)]}'
{"id":"openstack%2Fopenstack-ansible-os_keystone~666428","triplet_id":"openstack%2Fopenstack-ansible-os_keystone~master~Ide611fd3d88e352367220f05dbcf4186ac20319f","project":"openstack/openstack-ansible-os_keystone","branch":"master","topic":"bug/1833414","hashtags":[],"change_id":"Ide611fd3d88e352367220f05dbcf4186ac20319f","subject":"Fix loss of fernet and credential keys during Rocky to Stein upgrade","status":"MERGED","created":"2019-06-19 19:44:06.000000000","updated":"2019-06-24 19:26:59.000000000","submitted":"2019-06-24 19:06:44.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":8,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"666428-1561403204679-663f6094","meta_rev_id":"c3395367b1f28793264be94d090ea323a0e67b9e","_number":666428,"virtual_id_number":666428,"owner":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":17799,"name":"Logan V","email":"logan2211@gmail.com","username":"Logan2211"},{"value":0,"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},{"value":2,"date":"2019-06-24 19:06:44.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":17068,"name":"Jean-Philippe Evrard","email":"openstack@a.spamming.party","username":"evrardjp"},{"value":0,"date":"2019-06-24 16:10:05.000000000","_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":17799,"name":"Logan V","email":"logan2211@gmail.com","username":"Logan2211"},"all":[{"value":2,"date":"2019-06-20 16:00:00.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":17799,"name":"Logan V","email":"logan2211@gmail.com","username":"Logan2211"},{"value":2,"date":"2019-06-20 18:06:11.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":17068,"name":"Jean-Philippe Evrard","email":"openstack@a.spamming.party","username":"evrardjp"},{"value":0,"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"all":[{"value":0,"_account_id":17799,"name":"Logan V","email":"logan2211@gmail.com","username":"Logan2211"},{"value":1,"date":"2019-06-20 18:06:11.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":17068,"name":"Jean-Philippe Evrard","email":"openstack@a.spamming.party","username":"evrardjp"},{"value":0,"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Backport-Candidate":{"all":[{"value":0,"_account_id":17799,"name":"Logan V","email":"logan2211@gmail.com","username":"Logan2211"},{"value":0,"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":17068,"name":"Jean-Philippe Evrard","email":"openstack@a.spamming.party","username":"evrardjp"},{"value":0,"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"}],"values":{"-1":"Not A Backport Candidate"," 0":"Backport Review Needed","+1":"Proposed Backport"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":17068,"name":"Jean-Philippe Evrard","email":"openstack@a.spamming.party","username":"evrardjp"},{"_account_id":17799,"name":"Logan V","email":"logan2211@gmail.com","username":"Logan2211"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2019-06-20 08:05:17.000000000","updated_by":{"_account_id":17068,"name":"Jean-Philippe Evrard","email":"openstack@a.spamming.party","username":"evrardjp"},"reviewer":{"_account_id":17068,"name":"Jean-Philippe Evrard","email":"openstack@a.spamming.party","username":"evrardjp"},"state":"REVIEWER"},{"updated":"2019-06-20 16:00:00.000000000","updated_by":{"_account_id":17799,"name":"Logan V","email":"logan2211@gmail.com","username":"Logan2211"},"reviewer":{"_account_id":17799,"name":"Logan V","email":"logan2211@gmail.com","username":"Logan2211"},"state":"REVIEWER"},{"updated":"2019-06-20 18:06:11.000000000","updated_by":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"reviewer":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"state":"REVIEWER"},{"updated":"2019-06-24 19:06:44.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"9272a3fc7baea3ba139e091ab9d7912c7639eccf","author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"date":"2019-06-19 19:44:06.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"dc24c64a0d02006cd9f9736495bd687f48daba31","author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"date":"2019-06-19 19:47:09.000000000","message":"Patch Set 2: Commit message was updated.","accounts_in_message":[],"_revision_number":2},{"id":"eeed55bed56691de1787c79fb4ac18517055e7ee","author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"date":"2019-06-19 19:51:45.000000000","message":"Patch Set 3: Published edit on patch set 2.","accounts_in_message":[],"_revision_number":3},{"id":"1f61253e589d92e23109ebb70aa3c75ca2e11424","author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"date":"2019-06-19 20:02:24.000000000","message":"Patch Set 4: Published edit on patch set 3.","accounts_in_message":[],"_revision_number":4},{"id":"63776905561ebeb07ffaa41d8a3e4dc9ecc38848","author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"date":"2019-06-19 20:07:00.000000000","message":"Patch Set 5: Commit message was updated.","accounts_in_message":[],"_revision_number":5},{"id":"f3859557abc0674e5feba6378bbc3b96d38cf185","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-06-19 20:44:36.000000000","message":"Patch Set 5: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttp://docs.openstack.org/infra/manual/developers.html#automated-testing\n\n\n- openstack-ansible-linters http://logs.openstack.org/28/666428/5/check/openstack-ansible-linters/48aed38/ : FAILURE in 8m 52s\n- openstack-ansible-deploy-aio_metal-debian-stable http://logs.openstack.org/28/666428/5/check/openstack-ansible-deploy-aio_metal-debian-stable/eb7d850/ : FAILURE in 19m 27s\n- openstack-ansible-deploy-aio_metal-centos-7 http://logs.openstack.org/28/666428/5/check/openstack-ansible-deploy-aio_metal-centos-7/081d8d7/ : FAILURE in 24m 00s\n- openstack-ansible-deploy-aio_metal-opensuse-150 http://logs.openstack.org/28/666428/5/check/openstack-ansible-deploy-aio_metal-opensuse-150/3f020e2/ : FAILURE in 22m 37s\n- openstack-ansible-deploy-aio_metal-ubuntu-bionic http://logs.openstack.org/28/666428/5/check/openstack-ansible-deploy-aio_metal-ubuntu-bionic/7aa28ce/ : FAILURE in 17m 45s\n- openstack-ansible-deploy-aio_distro_metal-centos-7 http://logs.openstack.org/28/666428/5/check/openstack-ansible-deploy-aio_distro_metal-centos-7/231f7a1/ : FAILURE in 21m 15s\n- openstack-tox-docs http://logs.openstack.org/28/666428/5/check/openstack-tox-docs/38a1f14/html/ : SUCCESS in 3m 09s\n- openstack-ansible-uw_apache-centos-7 http://logs.openstack.org/28/666428/5/check/openstack-ansible-uw_apache-centos-7/dc2b026/ : FAILURE in 20m 00s\n- openstack-ansible-uw_apache-ubuntu-bionic http://logs.openstack.org/28/666428/5/check/openstack-ansible-uw_apache-ubuntu-bionic/cc5aac3/ : FAILURE in 7m 32s","accounts_in_message":[],"_revision_number":5},{"id":"6101f86cdeebc70bed1b1258af02c5f78aea0769","author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"date":"2019-06-19 21:14:26.000000000","message":"Patch Set 6: Published edit on patch set 5.","accounts_in_message":[],"_revision_number":6},{"id":"97083b971041ae73d710ae064280f21102b5d65e","author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"date":"2019-06-19 21:32:14.000000000","message":"Patch Set 7: Published edit on patch set 6.","accounts_in_message":[],"_revision_number":7},{"id":"5308b7219554da9dcba909af6149005061db6527","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-06-19 23:08:29.000000000","message":"Patch Set 7: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-ansible-linters http://logs.openstack.org/28/666428/7/check/openstack-ansible-linters/e4093b5/ : SUCCESS in 4m 51s\n- openstack-ansible-deploy-aio_metal-debian-stable http://logs.openstack.org/28/666428/7/check/openstack-ansible-deploy-aio_metal-debian-stable/f50a5c0/ : SUCCESS in 1h 04m 50s\n- openstack-ansible-deploy-aio_metal-centos-7 http://logs.openstack.org/28/666428/7/check/openstack-ansible-deploy-aio_metal-centos-7/21a4982/ : SUCCESS in 1h 19m 47s\n- openstack-ansible-deploy-aio_metal-opensuse-150 http://logs.openstack.org/28/666428/7/check/openstack-ansible-deploy-aio_metal-opensuse-150/00a8d96/ : SUCCESS in 1h 09m 44s\n- openstack-ansible-deploy-aio_metal-ubuntu-bionic http://logs.openstack.org/28/666428/7/check/openstack-ansible-deploy-aio_metal-ubuntu-bionic/73c90ed/ : SUCCESS in 1h 12m 27s\n- openstack-ansible-deploy-aio_distro_metal-centos-7 http://logs.openstack.org/28/666428/7/check/openstack-ansible-deploy-aio_distro_metal-centos-7/7674eff/ : SUCCESS in 58m 43s\n- openstack-tox-docs http://logs.openstack.org/28/666428/7/check/openstack-tox-docs/f1bbab5/html/ : SUCCESS in 2m 45s\n- openstack-ansible-uw_apache-centos-7 http://logs.openstack.org/28/666428/7/check/openstack-ansible-uw_apache-centos-7/2692859/ : SUCCESS in 35m 38s\n- openstack-ansible-uw_apache-ubuntu-bionic http://logs.openstack.org/28/666428/7/check/openstack-ansible-uw_apache-ubuntu-bionic/93d42cf/ : SUCCESS in 38m 03s","accounts_in_message":[],"_revision_number":7},{"id":"e6c7d95cf4af6ea2a75a749593acc068e8bd64ed","author":{"_account_id":17068,"name":"Jean-Philippe Evrard","email":"openstack@a.spamming.party","username":"evrardjp"},"date":"2019-06-20 08:05:17.000000000","message":"Patch Set 7: Code-Review+2\n\nmakes sense, with clear state.","accounts_in_message":[],"_revision_number":7},{"id":"93e21cd3cf7bb6ed0605a2a67da7e9553c4a55b7","author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"date":"2019-06-20 08:33:52.000000000","message":"Patch Set 7: Workflow-1\n\nPutting a temporary -W on this whilst I do additional tests in a live environment, further reviews welcome","accounts_in_message":[],"_revision_number":7},{"id":"7bbcfcf51e91456a8b0d5d3947b26a6cfbbef77b","author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"date":"2019-06-20 10:26:15.000000000","message":"Patch Set 7:\n\n(1 comment)\n\nI feel, that I\u0027m missing smth, but...\n\nSince we don\u0027t force people to move to symlinks (as we don\u0027t ever drop dir /etc/keystone), is there any reason to leave symlinks and care in the future about 2 possible situations? As we will be copying everything from venv every single time\n\nWon\u0027t people after migration be missing some configs (or they will be unmanageable) as we don\u0027t keep everything because of smart sources?\n\nIsn\u0027t it better to move *_key_repository to some other place by default, and cover this with upgrade script?","accounts_in_message":[],"_revision_number":7},{"id":"9ab7422c2952599dea9ceb49704565e0834675c4","author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"date":"2019-06-20 11:15:27.000000000","message":"Patch Set 7:\n\n\u003e (1 comment)\n \u003e \n \u003e I feel, that I\u0027m missing smth, but...\n \u003e \n\nMe too probably :)\n\n \u003e Since we don\u0027t force people to move to symlinks (as we don\u0027t ever\n \u003e drop dir /etc/keystone), is there any reason to leave symlinks and\n \u003e care in the future about 2 possible situations? As we will be\n \u003e copying everything from venv every single time\n \u003e \n\nI think we do force migration to a symlink now as the Stein code stands, and the current code completely deletes /etc/keystone and its contents? My /etc/keystone directory from Rocky was deleted and replaced with an empty dir in the venv and a symlink.\n\nThe data will only be copied from the venv once back to /etc/keystone, when stat.islnk is true.\n\n \u003e Won\u0027t people after migration be missing some configs (or they will\n \u003e be unmanageable) as we don\u0027t keep everything because of smart\n \u003e sources?\n\nI\u0027m not sure, do you have an example? As far as i know for a source install the only files present in /etc/keystone are the ones placed there by OSA, and the fernet keys.\n\n \u003e \n \u003e Isn\u0027t it better to move *_key_repository to some other place by\n \u003e default, and cover this with upgrade script?\n\nThere was talk about this on irc yesterday and mnaser suggested this would be a bit of an anti-pattern as every other openstack deployment puts these things in /etc/keystone.","accounts_in_message":[],"_revision_number":7},{"id":"6e3a40248cf2dfa9db797cc7a1617f4b4e40e61a","author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"date":"2019-06-20 11:16:58.000000000","message":"Patch Set 7:\n\n(1 comment)","accounts_in_message":[],"_revision_number":7},{"id":"a434a98ee3b74177027be00021ee624371a6bc81","author":{"_account_id":17799,"name":"Logan V","email":"logan2211@gmail.com","username":"Logan2211"},"date":"2019-06-20 11:55:44.000000000","message":"Patch Set 7: Code-Review-1\n\n(1 comment)\n\nThis looks like a good solution to get things back on the rails. Small fix up using synchronize module instead of shelling out would be good but lgtm otherwise.\n\nI still would be in favor of a full revert of smart sources and any config “versioning” we do on target hosts. Our configs are already versioned in config management using git, and the way smart sources is implemented created a lot of opportunity for bugs like this and serve very little purpose since the “versioning” provided can only be used in a rollback scenario with kludgy manual operations by the deployer. Ansible will never use smart sources configs, even in a rollback scenario, since it is going to template out new configs each run regardless.","accounts_in_message":[],"_revision_number":7},{"id":"91046dea8711c85ef0efd5453bb38c31afb83768","author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"date":"2019-06-20 12:08:09.000000000","message":"Patch Set 7:\n\n\u003e I think we do force migration to a symlink now as the Stein code stands, and the current code completely deletes /etc/keystone and its contents? My /etc/keystone directory from Rocky was deleted and replaced with an empty dir in the venv and a symlink.\n\nIt\u0027s true now, but with your patch this is not going to happen. So we will result in /etc/keystone being a directory for those, who migrate from Rocky, and symlink for new installations. So for migrated deployments files won\u0027t be copied from venv as well.\n\n\u003e Won\u0027t people after migration be missing some configs\n\nYep, you\u0027re right, it\u0027s not the case, as https://review.opendev.org/#/c/588960/ didn\u0027t drop any template","accounts_in_message":[],"_revision_number":7},{"id":"0e75d4963d95501acbcdcb36fa62092154525e02","author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"date":"2019-06-20 12:22:17.000000000","message":"Patch Set 7:\n\n(1 comment)","accounts_in_message":[],"_revision_number":7},{"id":"046f79a14d2433e111b6b6e25dd28789ed6eb620","author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"date":"2019-06-20 12:52:52.000000000","message":"Patch Set 7:\n\n(1 comment)","accounts_in_message":[],"_revision_number":7},{"id":"581046c6e6ca6b16b155ef3eccb43e5ad2a1455f","author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"date":"2019-06-20 13:22:30.000000000","message":"Patch Set 7:\n\n(1 comment)","accounts_in_message":[],"_revision_number":7},{"id":"38758bde68d594df896d8b7c64c12cafa4e8bbfa","author":{"_account_id":17799,"name":"Logan V","email":"logan2211@gmail.com","username":"Logan2211"},"date":"2019-06-20 14:45:05.000000000","message":"Patch Set 7:\n\n(1 comment)","accounts_in_message":[],"_revision_number":7},{"id":"d853c36902b59bf711ccc385833d51e6089394c6","author":{"_account_id":17799,"name":"Logan V","email":"logan2211@gmail.com","username":"Logan2211"},"date":"2019-06-20 14:45:48.000000000","message":"Patch Set 7:\n\n(1 comment)","accounts_in_message":[],"_revision_number":7},{"id":"fcda8bfd77dfbde008bfdcbb460c15f04da733fe","author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"date":"2019-06-20 15:48:01.000000000","message":"Patch Set 8: Published edit on patch set 7.","accounts_in_message":[],"_revision_number":8},{"id":"15058d92c3a4ccb36b40dc19200824d61e367b6b","author":{"_account_id":17799,"name":"Logan V","email":"logan2211@gmail.com","username":"Logan2211"},"date":"2019-06-20 16:00:00.000000000","message":"Patch Set 8: Code-Review+2","accounts_in_message":[],"_revision_number":8},{"id":"a9702edf1d4cffb1b0740f31ccc486e46ad4ceca","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-06-20 17:37:14.000000000","message":"Patch Set 8: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-ansible-linters http://logs.openstack.org/28/666428/8/check/openstack-ansible-linters/324b32e/ : SUCCESS in 5m 11s\n- openstack-ansible-deploy-aio_metal-debian-stable http://logs.openstack.org/28/666428/8/check/openstack-ansible-deploy-aio_metal-debian-stable/c874369/ : SUCCESS in 1h 04m 40s\n- openstack-ansible-deploy-aio_metal-centos-7 http://logs.openstack.org/28/666428/8/check/openstack-ansible-deploy-aio_metal-centos-7/51af39c/ : SUCCESS in 1h 18m 24s\n- openstack-ansible-deploy-aio_metal-opensuse-150 http://logs.openstack.org/28/666428/8/check/openstack-ansible-deploy-aio_metal-opensuse-150/a86e765/ : SUCCESS in 1h 28m 25s\n- openstack-ansible-deploy-aio_metal-ubuntu-bionic http://logs.openstack.org/28/666428/8/check/openstack-ansible-deploy-aio_metal-ubuntu-bionic/d85b376/ : SUCCESS in 1h 04m 12s\n- openstack-ansible-deploy-aio_distro_metal-centos-7 http://logs.openstack.org/28/666428/8/check/openstack-ansible-deploy-aio_distro_metal-centos-7/3852620/ : SUCCESS in 59m 51s\n- openstack-tox-docs http://logs.openstack.org/28/666428/8/check/openstack-tox-docs/2df6b28/html/ : SUCCESS in 2m 48s\n- openstack-ansible-uw_apache-centos-7 http://logs.openstack.org/28/666428/8/check/openstack-ansible-uw_apache-centos-7/b2c8455/ : SUCCESS in 36m 18s\n- openstack-ansible-uw_apache-ubuntu-bionic http://logs.openstack.org/28/666428/8/check/openstack-ansible-uw_apache-ubuntu-bionic/cd3fd32/ : SUCCESS in 32m 40s","accounts_in_message":[],"_revision_number":8},{"id":"29ede239898c5cd1e173ebe4bac74609aefc941d","author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"date":"2019-06-20 18:06:11.000000000","message":"Patch Set 8: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":8},{"id":"599aade442560bdff529f408f3f1366146989465","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-06-20 18:06:23.000000000","message":"Patch Set 8: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":8},{"id":"502fc1614bd83292077d93b51d8f1e19c11b9bd5","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-06-20 21:12:45.000000000","message":"Patch Set 8: Verified-2\n\nBuild failed (gate pipeline).  For information on how to proceed, see\nhttp://docs.openstack.org/infra/manual/developers.html#automated-testing\n\n\n- openstack-ansible-linters http://logs.openstack.org/28/666428/8/gate/openstack-ansible-linters/a4ac282/ : SUCCESS in 14m 36s\n- openstack-ansible-deploy-aio_metal-debian-stable http://logs.openstack.org/28/666428/8/gate/openstack-ansible-deploy-aio_metal-debian-stable/01195ab/ : TIMED_OUT in 3h 01m 32s\n- openstack-ansible-deploy-aio_metal-centos-7 http://logs.openstack.org/28/666428/8/gate/openstack-ansible-deploy-aio_metal-centos-7/ff7d0f0/ : SUCCESS in 1h 24m 21s\n- openstack-ansible-deploy-aio_metal-opensuse-150 http://logs.openstack.org/28/666428/8/gate/openstack-ansible-deploy-aio_metal-opensuse-150/ddb6e06/ : SUCCESS in 1h 09m 59s\n- openstack-ansible-deploy-aio_metal-ubuntu-bionic http://logs.openstack.org/28/666428/8/gate/openstack-ansible-deploy-aio_metal-ubuntu-bionic/f364344/ : SUCCESS in 57m 52s\n- openstack-ansible-deploy-aio_distro_metal-centos-7 http://logs.openstack.org/28/666428/8/gate/openstack-ansible-deploy-aio_distro_metal-centos-7/66aab78/ : SUCCESS in 57m 44s\n- openstack-tox-docs http://logs.openstack.org/28/666428/8/gate/openstack-tox-docs/56bf22f/html/ : SUCCESS in 6m 07s\n- openstack-ansible-uw_apache-centos-7 http://logs.openstack.org/28/666428/8/gate/openstack-ansible-uw_apache-centos-7/22e4857/ : SUCCESS in 35m 49s\n- openstack-ansible-uw_apache-ubuntu-bionic http://logs.openstack.org/28/666428/8/gate/openstack-ansible-uw_apache-ubuntu-bionic/98898ad/ : SUCCESS in 39m 11s","accounts_in_message":[],"_revision_number":8},{"id":"e2a86c8416ac769a1493f44f1694bd5eb25cbd7c","author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"date":"2019-06-24 16:10:05.000000000","message":"Patch Set 8:\n\nrecheck","accounts_in_message":[],"_revision_number":8},{"id":"4895b4d0ac05d57b642683608a5c3c53af27a88f","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-06-24 17:35:14.000000000","message":"Patch Set 8: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-ansible-linters http://logs.openstack.org/28/666428/8/check/openstack-ansible-linters/d96be7d/ : SUCCESS in 5m 47s\n- openstack-ansible-deploy-aio_metal-debian-stable http://logs.openstack.org/28/666428/8/check/openstack-ansible-deploy-aio_metal-debian-stable/b179570/ : SUCCESS in 1h 00m 58s\n- openstack-ansible-deploy-aio_metal-centos-7 http://logs.openstack.org/28/666428/8/check/openstack-ansible-deploy-aio_metal-centos-7/478a0a1/ : SUCCESS in 1h 19m 39s\n- openstack-ansible-deploy-aio_metal-opensuse-150 http://logs.openstack.org/28/666428/8/check/openstack-ansible-deploy-aio_metal-opensuse-150/1bceef5/ : SUCCESS in 1h 13m 18s\n- openstack-ansible-deploy-aio_metal-ubuntu-bionic http://logs.openstack.org/28/666428/8/check/openstack-ansible-deploy-aio_metal-ubuntu-bionic/d4458b2/ : SUCCESS in 1h 08m 44s\n- openstack-ansible-deploy-aio_distro_metal-centos-7 http://logs.openstack.org/28/666428/8/check/openstack-ansible-deploy-aio_distro_metal-centos-7/caad0fb/ : SUCCESS in 59m 24s\n- openstack-tox-docs http://logs.openstack.org/28/666428/8/check/openstack-tox-docs/b6bac4c/html/ : SUCCESS in 2m 47s\n- openstack-ansible-uw_apache-centos-7 http://logs.openstack.org/28/666428/8/check/openstack-ansible-uw_apache-centos-7/ac92491/ : SUCCESS in 44m 08s\n- openstack-ansible-uw_apache-ubuntu-bionic http://logs.openstack.org/28/666428/8/check/openstack-ansible-uw_apache-ubuntu-bionic/ffecf19/ : SUCCESS in 40m 36s","accounts_in_message":[],"_revision_number":8},{"id":"057813b9c295cafd83ed528e97d048af1e6ad88a","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-06-24 17:35:25.000000000","message":"Patch Set 8: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":8},{"id":"39fa8e561d3c31a041f9ed4ca73262bd6ad1c7b1","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-06-24 19:06:44.000000000","message":"Patch Set 8: Verified+2\n\nBuild succeeded (gate pipeline).\n\n- openstack-ansible-linters http://logs.openstack.org/28/666428/8/gate/openstack-ansible-linters/baefcc5/ : SUCCESS in 6m 04s\n- openstack-ansible-deploy-aio_metal-debian-stable http://logs.openstack.org/28/666428/8/gate/openstack-ansible-deploy-aio_metal-debian-stable/413a7f4/ : SUCCESS in 1h 01m 30s\n- openstack-ansible-deploy-aio_metal-centos-7 http://logs.openstack.org/28/666428/8/gate/openstack-ansible-deploy-aio_metal-centos-7/5621158/ : SUCCESS in 1h 21m 14s\n- openstack-ansible-deploy-aio_metal-opensuse-150 http://logs.openstack.org/28/666428/8/gate/openstack-ansible-deploy-aio_metal-opensuse-150/724f4b0/ : SUCCESS in 1h 01m 50s\n- openstack-ansible-deploy-aio_metal-ubuntu-bionic http://logs.openstack.org/28/666428/8/gate/openstack-ansible-deploy-aio_metal-ubuntu-bionic/ee54301/ : SUCCESS in 1h 07m 29s\n- openstack-ansible-deploy-aio_distro_metal-centos-7 http://logs.openstack.org/28/666428/8/gate/openstack-ansible-deploy-aio_distro_metal-centos-7/1cd1d10/ : SUCCESS in 57m 03s\n- openstack-tox-docs http://logs.openstack.org/28/666428/8/gate/openstack-tox-docs/058f6fd/html/ : SUCCESS in 3m 53s\n- openstack-ansible-uw_apache-centos-7 http://logs.openstack.org/28/666428/8/gate/openstack-ansible-uw_apache-centos-7/fc3c8fb/ : SUCCESS in 38m 13s\n- openstack-ansible-uw_apache-ubuntu-bionic http://logs.openstack.org/28/666428/8/gate/openstack-ansible-uw_apache-ubuntu-bionic/71febd4/ : SUCCESS in 29m 22s","accounts_in_message":[],"_revision_number":8},{"id":"9a27ad47ecfc06351f3b787e8eac884efc1ef1cb","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-06-24 19:06:44.000000000","message":"Change has been successfully merged by Zuul","accounts_in_message":[],"_revision_number":8},{"id":"e6a6522c7e5e003d56a3d9dab9a15207659ed97c","author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"date":"2019-06-24 19:26:59.000000000","message":"Patch Set 8: Cherry Picked\n\nThis patchset was cherry picked to branch stable/stein as commit 8fc9bbb88bf677ddbb5f2780e9ed2b7dcd668458","accounts_in_message":[],"_revision_number":8}],"current_revision_number":8,"current_revision":"8e1f7f4ad8918af9e467387144c7eede7f19f92a","revisions":{"71fce90d2a1f9d54f631525e85d021a7964e3cac":{"kind":"REWORK","_number":1,"created":"2019-06-19 19:44:06.000000000","uploader":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"ref":"refs/changes/28/666428/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-ansible-os_keystone","ref":"refs/changes/28/666428/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/1"}}},"commit":{"parents":[{"commit":"03b0aaf019d44e2fff3658a65c4f5cf503f61d35","subject":"Updated from OpenStack Ansible Tests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/03b0aaf019d44e2fff3658a65c4f5cf503f61d35"}]}],"author":{"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","date":"2019-06-19 19:17:02.000000000","tz":60},"committer":{"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","date":"2019-06-19 19:17:02.000000000","tz":60},"subject":"Fix loss of fernet tokens on Rocky to Stein upgrade for source installs","message":"Fix loss of fernet tokens on Rocky to Stein upgrade for source installs\n\nThe introduction of smart-soures in [1] created a code path\nwhich deletes the /etc/keystone directory before symlinking it\ninto the keystone venv and creating the necessary config files.\n\nUnfortunatley this has the side effect of also deleting any fernet\nkeys which pre-existed in the case of an upgrade from Rocky, and\nre-initialising a new key. The original keys are deleted in a way\nwhich is unrecoverable in the absence of a backup taken by the\noperator.\n\nFor minor upgrades between versions of Stein the smart-sources\ncode would have created a new empty /etc/keystone directory in\nthe newly created upgrade venv and re-initialised the fernet keys\nas would happen for a fresh installation, however the old keys\nwould be recoverable manually from the previous venv.\n\nThis change simplifies the smart-sources code to always keep the\nkeystone config files and fernet keys in the host /etc/keystone.\nThis ensures that the lifecycle of the fernet keys is not coupled\nto the lifecycle of the keystone venvs.\n\nIn addition, tasks are added to rescue any keys which have been\ncreated in the keystone venv by installations from the Stein\nrelease-candidate.\n\n[1] https://review.opendev.org/#/c/588960/\n\nChange-Id: Ide611fd3d88e352367220f05dbcf4186ac20319f\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/71fce90d2a1f9d54f631525e85d021a7964e3cac"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/71fce90d2a1f9d54f631525e85d021a7964e3cac"}]},"branch":"refs/heads/master"},"8f92fd13fcdb3f178f8589a39851b532d5b870b7":{"kind":"NO_CODE_CHANGE","_number":2,"created":"2019-06-19 19:47:09.000000000","uploader":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"ref":"refs/changes/28/666428/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-ansible-os_keystone","ref":"refs/changes/28/666428/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/2"}}},"commit":{"parents":[{"commit":"03b0aaf019d44e2fff3658a65c4f5cf503f61d35","subject":"Updated from OpenStack Ansible Tests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/03b0aaf019d44e2fff3658a65c4f5cf503f61d35"}]}],"author":{"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","date":"2019-06-19 19:17:02.000000000","tz":60},"committer":{"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","date":"2019-06-19 19:47:07.000000000","tz":0},"subject":"Fix loss of fernet tokens on Rocky to Stein upgrade for source installs","message":"Fix loss of fernet tokens on Rocky to Stein upgrade for source installs\n\nThe introduction of smart-soures in [1] created a code path\nwhich deletes the /etc/keystone directory before symlinking it\ninto the keystone venv and creating the necessary config files.\n\nUnfortunatley this has the side effect of also deleting any fernet\nkeys which pre-existed in the case of an upgrade from Rocky, and\nre-initialising a new key. The original keys are deleted in a way\nwhich is unrecoverable in the absence of a backup taken by the\noperator.\n\nFor minor upgrades between versions of Stein the smart-sources\ncode would have created a new empty /etc/keystone directory in\nthe newly created upgrade venv and re-initialised the fernet keys\nas would happen for a fresh installation, however the old keys\nwould be recoverable manually from the previous venv.\n\nThis change simplifies the smart-sources code to always keep the\nkeystone config files and fernet keys in the host /etc/keystone.\nThis ensures that the lifecycle of the fernet keys is not coupled\nto the lifecycle of the keystone venvs.\n\nIn addition, tasks are added to rescue any keys which have been\ncreated in the keystone venv by installations from the Stein\nrelease-candidate.\n\n[1] https://review.opendev.org/#/c/588960/\n\nCloses-Bug: 1833414\nChange-Id: Ide611fd3d88e352367220f05dbcf4186ac20319f\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/8f92fd13fcdb3f178f8589a39851b532d5b870b7"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/8f92fd13fcdb3f178f8589a39851b532d5b870b7"}]},"branch":"refs/heads/master"},"9ef493ff6dd66e95cfe1fe4dc52d7ab3b257c1e3":{"kind":"REWORK","_number":3,"created":"2019-06-19 19:51:45.000000000","uploader":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"ref":"refs/changes/28/666428/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-ansible-os_keystone","ref":"refs/changes/28/666428/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/3"}}},"commit":{"parents":[{"commit":"03b0aaf019d44e2fff3658a65c4f5cf503f61d35","subject":"Updated from OpenStack Ansible Tests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/03b0aaf019d44e2fff3658a65c4f5cf503f61d35"}]}],"author":{"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","date":"2019-06-19 19:17:02.000000000","tz":60},"committer":{"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","date":"2019-06-19 19:51:43.000000000","tz":0},"subject":"Fix loss of fernet tokens on Rocky to Stein upgrade for source installs","message":"Fix loss of fernet tokens on Rocky to Stein upgrade for source installs\n\nThe introduction of smart-soures in [1] created a code path\nwhich deletes the /etc/keystone directory before symlinking it\ninto the keystone venv and creating the necessary config files.\n\nUnfortunatley this has the side effect of also deleting any fernet\nkeys which pre-existed in the case of an upgrade from Rocky, and\nre-initialising a new key. The original keys are deleted in a way\nwhich is unrecoverable in the absence of a backup taken by the\noperator.\n\nFor minor upgrades between versions of Stein the smart-sources\ncode would have created a new empty /etc/keystone directory in\nthe newly created upgrade venv and re-initialised the fernet keys\nas would happen for a fresh installation, however the old keys\nwould be recoverable manually from the previous venv.\n\nThis change simplifies the smart-sources code to always keep the\nkeystone config files and fernet keys in the host /etc/keystone.\nThis ensures that the lifecycle of the fernet keys is not coupled\nto the lifecycle of the keystone venvs.\n\nIn addition, tasks are added to rescue any keys which have been\ncreated in the keystone venv by installations from the Stein\nrelease-candidate.\n\n[1] https://review.opendev.org/#/c/588960/\n\nCloses-Bug: 1833414\nChange-Id: Ide611fd3d88e352367220f05dbcf4186ac20319f\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/9ef493ff6dd66e95cfe1fe4dc52d7ab3b257c1e3"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/9ef493ff6dd66e95cfe1fe4dc52d7ab3b257c1e3"}]},"branch":"refs/heads/master"},"4e9bedd2a3b7a43bd96e3b80cbb435e79b7e4f4c":{"kind":"REWORK","_number":4,"created":"2019-06-19 20:02:24.000000000","uploader":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"ref":"refs/changes/28/666428/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-ansible-os_keystone","ref":"refs/changes/28/666428/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/4"}}},"commit":{"parents":[{"commit":"03b0aaf019d44e2fff3658a65c4f5cf503f61d35","subject":"Updated from OpenStack Ansible Tests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/03b0aaf019d44e2fff3658a65c4f5cf503f61d35"}]}],"author":{"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","date":"2019-06-19 19:17:02.000000000","tz":60},"committer":{"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","date":"2019-06-19 20:02:19.000000000","tz":0},"subject":"Fix loss of fernet tokens on Rocky to Stein upgrade for source installs","message":"Fix loss of fernet tokens on Rocky to Stein upgrade for source installs\n\nThe introduction of smart-soures in [1] created a code path\nwhich deletes the /etc/keystone directory before symlinking it\ninto the keystone venv and creating the necessary config files.\n\nUnfortunatley this has the side effect of also deleting any fernet\nkeys which pre-existed in the case of an upgrade from Rocky, and\nre-initialising a new key. The original keys are deleted in a way\nwhich is unrecoverable in the absence of a backup taken by the\noperator.\n\nFor minor upgrades between versions of Stein the smart-sources\ncode would have created a new empty /etc/keystone directory in\nthe newly created upgrade venv and re-initialised the fernet keys\nas would happen for a fresh installation, however the old keys\nwould be recoverable manually from the previous venv.\n\nThis change simplifies the smart-sources code to always keep the\nkeystone config files and fernet keys in the host /etc/keystone.\nThis ensures that the lifecycle of the fernet keys is not coupled\nto the lifecycle of the keystone venvs.\n\nIn addition, tasks are added to rescue any keys which have been\ncreated in the keystone venv by installations from the Stein\nrelease-candidate.\n\n[1] https://review.opendev.org/#/c/588960/\n\nCloses-Bug: 1833414\nChange-Id: Ide611fd3d88e352367220f05dbcf4186ac20319f\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/4e9bedd2a3b7a43bd96e3b80cbb435e79b7e4f4c"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/4e9bedd2a3b7a43bd96e3b80cbb435e79b7e4f4c"}]},"branch":"refs/heads/master"},"ab143450f58af7a36fa04f3c22f57affdcb2e020":{"kind":"NO_CODE_CHANGE","_number":5,"created":"2019-06-19 20:07:00.000000000","uploader":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"ref":"refs/changes/28/666428/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-ansible-os_keystone","ref":"refs/changes/28/666428/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/5"}}},"commit":{"parents":[{"commit":"03b0aaf019d44e2fff3658a65c4f5cf503f61d35","subject":"Updated from OpenStack Ansible Tests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/03b0aaf019d44e2fff3658a65c4f5cf503f61d35"}]}],"author":{"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","date":"2019-06-19 19:17:02.000000000","tz":60},"committer":{"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","date":"2019-06-19 20:06:58.000000000","tz":0},"subject":"Fix loss of fernet keys on Rocky to Stein upgrade for source installs","message":"Fix loss of fernet keys on Rocky to Stein upgrade for source installs\n\nThe introduction of smart-soures in [1] created a code path\nwhich deletes the /etc/keystone directory before symlinking it\ninto the keystone venv and creating the necessary config files.\n\nUnfortunatley this has the side effect of also deleting any fernet\nkeys which pre-existed in the case of an upgrade from Rocky, and\nre-initialising a new key. The original keys are deleted in a way\nwhich is unrecoverable in the absence of a backup taken by the\noperator.\n\nFor minor upgrades between versions of Stein the smart-sources\ncode would have created a new empty /etc/keystone directory in\nthe newly created upgrade venv and re-initialised the fernet keys\nas would happen for a fresh installation, however the old keys\nwould be recoverable manually from the previous venv.\n\nThis change simplifies the smart-sources code to always keep the\nkeystone config files and fernet keys in the host /etc/keystone.\nThis ensures that the lifecycle of the fernet keys is not coupled\nto the lifecycle of the keystone venvs.\n\nIn addition, tasks are added to rescue any keys which have been\ncreated in the keystone venv by installations from the Stein\nrelease-candidate.\n\n[1] https://review.opendev.org/#/c/588960/\n\nCloses-Bug: 1833414\nChange-Id: Ide611fd3d88e352367220f05dbcf4186ac20319f\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/ab143450f58af7a36fa04f3c22f57affdcb2e020"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/ab143450f58af7a36fa04f3c22f57affdcb2e020"}]},"branch":"refs/heads/master"},"46433ef20e5bf433112776413df8aba5b63aa6ab":{"kind":"REWORK","_number":6,"created":"2019-06-19 21:14:26.000000000","uploader":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"ref":"refs/changes/28/666428/6","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-ansible-os_keystone","ref":"refs/changes/28/666428/6","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/6"}}},"commit":{"parents":[{"commit":"03b0aaf019d44e2fff3658a65c4f5cf503f61d35","subject":"Updated from OpenStack Ansible Tests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/03b0aaf019d44e2fff3658a65c4f5cf503f61d35"}]}],"author":{"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","date":"2019-06-19 19:17:02.000000000","tz":60},"committer":{"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","date":"2019-06-19 21:14:17.000000000","tz":0},"subject":"Fix loss of fernet keys on Rocky to Stein upgrade for source installs","message":"Fix loss of fernet keys on Rocky to Stein upgrade for source installs\n\nThe introduction of smart-soures in [1] created a code path\nwhich deletes the /etc/keystone directory before symlinking it\ninto the keystone venv and creating the necessary config files.\n\nUnfortunatley this has the side effect of also deleting any fernet\nkeys which pre-existed in the case of an upgrade from Rocky, and\nre-initialising a new key. The original keys are deleted in a way\nwhich is unrecoverable in the absence of a backup taken by the\noperator.\n\nFor minor upgrades between versions of Stein the smart-sources\ncode would have created a new empty /etc/keystone directory in\nthe newly created upgrade venv and re-initialised the fernet keys\nas would happen for a fresh installation, however the old keys\nwould be recoverable manually from the previous venv.\n\nThis change simplifies the smart-sources code to always keep the\nkeystone config files and fernet keys in the host /etc/keystone.\nThis ensures that the lifecycle of the fernet keys is not coupled\nto the lifecycle of the keystone venvs.\n\nIn addition, tasks are added to rescue any keys which have been\ncreated in the keystone venv by installations from the Stein\nrelease-candidate.\n\n[1] https://review.opendev.org/#/c/588960/\n\nCloses-Bug: 1833414\nChange-Id: Ide611fd3d88e352367220f05dbcf4186ac20319f\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/46433ef20e5bf433112776413df8aba5b63aa6ab"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/46433ef20e5bf433112776413df8aba5b63aa6ab"}]},"branch":"refs/heads/master"},"c2d81653d1a62e76ae5710a6c8de16f502b82904":{"kind":"REWORK","_number":7,"created":"2019-06-19 21:32:14.000000000","uploader":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"ref":"refs/changes/28/666428/7","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-ansible-os_keystone","ref":"refs/changes/28/666428/7","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/7"}}},"commit":{"parents":[{"commit":"03b0aaf019d44e2fff3658a65c4f5cf503f61d35","subject":"Updated from OpenStack Ansible Tests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/03b0aaf019d44e2fff3658a65c4f5cf503f61d35"}]}],"author":{"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","date":"2019-06-19 19:17:02.000000000","tz":60},"committer":{"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","date":"2019-06-19 21:32:11.000000000","tz":0},"subject":"Fix loss of fernet keys on Rocky to Stein upgrade for source installs","message":"Fix loss of fernet keys on Rocky to Stein upgrade for source installs\n\nThe introduction of smart-soures in [1] created a code path\nwhich deletes the /etc/keystone directory before symlinking it\ninto the keystone venv and creating the necessary config files.\n\nUnfortunatley this has the side effect of also deleting any fernet\nkeys which pre-existed in the case of an upgrade from Rocky, and\nre-initialising a new key. The original keys are deleted in a way\nwhich is unrecoverable in the absence of a backup taken by the\noperator.\n\nFor minor upgrades between versions of Stein the smart-sources\ncode would have created a new empty /etc/keystone directory in\nthe newly created upgrade venv and re-initialised the fernet keys\nas would happen for a fresh installation, however the old keys\nwould be recoverable manually from the previous venv.\n\nThis change simplifies the smart-sources code to always keep the\nkeystone config files and fernet keys in the host /etc/keystone.\nThis ensures that the lifecycle of the fernet keys is not coupled\nto the lifecycle of the keystone venvs.\n\nIn addition, tasks are added to rescue any keys which have been\ncreated in the keystone venv by installations from the Stein\nrelease-candidate.\n\n[1] https://review.opendev.org/#/c/588960/\n\nCloses-Bug: 1833414\nChange-Id: Ide611fd3d88e352367220f05dbcf4186ac20319f\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/c2d81653d1a62e76ae5710a6c8de16f502b82904"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/c2d81653d1a62e76ae5710a6c8de16f502b82904"}]},"branch":"refs/heads/master"},"8e1f7f4ad8918af9e467387144c7eede7f19f92a":{"kind":"REWORK","_number":8,"created":"2019-06-20 15:48:01.000000000","uploader":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"ref":"refs/changes/28/666428/8","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-ansible-os_keystone","ref":"refs/changes/28/666428/8","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/8 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/8 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/8 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-ansible-os_keystone refs/changes/28/666428/8"}}},"commit":{"parents":[{"commit":"03b0aaf019d44e2fff3658a65c4f5cf503f61d35","subject":"Updated from OpenStack Ansible Tests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/03b0aaf019d44e2fff3658a65c4f5cf503f61d35"}]}],"author":{"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","date":"2019-06-19 19:17:02.000000000","tz":60},"committer":{"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","date":"2019-06-20 15:46:28.000000000","tz":0},"subject":"Fix loss of fernet and credential keys during Rocky to Stein upgrade","message":"Fix loss of fernet and credential keys during Rocky to Stein upgrade\n\nThis applies only to source based installations.\n\nThe introduction of smart-sources in [1] created a code path\nwhich deletes the /etc/keystone directory before symlinking it\ninto the keystone venv and creating the necessary config files.\n\nUnfortunatley this has the side effect of also deleting any fernet\nand credential keys which pre-existed in the case of an upgrade from\nRocky. The original keys were deleted simulataneously across the whole\nkeystone_all group in a way which is makes them unrecoverable in\nthe absence of a backup taken by the operator.\n\nThis change simplifies the smart-sources code to always keep the\nkeystone config files and fernet keys in the host /etc/keystone.\nThis ensures that the lifecycle of the fernet keys is not coupled\nto the lifecycle of the keystone venvs.\n\nIn addition, a task is added to rescue any keys which have been\ncreated in the keystone venv by installations from the Stein\nrelease-candidate.\n\n[1] https://review.opendev.org/#/c/588960/\n\nCloses-Bug: 1833414\nChange-Id: Ide611fd3d88e352367220f05dbcf4186ac20319f\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/8e1f7f4ad8918af9e467387144c7eede7f19f92a"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-ansible-os_keystone/commit/8e1f7f4ad8918af9e467387144c7eede7f19f92a"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
