)]}'
{"id":"openstack%2Fopenstack-helm~999899","triplet_id":"openstack%2Fopenstack-helm~master~I859c3a4d5e6c670e99b6b1cb138ec48f5a57456e","project":"openstack/openstack-helm","branch":"master","hashtags":[],"change_id":"I859c3a4d5e6c670e99b6b1cb138ec48f5a57456e","subject":"[WIP] Declarative RabbitMQ topology management","status":"NEW","created":"2026-08-05 19:45:37.000000000","updated":"2026-08-18 21:43:50.000000000","submit_type":"MERGE_IF_NECESSARY","mergeable":false,"submittable":false,"total_comment_count":0,"unresolved_comment_count":0,"work_in_progress":true,"has_review_started":false,"meta_rev_id":"e8b7a94cd643f29af6748f612464304c967f0c48","_number":999899,"virtual_id_number":999899,"owner":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"tag":"autogenerated:zuul:check","value":1,"date":"2026-08-18 21:43:50.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{"REVIEWER":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"reviewer_updates":[{"updated":"2026-08-05 20:33:13.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"4192284c1b6144f7762029e8456bb1a14393fb5b","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-08-05 19:45:37.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"2fffd84ca372c1e395bb961faae238e4b82fe9b9","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-08-05 19:46:00.000000000","message":"Uploaded patch set 2: Commit message was updated.","accounts_in_message":[],"_revision_number":2},{"id":"15a07827fc1dfa613c607d876ab5caeebe90a236","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-05 20:33:13.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/ef1f5c704dd948239d74616fc2a22f25\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/cc1f63491ffa425fae8bf487b92c0698 : SUCCESS in 3m 05s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/62ae3b481bae41c2b0d0b8f48433848c : SUCCESS in 3m 14s\n- openstack-helm-rabbitmq-crd-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/8d5504b798b241e6870f448fe887014d : SUCCESS in 45m 28s","accounts_in_message":[],"_revision_number":2},{"id":"ab36e526ae1687a9c4c411b0caf81075e86264f5","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-08-18 20:14:42.000000000","message":"Uploaded patch set 3.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":3},{"id":"e8b7a94cd643f29af6748f612464304c967f0c48","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-18 21:43:50.000000000","message":"Patch Set 3: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/1f882dd305a945a780b85118506b9470\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/c68649e1f3864f0e9540828407804cd8 : SUCCESS in 2m 58s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/72256eef55534c288bf58d6c96965f6b : SUCCESS in 4m 22s\n- openstack-helm-rabbitmq-crd-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/2aa84839bda746439c4bd76c14e9cc9d : SUCCESS in 1h 21m 57s","accounts_in_message":[],"_revision_number":3}],"current_revision_number":3,"current_revision":"349780e10b5d194a18c5204acb432c821fd0db18","revisions":{"54bc94e9972ba8a483873fc3484c601847c124a9":{"kind":"REWORK","_number":1,"created":"2026-08-05 19:45:37.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/99/999899/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/99/999899/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/99/999899/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/99/999899/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/99/999899/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/99/999899/1"}}},"commit":{"parents":[{"commit":"bffdae0e8aa6d1c6c85cd64cee540e1a51fa73d3","subject":"Merge \"Fix the mariadb-operator values overrides\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/bffdae0e8aa6d1c6c85cd64cee540e1a51fa73d3"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-08-05 19:44:24.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-08-05 19:45:35.000000000","tz":-300},"subject":"[WIP] Declarative RabbitMQ topology management","message":"[WIP] Declarative RabbitMQ topology management\n\nAdd seven custom resource definitions and a minimal reconciler to the\nrabbitmq chart, and let consumer charts declare their messaging vhost,\naccount, permissions and policies as custom resources instead of running a\nrabbit-init job with the RabbitMQ administrative connection URI mounted into\ntheir namespace.\n\nThe resources are the upstream messaging-topology-operator\u0027s, apart from the\nAPI group, so the same consumer chart templates work against either\nimplementation. Retargeting them at that operator means changing the\napiVersion and replacing rabbitmqClusterReference.name with a\nconnectionSecret, because upstream resolves the name to a RabbitmqCluster\nresource this chart does not create. Only connectionSecret and a foreign\nrabbitmqClusterReference.namespace are unimplemented, and both are rejected\nrather than ignored; a name pointing at another cluster is left untouched,\nso the two reconcilers can coexist in one namespace. The definitions carry\nupstream\u0027s exactly-one-of rule as a CEL validation rule, so it is enforced\nwithout a webhook.\n\nThere is deliberately no Connection kind. Upstream has none, nothing in\nrabbitmq.com/v1beta1 carries a broker address, and a chart already knows the\naddress from endpoints.oslo_messaging, which it renders into transport_url\ntoday. That is also why the User resources import their credentials instead\nof letting the reconciler generate a password: the two have to agree.\n\nconf.rabbitmq.policies is translated into one Policy resource per entry,\nreplacing the rabbitmqadmin import the job performed. Every converted chart\nships an ha_ttl_\u003cservice\u003e policy there, so skipping this would silently drop\nqueue mirroring and message expiry. Rendering fails on any other\nconf.rabbitmq key rather than discarding it.\n\nThe reconciler talks to the HTTP management API and uses nothing outside the\nPython standard library, so it runs on the openstack-client image the chart\nalready pulls. Its periodic resync also removes the guest account that\ndefinitions.json recreates on every node boot, which the one-shot\nrabbit-init job could not.\n\nAdd a check job deploying the compute kit over this path, and a\nverify-rabbitmq-topology.sh step that waits for every resource to report\nReady, reads the vhosts and accounts back out of the broker, and asserts the\nguest account is gone and no rabbit-init job remains. Without it the job\nwould pass whether or not any of this worked, because oslo.messaging retries\nits connection forever.\n\nBoth provisioning paths stay mutually exclusive and both new manifest\nswitches default to off, so existing deployments render unchanged apart from\nthe inert custom resource definitions.\n\nChange-Id: I859c3a4d5e6c670e99b6b1cb138ec48f5a57456e\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/54bc94e9972ba8a483873fc3484c601847c124a9"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/54bc94e9972ba8a483873fc3484c601847c124a9"}]},"branch":"refs/heads/master"},"2bb4b655919d8068abae9cdf0ae1b9731b25622a":{"kind":"NO_CODE_CHANGE","_number":2,"created":"2026-08-05 19:46:00.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/99/999899/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/99/999899/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/99/999899/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/99/999899/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/99/999899/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/99/999899/2"}}},"commit":{"parents":[{"commit":"bffdae0e8aa6d1c6c85cd64cee540e1a51fa73d3","subject":"Merge \"Fix the mariadb-operator values overrides\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/bffdae0e8aa6d1c6c85cd64cee540e1a51fa73d3"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-08-05 19:44:24.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-08-05 19:45:58.000000000","tz":-300},"subject":"[WIP] Declarative RabbitMQ topology management","message":"[WIP] Declarative RabbitMQ topology management\n\nAdd seven custom resource definitions and a minimal reconciler to the\nrabbitmq chart, and let consumer charts declare their messaging vhost,\naccount, permissions and policies as custom resources instead of running\na rabbit-init job with the RabbitMQ administrative connection URI\nmounted into their namespace.\n\nThe resources are the upstream messaging-topology-operator\u0027s, apart from\nthe API group, so the same consumer chart templates work against either\nimplementation. Retargeting them at that operator means changing the\napiVersion and replacing rabbitmqClusterReference.name with a\nconnectionSecret, because upstream resolves the name to a\nRabbitmqCluster resource this chart does not create. Only\nconnectionSecret and a foreign rabbitmqClusterReference.namespace are\nunimplemented, and both are rejected rather than ignored; a name\npointing at another cluster is left untouched, so the two reconcilers\ncan coexist in one namespace. The definitions carry upstream\u0027s\nexactly-one-of rule as a CEL validation rule, so it is enforced without\na webhook.\n\nThere is deliberately no Connection kind. Upstream has none, nothing in\nrabbitmq.com/v1beta1 carries a broker address, and a chart already knows\nthe address from endpoints.oslo_messaging, which it renders into\ntransport_url today. That is also why the User resources import their\ncredentials instead of letting the reconciler generate a password: the\ntwo have to agree.\n\nconf.rabbitmq.policies is translated into one Policy resource per entry,\nreplacing the rabbitmqadmin import the job performed. Every converted\nchart ships an ha_ttl_\u003cservice\u003e policy there, so skipping this would\nsilently drop queue mirroring and message expiry. Rendering fails on any\nother conf.rabbitmq key rather than discarding it.\n\nThe reconciler talks to the HTTP management API and uses nothing outside\nthe Python standard library, so it runs on the openstack-client image\nthe chart already pulls. Its periodic resync also removes the guest\naccount that definitions.json recreates on every node boot, which the\none-shot rabbit-init job could not.\n\nAdd a check job deploying the compute kit over this path, and a\nverify-rabbitmq-topology.sh step that waits for every resource to report\nReady, reads the vhosts and accounts back out of the broker, and asserts\nthe guest account is gone and no rabbit-init job remains. Without it the\njob would pass whether or not any of this worked, because oslo.messaging\nretries its connection forever.\n\nBoth provisioning paths stay mutually exclusive and both new manifest\nswitches default to off, so existing deployments render unchanged apart\nfrom the inert custom resource definitions.\n\nChange-Id: I859c3a4d5e6c670e99b6b1cb138ec48f5a57456e\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/2bb4b655919d8068abae9cdf0ae1b9731b25622a"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/2bb4b655919d8068abae9cdf0ae1b9731b25622a"}]},"branch":"refs/heads/master"},"349780e10b5d194a18c5204acb432c821fd0db18":{"kind":"REWORK","_number":3,"created":"2026-08-18 20:14:42.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/99/999899/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/99/999899/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/99/999899/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/99/999899/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/99/999899/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/99/999899/3"}}},"commit":{"parents":[{"commit":"bffdae0e8aa6d1c6c85cd64cee540e1a51fa73d3","subject":"Merge \"Fix the mariadb-operator values overrides\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/bffdae0e8aa6d1c6c85cd64cee540e1a51fa73d3"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-08-05 19:44:24.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-08-18 19:36:51.000000000","tz":-300},"subject":"[WIP] Declarative RabbitMQ topology management","message":"[WIP] Declarative RabbitMQ topology management\n\nAdd seven custom resource definitions and a minimal reconciler to the\nrabbitmq chart, and let consumer charts declare their messaging vhost,\naccount, permissions and policies as custom resources instead of running\na rabbit-init job with the RabbitMQ administrative connection URI\nmounted into their namespace.\n\nThe resources are the upstream messaging-topology-operator\u0027s, apart from\nthe API group, so the same consumer chart templates work against either\nimplementation. Retargeting them at that operator means changing the\napiVersion and replacing rabbitmqClusterReference.name with a\nconnectionSecret, because upstream resolves the name to a\nRabbitmqCluster resource this chart does not create. Only\nconnectionSecret and a foreign rabbitmqClusterReference.namespace are\nunimplemented, and both are rejected rather than ignored; a name\npointing at another cluster is left untouched, so the two reconcilers\ncan coexist in one namespace. The definitions carry upstream\u0027s\nexactly-one-of rule as a CEL validation rule, so it is enforced without\na webhook.\n\nThere is deliberately no Connection kind. Upstream has none, nothing in\nrabbitmq.com/v1beta1 carries a broker address, and a chart already knows\nthe address from endpoints.oslo_messaging, which it renders into\ntransport_url today. That is also why the User resources import their\ncredentials instead of letting the reconciler generate a password: the\ntwo have to agree.\n\nconf.rabbitmq.policies is translated into one Policy resource per entry,\nreplacing the rabbitmqadmin import the job performed. Every converted\nchart ships an ha_ttl_\u003cservice\u003e policy there, so skipping this would\nsilently drop queue mirroring and message expiry. Rendering fails on any\nother conf.rabbitmq key rather than discarding it.\n\nThe reconciler talks to the HTTP management API and uses nothing outside\nthe Python standard library, so it runs on the openstack-client image\nthe chart already pulls. Its periodic resync also removes the guest\naccount that definitions.json recreates on every node boot, which the\none-shot rabbit-init job could not.\n\nAdd a check job deploying the compute kit over this path, and a\nverify-rabbitmq-topology.sh step that waits for every resource to report\nReady, reads the vhosts and accounts back out of the broker, and asserts\nthe guest account is gone and no rabbit-init job remains. Without it the\njob would pass whether or not any of this worked, because oslo.messaging\nretries its connection forever.\n\nBoth provisioning paths stay mutually exclusive and both new manifest\nswitches default to off, so existing deployments render unchanged apart\nfrom the inert custom resource definitions.\n\nChange-Id: I859c3a4d5e6c670e99b6b1cb138ec48f5a57456e\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/349780e10b5d194a18c5204acb432c821fd0db18"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/349780e10b5d194a18c5204acb432c821fd0db18"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY"},{"label":"Workflow","status":"MAY"}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
