)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":32102,"name":"Manpreet Kaur","email":"kaurmanpreet2620@gmail.com","username":"manpreet"},"change_message_id":"b3de4946e17b49dd8eef3233b8da8a6b90974dcd","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":10,"id":"4b43061a_57666061","updated":"2022-08-05 04:21:21.000000000","message":"Hi Reviewers,\n\nI have updated the document with the conclusion as discussed in the last IRC meeting held on 2nd August [1]. Please review.\n\n[1] https://meetings.opendev.org/meetings/tacker/2022/tacker.2022-08-02-08.00.log.html#l-76","commit_id":"caf4594f76fa903f10fafbfce10735fb8a7d93f9"},{"author":{"_account_id":31857,"name":"Ayumu Ueha","email":"ueha.ayumu@fujitsu.com","username":"ueha"},"change_message_id":"2d0ea75d9fa7f43270b9ee19870d0d14f6ea1e89","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":10,"id":"ef0221d5_b13c7eb0","updated":"2022-08-09 06:01:52.000000000","message":"Sorry for the late review, please kindly find my comment.","commit_id":"caf4594f76fa903f10fafbfce10735fb8a7d93f9"},{"author":{"_account_id":32102,"name":"Manpreet Kaur","email":"kaurmanpreet2620@gmail.com","username":"manpreet"},"change_message_id":"9a2b1f5dc0494fed458c584022e167cd4c0b139c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":10,"id":"db809ada_235ac1b0","updated":"2022-08-08 14:35:42.000000000","message":"ping","commit_id":"caf4594f76fa903f10fafbfce10735fb8a7d93f9"},{"author":{"_account_id":32102,"name":"Manpreet Kaur","email":"kaurmanpreet2620@gmail.com","username":"manpreet"},"change_message_id":"0df0b95e1e3523abb97929f2d9d847f088bcca8a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":11,"id":"cffb7675_38b521c7","updated":"2022-08-09 07:05:30.000000000","message":"Thanks for review.","commit_id":"aed90244a9a355e0de93e8e33d2a4b0e70c41049"},{"author":{"_account_id":31857,"name":"Ayumu Ueha","email":"ueha.ayumu@fujitsu.com","username":"ueha"},"change_message_id":"11f807aa3900f76575207b6d0bb2dcdc5e487e78","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":11,"id":"f8e759ed_abc65636","updated":"2022-08-10 01:12:32.000000000","message":"Thanks for your rework, LGTM!","commit_id":"aed90244a9a355e0de93e8e33d2a4b0e70c41049"}],"specs/zed/enhance-multi-tenant-policy.rst":[{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"17a0de45c54d75d4507acfe8208ca771f77f1b74","unresolved":true,"context_lines":[{"line_number":43,"context_line":""},{"line_number":44,"context_line":"Below mention policies require necessitates change:"},{"line_number":45,"context_line":""},{"line_number":46,"context_line":"#. Heat Policies"},{"line_number":47,"context_line":""},{"line_number":48,"context_line":"   * resource_types:OS::Nova::Flavor"},{"line_number":49,"context_line":"   * resource_types:OS::Cinder::VolumeType"},{"line_number":50,"context_line":"   * resource_types:OS::Neutron::QoSPolicy"},{"line_number":51,"context_line":"   * resource_types:OS::Neutron::QoSBandwidthLimitRule"},{"line_number":52,"context_line":""},{"line_number":53,"context_line":"#. Nova Policies"},{"line_number":54,"context_line":""},{"line_number":55,"context_line":"   * os_compute_api:os-flavor-manage"},{"line_number":56,"context_line":"   * os_compute_api:os-flavor-manage:create"},{"line_number":57,"context_line":"   * os_compute_api:os-flavor-manage:delete"},{"line_number":58,"context_line":""},{"line_number":59,"context_line":"#. Neutron Policies"},{"line_number":60,"context_line":""},{"line_number":61,"context_line":"   * create_policy"},{"line_number":62,"context_line":"   * create_policy_bandwidth_limit_rule"},{"line_number":63,"context_line":""},{"line_number":64,"context_line":".. note:: The OpenStack policies are currently being investigated, hence the"},{"line_number":65,"context_line":"  above-mentioned policy list may change."}],"source_content_type":"text/x-rst","patch_set":7,"id":"d351f032_bc43c239","line":62,"range":{"start_line":46,"start_character":0,"end_line":62,"end_character":35},"updated":"2022-04-06 02:04:41.000000000","message":"this is a little more complex than we thought and with the new RBAC goal[1] it is going to be more complex.\n\nWith new RBAC, nova has made the flavor manage as system-admin[2] API (with scope as \u0027system\u0027 and scope thing is not configurable) and create server as project members (again scope as \u0027project\u0027). Now heat create_stack call both flavor manage and create server in nova and both operations are different scopped. The question is what scope token create_stack should have?\n\nSo in summary, with the new RBAC admin and the non-admin case of multi-tenancy tacker will be broken. this is an open question and we are in discussion of it in TC PTG. Please join there and bring tacker use case also\n\n- Thursday ~14 UTC https://etherpad.opendev.org/p/tc-zed-ptg#L84\n\n\n[1] https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html\n\n[2] https://review.opendev.org/c/openstack/nova/+/828994/8/nova/policies/flavor_manage.py#b36","commit_id":"13a8454a0107554b424d18ea196596803f78d729"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"17a0de45c54d75d4507acfe8208ca771f77f1b74","unresolved":true,"context_lines":[{"line_number":63,"context_line":""},{"line_number":64,"context_line":".. note:: The OpenStack policies are currently being investigated, hence the"},{"line_number":65,"context_line":"  above-mentioned policy list may change."},{"line_number":66,"context_line":""},{"line_number":67,"context_line":"2. Design for negative functional test cases"},{"line_number":68,"context_line":"--------------------------------------------"},{"line_number":69,"context_line":""}],"source_content_type":"text/x-rst","patch_set":7,"id":"10f6f442_5ed237f2","line":66,"range":{"start_line":66,"start_character":0,"end_line":66,"end_character":0},"updated":"2022-04-06 02:04:41.000000000","message":"so if we modify the mentioned policy, can non-admin instantiate the VNF? I mean is there any restriction from Tacker side or anything you need to modify in Tacker?","commit_id":"13a8454a0107554b424d18ea196596803f78d729"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"17a0de45c54d75d4507acfe8208ca771f77f1b74","unresolved":true,"context_lines":[{"line_number":80,"context_line":"in functional test cases. But in a multi-tenant environment following two"},{"line_number":81,"context_line":"approaches could be considered."},{"line_number":82,"context_line":""},{"line_number":83,"context_line":"#. Create notification servers in Zuul on two separate nodes."},{"line_number":84,"context_line":""},{"line_number":85,"context_line":"#. In existing design, mock HTTP request and response for notification servers."},{"line_number":86,"context_line":""}],"source_content_type":"text/x-rst","patch_set":7,"id":"5a528f84_65fd400f","line":83,"updated":"2022-04-06 02:04:41.000000000","message":"It will be a little difficult from zuul side because:\n\n1. you need to add more than one node with a specific port open (port open might need a special request to that node)\n2. write the http server via ansible playbook or so\n3. actual http request might fail on more timeout or so.\n\nIn upstream CI, it is difficult, maybe you can move this as alternate solution and if anyone would like to try it in 3rd party CI then they can do.","commit_id":"13a8454a0107554b424d18ea196596803f78d729"},{"author":{"_account_id":32102,"name":"Manpreet Kaur","email":"kaurmanpreet2620@gmail.com","username":"manpreet"},"change_message_id":"ed42f2a9214a3bd1b50892acabcd7f878981f8c8","unresolved":false,"context_lines":[{"line_number":80,"context_line":"in functional test cases. But in a multi-tenant environment following two"},{"line_number":81,"context_line":"approaches could be considered."},{"line_number":82,"context_line":""},{"line_number":83,"context_line":"#. Create notification servers in Zuul on two separate nodes."},{"line_number":84,"context_line":""},{"line_number":85,"context_line":"#. In existing design, mock HTTP request and response for notification servers."},{"line_number":86,"context_line":""}],"source_content_type":"text/x-rst","patch_set":7,"id":"d4bf5c44_377df650","line":83,"in_reply_to":"5a528f84_65fd400f","updated":"2022-04-06 04:28:45.000000000","message":"Ack, thanks for your insightful feedback, added the same in alternate section.","commit_id":"13a8454a0107554b424d18ea196596803f78d729"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"17a0de45c54d75d4507acfe8208ca771f77f1b74","unresolved":true,"context_lines":[{"line_number":82,"context_line":""},{"line_number":83,"context_line":"#. Create notification servers in Zuul on two separate nodes."},{"line_number":84,"context_line":""},{"line_number":85,"context_line":"#. In existing design, mock HTTP request and response for notification servers."},{"line_number":86,"context_line":""},{"line_number":87,"context_line":"Alternatives"},{"line_number":88,"context_line":"------------"}],"source_content_type":"text/x-rst","patch_set":7,"id":"a24e3131_0a8f0251","line":85,"range":{"start_line":85,"start_character":0,"end_line":85,"end_character":79},"updated":"2022-04-06 02:04:41.000000000","message":"+1, as long as you are asserting on the tenant_id in callback or so it should verify the notification isolation.","commit_id":"13a8454a0107554b424d18ea196596803f78d729"},{"author":{"_account_id":32102,"name":"Manpreet Kaur","email":"kaurmanpreet2620@gmail.com","username":"manpreet"},"change_message_id":"ed42f2a9214a3bd1b50892acabcd7f878981f8c8","unresolved":false,"context_lines":[{"line_number":82,"context_line":""},{"line_number":83,"context_line":"#. Create notification servers in Zuul on two separate nodes."},{"line_number":84,"context_line":""},{"line_number":85,"context_line":"#. In existing design, mock HTTP request and response for notification servers."},{"line_number":86,"context_line":""},{"line_number":87,"context_line":"Alternatives"},{"line_number":88,"context_line":"------------"}],"source_content_type":"text/x-rst","patch_set":7,"id":"767e1976_40bddf89","line":85,"range":{"start_line":85,"start_character":0,"end_line":85,"end_character":79},"in_reply_to":"a24e3131_0a8f0251","updated":"2022-04-06 04:28:45.000000000","message":"Ack","commit_id":"13a8454a0107554b424d18ea196596803f78d729"},{"author":{"_account_id":31857,"name":"Ayumu Ueha","email":"ueha.ayumu@fujitsu.com","username":"ueha"},"change_message_id":"2d0ea75d9fa7f43270b9ee19870d0d14f6ea1e89","unresolved":true,"context_lines":[{"line_number":159,"context_line":"  users to create VNF."},{"line_number":160,"context_line":"* Add negative functional test cases for notification server and vnf"},{"line_number":161,"context_line":"  instantiation for non admin role users."},{"line_number":162,"context_line":"  users can enable OpenStack policies."},{"line_number":163,"context_line":""},{"line_number":164,"context_line":"Dependencies"},{"line_number":165,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"}],"source_content_type":"text/x-rst","patch_set":10,"id":"868f433f_69c87cf8","line":162,"range":{"start_line":162,"start_character":2,"end_line":162,"end_character":38},"updated":"2022-08-09 06:01:52.000000000","message":"Didn\u0027t you forget to delete it?","commit_id":"caf4594f76fa903f10fafbfce10735fb8a7d93f9"},{"author":{"_account_id":32102,"name":"Manpreet Kaur","email":"kaurmanpreet2620@gmail.com","username":"manpreet"},"change_message_id":"0df0b95e1e3523abb97929f2d9d847f088bcca8a","unresolved":true,"context_lines":[{"line_number":159,"context_line":"  users to create VNF."},{"line_number":160,"context_line":"* Add negative functional test cases for notification server and vnf"},{"line_number":161,"context_line":"  instantiation for non admin role users."},{"line_number":162,"context_line":"  users can enable OpenStack policies."},{"line_number":163,"context_line":""},{"line_number":164,"context_line":"Dependencies"},{"line_number":165,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"}],"source_content_type":"text/x-rst","patch_set":10,"id":"df8ca4ae_8222f540","line":162,"range":{"start_line":162,"start_character":2,"end_line":162,"end_character":38},"in_reply_to":"868f433f_69c87cf8","updated":"2022-08-09 07:05:30.000000000","message":"Ack\n\nMy bad! Thanks for pointing it out. I removed unwanted sentences.","commit_id":"caf4594f76fa903f10fafbfce10735fb8a7d93f9"},{"author":{"_account_id":31857,"name":"Ayumu Ueha","email":"ueha.ayumu@fujitsu.com","username":"ueha"},"change_message_id":"11f807aa3900f76575207b6d0bb2dcdc5e487e78","unresolved":false,"context_lines":[{"line_number":159,"context_line":"  users to create VNF."},{"line_number":160,"context_line":"* Add negative functional test cases for notification server and vnf"},{"line_number":161,"context_line":"  instantiation for non admin role users."},{"line_number":162,"context_line":"  users can enable OpenStack policies."},{"line_number":163,"context_line":""},{"line_number":164,"context_line":"Dependencies"},{"line_number":165,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"}],"source_content_type":"text/x-rst","patch_set":10,"id":"43753c29_22b49fa7","line":162,"range":{"start_line":162,"start_character":2,"end_line":162,"end_character":38},"in_reply_to":"df8ca4ae_8222f540","updated":"2022-08-10 01:12:32.000000000","message":"Ack","commit_id":"caf4594f76fa903f10fafbfce10735fb8a7d93f9"}]}
