)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"d1f8d00755e5112e035a711e31faf9de79c2a681","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"65bb12e2_a2dbeac4","updated":"2023-08-02 15:02:09.000000000","message":"Adding PV to review.","commit_id":"71cc729099fb9a82ee54dd5971bb491775391313"},{"author":{"_account_id":35467,"name":"Luan Utimura","display_name":"Luan Utimura","email":"luan.utimura@luizalabs.com","username":"lutimura"},"change_message_id":"af30b3a54afcafe142bf59826da110efb0ca3323","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"b343fc93_394c66ff","updated":"2023-07-25 17:58:52.000000000","message":"Patchset 1 rendered doc page: https://storage.bhs.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_8e6/889646/1/check/openstack-tox-docs/8e6a222/docs/security/openstack/use-local-clis.html","commit_id":"71cc729099fb9a82ee54dd5971bb491775391313"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"ee90587c5225657514869585834f04987859a62b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"caa0072c_f3d1d718","updated":"2023-08-08 13:16:31.000000000","message":"couple of minor things ... looks good though.","commit_id":"71cc729099fb9a82ee54dd5971bb491775391313"},{"author":{"_account_id":35467,"name":"Luan Utimura","display_name":"Luan Utimura","email":"luan.utimura@luizalabs.com","username":"lutimura"},"change_message_id":"56c200d4e5193165e44d96648f6da57a859ab2b6","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"a2988994_4dffcc08","updated":"2023-08-08 19:33:52.000000000","message":"Patchset 3 rendered doc pages:\n\n* https://storage.gra.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_b35/889646/3/check/openstack-tox-docs/b358682/docs/security/openstack/use-local-clis.html\n\n* https://storage.gra.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_b35/889646/3/check/openstack-tox-docs/b358682/docs/security/openstack/security-overview.html\n\n(The latter was added as per Greg\u0027s request)","commit_id":"6a4ba4ae9ca5488f231acf2b9f4005569c80a403"},{"author":{"_account_id":35467,"name":"Luan Utimura","display_name":"Luan Utimura","email":"luan.utimura@luizalabs.com","username":"lutimura"},"change_message_id":"8bbb2663765ae5cdbf4fb02841ba1be268569cea","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"21548249_7715ef5f","updated":"2023-08-10 17:10:14.000000000","message":"Patchset 4 rendered doc page: https://storage.bhs.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_55c/889646/4/check/openstack-tox-docs/55ce8cd/docs/security/openstack/use-local-clis.html","commit_id":"9e35b2081a07cd57f3527529b3a064f3ed33dfb7"}],"doc/source/security/openstack/security-overview.rst":[{"author":{"_account_id":35467,"name":"Luan Utimura","display_name":"Luan Utimura","email":"luan.utimura@luizalabs.com","username":"lutimura"},"change_message_id":"010f3a0be8e471964004aa49bb67850a4d1d723d","unresolved":false,"context_lines":[{"line_number":10,"context_line":""},{"line_number":11,"context_line":"Many security features are not specific to |prod-os|, and are documented in"},{"line_number":12,"context_line":""},{"line_number":13,"context_line":".. xbooklink :ref:`Cloud Platform Security \u003coverview-of-starlingx-security\u003e`."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"This section covers security features that are specific to |prod-os|:"},{"line_number":16,"context_line":""}],"source_content_type":"text/x-rst","patch_set":3,"id":"52a92b2b_d454441e","side":"PARENT","line":13,"range":{"start_line":13,"start_character":19,"end_line":13,"end_character":33},"updated":"2023-08-08 19:20:28.000000000","message":"The term \"Cloud Platform\" doesn\u0027t seem to be used as often when referring to other documentation pages, so I took the opportunity to replace it with `|prod-long|`.\n\nHowever, I had to keep it outside `:ref:`, otherwise the expansion wouldn\u0027t work.","commit_id":"bc2f3c07ed4e0f5ab84dfcf6d35cf7f80d3cf9cd"}],"doc/source/security/openstack/use-local-clis.rst":[{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"ee90587c5225657514869585834f04987859a62b","unresolved":true,"context_lines":[{"line_number":1,"context_line":""},{"line_number":2,"context_line":".. tok1566218039402"},{"line_number":3,"context_line":".. _use-local-clis:"},{"line_number":4,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"cfd2f368_6b8b0654","line":1,"updated":"2023-08-08 13:16:31.000000000","message":"I know this isn\u0027t part of your review, but can you fix the incomplete sentence in \nhttps://docs.starlingx.io/security/openstack/security-overview.html\n\n   Many security features are not specific to StarlingX OpenStack, and are documented in  \u003ccurrently blank\u003e.\n   \n\nIt should be a reference to the StarlingX Kubernetes security section.","commit_id":"71cc729099fb9a82ee54dd5971bb491775391313"},{"author":{"_account_id":35467,"name":"Luan Utimura","display_name":"Luan Utimura","email":"luan.utimura@luizalabs.com","username":"lutimura"},"change_message_id":"010f3a0be8e471964004aa49bb67850a4d1d723d","unresolved":false,"context_lines":[{"line_number":1,"context_line":""},{"line_number":2,"context_line":".. tok1566218039402"},{"line_number":3,"context_line":".. _use-local-clis:"},{"line_number":4,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"8cb57aac_691043ac","line":1,"in_reply_to":"cfd2f368_6b8b0654","updated":"2023-08-08 19:20:28.000000000","message":"Done","commit_id":"71cc729099fb9a82ee54dd5971bb491775391313"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"ee90587c5225657514869585834f04987859a62b","unresolved":true,"context_lines":[{"line_number":29,"context_line":"access to the credentials of the Keystone user **admin** that comes pre-created"},{"line_number":30,"context_line":"with |prod-os|."},{"line_number":31,"context_line":""},{"line_number":32,"context_line":"A **Local LDAP Linux User Account**, on the other hand, is an account that, by"},{"line_number":33,"context_line":"default, only has access to the credentials of the Keystone user *who has the"},{"line_number":34,"context_line":"same username* as the |LDAP| account. Therefore, in order for you to access"},{"line_number":35,"context_line":"|prod-os| using an |LDAP| account, you first need to create a Keystone user"},{"line_number":36,"context_line":"for it."},{"line_number":37,"context_line":""},{"line_number":38,"context_line":"If this is your first access, you can use the **Sysadmin Local Linux Account**"},{"line_number":39,"context_line":"for this."},{"line_number":40,"context_line":""},{"line_number":41,"context_line":"For more information about creating Keystone users, managing projects, users"},{"line_number":42,"context_line":"and roles, see"},{"line_number":43,"context_line":"`Manage projects, users, and roles"},{"line_number":44,"context_line":"\u003chttps://docs.openstack.org/keystone/2023.1/admin/cli-manage-projects-users-and-roles.html\u003e`_."},{"line_number":45,"context_line":""},{"line_number":46,"context_line":".. important::"},{"line_number":47,"context_line":"    The Local |LDAP| Linux User Account *must* be a member of the |LDAP| group"},{"line_number":48,"context_line":"    **openstack** to have access to the |prod-os| configuration files. This"},{"line_number":49,"context_line":"    group is automatically created and made available after |prod-os| is"},{"line_number":50,"context_line":"    applied on the platform."},{"line_number":51,"context_line":""},{"line_number":52,"context_line":"    You can add an |LDAP| account to the |LDAP| group **openstack** by running:"},{"line_number":53,"context_line":""},{"line_number":54,"context_line":"    .. code-block:: none"},{"line_number":55,"context_line":""},{"line_number":56,"context_line":"        sudo ldapaddusertogroup \u003cUSER\u003e openstack"},{"line_number":57,"context_line":""},{"line_number":58,"context_line":"    See :ref:`Local LDAP Linux User Accounts \u003clocal-ldap-linux-user-accounts\u003e`"},{"line_number":59,"context_line":"    for more details."},{"line_number":60,"context_line":""},{"line_number":61,"context_line":".. rubric:: |proc|"},{"line_number":62,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"5670536f_bd1ddffe","line":59,"range":{"start_line":32,"start_character":0,"end_line":59,"end_character":21},"updated":"2023-08-08 13:16:31.000000000","message":"REWORD ?\n\nA **Local LDAP Linux User Account**, on the other hand, is an account with SSH privileges that is typically configured with only access to the credentials of a Keystone user *who has the same username* as the |LDAP| account.  To create such a composite Local LDAP and Keystone user account, see https://docs.starlingx.io/security/kubernetes/manage-local-ldap-39fe3a85a528.html .\n\n.. important\n    The Local |LDAP| Linux User Account *must* be a member of the |LDAP| group\n    **openstack** to have access to the |prod-os| configuration files. This\n    group is automatically created and made available after |prod-os| is\n    applied on the platform.\n    \nIf this is your first access to the system, you can use the **Sysadmin Local Linux Account** for Local CLI access.","commit_id":"71cc729099fb9a82ee54dd5971bb491775391313"},{"author":{"_account_id":35467,"name":"Luan Utimura","display_name":"Luan Utimura","email":"luan.utimura@luizalabs.com","username":"lutimura"},"change_message_id":"010f3a0be8e471964004aa49bb67850a4d1d723d","unresolved":false,"context_lines":[{"line_number":29,"context_line":"access to the credentials of the Keystone user **admin** that comes pre-created"},{"line_number":30,"context_line":"with |prod-os|."},{"line_number":31,"context_line":""},{"line_number":32,"context_line":"A **Local LDAP Linux User Account**, on the other hand, is an account that, by"},{"line_number":33,"context_line":"default, only has access to the credentials of the Keystone user *who has the"},{"line_number":34,"context_line":"same username* as the |LDAP| account. Therefore, in order for you to access"},{"line_number":35,"context_line":"|prod-os| using an |LDAP| account, you first need to create a Keystone user"},{"line_number":36,"context_line":"for it."},{"line_number":37,"context_line":""},{"line_number":38,"context_line":"If this is your first access, you can use the **Sysadmin Local Linux Account**"},{"line_number":39,"context_line":"for this."},{"line_number":40,"context_line":""},{"line_number":41,"context_line":"For more information about creating Keystone users, managing projects, users"},{"line_number":42,"context_line":"and roles, see"},{"line_number":43,"context_line":"`Manage projects, users, and roles"},{"line_number":44,"context_line":"\u003chttps://docs.openstack.org/keystone/2023.1/admin/cli-manage-projects-users-and-roles.html\u003e`_."},{"line_number":45,"context_line":""},{"line_number":46,"context_line":".. important::"},{"line_number":47,"context_line":"    The Local |LDAP| Linux User Account *must* be a member of the |LDAP| group"},{"line_number":48,"context_line":"    **openstack** to have access to the |prod-os| configuration files. This"},{"line_number":49,"context_line":"    group is automatically created and made available after |prod-os| is"},{"line_number":50,"context_line":"    applied on the platform."},{"line_number":51,"context_line":""},{"line_number":52,"context_line":"    You can add an |LDAP| account to the |LDAP| group **openstack** by running:"},{"line_number":53,"context_line":""},{"line_number":54,"context_line":"    .. code-block:: none"},{"line_number":55,"context_line":""},{"line_number":56,"context_line":"        sudo ldapaddusertogroup \u003cUSER\u003e openstack"},{"line_number":57,"context_line":""},{"line_number":58,"context_line":"    See :ref:`Local LDAP Linux User Accounts \u003clocal-ldap-linux-user-accounts\u003e`"},{"line_number":59,"context_line":"    for more details."},{"line_number":60,"context_line":""},{"line_number":61,"context_line":".. rubric:: |proc|"},{"line_number":62,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"40a437a1_0747013e","line":59,"range":{"start_line":32,"start_character":0,"end_line":59,"end_character":21},"in_reply_to":"5670536f_bd1ddffe","updated":"2023-08-08 19:20:28.000000000","message":"Done","commit_id":"71cc729099fb9a82ee54dd5971bb491775391313"},{"author":{"_account_id":34455,"name":"Lucas de Ataides Barreto","display_name":"Lucas de Ataides","email":"lucas.deataidesbarreto@windriver.com","username":"lucasdeataides"},"change_message_id":"6eed3d558ed065c1ed3a5d1ce2c9553eb7443490","unresolved":true,"context_lines":[{"line_number":128,"context_line":"If you need to run a |CLI| command that references a local file, then that file"},{"line_number":129,"context_line":"must be copied to or created in the shared directory between the host and the"},{"line_number":130,"context_line":"clients container. On the host side, the directory is located at"},{"line_number":131,"context_line":"``/var/opt/openstack``."},{"line_number":132,"context_line":""},{"line_number":133,"context_line":"If you are logged in as **sysadmin**, you just have to move your file to"},{"line_number":134,"context_line":"``/var/opt/openstack`` and reference it by its filename:"}],"source_content_type":"text/x-rst","patch_set":1,"id":"5ba18b27_2ba73159","line":131,"updated":"2023-08-07 12:12:35.000000000","message":"Should this be updated to reflect the changes of https://review.opendev.org/c/starlingx/openstack-armada-app/+/890544 ?","commit_id":"71cc729099fb9a82ee54dd5971bb491775391313"},{"author":{"_account_id":35467,"name":"Luan Utimura","display_name":"Luan Utimura","email":"luan.utimura@luizalabs.com","username":"lutimura"},"change_message_id":"010f3a0be8e471964004aa49bb67850a4d1d723d","unresolved":false,"context_lines":[{"line_number":128,"context_line":"If you need to run a |CLI| command that references a local file, then that file"},{"line_number":129,"context_line":"must be copied to or created in the shared directory between the host and the"},{"line_number":130,"context_line":"clients container. On the host side, the directory is located at"},{"line_number":131,"context_line":"``/var/opt/openstack``."},{"line_number":132,"context_line":""},{"line_number":133,"context_line":"If you are logged in as **sysadmin**, you just have to move your file to"},{"line_number":134,"context_line":"``/var/opt/openstack`` and reference it by its filename:"}],"source_content_type":"text/x-rst","patch_set":1,"id":"4efe793b_2ff9f1c9","line":131,"in_reply_to":"2afa2fac_02481d99","updated":"2023-08-08 19:20:28.000000000","message":"Since [890544](https://review.opendev.org/c/starlingx/openstack-armada-app/+/890544) was merged, I added a note mentioning the possibility of changing the directory with Helm overrides.","commit_id":"71cc729099fb9a82ee54dd5971bb491775391313"},{"author":{"_account_id":35467,"name":"Luan Utimura","display_name":"Luan Utimura","email":"luan.utimura@luizalabs.com","username":"lutimura"},"change_message_id":"e789f48deb0b96431ef20da0b471ec0bfaab821f","unresolved":true,"context_lines":[{"line_number":128,"context_line":"If you need to run a |CLI| command that references a local file, then that file"},{"line_number":129,"context_line":"must be copied to or created in the shared directory between the host and the"},{"line_number":130,"context_line":"clients container. On the host side, the directory is located at"},{"line_number":131,"context_line":"``/var/opt/openstack``."},{"line_number":132,"context_line":""},{"line_number":133,"context_line":"If you are logged in as **sysadmin**, you just have to move your file to"},{"line_number":134,"context_line":"``/var/opt/openstack`` and reference it by its filename:"}],"source_content_type":"text/x-rst","patch_set":1,"id":"2afa2fac_02481d99","line":131,"in_reply_to":"5ba18b27_2ba73159","updated":"2023-08-07 13:03:17.000000000","message":"Good point, Lucas.\n\nAlthough the default clients\u0027 working directory is still `/var/opt/openstack`, the change you mentioned plans to introduce the possibility of changing this directory through Helm overrides.\n\nOnce [890544](https://review.opendev.org/c/starlingx/openstack-armada-app/+/890544) is merged, I will update this documentation accordingly.","commit_id":"71cc729099fb9a82ee54dd5971bb491775391313"},{"author":{"_account_id":30539,"name":"Ron Stone","email":"ronald.stone@windriver.com","username":"ronstone2000"},"change_message_id":"9bb7eaa2f99d25c7b8261b72abc9a8beca41c4ac","unresolved":true,"context_lines":[{"line_number":13,"context_line":"controller node\u0027s local console or by |SSH|-ing to the |OAM| Floating IP"},{"line_number":14,"context_line":"Address."},{"line_number":15,"context_line":""},{"line_number":16,"context_line":".. rubric:: |context|"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":".. warning::"},{"line_number":19,"context_line":"    For security reasons, only administrative users should have |SSH|"}],"source_content_type":"text/x-rst","patch_set":3,"id":"e5051bb1_cfd3ff20","line":16,"updated":"2023-08-10 11:35:31.000000000","message":"Some of what is between here and line 54 is context, but some look like prerequisites, eg, 22-26. Suggest separating prerequisites out into a \n\n.. rubric:: |prereq|\n\nsection","commit_id":"6a4ba4ae9ca5488f231acf2b9f4005569c80a403"},{"author":{"_account_id":35467,"name":"Luan Utimura","display_name":"Luan Utimura","email":"luan.utimura@luizalabs.com","username":"lutimura"},"change_message_id":"01a894271c7330debf49164b4699cfd89812240a","unresolved":false,"context_lines":[{"line_number":13,"context_line":"controller node\u0027s local console or by |SSH|-ing to the |OAM| Floating IP"},{"line_number":14,"context_line":"Address."},{"line_number":15,"context_line":""},{"line_number":16,"context_line":".. rubric:: |context|"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":".. warning::"},{"line_number":19,"context_line":"    For security reasons, only administrative users should have |SSH|"}],"source_content_type":"text/x-rst","patch_set":3,"id":"8941c0ca_d4510ae7","line":16,"in_reply_to":"e5051bb1_cfd3ff20","updated":"2023-08-10 17:03:20.000000000","message":"I agree with you on this.\n\nIn the latest patchset I moved part of the top text into the \"About this task\" section (i.e., `context`) and also supplemented it with more information.\n\nThe part about account types is now part of the \"Prerequisite\" section (i.e., `prereq`).\n\nLet me know if you have any more suggestions.","commit_id":"6a4ba4ae9ca5488f231acf2b9f4005569c80a403"}]}
