)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":7130,"name":"David Hill","email":"davidchill@hotmail.com","username":"dhill"},"change_message_id":"67df7655768a30e3034cf077b3b30f715e8e91a4","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"91c3ee9a_f1bf0ec8","updated":"2022-02-16 23:16:24.000000000","message":"recheck\n","commit_id":"fff2f6310256993e3d8dfbb59a8f1493786edeb6"},{"author":{"_account_id":9976,"name":"Ronelle Landy","email":"rlandy@redhat.com","username":"rlandy"},"change_message_id":"fd02b96fc9c376e4b019165a12adb9949ad23db7","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"b7161ce0_4f863cc9","updated":"2022-02-17 11:48:45.000000000","message":"passes ovb now","commit_id":"3cbda551493a80d3a0f1f05acddfde6200fd7e5b"},{"author":{"_account_id":8367,"name":"Arx Cruz","email":"arxcruz@redhat.com","username":"arxcruz"},"change_message_id":"767d05aa729365b9b547cc14114c5304ad27b3a5","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"242bdb6d_5979c974","updated":"2022-02-17 09:01:35.000000000","message":"recheck","commit_id":"3cbda551493a80d3a0f1f05acddfde6200fd7e5b"},{"author":{"_account_id":8833,"name":"Rabi Mishra","email":"ramishra@redhat.com","username":"rabi"},"change_message_id":"fe32dd9d3eb5fafa6dfe722b242273dc76ab23f7","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"fff21134_674a1eb0","updated":"2022-02-17 12:46:25.000000000","message":"LGTM and seems to fix the issue. Probably need some feedback from security folks on doing the validation in step-2.","commit_id":"64a19091ab55202e6c37fa083035add2b42e9d5d"},{"author":{"_account_id":8449,"name":"Marios Andreou","email":"marios.andreou@gmail.com","username":"marios"},"change_message_id":"3f3bb9f3f3b18cb9d24e9ec2e2948b583a472668","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"1080b0c0_912d936c","updated":"2022-02-18 07:54:37.000000000","message":"recheck\n\nnot sure if this is a thing yet only one fail so far @ https://zuul.opendev.org/t/openstack/builds?job_name\u003dtripleo-ci-centos-9-scenario012-standalone","commit_id":"64a19091ab55202e6c37fa083035add2b42e9d5d"}],"deployment/haproxy/haproxy-pacemaker-puppet.yaml":[{"author":{"_account_id":8833,"name":"Rabi Mishra","email":"ramishra@redhat.com","username":"rabi"},"change_message_id":"3ec6d3ee13445ac968fb40ebc00c09dbd25a5e7f","unresolved":true,"context_lines":[{"line_number":342,"context_line":"            - name: Validate SSLCertificate is properly defined if PublicSSLCertificateAutogenerated is False"},{"line_number":343,"context_line":"              when:"},{"line_number":344,"context_line":"                - {get_param: EnablePublicTLS}"},{"line_number":345,"context_line":"                - step|int \u003d\u003d 2"},{"line_number":346,"context_line":"              vars:"},{"line_number":347,"context_line":"                ssl_cert: {get_param: SSLCertificate}"},{"line_number":348,"context_line":"                auto_gen: {get_param: PublicSSLCertificateAutogenerated}"}],"source_content_type":"text/x-yaml","patch_set":8,"id":"cce15d27_5db0fc1c","line":345,"range":{"start_line":345,"start_character":16,"end_line":345,"end_character":31},"updated":"2022-02-17 12:05:49.000000000","message":"step2?","commit_id":"3cbda551493a80d3a0f1f05acddfde6200fd7e5b"},{"author":{"_account_id":7130,"name":"David Hill","email":"davidchill@hotmail.com","username":"dhill"},"change_message_id":"71420d7c447d4d0bdb58ea28cdc07ef6c268b317","unresolved":false,"context_lines":[{"line_number":342,"context_line":"            - name: Validate SSLCertificate is properly defined if PublicSSLCertificateAutogenerated is False"},{"line_number":343,"context_line":"              when:"},{"line_number":344,"context_line":"                - {get_param: EnablePublicTLS}"},{"line_number":345,"context_line":"                - step|int \u003d\u003d 2"},{"line_number":346,"context_line":"              vars:"},{"line_number":347,"context_line":"                ssl_cert: {get_param: SSLCertificate}"},{"line_number":348,"context_line":"                auto_gen: {get_param: PublicSSLCertificateAutogenerated}"}],"source_content_type":"text/x-yaml","patch_set":8,"id":"8616cff1_865d3e74","line":345,"range":{"start_line":345,"start_character":16,"end_line":345,"end_character":31},"in_reply_to":"67530ab0_5ee91949","updated":"2022-02-17 12:28:59.000000000","message":"Also, if we run it in step1, CACerts hasn\u0027t been executed yet... but step2 solves this.   We\u0027d get the same failure as the customer had at step3 which might saves us some minutes still before the keystone/cinder-manage failure of step3.   Ideally, again, if we still had the PreNetworkConfig hook, we could run it in host_prep which comes way faster than step2 ... :\u0027(","commit_id":"3cbda551493a80d3a0f1f05acddfde6200fd7e5b"},{"author":{"_account_id":7130,"name":"David Hill","email":"davidchill@hotmail.com","username":"dhill"},"change_message_id":"32e538327a03a8b87d6f9ec890e6e93e3fed7662","unresolved":false,"context_lines":[{"line_number":342,"context_line":"            - name: Validate SSLCertificate is properly defined if PublicSSLCertificateAutogenerated is False"},{"line_number":343,"context_line":"              when:"},{"line_number":344,"context_line":"                - {get_param: EnablePublicTLS}"},{"line_number":345,"context_line":"                - step|int \u003d\u003d 2"},{"line_number":346,"context_line":"              vars:"},{"line_number":347,"context_line":"                ssl_cert: {get_param: SSLCertificate}"},{"line_number":348,"context_line":"                auto_gen: {get_param: PublicSSLCertificateAutogenerated}"}],"source_content_type":"text/x-yaml","patch_set":8,"id":"67530ab0_5ee91949","line":345,"range":{"start_line":345,"start_character":16,"end_line":345,"end_character":31},"in_reply_to":"cce15d27_5db0fc1c","updated":"2022-02-17 12:27:23.000000000","message":"Yes .  I wanted to run it in host_prep or even step1 so the failure comes earlier but if we do that, CACerts puppet manifests haven\u0027t been executed yet so this validation failed if the CA is missing and is not a trusted CA.  It worked in Train in my lab but I was using NodeTLSCaCerts which was run just after PreNetworkConfig ... ideally, those certificates validation should happen even before host_prep and fail the stack if you provide invalid certificiates but we\u0027re far from a perfect world.","commit_id":"3cbda551493a80d3a0f1f05acddfde6200fd7e5b"}]}
