)]}'
{"deployment/placement/placement-api-container-puppet.yaml":[{"author":{"_account_id":17216,"name":"Martin Schuppert","email":"mschuppert@redhat.com","username":"mcschupp"},"change_message_id":"040014f0b89e13437ec2aac41b24335110f39606","unresolved":true,"context_lines":[{"line_number":190,"context_line":"                - {get_param: PlacementWorkers}"},{"line_number":191,"context_line":"          - if:"},{"line_number":192,"context_line":"            - {get_param: PlacementEnforceSecureRbac}"},{"line_number":193,"context_line":"            - placement::policy::enforce_new_defaults: true"},{"line_number":194,"context_line":"              placement::policy::enforce_scope: true"},{"line_number":195,"context_line":"      service_config_settings:"},{"line_number":196,"context_line":"        rsyslog:"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"d46fd948_36d9de45","line":193,"updated":"2021-08-11 14:59:22.000000000","message":"or just set placement::policy::xxx: {get_param: PlacementEnforceSecureRbac} for both of them.","commit_id":"cdd715965ed961630bb4a404693b2074cafaf207"},{"author":{"_account_id":27419,"name":"David Vallee Delisle","email":"me@dvd.dev","username":"dvd"},"change_message_id":"9cda8531b63c82afdaf7b7c79409cc42a5cf1163","unresolved":false,"context_lines":[{"line_number":190,"context_line":"                - {get_param: PlacementWorkers}"},{"line_number":191,"context_line":"          - if:"},{"line_number":192,"context_line":"            - {get_param: PlacementEnforceSecureRbac}"},{"line_number":193,"context_line":"            - placement::policy::enforce_new_defaults: true"},{"line_number":194,"context_line":"              placement::policy::enforce_scope: true"},{"line_number":195,"context_line":"      service_config_settings:"},{"line_number":196,"context_line":"        rsyslog:"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"cdd7efc1_dd926763","line":193,"in_reply_to":"d46fd948_36d9de45","updated":"2021-08-11 18:11:48.000000000","message":"Good point!","commit_id":"cdd715965ed961630bb4a404693b2074cafaf207"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"9e558b07f51369e19575478e05d38e4ec6a16785","unresolved":true,"context_lines":[{"line_number":55,"context_line":"    description: The password for the Placement service and db account"},{"line_number":56,"context_line":"    type: string"},{"line_number":57,"context_line":"    hidden: true"},{"line_number":58,"context_line":"  PlacementEnforceSecureRbac:"},{"line_number":59,"context_line":"    description: \u003e"},{"line_number":60,"context_line":"      Enforcing authorization based on common RBAC personas only for Placement APIs."},{"line_number":61,"context_line":"    type: boolean"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"f0fbd86e_d47e323e","line":58,"range":{"start_line":58,"start_character":2,"end_line":58,"end_character":28},"updated":"2021-08-19 17:14:31.000000000","message":"This trying to figure out if we\u0027re going to use a single global parameter for this or not [0].\n\n[0] https://review.opendev.org/c/openstack/tripleo-heat-templates/+/781571","commit_id":"66082a66144dea39e9d1eb1e17f75f05fd5b250e"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"e5ec229b129f3206ab43683027fb5655575fab0a","unresolved":true,"context_lines":[{"line_number":55,"context_line":"    description: The password for the Placement service and db account"},{"line_number":56,"context_line":"    type: string"},{"line_number":57,"context_line":"    hidden: true"},{"line_number":58,"context_line":"  PlacementEnforceSecureRbac:"},{"line_number":59,"context_line":"    description: \u003e"},{"line_number":60,"context_line":"      Enforcing authorization based on common RBAC personas only for Placement APIs."},{"line_number":61,"context_line":"    type: boolean"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"dbdb7365_e38b0487","line":58,"range":{"start_line":58,"start_character":2,"end_line":58,"end_character":28},"in_reply_to":"30891666_599aaf98","updated":"2021-08-27 20:57:05.000000000","message":"Actually - looks like we\u0027re going with the global.\n\nBased on the conversation in another change [0], I added a separate global option for this [1]. I also updated a separate change using the global that you can use for an example [2].\n\n[0] https://review.opendev.org/c/openstack/tripleo-heat-templates/+/781571/14\n[1] https://review.opendev.org/c/openstack/tripleo-heat-templates/+/806449/1\n[2] https://review.opendev.org/c/openstack/tripleo-heat-templates/+/804277","commit_id":"66082a66144dea39e9d1eb1e17f75f05fd5b250e"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"3d0e502e6fa93dc0b9fb810cbc3ac5875d1d9678","unresolved":false,"context_lines":[{"line_number":55,"context_line":"    description: The password for the Placement service and db account"},{"line_number":56,"context_line":"    type: string"},{"line_number":57,"context_line":"    hidden: true"},{"line_number":58,"context_line":"  PlacementEnforceSecureRbac:"},{"line_number":59,"context_line":"    description: \u003e"},{"line_number":60,"context_line":"      Enforcing authorization based on common RBAC personas only for Placement APIs."},{"line_number":61,"context_line":"    type: boolean"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"30891666_599aaf98","line":58,"range":{"start_line":58,"start_character":2,"end_line":58,"end_character":28},"in_reply_to":"f0fbd86e_d47e323e","updated":"2021-08-25 13:18:52.000000000","message":"Sounds like we\u0027re going to pursue service-specific variables and then enable them via a single template, as opposed to a single global variable.","commit_id":"66082a66144dea39e9d1eb1e17f75f05fd5b250e"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"423fc9e661a5f2b6849372b38025818c40c8c31e","unresolved":true,"context_lines":[{"line_number":57,"context_line":"    hidden: true"},{"line_number":58,"context_line":"  EnforceSecureRbac:"},{"line_number":59,"context_line":"    description: \u003e"},{"line_number":60,"context_line":"      Enforcing authorization based on common RBAC personas only for Placement APIs."},{"line_number":61,"context_line":"    type: boolean"},{"line_number":62,"context_line":"    default: false"},{"line_number":63,"context_line":"  KeystoneRegion:"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"0ed26924_56be49ff","line":60,"range":{"start_line":60,"start_character":69,"end_line":60,"end_character":78},"updated":"2021-09-07 21:36:35.000000000","message":"Same comment here as in the other patches. Should this global reference service specific information? Or should we be using the same global definition everywhere?","commit_id":"461c711222fa09a7905abc83dc26b4a6e88f0e15"}],"releasenotes/notes/enable_secure_rbac_support_for_placement-57a806a58afd8ec1.yaml":[{"author":{"_account_id":7144,"name":"James Slagle","email":"jslagle@redhat.com","username":"slagle"},"change_message_id":"f1834e0dd302c220364e121f1cda26992f62de60","unresolved":true,"context_lines":[{"line_number":2,"context_line":"---"},{"line_number":3,"context_line":"features:"},{"line_number":4,"context_line":"  - |"},{"line_number":5,"context_line":"    The new parameter ``PlacementEnforceSecureRbac`` has been added to"},{"line_number":6,"context_line":"    enforce authorization based on common RBAC personas."},{"line_number":7,"context_line":"    This parameter is currently used by Placement only, but support"},{"line_number":8,"context_line":"    for the other services will be introduced later."}],"source_content_type":"text/x-yaml","patch_set":3,"id":"44986124_f82412fe","line":5,"updated":"2021-09-29 13:21:02.000000000","message":"should it be PlacementEnforceSecureRbac or EnforceSecureRbac?","commit_id":"461c711222fa09a7905abc83dc26b4a6e88f0e15"}]}
