)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":38360,"name":"Zachary Mark Raines","display_name":"Zachary Raines","email":"zachary.raines@canonical.com","username":"raineszm","status":"Sustaining Engineer @ Canonical"},"change_message_id":"350bd38e282ed0081f4f347901c2c561f7bd1897","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"c74443f1_6c332d15","updated":"2026-09-17 15:00:51.000000000","message":"Minor and pedantic commit message nits:\n\nShould it be `Closes-Bug` insted of `Fixes-bugs`? \n\nAnd `Assisted-By` for the agent trailer?\n\nOtherwise looks like a nice, targeted fix to me.","commit_id":"3c73f91dc15e249290d3c1cf32cbfe50bf40886f"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"fd215f5c38d13649d21aba6010e30d52d72b4819","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"c98a50ba_e825f095","updated":"2026-10-07 14:39:49.000000000","message":"it\u0027s a bit funny, but it doesn\u0027t work.\nhowever it works when adding a monitor-addr and monitor-port to the member (even if they are the same as the member addr and port)\n\nhaproxy config:\n```\nserver de57f986-b64f-4a41-9477-a0dfc40d2791 172.24.4.1:443 weight 1 check inter 5s fall 3 rise 3 ssl verify none sni ssl_fc_sni ciphers DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-CHACHA20-POLY1305 ciphersuites TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256 no-sslv3 no-tlsv10 no-tlsv11 alpn h2,http/1.1,http/1.0\n```\n\nthe `ssl` keyword enables ssl for all the connections to the member (user traffic \u0026 health checks)\n\nhaproxy doc says:\n\n| When this option is used, health checks are automatically sent in SSL too unless there is a \"port\" or an \"addr\" directive indicating the check should be sent to a different location.","commit_id":"3c73f91dc15e249290d3c1cf32cbfe50bf40886f"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"82683f1c0573c3ff528253d8ad8f5918a0342980","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"921859ff_155afe39","in_reply_to":"c98a50ba_e825f095","updated":"2026-10-07 14:55:47.000000000","message":"looks like a limitation with haproxy, I think we only need to update the doc that in the case of the amphora provider when using TCP HMs on a TLS pool:\n- the healthchecks are TCP when using a monitor_addr/port\n- the healthchecks are TLS when not using a monitor_addr/port","commit_id":"3c73f91dc15e249290d3c1cf32cbfe50bf40886f"}]}
