)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":33594,"name":"Thales Elero Cervi","display_name":"Thales Cervi","email":"thaleselero.cervi@windriver.com","username":"tcervi"},"change_message_id":"a74e95280bfc46593d430d81aa3635544348c7c4","unresolved":true,"context_lines":[{"line_number":9,"context_line":"It was observed that, when using the STX-Openstack app with HTTPS"},{"line_number":10,"context_line":"enabled, it was not possible to visualize / edit / create images using"},{"line_number":11,"context_line":"Horizon. This was caused because the SSL certificate (ca.crt) volume"},{"line_number":12,"context_line":"mount path defined in Horizon\u0027s configuration [1] was not the same as"},{"line_number":13,"context_line":"the default one created when using the Helm toolkit [2]."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"As specified in [3], one possible solution was to define a path to the"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":4,"id":"f6ac2511_f400f857","line":12,"updated":"2023-08-24 19:22:54.000000000","message":"You are correct here, I wonder why this path was chosen for Horizon on usptream OSH. That might be an interesting topic to bring to openstack/osh community attention.\nIt is important to  notice that the \"horizon/templates/deployment.yaml\" code was not present on our previous OSH base version [1], so that is why this bug only started to happen after our OSH-I/OSH uprevs.\n\nOn our app, we highly rely on \u0027/etc/ssl/certs/openstack-helm.crt\u0027 path for certificates indeed [2].\n\n[1] https://github.com/openstack/openstack-helm/blob/7803000a545687ec40b0ddc41d46a6b377dea45f/horizon/templates/deployment.yaml#L78\n[2] https://opendev.org/starlingx/openstack-armada-app/src/commit/be56c15bc043528f4448ae607182d97641fc8766/python3-k8sapp-openstack/k8sapp_openstack/k8sapp_openstack/helm/openstack.py#L685","commit_id":"24dc8c9dca6c2b19dc080ebc6172610b6a19d4a7"},{"author":{"_account_id":33594,"name":"Thales Elero Cervi","display_name":"Thales Cervi","email":"thaleselero.cervi@windriver.com","username":"tcervi"},"change_message_id":"dc46e73e6fadacfa9ac55109b7941141ed6b5379","unresolved":false,"context_lines":[{"line_number":9,"context_line":"It was observed that, when using the STX-Openstack app with HTTPS"},{"line_number":10,"context_line":"enabled, it was not possible to visualize / edit / create images using"},{"line_number":11,"context_line":"Horizon. This was caused because the SSL certificate (ca.crt) volume"},{"line_number":12,"context_line":"mount path defined in Horizon\u0027s configuration [1] was not the same as"},{"line_number":13,"context_line":"the default one created when using the Helm toolkit [2]."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"As specified in [3], one possible solution was to define a path to the"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":4,"id":"9c223edc_788fa775","line":12,"in_reply_to":"f6ac2511_f400f857","updated":"2023-08-28 15:02:00.000000000","message":"Done","commit_id":"24dc8c9dca6c2b19dc080ebc6172610b6a19d4a7"},{"author":{"_account_id":33594,"name":"Thales Elero Cervi","display_name":"Thales Cervi","email":"thaleselero.cervi@windriver.com","username":"tcervi"},"change_message_id":"a74e95280bfc46593d430d81aa3635544348c7c4","unresolved":false,"context_lines":[{"line_number":12,"context_line":"mount path defined in Horizon\u0027s configuration [1] was not the same as"},{"line_number":13,"context_line":"the default one created when using the Helm toolkit [2]."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"As specified in [3], one possible solution was to define a path to the"},{"line_number":16,"context_line":"TLS secret to be created, but that caused other services in Horizon to"},{"line_number":17,"context_line":"fail, so instead of doing that, the solution was to change Horizon\u0027s"},{"line_number":18,"context_line":"configuration to search the ca.crt file in the correct path."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":4,"id":"d975a07c_c7eac3f6","line":15,"updated":"2023-08-24 19:22:54.000000000","message":"Ok, so if we are not proceeding with certificate path please check my comments on your code changes bellow.","commit_id":"24dc8c9dca6c2b19dc080ebc6172610b6a19d4a7"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":33594,"name":"Thales Elero Cervi","display_name":"Thales Cervi","email":"thaleselero.cervi@windriver.com","username":"tcervi"},"change_message_id":"a74e95280bfc46593d430d81aa3635544348c7c4","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"54e49b87_bf7b9eaf","updated":"2023-08-24 19:22:54.000000000","message":"Thanks for quickly fixing this issue Lucas.\n\nI have some concerns on this fix approach, so left a couple of comments for us to discuss.\n\nAlso, please note that whenever we have to patch OSH-I or OSH source code, it is a good practice to propose same changes upstream. This way, we give back to the openstack community and also have other eyes on our proposals.\n\nA change to values.yaml is usually handled via static overrides, please check my comment bellow.","commit_id":"24dc8c9dca6c2b19dc080ebc6172610b6a19d4a7"},{"author":{"_account_id":35467,"name":"Luan Utimura","display_name":"Luan Utimura","email":"luan.utimura@luizalabs.com","username":"lutimura"},"change_message_id":"92040c17bc83b8a69f79b4e9866019959d3fc52c","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":4,"id":"9bfe0380_ab9504cf","in_reply_to":"54e49b87_bf7b9eaf","updated":"2023-08-24 19:36:39.000000000","message":"\u003e A change to values.yaml is usually handled via static overrides, please check my comment bellow.\n\nAgreed.\n\nWhat if we perform this override via plugin instead of static overrides?\nWe already have a bunch of HTTPS-related overrides being set there...","commit_id":"24dc8c9dca6c2b19dc080ebc6172610b6a19d4a7"},{"author":{"_account_id":35467,"name":"Luan Utimura","display_name":"Luan Utimura","email":"luan.utimura@luizalabs.com","username":"lutimura"},"change_message_id":"57fcdf492a091f4c523a7d63e38e2dac7a010a4d","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"6f8c1741_bd22bc15","in_reply_to":"7afe4328_973e9788","updated":"2023-08-28 15:13:50.000000000","message":"Me too.\n\nThank you, Lucas!","commit_id":"24dc8c9dca6c2b19dc080ebc6172610b6a19d4a7"},{"author":{"_account_id":34455,"name":"Lucas de Ataides Barreto","display_name":"Lucas de Ataides","email":"lucas.deataidesbarreto@windriver.com","username":"lucasdeataides"},"change_message_id":"baf523ee9e67e9bc56e8e15db6c8a3cc5dbd332f","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":4,"id":"d52ac42e_26f3fbd8","in_reply_to":"9bfe0380_ab9504cf","updated":"2023-08-28 13:22:55.000000000","message":"Based on the discussion on the StarlingX Matrix chat: https://matrix.to/#/!ALNJdVPzLBhgSGXwMi:opendev.org/$Qkf67WCHMUy2__V8BJsW2FxfAgGgkqgrta87ycDXtfg?via\u003dmatrix.org\u0026via\u003dopendev.org\ndo you agree with the new patchset?","commit_id":"24dc8c9dca6c2b19dc080ebc6172610b6a19d4a7"},{"author":{"_account_id":33594,"name":"Thales Elero Cervi","display_name":"Thales Cervi","email":"thaleselero.cervi@windriver.com","username":"tcervi"},"change_message_id":"dc46e73e6fadacfa9ac55109b7941141ed6b5379","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":4,"id":"7afe4328_973e9788","in_reply_to":"d52ac42e_26f3fbd8","updated":"2023-08-28 15:02:00.000000000","message":"I am fine with this new approach","commit_id":"24dc8c9dca6c2b19dc080ebc6172610b6a19d4a7"},{"author":{"_account_id":33594,"name":"Thales Elero Cervi","display_name":"Thales Cervi","email":"thaleselero.cervi@windriver.com","username":"tcervi"},"change_message_id":"15f0cb0e2c4a0601c53357abac68f0663210b6e5","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"50102e87_f6c2c46b","updated":"2023-08-28 15:01:24.000000000","message":"Thanks for updating it Lucas, looks like a better solution now.\nCheers!","commit_id":"efd6f74d40762afeebefad17b2e59626403e8eb3"}],"openstack-helm/debian/deb_folder/patches/0019-Change-Horizon-CA-Cert-file-path.patch":[{"author":{"_account_id":33594,"name":"Thales Elero Cervi","display_name":"Thales Cervi","email":"thaleselero.cervi@windriver.com","username":"tcervi"},"change_message_id":"b9265edbbbf7f5456f1b2306b527f913ad2d84d0","unresolved":true,"context_lines":[{"line_number":33,"context_line":"+++ b/horizon/templates/deployment.yaml"},{"line_number":34,"context_line":"@@ -72,7 +72,7 @@ spec:"},{"line_number":35,"context_line":"                 fieldPath: status.podIP"},{"line_number":36,"context_line":" {{- if or .Values.manifests.certificates .Values.tls.identity }}"},{"line_number":37,"context_line":"           - name: REQUESTS_CA_BUNDLE"},{"line_number":38,"context_line":"-            value: \"/etc/openstack-dashboard/certs/ca.crt\""},{"line_number":39,"context_line":"+            value: \"/etc/ssl/certs/openstack-helm.crt\""}],"source_content_type":"text/x-diff","patch_set":4,"id":"3fb0f2de_2f52d23b","line":36,"updated":"2023-08-24 19:28:52.000000000","message":"In the end, both solution options would require this file to be patched and therefore, would justify an upstream contribution.\n\n1) Start using the path argument to customize the cert path (given that the side-effects you mentioned are also fixed)\n2) Stop using a hard coded path here and use some information from values.yaml to customize it","commit_id":"24dc8c9dca6c2b19dc080ebc6172610b6a19d4a7"},{"author":{"_account_id":33594,"name":"Thales Elero Cervi","display_name":"Thales Cervi","email":"thaleselero.cervi@windriver.com","username":"tcervi"},"change_message_id":"97b8e39469ab64416b8ad79eb9544e501faf0f92","unresolved":false,"context_lines":[{"line_number":33,"context_line":"+++ b/horizon/templates/deployment.yaml"},{"line_number":34,"context_line":"@@ -72,7 +72,7 @@ spec:"},{"line_number":35,"context_line":"                 fieldPath: status.podIP"},{"line_number":36,"context_line":" {{- if or .Values.manifests.certificates .Values.tls.identity }}"},{"line_number":37,"context_line":"           - name: REQUESTS_CA_BUNDLE"},{"line_number":38,"context_line":"-            value: \"/etc/openstack-dashboard/certs/ca.crt\""},{"line_number":39,"context_line":"+            value: \"/etc/ssl/certs/openstack-helm.crt\""}],"source_content_type":"text/x-diff","patch_set":4,"id":"88f4238c_02c7a38d","line":36,"in_reply_to":"3fb0f2de_2f52d23b","updated":"2023-08-28 15:02:52.000000000","message":"Done","commit_id":"24dc8c9dca6c2b19dc080ebc6172610b6a19d4a7"},{"author":{"_account_id":33594,"name":"Thales Elero Cervi","display_name":"Thales Cervi","email":"thaleselero.cervi@windriver.com","username":"tcervi"},"change_message_id":"a74e95280bfc46593d430d81aa3635544348c7c4","unresolved":true,"context_lines":[{"line_number":36,"context_line":" {{- if or .Values.manifests.certificates .Values.tls.identity }}"},{"line_number":37,"context_line":"           - name: REQUESTS_CA_BUNDLE"},{"line_number":38,"context_line":"-            value: \"/etc/openstack-dashboard/certs/ca.crt\""},{"line_number":39,"context_line":"+            value: \"/etc/ssl/certs/openstack-helm.crt\""},{"line_number":40,"context_line":" {{- end }}"},{"line_number":41,"context_line":"           lifecycle:"},{"line_number":42,"context_line":"             preStop:"}],"source_content_type":"text/x-diff","patch_set":4,"id":"2eb6b65f_ab926eae","line":39,"updated":"2023-08-24 19:22:54.000000000","message":"I don\u0027t see whit this path should be hard coded here since there is already an entri for storing this value (OPENSTACK_SSL_CACERT on template).\nIf that is not easily accessible here, we might want to propose a new values.yaml entry to handle it.\n\nThe changes to deployment.yaml would then justify a code patch until OSH accept you suggestion upstream.","commit_id":"24dc8c9dca6c2b19dc080ebc6172610b6a19d4a7"},{"author":{"_account_id":33594,"name":"Thales Elero Cervi","display_name":"Thales Cervi","email":"thaleselero.cervi@windriver.com","username":"tcervi"},"change_message_id":"dc46e73e6fadacfa9ac55109b7941141ed6b5379","unresolved":false,"context_lines":[{"line_number":36,"context_line":" {{- if or .Values.manifests.certificates .Values.tls.identity }}"},{"line_number":37,"context_line":"           - name: REQUESTS_CA_BUNDLE"},{"line_number":38,"context_line":"-            value: \"/etc/openstack-dashboard/certs/ca.crt\""},{"line_number":39,"context_line":"+            value: \"/etc/ssl/certs/openstack-helm.crt\""},{"line_number":40,"context_line":" {{- end }}"},{"line_number":41,"context_line":"           lifecycle:"},{"line_number":42,"context_line":"             preStop:"}],"source_content_type":"text/x-diff","patch_set":4,"id":"95c3387b_cd3ddee1","line":39,"in_reply_to":"2eb6b65f_ab926eae","updated":"2023-08-28 15:02:00.000000000","message":"Done","commit_id":"24dc8c9dca6c2b19dc080ebc6172610b6a19d4a7"},{"author":{"_account_id":33594,"name":"Thales Elero Cervi","display_name":"Thales Cervi","email":"thaleselero.cervi@windriver.com","username":"tcervi"},"change_message_id":"a74e95280bfc46593d430d81aa3635544348c7c4","unresolved":true,"context_lines":[{"line_number":49,"context_line":"         {{- if .Values.manifests.certificates }}"},{"line_number":50,"context_line":"         # The CA certificate to use to verify SSL connections"},{"line_number":51,"context_line":"-        OPENSTACK_SSL_CACERT \u003d \u0027/etc/openstack-dashboard/certs/ca.crt\u0027"},{"line_number":52,"context_line":"+        OPENSTACK_SSL_CACERT \u003d \u0027/etc/ssl/certs/openstack-helm.crt\u0027"},{"line_number":53,"context_line":"         {{- end }}"},{"line_number":54,"context_line":" "},{"line_number":55,"context_line":"         # The OPENSTACK_KEYSTONE_BACKEND settings can be used to identify the"}],"source_content_type":"text/x-diff","patch_set":4,"id":"0cbf6a52_11451f3e","line":52,"updated":"2023-08-24 19:22:54.000000000","message":"We don\u0027t use to override values.yaml entries via patches, we use the Helm Release static override file for this kind of implementation [1]\n\n[1] https://opendev.org/starlingx/openstack-armada-app/src/commit/be56c15bc043528f4448ae607182d97641fc8766/stx-openstack-helm-fluxcd/stx-openstack-helm-fluxcd/manifests/horizon/horizon-static-overrides.yaml#L313","commit_id":"24dc8c9dca6c2b19dc080ebc6172610b6a19d4a7"},{"author":{"_account_id":33594,"name":"Thales Elero Cervi","display_name":"Thales Cervi","email":"thaleselero.cervi@windriver.com","username":"tcervi"},"change_message_id":"dc46e73e6fadacfa9ac55109b7941141ed6b5379","unresolved":false,"context_lines":[{"line_number":49,"context_line":"         {{- if .Values.manifests.certificates }}"},{"line_number":50,"context_line":"         # The CA certificate to use to verify SSL connections"},{"line_number":51,"context_line":"-        OPENSTACK_SSL_CACERT \u003d \u0027/etc/openstack-dashboard/certs/ca.crt\u0027"},{"line_number":52,"context_line":"+        OPENSTACK_SSL_CACERT \u003d \u0027/etc/ssl/certs/openstack-helm.crt\u0027"},{"line_number":53,"context_line":"         {{- end }}"},{"line_number":54,"context_line":" "},{"line_number":55,"context_line":"         # The OPENSTACK_KEYSTONE_BACKEND settings can be used to identify the"}],"source_content_type":"text/x-diff","patch_set":4,"id":"4a0b8288_caf5e302","line":52,"in_reply_to":"0cbf6a52_11451f3e","updated":"2023-08-28 15:02:00.000000000","message":"Done","commit_id":"24dc8c9dca6c2b19dc080ebc6172610b6a19d4a7"}]}
