)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":33594,"name":"Thales Elero Cervi","display_name":"Thales Cervi","email":"thaleselero.cervi@windriver.com","username":"tcervi"},"change_message_id":"faf1fea8b03db5c0b48c182ffd100e4885903d5a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":13,"id":"bf13984f_840f507c","updated":"2026-04-22 19:51:44.000000000","message":"Left a minor comment, but overall this doc looks excellent to me!","commit_id":"8a2e7b7ffc639fe440ab8b5ccf9e6d868b4bae3e"},{"author":{"_account_id":38183,"name":"Andre Badur","display_name":"andrebadur","email":"Andre.deHeldBadur@windriver.com","username":"andrebadur"},"change_message_id":"5570b7d25e33186f790127e2c0974fb5c5c4e5d2","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":13,"id":"128de3b6_72575559","updated":"2026-04-23 12:15:32.000000000","message":"recheck","commit_id":"8a2e7b7ffc639fe440ab8b5ccf9e6d868b4bae3e"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"db0372a1ba8ee047ad686935b63b12dc7df913a0","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":13,"id":"8cfb6ac2_bba85e21","in_reply_to":"128de3b6_72575559","updated":"2026-04-23 14:40:01.000000000","message":"Hey, build is breaking due to a ref issue, when https://review.opendev.org/c/starlingx/docs/+/984476 is merged build will be ok. Thanks!","commit_id":"8a2e7b7ffc639fe440ab8b5ccf9e6d868b4bae3e"}],"doc/source/security/openstack/dex-as-idp-for-openstack-keystone-c072603fc51f.rst":[{"author":{"_account_id":37148,"name":"Kayo Lourenço Gonçalves da Costa","display_name":"Kayo Costa","email":"kayo.goncalvesdacosta@windriver.com","username":"kayomj"},"change_message_id":"f8e7ea0f232a4582b7ca9636d58ac6b9ae4fee31","unresolved":true,"context_lines":[{"line_number":50,"context_line":"configured by default for both ``claim_groups: true`` and ``claim_groups:"},{"line_number":51,"context_line":"false``."},{"line_number":52,"context_line":""},{"line_number":53,"context_line":"The bootstrap should only be disabled if the you want to manually create the"},{"line_number":54,"context_line":"mappings, groups, and projects for |OIDC| users and groups."},{"line_number":55,"context_line":""},{"line_number":56,"context_line":"To manage federation manually set:"}],"source_content_type":"text/x-rst","patch_set":7,"id":"d73aedcc_ca74c0e9","line":53,"range":{"start_line":53,"start_character":41,"end_line":53,"end_character":44},"updated":"2026-04-15 17:43:37.000000000","message":"i think this word is misplaced.","commit_id":"d6c7e1179e9059a26b8390d6a5870e4d8604cbbe"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"70b78674369c73e8c25dd0f5f93868b5bd8ae3fb","unresolved":false,"context_lines":[{"line_number":50,"context_line":"configured by default for both ``claim_groups: true`` and ``claim_groups:"},{"line_number":51,"context_line":"false``."},{"line_number":52,"context_line":""},{"line_number":53,"context_line":"The bootstrap should only be disabled if the you want to manually create the"},{"line_number":54,"context_line":"mappings, groups, and projects for |OIDC| users and groups."},{"line_number":55,"context_line":""},{"line_number":56,"context_line":"To manage federation manually set:"}],"source_content_type":"text/x-rst","patch_set":7,"id":"e17324ab_17de700f","line":53,"range":{"start_line":53,"start_character":41,"end_line":53,"end_character":44},"in_reply_to":"d73aedcc_ca74c0e9","updated":"2026-04-15 20:54:47.000000000","message":"Done","commit_id":"d6c7e1179e9059a26b8390d6a5870e4d8604cbbe"},{"author":{"_account_id":37148,"name":"Kayo Lourenço Gonçalves da Costa","display_name":"Kayo Costa","email":"kayo.goncalvesdacosta@windriver.com","username":"kayomj"},"change_message_id":"f8e7ea0f232a4582b7ca9636d58ac6b9ae4fee31","unresolved":true,"context_lines":[{"line_number":80,"context_line":"This scenario works automatically with the configurations applied during the"},{"line_number":81,"context_line":"|prod-os| deployment."},{"line_number":82,"context_line":""},{"line_number":83,"context_line":"You only need to set ``conf.federation.dex_idp.enabled \u003d true`` in the Keystone"},{"line_number":84,"context_line":"overrides."},{"line_number":85,"context_line":""},{"line_number":86,"context_line":"``RedirectURI`` configurations are automatically added to Dex."},{"line_number":87,"context_line":""}],"source_content_type":"text/x-rst","patch_set":7,"id":"bb52d312_da5e28c5","line":84,"range":{"start_line":83,"start_character":0,"end_line":84,"end_character":10},"updated":"2026-04-15 17:43:37.000000000","message":"this is not required anymore, after change https://ala-codereviewti-prod.wrs.com/c/cgcs/opendev.org.starlingx.openstack-armada-app/+/36010,\nthe apply would be able to automatically enable dex_ipd when the proper conditions met, which are:\n- the user did not set manually to false\n- the oidc parameters are present\n- dex status is healthy\n- the endpoint domain is configured.","commit_id":"d6c7e1179e9059a26b8390d6a5870e4d8604cbbe"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"70b78674369c73e8c25dd0f5f93868b5bd8ae3fb","unresolved":false,"context_lines":[{"line_number":80,"context_line":"This scenario works automatically with the configurations applied during the"},{"line_number":81,"context_line":"|prod-os| deployment."},{"line_number":82,"context_line":""},{"line_number":83,"context_line":"You only need to set ``conf.federation.dex_idp.enabled \u003d true`` in the Keystone"},{"line_number":84,"context_line":"overrides."},{"line_number":85,"context_line":""},{"line_number":86,"context_line":"``RedirectURI`` configurations are automatically added to Dex."},{"line_number":87,"context_line":""}],"source_content_type":"text/x-rst","patch_set":7,"id":"e50b925a_c8334c7c","line":84,"range":{"start_line":83,"start_character":0,"end_line":84,"end_character":10},"in_reply_to":"826902fa_92a856d5","updated":"2026-04-15 20:54:47.000000000","message":"Done","commit_id":"d6c7e1179e9059a26b8390d6a5870e4d8604cbbe"},{"author":{"_account_id":37148,"name":"Kayo Lourenço Gonçalves da Costa","display_name":"Kayo Costa","email":"kayo.goncalvesdacosta@windriver.com","username":"kayomj"},"change_message_id":"a878191ab2795457ca2557e455608d221f966ab0","unresolved":true,"context_lines":[{"line_number":80,"context_line":"This scenario works automatically with the configurations applied during the"},{"line_number":81,"context_line":"|prod-os| deployment."},{"line_number":82,"context_line":""},{"line_number":83,"context_line":"You only need to set ``conf.federation.dex_idp.enabled \u003d true`` in the Keystone"},{"line_number":84,"context_line":"overrides."},{"line_number":85,"context_line":""},{"line_number":86,"context_line":"``RedirectURI`` configurations are automatically added to Dex."},{"line_number":87,"context_line":""}],"source_content_type":"text/x-rst","patch_set":7,"id":"826902fa_92a856d5","line":84,"range":{"start_line":83,"start_character":0,"end_line":84,"end_character":10},"in_reply_to":"bb52d312_da5e28c5","updated":"2026-04-15 17:54:12.000000000","message":"correct reference:\nhttps://review.opendev.org/c/starlingx/openstack-armada-app/+/980503","commit_id":"d6c7e1179e9059a26b8390d6a5870e4d8604cbbe"},{"author":{"_account_id":37278,"name":"Mateus Nascimento","display_name":"Mateus Nascimento","email":"Mateus.SoaresdoNascimento@windriver.com","username":"msoaresd"},"change_message_id":"d429ffbf4ebcfffea449b7dfd9041577bda8e28e","unresolved":true,"context_lines":[{"line_number":62,"context_line":"Except where explicitly stated, the values below are defaults and should only"},{"line_number":63,"context_line":"be changed when customization is required."},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"Recommended values"},{"line_number":66,"context_line":""},{"line_number":67,"context_line":".. code-block:: none"},{"line_number":68,"context_line":""}],"source_content_type":"text/x-rst","patch_set":8,"id":"dbe9627c_faa40636","line":65,"updated":"2026-04-16 19:05:35.000000000","message":"These values are the \"Default values\". “Recommended” is not a good word here, since it is recommended that the user set claim_groups: true and define their groups under \"groups\" if they want RBAC for their groups from the DEX connector.","commit_id":"bc635d484d0a8c6e3419bf8a1a292d441e733cc9"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"5d8d36cc42542cf5eab2a86bc7e5147aba7e0f52","unresolved":false,"context_lines":[{"line_number":62,"context_line":"Except where explicitly stated, the values below are defaults and should only"},{"line_number":63,"context_line":"be changed when customization is required."},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"Recommended values"},{"line_number":66,"context_line":""},{"line_number":67,"context_line":".. code-block:: none"},{"line_number":68,"context_line":""}],"source_content_type":"text/x-rst","patch_set":8,"id":"8df22412_babf4c23","line":65,"in_reply_to":"dbe9627c_faa40636","updated":"2026-04-16 19:38:08.000000000","message":"Done","commit_id":"bc635d484d0a8c6e3419bf8a1a292d441e733cc9"},{"author":{"_account_id":37278,"name":"Mateus Nascimento","display_name":"Mateus Nascimento","email":"Mateus.SoaresdoNascimento@windriver.com","username":"msoaresd"},"change_message_id":"d429ffbf4ebcfffea449b7dfd9041577bda8e28e","unresolved":true,"context_lines":[{"line_number":113,"context_line":"          enabled: false"},{"line_number":114,"context_line":""},{"line_number":115,"context_line":""},{"line_number":116,"context_line":"To verify if Dex was successfully enabled:"},{"line_number":117,"context_line":""},{"line_number":118,"context_line":"#.  Open Horizon"},{"line_number":119,"context_line":""},{"line_number":120,"context_line":"#.  Click “Login with oidc-auth-apps (Dex) SSO”"},{"line_number":121,"context_line":""},{"line_number":122,"context_line":"#.  Successful login confirms configuration"},{"line_number":123,"context_line":""},{"line_number":124,"context_line":""},{"line_number":125,"context_line":"Dex Scenarios"}],"source_content_type":"text/x-rst","patch_set":8,"id":"59e1d5f5_b0877d1f","line":122,"range":{"start_line":116,"start_character":0,"end_line":122,"end_character":43},"updated":"2026-04-16 19:05:35.000000000","message":"I think the correct place for this is above \"Dex Identity Provider Configuration - federation.dex_idp\", not under \"Advanced Usage\", since this is not advanced, it is just the normal procedure for login with DEX.","commit_id":"bc635d484d0a8c6e3419bf8a1a292d441e733cc9"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"5d8d36cc42542cf5eab2a86bc7e5147aba7e0f52","unresolved":false,"context_lines":[{"line_number":113,"context_line":"          enabled: false"},{"line_number":114,"context_line":""},{"line_number":115,"context_line":""},{"line_number":116,"context_line":"To verify if Dex was successfully enabled:"},{"line_number":117,"context_line":""},{"line_number":118,"context_line":"#.  Open Horizon"},{"line_number":119,"context_line":""},{"line_number":120,"context_line":"#.  Click “Login with oidc-auth-apps (Dex) SSO”"},{"line_number":121,"context_line":""},{"line_number":122,"context_line":"#.  Successful login confirms configuration"},{"line_number":123,"context_line":""},{"line_number":124,"context_line":""},{"line_number":125,"context_line":"Dex Scenarios"}],"source_content_type":"text/x-rst","patch_set":8,"id":"d4bced29_a59d92ae","line":122,"range":{"start_line":116,"start_character":0,"end_line":122,"end_character":43},"in_reply_to":"59e1d5f5_b0877d1f","updated":"2026-04-16 19:38:08.000000000","message":"Done","commit_id":"bc635d484d0a8c6e3419bf8a1a292d441e733cc9"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"38f45a0e43f101a1571125c4b44959e71dcdff15","unresolved":true,"context_lines":[{"line_number":15,"context_line":"delegates user authentication to Dex, while authorization, project scoping, and"},{"line_number":16,"context_line":"access control remain managed inside |prod-os|."},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"Dex federation is enabled (by default)."},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"When enabled:"},{"line_number":21,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"a0c263be_b8d216b0","line":18,"range":{"start_line":18,"start_character":0,"end_line":18,"end_character":14},"updated":"2026-04-20 16:32:13.000000000","message":"REWORD ?\n\n- Keystone Federation using WRCP \u0027oidc-auth-apps\u0027 (DEX) is enabled by default","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"5415badd40abc9658c71276c22e47d261e56c914","unresolved":false,"context_lines":[{"line_number":15,"context_line":"delegates user authentication to Dex, while authorization, project scoping, and"},{"line_number":16,"context_line":"access control remain managed inside |prod-os|."},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"Dex federation is enabled (by default)."},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"When enabled:"},{"line_number":21,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"4e3ba011_08d62ba1","line":18,"range":{"start_line":18,"start_character":0,"end_line":18,"end_character":14},"in_reply_to":"a0c263be_b8d216b0","updated":"2026-04-21 14:24:53.000000000","message":"Done","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"38f45a0e43f101a1571125c4b44959e71dcdff15","unresolved":true,"context_lines":[{"line_number":19,"context_line":""},{"line_number":20,"context_line":"When enabled:"},{"line_number":21,"context_line":""},{"line_number":22,"context_line":"-   Dex is registered as an Identity Provider"},{"line_number":23,"context_line":""},{"line_number":24,"context_line":"-   Default federation mapping is applied"},{"line_number":25,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"c49e757b_288f8f86","line":22,"range":{"start_line":22,"start_character":0,"end_line":22,"end_character":45},"updated":"2026-04-20 16:32:13.000000000","message":"REWORD ?\n\n- WRCP oidc-auth-apps (DEX) is automatically registered as the federated IDP for openstack keystone\n   * and WRCP oidc-auth-apps (DEX) is automatically configured with WRCP Local LDAP as its backend IDP; although additional backend IDPs can be configured.","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"5415badd40abc9658c71276c22e47d261e56c914","unresolved":false,"context_lines":[{"line_number":19,"context_line":""},{"line_number":20,"context_line":"When enabled:"},{"line_number":21,"context_line":""},{"line_number":22,"context_line":"-   Dex is registered as an Identity Provider"},{"line_number":23,"context_line":""},{"line_number":24,"context_line":"-   Default federation mapping is applied"},{"line_number":25,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"ca9046a1_2c1fe49e","line":22,"range":{"start_line":22,"start_character":0,"end_line":22,"end_character":45},"in_reply_to":"c49e757b_288f8f86","updated":"2026-04-21 14:24:53.000000000","message":"Done","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"38f45a0e43f101a1571125c4b44959e71dcdff15","unresolved":true,"context_lines":[{"line_number":21,"context_line":""},{"line_number":22,"context_line":"-   Dex is registered as an Identity Provider"},{"line_number":23,"context_line":""},{"line_number":24,"context_line":"-   Default federation mapping is applied"},{"line_number":25,"context_line":""},{"line_number":26,"context_line":"-   Required resources are created automatically:"},{"line_number":27,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"d1ddf67c_482442e8","line":24,"range":{"start_line":24,"start_character":0,"end_line":24,"end_character":41},"updated":"2026-04-20 16:32:13.000000000","message":"not sure average reader will know what this means","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"7f8c452547689fd9bc966a77ba416c25dd13b997","unresolved":false,"context_lines":[{"line_number":21,"context_line":""},{"line_number":22,"context_line":"-   Dex is registered as an Identity Provider"},{"line_number":23,"context_line":""},{"line_number":24,"context_line":"-   Default federation mapping is applied"},{"line_number":25,"context_line":""},{"line_number":26,"context_line":"-   Required resources are created automatically:"},{"line_number":27,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"e05b0c61_92d29ce7","line":24,"range":{"start_line":24,"start_character":0,"end_line":24,"end_character":41},"in_reply_to":"d1ddf67c_482442e8","updated":"2026-04-22 19:05:52.000000000","message":"Reference added.","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"38f45a0e43f101a1571125c4b44959e71dcdff15","unresolved":true,"context_lines":[{"line_number":28,"context_line":"    - Group"},{"line_number":29,"context_line":"    - Project"},{"line_number":30,"context_line":"    - Role and role assignment"},{"line_number":31,"context_line":"    - Federation protocol"},{"line_number":32,"context_line":""},{"line_number":33,"context_line":".. note::"},{"line_number":34,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"2c322738_61049cc1","line":31,"range":{"start_line":31,"start_character":0,"end_line":31,"end_character":25},"updated":"2026-04-20 16:32:13.000000000","message":"not sure average reader will know what this means\n\ndoes he need to know ?","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"7f8c452547689fd9bc966a77ba416c25dd13b997","unresolved":false,"context_lines":[{"line_number":28,"context_line":"    - Group"},{"line_number":29,"context_line":"    - Project"},{"line_number":30,"context_line":"    - Role and role assignment"},{"line_number":31,"context_line":"    - Federation protocol"},{"line_number":32,"context_line":""},{"line_number":33,"context_line":".. note::"},{"line_number":34,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"5cad959f_5207a83d","line":31,"range":{"start_line":31,"start_character":0,"end_line":31,"end_character":25},"in_reply_to":"2c322738_61049cc1","updated":"2026-04-22 19:05:52.000000000","message":"Done","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"38f45a0e43f101a1571125c4b44959e71dcdff15","unresolved":true,"context_lines":[{"line_number":39,"context_line":"-   Users authenticated via Dex:"},{"line_number":40,"context_line":""},{"line_number":41,"context_line":"    - Are identified by email"},{"line_number":42,"context_line":"    - Are added to a default group"},{"line_number":43,"context_line":"    - Receive access to a default project"},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"To verify if Dex was successfully enabled:"},{"line_number":46,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"e6e592cf_85aec365","line":43,"range":{"start_line":42,"start_character":0,"end_line":43,"end_character":41},"updated":"2026-04-20 16:32:13.000000000","message":"do you need to have a forward reference to where you can control/configure what keystone group and keystone project/tenant the OIDC/DEX user (identified by email) is assigned to ?","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"7f8c452547689fd9bc966a77ba416c25dd13b997","unresolved":false,"context_lines":[{"line_number":39,"context_line":"-   Users authenticated via Dex:"},{"line_number":40,"context_line":""},{"line_number":41,"context_line":"    - Are identified by email"},{"line_number":42,"context_line":"    - Are added to a default group"},{"line_number":43,"context_line":"    - Receive access to a default project"},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"To verify if Dex was successfully enabled:"},{"line_number":46,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"1d6b7e7b_d6e02db7","line":43,"range":{"start_line":42,"start_character":0,"end_line":43,"end_character":41},"in_reply_to":"e6e592cf_85aec365","updated":"2026-04-22 19:05:52.000000000","message":"Done","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"38f45a0e43f101a1571125c4b44959e71dcdff15","unresolved":true,"context_lines":[{"line_number":67,"context_line":""},{"line_number":68,"context_line":"-   Horizon WebSSO exposure"},{"line_number":69,"context_line":""},{"line_number":70,"context_line":"Except where explicitly stated, the values below are defaults and should only"},{"line_number":71,"context_line":"be changed when customization is required."},{"line_number":72,"context_line":""},{"line_number":73,"context_line":"Default values:"},{"line_number":74,"context_line":""},{"line_number":75,"context_line":".. code-block:: none"},{"line_number":76,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"d66a2105_d754d563","line":73,"range":{"start_line":70,"start_character":0,"end_line":73,"end_character":15},"updated":"2026-04-20 16:32:13.000000000","message":"shouldn\u0027t you mention that these are the helm overrides for the openstack keystone helm chart ?\n\nand refer to the commands for updating this if required.","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"7f8c452547689fd9bc966a77ba416c25dd13b997","unresolved":false,"context_lines":[{"line_number":67,"context_line":""},{"line_number":68,"context_line":"-   Horizon WebSSO exposure"},{"line_number":69,"context_line":""},{"line_number":70,"context_line":"Except where explicitly stated, the values below are defaults and should only"},{"line_number":71,"context_line":"be changed when customization is required."},{"line_number":72,"context_line":""},{"line_number":73,"context_line":"Default values:"},{"line_number":74,"context_line":""},{"line_number":75,"context_line":".. code-block:: none"},{"line_number":76,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"ccaa80a7_384cac5e","line":73,"range":{"start_line":70,"start_character":0,"end_line":73,"end_character":15},"in_reply_to":"d66a2105_d754d563","updated":"2026-04-22 19:05:52.000000000","message":"Done","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"38f45a0e43f101a1571125c4b44959e71dcdff15","unresolved":true,"context_lines":[{"line_number":81,"context_line":"            dex_idp:"},{"line_number":82,"context_line":"                enabled: false"},{"line_number":83,"context_line":"                provider_name: \"dex\""},{"line_number":84,"context_line":"                provider_remote_id: \"https://0.0.0.0:30556/dex\" # This IP is the one used in the DEX configuration"},{"line_number":85,"context_line":"                protocol_name: \"openid\""},{"line_number":86,"context_line":"                group_name: \"federated_users\""},{"line_number":87,"context_line":"                project_name: \"federation\""}],"source_content_type":"text/x-rst","patch_set":9,"id":"f8858d38_e279aece","line":84,"range":{"start_line":84,"start_character":45,"end_line":84,"end_character":52},"updated":"2026-04-20 16:32:13.000000000","message":"shouldn\u0027t this be \u003coam-floating-ip\u003e ?","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"5415badd40abc9658c71276c22e47d261e56c914","unresolved":false,"context_lines":[{"line_number":81,"context_line":"            dex_idp:"},{"line_number":82,"context_line":"                enabled: false"},{"line_number":83,"context_line":"                provider_name: \"dex\""},{"line_number":84,"context_line":"                provider_remote_id: \"https://0.0.0.0:30556/dex\" # This IP is the one used in the DEX configuration"},{"line_number":85,"context_line":"                protocol_name: \"openid\""},{"line_number":86,"context_line":"                group_name: \"federated_users\""},{"line_number":87,"context_line":"                project_name: \"federation\""}],"source_content_type":"text/x-rst","patch_set":9,"id":"9feaa6c8_2e711193","line":84,"range":{"start_line":84,"start_character":45,"end_line":84,"end_character":52},"in_reply_to":"f8858d38_e279aece","updated":"2026-04-21 14:24:53.000000000","message":"Done","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"38f45a0e43f101a1571125c4b44959e71dcdff15","unresolved":true,"context_lines":[{"line_number":92,"context_line":"                groups: []"},{"line_number":93,"context_line":"                groups_mapping: |"},{"line_number":94,"context_line":"                ..."},{"line_number":95,"context_line":"                default_mapping: |"},{"line_number":96,"context_line":"                    [{"},{"line_number":97,"context_line":"                    \"local\": [{"},{"line_number":98,"context_line":"                        \"user\": {\"name\": \"{0}\"},"},{"line_number":99,"context_line":"                        \"group\": {\"name\": \"{{ .Values.conf.federation.dex_idp.group_name }}\", \"domain\": {\"name\": \"Default\"}}"},{"line_number":100,"context_line":"                    }],"},{"line_number":101,"context_line":"                    \"remote\": [{\"type\": \"OIDC-email\"}]"},{"line_number":102,"context_line":"                    }]"},{"line_number":103,"context_line":""},{"line_number":104,"context_line":"Advanced Usage (optional)"},{"line_number":105,"context_line":"-------------------------"}],"source_content_type":"text/x-rst","patch_set":9,"id":"7807639e_67350531","line":102,"range":{"start_line":95,"start_character":0,"end_line":102,"end_character":22},"updated":"2026-04-20 16:32:13.000000000","message":"I think you need to explain the mapping here\n- locally the remote OIDC user\u0027s username gets mapped to \u0027{0}\u0027 (i.e. what you matched on ... which is the OIDC-email attribute)\n- locally \"ALL\" the remote OIDC users go into the SAME Keystone Group ? ... \u0027federated_users\u0027 ?\n- locally \"ALL\" the remote OIDC users go into the SAME Keystone Project/Tenant ? ... \u0027federation\u0027 ? \n\nbut where is the mapping to role ?\nis that done by group --\u003e role mapping in normal keystone API/CLI ?\n\n\nbut does this mean I can not\n- put some OIDC users in project X, and\n- put other OIDC users in project Y\n( ... which I would think would be a normal usecase. )\n\nAnd can I not put one particular OIDC user in multiple projects ?\n( that\u0027s another fairly common use case )","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"7f8c452547689fd9bc966a77ba416c25dd13b997","unresolved":false,"context_lines":[{"line_number":92,"context_line":"                groups: []"},{"line_number":93,"context_line":"                groups_mapping: |"},{"line_number":94,"context_line":"                ..."},{"line_number":95,"context_line":"                default_mapping: |"},{"line_number":96,"context_line":"                    [{"},{"line_number":97,"context_line":"                    \"local\": [{"},{"line_number":98,"context_line":"                        \"user\": {\"name\": \"{0}\"},"},{"line_number":99,"context_line":"                        \"group\": {\"name\": \"{{ .Values.conf.federation.dex_idp.group_name }}\", \"domain\": {\"name\": \"Default\"}}"},{"line_number":100,"context_line":"                    }],"},{"line_number":101,"context_line":"                    \"remote\": [{\"type\": \"OIDC-email\"}]"},{"line_number":102,"context_line":"                    }]"},{"line_number":103,"context_line":""},{"line_number":104,"context_line":"Advanced Usage (optional)"},{"line_number":105,"context_line":"-------------------------"}],"source_content_type":"text/x-rst","patch_set":9,"id":"39e33c71_82a1f2ca","line":102,"range":{"start_line":95,"start_character":0,"end_line":102,"end_character":22},"in_reply_to":"7807639e_67350531","updated":"2026-04-22 19:05:52.000000000","message":"Done","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"38f45a0e43f101a1571125c4b44959e71dcdff15","unresolved":true,"context_lines":[{"line_number":105,"context_line":"-------------------------"},{"line_number":106,"context_line":""},{"line_number":107,"context_line":"By default bootstrap is set to \"true\". When ``enabled: true`` the mappings are"},{"line_number":108,"context_line":"configured by default for both ``claim_groups: true`` and ``claim_groups:"},{"line_number":109,"context_line":"false``."},{"line_number":110,"context_line":""},{"line_number":111,"context_line":"The bootstrap should only be disabled if you want to manually create the"},{"line_number":112,"context_line":"mappings, groups, and projects for |OIDC| users and groups."}],"source_content_type":"text/x-rst","patch_set":9,"id":"9d8bd69c_fb5a6576","line":109,"range":{"start_line":108,"start_character":26,"end_line":109,"end_character":8},"updated":"2026-04-20 16:32:13.000000000","message":"I don\u0027t think you have said what \u0027claim_groups\u0027 controls ?","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"7f8c452547689fd9bc966a77ba416c25dd13b997","unresolved":false,"context_lines":[{"line_number":105,"context_line":"-------------------------"},{"line_number":106,"context_line":""},{"line_number":107,"context_line":"By default bootstrap is set to \"true\". When ``enabled: true`` the mappings are"},{"line_number":108,"context_line":"configured by default for both ``claim_groups: true`` and ``claim_groups:"},{"line_number":109,"context_line":"false``."},{"line_number":110,"context_line":""},{"line_number":111,"context_line":"The bootstrap should only be disabled if you want to manually create the"},{"line_number":112,"context_line":"mappings, groups, and projects for |OIDC| users and groups."}],"source_content_type":"text/x-rst","patch_set":9,"id":"5c3116cc_b3bcd719","line":109,"range":{"start_line":108,"start_character":26,"end_line":109,"end_character":8},"in_reply_to":"9d8bd69c_fb5a6576","updated":"2026-04-22 19:05:52.000000000","message":"Added reference above.","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"38f45a0e43f101a1571125c4b44959e71dcdff15","unresolved":true,"context_lines":[{"line_number":108,"context_line":"configured by default for both ``claim_groups: true`` and ``claim_groups:"},{"line_number":109,"context_line":"false``."},{"line_number":110,"context_line":""},{"line_number":111,"context_line":"The bootstrap should only be disabled if you want to manually create the"},{"line_number":112,"context_line":"mappings, groups, and projects for |OIDC| users and groups."},{"line_number":113,"context_line":""},{"line_number":114,"context_line":"To manage federation manually set:"},{"line_number":115,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"ed16f2d0_0c6ce468","line":112,"range":{"start_line":111,"start_character":0,"end_line":112,"end_character":59},"updated":"2026-04-20 16:32:13.000000000","message":"Can I not update the mappings after bootstrap of openstack, if conf.federation.bootstrap:enabled \u003d true ?","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"7f8c452547689fd9bc966a77ba416c25dd13b997","unresolved":false,"context_lines":[{"line_number":108,"context_line":"configured by default for both ``claim_groups: true`` and ``claim_groups:"},{"line_number":109,"context_line":"false``."},{"line_number":110,"context_line":""},{"line_number":111,"context_line":"The bootstrap should only be disabled if you want to manually create the"},{"line_number":112,"context_line":"mappings, groups, and projects for |OIDC| users and groups."},{"line_number":113,"context_line":""},{"line_number":114,"context_line":"To manage federation manually set:"},{"line_number":115,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"f41ea05b_9929bd5e","line":112,"range":{"start_line":111,"start_character":0,"end_line":112,"end_character":59},"in_reply_to":"ed16f2d0_0c6ce468","updated":"2026-04-22 19:05:52.000000000","message":"Done","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"38f45a0e43f101a1571125c4b44959e71dcdff15","unresolved":true,"context_lines":[{"line_number":111,"context_line":"The bootstrap should only be disabled if you want to manually create the"},{"line_number":112,"context_line":"mappings, groups, and projects for |OIDC| users and groups."},{"line_number":113,"context_line":""},{"line_number":114,"context_line":"To manage federation manually set:"},{"line_number":115,"context_line":""},{"line_number":116,"context_line":".. code-block:: none"},{"line_number":117,"context_line":""},{"line_number":118,"context_line":"    conf:"},{"line_number":119,"context_line":"      federation:"},{"line_number":120,"context_line":"        bootstrap:"},{"line_number":121,"context_line":"          enabled: false"},{"line_number":122,"context_line":""},{"line_number":123,"context_line":""},{"line_number":124,"context_line":"Dex Scenarios"}],"source_content_type":"text/x-rst","patch_set":9,"id":"0989ee14_4781eaab","line":121,"range":{"start_line":114,"start_character":0,"end_line":121,"end_character":24},"updated":"2026-04-20 16:32:13.000000000","message":"again ... you need to say what helm-overrides this is for ? ... is this another section of the helm overrides for the openstack keystone helm chart ?","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"7f8c452547689fd9bc966a77ba416c25dd13b997","unresolved":false,"context_lines":[{"line_number":111,"context_line":"The bootstrap should only be disabled if you want to manually create the"},{"line_number":112,"context_line":"mappings, groups, and projects for |OIDC| users and groups."},{"line_number":113,"context_line":""},{"line_number":114,"context_line":"To manage federation manually set:"},{"line_number":115,"context_line":""},{"line_number":116,"context_line":".. code-block:: none"},{"line_number":117,"context_line":""},{"line_number":118,"context_line":"    conf:"},{"line_number":119,"context_line":"      federation:"},{"line_number":120,"context_line":"        bootstrap:"},{"line_number":121,"context_line":"          enabled: false"},{"line_number":122,"context_line":""},{"line_number":123,"context_line":""},{"line_number":124,"context_line":"Dex Scenarios"}],"source_content_type":"text/x-rst","patch_set":9,"id":"9408a981_4bd51093","line":121,"range":{"start_line":114,"start_character":0,"end_line":121,"end_character":24},"in_reply_to":"0989ee14_4781eaab","updated":"2026-04-22 19:05:52.000000000","message":"Done","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"38f45a0e43f101a1571125c4b44959e71dcdff15","unresolved":true,"context_lines":[{"line_number":129,"context_line":"This scenario works automatically with the configurations applied during the"},{"line_number":130,"context_line":"|prod-os| deployment."},{"line_number":131,"context_line":""},{"line_number":132,"context_line":"enable dex_ipd is automatically applied if following conditions are met:"},{"line_number":133,"context_line":""},{"line_number":134,"context_line":"-   It is not set manually to false."},{"line_number":135,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"da31bfa3_4938be05","line":132,"range":{"start_line":132,"start_character":0,"end_line":132,"end_character":14},"updated":"2026-04-20 16:32:13.000000000","message":"REWORD ?\n\nEnabling of WRCP oidc-auth-apps (DEX) as the federated IDP for openstack keystone ...","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"5415badd40abc9658c71276c22e47d261e56c914","unresolved":false,"context_lines":[{"line_number":129,"context_line":"This scenario works automatically with the configurations applied during the"},{"line_number":130,"context_line":"|prod-os| deployment."},{"line_number":131,"context_line":""},{"line_number":132,"context_line":"enable dex_ipd is automatically applied if following conditions are met:"},{"line_number":133,"context_line":""},{"line_number":134,"context_line":"-   It is not set manually to false."},{"line_number":135,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"7eb441ee_892f970e","line":132,"range":{"start_line":132,"start_character":0,"end_line":132,"end_character":14},"in_reply_to":"da31bfa3_4938be05","updated":"2026-04-21 14:24:53.000000000","message":"Done","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"38f45a0e43f101a1571125c4b44959e71dcdff15","unresolved":true,"context_lines":[{"line_number":133,"context_line":""},{"line_number":134,"context_line":"-   It is not set manually to false."},{"line_number":135,"context_line":""},{"line_number":136,"context_line":"-   The |OIDC| parameters are present."},{"line_number":137,"context_line":""},{"line_number":138,"context_line":"-   Dex status is healthy."},{"line_number":139,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"5683923e_98888826","line":136,"range":{"start_line":136,"start_character":8,"end_line":136,"end_character":26},"updated":"2026-04-20 16:32:13.000000000","message":"what oidc parameters are you talking about ?\nare they the oidc parameters in \u0027system service-parameters ...\u0027\n\nif so, these will be set by default\n- on standalone and systemcontroller, to point to local DEX\n- on subcloud, to point to SystemController\u0027s DEX\n\nSo you might want to indicate that for this scenario, you have to reset the oidc parameters in \u0027system service-parameters ...\u0027 to point to local dex","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"7f8c452547689fd9bc966a77ba416c25dd13b997","unresolved":false,"context_lines":[{"line_number":133,"context_line":""},{"line_number":134,"context_line":"-   It is not set manually to false."},{"line_number":135,"context_line":""},{"line_number":136,"context_line":"-   The |OIDC| parameters are present."},{"line_number":137,"context_line":""},{"line_number":138,"context_line":"-   Dex status is healthy."},{"line_number":139,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"5a180cd4_5ab73dda","line":136,"range":{"start_line":136,"start_character":8,"end_line":136,"end_character":26},"in_reply_to":"5683923e_98888826","updated":"2026-04-22 19:05:52.000000000","message":"Done","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"38f45a0e43f101a1571125c4b44959e71dcdff15","unresolved":true,"context_lines":[{"line_number":137,"context_line":""},{"line_number":138,"context_line":"-   Dex status is healthy."},{"line_number":139,"context_line":""},{"line_number":140,"context_line":"-   The endpoint domain is configured."},{"line_number":141,"context_line":""},{"line_number":142,"context_line":"``RedirectURI`` configurations are automatically added to Dex."},{"line_number":143,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"55565f7f_f2a0e30b","line":140,"range":{"start_line":140,"start_character":0,"end_line":140,"end_character":38},"updated":"2026-04-20 16:32:13.000000000","message":"you should have a reference to point to the setting of endpoint domain ... average reader may not be aware what this is.","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"7f8c452547689fd9bc966a77ba416c25dd13b997","unresolved":false,"context_lines":[{"line_number":137,"context_line":""},{"line_number":138,"context_line":"-   Dex status is healthy."},{"line_number":139,"context_line":""},{"line_number":140,"context_line":"-   The endpoint domain is configured."},{"line_number":141,"context_line":""},{"line_number":142,"context_line":"``RedirectURI`` configurations are automatically added to Dex."},{"line_number":143,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"279a18c6_abe4523a","line":140,"range":{"start_line":140,"start_character":0,"end_line":140,"end_character":38},"in_reply_to":"55565f7f_f2a0e30b","updated":"2026-04-22 19:05:52.000000000","message":"Done","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"38f45a0e43f101a1571125c4b44959e71dcdff15","unresolved":true,"context_lines":[{"line_number":153,"context_line":"the |prod-os| Horizon ``RedirectURI`` for each subcloud where |prod-os| is"},{"line_number":154,"context_line":"installed."},{"line_number":155,"context_line":""},{"line_number":156,"context_line":"These Helm overrides were submitted in the following change: Automatically"},{"line_number":157,"context_line":"configures the Dex with the Keystone WebSSO redirect URI."},{"line_number":158,"context_line":""},{"line_number":159,"context_line":"Manually add a new ``RedirectURI``:"},{"line_number":160,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"2958e769_7da7e850","line":157,"range":{"start_line":156,"start_character":1,"end_line":157,"end_character":57},"updated":"2026-04-20 16:32:13.000000000","message":"is this stale text ?   remove ?\ncause isn\u0027t the point that it is NOT \u0027Automatically\u0027 done ?","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"5415badd40abc9658c71276c22e47d261e56c914","unresolved":false,"context_lines":[{"line_number":153,"context_line":"the |prod-os| Horizon ``RedirectURI`` for each subcloud where |prod-os| is"},{"line_number":154,"context_line":"installed."},{"line_number":155,"context_line":""},{"line_number":156,"context_line":"These Helm overrides were submitted in the following change: Automatically"},{"line_number":157,"context_line":"configures the Dex with the Keystone WebSSO redirect URI."},{"line_number":158,"context_line":""},{"line_number":159,"context_line":"Manually add a new ``RedirectURI``:"},{"line_number":160,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"f4467899_ad64af88","line":157,"range":{"start_line":156,"start_character":1,"end_line":157,"end_character":57},"in_reply_to":"2958e769_7da7e850","updated":"2026-04-21 14:24:53.000000000","message":"Done","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"38f45a0e43f101a1571125c4b44959e71dcdff15","unresolved":true,"context_lines":[{"line_number":160,"context_line":""},{"line_number":161,"context_line":".. code-block:: none"},{"line_number":162,"context_line":""},{"line_number":163,"context_line":"    \u003cWRO-KEYSTONE-EXTERNAL-URL\u003e/v3/auth/OS-FEDERATION/identity_providers/dex/protocols/openid/websso/redirect"},{"line_number":164,"context_line":"    This RedirectURI must be added to the client used in config.staticClients."},{"line_number":165,"context_line":"    Example:"},{"line_number":166,"context_line":""},{"line_number":167,"context_line":"    config:"},{"line_number":168,"context_line":"      staticClients:"},{"line_number":169,"context_line":"      - id: stx-oidc-client-app"},{"line_number":170,"context_line":"        name: STX OIDC Client app"},{"line_number":171,"context_line":"        redirectURIs:"},{"line_number":172,"context_line":"        - http://keystone.openstack.svc.cluster.local/v3/auth/OS-FEDERATION/identity_providers/dex/protocols/openid/websso/redirect"},{"line_number":173,"context_line":"        - https://10.20.9.3:30555/callback"},{"line_number":174,"context_line":"        secret: St8rlingX"}],"source_content_type":"text/x-rst","patch_set":9,"id":"dbcef006_4e90b7d6","line":174,"range":{"start_line":163,"start_character":0,"end_line":174,"end_character":25},"updated":"2026-04-20 16:32:13.000000000","message":"Again I think you need to specify the exact helm overrides and helm chart you are changing ... \nand even have all the commands ... i.e. helm-override-set and then system application-apply","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"7f8c452547689fd9bc966a77ba416c25dd13b997","unresolved":false,"context_lines":[{"line_number":160,"context_line":""},{"line_number":161,"context_line":".. code-block:: none"},{"line_number":162,"context_line":""},{"line_number":163,"context_line":"    \u003cWRO-KEYSTONE-EXTERNAL-URL\u003e/v3/auth/OS-FEDERATION/identity_providers/dex/protocols/openid/websso/redirect"},{"line_number":164,"context_line":"    This RedirectURI must be added to the client used in config.staticClients."},{"line_number":165,"context_line":"    Example:"},{"line_number":166,"context_line":""},{"line_number":167,"context_line":"    config:"},{"line_number":168,"context_line":"      staticClients:"},{"line_number":169,"context_line":"      - id: stx-oidc-client-app"},{"line_number":170,"context_line":"        name: STX OIDC Client app"},{"line_number":171,"context_line":"        redirectURIs:"},{"line_number":172,"context_line":"        - http://keystone.openstack.svc.cluster.local/v3/auth/OS-FEDERATION/identity_providers/dex/protocols/openid/websso/redirect"},{"line_number":173,"context_line":"        - https://10.20.9.3:30555/callback"},{"line_number":174,"context_line":"        secret: St8rlingX"}],"source_content_type":"text/x-rst","patch_set":9,"id":"3229d62d_79800c3e","line":174,"range":{"start_line":163,"start_character":0,"end_line":174,"end_character":25},"in_reply_to":"dbcef006_4e90b7d6","updated":"2026-04-22 19:05:52.000000000","message":"Done","commit_id":"e94e5e4b6b68864aec15bc31d236321bf3faa6a9"},{"author":{"_account_id":33594,"name":"Thales Elero Cervi","display_name":"Thales Cervi","email":"thaleselero.cervi@windriver.com","username":"tcervi"},"change_message_id":"faf1fea8b03db5c0b48c182ffd100e4885903d5a","unresolved":true,"context_lines":[{"line_number":9,"context_line":""},{"line_number":10,"context_line":".. rubric:: |context|"},{"line_number":11,"context_line":""},{"line_number":12,"context_line":"This documentation describes optional support for using \u0027platform\u0027"},{"line_number":13,"context_line":"``oidc-auth-apps`` (Dex |OIDC| Proxy |IdP|) for authentication of \u0027openstack\u0027"},{"line_number":14,"context_line":"Horizon and \u0027openstack\u0027 APIs/CLIs. In this integration, |prod-os| Keystone"},{"line_number":15,"context_line":"delegates user authentication to Dex, while authorization, project scoping, and"}],"source_content_type":"text/x-rst","patch_set":13,"id":"c8a45a38_17ee630e","line":12,"range":{"start_line":12,"start_character":29,"end_line":12,"end_character":37},"updated":"2026-04-22 19:51:44.000000000","message":"I would suggest to remove this \"optional\" word here.\nIt is not mandatory, indeed. But now that the platform bootstraps with oidc-auth applied by default, stx-opesntack will automatically apply configs required for this integration. It is \"optional\" to use, but available by default.\nUser can optionally disable the integration, also.\n\nBut still, I think this \"optional support\" reads different from what happens when stx-openstack is applied.","commit_id":"8a2e7b7ffc639fe440ab8b5ccf9e6d868b4bae3e"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"db0372a1ba8ee047ad686935b63b12dc7df913a0","unresolved":false,"context_lines":[{"line_number":9,"context_line":""},{"line_number":10,"context_line":".. rubric:: |context|"},{"line_number":11,"context_line":""},{"line_number":12,"context_line":"This documentation describes optional support for using \u0027platform\u0027"},{"line_number":13,"context_line":"``oidc-auth-apps`` (Dex |OIDC| Proxy |IdP|) for authentication of \u0027openstack\u0027"},{"line_number":14,"context_line":"Horizon and \u0027openstack\u0027 APIs/CLIs. In this integration, |prod-os| Keystone"},{"line_number":15,"context_line":"delegates user authentication to Dex, while authorization, project scoping, and"}],"source_content_type":"text/x-rst","patch_set":13,"id":"ccaf1081_51bd284b","line":12,"range":{"start_line":12,"start_character":29,"end_line":12,"end_character":37},"in_reply_to":"c8a45a38_17ee630e","updated":"2026-04-23 14:40:01.000000000","message":"Done","commit_id":"8a2e7b7ffc639fe440ab8b5ccf9e6d868b4bae3e"}],"doc/source/security/openstack/enable-dex-sso-a9e8e77ecf1b.rst":[{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"fe0abb488f4b65a994bde43b12da17a34a6d1612","unresolved":true,"context_lines":[{"line_number":4,"context_line":".. _enable-dex-sso-a9e8e77ecf1b:"},{"line_number":5,"context_line":""},{"line_number":6,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":7,"context_line":"Enable Dex SSO"},{"line_number":8,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":9,"context_line":""},{"line_number":10,"context_line":".. rubric:: |context|"}],"source_content_type":"text/x-rst","patch_set":4,"id":"8f61752f_33bfaa0f","line":7,"range":{"start_line":7,"start_character":11,"end_line":7,"end_character":14},"updated":"2026-04-06 12:33:46.000000000","message":"I would hesitate in calling this Single Sign On.\n\nNot sure it is truly single sign on.\n\ne.g. if I do DEX OIDC Authentication in support of \u0027platform\u0027 kubectl or \u0027platform\u0027 system/fm/software/sw-manager/dcmanager CLIs,\nwhen I logon to \u0027openstack\u0027 Horizon, will it automatically log in without asking me for a password ?\n\nunless it does that, I don\u0027t think we can call this SSO","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"70b78674369c73e8c25dd0f5f93868b5bd8ae3fb","unresolved":false,"context_lines":[{"line_number":4,"context_line":".. _enable-dex-sso-a9e8e77ecf1b:"},{"line_number":5,"context_line":""},{"line_number":6,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":7,"context_line":"Enable Dex SSO"},{"line_number":8,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":9,"context_line":""},{"line_number":10,"context_line":".. rubric:: |context|"}],"source_content_type":"text/x-rst","patch_set":4,"id":"5318ec79_df0712b3","line":7,"range":{"start_line":7,"start_character":11,"end_line":7,"end_character":14},"in_reply_to":"8f61752f_33bfaa0f","updated":"2026-04-15 20:54:47.000000000","message":"Done","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"fe0abb488f4b65a994bde43b12da17a34a6d1612","unresolved":true,"context_lines":[{"line_number":9,"context_line":""},{"line_number":10,"context_line":".. rubric:: |context|"},{"line_number":11,"context_line":""},{"line_number":12,"context_line":"This documentation describes the integration between Keystone and Dex using"},{"line_number":13,"context_line":"|OIDC| to enable federated authentication and |SSO|."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":".. rubric:: |prereq|"},{"line_number":16,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"bbfe5264_88696b25","line":13,"range":{"start_line":12,"start_character":29,"end_line":13,"end_character":52},"updated":"2026-04-06 12:33:46.000000000","message":"reword ?\n\noptional support for using \u0027platform\u0027 oidc-auth-apps (DEX OIDC Proxy IDP) for authentication of \u0027openstack\u0027 Horizon and \u0027openstack\u0027 APIs/CLIs .\n\n\n( is the above true ? is it supported for both horizon and clis ? )","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"70b78674369c73e8c25dd0f5f93868b5bd8ae3fb","unresolved":false,"context_lines":[{"line_number":9,"context_line":""},{"line_number":10,"context_line":".. rubric:: |context|"},{"line_number":11,"context_line":""},{"line_number":12,"context_line":"This documentation describes the integration between Keystone and Dex using"},{"line_number":13,"context_line":"|OIDC| to enable federated authentication and |SSO|."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":".. rubric:: |prereq|"},{"line_number":16,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"0f04c97f_a25d48ec","line":13,"range":{"start_line":12,"start_character":29,"end_line":13,"end_character":52},"in_reply_to":"1dcd6982_3f0aae94","updated":"2026-04-15 20:54:47.000000000","message":"Done","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":37278,"name":"Mateus Nascimento","display_name":"Mateus Nascimento","email":"Mateus.SoaresdoNascimento@windriver.com","username":"msoaresd"},"change_message_id":"c8101c8fda5f08b2e6158980963b6c6e158b6ba0","unresolved":true,"context_lines":[{"line_number":9,"context_line":""},{"line_number":10,"context_line":".. rubric:: |context|"},{"line_number":11,"context_line":""},{"line_number":12,"context_line":"This documentation describes the integration between Keystone and Dex using"},{"line_number":13,"context_line":"|OIDC| to enable federated authentication and |SSO|."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":".. rubric:: |prereq|"},{"line_number":16,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"1dcd6982_3f0aae94","line":13,"range":{"start_line":12,"start_character":29,"end_line":13,"end_character":52},"in_reply_to":"bbfe5264_88696b25","updated":"2026-04-06 18:19:45.000000000","message":"Yes, authentication is possible by the CLI (using oidc-auth -u \u003cuser\u003e) or through Horizon.","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"fe0abb488f4b65a994bde43b12da17a34a6d1612","unresolved":true,"context_lines":[{"line_number":14,"context_line":""},{"line_number":15,"context_line":".. rubric:: |prereq|"},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"-   Keystone deployed with a compatible image (latest |prod-os| Keystone image"},{"line_number":18,"context_line":"    already includes |OIDC| support)."},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"-   Dex (``oidc_auth_apps``) installed and running. Verify with: :command:`system application-list`."},{"line_number":21,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"eaa6d96d_9201ea2f","line":18,"range":{"start_line":17,"start_character":0,"end_line":18,"end_character":37},"updated":"2026-04-06 12:33:46.000000000","message":"I would remove ... user can\u0027t control this","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"44cc15ef833b249ee528fd0b4c50d31bda5ff4a5","unresolved":false,"context_lines":[{"line_number":14,"context_line":""},{"line_number":15,"context_line":".. rubric:: |prereq|"},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"-   Keystone deployed with a compatible image (latest |prod-os| Keystone image"},{"line_number":18,"context_line":"    already includes |OIDC| support)."},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"-   Dex (``oidc_auth_apps``) installed and running. Verify with: :command:`system application-list`."},{"line_number":21,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"759fce49_8ff5e93c","line":18,"range":{"start_line":17,"start_character":0,"end_line":18,"end_character":37},"in_reply_to":"eaa6d96d_9201ea2f","updated":"2026-04-09 18:42:54.000000000","message":"Done","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"fe0abb488f4b65a994bde43b12da17a34a6d1612","unresolved":true,"context_lines":[{"line_number":17,"context_line":"-   Keystone deployed with a compatible image (latest |prod-os| Keystone image"},{"line_number":18,"context_line":"    already includes |OIDC| support)."},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"-   Dex (``oidc_auth_apps``) installed and running. Verify with: :command:`system application-list`."},{"line_number":21,"context_line":""},{"line_number":22,"context_line":"-   Endpoint domain configured (required for all Dex communication)."},{"line_number":23,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"38b04abc_9904f359","line":20,"range":{"start_line":20,"start_character":0,"end_line":20,"end_character":100},"updated":"2026-04-06 12:33:46.000000000","message":"I would remove ... as of WRCP 26.03, oidc-auth-apps is automatically configured at install (or on upgrade to 26.03).","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"44cc15ef833b249ee528fd0b4c50d31bda5ff4a5","unresolved":false,"context_lines":[{"line_number":17,"context_line":"-   Keystone deployed with a compatible image (latest |prod-os| Keystone image"},{"line_number":18,"context_line":"    already includes |OIDC| support)."},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"-   Dex (``oidc_auth_apps``) installed and running. Verify with: :command:`system application-list`."},{"line_number":21,"context_line":""},{"line_number":22,"context_line":"-   Endpoint domain configured (required for all Dex communication)."},{"line_number":23,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"7913781d_1b3f7947","line":20,"range":{"start_line":20,"start_character":0,"end_line":20,"end_character":100},"in_reply_to":"38b04abc_9904f359","updated":"2026-04-09 18:42:54.000000000","message":"Done","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"fe0abb488f4b65a994bde43b12da17a34a6d1612","unresolved":true,"context_lines":[{"line_number":19,"context_line":""},{"line_number":20,"context_line":"-   Dex (``oidc_auth_apps``) installed and running. Verify with: :command:`system application-list`."},{"line_number":21,"context_line":""},{"line_number":22,"context_line":"-   Endpoint domain configured (required for all Dex communication)."},{"line_number":23,"context_line":""},{"line_number":24,"context_line":".. rubric:: |proc|"},{"line_number":25,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"3172e68e_a497fdee","line":22,"range":{"start_line":22,"start_character":0,"end_line":22,"end_character":68},"updated":"2026-04-06 12:33:46.000000000","message":"is this really required ?","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"44cc15ef833b249ee528fd0b4c50d31bda5ff4a5","unresolved":false,"context_lines":[{"line_number":19,"context_line":""},{"line_number":20,"context_line":"-   Dex (``oidc_auth_apps``) installed and running. Verify with: :command:`system application-list`."},{"line_number":21,"context_line":""},{"line_number":22,"context_line":"-   Endpoint domain configured (required for all Dex communication)."},{"line_number":23,"context_line":""},{"line_number":24,"context_line":".. rubric:: |proc|"},{"line_number":25,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"98152ddd_2747146c","line":22,"range":{"start_line":22,"start_character":0,"end_line":22,"end_character":68},"in_reply_to":"3172e68e_a497fdee","updated":"2026-04-09 18:42:54.000000000","message":"Done","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":37278,"name":"Mateus Nascimento","display_name":"Mateus Nascimento","email":"Mateus.SoaresdoNascimento@windriver.com","username":"msoaresd"},"change_message_id":"c8101c8fda5f08b2e6158980963b6c6e158b6ba0","unresolved":true,"context_lines":[{"line_number":23,"context_line":""},{"line_number":24,"context_line":".. rubric:: |proc|"},{"line_number":25,"context_line":""},{"line_number":26,"context_line":"Add the following Keystone override:"},{"line_number":27,"context_line":""},{"line_number":28,"context_line":".. code-block:: none"},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"    conf:"},{"line_number":31,"context_line":"      federation:"},{"line_number":32,"context_line":"        dex_idp:"},{"line_number":33,"context_line":"          enabled: true"},{"line_number":34,"context_line":""},{"line_number":35,"context_line":"Automatically:"},{"line_number":36,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"25cbed7a_44083ef4","line":33,"range":{"start_line":26,"start_character":0,"end_line":33,"end_character":23},"updated":"2026-04-06 18:19:45.000000000","message":"These overrides are no longer needed since https://review.opendev.org/c/starlingx/openstack-armada-app/+/980503 was merged.","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"fe0abb488f4b65a994bde43b12da17a34a6d1612","unresolved":true,"context_lines":[{"line_number":23,"context_line":""},{"line_number":24,"context_line":".. rubric:: |proc|"},{"line_number":25,"context_line":""},{"line_number":26,"context_line":"Add the following Keystone override:"},{"line_number":27,"context_line":""},{"line_number":28,"context_line":".. code-block:: none"},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"    conf:"},{"line_number":31,"context_line":"      federation:"},{"line_number":32,"context_line":"        dex_idp:"},{"line_number":33,"context_line":"          enabled: true"},{"line_number":34,"context_line":""},{"line_number":35,"context_line":"Automatically:"},{"line_number":36,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"5c475c3f_1ae320c8","line":33,"range":{"start_line":26,"start_character":0,"end_line":33,"end_character":23},"updated":"2026-04-06 12:33:46.000000000","message":"should you have the procedure for how to do this ?","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"44cc15ef833b249ee528fd0b4c50d31bda5ff4a5","unresolved":false,"context_lines":[{"line_number":23,"context_line":""},{"line_number":24,"context_line":".. rubric:: |proc|"},{"line_number":25,"context_line":""},{"line_number":26,"context_line":"Add the following Keystone override:"},{"line_number":27,"context_line":""},{"line_number":28,"context_line":".. code-block:: none"},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"    conf:"},{"line_number":31,"context_line":"      federation:"},{"line_number":32,"context_line":"        dex_idp:"},{"line_number":33,"context_line":"          enabled: true"},{"line_number":34,"context_line":""},{"line_number":35,"context_line":"Automatically:"},{"line_number":36,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"70789a54_5901ecad","line":33,"range":{"start_line":26,"start_character":0,"end_line":33,"end_character":23},"in_reply_to":"25cbed7a_44083ef4","updated":"2026-04-09 18:42:54.000000000","message":"Done","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"44cc15ef833b249ee528fd0b4c50d31bda5ff4a5","unresolved":false,"context_lines":[{"line_number":23,"context_line":""},{"line_number":24,"context_line":".. rubric:: |proc|"},{"line_number":25,"context_line":""},{"line_number":26,"context_line":"Add the following Keystone override:"},{"line_number":27,"context_line":""},{"line_number":28,"context_line":".. code-block:: none"},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"    conf:"},{"line_number":31,"context_line":"      federation:"},{"line_number":32,"context_line":"        dex_idp:"},{"line_number":33,"context_line":"          enabled: true"},{"line_number":34,"context_line":""},{"line_number":35,"context_line":"Automatically:"},{"line_number":36,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"0d041ea2_2fe5b66f","line":33,"range":{"start_line":26,"start_character":0,"end_line":33,"end_character":23},"in_reply_to":"5c475c3f_1ae320c8","updated":"2026-04-09 18:42:54.000000000","message":"Done","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"fe0abb488f4b65a994bde43b12da17a34a6d1612","unresolved":true,"context_lines":[{"line_number":32,"context_line":"        dex_idp:"},{"line_number":33,"context_line":"          enabled: true"},{"line_number":34,"context_line":""},{"line_number":35,"context_line":"Automatically:"},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"-   Dex is registered as an Identity Provider"},{"line_number":38,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"ec528fd2_453d11bc","line":35,"range":{"start_line":35,"start_character":0,"end_line":35,"end_character":13},"updated":"2026-04-06 12:33:46.000000000","message":"Do you mean that when the above keystone overrides are used, \nthe following things are done ?","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"44cc15ef833b249ee528fd0b4c50d31bda5ff4a5","unresolved":false,"context_lines":[{"line_number":32,"context_line":"        dex_idp:"},{"line_number":33,"context_line":"          enabled: true"},{"line_number":34,"context_line":""},{"line_number":35,"context_line":"Automatically:"},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"-   Dex is registered as an Identity Provider"},{"line_number":38,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"3d9f1f05_288c337a","line":35,"range":{"start_line":35,"start_character":0,"end_line":35,"end_character":13},"in_reply_to":"ec528fd2_453d11bc","updated":"2026-04-09 18:42:54.000000000","message":"Done","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"fe0abb488f4b65a994bde43b12da17a34a6d1612","unresolved":true,"context_lines":[{"line_number":34,"context_line":""},{"line_number":35,"context_line":"Automatically:"},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"-   Dex is registered as an Identity Provider"},{"line_number":38,"context_line":""},{"line_number":39,"context_line":"-   Default federation mapping is applied"},{"line_number":40,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"879fc948_02764d49","line":37,"range":{"start_line":37,"start_character":4,"end_line":37,"end_character":45},"updated":"2026-04-06 12:33:46.000000000","message":"? \u0027platform\u0027 DEX (oidc-auth-apps) is registered as an Identity Provider backend(?) for Keystone ... ? in addition to the default local SQL DB backend ?","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"48310bbe432726ef272ee1ed3bd9267501874360","unresolved":false,"context_lines":[{"line_number":34,"context_line":""},{"line_number":35,"context_line":"Automatically:"},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"-   Dex is registered as an Identity Provider"},{"line_number":38,"context_line":""},{"line_number":39,"context_line":"-   Default federation mapping is applied"},{"line_number":40,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"c221b664_bea7c1e6","line":37,"range":{"start_line":37,"start_character":4,"end_line":37,"end_character":45},"in_reply_to":"879fc948_02764d49","updated":"2026-04-16 18:16:05.000000000","message":"Done","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"fe0abb488f4b65a994bde43b12da17a34a6d1612","unresolved":true,"context_lines":[{"line_number":36,"context_line":""},{"line_number":37,"context_line":"-   Dex is registered as an Identity Provider"},{"line_number":38,"context_line":""},{"line_number":39,"context_line":"-   Default federation mapping is applied"},{"line_number":40,"context_line":""},{"line_number":41,"context_line":"-   Required resources are created automatically:"},{"line_number":42,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"74641285_bbe4dce7","line":39,"range":{"start_line":39,"start_character":0,"end_line":39,"end_character":41},"updated":"2026-04-06 12:33:46.000000000","message":"not sure what this means ?","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"48310bbe432726ef272ee1ed3bd9267501874360","unresolved":false,"context_lines":[{"line_number":36,"context_line":""},{"line_number":37,"context_line":"-   Dex is registered as an Identity Provider"},{"line_number":38,"context_line":""},{"line_number":39,"context_line":"-   Default federation mapping is applied"},{"line_number":40,"context_line":""},{"line_number":41,"context_line":"-   Required resources are created automatically:"},{"line_number":42,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"982f671b_2f0b5ba0","line":39,"range":{"start_line":39,"start_character":0,"end_line":39,"end_character":41},"in_reply_to":"74641285_bbe4dce7","updated":"2026-04-16 18:16:05.000000000","message":"More info in https://review.opendev.org/c/starlingx/docs/+/984476","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"fe0abb488f4b65a994bde43b12da17a34a6d1612","unresolved":true,"context_lines":[{"line_number":38,"context_line":""},{"line_number":39,"context_line":"-   Default federation mapping is applied"},{"line_number":40,"context_line":""},{"line_number":41,"context_line":"-   Required resources are created automatically:"},{"line_number":42,"context_line":""},{"line_number":43,"context_line":"    - Group"},{"line_number":44,"context_line":"    - Project"},{"line_number":45,"context_line":"    - Role and role assignment"},{"line_number":46,"context_line":"    - Federation protocol"},{"line_number":47,"context_line":""},{"line_number":48,"context_line":".. note::"},{"line_number":49,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"8b1ffc4b_5ea77bcc","line":46,"range":{"start_line":41,"start_character":0,"end_line":46,"end_character":25},"updated":"2026-04-06 12:33:46.000000000","message":"Not sure what this means either ...\n\ne.g. obvious question is how are OIDC users/groups assigned Keystone Roles ?","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":37278,"name":"Mateus Nascimento","display_name":"Mateus Nascimento","email":"Mateus.SoaresdoNascimento@windriver.com","username":"msoaresd"},"change_message_id":"c8101c8fda5f08b2e6158980963b6c6e158b6ba0","unresolved":true,"context_lines":[{"line_number":36,"context_line":""},{"line_number":37,"context_line":"-   Dex is registered as an Identity Provider"},{"line_number":38,"context_line":""},{"line_number":39,"context_line":"-   Default federation mapping is applied"},{"line_number":40,"context_line":""},{"line_number":41,"context_line":"-   Required resources are created automatically:"},{"line_number":42,"context_line":""},{"line_number":43,"context_line":"    - Group"},{"line_number":44,"context_line":"    - Project"},{"line_number":45,"context_line":"    - Role and role assignment"},{"line_number":46,"context_line":"    - Federation protocol"},{"line_number":47,"context_line":""},{"line_number":48,"context_line":".. note::"},{"line_number":49,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"48a98d32_ef775279","line":46,"range":{"start_line":39,"start_character":0,"end_line":46,"end_character":25},"updated":"2026-04-06 18:19:45.000000000","message":"This part is not clear, the mappings need to be better described, since there are several possible combinations of how users can configure them in the OpenStack documentation: https://docs.openstack.org/keystone/train/admin/federation/mapping_combinations.html\n\nAlso, by default, we use a mapping combination depending on whether the user wants to map OIDC groups to Keystone (claim_groups: true) or not (claim_groups: false): https://opendev.org/starlingx/openstack-armada-app/src/commit/c11ed279009ec0d2e2bb9cf388ff37b190741fc7/stx-openstack-helm-fluxcd/stx-openstack-helm-fluxcd/manifests/keystone/keystone-static-overrides.yaml#L615-L636\n\nIt is important to note that resources are created differently depending on whether claim_groups is set to true or false.\n\nIf claim_groups is true, the groups must exist in Keystone and can be bootstrapped with projects and roles using, for example, these overrides https://opendev.org/starlingx/openstack-armada-app/src/commit/c11ed279009ec0d2e2bb9cf388ff37b190741fc7/stx-openstack-helm-fluxcd/stx-openstack-helm-fluxcd/manifests/keystone/keystone-static-overrides.yaml#L610-L614 or created manually. If claim_groups is false, every OIDC user is assigned to a default generated group for federated users (federated_users) with member role: https://opendev.org/starlingx/openstack-armada-app/src/commit/c11ed279009ec0d2e2bb9cf388ff37b190741fc7/stx-openstack-helm-fluxcd/stx-openstack-helm-fluxcd/manifests/keystone/keystone-static-overrides.yaml#L600-L601","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"48310bbe432726ef272ee1ed3bd9267501874360","unresolved":false,"context_lines":[{"line_number":36,"context_line":""},{"line_number":37,"context_line":"-   Dex is registered as an Identity Provider"},{"line_number":38,"context_line":""},{"line_number":39,"context_line":"-   Default federation mapping is applied"},{"line_number":40,"context_line":""},{"line_number":41,"context_line":"-   Required resources are created automatically:"},{"line_number":42,"context_line":""},{"line_number":43,"context_line":"    - Group"},{"line_number":44,"context_line":"    - Project"},{"line_number":45,"context_line":"    - Role and role assignment"},{"line_number":46,"context_line":"    - Federation protocol"},{"line_number":47,"context_line":""},{"line_number":48,"context_line":".. note::"},{"line_number":49,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"7b24b406_b82f9e17","line":46,"range":{"start_line":39,"start_character":0,"end_line":46,"end_character":25},"in_reply_to":"48a98d32_ef775279","updated":"2026-04-16 18:16:05.000000000","message":"Done","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"48310bbe432726ef272ee1ed3bd9267501874360","unresolved":false,"context_lines":[{"line_number":38,"context_line":""},{"line_number":39,"context_line":"-   Default federation mapping is applied"},{"line_number":40,"context_line":""},{"line_number":41,"context_line":"-   Required resources are created automatically:"},{"line_number":42,"context_line":""},{"line_number":43,"context_line":"    - Group"},{"line_number":44,"context_line":"    - Project"},{"line_number":45,"context_line":"    - Role and role assignment"},{"line_number":46,"context_line":"    - Federation protocol"},{"line_number":47,"context_line":""},{"line_number":48,"context_line":".. note::"},{"line_number":49,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"ff7bcdff_39b76c32","line":46,"range":{"start_line":41,"start_character":0,"end_line":46,"end_character":25},"in_reply_to":"8b1ffc4b_5ea77bcc","updated":"2026-04-16 18:16:05.000000000","message":"https://review.opendev.org/c/starlingx/docs/+/984476","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"fe0abb488f4b65a994bde43b12da17a34a6d1612","unresolved":true,"context_lines":[{"line_number":51,"context_line":""},{"line_number":52,"context_line":".. rubric:: |result|"},{"line_number":53,"context_line":""},{"line_number":54,"context_line":"-   Horizon shows “Login with DEX SSO”"},{"line_number":55,"context_line":""},{"line_number":56,"context_line":"-   Users authenticated via Dex:"},{"line_number":57,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"f97844c9_71bd144a","line":54,"range":{"start_line":54,"start_character":30,"end_line":54,"end_character":34},"updated":"2026-04-06 12:33:46.000000000","message":"would it be more accurate to say \u0027oidc-auth-apps (DEX)\u0027\n\n\ni.e. to make it obvious to user that the local platform dex is being used","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"70b78674369c73e8c25dd0f5f93868b5bd8ae3fb","unresolved":false,"context_lines":[{"line_number":51,"context_line":""},{"line_number":52,"context_line":".. rubric:: |result|"},{"line_number":53,"context_line":""},{"line_number":54,"context_line":"-   Horizon shows “Login with DEX SSO”"},{"line_number":55,"context_line":""},{"line_number":56,"context_line":"-   Users authenticated via Dex:"},{"line_number":57,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"1ab906fb_9596238a","line":54,"range":{"start_line":54,"start_character":30,"end_line":54,"end_character":34},"in_reply_to":"f97844c9_71bd144a","updated":"2026-04-15 20:54:47.000000000","message":"Done","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"fe0abb488f4b65a994bde43b12da17a34a6d1612","unresolved":true,"context_lines":[{"line_number":56,"context_line":"-   Users authenticated via Dex:"},{"line_number":57,"context_line":""},{"line_number":58,"context_line":"    - Are identified by email"},{"line_number":59,"context_line":"    - Are added to a default group"},{"line_number":60,"context_line":"    - Receive access to a default project"},{"line_number":61,"context_line":""},{"line_number":62,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"369489d2_e1b6dfbc","line":59,"range":{"start_line":59,"start_character":0,"end_line":59,"end_character":34},"updated":"2026-04-06 12:33:46.000000000","message":"what default group ?\n \n and what exactly is meant by \u0027group\u0027 in context of Keystone ?\n is it the tenant ?","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"48310bbe432726ef272ee1ed3bd9267501874360","unresolved":false,"context_lines":[{"line_number":56,"context_line":"-   Users authenticated via Dex:"},{"line_number":57,"context_line":""},{"line_number":58,"context_line":"    - Are identified by email"},{"line_number":59,"context_line":"    - Are added to a default group"},{"line_number":60,"context_line":"    - Receive access to a default project"},{"line_number":61,"context_line":""},{"line_number":62,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"13071ce5_5bc15000","line":59,"range":{"start_line":59,"start_character":0,"end_line":59,"end_character":34},"in_reply_to":"369489d2_e1b6dfbc","updated":"2026-04-16 18:16:05.000000000","message":"https://review.opendev.org/c/starlingx/docs/+/984476","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"fe0abb488f4b65a994bde43b12da17a34a6d1612","unresolved":true,"context_lines":[{"line_number":57,"context_line":""},{"line_number":58,"context_line":"    - Are identified by email"},{"line_number":59,"context_line":"    - Are added to a default group"},{"line_number":60,"context_line":"    - Receive access to a default project"},{"line_number":61,"context_line":""},{"line_number":62,"context_line":""},{"line_number":63,"context_line":"Advanced Usage (optional)"}],"source_content_type":"text/x-rst","patch_set":4,"id":"9ee5fe41_afc67ae4","line":60,"range":{"start_line":60,"start_character":0,"end_line":60,"end_character":41},"updated":"2026-04-06 12:33:46.000000000","message":"what default project ?","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"48310bbe432726ef272ee1ed3bd9267501874360","unresolved":false,"context_lines":[{"line_number":57,"context_line":""},{"line_number":58,"context_line":"    - Are identified by email"},{"line_number":59,"context_line":"    - Are added to a default group"},{"line_number":60,"context_line":"    - Receive access to a default project"},{"line_number":61,"context_line":""},{"line_number":62,"context_line":""},{"line_number":63,"context_line":"Advanced Usage (optional)"}],"source_content_type":"text/x-rst","patch_set":4,"id":"adc0e2dc_ccacff98","line":60,"range":{"start_line":60,"start_character":0,"end_line":60,"end_character":41},"in_reply_to":"9ee5fe41_afc67ae4","updated":"2026-04-16 18:16:05.000000000","message":"https://review.opendev.org/c/starlingx/docs/+/984476","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"fe0abb488f4b65a994bde43b12da17a34a6d1612","unresolved":true,"context_lines":[{"line_number":58,"context_line":"    - Are identified by email"},{"line_number":59,"context_line":"    - Are added to a default group"},{"line_number":60,"context_line":"    - Receive access to a default project"},{"line_number":61,"context_line":""},{"line_number":62,"context_line":""},{"line_number":63,"context_line":"Advanced Usage (optional)"},{"line_number":64,"context_line":"-------------------------"}],"source_content_type":"text/x-rst","patch_set":4,"id":"93358945_0900c0e4","line":61,"updated":"2026-04-06 12:33:46.000000000","message":"and again, how is authorization, i.e. role assignment, being done ?","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"48310bbe432726ef272ee1ed3bd9267501874360","unresolved":false,"context_lines":[{"line_number":58,"context_line":"    - Are identified by email"},{"line_number":59,"context_line":"    - Are added to a default group"},{"line_number":60,"context_line":"    - Receive access to a default project"},{"line_number":61,"context_line":""},{"line_number":62,"context_line":""},{"line_number":63,"context_line":"Advanced Usage (optional)"},{"line_number":64,"context_line":"-------------------------"}],"source_content_type":"text/x-rst","patch_set":4,"id":"8df1cd40_fea42a33","line":61,"in_reply_to":"93358945_0900c0e4","updated":"2026-04-16 18:16:05.000000000","message":"https://review.opendev.org/c/starlingx/docs/+/984476","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":37278,"name":"Mateus Nascimento","display_name":"Mateus Nascimento","email":"Mateus.SoaresdoNascimento@windriver.com","username":"msoaresd"},"change_message_id":"c8101c8fda5f08b2e6158980963b6c6e158b6ba0","unresolved":true,"context_lines":[{"line_number":63,"context_line":"Advanced Usage (optional)"},{"line_number":64,"context_line":"-------------------------"},{"line_number":65,"context_line":""},{"line_number":66,"context_line":"To manage federation manually:"},{"line_number":67,"context_line":""},{"line_number":68,"context_line":".. code-block:: none"},{"line_number":69,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"e238516f_e2412921","line":66,"range":{"start_line":66,"start_character":0,"end_line":66,"end_character":30},"updated":"2026-04-06 18:19:45.000000000","message":"This part needs a better explanation and should mention that, by default, bootstrap is set to true. This is the reason why mappings are configured by default for both claim_groups: true and claim_groups: false, and it should also clarify that this is where the creation of groups and projects happens: https://opendev.org/starlingx/openstack-armada-app/src/commit/c11ed279009ec0d2e2bb9cf388ff37b190741fc7/stx-openstack-helm-fluxcd/stx-openstack-helm-fluxcd/manifests/keystone/keystone-static-overrides.yaml#L638-L640\n\nIt should also mention that bootstrap should only be disabled if the user wants to manually create the mappings, groups, and projects for OIDC users and groups.","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"44cc15ef833b249ee528fd0b4c50d31bda5ff4a5","unresolved":false,"context_lines":[{"line_number":63,"context_line":"Advanced Usage (optional)"},{"line_number":64,"context_line":"-------------------------"},{"line_number":65,"context_line":""},{"line_number":66,"context_line":"To manage federation manually:"},{"line_number":67,"context_line":""},{"line_number":68,"context_line":".. code-block:: none"},{"line_number":69,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"85ca4d75_ee6a7925","line":66,"range":{"start_line":66,"start_character":0,"end_line":66,"end_character":30},"in_reply_to":"e238516f_e2412921","updated":"2026-04-09 18:42:54.000000000","message":"Done","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"fe0abb488f4b65a994bde43b12da17a34a6d1612","unresolved":true,"context_lines":[{"line_number":63,"context_line":"Advanced Usage (optional)"},{"line_number":64,"context_line":"-------------------------"},{"line_number":65,"context_line":""},{"line_number":66,"context_line":"To manage federation manually:"},{"line_number":67,"context_line":""},{"line_number":68,"context_line":".. code-block:: none"},{"line_number":69,"context_line":""},{"line_number":70,"context_line":"    conf:"},{"line_number":71,"context_line":"      federation:"},{"line_number":72,"context_line":"        bootstrap:"},{"line_number":73,"context_line":"          enabled: false"},{"line_number":74,"context_line":""},{"line_number":75,"context_line":"Use this only if you are familiar with Keystone federation."},{"line_number":76,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"36893b5b_85e3c736","line":73,"range":{"start_line":66,"start_character":0,"end_line":73,"end_character":24},"updated":"2026-04-06 12:33:46.000000000","message":"unclear what this does differently than previous section description","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"44cc15ef833b249ee528fd0b4c50d31bda5ff4a5","unresolved":false,"context_lines":[{"line_number":63,"context_line":"Advanced Usage (optional)"},{"line_number":64,"context_line":"-------------------------"},{"line_number":65,"context_line":""},{"line_number":66,"context_line":"To manage federation manually:"},{"line_number":67,"context_line":""},{"line_number":68,"context_line":".. code-block:: none"},{"line_number":69,"context_line":""},{"line_number":70,"context_line":"    conf:"},{"line_number":71,"context_line":"      federation:"},{"line_number":72,"context_line":"        bootstrap:"},{"line_number":73,"context_line":"          enabled: false"},{"line_number":74,"context_line":""},{"line_number":75,"context_line":"Use this only if you are familiar with Keystone federation."},{"line_number":76,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"40dd18fe_3d5ede0f","line":73,"range":{"start_line":66,"start_character":0,"end_line":73,"end_character":24},"in_reply_to":"36893b5b_85e3c736","updated":"2026-04-09 18:42:54.000000000","message":"Done","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":37278,"name":"Mateus Nascimento","display_name":"Mateus Nascimento","email":"Mateus.SoaresdoNascimento@windriver.com","username":"msoaresd"},"change_message_id":"c8101c8fda5f08b2e6158980963b6c6e158b6ba0","unresolved":true,"context_lines":[{"line_number":119,"context_line":"    This RedirectURI must be added to the client used in config.staticClients."},{"line_number":120,"context_line":"    Example:"},{"line_number":121,"context_line":""},{"line_number":122,"context_line":"    config:"},{"line_number":123,"context_line":"    staticClients:"},{"line_number":124,"context_line":"    - id: stx-oidc-client-app"},{"line_number":125,"context_line":"        name: STX OIDC Client app"}],"source_content_type":"text/x-rst","patch_set":4,"id":"3eb5aca2_4f9145e6","line":122,"updated":"2026-04-06 18:19:45.000000000","message":"Indentation error","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"44cc15ef833b249ee528fd0b4c50d31bda5ff4a5","unresolved":false,"context_lines":[{"line_number":119,"context_line":"    This RedirectURI must be added to the client used in config.staticClients."},{"line_number":120,"context_line":"    Example:"},{"line_number":121,"context_line":""},{"line_number":122,"context_line":"    config:"},{"line_number":123,"context_line":"    staticClients:"},{"line_number":124,"context_line":"    - id: stx-oidc-client-app"},{"line_number":125,"context_line":"        name: STX OIDC Client app"}],"source_content_type":"text/x-rst","patch_set":4,"id":"c3b2afbb_51d08a45","line":122,"in_reply_to":"3eb5aca2_4f9145e6","updated":"2026-04-09 18:42:54.000000000","message":"Done","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":37278,"name":"Mateus Nascimento","display_name":"Mateus Nascimento","email":"Mateus.SoaresdoNascimento@windriver.com","username":"msoaresd"},"change_message_id":"c8101c8fda5f08b2e6158980963b6c6e158b6ba0","unresolved":true,"context_lines":[{"line_number":122,"context_line":"    config:"},{"line_number":123,"context_line":"    staticClients:"},{"line_number":124,"context_line":"    - id: stx-oidc-client-app"},{"line_number":125,"context_line":"        name: STX OIDC Client app"},{"line_number":126,"context_line":"        redirectURIs:"},{"line_number":127,"context_line":"        - http://keystone.openstack.svc.cluster.local/v3/auth/OS-FEDERATION/identity_providers/dex/protocols/openid/websso/redirect"},{"line_number":128,"context_line":"        - https://10.20.9.3:30555/callback"},{"line_number":129,"context_line":"        secret: St8rlingX"}],"source_content_type":"text/x-rst","patch_set":4,"id":"0183b504_85da23ed","line":126,"range":{"start_line":125,"start_character":0,"end_line":126,"end_character":21},"updated":"2026-04-06 18:19:45.000000000","message":"Indentation errors","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"},{"author":{"_account_id":33342,"name":"Elisamara Aoki Gonçalves","email":"elisamaraaoki.goncalves@windriver.com","username":"egoncalv"},"change_message_id":"44cc15ef833b249ee528fd0b4c50d31bda5ff4a5","unresolved":false,"context_lines":[{"line_number":122,"context_line":"    config:"},{"line_number":123,"context_line":"    staticClients:"},{"line_number":124,"context_line":"    - id: stx-oidc-client-app"},{"line_number":125,"context_line":"        name: STX OIDC Client app"},{"line_number":126,"context_line":"        redirectURIs:"},{"line_number":127,"context_line":"        - http://keystone.openstack.svc.cluster.local/v3/auth/OS-FEDERATION/identity_providers/dex/protocols/openid/websso/redirect"},{"line_number":128,"context_line":"        - https://10.20.9.3:30555/callback"},{"line_number":129,"context_line":"        secret: St8rlingX"}],"source_content_type":"text/x-rst","patch_set":4,"id":"646809ba_cd35e7db","line":126,"range":{"start_line":125,"start_character":0,"end_line":126,"end_character":21},"in_reply_to":"0183b504_85da23ed","updated":"2026-04-09 18:42:54.000000000","message":"Done","commit_id":"3182ae24e27a4f40d1ef7dc97985a7722227a5c7"}]}
