)]}'
{"nova/templates/configmap-etc.yaml":[{"author":{"_account_id":32871,"name":"Ksawery Dziekoński","email":"ksdziekonski@gmail.com","username":"ksdziekonski"},"change_message_id":"a22188d321132059fa0ae42abb87dbb8a12c6a26","unresolved":true,"context_lines":[{"line_number":84,"context_line":"{{- if eq $dbEngine \"mysql\" -}}"},{"line_number":85,"context_line":"{{- $_ :\u003d (printf \"%s?charset\u003dutf8\u0026ssl_ca\u003d/etc/mysql/certs/ca.crt\u0026ssl_key\u003d/etc/mysql/certs/tls.key\u0026ssl_cert\u003d/etc/mysql/certs/tls.crt\u0026ssl_verify_cert\" $connection ) | set .Values.conf.nova.database \"connection\" -}}"},{"line_number":86,"context_line":"{{- else if eq $dbEngine \"postgresql\" -}}"},{"line_number":87,"context_line":"{{- $_ :\u003d (printf \"%s?sslmode\u003dverify-full\u0026sslrootcert\u003d/etc/mysql/certs/ca.crt\u0026sslkey\u003d/etc/mysql/certs/tls.key\u0026sslcert\u003d/etc/mysql/certs/tls.crt\" $connection ) | set .Values.conf.nova.database \"connection\" -}}"},{"line_number":88,"context_line":"{{- else -}}"},{"line_number":89,"context_line":"{{- $_ :\u003d set .Values.conf.nova.database \"connection\" $connection -}}"},{"line_number":90,"context_line":"{{- end -}}"}],"source_content_type":"text/x-yaml","patch_set":4,"id":"522dfedf_39235922","line":87,"updated":"2021-02-23 05:55:50.000000000","message":"Generally speaking, we\u0027d like to have as strict of a TLS authentication process as possible, but it\u0027s worth remarking that `verify-full` can be a bit too aggressive in certain situations. Is that acceptable?\n\nRef: https://www.postgresql.org/docs/current/libpq-ssl.html#LIBPQ-SSL-SSLMODE-STATEMENTS","commit_id":"9d52356395e21dcfe5b61119f71408924e5b50cb"}],"nova/templates/cron-job-cell-setup.yaml":[{"author":{"_account_id":32871,"name":"Ksawery Dziekoński","email":"ksdziekonski@gmail.com","username":"ksdziekonski"},"change_message_id":"a22188d321132059fa0ae42abb87dbb8a12c6a26","unresolved":true,"context_lines":[{"line_number":55,"context_line":"{{- if and .Values.manifests.certificates $dbTlsSecret }}"},{"line_number":56,"context_line":"{{- $destUid :\u003d default 0 (index (default (dict) (index (dict \"envAll\" $envAll \"application\" \"cell_setup\" | include \"helm-toolkit.snippets.kubernetes_pod_security_context\" | fromYaml) \"securityContext\")) \"runAsUser\") -}}"},{"line_number":57,"context_line":"{{- $destGid :\u003d default 0 (index (default (dict) (index (dict \"envAll\" $envAll \"application\" \"cell_setup\" | include \"helm-toolkit.snippets.kubernetes_pod_security_context\" | fromYaml) \"securityContext\")) \"runAsGroup\") -}}"},{"line_number":58,"context_line":"{{- dict \"uid\" $destUid \"gid\" $destGid \"tlsSecret\" $dbTlsSecret \"targetVolume\" $dbTlsVolume | include \"helm-toolkit.snippets.tls_owner_fix_init_container\" | indent 12 }}"},{"line_number":59,"context_line":"{{- end }}"},{"line_number":60,"context_line":"          containers:"},{"line_number":61,"context_line":"            - name: nova-cell-setup"}],"source_content_type":"text/x-yaml","patch_set":4,"id":"a8131573_3fb26f90","line":58,"updated":"2021-02-23 05:55:50.000000000","message":"It\u0027s important to point out that this init container, which is used across patchsets in the `postgresql-tls` topic, is specifically dependent on https://review.opendev.org/c/openstack/openstack-helm-infra/+/771773, which also carries a few changes to the PostgreSQL infra chart, so merging this on it\u0027s own doesn\u0027t make much sense.","commit_id":"9d52356395e21dcfe5b61119f71408924e5b50cb"}]}
