)]}'
{"deployment/haproxy/haproxy-container-puppet.yaml":[{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"65436516372db7d7526643c68bb9a599ec01e6c9","unresolved":true,"context_lines":[{"line_number":332,"context_line":"          changed_when: puppet_host_outputs.rc \u003d\u003d 2"},{"line_number":333,"context_line":"          failed_when: false"},{"line_number":334,"context_line":"          vars:"},{"line_number":335,"context_line":"            puppet_execute: include tripleo::profile::base::haproxy"},{"line_number":336,"context_line":"            puppet_tags: tripleo::firewall::rule"},{"line_number":337,"context_line":"            puppet_modulepath: /etc/puppet/modules:/opt/stack/puppet-modules:/usr/share/openstack-puppet/modules"},{"line_number":338,"context_line":"            puppet_debug: {get_param: ConfigDebug}"}],"source_content_type":"text/x-yaml","patch_set":8,"id":"8227d1a4_9771bf65","side":"PARENT","line":335,"range":{"start_line":335,"start_character":28,"end_line":335,"end_character":67},"updated":"2021-01-14 14:14:28.000000000","message":"I should have mentioned this, too, but this doesn\u0027t invoke rule management either because it picks the tripleo::firewall::manage_firewall hieradata which is set to false if we use ansible to manage firewall rules...","commit_id":"bf17c1d97fd165c5d65ab29ea9d9a606ac8de6aa"}],"deployment/haproxy/haproxy-pacemaker-puppet.yaml":[{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"030af530b41aae654d3cd27b31e355b71fe488e7","unresolved":true,"context_lines":[{"line_number":270,"context_line":"              changed_when: puppet_host_outputs.rc \u003d\u003d 2"},{"line_number":271,"context_line":"              failed_when: false"},{"line_number":272,"context_line":"              vars:"},{"line_number":273,"context_line":"                puppet_execute: \"if hiera(\u0027enable_load_balancer\u0027, true) { class {\u0027::tripleo::haproxy\u0027: use_internal_certificates \u003d\u003e false, manage_firewall \u003d\u003e hiera(\u0027tripleo::firewall::manage_firewall\u0027, true), }}\""},{"line_number":274,"context_line":"                puppet_tags: tripleo::firewall::rule"},{"line_number":275,"context_line":"                puppet_modulepath: /etc/puppet/modules:/opt/stack/puppet-modules:/usr/share/openstack-puppet/modules"},{"line_number":276,"context_line":"                puppet_debug: {get_param: ConfigDebug}"}],"source_content_type":"text/x-yaml","patch_set":8,"id":"4233069d_677b9c8f","side":"PARENT","line":273,"range":{"start_line":273,"start_character":165,"end_line":273,"end_character":199},"updated":"2021-01-14 14:08:31.000000000","message":"I\u0027m afraid this logic works only with firewall management with puppet, and if we use firewall management by ansible this logic is always ignored, because the template file sets tripleo::firewall::manage_firewall: false .\nWe have already removed[1] the deprecated template to manage firewall rules by puppet but we should revert that or some fix to make this work as well with the composable role for standalone haproxy.\n\n[1] 4f198c32cb7e23b07bb1d722383d81b8ffaf4241","commit_id":"bf17c1d97fd165c5d65ab29ea9d9a606ac8de6aa"}]}
