)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":37632,"name":"Dmitriy Chubinidze","email":"dcu995@gmail.com","username":"chubinidzedr"},"change_message_id":"bc24007c5208a9086afa70ba090c855ef7d4bbbe","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"1fabbced_01016e4b","updated":"2025-09-05 00:28:44.000000000","message":"I\u0027m not entirely sure this is the best place for this \nnote, but I consider it as some starting point.","commit_id":"b9a3ed0a348bdcb1d9599a2494efa768fddf163b"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"67138e88acee4a6851e850ad35da30bee1dd0397","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"6f3ae431_e04067a9","updated":"2025-09-05 08:03:01.000000000","message":"About logging overall.\n\nBy default, log for all tasks is written to /openstack/log/ansible-logging/ansible.log. This path is controlled by ENV variable `ANSIBLE_LOG_PATH`. To change the log path operator can define a different value in /etc/openstack_deploy/user.rc file.\n\nOther then that, OpenStack-Ansible provides relatively easy integration with ARA (https://ara.recordsansible.org/) by setting environment variable `SETUP_ARA\u003dtrue` while running `bootstrap-ansible.sh`. This will install ARA client and ensure it\u0027s being used as a callback.\n\nARA Server must be deployed by operator. We suggest using `recordsansible.ara` collection for role on ARA Server deployment.\n\nThen you can supply following environmental variables on your deploy host, to instruct ARA client to use the server:\n\n```\nARA_API_CLIENT\u003dhttp\nARA_API_SERVER\u003dhttps://ara.example.com\nARA_API_INSECURE\u003dFalse\nARA_API_USERNAME\u003dara\nARA_API_PASSWORD\u003d\n``` \n\nYou can also use only client part of the ARA by setting `ARA_REPORT_TYPE\u003dhtml`, which will store an HTML report for each run locally on the deploy host.","commit_id":"be6b2bdde45018f0d53456151fa06d1b38878db4"},{"author":{"_account_id":37598,"name":"Ivan Anfimov","display_name":"Ivan Anfimov","email":"lazekteam@gmail.com","username":"anfimovir"},"change_message_id":"b42dec3a859d9bca2077b3a56022e7d28296e7c2","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":3,"id":"c0845df3_38be2710","updated":"2025-09-05 10:49:29.000000000","message":"@dcu995@gmail.com please rebase for fix merge conflict..","commit_id":"9a9f7bfd1cdf7ee6a2e34486f680b1cca23a5688"},{"author":{"_account_id":37632,"name":"Dmitriy Chubinidze","email":"dcu995@gmail.com","username":"chubinidzedr"},"change_message_id":"21729c2a78d848c282344e68dfb63c4e9ac5fa67","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"274701d4_a8a78cca","in_reply_to":"c0845df3_38be2710","updated":"2025-09-05 11:04:33.000000000","message":"Done,thx","commit_id":"9a9f7bfd1cdf7ee6a2e34486f680b1cca23a5688"},{"author":{"_account_id":37598,"name":"Ivan Anfimov","display_name":"Ivan Anfimov","email":"lazekteam@gmail.com","username":"anfimovir"},"change_message_id":"33009e8313113c966ea6c367c431d8d51c65c384","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":6,"id":"87c9fb31_9df82774","updated":"2025-09-05 15:15:03.000000000","message":"@dcu995@gmail.com\nhttps://docs.openstack.org/openstack-ansible/latest/user/security/hardening.html#hiding-secrets-in-openstack-ansible\n\nHmm.. may be update text with example for disabling or not need? I don\u0027t think it\u0027s very informative...","commit_id":"eeeb61b78e2e64193be8eacc7d048a1469cb33dc"},{"author":{"_account_id":37632,"name":"Dmitriy Chubinidze","email":"dcu995@gmail.com","username":"chubinidzedr"},"change_message_id":"afd0385d9068e4f710409fac335518601d97de65","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"29dfb394_49073da3","in_reply_to":"87c9fb31_9df82774","updated":"2025-09-08 11:27:41.000000000","message":"As this variable have only true/false values, I think this shouldn\u0027t be a problem 😊","commit_id":"eeeb61b78e2e64193be8eacc7d048a1469cb33dc"}],"doc/source/user/security/index.rst":[{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"67138e88acee4a6851e850ad35da30bee1dd0397","unresolved":true,"context_lines":[{"line_number":16,"context_line":"   ssl-certificates"},{"line_number":17,"context_line":"   security-headers"},{"line_number":18,"context_line":"   security-txt"},{"line_number":19,"context_line":"   hardening"},{"line_number":20,"context_line":"   nolog"},{"line_number":21,"context_line":"   non-root"},{"line_number":22,"context_line":"   password-rotation"}],"source_content_type":"text/x-rst","patch_set":2,"id":"0bfb8373_eecd42a2","line":20,"range":{"start_line":19,"start_character":0,"end_line":20,"end_character":8},"updated":"2025-09-05 08:03:01.000000000","message":"Maybe makes sense to re-factor `hardening` a little bit and place nolog info there? As these are really 2 tiny sections which kinda about general advises on security?","commit_id":"be6b2bdde45018f0d53456151fa06d1b38878db4"},{"author":{"_account_id":37632,"name":"Dmitriy Chubinidze","email":"dcu995@gmail.com","username":"chubinidzedr"},"change_message_id":"35298280522333cbd5f9bfaafc9d863a08a1951f","unresolved":false,"context_lines":[{"line_number":16,"context_line":"   ssl-certificates"},{"line_number":17,"context_line":"   security-headers"},{"line_number":18,"context_line":"   security-txt"},{"line_number":19,"context_line":"   hardening"},{"line_number":20,"context_line":"   nolog"},{"line_number":21,"context_line":"   non-root"},{"line_number":22,"context_line":"   password-rotation"}],"source_content_type":"text/x-rst","patch_set":2,"id":"f0211fff_3f669b59","line":20,"range":{"start_line":19,"start_character":0,"end_line":20,"end_character":8},"in_reply_to":"0bfb8373_eecd42a2","updated":"2025-09-05 10:15:22.000000000","message":"Thanks, seems like a good idea.","commit_id":"be6b2bdde45018f0d53456151fa06d1b38878db4"}],"doc/source/user/security/nolog.rst":[{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"67138e88acee4a6851e850ad35da30bee1dd0397","unresolved":true,"context_lines":[{"line_number":6,"context_line":"task output is hidden in logs."},{"line_number":7,"context_line":""},{"line_number":8,"context_line":"By default, this prevents sensitive values (such as passwords) from being"},{"line_number":9,"context_line":"written to log files. Disabling these variables can make debugging easier,"},{"line_number":10,"context_line":"but it also risks exposing secrets in plain text."},{"line_number":11,"context_line":""},{"line_number":12,"context_line":"Use them with caution: keep logging enabled for troubleshooting, but remember"}],"source_content_type":"text/x-rst","patch_set":2,"id":"57dce424_72ac874c","line":9,"range":{"start_line":9,"start_character":8,"end_line":9,"end_character":20},"updated":"2025-09-05 08:03:01.000000000","message":"Probably idea for a different doc, but I guess worth documenting the logging thing as well...","commit_id":"be6b2bdde45018f0d53456151fa06d1b38878db4"},{"author":{"_account_id":37632,"name":"Dmitriy Chubinidze","email":"dcu995@gmail.com","username":"chubinidzedr"},"change_message_id":"35298280522333cbd5f9bfaafc9d863a08a1951f","unresolved":false,"context_lines":[{"line_number":6,"context_line":"task output is hidden in logs."},{"line_number":7,"context_line":""},{"line_number":8,"context_line":"By default, this prevents sensitive values (such as passwords) from being"},{"line_number":9,"context_line":"written to log files. Disabling these variables can make debugging easier,"},{"line_number":10,"context_line":"but it also risks exposing secrets in plain text."},{"line_number":11,"context_line":""},{"line_number":12,"context_line":"Use them with caution: keep logging enabled for troubleshooting, but remember"}],"source_content_type":"text/x-rst","patch_set":2,"id":"3357af33_fb0fdffe","line":9,"range":{"start_line":9,"start_character":8,"end_line":9,"end_character":20},"in_reply_to":"57dce424_72ac874c","updated":"2025-09-05 10:15:22.000000000","message":"Yeah, I\u0027ll create logging section separately, thanks.","commit_id":"be6b2bdde45018f0d53456151fa06d1b38878db4"},{"author":{"_account_id":37598,"name":"Ivan Anfimov","display_name":"Ivan Anfimov","email":"lazekteam@gmail.com","username":"anfimovir"},"change_message_id":"08e2f788aec1ad0a8bbcd30e6bc4c9bbe89d8105","unresolved":true,"context_lines":[{"line_number":9,"context_line":"written to log files. Disabling these variables can make debugging easier,"},{"line_number":10,"context_line":"but it also risks exposing secrets in plain text."},{"line_number":11,"context_line":""},{"line_number":12,"context_line":"Use them with caution: keep logging enabled for troubleshooting, but remember"},{"line_number":13,"context_line":"that passwords may appear in the logs if protection is turned off."}],"source_content_type":"text/x-rst","patch_set":2,"id":"477be997_0718f765","line":12,"updated":"2025-09-05 00:57:22.000000000","message":"May be in warning style?","commit_id":"be6b2bdde45018f0d53456151fa06d1b38878db4"},{"author":{"_account_id":37632,"name":"Dmitriy Chubinidze","email":"dcu995@gmail.com","username":"chubinidzedr"},"change_message_id":"35298280522333cbd5f9bfaafc9d863a08a1951f","unresolved":false,"context_lines":[{"line_number":9,"context_line":"written to log files. Disabling these variables can make debugging easier,"},{"line_number":10,"context_line":"but it also risks exposing secrets in plain text."},{"line_number":11,"context_line":""},{"line_number":12,"context_line":"Use them with caution: keep logging enabled for troubleshooting, but remember"},{"line_number":13,"context_line":"that passwords may appear in the logs if protection is turned off."}],"source_content_type":"text/x-rst","patch_set":2,"id":"3e56e76b_f7a282d0","line":12,"in_reply_to":"477be997_0718f765","updated":"2025-09-05 10:15:22.000000000","message":"Done","commit_id":"be6b2bdde45018f0d53456151fa06d1b38878db4"}]}
