)]}'
{"id":"openstack%2Fopenstack-helm~992528","triplet_id":"openstack%2Fopenstack-helm~master~I89829176d4d85c7033af8ac2f5a8d6af23037e4d","project":"openstack/openstack-helm","branch":"master","attention_set":{},"removed_from_attention_set":{"3009":{"account":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"last_update":"2026-07-06 19:04:18.000000000","reason":"Change was submitted"},"5890":{"account":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"last_update":"2026-07-06 14:47:26.000000000","reason":"\u003cGERRIT_ACCOUNT_5890\u003e replied on the change","reason_account":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"}}},"hashtags":[],"change_id":"I89829176d4d85c7033af8ac2f5a8d6af23037e4d","subject":"Terminate API TLS with nginx sidecars","status":"MERGED","created":"2026-06-09 20:18:20.000000000","updated":"2026-07-06 19:09:57.000000000","submitted":"2026-07-06 19:04:18.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":4,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"992528","meta_rev_id":"f6551fa3c3628143f8d48a76d2ef8dd98aa2f0a6","_number":992528,"virtual_id_number":992528,"owner":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},{"value":0,"_account_id":34520,"name":"Sergiy Markin","email":"smarkin@mirantis.com","username":"sm515x"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2026-07-06 19:04:18.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"all":[{"value":2,"date":"2026-07-06 14:47:26.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},{"value":2,"date":"2026-07-06 17:36:31.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":34520,"name":"Sergiy Markin","email":"smarkin@mirantis.com","username":"sm515x"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":34520,"name":"Sergiy Markin","email":"smarkin@mirantis.com","username":"sm515x"},"all":[{"value":0,"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},{"value":1,"date":"2026-07-06 17:36:31.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":34520,"name":"Sergiy Markin","email":"smarkin@mirantis.com","username":"sm515x"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":34520,"name":"Sergiy Markin","email":"smarkin@mirantis.com","username":"sm515x"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-06-09 20:47:08.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2026-06-16 01:41:57.000000000","updated_by":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"reviewer":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"state":"CC"},{"updated":"2026-07-06 14:47:26.000000000","updated_by":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"reviewer":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"state":"REVIEWER"},{"updated":"2026-07-06 17:36:31.000000000","updated_by":{"_account_id":34520,"name":"Sergiy Markin","email":"smarkin@mirantis.com","username":"sm515x"},"reviewer":{"_account_id":34520,"name":"Sergiy Markin","email":"smarkin@mirantis.com","username":"sm515x"},"state":"REVIEWER"}],"messages":[{"id":"534db4547c4c8e9ba45e22fa86b4a280a2f2b4b1","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-09 20:18:20.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"c500d5f4852dadcc540ce7906ab0f3e90572ac09","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-09 20:37:45.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"c4f500defb62bbf7ed71fee110670539d8f18138","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-09 20:47:08.000000000","message":"Patch Set 1: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/62794ae781cd4aadad7db5cd1dddf2e3\n\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/ad7eef82837247b3a3dc80e1f7eca909 : FAILURE in 25m 50s","accounts_in_message":[],"_revision_number":1},{"id":"8ec711b17503e0a6f15ccd2ac5fb9d2d440becf9","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-09 20:53:21.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"1723646fd2d4c01364524d0809713a2c41db0db7","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-09 21:15:05.000000000","message":"Patch Set 3: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/cd1c06ef851e4b02b36ec5ce19a4c232\n\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/264f7ce8fa0f4e9a8ed68ab38b46abcf : FAILURE in 18m 15s","accounts_in_message":[],"_revision_number":3},{"id":"cd7c52dbbc226fba04cf1cc4e2afb199fb11ef7b","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-09 22:53:05.000000000","message":"Uploaded patch set 4.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":4},{"id":"28734a58b50307a05a85733c19d2e351d6146c91","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-09 23:14:36.000000000","message":"Uploaded patch set 5.","accounts_in_message":[],"_revision_number":5},{"id":"82e69b6f2695182d729d4164c3af830e24b7febe","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-09 23:31:10.000000000","message":"Patch Set 5: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/31d9423001f345ce854477b23453a85c\n\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/837af958c25a40c2a6227127ceb5d0b4 : FAILURE in 14m 31s","accounts_in_message":[],"_revision_number":5},{"id":"e7fed04647d5f1e112eaeb90bce1386378204c78","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-10 01:15:31.000000000","message":"Uploaded patch set 6.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":6},{"id":"1384e9a0a1f7a61c04ed8067321a155e60868716","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-10 04:04:02.000000000","message":"Uploaded patch set 7.","accounts_in_message":[],"_revision_number":7},{"id":"06dd14592b00af56e208f2a1d187252a709bbdfa","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-10 04:19:45.000000000","message":"Patch Set 7: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/52742301fda0409bb3a79230b1b572a5\n\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/87966ce5d88d45b1a6ea9efb994b5859 : FAILURE in 13m 51s","accounts_in_message":[],"_revision_number":7},{"id":"12b50cfd476ea29ddddb74b78dd10dbc3c426e5f","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-10 04:26:15.000000000","message":"Uploaded patch set 8.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":8},{"id":"1fa679c05154c8718a8a39e7824abfe1e8b9f351","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-10 05:00:53.000000000","message":"Patch Set 8: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/311496015764488da2bfc2f79bf5d527\n\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/8d0a4228d2214b60a44880805a039920 : FAILURE in 33m 32s","accounts_in_message":[],"_revision_number":8},{"id":"5b4811ecfe0728facbc76a1d5d8993329d3f8621","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-10 05:11:14.000000000","message":"Uploaded patch set 9.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":9},{"id":"fb3334ef3c2c0ccc4e4b4a2af54cfd62a1e54adb","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-10 06:16:04.000000000","message":"Patch Set 9: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/985f222f996a47a2953f66c07e44a0a5\n\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/d0dacacf7242455ebabe4771ac770795 : FAILURE in 57m 41s","accounts_in_message":[],"_revision_number":9},{"id":"418236827fe93b5a88191b4753ffc1b945da1157","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-10 06:38:16.000000000","message":"Uploaded patch set 10.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":10},{"id":"f3970418a7006f5cb2a40aed8205c5ea33122dc4","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-10 07:46:45.000000000","message":"Patch Set 10: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/8c74464f66464902a0d2c0f32e6ef78c\n\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/3122aa805cb947fa95b51e3fbd6fcc93 : FAILURE in 1h 05m 46s","accounts_in_message":[],"_revision_number":10},{"id":"585073affc27bc0dffbdd7044b78e4b556d11dfa","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-10 14:30:40.000000000","message":"Uploaded patch set 11.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":11},{"id":"10eb433105725556bdac4849347085965d596f2e","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-10 16:08:14.000000000","message":"Patch Set 11: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/bce50e3322964c19839544078d2520d6\n\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/930f2ec464e94f75b66e749cdadb5e4a : FAILURE in 1h 26m 47s","accounts_in_message":[],"_revision_number":11},{"id":"2a3f782a126d0a48f6c0f3e87692eaaa893106ce","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-10 16:23:25.000000000","message":"Uploaded patch set 12.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":12},{"id":"b6e1c0d68d808646cf989a0dff8d197f6d229728","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-10 17:18:56.000000000","message":"Patch Set 12: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/dbf7e66eb1c34fc4a21b14fdb95dd166\n\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/0fb15e3fe41641e690217752bfbc6602 : SUCCESS in 52m 21s","accounts_in_message":[],"_revision_number":12},{"id":"36001e12d03e2a9082c5d0798d96d15e24ee5976","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-10 20:07:46.000000000","message":"Uploaded patch set 13.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":13},{"id":"a5b8ff5a0ba0593789d5eb4b7a9a009c385b217b","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-10 20:56:10.000000000","message":"Patch Set 13: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/08e98f7e46d745d49411dafe6d14ba92\n\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/64f34479da06403fa6dc60d08b66ee3a : FAILURE in 45m 20s","accounts_in_message":[],"_revision_number":13},{"id":"8a38cc6dd9c110f318edb12915667a3b19299e4e","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-10 22:00:35.000000000","message":"Uploaded patch set 14.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":14},{"id":"f9dcebde9ec5f11163889fc7d59418aa0639b0cd","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-10 22:55:40.000000000","message":"Patch Set 14: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/b8593b54427e430db4344b4a9329fbc6\n\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/b54c4a1c68454bdd95a0d14d126cd6ab : SUCCESS in 52m 07s","accounts_in_message":[],"_revision_number":14},{"id":"9d46d034decd4f1d15231ce73be70f5c4f8db0e2","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-12 22:08:20.000000000","message":"Uploaded patch set 15.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":15},{"id":"ea037e4146ed0c46d9d4075bd47065b40df724d7","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-12 22:10:23.000000000","message":"Patch Set 15: Verified-1\n\nMerge Failed.\n\nThis change or one of its cross-repo dependencies was unable to be automatically merged with the current state of its repository. Please rebase the change and upload a new patchset.\nWarning:\n  Error merging gerrit/openstack/openstack-helm for 992528,15","accounts_in_message":[],"_revision_number":15},{"id":"0bb047f672c7dea4d8f18496d7d5045d6dd22773","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-12 22:25:52.000000000","message":"Uploaded patch set 16.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":16},{"id":"5426cf569a2e442994a28f7dc8fa10be9274bae2","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-12 23:15:07.000000000","message":"Patch Set 16: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/c06c2e4dd23644048142254d12805b38\n\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/c8279410d76549c18ecbba88a3d6bc6c : SUCCESS in 44m 37s","accounts_in_message":[],"_revision_number":16},{"id":"b9e809c8db19c2dbeea2d595e7c78130c187d9b9","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-15 17:55:30.000000000","message":"Uploaded patch set 17.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":17},{"id":"8d3eebd75a282c90455e4c534d55d0b0e85b7a4c","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-15 19:21:51.000000000","message":"Patch Set 17: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/ecb0882ee8db4dfd84effef127aa5cf9\n\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/97b39f6831944875b63eebd4b18ced6c : SUCCESS in 1h 20m 26s","accounts_in_message":[],"_revision_number":17},{"id":"aa991efa51806784fe6c2c0de6dad671b7d5d29d","author":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"date":"2026-06-16 01:41:57.000000000","message":"Patch Set 17:\n\n(1 comment)","accounts_in_message":[],"_revision_number":17},{"id":"d9d2cb69438a4aaca9cb64efcd14069fc051d64c","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-17 17:10:22.000000000","message":"Uploaded patch set 18.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":18},{"id":"8683a09a2b0981abff1b7222e6f83ee4dab26f50","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-17 18:01:20.000000000","message":"Patch Set 18: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/16e21ebb06e8435c85515c21dc619d25\n\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/0d608d32895248fa9502d07cb743ce5f : SUCCESS in 46m 48s","accounts_in_message":[],"_revision_number":18},{"id":"a5968630ad51ac208a0d497de99b57821589ae06","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-17 21:01:03.000000000","message":"Patch Set 18:\n\n(1 comment)","accounts_in_message":[],"_revision_number":18},{"id":"a89af830f4cb26964038bdf02ee1338969a15f3c","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-17 21:13:18.000000000","message":"Patch Set 18:\n\n(1 comment)","accounts_in_message":[],"_revision_number":18},{"id":"7d690dde330575efecdd9fd53e552b77e3dedcb7","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-17 21:24:36.000000000","message":"Uploaded patch set 19.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":19},{"id":"07a5dc6c6a5480b987c623fb712af0b29135d4fc","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-17 22:15:51.000000000","message":"Patch Set 19: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/ff73151910864f8fa5899b2feab9521b\n\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/9c3f29c754f84416a83352165664f775 : SUCCESS in 47m 56s","accounts_in_message":[],"_revision_number":19},{"id":"cec1cd1213fe77afc0c10ea76f8302ff3d9b1a57","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-18 18:04:58.000000000","message":"Uploaded patch set 20.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":20},{"id":"4dcdf6e0dda52e26472633c77ec7d7caaff24298","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-18 19:31:57.000000000","message":"Patch Set 20: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/42e0855cc5e6484495d81af4d57189ea\n\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/39d10570bd974effa4bb5ab5414e9191 : SUCCESS in 1h 20m 48s","accounts_in_message":[],"_revision_number":20},{"id":"fca6c4b77a4ba45fbb7d6424ac5036453f79c4d0","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-18 22:12:41.000000000","message":"Uploaded patch set 21.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":21},{"id":"469d0182119acf7755159574a5ba57248c88e94a","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-18 22:59:56.000000000","message":"Patch Set 21: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/1beb5851dea54a33bed7e5a810d7c86c\n\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/f3fdf14583b14a94a81da0655bf961de : SUCCESS in 45m 33s","accounts_in_message":[],"_revision_number":21},{"id":"945721d2b96202b08c2d784d92afd458445a0d1b","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-23 23:20:39.000000000","message":"Uploaded patch set 22.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":22},{"id":"1a7d24619f1551fb692758f6074a58ca17d8e73a","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-24 00:06:58.000000000","message":"Patch Set 22: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/d5ec8e8c9fa64855ad6c048c853dd938\n\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/967fe3fc307447c791ef940b25dfe2cd : SUCCESS in 45m 08s","accounts_in_message":[],"_revision_number":22},{"id":"8d03c26ec0ceb3e6a7f45683c11acb5a86c6e48f","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-25 15:07:23.000000000","message":"Uploaded patch set 23.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":23},{"id":"31557243e9dc1294efe8254fd7d6106fa1bfb0ff","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-25 16:38:54.000000000","message":"Patch Set 23: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/303a3eaeb8e2485480be78aa78710d2e\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/9adc8a1d6671453ea60dfba56d1842b9 : SUCCESS in 4m 34s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/9c357d7fb3aa4255a6fcfeb6257d4a77 : SUCCESS in 4m 19s\n- openstack-helm-linter https://zuul.opendev.org/t/openstack/build/05682fd8e2d3429aad16067926521b72 : SUCCESS in 3m 42s\n- openstack-helm-pre-commit https://zuul.opendev.org/t/openstack/build/8a7f710ef67f47e390ed5d0bea778c63 : SUCCESS in 4m 09s\n- openstack-helm-build-charts https://zuul.opendev.org/t/openstack/build/f1da2e63d72d457abd76fbb26fbd1d8f : SUCCESS in 5m 28s\n- openstack-helm-cinder-2025-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/1f704f191eb94c2187098a21f6ac62e5 : SUCCESS in 57m 11s\n- openstack-helm-compute-kit-2025-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/56ea828bb7f94d38932bd5f9a857fbe7 : SUCCESS in 1h 20m 57s\n- openstack-helm-cinder-2025-2-ubuntu_noble https://zuul.opendev.org/t/openstack/build/6a5189f3aa5c47cbbcc1fcd007911877 : SUCCESS in 40m 20s\n- openstack-helm-compute-kit-2025-2-ubuntu_noble https://zuul.opendev.org/t/openstack/build/877acbe7260744398aa9c605de22896c : SUCCESS in 1h 10m 36s\n- openstack-helm-cinder-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/184f72721e1f42a5a76bc43346f7a075 : SUCCESS in 49m 12s\n- openstack-helm-compute-kit-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/f45781aaaaa547629bcd212d5e0658e9 : SUCCESS in 45m 22s\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/831c67023a22450fb0639dacbdf89a71 : SUCCESS in 1h 26m 45s\n- openstack-helm-compute-kit-dpdk-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/8d8050c62aff4f15b876b2027bf6d24c : SUCCESS in 1h 06m 18s\n- openstack-helm-octavia-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/01000eb04cb14d4abfbb8385b1e9c009 : SUCCESS in 46m 05s\n- openstack-helm-logging https://zuul.opendev.org/t/openstack/build/ed420dd634ae4bf7929e1313c9fac986 : SUCCESS in 24m 55s\n- openstack-helm-monitoring https://zuul.opendev.org/t/openstack/build/a0815e2ad4494b089d07a43d74ab6ff9 : SUCCESS in 27m 30s","accounts_in_message":[],"_revision_number":23},{"id":"b89b4be6dc5952f32311026587489b8dbf73cae5","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-25 17:50:50.000000000","message":"Uploaded patch set 24.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":24},{"id":"cd14b741cc744c2fd2fda70db02112824c5222aa","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-25 19:10:51.000000000","message":"Patch Set 24: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/2569b12535eb408da0d67dae84bfd6a7\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/cf0f4e12818142bf873e32a7cb1efe2c : SUCCESS in 3m 22s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/737893711894483eb19499391937aa20 : SUCCESS in 3m 23s\n- openstack-helm-linter https://zuul.opendev.org/t/openstack/build/8cc9e70365ab4d4b99a96533bc9928d4 : SUCCESS in 2m 11s\n- openstack-helm-pre-commit https://zuul.opendev.org/t/openstack/build/a28dd91b8b2f4310bd3cf9bf6e4d8520 : SUCCESS in 2m 17s\n- openstack-helm-build-charts https://zuul.opendev.org/t/openstack/build/4f40a0a684eb466cac9ffcb1b06cf2c0 : SUCCESS in 5m 31s\n- openstack-helm-cinder-2025-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/e787d8b2616240d1b250a206c35fcd17 : SUCCESS in 46m 29s\n- openstack-helm-compute-kit-2025-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/cb34d7884e9c404f8a25fe6a1a3c61c2 : SUCCESS in 1h 11m 51s\n- openstack-helm-cinder-2025-2-ubuntu_noble https://zuul.opendev.org/t/openstack/build/a1e0dc2a6dfe4612ad2af9ec8a8053ee : SUCCESS in 39m 43s\n- openstack-helm-compute-kit-2025-2-ubuntu_noble https://zuul.opendev.org/t/openstack/build/35f6b7c8ea36458696e8e8b4b0802011 : SUCCESS in 46m 11s\n- openstack-helm-cinder-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/9bca354d218b47c4904c50101f61eef7 : SUCCESS in 33m 54s\n- openstack-helm-compute-kit-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/05a61b88eb6c469a9e7db6746fe45f7d : SUCCESS in 46m 15s\n- openstack-helm-compute-kit-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/82b03941500f43878b0550e4c8ecdc15 : SUCCESS in 1h 17m 45s\n- openstack-helm-compute-kit-dpdk-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/cacdfdd3635941e094212e44b7e2fe09 : SUCCESS in 1h 07m 49s\n- openstack-helm-octavia-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/0918ba63625b47c1b49214b5f0c154b6 : SUCCESS in 1h 04m 37s\n- openstack-helm-logging https://zuul.opendev.org/t/openstack/build/031b472812bf4f89b01ce88c0e80fce2 : SUCCESS in 39m 13s\n- openstack-helm-monitoring https://zuul.opendev.org/t/openstack/build/66a738cd35be4ad6a38021309707fe74 : SUCCESS in 25m 59s","accounts_in_message":[],"_revision_number":24},{"id":"86bce4816abd79001163f9ae89378561e756c448","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-25 19:11:22.000000000","message":"Patch Set 24:\n\nThis change is ready for review.","accounts_in_message":[],"_revision_number":24},{"id":"32c5fe23fd5ef9093fa15e7a19f6b5fe54ca919a","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-25 22:33:29.000000000","message":"Uploaded patch set 25.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":25},{"id":"5e980bf8d87d633ae0585fbc66e810dba1d9b3e3","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-26 00:11:42.000000000","message":"Patch Set 25: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/afd31b8e78be4d8e9f32e8cdc57efe09\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/f764d4dcc08345b1adfd7888488ce65a : SUCCESS in 2m 50s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/fdc28d86dd384c59a860143214c465a8 : SUCCESS in 2m 24s\n- openstack-helm-linter https://zuul.opendev.org/t/openstack/build/de9cf0fa91d34815ba3281e029c4f030 : SUCCESS in 2m 14s\n- openstack-helm-pre-commit https://zuul.opendev.org/t/openstack/build/4b663701f01e49b5af386f8d0a744365 : SUCCESS in 2m 48s\n- openstack-helm-build-charts https://zuul.opendev.org/t/openstack/build/6e0bc2788fb24c51b28d50db2bf73813 : SUCCESS in 6m 55s\n- openstack-helm-cinder-2025-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/9bc11f82a91b47299b239f4905a594dc : SUCCESS in 48m 34s\n- openstack-helm-compute-kit-2025-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/7698956e81174c3ba4b49cdd4354f991 : SUCCESS in 45m 55s\n- openstack-helm-cinder-2025-2-ubuntu_noble https://zuul.opendev.org/t/openstack/build/aa06d6629985464bba287fbf3e43901d : SUCCESS in 46m 12s\n- openstack-helm-compute-kit-2025-2-ubuntu_noble https://zuul.opendev.org/t/openstack/build/4baaf1ec7c754f968e162bedc4192f8c : SUCCESS in 43m 13s\n- openstack-helm-cinder-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/29f5fd33ccba4d9a985f4ae425f04b18 : SUCCESS in 40m 28s\n- openstack-helm-compute-kit-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/1d1b2bae7d6c4e01ae2b0da49689d5e6 : SUCCESS in 46m 48s\n- openstack-helm-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/87742e786fd64a969b8db70067ccf047 : FAILURE in 1h 29m 46s\n- openstack-helm-compute-kit-ovn-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/8b9161840df14f8daae747de9beade6e : SUCCESS in 1h 05m 43s\n- openstack-helm-compute-kit-dpdk-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/218db8cf545647cb95d9a571c88a3dc2 : SUCCESS in 54m 40s\n- openstack-helm-octavia-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/56648258719944d4ad8379029d7c7f4b : SUCCESS in 1h 28m 06s\n- openstack-helm-horizon-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/d616ee7738574034a585ec4374a2bbe1 : SUCCESS in 14m 35s\n- openstack-helm-logging https://zuul.opendev.org/t/openstack/build/3d8a57cebf154e3e8897f14f56e9280c : SUCCESS in 40m 37s\n- openstack-helm-monitoring https://zuul.opendev.org/t/openstack/build/ee0cde251f614213b6d75405b5d59d69 : SUCCESS in 21m 01s","accounts_in_message":[],"_revision_number":25},{"id":"0d89a0980f91366f186c82dd7b1cc023e82e071e","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-26 00:35:33.000000000","message":"Uploaded patch set 26.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":26},{"id":"7829f37785529dd19fe16a34c6a88ca6050940a5","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-26 01:24:32.000000000","message":"Patch Set 26: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/272564f094d34b25a09868ac81e38a92\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/d0b1e8774ce64ce6a7875044ed2fd38b : SUCCESS in 2m 27s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/1ceb5d9e46cf4ca48d89ac4c06950178 : SUCCESS in 3m 19s\n- openstack-helm-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/8b251609f31a4e8bafc67564914d7348 : FAILURE in 48m 07s","accounts_in_message":[],"_revision_number":26},{"id":"b942bae3a4a023a859a55d5723ca0aa2df039ca6","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-26 02:12:33.000000000","message":"Uploaded patch set 27.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":27},{"id":"b16656921dd44f17b5a219f33342f3571029b8e6","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-26 05:02:44.000000000","message":"Patch Set 27: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/3d918aa80c2a46ac9f1de1e4ae69e90a\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/415289db6367410a941c82d8d81898ed : SUCCESS in 5m 29s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/3ddc729840fc4f8f8d65f93cb7724af7 : SUCCESS in 3m 02s\n- openstack-helm-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/1d29cf02944c4a96a31323be3e15ced5 : FAILURE in 2h 00m 44s","accounts_in_message":[],"_revision_number":27},{"id":"d47d151ef7570bb218813d758d8d8e7abecb924f","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-26 20:14:27.000000000","message":"Uploaded patch set 28.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":28},{"id":"97c25b9c71622b35bc5dd95f7380473bfb5c139e","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-26 22:11:12.000000000","message":"Patch Set 28: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/fe4a8983f49b4cca9bc1693a3e97fbab\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/615764cea8554f68adc2d83d1419f9e2 : SUCCESS in 3m 15s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/67c346a148f2423b95186dbf489179ae : SUCCESS in 4m 40s\n- openstack-helm-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/264e35f760d34a7d8bf083125cfca830 : SUCCESS in 1h 46m 11s","accounts_in_message":[],"_revision_number":28},{"id":"27089cbc108d378ddfda3a1222acbcabd118cff3","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-26 22:17:26.000000000","message":"Uploaded patch set 29.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":29},{"id":"6c669d4e656fab6e6ed97ced28836fe8bbe931ed","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-26 23:51:38.000000000","message":"Patch Set 29: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/2e10cd73fcd84d4ba81d40ebbdb0e137\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/44f9e867bd1d49209e7740ee41bdf29f : SUCCESS in 3m 46s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/d9e98e81294c4c619a90aff60808ac9d : SUCCESS in 2m 58s\n- openstack-helm-linter https://zuul.opendev.org/t/openstack/build/663751d76dc34aedb3683e4a07f0c259 : SUCCESS in 2m 58s\n- openstack-helm-pre-commit https://zuul.opendev.org/t/openstack/build/588143df2b3b4ca08b62c552b3684d15 : SUCCESS in 2m 30s\n- openstack-helm-build-charts https://zuul.opendev.org/t/openstack/build/f039770a90f44be0870995a6e5e7c3cf : SUCCESS in 7m 11s\n- openstack-helm-cinder-2025-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/0c03640d490144a8b643b26e92f792d4 : SUCCESS in 25m 58s\n- openstack-helm-compute-kit-2025-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/d6b0cd74973043a9aa687f02b62773a0 : SUCCESS in 45m 44s\n- openstack-helm-cinder-2025-2-ubuntu_noble https://zuul.opendev.org/t/openstack/build/7ed2c865db924637aeafe72e70da331b : SUCCESS in 46m 42s\n- openstack-helm-compute-kit-2025-2-ubuntu_noble https://zuul.opendev.org/t/openstack/build/b08d6b0c2b6547288c7ef79c049285ef : SUCCESS in 1h 12m 24s\n- openstack-helm-cinder-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/3e0a9c500ee2489f948abedc42157f6e : SUCCESS in 29m 00s\n- openstack-helm-compute-kit-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/f0da2dc3e84740a9a045623f6101b58b : SUCCESS in 1h 18m 48s\n- openstack-helm-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/33c4d5c982644e5181b0f739ddd9570d : SUCCESS in 1h 01m 42s\n- openstack-helm-compute-kit-ovn-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/37f4cf258b52409a9bd6f57fd06c4cd1 : SUCCESS in 1h 06m 39s\n- openstack-helm-compute-kit-dpdk-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/e65faf5791a3444eb3c30be927f478ed : SUCCESS in 54m 54s\n- openstack-helm-octavia-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/8c2e457b518740a9aec6f8a7c6b106bd : SUCCESS in 1h 20m 03s\n- openstack-helm-horizon-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/7acd5b7191d84998a0e11e9139ae3015 : SUCCESS in 23m 35s\n- openstack-helm-logging https://zuul.opendev.org/t/openstack/build/782edaef3d924cab9902d2a23c90fbaf : SUCCESS in 32m 58s\n- openstack-helm-monitoring https://zuul.opendev.org/t/openstack/build/cbdba856bfe34a6b8be4f04340183214 : SUCCESS in 26m 44s","accounts_in_message":[],"_revision_number":29},{"id":"d2b74e309184d4bc14963b742476677ebaf629ed","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-06-30 17:39:21.000000000","message":"Patch Set 29:\n\n(1 comment)","accounts_in_message":[],"_revision_number":29},{"id":"1219f9f0e32d121bfc1ad666dd8b12ab3e28ae00","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-07-01 16:40:35.000000000","message":"Uploaded patch set 30.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":30},{"id":"87ba2855637cb73c1a0439b836986180c906d9ac","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-01 18:23:13.000000000","message":"Patch Set 30: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/bff7a8208211497d87e220b2dfc83668\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/1ba60d0536e04036885206ed27bd45f0 : SUCCESS in 2m 26s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/a772b46b1a59451c8958ef698f6b5f4c : SUCCESS in 4m 29s\n- openstack-helm-linter https://zuul.opendev.org/t/openstack/build/1dd6d19d5b2b4a1695ec39d105440b3d : SUCCESS in 2m 50s\n- openstack-helm-pre-commit https://zuul.opendev.org/t/openstack/build/30b9cee933804b36aaf14c7c6c8ae45e : SUCCESS in 4m 40s\n- openstack-helm-build-charts https://zuul.opendev.org/t/openstack/build/24011a4f4574459aad38d110f404ff74 : SUCCESS in 7m 53s\n- openstack-helm-cinder-2025-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/c327c275ac93403d95e0605d267ce2e4 : SUCCESS in 40m 10s\n- openstack-helm-compute-kit-2025-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/f977f8d095ab41f0926c8e74ea3d54f6 : SUCCESS in 1h 12m 52s\n- openstack-helm-cinder-2025-2-ubuntu_noble https://zuul.opendev.org/t/openstack/build/b71d289d9b924b3bafb0367edfc212fc : SUCCESS in 35m 40s\n- openstack-helm-compute-kit-2025-2-ubuntu_noble https://zuul.opendev.org/t/openstack/build/c00f3ad6dc824e798cfd422e692019ca : SUCCESS in 45m 27s\n- openstack-helm-cinder-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/e3470ca9c850497190d14fbf4cc0b4ee : SUCCESS in 48m 01s\n- openstack-helm-compute-kit-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/d58d6af71040450c8bd747854f567d33 : SUCCESS in 1h 14m 54s\n- openstack-helm-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/371c8dcd5ae34773ac59fa6e13ace9bb : SUCCESS in 1h 30m 22s\n- openstack-helm-compute-kit-ovn-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/a401e30a31d1474081caf34bd7cd2247 : SUCCESS in 45m 00s\n- openstack-helm-compute-kit-dpdk-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/49d9ecdab9424a8cad29a89ff4621045 : SUCCESS in 56m 16s\n- openstack-helm-octavia-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/d88976db9d874d41b32ebe47d2847e7a : SUCCESS in 45m 07s\n- openstack-helm-horizon-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/e7833e8d999e49b8b4cec07742ab5e81 : SUCCESS in 22m 20s\n- openstack-helm-logging https://zuul.opendev.org/t/openstack/build/f93c5b9e38c249aca22914e6a6f321a1 : SUCCESS in 45m 45s\n- openstack-helm-monitoring https://zuul.opendev.org/t/openstack/build/c217e6918a4e48da8db8ed09eb94c050 : SUCCESS in 34m 39s","accounts_in_message":[],"_revision_number":30},{"id":"e81b3c02a1403604069bfb39b70092b9c983d675","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-07-02 21:11:06.000000000","message":"Uploaded patch set 31.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":31},{"id":"a14ff99aeab526a971ac8487212be1bdd5e4e14e","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-02 23:02:47.000000000","message":"Patch Set 31: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/eb06425d00ae4bac9f58e2d0e89c5741\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/2e2af93e9e04475fae851496426d9100 : SUCCESS in 3m 56s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/665df2c5bc894cc29243ad1b5a71ef84 : SUCCESS in 2m 16s\n- openstack-helm-linter https://zuul.opendev.org/t/openstack/build/a5db44e4c5f1410988e0f05479659d4d : SUCCESS in 2m 19s\n- openstack-helm-pre-commit https://zuul.opendev.org/t/openstack/build/8b2d201b607544f0ae377b8218e6a516 : SUCCESS in 2m 35s\n- openstack-helm-build-charts https://zuul.opendev.org/t/openstack/build/e495f28adb494e00ad5ff231e61fb0cf : SUCCESS in 3m 10s\n- openstack-helm-cinder-2025-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/b3f7215eff9642fd8fb3eb4a231f89ec : SUCCESS in 35m 18s\n- openstack-helm-compute-kit-2025-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/7446cc8e03d94fd2913b5d42a620c7e3 : SUCCESS in 1h 15m 58s\n- openstack-helm-cinder-2025-2-ubuntu_noble https://zuul.opendev.org/t/openstack/build/ee87fc0f8a1f4d5f826b89c8853a14be : SUCCESS in 46m 48s\n- openstack-helm-compute-kit-2025-2-ubuntu_noble https://zuul.opendev.org/t/openstack/build/75416f716f004f7e8a7d2ecd072f2e3f : SUCCESS in 1h 12m 21s\n- openstack-helm-cinder-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/3dadc4973135465782a5f1f43678b8a0 : SUCCESS in 28m 06s\n- openstack-helm-compute-kit-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/41da26f2df024dfab1151899736af555 : SUCCESS in 46m 21s\n- openstack-helm-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/28bd61141b1945b1bf9d53c944608303 : SUCCESS in 1h 45m 43s\n- openstack-helm-compute-kit-ovn-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/ff1da1b9ce9243afac93188e49bc0ea8 : SUCCESS in 1h 03m 20s\n- openstack-helm-compute-kit-dpdk-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/755c7e4644564d678cfe0a9816191eae : SUCCESS in 56m 15s\n- openstack-helm-octavia-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/2008776452e84ce99855fa477669da27 : SUCCESS in 1h 20m 31s\n- openstack-helm-horizon-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/fe51f7d472384fa5ad22f58e33d0feda : SUCCESS in 24m 41s\n- openstack-helm-logging https://zuul.opendev.org/t/openstack/build/acb8f64c962c47188334e3485903b97f : SUCCESS in 39m 37s\n- openstack-helm-monitoring https://zuul.opendev.org/t/openstack/build/6cab040aef204d33950630e29e84e82f : SUCCESS in 32m 33s","accounts_in_message":[],"_revision_number":31},{"id":"ab8fe1096fecb6047a70d4a84198bcc1ddd95a92","author":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"date":"2026-07-06 14:47:26.000000000","message":"Patch Set 31: Code-Review+2","accounts_in_message":[],"_revision_number":31},{"id":"d4a189eb34d49a409e7102a9d2e2d305857ea895","author":{"_account_id":34520,"name":"Sergiy Markin","email":"smarkin@mirantis.com","username":"sm515x"},"date":"2026-07-06 17:36:31.000000000","message":"Patch Set 31: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":31},{"id":"853f2bc14651614bc49fb416bddb3b670d9ad29b","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-06 17:37:57.000000000","message":"Patch Set 31: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":31},{"id":"b2d1f12369ddb4828bcbc673a6cfe6a8ff6f1c3e","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-06 19:04:18.000000000","message":"Patch Set 31: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/075388bb2f1d407ab1202a532b6f114c\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/2a285275121248918b17233b52f30869 : SUCCESS in 5m 36s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/099e3744259a4ab2bbcf89e768db1200 : SUCCESS in 5m 32s\n- openstack-helm-linter https://zuul.opendev.org/t/openstack/build/62dd2c65d1bd41009ac0a552ee8d6380 : SUCCESS in 3m 51s\n- openstack-helm-cinder-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/1d86eed764354beaa65e68be8e16adf7 : SUCCESS in 30m 27s\n- openstack-helm-compute-kit-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/93801c565eb64fd8a2f0fe92d802d7e0 : SUCCESS in 1h 19m 23s\n- openstack-helm-logging https://zuul.opendev.org/t/openstack/build/0854308ec048443ba2c3f62ae00a7a74 : SUCCESS in 41m 56s\n- openstack-helm-monitoring https://zuul.opendev.org/t/openstack/build/3966531948fc4b85a66ad3bf90894022 : SUCCESS in 29m 38s","accounts_in_message":[],"_revision_number":31},{"id":"5dc4a2c14d1ae8ae68ecd5a8e00b87df046a1297","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-06 19:04:18.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":31},{"id":"f6551fa3c3628143f8d48a76d2ef8dd98aa2f0a6","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-06 19:09:57.000000000","message":"Patch Set 31:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/fc22ecb72f5c449f91615e3641236783\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/1485ad35f0c346029d61a35666535312 : SUCCESS in 1m 59s\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/6b6cb499e60f4491bd6cb848bbb5049d : SUCCESS in 40s","accounts_in_message":[],"_revision_number":31}],"current_revision_number":31,"current_revision":"d141687d3b237a3ed34e90ebafc7933b7cde7677","revisions":{"b2929c270473b67a16f50870d7afd535371006ba":{"kind":"REWORK","_number":1,"created":"2026-06-09 20:18:20.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/1"}}},"commit":{"parents":[{"commit":"72bc3884dff60cf56fa1320e98331fb96387af75","subject":"Use a dedicated client certificate for MariaDB TLS connections","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/72bc3884dff60cf56fa1320e98331fb96387af75"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 20:18:14.000000000","tz":-300},"subject":"keystone: Terminate API TLS with an nginx sidecar instead of Apache","message":"keystone: Terminate API TLS with an nginx sidecar instead of Apache\n\nReplace in-container Apache httpd TLS termination for the keystone API with\na dedicated nginx sidecar that terminates TLS and reverse-proxies to a uwsgi\nbackend in the same pod.\n\nThe keystone-api container now runs uwsgi directly, binding the identity\n\"service\" endpoint port (5000) over plain HTTP exactly as in the non-TLS\ncase. All Apache artifacts are removed: the conf.wsgi_keystone vhost,\nconf.software.apache2 settings, the mpm_event/security snippets and the\napache volumes, mounts and start/stop logic.\n\nNew pod.extraContainers.keystone_api / pod.extraVolumes.keystone_api hooks\nlet an override inject sidecar containers and volumes into the keystone-api\nDeployment. values_overrides/keystone/api-tls.yaml uses them to add an nginx\nsidecar that terminates TLS on port 443 (cert issued by ca-issuer) and proxies\nto 127.0.0.1:5000. When .Values.tls.identity is enabled the keystone-api\nService adds targetPort: 443 so in-cluster clients reach keystone over TLS on\nthe well-known service port, and the internal/default endpoint scheme flips to\nhttps.\n\nThe api-tls.yaml override is added to the openstack-helm-compute-kit-tls\njob. All other Zuul jobs are temporarily commented out in zuul.d/project.yaml\nwhile the nginx sidecar migration is iterated on, and must be restored before\nmerge.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/b2929c270473b67a16f50870d7afd535371006ba"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/b2929c270473b67a16f50870d7afd535371006ba"}]},"branch":"refs/heads/master"},"07996520e785d5802380349815043b379cfeaa5d":{"kind":"REWORK","_number":2,"created":"2026-06-09 20:37:45.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/2"}}},"commit":{"parents":[{"commit":"72bc3884dff60cf56fa1320e98331fb96387af75","subject":"Use a dedicated client certificate for MariaDB TLS connections","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/72bc3884dff60cf56fa1320e98331fb96387af75"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 20:37:23.000000000","tz":-300},"subject":"[WIP] keystone: Terminate API TLS with an nginx sidecar instead of Apache","message":"[WIP] keystone: Terminate API TLS with an nginx sidecar instead of Apache\n\nReplace in-container Apache httpd TLS termination for the keystone API with\na dedicated nginx sidecar that terminates TLS and reverse-proxies to a uwsgi\nbackend in the same pod.\n\nThe keystone-api container now runs uwsgi directly, binding the identity\n\"service\" endpoint port (5000) over plain HTTP exactly as in the non-TLS\ncase. All Apache artifacts are removed: the conf.wsgi_keystone vhost,\nconf.software.apache2 settings, the mpm_event/security snippets and the\napache volumes, mounts and start/stop logic.\n\nNew pod.extraContainers.keystone_api / pod.extraVolumes.keystone_api hooks\nlet an override inject sidecar containers and volumes into the keystone-api\nDeployment. values_overrides/keystone/api-tls.yaml uses them to add an nginx\nsidecar that terminates TLS on port 443 (cert issued by ca-issuer) and proxies\nto 127.0.0.1:5000. When .Values.tls.identity is enabled the keystone-api\nService adds targetPort: 443 so in-cluster clients reach keystone over TLS on\nthe well-known service port, and the internal/default endpoint scheme flips to\nhttps.\n\nThe api-tls.yaml override is added to the openstack-helm-compute-kit-tls\njob. All other Zuul jobs are temporarily commented out in zuul.d/project.yaml\nwhile the nginx sidecar migration is iterated on, and must be restored before\nmerge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/07996520e785d5802380349815043b379cfeaa5d"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/07996520e785d5802380349815043b379cfeaa5d"}]},"branch":"refs/heads/master"},"fb3c4e8f7af6cf066b1fbf0d87d4fc74fc0ec03e":{"kind":"REWORK","_number":3,"created":"2026-06-09 20:53:21.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/3"}}},"commit":{"parents":[{"commit":"72bc3884dff60cf56fa1320e98331fb96387af75","subject":"Use a dedicated client certificate for MariaDB TLS connections","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/72bc3884dff60cf56fa1320e98331fb96387af75"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 20:52:47.000000000","tz":-300},"subject":"[WIP] keystone: Terminate API TLS with an nginx sidecar instead of Apache","message":"[WIP] keystone: Terminate API TLS with an nginx sidecar instead of Apache\n\nReplace in-container Apache httpd TLS termination for the keystone API with\na dedicated nginx sidecar that terminates TLS and reverse-proxies to a uwsgi\nbackend in the same pod.\n\nThe keystone-api container now runs uwsgi directly, binding the identity\n\"service\" endpoint port (5000) over plain HTTP exactly as in the non-TLS\ncase. All Apache artifacts are removed: the conf.wsgi_keystone vhost,\nconf.software.apache2 settings, the mpm_event/security snippets and the\napache volumes, mounts and start/stop logic.\n\nNew pod.extraContainers.keystone_api / pod.extraVolumes.keystone_api hooks\nlet an override inject sidecar containers and volumes into the keystone-api\nDeployment. values_overrides/keystone/api-tls.yaml uses them to add an nginx\nsidecar that terminates TLS on port 443 (cert issued by ca-issuer) and proxies\nto 127.0.0.1:5000. When .Values.tls.identity is enabled the keystone-api\nService adds targetPort: 443 so in-cluster clients reach keystone over TLS on\nthe well-known service port, and the internal/default endpoint scheme flips to\nhttps.\n\nThe api-tls.yaml override is added to the openstack-helm-compute-kit-tls\njob. All other Zuul jobs are temporarily commented out in zuul.d/project.yaml\nwhile the nginx sidecar migration is iterated on, and must be restored before\nmerge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/fb3c4e8f7af6cf066b1fbf0d87d4fc74fc0ec03e"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/fb3c4e8f7af6cf066b1fbf0d87d4fc74fc0ec03e"}]},"branch":"refs/heads/master"},"4ad34ff6c2acbc773cfc97096437b00f973fb4cb":{"kind":"REWORK","_number":4,"created":"2026-06-09 22:53:05.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/4"}}},"commit":{"parents":[{"commit":"72bc3884dff60cf56fa1320e98331fb96387af75","subject":"Use a dedicated client certificate for MariaDB TLS connections","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/72bc3884dff60cf56fa1320e98331fb96387af75"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 22:52:52.000000000","tz":-300},"subject":"[WIP] keystone: Terminate API TLS with an nginx sidecar instead of Apache","message":"[WIP] keystone: Terminate API TLS with an nginx sidecar instead of Apache\n\nReplace in-container Apache httpd TLS termination for the keystone API with\na dedicated nginx sidecar that terminates TLS and reverse-proxies to a uwsgi\nbackend in the same pod.\n\nThe keystone-api container now runs uwsgi directly, binding the identity\n\"service\" endpoint port (5000) over plain HTTP exactly as in the non-TLS\ncase. All Apache artifacts are removed: the conf.wsgi_keystone vhost,\nconf.software.apache2 settings, the mpm_event/security snippets and the\napache volumes, mounts and start/stop logic.\n\nNew pod.extraContainers.keystone_api / pod.extraVolumes.keystone_api hooks\nlet an override inject sidecar containers and volumes into the keystone-api\nDeployment. values_overrides/keystone/api-tls.yaml uses them to add an nginx\nsidecar that terminates TLS on port 443 (cert issued by ca-issuer) and proxies\nto 127.0.0.1:5000. When .Values.tls.identity is enabled the keystone-api\nService adds targetPort: 443 so in-cluster clients reach keystone over TLS on\nthe well-known service port, and the internal/default endpoint scheme flips to\nhttps.\n\nThe api-tls.yaml override is added to the openstack-helm-compute-kit-tls\njob. All other Zuul jobs are temporarily commented out in zuul.d/project.yaml\nwhile the nginx sidecar migration is iterated on, and must be restored before\nmerge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/4ad34ff6c2acbc773cfc97096437b00f973fb4cb"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/4ad34ff6c2acbc773cfc97096437b00f973fb4cb"}]},"branch":"refs/heads/master"},"ad8c91dfe3460ae2c9d96b48cca50e3c92d1d847":{"kind":"REWORK","_number":5,"created":"2026-06-09 23:14:36.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/5"}}},"commit":{"parents":[{"commit":"72bc3884dff60cf56fa1320e98331fb96387af75","subject":"Use a dedicated client certificate for MariaDB TLS connections","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/72bc3884dff60cf56fa1320e98331fb96387af75"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 23:14:25.000000000","tz":-300},"subject":"[WIP] keystone: Terminate API TLS with an nginx sidecar instead of Apache","message":"[WIP] keystone: Terminate API TLS with an nginx sidecar instead of Apache\n\nReplace in-container Apache httpd TLS termination for the keystone API with\na dedicated nginx sidecar that terminates TLS and reverse-proxies to a uwsgi\nbackend in the same pod.\n\nThe keystone-api container now runs uwsgi directly, binding the identity\n\"service\" endpoint port (5000) over plain HTTP exactly as in the non-TLS\ncase. All Apache artifacts are removed: the conf.wsgi_keystone vhost,\nconf.software.apache2 settings, the mpm_event/security snippets and the\napache volumes, mounts and start/stop logic.\n\nNew pod.extraContainers.keystone_api / pod.extraVolumes.keystone_api hooks\nlet an override inject sidecar containers and volumes into the keystone-api\nDeployment. values_overrides/keystone/api-tls.yaml uses them to add an nginx\nsidecar that terminates TLS on port 443 (cert issued by ca-issuer) and proxies\nto 127.0.0.1:5000. When .Values.tls.identity is enabled the keystone-api\nService adds targetPort: 443 so in-cluster clients reach keystone over TLS on\nthe well-known service port, and the internal/default endpoint scheme flips to\nhttps.\n\nThe api-tls.yaml override is added to the openstack-helm-compute-kit-tls\njob. All other Zuul jobs are temporarily commented out in zuul.d/project.yaml\nwhile the nginx sidecar migration is iterated on, and must be restored before\nmerge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/ad8c91dfe3460ae2c9d96b48cca50e3c92d1d847"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/ad8c91dfe3460ae2c9d96b48cca50e3c92d1d847"}]},"branch":"refs/heads/master"},"9d496ede28592052266b1a844ff1b4230b300cf8":{"kind":"REWORK","_number":6,"created":"2026-06-10 01:15:31.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/6","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/6","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/6"}}},"commit":{"parents":[{"commit":"72bc3884dff60cf56fa1320e98331fb96387af75","subject":"Use a dedicated client certificate for MariaDB TLS connections","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/72bc3884dff60cf56fa1320e98331fb96387af75"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-10 01:15:28.000000000","tz":-300},"subject":"[WIP] keystone: Terminate API TLS with an nginx sidecar instead of Apache","message":"[WIP] keystone: Terminate API TLS with an nginx sidecar instead of Apache\n\nReplace in-container Apache httpd TLS termination for the keystone API with\na dedicated nginx sidecar that terminates TLS and reverse-proxies to a uwsgi\nbackend in the same pod.\n\nThe keystone-api container now runs uwsgi directly, binding the identity\n\"service\" endpoint port (5000) over plain HTTP exactly as in the non-TLS\ncase. All Apache artifacts are removed: the conf.wsgi_keystone vhost,\nconf.software.apache2 settings, the mpm_event/security snippets and the\napache volumes, mounts and start/stop logic.\n\nNew pod.extraContainers.keystone_api / pod.extraVolumes.keystone_api hooks\nlet an override inject sidecar containers and volumes into the keystone-api\nDeployment. values_overrides/keystone/api-tls.yaml uses them to add an nginx\nsidecar that terminates TLS on port 443 (cert issued by ca-issuer) and proxies\nto 127.0.0.1:5000. When .Values.tls.identity is enabled the keystone-api\nService adds targetPort: 443 so in-cluster clients reach keystone over TLS on\nthe well-known service port, and the internal/default endpoint scheme flips to\nhttps.\n\nThe api-tls.yaml override is added to the openstack-helm-compute-kit-tls\njob. All other Zuul jobs are temporarily commented out in zuul.d/project.yaml\nwhile the nginx sidecar migration is iterated on, and must be restored before\nmerge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/9d496ede28592052266b1a844ff1b4230b300cf8"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/9d496ede28592052266b1a844ff1b4230b300cf8"}]},"branch":"refs/heads/master"},"8469336892811c90a22a2e45add039712fe797a9":{"kind":"REWORK","_number":7,"created":"2026-06-10 04:04:02.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/7","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/7","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/7"}}},"commit":{"parents":[{"commit":"72bc3884dff60cf56fa1320e98331fb96387af75","subject":"Use a dedicated client certificate for MariaDB TLS connections","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/72bc3884dff60cf56fa1320e98331fb96387af75"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-10 04:03:54.000000000","tz":-300},"subject":"[WIP] Terminate API TLS with nginx sidecars instead of Apache","message":"[WIP] Terminate API TLS with nginx sidecars instead of Apache\n\nReplace in-container Apache httpd / chart-native nginx TLS termination for the\nOpenStack API services with a uniform nginx TLS-terminating sidecar injected\nvia pod.extraContainers, across keystone, glance, heat (api+cfn),\nnova (osapi+metadata), neutron and placement.\n\nFor each API component:\n\n* The main container runs uwsgi directly (Apache removed where present),\n  binding the endpoint \"service\" scope port over plain HTTP exactly as in the\n  non-TLS case; liveness/readiness probes hit that backend directly.\n* New pod.extraContainers.\u003ccomponent\u003e / pod.extraVolumes.\u003ccomponent\u003e hooks let\n  the per-chart values_overrides/\u003cchart\u003e/api-tls.yaml override inject an nginx\n  sidecar that terminates TLS on port 443 and reverse-proxies to the uwsgi\n  backend.\n* TLS is toggled independently per API service via .Values.tls.\u003cservice\u003e. When\n  enabled the chart issues the server certificate (gated on tls.\u003cservice\u003e, not\n  manifests.certificates, to avoid forcing RabbitMQ/DB TLS), renders the nginx\n  config ConfigMap and a Gateway API BackendTLSPolicy so the Envoy Gateway\n  re-encrypts to the sidecar, and the API Service gains targetPort: 443.\n* glance and neutron, which shipped a chart-native nginx sidecar, are converted\n  to the same extraContainers approach.\n* Consumer side: each service trusts the in-cluster TLS endpoints via the\n  ca-issuer CA (keystone_authtoken/clients cafile) and an https identity scheme.\n\nThe api-tls.yaml overrides are added to the openstack-helm-compute-kit-tls job.\nAll other Zuul jobs are temporarily commented out in zuul.d/project.yaml while\nthis is iterated on, and must be restored before merge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/8469336892811c90a22a2e45add039712fe797a9"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/8469336892811c90a22a2e45add039712fe797a9"}]},"branch":"refs/heads/master"},"a8170df62c62773eef276bef854ce1f86cdf0a84":{"kind":"REWORK","_number":8,"created":"2026-06-10 04:26:15.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/8","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/8","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/8 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/8 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/8 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/8"}}},"commit":{"parents":[{"commit":"72bc3884dff60cf56fa1320e98331fb96387af75","subject":"Use a dedicated client certificate for MariaDB TLS connections","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/72bc3884dff60cf56fa1320e98331fb96387af75"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-10 04:26:12.000000000","tz":-300},"subject":"[WIP] Terminate API TLS with nginx sidecars instead of Apache","message":"[WIP] Terminate API TLS with nginx sidecars instead of Apache\n\nReplace in-container Apache httpd / chart-native nginx TLS termination for the\nOpenStack API services with a uniform nginx TLS-terminating sidecar injected\nvia pod.extraContainers, across keystone, glance, heat (api+cfn),\nnova (osapi+metadata), neutron and placement.\n\nFor each API component:\n\n* The main container runs uwsgi directly (Apache removed where present),\n  binding the endpoint \"service\" scope port over plain HTTP exactly as in the\n  non-TLS case; liveness/readiness probes hit that backend directly.\n* New pod.extraContainers.\u003ccomponent\u003e / pod.extraVolumes.\u003ccomponent\u003e hooks let\n  the per-chart values_overrides/\u003cchart\u003e/api-tls.yaml override inject an nginx\n  sidecar that terminates TLS on port 443 and reverse-proxies to the uwsgi\n  backend.\n* TLS is toggled independently per API service via .Values.tls.\u003cservice\u003e. When\n  enabled the chart issues the server certificate (gated on tls.\u003cservice\u003e, not\n  manifests.certificates, to avoid forcing RabbitMQ/DB TLS), renders the nginx\n  config ConfigMap and a Gateway API BackendTLSPolicy so the Envoy Gateway\n  re-encrypts to the sidecar, and the API Service gains targetPort: 443.\n* glance and neutron, which shipped a chart-native nginx sidecar, are converted\n  to the same extraContainers approach.\n* Consumer side: each service trusts the in-cluster TLS endpoints via the\n  ca-issuer CA (keystone_authtoken/clients cafile) and an https identity scheme.\n\nThe api-tls.yaml overrides are added to the openstack-helm-compute-kit-tls job.\nAll other Zuul jobs are temporarily commented out in zuul.d/project.yaml while\nthis is iterated on, and must be restored before merge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/a8170df62c62773eef276bef854ce1f86cdf0a84"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/a8170df62c62773eef276bef854ce1f86cdf0a84"}]},"branch":"refs/heads/master"},"de7616f5a1922507e43f96bfcda48e3169bb3eb4":{"kind":"REWORK","_number":9,"created":"2026-06-10 05:11:14.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/9","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/9","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/9 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/9 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/9 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/9"}}},"commit":{"parents":[{"commit":"72bc3884dff60cf56fa1320e98331fb96387af75","subject":"Use a dedicated client certificate for MariaDB TLS connections","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/72bc3884dff60cf56fa1320e98331fb96387af75"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-10 05:11:12.000000000","tz":-300},"subject":"[WIP] Terminate API TLS with nginx sidecars instead of Apache","message":"[WIP] Terminate API TLS with nginx sidecars instead of Apache\n\nReplace in-container Apache httpd / chart-native nginx TLS termination for the\nOpenStack API services with a uniform nginx TLS-terminating sidecar injected\nvia pod.extraContainers, across keystone, glance, heat (api+cfn),\nnova (osapi+metadata), neutron and placement.\n\nFor each API component:\n\n* The main container runs uwsgi directly (Apache removed where present),\n  binding the endpoint \"service\" scope port over plain HTTP exactly as in the\n  non-TLS case; liveness/readiness probes hit that backend directly.\n* New pod.extraContainers.\u003ccomponent\u003e / pod.extraVolumes.\u003ccomponent\u003e hooks let\n  the per-chart values_overrides/\u003cchart\u003e/api-tls.yaml override inject an nginx\n  sidecar that terminates TLS on port 443 and reverse-proxies to the uwsgi\n  backend.\n* TLS is toggled independently per API service via .Values.tls.\u003cservice\u003e. When\n  enabled the chart issues the server certificate (gated on tls.\u003cservice\u003e, not\n  manifests.certificates, to avoid forcing RabbitMQ/DB TLS), renders the nginx\n  config ConfigMap and a Gateway API BackendTLSPolicy so the Envoy Gateway\n  re-encrypts to the sidecar, and the API Service gains targetPort: 443.\n* glance and neutron, which shipped a chart-native nginx sidecar, are converted\n  to the same extraContainers approach.\n* Consumer side: each service trusts the in-cluster TLS endpoints via the\n  ca-issuer CA (keystone_authtoken/clients cafile) and an https identity scheme.\n\nThe api-tls.yaml overrides are added to the openstack-helm-compute-kit-tls job.\nAll other Zuul jobs are temporarily commented out in zuul.d/project.yaml while\nthis is iterated on, and must be restored before merge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/de7616f5a1922507e43f96bfcda48e3169bb3eb4"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/de7616f5a1922507e43f96bfcda48e3169bb3eb4"}]},"branch":"refs/heads/master"},"5e7115b40fe03644a6758402a7bfb0436e247b22":{"kind":"REWORK","_number":10,"created":"2026-06-10 06:38:16.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/10","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/10","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/10 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/10 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/10 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/10"}}},"commit":{"parents":[{"commit":"72bc3884dff60cf56fa1320e98331fb96387af75","subject":"Use a dedicated client certificate for MariaDB TLS connections","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/72bc3884dff60cf56fa1320e98331fb96387af75"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-10 06:38:13.000000000","tz":-300},"subject":"[WIP] Terminate API TLS with nginx sidecars instead of Apache","message":"[WIP] Terminate API TLS with nginx sidecars instead of Apache\n\nReplace in-container Apache httpd / chart-native nginx TLS termination for the\nOpenStack API services with a uniform nginx TLS-terminating sidecar injected\nvia pod.extraContainers, across keystone, glance, heat (api+cfn),\nnova (osapi+metadata), neutron and placement.\n\nFor each API component:\n\n* The main container runs uwsgi directly (Apache removed where present),\n  binding the endpoint \"service\" scope port over plain HTTP exactly as in the\n  non-TLS case; liveness/readiness probes hit that backend directly.\n* New pod.extraContainers.\u003ccomponent\u003e / pod.extraVolumes.\u003ccomponent\u003e hooks let\n  the per-chart values_overrides/\u003cchart\u003e/api-tls.yaml override inject an nginx\n  sidecar that terminates TLS on port 443 and reverse-proxies to the uwsgi\n  backend.\n* TLS is toggled independently per API service via .Values.tls.\u003cservice\u003e. When\n  enabled the chart issues the server certificate (gated on tls.\u003cservice\u003e, not\n  manifests.certificates, to avoid forcing RabbitMQ/DB TLS), renders the nginx\n  config ConfigMap and a Gateway API BackendTLSPolicy so the Envoy Gateway\n  re-encrypts to the sidecar, and the API Service gains targetPort: 443.\n* glance and neutron, which shipped a chart-native nginx sidecar, are converted\n  to the same extraContainers approach.\n* Consumer side: each service trusts the in-cluster TLS endpoints via the\n  ca-issuer CA (keystone_authtoken/clients cafile) and an https identity scheme.\n\nThe api-tls.yaml overrides are added to the openstack-helm-compute-kit-tls job.\nAll other Zuul jobs are temporarily commented out in zuul.d/project.yaml while\nthis is iterated on, and must be restored before merge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/5e7115b40fe03644a6758402a7bfb0436e247b22"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/5e7115b40fe03644a6758402a7bfb0436e247b22"}]},"branch":"refs/heads/master"},"37523b6920025abca6b7fdf2fd49b73bc718266a":{"kind":"REWORK","_number":11,"created":"2026-06-10 14:30:40.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/11","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/11","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/11 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/11 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/11 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/11"}}},"commit":{"parents":[{"commit":"72bc3884dff60cf56fa1320e98331fb96387af75","subject":"Use a dedicated client certificate for MariaDB TLS connections","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/72bc3884dff60cf56fa1320e98331fb96387af75"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-10 14:30:37.000000000","tz":-300},"subject":"[WIP] Terminate API TLS with nginx sidecars instead of Apache","message":"[WIP] Terminate API TLS with nginx sidecars instead of Apache\n\nReplace in-container Apache httpd / chart-native nginx TLS termination for the\nOpenStack API services with a uniform nginx TLS-terminating sidecar injected\nvia pod.extraContainers, across keystone, glance, heat (api+cfn),\nnova (osapi+metadata), neutron and placement.\n\nFor each API component:\n\n* The main container runs uwsgi directly (Apache removed where present),\n  binding the endpoint \"service\" scope port over plain HTTP exactly as in the\n  non-TLS case; liveness/readiness probes hit that backend directly.\n* New pod.extraContainers.\u003ccomponent\u003e / pod.extraVolumes.\u003ccomponent\u003e hooks let\n  the per-chart values_overrides/\u003cchart\u003e/api-tls.yaml override inject an nginx\n  sidecar that terminates TLS on port 443 and reverse-proxies to the uwsgi\n  backend.\n* TLS is toggled independently per API service via .Values.tls.\u003cservice\u003e. When\n  enabled the chart issues the server certificate (gated on tls.\u003cservice\u003e, not\n  manifests.certificates, to avoid forcing RabbitMQ/DB TLS), renders the nginx\n  config ConfigMap and a Gateway API BackendTLSPolicy so the Envoy Gateway\n  re-encrypts to the sidecar, and the API Service gains targetPort: 443.\n* glance and neutron, which shipped a chart-native nginx sidecar, are converted\n  to the same extraContainers approach.\n* Consumer side: each service trusts the in-cluster TLS endpoints via the\n  ca-issuer CA (keystone_authtoken/clients cafile) and an https identity scheme.\n\nThe api-tls.yaml overrides are added to the openstack-helm-compute-kit-tls job.\nAll other Zuul jobs are temporarily commented out in zuul.d/project.yaml while\nthis is iterated on, and must be restored before merge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/37523b6920025abca6b7fdf2fd49b73bc718266a"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/37523b6920025abca6b7fdf2fd49b73bc718266a"}]},"branch":"refs/heads/master"},"e225ade2a0de72b140da61694ea8ef0a1aa7625d":{"kind":"REWORK","_number":12,"created":"2026-06-10 16:23:25.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/12","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/12","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/12 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/12 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/12 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/12"}}},"commit":{"parents":[{"commit":"72bc3884dff60cf56fa1320e98331fb96387af75","subject":"Use a dedicated client certificate for MariaDB TLS connections","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/72bc3884dff60cf56fa1320e98331fb96387af75"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-10 16:23:22.000000000","tz":-300},"subject":"[WIP] Terminate API TLS with nginx sidecars instead of Apache","message":"[WIP] Terminate API TLS with nginx sidecars instead of Apache\n\nReplace in-container Apache httpd / chart-native nginx TLS termination for the\nOpenStack API services with a uniform nginx TLS-terminating sidecar injected\nvia pod.extraContainers, across keystone, glance, heat (api+cfn),\nnova (osapi+metadata), neutron and placement.\n\nFor each API component:\n\n* The main container runs uwsgi directly (Apache removed where present),\n  binding the endpoint \"service\" scope port over plain HTTP exactly as in the\n  non-TLS case; liveness/readiness probes hit that backend directly.\n* New pod.extraContainers.\u003ccomponent\u003e / pod.extraVolumes.\u003ccomponent\u003e hooks let\n  the per-chart values_overrides/\u003cchart\u003e/api-tls.yaml override inject an nginx\n  sidecar that terminates TLS on port 443 and reverse-proxies to the uwsgi\n  backend.\n* TLS is toggled independently per API service via .Values.tls.\u003cservice\u003e. When\n  enabled the chart issues the server certificate (gated on tls.\u003cservice\u003e, not\n  manifests.certificates, to avoid forcing RabbitMQ/DB TLS), renders the nginx\n  config ConfigMap and a Gateway API BackendTLSPolicy so the Envoy Gateway\n  re-encrypts to the sidecar, and the API Service gains targetPort: 443.\n* glance and neutron, which shipped a chart-native nginx sidecar, are converted\n  to the same extraContainers approach.\n* Consumer side: each service trusts the in-cluster TLS endpoints via the\n  ca-issuer CA (keystone_authtoken/clients cafile) and an https identity scheme.\n\nThe api-tls.yaml overrides are added to the openstack-helm-compute-kit-tls job.\nAll other Zuul jobs are temporarily commented out in zuul.d/project.yaml while\nthis is iterated on, and must be restored before merge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/e225ade2a0de72b140da61694ea8ef0a1aa7625d"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/e225ade2a0de72b140da61694ea8ef0a1aa7625d"}]},"branch":"refs/heads/master"},"6d7917f752a22960459cee72de482f9c5505b985":{"kind":"REWORK","_number":13,"created":"2026-06-10 20:07:46.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/13","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/13","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/13 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/13 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/13 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/13"}}},"commit":{"parents":[{"commit":"72bc3884dff60cf56fa1320e98331fb96387af75","subject":"Use a dedicated client certificate for MariaDB TLS connections","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/72bc3884dff60cf56fa1320e98331fb96387af75"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-10 20:07:37.000000000","tz":-300},"subject":"[WIP] Terminate API TLS with nginx sidecars instead of Apache","message":"[WIP] Terminate API TLS with nginx sidecars instead of Apache\n\nReplace in-container Apache httpd / chart-native nginx TLS termination for the\nOpenStack API services with a uniform nginx TLS-terminating sidecar injected\nvia pod.extraContainers, across keystone, glance, heat (api+cfn),\nnova (osapi+metadata), neutron and placement.\n\nFor each API component:\n\n* The main container runs uwsgi directly (Apache removed where present),\n  binding the endpoint \"service\" scope port over plain HTTP exactly as in the\n  non-TLS case; liveness/readiness probes hit that backend directly.\n* New pod.extraContainers.\u003ccomponent\u003e / pod.extraVolumes.\u003ccomponent\u003e hooks let\n  the per-chart values_overrides/\u003cchart\u003e/api-tls.yaml override inject an nginx\n  sidecar that terminates TLS on port 443 and reverse-proxies to the uwsgi\n  backend.\n* TLS is toggled independently per API service via .Values.tls.\u003cservice\u003e. When\n  enabled the chart issues the server certificate and renders the nginx config\n  ConfigMap (both gated on tls.\u003cservice\u003e, not manifests.certificates, to avoid\n  forcing RabbitMQ/DB TLS), and the API Service gains targetPort: 443.\n* Exposing the service via the Gateway API stays in the overrides: the\n  gateway-tls.yaml extraObjects carry the HTTPRoute and (gated on tls.\u003cservice\u003e)\n  a BackendTLSPolicy so the Envoy Gateway re-encrypts to the sidecar. Charts\n  remain independent of how services are exposed outside the cluster.\n* glance and neutron, which shipped a chart-native nginx sidecar, are converted\n  to the same extraContainers approach.\n* Consumer side: each service trusts the in-cluster TLS endpoints via the\n  ca-issuer CA (keystone_authtoken/clients cafile, https client schemes, and\n  the neutron metadata agent reaches nova-metadata over https).\n\nThe api-tls.yaml overrides are added to the openstack-helm-compute-kit-tls job.\nAll other Zuul jobs are temporarily commented out in zuul.d/project.yaml while\nthis is iterated on, and must be restored before merge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/6d7917f752a22960459cee72de482f9c5505b985"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/6d7917f752a22960459cee72de482f9c5505b985"}]},"branch":"refs/heads/master"},"78e9c027a07521cbae31c9ad01fa00380b0c73c3":{"kind":"REWORK","_number":14,"created":"2026-06-10 22:00:35.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/14","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/14","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/14 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/14 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/14 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/14"}}},"commit":{"parents":[{"commit":"72bc3884dff60cf56fa1320e98331fb96387af75","subject":"Use a dedicated client certificate for MariaDB TLS connections","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/72bc3884dff60cf56fa1320e98331fb96387af75"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-10 21:40:38.000000000","tz":-300},"subject":"[WIP] Terminate API TLS with nginx sidecars instead of Apache","message":"[WIP] Terminate API TLS with nginx sidecars instead of Apache\n\nReplace in-container Apache httpd / chart-native nginx TLS termination for the\nOpenStack API services with a uniform nginx TLS-terminating sidecar, across\nkeystone, glance, heat (api+cfn), nova (osapi+metadata), neutron and placement.\n\nFor each API component:\n\n* The main container runs uwsgi directly (Apache removed where present),\n  binding the endpoint \"service\" scope port over plain HTTP exactly as in the\n  non-TLS case; liveness/readiness probes hit that backend directly.\n* New pod.extraContainers.\u003ccomponent\u003e / pod.extraVolumes.\u003ccomponent\u003e render\n  hooks let an override inject an nginx sidecar that terminates TLS on port 443\n  and reverse-proxies to the uwsgi backend.\n* TLS is toggled per service via .Values.tls.\u003cservice\u003e. When enabled the chart\n  issues the server certificate (gated on tls.\u003cservice\u003e, not\n  manifests.certificates, to avoid forcing RabbitMQ/DB TLS) and the API Service\n  gains targetPort: 443.\n\nExposure and the TLS objects live entirely in the overrides so the charts stay\nindependent of how services are exposed outside the cluster:\n\n* gateway-tls.yaml (unchanged) covers public-endpoint TLS only (gateway\n  terminates public TLS, plain HTTP to the backend).\n* gateway-api-tls.yaml is a new, self-contained \"secure everywhere\" override:\n  public TLS plus gateway\u003c-\u003epod TLS. It carries the nginx sidecar\n  (extraContainers/extraVolumes), the https schemes, the cert config and the\n  consumer-trust settings, and its extraObjects hold the HTTPRoute(s), the\n  nginx config ConfigMap(s) and the BackendTLSPolicy(ies) (so the Envoy Gateway\n  re-encrypts to the sidecar). The compute-kit-tls job uses this override.\n\n* glance and neutron, which shipped a chart-native nginx sidecar, are converted\n  to the same extraContainers approach.\n* Consumer side: each service trusts the in-cluster TLS endpoints via the\n  ca-issuer CA (keystone_authtoken/clients cafile, https client schemes, ks-*\n  registration jobs and rally test pods get the CA, and the neutron metadata\n  agent reaches nova-metadata over https).\n\nAll other Zuul jobs are temporarily commented out in zuul.d/project.yaml while\nthis is iterated on, and must be restored before merge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/78e9c027a07521cbae31c9ad01fa00380b0c73c3"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/78e9c027a07521cbae31c9ad01fa00380b0c73c3"}]},"branch":"refs/heads/master"},"9acb8b1ece8224d1c4cfb63f7d65892f7a322c1f":{"kind":"REWORK","_number":15,"created":"2026-06-12 22:08:20.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/15","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/15","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/15 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/15 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/15 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/15"}}},"commit":{"parents":[{"commit":"929e023e86e1002c36cf625470cb54c60fb04f3c","subject":"Use mTLS and a shared client certificate for RabbitMQ","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/929e023e86e1002c36cf625470cb54c60fb04f3c"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-12 22:05:17.000000000","tz":-300},"subject":"[WIP] Terminate API TLS with nginx sidecars instead of Apache","message":"[WIP] Terminate API TLS with nginx sidecars instead of Apache\n\nReplace in-container Apache httpd / chart-native nginx TLS termination for the\nOpenStack API services with a uniform nginx TLS-terminating sidecar, across\nkeystone, glance, heat (api+cfn), nova (osapi+metadata), neutron and placement.\n\nFor each API component:\n\n* The main container runs uwsgi directly (Apache removed where present),\n  binding the endpoint \"service\" scope port over plain HTTP exactly as in the\n  non-TLS case; liveness/readiness probes hit that backend directly.\n* New pod.extraContainers.\u003ccomponent\u003e / pod.extraVolumes.\u003ccomponent\u003e render\n  hooks let an override inject an nginx sidecar that terminates TLS on port 443\n  and reverse-proxies to the uwsgi backend.\n* TLS is toggled per service via .Values.tls.\u003cservice\u003e. When enabled the chart\n  issues the server certificate (gated on tls.\u003cservice\u003e, not\n  manifests.certificates, to avoid forcing RabbitMQ/DB TLS) and the API Service\n  gains targetPort: 443.\n\nExposure and the TLS objects live entirely in the overrides so the charts stay\nindependent of how services are exposed outside the cluster:\n\n* gateway-tls.yaml (unchanged) covers public-endpoint TLS only (gateway\n  terminates public TLS, plain HTTP to the backend).\n* gateway-api-tls.yaml is a new, self-contained \"secure everywhere\" override:\n  public TLS plus gateway\u003c-\u003epod TLS. It carries the nginx sidecar\n  (extraContainers/extraVolumes), the https schemes, the cert config and the\n  consumer-trust settings, and its extraObjects hold the HTTPRoute(s), the\n  nginx config ConfigMap(s) and the BackendTLSPolicy(ies) (so the Envoy Gateway\n  re-encrypts to the sidecar). The compute-kit-tls job uses this override.\n\n* glance and neutron, which shipped a chart-native nginx sidecar, are converted\n  to the same extraContainers approach.\n* Consumer side: each service trusts the in-cluster TLS endpoints via the\n  ca-issuer CA (keystone_authtoken/clients cafile, https client schemes, ks-*\n  registration jobs and rally test pods get the CA, and the neutron metadata\n  agent reaches nova-metadata over https).\n\nAll other Zuul jobs are temporarily commented out in zuul.d/project.yaml while\nthis is iterated on, and must be restored before merge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/9acb8b1ece8224d1c4cfb63f7d65892f7a322c1f"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/9acb8b1ece8224d1c4cfb63f7d65892f7a322c1f"}]},"branch":"refs/heads/master"},"8fc622ce3cfd955d60fa738ee9d54a7afaa2e7e4":{"kind":"REWORK","_number":16,"created":"2026-06-12 22:25:52.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/16","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/16","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/16 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/16 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/16 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/16"}}},"commit":{"parents":[{"commit":"9d891d3e679b522832c216f23e30e64a9b400681","subject":"Use mTLS and a shared client certificate for RabbitMQ","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/9d891d3e679b522832c216f23e30e64a9b400681"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-12 22:24:37.000000000","tz":-300},"subject":"[WIP] Terminate API TLS with nginx sidecars instead of Apache","message":"[WIP] Terminate API TLS with nginx sidecars instead of Apache\n\nReplace in-container Apache httpd / chart-native nginx TLS termination for the\nOpenStack API services with a uniform nginx TLS-terminating sidecar, across\nkeystone, glance, heat (api+cfn), nova (osapi+metadata), neutron and placement.\n\nFor each API component:\n\n* The main container runs uwsgi directly (Apache removed where present),\n  binding the endpoint \"service\" scope port over plain HTTP exactly as in the\n  non-TLS case; liveness/readiness probes hit that backend directly.\n* New pod.extraContainers.\u003ccomponent\u003e / pod.extraVolumes.\u003ccomponent\u003e render\n  hooks let an override inject an nginx sidecar that terminates TLS on port 443\n  and reverse-proxies to the uwsgi backend.\n* TLS is toggled per service via .Values.tls.\u003cservice\u003e. When enabled the chart\n  issues the server certificate (gated on tls.\u003cservice\u003e, not\n  manifests.certificates, to avoid forcing RabbitMQ/DB TLS) and the API Service\n  gains targetPort: 443.\n\nExposure and the TLS objects live entirely in the overrides so the charts stay\nindependent of how services are exposed outside the cluster:\n\n* gateway-tls.yaml (unchanged) covers public-endpoint TLS only (gateway\n  terminates public TLS, plain HTTP to the backend).\n* gateway-api-tls.yaml is a new, self-contained \"secure everywhere\" override:\n  public TLS plus gateway\u003c-\u003epod TLS. It carries the nginx sidecar\n  (extraContainers/extraVolumes), the https schemes, the cert config and the\n  consumer-trust settings, and its extraObjects hold the HTTPRoute(s), the\n  nginx config ConfigMap(s) and the BackendTLSPolicy(ies) (so the Envoy Gateway\n  re-encrypts to the sidecar). The compute-kit-tls job uses this override.\n\n* glance and neutron, which shipped a chart-native nginx sidecar, are converted\n  to the same extraContainers approach.\n* Consumer side: each service trusts the in-cluster TLS endpoints via the\n  ca-issuer CA (keystone_authtoken/clients cafile, https client schemes, ks-*\n  registration jobs and rally test pods get the CA, and the neutron metadata\n  agent reaches nova-metadata over https).\n\nAll other Zuul jobs are temporarily commented out in zuul.d/project.yaml while\nthis is iterated on, and must be restored before merge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/8fc622ce3cfd955d60fa738ee9d54a7afaa2e7e4"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/8fc622ce3cfd955d60fa738ee9d54a7afaa2e7e4"}]},"branch":"refs/heads/master"},"c22cffb37645b270892cad2995a73f021e82819d":{"kind":"REWORK","_number":17,"created":"2026-06-15 17:55:30.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/17","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/17","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/17 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/17 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/17 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/17"}}},"commit":{"parents":[{"commit":"9d891d3e679b522832c216f23e30e64a9b400681","subject":"Use mTLS and a shared client certificate for RabbitMQ","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/9d891d3e679b522832c216f23e30e64a9b400681"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-15 17:55:24.000000000","tz":-300},"subject":"[WIP] Terminate API TLS with nginx sidecars instead of Apache","message":"[WIP] Terminate API TLS with nginx sidecars instead of Apache\n\nReplace in-container Apache httpd / chart-native nginx TLS termination for the\nOpenStack API services with a uniform nginx TLS-terminating sidecar, across\nkeystone, glance, heat (api+cfn), nova (osapi+metadata), neutron and placement.\n\nFor each API component:\n\n* The main container runs uwsgi directly (Apache removed where present),\n  binding the endpoint \"service\" scope port over plain HTTP exactly as in the\n  non-TLS case; liveness/readiness probes hit that backend directly.\n* New pod.extraContainers.\u003ccomponent\u003e / pod.extraVolumes.\u003ccomponent\u003e render\n  hooks let an override inject an nginx sidecar that terminates TLS on port 443\n  and reverse-proxies to the uwsgi backend.\n* TLS is toggled per service via .Values.tls.\u003cservice\u003e. When enabled the chart\n  issues the server certificate (gated on tls.\u003cservice\u003e, not\n  manifests.certificates, to avoid forcing RabbitMQ/DB TLS) and the API Service\n  gains targetPort: 443.\n\nExposure and the TLS objects live entirely in the overrides so the charts stay\nindependent of how services are exposed outside the cluster:\n\n* gateway-tls.yaml (unchanged) covers public-endpoint TLS only (gateway\n  terminates public TLS, plain HTTP to the backend).\n* gateway-api-tls.yaml is a new, self-contained \"secure everywhere\" override:\n  public TLS plus gateway\u003c-\u003epod TLS. It carries the nginx sidecar\n  (extraContainers/extraVolumes), the https schemes, the cert config and the\n  consumer-trust settings, and its extraObjects hold the HTTPRoute(s), the\n  nginx config ConfigMap(s) and the BackendTLSPolicy(ies) (so the Envoy Gateway\n  re-encrypts to the sidecar). The compute-kit-tls job uses this override.\n\n* glance and neutron, which shipped a chart-native nginx sidecar, are converted\n  to the same extraContainers approach.\n* Consumer side: each service trusts the in-cluster TLS endpoints via the\n  ca-issuer CA (keystone_authtoken/clients cafile, https client schemes, ks-*\n  registration jobs and rally test pods get the CA, and the neutron metadata\n  agent reaches nova-metadata over https).\n\nAll other Zuul jobs are temporarily commented out in zuul.d/project.yaml while\nthis is iterated on, and must be restored before merge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/c22cffb37645b270892cad2995a73f021e82819d"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/c22cffb37645b270892cad2995a73f021e82819d"}]},"branch":"refs/heads/master"},"f81331eef6a43b42ef4422af11276578d0242508":{"kind":"REWORK","_number":18,"created":"2026-06-17 17:10:22.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/18","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/18","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/18 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/18 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/18 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/18"}}},"commit":{"parents":[{"commit":"91ea199f632620f49f5bb9c1f2944e6bcb5832cb","subject":"Remove Ingress templates; expose services via extraObjects","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/91ea199f632620f49f5bb9c1f2944e6bcb5832cb"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-17 17:06:18.000000000","tz":-300},"subject":"[WIP] Terminate API TLS with nginx sidecars instead of Apache","message":"[WIP] Terminate API TLS with nginx sidecars instead of Apache\n\nReplace in-container Apache httpd / chart-native nginx TLS termination for the\nOpenStack API services with a uniform nginx TLS-terminating sidecar, across\nkeystone, glance, heat (api+cfn), nova (osapi+metadata), neutron and placement.\n\nFor each API component:\n\n* The main container runs uwsgi directly (Apache removed where present),\n  binding the endpoint \"service\" scope port over plain HTTP exactly as in the\n  non-TLS case; liveness/readiness probes hit that backend directly.\n* New pod.extraContainers.\u003ccomponent\u003e / pod.extraVolumes.\u003ccomponent\u003e render\n  hooks let an override inject an nginx sidecar that terminates TLS on port 443\n  and reverse-proxies to the uwsgi backend.\n* TLS is toggled per service via .Values.tls.\u003cservice\u003e. When enabled the chart\n  issues the server certificate (gated on tls.\u003cservice\u003e, not\n  manifests.certificates, to avoid forcing RabbitMQ/DB TLS) and the API Service\n  gains targetPort: 443.\n\nExposure and the TLS objects live entirely in the overrides so the charts stay\nindependent of how services are exposed outside the cluster:\n\n* gateway-tls.yaml (unchanged) covers public-endpoint TLS only (gateway\n  terminates public TLS, plain HTTP to the backend).\n* gateway-api-tls.yaml is a new, self-contained \"secure everywhere\" override:\n  public TLS plus gateway\u003c-\u003epod TLS. It carries the nginx sidecar\n  (extraContainers/extraVolumes), the https schemes, the cert config and the\n  consumer-trust settings, and its extraObjects hold the HTTPRoute(s), the\n  nginx config ConfigMap(s) and the BackendTLSPolicy(ies) (so the Envoy Gateway\n  re-encrypts to the sidecar). The compute-kit-tls job uses this override.\n\n* glance and neutron, which shipped a chart-native nginx sidecar, are converted\n  to the same extraContainers approach.\n* Consumer side: each service trusts the in-cluster TLS endpoints via the\n  ca-issuer CA (keystone_authtoken/clients cafile, https client schemes, ks-*\n  registration jobs and rally test pods get the CA, and the neutron metadata\n  agent reaches nova-metadata over https).\n\nAll other Zuul jobs are temporarily commented out in zuul.d/project.yaml while\nthis is iterated on, and must be restored before merge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/f81331eef6a43b42ef4422af11276578d0242508"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/f81331eef6a43b42ef4422af11276578d0242508"}]},"branch":"refs/heads/master"},"dee0821786f8dcbd0f95ddc995e529fcc2f18520":{"kind":"REWORK","_number":19,"created":"2026-06-17 21:24:36.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/19","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/19","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/19 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/19 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/19 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/19"}}},"commit":{"parents":[{"commit":"91ea199f632620f49f5bb9c1f2944e6bcb5832cb","subject":"Remove Ingress templates; expose services via extraObjects","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/91ea199f632620f49f5bb9c1f2944e6bcb5832cb"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-17 21:24:01.000000000","tz":-300},"subject":"[WIP] Terminate API TLS with nginx sidecars instead of Apache","message":"[WIP] Terminate API TLS with nginx sidecars instead of Apache\n\nReplace in-container Apache httpd / chart-native nginx TLS termination for the\nOpenStack API services with a uniform nginx TLS-terminating sidecar, across\nkeystone, glance, heat (api+cfn), nova (osapi+metadata), neutron and placement.\n\nFor each API component:\n\n* The main container runs uwsgi directly (Apache removed where present),\n  binding the endpoint \"service\" scope port over plain HTTP exactly as in the\n  non-TLS case; liveness/readiness probes hit that backend directly.\n* New pod.extraContainers.\u003ccomponent\u003e / pod.extraVolumes.\u003ccomponent\u003e render\n  hooks let an override inject an nginx sidecar that terminates TLS on port 443\n  and reverse-proxies to the uwsgi backend.\n* TLS is toggled per service via .Values.tls.\u003cservice\u003e. When enabled the chart\n  issues the server certificate (gated on tls.\u003cservice\u003e, not\n  manifests.certificates, to avoid forcing RabbitMQ/DB TLS) and the API Service\n  gains targetPort: 443.\n\nExposure and the TLS objects live entirely in the overrides so the charts stay\nindependent of how services are exposed outside the cluster:\n\n* gateway-tls.yaml (unchanged) covers public-endpoint TLS only (gateway\n  terminates public TLS, plain HTTP to the backend).\n* gateway-api-tls.yaml is a new, self-contained \"secure everywhere\" override:\n  public TLS plus gateway\u003c-\u003epod TLS. It carries the nginx sidecar\n  (extraContainers/extraVolumes), the https schemes, the cert config and the\n  consumer-trust settings, and its extraObjects hold the HTTPRoute(s), the\n  nginx config ConfigMap(s) and the BackendTLSPolicy(ies) (so the Envoy Gateway\n  re-encrypts to the sidecar). The compute-kit-tls job uses this override.\n\n* glance and neutron, which shipped a chart-native nginx sidecar, are converted\n  to the same extraContainers approach.\n* Consumer side: each service trusts the in-cluster TLS endpoints via the\n  ca-issuer CA (keystone_authtoken/clients cafile, https client schemes, ks-*\n  registration jobs and rally test pods get the CA, and the neutron metadata\n  agent reaches nova-metadata over https).\n\nAll other Zuul jobs are temporarily commented out in zuul.d/project.yaml while\nthis is iterated on, and must be restored before merge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/dee0821786f8dcbd0f95ddc995e529fcc2f18520"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/dee0821786f8dcbd0f95ddc995e529fcc2f18520"}]},"branch":"refs/heads/master"},"aacf1584a56056214fdfe35e253cde63d879dafa":{"kind":"REWORK","_number":20,"created":"2026-06-18 18:04:58.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/20","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/20","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/20 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/20 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/20 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/20"}}},"commit":{"parents":[{"commit":"91ea199f632620f49f5bb9c1f2944e6bcb5832cb","subject":"Remove Ingress templates; expose services via extraObjects","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/91ea199f632620f49f5bb9c1f2944e6bcb5832cb"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-18 17:59:52.000000000","tz":-300},"subject":"[WIP] Terminate API TLS with nginx sidecars instead of Apache","message":"[WIP] Terminate API TLS with nginx sidecars instead of Apache\n\nReplace in-container Apache httpd / chart-native nginx TLS termination for the\nOpenStack API services with a uniform nginx TLS-terminating sidecar, across\nkeystone, glance, heat (api+cfn), nova (osapi+metadata), neutron and placement.\n\nFor each API component:\n\n* The main container runs uwsgi directly (Apache removed where present),\n  binding the endpoint \"service\" scope port over plain HTTP exactly as in the\n  non-TLS case; liveness/readiness probes hit that backend directly.\n* New pod.extraContainers.\u003ccomponent\u003e / pod.extraVolumes.\u003ccomponent\u003e render\n  hooks let an override inject an nginx sidecar that terminates TLS on port 443\n  and reverse-proxies to the uwsgi backend.\n* TLS is toggled per service via .Values.tls.\u003cservice\u003e. When enabled the chart\n  issues the server certificate (gated on tls.\u003cservice\u003e, not\n  manifests.certificates, to avoid forcing RabbitMQ/DB TLS) and the API Service\n  gains targetPort: 443.\n\nExposure and the TLS objects live entirely in the overrides so the charts stay\nindependent of how services are exposed outside the cluster:\n\n* gateway-tls.yaml (unchanged) covers public-endpoint TLS only (gateway\n  terminates public TLS, plain HTTP to the backend).\n* gateway-api-tls.yaml is a new, self-contained \"secure everywhere\" override:\n  public TLS plus gateway\u003c-\u003epod TLS. It carries the nginx sidecar\n  (extraContainers/extraVolumes), the https schemes, the cert config and the\n  consumer-trust settings, and its extraObjects hold the HTTPRoute(s), the\n  nginx config ConfigMap(s) and the BackendTLSPolicy(ies) (so the Envoy Gateway\n  re-encrypts to the sidecar). The compute-kit-tls job uses this override.\n\n* glance and neutron, which shipped a chart-native nginx sidecar, are converted\n  to the same extraContainers approach.\n* Consumer side: each service trusts the in-cluster TLS endpoints via the\n  ca-issuer CA (keystone_authtoken/clients cafile, https client schemes, ks-*\n  registration jobs and rally test pods get the CA, and the neutron metadata\n  agent reaches nova-metadata over https).\n\nAll other Zuul jobs are temporarily commented out in zuul.d/project.yaml while\nthis is iterated on, and must be restored before merge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/aacf1584a56056214fdfe35e253cde63d879dafa"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/aacf1584a56056214fdfe35e253cde63d879dafa"}]},"branch":"refs/heads/master"},"3b1947bd196f038391566bebc4044670c9abaff0":{"kind":"REWORK","_number":21,"created":"2026-06-18 22:12:41.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/21","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/21","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/21 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/21 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/21 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/21"}}},"commit":{"parents":[{"commit":"6ec1132485def4de18dcf00e4cb711925c42d70f","subject":"Remove Ingress templates; expose services via extraObjects","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/6ec1132485def4de18dcf00e4cb711925c42d70f"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-18 21:53:34.000000000","tz":-300},"subject":"[WIP] Terminate API TLS with nginx sidecars instead of Apache","message":"[WIP] Terminate API TLS with nginx sidecars instead of Apache\n\nReplace in-container Apache httpd / chart-native nginx TLS termination for the\nOpenStack API services with a uniform nginx TLS-terminating sidecar, across\nkeystone, glance, heat (api+cfn), nova (osapi+metadata), neutron and placement.\n\nFor each API component:\n\n* The main container runs uwsgi directly (Apache removed where present),\n  binding the endpoint \"service\" scope port over plain HTTP exactly as in the\n  non-TLS case; liveness/readiness probes hit that backend directly.\n* New pod.extraContainers.\u003ccomponent\u003e / pod.extraVolumes.\u003ccomponent\u003e render\n  hooks let an override inject an nginx sidecar that terminates TLS on port 443\n  and reverse-proxies to the uwsgi backend.\n* TLS is toggled per service via .Values.tls.\u003cservice\u003e. When enabled the chart\n  issues the server certificate (gated on tls.\u003cservice\u003e, not\n  manifests.certificates, to avoid forcing RabbitMQ/DB TLS) and the API Service\n  gains targetPort: 443.\n\nExposure and the TLS objects live entirely in the overrides so the charts stay\nindependent of how services are exposed outside the cluster:\n\n* gateway-tls.yaml (unchanged) covers public-endpoint TLS only (gateway\n  terminates public TLS, plain HTTP to the backend).\n* gateway-api-tls.yaml is a new, self-contained \"secure everywhere\" override:\n  public TLS plus gateway\u003c-\u003epod TLS. It carries the nginx sidecar\n  (extraContainers/extraVolumes), the https schemes, the cert config and the\n  consumer-trust settings, and its extraObjects hold the HTTPRoute(s), the\n  nginx config ConfigMap(s) and the BackendTLSPolicy(ies) (so the Envoy Gateway\n  re-encrypts to the sidecar). The compute-kit-tls job uses this override.\n\n* glance and neutron, which shipped a chart-native nginx sidecar, are converted\n  to the same extraContainers approach.\n* Consumer side: each service trusts the in-cluster TLS endpoints via the\n  ca-issuer CA (keystone_authtoken/clients cafile, https client schemes, ks-*\n  registration jobs and rally test pods get the CA, and the neutron metadata\n  agent reaches nova-metadata over https).\n\nAll other Zuul jobs are temporarily commented out in zuul.d/project.yaml while\nthis is iterated on, and must be restored before merge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/3b1947bd196f038391566bebc4044670c9abaff0"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/3b1947bd196f038391566bebc4044670c9abaff0"}]},"branch":"refs/heads/master"},"96856188db544aa63d89e4423c23927ed787fcbd":{"kind":"REWORK","_number":22,"created":"2026-06-23 23:20:39.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/22","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/22","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/22 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/22 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/22 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/22"}}},"commit":{"parents":[{"commit":"6ec1132485def4de18dcf00e4cb711925c42d70f","subject":"Remove Ingress templates; expose services via extraObjects","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/6ec1132485def4de18dcf00e4cb711925c42d70f"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-23 23:17:20.000000000","tz":-300},"subject":"[WIP] Terminate API TLS with nginx sidecars instead of Apache","message":"[WIP] Terminate API TLS with nginx sidecars instead of Apache\n\nReplace in-container Apache httpd / chart-native nginx TLS termination for the\nOpenStack API services with a uniform nginx TLS-terminating sidecar that is\ndefined entirely in the deployment overrides, so the charts stay agnostic of\nhow (and whether) their services are exposed over TLS. Covers glance, heat\n(api+cfn), nova (osapi+metadata), neutron and placement; keystone is converted\npartially (see below).\n\nServer-side TLS (the chart\u0027s own exposure):\n\n* The main container runs uwsgi directly (Apache removed where present),\n  binding the endpoint \"service\" scope port over plain HTTP exactly as in the\n  non-TLS case; liveness/readiness probes hit that backend directly.\n* New pod.extraContainers.\u003ccomponent\u003e / pod.extraVolumes.\u003ccomponent\u003e render\n  hooks let an override inject an nginx sidecar that terminates TLS on port 443\n  and reverse-proxies to the uwsgi backend.\n* The Service targetPort is decoupled from TLS into a dedicated\n  network.\u003ckey\u003e.target_port value (falling back to the Service port when\n  unset), so the chart no longer needs a tls toggle to point the Service at the\n  sidecar. The per-service tls.\u003cservice\u003e toggles and the API server-cert\n  rendering are removed from the charts entirely.\n* Exposure and the TLS objects live in values_overrides/\u003cchart\u003e/\n  gateway-api-tls.yaml: the nginx sidecar (extraContainers/extraVolumes), the\n  https schemes, and extraObjects holding the server Certificate, the\n  HTTPRoute(s), the nginx config ConfigMap(s) and the BackendTLSPolicy(ies) so\n  the Envoy Gateway re-encrypts to the sidecar. The compute-kit-tls job uses\n  this override. gateway-tls.yaml (public-endpoint TLS only) is unchanged.\n\nClient-side trust (outbound TLS to other services):\n\n* A single scalar secrets.tls.ca replaces the tls.identity / manifests.\n  certificates client-trust gating. It is null by default -\u003e no CA is mounted\n  and REQUESTS_CA_BUNDLE is left unset, so the chart renders zero TLS plumbing.\n  When set it names a CA-ONLY secret holding just ca.crt -- no server\n  certificate and, crucially, no private key (server or CA) reaches workload\n  pods. The chart mounts only ca.crt at /etc/ssl/certs/openstack-helm.crt and\n  points REQUESTS_CA_BUNDLE / OS_CACERT / per-client cafile there; this also\n  covers the ks-* registration jobs, rally test pods and the neutron metadata\n  agent reaching nova-metadata over https. Assumes every in-pod TLS server cert\n  is signed by the one ca-issuer CA managed by cert-manager.\n* The CA-only secret (openstack-helm-ca) is provisioned once into the workload\n  namespace by roles/deploy-charts (prepare-k8s.yaml), reading ca.crt from the\n  ca-issuer CA secret; no signing material is ever distributed to pods. The\n  override sets secrets.tls.ca to it and points cafiles at the canonical path.\n* The manifests.certificates value is retired from the migrated charts.\n\nkeystone keeps Apache httpd (mod_wsgi) behind the nginx sidecar because its\nfederated auth methods (OIDC/SAML2/Kerberos) delegate to Apache modules, and it\nstays on the tls.identity client-trust gate for now; it migrates to uwsgi +\nsecrets.tls.ca in a follow-up. nova\u0027s vencrypt cert (proxy\u003c-\u003ecompute VNC) is\nunrelated to API/outbound trust and is preserved.\n\nAll other Zuul jobs are temporarily commented out in zuul.d/project.yaml while\nthis is iterated on, and must be restored before merge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/96856188db544aa63d89e4423c23927ed787fcbd"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/96856188db544aa63d89e4423c23927ed787fcbd"}]},"branch":"refs/heads/master"},"bbe01c1670e7d00c40089ff8186e1182c2d14fa1":{"kind":"REWORK","_number":23,"created":"2026-06-25 15:07:23.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/23","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/23","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/23 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/23 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/23 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/23"}}},"commit":{"parents":[{"commit":"6ec1132485def4de18dcf00e4cb711925c42d70f","subject":"Remove Ingress templates; expose services via extraObjects","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/6ec1132485def4de18dcf00e4cb711925c42d70f"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-25 15:06:59.000000000","tz":-300},"subject":"Terminate API TLS with nginx sidecars instead of Apache","message":"Terminate API TLS with nginx sidecars instead of Apache\n\nReplace in-container Apache httpd / chart-native nginx TLS termination for the\nOpenStack API services with a uniform nginx TLS-terminating sidecar that is\ndefined entirely in the deployment overrides, so the charts stay agnostic of\nhow (and whether) their services are exposed over TLS. Covers glance, heat\n(api+cfn), nova (osapi+metadata), neutron and placement; keystone is converted\npartially (see below).\n\nServer-side TLS (the chart\u0027s own exposure):\n\n* The main container runs uwsgi directly (Apache removed where present),\n  binding the endpoint \"service\" scope port over plain HTTP exactly as in the\n  non-TLS case; liveness/readiness probes hit that backend directly.\n* New pod.extraContainers.\u003ccomponent\u003e / pod.extraVolumes.\u003ccomponent\u003e render\n  hooks let an override inject an nginx sidecar that terminates TLS on port 443\n  and reverse-proxies to the uwsgi backend.\n* The Service targetPort is decoupled from TLS into a dedicated\n  network.\u003ckey\u003e.target_port value (falling back to the Service port when\n  unset), so the chart no longer needs a tls toggle to point the Service at the\n  sidecar. The per-service tls.\u003cservice\u003e toggles and the API server-cert\n  rendering are removed from the charts entirely.\n* Exposure and the TLS objects live in values_overrides/\u003cchart\u003e/\n  gateway-api-tls.yaml: the nginx sidecar (extraContainers/extraVolumes), the\n  https schemes, and extraObjects holding the server Certificate, the\n  HTTPRoute(s), the nginx config ConfigMap(s) and the BackendTLSPolicy(ies) so\n  the Envoy Gateway re-encrypts to the sidecar. The compute-kit-tls job uses\n  this override. gateway-tls.yaml (public-endpoint TLS only) is unchanged.\n\nClient-side trust (outbound TLS to other services):\n\n* A single scalar secrets.tls.ca replaces the tls.identity / manifests.\n  certificates client-trust gating. It is null by default -\u003e no CA is mounted\n  and REQUESTS_CA_BUNDLE is left unset, so the chart renders zero TLS plumbing.\n  When set it names a CA-ONLY secret holding just ca.crt -- no server\n  certificate and, crucially, no private key (server or CA) reaches workload\n  pods. The chart mounts only ca.crt at /etc/ssl/certs/openstack-helm.crt and\n  points REQUESTS_CA_BUNDLE / OS_CACERT / per-client cafile there; this also\n  covers the ks-* registration jobs, rally test pods and the neutron metadata\n  agent reaching nova-metadata over https. Assumes every in-pod TLS server cert\n  is signed by the one ca-issuer CA managed by cert-manager.\n* The CA-only secret (openstack-helm-ca) is provisioned once into the workload\n  namespace by roles/deploy-charts (prepare-k8s.yaml), reading ca.crt from the\n  ca-issuer CA secret; no signing material is ever distributed to pods. The\n  override sets secrets.tls.ca to it and points cafiles at the canonical path.\n* The manifests.certificates value is retired from the migrated charts.\n\nkeystone keeps Apache httpd (mod_wsgi) behind the nginx sidecar because its\nfederated auth methods (OIDC/SAML2/Kerberos) delegate to Apache modules, and it\nstays on the tls.identity client-trust gate for now; it migrates to uwsgi +\nsecrets.tls.ca in a follow-up. nova\u0027s vencrypt cert (proxy\u003c-\u003ecompute VNC) is\nunrelated to API/outbound trust and is preserved.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/bbe01c1670e7d00c40089ff8186e1182c2d14fa1"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/bbe01c1670e7d00c40089ff8186e1182c2d14fa1"}]},"branch":"refs/heads/master"},"094432f91464a6d0b66169cd0b191b1c0a62462b":{"kind":"REWORK","_number":24,"created":"2026-06-25 17:50:50.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/24","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/24","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/24 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/24 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/24 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/24"}}},"commit":{"parents":[{"commit":"6ec1132485def4de18dcf00e4cb711925c42d70f","subject":"Remove Ingress templates; expose services via extraObjects","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/6ec1132485def4de18dcf00e4cb711925c42d70f"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-25 17:50:41.000000000","tz":-300},"subject":"Terminate API TLS with nginx sidecars","message":"Terminate API TLS with nginx sidecars\n\nReplace in-container Apache httpd / chart-native\nnginx TLS termination for the OpenStack API\nservices with a uniform nginx TLS-terminating\nsidecar defined entirely in the deployment\noverrides, so the charts stay agnostic of how\n(and whether) their services are exposed over\nTLS. Covers glance, heat (api+cfn), nova\n(osapi+metadata), neutron and placement;\nkeystone is converted partially (see below).\n\nServer-side TLS (the chart\u0027s own exposure):\n\n* The main container runs uwsgi directly\n  (Apache removed where present), binding the\n  endpoint \"service\" scope port over plain HTTP\n  exactly as in the non-TLS case;\n  liveness/readiness probes hit that backend\n  directly.\n* New pod.extraContainers.\u003ccomponent\u003e and\n  pod.extraVolumes.\u003ccomponent\u003e render hooks let\n  an override inject an nginx sidecar that\n  terminates TLS on port 443 and reverse-proxies\n  to the uwsgi backend.\n* The Service targetPort is decoupled from TLS\n  into a dedicated network.\u003ckey\u003e.target_port\n  value (falling back to the Service port when\n  unset), so the chart no longer needs a tls\n  toggle to point the Service at the sidecar.\n  The per-service tls.\u003cservice\u003e toggles and the\n  API server-cert rendering are removed from the\n  charts entirely.\n* Exposure and the TLS objects live in the\n  per-chart values_overrides/\u003cchart\u003e/\n  tls-gateway-and-sidecar.yaml override: the\n  nginx sidecar (extraContainers/extraVolumes),\n  the https schemes, and extraObjects holding\n  the server Certificate, the HTTPRoute(s), the\n  nginx config ConfigMap(s) and the\n  BackendTLSPolicy(ies) so the Envoy Gateway\n  re-encrypts to the sidecar. The compute-kit-tls\n  job uses this override. gateway-tls.yaml\n  (public-endpoint TLS only) is unchanged.\n\nClient-side trust (outbound TLS to other\nservices):\n\n* A single scalar secrets.tls.ca replaces the\n  tls.identity / manifests.certificates\n  client-trust gating. It is null by default -\u003e\n  no CA is mounted and REQUESTS_CA_BUNDLE is\n  left unset, so the chart renders zero TLS\n  plumbing. When set it names a CA-ONLY secret\n  holding just ca.crt -- no server certificate\n  and, crucially, no private key (server or CA)\n  reaches workload pods. The chart mounts only\n  ca.crt at /etc/ssl/certs/openstack-helm.crt\n  and points REQUESTS_CA_BUNDLE / OS_CACERT /\n  per-client cafile there; this also covers the\n  ks-* registration jobs, rally test pods and\n  the neutron metadata agent reaching\n  nova-metadata over https. Assumes every in-pod\n  TLS server cert is signed by the one ca-issuer\n  CA managed by cert-manager.\n* The CA-only secret (openstack-helm-ca) is\n  provisioned once into the workload namespace\n  by roles/deploy-charts (prepare-k8s.yaml),\n  reading ca.crt from the ca-issuer CA secret;\n  no signing material is ever distributed to\n  pods. The override sets secrets.tls.ca to it\n  and points cafiles at the canonical path.\n* The manifests.certificates value is retired\n  from the migrated charts.\n\nkeystone keeps Apache httpd (mod_wsgi) behind\nthe nginx sidecar because its federated auth\nmethods (OIDC/SAML2/Kerberos) delegate to\nApache modules, and it stays on the\ntls.identity client-trust gate for now; it\nmigrates to uwsgi + secrets.tls.ca in a\nfollow-up. nova\u0027s vencrypt cert (proxy\u003c-\u003ecompute\nVNC) is unrelated to API/outbound trust and is\npreserved.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/094432f91464a6d0b66169cd0b191b1c0a62462b"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/094432f91464a6d0b66169cd0b191b1c0a62462b"}]},"branch":"refs/heads/master"},"8e88235400ec7848a9a2cca30fdec556bbaec573":{"kind":"REWORK","_number":25,"created":"2026-06-25 22:33:29.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/25","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/25","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/25 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/25 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/25 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/25"}}},"commit":{"parents":[{"commit":"6ec1132485def4de18dcf00e4cb711925c42d70f","subject":"Remove Ingress templates; expose services via extraObjects","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/6ec1132485def4de18dcf00e4cb711925c42d70f"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-25 22:33:18.000000000","tz":-300},"subject":"Terminate API TLS with nginx sidecars","message":"Terminate API TLS with nginx sidecars\n\nReplace in-container Apache httpd / chart-native\nnginx TLS termination for the OpenStack API\nservices with a uniform nginx TLS-terminating\nsidecar defined entirely in the deployment\noverrides, so the charts stay agnostic of how\n(and whether) their services are exposed over\nTLS. Covers glance, heat (api+cfn), nova\n(osapi+metadata), neutron, placement, cinder,\naodh and gnocchi; keystone and horizon are\nconverted partially (see below).\n\nServer-side TLS (the chart\u0027s own exposure):\n\n* The main container runs uwsgi directly\n  (Apache removed where present), binding the\n  endpoint \"service\" scope port over plain HTTP\n  exactly as in the non-TLS case;\n  liveness/readiness probes hit that backend\n  directly.\n* New pod.extraContainers.\u003ccomponent\u003e and\n  pod.extraVolumes.\u003ccomponent\u003e render hooks let\n  an override inject an nginx sidecar that\n  terminates TLS on port 443 and reverse-proxies\n  to the uwsgi backend.\n* The Service targetPort is decoupled from TLS\n  into a dedicated network.\u003ckey\u003e.target_port\n  value (falling back to the Service port when\n  unset), so the chart no longer needs a tls\n  toggle to point the Service at the sidecar.\n  The per-service tls.\u003cservice\u003e toggles and the\n  API server-cert rendering are removed from the\n  charts entirely.\n* Exposure and the TLS objects live in the\n  per-chart values_overrides/\u003cchart\u003e/\n  tls-gateway-and-sidecar.yaml override: the\n  nginx sidecar (extraContainers/extraVolumes),\n  the https schemes, and extraObjects holding\n  the server Certificate, the HTTPRoute(s), the\n  nginx config ConfigMap(s) and the\n  BackendTLSPolicy(ies) so the Envoy Gateway\n  re-encrypts to the sidecar.\n\nClient-side trust (outbound TLS to other\nservices):\n\n* A single scalar secrets.tls.ca replaces the\n  tls.identity / manifests.certificates\n  client-trust gating. It is null by default -\u003e\n  no CA is mounted and REQUESTS_CA_BUNDLE is\n  left unset, so the chart renders zero TLS\n  plumbing. When set it names a CA-ONLY secret\n  holding just ca.crt -- no server certificate\n  and, crucially, no private key (server or CA)\n  reaches workload pods. The chart mounts only\n  ca.crt at /etc/ssl/certs/openstack-helm.crt\n  and points REQUESTS_CA_BUNDLE / OS_CACERT /\n  per-client cafile there; this also covers the\n  ks-* registration jobs, rally/selenium test\n  pods and the neutron metadata agent reaching\n  nova-metadata over https. Assumes every in-pod\n  TLS server cert is signed by the one ca-issuer\n  CA managed by cert-manager.\n* The CA-only secret (openstack-helm-ca) is\n  provisioned once into the workload namespace\n  by roles/deploy-charts (prepare-k8s.yaml),\n  reading ca.crt from the ca-issuer CA secret;\n  no signing material is ever distributed to\n  pods. The override sets secrets.tls.ca to it\n  and points cafiles at the canonical path.\n\nkeystone and horizon keep Apache httpd: keystone\nbecause its federated auth methods\n(OIDC/SAML2/Kerberos) delegate to Apache\nmodules, horizon because apache also serves the\ndashboard\u0027s static assets. In both, apache now\nserves plain HTTP behind the nginx sidecar (no\nSSLEngine), and horizon trusts the sidecar\u0027s\nX-Forwarded-Proto via SECURE_PROXY_SSL_HEADER.\nkeystone stays on the tls.identity client-trust\ngate for now and migrates to secrets.tls.ca in a\nfollow-up.\n\nmanifests.certificates is retired from the\nmigrated charts except neutron (OVN-agent certs,\nnot yet migrated) and cinder (its legacy\nstatefulset-volume mariadb/oslo_db certs, which\nare unrelated to the API path migrated here).\nnova\u0027s vencrypt cert (proxy\u003c-\u003ecompute VNC) is\nunrelated to API/outbound trust and is\npreserved.\n\nThe compute-kit-tls job is renamed to\nopenstack-helm-tls and switched to the 5-node\nrook nodeset; besides the compute kit it now\nalso deploys ceph, cinder and horizon (gated\ntasks in deploy-compute-kit.yaml) so their nginx\nTLS sidecars are exercised end to end. aodh and\ngnocchi have no CI job today and are validated by\nhelm template / helm lint only.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/8e88235400ec7848a9a2cca30fdec556bbaec573"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/8e88235400ec7848a9a2cca30fdec556bbaec573"}]},"branch":"refs/heads/master"},"fbd4399904b5d07ec5be6f0511f2a8be19b691fb":{"kind":"REWORK","_number":26,"created":"2026-06-26 00:35:33.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/26","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/26","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/26 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/26 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/26 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/26"}}},"commit":{"parents":[{"commit":"6ec1132485def4de18dcf00e4cb711925c42d70f","subject":"Remove Ingress templates; expose services via extraObjects","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/6ec1132485def4de18dcf00e4cb711925c42d70f"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-26 00:35:19.000000000","tz":-300},"subject":"[WIP] Terminate API TLS with nginx sidecars","message":"[WIP] Terminate API TLS with nginx sidecars\n\nReplace in-container Apache httpd / chart-native\nnginx TLS termination for the OpenStack API\nservices with a uniform nginx TLS-terminating\nsidecar defined entirely in the deployment\noverrides, so the charts stay agnostic of how\n(and whether) their services are exposed over\nTLS. Covers glance, heat (api+cfn), nova\n(osapi+metadata), neutron, placement, cinder,\naodh and gnocchi; keystone and horizon are\nconverted partially (see below).\n\nServer-side TLS (the chart\u0027s own exposure):\n\n* The main container runs uwsgi directly\n  (Apache removed where present), binding the\n  endpoint \"service\" scope port over plain HTTP\n  exactly as in the non-TLS case;\n  liveness/readiness probes hit that backend\n  directly.\n* New pod.extraContainers.\u003ccomponent\u003e and\n  pod.extraVolumes.\u003ccomponent\u003e render hooks let\n  an override inject an nginx sidecar that\n  terminates TLS on port 443 and reverse-proxies\n  to the uwsgi backend.\n* The Service targetPort is decoupled from TLS\n  into a dedicated network.\u003ckey\u003e.target_port\n  value (falling back to the Service port when\n  unset), so the chart no longer needs a tls\n  toggle to point the Service at the sidecar.\n  The per-service tls.\u003cservice\u003e toggles and the\n  API server-cert rendering are removed from the\n  charts entirely.\n* Exposure and the TLS objects live in the\n  per-chart values_overrides/\u003cchart\u003e/\n  tls-gateway-and-sidecar.yaml override: the\n  nginx sidecar (extraContainers/extraVolumes),\n  the https schemes, and extraObjects holding\n  the server Certificate, the HTTPRoute(s), the\n  nginx config ConfigMap(s) and the\n  BackendTLSPolicy(ies) so the Envoy Gateway\n  re-encrypts to the sidecar.\n\nClient-side trust (outbound TLS to other\nservices):\n\n* A single scalar secrets.tls.ca replaces the\n  tls.identity / manifests.certificates\n  client-trust gating. It is null by default -\u003e\n  no CA is mounted and REQUESTS_CA_BUNDLE is\n  left unset, so the chart renders zero TLS\n  plumbing. When set it names a CA-ONLY secret\n  holding just ca.crt -- no server certificate\n  and, crucially, no private key (server or CA)\n  reaches workload pods. The chart mounts only\n  ca.crt at /etc/ssl/certs/openstack-helm.crt\n  and points REQUESTS_CA_BUNDLE / OS_CACERT /\n  per-client cafile there; this also covers the\n  ks-* registration jobs, rally/selenium test\n  pods and the neutron metadata agent reaching\n  nova-metadata over https. Assumes every in-pod\n  TLS server cert is signed by the one ca-issuer\n  CA managed by cert-manager.\n* The CA-only secret (openstack-helm-ca) is\n  provisioned once into the workload namespace\n  by roles/deploy-charts (prepare-k8s.yaml),\n  reading ca.crt from the ca-issuer CA secret;\n  no signing material is ever distributed to\n  pods. The override sets secrets.tls.ca to it\n  and points cafiles at the canonical path.\n\nkeystone and horizon keep Apache httpd: keystone\nbecause its federated auth methods\n(OIDC/SAML2/Kerberos) delegate to Apache\nmodules, horizon because apache also serves the\ndashboard\u0027s static assets. In both, apache now\nserves plain HTTP behind the nginx sidecar (no\nSSLEngine), and horizon trusts the sidecar\u0027s\nX-Forwarded-Proto via SECURE_PROXY_SSL_HEADER.\nkeystone stays on the tls.identity client-trust\ngate for now and migrates to secrets.tls.ca in a\nfollow-up.\n\nmanifests.certificates is retired from the\nmigrated charts except neutron (OVN-agent certs,\nnot yet migrated) and cinder (its legacy\nstatefulset-volume mariadb/oslo_db certs, which\nare unrelated to the API path migrated here).\nnova\u0027s vencrypt cert (proxy\u003c-\u003ecompute VNC) is\nunrelated to API/outbound trust and is\npreserved.\n\nThe compute-kit-tls job is renamed to\nopenstack-helm-tls and switched to the 5-node\nrook nodeset; besides the compute kit it now\nalso deploys ceph, cinder and horizon (gated\ntasks in deploy-compute-kit.yaml) so their nginx\nTLS sidecars are exercised end to end. aodh and\ngnocchi have no CI job today and are validated by\nhelm template / helm lint only.\n\nAll other check-pipeline jobs are temporarily\ncommented out in zuul.d/project.yaml while this\nis iterated on; restore them before merge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/fbd4399904b5d07ec5be6f0511f2a8be19b691fb"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/fbd4399904b5d07ec5be6f0511f2a8be19b691fb"}]},"branch":"refs/heads/master"},"3099fccbad966b29a14b742eb74405a8473a9cd9":{"kind":"REWORK","_number":27,"created":"2026-06-26 02:12:33.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/27","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/27","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/27 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/27 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/27 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/27"}}},"commit":{"parents":[{"commit":"6ec1132485def4de18dcf00e4cb711925c42d70f","subject":"Remove Ingress templates; expose services via extraObjects","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/6ec1132485def4de18dcf00e4cb711925c42d70f"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-26 02:12:32.000000000","tz":-300},"subject":"[WIP] Terminate API TLS with nginx sidecars","message":"[WIP] Terminate API TLS with nginx sidecars\n\nReplace in-container Apache httpd / chart-native\nnginx TLS termination for the OpenStack API\nservices with a uniform nginx TLS-terminating\nsidecar defined entirely in the deployment\noverrides, so the charts stay agnostic of how\n(and whether) their services are exposed over\nTLS. Covers glance, heat (api+cfn), nova\n(osapi+metadata), neutron, placement, cinder,\naodh and gnocchi; keystone and horizon are\nconverted partially (see below).\n\nServer-side TLS (the chart\u0027s own exposure):\n\n* The main container runs uwsgi directly\n  (Apache removed where present), binding the\n  endpoint \"service\" scope port over plain HTTP\n  exactly as in the non-TLS case;\n  liveness/readiness probes hit that backend\n  directly.\n* New pod.extraContainers.\u003ccomponent\u003e and\n  pod.extraVolumes.\u003ccomponent\u003e render hooks let\n  an override inject an nginx sidecar that\n  terminates TLS on port 443 and reverse-proxies\n  to the uwsgi backend.\n* The Service targetPort is decoupled from TLS\n  into a dedicated network.\u003ckey\u003e.target_port\n  value (falling back to the Service port when\n  unset), so the chart no longer needs a tls\n  toggle to point the Service at the sidecar.\n  The per-service tls.\u003cservice\u003e toggles and the\n  API server-cert rendering are removed from the\n  charts entirely.\n* Exposure and the TLS objects live in the\n  per-chart values_overrides/\u003cchart\u003e/\n  tls-gateway-and-sidecar.yaml override: the\n  nginx sidecar (extraContainers/extraVolumes),\n  the https schemes, and extraObjects holding\n  the server Certificate, the HTTPRoute(s), the\n  nginx config ConfigMap(s) and the\n  BackendTLSPolicy(ies) so the Envoy Gateway\n  re-encrypts to the sidecar.\n\nClient-side trust (outbound TLS to other\nservices):\n\n* A single scalar secrets.tls.ca replaces the\n  tls.identity / manifests.certificates\n  client-trust gating. It is null by default -\u003e\n  no CA is mounted and REQUESTS_CA_BUNDLE is\n  left unset, so the chart renders zero TLS\n  plumbing. When set it names a CA-ONLY secret\n  holding just ca.crt -- no server certificate\n  and, crucially, no private key (server or CA)\n  reaches workload pods. The chart mounts only\n  ca.crt at /etc/ssl/certs/openstack-helm.crt\n  and points REQUESTS_CA_BUNDLE / OS_CACERT /\n  per-client cafile there; this also covers the\n  ks-* registration jobs, rally/selenium test\n  pods and the neutron metadata agent reaching\n  nova-metadata over https. Assumes every in-pod\n  TLS server cert is signed by the one ca-issuer\n  CA managed by cert-manager.\n* The CA-only secret (openstack-helm-ca) is\n  provisioned once into the workload namespace\n  by roles/deploy-charts (prepare-k8s.yaml),\n  reading ca.crt from the ca-issuer CA secret;\n  no signing material is ever distributed to\n  pods. The override sets secrets.tls.ca to it\n  and points cafiles at the canonical path.\n\nkeystone and horizon keep Apache httpd: keystone\nbecause its federated auth methods\n(OIDC/SAML2/Kerberos) delegate to Apache\nmodules, horizon because apache also serves the\ndashboard\u0027s static assets. In both, apache now\nserves plain HTTP behind the nginx sidecar (no\nSSLEngine), and horizon trusts the sidecar\u0027s\nX-Forwarded-Proto via SECURE_PROXY_SSL_HEADER.\nkeystone stays on the tls.identity client-trust\ngate for now and migrates to secrets.tls.ca in a\nfollow-up.\n\nmanifests.certificates is retired from the\nmigrated charts except neutron (OVN-agent certs,\nnot yet migrated) and cinder (its legacy\nstatefulset-volume mariadb/oslo_db certs, which\nare unrelated to the API path migrated here).\nnova\u0027s vencrypt cert (proxy\u003c-\u003ecompute VNC) is\nunrelated to API/outbound trust and is\npreserved.\n\nThe compute-kit-tls job is renamed to\nopenstack-helm-tls and switched to the 5-node\nrook nodeset; besides the compute kit it now\nalso deploys ceph, cinder and horizon (gated\ntasks in deploy-compute-kit.yaml) so their nginx\nTLS sidecars are exercised end to end. aodh and\ngnocchi have no CI job today and are validated by\nhelm template / helm lint only.\n\nAll other check-pipeline jobs are temporarily\ncommented out in zuul.d/project.yaml while this\nis iterated on; restore them before merge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/3099fccbad966b29a14b742eb74405a8473a9cd9"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/3099fccbad966b29a14b742eb74405a8473a9cd9"}]},"branch":"refs/heads/master"},"f656c98e64cde03e35e31bf1c4f717291ff3e9de":{"kind":"REWORK","_number":28,"created":"2026-06-26 20:14:27.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/28","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/28","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/28 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/28 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/28 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/28"}}},"commit":{"parents":[{"commit":"6ec1132485def4de18dcf00e4cb711925c42d70f","subject":"Remove Ingress templates; expose services via extraObjects","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/6ec1132485def4de18dcf00e4cb711925c42d70f"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-26 19:51:12.000000000","tz":-300},"subject":"[WIP] Terminate API TLS with nginx sidecars","message":"[WIP] Terminate API TLS with nginx sidecars\n\nReplace in-container Apache httpd / chart-native\nnginx TLS termination for the OpenStack API\nservices with a uniform nginx TLS-terminating\nsidecar defined entirely in the deployment\noverrides, so the charts stay agnostic of how\n(and whether) their services are exposed over\nTLS. Covers glance, heat (api+cfn), nova\n(osapi+metadata), neutron, placement, cinder,\naodh and gnocchi; keystone and horizon are\nconverted partially (see below).\n\nServer-side TLS (the chart\u0027s own exposure):\n\n* The main container runs uwsgi directly\n  (Apache removed where present), binding the\n  endpoint \"service\" scope port over plain HTTP\n  exactly as in the non-TLS case;\n  liveness/readiness probes hit that backend\n  directly.\n* New pod.extraContainers.\u003ccomponent\u003e and\n  pod.extraVolumes.\u003ccomponent\u003e render hooks let\n  an override inject an nginx sidecar that\n  terminates TLS on port 443 and reverse-proxies\n  to the uwsgi backend.\n* The Service targetPort is decoupled from TLS\n  into a dedicated network.\u003ckey\u003e.target_port\n  value (falling back to the Service port when\n  unset), so the chart no longer needs a tls\n  toggle to point the Service at the sidecar.\n  The per-service tls.\u003cservice\u003e toggles and the\n  API server-cert rendering are removed from the\n  charts entirely.\n* Exposure and the TLS objects live in the\n  per-chart values_overrides/\u003cchart\u003e/\n  tls-gateway-and-sidecar.yaml override: the\n  nginx sidecar (extraContainers/extraVolumes),\n  the https schemes, and extraObjects holding\n  the server Certificate, the HTTPRoute(s), the\n  nginx config ConfigMap(s) and the\n  BackendTLSPolicy(ies) so the Envoy Gateway\n  re-encrypts to the sidecar.\n\nClient-side trust (outbound TLS to other\nservices):\n\n* A single scalar secrets.tls.ca replaces the\n  tls.identity / manifests.certificates\n  client-trust gating. It is null by default -\u003e\n  no CA is mounted and REQUESTS_CA_BUNDLE is\n  left unset, so the chart renders zero TLS\n  plumbing. When set it names a CA-ONLY secret\n  holding just ca.crt -- no server certificate\n  and, crucially, no private key (server or CA)\n  reaches workload pods. The chart mounts only\n  ca.crt at /etc/ssl/certs/openstack-helm.crt\n  and points REQUESTS_CA_BUNDLE / OS_CACERT /\n  per-client cafile there; this also covers the\n  ks-* registration jobs, rally/selenium test\n  pods and the neutron metadata agent reaching\n  nova-metadata over https. Assumes every in-pod\n  TLS server cert is signed by the one ca-issuer\n  CA managed by cert-manager.\n* The CA-only secret (openstack-helm-ca) is\n  provisioned once into the workload namespace\n  by roles/deploy-charts (prepare-k8s.yaml),\n  reading ca.crt from the ca-issuer CA secret;\n  no signing material is ever distributed to\n  pods. The override sets secrets.tls.ca to it\n  and points cafiles at the canonical path.\n\nkeystone and horizon keep Apache httpd: keystone\nbecause its federated auth methods\n(OIDC/SAML2/Kerberos) delegate to Apache\nmodules, horizon because apache also serves the\ndashboard\u0027s static assets. In both, apache now\nserves plain HTTP behind the nginx sidecar (no\nSSLEngine), and horizon trusts the sidecar\u0027s\nX-Forwarded-Proto via SECURE_PROXY_SSL_HEADER.\nkeystone stays on the tls.identity client-trust\ngate for now and migrates to secrets.tls.ca in a\nfollow-up.\n\nmanifests.certificates is retired from the\nmigrated charts except neutron (OVN-agent certs,\nnot yet migrated). nova\u0027s vencrypt cert\n(proxy\u003c-\u003ecompute VNC) is unrelated to\nAPI/outbound trust and is preserved.\n\nThe compute-kit-tls job is renamed to\nopenstack-helm-tls and switched to the 5-node\nrook nodeset; besides the compute kit it now\nalso deploys ceph, cinder and horizon (gated\ntasks in deploy-compute-kit.yaml) so their nginx\nTLS sidecars are exercised end to end. aodh and\ngnocchi have no CI job today and are validated by\nhelm template / helm lint only.\n\nAll other check-pipeline jobs are temporarily\ncommented out in zuul.d/project.yaml while this\nis iterated on; restore them before merge.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/f656c98e64cde03e35e31bf1c4f717291ff3e9de"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/f656c98e64cde03e35e31bf1c4f717291ff3e9de"}]},"branch":"refs/heads/master"},"9ed140ecd4e1bc22c579ec592d1cf63167a2906c":{"kind":"REWORK","_number":29,"created":"2026-06-26 22:17:26.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/29","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/29","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/29 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/29 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/29 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/29"}}},"commit":{"parents":[{"commit":"6ec1132485def4de18dcf00e4cb711925c42d70f","subject":"Remove Ingress templates; expose services via extraObjects","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/6ec1132485def4de18dcf00e4cb711925c42d70f"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-26 22:17:25.000000000","tz":-300},"subject":"Terminate API TLS with nginx sidecars","message":"Terminate API TLS with nginx sidecars\n\nReplace in-container Apache httpd / chart-native\nnginx TLS termination for the OpenStack API\nservices with a uniform nginx TLS-terminating\nsidecar defined entirely in the deployment\noverrides, so the charts stay agnostic of how\n(and whether) their services are exposed over\nTLS. Covers glance, heat (api+cfn), nova\n(osapi+metadata), neutron, placement, cinder,\naodh and gnocchi; keystone and horizon are\nconverted partially (see below).\n\nServer-side TLS (the chart\u0027s own exposure):\n\n* The main container runs uwsgi directly\n  (Apache removed where present), binding the\n  endpoint \"service\" scope port over plain HTTP\n  exactly as in the non-TLS case;\n  liveness/readiness probes hit that backend\n  directly.\n* New pod.extraContainers.\u003ccomponent\u003e and\n  pod.extraVolumes.\u003ccomponent\u003e render hooks let\n  an override inject an nginx sidecar that\n  terminates TLS on port 443 and reverse-proxies\n  to the uwsgi backend.\n* The Service targetPort is decoupled from TLS\n  into a dedicated network.\u003ckey\u003e.target_port\n  value (falling back to the Service port when\n  unset), so the chart no longer needs a tls\n  toggle to point the Service at the sidecar.\n  The per-service tls.\u003cservice\u003e toggles and the\n  API server-cert rendering are removed from the\n  charts entirely.\n* Exposure and the TLS objects live in the\n  per-chart values_overrides/\u003cchart\u003e/\n  tls-gateway-and-sidecar.yaml override: the\n  nginx sidecar (extraContainers/extraVolumes),\n  the https schemes, and extraObjects holding\n  the server Certificate, the HTTPRoute(s), the\n  nginx config ConfigMap(s) and the\n  BackendTLSPolicy(ies) so the Envoy Gateway\n  re-encrypts to the sidecar.\n\nClient-side trust (outbound TLS to other\nservices):\n\n* A single scalar secrets.tls.ca replaces the\n  tls.identity / manifests.certificates\n  client-trust gating. It is null by default -\u003e\n  no CA is mounted and REQUESTS_CA_BUNDLE is\n  left unset, so the chart renders zero TLS\n  plumbing. When set it names a CA-ONLY secret\n  holding just ca.crt -- no server certificate\n  and, crucially, no private key (server or CA)\n  reaches workload pods. The chart mounts only\n  ca.crt at /etc/ssl/certs/openstack-helm.crt\n  and points REQUESTS_CA_BUNDLE / OS_CACERT /\n  per-client cafile there; this also covers the\n  ks-* registration jobs, rally/selenium test\n  pods and the neutron metadata agent reaching\n  nova-metadata over https. Assumes every in-pod\n  TLS server cert is signed by the one ca-issuer\n  CA managed by cert-manager.\n* The CA-only secret (openstack-helm-ca) is\n  provisioned once into the workload namespace\n  by roles/deploy-charts (prepare-k8s.yaml),\n  reading ca.crt from the ca-issuer CA secret;\n  no signing material is ever distributed to\n  pods. The override sets secrets.tls.ca to it\n  and points cafiles at the canonical path.\n\nkeystone and horizon keep Apache httpd: keystone\nbecause its federated auth methods\n(OIDC/SAML2/Kerberos) delegate to Apache\nmodules, horizon because apache also serves the\ndashboard\u0027s static assets. In both, apache now\nserves plain HTTP behind the nginx sidecar (no\nSSLEngine), and horizon trusts the sidecar\u0027s\nX-Forwarded-Proto via SECURE_PROXY_SSL_HEADER.\nkeystone stays on the tls.identity client-trust\ngate for now and migrates to secrets.tls.ca in a\nfollow-up.\n\nmanifests.certificates is retired from the\nmigrated charts except neutron (OVN-agent certs,\nnot yet migrated). nova\u0027s vencrypt cert\n(proxy\u003c-\u003ecompute VNC) is unrelated to\nAPI/outbound trust and is preserved.\n\nThe compute-kit-tls job is renamed to\nopenstack-helm-tls and switched to the 5-node\nrook nodeset; besides the compute kit it now\nalso deploys ceph, cinder and horizon (gated\ntasks in deploy-compute-kit.yaml) so their nginx\nTLS sidecars are exercised end to end. aodh and\ngnocchi have no CI job today and are validated by\nhelm template / helm lint only.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/9ed140ecd4e1bc22c579ec592d1cf63167a2906c"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/9ed140ecd4e1bc22c579ec592d1cf63167a2906c"}]},"branch":"refs/heads/master"},"5b3b3337a321cd59727bb0de0ab3bd838850b496":{"kind":"REWORK","_number":30,"created":"2026-07-01 16:40:35.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/30","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/30","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/30 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/30 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/30 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/30"}}},"commit":{"parents":[{"commit":"7cce5ac4555a1c2bddf2fdbb239028cee12e49c4","subject":"limit envsubst by specifying the list of env variables","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/7cce5ac4555a1c2bddf2fdbb239028cee12e49c4"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-01 16:35:00.000000000","tz":-300},"subject":"Terminate API TLS with nginx sidecars","message":"Terminate API TLS with nginx sidecars\n\nReplace in-container Apache httpd / chart-native\nnginx TLS termination for the OpenStack API\nservices with a uniform nginx TLS-terminating\nsidecar defined entirely in the deployment\noverrides, so the charts stay agnostic of how\n(and whether) their services are exposed over\nTLS. Covers glance, heat (api+cfn), nova\n(osapi+metadata), neutron, placement, cinder,\naodh and gnocchi; keystone and horizon are\nconverted partially (see below).\n\nServer-side TLS (the chart\u0027s own exposure):\n\n* The main container runs uwsgi directly\n  (Apache removed where present), binding the\n  endpoint \"service\" scope port over plain HTTP\n  exactly as in the non-TLS case;\n  liveness/readiness probes hit that backend\n  directly.\n* New pod.extraContainers.\u003ccomponent\u003e and\n  pod.extraVolumes.\u003ccomponent\u003e render hooks let\n  an override inject an nginx sidecar that\n  terminates TLS on port 443 and reverse-proxies\n  to the uwsgi backend.\n* The Service targetPort is decoupled from TLS\n  into a dedicated network.\u003ckey\u003e.target_port\n  value (falling back to the Service port when\n  unset), so the chart no longer needs a tls\n  toggle to point the Service at the sidecar.\n  The per-service tls.\u003cservice\u003e toggles and the\n  API server-cert rendering are removed from the\n  charts entirely.\n* Exposure and the TLS objects live in the\n  per-chart values_overrides/\u003cchart\u003e/\n  tls-gateway-and-sidecar.yaml override: the\n  nginx sidecar (extraContainers/extraVolumes),\n  the https schemes, and extraObjects holding\n  the server Certificate, the HTTPRoute(s), the\n  nginx config ConfigMap(s) and the\n  BackendTLSPolicy(ies) so the Envoy Gateway\n  re-encrypts to the sidecar.\n\nClient-side trust (outbound TLS to other\nservices):\n\n* A single scalar secrets.tls.ca replaces the\n  tls.identity / manifests.certificates\n  client-trust gating. It is null by default -\u003e\n  no CA is mounted and REQUESTS_CA_BUNDLE is\n  left unset, so the chart renders zero TLS\n  plumbing. When set it names a CA-ONLY secret\n  holding just ca.crt -- no server certificate\n  and, crucially, no private key (server or CA)\n  reaches workload pods. The chart mounts only\n  ca.crt at /etc/ssl/certs/openstack-helm.crt\n  and points REQUESTS_CA_BUNDLE / OS_CACERT /\n  per-client cafile there; this also covers the\n  ks-* registration jobs, rally/selenium test\n  pods and the neutron metadata agent reaching\n  nova-metadata over https. Assumes every in-pod\n  TLS server cert is signed by the one ca-issuer\n  CA managed by cert-manager.\n* The CA-only secret (openstack-helm-ca) is\n  provisioned once into the workload namespace\n  by roles/deploy-charts (prepare-k8s.yaml),\n  reading ca.crt from the ca-issuer CA secret;\n  no signing material is ever distributed to\n  pods. The override sets secrets.tls.ca to it\n  and points cafiles at the canonical path.\n\nkeystone and horizon keep Apache httpd: keystone\nbecause its federated auth methods\n(OIDC/SAML2/Kerberos) delegate to Apache\nmodules, horizon because apache also serves the\ndashboard\u0027s static assets. In both, apache now\nserves plain HTTP behind the nginx sidecar (no\nSSLEngine), and horizon trusts the sidecar\u0027s\nX-Forwarded-Proto via SECURE_PROXY_SSL_HEADER.\nkeystone stays on the tls.identity client-trust\ngate for now and migrates to secrets.tls.ca in a\nfollow-up.\n\nmanifests.certificates is retired from the\nmigrated charts except neutron (OVN-agent certs,\nnot yet migrated). nova\u0027s vencrypt cert\n(proxy\u003c-\u003ecompute VNC) is unrelated to\nAPI/outbound trust and is preserved.\n\nThe compute-kit-tls job is renamed to\nopenstack-helm-tls and switched to the 5-node\nrook nodeset; besides the compute kit it now\nalso deploys ceph, cinder and horizon (gated\ntasks in deploy-compute-kit.yaml) so their nginx\nTLS sidecars are exercised end to end. aodh and\ngnocchi have no CI job today and are validated by\nhelm template / helm lint only.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/5b3b3337a321cd59727bb0de0ab3bd838850b496"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/5b3b3337a321cd59727bb0de0ab3bd838850b496"}]},"branch":"refs/heads/master"},"d141687d3b237a3ed34e90ebafc7933b7cde7677":{"kind":"REWORK","_number":31,"created":"2026-07-02 21:11:06.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/28/992528/31","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/28/992528/31","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/31 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/31 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/31 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/28/992528/31"}}},"commit":{"parents":[{"commit":"a659ab8a2f1f03f7bce4cca1819dfac59e0ae4a5","subject":"Merge \"fix: wire identity.openrc to custom templates\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/a659ab8a2f1f03f7bce4cca1819dfac59e0ae4a5"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-06-09 19:01:43.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-02 21:10:22.000000000","tz":-300},"subject":"Terminate API TLS with nginx sidecars","message":"Terminate API TLS with nginx sidecars\n\nReplace in-container Apache httpd / chart-native\nnginx TLS termination for the OpenStack API\nservices with a uniform nginx TLS-terminating\nsidecar defined entirely in the deployment\noverrides, so the charts stay agnostic of how\n(and whether) their services are exposed over\nTLS. Covers glance, heat (api+cfn), nova\n(osapi+metadata), neutron, placement, cinder,\naodh and gnocchi; keystone and horizon are\nconverted partially (see below).\n\nServer-side TLS (the chart\u0027s own exposure):\n\n* The main container runs uwsgi directly\n  (Apache removed where present), binding the\n  endpoint \"service\" scope port over plain HTTP\n  exactly as in the non-TLS case;\n  liveness/readiness probes hit that backend\n  directly.\n* New pod.extraContainers.\u003ccomponent\u003e and\n  pod.extraVolumes.\u003ccomponent\u003e render hooks let\n  an override inject an nginx sidecar that\n  terminates TLS on port 443 and reverse-proxies\n  to the uwsgi backend.\n* The Service targetPort is decoupled from TLS\n  into a dedicated network.\u003ckey\u003e.target_port\n  value (falling back to the Service port when\n  unset), so the chart no longer needs a tls\n  toggle to point the Service at the sidecar.\n  The per-service tls.\u003cservice\u003e toggles and the\n  API server-cert rendering are removed from the\n  charts entirely.\n* Exposure and the TLS objects live in the\n  per-chart values_overrides/\u003cchart\u003e/\n  tls-gateway-and-sidecar.yaml override: the\n  nginx sidecar (extraContainers/extraVolumes),\n  the https schemes, and extraObjects holding\n  the server Certificate, the HTTPRoute(s), the\n  nginx config ConfigMap(s) and the\n  BackendTLSPolicy(ies) so the Envoy Gateway\n  re-encrypts to the sidecar.\n\nClient-side trust (outbound TLS to other\nservices):\n\n* A single scalar secrets.tls.ca replaces the\n  tls.identity / manifests.certificates\n  client-trust gating. It is null by default -\u003e\n  no CA is mounted and REQUESTS_CA_BUNDLE is\n  left unset, so the chart renders zero TLS\n  plumbing. When set it names a CA-ONLY secret\n  holding just ca.crt -- no server certificate\n  and, crucially, no private key (server or CA)\n  reaches workload pods. The chart mounts only\n  ca.crt at /etc/ssl/certs/openstack-helm.crt\n  and points REQUESTS_CA_BUNDLE / OS_CACERT /\n  per-client cafile there; this also covers the\n  ks-* registration jobs, rally/selenium test\n  pods and the neutron metadata agent reaching\n  nova-metadata over https. Assumes every in-pod\n  TLS server cert is signed by the one ca-issuer\n  CA managed by cert-manager.\n* The CA-only secret (openstack-helm-ca) is\n  provisioned once into the workload namespace\n  by roles/deploy-charts (prepare-k8s.yaml),\n  reading ca.crt from the ca-issuer CA secret;\n  no signing material is ever distributed to\n  pods. The override sets secrets.tls.ca to it\n  and points cafiles at the canonical path.\n\nkeystone and horizon keep Apache httpd: keystone\nbecause its federated auth methods\n(OIDC/SAML2/Kerberos) delegate to Apache\nmodules, horizon because apache also serves the\ndashboard\u0027s static assets. In both, apache now\nserves plain HTTP behind the nginx sidecar (no\nSSLEngine), and horizon trusts the sidecar\u0027s\nX-Forwarded-Proto via SECURE_PROXY_SSL_HEADER.\nkeystone stays on the tls.identity client-trust\ngate for now and migrates to secrets.tls.ca in a\nfollow-up.\n\nmanifests.certificates is retired from the\nmigrated charts except neutron (OVN-agent certs,\nnot yet migrated). nova\u0027s vencrypt cert\n(proxy\u003c-\u003ecompute VNC) is unrelated to\nAPI/outbound trust and is preserved.\n\nThe compute-kit-tls job is renamed to\nopenstack-helm-tls and switched to the 5-node\nrook nodeset; besides the compute kit it now\nalso deploys ceph, cinder and horizon (gated\ntasks in deploy-compute-kit.yaml) so their nginx\nTLS sidecars are exercised end to end. aodh and\ngnocchi have no CI job today and are validated by\nhelm template / helm lint only.\n\nChange-Id: I89829176d4d85c7033af8ac2f5a8d6af23037e4d\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/d141687d3b237a3ed34e90ebafc7933b7cde7677"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/d141687d3b237a3ed34e90ebafc7933b7cde7677"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":34520,"name":"Sergiy Markin","email":"smarkin@mirantis.com","username":"sm515x"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
