)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"989095c4aed8aba9fbcc88e666d5a82f80deda2c","unresolved":true,"context_lines":[{"line_number":4,"context_line":"Commit:     Kevin Carter \u003ckecarter@redhat.com\u003e"},{"line_number":5,"context_line":"CommitDate: 2021-08-11 11:58:39 -0500"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"Add a configuration option to enable secure RBAC in keystone"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"This adds a new option called HeatEnforceSecureRbac so that you can"},{"line_number":10,"context_line":"enable secure RBAC with keystone in TripleO deployments."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"d6c209ed_63bf8eb7","line":7,"range":{"start_line":7,"start_character":52,"end_line":7,"end_character":60},"updated":"2021-08-11 19:43:42.000000000","message":"heat*","commit_id":"554a8a2a310a1d377802750bd0fc77aa3b422755"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"989095c4aed8aba9fbcc88e666d5a82f80deda2c","unresolved":true,"context_lines":[{"line_number":7,"context_line":"Add a configuration option to enable secure RBAC in keystone"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"This adds a new option called HeatEnforceSecureRbac so that you can"},{"line_number":10,"context_line":"enable secure RBAC with keystone in TripleO deployments."},{"line_number":11,"context_line":""},{"line_number":12,"context_line":"This option sets the necessary oslo.policy configuration options in"},{"line_number":13,"context_line":"Heat\u0027s configuration file so support secure RBAC."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"4560929a_6c8a8040","line":10,"range":{"start_line":10,"start_character":24,"end_line":10,"end_character":32},"updated":"2021-08-11 19:43:42.000000000","message":"heat","commit_id":"554a8a2a310a1d377802750bd0fc77aa3b422755"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"989095c4aed8aba9fbcc88e666d5a82f80deda2c","unresolved":true,"context_lines":[{"line_number":10,"context_line":"enable secure RBAC with keystone in TripleO deployments."},{"line_number":11,"context_line":""},{"line_number":12,"context_line":"This option sets the necessary oslo.policy configuration options in"},{"line_number":13,"context_line":"Heat\u0027s configuration file so support secure RBAC."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"Change-Id: I865623feb4338c8f51b56d9916fe20f2c515a86e"},{"line_number":16,"context_line":"Signed-off-by: Kevin Carter \u003ckecarter@redhat.com\u003e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"e9faad99_24b58b46","line":13,"range":{"start_line":13,"start_character":26,"end_line":13,"end_character":28},"updated":"2021-08-11 19:43:42.000000000","message":"to*?","commit_id":"554a8a2a310a1d377802750bd0fc77aa3b422755"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":7353,"name":"Kevin Carter","email":"kevin@cloudnull.com","username":"cloudnull"},"change_message_id":"1a4a1aa2cd2b0ba308678a6a3708a303992faab5","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"47a83faa_76eda2ed","updated":"2021-10-29 16:37:15.000000000","message":"recheck","commit_id":"97392284c3d3738970c1119efcebb72da4aae01d"}],"deployment/heat/heat-base-puppet.yaml":[{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"79ca6e8cfe15917e47be65d5936b49e3f69914ec","unresolved":true,"context_lines":[{"line_number":140,"context_line":"    description: |"},{"line_number":141,"context_line":"      Use the advanced (eventlet safe) memcached client pool."},{"line_number":142,"context_line":"    default: true"},{"line_number":143,"context_line":"  HeatEnforceSecureRbac:"},{"line_number":144,"context_line":"    description: \u003e"},{"line_number":145,"context_line":"      Enforcing authorization based on common RBAC personas for Heat APIs."},{"line_number":146,"context_line":"    type: boolean"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"859e6837_c8447a8a","line":143,"updated":"2021-08-27 20:58:01.000000000","message":"Based on the conversation in another change [0], I added a separate global option for this [1]. I also updated a separate change using the global that you can use for an example [2].\n\n[0] https://review.opendev.org/c/openstack/tripleo-heat-templates/+/781571/14\n[1] https://review.opendev.org/c/openstack/tripleo-heat-templates/+/806449/1\n[2] https://review.opendev.org/c/openstack/tripleo-heat-templates/+/804277","commit_id":"554a8a2a310a1d377802750bd0fc77aa3b422755"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"e93fc47d1f02301a32211334091e44749202bbc9","unresolved":true,"context_lines":[{"line_number":162,"context_line":"      config_settings:"},{"line_number":163,"context_line":"        map_merge:"},{"line_number":164,"context_line":"          - if:"},{"line_number":165,"context_line":"            - {get_param: EnableSecureRbac}"},{"line_number":166,"context_line":"            - heat::policy::enforce_scope: true"},{"line_number":167,"context_line":"              heat::policy::enforce_new_defaults: true"},{"line_number":168,"context_line":"          - if:"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"eda1d19f_1603a346","line":165,"range":{"start_line":165,"start_character":26,"end_line":165,"end_character":42},"updated":"2021-09-03 20:20:38.000000000","message":"I think this is supposed to be EnforceSecureRbac?\n\nI added the option in https://review.opendev.org/c/openstack/tripleo-heat-templates/+/806449/3/deployment/keystone/keystone-container-puppet.yaml","commit_id":"2c188ba945735698df4368996f2ab179c64b90a2"},{"author":{"_account_id":7353,"name":"Kevin Carter","email":"kevin@cloudnull.com","username":"cloudnull"},"change_message_id":"dd0c9ae708bfac085f3b386a06b13e37e5587b60","unresolved":false,"context_lines":[{"line_number":162,"context_line":"      config_settings:"},{"line_number":163,"context_line":"        map_merge:"},{"line_number":164,"context_line":"          - if:"},{"line_number":165,"context_line":"            - {get_param: EnableSecureRbac}"},{"line_number":166,"context_line":"            - heat::policy::enforce_scope: true"},{"line_number":167,"context_line":"              heat::policy::enforce_new_defaults: true"},{"line_number":168,"context_line":"          - if:"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"8c4eb1c9_c84ce0bc","line":165,"range":{"start_line":165,"start_character":26,"end_line":165,"end_character":42},"in_reply_to":"eda1d19f_1603a346","updated":"2021-09-07 13:18:30.000000000","message":"Ack","commit_id":"2c188ba945735698df4368996f2ab179c64b90a2"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"7f60189032bdee9be2155ae71d4316287b5dedd7","unresolved":true,"context_lines":[{"line_number":142,"context_line":"    default: true"},{"line_number":143,"context_line":"  EnforceSecureRbac:"},{"line_number":144,"context_line":"    description: \u003e"},{"line_number":145,"context_line":"      Enforcing authorization based on common RBAC personas for Heat APIs."},{"line_number":146,"context_line":"    type: boolean"},{"line_number":147,"context_line":"    default: false"},{"line_number":148,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":3,"id":"7cf42ac4_066f6abc","line":145,"range":{"start_line":145,"start_character":64,"end_line":145,"end_character":68},"updated":"2021-09-07 21:37:53.000000000","message":"Similar comment here as the other patches. If this is a global variable, should it be referencing service specifics in the description? IIUC, this global will be redefined in multiple places. Do we want those definitions to all be the same?","commit_id":"97392284c3d3738970c1119efcebb72da4aae01d"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"b610d79e4dcf4c8607cca07d86402e15ec9d4642","unresolved":true,"context_lines":[{"line_number":142,"context_line":"    default: true"},{"line_number":143,"context_line":"  EnforceSecureRbac:"},{"line_number":144,"context_line":"    description: \u003e"},{"line_number":145,"context_line":"      Enforcing authorization based on common RBAC personas for Heat APIs."},{"line_number":146,"context_line":"    type: boolean"},{"line_number":147,"context_line":"    default: false"},{"line_number":148,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":3,"id":"ea1701fd_de01b2be","line":145,"range":{"start_line":145,"start_character":64,"end_line":145,"end_character":68},"in_reply_to":"5d521500_f6f22cc1","updated":"2021-11-29 15:07:50.000000000","message":"IIRC we should define the same description (as well as the other attributes like type, defualt and etc...) and this is enforced by pep8 rule.","commit_id":"97392284c3d3738970c1119efcebb72da4aae01d"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"6515240154df96a5b48cbd9b4bc8d208d981cbae","unresolved":true,"context_lines":[{"line_number":142,"context_line":"    default: true"},{"line_number":143,"context_line":"  EnforceSecureRbac:"},{"line_number":144,"context_line":"    description: \u003e"},{"line_number":145,"context_line":"      Enforcing authorization based on common RBAC personas for Heat APIs."},{"line_number":146,"context_line":"    type: boolean"},{"line_number":147,"context_line":"    default: false"},{"line_number":148,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":3,"id":"5d521500_f6f22cc1","line":145,"range":{"start_line":145,"start_character":64,"end_line":145,"end_character":68},"in_reply_to":"7cf42ac4_066f6abc","updated":"2021-11-04 19:54:50.000000000","message":"Here is the version used by most other services:\n\nhttps://github.com/openstack/tripleo-heat-templates/blob/master/deployment/keystone/keystone-container-puppet.yaml#L394-L404","commit_id":"97392284c3d3738970c1119efcebb72da4aae01d"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"8e1c2868479bc0db63121c0b4a3ae26ea1ef5252","unresolved":false,"context_lines":[{"line_number":142,"context_line":"    default: true"},{"line_number":143,"context_line":"  EnforceSecureRbac:"},{"line_number":144,"context_line":"    description: \u003e"},{"line_number":145,"context_line":"      Enforcing authorization based on common RBAC personas for Heat APIs."},{"line_number":146,"context_line":"    type: boolean"},{"line_number":147,"context_line":"    default: false"},{"line_number":148,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":3,"id":"939dc7e1_3ed645e0","line":145,"range":{"start_line":145,"start_character":64,"end_line":145,"end_character":68},"in_reply_to":"ea1701fd_de01b2be","updated":"2021-11-29 15:13:16.000000000","message":"Done","commit_id":"97392284c3d3738970c1119efcebb72da4aae01d"}],"releasenotes/notes/enable_secure_rbac_for_heat-963ccce84e630301.yaml":[{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"2a1601ecf76f23258d05434e7ca937b763b6b832","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"features:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    A new parameter ``EnableSecureRbac`` has been added to enforce"},{"line_number":5,"context_line":"    authorization based on common RBAC `personas \u003chttps://docs.openstack.org/keystone/latest/admin/service-api-protection.html#roles-definitions\u003e`_."}],"source_content_type":"text/x-yaml","patch_set":4,"id":"8c55db4b_8a25fce0","line":2,"range":{"start_line":2,"start_character":0,"end_line":2,"end_character":8},"updated":"2021-11-29 15:11:14.000000000","message":"The same content was added by the change for Glance, so we don\u0027t need to re-define the duplicated content here.","commit_id":"c9f1beaff1fca399d126d7b4e93b926a4b860772"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"8e1c2868479bc0db63121c0b4a3ae26ea1ef5252","unresolved":false,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"features:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    A new parameter ``EnableSecureRbac`` has been added to enforce"},{"line_number":5,"context_line":"    authorization based on common RBAC `personas \u003chttps://docs.openstack.org/keystone/latest/admin/service-api-protection.html#roles-definitions\u003e`_."}],"source_content_type":"text/x-yaml","patch_set":4,"id":"1abbe7b6_97d9d6d7","line":2,"range":{"start_line":2,"start_character":0,"end_line":2,"end_character":8},"in_reply_to":"8c55db4b_8a25fce0","updated":"2021-11-29 15:13:16.000000000","message":"Done","commit_id":"c9f1beaff1fca399d126d7b4e93b926a4b860772"}]}
