)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":36630,"name":"Winicius Allan Bezerra da Silva","display_name":"Winicius Allan","email":"winiciusab12@gmail.com","username":"winiciusallan"},"change_message_id":"1a8206e4dbb61aea8b8dd1a584515a5764a37ab6","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"e9c3b1e6_afd20dcb","updated":"2026-06-02 02:06:41.000000000","message":"LGTM!","commit_id":"91c66b130c49a60ccab825c2f1fcb03536c45d49"}],"doc/source/configuration/configuring.rst":[{"author":{"_account_id":36630,"name":"Winicius Allan Bezerra da Silva","display_name":"Winicius Allan","email":"winiciusab12@gmail.com","username":"winiciusallan"},"change_message_id":"1a8206e4dbb61aea8b8dd1a584515a5764a37ab6","unresolved":true,"context_lines":[{"line_number":104,"context_line":"        --email watcher@example.com watcher \\"},{"line_number":105,"context_line":"        --project\u003dKEYSTONE_SERVICE_PROJECT_NAME"},{"line_number":106,"context_line":"      $ openstack role add --project KEYSTONE_SERVICE_PROJECT_NAME \\"},{"line_number":107,"context_line":"        --user watcher admin"},{"line_number":108,"context_line":""},{"line_number":109,"context_line":""},{"line_number":110,"context_line":"#. You must register the Watcher Service with the Identity Service so that"}],"source_content_type":"text/x-rst","patch_set":1,"id":"f0c51e69_b609ee3e","side":"PARENT","line":107,"updated":"2026-06-02 02:06:41.000000000","message":"Nothing strictly related to your changes, but wondering if the watcher\u0027s user should have an admin or service role.\n\nhttps://github.com/openstack/watcher/blob/master/devstack/lib/watcher#L125-L127\n\nThe doc says admin as well as the devstack configuration, but the function header referenced above has the service role. Maybe something to fix in another patch?","commit_id":"7a69736061f8ea04a634dd4f285861814809097f"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"034d6406962177a4a78920b44700d46feb3b6274","unresolved":true,"context_lines":[{"line_number":104,"context_line":"        --email watcher@example.com watcher \\"},{"line_number":105,"context_line":"        --project\u003dKEYSTONE_SERVICE_PROJECT_NAME"},{"line_number":106,"context_line":"      $ openstack role add --project KEYSTONE_SERVICE_PROJECT_NAME \\"},{"line_number":107,"context_line":"        --user watcher admin"},{"line_number":108,"context_line":""},{"line_number":109,"context_line":""},{"line_number":110,"context_line":"#. You must register the Watcher Service with the Identity Service so that"}],"source_content_type":"text/x-rst","patch_set":1,"id":"77b6b95b_0b1b6dac","side":"PARENT","line":107,"in_reply_to":"f0c51e69_b609ee3e","updated":"2026-06-02 04:55:46.000000000","message":"The ideal goal in secure rbac role is to require service role for service users, instead of admin role, but I guess watcher still needs admin role to get access to the required API. Switching to the service role may require adjusting policy rules in each service so may require a long-term work. In fact the devstack code still assignes the admin role (though the comment indicates the service role, which should be fixed separately...)","commit_id":"7a69736061f8ea04a634dd4f285861814809097f"}]}
