)]}'
{"deployment/nova/nova-migration-target-container-puppet.yaml":[{"author":{"_account_id":23811,"name":"Oliver Walsh","email":"owalsh@redhat.com","username":"owalsh"},"change_message_id":"532e5b38c12a86159a1f7f6f96290c31894e22cf","unresolved":false,"context_lines":[{"line_number":67,"context_line":"    type: ../containers-common.yaml"},{"line_number":68,"context_line":""},{"line_number":69,"context_line":"  SshdBase:"},{"line_number":70,"context_line":"    type: ../../deployment/sshd/sshd-baremetal-ansible.yaml"},{"line_number":71,"context_line":"    properties:"},{"line_number":72,"context_line":"      EndpointMap: {get_param: EndpointMap}"},{"line_number":73,"context_line":"      ServiceNetMap: {get_param: ServiceNetMap}"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"7faddb67_1ee83614","line":70,"range":{"start_line":70,"start_character":10,"end_line":70,"end_character":59},"updated":"2019-08-13 19:04:10.000000000","message":"I assume that should be ../../deployment/deprecated/sshd/sshd-baremetal-puppet.yaml. \n\nThis service is basically a containerised version of it, on a different port, with some additional conf (e.g Match blocks in the sshd config).","commit_id":"bc78a6af54f3f97878c7539f500696452c7c7a49"},{"author":{"_account_id":25877,"name":"Luke Short","email":"ekultails@gmail.com","username":"ekultails"},"change_message_id":"ff4fb4df18976db33ea64bf2d0ed56b2e3c00e7d","unresolved":false,"context_lines":[{"line_number":67,"context_line":"    type: ../containers-common.yaml"},{"line_number":68,"context_line":""},{"line_number":69,"context_line":"  SshdBase:"},{"line_number":70,"context_line":"    type: ../../deployment/sshd/sshd-baremetal-ansible.yaml"},{"line_number":71,"context_line":"    properties:"},{"line_number":72,"context_line":"      EndpointMap: {get_param: EndpointMap}"},{"line_number":73,"context_line":"      ServiceNetMap: {get_param: ServiceNetMap}"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"7faddb67_2b57b25c","line":70,"range":{"start_line":70,"start_character":10,"end_line":70,"end_character":59},"in_reply_to":"7faddb67_1ee83614","updated":"2019-08-16 21:10:08.000000000","message":"Done","commit_id":"bc78a6af54f3f97878c7539f500696452c7c7a49"},{"author":{"_account_id":7144,"name":"James Slagle","email":"jslagle@redhat.com","username":"slagle"},"change_message_id":"8b857a0ab2059671c3bbddf0704afdc7c1e7a7d7","unresolved":false,"context_lines":[{"line_number":67,"context_line":"    type: ../containers-common.yaml"},{"line_number":68,"context_line":""},{"line_number":69,"context_line":"  SshdBase:"},{"line_number":70,"context_line":"    type: ../../deployment/deprecated/sshd/sshd-baremetal-puppet.yaml"},{"line_number":71,"context_line":"    properties:"},{"line_number":72,"context_line":"      EndpointMap: {get_param: EndpointMap}"},{"line_number":73,"context_line":"      ServiceNetMap: {get_param: ServiceNetMap}"}],"source_content_type":"text/x-yaml","patch_set":4,"id":"7faddb67_1c8da629","line":70,"updated":"2019-08-28 18:15:49.000000000","message":"what\u0027s the reasoning here?\n\nshould we hold off on marking the template deprecated while it\u0027s still in use here?","commit_id":"c13276bffbd5c7615cd376b8db34d2fce60bb209"},{"author":{"_account_id":7353,"name":"Kevin Carter","email":"kevin@cloudnull.com","username":"cloudnull"},"change_message_id":"6083a572697ce96fde9255ac42d96387ec63253f","unresolved":false,"context_lines":[{"line_number":67,"context_line":"    type: ../containers-common.yaml"},{"line_number":68,"context_line":""},{"line_number":69,"context_line":"  SshdBase:"},{"line_number":70,"context_line":"    type: ../../deployment/deprecated/sshd/sshd-baremetal-puppet.yaml"},{"line_number":71,"context_line":"    properties:"},{"line_number":72,"context_line":"      EndpointMap: {get_param: EndpointMap}"},{"line_number":73,"context_line":"      ServiceNetMap: {get_param: ServiceNetMap}"}],"source_content_type":"text/x-yaml","patch_set":4,"id":"7faddb67_d416af4a","line":70,"in_reply_to":"7faddb67_1c8da629","updated":"2019-09-04 01:29:19.000000000","message":"I think this was an early revision due to feedback within the ssh role. I will update this review to reflect what has been merged into tripleo-ansible.","commit_id":"c13276bffbd5c7615cd376b8db34d2fce60bb209"},{"author":{"_account_id":23811,"name":"Oliver Walsh","email":"owalsh@redhat.com","username":"owalsh"},"change_message_id":"374c07bc3790632ab198a4b94177412c7c7bb69e","unresolved":false,"context_lines":[{"line_number":67,"context_line":"    type: ../containers-common.yaml"},{"line_number":68,"context_line":""},{"line_number":69,"context_line":"  SshdBase:"},{"line_number":70,"context_line":"    type: ../../deployment/sshd/sshd-baremetal-ansible.yaml"},{"line_number":71,"context_line":"    properties:"},{"line_number":72,"context_line":"      EndpointMap: {get_param: EndpointMap}"},{"line_number":73,"context_line":"      ServiceNetMap: {get_param: ServiceNetMap}"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"3fa7e38b_6b18bc1c","line":70,"range":{"start_line":70,"start_character":10,"end_line":70,"end_character":59},"updated":"2019-09-19 10:52:39.000000000","message":"Can\u0027t use ansible for containerised services (yet), also this service needs support for sshd_config MATCH blocks with isn\u0027t implemented in the ansible role (yet).\n\nWas already fixed in PS3\nhttps://review.opendev.org/#/c/675708/3/deployment/nova/nova-migration-target-container-puppet.yaml@70","commit_id":"73ad0834ad3408f3cfe0314df425d8de7bdea7ce"},{"author":{"_account_id":25877,"name":"Luke Short","email":"ekultails@gmail.com","username":"ekultails"},"change_message_id":"92f2221b95f753973b404e99fd7eaf90fecf706c","unresolved":false,"context_lines":[{"line_number":67,"context_line":"    type: ../containers-common.yaml"},{"line_number":68,"context_line":""},{"line_number":69,"context_line":"  SshdBase:"},{"line_number":70,"context_line":"    type: ../../deployment/sshd/sshd-baremetal-ansible.yaml"},{"line_number":71,"context_line":"    properties:"},{"line_number":72,"context_line":"      EndpointMap: {get_param: EndpointMap}"},{"line_number":73,"context_line":"      ServiceNetMap: {get_param: ServiceNetMap}"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"3fa7e38b_d89836c1","line":70,"range":{"start_line":70,"start_character":10,"end_line":70,"end_character":59},"in_reply_to":"3fa7e38b_6b18bc1c","updated":"2019-09-25 15:54:22.000000000","message":"Switched back to using the (now) deprecated Puppet in my latest patch. I believe the match block concerns are addressed by this update: https://github.com/openstack/tripleo-ansible/commit/578962e83ffdf173c710b3c779b08e4bafed5490","commit_id":"73ad0834ad3408f3cfe0314df425d8de7bdea7ce"},{"author":{"_account_id":25877,"name":"Luke Short","email":"ekultails@gmail.com","username":"ekultails"},"change_message_id":"cf476630f399abb80c415977f1614fd27d3ea530","unresolved":false,"context_lines":[{"line_number":67,"context_line":"    type: ../containers-common.yaml"},{"line_number":68,"context_line":""},{"line_number":69,"context_line":"  SshdBase:"},{"line_number":70,"context_line":"    type: ../../deployment/sshd/sshd-baremetal-ansible.yaml"},{"line_number":71,"context_line":"    properties:"},{"line_number":72,"context_line":"      EndpointMap: {get_param: EndpointMap}"},{"line_number":73,"context_line":"      ServiceNetMap: {get_param: ServiceNetMap}"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"3fa7e38b_9bde260f","line":70,"range":{"start_line":70,"start_character":10,"end_line":70,"end_character":59},"in_reply_to":"3fa7e38b_945cbbed","updated":"2019-09-26 12:50:04.000000000","message":"Thanks for the feedback, Oliver. I\u0027ll investigate into adding this.","commit_id":"73ad0834ad3408f3cfe0314df425d8de7bdea7ce"},{"author":{"_account_id":23811,"name":"Oliver Walsh","email":"owalsh@redhat.com","username":"owalsh"},"change_message_id":"61e5cc70f04a69e154ed24c4b25f1fe7e8edd083","unresolved":false,"context_lines":[{"line_number":67,"context_line":"    type: ../containers-common.yaml"},{"line_number":68,"context_line":""},{"line_number":69,"context_line":"  SshdBase:"},{"line_number":70,"context_line":"    type: ../../deployment/sshd/sshd-baremetal-ansible.yaml"},{"line_number":71,"context_line":"    properties:"},{"line_number":72,"context_line":"      EndpointMap: {get_param: EndpointMap}"},{"line_number":73,"context_line":"      ServiceNetMap: {get_param: ServiceNetMap}"}],"source_content_type":"text/x-yaml","patch_set":12,"id":"3fa7e38b_945cbbed","line":70,"range":{"start_line":70,"start_character":10,"end_line":70,"end_character":59},"in_reply_to":"3fa7e38b_d89836c1","updated":"2019-09-26 09:03:06.000000000","message":"Nah, it needs to support creating/updating MATCH blocks for this service e.g https://github.com/openstack/puppet-tripleo/blob/master/manifests/profile/base/nova/migration/target.pp#L73","commit_id":"73ad0834ad3408f3cfe0314df425d8de7bdea7ce"},{"author":{"_account_id":7144,"name":"James Slagle","email":"jslagle@redhat.com","username":"slagle"},"change_message_id":"efc87ea15becbc208cbe6b40ffaaae6453ab5fb1","unresolved":false,"context_lines":[{"line_number":67,"context_line":"    type: ../containers-common.yaml"},{"line_number":68,"context_line":""},{"line_number":69,"context_line":"  SshdBase:"},{"line_number":70,"context_line":"    type: ../../deployment/deprecated/sshd/sshd-baremetal-puppet.yaml"},{"line_number":71,"context_line":"    properties:"},{"line_number":72,"context_line":"      EndpointMap: {get_param: EndpointMap}"},{"line_number":73,"context_line":"      ServiceNetMap: {get_param: ServiceNetMap}"}],"source_content_type":"text/x-yaml","patch_set":16,"id":"3fa7e38b_a25459c7","line":70,"updated":"2020-01-20 20:12:34.000000000","message":"this is back to one of my earlier concerns that this service now depends on a deprecated service.\n\nI think the steps here should be to:\n- add the new sshd template\n- update nova-migration-target-container-puppet to use the new template\n- deprecate the old sshd template\n\nThat can happen in a single patch or multiple patches, but we can\u0027t mark the old sshd template deprecated without first updating this service as well.","commit_id":"672b8c846287a30274a4c66601f6970b8f6cc2d3"},{"author":{"_account_id":23811,"name":"Oliver Walsh","email":"owalsh@redhat.com","username":"owalsh"},"change_message_id":"e20db804e8c598b56a10e2eb7cbd496e7fbce657","unresolved":false,"context_lines":[{"line_number":67,"context_line":"    type: ../containers-common.yaml"},{"line_number":68,"context_line":""},{"line_number":69,"context_line":"  SshdBase:"},{"line_number":70,"context_line":"    type: ../../deployment/deprecated/sshd/sshd-baremetal-puppet.yaml"},{"line_number":71,"context_line":"    properties:"},{"line_number":72,"context_line":"      EndpointMap: {get_param: EndpointMap}"},{"line_number":73,"context_line":"      ServiceNetMap: {get_param: ServiceNetMap}"}],"source_content_type":"text/x-yaml","patch_set":16,"id":"3fa7e38b_ea6e6a63","line":70,"in_reply_to":"3fa7e38b_a25459c7","updated":"2020-01-24 10:12:55.000000000","message":"nova-migration-target-container-puppet is a containerised sshd, sshd-baremetal-ansible is the host sshd.\n\nAFAIK we don\u0027t currently have a deploy step to generate container config using ansible roles. Until/unless we do we cannot switch nova-migration-target-container-puppet to ansible.\n\nAlso nova-migration-target-container-puppet requires more advanced sshd config, e.g Match blocks, which isn\u0027t currently supported in the tripleo-sshd ansible role.\n\nI think the only options for now are to not deprecated the puppet sshd service, or go ahead and deprecated it but duplicate the config_settings here.","commit_id":"672b8c846287a30274a4c66601f6970b8f6cc2d3"}],"deployment/sshd/sshd-baremetal-ansible.yaml":[{"author":{"_account_id":7144,"name":"James Slagle","email":"jslagle@redhat.com","username":"slagle"},"change_message_id":"02d504b93299d37a04d2551a405422c34175651b","unresolved":false,"context_lines":[{"line_number":90,"context_line":"      host_prep_tasks:"},{"line_number":91,"context_line":"        - name: Import TripleO SSH daemon role"},{"line_number":92,"context_line":"          include_role:"},{"line_number":93,"context_line":"            name: tripleo_sshd"},{"line_number":94,"context_line":"          vars:"},{"line_number":95,"context_line":"            tripleo_sshd_banner_text: {get_param: BannerText}"},{"line_number":96,"context_line":"            tripleo_sshd_message_of_the_day: {get_param: MessageOfTheDay}"}],"source_content_type":"text/x-yaml","patch_set":11,"id":"5faad753_bb283286","line":93,"updated":"2019-09-10 14:39:18.000000000","message":"looks like this needs to be \"tripleo-sshd\"","commit_id":"1c72ea126e8220fa7401482c290b69c4c305a16a"},{"author":{"_account_id":7353,"name":"Kevin Carter","email":"kevin@cloudnull.com","username":"cloudnull"},"change_message_id":"83883353951836c4db90f942bbd2e7c81bc483cf","unresolved":false,"context_lines":[{"line_number":90,"context_line":"      host_prep_tasks:"},{"line_number":91,"context_line":"        - name: Import TripleO SSH daemon role"},{"line_number":92,"context_line":"          include_role:"},{"line_number":93,"context_line":"            name: tripleo_sshd"},{"line_number":94,"context_line":"          vars:"},{"line_number":95,"context_line":"            tripleo_sshd_banner_text: {get_param: BannerText}"},{"line_number":96,"context_line":"            tripleo_sshd_message_of_the_day: {get_param: MessageOfTheDay}"}],"source_content_type":"text/x-yaml","patch_set":11,"id":"5faad753_baf57485","line":93,"in_reply_to":"5faad753_bb283286","updated":"2019-09-11 13:14:07.000000000","message":"Done","commit_id":"1c72ea126e8220fa7401482c290b69c4c305a16a"}],"deployment/sshd/sshd-baremetal-puppet.yaml":[{"author":{"_account_id":7353,"name":"Kevin Carter","email":"kevin@cloudnull.com","username":"cloudnull"},"change_message_id":"e6727ca7a43b4ffb57de6f55c780c4555364b737","unresolved":false,"context_lines":[{"line_number":80,"context_line":"          - tripleo::profile::base::sshd::bannertext: {get_param: BannerText}"},{"line_number":81,"context_line":"            tripleo::profile::base::sshd::motd: {get_param: MessageOfTheDay}"},{"line_number":82,"context_line":"            tripleo::profile::base::sshd::options: {get_param: SshServerOptions}"},{"line_number":83,"context_line":"            tripleo::profile::base::sshd::password_authentication: {get_param: PasswordAuthentication}"},{"line_number":84,"context_line":"          - if:"},{"line_number":85,"context_line":"            - {get_param: SshFirewallAllowAll}"},{"line_number":86,"context_line":"            - tripleo::sshd::firewall_rules:"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"7faddb67_063a41cc","side":"PARENT","line":83,"range":{"start_line":83,"start_character":0,"end_line":83,"end_character":102},"updated":"2019-08-12 19:04:45.000000000","message":"I don\u0027t see where \"password_authentication: {get_param: PasswordAuthentication}\" is implemented within the role?","commit_id":"618878bc35f84f5cf4af65c4ee1dcf2a5714db7c"},{"author":{"_account_id":7353,"name":"Kevin Carter","email":"kevin@cloudnull.com","username":"cloudnull"},"change_message_id":"e6727ca7a43b4ffb57de6f55c780c4555364b737","unresolved":false,"context_lines":[{"line_number":77,"context_line":"      service_name: sshd"},{"line_number":78,"context_line":"      config_settings:"},{"line_number":79,"context_line":"        map_merge:"},{"line_number":80,"context_line":"          - tripleo::profile::base::sshd::bannertext: {get_param: BannerText}"},{"line_number":81,"context_line":"            tripleo::profile::base::sshd::motd: {get_param: MessageOfTheDay}"},{"line_number":82,"context_line":"            tripleo::profile::base::sshd::options: {get_param: SshServerOptions}"},{"line_number":83,"context_line":"            tripleo::profile::base::sshd::password_authentication: {get_param: PasswordAuthentication}"},{"line_number":84,"context_line":"          - if:"},{"line_number":85,"context_line":"            - {get_param: SshFirewallAllowAll}"},{"line_number":86,"context_line":"            - tripleo::sshd::firewall_rules:"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"7faddb67_a629ed89","side":"PARENT","line":83,"range":{"start_line":80,"start_character":0,"end_line":83,"end_character":102},"updated":"2019-08-12 19:04:45.000000000","message":"I think these need to be translated into ansible variables in the role being called.\n\nvars:\n  tripleo_sshd_banner_text: {get_param: BannerText}\n  tripleo_sshd_message_of_the_day: {get_param: MessageOfTheDay}\n  tripleo_sshd_server_options: {get_param: SshServerOptions}","commit_id":"618878bc35f84f5cf4af65c4ee1dcf2a5714db7c"},{"author":{"_account_id":25877,"name":"Luke Short","email":"ekultails@gmail.com","username":"ekultails"},"change_message_id":"ff4fb4df18976db33ea64bf2d0ed56b2e3c00e7d","unresolved":false,"context_lines":[{"line_number":80,"context_line":"          - tripleo::profile::base::sshd::bannertext: {get_param: BannerText}"},{"line_number":81,"context_line":"            tripleo::profile::base::sshd::motd: {get_param: MessageOfTheDay}"},{"line_number":82,"context_line":"            tripleo::profile::base::sshd::options: {get_param: SshServerOptions}"},{"line_number":83,"context_line":"            tripleo::profile::base::sshd::password_authentication: {get_param: PasswordAuthentication}"},{"line_number":84,"context_line":"          - if:"},{"line_number":85,"context_line":"            - {get_param: SshFirewallAllowAll}"},{"line_number":86,"context_line":"            - tripleo::sshd::firewall_rules:"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"7faddb67_8db95e16","side":"PARENT","line":83,"range":{"start_line":83,"start_character":0,"end_line":83,"end_character":102},"in_reply_to":"7faddb67_063a41cc","updated":"2019-08-16 21:10:08.000000000","message":"Done","commit_id":"618878bc35f84f5cf4af65c4ee1dcf2a5714db7c"},{"author":{"_account_id":25877,"name":"Luke Short","email":"ekultails@gmail.com","username":"ekultails"},"change_message_id":"ff4fb4df18976db33ea64bf2d0ed56b2e3c00e7d","unresolved":false,"context_lines":[{"line_number":77,"context_line":"      service_name: sshd"},{"line_number":78,"context_line":"      config_settings:"},{"line_number":79,"context_line":"        map_merge:"},{"line_number":80,"context_line":"          - tripleo::profile::base::sshd::bannertext: {get_param: BannerText}"},{"line_number":81,"context_line":"            tripleo::profile::base::sshd::motd: {get_param: MessageOfTheDay}"},{"line_number":82,"context_line":"            tripleo::profile::base::sshd::options: {get_param: SshServerOptions}"},{"line_number":83,"context_line":"            tripleo::profile::base::sshd::password_authentication: {get_param: PasswordAuthentication}"},{"line_number":84,"context_line":"          - if:"},{"line_number":85,"context_line":"            - {get_param: SshFirewallAllowAll}"},{"line_number":86,"context_line":"            - tripleo::sshd::firewall_rules:"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"7faddb67_0d432e15","side":"PARENT","line":83,"range":{"start_line":80,"start_character":0,"end_line":83,"end_character":102},"in_reply_to":"7faddb67_a629ed89","updated":"2019-08-16 21:10:08.000000000","message":"Done","commit_id":"618878bc35f84f5cf4af65c4ee1dcf2a5714db7c"},{"author":{"_account_id":7353,"name":"Kevin Carter","email":"kevin@cloudnull.com","username":"cloudnull"},"change_message_id":"e6727ca7a43b4ffb57de6f55c780c4555364b737","unresolved":false,"context_lines":[{"line_number":81,"context_line":"            tripleo::profile::base::sshd::motd: {get_param: MessageOfTheDay}"},{"line_number":82,"context_line":"            tripleo::profile::base::sshd::options: {get_param: SshServerOptions}"},{"line_number":83,"context_line":"            tripleo::profile::base::sshd::password_authentication: {get_param: PasswordAuthentication}"},{"line_number":84,"context_line":"          - if:"},{"line_number":85,"context_line":"            - {get_param: SshFirewallAllowAll}"},{"line_number":86,"context_line":"            - tripleo::sshd::firewall_rules:"},{"line_number":87,"context_line":"                \u0027003 accept ssh from all\u0027:"},{"line_number":88,"context_line":"                  proto: \u0027tcp\u0027"},{"line_number":89,"context_line":"                  dport: 22"},{"line_number":90,"context_line":"            - tripleo::sshd::firewall_rules:"},{"line_number":91,"context_line":"                \u0027003 accept ssh from all\u0027:"},{"line_number":92,"context_line":"                  proto: \u0027tcp\u0027"},{"line_number":93,"context_line":"                  dport: 22"},{"line_number":94,"context_line":"                  extras:"},{"line_number":95,"context_line":"                    ensure: \u0027absent\u0027"},{"line_number":96,"context_line":""},{"line_number":97,"context_line":"      step_config: |"},{"line_number":98,"context_line":"        include ::tripleo::profile::base::sshd"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"7faddb67_869951d1","side":"PARENT","line":95,"range":{"start_line":84,"start_character":0,"end_line":95,"end_character":36},"updated":"2019-08-12 19:04:45.000000000","message":"this firewall condition needs to be present too.","commit_id":"618878bc35f84f5cf4af65c4ee1dcf2a5714db7c"},{"author":{"_account_id":25877,"name":"Luke Short","email":"ekultails@gmail.com","username":"ekultails"},"change_message_id":"ff4fb4df18976db33ea64bf2d0ed56b2e3c00e7d","unresolved":false,"context_lines":[{"line_number":81,"context_line":"            tripleo::profile::base::sshd::motd: {get_param: MessageOfTheDay}"},{"line_number":82,"context_line":"            tripleo::profile::base::sshd::options: {get_param: SshServerOptions}"},{"line_number":83,"context_line":"            tripleo::profile::base::sshd::password_authentication: {get_param: PasswordAuthentication}"},{"line_number":84,"context_line":"          - if:"},{"line_number":85,"context_line":"            - {get_param: SshFirewallAllowAll}"},{"line_number":86,"context_line":"            - tripleo::sshd::firewall_rules:"},{"line_number":87,"context_line":"                \u0027003 accept ssh from all\u0027:"},{"line_number":88,"context_line":"                  proto: \u0027tcp\u0027"},{"line_number":89,"context_line":"                  dport: 22"},{"line_number":90,"context_line":"            - tripleo::sshd::firewall_rules:"},{"line_number":91,"context_line":"                \u0027003 accept ssh from all\u0027:"},{"line_number":92,"context_line":"                  proto: \u0027tcp\u0027"},{"line_number":93,"context_line":"                  dport: 22"},{"line_number":94,"context_line":"                  extras:"},{"line_number":95,"context_line":"                    ensure: \u0027absent\u0027"},{"line_number":96,"context_line":""},{"line_number":97,"context_line":"      step_config: |"},{"line_number":98,"context_line":"        include ::tripleo::profile::base::sshd"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"7faddb67_0d5c8eeb","side":"PARENT","line":95,"range":{"start_line":84,"start_character":0,"end_line":95,"end_character":36},"in_reply_to":"7faddb67_869951d1","updated":"2019-08-16 21:10:08.000000000","message":"Done","commit_id":"618878bc35f84f5cf4af65c4ee1dcf2a5714db7c"},{"author":{"_account_id":7353,"name":"Kevin Carter","email":"kevin@cloudnull.com","username":"cloudnull"},"change_message_id":"e6727ca7a43b4ffb57de6f55c780c4555364b737","unresolved":false,"context_lines":[{"line_number":76,"context_line":"    value:"},{"line_number":77,"context_line":"      service_name: sshd"},{"line_number":78,"context_line":"      host_prep_tasks:"},{"line_number":79,"context_line":"        - name: Run firewall role"},{"line_number":80,"context_line":"          include_role:"},{"line_number":81,"context_line":"            name: tripleo-firewall"},{"line_number":82,"context_line":"          vars:"},{"line_number":83,"context_line":"            tripleo_firewall_rules:"},{"line_number":84,"context_line":"              \u002722 ssh\u0027:"},{"line_number":85,"context_line":"                proto: tcp"},{"line_number":86,"context_line":"                dport:"},{"line_number":87,"context_line":"                  - 22"},{"line_number":88,"context_line":""},{"line_number":89,"context_line":"        - name: Import TripleO SSH daemon role"},{"line_number":90,"context_line":"          import_role:"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"7faddb67_46f11901","line":87,"range":{"start_line":79,"start_character":0,"end_line":87,"end_character":22},"updated":"2019-08-12 19:04:45.000000000","message":"The firewall condition can be written like so\n\n\n- if:\n  - {get_param: SshFirewallAllowAll}\n  - name: Run firewall role\n    include_role:\n      name: tripleo-firewall\n    vars:\n      tripleo_firewall_rules:\n        \u0027003 accept ssh from all\u0027:\n          proto: tcp\n          dport: 22\n  - name: Run firewall role\n    include_role:\n      name: tripleo-firewall\n    vars:\n      tripleo_firewall_rules:\n        \u0027003 accept ssh from all\u0027:\n          proto: \u0027tcp\u0027\n          dport: 22\n          extras:\n            ensure: \u0027absent\u0027","commit_id":"e9c158560f09944cee16b8daeadf27a87db6ac6a"},{"author":{"_account_id":25877,"name":"Luke Short","email":"ekultails@gmail.com","username":"ekultails"},"change_message_id":"ff4fb4df18976db33ea64bf2d0ed56b2e3c00e7d","unresolved":false,"context_lines":[{"line_number":76,"context_line":"    value:"},{"line_number":77,"context_line":"      service_name: sshd"},{"line_number":78,"context_line":"      host_prep_tasks:"},{"line_number":79,"context_line":"        - name: Run firewall role"},{"line_number":80,"context_line":"          include_role:"},{"line_number":81,"context_line":"            name: tripleo-firewall"},{"line_number":82,"context_line":"          vars:"},{"line_number":83,"context_line":"            tripleo_firewall_rules:"},{"line_number":84,"context_line":"              \u002722 ssh\u0027:"},{"line_number":85,"context_line":"                proto: tcp"},{"line_number":86,"context_line":"                dport:"},{"line_number":87,"context_line":"                  - 22"},{"line_number":88,"context_line":""},{"line_number":89,"context_line":"        - name: Import TripleO SSH daemon role"},{"line_number":90,"context_line":"          import_role:"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"7faddb67_ad721a7b","line":87,"range":{"start_line":79,"start_character":0,"end_line":87,"end_character":22},"in_reply_to":"7faddb67_46f11901","updated":"2019-08-16 21:10:08.000000000","message":"Done","commit_id":"e9c158560f09944cee16b8daeadf27a87db6ac6a"},{"author":{"_account_id":7353,"name":"Kevin Carter","email":"kevin@cloudnull.com","username":"cloudnull"},"change_message_id":"e6727ca7a43b4ffb57de6f55c780c4555364b737","unresolved":false,"context_lines":[{"line_number":87,"context_line":"                  - 22"},{"line_number":88,"context_line":""},{"line_number":89,"context_line":"        - name: Import TripleO SSH daemon role"},{"line_number":90,"context_line":"          import_role:"},{"line_number":91,"context_line":"            name: tripleo_sshd"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"7faddb67_06ad61e9","line":90,"range":{"start_line":90,"start_character":10,"end_line":90,"end_character":21},"updated":"2019-08-12 19:04:45.000000000","message":"this will need to be `include_role` when passing variables in.","commit_id":"e9c158560f09944cee16b8daeadf27a87db6ac6a"},{"author":{"_account_id":25877,"name":"Luke Short","email":"ekultails@gmail.com","username":"ekultails"},"change_message_id":"ff4fb4df18976db33ea64bf2d0ed56b2e3c00e7d","unresolved":false,"context_lines":[{"line_number":87,"context_line":"                  - 22"},{"line_number":88,"context_line":""},{"line_number":89,"context_line":"        - name: Import TripleO SSH daemon role"},{"line_number":90,"context_line":"          import_role:"},{"line_number":91,"context_line":"            name: tripleo_sshd"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"7faddb67_4d6286af","line":90,"range":{"start_line":90,"start_character":10,"end_line":90,"end_character":21},"in_reply_to":"7faddb67_06ad61e9","updated":"2019-08-16 21:10:08.000000000","message":"Done","commit_id":"e9c158560f09944cee16b8daeadf27a87db6ac6a"}]}
