)]}'
{"id":"openstack%2Fopenstack-ansible-haproxy_server~1004591","triplet_id":"openstack%2Fopenstack-ansible-haproxy_server~master~Idc75b7eea9be504dafad50cf526e6d4326619360","project":"openstack/openstack-ansible-haproxy_server","branch":"master","hashtags":[],"change_id":"Idc75b7eea9be504dafad50cf526e6d4326619360","subject":"Ensure that TLS termination is allowed for TCP frontends","status":"NEW","created":"2026-09-08 13:24:45.000000000","updated":"2026-09-08 16:11:15.000000000","submit_type":"MERGE_IF_NECESSARY","mergeable":true,"submittable":false,"total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"5d1489a227e02e29a004e92fee580a7c364540cb","_number":1004591,"virtual_id_number":1004591,"owner":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"tag":"autogenerated:zuul:check","value":1,"date":"2026-09-08 16:11:15.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Backport-Candidate":{"all":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Not A Backport Candidate"," 0":"Backport Review Needed","+1":"Proposed Backport"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-09-08 16:11:15.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"cf701c10ba1a57144be118f2fa4d76a53f53fbe5","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"date":"2026-09-08 13:24:45.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"7aa3cee52e429758177b9d65d83ab7cb7c212273","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"date":"2026-09-08 13:26:59.000000000","message":"Patch Set 2: Published edit on patch set 1.","accounts_in_message":[],"_revision_number":2},{"id":"5d1489a227e02e29a004e92fee580a7c364540cb","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-08 16:11:15.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/959ed96151c542368dcef639264f26a4\n\n- openstack-ansible-linters-ubuntu-noble https://zuul.opendev.org/t/openstack/build/545ed00198074c33afefa97fc5dcdff5 : SUCCESS in 12m 30s\n- openstack-ansible-tox-molecule-debian-trixie https://zuul.opendev.org/t/openstack/build/44c4eb54abd44a31871edb0bcdd3407a : SUCCESS in 7m 05s\n- openstack-ansible-tox-molecule-ubuntu-noble https://zuul.opendev.org/t/openstack/build/3cfa69de705f4e39bd7bbd0f06e5aaa6 : SUCCESS in 7m 18s\n- openstack-ansible-tox-molecule-ubuntu-resolute https://zuul.opendev.org/t/openstack/build/00e27c1596644f1b9e56811dd67ad176 : SUCCESS in 12m 45s\n- openstack-ansible-tox-molecule-centos-10-stream https://zuul.opendev.org/t/openstack/build/dc145b7cc4c340c19110b01c3c0fdb21 : SUCCESS in 13m 57s\n- openstack-ansible-tox-molecule-rockylinux-10 https://zuul.opendev.org/t/openstack/build/1b90fe0585be4648838da4724e034868 : FAILURE in 6m 20s (non-voting)\n- openstack-ansible-deploy-infra_lxc-centos-10-stream https://zuul.opendev.org/t/openstack/build/7e03fe739efb4bc2b7b6bd8a4fd709c9 : SUCCESS in 1h 27m 32s\n- openstack-ansible-deploy-infra_lxc-debian-trixie https://zuul.opendev.org/t/openstack/build/fc9a25a995eb4440bf33334223cfbfe6 : SUCCESS in 1h 09m 33s\n- openstack-ansible-deploy-infra_lxc-rockylinux-10 https://zuul.opendev.org/t/openstack/build/e6da99f9f15849e7b89584ee540b2cd4 : SUCCESS in 1h 28m 15s\n- openstack-ansible-deploy-infra_lxc_tls-rockylinux-10 https://zuul.opendev.org/t/openstack/build/9562e96173554e72b07172d61504f5cb : SUCCESS in 1h 06m 16s\n- openstack-ansible-deploy-infra_lxc-ubuntu-noble https://zuul.opendev.org/t/openstack/build/a501e0372b7b4219a053f4c8d67d3a01 : SUCCESS in 1h 03m 07s\n- openstack-ansible-deploy-infra_lxc-ubuntu-resolute https://zuul.opendev.org/t/openstack/build/acabe12084d24f63ab7a12df1655f92e : SUCCESS in 1h 50m 19s\n- openstack-ansible-deploy-infra_lxc_stepca-ubuntu-noble https://zuul.opendev.org/t/openstack/build/be441b3f8c6a45e0b83f19fc4fb9906a : SUCCESS in 1h 45m 40s\n- openstack-ansible-deploy-infra_lxc_tls-ubuntu-noble https://zuul.opendev.org/t/openstack/build/0814a298aa484630868842855807fdca : SUCCESS in 1h 46m 48s\n- openstack-ansible-deploy-aio_metal-centos-10-stream https://zuul.opendev.org/t/openstack/build/74f78f62ef7f4ae8b3c54fc95bdd14d7 : SUCCESS in 1h 26m 20s\n- openstack-ansible-deploy-aio_metal-debian-trixie https://zuul.opendev.org/t/openstack/build/76f1ff62766f405899d280eb476f32d1 : SUCCESS in 1h 25m 16s\n- openstack-ansible-deploy-aio_metal-rockylinux-10 https://zuul.opendev.org/t/openstack/build/90d51bcde0384f7890aff61650c00e50 : SUCCESS in 56m 32s\n- openstack-ansible-deploy-aio_metal_tls-rockylinux-10 https://zuul.opendev.org/t/openstack/build/40f2066b3d074dd9b50d7236f6ad0039 : SUCCESS in 1h 13m 28s\n- openstack-ansible-deploy-aio_metal-ubuntu-noble https://zuul.opendev.org/t/openstack/build/c64a5e1986f349bcab8b1fb7532b13ce : SUCCESS in 48m 18s\n- openstack-ansible-deploy-aio_metal-ubuntu-resolute https://zuul.opendev.org/t/openstack/build/1589e24706304c69b3d7c90bc3d30e6e : SUCCESS in 1h 19m 15s\n- openstack-ansible-deploy-aio_metal_tls-ubuntu-noble https://zuul.opendev.org/t/openstack/build/fbd674c6bf724837a354fb11e38628d5 : SUCCESS in 49m 28s\n- openstack-ansible-upgrade-aio_metal-rockylinux-10 https://zuul.opendev.org/t/openstack/build/4fd2f4648eb94f5e8c2a7a03db130482 : SUCCESS in 1h 23m 04s\n- openstack-ansible-upgrade-aio_metal-ubuntu-noble https://zuul.opendev.org/t/openstack/build/de6fc808083c450fa5317dde5a9d34f9 : SUCCESS in 1h 17m 27s\n- openstack-ansible-upgrade-aio_metal_tls-ubuntu-noble https://zuul.opendev.org/t/openstack/build/6737cb0162544b12889a54978281ada6 : SUCCESS in 2h 36m 05s\n- openstack-ansible-upgrade-infra_lxc-ubuntu-noble https://zuul.opendev.org/t/openstack/build/42b120931f854518bd8d0f92d5e9835e : SUCCESS in 2h 28m 29s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/86bbc18d67eb42eda76eb1b3ba6d4c30 : SUCCESS in 4m 11s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/8c8b36b9fa454baea8c5f76773c8a31e : SUCCESS in 4m 00s","accounts_in_message":[],"_revision_number":2}],"current_revision_number":2,"current_revision":"617ffc7cbbd5b8bcbc1b4d97453fdec67264927e","revisions":{"a3564e16ef1313177ed4c1661f65fe4b9f25ee40":{"kind":"REWORK","_number":1,"created":"2026-09-08 13:24:45.000000000","uploader":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"ref":"refs/changes/91/1004591/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-ansible-haproxy_server","ref":"refs/changes/91/1004591/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-ansible-haproxy_server refs/changes/91/1004591/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-ansible-haproxy_server refs/changes/91/1004591/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-ansible-haproxy_server refs/changes/91/1004591/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-ansible-haproxy_server refs/changes/91/1004591/1"}}},"commit":{"parents":[{"commit":"58909b016c717b3b79716ed275c51576c5731050","subject":"haproxy_server: set X-Forwarded-Proto instead of appending","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-haproxy_server/commit/58909b016c717b3b79716ed275c51576c5731050"}]}],"author":{"name":"Dmitriy Rabotyagov","email":"dmitriy.rabotyagov@cleura.com","date":"2026-09-08 13:24:38.000000000","tz":120},"committer":{"name":"Dmitriy Rabotyagov","email":"dmitriy.rabotyagov@cleura.com","date":"2026-09-08 13:24:38.000000000","tz":120},"subject":"Ensure that TLS termination is allowed for TCP frontends","message":"Ensure that TLS termination is allowed for TCP frontends\n\nThere are usecases where TLS termination for TCP is beneficial and\nrequired by workloads.\nAnd there is no good reason not to allow such configurations to exist,\nas HAProxy is capable to terminate and re-establish TLS connection\nwhenever needed.\n\nThe major fallback of that, is that source IP of the connection would\nbe set to HAProxy server, unless transparent proxy is configured\nor proxy protocol is enabled, which can be configured\nthrough `haproxy_backend_server_options`.\n\nChange-Id: Idc75b7eea9be504dafad50cf526e6d4326619360\nSigned-off-by: Dmitriy Rabotyagov \u003cdmitriy.rabotyagov@cleura.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-haproxy_server/commit/a3564e16ef1313177ed4c1661f65fe4b9f25ee40"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-haproxy_server/commit/a3564e16ef1313177ed4c1661f65fe4b9f25ee40"}]},"branch":"refs/heads/master"},"617ffc7cbbd5b8bcbc1b4d97453fdec67264927e":{"kind":"REWORK","_number":2,"created":"2026-09-08 13:26:59.000000000","uploader":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"ref":"refs/changes/91/1004591/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-ansible-haproxy_server","ref":"refs/changes/91/1004591/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-ansible-haproxy_server refs/changes/91/1004591/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-ansible-haproxy_server refs/changes/91/1004591/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-ansible-haproxy_server refs/changes/91/1004591/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-ansible-haproxy_server refs/changes/91/1004591/2"}}},"commit":{"parents":[{"commit":"58909b016c717b3b79716ed275c51576c5731050","subject":"haproxy_server: set X-Forwarded-Proto instead of appending","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-haproxy_server/commit/58909b016c717b3b79716ed275c51576c5731050"}]}],"author":{"name":"Dmitriy Rabotyagov","email":"dmitriy.rabotyagov@cleura.com","date":"2026-09-08 13:24:38.000000000","tz":120},"committer":{"name":"Dmitriy Rabotyagov","email":"dmitriy.rabotyagov@cleura.com","date":"2026-09-08 13:26:59.000000000","tz":0},"subject":"Ensure that TLS termination is allowed for TCP frontends","message":"Ensure that TLS termination is allowed for TCP frontends\n\nThere are usecases where TLS termination for TCP is beneficial and\nrequired by workloads.\nAnd there is no good reason not to allow such configurations to exist,\nas HAProxy is capable to terminate and re-establish TLS connection\nwhenever needed.\n\nThe major fallback of that, is that source IP of the connection would\nbe set to HAProxy server, unless transparent proxy is configured\nor proxy protocol is enabled, which can be configured\nthrough `haproxy_backend_server_options`.\n\nChange-Id: Idc75b7eea9be504dafad50cf526e6d4326619360\nSigned-off-by: Dmitriy Rabotyagov \u003cdmitriy.rabotyagov@cleura.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-haproxy_server/commit/617ffc7cbbd5b8bcbc1b4d97453fdec67264927e"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-haproxy_server/commit/617ffc7cbbd5b8bcbc1b4d97453fdec67264927e"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY"},{"label":"Workflow","status":"MAY"},{"label":"Backport-Candidate","status":"MAY"}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Backport-Candidate","description":"Backport candidate status","status":"NOT_APPLICABLE","is_legacy":false,"applicability_expression_result":{"fulfilled":false,"status":"FAIL"},"submittability_expression_result":{"expression":"is:true","fulfilled":true,"status":"NOT_EVALUATED","passing_atoms":[],"failing_atoms":[],"atom_explanations":{}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
