)]}'
{"id":"openstack%2Fopenstack-helm~999342","triplet_id":"openstack%2Fopenstack-helm~master~Ic6dfcc4b5efea516ceb729e2bce22f5e1dc1f011","project":"openstack/openstack-helm","branch":"master","attention_set":{},"removed_from_attention_set":{"3009":{"account":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"last_update":"2026-08-03 15:41:21.000000000","reason":"Change was marked work in progress"}},"hashtags":[],"change_id":"Ic6dfcc4b5efea516ceb729e2bce22f5e1dc1f011","subject":"[WIP] Declarative MariaDB database management","status":"NEW","created":"2026-07-30 22:25:48.000000000","updated":"2026-08-08 01:47:45.000000000","submit_type":"MERGE_IF_NECESSARY","mergeable":true,"submittable":false,"total_comment_count":0,"unresolved_comment_count":0,"work_in_progress":true,"has_review_started":true,"meta_rev_id":"9d69d10c042abfb389f099c47959a31d86868317","_number":999342,"virtual_id_number":999342,"owner":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"tag":"autogenerated:zuul:check","value":1,"date":"2026-08-08 01:47:45.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{"REVIEWER":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"reviewer_updates":[{"updated":"2026-07-31 00:15:08.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"52d11f084e4d663a140070e1a9226664b683f713","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-07-30 22:25:48.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"bad2ce9620e95397f2ba89267d118f9a9481fba2","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-07-30 22:33:14.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"f7bcc4d43d8364e47beb6663792c5dded816fe7f","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-07-30 22:36:52.000000000","message":"Uploaded patch set 3: New patch set was added with same tree, parent tree, and commit message as Patch Set 2.","accounts_in_message":[],"_revision_number":3},{"id":"45ee72cf437387c7f63cfa1a37db98cb399a3824","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-31 00:15:08.000000000","message":"Patch Set 3: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/ca23e6c5d5ea450ba66ae14d2a80e737\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/0d34e20e60974431bfccb698dd6dade1 : SUCCESS in 3m 23s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/58f2a9524bcd434987799f396061aaba : SUCCESS in 2m 25s\n- openstack-helm-linter https://zuul.opendev.org/t/openstack/build/c40725c7aab74f2d9d2d4199d8c219c9 : SUCCESS in 4m 06s\n- openstack-helm-mariadb-crd-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/371a4bd135364881acedfd9fba108d8f : FAILURE in 1h 37m 44s","accounts_in_message":[],"_revision_number":3},{"id":"3d341468d6845ad0de32388a1ba97225c9285f0b","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-07-31 00:36:52.000000000","message":"Uploaded patch set 4.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":4},{"id":"992a19f2203a394da079933a69cc5c8adafcd2b3","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-31 01:29:50.000000000","message":"Patch Set 4: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/aa343ad217294a13ba96ed06e61f7e43\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/b30c218d022c4e6fbfc8632ad419a578 : SUCCESS in 3m 10s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/bf010d3023204d6ca3f16e6d36a67a09 : SUCCESS in 2m 16s\n- openstack-helm-linter https://zuul.opendev.org/t/openstack/build/a60f5933643c48f1bfdd92fba4d9b2e0 : SUCCESS in 2m 47s\n- openstack-helm-mariadb-crd-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/259585f09be5407a9d990d6eca163a1d : FAILURE in 51m 38s","accounts_in_message":[],"_revision_number":4},{"id":"9b8d712378edcf963c8a1f254532fba8381841ae","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-07-31 02:59:45.000000000","message":"Uploaded patch set 5.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":5},{"id":"72de9661b901f8c839d4bbdf36588f2058db9166","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-31 05:07:16.000000000","message":"Patch Set 5: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/3d855fa1b6c24c6bbfa799f0bdb39d21\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/eea4dd851fb1453882059b99bd65ad15 : SUCCESS in 5m 06s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/cb66c06368244c9fb45a18c8746a2d13 : SUCCESS in 4m 41s\n- openstack-helm-linter https://zuul.opendev.org/t/openstack/build/77ac75762e3442df8ab860b8c641e3e1 : SUCCESS in 4m 46s\n- openstack-helm-mariadb-crd-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/406b73f6f6df48df9a1583a71ca19f29 : SUCCESS in 1h 53m 11s","accounts_in_message":[],"_revision_number":5},{"id":"8b6aa49c6e7c1b3e83d5bb3ba6235f2ff8387ffa","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-08-03 15:41:21.000000000","message":"Uploaded patch set 6.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":6},{"id":"96ac35079c728bba59f747ba0e6dfd49a0757e49","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-03 17:07:26.000000000","message":"Patch Set 6: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/de03adf49a2e4a7d86bce5abfd1e8159\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/2cb29a6fc66946a9ac72cf1f0dc04e31 : SUCCESS in 5m 12s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/5a568d3d6279471bbc9efc9d673797f3 : SUCCESS in 3m 08s\n- openstack-helm-linter https://zuul.opendev.org/t/openstack/build/64a7c93280f54ce2bae4e5c8e5770ab9 : SUCCESS in 2m 50s\n- openstack-helm-mariadb-crd-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/f1e82c8b402d4cb89c38e7107781b178 : SUCCESS in 1h 19m 38s","accounts_in_message":[],"_revision_number":6},{"id":"15c347db7a0446d1d721b85bcdd5606682283842","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-08-03 17:11:39.000000000","message":"Uploaded patch set 7.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":7},{"id":"02b97ca8ff46909b22bf68b4165aadfe3ad360b2","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-03 19:02:41.000000000","message":"Patch Set 7: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/ecadd09fd468419fbab5194212a2db12\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/5c2c333480314d2ca2f290e9c94185d6 : SUCCESS in 4m 26s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/076a5403f9b247b292740c9f5cd43d53 : SUCCESS in 2m 30s\n- openstack-helm-linter https://zuul.opendev.org/t/openstack/build/b7fc6e5acaf24cc0b3ee4c0c7b98644e : SUCCESS in 3m 27s\n- openstack-helm-mariadb-crd-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/fa0d1f38c9f740239f9f6e6320cb96b2 : SUCCESS in 1h 37m 44s","accounts_in_message":[],"_revision_number":7},{"id":"77148aa0673e188a2cbfa8bd1ba3a2357abd1fb8","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-08-03 19:56:28.000000000","message":"Uploaded patch set 8.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":8},{"id":"d22e4f0ff47855aea25bf1e2ae8943442980cea2","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-03 20:58:14.000000000","message":"Patch Set 8: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/840a1139019547ae9dc5cacdd334bdfb\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/380c6de33b584ebda9fa532904bf5cd5 : SUCCESS in 2m 36s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/9b11affcbb2c49659c1670c96a47e371 : SUCCESS in 3m 04s\n- openstack-helm-linter https://zuul.opendev.org/t/openstack/build/baa93eedeaf64f20982997ef05dd9919 : SUCCESS in 3m 03s\n- openstack-helm-mariadb-crd-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/cc97a857f119463fbad62337aac18fd2 : SUCCESS in 59m 38s","accounts_in_message":[],"_revision_number":8},{"id":"774173a2fbc1c88edf4b8a7b9cb5b19a7c4485c7","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-08-07 19:34:41.000000000","message":"Uploaded patch set 9.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":9},{"id":"fd789d2fc62db5b8451567c628939c723226d742","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-07 21:18:09.000000000","message":"Patch Set 9: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/b606ddeb846b4b84aacfd5fb8b59d72c\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/e7cda806fdc14e3e88d214a79e0c65c5 : SUCCESS in 4m 02s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/0520ead9470d4abfbe72a6f781ad8340 : SUCCESS in 3m 15s\n- openstack-helm-linter https://zuul.opendev.org/t/openstack/build/aceebdc0e64d46829f1b1451a9c797ee : SUCCESS in 4m 09s\n- openstack-helm-mariadb-crd-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/31092976c59048ffae0253b09663bfc4 : SUCCESS in 1h 40m 37s","accounts_in_message":[],"_revision_number":9},{"id":"91c6b555c4f187f818fd7eea8256f7b107e1f9a8","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-08-07 21:49:11.000000000","message":"Uploaded patch set 10.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":10},{"id":"bb1c4c11410a5572a8668d6d697fb3057e17df66","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-07 23:22:35.000000000","message":"Patch Set 10: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/f9e77e7c89cc4691ba38b087310e10ff\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/894ac5e4f2c04150810ccdb326dd423c : SUCCESS in 3m 23s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/22c1875758a74777a99033bde2fe9889 : SUCCESS in 4m 43s\n- openstack-helm-linter https://zuul.opendev.org/t/openstack/build/b29b1c1772de4c7f80d10ff784d620fa : SUCCESS in 1m 49s\n- openstack-helm-mariadb-crd-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/ff854133faa24103a99a5bdd77a978b5 : SUCCESS in 1h 00m 32s\n- openstack-helm-mariadb-operator-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/2f0af89983544888815b640bf652f722 : SUCCESS in 1h 30m 26s","accounts_in_message":[],"_revision_number":10},{"id":"6cd005d5cc31e84471ac947b7184f19ef8c42393","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-08-07 23:58:02.000000000","message":"Uploaded patch set 11.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":11},{"id":"9d69d10c042abfb389f099c47959a31d86868317","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-08 01:47:45.000000000","message":"Patch Set 11: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/17ed72597fa24b2ba5aac0543aa6ee60\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/33613a8d675847e594d7e30026fe5980 : SUCCESS in 5m 09s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/681e8463193c4eb7b5447f1fda40a3a1 : SUCCESS in 3m 34s\n- openstack-helm-linter https://zuul.opendev.org/t/openstack/build/c8765b341622488eaa6a469882cee72d : SUCCESS in 4m 37s\n- openstack-helm-mariadb-crd-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/146691ff2b344cb99d64ae9cf93fc2b3 : SUCCESS in 1h 37m 14s\n- openstack-helm-mariadb-operator-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/affd5b60e980472198e8a37942a139c7 : SUCCESS in 1h 25m 26s\n- openstack-helm-pre-commit https://zuul.opendev.org/t/openstack/build/bcb2cd7b70c54d80a005b8ad3a809081 : SUCCESS in 2m 50s\n- openstack-helm-bandit https://zuul.opendev.org/t/openstack/build/f74be2a663be457ba6deabd1878c56a1 : SUCCESS in 3m 00s\n- openstack-helm-build-charts https://zuul.opendev.org/t/openstack/build/d09e3fe6fc284c168793094756d96543 : SUCCESS in 2m 51s\n- openstack-helm-cinder-2025-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/f300e5cf079a4bfbaaa86095a1ad6da4 : SUCCESS in 42m 51s\n- openstack-helm-compute-kit-2025-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/8a28e2bda0ec435fba302a2230f8268a : SUCCESS in 44m 51s\n- openstack-helm-cinder-2025-2-ubuntu_noble https://zuul.opendev.org/t/openstack/build/7a0cdb691f33463eae6c3ce60c2157e9 : SUCCESS in 43m 01s\n- openstack-helm-compute-kit-2025-2-ubuntu_noble https://zuul.opendev.org/t/openstack/build/f9c24cb2f6284c6c95e8cf4184d5c3f6 : SUCCESS in 1h 13m 27s\n- openstack-helm-cinder-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/75e239257e094ca2a0fa536f090242bd : SUCCESS in 45m 56s\n- openstack-helm-compute-kit-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/2a0d56ce8cc54ff1b6f40a2cd8676e63 : SUCCESS in 1h 12m 09s\n- openstack-helm-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/d114fd22583b46dbb39d799d18bdd8fd : SUCCESS in 1h 42m 40s\n- openstack-helm-compute-kit-dpdk-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/8bc7deb2850e49bbb86e6a3014ff4e25 : SUCCESS in 54m 34s\n- openstack-helm-octavia-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/133d3bf839804bc3b5efee67141a3078 : SUCCESS in 1h 19m 23s\n- openstack-helm-logging https://zuul.opendev.org/t/openstack/build/b94c66855e2f4750ae74cc5b909e8dba : SUCCESS in 25m 42s\n- openstack-helm-monitoring https://zuul.opendev.org/t/openstack/build/73eb18943f504ed2ad791044734d97e0 : SUCCESS in 33m 45s","accounts_in_message":[],"_revision_number":11}],"current_revision_number":11,"current_revision":"c943c71eb62bba995aefad3cf67977314c6d3042","revisions":{"d0a7fa49b7f53b0862a7313d30829e7790c848d7":{"kind":"REWORK","_number":1,"created":"2026-07-30 22:25:48.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/42/999342/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/42/999342/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/1"}}},"commit":{"parents":[{"commit":"50c697fc3cb4307d7f8e278a1ad7366e5f7260a7","subject":"Merge \"Terminate API TLS with nginx sidecars\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/50c697fc3cb4307d7f8e278a1ad7366e5f7260a7"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-30 22:23:08.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-30 22:23:08.000000000","tz":-300},"subject":"[WIP] Declarative MariaDB database management","message":"[WIP] Declarative MariaDB database management\n\nProvision service databases from custom resources reconciled inside the\ncluster, instead of running a per-chart db-init job that mounts the MariaDB\nadministrative connection URI into the OpenStack namespace.\n\nThe mariadb chart gains four namespaced CRDs in the\nmariadb.osh.openstack.org/v1alpha1 group -- Database, User, Grant and\nConnection -- and a single-file Python reconciler, modelled on the Galera\nprimary-election controller the chart already ships. The field names are a\nsubset of, and compatible with, the upstream mariadb-operator group, so the\nsame consumer templates can be retargeted at the full operator by changing one\napiVersion argument. Two deliberate divergences: spec.name carries the MariaDB\nobject name, because a schema called nova_api is not a valid Kubernetes object\nname, and maxUserConnections defaults to 0 rather than upstream\u0027s 10, which\nwould throttle every OpenStack service.\n\nConsumer charts render those resources through a new Helm-toolkit manifest,\nhelm-toolkit.manifests.mariadb_db. Everything is derived from the endpoints\nvalues the chart already declares, so no credential is duplicated: path is the\ndatabase name and auth.\u003cuserClass\u003e are the credentials. Charts owning several\ndatabases pass a databases list the way nova passes dbsToInit, and accounts\nshared between those databases collapse into a single User -- nova gets one\nUser and password secret for its three databases.\n\nA Connection materializes an oslo.config snippet secret which every\ndatabase-reading workload projects into the service config directory, via a new\nhelm-toolkit.snippets.mariadb_db_etc_sources. Wiring it into\nhelm-toolkit.manifests.job_db_sync covers the db-sync job of every chart at\nonce. Because a projected volume source is not optional, kubelet holds the pod\nuntil the reconciler has written the secret, so db-sync waits for the database\nrather than failing.\n\nkeystone, cinder, glance, heat, placement, nova and neutron are converted --\nevery chart owning a database in the compute kit plus cinder job. nova-compute\nand the neutron agents deliberately do not get the connection secret, since\nthey do not use the database.\n\nEverything is off by default, so the rendered output of all seven charts and of\nthe mariadb chart\u0027s existing resources is byte-identical; the only addition at\ndefault values is the four inert CRDs. Enabling the reconciler is gated so the\nmariadb-bin configmap keeps its hash, which would otherwise roll the galera\nstatefulset on upgrade. The new path is exercised by the\nopenstack-helm-mariadb-crd-2026-1-ubuntu_noble job and the per-chart\nvalues_overrides/\u003cchart\u003e/mariadb-crd.yaml overrides.\n\nAlso defines pod.resources.controller in the mariadb chart, which\ndeployment-controller.yaml has always referenced but which was never declared.\n\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\nChange-Id: Ic6dfcc4b5efea516ceb729e2bce22f5e1dc1f011\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/d0a7fa49b7f53b0862a7313d30829e7790c848d7"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/d0a7fa49b7f53b0862a7313d30829e7790c848d7"}]},"branch":"refs/heads/master"},"b377811a6739cad965f932344f605277dfc393e1":{"kind":"REWORK","_number":2,"created":"2026-07-30 22:33:14.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/42/999342/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/42/999342/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/2"}}},"commit":{"parents":[{"commit":"50c697fc3cb4307d7f8e278a1ad7366e5f7260a7","subject":"Merge \"Terminate API TLS with nginx sidecars\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/50c697fc3cb4307d7f8e278a1ad7366e5f7260a7"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-30 22:23:08.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-30 22:33:08.000000000","tz":-300},"subject":"[WIP] Declarative MariaDB database management","message":"[WIP] Declarative MariaDB database management\n\nProvision service databases from custom resources reconciled inside the\ncluster, instead of running a per-chart db-init job that mounts the MariaDB\nadministrative connection URI into the OpenStack namespace.\n\nThe mariadb chart gains four namespaced CRDs in the\nmariadb.osh.openstack.org/v1alpha1 group -- Database, User, Grant and\nConnection -- and a single-file Python reconciler, modelled on the Galera\nprimary-election controller the chart already ships. The field names are a\nsubset of, and compatible with, the upstream mariadb-operator group, so the\nsame consumer templates can be retargeted at the full operator by changing one\napiVersion argument. Two deliberate divergences: spec.name carries the MariaDB\nobject name, because a schema called nova_api is not a valid Kubernetes object\nname, and maxUserConnections defaults to 0 rather than upstream\u0027s 10, which\nwould throttle every OpenStack service.\n\nConsumer charts render those resources through a new Helm-toolkit manifest,\nhelm-toolkit.manifests.mariadb_db. Everything is derived from the endpoints\nvalues the chart already declares, so no credential is duplicated: path is the\ndatabase name and auth.\u003cuserClass\u003e are the credentials. Charts owning several\ndatabases pass a databases list the way nova passes dbsToInit, and accounts\nshared between those databases collapse into a single User -- nova gets one\nUser and password secret for its three databases.\n\nA Connection materializes an oslo.config snippet secret which every\ndatabase-reading workload projects into the service config directory, via a new\nhelm-toolkit.snippets.mariadb_db_etc_sources. Wiring it into\nhelm-toolkit.manifests.job_db_sync covers the db-sync job of every chart at\nonce. Because a projected volume source is not optional, kubelet holds the pod\nuntil the reconciler has written the secret, so db-sync waits for the database\nrather than failing.\n\nkeystone, cinder, glance, heat, placement, nova and neutron are converted --\nevery chart owning a database in the compute kit plus cinder job. nova-compute\nand the neutron agents deliberately do not get the connection secret, since\nthey do not use the database.\n\nEverything is off by default, so the rendered output of all seven charts and of\nthe mariadb chart\u0027s existing resources is byte-identical; the only addition at\ndefault values is the four inert CRDs. Enabling the reconciler is gated so the\nmariadb-bin configmap keeps its hash, which would otherwise roll the galera\nstatefulset on upgrade. The new path is exercised by the\nopenstack-helm-mariadb-crd-2026-1-ubuntu_noble job and the per-chart\nvalues_overrides/\u003cchart\u003e/mariadb-crd.yaml overrides.\n\nAlso defines pod.resources.controller in the mariadb chart, which\ndeployment-controller.yaml has always referenced but which was never declared.\n\nDNM: while this is in progress the check pipeline is trimmed to just\nopenstack-helm-linter and the new job, so iterating does not burn a full\nrun of every job. The commented block in zuul.d/project.yaml is delimited\nby DNM(mariadb-crd) markers and must be restored before this merges:\n`grep -rn \u0027DNM(mariadb-crd)\u0027 zuul.d/` must print nothing. The gate\npipeline is deliberately left untouched, so the full cinder and\ncompute-kit jobs still guard the merge.\n\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\nChange-Id: Ic6dfcc4b5efea516ceb729e2bce22f5e1dc1f011\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/b377811a6739cad965f932344f605277dfc393e1"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/b377811a6739cad965f932344f605277dfc393e1"}]},"branch":"refs/heads/master"},"09f727023c0597fa75aa12a3090d430e53ece780":{"kind":"NO_CHANGE","_number":3,"created":"2026-07-30 22:36:52.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/42/999342/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/42/999342/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/3"}}},"commit":{"parents":[{"commit":"50c697fc3cb4307d7f8e278a1ad7366e5f7260a7","subject":"Merge \"Terminate API TLS with nginx sidecars\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/50c697fc3cb4307d7f8e278a1ad7366e5f7260a7"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-30 22:36:51.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-30 22:36:51.000000000","tz":-300},"subject":"[WIP] Declarative MariaDB database management","message":"[WIP] Declarative MariaDB database management\n\nProvision service databases from custom resources reconciled inside the\ncluster, instead of running a per-chart db-init job that mounts the MariaDB\nadministrative connection URI into the OpenStack namespace.\n\nThe mariadb chart gains four namespaced CRDs in the\nmariadb.osh.openstack.org/v1alpha1 group -- Database, User, Grant and\nConnection -- and a single-file Python reconciler, modelled on the Galera\nprimary-election controller the chart already ships. The field names are a\nsubset of, and compatible with, the upstream mariadb-operator group, so the\nsame consumer templates can be retargeted at the full operator by changing one\napiVersion argument. Two deliberate divergences: spec.name carries the MariaDB\nobject name, because a schema called nova_api is not a valid Kubernetes object\nname, and maxUserConnections defaults to 0 rather than upstream\u0027s 10, which\nwould throttle every OpenStack service.\n\nConsumer charts render those resources through a new Helm-toolkit manifest,\nhelm-toolkit.manifests.mariadb_db. Everything is derived from the endpoints\nvalues the chart already declares, so no credential is duplicated: path is the\ndatabase name and auth.\u003cuserClass\u003e are the credentials. Charts owning several\ndatabases pass a databases list the way nova passes dbsToInit, and accounts\nshared between those databases collapse into a single User -- nova gets one\nUser and password secret for its three databases.\n\nA Connection materializes an oslo.config snippet secret which every\ndatabase-reading workload projects into the service config directory, via a new\nhelm-toolkit.snippets.mariadb_db_etc_sources. Wiring it into\nhelm-toolkit.manifests.job_db_sync covers the db-sync job of every chart at\nonce. Because a projected volume source is not optional, kubelet holds the pod\nuntil the reconciler has written the secret, so db-sync waits for the database\nrather than failing.\n\nkeystone, cinder, glance, heat, placement, nova and neutron are converted --\nevery chart owning a database in the compute kit plus cinder job. nova-compute\nand the neutron agents deliberately do not get the connection secret, since\nthey do not use the database.\n\nEverything is off by default, so the rendered output of all seven charts and of\nthe mariadb chart\u0027s existing resources is byte-identical; the only addition at\ndefault values is the four inert CRDs. Enabling the reconciler is gated so the\nmariadb-bin configmap keeps its hash, which would otherwise roll the galera\nstatefulset on upgrade. The new path is exercised by the\nopenstack-helm-mariadb-crd-2026-1-ubuntu_noble job and the per-chart\nvalues_overrides/\u003cchart\u003e/mariadb-crd.yaml overrides.\n\nAlso defines pod.resources.controller in the mariadb chart, which\ndeployment-controller.yaml has always referenced but which was never declared.\n\nDNM: while this is in progress the check pipeline is trimmed to just\nopenstack-helm-linter and the new job, so iterating does not burn a full\nrun of every job. The commented block in zuul.d/project.yaml is delimited\nby DNM(mariadb-crd) markers and must be restored before this merges:\n`grep -rn \u0027DNM(mariadb-crd)\u0027 zuul.d/` must print nothing. The gate\npipeline is deliberately left untouched, so the full cinder and\ncompute-kit jobs still guard the merge.\n\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\nChange-Id: Ic6dfcc4b5efea516ceb729e2bce22f5e1dc1f011\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/09f727023c0597fa75aa12a3090d430e53ece780"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/09f727023c0597fa75aa12a3090d430e53ece780"}]},"branch":"refs/heads/master"},"f19287e1291e15da7c1c059a5f4c64e110e1fe51":{"kind":"REWORK","_number":4,"created":"2026-07-31 00:36:52.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/42/999342/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/42/999342/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/4"}}},"commit":{"parents":[{"commit":"50c697fc3cb4307d7f8e278a1ad7366e5f7260a7","subject":"Merge \"Terminate API TLS with nginx sidecars\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/50c697fc3cb4307d7f8e278a1ad7366e5f7260a7"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-30 22:36:51.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-31 00:36:51.000000000","tz":-300},"subject":"[WIP] Declarative MariaDB database management","message":"[WIP] Declarative MariaDB database management\n\nProvision service databases from custom resources reconciled inside the\ncluster, instead of running a per-chart db-init job that mounts the MariaDB\nadministrative connection URI into the OpenStack namespace.\n\nThe mariadb chart gains four namespaced CRDs in the\nmariadb.osh.openstack.org/v1alpha1 group -- Database, User, Grant and\nConnection -- and a single-file Python reconciler, modelled on the Galera\nprimary-election controller the chart already ships. The field names are a\nsubset of, and compatible with, the upstream mariadb-operator group, so the\nsame consumer templates can be retargeted at the full operator by changing one\napiVersion argument. Two deliberate divergences: spec.name carries the MariaDB\nobject name, because a schema called nova_api is not a valid Kubernetes object\nname, and maxUserConnections defaults to 0 rather than upstream\u0027s 10, which\nwould throttle every OpenStack service.\n\nConsumer charts render those resources through a new Helm-toolkit manifest,\nhelm-toolkit.manifests.mariadb_db. Everything is derived from the endpoints\nvalues the chart already declares, so no credential is duplicated: path is the\ndatabase name and auth.\u003cuserClass\u003e are the credentials. Charts owning several\ndatabases pass a databases list the way nova passes dbsToInit, and accounts\nshared between those databases collapse into a single User -- nova gets one\nUser and password secret for its three databases.\n\nA Connection materializes an oslo.config snippet secret which every\ndatabase-reading workload projects into the service config directory, via a new\nhelm-toolkit.snippets.mariadb_db_etc_sources. Wiring it into\nhelm-toolkit.manifests.job_db_sync covers the db-sync job of every chart at\nonce. Because a projected volume source is not optional, kubelet holds the pod\nuntil the reconciler has written the secret, so db-sync waits for the database\nrather than failing.\n\nkeystone, cinder, glance, heat, placement, nova and neutron are converted --\nevery chart owning a database in the compute kit plus cinder job. nova-compute\nand the neutron agents deliberately do not get the connection secret, since\nthey do not use the database.\n\nEverything is off by default, so the rendered output of all seven charts and of\nthe mariadb chart\u0027s existing resources is byte-identical; the only addition at\ndefault values is the four inert CRDs. Enabling the reconciler is gated so the\nmariadb-bin configmap keeps its hash, which would otherwise roll the galera\nstatefulset on upgrade. The new path is exercised by the\nopenstack-helm-mariadb-crd-2026-1-ubuntu_noble job and the per-chart\nvalues_overrides/\u003cchart\u003e/mariadb-crd.yaml overrides.\n\nAlso defines pod.resources.controller in the mariadb chart, which\ndeployment-controller.yaml has always referenced but which was never declared.\n\nDNM: while this is in progress the check pipeline is trimmed to just\nopenstack-helm-linter and the new job, so iterating does not burn a full\nrun of every job. The commented block in zuul.d/project.yaml is delimited\nby DNM(mariadb-crd) markers and must be restored before this merges:\n`grep -rn \u0027DNM(mariadb-crd)\u0027 zuul.d/` must print nothing. The gate\npipeline is deliberately left untouched, so the full cinder and\ncompute-kit jobs still guard the merge.\n\nThe first CI run caught a percent-escaping bug: pymysql applies printf\nformatting to the whole statement whenever parameters are bound, so the\nliteral percent in \u0027user\u0027@\u0027%\u0027 was read as a format specifier and every\nCREATE USER failed with \"unsupported format character\". Accounts are now\nquoted through quote_account(), which doubles the percent when the\nstatement carries bound parameters. Also fold the utf8/utf8mb3 alias when\nchecking a database for character set drift, so a freshly created database\nis not reported as drifted and needlessly altered on every resync.\n\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\nChange-Id: Ic6dfcc4b5efea516ceb729e2bce22f5e1dc1f011\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/f19287e1291e15da7c1c059a5f4c64e110e1fe51"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/f19287e1291e15da7c1c059a5f4c64e110e1fe51"}]},"branch":"refs/heads/master"},"d4c1e9e22c659e34fb255ef3b88314c5f3333291":{"kind":"REWORK","_number":5,"created":"2026-07-31 02:59:45.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/42/999342/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/42/999342/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/5"}}},"commit":{"parents":[{"commit":"ce8c7069bcba495e3df4cc6075dc6870472f6c14","subject":"Merge \"Set Nova terminationGracePeriodSeconds to 180s\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/ce8c7069bcba495e3df4cc6075dc6870472f6c14"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-30 22:36:51.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-31 02:59:39.000000000","tz":-300},"subject":"[WIP] Declarative MariaDB database management","message":"[WIP] Declarative MariaDB database management\n\nProvision service databases from custom resources reconciled inside the\ncluster, instead of running a per-chart db-init job that mounts the MariaDB\nadministrative connection URI into the OpenStack namespace.\n\nThe mariadb chart gains four namespaced CRDs in the\nmariadb.osh.openstack.org/v1alpha1 group -- Database, User, Grant and\nConnection -- and a single-file Python reconciler, modelled on the Galera\nprimary-election controller the chart already ships. The field names are a\nsubset of, and compatible with, the upstream mariadb-operator group. Two\ndeliberate divergences: spec.name carries the MariaDB object name, because a\nschema called nova_api is not a valid Kubernetes object name, and\nmaxUserConnections defaults to 0 rather than upstream\u0027s 10, which would\nthrottle every OpenStack service.\n\nEach consumer chart declares its own resources in templates/mariadb-db.yaml,\ngated by manifests.mariadb_db. There is deliberately no Helm-toolkit manifest\ngenerating them: the databases a chart owns, their config sections and their\naccounts are part of that chart\u0027s contract, and a reader should see what a\nchart declares without following an indirection into shared code. It also lets\neach chart deviate freely -- placement writes a [placement_database] section,\nnova owns three databases behind a single account, so it declares one User and\none password secret alongside three Databases, Grants and Connections.\n\nThe templates hardcode no identity: the database name comes from\nendpoints.\u003ctype\u003e.path and the credentials from endpoints.\u003ctype\u003e.auth.\u003cclass\u003e,\nso nothing is duplicated. Rendering fails if manifests.job_db_init is also\nenabled, since both paths would write the same account\u0027s password.\n\nA Connection materializes an oslo.config snippet secret. Consuming it needs no\nchart template change, because pod.etcSources is already values-driven: the\nper-chart override lists the secret under every workload that reads the\ndatabase, including db-sync. Since a projected volume source is not optional,\nkubelet holds a pod until the secret exists, so db-sync waits for the database\nrather than failing. nova-compute and the neutron agents deliberately do not\nget the secret, as they do not use the database.\n\nkeystone, cinder, glance, heat, placement, nova and neutron are converted --\nevery chart owning a database in the compute kit plus cinder job.\n\nEverything is off by default, so the rendered output of all seven charts and of\nthe mariadb chart\u0027s existing resources is byte-identical; the only addition at\ndefault values is the four inert CRDs. Enabling the reconciler is gated so the\nmariadb-bin configmap keeps its hash, which would otherwise roll the galera\nstatefulset on upgrade.\n\nBecause the connection string leaves the service config,\nverify-mariadb-tls.sh now falls back to the Connection secret, and only\ninsists on finding a connection string once it knows tls.oslo_db is enabled.\n\nAlso defines pod.resources.controller in the mariadb chart, which\ndeployment-controller.yaml has always referenced but never declared.\n\nDNM: while this is in progress the check pipeline is trimmed to just\nopenstack-helm-linter and the new job, so iterating does not burn a full run of\nevery job. The commented block in zuul.d/project.yaml is delimited by\nDNM(mariadb-crd) markers and must be restored before this merges:\n`grep -rn \u0027DNM(mariadb-crd)\u0027 zuul.d/` must print nothing. The gate pipeline is\ndeliberately left untouched, so the full cinder and compute-kit jobs still\nguard the merge.\n\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\nChange-Id: Ic6dfcc4b5efea516ceb729e2bce22f5e1dc1f011\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/d4c1e9e22c659e34fb255ef3b88314c5f3333291"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/d4c1e9e22c659e34fb255ef3b88314c5f3333291"}]},"branch":"refs/heads/master"},"727c7cad707cfe985df09267c65a4b1562272e12":{"kind":"REWORK","_number":6,"created":"2026-08-03 15:41:21.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/42/999342/6","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/42/999342/6","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/6"}}},"commit":{"parents":[{"commit":"91697aa73e86bab174f7c1b5629f1642314ea5d1","subject":"Fix the mariadb-operator values overrides","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/91697aa73e86bab174f7c1b5629f1642314ea5d1"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-30 22:36:51.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-08-03 15:11:39.000000000","tz":-300},"subject":"[WIP] Declarative MariaDB database management","message":"[WIP] Declarative MariaDB database management\n\nProvision service databases from custom resources reconciled inside the\ncluster, instead of running a per-chart db-init job that mounts the MariaDB\nadministrative connection URI into the OpenStack namespace.\n\nThe mariadb chart gains four namespaced CRDs in the\nmariadb.osh.openstack.org/v1alpha1 group -- Database, User, Grant and\nConnection -- and a single-file Python reconciler, modelled on the Galera\nprimary-election controller the chart already ships. The field names are a\nsubset of, and compatible with, the upstream mariadb-operator group. Two\ndeliberate divergences: spec.name carries the MariaDB object name, because a\nschema called nova_cell0 is not a valid Kubernetes object name, and\nmaxUserConnections defaults to 0 rather than upstream\u0027s 10, which would\nthrottle every OpenStack service.\n\nEach consumer chart declares its own resources in templates/mariadb-db.yaml,\ngated by manifests.mariadb_db. There is deliberately no Helm-toolkit manifest\ngenerating them: the databases a chart owns, their config sections and their\naccounts are part of that chart\u0027s contract, and a reader should see what a\nchart declares without following an indirection into shared code. It also lets\neach chart deviate freely -- placement writes a [placement_database] section,\nand nova owns three databases behind a single account, so it declares one\nUser and one password secret alongside three Databases and Grants.\n\nnova is worth reading carefully, because which endpoint feeds which config\nsection is not obvious: oslo_db is the api database and supplies\n[api_database], while the plain [database] section addresses cell1 through\noslo_db_cell1. cell0 has no config section at all -- job-db-sync takes its URI\nfrom the chart\u0027s own secret_db_cell0 as DB_CONNECTION_CELL0 -- so it gets a\nDatabase and a Grant but no Connection, and nothing projects a cell0\nconnection secret. Projecting one would hold every nova pod in\nContainerCreating for ever, since a projected volume source is not optional.\n\nThe templates hardcode no identity: the database name comes from\nendpoints.\u003ctype\u003e.path and the credentials from endpoints.\u003ctype\u003e.auth.\u003cclass\u003e,\nso nothing is duplicated. Rendering fails if manifests.job_db_init is also\nenabled, since both paths would write the same account\u0027s password.\n\nA Connection materializes an oslo.config snippet secret. Consuming it needs no\nchart template change, because pod.etcSources is already values-driven: the\nper-chart override lists the secret under every workload that reads the\ndatabase, including db-sync. Since a projected volume source is not optional,\nkubelet holds a pod until the secret exists, so db-sync waits for the database\nrather than failing. nova-compute and the neutron agents deliberately do not\nget the secret, as they do not use the database.\n\nkeystone, cinder, glance, heat, placement, nova and neutron are converted --\nevery chart owning a database in the compute kit plus cinder job.\n\nEverything is off by default, so the rendered output of all seven charts and of\nthe mariadb chart\u0027s existing resources is byte-identical; the only addition at\ndefault values is the four inert CRDs. Enabling the reconciler is gated so the\nmariadb-bin configmap keeps its hash, which would otherwise roll the galera\nstatefulset on upgrade.\n\nBecause the connection string leaves the service config,\nverify-mariadb-tls.sh now falls back to the Connection secret, and only\ninsists on finding a connection string once it knows tls.oslo_db is enabled.\n\nAlso defines pod.resources.controller in the mariadb chart, which\ndeployment-controller.yaml has always referenced but never declared.\n\nDNM: while this is in progress the check pipeline is trimmed to just\nopenstack-helm-linter and the new job, so iterating does not burn a full run of\nevery job. The commented block in zuul.d/project.yaml is delimited by\nDNM(mariadb-crd) markers and must be restored before this merges:\n`grep -rn \u0027DNM(mariadb-crd)\u0027 zuul.d/` must print nothing. The gate pipeline is\ndeliberately left untouched, so the full cinder and compute-kit jobs still\nguard the merge.\n\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\nChange-Id: Ic6dfcc4b5efea516ceb729e2bce22f5e1dc1f011\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/727c7cad707cfe985df09267c65a4b1562272e12"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/727c7cad707cfe985df09267c65a4b1562272e12"}]},"branch":"refs/heads/master"},"4d1a207640e36476e60a0760bef1027d23d2a9e2":{"kind":"REWORK","_number":7,"created":"2026-08-03 17:11:39.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/42/999342/7","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/42/999342/7","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/7"}}},"commit":{"parents":[{"commit":"91697aa73e86bab174f7c1b5629f1642314ea5d1","subject":"Fix the mariadb-operator values overrides","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/91697aa73e86bab174f7c1b5629f1642314ea5d1"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-30 22:36:51.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-08-03 17:11:23.000000000","tz":-300},"subject":"[WIP] Declarative MariaDB database management","message":"[WIP] Declarative MariaDB database management\n\nProvision service databases from custom resources reconciled inside\nthe cluster, instead of running a per-chart db-init job that mounts\nthe MariaDB administrative connection URI into the OpenStack\nnamespace.\n\nThe mariadb chart gains four namespaced CRDs in the\nmariadb.osh.openstack.org/v1alpha1 group -- Database, User, Grant and\nConnection -- and a single-file Python reconciler, modelled on the\nGalera primary-election controller the chart already ships. The field\nnames are a subset of, and compatible with, the upstream\nmariadb-operator group. Two deliberate divergences: spec.name carries\nthe MariaDB object name, because a schema called nova_cell0 is not a\nvalid Kubernetes object name, and maxUserConnections defaults to 0\nrather than upstream\u0027s 10, which would throttle every OpenStack\nservice.\n\nEach consumer chart declares its own resources in\ntemplates/mariadb-db.yaml, gated by manifests.mariadb_db. There is\ndeliberately no Helm-toolkit manifest generating them: the databases a\nchart owns, their config sections and their accounts are part of that\nchart\u0027s contract, and a reader should see what a chart declares\nwithout following an indirection into shared code. It also lets each\nchart deviate freely -- placement writes a [placement_database]\nsection, and nova owns three databases behind a single account, so it\ndeclares one User and one password secret alongside three Databases\nand Grants.\n\nnova is worth reading carefully, because which endpoint feeds which\nconfig section is not obvious: oslo_db is the api database and\nsupplies [api_database], while the plain [database] section addresses\ncell1 through oslo_db_cell1. cell0 has no config section at all,\nbecause nova reads that connection from the cell mapping in the api\ndatabase rather than from nova.conf. Its Connection therefore writes a\nbare URI instead of a snippet, under the key job-db-sync already reads\nas DB_CONNECTION_CELL0, and the override points\nsecrets.oslo_db_cell0.nova at it and turns secret_db_cell0 off -- so\nthe chart stops generating a cell0 connection URI of its own. Nothing\nprojects that secret as a file: no oslo.config section would read it.\n\nThe templates hardcode no identity: the database name comes from\nendpoints.\u003ctype\u003e.path and the credentials from\nendpoints.\u003ctype\u003e.auth.\u003cclass\u003e, so nothing is duplicated. Rendering\nfails if manifests.job_db_init is also enabled, since both paths would\nwrite the same account\u0027s password.\n\nA Connection materializes a secret whose key and content\nsecretTemplate names, so the same kind serves an oslo.config snippet\nand a bare URI. Consuming it needs no chart template change either\nway, because the names come from values that are already indirections:\nthe per-chart override lists the snippet secret in pod.etcSources\nunder every workload that reads the database, including db-sync, and\nrepoints secrets.oslo_db_cell0.nova at the bare-URI one. Since a\nprojected volume source is not optional, kubelet holds a pod until the\nsecret exists, so db-sync waits for the database rather than failing.\nnova-compute and the neutron agents deliberately do not get the\nsecret, as they do not use the database.\n\nkeystone, cinder, glance, heat, placement, nova and neutron are\nconverted -- every chart owning a database in the compute kit plus\ncinder job.\n\nEverything is off by default, so the rendered output of all seven\ncharts and of the mariadb chart\u0027s existing resources is\nbyte-identical; the only addition at default values is the four inert\nCRDs. Enabling the reconciler is gated so the mariadb-bin configmap\nkeeps its hash, which would otherwise roll the galera statefulset on\nupgrade.\n\nBecause the connection string leaves the service config,\nverify-mariadb-tls.sh now falls back to the Connection secret, and\nonly insists on finding a connection string once it knows tls.oslo_db\nis enabled.\n\nAlso defines pod.resources.controller in the mariadb chart, which\ndeployment-controller.yaml has always referenced but never declared.\n\nDNM: while this is in progress the check pipeline is trimmed to just\nopenstack-helm-linter and the new job, so iterating does not burn a\nfull run of every job. The commented block in zuul.d/project.yaml is\ndelimited by DNM(mariadb-crd) markers and must be restored before this\nmerges: `grep -rn \u0027DNM(mariadb-crd)\u0027 zuul.d/` must print nothing. The\ngate pipeline is deliberately left untouched, so the full cinder and\ncompute-kit jobs still guard the merge.\n\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\nChange-Id: Ic6dfcc4b5efea516ceb729e2bce22f5e1dc1f011\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/4d1a207640e36476e60a0760bef1027d23d2a9e2"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/4d1a207640e36476e60a0760bef1027d23d2a9e2"}]},"branch":"refs/heads/master"},"010c55eabaf9cd5f29dbed7c10c4b34f2c2f54bf":{"kind":"REWORK","_number":8,"created":"2026-08-03 19:56:28.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/42/999342/8","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/42/999342/8","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/8 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/8 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/8 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/8"}}},"commit":{"parents":[{"commit":"91697aa73e86bab174f7c1b5629f1642314ea5d1","subject":"Fix the mariadb-operator values overrides","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/91697aa73e86bab174f7c1b5629f1642314ea5d1"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-30 22:36:51.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-08-03 19:56:19.000000000","tz":-300},"subject":"[WIP] Declarative MariaDB database management","message":"[WIP] Declarative MariaDB database management\n\nProvision service databases from custom resources reconciled inside\nthe cluster, instead of running a per-chart db-init job that mounts\nthe MariaDB administrative connection URI into the OpenStack\nnamespace.\n\nThe mariadb chart gains four namespaced CRDs in the\nmariadb.osh.openstack.org/v1alpha1 group -- Database, User, Grant and\nConnection -- and a single-file Python reconciler, modelled on the\nGalera primary-election controller the chart already ships.\n\nThe resources stay as close to their upstream mariadb-operator\ncounterparts as a partial implementation can. Every field the upstream\nk8s.mariadb.com/v1alpha1 resources accept is declared, so the API\nserver does not silently strip a resource written against upstream\ndocumentation, and the status subresource is structurally identical to\nupstream\u0027s: one conditions list of metav1.Condition, which is what\nmakes kubectl wait --for\u003dcondition\u003dReady work. A single string field\nwould have been easier for kubernetes-entrypoint to wait on, since it\ncompares one nested field against a string and cannot index a list,\nbut diverging here would make every resource in the group subtly\nincompatible with tooling written for the real operator. Teaching\nkubernetes-entrypoint to match a condition by type is the better fix,\nand is a prerequisite for declaring a custom_resources dependency on\nreadiness.\n\nWhat this reconciler does not implement it refuses rather than\nignores: passwordPlugin, require.ssl, require.issuer, require.subject,\nmaxScaleRef, tlsClientCertSecretRef, the object reference fields that\npin a referent\u0027s identity, and optional on a secret key reference all\nproduce a Ready condition of False naming the field. Quietly dropping\nan authentication plugin or a TLS requirement would leave the\ndeployment weaker than the resource asked for while reporting success.\nValues that agree with what the reconciler already does, such as\noptional: false, are accepted. Ownership is settled first, so a\nresource belonging to the upstream operator -- which legitimately uses\nthose fields -- is left alone, with reason NotOwned.\n\nTwo deliberate divergences remain: spec.name carries the MariaDB\nobject name, because a schema called nova_cell0 is not a valid\nKubernetes object name, and maxUserConnections defaults to 0 rather\nthan upstream\u0027s 10, which would throttle every OpenStack service.\n\nEach consumer chart declares its own resources in\ntemplates/mariadb-db.yaml, gated by manifests.mariadb_db. There is\ndeliberately no Helm-toolkit manifest generating them: the databases a\nchart owns, their config sections and their accounts are part of that\nchart\u0027s contract, and a reader should see what a chart declares\nwithout following an indirection into shared code. It also lets each\nchart deviate freely -- placement writes a [placement_database]\nsection, and nova owns three databases behind a single account, so it\ndeclares one User and one password secret alongside three Databases\nand Grants.\n\nnova is worth reading carefully, because which endpoint feeds which\nconfig section is not obvious: oslo_db is the api database and\nsupplies [api_database], while the plain [database] section addresses\ncell1 through oslo_db_cell1. cell0 has no config section at all,\nbecause nova reads that connection from the cell mapping in the api\ndatabase rather than from nova.conf. Its Connection therefore writes a\nbare URI instead of a snippet, under the key job-db-sync already reads\nas DB_CONNECTION_CELL0, and the override points\nsecrets.oslo_db_cell0.nova at it and turns secret_db_cell0 off -- so\nthe chart stops generating a cell0 connection URI of its own. Nothing\nprojects that secret as a file: no oslo.config section would read it.\n\nThe templates hardcode no identity: the database name comes from\nendpoints.\u003ctype\u003e.path and the credentials from\nendpoints.\u003ctype\u003e.auth.\u003cclass\u003e, so nothing is duplicated. Rendering\nfails if manifests.job_db_init is also enabled, since both paths would\nwrite the same account\u0027s password.\n\nA Connection materializes a secret whose key and content\nsecretTemplate names, so the same kind serves an oslo.config snippet\nand a bare URI. Consuming it needs no chart template change either\nway, because the names come from values that are already indirections:\nthe per-chart override lists the snippet secret in pod.etcSources\nunder every workload that reads the database, including db-sync, and\nrepoints secrets.oslo_db_cell0.nova at the bare-URI one. Since a\nprojected volume source is not optional, kubelet holds a pod until the\nsecret exists, so db-sync waits for the database rather than failing.\nnova-compute and the neutron agents deliberately do not get the\nsecret, as they do not use the database.\n\nkeystone, cinder, glance, heat, placement, nova and neutron are\nconverted -- every chart owning a database in the compute kit plus\ncinder job.\n\nEverything is off by default, so the rendered output of all seven\ncharts and of the mariadb chart\u0027s existing resources is\nbyte-identical; the only addition at default values is the four inert\nCRDs. Enabling the reconciler is gated so the mariadb-bin configmap\nkeeps its hash, which would otherwise roll the galera statefulset on\nupgrade.\n\nBecause the connection string leaves the service config,\nverify-mariadb-tls.sh now falls back to the Connection secret, and\nonly insists on finding a connection string once it knows tls.oslo_db\nis enabled.\n\nAlso defines pod.resources.controller in the mariadb chart, which\ndeployment-controller.yaml has always referenced but never declared.\n\nDNM: while this is in progress the check pipeline is trimmed to just\nopenstack-helm-linter and the new job, so iterating does not burn a\nfull run of every job. The commented block in zuul.d/project.yaml is\ndelimited by DNM(mariadb-crd) markers and must be restored before this\nmerges: `grep -rn \u0027DNM(mariadb-crd)\u0027 zuul.d/` must print nothing. The\ngate pipeline is deliberately left untouched, so the full cinder and\ncompute-kit jobs still guard the merge.\n\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\nChange-Id: Ic6dfcc4b5efea516ceb729e2bce22f5e1dc1f011\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/010c55eabaf9cd5f29dbed7c10c4b34f2c2f54bf"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/010c55eabaf9cd5f29dbed7c10c4b34f2c2f54bf"}]},"branch":"refs/heads/master"},"5b10af1db77f15cee760ec238daf9c1fb58740ea":{"kind":"REWORK","_number":9,"created":"2026-08-07 19:34:41.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/42/999342/9","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/42/999342/9","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/9 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/9 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/9 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/9"}}},"commit":{"parents":[{"commit":"7fd58999542d370d9d576cd548fdd325cb4ae945","subject":"Merge \"Spec: declarative MariaDB database management\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/7fd58999542d370d9d576cd548fdd325cb4ae945"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-30 22:36:51.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-08-07 19:34:03.000000000","tz":-300},"subject":"[WIP] Declarative MariaDB database management","message":"[WIP] Declarative MariaDB database management\n\nProvision service databases from custom resources reconciled inside\nthe cluster, instead of a per-chart db-init job that mounts the\nMariaDB administrative connection URI into the OpenStack namespace.\n\nThe mariadb chart gains four namespaced CRDs -- Database, User, Grant\nand Connection -- and a single-file Python reconciler modelled on the\nGalera primary-election controller the chart already ships.\n\nThe resources mirror their upstream mariadb-operator counterparts.\nEvery field upstream accepts is declared, because a definition that\nomits a field does not reject it -- the API server strips it silently\n-- and status is upstream\u0027s conditions list, so kubectl wait\n--for\u003dcondition\u003dReady works. What this reconciler does not implement\nit refuses rather than ignores: passwordPlugin, require.ssl,\nrequire.issuer, require.subject, maxScaleRef, tlsClientCertSecretRef,\nthe object reference fields that pin a referent\u0027s identity, and\noptional on a secret key reference. Quietly dropping an authentication\nplugin or a TLS requirement would leave a deployment weaker than it\nasked for while reporting success.\n\nmariadb_db.api_group chooses who reconciles them: the group this chart\nserves, or k8s.mariadb.com for the upstream operator, which is then\ndeployed separately. Rendering fails on any other value rather than\nproducing resources nothing reconciles. Connection.retryInterval is\nomitted for upstream, which has no such field, and User.spec.require\nonly exists from 0.37.0, so an older operator with tls.oslo_db would\ncreate accounts without REQUIRE X509.\n\nThe single intentional difference from upstream is maxUserConnections,\nwhich defaults to 0 rather than upstream\u0027s 10. A limit of ten would\nthrottle every OpenStack service.\n\nEach consumer chart declares its own resources in\ntemplates/mariadb-db.yaml, gated by manifests.mariadb_db. There is\ndeliberately no shared Helm-toolkit manifest: the databases a chart\nowns, their config sections and their accounts are part of that\nchart\u0027s contract, and keeping them local lets each chart deviate --\nplacement writes [placement_database], and nova owns three databases\nbehind one account. Identity is read from values the chart already\ndeclares, endpoints.\u003ctype\u003e.path and endpoints.\u003ctype\u003e.auth.\u003cclass\u003e, so\nnothing is duplicated. The schema name lives in spec.name because an\nunderscore is not valid in an object name: the resource for nova_cell0\nis named nova-cell0.\n\nA Connection materializes a secret whose key and content\nsecretTemplate names, so one kind serves both an oslo.config snippet\nand a bare URI. Consuming it needs no chart template change either\nway, because both names come from values that are already\nindirections: the override lists the snippet secret in pod.etcSources\nunder every workload that reads the database, and repoints\nsecrets.oslo_db_cell0.nova at the bare-URI one, which db-sync reads as\nDB_CONNECTION_CELL0 to write nova\u0027s cell0 mapping. Since a projected\nvolume source is not optional, kubelet holds a pod until the secret\nexists, so db-sync waits for the database rather than failing.\nnova-compute and the neutron agents do not use the database and are\nnot handed its credentials.\n\nkeystone, cinder, glance, heat, placement, nova and neutron are\nconverted. Everything is off by default, so all eight charts render\nbyte-identically; the only addition at default values is the four\ninert CRDs. Enabling the reconciler is gated so the mariadb-bin\nconfigmap keeps its hash, which would otherwise roll the galera\nstatefulset on upgrade.\n\nDNM: the check pipeline is trimmed to openstack-helm-linter and the\nnew job while this is in progress. The commented block in\nzuul.d/project.yaml is delimited by DNM(mariadb-crd) markers and must\nbe restored before this merges: `grep -rn \u0027DNM(mariadb-crd)\u0027 zuul.d/`\nmust print nothing. The gate pipeline is deliberately left untouched.\n\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\nChange-Id: Ic6dfcc4b5efea516ceb729e2bce22f5e1dc1f011\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/5b10af1db77f15cee760ec238daf9c1fb58740ea"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/5b10af1db77f15cee760ec238daf9c1fb58740ea"}]},"branch":"refs/heads/master"},"1f1fb0b2823665846549d68942fb673acd8b0c86":{"kind":"REWORK","_number":10,"created":"2026-08-07 21:49:11.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/42/999342/10","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/42/999342/10","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/10 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/10 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/10 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/10"}}},"commit":{"parents":[{"commit":"7fd58999542d370d9d576cd548fdd325cb4ae945","subject":"Merge \"Spec: declarative MariaDB database management\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/7fd58999542d370d9d576cd548fdd325cb4ae945"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-30 22:36:51.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-08-07 21:49:02.000000000","tz":-300},"subject":"[WIP] Declarative MariaDB database management","message":"[WIP] Declarative MariaDB database management\n\nProvision service databases from custom resources instead of a\nper-chart db-init job that mounts the MariaDB administrative URI into\nthe OpenStack namespace.\n\nThe mariadb chart gains four namespaced CRDs -- Database, User, Grant\nand Connection -- and a single-file Python reconciler modelled on the\nGalera controller it already ships. The resources mirror the upstream\nmariadb-operator ones: every field upstream accepts is declared, since\nthe API server silently strips what a definition omits, and status is\nupstream\u0027s conditions list, so kubectl wait --for\u003dcondition\u003dReady\nworks. Fields this reconciler does not implement are refused, not\nignored, because dropping an authentication plugin or a TLS\nrequirement would leave a deployment weaker than it asked for while\nreporting success. maxUserConnections defaults to 0 rather than\nupstream\u0027s 10, which would throttle every service.\n\nmariadb_db.api_group picks who reconciles them, this chart\u0027s\ncontroller or k8s.mariadb.com for the upstream operator, and rendering\nfails on anything else. The two differ only in\nConnection.retryInterval, absent upstream, and the password\nplaceholder, since upstream has no percent-encoded variant.\n\nEach consumer chart declares its own resources in\ntemplates/mariadb-db.yaml, gated by manifests.mariadb_db, with no\nshared Helm-toolkit manifest: the databases a chart owns and their\nconfig sections are part of that chart\u0027s contract, and keeping them\nlocal lets placement write [placement_database] and nova own three\ndatabases behind one account. Identity comes from\nendpoints.\u003ctype\u003e.path and endpoints.\u003ctype\u003e.auth.\u003cclass\u003e, so nothing is\nduplicated. An underscore is not valid in an object name, so the\nschema name lives in spec.name: the resource for nova_cell0 is named\nnova-cell0.\n\nA Connection materializes a secret whose key and content\nsecretTemplate names, so one kind serves both an oslo.config snippet\nand a bare URI, and consuming either needs no template change: the\noverride lists the snippet secret in pod.etcSources and repoints\nsecrets.oslo_db_cell0.nova at the bare-URI one, which db-sync reads as\nDB_CONNECTION_CELL0 for nova\u0027s cell0 mapping. A projected volume\nsource is not optional, so kubelet holds a pod until its secret exists\nand db-sync waits for the database rather than failing.\n\nkeystone, cinder, glance, heat, placement, nova and neutron are\nconverted, and two jobs deploy them from the same overrides, one per\noperator. Everything is off by default, so all eight charts render\nbyte-identically; the only addition at default values is the four\ninert CRDs.\n\nDNM: the check pipeline is trimmed to the linter and the two new jobs\nwhile this is in progress. Restore the block delimited by\nDNM(mariadb-crd) markers in zuul.d/project.yaml before this merges:\n`grep -rn \u0027DNM(mariadb-crd)\u0027 zuul.d/` must print nothing.\n\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\nChange-Id: Ic6dfcc4b5efea516ceb729e2bce22f5e1dc1f011\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/1f1fb0b2823665846549d68942fb673acd8b0c86"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/1f1fb0b2823665846549d68942fb673acd8b0c86"}]},"branch":"refs/heads/master"},"c943c71eb62bba995aefad3cf67977314c6d3042":{"kind":"REWORK","_number":11,"created":"2026-08-07 23:58:02.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/42/999342/11","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/42/999342/11","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/11 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/11 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/11 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/42/999342/11"}}},"commit":{"parents":[{"commit":"7fd58999542d370d9d576cd548fdd325cb4ae945","subject":"Merge \"Spec: declarative MariaDB database management\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/7fd58999542d370d9d576cd548fdd325cb4ae945"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-30 22:36:51.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-08-07 23:57:54.000000000","tz":-300},"subject":"[WIP] Declarative MariaDB database management","message":"[WIP] Declarative MariaDB database management\n\nProvision service databases from custom resources instead of a\nper-chart db-init job that mounts the MariaDB administrative URI into\nthe OpenStack namespace.\n\nThe mariadb chart gains four namespaced CRDs -- Database, User, Grant\nand Connection -- and a single-file Python reconciler modelled on the\nGalera controller it already ships. The resources mirror the upstream\nmariadb-operator ones: every field upstream accepts is declared, since\nthe API server silently strips what a definition omits, and status is\nupstream\u0027s conditions list, so kubectl wait --for\u003dcondition\u003dReady\nworks. Fields this reconciler does not implement are refused, not\nignored, because dropping an authentication plugin or a TLS\nrequirement would leave a deployment weaker than it asked for while\nreporting success. maxUserConnections defaults to 0 rather than\nupstream\u0027s 10, which would throttle every service.\n\nmariadb_db.api_group picks who reconciles them, this chart\u0027s\ncontroller or k8s.mariadb.com for the upstream operator, and rendering\nfails on anything else. The two differ only in\nConnection.retryInterval, absent upstream, and the password\nplaceholder, since upstream has no percent-encoded variant.\n\nEach consumer chart declares its own resources in\ntemplates/mariadb-db.yaml, gated by manifests.mariadb_db, with no\nshared Helm-toolkit manifest: the databases a chart owns and their\nconfig sections are part of that chart\u0027s contract, and keeping them\nlocal lets placement write [placement_database] and nova own three\ndatabases behind one account. Identity comes from\nendpoints.\u003ctype\u003e.path and endpoints.\u003ctype\u003e.auth.\u003cclass\u003e, so nothing is\nduplicated. An underscore is not valid in an object name, so the\nschema name lives in spec.name: the resource for nova_cell0 is named\nnova-cell0.\n\nA Connection materializes a secret whose key and content\nsecretTemplate names, so one kind serves both an oslo.config snippet\nand a bare URI, and consuming either needs no template change: the\noverride lists the snippet secret in pod.etcSources and repoints\nsecrets.oslo_db_cell0.nova at the bare-URI one, which db-sync reads as\nDB_CONNECTION_CELL0 for nova\u0027s cell0 mapping. A projected volume\nsource is not optional, so kubelet holds a pod until its secret exists\nand db-sync waits for the database rather than failing.\n\nkeystone, cinder, glance, heat, placement, nova and neutron are\nconverted, and two jobs deploy them from the same overrides, one per\noperator. Everything is off by default, so all eight charts render\nbyte-identically; the only addition at default values is the four\ninert CRDs.\n\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\nChange-Id: Ic6dfcc4b5efea516ceb729e2bce22f5e1dc1f011\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/c943c71eb62bba995aefad3cf67977314c6d3042"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/c943c71eb62bba995aefad3cf67977314c6d3042"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY"},{"label":"Workflow","status":"MAY"}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
