)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"change_message_id":"aa991efa51806784fe6c2c0de6dad671b7d5d29d","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":17,"id":"47b81c36_8f9bdfb1","updated":"2026-06-16 01:41:57.000000000","message":"So my concern about removing Apache for keystone is that most of the authentication methods rely on an Apache plugin which is not there with uWSGI.","commit_id":"c22cffb37645b270892cad2995a73f021e82819d"},{"author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"change_message_id":"a89af830f4cb26964038bdf02ee1338969a15f3c","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":17,"id":"e693fcb3_bf1ede9b","in_reply_to":"1d656b47_4dab714e","updated":"2026-06-17 21:13:18.000000000","message":"Probably now it is better to revert apache config for the keystone chart and then I will prepare a follow up change to move the apache to sidecar (with example override and with a test case for let say OIDC).","commit_id":"c22cffb37645b270892cad2995a73f021e82819d"},{"author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"change_message_id":"a5968630ad51ac208a0d497de99b57821589ae06","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":17,"id":"1d656b47_4dab714e","in_reply_to":"47b81c36_8f9bdfb1","updated":"2026-06-17 21:01:03.000000000","message":"I assume uwsgi server supports uwsgi binary protocol that can pass all environ keys from the frontend via the unix socket. So those users who need advanced auth features can do the following:\n\n1) configure uwsgi to bind a unix socket in addition to http-socket that is still necessary for health check\n2) run apache sidecar with necessary auth modules + mod_proxy_uwsgi. \n\nIn this case TLS can either be terminated in nginx sidecar or in apache sidecar.\n\nI will add an override example for the federated auth features.","commit_id":"c22cffb37645b270892cad2995a73f021e82819d"},{"author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"change_message_id":"d2b74e309184d4bc14963b742476677ebaf629ed","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":17,"id":"da6d4785_4f2db437","in_reply_to":"e693fcb3_bf1ede9b","updated":"2026-06-30 17:39:21.000000000","message":"Done","commit_id":"c22cffb37645b270892cad2995a73f021e82819d"}]}
