)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":34429,"name":"Tom Weininger","email":"dienste@weinimo.de","username":"tweining"},"change_message_id":"0694604cca2236b68a6245a5648c5ad44a81f715","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"30d9c2d0_e4511ae8","updated":"2024-04-08 13:43:35.000000000","message":"looks good in general.","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":34429,"name":"Tom Weininger","email":"dienste@weinimo.de","username":"tweining"},"change_message_id":"6b21b3421b5a4cd97aeb5aa7dd8a233aa1a1a6be","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"d55deb50_126ca263","updated":"2024-05-21 15:24:21.000000000","message":"typo only","commit_id":"0d955c5969e7ff9b86f93798bd999b7657f0b35b"},{"author":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},"change_message_id":"0a9eea05379964b20976b52a59ca1d84e275b5ef","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"f9b1311d_de41e7ab","updated":"2024-07-10 03:01:15.000000000","message":"A couple of items to discuss.","commit_id":"5e6590d3270e4b2ba9752e522544456c9a9f014b"},{"author":{"_account_id":34429,"name":"Tom Weininger","email":"dienste@weinimo.de","username":"tweining"},"change_message_id":"e67ed3e2d6adf9b71aafb15e14497dd53ba54a99","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"042e46db_b103f8d2","updated":"2024-07-31 10:34:57.000000000","message":"The link to this new rst in the index page is missing","commit_id":"e757f1bfa7d17153e904ce2fceddf121f0ad0aa7"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"063623bb17a3fa756a1c6a80e6e7e8ccc523b552","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"b4a39233_e8cf12c6","in_reply_to":"042e46db_b103f8d2","updated":"2024-08-07 09:59:47.000000000","message":"it\u0027s there: https://storage.gra.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_c56/915114/4/check/openstack-tox-docs/c56b538/docs/contributor/index.html\nI\u0027m moving the spec to the new 15 directory anyway","commit_id":"e757f1bfa7d17153e904ce2fceddf121f0ad0aa7"},{"author":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},"change_message_id":"03515f3c77acf17c220554f5473b3a3eb8d71fce","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"a004a426_258a3282","updated":"2024-08-12 21:23:44.000000000","message":"I am not a fan of this feature, but I think we have addressed ways for operators to disable it\u0027s use if they don\u0027t want to hand control over to users.","commit_id":"1b09ba8f378a61bc1d913be26fd7e0a28e950c27"}],"specs/version14.0/custom-security-groups-for-VIP-ports.rst":[{"author":{"_account_id":31335,"name":"Thobias Trevisan","email":"thobias_trevisan@sicredi.com.br","username":"thobiast"},"change_message_id":"17a5b84a873872b0e56965fd88859e98ae280c65","unresolved":true,"context_lines":[{"line_number":19,"context_line":"VIP ports of a load balancer in Octavia. There are some benefits from using"},{"line_number":20,"context_line":"custom security groups:"},{"line_number":21,"context_line":""},{"line_number":22,"context_line":"* Allowing incoming connections only from specific remote group IDs."},{"line_number":23,"context_line":""},{"line_number":24,"context_line":"* Having a unique API (The networking Security Groups API) to configure the"},{"line_number":25,"context_line":"  network security for all the users\u0027 resources."}],"source_content_type":"text/x-rst","patch_set":1,"id":"74b62431_70863f10","line":22,"updated":"2024-04-08 13:35:07.000000000","message":"Hi, It would be useful to enable the use of the SG as remote security group for backends. The goal is to restrict LB backends so they only accept traffic from the LB IPs. This is a security measure intended to prevent other VMs from directly accessing the LB backends. That feature would enhances security design for applications and it\u0027s a common architectural approach.","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},"change_message_id":"0a9eea05379964b20976b52a59ca1d84e275b5ef","unresolved":true,"context_lines":[{"line_number":19,"context_line":"VIP ports of a load balancer in Octavia. There are some benefits from using"},{"line_number":20,"context_line":"custom security groups:"},{"line_number":21,"context_line":""},{"line_number":22,"context_line":"* Allowing incoming connections only from specific remote group IDs."},{"line_number":23,"context_line":""},{"line_number":24,"context_line":"* Having a unique API (The networking Security Groups API) to configure the"},{"line_number":25,"context_line":"  network security for all the users\u0027 resources."}],"source_content_type":"text/x-rst","patch_set":1,"id":"e783b836_1e085bae","line":22,"in_reply_to":"4afef788_442d4fed","updated":"2024-07-10 03:01:15.000000000","message":"I agree, this should be another spec. Also, we currently support this via TLS client certificates. A secure way to address this issue.","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"06403594e188db25db1e579a3357cc2756695a40","unresolved":true,"context_lines":[{"line_number":19,"context_line":"VIP ports of a load balancer in Octavia. There are some benefits from using"},{"line_number":20,"context_line":"custom security groups:"},{"line_number":21,"context_line":""},{"line_number":22,"context_line":"* Allowing incoming connections only from specific remote group IDs."},{"line_number":23,"context_line":""},{"line_number":24,"context_line":"* Having a unique API (The networking Security Groups API) to configure the"},{"line_number":25,"context_line":"  network security for all the users\u0027 resources."}],"source_content_type":"text/x-rst","patch_set":1,"id":"4afef788_442d4fed","line":22,"in_reply_to":"74b62431_70863f10","updated":"2024-05-15 11:16:08.000000000","message":"Good point, I think it will be the next step after this feature, and it will have its own specification","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"383b5583be57951e90a25474a2a3513add4658c5","unresolved":true,"context_lines":[{"line_number":28,"context_line":"Proposed change"},{"line_number":29,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"A user will be able to provide a ``vip_sg_id`` parameter when creating a load"},{"line_number":32,"context_line":"balancer."},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"This parameter will be optional and defaulted to None. When it\u0027s not set, the"}],"source_content_type":"text/x-rst","patch_set":1,"id":"542c5a2f_4a0f6deb","line":31,"range":{"start_line":31,"start_character":31,"end_line":31,"end_character":56},"updated":"2024-04-11 09:26:52.000000000","message":"I\u0027ve just got feedback from operators on this: there are requests to have multiple vip_sg_ids per load balancer (It may impact the API as it would make sense to allow  the update of the sg_ids)","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"06403594e188db25db1e579a3357cc2756695a40","unresolved":false,"context_lines":[{"line_number":28,"context_line":"Proposed change"},{"line_number":29,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"A user will be able to provide a ``vip_sg_id`` parameter when creating a load"},{"line_number":32,"context_line":"balancer."},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"This parameter will be optional and defaulted to None. When it\u0027s not set, the"}],"source_content_type":"text/x-rst","patch_set":1,"id":"1d20c6cd_076b9c92","line":31,"range":{"start_line":31,"start_character":31,"end_line":31,"end_character":56},"in_reply_to":"542c5a2f_4a0f6deb","updated":"2024-05-15 11:16:08.000000000","message":"Done","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":34429,"name":"Tom Weininger","email":"dienste@weinimo.de","username":"tweining"},"change_message_id":"0694604cca2236b68a6245a5648c5ad44a81f715","unresolved":true,"context_lines":[{"line_number":35,"context_line":"behavior of the VIP port would not change."},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"If the parameter is set, Octavia would apply this security group to the VIP and"},{"line_number":38,"context_line":"VRRP ports. Then Octavia would create and manage a security group with rules"},{"line_number":39,"context_line":"for its internal communication (haproxy peering, VRRP communication). Thus the"},{"line_number":40,"context_line":"VIP port would have 2 security groups."},{"line_number":41,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"ab3861cc_a1e61faa","line":38,"range":{"start_line":38,"start_character":0,"end_line":38,"end_character":10},"updated":"2024-04-08 13:43:35.000000000","message":"Only in active-standby configuration, right? Maybe it\u0027s worth mentioning that explicitly. This feature would also work in standalone configuration.","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"06403594e188db25db1e579a3357cc2756695a40","unresolved":true,"context_lines":[{"line_number":35,"context_line":"behavior of the VIP port would not change."},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"If the parameter is set, Octavia would apply this security group to the VIP and"},{"line_number":38,"context_line":"VRRP ports. Then Octavia would create and manage a security group with rules"},{"line_number":39,"context_line":"for its internal communication (haproxy peering, VRRP communication). Thus the"},{"line_number":40,"context_line":"VIP port would have 2 security groups."},{"line_number":41,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"fcb2d2ae_ff042fef","line":38,"range":{"start_line":38,"start_character":0,"end_line":38,"end_character":10},"in_reply_to":"ab3861cc_a1e61faa","updated":"2024-05-15 11:16:08.000000000","message":"Amphora ports are always called VRRP ports regardless of the topology (see https://opendev.org/openstack/octavia/src/commit/5898d54b137f5fb7a1d45bf8d620ef8ab8133259/octavia/db/models.py#L684).\nI can change it to \"Amphora ports\"","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},"change_message_id":"50761defc27f9c6d0690802ccca862bc7813c5bf","unresolved":true,"context_lines":[{"line_number":37,"context_line":"If the parameter is set, Octavia would apply this security group to the VIP and"},{"line_number":38,"context_line":"VRRP ports. Then Octavia would create and manage a security group with rules"},{"line_number":39,"context_line":"for its internal communication (haproxy peering, VRRP communication). Thus the"},{"line_number":40,"context_line":"VIP port would have 2 security groups."},{"line_number":41,"context_line":""},{"line_number":42,"context_line":"No rules based on the port or the protocol of the listeners would be managed by"},{"line_number":43,"context_line":"Octavia, for each new listener, the user would have to add their own rules to"}],"source_content_type":"text/x-rst","patch_set":1,"id":"c1afaf63_9c7b0ef4","line":40,"range":{"start_line":40,"start_character":20,"end_line":40,"end_character":37},"updated":"2024-04-05 10:15:16.000000000","message":"2 security groups, 1 for incoming traffic to the LB VIP, and another 1 for the internal traffic within Octavia? Shouldn\u0027t the one within Octavia be out of the scope of this feature?\nExcept for this doubt, it all looks good to me","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"06403594e188db25db1e579a3357cc2756695a40","unresolved":false,"context_lines":[{"line_number":37,"context_line":"If the parameter is set, Octavia would apply this security group to the VIP and"},{"line_number":38,"context_line":"VRRP ports. Then Octavia would create and manage a security group with rules"},{"line_number":39,"context_line":"for its internal communication (haproxy peering, VRRP communication). Thus the"},{"line_number":40,"context_line":"VIP port would have 2 security groups."},{"line_number":41,"context_line":""},{"line_number":42,"context_line":"No rules based on the port or the protocol of the listeners would be managed by"},{"line_number":43,"context_line":"Octavia, for each new listener, the user would have to add their own rules to"}],"source_content_type":"text/x-rst","patch_set":1,"id":"da5b838b_7dcbc5fa","line":40,"range":{"start_line":40,"start_character":20,"end_line":40,"end_character":37},"in_reply_to":"9188b956_9f9e7b50","updated":"2024-05-15 11:16:08.000000000","message":"Done","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"10e554aa7eaedb3f5dfbd72893e3a9e7262dd217","unresolved":true,"context_lines":[{"line_number":37,"context_line":"If the parameter is set, Octavia would apply this security group to the VIP and"},{"line_number":38,"context_line":"VRRP ports. Then Octavia would create and manage a security group with rules"},{"line_number":39,"context_line":"for its internal communication (haproxy peering, VRRP communication). Thus the"},{"line_number":40,"context_line":"VIP port would have 2 security groups."},{"line_number":41,"context_line":""},{"line_number":42,"context_line":"No rules based on the port or the protocol of the listeners would be managed by"},{"line_number":43,"context_line":"Octavia, for each new listener, the user would have to add their own rules to"}],"source_content_type":"text/x-rst","patch_set":1,"id":"9188b956_9f9e7b50","line":40,"range":{"start_line":40,"start_character":20,"end_line":40,"end_character":37},"in_reply_to":"c1afaf63_9c7b0ef4","updated":"2024-04-05 13:56:45.000000000","message":"I think it should be detailed (maybe I should even provide more detail in the spec), because this 2nd SG is the one that is usually used by Octavia to allow incoming traffic to the LB, but with this RFE, this SG will not have any rule for the user traffic.\n\nSo in a traditional LB:\n\nSG contains rules for each listener + haproxy peering + VRRP\n\nin the \"custom SG\" mode:\n\nSG contains rules for haproxy peering + VRRP\nUser\u0027s SG contains rules for each listener","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":34429,"name":"Tom Weininger","email":"dienste@weinimo.de","username":"tweining"},"change_message_id":"0694604cca2236b68a6245a5648c5ad44a81f715","unresolved":true,"context_lines":[{"line_number":41,"context_line":""},{"line_number":42,"context_line":"No rules based on the port or the protocol of the listeners would be managed by"},{"line_number":43,"context_line":"Octavia, for each new listener, the user would have to add their own rules to"},{"line_number":44,"context_line":"theis security group."},{"line_number":45,"context_line":""},{"line_number":46,"context_line":""},{"line_number":47,"context_line":"Alternatives"}],"source_content_type":"text/x-rst","patch_set":1,"id":"56e223f6_c23c3204","line":44,"range":{"start_line":44,"start_character":0,"end_line":44,"end_character":5},"updated":"2024-04-08 13:43:35.000000000","message":"`this`","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"06403594e188db25db1e579a3357cc2756695a40","unresolved":false,"context_lines":[{"line_number":41,"context_line":""},{"line_number":42,"context_line":"No rules based on the port or the protocol of the listeners would be managed by"},{"line_number":43,"context_line":"Octavia, for each new listener, the user would have to add their own rules to"},{"line_number":44,"context_line":"theis security group."},{"line_number":45,"context_line":""},{"line_number":46,"context_line":""},{"line_number":47,"context_line":"Alternatives"}],"source_content_type":"text/x-rst","patch_set":1,"id":"9cc62e76_a4a30122","line":44,"range":{"start_line":44,"start_character":0,"end_line":44,"end_character":5},"in_reply_to":"56e223f6_c23c3204","updated":"2024-05-15 11:16:08.000000000","message":"Done","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":31357,"name":"LEDUC Florian","display_name":"Florian LEDUC","email":"florian.leduc@socgen.com","username":"leducflorian","status":"Société Générale"},"change_message_id":"cb903063b7e27526b5b52b83660462a769ac3387","unresolved":true,"context_lines":[{"line_number":64,"context_line":"---------------"},{"line_number":65,"context_line":""},{"line_number":66,"context_line":"The POST /v2/lbaas/loadbalancers endpoint is updated to accept an optional"},{"line_number":67,"context_line":"``vip_sg_id`` parameter (an UUID that represents a Neutron Security Group)."},{"line_number":68,"context_line":""},{"line_number":69,"context_line":"If the parameter is set, Octavia checks that the security group exists and that"},{"line_number":70,"context_line":"the user is allowed to use it, then Octavia creates the VIP object with this"}],"source_content_type":"text/x-rst","patch_set":1,"id":"54166af8_fcf535ca","line":67,"updated":"2024-04-12 09:38:37.000000000","message":"I think this line is confusing according to the line 18 in the \"problem description\" which is relevant for this spec. The user should have the choice to set one or more SGs for the LB. Morever, I assume the data model should stick with the security_group field for a port in neutron (a array of UUIDs).","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"06403594e188db25db1e579a3357cc2756695a40","unresolved":false,"context_lines":[{"line_number":64,"context_line":"---------------"},{"line_number":65,"context_line":""},{"line_number":66,"context_line":"The POST /v2/lbaas/loadbalancers endpoint is updated to accept an optional"},{"line_number":67,"context_line":"``vip_sg_id`` parameter (an UUID that represents a Neutron Security Group)."},{"line_number":68,"context_line":""},{"line_number":69,"context_line":"If the parameter is set, Octavia checks that the security group exists and that"},{"line_number":70,"context_line":"the user is allowed to use it, then Octavia creates the VIP object with this"}],"source_content_type":"text/x-rst","patch_set":1,"id":"030e4343_f9dcd006","line":67,"in_reply_to":"54166af8_fcf535ca","updated":"2024-05-15 11:16:08.000000000","message":"Done","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"d4d48e764d7f7e66e11043c712935f6b64bbff77","unresolved":true,"context_lines":[{"line_number":74,"context_line":"``vip_sg_id`` of a load balancer is not allowed."},{"line_number":75,"context_line":""},{"line_number":76,"context_line":"The ``vip_sg_id`` parameter is also added to the reply of the GET method."},{"line_number":77,"context_line":""},{"line_number":78,"context_line":""},{"line_number":79,"context_line":"Security impact"},{"line_number":80,"context_line":"---------------"}],"source_content_type":"text/x-rst","patch_set":1,"id":"a703d746_c99ecd63","line":77,"updated":"2024-04-05 15:39:05.000000000","message":"TODO: an other impact on the API, allowed_cidrs parameter should be denied on LBs with vip_sg_id","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"06403594e188db25db1e579a3357cc2756695a40","unresolved":false,"context_lines":[{"line_number":74,"context_line":"``vip_sg_id`` of a load balancer is not allowed."},{"line_number":75,"context_line":""},{"line_number":76,"context_line":"The ``vip_sg_id`` parameter is also added to the reply of the GET method."},{"line_number":77,"context_line":""},{"line_number":78,"context_line":""},{"line_number":79,"context_line":"Security impact"},{"line_number":80,"context_line":"---------------"}],"source_content_type":"text/x-rst","patch_set":1,"id":"c3194226_0256229e","line":77,"in_reply_to":"a703d746_c99ecd63","updated":"2024-05-15 11:16:08.000000000","message":"Done","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"d4d48e764d7f7e66e11043c712935f6b64bbff77","unresolved":true,"context_lines":[{"line_number":75,"context_line":""},{"line_number":76,"context_line":"The ``vip_sg_id`` parameter is also added to the reply of the GET method."},{"line_number":77,"context_line":""},{"line_number":78,"context_line":""},{"line_number":79,"context_line":"Security impact"},{"line_number":80,"context_line":"---------------"},{"line_number":81,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"aaf2c79c_d6121fb6","line":78,"updated":"2024-04-05 15:39:05.000000000","message":"TODO: vip_sg_id is not possible with SR-IOV LBs","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"06403594e188db25db1e579a3357cc2756695a40","unresolved":false,"context_lines":[{"line_number":75,"context_line":""},{"line_number":76,"context_line":"The ``vip_sg_id`` parameter is also added to the reply of the GET method."},{"line_number":77,"context_line":""},{"line_number":78,"context_line":""},{"line_number":79,"context_line":"Security impact"},{"line_number":80,"context_line":"---------------"},{"line_number":81,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"a8120a63_76ddd137","line":78,"in_reply_to":"aaf2c79c_d6121fb6","updated":"2024-05-15 11:16:08.000000000","message":"Done","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},"change_message_id":"bf2a4e322f07170791e070977787d5487a815cac","unresolved":true,"context_lines":[{"line_number":85,"context_line":""},{"line_number":86,"context_line":"It\u0027s up to the users to add rules to allow incoming traffic to the load"},{"line_number":87,"context_line":"balancer."},{"line_number":88,"context_line":""},{"line_number":89,"context_line":""},{"line_number":90,"context_line":"Notifications impact"},{"line_number":91,"context_line":"--------------------"}],"source_content_type":"text/x-rst","patch_set":1,"id":"864331ea_09a96c8d","line":88,"updated":"2024-04-09 15:56:12.000000000","message":"This should be gated by an RBAC policy so that access to this feature can be limited by the operator.","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"06403594e188db25db1e579a3357cc2756695a40","unresolved":false,"context_lines":[{"line_number":85,"context_line":""},{"line_number":86,"context_line":"It\u0027s up to the users to add rules to allow incoming traffic to the load"},{"line_number":87,"context_line":"balancer."},{"line_number":88,"context_line":""},{"line_number":89,"context_line":""},{"line_number":90,"context_line":"Notifications impact"},{"line_number":91,"context_line":"--------------------"}],"source_content_type":"text/x-rst","patch_set":1,"id":"701852ef_c67070a1","line":88,"in_reply_to":"864331ea_09a96c8d","updated":"2024-05-15 11:16:08.000000000","message":"Done","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"d4d48e764d7f7e66e11043c712935f6b64bbff77","unresolved":true,"context_lines":[{"line_number":147,"context_line":"4. Update the api-ref and the user guide."},{"line_number":148,"context_line":"5. Add required unit and functional tests."},{"line_number":149,"context_line":"6. Add tempest tests for this feature."},{"line_number":150,"context_line":""},{"line_number":151,"context_line":""},{"line_number":152,"context_line":"Dependencies"},{"line_number":153,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"}],"source_content_type":"text/x-rst","patch_set":1,"id":"98d03a36_5bfa38df","line":150,"updated":"2024-04-05 15:39:05.000000000","message":"TODO: add support in python-octaviaclient and openstacksdk","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"06403594e188db25db1e579a3357cc2756695a40","unresolved":false,"context_lines":[{"line_number":147,"context_line":"4. Update the api-ref and the user guide."},{"line_number":148,"context_line":"5. Add required unit and functional tests."},{"line_number":149,"context_line":"6. Add tempest tests for this feature."},{"line_number":150,"context_line":""},{"line_number":151,"context_line":""},{"line_number":152,"context_line":"Dependencies"},{"line_number":153,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"}],"source_content_type":"text/x-rst","patch_set":1,"id":"b7305c8f_7629750c","line":150,"in_reply_to":"98d03a36_5bfa38df","updated":"2024-05-15 11:16:08.000000000","message":"Done","commit_id":"fd8ae2581cb55bdd47889b0d08c77fc68d62876b"},{"author":{"_account_id":34429,"name":"Tom Weininger","email":"dienste@weinimo.de","username":"tweining"},"change_message_id":"6b21b3421b5a4cd97aeb5aa7dd8a233aa1a1a6be","unresolved":true,"context_lines":[{"line_number":79,"context_line":"Groups)."},{"line_number":80,"context_line":""},{"line_number":81,"context_line":"If the parameter is set, Octavia checks that the security groups exist and that"},{"line_number":82,"context_line":"the user is allowed to use then, then Octavia creates new VIPSecurityGroup"},{"line_number":83,"context_line":"objects with these new parameters."},{"line_number":84,"context_line":""},{"line_number":85,"context_line":"The PUT /v2/lbaas/loadbalancers endpoint is also updated, allowing to update"}],"source_content_type":"text/x-rst","patch_set":2,"id":"bfd3715d_76daa977","line":82,"range":{"start_line":82,"start_character":27,"end_line":82,"end_character":31},"updated":"2024-05-21 15:24:21.000000000","message":"them","commit_id":"0d955c5969e7ff9b86f93798bd999b7657f0b35b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"abe1ac72c316805750bfd5ba24375fa844c7f894","unresolved":false,"context_lines":[{"line_number":79,"context_line":"Groups)."},{"line_number":80,"context_line":""},{"line_number":81,"context_line":"If the parameter is set, Octavia checks that the security groups exist and that"},{"line_number":82,"context_line":"the user is allowed to use then, then Octavia creates new VIPSecurityGroup"},{"line_number":83,"context_line":"objects with these new parameters."},{"line_number":84,"context_line":""},{"line_number":85,"context_line":"The PUT /v2/lbaas/loadbalancers endpoint is also updated, allowing to update"}],"source_content_type":"text/x-rst","patch_set":2,"id":"049a296c_56d3bce0","line":82,"range":{"start_line":82,"start_character":27,"end_line":82,"end_character":31},"in_reply_to":"bfd3715d_76daa977","updated":"2024-06-26 11:15:45.000000000","message":"Done","commit_id":"0d955c5969e7ff9b86f93798bd999b7657f0b35b"},{"author":{"_account_id":30054,"name":"Grégoire Unbekandt","email":"gregoire.unbekandt@gmail.com","username":"yebinama"},"change_message_id":"5df677fe84cf96f4f76868cbf36a833afc0b73f3","unresolved":true,"context_lines":[{"line_number":82,"context_line":"the user is allowed to use then, then Octavia creates new VIPSecurityGroup"},{"line_number":83,"context_line":"objects with these new parameters."},{"line_number":84,"context_line":""},{"line_number":85,"context_line":"The PUT /v2/lbaas/loadbalancers endpoint is also updated, allowing to update"},{"line_number":86,"context_line":"the list of Security Groups."},{"line_number":87,"context_line":""},{"line_number":88,"context_line":"The ``vip_sg_ids`` parameter is also added to the reply of the GET method."}],"source_content_type":"text/x-rst","patch_set":2,"id":"3cfcb442_d9550d67","line":85,"updated":"2024-05-16 16:12:30.000000000","message":"What will happen if the user remove all security groups from the list? Will it be allowed?","commit_id":"0d955c5969e7ff9b86f93798bd999b7657f0b35b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"abe1ac72c316805750bfd5ba24375fa844c7f894","unresolved":true,"context_lines":[{"line_number":82,"context_line":"the user is allowed to use then, then Octavia creates new VIPSecurityGroup"},{"line_number":83,"context_line":"objects with these new parameters."},{"line_number":84,"context_line":""},{"line_number":85,"context_line":"The PUT /v2/lbaas/loadbalancers endpoint is also updated, allowing to update"},{"line_number":86,"context_line":"the list of Security Groups."},{"line_number":87,"context_line":""},{"line_number":88,"context_line":"The ``vip_sg_ids`` parameter is also added to the reply of the GET method."}],"source_content_type":"text/x-rst","patch_set":2,"id":"90960c6d_8ba8ddf8","line":85,"in_reply_to":"3cfcb442_d9550d67","updated":"2024-06-26 11:15:45.000000000","message":"when the list of SGs is empty, octavia switches back to the default behavior: it manages the SG rules\nif you want to remove a SG from the list but not let octavia manages the SGs, it\u0027s better to keep at least one empty SG in the list.","commit_id":"0d955c5969e7ff9b86f93798bd999b7657f0b35b"},{"author":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},"change_message_id":"0a9eea05379964b20976b52a59ca1d84e275b5ef","unresolved":true,"context_lines":[{"line_number":42,"context_line":"security group."},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"No rules based on the port or the protocol of the listeners would be managed by"},{"line_number":45,"context_line":"Octavia, for each new listener, the user would have to add their own rules to"},{"line_number":46,"context_line":"these security groups."},{"line_number":47,"context_line":""},{"line_number":48,"context_line":""},{"line_number":49,"context_line":"Alternatives"}],"source_content_type":"text/x-rst","patch_set":3,"id":"15cde2c6_c1a59afa","line":46,"range":{"start_line":45,"start_character":32,"end_line":46,"end_character":22},"updated":"2024-07-10 03:01:15.000000000","message":"So.. This seems like a support issue. What happens when users open internal use ports to the internet? I.e. they open the VRRP port to 0.0.0.0?\nIt seems like we would have to add tests that validate we don\u0027t have any ports listening on the VIP IP.","commit_id":"5e6590d3270e4b2ba9752e522544456c9a9f014b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"09bc658c3d50d2cf59ff3c77afcaba7bf22abfba","unresolved":true,"context_lines":[{"line_number":42,"context_line":"security group."},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"No rules based on the port or the protocol of the listeners would be managed by"},{"line_number":45,"context_line":"Octavia, for each new listener, the user would have to add their own rules to"},{"line_number":46,"context_line":"these security groups."},{"line_number":47,"context_line":""},{"line_number":48,"context_line":""},{"line_number":49,"context_line":"Alternatives"}],"source_content_type":"text/x-rst","patch_set":3,"id":"43854e85_d34d2fee","line":46,"range":{"start_line":45,"start_character":32,"end_line":46,"end_character":22},"in_reply_to":"003e2124_84209322","updated":"2024-07-10 09:54:20.000000000","message":"BTW the `nc \u003cvrrp_ip\u003e 1025` should be addressed in a bug fix, the internal security groups should use the management subnet CIDR and not 0.0.0.0/0","commit_id":"5e6590d3270e4b2ba9752e522544456c9a9f014b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"452a4cce133ac3efeef3f627afa7ecda2c06063e","unresolved":true,"context_lines":[{"line_number":42,"context_line":"security group."},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"No rules based on the port or the protocol of the listeners would be managed by"},{"line_number":45,"context_line":"Octavia, for each new listener, the user would have to add their own rules to"},{"line_number":46,"context_line":"these security groups."},{"line_number":47,"context_line":""},{"line_number":48,"context_line":""},{"line_number":49,"context_line":"Alternatives"}],"source_content_type":"text/x-rst","patch_set":3,"id":"003e2124_84209322","line":46,"range":{"start_line":45,"start_character":32,"end_line":46,"end_character":22},"in_reply_to":"15cde2c6_c1a59afa","updated":"2024-07-10 09:52:50.000000000","message":"internal ports are not exposed on the VIP address but on the VRRP address.\n\nthe \"Default\" SG already includes a SG rules for the haproxy peer port:\nhttps://opendev.org/openstack/octavia/src/branch/master/octavia/network/drivers/neutron/allowed_address_pairs.py#L186-L187\n\nsame for VRRP\nhttps://opendev.org/openstack/octavia/src/branch/master/octavia/network/drivers/neutron/allowed_address_pairs.py#L243-L247\n\nthose ports are already opened to the external network but on the VRRP address (`nc \u003cvrrp_ip\u003e 1025` works from any hosts)\n\nIMHO this spec/feature doesn\u0027t impact the behavior of the internal ports.","commit_id":"5e6590d3270e4b2ba9752e522544456c9a9f014b"},{"author":{"_account_id":34429,"name":"Tom Weininger","email":"dienste@weinimo.de","username":"tweining"},"change_message_id":"0a984c2bd9bc9a6ce78d03aa9d6a306a630c1b13","unresolved":true,"context_lines":[{"line_number":85,"context_line":"The PUT /v2/lbaas/loadbalancers endpoint is also updated, allowing to update"},{"line_number":86,"context_line":"the list of Security Groups."},{"line_number":87,"context_line":""},{"line_number":88,"context_line":"The ``vip_sg_ids`` parameter is also added to the reply of the GET method."},{"line_number":89,"context_line":""},{"line_number":90,"context_line":"Using ``vip_sg_ids`` is incompatible with some existing features in Octavia,"},{"line_number":91,"context_line":"like ``allowed_cidrs`` in the listeners. Setting ``allowed_cidrs`` in a load"}],"source_content_type":"text/x-rst","patch_set":3,"id":"4c4a8b06_d6637ce0","line":88,"range":{"start_line":88,"start_character":50,"end_line":88,"end_character":73},"updated":"2024-07-01 09:53:53.000000000","message":"```suggestion\nThe ``vip_sg_ids`` parameter is also added to the response of the GET, POST and PUT methods.\n```","commit_id":"5e6590d3270e4b2ba9752e522544456c9a9f014b"},{"author":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},"change_message_id":"0a9eea05379964b20976b52a59ca1d84e275b5ef","unresolved":true,"context_lines":[{"line_number":92,"context_line":"balancer with ``vip_sg_ids`` should be denied, updating the ``vip_sg_ids`` of a"},{"line_number":93,"context_line":"load balancer that includes listeners with ``allowed_cidrs`` too."},{"line_number":94,"context_line":""},{"line_number":95,"context_line":"``vip_sg_ids`` is also incompatible with SR-IOV enabled load balancers."},{"line_number":96,"context_line":""},{"line_number":97,"context_line":""},{"line_number":98,"context_line":"Security impact"}],"source_content_type":"text/x-rst","patch_set":3,"id":"d72df5c0_0526e558","line":95,"updated":"2024-07-10 03:01:15.000000000","message":"This also won\u0027t work for provider drivers, we should mention this.","commit_id":"5e6590d3270e4b2ba9752e522544456c9a9f014b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"452a4cce133ac3efeef3f627afa7ecda2c06063e","unresolved":true,"context_lines":[{"line_number":92,"context_line":"balancer with ``vip_sg_ids`` should be denied, updating the ``vip_sg_ids`` of a"},{"line_number":93,"context_line":"load balancer that includes listeners with ``allowed_cidrs`` too."},{"line_number":94,"context_line":""},{"line_number":95,"context_line":"``vip_sg_ids`` is also incompatible with SR-IOV enabled load balancers."},{"line_number":96,"context_line":""},{"line_number":97,"context_line":""},{"line_number":98,"context_line":"Security impact"}],"source_content_type":"text/x-rst","patch_set":3,"id":"d7f1b12c_9d561945","line":95,"in_reply_to":"d72df5c0_0526e558","updated":"2024-07-10 09:52:50.000000000","message":"I will update it","commit_id":"5e6590d3270e4b2ba9752e522544456c9a9f014b"},{"author":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},"change_message_id":"0a9eea05379964b20976b52a59ca1d84e275b5ef","unresolved":true,"context_lines":[{"line_number":98,"context_line":"Security impact"},{"line_number":99,"context_line":"---------------"},{"line_number":100,"context_line":""},{"line_number":101,"context_line":"There\u0027s no security impact, the security of newly created load balancers and"},{"line_number":102,"context_line":"listeners would be more restricted with this feature, because less rules are"},{"line_number":103,"context_line":"pushed to the security groups."},{"line_number":104,"context_line":""}],"source_content_type":"text/x-rst","patch_set":3,"id":"8d413239_98ae5d38","line":101,"updated":"2024-07-10 03:01:15.000000000","message":"This is not accurate. The Amphora historically have been a highly protected \"black box\". This change means users can shoot themselves in the foot either by not allowing traffic that is needed, but also by exposing components of the amphora itself.\nIt also means operators will not have as much visibility into the security stance of the amphora instances. It shifts the security stance from the operator knowing what is open to the end user being able to do whatever they want. I think the policy hook helps with this, but it\u0027s not ideal from a security stance.","commit_id":"5e6590d3270e4b2ba9752e522544456c9a9f014b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"452a4cce133ac3efeef3f627afa7ecda2c06063e","unresolved":true,"context_lines":[{"line_number":98,"context_line":"Security impact"},{"line_number":99,"context_line":"---------------"},{"line_number":100,"context_line":""},{"line_number":101,"context_line":"There\u0027s no security impact, the security of newly created load balancers and"},{"line_number":102,"context_line":"listeners would be more restricted with this feature, because less rules are"},{"line_number":103,"context_line":"pushed to the security groups."},{"line_number":104,"context_line":""}],"source_content_type":"text/x-rst","patch_set":3,"id":"37e26696_87058fc0","line":101,"in_reply_to":"8d413239_98ae5d38","updated":"2024-07-10 09:52:50.000000000","message":"ack, I\u0027ll mention it","commit_id":"5e6590d3270e4b2ba9752e522544456c9a9f014b"},{"author":{"_account_id":34429,"name":"Tom Weininger","email":"dienste@weinimo.de","username":"tweining"},"change_message_id":"0a984c2bd9bc9a6ce78d03aa9d6a306a630c1b13","unresolved":true,"context_lines":[{"line_number":119,"context_line":"---------------------"},{"line_number":120,"context_line":""},{"line_number":121,"context_line":"The impact for the end user is that they are responsible for allowing the"},{"line_number":122,"context_line":"incomming traffic to their load balancer. The creating of a new listener would"},{"line_number":123,"context_line":"request at least 2 API calls, one for creating the listener in Octavia, one for"},{"line_number":124,"context_line":"adding a new security group rule to their Neutron security group."},{"line_number":125,"context_line":""}],"source_content_type":"text/x-rst","patch_set":3,"id":"417f9621_43073d98","line":122,"range":{"start_line":122,"start_character":0,"end_line":122,"end_character":9},"updated":"2024-07-01 09:53:53.000000000","message":"```suggestion\nincoming traffic to their load balancer. The creating of a new listener would\n```","commit_id":"5e6590d3270e4b2ba9752e522544456c9a9f014b"},{"author":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},"change_message_id":"0a9eea05379964b20976b52a59ca1d84e275b5ef","unresolved":true,"context_lines":[{"line_number":140,"context_line":"Developer impact"},{"line_number":141,"context_line":"----------------"},{"line_number":142,"context_line":""},{"line_number":143,"context_line":"Impact is minimal, a few changes in the API and in the DB, only a few new"},{"line_number":144,"context_line":"conditionals in the allowed_address_pairs module."},{"line_number":145,"context_line":""},{"line_number":146,"context_line":"It could have a more significant impact if this feature is added to the"}],"source_content_type":"text/x-rst","patch_set":3,"id":"819882e4_d53ac3c9","line":143,"updated":"2024-07-10 03:01:15.000000000","message":"It adds a number of validation conditionals to the API code base. I.e. mixing CIDRs, SRIOV, provider drivers, etc. must all be checked to see if they are compatible with this change.","commit_id":"5e6590d3270e4b2ba9752e522544456c9a9f014b"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"452a4cce133ac3efeef3f627afa7ecda2c06063e","unresolved":true,"context_lines":[{"line_number":140,"context_line":"Developer impact"},{"line_number":141,"context_line":"----------------"},{"line_number":142,"context_line":""},{"line_number":143,"context_line":"Impact is minimal, a few changes in the API and in the DB, only a few new"},{"line_number":144,"context_line":"conditionals in the allowed_address_pairs module."},{"line_number":145,"context_line":""},{"line_number":146,"context_line":"It could have a more significant impact if this feature is added to the"}],"source_content_type":"text/x-rst","patch_set":3,"id":"fd9af6d9_706644c1","line":143,"in_reply_to":"819882e4_d53ac3c9","updated":"2024-07-10 09:52:50.000000000","message":"right, I\u0027ll detail the changes in the API","commit_id":"5e6590d3270e4b2ba9752e522544456c9a9f014b"},{"author":{"_account_id":34429,"name":"Tom Weininger","email":"dienste@weinimo.de","username":"tweining"},"change_message_id":"9eb8f03d87d076095b6939f935172e70275e3e98","unresolved":true,"context_lines":[{"line_number":68,"context_line":""},{"line_number":69,"context_line":"* ``sg_id``: the UUID of a Security Group"},{"line_number":70,"context_line":""},{"line_number":71,"context_line":"A load balancer (identified by its ID) or a VIP are linked to one or more"},{"line_number":72,"context_line":"security groups."},{"line_number":73,"context_line":""},{"line_number":74,"context_line":"It also requires an update of the data model in octavia-lib."},{"line_number":75,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"596a71ea_08e2c594","line":72,"range":{"start_line":71,"start_character":52,"end_line":72,"end_character":16},"updated":"2024-07-31 10:32:05.000000000","message":"So the Loadbalancer model changes as well and gets a `vip_security_groups` (or so) column that forms the relationship, right?","commit_id":"e757f1bfa7d17153e904ce2fceddf121f0ad0aa7"},{"author":{"_account_id":34429,"name":"Tom Weininger","email":"dienste@weinimo.de","username":"tweining"},"change_message_id":"9eb8f03d87d076095b6939f935172e70275e3e98","unresolved":true,"context_lines":[{"line_number":82,"context_line":"Groups)."},{"line_number":83,"context_line":""},{"line_number":84,"context_line":"If the parameter is set, Octavia checks that the security groups exist and that"},{"line_number":85,"context_line":"the user is allowed to use them, then Octavia creates new VIPSecurityGroup"},{"line_number":86,"context_line":"objects with these new parameters."},{"line_number":87,"context_line":""},{"line_number":88,"context_line":"The PUT /v2/lbaas/loadbalancers endpoint is also updated, allowing to update"}],"source_content_type":"text/x-rst","patch_set":4,"id":"8c187a14_7ca2cc8a","line":85,"range":{"start_line":85,"start_character":58,"end_line":85,"end_character":74},"updated":"2024-07-31 10:32:05.000000000","message":"nit, should probably be formated as monospace text.","commit_id":"e757f1bfa7d17153e904ce2fceddf121f0ad0aa7"}],"specs/version15.0/custom-security-groups-for-VIP-ports.rst":[{"author":{"_account_id":34429,"name":"Tom Weininger","email":"dienste@weinimo.de","username":"tweining"},"change_message_id":"e626720a30d6cddc93dcdcd02d38e4f82b121369","unresolved":true,"context_lines":[{"line_number":68,"context_line":""},{"line_number":69,"context_line":"* ``sg_id``: the UUID of a Security Group"},{"line_number":70,"context_line":""},{"line_number":71,"context_line":"A load balancer (identified by its ID) or a VIP are linked to one or more"},{"line_number":72,"context_line":"security groups."},{"line_number":73,"context_line":""},{"line_number":74,"context_line":"It also requires an update of the data model in octavia-lib."},{"line_number":75,"context_line":""}],"source_content_type":"text/x-rst","patch_set":5,"id":"84ee5277_67cef08c","line":72,"range":{"start_line":71,"start_character":62,"end_line":72,"end_character":16},"updated":"2024-08-07 10:14:01.000000000","message":"Further up in line 41ff. you describe there would be at least two security groups if ``vip_sg_ids`` is set. What if it hasn\u0027t been set? Would there be zero security groups then?","commit_id":"8260d13fc32abc13242518faf2756fef23464acc"},{"author":{"_account_id":34429,"name":"Tom Weininger","email":"dienste@weinimo.de","username":"tweining"},"change_message_id":"3f80123a605b75064bf9b7f0bc93058ffacbdd2b","unresolved":false,"context_lines":[{"line_number":68,"context_line":""},{"line_number":69,"context_line":"* ``sg_id``: the UUID of a Security Group"},{"line_number":70,"context_line":""},{"line_number":71,"context_line":"A load balancer (identified by its ID) or a VIP are linked to one or more"},{"line_number":72,"context_line":"security groups."},{"line_number":73,"context_line":""},{"line_number":74,"context_line":"It also requires an update of the data model in octavia-lib."},{"line_number":75,"context_line":""}],"source_content_type":"text/x-rst","patch_set":5,"id":"1727f31f_feec81bb","line":72,"range":{"start_line":71,"start_character":62,"end_line":72,"end_character":16},"in_reply_to":"28ca8ad1_be0b70a6","updated":"2024-08-12 08:52:52.000000000","message":"Thanks. It really helps to distinguish between those security groups.","commit_id":"8260d13fc32abc13242518faf2756fef23464acc"},{"author":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"change_message_id":"238f590f750c3bf356fc69fa95844ed01be0d332","unresolved":true,"context_lines":[{"line_number":68,"context_line":""},{"line_number":69,"context_line":"* ``sg_id``: the UUID of a Security Group"},{"line_number":70,"context_line":""},{"line_number":71,"context_line":"A load balancer (identified by its ID) or a VIP are linked to one or more"},{"line_number":72,"context_line":"security groups."},{"line_number":73,"context_line":""},{"line_number":74,"context_line":"It also requires an update of the data model in octavia-lib."},{"line_number":75,"context_line":""}],"source_content_type":"text/x-rst","patch_set":5,"id":"28ca8ad1_be0b70a6","line":72,"range":{"start_line":71,"start_character":62,"end_line":72,"end_character":16},"in_reply_to":"84ee5277_67cef08c","updated":"2024-08-09 13:50:00.000000000","message":"I\u0027ve just updated the spec, I tried to clarify that by using 2 different terms:\n- Custom Security Groups: provided by the user\n- Octavia-managed Security Group: created and managed by Octavia","commit_id":"8260d13fc32abc13242518faf2756fef23464acc"}]}
