)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":27339,"name":"Michal Arbet","email":"michal.arbet@ultimum.io","username":"michalarbet"},"change_message_id":"92d24ac739c5a3e499d9788900022845bb319f2f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"410fa0bb_aaacea0c","updated":"2026-08-04 16:35:34.000000000","message":"recheck neutron fixed","commit_id":"6e55d7edc9eabb62365e10b5cd72bc091a64be1d"},{"author":{"_account_id":27339,"name":"Michal Arbet","email":"michal.arbet@ultimum.io","username":"michalarbet"},"change_message_id":"7e01eac6051e3bf1dfeae577eb78fb8c8e097cb3","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"dc44e8ec_bfb495ef","updated":"2026-08-04 23:06:18.000000000","message":"recheck new images","commit_id":"c4608870e20728210bdec1f1cb389fd51b37625b"},{"author":{"_account_id":38857,"name":"Kurt Bendl","display_name":"kbendl","email":"kbendl@tool.net","username":"kbendl"},"change_message_id":"ff7f714c10f2a99d784e3e0af549eb62c0aa6e67","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"11ee4cea_4fbc8ba1","updated":"2026-08-10 13:43:44.000000000","message":"Considering the discussion last week in the #openstack-kolla irc regarding step-ca vs openBao: It seems to me, doing just a little reading, that step-ca is a one-shot tool to just handle certs, while openBao is an all-in-one secrets management tool that has solid security audit logging we could leverage for other things like tenant-specific keys, cider encryption, etc. Making security auditors happy is \"A Good Thing™\", OpenBao has logging and audit infrastructure that step-ca likely never will. I\u0027m not dis-ing the work at all. OpenBao has more knobs to figure out, for sure, but it makes more sense not to fragment and also to keep striving for more secure and supported supply chain in the codebase.","commit_id":"2863b017ef202898210ed7e74cfddf1f54bd1131"},{"author":{"_account_id":27339,"name":"Michal Arbet","email":"michal.arbet@ultimum.io","username":"michalarbet"},"change_message_id":"9bf0882aa2068c6f481ce57418eb25969ce67146","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"9b852b4a_4ff798aa","updated":"2026-08-07 09:19:17.000000000","message":"recheck infra issues","commit_id":"2863b017ef202898210ed7e74cfddf1f54bd1131"},{"author":{"_account_id":27339,"name":"Michal Arbet","email":"michal.arbet@ultimum.io","username":"michalarbet"},"change_message_id":"003f4527294b14dcf1dc2336fe07c23a09d19745","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"f39a56fd_0561dbac","updated":"2026-08-05 15:38:36.000000000","message":"recheck nonrelated","commit_id":"2863b017ef202898210ed7e74cfddf1f54bd1131"},{"author":{"_account_id":27339,"name":"Michal Arbet","email":"michal.arbet@ultimum.io","username":"michalarbet"},"change_message_id":"30184baedcdce00eaefc148cc25fc4bda7c3d5e7","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"0cdc8c79_b80571b3","updated":"2026-08-05 20:15:51.000000000","message":"recheck timeouts","commit_id":"2863b017ef202898210ed7e74cfddf1f54bd1131"},{"author":{"_account_id":27339,"name":"Michal Arbet","email":"michal.arbet@ultimum.io","username":"michalarbet"},"change_message_id":"7c5c6dc14ef1dba21efccf44a555a5e7e7d3c1e5","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"fb1e2640_c7b07ec4","in_reply_to":"11ee4cea_4fbc8ba1","updated":"2026-08-10 14:27:58.000000000","message":"Yes, step-ca doesn\u0027t try to do everything — I agree. It focuses solely on ACME.\n\nBut in the end, where is it set in stone that the ACME provider couldn\u0027t be configurable, allowing users to choose between OpenBao and step-ca?\n\nWhat if a user doesn\u0027t want to deploy, as you put it, a complex secrets management system, and genuinely only needs ACME?\n\nWe could simply have something like this in globals.yml:\n\nkolla_acme_provider: \"{% if whatever_needs_openbao_as_complex_system | bool %}openbao{% else %}step-ca{% endif %}\"\n\nThen we deploy the appropriate service based on that single variable. There\u0027s really nothing particularly complicated about that, and ultimately the choice is left to the user.","commit_id":"2863b017ef202898210ed7e74cfddf1f54bd1131"}]}
