)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":7130,"name":"David Hill","email":"davidchill@hotmail.com","username":"dhill"},"change_message_id":"bc0fcb33394d0e03b1640e5f55eb00b92a0d8a52","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"e7803d5e_91680f11","updated":"2022-02-25 01:34:24.000000000","message":"Should we abandon this now ?","commit_id":"59233e9d4c25d9065eaab83fe53f5440df7719bd"},{"author":{"_account_id":9976,"name":"Ronelle Landy","email":"rlandy@redhat.com","username":"rlandy"},"change_message_id":"54ae194a4bb6891f8a17b6459958da68841a8f46","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"4ea1ddb8_0d463458","updated":"2022-02-16 20:31:11.000000000","message":"Waiting on OVB results to see if this patch clears them","commit_id":"59233e9d4c25d9065eaab83fe53f5440df7719bd"},{"author":{"_account_id":7130,"name":"David Hill","email":"davidchill@hotmail.com","username":"dhill"},"change_message_id":"070744bdf70c034d4a7c21b6086bd50467a6e86a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"60bd64d5_ff90096a","updated":"2022-02-16 20:44:42.000000000","message":"Why is there no   \"SSLRootCertificate\": defined in the templates ?   It looks like you generate a SSL Certificate with a given issuer and never inject it in the overcloud.   That is not an issue with our patch I think.","commit_id":"59233e9d4c25d9065eaab83fe53f5440df7719bd"},{"author":{"_account_id":7130,"name":"David Hill","email":"davidchill@hotmail.com","username":"dhill"},"change_message_id":"a1ffe8796f91ec14c8f43a231b99ee857e795023","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"014ac98d_5b90fb43","updated":"2022-02-16 20:45:32.000000000","message":"You can see it here :\n\nhttps://review.rdoproject.org/zuul/build/1174dff0b6734a40acb0f093357c3b5b/log/logs/undercloud/home/zuul/inject-trust-anchor.yaml.txt.gz\n\n","commit_id":"59233e9d4c25d9065eaab83fe53f5440df7719bd"},{"author":{"_account_id":7130,"name":"David Hill","email":"davidchill@hotmail.com","username":"dhill"},"change_message_id":"8c71c91591c8fcc502c4376a70e6f0a96a316b0e","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"bf9381f9_90e99b9a","in_reply_to":"014ac98d_5b90fb43","updated":"2022-02-16 20:55:02.000000000","message":"Line 146/147:\n  OS::TripleO::NodeTLSCAData: OS::Heat::None\n  OS::TripleO::NodeTLSData: OS::Heat::None\n\nLine 203:\n  OS::TripleO::Services::CACerts: deployment/certs/ca-certs-baremetal-puppet.yaml\n\n\nand what I tested with was this:\n\n  SSLRootCertificate: |\n\nwhich the CI job is not using and using CAMap instead.   Is it possible that the CAMap is applied later on ?","commit_id":"59233e9d4c25d9065eaab83fe53f5440df7719bd"},{"author":{"_account_id":7130,"name":"David Hill","email":"davidchill@hotmail.com","username":"dhill"},"change_message_id":"2c10e9624182c229d928b2ed7a2ed42380e39016","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"c1e77d0d_4dd406b3","in_reply_to":"19c62065_d83e8978","updated":"2022-02-16 21:30:02.000000000","message":"Looks like I just got my answer here:\n\n    # NoteTLSData has been deprecated/removed in rocky and onwards\n    if tht_release in [\u0027mitaka\u0027, \u0027newton\u0027, \u0027ocata\u0027, \u0027pike\u0027, \u0027queens\u0027]:\n        output_dict[\"resource_registry\"][\"OS::TripleO::NodeTLSData\"] \u003d \\\n            \"{}/puppet/extraconfig/tls/tls-cert-inject.yaml\".format(source_dir)\n\nSo we just have to answer this question.  Is it because I run it in host_prep instead of step1 ?","commit_id":"59233e9d4c25d9065eaab83fe53f5440df7719bd"},{"author":{"_account_id":7130,"name":"David Hill","email":"davidchill@hotmail.com","username":"dhill"},"change_message_id":"958851c4b776fa6d208e8f669f7b62e25f1b7813","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"19c62065_d83e8978","in_reply_to":"bf9381f9_90e99b9a","updated":"2022-02-16 21:00:48.000000000","message":"NodeTLSCAData is injected at PreNetworkConfig and CAMap is injected as a service.  You need to fix the CI configuration to inject the CA trust certificate with SSLRootCertificate instead of using the CAMap ... unless we\u0027re deprecating SSLRootCertificate ?  If we are, this might be an issue if we need to signal using SSL before the configuration of the CACerts service.","commit_id":"59233e9d4c25d9065eaab83fe53f5440df7719bd"},{"author":{"_account_id":7130,"name":"David Hill","email":"davidchill@hotmail.com","username":"dhill"},"change_message_id":"eb4e5338578b26755b8397e9ca8ebfac87f7a91e","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"a29160a7_310bac71","in_reply_to":"c1e77d0d_4dd406b3","updated":"2022-02-16 21:47:25.000000000","message":"I suspect https://review.opendev.org/c/openstack/tripleo-heat-templates/+/829610 might be enough ... let\u0027s see what the gate keeper says.","commit_id":"59233e9d4c25d9065eaab83fe53f5440df7719bd"}]}
