[Openstack-operators] Keystone token HA

Matteo Panella matteo.panella at cnaf.infn.it
Mon Dec 21 08:57:14 UTC 2015


On 18/12/2015 17:55, Bajin, Joseph wrote:
> That was me.. 
> 
> We are using McRouter which then speaks to memcached to talk to all the
> memcache servers that you have up and running. It keeps track of what is
> up and down so it knows where to send traffic.  You can get pretty
> complicated with it and we have started to do more complex operations
> such as warming up cache’s, going across regions to look in that cache
> for things like tokens, and a few others. 

Warming up in case of a cache failure would indeed be nice, we have had
a few troubles with cache misses for nova-consoleauth and shared
keystoneclient token caches (mainly nova) in the past when a memcache
node failed and came back online. Nothing serious, but somewhat annoying :-)

Thanks for the example config, it's a good starting point (especially
for an McRouter newbie like myself).

All the best,
-- 
Matteo Panella
INFN CNAF
Via Ranzani 13/2 c - 40127 Bologna, Italy
Phone: +39 051 609 2903

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 1893 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://lists.openstack.org/pipermail/openstack-operators/attachments/20151221/a5220020/attachment.bin>


More information about the OpenStack-operators mailing list