)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"ca93a1825200a9888698e8dd5225c404995ff266","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"c8fec932_b25c9b8f","updated":"2021-11-02 13:31:29.000000000","message":"I tested it with:\nparameter_defaults:\n  NovaShowHostStatus: true\n  NovaRestrictLiveMigration: true\n  NovaRestrictLiveMigrationRole: demo\n  NovaApiHostStatusPolicy: \u0027role:reader\u0027\n  NovaApiPolicies: { nova-context_is_admin: { key: \u0027compute:get_all\u0027, value: \u0027\u0027 } }\n\nand got:\n\n# cat /var/lib/config-data/puppet-generated/nova/etc/nova/policy.yaml\n\u0027os_compute_api:os-migrate-server:migrate_live\u0027: \u0027role:demo\u0027\n\u0027compute:get_all\u0027: \u0027\u0027\n\u0027os_compute_api:servers:show:host_status\u0027: \u0027role:reader\u0027\n\nthe show command also worked as expected, non-admin demo user with the reader role, was able to query the host_status for a VM instance:\n\n# openstack --os-cloud standalone-demo server show test --os-compute-api-version 2.16 -c host_status -f json\n{\n  \"host_status\": \"UP\"\n}\n","commit_id":"3b90b883b9e3b7cb1ceab7d51302ef19510b4595"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"34cec745c85a24e1eb6c096b92c25ca1416c29e1","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"7588302d_637d241b","updated":"2021-11-05 09:44:25.000000000","message":"recheck","commit_id":"3b90b883b9e3b7cb1ceab7d51302ef19510b4595"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"d0413d6b9c402b387100594abc0a92d67620bc64","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"d92be5ee_92a69cb5","updated":"2021-11-09 09:12:11.000000000","message":"recheck","commit_id":"3b90b883b9e3b7cb1ceab7d51302ef19510b4595"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"e4eeb98e9194566f4936ace1274289e8b31d7240","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"98628eb2_14d68fbf","updated":"2021-11-03 09:04:44.000000000","message":"recheck tempest unrelated","commit_id":"3b90b883b9e3b7cb1ceab7d51302ef19510b4595"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"b7ed7c6a892bde07e3fcfefd1387e64d62e5999c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"36ee97cb_6d3f4421","updated":"2021-12-01 23:51:13.000000000","message":"The host_status controls here make sense and it looks like this works properly. Just noting a few typos inline.","commit_id":"40742089cda3807b99bfe7f14e9e08854b58bd4d"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"22801b0cfde6133fc98acc6c07901239bda20f0e","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"bac2ebe0_80f2569b","updated":"2021-11-25 09:16:29.000000000","message":"test results for scn002: https://c5fe111c55b70ba3b878-ae6729a96e1d6a6e5a3d46e4b2a2210d.ssl.cf2.rackcdn.com/819081/1/check/tripleo-ci-centos-8-scenario002-standalone/f9f7c27/logs/undercloud/var/lib/config-data/puppet-generated/nova/etc/nova/policy.yaml\n\nscn001: https://storage.bhs.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_a32/819080/1/check/tripleo-ci-centos-8-scenario001-standalone/a32a660/logs/undercloud/var/lib/config-data/puppet-generated/nova/etc/nova/policy.yaml","commit_id":"40742089cda3807b99bfe7f14e9e08854b58bd4d"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"307d9e1a966cf261e2043f1242c173d3137a3c88","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"c7e9cda9_93f6e806","updated":"2021-12-07 23:18:26.000000000","message":"LGTM","commit_id":"98af8699423e106fc1acbd6b4ba12ebb0b55ee91"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"8ca1ebab8b84b6dc0f250b049e45f697b7c474d9","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"1fc23f3d_efd0db11","updated":"2021-12-08 09:03:16.000000000","message":"check-rdo","commit_id":"98af8699423e106fc1acbd6b4ba12ebb0b55ee91"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"2b8382060415f2f21f103e28c5da0a340a28741a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"313eb545_766df821","updated":"2021-12-02 17:03:03.000000000","message":"check-rdo","commit_id":"98af8699423e106fc1acbd6b4ba12ebb0b55ee91"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"d111842e0a578b05720817c157e6498c600943d4","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"6ea5ffdb_a110a45c","updated":"2021-12-20 10:47:24.000000000","message":"could you merge please","commit_id":"98af8699423e106fc1acbd6b4ba12ebb0b55ee91"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"bb2744c57c541638b67f6bf68036ec398d416fb7","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"3e10a206_6b6d9b31","updated":"2021-12-13 11:38:27.000000000","message":"could you please merge that?","commit_id":"98af8699423e106fc1acbd6b4ba12ebb0b55ee91"},{"author":{"_account_id":27419,"name":"David Vallee Delisle","email":"me@dvd.dev","username":"dvd"},"change_message_id":"c503a1b1dc2242cf2832c500794d2d1bab69f74a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"523a9269_e90f1838","updated":"2021-12-14 14:42:52.000000000","message":"nice one but is there a scenario where we would like to add a different role or rule to both os_compute_api:servers:show:host_status and os_compute_api:servers:show:host_status:unknown-only? This is a bit limiting in this area but I think it\u0027s a good change for now.","commit_id":"98af8699423e106fc1acbd6b4ba12ebb0b55ee91"},{"author":{"_account_id":27419,"name":"David Vallee Delisle","email":"me@dvd.dev","username":"dvd"},"change_message_id":"25de98cce8cda2a3195950a20c57a2f0b37227c3","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"f9fa773b_927c493f","updated":"2022-01-06 17:47:04.000000000","message":"recheck","commit_id":"98af8699423e106fc1acbd6b4ba12ebb0b55ee91"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"ded0353b0ea93e5ff99a978b6f505739bf6596d8","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"8af10272_38f55260","updated":"2021-12-14 14:11:38.000000000","message":"sup","commit_id":"98af8699423e106fc1acbd6b4ba12ebb0b55ee91"}],"deployment/nova/nova-api-container-puppet.yaml":[{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"9a2b82e90e58eb76df21beccf631aa574af2f427","unresolved":true,"context_lines":[{"line_number":274,"context_line":"    default: false"},{"line_number":275,"context_line":"  NovaApiHostStatusPolicy:"},{"line_number":276,"context_line":"    description: |"},{"line_number":277,"context_line":"      A custom api policy for os_compute_api:servers:show:host_status."},{"line_number":278,"context_line":"      That rule, or a role, replaces the admins-only policy value when"},{"line_number":279,"context_line":"      NovaShowHostStatus is enabled. By default, it shows host_status among the"},{"line_number":280,"context_line":"      other Nova server details available for non-admins."}],"source_content_type":"text/x-yaml","patch_set":1,"id":"f43f2e17_3d2242cd","line":277,"range":{"start_line":277,"start_character":30,"end_line":277,"end_character":69},"updated":"2021-11-18 21:59:36.000000000","message":"I have to point out something unfortunately a bit complicated about showing host_status to non-admin.\n\nThe host_status controlled by os_compute_api:servers:show:host_status is a full host status that will show detail like: UP, DOWN, MAINTENANCE, UNKNOWN. DOWN means forced_down, MAINTENANCE means disabled, UNKNOWN means a heartbeat was not received within the configured threshold.\n\nBecause some operators do not wish to expose this much detail, another policy was added: os_compute_api:servers:show:host_status:unknown-only [1] that is a limited host status that will only show: UNKNOWN if the host is in status UNKNOWN and it will not reveal UP, DOWN, or MAINTENANCE.\n\nI think we should provide both options os_compute_api:servers:show:host_status and os_compute_api:servers:show:host_status:unknown-only for operators so that they can get exactly the behavior they want, depending on how much information about cloud internals they are willing to expose.\n\n[1] https://review.opendev.org/c/openstack/nova/+/679181\n[2] https://docs.openstack.org/nova/latest/configuration/policy.html","commit_id":"3b90b883b9e3b7cb1ceab7d51302ef19510b4595"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"6e1c5abc20a8627a5eb10b1375bee9a7c5a14b2f","unresolved":false,"context_lines":[{"line_number":274,"context_line":"    default: false"},{"line_number":275,"context_line":"  NovaApiHostStatusPolicy:"},{"line_number":276,"context_line":"    description: |"},{"line_number":277,"context_line":"      A custom api policy for os_compute_api:servers:show:host_status."},{"line_number":278,"context_line":"      That rule, or a role, replaces the admins-only policy value when"},{"line_number":279,"context_line":"      NovaShowHostStatus is enabled. By default, it shows host_status among the"},{"line_number":280,"context_line":"      other Nova server details available for non-admins."}],"source_content_type":"text/x-yaml","patch_set":1,"id":"a8ea016a_e061ed3b","line":277,"range":{"start_line":277,"start_character":30,"end_line":277,"end_character":69},"in_reply_to":"f43f2e17_3d2242cd","updated":"2021-11-22 15:13:11.000000000","message":"Done","commit_id":"3b90b883b9e3b7cb1ceab7d51302ef19510b4595"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"990b45450d1513b043e9d73d774f66a56532f566","unresolved":true,"context_lines":[{"line_number":421,"context_line":"                  $NETWORK: {get_param: [ServiceNetMap, NovaApiNetwork]}"},{"line_number":422,"context_line":"            nova::api::instance_name_template: {get_param: InstanceNameTemplate}"},{"line_number":423,"context_line":"            nova::policy::purge_config: true"},{"line_number":424,"context_line":"            nova::policy::policies:"},{"line_number":425,"context_line":"              map_merge:"},{"line_number":426,"context_line":"              - {get_param: NovaApiPolicies}"},{"line_number":427,"context_line":"              - if:"},{"line_number":428,"context_line":"                - {get_param: NovaRestrictLiveMigration}"},{"line_number":429,"context_line":"                - limit_live_migration:"},{"line_number":430,"context_line":"                    key: \u0027os_compute_api:os-migrate-server:migrate_live\u0027"},{"line_number":431,"context_line":"                    value:"},{"line_number":432,"context_line":"                      str_replace:"},{"line_number":433,"context_line":"                        template: \u0027role:LMROLENAME\u0027"},{"line_number":434,"context_line":"                        params:"},{"line_number":435,"context_line":"                           LMROLENAME: {get_param: NovaRestrictLiveMigrationRole}"},{"line_number":436,"context_line":"                - {}"},{"line_number":437,"context_line":"              - if:"},{"line_number":438,"context_line":"                - {get_param: NovaShowHostStatus}"},{"line_number":439,"context_line":"                - nova-host_status:"},{"line_number":440,"context_line":"                    key: \u0027os_compute_api:servers:show:host_status\u0027"},{"line_number":441,"context_line":"                    value: {get_param: NovaApiHostStatusPolicy}"},{"line_number":442,"context_line":"                - {}"},{"line_number":443,"context_line":"            nova::api::allow_resize_to_same_host: {get_param: NovaAllowResizeToSameHost}"},{"line_number":444,"context_line":"            nova_enable_db_purge: {get_param: NovaEnableDBPurge}"},{"line_number":445,"context_line":"            nova::cron::purge_shadow_tables::minute: {get_param: NovaCronPurgeShadowTablesMinute}"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"9f8e2cde_4f62f571","line":442,"range":{"start_line":424,"start_character":0,"end_line":442,"end_character":20},"updated":"2021-11-02 13:38:00.000000000","message":"so we could follow that path of adding knobs for a case-specific policies, or perhaps modify both NovaRestrictLiveMigration/NovaShowHostStatus and NovaRestrictLiveMigrationRole/NovaApiHostStatusPolicy to cover a generic interface for overriding arbitrary policies in NovaApiPolicies","commit_id":"3b90b883b9e3b7cb1ceab7d51302ef19510b4595"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"aa6bc27e5ce7345b65126482df61bfb84e1f3ac9","unresolved":true,"context_lines":[{"line_number":421,"context_line":"                  $NETWORK: {get_param: [ServiceNetMap, NovaApiNetwork]}"},{"line_number":422,"context_line":"            nova::api::instance_name_template: {get_param: InstanceNameTemplate}"},{"line_number":423,"context_line":"            nova::policy::purge_config: true"},{"line_number":424,"context_line":"            nova::policy::policies:"},{"line_number":425,"context_line":"              map_merge:"},{"line_number":426,"context_line":"              - {get_param: NovaApiPolicies}"},{"line_number":427,"context_line":"              - if:"},{"line_number":428,"context_line":"                - {get_param: NovaRestrictLiveMigration}"},{"line_number":429,"context_line":"                - limit_live_migration:"},{"line_number":430,"context_line":"                    key: \u0027os_compute_api:os-migrate-server:migrate_live\u0027"},{"line_number":431,"context_line":"                    value:"},{"line_number":432,"context_line":"                      str_replace:"},{"line_number":433,"context_line":"                        template: \u0027role:LMROLENAME\u0027"},{"line_number":434,"context_line":"                        params:"},{"line_number":435,"context_line":"                           LMROLENAME: {get_param: NovaRestrictLiveMigrationRole}"},{"line_number":436,"context_line":"                - {}"},{"line_number":437,"context_line":"              - if:"},{"line_number":438,"context_line":"                - {get_param: NovaShowHostStatus}"},{"line_number":439,"context_line":"                - nova-host_status:"},{"line_number":440,"context_line":"                    key: \u0027os_compute_api:servers:show:host_status\u0027"},{"line_number":441,"context_line":"                    value: {get_param: NovaApiHostStatusPolicy}"},{"line_number":442,"context_line":"                - {}"},{"line_number":443,"context_line":"            nova::api::allow_resize_to_same_host: {get_param: NovaAllowResizeToSameHost}"},{"line_number":444,"context_line":"            nova_enable_db_purge: {get_param: NovaEnableDBPurge}"},{"line_number":445,"context_line":"            nova::cron::purge_shadow_tables::minute: {get_param: NovaCronPurgeShadowTablesMinute}"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"d7ca09a7_03ca33c9","line":442,"range":{"start_line":424,"start_character":0,"end_line":442,"end_character":20},"in_reply_to":"7053b87c_022c0b50","updated":"2021-11-05 09:47:10.000000000","message":"yes, given that that environment file references NovaApiPolicy, if there is need in more customizations, the only viable option that remains is merging it into NovaApiPolicy. And the direct use of NovaApiPolicy parameter for extra customizations is no longer possible in fact.","commit_id":"3b90b883b9e3b7cb1ceab7d51302ef19510b4595"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"ab6f0ae751106ab359ae768d4b97b3953f645c8f","unresolved":true,"context_lines":[{"line_number":421,"context_line":"                  $NETWORK: {get_param: [ServiceNetMap, NovaApiNetwork]}"},{"line_number":422,"context_line":"            nova::api::instance_name_template: {get_param: InstanceNameTemplate}"},{"line_number":423,"context_line":"            nova::policy::purge_config: true"},{"line_number":424,"context_line":"            nova::policy::policies:"},{"line_number":425,"context_line":"              map_merge:"},{"line_number":426,"context_line":"              - {get_param: NovaApiPolicies}"},{"line_number":427,"context_line":"              - if:"},{"line_number":428,"context_line":"                - {get_param: NovaRestrictLiveMigration}"},{"line_number":429,"context_line":"                - limit_live_migration:"},{"line_number":430,"context_line":"                    key: \u0027os_compute_api:os-migrate-server:migrate_live\u0027"},{"line_number":431,"context_line":"                    value:"},{"line_number":432,"context_line":"                      str_replace:"},{"line_number":433,"context_line":"                        template: \u0027role:LMROLENAME\u0027"},{"line_number":434,"context_line":"                        params:"},{"line_number":435,"context_line":"                           LMROLENAME: {get_param: NovaRestrictLiveMigrationRole}"},{"line_number":436,"context_line":"                - {}"},{"line_number":437,"context_line":"              - if:"},{"line_number":438,"context_line":"                - {get_param: NovaShowHostStatus}"},{"line_number":439,"context_line":"                - nova-host_status:"},{"line_number":440,"context_line":"                    key: \u0027os_compute_api:servers:show:host_status\u0027"},{"line_number":441,"context_line":"                    value: {get_param: NovaApiHostStatusPolicy}"},{"line_number":442,"context_line":"                - {}"},{"line_number":443,"context_line":"            nova::api::allow_resize_to_same_host: {get_param: NovaAllowResizeToSameHost}"},{"line_number":444,"context_line":"            nova_enable_db_purge: {get_param: NovaEnableDBPurge}"},{"line_number":445,"context_line":"            nova::cron::purge_shadow_tables::minute: {get_param: NovaCronPurgeShadowTablesMinute}"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"edcf022c_282ece60","line":442,"range":{"start_line":424,"start_character":0,"end_line":442,"end_character":20},"in_reply_to":"9f8e2cde_4f62f571","updated":"2021-11-02 13:41:52.000000000","message":"Also I think we cannot rely on direct values for NovaApiPolicies, since it is already being referred in user-faced environments, like RBAC settings. And if a user needs more customizations, the best option would be to merge it with NovaApiPolicies...","commit_id":"3b90b883b9e3b7cb1ceab7d51302ef19510b4595"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"db9efe887a0d6216ef73dc881c58352d7c7c99a3","unresolved":true,"context_lines":[{"line_number":421,"context_line":"                  $NETWORK: {get_param: [ServiceNetMap, NovaApiNetwork]}"},{"line_number":422,"context_line":"            nova::api::instance_name_template: {get_param: InstanceNameTemplate}"},{"line_number":423,"context_line":"            nova::policy::purge_config: true"},{"line_number":424,"context_line":"            nova::policy::policies:"},{"line_number":425,"context_line":"              map_merge:"},{"line_number":426,"context_line":"              - {get_param: NovaApiPolicies}"},{"line_number":427,"context_line":"              - if:"},{"line_number":428,"context_line":"                - {get_param: NovaRestrictLiveMigration}"},{"line_number":429,"context_line":"                - limit_live_migration:"},{"line_number":430,"context_line":"                    key: \u0027os_compute_api:os-migrate-server:migrate_live\u0027"},{"line_number":431,"context_line":"                    value:"},{"line_number":432,"context_line":"                      str_replace:"},{"line_number":433,"context_line":"                        template: \u0027role:LMROLENAME\u0027"},{"line_number":434,"context_line":"                        params:"},{"line_number":435,"context_line":"                           LMROLENAME: {get_param: NovaRestrictLiveMigrationRole}"},{"line_number":436,"context_line":"                - {}"},{"line_number":437,"context_line":"              - if:"},{"line_number":438,"context_line":"                - {get_param: NovaShowHostStatus}"},{"line_number":439,"context_line":"                - nova-host_status:"},{"line_number":440,"context_line":"                    key: \u0027os_compute_api:servers:show:host_status\u0027"},{"line_number":441,"context_line":"                    value: {get_param: NovaApiHostStatusPolicy}"},{"line_number":442,"context_line":"                - {}"},{"line_number":443,"context_line":"            nova::api::allow_resize_to_same_host: {get_param: NovaAllowResizeToSameHost}"},{"line_number":444,"context_line":"            nova_enable_db_purge: {get_param: NovaEnableDBPurge}"},{"line_number":445,"context_line":"            nova::cron::purge_shadow_tables::minute: {get_param: NovaCronPurgeShadowTablesMinute}"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"7053b87c_022c0b50","line":442,"range":{"start_line":424,"start_character":0,"end_line":442,"end_character":20},"in_reply_to":"edcf022c_282ece60","updated":"2021-11-04 19:49:24.000000000","message":"You mean updating this, right?\n\nhttps://github.com/openstack/tripleo-heat-templates/blob/master/environments/enable-secure-rbac.yaml#L3","commit_id":"3b90b883b9e3b7cb1ceab7d51302ef19510b4595"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"f7bd1d9935b598bf7a19b8a0bf5958197dd9fb65","unresolved":true,"context_lines":[{"line_number":283,"context_line":"      details. NovaShowHostStatus \u0027hidden\u0027 puts it back being visible only for admins."},{"line_number":284,"context_line":"      Additional policies specified using NovaApiPolicies get merged with this"},{"line_number":285,"context_line":"      policy."},{"line_number":286,"context_line":"    default: \u0027rule:system_or_project_reader\u0027"},{"line_number":287,"context_line":"    type: string"},{"line_number":288,"context_line":""},{"line_number":289,"context_line":"parameter_groups:"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"68e76f63_9214bc00","line":286,"range":{"start_line":286,"start_character":14,"end_line":286,"end_character":43},"updated":"2021-11-23 12:06:42.000000000","message":"I\u0027m not sure what is the difference of rule to role, and what should I place here.\nLooking at https://review.opendev.org/c/openstack/tripleo-heat-templates/+/818840 example, I can\u0027t get the anwer yet.","commit_id":"714b561ecadc3aeefb237b6921dd90ad3577e358"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"b7ed7c6a892bde07e3fcfefd1387e64d62e5999c","unresolved":true,"context_lines":[{"line_number":267,"context_line":"    description: |"},{"line_number":268,"context_line":"      Allow overriding API policies to access the compute host status in the"},{"line_number":269,"context_line":"      requested Nova server details. The default value \u0027hidden\u0027 allows only admins to"},{"line_number":270,"context_line":"      access it. Setting it to \u0027all\u0027 (\u0027unknown-only\u0027) without additional fine-graned"},{"line_number":271,"context_line":"      tuning of NovaApiHostStatusPolicy shows the full (limited) host_status"},{"line_number":272,"context_line":"      to the system/project readers."},{"line_number":273,"context_line":"    default: \u0027hidden\u0027"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"e1cd6246_c399e1e4","line":270,"range":{"start_line":270,"start_character":78,"end_line":270,"end_character":84},"updated":"2021-12-01 23:51:13.000000000","message":"grained","commit_id":"40742089cda3807b99bfe7f14e9e08854b58bd4d"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"b7ed7c6a892bde07e3fcfefd1387e64d62e5999c","unresolved":true,"context_lines":[{"line_number":277,"context_line":"    description: |"},{"line_number":278,"context_line":"      A custom API policy for os_compute_api:servers:show:host_status and"},{"line_number":279,"context_line":"      os_compute_api:servers:show:host_status:unknown-only."},{"line_number":280,"context_line":"      These ruls, or roles, replace the admins-only policies based on the given"},{"line_number":281,"context_line":"      NovaShowHostStatus: \u0027unknown-only\u0027 shows the limited host status UNKNOWN"},{"line_number":282,"context_line":"      whenever a heartbeat was not received within the configured threshold, and"},{"line_number":283,"context_line":"      \u0027all\u0027 also reveals UP, DOWN, or MAINTENANCE statuses in the Nova server"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"a047b74a_1a4fcda3","line":280,"range":{"start_line":280,"start_character":12,"end_line":280,"end_character":16},"updated":"2021-12-01 23:51:13.000000000","message":"rules?","commit_id":"40742089cda3807b99bfe7f14e9e08854b58bd4d"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"9d88514b5a52d29c02402398d0ff2ecd4b923afc","unresolved":true,"context_lines":[{"line_number":285,"context_line":"      Additional policies specified using NovaApiPolicies get merged with this"},{"line_number":286,"context_line":"      policy."},{"line_number":287,"context_line":"    # TODO(bogdando): use rule:system_or_project_reader once tripleo enforces scopes"},{"line_number":288,"context_line":"    default: \u0027role:reader\u0027"},{"line_number":289,"context_line":"    type: string"},{"line_number":290,"context_line":""},{"line_number":291,"context_line":"parameter_groups:"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"297affa3_7136ef3d","line":288,"updated":"2021-11-23 12:52:29.000000000","message":"or should I use role:reader or role:member ?..","commit_id":"40742089cda3807b99bfe7f14e9e08854b58bd4d"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"af5efcecb977b430642804a5bfc71b18d4a96350","unresolved":true,"context_lines":[{"line_number":285,"context_line":"      Additional policies specified using NovaApiPolicies get merged with this"},{"line_number":286,"context_line":"      policy."},{"line_number":287,"context_line":"    # TODO(bogdando): use rule:system_or_project_reader once tripleo enforces scopes"},{"line_number":288,"context_line":"    default: \u0027role:reader\u0027"},{"line_number":289,"context_line":"    type: string"},{"line_number":290,"context_line":""},{"line_number":291,"context_line":"parameter_groups:"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"dfe254b5_6f441e73","line":288,"in_reply_to":"297affa3_7136ef3d","updated":"2021-11-23 13:10:56.000000000","message":"by default this shoudl be admin only but reader is correct.","commit_id":"40742089cda3807b99bfe7f14e9e08854b58bd4d"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"30a98c6d899dc805ca98c45e8eccca9cfb145ffb","unresolved":true,"context_lines":[{"line_number":285,"context_line":"      Additional policies specified using NovaApiPolicies get merged with this"},{"line_number":286,"context_line":"      policy."},{"line_number":287,"context_line":"    # TODO(bogdando): use rule:system_or_project_reader once tripleo enforces scopes"},{"line_number":288,"context_line":"    default: \u0027role:reader\u0027"},{"line_number":289,"context_line":"    type: string"},{"line_number":290,"context_line":""},{"line_number":291,"context_line":"parameter_groups:"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"d959dd78_19fd3c2f","line":288,"in_reply_to":"dfe254b5_6f441e73","updated":"2021-11-23 13:45:43.000000000","message":"thanks. the \"real\" default case would be admins only indeed, please see how this param works alongside NovaShowHostStatus: hidden default","commit_id":"40742089cda3807b99bfe7f14e9e08854b58bd4d"}],"releasenotes/notes/nova_api_show_host_status-f0dfaf4c2b0c536f.yaml":[{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"b7ed7c6a892bde07e3fcfefd1387e64d62e5999c","unresolved":true,"context_lines":[{"line_number":4,"context_line":"    Add `NovaShowHostStatus` to allow overriding API policies to access the compute"},{"line_number":5,"context_line":"    host status in the requested Nova server details. The default value \u0027hidden\u0027"},{"line_number":6,"context_line":"    allows only admins to access it. Setting it to \u0027all\u0027 (\u0027unknown-only\u0027) without"},{"line_number":7,"context_line":"    additional fine-graned tuning of `NovaApiHostStatusPolicy` shows the full"},{"line_number":8,"context_line":"    (limited) `host_status` to the system/project readers."},{"line_number":9,"context_line":""},{"line_number":10,"context_line":"    Add `NovaApiHostStatusPolicy` that defines a custom API policy for"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"24082724_24284ead","line":7,"range":{"start_line":7,"start_character":20,"end_line":7,"end_character":26},"updated":"2021-12-01 23:51:13.000000000","message":"grained","commit_id":"40742089cda3807b99bfe7f14e9e08854b58bd4d"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"b7ed7c6a892bde07e3fcfefd1387e64d62e5999c","unresolved":true,"context_lines":[{"line_number":10,"context_line":"    Add `NovaApiHostStatusPolicy` that defines a custom API policy for"},{"line_number":11,"context_line":"    `os_compute_api:servers:show:host_status and"},{"line_number":12,"context_line":"    `os_compute_api:servers:show:host_status:unknown-only`."},{"line_number":13,"context_line":"    These ruls, or roles, replace the admins-only policies based on the given"},{"line_number":14,"context_line":"    `NovaShowHostStatus`: \u0027unknown-only\u0027 shows the limited host status UNKNOWN"},{"line_number":15,"context_line":"    whenever a heartbeat was not received within the configured threshold, and"},{"line_number":16,"context_line":"    \u0027all\u0027 also reveals UP, DOWN, or MAINTENANCE statuses in the Nova server"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"8a11faf1_ab26af2e","line":13,"range":{"start_line":13,"start_character":10,"end_line":13,"end_character":14},"updated":"2021-12-01 23:51:13.000000000","message":"rules?","commit_id":"40742089cda3807b99bfe7f14e9e08854b58bd4d"}]}
