)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":28223,"name":"Cedric Jeanneret","display_name":"cjeanner (Tengu)","email":"cjeanner@redhat.com","username":"cjeanner"},"change_message_id":"9d6e4f9523ea8c7070faa44d220f49ea21e7ffca","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"55c6c826_eeb2935c","updated":"2022-08-23 09:32:45.000000000","message":"I need to ensure nothing may break on the system first.","commit_id":"298463b8104665b7cd7afea70c6d2952384d6b89"}],"deployment/metrics/collectd-container-puppet.yaml":[{"author":{"_account_id":28223,"name":"Cedric Jeanneret","display_name":"cjeanner (Tengu)","email":"cjeanner@redhat.com","username":"cjeanner"},"change_message_id":"9d6e4f9523ea8c7070faa44d220f49ea21e7ffca","unresolved":true,"context_lines":[{"line_number":638,"context_line":"                    name: rsyslog"},{"line_number":639,"context_line":"                    state: restarted"},{"line_number":640,"context_line":"        - name: add access to podman to collectd user"},{"line_number":641,"context_line":"          ansible.builtin.shell: sudo podman exec -it collectd setfacl -R -m u:collectd:rwx /run/podman"},{"line_number":642,"context_line":"          when:"},{"line_number":643,"context_line":"            - enable_sensubility"},{"line_number":644,"context_line":"            - step|int \u003d\u003d 4"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"d10bd0ec_5a926b6d","line":641,"updated":"2022-08-23 09:32:45.000000000","message":"IIRC that path is loaded from the host into the collectd container, isn\u0027t it? Meaning there will be some changes on that location *on the host* as well. Is there any side-effect to that setfacl?","commit_id":"298463b8104665b7cd7afea70c6d2952384d6b89"},{"author":{"_account_id":28223,"name":"Cedric Jeanneret","display_name":"cjeanner (Tengu)","email":"cjeanner@redhat.com","username":"cjeanner"},"change_message_id":"cdaf632dff54a400263fe07f7abc9591085928de","unresolved":true,"context_lines":[{"line_number":638,"context_line":"                    name: rsyslog"},{"line_number":639,"context_line":"                    state: restarted"},{"line_number":640,"context_line":"        - name: add access to podman to collectd user"},{"line_number":641,"context_line":"          ansible.builtin.shell: sudo podman exec -it collectd setfacl -R -m u:collectd:rwx /run/podman"},{"line_number":642,"context_line":"          when:"},{"line_number":643,"context_line":"            - enable_sensubility"},{"line_number":644,"context_line":"            - step|int \u003d\u003d 4"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"4bf228be_9c4f0c9e","line":641,"in_reply_to":"81ea02ba_1da8fcbb","updated":"2022-08-23 11:14:56.000000000","message":"OK. even if it\u0027s using a user-id instead of \"name\", it should be fine, iirc UID in containers have a dedicated range, far outside of the host ones. Might be OK with that.","commit_id":"298463b8104665b7cd7afea70c6d2952384d6b89"},{"author":{"_account_id":5241,"name":"Martin Magr","email":"mmagr@redhat.com","username":"mmagr"},"change_message_id":"f0c66e43480399be8d8435aff53ff5594e698f42","unresolved":true,"context_lines":[{"line_number":638,"context_line":"                    name: rsyslog"},{"line_number":639,"context_line":"                    state: restarted"},{"line_number":640,"context_line":"        - name: add access to podman to collectd user"},{"line_number":641,"context_line":"          ansible.builtin.shell: sudo podman exec -it collectd setfacl -R -m u:collectd:rwx /run/podman"},{"line_number":642,"context_line":"          when:"},{"line_number":643,"context_line":"            - enable_sensubility"},{"line_number":644,"context_line":"            - step|int \u003d\u003d 4"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"81ea02ba_1da8fcbb","line":641,"in_reply_to":"d10bd0ec_5a926b6d","updated":"2022-08-23 10:50:21.000000000","message":"Yes, you\u0027re right, it is mounted from the container host. I\u0027m not aware of any side effect besides having file ACL record on that path for a non-existent user on the container host. That is IMO a least intrusive way to allow access for sensubility.","commit_id":"298463b8104665b7cd7afea70c6d2952384d6b89"}]}
