)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"e70df7ffa7159cd500822e81973b376ae5202994","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"8c13902b_22a53811","updated":"2025-04-17 13:48:26.000000000","message":"Looks good ... just a bunch of minor comments.","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"3cff162923ab16dc025cf752bd8005d560d8e450","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"eb8d7834_58d3cf2d","updated":"2025-05-01 15:55:01.000000000","message":"Strangely I don\u0027t receive email notification for the comments.","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"5ae04c11df3486debba0e485dcff6adcc4264b9b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"1dc91c2c_0bc92b64","updated":"2025-06-30 12:22:12.000000000","message":"@chris.friesen@windriver.com ... have you had a chance to look thru this ?","commit_id":"e865d5c7ed809415ea648c16f15cba7510b7a489"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"82d54a63edbfb9fa3ff6d5aeb15b190914ba78db","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"093cf837_96e2f7ee","updated":"2025-05-28 13:47:10.000000000","message":"Just a reminder to TSC members, Thales, Chris and Shuquan, to review this spec that has been open for a while.","commit_id":"e865d5c7ed809415ea648c16f15cba7510b7a489"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"dfddd61fdbe9ecf913eb39a18acdb0ab8d3736ed","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"96fdf25a_f73488c3","updated":"2025-07-03 01:22:37.000000000","message":"Merging this as it has been reviewed by both myself and Thales of TSC team.","commit_id":"e865d5c7ed809415ea648c16f15cba7510b7a489"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"5e14dc2e6ec3bfa1f8bb4196655e9a6db9fe8ce7","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"5c019555_2ef7e393","updated":"2025-05-08 01:39:15.000000000","message":"Thales can you take a look at this ?","commit_id":"e865d5c7ed809415ea648c16f15cba7510b7a489"}],"doc/source/specs/stx-11.0/approved/security-2011127-pod-to-pod-IPsec.rst":[{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"e70df7ffa7159cd500822e81973b376ae5202994","unresolved":true,"context_lines":[{"line_number":3,"context_line":"  License. http://creativecommons.org/licenses/by/3.0/legalcode"},{"line_number":4,"context_line":""},{"line_number":5,"context_line":".."},{"line_number":6,"context_line":"  Many thanks to the OpenStack Nova team for the Example Spec that formed the"},{"line_number":7,"context_line":"  basis for this document."},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":10,"context_line":"Secure Inter Host Pod-to-Pod Network Traffic Using IPsec"}],"source_content_type":"text/x-rst","patch_set":1,"id":"1bc8dc3e_2b454946","line":7,"range":{"start_line":6,"start_character":0,"end_line":7,"end_character":26},"updated":"2025-04-17 13:48:26.000000000","message":"REMOVE ?","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"3cff162923ab16dc025cf752bd8005d560d8e450","unresolved":false,"context_lines":[{"line_number":3,"context_line":"  License. http://creativecommons.org/licenses/by/3.0/legalcode"},{"line_number":4,"context_line":""},{"line_number":5,"context_line":".."},{"line_number":6,"context_line":"  Many thanks to the OpenStack Nova team for the Example Spec that formed the"},{"line_number":7,"context_line":"  basis for this document."},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":10,"context_line":"Secure Inter Host Pod-to-Pod Network Traffic Using IPsec"}],"source_content_type":"text/x-rst","patch_set":1,"id":"499c9040_ac3f2d11","line":7,"range":{"start_line":6,"start_character":0,"end_line":7,"end_character":26},"in_reply_to":"1bc8dc3e_2b454946","updated":"2025-05-01 15:55:01.000000000","message":"Acknowledged","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"e70df7ffa7159cd500822e81973b376ae5202994","unresolved":true,"context_lines":[{"line_number":12,"context_line":""},{"line_number":13,"context_line":"Storyboard: https://storyboard.openstack.org/#!/story/2011127"},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"The objective of this feature is to secure inter host pod-to-pod network"},{"line_number":16,"context_line":"traffic for kubernetes applications on StarlingX platform. The proposed"},{"line_number":17,"context_line":"mechanism is by using IPsec."},{"line_number":18,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"84c72c60_529f48d7","line":15,"range":{"start_line":15,"start_character":36,"end_line":15,"end_character":43},"updated":"2025-04-17 13:48:26.000000000","message":"? configurably secure specific ?","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"3cff162923ab16dc025cf752bd8005d560d8e450","unresolved":false,"context_lines":[{"line_number":12,"context_line":""},{"line_number":13,"context_line":"Storyboard: https://storyboard.openstack.org/#!/story/2011127"},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"The objective of this feature is to secure inter host pod-to-pod network"},{"line_number":16,"context_line":"traffic for kubernetes applications on StarlingX platform. The proposed"},{"line_number":17,"context_line":"mechanism is by using IPsec."},{"line_number":18,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"a6f877f9_9e83c175","line":15,"range":{"start_line":15,"start_character":36,"end_line":15,"end_character":43},"in_reply_to":"84c72c60_529f48d7","updated":"2025-05-01 15:55:01.000000000","message":"Acknowledged","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"e70df7ffa7159cd500822e81973b376ae5202994","unresolved":true,"context_lines":[{"line_number":22,"context_line":"Currently on a StarlingX system, inter host traffics among application"},{"line_number":23,"context_line":"pods are not explicitly protected by the platform. Though applications"},{"line_number":24,"context_line":"may use other mechanism such as HTTPS to protect them, it means more"},{"line_number":25,"context_line":"works for the applications. Also the existing applications will need"},{"line_number":26,"context_line":"to be upgraded."},{"line_number":27,"context_line":""},{"line_number":28,"context_line":"This feature proposes to protect application traffic by using IPsec to"},{"line_number":29,"context_line":"encrypt inter host pod to pod traffic on cluster host network. This"}],"source_content_type":"text/x-rst","patch_set":1,"id":"4729cdda_3aba4d1e","line":26,"range":{"start_line":25,"start_character":28,"end_line":26,"end_character":15},"updated":"2025-04-17 13:48:26.000000000","message":"? Also existing applications, not supporting HTTPS, would need to be upgraded. ?","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"3cff162923ab16dc025cf752bd8005d560d8e450","unresolved":false,"context_lines":[{"line_number":22,"context_line":"Currently on a StarlingX system, inter host traffics among application"},{"line_number":23,"context_line":"pods are not explicitly protected by the platform. Though applications"},{"line_number":24,"context_line":"may use other mechanism such as HTTPS to protect them, it means more"},{"line_number":25,"context_line":"works for the applications. Also the existing applications will need"},{"line_number":26,"context_line":"to be upgraded."},{"line_number":27,"context_line":""},{"line_number":28,"context_line":"This feature proposes to protect application traffic by using IPsec to"},{"line_number":29,"context_line":"encrypt inter host pod to pod traffic on cluster host network. This"}],"source_content_type":"text/x-rst","patch_set":1,"id":"1393fe19_6379912f","line":26,"range":{"start_line":25,"start_character":28,"end_line":26,"end_character":15},"in_reply_to":"4729cdda_3aba4d1e","updated":"2025-05-01 15:55:01.000000000","message":"Acknowledged","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"e70df7ffa7159cd500822e81973b376ae5202994","unresolved":true,"context_lines":[{"line_number":25,"context_line":"works for the applications. Also the existing applications will need"},{"line_number":26,"context_line":"to be upgraded."},{"line_number":27,"context_line":""},{"line_number":28,"context_line":"This feature proposes to protect application traffic by using IPsec to"},{"line_number":29,"context_line":"encrypt inter host pod to pod traffic on cluster host network. This"},{"line_number":30,"context_line":"protection is provided by the platform which can be utilized by any"},{"line_number":31,"context_line":"applications. It protects applications from  both passive (i.e. snooping"}],"source_content_type":"text/x-rst","patch_set":1,"id":"96817d36_e6674ab6","line":28,"range":{"start_line":28,"start_character":25,"end_line":28,"end_character":33},"updated":"2025-04-17 13:48:26.000000000","message":"? configurably protect specific ?","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"3cff162923ab16dc025cf752bd8005d560d8e450","unresolved":false,"context_lines":[{"line_number":25,"context_line":"works for the applications. Also the existing applications will need"},{"line_number":26,"context_line":"to be upgraded."},{"line_number":27,"context_line":""},{"line_number":28,"context_line":"This feature proposes to protect application traffic by using IPsec to"},{"line_number":29,"context_line":"encrypt inter host pod to pod traffic on cluster host network. This"},{"line_number":30,"context_line":"protection is provided by the platform which can be utilized by any"},{"line_number":31,"context_line":"applications. It protects applications from  both passive (i.e. snooping"}],"source_content_type":"text/x-rst","patch_set":1,"id":"6e7dd5fa_b03fc6dd","line":28,"range":{"start_line":28,"start_character":25,"end_line":28,"end_character":33},"in_reply_to":"96817d36_e6674ab6","updated":"2025-05-01 15:55:01.000000000","message":"Acknowledged","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"e70df7ffa7159cd500822e81973b376ae5202994","unresolved":true,"context_lines":[{"line_number":39,"context_line":"their inter host pod-to-pod traffic."},{"line_number":40,"context_line":""},{"line_number":41,"context_line":"* End users: "},{"line_number":42,"context_line":"  End users can add, update or delete IPsec policies (i.e, what services,"},{"line_number":43,"context_line":"  protocols and ports to protect) for their applications. "},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"  End users can do these operations by updating polices stored in kubernetes"}],"source_content_type":"text/x-rst","patch_set":1,"id":"9bf15fdb_6775bb9d","line":42,"range":{"start_line":42,"start_character":59,"end_line":42,"end_character":64},"updated":"2025-04-17 13:48:26.000000000","message":"? specifying what ?","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"3cff162923ab16dc025cf752bd8005d560d8e450","unresolved":false,"context_lines":[{"line_number":39,"context_line":"their inter host pod-to-pod traffic."},{"line_number":40,"context_line":""},{"line_number":41,"context_line":"* End users: "},{"line_number":42,"context_line":"  End users can add, update or delete IPsec policies (i.e, what services,"},{"line_number":43,"context_line":"  protocols and ports to protect) for their applications. "},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"  End users can do these operations by updating polices stored in kubernetes"}],"source_content_type":"text/x-rst","patch_set":1,"id":"ecb57351_1bfd6a3e","line":42,"range":{"start_line":42,"start_character":59,"end_line":42,"end_character":64},"in_reply_to":"9bf15fdb_6775bb9d","updated":"2025-05-01 15:55:01.000000000","message":"Acknowledged","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"e70df7ffa7159cd500822e81973b376ae5202994","unresolved":true,"context_lines":[{"line_number":107,"context_line":""},{"line_number":108,"context_line":"* An application can protect its pod-to-pod traffic by TLS (HTTPS at REST for"},{"line_number":109,"context_line":"  example). But it has to be implemented by the application itself, which makes"},{"line_number":110,"context_line":"  the appliation more complicated. The proposed IPsec soluction is transparent"},{"line_number":111,"context_line":"  to the application, leaving the application focus on its business logic."},{"line_number":112,"context_line":""},{"line_number":113,"context_line":"Data model impact"}],"source_content_type":"text/x-rst","patch_set":1,"id":"4d3f4ba6_06681aaa","line":110,"range":{"start_line":110,"start_character":6,"end_line":110,"end_character":17},"updated":"2025-04-17 13:48:26.000000000","message":"typo","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"e70df7ffa7159cd500822e81973b376ae5202994","unresolved":true,"context_lines":[{"line_number":107,"context_line":""},{"line_number":108,"context_line":"* An application can protect its pod-to-pod traffic by TLS (HTTPS at REST for"},{"line_number":109,"context_line":"  example). But it has to be implemented by the application itself, which makes"},{"line_number":110,"context_line":"  the appliation more complicated. The proposed IPsec soluction is transparent"},{"line_number":111,"context_line":"  to the application, leaving the application focus on its business logic."},{"line_number":112,"context_line":""},{"line_number":113,"context_line":"Data model impact"}],"source_content_type":"text/x-rst","patch_set":1,"id":"ef43eafd_add451af","line":110,"range":{"start_line":110,"start_character":54,"end_line":110,"end_character":64},"updated":"2025-04-17 13:48:26.000000000","message":"typo","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"3cff162923ab16dc025cf752bd8005d560d8e450","unresolved":false,"context_lines":[{"line_number":107,"context_line":""},{"line_number":108,"context_line":"* An application can protect its pod-to-pod traffic by TLS (HTTPS at REST for"},{"line_number":109,"context_line":"  example). But it has to be implemented by the application itself, which makes"},{"line_number":110,"context_line":"  the appliation more complicated. The proposed IPsec soluction is transparent"},{"line_number":111,"context_line":"  to the application, leaving the application focus on its business logic."},{"line_number":112,"context_line":""},{"line_number":113,"context_line":"Data model impact"}],"source_content_type":"text/x-rst","patch_set":1,"id":"a8567180_4051662b","line":110,"range":{"start_line":110,"start_character":6,"end_line":110,"end_character":17},"in_reply_to":"4d3f4ba6_06681aaa","updated":"2025-05-01 15:55:01.000000000","message":"Acknowledged","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"3cff162923ab16dc025cf752bd8005d560d8e450","unresolved":false,"context_lines":[{"line_number":107,"context_line":""},{"line_number":108,"context_line":"* An application can protect its pod-to-pod traffic by TLS (HTTPS at REST for"},{"line_number":109,"context_line":"  example). But it has to be implemented by the application itself, which makes"},{"line_number":110,"context_line":"  the appliation more complicated. The proposed IPsec soluction is transparent"},{"line_number":111,"context_line":"  to the application, leaving the application focus on its business logic."},{"line_number":112,"context_line":""},{"line_number":113,"context_line":"Data model impact"}],"source_content_type":"text/x-rst","patch_set":1,"id":"33d98a4b_f08a45c3","line":110,"range":{"start_line":110,"start_character":54,"end_line":110,"end_character":64},"in_reply_to":"ef43eafd_add451af","updated":"2025-05-01 15:55:01.000000000","message":"Acknowledged","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"e70df7ffa7159cd500822e81973b376ae5202994","unresolved":true,"context_lines":[{"line_number":115,"context_line":""},{"line_number":116,"context_line":"* New kubernetes CRD for IPsec policies"},{"line_number":117,"context_line":"  New CRD (Custom Resource Definition) for pod-to-pod IPsec policies will be"},{"line_number":118,"context_line":"  introduced. User defined IPsec policies will be stored in CRs abedient to the CRD."},{"line_number":119,"context_line":""},{"line_number":120,"context_line":"  A IPsec policy is defined in the CR by a name, a service in a namespace and its"},{"line_number":121,"context_line":"  protocol/ports to be protected."}],"source_content_type":"text/x-rst","patch_set":1,"id":"97b7c7c4_cc74ba9a","line":118,"updated":"2025-04-17 13:48:26.000000000","message":"typo ?","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"3cff162923ab16dc025cf752bd8005d560d8e450","unresolved":false,"context_lines":[{"line_number":115,"context_line":""},{"line_number":116,"context_line":"* New kubernetes CRD for IPsec policies"},{"line_number":117,"context_line":"  New CRD (Custom Resource Definition) for pod-to-pod IPsec policies will be"},{"line_number":118,"context_line":"  introduced. User defined IPsec policies will be stored in CRs abedient to the CRD."},{"line_number":119,"context_line":""},{"line_number":120,"context_line":"  A IPsec policy is defined in the CR by a name, a service in a namespace and its"},{"line_number":121,"context_line":"  protocol/ports to be protected."}],"source_content_type":"text/x-rst","patch_set":1,"id":"6f825b2a_4474a95b","line":118,"in_reply_to":"97b7c7c4_cc74ba9a","updated":"2025-05-01 15:55:01.000000000","message":"Acknowledged","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"e70df7ffa7159cd500822e81973b376ae5202994","unresolved":true,"context_lines":[{"line_number":149,"context_line":"---------------------"},{"line_number":150,"context_line":""},{"line_number":151,"context_line":"* The feature will be implemented as a StarlingX optional app, the app needs to be"},{"line_number":152,"context_line":"  applied in order to for it to work."},{"line_number":153,"context_line":""},{"line_number":154,"context_line":"* If no pod-to-pod IPsec policies defined, the feature is equivalent to be disabled."},{"line_number":155,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"f97a0c70_1939cf21","line":152,"range":{"start_line":152,"start_character":19,"end_line":152,"end_character":22},"updated":"2025-04-17 13:48:26.000000000","message":"typo","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"3cff162923ab16dc025cf752bd8005d560d8e450","unresolved":false,"context_lines":[{"line_number":149,"context_line":"---------------------"},{"line_number":150,"context_line":""},{"line_number":151,"context_line":"* The feature will be implemented as a StarlingX optional app, the app needs to be"},{"line_number":152,"context_line":"  applied in order to for it to work."},{"line_number":153,"context_line":""},{"line_number":154,"context_line":"* If no pod-to-pod IPsec policies defined, the feature is equivalent to be disabled."},{"line_number":155,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"c32d82b3_bee42b53","line":152,"range":{"start_line":152,"start_character":19,"end_line":152,"end_character":22},"in_reply_to":"f97a0c70_1939cf21","updated":"2025-05-01 15:55:01.000000000","message":"Acknowledged","commit_id":"9dde8ea596db79c258c7bf8233864e420ec888b8"}]}
