)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":21129,"name":"Alan Bishop","email":"abishopsweng@gmail.com","username":"ASBishop","status":"ex Red Hat"},"change_message_id":"39a8b2f77bd96ad9ee9e9d40858ddcae4a705c3d","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"553ce731_42682487","updated":"2022-05-19 16:59:18.000000000","message":"Any reviewers have thoughts on this? I\u0027d like to see it move forward.","commit_id":"e0a3385657081cbeffd298e191e609cf30a5d7a6"},{"author":{"_account_id":21129,"name":"Alan Bishop","email":"abishopsweng@gmail.com","username":"ASBishop","status":"ex Red Hat"},"change_message_id":"fbc01d036d9c2b17596233c8efd98aa83cfa8257","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"065868ed_c6a1ed85","updated":"2022-05-11 00:36:27.000000000","message":"I still thing further cleanup is warranted, but this is a good interim patch that moves things forward. This mainly helps with DCN deployments that use non-pcmk haproxy.","commit_id":"e0a3385657081cbeffd298e191e609cf30a5d7a6"}],"deployment/haproxy/haproxy-container-puppet.yaml":[{"author":{"_account_id":21129,"name":"Alan Bishop","email":"abishopsweng@gmail.com","username":"ASBishop","status":"ex Red Hat"},"change_message_id":"93232ccc22edc6d59c4483c4cf02dc2218508cae","unresolved":true,"context_lines":[{"line_number":111,"context_line":"    default: true"},{"line_number":112,"context_line":"    description: Whether or not to enable the HAProxy stats interface."},{"line_number":113,"context_line":"    type: boolean"},{"line_number":114,"context_line":"  InternalTLSCRLPEMFile:"},{"line_number":115,"context_line":"    default: \u0027/etc/pki/CA/crl/overcloud-crl.pem\u0027"},{"line_number":116,"context_line":"    type: string"},{"line_number":117,"context_line":"    description: Specifies the default CRL PEM file to use for revocation if"},{"line_number":118,"context_line":"                 TLS is used for services in the internal network."},{"line_number":119,"context_line":"  InternalTLSCRLPEMDir:"},{"line_number":120,"context_line":"    default: \u0027/etc/pki/CA/crl/\u0027"},{"line_number":121,"context_line":"    type: string"},{"line_number":122,"context_line":"    description: The directory of the CRL PEM file to be mounted."},{"line_number":123,"context_line":""},{"line_number":124,"context_line":"conditions:"},{"line_number":125,"context_line":"  public_tls_enabled:"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"9e48d0a3_2c0423e9","line":122,"range":{"start_line":114,"start_character":0,"end_line":122,"end_character":65},"updated":"2022-05-04 15:58:54.000000000","message":"Can (should?) these parameters be deprecated? See comments below.","commit_id":"e0a3385657081cbeffd298e191e609cf30a5d7a6"},{"author":{"_account_id":21129,"name":"Alan Bishop","email":"abishopsweng@gmail.com","username":"ASBishop","status":"ex Red Hat"},"change_message_id":"93232ccc22edc6d59c4483c4cf02dc2218508cae","unresolved":true,"context_lines":[{"line_number":201,"context_line":"                params:"},{"line_number":202,"context_line":"                  $NETWORK: {get_param: [ServiceNetMap, HaproxyNetwork]}"},{"line_number":203,"context_line":"            tripleo::haproxy::redis_password: {get_param: RedisPassword}"},{"line_number":204,"context_line":"            # disable the use CRL file until we can restart the container when the file expires"},{"line_number":205,"context_line":"            tripleo::haproxy::crl_file: null"},{"line_number":206,"context_line":"            tripleo::haproxy::haproxy_stats: {get_param: HAProxyStatsEnabled}"},{"line_number":207,"context_line":"            enable_load_balancer: {get_param: EnableLoadBalancer}"},{"line_number":208,"context_line":"            tripleo::profile::base::haproxy::certificates_specs:"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"91418859_e07d59e7","line":205,"range":{"start_line":204,"start_character":0,"end_line":205,"end_character":44},"updated":"2022-05-04 15:58:54.000000000","message":"The puppet-tripleo parameter [1] defaults to undef, so use of a CRL file is disabled by default. I think you can just delete these lines.\n\nThis, in turn, means the InternalTLSCRLPEMFile parameter is no longer used. I don\u0027t understand this CRL stuff, but if both the regular and pcmk templates aren\u0027t configuring a CRL file then that suggests more cleanup is warranted. \n\nIf it\u0027s OK to totally disable use of the CRL file, then I assume something else is taking its place? Can anyone confirm?","commit_id":"e0a3385657081cbeffd298e191e609cf30a5d7a6"},{"author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"change_message_id":"ced5a45c93a102c7dc49859669f7037d19c6769d","unresolved":true,"context_lines":[{"line_number":201,"context_line":"                params:"},{"line_number":202,"context_line":"                  $NETWORK: {get_param: [ServiceNetMap, HaproxyNetwork]}"},{"line_number":203,"context_line":"            tripleo::haproxy::redis_password: {get_param: RedisPassword}"},{"line_number":204,"context_line":"            # disable the use CRL file until we can restart the container when the file expires"},{"line_number":205,"context_line":"            tripleo::haproxy::crl_file: null"},{"line_number":206,"context_line":"            tripleo::haproxy::haproxy_stats: {get_param: HAProxyStatsEnabled}"},{"line_number":207,"context_line":"            enable_load_balancer: {get_param: EnableLoadBalancer}"},{"line_number":208,"context_line":"            tripleo::profile::base::haproxy::certificates_specs:"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"3d4914df_e14fe83c","line":205,"range":{"start_line":204,"start_character":0,"end_line":205,"end_character":44},"in_reply_to":"91418859_e07d59e7","updated":"2022-05-19 19:46:04.000000000","message":"It looks like the CRL file (and cron job) was removed together with migrating from puppet to ansible for certmonger requests (commit 48832c961cd6866698c1e7585634381c43decc66).\n\nOCSP looks like an alternative, but I\u0027m not 100% sure all parts we need are implemented in haproxy and tls clients. Even if they support it, we would probably need to do OCSP stapling in haproxy, so that there is no performance impact. This would also need a cron job, making the configuration pretty similar, with all the same (if not more) points of failure.\n\nSo I think the way to go is to reinstate the CRL file.","commit_id":"e0a3385657081cbeffd298e191e609cf30a5d7a6"},{"author":{"_account_id":21129,"name":"Alan Bishop","email":"abishopsweng@gmail.com","username":"ASBishop","status":"ex Red Hat"},"change_message_id":"93232ccc22edc6d59c4483c4cf02dc2218508cae","unresolved":true,"context_lines":[{"line_number":249,"context_line":"                  - - {get_param: InternalTLSCAFile}"},{"line_number":250,"context_line":"                    - {get_param: InternalTLSCAFile}"},{"line_number":251,"context_line":"                    - \u0027ro,shared\u0027"},{"line_number":252,"context_line":"              - list_join:"},{"line_number":253,"context_line":"                  - \u0027:\u0027"},{"line_number":254,"context_line":"                  - - {get_param: InternalTLSCRLPEMDir}"},{"line_number":255,"context_line":"                    - {get_param: InternalTLSCRLPEMDir}"},{"line_number":256,"context_line":"                    - \u0027ro,shared\u0027"},{"line_number":257,"context_line":"      kolla_config:"},{"line_number":258,"context_line":"        /var/lib/kolla/config_files/haproxy.json:"},{"line_number":259,"context_line":"          # HAProxy 1.8 doesn\u0027t ship haproxy-systemd-wrapper, we have"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"0c3c95ef_b5b5f66d","line":256,"range":{"start_line":252,"start_character":0,"end_line":256,"end_character":33},"updated":"2022-05-04 15:58:54.000000000","message":"This is more of the stuff that is no longer relevant if we\u0027re not using the CRL file anymore.","commit_id":"e0a3385657081cbeffd298e191e609cf30a5d7a6"},{"author":{"_account_id":21129,"name":"Alan Bishop","email":"abishopsweng@gmail.com","username":"ASBishop","status":"ex Red Hat"},"change_message_id":"93232ccc22edc6d59c4483c4cf02dc2218508cae","unresolved":true,"context_lines":[{"line_number":311,"context_line":"                    - {get_param: EnableInternalTLS}"},{"line_number":312,"context_line":"                    - - /etc/pki/tls/certs/haproxy:/var/lib/kolla/config_files/src-tls/etc/pki/tls/certs/haproxy:ro,shared"},{"line_number":313,"context_line":"                      - /etc/pki/tls/private/haproxy:/var/lib/kolla/config_files/src-tls/etc/pki/tls/private/haproxy:ro,shared"},{"line_number":314,"context_line":"                      - list_join:"},{"line_number":315,"context_line":"                          - \u0027:\u0027"},{"line_number":316,"context_line":"                          - - {get_param: InternalTLSCRLPEMDir}"},{"line_number":317,"context_line":"                            - {get_param: InternalTLSCRLPEMDir}"},{"line_number":318,"context_line":"                            - \u0027ro\u0027"},{"line_number":319,"context_line":"              environment:"},{"line_number":320,"context_line":"                KOLLA_CONFIG_STRATEGY: COPY_ALWAYS"},{"line_number":321,"context_line":"      deploy_steps_tasks:"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"022aa1aa_060353fa","line":318,"range":{"start_line":314,"start_character":0,"end_line":318,"end_character":34},"updated":"2022-05-04 15:58:54.000000000","message":"More stuff that is no longer relevant?","commit_id":"e0a3385657081cbeffd298e191e609cf30a5d7a6"}]}
