)]}'
{"deployment/memcached/memcached-container-puppet.yaml":[{"author":{"_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"},"change_message_id":"7d1a0f28d8b58cb733df94ad3a45f47c8f22933a","unresolved":false,"context_lines":[{"line_number":167,"context_line":"                      $NETWORK: {get_param: [ServiceNetMap, MemcachedNetwork]}"},{"line_number":168,"context_line":"                principal:"},{"line_number":169,"context_line":"                  str_replace:"},{"line_number":170,"context_line":"                    template: \"rabbitmq/%{hiera(\u0027fqdn_$NETWORK\u0027)}\""},{"line_number":171,"context_line":"                    params:"},{"line_number":172,"context_line":"                      $NETWORK: {get_param: [ServiceNetMap, MemcachedNetwork]}"},{"line_number":173,"context_line":"                postsave_cmd: \"pkill -USR1 memcached\""}],"source_content_type":"text/x-yaml","patch_set":3,"id":"9f560f44_1032f60f","line":170,"range":{"start_line":170,"start_character":31,"end_line":170,"end_character":39},"updated":"2020-09-18 16:39:26.000000000","message":"memcached?","commit_id":"eea7a9346e139c0e5aaec500c71a7aeded183f55"},{"author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"change_message_id":"5f11ec73603f460cce2a7520ee6fbbf6d93b7fc8","unresolved":false,"context_lines":[{"line_number":167,"context_line":"                      $NETWORK: {get_param: [ServiceNetMap, MemcachedNetwork]}"},{"line_number":168,"context_line":"                principal:"},{"line_number":169,"context_line":"                  str_replace:"},{"line_number":170,"context_line":"                    template: \"rabbitmq/%{hiera(\u0027fqdn_$NETWORK\u0027)}\""},{"line_number":171,"context_line":"                    params:"},{"line_number":172,"context_line":"                      $NETWORK: {get_param: [ServiceNetMap, MemcachedNetwork]}"},{"line_number":173,"context_line":"                postsave_cmd: \"pkill -USR1 memcached\""}],"source_content_type":"text/x-yaml","patch_set":3,"id":"9f560f44_398d5435","line":170,"range":{"start_line":170,"start_character":31,"end_line":170,"end_character":39},"in_reply_to":"9f560f44_1032f60f","updated":"2020-09-21 08:32:18.000000000","message":"Done","commit_id":"eea7a9346e139c0e5aaec500c71a7aeded183f55"},{"author":{"_account_id":24245,"name":"Harald Jensås","email":"hjensas@redhat.com","username":"harald.jensas"},"change_message_id":"5d598b6d6017d0e4510bf825a33344e08a944eb4","unresolved":false,"context_lines":[{"line_number":62,"context_line":"                 of the internal network. Use this parameter with caution and be aware of"},{"line_number":63,"context_line":"                 opening memcached to external network can be dangerous."},{"line_number":64,"context_line":"    type: string"},{"line_number":65,"context_line":"  MemcachedTLS:"},{"line_number":66,"context_line":"    default: false"},{"line_number":67,"context_line":"    description: Set to True to enable TLS on Memcached service."},{"line_number":68,"context_line":"    type: boolean"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"3f65232a_e2a9b3df","line":65,"range":{"start_line":65,"start_character":2,"end_line":65,"end_character":14},"updated":"2020-10-23 10:21:25.000000000","message":"Is there a reason not to use the EnableInternalTLS which is used for all other services? (The EnableInternalTLS parameter is set to true when including environments/ssl/enable-internal-tls.yaml)","commit_id":"4ea9de3f0bc9fb3ff55089e468a78fa23501e4b3"},{"author":{"_account_id":24245,"name":"Harald Jensås","email":"hjensas@redhat.com","username":"harald.jensas"},"change_message_id":"91320c8740614a07113ed8b48c4e33444a381013","unresolved":false,"context_lines":[{"line_number":62,"context_line":"                 of the internal network. Use this parameter with caution and be aware of"},{"line_number":63,"context_line":"                 opening memcached to external network can be dangerous."},{"line_number":64,"context_line":"    type: string"},{"line_number":65,"context_line":"  MemcachedTLS:"},{"line_number":66,"context_line":"    default: false"},{"line_number":67,"context_line":"    description: Set to True to enable TLS on Memcached service."},{"line_number":68,"context_line":"    type: boolean"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"3f65232a_1547c71f","line":65,"range":{"start_line":65,"start_character":2,"end_line":65,"end_character":14},"in_reply_to":"3f65232a_42a2279c","updated":"2020-10-23 11:47:42.000000000","message":"Ok, thanks for explaining.","commit_id":"4ea9de3f0bc9fb3ff55089e468a78fa23501e4b3"},{"author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"change_message_id":"706ae50118999136e16df6e1c866e0f7d27d65f3","unresolved":false,"context_lines":[{"line_number":62,"context_line":"                 of the internal network. Use this parameter with caution and be aware of"},{"line_number":63,"context_line":"                 opening memcached to external network can be dangerous."},{"line_number":64,"context_line":"    type: string"},{"line_number":65,"context_line":"  MemcachedTLS:"},{"line_number":66,"context_line":"    default: false"},{"line_number":67,"context_line":"    description: Set to True to enable TLS on Memcached service."},{"line_number":68,"context_line":"    type: boolean"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"3f65232a_42a2279c","line":65,"range":{"start_line":65,"start_character":2,"end_line":65,"end_character":14},"in_reply_to":"3f65232a_e2453319","updated":"2020-10-23 10:59:19.000000000","message":"Moises also pointed out that Memcached doesn\u0027t support TLS on all platforms yet.","commit_id":"4ea9de3f0bc9fb3ff55089e468a78fa23501e4b3"},{"author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"change_message_id":"4234e68ccb74a0363302ff6e5834cc3332448e39","unresolved":false,"context_lines":[{"line_number":62,"context_line":"                 of the internal network. Use this parameter with caution and be aware of"},{"line_number":63,"context_line":"                 opening memcached to external network can be dangerous."},{"line_number":64,"context_line":"    type: string"},{"line_number":65,"context_line":"  MemcachedTLS:"},{"line_number":66,"context_line":"    default: false"},{"line_number":67,"context_line":"    description: Set to True to enable TLS on Memcached service."},{"line_number":68,"context_line":"    type: boolean"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"3f65232a_e2453319","line":65,"range":{"start_line":65,"start_character":2,"end_line":65,"end_character":14},"in_reply_to":"3f65232a_e2a9b3df","updated":"2020-10-23 10:33:53.000000000","message":"Yes, TLS on Memcached may have a performance impact. We didn\u0027t fully evaluate the significance of this, so in the future we might enable MemcachedTLS by default, when EnableInternalTLS is true, but initially we want to keep it separate.","commit_id":"4ea9de3f0bc9fb3ff55089e468a78fa23501e4b3"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"d3c1385f657ebfff1d2c5d04ce05edfb10b00e84","unresolved":false,"context_lines":[{"line_number":66,"context_line":"    default: false"},{"line_number":67,"context_line":"    description: Set to True to enable TLS on Memcached service."},{"line_number":68,"context_line":"    type: boolean"},{"line_number":69,"context_line":"  InternalTLSCAFile:"},{"line_number":70,"context_line":"    default: \u0027/etc/ipa/ca.crt\u0027"},{"line_number":71,"context_line":"    type: string"},{"line_number":72,"context_line":"    description: Specifies the default CA cert to use if TLS is used for"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"9f560f44_47073118","line":69,"range":{"start_line":69,"start_character":2,"end_line":69,"end_character":19},"updated":"2020-10-12 15:02:21.000000000","message":"I\u0027m afraid this parameter is not used in this template file.","commit_id":"4ea9de3f0bc9fb3ff55089e468a78fa23501e4b3"},{"author":{"_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"},"change_message_id":"440e1fa182a8a6555d5be98e75b827b06d1641e5","unresolved":false,"context_lines":[{"line_number":66,"context_line":"    default: false"},{"line_number":67,"context_line":"    description: Set to True to enable TLS on Memcached service."},{"line_number":68,"context_line":"    type: boolean"},{"line_number":69,"context_line":"  InternalTLSCAFile:"},{"line_number":70,"context_line":"    default: \u0027/etc/ipa/ca.crt\u0027"},{"line_number":71,"context_line":"    type: string"},{"line_number":72,"context_line":"    description: Specifies the default CA cert to use if TLS is used for"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"5f681702_c3793530","line":69,"range":{"start_line":69,"start_character":2,"end_line":69,"end_character":19},"in_reply_to":"5f681702_68c63e19","updated":"2020-10-18 15:05:59.000000000","message":"so let me remove this for now","commit_id":"4ea9de3f0bc9fb3ff55089e468a78fa23501e4b3"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"8c666b66582df29fc17459dd99202e1ee62227ae","unresolved":false,"context_lines":[{"line_number":66,"context_line":"    default: false"},{"line_number":67,"context_line":"    description: Set to True to enable TLS on Memcached service."},{"line_number":68,"context_line":"    type: boolean"},{"line_number":69,"context_line":"  InternalTLSCAFile:"},{"line_number":70,"context_line":"    default: \u0027/etc/ipa/ca.crt\u0027"},{"line_number":71,"context_line":"    type: string"},{"line_number":72,"context_line":"    description: Specifies the default CA cert to use if TLS is used for"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"5f681702_68c63e19","line":69,"range":{"start_line":69,"start_character":2,"end_line":69,"end_character":19},"in_reply_to":"7f6b1bfe_8b662c51","updated":"2020-10-18 08:12:48.000000000","message":"Sorry I\u0027ve been busy for this week and didn\u0027t have time to look into this.\n\nIf you need to only expose ca cert file to each containers, you don\u0027t need any changes in this memcached deployment template.\nThere already exists the implementation to add InternalTLSCAFile to basic container mounts, so all containers are supposed to have access to that file when internal tls is enabled.\n\nhttps://github.com/openstack/tripleo-heat-templates/blob/eaecf1bb72a0aed81cf8c60645086234a2afabff/deployment/containers-common.yaml#L145-L152","commit_id":"4ea9de3f0bc9fb3ff55089e468a78fa23501e4b3"},{"author":{"_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"},"change_message_id":"9023b0dbb27bd817bda9465353a2b6de22178ed1","unresolved":false,"context_lines":[{"line_number":66,"context_line":"    default: false"},{"line_number":67,"context_line":"    description: Set to True to enable TLS on Memcached service."},{"line_number":68,"context_line":"    type: boolean"},{"line_number":69,"context_line":"  InternalTLSCAFile:"},{"line_number":70,"context_line":"    default: \u0027/etc/ipa/ca.crt\u0027"},{"line_number":71,"context_line":"    type: string"},{"line_number":72,"context_line":"    description: Specifies the default CA cert to use if TLS is used for"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"7f6b1bfe_8b662c51","line":69,"range":{"start_line":69,"start_character":2,"end_line":69,"end_character":19},"in_reply_to":"9f560f44_47073118","updated":"2020-10-14 15:56:23.000000000","message":"Yeah, this should be passed down to the container. Can you help me find where to put it @Takashi? Greg is on PTO til next Monday.","commit_id":"4ea9de3f0bc9fb3ff55089e468a78fa23501e4b3"}]}
