From c3aa3c36233b79b3391e95a4ce100bde3e667391 Mon Sep 17 00:00:00 2001 From: Dmitriy Rabotyagov Date: Tue, 14 May 2024 13:41:30 +0200 Subject: [PATCH] Change example to contain domain name instead of UUID Depends-On: https://review.opendev.org/c/openstack/openstack-ansible-openstack_hosts/+/930272 Depends-On: https://review.opendev.org/c/openstack/openstack-ansible-rabbitmq_server/+/930446 Related-Bug: #2065680 Closes-Bug: #2064718 Change-Id: I5d9505ed4b385673cc719e9821ee2e1c2ba5c754 --- defaults/main.yml | 8 ++++---- .../federated_domain_names-4e169b8b9a947940.yaml | 13 +++++++++++++ 2 files changed, 17 insertions(+), 4 deletions(-) create mode 100644 releasenotes/notes/federated_domain_names-4e169b8b9a947940.yaml diff --git a/defaults/main.yml b/defaults/main.yml index ac118388..31d2a60a 100644 --- a/defaults/main.yml +++ b/defaults/main.yml @@ -464,7 +464,7 @@ keystone_sp: {} # metadata_file: 'metadata-keystone-idp.xml' # metadata_reload: 1800 # federated_identities: -# - domain: default +# - domain: Default # project: fedproject # group: fedgroup # role: member @@ -501,7 +501,7 @@ keystone_sp: {} # metadata_file: 'metadata-testshib-idp.xml' # metadata_reload: 1800 # federated_identities: -# - domain: default +# - domain: Default # project: fedproject # group: fedgroup # role: member @@ -527,7 +527,7 @@ keystone_sp: {} # metadata_file: 'metadata-adfs-idp.xml' # metadata_reload: 1800 # federated_identities: -# - domain: default +# - domain: Default # project: fedproject # group: fedgroup # role: member @@ -566,7 +566,7 @@ keystone_sp: {} # entity_ids: # - 'https://identity-provider/openid-endpoint/' # federated_identities: -# - domain: default +# - domain: Default # project: fedproject # group: fedgroup # role: member diff --git a/releasenotes/notes/federated_domain_names-4e169b8b9a947940.yaml b/releasenotes/notes/federated_domain_names-4e169b8b9a947940.yaml new file mode 100644 index 00000000..d323661d --- /dev/null +++ b/releasenotes/notes/federated_domain_names-4e169b8b9a947940.yaml @@ -0,0 +1,13 @@ +--- +issues: + - | + Due to the underlying `bug `_ + in Ansible collections for OpenStack, ``Default`` domain name can be + renamed to ``default`` under certain conditions. + One known example is having ``domain: default`` defenition under + ``keystone_sp -> trusted_idp_list -> federated_identities`` structure. +upgrade: + - | + Please, make sure that in case of federation usage you define domain + name instead of it's ID (ie. ``Default`` instead of ``default``) + under ``keystone_sp -> trusted_idp_list -> federated_identities``