)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"0340a0e4cf764a84732b248abe43f536d07ca611","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":13,"id":"65806b65_b64d59f7","updated":"2021-10-14 06:20:29.000000000","message":"recheck","commit_id":"9193090b1312a2fb6fe92961a3c0e29840c1b6f6"}],"deployment/glance/glance-api-container-puppet.yaml":[{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"a5b10aa32f7ed81567949e72dd8decb63e2d0e8c","unresolved":true,"context_lines":[{"line_number":344,"context_line":"  use_tls_proxy: {equals : [{get_param: EnableInternalTLS}, true]}"},{"line_number":345,"context_line":"  glance_workers_unset: {equals : [{get_param: GlanceWorkers}, \u0027\u0027]}"},{"line_number":346,"context_line":"  service_debug_unset: {equals : [{get_param: GlanceDebug}, \u0027\u0027]}"},{"line_number":347,"context_line":"  glance_enabled_secure_rbac: {equals : [{get_param: GlanceEnforceSecureRbac}, true]}"},{"line_number":348,"context_line":"  glance_netapp_nfs_enabled: {equals : [{get_param: GlanceNetappNfsEnabled}, true]}"},{"line_number":349,"context_line":"  glance_cache_enabled: {equals : [{get_param: GlanceCacheEnabled}, true]}"},{"line_number":350,"context_line":"  glance_multiple_locations:"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"08810216_d4f945eb","line":347,"updated":"2021-03-29 11:12:37.000000000","message":"there is ongoing effort to omit intrinsic conditions in heat and use get_param within \u0027if\u0027 sections directly. Could you please follow that approach?","commit_id":"b4eee8d023702e8d7588972357666122456b92ec"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"11872e80d4190b5f5a7eab8abb6c36064280e999","unresolved":false,"context_lines":[{"line_number":344,"context_line":"  use_tls_proxy: {equals : [{get_param: EnableInternalTLS}, true]}"},{"line_number":345,"context_line":"  glance_workers_unset: {equals : [{get_param: GlanceWorkers}, \u0027\u0027]}"},{"line_number":346,"context_line":"  service_debug_unset: {equals : [{get_param: GlanceDebug}, \u0027\u0027]}"},{"line_number":347,"context_line":"  glance_enabled_secure_rbac: {equals : [{get_param: GlanceEnforceSecureRbac}, true]}"},{"line_number":348,"context_line":"  glance_netapp_nfs_enabled: {equals : [{get_param: GlanceNetappNfsEnabled}, true]}"},{"line_number":349,"context_line":"  glance_cache_enabled: {equals : [{get_param: GlanceCacheEnabled}, true]}"},{"line_number":350,"context_line":"  glance_multiple_locations:"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"79b22852_3e72b58e","line":347,"in_reply_to":"08810216_d4f945eb","updated":"2021-03-30 09:18:03.000000000","message":"Ack","commit_id":"b4eee8d023702e8d7588972357666122456b92ec"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"a5b10aa32f7ed81567949e72dd8decb63e2d0e8c","unresolved":true,"context_lines":[{"line_number":525,"context_line":"            - {}"},{"line_number":526,"context_line":"            - glance::api::workers: {get_param: GlanceWorkers}"},{"line_number":527,"context_line":"          -"},{"line_number":528,"context_line":"            if:"},{"line_number":529,"context_line":"            - glance_enabled_secure_rbac"},{"line_number":530,"context_line":"            - glance::api::enforce_secure_rbac: {get_param: GlanceEnforceSecureRbac}"},{"line_number":531,"context_line":"              glance::policy::enforce_new_defaults: true"},{"line_number":532,"context_line":"              glance::policy::enforce_scope: true"},{"line_number":533,"context_line":"            - {}"},{"line_number":534,"context_line":"          -"},{"line_number":535,"context_line":"            if:"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"ab7d9420_13604b9b","line":532,"range":{"start_line":528,"start_character":0,"end_line":532,"end_character":49},"updated":"2021-03-29 11:12:37.000000000","message":"so this should be just:\n\n            if:\n            - {get_param: GlanceEnforceSecureRbac} \n            - glance::api::enforce_secure_rbac: true\n              glance::policy::enforce_new_defaults: true\n              glance::policy::enforce_scope: true","commit_id":"b4eee8d023702e8d7588972357666122456b92ec"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"11872e80d4190b5f5a7eab8abb6c36064280e999","unresolved":false,"context_lines":[{"line_number":525,"context_line":"            - {}"},{"line_number":526,"context_line":"            - glance::api::workers: {get_param: GlanceWorkers}"},{"line_number":527,"context_line":"          -"},{"line_number":528,"context_line":"            if:"},{"line_number":529,"context_line":"            - glance_enabled_secure_rbac"},{"line_number":530,"context_line":"            - glance::api::enforce_secure_rbac: {get_param: GlanceEnforceSecureRbac}"},{"line_number":531,"context_line":"              glance::policy::enforce_new_defaults: true"},{"line_number":532,"context_line":"              glance::policy::enforce_scope: true"},{"line_number":533,"context_line":"            - {}"},{"line_number":534,"context_line":"          -"},{"line_number":535,"context_line":"            if:"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"8e76dac8_c58891bc","line":532,"range":{"start_line":528,"start_character":0,"end_line":532,"end_character":49},"in_reply_to":"ab7d9420_13604b9b","updated":"2021-03-30 09:18:03.000000000","message":"Ack","commit_id":"b4eee8d023702e8d7588972357666122456b92ec"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"26ed26e2882c5294cd0c938939f8318d65933057","unresolved":true,"context_lines":[{"line_number":195,"context_line":"    description: \u003e"},{"line_number":196,"context_line":"      When using GlanceBackend \u0027file\u0027 and \u0027rbd\u0027 to enable or not sparse upload."},{"line_number":197,"context_line":"    type: boolean"},{"line_number":198,"context_line":"  GlanceEnforceSecureRbac:"},{"line_number":199,"context_line":"    description: Enable enforcing authorization based on common RBAC personas."},{"line_number":200,"context_line":"    type: boolean"},{"line_number":201,"context_line":"    default: false"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"2c42ea04_76ac318a","line":198,"range":{"start_line":198,"start_character":2,"end_line":198,"end_character":25},"updated":"2021-04-21 15:51:05.000000000","message":"This would be a general question but do we really expect the use case to enable SecureRBAC for only specific services ? If it is what we should enable for all services at once then I think having more general option(EnforceSecureRbac) and use it widely sounds better.","commit_id":"7d213ce82f2cac9edcd7f5ccc4be635034738bf9"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"65b2b652d3887329e01d40987860e0993cba50c5","unresolved":true,"context_lines":[{"line_number":195,"context_line":"    description: \u003e"},{"line_number":196,"context_line":"      When using GlanceBackend \u0027file\u0027 and \u0027rbd\u0027 to enable or not sparse upload."},{"line_number":197,"context_line":"    type: boolean"},{"line_number":198,"context_line":"  GlanceEnforceSecureRbac:"},{"line_number":199,"context_line":"    description: Enable enforcing authorization based on common RBAC personas."},{"line_number":200,"context_line":"    type: boolean"},{"line_number":201,"context_line":"    default: false"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"f8cf163a_754ffd0b","line":198,"range":{"start_line":198,"start_character":2,"end_line":198,"end_character":25},"in_reply_to":"29699bf8_f0b7ad21","updated":"2021-04-23 08:34:57.000000000","message":"Or this could be done similarly to the global debug control setting and it\u0027s case-by-case specific debug options.","commit_id":"7d213ce82f2cac9edcd7f5ccc4be635034738bf9"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"47f807195add90ad240cbe576cfedeff364ef4c6","unresolved":true,"context_lines":[{"line_number":195,"context_line":"    description: \u003e"},{"line_number":196,"context_line":"      When using GlanceBackend \u0027file\u0027 and \u0027rbd\u0027 to enable or not sparse upload."},{"line_number":197,"context_line":"    type: boolean"},{"line_number":198,"context_line":"  GlanceEnforceSecureRbac:"},{"line_number":199,"context_line":"    description: Enable enforcing authorization based on common RBAC personas."},{"line_number":200,"context_line":"    type: boolean"},{"line_number":201,"context_line":"    default: false"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"29699bf8_f0b7ad21","line":198,"range":{"start_line":198,"start_character":2,"end_line":198,"end_character":25},"in_reply_to":"2c42ea04_76ac318a","updated":"2021-04-21 18:57:41.000000000","message":"Support for secure RBAC may vary across services and I think making operator configure each service just so will be painful.\n\nI\u0027m trying to abstract most of that into a single template that people can use [0].\n\nIdeally, once the old deprecated policies go away, this option will always be true. I\u0027m not sure if we want to, or should add, a configuration option that we expect to disappear because it\u0027s the default behavior?\n\n[0] https://review.opendev.org/c/openstack/tripleo-heat-templates/+/781571","commit_id":"7d213ce82f2cac9edcd7f5ccc4be635034738bf9"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"d87213740d3c90beb22aebc32af2c10a8df77c8c","unresolved":true,"context_lines":[{"line_number":195,"context_line":"    description: \u003e"},{"line_number":196,"context_line":"      When using GlanceBackend \u0027file\u0027 and \u0027rbd\u0027 to enable or not sparse upload."},{"line_number":197,"context_line":"    type: boolean"},{"line_number":198,"context_line":"  GlanceEnforceSecureRbac:"},{"line_number":199,"context_line":"    description: Enable enforcing authorization based on common RBAC personas."},{"line_number":200,"context_line":"    type: boolean"},{"line_number":201,"context_line":"    default: false"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"c5cb990d_b82903b1","line":198,"range":{"start_line":198,"start_character":2,"end_line":198,"end_character":25},"in_reply_to":"35508e8b_3d869816","updated":"2021-06-01 23:16:57.000000000","message":"EnableSecureRbac sounds better because \"enforce_secure_rbac\" parameter is specific to glance.\n(Following format of the other parameters, Rbac would be better than RBAC)","commit_id":"7d213ce82f2cac9edcd7f5ccc4be635034738bf9"},{"author":{"_account_id":6796,"name":"Giulio Fidente","email":"gfidente@redhat.com","username":"gfidente"},"change_message_id":"7d86be3e69eb589164e2a6242c722ff87a072719","unresolved":true,"context_lines":[{"line_number":195,"context_line":"    description: \u003e"},{"line_number":196,"context_line":"      When using GlanceBackend \u0027file\u0027 and \u0027rbd\u0027 to enable or not sparse upload."},{"line_number":197,"context_line":"    type: boolean"},{"line_number":198,"context_line":"  GlanceEnforceSecureRbac:"},{"line_number":199,"context_line":"    description: Enable enforcing authorization based on common RBAC personas."},{"line_number":200,"context_line":"    type: boolean"},{"line_number":201,"context_line":"    default: false"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"35508e8b_3d869816","line":198,"range":{"start_line":198,"start_character":2,"end_line":198,"end_character":25},"in_reply_to":"f8cf163a_754ffd0b","updated":"2021-05-31 16:46:56.000000000","message":"+1 on using a single parameter for all components; not sure if you guys have thought about a name for it.\n\nWhat about: EnableSecureRBAC ?","commit_id":"7d213ce82f2cac9edcd7f5ccc4be635034738bf9"},{"author":{"_account_id":21129,"name":"Alan Bishop","email":"abishopsweng@gmail.com","username":"ASBishop","status":"ex Red Hat"},"change_message_id":"335cd61fbd82b0e417dfa8f3c26a1dc84ed98362","unresolved":true,"context_lines":[{"line_number":529,"context_line":"            - glance::api::enforce_secure_rbac: true"},{"line_number":530,"context_line":"              glance::policy::enforce_new_defaults: true"},{"line_number":531,"context_line":"              glance::policy::enforce_scope: true"},{"line_number":532,"context_line":"            - {}"},{"line_number":533,"context_line":"          -"},{"line_number":534,"context_line":"            if:"},{"line_number":535,"context_line":"            - cinder_backend_enabled"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"d87577e8_47d2719a","line":532,"updated":"2021-04-01 17:46:11.000000000","message":"https://review.opendev.org/c/openstack/tripleo-heat-templates/+/782978 is about to merge. It will change heat_template_version (L1) to wallaby, and the one of the motivations is it would eliminate the need for L532.","commit_id":"7d213ce82f2cac9edcd7f5ccc4be635034738bf9"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"d87213740d3c90beb22aebc32af2c10a8df77c8c","unresolved":true,"context_lines":[{"line_number":529,"context_line":"            - glance::api::enforce_secure_rbac: true"},{"line_number":530,"context_line":"              glance::policy::enforce_new_defaults: true"},{"line_number":531,"context_line":"              glance::policy::enforce_scope: true"},{"line_number":532,"context_line":"            - {}"},{"line_number":533,"context_line":"          -"},{"line_number":534,"context_line":"            if:"},{"line_number":535,"context_line":"            - cinder_backend_enabled"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"b26b2819_34d9ae4c","line":532,"in_reply_to":"2a38beff_f6aeb18d","updated":"2021-06-01 23:16:57.000000000","message":"I gave another thought on this and I now think it\u0027s better to keep current implementation. This helps users make easy transition when each services enable secure rbac by default.","commit_id":"7d213ce82f2cac9edcd7f5ccc4be635034738bf9"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"26ed26e2882c5294cd0c938939f8318d65933057","unresolved":true,"context_lines":[{"line_number":529,"context_line":"            - glance::api::enforce_secure_rbac: true"},{"line_number":530,"context_line":"              glance::policy::enforce_new_defaults: true"},{"line_number":531,"context_line":"              glance::policy::enforce_scope: true"},{"line_number":532,"context_line":"            - {}"},{"line_number":533,"context_line":"          -"},{"line_number":534,"context_line":"            if:"},{"line_number":535,"context_line":"            - cinder_backend_enabled"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"2a38beff_f6aeb18d","line":532,"in_reply_to":"d87577e8_47d2719a","updated":"2021-04-21 15:51:05.000000000","message":"If there is any plan to change the current default in service side then I\u0027d prefer setting false explicitly to avoid inconsistency between tripleo parameters and service parameters.","commit_id":"7d213ce82f2cac9edcd7f5ccc4be635034738bf9"},{"author":{"_account_id":21129,"name":"Alan Bishop","email":"abishopsweng@gmail.com","username":"ASBishop","status":"ex Red Hat"},"change_message_id":"cf22fd378040d0bd76229cf29ef5ff94aa73f21d","unresolved":true,"context_lines":[{"line_number":193,"context_line":"    description: \u003e"},{"line_number":194,"context_line":"      When using GlanceBackend \u0027file\u0027 and \u0027rbd\u0027 to enable or not sparse upload."},{"line_number":195,"context_line":"    type: boolean"},{"line_number":196,"context_line":"  EnableSecureRbac:"},{"line_number":197,"context_line":"    description: Enable enforcing authorization based on common RBAC personas."},{"line_number":198,"context_line":"    type: boolean"},{"line_number":199,"context_line":"    default: false"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"df40d1db_f85d32a5","line":196,"updated":"2021-07-12 14:44:51.000000000","message":"Because this is global parameter that will eventually be referenced by a number of templates, now is the time to ask if \"EnableSecureRBAC\" would look better. What do others think?","commit_id":"73b6acb33c823bc9eb0fa7e949f3884e5c138c47"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"8e2934b9b08821a8baac5bbe81162f0d2c5d1f3c","unresolved":true,"context_lines":[{"line_number":193,"context_line":"    description: \u003e"},{"line_number":194,"context_line":"      When using GlanceBackend \u0027file\u0027 and \u0027rbd\u0027 to enable or not sparse upload."},{"line_number":195,"context_line":"    type: boolean"},{"line_number":196,"context_line":"  EnableSecureRbac:"},{"line_number":197,"context_line":"    description: Enable enforcing authorization based on common RBAC personas."},{"line_number":198,"context_line":"    type: boolean"},{"line_number":199,"context_line":"    default: false"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"c87a102b_bde87ce5","line":196,"in_reply_to":"22e5232f_b41df3d5","updated":"2021-07-13 08:21:43.000000000","message":"Sorry ignore the last sentence. Glance has enforce_secure_rbac, not enable_secure_rbac...","commit_id":"73b6acb33c823bc9eb0fa7e949f3884e5c138c47"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"6bc193b0d25384840710ea79789b478ce0895836","unresolved":true,"context_lines":[{"line_number":193,"context_line":"    description: \u003e"},{"line_number":194,"context_line":"      When using GlanceBackend \u0027file\u0027 and \u0027rbd\u0027 to enable or not sparse upload."},{"line_number":195,"context_line":"    type: boolean"},{"line_number":196,"context_line":"  EnableSecureRbac:"},{"line_number":197,"context_line":"    description: Enable enforcing authorization based on common RBAC personas."},{"line_number":198,"context_line":"    type: boolean"},{"line_number":199,"context_line":"    default: false"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"22e5232f_b41df3d5","line":196,"in_reply_to":"579deaa1_daddb5f6","updated":"2021-07-13 08:19:19.000000000","message":"OK. Now I have better understanding about the situation after checking what Rabi mentioned.\n\n\"Enable\" is confusing and inaccurate here because secure rbac is enabled in some services, and renaming this to EnforceSecureRbac would explain what this does more clearly.\n\nIt is still an option to implement GlanceEnableSecureRbac because glance has own toggle to enable secure rbrac but it might not be very useful because users are less likely to enable secure RBAC with deprecated old policies.","commit_id":"73b6acb33c823bc9eb0fa7e949f3884e5c138c47"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"69d21aee0c889e553d5ecca31959b1babfccedcb","unresolved":true,"context_lines":[{"line_number":193,"context_line":"    description: \u003e"},{"line_number":194,"context_line":"      When using GlanceBackend \u0027file\u0027 and \u0027rbd\u0027 to enable or not sparse upload."},{"line_number":195,"context_line":"    type: boolean"},{"line_number":196,"context_line":"  EnableSecureRbac:"},{"line_number":197,"context_line":"    description: Enable enforcing authorization based on common RBAC personas."},{"line_number":198,"context_line":"    type: boolean"},{"line_number":199,"context_line":"    default: false"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"8998899f_caa345dc","line":196,"in_reply_to":"c87a102b_bde87ce5","updated":"2021-07-20 14:10:27.000000000","message":"Yes, I still feel it should be GlanceEnforceSecureRbac like earlier to be consistent with existing naming and it looks quite self explanatory that it\u0027s being enforced for glance only.","commit_id":"73b6acb33c823bc9eb0fa7e949f3884e5c138c47"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"aa3b01603f39f772e5b45cb90f741ff61a41217f","unresolved":true,"context_lines":[{"line_number":193,"context_line":"    description: \u003e"},{"line_number":194,"context_line":"      When using GlanceBackend \u0027file\u0027 and \u0027rbd\u0027 to enable or not sparse upload."},{"line_number":195,"context_line":"    type: boolean"},{"line_number":196,"context_line":"  EnableSecureRbac:"},{"line_number":197,"context_line":"    description: Enable enforcing authorization based on common RBAC personas."},{"line_number":198,"context_line":"    type: boolean"},{"line_number":199,"context_line":"    default: false"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"579deaa1_daddb5f6","line":196,"in_reply_to":"df40d1db_f85d32a5","updated":"2021-07-12 14:56:15.000000000","message":"I think Rbac is better than RBAC to be consistent with existing naming.","commit_id":"73b6acb33c823bc9eb0fa7e949f3884e5c138c47"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"aa3b01603f39f772e5b45cb90f741ff61a41217f","unresolved":true,"context_lines":[{"line_number":194,"context_line":"      When using GlanceBackend \u0027file\u0027 and \u0027rbd\u0027 to enable or not sparse upload."},{"line_number":195,"context_line":"    type: boolean"},{"line_number":196,"context_line":"  EnableSecureRbac:"},{"line_number":197,"context_line":"    description: Enable enforcing authorization based on common RBAC personas."},{"line_number":198,"context_line":"    type: boolean"},{"line_number":199,"context_line":"    default: false"},{"line_number":200,"context_line":"  KeystoneRegion:"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"d012e878_1fc37593","line":197,"range":{"start_line":197,"start_character":4,"end_line":197,"end_character":78},"updated":"2021-07-12 14:56:15.000000000","message":"Does it make sense to explain that this parameter is currently used by only Glance at this moment ? Description should be updated when we extend support.","commit_id":"73b6acb33c823bc9eb0fa7e949f3884e5c138c47"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"69d21aee0c889e553d5ecca31959b1babfccedcb","unresolved":false,"context_lines":[{"line_number":194,"context_line":"      When using GlanceBackend \u0027file\u0027 and \u0027rbd\u0027 to enable or not sparse upload."},{"line_number":195,"context_line":"    type: boolean"},{"line_number":196,"context_line":"  EnableSecureRbac:"},{"line_number":197,"context_line":"    description: Enable enforcing authorization based on common RBAC personas."},{"line_number":198,"context_line":"    type: boolean"},{"line_number":199,"context_line":"    default: false"},{"line_number":200,"context_line":"  KeystoneRegion:"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"656d8dac_b364ed91","line":197,"range":{"start_line":197,"start_character":4,"end_line":197,"end_character":78},"in_reply_to":"d012e878_1fc37593","updated":"2021-07-20 14:10:27.000000000","message":"Ack","commit_id":"73b6acb33c823bc9eb0fa7e949f3884e5c138c47"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"759f3268f335ce9d5a8b82942674d9d612eaada0","unresolved":true,"context_lines":[{"line_number":193,"context_line":"    description: \u003e"},{"line_number":194,"context_line":"      When using GlanceBackend \u0027file\u0027 and \u0027rbd\u0027 to enable or not sparse upload."},{"line_number":195,"context_line":"    type: boolean"},{"line_number":196,"context_line":"  GlanceEnforceSecureRbac:"},{"line_number":197,"context_line":"    description: \u003e"},{"line_number":198,"context_line":"      Enforcing authorization based on common RBAC personas only for Glance APIs."},{"line_number":199,"context_line":"    type: boolean"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"dba6e9e8_7c3d5ae0","line":196,"updated":"2021-08-27 21:03:58.000000000","message":"Based on the conversation in another change [0], I added a separate global option for this [1]. I also updated a separate change using the global that you can use for an example [2].\n\n[0] https://review.opendev.org/c/openstack/tripleo-heat-templates/+/781571/14\n[1] https://review.opendev.org/c/openstack/tripleo-heat-templates/+/806449/1\n[2] https://review.opendev.org/c/openstack/tripleo-heat-templates/+/804277","commit_id":"871d7ea936a53de795649b47f190b117c536ea86"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"d78b3ba3a2ea96e079025788a49d43e9e6f3345c","unresolved":true,"context_lines":[{"line_number":193,"context_line":"    description: \u003e"},{"line_number":194,"context_line":"      When using GlanceBackend \u0027file\u0027 and \u0027rbd\u0027 to enable or not sparse upload."},{"line_number":195,"context_line":"    type: boolean"},{"line_number":196,"context_line":"  GlanceEnforceSecureRbac:"},{"line_number":197,"context_line":"    description: \u003e"},{"line_number":198,"context_line":"      Enforcing authorization based on common RBAC personas only for Glance APIs."},{"line_number":199,"context_line":"    type: boolean"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"64926643_804118a1","line":196,"in_reply_to":"dba6e9e8_7c3d5ae0","updated":"2021-08-31 09:07:51.000000000","message":"Thanks for adding global option, I will update this patch accordingly.","commit_id":"871d7ea936a53de795649b47f190b117c536ea86"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"487ffae6897db0cf9aed477189c75ccdd64abc84","unresolved":true,"context_lines":[{"line_number":583,"context_line":"            - {get_param: GlanceEnforceSecureRbac}"},{"line_number":584,"context_line":"            - glance::api::enforce_secure_rbac: true"},{"line_number":585,"context_line":"              glance::policy::enforce_new_defaults: true"},{"line_number":586,"context_line":"              glance::policy::enforce_scope: true"},{"line_number":587,"context_line":"          - if:"},{"line_number":588,"context_line":"            - cinder_backend_enabled"},{"line_number":589,"context_line":"            - glance::backend::cinder::cinder_store_auth_address: {get_param: [EndpointMap, KeystoneV3Internal, uri]}"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"ad52be27_76b9f276","line":586,"range":{"start_line":586,"start_character":14,"end_line":586,"end_character":49},"updated":"2021-08-03 22:18:00.000000000","message":"I wonder if we want to enable this right now since glance doesn\u0027t support system-scope at all?\n\nI think the glance team is working on refactors to make support system scope easier.","commit_id":"871d7ea936a53de795649b47f190b117c536ea86"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"fe33679dd795265e8607a3670155e3b16d6fed97","unresolved":true,"context_lines":[{"line_number":583,"context_line":"            - {get_param: GlanceEnforceSecureRbac}"},{"line_number":584,"context_line":"            - glance::api::enforce_secure_rbac: true"},{"line_number":585,"context_line":"              glance::policy::enforce_new_defaults: true"},{"line_number":586,"context_line":"              glance::policy::enforce_scope: true"},{"line_number":587,"context_line":"          - if:"},{"line_number":588,"context_line":"            - cinder_backend_enabled"},{"line_number":589,"context_line":"            - glance::backend::cinder::cinder_store_auth_address: {get_param: [EndpointMap, KeystoneV3Internal, uri]}"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"b38a1b24_f2a24a75","line":586,"range":{"start_line":586,"start_character":14,"end_line":586,"end_character":49},"in_reply_to":"24548911_aee298ae","updated":"2021-09-07 08:15:53.000000000","message":"yeah, right. makes sense.","commit_id":"871d7ea936a53de795649b47f190b117c536ea86"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"28f20e8cded20df0a0453379a79a4a98721b575a","unresolved":true,"context_lines":[{"line_number":583,"context_line":"            - {get_param: GlanceEnforceSecureRbac}"},{"line_number":584,"context_line":"            - glance::api::enforce_secure_rbac: true"},{"line_number":585,"context_line":"              glance::policy::enforce_new_defaults: true"},{"line_number":586,"context_line":"              glance::policy::enforce_scope: true"},{"line_number":587,"context_line":"          - if:"},{"line_number":588,"context_line":"            - cinder_backend_enabled"},{"line_number":589,"context_line":"            - glance::backend::cinder::cinder_store_auth_address: {get_param: [EndpointMap, KeystoneV3Internal, uri]}"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"24548911_aee298ae","line":586,"range":{"start_line":586,"start_character":14,"end_line":586,"end_character":49},"in_reply_to":"3b7b7e23_88c9ded2","updated":"2021-08-31 15:10:17.000000000","message":"Someone could set enforce_secure_rbac \u003d True and enforce_new_defaults \u003d True using Xena and get all the project personas in glance, which could be useful, right?","commit_id":"871d7ea936a53de795649b47f190b117c536ea86"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"c3f743211818b61f73d22f6c6ca56066f01b180f","unresolved":true,"context_lines":[{"line_number":583,"context_line":"            - {get_param: GlanceEnforceSecureRbac}"},{"line_number":584,"context_line":"            - glance::api::enforce_secure_rbac: true"},{"line_number":585,"context_line":"              glance::policy::enforce_new_defaults: true"},{"line_number":586,"context_line":"              glance::policy::enforce_scope: true"},{"line_number":587,"context_line":"          - if:"},{"line_number":588,"context_line":"            - cinder_backend_enabled"},{"line_number":589,"context_line":"            - glance::backend::cinder::cinder_store_auth_address: {get_param: [EndpointMap, KeystoneV3Internal, uri]}"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"3b7b7e23_88c9ded2","line":586,"range":{"start_line":586,"start_character":14,"end_line":586,"end_character":49},"in_reply_to":"ad52be27_76b9f276","updated":"2021-08-31 09:03:08.000000000","message":"yeah, right.. this won\u0027t be needed after system scope implementation but at this moment we are not sure when system scope would be implemented and this is toggle to disable rbac so we might keep it there for some more time.","commit_id":"871d7ea936a53de795649b47f190b117c536ea86"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"088ada87f904f34de00608ac1288963fd671dadb","unresolved":true,"context_lines":[{"line_number":193,"context_line":"    description: \u003e"},{"line_number":194,"context_line":"      When using GlanceBackend \u0027file\u0027 and \u0027rbd\u0027 to enable or not sparse upload."},{"line_number":195,"context_line":"    type: boolean"},{"line_number":196,"context_line":"  EnforceSecureRbac:"},{"line_number":197,"context_line":"    description: \u003e"},{"line_number":198,"context_line":"      Enforcing authorization based on common RBAC personas only for Glance APIs."},{"line_number":199,"context_line":"    type: boolean"}],"source_content_type":"text/x-yaml","patch_set":9,"id":"9828359f_c6975593","line":196,"updated":"2021-09-07 21:20:32.000000000","message":"I\u0027ve added a global option for this that we can re-use across services. What you have below shouldn\u0027t need to change, but you won\u0027t need lines 196 - 200 I don\u0027t think.\n\nhttps://review.opendev.org/c/openstack/tripleo-heat-templates/+/806449/3/deployment/keystone/keystone-container-puppet.yaml","commit_id":"f9671159ad76ef81e87b8ce1e0e998760606c439"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"f4ed58489815f41da120a627b323adf8393933f1","unresolved":true,"context_lines":[{"line_number":193,"context_line":"    description: \u003e"},{"line_number":194,"context_line":"      When using GlanceBackend \u0027file\u0027 and \u0027rbd\u0027 to enable or not sparse upload."},{"line_number":195,"context_line":"    type: boolean"},{"line_number":196,"context_line":"  EnforceSecureRbac:"},{"line_number":197,"context_line":"    description: \u003e"},{"line_number":198,"context_line":"      Enforcing authorization based on common RBAC personas only for Glance APIs."},{"line_number":199,"context_line":"    type: boolean"}],"source_content_type":"text/x-yaml","patch_set":9,"id":"ff0fc37c_2fa9a0a3","line":196,"in_reply_to":"9828359f_c6975593","updated":"2021-09-13 10:46:02.000000000","message":"\u0027EnforceSecureRbac\u0027 need to be defined in this template because this template is not inheriting any settings from keystone service and even after enabling the EnforceSecureRbac from [1], glance api service will not consume parameter enabled via parameter_defaults.\n\n1]: https://review.opendev.org/c/openstack/tripleo-heat-templates/+/781571/14/environments/enable-secure-rbac.yaml#42","commit_id":"f9671159ad76ef81e87b8ce1e0e998760606c439"},{"author":{"_account_id":21129,"name":"Alan Bishop","email":"abishopsweng@gmail.com","username":"ASBishop","status":"ex Red Hat"},"change_message_id":"f416b7fff058278139c5f650c5dfff1fe4ca6fb6","unresolved":true,"context_lines":[{"line_number":193,"context_line":"    description: \u003e"},{"line_number":194,"context_line":"      When using GlanceBackend \u0027file\u0027 and \u0027rbd\u0027 to enable or not sparse upload."},{"line_number":195,"context_line":"    type: boolean"},{"line_number":196,"context_line":"  EnforceSecureRbac:"},{"line_number":197,"context_line":"    description: \u003e"},{"line_number":198,"context_line":"      Enforcing authorization based on common RBAC personas only for Glance APIs."},{"line_number":199,"context_line":"    type: boolean"}],"source_content_type":"text/x-yaml","patch_set":11,"id":"1d9f0bd9_a50192c9","line":196,"updated":"2021-10-06 15:33:42.000000000","message":"Keystone already defines this parameter, and so you\u0027ll need to declare it the exact same way in order to avoid the pep8 failure. See [1]\n\n[1] https://opendev.org/openstack/tripleo-heat-templates/src/branch/master/deployment/keystone/keystone-container-puppet.yaml#L394","commit_id":"d644d408b274dbea047f4c0faa84c30e25e9977c"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"f665160312912bef2990584174eca6cd15276f53","unresolved":true,"context_lines":[{"line_number":193,"context_line":"    description: \u003e"},{"line_number":194,"context_line":"      When using GlanceBackend \u0027file\u0027 and \u0027rbd\u0027 to enable or not sparse upload."},{"line_number":195,"context_line":"    type: boolean"},{"line_number":196,"context_line":"  EnforceSecureRbac:"},{"line_number":197,"context_line":"    description: \u003e"},{"line_number":198,"context_line":"      Enforcing authorization based on common RBAC personas only for Glance APIs."},{"line_number":199,"context_line":"    type: boolean"}],"source_content_type":"text/x-yaml","patch_set":11,"id":"e2a89b2a_1bcae377","line":196,"in_reply_to":"1d9f0bd9_a50192c9","updated":"2021-10-07 05:28:36.000000000","message":"ohh yes, seems this keystone patch recently got merged. I will update the parameter accordingly.","commit_id":"d644d408b274dbea047f4c0faa84c30e25e9977c"}],"releasenotes/notes/add_enforce_secure_rbac_for_rbac_support-2e00c2d8bb715321.yaml":[{"author":{"_account_id":21129,"name":"Alan Bishop","email":"abishopsweng@gmail.com","username":"ASBishop","status":"ex Red Hat"},"change_message_id":"335cd61fbd82b0e417dfa8f3c26a1dc84ed98362","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"features:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    The new parameter \u0027GlanceEnforceSecureRbac\u0027 has been added to enable"},{"line_number":5,"context_line":"    enforcing authorization based on common RBAC personas."}],"source_content_type":"text/x-yaml","patch_set":3,"id":"5e8501ca_1db88ce8","line":4,"updated":"2021-04-01 17:46:11.000000000","message":"1. Use double back-tics to quote, so ``GlanceEnforceSecureRbac``\n\n2. Mention it defaults to False (secure RBAC is experimental)\n\n3. I\u0027d like the release note file name to mention \"glance\" somewhere. Because it doesn\u0027t, the file name could be construed to suggest secure RBAC is supported in all of TripleO.","commit_id":"7d213ce82f2cac9edcd7f5ccc4be635034738bf9"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"d66d215291576758b0637ef4b235ef6aaaed2b35","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"features:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    The new parameter \u0027GlanceEnforceSecureRbac\u0027 has been added to enable"},{"line_number":5,"context_line":"    enforcing authorization based on common RBAC personas."}],"source_content_type":"text/x-yaml","patch_set":3,"id":"019b6051_e7cda8e8","line":4,"in_reply_to":"5e8501ca_1db88ce8","updated":"2021-04-05 18:35:18.000000000","message":"\u003e 1. Use double back-tics to quote, so ``GlanceEnforceSecureRbac``\n\u003e \n\u003e 2. Mention it defaults to False (secure RBAC is experimental)\n\u003e \n\u003e 3. I\u0027d like the release note file name to mention \"glance\" somewhere. Because it doesn\u0027t, the file name could be construed to suggest secure RBAC is supported in all of TripleO.\n\nIdeally, it would be awesome to have support across the board, but we\u0027re still working on it [0].\n\n[0] https://review.opendev.org/c/openstack/tripleo-heat-templates/+/781571","commit_id":"7d213ce82f2cac9edcd7f5ccc4be635034738bf9"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"976cea6655dff8eb1952d2ed80e8bc2535839149","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":4,"id":"d3b7ce78_a89e01d9","updated":"2021-06-16 13:23:44.000000000","message":"Please rename file name to reflect the change in parameter name.","commit_id":"d7b2d4a11f2042960615b9a54b709fb2b8fb2949"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"976cea6655dff8eb1952d2ed80e8bc2535839149","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"features:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    The new parameter \u0027GlanceEnforceSecureRbac\u0027 has been added to enable"},{"line_number":5,"context_line":"    enforcing authorization based on common RBAC personas."}],"source_content_type":"text/x-yaml","patch_set":4,"id":"bda6b117_be41b5da","line":4,"range":{"start_line":4,"start_character":23,"end_line":4,"end_character":46},"updated":"2021-06-16 13:23:44.000000000","message":"This should be updated as well.","commit_id":"d7b2d4a11f2042960615b9a54b709fb2b8fb2949"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"976cea6655dff8eb1952d2ed80e8bc2535839149","unresolved":true,"context_lines":[{"line_number":2,"context_line":"features:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    The new parameter \u0027GlanceEnforceSecureRbac\u0027 has been added to enable"},{"line_number":5,"context_line":"    enforcing authorization based on common RBAC personas."}],"source_content_type":"text/x-yaml","patch_set":4,"id":"30824b6d_f398be4b","line":5,"range":{"start_line":5,"start_character":57,"end_line":5,"end_character":58},"updated":"2021-06-16 13:23:44.000000000","message":"It would be useful if you can add a note that this parameter currently works only for Glance.","commit_id":"d7b2d4a11f2042960615b9a54b709fb2b8fb2949"}],"releasenotes/notes/enable_secure_rbac_support_for_glance-167d53c491cd326c.yaml":[{"author":{"_account_id":21129,"name":"Alan Bishop","email":"abishopsweng@gmail.com","username":"ASBishop","status":"ex Red Hat"},"change_message_id":"cf22fd378040d0bd76229cf29ef5ff94aa73f21d","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"features:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    The new parameter \u0027EnableSecureRbac\u0027 has been added to enable"},{"line_number":5,"context_line":"    enforcing authorization based on common RBAC personas."},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"    This parameter enables secure RBAC for glance only."}],"source_content_type":"text/x-yaml","patch_set":5,"id":"c25e6873_7a5a78e5","line":4,"updated":"2021-07-12 14:44:51.000000000","message":"nit: use double backticks to quote something (``EnableSecureRbac``)","commit_id":"73b6acb33c823bc9eb0fa7e949f3884e5c138c47"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"69d21aee0c889e553d5ecca31959b1babfccedcb","unresolved":false,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"features:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    The new parameter \u0027EnableSecureRbac\u0027 has been added to enable"},{"line_number":5,"context_line":"    enforcing authorization based on common RBAC personas."},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"    This parameter enables secure RBAC for glance only."}],"source_content_type":"text/x-yaml","patch_set":5,"id":"cb9a6969_d8501931","line":4,"in_reply_to":"c2282e4f_8fc40edb","updated":"2021-07-20 14:10:27.000000000","message":"Done","commit_id":"73b6acb33c823bc9eb0fa7e949f3884e5c138c47"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"aa3b01603f39f772e5b45cb90f741ff61a41217f","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"features:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    The new parameter \u0027EnableSecureRbac\u0027 has been added to enable"},{"line_number":5,"context_line":"    enforcing authorization based on common RBAC personas."},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"    This parameter enables secure RBAC for glance only."}],"source_content_type":"text/x-yaml","patch_set":5,"id":"c2282e4f_8fc40edb","line":4,"in_reply_to":"c25e6873_7a5a78e5","updated":"2021-07-12 14:56:15.000000000","message":"+1","commit_id":"73b6acb33c823bc9eb0fa7e949f3884e5c138c47"},{"author":{"_account_id":21129,"name":"Alan Bishop","email":"abishopsweng@gmail.com","username":"ASBishop","status":"ex Red Hat"},"change_message_id":"cf22fd378040d0bd76229cf29ef5ff94aa73f21d","unresolved":true,"context_lines":[{"line_number":4,"context_line":"    The new parameter \u0027EnableSecureRbac\u0027 has been added to enable"},{"line_number":5,"context_line":"    enforcing authorization based on common RBAC personas."},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"    This parameter enables secure RBAC for glance only."}],"source_content_type":"text/x-yaml","patch_set":5,"id":"85cb5c90_97e301af","line":7,"updated":"2021-07-12 14:44:51.000000000","message":"This patch introduces a new parameter that will eventually be used by all TripleO services affected by secure RBAC. While I realize this first patch only affects glance, this sentence seems to imply the parameter will be used only by glance.\n\nI don\u0027t know if I\u0027m being too picky, and would like to hear other opinions.","commit_id":"73b6acb33c823bc9eb0fa7e949f3884e5c138c47"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"69d21aee0c889e553d5ecca31959b1babfccedcb","unresolved":false,"context_lines":[{"line_number":4,"context_line":"    The new parameter \u0027EnableSecureRbac\u0027 has been added to enable"},{"line_number":5,"context_line":"    enforcing authorization based on common RBAC personas."},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"    This parameter enables secure RBAC for glance only."}],"source_content_type":"text/x-yaml","patch_set":5,"id":"1c836328_aa80d7d4","line":7,"in_reply_to":"41c599fa_50dfa3c3","updated":"2021-07-20 14:10:27.000000000","message":"Done","commit_id":"73b6acb33c823bc9eb0fa7e949f3884e5c138c47"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"aa3b01603f39f772e5b45cb90f741ff61a41217f","unresolved":true,"context_lines":[{"line_number":4,"context_line":"    The new parameter \u0027EnableSecureRbac\u0027 has been added to enable"},{"line_number":5,"context_line":"    enforcing authorization based on common RBAC personas."},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"    This parameter enables secure RBAC for glance only."}],"source_content_type":"text/x-yaml","patch_set":5,"id":"41c599fa_50dfa3c3","line":7,"in_reply_to":"85cb5c90_97e301af","updated":"2021-07-12 14:56:15.000000000","message":"I think it\u0027s better to explain current plan to extend this parameter to the other serivce like.\n\nThis parameter is currently used by Glance only, but support for the other services will be introduced later.","commit_id":"73b6acb33c823bc9eb0fa7e949f3884e5c138c47"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"088ada87f904f34de00608ac1288963fd671dadb","unresolved":true,"context_lines":[{"line_number":5,"context_line":"    enforce authorization based on common RBAC personas."},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"    This parameter is currently used by Glance only, but support"},{"line_number":8,"context_line":"    for the other services will be introduced later."}],"source_content_type":"text/x-yaml","patch_set":9,"id":"73ec2a7c_6aef8935","line":8,"updated":"2021-09-07 21:20:32.000000000","message":"This will need to be updated to reference the global parameter instead of the glance-specific one.","commit_id":"f9671159ad76ef81e87b8ce1e0e998760606c439"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"f4ed58489815f41da120a627b323adf8393933f1","unresolved":false,"context_lines":[{"line_number":5,"context_line":"    enforce authorization based on common RBAC personas."},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"    This parameter is currently used by Glance only, but support"},{"line_number":8,"context_line":"    for the other services will be introduced later."}],"source_content_type":"text/x-yaml","patch_set":9,"id":"e37922e5_632766bc","line":8,"in_reply_to":"73ec2a7c_6aef8935","updated":"2021-09-13 10:46:02.000000000","message":"Ack","commit_id":"f9671159ad76ef81e87b8ce1e0e998760606c439"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"3ad419a31fe3bc1ef1c8c6d0cc1fe12e2ae39d42","unresolved":true,"context_lines":[{"line_number":2,"context_line":"features:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    The new parameter ``EnforceSecureRbac`` has been added to"},{"line_number":5,"context_line":"    enforce authorization based on common RBAC personas."}],"source_content_type":"text/x-yaml","patch_set":10,"id":"56b0978f_3733e207","line":5,"range":{"start_line":5,"start_character":35,"end_line":5,"end_character":55},"updated":"2021-09-15 20:23:03.000000000","message":"nit: We could high-light that these are the project-admin, project-member, and project-reader personas and that system personas will come in a later release.","commit_id":"47619fab69b19da6db61f4a092e1d1015139f3e2"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"7cab88c28592e87c8f8a640b060d45b2ba2bacc7","unresolved":false,"context_lines":[{"line_number":2,"context_line":"features:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    The new parameter ``EnforceSecureRbac`` has been added to"},{"line_number":5,"context_line":"    enforce authorization based on common RBAC personas."}],"source_content_type":"text/x-yaml","patch_set":10,"id":"bdd36cb4_71e4dcf7","line":5,"range":{"start_line":5,"start_character":35,"end_line":5,"end_character":55},"in_reply_to":"56b0978f_3733e207","updated":"2021-10-05 11:33:35.000000000","message":"Ack","commit_id":"47619fab69b19da6db61f4a092e1d1015139f3e2"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"8ee343a8f58785c83fc6b379ee3c1e1de9ae94a8","unresolved":true,"context_lines":[{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    The new parameter ``EnforceSecureRbac`` has been added to"},{"line_number":5,"context_line":"    enforce authorization based on common RBAC personas."},{"line_number":6,"context_line":"    Currently the support is only available for project-admin,"},{"line_number":7,"context_line":"    project-member and project-reader personas and system personas"},{"line_number":8,"context_line":"    will come in a later release."}],"source_content_type":"text/x-yaml","patch_set":12,"id":"843d76d7_e472c012","line":8,"range":{"start_line":6,"start_character":3,"end_line":8,"end_character":33},"updated":"2021-10-07 12:35:33.000000000","message":"I\u0027m not sure this is true if you use EnforceSecureRbac: True and if nova configures enforce_scope\u003dTrue and enforce_new_defaults\u003dTrue. Some services might support more than just the project personas.\n\nSince this doesn\u0027t really expose new functionality that\u0027s useful, yet, do we want to include a release note for it?","commit_id":"0c08250e93b75910d78df0b9fae63e3da794fd22"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"83cea9e828c376faeb13c32b2ae99cdd0356449c","unresolved":true,"context_lines":[{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    The new parameter ``EnforceSecureRbac`` has been added to"},{"line_number":5,"context_line":"    enforce authorization based on common RBAC personas."},{"line_number":6,"context_line":"    Currently the support is only available for project-admin,"},{"line_number":7,"context_line":"    project-member and project-reader personas and system personas"},{"line_number":8,"context_line":"    will come in a later release."}],"source_content_type":"text/x-yaml","patch_set":12,"id":"c00abe0c_3e418b36","line":8,"range":{"start_line":6,"start_character":3,"end_line":8,"end_character":33},"in_reply_to":"843d76d7_e472c012","updated":"2021-10-13 05:04:49.000000000","message":"Well, generally when a new functionality is enabled in glance via THT the release note is expected to be added and even though glance supports only project personas ATM, I think release note required.\n\nHow about modifying the above statement by mentioning the \"glance specific support\" ?","commit_id":"0c08250e93b75910d78df0b9fae63e3da794fd22"}]}
