)]}'
{"id":"openstack%2Fopenstack-helm~1002206","triplet_id":"openstack%2Fopenstack-helm~master~I9c04787700accb2e57d44efb244b1d79c167ed11","project":"openstack/openstack-helm","branch":"master","hashtags":[],"change_id":"I9c04787700accb2e57d44efb244b1d79c167ed11","subject":"[WIP] Declarative Keystone identity management","status":"NEW","created":"2026-08-24 21:52:42.000000000","updated":"2026-08-31 22:11:01.000000000","submit_type":"MERGE_IF_NECESSARY","mergeable":true,"submittable":false,"total_comment_count":0,"unresolved_comment_count":0,"work_in_progress":true,"has_review_started":false,"meta_rev_id":"139898ba083e7b1915bd1d0c2aface408edaa2f6","_number":1002206,"virtual_id_number":1002206,"owner":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"tag":"autogenerated:zuul:check","value":1,"date":"2026-08-31 22:11:01.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{"REVIEWER":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"reviewer_updates":[{"updated":"2026-08-24 23:03:16.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"23a1c87f183066599ba50beb4619982c9e15626f","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-08-24 21:52:42.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"776546ebcfa779a6ad2cf39383b798ee6241054a","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-24 23:03:16.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/e4f01cb412f444c8b8792c50bd68fd2c\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/422f5076e5654b11909b517efb5ada7d : SUCCESS in 3m 34s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/64ca7c8b7f374bce9d7063491949f28f : SUCCESS in 3m 30s\n- openstack-helm-keystone-crd-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/e4ae2599993d4ba9886958d71f08e288 : SUCCESS in 55m 27s","accounts_in_message":[],"_revision_number":1},{"id":"bb3d2ae79315b827c3f74c0d3e0976098a72e879","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-08-31 20:43:20.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":2},{"id":"139898ba083e7b1915bd1d0c2aface408edaa2f6","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-31 22:11:01.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/7dba436a773b4ea3a3442a89a7f4e68a\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/1a5a32edc41445d7abd3160c3b8f807c : SUCCESS in 3m 27s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/ef8ec5af4ba646fa9073ae110c5d668b : SUCCESS in 3m 57s\n- openstack-helm-keystone-crd-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/ccb28051957f40feaef7861e81e76722 : SUCCESS in 1h 21m 39s","accounts_in_message":[],"_revision_number":2}],"current_revision_number":2,"current_revision":"e494076bcb8e1f2ea74a1b4fd8e2cbc91538394f","revisions":{"c6d770f24ac09c73e7230ce0da61b8c26a7757f5":{"kind":"REWORK","_number":1,"created":"2026-08-24 21:52:42.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/06/1002206/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/06/1002206/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/06/1002206/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/06/1002206/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/06/1002206/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/06/1002206/1"}}},"commit":{"parents":[{"commit":"0ee5adeffcaefb6f7a78bb23bf845414672e6827","subject":"Merge \"Migrate to RabbitMQ 4.x by default\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/0ee5adeffcaefb6f7a78bb23bf845414672e6827"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-08-24 19:47:23.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-08-24 21:52:41.000000000","tz":-300},"subject":"[WIP] Declarative Keystone identity management","message":"[WIP] Declarative Keystone identity management\n\nEvery chart that owns a service catalog entry provisions it with three\none-shot jobs -- ks-service, ks-user and ks-endpoints -- each mounting the\nKeystone administrative openrc secret into a pod in the OpenStack namespace\nand driving the openstack CLI with it. Thirty-four charts render a ks-user\njob, and eighty-seven of these jobs exist in total. They reconcile nothing,\nreport no status, and repair no drift.\n\nThe keystone chart gains seven custom resource definitions in the\nkeystone.osh.openstack.org/v1alpha1 group -- Domain, Project, Role, User,\nRoleAssignment, Service and Endpoint -- and a single-file Python reconciler,\nkeystone-identity-controller, which holds the only copy of the administrative\ncredentials that provisioning needs. Every operation is find-or-create:\nfind it, patch it if a field drifted, create it if absent. Readiness is a\nmetav1.Condition of type Ready, the same shape the mariadb and rabbitmq\ngroups use, and every kind joins the keystone category.\n\nTwo behaviours of the scripts are deliberately not carried over. An endpoint\nwhose URL changed is patched rather than deleted and recreated, so it keeps\nits ID; and duplicate endpoints are reported in the Ready message rather than\ndeleted, since deleting objects it did not create is not something a\ncontroller should do quietly. The password probe is carried over unchanged in\nsubstance: Keystone invalidates every token a user holds on any password\nwrite, so the password is only written when authenticating with it fails.\n\nEvery chart the compute kit deploys that owns a catalog entry is converted --\nglance, cinder, placement, nova, neutron and heat -- each rendering its\nresources in its own templates/identity-entities.yaml from the values it\nalready declares. There is no Helm-toolkit manifest generating them, because\na chart\u0027s users and catalog entries are part of its contract. The service\nusers, service types and endpoint URLs each chart declares were diffed\nagainst the env its three jobs render, and match. Heat keeps its\nks-user-domain job: the domain-scoped heat_stack_user account is not part of\nthis path.\n\nmanifests.identity_entities defaults to false in every consumer chart and\nmanifests.deployment_identity_controller to false in the keystone chart, so\nevery consumer chart renders byte for byte as before and the keystone chart\ngains only the definitions, which are inert with nothing to reconcile. The\ntwo paths are mutually exclusive and rendering fails if both are enabled.\n\nA check job deploys the compute kit plus Ceph and cinder over the new path.\nWhile this is WIP every other check job is commented out, so a buildset runs\nonly that one; they are restored before this merges.\n\nImplements the spec: declarative Keystone identity management.\n\nChange-Id: I9c04787700accb2e57d44efb244b1d79c167ed11\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/c6d770f24ac09c73e7230ce0da61b8c26a7757f5"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/c6d770f24ac09c73e7230ce0da61b8c26a7757f5"}]},"branch":"refs/heads/master"},"e494076bcb8e1f2ea74a1b4fd8e2cbc91538394f":{"kind":"REWORK","_number":2,"created":"2026-08-31 20:43:20.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/06/1002206/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/06/1002206/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/06/1002206/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/06/1002206/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/06/1002206/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/06/1002206/2"}}},"commit":{"parents":[{"commit":"a62d0e547362ee909d8c23b426d0ecfc5c171587","subject":"Merge \"ovn: add liveness probe checking br-int OpenFlow connectivity\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/a62d0e547362ee909d8c23b426d0ecfc5c171587"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-08-24 19:47:23.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-08-31 20:43:12.000000000","tz":-300},"subject":"[WIP] Declarative Keystone identity management","message":"[WIP] Declarative Keystone identity management\n\nEvery chart that owns a service catalog entry provisions it with three\none-shot jobs -- ks-service, ks-user and ks-endpoints -- each mounting the\nKeystone administrative openrc secret into a pod in the OpenStack namespace\nand driving the openstack CLI with it. Thirty-four charts render a ks-user\njob, and eighty-seven of these jobs exist in total. They reconcile nothing,\nreport no status, and repair no drift.\n\nThe keystone chart gains eight custom resource definitions in the\nkeystone.osh.openstack.org/v1alpha1 group -- Domain, Project, Role, Group,\nUser, RoleAssignment, Service and Endpoint -- and a single-file Python\nreconciler, keystone-identity-controller, which holds the only copy of the\nadministrative credentials that provisioning needs. Every operation is\nfind-or-create: find it, patch it if a field drifted, create it if absent.\nReadiness is a metav1.Condition of type Ready, the same shape the mariadb and\nrabbitmq groups use, and every kind joins the keystone category.\n\nTwo behaviours of the scripts are deliberately not carried over. An endpoint\nwhose URL changed is patched rather than deleted and recreated, so it keeps\nits ID; and duplicate endpoints are reported in the Ready message rather than\ndeleted, since deleting objects it did not create is not something a\ncontroller should do quietly. The password probe is carried over unchanged in\nsubstance: Keystone invalidates every token a user holds on any password\nwrite, so the password is only written when authenticating with it fails.\n\nRoleAssignment names exactly one subject, a user or a group, enforced the way\nits project-or-domain scope already is. Nothing converted here declares a\ngroup -- a service account is a user -- so Group and the group subject exist\nfor federation, which is the case that has no user to name: identities arrive\nfrom the identity provider as shadow users and are mapped into groups, which\ncarry the role assignments. They are settled now rather than with the rest of\nthe federation kinds because adding a subject to a required field later would\nbe a breaking change.\n\nEvery chart the compute kit deploys that owns a catalog entry is converted --\nglance, cinder, placement, nova, neutron and heat -- each rendering its\nresources in its own templates/identity-entities.yaml from the values it\nalready declares. There is no Helm-toolkit manifest generating them, because\na chart\u0027s users and catalog entries are part of its contract. The service\nusers, service types and endpoint URLs each chart declares were diffed\nagainst the env its three jobs render, and match. Heat keeps its\nks-user-domain job: the domain-scoped heat_stack_user account is not part of\nthis path.\n\nmanifests.identity_entities defaults to false in every consumer chart and\nmanifests.deployment_identity_controller to false in the keystone chart, so\nevery consumer chart renders byte for byte as before and the keystone chart\ngains only the definitions, which are inert with nothing to reconcile. The\ntwo paths are mutually exclusive and rendering fails if both are enabled.\n\nA check job deploys the compute kit plus Ceph and cinder over the new path.\nWhile this is WIP every other check job is commented out, so a buildset runs\nonly that one; they are restored before this merges.\n\nImplements the spec: declarative Keystone identity management.\n\nChange-Id: I9c04787700accb2e57d44efb244b1d79c167ed11\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/e494076bcb8e1f2ea74a1b4fd8e2cbc91538394f"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/e494076bcb8e1f2ea74a1b4fd8e2cbc91538394f"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY"},{"label":"Workflow","status":"MAY"}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
