)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":28223,"name":"Cedric Jeanneret","display_name":"cjeanner (Tengu)","email":"cjeanner@redhat.com","username":"cjeanner"},"change_message_id":"9493e999c826e4ef33ae54e990733aacf3df5159","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"aec8ad5e_974ecda0","updated":"2022-04-07 05:57:44.000000000","message":"recheck","commit_id":"2906b2e9f9b6238f510a35ecaea24fe8590b83d7"},{"author":{"_account_id":28223,"name":"Cedric Jeanneret","display_name":"cjeanner (Tengu)","email":"cjeanner@redhat.com","username":"cjeanner"},"change_message_id":"01d0ceb0d898a651146551649de92df8050301f1","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"0baa8411_ce38ec04","updated":"2022-04-08 12:46:28.000000000","message":"recheck","commit_id":"ec467dda1995c9a052a2324c7bc1fe0721737c9e"},{"author":{"_account_id":28223,"name":"Cedric Jeanneret","display_name":"cjeanner (Tengu)","email":"cjeanner@redhat.com","username":"cjeanner"},"change_message_id":"9a8db820a383870739604d41929802c4986c11a8","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"78693dd1_f7bd9704","updated":"2022-04-11 08:18:37.000000000","message":"recheck","commit_id":"ec467dda1995c9a052a2324c7bc1fe0721737c9e"},{"author":{"_account_id":28223,"name":"Cedric Jeanneret","display_name":"cjeanner (Tengu)","email":"cjeanner@redhat.com","username":"cjeanner"},"change_message_id":"e0ec558f11781df132f13064b3fe5f85cfc2653e","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"effa41e7_4372799f","updated":"2022-04-14 11:41:32.000000000","message":"switching back to WIP - testing something in order to NOT get the param on all nodes, in order to try to sort out Rabi\u0027s concerns.","commit_id":"283fd49f89f22e8e2ce395de048048962c8360c8"}],"common/services/role.role.j2.yaml":[{"author":{"_account_id":8833,"name":"Rabi Mishra","email":"ramishra@redhat.com","username":"rabi"},"change_message_id":"813c790a6ae5b4f5e1e1bbc9533833b963be2b6e","unresolved":true,"context_lines":[{"line_number":405,"context_line":"                name: tripleo_firewall"},{"line_number":406,"context_line":"              vars:"},{"line_number":407,"context_line":"                tripleo_firewall_rules: {get_attr: [FirewallRules, value]}"},{"line_number":408,"context_line":"                tripleo_masquerade_networks: {get_param: MasqueradeNetworks}"},{"line_number":409,"context_line":"          - {get_attr: [HostPrepTasks, value]}"},{"line_number":410,"context_line":"      pre_deploy_step_tasks: {get_attr: [PreDeployStepTasks, value]}"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"6b1fbc4d_c534adce","line":408,"range":{"start_line":408,"start_character":57,"end_line":408,"end_character":75},"updated":"2022-04-12 03:55:58.000000000","message":"Though this is only used for undercloud atm, with this if someone provides MasqueradeNetworks parameter, it would be applied to all roles.\n\nEarlier it only used to apply to roles where the service was included.","commit_id":"ec467dda1995c9a052a2324c7bc1fe0721737c9e"},{"author":{"_account_id":28223,"name":"Cedric Jeanneret","display_name":"cjeanner (Tengu)","email":"cjeanner@redhat.com","username":"cjeanner"},"change_message_id":"93fe3fce4b9c8ff57149acbdddf4bf6c926ce895","unresolved":false,"context_lines":[{"line_number":405,"context_line":"                name: tripleo_firewall"},{"line_number":406,"context_line":"              vars:"},{"line_number":407,"context_line":"                tripleo_firewall_rules: {get_attr: [FirewallRules, value]}"},{"line_number":408,"context_line":"                tripleo_masquerade_networks: {get_param: MasqueradeNetworks}"},{"line_number":409,"context_line":"          - {get_attr: [HostPrepTasks, value]}"},{"line_number":410,"context_line":"      pre_deploy_step_tasks: {get_attr: [PreDeployStepTasks, value]}"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"cfe4ab20_c75597e4","line":408,"range":{"start_line":408,"start_character":57,"end_line":408,"end_character":75},"in_reply_to":"6b1fbc4d_c534adce","updated":"2022-04-12 05:27:44.000000000","message":"Well, it\u0027s supposed to be passed in the undercloud.conf \"custom_env_files\"... If someone think it\u0027s a good idea to pass it to their overcloud deploy, that\u0027s their thing imho. And, maybe, it\u0027s not that bad to allow this in the end? Though they already have the ExtraFirewallRules (or something like that) iirc.","commit_id":"ec467dda1995c9a052a2324c7bc1fe0721737c9e"},{"author":{"_account_id":8833,"name":"Rabi Mishra","email":"ramishra@redhat.com","username":"rabi"},"change_message_id":"f7f90292b3ec83e284b5ee67b784c98dfe413f32","unresolved":false,"context_lines":[{"line_number":405,"context_line":"                name: tripleo_firewall"},{"line_number":406,"context_line":"              vars:"},{"line_number":407,"context_line":"                tripleo_firewall_rules: {get_attr: [FirewallRules, value]}"},{"line_number":408,"context_line":"                tripleo_masquerade_networks: {get_param: MasqueradeNetworks}"},{"line_number":409,"context_line":"          - {get_attr: [HostPrepTasks, value]}"},{"line_number":410,"context_line":"      pre_deploy_step_tasks: {get_attr: [PreDeployStepTasks, value]}"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"cc67762a_40efb6cf","line":408,"range":{"start_line":408,"start_character":57,"end_line":408,"end_character":75},"in_reply_to":"9ee335fc_798cbc00","updated":"2022-04-14 10:00:08.000000000","message":"\u003e Anyone could override the OS::Heat::None for that service and get it deployed anywhere as well\n\nIt won\u0027t, unless role_data has that service for the role[1], so the behavior after the change is not the same as before.\n\n[1] https://github.com/openstack/tripleo-heat-templates/blob/master/roles_data_undercloud.yaml#L41","commit_id":"ec467dda1995c9a052a2324c7bc1fe0721737c9e"},{"author":{"_account_id":8833,"name":"Rabi Mishra","email":"ramishra@redhat.com","username":"rabi"},"change_message_id":"66c6159df2dafd9769c062480d056128039f06bd","unresolved":false,"context_lines":[{"line_number":405,"context_line":"                name: tripleo_firewall"},{"line_number":406,"context_line":"              vars:"},{"line_number":407,"context_line":"                tripleo_firewall_rules: {get_attr: [FirewallRules, value]}"},{"line_number":408,"context_line":"                tripleo_masquerade_networks: {get_param: MasqueradeNetworks}"},{"line_number":409,"context_line":"          - {get_attr: [HostPrepTasks, value]}"},{"line_number":410,"context_line":"      pre_deploy_step_tasks: {get_attr: [PreDeployStepTasks, value]}"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"da477c7c_12297234","line":408,"range":{"start_line":408,"start_character":57,"end_line":408,"end_character":75},"in_reply_to":"cfe4ab20_c75597e4","updated":"2022-04-12 05:32:47.000000000","message":"Talking from only THT perspective, I don\u0027t think it\u0027s a good idea to change a parameter which was role specific (though indirectly by specifying the service for a role) and make it apply to all roles when specified.","commit_id":"ec467dda1995c9a052a2324c7bc1fe0721737c9e"},{"author":{"_account_id":28223,"name":"Cedric Jeanneret","display_name":"cjeanner (Tengu)","email":"cjeanner@redhat.com","username":"cjeanner"},"change_message_id":"9c307c715e5644cec8844a990d8dde73bf5906aa","unresolved":false,"context_lines":[{"line_number":405,"context_line":"                name: tripleo_firewall"},{"line_number":406,"context_line":"              vars:"},{"line_number":407,"context_line":"                tripleo_firewall_rules: {get_attr: [FirewallRules, value]}"},{"line_number":408,"context_line":"                tripleo_masquerade_networks: {get_param: MasqueradeNetworks}"},{"line_number":409,"context_line":"          - {get_attr: [HostPrepTasks, value]}"},{"line_number":410,"context_line":"      pre_deploy_step_tasks: {get_attr: [PreDeployStepTasks, value]}"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"9ee335fc_798cbc00","line":408,"range":{"start_line":408,"start_character":57,"end_line":408,"end_character":75},"in_reply_to":"da477c7c_12297234","updated":"2022-04-14 09:14:37.000000000","message":"Anyone could override the OS::Heat::None for that service and get it deployed anywhere as well. Not sure there\u0027s an actual big difference here. Both require an Operator to change values - the way it\u0027s done is a bit different (maybe the one I\u0027m proposing is easier), but I don\u0027t think it\u0027s a bad change. Of course, if there\u0027s another way, feel free to point it. Guess we could keep the service and inject in the ansible_group_vars the value we want, but I\u0027m not 100% sure this is really better...","commit_id":"ec467dda1995c9a052a2324c7bc1fe0721737c9e"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"28113423743efa9c29a53507ffccbea79e0c3833","unresolved":true,"context_lines":[{"line_number":446,"context_line":"      host_prep_tasks:"},{"line_number":447,"context_line":"        list_concat:"},{"line_number":448,"context_line":"          - {get_attr: [HostFirewallTasks, value]}"},{"line_number":449,"context_line":"{%- if role.name \u003d\u003d \u0027Undercloud\u0027 %}"},{"line_number":450,"context_line":"          - - name: Run firewall role"},{"line_number":451,"context_line":"              include_role:"},{"line_number":452,"context_line":"                name: tripleo_firewall"},{"line_number":453,"context_line":"              vars:"},{"line_number":454,"context_line":"                tripleo_masquerade_networks: {get_param: MasqueradeNetworks}"},{"line_number":455,"context_line":"{%- endif %}"},{"line_number":456,"context_line":"          - {get_attr: [HostPrepTasks, value]}"},{"line_number":457,"context_line":"      pre_deploy_step_tasks: {get_attr: [PreDeployStepTasks, value]}"}],"source_content_type":"text/x-yaml","patch_set":13,"id":"a1313586_fd7ba5bf","line":455,"range":{"start_line":449,"start_character":0,"end_line":455,"end_character":12},"updated":"2022-05-12 06:56:07.000000000","message":"This task has been migrated to deployment/tripleo-firewall/tripleo-firewall-baremetal-ansible.yaml and we should avoid adding this hear.\n\nIMO what we\u0027d need are\n- Add MasqueradeNetworks to the firewall resource and pass the parameter as tripleo_masquerade_networks\n- Implement a toggle in tripleo-ansible to disable management of masquerade rules\n- Set that toggle in masquerade-networks-baremetal-puppet.yaml to use puppet instead of ansible to manage masquerade rules.","commit_id":"087ceb63c0fcab36ad253528dd327e62c4ee8ab9"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"cee23e5c52ca4dbd575292cf07572ff366bdaf3f","unresolved":true,"context_lines":[{"line_number":446,"context_line":"      host_prep_tasks:"},{"line_number":447,"context_line":"        list_concat:"},{"line_number":448,"context_line":"          - {get_attr: [HostFirewallTasks, value]}"},{"line_number":449,"context_line":"{%- if role.name \u003d\u003d \u0027Undercloud\u0027 %}"},{"line_number":450,"context_line":"          - - name: Run firewall role"},{"line_number":451,"context_line":"              include_role:"},{"line_number":452,"context_line":"                name: tripleo_firewall"},{"line_number":453,"context_line":"              vars:"},{"line_number":454,"context_line":"                tripleo_masquerade_networks: {get_param: MasqueradeNetworks}"},{"line_number":455,"context_line":"{%- endif %}"},{"line_number":456,"context_line":"          - {get_attr: [HostPrepTasks, value]}"},{"line_number":457,"context_line":"      pre_deploy_step_tasks: {get_attr: [PreDeployStepTasks, value]}"}],"source_content_type":"text/x-yaml","patch_set":13,"id":"f403505a_4c318cf7","line":455,"range":{"start_line":449,"start_character":0,"end_line":455,"end_character":12},"in_reply_to":"a1313586_fd7ba5bf","updated":"2022-05-12 07:04:39.000000000","message":"Alternatively you can add restore the masquerade service and create masquerade-networks-baremetal-ansibe.yaml which just set the tripleo_masquerade_networks variable using ansible_group_vars .","commit_id":"087ceb63c0fcab36ad253528dd327e62c4ee8ab9"}],"deployment/masquerade-networks/masquerade-networks-baremetal-ansible.yaml":[{"author":{"_account_id":8833,"name":"Rabi Mishra","email":"ramishra@redhat.com","username":"rabi"},"change_message_id":"84dac09458dc2180296a843ff7a362d6d7f205b7","unresolved":true,"context_lines":[{"line_number":1,"context_line":"heat_template_version: wallaby"},{"line_number":2,"context_line":""},{"line_number":3,"context_line":"description: \u003e"},{"line_number":4,"context_line":"  Configure TripleO Masquerade networks with Ansible."}],"source_content_type":"text/x-yaml","patch_set":1,"id":"6e6247c4_5c2fcc10","line":1,"range":{"start_line":1,"start_character":0,"end_line":1,"end_character":30},"updated":"2022-04-07 03:20:17.000000000","message":"This service is redundant as you\u0027re using the THT parameter directly in common/services/role.role.j2.yaml.\n\n- I think we can convert the THT parameter MasqueradeNetworks role_specific\n- Or keep the service for backward compatibility and get the data from role_data/ServiceChain like others[1].\n\n[1] https://github.com/openstack/tripleo-heat-templates/blob/master/common/services/role.role.j2.yaml#L352","commit_id":"dfff4f4ff20faacbe866a9c00a625d6e476d7bfb"},{"author":{"_account_id":28223,"name":"Cedric Jeanneret","display_name":"cjeanner (Tengu)","email":"cjeanner@redhat.com","username":"cjeanner"},"change_message_id":"484b0fb83171a3e47a9fcf4689f1ca7b3ecd1c5c","unresolved":false,"context_lines":[{"line_number":1,"context_line":"heat_template_version: wallaby"},{"line_number":2,"context_line":""},{"line_number":3,"context_line":"description: \u003e"},{"line_number":4,"context_line":"  Configure TripleO Masquerade networks with Ansible."}],"source_content_type":"text/x-yaml","patch_set":1,"id":"8caeb84c_0b06f0a5","line":1,"range":{"start_line":1,"start_character":0,"end_line":1,"end_character":30},"in_reply_to":"6e6247c4_5c2fcc10","updated":"2022-04-07 04:40:04.000000000","message":"Removing the service makes more sense imho - the -puppet one is moved to \"deprecated\".\n\naaannnd I just did it wrong and didn\u0027t clean correctly in my last patch. Dang.","commit_id":"dfff4f4ff20faacbe866a9c00a625d6e476d7bfb"}],"releasenotes/notes/hiera-override-masquerade-a76dd47f15577150.yaml":[{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"8000047402296eea968c030af80737c7ede0ce77","unresolved":true,"context_lines":[{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    We cannot override the masquerade_networks using hieradata_override in the"},{"line_number":5,"context_line":"    undercloud.conf."},{"line_number":6,"context_line":"    We now must provide a custom env file, using custom_env_file and passing"},{"line_number":7,"context_line":"    the hash through MasqueradeNetworks parameter."},{"line_number":8,"context_line":"deprecations:"},{"line_number":9,"context_line":"  - |"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"ea956be8_4b997859","line":6,"range":{"start_line":6,"start_character":4,"end_line":6,"end_character":41},"updated":"2022-04-14 09:27:21.000000000","message":"same question I have here, where is that env file (not the CI only one)?","commit_id":"141b59c3e5743233b44e2e810bc400960beb54b0"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"fc622a62cfa9ecd31de707c723f670385bcb804e","unresolved":true,"context_lines":[{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    We cannot override the masquerade_networks using hieradata_override in the"},{"line_number":5,"context_line":"    undercloud.conf."},{"line_number":6,"context_line":"    We now must provide a custom env file, using custom_env_file and passing"},{"line_number":7,"context_line":"    the hash through MasqueradeNetworks parameter."},{"line_number":8,"context_line":"deprecations:"},{"line_number":9,"context_line":"  - |"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"bf24f310_0d5e230c","line":6,"range":{"start_line":6,"start_character":4,"end_line":6,"end_character":41},"in_reply_to":"bb813071_a04a8d9d","updated":"2022-04-14 11:38:32.000000000","message":"ok I see, please rephrase to a user should provide that file, if needed","commit_id":"141b59c3e5743233b44e2e810bc400960beb54b0"},{"author":{"_account_id":28223,"name":"Cedric Jeanneret","display_name":"cjeanner (Tengu)","email":"cjeanner@redhat.com","username":"cjeanner"},"change_message_id":"3f8dae64c44471c8887e86640acae7270240717a","unresolved":false,"context_lines":[{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    We cannot override the masquerade_networks using hieradata_override in the"},{"line_number":5,"context_line":"    undercloud.conf."},{"line_number":6,"context_line":"    We now must provide a custom env file, using custom_env_file and passing"},{"line_number":7,"context_line":"    the hash through MasqueradeNetworks parameter."},{"line_number":8,"context_line":"deprecations:"},{"line_number":9,"context_line":"  - |"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"9bddfc59_8c5f425f","line":6,"range":{"start_line":6,"start_character":4,"end_line":6,"end_character":41},"in_reply_to":"bf24f310_0d5e230c","updated":"2022-04-14 11:41:56.000000000","message":"Done","commit_id":"141b59c3e5743233b44e2e810bc400960beb54b0"},{"author":{"_account_id":28223,"name":"Cedric Jeanneret","display_name":"cjeanner (Tengu)","email":"cjeanner@redhat.com","username":"cjeanner"},"change_message_id":"63e491f76299d25c13b99e9a15312f708a391406","unresolved":true,"context_lines":[{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    We cannot override the masquerade_networks using hieradata_override in the"},{"line_number":5,"context_line":"    undercloud.conf."},{"line_number":6,"context_line":"    We now must provide a custom env file, using custom_env_file and passing"},{"line_number":7,"context_line":"    the hash through MasqueradeNetworks parameter."},{"line_number":8,"context_line":"deprecations:"},{"line_number":9,"context_line":"  - |"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"bb813071_a04a8d9d","line":6,"range":{"start_line":6,"start_character":4,"end_line":6,"end_character":41},"in_reply_to":"ea956be8_4b997859","updated":"2022-04-14 09:43:11.000000000","message":"Until now, it was in a custom hieradata_override passed in the undercloud.conf\nFrom now on, it\u0027s a yaml, still within the undercloud.conf, \"custom_env_files\".\n\nNote this is only when you want to override the default value. I didn\u0027t match anything about that in the docs - but I may have missed it?","commit_id":"141b59c3e5743233b44e2e810bc400960beb54b0"}]}
