)]}'
{"doc/source/howtos/zookeeper.rst":[{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"0e1164df0f3ae024043fd252c12c946d10001972","unresolved":false,"context_lines":[{"line_number":58,"context_line":"---------------------"},{"line_number":59,"context_line":""},{"line_number":60,"context_line":"ZooKeeper version 3.5.1 or greater is required for TLS support."},{"line_number":61,"context_line":"ZooKeeper performs hostname and validation, therefore each member of"},{"line_number":62,"context_line":"the ZooKeeper cluster should have its own certificate.  The"},{"line_number":63,"context_line":"``tools/zk-ca.sh`` script in the Zuul source code repository can be"},{"line_number":64,"context_line":"used to quickly and easily generate self-signed certificates for all"}],"source_content_type":"text/x-rst","patch_set":4,"id":"1fa4df85_3e79cb2e","line":61,"range":{"start_line":61,"start_character":28,"end_line":61,"end_character":42},"updated":"2020-03-11 22:45:26.000000000","message":"Should this be \"and client validation\"? Or perhaps \"performs hostname validation\".","commit_id":"b4a31eadcb9499e8a5f86e3af17ff47c45e510bf"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"f1b957e0070c390e73d4e523a5efef1aed30d7fb","unresolved":false,"context_lines":[{"line_number":58,"context_line":"---------------------"},{"line_number":59,"context_line":""},{"line_number":60,"context_line":"ZooKeeper version 3.5.1 or greater is required for TLS support."},{"line_number":61,"context_line":"ZooKeeper performs hostname and validation, therefore each member of"},{"line_number":62,"context_line":"the ZooKeeper cluster should have its own certificate.  The"},{"line_number":63,"context_line":"``tools/zk-ca.sh`` script in the Zuul source code repository can be"},{"line_number":64,"context_line":"used to quickly and easily generate self-signed certificates for all"}],"source_content_type":"text/x-rst","patch_set":4,"id":"1fa4df85_3ecc6b60","line":61,"updated":"2020-03-11 22:51:40.000000000","message":"Yep.  Fixed.","commit_id":"b4a31eadcb9499e8a5f86e3af17ff47c45e510bf"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"0e1164df0f3ae024043fd252c12c946d10001972","unresolved":false,"context_lines":[{"line_number":100,"context_line":""},{"line_number":101,"context_line":"    keyfile\u003d\u0027/etc/zookeeper/ca/keys/clientkey.pem\u0027,"},{"line_number":102,"context_line":"    certfile\u003d\u0027/etc/zookeeper/ca/certs/client.pem\u0027,"},{"line_number":103,"context_line":"    ca\u003d\u0027/etc/zookeeper/ca/certs/cacert.pem\u0027,"}],"source_content_type":"text/x-rst","patch_set":4,"id":"1fa4df85_5e97e73b","line":103,"updated":"2020-03-11 22:45:26.000000000","message":"Might be worth adding the section to which to add these key value pairs.","commit_id":"b4a31eadcb9499e8a5f86e3af17ff47c45e510bf"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"f1b957e0070c390e73d4e523a5efef1aed30d7fb","unresolved":false,"context_lines":[{"line_number":100,"context_line":""},{"line_number":101,"context_line":"    keyfile\u003d\u0027/etc/zookeeper/ca/keys/clientkey.pem\u0027,"},{"line_number":102,"context_line":"    certfile\u003d\u0027/etc/zookeeper/ca/certs/client.pem\u0027,"},{"line_number":103,"context_line":"    ca\u003d\u0027/etc/zookeeper/ca/certs/cacert.pem\u0027,"}],"source_content_type":"text/x-rst","patch_set":4,"id":"1fa4df85_ded8b71f","line":103,"updated":"2020-03-11 22:51:40.000000000","message":"Yep.  Doesn\u0027t exist in Zuul yet.","commit_id":"b4a31eadcb9499e8a5f86e3af17ff47c45e510bf"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"b076e0e95d3d1ff84d4cb23c5e788d162da0d2f8","unresolved":false,"context_lines":[{"line_number":93,"context_line":""},{"line_number":94,"context_line":"Change the name of the certificate filenames as appropriate for the"},{"line_number":95,"context_line":"host (e.g., ``zookeeper1.example.com.jks``).  Note that the keystore"},{"line_number":96,"context_line":"password ``changeit`` does not need to be changed unless you want to."},{"line_number":97,"context_line":""},{"line_number":98,"context_line":"In order to disable plaintext connections, ensure that the"},{"line_number":99,"context_line":"``clientPort`` option does not appear in ``zoo.cfg``.  Use the new"}],"source_content_type":"text/x-rst","patch_set":8,"id":"1fa4df85_03f90f4c","line":96,"updated":"2020-03-12 16:05:49.000000000","message":"Good idea, or maybe \"keystorepassword\".  I should also expaind on why we don\u0027t need to change it (some java programs behave badly if a keystore has no password or a blank password).","commit_id":"9c5e973e24ca051865395d1f8127102c096840ce"},{"author":{"_account_id":9311,"name":"Tristan Cacqueray","email":"tdecacqu@redhat.com","username":"tristanC"},"change_message_id":"d4d9aabc9bd834d3fff988187752e10372b4bf78","unresolved":false,"context_lines":[{"line_number":93,"context_line":""},{"line_number":94,"context_line":"Change the name of the certificate filenames as appropriate for the"},{"line_number":95,"context_line":"host (e.g., ``zookeeper1.example.com.jks``).  Note that the keystore"},{"line_number":96,"context_line":"password ``changeit`` does not need to be changed unless you want to."},{"line_number":97,"context_line":""},{"line_number":98,"context_line":"In order to disable plaintext connections, ensure that the"},{"line_number":99,"context_line":"``clientPort`` option does not appear in ``zoo.cfg``.  Use the new"}],"source_content_type":"text/x-rst","patch_set":8,"id":"1fa4df85_43686720","line":96,"range":{"start_line":96,"start_character":11,"end_line":96,"end_character":19},"updated":"2020-03-12 16:00:54.000000000","message":"If we don\u0027t have to change it, shouldn\u0027t this value be renamed to something else like \u0027secret\u0027 ?","commit_id":"9c5e973e24ca051865395d1f8127102c096840ce"},{"author":{"_account_id":3099,"name":"David Shrewsbury","email":"dshrewsb@redhat.com","username":"dshrews"},"change_message_id":"d43fb274d343bd7a764b957f726a74e3fb9c6b6f","unresolved":false,"context_lines":[{"line_number":96,"context_line":"password ``keystorepassword``, which is set by the ``zk-ca.sh``"},{"line_number":97,"context_line":"script, does not need to be changed as long as file permissions"},{"line_number":98,"context_line":"provide sufficient protection.  The password is present because many"},{"line_number":99,"context_line":"Java utilities misbehave when interacting with keystores with with"},{"line_number":100,"context_line":"empty or missing passwords."},{"line_number":101,"context_line":""},{"line_number":102,"context_line":"In order to disable plaintext connections, ensure that the"}],"source_content_type":"text/x-rst","patch_set":9,"id":"1fa4df85_c77302b1","line":99,"range":{"start_line":99,"start_character":57,"end_line":99,"end_character":66},"updated":"2020-03-12 16:20:54.000000000","message":"nit: double \u0027with\u0027","commit_id":"f97c56033679e5fa8d9dbde6c43a472b5d880885"},{"author":{"_account_id":3099,"name":"David Shrewsbury","email":"dshrewsb@redhat.com","username":"dshrews"},"change_message_id":"d43fb274d343bd7a764b957f726a74e3fb9c6b6f","unresolved":false,"context_lines":[{"line_number":109,"context_line":"   server.2\u003dzookeeper2.example.com:2888:3888"},{"line_number":110,"context_line":"   server.3\u003dzookeeper3.example.com:2888:3888"},{"line_number":111,"context_line":""},{"line_number":112,"context_line":"This format normally includes ``;2181`` at the end of each line,"},{"line_number":113,"context_line":"signifying that the server should listen on port 2181 for plaintext"},{"line_number":114,"context_line":"client connections (this is equivalent to the ``clientPort`` option)."},{"line_number":115,"context_line":"Omit it to disable plaintext connections.  The earlier addition of"}],"source_content_type":"text/x-rst","patch_set":9,"id":"1fa4df85_87aaeacf","line":112,"range":{"start_line":112,"start_character":32,"end_line":112,"end_character":37},"updated":"2020-03-12 16:20:54.000000000","message":"Should this be \":2181\" instead? Semicolon seems odd given the use of colons in the examples above.","commit_id":"f97c56033679e5fa8d9dbde6c43a472b5d880885"}],"tests/base.py":[{"author":{"_account_id":9311,"name":"Tristan Cacqueray","email":"tdecacqu@redhat.com","username":"tristanC"},"change_message_id":"d5f0d85a9e1e3c93c88d0a5e29551fc223e17786","unresolved":false,"context_lines":[{"line_number":3193,"context_line":"            info\u003dself.info,"},{"line_number":3194,"context_line":"            connections\u003dself.connections,"},{"line_number":3195,"context_line":"            zk_hosts\u003dself.zk_hosts,"},{"line_number":3196,"context_line":"            zk_timeout\u003d10,"},{"line_number":3197,"context_line":"            command_socket\u003dos.path.join(self.test_root, \u0027web.socket\u0027),"},{"line_number":3198,"context_line":"            authenticators\u003dself.authenticators)"},{"line_number":3199,"context_line":"        self.web.start()"}],"source_content_type":"text/x-python","patch_set":19,"id":"df33271e_87a56fb8","line":3196,"range":{"start_line":3196,"start_character":12,"end_line":3196,"end_character":26},"updated":"2020-03-23 17:21:36.000000000","message":"Is this still needed?","commit_id":"93ec3daf4745a0c2cd586b83edcdabfb1eef0513"}],"tools/zk-ca.sh":[{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"b076e0e95d3d1ff84d4cb23c5e788d162da0d2f8","unresolved":false,"context_lines":[{"line_number":1,"context_line":"#!/bin/sh"},{"line_number":2,"context_line":""},{"line_number":3,"context_line":"# Copyright 2020 Red Hat, Inc"},{"line_number":4,"context_line":"#"}],"source_content_type":"text/x-sh","patch_set":8,"id":"1fa4df85_a3935b00","line":1,"updated":"2020-03-12 16:05:49.000000000","message":"Just trying to be helpful.  This seemed like more of a bash thing than ansible: a sequence of commands with conditionals.  There\u0027s no interacting with remote nodes or anything.  This is pretty easy to invoke from ansible.  But sure, maybe in the future we should move this to galaxy or something.","commit_id":"9c5e973e24ca051865395d1f8127102c096840ce"},{"author":{"_account_id":9311,"name":"Tristan Cacqueray","email":"tdecacqu@redhat.com","username":"tristanC"},"change_message_id":"d4d9aabc9bd834d3fff988187752e10372b4bf78","unresolved":false,"context_lines":[{"line_number":1,"context_line":"#!/bin/sh"},{"line_number":2,"context_line":""},{"line_number":3,"context_line":"# Copyright 2020 Red Hat, Inc"},{"line_number":4,"context_line":"#"}],"source_content_type":"text/x-sh","patch_set":8,"id":"1fa4df85_83117faf","line":1,"updated":"2020-03-12 16:00:54.000000000","message":"That\u0027s a bit odd to provide such script, wouldn\u0027t it better to wrap the commands with an ansible role to improve re-usability?","commit_id":"9c5e973e24ca051865395d1f8127102c096840ce"},{"author":{"_account_id":9311,"name":"Tristan Cacqueray","email":"tdecacqu@redhat.com","username":"tristanC"},"change_message_id":"bcd76d143bce58d4e287c9646c5ff1d2495983fc","unresolved":false,"context_lines":[{"line_number":1,"context_line":"#!/bin/sh"},{"line_number":2,"context_line":""},{"line_number":3,"context_line":"# Copyright 2020 Red Hat, Inc"},{"line_number":4,"context_line":"#"}],"source_content_type":"text/x-sh","patch_set":8,"id":"1fa4df85_2749b65f","line":1,"in_reply_to":"1fa4df85_a3935b00","updated":"2020-03-12 16:18:56.000000000","message":"I meant we are probably going to use this script, and I guess other too. How is opendev admin going to setup TLS for zk?\n\nShould I copy and execute it in zuul-operator?","commit_id":"9c5e973e24ca051865395d1f8127102c096840ce"},{"author":{"_account_id":9311,"name":"Tristan Cacqueray","email":"tdecacqu@redhat.com","username":"tristanC"},"change_message_id":"a6586f964a4c3fecbeac46373d463bd7736c00bb","unresolved":false,"context_lines":[{"line_number":1,"context_line":"#!/bin/sh"},{"line_number":2,"context_line":""},{"line_number":3,"context_line":"# Copyright 2020 Red Hat, Inc"},{"line_number":4,"context_line":"#"}],"source_content_type":"text/x-sh","patch_set":10,"id":"1fa4df85_dbd437c0","line":1,"updated":"2020-03-12 20:03:03.000000000","message":"Should it run with the `-e` argument?","commit_id":"11b6de86066a0a284f9ee9a9cd195217314530e3"},{"author":{"_account_id":9311,"name":"Tristan Cacqueray","email":"tdecacqu@redhat.com","username":"tristanC"},"change_message_id":"7e50d8b6351239d686b841c0d4406e38df99d51f","unresolved":false,"context_lines":[{"line_number":96,"context_line":"    exit 1"},{"line_number":97,"context_line":"fi"},{"line_number":98,"context_line":""},{"line_number":99,"context_line":"cd $CAROOT"},{"line_number":100,"context_line":""},{"line_number":101,"context_line":"if [ ! -d \"$CAROOT/demoCA\" ]; then"},{"line_number":102,"context_line":"    echo \u0027Generate CA\u0027"}],"source_content_type":"text/x-sh","patch_set":10,"id":"1fa4df85_96f456d1","line":99,"range":{"start_line":99,"start_character":0,"end_line":99,"end_character":10},"updated":"2020-03-12 20:44:45.000000000","message":"This is not working when CAROOT is not absolute.","commit_id":"11b6de86066a0a284f9ee9a9cd195217314530e3"},{"author":{"_account_id":16068,"name":"Tobias Henkel","email":"tobias.henkel@bmw.de","username":"tobias.henkel"},"change_message_id":"4c5c6cfd04026b72042c85830c819f7b67a174fd","unresolved":false,"context_lines":[{"line_number":64,"context_line":"    openssl ca $CONFIG -batch -policy policy_anything -days 3560 \\"},{"line_number":65,"context_line":"            -out $CAROOT/certs/$SERVER.pem \\"},{"line_number":66,"context_line":"            -infiles $CAROOT/demoCA/reqs/${SERVER}req.pem"},{"line_number":67,"context_line":"    cat $CAROOT/certs/$SERVER.pem $CAROOT/keys/${SERVER}key.pem \\"},{"line_number":68,"context_line":"        \u003e $CAROOT/keystores/$SERVER.pem"},{"line_number":69,"context_line":"}"},{"line_number":70,"context_line":""}],"source_content_type":"text/x-sh","patch_set":19,"id":"df33271e_04f2189b","line":67,"updated":"2020-04-03 13:41:46.000000000","message":"Can this be used directly or does it need to be converted to jks for use in zk?","commit_id":"93ec3daf4745a0c2cd586b83edcdabfb1eef0513"},{"author":{"_account_id":16068,"name":"Tobias Henkel","email":"tobias.henkel@bmw.de","username":"tobias.henkel"},"change_message_id":"f22ff7ae7b0da3ad630dc06e2ee166d7404adde2","unresolved":false,"context_lines":[{"line_number":64,"context_line":"    openssl ca $CONFIG -batch -policy policy_anything -days 3560 \\"},{"line_number":65,"context_line":"            -out $CAROOT/certs/$SERVER.pem \\"},{"line_number":66,"context_line":"            -infiles $CAROOT/demoCA/reqs/${SERVER}req.pem"},{"line_number":67,"context_line":"    cat $CAROOT/certs/$SERVER.pem $CAROOT/keys/${SERVER}key.pem \\"},{"line_number":68,"context_line":"        \u003e $CAROOT/keystores/$SERVER.pem"},{"line_number":69,"context_line":"}"},{"line_number":70,"context_line":""}],"source_content_type":"text/x-sh","patch_set":19,"id":"df33271e_67e046fc","line":67,"in_reply_to":"df33271e_04f2189b","updated":"2020-04-03 14:11:07.000000000","message":"Yes, can be used, see https://review.opendev.org/#/c/712817/7/doc/source/examples/zoo.cfg","commit_id":"93ec3daf4745a0c2cd586b83edcdabfb1eef0513"}],"zuul/cmd/scheduler.py":[{"author":{"_account_id":9311,"name":"Tristan Cacqueray","email":"tdecacqu@redhat.com","username":"tristanC"},"change_message_id":"f8e96e3a92785ba52504cde884bf2eb1f7ffc418","unresolved":false,"context_lines":[{"line_number":159,"context_line":"        zookeeper.connect("},{"line_number":160,"context_line":"            zookeeper_hosts,"},{"line_number":161,"context_line":"            timeout\u003dzookeeper_timeout,"},{"line_number":162,"context_line":"            auth_data\u003dzuul.zk_auth.from_config(self.config),"},{"line_number":163,"context_line":"            tls_cert\u003dzookeeper_tls_cert,"},{"line_number":164,"context_line":"            tls_key\u003dzookeeper_tls_key,"},{"line_number":165,"context_line":"            tls_ca\u003dzookeeper_tls_ca)"}],"source_content_type":"text/x-python","patch_set":13,"id":"1fa4df85_813df22d","line":162,"updated":"2020-03-12 22:35:39.000000000","message":"this is missing the use_ssl argument.","commit_id":"6cb9c1ae95ac0a3bb5e584da972bf5bc4c3e114e"},{"author":{"_account_id":9311,"name":"Tristan Cacqueray","email":"tdecacqu@redhat.com","username":"tristanC"},"change_message_id":"019160ab4564455b8af576f55208dbceb641fca3","unresolved":false,"context_lines":[{"line_number":159,"context_line":"        zookeeper.connect("},{"line_number":160,"context_line":"            zookeeper_hosts,"},{"line_number":161,"context_line":"            timeout\u003dzookeeper_timeout,"},{"line_number":162,"context_line":"            auth_data\u003dzuul.zk_auth.from_config(self.config),"},{"line_number":163,"context_line":"            tls_cert\u003dzookeeper_tls_cert,"},{"line_number":164,"context_line":"            tls_key\u003dzookeeper_tls_key,"},{"line_number":165,"context_line":"            tls_ca\u003dzookeeper_tls_ca)"}],"source_content_type":"text/x-python","patch_set":13,"id":"1fa4df85_a15b4e52","line":162,"in_reply_to":"1fa4df85_813df22d","updated":"2020-03-12 23:03:20.000000000","message":"oops, that\u0027s not the kazoo function.","commit_id":"6cb9c1ae95ac0a3bb5e584da972bf5bc4c3e114e"}]}
