)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"db3982e0544ecb0ff59499c217feeb422c00ddef","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"cb1c6325_bb9eb8ce","updated":"2022-03-22 14:53:48.000000000","message":"Thanks for the proposal!","commit_id":"0f51c0a6a03dd77378c5cf1e274befd86c98750a"},{"author":{"_account_id":11600,"name":"Michał Dulko","email":"michal.dulko@gmail.com","username":"dulek"},"change_message_id":"44ed24cb8b175a89adce869a46973126d84bec12","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"dad51cc8_f22cbc1d","updated":"2022-04-05 10:46:51.000000000","message":"Ah, also any considerations on testing? I guess we\u0027d need a new CI gate with these drivers configured and some minimal tempest test to be able to test the functionality.","commit_id":"3e4d10befede8bfbfef7cdf07deafa788443cb82"},{"author":{"_account_id":11600,"name":"Michał Dulko","email":"michal.dulko@gmail.com","username":"dulek"},"change_message_id":"b8434f7271baf72b312033f7df81a51854c3f941","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"1777fe8b_74117ba5","updated":"2022-04-05 10:45:09.000000000","message":"We\u0027ve discussed this on the PTG and the comments come from there. They\u0027re pretty minor though.","commit_id":"3e4d10befede8bfbfef7cdf07deafa788443cb82"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"040396741348e94ece9e2052ef05e6151fe35b29","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"ca37d82a_ae3609d8","in_reply_to":"dad51cc8_f22cbc1d","updated":"2022-04-06 10:56:12.000000000","message":"Well, I haven\u0027t consider test for this. I will try to design a new CI gate for this asap.","commit_id":"3e4d10befede8bfbfef7cdf07deafa788443cb82"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"7d3cce8ea2ba11d9463c10f387074721ed6c55a7","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"0244249c_fc797167","updated":"2022-05-03 14:57:11.000000000","message":"LGTM, there are just some minor rewording that would be nice:","commit_id":"2e452594270a1b7f312690cc8d361edeb5432161"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"2a2706557d0cd61fc48609c1dd8a36c28e34cb28","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"cefdccfa_fe8ddfeb","in_reply_to":"0244249c_fc797167","updated":"2022-05-04 03:53:13.000000000","message":"Thanks very much.","commit_id":"2e452594270a1b7f312690cc8d361edeb5432161"}],"doc/source/devref/annotation_project_driver.rst":[{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"db3982e0544ecb0ff59499c217feeb422c00ddef","unresolved":true,"context_lines":[{"line_number":23,"context_line":""},{"line_number":24,"context_line":"Now, ``kuryr-kubernetes`` just implement a default project driver, the project"},{"line_number":25,"context_line":"id of openstack resource which used to support k8s resource was specified by"},{"line_number":26,"context_line":"configuretion option ``neutron_defaults.project``. This means all of these"},{"line_number":27,"context_line":"openstack resources have a same project id. This will result in some puzzling"},{"line_number":28,"context_line":"issues in multiple tenant environment. Such as, the metering and billing system"},{"line_number":29,"context_line":"can not classify these resoruces and the resources will exceed the tenant\u0027s"}],"source_content_type":"text/x-rst","patch_set":1,"id":"a39e830c_0c32694f","line":26,"range":{"start_line":26,"start_character":0,"end_line":26,"end_character":13},"updated":"2022-03-22 14:53:48.000000000","message":"typo: configuration","commit_id":"0f51c0a6a03dd77378c5cf1e274befd86c98750a"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"12c5198cb60a6492552e5236317087a2d37bb580","unresolved":false,"context_lines":[{"line_number":23,"context_line":""},{"line_number":24,"context_line":"Now, ``kuryr-kubernetes`` just implement a default project driver, the project"},{"line_number":25,"context_line":"id of openstack resource which used to support k8s resource was specified by"},{"line_number":26,"context_line":"configuretion option ``neutron_defaults.project``. This means all of these"},{"line_number":27,"context_line":"openstack resources have a same project id. This will result in some puzzling"},{"line_number":28,"context_line":"issues in multiple tenant environment. Such as, the metering and billing system"},{"line_number":29,"context_line":"can not classify these resoruces and the resources will exceed the tenant\u0027s"}],"source_content_type":"text/x-rst","patch_set":1,"id":"32e9e6b3_a7a4e83d","line":26,"range":{"start_line":26,"start_character":0,"end_line":26,"end_character":13},"in_reply_to":"a39e830c_0c32694f","updated":"2022-03-23 03:14:25.000000000","message":"Done","commit_id":"0f51c0a6a03dd77378c5cf1e274befd86c98750a"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"db3982e0544ecb0ff59499c217feeb422c00ddef","unresolved":true,"context_lines":[{"line_number":24,"context_line":"Now, ``kuryr-kubernetes`` just implement a default project driver, the project"},{"line_number":25,"context_line":"id of openstack resource which used to support k8s resource was specified by"},{"line_number":26,"context_line":"configuretion option ``neutron_defaults.project``. This means all of these"},{"line_number":27,"context_line":"openstack resources have a same project id. This will result in some puzzling"},{"line_number":28,"context_line":"issues in multiple tenant environment. Such as, the metering and billing system"},{"line_number":29,"context_line":"can not classify these resoruces and the resources will exceed the tenant\u0027s"},{"line_number":30,"context_line":"quota. In order to resolve this issues, we need ensure these resources have"}],"source_content_type":"text/x-rst","patch_set":1,"id":"ac49652b_41aebb6a","line":27,"range":{"start_line":27,"start_character":25,"end_line":27,"end_character":26},"updated":"2022-03-22 14:53:48.000000000","message":"typo: the","commit_id":"0f51c0a6a03dd77378c5cf1e274befd86c98750a"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"12c5198cb60a6492552e5236317087a2d37bb580","unresolved":false,"context_lines":[{"line_number":24,"context_line":"Now, ``kuryr-kubernetes`` just implement a default project driver, the project"},{"line_number":25,"context_line":"id of openstack resource which used to support k8s resource was specified by"},{"line_number":26,"context_line":"configuretion option ``neutron_defaults.project``. This means all of these"},{"line_number":27,"context_line":"openstack resources have a same project id. This will result in some puzzling"},{"line_number":28,"context_line":"issues in multiple tenant environment. Such as, the metering and billing system"},{"line_number":29,"context_line":"can not classify these resoruces and the resources will exceed the tenant\u0027s"},{"line_number":30,"context_line":"quota. In order to resolve this issues, we need ensure these resources have"}],"source_content_type":"text/x-rst","patch_set":1,"id":"ed169a46_b347d3f8","line":27,"range":{"start_line":27,"start_character":25,"end_line":27,"end_character":26},"in_reply_to":"ac49652b_41aebb6a","updated":"2022-03-23 03:14:25.000000000","message":"Done","commit_id":"0f51c0a6a03dd77378c5cf1e274befd86c98750a"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"db3982e0544ecb0ff59499c217feeb422c00ddef","unresolved":true,"context_lines":[{"line_number":26,"context_line":"configuretion option ``neutron_defaults.project``. This means all of these"},{"line_number":27,"context_line":"openstack resources have a same project id. This will result in some puzzling"},{"line_number":28,"context_line":"issues in multiple tenant environment. Such as, the metering and billing system"},{"line_number":29,"context_line":"can not classify these resoruces and the resources will exceed the tenant\u0027s"},{"line_number":30,"context_line":"quota. In order to resolve this issues, we need ensure these resources have"},{"line_number":31,"context_line":"different project id."},{"line_number":32,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"89b0dd0c_f0405ef2","line":29,"range":{"start_line":29,"start_character":23,"end_line":29,"end_character":32},"updated":"2022-03-22 14:53:48.000000000","message":"typo","commit_id":"0f51c0a6a03dd77378c5cf1e274befd86c98750a"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"12c5198cb60a6492552e5236317087a2d37bb580","unresolved":false,"context_lines":[{"line_number":26,"context_line":"configuretion option ``neutron_defaults.project``. This means all of these"},{"line_number":27,"context_line":"openstack resources have a same project id. This will result in some puzzling"},{"line_number":28,"context_line":"issues in multiple tenant environment. Such as, the metering and billing system"},{"line_number":29,"context_line":"can not classify these resoruces and the resources will exceed the tenant\u0027s"},{"line_number":30,"context_line":"quota. In order to resolve this issues, we need ensure these resources have"},{"line_number":31,"context_line":"different project id."},{"line_number":32,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"2b69abc4_570574b5","line":29,"range":{"start_line":29,"start_character":23,"end_line":29,"end_character":32},"in_reply_to":"89b0dd0c_f0405ef2","updated":"2022-03-23 03:14:25.000000000","message":"Done","commit_id":"0f51c0a6a03dd77378c5cf1e274befd86c98750a"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"db3982e0544ecb0ff59499c217feeb422c00ddef","unresolved":true,"context_lines":[{"line_number":27,"context_line":"openstack resources have a same project id. This will result in some puzzling"},{"line_number":28,"context_line":"issues in multiple tenant environment. Such as, the metering and billing system"},{"line_number":29,"context_line":"can not classify these resoruces and the resources will exceed the tenant\u0027s"},{"line_number":30,"context_line":"quota. In order to resolve this issues, we need ensure these resources have"},{"line_number":31,"context_line":"different project id."},{"line_number":32,"context_line":""},{"line_number":33,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"f9938e2e_15bd7ec9","line":30,"range":{"start_line":30,"start_character":27,"end_line":30,"end_character":31},"updated":"2022-03-22 14:53:48.000000000","message":"these","commit_id":"0f51c0a6a03dd77378c5cf1e274befd86c98750a"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"12c5198cb60a6492552e5236317087a2d37bb580","unresolved":false,"context_lines":[{"line_number":27,"context_line":"openstack resources have a same project id. This will result in some puzzling"},{"line_number":28,"context_line":"issues in multiple tenant environment. Such as, the metering and billing system"},{"line_number":29,"context_line":"can not classify these resoruces and the resources will exceed the tenant\u0027s"},{"line_number":30,"context_line":"quota. In order to resolve this issues, we need ensure these resources have"},{"line_number":31,"context_line":"different project id."},{"line_number":32,"context_line":""},{"line_number":33,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"7d45bf76_b0a88b20","line":30,"range":{"start_line":30,"start_character":27,"end_line":30,"end_character":31},"in_reply_to":"f9938e2e_15bd7ec9","updated":"2022-03-23 03:14:25.000000000","message":"Done","commit_id":"0f51c0a6a03dd77378c5cf1e274befd86c98750a"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"db3982e0544ecb0ff59499c217feeb422c00ddef","unresolved":true,"context_lines":[{"line_number":34,"context_line":"Overview"},{"line_number":35,"context_line":"--------"},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"Implement a annotation project driver for ``namespace``, ``pod`. ``service``"},{"line_number":38,"context_line":"and ``network policy``. The driver can read project id from the annotations of "},{"line_number":39,"context_line":"this resources\u0027 namespace."},{"line_number":40,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"2e9ff5cd_7011359d","line":37,"range":{"start_line":37,"start_character":10,"end_line":37,"end_character":11},"updated":"2022-03-22 14:53:48.000000000","message":"an","commit_id":"0f51c0a6a03dd77378c5cf1e274befd86c98750a"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"12c5198cb60a6492552e5236317087a2d37bb580","unresolved":false,"context_lines":[{"line_number":34,"context_line":"Overview"},{"line_number":35,"context_line":"--------"},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"Implement a annotation project driver for ``namespace``, ``pod`. ``service``"},{"line_number":38,"context_line":"and ``network policy``. The driver can read project id from the annotations of "},{"line_number":39,"context_line":"this resources\u0027 namespace."},{"line_number":40,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"5ba52bc9_b723b195","line":37,"range":{"start_line":37,"start_character":10,"end_line":37,"end_character":11},"in_reply_to":"2e9ff5cd_7011359d","updated":"2022-03-23 03:14:25.000000000","message":"Done","commit_id":"0f51c0a6a03dd77378c5cf1e274befd86c98750a"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"db3982e0544ecb0ff59499c217feeb422c00ddef","unresolved":true,"context_lines":[{"line_number":35,"context_line":"--------"},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"Implement a annotation project driver for ``namespace``, ``pod`. ``service``"},{"line_number":38,"context_line":"and ``network policy``. The driver can read project id from the annotations of "},{"line_number":39,"context_line":"this resources\u0027 namespace."},{"line_number":40,"context_line":""},{"line_number":41,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"9dd1f035_b44c1432","line":38,"range":{"start_line":38,"start_character":78,"end_line":38,"end_character":79},"updated":"2022-03-22 14:53:48.000000000","message":"please remove the whitespace","commit_id":"0f51c0a6a03dd77378c5cf1e274befd86c98750a"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"12c5198cb60a6492552e5236317087a2d37bb580","unresolved":false,"context_lines":[{"line_number":35,"context_line":"--------"},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"Implement a annotation project driver for ``namespace``, ``pod`. ``service``"},{"line_number":38,"context_line":"and ``network policy``. The driver can read project id from the annotations of "},{"line_number":39,"context_line":"this resources\u0027 namespace."},{"line_number":40,"context_line":""},{"line_number":41,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"d35bc3c3_361fb0af","line":38,"range":{"start_line":38,"start_character":78,"end_line":38,"end_character":79},"in_reply_to":"9dd1f035_b44c1432","updated":"2022-03-23 03:14:25.000000000","message":"Done","commit_id":"0f51c0a6a03dd77378c5cf1e274befd86c98750a"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"db3982e0544ecb0ff59499c217feeb422c00ddef","unresolved":true,"context_lines":[{"line_number":40,"context_line":""},{"line_number":41,"context_line":""},{"line_number":42,"context_line":"Proposed Solution"},{"line_number":43,"context_line":"-----------------"},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"Introduce an annotation ``openstack.org/kuryr-project``, the annotation should"},{"line_number":46,"context_line":"be set when a k8s namespace was created. The annotation\u0027s value is a openstack"}],"source_content_type":"text/x-rst","patch_set":1,"id":"c5dca901_b9555ef5","line":43,"updated":"2022-03-22 14:53:48.000000000","message":"Can you detail how the openstack authentication would look like?\nI would be interested in knowing the tenant and projects relation","commit_id":"0f51c0a6a03dd77378c5cf1e274befd86c98750a"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"12c5198cb60a6492552e5236317087a2d37bb580","unresolved":false,"context_lines":[{"line_number":40,"context_line":""},{"line_number":41,"context_line":""},{"line_number":42,"context_line":"Proposed Solution"},{"line_number":43,"context_line":"-----------------"},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"Introduce an annotation ``openstack.org/kuryr-project``, the annotation should"},{"line_number":46,"context_line":"be set when a k8s namespace was created. The annotation\u0027s value is a openstack"}],"source_content_type":"text/x-rst","patch_set":1,"id":"9c6d86a7_c6597215","line":43,"in_reply_to":"c5dca901_b9555ef5","updated":"2022-03-23 03:14:25.000000000","message":"Done","commit_id":"0f51c0a6a03dd77378c5cf1e274befd86c98750a"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"db3982e0544ecb0ff59499c217feeb422c00ddef","unresolved":true,"context_lines":[{"line_number":48,"context_line":"openstack project, one openstack project can assocate multiple k8s namespace."},{"line_number":49,"context_line":""},{"line_number":50,"context_line":"When user create a ``pod``, ``service`` or ``network policy``, the new project"},{"line_number":51,"context_line":"driver will retrieve these resrouces\u0027s namespace and get the namespace\u0027s"},{"line_number":52,"context_line":"information, then the driver will try to get project id from annotaion"},{"line_number":53,"context_line":"``openstack.org/kuryr-project``. If the driver succeed get project id, the"},{"line_number":54,"context_line":"project id will return to these resource\u0027s handlers, then these handlers will"}],"source_content_type":"text/x-rst","patch_set":1,"id":"3b4f4321_4213a064","line":51,"range":{"start_line":51,"start_character":27,"end_line":51,"end_character":36},"updated":"2022-03-22 14:53:48.000000000","message":"typo","commit_id":"0f51c0a6a03dd77378c5cf1e274befd86c98750a"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"12c5198cb60a6492552e5236317087a2d37bb580","unresolved":false,"context_lines":[{"line_number":48,"context_line":"openstack project, one openstack project can assocate multiple k8s namespace."},{"line_number":49,"context_line":""},{"line_number":50,"context_line":"When user create a ``pod``, ``service`` or ``network policy``, the new project"},{"line_number":51,"context_line":"driver will retrieve these resrouces\u0027s namespace and get the namespace\u0027s"},{"line_number":52,"context_line":"information, then the driver will try to get project id from annotaion"},{"line_number":53,"context_line":"``openstack.org/kuryr-project``. If the driver succeed get project id, the"},{"line_number":54,"context_line":"project id will return to these resource\u0027s handlers, then these handlers will"}],"source_content_type":"text/x-rst","patch_set":1,"id":"4c0ae97d_3e39503d","line":51,"range":{"start_line":51,"start_character":27,"end_line":51,"end_character":36},"in_reply_to":"3b4f4321_4213a064","updated":"2022-03-23 03:14:25.000000000","message":"Done","commit_id":"0f51c0a6a03dd77378c5cf1e274befd86c98750a"},{"author":{"_account_id":11600,"name":"Michał Dulko","email":"michal.dulko@gmail.com","username":"dulek"},"change_message_id":"b8434f7271baf72b312033f7df81a51854c3f941","unresolved":true,"context_lines":[{"line_number":47,"context_line":"``neutron`` and ``octavia``. ``Neutron`` and ``octavia`` use openstack project"},{"line_number":48,"context_line":"id to isolate their resources, so we can treat a openstack project as a"},{"line_number":49,"context_line":"metering or billing tenant. Generally, ``kuryr-kubernetes`` use ``kuryr`` user"},{"line_number":50,"context_line":"to create/delete/update/read ``neutron`` or ``octavia`` resources. The"},{"line_number":51,"context_line":"``kuryr`` user has admin role, so ``kuryr-kubernetes`` can manage any project\u0027s"},{"line_number":52,"context_line":"resources."},{"line_number":53,"context_line":""},{"line_number":54,"context_line":"So, I propose that we introduce an annotation ``openstack.org/kuryr-project``,"}],"source_content_type":"text/x-rst","patch_set":3,"id":"3d396a67_aea16922","line":51,"range":{"start_line":50,"start_character":67,"end_line":51,"end_character":29},"updated":"2022-04-05 10:45:09.000000000","message":"Does Kuryr user need to be an admin? Couldn\u0027t it simply have access to all the necessary projects?","commit_id":"3e4d10befede8bfbfef7cdf07deafa788443cb82"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"040396741348e94ece9e2052ef05e6151fe35b29","unresolved":true,"context_lines":[{"line_number":47,"context_line":"``neutron`` and ``octavia``. ``Neutron`` and ``octavia`` use openstack project"},{"line_number":48,"context_line":"id to isolate their resources, so we can treat a openstack project as a"},{"line_number":49,"context_line":"metering or billing tenant. Generally, ``kuryr-kubernetes`` use ``kuryr`` user"},{"line_number":50,"context_line":"to create/delete/update/read ``neutron`` or ``octavia`` resources. The"},{"line_number":51,"context_line":"``kuryr`` user has admin role, so ``kuryr-kubernetes`` can manage any project\u0027s"},{"line_number":52,"context_line":"resources."},{"line_number":53,"context_line":""},{"line_number":54,"context_line":"So, I propose that we introduce an annotation ``openstack.org/kuryr-project``,"}],"source_content_type":"text/x-rst","patch_set":3,"id":"b89b6867_1c1d92a6","line":51,"range":{"start_line":50,"start_character":67,"end_line":51,"end_character":29},"in_reply_to":"3d396a67_aea16922","updated":"2022-04-06 10:56:12.000000000","message":"You mean that the kuryr just only has reader role? I haven\u0027t try this. I will test it asap.","commit_id":"3e4d10befede8bfbfef7cdf07deafa788443cb82"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"4037cfad979000b141687c33f08f5abc6e883f5c","unresolved":true,"context_lines":[{"line_number":47,"context_line":"``neutron`` and ``octavia``. ``Neutron`` and ``octavia`` use openstack project"},{"line_number":48,"context_line":"id to isolate their resources, so we can treat a openstack project as a"},{"line_number":49,"context_line":"metering or billing tenant. Generally, ``kuryr-kubernetes`` use ``kuryr`` user"},{"line_number":50,"context_line":"to create/delete/update/read ``neutron`` or ``octavia`` resources. The"},{"line_number":51,"context_line":"``kuryr`` user has admin role, so ``kuryr-kubernetes`` can manage any project\u0027s"},{"line_number":52,"context_line":"resources."},{"line_number":53,"context_line":""},{"line_number":54,"context_line":"So, I propose that we introduce an annotation ``openstack.org/kuryr-project``,"}],"source_content_type":"text/x-rst","patch_set":3,"id":"4fe4be5a_da502c12","line":51,"range":{"start_line":50,"start_character":67,"end_line":51,"end_character":29},"in_reply_to":"b89b6867_1c1d92a6","updated":"2022-04-15 07:54:52.000000000","message":"Hi Michal, Kuryr user must is an admin, the kuryr user need to create/update/delete related openstack resources which within other project.","commit_id":"3e4d10befede8bfbfef7cdf07deafa788443cb82"},{"author":{"_account_id":11600,"name":"Michał Dulko","email":"michal.dulko@gmail.com","username":"dulek"},"change_message_id":"b8434f7271baf72b312033f7df81a51854c3f941","unresolved":true,"context_lines":[{"line_number":68,"context_line":"When user create a ``pod``, ``service`` or ``network policy``, the new project"},{"line_number":69,"context_line":"driver will retrieve these resources\u0027s namespace and get the namespace\u0027s"},{"line_number":70,"context_line":"information, then the driver will try to get project id from annotaion"},{"line_number":71,"context_line":"``openstack.org/kuryr-project``. If the driver succeed get project id, the"},{"line_number":72,"context_line":"project id will return to these resource\u0027s handlers, then these handlers will"},{"line_number":73,"context_line":"create related openstack resource with the project id."},{"line_number":74,"context_line":""},{"line_number":75,"context_line":"For namespace, then namespace handler can get namespace information form the"},{"line_number":76,"context_line":"``on_present`` function\u0027s parameter. So, the namespace annotaion project driver"}],"source_content_type":"text/x-rst","patch_set":3,"id":"0d9b2021_3102332e","line":73,"range":{"start_line":71,"start_character":33,"end_line":73,"end_character":54},"updated":"2022-04-05 10:45:09.000000000","message":"Just one note - this is only solving the billing/resource ownership issues. No isolation in terms of networking will be achieved that way.","commit_id":"3e4d10befede8bfbfef7cdf07deafa788443cb82"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"040396741348e94ece9e2052ef05e6151fe35b29","unresolved":true,"context_lines":[{"line_number":68,"context_line":"When user create a ``pod``, ``service`` or ``network policy``, the new project"},{"line_number":69,"context_line":"driver will retrieve these resources\u0027s namespace and get the namespace\u0027s"},{"line_number":70,"context_line":"information, then the driver will try to get project id from annotaion"},{"line_number":71,"context_line":"``openstack.org/kuryr-project``. If the driver succeed get project id, the"},{"line_number":72,"context_line":"project id will return to these resource\u0027s handlers, then these handlers will"},{"line_number":73,"context_line":"create related openstack resource with the project id."},{"line_number":74,"context_line":""},{"line_number":75,"context_line":"For namespace, then namespace handler can get namespace information form the"},{"line_number":76,"context_line":"``on_present`` function\u0027s parameter. So, the namespace annotaion project driver"}],"source_content_type":"text/x-rst","patch_set":3,"id":"6d46579d_440729f4","line":73,"range":{"start_line":71,"start_character":33,"end_line":73,"end_character":54},"in_reply_to":"0d9b2021_3102332e","updated":"2022-04-06 10:56:12.000000000","message":"Yep, The networking isolation need more works. I will add some notes in next patch to avoid potential misunderstand.","commit_id":"3e4d10befede8bfbfef7cdf07deafa788443cb82"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"4037cfad979000b141687c33f08f5abc6e883f5c","unresolved":false,"context_lines":[{"line_number":68,"context_line":"When user create a ``pod``, ``service`` or ``network policy``, the new project"},{"line_number":69,"context_line":"driver will retrieve these resources\u0027s namespace and get the namespace\u0027s"},{"line_number":70,"context_line":"information, then the driver will try to get project id from annotaion"},{"line_number":71,"context_line":"``openstack.org/kuryr-project``. If the driver succeed get project id, the"},{"line_number":72,"context_line":"project id will return to these resource\u0027s handlers, then these handlers will"},{"line_number":73,"context_line":"create related openstack resource with the project id."},{"line_number":74,"context_line":""},{"line_number":75,"context_line":"For namespace, then namespace handler can get namespace information form the"},{"line_number":76,"context_line":"``on_present`` function\u0027s parameter. So, the namespace annotaion project driver"}],"source_content_type":"text/x-rst","patch_set":3,"id":"7b79eb42_d0ccd31f","line":73,"range":{"start_line":71,"start_character":33,"end_line":73,"end_character":54},"in_reply_to":"6d46579d_440729f4","updated":"2022-04-15 07:54:52.000000000","message":"Done","commit_id":"3e4d10befede8bfbfef7cdf07deafa788443cb82"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"7d3cce8ea2ba11d9463c10f387074721ed6c55a7","unresolved":true,"context_lines":[{"line_number":27,"context_line":"openstack resources have the same project id. This will result in some puzzling"},{"line_number":28,"context_line":"issues in multiple tenant environment. Such as, the metering and billing system"},{"line_number":29,"context_line":"can not classify these resources and the resources will exceed the tenant\u0027s"},{"line_number":30,"context_line":"quota. In order to resolve these issues, we need ensure these resources have"},{"line_number":31,"context_line":"different project id (For the sake of simplicity, we can treat a project as a"},{"line_number":32,"context_line":"tenant)."},{"line_number":33,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"1c58707c_c0193918","line":30,"range":{"start_line":30,"start_character":44,"end_line":30,"end_character":55},"updated":"2022-05-03 14:57:11.000000000","message":"need to ensure","commit_id":"2e452594270a1b7f312690cc8d361edeb5432161"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"2a2706557d0cd61fc48609c1dd8a36c28e34cb28","unresolved":false,"context_lines":[{"line_number":27,"context_line":"openstack resources have the same project id. This will result in some puzzling"},{"line_number":28,"context_line":"issues in multiple tenant environment. Such as, the metering and billing system"},{"line_number":29,"context_line":"can not classify these resources and the resources will exceed the tenant\u0027s"},{"line_number":30,"context_line":"quota. In order to resolve these issues, we need ensure these resources have"},{"line_number":31,"context_line":"different project id (For the sake of simplicity, we can treat a project as a"},{"line_number":32,"context_line":"tenant)."},{"line_number":33,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"16bda1f8_7188105e","line":30,"range":{"start_line":30,"start_character":44,"end_line":30,"end_character":55},"in_reply_to":"1c58707c_c0193918","updated":"2022-05-04 03:53:13.000000000","message":"Done","commit_id":"2e452594270a1b7f312690cc8d361edeb5432161"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"7d3cce8ea2ba11d9463c10f387074721ed6c55a7","unresolved":true,"context_lines":[{"line_number":43,"context_line":"Proposed Solution"},{"line_number":44,"context_line":"-----------------"},{"line_number":45,"context_line":""},{"line_number":46,"context_line":"Now, the openstack resources that created by ``kuryr-kubernetes`` only involved"},{"line_number":47,"context_line":"``neutron`` and ``octavia``. ``Neutron`` and ``octavia`` use openstack project"},{"line_number":48,"context_line":"id to isolate their resources, so we can treat a openstack project as a"},{"line_number":49,"context_line":"metering or billing tenant. Generally, ``kuryr-kubernetes`` use ``kuryr`` user"}],"source_content_type":"text/x-rst","patch_set":4,"id":"d7b7d718_4225fde8","line":46,"range":{"start_line":46,"start_character":71,"end_line":46,"end_character":79},"updated":"2022-05-03 14:57:11.000000000","message":"involves","commit_id":"2e452594270a1b7f312690cc8d361edeb5432161"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"7d3cce8ea2ba11d9463c10f387074721ed6c55a7","unresolved":true,"context_lines":[{"line_number":43,"context_line":"Proposed Solution"},{"line_number":44,"context_line":"-----------------"},{"line_number":45,"context_line":""},{"line_number":46,"context_line":"Now, the openstack resources that created by ``kuryr-kubernetes`` only involved"},{"line_number":47,"context_line":"``neutron`` and ``octavia``. ``Neutron`` and ``octavia`` use openstack project"},{"line_number":48,"context_line":"id to isolate their resources, so we can treat a openstack project as a"},{"line_number":49,"context_line":"metering or billing tenant. Generally, ``kuryr-kubernetes`` use ``kuryr`` user"}],"source_content_type":"text/x-rst","patch_set":4,"id":"bf3e52d1_4ed4930b","line":46,"range":{"start_line":46,"start_character":32,"end_line":46,"end_character":41},"updated":"2022-05-03 14:57:11.000000000","message":"that are created","commit_id":"2e452594270a1b7f312690cc8d361edeb5432161"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"2a2706557d0cd61fc48609c1dd8a36c28e34cb28","unresolved":false,"context_lines":[{"line_number":43,"context_line":"Proposed Solution"},{"line_number":44,"context_line":"-----------------"},{"line_number":45,"context_line":""},{"line_number":46,"context_line":"Now, the openstack resources that created by ``kuryr-kubernetes`` only involved"},{"line_number":47,"context_line":"``neutron`` and ``octavia``. ``Neutron`` and ``octavia`` use openstack project"},{"line_number":48,"context_line":"id to isolate their resources, so we can treat a openstack project as a"},{"line_number":49,"context_line":"metering or billing tenant. Generally, ``kuryr-kubernetes`` use ``kuryr`` user"}],"source_content_type":"text/x-rst","patch_set":4,"id":"b71c1850_3fa30c5a","line":46,"range":{"start_line":46,"start_character":32,"end_line":46,"end_character":41},"in_reply_to":"bf3e52d1_4ed4930b","updated":"2022-05-04 03:53:13.000000000","message":"Done","commit_id":"2e452594270a1b7f312690cc8d361edeb5432161"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"2a2706557d0cd61fc48609c1dd8a36c28e34cb28","unresolved":false,"context_lines":[{"line_number":43,"context_line":"Proposed Solution"},{"line_number":44,"context_line":"-----------------"},{"line_number":45,"context_line":""},{"line_number":46,"context_line":"Now, the openstack resources that created by ``kuryr-kubernetes`` only involved"},{"line_number":47,"context_line":"``neutron`` and ``octavia``. ``Neutron`` and ``octavia`` use openstack project"},{"line_number":48,"context_line":"id to isolate their resources, so we can treat a openstack project as a"},{"line_number":49,"context_line":"metering or billing tenant. Generally, ``kuryr-kubernetes`` use ``kuryr`` user"}],"source_content_type":"text/x-rst","patch_set":4,"id":"117fa6cc_aac388ac","line":46,"range":{"start_line":46,"start_character":71,"end_line":46,"end_character":79},"in_reply_to":"d7b7d718_4225fde8","updated":"2022-05-04 03:53:13.000000000","message":"Done","commit_id":"2e452594270a1b7f312690cc8d361edeb5432161"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"7d3cce8ea2ba11d9463c10f387074721ed6c55a7","unresolved":true,"context_lines":[{"line_number":54,"context_line":"So, I propose that we introduce an annotation ``openstack.org/kuryr-project``,"},{"line_number":55,"context_line":"the annotation should be set when a k8s namespace was created. The annotation\u0027s"},{"line_number":56,"context_line":"value is a openstack project\u0027s id. One k8s namespace can only specify one"},{"line_number":57,"context_line":"openstack project, but for openstack project, one openstack project can"},{"line_number":58,"context_line":"assocate with one or multiple k8s namespace."},{"line_number":59,"context_line":""},{"line_number":60,"context_line":".. note::"}],"source_content_type":"text/x-rst","patch_set":4,"id":"679e1b24_b2521f43","line":57,"range":{"start_line":57,"start_character":23,"end_line":57,"end_character":45},"updated":"2022-05-03 14:57:11.000000000","message":"this could be removed","commit_id":"2e452594270a1b7f312690cc8d361edeb5432161"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"2a2706557d0cd61fc48609c1dd8a36c28e34cb28","unresolved":false,"context_lines":[{"line_number":54,"context_line":"So, I propose that we introduce an annotation ``openstack.org/kuryr-project``,"},{"line_number":55,"context_line":"the annotation should be set when a k8s namespace was created. The annotation\u0027s"},{"line_number":56,"context_line":"value is a openstack project\u0027s id. One k8s namespace can only specify one"},{"line_number":57,"context_line":"openstack project, but for openstack project, one openstack project can"},{"line_number":58,"context_line":"assocate with one or multiple k8s namespace."},{"line_number":59,"context_line":""},{"line_number":60,"context_line":".. note::"}],"source_content_type":"text/x-rst","patch_set":4,"id":"261da6bd_b799b59d","line":57,"range":{"start_line":57,"start_character":23,"end_line":57,"end_character":45},"in_reply_to":"679e1b24_b2521f43","updated":"2022-05-04 03:53:13.000000000","message":"Done","commit_id":"2e452594270a1b7f312690cc8d361edeb5432161"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"7d3cce8ea2ba11d9463c10f387074721ed6c55a7","unresolved":true,"context_lines":[{"line_number":55,"context_line":"the annotation should be set when a k8s namespace was created. The annotation\u0027s"},{"line_number":56,"context_line":"value is a openstack project\u0027s id. One k8s namespace can only specify one"},{"line_number":57,"context_line":"openstack project, but for openstack project, one openstack project can"},{"line_number":58,"context_line":"assocate with one or multiple k8s namespace."},{"line_number":59,"context_line":""},{"line_number":60,"context_line":".. note::"},{"line_number":61,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"348e20f4_81c5a22c","line":58,"range":{"start_line":58,"start_character":0,"end_line":58,"end_character":8},"updated":"2022-05-03 14:57:11.000000000","message":"be associated","commit_id":"2e452594270a1b7f312690cc8d361edeb5432161"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"2a2706557d0cd61fc48609c1dd8a36c28e34cb28","unresolved":false,"context_lines":[{"line_number":55,"context_line":"the annotation should be set when a k8s namespace was created. The annotation\u0027s"},{"line_number":56,"context_line":"value is a openstack project\u0027s id. One k8s namespace can only specify one"},{"line_number":57,"context_line":"openstack project, but for openstack project, one openstack project can"},{"line_number":58,"context_line":"assocate with one or multiple k8s namespace."},{"line_number":59,"context_line":""},{"line_number":60,"context_line":".. note::"},{"line_number":61,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"9459733d_a8138c32","line":58,"range":{"start_line":58,"start_character":0,"end_line":58,"end_character":8},"in_reply_to":"348e20f4_81c5a22c","updated":"2022-05-04 03:53:13.000000000","message":"Done","commit_id":"2e452594270a1b7f312690cc8d361edeb5432161"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"7d3cce8ea2ba11d9463c10f387074721ed6c55a7","unresolved":true,"context_lines":[{"line_number":77,"context_line":"    This is only solving the resource ownership issues. No isolation in terms"},{"line_number":78,"context_line":"    of networking will be achieved this way."},{"line_number":79,"context_line":""},{"line_number":80,"context_line":"For namespace, then namespace handler can get namespace information form the"},{"line_number":81,"context_line":"``on_present`` function\u0027s parameter. So, the namespace annotaion project driver"},{"line_number":82,"context_line":"can try get project id from the information directly."},{"line_number":83,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"ebb6d300_80f0d528","line":80,"range":{"start_line":80,"start_character":68,"end_line":80,"end_character":72},"updated":"2022-05-03 14:57:11.000000000","message":"from","commit_id":"2e452594270a1b7f312690cc8d361edeb5432161"},{"author":{"_account_id":28329,"name":"yangjianfeng","display_name":"JeffYang","email":"yjf1970231893@gmail.com","username":"yangjianfeng"},"change_message_id":"2a2706557d0cd61fc48609c1dd8a36c28e34cb28","unresolved":false,"context_lines":[{"line_number":77,"context_line":"    This is only solving the resource ownership issues. No isolation in terms"},{"line_number":78,"context_line":"    of networking will be achieved this way."},{"line_number":79,"context_line":""},{"line_number":80,"context_line":"For namespace, then namespace handler can get namespace information form the"},{"line_number":81,"context_line":"``on_present`` function\u0027s parameter. So, the namespace annotaion project driver"},{"line_number":82,"context_line":"can try get project id from the information directly."},{"line_number":83,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"29f38325_dc5740aa","line":80,"range":{"start_line":80,"start_character":68,"end_line":80,"end_character":72},"in_reply_to":"ebb6d300_80f0d528","updated":"2022-05-04 03:53:13.000000000","message":"Done","commit_id":"2e452594270a1b7f312690cc8d361edeb5432161"}]}
