Keystone key repository missing for credentials
Affects | Status | Importance | Assigned to | Milestone | ||
---|---|---|---|---|---|---|
kolla | ||||||
Rocky |
New
|
Medium
|
Unassigned | |||
Stein |
New
|
Medium
|
Unassigned | |||
Train |
New
|
Medium
|
Unassigned | |||
Ussuri |
Triaged
|
Medium
|
Dincer Celik | |||
kolla-ansible |
Won't Fix
|
Medium
|
Unassigned | |||
Rocky |
Won't Fix
|
Medium
|
Unassigned | |||
Stein |
Won't Fix
|
Medium
|
Unassigned | |||
Train |
Won't Fix
|
Medium
|
Unassigned | |||
Ussuri |
Won't Fix
|
Medium
|
Unassigned |
Bug Description
Keystone uses the [credential]
This is not configured with Kolla-Ansible. On a Stein deployment, we see periodic ERROR logs associated with it:
2020-02-17 17:00:25.263 30 ERROR keystone.
Note from the docs: Fernet keys used to encrypt credentials have no relationship to Fernet keys used to encrypt Fernet tokens. Both sets of keys should be managed separately and require different rotation policies. Do not share this repository with the repository used to manage keys for Fernet tokens.
Changed in kolla-ansible: | |
importance: | Undecided → Medium |
Changed in kolla-ansible: | |
assignee: | nobody → Dincer Celik (osmanlicilegi) |
affects: | kolla-ansible → kolla |
Changed in kolla: | |
milestone: | 10.0.0 → none |
Pierre, do you know what would be affected by this? Seems like it must be a less frequently used feature otherwise we'd hear about it.