)]}'
{"doc/source/installation/network_namespace.rst":[{"author":{"_account_id":23567,"name":"Luis Tomas Bolivar","email":"ltomasbo@redhat.com","username":"ltomasbo"},"change_message_id":"1f9d5dbcc7689d4d941799463b102a24dd819614","unresolved":false,"context_lines":[{"line_number":87,"context_line":"  KURYR_ENABLED_HANDLERS\u003dvif,lb,lbaasspec,namespace"},{"line_number":88,"context_line":""},{"line_number":89,"context_line":".. note::"},{"line_number":90,"context_line":"  In case ovn-octavia driver is used there is no need to enforce security group rules"},{"line_number":91,"context_line":"  at the load balancer level. To disable the enforcement, you need to set the following variable:"},{"line_number":92,"context_line":"  KURYR_ENFORCE_SG_RULES\u003dFalse"},{"line_number":93,"context_line":""},{"line_number":94,"context_line":"Testing the network per namespace functionality"},{"line_number":95,"context_line":"-----------------------------------------------"}],"source_content_type":"text/x-rst","patch_set":10,"id":"9fb8cfa7_95a8088c","line":92,"range":{"start_line":90,"start_character":0,"end_line":92,"end_character":30},"updated":"2019-07-01 07:42:53.000000000","message":"perhaps I would put it in a more generic way. \"If the loadbalancer maintains the source IP (such as ovn-octavia driver), there is no need to enforce sg rules at the load balancer level ...","commit_id":"1572556da837d1b1a6c5d401a0bfb3cdab70139a"}],"doc/source/installation/network_policy.rst":[{"author":{"_account_id":23567,"name":"Luis Tomas Bolivar","email":"ltomasbo@redhat.com","username":"ltomasbo"},"change_message_id":"1f9d5dbcc7689d4d941799463b102a24dd819614","unresolved":false,"context_lines":[{"line_number":67,"context_line":"    KURYR_SUBNET_DRIVER\u003dnamespace"},{"line_number":68,"context_line":""},{"line_number":69,"context_line":".. note::"},{"line_number":70,"context_line":"  In case ovn-octavia driver is used there is no need to enforce security group rules"},{"line_number":71,"context_line":"  at the load balancer level. To disable the enforcement, you need to set the following variable:"},{"line_number":72,"context_line":"  KURYR_ENFORCE_SG_RULES\u003dFalse"},{"line_number":73,"context_line":""},{"line_number":74,"context_line":"Testing the network policy support functionality"},{"line_number":75,"context_line":"------------------------------------------------"}],"source_content_type":"text/x-rst","patch_set":10,"id":"9fb8cfa7_5596104e","line":72,"range":{"start_line":70,"start_character":1,"end_line":72,"end_character":30},"updated":"2019-07-01 07:42:53.000000000","message":"ditto","commit_id":"1572556da837d1b1a6c5d401a0bfb3cdab70139a"}],"kuryr_kubernetes/config.py":[{"author":{"_account_id":11600,"name":"Michał Dulko","email":"michal.dulko@gmail.com","username":"dulek"},"change_message_id":"fbaf8769d8b6289a01613ba8c6004a1af9fb2d80","unresolved":false,"context_lines":[{"line_number":226,"context_line":"                        (\u0027update\u0027, \u0027add rules to the existing VIP SG\u0027)],"},{"line_number":227,"context_line":"               default\u003d\u0027update\u0027),"},{"line_number":228,"context_line":"    cfg.BoolOpt(\u0027enforce_sg_rules\u0027,"},{"line_number":229,"context_line":"                help\u003d_(\"Enable the enforcement of SG rules at the lbaas SG \""},{"line_number":230,"context_line":"                       \"in case the lbaas does not maintains the source IP \""},{"line_number":231,"context_line":"                       \"of the caller resource\"),"},{"line_number":232,"context_line":"                default\u003dTrue),"}],"source_content_type":"text/x-python","patch_set":7,"id":"9fb8cfa7_ae1acc79","line":229,"range":{"start_line":229,"start_character":66,"end_line":229,"end_character":71},"updated":"2019-06-27 09:43:52.000000000","message":"LB?","commit_id":"626395766934da51329c8b9ac7704cba9af2fca9"},{"author":{"_account_id":11600,"name":"Michał Dulko","email":"michal.dulko@gmail.com","username":"dulek"},"change_message_id":"fbaf8769d8b6289a01613ba8c6004a1af9fb2d80","unresolved":false,"context_lines":[{"line_number":227,"context_line":"               default\u003d\u0027update\u0027),"},{"line_number":228,"context_line":"    cfg.BoolOpt(\u0027enforce_sg_rules\u0027,"},{"line_number":229,"context_line":"                help\u003d_(\"Enable the enforcement of SG rules at the lbaas SG \""},{"line_number":230,"context_line":"                       \"in case the lbaas does not maintains the source IP \""},{"line_number":231,"context_line":"                       \"of the caller resource\"),"},{"line_number":232,"context_line":"                default\u003dTrue),"},{"line_number":233,"context_line":"]"}],"source_content_type":"text/x-python","patch_set":7,"id":"9fb8cfa7_ce1f006a","line":230,"range":{"start_line":230,"start_character":36,"end_line":230,"end_character":41},"updated":"2019-06-27 09:43:52.000000000","message":"LB?","commit_id":"626395766934da51329c8b9ac7704cba9af2fca9"},{"author":{"_account_id":11600,"name":"Michał Dulko","email":"michal.dulko@gmail.com","username":"dulek"},"change_message_id":"fbaf8769d8b6289a01613ba8c6004a1af9fb2d80","unresolved":false,"context_lines":[{"line_number":227,"context_line":"               default\u003d\u0027update\u0027),"},{"line_number":228,"context_line":"    cfg.BoolOpt(\u0027enforce_sg_rules\u0027,"},{"line_number":229,"context_line":"                help\u003d_(\"Enable the enforcement of SG rules at the lbaas SG \""},{"line_number":230,"context_line":"                       \"in case the lbaas does not maintains the source IP \""},{"line_number":231,"context_line":"                       \"of the caller resource\"),"},{"line_number":232,"context_line":"                default\u003dTrue),"},{"line_number":233,"context_line":"]"}],"source_content_type":"text/x-python","patch_set":7,"id":"9fb8cfa7_6e10545a","line":230,"range":{"start_line":230,"start_character":51,"end_line":230,"end_character":60},"updated":"2019-06-27 09:43:52.000000000","message":"maintain?","commit_id":"626395766934da51329c8b9ac7704cba9af2fca9"}],"kuryr_kubernetes/controller/drivers/lbaasv2.py":[{"author":{"_account_id":23567,"name":"Luis Tomas Bolivar","email":"ltomasbo@redhat.com","username":"ltomasbo"},"change_message_id":"254a40fb09f04704c1cf0e1192bae0ee61331849","unresolved":false,"context_lines":[{"line_number":397,"context_line":"            CONF.kubernetes.service_security_groups_driver \u003d\u003d \u0027namespace\u0027)"},{"line_number":398,"context_line":"        create_sg \u003d CONF.octavia_defaults.sg_mode \u003d\u003d \u0027create\u0027"},{"line_number":399,"context_line":""},{"line_number":400,"context_line":"        if namespace_isolation and service_type \u003d\u003d \u0027ClusterIP\u0027:"},{"line_number":401,"context_line":"            self._extend_lb_security_group_rules(loadbalancer, listener)"},{"line_number":402,"context_line":"        elif create_sg:"},{"line_number":403,"context_line":"            self._create_lb_security_group_rule(loadbalancer, listener)"},{"line_number":404,"context_line":""},{"line_number":405,"context_line":"    def ensure_listener(self, loadbalancer, protocol, port,"},{"line_number":406,"context_line":"                        service_type\u003d\u0027ClusterIP\u0027):"}],"source_content_type":"text/x-python","patch_set":6,"id":"9fb8cfa7_92508c60","line":403,"range":{"start_line":400,"start_character":0,"end_line":403,"end_character":71},"updated":"2019-06-24 08:41:13.000000000","message":"perhaps this needs to be reshuffle. We always need to create the SG for the loadbalancer if create mode is active. Otherwise, e.g., if ovn-octavia driver is used, the default SG will be modified with the listener rules. So perhaps worth to split these two into:\nif create_sg:\n   ....\nif namespace_isolation and servi...\n   ....\n\nAnd we probably need to only skip the second if enforce_sg_rules is not activated","commit_id":"7cc02fb48f637d667d9eb416066126e325cc3329"}]}
