[openstack-dev] [tripleo] Fernet Key rotation

Adam Young ayoung at redhat.com
Wed Aug 10 14:11:50 UTC 2016


On 08/09/2016 09:21 PM, Adam Young wrote:
> On 08/09/2016 06:00 PM, Zane Bitter wrote:
>>
>> In either case a good mechanism might be to use a Heat Software 
>> Deployment via the Heat API directly (i.e. not as part of a stack) to 
>> push changes to the servers. (I say 'push' but it's more a case of 
>> making the data available for os-collect-config to grab it.)
>
> This is the part that interests me most.  The rest, I'll code in 
> python and we can call either from mistral or from Cron.  What would a 
> stack like this look like?  Are there comparable examples?
>
>
> __________________________________________________________________________ 
>
> OpenStack Development Mailing List (not for usage questions)
> Unsubscribe: 
> OpenStack-dev-request at lists.openstack.org?subject:unsubscribe
> http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev

So, another aspect to the  problem is also that this needs to be done 
initially as part of the overcloud deployment.  If we go Fernet, the 
keys need to be in place when the Keystone servers boot.




More information about the OpenStack-dev mailing list