)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"0512d378c122133a82528a956a540abe68572e2d","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"9fca4028_4236e318","updated":"2023-05-29 09:46:18.000000000","message":"LGTM","commit_id":"b75a9d0dd07d1fe1b578398714e776911f3fb2a9"}],"doc/source/user/security/ssl-certificates.rst":[{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"3081f59bfeaa1cdfbd943d456a88ae40cd5747c9","unresolved":true,"context_lines":[{"line_number":284,"context_line":"As a result, when keystone is available over HTTPS, each service will try to"},{"line_number":285,"context_line":"reach it over HTTP that will fail."},{"line_number":286,"context_line":""},{"line_number":287,"context_line":"To avoid downtime, it is recommended to enable ``keystone_accept_both_protocols``"},{"line_number":288,"context_line":"until all services are configured correctly. It allows keystone to listen on"},{"line_number":289,"context_line":"both HTTP and HTTPS."},{"line_number":290,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"2129d0a6_77c5667e","line":287,"range":{"start_line":287,"start_character":0,"end_line":287,"end_character":17},"updated":"2023-05-25 21:36:33.000000000","message":"I\u0027d say that just setting keystone_accept_both_protocols might not be enough, as you\u0027d need to somehow cleanup http endpoints for each service after role is finished and service is switched to HTTPS (and vice versa), as otherwise it could be like round-robin in endpoint discovery?","commit_id":"0e9fc6dc5d01eaf20a5eeb60b38dfd28ee12f6ce"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"3436cb17e01d8eb170a787d931c0044c0b15df11","unresolved":false,"context_lines":[{"line_number":284,"context_line":"As a result, when keystone is available over HTTPS, each service will try to"},{"line_number":285,"context_line":"reach it over HTTP that will fail."},{"line_number":286,"context_line":""},{"line_number":287,"context_line":"To avoid downtime, it is recommended to enable ``keystone_accept_both_protocols``"},{"line_number":288,"context_line":"until all services are configured correctly. It allows keystone to listen on"},{"line_number":289,"context_line":"both HTTP and HTTPS."},{"line_number":290,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"7b9edeb6_53791cc1","line":287,"range":{"start_line":287,"start_character":0,"end_line":287,"end_character":17},"in_reply_to":"2129d0a6_77c5667e","updated":"2023-05-25 22:35:42.000000000","message":"so you are right that setting it for keystone is not enough\nwhen you wrote this comment I was fixing it because I noticed that for ex. nova uses service catalog to fetch placement URL but it doesn\u0027t refresh this url until restart.","commit_id":"0e9fc6dc5d01eaf20a5eeb60b38dfd28ee12f6ce"}]}
