)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":8833,"name":"Rabi Mishra","email":"ramishra@redhat.com","username":"rabi"},"change_message_id":"c409de76a4d23600a0fe6744e53eba2e81124687","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"ad83259d_7173059a","updated":"2021-12-21 02:29:49.000000000","message":"\u003e I want to say this is on purpose as we may not have public access from some nodes.\n\nNot intentional, purely not understood properly.\n\nAs explained by Takashi www_authenticate_uri is sent back by the middleware to the API caller ( i.e client) when there is no auth token in the request header (and auth_url is used  to validate the token). Clients always use public endpoint to authenticate.","commit_id":"160936df134a471cfd245bd60964046027a571ea"},{"author":{"_account_id":21129,"name":"Alan Bishop","email":"abishopsweng@gmail.com","username":"ASBishop","status":"ex Red Hat"},"change_message_id":"be47dfa67e3c5c79ce1bf44687b1c4822a324bad","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"fc78d3fd_ced56dbd","updated":"2021-12-20 18:10:45.000000000","message":"I think this patch is taking the puppet parameter description too literally, and I suspect the author who originally wrote the comment didn\u0027t mean for it to be interpreted this way. It doesn\u0027t make sense to have services *not* using the internal API network.\n\nI don\u0027t think the code should be forced to match an unfortunately worded comment. And I also don\u0027t think it\u0027s worth the trouble to update the comment in a large number of puppet modules unless the comment is confusing a lot of users.","commit_id":"160936df134a471cfd245bd60964046027a571ea"},{"author":{"_account_id":14985,"name":"Alex Schultz","email":"aschultz@next-development.com","username":"mwhahaha"},"change_message_id":"df1a3fd1f9ecd7c9a817039e7b4f727fd48b3309","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"e9def0e0_93cee06f","updated":"2021-12-20 15:05:38.000000000","message":"I want to say this is on purpose as we may not have public access from some nodes. Are we sure we have to do this?","commit_id":"160936df134a471cfd245bd60964046027a571ea"},{"author":{"_account_id":22954,"name":"Juan Badia Payno","email":"jbadiapa@redhat.com","username":"jbadiapa"},"change_message_id":"00d59f63915aad0a063ce9c6ecfed4d4985de31c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"cab9b612_29c06902","updated":"2021-12-21 22:17:04.000000000","message":"Not sure whether this [1] affected the failure on the job tripleo-ci-centos-8-standalone-on-multinode-ipa [2].\n\n[1] - https://review.opendev.org/c/openstack/tripleo-heat-templates/+/822330\n[2] - https://zuul.opendev.org/t/openstack/build/c7bd39183e1f4654a1e9af924e2c5457/log/logs/undercloud/home/zuul/standalone_deploy.log\n\nPaste part of the error to avoid missing it.\n2021-12-21 20:14:43.853507 | fa163ed4-0ab4-04da-5494-000000000664 |       TASK | Ensure system is NTP time synced\n\n0000000, correction: 0.000000002, skew: 0.000\\ntry: 26, refid: 00000000, correction: 0.000000002, skew: 0.000\\ntry: 27, refid: 00000000, correction: 0.000000002, skew: 0.000\\ntry: 28, refid: 00000000, correction: 0.000000002, skew: 0.000\\ntry: 29, refid: 00000000, correction: 0.000000003, skew: 0.000\\ntry: 30, refid: 00000000, correction: 0.000000003, skew: 0.000\", \"stdout_lines\": [\"try: 1, refid: 00000000, correction: 0.000000000, skew: 0.000\", \"try: 2, refid: 00000000, correction: 0.000000000, skew: 0.000\", \"try: 3, refid: 00000000, correction: 0.000000000, skew: 0.000\", \"try: 4, refid: 00000000, correction: 0.000000000, skew: 0.000\", \"try: 5, refid: 00000000, correction: 0.000000000, skew: 0.000\", \"try: 6, refid: 00000000, correction: 0.000000000, skew: 0.000\", \"try: 7, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 8, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 9, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 10, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 11, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 12, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 13, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 14, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 15, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 16, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 17, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 18, refid: 00000000, correction: 0.000000002, skew: 0.000\", \"try: 19, refid: 00000000, correction: 0.000000002, skew: 0.000\", \"try: 20, refid: 00000000, correction: 0.000000002, skew: 0.000\", \"try: 21, refid: 00000000, correction: 0.000000002, skew: 0.000\", \"try: 22, refid: 00000000, correction: 0.000000002, skew: 0.000\", \"try: 23, refid: 00000000, correction: 0.000000002, skew: 0.000\", \"try: 24, refid: 00000000, correction: 0.000000002, skew: 0.000\", \"try: 25, refid: 00000000, correction: 02021-12-21 20:19:34.387325 | fa163ed4-0ab4-04da-5494-000000000664 |      FATAL | Ensure system is NTP time synced | standalone-0 | error\u003d{\"changed\": true, \"cmd\": [\"chronyc\", \"waitsync\", \"30\"], \"delta\": \"0:04:50.267677\", \"end\": \"2021-12-21 20:19:34.347302\", \"msg\": \"non-zero return code\", \"rc\": 1, \"start\": \"2021-12-21 20:14:44.079625\", \"stderr\": \"\", \"stderr_lines\": [], \"stdout\": \"try: 1, refid: 00000000, correction: 0.000000000, skew: 0.000\\ntry: 2, refid: 00000000, correction: 0.000000000, skew: 0.000\\ntry: 3, refid: 00000000, correction: 0.000000000, skew: 0.000\\ntry: 4, refid: 00000000, correction: 0.000000000, skew: 0.000\\ntry: 5, refid: 00000000, correction: 0.000000000, skew: 0.000\\ntry: 6, refid: 00000000, correction: 0.000000000, skew: 0.000\\ntry: 7, refid: 00000000, correction: 0.000000001, skew: 0.000\\ntry: 8, refid: 00000000, correction: 0.000000001, skew: 0.000\\ntry: 9, refid: 00000000, correction: 0.000000001, skew: 0.000\\ntry: 10, refid: 00000000, correction: 0.000000001, skew: 0.000\\ntry: 11, refid: 00000000, correction: 0.000000001, skew: 0.000\\ntry: 12, refid: 00000000, correction: 0.000000001, skew: 0.000\\ntry: 13, refid: 00000000, correction: 0.000000001, skew: 0.000\\ntry: 14, refid: 00000000, correction: 0.000000001, skew: 0.000\\ntry: 15, refid: 00000000, correction: 0.000000001, skew: 0.000\\ntry: 16, refid: 00000000, correction: 0.000000001, skew: 0.000\\ntry: 17, refid: 00000000, correction: 0.000000001, skew: 0.000\\ntry: 18, refid: 00000000, correction: 0.000000002, skew: 0.000\\ntry: 19, refid: 00000000, correction: 0.000000002, skew: 0.000\\ntry: 20, refid: 00000000, correction: 0.000000002, skew: 0.000\\ntry: 21, refid: 00000000, correction: 0.000000002, skew: 0.000\\ntry: 22, refid: 00000000, correction: 0.000000002, skew: 0.000\\ntry: 23, refid: 00000000, correction: 0.000000002, skew: 0.000\\ntry: 24, refid: 00000000, correction: 0.000000002, skew: 0.000\\ntry: 25, refid: 00000000, correction: 0.000000002, skew: 0.000\\ntry: 26, refid: 00000000, correction: 0.000000002, skew: 0.000\\ntry: 27, refid: 00000000, correction: 0.000000002, skew: 0.000\\ntry: 28, refid: 00000000, correction: 0.000000002, skew: 0.000\\ntry: 29, refid: 00000000, correction: 0.000000003, skew: 0.000\\ntry: 30, refid: 00000000, correction: 0.000000003, skew: 0.000\", \"stdout_lines\": [\"try: 1, refid: 00000000, correction: 0.000000000, skew: 0.000\", \"try: 2, refid: 00000000, correction: 0.000000000, skew: 0.000\", \"try: 3, refid: 00000000, correction: 0.000000000, skew: 0.000\", \"try: 4, refid: 00000000, correction: 0.000000000, skew: 0.000\", \"try: 5, refid: 00000000, correction: 0.000000000, skew: 0.000\", \"try: 6, refid: 00000000, correction: 0.000000000, skew: 0.000\", \"try: 7, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 8, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 9, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 10, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 11, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 12, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 13, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 14, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 15, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 16, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 17, refid: 00000000, correction: 0.000000001, skew: 0.000\", \"try: 18, refid: 00000000, correction: 0.000000002, skew: 0.000\", \"try: 19, refid: 00000000, correction: 0.000000002, skew: 0.000\", \"try: 20, refid: 00000000, correction: 0.000000002, skew: 0.000\", \"try: 21, refid: 00000000, correction: 0.000000002, skew: 0.000\", \"try: 22, refid: 00000000, correction: 0.000000002, skew: 0.000\", \"try: 23, refid: 00000000, correction: 0.000000002, skew: 0.000\", \"try: 24, refid: 00000000, correction: 0.000000002, skew: 0.000\", \"try: 25, refid: 00000000, correction: 0.000000002, skew: 0.000\", \"try: 26, refid: 00000000, correction: 0.000000002, skew: 0.000\", \"try: 27, refid: 00000000, correction: 0.000000002, skew: 0.000\", \"try: 28, refid: 00000000, correction: 0.000000002, skew: 0.000\", \"try: 29, refid: 00000000, correction: 0.000000003, skew: 0.000\", \"try: 30, refid: 00000000, correction: 0.000000003, skew: 0.000\"]}\n\n2021-12-21 20:19:34.390489 | fa163ed4-0ab4-04da-5494-000000000664 |     TIMING | Ensure system is NTP time synced | standalone-0 | 0:08:26.123664 | 290.53s","commit_id":"160936df134a471cfd245bd60964046027a571ea"},{"author":{"_account_id":14985,"name":"Alex Schultz","email":"aschultz@next-development.com","username":"mwhahaha"},"change_message_id":"9594bbfbe369a41135fa5a6a7241b0b86b365535","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"434e04a2_5851d9d2","updated":"2021-12-21 14:25:57.000000000","message":"hopefully this doesn\u0027t break anything","commit_id":"160936df134a471cfd245bd60964046027a571ea"},{"author":{"_account_id":9976,"name":"Ronelle Landy","email":"rlandy@redhat.com","username":"rlandy"},"change_message_id":"5b2b46762b875a7fcafb0b5eed57f5a59e5f75b5","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"21b99b1a_6d317bce","updated":"2022-01-03 20:21:30.000000000","message":"recheck","commit_id":"160936df134a471cfd245bd60964046027a571ea"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"ee33d0062937d5a6b96a786458801ef832bcb526","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"62a28e0a_6b739a09","updated":"2022-01-03 02:45:58.000000000","message":"recheck","commit_id":"160936df134a471cfd245bd60964046027a571ea"},{"author":{"_account_id":9976,"name":"Ronelle Landy","email":"rlandy@redhat.com","username":"rlandy"},"change_message_id":"5c19de58c5877338fa736315bca0ff76e5bbf007","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"72e0f0b8_d8b5bf5f","updated":"2021-12-21 17:56:46.000000000","message":"recheck","commit_id":"160936df134a471cfd245bd60964046027a571ea"},{"author":{"_account_id":8833,"name":"Rabi Mishra","email":"ramishra@redhat.com","username":"rabi"},"change_message_id":"194712325974e4b693cfbbf5c9a7866b224f81c6","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"ee5ecb8e_3b207101","updated":"2022-01-03 10:35:59.000000000","message":"recheck","commit_id":"160936df134a471cfd245bd60964046027a571ea"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"85d7280820054701bc65009b1773be2015f565ad","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"c6e59732_5069db03","in_reply_to":"00939f9c_607a73da","updated":"2021-12-20 23:46:05.000000000","message":"That is correct.\n\nJust a side note:\ns3_token middleware has the same www_authenticate_uri parameter(and the deprecated auth_uri parameter) but in this case these uri are used to contact Keystone API, and are not used in 401 responses, so this change doesn\u0027t touch that.","commit_id":"160936df134a471cfd245bd60964046027a571ea"},{"author":{"_account_id":14985,"name":"Alex Schultz","email":"aschultz@next-development.com","username":"mwhahaha"},"change_message_id":"e15b4733a1c238d41680246b5cffd388b7dee709","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"f1b51a55_62c3feb6","in_reply_to":"14af385a_0cba0a3d","updated":"2021-12-21 22:44:51.000000000","message":"https://bugs.launchpad.net/tripleo/+bug/1955508 will need to be fixed before this can land","commit_id":"160936df134a471cfd245bd60964046027a571ea"},{"author":{"_account_id":21129,"name":"Alan Bishop","email":"abishopsweng@gmail.com","username":"ASBishop","status":"ex Red Hat"},"change_message_id":"5283293030531f1f0ac639b5016541c8877aae12","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"00939f9c_607a73da","in_reply_to":"6dc9fded_a8818193","updated":"2021-12-20 23:41:12.000000000","message":"OK, I think I understand. Services will use the auth_url to contact keystone via the internal API network. www_authenticate_uri is only used if a 401 response has to be returned, in which case it makes sense to specify the public interface.\n\nIs my understanding correct?","commit_id":"160936df134a471cfd245bd60964046027a571ea"},{"author":{"_account_id":22954,"name":"Juan Badia Payno","email":"jbadiapa@redhat.com","username":"jbadiapa"},"change_message_id":"6bafd88ff815fca59dee65bb500c5f715bf7fd86","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"14af385a_0cba0a3d","in_reply_to":"cab9b612_29c06902","updated":"2021-12-21 22:35:27.000000000","message":"The error was due to the configuration of the NTP server, it can not be reached as Alex commented.","commit_id":"160936df134a471cfd245bd60964046027a571ea"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"09c115d6621ca42003435275f91b1848f72e31fa","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"7edce5ab_45d6f19b","in_reply_to":"e9def0e0_93cee06f","updated":"2021-12-20 23:17:30.000000000","message":"www_authenticate_uri is included in response header when 401 is returned from Keystone. It is used not by keystonemiddleware but by client. We should not expose internal url to client.","commit_id":"160936df134a471cfd245bd60964046027a571ea"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"09c115d6621ca42003435275f91b1848f72e31fa","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"6dc9fded_a8818193","in_reply_to":"fc78d3fd_ced56dbd","updated":"2021-12-20 23:17:30.000000000","message":"The usage of public endpoint is mentioned not only in puppet-keystone but also in keystonemiddleware itself. The description in puppet-keystone just follow the one in keystonemiddleware.\n\nAlso, as I mentioned in my reply to Alex, the url set to this parameter is exposed to client. We should not use any internal thing.","commit_id":"160936df134a471cfd245bd60964046027a571ea"}]}
