)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"8f711a6408893d31b21e71ed31daa8dfc48fc0f7","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"9a7a8271_36b14cff","updated":"2022-10-03 16:11:48.000000000","message":"-1 for visibility only","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"dca38d56e825cd7b4b1c119138925f2d0857e506","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"dba58552_e56afa36","updated":"2022-11-02 11:30:47.000000000","message":"-1 for visibility. I would like to discuss the pending topics:\n1) The creation of the default SG rules. When it is done? This should be specify in the spec.\n2) The default DB table is missing a field, according to my comment.","commit_id":"6f58256068e13df01112f824aafeba51e4ea2bcb"},{"author":{"_account_id":15554,"name":"Bence Romsics","email":"bence.romsics@gmail.com","username":"ebenrom","status":"inactive contributor"},"change_message_id":"9c3be94bd4a1cfc8c859fb9e7b57fd55cfb1eec0","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"c3f5a89e_5fd316e9","updated":"2022-11-09 15:10:18.000000000","message":"Looks close to complete.","commit_id":"6f58256068e13df01112f824aafeba51e4ea2bcb"},{"author":{"_account_id":5948,"name":"Oleg Bondarev","email":"obondarev@mirantis.com","username":"obondarev"},"change_message_id":"1bf286583dff9a81b7888001a1738b990f16c9e6","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"77da73bd_2b6f44af","updated":"2022-11-17 14:50:39.000000000","message":"LGTM, no upgrade impact expected, right?","commit_id":"d55ea74e5991dddc50212241376fb51516733873"},{"author":{"_account_id":5948,"name":"Oleg Bondarev","email":"obondarev@mirantis.com","username":"obondarev"},"change_message_id":"43c0e1dcf30099ef6221cf8555b79ced53ae850d","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"eef51ee8_aac6ffc2","updated":"2022-11-17 15:22:26.000000000","message":"Thanks!","commit_id":"d55ea74e5991dddc50212241376fb51516733873"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"5c1c1565843307878c68ed1dc17288b7d6c1c7ef","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"e8621b43_1420c8e5","in_reply_to":"77da73bd_2b6f44af","updated":"2022-11-17 15:15:37.000000000","message":"no upgrade impact expected at all :)","commit_id":"d55ea74e5991dddc50212241376fb51516733873"}],"specs/2023.1/configurable-default-sg-rules.rst":[{"author":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"change_message_id":"04fa4c22ba637eacddc83dcfc27ff76e64ff14f3","unresolved":true,"context_lines":[{"line_number":18,"context_line":"requested to be listed via API. For each of such ``default`` security group"},{"line_number":19,"context_line":"Neutron automatically creates 4 hardcoded rules. Those rules allows:"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"* all ``IPv4`` egress traffic from the port,"},{"line_number":22,"context_line":"* all ``IPv6`` egress traffic from the port,"},{"line_number":23,"context_line":"* all ``IPv4`` ingress traffic to the port incoming from other ports which are"},{"line_number":24,"context_line":"  using the same security group,"}],"source_content_type":"text/x-rst","patch_set":1,"id":"b716d2b6_c364af6f","line":21,"range":{"start_line":21,"start_character":0,"end_line":21,"end_character":1},"updated":"2022-09-22 09:57:51.000000000","message":"nit; these should be # to have numbered list (I think) as you reference them by number below","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"a4a6de16bd1d5661e3e6cedc39f9380bdf19c2da","unresolved":false,"context_lines":[{"line_number":18,"context_line":"requested to be listed via API. For each of such ``default`` security group"},{"line_number":19,"context_line":"Neutron automatically creates 4 hardcoded rules. Those rules allows:"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"* all ``IPv4`` egress traffic from the port,"},{"line_number":22,"context_line":"* all ``IPv6`` egress traffic from the port,"},{"line_number":23,"context_line":"* all ``IPv4`` ingress traffic to the port incoming from other ports which are"},{"line_number":24,"context_line":"  using the same security group,"}],"source_content_type":"text/x-rst","patch_set":1,"id":"aa995f3b_66b0fe60","line":21,"range":{"start_line":21,"start_character":0,"end_line":21,"end_character":1},"in_reply_to":"6a9272f2_45780725","updated":"2022-10-05 20:14:10.000000000","message":"Done","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"8f711a6408893d31b21e71ed31daa8dfc48fc0f7","unresolved":true,"context_lines":[{"line_number":18,"context_line":"requested to be listed via API. For each of such ``default`` security group"},{"line_number":19,"context_line":"Neutron automatically creates 4 hardcoded rules. Those rules allows:"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"* all ``IPv4`` egress traffic from the port,"},{"line_number":22,"context_line":"* all ``IPv6`` egress traffic from the port,"},{"line_number":23,"context_line":"* all ``IPv4`` ingress traffic to the port incoming from other ports which are"},{"line_number":24,"context_line":"  using the same security group,"}],"source_content_type":"text/x-rst","patch_set":1,"id":"6a9272f2_45780725","line":21,"range":{"start_line":21,"start_character":0,"end_line":21,"end_character":1},"in_reply_to":"b716d2b6_c364af6f","updated":"2022-10-03 16:11:48.000000000","message":"+1","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"change_message_id":"04fa4c22ba637eacddc83dcfc27ff76e64ff14f3","unresolved":true,"context_lines":[{"line_number":20,"context_line":""},{"line_number":21,"context_line":"* all ``IPv4`` egress traffic from the port,"},{"line_number":22,"context_line":"* all ``IPv6`` egress traffic from the port,"},{"line_number":23,"context_line":"* all ``IPv4`` ingress traffic to the port incoming from other ports which are"},{"line_number":24,"context_line":"  using the same security group,"},{"line_number":25,"context_line":"* all ``IPv6`` ingress traffic to the port incoming from other ports which are"},{"line_number":26,"context_line":"  using the same security group."},{"line_number":27,"context_line":""},{"line_number":28,"context_line":"For any other security group created by user, Neutron automatically creates 2"},{"line_number":29,"context_line":"rules which allows:"}],"source_content_type":"text/x-rst","patch_set":1,"id":"e56e1cb0_d79926d8","line":26,"range":{"start_line":23,"start_character":0,"end_line":26,"end_character":32},"updated":"2022-09-22 09:57:51.000000000","message":"the so liked remote groups:-)","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"a4a6de16bd1d5661e3e6cedc39f9380bdf19c2da","unresolved":false,"context_lines":[{"line_number":20,"context_line":""},{"line_number":21,"context_line":"* all ``IPv4`` egress traffic from the port,"},{"line_number":22,"context_line":"* all ``IPv6`` egress traffic from the port,"},{"line_number":23,"context_line":"* all ``IPv4`` ingress traffic to the port incoming from other ports which are"},{"line_number":24,"context_line":"  using the same security group,"},{"line_number":25,"context_line":"* all ``IPv6`` ingress traffic to the port incoming from other ports which are"},{"line_number":26,"context_line":"  using the same security group."},{"line_number":27,"context_line":""},{"line_number":28,"context_line":"For any other security group created by user, Neutron automatically creates 2"},{"line_number":29,"context_line":"rules which allows:"}],"source_content_type":"text/x-rst","patch_set":1,"id":"3ce2acf9_6f5f011d","line":26,"range":{"start_line":23,"start_character":0,"end_line":26,"end_character":32},"in_reply_to":"e56e1cb0_d79926d8","updated":"2022-10-05 20:14:10.000000000","message":"yeah :)","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"8f711a6408893d31b21e71ed31daa8dfc48fc0f7","unresolved":true,"context_lines":[{"line_number":33,"context_line":""},{"line_number":34,"context_line":"There is at least couple of issues with such approach:"},{"line_number":35,"context_line":""},{"line_number":36,"context_line":"* it is known fact that SG rules with remote_group_id (rule 3. and 4. above)"},{"line_number":37,"context_line":"  don\u0027t scale well e.g. with neutron-openvswitch-agent [1]_,"},{"line_number":38,"context_line":"* some operators would like to define different rules to be created by"},{"line_number":39,"context_line":"  default for each new project."}],"source_content_type":"text/x-rst","patch_set":1,"id":"2d64ed23_570e1dfb","line":36,"range":{"start_line":36,"start_character":2,"end_line":36,"end_character":32},"updated":"2022-10-03 16:11:48.000000000","message":"nit: \"it is a known fact the the security group rules\"","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"a4a6de16bd1d5661e3e6cedc39f9380bdf19c2da","unresolved":false,"context_lines":[{"line_number":33,"context_line":""},{"line_number":34,"context_line":"There is at least couple of issues with such approach:"},{"line_number":35,"context_line":""},{"line_number":36,"context_line":"* it is known fact that SG rules with remote_group_id (rule 3. and 4. above)"},{"line_number":37,"context_line":"  don\u0027t scale well e.g. with neutron-openvswitch-agent [1]_,"},{"line_number":38,"context_line":"* some operators would like to define different rules to be created by"},{"line_number":39,"context_line":"  default for each new project."}],"source_content_type":"text/x-rst","patch_set":1,"id":"acf8f615_e5fce55a","line":36,"range":{"start_line":36,"start_character":2,"end_line":36,"end_character":32},"in_reply_to":"2d64ed23_570e1dfb","updated":"2022-10-05 20:14:10.000000000","message":"Done","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"change_message_id":"04fa4c22ba637eacddc83dcfc27ff76e64ff14f3","unresolved":true,"context_lines":[{"line_number":38,"context_line":"* some operators would like to define different rules to be created by"},{"line_number":39,"context_line":"  default for each new project."},{"line_number":40,"context_line":""},{"line_number":41,"context_line":"Of course, those rules created by default by Neutron can be easy removed by the"},{"line_number":42,"context_line":"security group owner, but having possibility to define different set of rules"},{"line_number":43,"context_line":"added automatically to each security group could make it easier for users and"},{"line_number":44,"context_line":"administrators of the cloud."}],"source_content_type":"text/x-rst","patch_set":1,"id":"4110994a_7c213659","line":41,"range":{"start_line":41,"start_character":60,"end_line":41,"end_character":64},"updated":"2022-09-22 09:57:51.000000000","message":"nit:easily","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"a4a6de16bd1d5661e3e6cedc39f9380bdf19c2da","unresolved":false,"context_lines":[{"line_number":38,"context_line":"* some operators would like to define different rules to be created by"},{"line_number":39,"context_line":"  default for each new project."},{"line_number":40,"context_line":""},{"line_number":41,"context_line":"Of course, those rules created by default by Neutron can be easy removed by the"},{"line_number":42,"context_line":"security group owner, but having possibility to define different set of rules"},{"line_number":43,"context_line":"added automatically to each security group could make it easier for users and"},{"line_number":44,"context_line":"administrators of the cloud."}],"source_content_type":"text/x-rst","patch_set":1,"id":"949c048d_fa1efd29","line":41,"range":{"start_line":41,"start_character":60,"end_line":41,"end_character":64},"in_reply_to":"4110994a_7c213659","updated":"2022-10-05 20:14:10.000000000","message":"Done","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"change_message_id":"04fa4c22ba637eacddc83dcfc27ff76e64ff14f3","unresolved":true,"context_lines":[{"line_number":48,"context_line":""},{"line_number":49,"context_line":"To solve the problem described above, proposal is to introduce new API to create"},{"line_number":50,"context_line":"``security group rules template`` used to create new security group rules for"},{"line_number":51,"context_line":"each new security group."},{"line_number":52,"context_line":"To keep backward compatybility with the existing hardoded rules, by default"},{"line_number":53,"context_line":"Neutron will have configured the same 4 rules as are hardcoded today (see above"},{"line_number":54,"context_line":"for defails). Cloud admin will be able to delete those rules and create new ones"}],"source_content_type":"text/x-rst","patch_set":1,"id":"79df8c4b_9722b211","line":51,"updated":"2022-09-22 09:57:51.000000000","message":"for the given tenant?","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"change_message_id":"3c830f72c936479125e8875cf97ede6342ab3647","unresolved":false,"context_lines":[{"line_number":48,"context_line":""},{"line_number":49,"context_line":"To solve the problem described above, proposal is to introduce new API to create"},{"line_number":50,"context_line":"``security group rules template`` used to create new security group rules for"},{"line_number":51,"context_line":"each new security group."},{"line_number":52,"context_line":"To keep backward compatybility with the existing hardoded rules, by default"},{"line_number":53,"context_line":"Neutron will have configured the same 4 rules as are hardcoded today (see above"},{"line_number":54,"context_line":"for defails). Cloud admin will be able to delete those rules and create new ones"}],"source_content_type":"text/x-rst","patch_set":1,"id":"9f36262a_03395350","line":51,"in_reply_to":"607752ab_f6dfe0fc","updated":"2022-10-12 11:39:42.000000000","message":"Ack","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"8f711a6408893d31b21e71ed31daa8dfc48fc0f7","unresolved":true,"context_lines":[{"line_number":48,"context_line":""},{"line_number":49,"context_line":"To solve the problem described above, proposal is to introduce new API to create"},{"line_number":50,"context_line":"``security group rules template`` used to create new security group rules for"},{"line_number":51,"context_line":"each new security group."},{"line_number":52,"context_line":"To keep backward compatybility with the existing hardoded rules, by default"},{"line_number":53,"context_line":"Neutron will have configured the same 4 rules as are hardcoded today (see above"},{"line_number":54,"context_line":"for defails). Cloud admin will be able to delete those rules and create new ones"}],"source_content_type":"text/x-rst","patch_set":1,"id":"c474ee1a_6d70eefc","line":51,"in_reply_to":"79df8c4b_9722b211","updated":"2022-10-03 16:11:48.000000000","message":"hmmm, I\u0027m not sure the default SG rules are per project but per cloud.","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"a4a6de16bd1d5661e3e6cedc39f9380bdf19c2da","unresolved":true,"context_lines":[{"line_number":48,"context_line":""},{"line_number":49,"context_line":"To solve the problem described above, proposal is to introduce new API to create"},{"line_number":50,"context_line":"``security group rules template`` used to create new security group rules for"},{"line_number":51,"context_line":"each new security group."},{"line_number":52,"context_line":"To keep backward compatybility with the existing hardoded rules, by default"},{"line_number":53,"context_line":"Neutron will have configured the same 4 rules as are hardcoded today (see above"},{"line_number":54,"context_line":"for defails). Cloud admin will be able to delete those rules and create new ones"}],"source_content_type":"text/x-rst","patch_set":1,"id":"607752ab_f6dfe0fc","line":51,"in_reply_to":"c474ee1a_6d70eefc","updated":"2022-10-05 20:14:10.000000000","message":"each tenant have got always created automatically security group named \"default\" and that one have 4 rules and uses remote_group_id by default.\nFor any other security group which tenant will create there are always 2 rules added by default (those 2 which allows all egress traffic).","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"8f711a6408893d31b21e71ed31daa8dfc48fc0f7","unresolved":true,"context_lines":[{"line_number":49,"context_line":"To solve the problem described above, proposal is to introduce new API to create"},{"line_number":50,"context_line":"``security group rules template`` used to create new security group rules for"},{"line_number":51,"context_line":"each new security group."},{"line_number":52,"context_line":"To keep backward compatybility with the existing hardoded rules, by default"},{"line_number":53,"context_line":"Neutron will have configured the same 4 rules as are hardcoded today (see above"},{"line_number":54,"context_line":"for defails). Cloud admin will be able to delete those rules and create new ones"},{"line_number":55,"context_line":"which will be then used by Neutron for every new security group."}],"source_content_type":"text/x-rst","patch_set":1,"id":"333f5c83_c17726a4","line":52,"range":{"start_line":52,"start_character":17,"end_line":52,"end_character":30},"updated":"2022-10-03 16:11:48.000000000","message":"nit: compatibility","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"change_message_id":"04fa4c22ba637eacddc83dcfc27ff76e64ff14f3","unresolved":true,"context_lines":[{"line_number":49,"context_line":"To solve the problem described above, proposal is to introduce new API to create"},{"line_number":50,"context_line":"``security group rules template`` used to create new security group rules for"},{"line_number":51,"context_line":"each new security group."},{"line_number":52,"context_line":"To keep backward compatybility with the existing hardoded rules, by default"},{"line_number":53,"context_line":"Neutron will have configured the same 4 rules as are hardcoded today (see above"},{"line_number":54,"context_line":"for defails). Cloud admin will be able to delete those rules and create new ones"},{"line_number":55,"context_line":"which will be then used by Neutron for every new security group."}],"source_content_type":"text/x-rst","patch_set":1,"id":"c201f554_1ec931cc","line":52,"range":{"start_line":52,"start_character":49,"end_line":52,"end_character":57},"updated":"2022-09-22 09:57:51.000000000","message":"nit: hardcoded","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"a4a6de16bd1d5661e3e6cedc39f9380bdf19c2da","unresolved":false,"context_lines":[{"line_number":49,"context_line":"To solve the problem described above, proposal is to introduce new API to create"},{"line_number":50,"context_line":"``security group rules template`` used to create new security group rules for"},{"line_number":51,"context_line":"each new security group."},{"line_number":52,"context_line":"To keep backward compatybility with the existing hardoded rules, by default"},{"line_number":53,"context_line":"Neutron will have configured the same 4 rules as are hardcoded today (see above"},{"line_number":54,"context_line":"for defails). Cloud admin will be able to delete those rules and create new ones"},{"line_number":55,"context_line":"which will be then used by Neutron for every new security group."}],"source_content_type":"text/x-rst","patch_set":1,"id":"b904bc47_1e8a4426","line":52,"range":{"start_line":52,"start_character":17,"end_line":52,"end_character":30},"in_reply_to":"333f5c83_c17726a4","updated":"2022-10-05 20:14:10.000000000","message":"Done","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"a4a6de16bd1d5661e3e6cedc39f9380bdf19c2da","unresolved":false,"context_lines":[{"line_number":49,"context_line":"To solve the problem described above, proposal is to introduce new API to create"},{"line_number":50,"context_line":"``security group rules template`` used to create new security group rules for"},{"line_number":51,"context_line":"each new security group."},{"line_number":52,"context_line":"To keep backward compatybility with the existing hardoded rules, by default"},{"line_number":53,"context_line":"Neutron will have configured the same 4 rules as are hardcoded today (see above"},{"line_number":54,"context_line":"for defails). Cloud admin will be able to delete those rules and create new ones"},{"line_number":55,"context_line":"which will be then used by Neutron for every new security group."}],"source_content_type":"text/x-rst","patch_set":1,"id":"0091ac0d_b9257e3d","line":52,"range":{"start_line":52,"start_character":49,"end_line":52,"end_character":57},"in_reply_to":"c201f554_1ec931cc","updated":"2022-10-05 20:14:10.000000000","message":"Done","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"8f711a6408893d31b21e71ed31daa8dfc48fc0f7","unresolved":true,"context_lines":[{"line_number":62,"context_line":""},{"line_number":63,"context_line":"* ``GET /v2.0/default-security-group-rules``"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"  List default security group rules used to create rules for every new"},{"line_number":66,"context_line":"  Security Group"},{"line_number":67,"context_line":""},{"line_number":68,"context_line":"  Response::"}],"source_content_type":"text/x-rst","patch_set":1,"id":"04fdd584_5775abb1","line":65,"range":{"start_line":65,"start_character":7,"end_line":65,"end_character":35},"updated":"2022-10-03 16:11:48.000000000","message":"Question 1: what are the default default SG rules (note I intentionally used the word \"default\" twice) that a new system will have? None? The 4 existing ones for the default SG?\n\nQuestion 2: for the default security group we create now 4 rules. For a new SG, we always create 2 rules. Will we have two templates, one for the default SG and another one for the default rules to be added in a normal SG?","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"a4a6de16bd1d5661e3e6cedc39f9380bdf19c2da","unresolved":true,"context_lines":[{"line_number":62,"context_line":""},{"line_number":63,"context_line":"* ``GET /v2.0/default-security-group-rules``"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"  List default security group rules used to create rules for every new"},{"line_number":66,"context_line":"  Security Group"},{"line_number":67,"context_line":""},{"line_number":68,"context_line":"  Response::"}],"source_content_type":"text/x-rst","patch_set":1,"id":"b75f9f45_f4f2b0f5","line":65,"range":{"start_line":65,"start_character":7,"end_line":65,"end_character":35},"in_reply_to":"04fdd584_5775abb1","updated":"2022-10-05 20:14:10.000000000","message":"\u003e Question 1: what are the default default SG rules (note I intentionally used the word \"default\" twice) that a new system will have? None? The 4 existing ones for the default SG?\n\nBy default we will have those 4 mentioned above added as new \"default default\" rules.\n\n\u003e \n\u003e Question 2: for the default security group we create now 4 rules. For a new SG, we always create 2 rules. Will we have two templates, one for the default SG and another one for the default rules to be added in a normal SG?\n\nKind of, please see L81 and attribute \"used_in_default_security_group\" which will tell if rule should be used in \"default\" SG or only in other security groups.","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"d6bd2bed01320e44a918614f8d4f5aa64cb8f814","unresolved":false,"context_lines":[{"line_number":62,"context_line":""},{"line_number":63,"context_line":"* ``GET /v2.0/default-security-group-rules``"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"  List default security group rules used to create rules for every new"},{"line_number":66,"context_line":"  Security Group"},{"line_number":67,"context_line":""},{"line_number":68,"context_line":"  Response::"}],"source_content_type":"text/x-rst","patch_set":1,"id":"c395f575_5e596370","line":65,"range":{"start_line":65,"start_character":7,"end_line":65,"end_character":35},"in_reply_to":"707f448b_4e69a2b0","updated":"2022-10-18 07:19:57.000000000","message":"I didn\u0027t see the \"used_in_default_security_group\" field in the JSONs. BTW, I think we need to add it to the DB table.","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"change_message_id":"3c830f72c936479125e8875cf97ede6342ab3647","unresolved":true,"context_lines":[{"line_number":62,"context_line":""},{"line_number":63,"context_line":"* ``GET /v2.0/default-security-group-rules``"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"  List default security group rules used to create rules for every new"},{"line_number":66,"context_line":"  Security Group"},{"line_number":67,"context_line":""},{"line_number":68,"context_line":"  Response::"}],"source_content_type":"text/x-rst","patch_set":1,"id":"707f448b_4e69a2b0","line":65,"range":{"start_line":65,"start_character":7,"end_line":65,"end_character":35},"in_reply_to":"b75f9f45_f4f2b0f5","updated":"2022-10-12 11:39:42.000000000","message":"thanks, for me looks ok","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"change_message_id":"04fa4c22ba637eacddc83dcfc27ff76e64ff14f3","unresolved":true,"context_lines":[{"line_number":226,"context_line":""},{"line_number":227,"context_line":"  Delete default security group rule used to create rules for every new"},{"line_number":228,"context_line":"  Security Group"},{"line_number":229,"context_line":""},{"line_number":230,"context_line":"DB Impact"},{"line_number":231,"context_line":"---------"},{"line_number":232,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"3eaa5554_92dc439c","line":229,"updated":"2022-09-22 09:57:51.000000000","message":"Is PUT planned to be supported?\nWould have strange anyway, would effect for the next created groups only, or such","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"change_message_id":"e6dfa9cbfb78e31a6b8d0b049ee7da8e6b35ca65","unresolved":true,"context_lines":[{"line_number":226,"context_line":""},{"line_number":227,"context_line":"  Delete default security group rule used to create rules for every new"},{"line_number":228,"context_line":"  Security Group"},{"line_number":229,"context_line":""},{"line_number":230,"context_line":"DB Impact"},{"line_number":231,"context_line":"---------"},{"line_number":232,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"4d409633_73ac24a5","line":229,"in_reply_to":"25cc6daa_f092e6cb","updated":"2022-10-05 13:07:01.000000000","message":"ack. This could be written here or in the docs later","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"8f711a6408893d31b21e71ed31daa8dfc48fc0f7","unresolved":true,"context_lines":[{"line_number":226,"context_line":""},{"line_number":227,"context_line":"  Delete default security group rule used to create rules for every new"},{"line_number":228,"context_line":"  Security Group"},{"line_number":229,"context_line":""},{"line_number":230,"context_line":"DB Impact"},{"line_number":231,"context_line":"---------"},{"line_number":232,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"25cc6daa_f092e6cb","line":229,"in_reply_to":"3eaa5554_92dc439c","updated":"2022-10-03 16:11:48.000000000","message":"That\u0027s only my opinion, but if we are going to define global resources, like those default SG rules, I would prefer to use statically defined rules. In other words, not to be able to modify them.","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"a4a6de16bd1d5661e3e6cedc39f9380bdf19c2da","unresolved":false,"context_lines":[{"line_number":226,"context_line":""},{"line_number":227,"context_line":"  Delete default security group rule used to create rules for every new"},{"line_number":228,"context_line":"  Security Group"},{"line_number":229,"context_line":""},{"line_number":230,"context_line":"DB Impact"},{"line_number":231,"context_line":"---------"},{"line_number":232,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"c2e9682c_c2c28977","line":229,"in_reply_to":"4d409633_73ac24a5","updated":"2022-10-05 20:14:10.000000000","message":"I didn\u0027t plan to support PUT as it\u0027s also not supported by Security group rules API currently.","commit_id":"acb511c1e54758b3457b1a90c910255a0315d4f9"},{"author":{"_account_id":4694,"name":"Miguel Lavalle","email":"miguel@mlavalle.com","username":"minsel"},"change_message_id":"887864c5088113fee04e367a793a201f0a8ec583","unresolved":true,"context_lines":[{"line_number":16,"context_line":"For every project, Neutron always creates security group called ``default``. It"},{"line_number":17,"context_line":"is created always when first time security groups are going to be used or"},{"line_number":18,"context_line":"requested to be listed via API. For each of such ``default`` security group"},{"line_number":19,"context_line":"Neutron automatically creates 4 hardcoded rules. Those rules allows:"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"#. all ``IPv4`` egress traffic from the port,"},{"line_number":22,"context_line":"#. all ``IPv6`` egress traffic from the port,"}],"source_content_type":"text/x-rst","patch_set":2,"id":"eb995030_77c2f873","line":19,"range":{"start_line":19,"start_character":61,"end_line":19,"end_character":67},"updated":"2022-11-01 17:20:17.000000000","message":"nit: allow","commit_id":"6f58256068e13df01112f824aafeba51e4ea2bcb"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"2073f2d12f3e2843f78aab08010e6b6f914ed99d","unresolved":false,"context_lines":[{"line_number":16,"context_line":"For every project, Neutron always creates security group called ``default``. It"},{"line_number":17,"context_line":"is created always when first time security groups are going to be used or"},{"line_number":18,"context_line":"requested to be listed via API. For each of such ``default`` security group"},{"line_number":19,"context_line":"Neutron automatically creates 4 hardcoded rules. Those rules allows:"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"#. all ``IPv4`` egress traffic from the port,"},{"line_number":22,"context_line":"#. all ``IPv6`` egress traffic from the port,"}],"source_content_type":"text/x-rst","patch_set":2,"id":"cef89641_3deabec1","line":19,"range":{"start_line":19,"start_character":61,"end_line":19,"end_character":67},"in_reply_to":"eb995030_77c2f873","updated":"2022-11-10 19:39:31.000000000","message":"Done","commit_id":"6f58256068e13df01112f824aafeba51e4ea2bcb"},{"author":{"_account_id":15554,"name":"Bence Romsics","email":"bence.romsics@gmail.com","username":"ebenrom","status":"inactive contributor"},"change_message_id":"9c3be94bd4a1cfc8c859fb9e7b57fd55cfb1eec0","unresolved":true,"context_lines":[{"line_number":47,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":48,"context_line":""},{"line_number":49,"context_line":"To solve the problem described above, proposal is to introduce new API to create"},{"line_number":50,"context_line":"``security group rules template`` used to create new security group rules for"},{"line_number":51,"context_line":"each new security group."},{"line_number":52,"context_line":"To keep backward compatibility with the existing hardcoded rules, by default"},{"line_number":53,"context_line":"Neutron will have configured the same 4 rules as are hardcoded today (see above"}],"source_content_type":"text/x-rst","patch_set":2,"id":"59635c02_55f6ae60","line":50,"range":{"start_line":50,"start_character":23,"end_line":50,"end_character":31},"updated":"2022-11-09 15:10:18.000000000","message":"side note: This seems to me better wording to use in the docs to be written (api-ref, etc) than \"default default\". The latter could be prone to confusion.","commit_id":"6f58256068e13df01112f824aafeba51e4ea2bcb"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"4c3868e6d6702f2d74df8204703bec4c66dfdf75","unresolved":true,"context_lines":[{"line_number":47,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":48,"context_line":""},{"line_number":49,"context_line":"To solve the problem described above, proposal is to introduce new API to create"},{"line_number":50,"context_line":"``security group rules template`` used to create new security group rules for"},{"line_number":51,"context_line":"each new security group."},{"line_number":52,"context_line":"To keep backward compatibility with the existing hardcoded rules, by default"},{"line_number":53,"context_line":"Neutron will have configured the same 4 rules as are hardcoded today (see above"}],"source_content_type":"text/x-rst","patch_set":2,"id":"e768ca3c_506228df","line":50,"range":{"start_line":50,"start_character":23,"end_line":50,"end_character":31},"in_reply_to":"59635c02_55f6ae60","updated":"2023-12-14 13:00:47.000000000","message":"Some 13 months later, I arrived at the same conclusion independently 😅 https://review.opendev.org/c/openstack/python-openstackclient/+/903672/1/openstackclient/network/v2/default_security_group_rule.py#41","commit_id":"6f58256068e13df01112f824aafeba51e4ea2bcb"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"3a23b78c8d88361e84544bcb279f92f3a417889b","unresolved":true,"context_lines":[{"line_number":47,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":48,"context_line":""},{"line_number":49,"context_line":"To solve the problem described above, proposal is to introduce new API to create"},{"line_number":50,"context_line":"``security group rules template`` used to create new security group rules for"},{"line_number":51,"context_line":"each new security group."},{"line_number":52,"context_line":"To keep backward compatibility with the existing hardcoded rules, by default"},{"line_number":53,"context_line":"Neutron will have configured the same 4 rules as are hardcoded today (see above"}],"source_content_type":"text/x-rst","patch_set":2,"id":"6213dc09_0e38e8cd","line":50,"range":{"start_line":50,"start_character":23,"end_line":50,"end_character":31},"in_reply_to":"e768ca3c_506228df","updated":"2023-12-15 15:51:07.000000000","message":"TBH I also though about that but it was already too late as things were merged and released already so it wouldn\u0027t be easy to rename it now.","commit_id":"6f58256068e13df01112f824aafeba51e4ea2bcb"},{"author":{"_account_id":15554,"name":"Bence Romsics","email":"bence.romsics@gmail.com","username":"ebenrom","status":"inactive contributor"},"change_message_id":"9c3be94bd4a1cfc8c859fb9e7b57fd55cfb1eec0","unresolved":true,"context_lines":[{"line_number":68,"context_line":"  Response::"},{"line_number":69,"context_line":""},{"line_number":70,"context_line":"    {"},{"line_number":71,"context_line":"      \"default_security_group_rules\": ["},{"line_number":72,"context_line":"      {"},{"line_number":73,"context_line":"          \"direction\": \"egress\","},{"line_number":74,"context_line":"          \"ethertype\": \"IPv6\","}],"source_content_type":"text/x-rst","patch_set":2,"id":"d6db22d9_78ff5a6e","line":71,"range":{"start_line":71,"start_character":38,"end_line":71,"end_character":39},"updated":"2022-11-09 15:10:18.000000000","message":"When this list is empty I guess we\u0027ll get empty default security groups and not today\u0027s behavior, right?","commit_id":"6f58256068e13df01112f824aafeba51e4ea2bcb"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"2073f2d12f3e2843f78aab08010e6b6f914ed99d","unresolved":false,"context_lines":[{"line_number":68,"context_line":"  Response::"},{"line_number":69,"context_line":""},{"line_number":70,"context_line":"    {"},{"line_number":71,"context_line":"      \"default_security_group_rules\": ["},{"line_number":72,"context_line":"      {"},{"line_number":73,"context_line":"          \"direction\": \"egress\","},{"line_number":74,"context_line":"          \"ethertype\": \"IPv6\","}],"source_content_type":"text/x-rst","patch_set":2,"id":"6884b252_246fc571","line":71,"range":{"start_line":71,"start_character":38,"end_line":71,"end_character":39},"in_reply_to":"d6db22d9_78ff5a6e","updated":"2022-11-10 19:39:31.000000000","message":"correct. Let me explicitly write it there","commit_id":"6f58256068e13df01112f824aafeba51e4ea2bcb"},{"author":{"_account_id":15554,"name":"Bence Romsics","email":"bence.romsics@gmail.com","username":"ebenrom","status":"inactive contributor"},"change_message_id":"9c3be94bd4a1cfc8c859fb9e7b57fd55cfb1eec0","unresolved":true,"context_lines":[{"line_number":78,"context_line":"          \"protocol\": null,"},{"line_number":79,"context_line":"          \"remote_group_id\": null,"},{"line_number":80,"context_line":"          \"remote_ip_prefix\": null,"},{"line_number":81,"context_line":"          \"used_in_default_security_group\": True"},{"line_number":82,"context_line":"          \"revision_number\": 1,"},{"line_number":83,"context_line":"          \"created_at\": \"2022-09-15T19:16:56Z\","},{"line_number":84,"context_line":"          \"updated_at\": \"2022-09-15T19:16:56Z\","}],"source_content_type":"text/x-rst","patch_set":2,"id":"c674e985_e8b3ade1","line":81,"range":{"start_line":81,"start_character":11,"end_line":81,"end_character":41},"updated":"2022-11-09 15:10:18.000000000","message":"It seems to me this is not explained in the spec itself, only in the comments.","commit_id":"6f58256068e13df01112f824aafeba51e4ea2bcb"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"d6bd2bed01320e44a918614f8d4f5aa64cb8f814","unresolved":true,"context_lines":[{"line_number":163,"context_line":""},{"line_number":164,"context_line":"* ``POST /v2.0/default-security-group-rules``"},{"line_number":165,"context_line":""},{"line_number":166,"context_line":"  Create default security group rule used to create rules for every new"},{"line_number":167,"context_line":"  Security Group"},{"line_number":168,"context_line":""},{"line_number":169,"context_line":"  Request::"}],"source_content_type":"text/x-rst","patch_set":2,"id":"44e0101d_5a7f8d55","line":166,"range":{"start_line":166,"start_character":1,"end_line":166,"end_character":26},"updated":"2022-10-18 07:19:57.000000000","message":"Similar question here: when the system is fresh installed, when/how those rules are created? The installer (devstack/kolla/tripleo) is going to create those rules?","commit_id":"6f58256068e13df01112f824aafeba51e4ea2bcb"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"46b60e506fb20c89bc9d8c91c9a3738d5e03536a","unresolved":true,"context_lines":[{"line_number":163,"context_line":""},{"line_number":164,"context_line":"* ``POST /v2.0/default-security-group-rules``"},{"line_number":165,"context_line":""},{"line_number":166,"context_line":"  Create default security group rule used to create rules for every new"},{"line_number":167,"context_line":"  Security Group"},{"line_number":168,"context_line":""},{"line_number":169,"context_line":"  Request::"}],"source_content_type":"text/x-rst","patch_set":2,"id":"343138b3_a9f325b5","line":166,"range":{"start_line":166,"start_character":1,"end_line":166,"end_character":26},"in_reply_to":"44e0101d_5a7f8d55","updated":"2022-10-25 14:30:15.000000000","message":"I though that db migration script will basically add those default rules  so they will be there always from the beginning.","commit_id":"6f58256068e13df01112f824aafeba51e4ea2bcb"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"d6bd2bed01320e44a918614f8d4f5aa64cb8f814","unresolved":true,"context_lines":[{"line_number":230,"context_line":"DB Impact"},{"line_number":231,"context_line":"---------"},{"line_number":232,"context_line":""},{"line_number":233,"context_line":"Default security group rule DB table:"},{"line_number":234,"context_line":""},{"line_number":235,"context_line":"+-------------------+---------+-------+------+---------------------------------------+"},{"line_number":236,"context_line":"| Attribute         | Type    | Req   | CRUD | Description                           |"}],"source_content_type":"text/x-rst","patch_set":2,"id":"3c72eec2_d23ac08c","line":233,"range":{"start_line":233,"start_character":0,"end_line":233,"end_character":37},"updated":"2022-10-18 07:19:57.000000000","message":"Should we need a new field called \"used_in_default_security_group\" or something related?","commit_id":"6f58256068e13df01112f824aafeba51e4ea2bcb"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"2073f2d12f3e2843f78aab08010e6b6f914ed99d","unresolved":false,"context_lines":[{"line_number":230,"context_line":"DB Impact"},{"line_number":231,"context_line":"---------"},{"line_number":232,"context_line":""},{"line_number":233,"context_line":"Default security group rule DB table:"},{"line_number":234,"context_line":""},{"line_number":235,"context_line":"+-------------------+---------+-------+------+---------------------------------------+"},{"line_number":236,"context_line":"| Attribute         | Type    | Req   | CRUD | Description                           |"}],"source_content_type":"text/x-rst","patch_set":2,"id":"364063cc_fad32be9","line":233,"range":{"start_line":233,"start_character":0,"end_line":233,"end_character":37},"in_reply_to":"3c72eec2_d23ac08c","updated":"2022-11-10 19:39:31.000000000","message":"Right. I forgot about it :)","commit_id":"6f58256068e13df01112f824aafeba51e4ea2bcb"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"cba3a1751907d4cf73ca694877ad411348f62d5b","unresolved":false,"context_lines":[{"line_number":53,"context_line":"Neutron will have configured the same 4 rules as are hardcoded today (see above"},{"line_number":54,"context_line":"for defails). Cloud admin will be able to delete those rules and create new ones"},{"line_number":55,"context_line":"which will be then used by Neutron for every new security group."},{"line_number":56,"context_line":"In case when list of the ``default_security_group_rule`` is empty, new security"},{"line_number":57,"context_line":"groups will be created without any rules created by default."},{"line_number":58,"context_line":""},{"line_number":59,"context_line":"REST API Impact"},{"line_number":60,"context_line":"---------------"}],"source_content_type":"text/x-rst","patch_set":3,"id":"0b6d5158_840a208d","line":57,"range":{"start_line":56,"start_character":0,"end_line":57,"end_character":60},"updated":"2022-11-17 10:59:04.000000000","message":"Well, at least if no default SG rule is created, the default FW behaviour will be to block everything. This should not be a security problem.","commit_id":"d55ea74e5991dddc50212241376fb51516733873"}]}
