)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"b95fd456078e69f99a49203ea2cfbdadc3b69d76","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"f734ee0b_8a8402f9","updated":"2021-11-24 21:58:07.000000000","message":"We will need to make sure we incorporate this change into the stable/wallaby backport \n\nhttps://review.opendev.org/c/openstack/tripleo-heat-templates/+/818640","commit_id":"1f79df6dabfb00062206e4f723b4460eb3dd58d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"5703f8913bf28074070197251f53fec8005bb235","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"c27bfb12_e9f73dd1","updated":"2021-11-12 12:54:21.000000000","message":"makes sense!","commit_id":"1f79df6dabfb00062206e4f723b4460eb3dd58d6"}],"environments/enable-secure-rbac.yaml":[{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"b19e2d80741c29ba4fc954f0c5f09881b301ce2a","unresolved":true,"context_lines":[{"line_number":1016,"context_line":"      value: \"rule:admin_api or (role:reader and project_id:%(project_id)s) or rule:shared or rule:external or rule:context_is_advsvc\""},{"line_number":1017,"context_line":"    neutron-get_network_router_external:"},{"line_number":1018,"context_line":"      key: \"get_network:router:external\""},{"line_number":1019,"context_line":"      value: \"role:reader\""},{"line_number":1020,"context_line":"    neutron-get_network_segments:"},{"line_number":1021,"context_line":"      key: \"get_network:segments\""},{"line_number":1022,"context_line":"      value: \"rule:admin_api\""}],"source_content_type":"text/x-yaml","patch_set":1,"id":"7d4b3dd3_1c4716e2","line":1019,"range":{"start_line":1019,"start_character":14,"end_line":1019,"end_character":25},"updated":"2021-11-18 01:02:33.000000000","message":"Ok - just to make sure, this is going to open any network with the external attribute set to True to any use in the deployment (assuming implied roles are not broken by the operator).\n\nIf that\u0027s the intent, that makes sense. This also means anyone with a system-scoped token can also view these networks.\n\nI think we\u0027re still working out some of those details in the community goal, but for today this probably makes sense.","commit_id":"1f79df6dabfb00062206e4f723b4460eb3dd58d6"},{"author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"change_message_id":"e8989cc5ae94e212049f676549c68606ad83b156","unresolved":false,"context_lines":[{"line_number":1016,"context_line":"      value: \"rule:admin_api or (role:reader and project_id:%(project_id)s) or rule:shared or rule:external or rule:context_is_advsvc\""},{"line_number":1017,"context_line":"    neutron-get_network_router_external:"},{"line_number":1018,"context_line":"      key: \"get_network:router:external\""},{"line_number":1019,"context_line":"      value: \"role:reader\""},{"line_number":1020,"context_line":"    neutron-get_network_segments:"},{"line_number":1021,"context_line":"      key: \"get_network:segments\""},{"line_number":1022,"context_line":"      value: \"rule:admin_api\""}],"source_content_type":"text/x-yaml","patch_set":1,"id":"84bb86a0_3dde11f9","line":1019,"range":{"start_line":1019,"start_character":14,"end_line":1019,"end_character":25},"in_reply_to":"0b901998_5a6fc6cd","updated":"2021-11-19 18:13:45.000000000","message":"Ack","commit_id":"1f79df6dabfb00062206e4f723b4460eb3dd58d6"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"7d346da08fe74c137d2a296fa8e48b97029e08fb","unresolved":true,"context_lines":[{"line_number":1016,"context_line":"      value: \"rule:admin_api or (role:reader and project_id:%(project_id)s) or rule:shared or rule:external or rule:context_is_advsvc\""},{"line_number":1017,"context_line":"    neutron-get_network_router_external:"},{"line_number":1018,"context_line":"      key: \"get_network:router:external\""},{"line_number":1019,"context_line":"      value: \"role:reader\""},{"line_number":1020,"context_line":"    neutron-get_network_segments:"},{"line_number":1021,"context_line":"      key: \"get_network:segments\""},{"line_number":1022,"context_line":"      value: \"rule:admin_api\""}],"source_content_type":"text/x-yaml","patch_set":1,"id":"0b901998_5a6fc6cd","line":1019,"range":{"start_line":1019,"start_character":14,"end_line":1019,"end_character":25},"in_reply_to":"7d4b3dd3_1c4716e2","updated":"2021-11-18 14:50:07.000000000","message":"Yes, that\u0027s the intent here. Basically router:external networks are networks which are visible for all users in the cloud. That\u0027s how neutron works currently. And that change is just to expose \"router:external\" attribute for all users - if it\u0027s external network it can be shown to users without problem.","commit_id":"1f79df6dabfb00062206e4f723b4460eb3dd58d6"}]}
