)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":8833,"name":"Rabi Mishra","email":"ramishra@redhat.com","username":"rabi"},"change_message_id":"c8d6093a5d080d5c173028985db9566014bf068e","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"4f8ee1db_af0b8062","updated":"2022-06-27 05:45:18.000000000","message":"I think it\u0027s still there in puppet https://github.com/openstack/puppet-heat/blob/master/manifests/keystone/auth.pp#L169 (not used correctly in THT though)\n\nIf we want to drop it, we should cleanup from puppet completely.","commit_id":"4f942b515d97d705db5f2a51d323f1e46309fe90"},{"author":{"_account_id":30073,"name":"Brendan Shephard","email":"bshephar@bne-home.net","username":"bshephar"},"change_message_id":"469ba059d0fa86cdc52f3a8b596385c2c954f593","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"8f0e1634_278c5dfe","updated":"2022-06-27 05:13:03.000000000","message":"No point in deprecating if it is already not working.","commit_id":"4f942b515d97d705db5f2a51d323f1e46309fe90"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"c08626950f6d47978a1b6c9bf5bb6a276c273d08","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"b1362ad4_e6c0100e","in_reply_to":"28ba910c_5cbbdcf7","updated":"2022-06-27 07:03:12.000000000","message":"I\u0027ve updated the patch to fix the ignore parameter and allow customizing trustor roles.","commit_id":"4f942b515d97d705db5f2a51d323f1e46309fe90"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"632fcb2efa0e37a4af4a94e2bcd75cc11127ce07","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"89ed872a_647b281d","in_reply_to":"4f8ee1db_af0b8062","updated":"2022-06-27 06:11:45.000000000","message":"I\u0027m afraid I didn\u0027t get your point. I disagree with removing the feature from puppet-keystone because usage of trusts_delegated_roles is still valid in heat. Removal from puppet-keystone should be determined independently from TripleO, IMO.\n\nIt\u0027s true that the implementation is still there, but tripleo is not using it. We hardcode trusts_delegated_roles by [] so even if we fix role creation (which should be implemented by tripleo-ansible now), the created role is never used actually.","commit_id":"4f942b515d97d705db5f2a51d323f1e46309fe90"},{"author":{"_account_id":8833,"name":"Rabi Mishra","email":"ramishra@redhat.com","username":"rabi"},"change_message_id":"3d3ef60701e5c45aabc1943ca99e1085504ca235","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"28ba910c_5cbbdcf7","in_reply_to":"89ed872a_647b281d","updated":"2022-06-27 06:19:45.000000000","message":"That\u0027s what I\u0027m saying. If we want to keep the feature in puppet use it in THT, Don\u0027t hardcode trusts_delegated_roles in THT to [] and use the feature to create  roles (if not existing) as there may be a case some deployments that won\u0027t delegate all exisiting roles to the trustee (which is is the default).\n\nHowever, I don\u0027t see custom trusts_delegated_roles being used by anyone.","commit_id":"4f942b515d97d705db5f2a51d323f1e46309fe90"}],"deployment/heat/heat-api-container-puppet.yaml":[{"author":{"_account_id":8833,"name":"Rabi Mishra","email":"ramishra@redhat.com","username":"rabi"},"change_message_id":"5c7ed37bf5cc19c75f65b5d8fb7cd23e41f6268e","unresolved":true,"context_lines":[{"line_number":85,"context_line":"    description: Create delegated roles"},{"line_number":86,"context_line":"  HeatDelegatedRoles:"},{"line_number":87,"context_line":"    type: comma_delimited_list"},{"line_number":88,"context_line":"    default: \u0027heat_stack_owner\u0027"},{"line_number":89,"context_line":"    descrpiton: List of trustor roles to be delegated to heat."},{"line_number":90,"context_line":""},{"line_number":91,"context_line":"conditions:"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"2a11b255_cbe42304","line":88,"range":{"start_line":88,"start_character":13,"end_line":88,"end_character":31},"updated":"2022-06-27 08:15:47.000000000","message":"Leave it [].. There is no heat_stack_owner role.","commit_id":"d148c3113482a473086d61184d73007750f527e2"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"3e19b91371c257d8ba1c055082c84a5ecc0e72d6","unresolved":false,"context_lines":[{"line_number":85,"context_line":"    description: Create delegated roles"},{"line_number":86,"context_line":"  HeatDelegatedRoles:"},{"line_number":87,"context_line":"    type: comma_delimited_list"},{"line_number":88,"context_line":"    default: \u0027heat_stack_owner\u0027"},{"line_number":89,"context_line":"    descrpiton: List of trustor roles to be delegated to heat."},{"line_number":90,"context_line":""},{"line_number":91,"context_line":"conditions:"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"7910237f_1066ff6a","line":88,"range":{"start_line":88,"start_character":13,"end_line":88,"end_character":31},"in_reply_to":"2a11b255_cbe42304","updated":"2022-06-27 12:06:11.000000000","message":"Done","commit_id":"d148c3113482a473086d61184d73007750f527e2"},{"author":{"_account_id":8833,"name":"Rabi Mishra","email":"ramishra@redhat.com","username":"rabi"},"change_message_id":"83c651d0df3f68144f5632564357d2bd3b4dff09","unresolved":true,"context_lines":[{"line_number":86,"context_line":"  HeatDelegatedRoles:"},{"line_number":87,"context_line":"    type: comma_delimited_list"},{"line_number":88,"context_line":"    default: \u0027heat_stack_owner\u0027"},{"line_number":89,"context_line":"    descrpiton: List of trustor roles to be delegated to heat."},{"line_number":90,"context_line":""},{"line_number":91,"context_line":"conditions:"},{"line_number":92,"context_line":"  heat_workers_set:"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"7ed29ead_12fa30df","line":89,"range":{"start_line":89,"start_character":4,"end_line":89,"end_character":15},"updated":"2022-06-27 09:54:44.000000000","message":"typo","commit_id":"d148c3113482a473086d61184d73007750f527e2"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"3e19b91371c257d8ba1c055082c84a5ecc0e72d6","unresolved":false,"context_lines":[{"line_number":86,"context_line":"  HeatDelegatedRoles:"},{"line_number":87,"context_line":"    type: comma_delimited_list"},{"line_number":88,"context_line":"    default: \u0027heat_stack_owner\u0027"},{"line_number":89,"context_line":"    descrpiton: List of trustor roles to be delegated to heat."},{"line_number":90,"context_line":""},{"line_number":91,"context_line":"conditions:"},{"line_number":92,"context_line":"  heat_workers_set:"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"ac22121b_5394714c","line":89,"range":{"start_line":89,"start_character":4,"end_line":89,"end_character":15},"in_reply_to":"7ed29ead_12fa30df","updated":"2022-06-27 12:06:11.000000000","message":"Done","commit_id":"d148c3113482a473086d61184d73007750f527e2"},{"author":{"_account_id":8833,"name":"Rabi Mishra","email":"ramishra@redhat.com","username":"rabi"},"change_message_id":"271bd85755c43d393d0fb44601b9d03f8b36be15","unresolved":true,"context_lines":[{"line_number":172,"context_line":"          roles:"},{"line_number":173,"context_line":"            list_concat:"},{"line_number":174,"context_line":"              - - heat_stack_user"},{"line_number":175,"context_line":"              - if:"},{"line_number":176,"context_line":"                  - {get_param: HeatConfigureDelegatedRoles}"},{"line_number":177,"context_line":"                  - {get_param: HeatDelegatedRoles}"},{"line_number":178,"context_line":"          domains:"},{"line_number":179,"context_line":"            - heat_stack"},{"line_number":180,"context_line":"      monitoring_subscription: {get_param: MonitoringSubscriptionHeatApi}"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"21a7be21_c048b8ad","line":177,"range":{"start_line":175,"start_character":0,"end_line":177,"end_character":51},"updated":"2022-06-27 07:55:56.000000000","message":"Doesn\u0027t https://github.com/openstack/puppet-heat/blob/master/manifests/keystone/auth.pp#L169-L176 take care of that?","commit_id":"d148c3113482a473086d61184d73007750f527e2"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"8b21d83cb8dc7edd7cb40d95c387256bca9bc1f9","unresolved":true,"context_lines":[{"line_number":172,"context_line":"          roles:"},{"line_number":173,"context_line":"            list_concat:"},{"line_number":174,"context_line":"              - - heat_stack_user"},{"line_number":175,"context_line":"              - if:"},{"line_number":176,"context_line":"                  - {get_param: HeatConfigureDelegatedRoles}"},{"line_number":177,"context_line":"                  - {get_param: HeatDelegatedRoles}"},{"line_number":178,"context_line":"          domains:"},{"line_number":179,"context_line":"            - heat_stack"},{"line_number":180,"context_line":"      monitoring_subscription: {get_param: MonitoringSubscriptionHeatApi}"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"25ce6964_80e475c5","line":177,"range":{"start_line":175,"start_character":0,"end_line":177,"end_character":51},"in_reply_to":"21a7be21_c048b8ad","updated":"2022-06-27 08:04:21.000000000","message":"We no longer enable any keystone_* resources in puppet and using ansible to manage roles. So that logic in puppet-heat is no longer used we should customize ansible var to create the additional roles.\n\nWhat we still use from puppet is the modification of heat.conf to configure trusts_delegated_roles, but this is just putting what is passed by parameter/hieradata so we need if logic in tht as I implemented in engine.yaml","commit_id":"d148c3113482a473086d61184d73007750f527e2"},{"author":{"_account_id":8833,"name":"Rabi Mishra","email":"ramishra@redhat.com","username":"rabi"},"change_message_id":"5c7ed37bf5cc19c75f65b5d8fb7cd23e41f6268e","unresolved":true,"context_lines":[{"line_number":172,"context_line":"          roles:"},{"line_number":173,"context_line":"            list_concat:"},{"line_number":174,"context_line":"              - - heat_stack_user"},{"line_number":175,"context_line":"              - if:"},{"line_number":176,"context_line":"                  - {get_param: HeatConfigureDelegatedRoles}"},{"line_number":177,"context_line":"                  - {get_param: HeatDelegatedRoles}"},{"line_number":178,"context_line":"          domains:"},{"line_number":179,"context_line":"            - heat_stack"},{"line_number":180,"context_line":"      monitoring_subscription: {get_param: MonitoringSubscriptionHeatApi}"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"2c45039b_cdda088e","line":177,"range":{"start_line":175,"start_character":0,"end_line":177,"end_character":51},"in_reply_to":"25ce6964_80e475c5","updated":"2022-06-27 08:15:47.000000000","message":"OK, it\u0027s going to be confusing with mix of ansible and puppet I guess.","commit_id":"d148c3113482a473086d61184d73007750f527e2"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"3e19b91371c257d8ba1c055082c84a5ecc0e72d6","unresolved":false,"context_lines":[{"line_number":172,"context_line":"          roles:"},{"line_number":173,"context_line":"            list_concat:"},{"line_number":174,"context_line":"              - - heat_stack_user"},{"line_number":175,"context_line":"              - if:"},{"line_number":176,"context_line":"                  - {get_param: HeatConfigureDelegatedRoles}"},{"line_number":177,"context_line":"                  - {get_param: HeatDelegatedRoles}"},{"line_number":178,"context_line":"          domains:"},{"line_number":179,"context_line":"            - heat_stack"},{"line_number":180,"context_line":"      monitoring_subscription: {get_param: MonitoringSubscriptionHeatApi}"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"434d926e_6add0e9f","line":177,"range":{"start_line":175,"start_character":0,"end_line":177,"end_character":51},"in_reply_to":"2c45039b_cdda088e","updated":"2022-06-27 12:06:11.000000000","message":"Done","commit_id":"d148c3113482a473086d61184d73007750f527e2"}],"deployment/heat/heat-engine-container-puppet.yaml":[{"author":{"_account_id":8833,"name":"Rabi Mishra","email":"ramishra@redhat.com","username":"rabi"},"change_message_id":"5c7ed37bf5cc19c75f65b5d8fb7cd23e41f6268e","unresolved":true,"context_lines":[{"line_number":109,"context_line":"    type: comma_delimited_list"},{"line_number":110,"context_line":"    default: []"},{"line_number":111,"context_line":"    description: An array of directories to search for plug-ins."},{"line_number":112,"context_line":"  HeatConfigureDelegatedRoles:"},{"line_number":113,"context_line":"    type: boolean"},{"line_number":114,"context_line":"    default: false"},{"line_number":115,"context_line":"    description: Create delegated roles"},{"line_number":116,"context_line":"  HeatDelegatedRoles:"},{"line_number":117,"context_line":"    type: comma_delimited_list"},{"line_number":118,"context_line":"    default: \u0027heat_stack_owner\u0027"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"13fa2d6a_581e9319","line":115,"range":{"start_line":112,"start_character":0,"end_line":115,"end_character":39},"updated":"2022-06-27 08:15:47.000000000","message":"Don\u0027t need this parameter here.","commit_id":"d148c3113482a473086d61184d73007750f527e2"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"3e19b91371c257d8ba1c055082c84a5ecc0e72d6","unresolved":false,"context_lines":[{"line_number":109,"context_line":"    type: comma_delimited_list"},{"line_number":110,"context_line":"    default: []"},{"line_number":111,"context_line":"    description: An array of directories to search for plug-ins."},{"line_number":112,"context_line":"  HeatConfigureDelegatedRoles:"},{"line_number":113,"context_line":"    type: boolean"},{"line_number":114,"context_line":"    default: false"},{"line_number":115,"context_line":"    description: Create delegated roles"},{"line_number":116,"context_line":"  HeatDelegatedRoles:"},{"line_number":117,"context_line":"    type: comma_delimited_list"},{"line_number":118,"context_line":"    default: \u0027heat_stack_owner\u0027"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"49dcc48f_302179c5","line":115,"range":{"start_line":112,"start_character":0,"end_line":115,"end_character":39},"in_reply_to":"13fa2d6a_581e9319","updated":"2022-06-27 12:06:11.000000000","message":"Done","commit_id":"d148c3113482a473086d61184d73007750f527e2"},{"author":{"_account_id":8833,"name":"Rabi Mishra","email":"ramishra@redhat.com","username":"rabi"},"change_message_id":"5c7ed37bf5cc19c75f65b5d8fb7cd23e41f6268e","unresolved":true,"context_lines":[{"line_number":115,"context_line":"    description: Create delegated roles"},{"line_number":116,"context_line":"  HeatDelegatedRoles:"},{"line_number":117,"context_line":"    type: comma_delimited_list"},{"line_number":118,"context_line":"    default: \u0027heat_stack_owner\u0027"},{"line_number":119,"context_line":"    descrpiton: List of trustor roles to be delegated to heat."},{"line_number":120,"context_line":"  ClientRetryLimit:"},{"line_number":121,"context_line":"    type: number"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"b24a94f7_bd802b10","line":118,"range":{"start_line":118,"start_character":13,"end_line":118,"end_character":31},"updated":"2022-06-27 08:15:47.000000000","message":"same here. default []","commit_id":"d148c3113482a473086d61184d73007750f527e2"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"3e19b91371c257d8ba1c055082c84a5ecc0e72d6","unresolved":false,"context_lines":[{"line_number":115,"context_line":"    description: Create delegated roles"},{"line_number":116,"context_line":"  HeatDelegatedRoles:"},{"line_number":117,"context_line":"    type: comma_delimited_list"},{"line_number":118,"context_line":"    default: \u0027heat_stack_owner\u0027"},{"line_number":119,"context_line":"    descrpiton: List of trustor roles to be delegated to heat."},{"line_number":120,"context_line":"  ClientRetryLimit:"},{"line_number":121,"context_line":"    type: number"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"b68a0dc4_d4b2fb01","line":118,"range":{"start_line":118,"start_character":13,"end_line":118,"end_character":31},"in_reply_to":"b24a94f7_bd802b10","updated":"2022-06-27 12:06:11.000000000","message":"Done","commit_id":"d148c3113482a473086d61184d73007750f527e2"},{"author":{"_account_id":8833,"name":"Rabi Mishra","email":"ramishra@redhat.com","username":"rabi"},"change_message_id":"83c651d0df3f68144f5632564357d2bd3b4dff09","unresolved":true,"context_lines":[{"line_number":116,"context_line":"  HeatDelegatedRoles:"},{"line_number":117,"context_line":"    type: comma_delimited_list"},{"line_number":118,"context_line":"    default: \u0027heat_stack_owner\u0027"},{"line_number":119,"context_line":"    descrpiton: List of trustor roles to be delegated to heat."},{"line_number":120,"context_line":"  ClientRetryLimit:"},{"line_number":121,"context_line":"    type: number"},{"line_number":122,"context_line":"    default: 2"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"2a81188c_88fb8b20","line":119,"range":{"start_line":119,"start_character":3,"end_line":119,"end_character":14},"updated":"2022-06-27 09:54:44.000000000","message":"typo","commit_id":"d148c3113482a473086d61184d73007750f527e2"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"3e19b91371c257d8ba1c055082c84a5ecc0e72d6","unresolved":false,"context_lines":[{"line_number":116,"context_line":"  HeatDelegatedRoles:"},{"line_number":117,"context_line":"    type: comma_delimited_list"},{"line_number":118,"context_line":"    default: \u0027heat_stack_owner\u0027"},{"line_number":119,"context_line":"    descrpiton: List of trustor roles to be delegated to heat."},{"line_number":120,"context_line":"  ClientRetryLimit:"},{"line_number":121,"context_line":"    type: number"},{"line_number":122,"context_line":"    default: 2"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"56324869_8c91a20c","line":119,"range":{"start_line":119,"start_character":3,"end_line":119,"end_character":14},"in_reply_to":"2a81188c_88fb8b20","updated":"2022-06-27 12:06:11.000000000","message":"Done","commit_id":"d148c3113482a473086d61184d73007750f527e2"},{"author":{"_account_id":8833,"name":"Rabi Mishra","email":"ramishra@redhat.com","username":"rabi"},"change_message_id":"5c7ed37bf5cc19c75f65b5d8fb7cd23e41f6268e","unresolved":true,"context_lines":[{"line_number":216,"context_line":"          - if:"},{"line_number":217,"context_line":"            - heat_workers_set"},{"line_number":218,"context_line":"            - heat::engine::num_engine_workers: {get_param: HeatWorkers}"},{"line_number":219,"context_line":"          - if:"},{"line_number":220,"context_line":"            - {get_param: HeatConfigureDelegatedRoles}"},{"line_number":221,"context_line":"            - heat::engine::trusts_delegated_roles: {get_param: HeatDelegatedRoles}"},{"line_number":222,"context_line":"      service_config_settings:"},{"line_number":223,"context_line":"        rsyslog:"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"47ed0e03_59db883d","line":220,"range":{"start_line":219,"start_character":0,"end_line":220,"end_character":54},"updated":"2022-06-27 08:15:47.000000000","message":"Don\u0027t need this condition.","commit_id":"d148c3113482a473086d61184d73007750f527e2"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"3e19b91371c257d8ba1c055082c84a5ecc0e72d6","unresolved":false,"context_lines":[{"line_number":216,"context_line":"          - if:"},{"line_number":217,"context_line":"            - heat_workers_set"},{"line_number":218,"context_line":"            - heat::engine::num_engine_workers: {get_param: HeatWorkers}"},{"line_number":219,"context_line":"          - if:"},{"line_number":220,"context_line":"            - {get_param: HeatConfigureDelegatedRoles}"},{"line_number":221,"context_line":"            - heat::engine::trusts_delegated_roles: {get_param: HeatDelegatedRoles}"},{"line_number":222,"context_line":"      service_config_settings:"},{"line_number":223,"context_line":"        rsyslog:"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"dc97e6f3_d2b54551","line":220,"range":{"start_line":219,"start_character":0,"end_line":220,"end_character":54},"in_reply_to":"47ed0e03_59db883d","updated":"2022-06-27 12:06:11.000000000","message":"Done","commit_id":"d148c3113482a473086d61184d73007750f527e2"}]}
