"},{"line_number":66,"context_line":"  vars:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"bf17959d_90e57bd1","line":63,"range":{"start_line":63,"start_character":43,"end_line":63,"end_character":69},"updated":"2024-05-28 11:10:15.000000000","message":"ditto","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"77479d38330869131486be76ec54859db82995e6","unresolved":false,"context_lines":[{"line_number":60,"context_line":""},{"line_number":61,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":62,"context_line":"  when:"},{"line_number":63,"context_line":"    - kolla_copy_ca_into_containers | bool or redis_enable_tls | bool"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"- name: Copying over masakari.conf"},{"line_number":66,"context_line":"  vars:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"578d3105_2e00c4de","line":63,"range":{"start_line":63,"start_character":43,"end_line":63,"end_character":69},"in_reply_to":"79cf469c_ff12d480","updated":"2024-06-17 09:51:31.000000000","message":"Done","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"9c359ba0627bf08afadcf2bf01d4eafa3c3adfed","unresolved":true,"context_lines":[{"line_number":60,"context_line":""},{"line_number":61,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":62,"context_line":"  when:"},{"line_number":63,"context_line":"    - kolla_copy_ca_into_containers | bool or redis_enable_tls | bool"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"- name: Copying over masakari.conf"},{"line_number":66,"context_line":"  vars:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"79cf469c_ff12d480","line":63,"range":{"start_line":63,"start_character":43,"end_line":63,"end_character":69},"in_reply_to":"91337423_15a86da8","updated":"2024-05-28 14:21:03.000000000","message":"ditto","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"f9bfaa6520a5dc8a8c0a6524ef76862fa0837fa2","unresolved":false,"context_lines":[{"line_number":60,"context_line":""},{"line_number":61,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":62,"context_line":"  when:"},{"line_number":63,"context_line":"    - kolla_copy_ca_into_containers | bool or redis_enable_tls | bool"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"- name: Copying over masakari.conf"},{"line_number":66,"context_line":"  vars:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"91337423_15a86da8","line":63,"range":{"start_line":63,"start_character":43,"end_line":63,"end_character":69},"in_reply_to":"bf17959d_90e57bd1","updated":"2024-05-28 13:42:51.000000000","message":"Done","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"4585b081f40966aa637cf4eedc4d16a115639907","unresolved":true,"context_lines":[{"line_number":60,"context_line":""},{"line_number":61,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":62,"context_line":"  when:"},{"line_number":63,"context_line":"    - kolla_copy_ca_into_containers | bool or redis_enable_tls | bool"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"- name: Copying over masakari.conf"},{"line_number":66,"context_line":"  vars:"}],"source_content_type":"text/x-yaml","patch_set":25,"id":"8e22468c_87488c39","line":63,"range":{"start_line":63,"start_character":0,"end_line":63,"end_character":69},"updated":"2024-05-28 14:10:55.000000000","message":"forgot drop this and modify ansible/roles/masakari/tasks/copy-certs.yml","commit_id":"5109ca657d763c323b0606e1b06482bfe2e8fc3b"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"77479d38330869131486be76ec54859db82995e6","unresolved":false,"context_lines":[{"line_number":60,"context_line":""},{"line_number":61,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":62,"context_line":"  when:"},{"line_number":63,"context_line":"    - kolla_copy_ca_into_containers | bool or redis_enable_tls | bool"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"- name: Copying over masakari.conf"},{"line_number":66,"context_line":"  vars:"}],"source_content_type":"text/x-yaml","patch_set":25,"id":"228d8d13_2ef54786","line":63,"range":{"start_line":63,"start_character":0,"end_line":63,"end_character":69},"in_reply_to":"8e22468c_87488c39","updated":"2024-06-17 09:51:31.000000000","message":"Done","commit_id":"5109ca657d763c323b0606e1b06482bfe2e8fc3b"}],"ansible/roles/masakari/tasks/copy-certs.yml":[{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"4585b081f40966aa637cf4eedc4d16a115639907","unresolved":true,"context_lines":[{"line_number":3,"context_line":"  import_role:"},{"line_number":4,"context_line":"    role: service-cert-copy"},{"line_number":5,"context_line":"  vars:"},{"line_number":6,"context_line":"    project_services: \"{{ masakari_services }}\""},{"line_number":7,"context_line":""},{"line_number":8,"context_line":"- name: \"Copy certificates and keys for Redis\""},{"line_number":9,"context_line":"  import_role:"}],"source_content_type":"text/x-yaml","patch_set":25,"id":"d4d6c30f_eb7f4591","line":6,"updated":"2024-05-28 14:10:55.000000000","message":"when: kolla_copy_ca_into_containers | bool","commit_id":"5109ca657d763c323b0606e1b06482bfe2e8fc3b"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"77479d38330869131486be76ec54859db82995e6","unresolved":false,"context_lines":[{"line_number":3,"context_line":"  import_role:"},{"line_number":4,"context_line":"    role: service-cert-copy"},{"line_number":5,"context_line":"  vars:"},{"line_number":6,"context_line":"    project_services: \"{{ masakari_services }}\""},{"line_number":7,"context_line":""},{"line_number":8,"context_line":"- name: \"Copy certificates and keys for Redis\""},{"line_number":9,"context_line":"  import_role:"}],"source_content_type":"text/x-yaml","patch_set":25,"id":"4cd14df5_3ffd13fa","line":6,"in_reply_to":"d4d6c30f_eb7f4591","updated":"2024-06-17 09:51:31.000000000","message":"Done","commit_id":"5109ca657d763c323b0606e1b06482bfe2e8fc3b"}],"ansible/roles/mistral/tasks/config.yml":[{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"7779ba381fa6abf437c7f5cfbe3d0498651be642","unresolved":true,"context_lines":[{"line_number":33,"context_line":""},{"line_number":34,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":35,"context_line":"  when:"},{"line_number":36,"context_line":"    - kolla_copy_ca_into_containers | bool or redis_enable_tls | bool"},{"line_number":37,"context_line":""},{"line_number":38,"context_line":"- name: Copying over config.json files for services"},{"line_number":39,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"c27b57c2_9cdef519","line":36,"range":{"start_line":36,"start_character":43,"end_line":36,"end_character":69},"updated":"2024-05-28 11:10:15.000000000","message":"ditto","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"77479d38330869131486be76ec54859db82995e6","unresolved":false,"context_lines":[{"line_number":33,"context_line":""},{"line_number":34,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":35,"context_line":"  when:"},{"line_number":36,"context_line":"    - kolla_copy_ca_into_containers | bool or redis_enable_tls | bool"},{"line_number":37,"context_line":""},{"line_number":38,"context_line":"- name: Copying over config.json files for services"},{"line_number":39,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"963129fb_54461aed","line":36,"range":{"start_line":36,"start_character":43,"end_line":36,"end_character":69},"in_reply_to":"172299e3_d47ccaeb","updated":"2024-06-17 09:51:31.000000000","message":"Done","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"9c359ba0627bf08afadcf2bf01d4eafa3c3adfed","unresolved":true,"context_lines":[{"line_number":33,"context_line":""},{"line_number":34,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":35,"context_line":"  when:"},{"line_number":36,"context_line":"    - kolla_copy_ca_into_containers | bool or redis_enable_tls | bool"},{"line_number":37,"context_line":""},{"line_number":38,"context_line":"- name: Copying over config.json files for services"},{"line_number":39,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"172299e3_d47ccaeb","line":36,"range":{"start_line":36,"start_character":43,"end_line":36,"end_character":69},"in_reply_to":"8f4f0646_d55f5416","updated":"2024-05-28 14:21:03.000000000","message":"ditto","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"f9bfaa6520a5dc8a8c0a6524ef76862fa0837fa2","unresolved":false,"context_lines":[{"line_number":33,"context_line":""},{"line_number":34,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":35,"context_line":"  when:"},{"line_number":36,"context_line":"    - kolla_copy_ca_into_containers | bool or redis_enable_tls | bool"},{"line_number":37,"context_line":""},{"line_number":38,"context_line":"- name: Copying over config.json files for services"},{"line_number":39,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"8f4f0646_d55f5416","line":36,"range":{"start_line":36,"start_character":43,"end_line":36,"end_character":69},"in_reply_to":"c27b57c2_9cdef519","updated":"2024-05-28 13:42:51.000000000","message":"Done","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"}],"ansible/roles/redis/tasks/config.yml":[{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"c6f2b7eb846f17e87d40d7d07da79565c402939b","unresolved":true,"context_lines":[{"line_number":28,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":29,"context_line":"  vars:"},{"line_number":30,"context_line":"    project_services: \"{{ redis_services }}\""},{"line_number":31,"context_line":"  when: enable_redis | bool and redis_enable_tls | bool"},{"line_number":32,"context_line":""},{"line_number":33,"context_line":"- name: Copying over redis config files"},{"line_number":34,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"f16c7128_6f3bbb6b","line":31,"updated":"2024-03-07 07:17:26.000000000","message":"can you please format this as a list for better readability like in the other \"when\"s around this? same for all other occurrences in this patch","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"bd4839b3d3ec5ab2c9ef3b4c4d5924da2851763e","unresolved":false,"context_lines":[{"line_number":28,"context_line":"- include_tasks: copy-certs.yml"},{"line_number":29,"context_line":"  vars:"},{"line_number":30,"context_line":"    project_services: \"{{ redis_services }}\""},{"line_number":31,"context_line":"  when: enable_redis | bool and redis_enable_tls | bool"},{"line_number":32,"context_line":""},{"line_number":33,"context_line":"- name: Copying over redis config files"},{"line_number":34,"context_line":"  template:"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"04661cf9_4378fddd","line":31,"in_reply_to":"f16c7128_6f3bbb6b","updated":"2024-03-07 13:39:30.000000000","message":"Acknowledged","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"fd7e4a30ad80f152e8ae4a391372b01d80ada6bd","unresolved":true,"context_lines":[{"line_number":29,"context_line":"  vars:"},{"line_number":30,"context_line":"    project_services: \"{{ redis_services }}\""},{"line_number":31,"context_line":"  when:"},{"line_number":32,"context_line":"    - enable_redis | bool"},{"line_number":33,"context_line":"    - redis_enable_tls | bool"},{"line_number":34,"context_line":""},{"line_number":35,"context_line":"- name: Copying over redis config files"}],"source_content_type":"text/x-yaml","patch_set":15,"id":"92fc522a_29bd30a8","line":32,"updated":"2024-04-15 11:03:29.000000000","message":"this one is redundant, right?","commit_id":"f782094befbfe762912cf95fdc4b719a030f7329"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"1b5c5a0e2ae27a0b01c2f15c33c4dd6b1bc94922","unresolved":true,"context_lines":[{"line_number":29,"context_line":"  vars:"},{"line_number":30,"context_line":"    project_services: \"{{ redis_services }}\""},{"line_number":31,"context_line":"  when:"},{"line_number":32,"context_line":"    - enable_redis | bool"},{"line_number":33,"context_line":"    - redis_enable_tls | bool"},{"line_number":34,"context_line":""},{"line_number":35,"context_line":"- name: Copying over redis config files"}],"source_content_type":"text/x-yaml","patch_set":15,"id":"ab8815b4_9deb6de6","line":32,"in_reply_to":"5d2f8177_2857e2d8","updated":"2024-04-19 10:59:11.000000000","message":"I don\u0027t see this addressed?","commit_id":"f782094befbfe762912cf95fdc4b719a030f7329"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"e82a3433b2f82baa3029b0f6ca5476e08044bdff","unresolved":false,"context_lines":[{"line_number":29,"context_line":"  vars:"},{"line_number":30,"context_line":"    project_services: \"{{ redis_services }}\""},{"line_number":31,"context_line":"  when:"},{"line_number":32,"context_line":"    - enable_redis | bool"},{"line_number":33,"context_line":"    - redis_enable_tls | bool"},{"line_number":34,"context_line":""},{"line_number":35,"context_line":"- name: Copying over redis config files"}],"source_content_type":"text/x-yaml","patch_set":15,"id":"5d2f8177_2857e2d8","line":32,"in_reply_to":"92fc522a_29bd30a8","updated":"2024-04-17 10:54:28.000000000","message":"Acknowledged","commit_id":"f782094befbfe762912cf95fdc4b719a030f7329"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"dcd25fa4585be54772db61ee28222b697096376e","unresolved":true,"context_lines":[{"line_number":29,"context_line":"  vars:"},{"line_number":30,"context_line":"    project_services: \"{{ redis_services }}\""},{"line_number":31,"context_line":"  when:"},{"line_number":32,"context_line":"    - enable_redis | bool"},{"line_number":33,"context_line":"    - redis_enable_tls | bool"},{"line_number":34,"context_line":""},{"line_number":35,"context_line":"- name: Copying over redis config files"}],"source_content_type":"text/x-yaml","patch_set":15,"id":"bad69fc7_f36a3cb8","line":32,"in_reply_to":"ab8815b4_9deb6de6","updated":"2024-04-22 06:43:24.000000000","message":"I deleted the conditions from the copy-certs task, so I kept these in. I think it\u0027s better this way.","commit_id":"f782094befbfe762912cf95fdc4b719a030f7329"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"378dfc3a4f60b53c059486d9aedec1af37acad92","unresolved":false,"context_lines":[{"line_number":29,"context_line":"  vars:"},{"line_number":30,"context_line":"    project_services: \"{{ redis_services }}\""},{"line_number":31,"context_line":"  when:"},{"line_number":32,"context_line":"    - enable_redis | bool"},{"line_number":33,"context_line":"    - redis_enable_tls | bool"},{"line_number":34,"context_line":""},{"line_number":35,"context_line":"- name: Copying over redis config files"}],"source_content_type":"text/x-yaml","patch_set":15,"id":"93e07f08_aca8429b","line":32,"in_reply_to":"bad69fc7_f36a3cb8","updated":"2024-04-23 15:27:00.000000000","message":"I just made the the patch depend on  https://review.opendev.org/c/openstack/kolla-ansible/+/915901, there are no redundant conditionals now.","commit_id":"f782094befbfe762912cf95fdc4b719a030f7329"}],"ansible/roles/redis/tasks/copy-certs.yml":[{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"98f1cf19798e6a213858d66c84b97c3c34f29ec7","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"- debug:"},{"line_number":3,"context_line":"    msg: \"Redis Services for TLS copy {{ item.key }}\""},{"line_number":4,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":5,"context_line":""},{"line_number":6,"context_line":"- name: Copying over extra CA certificates"},{"line_number":7,"context_line":"  become: true"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"b70faddf_7f3c091e","line":4,"range":{"start_line":2,"start_character":0,"end_line":4,"end_character":82},"updated":"2024-02-27 09:45:40.000000000","message":"not needed","commit_id":"73bc93353abf9f3cb39d309aa21e3263e1b4d264"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"52d4a228cd27438133fcd431ffcf5ba02d70b374","unresolved":false,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"- debug:"},{"line_number":3,"context_line":"    msg: \"Redis Services for TLS copy {{ item.key }}\""},{"line_number":4,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":5,"context_line":""},{"line_number":6,"context_line":"- name: Copying over extra CA certificates"},{"line_number":7,"context_line":"  become: true"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"794eb414_a53762d4","line":4,"range":{"start_line":2,"start_character":0,"end_line":4,"end_character":82},"in_reply_to":"37f8c4f8_6fe81b6c","updated":"2024-02-27 13:20:52.000000000","message":"fixed, thank you","commit_id":"73bc93353abf9f3cb39d309aa21e3263e1b4d264"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"7e9b5b6ad09c200ef06abec48c4c2879e8b74e1e","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"- debug:"},{"line_number":3,"context_line":"    msg: \"Redis Services for TLS copy {{ item.key }}\""},{"line_number":4,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":5,"context_line":""},{"line_number":6,"context_line":"- name: Copying over extra CA certificates"},{"line_number":7,"context_line":"  become: true"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"37f8c4f8_6fe81b6c","line":4,"range":{"start_line":2,"start_character":0,"end_line":4,"end_character":82},"in_reply_to":"b70faddf_7f3c091e","updated":"2024-02-27 11:01:59.000000000","message":"good catch!","commit_id":"73bc93353abf9f3cb39d309aa21e3263e1b4d264"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"c6f2b7eb846f17e87d40d7d07da79565c402939b","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"- name: Copying over extra CA certificates"},{"line_number":3,"context_line":"  become: true"},{"line_number":4,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":5,"context_line":"  copy:"},{"line_number":6,"context_line":"    src: \"{{ kolla_certificates_dir }}/ca/\""},{"line_number":7,"context_line":"    dest: \"{{ node_config_directory }}/{{ item.key }}/ca-certificates\""}],"source_content_type":"text/x-yaml","patch_set":12,"id":"526fa619_7470766c","line":4,"updated":"2024-03-07 07:17:26.000000000","message":"can you please move this line after the copy block?\n\nalso I don\u0027t see where \"project_services\" is getting defined, should this be \"redis_services\"?","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"bd4839b3d3ec5ab2c9ef3b4c4d5924da2851763e","unresolved":false,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"- name: Copying over extra CA certificates"},{"line_number":3,"context_line":"  become: true"},{"line_number":4,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":5,"context_line":"  copy:"},{"line_number":6,"context_line":"    src: \"{{ kolla_certificates_dir }}/ca/\""},{"line_number":7,"context_line":"    dest: \"{{ node_config_directory }}/{{ item.key }}/ca-certificates\""}],"source_content_type":"text/x-yaml","patch_set":12,"id":"23edae0e_7800d7f6","line":4,"in_reply_to":"0c611770_edfc6779","updated":"2024-03-07 13:39:30.000000000","message":"Acknowledged","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"cee9475902ec060901bd74827313f6251537d2f1","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"- name: Copying over extra CA certificates"},{"line_number":3,"context_line":"  become: true"},{"line_number":4,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":5,"context_line":"  copy:"},{"line_number":6,"context_line":"    src: \"{{ kolla_certificates_dir }}/ca/\""},{"line_number":7,"context_line":"    dest: \"{{ node_config_directory }}/{{ item.key }}/ca-certificates\""}],"source_content_type":"text/x-yaml","patch_set":12,"id":"0c611770_edfc6779","line":4,"in_reply_to":"526fa619_7470766c","updated":"2024-03-07 08:52:06.000000000","message":"\"project_services\" can be passed as a variable when \"include_role\" or \"include_task\" is used. This way,the role can be reused to add certificates to other containers that are using redis. For examle, I use this at my upcomming [patch](https://review.opendev.org/c/openstack/kolla-ansible/+/909201/3/ansible/roles/keystone/tasks/copy-certs.yml) for Keystone Redis caching backend, where \"project_services\" is set to \"keystone_services\".\n\nI may move this task to \"service-cert-copy\" role, so that it\u0027s clear that it\u0027s to be used using \"include_role\" in other services.","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"c6f2b7eb846f17e87d40d7d07da79565c402939b","unresolved":true,"context_lines":[{"line_number":13,"context_line":""},{"line_number":14,"context_line":"- name: Copying over TLS certificate"},{"line_number":15,"context_line":"  become: true"},{"line_number":16,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":17,"context_line":"  copy:"},{"line_number":18,"context_line":"    src: \"{{ backend_tls_cert }}\""},{"line_number":19,"context_line":"    dest: \"{{ node_config_directory }}/{{ item.key }}/{{ redis_tls_certfile }}\""}],"source_content_type":"text/x-yaml","patch_set":12,"id":"3d6724b3_9775cc8a","line":16,"updated":"2024-03-07 07:17:26.000000000","message":"dito","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"bd4839b3d3ec5ab2c9ef3b4c4d5924da2851763e","unresolved":false,"context_lines":[{"line_number":13,"context_line":""},{"line_number":14,"context_line":"- name: Copying over TLS certificate"},{"line_number":15,"context_line":"  become: true"},{"line_number":16,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":17,"context_line":"  copy:"},{"line_number":18,"context_line":"    src: \"{{ backend_tls_cert }}\""},{"line_number":19,"context_line":"    dest: \"{{ node_config_directory }}/{{ item.key }}/{{ redis_tls_certfile }}\""}],"source_content_type":"text/x-yaml","patch_set":12,"id":"b01ccdd6_3209530c","line":16,"in_reply_to":"3d6724b3_9775cc8a","updated":"2024-03-07 13:39:30.000000000","message":"Acknowledged","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"c6f2b7eb846f17e87d40d7d07da79565c402939b","unresolved":true,"context_lines":[{"line_number":38,"context_line":"    mode: \"0600\""},{"line_number":39,"context_line":"  vars:"},{"line_number":40,"context_line":"    keys:"},{"line_number":41,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ inventory_hostname }}/{{ project_name }}-key.pem\""},{"line_number":42,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ inventory_hostname }}-key.pem\""},{"line_number":43,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ redis_tls_keyfile  }}\""},{"line_number":44,"context_line":"    backend_tls_key: \"{{ lookup(\u0027first_found\u0027, keys) }}\""}],"source_content_type":"text/x-yaml","patch_set":12,"id":"02c53ff9_118ec5cd","line":41,"range":{"start_line":41,"start_character":63,"end_line":41,"end_character":89},"updated":"2024-03-07 07:17:26.000000000","message":"shouldn\u0027t this also use \"redis_tls_keyfile\"?","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"bd4839b3d3ec5ab2c9ef3b4c4d5924da2851763e","unresolved":false,"context_lines":[{"line_number":38,"context_line":"    mode: \"0600\""},{"line_number":39,"context_line":"  vars:"},{"line_number":40,"context_line":"    keys:"},{"line_number":41,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ inventory_hostname }}/{{ project_name }}-key.pem\""},{"line_number":42,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ inventory_hostname }}-key.pem\""},{"line_number":43,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ redis_tls_keyfile  }}\""},{"line_number":44,"context_line":"    backend_tls_key: \"{{ lookup(\u0027first_found\u0027, keys) }}\""}],"source_content_type":"text/x-yaml","patch_set":12,"id":"de471d62_cae8d633","line":41,"range":{"start_line":41,"start_character":63,"end_line":41,"end_character":89},"in_reply_to":"02c53ff9_118ec5cd","updated":"2024-03-07 13:39:30.000000000","message":"Acknowledged","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"4f0ac57762d0df7841e06d6b6b5e9de381837c99","unresolved":true,"context_lines":[{"line_number":26,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ inventory_hostname }}-cert.pem\""},{"line_number":27,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ redis_tls_certfile }}\""},{"line_number":28,"context_line":"    backend_tls_cert: \"{{ lookup(\u0027first_found\u0027, certs) }}\""},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"  notify:"},{"line_number":31,"context_line":"    - \"Restart {{ item.key }} container\""},{"line_number":32,"context_line":"  when:"}],"source_content_type":"text/x-yaml","patch_set":14,"id":"f994f897_9cce5b03","line":29,"updated":"2024-03-11 15:21:35.000000000","message":"inconsistent blank line usage","commit_id":"49ffbb04fc56be90e9e4cf727eb40593357ef04c"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"b0f64cd3790274a558cbbb44412afd88ff49bede","unresolved":false,"context_lines":[{"line_number":26,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ inventory_hostname }}-cert.pem\""},{"line_number":27,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ redis_tls_certfile }}\""},{"line_number":28,"context_line":"    backend_tls_cert: \"{{ lookup(\u0027first_found\u0027, certs) }}\""},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"  notify:"},{"line_number":31,"context_line":"    - \"Restart {{ item.key }} container\""},{"line_number":32,"context_line":"  when:"}],"source_content_type":"text/x-yaml","patch_set":14,"id":"f480cfcb_4593baa6","line":29,"in_reply_to":"f994f897_9cce5b03","updated":"2024-03-12 14:55:51.000000000","message":"Done","commit_id":"49ffbb04fc56be90e9e4cf727eb40593357ef04c"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"4f0ac57762d0df7841e06d6b6b5e9de381837c99","unresolved":true,"context_lines":[{"line_number":27,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ redis_tls_certfile }}\""},{"line_number":28,"context_line":"    backend_tls_cert: \"{{ lookup(\u0027first_found\u0027, certs) }}\""},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"  notify:"},{"line_number":31,"context_line":"    - \"Restart {{ item.key }} container\""},{"line_number":32,"context_line":"  when:"},{"line_number":33,"context_line":"    - enable_redis | bool"},{"line_number":34,"context_line":"    - redis_enable_tls | bool"},{"line_number":35,"context_line":""},{"line_number":36,"context_line":"- name: Copying over TLS key"},{"line_number":37,"context_line":"  become: true"}],"source_content_type":"text/x-yaml","patch_set":14,"id":"9cd5e4ff_4fbb5371","line":34,"range":{"start_line":30,"start_character":1,"end_line":34,"end_character":29},"updated":"2024-03-11 15:21:35.000000000","message":"please keep the ordering of `notify` and `when` the same in the same file (it\u0027s the reverse in the \"copying over extra ca certficates\" task).","commit_id":"49ffbb04fc56be90e9e4cf727eb40593357ef04c"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"b0f64cd3790274a558cbbb44412afd88ff49bede","unresolved":false,"context_lines":[{"line_number":27,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ redis_tls_certfile }}\""},{"line_number":28,"context_line":"    backend_tls_cert: \"{{ lookup(\u0027first_found\u0027, certs) }}\""},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"  notify:"},{"line_number":31,"context_line":"    - \"Restart {{ item.key }} container\""},{"line_number":32,"context_line":"  when:"},{"line_number":33,"context_line":"    - enable_redis | bool"},{"line_number":34,"context_line":"    - redis_enable_tls | bool"},{"line_number":35,"context_line":""},{"line_number":36,"context_line":"- name: Copying over TLS key"},{"line_number":37,"context_line":"  become: true"}],"source_content_type":"text/x-yaml","patch_set":14,"id":"0b1d2569_b3c669bb","line":34,"range":{"start_line":30,"start_character":1,"end_line":34,"end_character":29},"in_reply_to":"9cd5e4ff_4fbb5371","updated":"2024-03-12 14:55:51.000000000","message":"Done","commit_id":"49ffbb04fc56be90e9e4cf727eb40593357ef04c"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"4f0ac57762d0df7841e06d6b6b5e9de381837c99","unresolved":true,"context_lines":[{"line_number":46,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ inventory_hostname }}-key.pem\""},{"line_number":47,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ redis_tls_keyfile }}\""},{"line_number":48,"context_line":"    backend_tls_key: \"{{ lookup(\u0027first_found\u0027, keys) }}\""},{"line_number":49,"context_line":"  notify:"},{"line_number":50,"context_line":"    - \"Restart {{ item.key }} container\""},{"line_number":51,"context_line":"  when:"},{"line_number":52,"context_line":"    - enable_redis | bool"},{"line_number":53,"context_line":"    - redis_enable_tls | bool"}],"source_content_type":"text/x-yaml","patch_set":14,"id":"76e2b8d5_8f1a1441","line":51,"range":{"start_line":49,"start_character":1,"end_line":51,"end_character":7},"updated":"2024-03-11 15:21:35.000000000","message":"see above, please keep the ordering of elements consistent (notify, when)","commit_id":"49ffbb04fc56be90e9e4cf727eb40593357ef04c"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"b0f64cd3790274a558cbbb44412afd88ff49bede","unresolved":false,"context_lines":[{"line_number":46,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ inventory_hostname }}-key.pem\""},{"line_number":47,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ redis_tls_keyfile }}\""},{"line_number":48,"context_line":"    backend_tls_key: \"{{ lookup(\u0027first_found\u0027, keys) }}\""},{"line_number":49,"context_line":"  notify:"},{"line_number":50,"context_line":"    - \"Restart {{ item.key }} container\""},{"line_number":51,"context_line":"  when:"},{"line_number":52,"context_line":"    - enable_redis | bool"},{"line_number":53,"context_line":"    - redis_enable_tls | bool"}],"source_content_type":"text/x-yaml","patch_set":14,"id":"ac1cd588_96eeddb3","line":51,"range":{"start_line":49,"start_character":1,"end_line":51,"end_character":7},"in_reply_to":"76e2b8d5_8f1a1441","updated":"2024-03-12 14:55:51.000000000","message":"Done","commit_id":"49ffbb04fc56be90e9e4cf727eb40593357ef04c"},{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"fd7e4a30ad80f152e8ae4a391372b01d80ada6bd","unresolved":true,"context_lines":[{"line_number":8,"context_line":"    mode: \"0644\""},{"line_number":9,"context_line":"  when:"},{"line_number":10,"context_line":"    - kolla_copy_ca_into_containers | bool"},{"line_number":11,"context_line":"    - enable_redis | bool"},{"line_number":12,"context_line":"    - redis_enable_tls | bool"},{"line_number":13,"context_line":"  notify:"},{"line_number":14,"context_line":"    - \"Restart {{ item.key }} container\""}],"source_content_type":"text/x-yaml","patch_set":15,"id":"77b5ab19_f4937f07","line":11,"updated":"2024-04-15 11:03:29.000000000","message":"ditto","commit_id":"f782094befbfe762912cf95fdc4b719a030f7329"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"e82a3433b2f82baa3029b0f6ca5476e08044bdff","unresolved":false,"context_lines":[{"line_number":8,"context_line":"    mode: \"0644\""},{"line_number":9,"context_line":"  when:"},{"line_number":10,"context_line":"    - kolla_copy_ca_into_containers | bool"},{"line_number":11,"context_line":"    - enable_redis | bool"},{"line_number":12,"context_line":"    - redis_enable_tls | bool"},{"line_number":13,"context_line":"  notify:"},{"line_number":14,"context_line":"    - \"Restart {{ item.key }} container\""}],"source_content_type":"text/x-yaml","patch_set":15,"id":"88f3aac3_1f382e91","line":11,"in_reply_to":"77b5ab19_f4937f07","updated":"2024-04-17 10:54:28.000000000","message":"Acknowledged","commit_id":"f782094befbfe762912cf95fdc4b719a030f7329"},{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"fd7e4a30ad80f152e8ae4a391372b01d80ada6bd","unresolved":true,"context_lines":[{"line_number":13,"context_line":"  notify:"},{"line_number":14,"context_line":"    - \"Restart {{ item.key }} container\""},{"line_number":15,"context_line":""},{"line_number":16,"context_line":"- name: Copying over TLS certificate"},{"line_number":17,"context_line":"  become: true"},{"line_number":18,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":19,"context_line":"  copy:"}],"source_content_type":"text/x-yaml","patch_set":15,"id":"db31d2ba_a904d24e","line":16,"updated":"2024-04-15 11:03:29.000000000","message":"what\u0027s wrong with service-cert-copy role?","commit_id":"f782094befbfe762912cf95fdc4b719a030f7329"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"e82a3433b2f82baa3029b0f6ca5476e08044bdff","unresolved":false,"context_lines":[{"line_number":13,"context_line":"  notify:"},{"line_number":14,"context_line":"    - \"Restart {{ item.key }} container\""},{"line_number":15,"context_line":""},{"line_number":16,"context_line":"- name: Copying over TLS certificate"},{"line_number":17,"context_line":"  become: true"},{"line_number":18,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":19,"context_line":"  copy:"}],"source_content_type":"text/x-yaml","patch_set":15,"id":"2f903cf5_5fc1c547","line":16,"in_reply_to":"6838cc90_e5126dbd","updated":"2024-04-17 10:54:28.000000000","message":"Acknowledged","commit_id":"f782094befbfe762912cf95fdc4b719a030f7329"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"a2b1f9dc11f8bc8d29770295af4f6555c7745148","unresolved":true,"context_lines":[{"line_number":13,"context_line":"  notify:"},{"line_number":14,"context_line":"    - \"Restart {{ item.key }} container\""},{"line_number":15,"context_line":""},{"line_number":16,"context_line":"- name: Copying over TLS certificate"},{"line_number":17,"context_line":"  become: true"},{"line_number":18,"context_line":"  with_dict: \"{{ project_services | select_services_enabled_and_mapped_to_host }}\""},{"line_number":19,"context_line":"  copy:"}],"source_content_type":"text/x-yaml","patch_set":15,"id":"6838cc90_e5126dbd","line":16,"in_reply_to":"db31d2ba_a904d24e","updated":"2024-04-15 11:38:31.000000000","message":"There\u0027s this condition, that implies HAProxy is used. I assume this is why [rabbitmq](https://opendev.org/openstack/kolla-ansible/src/branch/master/ansible/roles/rabbitmq/tasks/copy-certs.yml) has a copy of the role.\n```yaml\n  when:\n    - item.value.haproxy is defined\n    - item.value.haproxy.values() | selectattr(\u0027enabled\u0027, \u0027defined\u0027) | map(attribute\u003d\u0027enabled\u0027) | map(\u0027bool\u0027) | select | list | length \u003e 0\n    - item.value.haproxy.values() | selectattr(\u0027tls_backend\u0027, \u0027defined\u0027) | map(attribute\u003d\u0027tls_backend\u0027) | map(\u0027bool\u0027) | select | list | length \u003e 0\n    - not kolla_externally_managed_cert | bool\n```\nI had already got this proposed in a different patch for [proxysql](https://review.opendev.org/c/openstack/kolla-ansible/+/9099120, where I changed the condition in service-cert-copy. So we can wait until proxysql patch getes merged and then we can use it.","commit_id":"f782094befbfe762912cf95fdc4b719a030f7329"},{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"fd7e4a30ad80f152e8ae4a391372b01d80ada6bd","unresolved":true,"context_lines":[{"line_number":27,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ redis_tls_certfile }}\""},{"line_number":28,"context_line":"    backend_tls_cert: \"{{ lookup(\u0027first_found\u0027, certs) }}\""},{"line_number":29,"context_line":"  when:"},{"line_number":30,"context_line":"    - enable_redis | bool"},{"line_number":31,"context_line":"    - redis_enable_tls | bool"},{"line_number":32,"context_line":"  notify:"},{"line_number":33,"context_line":"    - \"Restart {{ item.key }} container\""}],"source_content_type":"text/x-yaml","patch_set":15,"id":"fb92deed_c2b98bab","line":30,"updated":"2024-04-15 11:03:29.000000000","message":"ditto","commit_id":"f782094befbfe762912cf95fdc4b719a030f7329"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"e82a3433b2f82baa3029b0f6ca5476e08044bdff","unresolved":false,"context_lines":[{"line_number":27,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ redis_tls_certfile }}\""},{"line_number":28,"context_line":"    backend_tls_cert: \"{{ lookup(\u0027first_found\u0027, certs) }}\""},{"line_number":29,"context_line":"  when:"},{"line_number":30,"context_line":"    - enable_redis | bool"},{"line_number":31,"context_line":"    - redis_enable_tls | bool"},{"line_number":32,"context_line":"  notify:"},{"line_number":33,"context_line":"    - \"Restart {{ item.key }} container\""}],"source_content_type":"text/x-yaml","patch_set":15,"id":"d9d77279_a7e9b8f6","line":30,"in_reply_to":"fb92deed_c2b98bab","updated":"2024-04-17 10:54:28.000000000","message":"Acknowledged","commit_id":"f782094befbfe762912cf95fdc4b719a030f7329"},{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"fd7e4a30ad80f152e8ae4a391372b01d80ada6bd","unresolved":true,"context_lines":[{"line_number":46,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ redis_tls_keyfile }}\""},{"line_number":47,"context_line":"    backend_tls_key: \"{{ lookup(\u0027first_found\u0027, keys) }}\""},{"line_number":48,"context_line":"  when:"},{"line_number":49,"context_line":"    - enable_redis | bool"},{"line_number":50,"context_line":"    - redis_enable_tls | bool"},{"line_number":51,"context_line":"  notify:"},{"line_number":52,"context_line":"    - \"Restart {{ item.key }} container\""}],"source_content_type":"text/x-yaml","patch_set":15,"id":"02a1fbff_542b862f","line":49,"updated":"2024-04-15 11:03:29.000000000","message":"ditto","commit_id":"f782094befbfe762912cf95fdc4b719a030f7329"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"e82a3433b2f82baa3029b0f6ca5476e08044bdff","unresolved":false,"context_lines":[{"line_number":46,"context_line":"      - \"{{ kolla_certificates_dir }}/{{ redis_tls_keyfile }}\""},{"line_number":47,"context_line":"    backend_tls_key: \"{{ lookup(\u0027first_found\u0027, keys) }}\""},{"line_number":48,"context_line":"  when:"},{"line_number":49,"context_line":"    - enable_redis | bool"},{"line_number":50,"context_line":"    - redis_enable_tls | bool"},{"line_number":51,"context_line":"  notify:"},{"line_number":52,"context_line":"    - \"Restart {{ item.key }} container\""}],"source_content_type":"text/x-yaml","patch_set":15,"id":"ab7f2b3d_282cc44e","line":49,"in_reply_to":"02a1fbff_542b862f","updated":"2024-04-17 10:54:28.000000000","message":"Acknowledged","commit_id":"f782094befbfe762912cf95fdc4b719a030f7329"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"7779ba381fa6abf437c7f5cfbe3d0498651be642","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"- name: \"Copy certificates and keys for {{ project_name }}\""},{"line_number":3,"context_line":"  import_role:"},{"line_number":4,"context_line":"    role: service-cert-copy"},{"line_number":5,"context_line":"  vars:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"ccd41e77_6095f2ac","line":2,"updated":"2024-05-28 11:10:15.000000000","message":"shouldn\u0027t we add the import service-cert-copy role here as in all other services? before this task","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"c1a7c1ffb96420f78885cdf615fb84bee3e15392","unresolved":false,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"- name: \"Copy certificates and keys for {{ project_name }}\""},{"line_number":3,"context_line":"  import_role:"},{"line_number":4,"context_line":"    role: service-cert-copy"},{"line_number":5,"context_line":"  vars:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"b814b695_b1068241","line":2,"in_reply_to":"4f3af7e2_49b19cfe","updated":"2024-05-28 14:22:37.000000000","message":"sorry for confusion, lets leave this as is.","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"b916f29cf841d0b38522fd1f592d091d1e5b8605","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"- name: \"Copy certificates and keys for {{ project_name }}\""},{"line_number":3,"context_line":"  import_role:"},{"line_number":4,"context_line":"    role: service-cert-copy"},{"line_number":5,"context_line":"  vars:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"4f3af7e2_49b19cfe","line":2,"in_reply_to":"686a0303_4d4da6a1","updated":"2024-05-28 14:18:06.000000000","message":"I also don\u0027t understand, Maksim could you elaborate?\n\nThis seems to be the same mechanism as e.g. used in glance/tasks/copy-certs.yml, no?","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"4585b081f40966aa637cf4eedc4d16a115639907","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"- name: \"Copy certificates and keys for {{ project_name }}\""},{"line_number":3,"context_line":"  import_role:"},{"line_number":4,"context_line":"    role: service-cert-copy"},{"line_number":5,"context_line":"  vars:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"4b761337_6a545dc5","line":2,"in_reply_to":"686a0303_4d4da6a1","updated":"2024-05-28 14:10:55.000000000","message":"I mean do we really need new ansible/roles/redis/tasks/copy-certs.yml since we already modified copy-certs.yml for all other roles to copy redis certs?","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"96ed591f116956847b22d230fad98acf0f6da425","unresolved":false,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"- name: \"Copy certificates and keys for {{ project_name }}\""},{"line_number":3,"context_line":"  import_role:"},{"line_number":4,"context_line":"    role: service-cert-copy"},{"line_number":5,"context_line":"  vars:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"1fd4fdb5_a5f75a67","line":2,"in_reply_to":"b814b695_b1068241","updated":"2024-05-28 14:23:28.000000000","message":"this - I mean only ansible/roles/redis/tasks/copy-certs.yml","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"651d59c3a7cd04b1de7440795cfbcdfb02f66561","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"- name: \"Copy certificates and keys for {{ project_name }}\""},{"line_number":3,"context_line":"  import_role:"},{"line_number":4,"context_line":"    role: service-cert-copy"},{"line_number":5,"context_line":"  vars:"}],"source_content_type":"text/x-yaml","patch_set":23,"id":"686a0303_4d4da6a1","line":2,"in_reply_to":"ccd41e77_6095f2ac","updated":"2024-05-28 13:43:21.000000000","message":"I don\u0027t know what you mean by that","commit_id":"97da8e3e48cde5e98434cf2aa3a7aed0936f78e5"}],"ansible/roles/redis/templates/redis-sentinel.json.j2":[{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"7de9752a15e62bce9e773bd7788e2136bb85e960","unresolved":true,"context_lines":[{"line_number":9,"context_line":"        }"},{"line_number":10,"context_line":"        {% if redis_enable_tls | bool %},"},{"line_number":11,"context_line":"        {% if not redis_tls_use_openstack_ca | bool %}"},{"line_number":12,"context_line":""},{"line_number":13,"context_line":"        {"},{"line_number":14,"context_line":"            \"source\": \"{{ container_config_directory }}/ca-certificates/{{ redis_tls_cafile }}\","},{"line_number":15,"context_line":"            \"dest\": \"{{ redis_tls_container_path ~ \u0027/\u0027 ~ redis_tls_cafile }}\","}],"source_content_type":"text/x-jinja2","patch_set":1,"id":"0e3b4c53_c9871976","line":12,"updated":"2024-02-16 09:42:08.000000000","message":"unnecessary newline","commit_id":"f8a22eabf37c797d90a51e30f661762affdbff55"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"25ac711d7610b11259ca0379bb466e3a82a01d27","unresolved":false,"context_lines":[{"line_number":9,"context_line":"        }"},{"line_number":10,"context_line":"        {% if redis_enable_tls | bool %},"},{"line_number":11,"context_line":"        {% if not redis_tls_use_openstack_ca | bool %}"},{"line_number":12,"context_line":""},{"line_number":13,"context_line":"        {"},{"line_number":14,"context_line":"            \"source\": \"{{ container_config_directory }}/ca-certificates/{{ redis_tls_cafile }}\","},{"line_number":15,"context_line":"            \"dest\": \"{{ redis_tls_container_path ~ \u0027/\u0027 ~ redis_tls_cafile }}\","}],"source_content_type":"text/x-jinja2","patch_set":1,"id":"ffbb197a_1d2b6f08","line":12,"in_reply_to":"0e3b4c53_c9871976","updated":"2024-02-16 10:17:33.000000000","message":"Acknowledged","commit_id":"f8a22eabf37c797d90a51e30f661762affdbff55"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"c6f2b7eb846f17e87d40d7d07da79565c402939b","unresolved":true,"context_lines":[{"line_number":17,"context_line":"        },"},{"line_number":18,"context_line":"        {% endif %}"},{"line_number":19,"context_line":"        {"},{"line_number":20,"context_line":"            \"source\": \"{{ container_config_directory }}/redis-cert.pem\","},{"line_number":21,"context_line":"            \"dest\": \"{{ redis_tls_container_path ~ \u0027/\u0027 ~ redis_tls_certfile }}\","},{"line_number":22,"context_line":"            \"owner\": \"redis\","},{"line_number":23,"context_line":"            \"perm\": \"0600\""}],"source_content_type":"text/x-jinja2","patch_set":12,"id":"fbb3a52b_cc39dece","line":20,"range":{"start_line":20,"start_character":56,"end_line":20,"end_character":70},"updated":"2024-03-07 07:17:26.000000000","message":"doesn\u0027t this also need to use redis_tls_certfile?","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"bd4839b3d3ec5ab2c9ef3b4c4d5924da2851763e","unresolved":false,"context_lines":[{"line_number":17,"context_line":"        },"},{"line_number":18,"context_line":"        {% endif %}"},{"line_number":19,"context_line":"        {"},{"line_number":20,"context_line":"            \"source\": \"{{ container_config_directory }}/redis-cert.pem\","},{"line_number":21,"context_line":"            \"dest\": \"{{ redis_tls_container_path ~ \u0027/\u0027 ~ redis_tls_certfile }}\","},{"line_number":22,"context_line":"            \"owner\": \"redis\","},{"line_number":23,"context_line":"            \"perm\": \"0600\""}],"source_content_type":"text/x-jinja2","patch_set":12,"id":"32796086_4cdfc8bc","line":20,"range":{"start_line":20,"start_character":56,"end_line":20,"end_character":70},"in_reply_to":"fbb3a52b_cc39dece","updated":"2024-03-07 13:39:30.000000000","message":"Acknowledged","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"}],"ansible/roles/redis/templates/redis.conf.j2":[{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"bcd5e99a3301e38bac800b037105903669c65482","unresolved":true,"context_lines":[{"line_number":1,"context_line":"bind {{ api_interface_address }}"},{"line_number":2,"context_line":"port {{ \u00270\u0027 if redis_enable_tls | bool else redis_port }}"},{"line_number":3,"context_line":"tcp-backlog 511"},{"line_number":4,"context_line":"timeout 0"},{"line_number":5,"context_line":"tcp-keepalive 300"}],"source_content_type":"text/x-jinja2","patch_set":3,"id":"b56d2782_2d28d692","line":2,"range":{"start_line":2,"start_character":0,"end_line":2,"end_character":2},"updated":"2024-02-19 14:42:03.000000000","message":"this does not honor the setting of redis_port.\n\nwe should make sure to at least mention this in the release notes, that when enabling redis_enable_tls access via the unencryped port will be blocked.","commit_id":"b74011d48fee6592508334b4aad730dfbb277f29"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"517d1d23220c9e53e6b5e76de206ba12b141dcd4","unresolved":false,"context_lines":[{"line_number":1,"context_line":"bind {{ api_interface_address }}"},{"line_number":2,"context_line":"port {{ \u00270\u0027 if redis_enable_tls | bool else redis_port }}"},{"line_number":3,"context_line":"tcp-backlog 511"},{"line_number":4,"context_line":"timeout 0"},{"line_number":5,"context_line":"tcp-keepalive 300"}],"source_content_type":"text/x-jinja2","patch_set":3,"id":"d73b936d_c2c5c23b","line":2,"range":{"start_line":2,"start_character":0,"end_line":2,"end_character":2},"in_reply_to":"b56d2782_2d28d692","updated":"2024-02-20 09:04:20.000000000","message":"Acknowledged","commit_id":"b74011d48fee6592508334b4aad730dfbb277f29"}],"doc/source/admin/tls.rst":[{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"4d012702ed6f88d4cb300a2729085e7cb9822b21","unresolved":true,"context_lines":[{"line_number":374,"context_line":""},{"line_number":375,"context_line":".. code:: yaml"},{"line_number":376,"context_line":""},{"line_number":377,"context_line":"   redis_tls_port: \"6443\""},{"line_number":378,"context_line":"   redis_sentinel_tls_port: \"26443\""},{"line_number":379,"context_line":""},{"line_number":380,"context_line":"Redis certificates should be located in ``/etc/kolla/certificates``"},{"line_number":381,"context_line":""}],"source_content_type":"text/x-rst","patch_set":11,"id":"6841c8b5_ef56c384","line":378,"range":{"start_line":377,"start_character":0,"end_line":378,"end_character":35},"updated":"2024-02-28 15:50:45.000000000","message":"please update these to the new values.","commit_id":"f0d34317c0cbda9751544904719e8d3cb6f6948e"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"fb06fd7356f3d71a2d4abb01e9c70dd89a77a5f5","unresolved":false,"context_lines":[{"line_number":374,"context_line":""},{"line_number":375,"context_line":".. code:: yaml"},{"line_number":376,"context_line":""},{"line_number":377,"context_line":"   redis_tls_port: \"6443\""},{"line_number":378,"context_line":"   redis_sentinel_tls_port: \"26443\""},{"line_number":379,"context_line":""},{"line_number":380,"context_line":"Redis certificates should be located in ``/etc/kolla/certificates``"},{"line_number":381,"context_line":""}],"source_content_type":"text/x-rst","patch_set":11,"id":"e0fba83d_15b39c88","line":378,"range":{"start_line":377,"start_character":0,"end_line":378,"end_character":35},"in_reply_to":"6841c8b5_ef56c384","updated":"2024-02-28 16:22:09.000000000","message":"Acknowledged","commit_id":"f0d34317c0cbda9751544904719e8d3cb6f6948e"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"4d012702ed6f88d4cb300a2729085e7cb9822b21","unresolved":true,"context_lines":[{"line_number":381,"context_line":""},{"line_number":382,"context_line":".. code:: yaml"},{"line_number":383,"context_line":""},{"line_number":384,"context_line":"   # Enables TLS for Redis"},{"line_number":385,"context_line":"   redis_enable_tls: \"yes\""},{"line_number":386,"context_line":""},{"line_number":387,"context_line":"   # Certificate \u0026 Key"},{"line_number":388,"context_line":"   redis_tls_certfile: \"redis-cert.pem\""}],"source_content_type":"text/x-rst","patch_set":11,"id":"a3eeeca2_3f964295","line":385,"range":{"start_line":384,"start_character":0,"end_line":385,"end_character":26},"updated":"2024-02-28 15:50:45.000000000","message":"please update this. There should be some text that this is now dependent on `kolla_enable_tls_backend` in the intro text to this section imho.","commit_id":"f0d34317c0cbda9751544904719e8d3cb6f6948e"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"fb06fd7356f3d71a2d4abb01e9c70dd89a77a5f5","unresolved":false,"context_lines":[{"line_number":381,"context_line":""},{"line_number":382,"context_line":".. code:: yaml"},{"line_number":383,"context_line":""},{"line_number":384,"context_line":"   # Enables TLS for Redis"},{"line_number":385,"context_line":"   redis_enable_tls: \"yes\""},{"line_number":386,"context_line":""},{"line_number":387,"context_line":"   # Certificate \u0026 Key"},{"line_number":388,"context_line":"   redis_tls_certfile: \"redis-cert.pem\""}],"source_content_type":"text/x-rst","patch_set":11,"id":"6835b108_e31a73f2","line":385,"range":{"start_line":384,"start_character":0,"end_line":385,"end_character":26},"in_reply_to":"a3eeeca2_3f964295","updated":"2024-02-28 16:22:09.000000000","message":"Acknowledged","commit_id":"f0d34317c0cbda9751544904719e8d3cb6f6948e"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"c6f2b7eb846f17e87d40d7d07da79565c402939b","unresolved":true,"context_lines":[{"line_number":365,"context_line":"appropriate hosts in the appropriate location."},{"line_number":366,"context_line":""},{"line_number":367,"context_line":"Redis TLS Certificates"},{"line_number":368,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":369,"context_line":""},{"line_number":370,"context_line":"Redis uses Redis-Sentinel for high availability, not HAProxy, that\u0027s why"},{"line_number":371,"context_line":"it has it\u0027s own certificates. Note that when Redis TLS is enabled, the"}],"source_content_type":"text/x-rst","patch_set":12,"id":"9b0f28f0_b9a8a082","line":368,"updated":"2024-03-07 07:17:26.000000000","message":"nit: please make the length of this match the text above","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"bd4839b3d3ec5ab2c9ef3b4c4d5924da2851763e","unresolved":false,"context_lines":[{"line_number":365,"context_line":"appropriate hosts in the appropriate location."},{"line_number":366,"context_line":""},{"line_number":367,"context_line":"Redis TLS Certificates"},{"line_number":368,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":369,"context_line":""},{"line_number":370,"context_line":"Redis uses Redis-Sentinel for high availability, not HAProxy, that\u0027s why"},{"line_number":371,"context_line":"it has it\u0027s own certificates. Note that when Redis TLS is enabled, the"}],"source_content_type":"text/x-rst","patch_set":12,"id":"21f3444b_43860056","line":368,"in_reply_to":"9b0f28f0_b9a8a082","updated":"2024-03-07 13:39:30.000000000","message":"Acknowledged","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"c6f2b7eb846f17e87d40d7d07da79565c402939b","unresolved":true,"context_lines":[{"line_number":368,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":369,"context_line":""},{"line_number":370,"context_line":"Redis uses Redis-Sentinel for high availability, not HAProxy, that\u0027s why"},{"line_number":371,"context_line":"it has it\u0027s own certificates. Note that when Redis TLS is enabled, the"},{"line_number":372,"context_line":"non-TLS ports for both Redis and Redis Sentinel are disabled. Instead,"},{"line_number":373,"context_line":"the following ports are used"},{"line_number":374,"context_line":""}],"source_content_type":"text/x-rst","patch_set":12,"id":"9c0089eb_281b9692","line":371,"range":{"start_line":371,"start_character":7,"end_line":371,"end_character":11},"updated":"2024-03-07 07:17:26.000000000","message":"nit: its","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"bd4839b3d3ec5ab2c9ef3b4c4d5924da2851763e","unresolved":false,"context_lines":[{"line_number":368,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":369,"context_line":""},{"line_number":370,"context_line":"Redis uses Redis-Sentinel for high availability, not HAProxy, that\u0027s why"},{"line_number":371,"context_line":"it has it\u0027s own certificates. Note that when Redis TLS is enabled, the"},{"line_number":372,"context_line":"non-TLS ports for both Redis and Redis Sentinel are disabled. Instead,"},{"line_number":373,"context_line":"the following ports are used"},{"line_number":374,"context_line":""}],"source_content_type":"text/x-rst","patch_set":12,"id":"39fd47a2_6eb511f3","line":371,"range":{"start_line":371,"start_character":7,"end_line":371,"end_character":11},"in_reply_to":"9c0089eb_281b9692","updated":"2024-03-07 13:39:30.000000000","message":"Acknowledged","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"}],"releasenotes/notes/implement-redis-tls-11e470ced256611a.yaml":[{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"bcd5e99a3301e38bac800b037105903669c65482","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"features:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    Implements TLS support for Redis."},{"line_number":5,"context_line":"    `Partial Blueprint redis-caching-backend \u003chttps://blueprints.launchpad.net/kolla-ansible/+spec/redis-caching-backend\u003e`__"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"38f9756b_d9722bca","line":5,"range":{"start_line":4,"start_character":4,"end_line":5,"end_character":124},"updated":"2024-02-19 14:42:03.000000000","message":"this is missing an `upgrades` section, which mentions that if TLS support is enabled access via the non TLS port will stop working.","commit_id":"b74011d48fee6592508334b4aad730dfbb277f29"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"517d1d23220c9e53e6b5e76de206ba12b141dcd4","unresolved":false,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"features:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    Implements TLS support for Redis."},{"line_number":5,"context_line":"    `Partial Blueprint redis-caching-backend \u003chttps://blueprints.launchpad.net/kolla-ansible/+spec/redis-caching-backend\u003e`__"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"f36a8439_6c3b1d3e","line":5,"range":{"start_line":4,"start_character":4,"end_line":5,"end_character":124},"in_reply_to":"38f9756b_d9722bca","updated":"2024-02-20 09:04:20.000000000","message":"Acknowledged","commit_id":"b74011d48fee6592508334b4aad730dfbb277f29"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"c6f2b7eb846f17e87d40d7d07da79565c402939b","unresolved":true,"context_lines":[{"line_number":5,"context_line":"    `Partial Blueprint redis-caching-backend \u003chttps://blueprints.launchpad.net/kolla-ansible/+spec/redis-caching-backend\u003e`__"},{"line_number":6,"context_line":"upgrade:"},{"line_number":7,"context_line":"  - |"},{"line_number":8,"context_line":"    Enabling Redis TLS port `redis_enable_tls: 1` blocks Redis non-TLS port"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"923a5cca_4a1500cf","line":8,"range":{"start_line":8,"start_character":29,"end_line":8,"end_character":48},"updated":"2024-03-07 07:17:26.000000000","message":"this should be quoted in double backticks\n\nbut also I\u0027m not sure that this \"upgrade\" section is needed, since this only affects deployments that actively override the default and thus should know what they are doing","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"bd4839b3d3ec5ab2c9ef3b4c4d5924da2851763e","unresolved":false,"context_lines":[{"line_number":5,"context_line":"    `Partial Blueprint redis-caching-backend \u003chttps://blueprints.launchpad.net/kolla-ansible/+spec/redis-caching-backend\u003e`__"},{"line_number":6,"context_line":"upgrade:"},{"line_number":7,"context_line":"  - |"},{"line_number":8,"context_line":"    Enabling Redis TLS port `redis_enable_tls: 1` blocks Redis non-TLS port"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"c3d1bf1f_c93dbfd7","line":8,"range":{"start_line":8,"start_character":29,"end_line":8,"end_character":48},"in_reply_to":"8dd43584_13fd0bf9","updated":"2024-03-07 13:39:30.000000000","message":"Acknowledged","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"cee9475902ec060901bd74827313f6251537d2f1","unresolved":true,"context_lines":[{"line_number":5,"context_line":"    `Partial Blueprint redis-caching-backend \u003chttps://blueprints.launchpad.net/kolla-ansible/+spec/redis-caching-backend\u003e`__"},{"line_number":6,"context_line":"upgrade:"},{"line_number":7,"context_line":"  - |"},{"line_number":8,"context_line":"    Enabling Redis TLS port `redis_enable_tls: 1` blocks Redis non-TLS port"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"8dd43584_13fd0bf9","line":8,"range":{"start_line":8,"start_character":29,"end_line":8,"end_character":48},"in_reply_to":"923a5cca_4a1500cf","updated":"2024-03-07 08:52:06.000000000","message":"I think the information is key, I will move it to features section","commit_id":"321a4eeee9801b0f4be4aa0ad94ba929ca4bd9ff"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"c84365a0424654973166794e3679e2370e7e15b0","unresolved":true,"context_lines":[{"line_number":2,"context_line":"features:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    Implements TLS support for Redis."},{"line_number":5,"context_line":"    Enabling Redis TLS port ``redis_enable_tls: 1`` blocks Redis non-TLS port"},{"line_number":6,"context_line":"    `Partial Blueprint redis-caching-backend \u003chttps://blueprints.launchpad.net/kolla-ansible/+spec/redis-caching-backend\u003e`__"}],"source_content_type":"text/x-yaml","patch_set":20,"id":"679c2585_7659e60a","line":5,"range":{"start_line":5,"start_character":0,"end_line":5,"end_character":2},"updated":"2024-04-30 13:30:23.000000000","message":"please also put a link to the new docs in the reno.\nYou can see an example how this is done e.g. here: https://review.opendev.org/c/openstack/kolla-ansible/+/915975/3/releasenotes/notes/adds-node-exporter-targets-extra-c037d4755d1002e8.yaml","commit_id":"2eaa18ccc358fb80b45a4f26486812b55bf349ae"},{"author":{"_account_id":36624,"name":"Matúš Jenča","email":"matus.jenca@dnation.cloud","username":"matusjenca"},"change_message_id":"b13e821c22469e47e785009d9905cb9ec3152f8d","unresolved":false,"context_lines":[{"line_number":2,"context_line":"features:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    Implements TLS support for Redis."},{"line_number":5,"context_line":"    Enabling Redis TLS port ``redis_enable_tls: 1`` blocks Redis non-TLS port"},{"line_number":6,"context_line":"    `Partial Blueprint redis-caching-backend \u003chttps://blueprints.launchpad.net/kolla-ansible/+spec/redis-caching-backend\u003e`__"}],"source_content_type":"text/x-yaml","patch_set":20,"id":"200da0bc_bfb8dea7","line":5,"range":{"start_line":5,"start_character":0,"end_line":5,"end_character":2},"in_reply_to":"679c2585_7659e60a","updated":"2024-05-02 08:34:49.000000000","message":"Done","commit_id":"2eaa18ccc358fb80b45a4f26486812b55bf349ae"}]}
