)]}'
{"deployment/nova/nova-libvirt-container-puppet.yaml":[{"author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"change_message_id":"5e811b2632f459cfc90dbbd85f55ce23a84d6e01","unresolved":true,"context_lines":[{"line_number":799,"context_line":"                            # Copy cert and key to libvirt dirs"},{"line_number":800,"context_line":"                            cp /etc/pki/tls/certs/libvirt-server-cert.crt /etc/pki/libvirt/servercert.pem"},{"line_number":801,"context_line":"                            cp /etc/pki/tls/private/libvirt-server-cert.key /etc/pki/libvirt/private/serverkey.pem"},{"line_number":802,"context_line":"                            systemctl reload libvirtd"},{"line_number":803,"context_line":"                          key_size:"},{"line_number":804,"context_line":"                            if:"},{"line_number":805,"context_line":"                              - key_size_libvirtvnc_override_unset"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"caa46319_21c09230","side":"PARENT","line":802,"updated":"2021-05-05 09:14:15.000000000","message":"You don\u0027t mention removing libvirtd reload in the description. Would the cert still be reloaded by libvirt without this?","commit_id":"40528d4a86aa9f4068a9a0acaf8b9aa989deb54b"},{"author":{"_account_id":17216,"name":"Martin Schuppert","email":"mschuppert@redhat.com","username":"mcschupp"},"change_message_id":"129ce9b8dbc90bc1f8633eb9acdc04b4a9da5b97","unresolved":true,"context_lines":[{"line_number":799,"context_line":"                            # Copy cert and key to libvirt dirs"},{"line_number":800,"context_line":"                            cp /etc/pki/tls/certs/libvirt-server-cert.crt /etc/pki/libvirt/servercert.pem"},{"line_number":801,"context_line":"                            cp /etc/pki/tls/private/libvirt-server-cert.key /etc/pki/libvirt/private/serverkey.pem"},{"line_number":802,"context_line":"                            systemctl reload libvirtd"},{"line_number":803,"context_line":"                          key_size:"},{"line_number":804,"context_line":"                            if:"},{"line_number":805,"context_line":"                              - key_size_libvirtvnc_override_unset"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"b4eb859f_a234cb00","side":"PARENT","line":802,"in_reply_to":"caa46319_21c09230","updated":"2021-05-05 09:34:43.000000000","message":"I removed it because libvirt is running in a container and not on the host, so the current reload does not have any effect. But I\u0027ll not remove it, I\u0027ll change it to trigger reload on tripleo_nova_libvirt instead","commit_id":"40528d4a86aa9f4068a9a0acaf8b9aa989deb54b"},{"author":{"_account_id":17216,"name":"Martin Schuppert","email":"mschuppert@redhat.com","username":"mcschupp"},"change_message_id":"cdb05acd6a791251d6c5647f5296ad6ba054e5ca","unresolved":true,"context_lines":[{"line_number":118,"context_line":"    type: string"},{"line_number":119,"context_line":"    description: Specifies the default CA cert to use if TLS is used for"},{"line_number":120,"context_line":"                 services in the internal network."},{"line_number":121,"context_line":"  InternalTLSNbdCAFile:"},{"line_number":122,"context_line":"    default: \u0027/etc/ipa/ca.crt\u0027"},{"line_number":123,"context_line":"    type: string"},{"line_number":124,"context_line":"    description: Specifies the CA cert to use for NBD TLS."}],"source_content_type":"text/x-yaml","patch_set":3,"id":"8ababab8_51383501","side":"PARENT","line":121,"updated":"2021-05-05 09:44:00.000000000","message":"can we remove the params in this case as the certs are the same, or do we need to handle deprecation?","commit_id":"40528d4a86aa9f4068a9a0acaf8b9aa989deb54b"},{"author":{"_account_id":17216,"name":"Martin Schuppert","email":"mschuppert@redhat.com","username":"mcschupp"},"change_message_id":"481bc2327ef2896b34dbd5c3e20eb222e56578cf","unresolved":true,"context_lines":[{"line_number":118,"context_line":"    type: string"},{"line_number":119,"context_line":"    description: Specifies the default CA cert to use if TLS is used for"},{"line_number":120,"context_line":"                 services in the internal network."},{"line_number":121,"context_line":"  InternalTLSNbdCAFile:"},{"line_number":122,"context_line":"    default: \u0027/etc/ipa/ca.crt\u0027"},{"line_number":123,"context_line":"    type: string"},{"line_number":124,"context_line":"    description: Specifies the CA cert to use for NBD TLS."},{"line_number":125,"context_line":"  InternalTLSVncCAFile:"},{"line_number":126,"context_line":"    default: \u0027/etc/ipa/ca.crt\u0027"},{"line_number":127,"context_line":"    type: string"},{"line_number":128,"context_line":"    description: Specifies the CA cert to use for VNC TLS."},{"line_number":129,"context_line":"  InternalTLSQemuCAFile:"},{"line_number":130,"context_line":"    default: \u0027/etc/ipa/ca.crt\u0027"},{"line_number":131,"context_line":"    type: string"},{"line_number":132,"context_line":"    description: Specifies the CA cert to use for qemu."},{"line_number":133,"context_line":"  CertificateKeySize:"},{"line_number":134,"context_line":"    type: string"},{"line_number":135,"context_line":"    default: \u00272048\u0027"}],"source_content_type":"text/x-yaml","patch_set":10,"id":"cd3becff_bbecd42d","side":"PARENT","line":132,"range":{"start_line":121,"start_character":0,"end_line":132,"end_character":55},"updated":"2021-05-26 16:20:24.000000000","message":"in this case, do we have to handle all the the parameter removal via deprecation when we reduced the same functionality to a single CA cert? all certs are the same as they use the same network when request them?","commit_id":"90f3f42736a89066cc1766896280e6860eaf8e69"}],"releasenotes/notes/nova_libvirt_ssl_cert_simplification-dbee541be9f55ce5.yaml":[{"author":{"_account_id":17216,"name":"Martin Schuppert","email":"mschuppert@redhat.com","username":"mcschupp"},"change_message_id":"2b8335bd9746b159a6a3734fbeb3c3a27d2623d0","unresolved":true,"context_lines":[{"line_number":12,"context_line":""},{"line_number":13,"context_line":"    The intention (of libvirt) is that you can just use the"},{"line_number":14,"context_line":"    default_tls_x509_* config attributes so that you don’t need to set any"},{"line_number":15,"context_line":"    other `*_tls*` parameters, unless_ you need different certificates for"},{"line_number":16,"context_line":"    some services. The rationale for that is that some services (e.g."},{"line_number":17,"context_line":"    migration / NBD) are only exposed to internal infrastructure; while"},{"line_number":18,"context_line":"    some sevices (VNC, Spice) might be exposed publically, so might need"}],"source_content_type":"text/x-yaml","patch_set":9,"id":"41f2cccf_494db1c8","line":15,"range":{"start_line":15,"start_character":31,"end_line":15,"end_character":39},"updated":"2021-05-26 12:09:44.000000000","message":"how could I miss this ... this resulted in all the release notes failures...","commit_id":"fd3c2013c2d8a31a538c7dd7a6207beb1fbc7f19"}]}
